Slashdot Mirror


Attackers Use Email Spam To Infect Point-of-Sale Terminals

jfruh writes: Point-of-sale software has meant that in many cases where once you'd have seen a cash register, you now see a general-purpose PC running point-of-sale (PoS) software. Unfortunately, those PCs have all the usual vulnerabilities, and when you run software on it that processes credit card payments, they become a tempting target for hackers. One of the latest attacks on PoS software comes in the form of malicious Word macros downloaded from spam emails.

9 of 85 comments (clear)

  1. E-mail client? by Todd+Knarr · · Score: 5, Insightful

    So, WTF is an e-mail client doing on a POS terminal in the first place? It doesn't need one, it shouldn't have one. Ditto a Web browser. You don't have to worry about vulnerabilities in software that isn't present on the machine in the first place. There are of course other things to be looked at, but those are a good starting point.

    1. Re:E-mail client? by sydbarrett74 · · Score: 4, Insightful

      Quoted for truth.

      The POS terminal should be a single-purpose device, with nothing but the POS software suite running on it and that's it. If employees want to check email or play LatestGreatestGame, they can do it on their own fucking devices. Or maybe, just maybe, they can clean or do other work around the business. There's always some work that can be done at a retail establishment. 'If you have time to lean, you have time to clean.'

      --
      'He who has to break a thing to find out what it is, has left the path of wisdom.' -- Gandalf to Saruman
    2. Re:E-mail client? by PTBarnum · · Score: 4, Insightful

      In a small business, the owner/manager may well be sitting at the POS terminal to help customers, but also doing other business tasks in between. It would be great if they had different computers for this, but there may not be space/budget for that.

      In a larger system, there might be general purpose computers sitting on the same network as the POS system without proper firewalls between them. So the malware hits a general purpose system first, then uses that platform to attack the POS.

    3. Re:E-mail client? by adolf · · Score: 4, Interesting

      I used to look after the POS machines for small chain of retail establishments.

      The reason that an e-mail client was on the POS machines was because the boss was cheap, and having separate machines for internal business and external transactions seemed expensive to him, even when business halts because some bored lackey decided that they needed the latest "OMG PONIES!!" screensaver on the fucking cash register.

      The reason that web browsers were on the POS machines was because Verizon are a bunch of fucks who couldn't be bothered to write a local client, but were perfectly content to always have a dependency on (old) Java and (old) Internet Explorer under (old) Windows.

      The reason that the the POS machines ran as Administrator was because my counterparts who were also charged with looking after said machines couldn't be bothered to get anything to work with regular user accounts, and would actively sabotage my efforts to improve security.

      The reasons that I no longer concern myself with the retail operations of that company are detailed above.

    4. Re:E-mail client? by Todd+Knarr · · Score: 4, Insightful

      For the first, tough. If they can't properly handle other people's financial information like credit-card numbers and PINs, they shouldn't be handling that information. Just like with a restaurant that claims they can't afford to maintain proper sanitary conditions to prepare food for customers.

      As for the second, in larger organizations there's never any reason to have a general-purpose computer on the POS network that can access or be accessed from the outside world. I know, I helped build and maintain a national network of POS systems that maintained that separation. If corporate IT and the software vendor can't make it work, I'll be happy to quote an hourly rate for the work.

    5. Re:E-mail client? by Whiteox · · Score: 4, Informative

      Email is there in Win XP and later. These POS terminals are full computers with a cash drawer underneath, merchant banking device and card swipe periperhals. They are networked to a local printer and mainly controlled by IT through remote desktop. They are typically in smaller shops with 2 or more terminals. They do stock control, daily cash calculations etc as they replace traditional Z type cash registers.
      Emails are sent by head office to all managers. Intranet and internet are available as well. So yes, they can be infected with spam emails.

      --
      Don't be apathetic. Procrastinate!
  2. retail management by roman_mir · · Score: 3, Informative

    I supply various systems, including retail chain management built with security by design. It is hard to achieve proper security in stores and offices, the users are so far away from being computer savvy it hurts. We move them off windows in many cases to Linux solutions. In any case POS should not be connected to the Internet. We set up linux machines as router / firewall and as a store management server. It talks to everything on the inside, it provides connectivity for the bank terminals, the cameras and another administrative computer. POS gets its instructiin s through it and offloads sales data to it and then everything is synchronized with the central system by it.
    The amount of crazy that happens in stores is staggering, almost inconceivable. We have to prevent meltdown with minimal resources and as little pain as possible but it is not easy when a retailer has a few stores and maybe one admin. Remote administration is vital, proper backup solutions are vital, the whole thine can degrade in no time if none is watching.

  3. Re:Windows XP, not Linux by ihtoit · · Score: 3, Interesting

    because word macros are still fundamentally tied to the way the kernel works with metafiles (ie the first thing it does with any binary object is try to execute it), and Windows xp comes wth an email client installed by default (Outlook Express) which for some unknown reason and unlike earlier versions of Windows (any from the 9x stable spring to mind) you can't deselect it from optional component install.

    --
    Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
  4. Re:Employees think the POS is their personal compu by Antique+Geekmeister · · Score: 4, Informative

    > This is what happens when you have employees who think they have a god given right to surf the internet

    Or when you have an employer mandate to check employee email about store policies, schedules, delivery dates, and inventory, verifying store hours for other branches, verifying alternative vendor prices for price matching, checking the weather for a customer buying exterior paint, looking up a product review or product specifications with a customer, or any of a dozen other uses. It is _embarrassing_ for a modern vendor to be unable to work with a customer checking the same information that the customer can obtain at home on their home computer, or to be unable to print out the specifications for a product that the vendor sells.

    Such terminals have become quite common and are much more necessary now that customers expect one store to be able to verify inventory or reserve an item before proceeding to another physical store. If they cannot do this, they will lose the sale to an online vendor.