[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 3fS3jid.jpg (289 KB, 1338x1080)
289 KB
289 KB JPG
There's this huge financial company in my country that's basically backed by the government. They're running everything — transport, banks, ATMs, payment terminals — total monopoly.

You can't even ride a bus without having their app installed and buying a ticket through it. What really caught my attention though are their kiosk terminals. I'm almost certain they're weak as hell.

I'm thinking if I can figure out the endpoint these kiosks are sending payment requests to, I could intercept or replay them. Since the payment amount is determined by the actual cash inserted into the terminal, there’s probably a way to spoof that request. If that’s possible, I could essentially trigger a kind of "infinite money" bug by mimicking the right calls.

The kiosk does not have a card reader or anything, its a simple touchscreen I am thinking running android cause it is using a SIM card to connect to internet. You simply select a service you want to pay (steam, bills, etc) then feed money and pay.
>>
File: 1727734899180781.png (117 KB, 295x295)
117 KB
117 KB PNG



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.