<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A little about the Shmoocon ATM</title>
	<atom:link href="http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/feed" rel="self" type="application/rss+xml" />
	<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm</link>
	<description>Edge.I-Hacked is a security / tech / hardware news blog</description>
	<lastBuildDate>Tue, 22 Dec 2009 15:18:06 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Brad Carter&#8217;s Homepage &#187; ShmooCon 2009</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374762</link>
		<dc:creator>Brad Carter&#8217;s Homepage &#187; ShmooCon 2009</dc:creator>
		<pubDate>Wed, 11 Feb 2009 15:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374762</guid>
		<description>[...] Hevnsnt and Surbo later discovered that the entire cover of the ATM could be opened up, which they wrote about here. And where you can see a picture of our sticker, available for download from [...]</description>
		<content:encoded><![CDATA[<p>[...] Hevnsnt and Surbo later discovered that the entire cover of the ATM could be opened up, which they wrote about here. And where you can see a picture of our sticker, available for download from [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hevnsnt</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374761</link>
		<dc:creator>hevnsnt</dc:creator>
		<pubDate>Tue, 10 Feb 2009 20:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374761</guid>
		<description>I recall a Defcon where the graphics got &quot;updated&quot; on the ATM machine.  I didnt see a CDROM inside -- But I didnt get a lot of time to look in there before Mouse came around</description>
		<content:encoded><![CDATA[<p>I recall a Defcon where the graphics got &#8220;updated&#8221; on the ATM machine.  I didnt see a CDROM inside &#8212; But I didnt get a lot of time to look in there before Mouse came around</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rbcp</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374760</link>
		<dc:creator>rbcp</dc:creator>
		<pubDate>Tue, 10 Feb 2009 19:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374760</guid>
		<description>Was there a CD-ROM drive in there?  On the admin screen, there was an option to update the graphics on the machine via CD.</description>
		<content:encoded><![CDATA[<p>Was there a CD-ROM drive in there?  On the admin screen, there was an option to update the graphics on the machine via CD.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: surbo</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374759</link>
		<dc:creator>surbo</dc:creator>
		<pubDate>Tue, 10 Feb 2009 16:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374759</guid>
		<description>RBCP and Skydog you guys need your own show for real - lol good stuff! 
For the record I was just waiting for my cash and I thought to myself &quot;I hope this thing has not been hacked&quot; as I tugged a little on the top of the machine. The case fell forward and I could see the network ports and the card reader and bunch of stuff that hackers would love to play with. My cash still came out but I quickly thought to myself - well time to cancel my credit card. =)</description>
		<content:encoded><![CDATA[<p>RBCP and Skydog you guys need your own show for real &#8211; lol good stuff!<br />
For the record I was just waiting for my cash and I thought to myself &#8220;I hope this thing has not been hacked&#8221; as I tugged a little on the top of the machine. The case fell forward and I could see the network ports and the card reader and bunch of stuff that hackers would love to play with. My cash still came out but I quickly thought to myself &#8211; well time to cancel my credit card. =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Shmoocon 2009 In Review</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374758</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Shmoocon 2009 In Review</dc:creator>
		<pubDate>Tue, 10 Feb 2009 14:51:18 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374758</guid>
		<description>[...] As I&#8217;ve said before, don&#8217;t use ATMs at Hacker Conventions. [...]</description>
		<content:encoded><![CDATA[<p>[...] As I&#8217;ve said before, don&#8217;t use ATMs at Hacker Conventions. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rbcp</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374756</link>
		<dc:creator>rbcp</dc:creator>
		<pubDate>Tue, 10 Feb 2009 07:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374756</guid>
		<description>skydog - what did I do wrong here?  I put a funny sticker on an ATM machine.  Is this illegal?  I&#039;m not the one who put the ATM into admin mode; that was I-ball.  And he just did it to see if he could.  He didn&#039;t magically reprogram it and steal everyone&#039;s money.  Why are you being all pissy with me for no reason?  Why not yell at hevnsnt for opening the thing?</description>
		<content:encoded><![CDATA[<p>skydog &#8211; what did I do wrong here?  I put a funny sticker on an ATM machine.  Is this illegal?  I&#8217;m not the one who put the ATM into admin mode; that was I-ball.  And he just did it to see if he could.  He didn&#8217;t magically reprogram it and steal everyone&#8217;s money.  Why are you being all pissy with me for no reason?  Why not yell at hevnsnt for opening the thing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danphilpott</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374755</link>
		<dc:creator>danphilpott</dc:creator>
		<pubDate>Mon, 09 Feb 2009 18:48:21 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374755</guid>
		<description>Hard to believe anyone with even a passing knowledge of the security issues revolving around standalone ATM kiosks would trust one. The inconvenience of possibly having cash unavailable at all followed by canceling and getting cards reissued is generally greater than the convenience of immediate access.  Better to carry backup cash about yourself for short-of-cash situations.</description>
		<content:encoded><![CDATA[<p>Hard to believe anyone with even a passing knowledge of the security issues revolving around standalone ATM kiosks would trust one. The inconvenience of possibly having cash unavailable at all followed by canceling and getting cards reissued is generally greater than the convenience of immediate access.  Better to carry backup cash about yourself for short-of-cash situations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ax0n</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374754</link>
		<dc:creator>ax0n</dc:creator>
		<pubDate>Mon, 09 Feb 2009 18:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374754</guid>
		<description>haha copy/paste fail. I obviously got access to your site. :P</description>
		<content:encoded><![CDATA[<p>haha copy/paste fail. I obviously got access to your site. <img src='http://edge.i-hacked.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ax0n</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374753</link>
		<dc:creator>ax0n</dc:creator>
		<pubDate>Mon, 09 Feb 2009 18:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374753</guid>
		<description>A few things.  I can&#039;t get to your site to see the comments but I can get to it via RSS so here are my thoughts from what I know:

1) The PIN PAD is encrypted ON THE KEYPAD before it goes to the ATM.

2) The upper panel with the electronics is usually pretty insecure. &lt;a HREF=&quot;http://www.h-i-r.net/2008/10/peek-inside-simple-atm-machine.html&quot; rel=&quot;nofollow&quot;&gt;See my &quot;Inside an ATM&quot; article on HiR&lt;/a&gt;. The reason I had an ATM to play with is that its keypad could not be updated to an encrypted model (see #1 above) and this couldn&#039;t be activated. It was useless. 

3) Assuming the attacker can access the administrative part of the ATM, he/she might be able to tell it to dial another number. 

4) I don&#039;t know what the protocol is, or what data (aside from PIN) is encrypted on the line that would make #3 exploitable. I have only dealt with ATM HARDWARE.</description>
		<content:encoded><![CDATA[<p>A few things.  I can&#8217;t get to your site to see the comments but I can get to it via RSS so here are my thoughts from what I know:</p>
<p>1) The PIN PAD is encrypted ON THE KEYPAD before it goes to the ATM.</p>
<p>2) The upper panel with the electronics is usually pretty insecure. <a HREF="http://www.h-i-r.net/2008/10/peek-inside-simple-atm-machine.html" rel="nofollow">See my &#8220;Inside an ATM&#8221; article on HiR</a>. The reason I had an ATM to play with is that its keypad could not be updated to an encrypted model (see #1 above) and this couldn&#8217;t be activated. It was useless. </p>
<p>3) Assuming the attacker can access the administrative part of the ATM, he/she might be able to tell it to dial another number. </p>
<p>4) I don&#8217;t know what the protocol is, or what data (aside from PIN) is encrypted on the line that would make #3 exploitable. I have only dealt with ATM HARDWARE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: skydog</title>
		<link>http://edge.i-hacked.com/a-little-about-the-shmoocon-atm/comment-page-1#comment-374752</link>
		<dc:creator>skydog</dc:creator>
		<pubDate>Mon, 09 Feb 2009 18:15:21 +0000</pubDate>
		<guid isPermaLink="false">http://edge.i-hacked.com/?p=2048#comment-374752</guid>
		<description>rbcp, you and your crew have a reputation of pushing the boundaries of what would be considered responsible or mature or even common sense. Didn&#039;t we discuss this in the third floor elevator area Saturday night? Let&#039;s look back to phreaknic a few years ago when you and murdoc conned the hotel telco provider into forwarding all of the hotel&#039;s calls to your cell phone(s). You yourself admitted that you two took credit card numbers from the people calling in, although you claim that you didn&#039;t do anything with them. 

For someone that has kids to support, you don&#039;t seem to exercise good judgement. While the PN telephone jack was clever, and truth be told, very inventive, when you took CC info, you crossed a boundary that could put you and your cohorts in jail.

Time will tell if you wise up, or become someone&#039;s prison bitch. You seem to be an intelligent guy, but you need to channel that power into something constructive and leave the pranks to the minors who won&#039;t end up doing hard time.</description>
		<content:encoded><![CDATA[<p>rbcp, you and your crew have a reputation of pushing the boundaries of what would be considered responsible or mature or even common sense. Didn&#8217;t we discuss this in the third floor elevator area Saturday night? Let&#8217;s look back to phreaknic a few years ago when you and murdoc conned the hotel telco provider into forwarding all of the hotel&#8217;s calls to your cell phone(s). You yourself admitted that you two took credit card numbers from the people calling in, although you claim that you didn&#8217;t do anything with them. </p>
<p>For someone that has kids to support, you don&#8217;t seem to exercise good judgement. While the PN telephone jack was clever, and truth be told, very inventive, when you took CC info, you crossed a boundary that could put you and your cohorts in jail.</p>
<p>Time will tell if you wise up, or become someone&#8217;s prison bitch. You seem to be an intelligent guy, but you need to channel that power into something constructive and leave the pranks to the minors who won&#8217;t end up doing hard time.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
