<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ebook success: Guide to writing, marketing, delivering and selling your ebook &#187; get stuff for free</title>
	<atom:link href="http://e-booknow.com/blog/tag/get-stuff-for-free/feed/" rel="self" type="application/rss+xml" />
	<link>http://e-booknow.com/blog</link>
	<description>Complete guide to writing, marketing and selling your ebook</description>
	<lastBuildDate>Mon, 26 Jul 2010 19:13:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The truth about hacking Paypal Buy Now buttons</title>
		<link>http://e-booknow.com/blog/2008/02/29/the-truth-about-hacking-paypal-buy-now-buttons/</link>
		<comments>http://e-booknow.com/blog/2008/02/29/the-truth-about-hacking-paypal-buy-now-buttons/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 03:02:42 +0000</pubDate>
		<dc:creator>ebooknow</dc:creator>
				<category><![CDATA[paypal]]></category>
		<category><![CDATA[get stuff for free]]></category>
		<category><![CDATA[paypal hacks]]></category>

		<guid isPermaLink="false">http://e-booknow.com/blog/2008/02/29/the-truth-about-hacking-paypal-buy-now-buttons/</guid>
		<description><![CDATA[After watching the video that I&#8217;ve featured to the right, I decided I was going to try to hack a buddy&#8217;s website.  I told him what I was going to do and he gave me the go ahead.  It would&#8217;ve been much more fun to do it without asking.  Just like in [...]]]></description>
			<content:encoded><![CDATA[<p>After watching the video that I&#8217;ve featured to the right, I decided I was going to try to hack a buddy&#8217;s website.  I told him what I was going to do and he gave me the go ahead.  It would&#8217;ve been much more fun to do it without asking.  Just like in the video, I copied his html for the web page; changed the values from the original price to $0.01; opened the new page in my browser; and clicked on the Buy Now button.  Sure enough, the price was now a penny &#8211; a savings of $12.98.  I made the payment and, less than a minute later, received the download link to his product.<br />
<span id="more-68"></span></p>
<table>
<tr>
<td>He tried the same to me but I had Payloadz&#8217;s price checking feature turned on so that product delivery to him did not occur.  I told him that I thought it would be funny to buy his product for a penny; send him a bunch of emails complaining about the product; and then request a refund for the full price.</td>
<td><a href="http://www.flickr.com/photos/43698630@N00/839984821/" target="_blank"><img src="http://farm2.static.flickr.com/1154/839984821_f1ee986935_t.jpg" border="0" /></a><br />
<small><a href="http://www.photodropper.com/creative-commons/" title="creative commons" target="_blank"><img src="http://e-booknow.com/blog/wp-content/plugins/photo_dropper/images/cc.png" alt="Creative Commons License" align="absmiddle" border="0" height="16" width="16" /></a> <a href="http://www.photodropper.com/photos/" target="_blank">photo</a> credit: <a href="http://www.flickr.com/photos/43698630@N00/839984821/" title="gutter" target="_blank">gutter</a></small></td>
</tr>
</table>
<p>I did some searching to see if I could force an echeck on him but it doesn&#8217;t appear that that is controlled in the Buy Now button code.  I was able to change some of the code and deactivate his product delivery system (at least for my order alone).  Anyhow, it was a good lesson in being aware of what&#8217;s out there so you don&#8217;t lose a few sales to thieves.</p>
<p>There are still several problems with the hack.  If the hacker pays with his paypal account or credit card, he has divulged his identity.  Who&#8217;s going to ship a product if they only receive payment of a penny?  It appears the hacker would have to steal someone&#8217;s credit card to pull it off and remain anonymous but what&#8217;s the point?  He&#8217;d only be doing a favor to the cardholder by charging a penny per product.  I wouldn&#8217;t even dignify this little trick by calling it a hack.  It&#8217;s pretty brainless.  In the end, it&#8217;s a good argument for encrypting your Buy Now buttons.</p>
]]></content:encoded>
			<wfw:commentRss>http://e-booknow.com/blog/2008/02/29/the-truth-about-hacking-paypal-buy-now-buttons/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
