salmg/academy
Sign in

Terms of use

This is a teaching platform for payment-systems security. One rule matters more than the rest: test only what you own, or what you hold written authorisation to test.

Last reviewed 2026-08-31

What this site is for

This is a teaching platform for payment-systems security. It exists so that researchers, students, penetration testers, engineers building payment systems, and the people who have to defend them can understand how these protocols actually work — including how they fail.

Everything here is published research, public specification, or analysis of data captured from cards and terminals the author was authorised to test. Nothing on this site is a novel undisclosed vulnerability, and nothing here is offered as a tool for committing fraud.

Acceptable use

Test only what you own, or what you hold written authorisation to test. That sentence is the whole of the acceptable-use policy, and everything below is a consequence of it.

In most jurisdictions, using a payment credential you are not entitled to use is a criminal offence regardless of your intent, and so is intercepting a transaction between parties who have not asked you to. "It was for research" describes a motive. It is not a legal defence, and it is not one this site can provide you with.

Payment schemes publish test card sets, and test terminals can be bought. If a question can be answered with a test card, answer it with a test card.

Cardholder data

Do not send real cardholder data to this site — not in an exercise answer, not in a support message, not in a capture. There is no facility for accepting it and no lawful basis for holding it.

The captures published here were sanitised before they were stored, not before they were published: every account number was replaced with a published test number and every record rebuilt around it, including the certificates that would otherwise let the original be recovered. The method is taught in the course, because getting it wrong is easy and the failure is silent.

Accounts

You are responsible for your account and for keeping your password and any second factor to yourself. Tell us if you think someone else has access to it. Accounts are for one person; enrolments are not transferable.

Accounts that are used to distribute course material, or to attack this site or its other users, are closed without a refund.

The material itself

The lessons, diagrams, exercises and sanitised captures are the author's work and are licensed to you for your own study. Quote from them with attribution; do not republish them wholesale or resell them.

Specifications, papers and reports cited on the references page belong to their authors and publishers, and are linked rather than reproduced.

No warranty, and what that means here

The material is provided as it is. It is researched carefully and corrected in public when it turns out to be wrong — several lessons carry a note saying what this course previously got wrong and how it was found — but no course can promise to be current with a field that moves this fast, and none of it is legal, compliance or security advice for your specific system.

To the extent the law allows, the author is not liable for what you do with what you learn here.

Found a problem with this site

Reports about this platform's own security are welcome. Tell us before telling anyone else, give us a reasonable time to fix it, and do not access other people's accounts or data while proving your point. Findings handled that way get credited.