1059 lines
71 KiB
Markdown
1059 lines
71 KiB
Markdown
# CCNewbs
|
||
|
||
|
||
---
|
||
|
||
Complete Guide to Carding for Newbs. Learn to
|
||
Card.
|
||
By Sacky
|
||
VIRTUAL CARDING
|
||
This chapter is about virtual carding. Virtual carding is the art of ordering goods online using
|
||
stolen credit cards, also known as “CVV”, “pizza”, "FULLZ", any any other names the
|
||
members of the community use
|
||
to disguise their intentions. Although this seems easy, there are many pitfalls you might want
|
||
to be aware of when doing that, especially since merchants are getting more and more aware
|
||
of online fraud. Want to know how to get free goods? Let's get started!
|
||
HOW IT WORKS
|
||
The first thing is to ask yourself, how much do you want to card, and what do you want to
|
||
card? Then, you will have to pick one of those 3 levels. Each level represents a difficulty level
|
||
and you will see the prerequisites.
|
||
Level 1: Easy carding
|
||
This level is used for very easy things to card, for example restaurants and small phone
|
||
orders, mostly under $50. This is the entry point of most carders. For that, you will need:
|
||
1. Credit card number.
|
||
2. Expiration date.
|
||
Level 2: Intermediate carding
|
||
This level is used for online transactions that are slighly higher, like background reports, or a
|
||
very
|
||
small physical item. You will need:
|
||
1. Credit card number
|
||
2. Expiration date
|
||
3. CCV code
|
||
4. Cardholder name
|
||
5. Full billing address
|
||
6. Sometimes, phone number of the account
|
||
|
||
Level 3: Hard carding
|
||
This is not recommenced for beginning carders. Here we are talking about everything above
|
||
level 2, such as large physical items, or highsecurity websites like Newegg, TigerDirect, and
|
||
sites that require Account TakeOver (for ATO, see section 1.2 of this guide). Computer parts,
|
||
electonics, and many other items fall in this level. You need:
|
||
1. Credit card number
|
||
2. Expiration date
|
||
3. CCV code
|
||
4. Cardholder name
|
||
5. Full billing address
|
||
6. Phone numbers
|
||
7. SSN
|
||
8. DOB
|
||
9. Recommended, background report (optional)
|
||
If you are aiming for level 1 carding, you just need to call for pizza and order pizza to another
|
||
address, no need to write lengthy paragraphs on this one. This is easy and is pretty
|
||
straightfordward.
|
||
If you are aiming for level 2, you can card background reports or small physical items, mostly
|
||
under $150. All orders are done online, and you will have to enter the correct billing address,
|
||
shipping address, and card information.
|
||
Now, you must see if the websites says billing phone number on file with the bank, or simply
|
||
contact phone number. If the website asks for billing phone number, you have to put the
|
||
phone number on file with the bank for the cardholder, otherwise it is safe to put your burner
|
||
phone number. Now, is the website going to call you? It depends on the order, their policy and
|
||
their
|
||
suspicion about you, so there's no safe answer to this question. Remember that carding is
|
||
often trial and error.
|
||
When you use a card to hit a website, do not hit another website using the same card until
|
||
your order has shipped. Making an order go though and having a charge approval is easy, but
|
||
getting it shipped is often where the challenge lies.
|
||
A level 2 site that is often carded is peoplefinders.com. This is where carders get most of their
|
||
background reports. It is a good playground to test your skills, and will prove useful later.
|
||
Now, on to level 3. You probably saw the information required, now how to get it? First, if your
|
||
subject is aged under 40, chances are that you are out of luck. Otherwise, read on.
|
||
|
||
First, you need to get the right type of card. This is called finding the right BIN (Bank
|
||
Identification Number). The BIN is the first 6 digits on the card and is used to identify the card
|
||
type as well as the issuing bank. To learn more, go to bindb.com, at the top go on Bin Search,
|
||
and enter the first 6 digits of the card. They will tell you the issuing bank, and card type. You
|
||
have debit and credit cards, and the card type can vary. From the weakest to the strongest,
|
||
they are:
|
||
● Secured: Very low limits, sometimes around $300
|
||
● Classic: Low limits, sometimes around $1000
|
||
● Gold: Average limits, can be around $3000
|
||
● Platinum: High limits, can be around $8000
|
||
● Business: Very high limits, in the 5 digits, often around $15,000
|
||
● Signature: The best ones, I got cards that had $30,000 of credit limit
|
||
Note that those numbers are subject to change according to the cardholder's credit score,
|
||
history, and spending patterns. For the benefit of this guide, we will only work with credit
|
||
cards. By experience, debit cards often do not have funds, and have tighter security for online
|
||
purchases. In other words, they are rubbish for level 3 carding, but may have other uses, like
|
||
level 1 or level 2 purchases.
|
||
Register an account on any SSN finder site such as ssnfinder.ru or ssndob.cc and look for
|
||
your subject. At the same time, go on peoplefinders.com and get the full background report of
|
||
your subject using a level 2 card. Once you have the background report, look if the addresses
|
||
and date of birth match on the report and on backstab. If everything matches, you can
|
||
assume the SSN will be correct. Use your common sense to compare the backstab and
|
||
peoplefinders results to make sure you didn't get the wrong information. About 80% of the
|
||
subjects over 40 years old can be found.
|
||
You have the SSN and DOB? Great! Now, time to get the mother maiden name. This is
|
||
slightly harder and will work if your victim is in one of those states: Arizona, California,
|
||
Delaware, Idaho, Indiana, Kentucky, Maine, Maryland, Massachussetts, Minnesota, Nevada,
|
||
New Hampshire, New Jersey, Ohio, Rhode Island, South Dakota, Texas. Go on archives.com
|
||
and card an account, then look for your subject's mother (look at the background report for
|
||
her name and date of birth), and try to look for her birth record. This is a trial and error case
|
||
and works about 50% of the time.
|
||
|
||
Why get all this information? Because many level 3 sites will have either VBV (Verified by
|
||
Visa) or MCSC (MasterCard Secure Code) protection during checkout. This is a form that is
|
||
presented by the issuing bank of the credit card and asks for additional questions.
|
||
Although every type of card is different, the commonly asked questions are:
|
||
1. Date of Birth
|
||
2. Last 4 digits of SSN
|
||
3. Full name on card
|
||
4. Billing zip code
|
||
If you fail any of those questions, the order will not go through. Now, why did we need all this
|
||
information? Because we will perform a ATO on the account. This is tricky. Read the next
|
||
section for a detailed description of Account TakeOver fraud.
|
||
ACCOUNT TAKE-OVER FRAUD (ATO)
|
||
Do you dream of carding thousands of dollars worth of computer hardware on Newegg? It's
|
||
doable, but not easy. You have to follow the right steps. I carded a $10,000 gaming rig in
|
||
under 2 weeks using platinum cards by following that guide, so I'm in position to tell you how.
|
||
First thing, check the balance of your credit card. Now, before going crazy, remember this rule
|
||
of thumb: Do not use card checkers! They burn the card very quick. Let me explain.
|
||
Every transaction automatically gets a fraud score between 0 and 999. The system used to
|
||
evaluate transactions is the same used by the big 4 banks and is called Fair Issac.
|
||
Transactions having a fraud score over 300 will hit manual review by an agent, who will
|
||
decide if they contact the cardholder or just let it though. Scores over 500 with autodecline,
|
||
block the card, and an agent will contact the cardholder. Some banks have different criterias,
|
||
but things that can affect the fraud score are:
|
||
1. Comparison with the usual spending pattern of the cardholder
|
||
2. Location of the charge
|
||
3. Amount
|
||
4. Risk factor of the associated merchant
|
||
|
||
For example, a $20 charge in the cardholder's local Walmart will not trigger anything, but a
|
||
large purchase of $2000 on Newegg.com will have a high fraud score and probably
|
||
autodecline if the cardholder rarely makes online purchases.
|
||
So how is this relevant? A small cardnotpresent charge followed by a big charge will make
|
||
the fraud score very high, because they assume you are testing the card. If they see a small
|
||
$1 charge, then a few minutes later a large purchase online, they will autodecline the card
|
||
and your plan will likely fail.
|
||
There are much better ways to check if a card works. The best way is to call the bank's
|
||
tollfree number and use the automated prompts. This brings no danger, however use
|
||
Spooftel to spoof your number to display the cardholder's number. Once you do that, you are
|
||
ready to call the issuing bank's number and check how much is left on the card. Let's get to it.
|
||
Call the bank using your burner phone and have in hand the following information, according
|
||
to the bank. The automated prompt will give you access to the transaction list, balance, and a
|
||
few other options.
|
||
If, for any bank, you enter the card number and the system immediately transfers you to an
|
||
agent without additional questions, it means the account is closed and the card is burnt. No
|
||
need to waste time on this one, just hang up and use another card. The agent will only tell you
|
||
the same thing, and you will look dumb.
|
||
It's always a good practice to take note of the last transactions and amounts, just in case you
|
||
get asked for them later. Listen to them and write them down, I recommend up to 8
|
||
transactions for maximum safety.
|
||
So you have the balance and the available credit line now. Nice! So you know how much you
|
||
can spend online. Before you go crazy though, there is one more obstacle you need to be
|
||
aware of: many sites like Newegg or TigerDirect refuse to ship to an address that is not on file
|
||
with the bank. And chances are that your cardholder does not reside at your drop address.
|
||
Here is how we will solve this problem, introducing the Account TakeOver fraud, also known
|
||
as ATO.
|
||
ATO is the process in which a fraudster (you) calls the bank to make whatever changes he
|
||
wants to the account, without the cardholder knowing. This involves speaking with a customer
|
||
service agent and using social engineering. Before you even think about pressing 0 to speak
|
||
to an agent, make sure you have, at the very least, the following information in hand:
|
||
1. Full card number, expiration date, CCV code
|
||
2. Full billing address of the cardholder (and county)
|
||
|
||
3. Date of birth (and write down the age too, not just the DOB)
|
||
4. SSN
|
||
5. MMN (Mother Maiden Name)
|
||
6. Employer name (facultative, if possible, try to find it on Facebook)
|
||
7. Car make and model (facultative, if possible, try to do a Google StreetView on the
|
||
CH's house)
|
||
8. House size and value (facultative, if possible find it in realestate.com as this is public
|
||
information)
|
||
9. Driver's license number, expiration, state (facultative)
|
||
10.Previous addresses
|
||
11.Background report
|
||
In case you do not have the MMN, try to guess using common last names in the background
|
||
report. If you really cannot find it, sometimes it is possible to get around it with other
|
||
questions. Once you have this information in hand, study it, try to remember it. Remember,
|
||
you are the cardholder, the card is yours, and you are confident, just like when you call your
|
||
own bank for a legitimate request.
|
||
When you call the bank, you will be usually asked for 3 security tokens. Those tokens can be,
|
||
but are not limited to: DOB, SSN, Address, CCV code, cellphone, MMN. If you fail 1 token,
|
||
you will be asked 2 more. At this point, 2 things can happen:
|
||
1. You did it correctly, so the agent will listen to you and will do whatever request you
|
||
have to do
|
||
2. on the CH's account, and no flags will be raised.The agent suspects an ATO is
|
||
occuring, and transfers you do the securiy department. This is called the Verid
|
||
department, and you will be asked 2 OoW (Out of Wallet) questions. Those are
|
||
multiplechoice questions based on the cardholder's credit history and public records.
|
||
They can be easy or tricks, it's random every time it happens. If you fail those, they will
|
||
tell you that they can't help you and will suggest you show up in person at your bank.
|
||
They will also ring the cardholder. So if you fail this one, forget this card, it's burnt to a
|
||
crisp.
|
||
The first thing you want to do on the account is change the billing phone number. Only that.
|
||
Do nothing else, as making too many changes will raise a red flag on the account. Call to
|
||
change the main billing number and let the card sit still for at least 5 days.
|
||
All right, are you ready? Relax, sit in your favorite couch, call the bank, listen to the prompts,
|
||
and press 0. The message goes on, this call may be recorded for quality purposes.
|
||
|
||
This is the first example, if you have the correct MMN (this is the most frequently asked
|
||
token).
|
||
Agent: Thank you for calling Chase, my name is Bob, who am I speaking with?
|
||
You: James R Layton.
|
||
Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden
|
||
name on the account?
|
||
You: Lucile.
|
||
Agent: Thank you, and what is your date of birth?
|
||
You: October 1st, 1965.
|
||
Agent: Thank you mister Layton, what can I do for you today?
|
||
This is the second example, if you do not have the MMN. Guess it, and do not hesitate. You
|
||
know yourself better than the agent does, and they can only rely on the information they have
|
||
on their screen to validate your answers.
|
||
Agent: Thank you for calling Chase, my name is Bob, who am I speaking with?
|
||
You: James R Layton.
|
||
Agent: Thank you mister Latyon, and for security purposes, may I have the mother's maiden
|
||
name on the account?
|
||
You: Smith.
|
||
Agent: I actually have something different here, it starts with C.
|
||
You: With C? It's impossible! Her name was Lucy Smith, she never used any other name!
|
||
Agent: Well, you do not have any other name that might start with C? (if you have a last name
|
||
starting with C on the background report)
|
||
You: My aunt's maiden name is Charlotte, but I doubt that's the answer you have on file. (if
|
||
you have nothing like that on the report)
|
||
You: No, no one in my family uses such a name.
|
||
Agent: Oh well, let me take note of this for you, can you confirm the last 4 digits of your social
|
||
security number?
|
||
You: 4456.
|
||
Agent: Thank you, and what is your date of birth?
|
||
|
||
You: October 1st, 1965.
|
||
Agent: And you billing address with the zip code?
|
||
You: 123 Fake Street, Fakeville, NY, 10008.
|
||
Agent: Thank you Mr. Layton, how can I help you today?
|
||
If you hear that, it means you got in. Otherwise, you will be transferred to the security
|
||
department for the multiplechoice questions, have your report in hand. If you fail, the card is
|
||
dead. Make sure you spoofed the cardholder's number, otherwise you could be asked for
|
||
other questions like driver's license number, vehicule plate number, etc. Those are questions
|
||
you probably do not have the answer to.
|
||
Now, what you want to do is change the billing phone number. A sample dialog with the agent
|
||
can go as follow.
|
||
You: I would like to change my phone number. This phone will be disconnected tomorrow and
|
||
I want to give you my new primary number so you can reach me if there is something.
|
||
Agent: Okay I see, what is the number?
|
||
You: 2345678901.
|
||
Agent: Thank you, is there something else I can do for you?
|
||
You: No thanks.
|
||
Agent: Thank you for calling Chase, have a wonderful night.
|
||
Once you passed the verification part, the rest is pretty straightforward and is relaxing. Now
|
||
that you changed the billing number, let the card rest for at least 5 days. Do not make any
|
||
transaction. The cardholder will continue to use his card normally too. During your call, at the
|
||
end, if you failed the MMN question, you might want to remind the agent to change the MMN
|
||
on file to avoid problems next time you call.
|
||
Also take note, at any point, if the agent wants to put you on hold, or says he needs to verify
|
||
something and will be back, wait for him to put you on hold, and hang up. It basically means
|
||
they are going to ring the cardholder. If this happens, you might want to wait at least 48 hours
|
||
before calling again, and you will see just by the automated prompts if the card is burnt or not.
|
||
Maybe they did not call the cardholder, but in 90% of the cases, they did. It happens,
|
||
especially with Citibank, who likes to replace the Verid questions by a quick ring to the
|
||
cardholder.
|
||
|
||
The questions often change when you call, but they always follow a certain pattern. By
|
||
experience, I will give you the tokens usually asked by the big 4 banks, but we aware that
|
||
they might change, or they might ask you other questions if they believe you are bogus. They
|
||
can ask for your age to throw you off, as you might not have to calculate it fast enough using
|
||
the DOB. If you fail this verification, you will be transferred to Verid department.
|
||
Since you have to wait 5 days, it's a good idea to create an account on your target website,
|
||
browse the items, put some in your cart, go to checkout, go back, remove items, read
|
||
descriptions. Just try to appear like a legitimate shopper. Remember that $1000 is a lot of
|
||
money for the average American and if you show you don't care about your money and just
|
||
throw items in your cart, you raise flags. Look like you care about how much it costs.
|
||
There is also a technique that works well with Citibank: when you are asked for the MMN by
|
||
the automated system, if you fail, you will hear “the agent might need to ask you verification
|
||
questions”, and if you succeed, you will be connected and everything will be a breeze. When
|
||
the automated system asks you for the password, say “Jope” while putting a high tone on the
|
||
O sound, then slightly lower your pitch. Say the word at normal speed, like when you are
|
||
talking to someone. This will trick the automated system into beleiving that you got it right.
|
||
You might have to retry 23 times for it to work, but I got it with almost all my accounts. This
|
||
will save you a lot of hassle with the agent and will make the call extremely easy.
|
||
Once you got rid of this verification process, it will be easier next time you call the bank for
|
||
this account. So let's suppose you followed me and let it sit for 5 days. Call again, and this
|
||
time, we will add a temporary shipping address to the account. A transcript can go as follow:
|
||
(pass verification questions) You: I want to make a purchase from Newegg.com but they ask
|
||
me to add a temporary shipping
|
||
address on file. I'm not sure how that works, do I just tell you where I want them to send my
|
||
order?
|
||
Agent: Let me help you with that, we can add an alternate address on the account, what
|
||
would be the address?
|
||
You: 123 Fraud Street, Cardingville, CA, 98765.
|
||
Agent: No problem mister Layton, I have notated the account for you, is there something else
|
||
I can assist you with today?
|
||
You: No thank you
|
||
Agent: Have a good afternoon.
|
||
|
||
Almost all banks allow that, except Bank of America, who can only change the mailing
|
||
address. That's why their cards are not the best when it comes to level 3 carding, but some
|
||
stores will do a conference call with the bank to bypass this restriction. Chase works the best
|
||
for temporary shipping addresses, but is hard to ATO. It all depends on your skills and what
|
||
you're comfortable with. All US banks accept a Canadian address, and some banks may
|
||
accept an international address.
|
||
Once you have added the alternate address in the account, it's time to make the hit. Take
|
||
your account on the website you want to card, shop a little bit again, then proceed to
|
||
checkout. Try not to go over $2000 per order. Enter the correct billing address, doublecheck
|
||
the information. Enter the billing phone number (the one you added on the file at the bank),
|
||
then your shipping address. Triplecheck all the information for accuracy.
|
||
Then, send the order. You might be greeted by a VBV or MCSC form, but if you have the
|
||
required information, it should not be a problem. Enter the information they want to get, and
|
||
submit the order. Also, some websites like TigerDirect will ask you for your DOB and will give
|
||
you 3 verification questions to answer. Those are public records and can easily be found in
|
||
your background report, so don't be scared. If you fail 1 question, you will be asked an
|
||
additional question. If you fail 2 or more, the order will be put “on hold” and things will get
|
||
harder, so try not to fail.
|
||
At this point, 2 things can happen when you submit the order. It depends on the spending
|
||
habits of the cardholder, and will make things easier or harder for you.
|
||
1. The order goes through without any problem, and becomes “pending” status.
|
||
2. The transaction get declined and the website says to call the issuing bank. If this
|
||
happens, call the bank, the system will act like the card is burnt (transfer without any
|
||
additional questions), and a fraud agent will answer. Remember, the card is yours, tell
|
||
them you authorized the transaction, but you don't know why it's declined. It's usually
|
||
easy if you have the correct information, but if you ATO'd the account before, chances
|
||
are that you have everything it takes. When the agent tells you you are all set, resend
|
||
the order on the website. Call as soon as you get the decline, don't wait, otherwise the
|
||
real cardholder will get a call you don't want him to get.
|
||
|
||
All right, the order is now sent and the status is “pending”. The next section will tell you why
|
||
some orders get canceled (newbie mistakes), and why in your case everything should be all
|
||
right. Take a deep breath and hop to the next section.
|
||
WHY ORDERS GET CANCELED
|
||
When a website receives an order of about $1000, we understand that they try to protect
|
||
themselves. What is the first thing that a website will do to verify the order? That's right, they
|
||
will call the issuing bank and will check if the billing phone number you entered is correct,
|
||
otherwise they will ask for it, and will ring it. You can receive the call, or the cardholder will,
|
||
depending if you ATO'd the account correctly.
|
||
This is why orders get canceled when newbies enter a credit card order and expect to receive
|
||
a free iPhone from the Apple store. They are not fools and want to protect themselves.
|
||
However, if you took care of changing the billing number on file, you will get the call and you
|
||
will be able to confirm the order.
|
||
Not so fast, a call is not simply “is everything okay?”, but rather a verification call where they
|
||
want to see if you are really the cardholder or not. They sometimes ask you for verification
|
||
questions similar to Verid questions, but all the questions are taken from public reports. They
|
||
can also ask you if you put the shipping address on file with the bank (you hopefully did), and
|
||
they will call the bank to verify. Also, in some rare cases, they can make a conference call
|
||
with you and the bank, but you will be asked for the usual questions, which means last 4 of
|
||
SSN, DOB, last transactions, etc.
|
||
If you are a newbie and just put some credit card information on a website hoping to get a free
|
||
iPhone, you will just see the order passing to Canceled state without any details and you will
|
||
not even get a call. This is the reason why people post threads about “carding does not work”
|
||
and get the same answers.
|
||
If you passed the verification call, the representative will tell you that everything is okay and
|
||
that they will have the order shipped out today. This is good news! At this stage, I received
|
||
100% of my items, I never had problems past the verification stage. Now you may be tempted
|
||
to hit another site; resist to the temptation. You ATO'd card can almost be considered a level
|
||
4 card, at you own the account and can do whatever you want, so it has a high sentimental
|
||
|
||
value. Wait for the order to ship and the package to leave the merchant before you hit another
|
||
webstore.
|
||
I recommend carding in the morning, to avoid letting a charge sit on the card for too long. You
|
||
never know how often a cardholder checks his statement online. I had cards that died within
|
||
hours, and other ones lasted 3 months. Once the package is shipped, you can card another
|
||
store, no need to call the bank, as your drop address is already on file. Repeat until the card
|
||
is burnt. Once it is burnt, never show your face at the drop again. The alternate address is on
|
||
the bank's records and they can send Law Enforcement to this place. A drop is like a condom,
|
||
use it once, do all your business, and trash it, because it becomes dirty.
|
||
Another verification step they can take is send you an email asking for scans of your ID
|
||
documents, such as passport and driver's license. These can easily be photoshopped and
|
||
there are templates available everywhere. Utility bills are pretty easy to forge too, so don't
|
||
worry about this part. Do what you have to do, but be quick.
|
||
Another step you can take, is to put the shipping name on the package to a family member of
|
||
yours, for example if the cardholder's name is James Latyon, send the package to a certain
|
||
Harry Layton (find a name that's on the report and have their DOB, in case) and say you are
|
||
sending the package to your son / brother / whatever relationship you have on your report.
|
||
Also, keep in mind that no method is perfect, and the website can cancel the order simply
|
||
because they feel it is not safe to process it. Nothing is perfect, but if you ATO'd the account
|
||
successfully, it should be easy. Remember to stay under $2000 per order. You never know
|
||
what other tricks they may use to catch you.
|
||
Always choose the fastest shipping method. Some say it raises flags, but if you did everything
|
||
else correctly, that will not be the reason why your order fails. Besides, it greatly reduces your
|
||
chances of getting an intercepted package, which is a pain in the ass and makes your efforts
|
||
worthless.
|
||
This brings me to the topic of finding a drop to ship your order to. You can ship it to your
|
||
house without any problem, if you want the police to knock at your door and make you ride
|
||
dirty to the police station, and get in a steaming pile of shit of trouble. So read on to find out
|
||
how to ship your order safely.
|
||
|
||
DROPS
|
||
A “drop” is a place, or location, where you have illegal, carded, or stolen goods shipped to. It
|
||
has to be a place that has no link with your current life and is in no way linked to you.
|
||
Finding a drop is not really hard. You can go on Craigslist and find houses for rent, or just
|
||
drive around your neighborhood looking for houses for sale where you can ship goods to.
|
||
Make sure the house has no big windows that allow the driver to see that the house is empty.
|
||
You don't want to have the package returned to the sender because of that. Just use your
|
||
brain to find a decent house that you think is worth shipping a package to. Usually pick a town
|
||
close to yours, but not in your neighborhood.
|
||
The big day has come: UPS tracking shows “Out for Delivery”. Yeah! Now check if the
|
||
package requires a signature. All carriers require it, except UPS. For UPS, you can see if
|
||
Signature Required is written on your tracking page. If nothing mentions a signature, or if you
|
||
are not sure, then signature is not required.
|
||
Method 1: Acting like you are away
|
||
If you don't need a signature, you can leave a note on the door, “we are away, please leave
|
||
package here, take this as my signature” and you might as well print the order confirmation
|
||
page showing the tracking number and put it with your note to make your case stronger. The
|
||
driver makes the final decision about leaving the package or not, but usually there is no
|
||
problem with UPS when they don't need signature. Sign the note, put the order confirmation
|
||
page with it, stick it in the door, and wait in your car not far from the place. When the driver
|
||
leaves the place, grab the package, and put it in your car. Then skip method 2, and continue
|
||
reading.
|
||
Method 2: Acting like you own the place
|
||
The second method is when a signature is required. You will have to meet face to face with
|
||
the driver. Remember one thing, you can relax. The driver's job is not to investigate fraud, but
|
||
only to make sure the package does to the right received. So you must just make him believe
|
||
the package is yours, they don't care about fraud (but don't be stupid and talk about your
|
||
crime). Carry a printout of the order confirmation page, the tracking number open on your
|
||
smartphone (use VPN!), and look like you've been waiting for him. You might wait at the drop,
|
||
sitting on the front lawn, or doing whatever you want. However keep in mind that waiting in the
|
||
|
||
car when the driver sees you get out of the car is highly suspicious. If you choose to wait at
|
||
the drop while being visible, take down any “for sale” or “for rent” signs, and call the bank's
|
||
automated system prior to showing up to ensure the card is still valid and the police is not
|
||
waiting for you. Greet the driver, show papers, sign the cardholder's name, and proceed to
|
||
the next section.
|
||
Sometimes, the driver might get cocky and ask, why your name is not the same one than
|
||
what's written on the package, or why you're not inside. You can tell that you recently moved,
|
||
and you put it under someone else's name because you have “problems with customs”. When
|
||
they get cocky, you can threat them to make a complaint at their local UPS hub, they usually
|
||
calm down and hand over the package. I had a cocky driver in my last carding trip in
|
||
Minnesota, and I had to use this method, and I finally got my package.
|
||
By experience, when you have brokerage fees to pay (like international package), you can
|
||
call UPS before getting the order and ask the amount. Leave a money order on the door and
|
||
the driver will take it and leave the package. You will avoid getting a InfoNotice that way, and
|
||
the driver will believe you own the place. I did that a lot of times and no failure so far.
|
||
Picking your package at the UPS facility
|
||
In some unfortunate circumstances, the package can end up at the local UPS facility and will
|
||
require governmentissued ID to be picked up. This happens if you missed your drop, for
|
||
example. In that case, don't bother making a fake ID, as there is a better trick.
|
||
The package is usually held for 5 business days before it is sent back to the sender. The day
|
||
the package arrives at the facility is day 0. Two scenarios can happen:
|
||
Scenario 1: You get a call from the UPS branch
|
||
They will probably call you and say something along the lines of, we have a package for
|
||
James Fakename waiting at the facility for pickup. Just tell them that you don't know this
|
||
person. Here's a sample script of what it should look like:
|
||
UPS: Hello, may I talk to James Fakename please?
|
||
You: I think you may have the wrong number, who is speaking?
|
||
UPS: This is the UPS branch, we called the phone number we had on the package.
|
||
You: Oh, I was waiting for a package too, and it didn't get delivered. Is this a package from
|
||
Newegg, a smal box?
|
||
|
||
UPS: Yes, we have one small box waiting here, for James Fakename.
|
||
You: I have a tracking number, can you check if the last 4 digits are 3382?
|
||
UPS: Yes they are.
|
||
You: I'm very surprised, because my name is Fake Name and I was waiting for this one. I
|
||
have no idea who James Fakename is. They looked confused when I placed the order too.
|
||
UPS: Well, the package will be sitting here, just come pick it up when you are ready.
|
||
This worked me twice. I had 2 drops to watch at the same time and I missed one package.
|
||
This allowed me to pick it up.
|
||
Scenario 2: You do not get a call
|
||
On the morning of day 5, call the tollfree number and ask to be transferred to the local
|
||
branch. You can do the same scenario, and inquire about a package waiting there for you.
|
||
You must look confused a bit in your voice and look like someone who was victim of a
|
||
mistake from the online store, and they will gladly hand over the package to you. Everytime I
|
||
did it, I never got asked for any form id ID and it was all smooth.
|
||
Do not give your real name. Test the card before going (call the bank), and only do it if the
|
||
card is still live, otherwise it can be dangerous. You can also send a mule if you are too afraid,
|
||
but I showed my face a few times when the card was still live and never ran into issues.
|
||
After getting your package
|
||
I sometimes skip this part when I am lazy, but you should be extra careful. Your freedom has
|
||
no price tag, so take 5 more minutes to do this precaution.
|
||
Drive to a nearby park or public place, and open the cardboard packaging. Look for any
|
||
device that may be tracking your position, such as bugs, GPS devices, etc. Then destroy the
|
||
shipping label (you can burn it to make sure), throw the cardboard packaging away, and you
|
||
now have in your hands a precious item you carded using your ATOd card. Also burn the
|
||
order confirmation page if you decided to go this route and you brought it to the drop! At this
|
||
point, you can consider your carding heist a “success”! Drive home, relax, you owned the
|
||
bank and the website.
|
||
If the card is still valid and there was no tracking device, you can card to the same drop again
|
||
until the card burns. Get as much as you can out of it. Burn the card to a crisp. I remember
|
||
|
||
getting $10,000 worth of electronics on a Chase card at the same drop, split on 5 orders. This
|
||
was a moneymaking week.
|
||
All right, you carded the item, ATO'd the account, got items, more items, burnt that drop to a
|
||
crisp too, now the card is dead... either over the credit limit, or flagged by the cardholder.
|
||
Never show your face to that drop again, and enjoy your goods!
|
||
What happens after? Read on to find out.
|
||
CHARGEBACKS
|
||
A recurring question is, when the card is declared stolen and the transaction is disputed
|
||
because of fraud, who takes the hit?
|
||
In the case of a cardpresent transaction using chip & PIN in countries where they use that
|
||
technology, the bank takes the hit when the transaction is declared fraudulent.
|
||
In all other cases, it's the unfortunate merchant that takes the entire loss. So if you card
|
||
Newegg for $2000, they pay about $1600 for the merchandise that they send you, and they
|
||
are short the money because you carded them, so they have to make 6 similar big orders
|
||
without problems to cover that loss. You now undertand why they make verifications and don't
|
||
want to be carded.
|
||
Some big merchants like TigerDirect and Newegg will just eat the loss and assume that they
|
||
failed at fraud detection, but smaller merchants will make a formal complaint at their police
|
||
department. Now, is the police going to investigate? It depends.
|
||
If a merchant reports a $200 loss for an order shipped out of state using a stolen credit card,
|
||
there is a 99% chance that the police will not even open an investigation for that. However if
|
||
they report a $3000 loss using a stolen card from the same state and shipped in a nearby city,
|
||
LE (Law Enforcement) might move for that.
|
||
|
||
It also depends on the volume of complaints, the amount of loss compared to the size of the
|
||
city, and whether there is an obvious pattern between fraud complaints or not. You should try
|
||
to make your orders not linkable to each other, and use your common sense to avoid creating
|
||
a pattern that might trigger an investigation.
|
||
It also depends if the cardholder himself decides to make a complaint or not. As long as they
|
||
get refunded by their bank (which they do), chances are that they will not care and just forget
|
||
all that. But some more mad people can decide to make a police report for identity theft.
|
||
Again, there will be an investigation if there is an obvious pattern. It all depends which city you
|
||
are talking about.
|
||
So remember, when you card a website, they take the loss in case of a chargeback, so they
|
||
want to protect themselves. You have to be smart and ask yourself, if I were in the shoes of
|
||
the website owner, how would I catch fraudsters?
|
||
Sometimes, you might receive an email from the store asking you to provide more
|
||
information about the chargeback, such as authorization forms or documents. Just ignore that
|
||
email. Do not become cocky and answer “I got you!” because it could be the difference
|
||
between an investigation or not. Keep it dead.
|
||
WARRANTY FRAUD
|
||
A very fun type of virtual carding is warranty fraud. I got some $1000 CPUs from Intel and
|
||
motherboards from ASUS using that trick. Here's how it works.
|
||
Many companies, especially electronics, offer what is called “advance RMA”. This is a type of
|
||
warranty replacement where the company sends you the new product first, along with a return
|
||
box for you to return the defective item to them. They sometimes ask for a credit card number
|
||
in order to make sure you will return the defevtive item. This is where we can take advantage
|
||
of the system.
|
||
It works will Dell, Intel and ASUS, perhaps a lot of other ones, but they are the ones I have
|
||
experience with so far. You can PM sellers on eBay to ask for serial numbers of products, or
|
||
you can simply card a product and request a RMA using its serial number. Call the
|
||
manufacturer, say that your product is defective (use a diagnostic that makes sure it's really
|
||
this product that is faulty, such as “the video card shows nothing on the screen, I tried 2
|
||
screens, but it works with other video cards”, and ask if they offer advance RMA, they mostly
|
||
|
||
will. Use a level 2 card and have it shipped to your drop address. If they ask why, just tell
|
||
them you are on vacation there and your computer broke.
|
||
When you receive it, take the package, and disappear. You just got more free stuff using a
|
||
credit card that will eventually, maybe, get a chargeback, but you get the point.
|
||
For Intel, they ask for the 5 lines of text on the CPU itself, and a credit card for hold, so you
|
||
need to have the unit in your hands for it to work.
|
||
For ASUS, the serial number is enough, they require a credit card.
|
||
For Dell, it's the easiest, no credit card needed, just order your free item on the phone without
|
||
credit card, you just need a name and an address.
|
||
Feel free to discover weaknesses in other companies' systems, this is a relatively new kind of
|
||
fraud and has not been patched. Many people use that to get free Xbox Series from
|
||
Microsoft. Most companies require that this warranty claim is done over the phone but don't
|
||
worry, it's simple, and most of them don't seem to care about their job. I had 2 declines when
|
||
carding Intel, the third one worked like a charm, and they did not even get cocky about it.
|
||
You can keep one for yourself and sell the other one on eBay or Craigslist, it's easy money to
|
||
make. The point is that they have to try to screen fraud at the same time than offering a
|
||
seamless experience for legitimate customers. We just abuse the system.
|
||
PICKING THE BEST CARDS
|
||
If you don't have access to fulls, or you have a CCV autoshop and you want to get the best
|
||
out of it, there's a trick that can save you money, if you have a bit of time to invest. It works
|
||
with any autoshop as long as you can see the name and zip of the cardholder.
|
||
First, search by desired BIN. If you like ATOs and you want good cards, BINs 426684 and
|
||
438854 work well, but that is up to you. If you can't search by BIN, just pick Credit Cards from
|
||
any bank. Once you are in the list, find cardholders corresponding to your gender, and for
|
||
each one, do the same thing.
|
||
Search their name and zip on Backstab or SSNFinder to check if you can find them. Most of
|
||
time time (>50%), you will not, especially if the cardholder is under 45 years old. So just do
|
||
|
||
the same for the next result. When you have the SSN and DOB of the cardholder, before
|
||
buying the card, do this thing to doublecheck the info:
|
||
Go on peoplefinders.com and get their background report. Check if the DOBs match, and if
|
||
the address list matches too, to make sure you have their SSN and DOB 100% accurate.
|
||
When you are sure, buy the card, and buy SSN and DOB. You now have a fulls. You can go
|
||
on archives.com or ancestry.org to get their MMN. Here's how to search;
|
||
Card an account on any of those 2 sites (level 2 card is enough, it's very easy). Get the
|
||
mother's name on the background report, and search using her first and last name, and
|
||
correct date of birth. Search for “marriage” records, if you can't find any, search “birth”
|
||
records. If you don't find anything, try searching for the father's marriage records. Note that
|
||
not every state / county has their records made public, so it's possible that you won't find it at
|
||
all; it's okay, just make one up when you ATO the card.
|
||
This way, you can scrub the autoshops and select only the cards where you can have full
|
||
information. This is my trick to get only good cards. Of course, the best option is to find a fulls
|
||
vendor, but there are not a lof of them, so escalate your cards the way you desire.
|
||
Make sure your cards are well organized. I have included a sample Excel file where you can
|
||
see how my cards are organized. All cards can be sorted by name, address, number,
|
||
expiration, DOB, SSN, etc. Look at the file for more information. Also, use line colors for
|
||
different meanings. Example, white rows mean that the card is mine, and still not used. Call
|
||
the bank before adding the card to the list, because you want to trash junk cards right away.
|
||
Yellow means that the card is burnt, and blue means that the card is currently being striked,
|
||
so I know what to focus on. Green means that I fucked up the cardholder's credit history using
|
||
his DOB and SSN. When you look for fulls, look at your Excel file, and with the colors, you
|
||
can find your card quickly.
|
||
Then, just check the balance, study the background report, and you are ready to hit big shops
|
||
and get stuff at your drop!
|
||
COMMERCIAL FRAUD
|
||
Want another (and probably easier) to get items shipped to your drop and getting tired of
|
||
carding Newegg and TigerDirect? All right, I'll show you another method for that. This method
|
||
works best for Canada but is really good for USA too.
|
||
You can find any major provider that only sells to commercial customers. For computer parts,
|
||
for example, you can targer ASI, Synnex, and so on. The goal is to get the business
|
||
|
||
registration certificate of a business in the town you wish to have your drop. This certificate is
|
||
usually public data and can be found on the registration records depending which state or
|
||
province you are in. Once you got the business registration documents from a business that
|
||
operates in the same field of activity you wish to get items for, you are ready to hit the
|
||
provider.
|
||
Apply for an account at one of those providers using that document, put all the business
|
||
address info, but put a drop address close to that place, and your burner phone number. Both
|
||
providers (ASI and Synnex) usually don't call, but just in case, better stay safe. It usually
|
||
takes 2448 hours to open an account. “Your name” is the name of the real business owner.
|
||
On the credit application, do not request net terms, just write “no credit” and let them know
|
||
you will pay before getting items shipped.
|
||
On the credit card authorization form, put the cardholder's (pizza) name, address, card
|
||
number, expiration date, CVC code. Let them know that this person is an “officer” at your
|
||
business, such as a remote sales representative. Once the application is approved, you are
|
||
good to go and hit big amounts. The reason is that they do not make verification when
|
||
sending orders, as they almost never get fraudulent orders. They assume that commercial
|
||
customers are always going to be legit, but in fact, we use someone else's business
|
||
documents to trick them into thinking you are the business owner.
|
||
I was able to pull over $5,000 per order using that technique; the merchant is considered
|
||
lowrisk so there are very few declines, and verifications are almost nonexistent. With
|
||
computer parts, it's extremely easy to do that, you can try other commercial providers. Now
|
||
you are playing in the big game, and the possibilities are endless. Make sure to never show
|
||
your face at the drop once the card burns, as they will really try to find what happened.
|
||
NEWEGG AND TIGERDIRECT
|
||
Always wanted to card those 2 big merchants to get electronics? I will tell you how. This is
|
||
normal difficulty if you know what you are doing and if you are good at social engineering. You
|
||
need, at the very least:
|
||
1. Cardholder's account ATO and billing phone number changed to your burner
|
||
2. Shipping address on file with the bank
|
||
3. Full background report on the cardholder
|
||
4. Story about why you ship to that address
|
||
|
||
5. Local area of the cardholder: restaurants, shopping malls...
|
||
And remember, mail forwarding companies are blacklisted by those merchants. Don't try
|
||
shipping to MyUS, Bongo, and so on, as it will automatically cancel the order. Which
|
||
American would use a US card to ship to a forwarding company to get it out of the country?
|
||
None. Have a normal drop address.
|
||
Number 5 might seem strange, but it's true. Some people, including myself, have been asked
|
||
“can you name a local restaurant near your house” to make sure you are the cardholder. So
|
||
it's not a bad idea to get familiar with the surroundings (major malls and restaurants) in case
|
||
that happens. You'll thank yourself later.
|
||
So, take your time to browse, look around, read descriptions, and appear like a legitimate
|
||
shopper. Once you did that a few days and the account is ready, send the order, and try not
|
||
to go over $2,000. The order will be placed on “hold” status, and you will have to talk to the
|
||
verification department. I will describe the procedure for TigerDirect, but Newegg is fairly
|
||
similar.
|
||
TigerDirect's website will ask you for addresses, credit card information, then you will have to
|
||
pass VBV/MCSC. After that, they will ask you for your date of birth. Then, 3 verification
|
||
questions will pop. They are public record information about the cardholder and can be found
|
||
in your background report. Try to have so much information that you feel like the cardholder is
|
||
your friend. Answer the 3 questions and be quick. If you fail one, you will be asked an
|
||
additional question. If you fail 2 or more, forget your order. Once you send everything, your
|
||
order will be “on hold” status. You need to call the verification department. Conversation goes
|
||
as follow, usually:
|
||
Rep: Thank you for calling TigerDirect verification department, can I have your order number?
|
||
You: 123456
|
||
Rep: All right, what is your name?
|
||
You: James Layton
|
||
Rep: Thank you Mr. Latyon, let me verify the order for you.
|
||
(you will be on hold about 2 minutes)
|
||
Rep: Thank you for holding, is <name on the package> a tenant at the shipping address?
|
||
You: Yes (giving the wrong answer voids the order)
|
||
|
||
Rep: I could not locate that person in the system. So you will be offered 2 options. Either we
|
||
ship to your billing address, or you need to call your bank to add the shipping address as an
|
||
alternate address on file so we can ship there.
|
||
You: I already did.
|
||
Rep: Oh really? All right then, let me verify that for you. Please wait.
|
||
(you will be on hold while they call your bank, sometimes they can make a 3way call)
|
||
Rep: All right, I see the shipping address is on file. Thank you, and is it okay if I call you on
|
||
that phone number, 1234567890? (whatever phone is the primary billing number)
|
||
You: Yes, sure.
|
||
Rep: Thank you, hold on.
|
||
(the phone will ring, pick the call, or the order will be void)
|
||
Rep: All right, we have successfully verified your identity Mr. Latyon. We will have the order
|
||
shipped out to you tonight.
|
||
See the pitfalls in the dialog above. You must assume that the shipping name is a tenant at
|
||
the address. For example, if the cardholder's name is James Latyon, you can ship to a
|
||
Joseph Layton and assume it's your son, but make sure that name is on the background
|
||
report and you have their DOB. Sometimes they may ask for it if they get suspicious.
|
||
It is also a good practice to avoid Hotmail addresses; anyone can make a fake Hotmail under
|
||
someone
|
||
else's name. You should use a custom email with a custom domain.Next, you must make
|
||
sure you can pick the phone when they call the “billing” number. If you do all that correctly,
|
||
you are good to go and you will get your parts. They do not ask for scans of documents,
|
||
everything is done over the phone.
|
||
THE PTO
|
||
When you commit Account TakeOver fraud, also known as ATO, you take “ownership” of the
|
||
victim's account. Even if you change the phone number on file, they still keep record of the
|
||
previous phone number. This is where this section will prove useful. I will give you the
|
||
transcript of a failed ATO I had 2 months ago, and you will understand.
|
||
(pass verification questions) Me: I am calling because I tried to place an order online, but it
|
||
got declined. The charge is $1500 and the merchant is Newegg.
|
||
Agent: No problem Mr. Johnson, let me see what I can do for you, can you please hold?
|
||
(by experience, if they put you on hold, hang up, it's most likely burnt, here it took 5 minutes)
|
||
Agent: Hello?
|
||
Me: Yes madam, I'm still holding.
|
||
|
||
Agent: Unfortunately I will not be able to let the charge go though, and I can no longer provide
|
||
service on this account.
|
||
Me: How about my card? What should I do?
|
||
Agent: You can destroy the card, as you are not the real Robert Johnson.
|
||
This is a situation that sucks, and there's a way to avoid that. It has to be done before calling
|
||
the bank. What happened here is that the agent called the previous number, even if I changed
|
||
it a few days ago. The real cardholder got the call, and you can imagine the rest.
|
||
First of all, take the real phone number of the cardholder, and use WhitePages to find who is
|
||
the phone provider. If you cannot find it, then you might want to use Spooftel and call the
|
||
various providers (AT&T, Verizon, Sprint, etc.) and use their automated system to try to find
|
||
out if the number is registered with them. You can use phonevalidator.com to see if the phone
|
||
is a cellphone or a landline. When you have the background report of the victim, you can see
|
||
that they often have many phone numbers. Use the service to find which one is landline and
|
||
which one is cellphone. For cellphones, it's very easy to find the provider, as most of them
|
||
allow you to call the phone and press * (star) to go in the voicemail settings, so you recognize
|
||
the greeting. Use your logic, and write the phone numbers, probably like that:
|
||
Phone 1, landline, 5551234567, Verizon Phone 2, cellphone, 6662345678, AT&T
|
||
Now, remember, you have the full address, DOB, SSN, and more information on the
|
||
cardholder, and you know what is his phone company. What are we gonna do? That's right,
|
||
Call Forwarding!
|
||
Call up the phone company using the opposite phone (if billing number is the landline, call
|
||
with the cellphone, and vice versa), spoof the number. When you talk with the customer
|
||
service department, it might go as follow. Don't forget that it's less secure than banks, as it's
|
||
not about finances. But it can have worse consequences.
|
||
Agent: Thank you for calling Verizon, my name is Mohammed, how can I help you?
|
||
Me: Hi! I will be away from my house in the next days but I'm waiting for an important call on
|
||
my landline. Since I cannot reach the other party, I would like to set call forwarding so I will
|
||
receive the call on my cellphone.
|
||
Agent: No problem, can I have your name?
|
||
Me: Barack Obama.
|
||
Agent: Thank you Mr. Obama, what is your full address?
|
||
Me: 123 fake Street, Washington DC, 12345.
|
||
|
||
Agent: Thank you, and may I have your date of birth?
|
||
Me: October 11 st , 845.
|
||
Agent: Thank you. Did you know that you can press *72 on your phone to activate call
|
||
forwarding? This is an easy way to do it without calling customer service.
|
||
Me: Thanks for the tip, however I'm not home at the moment, so I am unable to do that.
|
||
Agent: Okay no problem, I will activate it for you. What is the phone number you would like
|
||
the calls forwarded to?
|
||
Me: That's my cellphone, 4561233245. (your burner phone)
|
||
Agent: All right, and you want it to start now?
|
||
Me: Yes, please.
|
||
Agent: No problem, I activated it for you. When you will be home, you can use *72 again to
|
||
deactivate the forwarding.
|
||
Me: Thanks.
|
||
Agent: Is there anything else I can help you with?
|
||
Me: Nope, thanks.
|
||
Some phone companies, AT&T by experience, ask for a 4digit PIN, but it can be easily
|
||
bypassed using DOB and last 4 of SSN. The good point is that, if you are extremely unlucky
|
||
and fail (which should not happen because it's easier than banks), the card will not burn. This
|
||
is the PTO, Phone TakeOver fraud.
|
||
Now you are ready to call the bank to ATO. If they decide to call the billing number (happens
|
||
very rarely), you will answer the phone, and it will destroy all suspicions they have. The
|
||
cardholder will probably be locked out of his account, but that's not your problem. The first
|
||
dialog (failed ATO) can be avoided if you do that before.
|
||
When your business is finished, do not forget to call Verizon (or his company) to deactivate
|
||
call forwarding. The goal is to get free stuff, not make the cardholder lose friends because
|
||
they can't reach him, use a bit of compassion. If you think you will need his phone line for a
|
||
few days, you can use RingCentral phone system and decide which numbers you want to
|
||
take the calls from, and which ones you just want blindly transferred to the cardholder. He will
|
||
probably never notice that someone fucked with his phone line, but will notice the charged on
|
||
his card!
|
||
Some websites do not require the shipping address to be on file with the company; in those
|
||
cases, you can do a PTO without doing an ATO, and put the correct billing number on the
|
||
|
||
website. Take the call from them and confirm the order, and restore his phone line. Use your
|
||
imagination for the rest.
|
||
MAXIMUM FRAUD PREVENTION
|
||
The most popular software used by merchants for fraud prevention is the Minfraud software,
|
||
designed by Maxmind. It is used to keep fraudsters as bay, but their formula is not so secret. I
|
||
will give you the formula, and explain the variables. There is a way to keep this score low.
|
||
Many stores have their own preset limits, which are not made public because each store is
|
||
different. For example, a store can say that over 7 they send the order to manual review, and
|
||
over 9 they cancel it. The definition of the variables goes as follow:
|
||
1. IsFreeEmail Is the email address from a free provider like Hotmail or Yahoo?
|
||
2. CountryDoesntMatch Are the shipping and billing countries different?
|
||
3. IsAnonymousProxy Is the user using an anonymous proxy like a VPN or blacklisted
|
||
Socks?
|
||
4. HighRiskCountry Is the order involving Ghana, Nigeria, or Vietnam? List updated
|
||
often.
|
||
5. BsDistance Distance between billing and shipping addresses, in kilometers.
|
||
6. MaxEarthArc The halfcircumference of Earth, currently set at 20,037 kilometers.
|
||
7. BinDoesntMatch Is the BIN from a different country than the IP address used to order?
|
||
8. BinNameDoesntMatch If user is asked for bank name, did he answer correctly?
|
||
9. CarderEmail Was the email used for fraud on other sites using Maxmind?
|
||
10. HighRiskUsername Was the username used for fraud on other sites using Maxmind?
|
||
11. HighRiskPassword Is the password the same than the ones used for fraudulent
|
||
orders?
|
||
12. ShipForward Is the shipping address a mail forwarding company?
|
||
13. ProxyScore Is the IP address a proxy or socks?
|
||
The algorithm used for fraud score calculation goes as follow:
|
||
2.5 * IsFreeEmail
|
||
1. 2.5 * CountryDoesntMatch
|
||
2. 5.0 * IsAnonymousProxy
|
||
3. 5.0 * HighRiskCountry
|
||
4. 10.0 * min(BsDistance, 5000) / MaxEarthArc
|
||
5. 2.0 * BinDoesntMatch
|
||
6. 1.0 * BinNameDoesntMatch
|
||
|
||
7. 5.0 * CarderEmail
|
||
8. 5.0 * HighRiskUsername
|
||
9. 5.0 * HighRiskPassword
|
||
10. 5.0 * ShipForward
|
||
11. 2.5 * ProxyScore = Maxmind score for this order
|
||
Now that you have this formula, let's see how we can reduce the score to almost 0. Although
|
||
many stores use proprietary software, this one is widely used and is the most popular. Since
|
||
there is no way of knowing which software the shop uses, just pay attention to all the
|
||
variables and try to look legit. Here is a more indepth explanation of each variable and how to
|
||
pay attention to it.
|
||
1. IsFreeEmail
|
||
This variable is set to 1 if you use a free email like Hotmail and Yahoo, so don't use it. I'll give
|
||
you a trick. Remember the Stripe cashout part? Create an email address from the same
|
||
domain, like shopper.name@myfakeshop.com and use it. Since it's a paid email, this flag will
|
||
not be raised. I always did that for my orders.
|
||
2. CountryDoesntMatch
|
||
This variable is set to 1 if you ship to a different country than the billing address. This can be
|
||
solved by using a card from the same country than the shipping address. This is easier if you
|
||
ship to USA. Note that this is not a big deal since you can make an excuse, but let's not raise
|
||
flags for nothing.
|
||
3. IsAnonymousProxy
|
||
This variable is set to 1 if you use a VPN or public anonymous proxy. This is also true for
|
||
blacklisted socks. You can use a RDP instead, or if you can't get one, try to find a clean
|
||
socks, but it's mostly trial and error.
|
||
4. HighRiskCountry
|
||
This variable is set to 1 if you have either the billing or shipping address in a country that is
|
||
considered high risk. Since this list is always updated, I can't provide the list, but no western
|
||
country is in that list, so if you are in UK or in USA, no danger.
|
||
|
||
5. BsDistance and 6. MaxEarthArc
|
||
This is the distance, in kilometers, between the billing and shipping addresses, up to a
|
||
maximum of score 10. You can solve this problem by getting cards in the same state than you
|
||
are shipping to. Using a California card to ship to New Hampshire will raise this score.
|
||
7. BinDoesntMatch
|
||
This variable is set to 1 if the BIN is from a different country than the billing address. This is
|
||
the problem with nonAVS cards, and why I don't recommend them. Stick to AVS, and get a
|
||
BIN from the same country. Use common sense.
|
||
8. BinNameDoesntMatch
|
||
This variable is set to 1 if the user answers the question “issuing bank name” incorrectly. So
|
||
for this one, do a BIN check, and write the correct name, exactly as it appears in your BIN
|
||
info, and you will be fine.
|
||
9. CarderEmail
|
||
This variable is set to 1 if the email address was previously used for carding. All websites
|
||
send regular usage data to Maxmind and they have a list of the carder email addresses. One
|
||
mistake carders make is reusing email addresses, thinking that shops don't know that the
|
||
previous shop was carded. Maxmind holds a list of carder email addresses submitted by
|
||
shops. Use each email address only once, and use a different email next time you card.
|
||
10. HighRiskUsername
|
||
This variable is set to 1 if the username was previously used for carding. Read the above
|
||
statement and do the same thing than email addresses.
|
||
11. HighRiskPassword
|
||
This variable is set to 1 if the password was previously used for carding. Pay attention to not
|
||
reuse passwords across sites.
|
||
12. ShipForward
|
||
|
||
This variable is set to 1 if the shipping address is a mail forwarding company. They include
|
||
MyUS, Bongo, and many others. Some sites will outright ban those addresses and cancel
|
||
every order made to them. Avoid shipping there, there are many other options to get drops.
|
||
13. ProxyScore
|
||
This variable is set to 1 if the originating IP addresses is a proxy, or a socks. If the proxy's
|
||
goal is to be anonymous, then the variable IsAnonymousProxy will be set to 1 also.
|
||
Having all this information in hand will allows you to nuke fraud prevention systems and get
|
||
your stuff even more easily. The highrisk country list is always updated but you can always
|
||
google for it if you want to have an uptodate list.
|
||
Always use a VPN with your socks proxy. The TrueIP technology used by many fraud
|
||
prevention software can sometimes bypass your proxy and get your real IP, so pay attention.
|
||
AVS
|
||
AVS is Address Verification System, a fraud prevention system used by shops to make sure
|
||
the billing address is correct.
|
||
It works by computing the numeric part of the address (street address and zip code) against
|
||
what's on file with the bank to make sure it is accurate. It compares only the numeric portion
|
||
only; so 123 Right Street is the same than 123 Wrong Way. The zip code is compared in full.
|
||
Why is AVS important? Because it causes automatic declines on many site if the AVS does
|
||
not fully match. If the cardholder can't write his own address, the website will not believe for a
|
||
second that you are the genuine cardholder. Many sellers sell nonavs cards. Is this good?
|
||
We'll see.
|
||
Let's say you have a nonavs Amex card from Colombia (those are very popular). People tend
|
||
to use those on USA online stores and put the billing address and shipping address to be the
|
||
same, hoping the card will pass AVS. It will. But...
|
||
A clever fraud screening agent will see that the BIN is from Colombia. What is the chance that
|
||
someone with a Colombia card has a USA billing address on file, especially knowing the card
|
||
|
||
is non avs? That's right, very slim. Expect the order to be cancelled right away unless the
|
||
fraud agent is very stupid (they are getting more and more clever those days).
|
||
Nonavs card are to be taken with caution. Do not assume you are able to card any shop with
|
||
these just because they do not use address verification systems.
|
||
SPOOF YOUR E-MAIL
|
||
Sometimes you might need to impersonate someone and spoof an email for various reasons.
|
||
There's a clean and undetectable way to do that, and that's what I'm going to explain here.
|
||
The email will look 100% legit.
|
||
To spoof emails, you will require to make the email yourself. This means creating the
|
||
headers and everything. To make a test, just send a "Hello World" to a test Hotmail address,
|
||
click on "View Message Source", and you will see the top headers. Paste everything (the
|
||
source) in a Notepad++ document. You will see a header that looks like:
|
||
From: Real Name <realname@tcf.onion>
|
||
Modify it to the one you want to show, it's pretty selfexplanatory. For example, change it to
|
||
that:
|
||
From: TCF Hack <tcf@tcf.onion>
|
||
Then you have the full email in a Notepad++ document. Next, get a Telnet client. I
|
||
recommend Putty, it can be downloaded for free. Next, make sure you use an anonymous
|
||
connection (I advise against VPN as it is obvious it's coming from a public proxy; use
|
||
something like a hacked wifi, 3G dongle, etc.) and your security is correct.
|
||
Find the mail exchange server for your domain. For that, go on
|
||
http://www.dnsqueries.com/en/mx lookup.php and enter your domain, example "hotmail.com"
|
||
and you will get the mail exchange addresses. If there are many, just pick one random. In
|
||
your case it will be "mx3.hotmail.com".
|
||
We have everything we need! Open a Putty Telnet connection to your mail exchange server,
|
||
port 25. The "conversation" will go as follow (it can vary a bit, depending on the messaging
|
||
software):
|
||
Send: EHLO mx.spoofedserver.com
|
||
Response: Welcome mx.fakeserver.com
|
||
|
||
Send: MAIL FROM: spoofedemail@dsfdsagsdg.com
|
||
Response: 250 2.1.0 Ok
|
||
Send: RCPT TO: destination@fdsgsfdg.com
|
||
Response: 250 2.1.5 Ok
|
||
Send: DATA
|
||
Response: 354 end data with <CR><LF>.<CR><LF>
|
||
(paste all your data here, the one you edited with Notepad, then press Enter, put a dot (.) and press
|
||
Enter again)
|
||
Response: 250 2.0.0 Ok: queued as 43958340634
|
||
Your fake email is sent. Note that for some providers like Hotmail, if you attempt that (from
|
||
Hotmail to Hotmail), they will put it in Junk Mail because the originating IP is not one of
|
||
Hotmail's servers and they recognize it as spoofed. However if you send an email to Hotmail
|
||
from another server (example @tcf.onion), it will work like a charm. For smaller messaging
|
||
servers, everything will go smooth. Now more people will fall for your scams.
|
||
COMPLETELY SPOOF YOURSELF
|
||
This is about people who are serious into hiding your identity. Newbies would assume that by
|
||
changing your VPN location, you are someone new. More advanced users will say that by
|
||
changing your VPN, your Socks, and by using a completely new browser with user agent,
|
||
changing fonts, resolution and systme time, you are better. In fact, both are wrong. Payment
|
||
processors and Paypal have extremely advanced ways to fingerprint people and we will learn
|
||
here how to bypass that.
|
||
What software or websites (through complex Javascript calls) can use to fingerprint you can
|
||
include motherboard serial numbers, system UUID (unique identifier), and so on. That's a lot
|
||
of stuff to spoof! To spare you the research of spoofing everything, I have prepared a small
|
||
program, DMI Spoof, included in this package. This program was written by myself and is
|
||
used to modify a VirtualBox virtual machine to make it appear completely new!
|
||
Run DMI Spoof and you will be asked for 2 parameters. 1) VboxManage.exe path. This is the full
|
||
path of the VboxManage.exe file, usually located in the same installation directory than
|
||
VirtualBox. 2) Name of your VM. When you open VirtualBox, this is the name that appears in
|
||
bold black characters in the list. You know what this is.
|
||
|
||
Note that you can also supply those parameters at the command line to run it faster, the first
|
||
parameter will be the VboxManage.exe path, and the second paramater will be the VM name.
|
||
It provides a faster way to spoof everything.
|
||
Once you supplied those 2 parameters, DMI Spoof will alter the VM to change the BIOS
|
||
brand, motherboard information and serial numbers, CPUID information and a few other
|
||
parameters. You will appear as having a completely new computer made of completely
|
||
different hardware, with no way of knowing that this has been spoofed.
|
||
Once you boot into your VM, change the following settings in Windows, as they can also be
|
||
used to fingerprint you, and cannot be altered using DMI Spoof:
|
||
1. Screen resolution (you can usually drag a corner of your VM)
|
||
2. Install or delete a font in the Fonts folder (font list can be found using JS)
|
||
3. Change the computer name (requires reobot)
|
||
4. Use Tmac to spoof the network MAC address (can be found using advanced
|
||
Javascript)
|
||
5. Change useragent (use the User Agent Switcher extension for Firefox)
|
||
6. Change VPN location or Socks proxy (this is obvious)
|
||
Once you changed everything, do not reaccess your sites from the same IP than before, or
|
||
you will have to restart the whole process!
|
||
This is enough to protect you from all fingerprinting processes; for payment processors and
|
||
high security sites, this is a must. There is no such thing as “too much security”.
|
||
Note that all this stuff is equivalent to getting a new computer. You will appear as completely
|
||
new and there is no way to trace this back to the original machine. Spoofing DMI is something
|
||
easier done on a virtual machine, and if you read this chapter correctly, you know that you
|
||
must always place your carding software in a virtual machine for maximum security.
|
||
SAFEGUARDING YOUR VPN
|
||
When it comes to using a VPN, many people have a sharky connection and their VPN
|
||
connection disconnects sometimes. What happens if you are using an autocashout script or
|
||
you are logged in using your fake username on an online shop? That's right. The connection
|
||
will be established and will reveal your real IP. For Windows 7+ users, there is a
|
||
Windowsnative protection you can use to avoid such a thing.
|
||
|
||
When you connect your VPN the first time, Windows will ask you if this connection is Home,
|
||
Office or Public network. You must select Public. Then go in the Windows advanced firewall
|
||
settings and follow these steps to protect yourself:
|
||
1) Go in the “outbound traffic rules” section of the advanced configuration window.
|
||
2) Rightclick on “outbound traffic rules” and select “add rule”.
|
||
3) You will be asked which type of rule you want to create. Select “program”.
|
||
4) Click on “browse” and select the .exe file of the application you want, for example
|
||
Firefox.
|
||
5) Select “block connection”.
|
||
6) When asked when will the rule be applied, check “home” and “office”, uncheck “public”.
|
||
7) Give a meaningful name to this rule, for example “VPN Firefox”.
|
||
8) Create the same rule for every program you want to safeguard.
|
||
This way, all connections not on the Public domain (not made through VPN) will be blocked
|
||
for the selected programs, while still allowing the system requests to take the standard way. If
|
||
your VPN is disconnected, you will not be able to use those programs. You should do this for:
|
||
1. Firefox
|
||
2. Google Chrome
|
||
3. Tor Browser
|
||
4. Tor Process
|
||
5. SOCKS Proxy
|
||
6. Proxifier
|
||
7. Pidgin
|
||
8. Thunderbird
|
||
9. Any other program you might judge useful.
|
||
Note that you can't just block every single packet not sent through the VPN. Many programs
|
||
including the operating system itself must communicate on the local network without
|
||
restrictions, and using the rule “block all programs” instead of selecting a program can make
|
||
the system instable and have unpredictable consequences. Also, you need to use traffic on
|
||
the “Home” domain to be able to connect to your VPN.
|
||
This ensures that your IP will never be revealed in case of a disconnection. In that case, just
|
||
reconnect your VPN and everything will continue as normal. You will not have to constantly
|
||
watch your connection status.
|
||
|
||
In case you do not know the path of the file you should choose, you can open the task
|
||
manager using Ctrl + Alt + Delete (or rightclick on the taskbar and select “open task
|
||
manager”), rightclick on the process and select “open file location”. This will give you the full
|
||
path of the file, so you can add it to the firewall rules.
|
||
For older Windows, you can use Comodo firewall to achieve the same thing, however this is
|
||
beyond the scope of this tutorial and has proven to cause system instability. The Windows 7+
|
||
native method has proven to be the most stable and most secure as of now, so enjoy your
|
||
protected system!
|
||
MOST COMMON MISTAKES
|
||
This section talks about the most common mistakes newbies make when they start carding.
|
||
Some can be fatal, other one are just not important, but it's important to understand those
|
||
points.
|
||
#1 – Bragging about your stuff
|
||
When you get free stuff, do not brag to your friends, your family, or girls. You never know
|
||
when someone will be pissed at you and decide to report you. Keep it for yourself, and be
|
||
quiet about it! Just say you have a way to get cheap stuff, and it's private. That's all.
|
||
#2 – Linking to your personal life
|
||
Do not ask a friend to use his house as a drop. Do not ship to your workplace, your dad's
|
||
house, or worse, your own house! If the police shows up at your friend's house, he will rat you
|
||
out for sure. Don't trust people that much.
|
||
#3 – Starting too big
|
||
When you first start carding, do not attack merchants like Newegg or TigerDirect. They are
|
||
not easy and they will give you a negative feeling about carding before you even get free stuff.
|
||
Start small, for example, clothes.
|
||
#4 – Using the same nickname on hacking boards and on clearnet sites
|
||
Many newbies forget that, and yes, there are probably LE officers on DW, watching what's
|
||
going on. If they can Google your username and see your Facebook or anything else, you're
|
||
fucked. Use a name that you use nowhere else!
|
||
|
||
#5 – Responding to allegations of fraud
|
||
Sometimes, you can get caught offbalance, and for example, a shop will respond by “the
|
||
order was fraudulent, so we canceled it”. If you carded them successfully 3 times before, don't
|
||
talk about it. If you just want to show them that you owned them, it can persuade LE to track
|
||
you, because you just linked the fraudulent orders together. Just don't reply anything.
|
||
#6 – Not washing your bitcoins
|
||
If you buy (or card) bitcoins with Virwox, they can use the blockchain to trace where those
|
||
bitcoins went, and eventualy link to you. Use a service like BTC Fog to wash them and get
|
||
brand new bitcoins, not linkable to you, for your underground operations.
|
||
#7 – Talking to your partners on a traceable site
|
||
Do not use Facebook to talk to your partner about carding. Any LE officers can subpoena
|
||
Facebook to get your conversation history and catch you. Use Pidgin/Gajim + OTR/OMEMO
|
||
to encrypt your conversation, and use VPN to connect. Make sure you're not traceable.
|
||
#8 – Getting caught offbalance during an ATO
|
||
When you are ATOing an account, stay calm, do not get thrown off by questions. If you
|
||
answer incorrectly (because very often, they have inaccurate information), stay calm and
|
||
explain yourself, remember, the card is yours. Do not show fear, because they will catch you.
|
||
#9 – Hitting the same drop
|
||
This is pretty selfexplanatory; finding drops is a pain, but make the extra effort and get a
|
||
virgin drop. There is already heat on the first place, so do not put more and risk getting
|
||
caught. A drop is good for 3 days; after that, time to move on. You can apply this principle
|
||
with girls too.
|
||
#10 – Accessing your fake eshop without VPN
|
||
When your Stripe account gets burnt and they subpoena your fake eshop to give them the
|
||
access log, you don't want them to see your real IP and trace back to you. Always use VPN to
|
||
upload files, test your shop, and so on.
|
||
|
||
I hope this guide was useful to you. I tried to put as much as my knowledge as possible to
|
||
help fellow carders in the underground world. Use any part you might find useful to you and
|
||
try to hit for big. Again, thanks to everyone who bought the guide, and if you have any
|
||
question, post in the marketplace so you can be provided better help.
|
||
REMEMBER: Be safe!
|
||
Sacky
|