<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; atm hacking</title>
	<atom:link href="http://www.darknet.org.uk/tag/atm-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Stealing ATM Pin Numbers Using Thermal Imaging Cameras</title>
		<link>http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/</link>
		<comments>http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/#comments</comments>
		<pubDate>Wed, 24 Aug 2011 16:33:35 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[atm hacking]]></category>
		<category><![CDATA[atm pin stealing]]></category>
		<category><![CDATA[atm pin theft]]></category>
		<category><![CDATA[atm security]]></category>
		<category><![CDATA[atm security hacking]]></category>
		<category><![CDATA[atm skimming]]></category>
		<category><![CDATA[hack an atm]]></category>
		<category><![CDATA[michal-zalewski]]></category>
		<category><![CDATA[skimming]]></category>
		<category><![CDATA[stealing atm pin number]]></category>
		<category><![CDATA[thermal imaging]]></category>
		<category><![CDATA[thermal imaging camera]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3178</guid>
		<description><![CDATA[Now this is a really neat bit of hardware hacking, it&#8217;s been a while since we&#8217;ve reported on any kind of ATM Skimming or ATM Hacking stories. You may remember back in November 2010 &#8211; European Banks Seeing New Wave Of ATM Skimming or way back in 2008 when Pro ATM Hacker ‘Chao’ Gives Out [...]]]></description>
			<content:encoded><![CDATA[<p>Now this is a really neat bit of <a href="http://www.darknet.org.uk/category/hardware-hacking/">hardware hacking</a>, it&#8217;s been a while since we&#8217;ve reported on any kind of <a href="http://www.darknet.org.uk/tag/atm-skimming/">ATM Skimming</a> or <a href="http://www.darknet.org.uk/tag/atm-hacking/">ATM Hacking</a> stories.</p>
<p>You may remember back in November 2010 &#8211; <a href="http://www.darknet.org.uk/2010/11/european-banks-seeing-new-wave-of-atm-skimming/" title="European Banks Seeing New Wave Of ATM Skimming">European Banks Seeing New Wave Of ATM Skimming</a> or way back in 2008 when <a href="http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/" title="Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips">Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips</a>.</p>
<p>The latest is this neat hack that came out of a method outlined by <a href="http://www.darknet.org.uk/tag/michal-zalewski/">Michal Zalewski</a> back in 2005:</p>
<p><a href="http://lcamtuf.coredump.cx/tsafe/">Cracking safes with thermal imaging</a></p>
<blockquote><p>Security researchers have found that thermal cameras can be combined with computer algorithms to automate the process of stealing payment card data processed by automatic teller machines.</p>
<p>At the Usenix Security Symposium in San Francisco last week, the researchers said the technique has advantages over more common ATM skimming methods that use traditional cameras to capture the PINs people enter during transactions. That&#8217;s because customers often obscure a camera&#8217;s view with their bodies, either inadvertently or on purpose. What&#8217;s more, it can take a considerable amount of time for crooks to view the captured footage and log the code entered during each session.</p>
<p>Thermal imaging can vastly improve the process by recovering the code for some time after each PIN is entered. Their output can also be processed by an algorithm that automates the process of translating it into the secret code.</p></blockquote>
<p>The hack works extremely efficiently on ATMs using plastic keypads, it will not work on metal keypads and this method works up to 60 seconds after you&#8217;ve used the ATM.</p>
<p>I&#8217;m not sure about you guys but all the ATMs I&#8217;ve seen here are using metal keypads, so it wouldn&#8217;t work too well over here.</p>
<p>Either way it&#8217;s a fairly cool hack and I&#8217;m glad to see, so far there&#8217;s no proof of thieves using it in the wild.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The findings expand on 2005 research from Michal Zalewski, who is now a member of Google&#8217;s security team. The Usenix presenters tested the technique laid out by Zalewski on 21 subjects who used 27 randomly selected PINs and found the rate of success varied depending on variables including the types of keypads and the subjects&#8217; body temperature.</p>
<p>“In summary, while we document that post-hoc thermal imaging attacks are feasible and automatable, we also find that the window of vulnerability is far more modest than some feared and that there are simple counter-measures (i.e., deploying keypads with high thermal conductivity) that can shrink this vulnerability further still,” the researchers wrote.</p></blockquote>
<p>I wonder if we&#8217;ll see a spate of real life attacks based around this technique now the paper has been published publicly.</p>
<p>You can grab the paper discussing the technique here: <a href="http://www.usenix.org/events/woot11/tech/final_files/Mowery.pdf">Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks</a> [PDF].</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/08/18/thermal_imaging_atm_fraud/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3178+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;t=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;title=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;title=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;title=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/&amp;title=Stealing+ATM+Pin+Numbers+Using+Thermal+Imaging+Cameras" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fstealing-atm-pin-numbers-using-thermal-imaging-cameras%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/stealing-atm-pin-numbers-using-thermal-imaging-cameras/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Pro ATM Hacker &#8216;Chao&#8217; Gives Out ATM Hacking Tips</title>
		<link>http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/</link>
		<comments>http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 10:11:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[arrested]]></category>
		<category><![CDATA[atm fraud]]></category>
		<category><![CDATA[atm hacker chao]]></category>
		<category><![CDATA[atm hacking]]></category>
		<category><![CDATA[chao]]></category>
		<category><![CDATA[cloning atm cards]]></category>
		<category><![CDATA[credit-card-fraud]]></category>
		<category><![CDATA[turkey]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1093</guid>
		<description><![CDATA[It seems like ATM hacking is still the way to go for those into a bit of hardware hacking. One of the most notorious and well known ATM hackers was recently arrest in Turkey and a list of his tips discovered online where he also sold the ATM skimming equipment. Well his tips can&#8217;t be [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like ATM hacking is still the way to go for those into a bit of hardware hacking. One of the most notorious and well known ATM hackers was recently arrest in Turkey and a list of his tips discovered online where he also sold the ATM skimming equipment.</p>
<p>Well his tips can&#8217;t be THAT good if he got caught can they?</p>
<blockquote><p>A bank-machine hacker who reportedly was arrested earlier this month in Turkey gave would-be fraudsters tips on how to install rogue card-reading devices, including advising them to target drive-through ATMs (automated teller machines) and avoid towns with fewer than 15,000 residents. </p>
<p>The hacker, who went by the handle &#8220;Chao,&#8221; reportedly was arrested earlier this month in Turkey. He was one of the most well-known ATM hackers in the world, according to Uri Rivner, head of new technologies for RSA Consumer Solutions. </p>
<p>Chao sold fake faceplates that fraudsters could attach to the card slots in ATMs. These &#8220;skimmer&#8221; devices can read the magnetic stripe of every customer&#8217;s ATM or credit card, and are often used in conjunction with a hidden camera that watches people enter their PINs (personal identification numbers), Rivner said. Alternatively, criminals can attach an extra keypad on top of the one in the machine and capture the PIN that way, he added. </p></blockquote>
<p>It seems like the old methods are still prevailing but the kit used is probably lot smaller, neater and unobtrusive. They skim your card, record your pin on the number pad with a micro dot camera and usually beam it all to a wifi PC nearby which will pipe it back to the owner over the net with a 3G phone or similar.</p>
<p>Just be careful where you use the ATM machine and cover the numberpad with your other hand when you are typing to the PIN to be extra vigilant.</p>
<blockquote><ul>
<li>don&#8217;t install a skimmer in the morning, because people are more vigilant then;</li>
<li>determine where a person would have to stand to keep an eye on everything happening on that block;</li>
<li>avoid blocks where more than 250 people per day walk through, because of the danger of detection;</li>
<li>don&#8217;t install skimmers in towns with fewer than 15,000 people, because people in those towns know what their ATMs look like; </li>
<li>avoid areas with small shops open 24 hours a day, because there may be surveillance cameras and vigilant shopkeepers;</li>
<li>don&#8217;t set up in areas where a lot of illegal immigrants live;</li>
<li>places with a lot of tourist traffic are good;</li>
<li>look for affluent neighborhoods and drive-through ATMs;</li>
<li>ATMs near cash-only bars are a good bet for lots of customer activity.</li>
</ul>
</blockquote>
<p>The tips are really nothing ground-breaking, but interesting to read nevertheless. Most of them could be considered common sense, but some like not targeting really small towns are quite interesting.</p>
<p>I would have thought busy times would have been the best time to go in as long as there is no-one else queuing at the ATM machine.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2008/092908-a-pros-tips-on-atm.html">NetworkWorld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1093+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;t=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;title=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;title=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;title=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/&amp;title=Pro+ATM+Hacker+%E2%80%98Chao%E2%80%99+Gives+Out+ATM+Hacking+Tips" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F09%2Fpro-atm-hacker-chao-gives-out-atm-hacking-tips%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/09/pro-atm-hacker-chao-gives-out-atm-hacking-tips/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

