TechGromit wrote: » interesting attack, I wonder if payments from customers were also processed by newegg as well. It's would become pretty apparent pretty quickly that something was wrong if customers suddenly stopped ordering anything from your website, when you had hundreds, if not thousands of transactions a day, the day before. If so, a better approach would be to either forward the payment information to the actual egghead payment server so there no indication of an issue, or some kind of randomizer that was redirect only limited number of customers per hour.