Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 700 Vote(s) - 3.53 Average
  • 1
  • 2
  • 3
  • 4
  • 5
NFC Flaws Leave ATMs Vulnerable

#1
A researcher managed to exploit ATMs through flaws of NFC, using his phone. This includes forcing it to spit out bills.

Quote:Many people have probably fantasized about getting more money out of an ATM than they have in their bank accounts. Some have even successfully tried all sorts of methods to exploit ATMs by physically tinkering with the machines’ hardware. But now, a researcher has managed to hack ATMs and other point-of-sale (POS) machines by simply waving his phone over a contactless card reader.

According to

[To see links please register here]

, Joseph Rodriguez, a security consultant at IOActive, managed to exploit a flaw in the NFC system of ATMs and POS systems found widely in shopping malls, restaurants, and retail stores. He used a phone with NFC and an Android app that he designed to infect the NFC reader chips of these machines with a variety of bugs to crash them, hack them to collect credit card data, invisibly change the value of transactions, and even “jackpot” some ATMs into spitting out cash. However, the last exploit also required manipulation of existing vulnerabilities in the ATMs’ software.

“You can modify the firmware and change the price to one dollar, for instance, even when the screen shows that you’re paying 50 dollars. You can make the device useless, or install a kind of ransomware. There are a lot of possibilities here,” Rodriguez told Wired. “If you chain the attack and also send a special payload to an ATM’s computer, you can jackpot the ATM-like cash-out, just by tapping your phone,” he added.

Rodriguez began his research into the ability to hack ATMs’ contactless card readers by buying NFC readers and point-of-sale devices from eBay. He soon discovered that many of them did not validate the size of the data packet being sent via NFC from a credit card to the reader. Using a custom Android app, he sent a data packet hundreds of times larger than what the machine expected, thereby triggering a “buffer overflow,” a decades-old software vulnerability that allows an attacker to corrupt a device’s memory and run their own code.

Rodriguez informed the affected brands and vendors of the security vulnerability about a year ago, but he says that the sheer number of devices that need to be physically patched is huge and will take a lot of time. The fact that many POS terminals don’t get regular software updates makes this flaw even more dangerous.

The researcher kept most of his findings hidden for a year but now pans to share technical details about them to push affected vendors to implement patches.

Read More:

[To see links please register here]

Reply

#2
Wow this is pure gold I wish I was informed enough to get an android setup with the software Id be good at the next steps haha
Reply

#3
Good good good good good Good good good good good
Reply

#4
"kept most of his findings hidden for a year"
the dude cashed out for a while, rite?
Reply

#5
really? crazy world out there
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through