[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label ATM. Tampilkan semua postingan
Tampilkan postingan dengan label ATM. Tampilkan semua postingan

28/10/11

More Mac malware - new Tsunami backdoor variants discovered

WavesAs our friends at ESET have mentioned on their blog, new variants of the latest Mac malware - the Tsunami backdoor Trojan - have been discovered.

SophosLabs has received a few new samples of the malware - which can be used both to launch denial-of-service attacks and by remote hackers to gain access to your computer.

The new versions, which Sophos is adding detection for as OSX/Tsunami-Gen, are builds for 32-bit Intel x86 and PowerPC Mac computers, whereas the original version was 64-bit only. In addition, the new samples use a different IRC domain for their command & control server.

Some folks have questioned why the computer security industry has dubbed this threat "Tsunami", and I must admit that I find myself feeling somewhat uncomfortable with the name because of the devastating natural disasters that have struck in some parts of the world.

The truth is, however, that the name derives from one of the commands that can be sent to computers running the malicious code, to flood a target with internet traffic.

Tsunami command

It's actually the same command that was built into the Linux version of the attack tool (which Sophos calls Troj/Kaiten) first seen some years ago.

Because we see considerably less malware for Mac OS X than we do for Windows, new Mac threats tend to make the news headlines. It's important to note that the sky is not falling, and we believe the threat posed by OSX/Tsunami is currently quite low. Indeed, we have not received any reports from customers yet of infections by this Mac malware.

Nevertheless, it's clear that someone is working on developing new versions of this code for the Mac platform and you have to presume they are not doing it purely for the intellectual challenge. (If they are, Lord help them.. it's not much of a challenge)

Mac users would be wise to take preventative steps against this, and the other malware which we see for the Mac OS X platform. Free anti-virus software is available for Mac home users - so there's really no excuse.
Read More...

14/10/11

ATM Skimmer Powered by MP3 Player

Almost a year ago, I wrote about ATM skimmers made of parts from old MP3 players. Since then, I’ve noticed quite a few more ads for these MP3-powered skimmers in the criminal underground, perhaps because audio skimmers allow fraudsters to sell lucrative service contracts along with their theft devices.

Using audio to capture credit and debit card data is not a new technique, but it is becoming vogue: Square, an increasingly popular credit card reader built for the iPhone, works by plugging into the headphone jack on the iPhone and converting credit card data stored on the card into audio files.

An audio skimmer for a Diebold ATM.

The device pictured here is a card skimmer designed to fit over the card acceptance slot on a Diebold Opteva 760, one of the most common ATMs around. The green circuit board on the left was taken from an MP3 player (no idea which make or model). When a card is slid past the magnetic reader (the small black rectangle at the end of the black and red wires near the center of the picture), the MP3 player “hears” the data stored on the card’s magnetic stripe, and records it as an audio file to a tiny embedded flash memory device.


The card skimmer comes with a false panel that fits snugly into the top of the ATM; it contains a miniature video camera that records victims entering their PIN when the card skimmer slot is activated. The battery included in the hidden camera lasts for six hours, according to the ad posted by the skimmer’s designer. The entire package costs $1,500, payable via virtual currencies such as WebMoney and Liberty Reserve.

The vendor of this skimmer kit advertises “full support after purchase,” and “easy installation (10-15 seconds).” But the catch with this skimmer is that the price tag is misleading. That’s because the audio files recorded by the device are encrypted. The Mp3 files are useless unless you also purchase the skimmer maker’s decryption service, which decodes the audio files into a digital format that can be encoded onto counterfeit ATM cards.

In fairness, the seller does note in the fine print that third party software is required to decrypt the audio files, and that he is “working closely with another partner for this service.” That partner is a different fraudster who will decrypt the audio files in exchange for 20 percent of the stolen card numbers and PINs. Read More...

21/09/11

Microsoft dumps partner over telephone scam claims

One of Microsoft's Gold Partners has had its relationship with the software giant unceremoniously terminated, after being revealed to be orchestrating a telephone support scam.

Comantra, based in India, are said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections.
The bogus support calls came from Comantra employees who claimed to be representing Microsoft, and used scare tactics to talk users into opening the Event Viewer on Windows, where a seemingly dangerous list of errors would be seen.

Once terrified by what appears to be a worrying collection of warning messages, and believing this was evidence of a malware infection, users would be tricked into allowing Comantra technicians to gain remote access to their computer, and hand over their credit card details to fix any "problems".
In the past, vulnerable elderly people have even been told by scammers that heavy rain may have caused a computer virus infection.

What makes the scam particularly audacious is that during the scam campaign, Comantra were a certified Gold partner of Microsoft, and when quizzed by skeptical computer owners would use their status to trick potential victims into believing the call was legitimate.
Comantra website
A search for "Comantra" on the internet finds a large number of posts and complaints about the scam telephone calls, stretching back over 18 months. Some users have even asked on Microsoft's own message forums how it is possible for the firm to have "Gold Partner" status.

As PC Pro reports, a Microsoft spokesperson has now confirmed that Comantra has at long last been struck off their Gold Partner list:
"We were made aware of a matter involving one of the members of the Microsoft Partner Network acting in a manner that caused us to raise concerns about this member's business practices. Following an investigation, the allegations were confirmed and we took action to terminate our relationship with the partner in question and revoke their Gold status."
"There are no circumstances under which we would ever allow partners or any other organisations to pose as Microsoft. We view matters such as these extremely seriously and take immediate action if such behaviour is brought to our attention and found to be the case."
Hmm.. Maybe someone should tell Comantra to update their website and remove that Gold Partner logo?

Comantra website with Gold Partner logo
Listen to this great podcast by Sophos experts Paul Ducklin and Sean Richmond where they discuss the problem of fake tech support calls, and the ways in which you can avoid falling for scams like this yourself:


(Duration 6:15 minutes, size 4.5MBytes)
Also, make sure that your family and friends are on their guard against suspicious tech support calls telling them about infections on their computer - even if the callers do claim to be from Microsoft. It only takes a lapse of common sense for you to hand your credit card details straight down the line to a criminal.

nb : nakedsecurity.sophos
Read More...

20/09/11

Gang Used 3D Printers for ATM Skimmers

An ATM skimmer gang stole more than $400,000 using skimming devices built with the help of high-tech 3D printers, federal prosecutors say.

Before I get to the gang, let me explain briefly how ATM skimmers work, and why 3D printing is a noteworthy development in this type of fraud. Many of the ATM skimmers profiled in my skimmer series are carefully hand-made and crafted to blend in with the targeted cash machine in both form and paint color. Some skimmer makers even ask customers for a photo of the targeted cash machine before beginning their work.

The skimmer components typically include a card skimmer that fits over the card acceptance slot and steals the data stored on the card’s magnetic stripe, and a pinhole camera built into a false panel that thieves can fit above or beside the PIN pad. If these components don’t match just-so, they’re more likely to be discovered and removed by customers or bank personnel, leaving the thieves without their stolen card data.

Enter the 3D printer. This fascinating technology, explained succinctly in the video below from 3D printing company i.materialise, takes two dimensional computer images and builds them into three dimensional models by laying down successive layers of powder that are heated, shaped and hardened.

3D printing in action from i.materialise on Vimeo.

Apparently, word is spreading in the cybercrime underworld that 3D printers produce flawless skimmer devices with exacting precision. Last year, i-materialise blogged about receiving client’s order for building a card skimmer. The company said it denied the request when it became clear the ordered product was a fraud device.


3D printer firm i.materialise received and promptly declined orders for this skimmer device - a card acceptance slot overlay
In June, a federal court indicted four men from South Texas (PDF) who authorities say had reinvested the profits from skimming scams to purchase a 3D printer. According to statements by the U.S. Secret Service, the gang’s leader, Jason Lall of Houston, was sent to prison for ATM fraud in 2009. Lall was instrumental in obtaining skimming devices, and the gang soon found themselves needing to procure their own skimmers. The trouble is, skimmer kits aren’t cheap: They range from $2,000 to more than $10,000 per kit.

Secret Service agents said in court records that on May 4, 2011, their undercover informer engaged in a secretly taped discussion with the ring’s members about a strategy for obtaining new skimmers. John Paz of Houston, one of the defendants, was allegedly the techie who built the skimming devices using a 3-D printer that the suspects purchased together. The Secret Service allege they have Paz on tape explaining the purchase of the expensive printer.

“When [Lall was] put in jail, we asked, ‘What are we going to do?’ and we had to figure it out and that’s when we came up with this unit,” Paz allegedly told the undercover officer.

The government alleges Paz also was the guy who encoded the stolen card data onto counterfeit cards. The feds say Albert Richard of Missouri City, Texas prepared ATMs at numerous banks where the skimming devices were installed, by covering the ATM cameras or spray-painting over them, and by acting as a lookout.

A fourth defendant, John Griffin, is alleged to have used the counterfeit cards to withdraw funds at different ATMs around Texas. Prosecutors allege the group stole more than $400,000 between Aug. 2009 and June 2011. Prior to their arrest this summer, the gang started making decent money but they split the profits between them. Federal prosecutors say the men stole $57.808.14 in month of April 2011 alone (yes, that’s an odd amount to have come out of ATMs, but I digress).

The court documents don’t say how much the men spent on the 3D printer, nor do they include pictures of the fraud devices. The Secret Service declined to offer more details, citing an ongoing investigation. But i.materialize’s Franky De Schouwer said a high quality 3D printer can be had for between $10,000 and $20,000.

“Just looking at the idea of 3D printing a potential skimming device, a criminal could invest in buying a desktop 3D printer,” De Schouwer wrote in an email to KrebsOnSecurity. “Not a kit printer in the line of a Makerbot or a RepMan but a desktop printer of a high end manufacturer of 3D printers like Objet, 3D Systems or Stratasys (HP). You could get one of those between $10,000 – $20,000 and they will print a high quality skimming device that, including some post finishing, will look like the real thing.”

De Schouwer said his company thankfully hasn’t had any more requests to print ATM skimming devices. But that doesn’t mean the demand has gone away.

“We do notice that some people end up on our blog with the keywords ‘I want to buy an ATM skimming device,” he said.

nb : krebsonsecurity Read More...

14/09/11

Hackers steal credit card details at Wisconsin and Tennessee Wilderness resorts

Credit card loss at vacation resortsBad news if you have been on vacation at one of the Wilderness resorts in Tennessee and Wisconsin in the last couple of years - hackers may now have your credit card details.

VacationLand Vendors Inc, a firm which provides arcade and vending machines to businesses, has revealed that a hacker broke into its credit card processing systems and stolen up to 40,000 credit card details.

The credit cards were used in arcades at the Wilderness Hotel & Golf Resort in Wisconsin, and the Wilderness at the Smokies Waterpark Resort in Tennessee.
Precise details of how the data breach occurred have not been made public, but the company has published a warning on its website, and advised customers to keep their eyes peeled for unusual transactions on their credit cards.

Statement from VacationLand Vendors

Vacationland Vendors says that it "deeply regrets" the security breach and shut down its systems at the affected arcades as soon as it discovered the problem on March 25, 2011 - but that patrons may be impacted as far back as December 12, 2008.

The FTC has produced a website all about how consumers can protect themselves against identity theft.

nb : nakedsecurity.sophos
Read More...

29/08/11

Cisco Aims for a Go-anywhere Router



Cisco Systems made its fortune selling routers for the cores of enterprise and service-provider networks, but now the company is sending its technology farther from those cozy confines than ever before.

The Cisco Integrated Services Router 819 Machine-to-Machine Gateway, available immediately, is the smallest member of the ISR family of branch and remote-office routers and is designed to withstand outdoor environments with extreme temperatures. Target markets for the device include truck fleets, tollbooths and ATMs (automated teller machines). The ISR 819 can also serve as a conventional router in a remote office, said Inbar Lasser-Raab, senior director of marketing for borderless networks.

Unlike most routers, the 819 relies primarily on cellular data to reach the Internet. This opens up more possible uses for the router, including moving vehicles. The router, which weighs only 2.3 pounds (1 kilogram) and is thicker but smaller than a tablet, starts at US$1,600. A slightly larger, hardened version, which is waterproof and has a temperature range from -13 degrees to 140 degrees Fahrenheit (-25 to 60 Celsius), starts at $2,300.

To ensure communication in isolated locations, the ISR 819 is equipped for 3G connectivity. It is available with both GSM (Global System for Mobile Communications) and CDMA (Code-Division Multiple Access) technology and has room for two SIM (Subscriber Identity Module) cards, so users can set up service with two different mobile operators for redundancy. Cisco is also eyeing 4G capability next year, though most machine-to-machine (M2M) applications aren't bandwidth-hungry.

M2M (machine-to-machine) networking is expected to grow rapidly in the coming years. Functions such as meter-reading, asset tracking and supply-level notifications can be automated through radios built into systems in the field, and wireless links can help to make it easier to network those devices.

As an example of how this type of device could work, a small wireless router in an ATM could send a signal when the amount of cash available in the machine fell to a certain level. It could immediately communicate over the cellular network to a similar router in an armored truck, and the driver of the truck would be given instructions to deliver more cash to that ATM.

Trucks, vending machines and other systems in the field have had wireless connectivity before, but Cisco calls the ISR 819 its first router for these types of applications that has all the features of the popular ISR line. For example, it includes stateful and application-inspection firewall capability, encryption for VPNs (virtual private networks), and features to optimize voice and video, according to Cisco.

There are 3G routers on the market from smaller vendors, but the fact that the 819 has the same software as Cisco's other popular ISR models is likely to make it more attractive to enterprises that have already invested in Cisco, said analyst Mike Spanbauer of Current Analysis. Cisco is more dominant in the router market for small and medium-sized companies than it is even in other areas of switching and routing, Spanbauer said.
"It's more about operational efficiency than necessarily bringing out a new service that didn't exist before," Spanbauer said.

But because so many features are built into it, the 819 may inspire new uses of remote routers in the future, he said. It will probably take less custom code and help from consultants to get a new use case off the ground, he said.

"Having the collapsed service offering on a single device does breed simplicity and encourages creativity in deployment," he said.

A renewed commitment by mobile operators could also help to boost the use of machine-to-machine applications, said IDC analyst Rohit Mehra. Some carriers have been slow to support machine-to-machine because they were focused on keeping up with consumers' use of mobile data on smartphones, he said. M2M will be an important source of market growth now that almost all consumers have cellphones.

nb : pcworld Read More...

24 August 2011 | 2,803 views Stealing ATM Pin Numbers Using Thermal Imaging Cameras

Now this is a really neat bit of hardware hacking, it’s been a while since we’ve reported on any kind of ATM Skimming or ATM Hacking stories.

You may remember back in November 2010 – European Banks Seeing New Wave Of ATM Skimming or way back in 2008 when Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips.

The latest is this neat hack that came out of a method outlined by Michal Zalewski back in 2005:
Cracking safes with thermal imaging

Security researchers have found that thermal cameras can be combined with computer algorithms to automate the process of stealing payment card data processed by automatic teller machines.

At the Usenix Security Symposium in San Francisco last week, the researchers said the technique has advantages over more common ATM skimming methods that use traditional cameras to capture the PINs people enter during transactions. That’s because customers often obscure a camera’s view with their bodies, either inadvertently or on purpose. What’s more, it can take a considerable amount of time for crooks to view the captured footage and log the code entered during each session.
 Thermal imaging can vastly improve the process by recovering the code for some time after each PIN is entered. Their output can also be processed by an algorithm that automates the process of translating it into the secret code.

The hack works extremely efficiently on ATMs using plastic keypads, it will not work on metal keypads and this method works up to 60 seconds after you’ve used the ATM.

I’m not sure about you guys but all the ATMs I’ve seen here are using metal keypads, so it wouldn’t work too well over here.
Either way it’s a fairly cool hack and I’m glad to see, so far there’s no proof of thieves using it in the wild.
The findings expand on 2005 research from Michal Zalewski, who is now a member of Google’s security team. The Usenix presenters tested the technique laid out by Zalewski on 21 subjects who used 27 randomly selected PINs and found the rate of success varied depending on variables including the types of keypads and the subjects’ body temperature.

“In summary, while we document that post-hoc thermal imaging attacks are feasible and automatable, we also find that the window of vulnerability is far more modest than some feared and that there are simple counter-measures (i.e., deploying keypads with high thermal conductivity) that can shrink this vulnerability further still,” the researchers wrote.
I wonder if we’ll see a spate of real life attacks based around this technique now the paper has been published publicly.

You can grab the paper discussing the technique here: Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks [PDF].

nb : darknet Read More...

26/08/11

Stealing ATM Pin Numbers Using Thermal Imaging Cameras

Now this is a really neat bit of hardware hacking, it’s been a while since we’ve reported on any kind of ATM Skimming or ATM Hacking stories.
You may remember back in November 2010 – European Banks Seeing New Wave Of ATM Skimming or way back in 2008 when Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips.
The latest is this neat hack that came out of a method outlined by Michal Zalewski back in 2005:
Cracking safes with thermal imaging

Security researchers have found that thermal cameras can be combined with computer algorithms to automate the process of stealing payment card data processed by automatic teller machines.
At the Usenix Security Symposium in San Francisco last week, the researchers said the technique has advantages over more common ATM skimming methods that use traditional cameras to capture the PINs people enter during transactions. That’s because customers often obscure a camera’s view with their bodies, either inadvertently or on purpose. What’s more, it can take a considerable amount of time for crooks to view the captured footage and log the code entered during each session.
Thermal imaging can vastly improve the process by recovering the code for some time after each PIN is entered. Their output can also be processed by an algorithm that automates the process of translating it into the secret code.
The hack works extremely efficiently on ATMs using plastic keypads, it will not work on metal keypads and this method works up to 60 seconds after you’ve used the ATM.
I’m not sure about you guys but all the ATMs I’ve seen here are using metal keypads, so it wouldn’t work too well over here.
Either way it’s a fairly cool hack and I’m glad to see, so far there’s no proof of thieves using it in the wild.

The findings expand on 2005 research from Michal Zalewski, who is now a member of Google’s security team. The Usenix presenters tested the technique laid out by Zalewski on 21 subjects who used 27 randomly selected PINs and found the rate of success varied depending on variables including the types of keypads and the subjects’ body temperature.
“In summary, while we document that post-hoc thermal imaging attacks are feasible and automatable, we also find that the window of vulnerability is far more modest than some feared and that there are simple counter-measures (i.e., deploying keypads with high thermal conductivity) that can shrink this vulnerability further still,” the researchers wrote.
I wonder if we’ll see a spate of real life attacks based around this technique now the paper has been published publicly.
You can grab the paper discussing the technique here: Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks [PDF].

nb : darknet Read More...