<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Fedex Kinko&#8217;s smart cards hacked</title>
	<atom:link href="http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Mon, 23 Nov 2009 07:07:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Fat Loss 4 Idiots</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-3/#comment-107194</link>
		<dc:creator>Fat Loss 4 Idiots</dc:creator>
		<pubDate>Fri, 13 Nov 2009 16:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-107194</guid>
		<description>I&#039;ve really enjoyed reading your articles.  You obviously know what you are talking about!  Your site is so easy to navigate too, I&#039;ve bookmarked it in my favourites :-D</description>
		<content:encoded><![CDATA[<p>I&#8217;ve really enjoyed reading your articles.  You obviously know what you are talking about!  Your site is so easy to navigate too, I&#8217;ve bookmarked it in my favourites :-D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ejonesss</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-3/#comment-52352</link>
		<dc:creator>ejonesss</dc:creator>
		<pubDate>Wed, 26 Nov 2008 05:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-52352</guid>
		<description>at this point the attacker can take the card to the service counter and ask for the balance in cash

unfortunately look at image

http://hackadaycom.files.wordpress.com/2008/11/overview.jpg?w=450&amp;h=338

the smart chip has been soldered to (a dead give away that the card has been tampered with).

you may want to try getting a proper connector maybe salvage the card reader slot from an old dish receiver or something.</description>
		<content:encoded><![CDATA[<p>at this point the attacker can take the card to the service counter and ask for the balance in cash</p>
<p>unfortunately look at image</p>
<p><a href="http://hackadaycom.files.wordpress.com/2008/11/overview.jpg?w=450&amp;h=338" rel="nofollow">http://hackadaycom.files.wordpress.com/2008/11/overview.jpg?w=450&amp;h=338</a></p>
<p>the smart chip has been soldered to (a dead give away that the card has been tampered with).</p>
<p>you may want to try getting a proper connector maybe salvage the card reader slot from an old dish receiver or something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piglet</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17493</link>
		<dc:creator>piglet</dc:creator>
		<pubDate>Tue, 01 Aug 2006 22:35:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17493</guid>
		<description>Hi,
   The torrent in comment 28 doesn&#039;t seem to work. Can someone point me in the direction of a stream that DOES work since I&#039;m gagging to see the guys in action. I also have a vested interest since I&#039;m hoping to do a UK reprise on the hack with the Boots Advantage card. Similarly, it only has 6 connectors &amp; has been going since 1997 so it MUST be quite old technology. Also, being a FREE card, cost is everything. I&#039;ve got everything crossed that they have used an SLE4418 so not even a pin-code is needed ;-)

Many thanks in advance, Sean.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
   The torrent in comment 28 doesn&#8217;t seem to work. Can someone point me in the direction of a stream that DOES work since I&#8217;m gagging to see the guys in action. I also have a vested interest since I&#8217;m hoping to do a UK reprise on the hack with the Boots Advantage card. Similarly, it only has 6 connectors &#038; has been going since 1997 so it MUST be quite old technology. Also, being a FREE card, cost is everything. I&#8217;ve got everything crossed that they have used an SLE4418 so not even a pin-code is needed ;-)</p>
<p>Many thanks in advance, Sean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piglet</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17495</link>
		<dc:creator>piglet</dc:creator>
		<pubDate>Mon, 31 Jul 2006 16:42:34 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17495</guid>
		<description>One last question (please don&#039;t tell me to UAFSE). I&#039;ve ordered a USB smart-card reader-writer. Is their freeware to allow me to simply alter the card?</description>
		<content:encoded><![CDATA[<p>One last question (please don&#8217;t tell me to UAFSE). I&#8217;ve ordered a USB smart-card reader-writer. Is their freeware to allow me to simply alter the card?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piglet</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17494</link>
		<dc:creator>piglet</dc:creator>
		<pubDate>Mon, 31 Jul 2006 01:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17494</guid>
		<description>In the UK, Boots Advantage Cards have only 6 connectors. The connector matrix is a rectangle so I&#039;m guessing it&#039;s the same &#039;6 lines used, only put 6 onto the thing&#039;.</description>
		<content:encoded><![CDATA[<p>In the UK, Boots Advantage Cards have only 6 connectors. The connector matrix is a rectangle so I&#8217;m guessing it&#8217;s the same &#8216;6 lines used, only put 6 onto the thing&#8217;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piglet</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17496</link>
		<dc:creator>piglet</dc:creator>
		<pubDate>Mon, 31 Jul 2006 00:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17496</guid>
		<description>Going back to comment 26, in the UK, the chain of pharmacists use a smartcard with just 6 connectors. Is this the standard chip with different connectors. Can I read this with a standard reader?</description>
		<content:encoded><![CDATA[<p>Going back to comment 26, in the UK, the chain of pharmacists use a smartcard with just 6 connectors. Is this the standard chip with different connectors. Can I read this with a standard reader?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frodus</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17498</link>
		<dc:creator>frodus</dc:creator>
		<pubDate>Wed, 21 Jun 2006 20:11:05 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17498</guid>
		<description>A few years ago, there was a free reader from American Express, I got one, free of charge, no shipping. Need a smart card though...</description>
		<content:encoded><![CDATA[<p>A few years ago, there was a free reader from American Express, I got one, free of charge, no shipping. Need a smart card though&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frodus</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17497</link>
		<dc:creator>frodus</dc:creator>
		<pubDate>Wed, 21 Jun 2006 20:10:50 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17497</guid>
		<description>A few years ago, there was a free reader from American Express, I got one, free of charge, no shipping. Need a smart card though...</description>
		<content:encoded><![CDATA[<p>A few years ago, there was a free reader from American Express, I got one, free of charge, no shipping. Need a smart card though&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maluc</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17499</link>
		<dc:creator>maluc</dc:creator>
		<pubDate>Fri, 28 Apr 2006 21:53:25 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17499</guid>
		<description>well i found the code just now, and having tried many methods over these two months.. the one that worked like a charm was a logic analyzer .. if ur smart u can find one for $155US shipped, and worth every penny

u can also do as a friend is doing, and make your own logic analyzer using the parallel port.. but it can be a pain in the ass; microcontroller versions even worse +_+

the keckslist example is also a nice possibility, but you have to make sure to get a smartcard reader that has a &#039;read security memory&#039; command for the sle4442 ..the ACR30 does not!

good luck,
maluc ^^</description>
		<content:encoded><![CDATA[<p>well i found the code just now, and having tried many methods over these two months.. the one that worked like a charm was a logic analyzer .. if ur smart u can find one for $155US shipped, and worth every penny</p>
<p>u can also do as a friend is doing, and make your own logic analyzer using the parallel port.. but it can be a pain in the ass; microcontroller versions even worse +_+</p>
<p>the keckslist example is also a nice possibility, but you have to make sure to get a smartcard reader that has a &#8216;read security memory&#8217; command for the sle4442 ..the ACR30 does not!</p>
<p>good luck,<br />
maluc ^^</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan kamfolt</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17500</link>
		<dc:creator>ryan kamfolt</dc:creator>
		<pubDate>Thu, 27 Apr 2006 11:19:29 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17500</guid>
		<description>Sorry for some reason on my server you have to add the / to the end of the address so here is a working address:

http://www.keckslist.org/kinkos/</description>
		<content:encoded><![CDATA[<p>Sorry for some reason on my server you have to add the / to the end of the address so here is a working address:</p>
<p><a href="http://www.keckslist.org/kinkos/" rel="nofollow">http://www.keckslist.org/kinkos/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan kamfolt</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17501</link>
		<dc:creator>ryan kamfolt</dc:creator>
		<pubDate>Thu, 27 Apr 2006 10:55:43 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17501</guid>
		<description>HTTP://67.119.87.140/kinkos</description>
		<content:encoded><![CDATA[<p>HTTP://67.119.87.140/kinkos</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan kamfolt</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17502</link>
		<dc:creator>ryan kamfolt</dc:creator>
		<pubDate>Thu, 27 Apr 2006 10:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17502</guid>
		<description>The page is still there but you have to type the address out because the capitol KINKOS doesnt work so it should look like http://www.keckslist.org/k i n k o s without the spaces of course</description>
		<content:encoded><![CDATA[<p>The page is still there but you have to type the address out because the capitol KINKOS doesnt work so it should look like <a href="http://www.keckslist.org/k" rel="nofollow">http://www.keckslist.org/k</a> i n k o s without the spaces of course</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: someone in black and purple</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17503</link>
		<dc:creator>someone in black and purple</dc:creator>
		<pubDate>Mon, 24 Apr 2006 11:46:29 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17503</guid>
		<description>to add to what #33 said and #34&#039;s comments...

I also work at FedEx Kinko&#039;s  and I&#039;ve worked at several branches so let me clarify; technically anyone who attempts to refund the money off of a purple stored value card is only supposed to fill out a refund form when they are receiving more than $10 back. However in my experiance management never enforced this policy except at one store, and even in that case the customer can make up completely false information as we don&#039;t check their actual ID.

Quick question, why does this seem so much of a longer process than it looks in the video? do logic analyzers connect to the stores card readers or to your own? and what is #48&#039;s method? does anyone have his page saved, the page is now gone...</description>
		<content:encoded><![CDATA[<p>to add to what #33 said and #34&#8217;s comments&#8230;</p>
<p>I also work at FedEx Kinko&#8217;s  and I&#8217;ve worked at several branches so let me clarify; technically anyone who attempts to refund the money off of a purple stored value card is only supposed to fill out a refund form when they are receiving more than $10 back. However in my experiance management never enforced this policy except at one store, and even in that case the customer can make up completely false information as we don&#8217;t check their actual ID.</p>
<p>Quick question, why does this seem so much of a longer process than it looks in the video? do logic analyzers connect to the stores card readers or to your own? and what is #48&#8217;s method? does anyone have his page saved, the page is now gone&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maluc</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17504</link>
		<dc:creator>maluc</dc:creator>
		<pubDate>Sun, 26 Mar 2006 07:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17504</guid>
		<description>**update to end of #47 .. if you ignore the flowchart on page 4 of ACS&#039;s pc/sc programming reference: http://acs.com.hk/downloads_manual/PMA_ACx30.pdf

you can connect just fine without &#039;selecting&#039; the memory type.. just connect with SCARD_PROTOCOL_T0 (or SCARD_PROTOCOL_DEFAULT)

flowchart to follow:
SCardEstablishContext
SCardListReaders (use first string returned)
SCardConnect (SCARD_SHARE_SHARED &amp; SCARD_PROTOCOL_T0 &lt;-zero not &#039;oh&#039;)
SCardTransmit (SCARD_PCI_T0 &amp; SendBuffer filled with {0x00, Command, Arg1, Arg2, ...}
all transmits..
SCardDisconnect (SCARD_LEAVE_CARD)
SCardReleaseContext

Commands for Transmit:
Read: 0x00, Write: 0x01, WriteProtected: 0x02,
SubmitSecCode(PCODE): 0x03, ChangeSecCode:0x04?,
ReadSecCode: SendBuff[0xFF,0xB1,0x00,0x00,0x00]
*write/writep/changecode untested as i haven&#039;t gotten the seccode yet - batt wires crossed on way home :/ .. tape em up as i shoulda done..

also, #48s method works, although his example isnt a how-to.. read your datasheets. also, i HIGHLY advise u invest the $2.49+tax at fryes or an electronic store and buy some conductive copper tape instead of using 22-26 gauge wire.. its too thick to fit in the reader

conductive tape is paper thin and copper on the top side.. extend it 2-3inches past card across tape/paper, as it gets sucked in kinda deep.. then u can solder on some wires
http://www.tedpella.com/16067.jpg</description>
		<content:encoded><![CDATA[<p>**update to end of #47 .. if you ignore the flowchart on page 4 of ACS&#8217;s pc/sc programming reference: <a href="http://acs.com.hk/downloads_manual/PMA_ACx30.pdf" rel="nofollow">http://acs.com.hk/downloads_manual/PMA_ACx30.pdf</a></p>
<p>you can connect just fine without &#8217;selecting&#8217; the memory type.. just connect with SCARD_PROTOCOL_T0 (or SCARD_PROTOCOL_DEFAULT)</p>
<p>flowchart to follow:<br />
SCardEstablishContext<br />
SCardListReaders (use first string returned)<br />
SCardConnect (SCARD_SHARE_SHARED &#038; SCARD_PROTOCOL_T0 < -zero not 'oh')<br />
SCardTransmit (SCARD_PCI_T0 &#038; SendBuffer filled with {0x00, Command, Arg1, Arg2, ...}<br />
all transmits..<br />
SCardDisconnect (SCARD_LEAVE_CARD)<br />
SCardReleaseContext</p>
<p>Commands for Transmit:<br />
Read: 0x00, Write: 0x01, WriteProtected: 0x02,<br />
SubmitSecCode(PCODE): 0x03, ChangeSecCode:0x04?,<br />
ReadSecCode: SendBuff[0xFF,0xB1,0x00,0x00,0x00]<br />
*write/writep/changecode untested as i haven't gotten the seccode yet - batt wires crossed on way home :/ .. tape em up as i shoulda done..</p>
<p>also, #48s method works, although his example isnt a how-to.. read your datasheets. also, i HIGHLY advise u invest the $2.49+tax at fryes or an electronic store and buy some conductive copper tape instead of using 22-26 gauge wire.. its too thick to fit in the reader</p>
<p>conductive tape is paper thin and copper on the top side.. extend it 2-3inches past card across tape/paper, as it gets sucked in kinda deep.. then u can solder on some wires<br />
<a href="http://www.tedpella.com/16067.jpg" rel="nofollow">http://www.tedpella.com/16067.jpg</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan kamfolt</title>
		<link>http://hackaday.com/2006/03/02/fedex-kinkos-smart-cards-hacked/comment-page-2/#comment-17505</link>
		<dc:creator>ryan kamfolt</dc:creator>
		<pubDate>Wed, 22 Mar 2006 13:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2006/03/02/fedex-kinkos-smart-cards-hacked/#comment-17505</guid>
		<description>OK GUYS IM BACK. I WAS THE ONE WHO POSTED THE #42 AND #43 COMMENT. I WAS ONLY KIDDING. BUT I DO HAVE THE CODE AND BY VISITING MY SITE I AM SHOWING HOW I GOT THE CODE BUT NOT THE PROGRAMMING I USED OR A FEW OTHER THINGS YOU CAN GET THE HINT BY GETTIN WHITEPAPERS ON THE CARD AND ALSO BUYING A SAUDER IRON. HERES THE STUFF: HTTP://WWW.KECKSLIST.ORG/KINKOS</description>
		<content:encoded><![CDATA[<p>OK GUYS IM BACK. I WAS THE ONE WHO POSTED THE #42 AND #43 COMMENT. I WAS ONLY KIDDING. BUT I DO HAVE THE CODE AND BY VISITING MY SITE I AM SHOWING HOW I GOT THE CODE BUT NOT THE PROGRAMMING I USED OR A FEW OTHER THINGS YOU CAN GET THE HINT BY GETTIN WHITEPAPERS ON THE CARD AND ALSO BUYING A SAUDER IRON. HERES THE STUFF: HTTP://WWW.KECKSLIST.ORG/KINKOS</p>
]]></content:encoded>
	</item>
</channel>
</rss>
