Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/22/2019
06:30 PM
50%
50%

New Software Skims Credit Card Info From Online Credit Card Transactions

The new exploit builds a fake frame around legitimate portions of an online commerce website.

A new strain of software designed to steal financial information from retail websites has surfaced,  demonstrating criminals' ability to adapt and improve their tools in the face of improved security measures.

The software, discovered by researcher Jérôme Segura at Malwarebytes, takes advantage of the popular retail practice of using a third-party credit card payment organization to facilitate credit card use. In this case, the software targets companies using Magento as their financial processing service provider. The malicious software inserts an iframe around the display code that would send the customer to Magento to finalize a purchase — an iframe that requests and captures the customer payment card info far earlier than it would be requested in a legitimate transaction.

This new attack is similar to an earlier overlay code tactic used by Magecart. It allows the purchase to proceed, minimizing the speed with which it might be found, but will exfiltrate customer payment information in the process. The only real clue for those who don't have the checkout page layout memorized is the process by which payment information is requested twice — which should alert all consumers that something is amiss.

Read more here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
5/23/2019 | 8:33:36 AM
Temporary card numbers
There is a great technolgy where credit card companies allow the user a one-time card number which vanishes as soon as transaction done - very effective and should be used more.  Secondly, have a card with a low low credit limit, $500 or so that IF it ever does get compromised, then thief cannot by a Corvette with it - maybe tires or something like that and financially easy to recover from. 
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
5/23/2019 | 11:07:49 AM
Re: Temporary card numbers
I've done the same for the credit limit.  I use only one credit card.  Who offers the one time credit card number?

 

 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
5/23/2019 | 12:37:42 PM
Re: Temporary card numbers
I have to check the techs on that, Clark Howard - our consumer pro down here in Georgia, advocates for it all of the time.  Should be buried under options in your card-holder site, such as Capital One. 

 
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
US Sets $5 Million Bounty For Russian Hacker Behind Zeus Banking Thefts
Jai Vijayan, Contributing Writer,  12/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19719
PUBLISHED: 2019-12-11
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
CVE-2019-19720
PUBLISHED: 2019-12-11
Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.
CVE-2019-19707
PUBLISHED: 2019-12-11
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.
CVE-2019-19708
PUBLISHED: 2019-12-11
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
CVE-2019-19709
PUBLISHED: 2019-12-11
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.