<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Sun, 17 Feb 2008 17:09:14 -0000</lastBuildDate><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320632</link><description>just a quick question, ive heard that wincor now have a sensor that detects any foreign object like a skimmer and shuts down the atm. does anybody know how long it takes for it to detect anything and how can one tell if it has those sensors bcuz i know they are optional.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mussa</dc:creator><pubDate>Sun, 17 Feb 2008 17:09:14 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320631</link><description>Sorry one clarification, this would apply to a visa upgraded ATM but most old ones are visa key pad upgraded.  The reason is that the passwords reside in the motherboard and the master keys are now in the visa key pad which means you can reset the mother board independent of the visa master keys.&lt;br&gt;Thanks,</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave</dc:creator><pubDate>Sat, 12 Jan 2008 01:13:23 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320630</link><description>Guys, I have worked with Tranax extensively and I can tell you this, it is very easy to reprogram an atm to give out lower denominations than are in it.  If you have the password; however, most people do change those passwords but I have found many that are the standard factory default passwords.  I'm not sure about the current tranax model but from the 1500 series down you can leave factory passwords in.&lt;br&gt;&lt;br&gt;Ok so here is where everyone says great but you have to find one with factory password or know the password to make the demonination changes. True but there is a back door.  I wont tell you the specifics but for the service tech that answered above address this one.  What is someone clears the NVRam?  now the passwords are reset but the master keys still reside within the ATM.&lt;br&gt;&lt;br&gt;Thanks,</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave</dc:creator><pubDate>Sat, 12 Jan 2008 01:10:57 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320629</link><description>ok, just to clarify some of this, i am a head tech for one of the countries largest atm distributors, so allow me to clarifty.&lt;br&gt;&lt;br&gt;1) if you change the denomination, yes you get away with it, you do NOT have to make a change at the host as the previous poster suggested (that only applies to surcharge, not to dispensed amount)&lt;br&gt;&lt;br&gt;2) all currently manufactured atm's REQUIRE that you change the master password to the atm, the passwords they're using to "hack" these are defaults that the atm's ship at, and for the longest time you didn't have to change them and many people just left them, all current software versions require a password change.&lt;br&gt;&lt;br&gt;3) unless you're using a card generator you can get caught very easily doing this, and most people that try this do get caught, it is possible to look at the changes made on the atm, and when you see the denomination changed, then somebody pulls a load of cash, you just track that card number.&lt;br&gt;&lt;br&gt;4) there is NOT a magic back door, it's just that most people are lazy and don't want to make any changes they don't have to make.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ATM Tech</dc:creator><pubDate>Wed, 14 Nov 2007 12:54:25 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320628</link><description>Alex and ATM guy are both correct.  As an ATM tech, there are lots of back-end procedures that keep idiots like you from stealing from an ATM.  &lt;br&gt;&lt;br&gt;Yes, you can change the denomination at the terminal, but unless it is also changed on the processors end then you'll still be charged the full amount of your withdrawal.  Go ahead and put your card in nub.&lt;br&gt;&lt;br&gt;And how about this?  Instead of feeling like it's your right to scam the IDIOTS who build and run these ATM's, get a job and contribute to society.  The only reason we need the type of security currently found on ATM's is because of worthless two-bit hacks such as yourselves.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Get a Job</dc:creator><pubDate>Wed, 05 Sep 2007 14:19:31 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320627</link><description>There are strict policies and security procedures regarding ATM installation &amp;amp; operation, which when followed properly make this 100% impossible. &lt;br&gt;&lt;br&gt;Unfortunately, the amount of white-label ATM operators who don't follow them is growing. (For example, to enter the secret master keys to connect to the network you are supposed to have TWO separate people enter codes which get mailed to the company in two separate envelopes and they should not be entered at the same time, and they should be destroyed as soon as they are entered.. and companies send one guy to install the ATM all the time, sigh)&lt;br&gt;&lt;br&gt;To make matters worse, some of the newer ATMs do allow you to enter a service menu without opening the ATM or doing anything more suspicious than entering a few codes in the keyboard and a numerical password. (Not that opening the ATM for half a second and closing it (say on an MCD-2) is all that difficult to begin with, at least if you're an ATM technician and have master keys.., but seriously, what were people thinking when they removed this?! And the older machines even required you to open it ALL the way up AND flip a switch inside it to enter supervisor mode (MCD-1) )&lt;br&gt;&lt;br&gt;The only good news is that only the owner of the stolen card who failed to report it stolen (only someone mental would use their own ATM card) OR the silly ATM owner will incur the losses if you simply reprogram the denomination of bills inside the machine. So this means non-moronic ATM providers and users are perfectly safe. &lt;br&gt;&lt;br&gt;PS: Erasing the log only erases it on the machine. The network still has copies of all transactions.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alex</dc:creator><pubDate>Sat, 01 Sep 2007 18:30:05 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320626</link><description>this scam works in the UK, but only on the american type ATM's people say this don't work, it does if it was non-reprogramable then it would be useless because what if the time would alter then it would have to be changed back.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">yaknivek</dc:creator><pubDate>Sat, 16 Jun 2007 23:23:29 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320625</link><description>Yes. But not by much.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 29 Mar 2007 17:32:49 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320624</link><description>What is this blog about? I scroll and find a bunch of kids making asinine threats to one another. Are any of you nitwits older then say 13?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Walter</dc:creator><pubDate>Thu, 29 Mar 2007 17:27:40 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320623</link><description>&amp;gt;What a piece of Garbage. I remember seeing the &amp;gt;prototype of the Tranax at the BAI trade show in &amp;gt;Dallas somewhere around 1999. It’s a real Rube &amp;gt;Goldberg contraption. I believe this thing was &amp;gt;developed in some guys garage. It cannot be &amp;gt;compared to the real ATMs that are made by Diebold, &amp;gt;NCR, and Fujitsu which are remarkably secure and &amp;gt;reliable.&lt;br&gt;&lt;br&gt;The Tranax machine is by far the best 3rd party bank machine made. It is professionally made, well designed and operates flawlessly. We operate a large number of these. I would rather own these than the others you mention, which I have also worked on.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ATM Guy</dc:creator><pubDate>Thu, 22 Mar 2007 14:20:05 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320622</link><description>I work on and program these machines every day. &lt;br&gt;&lt;br&gt;There is a fact you are missing. You can program whatever denomination of bill you want into the machine, however the processor the machine dials into and connects to has to have the matching amount programmed in. If it is set at the processor server end to $20, you can enter $5, $10 whatever the hell you want, it still knows it should have $20's in it.&lt;br&gt;&lt;br&gt;The average layman or even medium tech aware can do little more than screw the machine up by going into management and playing with settings.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ATM Guy</dc:creator><pubDate>Thu, 22 Mar 2007 14:16:43 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320621</link><description>"FBI" needs to take advantage of our public school system before he(she?)makes any sort of legal declarations. "DUH" would be a better handle.  :O/</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Walter</dc:creator><pubDate>Fri, 09 Feb 2007 19:00:06 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320620</link><description>I'm so sorry!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sat, 03 Feb 2007 10:38:03 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320619</link><description>you are a fucking stupid arsehole nothing but a typical deadbeat scamming bastard just close this site down Ill report you son of a bitch to the FBI for money laundering and fraud you'll get 10 years &lt;br&gt;I have copied this website for proof and have your IP adress and adress details and thats all proof they need to aresst your scamming arse , just a reminder when your in prision dont drop the soap</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">FBI</dc:creator><pubDate>Sat, 03 Feb 2007 10:30:54 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320618</link><description>Mmmmm... all of this makes me think of the disaster Diebold has going with their electronic voting machine! If it's electronic you can bet your 'arse' someone can manipulate it.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Walter</dc:creator><pubDate>Fri, 29 Dec 2006 22:23:23 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320617</link><description>With everyone wanting to get ahold of the manual now, it raises a question since I received mine in about 2 minutes.&lt;br&gt;&lt;br&gt;Am I the only one with access to Google?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Blank</dc:creator><pubDate>Sat, 07 Oct 2006 05:02:09 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320616</link><description>Wow, I found out for myself. The manual is out there still, but you have to view it as HTML, to get the cached version of it. What a piece of Garbage.  I remember seeing the prototype of the Tranax at the BAI trade show in Dallas somewhere around 1999. It's a real Rube Goldberg contraption. I believe this thing was developed in some guys garage.  It cannot be compared to the real ATMs that are made by Diebold, NCR, and Fujitsu which are remarkably secure and reliable.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chico</dc:creator><pubDate>Mon, 02 Oct 2006 09:34:42 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320615</link><description>For all those who have "found" the manual.  Isn't there a switch that needs to be flipped before you can enter the "Master Password"  I serviced many different types of ATM machines, and they all had a service switch/key that was located under a locked hood on the stand alone models or in the rear of the machine on the through the wall modeld. This switch needed to be activated before anyone could go into diagnostic or programming modes.  I think there is more to this story that is being left out.  Perhaps the armored car company, left the machine in service mode, or the thief did more than just enter a password.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chico</dc:creator><pubDate>Mon, 02 Oct 2006 09:04:39 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320614</link><description>This reality stuff is scary.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mrskin</dc:creator><pubDate>Sun, 01 Oct 2006 01:53:39 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320613</link><description>@ Chris,&lt;br&gt;&lt;br&gt;Yes, you can still get hold of a copy of the TRANSACTION journal from the switch which links the bank's computer to the ATM.&lt;br&gt;&lt;br&gt;However, the transaction journal does not include terminal-only entries like power on/off, change of receipt layout or changes to passwords. Dial-up machines like the Minibank only communicate with the switch (and bank's computers) when there is something "interesting" happening, like a request for cash to be dispensed.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ATM Tech</dc:creator><pubDate>Tue, 26 Sep 2006 01:35:09 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320612</link><description>Hell yes I believe it, in fact the woman who issued me my first VISA card, took me OUT TO THE ATM, and put the card in, and PRESSED THE KEYS to bring up a SPECIAL MENU, in which she ACTIVATED MY VISA.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">[Wah!] Jake's Mom</dc:creator><pubDate>Mon, 25 Sep 2006 10:47:01 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320611</link><description>whoa, that's one clever sonofabitch! lol.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">halfkoreanstudmuffin</dc:creator><pubDate>Sun, 24 Sep 2006 21:41:36 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320610</link><description>jack, [wah!] your mothers [wah! wah!].</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">NightStalker-</dc:creator><pubDate>Sun, 24 Sep 2006 10:22:02 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320609</link><description>why are you all so suprised?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">retards</dc:creator><pubDate>Sun, 24 Sep 2006 05:37:49 -0000</pubDate></item><item><title>Re: ATM Backdoor&amp;#8230;  Why is no one talking about this?</title><link>http://www.matasano.com/log/506/atm-backdoor-why-is-no-one-talking-about-this/#comment-2320608</link><description>yeah then what? I will skin your [wah!] after I [wah wah!] her then I put a shotgun to your [wah wah wah] and rip off your [wah!] head, after that I torture and [wah wah wah wah] your whole family if you open your mouth again [wah!]...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">jack-</dc:creator><pubDate>Sat, 23 Sep 2006 11:17:19 -0000</pubDate></item></channel></rss>