{"id":35337,"date":"2019-10-31T22:03:44","date_gmt":"2019-10-31T19:03:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya\/"},"modified":"2019-10-31T22:03:44","modified_gmt":"2019-10-31T19:03:44","slug":"karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya","title":{"rendered":"Carding and \"black boxes\": How ATMs Are Hacked Today","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The metal boxes with money standing on the city streets can't help but attract the attention of those looking for quick profits. While earlier methods for emptying ATMs relied purely on physical techniques, now increasingly sophisticated tricks related to computers are being employed. Currently, one of the most relevant tactics is the \"black box\" containing a single-board computer inside. In this article, we'll discuss how it works.<\/p>\n<p><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"#a1\">\u2013 The Evolution of ATM Carding<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#a2\">\u2013 First Encounter with the \"Black Box\"<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#a3\">\u2013 Analyzing ATM Communications<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#a4\">\u2013 Where Do \"Black Boxes\" Come From?<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"#a5\">\u2013 The \"Last Mile\" and Fake Processing Centers<\/a><\/noindex><\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/47333c20aff11ea2c80330b0d42f6e23.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><em>The head of the International ATM Industry Association (ATMIA) <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ncr.com\/company\/blogs\/financial\/what-security-threats-will-the-financial-institutions-face-in-2018\">highlighted<\/a><\/noindex> \"Black boxes\" as the most dangerous threat to ATMs.<\/em><\/p>\n<p><\/p>\n<p>A typical ATM is a set of ready-made electromechanical components housed in one case. ATM manufacturers build their metal creations from a banknote dispenser, card reader, and other components that have been developed by third-party suppliers. It's like a LEGO set for adults. The completed components are housed within the ATM's casing, usually composed of two compartments: the upper compartment (the \"cabinet\" or \"service area\") and the lower compartment (the safe). All electromechanical components are connected through USB and COM ports to the system unit, which functions as the host in this case. Older ATM models may also feature connections via the SDC bus.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" name=\"a1\"><\/a><\/noindex><\/p>\n<h1 id=\"evolyuciya-bankomatnogo-kardinga\">The Evolution of ATM Carding<\/h1>\n<p><\/p>\n<p>ATMs with large sums of money inside invariably lure carders in. Initially, carders exploited only the blatant physical shortcomings of ATM security \u2014 using skimmers and shimmers to steal data from magnetic stripes; counterfeit PIN pads and cameras to capture PIN codes; and even fake ATMs.<\/p>\n<p><\/p>\n<p>Then, as ATMs began to be equipped with standardized software operating under common standards, such as XFS (eXtensions for Financial Services), carders started attacking ATMs with computer viruses.<\/p>\n<p><\/p>\n<p>Among them were Trojan.Skimmer, Backdoor.Win32.Skimer, Ploutus, ATMii, and numerous other named and unnamed malware that carders introduce to the ATM host either through a bootable flash drive or via a remote control TCP port.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/04764520b48f08986f8d7821657a333e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>ATM Infection Process<\/em><\/p>\n<p><\/p>\n<p>By taking control of the XFS subsystem, malware can issue commands to the cash dispensing device without authorization, or give commands to the card reader to read\/write the magnetic stripe of a bank card and even extract the transaction history stored on the EMV chip card. The EPP (Encrypting PIN Pad) deserves special attention. It is generally accepted that the PIN entered on it cannot be intercepted. However, XFS allows the EPP to operate in two modes: 1) open mode (for entering various numerical parameters, such as the amount to be cashed out); 2) secure mode (the EPP switches to this mode when a PIN or encryption key needs to be entered). This feature of XFS enables a carder to carry out a MiTM attack: intercept the activation command for secure mode sent from the host to the EPP, and then inform the EPP that the operation should continue in open mode. In response, the EPP sends key presses in plain text.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/9dd898db2dae383458f2864c0ec5b99f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>The Principle of the 'Black Box'<\/em><\/p>\n<p><\/p>\n<p>In recent years, <noindex><a rel=\"nofollow\" href=\"https:\/\/m.itcafe.hu\/dl\/cnt\/2017-09\/140653\/atm.pdf\">according to<\/a><\/noindex> Europol, malware for ATMs has noticeably evolved. Carders no longer need physical access to the ATM to infect it. They can infect ATMs through remote network attacks, using the bank's corporate network for this purpose. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.theguardian.com\/technology\/2018\/jan\/29\/jackpotting-hackers-atm-cash-machine-give-away\">According to data<\/a><\/noindex> Group IB reported that in 2016, ATMs in more than 10 European countries were subjected to remote attacks.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/15ba7d1405594fd547e4cefb3ed167a8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>Attacking an ATM via Remote Access<\/em><\/p>\n<p><\/p>\n<p>Antiviruses, firmware update blocking, USB port disabling, and hard disk encryption provide some level of protection against carders' virus attacks on ATMs. But what if the carder does not attack the host but connects directly to the peripherals (via RS232 or USB) \u2013 to the card reader, PIN pad, or cash dispensing device?<\/p>\n<p>\n<noindex><a rel=\"nofollow\" name=\"a2\"><\/a><\/noindex><\/p>\n<h1 id=\"pervoe-znakomstvo-s-chyornym-yaschikom\">First Encounter with the 'Black Box'<\/h1>\n<p><\/p>\n<p>Today, technically savvy carders <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=q5tQWe6YsLM\">act precisely this way<\/a><\/noindex>, using so-called \u201cblack boxes\u201d for stealing cash from ATMs \u2013 specially programmed single-board microcomputers, like Raspberry Pi. These \u201cblack boxes\u201d completely empty ATMs in a manner that is utterly bewildering (from the bankers' perspective). Carders connect their magical device directly to the cash dispensing machine to extract all available money from it. Such an attack bypasses all software security measures deployed on the ATM host (such as antivirus programs, integrity checks, full disk encryption, etc.).<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/e5fc980d164c09bef50cf8e2b4fa86b2.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>\u201cBlack box\u201d based on Raspberry Pi<\/em><\/p>\n<p><\/p>\n<p>The largest ATM manufacturers and government intelligence agencies, having encountered several implementations of the \u201cblack box,\u201d <noindex><a rel=\"nofollow\" href=\"https:\/\/www.theguardian.com\/technology\/2018\/jan\/29\/jackpotting-hackers-atm-cash-machine-give-away\">warn<\/a><\/noindex>, that these ingenious computers compel ATMs to spit out all available cash; at a rate of 40 banknotes every 20 seconds. The intelligence agencies also warn that carders most often target ATMs located in pharmacies, shopping centers; as well as ATMs that service motorists \u201con the go.\u201d<\/p>\n<p><\/p>\n<p>Furthermore, to avoid detection by cameras, the most cautious carders recruit some not-so-valuable partner, a mule. To prevent this partner from stealing the \u201cblack box,\u201d they use <noindex><a rel=\"nofollow\" href=\"http:\/\/krebsonsecurity.com\/2015\/01\/thieves-jackpot-atms-with-black-box-attack\/\">the following scheme<\/a><\/noindex>. They remove key functionality from the \u201cblack box\u201d and connect a smartphone to it, which is used as a channel for remote command transmission to the stripped-down \u201cblack box\u201d over the IP protocol.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/c4cf8b34b738997face367ae10bc57e4.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>Modification of the \u201cblack box,\u201d activated via remote access<\/em><\/p>\n<p><\/p>\n<p>How does this look from the bankers' perspective? The video camera recordings show something like the following: an individual opens the top compartment (service area), connects the ATM to the \u201cmagic box,\u201d closes the top compartment, and leaves. After a short while, several people, appearing to be ordinary customers, approach the ATM and withdraw large sums of money. The carder then returns to retrieve their little magical device from the ATM. Typically, the fact that the ATM has been attacked with a \u201cblack box\u201d is only discovered several days later: when the empty safe and the cash withdrawal journal do not match. As a result, bank employees are left only to <noindex><a rel=\"nofollow\" href=\"https:\/\/gsec.hitb.org\/materials\/sg2016\/whitepapers\/ATMs%20and%20Their%20Dirty%20Little%20Secrets%20-%20Olga%20Kochetova%20&amp;%20Alexey%20Osipov.pdf\">scratch their heads<\/a><\/noindex>.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" name=\"a3\"><\/a><\/noindex><\/p>\n<h1 id=\"analiz-bankomatnyh-kommunikaciy\">Analysis of ATM Communications<\/h1>\n<p><\/p>\n<p>As mentioned earlier, the interaction between the system unit and peripheral devices occurs through USB, RS232, or SDC. The carder connects directly to the peripheral device's port and sends commands to it, bypassing the host. This is quite straightforward since standard interfaces do not require specific drivers. Proprietary protocols used for interaction between peripherals and hosts do not require authentication (as the device is within a trusted zone); thus, these unsecured protocols are easily monitored and susceptible to replay attacks.<\/p>\n<p><\/p>\n<p>Thus, carders can use software or hardware traffic analyzers by connecting them directly to the port of a specific peripheral device (for instance, to a card reader) to capture transmitted data. By using the traffic analyzer, the carder learns all the technical details of the ATM's operation, including undocumented features of its peripherals (for example, the firmware modification function of the peripheral device). As a result, the carder gains full control over the ATM. Additionally, detecting the presence of a traffic analyzer is quite difficult. <\/p>\n<p><\/p>\n<p>Direct control over the cash dispensing device means that ATM cassettes can be emptied without any logs being recorded, which usually would be done by the software deployed on the host. For those unfamiliar with the software-hardware architecture of an ATM, this can indeed seem like magic.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" name=\"a4\"><\/a><\/noindex><\/p>\n<h1 id=\"otkuda-berutsya-chyornye-yaschiki\">Where do 'black boxes' come from?<\/h1>\n<p><\/p>\n<p>ATM suppliers and subcontractors develop debugging tools for diagnosing the ATM's hardware, including electromechanical systems responsible for cash withdrawal. Among such tools are: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.atmdesk.com\">ATMDesk<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.afferentsoftware.com\/rapidfire-range\">RapidFire ATM XFS<\/a><\/noindex>. The image below presents several other diagnostic tools.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/f01c409f32a748a1376f490c9241ea11.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>ATMDesk Control Panel<\/em><\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/b867ec0854bf9cf75598a4fc68318771.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>RapidFire ATM XFS Control Panel<\/em><\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/b5d4a6264efa52bf0b06ec3fbeff2207.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>Comparative Characteristics of Several Diagnostic Tools<\/em><\/p>\n<p><\/p>\n<p>Access to such utilities is typically restricted by personalized tokens; they only function when the banknote dispenser's safe door is open. However, by simply modifying a few bytes in the utility's binary code, carders can \"test\" cash withdrawals \u2013 bypassing the checks implemented by the utility's manufacturer. <noindex><a rel=\"nofollow\" href=\"https:\/\/securelist.com\/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut\/74533\">use the same name for<\/a><\/noindex> Carders install such modified utilities on their laptop or single-board computer, which are then directly connected to the cash dispensing device for unauthorized cash extraction.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" name=\"a5\"><\/a><\/noindex><\/p>\n<h1 id=\"poslednyaya-milya-i-poddelnyy-processingovyy-centr\">\"Last mile\" and fraudulent processing center<\/h1>\n<p><\/p>\n<p>Direct interaction with peripherals, without communicating with the host \u2013 is just one of the effective techniques in carding. Other techniques rely on the fact that there is a wide variety of network interfaces through which the ATM connects to the outside world. From X.25 to Ethernet and cellular communication. Many ATMs can be identified and located via the Shodan service (the most concise instructions on how to use it are presented <noindex><a rel=\"nofollow\" href=\"http:\/\/magazine.hitb.org\/issues\/HITB-Ezine-Issue-007.pdf\">here<\/a><\/noindex>), - followed by an attack exploiting vulnerable security configurations, the administrator's negligence, and weak communications between various divisions of the bank.<\/p>\n<p><\/p>\n<p>\"Last mile\" connectivity between the ATM and the processing center is rich with various technologies that can serve as entry points for the carder. Interaction can occur via wired (telephone line or Ethernet) or wireless (Wi-Fi, cellular: CDMA, GSM, UMTS, LTE) communication methods. Security mechanisms may include: 1) hardware or software tools to support VPN (both standard, built into the OS, and from third-party vendors); 2) SSL\/TLS (specific to certain ATM models or from third-party vendors); 3) encryption; 4) message authentication.<\/p>\n<p><\/p>\n<p>However <noindex><a rel=\"nofollow\" href=\"https:\/\/gsec.hitb.org\/materials\/sg2016\/whitepapers\/ATMs%20and%20Their%20Dirty%20Little%20Secrets%20-%20Olga%20Kochetova%20&amp;%20Alexey%20Osipov.pdf\">seems<\/a><\/noindex>, for banks, the mentioned technologies appear very complex, and therefore they do not burden themselves with special network security; or implement it incorrectly. At best, the ATM connects to a VPN server, and within the private network, it connects to the processing center. Moreover, even if banks manage to implement the aforementioned security mechanisms, the carder already has effective attacks against them. Thus, even if security meets the PCI DSS standard, ATMs still remain vulnerable.<\/p>\n<p><\/p>\n<p>One of the main requirements of PCI DSS: all confidential data, when transmitted over a public network, must be encrypted. And in fact, we do have networks that were originally designed to fully encrypt data! Therefore, there is a temptation to say: \u201cWe have encrypted data because we use Wi-Fi and GSM.\u201d However, many of these networks do not provide sufficient protection. Cellular networks of all generations have long been hacked. Definitively and irrevocably. And there are even providers that offer devices to intercept data transmitted over them.<\/p>\n<p><\/p>\n<p>Therefore, either in insecure communication or in a 'private' network, where each ATM broadcasts about itself to other ATMs, a MiTM attack 'fake processing center' can be initiated, leading to the carder taking control of data streams being transmitted between the ATM and the processing center.<\/p>\n<p><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/gsec.hitb.org\/materials\/sg2016\/whitepapers\/ATMs%20and%20Their%20Dirty%20Little%20Secrets%20-%20Olga%20Kochetova%20&amp;%20Alexey%20Osipov.pdf\">Such MiTM attacks<\/a><\/noindex> potentially threaten thousands of ATMs. On the way to the genuine processing center, the carder inserts their fake one. This fake processing center instructs the ATM to dispense banknotes. Meanwhile, the carder configures their processing center in such a way that cash dispensing occurs regardless of which card is inserted into the ATM \u2013 even if it is expired, or has a zero balance. The main thing is for the fake processing center to 'recognize' it. The fake processing center can either be a makeshift device or a simulator of a processing center originally designed for debugging network settings (another gift from the 'manufacturer' to the carders).<\/p>\n<p><\/p>\n<p>In the next figure <noindex><a rel=\"nofollow\" href=\"https:\/\/securelist.com\/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut\/74533\">is presented<\/a><\/noindex> the command dump to dispense 40 banknotes from the fourth cassette, sent from a fraudulent processing center and stored in the ATM software logs. They look almost real.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Carding and &quot;black boxes&quot;: How ATMs Are Hacked Today\" src=\"\/wp-content\/uploads\/cbff34aa336ea727710a6df49599ffaa.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>Command dump from the fraudulent processing center<\/em><\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/455210\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0442\u043e\u044f\u0449\u0438\u0435 \u043d\u0430 \u0443\u043b\u0438\u0446\u0430\u0445 \u0433\u043e\u0440\u043e\u0434\u0430 \u0436\u0435\u043b\u0435\u0437\u043d\u044b\u0435 \u043a\u043e\u0440\u043e\u0431\u043a\u0438 \u0441 \u0434\u0435\u043d\u044c\u0433\u0430\u043c\u0438 \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u043d\u0435 \u043f\u0440\u0438\u0432\u043b\u0435\u043a\u0430\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043b\u044e\u0431\u0438\u0442\u0435\u043b\u0435\u0439 \u0431\u044b\u0441\u0442\u0440\u043e\u0439 \u043d\u0430\u0436\u0438\u0432\u044b. \u0418 \u0435\u0441\u043b\u0438 \u0440\u0430\u043d\u044c\u0448\u0435 \u0434\u043b\u044f \u043e\u043f\u0443\u0441\u0442\u043e\u0448\u0435\u043d\u0438\u044f \u0431\u0430\u043d\u043a\u043e\u043c\u0430\u0442\u043e\u0432 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u043b\u0438 \u0447\u0438\u0441\u0442\u043e \u0444\u0438\u0437\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u043c\u0435\u0442\u043e\u0434\u044b, \u0442\u043e \u0442\u0435\u043f\u0435\u0440\u044c \u0432 \u0445\u043e\u0434 \u0438\u0434\u0443\u0442 \u0432\u0441\u0435 \u0431\u043e\u043b\u0435\u0435 \u0438\u0441\u043a\u0443\u0441\u043d\u044b\u0435 \u0442\u0440\u044e\u043a\u0438, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430\u043c\u0438. \u0421\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0439 \u0438\u0437 \u043d\u0438\u0445 \u2014 \u044d\u0442\u043e \u00ab\u0447\u0435\u0440\u043d\u044b\u0439 \u044f\u0449\u0438\u043a\u00bb \u0441 \u043e\u0434\u043d\u043e\u043f\u043b\u0430\u0442\u043d\u044b\u043c \u043c\u0438\u043a\u0440\u043e\u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043e\u043c \u0432\u043d\u0443\u0442\u0440\u0438. \u041e \u0442\u043e\u043c, \u043a\u0430\u043a \u043e\u043d [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-35337","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0442\u043e\u044f\u0449\u0438\u0435 \u043d\u0430 \u0443\u043b\u0438\u0446\u0430\u0445 \u0433\u043e\u0440\u043e\u0434\u0430 \u0436\u0435\u043b\u0435\u0437\u043d\u044b\u0435 \u043a\u043e\u0440\u043e\u0431\u043a\u0438 \u0441 \u0434\u0435\u043d\u044c\u0433\u0430\u043c\u0438 \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u043d\u0435 \u043f\u0440\u0438\u0432\u043b\u0435\u043a\u0430\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043b\u044e\u0431\u0438\u0442\u0435\u043b\u0435\u0439 \u0431\u044b\u0441\u0442\u0440\u043e\u0439 \u043d\u0430\u0436\u0438\u0432\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u0440\u0434\u0438\u043d\u0433 \u0438 \u00ab\u0447\u0451\u0440\u043d\u044b\u0435 \u044f\u0449\u0438\u043a\u0438\u00bb: \u043a\u0430\u043a \u0432\u0437\u043b\u0430\u043c\u044b\u0432\u0430\u044e\u0442 \u0431\u0430\u043d\u043a\u043e\u043c\u0430\u0442\u044b \u0441\u0435\u0433\u043e\u0434\u043d\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0442\u043e\u044f\u0449\u0438\u0435 \u043d\u0430 \u0443\u043b\u0438\u0446\u0430\u0445 \u0433\u043e\u0440\u043e\u0434\u0430 \u0436\u0435\u043b\u0435\u0437\u043d\u044b\u0435 \u043a\u043e\u0440\u043e\u0431\u043a\u0438 \u0441 \u0434\u0435\u043d\u044c\u0433\u0430\u043c\u0438 \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u043d\u0435 \u043f\u0440\u0438\u0432\u043b\u0435\u043a\u0430\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043b\u044e\u0431\u0438\u0442\u0435\u043b\u0435\u0439 \u0431\u044b\u0441\u0442\u0440\u043e\u0439 \u043d\u0430\u0436\u0438\u0432\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:03:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:03:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Carding and 'black boxes': how ATMs are hacked today | ProHoster","description":"The iron boxes with money standing on the streets of the city cannot help but attract the attention of quick profit seekers.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u0440\u0434\u0438\u043d\u0433 \u0438 \u00ab\u0447\u0451\u0440\u043d\u044b\u0435 \u044f\u0449\u0438\u043a\u0438\u00bb: \u043a\u0430\u043a \u0432\u0437\u043b\u0430\u043c\u044b\u0432\u0430\u044e\u0442 \u0431\u0430\u043d\u043a\u043e\u043c\u0430\u0442\u044b \u0441\u0435\u0433\u043e\u0434\u043d\u044f | ProHoster","og:description":"\u0421\u0442\u043e\u044f\u0449\u0438\u0435 \u043d\u0430 \u0443\u043b\u0438\u0446\u0430\u0445 \u0433\u043e\u0440\u043e\u0434\u0430 \u0436\u0435\u043b\u0435\u0437\u043d\u044b\u0435 \u043a\u043e\u0440\u043e\u0431\u043a\u0438 \u0441 \u0434\u0435\u043d\u044c\u0433\u0430\u043c\u0438 \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u043d\u0435 \u043f\u0440\u0438\u0432\u043b\u0435\u043a\u0430\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043b\u044e\u0431\u0438\u0442\u0435\u043b\u0435\u0439 \u0431\u044b\u0441\u0442\u0440\u043e\u0439 \u043d\u0430\u0436\u0438\u0432\u044b.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/karding-i-chyornye-yashhiki-kak-vzlamyvayut-bankomaty-segodnya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:03:44+00:00","article:modified_time":"2019-10-31T19:03:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35337","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 22:50:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:22:35","updated":"2026-01-21 22:50:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=35337"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35337\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=35337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=35337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=35337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}