How I Could Steal Money from Instagram, Google and Microsoft
arneswinnen.net
arneswinnen.net
I need to add though that phone payment is mainly used for sites targeted at kids, sites that normal acquirers don't allow (file sharing) and donations (e.g. text XYZ to 000 to donate 5€). Not usually when ordering stuff from Amazon etc.
Or SofortÜberweisung where you give the login data to your online banking and a TAN to a shady 3rd party company and they perform the wire transfer for you - while sending a confirmation to the merchant that the money has been sent.
No, this is not a joke. https://de.wikipedia.org/wiki/Sofortüberweisung
And more and more, especially younger, people have credit cards for digital purchases (and travelling).
In the US it is compounded by the fragmented telco system. You can find numbers in the US that'll pay several cents (some bill up to dozens of cents/minute). This was really heavily abused by things like FreeConferenceCalls or "sexy local chat" lines. It's also used to provide "radio-by-phone" for expats. They'll target a large immigrant population, then play home-town stations over the phone call. This lets people without data use their unlimited-US calling get radio from home without paying directly. Lots of money to be made coming up with ideas like this.
The FCC has ruled this is mandatory and slapped US telcos that blocked such traffic. Though the owners of such numbers now usually mandate that the business be based or have operation in their jurisdiction to avoid running into more challenges.
The motivation is much higher to keep the bug for yourself and create several 10 000 easily before anyone ever would notice.
A few thousand extra bucks totally worth risking your job and possible jail time.
As long as there's no threat of selling the exploit to another party, there's nothing illegal about it.
Saw a talk on bug bounties a while ago. The people getting the most bounties are on India.
A few hundred dollars a year is nothing for these companies, not to mention that if you actually tried to abuse this to a substantial level I am 100% confident that it would be detected and blocked.
It's like filing a bug bounty that you can sign up for multiple AWS accounts and mine bitcoins in the free tier. Up to a certain level, they just don't care. Past that level, you'll be detected and mitigated against.
If you just lose some money, you can budget for that right next to the risk somebody throws rocks in your window or the risk that somebody steals the company car.
Yes, Facebook sounded quite confident that such attempts would be detected and blocked. It seemed like they gave him bounty just to get him out of their hair.
In this case, the attacker would be committing fraud by repeatedly causing calls. But they can probably get away with it. They'll just get cut off. Especially with premium ($0.50+) numbers from more exotic locales - it's too hard to chase people down and prove it. Heck, a US company I advised for lost $90K to a guy in Quebec and it was too hard to go bother going after him. We thought about it for about 30 minutes than just gave up.
So what he did was to get one of those numbers and then have Google / Facebook / Instagram call that number repeatedly and that's how he would get money.
The cases of telecom fraud that I know of that were caught are usually due to incredible arrogance on the perpetrator's fault. In one case, he actually called the company he was attacking to gloat that they could never get him. (The company used a super-vulnerable-yet-expensive switch that literally had bugs like "&admin=1 gets superuser".) I've not seen a VoIP system that was remotely secure.
While you can make some money off fraud on normal-priced international calling it certainly makes it much more difficult and noticeable.
It won't come to that though. They will listen to a complaint and reverse a charge I didn't authorize.
Unless it's a massive set of charges, the resulting collections activity and credit score hit will likely cost a lot more than you're saving by ignoring the bill.
You can't just "refuse to pay your cellphone bill" just like you can't just refuse to pay your credit card bill or refuse to pay your electric bill.
"I did not authorize this charge. If you disagree, take me to court."
So they can drop the charge, or they can take you to court. I find my chances fairly good at disputing a charge I did not authorize in front of a judge. I am willing to take that risk.
Besides, if the exploiter spreads the calls out well enough, I wonder how long it would take until it gets detected..
"Twilio does not support outbound calls [...] to [...] premium rate telephone numbers."
https://www.twilio.com/help/faq/voice/what-types-of-phone-nu...
When input validation doesn't stop at ";&' and similar :)