ATM Software Flaws Left Piles of Cash for Anyone Who Knew to Look
Summary
Unlocking them with safecracking techniques, rigging them to steal users personal data and PINs, crafting and refining ATM malware and, of course, hacking them to spit out all their cash. But on Friday, independent researcher Matt Burch is presenting findings related to the “financial” or “enterprise” ATMs used in banks and other large institutions. The vulnerabilities, which the company says have all been patched, could be exploited by attackers to bypass an unpatched ATMs hard drive encryption and take full control of the machine. “The core deficiency that I’m exploiting is that the Linux partition was not encrypted.” Burch found that he could manipulate the location of critical system validation files to redirect code execution; in other words, grant himself control of the ATM. And Burch adds that he believes Diebold Nixdorf addressed the vulnerabilities on a more fundamental level in April with VSS version 4.4 that encrypts the Linux partition.