Monday, September 14, 2009

Hacker Hits RBS WorldPay Systems Database



Hacker Hits RBS WorldPay Systems Database



Romanian hacker says he discovered a SQL injection flaw on a WorldPay application, but RBS says no merchant or cardholder data was compromised



By Kelly Jackson Higgins | DarkReading

A Romanian hacker well-known for discovering SQL injection vulnerabilities in high-profile Websites has struck again -- this time on RBS WorldPay's site, where he says he hit the jackpot, the company's database.



The hacker, who goes by "Unu," says he accessed RBS WorldPay's database via a SQL injection flaw in one of its Web applications. RBS WorldPay maintains Unu accessed a test database that didn't carry any live data, and that no merchant or cardholder data accounts were compromised. The company has since taken down the pages.



Unu says the company's response to his email warning of the vulnerability, as well as other security problems, was "unprofessional" and "confused."

Continue Dark Reading



Bonus Coverage!

RBS WorldPay downplays database hack reports

Updated RBS WorldPay and a hacker are at loggerheads over the seriousness of a supposed breach on websites run by the payment processing firm.



Security shortcomings - since blocked - on RBS WorldPay website exposed confidential information, including admin passwords and the contact details of partners, according to blog posts by Romanian hacker Unu.

The grey-hat hacker previously exposed similar problems on the websites of the UK parliament and HSBC France, among many others. As before he published screenshots to back up his latest claims.


RBS WorldPay initially responded to our inquiries by saying that the reported SQL injection attacks mounted by Unu were thrown against test websites. All the dummy data involved was fictitious and in no way confidential, so there was no breach...



Editor's Note: You may or may not remember that RBS WorldPay previously had 1.5 million cards hacked.  Here's a refresher provided by DataLossdb.com















1.5 million credit card records compromised via hack
Records 1,500,000
Record Types CCN SSN
Breach Type Hack
Source Unknown
Organization RBS Worldpay
Other Organizations None
Lawsuit? YES
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: securityninja

TIMELINE

















DateEvent
2008-11-10 Incident Occured
None. Add Data Incident Discovered By Organization
2008-12-23 Organization Reports Incident
2008-12-23 Organization Mails Notifications
None. Add Data Records Recovered
2009-02-18 Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS






recordsdateorganizations
206,000 2005-12-28 Marriott International
679 2007-05-29 Mytreo.net
55,000 2006-01-08 Kerzner International Bahamas Limited, Atlantis

MAP OF INCIDENT LOCATION

Map
Satellite
Hybrid
Address: United States

Have a better address for this incident? Suggest it!
suggest a new reference

REFERENCES



Internet Gambling Initiative Gains Momentum



Congress Encouraged to Collect Billions in New Revenue with Internet Gambling Regulation in New Advertising Campaign



WASHINGTON, Sept. 14 /PRNewswire-USNewswire/ -- The Safe and Secure Internet Gambling Initiative launched a new online advertising campaign today in support of the Internet Gambling Regulation, Consumer Protection and Enforcement Act of 2009 (H.R. 2267), legislation that would establish a framework to permit licensed gambling operators to accept wagers from individuals in the U.S.



The ads advocate regulating Internet gambling to protect the millions of Americans who continue to gamble online despite government attempts to prohibit the activity and to collect up to $62.7 billion in new revenues for the federal government in the first decade.




"As Congress searches for ways to pay for health care reform and other worthy programs, it should end the unsuccessful prohibition of Internet gambling and start collecting taxes on the billions in revenue currently lost to unlicensed, offshore gambling operators," said Jeffrey Sandman, spokesperson for the Safe and Secure Internet Gambling Initiative.



House Committee of Financial Services Chairman Barney Frank (D-MA) has announced his intent to hold a hearing and markup on the Internet Gambling Regulation, Consumer Protection and Enforcement Act of 2009 this fall. Since introduction of the legislation by Chairman Frank in May, a bipartisan group of more than 50 co-sponsors have signed onto the bill. Supporters include many senior ranking representatives such as George Miller (D-CA), chairman of the Committee on Education and Labor, John Conyers (D-MI), chairman of the Committee on the Judiciary, Charles Rangel (D-NY), chairman of the Committee on Ways and Means, Edolphus Towns (D-NY), chairman of the Committee on Oversight and Government Reform, Pete King (R-NY), ranking member of the Homeland Security Committee and Ron Paul (R-TX), vice-chairman of the Oversight and Investigations subcommittee.



The ads will appear on the Web sites of publications such as the Washington Post, The Hill and Politico, as well as on the Huffington Post, Political Wire the Talking Points Memo...and obviously, right here on the PIN Payments News Blog!  



Copies of the advertisements can be found here: Protect Consumers and Generate Billions, End Prohibition! Again, Protect Children and Consumers.



About Safe and Secure Internet Gambling Initiative



The Safe and Secure Internet Gambling Initiative promotes the freedom of individuals to gamble online with the proper safeguards to protect consumers and ensure the integrity of financial transactions. For more information on the Initiative, please visit www.safeandsecureig.org. The Web site provides a means by which individuals can register support for regulated Internet gambling with their elected representatives.



SOURCE Safe and Secure Internet Gambling Initiative





Reblog this post [with Zemanta]

Smart Card Alliance Decries End to End Encryption





Smart Card Alliance Pushes Contactless Smart Cards over E2EE



According to Randy Vanderhoof, the executive director of the Smart Card Alliance, the US payments industry should use contactless chip cards along with dynamic cryptograms vs. E2EE in the fight against the bad guys...



I agree that the term "End-to-End Encryption" is buzz word and is used too "loosely" by too many players in the industry. 



True End-to-End Encryption means, first and foremost, that the card holder data must be "instantaneously" encrypted once the card is swiped.  The encrypted packet must stay that way (encrypted) until it reaches it's final destination.  There is only one transaction that can be fully end-to-end encrypted (*Zones 1-5)  and that is a PIN based transaction.  At best, other transactions can be End to (Almost) End Encrypted through *Zones 1-4. 



HomeATM's PCI 2.x certified PIN Entry Pad instantaneously encrypts the card holder data (including the Track2 data)  Credit and Debit card details remain encrypted via the HomeATM processing methodology through Zones 1-4.  A HomeATM processed PIN based transaction is 100% End to End Encrypted through Zones 1-5.



*See chart below for a Zone 1 through Zone 5 illustration provided by Mercator 



From SCA's new paper:

End-to-End Encryption and Chip Cards in the U.S. Payments Industry

Publication Date: September 2009



Recent and highly publicized data breaches at merchants and processors involving payment cardholder data have had a significant impact on the payments industry. For example, Wired magazine reported that Heartland Payment Systems estimates that the breach it experienced in 2008 has conservatively cost the company in excess of $12 million.[1] According to Bank Info Security magazine, the breach impacted at least 659 banks and credit unions.[2]



Analysis of the attacks has led to a flurry of interest in the implementation of end-to-end encryption solutions to protect cardholder data. Electronic payments industry stakeholders are taking action to address data security problems through the Accredited Standards Committee X9 (ASC X9) by embarking on the development of a new standard to protect cardholder data with end-to-end encryption.[3] This paper presents the Smart Card Alliance perspectives on this initiative.



Encryption of data would make it much harder for attackers to benefit from the kind of network break-in that Heartland suffered. Since sensitive data was not sufficiently protected, cyber-thieves were capable of stealing millions of debit and credit card details for several months after initially infiltrating the Heartland computer systems.[4]



Supporters of end-to-end encryption envision that cardholder data would be encrypted from the moment the magnetic stripe of the payment card is swiped through the end of the payment processing cycle. The devil is in the details, however. End-to-end encryption does not necessarily mean the same thing to all people, and the payments industry has not yet defined standards.



Editor's Note:  Very well put.  Click the Zone 1-5 chart on the right to enlarge:



This position paper attempts to clarify and define end-to-end encryption, and detail the problems it solves and those it does not. It also explores the advantages of an alternative strategy for protecting cardholder data–moving data protection to the true endpoint, the payment card itself, using chip card technology.



Instead of implementing “chip and PIN” and following the full EMV standard, this paper proposes a new course optimized for the U.S. market: using contactless chip cards, including a dynamic cryptogram with each transaction and authorizing transactions online.



The existing U.S. payments infrastructure can process such transactions today in the same way that current contactless payment transactions are accepted.



Compared to end-to-end encryption, contactless cards with dynamic cryptograms would have the following advantages:

  • Result in less impact on the payments acceptance infrastructure for merchants, acquirers and issuers

  • Enable merchants to implement a solution more quickly and without waiting for new standards

  • Provide a high level of cardholder data protection by including a dynamic cryptogram with each transaction

  • Reduce the threats posed by cloning magnetic stripe-based cards and stealing cardholder data

The Smart Card Alliance is making another important recommendation as well. If the industry does indeed move forward with end-to-end encryption, the standard should be defined in a way that lays the messaging foundation for globally-interoperable secure payment transactions using chip card technology in the future. This would have no impact on end-to-end encryption cost or complexity, and yet would make the U.S. payments messaging standard compatible with global payments infrastructure requirements.

What Is End-To-End Encryption?

The Computer Desktop Encyclopedia defines end-to-end encryption as the continuous protection of the confidentiality and integrity of transmitted information by encrypting it at the origin and decrypting at its destination.[5]





A reasonably good example of true end-to-end encryption is the distribution of a secret key under a Key Exchange Key (KEK) process between two hardware security modules (HSMs). The KEK process is a common practice in many industries including government, telecommunications and banking, in applications where end-to-end security must be ensured. Using this technique, the secret key is never seen in the clear outside of the two endpoints. The first HSM (the origin) encrypts the secret key using the Key Exchange Key then the encrypted key can be securely sent to the second HSM (the destination) where it is decrypted.

With respect to a payment transaction, “origin” and “destination” are not single places, causing the potential for confusion. There are many temporary endpoints in a transaction lifecycle where all or part of the transaction information is required. In addition, there are several processes, starting with authorization and settlement; but data may be used or stored for refunds, chargebacks or reporting purposes in other places as well. The figure above  illustrates a generic credit card transaction process today.




"Implementing end-to-end encryption is not a panacea; in fact, it may be more akin to putting a steel door on a grass hut," says Randy Vanderhoof, executive director, Smart Card Alliance.


Download the paper to read more...or click here to read the summary at the Smart Card Alliance website



Reblog this post [with Zemanta]

Intuit "Into Mint" for $170 Million

TechCrunch's Michael Arrington is reporting that Mint is being acquired by Intuit.  According to him...



Intuit will acquire the free online personal finance service Mint, we’ve confirmed from a source close to the deal, for around $170 million. The deal should be announced in the next few days.



This is a terrific exit for Mint, which first launched two years ago at TechCrunch50. Mint took the top prize at that event and has been growing fast ever since. Their last round of financing valued the company at $140 million.

Continue Reading at TechCrunch





Reblog this post [with Zemanta]

Disqus for ePayment News