Live data from Hacker News

Target Confirms Point-of-Sale Malware Was Used in Attack

securityweek.com

11–13 of 13 posts

Re: Target Confirms Point-of-Sale Malware Was Used in Attack

#11
post #5

These systems are usually windows machines - typically "hardened" to various degrees (lock out USB keys etc) and protected by enterprise anti-virus solutions (mcafee, etc) The windows build is typically a single "golden image" with a known checksum that can be blasted down to machines over wan/lan during the evening. Source: I used build and deploy the image to many thousands of POS systems at Dixons Store Groups ret…

[deleted]

Re: Target Confirms Point-of-Sale Malware Was Used in Attack

#12
Two questions:

1. How do you get 40 million cards in a day from scraping RAM? Wouldn't it be limited to live transactions? 40m seems like a huge number of transactions for one day. An average ticket of $50 would make it a 2 billion dollar day.

2. Why does the card data need to be decrypted on the POS system? Why can't it be sent to a central service and decrypted there and an authorization code is sent back?

Re: Target Confirms Point-of-Sale Malware Was Used in Attack

#13

Two questions: 1. How do you get 40 million cards in a day from scraping RAM? Wouldn't it be limited to live transactions? 40m seems like a huge number of transactions for one day. An average ticket of $50 would make it a 2 billion dollar day. 2. Why does the card data need to be decrypted on the POS system? Why can't it be sent to a central service and decrypted there and an authorization code is sent back?

From Target's press release, this happened between Nov. 27 and Dec. 15, so it's closer to three weeks. Dec. 15 was just the first day they confirmed the problem.
Post reply on HN