funsec mailing list archives
Re: Windows-Based ATM Machine Hacked, Gets 'Painted'
From: "James (njan) Eaton-Lee" <james.mailing () gmail com>
Date: Mon, 26 Feb 2007 15:49:05 +0000
Dennis Henderson wrote:
And stupidly enough they likely allow configuration of the system from the keypad instead of the normal keyboard... Could also be from a "window" of control opportunity after power cycling the ATM. Its amazing the things you can find inside an ATM besides cash.... laptops, very small computers, mice, keyboards... :)
First off, clicking links, I don't think this is actually an ATM; it doesn't look nearly robust enough in the pictures to be one, and based on the description on the page this comes from ("some cheap ATM machine touch screen thing at Cinema 9"), it sounds more like a ticket pickup/purchase machine, which makes it sound increasingly likely there's a weak(er) backend infrastructure. Ok, still processing cards, but still.. probably no cash by the looks of it..
Nevertheless, for my 2c..I think it's most likely whatever management infrastructure sits behind the device had been compromised in this instance, and as the article aludes to, this generally doesn't mean that customer data or the security of cards and PIN numbers has been compromised.
This may not be an ATM, but.. a large proportion of the security of an ATM is derived from the (actually fairly complex) security standards set for these. Visa's own "PIN Entry Device" (PED) requirements (http://partnernetwork.visa.com/dv/pin/main.jsp), and the Payment Card Industry standards are two examples of such standards.
The PIN entry device itself isn't just a ps/2 or USB Human Input Device - it's actually designed specifically to avoid dataloss even when the main CPU/computer is compromised, and the actual keypushes are entirely out-of-band from the normal input devices attached to the PC within the ATM.
They're fairly self-contained, sophisticated units with their own microprocessors, linked to the card readers themselves. From what I've seen, at least with lower-end devices such as this one, the PED unit frequently attaches to the PC in the back of the unit via RS232 or USB.
See the following for some more information on vaguely how the PED/keypad units are constructed:
http://partnernetwork.visa.com/dv/pin/pdf/Technical_FAQs.pdf http://www.theregister.co.uk/2004/07/21/atm_keypad_security/ - James. -- James (njan) Eaton-Lee | UIN: 10807960 | http://www.jeremiad.org "The universe is run by the complex interweaving of three elements: Energy, matter, and enlightened self-interest." - G'Kar https://www.bsrf.org.uk | ca: https://www.cacert.org/index.php?id=3 --
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- [privacy] U.S. 'Licence to Snoop' on British Air Travellers Fergie (Jan 01)
- <Possible follow-ups>
- Re: [privacy] U.S. 'Licence to Snoop' on British Air Travellers Juha-Matti Laurio (Jan 03)
