Magecart Hackers Perfect Fake Checkout Pages

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ต.ค. 2024

ความคิดเห็น • 118

  • @shapelessed
    @shapelessed ปีที่แล้ว +193

    Virtual credit cards just keep looking more and more like a compelling option...

    • @hydrochlor
      @hydrochlor ปีที่แล้ว +23

      This type of fraud may be reduced if more nations adopted Strong Customer Authentication as a legal requirement, for example, in the EU. It's similar to two factor authentication in that it doesn't matter if a hacker has your card details because a digital payment with the card can't be done without, say, an electronic id, a personal pin code, or a 2fa text message to the card's owner's phone.
      You could argue that the hacker could simply create a fraudulent popup to force you to fill out the form, but the process always takes you to your bank's website, where you must complete the 2FA. Furthermore, the bank informs you of the destination of the payment as well as the amount of the transaction. Once the two-factor authentication is complete, you've only granted your card for that one specific transaction, for that one amount of money, and no others.

    • @trashfireblog5147
      @trashfireblog5147 ปีที่แล้ว

      Or... you know.. cryptocurrency?
      Bring security to ALL payments, and discard the global banking cartel in the process.
      There is no card. You scan a QR code, and approve the payment from your wallet. Simple as that.

    • @UmVtCg
      @UmVtCg ปีที่แล้ว +13

      @@hydrochlor I'm in the EU. Now, in my country we rarely use creditcards. Services like iDeal which use a debit card and paypal are more popular here. Let's be honest, the US with their magnetic strip credit cards are way behind the curve.

    • @tonyrex99
      @tonyrex99 ปีที่แล้ว +11

      @@hydrochlor I was suprised to find out that american cards don't have a one time pin for every transaction. Its common here in Africa, the pin can be generated thru hard token, sent to your phone or through bank app.

    • @mb00001
      @mb00001 ปีที่แล้ว +1

      ​@@hydrochlor Barclays in the uk has had PinSentry for quite a while, its a multi purpose 2fa, but it's not used for card transactions 😂

  • @thoughtfulwaffler
    @thoughtfulwaffler ปีที่แล้ว +41

    Magecarts sabotaging one another is actually funny

  • @TheColinputer
    @TheColinputer ปีที่แล้ว +17

    For years i have been using a dedicated debit card for online stuff. I just transfer money from another account into it when i want to buy something. The rest of the time it only has about 10-20$ in it to cover things like icloud subscriptions etc.

  • @SameAsAnyOtherStranger
    @SameAsAnyOtherStranger ปีที่แล้ว +63

    Since day one, or back when the internet was revealed to be as vulnerable as it is in the nineties, credit card companies have done so little to make information transfer secure. Just watching this video, I thought of a security feature which would thwart this kind of attack. Depending on the average frequency of transactions, a cc company could essentially "ping" transactions at odd intervals and insure that the transaction is processed through the proper channels. But like all financial instruments, credit card companies are relieved of responsibility before anyone else. But keeping criminals fat and happy is probably what has kept the U.S. financial system afloat. It certainly is criminal to turn the onus of opsec into an externality by shifting it to the consumer or the retailer.

    • @Seytonic
      @Seytonic  ปีที่แล้ว +30

      To add to that, credit card companies charge an "admin fee" to retailers for each chargeback. I wouldn't be surprised if they were making more money than they are losing from fraud.

    • @error-42
      @error-42 ปีที่แล้ว

      Or maybe the simpler solution: you tell your cc company to give the marketplace the money; and not tell the marketplace info to take all the money from you, possibly later.

    • @the_steamtrain1642
      @the_steamtrain1642 ปีที่แล้ว

      Idk if credit cards are something mainly used in the US but I've (from NL) have only used a bank card to date, you can set limits on in-store and online transfers and you can require the use of an e-dentifier (device that returns confirmation you have the bank card) for transfers over a certain amount

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      @@the_steamtrain1642 I think NL is a special case, I was so confused in Amsterdam when shops wouldn't accept my Visa Card 😂

  • @Shrek5when
    @Shrek5when ปีที่แล้ว +30

    Cool to see you experimenting with the new format 👍

    • @Seytonic
      @Seytonic  ปีที่แล้ว +8

      Thanks : ) The plan is to have these out more regularly. Sorry the last couple weeks have been slow!

    • @Shrek5when
      @Shrek5when ปีที่แล้ว +4

      @@Seytonicthese videos are always great, I don’t mind the wait 👍

    • @thecrazymoon6578
      @thecrazymoon6578 ปีที่แล้ว +3

      Its quite good

    • @anteshell
      @anteshell ปีที่แล้ว

      So what's the new format compared to the old? I've watched every video for a quite long time and I fail to see any difference, except for the removal of the intro that happened long time ago.

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      @@anteshell New format is a single topic as opposed to multiple topics in a single video

  • @georgeprout42
    @georgeprout42 ปีที่แล้ว +18

    Interesting how cc numbers sell for as little as 15 cents, which happens to be pretty much the same amount Ticketmaster got fined - 13.3p x 9.4M victims.
    No wonder protecting personal data is such a low priority. The banks would have had to reissue 9.4M cards, include postage costs and that's an order of magnitude greater than the 'fine'...

  • @midimusicforever
    @midimusicforever ปีที่แล้ว +7

    I love how they stabotage one another. It actually is helpful, and also funny.

  • @socialdamage
    @socialdamage ปีที่แล้ว +41

    There is another interesting similiar approach where you fake a Browser inside the Browser window to ask for login details. It even detects if you use chrome or safari and if its windows or mac for the designs. But this Checkout Popup is a wild one!

    • @Seytonic
      @Seytonic  ปีที่แล้ว +14

      I've covered a few cases of that kind of trick. It's damn good, could see myself being caught out by it.

    • @gangsterism
      @gangsterism ปีที่แล้ว +1

      @@Seytonic the fake browser window is good, but you can still spot it but if a website gets hacked your debit card will go goop mode

    • @w花b
      @w花b ปีที่แล้ว

      Saw one with Microsoft login

  • @metcaelfe
    @metcaelfe ปีที่แล้ว +23

    2FA and 3D Secure are essential, but also nullify some claims.
    There is no perfect solution when dealing with e-commerce fraud

    • @dinred_
      @dinred_ ปีที่แล้ว +4

      Every payment processor in the EU is required to have 3d secure enabled thanks to the DSP2 directive, same with India. This is really effective at countering carding, since it's a thing to make a purchase with a stolen credit card, but this becomes nearly impossible when the payment processor requires you to enter a personal code on your own phone before allowing the payment.

    • @alainportant6412
      @alainportant6412 ปีที่แล้ว

      @@dinred_ Right, but Fuck the EU.

  • @gFamWeb
    @gFamWeb ปีที่แล้ว +2

    1. the actual french site is un-redacted for a frame or so in the video
    2. changing just the last number for a credit card won't actually affect much, it's a check digit and can easily be fixed.

  • @s.h.i.e.l.d5893
    @s.h.i.e.l.d5893 ปีที่แล้ว

    Damn dude! Quality is getting too good! And voice overs are just on 🔥 fire!

  • @tobiaskap3274
    @tobiaskap3274 ปีที่แล้ว +9

    Well, Mercadopago it's not a random payment processor, it's probably one of the biggest ones 😂

  • @DJAlexParker
    @DJAlexParker ปีที่แล้ว +22

    Hello, world!

  • @kmcat
    @kmcat ปีที่แล้ว +3

    15£ admin fee for the bank for not spotting a fraudulent transaction on their multibillion pound computer

  • @zacpackman9186
    @zacpackman9186 ปีที่แล้ว +1

    awsome vid mate. are u aware of any protections for this as a customer on these sites.

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      Thanks :) I would focus on making sure damage is minimised if you are caught in something like this, as they're sometimes impossible to spot. Sometimes millions of creds are scooped up before anyone realises.

  • @IamwhoIam333
    @IamwhoIam333 ปีที่แล้ว +3

    5 time's in 9 months I have had to replace my debit card because of this.
    I have ALL kinds of security settings set up with my bank now. I get notices for everything even if it a$1.00 now.
    Fortunately , they have not profited from me yet. It is just very annoying to call all the people who are on prepaid payments for my responsibilities.

  • @diwakar_tsn
    @diwakar_tsn ปีที่แล้ว

    Finally video after long time ❤

  • @huddunlap3999
    @huddunlap3999 ปีที่แล้ว

    Good info

  • @christianbrzeski4132
    @christianbrzeski4132 ปีที่แล้ว +1

    How do the hackers obtain the credit card information when almost all new browser have CORS disabled by default, which prevents data being send from a legitimate website to a fraudulent website?

  • @onemoreguyonline7878
    @onemoreguyonline7878 ปีที่แล้ว

    This sounds like the OG Zeus trojan

  • @daviddaniel4844
    @daviddaniel4844 ปีที่แล้ว

    bring more videos like this

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      Willdo, thanks for watching :)

  • @Obama_
    @Obama_ ปีที่แล้ว +1

    God damn it!

  • @ejonesss
    @ejonesss ปีที่แล้ว +5

    how are the bad actors able to inject the malicious code?
    surely they cant be compromising the buyer's end they have to exploiting a vulnerability in the magento shopping cart software and the server?

    • @antonpetrochenko5188
      @antonpetrochenko5188 ปีที่แล้ว +2

      They are, in fact, compromising the buyer's end for the most part. All they need is an entry point, which in one case was a compromised chat widget. From there, it's as simple as just editing the HTML markup to include their own checkout form. As long as they can load their own JS they can do whatever.

  • @owzzzz3172
    @owzzzz3172 ปีที่แล้ว +2

    New vid Pog

  • @VincentFischer
    @VincentFischer 11 หลายเดือนก่อน

    How often do you guys look at you creditcard while having htop open?

  • @Rerbun
    @Rerbun ปีที่แล้ว

    I'm glad we barely use credit cards in the Netherlands

  • @lucasmenten
    @lucasmenten ปีที่แล้ว

    I can't believe payments without 2fa are still a thing in some places...

  • @jaromir_kovar
    @jaromir_kovar ปีที่แล้ว +4

    thank you for the heads-up! That's crazy. Do I understand correctly that there is no way to tell from a regular end-user's perspective?
    Would it help to always cancel the first payment gateway window that opens and click on the payment again, or not really?

    • @Seytonic
      @Seytonic  ปีที่แล้ว +4

      If you check the Network section of Chrome's DevTools, you can get information on the domains your browser is connecting to, which might reveal a malicious domain. But from an end user perspective, it's often completely invisible.

    • @jaromir_kovar
      @jaromir_kovar ปีที่แล้ว

      @@Seytonic Thank you for your reply and advice. That's scary.

    • @miguelguthridge
      @miguelguthridge ปีที่แล้ว +3

      @@Seytonic This sounds like something that might be better done using a web extension - you could detect payment modals and then when they are submitted, give people a heads up if the request is going to be sent to an unrecognised domain (ie not a major payment processor company, and not the website you're currently on). Obviously there's a big risk of false positives, so you wouldn't want to block it entirely, but having an "it looks like this payment request is going to [website address], do you want to allow it?" could be a great solution, since it's unlikely that bad actors bother buying legit seeming domains for payment processing. At the very least it'd increase the barrier to entry for the bad actors and make them have to spend more time and money to seem legit.

    • @thecrazymoon6578
      @thecrazymoon6578 ปีที่แล้ว +2

      Maybe just put fake info in the first form.

  • @NoahNobody
    @NoahNobody ปีที่แล้ว

    I guess my bank card is now the safest payment method as it requires a pin from a table of stored pins, and also a pin verification sent to my phone.

  • @dburton2765
    @dburton2765 ปีที่แล้ว

    Have you ever found anyone hacking into Amazon? I've not been on your channel long, so not sure.

  • @ggsap
    @ggsap ปีที่แล้ว +2

    Please bring back multi story videos

  • @ThatOneOddGuy
    @ThatOneOddGuy ปีที่แล้ว +2

    If this template had already been used alot so far a new one will appear soon
    You should make a vidoe as a update on the newer ones since that's probably what will be in circulation more since this 1st templete has been noted to be fake

    • @anteshell
      @anteshell ปีที่แล้ว

      This is a youtube video. It cannot be updated to include the latest info when ever it pops up.

    • @ThatOneOddGuy
      @ThatOneOddGuy ปีที่แล้ว

      @@anteshell typed the wrong thing my grammar was a mess

    • @anteshell
      @anteshell ปีที่แล้ว

      @@ThatOneOddGuy No prob. Everyone makes mistakes once in a while. ;)

    • @ThatOneOddGuy
      @ThatOneOddGuy ปีที่แล้ว

      @@anteshell yeah man

  • @SuperNikio2
    @SuperNikio2 ปีที่แล้ว

    Bro really just called the biggest South American e-commerce/payment platform "some random payment processor".

    • @midimusicforever
      @midimusicforever ปีที่แล้ว

      To a random French person, that's what it is.

  • @paxdriver
    @paxdriver ปีที่แล้ว

    I bet gpt mat he'd the css style for the modal in 3 seconds and generated all the common text

  • @whoman0385
    @whoman0385 ปีที่แล้ว

    and thats why its better to just use stripe..

  • @sauliusjance6300
    @sauliusjance6300 ปีที่แล้ว

    I think you should do more than one story because it feels so meah... or make more frequent videos

    • @Seytonic
      @Seytonic  ปีที่แล้ว +2

      More frequent videos 💪 I appreciate the feedback :)

  • @tyrojames9937
    @tyrojames9937 ปีที่แล้ว

    CANCELL myONLINE SHOPPING!😂😂

  • @jamesw9223
    @jamesw9223 ปีที่แล้ว

    Can't steal my card info if I only use cash

  • @reegyreegz
    @reegyreegz ปีที่แล้ว

    Hahaha when i hear this it always makes me laugh 3:40

  • @NithinJune
    @NithinJune ปีที่แล้ว

    Well that’s the last time i don’t use paypal or something

  • @bnk28zfp
    @bnk28zfp ปีที่แล้ว

    finaly new video!!! thanks!!! 👏🇺🇸🇺🇸🇺🇦🇺🇦

  • @gameboyv1790
    @gameboyv1790 ปีที่แล้ว

    Does anyone know how to make a drive by download website

  • @Wish13
    @Wish13 ปีที่แล้ว

    YESSSSS

  • @iraklimgeladze5223
    @iraklimgeladze5223 ปีที่แล้ว

    Still don't get it, how hackers injected there code

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      If you have access to the server you can modify the code running on the website, or add your own

    • @iraklimgeladze5223
      @iraklimgeladze5223 ปีที่แล้ว

      @@Seytonic sure, i understand, but is injection coming unsecure cookies?
      On my site i give authorisation cookie token and small experience date and do prepare statement? Do i need to something more?

  • @afdashtech5322
    @afdashtech5322 ปีที่แล้ว +1

    💀

  • @shaneintegra
    @shaneintegra ปีที่แล้ว +1

    The thing i dont understand is... if they end up stealing your card details. Do they just buy stuff with it and send it to their house? Lol

    • @Seytonic
      @Seytonic  ปีที่แล้ว +2

      Yup, many do. Police won't investigate crimes of small transactions.

  • @synistree
    @synistree ปีที่แล้ว

    Plus high charge back rate means the vendor will be "higher risk" so they get screwed (usually based on % by volume) and sometimes can't find any processors to take them. Jerk move to small businesses

  • @user-xb8sq3xk7x
    @user-xb8sq3xk7x ปีที่แล้ว

    All they did was rip the logo and the stylesheet of the original website 😂

  • @anonazerty165
    @anonazerty165 ปีที่แล้ว +1

    Thank you, the content is good but I honestly really dislike this format. The ratio of sponsors/length of video is insane, and when removing the intro you realize there is like 2 or 3min of actual content.

    • @Seytonic
      @Seytonic  ปีที่แล้ว +1

      This sponsor spot is longer than I would like for this format - though I agreed on the spot before the format change, in the future it won't be as long. There is still 4:46 of content though :) I plan on putting these out on a more regular basis, so it will tally up to more content in general. Thanks for taking the time to leave some feedback :)

    • @anonazerty165
      @anonazerty165 ปีที่แล้ว

      @@Seytonic Thank you I appreciate the response :)

  • @chloeleo
    @chloeleo ปีที่แล้ว +1

    honestly wish the internet adopted crypto as standard payment, yes its got its faults and yes its a volatile market but the ability to create new wallets easily alone sets it way above credit cards but also you being the one that sends the money rather than them pulling the money through gives the buyer much more control.

  • @gmdzbanwic
    @gmdzbanwic ปีที่แล้ว

    fake rayban been up for times on facebook ur lacking now there is bitcoin campaigns mostly

    • @gmdzbanwic
      @gmdzbanwic ปีที่แล้ว

      I wonder how they bypass facebook is it once on check or every 1k hitts and scans ips for location etc

  • @umikaliprivate
    @umikaliprivate ปีที่แล้ว +1

    what if you made a malicious extension that would make a fake popup box, that you would enter your details into

    • @RokeJulianLockhart.s13ouq
      @RokeJulianLockhart.s13ouq ปีที่แล้ว +1

      What do you mean what if? You'd have made a malicious extension that you would enter your details into.

    • @umikaliprivate
      @umikaliprivate ปีที่แล้ว

      @@RokeJulianLockhart.s13ouq you could just disguise it as an adblocker or something

  • @honeypotts5125
    @honeypotts5125 ปีที่แล้ว

    Idk what's different, but I like your videos a lot less these days...

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      Do elaborate if you can, was the topic not to your liking?

    • @honeypotts5125
      @honeypotts5125 ปีที่แล้ว

      Stuff lately I suppose feels "low-stakes".I guess I'm just another sensationalism seeking simpleton. I'm not unsubbing. Just noticed the last few vids didn't hit the spot like usual. Whatever the case, didn't mean to offend.

    • @Seytonic
      @Seytonic  ปีที่แล้ว

      ​@@honeypotts5125 No offence taken, was just curious to know more. But yea, in fairness news has been a bit slow recently. Next one should be good though :)

  • @duckqlz777
    @duckqlz777 ปีที่แล้ว

    I hate 1 topic videos...

  • @morsine
    @morsine ปีที่แล้ว

    countries need to learn from Iran, our banking system is way more secure, to start, no one can withdraw any money from your bank just by knowing your credit card information and anything about yourself..

  • @pineapple8939
    @pineapple8939 ปีที่แล้ว +1

    first

  • @fruitenjoyer4248
    @fruitenjoyer4248 ปีที่แล้ว

    First

  • @urbanws1234
    @urbanws1234 ปีที่แล้ว

    Most Interesting about channels like this is they never offer real working solutions to these problems. These types of attacks are preventable and easily detected and stopped.Wondering why the working solutions are never presented 🤔

    • @Seytonic
      @Seytonic  ปีที่แล้ว +2

      I’m not aware of an easy catch all solution to this problem, please share

    • @bobross2404
      @bobross2404 ปีที่แล้ว +3

      unless you regularly visit that french traveling site, how could you possibly even tell that that modal was fake and malicious? I *highly* doubt you click on terms of service to read them before checkout lol

    • @urbanws1234
      @urbanws1234 ปีที่แล้ว

      ​@@Seytonic Lets say I did start to share. What would you do with the the Information 🤔 Where would it end up 🤔 Who would see it and Analyze it for more Vulnerabilities than can be exploited🤔 Playing Cat and Mouse Games with Cyber Security is a fools task that QUICKLY leads to new Threats on existing solutions. 😲 Without Knowing you I am confident in saying You are Well aware of that aspect.
      It is the same thing as asking a Bank for the Blueprints and security measures being used. Wonder if they would Share 🤔
      😈👺☠

    • @JesusKnocks.
      @JesusKnocks. ปีที่แล้ว

      @@urbanws1234 you’re weird. I pray never to meet someone in IT like you or at least be able to fire them.
      Pathetic. Especially since CTI is a basic part of cybersecurity