Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Networking

    Black Hat: Credit Card Payment Terminals at Risk

    Written by

    Sean Michael Kerner
    Published July 26, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      LAS VEGAS €” Payment terminals are ubiquitous in modern society, enabling us to pay for anything we want with a credit card. At the Black Hat security conference here, a pair of security researchers demonstrated in front of a live audience that those payment terminals are not as secure as they should be.

      In a talk titled €œPinpadpwn,€ security researcher Rafael Dominguez Vega and the legendary hacker known only as Nils, explained that the attack surface for payment terminals has grown as usage has gone up. Nils is perhaps best known as the man that walked into the Pwn2own hacking challenge in 2009 and deftly hacked all three major Web browsers.

      In setting the groundwork for their exploitation, Vega noted that payment terminals are essentially small computers, and as is the case with any other machine that takes in data, there are vulnerabilities. The two researchers were able to acquire multiple payment machines from eBay. Vega commented that it’s now easy and cheap to buy payment terminals online as the current economic slowdown has forced a lot of businesses to close and sell their assets.

      During their research, Nils said that they found vulnerabilities with all the payment card terminal vendors. That said, Nils stressed that in his presentation, there would be no €œnaming and shaming€ of the affected vendors. He added that the two researchers also responsibly disclosed the vulnerabilities to vendors, as well.

      Among the exploits that Nils was able to demonstrate in front of the lively Black Hat audience, was how he could insert a malicious payment card into a payment card unit and get the system to do what he wanted. In the first demonstration, Nils got the payment card terminal to load his own custom code€”much to the audience’s delight€”and began to play a simple arcade game. Then to prove he had full control of the device, Nils printed out the game score with the payment terminal printer.

      “We have code execution in the context of the payment application,” said Nils, adding that the system€™s vendor is now working on a fix.

      In another demo, Nils put in a malicious payment card with a picture of the Disney Tinkerbell character.

      “Tinkerbell will put the pixie dust on the machine for us,” said Nils.

      The €œpixie dust€ is in fact some malicious code that sits on the payment terminal. An attacker would attempt to use the card, get an invalid card error and then just walk away. What actually happened on the payment card terminal is that Nils’ code is running and collecting all future inputted credit card information.

      Nils then pulled out a payment card with a picture of Winnie the Pooh on it.

      “Winnie the Pooh is now retrieving the honey from the terminal,” said Nils. “The honey being the money and credit card information.”

      With the Tinkerbell and Pooh attack, Nils said he reported the vulnerability to the vendor at the beginning of July and a patch has already been issued. That said, he noted that it will likely take some time before all the affected terminals are updated.

      “There is a lot of trust in the use of payment terminals,” said Nils. “While there is a lot of effort put into the physical security of the devices, we would like to see similar effort put into the software security, too.”

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×