香蕉久久综合-香蕉久久夜色精品国产尤物-香蕉久久夜色精品国产-香蕉久久久久-久久网站视频-久久网免费

English 中文網 漫畫網 愛新聞iNews 翻譯論壇
中國網站品牌欄目(頻道)
當前位置: Language Tips> 閱讀天地> 新聞選讀

黑客令ATM機自動吐鈔
Hacker ATM attacks show security holes

[ 2010-08-02 13:40]     字號 [] [] []  
免費訂閱30天China Daily雙語新聞手機報:移動用戶編輯短信CD至106580009009

上周,在美國拉斯韋加斯舉行的電腦安全專業大會“黑帽大會”上,一位計算機黑客向觀眾展示了不用銀行卡就能讓ATM機瘋狂吐鈔的“絕技”,讓現場觀眾看得目瞪口呆。這位黑客名叫杰克,其實是一位資深的計算機安全研究人員,他花了兩年的時間研究各種獨立ATM機,并找到了這些設備的漏洞。他發現同一廠商制造的同一型號ATM機使用的鑰匙都是一樣的,他在展示時用鑰匙打開一臺ATM里含有標準USB裝置的部件,插入他自己寫的破解程序,然后順利操控ATM電腦,讓機器自己吐出鈔票。杰克展示的另一種攻擊方式則更具威脅性,他是通過網絡對ATM系統進行遠程操控,利用ATM廠商與ATM機網絡連接中的漏洞入侵ATM機的電腦系統,不用任何密碼便能自如操控ATM機。杰克在會上沒有深入說明入侵ATM方法的具體操作細節,以及涉及的ATM廠商。他強調,他“不是在教大家破解ATM機 ”,而是要讓ATM廠商提高警覺。

黑客令ATM機自動吐鈔

黑客令ATM機自動吐鈔

A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.

A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.

The attacks demonstrated Wednesday targeted standalone ATMs. But they could potentially be used against the ATMs operated by mainstream banks.

Computer hacker Barnaby Jack spent two years tinkering in his Silicon Valley apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.

His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.

He showed off his results here at the Black Hat conference, an annual gathering devoted to exposing the latest computer-security vulnerabilities.

His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.

Jack, who works as director of security research for Seattle-based IOActive Inc, showed in a theatrical demonstration two ways he can get ATMs to spit out money:

- He found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer. He figured this out by ordering three ATMs from different manufacturers for a few thousand dollars each. Then he compared the keys he got to pictures of other keys, found on the internet.

He used his key to unlock a compartment in the ATM that had standard USB slots. He inserted a program he had written into one of them, commanding the ATM to dump its vaults.

- He hacked into the machines by exploiting weaknesses in the way ATM makers communicate with the machines over the internet. Jack said the problem is that outsiders are permitted to bypass the need for a password. He didn't go into much more detail because he said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes."

The remote style of attack is more dangerous because an attacker doesn't need to open up the ATMs.

It allows an attacker to gain full control of the ATMs and not only order it to spit out money, but also to silently harvest card data from anyone who uses the machines. It also affects more than just the standalone ATMs vulnerable to the physical attack, and could potentially be used against the kinds of ATMs used by mainstream banks.

Jack said he didn't think he'd be able to break the ATMs when he first started probing them.

Jack said the manufacturers whose machines he studied are deploying software fixes for both vulnerabilities, but added that the prevalence of remote-management software broadly opens up ATMs to hacker attacks.

相關閱讀

法男子入侵奧巴馬微博賬號被捕

英一提款機雙倍吐錢 百人排隊取款

(Agencies)

黑客令ATM機自動吐鈔

(中國日報網英語點津 Helen 編輯)

 
中國日報網英語點津版權說明:凡注明來源為“中國日報網英語點津:XXX(署名)”的原創作品,除與中國日報網簽署英語點津內容授權協議的網站外,其他任何網站或單位未經允許不得非法盜鏈、轉載和使用,違者必究。如需使用,請與010-84883631聯系;凡本網注明“來源:XXX(非英語點津)”的作品,均轉載自其它媒體,目的在于傳播更多信息,其他媒體如需轉載,請與稿件來源方聯系,如產生任何問題與本網無關;本網所發布的歌曲、電影片段,版權歸原作者所有,僅供學習與研究,如果侵權,請提供版權證明,以便盡快刪除。
 

關注和訂閱

人氣排行

翻譯服務

中國日報網翻譯工作室

我們提供:媒體、文化、財經法律等專業領域的中英互譯服務
電話:010-84883468
郵件:translate@chinadaily.com.cn