Usually customers won't note the manipulations. Removing the magnetic stripe would improve the situation, but note that the cards must be authenticated with a real challenge-response protocol if a real security improvement is the target.
Showing posts with label sniffing. Show all posts
Showing posts with label sniffing. Show all posts
Sunday, 30 May 2010
German Police publishes ATM Crime Numbers
The german federal police has published the 2009 numbers for ATM fraud. 964 ATM machines have been manipulated, that#s 20% more than 2008. Usually the PIN is spied out and the magnetic stripe data of the banking card is read. The data is transferred via a wireless connection who make a copy of the card and use that at another ATM.
Sunday, 8 November 2009
PhoneSnoop Turns BlackBerries into Bugs
A simple BlackBerry program called PhoneSnoop will turn your BlackBerry into a bug. The attacker will install it on a BlackBerry he found lying around. Then calling the BlackBerry from a preconfigured telephone number will put the Balckberry into SpeakerPhone mode and all conversations near the affected BlackBerry can be overheard at the remote end of the call.
This is not a security issue of the BlackBerry operating system, because the root cause here is that the attacker had full control over the phone when he installed the software. For a minimum level of security, the BlackBerry should be configured to require a password ofter a short period of inactivity.
However, the morale here is that you shouldn't think "I don't have sensitive information on my telephone, so I don't need to secure it".
Sunday, 30 August 2009
Real Time Keylogging
According to New York Times the trojan Clampi is able to send key presses in real time. This means that it can be used to attack one time password (OTP) systems.
From here on, it seems necessary to consider a more complex mode of OTP known as EMV CAP respectively Visa DPA. Here a challenge is sent from the server which is signed by a smart card. Therefore the attacker cannot submit the stolen OTP signature for any other purpose than it was originally intended for.
Labels:
e-crime,
one time passwords,
smart cards,
sniffing
Tuesday, 18 August 2009
Voting Computer Tempest Attack
Youtube has a video where the german hacker club CCC shows how to read out the votes cast on an online voting machine. The electromagnetic radiation generated by the machine, in particular it's pressure sensitive input device, is measured by a sensitive radio scanner. It seems that almost any man-machine interface is threatend by this kind of attack.
Wednesday, 12 August 2009
Flash Cookies
Kate McKinley from iSEC Partners notes that Adabe's flash browser plugin can be used to store persistent data and thus track internet usage. Even worse, those flash cookies cannot be deleted through the browser settings. She descrribes a complicated procedure for managing and deleting flash cookies. This is annoying.
Thursday, 30 July 2009
Tempest Reloaded
Italian hackers found out that key presses on PS/2 keyboards can be sniffed out by measuring traces of the signals on the neutal line of the power supply of the computer they are connected to.
However, ATMs used where I live have a secure pinpad which also encrypts the PIN before it is sent to the bank for checking. I find it hard to believe that such a device leaks out the PIN so easily. A quick google query shows that there are such and such keyboards. Please note that the ones with PS/2 seem to lack VISA approval.
Subscribe to:
Posts (Atom)