prof.apokalips

POS Environment and EFT Terminal Penetration Testing Checklist

This checklist for high-level test focus areas and can be used necessarily for test planning.

Focus Area 1 - Test reading of card in EFT Terminal

Focus Area 2 - Information from the EFT device

Recommendation is to do this test as the last test to not break the terminal.

Focus Area 3 - Connections on the EFT device

Focus Area 4 – Connection between EFT and ECR

Focus Area 5 – Data stored in memory & storage on the ECR

Focus Area 6 – Data transferred to and from the EFT server

Man in the middle. Note, do not perform any test against the host.

BACK