{"id":71320,"date":"2014-08-05T13:17:40","date_gmt":"2014-08-05T17:17:40","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-07-20T11:49:43","modified_gmt":"2021-07-20T15:49:43","slug":"remote-desktop-open-door-to-pos-malware","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/","title":{"rendered":"Remote Desktop Opens Door to POS Malware"},"content":{"rendered":"<p><a href=\"https:\/\/www.ecvv.com\/product\/4330896.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-98600 \" title=\"Remote Desktop Opens Door to POS Malware\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/all_in_one_pos.jpg?resize=109%2C107&#038;ssl=1\" alt=\"Remote Desktop Opens Door to POS Malware\" width=\"109\" height=\"107\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/all_in_one_pos.jpg?resize=150%2C147&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/all_in_one_pos.jpg?resize=75%2C73&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/all_in_one_pos.jpg?w=498&amp;ssl=1 498w\" sizes=\"auto, (max-width: 109px) 100vw, 109px\" \/><\/a>The U.S. <strong>Department of Homeland Security (DHS)<\/strong> has issued a warning to retailers. DHS reports that cybercriminals are using <strong>remote desktop software<\/strong> to open up retailers&#8217; networks to <strong>point-of-sale malware<\/strong> attacks. <a title=\"Point of Sale\" href=\"http:\/\/whatis.techtarget.com\/definition\/point-of-sale-terminal-POS-terminal\" target=\"_blank\" rel=\"noopener noreferrer\">Point of Sale<\/a> (POS) systems have been at the heart of many of the recent data breaches. Retailers impacted include <a title=\"Target\" href=\"https:\/\/web.archive.org\/web\/20191016012257\/https:\/\/blogs.wsj.com\/corporate-intelligence\/2013\/12\/27\/targets-data-breach-timeline\/\" target=\"_blank\" rel=\"noopener noreferrer\">Target<\/a>, <a title=\"Jimmy John's\" href=\"https:\/\/krebsonsecurity.com\/2014\/07\/sandwich-chain-jimmy-johns-investigating-breach-claims\/\" target=\"_blank\" rel=\"noopener noreferrer\">Jimmy John&#8217;s<\/a>.\u00a0<span style=\"color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 19.600000381469727px;\"><a title=\"P.F. Chang&#039;s\" href=\"https:\/\/web.archive.org\/web\/20171204113950\/https:\/\/www.pfchangs.com\/security\/\" target=\"_blank\" rel=\"noopener noreferrer\">P.F. Chang&#8217;s<\/a>, <a title=\"Neiman Marcus\" href=\"https:\/\/web.archive.org\/web\/20211001220122\/https:\/\/www.nytimes.com\/2014\/01\/24\/business\/neiman-marcus-breach-affected-1-1-million-cards.html\" target=\"_blank\" rel=\"noopener noreferrer\">Neiman Marcus<\/a>, <a title=\"Michaels\" href=\"https:\/\/web.archive.org\/web\/20221127203459\/https:\/\/www.michaels.com\/notices\/ca-notices.html\" target=\"_blank\" rel=\"noopener noreferrer\">Michaels<\/a>, <a title=\" Sally Beauty Supply\" href=\"http:\/\/krebsonsecurity.com\/2014\/03\/zip-codes-show-extent-of-sally-beauty-breach\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sally Beauty Supply<\/a>, and <a title=\"Goodwill Industries International\" href=\"http:\/\/krebsonsecurity.com\/2014\/07\/banks-card-breach-at-goodwill-industries\/\" target=\"_blank\" rel=\"noopener noreferrer\">Goodwill Industries International<\/a> t<\/span><span style=\"color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 19.600000381469727px;\">he<em> <a title=\"New York Times\" href=\"http:\/\/www.nytimes.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">New York Times<\/a> <\/em><\/span>reported.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20201029221808\/https:\/\/www.choosewhat.com\/starticles\/6-easy-ways-to-protect-your-credit-card-processing-system-from-hackers\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98607 \" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers1-1-e1564260780511-150x119.jpg?resize=113%2C90&#038;ssl=1\" alt=\"\" width=\"113\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers1-1-e1564260780511.jpg?resize=150%2C119&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers1-1-e1564260780511.jpg?resize=75%2C60&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers1-1-e1564260780511.jpg?w=742&amp;ssl=1 742w\" sizes=\"auto, (max-width: 113px) 100vw, 113px\" \/><\/a>Research conducted by the <a title=\"U.S. Department of Homeland Security\" href=\"https:\/\/WWW.DHS.GOV\" target=\"_blank\" rel=\"noopener noreferrer\">DHS<\/a>, the <a title=\"Secret Service\" href=\"http:\/\/www.secretservice.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">Secret Service<\/a>, the <a title=\"National Cybersecurity and Communications Integration Center\" href=\"https:\/\/web.archive.org\/web\/20150905132538\/http:\/\/www.dhs.gov\/about-national-cybersecurity-communications-integration-center\" target=\"_blank\" rel=\"noopener noreferrer\">National Cybersecurity and Communications Integration Center<\/a>, and security firm <a title=\"Trustwave SpiderLab\" href=\"https:\/\/web.archive.org\/web\/20150215183448\/http:\/\/www.trustwave.com:80\/Services\/SpiderLabs-Services\/\" target=\"_blank\" rel=\"noopener noreferrer\">Trustwave SpiderLab<\/a>. have following the attacks. During the attacks, <strong>Cybercriminals are scanning<\/strong> corporate systems for <strong>remote desktop software. <\/strong>The attackers are looking for\u00a0<span style=\"color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 19.600000381469727px;\"><a title=\"Microsoft\" href=\"http:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> (<a title=\"NASDAQ | MSFT\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-MSFT\/\" target=\"_blank\" rel=\"noopener noreferrer\">MSFT<\/a>) <a title=\"RDP\" href=\"http:\/\/windows.microsoft.com\/en-us\/windows7\/products\/features\/remote-desktop-connection\" target=\"_blank\" rel=\"noopener noreferrer\">Remote Desktop<\/a>,\u00a0<a title=\"Apple Computers\" href=\"http:\/\/www.apple.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple<\/a> (<a title=\"NASDAQ : AAPL\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-AAPL\/\" target=\"_blank\" rel=\"noopener noreferrer\">AAPL<\/a>) <a title=\"Apple Remote Desktop\" href=\"https:\/\/www.apple.com\/remotedesktop\/\" target=\"_blank\" rel=\"noopener noreferrer\">Remote Desktop<\/a>, <a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> (<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>) <a title=\"Chrome Remote Desktop\" href=\"http:\/\/www.pcworld.com\/article\/2154184\/access-your-pcs-remotely-for-free-with-chrome-remote-desktop.html\" target=\"_blank\" rel=\"noopener noreferrer\">Chrome Remote Desktop<\/a>, <a title=\"Splashtop\" href=\"http:\/\/www.splashtop.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Splashtop<\/a>, <a title=\"Pulseway\" href=\"https:\/\/www.pulseway.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Pulseway<\/a>, and <a title=\"LogMeIn join.me\" href=\"https:\/\/www.goto.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">LogMeIn&#8217;s join.me<\/a>.<\/span><\/p>\n<h3>Install malware<\/h3>\n<p><span style=\"color: #333333; font-family: Arial, Helvetica, sans-serif;\">After finding an exposed system, attackers<\/span> launch <strong>brute force attacks on the login<\/strong> feature. <a href=\"https:\/\/web.archive.org\/web\/20160729153456\/http:\/\/www.fierceitsecurity.com:80\/?\" target=\"_blank\" rel=\"noopener noreferrer\"><em>FireceIT Security<\/em><\/a> <a href=\"https:\/\/web.archive.org\/web\/20150919010019\/http:\/\/www.fierceitsecurity.com\/story\/remote-desktop-software-opens-retailers-doors-pos-malware\/2014-07-31\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that once the attackers gain network access, they deploy <strong>Backoff POS malware.\u00a0 steal customer payment data and hide the theft using encryption. <\/strong>\u00a0An <a href=\"https:\/\/web.archive.org\/web\/20181116144918\/https:\/\/www.us-cert.gov\/security-publications\/Backoff-Point-Sale-Malware\" target=\"_blank\" rel=\"noopener noreferrer\">alert<\/a> was issued by <strong><a href=\"http:\/\/www.us-cert.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">US-CERT<\/a><\/strong> on 07-31-2014 that explained how the malware gets installed.<\/p>\n<p style=\"padding-left: 30px;\"><em>At the time of discovery and analysis, the [Backoff] malware variants had low to zero percent anti-virus detection rates, which means that fully updated anti-virus engines on fully patched computers could not identify the malware as malicious<\/em><\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20150926084842\/http:\/\/blogs.norman.com\/2012\/for-consumption\/new-malware-type-old-security-threat\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98609 \" title=\"malware\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware-4.jpg?resize=90%2C90&#038;ssl=1\" alt=\"malware\" width=\"90\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware-4.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware-4.jpg?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/malware-4.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 90px) 100vw, 90px\" \/><\/a>US-CERT has informed <strong>anti-virus vendors<\/strong> of the threat from <a href=\"https:\/\/web.archive.org\/web\/20140804030626\/http:\/\/blog.spiderlabs.com:80\/2014\/07\/backoff-technical-analysis.html\" target=\"_blank\" rel=\"noopener noreferrer\">Backoff malware<\/a> and they will be <strong>updating their software<\/strong> to detect and block the malware. The malware can <strong>scrape memory for track data, log keystrokes, engage in command and control communication, and inject a malicious stub<\/strong> into explorer.exe that ensures &#8220;persistence in the event the malicious executable crashes or is forcefully stopped.&#8221;<\/p>\n<p>The article concludes, &#8220;The impact of a <strong>compromised POS system<\/strong> can affect both the businesses and consumer by exposing customer data such as names, mailing addresses, <strong>credit\/debit card numbers<\/strong>, phone numbers, and e-mail addresses to criminal elements. These breaches can impact a business&#8217; brand and reputation, while consumers&#8217; information can be used to make fraudulent purchases or risk compromise of bank accounts.<\/p>\n<p><strong><em> rb-<\/em><\/strong><\/p>\n<p><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98611 \" title=\"Lesson learned?\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/why_boys_need_parents.jpg?resize=115%2C108&#038;ssl=1\" alt=\"Lesson learned?\" width=\"115\" height=\"108\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/why_boys_need_parents.jpg?resize=150%2C141&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/why_boys_need_parents.jpg?resize=75%2C71&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/why_boys_need_parents.jpg?w=450&amp;ssl=1 450w\" sizes=\"auto, (max-width: 115px) 100vw, 115px\" \/>If mega-firms like Target can be breached, what chance do small mom-and-pop POS firms in schools, food trucks, kiosks at the airport stand? I say not much. I have worked with several POS vendors and it seems they barely understand their own product, let alone SSL certs, VPNs. <\/em><\/p>\n<p><em>Here are some tips from <a title=\"Data Breach Investigations Report (DBIR) \" href=\"http:\/\/www.verizonenterprise.com\/DBIR\/\" target=\"_blank\" rel=\"noopener noreferrer\">Verizon\u2019s 2012 research<\/a> into security breaches affecting companies that use POS systems to process customer payments. Make sure your POS vendor does the following: <\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>1.\u00a0 Change administrative passwords on all POS systems.<\/strong> (Hackers are scanning the Internet for easily guessable passwords).<\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>2.\u00a0 Implement a firewall or access control list on remote access \/administration services.<\/strong> (If hackers can\u2019t reach your systems, they can\u2019t easily steal from it).<\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>3.\u00a0 Avoid using POS systems to browse the web<\/strong> (or anything else on the Internet).<\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>4.\u00a0 Make sure your POS is a <a title=\"What is PCI DDS?\" href=\"https:\/\/web.archive.org\/web\/20200501132614\/https:\/\/searchfinancialsecurity.techtarget.com\/definition\/PCI-DSS-Payment-Card-Industry-Data-Security-Standard\" target=\"_blank\" rel=\"noopener noreferrer\">PCI DSS compliant<\/a> application<\/strong> (ask your vendor) <\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>5.\u00a0 Use password management software like <a title=\"LastPass Password Management\" href=\"https:\/\/lastpass.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">LastPass<\/a> to generate secure passwords. <\/strong>(<\/em><em>LastPass<\/em> allows you to avoid storing passwords in your browsers and can generate ready-to-use secure passwords for you).<\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/time.com\/3070555\/malware-backoff-dhs-hacking-retail\/\" target=\"_blank\" rel=\"noopener noreferrer\">600 Retailers Ensnared in Major New Malware Hack, Cybersecurity Firm Says<\/a> (time.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2292,420,101,536,92,23,82,421,2205,2206,2207,4],"class_list":["post-71320","post","type-post","status-publish","format-standard","hentry","category-security","tag-2292","tag-aapl","tag-apple","tag-goog","tag-google","tag-malware","tag-microsoft","tag-msft","tag-point-of-sale","tag-pos","tag-remote-desktop","tag-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"RB\"\/>\n\t<meta name=\"keywords\" content=\"point of sale,malware,apple,microsoft,google,pos,remote desktop,aapl,goog,msft,2014,security\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Bach Seat | The view from where I am sitting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Remote Desktop Opens Door to POS Malware | Bach Seat\" \/>\n\t\t<meta property=\"og:description\" content=\"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-08-05T17:17:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-07-20T15:49:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ralph.bach.14\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@rbach48334\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Remote Desktop Opens Door to POS Malware | Bach Seat\" \/>\n\t\t<meta name=\"twitter:description\" content=\"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@rbach48334\" \/>\n\t\t<meta name=\"twitter:image\" content=\"http:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#article\",\"name\":\"Remote Desktop Opens Door to POS Malware | Bach Seat\",\"headline\":\"Remote Desktop Opens Door to POS Malware\",\"author\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/rbach.net\\\/wp-content\\\/uploads\\\/all_in_one_pos-150x147.jpg\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#articleImage\"},\"datePublished\":\"2014-08-05T13:17:40-04:00\",\"dateModified\":\"2021-07-20T11:49:43-04:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#webpage\"},\"articleSection\":\"Security, 2014, AAPL, Apple, GOOG, Google, Malware, Microsoft, MSFT, Point of sale, POS, Remote Desktop, Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/rbach.net\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#listItem\",\"name\":\"Remote Desktop Opens Door to POS Malware\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#listItem\",\"position\":3,\"name\":\"Remote Desktop Opens Door to POS Malware\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\",\"name\":\"RB\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r\",\"width\":96,\"height\":96,\"caption\":\"RB\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\",\"url\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/\",\"name\":\"RB\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r\",\"width\":96,\"height\":96,\"caption\":\"RB\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#webpage\",\"url\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/\",\"name\":\"Remote Desktop Opens Door to POS Malware | Bach Seat\",\"description\":\"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/remote-desktop-open-door-to-pos-malware\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"datePublished\":\"2014-08-05T13:17:40-04:00\",\"dateModified\":\"2021-07-20T11:49:43-04:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rbach.net\\\/#website\",\"url\":\"https:\\\/\\\/rbach.net\\\/\",\"name\":\"Bach Seat\",\"description\":\"The view from where I am sitting\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Remote Desktop Opens Door to POS Malware | Bach Seat","description":"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII","canonical_url":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/","robots":"max-image-preview:large","keywords":"point of sale,malware,apple,microsoft,google,pos,remote desktop,aapl,goog,msft,2014,security","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#article","name":"Remote Desktop Opens Door to POS Malware | Bach Seat","headline":"Remote Desktop Opens Door to POS Malware","author":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"publisher":{"@id":"https:\/\/rbach.net\/#person"},"image":{"@type":"ImageObject","url":"http:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#articleImage"},"datePublished":"2014-08-05T13:17:40-04:00","dateModified":"2021-07-20T11:49:43-04:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#webpage"},"isPartOf":{"@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#webpage"},"articleSection":"Security, 2014, AAPL, Apple, GOOG, Google, Malware, Microsoft, MSFT, Point of sale, POS, Remote Desktop, Security"},{"@type":"BreadcrumbList","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/rbach.net#listItem","position":1,"name":"Home","item":"https:\/\/rbach.net","nextItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","position":2,"name":"Security","item":"https:\/\/rbach.net\/index.php\/category\/security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#listItem","name":"Remote Desktop Opens Door to POS Malware"},"previousItem":{"@type":"ListItem","@id":"https:\/\/rbach.net#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#listItem","position":3,"name":"Remote Desktop Opens Door to POS Malware","previousItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","name":"Security"}}]},{"@type":"Person","@id":"https:\/\/rbach.net\/#person","name":"RB","image":{"@type":"ImageObject","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r","width":96,"height":96,"caption":"RB"}},{"@type":"Person","@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author","url":"https:\/\/rbach.net\/index.php\/author\/administrator\/","name":"RB","image":{"@type":"ImageObject","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r","width":96,"height":96,"caption":"RB"}},{"@type":"WebPage","@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#webpage","url":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/","name":"Remote Desktop Opens Door to POS Malware | Bach Seat","description":"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/rbach.net\/#website"},"breadcrumb":{"@id":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/#breadcrumblist"},"author":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"creator":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"datePublished":"2014-08-05T13:17:40-04:00","dateModified":"2021-07-20T11:49:43-04:00"},{"@type":"WebSite","@id":"https:\/\/rbach.net\/#website","url":"https:\/\/rbach.net\/","name":"Bach Seat","description":"The view from where I am sitting","inLanguage":"en-US","publisher":{"@id":"https:\/\/rbach.net\/#person"}}]},"og:locale":"en_US","og:site_name":"Bach Seat | The view from where I am sitting","og:type":"article","og:title":"Remote Desktop Opens Door to POS Malware | Bach Seat","og:description":"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII","og:url":"https:\/\/rbach.net\/index.php\/remote-desktop-open-door-to-pos-malware\/","og:image":"https:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg","og:image:secure_url":"https:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg","article:published_time":"2014-08-05T17:17:40+00:00","article:modified_time":"2021-07-20T15:49:43+00:00","article:publisher":"https:\/\/www.facebook.com\/ralph.bach.14","twitter:card":"summary","twitter:site":"@rbach48334","twitter:title":"Remote Desktop Opens Door to POS Malware | Bach Seat","twitter:description":"DHS issued an alert that remote desktop software is opening retailers to stealth POS malware attacks to steal credit cards and PII","twitter:creator":"@rbach48334","twitter:image":"http:\/\/rbach.net\/wp-content\/uploads\/all_in_one_pos-150x147.jpg"},"aioseo_meta_data":{"post_id":"71320","title":"#post_title #separator_sa #site_title&nbsp;","description":"#post_excerpt","keywords":[{"label":"Point of sale","value":"Point of sale"},{"label":"Malware","value":"Malware"},{"label":"Apple","value":"Apple"},{"label":"Microsoft","value":"Microsoft"},{"label":"Google","value":"Google"},{"label":"POS","value":"POS"},{"label":"Remote Desktop","value":"Remote Desktop"},{"label":"AAPL","value":"AAPL"},{"label":"GOOG","value":"GOOG"},{"label":"MSFT","value":"MSFT"}],"keyphrases":{"focus":{"keyphrase":"malware","score":100,"analysis":{"keyphraseInTitle":{"title":"Focus Keyphrase in SEO title","description":"Focus Keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseInURL":{"title":"Focus Keyphrase in URL","description":"Focus Keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInSubHeadings":{"title":"Focus Keyphrase in Subheadings","description":"Your H2 or H3 subheading reflects the topic of your copy. Good job!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":"#post_title #separator_sa #site_title","og_description":"#post_excerpt","og_object_type":"article","og_image_type":"content","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":true,"twitter_card":"summary","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","location":null,"local_seo":{"locations":{"business":{"name":"","businessType":"","image":"","areaServed":"","urls":{"website":"","aboutPage":"","contactPage":""},"address":{"streetLine1":"","streetLine2":"","zipCode":"","city":"","state":"","country":"","addressFormat":"#streetLineOne\n#streetLineTwo\n#city, #state #zipCode"},"contact":{"email":"","phone":"","phoneFormatted":"","fax":"","faxFormatted":""},"ids":{"vat":"","tax":"","chamberOfCommerce":""},"payment":{"priceRange":"","currenciesAccepted":"","methods":""}}},"openingHours":{"useDefaults":true,"show":true,"alwaysOpen":false,"use24hFormat":false,"timezone":"","labels":{"closed":"","alwaysOpen":""},"days":{"monday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"tuesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"wednesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"thursday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"friday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"saturday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"sunday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"}}}},"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:53:36","updated":"2022-09-14 16:35:49","seo_analyzer_scan_date":null},"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/71320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=71320"}],"version-history":[{"count":25,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/71320\/revisions"}],"predecessor-version":[{"id":132164,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/71320\/revisions\/132164"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=71320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=71320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=71320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}