Go Back   Carder.life > [en] International Forum > Virtual carding



Reply
 
Thread Tools Display Modes
  #1  
Old 01-20-2025, 02:17 AM

spalr spalr is offline
Join Date: Aug 2022
Posts: 111
Default


You're here because you want the finer things in life but you're not about that "paying" part. JomaShops got the bling and we've got the know-how to get it. This isn't your corner store hustle JomaShops a grey market playground where luxury watches flow. But don't get cocky – they've got security just not the kind that can stop a determined bastard like you.


NAME: JomaShop
URL: https://jomashop.com
PAYMENT SYSTEM: Braintree
FRAUD SYSTEM: Forter
PRODUCTS: Luxury Watches
DIFFICULTY LEVEL: 6/10
Disclaimer: The information provided in this writeup and all my writeups and guides are intended for educational purposes only. It is a study of how fraud operates and is not intended to promote endorse or facilitate any illegal activities. I cannot be held liable for any actions taken based on this material or any material posted by my account. Please use this information responsibly and do not engage in any criminal activities.
Why JomaShop?
So why are we targeting JomaShop? These guys are the black sheep of the luxury watch world selling legitimate high-end timepieces in a way that's a bit unorthodox. They operate in a shady gray market not exactly following the manufacturers rulebook. Its like they're the rebellious cousin of the black market - all the bling but with a questionable approach.

And the watches? These bad boys can be flipped for some serious cash. Were talking about a potential payday that's no joke.
Now lets talk about their security or the lack thereof. JomaShop uses Braintree for payment processing and Forter for fraud detection. Sounds intimidating? Not really. Their setup has some vulnerabilities. And the best part? No 3D Secure to mess things up. Its almost like they're asking for it.
Recon
Before we go balls to the wall lets do some digging. Fire up your favorite network sniffer (https://portswigger.net/burp if you've got half a brain) and poke around JomaShops site. You'll see they're in bed with https://www.braintree.com/ for payments and Forter for fraud prevention.

Forter...that name might ring a bell. These guys are usually a royal pain in the ass. But on JomaShop their fraud checks are like a lazy security guard – they only show up after your payments already cleared. That's our goddamn window of opportunity.
Forter

Here's how Forters post-auth assesment works on JomaShop:
  • Astronomical Fraud Score: If Forter thinks you're a fraudster (and they're right ) your transaction will be dead.

  • High Fraud Score: JomaShop will demand pics of the card and ID especially if you're ordering over two grand. Time to get creative with Photoshop or find a reliable fake ID guy.

  • Medium Fraud Score: Forter flags you and JomaShop wants a little "chat" to verify things. Get ready to bullshit your way through a phone call using the cardholders info.

  • Low Fraud Score: Forter gives you the green light your order ships and you're one step closer to that shiny new Patek Philippe.


Carding JomaShop

Here's the step-by-step on how to rob JomaShop blind:
  1. Get Your Shit Together: Antidetect browser fresh-ass proxies and clean high-balance cards. This ain't amateur hour.

  2. Hunt for Discounts: JomaShops always got some coupon code bullshit going on. Scour their site hit up those shady coupon sites – every dollar saved is a dollar earned. New customer codes are like gold dust to pack more $$$ on each of your order and it makes you a lot more legitimate in the eyes of the antifraud.

  3. Act Natural: Don't just grab the priciest watch and run. Browse around like you actually give a shit. Read descriptions add some crap to your wishlist – you're a sophisticated criminal act like it.

  4. Cart and Chill: Add your target to the cart but don't rush it. Let it sit there. Browse some more or go jerk off and come back later. Patience young grasshopper.

  5. Checkout Smooth Operator: Take your time filling out the forms. No copy-pasting you moron. And don't forget that sweet discount code (I forgot to use it here lol).


  6. Payment Roulette: Use your squeaky-clean card. Remember Forters verdict comes after the payment so its a bit of a gamble every time.


  7. Confirmation and Shipping: Pray to whatever dark gods you believe in and watch your email like a hawk. If you're lucky you'll get a tracking number.


Advanced Tactics
Email Trick
JomaShops dumb enough to let you create an account with the cardholders email without verifying it. And Forter? They fucking love emails.
  1. Make a JomaShop account using the cardholders email.

  2. Place your order with a fresh card and a clean proxy.

  3. Spam the living hell out of the cardholders inbox to bury that order confirmation email.


JomaShop also offers a guest checkout tracking link so you don't even need an account. This might lower your fraud score especially if the emails got some history with Forter powered sites. But its a one-time deal. If you get flagged for a medium-risk review you're screwed without email access. Unless you've got the balls to call them and pretend you typed your email wrong.
PayPal: Your Sneaky Backdoor

JomaShop accepts PayPal and that's where our little PayPal method comes into play:
  1. Load up your cart and head to checkout.

  2. Use the cardholders real addressas the shipping address.
    • This is crucial – PayPal demands a legit address.

    • Make sure it matches PayPals records for the card.


  3. Hit Pay with PayPal.
    • PayPal sees a verified shipping address and relaxes.

    • Their fraud detections basically taking a siesta.

    • Authorization goes through without a hitch.


  4. After PayPals thumbs-up but BEFORE the final confirmation:
    • JomaShop lets you "review" your order.

    • Change the shipping address to your drop.

    • PayPal wont even notice.


  5. Smash that Pay Now button.
    • Transaction processes using PayPals pre-authorized token.

    • JomaShop gets your updated shipping info.

    • Package heads to your drop.



This works because PayPal does its security check during the initial authorization. JomaShop will happily process the order with the new shipping address and your stolen goods are practically in your hands.
Conclusion
Hitting JomaShop is a risky business but the payoff is huge. Their securitys got holes but their fraud detection can still fuck you over. Play it smart and you'll be swimming in luxury watches. Screw it up and you'll be left with jack shit.
This ain't a game for pussies. You need to be sharp ruthless and willing to gamble. But if you've got the stones JomaShop can be your personal ATM.
Now go out there and make some goddamn money. And if you get caught don't come crying to me.
Reply

Tags
NULL

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT. The time now is 12:52 PM.