<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Google Checkout, Paypal killer?</title>
	<atom:link href="http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/feed/" rel="self" type="application/rss+xml" />
	<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/</link>
	<description>Web development, information security and Unix system administration</description>
	<pubDate>Mon, 06 Oct 2008 15:35:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: SCAM ALERT</title>
		<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-282518</link>
		<dc:creator>SCAM ALERT</dc:creator>
		<pubDate>Thu, 25 Sep 2008 02:55:19 +0000</pubDate>
		<guid isPermaLink="false">http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-282518</guid>
		<description>The SCAM in the post Number 9 above is SOOOOOO lame and stupid.
DO you really people will give YOU their paypal password? 

hey people . WATCH OUT . THIS IS A SCAM .
THIS IS AN VERY OLD TRICK TO CATCH PEOPLE PASSWORDS.

DONT TRY THIS</description>
		<content:encoded><![CDATA[<p>The SCAM in the post Number 9 above is SOOOOOO lame and stupid.<br />
DO you really people will give YOU their paypal password? </p>
<p>hey people . WATCH OUT . THIS IS A SCAM .<br />
THIS IS AN VERY OLD TRICK TO CATCH PEOPLE PASSWORDS.</p>
<p>DONT TRY THIS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-237882</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Fri, 04 Jan 2008 00:37:59 +0000</pubDate>
		<guid isPermaLink="false">http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-237882</guid>
		<description>Paypal has changed it's email bot and I have been searching online for hours and now I have it. So heres the hack:

This is how to hack the paypal accounts hurry before it's too late and paypal changes the bots again.
This is the new bot and everything you need to know to get into paypal. 
Remember that it might not work the first time so try it a few times and it will work.

HOW TO HACK INTO PAYPAL ACCOUNT!!! 


1) The following complete hacking tutorial contains materials that may not be suitable for irresponsible internet users, reader discretion is advised!
we have to put that so we don't get i trouble.
2) The hacking method is based on a secretly discovered security flaw in the PayPal (www.paypal.com) mailing address confirmation system. It will only work BEFORE PayPal discovers this serious security flaw and fixes it. Take your action FAST!
3) This method works for any body with PayPal accounts with CONFIRMED MAILING ADDRESSES. It will never work for PayPal user without a confirmed mailing address. THIS MEANS YOU HAVE TO PUT A CREDIT CARD OR BANK ACCOUNT ON YOUR PAYPAL ACCOUNT!!!
4) By strictly following instructions in the following tutorial, you'll gain unlimited access to various PayPal accounts with confirmed mailing addresses. Use those accounts AT YOUR OWN RISK. You?re responsible for your action!
5) When you use PayPal, NEVER log on to sites that do not start EXACTLY with www.paypal.com even if it contains the term ?paypal? in it.

PayPal is the latest victim of internet hackers. Despite the company?s seemingly perfect security system, a serious security flaw in the ADDRESS CONFIRMATION PROCESS of PayPal?s members? accounts has been discovered by a few experienced hackers from Russia. The hacking process has been simplified a while ago and it was revealed on a Russian language hacking website.
PayPal was immediately alerted of this security flaw after the Russian language hacking tutorial was published on the website, but in order to prevent its customers from losing trust in internet banking, PayPal chose NOT to alert its customers of this security flaw and has then secretly BANNED numerous online articles that contained information of this security flaw.
However, it has been confirmed that due to technical difficulty, PayPal has NOT yet fixed the problem and at this moment right now, anyone can STILL hack into a great number of PayPal accounts with confirmed addresses.
To inform users worldwide of this problem, I?ve attached an English version of the hacking process. Remember, to get the whole thing to work, you MUST
STRICTLY follow the instructions and have a PayPal account with a confirmed mailing address!

HACKING PROCESS:
Every PayPal member is identified by his/her Email and the majority of the PayPal members use Hotmail. After completion of the mailing address confirmation process, usually by adding a CREDIT CARD OR BANK ACCOUNT, PayPal automatically sends the user?s address confirmation info to a mailerbot associated with the user?s Email, in most cases, it?s Hotmail mailerbot.
The security flaw occurs RIGHT HERE! Both Yahoo and Hotmail mailerbots can be confused by a random user and sends out information saved on its server to that user.
To get PayPal account information of numerous random PayPal users from a Hotmail mailerbot, you have to do the following:

1) Log into your www.paypal.com homepage, and click on ?Profile?, and then click on
?Street Address? under ?Account Information?.

2) Find the Address whose status is ?Home?, and if it says ?confirmed?, then please read on.

Basically, A Confirmed Address is any address at which you receive your credit card statement. If you receive a credit card bill at this address, you can confirm it by entering your credit card information. This information will only be used to confirm your address. Your card will not be charged by PayPal.

So, if your Home address is NOT confirmed, then FOLLOW THE INSTRUCTIONS ON PAYPAL AND ADD A CREDIT CARD TO CONFIRM YOUR MAILING ADDRESS.

3) Okay, the bot that this will work for is yah_emailbot@yahoo.com
This is the new bot for Yahoo.com. (Note: You don't have to have a Yahoo email address to do this)

NOW:
Log in to your paypal email account and send an Email to:
(yah_emailbot@yahoo.com)

In the subject line, write:
789bot4*5%8verif-0e24 (To confuse the yahoo mailerbot)

In the email body, please write exactly 11 lines, which MUST BE as follows:
In line 1:Subject-Type: ?text/plain="+1"?

In line 2: charset=us-english 
(To make the reply readable in your language so put you own language here otherwise it might come in a laguage you don't understand)

In line 3: botbody*78#9 confirmation0e24.hotmail.com
(To confuse the mailerbot)

In line 4: p38ylec00rm::s%%(a href=http://www.paypal.com%%)
(To make the mailerbot start retrieving information acquired from PayPal.)

In line 5: Your primary email at paypal
(To retrieve information from PayPal, The mailerbot now needs an Email which is the primary Email of a PayPal account with a confirmed mailing address, you have to use your own Email as a bait Email and you?ll need to receive info of other accounts from this Email too, so be sure this is your primary Email at PayPal.)

In line 6: start (retrieve &#62; 07)
(To activate the mailerbot's retrieval function at the highest speed)

In line 7: verify#8% (*value= = float)
(This will trick him to send it to your email adress instead of the administrators)

In line 8: Your PayPal password
(Now you have to enter your paypal password to confuse the bot so it thinks your the administrator of paypal and it can send you the emails and passwords of people.)

In line 9: #searchppagend72hrlog
(to get info from PayPal members who had their addresses confirmed in the last 72 hours)

In line 10 send#%*idR20334-tsa-0583
(This will make the mailerbot send all the info to your email)

In line 11 (#%7*tmbot*="+098")
(this covers you trail so they cant find you. Last step!)

If you specifically follow the instructions above, you'll have email, passwords and all sorts of information of PayPal users who had their mailing addresses confirmed over the last 72 hours.</description>
		<content:encoded><![CDATA[<p>Paypal has changed it&#8217;s email bot and I have been searching online for hours and now I have it. So heres the hack:</p>
<p>This is how to hack the paypal accounts hurry before it&#8217;s too late and paypal changes the bots again.<br />
This is the new bot and everything you need to know to get into paypal.<br />
Remember that it might not work the first time so try it a few times and it will work.</p>
<p>HOW TO HACK INTO PAYPAL ACCOUNT!!! </p>
<p>1) The following complete hacking tutorial contains materials that may not be suitable for irresponsible internet users, reader discretion is advised!<br />
we have to put that so we don&#8217;t get i trouble.<br />
2) The hacking method is based on a secretly discovered security flaw in the PayPal (www.paypal.com) mailing address confirmation system. It will only work BEFORE PayPal discovers this serious security flaw and fixes it. Take your action FAST!<br />
3) This method works for any body with PayPal accounts with CONFIRMED MAILING ADDRESSES. It will never work for PayPal user without a confirmed mailing address. THIS MEANS YOU HAVE TO PUT A CREDIT CARD OR BANK ACCOUNT ON YOUR PAYPAL ACCOUNT!!!<br />
4) By strictly following instructions in the following tutorial, you&#8217;ll gain unlimited access to various PayPal accounts with confirmed mailing addresses. Use those accounts AT YOUR OWN RISK. You?re responsible for your action!<br />
5) When you use PayPal, NEVER log on to sites that do not start EXACTLY with <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> even if it contains the term ?paypal? in it.</p>
<p>PayPal is the latest victim of internet hackers. Despite the company?s seemingly perfect security system, a serious security flaw in the ADDRESS CONFIRMATION PROCESS of PayPal?s members? accounts has been discovered by a few experienced hackers from Russia. The hacking process has been simplified a while ago and it was revealed on a Russian language hacking website.<br />
PayPal was immediately alerted of this security flaw after the Russian language hacking tutorial was published on the website, but in order to prevent its customers from losing trust in internet banking, PayPal chose NOT to alert its customers of this security flaw and has then secretly BANNED numerous online articles that contained information of this security flaw.<br />
However, it has been confirmed that due to technical difficulty, PayPal has NOT yet fixed the problem and at this moment right now, anyone can STILL hack into a great number of PayPal accounts with confirmed addresses.<br />
To inform users worldwide of this problem, I?ve attached an English version of the hacking process. Remember, to get the whole thing to work, you MUST<br />
STRICTLY follow the instructions and have a PayPal account with a confirmed mailing address!</p>
<p>HACKING PROCESS:<br />
Every PayPal member is identified by his/her Email and the majority of the PayPal members use Hotmail. After completion of the mailing address confirmation process, usually by adding a CREDIT CARD OR BANK ACCOUNT, PayPal automatically sends the user?s address confirmation info to a mailerbot associated with the user?s Email, in most cases, it?s Hotmail mailerbot.<br />
The security flaw occurs RIGHT HERE! Both Yahoo and Hotmail mailerbots can be confused by a random user and sends out information saved on its server to that user.<br />
To get PayPal account information of numerous random PayPal users from a Hotmail mailerbot, you have to do the following:</p>
<p>1) Log into your <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> homepage, and click on ?Profile?, and then click on<br />
?Street Address? under ?Account Information?.</p>
<p>2) Find the Address whose status is ?Home?, and if it says ?confirmed?, then please read on.</p>
<p>Basically, A Confirmed Address is any address at which you receive your credit card statement. If you receive a credit card bill at this address, you can confirm it by entering your credit card information. This information will only be used to confirm your address. Your card will not be charged by PayPal.</p>
<p>So, if your Home address is NOT confirmed, then FOLLOW THE INSTRUCTIONS ON PAYPAL AND ADD A CREDIT CARD TO CONFIRM YOUR MAILING ADDRESS.</p>
<p>3) Okay, the bot that this will work for is <a href="mailto:yah_emailbot@yahoo.com">yah_emailbot@yahoo.com</a><br />
This is the new bot for Yahoo.com. (Note: You don&#8217;t have to have a Yahoo email address to do this)</p>
<p>NOW:<br />
Log in to your paypal email account and send an Email to:<br />
(yah_emailbot@yahoo.com)</p>
<p>In the subject line, write:<br />
789bot4*5%8verif-0e24 (To confuse the yahoo mailerbot)</p>
<p>In the email body, please write exactly 11 lines, which MUST BE as follows:<br />
In line 1:Subject-Type: ?text/plain=&#8221;+1&#8243;?</p>
<p>In line 2: charset=us-english<br />
(To make the reply readable in your language so put you own language here otherwise it might come in a laguage you don&#8217;t understand)</p>
<p>In line 3: botbody*78#9 confirmation0e24.hotmail.com<br />
(To confuse the mailerbot)</p>
<p>In line 4: p38ylec00rm::s%%(a href=http://www.paypal.com%%)<br />
(To make the mailerbot start retrieving information acquired from PayPal.)</p>
<p>In line 5: Your primary email at paypal<br />
(To retrieve information from PayPal, The mailerbot now needs an Email which is the primary Email of a PayPal account with a confirmed mailing address, you have to use your own Email as a bait Email and you?ll need to receive info of other accounts from this Email too, so be sure this is your primary Email at PayPal.)</p>
<p>In line 6: start (retrieve &gt; 07)<br />
(To activate the mailerbot&#8217;s retrieval function at the highest speed)</p>
<p>In line 7: verify#8% (*value= = float)<br />
(This will trick him to send it to your email adress instead of the administrators)</p>
<p>In line 8: Your PayPal password<br />
(Now you have to enter your paypal password to confuse the bot so it thinks your the administrator of paypal and it can send you the emails and passwords of people.)</p>
<p>In line 9: #searchppagend72hrlog<br />
(to get info from PayPal members who had their addresses confirmed in the last 72 hours)</p>
<p>In line 10 send#%*idR20334-tsa-0583<br />
(This will make the mailerbot send all the info to your email)</p>
<p>In line 11 (#%7*tmbot*=&#8221;+098&#8243;)<br />
(this covers you trail so they cant find you. Last step!)</p>
<p>If you specifically follow the instructions above, you&#8217;ll have email, passwords and all sorts of information of PayPal users who had their mailing addresses confirmed over the last 72 hours.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: b8maysofot</title>
		<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-160695</link>
		<dc:creator>b8maysofot</dc:creator>
		<pubDate>Fri, 08 Sep 2006 12:24:40 +0000</pubDate>
		<guid isPermaLink="false">http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-160695</guid>
		<description>Hello, can i use your information on my site?</description>
		<content:encoded><![CDATA[<p>Hello, can i use your information on my site?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erdbeere</title>
		<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-145441</link>
		<dc:creator>Erdbeere</dc:creator>
		<pubDate>Mon, 24 Jul 2006 03:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-145441</guid>
		<description>I checked out “Google-checkout”.
The overall process seems to be very easy but exactly that makes this solution very vulnerable. During checkout there was no security question to make sure that I’m indeed the owner of the Google account or the associated Credit Cards in that account. Of course I used my username and password but because there are so many Google sites, using the same username and password, it is very easy to loose your login information on a hijacking page as you might not check the url for Ad-Words or Gmail every time you log on as those services never had the possibility to shop with your Credit Card.
Now because you have one account and login information for all it is quite possible that hackers will try to get your login information from any Google service out there! Even worth is the fact that the hacker can change the password without any problem. The owner of the account might not even get any information about the password change as the e-mail is sent to the according and hijacked Gmail account.
Because of this HUGE security risk I would not recommend using Google checkout!
Please checkout the http://www.thebilliondollarpatent.com as s-registration solution that Google should have implemented in their service to make it solid and secure. This solution is requiring a third credential called TAN to make sure that ONLY the owner of that account is able to shop online even in case the account is hijacked.
I hope that everybody is aware of the security issue with Google checkout and will inform Google of a better solution!
Thanks and be safe;-)))!!</description>
		<content:encoded><![CDATA[<p>I checked out “Google-checkout”.<br />
The overall process seems to be very easy but exactly that makes this solution very vulnerable. During checkout there was no security question to make sure that I’m indeed the owner of the Google account or the associated Credit Cards in that account. Of course I used my username and password but because there are so many Google sites, using the same username and password, it is very easy to loose your login information on a hijacking page as you might not check the url for Ad-Words or Gmail every time you log on as those services never had the possibility to shop with your Credit Card.<br />
Now because you have one account and login information for all it is quite possible that hackers will try to get your login information from any Google service out there! Even worth is the fact that the hacker can change the password without any problem. The owner of the account might not even get any information about the password change as the e-mail is sent to the according and hijacked Gmail account.<br />
Because of this HUGE security risk I would not recommend using Google checkout!<br />
Please checkout the <a href="http://www.thebilliondollarpatent.com" rel="nofollow">http://www.thebilliondollarpatent.com</a> as s-registration solution that Google should have implemented in their service to make it solid and secure. This solution is requiring a third credential called TAN to make sure that ONLY the owner of that account is able to shop online even in case the account is hijacked.<br />
I hope that everybody is aware of the security issue with Google checkout and will inform Google of a better solution!<br />
Thanks and be safe;-)))!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Silvester</title>
		<link>http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-143863</link>
		<dc:creator>James Silvester</dc:creator>
		<pubDate>Mon, 10 Jul 2006 18:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://tabo.aurealsys.com/archives/2006/06/29/google-checkout-paypal-killer/#comment-143863</guid>
		<description>With any luck, this will drive down fees on paypal too.</description>
		<content:encoded><![CDATA[<p>With any luck, this will drive down fees on paypal too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
