Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 59 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow Credit Card Theft
EH-Net
May 25, 2012, 08:54:56 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Credit Card Theft  (Read 2231 times)
0 Members and 1 Guest are viewing this topic.
MicroJay
Full Member
***
Offline Offline

Posts: 101



View Profile
« on: March 18, 2010, 12:37:03 PM »

Just some food for thought...

Just recently, we had to find specific hard drives to replace a failed hard drive (equipment only ran specific types due to firmware size).  Being that the hard drives are no longer available, only three sites on the Internet stated they carried them.  The one website that we went to was a very interesting site.  Red flags were flying all around my office!  First, the website did not utilize https for transactions.  That should have turned anyone away!  But, my colleague called them up and ordered over the phone thinking that was a safer way to obtain what was needed.  Wonder how the company entered the information?...through the web!  I got an email stating that my order was processed and included is the username and password (another red flag flying around)!  Then another email came through stating welcome and if there are any questions to call (555) 555-1234 or send an email to dummyemail@xyz.com (xyz was actually the name of the emerchant software they were using!).  Even the favorite icon for their site was the same as the emerchant software site!  I immediately had the credit card canceled and a new one reissued.
 
A week later...an email from amazon.com came to my attention.  Your credit card ending in #### was used to open a new account.  We have closed the account.  If this account was closed in error, please contact us to resolve.  Then two days later...another email stating your Amazon order has been canceled!  Obviously someone was using the credit card utilized in the purchase!

Just shows how companies just throw up a store front to get business but lack the knowledge/resources to make it secure for the consumer.

Granted…The colleague should have left that merchant in the dust after knowing they had a high chance of having a vulnerable site.

Live and learn!
Logged

GSEC - GCIH - GSNA
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #1 on: March 18, 2010, 01:26:08 PM »

Was any legal action sought out against the offender?

Makes me wonder how many times the common internet user falls target to this type of buying scam. I could just imagine if a person had enough time on their hands and could mimic a site like amazon / eBay & pull off this same scam.

Today, I get pop-ups sometimes of site's that look extremely legit and they'll want a lot of information when you go to sign up (Like your address, zip, phone, your e-mail address, your alternate e-mail address, your 3rd alternate e-mail address, etc (joking...they only want one)). These sites are so quickly and poorly put up that they don't even utilize ssl (like you said) and some are vulnerable to your typical ' or 1=1-- SQL Auth Bypass Attack.

I'm surprised they actually had a phone number on their site to process the calls, etc - these guys seem to have their plan well thought out. Good read Jay.
Logged

OSCP, OWSP, eCPPT
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #2 on: March 19, 2010, 03:39:02 AM »

good story! quick thinking on the credit card cancellation! definately something to think about...
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.296 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.