Thu 21 Sep 2006
from Wired
A security expert in New York has learned how to get free money from some ATMs by entering a special code sequence on the PIN pad.
Last week, news reports circulated about a cyber thief who strolled into a gas station in Virginia Beach, Virginia, and, with no special equipment, reprogrammed the mini ATM in the corner to think it had $5.00 bills in its dispensing tray, instead of $20.00 bills.
Using a pre-paid debit card, the crook then made a withdrawal, and casually strolled off with a 300% profit in his pocket.
Foolishly, he left the ATM misprogrammed this way for 9 days — presumably to the delight of other customers — before a good Samaritan reported the issue and exposed the caper.
How, exactly, he pulled off the swindle remained unreported. Curious, Dave Goldsmith, a computer security researcher at Matasano Security began poking around. Based on CNN’s video, he identified the ATM as a Tranax Mini Bank 1500 series.
He then set out to see if he could get a copy of the manual for the apparently-vulnerable machine to find out how the hack worked. Fifteen minutes later, he reported success.
Now Working! Download Operator Manual
9 Responses to “ATM Hack Uncovered *Working Link Update*”
Leave a Reply
You must be logged in to post a comment.
September 21st, 2006 at 11:46 pm
the link to the manual is dead. does anyone have a mirror?
September 22nd, 2006 at 3:18 am
I just looked at it today, I’ll see if I have a copy in my cache still…
September 22nd, 2006 at 3:28 am
sorry, no luck… got cleared on the restart
September 22nd, 2006 at 6:07 am
I will post on edge later today
September 23rd, 2006 at 12:47 am
here ya goes lads:
http://www.s0beit.teamauxiliary.com/images/Tranax_MB_Operator_Manual.pdf
September 23rd, 2006 at 11:00 am
I updated the post with s0beit’s link for now, until hevnsnt get it on edge.
September 23rd, 2006 at 12:38 pm
[...] Also with default passwords of Master = 555555 Service = 222222 Operator = 111111 you are asking for problems. Here are a few more links with information of this blunder. Link 1, Link 2, Link 3, Link 4 [...]
September 23rd, 2006 at 11:32 pm
thanks! cya on the news (joke)
May 28th, 2007 at 5:54 pm
Holy cow! Look on page 96+
If you can social engineer your way into rebooting the atm without being noticed, you could put any image you want, using only a homebuilt cable and your laptop!… without need for a password!!