Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > Can you suggest tools to detect Bluetooth-based card-skimming devices?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Can you suggest tools to detect Bluetooth-based card-skimming devices?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Wireless networks news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 22 July 2007

Can you suggest tools to detect Bluetooth-based card skimming devices?


>
EXPERT RESPONSE

Credit or ATM card skimming occurs during a legitimate payment transaction, when someone handling your card takes the opportunity to surreptitiously swipe the card's magnetic strip, then visually observe the PIN you enter into a point-of-sale device. It may also happen when an imposter device (e.g., a phony ATM machine) is used to trick you into swiping your card, perhaps accompanied by a pinhole camera used to record PIN entry. There are two ways that Bluetooth can enter this picture:

  • Some mobile point-of-sale terminals swipe cards in the usual fashion, but then transmit that payment data over wireless to a nearby Bluetooth access point. If a payment transaction were to be conducted without Bluetooth or higher-layer encryption (e.g., SSL), card data sent over Bluetooth might be eavesdropped upon.
  • Some "contactless" payment systems use mobile phones with Bluetooth technology to conduct purchases over wireless without physically swiping a credit card. In this case, an unsecured or vulnerable Bluetooth interface might be exploited to grab ("snarf") stored card data from the mobile phone.

Neither threat appears to be common. A merchant using a Bluetooth point of sale terminal should encrypt anything sent over wireless, and most new contactless payment systems use RFID rather than Bluetooth. Merchants might still be concerned about fraudulent card readers that use Bluetooth to upload skimmed data for storage/use elsewhere. But in all cases, there are tools that could alert you to the repeated/frequent presence of the same, unknown, rogue Bluetooth device.

One way to detect Bluetooth rogues is to run a Bluetooth discovery program on a laptop. For example, freely-available Bluetooth scanners for Windows XP are available from AirMagnet and Network Chemistry. However, like Wi-Fi stumblers, these discovery programs just periodically sample the airwaves. Continuous Bluetooth rogue detection over a larger area requires a Bluetooth-aware IDS solution like Red-M's Red-Alert PRO.

Bear in mind that plenty of unknown Bluetooth devices will probably come and go over time, as strangers carrying Bluetooth phones and Bluetooth headsets and other Bluetooth peripherals pass through any business establishment. However, Bluetooth discovery and IDS tools can help you spot an unknown Bluetooth device that always seems to be hanging around, and help you determine the type of device and its approximate location.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
Can you create a persistent wireless connection to a wired LAN?
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
What can we expect in an 802.11n Wireless LAN standard implementation?
Can 802.11 protocols be used with GPRS connectivity?
Next generation wireless local area networks'(WLANs) important features
My wireless laptop connectivity disconnected once I downgraded my OS
How to debug poor WLAN performance
How to know if you're connecting to fake or real access points (APs)
NAC solution authentication fix for your wireless network
What is the difference between a GRE tunnel and IPsec tunnel?

Wireless Security
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Wireless hot spot security -- podcast
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works
Will WPA2-PSK keep wireless networks safe from war drivers?
How to know if you're connecting to fake or real access points (APs)
Wireless network security made easy - from "The Book of PF"
Will 802.11n WAPs we purchase today be compatible with NAC?
Wireless network security: Controlling secondary connections
How do we control who gets our wireless network's free Internet access?

Wireless Network Security
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Wireless hot spot security -- podcast
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works
Will WPA2-PSK keep wireless networks safe from war drivers?
How to know if you're connecting to fake or real access points (APs)
NAC solution authentication fix for your wireless network
Wireless network security made easy - from "The Book of PF"
How do I troubleshoot wireless access points (APs) losing connectivity?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts