hard to believe he's clever enough to get one over on the payment processing system and not clever enough to not hit the same place several times!!!
MIND BOGGLING
Spanish police arrested a hacker who allegedly manipulated a hotel booking website, allowing him to pay one cent for luxury hotel stays. He also raided the mini-bars and didn't settle some of those tabs, police say. "This cyberattack was specifically designed to alter the payment validation system, and this is the first time …
"hard to believe he's clever enough to get one over on the payment processing system and not clever enough to not hit the same place several times!!!"
And staying multiple nights at a time.
If the billing was heavily discounted rather than free, nobody may have noticed. Could have been a coupon, points, package deal, etc. Creating a coupon code in the system and using that to get a top end room for budget pricing would have been a better hack.
The "loss" by the hotel is really their housekeeping and mini bar since I'd be amazed if the super expensive rooms are booked solid. We all know that a £9 bottle of water doesn't cost them more than 50p and a tiny bag of crisps about the same.
"...We all know that a £9 bottle of water doesn't cost them more than 50p and a tiny bag of crisps about the same..."
Blasphemy!!!
Do you have any idea how much individually wrapped cashews cost ?!? Those are bespoke items !!! The best of the best. They have to have an order of magnitudes longer shelf life as they are never used nor replaced, yet they have to taste just as stale when perfectly fresh. They have to be sound-resistant and not crumble when a parent screams at some lost kid who unrwapped them before they could stop him, they are individually and manually infused at the factory with purified guilt...Little idea do you have of the work that goes in crafting those.
Though the hack in the article was probably more sophisticated, I had a customer using PayPal who replicated what PayPal sends back to me with a legitimate order. They paid $0.01 so that an actual order was raised, but managed to send me something that told me it was the correct amount. As I'm selling software registration codes, I sent the code before I realised, so that was something I couldn't take back. It only happened once, and I've changed the system now, and blocked the code so it can't be used again. I considered more robust checks, but most of those would have involved not trusting valid customers, so the potential push-back and loss of sales from that was not worth it, much like over-aggressive copy protection on software in years gone by.