Newer versions of Windows make this exploit far more difficult [2].
[1] http://www.dailytech.com/Appalling+Negligence+DecadeOld+Wind...
[2] http://en.wikipedia.org/wiki/Address_space_layout_randomizat...
11–20 of 30 posts
Newer versions of Windows make this exploit far more difficult [2].
[1] http://www.dailytech.com/Appalling+Negligence+DecadeOld+Wind...
[2] http://en.wikipedia.org/wiki/Address_space_layout_randomizat...
Earlier quoted context omitted.
> How RAM Scrapers Work > Once on a targeted system, RAM scrapers work by examining the list of processes that are running on the system and inspecting the memory for data that matches the structure of credit card data, such as the account number, expiration date, and other information stored on a card’s magnetic stripe. No hooking, sounds exactly like they're looking through the memory assigned to each process looki…
Okay, so, how do they harvest live data? Scan constantly? That would have a risk of missing something or of slowing down the system. I suspect that is just an oversimplification, of course, unless they post the malware in question I can't really say for sure.
further reading: http://www.trendmicro.com/cloud-content/us/pdfs/security-int...
This article [1] argues that RAM scrapers are only able to work because the point-of-sale systems are running Windows XP. Newer versions of Windows make this exploit far more difficult [2]. [1] http://www.dailytech.com/Appalling+Negligence+DecadeOld+Wind... [2] http://en.wikipedia.org/wiki/Address_space_layout_randomizat...
Earlier quoted context omitted.
> How RAM Scrapers Work > Once on a targeted system, RAM scrapers work by examining the list of processes that are running on the system and inspecting the memory for data that matches the structure of credit card data, such as the account number, expiration date, and other information stored on a card’s magnetic stripe. No hooking, sounds exactly like they're looking through the memory assigned to each process looki…
Okay, so, how do they harvest live data? Scan constantly? That would have a risk of missing something or of slowing down the system. I suspect that is just an oversimplification, of course, unless they post the malware in question I can't really say for sure.
so are these hardware that somehow people manage to sneak and install on a store's network? How would them monitor traffic and get the credit card info? Edit: The articles does say: "Attackers installed these RAM scrapers surreptitiously on the point-of-sale systems used to scan and process credit and debit card transactions at Albertson’s and Supervalu. The tools make it easy to steal card numbers by the millions as…
"RAM scrapers, by contrast, can be installed remotely on a Big Box
retailer’s network and deployed widely to dozens of stores in a
franchise, without an attacker ever leaving his computer. They can
also be deleted remotely to erase crucial evidence of the crime."
The ability to remotely install and delete RAM scrapers from anywhere in the world precludes this being a hardware device.From what I gather from the article, the systems which RAM scrapers attack were running on general purpose computers, with very similar vulnerabilities. Why isn't sensitive software like this built and audited with the same concern for reliability and security as avionics, medical equipment, SCADA, etc.? Certainly the cost in financial losses caused by these attacks makes this a pertinent question.
From what I gather from the article, the systems which RAM scrapers attack were running on general purpose computers, with very similar vulnerabilities. Why isn't sensitive software like this built and audited with the same concern for reliability and security as avionics, medical equipment, SCADA, etc.? Certainly the cost in financial losses caused by these attacks makes this a pertinent question.
How much did it cost the guy who made this decision? Zero. All the cost and blame falls on the person who came after who has to clean it up.