• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Researchers find RCE bug in older Diebold Nixdorf ATMs

5710

The NightSrOrm a group of IT security people, enthusiasts, who share the same interests have tracked a Remote Code Execution (RCE) flaw in older Opteva ATM models' software, A publicly exposed OS service present in Diebold Nixdorf's Opteva ATM series that could be compromised when remotely exploited with reverse shells to deploy malicious payloads. The company is currently notifying its customers about this vulnerability and has released software patches to fix this flaw. The story was initiated in early 2019, when the group "accidentally" accessed a Diebold ATM - a company specialized in providing ATMs around the world.

And they managed to identify that port 8043 which basically deals with service within the XFS suite of service was listening public on the surface scan. And when this port was accessed with an http request a very familiar message of a strange service was reported, but on further analysis, this exe file calls to many libraries, including a library called VDMXFS.dll.

The program used a function: RemotingConfiguration.Configure("server.config"), which was probably the config file here. And the analysis of this was reported to have few "clues", and since the program already used .NET Remoting Programming techniques, the team found a pretty detailed description and programmed two applications to create an Interactive network and the results were quite reasonable. This lead to two errors: XXE and XML Deserialization.

But later it was found that XXE was not feasible and hence on focusing XML Deserialization analysis, RemotingConfiguration class belonging to the System.Runtime.Remoting library, according to the description of M$ library seemed to send and receive serialization data. And the payload was created, tested and exploited.

After knowing about this RCE flaw in their older operating systems. Diebold Nixdorf is in the process of notifying all its customers using older Opteva ATMs of this issue. In addition, they have advised the operators to update to the latest version (4.1.22) of the ATM operating system, as one of the countermeasures. Besides the fact that all the Opteva systems are shipped with an inbuilt terminal-based firewall, the information is that this terminal based firewall of the system was mostly inactive during this evaluation. Yet there are no reports of this potential exposure being exploited outside a test environment.

Tags:
johndennisgt
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in Researchers find RCE bug in older Diebold Nixdorf ATMs

Related Tutorials in Researchers find RCE bug in older Diebold Nixdorf ATMs

How to Permanently Disable SELinux in Rocky Linux 9.2
How to Permanently Disable SELinux in Rocky Linux 9.2
Aug 7, 2023
How to Secure Apache Web Server on Linuxmint 18.03
How to Secure Apache Web Server on Linuxmint 18.03
Mar 18, 2019
How to Install and Configure CSF on Rocky Linux 9.2
How to Install and Configure CSF on Rocky Linux 9.2
Jul 5, 2023
How To Install ModSecurity On Linux Mint 20.2
How To Install ModSecurity On Linux Mint 20.2
Mar 7, 2022
How to install VSFTPD Server on Oracle Linux 8.8
How to install VSFTPD Server on Oracle Linux 8.8
Mar 11, 2024
How to allow Port for particular IP in CSF on Oracle Linux 9.3
How to allow Port for particular IP in CSF on Oracle Linux 9.3
Jan 18, 2024
How to allow domains by reverse DNS lookup in CSF on Oracle Linux 9.2
How to allow domains by reverse DNS lookup in CSF on Oracle Linux 9.2
Apr 6, 2024

Related Forums in Researchers find RCE bug in older Diebold Nixdorf ATMs

Related Forums in Researchers find RCE bug in older Diebold Nixdorf ATMs

Mongodb
caden class=
Unrecognized option: security In MongoDB 4.0.11 On CentOS 7.6
Aug 31, 2019
Linux
mason class=
semanage command not found
Apr 10, 2017
SELinux
liam class=
Port tcp/23456 already defined
Apr 17, 2017
SELinux
karljustin class=
default SELinux Labels in system
Mar 12, 2018
Clickjacking
logan class=
How to block clickjacking attack
Apr 7, 2017
WHM cPanel
jayce class=
How to deny the particular IP to access particular domain in cpanel
Mar 28, 2017

Related News in Researchers find RCE bug in older Diebold Nixdorf ATMs

Related News in Researchers find RCE bug in older Diebold Nixdorf ATMs

5 Best Secure and Private Web Browsers to Look Our For
5 Best Secure and Private Web Browsers to Look Our For
Nov 24, 2018
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
RoboCyberWall created to block Linux Server Hacks
RoboCyberWall created to block Linux Server Hacks
Oct 5, 2017
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Security Breach In The World's First Domain Registrar Network Solutions
Security Breach In The World's First Domain Registrar Network Solutions
Nov 5, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Hackers set off 156 emergency sirens in Dallas over dozen times
Hackers set off 156 emergency sirens in Dallas over dozen times
Apr 10, 2017
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Lucas ?
Various options in Top command

Am using Top command only to view the load average, what are the various options in Top command..??

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.