First Time I Ever Had This PayPal Problem...How???

9 replies
Okay, this is the first time this has ever happened to me and I don't even get
how it's possible. So if there are any techies out there who can explain this,
I'd be very grateful.

I just received a PayPal payment for one of my products, which is delivered
via DLGuard. Normally, when a payment is made, if it's an echeck or anything
that has to be confirmed, DLGuard delays in sending the person to the
download page and emailing out the download email. Thus, I don't get one
of those subscribe emails.

With me so far?

Well today, the payment that came in was for 1 cent. Now, normally I
wouldn't be too concerned, but the receipt from PayPal had the name of
the product and all the correct info. It appeared that the person got my
product for 1 cent. However, I did NOT receive a subscribe email and when
going into DLGuard, there was no record of the purchase, so it appears
that this person didn't get it, though I really can't know for certain.

What I don't understand is how is somebody able to change the price of
what they're paying for? Isn't that hardcoded in the payment page
generated by DLGuard and PayPal?

I'm totally confused.

In the meantime, I have banned this email address, which is from the
country BG, wherever that is.

If anybody can explain how the above can happen, I'd appreciate it.

This has been one crazy week.
#paypal #problemhow #time
  • Profile picture of the author mormel
    Hi Steven,

    BG is Bulgaria, a country in Eastern Europe. Lots of young computer wizzes can be found in Bulgaria and Rumania. I think one of them played a sort of joke on you: a prank to show that they could hack your Paypal account. It only costs them one cent, they can't be punished for it (because they didn't steal anything) and they laugh their asses off, knowing you don't know what happend to you and are scared shitless what they might do to you.

    Everybody has his own kind of fun...

    Yours, warriorly, Ed
    Signature

    Get my WSO: The PPC Horizon Report (http://www.warriorforum.com/warrior-...ney-table.html)
    Read Why You PPC'ers Are Leaving Money on the Table!

    {{ DiscussionBoard.errors[508446].message }}
    • Profile picture of the author Steven Wagenheim
      Originally Posted by mormel View Post

      Hi Steven,

      BG is Bulgaria, a country in Eastern Europe. Lots of young computer wizzes can be found in Bulgaria and Rumania. I think one of them played a sort of joke on you: a prank to show that they could hack your Paypal account. It only costs them one cent, they can't be punished for it (because they didn't steal anything) and they laugh their asses off, knowing you don't know what happend to you and are scared shitless what they might do to you.

      Everybody has his own kind of fun...

      Yours, warriorly, Ed

      Ed, please clarify this for me.

      Are you saying that they just hacked the PayPal payment page or are
      you saying that they actually did or can hack into my account (meaning
      that they'd have to guess the password [one would think] and thus be
      able to transfer all the funds in it, change the account info and so on?

      And if the latter, how concerned do I need to be? Should I immediately
      change my password (already tough enough to guess) and/or take
      other preventative measures?

      Sheesh, first my blog, now this.

      Don't people have anything better to do with their time than to screw
      around with somebody's business?
      {{ DiscussionBoard.errors[508653].message }}
      • Profile picture of the author Ivancho
        Originally Posted by Steven Wagenheim View Post

        Ed, please clarify this for me.

        Are you saying that they just hacked the PayPal payment page or are
        you saying that they actually did or can hack into my account (meaning
        that they'd have to guess the password [one would think] and thus be
        able to transfer all the funds in it, change the account info and so on?

        And if the latter, how concerned do I need to be? Should I immediately
        change my password (already tough enough to guess) and/or take
        other preventative measures?

        Sheesh, first my blog, now this.

        Don't people have anything better to do with their time than to screw
        around with somebody's business?
        Hi Steven,

        No they have't hacked your paypal email, they are basiclly edit the price via the source code...

        This is what they done for me...
        {{ DiscussionBoard.errors[508672].message }}
  • Profile picture of the author Efrain Hernandez
    There's a Firefox plug-in that allows you to do that. It's called Tamper Data. Do a Google search for "tamper data paypal".
    {{ DiscussionBoard.errors[508479].message }}
  • {{ DiscussionBoard.errors[508531].message }}
    • Profile picture of the author Harvey Segal
      Originally Posted by Don Schenk View Post

      And they probably read the WF and are ROTFLTAO.
      But if you see what Sam has now said they did not get access to the
      product so they are now ROTFcursing

      Harvey
      {{ DiscussionBoard.errors[509797].message }}
  • Profile picture of the author Ivancho
    Hi their, I am personally from BG but live in UK now. No comment Steve. I really respect you and enjoy all your post. For now in Bulgaria their are alot of people doing this. I even too receive a email today of 1 cent purchase and guest what the guy who purchase it is also from Bulgaria and even better from my own town. If I was at my country I will definatlly go drive to his home as I have his address and all his info via paypal...

    btw: I went too much in details, but I done a research how this can be done and found out a simple way ( I would't share it here Steve ) cause many scammers will start doing it :S if they don't already.

    By the way - don't worry if you are using DlGuard, they can't get to download page before they pay the full price of your product...

    Hope this helps...
    {{ DiscussionBoard.errors[508562].message }}
  • Profile picture of the author gcrocker
    Are the PayPal forms secure? When you create them, you can set them up either secure or not, and I believe a non-secure form can be trivially abused (basically by changing the amount specified in a hidden form field). In a secure PayPal form, the amount is encrypted. If you go to the page where your form is, do a view source, and see a form with the amount in visible text, you might want to change the form.

    It's been a while since I've done this, so I may be off base, but I think it's right. I haven't used DLGuard, so I'm not sure whether it's making your PayPal form for you, in which case you might not have control over this.

    Damn, that was a lot of disclaimers. Sorry!

    -glenn
    {{ DiscussionBoard.errors[508568].message }}
    • Profile picture of the author Efrain Hernandez
      Originally Posted by gcrocker View Post

      Are the PayPal forms secure?
      Apparently not.

      Since they were able to change Steven's and Ivancho's price.
      {{ DiscussionBoard.errors[508581].message }}
  • Profile picture of the author globalpro
    Steven,

    Ivancho is correct in what has happened and Efrain's post shows one way it can be done. I use the RAP script and there was a problem with this a while back. It's since been fixed with RAP, but not sure how to advise you.

    Does DL Guard generate a payment link for the product?

    Thanks,

    John
    {{ DiscussionBoard.errors[509348].message }}
  • Profile picture of the author samstephens
    Does DL Guard generate a payment link for the product?
    Yes, DLGuard does create a sales link for you!

    they can't be punished for it (because they didn't steal anything)
    Actually, this is stealing - if I had a shop and I sold a TV for $1500, and someone walked in the shop, threw 1 cent on the table, grabbed the TV, and ran outside, then that's stealing.

    If they pay anything less than the correct price, it's stealing, and punishable.


    NOW, on to DLGuard:

    Steven, this is actually quite a common Paypal trick, and something people who don't use protection will get burned by more and more often.

    It's quite an old trick, so you must have been lucky to not get hit, yet

    The good news is you're using DLGuard - the reason your "customer" isn't listed in DLGuard is that DLGuard saw they paid you 1 cent, and rejected their sale.

    So you get their 1 cent, and they get nothing.

    So you're safe, nothing to worry about!

    If you have a spare few minutes, you can report them to Paypal for fraud and theft.

    But again, they DIDN'T get access to your product - DLGuard blocked them.

    cheers
    Sam
    Signature
    DLGuard v5 - The Warrior Edition
    Full integration with JVZoo, DigiResults, and WSO Pro for secure WSO's and WSO memberships.

    www.dlguard.com
    Serving the Warrior Forum since 2004
    {{ DiscussionBoard.errors[509532].message }}

Trending Topics