Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Backoff PoS Malware Boomed In Q3
Newest First  |  Oldest First  |  Threaded View
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
10/27/2014 | 1:49:09 PM
Re: Justification for not implementing PoS safeguards?
I would say that a major issue is the lack of qualified security personnel.  In my experience, there is currently a severe lack of people with an information security background.
aws0513
100%
0%
aws0513,
User Rank: Ninja
10/27/2014 | 12:01:02 PM
Re: Justification for not implementing PoS safeguards?
I feel "unawarness" is a blanket statement for several situations to include:
  • No IT security team (this is still a reality in smaller companies).
  • Poorly manned or resourced IT security team.
  • An IT security team that has little or no real management backing or influence.
  • Management that just doesn't get it...  period.

My favorite quote to sum up my personal feelings of this Backoff PoS debacle:
"The power of accurate observation is commonly called cynicism by those who have not got it." - George Bernard Shaw

 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
10/27/2014 | 11:38:23 AM
Re: Justification for not implementing PoS safeguards?
Ha, no apologies needed. I feel that was a very concise and well appropriated manner to answer my question. I just cannot fathom those as justifiable with the current predicament companies are experiencing. Is the managment "unawareness" for enterprises that don't have a InfoSec team or CISO? If there is still "unawareness" to that end, I feel at this point it would just be apathy.
prospecttoreza
50%
50%
prospecttoreza,
User Rank: Strategist
10/27/2014 | 10:31:01 AM
...incredibly difficalt ?
The retailers normally buy the PoS systems from integrators. They do not put it together themselves. At which point the systems acuire the valnerabilities - are they improperly configured when installed? Or the retailers IT tinker with them and break the defences to make them work with the company systems? If it is the latter, i would like to read a details explanation of the difficalties, with scripts attached.
aws0513
50%
50%
aws0513,
User Rank: Ninja
10/27/2014 | 9:56:26 AM
Re: Justification for not implementing PoS safeguards?
I cannot swallow many justifications at this time, but I can predict some of what is being served up.
  • Lack of technical manpower (tossed salad).
  • Logistics issues regarding upgrading of older hardware (salad dressing).
  • Management "unawareness" (tasteless cooked chicken).
  • Management denial or refusal to deal with the problem (ostrich soup).
  • Immediate funding issues (the normal catch-all vanilla ice cream dessert with multiple toppings).

That is the usual menu items. 
At the moment, I cannot think of any specials that the corporate chefs have served in the past, but I'm sure there are some original dishes being developed in backwater kitchens out there.

(Sorry for the food references, but I am in a goofy mood this morning...  and I need a breakfast break)

 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
10/27/2014 | 8:31:46 AM
Justification for not implementing PoS safeguards?
Is there any reason, especially with the current popularity of these exploits, that retailers would not be implementing these best practices when it comes to PoS? Perhaps employee bandwidth? Some of these recommendations could be followed by changing simple infrastructure elements that don't require any monetary involvement.  
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
10/27/2014 | 7:00:42 AM
About the repor
I agree with data and observations proposed in the report, anyway I hope that next reports could provide more detailed info. I suggest the readers to read the US CERT document mentioned in the report about Backoof POS malware.

We all agree that industry must assume a proper security posture to avoid further damages 


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Data Breaches Affect the Enterprise
Data breaches continue to cause negative outcomes for companies worldwide. However, many organizations report that major impacts have declined significantly compared with a year ago, suggesting that many have gotten better at containing breach fallout. Download Dark Reading's Report "How Data Breaches Affect the Enterprise" to delve more into this timely topic.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-36328
PUBLISHED: 2021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.
CVE-2021-36329
PUBLISHED: 2021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.
CVE-2021-36330
PUBLISHED: 2021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.
CVE-2021-41256
PUBLISHED: 2021-11-30
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giv...
CVE-2021-36326
PUBLISHED: 2021-11-30
Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format...