• Advertise
  • Submit a Press Release
NewsBTC
Bitcoin & cryptocurrency news today, price & technical analysis
Price & Market
Cap Data from
Nomics Logo
  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • TradeeToro
  • Invest BTCTry
  • Join STC ICOBuy
No Result
View All Result
  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • TradeeToro
  • Invest BTCTry
  • Join STC ICOBuy
No Result
View All Result
NewsBTC
No Result
View All Result
Price & Market
Cap Data from
Nomics Logo

Rapid7 Researchers Pinpoint Point-of-Sale Vulnerabilities

newsbtc by newsbtc
5 years ago
in
Reading Time: 3min read
Point-of-Sale Vulnerabilities
Advertisement

Most people are well aware of how using credit cards is becoming a significant security risk these days. Not just online, where data breaches are running rampant these days. But also in real life, as Hotel point-of-sale devices are vulnerable to attacks and malware injections. The world needs a better way to transfer money between users; that much is certain.

The annual DefCon conference is a great event where security researchers showcase their recent findings and exploit them through a proof-of-concept. Rapid7 researchers will focus on the many different vulnerabilities affected point-of-sale devices dealing with payment cards.

Using Point-of-Sale Devices As A Keyboard

One of the most common types of attacks comes in the form of reading the card’s magnetic stripe. As all of the sensitive payment information is stored on this stripe, assailants can clone credit cards for nefarious purposes. Although this vulnerability has been around for many years now, finding a solution is proving to be a bigger challenge than assumed.

5 BTC + 300 Free Spins for new players & 15 BTC + 35.000 Free Spins every month, only at mBitcasino. Play Now!

The Rapid7 team has discovered a way to inject operating system commands into a Windows-based point-of-sale system through the magstripe reader. In most cases, this part of the magstripe reader is configured to act as a ‘general purpose device”. This allows misuse of the instrument commands, including the installation of malware or opening the register. None of these attacks should be possible in this capacity, yet the majority of point-of-sale devices is vulnerable to this type of attack.

To make matters worse, these attacks can be executed by a device with a programmable electromagnetic field. Distract the cashier for a few seconds, and before you know it, the point of sale device turns into a remotely controllable keyboard. Interestingly enough, Rapid7 has discovered this exploit is affecting nearly all point-of-sale devices manufactured by Samsung,

Manufacturers Need To Take Responsibility

Addressing these problems should not be overly difficult, as two key areas need to be targeted. First of all, magstripe readers should never be used as a keyboard, which can be solved by a software fix. Additionally, applications running on these devices need to be limited regarding accepted commands and data. Injecting keystrokes should never be possible, to begin with, yet right now, assailants can inject those without problems.

Given the mounting number of data breaches around the world, it is not difficult to see where the problems are coming from. Point-of-sale hardware and software used for standard payment methods are both inherently insecure. More secure solutions need to be created, and it will be up to manufacturers to create better countermeasures.

Source: Threatpost

Header image courtesy of Shutterstock

Tags: defconMagnetic StripemalwareNewsOpinionpoint of saleRapid7samsungSecurity Researchers
TweetShare
Nexo Logo
BitStarz Player Lands $2,459,124 Record Win! Could you be next big winner? Win up to $1,000,000 in One Spin at CryptoSlots
newsbtc

newsbtc

Related Posts

Binance BNB BNBUSDT

Binance offers Tesla stock token, could Coinbase (COIN) follow?

2 hours ago
Bitcoin BTC

How COPA’s lawsuit against Craig Wright could benefit Bitcoin

3 hours ago
crypto bitcoin fireworks

Grand Finale: Bitcoin Price Closes Record High Weekly, Could Conclude Cycle

3 hours ago
Bitcoin BTCUSD

Why MicroStrategy decided to paid its Board of Directors in Bitcoin

4 hours ago
holdefi

Holdefi: A Unique Decentralized Lending Platform Shaping the Future of DeFi

5 hours ago
Unicly

Capitalizing on Blockchain’s Promise, Unicly Delivers NFT Fractionalization

6 hours ago

Premium Partners

Top Brokers

eToro

eToro

Review · Visit
Evolve Markets

Evolve Markets

Review · Visit
Bybit

Bybit

Review · Visit
ArbiSmart

ArbiSmart

Review · Visit
PrimeXBT

PrimeXBT

Review · Visit
Moneta Markets

Moneta Markets

Review · Visit

Top Casinos

BitStarz

BitStarz

Review · Visit
mBit

mBit

Review · Visit
CryptoGames

CryptoGames

Review · Visit
Bonusfinder DE

Bonusfinder DE

Review · Visit
Bspin

Bspin

Review · Visit
Wolf Bet

Wolf Bet

Review · Visit

Top Sportsbooks

1xBit

1xBit

Review · Visit

Top ICOs

Student Coin

Student Coin

Review · Visit

Token sale

Holdefi

Holdefi

Review · Visit

Press Releases

Raze Network to Launch Its Public Distribution Sale on Balancer Liquidity Bootstrapping Pool

April 12, 2021

Blockchain Goes Mainstream With Rowan Energy

April 12, 2021

Two Leading Russian Media and PR Agencies United Into One Full Cycle Advertising Agency

April 9, 2021

Newsletter Signup


ABOUT US

NewsBTC is a cryptocurrency news service that covers bitcoin news today, technical analysis & forecasts for bitcoin price and other altcoins. Here at NewsBTC, we are dedicated to enlightening everyone about bitcoin and other cryptocurrencies.

We cover BTC news related to bitcoin exchanges, bitcoin mining and price forecasts for various cryptocurrencies.

COMPANY

  • Advertising
  • Comments Policy
  • Privacy Center
  • Sitemap
  • About Us
  • Contact

Technical Analysis

  • Bitcoin (BTC)
  • Ethereum (ETH)
  • Ripple (XRP)
  • Chainlink (LINK)
  • Cardano (ADA)
  • Tezos (XTZ)

LINKS

Auto Trading Software ▸

Cryptocurrency news

  • Bitcoin
  • Ethereum
  • Ripple
  • Chainlink
  • Cardano
  • EOS
  • Tezos

© 2020 NewsBTC. All Rights Reserved.

  • News
    • Bitcoin
    • Ethereum
    • Ripple
    • Cardano
    • Tezos
    • EOS
    • Chainlink
    • Sponsored
    • Press Releases
  • Analysis
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Cardano (ADA)
    • Chainlink (LINK)
    • Litecoin (LTC)
    • Tezos (XTZ)
    • Zcash (ZEC)
    • EOS
    • YearnFinance (YFI)
  • Education
    • Accepting Bitcoin payments
    • Using Bitcoin
    • What is Bitcoin Mining
    • How to Trade Bitcoin
    • How to Buy Bitcoin
    • Digital Currency Exchange
    • Proof of Existence
    • Is Bitcoin legal?
    • Bitcoin Books
  • Trading Course
  • Directory
    • Crypto Businesses
    • Bitcoin Brokers
    • Casinos
    • Sportsbooks
  • Trade
  • Invest BTC
  • Join STC ICO

© 2020 NewsBTC. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.