Quantcast

Don't have an account? Register Now! Forgot password?

Maximum IT
News

Hackers Targeting Windows XP-Based ATM Machines

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

We're not going to start hiding our millions under our mattress (that's right, all bloggers roll in obscene amounts of money and own private jets), but the next time we withdraw a wad of cash, it might be a good idea to skip the ATM and flirt with a real live teller instead. That's because about 20 ATMs, mostly in Eastern Europe, have recently been hacked and are thought to be a testing ground before spreading to other ATMs, including those in the U.S.

"Trustwave's SpiderLabs performed the analysis of malware found installed on compromised ATMs in the Eastern European region," TrustWare said. "This malware captures magnetic stripe data and PIN codes from the private memory space of transaction-processing applications installed on a compromised ATM."

According to the report, the compromised ATMs all ran Microsoft's Windows XP operating system. The malware is installed and activated through a dropper file and once compromised, hackers then have full control over the machine via a customized user interface and accessible by inserting a special controller card into the ATM.

"This malware is unlike any we have ever had experiece with," TrustWare added.

Image Credit: ITNews

COMMENTS
avatarAtm skimmers+pinpads

Examples of our product:
http://img13.imageshack.us/img13/3775/pinpad.jpg
http://img13.imageshack.us/img13/8742/skimmer7708.jpg
You might know just how much money you can make with this (hint: $100k + in a weekend is normal) We manufacture and sell products to attach on the exterior of an ATM machine to record the magnetic swipe data, and a pinpad to record the pins pressed. The equipment comes in two models, wireless transfer via SMS GSM and non-wireless. With the GSM wireless model, you can recieve the tracks and pins remotely. Making new non-legit cards is trivial with a MSR206 (magstripe writer/reader). And then cash out.
For more details, or if you wish to make an enquiry about buying our atm skimmers contact us on ICQ messenger 570371134 or on email, kazr23@safe-mail.netto check out our website, photos, and the catalog with much more information, technical specs, videos and photos. thanks.

Login or register to post comments
avatarWoof!

Yet another way to end up making license plates for several years.

Login or register to post comments
avatarWoof!

Yet another way to end up making license plates for several years.

Login or register to post comments
avatarYeah, so ATM's aren't so secure

What happened to the ATM encryption and Trace back? BIG Danny :)

Login or register to post comments
avatarI do not think the ATMs

I do not think the ATMs themselves are at risk here. Trying to rob an ATM is not a very rewarding business for robbers. Too much efforts for a limited amount of money. I would tend to think that the people doing this are more interesting in collecting CC data and then sell it on the black market.

An ATM is basically a safe with a PC, an LCD monitor and some additional devices. Running XP on an ATM! So what? ATMs have been running OS/2, then XP for years. In the last decade, Linux-based ATMs also appeared.

ATMs are not on the Internet. Installing cracking software on an ATM requires physical access to the insides of the ATM.  IMHO, I think it is only possible with insider complicity at the ATM provider, branch management or ATM service (bills replenishment and maintenance) provider levels.

Login or register to post comments
avatarI'm sorry, but...

Everyone on the site loses points for typing "ATM MACHINE." That's what the M stands for. That's like saying portable document format format. No nerd cred for you!

Login or register to post comments
avatarI just finished a Java

I just finished a Java assignment for school. Divide by zero was handled:

 

if ((this.rightWOperand == 0) || (this.rightROperand == 0))

             this.errorState = true;

 

You're welcome "Smart" ship.

Login or register to post comments
avatarHackers

Boy those pesky hackers are something else arent they?

 

RT
http://www.online-privacy.vze.com

Login or register to post comments
avatarNuclear

I have heard they run it in nuclear power plants too. how about that. steve gibson was just ranting about this very thing a few weeks ago. must have gave them the idea.

 How do you go about finding out if your local atm is running windows...it would be kinda awkward calling and asking. 

Login or register to post comments
avatar   This is what happens

   This is what happens when you promote XP over every other OS out there. Yes, XP is great, yes XP is secure, but that doesn't mean it's perfect. The fanboys have taken over!!! RUN FOR YOUR LIFE! 

 

◘•↑OfNeutrals↨♠and♠↨Extremes↓•◘

Login or register to post comments
avatarAdd me to the "Windows on

Add me to the "Windows on the ATM, WTF" group of people.  I mean, this is insane!  Seriously, what's next,  Windows on your Electronic Voting machines?  Oh, wait...

Login or register to post comments
avatarHow to spot the WinXP ATM's?

Anyone know what banks are affected or the manufacture of the ATM's that have WinXP on them? I like XP but would prefer some software written specifically for my ATM's!

Login or register to post comments
avatarWindows XP is seriously on

Windows XP is seriously on some ATM machines? Wow, who is the idiot that would come of with that smart idea? 

Login or register to post comments
avatarWindows XP on an ATM Machine

Windows XP on an ATM Machine Seriously?  Aren't you just asking for trouble.  And they are freely connected to the internet?  Can't wait to be using an ATM machine and experience a blue screen of death right in the middle of a transaction.

Login or register to post comments
avatarits him!

http://www.technovelgy.com/graphics/content08/john-connor-easy-money.jpg

Either He's real or It's Viral Marketing from the new movie lolz.

______________________________________________

he's pwning with a trackpad? oh really? oh reheheheeally?

Login or register to post comments
avatarCould try Vi$ta

Well that puts the emphassis on M$ as some like to type.

Login or register to post comments
avatarDivide By Zero!

Almost as bad as a divide-by-zero error crashing a U.S. naval warship...

http://www.wired.com/science/discoveries/news/1998/07/13987

 

 

Login or register to post comments
avatarCurrent Attack Vector

I think the current attack vector is an early version of the malware sample, and future attacks will add functionality such as propagation via the ATM network.

 

 ------

http://www.atmsecurity.com

Login or register to post comments
This Month's Issue
FEATURE Windows XP/Vista/7 Tips!FEATURE Monitor Roundup: 7 LCDs ReviewedHOW TOMaster PhotoshopFEATUREAMD's Awesome New GPUWHITE PAPEROrganic LEDs