Account Options

  1. Sign in
The old Google Groups will be going away soon.
Switch to the new Google Groups.
Google Groups Home
« Groups Home
Cracking ATM Card Codes
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  2 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
"Jason Lane"  
View profile  
 More options Sep 3 1994, 8:06 am
Newsgroups: alt.folklore.urban
From: jl...@cix.compulink.co.uk ("Jason Lane")
Date: Sat, 3 Sep 1994 12:06:59 GMT
Local: Sat, Sep 3 1994 8:06 am
Subject: Re: Cracking ATM Card Codes
In Ref To Using cards in machines that have no direct connection ie n*b
apart from end of day batching. Encyripted on track 3 is the weekly
limit of the acc. this is overwritten when you make a withdraw with time
 and date and amount. so if you know what numbers they are they can be
erased and mulitple withdraws made with the same card !.

it does work ask a certain inmate of HMP. Brixton

Regards Jlane > ==========

> alt.folklore/urban #4, from ni...@audi.optimation.co.nz, 3087 chars,

Wed  31 Aug 1994 01:14:57
> ----------
> Article: 106312 of alt.folklore.urban
> Newsgroups: alt.folklore.urban
> Path:

cix.compulink.co.uk!uknet!EU.net!uunet!comp.vuw.ac.nz!actrix.gen.nz!opti
mation.co.nz!audi!nickg
> From: ni...@audi.optimation.co.nz (Nick Gridley)
> Subject: Re: Cracking ATM Card Codes
> In-Reply-To: sys...@codewks.nacjack.gen.nz's message of Sat, 27 Aug 94
14:02:56 +1200
> Message-ID: <NICKG.94Aug31131...@audi.optimation.co.nz>
> Sender: ni...@optimation.co.nz (Nick Gridley)
> Organization: Optimation Consulting
> References: <mcqCuuowA....@netcom.com>

<L4TqRc1w1...@codewks.nacjack.gen.nz>
> Date: Wed, 31 Aug 1994 01:14:57 GMT
> Lines: 47

> In article <L4TqRc1w1...@codewks.nacjack.gen.nz>

sys...@codewks.nacjack.gen.nz (Wayne W. McDougall) writes:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
HALLAM-BAKER Phillip  
View profile  
 More options Sep 3 1994, 8:48 am
Newsgroups: alt.folklore.urban
From: hal...@dxal18.cern.ch (HALLAM-BAKER Phillip)
Date: Sat, 3 Sep 1994 12:48:27 GMT
Local: Sat, Sep 3 1994 8:48 am
Subject: Re: Cracking ATM Card Codes

From phrack:

    Track I is 210 bpi. Track II is 75 bpi.

    The next chart shows the Magnetic Stripe Data Format (Track I)

 Field #   Length    Name of Field
 -------   ------    -------------

 1         1         Start Sentinel (STX)
 2         1         Format Code
 3         13/16     Primary Account Number
 4         1         Separator (^) HEX 5E
 5         2-26      Card Holder Name
 6         1         Separator (^) HEX 5E
 7         4         Card Expiration in format MMYY
 8         3         Service Code (?) 000 WORKS.
 9         0/5       Pin Verification Field
 10                  Discretionary Data Depends on 3, 5, 9
 11        11        Visa Reserved Always last 11 positions
 12        1         End Sentinel (ETX)
 13        1         LRC

    Maximum Record Length is 79 Characters

    The next chart shows the Magnetic Stripe Data Format (Track II)

 Field #   Length    Name of Field
 -------   ------    -------------

    1         1         Start Sentinel (STX)
    2         13/16     Primary Account Number
    3         1         Separator (=) HEX 3D
    4         4         Card Expiration Date in format MMYY
    5         3         Service Code (?) 000 works.
    6         0/5       Pin Verification Field
    7                   Discretionary Data Depends on 2, 6
    8         1         End Sentinel (ETX)
    9         1         LRC

    "The LRC is calculated by performing a BITWISE XOR (Exclusive OR) on all
ASCII values of the characters in the Inquiry - EXCLUDING the <STX> but
INCLUDING the <ETX>."

<STX> is HEX 02.
<ETX> is HEX 03.

Its probably written out in some ISO standard somewhere. The cards have to be
interoperable.

It is a very silly system and one that should be improved. Fortunately
Mastercard have announced a move to using smartcards. These at least cut out
one layer of abuse - forged cards made using data from old receipts.
Hopefully AMEX and VISA will follow. It is very annoying to have to use
RSA encryption (at cost) to provide poor security safeguards when fixing the
credit card co's scheme provides much better security without needing
encryption.

Any system that depends on simple encryption (ie not digital signatures) for
authentication is inherently weak. When the comparison of the challenge key
is made there are opportunities for interception. In the case of home shopping
the accounts dept of the store in question gets to read all the data they need
to rip off the customer.

--
Phillip M. Hallam-Baker

Not Speaking for anyone else.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »