Carding Guide: CARiD
Get ready. If youve been jacking off to
overpriced mufflers and fancy rims without actually owning them, its time to put your carding skills where your mouth is and hit
CarID.
View attachment 46383
CarID.com has a mountain of auto parts and their security is
weak as water. From cheap air fresheners to custom body kits, they have it all - and were about to help ourselves.
This isnt just about getting a free muffler. Were going to turn
CarID into our own parts supplier. Their inventory is huge, their prices are
high and their protection is
crap. Perfect for us.
Dont get too cocky though. This still takes some skill. Well need to navigate their system, exploit their weaknesses and get away with the goods without tripping any alarms.
So get your cards ready and fire up your proxies. Were about to show
CarID what happens when you leave your warehouse door open. Lets get in and see how we can turn their stock into our profit.
Why CarID?
CarID is the shit when it comes to
high value auto parts with security as
weak as piss. Their inventory is huge, from cheap air fresheners to custom body kits worth thousands. This variety lets us mix our hits and keep it legit.
The real money is in their
high ticket items. Performance parts, custom wheels, high end stereo systems - one good score can set you up for weeks. And this stuff sells fast. Car enthusiasts are always looking for deals, meaning quick flips and less chance of chargebacks.
CarID works with hundreds of brands, so we can spread our activity and avoid patterns. Their global shipping opens up international card and drop possibilities. And theyre used to gift orders, so different billing and shipping addresses wont raise any flags.
In short,
CarID is the perfect target -
high value goods, diverse inventory and
weak security. While others are fighting over electronics and fashion, were raiding an auto parts factory.
Recon
Opening up the
Burp Suite we can see that
CarIDs security is as basic as a cavemans club. No third party fraud system in sight, just some useless analytics crap that wont do jack to stop us.
View attachment 46385
Now heres where it gets interesting.
CarID uses
CyberSource for payments which implements
3DS 2.0. You might think this is bad news, but hold your horses - its actually a gift if you know how to play it right.
View attachment 46386
Before you even send over the payment details your devices fingerprint gets sent to
Cardinal Commerce, the
3DS processor. The code looks something like this:
JSON:
{
"Cookies": {
"Legacy": true,
"LocalStorage": true,
"SessionStorage": true
},
"DeviceChannel": "Mobile",
"Extended": {
"Browser": {
"Adblock": true,
"AvailableJsFonts": [
"Comic Sans MS",
"Georgia",
"Papyrus",
"Arial Black",
"Trebuchet MS"
],
"DoNotTrack": "disabled",
"JavaEnabled": true
},
"Device": {
"ColorDepth": 24,
"Cpu": "ARM",
"Platform": "Linux",
"TouchSupport": {
"MaxTouchPoints": 5,
"OnTouchStartAvailable": true,
"TouchEventCreationSuccessful": true
}
}
},
"Fingerprint": "d9f8a4b5c3d2e1f0a5b6c7d8e9f0a1b2",
"FingerprintingTime": 42,
"FingerprintDetails": {
"Version": "2.1.0"
},
"Language": "en-GB",
"Latitude": null,
"Longitude": null,
"OrgUnitId": "61ddefdbcac40279f9950adf",
"Origin": "Falcon",
"Plugins": [
"QuickTime::Video Format::video/quicktime~mov",
"Flash Player::Flash Content::application/x-shockwave-flash",
"HTML5 Audio::Audio Format::audio/mpeg"
],
"ReferenceId": "e1f23456-g7h8-90ij-klmn-opqrstuvwxyz",
"Referrer": "https://carid.com",
"Screen": {
"FakedResolution": false,
"Ratio": 1.777,
"Resolution": "2560x1440",
"UsableResolution": "2560x1300",
"CCAScreenSize": "01"
},
"CallSignEnabled": null,
"ThreatMetrixEnabled": false,
"ThreatMetrixEventType": "LOGIN",
"ThreatMetrixAlias": "UserAlias456",
"TimeOffset": -300,
"UserAgent": "Mozilla/5.0 (Linux; Android 10; Pixel 3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Mobile Safari/537.36",
"UserAgentDetails": {
"FakedOS": false,
"FakedBrowser": false
},
"BinSessionId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
}
So what does this mean for us? It means your antidetect setup is key. If your fingerprint looks sketchy youre screwed before you even enter your card details. But get this right and youve got a clear path to the money.
But dont get ahead of yourself just yet. Ive got a trick up my sleeve thatll make carding
CarID easier. Well get to that good stuff soon enough.
Payment Processing
CarID uses
CyberSource with
3DS 2.0 for payments. This might seem like a problem, but its actually good news for us.
3DS 2.0 is more flexible than the previous one. The companies behind it realized strict security was killing sales so they made it dynamic. This works in our favor.
Heres the thing:
3DS 2.0 decides in real-time whether to show a
3DS prompt. Its not a simple yes/no based on the card anymore. This gives us room.
Incluso las tarjetas que normalmente activan
la 3DS pueden evitarla si reducimos lo suficiente nuestra puntuación de riesgo. Todo depende de cómo
Cardinal Commerce , el procesador
de la 3DS , vea nuestra transacción (siempre que no haya un sistema de fraude de IA de por medio).
Tenemos dos opciones:
- Tarjetas que no son VBV : siguen siendo las más fáciles si están disponibles.
- Manipulación del puntaje de riesgo : al modificar la huella digital del dispositivo, potencialmente podemos omitir la 3DS en las tarjetas que lo requieren.
El intento de la 3DS 2.0 de equilibrar la seguridad y la experiencia del usuario nos ha dado una oportunidad. Vamos a aprovecharla.
Cómo minimizar el riesgo de su 3DS 2.0
Vayamos a lo bueno. A diferencia de esos sofisticados sistemas de fraude con inteligencia artificial,
3DS 2.0 está sujeto a políticas de privacidad y leyes de manejo de datos. Esto significa que funciona con un conjunto de datos limitado: solo su dirección IP y la huella digital de su navegador.
Puede que me equivoque en algunos detalles, pero esto es lo que me ha funcionado:
***Texto oculto: no se puede citar.***
Recuerda que esto no es infalible, pero es una forma sencilla y eficaz de reducir tu puntuación de riesgo
de 3DS 2.0 y aumentar tus posibilidades de evitar esos molestos mensajes
de 3DS . No querrás que aparezca esta pantalla:
View attachment 46387
Requisitos y flujo
Requisitos:
- Tarjeta que no sea VBV O use nuestro truco anterior.
- Proxies residenciales limpios que coinciden con tarjetas de país
- Configuración sólida de navegador antidetección
- Dirección de entrega
Fluir:
- Utilice nuestro truco anterior si está utilizando tarjetas VBV
- Añadir artículos al carrito .
- Vaya a la caja . Utilice la opción de pago como invitado si es posible.
- Complete los datos de envío con cuidado . No copie ni pegue.
- Envíe el pedido y contenga la respiración .
- Si tiene éxito, no vuelva a pulsar CarID inmediatamente. Espacie sus intentos.
En mi experiencia, nunca me ha ocurrido que
CarID cancelara una transacción ni solicitara la devolución de un artículo. Sin embargo, no los he contactado más de cinco veces en total (todas enviadas), por lo que los resultados pueden variar. Esté siempre preparado para cancelaciones o devoluciones.
Conseguimos los secretos
de CarID y ahora tienes un plan para convertir su inventario en tu propia tienda de repuestos. Desde las debilidades
de 3DS 2.0 hasta el truco más simple, tienes las herramientas para ganar mucho dinero.
Ahora ve y construye ese auto de tus sueños, una pieza a la vez.
Sólo recuerda que si te atrapan y cometes un error, no aprendiste nada de esto de mí. Doctrina fuera.