Hack turns Square into criminal tool
August 5, 2011 by Glenn Chapman
Hackers have shown how to turn the mobile payment service Square into a convenient tool for criminals to pump cash from stolen credit card numbers.
Hackers have shown how to turn mobile payment service Square into a convenient tool for criminals to pump cash from stolen credit card numbers.
Adam Laurie and Zac Franken of computer security firm Aperture Labs used a homemade software program and an easily bought iPad audio wire to trick Square in a way that could be a bonanza for crooks.
Laurie could type credit card numbers into his laptop, which converts to sound data sent to Square, where the transaction registers as if a real card were swiped in a dongle.
"Traditionally, the way you make money from stolen credit cards is sell the data to someone else or buy goods on it, then resell the goods and get the cash," Laurie said while demonstrating the hack at a Black Hat computer security gathering in Las Vegas.
"This really takes the hassle out of it... I can put the money right in the account and it only costs me 2.75 percent."
The percentage he cited was the fee charged by Square, which was co-founded by Jack Dorsey, a Silicon Valley star who helped create popular micro-blogging service Twitter.
Square markets a pocket-sized credit card reader that can be plugged into a smartphone to allow anyone to accept credit or debit card payments on the spot.
Franken and Laurie, whose hacker name is "Major Malfunction," said that they were waiting for a flight at an airport when then figured out how to convert Square into a handy tool for cashing in on stolen credit cards.
Laurie realized that the Square "dongle" used to swipe credit cards plugged into an iPad audio jack, indicating that the small device essentially converted magnetic stripe data to sound then interpreted by the service's software.
He quickly modified software he wrote five years earlier for reading and replicating magnetic stripe data.
Franken and Laurie strolled to an airport shop and bought a wire to plug his laptop into the iPad jack where the dongle would have gone.
"Credit card data is getting skimmed all the time," Laurie said, holding up a pre-paid credit card he used for the demonstration. "Instead of buying this I could have bought it on the Internet from a criminal gang."
Funds are dumped into an individual's Square account to be removed before anyone catches on, according to the hackers.
"You'd have to set up dodgy accounts that don't trace back to you," Laurie said. "But, that is standard practice."
Laurie and Franken said that they shared their findings with Square in February only to be told that it wasn't seen as a threat and that traffic analysis would expose those kinds of transactions.
The hackers had also heard unconfirmed reports that Square planned to release new dongles that encrypt transaction data.
"Encryption would be a good thing," Franken said. "The way it is at the moment a cable between two devices and you can inject credit card numbers right into the system," he continued.
Since Square promises to have money from transactions in accounts within a day, money milked from stolen credit card data could be made off with quickly provided amounts were extreme enough to be noticed, Franken said.
(c) 2011 AFP
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
32 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
42 comments
-
Climate scientists say they have solved riddle of rising sea,
31 comments
-
SpaceX capsule has 'new car' smell, astronauts say (Update),
2 comments
-
Need a rigid insulation material???
13 hours ago
-
magnets or EMF in car bumpers to protect from fender bender
May 26, 2012
-
length of wire in a coil of known dimensions?
May 25, 2012
-
India Engineering Powerhouse
May 25, 2012
-
electromagnet core dereference between hard and soft iron
May 25, 2012
-
Measuring water pressure in an open tank
May 24, 2012
- More from Physics Forums - General Engineering
More news stories
Browser wars flare in mobile space
The browser wars are heating up again, but this time the fight is for dominance of the mobile Internet.
6 hours ago |
5 / 5 (1) |
2
Probability of contamination from severe nuclear reactor accidents is higher than expected: study
Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...
Technology / Energy & Green Tech
May 22, 2012 |
3.6 / 5 (22) |
56
|
SpotterRF debuts Radar Backpack Kit (w/ Video)
(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...
HyperSolar shows dirty water no barrier to power world
(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the companys ultimate vision, successfully producing ...
Tesla to launch electric sedan in US on June 22
Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.
Technology / Energy & Green Tech
May 22, 2012 |
4.5 / 5 (11) |
18
Nvidia trumpets Tegra 3 phone design wins for 2012
(Phys.org) -- Nvidias competitive war paint has a name, Tegra 3. On the heels of Nvidia announcements about lowering costs of its Tegra 3 processors and Nvidia-enabled tablets running Android Ice Cream ...
Scientist: Evolution debate will soon be history
(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.
Dell tablet leak: 10.1-inch display, two-battery choice
(Phys.org) -- Headline after headline talks about vendors tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...
Keep food safety in mind this memorial day weekend
(HealthDay) -- Picnics, parades and cookouts are as much a part of Memorial Day weekend as tributes to the United States' war veterans.
Social welfare cuts ultimately come with heavy price, researchers say
(Phys.org) -- Slashing government funding for Medicaid, food stamps and other programs that serve the poor while politically popular with some lawmakers and many conservatives may do more harm ...
Is a classical electrodynamics law incompatible with special relativity?
(Phys.org) -- The laws of classical electromagnetism that were developed in the 19th century are the same laws that scientists use today. They include Maxwell’s four equations along with the Lorentz la ...
Aug 06, 2011
Rank: 1 / 5 (1)
There are many different definitions for "program". But if it's software, it's a program. So there is no need to write both. If you want to get technical, not all software runs on what we normally think of as computers, so if you really feel the need to be specific, "computer software" or "home computer software" is perhaps overly descriptive in most circumstances, but at least it's not -- quite -- redundant.
Oct 03, 2011
Rank: not rated yet
when then figured out how to convert Square into a handy tool for cashing in on stolen credit cards.
when THEY