Slashdot Mirror


Googling for ATM Master Passwords

default DOLLAR writes to mention an eWeek article following up on the ATM reprogramming scam pulled in Virginia Beach last week. A security researcher in New York has used a YouTube video, a few Google searches, and other legal methods to discover the master passwords to thousands of ATMs across the country. From the article: "Dave Goldsmith, founder and president of penetration testing outfit Matasano Security, in New York, did not say how he obtained the operator manual--which contains master passwords and other sensitive security information about the cash-dispensing machines--but an eWEEK investigation shows that a simple Google query will return a 102-page PDF file that provides a road map to the hack."

24 of 356 comments (clear)

  1. Giddy-up! by Logiksan · · Score: 5, Funny

    *runs off to Google and YouTube as fast as his little fingers will take him*

    1. Re:Giddy-up! by russ1337 · · Score: 5, Informative

      Well you can always find more interesting things by doing a Google search for: [Confidential "not for public release"] Like this

      This technique was posted on Boing Boing and Bruce Schneier a couple of weeks ago. Still. Plenty of good stuff out there.

    2. Re:Giddy-up! by Marxist+Hacker+42 · · Score: 4, Informative

      Besides, I was wrong- only the PDF for THAT SPECIFIC MODEL has been removed. Operators manuals for hundreds of other ATMs still are up....

      --
      SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
    3. Re:Giddy-up! by dan828 · · Score: 5, Funny

      Kids these days got it easy. In my day you had to spend hours digging though dumpsters, now you just click a couple of buttons. What is the world coming to?

  2. Re:Trivial search - and the password is.... by 1010110010 · · Score: 5, Funny

    1 2 3 4 5? That's the combination an idiot would have on his luggage!

  3. Re:Trivial search - and the password is.... by JesseL · · Score: 4, Funny

    That's the combination to my luggage!

    --
    "Prefiero morir de pie que vivir siempre arrodillado!"
  4. Casino by Enderandrew · · Score: 4, Informative

    I recently did IT for the largest casino company on the planet. I was dual-property and responsible for two casinos. The master code that would open the keyboxes and get you keys to anywhere in the casino was 654321. And people told each other all their passwords and such all the time.

    I couldn't believe it.

    --
    http://blindscribblings.com - Tasty pop-culture in conceptual fashion.
    1. Re:Casino by TopShelf · · Score: 5, Insightful
      That's a perfect illustration of how technological devices are only a small part of security. Having solid policies that are actually followed means every bit as much, if not more. From TFA:

      "This isn't a vulnerability," Goldsmith explained. "It's someone exploiting a policy weakness, where ATM owners install these things and never change the default password."

      All that's in the PDF is the default password, following a warning in BIG BOLD TYPE saying that you need to change the default password before deploying the machine. Would they put in a new combination lock on their vault and leave a combo of 1-2-3? I should hope not...
      --
      Stop by my site where I write about ERP systems & more
  5. Aha! by The+Grey+Clone · · Score: 4, Funny

    We've finally found that mysterious step 2!

  6. We're rich!! We're rich!!! by queenb**ch · · Score: 4, Funny

    Phhhtttt!!!

    That's to all of you who made fun of us geeks!

    *Rude Hand Gesture*

    That's for every bully who ever shoved someone into a locker during PE.

    Due to our superior ability to manipulate poorly secured cash dispensing devices, we shall now rule the world!

    First the treasury...then the military. World domination cannot be far behind.

    2 cents,

    QueenB

    --
    HDGary secures my bank :/
  7. Nine Days.... by Mr.Scamp · · Score: 5, Funny

    The machine gave $20's for $5's for NINE days after it was reprogrammed before someone commented on it. God Bless America.

    1. Re:Nine Days.... by geekoid · · Score: 4, Insightful

      Yes.

      It's called honesty and ethics.
      But if you leve your car door unlocked, and someone takes it, I'm sure you won't mind, since it was your 'fault'.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  8. Re:The default password is... by Talondel · · Score: 5, Informative
  9. WOW by Anon-Admin · · Score: 4, Informative

    Wow that is cool, it was a quick search and I found it!

    It says that to enter the management screen you hold the key and press one. Then the default UID is 00 and the default password is 12345 so you should enter 0012345 into the prompt.

    I am off to the ATM down stairs. I could use a little extra cash.

  10. "Gawd, Idiots!" by patrixmyth · · Score: 4, Insightful

    Here I was thinking that the problems with voting machines had to be intentional, since ATM's were so much better secured. Now that I find out that a keystroke combination on the interface of an ATM will bring up a GUI to reprogram the machine, protected only by a default password, I can rest assured that the world is not as shrouded in conspiracy as I feared. It's just full of very very very (very very very very very) stupid people. Now, watch as one of these aforementioned idiots elected to public office blames this on Google.

    --
    "Don't you know you're going to shock the monkey?"- Peter Gabriel
  11. Re:The default password is... by jenkin+sear · · Score: 4, Funny

    I thought it was up, up, down, down, left, right, left, right, B, A, Start ...

    --
    What a strange bird is the pelican, his beak can hold more than his belly can.
  12. Re:We're rich!! We're rich!!! by lomedhi · · Score: 5, Funny

    2 cents,

    Please enter a multiple of $5 or $20.

    --
    Did you say "insightful" or "inciteful"?
  13. there's enough clues in the article..... by nblender · · Score: 4, Informative
    For this one you have to carefully RTFA. You actually have to do it. Not just pretend. A simple google search, plus some whois sleuthing to confirm you have the right one, will turn up a company that currently has it's "support.html" disabled (404), but the wayback machine has an old (2005) copy of "support.htm" which has a list of error codes, FAQ, etc, for the machine in question. It's not too much of a stretch to believe that someone put the manual up for download at some point.

    No, I don't have the manual. I don't really care either, it was an interesting academic exercise.

  14. Re:The default password is... by zenray · · Score: 4, Interesting

    001234 as stated in the link. But to be fair it also stated in very big bold type that this default master password should be changed. The fact the master password remains unchanged is a user error in the setup and not a design flaw. Every master password not changed was left that way by 'somebody'. That 'somebody' needs to sued (or beaten severly about the head and shoulders with a security clue stick) for allowing easy access to the money. Unless they were ordered by managment to leave it as defaulted.

    --
    zenray
  15. Re:The default password is... by CastrTroy · · Score: 4, Insightful

    However, should ATMs even come with a default password so that they can be hacked? Shouldn't reprogramming them require using some sort of physical/electronic key thats more difficult for people to get ahold of? If you can reprogram an ATM by walking up to it and typing in any code, regardless of whether it's the default password or not, then the ATM security is terrible. It's one thing to put a default password on a digital cable box for blocking channels, it's another matter entirely to put a default password on an ATM.

    --

    Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
  16. Ready-Set -Go by Analogy+Man · · Score: 4, Funny
    However, should voting machines even come with a default password so that they can be hacked? Shouldn't reprogramming them require using some sort of physical/electronic key thats more difficult for people to get ahold of? If you can reprogram a voting machine by walking up to it and typing in any code, regardless of whether it's the default password or not, then the voting machine security is terrible. It's one thing to put a default password on a digital cable box for blocking channels, it's another matter entirely to put a default password on a voting machine.

    Which one gets fixed first!

    --
    When the people fear their government, there is tyranny; when the government fears the people, there is liberty.
  17. ATM Industry Association warned them. by gurps_npc · · Score: 4, Interesting
    Back in Feb 2005, the ATM Industry Association released a memo or press announcement, found here:

    http://www.gasa-cognito.com/media/GASA-ATMIA%20Fra ud%20Alert1.pdf#search=%22atm%20master%20password% 22

    It specifically warned the industry that their passwords were getting out and to tell the banks to CHANGE them.

    Frankly, I have zero sympathy for the bank that lost cash.

    And not much respect for the idiots that did not report it. What, did they think the banks would never find out what happened? That when they did find out, they would not 'correct' the accounts?

    Either report it, or get yourself an untraceable card and return.

    --
    excitingthingstodo.blogspot.com
  18. Re:The default password is... by Tumbleweed · · Score: 4, Insightful

    But to be fair it also stated in very big bold type that this default master password should be changed. The fact the master password remains unchanged is a user error in the setup and not a design flaw.

    I would say that's incorrect. It should be a trivial matter for the software to be written to REQUIRE the default password to be changed before the machine will actually give out money. Rather like having to immediately change your password when you first login to an account. It's not a difficult concept, and while this is technically a 'lack' of a feature rather than a bug, it's certainly a flaw in design, and a pretty basic one at that.

  19. Re:No password needed.. by avenj · · Score: 4, Funny

    That may work for the Irish, but what if you're Russian?