It is well known that ATM machines running Windows XP (embedded or not) are frequently exposed to attacks. When combined with the lack of updates and poor configuration by IT administrators, the result is a worrying vulnerability that can be very easily exploited.
One of the users of the Russian blogging platform Habrahabr discovered that an ATM machine operated by the state bank Sberbank and running on Windows XP suffers from a security flaw that makes it possible for almost anyone to exploit it.
But how do you hack an ATM machine? It seems that the full-screen lock system that blocks access to various parts of an ATM's operating system could be bypassed via Sticky Keys.
This is essentially a feature that belongs to Windows XP and can be easily activated by pressing the Shift key five times in a row. This way you can access Windows settings, the taskbar, and the Start menu.
In short, a hacker could very easily reach various parts of the operating system using the touchscreen which, of course, opens the door to a range of malicious activities such as software development and modifying startup scripts.
What's worse is that Sberbank seems to be aware of the problem but has shown no interest in resolving it. Specifically, the bank was notified 3 weeks ago and although it promised an emergency solution, this has not happened yet.
While this is not an issue related to Windows XP, which no longer receives security updates, it is concerning that there are still many banks running the 2001 operating system.
