• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Security guidelines for Windows XP based ATMs

        Doug | Date: Nov 11, 2004 | Comments: 1



        • Print PDF
        • Filed Under: News

        As Automated Teller Machines (ATMs) migrate from OS/2 to Windows XP (and XP Embedded), and from X25-based protocols to TCP/IP, they become susceptible to many of the same threats as desktop systems and servers, according to the Global ATM Security Alliance (GASA).


        To meet these new threats, the group has published what it claims are the first international cyber security guidelines for the ATM industry.

        "New platforms utilizing mainstream technologies are being introduced, which is dramatically altering the vulnerability landscape associated with [the] traditionally proprietary system," explained Ian Simpson, the manual's author. "The recommendations presented in this manual are essentially designed to provide a common sense approach to risk mitigation as a result of the rapidly changing threat model that the introduction to the ATM channel of the Windows XP and other common use operating systems, as well as the TCP/IP network protocol suite, has created," Simpson continued.

        Last year, two U.S. financial institutions were hit with a computer worm that invaded ATMs running Windows XP Embedded. The ATMs were manufactured by Diebold, one of the world's leading ATM suppliers. According to NewScientist.com, the culprit was a worm called Welchia, which caused an overload of traffic on the network resulting in the ATMs being shut down. Welchia reportedly exploited a vulnerability in Windows XP Embedded's RPC DCOM function.

        Microsoft subsequently issued a string of security patches for Windows XP and XP Embedded, including ones for Sasser worm, the Download.ject Trojan, the release of Service Pack 2 (SP2) containing numerous security fixes for Windows XP, and the preview release of SP2 for XP Embedded with similar security enhancements.

        Further information on GASA's cyber security guidelines for the ATM industry is available on GASA's website.



        Related stories:
        • Worm infects ATM machines of two US financial institutions
        • CA releases anti-virus software for Windows XP Embedded SP2
        • Microsoft releases free Windows XP Embedded SP2 "preview"
        • Microsoft patches critical vulnerabilities in XP, XP Embedded
        • Windows XP Service Pack 2 Beta addresses security concerns
        • Bsquare adds security package to Windows XP Embedded
        • Windows XP Embedded security package updated
        • Security alert: Download.ject impacts XP Embedded webservers
        • Microsoft issues Windows XP Embedded patch for Sasser worm
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.