Saltar al contenido
02 · Auditoría02 · Auditing

Pentest de ATM, POS y Switch TransaccionalATM, POS and Transaction Switch Penetration Testing

Cajeros, terminales de punto de venta y conmutador de transacciones.Cash machines, point of sale terminals and transaction switch.

PCI-DSS · PCI PINPCI-DSS · PCI PIN 2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

¿Qué es este servicio?What is this service?

Es la evaluación de seguridad de la infraestructura de pagos: cajeros automáticos, terminales de punto de venta y el conmutador que enruta las transacciones entre ellos y el core bancario.

A security assessment of payment infrastructure: automated teller machines, point of sale terminals and the switch routing transactions between them and the banking core.

¿Para qué se usa?What is it used for?

Sirve porque en esta infraestructura un fallo se traduce en pérdida directa de dinero, no en un riesgo abstracto. Se revisa la seguridad física del cajero, el sistema operativo que lo controla, el cifrado del PIN de punta a punta, la validación de mensajes en el conmutador y la posibilidad de alterar o repetir una transacción.

It matters because here a flaw translates into direct monetary loss, not an abstract risk. It reviews the ATM's physical security, the operating system controlling it, end-to-end PIN encryption, message validation at the switch and the ability to alter or replay a transaction.

Qué beneficios traeBenefits it delivers

  • Encuentra fallos con impacto económico inmediato y cuantificable, que es un argumento fácil para la dirección.
  • Revisa el conmutador transaccional, que suele quedar fuera de los pentest normales por miedo a tocarlo.
  • Verifica el cifrado del PIN en todo el recorrido, que es donde se concentran los requisitos de las marcas.
  • Cubre el vector físico del cajero, que es real y que un pentest de red no ve.
  • Finds flaws with immediate, quantifiable financial impact, an easy argument for management.
  • Reviews the transaction switch, usually left out of normal testing for fear of touching it.
  • Verifies PIN encryption across the whole path, where the brands' requirements concentrate.
  • Covers the ATM's physical vector, which is real and which a network test never sees.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • Aplica a bancos, procesadores y adquirentes costarricenses por vía contractual con las marcas de pago.
  • Para entidades supervisadas se suma al marco de riesgo tecnológico del Acuerdo CONASSIF 5-24.
  • It applies to Costa Rican banks, processors and acquirers through their contracts with the payment brands.
  • For supervised entities it adds to the technology risk framework of CONASSIF Agreement 5-24.

InternacionalInternational

  • PCI-DSS aplica a todo el entorno que almacene, procese o transmita datos de tarjeta, y el conmutador está de lleno dentro.
  • Existen estándares específicos del ecosistema de pagos para la gestión del PIN y de los dispositivos de captura.
  • Las marcas de pago imponen requisitos propios a los adquirentes y procesadores.
  • PCI-DSS applies to any environment storing, processing or transmitting card data, and the switch is squarely inside it.
  • There are dedicated payment ecosystem standards for PIN management and capture devices.
  • Payment brands impose their own requirements on acquirers and processors.

Requisitos mínimosMinimum requirements

  • Autorización por escrito y coordinación con operaciones, porque un cajero fuera de servicio afecta a clientes reales.
  • Un equipo de laboratorio o una ventana en un cajero fuera de servicio: no se prueba contra un cajero en operación.
  • Diagramas del flujo transaccional y del conmutador.
  • Coordinación con el fabricante cuando el equipo esté bajo garantía o soporte.
  • Written authorisation and coordination with operations, since an out-of-service ATM affects real customers.
  • A lab unit or a window on a decommissioned ATM: testing is not done against a live machine.
  • Transaction flow and switch diagrams.
  • Coordination with the manufacturer where the equipment is under warranty or support.

Plazo típico de entregaTypical delivery time

3 a 6 semanas 3 to 6 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de tres a seis semanas. La disponibilidad del equipo de laboratorio es casi siempre el cuello de botella: conseguir un cajero fuera de servicio para pruebas puede tomar más tiempo que las pruebas mismas.

The usual market range runs from three to six weeks. Lab equipment availability is almost always the bottleneck: getting a decommissioned ATM for testing can take longer than the testing itself.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

ATMATM
Cajero automático. Automated teller machine.
POSPOS
Terminal de punto de venta, el dispositivo donde el cliente pasa la tarjeta. Point of sale terminal, the device where the customer presents the card.
Switch transaccionalTransaction switch
Sistema que enruta y autoriza las transacciones entre los terminales y el core bancario. The system routing and authorising transactions between terminals and the banking core.
HSMHSM
Módulo de seguridad de hardware: equipo dedicado que custodia las claves criptográficas y opera con el PIN. Hardware security module: dedicated equipment safeguarding cryptographic keys and handling PIN operations.
JackpottingJackpotting
Ataque que hace que un cajero dispense efectivo sin una transacción legítima detrás. An attack making an ATM dispense cash without a legitimate transaction behind it.
PentestPentest
Prueba de intrusión: se ataca el sistema con autorización previa y por escrito, para encontrar lo que encontraría un atacante real. Penetration test: the system is attacked with prior written authorisation, to find what a real attacker would find.
RoERoE
Reglas de compromiso: el documento que define qué se puede atacar, cuándo, con qué técnicas y a quién avisar. Rules of Engagement: the document defining what may be attacked, when, with which techniques and who to notify.
MITRE ATT&CKMITRE ATT&CK
Base de conocimiento pública de tácticas y técnicas usadas por atacantes reales. Public knowledge base of tactics and techniques used by real attackers.