Attacks/Breaches
10/25/2012
01:11 PM
50%
50%

Barnes & Noble Probes PIN Keypad Hack

Criminals hacked one PIN keypad in each of 63 stores and have already used the stolen data to commit fraud. Was it an inside job?

Barnes & Noble also recommended that potentially affected consumers beware identity theft, and watch for accounts that might have been opened in their name, but without their knowledge. But in its statement, the company made no mention of providing identity theft monitoring or protection services to affected consumers.

How difficult would it be to tamper with PIN pads at 63 different stores, across nine states? "This is no small undertaking," Edward Schwartz, the chief security officer at RSA, told the Times. "An attack of this type involves many different phases of reconnaissance and multiple levels of exploitation." In addition, the attacks are notable for the geographic distance between affected stores.

The complexity involved in the attacks has led some security observers to conclude that it must have been an inside job. In an emailed statement, Gunter Ollmann, VP of research for computer security firm Damballa, said that with only one PIN card reader having been hacked per store, it didn't "smell of a supply chain problem," meaning it was unlikely "that a batch of card readers were compromised at the manufacturers or distribution center." In addition, most PIN pad attacks require attackers to return to the terminal to retrieve intercepted data, sometimes repeatedly.

One possibility is that the Barnes & Noble attackers installed card skimmers in the PIN pads. Although the Payment Card Industry Data Security Standard (PCI DSS) requires all stored credit card data to be encrypted--and states exempt businesses from having to notify customers of data breaches, if the information was encrypted--PIN-pad skimmers literally tap into the available data before it even has a chance to be stored, by capturing it at the moment that a card gets swiped.

Last year, attackers used skimming technology to compromise data from 90 PIN pad terminals--across 20 states--at arts and crafts outlets owned by Michaels Stores. Rather than literally forcing open the PIN pads in-store and inserting a skimming chip, however, security experts suspect that attackers might have performed a social-engineering attack, and while a cashier was distracted, physically swapped the existing PIN pads for a lookalike version that already had a skimmer installed.

Unfortunately, attacks against PIN card terminals continue to grow more sophisticated. At the Black Hat information security conference earlier this year, for example, researchers demonstrated a proof-of-concept PIN pad attack against terminals available in Europe, in which they used a Trojan credit card to infect the terminal with malware, which began recording all available card information, including debit card PIN codes. When an attacker returned and reinserted their card in the terminal, the malware copied all of the stolen, stored data back onto the card, then deleted itself to hide all signs of the attack.

A security information and event management system serves as a repository for all the security alerts and logging systems from a firm's devices. But this can be overkill for a company that is understaffed or has overestimated its security information needs. In our report, Does SIEM Make Sense For Your Company?, we discuss 10 questions to ask yourself in determining whether SIEM makes sense for you--and how to pick the right system if it does. (Free registration required.)

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
10/30/2012 | 5:27:39 PM
re: Barnes & Noble Probes PIN Keypad Hack
If this was an inside job the Barnes and Nobel has way overqualified sales people working the registers. GǣA sophisticated criminal effort does not sound like it could be committed by the sales clerk who just directed me to the travel section. Not at all putting down sales clerks but if you have the ability to carry out a sophisticated criminal attack then they are probably in the wrong field. 63 stores that were effected is quite a feat considering the security on these pos terminals, which leaves the obvious, an inside job.

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5027
Published: 2014-12-26
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2062. Reason: This candidate is a reservation duplicate of CVE-2010-2062. Notes: All CVE users should reference CVE-2010-2062 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2010-1441
Published: 2014-12-26
Multiple heap-based buffer overflows in VideoLAN VLC media player before 1.0.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) A/52, (2) DTS, or (3) MPEG Audio decoder.

CVE-2010-1442
Published: 2014-12-26
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.

CVE-2010-1443
Published: 2014-12-26
The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format...

CVE-2010-1444
Published: 2014-12-26
The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted archive.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.