Bonum Certa Men Certa

Why Crackers Prefer Windows on Cash Machines

ATM pinpad in German



Summary: Windows makes a lot of money for the bad guys, who are exploiting Windows-based ATMs

ATMs that run Windows are running for criminals to take advantage of them. This is a subject that we covered many times before along with examples. See the following older posts for background:



Here is Slashdot's summary about the latest example:

"Windows CE-based ATMs can easily be made to dole out cash, according to security researcher Barnaby Jack. Exploiting bugs in two different ATM machines at Black Hat, the researcher from IOActive was able to get them to spit out money on demand and record sensitive data from the cards of people who used them. Jack believes a large number of ATMs have remote management tools that can be accessed over a telephone. After experimenting with two machines he purchased, Jack developed a way of bypassing the remote authentication system and installing a homemade rootkit, named Scrooge,"


This links to IDG, which says:

The machines Jack hacked were, however, based on Microsoft's Windows CE operating system.


And from ZDNet:

At the Black Hat security conference here, Jack demonstrated two different attacks against Windows CE-based ATMs — a physical attack using a master key purchased on the Web and a USB stick to overwrite the machine’s firmware; and a remote attack that exploited a flaw in the way ATMs authenticate firmware upgrades.


Glyn Moody cannot comprehend such a tactless choice of Windows CE for ATMs. He asks, "why not just leave the notes out in the open?"

It should be no surprise that Google's vulnerabilities in Chrome are sometimes caused by Windows' inherent insecurity and this time for a change, "Google patches Chrome, sidesteps Windows kernel bug," reports IDG. "Microsoft was not available for comment late Tuesday."

It it worth adding that many Firefox flaws are Windows-only as well. Sometimes GNU/Linux is also affected and this new article says that "Google also released workarounds for two vulnerabilities in external components, helping to protect from flaws in the Windows kernel and GNU glibc components." Nothing is infallible, but Microsoft tends to fail more often than the rest and it hides this.

Recent Techrights' Posts

Online Media as a Lying Machine of Microsoft and Bill Gates (and, As Usual, Follow the Money)
The lies go a lot further than greenwashing
Today in Techrights
Some of the latest articles
A Code of Conduct Can Lead to Deterioration of Quality Control in Linux (Nobody Reprimanded for Technical Issues, Instead Critics at Times of Crisis Get Reprimanded)
Quality control demands opinionated people, even blunt opinions at times
Microsoft, Very Deep in Debt, Trying to Take Over Other Companies Without Paying to Buy Them
the CEO strengthened his loyalty to Microsoft
Misogynists Versus Techrights
the "imams" of the tech world
IRC Proceedings: Sunday, December 10, 2023
IRC logs for Sunday, December 10, 2023
Over at Tux Machines...
GNU/Linux news
Links 11/12/2023: Climate News and Chatbots as Plagiarism
Links for the day
Links 10/12/2023: Second Belmarsh Tribunal For Assange, EU Legislates for Buzzwords
Links for the day
Links 10/12/2023: Inflation Woes, Tensions With China
Links for the day
IRC Proceedings: Saturday, December 09, 2023
IRC logs for Saturday, December 09, 2023
Links 09/12/2023: Dictator's Nomination in Russia
Links for the day
[Video] To Combat Efforts to Cancel or Kill the Career (and Reputation) of the People Who Made GNU/Linux We Must Rally the Community
nobody speaks better for projects and for licences than their own founders
Electronic Frontier Foundation Incorporated is Run by/for Corporations Now (Members' Money is Less Than a Quarter of the Money EFF Receives)
Facebook bribes
The EFF Should Know Better, But It Is Promoting Mass Surveillance by Facebook (an Endorsement of Lies)
What is going on at the EFF?
Feedback Desired
Feedback can be sent by E-mail
A Message in Support of Richard Stallman, Condemning Those Who Misportray Him
message about Richard Stallman (RMS)
Links 09/12/2023: Many 'Open'AI Employees Strongly Dislike Microsoft, Many Impending Strikes
Links for the day
IRC Proceedings: Friday, December 08, 2023
IRC logs for Friday, December 08, 2023
Over at Tux Machines...
GNU/Linux news