About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add Mordecai to your ignore list  
Old 2007-01-20, 06:00
Mordecai Mordecai is offline
Regular
 
Good-bye Blue Monday! Send a message via AIM to Mordecai Send a message via MSN to Mordecai
Default

i'm sorry if this is in the wrong place, but i'm trying to find out how i could possibly make a pin generator. the pin in question is 20 digits, numbers and letters. it is for a pre-paid card. let's say i can get 2 or more of these pins (real ones) and then use those to find a pattern or what not. how exactly would i do this and how do people actually make pin generators?
Reply With Quote
  #2   Add Lord_Alex to your ignore list  
Old 2007-01-20, 11:55
Lord_Alex Lord_Alex is offline
 
Ottawa Ontario Canada
Default

LoL

20 digits. That's only 36^20 (13,367,494,538,843,734,067,838,845,976,576) permutations. Of course, not all are valid.

You'll probably need to gather a couple hundred PINs to start seeing a pattern.

I would start looking at extending the data set by applying a coordinate reconstruction strategy... That is to say you map "virtual" coordinates based on your samples.

So lets say your pin is GnpyiN2uTDzx1QvW05oU, we split it into groups of 5 and plot those 4 groups of 5 digits into a 4 dimensional space. You think it's gonna get hairy? You bet.

W1=Gnpyi, X1=N2uTD, Y1=zx1Qv Z1=W05oU

We'll call the W series your "time" value. Plot your thousands of PINs into this type of grid system (You might need to whip up an OpenGL visualization engine) and see if you notice any neato patterns. Yeah, you'll need to convert your letters/numbers into a number.

Chances are you won't see anything meaningful. So alter your plotting scheme. Again and again and again. Eventually, you'll find a pattern: http://www.doxpara.com/pics/index.php?album=phentropy/

We use this technique to discover that the Pseudo Random Number Generator used in most operating systems is horribly predictable. Actually, most sources of "random" data follow a pretty basic pattern.

http://www.scholarpedia.org/article/...Reconstruction http://en.wikipedia.org/wiki/Attractor

Basically, let's just say your task isn't easy. Hell, they might not even use a system vulnerable to this type of attack.

It might be extremely easy too, though. It could be sequential.

Good luck!
Reply With Quote
  #3   Add Mordecai to your ignore list  
Old 2007-01-20, 16:06
Mordecai Mordecai is offline
Regular
 
Good-bye Blue Monday! Send a message via AIM to Mordecai Send a message via MSN to Mordecai
Default

well the pre-paid card is for a free online game, allowing you to use "cash items" that you would normally buy, so i doubt they're going to be extremely precautious with the pin generation. it's not like i'm trying to steal windows vista. but i dunno if this is worth doing now, it sounds way beyond me. i can admit when i'm beat.
Reply With Quote
  #4   Add larzuf to your ignore list  
Old 2007-01-20, 17:03
larzuf larzuf is offline
 
USA
Default

Quote:
quote:Originally posted by Lord_Alex:

LoL

20 digits. That's only 36^20 (13,367,494,538,843,734,067,838,845,976,576) permutations. Of course, not all are valid.

You'll probably need to gather a couple hundred PINs to start seeing a pattern.

I would start looking at extending the data set by applying a coordinate reconstruction strategy... That is to say you map "virtual" coordinates based on your samples.

So lets say your pin is GnpyiN2uTDzx1QvW05oU, we split it into groups of 5 and plot those 4 groups of 5 digits into a 4 dimensional space. You think it's gonna get hairy? You bet.

W1=Gnpyi, X1=N2uTD, Y1=zx1Qv Z1=W05oU

We'll call the W series your "time" value. Plot your thousands of PINs into this type of grid system (You might need to whip up an OpenGL visualization engine) and see if you notice any neato patterns. Yeah, you'll need to convert your letters/numbers into a number.

Chances are you won't see anything meaningful. So alter your plotting scheme. Again and again and again. Eventually, you'll find a pattern: http://www .doxpara.c om/pics/index.php?album=phentropy/

We use this technique to discover that the Pseudo Random Number Generator used in most operating systems is horribly predictable. Actually, most sources of "random" data follow a pretty basic pattern.

http ://www.sch olarpedia.org/article/Attractor_Reconstruction http://en.wikipedia.org/wiki/Attractor

Basically, let's just say your task isn't easy. Hell, they might not even use a system vulnerable to this type of attack.

It might be extremely easy too, though. It could be sequential.

Good luck!
Kudos to you. That is one of the best responses I've ever seen in this forum.

Reply With Quote
  #5   Add spindl3--chopper to your ignore list  
Old 2007-01-20, 21:01
spindl3--chopper spindl3--chopper is offline
Regular
 
Chowick, Auckland Send a message via MSN to spindl3--chopper
Default

use a proxy coz thell red flag ur ip after about 3-20 attemts

like how pre paid phone cards dont let u enter codes 4 ages if u fuck it up 2 many times
Reply With Quote
  #6   Add Mordecai to your ignore list  
Old 2007-01-20, 23:05
Mordecai Mordecai is offline
Regular
 
Good-bye Blue Monday! Send a message via AIM to Mordecai Send a message via MSN to Mordecai
Default

ok a little update. this is a completely different story now, but i didn't feel like making a new thread. i'm in possession of 6 pins, all are legit, EXCEPT they don't work on the website because they were never activated by the cashier. therein lies the problem. i'm wondering if anyone knows exactly what happens to the card information when it is scanned and "purchased", and if there's any way for me to send that info to the server myself.

i'm assuming the way it works is it sends the card's transaction number to the game's web server and records it as purchased. the store probably has their own permissions for sending data and are recognized as a seller of these cards, so the data goes in with no problem.

so, now the issue becomes more of hacking than number generating. anyone have any thoughts on this?



btw, thank you for whoever replied to my op, that was very informative.
Reply With Quote
  #7   Add Mordecai to your ignore list  
Old 2007-01-21, 21:31
Mordecai Mordecai is offline
Regular
 
Good-bye Blue Monday! Send a message via AIM to Mordecai Send a message via MSN to Mordecai
Default

bump...anybody?
Reply With Quote
  #8   Add RipSlider to your ignore list  
Old 2007-01-21, 23:49
RipSlider RipSlider is offline
 
England
Default

OK.

Lets assume the system works like this>

The cards hold PRNG'd numbers. Each is, we assume, unique.

At this point, you buy it. The POS system at the shop takes some data from a bar code on the back of it or attached to it. If we assume that this is not a 2d barcord, then there can only be a specific number of bytes of data held in the barcode, certainly less than there are possible key values.

So, here is the first question: if you DON'T get the card authourised, then it doesn't work. However, the barcode can't hold as many values as the card is capable of.

This leaves a few options:

1) There is a sub-sequence in the card for example, the middle 12 character or something ) that is unique, and the rest of digits are just fillers

2) That some form of hash exists of the code on the card that CAN be held on the bar code

3) Something else is happening.

My money is on 3) because I think I'm missing something simple.

After that, once you have found the "key", you should be in a position for code up a sequence generator that allows you to pre-calculate more in the same sequence.

For example, there would probably be a sequence for £10 cards, £20 cards etc.

After that, you have the real work of actually writing the systerm and missing all the IV's, in this case a collision would be one that is already activeated at the POS AND has been used.

Rip
Reply With Quote
  #9   Add sirholkms to your ignore list  
Old 2007-01-23, 01:30
sirholkms sirholkms is offline
Regular
 
Send a message via ICQ to sirholkms Send a message via AIM to sirholkms Send a message via MSN to sirholkms Send a message via Yahoo to sirholkms Send a message via Skype™ to sirholkms
Default

Quote:
quote:Originally posted by Lord_Alex:

LoL

20 digits. That's only 36^20 (13,367,494,538,843,734,067,838,845,976,576) permutations. Of course, not all are valid.

You'll probably need to gather a couple hundred PINs to start seeing a pattern.

I would start looking at extending the data set by applying a coordinate reconstruction strategy... That is to say you map "virtual" coordinates based on your samples.

So lets say your pin is GnpyiN2uTDzx1QvW05oU, we split it into groups of 5 and plot those 4 groups of 5 digits into a 4 dimensional space. You think it's gonna get hairy? You bet.

W1=Gnpyi, X1=N2uTD, Y1=zx1Qv Z1=W05oU

We'll call the W series your "time" value. Plot your thousands of PINs into this type of grid system (You might need to whip up an OpenGL visualization engine) and see if you notice any neato patterns. Yeah, you'll need to convert your letters/numbers into a number.

Chances are you won't see anything meaningful. So alter your plotting scheme. Again and again and again. Eventually, you'll find a pattern: http://www .doxpara.c om/pics/index.php?album=phentropy/

We use this technique to discover that the Pseudo Random Number Generator used in most operating systems is horribly predictable. Actually, most sources of "random" data follow a pretty basic pattern.

http ://www.sch olarpedia.org/article/Attractor_Reconstruction http://en.wikipedia.org/wiki/Attractor

Basically, let's just say your task isn't easy. Hell, they might not even use a system vulnerable to this type of attack.

It might be extremely easy too, though. It could be sequential.

Good luck!
Number plane? Scatter plot?...

Reply With Quote
  #10   Add Lord_Alex to your ignore list  
Old 2007-01-23, 02:16
Lord_Alex Lord_Alex is offline
 
Ottawa Ontario Canada
Default

Quote:
quote:Originally posted by sirholkms:

Number plane? Scatter plot?...
Uhhh, not quite. But that's the idea. Plot the numbers in a way and a pattern might result. Stephen Wolfram's "A New Kind of Science" covers it a bit concerning PRNGs, as does Michal Zalewski's "Silence on the Wire".

"Dissonant numbers: an analysis of pseudo-random sequences" by Jonathan E. Magen and Altan Orhon

http://lcamtuf.coredump.cx/newtcp/ has some more graphics relating to PRNG and TCP/IP Sequence Number analysis. Your pins are probably based on similar concepts.

Math is fun... lol
Reply With Quote
 #11 
Old 2007-01-23, 02:28
Lord_Alex Lord_Alex is offline
Regular
 
Default Re: pre-paid card pin generator

Ok, as for hacking the game server... That's illegal. I guess you're not concerned about that part.

I would start with analyzing the scripts that are used to authenticate your PIN against some type of database of purchased PINs.

Look at the source of your login page.

Try simple things like an SQL injection.

Is the POS an international setup like 7/11 or is it just a dodgey corner store? That tells you the scope of the game and it's customers. If it's a really small operation, chances are that they use in-house coders who might not be very experienced with their coding security practices.

A very big game-house like Blizzard will be very secure against basic web-hacking attempts.

I'm guessing you want to print a list of valid PINs and potentially their credit balance, among other info?

Maybe post more info and some help will arrive
 #12 
Old 2007-01-28, 03:30
Mordecai Mordecai is offline
Regular
 
Default Re: pre-paid card pin generator

well the company is very big in korea but relatively small in the us. the cards are sold in target locations usa-wide. as for how secure their server is? i'm not really sure. i haven't heard of a lot of players packet-editing in-game, but there are shitloads of script kiddies that hack constantly. the company's website is maplestory.nexon.net and like i said before i have 3 working PINs.
Reply

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics