DEF CON Safe Mode - Trey Keown and Brenda So - Applied Cash Eviction through ATM Exploitation

Поделиться
HTML-код
  • Опубликовано: 21 ноя 2024

Комментарии • 55

  • @Solid_Fuel
    @Solid_Fuel 4 года назад +79

    audio quality already makes this so much better than so many other talks on this channel

    • @celestemangonya
      @celestemangonya 3 года назад

      yeah for a conference with a huge number of computer professionals they sure seem to have an issue recording a simple talk lol

  • @summarity
    @summarity 4 года назад +11

    Every single presenter has a different solution for audio, yet they're all better than the in-person DEF CON recordings ever were.

  • @DavidTomaschik
    @DavidTomaschik 4 года назад +54

    It's got to be so hard to give a talk to just a camera. No audience energy to feed off of. Great work for doing so.

    • @ClumsyCars
      @ClumsyCars 4 года назад +5

      Here I was sitting here thinking to myself "what a dead crowd"

    •  4 года назад +1

      Just imagine a Twitch chat going "driink! DRIIIIIIIIINK!"

  • @logicawe
    @logicawe 4 года назад +38

    I just came to watch it rain cash. I was not disappointed. 49:15

  • @neverbetter5434
    @neverbetter5434 4 года назад +4

    The video ending with cash just dripping out of the ATM is so BALLER. You guys did such a great job walking everyone through the reverse engineering that went into this and the conclusion is totally worth it. Next time drop the mic!

  • @DrTune
    @DrTune 4 года назад +16

    "Copies the TCP packet to a global buffer without a bounds check". ... LOL!

  • @pyramydseven
    @pyramydseven 4 года назад +16

    Great job. Sadly, as long as the people who make decisions about investing in security, which I would like to say know absolutely nothing about technology let alone security, continue to ignore advice, continue to cut corners, continue to exploit their employees and/or consultants, these types of situations will continue to exist. Great job guys and gals!

    • @uuuuuhhlettuce3909
      @uuuuuhhlettuce3909 4 года назад +1

      Sad for whom? ;)

    • @swine13
      @swine13 4 года назад

      @@uuuuuhhlettuce3909 well, us. The consumers who get left with all the costs being pushed on us, at the end of the day.
      Every time a big company like this gets robbed, you think the CEO foots that bill? No, they just restructure their payment models and shift things around and we end up paying for it.

  • @psy0rz
    @psy0rz 4 года назад +1

    Very good talk and excellent reversing job!

  • @matrixstorm00
    @matrixstorm00 4 года назад +1

    Really enjoyed this talk. Thank you!

  • @andrewbonstrom2252
    @andrewbonstrom2252 4 года назад

    Excellent talk! Thanks for the share

  • @David-mw8vr
    @David-mw8vr 4 года назад +1

    red balloon always does the coolest shit they were on vice and did some awesome stuff

  • @Theobroma-p3n
    @Theobroma-p3n 4 года назад

    Best. panel title. ever.

  • @wisid
    @wisid 4 года назад +7

    Awesome, doom. The challenge should be shooting enemies to get your cash

  • @u0000-u2x
    @u0000-u2x 4 года назад +1

    great presentation. nice job rbs

  • @excitedbox5705
    @excitedbox5705 4 года назад +1

    why desolder the chip multiple times instead of mounting it on a pcb and with some test pads? Or make it socketed. Once you can load your own firmware you could just activate the make it rain function by activating the bill dispenser.

  • @boubtanehoussem9104
    @boubtanehoussem9104 4 года назад

    Great talk ! Keep it up

  • @thomaskellar5148
    @thomaskellar5148 4 года назад

    Great talk

  • @jamesfreewill3084
    @jamesfreewill3084 4 года назад

    I been working on this project for fun myself

  • @SD-xu3mz
    @SD-xu3mz 3 года назад

    based

  • @ScottHughes
    @ScottHughes 4 года назад +12

    Great talk, but "umm" needs to be piped to /dev/null

    • @TreyKeown
      @TreyKeown 4 года назад +6

      Haha! Unfortunately true, wish it were that easy. Didn't catch the level of "umm"s until well after we shot the talk.

    • @Prohibitorum
      @Prohibitorum 4 года назад +4

      @@TreyKeown Recording and seeing yourself talk like this is the easiest way to fix these things! Next talk you'll do it less, I'm sure. I find just quiet instead of 'uhm' works great, and found it easy to adapt to doing that.

    • @swine13
      @swine13 4 года назад

      @@TreyKeown My favourite thing to do was just try and consciously change my "umm"s to "uhh/ahh"s - I had a friend who worked in the business of phone sales, as he was saying that making "uh" sounds instead of "um" can make you sound more... polished? Professional? I can't remember the P word but it was supposed to sound better to people.
      I found it was way easier to get myself saying "uhh" reliably, as opposed to un-teaching myself a habit that I've had for 30 or so years in saying "um". 😁
      (Fwiw i dont even know what the difference is. If there is one, it's definitely working on a subconscious level AFAICT... 🤔)
      Ps. really cool talk - thanks!!

  • @ben-brady
    @ben-brady 4 года назад +8

    First, good talk.

    • @Dorumin
      @Dorumin 4 года назад +5

      man the talk is 50 minutes long and you commented 3min after posting

    • @pyramydseven
      @pyramydseven 4 года назад +6

      @@Dorumin Hey, some people are just great at determining an overall level of success in mere minutes. Or, perhaps this person has already watched it, perhaps in person. Perhaps, they hacked the matrix.

    • @Dorumin
      @Dorumin 4 года назад

      @@pyramydseven cue "What is real" speech

    • @lilz3bra
      @lilz3bra 4 года назад +1

      @@Dorumin I used to "study" 600+ pages in 30 minutes before an exam back in college so it might be possible to watch an hour long video in 2 minutes...

    • @swine13
      @swine13 4 года назад

      @@lilz3bra you can definitely do this with the titanic. You can just skip to the last 3min because it turns out the boat sank anyway

  • @SergeyKataev
    @SergeyKataev 4 года назад

    Nice :D

  • @henke37
    @henke37 4 года назад +1

    And of course doom runs smoother than any other software on the system.

  • @QuadDerrick
    @QuadDerrick Год назад

    hope bankers dont kill brenda so like they killed jack barnaby

  • @BillyHudson1
    @BillyHudson1 3 года назад

    Canadians are nice but don't mess with our tax man.

  • @meonline44
    @meonline44 4 года назад

    Ummm...

  • @excitedbox5705
    @excitedbox5705 4 года назад

    Did you try enabling USB? A lot of ATMs have the USB turned off as a security measure. There was a gang of thieves ripping the Camera out of ATMs and hooking a USB keyboard to the wires.

    • @swine13
      @swine13 4 года назад

      But what if there isn't any keyboard drivers or anything written into the firmware? Like at the start? Wouldnt the USB keyboard just not work?

    • @excitedbox5705
      @excitedbox5705 4 года назад

      @@swine13 ATMs run on windows and unless they take out the driver or like I suggest disable it, the keyboard will work. That is how this gang got in. The ATMs used USB for their security cameras so by cutting the camera off and splicing in a USB keyboard they were auto detected. USB is not like ps2 or serial where the system only activates the device on boot since you don't want to reboot to use a flash drive or whatever.

  • @SLLabsKamilion
    @SLLabsKamilion 4 года назад

    This is so frustrating to watch with all the 'um' and 'uh' pauses from Trey.

  • @lynzoido
    @lynzoido 4 года назад

    Mey lau. I cook you eat. Shin shin. So life-like

    • @lynzoido
      @lynzoido 4 года назад

      @@remley8877 me rikey

    • @cypher9000
      @cypher9000 4 года назад +1

      I'm so ronery.

  • @glitchedpixelscriticaldamage
    @glitchedpixelscriticaldamage 4 года назад

    Lame.