EH-Net

Ethical Hacking Discussions and Related Certifications => Malware => Topic started by: jason on November 02, 2008, 08:36:07 PM



Title: Custom sniffer for PCI info
Post by: jason on November 02, 2008, 08:36:07 PM
Looks like another person just got taken down in the identity theft ring that included TJX and several other retailers. Apparent he wrote a custom sniffer to grab payment card info off the wire as it went between cash registers and the processing servers.

http://blog.wired.com/27bstroke6/2008/10/fed-blotter-new.html (http://blog.wired.com/27bstroke6/2008/10/fed-blotter-new.html)


Title: Re: Custom sniffer for PCI info
Post by: shednik on November 03, 2008, 07:40:19 AM
Very interesting....I still will never use anything but cash at places like TJX after the article I read that even after the breach they still follow poor  security practices (http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/)


Title: Re: Custom sniffer for PCI info
Post by: jason on November 03, 2008, 07:42:26 AM
Yup, not only insecure but wilfully so.