1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Hmmm something isnt right (paypal releated)

Discussion in 'BlackHat Lounge' started by bobafreak, Dec 17, 2013.

  1. bobafreak

    bobafreak Newbie

    Joined:
    Dec 17, 2013
    Messages:
    4
    Likes Received:
    0
    Ok so i setup a new account since my old legit one was previously limited permanently. Heres what i did. i ordered from a vendor here and started a vcc and vba. the address i have on there is a legit address. (done). (brothers) i then tried to make another account which would be my legitimate account. i did the following steps

    went to a public wifi (mcdonalds)
    made a new email address, opened new paypal, used my real first and last name, gave them my new po box, instead of giving them my checking account info i decided to use my savings account info only thing is the routing number was the same from my checking account on the account that was closed. which i didnt think would be a issue, saw paypal added the funds to the savings, i input the amount to confirm the bank information only to find out this morning they limited this account as well. is it because i used my real name or because of the savings account info and routing number? So far the stealth one hasent been touched or flagged.

    My questions
    I plan on trying this again with the same steps above but going to chase and opening a new bank account and not use anything old besides my real name or should i switch my name or does that not matter? like i said i want this to be my legit account. Also should i try my po box again or use another valid address i can get my mail from (parents, friends)

    I also wondered using my stealth account could i just apply for a paypal debit card since the address is legit, the vba is a us one and just use it at a atm? if they asked me for a social i have a few valid legit ones i could use as well. i just didnt know if they match the socials with the names.

    thanks for the help guys im still trying to figure how my legit one got flagged and the stealth didnt using the same computer. 2 different public locations only thing i can think of is the routing number that screwed it all up or my first and last name.....
     
    Last edited: Dec 17, 2013
  2. JustUs

    JustUs Power Member

    Joined:
    May 6, 2012
    Messages:
    609
    Likes Received:
    451
    1. Your real name;
    2. Your browser is fingerprinted and unique enough that a good match is likely.

    Browser fingerprinting not only relies on the browser that you are using, but more on the configuration of your computer - the fonts installed, java, Adobe products and several other variables. All of these are read with javascript.

    Next time, do a base install of your favored OS, no browser, no browser add ons, no adobe products, no office product or other productivity software - nothing except some antivirus software - in a VM, and use that from a public hotspot. Use IE if you go this route.

    Barring that, download a copy of some open source Webkit based browser, and modify it to deliver your custom finger print that match 1 of every two users instead of 1 in 85 million.

    Edit (add):
    And, beware, this article runs both ways:
    http://freehaven.net/anonbib/cache/hintz02.html
     
    Last edited: Dec 18, 2013
  3. bobafreak

    bobafreak Newbie

    Joined:
    Dec 17, 2013
    Messages:
    4
    Likes Received:
    0
    Thanks for the information. Very good article. So what I did was avoid the above and decided to go to a kinkos office and use a public computer to setup my pp account. I opened up a us vba, used my real name and moms address, new phone number (google voice), I got the transactions that have shown from paypal for the confirmation part and now its verified. Now to see if it'll get flagged. Last one was flagged within 24 hrs of confirming the bank account. Keeping fingers crossed.
     
  4. bobafreak

    bobafreak Newbie

    Joined:
    Dec 17, 2013
    Messages:
    4
    Likes Received:
    0
    update 12-26
    So far the accounts are both still active. the stealth and legitimate account are linked to 2 vba two different addresses on 2 different computers in 2 different locations. (yes im paranoid) lol. My legit pp received its atm card at my moms. I need to switch my po box from the one that was limited to a new po box which i plan on doing tomorrow (maybe). Still debating and brainstorming. Ill let you know and keep updating. So far, so good.
     
  5. bobafreak

    bobafreak Newbie

    Joined:
    Dec 17, 2013
    Messages:
    4
    Likes Received:
    0
    Stealth account finally limited however i know you guys said 20k would limit it. However i was able to hit over 30k within this beginning post to now. Just thought i keep updating. So im thinking of saving it going with another or submit documents. The legit account is still active.

    Resson i feel it limited well wifi i been using well they changed the pw so i couldn't log onto that PayPal from that Wi-Fi but i could still enter the pp account logged on to a public Wi-Fi transferred the money Sunday. Woke up early today tuesday to see the account was limited. So im guessing that had something to do with it.
     
    Last edited: Jul 1, 2014
  6. facebookdude

    facebookdude Elite Member

    Joined:
    Feb 28, 2010
    Messages:
    1,506
    Likes Received:
    2,490
    Nice, I have been contemplating starting another PayPal but it always seemed too difficult. I use Virtual Box to run my virtual machines so I would run my PayPal through that as it would show up as a totally new computer. Plus I would buy a private proxy paying yearly so I am the only user using that IP. With that + the VBA I really don't see how it would fail.
     
  7. timeleaper

    timeleaper Newbie

    Joined:
    Jul 1, 2014
    Messages:
    44
    Likes Received:
    54
    I've never had trouble with paypal. I've used it for years. Really hope things work out for you. Good luck
     
  8. bobafreak

    bobafreak Newbie

    Joined:
    Dec 17, 2013
    Messages:
    4
    Likes Received:
    0
    Ill have to look into that. Right now i have a new pp i started 4 months ago(just in case something like this happened) that im currently adding a vba and vcc to. (Another stealth account) problem is i STILL dont have the wifi password to the main pp account. Im afraid to use another public wifi for it to pretty much limit again. All this is trial and error right now. Does anyone know logging on to the main account different from the ip it originally uses(business location) from a home computer to send funds to the stealth account will trigger a flag due to the original account never using the computer im on(home computer)?
    This computer is new and free from any pp. The isp is also new as well. Just trying to avoid landmines. Hooefully this guide comes in handy for the next person. If anyone is interested in how i did it and progressed it to how i got to that extent, im more than happy to share.

    Also i was thinking about trying backtrack 5 and vm to see if i could break the wpa that the wifi is connected to.