Hyphen
Member
I would guess that they were using the Avantix hardware but with their own software, as they won't have been able to get into the operating system they come with. This would be consistent with them buying tickets to clone the magnetic strip wholesale, rather than attempting to reverse engineer it.
I know the Windows Mobile that Avantix uses is fairly well locked down from the onboard user interface point of view (primarily done to stop guards from installing things or going into its Control Panel and messing around), but I'd be surprised if it was that heavily protected against offboard attacks, given the unlikelihood of (legitimate) users wanting to plug them into PCs.
WinMo was a great OS in its day, but like Windows XP now - the security model baked in doesn't quite cut it any more. Recalling back to my days of owning WinMo phones, the OS by default talks quite happily to any PC it finds over ActiveSync, and there's quite a lot of scope for retrieving data, installing and running applications and modifying system settings from the appropriate developer kit.
Android (I can't speak for iOS) does much the same if the correct options for USB debugging and installing unsigned software are enabled - but these are turned off by default.
That saaaaid, the above is probably well beyond the skills and knowhow of a bunch of ticket cloners.
EDIT: too slow typing, cjmillsnun beat me to it!
Last edited: