The new generation of EMV skimming device

Magseek

New Member
Registered User
Joined
Jul 22, 2018
Messages
7
Likes
6
Points
3
Age
62
I’ll start by explaining at a high level how an EMV transaction is process. The reason I explain this is so you know how we can extract the data. I am simplifying it so that I don’t lose everyone with technical details, for those of you who would like to go more technical, let me know and if enough people ask for it I’ll write something.

Overview of a transaction
The transaction starts after the user of the POS has enter the amount and gives the POS to the cardholder that insert his card into it. The sequence goes as follow:

Power up
The POS will power the chip card (Important because we will use this power for our device, no battery needed)

Answer To Reset - ATR
The Card responds with ATR which is a number telling the POS what kind of card has been inserted

AID
As you may know each POS supports predefine cards that some of you refer as BIN. In MSR transaction the BIN was use to know where to forward the transaction, with EMV each card supports one or more “application” or software. Each of these applications has an Application ID or AID, if you look on an EMV receipt you will see which AID on the card was used to process the transaction something like “A0000000041010” which is the Mastercard AID. So POS looks at AID available on the cards and selects the one that is compatible.

Application Records
The POS will then read records of data associated with the AID selected, the data contain in these records contain (but not limited to) the Cardholder verification methods (CVM or EMV tag 8E) this tells the POS what method of cardholder verification should be use.

Some other data read is the Track 2 equivalent data (EMV Tag 57) this represent half of what we are extracting.

Pin Validation
I am skipping some steps in transaction that are irrelevant for explaining the device.
On most POS device the PIN is validated by the card itself, on ATM and unattended devices (kiosk, gas pump) the PIN is validated online. IMPORTANT the device only works on standard POS.
So at this point the POS will issue a Verify command to the card with the PIN, (second and last part of information that we extract), the card will respond and continue the transaction if the PIN is valid.

The rest of the transaction is irrelevant to us, we have all what we need.

How it works
The device is built on a flexible PCB of 100 µm thickness, it is inserted the first time in the POS with your card on a regular transaction. When you remove your card the PCB will stay in place because of an adhesive. So from now on whenever you insert a card in the POS our circuit is between the card and the reader, this means that all communication between POS and card are going thru it.
We just listen on the communication for the TAG 57 (track 2) and pin validation (PIN) and keep those values. Since we had to keep the circuit VERY small we can only store 75 to 90 combination of track/PIN. To extract the data, we use Bluetooth with an Android app. You just have to be in Bluetooth range when a card is inserted in the POS (because of power) to receive all the data and go back whenever you need more…
 

Dixkhead20

New Member
Registered User
Joined
Jun 28, 2018
Messages
9
Likes
0
Points
1
Age
35
I really don't undastand de abbreviations and terminologies used in here bt im very interested in it since its 4 knowledge purpose. Pls help me undastand n wat ma work shud b in dis tank u
 

Magseek

New Member
Registered User
Joined
Jul 22, 2018
Messages
7
Likes
6
Points
3
Age
62
POS - Point of Sale or the terminal you insert your card into
EMV - ( eurocard - visa -Mastercard ) chip card protocol for payment
ATR - Answer To Reset - the response the card sends to the terminal when inserted
AID - Application identifier a number associated with each aquirer card software
CVM - Cardholder verification Method, how the terminal should identify the cardholder (Offline plaintext PIN, Online PIN,Offline plaintext PIN and signature,Offline enciphered PIN,Offline enciphered PIN and signature,Signature,No CVM performed)
PCB - Printed circuit board

As for your work in this, everything is already done and working, as you say it is for general knowledge
 

Dixkhead20

New Member
Registered User
Joined
Jun 28, 2018
Messages
9
Likes
0
Points
1
Age
35
Im grateful for ur sacsint n precise explantion buddy tumbs up for this knowledge

Pls I want to knw the meaning of skimming n

Secondly how how do I possess the device. Tanks Buddy
 

Magseek

New Member
Registered User
Joined
Jul 22, 2018
Messages
7
Likes
6
Points
3
Age
62
If you want more info contact me ICQ- 682163935
 

Reahat

New Member
Registered User
Joined
Jul 28, 2019
Messages
1
Likes
0
Points
0
Age
38
CONTACT ME HERE

ICQ: @748368604
TELEGRAM: DarthMaul05
 
Top Bottom