Hacker News new | past | comments | ask | show | jobs | submit login

Care to elaborate on the flaw in their system that you exploited? I'm sure I'm not the only one interested.



Sure. This was somewhere around 10 years ago so my memory is slightly fuzzy on all the technical details but heres the gist of it:

As an operator your main interface to their system was a Java desktop application. Basically you sit there waiting for it to go 'ding!', you read the question, and accept if you think you're capable of answering. You would research (they heavily pushed their sources but Google was better about 100% of the time) and then communicate the answer back to the user using the application.

Once it was accepted the application would make an HTTP request to ChaCha's server to basically say 'A question was answered by this user'. This was easily visible using normal tools like Wireshark, etc. For your efforts you would be rewarded some very small amount of money, something like $.02.

I simply wrote a VB.NET application to hit this HTTP endpoint over and over again which would add money to my account without me doing any work. They didn't seem to be doing any verification that I had actually been given questions to answer.

The reason they noticed me was because I left ~8 instances of this program running for like 3 days straight which netted me hundreds of dollars ready to be cashed out, way more than any operator would be even remotely capable of normally given their pay scheme. So I was smart enough to figure this out but dumb enough to get caught almost immediately. And I'm not a lawyer but my guess is that this was considered fraud. Glad my morals eventually straightened out before I got myself in real trouble, honestly this was a decent lesson for 15 year old me.


>> honestly this was a decent lesson for 15 year old me

And not a bad lesson for the company, either :)


It honestly sounds like Cookie Clicker, but for money..

(If you don't know what that is, just stay away)




Consider applying for YC's first-ever Fall batch! Applications are open till Aug 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: