Cashpoints at two US banks have been infected by viruses, with similar breaches tipped to become more common. Automatic teller machines at two banks running Microsoft's popular Windows software were infected by a computer virus in August, the maker of the machines said on Monday. The ATM infections, first reported by SecurityFocus.com, are believed to be the first of a computer virus wiggling directly onto cash machines.
Computer security experts predicted more problems to come as Windows migrates to critical systems consumers rely on. An unknown number of ATMs running Windows XP Embedded were shut down during the spread of the so-called "Nachi'' worm, said officials at Diebold, which made the ATMs and refused to name the customers affected. The Nachi worm, also called "Welchia,'' was written to clean up after the MSBlast, or Blaster, worm. Instead it crippled or congested networks around the world, including the check-in system at Air Canada. Both worms spread through a hole in Windows XP, 2000, NT and Server 2003.
In January, the SQL Slammer worm led to technical problems that temporarily kept Bank of America's customers from their cash, but did not directly cause the ATM outage. "It's a harbinger of things to come,'' said Bruce Schneier, chief technical officer of network monitoring firm Counterpane Internet Security.
View: The full story
News source: ZDNet UK
Computer security experts predicted more problems to come as Windows migrates to critical systems consumers rely on. An unknown number of ATMs running Windows XP Embedded were shut down during the spread of the so-called "Nachi'' worm, said officials at Diebold, which made the ATMs and refused to name the customers affected. The Nachi worm, also called "Welchia,'' was written to clean up after the MSBlast, or Blaster, worm. Instead it crippled or congested networks around the world, including the check-in system at Air Canada. Both worms spread through a hole in Windows XP, 2000, NT and Server 2003.
In January, the SQL Slammer worm led to technical problems that temporarily kept Bank of America's customers from their cash, but did not directly cause the ATM outage. "It's a harbinger of things to come,'' said Bruce Schneier, chief technical officer of network monitoring firm Counterpane Internet Security.
What's new:
* Installing TLB skins and plugin skins from zip files
* Enhanced tips with icons and some HTML tags support
* Transparency of tips in Windows XP
* Changing time of opening and closing of tips
* Improved integration with Windows XP visual styles
* Options for overlays images: alignment, stretch
* Improved hot keys handling
Bug fixed:
* Impossible to unlock buttons in some cases
* Impossible to run My Computer from desktop virtual folder
* Sometimes nag screen appears in registered version
* some minor fixes
Also some plugins have been updated:
Command Line v.3.0
Drive Space v.2.0
CD Control v.3.0
Net Monitor v.2.0
Mail Monitor 1.9.5 beta

Prolly checks in place to notice missing money/iffy transactions
But if you could without getting caught you could make money up
im not saying im gonna do it, but it certainly is possible
CC numbers / Pins etc are ways to access limited amounts of cash. If someone was to penetrate the network, sniff domain admin details etc, they could find their way into the real money, the central respository if you like. A system that allows you to perform xfers from accounts in bulk, etc.
And obviously I'm talking about this from a security admin POV not a "hell this is a good idea" POV.
I can just imagine going to a cash machine, inserting my card and then the screen flashes a couple of time, and starts to play pong. That would be so funny.
Actually, a large percentabe of them of them have used OS/2. Bank of America has just announced that they are in the process of converting to an embedded version of NT (I beleive it was stripped-down NT4). Seems to me like going from one old technology to another... If something works, stick with it! Even if it is DOS 6.22!
The amount of windows ATM's i have seen with red cross errors is also amusing. Other than to have 'pretty' colours there is no need to use MS on ATM's, stupidity!
I also find them more anoying to use and slower. (well the software) Its like do you want this? do you want do this? NO i just want some money!
Excepts, maybe just before it closes the draw where it gives u your money,
As for getting PIN numbers... don't bet on it. All PIN numbers are encrypted by the ATM and decoded by the bank. Each ATM has a different encryption set.
I thought most ATMs still used X25 because it was so reliable.
I agree with you on security.
I have less to fear about OS security issues (regardless of MS, Linux, OS2, DOS) than someone looking over my shoulder (or with a covert video cam) and mugging me!
This is nothing to start an OS war over...
That's a stupid statement. That is like saying "I won't ever go into an aeroplane because there is a chance it may crash! What's the weather like inside your bubble today?
Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!
Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.