Hackers steal card data from Neiman Marcus
krebsonsecurity.com
krebsonsecurity.com
That is the state of security at the moment, not only is it easy to hack into sites, but it is easy to cover you tracks and not be discovered.
Vendors have resorted to trawling the carding forums and buying up dumps to figure out who has been hacked.
I can't remember the industry ever being so imbalanced towards the black hats.
Well if it’s an SQL injection attack, which is a very common way of hacking web sites, there is no way to even know it happened. Unless you keep a record of everything users input into text boxes you have no way of knowing. The intruder takes the data and he’s off and you have no indication that something went wrong. You’ll have a spike in your database usage if someone requested a SELECT * query but unless something odd happens chances are you won’t go looking for it.
I can't remember the industry ever being so imbalanced towards the black hats.
The industry was always imbalanced. If we go ten years back spam for example was a menace, today not so much. There are always fights won and lost. The problem nowadays is that e-commerce is exploding and a single hack can turn up to be huge. You hack into a site and you end-up with 150mm credit cards (aka the Target case). Ten years ago not even Amazon had such a big customer base.
To make a charge, the POS terminal packages the mag stripe data (and the encrypted PIN-block if doing debit) together with the POS terminal's ID, the amount to be charged, and maybe the CVV2 or the billing zip code, etc., into an HTTPS request to the payment processor. A second or two later, the payment processor responds, and the terminal completes the transaction.
If that's how Target's POS terminals work, then the hackers probably managed to push a "software update" out to the terminals causing them to tee the data off to the hackers' server whenever a transaction was made.
The reason the debit PINs were safe is that the PIN pads on which the customers enter their PINs are separate self-contained devices which encrypt the PINs before they leave the pad. Only the payment processor has the key needed to decrypt the PIN blocks, and PIN pads don't accept "software updates". PIN pads have been hacked in the past, but such attacks are far less scalable because they require modifying hardware at each affected POS terminal.
The new news about Target breaching contact info for 70m customers simply confirms that the hackers had free reign on Target's corporate network.
But in order to pull it off on the scale they did, the bad guys must have broken into Target's corporate network. Apparently, the level of access they achieved allowed them to raid the marketing database as well as to hack large numbers of POS terminals to leak the card swipe data.
The marketing database, BTW, contained name and contact information, but not credit card details. The bad guys might find it useful for phishing attacks.