DEF CON 32 - Where’s the Money-Defeating ATM Disk Encryption - Matt Burch

DEF CON 32 - Where’s the Money-Defeating ATM Disk Encryption - Matt Burch

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 38:32

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video reveals a critical vulnerability in Debold Nixdorf’s Dynamic Security Suite, exposing ATM systems to full compromise via unencrypted Linux partitions and flawed pre-boot authentication. Despite multiple patches, the attack surface remains recursive and exploitable across all versions due to weak integrity checks and lack of encryption. 0:50

Key Takeaways:
• The ATM industry uses two classes of systems—consumer-grade and enterprise-class—with significant security gaps in the top hat (non-secure) portion 1:14.
• Debold Nixdorf’s Dynamic Security Suite uses an unencrypted Linux partition ("super sheep") that allows attackers to manipulate boot processes and gain root access 2:39.
• A critical vulnerability in version 18x allows attackers to bypass pre-boot authentication by modifying background images and exploiting unvalidated files 13:22.
• Attackers can pivot from Linux to Windows using mount wiart to decrypt the OS, enabling malicious code execution and money dispensing 19:07.
• Multiple service releases (e.g., 12, 15, 16) introduced mitigations, but each created new attack vectors—such as null sum checks and sim link manipulation—proving the vulnerability is recursive 27:45.
• The root cause is the unencrypted Linux system; full disk encryption and disabling TPM key exposure via "Enable Security Check" are recommended defenses 37:05.

This research has led Debold to redesign super sheep with full encryption in version 4.4, but organizations must proactively patch and enforce physical access controls to mitigate ongoing risks. 36:47(https://www.you

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

over the past several years this content has been both a passion and an obsession of mine that has led me down some very interesting paths and I am very honored and privileged to be able to finally do public disclosure of this content here today so my name is Matt bur and I am an independent security researcher with a passion for iot and Hardware devices I have developed several MFA bypass tools affecting various MDM Solutions I have performed expert opinion against a major ATM manufacturer and I have had the opportunity of examining cartel designed ATM blackbox devices for today's agenda we'll take a brief look at the ATM industry and then we'll introduce Debold Nix dorf's dyamic Security Suite uh we'll then dive a little bit deeper into the pre-boot authentication process implemented wit…