{"id":2317,"date":"2016-08-04T04:15:14","date_gmt":"2016-08-04T08:15:14","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2317"},"modified":"2019-11-15T14:58:50","modified_gmt":"2019-11-15T11:58:50","slug":"hacking-lottery","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/hacking-lottery\/2317\/","title":{"rendered":"Dijital \u00e7a\u011f\u0131n piyango doland\u0131r\u0131c\u0131lar\u0131"},"content":{"rendered":"<p>Deyi\u015fe g\u00f6re, \u201cPiyango, matemati\u011fi k\u00f6t\u00fc olanlar i\u00e7in vergidir.\u201d Bunun nedeni, b\u00fcy\u00fck reklam\u0131 yap\u0131lan ikramiye kazananlar\u0131n say\u0131s\u0131n\u0131n olduk\u00e7a az olmas\u0131d\u0131r. Piyangoyu kazanmay\u0131 d\u00fc\u015f\u00fcnmek e\u011flencelidir, ancak bunu hayal etmek \u00e7o\u011fumuzun yapabildi\u011fi tek \u015feydir \u2013 piyango kazanabilmek i\u00e7in olduk\u00e7a \u015fansl\u0131 olmak gerek. Devasa piyangolar\u0131 kazanmak i\u00e7in al\u0131\u015ft\u0131rma yapamazs\u0131n\u0131z, strateji geli\u015ftiremezsiniz ya da kendinizi bunun i\u00e7in e\u011fitemezsiniz. Baz\u0131lar\u0131 ise hile yapar.<\/p>\n<p><strong>Durum 1: Makineyi aldatmak<\/strong><br>\nTuhaf durum <a href=\"http:\/\/www.nbcnews.com\/news\/us-news\/brother-jackpot-rigger-massive-lottery-scandal-arrested-n551941\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">10 y\u0131l s\u00fcren ara\u015ft\u0131rma<\/a>n\u0131n ard\u0131ndan a\u00e7\u0131kl\u0131\u011fa kavu\u015ftu. 2006 y\u0131l\u0131nda, Amerikan emniyeti Tommy Tipton\u2019\u0131n ayn\u0131 seriden ard\u0131\u015f\u0131k 500.000 dolar\u0131 oldu\u011funu ortaya \u00e7\u0131kard\u0131.<\/p>\n<p>Paran\u0131n ger\u00e7ekten sahibi oldu\u011funu kan\u0131tlamak i\u00e7in, Tipton piyangoyu kazand\u0131\u011f\u0131n\u0131 ancak kazand\u0131\u011f\u0131 paran\u0131n %10\u2019unu arkada\u015f\u0131na verdi\u011fini a\u00e7\u0131klad\u0131.  Tipton bo\u015fanma a\u015famas\u0131nda olduklar\u0131 kar\u0131s\u0131ndan paray\u0131 saklamak i\u00e7in bu oyunu tasarlad\u0131\u011f\u0131n\u0131 s\u00f6yledi. Mahkeme Tipton\u2019un a\u00e7\u0131klamas\u0131n\u0131 kabul etti ve bu konuyu ara\u015ft\u0131rmay\u0131 b\u0131rakt\u0131.<\/p>\n<p>Ancak bir \u015fey farkedilmeden ge\u00e7ilmi\u015fti. \u015eansl\u0131 kazanan\u0131n karde\u015fi Eddie Tipton Multi-Devlet Piyango Derne\u011fi (b\u00fcy\u00fck ihtimalle bunu daha \u00f6nce duymam\u0131\u015ft\u0131n\u0131z) taraf\u0131ndan i\u015fe al\u0131nm\u0131\u015ft\u0131 ancak oyunlar\u0131ndan baz\u0131lar\u0131n\u0131 (Powerball ve Mega Millions) muhakkak g\u00f6rm\u00fc\u015fs\u00fcnd\u00fcr. Eddie Tipton bilgi g\u00fcvenli\u011finden sorumluydu ve rastgele say\u0131 jenarat\u00f6r\u00fcn\u00fcn (RNG- piyango i\u00e7in yap\u0131lan makine) yap\u0131mc\u0131lar\u0131ndan biriydi.<\/p>\n<p>Ancak bu \u00e7ok daha sonra, birka\u00e7 devletteki piyango dernekleri piyangoyu almak \u00fczere insanlar\u0131n kendileri gitmek yerine ba\u015fka birilerini g\u00f6nderdi\u011fini tescilleyince a\u00e7\u0131kl\u0131\u011fa kavu\u015fmu\u015ftu. 2011\u2019de piyango kazanan\u0131, biletin kendisine Tommy Tipton\u2019un s\u00f6yledi\u011fi ki\u015fiden ald\u0131\u011f\u0131n\u0131, \u00e7\u0131kan ikramiyeden \u00f6d\u00fcl verece\u011fini s\u00f6z verdi\u011fini s\u00f6yledi. Nedeni neydi? Bo\u015fanmak \u00fczere oldu\u011fu kar\u0131s\u0131. Kazanan numara? Eddie Tipton\u2019un tasarlad\u0131\u011f\u0131 sistem taraf\u0131ndan olu\u015fturuldu.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Lottery official gets prison for trying to rig $14 million jackpot <a href=\"http:\/\/t.co\/CSrlZhUWHT\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/CSrlZhUWHT<\/a> <a href=\"http:\/\/t.co\/63goAApkUP\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/63goAApkUP<\/a><\/p>\n<p>\u2014 New York Post (@nypost) <a href=\"https:\/\/twitter.com\/nypost\/status\/641820275043119104?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">September 10, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>2011\u2019de ba\u011flant\u0131l\u0131 ba\u015fka bir olay oldu. Kanadal\u0131 bir vatanda\u015f tan\u0131t\u0131l\u0131rken kendi ismini vermeden 16.5 milyon dolarl\u0131k piyangoyu kazand\u0131. Ara\u015ft\u0131rman\u0131n bir k\u0131sm\u0131 olarak piyango derne\u011fi, kazanan bileti kimin ald\u0131\u011f\u0131n\u0131n izlenmesini istedi. Baz\u0131 insanlar Eddie Tipton\u2019un sesini hemen tan\u0131d\u0131lar. Ara\u015ft\u0131rmac\u0131lar telefon g\u00f6r\u00fc\u015fmelerini analiz etti ve Eddie ile su\u00e7lar\u0131 aras\u0131ndaki ba\u011f\u0131 buldular.<\/p>\n<p>Bu kan\u0131t Eddie Tipton\u2019a kar\u015f\u0131 a\u00e7\u0131lan davada kullan\u0131ld\u0131. 2015 y\u0131l\u0131nda, su\u00e7u kan\u0131tland\u0131 ve 10 y\u0131l hapse mahkum edildi. Ancak, temyiz ile serbest b\u0131rak\u0131ld\u0131.<\/p>\n<p>Eninde sonunda, ara\u015ft\u0131rma bir\u00e7ok b\u00f6lgede alt\u0131 doland\u0131r\u0131c\u0131l\u0131\u011f\u0131 ortaya \u00e7\u0131kard\u0131. Bu doland\u0131r\u0131c\u0131lar, y\u00fczbinlerce dolar\u0131 \u00e7alm\u0131\u015ft\u0131. <\/p>\n<p>Puzzle\u2019\u0131n en ilgi \u00e7ekici taraf\u0131 doland\u0131r\u0131c\u0131l\u0131\u011f\u0131n teknik metodu. Ara\u015ft\u0131rmalar Eddie Tipton\u2019un tasarlad\u0131\u011f\u0131 RNG\u2019yi modifiye etti\u011fini ve rastgele de\u011fil tahmin edilebilir say\u0131lar \u00fcretti\u011fini ortaya \u00e7\u0131kard\u0131. Al\u0131c\u0131n\u0131n numaralar\u0131 doldurdu\u011fu piyango biletlerini kullanmak sahtekarl\u0131\u011f\u0131n gerekli bir b\u00f6l\u00fcm\u00fcyd\u00fc. <\/p>\n<p>\u00c7ekili\u015fin yap\u0131ld\u0131\u011f\u0131 y\u0131l\u0131n belirli \u00fc\u00e7 g\u00fcn\u00fc, <em>haftan\u0131n belirli iki g\u00fcn\u00fc ve g\u00fcn\u00fcn belli saatlerinde<\/em> bu tema \u00e7al\u0131\u015f\u0131yordu. Eddie Tipton g\u00fcnl\u00fck g\u00fcvenlik denetimi tamamland\u0131\u011f\u0131nda sistemin i\u00e7ine g\u00f6m\u00fcl\u00fc bir .dll dosyas\u0131 geli\u015ftirdi.<\/p>\n<p>Bu kas\u0131tl\u0131 su\u00e7u kan\u0131tlamas\u0131 zordu \u00e7\u00fcnk\u00fc \u00e7al\u0131\u015ft\u0131ktan sonra dosya kendini siliyordu. Ancak, adli tabip tak\u0131m\u0131 \u00e7ekili\u015flerden birinde kullan\u0131lan kodu bulmay\u0131 ba\u015fard\u0131lar.<\/p>\n<p>Gayet s\u0131ra d\u0131\u015f\u0131 yeniden canland\u0131rma yap\u0131ld\u0131, bir adli tabip tak\u0131m\u0131 modifiye edilmi\u015f RNG\u2019yi kullanarak son \u00e7ekili\u015fi tekrar etmeyi (saati do\u011fru zamanda ayarlayarak) ba\u015fard\u0131lar ve ayn\u0131 kazanan numaralar\u0131 elde ettiler.<\/p>\n<p>RNG ile u\u011fra\u015fan sofistike bir program\u0131n d\u0131\u015f\u0131nda, Eddie Tipton video izleme sistemini biletlerin sat\u0131ld\u0131\u011f\u0131 yerde baypas eden sistemlerle \u00f6nlem ald\u0131. \u0130\u015fte buras\u0131 hack yetene\u011finin ilk patlama yeri oldu \u2013 sistemi bir\u00e7ok de\u011fi\u015fkenle aldatamad\u0131. Bir yak\u0131n\u0131n\u0131 bu i\u015fe soktu, kazanan bileti sat\u0131n ald\u0131ktan sonra, su\u00e7 ortaklar\u0131yla telefonda konu\u015ftu ve kusursuz gibi g\u00f6r\u00fcnen bu doland\u0131r\u0131c\u0131l\u0131\u011f\u0131 kendi bitirdi. <\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">How do you make a completely anonymous phone call? It's harder than you think \u2013 <a href=\"http:\/\/t.co\/KZbvNxx7wz\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/KZbvNxx7wz<\/a> <a href=\"http:\/\/t.co\/oocb9LHjlp\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/oocb9LHjlp<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/585513680009359361?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">April 7, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><a href=\"https:\/\/www.kaspersky.com\/blog\/art-making-anonymous-calls\/8225\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Takip edilmekten ka\u00e7mak<\/a> bug\u00fcnlerde zor. \u00d6rnek olarak, davac\u0131 biletlerin sat\u0131ld\u0131\u011f\u0131 zaman Tipton\u2019un co\u011frafi konumunu kan\u0131t olarak kulland\u0131. Ba\u015fka bir kan\u0131t ise, su\u00e7 ortaklar\u0131ndan birinin LinkedIn g\u00f6nderisinde \u201cEddie ile \u00e7al\u0131\u015fmaya her zaman haz\u0131r\u0131m\u201d payla\u015fmas\u0131 oldu. <\/p>\n<p>Onu g\u00fcvenli hale getirmesi gereken insanlardan sistemi nas\u0131l korursunuz? Bu tezgah ortaya \u00e7\u0131kar \u00e7\u0131kmaz, Iowa piyango derne\u011fi ekipman\u0131n\u0131 ve yaz\u0131l\u0131mlar\u0131n\u0131 de\u011fi\u015ftirdi. Modifiye etmek i\u00e7in yeni yaz\u0131l\u0131mlara bakt\u0131, daha yeni video izleme sistemleri edindi ve \u00e7al\u0131\u015fanlar\u0131n doland\u0131rma olas\u0131l\u0131\u011f\u0131na kar\u015f\u0131n fonksiyonlar kulland\u0131. <\/p>\n<p><strong>Durum 2: Makineyi bozmak <\/strong><br>\n<a href=\"http:\/\/www.tripwire.com\/state-of-security\/latest-security-news\/six-suspects-arrested-for-manipulating-5-card-cash-lottery-game-terminals\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">2015, Connecticut\u2019ta ya\u015fanan bir ba\u015fka hikayede<\/a> doland\u0131r\u0131c\u0131lar i\u015flerini piyangoyu hacklemek i\u00e7in kulland\u0131lar. Eddie Tipton\u2019dan farkl\u0131 olarak, RNG sistemine eri\u015fimleri yoktu; piyango bileti makinelerinin y\u00fcklendi\u011fi yerlerde \u00e7al\u0131\u015f\u0131yorlard\u0131. <\/p>\n<p>Bu doland\u0131r\u0131c\u0131lar makinelerin 5 Kart Nakit piyangosu i\u00e7in ekstra bilet basmas\u0131n\u0131 sa\u011flayan bir yol buldular. \u00d6rne\u011fin, de\u011fi\u015ftirilen makineler %67 oran\u0131nda kazanan bilet bas\u0131yordu normal makinelerin kazanan bilet basma olas\u0131l\u0131\u011f\u0131 ise %24.<br>\nSonu\u00e7 olarak, 5 Kart Nakit piyangosu Kas\u0131m 2015 y\u0131l\u0131nda durduruldu ve o zamandan beri de art\u0131k oynanm\u0131yor. Organizat\u00f6rler de\u011fi\u015ftirilmesi zor olan yeni sistemler geli\u015ftirdi\u011fini duyurdu.<\/p>\n<p><a href=\"http:\/\/www.courant.com\/breaking-news\/hc-more-5-card-cash-lottery-arrests-0406-20160405-story.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Hartford Courant\u2019a g\u00f6re<\/a>, su\u00e7lular\u0131n anla\u015fmak kulland\u0131\u011f\u0131 teknikler geli\u015fti. Kasten makineyi yava\u015flatt\u0131lar, \u00f6rne\u011fin birden fazla rapor iste\u011fi yollayara yazd\u0131rma i\u015flemini ba\u015flatt\u0131lar. Teknik \u00f6zellikler ekstra y\u00fcklenmenin sonucunda sistemin gecikmesine neden oldular, bu da kullanan ki\u015finin hangi biletin kazanaca\u011f\u0131n\u0131 g\u00f6rmesini sa\u011flad\u0131. Kazanan bilet de\u011filse doland\u0131r\u0131c\u0131lar sat\u0131n alma i\u015flemini durdurup prosed\u00fcr\u00fc tekrar ediyorlard\u0131.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Cops: Lottery terminal hack allowed suspects to print more winning tickets <a href=\"https:\/\/t.co\/l5Rm8QFlDu\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/l5Rm8QFlDu<\/a> by <a href=\"https:\/\/twitter.com\/dangoodin001?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">@dangoodin001<\/a><\/p>\n<p>\u2014 Ars Technica (@arstechnica) <a href=\"https:\/\/twitter.com\/arstechnica\/status\/713430254803615744?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">March 25, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><strong>Eski moda: Toplarla u\u011fra\u015fmak<\/strong><br>\nTabiki hile yapmak piyango d\u00fcnyas\u0131nda yeni bir \u015fey de\u011fil. Kolay yoldan paran\u0131n d\u00fcnyan\u0131n her yerinde \u00e7ekicili\u011fi vard\u0131r. 1980\u2019de, Pennsylvania\u2019da TV piyangosunun sunucusu makinedeki toplar\u0131 daha a\u011f\u0131r olan kopyalar\u0131yla de\u011fi\u015ftirdi, bu da \u00e7ekili\u015flerde sadece 4 ve 6 toplar\u0131n\u0131n \u00e7\u0131kmas\u0131yla sonu\u00e7land\u0131. 666 \u00e7ekili\u015ften sonra, organizat\u00f6rler d\u00f6rt ve alt\u0131lara sahip bilete sahip birinin bu i\u015fle bir ilgi olabilece\u011fini d\u00fc\u015f\u00fcnd\u00fc ve bu da ara\u015ft\u0131rmalar\u0131 ba\u015flatmaya yetiyordu. <\/p>\n<p>Doland\u0131r\u0131c\u0131l\u0131k dijital \u00e7a\u011fda daha kolay gibi g\u00f6r\u00fcnebilir. Ancak su\u00e7lular toplar\u0131 de\u011fi\u015ftirse de, bilgisayarlara k\u00f6t\u00fc kodlar girse de, ayn\u0131 zamanda hatalar yap\u0131yorlar. Piyango \u00f6d\u00fcl\u00fc harika bir \u00f6d\u00fcl gibi g\u00f6r\u00fcnebilir ancak size hayal etmeye devam etmenizi \u00f6neririz \u00e7\u00fcnk\u00fc hatas\u0131z kurnaz bir plan yoktur \u2013bunlar\u0131n hepsi su\u00e7.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Deyi\u015fe g\u00f6re, \u201cPiyango, matemati\u011fi k\u00f6t\u00fc olanlar i\u00e7in vergidir.\u201d Bunun nedeni, b\u00fcy\u00fck reklam\u0131 yap\u0131lan ikramiye kazananlar\u0131n say\u0131s\u0131n\u0131n olduk\u00e7a az olmas\u0131d\u0131r. Piyangoyu kazanmay\u0131 d\u00fc\u015f\u00fcnmek e\u011flencelidir, ancak bunu hayal etmek \u00e7o\u011fumuzun yapabildi\u011fi tek<\/p>\n","protected":false},"author":2049,"featured_media":2318,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[948,545,949,510],"class_list":{"0":"post-2317","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-adalet","9":"tag-hack","10":"tag-piyango","11":"tag-siber-suclular"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/hacking-lottery\/2317\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/hacking-lottery\/7459\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/hacking-lottery\/7483\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/hacking-lottery\/7448\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/hacking-lottery\/8821\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/hacking-lottery\/8684\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/hacking-lottery\/12627\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/hacking-lottery\/12685\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/hacking-lottery\/5914\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/hacking-lottery\/8321\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/hacking-lottery\/12109\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/hacking-lottery\/12627\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/hacking-lottery\/12685\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/hacking-lottery\/12685\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/adalet\/","name":"adalet"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2049"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2317"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2317\/revisions"}],"predecessor-version":[{"id":7163,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2317\/revisions\/7163"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2318"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}