Investor Presentaiton
ATM Vulnerabilities
Most ATM machines are based on a Windows operating system and have a standard PC
architecture which may have vulnerabilities that increases their risk exposure:
16
Application Vulnerabilities
Logic errors for "On Us"
and/or "Not On Us"
transactions
Inappropriate PIN
validation behavior
Unexpected application
response to user error
conditions
Unexpected application
response to user cash
tampering
Logging/storage of
sensitive customer
information or
cryptographic material
Ability of maintenance
personnel to bypass
application controls
.
Network Based Vulnerabilities
Existence of vulnerable
and/or unnecessary
network services
Existence of exposed
administrative interfaces
• Use of insecure
communication protocols
Existence of permissive
firewall rules within the
ATM network or VPN
terminator
•
Host Based Vulnerabilities
Unnecessary running
services
Missing patches
•
Insecure default
configurations
Insufficient audit logging
User account management
weaknesses
Inappropriate anti-virus
and/or firewall
configurations
Weak password and
account policies
Weak ATM BIOS
configurationView entire presentation