underrrun ([info]underrrun) wrote,
@ 2005-08-08 13:54:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Kiosk Hacking
Ok it's time for a public update for once in a while. This one is about my hacking adventure in Baltimore on August 3, 2005 .

While I was in Baltimore at the Nation Aquarium I happened upon this self-service kiosk made by Radiant Systems. After a bit of research after wards I found it to be the K600. The kiosk was used to pick up (or buy?) tickets for the aquarium. Well, like most kiosks, I'm sure this one had a vulnerability some where. After playing around with it for a while I saw a Right-Click menu blink really quickly. Bingo!!! But I wasn't sure how I did (I still don't know how....). My conclusion is that there is an error in the touchscreen (either hardware or driver) that allowed a right click signal to be sent when given erroneous data of some sort. I was able to keep recreating the right click menu by trying a variety of things: clicking in multiple places at the same time, holding and dragging and pressing at random intervals (once again, I'm not sure how it come up, it might even be built into the screen but I don't know how it works). Anyway after looking at the menu I immediately realized it was Firefox, which gave me a few extra things to do. Things I was able to do:

-View Source -- Not very fruitful, the source didn't show much.
-Back -- This didn't do much either, I was able to see the previous screen.
-Block Images from localhost -- This was particularly evil, nuff said.
-Search Web for ... -- After playing around for a bit more I was able to select some text and Right Click it to use this menu item. This opened a new tab (w00t) and google was not found so it opened a null (about:blank?) window. This is particularly bad because I could have clicked the first tab and then the 'X' in the corner and left the kiosk in a blank white screen. But I showed mercy and put it back...

Unfortunately I was with a group tour and I had to leave before I could finish exploring. Things I should have done:

-Save Page As... -- I could have used this to browse through the File System and see what's on it.
-Back -- I should have pressed this twice to see if it printed the last person's tickets again.

Here is a picture taken by a friend on the trip as well. It shows me leaning on the kiosk with a new tab open on the screen.

You can't see the screen that well, but you should be able to make out the new tab. Take a look here if you want to see a better resolution.



(Post a new comment)


(Anonymous)
2005-08-09 01:36 am UTC (link)
Good heavens.

Your link to hackaday has moved that picture into the thousands of views.

(Reply to this)


[info]taudiophile
2005-08-09 01:37 am UTC (link)
err that was me ^

(Reply to this) (Thread)


[info]magnavoid
2005-08-09 07:27 am UTC (link)
hey aaron this is mike

(Reply to this) (Parent)


[info]underrrun
2005-08-09 12:27 pm UTC (link)
Wow...well at least you have bragging rights to a popular photo :P

(Reply to this) (Parent)


[info]magnavoid
2005-08-09 07:26 am UTC (link)
nice! i wanna do that .... gee i just hacked my self some free wifi in Oregon. i am at my cousins house! he has dial up. i brought my desk top and i brought my can antenna. i ran come air snort and there must have been a ton of traffic because i got in in about 10 seconds.

(Reply to this)


[info]asu_ska_kid
2005-08-09 05:41 pm UTC (link)
considering firefox is open source you would have thought they would remove most of its functionality... You should go back and see if you can get free tickets.

(Reply to this) (Thread)


[info]underrrun
2005-08-10 12:34 am UTC (link)
Firefox isn't the problem... it was a faulty touchscreen. Anyway ... firefox was put there by the national aquarium not radiant systems. If they wanted to be more secure, I think there is a kiosk extention for firefox that allows you to disable the right click menu among other things.

(Reply to this) (Parent)


[info]self_manipulate
2005-08-10 10:19 am UTC (link)
I find myself doing this sort of crap all the time.

You'd be shocked at how many things like this have stupid exploits.

(Reply to this)

Exploit with Kiosks
(Anonymous)
2005-08-10 01:59 pm UTC (link)
Thanks for pointing this out to us. We did quite a bit of extensive testing and were not able to replicate the exact touch sequence that you used to bring up the right click functionality. However, we have since changed the configuration of Firefox to disable the right click menu.

Thanks again for bringing this to our attention and enabling us to fix this issue.

IT Staff
National Aquarium in Baltimore

(Reply to this) (Thread)

Re: Exploit with Kiosks
[info]magnavoid
2005-08-10 05:43 pm UTC (link)
LOL ...

(Reply to this) (Parent)(Thread)

Re: Exploit with Kiosks
[info]xaggroth
2005-08-10 07:28 pm UTC (link)
lmao
wow.
that kinda sucks.

(Reply to this) (Parent)(Thread)

Re: Exploit with Kiosks
[info]magnavoid
2005-08-11 07:23 am UTC (link)
yes it does...

(Reply to this) (Parent)

Re: Exploit with Kiosks
[info]erics_werld
2005-08-10 08:44 pm UTC (link)
it's the NATION Aquarium, ya dumbass

(Reply to this) (Parent)


Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…