Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

1–10 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#2
Embedded software is easy to hack. Spend quite a bit of money getting access to the binary running a common ATM platform. Reverse engineer it. Find a vulnerability. Trigger it. Done!

The age of (common) embedded system exploitation is finally upon us.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#3
post #2

Embedded software is easy to hack. Spend quite a bit of money getting access to the binary running a common ATM platform. Reverse engineer it. Find a vulnerability. Trigger it. Done! The age of (common) embedded system exploitation is finally upon us.

The "hack" in question involves replacing the hard drive.

This isn't an embedded issue. This is a physical access to OS issue.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#4
I am guessing the pulled an unencrypted hard drive from the ATM, analyzed it and the commands. Found the one that spits out cash.

They pop in one with modified code and reboot it to read the new drive.

Only similar ATM I can guess in Canada would already be suspect, in convenience stores, clubs, weed shops, strip clubs lol... The none bank name brand.

Had one bluescreened after taking money from account but before outputting money.

Was running Windows.

Didn't give any money, but kept the money from the account.

Had to call my bank.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#5
post #3
post #2

Embedded software is easy to hack. Spend quite a bit of money getting access to the binary running a common ATM platform. Reverse engineer it. Find a vulnerability. Trigger it. Done! The age of (common) embedded system exploitation is finally upon us.

The "hack" in question involves replacing the hard drive. This isn't an embedded issue. This is a physical access to OS issue.

It doesn't help that almost all the fascia locks on each vendor's machines are a standard key. With that standard key, you have full access to the computer or embedded device drive.

Nowadays the communication link to the dispenser is encrypted, making swapping the hard drive useless. The real problem is the machines aren't replaced very often so there are quite a few old models out in the field that are susceptible to these sort of attacks.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#8

The Reuters article is very low on detail. https://krebsonsecurity.com is much more informative.

Direct link to the Krebs story:

https://krebsonsecurity.com/2018/01/first-jackpotting-attack...

Nice little punchline at the end too:

"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack."

Post reply on HN