Global pressure mounts on Israel as Gaza death toll surges, war deepens    Egypt targets 7.7% AI contribution to GDP by 2030: Communications Minister    Irrigation Minister highlights Egypt's water challenges, innovation efforts at DAAD centenary celebration    Egypt discusses strengthening agricultural ties, investment opportunities with Indian delegation    Al-Sisi welcomes Spain's monarch in historic first visit, with Gaza, regional peace in focus    Cairo governor briefs PM on Khan el-Khalili, Rameses Square development    El Gouna Film Festival's 8th edition to coincide with UN's 80th anniversary    Egypt's gold prices fall on Wednesday    Egypt expands medical, humanitarian support for Gaza patients    Egypt condemns Israeli offensive in Gaza City, warns of grave regional consequences    Cairo University, Roche Diagnostics inaugurate automated lab at Qasr El-Ainy    Egypt investigates disappearance of ancient bracelet from Egyptian Museum in Tahrir    Egypt launches international architecture academy with UNESCO, European partners    Egypt signs MoUs with 3 European universities to advance architecture, urban studies    Egypt's Sisi, Qatar's Emir condemn Israeli strikes, call for Gaza ceasefire    Egypt condemns terrorist attack in northwest Pakistan    Egyptian pound ends week lower against US dollar – CBE    Egypt hosts G20 meeting for 1st time outside member states    Egypt to tighten waste rules, cut rice straw fees to curb pollution    Egypt seeks Indian expertise to boost pharmaceutical industry    Egypt prepares unified stance ahead of COP30 in Brazil    Egypt harvests 315,000 cubic metres of rainwater in Sinai as part of flash flood protection measures    Al-Sisi says any party thinking Egypt will neglect water rights is 'completely mistaken'    Egyptian, Ugandan Presidents open business forum to boost trade    Egypt's Sisi, Uganda's Museveni discuss boosting ties    Egypt's Sisi warns against unilateral Nile measures, reaffirms Egypt's water security stance    Greco-Roman rock-cut tombs unearthed in Egypt's Aswan    Egypt reveals heritage e-training portal    Sisi launches new support initiative for families of war, terrorism victims    Egypt expands e-ticketing to 110 heritage sites, adds self-service kiosks at Saqqara    Palm Hills Squash Open debuts with 48 international stars, $250,000 prize pool    On Sport to broadcast Pan Arab Golf Championship for Juniors and Ladies in Egypt    Golf Festival in Cairo to mark Arab Golf Federation's 50th anniversary    Germany among EU's priciest labour markets – official data    Paris Olympic gold '24 medals hit record value    A minute of silence for Egyptian sports    Russia says it's in sync with US, China, Pakistan on Taliban    It's a bit frustrating to draw at home: Real Madrid keeper after Villarreal game    Shoukry reviews with Guterres Egypt's efforts to achieve SDGs, promote human rights    Sudan says countries must cooperate on vaccines    Johnson & Johnson: Second shot boosts antibodies and protection against COVID-19    Egypt to tax bloggers, YouTubers    Egypt's FM asserts importance of stability in Libya, holding elections as scheduled    We mustn't lose touch: Muller after Bayern win in Bundesliga    Egypt records 36 new deaths from Covid-19, highest since mid June    Egypt sells $3 bln US-dollar dominated eurobonds    Gamal Hanafy's ceramic exhibition at Gezira Arts Centre is a must go    Italian Institute Director Davide Scalmani presents activities of the Cairo Institute for ITALIANA.IT platform    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Bunker-busting ATM attacks show security holes
Published in Daily News Egypt on 29 - 07 - 2010

LAS VEGAS: A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.
The attacks demonstrated Wednesday targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks.
Criminals have long known that ATMs aren't tamperproof.
There are many types of attacks in use today, ranging from sophisticated to foolhardy: installing fake card readers to steal card numbers, hiding tiny surveillance cameras to capture PIN codes, covering the dispensing slot to intercept money and even hauling the ATMs away with trucks in hopes of cracking them open later.
Computer hacker Barnaby Jack spent two years tinkering in his Silicon Valley apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.
His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.
He showed off his results here at the Black Hat conference, an annual gathering devoted to exposing the latest computer-security vulnerabilities.
His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.
His talk was one of the conference's most widely anticipated, as it had been pulled a year ago over concerns that fixes for the ATMs wouldn't be in place in time. He used the extra year to craft more dangerous attacks.
Jack, who works as director of security research for Seattle-based IOActive Inc., showed in a theatrical demonstration two ways he can get ATMs to spit out money:
— Jack found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer.
He figured this out by ordering three ATMs from different manufacturers for a few thousand dollars each. Then he compared the keys he got to pictures of other keys, found on the Internet.
He used his key to unlock a compartment in the ATM that had standard USB slots. He then inserted a program he had written into one of them, commanding the ATM to dump its vaults.
— Jack also hacked into ATMs by exploiting weaknesses in the way ATM makers communicate with the machines over the Internet. Jack said the problem is that outsiders are permitted to bypass the need for a password.
He didn't go into much more detail because he said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes."
The remote style of attack is more dangerous because an attacker doesn't need to open up the ATMs.
It allows an attacker to gain full control of the ATMs. Besides ordering it to spit out money, attackers can silently harvest account data from anyone who uses the machines.
It also affects more than just the standalone ATMs vulnerable to the physical attack; the method could potentially be used against the kinds of ATMs used by mainstream banks.
Jack said he didn't think he'd be able to break the ATMs when he first started probing them.
"My reaction was, 'this is the game-over vulnerability right here,'" he said of the remote hack. "Every ATM I've looked at, I've been able to find a flaw in. It's a scary thing."
Kurt Baumgartner, a senior security researcher with antivirus software maker Kaspersky Lab, called the demonstration a "thrill" to watch and said it is important to improving the security of machines that can each hold tens of thousands of dollars in cash.
However, he said he doesn't think it will result in widespread attacks because banks don't use the standalone systems and Jack didn't release his attack code.
Jack wouldn't identify the ATM makers. He put stickers over the ATM makers' names on the two machines used in his demonstration.
But the audience, which burst into applause when he made the machines spit out money, could see from the screen prompts on the ATM that one of the machines was made by Tranax Technologies Inc., based in Hayward, California. Tranax did not immediately respond to e-mail messages from The Associated Press.
Triton Systems, of Long Beach, Mississippi, confirmed that one of its ATMs was used in the demonstration.
It said Jack alerted the company to the problems and that Triton now has a software update in place that prevents unauthorized software from running on its ATMs.
Bob Douglas, Triton's vice president of engineering, said customers can buy ATMs with unique keys but generally don't, preferring to have a master key for cost and convenience.
"Imagine if you have an estate of several thousand ATMs and you want to access 20 or so of them in one day," he wrote in an e-mail to the AP.
"It would be a logistical nightmare to have all the right keys at just the right place at just the right time."
Other ATM manufacturers contacted by the AP also did not immediately respond to messages.
Jack said the manufacturers whose machines he studied are deploying software fixes for both vulnerabilities, but added that the prevalence of remote-management software broadly opens up ATMs to hacker attacks.


Clic here to read the story from its source.