{"id":240982,"date":"2024-07-08T20:50:03","date_gmt":"2024-07-08T20:50:03","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/08\/hackers-reverse-engineer-ticketmasters-barcode-system-to-unlock-resales-on-other-platforms\/"},"modified":"2025-06-25T17:15:12","modified_gmt":"2025-06-25T17:15:12","slug":"hackers-reverse-engineer-ticketmasters-barcode-system-to-unlock-resales-on-other-platforms","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/08\/hackers-reverse-engineer-ticketmasters-barcode-system-to-unlock-resales-on-other-platforms\/","title":{"rendered":"Hackers reverse-engineer Ticketmaster\u2019s barcode system to unlock resales on other platforms"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>Scalpers have used a security researcher\u2019s findings to reverse-engineer \u201cnontransferable\u201d digital tickets from Ticketmaster and AXS, allowing transfers outside their apps. The workaround was revealed in a lawsuit AXS filed in May against third-party brokers adopting the practice, according to <em>404 Media<\/em>, which first <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:1;pos:1\" class=\"link \" href=\"https:\/\/www.404media.co\/scalpers-are-working-with-hackers-to-liberate-non-transferable-tickets-from-ticketmasters-ecosystem\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:reported;elm:context_link;elmt:doNotAffiliate;cpos:1;pos:1;itc:0;sec:content-canvas\">reported<\/a> the news.<\/p>\n<p>The saga began in February when an anonymous security researcher, going by the pseudonym Conduition, <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:2;pos:1\" class=\"link \" href=\"https:\/\/conduition.io\/coding\/ticketmaster\/?ref=404media.co\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:published technical details;elm:context_link;elmt:doNotAffiliate;cpos:2;pos:1;itc:0;sec:content-canvas\">published technical details<\/a> about how Ticketmaster generates its electronic tickets. If you aren\u2019t already familiar with how modern e-ticketing systems work, Ticketmaster and AXS lock ticket resales inside their platforms, preventing transfers on third-party services like <a data-i13n=\"cpos:3;pos:1\" href=\"https:\/\/www.engadget.com\/2015-11-19-seatgeek-ticket-reselling.html\" data-ylk=\"slk:SeatGeek;cpos:3;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \">SeatGeek<\/a> and <a data-i13n=\"cpos:4;pos:1\" href=\"https:\/\/www.engadget.com\/recommended-reading-stubhub-4-billion-worst-timing-ever-140040365.html\" data-ylk=\"slk:StubHub;cpos:4;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \">StubHub<\/a>. (For higher-priority events, they often take it a step further by prohibiting transfers to other accounts on the same platform.)<\/p>\n<p>Although the companies claim the practice is strictly a security measure, it also conveniently allows them to control how and when their tickets are resold. (Yay, capitalism?)<\/p>\n<figure class=\"caas-figure\">\n<div class=\"caas-figure-with-pb\" style=\"max-height: 540px\">\n<div>\n<div class=\"caas-img-container caas-img-loader\" style=\"padding-bottom:56%\"><img decoding=\"async\" class=\"caas-img caas-lazy has-preview\" alt=\"Side-by-side phone screenshots of the Ticketmaster app showing event barcodes.\" src=\"https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/MrbKKJ3UzLiDabwf5AO7wQ--\/YXBwaWQ9aGlnaGxhbmRlcjt3PTk2MDtoPTU0MA--\/https:\/\/s.yimg.com\/os\/creatr-uploaded-images\/2024-07\/f694c5e0-3d5e-11ef-bffa-b9f3507082ec\"\/><img decoding=\"async\" alt=\"Side-by-side phone screenshots of the Ticketmaster app showing event barcodes.\" src=\"https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/MrbKKJ3UzLiDabwf5AO7wQ--\/YXBwaWQ9aGlnaGxhbmRlcjt3PTk2MDtoPTU0MA--\/https:\/\/s.yimg.com\/os\/creatr-uploaded-images\/2024-07\/f694c5e0-3d5e-11ef-bffa-b9f3507082ec\" class=\"caas-img\"\/><\/div>\n<\/div>\n<\/div>\n<p><figcaption class=\"caption-collapse\"><span class=\"caption-credit\"> Ticketmaster<\/span><\/figcaption><\/p>\n<\/figure>\n<p>Ticketmaster and AXS create their \u201cnontransferable\u201d tickets using rotating barcodes that change every few seconds, preventing working screenshots or printouts. On the back end, it uses similar underlying tech similar to <a data-i13n=\"cpos:5;pos:1\" href=\"https:\/\/www.engadget.com\/twilio-hack-leaves-authy-users-exposed-to-text-messaging-scams-165156650.html\" data-ylk=\"slk:two-factor authentication apps;cpos:5;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \">two-factor authentication apps<\/a>. In addition, the codes are only generated shortly before an event starts, limiting the window for sharing them outside the apps. Without interference from outside parties, the platforms get to lock ticket buyers into their own resale services, giving them vertical control of the entire ecosystem.<\/p>\n<p>That\u2019s where the hackers come in. Using Conduition\u2019s published findings, they extracted the platforms\u2019 secret tokens that generate new tickets, using an Android phone with its Chrome browser connected to Chrome DevTools on a desktop PC. Using the tokens, they create a parallel ticketing infrastructure that regenerates genuine barcodes on other platforms, allowing them to sell working tickets on platforms Ticketmaster and AXS don\u2019t allow. Online reports claim the parallel tickets often work at the gates.<\/p>\n<p>According to <em>404 Media<\/em>, AXS\u2019 lawsuit accuses the defendants of selling \u201ccounterfeit\u201d tickets (even though they usually work) to \u201cunsuspecting customers.\u201d The court documents allegedly describe the parallel tickets as \u201ccreated, in whole or in part by one or more of the Defendants illicitly accessing and then mimicking, emulating, or copying tickets from the AXS Platform.\u201d<\/p>\n<p>AXS\u2019 lawsuit claims the company doesn\u2019t know how the hackers are doing it. The promise of essentially jailbreaking Ticketmaster is so lucrative that several brokers have reportedly tried hiring Conduition to help them build their own parallel ticket-generating platforms. Services already operating on the researcher\u2019s findings go by names like Secure.Tickets, Amosa App, Virtual Barcode Distribution and Verified-Ticket.com.<\/p>\n<p><em>404 Media<\/em>\u2019s <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:6;pos:1\" class=\"link \" href=\"https:\/\/www.404media.co\/scalpers-are-working-with-hackers-to-liberate-non-transferable-tickets-from-ticketmasters-ecosystem\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:entire story is worth reading;elm:context_link;elmt:doNotAffiliate;cpos:6;pos:1;itc:0;sec:content-canvas\">entire story is worth reading<\/a>. More technically minded folks may take an interest in Conduition\u2019s earlier findings, which illustrate what the ticketing behemoths are <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:7;pos:1\" class=\"link \" href=\"https:\/\/conduition.io\/coding\/ticketmaster\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:doing on their back ends;elm:context_link;elmt:doNotAffiliate;cpos:7;pos:1;itc:0;sec:content-canvas\">doing on their back ends<\/a> to <a data-i13n=\"cpos:8;pos:1\" href=\"https:\/\/www.engadget.com\/ticketmaster-owner-sued-by-doj-and-30-attorneys-general-over-alleged-monopoly-160153725.html\" data-ylk=\"slk:keep the entire ecosystems in their clutches;cpos:8;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \">keep the entire ecosystems in their clutches<\/a>.<\/p>\n<\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.engadget.com\/hackers-reverse-engineer-ticketmasters-barcode-system-to-unlock-resales-on-other-platforms-194826061.html?src=rss\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Scalpers have used a security researcher\u2019s findings to reverse-engineer \u201cnontransferable\u201d digital tickets from Ticketmaster and AXS, allowing transfers outside their apps. The workaround was<\/p>\n","protected":false},"author":1,"featured_media":240983,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[159],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/240982"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=240982"}],"version-history":[{"count":0,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/240982\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/240983"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=240982"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=240982"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=240982"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}