Hacker extracts cash from ATMs
Last Updated: Thursday, July 29, 2010 | 10:20 AM ET
The Associated Press
Related
The attacks demonstrated Wednesday targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks.
(Tony Smyth/CBC)A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.
The attacks demonstrated Wednesday in Las Vegas targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks.
Criminals have long known that ATMs aren't tamperproof.
There are many types of attacks in use today, ranging from sophisticated to foolhardy: installing fake card readers to steal card numbers, hiding tiny surveillance cameras to capture PIN codes, covering the dispensing slot to intercept money and even hauling the ATMs away with trucks in hopes of cracking them open later.
Computer hacker Barnaby Jack spent two years tinkering in his Silicon Valley apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.
His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.
He showed off his results at the Black Hat conference in Las Vegas, an annual gathering devoted to exposing the latest computer-security vulnerabilities.
His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.
His talk was one of the conference's most widely anticipated, as it had been pulled a year ago over concerns that fixes for the ATMs wouldn't be in place in time. He used the extra year to craft more dangerous attacks.
Jack, who works as director of security research for Seattle-based IOActive Inc., showed in a theatrical demonstration two ways he can get ATMs to spit out money:
- He found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer. He used his key to unlock a compartment in the ATM that had standard USB slots. He then inserted a program he had written into one of them, commanding the ATM to dump its vaults.
- Jack also hacked into ATMs by exploiting weaknesses in the way ATM makers communicate with the machines over the internet. He said the problem is that outsiders are permitted to bypass the need for a password.
Jack said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes."
Share Tools
Top News Headlines
- Syria massacre toll up to 116, UN monitor says
- The UN Security Council is holding an emergency meeting Sunday to discuss the recent massacre in the Syrian town of Houla, in which 116 people died, many of them children under the age of 10. more »
- Montreal protesters march in peaceful defiance
- The clanging of pots and pans sounded throughout Montreal's downtown core Saturday night and into early Sunday morning, as thousands of protesters marched on in peaceful — but loud — defiance of Bill 78. more »
- Love film a 2nd win for Cannes director
- Michael Haneke won the Cannes Film Festival's top trophy for a second time with his film about love and death, Amour. more »
- Lady Gaga nixes Indonesia show after threats
- Lady Gaga cancelled her sold-out show in Indonesia after Islamist hard-liners threatened violence, claiming her sexy clothes and provocative dance moves would corrupt the youth. more »
Latest Business Headlines
- Bankia asks Spain for €19B
- The board of directors of Spain's troubled bank, Bankia, has asked the Spanish government for €19 billion ($24.5 billion Cdn) in financial support. more »
- EI reforms aim to boost employment, Flaherty says
- Finance Minister Jim Flaherty defended his government's proposals to change employment insurance, saying the aim is to remove "disincentives to employment." more »
- Employment Insurance review boards to be scrapped
- The federal government is scrapping two review boards used by people appealing decisions made about their employment insurance. more »
- Ottawa moves to limit foreign investment reviews
- The federal government is raising to $1 billion the amount of foreign money that can go into a Canadian company before the investment is reviewed. The review has been used in the past to block foreign takeovers of MDA and Potash Corp. more »
Lang & O'Leary Exchange
Markets
| Index | Last Trade | Change |
|---|---|---|
| TSX COMPOSITE | 11576.47 | 10.4 |
| DOW | 12454.83 | -74.92 |
| NASDAQ | 2837.53 | -1.85 |
| SP 500 | 1317.82 | -2.86 |
| NYSE COMPOSITE | 7534.32 | -18.01 |
| AMEX | 2227.37 | 1.45 |
| TSX-VENTURE | 1309.27 | 26.8 |
The data on this site is informational only and may be delayed; it is not intended as trading or investment advice and you should not rely on it as such.
Business Features
- Teen struck by lightning in Ottawa dies
- Missing Winnipeg children found in Mexico
- Quebec tornadoes cause millions in damage
- Montreal protesters march in peaceful defiance
- Syria massacre toll up to 116, UN monitor says
- Woman's remains found in hockey bag on Cape Breton river
- Everest team unable to bring down Toronto woman's body
- WWE apologizes to Brazil over Canadian's flag stomp
- Pope's butler arrested in Vatican leaks scandal

