Quote:
Originally Posted by vadim-123
Вопросы автору:
1. Вы можете реализовать то же самое под Samsung Pay? Было бы намного интереснее.
2. Что значит отключить чип? Вы изменяете сервис код с 201 на 101? Такая транзация быстрее всего будет отклонена банков из за неверного CCV (для MasterCard и Visa).
3. Видео - chase - это видео то же 2015 года. Но из видео я не могу сказать что оплата была именно этой картой ) Очень похоже на постановочную сценку!
4. И даже если так - то можно и на магнитной полосе изменить 201 на 101 и это действительно, может сработать, но как говорит практика, это 1 дамп из 1000 , тем более на подлимитные транзы.
Добавлено через 9 минут 5 секунд
Потому что, мы все здесь, картопизделы)
|
Questions to the author:
1. Can you do the same for Samsung Pay? It would be much more interesting.
A. Working on apple pay and samsung pay not available yet.
2. What does it mean to turn off the chip? Do you change the service code from 201 to 101? Such a transaction will most quickly be rejected by banks due to incorrect CCV (for MasterCard and Visa).
A. service code stored on mag and yes is possible to change code or bypass this remove of service code to turn off chip+pin allow you to push data to terminal when card would ask for card to be dipped not asking for dip card bypass allowing for swipe only as service bits have been changed.
There service code is most where you will find the interesting stuff.
for example
First digits
1. International interchange OK
2. Internationa interchange, US IC (CHIP) where feasible
5. National interchage only under bilaterla agreement
6 National interchange only except under bilateral agreemen, (Use IC chip) where feasible
7 No interchange except under bilateral agreement (closed loops)
Second Digits
0. Normal
2. Contact Issuer Via Online Means
4. Contact Issuer Via Online Means (except under bilateral agreement)
Third Digit
0. No restrictions (PIN REQUIRED)
1. No restrictions
2. Goods and Services only (NO CASH)
3. ATM Onlin ( PIN REQUIRED)
4. Cash Only
5. Goods and services only (NO CASH) PIN REQUIRED
6. No restrictions (Use Pin Where Feasible)
7 Goods and services (No Cash) Use PIN where feasible
What mag spoof can do is disable the bits that show the card is Chip+PIN this allows you to use without need to "DIP" card for 2nd auth as the bits that show the card is C+P are disabled.
Interesting is the Track 2 with 5-bit ( 4 data bits and + 1 parity with allow for 16 possible chars num 0-9 and six chars ;:<=>?
Start Sentinel
PAN
Separator
EXP Date
Service Code - three digit first digit specifies interchange rule set 2nd is auth processing and third is range of service..
Discretionary data ( as in T1)
End Sentinel
LRC check
;CARDNUMBER=YYMM SSSS DISCRETIONARY?LCR
A. Agree video is not best and will update videos soon to show better working of device.
A. this is not for us to test but has been working valid on many cards without issue or report in