This page permanently redirects to gemini://gemini.techrights.org/2010/07/29/crackers-love-windows/.

● 07.29.10

●● Why Crackers Prefer Windows on Cash Machines

Posted in Microsoft, Security, Windows at 11:02 am by Dr. Roy Schestowitz

Summary: Windows makes a lot of money for the bad guys, who are exploiting Windows-based ATMs

ATMs that run Windows are running for criminals to take advantage of them. This is a subject that we covered many times before along with examples. See the following older posts for background:

ATMs That Run Windows Fall Into Hands of CrackersCitibank Signs Deals with Microsoft, Deliberately Blocks GNU/Linux UsersEye on Security: Windows Zombies, ATM Malware, and TrojansEye on Insecurity: Illusion of Windows Security; Popupware, and ATM Malware

Here is Slashdot’s summary about the latest example:

=> ↺ summary

“Windows CE-based ATMs can easily be made to dole out cash, according to security researcher Barnaby Jack. Exploiting bugs in two different ATM machines at Black Hat, the researcher from IOActive was able to get them to spit out money on demand and record sensitive data from the cards of people who used them. Jack believes a large number of ATMs have remote management tools that can be accessed over a telephone. After experimenting with two machines he purchased, Jack developed a way of bypassing the remote authentication system and installing a homemade rootkit, named Scrooge,”

This links to IDG, which says:

=> ↺ says

The machines Jack hacked were, however, based on Microsoft’s Windows CE operating system.

And from ZDNet:

=> ↺ from ZDNet

At the Black Hat security conference here, Jack demonstrated two different attacks against Windows CE-based ATMs — a physical attack using a master key purchased on the Web and a USB stick to overwrite the machine’s firmware; and a remote attack that exploited a flaw in the way ATMs authenticate firmware upgrades.

Glyn Moody cannot comprehend such a tactless choice of Windows CE for ATMs. He asks, “why not just leave the notes out in the open?”

It should be no surprise that Google’s vulnerabilities in Chrome are sometimes caused by Windows’ inherent insecurity and this time for a change, “Google patches Chrome, sidesteps Windows kernel bug,” reports IDG. “Microsoft was not available for comment late Tuesday.”

=> ↺ reports IDG

It it worth adding that many Firefox flaws are Windows-only as well. Sometimes GNU/Linux is also affected and this new article says that “Google also released workarounds for two vulnerabilities in external components, helping to protect from flaws in the Windows kernel and GNU glibc components.” Nothing is infallible, but Microsoft tends to fail more often than the rest and it hides this. █

=> ↺ this new article | it hides this

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.

Permalink  Send this to a friend

=> Permalink | ↺ Send this to a friend


=> Techrights

➮ Sharing is caring. Content is available under CC-BY-SA.

Proxy Information
Original URL
gemini://gemini.techrights.org/2010/07/29/crackers-love-windows
Status Code
Success (20)
Meta
text/gemini;lang=en-GB
Capsule Response Time
279.795325 milliseconds
Gemini-to-HTML Time
1.018094 milliseconds

This content has been proxied by September (ba2dc).