Skip to content
SECURITY AUDIT

Kiosk Systems

Kiosk systems are only as secure as their restrictions. Our penetration tests reveal whether the intended kiosk application can be trusted and whether it is possible to gain access to the operating system, data, or internal functions.

Scope of the pentest

In this penetration test, our ethical hackers conduct a targeted analysis of your kiosk systems to identify potential breakout vulnerabilities that could be exploited to bypass application restrictions and gain access to the operating system, file system, or other functions.
The test can be conducted on-site at your location or remotely.

Exemplary test objects:

Windows Kiosk

We check whether it is possible to exit kiosk mode and gain access to Windows features, files, or a shell.

Android Kiosk

We test whether app restrictions can be bypassed to access system functions, data, or other applications.

Embedded Terminal

We analyze local interfaces, system functions, and potential points of exploitation, all the way down to accessing the underlying operating system.

Smart TVs

We check whether the intended interface is reliable and whether it allows access to internal features, apps, files, or network services.

Most kiosk systems are inadequately secured and allow a physical attacker to gain access to the underlying operating system and data. ¹

In many large companies, self-service kiosks, information terminals, or publicly accessible systems are directly available to customers, visitors, or employees. ²

Penetration Test of
Kiosk Systems

Our approach

Kiosk systems and terminals with restricted functionality are designed to limit users to specific functions. At the same time, physical access, operating system functions, connected peripherals, and local interfaces present potential vulnerabilities that can be exploited to circumvent these restrictions.

As part of a kiosk penetration test, we analyze the system from the perspective of an attacker with physical access to the device. The goal is to determine whether a kiosk breakout is possible and whether this would allow access to the underlying operating system, local data, restricted applications, system functions, or connected resources.

The security analysis is conducted primarily manually and is based on realistic attack scenarios. Among other things, we examine accessible operating system functions, typical kiosk breakout techniques, peripheral interfaces, local misconfigurations, hidden system functions, and potential paths for privilege escalation.

kiosk

The specific devices, interfaces, and attack scenarios to be tested will, of course, be coordinated with you in advance. Depending on the system, we will examine, for example, kiosk breakout possibilities, local permissions, connected peripherals, operating system functions, and methods for privilege escalation. If you are interested, feel free to request further details or create a non-binding quote using our configurator.

Standards and Qualifications

We follow recognized international standards for our pentest procedure.

Our penetration testers are highly qualified and certified with several recognized hacking certificates.

Sources

1 - Own Statistic
2 - Own Statistic