Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update description of idea involving Paytm Spoof #10

Merged
merged 2 commits into from
Apr 24, 2019

Conversation

theWhiteWulfy
Copy link
Contributor

I decompiled the spoofPaytm APK and updated the screen layouts and added a QR code scanner that pulled the number from Paytm's API. I tried to use this around my college, most merchants in our area wait for the payment SMS to arrive before final transaction. That was Jan 18.
Last month I checked QR code API has been shut down. A friend of mine suggested to make a modified client, but it does not seem to work as such as a second refresh potentially removes the false transaction. Any more delay to server sync shows 'No Internet Error'.
Since I'm feel bad, if someone defrauds unsuspecting merchants or is himself caught in a jeopardy, I'm against uploading such apps to websites where it could be generally accessed. Though if you would like I could provide a POC video.

theWhiteWulfy and others added 2 commits April 24, 2019 01:15
I decompiled the spoofPaytm APK and updated the screen layouts and added a QR code scanner that pulled the number from Paytm's API. I tried to use this around my college, most merchants in our area wait for the payment SMS to arrive before final transaction. That was Jan 18. 
Last month I checked QR code API has been shut down. A friend of mine suggested to make a modified client, but it does not seem to work as such as a second refresh potentially removes the false transaction. Any more delay to server sync shows 'No Internet Error'.
Since I'm feel bad, if someone defrauds unsuspecting merchants or is himself caught in a jeopardy, I'm against uploading such apps to websites where it could be generally accessed. Though if you would like I could provide a POC video.
@captn3m0
Copy link
Owner

Thanks! Very stupid of me to miss checking Play Store 🤦‍♂️

I've changed the wording slightly, hope that's fine. Instead of the PoC Video, I'd be very interested in a writeup on the QR Code, and the corresponding API that it uses.

@captn3m0 captn3m0 merged commit bf921d3 into captn3m0:master Apr 24, 2019
@theWhiteWulfy
Copy link
Contributor Author

Thank you! The rewording was essential as it was in first person form.
I've my B.Tech final exams in the next 3 weeks and will do the writeup after that.
I'll definitely write a detailed write-up on the QR Code, and the corresponding API, and update you with the link here when it is done.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants