DefCon Hackers Tell How They Cracked Brink's Safe in 60 Seconds
eweek.com
eweek.com
"So the issue isn't so much that there is no
acknowledgment that there is a problem; rather,
the vendors have been pointing fingers about
whose problem it is for over a year, without
progress made on the actual resolution."
And my colleagues wonder why I support full disclosure. I tell you what - if I was a bank that used these products, I'd be going around and epoxying these USB ports closed ASAP.They'd done a pretty good job securing the OS and device itself: we couldn't actually connect it to any networks, so network penetration testing was difficult, and there were no USB ports or CD drives. Unfortunately for them, they did leave an archaic port open on the back of the device. Now, this wasn't a USB port or anything, but (with certain difficult-to-source adaptors) we were able to get an external 3.5" floppy drive hooked up -- through which we could (slowly) load arbitrary executables, and take over the device.
When we explained this finding, the client told us that certain customers of theirs required this port for proprietary communication, and that they couldn't remove it from production. The end result was that for every production run of this device that wasn't going to one of those edge-case customers, epoxy was manually applied to close off the port.
Not the most elegant solution, but I guess it worked!
I don't know where the hardware was going, but computers are often either located in places where only trusted employees are permitted, or where there is not-infrequent foot traffic. Combine either trusted employees or random, unpredictable passers-by with regular inspection of the hardware, and you have a pretty decent solution.
Epoxied ports can also be used as an after-the-fact intrusion warning. You know the thing was epoxied from the factory. If your inspection reveals that the epoxy is missing or has been altered, then you're almost certain that something nefarious was going on.
My point is, if these machines were destined for public places, it wouldn't surprise me if a man in overalls could sit next to them and grind away epoxy with impunity for hours before anyone would think twice about it.
I don't really consider the show to be scientific, it's purely anecdotal, but it's definitely kind of interesting.
Though, we can't know if the client was looking for intrusion prevention, or merely after-the-fact intrusion detection. :)
These security hacks are cute, but sometimes I feel they are nothing more than advertisements? Don't we always have one of these "golly gee, I had no idea?" hacks around this time of year?
If I didn't have a company to promote, I don't know if I would come foreward with vunerabilities? Especially for a theiving bank? (I don't like banks these days. The fees are a slap in the face, along with pawn shop/Payday interest rates they charge us, and in return give us 0% on our money in most cases? $1500 minimum balance in order to not pay a monthly service charge? And, yes--I wished we let them suffocate in 2008. The myth of Capitalilism?)
IMHO--the biggest deterrent to crime these days is the proliferation of video cameras. They are everywhere.
You're likely mistaken. The device whose ports we are talking about epoxying was referred to by david_shaw. Noone in the thread has speculated as to the type or model of device. The only information we have about the device comes from david_shaw:
"I can't give specific details (for obvious NDA-related reasons), but this application was a large device that interfaced with mission-critical hardware -- and ran Windows XP embedded."
> If I didn't have a company to promote, I don't know if I would come foreward with vunerabilities? [sic]
If you were not doing the research for a paying client, nor were you doing it to publish a report, why would you be doing it?
> ...the biggest deterrent to crime these days is the proliferation of video cameras...
London has a very dense CCTV deployment. Look at the crime-reduction studies that have been done since their deployment. It'll be enlightening.
Also, I am now on notice that you will not likely work for a bank. Thank you for that information, I guess.
And, uh, my bank is a lot better than yours, it seems. Shop around!
This is a less than perfect solution, of course. The manufacturer of these safes deserves all of the flack it gets for not fixing the vulnerability /tout suite/. If I remember the article correctly, they've known about the attack for a year!!!
They also just invented the newest SaaS model: "Smashing as a Service"
And now you're telling me this is an actual thing?? My life is a lie.
They always thought it was "unfair" when I beat them.
Well maybe you shouldn't enjoy playing such poorly designed games then!
Applies equally to poor security practices. Play stupid games, win stupid prizes.
1) is not connected to the internet
2) you can't add external storage
I see people getting upset all the time about cashier tills running windows xp - but that doesn't make any sense. If the software works fine in that situation then it could be just as well running windows 3.11 and I don't see a problem.
There are unpatched 0-days that go back years that still make WinXP dangerous to have on any sort of network. Not only that, but they will never be fixed. Nor can you fix them yourself (no source code).
And yes, cash registers will be networked because of data mining. I can get an accurate picture of store utilization solely by watching registers. And also by seeing what was purchased, I can change inventory appropriately. So yes, networking is essential. Perhaps it's not for the small business that handles flea markets and such.
I only specified networking.
Its also how Target was attacked. Their registers are networked yet there was a hole from the internet to their corporate net. That hole was through their HVAC control system.
The Tl;Dr. Is that you design a secure system, so that if one part fails, the whole system doesn't fall like a house of cards. Security through layers.
There are few things better than showing up to a security review gig and have them running XP. Makes my job super easy and clients love when I rain down bugs. It's even better because we can actually write exploits in a short time frame. Love XP.
https://www.youtube.com/watch?v=mdnHHNeesPE and this https://www.youtube.com/watch?v=HxQUKAjq-7w
does not compute....
"0-day" is a vulnerability that's discovered at the same time there are already exploits in the wild. It means you have zero days to get a patch deployed before the target is vulnerable to attack. Obviously a very bad situation to be in.
And yet these days it gets thrown around as if it describes the severity of the vulnerability itself. Thus the above scoffing at "0-days that go back years". What does that mean? It's like saying you have a matinee movie on blue-ray that you'll watch tonight.
I suppose one could have a patched 0-day? It would need to be be fixed by the vendor without them ever acknowledging the underlying issue existed, right?
As for the "go back years" bit, the guy just has some XP vulns that were found ages back and he's never released them, and of course they still work.
(Having worked somewhere close to the field of XP-for-POS, the answer appears to be that the customers really do not like having to do updates. They'd much rather just firewall the tills and hope they don't suffer a stuxnet. They're attacked surprisingly rarely because you can't steal money over the internet this way.)
For instance, the USB port could be on a daughter board, and requires you to enter a password on the plugged in keyboard before the daughter board would complete the connection to the main motherboard.
The really simple method would be to at least have a USB Lock that plugs into the USB port, and once locked it hooks into a USB port and if physically ripped out without unlocking, it would rip out the USB port with it. This is something they can retrofit quickly while figuring out other problems with their software problems.
We then allowed them to be re-enabled selectively based on a challenge-response touch screen input (didn't require connectivity, just pre-shared keys to verify the response) or via our server (if connectivity was stable and the touch screen had an issue).
Assuming you have a team competent enough to build a platform that you can at minimum reboot and ensure it'll always come back up, you'd never, ever want to automatically let someone access your system.
Having a usb outside is invitation to do something with it.
What a stupid vulnerability.
In-case anyone was also wondering what that is, after looking it up, it's provisional credit with the bank... The safe transmit daily deposit data to the bank, and the bank credits your account.
If the transfer of ownership is completed the instant the store drops the cash into the safe, they only have an interest in securing the path to the point of deposit, and have no interest in securing the safe itself.
Indeed, the naive criminal plot would be to adjust the store surveillance cameras such that the safe-deposit process could be visually verified, but the cracking process would be obfuscated. Then a store employee cracks the store's own safe, takes the money out, and takes it out through the loading dock with the trash.
[Edit:] It seems as though the safe credit is actually a provisional deposit, and banks aren't all that crazy after all.
"tool that Salazar and Petro created basically emulates mouse and keyboard presses"
USB Rubber ducky? Neat tool that is.You don't buy a safe so that you'll never get robbed. Banks don't have that as a desirable security posture! [+] You buy a safe to cheaply decrease the total cost of theft.
[+] Fun fact: average bank robbery costs the bank only $8k or so in lost cash. This is one of the many reasons why every bank in the country has In The Event Of A Bank Robbery Don't Try To Be A Hero Seriously It's Pocket Lint in their training about it.
Also, as this argument depends in part on insurance, the insurance companies are entitled to the same information.
The real point here, however, is not that the safes can be broken, but that they can be broken relatively easily with techniques that have been known for a long time, and which can be defended against. There is no strong case to be made that this is a well-engineered product.
USBdriveby is a device you stylishly wear around your neck which can quickly and covertly install a backdoor and override DNS settings on an unlocked machine via USB in a matter of seconds. It does this by emulating a keyboard and mouse, blindly typing controlled commands, flailing the mouse pointer around and weaponizing mouse clicks.
Wouldn't it be much, much better to just keep the topics secret until the moment of disclosure?
From the pictures, it looks like the same hardware.
I wonder if the vulnerability is specific to the customer or the hardware?
https://www.youtube.com/watch?feature=player_detailpage&v=nB...
but USB sticks are probably a little less suspicious than crow bars.
nothing else to read here.