Forum: The Classroom
Topic: Credit Card Fraud
started by: CatKnight

Posted by CatKnight on Mar. 19 2001,23:51
I was wondering if this would be possible. You know how when you buy something with your credit card, the scanner reads the name and number on the magnetic strip? I believe it also reads the number to call for authorization. After scanning the modem calls the auth center and confirms/denies the purchase. Why couldn't you make a credit card out of plastic, encode the correct data on the strip, including an anonymous phone number. At this phone number, set up a computer that recieves the authorization calls and approves them. I'm sure there are lots of complications to work out...I was just wondering if this would be theoretically posible?
Posted by Prometheus on Mar. 20 2001,14:47
I always assumed that the number was programmed into the register, not the card... but hey, I've been known to be wrong.
What surprises me is that nobody has ever (to my knowledge) hacked into a register's point-of-sale system. I know for a fact that Best Buy's are connected to the internet, which means that it should be possible.

------------------
Necesse est multos timeat quem multi timent.


Posted by askheaves on Mar. 20 2001,16:03
Best Buy's terminals all run NT 4.0... I saw one rebooting yesterday.
Posted by L33T_h4x0r_d00d on Mar. 20 2001,16:44
quote:
Originally posted by syf0n:
when it calls that number it authenticates the cc# with a humungous server at Visa world headquarters, the server that handles like 15,000 transactions per second.

Where the fuck did you get that steaming pile of goat shit? Lets think about this...why would they make EVERYONE call one place. First of all for everyone but a select few it would be a long distance call. Then you would have to have a MASSIVE fucking server cluster to handle the millions of requests per day.

<non-bullshit story> The people i bought my sun server from were called Integrion. They did all the CC validation for the DC metro area(maryland, Washington, Northern VA, and a small part of WVA) They had 52 Sun enterprise servers that handled that small area. They held a database that had everyones credit limit and current spendings for people in the area. They were also attached to Visa's private network. If someone from outside their area called in they would pull that persons records over the private network and validate the transaction or deny it. When small businesses gets a mechant account with visa or master card they have to buy a card reader.(there is a standard so you can use 1 reader to call Visa, Mastercard, Discover and Diners club) They also get the local access number for visa. They have to put the access number in themselves. When a visa card is swiped the card reader knows its a visa and calls visa. If its mastercard it calls master card. Their private network is a dedicated isdn, just like portions of the FAA. </non-bullshit story>

And yes best buy does use Win Nt for their registers and their service terminals(If i have to see that damn S.T.A.R. screen one more fucking time...) The registers use an AMD k6-2 board, a 350 processor and 32megs of mem. The S.T.A.R. system is how they track merchandise and service items. Its a VB front end that ties into a SQL database that FUCKING CRASHES EVERY THIRD TRANSACTION. And the internet connection is done by vpn(usually over satellite) back to BB headquarters and the merchant accounts. Also the music you hear in the store is playing off a monthly Cd thats distributed to the stores with their "WAKE YOUR ASS UP EARLY IN THE MORNING ON A SATURDAY AND WATCH THIS BORING ASS TAPE" that they show at 6:00 in the morning to the employees one saturday a month. Toys R Us on the other hand gets all their shit piped in hot and steamy from marketing via satellite.

just in case you were wondering....


Posted by whiskey@throttle on Mar. 20 2001,18:12
You know, there are a lot of fun things you can do at your local Best Buy. I guess all the stores are built around a certain system that can be easily manipulated and toyed with. I will find the link and post more if I can...
Posted by Prometheus on Mar. 21 2001,02:51
quote:
Originally posted by L33T_h4x0r_d00d:
Also the music you hear in the store is playing off a monthly Cd thats distributed to the stores with their "WAKE YOUR ASS UP EARLY IN THE MORNING ON A SATURDAY AND WATCH THIS BORING ASS TAPE" that they show at 6:00 in the morning to the employees one saturday a month. Toys R Us on the other hand gets all their shit piped in hot and steamy from marketing via satellite.

... sounds like a fellow employee.


------------------
Necesse est multos timeat quem multi timent.


Posted by CatKnight on Mar. 21 2001,02:54
well duh
Posted by Dark Knight Bob on Mar. 22 2001,21:56
don't know about credit cards but my dad got his bank account emptied and into £50 overdraft from his switch debit card. the guy who was working for a couple weeks down at aa petrol station just down from our house swiped it into some kind of machine when my dad/mum wasnt looking (joint bank account my dad puts money in my mum takes it out ) thus making a clone of it and buggered off to birmingham of all places (i was hoping to bump into the guy when i went up their for jiu jitsu tournament {see other thread},and test out ma skillz on him > )anywayz if you can simply clone them then i'm sure you can do the same with credit cards...if you can find somway of reading off the microchip embeddd on it somehow.

moral: if someguy takes your card to pay for something and goes out back or moves his hand below the desk make sure you call the manager and get his ass busted. and what the hey break his arm too >:]


Powered by Ikonboard 3.1.4 © 2006 Ikonboard