11 ms·
DefCon Hackers Tell How They Cracked Brink's Safe in 60 Seconds
- striking 11y agoSo the hack is a classic kiosk mode breakout, like you could try to do with poorly secured public computers. The wonder here is not in the hack, because it's just a set of keypresses and mouse clicks. The wonder instead lies with the the manufacturer who made a safe stupid enough to be bypassed with a mouse and keyboard.
- wil421 11y agoWho put the USB port on the outside? The article made it seem like they didnt need to use the USB port for normal operations (unlocking/locking). So why didnt they face it toward the safe or disable access somehow until the safe is unlocked. I'm not going to even touch on the Windows XP issue.
- gambiting 11y agoWindows XP is completely safe if: 1) is not connected to the internet 2) you can't add external storage I see people getting upset all the time about cashier tills running windows xp - but that doesn't make any sense. If the software works fine in that situation then it could be just as well running windows 3.11 and I don't see a problem.
- kefka 11y agoKeep telling yourself that. There are unpatched 0-days that go back years that still make WinXP dangerous to have on any sort of network. Not only that, but they will never be fixed. Nor can you fix them yourself (no source code). And yes, cash registers will be networked because of data mining. I can get an accurate picture of store utilization solely by watching registers. And also by seeing what was purchased, I can change inventory appropriately. So yes, networking is essential. Perhaps it's not for the small business that handles flea markets and such.
- gambiting 11y agoSo the machine connected to your Windows XP tills has internet access and/or external storage enabled. Of course that's not safe....if I said "not connected to a network" would that be better?
- kbenson 11y agoYou can say that... but I think GP's point is that there's an obvious behavioral pattern to that, which is less data mining of your sales info and customer's buying habits, compared to the sometimes unobvious but major downside of the terminals being hacked. I think we've seem what choices businesses make when presented with the obvious upside over the poorly understood downside.
- kefka 11y agoNope. You just flipped one of your caveats: no internet connectivity. I only specified networking. Its also how Target was attacked. Their registers are networked yet there was a hole from the internet to their corporate net. That hole was through their HVAC control system. The Tl;Dr. Is that you design a secure system, so that if one part fails, the whole system doesn't fall like a house of cards. Security through layers.
- eli 11y agoWindows XP Embedded is still supported and still gets security patches. I'm also pretty sure you can get the source to it too, if you pay Microsoft and sign an NDA.
- goldmouth 11y agoWindows XP; the security researchers favorite distro. There are few things better than showing up to a security review gig and have them running XP. Makes my job super easy and clients love when I rain down bugs. It's even better because we can actually write exploits in a short time frame. Love XP.
- emcrazyone 11y agoSomewhat related, check this out. In the video they theorize that the power line attack is obfuscated by software techniques. An old OS may have buggy USB drivers I can imagine but they claim the OS does not matter. https://www.youtube.com/watch?v=mdnHHNeesPE https://www.youtube.com/watch?v=mdnHHNeesPE and this https://www.youtube.com/watch?v=HxQUKAjq-7w https://www.youtube.com/watch?v=HxQUKAjq-7w
- deleted 11y ago[deleted]
- pjc50 11y agoEvidently it's not completely secure if you can add an external keyboard and it's in kiosk mode. (Having worked somewhere close to the field of XP-for-POS, the answer appears to be that the customers really do not like having to do updates. They'd much rather just firewall the tills and hope they don't suffer a stuxnet. They're attacked surprisingly rarely because you can't steal money over the internet this way.)
- x0054 11y agoI am guessing it's a failsafe in case the touch screen on the safe fails and they need to plug in a keyboard to open it / diagnose it. It's a legitimate thing to do, but you would think that the USB port would have protection. For instance, the USB port could be on a daughter board, and requires you to enter a password on the plugged in keyboard before the daughter board would complete the connection to the main motherboard. The really simple method would be to at least have a USB Lock that plugs into the USB port, and once locked it hooks into a USB port and if physically ripped out without unlocking, it would rip out the USB port with it. This is something they can retrofit quickly while figuring out other problems with their software problems.
- allworknoplay 11y agoAuto-enabling keyboard input at all is totally crazy; if you can type you can compromise something. my last startup (it's still around, just without me) makes kiosks with touch displays and accessible usb ports, and disabling that shit was the first obvious move. We then allowed them to be re-enabled selectively based on a challenge-response touch screen input (didn't require connectivity, just pre-shared keys to verify the response) or via our server (if connectivity was stable and the touch screen had an issue). Assuming you have a team competent enough to build a platform that you can at minimum reboot and ensure it'll always come back up, you'd never, ever want to automatically let someone access your system.
- timboslice 11y ago10+ years ago I was at a public library with terminals that were in kiosk mode with IE in fullscreen, hidden start menu etc. I used a paperclip to eject the cd drive, put in a CD with autorun, and voila, visible start menu and was able to get to the internet from IE
- mtuncer 11y agoanything exposed outside is a potential risk. If there is a button you press it. If it is a hole, you stick something inside. Having a usb outside is invitation to do something with it.
- amalag 11y agoI hear Brink's QA department is hiring.
- golergka 11y agoI hope they are also firing.
- juliangregorian 11y agothatsthejoke.gif
- mannykannot 11y agoQA is not the solution - this is a design failure.
- sliverstorm 11y agoKiosk breakouts were fun as a kid. I used to get around time limits on library computers by breaking out via the volume control tray icon.
- allworknoplay 11y agoSeriously -- this is ludicrous. I founded a hardware tech company a few years back that does a similar thing (machines in very public places) and -- knowing approximately dick about building robust hardware -- auto mounting of input devices was basically the first thing I locked down once I had the basics up and running. What a stupid vulnerability.
- Vexs 11y ago"tool that Salazar and Petro created basically emulates mouse and keyboard presses" USB Rubber ducky? Neat tool that is.
- VMG 11y agoThanks, haven't heard of it before http://usbrubberducky.com/ http://usbrubberducky.com/
- Vexs 11y agoIt's pretty cool- afaik, it's based off of the teensy 2.0 uC. There's actually some neat firmware that lets it emulate a flash drive at the same time as a keyboard/mouse, allowing you to deploy software on the flash drive. For that reason especially, it could be useful for anyone in IT.
- powertower 11y ago> Oscar Salazar, senior security associate at security firm Bishop Fox explained that money inserted into the CompuSafe is automatically deposited to the retail store's bank account. In-case anyone was also wondering what that is, after looking it up, it's provisional credit with the bank... The safe transmit daily deposit data to the bank, and the bank credits your account.
- ams6110 11y agoWhich they will certainly debit out of your account if the money isn't actually in the safe.
- mfoy_ 11y agoInteresting article aside, was the shadowy ninja with a fedora really necessary?
- Polecat 11y agoScience is my rifle. Intellect is my blade.
- usefulcat 11y agoAlso, isn't that figure holding the sword with the blade pointed towards his own neck? The blade looks pretty straight compared to most katana pictures I've seen but notice the tip.
- 0xffff2 11y agoIt's straight because it's a Ninjato[1], not a katana. It's most definitely being held backwards though. [1] https://en.wikipedia.org/wiki/Ninjat%C5%8D https://en.wikipedia.org/wiki/Ninjat%C5%8D
- FLUX-YOU 11y agoI'm starting to think it's actually a running joke and all technical/security writers just have a League of Shadows to keep cyberfedorabushido alive
- edc117 11y agoThey've known about the vulnerability for a -year-?? Come on. In some fields, fine, but in a safe company?
- mfoy_ 11y agoThey probably assumed that the cost of fixing the issue and actually pushing that fix to every unit in the field would outweigh the cost of not fixing it.
- john_b 11y agoTrue, though now that it's public they may start accounting for the potential cost of lawsuits within the next year.
- celticninja 11y agodepending on how the usb slot is used surely the fix could be as simple as a tube of superglue (assuming you dont need the usb slot).
- mannykannot 11y agoWe will see if they dare use the 'it is not supposed to be secure' excuse that lock-maker Onity made (Onity is the company that charged its customers for fixing its faulty product.)
- patio11 11y agoA strong engineering case can be made for "Look, if you installed a Brinks safe for a year, experienced no employee theft, and then had an Evil Hacker come in and swipe $10k from you, you got excellent ROI. Your insurance will inevitably pay the claim. We'll reimburse them. They won't cancel your policy. 998 similarly situated stores lost nothing; the last one had someone crash a pickup truck through the window and winch the safe away. Terrible thing, that, but that's why we're all insured." You don't buy a safe so that you'll never get robbed. Banks don't have that as a desirable security posture! [+] You buy a safe to cheaply decrease the total cost of theft. [+] Fun fact: average bank robbery costs the bank only $8k or so in lost cash. This is one of the many reasons why every bank in the country has In The Event Of A Bank Robbery Don't Try To Be A Hero Seriously It's Pocket Lint in their training about it.
- coldcode 11y agoEven funnier that the money is the banks' once it goes into the safe. So once again the reason to rob a bank is "that's were the money is" except here you can do it with a usb widget. If the money stays in the safe overnight (how often do the Brinks people come?) it's a pretty easy score.
- logfromblammo 11y agoNow, I'm not all that familiar with the banking industry, but it seems like assuming ownership of bearer instruments (banknotes) before they are actually in your possession seems like a risky practice. You're basically assuming that all those third parties involved in securing your property are going to do their very best to prevent you from losing it, without actually having much at stake themselves. If the transfer of ownership is completed the instant the store drops the cash into the safe, they only have an interest in securing the path to the point of deposit, and have no interest in securing the safe itself. Indeed, the naive criminal plot would be to adjust the store surveillance cameras such that the safe-deposit process could be visually verified, but the cracking process would be obfuscated. Then a store employee cracks the store's own safe, takes the money out, and takes it out through the loading dock with the trash. [Edit:] It seems as though the safe credit is actually a provisional deposit, and banks aren't all that crazy after all.
- pjc50 11y agoBanks are quite adept at both insurance and recovery from petty fraud.
- soyiuz 11y agoIs it exactly 60 seconds? Or more like 58? or 71? Not a fan of such sensationalist headlines.
- acveilleux 11y agoIt's probably blind so it's more like "about a minute".
- Spoom 11y agoI predict they will attempt to shut down the talk before it happens via legal means.
- beambot 11y agoI have a question about this: With all the BlackHat / Defcon talks that have been squelched over the years in the run-up to the conference... why do they still advertise talks ahead of time? Wouldn't it be much, much better to just keep the topics secret until the moment of disclosure?
- orf 11y agoThat would derail the hype train
- jhull 11y ago'...[they] literally "smashed" on the keyboard to see what would happen when arbitrary keys were pressed together. Using that smashing technique, the researchers were able to figure out how to escape the kiosk mode.' They also just invented the newest SaaS model: "Smashing as a Service"
- stygiansonic 11y agoSounds like keyboard fuzzing; a strange way to get out of kiosk mode, but hey, it worked.
- hwillis 11y agoCertainly does. Public terminals at Boston University used to crash to desktop if you smashed on the keyboard enough.
- kbenson 11y agoThis is a tried and true technique used by students for decades.
- FeepingCreature 11y agoWhen I was a kid, a bookstore nearby had a computer where you could download free software, with a closed interface. Anyway, some guys came along and were like "look, we're gonna hack this thing", at which point they started mashing on the keyboard like madmen. (The poor beeps of that abused computer ...) And now you're telling me this is an actual thing?? My life is a lie.
- kbenson 11y agoWhat do you think fuzzing is? Keyboard mashing taken to 11. ;)
- GauntletWizard 11y agoI learned an awful lot about software testing and security as a kid trying to sneak illicit games onto school computers. Granted, this was in the 95/3.1 days, so it was a little easier ;)
- at-fates-hands 11y agoSo if they can use the exploit to open the safe, I'm assuming there is a way to then lock the safe down and keep the Brinks and company employees out of the safe?
- xenophonf 11y ago"So the issue isn't so much that there is no acknowledgment that there is a problem; rather, the vendors have been pointing fingers about whose problem it is for over a year, without progress made on the actual resolution." And my colleagues wonder why I support full disclosure. I tell you what - if I was a bank that used these products, I'd be going around and epoxying these USB ports closed ASAP.
- david_shaw 11y agoI used to work as a penetration tester, and one of our clients hired us to perform a "custom application" assessment. I can't give specific details (for obvious NDA-related reasons), but this application was a large device that interfaced with mission-critical hardware -- and ran Windows XP embedded. They'd done a pretty good job securing the OS and device itself: we couldn't actually connect it to any networks, so network penetration testing was difficult, and there were no USB ports or CD drives. Unfortunately for them, they did leave an archaic port open on the back of the device. Now, this wasn't a USB port or anything, but (with certain difficult-to-source adaptors) we were able to get an external 3.5" floppy drive hooked up -- through which we could (slowly) load arbitrary executables, and take over the device. When we explained this finding, the client told us that certain customers of theirs required this port for proprietary communication, and that they couldn't remove it from production. The end result was that for every production run of this device that wasn't going to one of those edge-case customers, epoxy was manually applied to close off the port. Not the most elegant solution, but I guess it worked!
- x0054 11y agoWhy not simply score the motherboard around the port to cut the traces? Epoxy sounds like such an inelegant solution. But I am a neat freak :)
- xenophonf 11y agoI personally would prefer epoxy because just about anybody can apply it, whereas to safely cut traces on a motherboard requires someone with a modicum of technical skill, the purchase of suitable tools, hardware testing afterwards, etc.
- zimbu668 11y agoI was expecting something like this: https://www.youtube.com/watch?feature=player_detailpage&v=nBhOjWHbD6M#t=148 https://www.youtube.com/watch?feature=player_detailpage&v=nB... but USB sticks are probably a little less suspicious than crow bars.
- christop 11y agoSomebody took Microcorruption a bit too literally!
- god_bless_texas 11y agoIs this actually made by Brinks?. Loomis offers a similar product named "SafePoint". From the pictures, it looks like the same hardware. I wonder if the vulnerability is specific to the customer or the hardware?
- tlb 11y agoMade by Tidel. http://www.tidel.com/ http://www.tidel.com/.
- gcb0 11y ago> safe had a usb port. nothing else to read here.
- flashman 11y agoThis sounds a lot like Samy Kamkar's USBdriveby tool: http://samy.pl/usbdriveby/ http://samy.pl/usbdriveby/ USBdriveby is a device you stylishly wear around your neck which can quickly and covertly install a backdoor and override DNS settings on an unlocked machine via USB in a matter of seconds. It does this by emulating a keyboard and mouse, blindly typing controlled commands, flailing the mouse pointer around and weaponizing mouse clicks.