Cash machines robbed with infected USB sticks
bbc.co.uk
bbc.co.uk
The summary is there there are only a few vendors of ATMs and ATM software. They often have a tubular lock with a small number of lock combinations. You open it, and there's the main board. USB (some with auto-play still enabled), CF card (main storage), everything. Plug in what you want. Some insist on code-signing of the CF card to boot, but it can be bypassed.
Often they are exposed to the internet, and as of the talk at least one vendor had a pre-login vulnerability to an internet-exposed port (which the speaker reported, so that particular one is probably fixed now, but goodness knows if the sites in the real world are patched).
Once you have your code running, it's game over. Open the cash drawer, record stripe data (and phone it to yourself whenever you like), rootkit the device to make yourself undetectable.
He bought several ATMs of the most popular model to experiment, right off the internet, some from the vendors themselves. Nobody questioned him.
Watch the talk, it was great.
Fun watch indeed!
Port 18456 is the port BTW. If you do a masscan sweep you'll find a ton of them facing the internet.....
I don't think he ever released his exploit or scrooge rootkit.
Now, for people who believe the generally good nature of states (and/or Santa) this might not even raise an eyebrow, but for people who have read their history, well...
1. The attackers knew there was a USB port on these devices that would auto-play, or at least trigger the auto-play dialog. 2. The attackers knew all of the software internals of the machines before they started. You don't just write code that works with any old ATM software. 3. The article stated that 'the organisers displayed "profound knowledge of the target ATMs"'. "Profound knowledge" seems to be an understatement. That's the kind of knowledge that you get when you work for a company that designs and builds ATMs.
Really, I don't see this as anything more than something to chuckle at. It's like if a restaurant was robbed by someone that knew the code for the back door and that a spare key to the safe was taped to the underside of the desk in the back room. If you know what you're doing, of course you can break in.
Or you just buy your own:
http://www.ebay.com/sch/Business-Industrial-/12576/i.html?_f...
:->, of course.
EDIT: Originally tried to raise a smiley to the Nth degree, but HN appears to dislike consecutive asterisks and kept munging them to nothingness.
Making ATM's only available to organizations with a full banking license might help and some body define proper security standards Bruce Schenier's looking for a new job maybe he might want to take this on?
Sort of like the problems we have right now with locks.
what needs to happen is that all the executives of the ATM company and the bank concerned (going back 15 years or so) need to be banned for life from ever being directors and b from ever working in the finance industry
Do you have unique experience to justify up your vitriol?
Common... Someone used an X-acto knife to plug in an USB stick on a PC configured to auto-play it and we should take it as a proof that "physical access to the internal electronics then the game is over"?
Companies like Brinks are using special sprays that renders bills unusable in case someone tries to break in the safes if I'm not mistaken.
What about an ATM where any tentative of opening it to physically access the internal electronics would result in the ATM bricking and all the bills getting instantly sprayed as to render them unusable?
What about spraying the bills and rendering them unusable in case the ATM is powered down and making it impossible to install new software without powering the machine down? (so that when you come with your new harddisk and access the internal to plug it in, you're SOL). This would even have the benefit of rendering attacks of the type: "I come with a truck and steal the part of the wall that contains the ATM" impractical (yes, people have done these).
And where the only way to prevent that, for example during legitimate maintenance, would be to first enter a token generated by the ATM company and communicated to the (legit) employee doing the maintenance when he's working on the machine?
I've never worked on ATMs and I'm sure it shows, but that's not the point.
Honestly I find it quite sad that simply plugging in an USB stick allows to steal money from the machine.
I find it also very sad that several people here consider that "nothing can be done against a rogue employee" or that "nothing can be done if you have physical access to the internal electronics".
And I do honestly hope that people working on ATMs will start thinking about how to better secure their ATMs and which kind of trust systems can be put in place so that rogue employees (and other thieves) have a much harder time attacking ATMs.
"It seems to me the failure was using materials that could be quickly breached and then patched."
That is just one failure. The attacker exploited several holes and the answer from ATM companies should be more complex than just putting duct tape on one of the holes.
Your suggestion with regards to maintenance is indeed a valid one, but again the increase in cost is simply to big. Most financial institutions in my country and region (western europe) actually see ATM purely as a cost, and install them simply because they want customers to get a hold of their money. It is that simple. So why would they increase the costs?
I think, and I don't want to start any flamewars or anything, that reconsidering the use of Windows in its current form is a valid route. If you were to start from an extremely limited & stripped down version sure, but not in the way companies are currently using it (for those that might wonder, yes full installs of windows happen all the time).
Anyway, I'm glad this is in the open. The more people talk about it, the more things will change.
I used to work in a supermarket with the 'self service' checkouts. The cash dispenser internals looks to be exactly the same as that in basic ATMs [0]. Without going into too many details, in our case the security was minimal and there was no tamper proofing. If you really wanted to get inside it wouldn't have been particularly hard. ATMs may by different as they are slightly more portable than a checkout though :)
[0] http://gadgets.boingboing.net/2009/05/11/this-picture-of-an-...
for physical access Having ATM'S that self destruct on tampering woudl be another possibility like the iron key USB sticks and bank grade key stores
Here's a video of a demonstration given back in November of a system (Crossing Guard) being developed at Dartmouth (under the Trustworthy Cyber Infrastructure for the Power Grid). The attack takes advantage of lower level USB operation and does not rely on autoplay.
[Edit: missing 'not']
2. Most likely it's (and old) windows. You don't need to write special code for any old ATM software. They could even just use autoplay once to test the grounds and copy anything they could back to the USB for analysis.
3. Ok, I'm not saying the profound knowledge / inside job was not involved... but people have done much more crazy and advanced attacks on black boxes with next to no knowledge. Once they knew they have access to software inside with auto-play they could do anything. Even connect the box to wifi via usb and do everything else remotely.
A well-designed system can withstand the attacker knowing all of its details aside from the secret key chosen by the owner. That's the whole point of avoiding "security through obscurity".
I haven't had a chance to look at the exploit but I'd assume it didn't necessarily use auto-play. The OS images that are loaded on these machines are highly customized and would likely prevent auto-loading a usb driver. However, either it auto-loaded or they exploited some other USB bug in Windows.
Once they could load code then they would have been able to manipulate the cash dispenser using an XFS app[0]. This would let them dispense bills from the safe to the customer facing throat. However, once the machine was restocked the bill counts would be off and the banks backend should detect the tampering.
Based on the story it sounds like they were able to load code into the banking application to allow activating their hack from the pin pad. To me that seems to indicate either a former engineer of NCR/Diebold or someone who got their hands on a used ATM and spent a lot of time reverse engineering the application software and chassis.
I've also made the assumption that this was done on a free-standing ATM[1]. Wall mount ATMs that you see at most banks are mostly behind the wall and would be extremely difficult to get access to a USB port.
[0] http://en.wikipedia.org/wiki/CEN/XFS [1] http://www.diebold.com/products-services/atm-self-service/te...
https://www.informationweek.com/mobile/banks-struggle-to-get...
http://www.engadget.com/2007/02/25/windows-based-atm-machine...
What's "Regular" Windows" when it's at home? The couple of ATMs I managed to see the inside of were either running WinCE or OS/2.
Looks like they are windows based machines. Wonder if they left auto-play running on them?
I'd bet they use standard PC motherboards. The only unusual things the thiefs knew where where to open the hole, and how to use the cash dispenser (altough, I'm quite sure one'd be able to get the entire dispenser documentation from Google).
Knowing that they are Windows machines, why don't people attack the ATMs by the network?
As far the network, you cant access ATMs from the Internet at least in the US. Most of the providers have leased lines to a central server somewhere and then leased lines to whatever 3rd parties they talk to. US banks arent too crazy on letting people remotely service ATMs that are having software problems.