Isn't life wonderful
Sep 05, 2023
Last reply: 2 years ago
29 Replies
formatting link
Am 05.09.2023 um 15:19:14 Uhr schrieb Chris Elvidge:
And that is called security? For me it looks like bank's security isn't real security if that can be disabled with a product that can be bought by everyone.
Many things can be broken with the aid of a battery powered drill or angle grinder that anyone can buy.
The article talks about interception or tapping so it sounds like they managed to tap the link between the ATM and the bank and figure out how to fake a bank's OK response to the request from the ATM using a Pi to do the work.
Chances are the bank was depending on the line being secure rather than using good encryption to provide secure communications over an insecure line.
Banks have been aware of the need to encrypt communications for many decades.
In this case:
| According to court records, the three used a device called a | “raspberry pi” that is plugged into ATMs and deactivates its security | systems so they could remove the cash drawer.
My guess is they compromised some kind of software-controlled electronic lock.
Don't wander around at night carrying a Raspberry Pi or you might be arrested for "going equipped"!
---druck
My guess is that the ATMs were the on-third-party premises kind. They are available second-hand in an uncontrolled market, and various online videos have surfaced showing teardowns - for which some study has revealed software exploits.
On the subject of ATMs
Funny true story "The ATM Glitch That Made a Millionaire"
formatting link
Am 05.09.2023 um 20:52:58 Uhr schrieb Richard Kettlewell:
Why is it possible to plug something in without having to crack a door open or similar? Why isn't the software access directly at the hardware secured by a password?
Maybe they did crack a door open. The information presented is very thin.
Maybe it is, and the Pi was somehow involved in bypassing that.
Another possibility would be authentication based on some physical token (e.g. a smartcard) with the Pi emulating it and attacking the control software via that channel.
Because the ATM is designed to be installed in a secured room? The only think anybody needs to enter it for is the stuff more cash into its cash drawer (or in India, where ATMs typically can accept as well as pay out cash), to remove incoming cash from its deposit drawer.
No need. You typically need a physical key to access the cont of the ATM's cash drawer(s). Each ATM is run by its own copy of a fairly dumb finite state machine (FSM), which knows just enough to run its display, handle the smartcard reader and interpret the punter's key presses. The ATM's controlling FSM is in turn overseen by an ATM network management process running on a bigger box back at head office.
Marco,
How come you think that neither (door, password) was present ? What's your underbuilding for it ?
Also, what makes you think they "plugged something in" to begin with ? The security-system "hacking" intruders on TV always seem to be using "alligator clip" wires connected to some gizmo they bring with them.
In this case the Pi /could/ have been connected to a dummy bank card (with a thin flat cable) and used to emulate a special kind of smart-card. Who knows ...
IOW, when thinking about *possibilities*, be carefull not to put them forward as if they are facts (and /especially not/ post complaints based on such "facts").
Regards, Rudy Wieser
P.s. You might like the below link :
formatting link
I should have added that, at least back in the 90s when I was dealing with ATM networks and the software that interfaces that network to the financial system the ATM network is front-ending, the network was typically using X.25 or SDLC (if connected to an IBM box).
I'd imagine the RPi was being used to emulate an idle ATM while the actual ATM's cash drawers were being emptied: because it would be normal for an ATM to report access to its cash drawer(s) to the network manager both as a security check as well as to report events such as the machine running out of cash to the network operators. The short disconnections while the RPi was plugged in and removed would typically be reported as network blips but otherwise ignored because the ATM network protocols are typically fairly fault tolerant.
Am 06.09.2023 um 12:49:18 Uhr schrieb Richard Kettlewell:
A good concept of that is that such a card carries information like a certificate or a password, so simply emulating such a card cannot go around the normal authentication.
<pedant>
Robbery is stealing something from someone by using force or threatening to use force.
So it should be "raspberry-pi-used-to-steal-from-atm"
</pedant>
Remember SMS spotting has a per spot cost to SOTA and so it should be used only when your mobile internet connection is not available at the summit.
73 Andy
How did that get there and not in an email. :-(
That’s what the reporting says. Whether it’s accurate or not I can’t say, but that’s what we’ve got to work with.
Richard,
I've read the linked article, and all it says is "nor was it confirmed how the Pis were used beyond as tools to bypass security somehow". IOW, no "plugged in" of any kind mentioned. For all I know they used it as a wedge to keep the cash drawer open. :-)
Yes, I did read that article. Though alas, the "EverythingLubbock" link just shows an "not available in your region" page to me.
Regards, Rudy Wieser
[ snip ]
Really? I had a drive thru ATM reboot on me once, The boot screen said it was running Windows. Any chance it was a case of a bigger box way back at the head office rebooting and displaying a reboot screen on that ATM. Not a chance! The bank was Synovis.
A good many of them were running Windows NT when Microsoft ended support - ISTR hearing the banks negotiated a support extension.
That being said this doesn't invalidate the claim that they run a fairly dumb FSM (flying spaghetti monster) under Windows NT.
That's how they were originally, but these days some run Windows (often out o support versions) and serve advertising while you try to get your cash out. They offer the a huge range of world class vulnerabilities that only Microsoft can provide.
---druck
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required