Wednesday, 27 August 2008

Exploiting Paypal order system

So you decided to purchase download software, that they require you to pay via paypal? If when the link was compiled they decided it would be much better not to encrypt the link, they just opened a nice hole for us.

1) Basicly all you want to do is open the source of the pay page then search for the keyword "return".

right click -> view source || or view -> page source

You should always use a proxy for safety but it is not really necessary, as you could always argue you wanted to buy it then decided not too.

2) you should find a value copy it and paste it into your browser.

Example:



3) you should now see a thank you page, giving you the URL to download the program!


Remember there has to be a thank you page with the url or this exploit will not work. The program can not be emailed to you by using this exploit. it just wont work.



If you find sites that allow you to use this exploit paste it in here and i will edit this post and add them here:

http://www.ramphelp.com/halfpipe.html [Patched - they use the email now]

Written by Nazim

No comments: