Hacker News new | past | comments | ask | show | jobs | submit login

This article [1] argues that RAM scrapers are only able to work because the point-of-sale systems are running Windows XP.

Newer versions of Windows make this exploit far more difficult [2].

[1] http://www.dailytech.com/Appalling+Negligence+DecadeOld+Wind...

[2] http://en.wikipedia.org/wiki/Address_space_layout_randomizat...




I wouldn't call a RAM scraper an exploit. ASLR isn't an effective protection against a program that reads from memory. Driver signing in newer versions of Windows is a more appropriate protection but will still fall short of stopping a motivated attacker.


Most of POS terminals aren't using Windows, but embedded custom operating system, firmware & software. https://news.ycombinator.com/item?id=8409305




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: