Files
MISFIT/CCNewbs_pdf.md
2026-05-19 19:13:06 -07:00

1059 lines
71 KiB
Markdown
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# CCNewbs
---
Complete Guide to Carding for Newbs. Learn to
Card.
­By Sacky
VIRTUAL CARDING
This chapter is about virtual carding. Virtual carding is the art of ordering goods online using
stolen credit cards, also known as “CVV”, “pizza”, "FULLZ", any any other names the
members of the community use
to disguise their intentions. Although this seems easy, there are many pitfalls you might want
to be aware of when doing that, especially since merchants are getting more and more aware
of online fraud. Want to know how to get free goods? Let's get started!
HOW IT WORKS
The first thing is to ask yourself, how much do you want to card, and what do you want to
card? Then, you will have to pick one of those 3 levels. Each level represents a difficulty level
and you will see the prerequisites.
Level 1: Easy carding
This level is used for very easy things to card, for example restaurants and small phone
orders, mostly under $50. This is the entry point of most carders. For that, you will need:
1. Credit card number.
2. Expiration date.
Level 2: Intermediate carding
This level is used for online transactions that are slighly higher, like background reports, or a
very
small physical item. You will need:
1. Credit card number
2. Expiration date
3. CCV code
4. Cardholder name
5. Full billing address
6. Sometimes, phone number of the account
Level 3: Hard carding
This is not recommenced for beginning carders. Here we are talking about everything above
level 2, such as large physical items, or high­security websites like Newegg, TigerDirect, and
sites that require Account Take­Over (for ATO, see section 1.2 of this guide). Computer parts,
electonics, and many other items fall in this level. You need:
1. Credit card number
2. Expiration date
3. CCV code
4. Cardholder name
5. Full billing address
6. Phone numbers
7. SSN
8. DOB
9. Recommended, background report (optional)
If you are aiming for level 1 carding, you just need to call for pizza and order pizza to another
address, no need to write lengthy paragraphs on this one. This is easy and is pretty
straightfordward.
If you are aiming for level 2, you can card background reports or small physical items, mostly
under $150. All orders are done online, and you will have to enter the correct billing address,
shipping address, and card information.
Now, you must see if the websites says billing phone number on file with the bank, or simply
contact phone number. If the website asks for billing phone number, you have to put the
phone number on file with the bank for the cardholder, otherwise it is safe to put your burner
phone number. Now, is the website going to call you? It depends on the order, their policy and
their
suspicion about you, so there's no safe answer to this question. Remember that carding is
often trial and error.
When you use a card to hit a website, do not hit another website using the same card until
your order has shipped. Making an order go though and having a charge approval is easy, but
getting it shipped is often where the challenge lies.
A level 2 site that is often carded is peoplefinders.com. This is where carders get most of their
background reports. It is a good playground to test your skills, and will prove useful later.
Now, on to level 3. You probably saw the information required, now how to get it? First, if your
subject is aged under 40, chances are that you are out of luck. Otherwise, read on.
First, you need to get the right type of card. This is called finding the right BIN (Bank
Identification Number). The BIN is the first 6 digits on the card and is used to identify the card
type as well as the issuing bank. To learn more, go to bindb.com, at the top go on Bin Search,
and enter the first 6 digits of the card. They will tell you the issuing bank, and card type. You
have debit and credit cards, and the card type can vary. From the weakest to the strongest,
they are:
● Secured: Very low limits, sometimes around $300
● Classic: Low limits, sometimes around $1000
● Gold: Average limits, can be around $3000
● Platinum: High limits, can be around $8000
● Business: Very high limits, in the 5 digits, often around $15,000
● Signature: The best ones, I got cards that had $30,000 of credit limit
Note that those numbers are subject to change according to the cardholder's credit score,
history, and spending patterns. For the benefit of this guide, we will only work with credit
cards. By experience, debit cards often do not have funds, and have tighter security for online
purchases. In other words, they are rubbish for level 3 carding, but may have other uses, like
level 1 or level 2 purchases.
Register an account on any SSN finder site such as ssnfinder.ru or ssndob.cc and look for
your subject. At the same time, go on peoplefinders.com and get the full background report of
your subject using a level 2 card. Once you have the background report, look if the addresses
and date of birth match on the report and on backstab. If everything matches, you can
assume the SSN will be correct. Use your common sense to compare the backstab and
peoplefinders results to make sure you didn't get the wrong information. About 80% of the
subjects over 40 years old can be found.
You have the SSN and DOB? Great! Now, time to get the mother maiden name. This is
slightly harder and will work if your victim is in one of those states: Arizona, California,
Delaware, Idaho, Indiana, Kentucky, Maine, Maryland, Massachussetts, Minnesota, Nevada,
New Hampshire, New Jersey, Ohio, Rhode Island, South Dakota, Texas. Go on archives.com
and card an account, then look for your subject's mother (look at the background report for
her name and date of birth), and try to look for her birth record. This is a trial and error case
and works about 50% of the time.
Why get all this information? Because many level 3 sites will have either VBV (Verified by
Visa) or MCSC (MasterCard Secure Code) protection during checkout. This is a form that is
presented by the issuing bank of the credit card and asks for additional questions.
Although every type of card is different, the commonly asked questions are:
1. Date of Birth
2. Last 4 digits of SSN
3. Full name on card
4. Billing zip code
If you fail any of those questions, the order will not go through. Now, why did we need all this
information? Because we will perform a ATO on the account. This is tricky. Read the next
section for a detailed description of Account Take­Over fraud.
ACCOUNT TAKE-OVER FRAUD (ATO)
Do you dream of carding thousands of dollars worth of computer hardware on Newegg? It's
doable, but not easy. You have to follow the right steps. I carded a $10,000 gaming rig in
under 2 weeks using platinum cards by following that guide, so I'm in position to tell you how.
First thing, check the balance of your credit card. Now, before going crazy, remember this rule
of thumb: Do not use card checkers! They burn the card very quick. Let me explain.
Every transaction automatically gets a fraud score between 0 and 999. The system used to
evaluate transactions is the same used by the big 4 banks and is called Fair Issac.
Transactions having a fraud score over 300 will hit manual review by an agent, who will
decide if they contact the cardholder or just let it though. Scores over 500 with auto­decline,
block the card, and an agent will contact the cardholder. Some banks have different criterias,
but things that can affect the fraud score are:
1. Comparison with the usual spending pattern of the cardholder
2. Location of the charge
3. Amount
4. Risk factor of the associated merchant
For example, a $20 charge in the cardholder's local Walmart will not trigger anything, but a
large purchase of $2000 on Newegg.com will have a high fraud score and probably
auto­decline if the cardholder rarely makes online purchases.
So how is this relevant? A small card­not­present charge followed by a big charge will make
the fraud score very high, because they assume you are testing the card. If they see a small
$1 charge, then a few minutes later a large purchase online, they will auto­decline the card
and your plan will likely fail.
There are much better ways to check if a card works. The best way is to call the bank's
toll­free number and use the automated prompts. This brings no danger, however use
Spooftel to spoof your number to display the cardholder's number. Once you do that, you are
ready to call the issuing bank's number and check how much is left on the card. Let's get to it.
Call the bank using your burner phone and have in hand the following information, according
to the bank. The automated prompt will give you access to the transaction list, balance, and a
few other options.
If, for any bank, you enter the card number and the system immediately transfers you to an
agent without additional questions, it means the account is closed and the card is burnt. No
need to waste time on this one, just hang up and use another card. The agent will only tell you
the same thing, and you will look dumb.
It's always a good practice to take note of the last transactions and amounts, just in case you
get asked for them later. Listen to them and write them down, I recommend up to 8
transactions for maximum safety.
So you have the balance and the available credit line now. Nice! So you know how much you
can spend online. Before you go crazy though, there is one more obstacle you need to be
aware of: many sites like Newegg or TigerDirect refuse to ship to an address that is not on file
with the bank. And chances are that your cardholder does not reside at your drop address.
Here is how we will solve this problem, introducing the Account Take­Over fraud, also known
as ATO.
ATO is the process in which a fraudster (you) calls the bank to make whatever changes he
wants to the account, without the cardholder knowing. This involves speaking with a customer
service agent and using social engineering. Before you even think about pressing 0 to speak
to an agent, make sure you have, at the very least, the following information in hand:
1. Full card number, expiration date, CCV code
2. Full billing address of the cardholder (and county)
3. Date of birth (and write down the age too, not just the DOB)
4. SSN
5. MMN (Mother Maiden Name)
6. Employer name (facultative, if possible, try to find it on Facebook)
7. Car make and model (facultative, if possible, try to do a Google StreetView on the
CH's house)
8. House size and value (facultative, if possible find it in realestate.com as this is public
information)
9. Driver's license number, expiration, state (facultative)
10.Previous addresses
11.Background report
In case you do not have the MMN, try to guess using common last names in the background
report. If you really cannot find it, sometimes it is possible to get around it with other
questions. Once you have this information in hand, study it, try to remember it. Remember,
you are the cardholder, the card is yours, and you are confident, just like when you call your
own bank for a legitimate request.
When you call the bank, you will be usually asked for 3 security tokens. Those tokens can be,
but are not limited to: DOB, SSN, Address, CCV code, cellphone, MMN. If you fail 1 token,
you will be asked 2 more. At this point, 2 things can happen:
1. You did it correctly, so the agent will listen to you and will do whatever request you
have to do
2. on the CH's account, and no flags will be raised.The agent suspects an ATO is
occuring, and transfers you do the securiy department. This is called the Verid
department, and you will be asked 2 OoW (Out of Wallet) questions. Those are
multiple­choice questions based on the cardholder's credit history and public records.
They can be easy or tricks, it's random every time it happens. If you fail those, they will
tell you that they can't help you and will suggest you show up in person at your bank.
They will also ring the cardholder. So if you fail this one, forget this card, it's burnt to a
crisp.
The first thing you want to do on the account is change the billing phone number. Only that.
Do nothing else, as making too many changes will raise a red flag on the account. Call to
change the main billing number and let the card sit still for at least 5 days.
All right, are you ready? Relax, sit in your favorite couch, call the bank, listen to the prompts,
and press 0. The message goes on, this call may be recorded for quality purposes.
This is the first example, if you have the correct MMN (this is the most frequently asked
token).
Agent: Thank you for calling Chase, my name is Bob, who am I speaking with?
You: James R Layton.
Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden
name on the account?
You: Lucile.
Agent: Thank you, and what is your date of birth?
You: October 1st, 1965.
Agent: Thank you mister Layton, what can I do for you today?
This is the second example, if you do not have the MMN. Guess it, and do not hesitate. You
know yourself better than the agent does, and they can only rely on the information they have
on their screen to validate your answers.
Agent: Thank you for calling Chase, my name is Bob, who am I speaking with?
You: James R Layton.
Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden
name on the account?
You: Smith.
Agent: I actually have something different here, it starts with C.
You: With C? It's impossible! Her name was Lucy Smith, she never used any other name!
Agent: Well, you do not have any other name that might start with C? (if you have a last name
starting with C on the background report)
You: My aunt's maiden name is Charlotte, but I doubt that's the answer you have on file. (if
you have nothing like that on the report)
You: No, no one in my family uses such a name.
Agent: Oh well, let me take note of this for you, can you confirm the last 4 digits of your social
security number?
You: 4456.
Agent: Thank you, and what is your date of birth?
You: October 1st, 1965.
Agent: And you billing address with the zip code?
You: 123 Fake Street, Fakeville, NY, 10008.
Agent: Thank you Mr. Layton, how can I help you today?
If you hear that, it means you got in. Otherwise, you will be transferred to the security
department for the multiple­choice questions, have your report in hand. If you fail, the card is
dead. Make sure you spoofed the cardholder's number, otherwise you could be asked for
other questions like driver's license number, vehicule plate number, etc. Those are questions
you probably do not have the answer to.
Now, what you want to do is change the billing phone number. A sample dialog with the agent
can go as follow.
You: I would like to change my phone number. This phone will be disconnected tomorrow and
I want to give you my new primary number so you can reach me if there is something.
Agent: Okay I see, what is the number?
You: 234­567­8901.
Agent: Thank you, is there something else I can do for you?
You: No thanks.
Agent: Thank you for calling Chase, have a wonderful night.
Once you passed the verification part, the rest is pretty straightforward and is relaxing. Now
that you changed the billing number, let the card rest for at least 5 days. Do not make any
transaction. The cardholder will continue to use his card normally too. During your call, at the
end, if you failed the MMN question, you might want to remind the agent to change the MMN
on file to avoid problems next time you call.
Also take note, at any point, if the agent wants to put you on hold, or says he needs to verify
something and will be back, wait for him to put you on hold, and hang up. It basically means
they are going to ring the cardholder. If this happens, you might want to wait at least 48 hours
before calling again, and you will see just by the automated prompts if the card is burnt or not.
Maybe they did not call the cardholder, but in 90% of the cases, they did. It happens,
especially with Citibank, who likes to replace the Verid questions by a quick ring to the
cardholder.
The questions often change when you call, but they always follow a certain pattern. By
experience, I will give you the tokens usually asked by the big 4 banks, but we aware that
they might change, or they might ask you other questions if they believe you are bogus. They
can ask for your age to throw you off, as you might not have to calculate it fast enough using
the DOB. If you fail this verification, you will be transferred to Verid department.
Since you have to wait 5 days, it's a good idea to create an account on your target website,
browse the items, put some in your cart, go to checkout, go back, remove items, read
descriptions. Just try to appear like a legitimate shopper. Remember that $1000 is a lot of
money for the average American and if you show you don't care about your money and just
throw items in your cart, you raise flags. Look like you care about how much it costs.
There is also a technique that works well with Citibank: when you are asked for the MMN by
the automated system, if you fail, you will hear “the agent might need to ask you verification
questions”, and if you succeed, you will be connected and everything will be a breeze. When
the automated system asks you for the password, say “Jope” while putting a high tone on the
O sound, then slightly lower your pitch. Say the word at normal speed, like when you are
talking to someone. This will trick the automated system into beleiving that you got it right.
You might have to retry 2­3 times for it to work, but I got it with almost all my accounts. This
will save you a lot of hassle with the agent and will make the call extremely easy.
Once you got rid of this verification process, it will be easier next time you call the bank for
this account. So let's suppose you followed me and let it sit for 5 days. Call again, and this
time, we will add a temporary shipping address to the account. A transcript can go as follow:
(pass verification questions) You: I want to make a purchase from Newegg.com but they ask
me to add a temporary shipping
address on file. I'm not sure how that works, do I just tell you where I want them to send my
order?
Agent: Let me help you with that, we can add an alternate address on the account, what
would be the address?
You: 123 Fraud Street, Cardingville, CA, 98765.
Agent: No problem mister Layton, I have notated the account for you, is there something else
I can assist you with today?
You: No thank you
Agent: Have a good afternoon.
Almost all banks allow that, except Bank of America, who can only change the mailing
address. That's why their cards are not the best when it comes to level 3 carding, but some
stores will do a conference call with the bank to bypass this restriction. Chase works the best
for temporary shipping addresses, but is hard to ATO. It all depends on your skills and what
you're comfortable with. All US banks accept a Canadian address, and some banks may
accept an international address.
Once you have added the alternate address in the account, it's time to make the hit. Take
your account on the website you want to card, shop a little bit again, then proceed to
checkout. Try not to go over $2000 per order. Enter the correct billing address, double­check
the information. Enter the billing phone number (the one you added on the file at the bank),
then your shipping address. Triple­check all the information for accuracy.
Then, send the order. You might be greeted by a VBV or MCSC form, but if you have the
required information, it should not be a problem. Enter the information they want to get, and
submit the order. Also, some websites like TigerDirect will ask you for your DOB and will give
you 3 verification questions to answer. Those are public records and can easily be found in
your background report, so don't be scared. If you fail 1 question, you will be asked an
additional question. If you fail 2 or more, the order will be put “on hold” and things will get
harder, so try not to fail.
At this point, 2 things can happen when you submit the order. It depends on the spending
habits of the cardholder, and will make things easier or harder for you.
1. The order goes through without any problem, and becomes “pending” status.
2. The transaction get declined and the website says to call the issuing bank. If this
happens, call the bank, the system will act like the card is burnt (transfer without any
additional questions), and a fraud agent will answer. Remember, the card is yours, tell
them you authorized the transaction, but you don't know why it's declined. It's usually
easy if you have the correct information, but if you ATO'd the account before, chances
are that you have everything it takes. When the agent tells you you are all set, resend
the order on the website. Call as soon as you get the decline, don't wait, otherwise the
real cardholder will get a call you don't want him to get.
All right, the order is now sent and the status is “pending”. The next section will tell you why
some orders get canceled (newbie mistakes), and why in your case everything should be all
right. Take a deep breath and hop to the next section.
WHY ORDERS GET CANCELED
When a website receives an order of about $1000, we understand that they try to protect
themselves. What is the first thing that a website will do to verify the order? That's right, they
will call the issuing bank and will check if the billing phone number you entered is correct,
otherwise they will ask for it, and will ring it. You can receive the call, or the cardholder will,
depending if you ATO'd the account correctly.
This is why orders get canceled when newbies enter a credit card order and expect to receive
a free iPhone from the Apple store. They are not fools and want to protect themselves.
However, if you took care of changing the billing number on file, you will get the call and you
will be able to confirm the order.
Not so fast, a call is not simply “is everything okay?”, but rather a verification call where they
want to see if you are really the cardholder or not. They sometimes ask you for verification
questions similar to Verid questions, but all the questions are taken from public reports. They
can also ask you if you put the shipping address on file with the bank (you hopefully did), and
they will call the bank to verify. Also, in some rare cases, they can make a conference call
with you and the bank, but you will be asked for the usual questions, which means last 4 of
SSN, DOB, last transactions, etc.
If you are a newbie and just put some credit card information on a website hoping to get a free
iPhone, you will just see the order passing to Canceled state without any details and you will
not even get a call. This is the reason why people post threads about “carding does not work”
and get the same answers.
If you passed the verification call, the representative will tell you that everything is okay and
that they will have the order shipped out today. This is good news! At this stage, I received
100% of my items, I never had problems past the verification stage. Now you may be tempted
to hit another site; resist to the temptation. You ATO'd card can almost be considered a level
4 card, at you own the account and can do whatever you want, so it has a high sentimental
value. Wait for the order to ship and the package to leave the merchant before you hit another
webstore.
I recommend carding in the morning, to avoid letting a charge sit on the card for too long. You
never know how often a cardholder checks his statement online. I had cards that died within
hours, and other ones lasted 3 months. Once the package is shipped, you can card another
store, no need to call the bank, as your drop address is already on file. Repeat until the card
is burnt. Once it is burnt, never show your face at the drop again. The alternate address is on
the bank's records and they can send Law Enforcement to this place. A drop is like a condom,
use it once, do all your business, and trash it, because it becomes dirty.
Another verification step they can take is send you an e­mail asking for scans of your ID
documents, such as passport and driver's license. These can easily be photoshopped and
there are templates available everywhere. Utility bills are pretty easy to forge too, so don't
worry about this part. Do what you have to do, but be quick.
Another step you can take, is to put the shipping name on the package to a family member of
yours, for example if the cardholder's name is James Latyon, send the package to a certain
Harry Layton (find a name that's on the report and have their DOB, in case) and say you are
sending the package to your son / brother / whatever relationship you have on your report.
Also, keep in mind that no method is perfect, and the website can cancel the order simply
because they feel it is not safe to process it. Nothing is perfect, but if you ATO'd the account
successfully, it should be easy. Remember to stay under $2000 per order. You never know
what other tricks they may use to catch you.
Always choose the fastest shipping method. Some say it raises flags, but if you did everything
else correctly, that will not be the reason why your order fails. Besides, it greatly reduces your
chances of getting an intercepted package, which is a pain in the ass and makes your efforts
worthless.
This brings me to the topic of finding a drop to ship your order to. You can ship it to your
house without any problem, if you want the police to knock at your door and make you ride
dirty to the police station, and get in a steaming pile of shit of trouble. So read on to find out
how to ship your order safely.
DROPS
A “drop” is a place, or location, where you have illegal, carded, or stolen goods shipped to. It
has to be a place that has no link with your current life and is in no way linked to you.
Finding a drop is not really hard. You can go on Craigslist and find houses for rent, or just
drive around your neighborhood looking for houses for sale where you can ship goods to.
Make sure the house has no big windows that allow the driver to see that the house is empty.
You don't want to have the package returned to the sender because of that. Just use your
brain to find a decent house that you think is worth shipping a package to. Usually pick a town
close to yours, but not in your neighborhood.
The big day has come: UPS tracking shows “Out for Delivery”. Yeah! Now check if the
package requires a signature. All carriers require it, except UPS. For UPS, you can see if
Signature Required is written on your tracking page. If nothing mentions a signature, or if you
are not sure, then signature is not required.
Method 1: Acting like you are away
If you don't need a signature, you can leave a note on the door, “we are away, please leave
package here, take this as my signature” and you might as well print the order confirmation
page showing the tracking number and put it with your note to make your case stronger. The
driver makes the final decision about leaving the package or not, but usually there is no
problem with UPS when they don't need signature. Sign the note, put the order confirmation
page with it, stick it in the door, and wait in your car not far from the place. When the driver
leaves the place, grab the package, and put it in your car. Then skip method 2, and continue
reading.
Method 2: Acting like you own the place
The second method is when a signature is required. You will have to meet face to face with
the driver. Remember one thing, you can relax. The driver's job is not to investigate fraud, but
only to make sure the package does to the right received. So you must just make him believe
the package is yours, they don't care about fraud (but don't be stupid and talk about your
crime). Carry a printout of the order confirmation page, the tracking number open on your
smartphone (use VPN!), and look like you've been waiting for him. You might wait at the drop,
sitting on the front lawn, or doing whatever you want. However keep in mind that waiting in the
car when the driver sees you get out of the car is highly suspicious. If you choose to wait at
the drop while being visible, take down any “for sale” or “for rent” signs, and call the bank's
automated system prior to showing up to ensure the card is still valid and the police is not
waiting for you. Greet the driver, show papers, sign the cardholder's name, and proceed to
the next section.
Sometimes, the driver might get cocky and ask, why your name is not the same one than
what's written on the package, or why you're not inside. You can tell that you recently moved,
and you put it under someone else's name because you have “problems with customs”. When
they get cocky, you can threat them to make a complaint at their local UPS hub, they usually
calm down and hand over the package. I had a cocky driver in my last carding trip in
Minnesota, and I had to use this method, and I finally got my package.
By experience, when you have brokerage fees to pay (like international package), you can
call UPS before getting the order and ask the amount. Leave a money order on the door and
the driver will take it and leave the package. You will avoid getting a InfoNotice that way, and
the driver will believe you own the place. I did that a lot of times and no failure so far.
Picking your package at the UPS facility
In some unfortunate circumstances, the package can end up at the local UPS facility and will
require government­issued ID to be picked up. This happens if you missed your drop, for
example. In that case, don't bother making a fake ID, as there is a better trick.
The package is usually held for 5 business days before it is sent back to the sender. The day
the package arrives at the facility is day 0. Two scenarios can happen:
Scenario 1: You get a call from the UPS branch
They will probably call you and say something along the lines of, we have a package for
James Fakename waiting at the facility for pickup. Just tell them that you don't know this
person. Here's a sample script of what it should look like:
UPS: Hello, may I talk to James Fakename please?
You: I think you may have the wrong number, who is speaking?
UPS: This is the UPS branch, we called the phone number we had on the package.
You: Oh, I was waiting for a package too, and it didn't get delivered. Is this a package from
Newegg, a smal box?
UPS: Yes, we have one small box waiting here, for James Fakename.
You: I have a tracking number, can you check if the last 4 digits are 3382?
UPS: Yes they are.
You: I'm very surprised, because my name is Fake Name and I was waiting for this one. I
have no idea who James Fakename is. They looked confused when I placed the order too.
UPS: Well, the package will be sitting here, just come pick it up when you are ready.
This worked me twice. I had 2 drops to watch at the same time and I missed one package.
This allowed me to pick it up.
Scenario 2: You do not get a call
On the morning of day 5, call the toll­free number and ask to be transferred to the local
branch. You can do the same scenario, and inquire about a package waiting there for you.
You must look confused a bit in your voice and look like someone who was victim of a
mistake from the online store, and they will gladly hand over the package to you. Everytime I
did it, I never got asked for any form id ID and it was all smooth.
Do not give your real name. Test the card before going (call the bank), and only do it if the
card is still live, otherwise it can be dangerous. You can also send a mule if you are too afraid,
but I showed my face a few times when the card was still live and never ran into issues.
After getting your package
I sometimes skip this part when I am lazy, but you should be extra careful. Your freedom has
no price tag, so take 5 more minutes to do this precaution.
Drive to a nearby park or public place, and open the cardboard packaging. Look for any
device that may be tracking your position, such as bugs, GPS devices, etc. Then destroy the
shipping label (you can burn it to make sure), throw the cardboard packaging away, and you
now have in your hands a precious item you carded using your ATOd card. Also burn the
order confirmation page if you decided to go this route and you brought it to the drop! At this
point, you can consider your carding heist a “success”! Drive home, relax, you owned the
bank and the website.
If the card is still valid and there was no tracking device, you can card to the same drop again
until the card burns. Get as much as you can out of it. Burn the card to a crisp. I remember
getting $10,000 worth of electronics on a Chase card at the same drop, split on 5 orders. This
was a money­making week.
All right, you carded the item, ATO'd the account, got items, more items, burnt that drop to a
crisp too, now the card is dead... either over the credit limit, or flagged by the cardholder.
Never show your face to that drop again, and enjoy your goods!
What happens after? Read on to find out.
CHARGEBACKS
A recurring question is, when the card is declared stolen and the transaction is disputed
because of fraud, who takes the hit?
In the case of a card­present transaction using chip & PIN in countries where they use that
technology, the bank takes the hit when the transaction is declared fraudulent.
In all other cases, it's the unfortunate merchant that takes the entire loss. So if you card
Newegg for $2000, they pay about $1600 for the merchandise that they send you, and they
are short the money because you carded them, so they have to make 6 similar big orders
without problems to cover that loss. You now undertand why they make verifications and don't
want to be carded.
Some big merchants like TigerDirect and Newegg will just eat the loss and assume that they
failed at fraud detection, but smaller merchants will make a formal complaint at their police
department. Now, is the police going to investigate? It depends.
If a merchant reports a $200 loss for an order shipped out of state using a stolen credit card,
there is a 99% chance that the police will not even open an investigation for that. However if
they report a $3000 loss using a stolen card from the same state and shipped in a nearby city,
LE (Law Enforcement) might move for that.
It also depends on the volume of complaints, the amount of loss compared to the size of the
city, and whether there is an obvious pattern between fraud complaints or not. You should try
to make your orders not linkable to each other, and use your common sense to avoid creating
a pattern that might trigger an investigation.
It also depends if the cardholder himself decides to make a complaint or not. As long as they
get refunded by their bank (which they do), chances are that they will not care and just forget
all that. But some more mad people can decide to make a police report for identity theft.
Again, there will be an investigation if there is an obvious pattern. It all depends which city you
are talking about.
So remember, when you card a website, they take the loss in case of a chargeback, so they
want to protect themselves. You have to be smart and ask yourself, if I were in the shoes of
the website owner, how would I catch fraudsters?
Sometimes, you might receive an e­mail from the store asking you to provide more
information about the chargeback, such as authorization forms or documents. Just ignore that
e­mail. Do not become cocky and answer “I got you!” because it could be the difference
between an investigation or not. Keep it dead.
WARRANTY FRAUD
A very fun type of virtual carding is warranty fraud. I got some $1000 CPUs from Intel and
motherboards from ASUS using that trick. Here's how it works.
Many companies, especially electronics, offer what is called “advance RMA”. This is a type of
warranty replacement where the company sends you the new product first, along with a return
box for you to return the defective item to them. They sometimes ask for a credit card number
in order to make sure you will return the defevtive item. This is where we can take advantage
of the system.
It works will Dell, Intel and ASUS, perhaps a lot of other ones, but they are the ones I have
experience with so far. You can PM sellers on eBay to ask for serial numbers of products, or
you can simply card a product and request a RMA using its serial number. Call the
manufacturer, say that your product is defective (use a diagnostic that makes sure it's really
this product that is faulty, such as “the video card shows nothing on the screen, I tried 2
screens, but it works with other video cards”, and ask if they offer advance RMA, they mostly
will. Use a level 2 card and have it shipped to your drop address. If they ask why, just tell
them you are on vacation there and your computer broke.
When you receive it, take the package, and disappear. You just got more free stuff using a
credit card that will eventually, maybe, get a chargeback, but you get the point.
For Intel, they ask for the 5 lines of text on the CPU itself, and a credit card for hold, so you
need to have the unit in your hands for it to work.
For ASUS, the serial number is enough, they require a credit card.
For Dell, it's the easiest, no credit card needed, just order your free item on the phone without
credit card, you just need a name and an address.
Feel free to discover weaknesses in other companies' systems, this is a relatively new kind of
fraud and has not been patched. Many people use that to get free Xbox Series from
Microsoft. Most companies require that this warranty claim is done over the phone but don't
worry, it's simple, and most of them don't seem to care about their job. I had 2 declines when
carding Intel, the third one worked like a charm, and they did not even get cocky about it.
You can keep one for yourself and sell the other one on eBay or Craigslist, it's easy money to
make. The point is that they have to try to screen fraud at the same time than offering a
seamless experience for legitimate customers. We just abuse the system.
PICKING THE BEST CARDS
If you don't have access to fulls, or you have a CCV autoshop and you want to get the best
out of it, there's a trick that can save you money, if you have a bit of time to invest. It works
with any autoshop as long as you can see the name and zip of the cardholder.
First, search by desired BIN. If you like ATOs and you want good cards, BINs 426684 and
438854 work well, but that is up to you. If you can't search by BIN, just pick Credit Cards from
any bank. Once you are in the list, find cardholders corresponding to your gender, and for
each one, do the same thing.
Search their name and zip on Backstab or SSNFinder to check if you can find them. Most of
time time (>50%), you will not, especially if the cardholder is under 45 years old. So just do
the same for the next result. When you have the SSN and DOB of the cardholder, before
buying the card, do this thing to double­check the info:
Go on peoplefinders.com and get their background report. Check if the DOBs match, and if
the address list matches too, to make sure you have their SSN and DOB 100% accurate.
When you are sure, buy the card, and buy SSN and DOB. You now have a fulls. You can go
on archives.com or ancestry.org to get their MMN. Here's how to search;
Card an account on any of those 2 sites (level 2 card is enough, it's very easy). Get the
mother's name on the background report, and search using her first and last name, and
correct date of birth. Search for “marriage” records, if you can't find any, search “birth”
records. If you don't find anything, try searching for the father's marriage records. Note that
not every state / county has their records made public, so it's possible that you won't find it at
all; it's okay, just make one up when you ATO the card.
This way, you can scrub the autoshops and select only the cards where you can have full
information. This is my trick to get only good cards. Of course, the best option is to find a fulls
vendor, but there are not a lof of them, so escalate your cards the way you desire.
Make sure your cards are well organized. I have included a sample Excel file where you can
see how my cards are organized. All cards can be sorted by name, address, number,
expiration, DOB, SSN, etc. Look at the file for more information. Also, use line colors for
different meanings. Example, white rows mean that the card is mine, and still not used. Call
the bank before adding the card to the list, because you want to trash junk cards right away.
Yellow means that the card is burnt, and blue means that the card is currently being striked,
so I know what to focus on. Green means that I fucked up the cardholder's credit history using
his DOB and SSN. When you look for fulls, look at your Excel file, and with the colors, you
can find your card quickly.
Then, just check the balance, study the background report, and you are ready to hit big shops
and get stuff at your drop!
COMMERCIAL FRAUD
Want another (and probably easier) to get items shipped to your drop and getting tired of
carding Newegg and TigerDirect? All right, I'll show you another method for that. This method
works best for Canada but is really good for USA too.
You can find any major provider that only sells to commercial customers. For computer parts,
for example, you can targer ASI, Synnex, and so on. The goal is to get the business
registration certificate of a business in the town you wish to have your drop. This certificate is
usually public data and can be found on the registration records depending which state or
province you are in. Once you got the business registration documents from a business that
operates in the same field of activity you wish to get items for, you are ready to hit the
provider.
Apply for an account at one of those providers using that document, put all the business
address info, but put a drop address close to that place, and your burner phone number. Both
providers (ASI and Synnex) usually don't call, but just in case, better stay safe. It usually
takes 24­48 hours to open an account. “Your name” is the name of the real business owner.
On the credit application, do not request net terms, just write “no credit” and let them know
you will pay before getting items shipped.
On the credit card authorization form, put the cardholder's (pizza) name, address, card
number, expiration date, CVC code. Let them know that this person is an “officer” at your
business, such as a remote sales representative. Once the application is approved, you are
good to go and hit big amounts. The reason is that they do not make verification when
sending orders, as they almost never get fraudulent orders. They assume that commercial
customers are always going to be legit, but in fact, we use someone else's business
documents to trick them into thinking you are the business owner.
I was able to pull over $5,000 per order using that technique; the merchant is considered
low­risk so there are very few declines, and verifications are almost nonexistent. With
computer parts, it's extremely easy to do that, you can try other commercial providers. Now
you are playing in the big game, and the possibilities are endless. Make sure to never show
your face at the drop once the card burns, as they will really try to find what happened.
NEWEGG AND TIGERDIRECT
Always wanted to card those 2 big merchants to get electronics? I will tell you how. This is
normal difficulty if you know what you are doing and if you are good at social engineering. You
need, at the very least:
1. Cardholder's account ATO and billing phone number changed to your burner
2. Shipping address on file with the bank
3. Full background report on the cardholder
4. Story about why you ship to that address
5. Local area of the cardholder: restaurants, shopping malls...
And remember, mail forwarding companies are blacklisted by those merchants. Don't try
shipping to MyUS, Bongo, and so on, as it will automatically cancel the order. Which
American would use a US card to ship to a forwarding company to get it out of the country?
None. Have a normal drop address.
Number 5 might seem strange, but it's true. Some people, including myself, have been asked
“can you name a local restaurant near your house” to make sure you are the cardholder. So
it's not a bad idea to get familiar with the surroundings (major malls and restaurants) in case
that happens. You'll thank yourself later.
So, take your time to browse, look around, read descriptions, and appear like a legitimate
shopper. Once you did that a few days and the account is ready, send the order, and try not
to go over $2,000. The order will be placed on “hold” status, and you will have to talk to the
verification department. I will describe the procedure for TigerDirect, but Newegg is fairly
similar.
TigerDirect's website will ask you for addresses, credit card information, then you will have to
pass VBV/MCSC. After that, they will ask you for your date of birth. Then, 3 verification
questions will pop. They are public record information about the cardholder and can be found
in your background report. Try to have so much information that you feel like the cardholder is
your friend. Answer the 3 questions and be quick. If you fail one, you will be asked an
additional question. If you fail 2 or more, forget your order. Once you send everything, your
order will be “on hold” status. You need to call the verification department. Conversation goes
as follow, usually:
Rep: Thank you for calling TigerDirect verification department, can I have your order number?
You: 123456
Rep: All right, what is your name?
You: James Layton
Rep: Thank you Mr. Latyon, let me verify the order for you.
(you will be on hold about 2 minutes)
Rep: Thank you for holding, is <name on the package> a tenant at the shipping address?
You: Yes (giving the wrong answer voids the order)
Rep: I could not locate that person in the system. So you will be offered 2 options. Either we
ship to your billing address, or you need to call your bank to add the shipping address as an
alternate address on file so we can ship there.
You: I already did.
Rep: Oh really? All right then, let me verify that for you. Please wait.
(you will be on hold while they call your bank, sometimes they can make a 3­way call)
Rep: All right, I see the shipping address is on file. Thank you, and is it okay if I call you on
that phone number, 123­456­7890? (whatever phone is the primary billing number)
You: Yes, sure.
Rep: Thank you, hold on.
(the phone will ring, pick the call, or the order will be void)
Rep: All right, we have successfully verified your identity Mr. Latyon. We will have the order
shipped out to you tonight.
See the pitfalls in the dialog above. You must assume that the shipping name is a tenant at
the address. For example, if the cardholder's name is James Latyon, you can ship to a
Joseph Layton and assume it's your son, but make sure that name is on the background
report and you have their DOB. Sometimes they may ask for it if they get suspicious.
It is also a good practice to avoid Hotmail addresses; anyone can make a fake Hotmail under
someone
else's name. You should use a custom e­mail with a custom domain.Next, you must make
sure you can pick the phone when they call the “billing” number. If you do all that correctly,
you are good to go and you will get your parts. They do not ask for scans of documents,
everything is done over the phone.
THE PTO
When you commit Account Take­Over fraud, also known as ATO, you take “ownership” of the
victim's account. Even if you change the phone number on file, they still keep record of the
previous phone number. This is where this section will prove useful. I will give you the
transcript of a failed ATO I had 2 months ago, and you will understand.
(pass verification questions) Me: I am calling because I tried to place an order online, but it
got declined. The charge is $1500 and the merchant is Newegg.
Agent: No problem Mr. Johnson, let me see what I can do for you, can you please hold?
(by experience, if they put you on hold, hang up, it's most likely burnt, here it took 5 minutes)
Agent: Hello?
Me: Yes madam, I'm still holding.
Agent: Unfortunately I will not be able to let the charge go though, and I can no longer provide
service on this account.
Me: How about my card? What should I do?
Agent: You can destroy the card, as you are not the real Robert Johnson.
This is a situation that sucks, and there's a way to avoid that. It has to be done before calling
the bank. What happened here is that the agent called the previous number, even if I changed
it a few days ago. The real cardholder got the call, and you can imagine the rest.
First of all, take the real phone number of the cardholder, and use WhitePages to find who is
the phone provider. If you cannot find it, then you might want to use Spooftel and call the
various providers (AT&T, Verizon, Sprint, etc.) and use their automated system to try to find
out if the number is registered with them. You can use phonevalidator.com to see if the phone
is a cellphone or a landline. When you have the background report of the victim, you can see
that they often have many phone numbers. Use the service to find which one is landline and
which one is cellphone. For cellphones, it's very easy to find the provider, as most of them
allow you to call the phone and press * (star) to go in the voicemail settings, so you recognize
the greeting. Use your logic, and write the phone numbers, probably like that:
Phone 1, landline, 555­123­4567, Verizon Phone 2, cellphone, 666­234­5678, AT&T
Now, remember, you have the full address, DOB, SSN, and more information on the
cardholder, and you know what is his phone company. What are we gonna do? That's right,
Call Forwarding!
Call up the phone company using the opposite phone (if billing number is the landline, call
with the cellphone, and vice versa), spoof the number. When you talk with the customer
service department, it might go as follow. Don't forget that it's less secure than banks, as it's
not about finances. But it can have worse consequences.
Agent: Thank you for calling Verizon, my name is Mohammed, how can I help you?
Me: Hi! I will be away from my house in the next days but I'm waiting for an important call on
my landline. Since I cannot reach the other party, I would like to set call forwarding so I will
receive the call on my cellphone.
Agent: No problem, can I have your name?
Me: Barack Obama.
Agent: Thank you Mr. Obama, what is your full address?
Me: 123 fake Street, Washington DC, 12345.
Agent: Thank you, and may I have your date of birth?
Me: October 11 st , 845.
Agent: Thank you. Did you know that you can press *72 on your phone to activate call
forwarding? This is an easy way to do it without calling customer service.
Me: Thanks for the tip, however I'm not home at the moment, so I am unable to do that.
Agent: Okay no problem, I will activate it for you. What is the phone number you would like
the calls forwarded to?
Me: That's my cellphone, 456­123­3245. (your burner phone)
Agent: All right, and you want it to start now?
Me: Yes, please.
Agent: No problem, I activated it for you. When you will be home, you can use *72 again to
deactivate the forwarding.
Me: Thanks.
Agent: Is there anything else I can help you with?
Me: Nope, thanks.
Some phone companies, AT&T by experience, ask for a 4­digit PIN, but it can be easily
bypassed using DOB and last 4 of SSN. The good point is that, if you are extremely unlucky
and fail (which should not happen because it's easier than banks), the card will not burn. This
is the PTO, Phone Take­Over fraud.
Now you are ready to call the bank to ATO. If they decide to call the billing number (happens
very rarely), you will answer the phone, and it will destroy all suspicions they have. The
cardholder will probably be locked out of his account, but that's not your problem. The first
dialog (failed ATO) can be avoided if you do that before.
When your business is finished, do not forget to call Verizon (or his company) to deactivate
call forwarding. The goal is to get free stuff, not make the cardholder lose friends because
they can't reach him, use a bit of compassion. If you think you will need his phone line for a
few days, you can use RingCentral phone system and decide which numbers you want to
take the calls from, and which ones you just want blindly transferred to the cardholder. He will
probably never notice that someone fucked with his phone line, but will notice the charged on
his card!
Some websites do not require the shipping address to be on file with the company; in those
cases, you can do a PTO without doing an ATO, and put the correct billing number on the
website. Take the call from them and confirm the order, and restore his phone line. Use your
imagination for the rest.
MAXIMUM FRAUD PREVENTION
The most popular software used by merchants for fraud prevention is the Minfraud software,
designed by Maxmind. It is used to keep fraudsters as bay, but their formula is not so secret. I
will give you the formula, and explain the variables. There is a way to keep this score low.
Many stores have their own preset limits, which are not made public because each store is
different. For example, a store can say that over 7 they send the order to manual review, and
over 9 they cancel it. The definition of the variables goes as follow:
1. IsFreeEmail Is the e­mail address from a free provider like Hotmail or Yahoo?
2. CountryDoesntMatch Are the shipping and billing countries different?
3. IsAnonymousProxy Is the user using an anonymous proxy like a VPN or blacklisted
Socks?
4. HighRiskCountry Is the order involving Ghana, Nigeria, or Vietnam? List updated
often.
5. BsDistance Distance between billing and shipping addresses, in kilometers.
6. MaxEarthArc The half­circumference of Earth, currently set at 20,037 kilometers.
7. BinDoesntMatch Is the BIN from a different country than the IP address used to order?
8. BinNameDoesntMatch If user is asked for bank name, did he answer correctly?
9. CarderEmail Was the e­mail used for fraud on other sites using Maxmind?
10. HighRiskUsername Was the username used for fraud on other sites using Maxmind?
11. HighRiskPassword Is the password the same than the ones used for fraudulent
orders?
12. ShipForward Is the shipping address a mail forwarding company?
13. ProxyScore Is the IP address a proxy or socks?
The algorithm used for fraud score calculation goes as follow:
2.5 * IsFreeEmail
1. 2.5 * CountryDoesntMatch
2. 5.0 * IsAnonymousProxy
3. 5.0 * HighRiskCountry
4. 10.0 * min(BsDistance, 5000) / MaxEarthArc
5. 2.0 * BinDoesntMatch
6. 1.0 * BinNameDoesntMatch
7. 5.0 * CarderEmail
8. 5.0 * HighRiskUsername
9. 5.0 * HighRiskPassword
10. 5.0 * ShipForward
11. 2.5 * ProxyScore = Maxmind score for this order
Now that you have this formula, let's see how we can reduce the score to almost 0. Although
many stores use proprietary software, this one is widely used and is the most popular. Since
there is no way of knowing which software the shop uses, just pay attention to all the
variables and try to look legit. Here is a more in­depth explanation of each variable and how to
pay attention to it.
1. IsFreeEmail
This variable is set to 1 if you use a free e­mail like Hotmail and Yahoo, so don't use it. I'll give
you a trick. Remember the Stripe cashout part? Create an e­mail address from the same
domain, like shopper.name@myfakeshop.com and use it. Since it's a paid e­mail, this flag will
not be raised. I always did that for my orders.
2. CountryDoesntMatch
This variable is set to 1 if you ship to a different country than the billing address. This can be
solved by using a card from the same country than the shipping address. This is easier if you
ship to USA. Note that this is not a big deal since you can make an excuse, but let's not raise
flags for nothing.
3. IsAnonymousProxy
This variable is set to 1 if you use a VPN or public anonymous proxy. This is also true for
blacklisted socks. You can use a RDP instead, or if you can't get one, try to find a clean
socks, but it's mostly trial and error.
4. HighRiskCountry
This variable is set to 1 if you have either the billing or shipping address in a country that is
considered high risk. Since this list is always updated, I can't provide the list, but no western
country is in that list, so if you are in UK or in USA, no danger.
5. BsDistance and 6. MaxEarthArc
This is the distance, in kilometers, between the billing and shipping addresses, up to a
maximum of score 10. You can solve this problem by getting cards in the same state than you
are shipping to. Using a California card to ship to New Hampshire will raise this score.
7. BinDoesntMatch
This variable is set to 1 if the BIN is from a different country than the billing address. This is
the problem with non­AVS cards, and why I don't recommend them. Stick to AVS, and get a
BIN from the same country. Use common sense.
8. BinNameDoesntMatch
This variable is set to 1 if the user answers the question “issuing bank name” incorrectly. So
for this one, do a BIN check, and write the correct name, exactly as it appears in your BIN
info, and you will be fine.
9. CarderEmail
This variable is set to 1 if the e­mail address was previously used for carding. All websites
send regular usage data to Maxmind and they have a list of the carder e­mail addresses. One
mistake carders make is reusing e­mail addresses, thinking that shops don't know that the
previous shop was carded. Maxmind holds a list of carder e­mail addresses submitted by
shops. Use each e­mail address only once, and use a different e­mail next time you card.
10. HighRiskUsername
This variable is set to 1 if the username was previously used for carding. Read the above
statement and do the same thing than e­mail addresses.
11. HighRiskPassword
This variable is set to 1 if the password was previously used for carding. Pay attention to not
re­use passwords across sites.
12. ShipForward
This variable is set to 1 if the shipping address is a mail forwarding company. They include
MyUS, Bongo, and many others. Some sites will outright ban those addresses and cancel
every order made to them. Avoid shipping there, there are many other options to get drops.
13. ProxyScore
This variable is set to 1 if the originating IP addresses is a proxy, or a socks. If the proxy's
goal is to be anonymous, then the variable IsAnonymousProxy will be set to 1 also.
Having all this information in hand will allows you to nuke fraud prevention systems and get
your stuff even more easily. The high­risk country list is always updated but you can always
google for it if you want to have an up­to­date list.
Always use a VPN with your socks proxy. The TrueIP technology used by many fraud
prevention software can sometimes bypass your proxy and get your real IP, so pay attention.
AVS
AVS is Address Verification System, a fraud prevention system used by shops to make sure
the billing address is correct.
It works by computing the numeric part of the address (street address and zip code) against
what's on file with the bank to make sure it is accurate. It compares only the numeric portion
only; so 123 Right Street is the same than 123 Wrong Way. The zip code is compared in full.
Why is AVS important? Because it causes automatic declines on many site if the AVS does
not fully match. If the cardholder can't write his own address, the website will not believe for a
second that you are the genuine cardholder. Many sellers sell non­avs cards. Is this good?
We'll see.
Let's say you have a non­avs Amex card from Colombia (those are very popular). People tend
to use those on USA online stores and put the billing address and shipping address to be the
same, hoping the card will pass AVS. It will. But...
A clever fraud screening agent will see that the BIN is from Colombia. What is the chance that
someone with a Colombia card has a USA billing address on file, especially knowing the card
is non avs? That's right, very slim. Expect the order to be cancelled right away unless the
fraud agent is very stupid (they are getting more and more clever those days).
Non­avs card are to be taken with caution. Do not assume you are able to card any shop with
these just because they do not use address verification systems.
SPOOF YOUR E-MAIL
Sometimes you might need to impersonate someone and spoof an e­mail for various reasons.
There's a clean and undetectable way to do that, and that's what I'm going to explain here.
The e­mail will look 100% legit.
To spoof e­mails, you will require to make the e­mail yourself. This means creating the
headers and everything. To make a test, just send a "Hello World" to a test Hotmail address,
click on "View Message Source", and you will see the top headers. Paste everything (the
source) in a Notepad++ document. You will see a header that looks like:
From: Real Name <realname@tcf.onion>
Modify it to the one you want to show, it's pretty self­explanatory. For example, change it to
that:
From: TCF Hack <tcf@tcf.onion>
Then you have the full e­mail in a Notepad++ document. Next, get a Telnet client. I
recommend Putty, it can be downloaded for free. Next, make sure you use an anonymous
connection (I advise against VPN as it is obvious it's coming from a public proxy; use
something like a hacked wifi, 3G dongle, etc.) and your security is correct.
Find the mail exchange server for your domain. For that, go on
http://www.dnsqueries.com/en/mx lookup.php and enter your domain, example "hotmail.com"
and you will get the mail exchange addresses. If there are many, just pick one random. In
your case it will be "mx3.hotmail.com".
We have everything we need! Open a Putty Telnet connection to your mail exchange server,
port 25. The "conversation" will go as follow (it can vary a bit, depending on the messaging
software):
Send: EHLO mx.spoofedserver.com
Response: Welcome mx.fakeserver.com
Send: MAIL FROM: spoofedemail@dsfdsagsdg.com
Response: 250 2.1.0 Ok
Send: RCPT TO: destination@fdsgsfdg.com
Response: 250 2.1.5 Ok
Send: DATA
Response: 354 end data with <CR><LF>.<CR><LF>
(paste all your data here, the one you edited with Notepad, then press Enter, put a dot (.) and press
Enter again)
Response: 250 2.0.0 Ok: queued as 43958340634
Your fake e­mail is sent. Note that for some providers like Hotmail, if you attempt that (from
Hotmail to Hotmail), they will put it in Junk Mail because the originating IP is not one of
Hotmail's servers and they recognize it as spoofed. However if you send an e­mail to Hotmail
from another server (example @tcf.onion), it will work like a charm. For smaller messaging
servers, everything will go smooth. Now more people will fall for your scams.
COMPLETELY SPOOF YOURSELF
This is about people who are serious into hiding your identity. Newbies would assume that by
changing your VPN location, you are someone new. More advanced users will say that by
changing your VPN, your Socks, and by using a completely new browser with user agent,
changing fonts, resolution and systme time, you are better. In fact, both are wrong. Payment
processors and Paypal have extremely advanced ways to fingerprint people and we will learn
here how to bypass that.
What software or websites (through complex Javascript calls) can use to fingerprint you can
include motherboard serial numbers, system UUID (unique identifier), and so on. That's a lot
of stuff to spoof! To spare you the research of spoofing everything, I have prepared a small
program, DMI Spoof, included in this package. This program was written by myself and is
used to modify a VirtualBox virtual machine to make it appear completely new!
Run DMI Spoof and you will be asked for 2 parameters. 1) VboxManage.exe path. This is the full
path of the VboxManage.exe file, usually located in the same installation directory than
VirtualBox. 2) Name of your VM. When you open VirtualBox, this is the name that appears in
bold black characters in the list. You know what this is.
Note that you can also supply those parameters at the command line to run it faster, the first
parameter will be the VboxManage.exe path, and the second paramater will be the VM name.
It provides a faster way to spoof everything.
Once you supplied those 2 parameters, DMI Spoof will alter the VM to change the BIOS
brand, motherboard information and serial numbers, CPUID information and a few other
parameters. You will appear as having a completely new computer made of completely
different hardware, with no way of knowing that this has been spoofed.
Once you boot into your VM, change the following settings in Windows, as they can also be
used to fingerprint you, and cannot be altered using DMI Spoof:
1. Screen resolution (you can usually drag a corner of your VM)
2. Install or delete a font in the Fonts folder (font list can be found using JS)
3. Change the computer name (requires reobot)
4. Use Tmac to spoof the network MAC address (can be found using advanced
Javascript)
5. Change user­agent (use the User Agent Switcher extension for Firefox)
6. Change VPN location or Socks proxy (this is obvious)
Once you changed everything, do not re­access your sites from the same IP than before, or
you will have to restart the whole process!
This is enough to protect you from all fingerprinting processes; for payment processors and
high security sites, this is a must. There is no such thing as “too much security”.
Note that all this stuff is equivalent to getting a new computer. You will appear as completely
new and there is no way to trace this back to the original machine. Spoofing DMI is something
easier done on a virtual machine, and if you read this chapter correctly, you know that you
must always place your carding software in a virtual machine for maximum security.
SAFEGUARDING YOUR VPN
When it comes to using a VPN, many people have a sharky connection and their VPN
connection disconnects sometimes. What happens if you are using an auto­cashout script or
you are logged in using your fake username on an online shop? That's right. The connection
will be established and will reveal your real IP. For Windows 7+ users, there is a
Windows­native protection you can use to avoid such a thing.
When you connect your VPN the first time, Windows will ask you if this connection is Home,
Office or Public network. You must select Public. Then go in the Windows advanced firewall
settings and follow these steps to protect yourself:
1) Go in the “outbound traffic rules” section of the advanced configuration window.
2) Right­click on “outbound traffic rules” and select “add rule”.
3) You will be asked which type of rule you want to create. Select “program”.
4) Click on “browse” and select the .exe file of the application you want, for example
Firefox.
5) Select “block connection”.
6) When asked when will the rule be applied, check “home” and “office”, uncheck “public”.
7) Give a meaningful name to this rule, for example “VPN Firefox”.
8) Create the same rule for every program you want to safeguard.
This way, all connections not on the Public domain (not made through VPN) will be blocked
for the selected programs, while still allowing the system requests to take the standard way. If
your VPN is disconnected, you will not be able to use those programs. You should do this for:
1. Firefox
2. Google Chrome
3. Tor Browser
4. Tor Process
5. SOCKS Proxy
6. Proxifier
7. Pidgin
8. Thunderbird
9. Any other program you might judge useful.
Note that you can't just block every single packet not sent through the VPN. Many programs
including the operating system itself must communicate on the local network without
restrictions, and using the rule “block all programs” instead of selecting a program can make
the system instable and have unpredictable consequences. Also, you need to use traffic on
the “Home” domain to be able to connect to your VPN.
This ensures that your IP will never be revealed in case of a disconnection. In that case, just
reconnect your VPN and everything will continue as normal. You will not have to constantly
watch your connection status.
In case you do not know the path of the file you should choose, you can open the task
manager using Ctrl + Alt + Delete (or right­click on the taskbar and select “open task
manager”), right­click on the process and select “open file location”. This will give you the full
path of the file, so you can add it to the firewall rules.
For older Windows, you can use Comodo firewall to achieve the same thing, however this is
beyond the scope of this tutorial and has proven to cause system instability. The Windows 7+
native method has proven to be the most stable and most secure as of now, so enjoy your
protected system!
MOST COMMON MISTAKES
This section talks about the most common mistakes newbies make when they start carding.
Some can be fatal, other one are just not important, but it's important to understand those
points.
#1 Bragging about your stuff
When you get free stuff, do not brag to your friends, your family, or girls. You never know
when someone will be pissed at you and decide to report you. Keep it for yourself, and be
quiet about it! Just say you have a way to get cheap stuff, and it's private. That's all.
#2 Linking to your personal life
Do not ask a friend to use his house as a drop. Do not ship to your workplace, your dad's
house, or worse, your own house! If the police shows up at your friend's house, he will rat you
out for sure. Don't trust people that much.
#3 Starting too big
When you first start carding, do not attack merchants like Newegg or TigerDirect. They are
not easy and they will give you a negative feeling about carding before you even get free stuff.
Start small, for example, clothes.
#4 Using the same nickname on hacking boards and on clearnet sites
Many newbies forget that, and yes, there are probably LE officers on DW, watching what's
going on. If they can Google your username and see your Facebook or anything else, you're
fucked. Use a name that you use nowhere else!
#5 Responding to allegations of fraud
Sometimes, you can get caught off­balance, and for example, a shop will respond by “the
order was fraudulent, so we canceled it”. If you carded them successfully 3 times before, don't
talk about it. If you just want to show them that you owned them, it can persuade LE to track
you, because you just linked the fraudulent orders together. Just don't reply anything.
#6 Not washing your bitcoins
If you buy (or card) bitcoins with Virwox, they can use the blockchain to trace where those
bitcoins went, and eventualy link to you. Use a service like BTC Fog to wash them and get
brand new bitcoins, not linkable to you, for your underground operations.
#7 Talking to your partners on a traceable site
Do not use Facebook to talk to your partner about carding. Any LE officers can subpoena
Facebook to get your conversation history and catch you. Use Pidgin/Gajim + OTR/OMEMO
to encrypt your conversation, and use VPN to connect. Make sure you're not traceable.
#8 Getting caught off­balance during an ATO
When you are ATOing an account, stay calm, do not get thrown off by questions. If you
answer incorrectly (because very often, they have inaccurate information), stay calm and
explain yourself, remember, the card is yours. Do not show fear, because they will catch you.
#9 Hitting the same drop
This is pretty self­explanatory; finding drops is a pain, but make the extra effort and get a
virgin drop. There is already heat on the first place, so do not put more and risk getting
caught. A drop is good for 3 days; after that, time to move on. You can apply this principle
with girls too.
#10 Accessing your fake e­shop without VPN
When your Stripe account gets burnt and they subpoena your fake e­shop to give them the
access log, you don't want them to see your real IP and trace back to you. Always use VPN to
upload files, test your shop, and so on.
I hope this guide was useful to you. I tried to put as much as my knowledge as possible to
help fellow carders in the underground world. Use any part you might find useful to you and
try to hit for big. Again, thanks to everyone who bought the guide, and if you have any
question, post in the marketplace so you can be provided better help.
REMEMBER: Be safe!
­Sacky