Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 44 guests online
You are here:
Home
Resources
News from the Outside World
Juniper Pulls Researcher's Black Hat ATM Talk
EH-Net
May 24, 2013, 03:24:31 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
News from the Outside World
(Moderator:
don
) >
Juniper Pulls Researcher's Black Hat ATM Talk
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Juniper Pulls Researcher's Black Hat ATM Talk (Read 3526 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4168
Editor-In-Chief
Juniper Pulls Researcher's Black Hat ATM Talk
«
on:
July 03, 2009, 11:49:43 AM »
Quote
It's not very often in Las Vegas that the money stays inside the ATM. But that's exactly what will happen at the upcoming Black Hat conference after Juniper Networks decided to scrap a presentation by one of its researchers who was set to show how a cash machine software vulnerability could be used to spew twenty-dollar bills.
The planned talk by Barnaby Jack, titled "Jackpotting Automated Teller Machines," was pulled after the affected ATM maker raised concerns that it would not be able to fix the flaw in time. Juniper did not identify the ATM vendor but said in a statement that others may also be affected by this issue.
"Considering the scope and possible exposure of this issue on other vendors, Juniper decided to postpone Jack's presentation until all affected vendors have sufficiently addressed the issues found in his research," Steve Manzuik, Juniper's senior manager of security research, said in a statement. "As always, Juniper is committed to the responsible disclosure of security vulnerabilities.
It is unclear exactly what Jack planned to unveil in his presentation, but cash machine issues have made the news in recent months. In March, Diebold revealed that it issued a security update for its Windows-based ATMs after a number of its machines in Russia were infected with customized trojans.
"We are reaching out to other ATM vendors with the offer to assist them with promptly and diligently addressing the security risks and vulnerabilities uncovered in Jack's research," Manzuik said.
This is not the first time a Black Hat presentation was deemed too controversial to see the light of day. In 2005, Cisco and Internet Security Systems (ISS), now owned by IBM, threatened to sue researcher Michael Lynn just hours before he was to deliver a talk about vulnerabilities in the Cisco IOS. Lynn quit his job at ISS and proceeded anyway. Soon after, he settled with the two companies, essentially promising not to further discuss the exploit.
In 2007, security services consultant IOActive bowed to pressure from HID Global to withdraw its presentation. IOActive's director of research and development, Chris Paget, had planned to demonstrate security weaknesses in HID's RFID technology.
And last year, a judge in Boston issued a temporary restraining order against three Massachusetts Institute of Technology students who had planned to present their findings on vulnerabilities in the Massachusetts Bay Transportation Authority's subway fare collection system. The MBTA later dropped its lawsuit, but the talk never happened.
Original story:
http://www.scmagazineus.com/Juniper-pulls-researchers-Black-Hat-ATM-talk/article/139402/
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
former33t
Full Member
Offline
Posts: 226
Re: Juniper Pulls Researcher's Black Hat ATM Talk
«
Reply #1 on:
July 05, 2009, 09:38:14 PM »
This of course is just a gut reaction since none of us know the full details about the vulnerability and timelines given to the companies to fix the problem, but I think this is garbage.
If Jack (and/or Juniper) contacted ATM vendors at any time prior to the presentation, they did their due diligence (I mean Black Hat is still more than 3 weeks away still).
As vulnerabilities go, managers often have to sit around in a room and justify how quickly they need to implement a fix. They do some cost benefit analysis and make a determination on how much overtime to pay vs loss of reputation when the vulnerability is disclosed. If this is for real, its a no brainer. If vulnerable ATM's will spit out $20's, seems like there's an immediate loss scenario if I've ever seen one. What is stopping the vendor from getting a fix out on the street in the next three weeks (assuming they were only notified on the 3rd)?
I personally think that while they could use more time (vendors always want more time), this is more about the vulnerability not being released at Black Hat, THE premier security conference. I think vendors in general think "anywhere but Black Hat."
Just my $.02, but that's what I think is going on here.
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
dalepearson
Sr. Member
Offline
Posts: 357
Re: Juniper Pulls Researcher's Black Hat ATM Talk
«
Reply #2 on:
July 07, 2009, 09:20:38 AM »
Its always frustrating when this sort of information sharing gets pulled, and it does seem to be occuring more often.
Personally I think this is a tricky one. I am sure the researchers have given appropriate disclosure, but its not clear if the vendor has got a fix (perhaps Jack made a recommendation) or if a fix has been identified, but its just going to take them to long to get a fix out through the impacted networks.
Like all these things, we dont have the full story, I just hope either way they do get it resolved and make use of the excellent work the security community provide.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Ketchup
Hero Member
Offline
Posts: 1021
Re: Juniper Pulls Researcher's Black Hat ATM Talk
«
Reply #3 on:
July 07, 2009, 10:03:49 AM »
Personally, I can't wait to see what the vulnerability is/was when it does get released. I am also curious what the attack vector will be considering the restricted input controls on an ATM.
Logged
~~~~~~~~~~~~~~
Ketchup
dalepearson
Sr. Member
Offline
Posts: 357
Re: Juniper Pulls Researcher's Black Hat ATM Talk
«
Reply #4 on:
July 07, 2009, 10:16:06 AM »
I wonder if its related to the issue that we have heard about before at the manufacturing process.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.