Command Injection Tops List of Retail Attack Vectors | Internet News

Command Injection Tops List of Retail Attack Vectors

Jan 7, 2015
1 minute read

Point-of-sale (PoS) malware is not the leading cause of retail security incidents, according to IBM. While the U.S. Secret Service believes more than 1,000 retailers have been infected by PoS malware such as Backoff malware, IBM found that command injection vulnerabilities were the leading root cause of retail security incidents in 2014. Retailers reported approximately 6,000 command injection incidents in 2014.

Kuhn told eSecurityPlanet that command injection attacks work against Web applications rather than databases.

“Essentially Shellshock was a command injection. It’s simply injecting shell commands into a Web application with the hope that the backend system will execute the instructions,” Kuhn said. “An attacker would be looking for a flaw on the retailer’s website to accomplish the attack, normally targeting PHP and CGI-based applications.”

Read the full story at eSecurity Planet:
Black Friday Cyber Attacks Declined in 2014

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.