4 ms·
I realise that, but perhaps wasn't clear in what I was trying to say. In the UK many businesses manually enter in the amount into the POS device. The customer
by JosephRedfern 6y ago
I realise that, but perhaps wasn't clear in what I was trying to say.
In the UK many businesses manually enter in the amount into the POS device. The customer will then insert their card and enter their pin, the transaction will take place (as you say, ultimately down to the issuing bank), and the device will indicate whether the transaction was successfully or not (printing a receipt as well as an indication on the screen). Some places have tighter integration with tills etc, but to my knowledge it's down to the POS device (which is assumed secure) to communicate the status of the transaction to the till.
My suggestion is that given full control over the POS device (i.e. your card triggers buffer overflow in the POS and you get code execution), you could make it behave as if the transaction had been successfully processed (by showing the same message and issuing the same receipt) without actually debiting any accounts or making any actual transaction.
- jaywalk 6y agoIt really depends on the type of integration used between the terminal and the POS. Sometimes the terminal handles everything and just communicates the status to the POS, in which case your attack would be viable. But it's also possible for the terminal to just package up the info and pass it off to the POS to handle the communication. Source: I've built a custom integration with Verifone terminals.