Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,152,215 members, 7,815,245 topics. Date: Thursday, 02 May 2024 at 09:32 AM

Qubweb-what Are The Vulnerabilities In The ATM Machine? - Science/Technology - Nairaland

Nairaland Forum / Science/Technology / Qubweb-what Are The Vulnerabilities In The ATM Machine? (480 Views)

Software Vulnerabilities Found In Hikvision And Dahua Surveillance Cameras / Emmanuel Okafor: Pupil Builds An ATM That Works With Bank Card Using Carton / Talented Boy Manufactures ATM That Dispenses Cash In Imo State (Video) (2) (3) (4)

(1) (Reply)

Qubweb-what Are The Vulnerabilities In The ATM Machine? by Qubweb: 2:18pm On Aug 25, 2019
The ATM system in Nigeria is not secure, the only reason why we don’t hear of ATM thefts often is because of the physical security of the ATM area not that the main software in the machine is secure per-say. That is for Nigeria, and I believe this applies to most developing African countries.
According to news reports, a staggering 85 percent of ATM cash machines can be hacked and tricked into dispensing free cash within just 20 minutes.
A number of successful attempts have been made gain access to an ATMs operating system, and these attempts have been turned a blind eye to, since not all of them lead actually to cash dispensal.
Hackers targeted ATMs belonging to unity bank , first bank and mostly ATMs using Diebold Nixdorf technology and found four main vulnerabilities categories: insufficient network security; insufficient peripheral security; improper configuration of systems or devices; and vulnerabilities within the configuration of the application control.

due to the insufficient network security and even adequate dispersion methods a criminal with access to the ATM network can “target available network services, intercept and spoof traffic, and attack network equipment.”, if you feel am just making this up, why do ATMs suffer from “no network”, or “out of service” in nigeria and other west African countries from time to time.this is not supposed to be and has lead to alot of exploitation holes in the remote banking system.
Criminals can also spoof responses from the processing center or obtain control of the ATM, either by remote attacks or physically, with adequate tools,a hacker to hack an ATM machine remotely from a car in 53mins and with physical access in 20mins.
Through the vulnerabilities CVE-2017-8464 and CVE-2018-1038 they could enable remotely running arbitrary code and subsequently escalating privileges; this resulted in the ability to “disable security mechanisms and control output of banknotes from the dispenser.” amazing right this is just little of what an amateur hacker can achieve, if there weren’t bank guards watching the ATM.

The quickest method is also the loudest, hackers that partner with robbers can carry out Black Box attacks which only takes 10 minutes to obtain cash from the machine.

A Black Box attack is done by drilling a hole in the side of the ATM case to gain access to the cables connecting the ATM cash box to the ATM OS. A ready made tool is then connected to the ATM letting the threat actors withdraw as much cash as they like.
All these vulnerabilities have been quarantined in the western countries but are neglected in Nigeria and other developing countries in Africa, I learnt all these by observing these ATM systems and asking harmless questions, I wonder what I will have done if I where a black hat hacker.i advice these banks to buy more sophisticated ATM systems and upgrade there remote network systems, I give credit to zenith and gtbank for there well secured systems and I advice other Banks to try more.
This was a selected answer from qubweb.com visit the link below to see more answers or give your own contributions.
https://qubweb.com/question/what-are-the-vulnerabilities-in-the-atm-machine/
Re: Qubweb-what Are The Vulnerabilities In The ATM Machine? by doubleportion: 3:19pm On Aug 25, 2019
You must be a WHITE HAT HACKER grin grin

Re: Qubweb-what Are The Vulnerabilities In The ATM Machine? by Qubweb: 11:02pm On Aug 25, 2019
doubleportion:
You must be a WHITE HAT HACKER grin grin
yes I am

(1) (Reply)

A Huge Python Killed This Morning. / Check The Network With The Best Internet Speed In Your Area With Whofast Tool / This Xiaomi Device Charges Your Smartphone & Keeps Your Hands Warm

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 13
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.