<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More POS Hacks Grab CC Numbers</title>
	<atom:link href="http://www.spacerogue.net/wordpress/?feed=rss2&#038;p=72" rel="self" type="application/rss+xml" />
	<link>http://www.spacerogue.net/wordpress/?p=72</link>
	<description>Personal weblog of Space Rogue, former L0pht member and editor of the Hacker News Network.</description>
	<lastBuildDate>Mon, 13 May 2013 14:14:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
	<item>
		<title>By: xodusprime</title>
		<link>http://www.spacerogue.net/wordpress/?p=72&#038;cpage=1#comment-12468</link>
		<dc:creator>xodusprime</dc:creator>
		<pubDate>Mon, 12 May 2008 04:02:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.spacerogue.net/wordpress/?p=72#comment-12468</guid>
		<description><![CDATA[I&#039;ve got to say, after installing and maintaining POS systems for a while, there is quite a bit that can be done, even without any hardware modification.  The credit-card bridging software used by a number of POS software platforms can often be accessed to pull back full names and credit card numbers from each transaction.  While not as powerful has having a PIN, if the clerk had to manually enter anything, or if it was a phone order, often times the CVV number will be included in these records.

Since many small businesses use their POS server as an office computer as well, it&#039;s just a matter of nabbing the IP address and getting yourself a backdoor.  While it isn&#039;t something that can be done easily, I don&#039;t think it would be more difficult than dismantling a pin-pad and including a capture device.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve got to say, after installing and maintaining POS systems for a while, there is quite a bit that can be done, even without any hardware modification.  The credit-card bridging software used by a number of POS software platforms can often be accessed to pull back full names and credit card numbers from each transaction.  While not as powerful has having a PIN, if the clerk had to manually enter anything, or if it was a phone order, often times the CVV number will be included in these records.</p>
<p>Since many small businesses use their POS server as an office computer as well, it&#8217;s just a matter of nabbing the IP address and getting yourself a backdoor.  While it isn&#8217;t something that can be done easily, I don&#8217;t think it would be more difficult than dismantling a pin-pad and including a capture device.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
