Hacker News new | past | comments | ask | show | jobs | submit login

> Privilege escalation is not a problem on ATMs.

https://vuldb.com/?id.79002




I expect that most people miss that ATM manufacturers continue to put security holes in ATMs (https://www.wired.com/2014/11/nashville/) one of the 'fixes' was to make bank access unprivileged. But wait, if I have an escalation vulnerability ...


Sigh. Okay let me rephrase. The thing normally called "privilege escalation", where software that is executing on a machine escapes a sandbox or gets into kernel mode, is not a problem on ATMs.

That page is talking about pressing keys to exploit software flaws in already-privileged software, which is an extremely separate topic.


Privilege escalations come in many shapes and sizes, it is not limited to software escaping a sandbox or to get into kernel mode, it is also explicitly used to refer to users of a system managing to leverage their normal access into a more powerful one.


But in context I was clearly talking about the former, because the topic is software exploiting CPU backdoors.


This can be combined with another exploit that allows the user to execute user code to achieve root on the ATM, so it's still troubling.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: