Ben Cantrick (mackys) wrote,
Ben Cantrick
mackys

  • Mood:

[Reddit] Freestanding ATMs don't encrypt your account info before sending it over the phone lines.


The phone line running from the ATM machine to an ordinary British Telcom socket was unplugged and a two-way adaptor inserted. The MP3 player was then placed between the ATM machine’s output cable and the phone socket. The player would record the tones, which resemble the kind of sound emitted by a fax machine. These were then interpreted using a modem line tap, or MLT, acquired from Canada, or passed through a computer software program bought illicitly in Ukraine.

Parsons was able to exploit his knowledge of credit card security systems to put together credit card numbers and the cards’ expiry dates. The gang used the data to encode and clone a number of credit cards. The stolen data were later tracked back to purchases worth £200,000, although police were able to trace only £14,000 to Parsons.


http://www.timesonline.co.uk/article/0,,29389-2453590,00.html


Best hack I've heard of in months! Recording modem signals with a fake phone jack with an iPod inside, then analyzing them to get the numbers. Sweet!

As for the banks, hey guys: Public Key Crypto. I know, it's just so new and fancy...
Subscribe
  • Post a new comment

    Error

    default userpic

    Your reply will be screened

    Your IP address will be recorded 

    When you submit the form an invisible reCAPTCHA check will be performed.
    You must follow the Privacy Policy and Google Terms of use.
  • 2 comments