• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

Hacker spent only $10, ATM hacked spewed million$ non-stop

Ass_Loong_Son

Alfrescian
Loyal
http://www.pcworld.com/businesscent...rn_from_the_black_hat_atm_hack.html?tk=hp_blg


Security July 29, 2010 10:06 AM
Important Lessons to Learn from the Black Hat ATM Hack



By Tony Bradley, PC World

A security researcher named Barnaby Jack amazed attendees at the Black Hat security conference by hacking ATM machines in a session titled "Jackpotting Automated Teller Machines Redux". There are some important lessons to be learned from the hacks Jack demonstrated, and they apply to more than just ATM machines.


Barnaby Jack dazzled Black Hat in a session called Jackpotting Automated Teller Machines Redux"Jack's exploits--one involving physical access to the ATM machine using a master key available online, and the other dialing in remotely to gain access--focused on ATM machines from Triton and Tranax. However, the issue is not necessarily limited to these two. Jack explained to his audience that he has yet to find an ATM machine that he couldn't crack and retrieve cash from.

It's an impressive hack. Who wouldn't like to just walk up to an ATM machine and cause it to spew money as if you'd hit the jackpot on a Vegas slot machine? But, most businesses don't own ATM machines, so why should IT admins care about the ATM hack?

The answer is that it's not just about ATM machines. The ATM machine is just one sensational example of poor physical security combined with poor digital security on a legacy or niche platform. Computers are everywhere, but many of them are not monitored for security issues or updated on a regular basis to protect them.

Toralv Dirro, a security researcher with McAfee, explained in a blog post "Most people tend to ignore the fact that a lot of today's devices and machines are running fairly standard computers and operating systems internally. ATM machines, cars, medical devices, even your TV may have such a computer inside, allowing updates over a network. Software unfortunately has flaws."

Dirro goes on to explain that the more complex the system is, the more likely it is to have flaws that can be discovered and exploited given enough time. Many of these systems--particularly systems such as the software running the ATM machine at the corner gas station--are fairly complex and need to be periodically updated to ensure they are secure and protected.

There are also national security implications. Many of the utilities like water and electricity, chemical processing plants, manufacturing facilities, trains and subways, and other elements of the critical infrastructure that form the backbone of productivity, commerce and security for the country rely on archaic, legacy systems that are not frequently updated, yet likely have exploitable holes for an attacker that looks hard enough.

To make matters worse, many of these systems were originally standalone, but have been connected to the Internet over time, making it possible to access and exploit them remotely. The ATM machine hack demonstrates the need to provide better security for these systems.

It is unrealistic to expect these legacy and niche systems to be constantly updated. Running firewalls or common antimalware protection is also highly impractical. However, as Dirro points out, "the future is in using Application Control, Configuration Control and Change Control to lock down those systems, so you can still make authorized updates and changes but not run unauthorized code from an attacker."
 

Ass_Loong_Son

Alfrescian
Loyal
Lets have it at all our Singapore Casinos! Hackpot!

Master key cost only $10 ordered on the internet.

USB thumb drive stores the hackers program tool.

Walk up to the ATM, open it with the key, plug in the USB Thumb Drive, and the ATM spew $million$ non-stop!

:biggrin::biggrin::biggrin::biggrin:


http://blogs.pcmag.com/securitywatch/2010/07/atm_hacking_demo_a_hit_at_blackhat.php


Thursday July 29, 2010
ATM Hacking Demo a Hit at BlackHat


atmhack-thumb-450x251-13945.jpg


Researcher Barnaby Jack at the Black Hat Briefings in Vegas has demonstrated research he has done into attacking ATMs (automated teller machines).

He showed two attacks. In the first he simply walks up to the ATM and opens it; they use master keys for the convenience of maintenance and filling. He then attaches a USB device to it to install code and restart it. In the second he remotely bypasses authentication to the ATM over the network (I'm not sure how he got on the network with the ATM, but it's a relatively small point). He then remotely installs a rootkit which gives him complete control he can exercise either over the network or by entering a special code on the machine or swiping a special card. And for good measure, the rootkit can capture all card swipes and PINs and feed them back to a command and control server.

atmhack.jpg

There probably are many better-defended ATMs out there, but there are likely many cheap, sloppy ones as well. Click here for one of many poor-quality videos of the ATM hack on YouTube.
 

Ass_Loong_Son

Alfrescian
Loyal
http://tw.news.yahoo.com/article/url/d/a/100730/8/2a6h0.html


美專家破解示範 ATM瘋狂吐鈔
TVBS 更新日期:"2010/07/30 11:42"

提款機有可能不需要密碼,就能瘋狂吐出現鈔嗎?美國一名資訊安全公司的主管,花了2年時間研究,找出ATM提款機的漏洞,他先是在網路上,花10美元買了一把鑰匙,打開提款機,插入他所寫的破解程式,白花花的鈔票,立刻一張張乖乖吐出來,讓看到這一幕的人,驚呼實在太神奇了。

伴隨著音樂聲,ATM狂吐鈔票,這不是哪個大戶在領錢,而是資訊安全專家示範,如何侵入ATM盜領現金,現場一片驚呼。

一年一度的Black Hat「黑帽」,電腦安全會議上,這位叫傑克的男子,花了2年時間破解ATM,找出入侵漏洞,發表大會上,傑克搬來了2台提款機實際操作,他用了一把網路上買來的10美元鑰匙,就能輕鬆打開這2款ATM,然後插入寫有破解程式的隨身碟,ATM就開始狂吐鈔。

傑克還秀了另一種,用遙控方式,照樣能讓ATM乖乖聽話。ATM破解人傑克:「所以這些都是,總計1百萬的鈔票。」

雖然沒有詳細的說明,到底是如何破解,但是傑克聲稱他,可以百分之百破解ATM,隨處可見的提款機,已經成了民眾生活中,不可或缺的一部分,電腦安全會議希望,能提醒提款機製造商和銀行,重視ATM的保全問題。
 
Top