How RAM Scrapers Work: The Tool Behind the Latest Credit Card Hacks
wired.com
wired.com
The problem is there aren't many chipped cards at all.
Why isn't sensitive software like this built and audited with the same concern for reliability and security as avionics, medical equipment, SCADA, etc.? Certainly the cost in financial losses caused by these attacks makes this a pertinent question.
Imply that it is. It very very often isn't at all.
How much did it cost the guy who made this decision? Zero. All the cost and blame falls on the person who came after who has to clean it up.
These are likely using hooking. They don't scan RAM all the time, instead they patch or inject code into the POS software and then record the data when that code is called.
Think of something like Microsoft Detours. RAM scrapers seems a pretty inaccurate description.
> Once on a targeted system, RAM scrapers work by examining the list of processes that are running on the system and inspecting the memory for data that matches the structure of credit card data, such as the account number, expiration date, and other information stored on a card’s magnetic stripe.
No hooking, sounds exactly like they're looking through the memory assigned to each process looking for the right looking data.
I suspect that is just an oversimplification, of course, unless they post the malware in question I can't really say for sure.
further reading: http://www.trendmicro.com/cloud-content/us/pdfs/security-int...
That sounds bad, but I wonder if this system was issuing huge numbers of alerts all the time, leaving the security staff no real option but to ignore the alerts. I'd be curious to see the false positive rate. It seems like for an off-the-shelf security system that you buy, false positives must be a huge problem, because it hasn't been tuned to your data.
Newer versions of Windows make this exploit far more difficult [2].
[1] http://www.dailytech.com/Appalling+Negligence+DecadeOld+Wind...
[2] http://en.wikipedia.org/wiki/Address_space_layout_randomizat...
Edit: The articles does say: "Attackers installed these RAM scrapers surreptitiously on the point-of-sale systems used to scan and process credit and debit card transactions at Albertson’s and Supervalu. The tools make it easy to steal card numbers by the millions as they pass through the system."
But still a bit confusing if these are hardware devices or somehow they install software to do this.
"RAM scrapers, by contrast, can be installed remotely on a Big Box
retailer’s network and deployed widely to dozens of stores in a
franchise, without an attacker ever leaving his computer. They can
also be deleted remotely to erase crucial evidence of the crime."
The ability to remotely install and delete RAM scrapers from anywhere in the world precludes this being a hardware device.