All the latest UK technology news, reviews and analysis

Black Hat: Hacker makes ATMs spew money

by Iain Thomson

More from this author

29 Jul 2010

Be the first to comment

  • Tweet this
Black Hat 2010
ATMs could be hacked to release their entire contents

Security researcher Barnaby Jacks has used the Black Hat briefings to demonstrate an interesting way of getting money out of an ATM machine.

Jacks, who is head of research at cyber security consultancy IOActive, demonstrated the attack on two common ATM platforms.

The first attack unlocked the machine using standard keys purchased on the internet. Jacks inserted a USB stick which overwrote the ATM's firmware and caused it to spew fake million dollar bills.

The second attack involved using the remote updating capabilities of an ATM to upload code that caused the machine to empty itself of cash, and record card details and PINs.

"Every ATM I've looked at, I've found a game-over vulnerability that allows me to get cash," said Jacks. "So far I've looked at four, and I'm running four-for-four at the moment."

Jacks bought the ATMs online to test his hack before going public. He was due to give his presentation at last year's Black hat conference, but was stopped after legal action and because a fix for the problem was not available.

Most ATMs use Windows CE or a cut down version of Windows XP, but Jacks used a cloned version of the firmware in the machines to carry out the attacks.

The remote attack could also be performed using VoIP technology, Jacks said, since code is available to scan 10,000 dial-up numbers for the machines in less than an hour.

Bob Douglas, vice president of engineering at Triton, which manufacturers one of the ATMs used, claimed that the company had developed a defence against the attack and had made it available in December.

"The problem was solved by remote update and we give customers the option of an individual, unpickable lock to their system," he said.

Firmware updates now require a digital signature before they can be installed on ATM machines, according to Douglas.

The case is more worrying because Jacks said that the same systems used by the ATM builders are used in voting machines, making electoral fraud very easy.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Oracle DBA, Database Administrator (Oracle, SQL, RAC), NEWPORT

Database Administrator (Oracle,DBA, SQL, RAC) Opus...

Client Relationships Manager

Sales and Account Management, Account Manager, Client...

SQL Database Analyst - Leading Consultancy - £28-35K + Bens + B

SQL Database Analyst - Leading Consultancy - £28-35K...

Business Intelligence Developer, BI Developer

BusinessObjects - Data Integrator 11.5 and Core Tools...

To send to more than one email address, simply separate each address with a comma.