| By Ryan Sherstobitoff | Article Rating: |
|
| September 2, 2008 02:30 PM EDT | Reads: |
2,170 |
Wireless networks and endpoints offer convenience and connectivity, but unless properly secured, they also offer a means of egress into the network. As evidenced by recent headlines surrounding undiscovered data breaches and subsequent public exposure, hackers have begun to turn their eye toward breaching wireless networks and taking advantage of the many weaknesses incumbent. At the same time, we continue to see a trend toward stealing cardholder information from retailers such as TJ Maxx and Hannaford Brothers. According to a recent study conducted by the Verizon Business Risk Team, 84 percent of the data compromised in documented breaches pertained to cardholder information. [1]
The use of mobile networks is not an uncommon way of providing access for employees throughout a corporate campus. However, these networks come with several often-ignored dangers, including the exploitation of WEP (Wired Equivalent Privacy) and access points being deployed with minimal security measures.
If not properly mitigated, these vulnerabilities can eventually result in the exposure of private information as well as compliance violations if an exposure were to occur through one of those vulnerabilities.
The Target: Wireless Point-of-Sale (POS)
From an architectural perspective, a POS system runs an operating system (see Figure 1), likely a version of Windows or Linux designed to limit functionality - meaning not all O/S functions are available to the logged-in user. These devices are physically divided into two different components:
- Card Reader: A system that reads the card as it is swiped.
- Transaction Unit: A system that sends the card information to an authorization source.
The POS system is the primary hub between the store and the internal branch servers and is usually part of a collection of networked POS endpoints located at checkout stands. The information read at the POS via the above components will be sent to an authorization source (e.g., Amex) through the transaction unit that in some cases is integrated together with a magnetic card reader, such as a Verifone device.
In addition, the payment information that is read at the POS when making a purchase may be sent over the network to a branch server to collect information for auditing purposes.
Normally the information sent between the retailer and the authorization source will use strong encryption to protect the information. However, network security between the POS and the internal branch servers may or may not be encrypted depending on the configuration.
Published September 2, 2008 Reads 2,170
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Ryan Sherstobitoff
Ryan Sherstobitoff is the Chief Corporate Evangelist at Panda Security USA (www.pandasecurity.com). He is widely recognized as a security expert throughout the country and lectures audiences across the U.S. on cybercrime trends as well as corporate risk assessments. He can be reached at ryans@us.pandasecurity.com or through the PandaLabs blog at http://pandalabs.pandasecurity.com/.
- Typhoon Ondoy (Ketsana) and Floods Hit the Philippines
- Confessions of a Ulitzer Addict
- RIM Launches BlackBerry Desktop Manager for Mac Users
- Unisys Provides Mobile Support
- Rapid Application Delivery - Going Hybrid
- Ulitzer Live! New Media Power Panel at Santa Clara Convention Center
- Rhomobile CEO to Speak at iPhone Developer Summit 2009 West
- Rhomobile to Announce Production Release of RhoHub at 4th Cloud Expo
- First Open Source 4G Mobile Cloud Platform
- Sybase Named “Silver Sponsor” of iPhone Developer Summit
- Easiest Way to Make an iPhone Media App
- Top 10 Telecom Predictions for 2010
- Typhoon Ondoy (Ketsana) and Floods Hit the Philippines
- Confessions of a Ulitzer Addict
- RIM Launches BlackBerry Desktop Manager for Mac Users
- Build Reliability into Cloud Computing for SMBs
- Unisys Provides Mobile Support
- Is AT&T Apple's Achilles Heel?
- If They Don’t Throw Chairs Maybe You’re Not THAT Important
- Cloud Computing ERP Suite For the iPhone
- Stewart McKie Launches Mobile Tagging and Content Delivery Topic on Ulitzer
- Technology Face-Off: Augmented Reality vs Mobile Image
- Apple Approves First Official Porn Star App for iPhone
- Amazon S3 vs Amazon EBS on the Elastic Cloud
- Where Are RIA Technologies Headed in 2008?
- i-Technology Viewpoint: Should RIM BlackBerries Be Rented?
- Trump's Apprentice Runner-Up Rebecca Jarvis Has $150,000 Job Offer From SYS-CON Media
- Has the Technology Bounceback Begun?
- Microsoft and Sprint Collaborate on Mobile Search
- "Mobile Web 2.0" – How Web 2.0 Impacts Mobility & Digital Convergence
- Ringback Tones
- Mobile Music Gets Boost From New W600 "Walkman Phone"
- The Top 250 Players in the Cloud Computing Ecosystem
- i-Technology Blog: Zero-Cost Telephony, the 6-Ton Elephant in the Telco Room
- Alcatel + Microsoft = Internet TV Over IP, a.k.a. "IPTV," Coming Soon To a PC or TV Near You
- SIMply Big: SIM Cards For New Mobile Personal Storage






























