09/22/12

Hacking the Credit Card Code

gAtO wAs- surfing around and found this information targeted at future cyber gAtIcOs- These are the basic tricks that the bad guy’s are using to game the system. and they share this basic information to help other stupid wanna-bee bad guys. TRUST but VERIFY – be a critical reader and remember that this comes from bad guy’s always trying to trick you. I checked out most of the LINKS and deleted any ones I though may be bad. Some of this is a bullshit, some stupid  and some is real from what I can tell – enjoy–gATO oUt  

for educational PURPOSES ONLY. – how the Cyber Criminals are using the system for cyber-money laundering. 

Cracking The Credit Card Code

Credit Cards 2 BTC-Bitcoin – BTC-Bitcoin 2 Credit Cards

 

Wasn’t quite sure where to put this, but I decided I’d share some information on the actual code of a credit card.

In reading this you will be able to interpret credit card codes efficiently and actually be able to learn about the card itself. This is all simply by knowing the 16 digits on the front of a card.

The first digit of a card is called the Major Industry Identifier (MII). It designates the category of the entity which issued to card. This is useful in finding what exactly the card is for.

1 and 2 are Airlines,

3 is Travel and Entertainment

4 and 5 are Banking and Financial

6 is Merchandizing and Banking

7 is Petroleum

8 is Telecommunications

9 is a National assignment

The first 6 digits are the Issuer Identification Number (IIN). It will identify the institution that issued the card.

Visa: 4xxxxx

Mastercard: 51xxxx – 55xxxx

Discover: 6011xx, 644xxx, 65xxxx

Amex: 34xxxx, 37xxxx

Cards can be looked up by their IIN. A card that starts with 376211 is a Singapore Airlines Krisflyer American Express Gold Card. 529962 designates a pre-paid Much-Music MasterCard.
The 7th and following digits, excluding the final digit, are the person’s account number. This leaves a trillion possible combinations.

The final digit is the check digit or checksum. It is used to validate the credit card number using the Luhn algorithm

How to use this information to validate a credit card with your brain:

Take the below number (or any credit card number)

4417 1234 5678 9113

Now, double every other digit from the right

(4×2, 1×2, 1×2, 3×2, 5×2, 7×2, 9×2, 1×2)

Add these new digits to the undoubled ones (4, 7, 2, 4, 6, 8, 1, 3)

All double digit numbers are added as a sum of their digits, so 14 becomes 1+4.

8+4+2+7+2+2+6+4+1+0+6+1+4+8+1+8+1+2+3 = 70

If the final sum is divisible by 10, then the credit card number is valid.

If it’s not divisible by 10, the number is invalid or fake.

In this case, 70 is divisible by 10, so the credit card number is indeed valid. This works with every credit card and opens many ideas to the mind.

 

Credit Cards to BTC-Bitcoin

These are methods that have been discussed on HackBB for cashing CCs into bitcoins. Before I continue let me get this out of the way. No you can not cash your CVV directly into bitcoins. Exchangers know the risk involved in accepting reversible credit for non-reversible currency, and the few that have ever accepted direct CC payments were scammed out of business. There are ways around this issue..

CC -> SLL -> BTC

Editors Note:

VirWox wised up to this method and started forcing users to validate their SL avatars..

http://clsvtzwzdgzkjda7.onion/viewtopic.php?f=49&t=1836

Thought I’d tidy this up a bit with a noob-friendly tutorial on how to buy bitcoins with a CVV through VirWox.

What you will need.

  • Valid CVV (any country will do)
  • Clean Socks5 proxy as close as possible to cardholder’s address
  • Good DNS setup

Ok lets get started.

You’ll need an email account. Go create a new one at yahoo/gmail/whatever…..doesn’t matter which (i wouldn’t use tormail for this……too much of a flag).

Go to https://www.virwox.com/, and create a new account using the email you just set up and the name on the CVV. Just make up a fake SL avatar – you don’t need to validate it.

You will then have to confirm your new account by retrieving the temp password from your email.

First thing to do in Virwox is change your password in the “Change Settings” tab on the left.
Now we’re ready to do some carding. Click “deposit” and scroll down to the Skrill(moneybookers) option. Then enter the max amount for the currency of your card (currently $56 for USA cards) and click the moneybookers logo.

If you have NoScript installed you will have to temporarily allow all this page. Enter the details you have for the CVV and make up a fake date of birth if you dont have a genuine one.

If all goes well, you will then be taken back to the main page with your USD/EUR/GBP balance filled.

On the “exchange” menu left of screen choose USD/SLL to convert to Linden $s, then BTC/SLL to convert to bitcoin.

Now withdraw.

Easy Profit.

Note:

  • Typically Virwox hold funds for 48 hours before releasing.
  • You can process payments a total of 3 times with each card…..one transaction every 24hours.

CC -> Moneygram -> BTC

If you have fulls (ssn, dob, etc) you can try cashing out through moneygram. To do this just go to site and sign up for an account under the cardholders name. Be sure to chain a regional socks5 with your Tor connection so you appear to be from the same country that the cardholder is in [4]. Select Same Day service. It will prompt you for the card details, dob, and the last 4 digits of the ssn. I would suggest running this name through a background check (any background search site will do) in case you have to answer a security question to send the funds over. Don’t try to send over too much. If you accidentally go over the limit or try to send a suspicious amount you risk flagging the account. No more than $300 from each CC. If everything goes smoothly you can try exchanging through https://wm-center.com for bitcoins. You can find more information on WM-Center here: https://en.bitcoin.it/wiki/WM-Center

CC -> Forex -> BTC

The process is actually really simple. I was surprised to find the site. Kinda found it by accident actually.

Site: http://www.rationalfx.com

Using a foreign currency exchange site to change money on a credit card into a foreign currency and to wire transfer the money into a bank account.

In this case, the bank account is at https://mtgox.com

The process goes as follows:

  • Make an email account anywhere.
  • Make an account at MtGox.
  • Make an account at rationalfx.com. (all account info in the name of the cc holder).
  • In rationalfx, add account details, addy, card number, MtGox wire info.
  • Make a transfer.

Process takes 3-5 business days… It turns a cc transaction into a wire transfer so it takes a couple days… (Note: in the interest of speed and not getting the transaction reversed, Monday/Tuesday is the best day to start the transaction)

Once the money is in MtGox, turn it into bitcoins as quickly as possible and move it into your other bit wallets. Wash the coins if necessary…

Easy huh?

Already pulled it off once. 400GBP through a MC without any issues. rationalfx does not seem to have any real safeguards in place. Tor works fine there (though it is best to use an exit node wherever your card holder lives).

When I was testing it first with a visa, it told me 3 times in a row that the transfer failed. I lowered the amount each time and tried again. After the 3rd time it went through but I didn’t have the Verified by Visa password so I couldn’t continue. BOTH Visa AND MC , it seems, will pop up with a verification thingy if its enabled on the card. (Usually US/UK cards)

Make sure when you deposit to MtGox, you include the account identification info for that spacific account. You can find it on the ‘funding options’ -> ‘Bank wire’ page… If you forget that info you wont get your money..
So there you have it. Its simple as pie.. This is not 100% of the info but ya’ll can figure out the rest..

I know ya’ll prolly wont but if you are feeling generous…

Hope you enjoy..

Cashing Methods

This is a collection of cashing techniques that have been discussed on HackBB. Keep in mind before you get started you will need to know how to chain a socks5 with Tor to avoid tripping a fraud filter [1].

Easy PP/CVV cashout

I will preface this by admitting that I may have something to gain since I sell the tools needed to make this work. My mind played connect the dots when reading the forum and checking my messages, and I realized it’s easy to cash out with a little investment and work ahead of time.

I can’t guarantee this will work, I never tried it. But I do understand the systems involved so I’m as confidant as I can be.

Everybody wants to know how to cash out. Well, that is easy, the hard part is getting away with it. Any fuckin moron can rob a bank, but it takes a genius to do it time and time again while leaving the investigators in a state of mental confusion akin to drinking mercury and pithing their brains with an icepick.

This is not a step-by-step. Google is your friend (unless you’re signed in). I don’t hold hands, if you can’t figure it out on your own from here, it’s not in your scope.

Ingredients:

  • EU paypal account
  • Fresh email.
  • Anon debit card
  • CVV’s
  • Balls

Ok, Open an EU paypal account from one of the countries below. You can use fakenamegenerator.com or whatever you want. Just make sure is is a merchant and not personal. There are 3 levels, go with the middle. Get an Anonymous debit card, and link it to the paypal, using the CC and not the bank. I know for sure that the bank wont work for US accounts, as it is a deposit only bank account number. Depending on the country and the country’s banking regs, paypal may or may not try to take back the verification amount they sent. Forget that.

Once the paypal and debit card are connected successfully, it is time to get your free money. I don’t know what language you are using in the EU paypal, but it goes something like this: Merchant tools–>Generate Paypal button. Alternatively, you can google “paypal but it now button” in quotes. Figure it out.

I hope to god you got a CVV by now, because that’s whats next. Using the code you got for the BIN button, go to http://htmlpreview.richiebrownlee.com/ Paste the code, click the button, and now you are at a paypal purchase page. Depending on where you are, and I haven’t figured this out yet, you may have an option to pay with CC. It used to be that with USA, you could pay with CC but not sign up. So make sure you have a USA CC. If you registered a simple personal account, paypal will ask buyers to sign up first, and you might as well stop there.

If you see the option to either sign up or pay with CC, you are GOLD.

The amount will be immediately available on the paypal you created. Now, just withdraw funds to the debit card. 3-5 days, it will be there. Go shopping. See the girl with the big titties? Buy her a drink. You win.

I cannot account for moneybookers, as I’ve never used it, but I imagine it would work the same way. To test with moneybookers, I suggest linking to a greendot card with a throw away account, since you need to verify SSN. That can be your legit moneybookers anyway.

Here is a list of countries that SUPPOSEDLY don’t need a VBA, only a CC:

Bulgaria

Chile

Cyprus

Estonia

Gibraltar

Iceland

Indonesia

Latvia

Liechtenstein

Lithuania

Italy

Israel

Liechtenstein

Luxembourg

Malaysia

Malta

Philippines

Poland

Romania

San Marino

Slovakia

Slovenia

Turkey

UAE

Uruguay

 

I’ll share with you a cashout method

I’ve been using square on my android to cash out cards… All I did was register with jingit com and apply for their visa debit card… I do it this was cause I just watch some ads until I make $2.00 which is the fee for the card… once the card arrives you’ll get an account # and routing # as if it were a checkings account. (when you apply for the jingit card make sure you match FB’s DOB with jingit card on the application form)

now you register on squareup com and link it to the debit card acc. to verify the initial deposit they make don’t wait til you get the statement, call the # on the back of the card and you can get your transaction history over the phone. (I forgot you have to activate the card over the phone. this is why you need the SSN and DOB)

I only do this over open wifi and my android is not activated with any company. Also you must have location services enabled so don’t do it close to your home.

you don’t need the reader, you can charge cards manually entering the card info. you need at least the billing zipcode. transactions under $25 don’t require signature and you can skip the receipt.

I always get another prepaid card to swipe it when I use a new acc for the first time, I never start using an acc entering numbers manually… it’ll raise flags. don’t use your own card linked to your bank… that would be stupid

Beating the Online Casinos/Bookies (uk)
What you need

  • 2 machines, or an accomplice to play your dummy account.
  • UK non-3DS CVV
  • 50 GBP cash
  • Access to a William Hill shop

Create 1st account

Setup VM on system 1. I’m not going in to any great detail on how to do this as it’s covered elsewhere on the board. Use something like: Tor -> VM -> [UK]VPN / VPN1 -> VM -> [UK]VPN2.

Download the software and setup an account using either your genuine details, or some fictitious details from the local area of the shop you will be using. The deposit option you are interested in is “Quick Cash”

Off you go to a local William Hill shop to buy your Quick Cash voucher (say 50 GBP for this example). The shop prints 2 vouchers. One they keep which you will have to sign (in your fake name if you’ve used one), the other is given to you and contains the transaction code to enable you to deposit online.

Now either contact your accomplice who will play the other account or:

Create 2nd Account

Setup VM on system 2.

Download the software same as for Account 1, and this time setup the account using the details from your CVV. Deposit using CVV (eg 400 GBP).

Dumping Chips

Again, i’m not going into any great detail on this….if you don’t know how to play poker, then learn…fast. Become familiar with which hands tend to generate the largest pots (eg AA vs KK). 6-handed tables are a good choice (0.50/1 for these amounts).

Over the course of 1-2 hours, pass chips from Account 2 -> Account1, randomly losing some chips to the other players at the table. A reasonable target is for Account 1 to be +300.

Cashing out

Ok, you’re happy with your 300 profit. Click withdraw in the cashier, again choosing the “Quick Cash” option. Print off the voucher, then return to the shop where you were earlier in the day. Present the voucher, sign your name again to verify and walk out the shop 300 GBP richer for a few hours work.

Note: It’s probably not a great idea to use fictitious details if you use a shop in your own local area. No ID should be required for amount <500 GBP. If you’ve dumped chips with enough care, it’s almost impossible to prove you were involved in any fraudulent activity. You’ll have cash in your hand before anyone realizes any fraud has taken place, so no chance of freezing accounts.

Carding Online

Editors Note:

I edited out the “ATTAINING HIGHER LEVELS OF ANONYMITY” section due to it being

obviously wrong and changed the CC check link. Don’t add it in.

LEGAL TIDBITS

This FAQ is intended for educational PURPOSES ONLY.

THE BIG QUESTION: WHAT IS CARDING?

- Well, defined loosely, carding is the art of credit card manipulation to access goods or services by way of fraud. But dont let the “politically correct” definition of carding stop fool you, because carding is more than that. Much more.

Although different people card for different reasons, the motive is usually tied to money. Yea, handling a $9,000 plasma television in your hands and knowing that you didnt pay one red cent for it is definitely a rush.

But other factors contribute to your personal reason for carding. Many carders in the scene come from poor countries, such as Argentina, Pakistan, and Lebanon where $50 could mean a weeks pay, on a good day. Real carders (the one that have been in the scene the longest) seem to card for something more, however. The thrill of cc manipulation? The rush that the federalles could bust down your door at any minute? The defiance of knowing that everyday that you are walking among the public is another day that you have gotten away with a federal crime?

Whatever your persona reason for carding is, this tutorial should answer a few noobie questions and take the guessing out of the entire carding game. The resources and techniques mentioned in this tutorial are NOT, I repeat, NOT the only methods of carding. Experience in carding is key. You have to practice your own methods and try out new techniques in carding to really get a system that works for you. This tutorial is meant to get you on your way.

THE BASICS: WHAT DO I NEED AND WHERE DO I GET IT?

Credit Cards: Yes, CCZ.

“do you have any ccz” “where can I hack CCZ” “where can I get a list of valid CCZ?”

You need money to make money. Plain and simple. Which means that the only way your gonna be able to get ccs if you have ABSOLUTELY NO MONEY is if you successfully rip a noobie with 100 cards (but what noobie has 100 cards?), if you have any background in database hacking, if you trade for your shit, or if you know someone that’s willing to give you ccz all day.

I know thats a discouraging statement to all of you, but we have to keep shit realistic. The easiest way to get ccz is to purchase them.

“but I can’t get a job/I don’t wanna work!”

Having a regular 9 to 5 job is not a bad idea in the carding scene. Not only will you have some sort of alliby to why you have all this expensive shit in your house, but you can also use the money (who cant nowadays) to pay bills. You cant card forever, and you cant sustain yourself by carding alone.

If you are REALLY strapped for cash, you have to go through the alternative: trade for your resources. you have to be resourceful in carding, meaning you have to use what you got. Got a psybnc admin account? Offer psybnc user for a cc or two. Got shells? roots? Can you make verification phone calls? just ask yourself “what do I have that might be valuable to someone else?” and work with that. It dosnt have to be big, it just has to get you a few cc’s in your palms.

Once you’ve run your first successful cc scam, DONT SPEND ALL YOUR EARNINGS. Save $200 and re-invest back into the carding community. head to SC and get better cards. If you have level 2 cards, I suggest carding C2it/Paypal and using that $$ to buy ccs. (successful C2it/PP scamming techniques will not be discussed in this tut, sorry)

To other minor pointers on rippers and legit sellers, please scroll down to “SELLERS, TRADERS, AND RIPPERS, OH MY!”

“where can I check my CCZ?”

Knowing wether your cc is valid or not is really important for saving some time and energy. you can check them under http://www.soundcloud.com

The idea way for checking ccz is through an online merchant (authorize.net, linkpintcentral.) These merchants can verify cc amounts without charging your ccs. Good luck finding one. People on IRC want a ridiculous trade for These merchants (cvv lists, cash). So if you run accrosss a legit merc, dont give it out! even to your best buds! online mercs are gold in the world of carding.

Other methods for verifying cc amounts include registering your cc on an online bank. (You will need at least a level 2 card, level 3 for ATM cards). alot of online banks can give you limit, billing addy, ect ect but they require at least a level 2 cc (more info on ccz below)

CREDIT CARD FRAUD: INFORMATION IS KEY.

I want to make something clear right now. The secret to carding is not the number of cards you own, its what you can do with the cards. What do I mean by that? Simple.

Hypotherical situation: My name is Johnny and I have 3 ccs with SSN, DOB, CVV NUMBER, MMN, NAME, STREET ADDRESS, CITY, ZIP, AND BILLING TELEPHONE NUMBER. I have a friend named Billy. Billy has 300 CCCZ with CVV, MMN, NAME, STREET ADDRESS, CITY, ZIP, AND BILLING TEL. NUMBER. Whos more likely to successfully card something?

Simply put, I (Johnny) am. Why? Because I have more information that can prove that I am the person who owns this CC than Billy does with his 300 CCVZ. Does that mean Billy’s not gonna card anything? No, that just means Billy’s gonna have a hard time carding anything without verification.

So to sum up this lesson, you have to get information on your mark (the person that youre impersonating.) #1 rule in carding is: the more information you have on a person, the better chances you have for a successful transaction. Here is the information you’re looking for(note: the levels of a card is not a tehcnical carding term, I’ just used L1 L2 L3 to simplify shit throughout the tutorial.) :

NAME: ADDRESS: CITY: STATE: ZIP CODE: TEL. BILLING NUMBER: CARD NUMBER: CARD EXP DATE: CVV CODE:

(LEVEL 1: REGULAR CVV. If you have this much info, youve got yourself a regular cc. Nowadays you need this much info for carding ANYTHING worth mentioning. If you have any less than this information, you’re shit outta luck. :\)

Social Security Number (SSN): Date Of Birth (DOB): Mothers Maiden Name (MMN):

(LEVEL 2: (PARTIAL FULL-INFO) If you have this much info, your ccz are on another level. With this info, you should be able to card PayPal, C2IT, and other sites without too much of a hassle.)

BANK ACCOUNT NUMBER: ROUTING NUMBER: BANK NAME: BANK NUMBER: DRIVERS LICENSE NUMBER: PIN NUMBER (For CC or ATM card)

(LEVEL 3: (true full-info) If you have this info, youre cc is ready to card anything your heart desires)

Now if all you have is a regular cc, dont discourage. Just do some research and build your cards as much as possible:

First, go to whitepages.com and try to lookup your marks street address and phone number. Make sure it matches the info you have on your cc..

Last, but not least, take a quick look in ancestry.com. Ancestry.com is a bit of a pain, but you can lookup DOB and MMN (ie, if your marks name is anthony hawkins, his father is david hawkins and his mothers name is bella donna, Donna is the MMN)

So size up your cards and move on to the next lesson:

DROPS AND VERIFICATION TECHNIQUES:

The right drop is essential to your scamming needs. Finding legitamite drops inside and outside of the US is hard. Many people keep your shit and don’t send, or some people dont pick up the package at all! (theres nothing worse than watching your hard-earned laptop going back to the store because it was refused by the recepient)

If you live inside (or even outside) the USA, you’re better off scoping a drop out on your own. A drop is basically an empty home that looks to be inhabited. This is the shipping address you use for your carding needs. Your items should only picked up at night. As awlays, be sure to have a cover-story in case someone asks why youre snooping around an empty home. “I’m picking up a package for the person that used to live here” is a legit excuse. Or even “my father is the real-estate agent.” is good. Just keep in mind that if you order anything over $500, it will USUALLY need to be signed for, (this statement is based upon FEDEX/UPS policies. I’ve gotten feedback from people that state they have gotten their local UPS employee to drop merchandise worth 1k at thir doorstop using a note, but these are uncomfirmed rumours.) Wether youre willing to sit and wait all day on the doorsteps of your drop, or you rather leave the postman a note that says you’ll pick it up at the nearest postal station, its up to you. (Dont panic if you have to pick up a package at the station. When you walk in, you need to be calm so it dosent arise suspicion. If the clerk asks you to wait more than 3 minutes, PLEASE dont stand there waiting to get busted, tell him/her you have a prior engagement and quickly exit stage left. )

If you live outside the USA, youre just gonna have to trust someone. The easiest way to get a legit drop in the USA is to ask around for people that have had successful experiences with a drop. Most drops hold a 50/50 or “you card something you card me sommething” policy. If you’re talking so someone thats trying to cut themselves in to the deal “Ie yes, I know someone but you have to card me something too” just move on, they’re wasting your time.

Just a quick note, if you’re carding something like a plasma television, you’ll have better luck using a drop from the same state, changing the billing addy (you can change a billing addy with a level 2 card, youll need a L2 card for carding a plasma tv neways) and acting like you just moved. (have that mindset when you call in: I am (name of cardholder) and I just moved from (city a) to (city b)) Once you have the item in your possession, you SHOULD GUESS THAT YOUR DROP HAS BEEN FLAGGED. What does this mean? YOU SHOULD NOT – I REPEAT SHOULD NOT RETURN TO A DROP ONCE YOU’VE CARDED EXPENSIVE SHIT TO IT. Regardless of wether your drop is flagged or not, do you really want to take the chances?

The cellular phone: The anonymous cell phone is the carders sword. With it, you will make several calls to several companies using several names. You should keep this cellular phone for carding ONLY. (just in case you become confused and forget who youre talking to.) If you have a phone phreaking connection, youre a lucky SOB. For the rest of us, we gotta go out and get a pre-paid cellular phone. (a phone which dosent require much info to purchase and use.)

THE SITES: WHATS CARDABLE AND WHATS NOT?

Ok, so you got your ccs, your drop and youre as anonymous as you can make yourself. Now what sites are cardable? This is the easiest question I have to answer on this FAQ.

-ANY AND ALL SITES ARE CARDABLE- (THX CIA AND `Q_)

Why do I say that? because it’s true. Like I said in chapter two of this little tutorial, its not about how many cards you have, its what you can do with them. Alot of this has to do with your mindset as well.

If you have a card from Johnny Knoxville from Texas, you must be Johnny Knoxville from texas. Depending on the information that you have acquired from Johnny Knoxvile, you must convince merchants and I-stores that you A R E Johnny Knoxville.

When approaching these I-stores, you want to scope things out first. Ask yourself a few questions:

-whats their policy on different shipping address than billing addess?

If they have a “must call” policy, make sure to give them an anonymous number where you can be reached (have your anon cell phone ready for this.)

-do they accept other payments besides credit?

If they accept other payment methods, sometimes its easier to card with a different payment method. (Ive had more luck on Dell.com with online checks that I have with credit cards.)

Whatever you card, make sure that you have all your info prepped before carding it. If youre carding something over 1k, get on your anonymous celly and call up the banking institution of the person’s card youre holding. Make sure to let them know that youre making a purchase of a large limit, so they dont deny your card.

Know Thy Enemy: What the CC Payment Gateways Check for Fraud

These are the measures taken by CardPay which is a payment gateway to rate fraud. It wouldn’t be really hard to imagine that other gateways take the same measures. Although we all know the rules of thumbs, I thought it would be interesting to see what they *actually* measure to evaluate high risk of fraud. The amount of information that they actually collect is mind blowing.

Fraud Screening system of CardPay Inc. Payment gateway performs comprehensive analysis of transaction data, using several techniques simultaneously. Data from external systems used during screening process, also as internal transactions history and various lists.

Transaction passes through so called “pipeline”, consisting of following steps:

  • Rules system
  • Card and cardholder’s data analysis using automated fraud screening service
  • Multivariate regression analysis of in-house transactions database.
  • The above mentioned subsystems are described in more details in the following section.

Rules system: Fraud rules logic implemented in stored procedures by Oracle DBMS, which enables adding and modifying rules without service downtime. Before passing order through rules chain, additional information retrieved from MaxMind credit card fraud prevention service. MaxMind returns to gateway following data:

  • Cardholder located in high-risk country. At a moment following countries recognized as high risk: Egypt, Ghana, Indonesia, Lebanon, Macedonia, Morocco, Nigeria, Pakistan, Romania, Serbia and Montenegro, Ukraine, or Vietnam.
  • Whether country of IP address matches billing address country (mismatch = higher risk)
  • Country Code of the IP address
  • Distance from IP address to Billing Location in kilometers (large distance = higher risk)
  • Estimated State/Region of the IP address
  • Estimated City of the IP address
  • Estimated Latitude of the IP address
  • Estimated Longitude of the IP address
  • ISP of the IP address
  • Organization of the IP address
  • Whether IP address is behind an anonymous proxy(anonymous proxy = very high risk)
  • Likelihood of IP Address being an open proxy(transparent)
  • Whether e-mail is from free e-mail provider
  • Whether e-mail is in database of high risk e-mails
  • Whether usernameMD5 input is in database of high risk usernames.
  • Whether passwordMD5 input is in database of high risk passwords.
  • Whether country of issuing bank based on BIN number matches billing address country
  • Country Code of the bank which issued the credit card based on BIN number
  • Whether name of issuing bank matches entered BIN name. A return value of Yes provides a positive indication that cardholder is in possession of credit card
  • Name of the bank which issued the credit card based on BIN number
  • Whether customer service phone number matches BIN phone. A return value of Yes provides a positive indication that cardholder is in possession of credit card.
  • Customer service phone number listed on back of credit card.
  • Whether the customer phone number is in the billing zip code.
  • Whether shipping address is in database of known mail drops.
  • Whether billing city and state match ZIP code.
  • Whether shipping city and state match ZIP code.

After gathering of all data, rules in chain applies to order data sequentially, increasing or decreasing total fraud score.

Rules chain consists of following rules:

  • Cardholder country rating(global list)
  • Cardholder country rating(as set up by merchant)
  • Cardholders IP found in black lists
  • Cardholders IP range found in black list
  • Cardholders email found in merchants black list
  • Cardholders email found in global black list
  • Cardholders email found in forbidden email providers list
  • Card PAN doesnt present in global black list
  • Card PAN doesnt present in merchants black list
  • Cardholders address not in global black list
  • Cardholders address not in merchants black list
  • Order amount doesnt exceeds global purchase limit
  • Order amount doesnt exceeds local(merchant) purchase limit
  • Single PAN daily turnover doesnt exceeds global daily limit
  • Single PAN daily turnover doesnt exceeds local(merchant) daily limit
  • Billing address daily turnover doesnt exceeds global daily limit
  • Billing address daily turnover doesnt exceeds local(merchant) daily limit
  • PAN number brute force check
  • Expiry date brute force check
  • CVV brute force check

This is base rules set. Our fraud officer constantly monitors transaction flow and modifies existing rules and implements new ones to gain maximum fraud prevention efficiency.

Transaction history analysis(in-house service): After successful rules checking, transaction data verified against pool of existing transactions, enabling most accurate results and fraud decisions possible. If this routine detects no reasons to block further processing.

Transaction history analysis(external service): If in-house transaction history doesn’t shows signs of fraud, external database enters into business.

Online Verification Procedures
Over the years, I’ve come across dozens of procedure lists for top-tier merchants regarding online transations and fraud reduction. I’ll detail several companies verification procedures below.

While most virtual carders are aware of the various procedures in place to verify orders placed online, few actually understand the implementation of fraud scoring, and the order in which these verification methods are used.
The Risk Management Toolkit

  • AVS
  • CVV
  • IP/GEO/BIN
  • Cardholder Authentication (VbV/MSC)
  • Phone Verifications
  • Manual Order Reviews
  • Chargebacks & Representments
  • PCI Compliance & Data Security

 

AVS – Address Verification Service

How It Works

  • Provides a Match or Non-Match Result for only the Billing Street # and Billing Zip Code… not the actual address. (i.e. “1234 Test Street” is parsed into “1234” just the same as “1234 Wrong Way” would be).

Implementation

  • Available on any Internet merchant account and virtually any Payment Gateway.
  • Most gateways provide an AVS configuration area where you can specify whether you want to automatically“decline” (i.e. do not settle) an authorization that has an AVS mis-match or non-match.

Benefits

  • Easy to implement Limitations
  • Works only for U.S., CND, U.K. cardholders so this does not help you scrub most international transactions.
  • A growing % of compromised credit cards – especially those obtained through inside jobs or hacked databases– will also contain the necessary information to provide a valid AVS match result.

Recommendation

  • If you handle a mix of int’l and U.S. sales, you will want consider scrubbing with AVS on the U.S. transactions but do NOT scrub via AVS for any international transactions as they will always fail. AVS should not beconsidered a primary means of verifying the validity of a transaction. Nearly 20% of the fraud can potentially be eliminated by scrubbing “Non-Matched” AVS match results.

CVV – Card Verification Value

How It Works

  • A service with many names – CVV2, CVC2, CID – but the premise is the same for all.
  • Provides a Match or Non-Match Result for the 3-digit or 4-digit number embossed on the back of the cardholder’s card. The CVV is NOT generally encoded on the magnetic stripe and therefore is less likely to be captured as part of a card skimming tactic.

Implementation

  • Available on any Internet merchant account and virtually any Payment Gateway.
  • Most gateways provide an CVV configuration area where you can specify whether you want to automatically “decline” (i.e. do notsettle) an authorization that has an CVV non-match or non-entry.

Benefits

  • Works for virtually ALL cardholder accounts – both U.S. and international.
  • There is no valid reason why a legitimate cardholder, in possession of the card, would not be able to enter a 100% matching numberfor this.
  • Merchants are not allowed to store CVV and as such the CVV # is less vulnerable than the data used for AVS.

Limitations

  • CVV data can only be used for a real-time transaction. CVV data can not be stored and therefore can not be utilized for Recurring Transactions.

Recommendation

  • CVV is a recommended service to utilize for ALL initial transactions processed. Based on our internal charge-back analysis, merchants can reduce their fraud ratesby as much as 70% by simply requiring a matching CVV result.

IP/GEO/BIN Scrubbing

How It Works

  • Compares the IP address of the customer purchasing with their stated geographic location (i.e. why is the customer from California ordering from Europe?)
  • Compares the BIN # (first 6 digits) of the credit card with the IP or stated geographic location of the customer (i.e. the customer isusing an US-issued credit card but they are from Europe?)
  • Based on the IP and BIN # and other customer-inputted data, a vast amount of information can be returned on the transaction.

Implementation

  • Custom direct integration into a service such as MaxMind.com
  • Use an existing integration that is part of a Shopping Cart such as X-Cart, LiteCommerce, osCommerce, ZenCart,ASPDotNetStorefront.
  • Use an existing integration that is part of a Billing System such as WHMCompleteSolution, ClientExec or Ubersmith.

•Use an existing integration that is part of a Payment Gateway such as the Quantum Payment Gateway.

Benefits

  • Fast, Cost Effective and Non-Intrusive
  • Provides merchants with an excellent “do the pieces fit consistently?” analysis.
  • Can block up to 89% of all fraud if properly implemented

Limitations

  • Generally not reliable for AOL users due to the way that AOL routes its traffic (AOL users require a merchant-specific approach)
  • Proxy database is always in a real-time process of being updated as new proxies open up.

Recommendation

  • IP/GEO/BIN fraud scores should be used in the order evaluation process more as a means of flagging transactions as “high risk” formore intensive scrubbing vs. being an outright decline.

Examples of what IP Geo-Location can tell you:

YELLOW ALERTS

  • Free E-mail Address: is the user ordering from a free e-mail address?
  • Customer Phone #: does the customer phone # match the user’s billing location? (Only for U.S.)
  • BIN Country Match: does the BIN # from the card match the country the user states they are in?
  • BIN Issuing Bank Name: does the user’s inputted name for the bank match the database for that BIN?
  • BIN Phone Match: does the customer service phone # given by the user match the database for that BIN?

RED ALERTS

  • Country Match: does the country that the user is ordering from match where they state they are ordering from?
  • High Risk Country: is the user ordering from one of the designated high risk countries?
  • Anonymous Proxy & Proxy Score: what is the likelihood that the user is utilizing an anonymous proxy?
  • Carder E-mail: is the user ordering from an e-mail address that has been used for fraudulent orders?
  • High Risk Username/Passwords: is the user utilizing a username or password used previously for fraud?
  • Ship Forwarding Address: is the user specifying a known drop shipping address

IP/GEO/BIN Scrubbing (Continued)

Open/Anonymous Proxies: an open proxy is often a compromised “zombie” computer running a proxy service that was installed by a computer virus or hacker. The computer is then used to commit credit card fraud or other illegal activity. In some circumstances, an open proxy may be a legitimate anonymizing service that is simply recycling its IP addresses. Detecting anonymous proxies is always an on going battle as new ones pop up and may remain undetected for some time.

26% of orders placed with from open proxies on the MaxMind min Fraud service ended up being fraudulent. Extra verification steps are strongly recommended for any transaction originating from anopen/anonymous proxy.

High-Risk Countries: these are countries that have a disproportionate amount of fraudulent orders, specificallyEgypt, Ghana, Indonesia, Lebanon, Macedonia, Morocco,Nigeria, Pakistan, Romania, Serbia and Montenegro, Ukraine and Vietnam. 32% of orders placed through the MaxMind min Fraud service from high-risk countries were fraudulent. Extra verification steps should be required for any transaction originating from a high risk country.

Country Mismatch: this takes place when the IP geolocation country of the customer does not match their billing country. 21% of orders placed with a country mismatch on the MaxMind m******* service ended up being fraudulent. Extra verification steps are recommended for any transaction with a country mismatch.

Results that speak for themselves:

ChangeIP – is a DNS and domain name registration provider. The company provides free and custom Dynamic DNS services to more than 50,000 users. Before implementing MaxMind, ChangeIP was losing as much as $1,000 per month because it sold instantly delivered digital goods and could not recover the losses if the purchase turned out to be fraudulent. After implementing MaxMind, losses were reduced by 90%.

MeccaHosting – is a Web hosting company based in Colorado. Since integrating MaxMind, Mecca Hosting has not received a single chargeback. On average, 12-15 fraudulent orders pass through the in-house checks each month but are flagged by MaxMind. Over the last 5 months, this has saved MeccaHosting atleast 60 chargebacks and $6,000 in unnecessary costs.

Red Fox UK – is a Web hosting provider and software development company based in the UK which offers solutions for smalland medium sized businesses all over the world. By using MaxMind, Red Fox UK was able to increase its revenue by 4% while reducing its chargebacks by 90%.

365 Inc. – is a digital media and e-tailer specializing in soccer & rugby with a large international customer base that processes over 10,000 transactions per month. By integrating MaxMind, chargebacks were reduced byover 96% from more than $10,000 per month to less than $500 per month. At this point, most charge backs are general order disputes as opposed to fraud.

Whew. A lot of editing. I’ll post the remainder in a bit.

 

Share on TumblrSubmit to StumbleUponhttp://uscyberlabs.com/blog/wp-content/uploads/2012/09/bitcoin_visa.jpgDigg ThisSubmit to reddit
08/28/12

Black Market in Tor Growing

gAtO been down sIcK so I had to slow down so I’ve been reading underground looking around and the .onion network is beginning to take shape as more users explore it. Let’s just say it’s growing. In the Black Market things are looking up per say, more newbies and more scams with money mules, shipping mules, bot’s rentals and creation and trade. Here are two different crime recruitment points one the physical/ one code / and they are taking advantage of the economics of the situation.

People are losing their homes and eviction is coming “well I can do this for these guys online and I can make a little money and pay a few bills buy some food”. Grooming these new cyber shipping mules is a full time job, but they select and groom some for more and more /—then hit’s them with money mules transactions and they’re hooked. Greed / Pay the rent/ Now these guy know that as the money mule get’s more and more orders right the amount will go up and when they will bail with the criminals money is anyones guess, but by this time they have funneled so much money or goods thru these mules that they are throw away at the end of the life cycle of use. You also have the new code warriors watching and trading in botware working in Tor. Why because it works -/ and other have seen the .onion network as a new area were if they keep quite nobody can find them. If you keep quite nobody will know what your doing and that’s why Tor is working for the bad guys – Why can’t it work for the good guy’s when are we going to start using the best technology for the best job and leave all this other politics alone.

Cyber crime is working in the .onion but when will the law catch up, never I guess 2 many lost opportunities when they treat everyone like shit, just like the ugNazi CC bust- do they have a clue how many other CC sites are out there working in Tor and/or the surface web… . Silk road is all the rage while Black Market Reload sells explosives and drugs but come on the school boys in Cornell and other places are putting their finger into Tor to defeat Tor-attack the Tor Network Yeah – Yeah- “What If- What If -does not work in Tor students”, as they go for Silk Road the hundred of other places were real commercial cyber crooks get away with everything they can is working hard for the money boy’s and girls…. One service takes stolen credit cards to buy goods and directly ship products to the Ebay customer who purchase it and they pay them clean money while their new iPad was purchased with a stolen CC. It’s just these newbies in Tor think they are hip and cool in the surface but in the Tor network the good old boy’s that were there in the beginning are watching with a grim silly smile, knowing but not telling… gATO oUT 

Share on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
07/25/12

Profiling a Corporation -metadata attack vector

gAtO sEe - that in todays world getting a corporate profile for an attack plan has become easy thanks due to their own fault. This leads down the road to ruin corporate reputation, stolen IP-Intellectual property, competitive advantage and loss of data. Of course for social activist, criminals, competitor and national governments who use the technology against them to make available unhidden access to your networks. How? 

Metadata Information leaks by the corporation and their employees. According to retrieve information and the metadata in company documents 71% of Forbes 2000 companies may be using vulnerable and out of date version of Microsoft Office and Adobe software that allows hackers to Identify —>

Usernames – emails addresses network details and vulnerable software versions to implement a Advance Persistant Threat (APT).

Metadata in documents that your company distributes constitute information leaks and it can provide all kinds of information to any attacker. The high tech sector publishes more documents across websites than any other industry. Something else your employee on LinkedIn give all kinds of information about your company and your plans, even employment adds can help a potential hacker know what you are doing and maybe design the APT geared towards that subject.

Remember todays cyber attacker have support from lot’s of eye’s and ears, like hacktivist they have many people that can scan your website and look for information that can help the attack. You have 3 different attack vectors to worry about today:

  • IP based attacks
  • Web-Software attacks
  • Information Attacks

Corporate American take care of your metadata or it will bite you hard -gAtO oUt

Share on TumblrSubmit to StumbleUponhttp://uscyberlabs.com/blog/wp-content/uploads/2012/07/a_leaking-Data.tiffDigg ThisSubmit to reddit
07/11/12

CyberPeace -not- CyberWar

gAtO sEe - In the last couple of days Gen. Keith Alexander has been pushing the Cyber War agenda. -The issues around warfare are very different in cyberspace than in the physical world, and the United States is looking into “alternative strategies,” said Alexander, while not offering further details. In another place he was telling us that the CIA will not use the new cyber laws to spy on our email. Ok so you gonna be a sheep and follow the word of the government. We won’t spy on you.

Alexander said “civil liberties and privacy can work harmoniously with cybersecurity”. Come on General your a nice guy, gAtO met you —/ you have a passion but every time you bring out —/ Oops there went the Power Grid, Oops.. there went the financial sector, scare me, scare me. I know it’s your job to secure our country to protect our nation cyber infrastructure. Don’t trample on our cyber right any more please.

Hay here is a solution for you use a Tor-.onion network-(any anonymized network) to tie your power grid, and/or your financial services. If you can’t close down Silk Road in onion-land your C&C for your power grid and financial services should be invisible to everyone except on a need to know. gAtO just save you 14 trillion in R&D…//

gAtO has not heard one word about Cyber Peace from any responsible government in the world. Everyone is looking for their own cyber posture, their own cyber weapons/ budget/ programs/ money// , but not one has said let’s work together to make it better for peace, guess there is no money in Cyber Peace. Espionage, spying is the job of governments why would they destroy their own tools, weapons and just tweak our cyber-rights a wee bit, for our cyber freedoms and safety, to protect our government and you -lol.

Here is a simple idea crowd-source our problems. The one major resource in cyber-space is number of people that can see the same message. In crowd-source we can give the facts and ask anyone to help solve city budgets, ways to harvest more vegetable/per vertical/ sq.ft. Ask people how would you protect our electric grid // you be surprised by the creative answers you get, OK some may be crazy but…//. It may not be the right solution, but the power of the minds of people collaborating is what this new technology is built for. FaceBook is about ME- Twitter is about the rest of the world- but the new winner is —/ Comments /— have become more important than the article-subject itself because the conversation within in the comments shows social communication and problem solving by the masses.

Let’s change the message to CyberPeace, everyone has a solution, but remember that all your comments are the new gold so watch what you say to that troll on huffpost— gAtO oUt

 

Read more: Alexander: U.S. looking for offensive alternatives in cyberspace – FierceGovernmentIT http://www.fiercegovernmentit.com/story/alexander-us-looking-offensive-alternatives-cyberspace/2012-07-11#ixzz20KW1Lcf2

Share on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
07/5/12

The Deep Dark Web -Book

gAtO sAy -mEoW you all- we have a new book coming out soon “The Deep Dark Web” and just wanted to write this as the foreword for the book, I thought it was interesting …//looking for peer review of book…write us

This book is to inform you about “The Deep Dark Web”. We hear that it’s a bad place full of crooks and hackers, but it is more a place were you have total anonymity as an online-user and yes there are ugly places in the dark web but it’s a small part of it. What it really is all about it’s freedom of expression, freedom of speech worldwide, supported by “us/we” the users of the network. It’s not controlled by any government, but blocked by a few like Syria, Iran, Ethiopia, China to name a few governments that want to deny their own people free access to information, to speak freely about their grievances and unite to tear down there walls of oppression.

Pierluigi and I (gAtO) share a passion for cyber security we write different blogs Pierluigi has http://securityaffairs.co/wordpress/ and my site is uscyberlabs.com . We also write at other blogs and print media. We did’nt know it at the time but, we were writing cyber history as the 2011- 2012 cyber explosion took off we were at ground zero writing about Stuxnet, HBGrays, the LulzPirates, Anonymous but the Arab Spring was an awaking :

The recent revolution in Egypt that ended the autocratic presidency of Hosni Mubarak was a modern example of successful nonviolent resistance. Social Media technologies provided a useful tool for the young activist to orchestrate this revolution. However the repressive Mubarak regime prosecuted many activists and censored a number of websites. This made their activities precarious, making it necessary for activists to hide their identity on the Internet. The anonymity software Tor was a tool used by some bloggers, journalists and online activists to protect their identity and to practice free speech.

Today we have lot’s of anonymity communication tools I2P, Freenet, Gnunet and Tor to name a few. Why did the TorProject.org Tor-.onion network become the facto application to get free, private, anonymized Internet access. My conclusion is it’s humble beginnings with “Naval Research Project & DARPA (Defense Advanced Research Project Agency) ” sponsored, maybe you heard of DARPA they kinda created the Internet a long time ago. The government wanted to have a communication secure media that would piggy-bak on the establish Internet. From my point of view when they saw how good this worked the government used it to allow it’s agents to quietly use the network for CIA covert operations (just to name a few alphabet soup government agencies that use it). For example a branch of the U.S. Navy uses Tor for open source intelligence gathering, and one of its teams used Tor while deployed in the Middle East recently. Law enforcement uses Tor for visiting or surveilling web sites without leaving government IP addresses in their web logs, and for security during sting operations.

Journalist got a hold of this tool and they too were able to file reports before governments agents censored their interviews and film footage. The EFF (Electronic Frontier Foundation) got a hold of the Tor-networks and promoted it to maintaining civil liberties online. When the common business executive visited a foreign country (like China know to monitor foreigners Internet access) they now had a way to securely connect to their corporate HQ data-center without being monitored and giving away IP (Intellectual Properties). The Tor-Network became to good and the bad guy’s moved in to keep their illegal business safer from the law. The Internet Cyber-criminal has used the claer-web since the start so of course they went over to the Tor-.onion network because it works if you use it right and keeps you anonymous online.

With all this happening and the “Year of the Hack 2011” you can see why security geeks like Pierluigi and I became intrigued with this subject and we teamed up to write this manuscript hoping to answer some of the questions our friends, and peers were asking us about this mysterious hidden world call the deep dark web. We outlined a table of content and started to write about it in our blogs and the story unfolds from here to you. We hope to educate you on how this network works without too much geek talk (ok just a little). We cover the cyber criminals and their ecosystem we cover the financial currency (bitCoins) that is replacing fiat currencies all over the world during this unstable financial times. We tried to cover all the good , the bad and the ugly of the .onion network. We hope it will answer some of your questions but I am sure that more question will come up so feel free to come to our websites and give us a shout and ask your questions about the deep dark web…. - gAtO oUT 

Share on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
06/17/12

Cyber Black Market- Underground Economy

gAtO rEaD -the FBI leaked an unclassified report 24 April 2012 Intelligence Assessment “BitCoin Virtual Currency: Unique Features Present Distinct Challenges for Deterring Illicit Activity” : – http://cryptome.org/2012/05/fbi-bitcoin.pdf  – At that time BitCoins (BTC) were going about $4.25 USD per coin

as of Sun: Jun17 2012 it trading at $6:26714 a high of $6.52999 and low of $6.22130 check out – https://mtgox.com/  — and going up to $30 USD by Christmas

All that glitters is gold and he’s buying a stairway to heaven – with BitCoins mAyBe -sI -nO – more info in our new upcoming book about “The Deep-Dark Web” - 

What are BitCoins -

Bitcoin is a new digital currency. By using proven strong cryptography, a new currency has been created for the internet. One of the key features of Bitcoin is that it is an open system with no person or authority that governs the system. This means that you can treat it like cash: nobody can freeze your account, no chargeback’s, complete transparency and more.

This new currency opens massive opportunities for the internet.

Perfect Money – Liberty Reserves -Wire Tranfer -Pecunix -HD-Money -C-Gold -VouchX -Cosmic Pay -MtGox Coupons -Boleto -Banco Rendimento -CyberPlat -Qiwi -Money Gram -CVS ?7-11 -Wallmart -BitStamps -Dwolla -BTC-E Coupons

GaTo use to support wall street back in the day from 1 New York Plaza. overlooking the Battery Park. Those were the day out of the windows we could see traders coming into the park at lunch time and score there powdered lunch from the locals but that’s another story… these traders will take a look at BTC and once they get a whiff of the virtual money they will strike and it looks like the commercial criminals are already doing it.

 

 

 

 

 

http://bitcoincharts.com/markets/currencies/ - As you can see from the chart above While currencies from all over the world are going down because of the current financial world problems BitCoins are going UP-

Hal-Cash – from Russia with Love—Video – Market to Latin America

Here is an add for selling 100% anon visa cards with loaded BitCoins or whatever currency you want on them – by the way there are opportunities for -Now Hiring – money Mules and Drop Shipments scams for any sucker that want this kind of job- your a fool to buy this in my opinion they can sell you loaded Visa Card on one hand and Selling 100% Valid CVV and dumps of these card I assume but I’m a paranoid gAtO – I may be wrong – don’t try this at home kiddies—//

 

BitCoins are coming up and they are replacing the new fiat currencies especially in EU why because of the current problems in Greece and Spain – Below I added a list of -[1]Ways to get bitcoins…    – As you can see if you go to these they are scams for Gamblin and all kinds of underworld stuff- BUT how many people play -Online Poker and other gambling games. Oh and these are all in the ClearWeb – Yes the evil Internet not the ToR-.onion network ..

 

Now the -gAtO fUnnY- part is you can go to 7-11, Wallmart and just about anyplace and buy into this new currency so it’s not illegal to use these currencies but maybe it’s me gAtO is to dumb to use these but many, many merchants are now accepting all these new online currencies – so maybe it’s not so

stupid If someone wants to buy my- 1972 Action GI Joe Doll why shouldn’t I let them pay in BitCoins or any other currency -

Now in the Black Market of the ToR-.onion network it’s alive and well - http://clsvtzwzdgzkjda7.onion/viewtopic.php?f=50&t=1803&sid=4e3a4c75f43e3e82fe011d6c1e6601df&start=10  -

Now as you can see this is a boom to criminals to laundry their cash – but they been using FarmVille and other games to laundry money why not use this new untraceable money. I will leave the crime stuff for anther posting but I just wanted to give you all a taste of what is going on and what can happened with your money - gAtO oUt

Reference: Lab Notes —

http://bitcoincharts.com/

https://mtgox.com/

http://translate.google.com/translate?hl=en&sl=&tl=en&u=http%3A%2F%2Fgb.pl%2Fbanki%2Fkarty%2Fwyplata-z-bankomatu-bez-karty.html

From Russia with Love now in the USA -Hal-Cash and of course in Latin America

http://www.halcashusa.com/

How Does Bitcoin Work?

To use Bitcoin, an individual first downloads and installs the free Bitcoin software (client).

The application uses Public Key Cryptography (PKI) to automatically generate a Bitcoin address

where the user can receive payments. The address is a unique 36 character-long string of

numbers and letters and is stored in a user’s virtual “wallet” on his or her local file system. Users

can create as many Bitcoin addresses as they like to receive payments and can use a new address

for every transaction they receive.

 

To send bitcoins, users input the address they would like to send their bitcoins to and the

amount of bitcoins they would like to transfer. The user’s computer then digitally signs the

transaction and sends the information to the distributed, P2P Bitcoin network. The P2P network

verifies that the person sending the bitcoins is the current owner of the bitcoins they are sending,

prohibiting a malicious user from spending the same bitcoins twice. Once the transaction has

been validated by the Bitcoin network, receivers can spend the bitcoins they have received. This

process usually takes a few minutes and is not reversible.

 

(U) The Bitcoin software program controls the rate of bitcoin creation, but it does not control the

market value of a bitcoin; the market value is determined by the supply of bitcoins in circulation

and people’s desire to hold or trade bitcoins.52, 53 Unlike most fiat currencies, in which central

banks can arbitrarily increase the supply of currency, Bitcoin is designed to eventually contain

21 million bitcoins; no additional coins will be created after that point, preventing inflation.

 

Bitcoin was created in such a way that the clients “mine” bitcoins at a predetermined rate.

This chart illustrates the growth rate from 2009 to 2033, the year the last new bitcoin will be

created.

 

[1]Ways to get bitcoins… ClearWeb Sites not ToR-.onion network stuff 

 

http://bit.ly/cmpbx (exchange) https://campbx.com/

http://bit.ly/btcxchange (exchange) http://www.cryptoxchange.com/  Australian -Last Price : 6.49999 Buy :6.56200 Sell : 6.56115 Volume : 351.61962

http://bit.ly/virwox1 (exchange) https://www.virwox.com/    53,267 users / 15,320,752,995 L$ exchanged

http://bit.ly/coinabul Physical Gold http://coinabul.com/   BTC Spot: $6.41 Australia

http://bit.ly/triplemining (mining pool) https://opticbit.triplemining.com/register  -BTC Mining Pool

http://bit.ly/poolcoin (mining pool) http://pool.betcoin.co/

http://bit.ly/btcplus (java cpw web pool) http://www.bitcoinplus.com/  BTC Minig Scam

http://bit.ly/mycryptcoin (free btc) http://mycryptcoin.com/

http://bit.ly/bitcrate (free) http://www.bitcrate.net/

http://bit.ly/btcbonus (rebates for online purchaces) http://bitcoinbonus.com/

http://bit.ly/bitgigs (classified/fiverr like) http://www.bitgigs.com/  Work or sell for BTC money

http://bit.ly/freebtc1 (survey) http://www.freebitcoins.org/

http://bit.ly/earnbtc (survey) http://earnthebitcoin.com/

http://bit.ly/lfnu1 (url shorten) http://l.f.nu/?partner=15tZJ7sWuDJHgtYbyiymo1zbR3FkGkRBTq

http://bit.ly/coinurl1 (url shorten) https://coinurl.com/

http://bit.ly/anonads (ads) http://anonymousads.com/

http://bit.ly/qmt5sL (ads, and free btc) http://dailybitcoins.org/

http://bit.ly/coinad (ads, and free btc) https://www.coinad.com/

http://bit.ly/5minbtc (ads free btc) http://www.fiveminutecoin.com/

http://bit.ly/btckamikaze (gamble) http://bitcoin-kamikaze.com/

http://bitcoin-kamikaze.com BitCoin LoTTo

http://bit.ly/btcminefield (gamble) http://minefield.bitcoinlab.org/

http://bit.ly/bitcoindarts (gamble) http://bitcoindarts.movoda.net

http://bit.ly/btcchess (gamble) Chess www.fantasypublishings.com/

BitCoin Ptramid Features

http://bit.ly/bpyramid (ads and pyramid scheme) http://bitcoinpyramid.com/

http://bit.ly/bidbtc (pyramid) http://bidonbitcoins.com/

http://bit.ly/btcmatrix (pyramid) http://btcmatrix.com/

http://bit.ly/sldoubler (ponzi) http://sldoubler.com/

http://bit.ly/smsdragon (txt) https://www.smsdragon.com/

http://bit.ly/btccalipers (calipers) http://www.goldenmeancalipers.com/

http://bit.ly/btctrading (forum) http://www.bitcointrading.com/

Use BitCoins to buy domain and hosting services

http://bit.ly/bitdomain (web host) http://www.bitdomain.biz/

http://bit.ly/cinfu (web host) https://panel.cinfu.com/

http://bit.ly/btchost (web hosting) http://www.btcwebhost.com/

http://bit.ly/joinorangewebsite (web host) http://www.orangewebsite.com/affiliate/

http://bit.ly/surf4btc (paid 2 surf) http://surfformoney.net/ref/

http://pyramining.com/referral/

Underground Economy – basics

Reloadable Debit Cards

Basics

Greendot and other Reloadable debit cards can be used in an attempt to allow for anonymous financial transfer between customers and vendors. Vendors need to cash money out. They can accomplish this by setting up Greendot cards with stolen identities and getting them shipped to mail boxes set up with fake identification cards. Customers need to load money in. They can do this by going to any store that sells Greendot reload paks. Customers merely hand the clerk some cash and in return get a cardboard card with a load number on it. The customer can transfer this load number to the vendor via an encrypted and anonymous channel. The vendor then applies the loaded funds to the card via the internet. The loaded funds can then be cashed out at an ATM.

Security

These cards should be viewed as financial networks. The financial information consists of the traffic and the cards are the nodes. Reloadable debit card networks have a high degree of cross network contamination. One additional network involved is the mail system, the vendor is required to have the card shipped to a physical mail box. This may not be particularly risky due to the fact that it is unlikely the card is being watched at this point as no customers are aware of it yet. However it is important for vendors to remember that the reloadable debit card company will keep their box information on record. Another network the vendor needs to utilize is the telecommunications network. Vendors are required to talk over a telephone to activate the card. The risk inherent in this can be minimized if the vendor uses a burner phone. Vendors are also required to make an initial visit to a store in order to obtain their temporary card prior to being mailed one. They will likely be recorded by CCTV cameras. Customers also have to worry about CCTV cameras as they must hand money to a clerk in a store. Customers can not take adequate measures to disguise their identity during this process as there is direct human interaction.

Reloadable debit cards have a distinct disadvantage of being highly centralized. Vendors tend to have many customers send funding to a single centralized card. This means that a single compromised customer can compromise the Greendot card of the vendor. The only way to prevent this is for the seller to use multiple Greendot cards, one for each customer to be perfect. This is not very feasible.

If a malicious customer identifies the card of a vendor it is possible for network analysis to map out the financial network involved with this buyer. Records are kept of funds being transferred from a reload pack into a cash out card. The time and location of reload pack sales that are used to fund cash out cards can be determined. A single compromised customer can use this information to gather video surveillance of every single person who has loaded funding to the card of the seller. This may not hold up as evidence by itself but it is strong intelligence indicating that a person who has sent funds to a vendor is in fact a drug customer.

Conclusion

Greendot and other Reloadable debit cards are not a safe means of conducting anonymous financial transfer. The financial networks created by these cards are very prone to network analysis. There is an unacceptable amount of cross network contamination for vendors. The load points for introducing finances into the network are also under too much surveillance.

Tips

Customers can out source the purchase of reload moneypaks. Good solutions may include utilizing bums and transients.

Vendors should avoid Greendot type reloadable debit cards. If they are used they should be highly compartmentalized (different cards for different groups of people). Compartmentalization is not possible in all cases though. Remember, if a single customer is malicious they can compromise the entire compartment. This puts customers at risk as well!

Greendot cards are prone to being frozen. Triggers include typical patterns associated with narcotics trafficking; cashing out very soon after cashing in, getting payments from diverse geographic areas (geographic based compartmentalization of customers is suggested), particularly large amounts of money going through a card in a short period of time etc.

WU/MG

Basics

Western Union and Moneygram money wires involve a customer sending funds to a vendor over the WU or MG financial network. Customers must go to a location that offers one of these services and hand money to a clerk. Depending on the country of the customer they may be required to show identification for any amount of money. In all locations identification must be shown for amounts of money over a certain limit, usually $500 or $1000. Customers fill out forms that are specially designed for gathering fingerprints and are usually under video surveillance.

Security

Despite their many short comings WU and MG both offer substantial benefits over reloadable debit cards. It is easier to use multiple pseudonyms for pick up from these services, the number of pseudonyms you have is limited only by the number of fake ID cards you can get. Unlike with Reloadable debit cards vendors are not required to use stolen identities. They are also not required to set up mail boxes or make telephone calls (WU). The ability to easily use multiple pseudonyms makes it easier to decentralize and compartmentalize the financial networks. If a different fake ID is used for each customer, a single malicious customer will not be able to map out the entire network based on transaction records.

It is possible that a single malicious customer could use video surveillance and facial recognition to tie a multiple fake ID pseudonyms to a single person. After identifying the vendor in a single transaction facial recognition could identify them every time they send funding, even if they use a different fake identification document. This attack is possible but it is not likely to be used against drug traffickers at the current time.

One of the primary disadvantages of WU and MG is the fact that there are a limited number of locations a vendor can cash out from. Customers know the rough geographic area a vendor will pick up the wire from because when sending a WU or MG the city of the vendor must be listed on the form. This allows for surveillance teams to stake out a number of possible locations the pick up may be made at. These surveillance teams can be alerted when the target attempts pick up and then move in on the target. This risk is much smaller with Greendot cards because Greendot funding can be taken out from a large number of ATM’s distributed through out a wide geographic area.

Tips

WU and MG have a substantial benefit over Greendot in that they can be used for funding E-currency. E-currency can dramatically increase the security of a financial transfer.

Customers and vendors can and should use fake identification to counter the record keeping of transactions. Even if a vendor is legitimate customers may be flagged if they send large sums of money with their real identification.

In some cases question and answer can be used to remove the need for identification. If this is allowed or not is highly dependent on the particular area of the customer/vendor

Wearing gloves or avoiding finger contact with the forms can countermeasure leaving fingerprints. Using stencils to fill out the forms at a private location can counter hand writing analysis. However, video surveillance is something that can not be countered.

Note: Forms are designed to pick up fingerprints

E-currency

Basics

Traditional E-currency systems (LR, PX) are relatively complex systems of financial transfer involving many companies. Usually an E-currency system is structured as follows; a main digital gold company stores gold bars in a vault and creates audited cryptographically secure digital currency units. The main E-currency company runs a website that allows owners of the currency to manage their accounts as well as send and accept funding. Usually the main E-currency company is not interested in selling small amounts of currency. The main E-currency company will usually only sell large amounts of digital currency to exchanger companies. Average users of E-currency systems only deal with exchangers and use the main digital currency company only to manage their accounts.

E-currency exchangers are located around the world and they accept payment in various ways according to their own policy. Usually E-currency exchangers have no affiliation with the main E-currency company. Some exchangers are even scammers so be careful who you work with!

To load E-currency first you need to set up an account with the parent company. It is free to do this and usually requires no identification at best or at worst easy to forge identification. You should make sure to protect your anonymity when you set up E-currency accounts, at the very least you should use Tor or similar technology to protect from network forensics. Make sure the E-mail data you register with is no tied to you in anyway and was also obtained anonymously. After you have your account set up you will be given a number which can be used to transfer currency to your account. Now you need to set up an order with an exchanger, it is suggested that you use offshore exchange services. How the exchanger accepts funding is totally up to their policy, many accept western union and some accept cash in the mail. After the exchanger gets the funding you send them they will transfer E-currency to your account minus a transaction fee. From here you can either send the E-currency to a vendors account or you can cash it out and have it sent to a vendor via another method through another exchanger. Exchangers cash in and out meaning you can not only buy E-currency from an exchanger for cash but you can also sell E-currency to an exchanger for cash.

Security

E-currency can be seen as similar to a financial multi-hop proxy, the first hop being the exchanger and the second hop being the E-currency company. This can add jurisdictional complication to financial network analysis attacks. You must make sure to follow normal operational security procedures when using E-currency, for example make sure to use anonymizers when interacting with the digital website and use fake identification for loading currency if possible. E-currency can also be used to create highly decentralized overlay networks, further adding to security of both customers and vendors.

Tips

If a vendor accepts WU but not E-currency customers can use E-currency to send WU. After loading E-currency merely cash it out via another exchanger to the WU details of the vendor.

Vendors can decentralize their financial networks by creating new E-currency accounts for each customer. Although this is time intensive the benefits are very extreme and it is highly suggested. If every customer is presented with a different E-currency account it will make it impossible for financial intelligence to map out customer networks. A malicious customer only knows the E-currency account they sent payment to, since no other customers sent payment to the same account the malicious customer gains no useful intelligence.

Vendors can appear to accept any payment method an exchanger offers while actually layering the funding through E-currency accounts. When a customer places an order merely set up a request for funding with an E-currency exchanger and then present the customer with the funding information of the exchanger. The exchanger gets the funding from the customer and then puts it into the vendors E-currency account. This allows vendors to accept payment to any location they can find an exchanger in.

E-currency can be layered through multiple accounts prior to cashing out. It may be difficult for a legal team to prove an account that cashed out marked E-currency belongs to the same person who was sent the E-currency in the first place.

Online E-currency casinos can be used to cheaply add more jurisdictions to a trace and potentially mix the finances of the vendor with many others. If a vendor loads E-currency to buy digital casino chips and then cashes the casino chips out for E-currency to a new account it will probably make it harder for financial intelligence agents to follow the trail and can unlink accounts from each other.

Trust Networks

Basics

Open trust networks are potentially a great way to cash out/in E-currency. Assume that Alice has obtained $10,000 worth of E-currency from her customers. Assume Alice and Bob are in a trusted relationship with each other. Perhaps Bob wants to purchase several thousand dollars worth of E-currency. Rather than go through an independent exchanger Bob may choose to send Alice his cash in return for E-currency. This allows Bob to obtain E-currency with high anonymity and also allows Alice to cash out via a trusted node. This can present a virtual dead end to financial intelligence teams. If the E-currency was watched they see it go to Bobs account but they do not know who Bob is or how he obtained the E-currency. Even if Bob paid for the E-currency via WU and was on CCTV, the agents will not know where the funding was sent from. Cashing out of this system is eventually required unless the system continues to grow (Open versus Closed). Cashing out of a closed trust network can be done by Bob ordering product from another vendor and then selling it locally.

Borrowed Bank Accounts / Underground ATM cards

Borrowed bank accounts and underground ATM cards are useful for cashing out E-currency anonymously. They are also useful for taking bank wires as a method of payment. You need to be able to get the details of a bank account as well as a skim of the magnetic stripe of the ATM card tied to the account. If you can do this, you can cash the E-currency out through an exchanger via bank wire to the account you have a card for. You can now cash the money out at any ATM the card is accepted at. If you can get the skim of the ATM card, you can simply encode it to blank card stock for cashing out with.

I suggest not to take money out of the persons bank account unless you put it in. This will reduce the chances that they quickly notice you borrowed their bank account. You could leave extra money in the account as well, the person it belongs to may be less likely to report suspicious transactions if they are afraid they will lose whatever you left behind.

There are various organizations willing to offer ATM cards capable of being funded with E-currency and cashed out with at an ATM. Some of these services are scams and others are legit. Some require identification but these can be countered with fake documents.

Mule Networks

Mule networks can be used to help cash out funding. Obtaining a mule network is a difficult and time consuming task. The most common technique is to offer ‘work at home’ job offers. People accept the job offer and are led to think that they are working for an official company when in reality they are merely picking up money and sending it on. It is expensive to fund these networks and only very realistic for large vendors. It is possible that feds will accept such offers in an attempt to perform human sybil attacks on the networks formed.

Bitcoin

Bitcoin is a newer type of decentralized digital currency. The underlying system of Bitcoin is quite complex and difficult to summarize. It is suggested that you go to the bitcoin[1] website and learn about the system. There are various ways to anonymize Bitcoin transactions. As of 2011 June 14, bitcoins trade for approximately 20 US dollars per coin. A combination of Bitcoin and blind signature digital currency systems is likely the ideal way to cash in and out, however such systems are still largely experimental and developing. Additional laundry systems were available as a hidden services, however they have gone AWOL.[2]

Share on TumblrSubmit to StumbleUponhttp://uscyberlabs.com/blog/wp-content/uploads/2012/06/aa_bitCoin_001.tiffDigg ThisSubmit to reddit
06/11/12

ToR Black Market CyberCrime EcoSystem

gAtO tHiNkS - the Black Market in cyber space exist in both the surfaceWeb and the darkWeb. For some reason the general internet user thinks of the ToR-.onion network is for bad guys only and only because of the Black Market in the onion network which is a small part of the network… The general concession is the black market rules in ToR onionLand is a joke let me tell you why.

What is the Cyber Black Market:

A black market or underground economy is a market in goods or services which operates outside the formal one(s) supported by established state power.

From DHS CyberCrimes is a bigger threat than terrorism – From Symantec/Norton Cyber Crime Statistics in the SurfaceWeb:

Here are some quotes from their report.

1.Cybercrime cost $388 billion across 24 countries.

2.  69% of adults have been a victim of cybercrime.

3.10% of mobile phone users have experienced cybercrime, up 42% from last year.

4.Cybercrime costs the world significantly more than the global black market in marijuana, cocaine and heroin combined ($288B).

White Collar -Cyber Crime

In the Surface Web -CyberSpace- crime is well and dandy but we have become accustom to it – If your a Windows user how many security updates do you get a week, a month. That alone tell you that in the surface Internet we have lot’s of cyber-crime going on — and so pharmacy spam email are normal, offers from Africa millionaire that left you money come every other day. In these hard economic times offers to make big bucks $$ working from home -becoming a re-shipping mules for commercial criminals are normal offers from people looking for jobs. These are all organize cyber criminals groups. dealing in the surface web.

Blue Collar -Cyber Crime

Now take ToR-.onion Black Market: It’s a little more in your face drugs, guns, stolen goods, sex, hacked data- in the darkWeb you know that these merchants are crooks and criminals. In Silk Road or BlackMarket Reload they now verified sellers and now even buyers. To make it look more legit. What does verified mean in these .onion market-places. It usually mean that the admin of the site has somehow check that this is a real person w/real whatever. Or he has done business with someone and they write a nice review. Never thinking that the review could be the crook with another login name just like they do in the surfaceWeb. 

gAtO would not do business with any black market in the surfaceWeb or the darkWeb -If my products are bad at least I can complain to Amazon, I can’t do anything but write a bad review in BlackMarket-Reload in the darkWeb.

  -honest crooks? In the Tor-.onion Black Market you can assume everyone is a thief a crook or a criminal.

CyberCrime EcoSystem. 

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Let’s look at the black market in the surface web.:

WHITE COLLAR CYBER CRIMES – cybercrime ecosystem

ATM skimming: – ATM skimming is proliferating, next to the overall availability of bank plastic cards, holograms and pretty much everything a carder needs to cash out the fraudulently obtained credit card data.

pharmaceutical e-mail spam problem: -The general public is addictive to drugs- legal – illegal – copy-drugs – fake claim drugs – and they e-mail you the consumer you seen them “Viagra” cheap -Canada – Europe – nah it from Asia or Russia.

Eastern Europe is the epicenter of the cybercrime epidemic-financially-motivated cybercrime – without question hackers in Russia and Eastern Europe are the most active, if not also the most profitable. sophisticated groups tend to be regional and stick to attacking their own (Brazil is a good example).

active malware/crimeware campaigns:

sophisticated cybercriminals:

Risk-forwarding cybercrime ecosystem

the rise of money mule recruitment

Are reshipping mules more popular than money mules 

advanced persistent threats (APT attacks)

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Let’s look at the black market in the dark web.:

BLUE/BROWN/BLACK-(low end) COLLAR CYBER CRIMES

Selling Drugs

Selling Guns and explosives

Selling Stolen goods

Selling Hacked Data

Selling Sex

Buy an Assassin 

Rent a Hacker

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

So now we can see that in the Surface black market the legit merchants are watching everything you do and selling your information to the highest bidder. While the sophisticated crimes agains normal people backed by organized crimes is normal in the clearWeb. So in the Deep -Dark -Tor -.onion web the low end criminals haunt this area. The problem I have is that the same things that are in the deep dark web are the same things I can get at -EBAy- Guns – Stolen Goods, -CraigsList-  Assassin, legal/illegal Drugs, Sex, Stolen Damage Goods, Drugs, so in the surface web you can get the same as the dark web what’s the difference. Inside the matrix you have more anonymity -

No matter the anonymity gATO would not do business with the black market in the deep web or out. Use your own common sense my friends. We are judging that those people that use the ToR protocol to communicate with more privacy are all bad when only a few sites sell (bad) stuff there is some good in the network – and – bottom line –it’s all about freedom of choice  . The other thing is that the commercial cyber-criminals ecosystem in the clearWeb has not picked up on this newer technology (ToR-onion network) that is more secure and are harder to scam and gain your personal and their information while online.

The Black Market is the same or worse in the surface web than in the deep-dark web so- stay away from the black market period use the ToR network to be smarter, quiter without leaving digital bread-crums -

Below I have my notes and the ToR Cleaned Hidden Directory WiKi so you can see yourself some of the things that go into the black market Tor-.onion network- Remember that this is only a small part of the network their is millions of terabytes undiscovered in the ToR-.onion network it’s just hidden. They don’t want you too know.

Goerge Carlin said it best – Your not in the club- and they are not going to let you in – they are never going to let you in- 

They are going to scare you away from the ToR-.onion network because  “they” the powers that be –will hide their little business secrets in this network and they want to scare you away from it.  I found a great article from “Kerb on Security Interview” outlining the cyber criminal ecosystem where I drew a lot of the surface web black market anyway - gAtO oUt

lab Notes: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

lab Notes: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

lab Notes: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

 

ToR Cleaned Hidden Directory Wiki

http://3suaolltfj2xjksb.onion/hiddenwiki/index.php/Main_Page

Hidden services – HTTP/HTTPS

Volunteers last verified that all services in this section were up, or marked as DOWN, on: 2012-01-24

Introduction Points

OnionLand link indexes and search engines.

Hidden Wikis

Index pages in Wiki-based format.

Other indexes

Other places/directories you may be able to find links.

Search engines

Google for Tor. Search for links.

  • TORCH – Tor Search Engine. Claims to index around 1.1 Million pages.
  • Deepsearch – Another search engine.
  • Torgle – Torgle revived. Based on OnionWare’s server. Web crawler.
  • The Abyss – Administrator’s search engine. Supports submitted links.
  • Ahmia.fi – Clearnet search engine for Tor Hidden Services (allows you to add new sites to its database).
  • DuckDuckGo, clearnet – Clearnet metasearch engine with heavy filtering. Not like the aforementioned search engines to look up Hidden Services. Just searches the clearnet.

Other general stuff to see

Starting places.

Marketplace

See also: Marketplace Reviews – Reviews of the marketplace experience (ALL reviews go in this article, NOT in the listings below).
See also: The separate Drugs and Erotica sections for those specific services.
Remember that “feedback” can be faked in the Marketplace Reviews. Try to use escrow as much as possible to ensure you won’t be scammed.

Financial Services

Currencies, banks, money markets, clearing houses, exchangers.

  • Anonymous Internet Banking Anonymous Debit Cards with EU bank account and VCCs by A HackBB trusted vendor
  • The Bitcoin Laundry Service- Bitcoin Laundry service.
  • InstaCard – Sell your bitcoins for a virtual VISA credit card, in $25, $50, or $100 denominations. $5 fee.
  • Paypal4free – Hacked Paypal accounts for cheap, with balances
  • PayPal Store – Purchase clean, verified USA PayPal accounts with Bitcoin. (Host: FH)
  • Bitcoin Fog – Laundry service.
  • anonXchange – Ecurrency exchanger, exchange LR, Bitcoin, PSC, Ukash, Pecunix, Cash. Also doing Bitcoin washing.
  • Acrimonious – A bitcoin escrow checkout. Free if there are no disputes. Works with tor2web. (UNABLE TO REGISTER)
  • Bitcoin2CC, clearnet – Converts your Bitcoins into a virtual VISA credit card instantly.
  • The Bitcoin Washing Machine – Can launder large amounts of coins without same-coin contamination. (Host: FH)
  • Little BTC Ebook – The new way of selling and buying Bitcoin is through Second Life, more information here.

Commercial Services

Hosting / Web / File / Image

  • The Onion Cloud - Tor/ownCloud based cloud. Login/Pass: public/public. (Host: FH)
  • Megaupload.com Accounts for BTC - sells megaupload.com accounts in exchange for bitcoins
  • TOR host - Host your site anonymously in deep web for free. - DOWN 2011-12-24
  • bittit, clearnet - Host and sell your original pictures for Bitcoins.
  • Mystery File a Day - Want to see something cool?
  • Blolylo - Simple file uploads. Won't accept plain text files. 2 MiB upload limit. (Host: FH) (Blank page) - Broken 2011-06-09
  • CircleServices - Mixie's place. Provides: Circle-Talk, TorPM, ImgZapr, SnapBBS, qPasteBin, AnonyShares, Circle-IRC. (Provider: CS)
  • Anonyshares - File upload up to 10MB. (Provider: CS)
  • qPasteBin - A pastebin. (Provider: CS)
  • 5am - File dump and Image Board. 5MB Limit. DOWN 2012-01-05
  • Potaoto - Image hosting. Generates large thumbnails. DOWN 2012-01-05
  • Onion Fileshare - 2GB Upload file size limit. Upload any files you want.
  • ES Simple Uploader - Upload images, docs and other files. 2 MiB upload limit. (Host: FH)
  • IMGuru (More info) - Fast GIF/JPEG host. No images removed. If you get the error Invalid File, retry the upload. (Host: FH)
  • TorIB - Create and run your own imageboard. (Host: FH) (Neglected status note) - Broken 2010-06-16
  • SquareBoard - Upload and share high quality images. (Moderated)
  • sTORage - Upload files. Has WebDAV support.
  • Onion Image Uploader - Image Hosting. 2 MiB upload limit. Generates medium thumbnails. (Host: FH)
  • Freedom Hosting (More info) - Hosting Service with PHP/MySQL. As of 2011-06-04, it hosts about 50% of the live OnionWeb by onion. UPDATE 2011-06-05, probably owns a lot more than that now. Invite-only.
  • PasteOnion - Paste and share text, sources, whatever. You can make your paste public or set a password. (Host: FH)
  • QicPic - Upload any type of file. Caches and compresses uploaded files to decrease loading time. (Host: FH)

Blogs / Essays

Forums / Boards / Chans

SnapBBS

A relatively simplistic messaging board owned by Mixie. Various discussion boards. There's lots of these, but here are a couple.

Other forums

Other forum types. Usually phpBB.

Imageboards

Non-CP or generally safe imageboards on Tor.

  • Torchan - /b/, /i/, programming, revolution, tons of other boards
  • Anonchan - Boards: /b/ - Random, /a/ - Anime/Manga/NSFW.
  • Hidden Image Site - HIS
  • TriChan - Revived, now only has /p/ Pokemon, /mlp/ My Little Pony, and /b/ Random
  • Lukochan - A Russian/English text discussion board in imageboard style.

Deaths (R.I.P):

  • RundaChan - Share ideas and ask or answer questions
  • Bobby's board Channel with currently only 2 boards but growing - about 75% LOL 0% uptime

Forums Scripts Besides SnapBBS

  • PunBB 1.3.6 Forum script - During installation, you need not give your email address to create your forum! When registering you do not need feeding your e-mail! You can register without e-mail. The script does not register in the forum database your IP! nor the Administrator / Moderator cannot see your IP address gives you a much safer use of the forum because your IP is not logged anywhere in the database! Two mirrors download.

If anyone knows of anything else that provides this, send an e-mail.

Email / Messaging

See also: The compendium of clearnet Email providers.

Political Advocacy

Whistleblowing

WikiLeaks

See also: WikiLeaks Official Site and Official Submission Onion (temporarily closed).

Operation AntiSec

Other

H/P/A/W/V/C

Hack, Phreak, Anarchy (internet), Warez, Virus, Crack.

Audio - Music / Streams

Video - Movies / TV

Books

See also: Category:Novel - List of books on this wiki.

Drugs

Noncommercial (D)

These sites have only drug-related information/talk. No sales or venues.

Commercial (D)

See also: Marketplace Reviews and Onion Reviews - Reviews of the marketplace experience (ALL reviews go in these articles, NOT in the listings below).

  • oxiD Shop - Marijuana, Cocaine (Bitcoin)
  • Silk Road - Marketplace with escrow (Bitcoin)
  • Pot2Peer - Marijuana and cannabis products delivered safely and discreetly to your door. Always anonymous. (Bitcoin)
  • Paradoxum - Cannabis, MDMA, LSD, Mushrooms, Coke, DMT (BTC, Dwolla, Pecunix, LR, Paxum)
  • DrugSpace - Dispensary Grade Sour Diesel Marijuana and Cambodian strain Psilocybin Mushrooms. Get the URL from the Onion Reviews, people keep changing it here
  • Trees by Mail Beta - Cannabis from Northern California (Bitcoin)
  • and - Yummy edibles and other cannabis related stuff. Nothing but the best. (Paypal and Bitcoin)

Erotica

Adult

Noncommercial (E)

Commercial (E)

See also: Marketplace Reviews - Reviews of the marketplace experience (ALL reviews go in this article, NOT in the listings below).

Paraphilias

Uncategorized

Services that defy categorization, or that have not yet been sorted.

  • Kenny - You killed Kenny! You're a bastard! DOWN
  • Carson - Nature Boy poem. Previously The Ultimate Guide for Anonymous and Secure Internet Usage v1.0.1.
  • The LG enV2 - Very basic information and photo gallery about a wireless digital messaging phone. (Host: FH)
  • Questions and Answers - A little truth game. Ask questions and give answers anonymously. Answers also support image uploading.
  • noreason - Info and pdf files on weapons, locks, survival, poisons, protesters, how to kill. Hidden Wiki, TorDir, Steal this wiki, Telecomix Crypto Munitions Bureau mirrors. Guro, dofantasy / Fansadox Collection. DOWN D:
  • The Outlaw Project - "Free for all" - links to various files and known .onion sites. Onion address hosted an FTP service.
  • Fenergy file-server - File collection that includes books and other resources energy related.

Non-English

Czech / ?eština

Danish / Dansk

  • DanishChan - Scandinavian focused imageboard. Boards include drugs and IT security as well as a Random board. Fast and clean layout, little downtime.
  • drugs.dk - Danish Drug Trade. (Host: CS)

Dutch / Nederlands

Estonian / Eesti

  • Vileveeb - Anonüümsete raportite esitamine. DOWN 2012-01-24

Finnish / Suomi

French / Français

German / Deutsch

Hebrew / ?????

  • Samim.onion - Selling and shipping of drugs and medicine in Israel (Bitcoin). (Host: FH)

Italian / Italiano

Japanese / ???

Korean / ???

  • ?? - ??? ?? ??? (??????)

Polish / Polski

  • Torowisko - Forum Polskiej Spo?eczno?ci Tor. Nowe ogólnotematyczne forum bez rejestracji i cenzury. Godny Nast?pca Onionforum, ju? z ponad 8000 postami (codziennie przybywaj? nowe!). (Host: FH)
  • Fundacja Panoptykon, clearnet - Strona fundacji przeciwstawiaj?cej si? coraz powszechniejszej inwigilacji oraz tendencjom nasilania nadzoru i kontroli nad spo?ecze?stwem.
  • George Orwell "Rok 1984" - polskie t?umaczenie znanej powie?ci
  • Polska Ukryta Wiki - PUW, wiki polskiej spo?eczno?ci Tor. (Host: FH)
  • FAQ – Freely Answered Questions - Portal typu Q&A, gdzie mo?esz zadawa? pytania zwi?zane z undergroundem (czyt. pytania niewygodne). (Host: FH)

Strony porzucone, nieaktywne lub ?mieciowe:

Portuguese / Portugues

Caravana Brasil

Russian / ???????

  • R2D2 - ????????? ?????, ??????? ????????????, ???????? ????????
  • Runion - ????????? ?????: Bitcoin, Tor, ????????? ?????
  • Runion Wiki - ??????? ?????? ? ????????? ? Runion ?? ???????
  • ??????? - ??????? ??????? ?????. (Host: FH)
  • ???? - ??????????? ???????? ???????? ?????????????. (Host: FH)
  • ??? - ????????? ????????????? ?????.
  • ????????, clearnet - ?????? ???????? ????????????? ????????? ????????.
  • ?????-?????? - ????? ??????? ?????? ? ???? ?? ??????? ?????. (Host: FH)
  • Russian Road - ??????? Silk Road(?????????, ??????, ?????????, ?????????)

Slovak / Slovenský

Spanish / Español

  • Abusos - Abusos judiciales en España.
  • Quema tu móvil!, clearnet - Interceptación de comunicaciones móviles. Cell phone eavesdropping techniques used by Intel agencies. DOWN 2012-01-24
  • HoneyNet, clearnet - Hacking ético, técnicas especiales de seguridad empleadas en los test de intrusión para evitar ser detectados. DOWN 2012-01-24
  • T0rtilla - Shoutox webchat. (Host: FH)
  • CebollaChan - CebollaChan, el tor-chan en Castellano.
  • T0rtilla - Shoutbox webchat. (Direct FH URL). (Host: FH)
  • Forocoches 2.0 - Torocoches - Forocoches 2.0 (Host: FH)

Swedish / Svenska

Hidden Services - Other Protocols

Volunteers last verified that all services in this section were up, or marked as DOWN, on: 2011-06-08
For configuration and service/uptime testing, all services in this section MUST list the active port in their address. Exception: HTTP on 80, HTTPS on 443.
For help with configuration, see the TorifyHOWTO and End-to-end connectivity issues.

P2P FileSharing

Running P2P protocols within Tor requires OnionCat. Therefore, see the OnionCat section for those P2P services.
IMPORTANT: It is possible to use Tor for P2P. However, if you do, the right thing must also be done by giving back the bandwidth used. Otherwise, if this is not done, Tor will be crushed taking everyone along with it.

  • The Pirate Bay - Download music, movies, games, software! The Pirate Bay - The galaxy's most resilient BitTorrent site - Official(?)
  • GNUnet files sharing - GNUnet URI index site with forum. (Host: FH)
  • Sea Kitten Palace - Torrent site and tracker for extreme content (real gore, animal torture, shockumentaries/mondo cinema, and Disney movies)
  • AshANitY - Anonymous sharing of Humanity, torrents. (Host: FH)

Chat centric services

Some people and their usual server hangouts may be found in the Contact Directory.

IRC

See also: IRC Anonymity Guide

  • AnoNet - Each server is on its own network and connects to a chat cloud

running on: (various).oftc.net, ports:: plaintext: 6667 ssl: 6697

  • Federation: OnionNet - IRC network comprised of:

running on: unknown, ports:: plaintext: 6668, ssl: none

 

running on: (various).freenode.net, ports:: plaintext: 6667 ssl: 6697/7070

running on: kropotkin.computersforpeace.net, ports:: plaintext: none ssl: 6697

running on: unknown, ports:: plaintext: 6667 ssl: 9999

  • hackint - hackint is a communication network for the hacker community.

running on: lechuck.darmstadt.ccc.de, ports:: plaintext: none ssl: 6697

running on: unknown, ports:: ssl: 6697

SILC

XMPP (formerly Jabber)

  • xmpp:ch4an3siqc436soc.onion:5222 – public server. No SSL. Chatrooms. No S2S. – DOWN 2011-08-01
  • xmpp:okj7xc6j2szr2y75.onion:5222 – xmpp:jabber.ccc.de:5222 as a hidden service

TorChat Addresses

Humans are listed in the above contact directory. Bots are listed below.

  • 7oj5u53estwg2pvu.onion:11009 – TorChat InfoServ #2nd, by ACS.
  • gfxvz7ff3bzrtmu4.onion:11009 – TorChat InfoServ #1st, by ACS.

OnionCat Addresses

List of only the Tor-backed fd87:d87e:eb43::/48 address space, sorted by onion. There are instructions for using OnionCat, Gnutella, BitTorrent Client, and BitTorrent Tracker.

  • 62bwjldt7fq2zgqa.onion:8060
  • fd87:d87e:eb43:f683:64ac:73f9:61ac:9a00 – ICMPv6 Echo Reply
  • a5ccbdkubbr2jlcp.onion:8060 – mail.onion.aio
  • fd87:d87e:eb43:0744:208d:5408:63a4:ac4f – ICMPv6 Echo Reply
  • ce2irrcozpei33e6.onion:8060 – bank-killah
  • fd87:d87e:eb43:1134:88c4:4ecb:c88d:ec9e – ICMPv6 Echo Reply
  • [fd87:d87e:eb43:1134:88c4:4ecb:c88d:ec9e]:8333 – Bitcoin Seed Node
  • taswebqlseworuhc.onion:8060 – TasWeb – DOWN 2011-09-08
  • fd87:d87e:eb43:9825:6206:0b91:2ce8:d0e2 – ICMPv6 Echo Reply
  • http://[fd87:d87e:eb43:9825:6206:0b91:2ce8:d0e2]/
  • gopher://[fd87:d87e:eb43:9825:6206:0b91:2ce8:d0e2]:70/
  • vso3r6cmjoomhhgg.onion:8060 – echelon
  • fd87:d87e:eb43:ac9d:b8f8:4c4b:9cc3:9cc6 – ICMPv6 Echo Reply

Bitcoin Seeding

Instructions

  • bitcoinbudtoeks7.onion:8333 – DOWN 2011-08-20
  • nlnsivjku4x4lu5n.onion:8333 – DOWN 2011-08-20
  • xqzfakpeuvrobvpj.onion:8333
  • z6ouhybzcv4zg7q3.onion:8333

Dead Hidden Services

Main article: List of dead hidden services

Do not simply remove services that appear to be offline from the above list! Services can go down temporarily, so we keep track of when they do and maintain a list of dead hidden services.

  • In addition to an onion simply being gone (Tor cannot resolve the onion), sites that display 404 (and use a known onion/URL based hosting service) are the only other thing that is considered truly DOWN. Presumably the account is gone.
  1. If a service has been down for a while, tag it with ‘ – DOWN YYYY-MM-DD’ (your guess as to when it went down).
  2. If a tagged service on the above list of live hidden services has come back up, remove the DOWN tag.
  3. If a tagged service is still down after a month, please move it (along with the DOWN tag) to the list of dead hidden services.
  • The general idea of the remaining four service states below is that, if the Hidden Service Descriptor is available, and something is responding behind it… the service is considered up, and we track that fact on the Main Page. If any of these subsequently go offline, append the DOWN tag and handle as above.
  1. Hello world’s / statements, minimal sites, services with low user activity, etc (while boring)… are listed as usual.
  2. Broken services are those that display 404 (and do not use a known hosting service), PHP or other errors (or they fail silently)… any of which prevent the use of the service as intended. They also include blank pages, empty dirs and neglected status notes. Presumably the operator is in limbo. Broken services are tagged with ‘ (reason) – Broken YYYY-MM-DD’ (your guess as to when it went broken)
  3. Services that automatically redirect to another service (such as by HTTP protocol or script), have their redirection destinations noted in their descriptions. These are tagged with ‘ – Redir YYYY-MM-DD’ (your guess as to when it went redir)
  4. Sites that are formally closed via announcement are tagged with ‘ – Closed YYYY-MM-DD’ (your guess as to when it went closed)

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Kerb on Security Interview:

Black Market : Tales from the underground

http://www.zdnet.com/blog/security/q-a-of-the-week-tales-from-the-underground-featuring-brian-krebs/12414

ATM skimming

ATM skimming is proliferating, next to the overall availability of bank plastic cards, holograms and pretty much everything a carder needs to cash out the fraudulently obtained credit card data. From ATM skimmers with bluetooth notification, to ATM skimmers with SMS notification, what are some of the latest innovations in this field that you’re observing?

Brian: One innovation in skimming that I wrote about recently is that crooks are starting to turn to 3D Printers to make these devices. An investigator in California shared with me some photos of was was believed to be a 3D printed skimming device, which was the news hook for that story. But as I was researching the topic, I discovered that a skimmer gang had recently been convicted of creating skimming devices made with a 3D printer they had purchased with the proceeds of their previous skimming crimes.

pharmaceutical affiliate networks

Brian: I think there are a few trends emerging, and they all have to do with the fact that it’s getting harder for rogue pharmacies to make money. One is a shift toward more generic and herbal medications. The affiliate programs seem to be looking for drugs to sell that don’t incur intellectual property violation cases, which can get them shut down in a hurry. But I think it is becoming much harder for the larger volume spam and scareware affiliate programs out there to retain reliable processing, and that’s a long overdue but welcome development.

Eastern Europe is the epicenter of the cybercrime epidemic

Brian: If you mean financially-motivated cybercrime that affects the rest of the world, I would say without question hackers in Russia and Eastern Europe are the most active, if not also the most profitable. I think there are cases where (dis)organized crime groups have and are conducting a lot of cybercrimes, but many of these sophisticated groups tend to be regional and stick to attacking their own (Brazil is a good example).

But generally speaking I think it is a mistake to try to measure cybercrime by actual losses, which almost never comes close to the real losses and damage done by cybercrime, costs incurred by software and hardware and personnel defenses, etc. Don’t get me wrong: I strongly believe that all nations should be working harder to quantify and publish data about cybercrime losses, particularly in the financial sectors. But the reality is that even some of the most active criminal groups — such as the rogue pharmacy “partnerka” programs like SpamIt and GlavMed and Rx-Promotion — employed some of the biggest botmasters with the biggest botnets, and while some of them made a lot of money, most did not. And the spam partnerkas are excellent examples of cases where there are huge asymmetries between their earnings for these activities and the tens of billions of dollars companies and individuals need to spend each year to try to block all of its attendant ills.

active malware/crimeware campaigns:

I think we can continue to expect to see Microsoft doing whatever it can to disrupt cyber criminal activity, because 95 percent of it or more is aimed squarely at their customer base. Whether the gains from those take downs and targeted actions have long or short-term consequences may not be so important to Microsoft. From my lengthy interviews with Microsoft’s chief legal strategist on this subject, it was clear that their first order of business with these actions is raising the costs of doing business for the bad guys, and I think on that front they probably will succeed in the long run if they keep going after them as they are.

cybercrime ecosystem – sophisticated cybercriminals

I consider it a badge of honor that these guys bother to thumb their noses at me. The most recent one I’m aware of was whoever was in charge of coding the Citadel Trojan added some strings in the malware that said, “”Coded by BRIAN KREBS for personal use only. I love my job & wife”. Sort of a friendly jab and a vague, nonspecific threat rolled into one. Sometimes it is just kids looking for attention, but by and large I think most of these guys truly resent having any outside light — especially from “amers” or Americans — shed on their operations. They also don’t like it when you distill their operations, norms or processes into bite sized chunks that demystify their ecosystem or forums.

I can’t speak for law enforcement activity, but as a journalist and investigative reporter, I’m always sad to see these communities go away. I think it’s safe to say that most of them are already infiltrated by several national law enforcement organizations. I’d be very surprised if they were not. Some operating right now probably were even set up by law enforcement. We’ve seen them do that a few times before. I think most of the fraudsters who’ve been doing this long enough probably understand that and act accordingly. Others do not, and that is why you tend to see lots of people come and go, but the same core group of a few hundred guys are the top dogs on most important forums.

Communities and crime forums are great places to learn intelligence about upcoming and ongoing attacks, breaches, 0days, etc. Shutting them down seems to me to be counterproductive, since you almost always force the forums to go more underground and use more security features to keep untrusted people out, and known sources of intelligence go away, or worse yet change their nicks and contact info and all of a sudden a source you have developed you may never see or hear from again.

Risk-forwarding cybercrime ecosystem

the rise of money mule recruitment

Brian: I’ve identified quite a few distinct money mule recruitment networks. I don’t know about templates, but many of them tend to recycle the same HMTL content and change the names of the fake companies. That’s handy I guess for keeping track of which group recruited which mules, but beyond that I’m not sure it tells you much. What I have noticed is that money mules are the bottleneck for this type of fraud, and often
times the cyber crooks will leave money in the victim’s account because they simply didn’t have enough mules to help them haul all of the loot. So with any one victim, it’s typical to find mules recruited through 4-6 different mule recruitment gangs, because the fraudsters who outsource this recruitment will simply go from one to the other purchasing the services of these recruitment gangs until they’ve got enough to help them haul the loot, or they’ve exhausted the available mule supply. But usually, the mule gangs don’t have any problem finding new recruits.

Are reshipping mules more popular than money mules 

Brian: I think reshipping mules tend to be more useful. Most regular money mules are one-and-done. They’re used for a single task and then discarded (although one group I am following re-uses money mules as many times as they can before the mule starts to ask for their monthly salary). Typically, a reshipping gang will get 3-5 packages reshipped per weekday per mule, and the average reshipping mule works for 30 days before figuring out they’ve been working for free and great personal risk and they’re never going to get paid, or the check they got from their employer just bounced. But several mule gangs I’m aware of do both reshipping and money mules interchangeably.

Online gambling

advanced persistent threats (APT attacks)

Brian: I think if there has been a net positive about the shift in focus (at least from the mainstream security industry) away from traditional threats to APT attacks it is in the increased attention paid to social engineering attacks, which form the basis of most successful attacks today. 0day threats get a lot of press and are frequently associated with APT attacks, but it is far more common for these attacks to leverage known vulnerabilities for which there are patches, much like exploit packs that are used in many Zeus attacks and other more traditional cyber crimes. Unfortunately, educating users about what not to click on or trust or open is always an uphill battle. There are some things that companies could be doing more on this front, and I’d like to see more firms randomly test their employees to help speed the process of learning how not to fall for phishing and social engineering scams.

scareware industry, scareware remains one of the most profitable monetization strategies within the cybercrime ecosystem

Brian: I don’t think scareware is the same scourge it used to be, although it’s clearly still a problem. I would say this problem — like the pharma spam problem — must be attacked at the payment processing point; that is where it makes the most sense. There are some things afoot in the payment processing space that I think will probably start to show major results in the coming months on this front, but the proof will be when the scareware partnerka programs start dying off completely because the business model has dried up. I think we can expect to see the costs of acquiring banks taking on this business continue to rise, and that will help make the scareware industry less profitable and less attractive for scammers.

like the pharma spam problem

 

Share on TumblrSubmit to StumbleUponhttp://uscyberlabs.com/blog/wp-content/uploads/2012/06/deepweb_map2-341x1024.jpgDigg ThisSubmit to reddit
05/30/12

Hide SCADA in the ToR network – ..-hiding in plain site..

Hide SCADA in the ToR network – ..FREE-hiding in plain site..

any internet connection 2-ToR

gAtO cAn -now provide your company a FREE .onion network – reliable 24/7 secure / encrypted / untraceable communication between your SCADA systems talking to each other and the main office giving you real-time data from any remote SCADA  site. As an example from Scheider Electric white paper on – Video Surveillance Integrated with SCADA – White Paper  – we can now take that physical video security of all your remote video assets and transmit them securely, encrypted and untraceable to anyplace in the world to your datacenter. When going in and out of the invisible .onion network, you can control the entry and exit relays so picking safe verified relays to use is easy, or you can use your own relays, the more relays the better the system becomes at making you more invisible. The more people that use it the more untraceable and unmonitored it becomes. This kind of SCADA  communication in the ToR- onion network redefines geo-political digital boundaries. Since it rides on any Internet connection it can be used anywhere.

in the ToR-.onion network merchants can’t spy on you and they can’t steal your information

Not if but when —business take over the ToR- .onion network it will change the landscape and give it more order but it will still give the user anonymity thats the key to this network your signal, your voice cannot be found but you can still communicate. The ToR- .onion network rides not on top or the bottom of the digital super-highway but thru it.

Let’s keep in mind that access to the ToR-.onion network is FREE to anyone and your company’s use of the network makes it safer for everyone since the more people use it the more unreachable-undetectable you become. But in business you also have to deal with hostile governments and protecting your people and assets thru a ToR .onion network becomes even more critical. You can still operate but be safe and secure in your business communications.

The ToRProject.org is something that is making an impact on the very lives of people that want to have a free safe secure voice. Just look at Mr Chen a dissident from China he was jailed because he spoke up about the disable in China. The ToRProject.com helps people like Mr. Chen speak and to remain in anonymity. But by adding real business -reays into the ToR- .onion network we will give these people and the business more transparency, it makes you more invisible on the internet. You can donate to the ToR project and it’s a 501(c), so it’s deductible. Look at the donors list and see who support this invisible network. U.S Naval Research, National Science Foundation- DARPA – National Christian Foundation are some of the people supporting the ToR Project, it’s not so bad if they use it— see lab Notes below -

How you gonna hack what you can’t find, can’t see and can’t trace to you?

Just think mr. bankers a free secret untraceable encrypted-communication place were you can do your banking deals -in secret- and nobody but you and your closes friends know it even exist, not the government, not your spouse and harder for criminals to find your valuable data. It hides you in an Internet bubble of packets were nobody knows who you are or how to find you. Try can’t even tell it’s a ToR- .onion network it hides it’s signal to blend into the bit’s and bytes of the landscape in the digital noise.

Technically it pretty cheap get the free software as many copies as you need FREE!!! No volume pricing no updates FREE!!! Once your computer that talks to the internet hooks up to a ToR- Relays it’s in the matrix. If you add your own ToR-Relays you can use trusted Relays as entry and exit nodes into the ToR-.onion network so you can let the program use it randomness or choose a path into a FREE invisible communication media accessible from any Internet connection. -

The ToRProject.org is currently still fighting censorship and monitoring in China, Iran, Syria and others were people are being killed and sent home in small boxes to their relatives. Because that person could not use a ToR-network access to his gmail account that was monitored they showed him his emails and his guilt and killed him. That’s how brutal it can become if you cannot have a safe secure access to a basic email to communicate with the world. Government will kill you for what you say. Donate to the ToRProject.org

It’s easy -if all else fails call the gAtO I can help your business become invisible in/on the Internet- gATO oUt.

We use the ToR network for all communication in SCADA systems.  Here are a few SCADA White papers try them with ToR- .onion Networks.

 

lab Notes— gAtO 5/29/12

Tor: Sponsors

The Tor Project’s diversity of users means we have a diversity of funding sources too — and we’re eager to diversify even further! Our sponsorships are divided into levels based on total funding received:

Magnoliophyta (over $1 million)

Liliopsida (up to $750k)

Asparagales (up to $500k)

Alliaceae (up to $200k)

  • You or your organization?

Allium (up to $100k)

Allium cepa (up to $50k)

Past sponsors

We greatly appreciate the support provided by our past sponsors in keeping the pre-501(c)(3) Tor Project progressing through our ambitious goals:

WiKi-Pedia

http://en.wikipedia.org/wiki/SCADA

SCADA (supervisory control and data acquisition) generally refers to industrial control systems (ICS): computer systems that monitor and control industrial, infrastructure, or facility-based processes, as described below:

  • Industrial processes include those of manufacturing, production, power generation, fabrication, and refining, and may run in continuous, batch, repetitive, or discrete modes.
  • Infrastructure processes may be public or private, and include water treatment and distribution, wastewater collection and treatment, oil and gas pipelines, electrical power transmission and distribution, wind farms, civil defense siren systems, and large communication systems.
  • Facility processes occur both in public facilities and private ones, including buildings, airports, ships, and space stations. They monitor and control HVAC, access, and energy consumption.

A SCADA system usually consists of the following subsystems:

  • A human–machine interface or HMI is the apparatus or device which presents process data to a human operator, and through this, the human operator monitors and controls the process.
  • A supervisory (computer) system, gathering (acquiring) data on the process and sending commands (control) to the process.
  • Remote terminal units (RTUs) connecting to sensors in the process, converting sensor signals to digital data and sending digital data to the supervisory system.
  • Programmable logic controller (PLCs) used as field devices because they are more economical, versatile, flexible, and configurable than special-purpose RTUs.
  • Communication infrastructure connecting the supervisory system to the remote terminal units.
  • Various process and analytical instrumentation

 

Share on TumblrSubmit to StumbleUponhttp://uscyberlabs.com/blog/wp-content/uploads/2012/05/Scada_Comm_01-300x258.pngDigg ThisSubmit to reddit
05/27/12

Information Leakage -Scrubbing Document Formats

gAtO tHiNk - that our documents have too much information about us – it’s called metadata  and it’s embedded in the picture you just took with your iPhone/android phone. It has your geo-location and other information that you should clean up before you post it on Facebook  or Pintrest -so here a re a few tips to keep you paranoid.

Many document formats conveniently embed personally identifying attributes, and sometimes even attempt to limit redistribution. This can be problematic to whistle blowers who need to produce/deliver incriminating memos and photos to journalists, and also to academic researchers who wish to electronically publish their work anonymously.

 Microsoft Office

Microsoft Office embeds your name, machine name, initials, company name, and revision information in documents that you create.

According to Microsoft’s knowledge base article on the Metadata, the best way to remove all personal metadata from a document is to go to Tools | Options | Security Tab | “Remove personal information from this file on save”. Be warned that this does NOT remove hidden text and comment text that may have been added, but those tasks are also covered in that article.

Microsoft also provides the Remove Hidden Data Tool that apparently accomplishes those same functions but from outside of Microsoft Office.

This NSA Guide to sanitizing documents might also be of some interest, but I think the Microsoft KB articles cover the info better and in more depth.

StarOffice/OpenOffice

By default, users of StarOffice/OpenOffice are not safe either. Both of these programs will save personal information in XML markup at the top of documents. It can be removed by going to File | Properties and unchecking “Apply User Data”, and also clicking on “Delete”. Unfortunately it does not remove creation and modification times. It’s not clear how to do this without editing the file raw in a plain text editor such as notepad.

 Document DRM – Digital Rights Mangement

Document DRM can come in all shapes and sizes, mostly with the intent to restrict who can view a document and how many times they can view or print it (in some cases even keeping track of everyone who has handled a document). For whistleblowers who need to circumvent DRM to distribute a document, the most universal approach is to use the “Print Screen” key to take a screenshot of your desktop with each page of the document and paste each screenshot into Windows Paint and save it. Some DRM software will attempt to prevent this behavior. This can be circumvented by installing the 30 day trial of the product VMWare Workstation and installing a copy of Windows and the DRM reader onto it. You can then happily take screenshots using VMWare’s “Capture Screen” or even the “Capture Movie” feature, and the DRM software will be none the wiser. With a little image cropping, you can produce a series of images that can be distributed or printed freely.

The VMWare approach may be problematic for DRM that relies on a TPM chip. The current versions of VMWare neither emulate nor provide pass-through access to the TPM. However, TPM-based DRM systems are still in the prototype stage, and since it is possible to emulate and virtualize a TPM, it should only be a matter of time before some form of support is available in VMWare.

Depending on the DRM software itself, cracks may also be available to make this process much more expedient. Casual searching doesn’t turn up much, most likely due the relative novelty (and public scarcity) of document-oriented DRM. Note that when doing your own google searching for this type of material, be sure to check the bottom of the page for notices of DMCA 512 takedowns censoring search results. It is usually possible to recover URLs from chillingeffects’ C&D postings. That, or use a google interface from another country such as Germany.

 Image Metadata

Metadata automatically recorded by digital cameras and photo editing utilities may also be problematic for anonymity. There are three main formats for image metadata: EXIF, IPTC, and XMP. Each format has several fields that should be removed from any image produced by a photographer or depicting a subject who requires anonymity. Fields such as camera model and serial numbers, owner names, locations, date, time and timezone information are all directly detrimental to anonymity. In fact, there is even a metadata spec for encoding GPS data in images. Camera equipped cell phones with GPS units installed for E911 purposes could conceivably add GPS tags automatically to pictures.

The WikiMedia Commons contains a page with information on programs capable of editing this data for each OS. My preferred method is to use the perl program ExifTool, which can strip all metadata from an image with a single command: exiftool -All= image.jpg. MacOS and Linux users should be able to download and run the exiftool program without any fuss(for Ubuntu install package libimage-exiftool-perl). Windows users will have to install ActivePerl and run perl exiftool -All= image.jpg instead. Running exiftool without the -All= switch will display existing metadata. The -U switch will show raw tags that the tool does not yet fully understand. As far as I can tell, the -All= switch is in fact able remove tags that the tool does not fully understand.

Another easy way to remove all metadata from an image it to open it in MS Paint, copy it, and paste it into another copy of paint. The Windows clipboard only copies the raw pixels and leaves the metadata behind. -gAtO oUt

Share on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
05/19/12

Social Engineering XBox Live Accounts

gAtO FoUnD – These in the deepWeb and though people can see Social Engineering (SE) basics. They are right in a way if you keep calling support you will eventually get someone that does not give a shit and give you the information you need. These same SE tactic’s will work on just about most Internet based games and other accounts online: – gAtO oUt —–

It is illegal to do thing like this to gain access to other people accounts, do not try this at home kiddies…

Plan # 1 — How to DOX & Reset Xbox Live accounts: 

1. Start off by calling 1877-438-9863 (Zune). Press 0 and wait to be transferred to an operator. Once you’re transferred to an operator tell them this: “I’m trying to sign into the Zune software but I forgot the email address I used to sign in.” They will ask for your name (Provide any name you want) and phone number. When they ask for the phone number to pull up your account, say you don’t remember it. Ask them if they will pull up your account using your ZuneTag. Give them the GamerTag you want the info on.

2. Once it’s confirmed that the account is pulled up, they will ask you for the secret answer/ billing info. Tell them this: “My Dad made my account and I don’t know what information he put on it. Can I please call back when he gets home? Could you also provide me a case number?” Once the agent says they’re generating you a case number tell them this: “Can you please attach my account to the case number so when I call back they can pull it up right away?” If they say Yes, you call has been a success. If they say no, hang up and call again.

3. Once you’ve obtained the case number call 1866-727-2338 (PC Safety) and press “1″ (10) times until you’ve reached an operator. Once the operator picks up, they will ask for your name and case number. Say this: “I have a case number.” So you don’t answer the question where they ask for your name. Once it’s confirmed that the case number is pulled up say, “I’m calling regarding an Anti-Virus software link I was supposed to receive in my email, but I never got the email. The last agent I spoke to said he would email it to me. Can you please repeat the email back to me so I can make sure it wasn’t mispelled by the last agent?” They will read off the email. Then say: “I want to make sure this is the right case, can you verify the name?” They will read off the name. Slowly ask for all the other information. This may take a few calls! Once you have the Full Name and Zip Code, you can Google the Zip Code and find the state. Then go to WhitePages.com and search with the info you got. Call PC Safety back and verify it. If it’s not right, keep trying until you get an agent who spills the address.

Your call has been a success and you know have all the info to an Xbox Live account except the password. To retrieve the password, go to Google and search “Windows Live Validation Page” and click the first link then follow the steps. PLEASE VIEW BELOW! THIS IS VERY HELPFUL WHEN CALLING IN!

——————————————

Name:

City:

State:

Zip:

Phone:

Email:

Alt:

 

Plan #2 —- How to dox an Xbox 360 account. –

Disclaimer: I  have no involvement in what you do with this. I am not saying doxing accounts is a good thing, I am only trying to make some money. During this eBook you will be discovering how to gain someone’s personal information via Xbox Customer Support. (UK/US/CA/AUS). This eBook does contain one rule you do not dox any accounts from this list (http://cl1p.net/originalgamertag/). This is a warning; bad things will happen if you do.

I will not help you reset the tag.

 

So let’s get started!

Numbers:

Microsoft PC Support: +18667272338

Xbox LIVE Support (United Kingdom):  +4408005871102

Xbox LIVE Support (United States):  +18004699269

This tutorial is going to be colour coded.

 

What you are actually going to be doing.

During this eBook you are going to be learning a very valuable skill. You are going to be learning how to dox an Xbox LIVE account via Xbox Customer Support. Throughout this tutorial you are going to be learning what to do and what not to do. It’s always best to learn about some of the stuff in this tutorial before you actually go and perform it.  You are going to need a reference number from Xbox Customer Support (this will be explained further into the eBook).  This is probably the most important part of this entire eBook as it is the key to getting a successful dox.

Step 1: Getting a working reference number.

From reading above, you will probably have learnt the importance of a reference number.  This is probably the hardest thing to do without the entire eBook. You need to be careful as the representatives are sneaky and will just give you a non-working reference number. Therefore you need to get a fully working one. You may ask yourself how? This is how:

Conversation: (between you and the support representative, he/she’s colour will be in green your colour is red).

1/ Call Xbox Customer support (the correct number for your region) and hit the number two on the keypad five times. This is going to put you straight through to a support representative.

“Hello, thank you for calling Xbox Customer Support my name is Monster how may I help you?”

“Hello Monster, my name is (yourname) and I’ve been having some issues with a reference number that I received earlier from one of your colleagues.”

“Oh sorry (yourname) is it possible to get that reference number quickly? “

“Sorry no, I threw it away since it didn’t work.. I’m sorry I never knew I had to keep it.”

“That’s okay (yourname) what is the gamertag on the account?”

(Here you say what gamertag you are trying to dox..)

“The gamertag is (gamertag you are trying to dox)”

“Okay, just give me a second to pull that up.”

“Okay, thanks.”

“Okay, I’ve got the account. Can we go through a few verification steps if you don’t mind?”

“Yeah sure.”

“Okay then sir, what is the first name and email address on the account”

“Yes the email address is: randomemail@me.com and the name is ‘random’.

“Oh, I’m ever so sorry. I need to dash off back to a personal family meeting. Is there any way I can grab a new reference number, one that actually works?”

“Oh. Okay then sir, just give me a moment. (Here is where they are attaching a reference number to the account). Okay this is your reference number:  (It should start with the numbers ‘115’ and is 10 – 15 digits long).

“(Repeat the reference number so they can confirm it) Thanks! I will definitely

Call back later, thanks for being such a great help (Dox)!”

“No problem sir, thanks for calling Xbox Customer Support and have a great day.”

Step 2: Using the reference number you just got from Xbox Customer Support.

Okay, so if you got this far, congratulations! You are one step closer to doxing an Xbox LIVE account. What you want to do is call Microsoft PC Support (number at the first page of the Book) and once you hear the robot on the phone; press the number one five times. This will put you straight through to a representative, you may be on hold for a while as they do get a lot of calls an hour. In the usual style of this eBook I will do a conversation log like normal. Just some tips for you here:

Give them the reference number and no name, so when they say (again green representative colour) “Hello, thank you for contacting Microsoft PC safety what is your case number and name please?” You just want to say the case number (reference number).

And you want to say “Hello, I was told to come here so I can make sure the information on my account is correct. As my brother made the account and he is recently deceased”.  This will make them feel sympathetic towards you and they will try to make you happy.

Same colours as before, you are red and the support rep is green.

“Hello and welcome to Microsoft PC safety, what is your name and case number?”

“Hello and my case number is: (say your reference number)”

“Okay sir, what seems to be the problem?”

“I just need to verify the information on my account, as it used to be my brothers account but he is now deceased.”

“Okay sir, I’m sorry to hear that. What information would you like to verify?”

“I just need to make sure the name on the account has changed properly, as I called earlier to get it changed but I lost the connection with the representative.”

“Okay sir, just one moment.”

“Okay the name on the account is..”

 

Okay, the conversation above is recorded with a representative that doesn’t know the Microsoft policy. If you get one that does just put the phone down and keep calling. You will get it.

The representative that normally gives out information is called: Shackeel. By having the name of the account owner, you can put the phone down and call back. This way when you re-call you won’t have to do any verification steps, they will just hand the account information over.

There will be many updates on this eBook as time goes by. To receive an update you must PM me on HackForums with the transaction ID.

By leaking this eBook, you do not get free updates. This way I can stop people from leaking my hard work. I do not condone in this in any way, shape, or form. I am just trying to make some money.  The next update will be in around a week so make sure you PM me! (Make sure the PM title is the transaction ID).

 

 

 

Share on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit