Slashdot Log In
Googling for ATM Master Passwords
Posted by
Zonk
on Thu Sep 21, 2006 03:31 PM
from the that-should-probably-not-be-online dept.
from the that-should-probably-not-be-online dept.
default DOLLAR writes to mention an eWeek article following up on the ATM reprogramming scam pulled in Virginia Beach last week. A security researcher in New York has used a YouTube video, a few Google searches, and other legal methods to discover the master passwords to thousands of ATMs across the country. From the article: "Dave Goldsmith, founder and president of penetration testing outfit Matasano Security, in New York, did not say how he obtained the operator manual--which contains master passwords and other sensitive security information about the cash-dispensing machines--but an eWEEK investigation shows that a simple Google query will return a 102-page PDF file that provides a road map to the hack."
Related Stories
[+]
Another ATM Maker Pwned by Googling 252 comments
bagsc writes "Kevin Poulsen of Wired.com strikes fear into another ATM manufacturer. This time, Triton ATMs had their super-secret master codes revealed by simple Google searches. Tranax was the most recent company with this problem, but probably not the last."
[+]
Slashback: ITunes, Debian, ATMs 122 comments
Slashback tonight brings some clarifications and updates to previous Slashdot stories, including: iTunes 7.0, Wal-Mart threatens studios over iTunes sales, debate over a proposal to fund Debian, and Googling for ATM master passwords. Read on for details.
Offsite: Wired Coverage
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Giddy-up! (Score:5, Funny)
Re:Giddy-up! (Score:5, Informative)
This technique was posted on Boing Boing and Bruce Schneier a couple of weeks ago. Still. Plenty of good stuff out there.
Parent
Re:Giddy-up! (Score:5, Informative)
Parent
Re:Giddy-up! (Score:5, Funny)
Parent
Trivial search - and the password is.... (Score:4, Funny)
12345
Oh wait. That's my ATM PIN.
Re:Trivial search - and the password is.... (Score:5, Funny)
Parent
Re:Trivial search - and the password is.... (Score:4, Funny)
Parent
Casino (Score:5, Informative)
I couldn't believe it.
Re:Casino (Score:5, Insightful)
All that's in the PDF is the default password, following a warning in BIG BOLD TYPE saying that you need to change the default password before deploying the machine. Would they put in a new combination lock on their vault and leave a combo of 1-2-3? I should hope not...
Parent
Re:Casino (Score:4, Interesting)
Casinos prosecute is you steal $5 from them.
Parent
Aha! (Score:5, Funny)
We're rich!! We're rich!!! (Score:5, Funny)
That's to all of you who made fun of us geeks!
*Rude Hand Gesture*
That's for every bully who ever shoved someone into a locker during PE.
Due to our superior ability to manipulate poorly secured cash dispensing devices, we shall now rule the world!
First the treasury...then the military. World domination cannot be far behind.
2 cents,
QueenB
Re:We're rich!! We're rich!!! (Score:5, Funny)
Please enter a multiple of $5 or $20.
Parent
Nine Days.... (Score:5, Funny)
Re:Nine Days.... (Score:5, Insightful)
It's called honesty and ethics.
But if you leve your car door unlocked, and someone takes it, I'm sure you won't mind, since it was your 'fault'.
Parent
WOW (Score:5, Informative)
It says that to enter the management screen you hold the key and press one. Then the default UID is 00 and the default password is 12345 so you should enter 0012345 into the prompt.
I am off to the ATM down stairs. I could use a little extra cash.
"Gawd, Idiots!" (Score:5, Insightful)
there's enough clues in the article..... (Score:5, Informative)
No, I don't have the manual. I don't really care either, it was an interesting academic exercise.
ATM Industry Association warned them. (Score:5, Interesting)
http://www.gasa-cognito.com/media/GASA-ATMIA%20Fra ud%20Alert1.pdf#search=%22atm%20master%20password% 22 [gasa-cognito.com]
It specifically warned the industry that their passwords were getting out and to tell the banks to CHANGE them.
Frankly, I have zero sympathy for the bank that lost cash.
And not much respect for the idiots that did not report it. What, did they think the banks would never find out what happened? That when they did find out, they would not 'correct' the accounts?
Either report it, or get yourself an untraceable card and return.
Re:The default password is... (Score:5, Informative)
Parent
Re:The default password is... (Score:5, Funny)
Parent
Re:The default password is... (Score:5, Insightful)
Parent
Ready-Set -Go (Score:5, Funny)
Which one gets fixed first!
Parent
Re:The default password is... (Score:5, Insightful)
I would say that's incorrect. It should be a trivial matter for the software to be written to REQUIRE the default password to be changed before the machine will actually give out money. Rather like having to immediately change your password when you first login to an account. It's not a difficult concept, and while this is technically a 'lack' of a feature rather than a bug, it's certainly a flaw in design, and a pretty basic one at that.
Parent
Re:Has to be said (Score:4, Informative)
Parent