![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]()
|
![]() |
next newest topic | next oldest topic |
Author | Topic: Clever scam executed stupidly |
EngrBohn Highlie ![]() ![]() ![]() ![]() Posts: 742 |
![]() ![]() ![]() ![]() ![]() Yesterday, we got a call from our bank regarding a suspicious $18.42 charge dated 15 April. Apparently, the bank's system was recently cracked, and the intruders managed to obtain several card/authorization combinations. Not all of them were valid, but some were. And so the thieves decided to use an online payment system to steal small amounts of money from each card. After all, a small, non-round number like $18.42 could easily be dismissed when reviewing the account as something we forgot about. And doing it over ~500 cards yields almost $2000 booty for a day's "work". Clever scam. But the bank caught on pretty quick when 500 cards each had a charge of $18.42 to the same place in a single day. So we told the bank which recent charges should be approved, cancelled the card number, and are getting a new card FedEx'd to us. ------------------ IP: Logged |
Miles Geek ![]() ![]() ![]() Posts: 68 |
![]() ![]() ![]() ![]() ![]() ![]() "It almost worked, Pinky! Next time don't sit on the ENTER button, just push it." "Ha, ha, NARF!" "Well, we better rest up for tomorrow night." "Why, what are we going to do tomorrow night, Brain?" "The same thing we do every night: TRY TO TAKE OVER THE WORLD!" IP: Logged |
GameMaster Super Geek ![]() ![]() ![]() ![]() Posts: 174 |
![]() ![]() ![]() ![]() ![]() might have worked if they chose different amounts... They didn't notice some one hacked their system? Don't get a new card, get a new company. IP: Logged |
macadddikt18 SuperBlabberMouth! ![]() ![]() ![]() ![]() ![]() Posts: 1387 |
![]() ![]() ![]() ![]() ![]() It does strike me odd, that they did not see that someone had hacked it, but that they did see, the amounts. If i was a hacker i would have done different amounts as well. I agree, you should get a new bank, but hey, such is the world we live in. Nayt ------------------ IP: Logged |
Rednivek Super Geek ![]() ![]() ![]() ![]() Posts: 147 |
![]() ![]() ![]() ![]() Yes, tell Mr Drysdale that you're going to another bank. IP: Logged |
rw Super Geek ![]() ![]() ![]() ![]() Posts: 213 |
![]() ![]() ![]() ![]() ![]() Well, the bank made a mistake (they got hacked) and the hackers made a mistake (they got caught). I think it's interesting that we all know exactly what the hackers should have done, but we have no advice for the bank. We jus say "get a new bank", and hope that the new one knows something we don't. IP: Logged |
+Andrew Super Geek ![]() ![]() ![]() ![]() Posts: 220 |
![]() ![]() ![]() ![]() ![]() quote: The advice to the bank would be pretty simple and obvious: implement secure computer systems. But that's their job. They're supposed to know that and be doing it already. -Andrew IP: Logged |
TheAnnoyedCockroach Alpha Geek ![]() ![]() ![]() ![]() Posts: 282 |
![]() ![]() ![]() ![]() ![]() I've got a great idea for the bank... Use Linux. ------------------ IP: Logged |
macadddikt18 SuperBlabberMouth! ![]() ![]() ![]() ![]() ![]() Posts: 1387 |
![]() ![]() ![]() ![]() ![]() I have a better idea. Use mac os x. Power and security of unix, with a beautiful GUI. That way anyone can use it. Nayt ------------------ IP: Logged |
EngrBohn Highlie ![]() ![]() ![]() ![]() Posts: 742 |
![]() ![]() ![]() ![]() ![]() Before this kicks off an OS holy war, I'd like to point out a couple obvious aspects to cracking systems: - Free software does not make a system secure. There is plenty of evidence that there are security flaws in free software. The difference, of course, is the turn-around time between identification and correction, and the ability of people outside the development organization to review the code for errors (as opposed to black- or gray-box discovery). - No software can overcome the human element. -- If the administrator does not apply the appropriate patches, then it does not matter that the security flaw has been fixed, since the fix isn't on the system. -- If users are careless with their passwords... Of course, I don't know what the particular vulnerability was that allowed their system to be cracked. It might have been the human element, or it might not have been. It might be that the system was running the tightest known NetBSD configuration possible and that the cracker discovered some before-now unknown buffer overflow and chose to exploit it and not announce it through Bugtraq, or it might be running WinNT 3.5 with software that hasn't been upgraded since 1996. In the absence of facts, trying to simplify the problem to that of a particular OS, or even to that of software, is likely to make you end up looking foolish. ------------------ IP: Logged |
Oldguy geek Alpha Geek ![]() ![]() ![]() ![]() Posts: 309 |
![]() ![]() ![]() ![]() quote:
IP: Logged |
garyi Single Celled Newbie ![]() Posts: 1 |
![]() ![]() ![]() ![]() ![]() In england not too long ago a cash machine appeared in a town down south. However it wouldn't tend, it would allow you to enter your pin but would then say the machine was out of cash. It was actually a scam set up by a group of people. They bought the rent on the building in the high street, installed a cash machine which was patched straight to the web, every pin that was entered was sent down a modem with all relevent info pertaining to the persons card. The scammers then created new cards with a magnetic strip with the pin on, then off to a proper machine to draw moneies, they got away with over 180 grand before someone got suspicious of the cash machine never vending. clever sods. IP: Logged |
dragonman97 Super Geek ![]() ![]() ![]() ![]() Posts: 193 |
![]() ![]() ![]() ![]() ![]() Cockroach: I commend you for your wise words. Nayt: Why on earth would you need Aqua on a server?! Garyi: Interesting story; I admit that this thought had crossed my mind, but I am not malicious/evil enough to use my skills in that fashion. IP: Logged |
GameMaster Super Geek ![]() ![]() ![]() ![]() Posts: 174 |
![]() ![]() ![]() ![]() ![]() Linux is safer than Unix or MacOS because of it's open source. It means when a explotation is discovered, some one from the public jumps on it to save his ass, and it is out before a copany can realse it. I seem to remeber several exsamples. The reason why we simply say "get another bank" is because banks jobs are to be secure, and if they didn't realize a hack, they dropped the ball. Without knowing how the exploit happened can anyone really offer any "should have done this" advice to the bank? This reminds me of the rounding worm... every time calculations with money happen, there is often a fraction of a cent left over, and if you store those fractions of a cent in a private swiss bank account, you could amass a large sum of money that no one would think to miss. Unfortunatly, the idea spread a bit, and got put in a few movies and now companies watch their fractions of cents closely. IP: Logged |
MightyJoeSakic Geek Larva ![]() ![]() ![]() Posts: 23 |
![]() ![]() ![]() ![]() ![]() Why do intelligent people have such problems pulling off crimes? lol I mean if you look at this thing....they were at least intelligent enough to figure out how to crack the bank's computers, but then screwed up on the little details. Stupid people on the other hand are always pulling off crime sprees....maybe the old tried and true "Stick'em Up!" works better. *shrug* I guess most of them end up getting caught in the end anyway so I might as well worry about something more important like how to get home while avoiding direct contact with the "daystar" outside... ------------------ IP: Logged |
All times are Pacific Time | next newest topic | next oldest topic |
![]() ![]() |
© 2002 Geek Culture® All Rights Reserved.
Powered by Infopop www.infopop.com © 2000
Ultimate Bulletin Board 5.47e
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |