0x00 - Sandbox Escape in Point of Sale (POS)
0x00 - Sandbox Escape in Point of Sale (POS)
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
A point of sale (POS) is the hardware merchants use to process payments and complete customer purchases.
Modern POS systems run on tablets using a kiosk (restricted) mode such that users cannot interact with other features (i.e.: other apps)
One way to escape the restricted mode is to find a link in the available application which will redirect you to another app - in this case the browser or App store.
Once that is achieved, you can navigate to a malicious application that you are hosting on the internet or install an APK that will trick the users into entering their credit card information (skimming).