Skip to Content
Hacking Point of Sale: Payment Application Secrets, Threats, and Solutions
book

Hacking Point of Sale: Payment Application Secrets, Threats, and Solutions

by Slava Gomzin
February 2014
Intermediate to advanced
312 pages
6h 58m
English
Wiley
Content preview from Hacking Point of Sale: Payment Application Secrets, Threats, and Solutions

Chapter 5

Penetrating Security Free Zones

If you give to a thief he cannot steal from you, and then he is no longer a thief.

William Saroyan

PCI security standards put the responsibility for implementing security controls on the payment processing industry—merchants, payment gateways and processors, and software vendors. An interesting trend is emerging, however, where instead of requiring payment system vendors (either hardware or software—in this case, there is no big difference from the merchant's viewpoint) to supply secure systems “out of the box,” the standards allow multiple vulnerabilities to be built into software and hardware by design. At the same time, merchants are required to implement security controls that compensate for the lack of security in their payment systems. The merchants hope that security comes from the software and hardware vendors, who are in turn relying on the merchants to secure their own store environments. The results: multiple security breaches. Examples of this scenario include unprotected data in memory, unencrypted local network traffic, and other vulnerabilities, which are discussed in this chapter.

Payment Application Memory

In November 2009, Visa issued its Data Security Alert called “Targeted Hospitality Sector Vulnerabilities” where the biggest payment card brand admitted that “the increasing use of debugging tools that parse data from volatile memory suggests that attackers may have successfully adapted their techniques to obtain payment ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Information Security Management Principles, 3rd Edition

Information Security Management Principles, 3rd Edition

Andy Taylor, David Alexander, Amanda Finch, David Sutton

Publisher Resources

ISBN: 9781118810071Purchase book