BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Very Pwned: Hacking Verifoneâ€™s card machine three 
 times in a\n   row\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Exploit ð
 Ÿª²\n   When: Saturday\, Aug 8\, 11:00 - 11:59 PDT\n   Where: LVCCW Level 
 1 Hall 3 903 (Main Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   E
 veryday billions of credit card transactions are made worldwide\, with\n  
  the vast majority being done on purpose-built card machines. In the\n   U
 SA alone\, nearly 400 million transactions are performed per day on\n   th
 ese popular devices present in nearly every retail store. In this\n   talk
 \, Iâ€™ll focus on a widely deployed Verifone product line of card\n   mac
 hines\, with an estimated global deployment of over one million\n   units.
  For several consecutive years I conducted an annual security\n   assessme
 nt on these devices\, until a pattern emerged: I'd arrive at\n   the asses
 sment\, find a fresh set of vulnerabilities\, gain root access\,\n   and t
 hen have Verifone patch the devices â€” only for me to return the\n   foll
 owing year and gain root access in a new way. Iâ€™ll demonstrate\n   the t
 hree separate attack chains I discovered\, two of which only\n   required 
 network access to the target. Iâ€™ll also detail additional\n   vulnerabil
 ities that could be used to disable hardening features such\n   as grsecur
 ity\, including the ability to modify the file system to gain\n   persiste
 nt access. Next\, Iâ€™ll show how an attacker could leverage\n   this acce
 ss to continuously capture credit card information - contrary\n   to the d
 eviceâ€™s security claims. Finally\, in a homage to\n   trixr4skids' DEF C
 ON 25 talk in which he hacked an older series of\n   Verifone's devices\, 
 I'll also run Doom.\n\n   DEF CON 25 - trixr4skids' DOOMed Point of Sale S
 ystems CCC May Contain\n   Hackers2022 - Thomas Rinsma's Payment terminals
  as general purpose\n   (game-)computers\n\n   SpeakerBio:  Reino Mostert\
 , Orange Cyberdefense\n\n   Reino is a hacker who has been working as a pe
 netration tester for the\n   past decade. He has hacked various payment sy
 stems - from credit card\n   devices all the way to payment switches\, and
  has given talks at\n   numerous cons. He enjoys coffee and hacking.\n\n  
  '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T185900Z
DTSTART:20260808T180000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:Very Pwned: Hacking Verifoneâ€™s card machine three times in a row
END:VEVENT
END:VCALENDAR
