Kiosk Breakouts: Context Menu via Internet Explorer
8
Kiosk Breakouts: Notepad++ Run Prompt
9
Keyboards with Media Keys
10
Barcode Scanners as Keyboards
11
Privilege Escalation
12
Remarks on Scoping
13
Getting the Goods
14
MagStripe Reader "Malware"
15
MagStripe Reader: Authentication Weakness
16
Two-tier Architecture and Direct Database Access
17
Oracle OPERA: Disclosed Vulnerabilities
18
Oracle OPERA: Exposed Session Logs (#1)
19
Oracle OPERA: Exposed Database Creds (#2)
20
Oracle OPERA: Remote Code Execution (#3)
21
Oracle OPERA: Extracting Sensitive Data
22
Arbitrary Refunds with URI Schemes
23
Takeaways
Description:
Explore the world of Point of Sale (PoS) system hacking in this 38-minute conference talk from NorthSec. Dive into the methods attackers use to exploit technical and policy vulnerabilities in credit card fraud schemes. Learn about physical security approaches, kiosk breakouts, and sensitive data extraction techniques. Gain insights from real-life examples, including critical vulnerabilities in Oracle's hotel management platform. Discover topics such as PCI-DSS vs PA-DSS, administrative start-up scripts, accessibility keyboard shortcuts, Microsoft Office macros, and privilege escalation. Examine the risks associated with barcode scanners, magstripe readers, and two-tier architecture. Understand the implications of exposed session logs, database credentials, and remote code execution in Oracle OPERA. Conclude with valuable takeaways to enhance your understanding of PoS system security.