Man dupes travel portals, books 1,500 air tickets without paying a penny

A Master mind in hacking payment gateway

Image result for air ticket payment gateway hack



Who is he ? 

a man smiling for the camera: Rajpratap Parmar

A 27-year-old man from Madhya Pradesh allegedly took at least four travel portals for a ride by booking over 1,500 air tickets without paying a single penny in the last two years. Rajpratap Parmar, who was arrested on Tuesday along with two of his relatives from Datia, made around Rs 2 crore in the process, said the police.

After discovering an alleged loophole in the payment gateway system of the portals, Parmar — a Class XII passout — approached several travel agencies across the country and provided them air tickets at 80 per cent of the rates available in the market.

How it is started to find ?

The alleged scam was unearthed when a Mumbai-based man booked air tickets for Goa. When he took a printout of the air tickets, he realized that the mobile number and email address mentioned on the ticket did not belong to him. Also, the amount that he had paid and the one mentioned on the ticket was different.

Suspecting that his details may have been compromised, the man submitted written complaints to unit 7 of the Mumbai Crime Branch. During investigation, unit VII in charge Satish Taware and Inspector N Sridhankar found out about the scam.

An officer probing the case said that nearly two years ago, Parmar, who hails from Datia in MP, discovered a loophole in some of the travel portal payment gateways.

How he Hacked ?

Parmar would accept travel bookings from agents across the country. While filling in the person’s details online, he would enter an incorrect mobile number and email address to ensure that the person does not receive any alert. He would then enter his card details and continue with the transaction till he had to select between the submit and cancel payment options,” he added.
At this point, he would click on cancel and press escape several times to freeze the page. He would then tinker with the URL and write ‘success’ in the URL address bar to show that he had clicked on submit. He then copy-pasted the link to another tab and pressed enter. The system would think the payment has been authorized and generate tickets without Parmar actually having made any payment,” the officer said.
Image result for air ticket payment gateway hack

Published by arjunpremier

Software Engineer, Blogger,

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Design a site like this with WordPress.com
Get started