Friday, February 26, 2010

Credit card skimming attacks on pay-at-the-pump petrol stations

According to US media reports, criminals have launched large-scale attacks on petrol pumps with built-in card payment systems to gain access to card data. Similar attacks that involve the attachment of special skimming devices over the legitimate equipment to copy card data, have previously only targeted cash points. Attackers often obtain the PIN with a hidden camera or a secondary PIN pad placed over the machine's original keyboard.

In the current cases, skimming devices attached to petrol pump terminals are said to use Bluetooth to transmit the data to criminals operating near by. The attackers then use the skimmed details to forge cards and withdraw money from cash points. Approximately 180 petrol pumps with pay-at-the-pump functionality from Salt Lake to Provo are said to have been manipulated by the currently unknown perpetrators. Local police at one location say the modification to the pump was unnoticeable. The fraud was only detected when several attack victims could be traced back to having used the same petrol pump at a 7-Eleven station.

Petrol stations with pay-at-the-pump functionality are also becoming increasingly popular in Germany and in the UK there are a considerable number of installations. So far there have been no reports of successful skimming attacks on UK or German pumps.

Similar to existing terminals in retail outlets, many systems at petrol stations support EMV and encrypt the communication between the card's chip and the terminal to a certain degree to impede skimming attacks. However, the magnetic stripes, still included on most cards for compatibility reasons, allow the criminals to read out data they are looking for.

Whether the EMV method, or the magnetic stripe was used for making a payment is ultimately inconsequential to customers – they tend to get their money refunded regardless. The difference is only important for establishing liability in cases of misuse. If the card wasn't EMV enabled, liability rests with the card issuer, which is generally the bank. If, on the other hand, the card was EMV enabled but the terminal wasn't, liability rests with the retailer. However, UK researchers demonstrated only recently that the EMV process used with UK cards is also open to attacks.

Monday, April 13, 2009

National Satellites are they Hackable ...!

According to
" http://www.infiltrated.net/amishAttacks.html "
reported on 9th april
"Security experts are reporting today that Amish hackers equipped with reverse engineered VCIM's have hacked into Instar's vehicle satellite navigation systems and are extorting Instar."
while some witnessess were also reported saying
"It's horrible. I was headed down Main Street and my Garmin told me to turn right. 20 minutes later not only was I was late for my interview, I went from being in Colorado to driving down Fifth Avenue in New York City." stated a visibly shaken John McSmith.


The article which reports the incident also shows pictures of the INstar device showing altered text. Although the authenticity of such news is a question in in itself but IMHO it seems practical to a point that the hacked VCIM can change the behavior of that particular device but not the satellite transmission itself. I would be looking forward for the details if any are released from some reliable source.

Thursday, March 12, 2009

Adobe Vulnerability takes a new turn

The new adobe vulnerability is now exploitable not only by reading the infected pdf file but also by at least three different methods using metadata which is used by windows to show file information. It turns out that adobe has a shell extension which get the file information. Security Researcher "Didier Stevens" have released a short video on his blog which shows how this vulnerability can be easily exploited in windows. The dangers associated with this vulnerability have leveraged the threat level using the JBIG2Decode exploit. Meanwhile a new exploit have also been released today which shows foxit pdf viewer (the alternative to adobe viewer) as the victim. The only tip that I can give you guys now is to only open files or should I say receive files from trusted sources.

The video and the original blog post can be found on the following links.
http://www.youtube.com/v/2poufBYBBoo&rel=1&fs=1&showsearch=0
http://blog.didierstevens.com/2009/03/04/quickpost-jbig2decode-trigger-trio/