Skip to navigation
Latest News

Hacker tricks ATM into doling out free cash

money

By Reuters

Posted on 29 Jul 2010 at 08:22

A security expert showed off techniques for breaking into ATMs, causing machines to spit out cash to a cheering crowd at Black Hat in Las Vegas.

"I hope to change the way people look at devices that from the outside are seemingly impenetrable," Barnaby Jack, director of research at security consulting firm IOActive Labs, told a standing-room-only crowd before launching the demonstration using equipment he purchased over the internet.

I'm not naive enough to think I'm the only person who can do it

He spent over a year learning to break into stand-alone bank machines found at gas stations, bars and retail establishments.

At the annual Black Hat conference, Jack showed how he could upload his home-brewed piece of software dubbed Dillinger - named after the infamous bank robber - to an ATM made by privately held Tranax Technologies. After he infected the ATM, he approached the machine and instructed it to start dispensing cash.

Jack used a key available over the internet to open the case of an ATM from privately held Triton Systems, then inserted a USB thumb drive that forced the machine to spit out its entire jackpot.

The ATMs he tested run on Windows CE.

He said both the ATM makers have issued software that would prevent hackers from repeating the same attacks he performed onstage, but he added that ATMs from all manufacturers are still vulnerable to attack.

"I'm not naive enough to think I'm the only person who can do it," he said.

He also said he believed that the ATMs used by financial institutions were also vulnerable, but that he had not simulated any attacks because he had not been able to get hold of any bank ATMs.

Bob Douglas, vice president of engineering for Triton, said he was not aware of any successful attacks on his company's equipment.

Officials with Tranax could not be reached for comment.

User comments

John Connor was already doing this back in '92.

Easy money...

By lkipper on 29 Jul 2010

I don't know the insides of these things - but if you've got a key to open the case, wouldn't a big hammer serve just as well to get at the contents? After all, it's not as if you're not going to be noticed?

By AdrianB on 29 Jul 2010

kipper: the technology has hardly moved on since 1992, many atm's such as the ones describe in the article connect to a network via GSM.

Adrian: the money is stored in impenetrable hoppers/caddies within the machine.

By dodge1963 on 29 Jul 2010

Thanks dodge - though I'll fail to resist the temptation to say "I'll bet Dr Who's Sonic Screwdriver could get into the impenetrable hoppers!"

By AdrianB on 29 Jul 2010

Leave a comment

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links

ADVERTISEMENT

 
SEARCH
SIGN UP

Your email:

Your password:

remember me

ADVERTISEMENT

advertisement


Hitwise Top 10 Website 2009
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.