Professor
Professional
- Messages
- 1,752
- Reaction score
- 1,718
- Points
- 113
From Site Reconnaissance to Systematic Execution
INTRODUCTION
This manual is designed for carders who already understand the fundamentals of carding: working with proxies, anti-detect browsers, and having access to quality material. However, if you're still receiving cancellations one after another, the problem isn't your technique — it's your strategic approach to target selection and site adaptation.Modern carding in 2026 is not simply carding. It's analytical work encompassing target reconnaissance, understanding anti-fraud system architecture, knowledge of payment gateways, and the ability to build trust in your transaction. Fraud systems have evolved: they now use AI, analyze behavioral patterns, and adapt in real time.
This manual is your filter for site selection. Don't waste time on targets that don't pass inspection. Better to study 10 sites and successfully card 3 than to hammer 50 sites and get cancellations everywhere.
PART 1: FOUNDATION — BASIC REQUIREMENTS
Before diving into the checklist, ensure your infrastructure meets the minimum requirements for 2026.1.1 Material (CC)
| Requirement | Why It Matters | How to Verify |
|---|---|---|
| Non-VBV BIN | 3D Secure kills 90% of transactions. Non-VBV cards pass without OTP | Check dump tags: 3DS: No, VBV: N |
| Active balance | Dead card = wasted time | Use good card checkers |
| Fresh status | Compromised card may be blacklisted | Check via checker before purchase |
| BIN analysis | Business/Signature/Platinum have higher limits | binx.vip, binbase.com, bins.pro |
Key point: Non-VBV cards aren't just "cards without 3DS." They're cards whose issuer doesn't participate in the verification program, or the transaction is classified as low-risk. Non-VBV card prices are 3-10x higher than VBV, but success rate on 2D gateways reaches 70-85% versus 5-10% for VBV.
1.2 Proxies
| Type | Reliability | For Which Operations |
|---|---|---|
| Residential (ISP) | 10/10 | Primary choice. IPQS score > 80 |
| Mobile (4G/5G) | 9/10 | For high-value transactions, PayPal |
| Datacenter | 3/10 | DO NOT USE — instant flag |
Verification: whoer.net, pixelscan.net, IPQS. Score must be > 80 out of 100. Proxy time must match cardholder billing time (difference no more than 1 hour).
1.3 Anti-Detect Browser
| Browser | Price | Features |
|---|---|---|
| Octo Browser | $29/mo | Good balance, stable |
| Linken Sphere | $50/mo | Powerful but complex |
| Dolphin Anty | $20/mo | Simple interface |
| Incogniton | $19/mo | Cheap, stable |
Settings: WebRTC disabled, Canvas not static, timezone = proxy, language = cardholder region.
1.4 Operating System & Device
Modern anti-fraud systems analyze device fingerprints. Windows 10/11 covers 65% of users — optimal choice. macOS for premium segment. Avoid Linux — instant red flag. Mobile emulation (Android/iOS) for mobile-first platforms.PART 2: SITE RECONNAISSANCE CHECKLIST — 6 CRITICAL QUESTIONS
This is the core of the manual. Each question is a vulnerability check before carding. Skipping one point = high cancellation risk.
QUESTION 1: Can I place an order with any email address?
Why it's critical:Email is one of the strongest legitimacy indicators for anti-fraud systems. Using the cardholder's email (from a log) reduces fraud score by 20-40%. If the site allows guest checkout with any email — even better.
How to test:
| Check | Testing Method | What It Gives You |
|---|---|---|
| Guest checkout with any email | Try ordering without registration, use arbitrary email | No email access needed |
| Registration without verification | Create account with non-existent email | No inbox access needed |
| Confirmation sent to unverified email | Check if email arrives after order | You can see order status |
2026 Reality: Many sites sacrifice security for conversion. Email verification creates friction — and friction = lost sales. Look for sites without it. However, remember: absence of verification doesn't mean absence of other protections.
Strategy: If site requires email verification — use email from cardholder log. If no log — find another site.
QUESTION 2: Can I track order status without an account?
Why it's critical:Without tracking, you work blind. You don't know if the order shipped, was cancelled, or is sitting in manual review. By the time you find out — it's too late to change anything.
Tracking types:
| Site Type | How to Track | Difficulty | Suitability |
|---|---|---|---|
| Direct status URL | /order-status/12345 | Easy | Ideal |
| Order number + ZIP required | Enter two fields | Medium | Acceptable |
| Account only | Login required | Hard | Avoid |
| OTP to email | Cardholder email access needed | Very Hard | Only with log |
Tip: Look for sites where status is available by order number. That's your reconnaissance. If site requires account — it's a minus, but not a dealbreaker if you have cardholder email access.
QUESTION 3: Can I change shipping address after checkout?
Why it's a weapon:You use cardholder billing to pass anti-fraud (AVS check passes). But the package needs to go elsewhere. If the site allows address change after checkout — that's gold.
Two approaches:
- Self-service through order management — if "Change Address" option exists in account or via email link.
- Through support — social engineering.
How to test:
- Study FAQ, Shipping Policy, Return Policy — often states if address change is possible.
- Make test order for small amount ($1-5) with dummy card.
- Check if account has "Address Change" section.
Pro tip: Support operators are low-wage employees who don't always follow security protocols. The "oops, wrong address, can you fix it?" story works 60-70% of the time.
Risk: If site requires identity verification for address change — red flag. Avoid such sites.
QUESTION 4: Can I change recipient email after order?
Critical for digital goods:Gift cards, subscriptions, games. Some sites allow changing recipient email after purchase — because email typos are a common problem.
Scheme:
- Use cardholder email at checkout (passes anti-fraud)
- After order processing, change recipient email to yours
- Gift card arrives to you
Amazon — classic example: Their anti-fraud is strict, but they allow changing recipient email for digital codes. With a good log, you're virtually invisible.
How to test:
- Make test order for digital product at minimum amount.
- Check if "Change recipient email" option exists in confirmation email.
- If not — try through support.
Risk: If site blocks email change after order — it's fraud protection. Avoid such sites for digital goods.
QUESTION 5: Can I change shipping address after PayPal authorization?
This is the cutting edge of carding:Some sites use PayPal Standard Checkout, which has a critical vulnerability:
- Enter real cardholder address when paying via PayPal
- PayPal conducts fraud check and approves (address known, high trust)
- Before final confirmation on site — change address to drop
- PayPal already conducted check, order processes
Why it works: PayPal checks transaction on their side, but site may allow data change before final confirmation.
How to find:
- Look for sites with PayPal Standard Checkout (not Express).
- Check if there's a confirmation step after returning from PayPal.
- Test on small amounts.
Important: Many sites use Express Checkout, which processes data instantly. But if you find a site with Standard — it's pure gold.
Risk: PayPal may block account on suspicious activity. Don't use your main PayPal for tests.
QUESTION 6: What's the site's anti-fraud and payment gateway?
Payment gateway identification:| Gateway | HTML Signs | Features | Bypass Risk |
|---|---|---|---|
| Stripe | js.stripe.com | Good anti-fraud, but bypasses exist | Medium |
| Braintree | braintreegateway.com | Softer than Stripe | Low |
| Authorize.net | authorize.net | Old, many holes | Low |
| Shopify Payments | shopify.com | Strict, but MOTO exists | High |
| PayPal Standard | paypal.com | Vulnerable to address change | Low |
How to identify: Open browser console (F12) → Network → look for requests to payment domains.
Anti-fraud system identification:
| System | Signs | Bypass Difficulty |
|---|---|---|
| Forter | Aggressive, AI-based | High |
| Riskified | Medium, behavioral | Medium |
| Kount | Hard, lots of data | High |
| Sift | Behavioral | Medium |
| No system | Only basic checks | Low |
Tip: Start with sites where anti-fraud is weak (Braintree, Authorize.net). Avoid Forter and Kount initially.
PART 3: STEP-BY-STEP SITE WORKING GUIDE
Step 1: Reconnaissance (1-2 days per site)
What to do:- Study FAQ, Shipping Policy, Return Policy, Privacy Policy.
- Check how to track order (try to find status page).
- Find support contacts (email, phone, chat).
- Determine payment gateway (via HTML or test order).
- Check for 3DS (test order for $1).
- Determine anti-fraud system (via HTML or indirect signs).
What to log:
- Site URL
- Payment gateway
- Anti-fraud system
- 3DS presence
- Order tracking method
- Address/email change capability
Step 2: Test Order ($1-5)
What to do:- Place order with dummy card (not cardholder).
- Check if passes without 3DS.
- See how to track status.
- Try changing address/email after order.
- Check if confirmation arrives to email.
What to record:
- Did order pass
- Was there 3DS
- How to track
- Can data be changed
Step 3: Main Order
Parameters:- Email: Cardholder email (if possible) or yours
- Billing: Cardholder address (to pass AVS)
- Shipping: Drop address (if possible)
- Amount: No more than 30-40% of card limit
- Time: Working hours by cardholder timezone (9:00–21:00)
What to do:
- Warm-up: 15-30 minutes mimicking real behavior
- Manual data entry (no copy-paste)
- Delays between fields (2-5 seconds)
- Single click on payment button
Step 4: Post-Processing
What to do:- Track status every 24 hours
- If pending > 3 days — call support
- If shipped — work with reroute
- Record result in log
If cancelled:
- Check error code (F12 → Network → Response)
- card_declined — dead card
- fraudulent — anti-fraud triggered
- 3d_secure_required — 3DS, need Non-VBV card
PART 4: STRATEGIES, TRICKS AND NUANCES
4.1 Profile Warm-Up
What to do:- Visit 3-4 major legitimate resources (Wikipedia, CNN, local news)
- Enter site via search engine (Google), not direct link
- Spend 5-10 minutes on site
- Browse 3-4 products, add to comparison
- Study "About Us" and "Shipping Policy"
- Add item to cart and wait 2-3 minutes
What not to do:
- Don't go directly to checkout
- Don't use identical patterns for different orders
- Don't warm up too long (over 1 hour — suspicious)
4.2 Working with AVS
AVS (Address Verification System) compares billing address with address on card. If mismatch — cancellation.How to pass:
- Billing = cardholder address (from Fullz)
- ZIP must match exactly
- If unsure — verify cardholder via WhitePages/TruthFinder
4.3 Working with 3DS
If card is VBV:- Look for Non-VBV BIN
- Use threshold exemptions (amount < €30)
- Social engineering (not recommended for beginners)
If card is Non-VBV:
- Use 2D gateways
- Avoid sites with mandatory 3DS
4.4 Working with PayPal
Address change scheme:- Enter cardholder address at payment
- Wait for PayPal authorization
- Before final confirmation on site, change address to drop
Risks:
- PayPal may block account
- Not all sites support this vulnerability
4.5 Working with Digital Goods
Recipient email change scheme:- Use cardholder email at checkout
- After order processing, change recipient email to yours
- Gift card arrives to you
Sites with this vulnerability: Amazon, some gift card shops.
PART 5: COMMON MISTAKES AND HOW TO FIX THEM
| Mistake | Why It's Bad | How to Fix |
|---|---|---|
| Carding without site reconnaissance | You don't know what awaits you | 1-2 days studying |
| Using your own email | Higher fraud score | Use cardholder email |
| Billing ≠ cardholder address | AVS mismatch | Always billing = cardholder |
| Ignoring 3DS | Wasting time on 3D sites | Test with $1 |
| No order tracking | Working blind | Find tracking method |
| Amount > 40% of limit | Fraud trigger | Split into parts |
| Too fast checkout | Bot pattern | Add delays |
| Using one antidetect | Single fingerprint | Change settings |
| Ignoring checker | Wasting time on dead cards | Always check |
| Repeat carding on same site | IP/fingerprint ban | Change proxy and antidetect |
PART 6: RISKS AND MINIMIZATION
6.1 Technical Risks
| Risk | Probability | Minimization |
|---|---|---|
| Proxy blocked | Medium | Use residential, change every 2-3 orders |
| Antidetect burned | Medium | Check on browserleaks.com |
| WebRTC leak | High | Disable WebRTC, check on ipleak.net |
| Static fingerprint | Medium | Change resolution, fonts, language |
6.2 Operational Risks
| Risk | Probability | Minimization |
|---|---|---|
| Cancellation after shipping | Medium | Track status, call support |
| Package return | Medium | Work with reroute |
| Account block | High | Don't use one account for many orders |
| Cardholder chargeback | High | Act fast, don't wait |
6.3 Legal Risks
| Risk | Probability | Minimization |
|---|---|---|
| Law enforcement tracking | Low (for small operations) | Use anonymizers |
| Account freezing | Medium | Don't store money in one account |
| Prosecution | Low | Don't work in your own country |
PART 7: COMPLETE PRE-CARDING CHECKLIST
Infrastructure
- □ Proxy residential, IPQS > 80
- □ Proxy time = cardholder billing
- □ Antidetect configured, WebRTC disabled
- □ Canvas not static
Material
- □ Card Non-VBV (or VBV with bypass)
- □ Balance verified
- □ Fullz with SSN/DOB
- □ Billing verified
Site
- □ Reconnaissance complete (1-2 days)
- □ Payment gateway identified
- □ Anti-fraud identified
- □ 3DS checked
- □ Order tracking found
- □ Address change possible
- □ Email change possible (for digital)
Order
- □ Cardholder email (if possible)
- □ Billing = cardholder address
- □ Shipping = drop address
- □ Amount < 40% of limit
- □ Working hours by cardholder
- □ Warm-up 15-30 minutes
- □ Manual data entry
Post-Processing
- □ Status tracked
- □ Log filled
- □ Plan B (call, reroute)
PART 8: KEY CONCLUSIONS
- Reconnaissance matters more than carding. 1-2 days studying a site will save you weeks of failure.
- Cardholder email is the key to trust. Fraud systems see email history and grant more trust.
- Non-VBV cards are gold. 70-85% success on 2D gateways versus 5-10% for VBV.
- Address change after order is your trump card. Use cardholder billing to pass, then change to drop.
- PayPal Standard is a vulnerability. If you find a site with this vulnerability — it's pure gold.
- Logging is the only way to find working sites. Keep a log of all attempts.
- AI changed the game. Fraud systems now analyze behavior in real time. Your job is to look like a real user.
- Fraud systems are built by humans. They have weaknesses. Your job is to find those cracks.
PART 9: ADVANCED TECHNIQUES
9.1 Behavioral Mimicry
Modern fraud systems track micro-movements of cursor and typing speed. Simulate human input via Bezier curves with randomized acceleration, avoiding linear trajectories. Before checkout, "scan" site content (scrolling, hovering over images) mimicking real user interest.9.2 Latency-Based Proxy Orchestration
For Stripe Radar, ping between client and gateway is critical. Choose proxy exit node with RTT < 30ms to cardholder billing address. Force DNS servers of same ISP to avoid DNS leak and timezone mismatch.9.3 Neural Behavioral Simulation (NBS)
Core of advanced approach. Anti-fraud tracks cursor micro-movements and keystroke dynamics. Use asynchronous interaction, DOM scanning, randomized delays.9.4 Direct Gateway API Injection (DAI)
In some cases, bypass standard Stripe Checkout form and work directly through API requests, emulating calls from mobile app. Header obfuscation: form X-Stripe-Client-User-Agent and Stripe-Version headers in exact accordance with current Stripe-Android or Stripe-iOS libraries.CONCLUSION
This manual is not just theory. It's your filter for site selection and strategy for successful operations. Each checklist point is a vulnerability check that can be exploited.Remember: success is directly proportional to thoroughness of reconnaissance. Don't skip steps out of laziness — that's how amateurs get caught. Work systematically, keep a log, adapt to each site — and results will come.
Good luck, brother. If anything — ask.