Wed Oct 31, 2012, 12:57 PM
mahatmakanejeeves (3,669 posts)
60-Second Cash Kiosk Hackers Steal $1 Million: FBI
Source: Information Week
By Mathew J. Schwartz InformationWeek October 31, 2012 12:02 PM The FBI has arrested more than a dozen people on charges that they participated in a gang that stole over $1 million via cash-advance kiosks at 11 casinos and resorts. According to the FBI, the related indictment, unsealed Friday, said the gang "stole the money by exploiting a gap--which required multiple withdrawals all within 60 seconds--in Citibank's electronic transaction security protocols." The gang predominantly targeted casinos and resorts in Las Vegas and southern California. .... According to court documents, accused ringleader Ara Keshishyan, 29, recruited other members of the gang to open multiple Citibank checking accounts, which he filled with seed money. "When inside the casino, the conspirators, including Keshishyan, used cash advance kiosks at casinos in California and Nevada to withdraw -- all within 60 seconds -- several times the amount of money deposited into the accounts, by exploiting the Citibank security gap they discovered." .... Attackers are increasingly using a simple method for finding flaws in websites and applications: They Google them. Using Google code search, hackers can identify crucial vulnerabilities in application code strings, providing the entry point they need to break through application security. Read more: http://www.informationweek.com/security/attacks/60-second-cash-kiosk-hackers-steal-1-mil/240012604
|
14 replies, 2065 views
| Author | Time | Post | |
| mahatmakanejeeves | Oct 2012 | OP | |
| corkhead | Oct 2012 | #1 | |
| SoapBox | Oct 2012 | #3 | |
| Ikonoklast | Oct 2012 | #2 | |
| cosmicone | Oct 2012 | #4 | |
| mikeytherat | Oct 2012 | #5 | |
| DoBotherMe | Oct 2012 | #7 | |
| Doremus | Oct 2012 | #10 | |
| Kelvin Mace | Oct 2012 | #9 | |
| htuttle | Oct 2012 | #12 | |
| olddad56 | Oct 2012 | #6 | |
| dixiegrrrrl | Oct 2012 | #8 | |
| PopeOxycontinI | Oct 2012 | #11 | |
| Volaris | Oct 2012 | #13 | |
| KansDem | Oct 2012 | #14 |
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 01:01 PM
corkhead (3,989 posts)
1. No honor among thieves
|
Poor Shitibank
|
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 01:04 PM
Ikonoklast (21,699 posts)
2. But Republicans that steal BILLIONS can't ever be found.
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 01:04 PM
cosmicone (3,428 posts)
4. It is pretty lousy programming.
|
When one transaction opens, it should lock the account until it is complete before another transaction can be started whether in 60 seconds or not.
|
Response to cosmicone (Reply #4)
Wed Oct 31, 2012, 01:17 PM
mikeytherat (6,827 posts)
5. Exactly. Whatever happened to record locking?
|
That's old school.
mikey_the_rat |
Response to cosmicone (Reply #4)
Wed Oct 31, 2012, 02:03 PM
DoBotherMe (1,778 posts)
7. Can citibank make money in 60 seconds?
|
That would be a reason to overlook security. Dana ; )
|
Response to DoBotherMe (Reply #7)
Wed Oct 31, 2012, 02:27 PM
Doremus (5,161 posts)
10. Or security costs money they'd rather funnel to themselves than the 99%. nt
Response to cosmicone (Reply #4)
Wed Oct 31, 2012, 02:25 PM
Kelvin Mace (9,904 posts)
9. i'm guessing
|
based on when I worked installing PCs in banks and got to ask lots of questions of the ATM guys that they are sacrificing security for speed. But, this all begs the question: Why is the source code for ATMs on the net? Didn't Diebold learn anything with the voting machine fiasco?
|
Response to cosmicone (Reply #4)
Wed Oct 31, 2012, 05:55 PM
htuttle (21,196 posts)
12. Comp Sci 101
|
Writing a simple transaction engine that locks the account and avoids issues like this is often one of the class assignments.
Guess the ATM programmers didn't take that class? |
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 01:44 PM
olddad56 (2,867 posts)
6. they stole the money that Citibank stole from the taxpayers during the bailout.
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 02:16 PM
dixiegrrrrl (31,437 posts)
8. I want to know more about this "security gap"
|
( pen and paper at the ready....)
|
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 03:56 PM
PopeOxycontinI (127 posts)
11. I bet we see...
|
a lot of this shit after Sandy. Lots of people camping out at
unsecured wi-fi spots. Easy for a hacker to get your shit that way. |
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 06:18 PM
Volaris (1,594 posts)
13. I know it's tantamount to supporting vigilante justice,
|
but honestly, I almost can't feel bad for Citibank. Fuck em.
|
Response to mahatmakanejeeves (Original post)
Wed Oct 31, 2012, 08:04 PM
KansDem (24,510 posts)
14. Time to send in...
|
Robert De Niro!
Anyone got a hammer? |

