Quantcast
Article Index |Advertise | Mobile | RSS | Wireless | Newsletter | Archive | Corrections | Syndication | Contact us | About Us| Services
 
  Breaking News :    
Advertisement
Inquirer Mobile
Property Guide

INQUIRER ALERT
Get the free INQUIRER newsletter
Enter your email address:

 
Breaking News / Infotech Type Size: (+) (-)
You are here: Home > News > Breaking News > Infotech

  ARTICLE SERVICES      
     Reprint this article     Print this article  
    Send Feedback  
    Post a comment   Share  

  RELATED STORIES  




imns



Hack attack hits ATM jackpots


Agence France-Presse
First Posted 06:31:00 08/01/2010

Filed Under: Internet, Banking, Software, Crime and Law and Justice

LAS VEGAS, Nevada, United States? Computer security researcher Barnaby Jack jokes that he has resorted to hiding cash under his bed since figuring out how to crack automated teller machines remotely using the Internet.

The New Zealand native on Saturday demonstrated his "ATM jackpotting" discovery for an overflow crowd of hackers during a presentation at the infamous DefCon gathering in Las Vegas.

"You don't have to go to the ATM at all," Jack told AFP after briefing fellow software savants. "You can do it from the comfort of your own bedroom."

Jack proved his findings using two kinds of ATMs typically found in corner stores, bars, or other "stand-alone" venues in the United States but said the flaw likely exists in machines at banks.

Banks use "remote management" software to monitor and control their ATMs, and Jack used a weakness in that kind of code to take control of machines by way of the Internet.

He found a way to bypass having to submit passwords and serial numbers to access ATMs remotely. Once in the machines, he could command them to spit out cash or transfer funds.

He could also capture account data from magnetic strips on credit or bank cards as well as passwords punched in by ATM users.

"When you think about ATM security you generally think about the hardware side; is it bolted down and are the cameras in position," Jack said.

"This is the first time anyone has taken the approach of trying to attack the underlying software. It is time to find software defenses rather than hardware defenses."

Jack did his research on ATMs he bought on the Internet. He also found master keys for stand-alone machines available for purchase online, meaning hackers could walk up and tinker with ATM software, he added.

"We shouldn't dwell on the walk-up attack, because no physical access is required," Jack said. "They have a flaw that lets me bypass all authentication on the device on the Internet, and I am the ATM at that stage."

He didn't reveal specifics of the attack to hackers even though the ATM makers were told of the flaw and have bolstered machine defenses.

"I might get my butt in hot water if I released the code," said the IO Active software security researcher who did the ATM hack ?as a hobby.?

"I was careful not to release the keys to the kingdom."

Jack said he doesn't know if criminals have exploited the software flaw "in the wild" but that it is tough to be certain.

"It is not an easy attack to replicate but I am not naive enough to think I am the only one who can do it," Jack said, admitting he has grown wary of ATMs. "I just keep my cash under the bed now, mate."



Copyright 2012 Agence France-Presse. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.



Share

RELATED STORIES:

OTHER STORIES:



  ^ Back to top

© Copyright 2001-2012 INQUIRER.net, An INQUIRER Company

The INQUIRER Network: HOME | NEWS | SPORTS | SHOWBIZ & STYLE | TECHNOLOGY | BUSINESS | OPINION | GLOBAL NATION | Site Map
Services: Advertise | Buy Content | Wireless | Newsletter | Low Graphics | Search / Archive | Article Index | Contact us
The INQUIRER Company: About the Inquirer | User Agreement | Link Policy | Privacy Policy

Advertisement
Megaworld
TAGAYTAY FONTAINE VILLAS
Radio on Inquirer.net
Pacquiao