PLA Forums

Other Stuff That Has Little To Do With PLA => Techinical Shit => Phreaking, Hacking, Social Engineering, Lock Picking => Topic started by: rbcp on October 06, 2006, 09:02:54 AM

Title: How to hack an ATM
Post by: rbcp on October 06, 2006, 09:02:54 AM
Just watched a cool thing on Gizmodo showing how to get into the menu on an ATM machine and change settings.  Nothing that will give you free money, but you can change the customized message that's printed on the receipts.

http://www.youtube.com/v/At_HDzJjwHU (http://www.youtube.com/v/At_HDzJjwHU)

I know where there's an ATM that looks similar to that.  I'm going to try it out next time I'm there.
Title: Re: How to hack an ATM
Post by: frog on October 06, 2006, 09:11:24 AM
I know where there's an ATM that looks similar to that.  I'm going to try it out next time I'm there.

If it's anything like most electronic devices, getting into that screenie thing will be the same or very similar across most ATMs. So everyone should try it!
Title: Re: How to hack an ATM
Post by: Alpha Omicron on October 06, 2006, 10:54:08 AM
How about a textual explanation for the dial-up scum?
Title: Re: How to hack an ATM
Post by: MattGSX on October 06, 2006, 11:01:54 AM
You do realize that most ATM's have cameras mounted on them, right? I don't know what the risk is associated with this or if they also log use/transactions, so... I dunno. If anyone does do this, don't do something fucking stupid like change it to a PLA advertisement unless you really want it to come back here.
Title: Re: How to hack an ATM
Post by: Raptor on October 06, 2006, 11:08:43 AM
I agree it would get attention back here, But the cameras are monitoring more of your face, (or body when U steal from and/or rape someone using the ATM. What appeares on the screen is usually confidential for the videos.

and btw, the ATM's showed in the video did not have cameras. If it Inside a financial instirution, then yes, it will have cameras. But in the mall/ 7 Elleven, its unlikely for there to be cameras
Title: Re: How to hack an ATM
Post by: CountyKid on October 06, 2006, 11:10:40 AM
I agree it would get attention back here, But the cameras are monitoring more of your face, (or body when U steal from and/or rape someone using the ATM. What appeares on the screen is usually confidential for the videos.

  Yeah so?

  It's still a bad idea.
Title: Re: How to hack an ATM
Post by: MattGSX on October 06, 2006, 11:34:23 AM
There might not be cameras at the ATM, but there's DEFINATELY one in the store/mall, and if there's a good enough one to get a profile shot, then you're even MORE fucked. I agree with Nate. This is an awful idea. And I have to state again: If someone is gonig to do this, PLEASE don't reference the PLA site on it. The last thing we need are more spooks/shills (I'm thinking Cal's)
Title: Re: How to hack an ATM
Post by: Raptor on October 06, 2006, 11:36:32 AM
lets see how RBCP's experiment turns out.
Title: Re: How to hack an ATM
Post by: computerwiz_222 on October 06, 2006, 02:13:24 PM
Yeah, ATMs are serious business. They contain something of value and you wouldn't want to go messing with them. If you get caught then you could get in trouble. Please do not tell everyone you saw this on PLA, the last thing we need is to be shut down for "having guides to hack an atm" even though we don't. I would not suggest doing this.
Title: Re: How to hack an ATM
Post by: Raptor on October 06, 2006, 05:14:12 PM
If you are doing nothing more than pressing buttons allready installed on the machene (i.e. not hardwiring some kind of "elite haxing machene!1" to it. What if grandma cant see and hits that particular button combination? I'm not saying anyone should attempt it, or that its a good idea, but what would they charge you with "Entering secret acces codes to CHANGE THE RECIPT!" Oh noes! that one serious fellon right there. But we wouldn't want PLA to be shut down either now would we?
Title: Re: How to hack an ATM
Post by: silentneep on October 06, 2006, 06:51:44 PM
I think I-ball was trying to explain this to me one day... but it didn't work on any of the ATMS he found or something.
Title: Re: How to hack an ATM
Post by: gangals on October 06, 2006, 07:14:34 PM
Please note that the ATM that they tried it on was a mobile unit with no camera.
Title: Re: How to hack an ATM
Post by: MattGSX on October 06, 2006, 07:32:24 PM
Please note that just because there's not a camera on the ATM there may be nearby cameras, and one may get a profile view of you at the ATM which is even more incriminating.

See above posts. I still say it's one of those cool things to know but a bad idea in general
Title: Re: How to hack an ATM
Post by: gangals on October 06, 2006, 08:26:24 PM
I wasn't promoting it, just saying that when they made the video, they didn't just pick any ol' ATM, that there are thing to think about if one was to go through with the plan.

But I agree with you, I really don't feel like pushing my luck and see if I get pwned in the @ss for doing something like that.
Title: Re: How to hack an ATM
Post by: MattGSX on October 06, 2006, 08:40:10 PM
I totally just had a mental flash of Office Space with the "federal, pound you in the ass prison" thing after you said that. Maybe because pwned and pound look similar, I'm not sure. It amused me to no end, at least.
Title: Re: How to hack an ATM
Post by: gangals on October 06, 2006, 08:50:21 PM
Well at least I'll get my conjugal visits right? Oh wait, I don't get those now...
Title: Re: How to hack an ATM
Post by: frog on October 15, 2006, 03:02:56 PM
Did anyone write down how to do this, or save the video? I just found that model of ATM, and the video is gone from YouTube thanks to some prick recently hacking an ATM for MONEYS and being caught.
Title: Re: How to hack an ATM
Post by: Raptor on October 15, 2006, 03:06:47 PM
like zOMG in teh terminator 2 the kid like, haxes an ATM with like, a LEET LINIX HAXER COMPUTOR MACHENE!!
is that possible in real life !
Title: Re: How to hack an ATM
Post by: gangals on October 15, 2006, 04:34:56 PM
Did anyone write down how to do this, or save the video? I just found that model of ATM, and the video is gone from YouTube thanks to some prick recently hacking an ATM for MONEYS and being caught.

I think I did, when I visit that computer tmw, I'll post
Title: Re: How to hack an ATM
Post by: rbcp on October 15, 2006, 04:56:41 PM
like zOMG in teh terminator 2 the kid like, haxes an ATM with like, a LEET LINIX HAXER COMPUTOR MACHENE!!
is that possible in real life !

That was an Atari, not Linux.  You have to use an Atari to do it or it won't work.  They stopped selling them cause everyone was using them to hax ATMs, so good luck finding one.
Title: Re: How to hack an ATM
Post by: frog on October 16, 2006, 02:25:44 PM
I think I did, when I visit that computer tmw, I'll post

WHERE IS IT GANGALS???
Title: Re: How to hack an ATM
Post by: jimb20 on October 16, 2006, 02:50:59 PM
I think I did, when I visit that computer tmw, I'll post

WHERE IS IT GANGALS???

i would like to see it too
Title: Re: How to hack an ATM
Post by: frog on October 16, 2006, 03:22:30 PM
Nevermind, I found something even better.
Title: Re: How to hack an ATM
Post by: Telcogal on October 16, 2006, 03:24:04 PM
http://edge.i-hacked.com/atm-hack-uncovered
Title: Re: How to hack an ATM
Post by: gangals on October 16, 2006, 06:51:24 PM
I think I did, when I visit that computer tmw, I'll post

WHERE IS IT GANGALS???

Well I decided to solder some stuff at a friend's house last night so I ended up not going to class, and I won't be back at that computer till Wed.
Title: Re: How to hack an ATM
Post by: frog on October 16, 2006, 07:52:25 PM
Telcogal, you posted! I haven't talked to you in seven ages of men!

And thanks a lot! I had found a shitty text version of the manual that wasn't complete and didn't, obviously, have pictures. This is more than I could ask for. Marry me?


The said model, Tranax MB1500, appears to be identical to the Nautilus Hyosung MB1500. So make sure you test out on both!
Title: Re: How to hack an ATM
Post by: Telcogal on October 20, 2006, 01:55:53 PM
A perfect crime for sure........and to think I bought gas there and didn't use the damn ATM.   *hiding*

http://www.youtube.com/watch?v=cmW_4R81jVU

http://www.securityfocus.com/brief/310

Glad you liked the manual !
Title: Re: How to hack an ATM
Post by: . on October 23, 2006, 12:15:22 AM
like zOMG in teh terminator 2 the kid like, haxes an ATM with like, a LEET LINIX HAXER COMPUTOR MACHENE!!
is that possible in real life !

That was an Atari, not Linux.  You have to use an Atari to do it or it won't work.  They stopped selling them cause everyone was using them to hax ATMs, so good luck finding one.

Never tried in my life to hack an ATM but believe me or not I do have an Atari and a COLECO and also and old Texas instruments LAptop with Windows 95'
Title: Re: How to hack an ATM
Post by: trevelyn on October 27, 2006, 02:15:20 PM
 :) i have found that on "Triton" and some other ATMs if you hold the very last key down at the bottom of the right side (ususally blank) and press "1" A new screen appears asking if you would like to print customer receipts or "Managerial duties" or something similar.  heres a digram:

[1] [2] [3] [a]

     

i think.. but anyways hold down a and press 1 if you go to maanger duties it asks for a passwd maybe before hand go ask the clerck what their store number is (if franchised) or just try normal default passwords like 1111 1234 4321 etc.  I tried to BF the password once with like 5 trys before being seated in a crowded Eat and Park.  :)
Title: Re: How to hack an ATM
Post by: gangals on October 27, 2006, 02:23:35 PM
Found that tut frog, I ended up writing it on a scrap piece of paper and just now found it:

Press CLEAR, ENTER, and CANCEL at the same time for 2 seconds.

Then press 1, 2, then 3.

When it asks for pass, try 555555, 222222, or 111111.
Title: Re: How to hack an ATM
Post by: I-baLL on October 28, 2006, 12:33:39 AM

i think.. but anyways hold down a and press 1 if you go to maanger duties it asks for a passwd maybe before hand go ask the clerck what their store number is (if franchised) or just try normal default passwords like 1111 1234 4321 etc.  I tried to BF the password once with like 5 trys before being seated in a crowded Eat and Park.  :)

I don't think that the store people actually have the ATM password. I think it's the ATM distributor who has it.

Triton seem to like 6 digit passwords.
Title: Re: How to hack an ATM
Post by: Reverend Greed on December 23, 2006, 11:52:14 PM
Good discussion.

I just want to make a few points.

ATM cameras these days not only record you, but the transation you are conducting in real time.  So, the moment you start hitting buttons - it signals the camera to record you and what's being done.  The data is still recorded on regular VHS tape.  The tapes are generally kept in storage for a period of 7 years.  Also, the cameras span more than you think.  They are used to span into the parking lots in order to catch view a vehicle's license plate of a potential fraudster or bank robber.  So, if you plan on doing something - my recommendation is going late at night and with a disguise, remove jewelry, cover tattoos, etc, and park way away from view of the ATM.

ATM machines require a once a month surprise audit by bank/credit union employees.  On older machines - the machine is placed in an "Out of Service" operation.  At which time - the ATM the 911 button is exercised (if the machine has one) and the withdrawal of cash with a dummy ATM card is conducted with a 4 digit "ATM code".  The code is dependent on what the particular branch assigned it as.  On newer machines - again the "Out of Service" is placed, but now, an employee, generally the manager uses his/her own card to withdrawal cash then immediately deposit it.  The purpose of this also is to make sure the timestamp is correct when a transaction occurs.  The newer machines are produced by Wincor Nixdorf utilizing IBM software for production.  All maintenance modes for the ATM are set inside the bank - this includes displayed advertisements.  The vast majority of banks and credit unions contract to third party vendors in the event of a machine failure (i.e. cash stuck in the dispensor) and the ATM automatically notifies that vendor to send a service technician out to fix it especially on weekends when most banks are closed.  Most machines in service do not allow any form of transation unless you have an ATM card.

Title: Re: How to hack an ATM
Post by: trevelyn on December 24, 2006, 06:49:15 AM
heres a triton trying to boot windows XP pro i found in a mall:

(http://i107.photobucket.com/albums/m281/trevelyn2006/triton1.jpg)

i would never steal from one, i just want to see the "managerial duties" under the options screen i found.  Stealing is ass, unless it's from a phone company.  :P
Title: Re: How to hack an ATM
Post by: Raptor on December 24, 2006, 08:12:09 AM
The ATM machines in our mall seem to have been out of service for the last 3 months. It's funny that no one cares enough to want to fix it. Even more funny, is the dvd rental machine (Similar to a red box) that has a norton antivirus prompt up, covering the entire screen. Thats been there just as long as the ATM's have been down. Why the hell would a video rental machine get a virus? Some idiot set it to do a regular scan every week or something, and then no one can get movies out of it. I'd like to see a thread about hacking photo processing machines, like the ones you see in CVS
Title: Re: How to hack an ATM
Post by: I-baLL on December 24, 2006, 08:54:03 AM
Most ATMs do not have any video cameras. That's because most ATMs aren't bank ATMs but are private ATMs at delis, groceries, strip clubs, etc. There might a surveillance camera nearby but they're usually not pointed directly at the ATM. You think that's bad? Here's something else that's interesting. The surveillance tapes for security camera tend to get reused. They only get put into storage if something actually happens. And since tape is a magnetic film media the magnetic coating wears off the tape thus maknig the surveillance tapes useless. I've read a book where people from the FBI Crime Lab were interviewed and they were all bitching about that.

I never heard the thing about banks auditing their own ATMs every month. It makes sense but why do they need to withdraw money to check the timestamp? The time can usually be checked in the settings menu or recieved through giving a bad pin to the ATM and thus getting a "Transaction Denied" reciept. You can also just check your balance and the receipt will have the date and time on it.

Also, I remember some big hoopla on Slashdot a couple of years ago when Diebold decided to connect at least some of their ATMs to the internet. I should find that article.

Hmm... Rev. Greed, it seems that you're getting your info from a single source. I can tell by this line:

"The newer machines are produced by Wincor Nixdorf utilizing IBM software for production"

Because a lot of banks also tend to use Diebold machines.

So, whatever source you're using it's referring to a specific set of banks. I'm not saying that what you;re sauing is wrong. I'm just saying that it isn't an overall picture of things. Also, can you tell us more about the audits? What are they done for exactly? Cause the timestamp thing is weird cause there's no need to withdraw money to check the time.

Good discussion.

I just want to make a few points.

ATM cameras these days not only record you, but the transation you are conducting in real time.  So, the moment you start hitting buttons - it signals the camera to record you and what's being done.  The data is still recorded on regular VHS tape.  The tapes are generally kept in storage for a period of 7 years.  Also, the cameras span more than you think.  They are used to span into the parking lots in order to catch view a vehicle's license plate of a potential fraudster or bank robber.  So, if you plan on doing something - my recommendation is going late at night and with a disguise, remove jewelry, cover tattoos, etc, and park way away from view of the ATM.

ATM machines require a once a month surprise audit by bank/credit union employees.  On older machines - the machine is placed in an "Out of Service" operation.  At which time - the ATM the 911 button is exercised (if the machine has one) and the withdrawal of cash with a dummy ATM card is conducted with a 4 digit "ATM code".  The code is dependent on what the particular branch assigned it as.  On newer machines - again the "Out of Service" is placed, but now, an employee, generally the manager uses his/her own card to withdrawal cash then immediately deposit it.  The purpose of this also is to make sure the timestamp is correct when a transaction occurs.  The newer machines are produced by Wincor Nixdorf utilizing IBM software for production.  All maintenance modes for the ATM are set inside the bank - this includes displayed advertisements.  The vast majority of banks and credit unions contract to third party vendors in the event of a machine failure (i.e. cash stuck in the dispensor) and the ATM automatically notifies that vendor to send a service technician out to fix it especially on weekends when most banks are closed.  Most machines in service do not allow any form of transation unless you have an ATM card.


Title: Re: How to hack an ATM
Post by: Reverend Greed on December 24, 2006, 12:14:57 PM
Hello,

Quote
Most ATMs do not have any video cameras. That's because most ATMs aren't bank ATMs but are private ATMs at delis, groceries, strip clubs, etc. There might a surveillance camera nearby but they're usually not pointed directly at the ATM.

You're right about that, however, I was refering to machines at the actual bank.

Quote
I never heard the thing about banks auditing their own ATMs every month. It makes sense but why do they need to withdraw money to check the timestamp? The time can usually be checked in the settings menu or recieved through giving a bad pin to the ATM and thus getting a "Transaction Denied" reciept. You can also just check your balance and the receipt will have the date and time on it.

Banks and Credit Unions are insured by the FDIC and NCUA accordingly.  Banks/Credit Unions are required to have monthly "surprise" audits on every teller, the vault, and the ATM machines as a measure to prevent insider fraud.  Also, the audit is required by internal auditors because private insurance companies require it.  Here's why:  when an individual files a Regulation E disbute regarding the use of an unauthorized transation whether it be the customer placed his/her PIN on the back of the card and money was withdrawn or a transation from the internet lets say - the customer is held harmless and the bank will take the loss.  When the bank reaches their ceiling amount of say $50,000 in an annual time frame, then their private insurance will begin to cover the losses.  The audits on the ATM machines even include counting the money the ATM should have for that day.  A withdrawal from the ATM machine during this audit with ensure this:

1)  That the ATM is able to balance its cash flow.
2)  That customers have access to cash withdrawals.
3)  It provides an accurate mark of a timestamp because the majority of fraudulent transations are withdrawals.  (i.e. I lost my ATM card - it wasn't me who withdrew the cash.)

Quote
Also, I remember some big hoopla on Slashdot a couple of years ago when Diebold decided to connect at least some of their ATMs to the internet. I should find that article.

That would be a little scary.  From personal experience - they can be connected to intranets as a means for management to maintain appropriate cash on hand and balancing issues.

Quote
Hmm... Rev. Greed, it seems that you're getting your info from a single source. I can tell by this line:

"The newer machines are produced by Wincor Nixdorf utilizing IBM software for production"

This single source is me.  I'm in the banking industry.  Wincor Nixdorf is one of the biggest suppliers of ATMs in the world.  I believe they rank third, but I'm not for sure.  I reside in Central California and these are the brands I most commonly see.
Title: Re: How to hack an ATM
Post by: Raptor on December 24, 2006, 03:21:15 PM
about those magnetic tapes, possibly a few hard drive magnets would take care of that "evidence"? heheheh
Title: Re: How to hack an ATM
Post by: MattGSX on January 21, 2007, 01:20:47 AM
Yeah, that's a great idea. How would you get the tape? Security cameras typically broadcast onto a closed-circuit network, which is then taped. In some situations, There can be one tape showing a pint-sized version of each camera, one tape switching between each camera, and then a single tape per camera. In some cases, these tapes aren't even made by the business, but by an outside company, meaning you'd have to track the company down and sneak in to obtain the tapes.

Of course, if you're trying to do this at a gas station or somewhere similar, have fun. Most gas stations around here have a separate camera in the manager's office that feeds either directly to a remote location (the way I just explained), to a hard drive (if the company can afford digital security cams or just uses all x10 stuff), or to another location for security. The gas station down the street from me has the manager's camera feed directly to the manager's house (next door), though this could also be an anomaly.
Title: Re: How to hack an ATM
Post by: linear on January 21, 2007, 01:45:36 AM
Also, I remember some big hoopla on Slashdot a couple of years ago when Diebold decided to connect at least some of their ATMs to the internet. I should find that article.

That's because the people on slashdot who read that were morons. Diebold wasn't stupid enough to connect their ATM machines to the internet. that's absurd. What happened was that diebold produced "WebATM's" for wells fargo.

People read "Web" and automatically assumed it was going to be connected to the internet. but why would anyone do that? It was a WebATM because it could display "Web" content. it's an internal network that displays information tot he end-user on a web-like interface.

no internet.
Title: Re: How to hack an ATM
Post by: trevelyn on January 21, 2007, 09:26:39 AM
 :S  oh, i forgot about a video camera.. I thought the carmeras on a Triton were useless, heh.  Everytime im in a restaurant or convenience store and i see one i bring up the secret menu i found and bruteforce the passwd at least 5 or 6 times before giving up.  whoops.  It's not like im trying to steal, i just want to see what "Manager's duties" means.. like whats behind the cloak you know?