Hackers Targeting Windows XP-Based ATM Machines
Posted 06/04/09 at 03:30:20 PM by Paul Lilly
We're not going to start hiding our millions under our mattress (that's right, all bloggers roll in obscene amounts of money and own private jets), but the next time we withdraw a wad of cash, it might be a good idea to skip the ATM and flirt with a real live teller instead. That's because about 20 ATMs, mostly in Eastern Europe, have recently been hacked and are thought to be a testing ground before spreading to other ATMs, including those in the U.S.
"Trustwave's SpiderLabs performed the analysis of malware found installed on compromised ATMs in the Eastern European region," TrustWare said. "This malware captures magnetic stripe data and PIN codes from the private memory space of transaction-processing applications installed on a compromised ATM."
According to the report, the compromised ATMs all ran Microsoft's Windows XP operating system. The malware is installed and activated through a dropper file and once compromised, hackers then have full control over the machine via a customized user interface and accessible by inserting a special controller card into the ATM.
"This malware is unlike any we have ever had experiece with," TrustWare added.

Image Credit: ITNews
Atm skimmers+pinpads
Submitted by anonuser on Sun, 06/28/2009 - 6:45pm
Examples of our product:
http://img13.imageshack.us/img13/3775/pinpad.jpg
http://img13.imageshack.us/img13/8742/skimmer7708.jpg
You might know just how much money you can make with this (hint: $100k + in a weekend is normal) We manufacture and sell products to attach on the exterior of an ATM machine to record the magnetic swipe data, and a pinpad to record the pins pressed. The equipment comes in two models, wireless transfer via SMS GSM and non-wireless. With the GSM wireless model, you can recieve the tracks and pins remotely. Making new non-legit cards is trivial with a MSR206 (magstripe writer/reader). And then cash out.
For more details, or if you wish to make an enquiry about buying our atm skimmers contact us on ICQ messenger 570371134 or on email, kazr23@safe-mail.netto check out our website, photos, and the catalog with much more information, technical specs, videos and photos. thanks.
Woof!
Submitted by domih2009 on Thu, 07/02/2009 - 9:08pm
Yet another way to end up making license plates for several years.
Yeah, so ATM's aren't so secure
Submitted by dcdannyf on Tue, 06/16/2009 - 9:26am
What happened to the ATM encryption and Trace back? BIG Danny :)
I do not think the ATMs
Submitted by domih2009 on Sat, 06/06/2009 - 10:47am
I do not think the ATMs themselves are at risk here. Trying to rob an ATM is not a very rewarding business for robbers. Too much efforts for a limited amount of money. I would tend to think that the people doing this are more interesting in collecting CC data and then sell it on the black market.
An ATM is basically a safe with a PC, an LCD monitor and some additional devices. Running XP on an ATM! So what? ATMs have been running OS/2, then XP for years. In the last decade, Linux-based ATMs also appeared.
ATMs are not on the Internet. Installing cracking software on an ATM requires physical access to the insides of the ATM. IMHO, I think it is only possible with insider complicity at the ATM provider, branch management or ATM service (bills replenishment and maintenance) provider levels.
I'm sorry, but...
Submitted by benvoliothefirst on Fri, 06/05/2009 - 3:33pm
Everyone on the site loses points for typing "ATM MACHINE." That's what the M stands for. That's like saying portable document format format. No nerd cred for you!
I just finished a Java
Submitted by pcfxer on Fri, 06/05/2009 - 12:05pm
I just finished a Java assignment for school. Divide by zero was handled:
if ((this.rightWOperand == 0) || (this.rightROperand == 0))
this.errorState = true;
You're welcome "Smart" ship.
Hackers
Submitted by AsanDanny on Fri, 06/05/2009 - 3:32am
Boy those pesky hackers are something else arent they?
RT
http://www.online-privacy.vze.com
Nuclear
Submitted by lataesippinyuppie on Thu, 06/04/2009 - 6:50pm
I have heard they run it in nuclear power plants too. how about that. steve gibson was just ranting about this very thing a few weeks ago. must have gave them the idea.
How do you go about finding out if your local atm is running windows...it would be kinda awkward calling and asking.
This is what happens
Submitted by ONaE on Thu, 06/04/2009 - 6:07pm
This is what happens when you promote XP over every other OS out there. Yes, XP is great, yes XP is secure, but that doesn't mean it's perfect. The fanboys have taken over!!! RUN FOR YOUR LIFE!
◘•↑OfNeutrals↨♠and♠↨Extremes↓•◘
Add me to the "Windows on
Submitted by jcollins on Thu, 06/04/2009 - 1:40pm
Add me to the "Windows on the ATM, WTF" group of people. I mean, this is insane! Seriously, what's next, Windows on your Electronic Voting machines? Oh, wait...
How to spot the WinXP ATM's?
Submitted by worm8199 on Thu, 06/04/2009 - 1:01pm
Anyone know what banks are affected or the manufacture of the ATM's that have WinXP on them? I like XP but would prefer some software written specifically for my ATM's!
Windows XP is seriously on
Submitted by popstop785 on Thu, 06/04/2009 - 12:52pm
Windows XP is seriously on some ATM machines? Wow, who is the idiot that would come of with that smart idea?
Windows XP on an ATM Machine
Submitted by ZayLay on Thu, 06/04/2009 - 12:48pm
Windows XP on an ATM Machine Seriously? Aren't you just asking for trouble. And they are freely connected to the internet? Can't wait to be using an ATM machine and experience a blue screen of death right in the middle of a transaction.
its him!
Submitted by smashingpumpin on Thu, 06/04/2009 - 12:34pm
http://www.technovelgy.com/graphics/content08/john-connor-easy-money.jpg
Either He's real or It's Viral Marketing from the new movie lolz.
______________________________________________
he's pwning with a trackpad? oh really? oh reheheheeally?
Could try Vi$ta
Submitted by DrMD on Thu, 06/04/2009 - 12:25pm
Well that puts the emphassis on M$ as some like to type.
Divide By Zero!
Submitted by Stever on Fri, 06/05/2009 - 7:03am
Almost as bad as a divide-by-zero error crashing a U.S. naval warship...
http://www.wired.com/science/discoveries/news/1998/07/13987
Current Attack Vector
Submitted by Simonboura on Tue, 10/27/2009 - 10:06am
I think the current attack vector is an early version of the malware sample, and future attacks will add functionality such as propagation via the ATM network.
------
http://www.atmsecurity.com
Feature
Review
Feature
Feature
Feature






