青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品

Michael's Space

Technology changes the world, serves the people.
Source: http://www.wired.com/threatlevel/2010/07/atms-jackpotted/

Researcher Demonstrates ATM ‘Jackpotting’ at Black Hat Conference

LAS VEGAS — In a city filled with slot machines spilling jackpots, it was a “jackpotted” ATM that got the most attention Wednesday at the Black Hat security conference, when researcher Barnaby Jack demonstrated two suave hacks against automated teller machines that made them spew out dozens of crisp bills.

The audience greeted the demonstration with hoots and applause.

In one of the attacks, Jack reprogrammed the ATM remotely over a network, without touching the machine; the second attack required he open the front panel and plug in a USB stick loaded with malware.

Jack, director of security research at IOActive Labs, focused his hack research on standalone and hole-in-the-wall ATMs — the kind installed in retail outlets and restaurants. He did not rule out that bank ATMs could have similar vulnerabilities, but he hasn’t yet examined them.

The two systems he hacked onstage were made by Triton and Tranax. The Tranax hack was conducted using an authentication bypass vulnerability that Jack found in the system’s remote monitoring feature, which can be accessed over the internet or dial-up, depending on how the owner configured the machine.

Tranax’s remote monitoring system is turned on by default, but Jack said the company has since begun advising customers to protect themselves from the attack by disabling the remote system.

To conduct the remote hack, an attacker would need to know an ATM’s IP address or phone number. Jack said he believes about 95 percent of retail ATMs are on dial-up; a hacker could war dial for ATMs connected to telephone modems, and identify them by the cash machine’s proprietary protocol.

The Triton attack was made possible by a security flaw that allowed unauthorized programs to execute on the system. The company distributed a patch last November so that only digitally signed code can run on them.

Both the Triton and Tranax ATMs run on Windows CE.

Using a remote attack tool, dubbed Dillinger, Jack was able to exploit the authentication-bypass vulnerability in Tranax’s remote monitoring feature and upload software or overwrite the entire firmware on the system. With that capability, he installed a malicious program he wrote, called Scrooge.

Scrooge lurks on the ATM quietly in the background until someone wakes it up in person. It can be initiated in two ways — either through a touch-sequence entered on the ATM’s keypad or by inserting a special control card. Both methods activate a hidden menu an attacker can use to make the machine spew out money or print receipts. Scrooge will also capture magstripe data embedded in bank cards other users insert into the ATM.

To demonstrate, Jack punched keys on the keypad to call up the menu, then instructed the machine to spit out 50 bills from one of four cassettes. The screen lit up with the word “Jackpot!” as the bills came flying out the front.

To hack the Triton, he used a key to open the machine’s front panel, then connected a USB stick containing his malware. The ATM uses a uniform lock on all of its systems — the kind used on filing cabinets — that can be opened with a $10 key available on the web. The same key opens every Triton ATM.

Two Triton representatives said at a press conference after the presentation that its customers preferred a single lock on systems so they could easily manage fleets of machines without requiring numerous keys. But they said Triton offers a lock upgrade kit to customers who request it — the upgraded lock is a Medeco pick-resistant, high-security lock.

Similar malware attacks were discovered on bank ATMs in Eastern Europe last year. Security researchers at Trustwave, based in Chicago, found the malware on 20 machines in Russia and Ukraine that were all running Microsoft’s Windows XP operating system. They said they found signs that hackers were planning on bringing their attacks to machines in the United States. The malware was designed to attack ATMs made by Diebold and NCR.

Those attacks required an insider, such as an ATM technician or anyone else with a key to the machine, to place malware on the ATM. Once that was done, attackers could insert a control card into the machine’s card reader to trigger the malware and give them control of the machine through a custom interface and the ATM’s keypad.

The malware captured account numbers and PINs from the machine’s transaction application and then delivered it to the thief on a receipt printed from the machine in an encrypted format, or to a storage device inserted in the card reader. A thief could also instruct the machine to eject whatever cash was inside the machine. A fully loaded bank ATM can hold up to $600,000.

Earlier this year, in a separate incident, a Bank of America employee was charged with installing malware on his employer’s ATMs that allowed him to withdraw thousands of dollars without leaving a transaction record.

Jack was slated to give the same ATM vulnerability talk at Black Hat last year, but his then-employer Juniper Networks canceled the talk weeks before the conference after an unnamed ATM vendor expressed concern. He said on Wednesday that the earlier talk was withdrawn to allow Triton time to implement a patch to address the code-execution vulnerability targeted in his demonstration. The company released the patch eight months ago.

Jack said that so far he’s examined ATMs made by four manufacturers and all of them have vulnerabilities. “Every ATM I’ve looked at allows that ‘game over.’ I’m four for four,” he said at the press conference. He wouldn’t discuss the vulnerabilities in the two ATMs not attacked on Wednesday because he said his previous employer, Juniper Networks, owns that research.

Jack said his aim in demonstrating the hacks is to get people to look more closely at the security of systems that are presumed to be locked down and impenetrable.

Photo: Isaac Brekken/Associated Press



Read More http://www.wired.com/threatlevel/2010/07/atms-jackpotted/#ixzz0vAgMMN79

青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品
  • <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>
            欧美日韩午夜| 国内成+人亚洲| 亚洲国产精品视频| 香蕉久久一区二区不卡无毒影院| 国产精品乱码久久久久久| 欧美高清视频一区二区三区在线观看| 久久男女视频| 狂野欧美一区| 欧美精品在线观看一区二区| 麻豆成人在线播放| 欧美日韩蜜桃| 国产偷自视频区视频一区二区| 国产日韩欧美在线视频观看| 国产综合色在线| 亚洲国产毛片完整版 | 欧美激情第9页| 欧美精品系列| 国产精品一区二区你懂得| 国产一区二区三区精品久久久| 精品动漫一区二区| 一区二区高清视频在线观看| 午夜精品久久久久久久99热浪潮 | 亚洲黄色三级| 亚洲视频网在线直播| 欧美一区二区成人6969| 牛牛国产精品| 国产精品男女猛烈高潮激情| 亚洲女ⅴideoshd黑人| 亚洲一区图片| 欧美a一区二区| 国产日韩精品电影| 日韩视频在线观看一区二区| 午夜久久tv| 亚洲国产小视频| 亚洲欧美日韩一区二区三区在线观看 | 老司机精品久久| 亚洲美女毛片| 久久天天躁狠狠躁夜夜av| 国产精品久久久久久久第一福利| 亚洲国产精品第一区二区三区| 亚洲自拍偷拍福利| 亚洲二区精品| 久久青草久久| 国内成人在线| 午夜天堂精品久久久久| 亚洲精品社区| 欧美成人在线免费观看| 国产区欧美区日韩区| 亚洲视频精品| 欧美激情第五页| 久久婷婷av| 国语自产精品视频在线看8查询8| 亚洲午夜视频在线| 欧美国产日韩亚洲一区| 久久激情综合网| 国产亚洲欧美一区二区三区| 亚洲一区亚洲| 亚洲午夜国产一区99re久久 | 欧美黄色大片网站| 久久九九国产| 狠狠干综合网| 久久亚洲欧洲| 久久大逼视频| 好吊色欧美一区二区三区四区| 欧美一级片久久久久久久| 日韩亚洲在线| 欧美亚洲第一页| 亚洲欧美在线aaa| 制服丝袜激情欧洲亚洲| 国产精品日本欧美一区二区三区| 中日韩男男gay无套| 一本色道久久88综合亚洲精品ⅰ| 欧美日韩视频在线| 夜夜爽www精品| aa级大片欧美三级| 欧美视频在线观看视频极品| 亚洲欧美一区二区三区久久| 亚洲一区视频在线观看视频| 国产亚洲精品久久久久婷婷瑜伽| 久久久91精品国产| 欧美专区在线| 亚洲国产精品国自产拍av秋霞| 91久久线看在观草草青青| 美女国产一区| 欧美成人午夜剧场免费观看| 在线综合亚洲| 亚洲在线视频网站| 精品1区2区| 亚洲欧洲日韩在线| 国产精品日本| 欧美va天堂| 欧美片在线观看| 久久精品国产精品亚洲精品| 久久久久久久性| 亚洲一区二区免费| 午夜精品亚洲| 一本一本久久a久久精品综合麻豆 一本一本久久a久久精品牛牛影视 | 一区二区三区在线免费观看 | 欧美一区二区视频在线观看| 欧美一级欧美一级在线播放| 亚洲第一页自拍| 亚洲在线观看免费| 亚洲激情视频在线播放| 一区二区三区日韩欧美| 国产亚洲精品久| 日韩午夜精品视频| 狠狠综合久久av一区二区小说 | 久久国产精彩视频| 欧美成人自拍视频| 新67194成人永久网站| 免费亚洲一区二区| 性欧美8khd高清极品| 久久精品在线观看| 欧美日韩三级| 欧美a级一区二区| 亚洲国产小视频| 欧美香蕉视频| 欧美激情片在线观看| 国产精品看片资源| 亚洲国产视频一区二区| 狠狠色噜噜狠狠色综合久 | 久久久综合香蕉尹人综合网| 亚洲一区二区欧美日韩| 欧美成人在线影院| 免费亚洲网站| 极品尤物av久久免费看| 午夜精品久久久久久99热软件| 亚洲欧洲日本专区| 久久精品主播| 欧美在线在线| 国产噜噜噜噜噜久久久久久久久| 欧美国产日韩亚洲一区| 亚洲电影av| 久久久亚洲国产天美传媒修理工| 亚洲免费视频网站| 欧美乱妇高清无乱码| 欧美激情1区2区3区| 亚洲成人直播| 欧美 日韩 国产精品免费观看| 国产精品一区视频网站| 一二三区精品福利视频| 在线一区二区日韩| 欧美精品免费在线| 91久久精品美女高潮| 亚洲国内自拍| 欧美成人免费观看| 亚洲精品国产系列| 亚洲精品视频在线| 欧美日韩国产一区二区三区| 欧美丰满高潮xxxx喷水动漫| 91久久精品国产91性色tv| 美女久久网站| 99这里有精品| 羞羞视频在线观看欧美| 国产精品专区第二| 欧美一区免费视频| 欧美高清不卡在线| 日韩视频在线观看免费| 欧美一区二区视频网站| 美女国产一区| 亚洲人成在线播放| 欧美日韩直播| 亚洲一区二区伦理| 久久久精品动漫| 在线成人黄色| 欧美三级在线| 亚洲视频www| 美女黄网久久| 亚洲精品视频在线观看免费| 国产精品yjizz| 亚洲欧美综合| 亚洲福利在线观看| 国产精品99久久不卡二区| 国产精品a久久久久久| 久久动漫亚洲| 亚洲美女淫视频| 免费欧美日韩| 亚洲色图在线视频| 极品少妇一区二区| 欧美日本亚洲| 欧美在线日韩在线| 欧美大尺度在线| 欧美中文在线观看| 亚洲欧洲一区| 精品91在线| 欧美日韩亚洲综合在线| 久久久国产精品一区二区中文| 亚洲黄色片网站| 久久五月天婷婷| 亚洲天堂男人| 亚洲国产视频一区| 国产精品网站在线播放| 久久免费高清| 欧美影院在线| 中文亚洲欧美| 亚洲九九爱视频| 欧美成人官网二区| 久久婷婷丁香| 欧美一区二区三区视频免费播放| 一本色道精品久久一区二区三区|