Security researcher sounds alarm over ATM NFC reader vulnerabilities

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=-0qW2SBk-HM



Duration: 2:53
75 views
0


Reported today on The Verge

For the full article visit: https://www.theverge.com/2021/6/28/22553646/atm-point-of-sale-nfc-readers-hack-security-vulnerability-jackpotting

Reported today in The Verge.

Security researcher sounds alarm over ATM NFC reader vulnerabilities

IOActive security researcher Josep Rodriquez has warned that the NFC readers used in many modern ATMs and point-of-sale systems are leaving them vulnerable to attacks, Wired reports. The flaws make them vulnerable to a range of problems, including being crashed by a nearby NFC device, locked down as part of a ransomware attack, or even hacked to extract certain credit card data.

Rodriquez even warns that the vulnerabilities could be used as part of a so-called "jackpotting" attack to trick a machine into spitting out cash. However, such an attack is only possible when paired with exploits of additional bugs, and Wired says it was not able to view a video of such an attack because of IOActive's confidentiality agreement with the affected ATM vendor.

By relying on vulnerabilities in the machines' NFC readers, Rodriquez's hacks are relatively easy to execute. While some previous attacks have relied on using devices like medical endoscopes to probe machines, Rodriquez' can simply wave an Android phone running his software in front of a machine's NFC reader to exploit any vulnerabilities it might have.

In one video shared with Wired, Rodriquez causes an ATM in Madrid to display an error message, simply by waving his smartphone over its NFC reader. The machine then became unresponsive to real credit cards held up to the reader.

The research highlights a couple of big problems with the systems. The first is that many of the NFC readers are vulnerable to relatively simple attacks, Wired reports. For example, in some cases the readers aren't verifying how much data they're receiving, which means Rodriquez was able to overwhelm the system with too much data and corrupt its memory




Other Videos By Colin Boyd SEO


2021-06-28YouTube TV launches 4K and offline downloads today, but they don’t come cheap
2021-06-28Australian regulator says Apple’s AirTag batteries are too easy for kids to access
2021-06-28All the announcements from Samsung’s virtual MWC event
2021-06-28Loki is coming to Fortnite in July
2021-06-28Samsung’s Galaxy Book Flex2 Alpha laptop is $250 off at Best Buy
2021-06-28The 12.9 Max Plus is Brydge’s best iPad keyboard yet
2021-06-28Netflix users on Android can now stream partially downloaded content
2021-06-28Microsoft keeps hinting at an October release for Windows 11
2021-06-28Honda’s first electric SUV in the US will be called ‘Prologue’
2021-06-28Qualcomm’s Snapdragon 888 Plus ups the CPU and AI performance
2021-06-28Security researcher sounds alarm over ATM NFC reader vulnerabilities
2021-06-28The best deals on true wireless earbuds right now
2021-06-28Lenovo announces $679 13-inch Android tablet that works as a portable monitor
2021-06-28The Lenovo Smart Clock 2 gives Google Assistant a new look
2021-06-27The best deals on 4K TVs
2021-06-27Listen to the sounds of China’s Zhurong rover on the surface of Mars
2021-06-27New trailers: The Harder They Fall, Ted Lasso, The Suicide Squad, and more
2021-06-27Leaked renders of Samsung Galaxy Buds 2 show four color options
2021-06-27YouTube reportedly took down videos by group documenting human rights abuses in China
2021-06-26Volkswagen plans to stop selling combustion engine vehicles in Europe by 2035
2021-06-26FCC filing shows Verizon has built a smart display powered by Amazon’s Alexa