MagSpoof – wireless credit card/magstripe spoofer
github.com
github.com
The Samy MySpace worm: https://en.wikipedia.org/wiki/Samy_%28computer_worm%29
EverCookies: http://samy.pl/evercookie/
SkyJack: https://en.wikipedia.org/wiki/SkyJack
And so much more... http://samy.pl/ https://en.wikipedia.org/wiki/Samy_Kamkar
I guess these are the type of guys that would start to approach the definition of a modern polymath maybe?
Not saying he is one necessarily (or that he isn't), but what would examples of modern polymaths are there? considering a lot of the fields to be mastered need enough detail and knowledge that it seems hard to find one.
[1] http://gingerybooks.com/I think a modern polymath could look a bit different than the ones in the classical sense. To be able to make contributions to the fields you mentioned, I guess you would need more years of study than anyone could dedicate to, just because those fields seem to be very hard, especially considering the degree at which nowadays we would consider someone proficient in any of these.
Well, I'm not sure, I'm actually wondering. For your particular definition, or something close to it, who would you say it gets close?
https://www.youtube.com/user/bkraz333 http://benkrasnow.blogspot.com/
Most people always think of the usual guys when talking about polymaths, and it seems like modern ones are never mentioned.
SkyJack is a drone engineered to autonomously seek out,
hack, and wirelessly take over other drones within wifi
distance, creating an army of zombie drones under your
control.
...and then: No authentication or encryption is used by the Parrot
to secure the connection with the pilot.
Well, there's your problem!I knew from people losing their cards which continued working some places but not others there was a relationship in the issuing. I got a reader, decoded the card (zeropadded student ID, issue number, and XOR checksum).
I found other places to find the student ID number, and could enumerate a few issue numbers. I built this spoofer: http://www.instructables.com/id/Arduino-Magstripe-Emulator/ Then I could get into my friend's apartments (as a POC with their permission of course).
I disclosed and got a thank you (I built a good relationship with my IT dept over the years), but never figured out if they fixed it.
For example, if you happen to need a unique ID for each card, and you roll your own "random id generator" you might happen to encounter pitfalls that would've been solved by using UUIDs.
Or you try to get some sort of hash value from the card info (to verify validity or whatever) and instead of using a known hashing algorithm you try to roll your own.
And I would guess a long list of etceteras.
So when a system that should be for the most part trivial to implement correctly is full of these holes then people like GP will start poking around and ultimately start finding a lot of issues that would make it actually not "good enough".
I mean sure, keys are just there to keep honest people out, but if you can use a standard key that would foil both honest AND a few opportunistic dishonest people then why are you instead trying to use your own "custom key" that happens to be much easier to defeat? Especially if said standard key is not really that much harder to implement.
I had a similar experience at my university. I found easy unauthenticated sourcing of most of the data needed to clone the card of anybody by name. The issue number was the only thing to guess, but easy to bruteforce on something low-stakes like vending machines. The card was used for food, a debit-card-like system, automated door locks to semi-public buildings and on-campus housing.
With the permission and cooperation of the university security, I made a card of a high-level security guy (who could have been targeted using the public/semi-public org chart) and swiped into their datacenter where all the university data is hosted, along with that of some partners with sensitive data. Luckily the innermost parts need an RFID or something which I didn't have access to, but potentially I could have tailgated or social-engineered my way into that. They weren't interested in letting me research whether I could crack the RFID. :(
I was told my demo made a big splash, but IIRC I checked a year or two later and my source for the ID data was still wide open. There's having imperfect locks and then there's leaving all your keys out in public.
How about to casually insert a duplicated key like everyone else?
My point is that being able to trivially hijack arbitrary identities without even knowing the person let alone physically finding them, is not "good enough." It'd be like if you could make arbitrary car keys with just a VIN, and the VIN is displayed prominently, it would be silly to say "Well now, it keeps honest people honest, so it's good enough."
Now, lots of places in the 1970s and 1980s, and some into the 1990s and 2000s, may have been engaging in the practice of posting grades by SSN or student ID #, even though posting by either had long been explicitly prohibited by FERPA regulations.
What did happen in 2001 that may be relevant to awareness of the rule is the publication of a finding in response to a complaint for posting with the last 4 digits of the SSN.
http://www2.ed.gov/policy/gen/guid/fpco/ferpa/library/hunter...
https://github.com/samyk/magspoof#american-express-card-numb...
> I found a global pattern that allows me to accurately predict American Express card numbers by knowing a full card number, even if already reported lost or stolen. > This means if I were to obtain your Amex card and you called it in as lost or stolen, the moment you get a new card, I know your new credit card number.
I've got 2 AMEX cards - one reissued and ends with 0, another issued the first time and ends with non-0. (I'm ignoring the check digit)
This card also had the embedded chip, so that may be why it had the new number.
It would have been as much software update to have implemented PIN and would've brought security to the level of ATM cards.
The generation and provisioning of card numbers is limited by other systems which includes fraud detection, account processing, auditing and other backend systems.
In every case were I used a USA chip card (with no PIN), the card reader prompted for a signature, so it was no problem.
Though I really don't understand why USA issuers and merchants went with a chip-only system, seems like it would have been trivial to allow PIN too.
Though even Chip and PIN only fights a small portion of the fraud - every time I've experienced credit card fraud, it's been with internet purchases. Amex used to let me generate a temporary card number for each merchant, I used that all the time, but they dropped the service for some reason.
It's also a great deal more difficult to extract the secret information from the chip; I don't know if anyone has done so yet.
And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported.
So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will continue using it via NFC supported terminals.
I believe they give you $50-100 just to use Samsung Pay right now for one example.
That's how it works for all countries other than the US. In the US EMV capable terminals are not common so transactions in the US are typically permitted no matter if magstripe or EMV. This is why starting with October this year the US are finally making the switch to EMV and once that roll-out is complete, magstripe transactions could (theoretically) be either disabled or severely limited. For instance you might have to confirm a magstripe transaction with a text message.
Sure it could check for the actual chip, but credit card fraudsters aren't creating fake cards that include the chip so that wouldn't help either.
I would argue the way they should implement it is such that the bank itself rejects the transaction if it knows the card is chip enabled and the terminal is as well.
If the terminal doesn't support it the processor always lets it through. If the terminal does support it the processor only lets it through if using chip and pin. Then again, maybe there won't be non chip and pin terminal much longer so that won't matter.
Should that read 'credit card fraudsters are creating fake cards that include the chip' ?
(for example, the EMV standard explicitly handles various failure modes like "PIN-pad is broken", "card holder does not remember PIN" and so on, and allows configurations that accept such transactions)
For the longest time, chip-and-pin readers in most european countries would let you just swipe the magnetic card if you didn't have a chip.. this allowed americans (and whoever else still uses this technology) to be able to shop when they travel.
Unfortunately a disproportionate amount of theft occurs by bypassing the chip-and-pin system. Many european countries and banks finally had enough and said "no more loopholes, chip-and-pin only" and set a date.
Lo and behold this spurred the US banks to finally start releasing chip-and-pin enabled cards, otherwise their clients would find themselves unable to buy things overseas.
The deadlines have come and went in my country, and today it is literally impossible to buy anything with just a magnetic stripe.
I imagine the US will solve the problem the same way.. by no longer allowing magnetic stripes to be used.
More annoyingly, whether I swiped or dipped, a signature was required. Except, again, where there was no way to sign (parking garages). Then, magically, my PIN was "good enough".
I went out of my way to get EMV cards last year due to upcoming trips, because I had only been overseas sporadically over the past decade and assumed that the magstripe was gone. It was not. If anything, merchants seemed more able to deal with them than 10 years ago, where I occasionally had a clerk who couldn't figure out whether to swipe extremely slowly, or quickly enough to set fire to the equipment.
As a UK resident with a UK card it's been a long time since I swiped or signed. I think you must have the "require signature always" bit set on your cards because someone in the issuing chain doesn't trust EMV.
I don't think I have a single card that supports pin.
Here is the campaign that was ran by the largest payment processor letting everyone know the old system was going away. It was heavily advertised all over the country.
http://www.valitor.is/fyrirtaekjalausnir/pinnid-a-minnid/
Perhaps there is somehow an exception for foreign cards? But this is news to me, and seems like it defeats the entire purpose.
A European-issued card would deny use of the magstripe on an EMV reader. This could possibly by overridden by the cashier, but most won't have the authority to do this. (The merchant takes responsibility for fraud in this case.)
Fortunately, it is easy to detect! The terminal will send the magstripe data online when authorizing the transaction, and the backend systems will identify the corruption in magstripe data and identify it as fraud.
Another way of looking at it is that the magstripe reader is a wireless receiver. It just usually works with signals so weak that they can only be transmitted a miniscule distance.
https://www.anfractuosity.com/projects/optical-magnetic-stri...
I'm planning on seeing if I can decode data from higher density mediums with the same approach, when I can get my hands on some iron nanoparticles.
Edit: I meant on an EMV compliant terminal.
Edit: Also, that is considered fraud and your best not testing it, unless you like the prison environment.
Yes everyone is going to run around and scream 'security!!' when they realize how ridiculously trivial this process always has been, but it does not change facts - it has always been this easy, but this is a new way to highlight that fact.