版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
XP Windows7
XP Windows7
XP
XP ATM
WindowsXP'sretirementcouldputATMsandmoreatrisk
XP
AfterApril8th,2014,Microsoft(MSFT)willendsupport,includingautomaticsecuritypatches,forits13-year-oldWindowsXPoperatingsystem.Thismaysoundlikeaninconvenienceprimarilyforgovernmentagenciesandaginguncles,butanothermajorsetofWindowsXPusersaretheautomatedtellermachinesandcreditcardsalessystemsthathandlebillionsofdollarsoftransactionsdaily.
201448
Microsoft
13
Windows
XP
WindowsXP
Whilemajorretailersandbanksarelikelytobewell-preparedfortheendofXP,financialsystemsbasedonthesoftwarearealsointhehandsofafar-reachinghodgepodgeofindependentATMoperatorsandsmallbusinesses.Despiteamplewarning,industryanalystsandinsidersagreethathighcostandinconveniencewillkeepplentyofthesesmallerplayersrunningoutdatedsoftwareformanymonthstocome--withseriousimplicationsforthesecurityoftheirsystems.
XP
JerryNevins,co-owneroftheKansasCitycocktailbarSnow&Co.,isclosetothedilemma.Snow&Co.boughtapointofsalesystemlessthanayearagofromthepaymentsservicerMicros--onlytobetoldwithinafewmonthsoftheneedforanupgradetoWindows7,atacostof$1,700forthesingle-storesystem.Luckily,Snow&Co.wasstillunderaserviceagreement,soitsupgradewasfree.ButasNevinsputsit,"Ifyou'reasmallbusiness,anunexpected$1,700mightbelike,eh,I'llgoaheadandtakemychances."Moreover,Nevinsdescribesa"hugeline"ofMicroscustomerswaitingforanupgrade.He'scrossinghisfingersthatSnow&Co.willbeupgradedbeforetheApril8deadline.
Snow&Co
Micros
Windows7
1700
1700
Coststoretailcreditcardprocessorswillvarywidely,saysJohnBerkeleyofMercuryPaymentSystems."IfyouhavetherighthardwareyoucanjustupgradetheOS,butforsomemerchantsupgradingfromXPtoWindows7canmeanallnewhardware,"likelycostingmuchmorethanthat$1,700.
MercuryPaymentsSystems
1700
ThechallengesofupgradingbecomeevenbiggerinthecaseofATMs.ATMmanufacturersareofferingsoftwareupgradesformachinesstillbasedonXP--thoughsomeofthosehavebeenavailableforlessthanamonth.Butthecosttoupgradecanbestaggering.
ATM
ATM
XP
ATM
AccordingtoJayWeber,vicepresidentinchargeofNorthAmericandebitandATMsystemsforFISGlobal,"AnATMmachinepurchasedinthelastfiveyears...wouldonlyneedasoftwareupgradeof$4,000to5,000permachine."ThatsoftwarecostissohighinpartbecausemuchspecializedsoftwarewrittenforWindowsXPcan'tbeeasilyportedtoanewoperatingsystem.ButATMs10yearsoldormorewouldneedtobecompletelyreplaced,andWebersaysthatnewhigh-endATMscancostatleast$50,000to$60,000perdevice.
FISGlobal
ATM
ATM
40005000
ATM
WindowsXP
10
ATM
ATM
ATMoperatorsandbusinessownersarelargelybeinglefttodecideontheirownwhethertoupgradeornot,saysWeber."Organizationsaretryingtolookattheinvestmentoftheupgradeandweightitagainsttheirperceivedrisk"--andmanyseemtobereadytotaketheirchances."[April9th]isgoingtocomeandgo,andtherearegoingtobesomemerchantswhohaven'tdoneityet,"saysBerkeley.Weberspeculatesthat"it'sgoingtobeatrickleapproach,aslowerramp-up,"withmanysystemsgoingwithoutanupgrade--andremainingofficiallyinsecure--throughtheendof2014.
ATM
2014
Thishesitancymaybeworsenedbecauseoperatorsaregettingmixedmessagesabouttheirrisk.ThePaymentsCardIndustrySecurityStandardsCouncilhasissuedpublicwarningsabouttheneedforretailerstoupgradetheirpointofsalesystems,buttheircurrentsetofstandards,whichareusedtodetermineeligibilitytooperateoncreditcardnetworks,donotrequireit.AndWeberhimselfseemssanguine:"Theriskishardtoquantify.There'salotoftechnologyinplaceinthemarketplacetohelpmitigatetherisk,"suchasthe"fairlyclosedtelecomenvironment"thatmostpaymentsystemsoperateon.
thePaymentsCardIndustrySecurity
StandardsCouncil
ButBogdanBotezatu,seniore-threatanalystfortheanti-malwaresoftwarecompanyBitdefender,couldn'tdisagreemore.Hetalksabouttheissuewiththebarelysuppressedterrorofafatherwatchinghisteenagesondrivesoloforthefirsttime."They'renotpanicky,"hesays,"andactuallythatmakesmepanicky."
XP
XP
Bitdefender
Botezatu,whohauntsundergroundhackingforumstokeepaneyeonloomingsecuritythreats,claimsthathackersaregearinguptoraidsuddenlyinsecureXPmachinestheminuteMicrosoftsupportends."Whenanoperatingsystemisannouncedasreachingitsendoflife,[hackers]arefranticallylookingforexploits,becausethentheycanuseitindefinitely,"hesays."It'stheholygrailofmalware."
XP
WindowsXP
Totakefullestadvantageofthesituation,black-marketvendorssellingnewXPexploitshavebeenstockpilingthem,waitingtoreleasethemuntilafterMicrosoftisnolongermonitoringandrepairingsecurityflaws.Thoughthird-partysecurityfirmswillcontinuetoupdateanti-malwareprogramsforXP,usersnotrunningorupdatingsuchsoftwarecouldbepermanentlyvulnerabletoanever-growingsetofexploits.MercuryPaymentSystems'JohnBerkeleyconfirmsthat"Ifahackerdiscovers[avulnerability]amonthortwoaftertheendof[XPsupport],theyhavemoretimetoexploitthat."
XP
XP
XP
Theseexploitscouldrangefromstealingcreditcardinformationfromsmallvendorstoevenmoredramaticformsoftheft,manyofthemeasilycircumventingexternalsecuritymeasuressuchasthesemi-closedpaymentsnetwork.BotezatusaystherehavebeenreportsofanATMexploitthroughamobilephoneconnectedthroughanATM'scardreader.HealsocitesalegendarystuntbythesecurityexpertBarnabyJackattheBlackHatsecurityconferencein2010,wherehedemonstrateda"Jackpotting"hackthateasilyemptiedanXP-basedATMmachine.AccordingtoBotezatu,Jack,whodiedin2013,neverrevealedthenatureofthisexploit,meaningthatitcouldremainanunpatchedvulnerabilityinXP-basedmachines.
ATM
ATM
2010
XPATM
2013
XPATM
Mosttroublingofall,BotezatupredictsthatunsecuredXPmachinesofallkindswillbecompromisedbyhackerstoformnewbotnets.Thiskindofsystem,inwhichhackedsystems'processorsareputtonewtasksunbeknownsttotheirowners,canbeusedforeverythingfrommassiveDenialofServiceattackstominingcryptocurrency,and
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 場(chǎng)地使用租賃合同租賃合同
- 未成年演員聘用合同書
- 2025年度跨境電子支付系統(tǒng)開發(fā)與運(yùn)營(yíng)合同3篇
- 2024版給水安裝工程分包合同2篇
- 2025年快速消費(fèi)品水路運(yùn)輸服務(wù)合同2篇
- 工程總承包合同補(bǔ)充協(xié)議書
- 二手房買賣墊資合同(2024版)
- 2024行政合同在公共衛(wèi)生事件應(yīng)對(duì)中的法律依據(jù)與實(shí)施3篇
- 2025年度逆向供應(yīng)鏈管理合同2篇
- 2025年度民品典當(dāng)借款合同法律保障范本2篇
- 獵聘-2024高校畢業(yè)生就業(yè)數(shù)據(jù)報(bào)告
- 2024年公務(wù)員考試必背常識(shí)大全
- 勞工與人權(quán)管理核心制度
- 北師大版數(shù)學(xué)五年級(jí)上冊(cè)第三單元《倍數(shù)與因數(shù)》大單元整體教學(xué)設(shè)計(jì)
- 中藥灌腸方法
- 醫(yī)美整形美容醫(yī)院眼部抗衰品牌課件
- 軟件研發(fā)安全管理制度
- 大學(xué)暑假假期社會(huì)實(shí)踐心得體會(huì)3篇
- 科普產(chǎn)業(yè)發(fā)展現(xiàn)狀調(diào)查報(bào)告
- 2024湖南湘電集團(tuán)有限公司招聘筆試參考題庫(kù)附帶答案詳解
- 新課標(biāo)人教版小學(xué)四年級(jí)體育與健康下冊(cè)全冊(cè)教案設(shè)計(jì)及教學(xué)反思
評(píng)論
0/150
提交評(píng)論