4 ms·
I don't think the Target POS terminals were on the Internet. The Brian Krebs article stated that the hacker compromised an externally facing web server and use
by coleca 13y ago
I don't think the Target POS terminals were on the Internet. The Brian Krebs article stated that the hacker compromised an externally facing web server and used that as a bridge to get into the corporate (private) network.
Since the POS terminals were all running a variant of Windows, it might have been as simple as querying the Active Directory to find out where everything was located within the Target network (at least for the Windows machines). Comments in the Krebs article also speculated that they exploited an account with a BMC systems management tool used at Target as well.
- walshemj 13y agoWell should there not have been an air gap between the internet facing systems and the core network that runs the pos. Best practice would have the POS systems on a separate air gaped network to the main Target intranet as well.
- dobbsbob 13y agothey had some lazy method where an admin could log in and update all the POS systems at once. of course this was not done using ssh keys and probably weak password + gui
- forgottenpass 13y agoDepends on how you define airgapping. If it's a fungible "you know what I mean," well then obviously yes. If it's an actual air gap, then no. Practical business requirements on inventory management, sales metrics, system administration and (funnily enough) payment processing all prevent a register network from being airgapped. If you want to say their protection of those communication channels was shit, well, we already have proof it was. But airgapping? Not so much.
- coleca 13y agoIt wouldn't be a best practice to isolate the POS environments from all the other internal systems. Pricing, items, taxes, offers, coupons, etc. are all separate systems on the corporate network. They all need to communicate to the POS. It isn't realistic to air gap the POS at a business the scale of Target. PCI rules just state the cardholder data environment (CDE) needs to be segmented from the rest of the corporate network (in addition to many other obligations). That would usually be done with VLANs and firewalls, but both are still on the same layer 2 network.
- walshemj 13y agoyou only allow the POS system to be reachable by systems that ABSOLUTLY need to. NOT! every tom dick and harry in marketing - you can do a nightly dump of finance data off this network for data warehousing analytics and what have you.
- 0xdeadbeefbabe 13y agoBest practice is to make more money than you lose. Hah.