17-year-old is author of BlackPOS/Kaptoxa malware used against Target?
intelcrawler.com
intelcrawler.com
Russians can get away with this because their gov doesn't care about US fraud, also no extradition treaty. Sadly this kid can never travel anywhere ever again unless it's directly to Brazil or another country with no US extradition treaty because they will get him even if it takes 5+years from now they will watch waiting for him to make a mistake and update VKontakte (russian FB) on his Turkey vacation plans.
1. heuristically detects unconfigured/default-passworded L2/L3 hardware (e.g. routers) on the network;
2. generates and sets a strong password for that hardware itself;
3. proxies all further access to that hardware, keeping the password only between it and the captured devices (and hopefully delivered only over TLS, if that's possible);
and 4. has actually-sensible security itself (e.g. using SSH keys, HTTPS client certificates, or any other non-repudiatable token type.)
Effectively, it'd act as an automatic password vault and security gateway for all the devices too simple to have good security themselves.
[1] This part is important. In most companies, whenever you have a tech leave who knew a password? You've got to reset that password. You might not even know which passwords they knew, so you have to reset everything to be safe. And then the passwords other techs have memorized are invalidated. Incredibly painful.
It would probably be feasible to fork the RANCID network device configuration version control application to create something that could do what you're describing out of FLOSS components, too.
Yeah it's not very clear to me either. Not sure if the relevant Target part is in the second IM transcript where ree4 seems to try and sell a special version of his product that CAN work with Verifones for 2000 USD?
Tossed into photoshop and just put all versions over each other w/ darken layer...
Looks like zoparlek@thiessen.org but theres a few characters that look a bit iffy.
Edit: Got the above by combining emails censored in the top part of the first screenshot. You can definitely reveal the full email if you incorporate the other screenshots.
security considerations aside, this is also more expensive and harder to implement than a private net. so someone actually sat down, and made this decision deliberately.
pretty fucking amazing, if you ask me.
A typical small-shop retail arrangement is to have the POS terminals behind a NAT router which is behind another NAT router that also serves up the customer-convenience WiFi AP.
When a terminal wants to put through a charge, it simply makes an HTTPS request to the payment processor. One or two seconds later, the request comes back, declined or accepted and here's the approval code. At that point, the POS sanitizes away the credit card details and applies the credit tender. Enjoy your latte, ma'am!
To hack such a system, you need to get onto the POS LAN. E.g., maybe there's a store server on the with an SSH login, which you've uncovered after breaking into the corporate above-store network. Or maybe a disgruntled employee installs malware from a USB stick.
Then you exfiltrate the captured swipes, hopefully without leaving enough tracks to get caught. E.g., the malware periodically uploads the intercepts to some FTP site to which you can get access. Or, in the case of the disgruntled employee, it could simply involve dragging the files to the USB stick.
Between the store and the payment processor, we should be safe, given we're using HTTPS. However, payment processors have themselves been hacked. E.g., Heartland†.
†http://voices.washingtonpost.com/securityfix/2009/01/payment...
Historical reasons? target does has a /16.
They can probably fill that block many times over now, but it would make sense that their numbering scheme has historical roots and to continue using that space for interstore communication today. They got it in 1993, back when we were still pretending like exhausting the v4 space wasn't a thing and before everyone started acting like the fact a many-to-one NAT requires what is effectively a statefull firewall somehow offered a security advantage you couldn't get by just writing those firewall rules.
I was at an organization with a large v4 block once. It took a few years of having my desktop, laptop, and cellphone wifi connections all with routable v4 addresses before I stopped thinking it was weird, bad design and really came to appreciate: "oh shit, this is how the internet is supposed to be and it is so much nicer to work with."
(I worked at the company with /8 IP block and always thought that this is how the founding fathers intended it to be).
Since the POS terminals were all running a variant of Windows, it might have been as simple as querying the Active Directory to find out where everything was located within the Target network (at least for the Windows machines). Comments in the Krebs article also speculated that they exploited an account with a BMC systems management tool used at Target as well.
Best practice would have the POS systems on a separate air gaped network to the main Target intranet as well.
Practical business requirements on inventory management, sales metrics, system administration and (funnily enough) payment processing all prevent a register network from being airgapped. If you want to say their protection of those communication channels was shit, well, we already have proof it was. But airgapping? Not so much.
PCI rules just state the cardholder data environment (CDE) needs to be segmented from the rest of the corporate network (in addition to many other obligations). That would usually be done with VLANs and firewalls, but both are still on the same layer 2 network.
The technical part is silly easy. The hard part is the moral and fear of loosing what you gained honestly so far. And for that, being a teenager is much easier.
So, what is really the surprise here? It is not like it was a elegant worm or anything. It was just not looked after for ages. The real interesting info in this whole history is why it was ignored for so long, and who monetized it later one (hint: i doubt it was the teenage kid)
It is also much easy to be motivated to do something like this, than another business app in Java.
But 'tis enough ranting, my borsch is getting cold.
Skolkovo is just another way to steal money from the taxpayers under the guise of innovation. Which they already did: $3.72 billion dollars (125 bullion rubles).
http://www.themoscowtimes.com/news/article/skolkovo-warned-o...
The borsch was delicious as well, thanks for asking.
A buddy of mine from IRC links me a webpage like he usually does, most of the time it's a static HTML file buried deep into the file structure of some large corporate site. This file was different, it was the CC database for a huge site.
Few weeks later police kick my door down, seize most of my personal electronics, and I have yet to hear from them or see my equipment.
I ask because it's pretty easy to find carding forums on Tor, to the point that I can't imagine the police bust the door down of everyone they can identify as having glanced at a CC dump.