HomeLatest ThreadsGreatest ThreadsForums & GroupsMy SubscriptionsMy Posts
DU Home » Latest Threads » Forums & Groups » Main » Latest Breaking News (Forum) » 60-Second Cash Kiosk Hack...

Wed Oct 31, 2012, 12:57 PM

60-Second Cash Kiosk Hackers Steal $1 Million: FBI

Source: Information Week

By Mathew J. Schwartz InformationWeek
October 31, 2012 12:02 PM

The FBI has arrested more than a dozen people on charges that they participated in a gang that stole over $1 million via cash-advance kiosks at 11 casinos and resorts.

According to the FBI, the related indictment, unsealed Friday, said the gang "stole the money by exploiting a gap--which required multiple withdrawals all within 60 seconds--in Citibank's electronic transaction security protocols." The gang predominantly targeted casinos and resorts in Las Vegas and southern California.
....

According to court documents, accused ringleader Ara Keshishyan, 29, recruited other members of the gang to open multiple Citibank checking accounts, which he filled with seed money. "When inside the casino, the conspirators, including Keshishyan, used cash advance kiosks at casinos in California and Nevada to withdraw -- all within 60 seconds -- several times the amount of money deposited into the accounts, by exploiting the Citibank security gap they discovered."
....

Attackers are increasingly using a simple method for finding flaws in websites and applications: They Google them. Using Google code search, hackers can identify crucial vulnerabilities in application code strings, providing the entry point they need to break through application security.

Read more: http://www.informationweek.com/security/attacks/60-second-cash-kiosk-hackers-steal-1-mil/240012604

14 replies, 2065 views

Reply to this thread

Back to top Alert abuse

Always highlight: 10 newest replies | Replies posted after I mark a forum
Replies to this discussion thread
Arrow 14 replies Author Time Post
Reply 60-Second Cash Kiosk Hackers Steal $1 Million: FBI (Original post)
mahatmakanejeeves Oct 2012 OP
corkhead Oct 2012 #1
SoapBox Oct 2012 #3
Ikonoklast Oct 2012 #2
cosmicone Oct 2012 #4
mikeytherat Oct 2012 #5
DoBotherMe Oct 2012 #7
Doremus Oct 2012 #10
Kelvin Mace Oct 2012 #9
htuttle Oct 2012 #12
olddad56 Oct 2012 #6
dixiegrrrrl Oct 2012 #8
PopeOxycontinI Oct 2012 #11
Volaris Oct 2012 #13
KansDem Oct 2012 #14

Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 01:01 PM

1. No honor among thieves

Poor Shitibank

Reply to this post

Back to top Alert abuse Link here Permalink


Response to corkhead (Reply #1)

Wed Oct 31, 2012, 01:04 PM

3. You said it!

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 01:04 PM

2. But Republicans that steal BILLIONS can't ever be found.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 01:04 PM

4. It is pretty lousy programming.

When one transaction opens, it should lock the account until it is complete before another transaction can be started whether in 60 seconds or not.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to cosmicone (Reply #4)

Wed Oct 31, 2012, 01:17 PM

5. Exactly. Whatever happened to record locking?

That's old school.

mikey_the_rat

Reply to this post

Back to top Alert abuse Link here Permalink


Response to cosmicone (Reply #4)

Wed Oct 31, 2012, 02:03 PM

7. Can citibank make money in 60 seconds?

That would be a reason to overlook security. Dana ; )

Reply to this post

Back to top Alert abuse Link here Permalink


Response to DoBotherMe (Reply #7)

Wed Oct 31, 2012, 02:27 PM

10. Or security costs money they'd rather funnel to themselves than the 99%. nt

Reply to this post

Back to top Alert abuse Link here Permalink


Response to cosmicone (Reply #4)

Wed Oct 31, 2012, 02:25 PM

9. i'm guessing

based on when I worked installing PCs in banks and got to ask lots of questions of the ATM guys that they are sacrificing security for speed. But, this all begs the question: Why is the source code for ATMs on the net? Didn't Diebold learn anything with the voting machine fiasco?

Reply to this post

Back to top Alert abuse Link here Permalink


Response to cosmicone (Reply #4)

Wed Oct 31, 2012, 05:55 PM

12. Comp Sci 101

Writing a simple transaction engine that locks the account and avoids issues like this is often one of the class assignments.

Guess the ATM programmers didn't take that class?

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 01:44 PM

6. they stole the money that Citibank stole from the taxpayers during the bailout.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 02:16 PM

8. I want to know more about this "security gap"

( pen and paper at the ready....)

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 03:56 PM

11. I bet we see...

a lot of this shit after Sandy. Lots of people camping out at
unsecured wi-fi spots. Easy for a hacker to get your shit that
way.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 06:18 PM

13. I know it's tantamount to supporting vigilante justice,

but honestly, I almost can't feel bad for Citibank. Fuck em.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to mahatmakanejeeves (Original post)

Wed Oct 31, 2012, 08:04 PM

14. Time to send in...

Robert De Niro!



Anyone got a hammer?

Reply to this post

Back to top Alert abuse Link here Permalink

Reply to this thread