新足迹

 找回密码
 注册

精华好帖回顾

· 外汇保证金新手投资完全手册(2010年修改版) (2010-1-10) 猎梦人 · 二毛打狗记 (2009-5-7) edith921
· 写点卖车经历,回国前最后为车版做点贡献 (2013-1-31) look2046 · 澳洲人物八卦帖 (2010-8-5) JuJu
Advertisement
Advertisement
查看: 1853|回复: 10

黑客攻击ATM,能令其吐钱! [复制链接]

头像被屏蔽

禁止发言

发表于 2010-7-30 16:31 |显示全部楼层
此文章由 iami 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 iami 所有!转贴必须注明作者、出处和本声明,并保持内容完整
Hack makes ATMs spew out cash

两种攻击方法:
1。物理+软件:打开atm,给atm灌入自己写的程序,让机器吐钱
2.远程攻击。绕开password,命令机器吐钱,还同时可以获得atm上用户的密码等信息。

这老兄自己买来几台atm搞了两年,折腾出这个结果。
具体细节没有在会议上公布

预知详情,请度原文。
不过我已经把最重要的抓出来了。


http://www.smh.com.au/technology ... 20100730-10yuv.html



A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.

The attacks successfully targeted standalone ATMs, but they could potentially be used against the ATMs operated by mainstream banks.

Criminals have long known that ATMs aren't tamperproof.



There are many types of attacks in use today, ranging from sophisticated to foolhardy: installing fake card readers to steal card numbers, hiding tiny surveillance cameras to capture PIN codes, covering the dispensing slot to intercept money and even hauling the ATMs away with trucks in the hopes of cracking them open later.

Computer hacker Barnaby Jack spent two years tinkering in his Silicon Valley apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.

His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.

He showed off his results at the Black Hat conference in Las Vegas, an annual gathering devoted to exposing the latest computer-security vulnerabilities.

His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.

His talk was one of the conference's most widely anticipated, as it had been pulled a year ago over concerns that fixes for the ATMs would not be in place in time. He used the extra year to craft more dangerous attacks.

Jack, who works as director of security research for Seattle-based IOActive, showed in a theatrical demonstration two ways he can get ATMs to spit out money.

Jack found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer. He figured this out by ordering three ATMs from different manufacturers for a few thousand dollars each. Then he compared the keys he got to pictures of other keys, found on the internet.

He used his key to unlock a compartment in the ATM that had standard USB slots. He then inserted a program he had written into one of them, commanding the ATM to dump its vaults.

Jack also hacked into ATMs by exploiting weaknesses in the way ATM makers communicate with the machines over the internet. Jack said the problem was that outsiders were permitted to bypass the need for a password. He didn't go into much more detail because he said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes".

The remote style of attack is more dangerous because an attacker doesn't need to open up the ATMs.

It allows an attacker to gain full control of the ATMs. Besides ordering it to spit out money, attackers can silently harvest account data from anyone who uses the machines. It also affects more than just the standalone ATMs vulnerable to the physical attack; the method could potentially be used against the kinds of ATMs used by mainstream banks.

Jack said he didn't think he'd be able to break the ATMs when he first started probing them.

"My reaction was, 'This is the game-over vulnerability right here,'" he said of the remote hack. "Every ATM I've looked at, I've been able to find a flaw in. It's a scary thing."

Kurt Baumgartner, a senior security researcher with anti-virus software maker Kaspersky Lab, called the demonstration a "thrill" to watch and said it was important to improving the security of machines that can each hold tens of thousands of dollars in cash. However, he said he does not think it will result in widespread attacks because banks don't use the standalone systems and Jack did not release his attack code.

Jack would not identify the ATM makers. He put stickers over the ATM makers' names on the two machines used in his demonstration. But the audience, which burst into applause when he made the machines spit out money, could see from the screen prompts on the ATM that one of the machines was made by Tranax Technologies, based in Hayward, California. Tranax did not respond to email messages from The Associated Press.

Triton Systems, of Long Beach, confirmed that one of its ATMs was used in the demonstration. It said Jack alerted the company to the problems and that Triton now had a software update in place that prevents unauthorised software from running on its ATMs.

Bob Douglas, Triton's vice-president of engineering, said customers could buy ATMs with unique keys but generally do not, preferring to have a master key for cost and convenience.

"Imagine if you have an estate of several thousand ATMs and you want to access 20 or so of them in one day," he wrote in an email to the AP. "It would be a logistical nightmare to have all the right keys at just the right place at just the right time."

Other ATM manufacturers contacted by the AP also did not respond to messages.

Jack said the manufacturers whose machines he studied were deploying software fixes for both vulnerabilities, but added that the prevalence of remote-management software broadly opened up ATMs to hacker attacks.

[ 本帖最后由 iami 于 2010-7-30 16:32 编辑 ]

评分

参与人数 2积分 +16 收起 理由
degra + 8 谢谢奉献
bulaohu + 8 感谢分享

查看全部评分

签名被屏蔽
Advertisement
Advertisement

退役斑竹 2008年度奖章获得者

发表于 2010-7-30 16:34 |显示全部楼层
此文章由 dickson 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 dickson 所有!转贴必须注明作者、出处和本声明,并保持内容完整
太复杂, 拿个煤气罐往里灌点煤气, 然后点火
头像被屏蔽

禁止发言

发表于 2010-7-30 16:39 |显示全部楼层
此文章由 iami 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 iami 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 dickson 于 2010-7-30 04:34 PM 发表
太复杂, 拿个煤气罐往里灌点煤气, 然后点火


其实这是非常高效的办法。中东人就在这么干
签名被屏蔽
头像被屏蔽

禁止访问

发表于 2010-7-30 16:48 |显示全部楼层
此文章由 买房子啊 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 买房子啊 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 dickson 于 2010-7-30 16:34 发表
太复杂, 拿个煤气罐往里灌点煤气, 然后点火


这就是ML跟QJ的区别

评分

参与人数 1积分 +3 收起 理由
jerryclark + 3 其实没啥区别,该爽的还是爽了 ...

查看全部评分

发表于 2010-7-30 17:08 |显示全部楼层
此文章由 CCNBand 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 CCNBand 所有!转贴必须注明作者、出处和本声明,并保持内容完整
卧槽,为这个还开个新闻发布会
头像被屏蔽

禁止访问

发表于 2010-7-30 17:12 |显示全部楼层
此文章由 ah123 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 ah123 所有!转贴必须注明作者、出处和本声明,并保持内容完整
DICKSON是中东人
Advertisement
Advertisement

发表于 2010-7-30 17:35 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 CCNBand 于 2010-7-30 17:08 发表
卧槽,为这个还开个新闻发布会


这是Black Hat,全球最大的年度黑客会议

发表于 2010-8-4 02:28 |显示全部楼层
此文章由 卖房子阿 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 卖房子阿 所有!转贴必须注明作者、出处和本声明,并保持内容完整
以我端了 警察快来
头像被屏蔽

禁止发言

发表于 2010-8-6 23:47 |显示全部楼层
此文章由 阳光老帅 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 阳光老帅 所有!转贴必须注明作者、出处和本声明,并保持内容完整
黑客就是有钱,自己买几台ATM练着玩

发表于 2010-8-18 18:56 |显示全部楼层
此文章由 nikita17 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 nikita17 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 iami 于 2010-7-30 16:39 发表


其实这是非常高效的办法。中东人就在这么干


不算高效吧。一个小电钻,15分钟搞掂,行内的人都知道的。

发表于 2010-8-18 18:58 |显示全部楼层
此文章由 abbott1980 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 abbott1980 所有!转贴必须注明作者、出处和本声明,并保持内容完整
还不如直接抢银行 爽快
Advertisement
Advertisement

发表回复

您需要登录后才可以回帖 登录 | 注册

本版积分规则

Advertisement
Advertisement
返回顶部