Showing posts with label Payment. Show all posts
Showing posts with label Payment. Show all posts

Sunday, 30 November 2014

US Parking Malware



The payment of various car parks in the United States are infected by malware, where possible, data from credit and debit cards from an unknown number of customers have been stolen. Before warns SP Plus an American company that parking services offered to owners of real estate, such as shopping malls and offices.

SP Plus received a message from the provider that manages the payment systems in the parking garages. An attacker could access the remote access tool received from the supplier and so could log on to the payment. There installed the malware attacker could intercept the data of payment cards which was settled in the car parks. It would be the cardholder's details (cardholder's name, card number, expiration date and verification code).

In all, 17 parks have been affected. Whether there actually map data can be stolen SP Plus does not say, but the company decided to issue a warning. Meanwhile, the malware would be disabled on all affected systems. In addition, the company's supplier obliged henceforth to use two-factor authentication when logging on to the payment.

17 SP+ Affected Parking Location's

Monday, 21 July 2014

PayPal lets bug webshops arbitrary amount Checkout

Paypal Bug

A bug in the online payment service PayPal enables webshops to settle after the customer has been given. Attachment for a different amount any amount Thus, the customer thinks he is buying something for one euro, for example, while the shop settles 200 euros.
However, the customer receives only the confirmation email from PayPal that 200 euros is charged. The problem is when using the PayPal Express Checkout, says the German security researcher Jan Kechel . This confirms the customer in its PayPal payment environment and think you have judged. After the payment through PayPal, the user is sent back to the shop, where another function is called that allows you to transfer, without the customer has given consent another amount will be.
Kechel discovered the problem and reported it to PayPal. The payment service stated that it is not a bug but is "intended behavior", due to small differences in transport costs and the like. The researcher believes that PayPal however all amounts greater than the fixed amount must confirm this. Again by the customer As evidence Kechel made ​​this demonstration .