smscheck
p/smscheck
SMS Verification For Your Website
Bob Swinson
My SMS Check — Stop free trial spam and other fraud with a simple SMS check
3
Checks SMS for your users.
Replies
Bob Swinson
About 16 months ago, I was victim to a large card testing attack. A card testing attack's basically when an attacker is testing stolen credit cards with your payment gateway so that cards that can still be swiped will be either be used to make bigger purchases, or to be resold in the black market. Long story short, cost me a bunch of money. I solved it finally by having a 1-time SMS verification for my users that tries to access the payment page. And I ensure that the phone number they use is a real phone number (i.e. has a carrier). This makes it prohibitively expensive for any attacker to use multiple accounts in an attack. This stopped the attack while various other things like captcha, email verification, etc. didn't do anything. Instead of copy/pasting this solution for every single new SaaS I launch, I decided to centralize it to a server so I can more easily implement this technique in the future. And since this method's been working well to protect my sites, I thought I'd share it with you guys as well. Would love any feedback, and you get 20 free SMS verifications, along with significant tiered discounts for the first 100 customers! P.S: While you can just use this tool to protect your payment page, you can also use this to protect against users making 100s of emails to keep using your free trials without ever paying, and any other attacks that involve requiring multiple accounts to execute.
Cory Zue
I get fake / bot sign ups on all my sites a few months after launch. This looks like a super simple way to stop them. Congratulations on the launch!