UKAU

Security, Compliance & Awareness

Hacking Horror of the Month - Hacking ATMs

A recent news story from Virginia, USA highlights the pitfalls of failing to change default passwords.

A man walked up to an ATM at a service station and, using the standard console accessible to all users, reprogrammed the machine to dispense $20 notes instead of $5 notes.  Net result was that if a customer requested $80, the machine would dispense $320, but the customer’s account would only be debited $80!

It transpired that the password for the machine allowing access to diagnostic mode had been left at its default setting – which in turn was published in an online service manual.  (The manual also gave any reader additional helpful information such as default combinations for the safe and instructions on how to enter diagnostic mode).

It was nine days before an unusually honest user flagged the situation with staff at the service station.  We do not know how many punters “hit the jackpot” in the meantime!

Whilst the story sounds like one of those popular urban myths, it is apparently true (read it in full at http://www.securityfocus.com/brief/310) and, from a security perspective, highlights the importance of changing default password settings at network entry points.  As part of penetration testing projects, Safecoms naturally checks to see whether any of the client’s Internet facing hosts have weak remote access authentication settings.  On more than one occasion we have found Internet facing servers accessible through well known default passwords – the hacker’s equivalent of the overly generous ATM.


InfoAware

InfoAware is our training solution for User Awareness, IT Staff Awareness and Information Governance.  Covering all the relevant topics required by international standards such as ISO 17799, it comprises a multimedia Video/DVD and Learning Management System. 

InfoAware is easy to deploy over the Intranet and can be used for induction and refresher training courses.  InfoAware takes users through a multi-choice question and answer session on each topic and allows organisations to deploy additional training material and policy documents to all staff.

More details can be found at www.infoaware.com

Contact

Safecoms has operations in the UK and Australia, with representatives in the USA, Asia and the West of Scotland.

If you would like someone from Safecoms to contact you please email us at info@safecoms.co.uk