Bunker-busting ATM attacks show security holes

July 29, 2010 By JORDAN ROBERTSON , AP Technology Writer
Bunker-busting ATM attacks show security holes (AP)

Enlarge

Barnaby Jack demonstrates an attack on two automated teller machines during the Black Hat technology conference in Las Vegas on Wednesday, July 28, 2010. The attacks demonstrated Wednesday targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks. (AP Photo/Isaac Brekken)

(AP) -- A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.

The attacks demonstrated Wednesday targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks.

Criminals have long known that ATMs aren't tamperproof.

There are many types of attacks in use today, ranging from sophisticated to foolhardy: installing fake card readers to steal card numbers, hiding tiny surveillance cameras to capture PIN codes, covering the dispensing slot to intercept money and even hauling the ATMs away with trucks in hopes of cracking them open later.

Barnaby Jack spent two years tinkering in his apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.

His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.

He showed off his results here at the Black Hat conference, an annual gathering devoted to exposing the latest computer-security vulnerabilities.

His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.

His talk was one of the conference's most widely anticipated, as it had been pulled a year ago over concerns that fixes for the ATMs wouldn't be in place in time. He used the extra year to craft more dangerous attacks.

Jack, who works as director of security research for Seattle-based IOActive Inc., showed in a theatrical demonstration two ways he can get ATMs to spit out money:

- Jack found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer. He figured this out by ordering three ATMs from different manufacturers for a few thousand dollars each. Then he compared the keys he got to pictures of other keys, found on the Internet.

He used his key to unlock a compartment in the ATM that had standard USB slots. He then inserted a program he had written into one of them, commanding the ATM to dump its vaults.

- Jack also hacked into ATMs by exploiting weaknesses in the way ATM makers communicate with the machines over the Internet. Jack said the problem is that outsiders are permitted to bypass the need for a password. He didn't go into much more detail because he said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes."

The remote style of attack is more dangerous because an attacker doesn't need to open up the ATMs.

It allows an attacker to gain full control of the ATMs. Besides ordering it to spit out money, attackers can silently harvest account data from anyone who uses the machines. It also affects more than just the standalone ATMs vulnerable to the physical attack; the method could potentially be used against the kinds of ATMs used by mainstream banks.

Jack said he didn't think he'd be able to break the ATMs when he first started probing them.

"My reaction was, 'this is the game-over vulnerability right here,'" he said of the remote hack. "Every ATM I've looked at, I've been able to find a flaw in. It's a scary thing."

Kurt Baumgartner, a senior security researcher with antivirus software maker Kaspersky Lab, called the demonstration a "thrill" to watch and said it is important to improving the security of machines that can each hold tens of thousands of dollars in cash. However, he said he doesn't think it will result in widespread attacks because banks don't use the standalone systems and Jack didn't release his attack code.

Jack wouldn't identify the ATM makers. He put stickers over the ATM makers' names on the two machines used in his demonstration. But the audience, which burst into applause when he made the machines spit out money, could see from the screen prompts on the ATM that one of the machines was made by Tranax Technologies Inc., based in Hayward, Calif. Tranax did not immediately respond to e-mail messages from The Associated Press.

Triton Systems, of Long Beach, Miss., confirmed that one of its ATMs was used in the demonstration. It said Jack alerted the company to the problems and that Triton now has a software update in place that prevents unauthorized software from running on its ATMs.

Bob Douglas, Triton's vice president of engineering, said customers can buy ATMs with unique keys but generally don't, preferring to have a master key for cost and convenience.

"Imagine if you have an estate of several thousand ATMs and you want to access 20 or so of them in one day," he wrote in an e-mail to the AP. "It would be a logistical nightmare to have all the right keys at just the right place at just the right time."

Other manufacturers contacted by the AP also did not immediately respond to messages.

Jack said the manufacturers whose machines he studied are deploying software fixes for both vulnerabilities, but added that the prevalence of remote-management software broadly opens up ATMs to attacks.

©2010 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

FredJose
Jul 29, 2010

Rank: not rated yet
I hope he remains resistant to the idea of going into the business of hacking atms and banks....
So far so good.
frajo
Jul 30, 2010

Rank: not rated yet
His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.
And, as always, no mention of the operating system. And no mention of the fact that news of this kind weren't heard of in the days when ATMs didn't yet run on Windows.
Rank 5 /5 (6 votes)
Related Stories
Relevant PhysicsForums posts
  • Empirical data regarding shower heads and water
    created1 hour ago
  • feed hold button on CNC lathe
    created21 hours ago
  • Mechanics of Solids ( Final exam question) please help!
    created23 hours ago
  • RFAC in Fortran
    createdFeb 09, 2012
  • dynamics 2/32
    createdFeb 08, 2012
  • dynamics
    createdFeb 08, 2012
  • More from Physics Forums - General Engineering

More news stories

Soraa LED light may dim 50-watt halogen rivals

(PhysOrg.com) -- Soraa, a Fremont, California company founded in 2008, this week launched its first product, a light that uses LEDS (light emitting diodes). The "Soraa LED MR16 lamp" is the "perfect" replacement ...

Technology / Semiconductors

created 21 hours ago | popularity 4.3 / 5 (17) | comments 18 | with audio podcast report

Samsung can continue selling Galaxy tabs in Germany: court

South Korea's Samsung Electronics can continue to sell its Galaxy Tab 10.1N tablet computer in Germany, a German court ruled Thursday, rejecting a bid by arch-rival Apple to have them banned.

Technology / Business

created 19 hours ago | popularity 3.7 / 5 (3) | comments 3

Digital photos could put kids at risk

A study published in the International Journal of Electronic Security and Digital Forensics this month suggests that parents and carers could be putting children at risk if they upload digital photos that are automatically "geota ...

Technology / Internet

created 15 hours ago | popularity 5 / 5 (1) | comments 3

Google launches Chrome browser for Android smartphones

With more and more people connecting to the Internet through a phone or a tablet instead of a PC, Google Inc. is bringing its fast-growing browser, Chrome, to the newest Android-powered mobile devices.

Technology / Software

created 18 hours ago | popularity 5 / 5 (4) | comments 0

Model analyzes shape-memory alloys for use in earthquake-resistant structures

Recent earthquake damage has exposed the vulnerability of existing structures to strong ground movement. At the Georgia Institute of Technology, researchers are analyzing shape-memory alloys for their potential ...

Technology / Engineering

created 16 hours ago | popularity 5 / 5 (1) | comments 0 | with audio podcast


'Dark plasmons' transmit energy

Microscopic channels of gold nanoparticles have the ability to transmit electromagnetic energy that starts as light and propagates via "dark plasmons," according to researchers at Rice University.

FDA-approved drug rapidly clears amyloid from the brain, reverses Alzheimer's symptoms in mice

Neuroscientists at Case Western Reserve University School of Medicine have made a dramatic breakthrough in their efforts to find a cure for Alzheimer's disease. The researchers' findings, published in the journal Science, show t ...

Hydrogen from acidic water: Researchers develop potential low cost alternative to platinum for splitting water

A technique for creating a new molecule that structurally and chemically replicates the active part of the widely used industrial catalyst molybdenite has been developed by researchers with the Lawrence Berkeley ...

Ultraviolet protection molecule in plants yields its secrets

Lying around in the sun all day is hazardous not just for humans but also for plants, which have no means of escape. Ultraviolet (UV) radiation from the sun can damage proteins and DNA inside cells, leading ...

Anyone can learn to be more inventive, cognitive researcher says

There will always be a wild and unpredictable quality to creativity and invention, says Anthony McCaffrey, a cognitive psychology researcher at the University of Massachusetts Amherst, because an "Aha moment" is rare and ...

Flexible paper robots

(PhysOrg.com) -- These inexpensive robots can stretch, bend and twist under control, and lift objects up to 120 times their own weight. Being soft, they can apply gentle and even pressure, and adapt to varied ...