Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/28/2010
11:27 PM
50%
50%

ATMs At Risk, Researcher Warns At Black Hat

Barnaby Jack demonstrates remote and local exploits that work on popular bank machines

LAS VEGAS, NEVADA -- Black Hat USA 2010 -- A security researcher today gave notice to companies that make automated teller machines (ATMs).

Click here for more of Dark Reading's Black Hat articles.

Here on the first day of the Black Hat conference, Barnaby Jack, director of research at IOActive, demonstrated attacks that would allow a criminal to compromise ATMs, allowing hypothetical thieves to steal cash, copy customers' ATM card data, or learn the master passwords of the machines. While one of the attacks required a few seconds to open the ATM and insert a USB drive with code to overwrite the system, the other attack used a remote management feature commonly found on standalone ATMs.

Jack's presentation targeted machines made by Tranax and Triton, but other ATMs likely have similar security issues, he said.

"I found specific vulnerabilities in the ATM machines," Jack said during a press conference following the presentation. "But the attack surface is [similar] across the ATM industry as a whole ... In every ATM system I've looked at, I've been able to find flaws."

Jack said he used fairly simple analyses of the operating system and software commonly found on ATMs to create the exploits he demonstrated on stage. "We are back to 1999 in terms of code quality," he said.

Other security experts who watched the presentation agreed that ATM software would likely be a gold mine for security researchers.

"The presentation shows that the security of these machines need to be revisited because they were never architected with [online] security in mind," says Jamie Butler, director of research for security firm Mandiant.

In the past, cybercriminal attacks on cash machines have generally focused on physical attacks, such as adding skimmers to steal users' ATM card data -- or even stealing the whole machine. Instead, IOActive's Jack focused on the software, creating a remote administration tool, dubbed Dillinger, and rootkit, known as Scrooge. Dillinger allows a person to easily select known ATMs and retrieve data or send payloads, while Scrooge, which can be sent to an ATM as a payload, overwrites the system's programming to allow a person to control the machine.

Most standalone ATMs, such as those frequently found in convenience stores and bars, run on Windows CE. But Jack stressed that the vulnerabilities he found were in the proprietary cash management software, not in the operating system.

A compromised cash machine can be controlled by a person who inserts a card with special codes stored on the magstripe or who types a code on the ATM's keys, Jack said. He demonstrated Scrooge's ability to make the ATM dispense 50 bills -- all novelty cash in his demonstration -- and to store the details of any card inserted into the machine.

Triton, the maker of one of the ATMs, has required that all code running on its system be signed. It offers its customers special tamper-resistant keys for preventing access to the internal components of a cash machine, said Bob Douglas, vice president of engineering for the firm.

Slideshow: Barnaby Jack Hits The Jackpot With ATM Hack
Barnaby Jack Hits The Jackpot With ATM Hack
(view slideshow)
"We have developed a defense against attacks of this nature," Douglas said.

This is not the first time ATMs have been targeted with rogue code.

In 2009, Diebold, the No. 2 maker of ATMs, warned customers that more than 20 cash machines in Eastern Europe had been found to contain malicious code. The software had features similar to those demonstrated by IOActive's Jack, allowing criminals to steal and retrieve ATM card data and dispense cash from the cartridges. At the time, security researchers claimed the attack was an inside job, but Jack said his research has convinced him otherwise.

"Based on what I have seen, I think there is a possibility that the attacks were software-based," Jack said.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...