Target Confirms Point-of-Sale Malware Was Used in Attack
securityweek.com
Target Confirms Point-of-Sale Malware Was Used in Attack
1–10 of 13 posts
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#2Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#3Does anybody know what kind of operating system is running on the devices?
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#4Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#5The windows build is typically a single "golden image" with a known checksum that can be blasted down to machines over wan/lan during the evening.
Source: I used build and deploy the image to many thousands of POS systems at Dixons Store Groups retail chains (UK)
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#6Does anybody know what kind of operating system is running on the devices?
It's likely a windows-based platform, as Windows has been almost exclusively the platform targeted by memory parser POS malware.
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#7Does anybody know what kind of operating system is running on the devices?
It's likely a windows-based platform, as Windows has been almost exclusively the platform targeted by memory parser POS malware.
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#8These systems are usually windows machines - typically "hardened" to various degrees (lock out USB keys etc) and protected by enterprise anti-virus solutions (mcafee, etc) The windows build is typically a single "golden image" with a known checksum that can be blasted down to machines over wan/lan during the evening. Source: I used build and deploy the image to many thousands of POS systems at Dixons Store Groups ret…
"Enterprise anti-virus" what a joke. Put the lawyers to work
Also, they apparently forgot to firewall it to only their internal network.
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#9In many ways this isn't surprising and has just been a matter of time. PoS systems are some of the least thoroughly engineered and least well protected yet critically important systems in existence. Hundreds of billions of dollars in transactions are processed through these often half-assed engineered systems.
I agree more can and should be done, but protecting against targeted malware by a sophisticated attacker is a very difficult problem. The amount of money at stake is large, so the resources expended by the attackers is also large.
Personally I believe that the current credit card system is broken and needs a significant change, but this is a very difficult process.
Re: Target Confirms Point-of-Sale Malware Was Used in Attack
#10These systems are usually windows machines - typically "hardened" to various degrees (lock out USB keys etc) and protected by enterprise anti-virus solutions (mcafee, etc) The windows build is typically a single "golden image" with a known checksum that can be blasted down to machines over wan/lan during the evening. Source: I used build and deploy the image to many thousands of POS systems at Dixons Store Groups ret…
I've had quite a few experiences as a customer at PC World when they've had "till failures" - ironic for a computer store. They often blame head office for overnight updates gone wrong.