{"id":69737,"date":"2026-09-15T12:32:05","date_gmt":"2026-09-15T10:32:05","guid":{"rendered":"https:\/\/www.usd.de\/?p=69737"},"modified":"2026-09-18T12:46:59","modified_gmt":"2026-09-18T10:46:59","slug":"point-of-sale-pentest","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/point-of-sale-pentest\/","title":{"rendered":"POS System Pentesting: Can a Checkout Become an Entry Point into the Corporate Network?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Today, POS systems are directly connected to business processes, payment services, and corporate networks. If a POS system is compromised, the impact can extend far beyond the individual device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/www.usd.de\/en\/pentest\/\">pentest<\/a> of POS systems and kiosk applications, therefore, does not only examine the visible application. It also looks at the underlying operating system, potential privilege escalation paths, physical interfaces, and the question of what impact a successful compromise could have on connected systems.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Why POS Systems Are More Than Just Checkouts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At first glance, many POS systems appear highly restricted. Only the functions required for the respective use case are visible. In the background, however, these systems often access product databases, communicate with payment service providers, exchange data with backend systems, or are connected to corporate domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What may initially appear to be a standalone system is often part of an infrastructure with numerous connections to other applications and systems.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The First Step: Breaking Out of Kiosk Mode<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A central part of many pentests is checking the kiosk mode. The objective is to determine whether the intended restrictions can be bypassed and whether additional system functions become accessible as a result.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, however, we repeatedly see that such restrictions can be bypassed. Potential entry points include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Unlocked keyboard shortcuts<\/li>\n\n\n\n<li>Incorrect input that puts the application into an unexpected state<\/li>\n\n\n\n<li>Insufficiently secured operating system functions<\/li>\n\n\n\n<li>Applications or tools that are not required for operation, such as terminal emulators or administration tools<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A pentest does not only examine whether such a breakout is possible. It also assesses which additional access and escalation options could result from it.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Often Underestimated Risk of Physical Attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">POS systems differ from many other corporate systems because of where they are used. They are often located in places where many people move freely every day and can interact with them directly, such as self-checkout terminals, ticket machines, or other self-service systems. Unlike traditional endpoint devices, they are often placed in publicly accessible areas and are not permanently supervised. This creates potential entry points that are not relevant for many other corporate systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is precisely the combination of physical access and network connectivity that makes these systems attractive to attackers. Security measures that are standard in data centers or office environments cannot always be implemented in the same way at a self-service checkout.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is why pentests also examine a system\u2019s physical attack surface. This includes, among other things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>USB ports<\/li>\n\n\n\n<li>Ethernet ports<\/li>\n\n\n\n<li>Service and maintenance interfaces<\/li>\n\n\n\n<li>BIOS and boot configurations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If these components are not sufficiently secured, they can create additional entry points or bypass existing security measures. In our pentests, we repeatedly see that unprotected USB ports or maintenance interfaces alone can be enough to bypass existing safeguards.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Access to the Operating System Is Not the End of the Attack<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For attackers, access to the operating system is often only the first step. They then frequently try to escalate their privileges and gain access to additional resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The techniques used for this often differ only slightly from attacks in traditional Windows environments. Vulnerabilities in the operating system, insecure configurations, or overprivileged user accounts can help attackers expand their options.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, operating system hardening also plays an important role for POS systems. A securely configured kiosk mode alone is not enough if attackers can gain additional privileges in other ways.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">From the POS System into the Corporate Network<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The situation becomes particularly critical when POS systems are directly connected to a corporate network, are part of a corporate domain, or have extensive network connections. In such scenarios, a compromised POS system can become the starting point for further attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If these systems are not sufficiently segmented, other systems may be reachable from there. These include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>other POS systems<\/li>\n\n\n\n<li>backend systems<\/li>\n\n\n\n<li>databases<\/li>\n\n\n\n<li>employee endpoints<\/li>\n\n\n\n<li>server infrastructures<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In the worst case, attackers move step by step through the environment and continue to extend their privileges. As a result, an incident that starts at a single checkout can affect significantly larger parts of the infrastructure. This means that not only IT systems may be impacted, but also the business processes that depend on them.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\"When performing pentests of POS systems, we do not only look at the kiosk application itself. It usually becomes most interesting when we consider the entire system environment. This is where we often see what impact a compromise could actually have. Companies gain a sound basis for assessing risks and prioritizing security measures.\"<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>Samir Benzammour, Senior Consultant IT Security, usd AG<\/em><\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/Samir-Benzammour-1024x1024.png\" alt=\"\" class=\"wp-image-66541\" style=\"width:180px;height:auto\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Why Kiosk Pentests and Active Directory Pentests Belong Together<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">POS systems are usually connected to a domain on-site, allowing administrators and service providers to maintain and update the systems remotely. However, this connection also introduces risks. If attackers manage to compromise a POS system, they may also gain additional permissions within the domain, significantly expanding the potential attack surface. A pentest of the POS system shows whether the device can be abused as an entry point and what attack vectors are associated with it. An <a href=\"https:\/\/www.usd.de\/en\/pentest\/active-directory-pentest\/\">Active Directory Pentest<\/a>, on the other hand, assesses what impact such an entry point could have within the corporate environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among other things, this includes analyzing trust relationships, permissions, and misconfigurations within the domain. Only the combination of both security analyses provides a holistic view of the risks and their potential impact on the company.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Which Measures Often Improve POS System Security?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The results of a pentest usually provide specific guidance on how to secure the systems. The objective is not only to prevent a breakout from kiosk mode but also to limit the impact of a possible compromise. A pentest is particularly useful when POS systems are publicly accessible, for example, as self-checkout solutions or kiosk applications, communicate with additional backend systems or are directly integrated into corporate networks and Active Directory environments. Common measures include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>consistent restriction of kiosk mode<\/li>\n\n\n\n<li>deactivation of functions and applications that are not required<\/li>\n\n\n\n<li>protection of physical interfaces<\/li>\n\n\n\n<li>minimum user privileges<\/li>\n\n\n\n<li>operating system hardening<\/li>\n\n\n\n<li>network segmentation and the most restrictive domain connection possible<\/li>\n\n\n\n<li>secure update and maintenance processes<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Which measures are appropriate depends on the specific system landscape and the risks identified. The objective should always be to reduce the attack surface as much as possible. POS systems should therefore not be considered trusted by default. They should only be able to access the systems and resources that are actually required for their operation.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Looking Beyond the Checkout<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Modern POS systems, self-checkout solutions, and kiosk applications are no longer isolated devices. Their security, therefore, often affects much more than a single sales or service process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, a pentest of POS systems is often not only about uncovering individual vulnerabilities. Rather, it provides the basis for making informed decisions on how to secure POS systems and the systems connected to them.<\/p>\n\n\n\n<div style=\"height:5px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"wp-block-paragraph\">Looking to assess the potential impact of a compromised POS system on your IT environment? <a href=\"https:\/\/www.usd.de\/en\/contact-form-analysis-pentests\/\">Contact us<\/a>, and together we will determine which approaches are right for you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, POS systems are directly connected to business processes, payment services, and corporate networks. If a POS system is compromised, the impact can extend far beyond the individual device. A pentest of POS systems and kiosk applications, therefore, does not only examine the visible application. It also looks at the underlying operating system, potential privilege [&hellip;]<\/p>\n","protected":false},"author":112,"featured_media":69729,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[373,374,10757],"tags":[10460,15228,15229,15234,15235,15230,378,15232,15233,15231],"class_list":["post-69737","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en","category-pentests-security-analyses-en","category-usd-herolab-en","tag-active-directory-en","tag-kassen-pentest","tag-kassensysteme","tag-kiosk-application-security","tag-kiosk-applications","tag-kioskanwendungen","tag-pentest-en","tag-point-of-sale-pentest","tag-pos-pentest","tag-pos-security"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/69737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/112"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=69737"}],"version-history":[{"count":3,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/69737\/revisions"}],"predecessor-version":[{"id":69741,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/69737\/revisions\/69741"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/69729"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=69737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=69737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=69737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}