For the Love of Money Finding and Exploiting Vulnerabilities in Mobile Point of Sales Systems @HackersOnBoard
For the Love of Money Finding and Exploiting Vulnerabilities in Mobile Point of Sales Systems  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 1 day ago
These days it's hard to find a business that doesn't accept faster payments. Mobile Point of Sales (mPOS) terminals have propelled this growth lowering the barriers for small and micro-sized businesses to accept non-cash payments. Older payment technologies like mag-stripe still account for the largest majority of all in-person transactions. This is complicated further by the introduction of new payment standards such as NFC. As with each new iteration in payment technology, inevitably weaknesses are introduced into this increasingly complex payment eco-system.

In this talk, we ask what are the security and fraud implications of removing the economic barriers to accepting card payments; and what are the risks associated with continued reliance on old card standards like mag-stripe? In the past, testing for payment attack vectors has been limited to the scope of individual projects and to those that have permanent access to POS and payment infrastructure. Not anymore!

In what we believe to be the most comprehensive research conducted in this area, we consider four of the major mPOS providers spread across the US and Europe; Square, SumUp, iZettle, and Paypal. We provide live demonstrations of new vulnerabilities that allow you to MitM transactions, send arbitrary code via Bluetooth and mobile application, modify payment values for mag-stripe transactions, and a vulnerability in firmware; DoS to RCE. Using this sampled geographic approach, we are able to show the current attack surface of mPOS and, to predict how this will evolve over the coming years.

For audience members that are interested in integrating testing practices into their organization or research practices, we will show you how to use mPOS to identify weaknesses in payment technologies, and how to remain undetected in spite of anti-fraud and security mechanisms.



Black Hat USA 2018
For the Love of Money Finding and Exploiting Vulnerabilities in Mobile Point of Sales SystemsBlack Hat USA 2018 - Detecting Credential Compromise in AWSDEF CON 27 - Jeff Dileo - Evil eBPF In-Depth Practical Abuses of an In-Kernel Bytecode RuntimeDEF CON 27 - Matt Wixey - Sound Effects Exploring Acoustic Cyber-weaponsDEF CON 27 - Cult of the Dead Cow - Change the World, cDc Style Cow tips from the first 35 yearsDEF CON 27 - Panel - DEFCON Wants to Help Hackers Anonymously Submit Bugs to the GovernmentDEF CON 27 - Anish Athalye - Want Strong Isolation Just Reset Your ProcessorDEF CON 27 - Wenxiang Qian - Breaking Google Home: Exploit It with SQLite(Magellan)DEF CON 27 - Joe Grand - Behind the Scenes of the DEF CON 27 BadgeDEF CON 27 - Firmware Slap Automating Discovery of Exploitable Vulnerabilities in FirmwareBlack Hat USA 2018 - Threat Modeling in 2018 Attacks, Impacts and Other UpdatesDEF CON 27 - Bernhard Mueller - The Ether Wars Exploits counter-exploits and honeypots on Ethereum
HackersOnBoard |

For the Love of Money Finding and Exploiting Vulnerabilities in Mobile Point of Sales Systems

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER