CASH PAYMENT in MALAYSIA #wckl koko crunch WARNING: highly technical
May 24, 2015
CASH PAYMENT in MALAYSIA
#wckl koko crunch
WARNING: highly technical
@arzumy
SAYS
GROUPON
GROUPON
ipay88
maybank2u
billplz
billplz
fpx
rhb now
FPX, MAYBANK2U & RHB NOW
requirements workflow
featuresAPI calls
why
WHY CASH PAYMENT
DISCLAIMER!
TECH REQUIREMENTS
FPX
java public ip*
*not really
web app
ssl public ip*
*not really, if you can convince them
web app
MAYBANK2U
public ip*
*not really
web app
RHB NOW
GENERAL WORKFLOW
reading drive c:
FPX
our app fpx bank
java daemon
browser
our app maybank2ubrowser
MAYBANK2U
our app rhb nowbrowser
RHB NOW
FEATURE: SANDBOX
FPX M2U RHB
Y Y YIP
whitelistOffice hour
make sure your account manager is online
FEATURE: REQUERY
FPX M2U RHB
Y Y Y
beg & steal browseronly
N
FEATURE: SECURITY
FPX M2U RHB
obscurity&
trust
hashedrequest
signedxml
PEEK AT THE API CALLS
FPXmessage:request|message.type:AR|message.token:01|message.orderno:720136345498125710....
<?xml version="1.0" encoding="UTF- 8"?><SELLER_FPX_REQ><MESG_TYPE>AR</MESG_TYPE><MESG_T OKEN>01</MESG_TOKEN>....
POST ?MsgToFpx=<?xml version="1.0" encoding="UTF- 8"?><SELLER_FPX_REQ><MESG_TYPE>AR</MESG_TYPE><MESG_T OKEN>01</MESG_TOKEN>....
...and repeat string manipulation
GET ?sendString=Login$111$1$125.00$1$ABC1234$$$https://XYZ/...
response
MAYBANK2U
?transDate=2009-11-26T18:10:36.195+08:00&status=00&transAmo...
request
FORM POST
response
request
RHB NOW
FORM POST
OTHER MISC STUFFTHAT I CAN THINK OF
ON THE SPOTIF WE HAVE TIME
HELP THE COMMUNITY@arzumy