HF2020 XFS ATM Jackpotting Alexandre Beaulieu
HF2020 XFS ATM Jackpotting Alexandre Beaulieu
Jackpotting
21/01/2020 - Alexandre Beaulieu
About Me
Alexandre Beaulieu
• Computer
• Safe
• Cash / Bill Cassettes
• Card Reader
• PIN Keypad
• Tactile Screen
• Cash Dispenser
• USB cables connecting everything
together
• Anti-tamper & anti-intrusion
mechanisms
• Auditing mechanisms
Basics - The Computer
• Command-Line Driven
• Scriptable (Intrusion Testing
Engagements)
• Extendable (Easily add commands)
• Currently, only a fraction of XFS
• Cash Dispenser Modules
• Info Commands
• Will never include XFS SPIs and
drivers
• Link:
https://github.com/GoSecure/xfsc
XFS – The Raspberry Pi Attack
You might have heard of it in the News
• Criminals drill or cut a hole near where the cash dispenser’s USB
cable/port is (Based on ATM model)
• Plug Pi
• Take bills
• Leave before any alarms trigger
XFS – The Remote Jackpotting Attack
Mr. Robot would be proud
Bottom-Line: With XFS access, you have full control over the ATM
hardware
Defending Against Threats
Defense – Outgoing Tunnel
• XFS Specification
• XFS Exploration Tool
• (Drivers not included)
• Use responsibly
• CEN/XFS Jackpotting (Blog)
• Icons: https://draw.io
Questions / Comments ?