ATM Hackers Have Picked Up Some Clever New Tricks
wired.com
wired.com
Was shocked to recently find semi-modern (mid-2000s) gas-pumps for sale cheap on eBay so who knows.
It would still probably be "fun" (not easy) for someone who hasn't done it before, but not impossible.
Picking it up only solves half the problem, and the easier half.
They are also very very insecure. You can literally just walk around behind them and attach stuff without anyone really noticing.
I was renewing my registration at a DMV kiosk, which is like an ATM that spits out registration tags instead of money. The machine was broken, and the supermarket said to just call the number on the side. I did so, and they told me to unplug it and plug it back in. So I went around the back and did exactly that. No one questioned me.
Then they remotely logged in, messed around on it (which I could watch them do on the display) and it was fixed.
But my point here is that no one questioned me when I went around back, no one questioned a mouse moving around on a touch screen, no one questioned random control panels coming up, and the people who owned it (the DMV) didn't seem to care about the information leaks they were providing me.
It seems like the ATM's software might work like this: on bootup, connect to server atm.foobar.com at port xyz.
Oh, right. In that case, you'd write an MITM server. You could sneak a raspberry pi so that it goes ATM <-> RPI <-> ethernet, and then set up the RPI to broadcast all the network traffic via a wifi dongle to your laptop.
But... certificate pinning would trivially subvert that. I guess ATM manufacturers might not have done any pentests though, so perhaps they don't do cert pinning.
Assuming cert pinning, is there still a way?
The few times I've used one they also take a ridiculous amount of time to connect/return anything, on the order of 30s-1m.
The jacks official name for the jack is Modular connector[1]. 6P6C for RJ14, 6P2C for RJ11 and 8P8C for RJ45 (what you described as cat5 jack)
Fun fact, the modems still negotiate at 2400 or 9600 baud, because the extended negotiation times of higher-speed protocols more than negate time saved in transferring the small payload.
They even make gateways to bridge old dial-up ATMs to IP: https://atmpartmart.com/wireless-atm-modems/systech-box-ipg-...
I've worked on a team that reverse engineered and did security audits on a lot of commercial and consumer applications. We've seen cert pinning implemented correctly was maybe like once or twice a year by companies large enough to where their security team was larger than most software companies entire payroll.
Basically, it's not a thing that exist because it is really hard to implement properly. The threat model for being MITM'ed with cert spoofing is pretty exotic. In the end, cert pinning means your application is not working if something goes wrong with the certs, which EVERYONE at some point forgets to renew, or, worse, you CA inadvertently gets hosed.
For the remote attacks, though, like the one where it said could result in many ATMs at the same time being hacked, I don't begin to understand where the attack vector starts.
Similarly, there are several ways that attackers can find ATMs on the internet or telephone system in bulk. Although the situation has improved, ATMs historically had very poor authentication for remote management (some likely still do) which made them vulnerable to malicious reconfiguration over the internet or telephone modem.
Don't run your ATM under Windows and connected to the Internet. I recall reading an instructional manual that required the visit of two technicians, that installed and configured a black-box that required the entry of two unique codes to be activated. Communication to the back-end being done on private leased-lines. Then they upgraded the ATMs to Windows running over the Internet :o ..
I'd go further than that. These companies are, demonstrably, run by total idiots.
I knew someone who worked for an ATM company back in the mid 1980s. Coordinated attacks exploiting weaknesses were routine even then!
That's right. People have been finding hacks to steal cash from ATMs for at least 35 years!
That's 35 freaking calendar years. How much is that in Internet years? :)
I would think that after you had physical possession of the ATM this would be a non-issue. You're free to do whatever you want with it, as long as it's hidden well enough it doesn't get tracked down.
A GPS tracker in the money compartment is an interesting idea, but I would think that it wouldn't be to hard to defeat with either a faraday something or other or just disrupt the GPS signal [0].
That being said, this requires someone to be thinking about it, which may or may not be happening.
[0] https://www.economist.com/international/2013/07/27/out-of-si...
There's not much a few basic power tools can't get into, given enough time to use them.
Seemed to happen in Philadelphia often this year. Many gases could do the job with the right amount of oxygen.
Canada had an interesting duo that used portable welders to cut holes in just the right spot. The travelled around a lot and hit 50 indoor ATMs after-hours (interesting video): https://youtu.be/HWg6GcthZi8?t=44
The blast pops the box out, then the box can be opened with regular worshop tools in a safe house.
Source: I used to operate some ATM’s as a side biz.
https://www.youtube.com/watch?v=VTe0cdxdSEo
https://www.youtube.com/watch?v=QTyON6gPTFI
Ah, and here was a failed attempt to do the same in Virginia:
https://www.youtube.com/watch?v=u2TSGyXejls
How much cash does an ATM hold anyway?
https://www.theguardian.com/uk-news/2020/mar/23/ram-raiders-...