Jump to content

Recommended Posts

Posted
Yes, it'd be cheeky bearing in mind how many places still rock 2000 and NT4 both front and back of shop in an "if it isn't broke, don't fix it" method.

 

most ATM's run on 2000 or Xp!

Posted

This seems appropriate. :)

 

This talk will discuss a case in which criminals compromised and robbed an ATM by infecting it with specially crafted malware. The successful compromise of an ATM can easily result in the loss of several hundred thousand dollars.

 

Most automated teller machines (ATMs) run regular Windows systems and can be controlled like any other computer. The first public demonstration of an ATM hack was given in 2010 - but how bad is this threat really? It turns out there is a multi-million dollar business behind ATM hacks. This talk reveals how these criminal gangs operate by disclosing information obtained through forensic analysis of a real compromise. In the analyzed case some malware was used to control the hacked machine that was written specifically for the targeted ATM brand. By reverse-engineering this malware, we gained unique insights into the technologies used by the intruders. The malicious features range from balance monitoring over cash-out commands to the wiping of the machine to cover up traces of the attack. They can be accessed through special number codes that are entered directly via the machine's number pad.

 

https://www.youtube.com/watch?v=0c08EYv4N5A

Posted
I wonder if it would be worth an FOI request onto what operating systems they use.. Or could they refuse to answer for security reasons? (Which might just be caused by using Windows XP :p)
Posted

Well, today I learned. Hm.

 

Personally I'm not too keen on banking with someone that still uses XP, but considering banks are apparently still using much older systems anyway, it appears to be one of those 'You're :censored: either way' moments

Posted
The age of a system can also count in it's defence, ala the "security by obscurity" thing. For a few years after an operating system is defunct and likely to be used exploits still be published and used against them, but at a point it becomes less and less common due to the lack of use. I remember reading about one bank in the US who's been using NT4 pretty much since 1999 and still does who have a "deal" with (read- pay a buttload of money to) MS to keep an eye and publish patches etc. I say still does, that was some point last year. XP may be a different case - it's proven popularity and the likelihood of it's use continuing for a few years for some people may mean people keep trying to take advantage of that fact.
Posted
My current establishment works with XP, however one condition of being offered the job was that the company makes active progress to upgrading to Win 7 at the least. When I arrived yesterday, half of the company was on Windows 7.
Posted (edited)
The age of a system can also count in it's defence, ala the "security by obscurity" thing. For a few years after an operating system is defunct and likely to be used exploits still be published and used against them, but at a point it becomes less and less common due to the lack of use.

At this point, I was going to respond with "Yeah, but if those 'rare users' happen to traffic and house millions, that's a target worth pursuing. Especially if you program for the older systems and release it 'into the wild', when it does come back with a successful infection, high chances are it's something valuable.

 

But then you continued..

I remember reading about one bank in the US who's been using NT4 pretty much since 1999 and still does who have a "deal" with (read- pay a buttload of money to) MS to keep an eye and publish patches etc. I say still does, that was some point last year. XP may be a different case - it's proven popularity and the likelihood of it's use continuing for a few years for some people may mean people keep trying to take advantage of that fact.

So maybe that won't be the case. Maybe. Far as I see it, until there's a whistleblower we're not going to find out any time soon. If I ran a bank I'd withhold infrastructure information at every possible opportunity to prevent any kind of information getting into the hands of the bad guys (although they will always have their methods..)

Edited by Garacesh
Posted
I read something the other day about floppy disks still being the legal form of submission of certain data to the US IRS (tax authorities) while more modern and secure methods are not... apparently it's in statute and so requires a law change to amend. Antiquated operating systems in banks may not entirely be the fault of the bank!
Posted
The nhs and pc world are still on xp!

I'd expect nothing less for PC World

 

I read something the other day about floppy disks still being the legal form of submission of certain data to the US IRS (tax authorities) while more modern and secure methods are not... apparently it's in statute and so requires a law change to amend. Antiquated operating systems in banks may not entirely be the fault of the bank!

Indeed - I vaguely touched over a similar article, too.

Realistically we shouldn't have to write into law that banks must or must not use certain operating systems. Given the sheer amount of operating systems out there that are still used (XP, Vista, 7, 8, 8.1, Mac (Can you use older versions of iOS? I'm not sure (Yay! Nested parenthesis!)), Every distro of Linux) the law would require constant maintenance and updating, pruning the list, adding new ones, keeping on top of security updates/patches/exploits and holes.. What would happen if an 'accepted and legal' operating system used by $popularbank turns out to have a huge hole in it? The hole is discovered, but you can't just write out of law that the OS is now illegal to use. Banks wouldn't be able to make the switch so instantly, it's just not feasible for any kind of infrastructure.

Posted

There is nothing inherently insecure about windows XP, Microsoft have been patching every vulnerability found for 10 years+ so its surprisingly secure.

 

There is a big difference between exploitable remote weaknesses in the OS and tiny little generic problems that most patches fix.

 

I'm certainly not recommending staying on it, but there really isn't any need to panic. Your far more likely to get problems in a bank from someone installing a physical key logger or inside job to be honest.

Posted
There is nothing inherently insecure about Windows XP, Microsoft have been patching every vulnerability found for 10 years+ so it's surprisingly secure.

I don't know how you have come to this conclusion, but you couldn't be more wrong! XP is a joke when it comes to security. :rolleyes:

 

http://i.imgur.com/JlMJnIk.png

 

http://i.imgur.com/YdZ28Xj.png

 

The infection rate chart on the left shows a clear distinction between newer and older operating system versions. The infection rate for Windows XP (a CCM of 9.1) is significantly higher than the infection rates for both Windows Vista and Windows 7 (5.5 and 4.9, respectively), which in turn are significantly higher than the infection rate for Windows 8 (1.6). Newer operating system versions are not vulnerable to several common exploits that are widely used against older versions, and include a number of security features and mitigations that older versions of Windows lack. (Source)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...