Ads skipped

DEF CON 31 - Contactless Overflow Code Execution in Payment Terminals & ATMs - Josep Rodriguez

120K views · Sep 17, 2023 · Science & Technology

Comments · 179

  • @TheSparcguy · 3 years ago (edited)

    I can't wait for the next time that I pay for my coffee my payment terminal asks me if I want to play doom.

    265

  • @publicacct5626 · 3 years ago (edited)

    This kind of hack just blows my mind. It was all incredibly easy, basic stuff. JTAG debugging enabled to dump the firmware, accepting 64KB inputs that automatically overflow... We hold the assumption that manufactures do the bare minimum to prevent extremely easy exploits like this. So no one really even bothers to look. But once it's proven that there is incredibly low-hanging fruit available, expect more people to start poking at systems like this to see if they also have easy-mode hacking enabled.

    146

  • @ConstantlyDamaged · 3 years ago

    Very nice work, and huge props for waiting that two years for the vendors. Great talk.

    35

  • @joemerino3243 · 3 years ago

    The video: an incredible find of multiple crippling vulnerabilities in everyday money-handling devices;<br>The comments: oMg thE SoUnd iS bUzZinG

    14

  • @tissuepaper9962 · 3 years ago

    <a href="https://www.youtube.com/watch?v=eV76vObO2IM&amp;t=920">15:20</a> When he said these things don&apos;t have secure boot I could not contain my &quot;woah!&quot;. How the fuck is an ATM part less secure than like basic android smartphones?

    146

  • @davidjohnston4240 · 2 years ago

    I&apos;ve written a lot of security oriented code in my career. These errors are really basic mistakes. It&apos;s pretty shocking to see them present in the majority of payment terminals.

    33

  • @GBlunted · 3 years ago

    Damn, those kiosk 3 terminals are attached to almost everything possible where i live! From Red box to carwash to every vending machine

    36

  • @zerog2000 · 3 years ago

    Wow rolling physical firmware updates on millions of devices is going to be a pain. <br>Ok, let’s be real - alot of the POS stuff may never get patched ;)

    117

  • @arman_ · 3 years ago

    great talk Josep, and amazing research.

    28

  • @joepastafari · 2 years ago

    <a href="https://www.youtube.com/watch?v=eV76vObO2IM&amp;t=1985">33:05</a> thanks for fixing the audio

    2

  • @strikeout5 · 2 years ago

    Complete lack of binary protections is wild to me. NX, stack cookies, ASLR... all would have made this much harder.

    2

  • @dickheadrecs · 3 years ago

    SNACK OVERFLOW

    23

Up next

LIVE

The Dark Side of Wireless Networks: Intro to Wi-Fi Hacking - Megi Bashi - Ryan Dinnan

BSides Prishtina · 197K views

LIVE

DEF CON 32 - From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller - Stacksmashing

DEFCONConference · 584K views

LIVE

Atlant Security Plugin Review: Performance, Code Quality, and Signs of AI Vibe Coding

WordPress Speed Doctor · 105 views

LIVE

Jackpotting ATM's (Automated Teller Machines) - Its easier than you might think - Alexander Forbes

Disobey · 110K views

LIVE

Hacking Through the Air | Contactless Payments and NFC | Sumsub

Sumsub · 215K views

LIVE

1,200 AI Agents Found a Secret Way to Talk. Then 700 Attacked.

Chief Agent Officer · 540 views

LIVE

I Hacked Into My Own Car

Steve Mould · 2.8M views

LIVE

EU Tells USA To BACK OFF! Dutch BAN Microsoft, Bonds COLLAPSE, Trump PANICS

House of El · 244K views

LIVE

DEF CON 31 - Infinite Money Glitch - Hacking Transit Cards - Bertocchi, Campbell, Gibson, Harris

DEFCONConference · 446K views

LIVE

DEF CON 32 - Where’s the Money-Defeating ATM Disk Encryption - Matt Burch

DEFCONConference · 41K views

LIVE

DEF CON 33 - RF Village - Tactical Flipper Zero You Have 1 Hour and No Other Equipment - Grey Fox

DEFCONConference · 37K views

LIVE

How We Hacked a TP-Link Router and Took Home $55,000 in Pwn2Own

Flashback Team · 425K views

LIVE

DEF CON 31 - Smashing the State Machine the True Potential of Web Race Conditions - James Kettle

DEFCONConference · 43K views

LIVE

The Greatest Fraud In Human History | Prof. Richard Werner

The Peter McCormack Show · 834K views

LIVE

Claude Took On the Riemann Hypothesis. Here’s What Actually Happened

Ellie Sleightholm · 496K views

LIVE

The AI Bank Run Has Started

Sasha Yanshin · 302K views

LIVE

Hacking cell phones like Mr Robot

David Bombal · 972K views

LIVE

Bsides Tallinn #3 Stefano Amorelli Credit cards tech and threats - how hackers pay with your money

BSides Tallinn · 287 views

LIVE

how is this hacking tool legal?

Low Level · 606K views

LIVE

DEF CON 31 - Defender Pretender When Windows Defender Updates Become a Security Risk -Bar, Attias

DEFCONConference · 15K views

LIVE

ReactJS Full Course 2026 | Build and Deploy a Beginner Ecommerce Website using React

PedroTech · 232K views

LIVE

Full Stack AI App: Build a Real-Time Voice Agent Interview Platform

JavaScript Mastery · 1.2M views

LIVE

How To Hack IoT Cameras

Hidden Systems (By JSON:Sec) · 254K views

LIVE

Colossus - The Greatest Secret in the History of Computing

The Centre for Computing History · 1M views

LIVE

DEF CON 32 - Unsaflok: Hacking millions of hotel locks - Lennert Wouters, Ian Carroll

DEFCONConference · 70K views

LIVE

DEFCON 19: Steal Everything, Kill Everyone, Cause Total Financial Ruin! (w speaker)

Christiaan008 · 1.6M views

YouTube, with the door locked.

Aegis plays a clean stream instead of YouTube's player, so pre-roll ads, trackers, and fingerprinting never ride along. Drop Shields any time if you want the official player back.