According to US media reports, criminals have launched large-scale attacks on petrol pumps with built-in card payment systems to gain access to card data. Similar attacks that involve the attachment of special skimming devices over the legitimate equipment to copy card data, have previously only targeted cash points. Attackers often obtain the PIN with a hidden camera or a secondary PIN pad placed over the machine's original keyboard.
In the current cases, skimming devices attached to petrol pump terminals are said to use Bluetooth to transmit the data to criminals operating near by. The attackers then use the skimmed details to forge cards and withdraw money from cash points. Approximately 180 petrol pumps with pay-at-the-pump functionality from Salt Lake to Provo are said to have been manipulated by the currently unknown perpetrators. Local police at one location say the modification to the pump was unnoticeable. The fraud was only detected when several attack victims could be traced back to having used the same petrol pump at a 7-Eleven station.
Petrol stations with pay-at-the-pump functionality are also becoming increasingly popular in Germany and in the UK there are a considerable number of installations. So far there have been no reports of successful skimming attacks on UK or German pumps.
Similar to existing terminals in retail outlets, many systems at petrol stations support EMV and encrypt the communication between the card's chip and the terminal to a certain degree to impede skimming attacks. However, the magnetic stripes, still included on most cards for compatibility reasons, allow the criminals to read out data they are looking for.
Whether the EMV method, or the magnetic stripe was used for making a payment is ultimately inconsequential to customers – they tend to get their money refunded regardless. The difference is only important for establishing liability in cases of misuse. If the card wasn't EMV enabled, liability rests with the card issuer, which is generally the bank. If, on the other hand, the card was EMV enabled but the terminal wasn't, liability rests with the retailer. However, UK researchers demonstrated only recently that the EMV process used with UK cards is also open to attacks.
Showing posts with label creditcard. Show all posts
Showing posts with label creditcard. Show all posts
Friday, February 26, 2010
Thursday, January 29, 2009
Heartland Sniffer Hid In Unallocated Portion Of Disk
While I was surfing online today, this news was something really interesting.
“The sniffer malware that surreptitiously siphoned tons of payment card data from card processor Heartland Payment Systems hid in an unallocated portion of a server’s disk. The malware, which was ultimately detected courtesy of a trail of temp files, was hidden so well that it eluded two different teams of forensic investigators brought in to find it after fraud alerts went off at both Visa and MasterCard, according to Heartland CFO Robert Baldwin.”
“A significant portion of the sophistication of the attack was in the cloaking,” Baldwin said.
Payment security experts pretty much agreed that hiding files in unallocated disk space is a fairly well-known tactic. But it requires such a high level of access—as well as the skill to manipulate the operating system—that is also indicates a very sophisticated attack. One of those security experts—who works for a very large U.S. retail chain and asked to have her name withheld—speculated that the complex nature of the hiding place, coupled with the relatively careless leaving of temp files, could suggest a less-skilled cyberthief who simply obtained some very powerful tools.
The complete article can be found on http://www.storefrontbacktalk.com/securityfraud/heartland-sniffer-hid-in-unallocated-portion-of-disk/
“The sniffer malware that surreptitiously siphoned tons of payment card data from card processor Heartland Payment Systems hid in an unallocated portion of a server’s disk. The malware, which was ultimately detected courtesy of a trail of temp files, was hidden so well that it eluded two different teams of forensic investigators brought in to find it after fraud alerts went off at both Visa and MasterCard, according to Heartland CFO Robert Baldwin.”
“A significant portion of the sophistication of the attack was in the cloaking,” Baldwin said.
Payment security experts pretty much agreed that hiding files in unallocated disk space is a fairly well-known tactic. But it requires such a high level of access—as well as the skill to manipulate the operating system—that is also indicates a very sophisticated attack. One of those security experts—who works for a very large U.S. retail chain and asked to have her name withheld—speculated that the complex nature of the hiding place, coupled with the relatively careless leaving of temp files, could suggest a less-skilled cyberthief who simply obtained some very powerful tools.
The complete article can be found on http://www.storefrontbacktalk.com/securityfraud/heartland-sniffer-hid-in-unallocated-portion-of-disk/
Subscribe to:
Posts (Atom)