Tactics of Physical Pen Testers

freeCodeCamp Talks
22 Sept 202044:16

Summary

TLDRThe speaker, a physical security expert, debunks the myth that lock picking is the primary method used for covert entry. Instead, he shares practical and often overlooked techniques such as hinge pin removal, latch slipping, and exploiting poor door fitment. He also discusses electronic access control vulnerabilities, the use of common keys for access points, and the importance of being confident and appearing to belong when gaining unauthorized access. The talk is filled with real-world examples and advice on improving physical security measures.

Takeaways

  • 🔓 The speaker emphasizes that lock picking is often the least common method used to gain unauthorized access to buildings, suggesting that other techniques are more frequently employed.
  • 🛠️ The script highlights various physical security vulnerabilities, such as easily removable hinge pins and improperly installed latches, which can be exploited to bypass locked doors.
  • 🔑 The importance of understanding the type of lock and security system in place is underscored, as knowing the common keys or methods to exploit them can be advantageous in physical penetration testing.
  • 💡 The concept of 'social engineering' is implied through stories where confidence and appearing to belong can lead to successful unauthorized access, such as posing as an elevator repair technician.
  • 🛡️ Simple and inexpensive solutions, like security hinges and jam pins, are suggested to improve physical security and prevent easy access through doors.
  • 👮‍♂️ The role of security guards and their interaction with intruders is discussed, noting that their training and vigilance can vary significantly.
  • 🚪 The script points out that electronic access control systems, such as HID proximity cards, can be vulnerable to cloning and sniffing attacks.
  • 🔍 The use of everyday objects and tools, such as under-door tools and wire bridges, to gain access is demonstrated, showing that specialized lock-picking skills are not always necessary.
  • 🏢 The speaker shares anecdotes from physical security testing jobs, illustrating the diverse methods used to infiltrate buildings and the human elements that can be manipulated.
  • 🔗 The importance of cross-training in both physical and electronic security domains is suggested, as knowledge in both areas can enhance the effectiveness of a security professional.
  • 📈 The script concludes with a call to action for security professionals to be aware of the physical side of security, implying that a comprehensive approach is necessary to ensure robust security measures.

Q & A

  • What is the common misconception about the job of a physical security expert as described in the script?

    -The common misconception is that physical security experts, often referred to as 'break-in guys', primarily use lock picking to gain access to secure spaces. However, the script clarifies that lock picking is actually a less common method and is far down on the list of techniques used.

  • What is the first method mentioned in the script that can be used to bypass door security without picking the lock?

    -The first method mentioned is knocking out hinge pins, which allows the door to be removed from its frame, bypassing any locks on it.

  • What is a security hinge and how does it prevent the hinge pin removal method?

    -A security hinge is a type of hinge that has a peg which goes into a hole when the door is closed. This prevents the door from being removed from the frame even if the hinge pins are knocked out, as the peg blocks the attack.

  • What is a jam pin and how does it help in making a conventional hinge more secure?

    -A jam pin is a security-enhancing replacement for the screws in a conventional hinge. It transforms the hinge into a security hinge by preventing the hinge pin from being knocked out without the need to rehang the door.

  • What is the importance of properly installed latches in door security as highlighted in the script?

    -Properly installed latches, specifically dead latches, are crucial for door security because they prevent the door from being opened by latch slipping tools. If the latch is not installed correctly, it can be easily manipulated, compromising the security of the door.

  • What is a crash bar and why is it vulnerable to certain attacks as described in the script?

    -A crash bar is a type of door mechanism often used for emergency exits. It is vulnerable to attacks because it can be triggered by inserting a rod or other object through a gap in the door and pressing the bar, allowing unauthorized access.

  • What is the purpose of the 'thumb turn flipper' tool mentioned in the script?

    -The 'thumb turn flipper' is a tool used to manipulate thumb turn locks or deadbolts from the outside. It is used to unlock doors that have a thumb turn on the inside, allowing access without the need for a key.

  • What is the significance of the 'under door tool' in the context of the script?

    -The 'under door tool' is significant because it demonstrates how attackers can exploit poorly secured doors with lever-style handles. By reaching under the door and manipulating the handle, an attacker can open the door without needing to pick the lock.

  • What is the role of the 'postal switch' in a Door King access control system as described in the script?

    -The 'postal switch' in a Door King system is a momentary switch that, when activated, can trigger the door's relays to fire, effectively unlocking the door. It can be used as a bypass method if an attacker can access the switch.

  • What is the 'CH-751' key mentioned in the script and why is it significant?

    -The 'CH-751' key is a very common key used for various locks, including filing cabinets. It is significant because it can often open many locks by default, making it a useful tool for physical security testers.

  • What is the '1284X' key and why is it noteworthy in the context of the script?

    -The '1284X' key is a key used by the Ford Motor Company for their fleet vehicles, such as Crown Victorias. It is noteworthy because it is not a restricted key and can open many police vehicles and even start their engines, highlighting a potential security vulnerability.

Outlines

00:00

🔓 The Misconception of Lock Picking in Physical Security

The speaker, a professional in physical security, dispels the common myth that his job primarily revolves around lock picking. Despite the excitement associated with being a 'break-in guy', he clarifies that lock manipulation is far down the list of techniques used to gain entry into secured spaces. He emphasizes that his role involves various other methods, including covert entry tactics, and that the romanticized idea of lock picking is not the central aspect of his work.

05:01

🚪 Exploiting Door Vulnerabilities in Physical Penetration Testing

This section delves into the reality of how physical penetration testers gain access to buildings, focusing on the weaknesses of doors and their components. The speaker discusses the ease of removing hinge pins as a method of entry, regardless of the number of locks on a door. He also introduces the concept of security hinges and jam pins as solutions to strengthen door security. Additionally, he touches on the ineffectiveness of certain latch installations and the importance of dead latches in preventing unauthorized access.

10:01

🛠️ Practical Solutions to Common Physical Security Flaws

The speaker provides practical and cost-effective solutions to address common physical security issues. He highlights the use of security hinges and jam pins to prevent hinge pin removal, and discusses the importance of proper door fitment to ensure dead latches function correctly. He also addresses the risks associated with electronic strike plates and the use of thumb turn flippers as potential security threats, suggesting that understanding these vulnerabilities is crucial for improving physical security measures.

15:02

🕵️‍♂️ Advanced Techniques for Bypassing Physical Security

This paragraph explores more sophisticated methods used by physical security professionals to bypass security systems. The speaker describes using tools to exploit gaps under doors, reach through to thumb turns, and even manipulate request to exit sensors using cold gas clouds. He also touches on the use of dual-technology sensors that combine passive infrared and microwave radar to prevent such bypasses, emphasizing the need for robust security measures.

20:03

🛡️ Creative and Inexpensive Security Solutions for Doors

The speaker shares unconventional yet effective methods for enhancing door security. He discusses the use of door shrouds, clips, and other simple devices to prevent unauthorized access through under-door tools. These solutions are not only cost-effective but also easy to implement, demonstrating that creativity can play a significant role in improving physical security.

25:04

🔑 The Art of Key Stealing and Its Implications for Security

In this section, the speaker humorously discusses the ease of stealing keys from lock boxes and the surprising prevalence of universal keys across security systems. He highlights the lack of security in using common keys for access control boxes and the potential risks of not securing these keys properly. The speaker encourages security professionals to be aware of these vulnerabilities and to implement more robust key management practices.

30:05

🛠️ Leveraging Common Keys and Simple Tools in Security Breaches

The speaker shares anecdotes about using common keys and simple tools to breach security systems. He demonstrates how easily accessible keys, such as those for elevators, filing cabinets, and vehicles, can be used to gain unauthorized access. He also discusses the use of jigglers and wire bridges to manipulate locks and suggests that security professionals should be aware of these simple yet effective techniques used by intruders.

35:05

💼 The Importance of Confidence and Belonging in Physical Security Breaches

This paragraph emphasizes the power of confidence and the appearance of belonging when attempting to breach security. The speaker recounts stories of individuals who successfully gained access to facilities by acting as if they were authorized personnel, such as armed guards or service technicians. He suggests that security professionals should be trained to question and verify the credentials of anyone entering a secured area, regardless of their appearance or demeanor.

40:05

👮‍♂️ The Role of Armed Guards and the Potential for Security Breaches

The speaker discusses the challenges of interacting with armed guards and the potential for security breaches due to human error or lapses in judgment. He recounts a story of attempting to clone electronic credentials while posing as a police officer to gain the trust of the guards. The anecdote highlights the importance of vigilance and the need for guards to maintain a high level of suspicion and awareness to prevent unauthorized access.

🏢 Real-World Applications of Physical Security Breaching Techniques

In the final paragraph, the speaker wraps up his presentation by summarizing the various techniques and strategies discussed for breaching physical security. He encourages the audience to consider the physical aspects of security alongside digital measures and to test their own security systems for vulnerabilities. The speaker also hints at additional stories and insights that can be shared during a Q&A session, emphasizing the importance of continuous learning and adaptation in the field of security.

Mindmap

Keywords

💡Lock picking

Lock picking is the art of manipulating the components of a lock to open it without using the original key. In the context of the video, it is portrayed as a common yet not the primary method used by physical security experts to gain access to secured spaces. The speaker clarifies that while lock picking is often romanticized, it is actually quite low on the list of techniques they use.

💡Covert entry team

A covert entry team is a group of specialists who infiltrate secured areas discreetly, often for testing security measures. In the video, the speaker mentions running such a team with Robert Bobbik, emphasizing the variety of skills and tactics beyond lock picking that they employ.

💡Hinge pins

Hinge pins are the metal rods that connect the door to its hinges. The script describes a technique where these pins can be knocked out, allowing the door to be removed from its frame as an alternative to picking the lock, illustrating a physical security flaw that can be easily fixed.

💡Jam pins

Jam pins are a security enhancement for door hinges that prevent the door from being removed by removing the hinge pins. The speaker recommends jam pins as an inexpensive and effective solution to improve physical security against hinge pin removal attacks.

💡Latch slipping

Latch slipping is a technique used to open doors without a key, where a tool is used to manipulate the latch into the unlocked position. The video describes how improper installation of latches can make them vulnerable to this attack, and the importance of using dead latches to prevent it.

💡Dead latch

A dead latch is a type of door latch mechanism that cannot be opened from the outside without a key. The script explains that modern doors should have dead latches to prevent latch slipping, and that proper installation is crucial for security.

💡Electronic access control

Electronic access control systems are used to manage and monitor entry to a building or room using electronic credentials like keycards or fobs. The speaker discusses various ways these systems can be compromised, such as by credential cloning or sniffing.

💡Credential cloning

Credential cloning involves copying the information from an access control card or fob to create a duplicate. In the video, the technique is shown as a method to gain unauthorized access by capturing credentials from a distance using specialized equipment.

💡Door fitment

Door fitment refers to how well a door is installed and aligned within its frame. The script points out that poor door fitment can lead to security vulnerabilities, such as the ability to bypass locks using simple tools or techniques.

💡Crash bars

Crash bars, also known as panic bars, are mechanisms used on emergency exits that allow the door to be pushed open. The video describes how weather stripping or other barriers can be bypassed to activate the crash bar from the outside, demonstrating a security oversight.

💡Under door tools

Under door tools are devices used to manipulate the locking mechanism or handle of a door from underneath, allowing it to be opened without a key. The speaker mentions these tools as part of their arsenal for gaining access to rooms, highlighting the need for proper door handle protection.

Highlights

The speaker runs a covert entry team and discusses the misconception that their job primarily involves lock picking, which is actually a less common method.

Photo shoot for an article showcasing the team's work led to a demonstration of lock picking, though it's not the main technique used.

Lock manipulation is described as the ninth method tried to gain entry, emphasizing there are more common techniques.

The importance of understanding door hardware and installation, such as hinge pins and security hinges, is highlighted as a way to improve physical security.

Jam pins are recommended as an easy and cost-effective solution to enhance door security.

The use of latch slipping tools to bypass doors without picking locks is demonstrated, showing a common vulnerability in door installations.

The concept of dead latches is introduced, explaining how they prevent latch slipping attacks.

Proper door fitment, including the correct installation of strike plates and latches, is emphasized as crucial for security.

The exploitation of gaps in door installations, such as with crash bars and weather stripping, is shown as an easy entry method.

The use of tools to flip thumb turns on the other side of the door is demonstrated, bypassing the need for a physical key.

The vulnerability of frameless glass doors and the use of simple tools to reach and operate handles or locks from the outside.

The speaker discusses the use of under-door tools to manipulate lever-style door handles from underneath, bypassing the lock entirely.

The effectiveness of simple measures like clips or shrouds on door handles to prevent under-door tool attacks is mentioned.

The potential for stealing keys or key information from lock boxes or access control panels is highlighted.

The use of common keys for certain access control systems, like the Door King and Linear keys, to gain unauthorized access is demonstrated.

The speaker shares stories of successful physical penetrations using confidence and the appearance of belonging, such as posing as service technicians.

The importance of cross-training in both physical and electronic security to better understand and exploit vulnerabilities.

The use of long-range readers and other electronic devices to capture credentials for cloning purposes.

The speaker concludes by encouraging the audience to consider physical security methods beyond lock picking and to utilize simple yet effective techniques.

Transcripts

play00:00

so yeah many of us have fun gigs though

play00:02

many of us have really fun jobs people

play00:04

come up to me a lot

play00:05

and they say oh my gosh deviant you know

play00:07

physical security and break it in that's

play00:09

your job is so cool i like it and yes i

play00:12

get it right like

play00:13

being the break-in guy is fun if you've

play00:15

never met me that i run a covert entry

play00:17

team

play00:17

robert bobbik and our crew of hooligans

play00:20

in places we shouldn't be

play00:22

but the funny thing people kind of

play00:24

romanticize this notion like yes

play00:27

our ops division does very dynamic door

play00:29

kicker stuff

play00:31

but for this one scene here this was a

play00:33

photo shoot when an article came out

play00:34

about what we do

play00:36

they were like oh yeah get some pics and

play00:37

get some pics in your hands right

play00:39

and so like i'm here picking a door

play00:42

now everyone has said to me i'm known as

play00:45

this lock picker and like maybe i've

play00:47

taught some of you about lock picking if

play00:48

you've ever seen like any of these

play00:49

animations that tool has on all of our

play00:51

slides like

play00:52

if you've ever learned how a lock works

play00:54

you saw the little pins and they

play00:56

they bind but they push up with a key

play00:58

and if i don't have a key like how do i

play01:00

get in the lock like

play01:01

i've taught about lock picking forever

play01:04

and everyone thinks of me as this lock

play01:05

picker and they say oh yes so like i'd

play01:07

love to have that job man

play01:09

like that's you know you at a door at

play01:10

two in the morning with those picks out

play01:11

i wish i could do that and get paid

play01:13

which again like sure that's fun and i

play01:17

have

play01:17

picked locks to get into secured spaces

play01:20

but this [ __ ] here manipulating the pins

play01:23

with like pick tools

play01:25

it's something like the ninth thing on

play01:27

the list of stuff we try

play01:28

to get into buildings and this whole

play01:31

talk is not this is like the last

play01:33

lock-picking slide in the talk

play01:35

because this is not a lock-picking talk

play01:37

i am i know hooray is what i say because

play01:39

i'm so

play01:40

tired hey you made it i'm so tired of

play01:43

talking about lock picking

play01:44

i love like i love when someone new is

play01:46

learning it right and if someone's never

play01:47

done this and they get it

play01:49

and it's this whoa moment that's fun but

play01:52

i gotta

play01:52

stop this illusion that we are picking

play01:55

lock like how many times do you pick a

play01:56

door

play01:57

you don't johnny like [ __ ] yeah vince

play02:00

and you like you don't really pick

play02:01

doors this this [ __ ] is great that's not

play02:04

what we do

play02:06

so let's talk about how physical pen

play02:08

testers actually get into buildings

play02:10

how real covert entry tends to work and

play02:12

how you fix almost all of it

play02:15

dumb [ __ ] right like right off the bat i

play02:16

have not i've legit

play02:18

knocked hinge pins out of doors you just

play02:20

bang a hinge pin out walk the door i

play02:22

don't care how many locks are on the

play02:23

door

play02:24

if you can walk that door away from the

play02:26

frame walk in

play02:28

this is a thing that you can do with

play02:29

like a nail or a nice little orange tool

play02:31

so you don't bust up your fingers

play02:33

but again like all these locks in the

play02:35

door what you don't see are hinges

play02:36

hinges are on the outside of this door

play02:39

this is an absolute method that gets you

play02:41

into places

play02:42

and stupid easy to fix i'm giving you

play02:45

like easy ones off the bat here

play02:47

this is a security hinge the door swings

play02:50

shut

play02:51

little peg goes in a little hole doesn't

play02:53

matter if you bang the hinge pins out

play02:55

you can't wrench that away from the door

play02:56

frame

play02:57

because the peg is in the hole like

play02:58

literally it puts it it puts a block

play03:00

from that attack

play03:02

if you don't want to buy new hinges and

play03:03

re-hang all your doors i'm huge into

play03:06

recommending what are called jam pins

play03:08

i don't sell any of this stuff like i

play03:10

know some of the firms that make it but

play03:11

like

play03:12

brilliant idea what are jam pins you

play03:14

have a conventional hinge

play03:15

take out these two screws replace them

play03:18

with jam pins

play03:19

take out these two screws replace them

play03:22

with [ __ ] all

play03:23

you just made a security hinge and you

play03:25

didn't rehang your door

play03:27

like two dollars i think brilliant kind

play03:30

of solutions

play03:31

easy easy stuff slipping latches and

play03:34

such

play03:35

like people see me like oh he's taking a

play03:37

tool out of his pocket he's going to

play03:38

open that door what's he doing

play03:39

i'm not taking pics out of my pocket

play03:41

most of the time

play03:42

i am doing sound by the way oh no sound

play03:45

we're gonna need sound

play03:46

who's my sound guy back there let's see

play03:52

anybody you hear it all right oh well

play03:55

well i don't know why we're not getting

play03:56

sound but yell the guy in the back he's

play03:57

not doing anything

play03:59

so yeah like this is a completely locked

play04:01

door this is a water treatment facility

play04:03

this is like the room where they

play04:04

chlorinate and prep the water for the

play04:06

supply and i'm not picking the lock i'm

play04:08

just attacking it with a little

play04:10

latch slipping tool you should not be

play04:12

able to do this

play04:13

on most systems right

play04:17

here's a door

play04:20

there we go is there some sound can

play04:22

anyone in the back turn the sound the

play04:24

[ __ ] up please

play04:27

there's a remote oh wow this is like

play04:30

dad's living room

play04:31

way too many buttons is that a thing

play04:34

is that happening i don't know whatever

play04:37

all right i don't care i'm gonna keep

play04:38

going

play04:39

but yeah like this little tool this

play04:41

little stupid hook that we've been

play04:42

selling in our student kits we give them

play04:44

to you you give them to students

play04:45

it's like a five dollar part and it gets

play04:48

through so many doors what we're doing

play04:50

here

play04:50

it's not that you can like reach the

play04:52

latch here's a latch you can't reach

play04:54

with a hook because it's got that big

play04:55

plate over it right

play04:56

get yourself a big piece of wire

play05:00

oops the problem is not that you can

play05:03

touch or can't touch the latch the

play05:05

problem in all these bits of footage

play05:06

here

play05:07

is that the latch is not installed

play05:08

properly latches

play05:10

in a modern environment should be what

play05:12

are called dead latches

play05:14

in fact this is a picture of a dead

play05:16

latch well let's talk about

play05:18

what is a dead latch what is not well

play05:20

this is the latch

play05:21

right this is what goes into the strike

play05:22

plate holds the door shut

play05:24

if you lean on the door the door does

play05:25

not pop open

play05:27

you might remember doors that only ever

play05:28

had this this is what a door used to

play05:30

look like

play05:31

long time ago and then all of a sudden

play05:32

you started getting this extra little

play05:34

button

play05:34

sometimes called a guard bolt sometimes

play05:37

called the dead latch

play05:38

plunger has a lot of names but that

play05:40

extra button that i will highlight in

play05:41

red here

play05:42

that indicates that you have a dead

play05:44

latch mechanism

play05:46

the dead latch plunger or the guard bolt

play05:49

many people only see it when the door is

play05:50

open

play05:51

and you know it's not always in this

play05:52

configuration sometimes it's next to the

play05:54

latch it's

play05:55

there's a lot of styles no matter what

play05:57

style you have

play05:59

you might not know when the door shuts

play06:02

that's supposed to be held back

play06:04

it's supposed to be pressed back into

play06:06

the door by the strike plate

play06:07

it's not supposed to pop out into the

play06:08

hole if that is pressed back

play06:11

that latch is now dead you can't hook it

play06:14

slip it shim it anything like that

play06:16

that's how this is supposed to work but

play06:18

the problem is door fitment

play06:20

if you don't have the right hardware

play06:22

mounting and you don't have the door

play06:23

hung

play06:23

properly we see this all the time on

play06:26

doors man

play06:28

this we've got a nice door properly

play06:30

locked okay this is a piece of trash

play06:33

literally a piece of plastic garbage

play06:35

shoved in

play06:37

boom server room look at the size of

play06:39

that strike plate hole

play06:41

you could drive a truck into that why is

play06:43

it so huge is this the strike plate that

play06:45

came with this

play06:45

handle set what do you think this is

play06:49

yes i heard it say it louder electronic

play06:52

strike plate this is a card reader

play06:54

access door

play06:55

so they retrofit the additional like the

play06:57

original plate of strike plate they put

play06:59

like a

play06:59

separate unit a solenoid powered strike

play07:02

and there's all different configurations

play07:03

of this kind of hardware

play07:05

we literally know integrators and

play07:07

installers who are like oh make sure you

play07:09

always get like the jp 41 that's the one

play07:11

with the big hole

play07:12

it always works no matter what door the

play07:14

client has it's no problem

play07:16

no that is not how this is supposed to

play07:19

work you are

play07:19

really undermining your security another

play07:22

door

play07:22

another water facility right nice lock i

play07:26

mean

play07:26

i'm i'm a decent enough picker i'm not

play07:28

going to try to pick this

play07:29

why not because boom bad door fitment

play07:32

over and over and over

play07:33

and like you know you don't want me in

play07:35

there i don't belong in this room

play07:38

five dollar hook gets me in when a nice

play07:41

lock could have prevented me

play07:42

if they had properly set the door up

play07:45

let's talk about this kind of door

play07:46

fitment problem you got crash bars let's

play07:48

just reach through

play07:49

you've told stories like this forever

play07:52

what

play07:52

happened there i was like talking to

play07:53

point of johnny right let's watch that

play07:55

again crash bar

play07:56

let's get a bent rod and just slip it

play08:00

through and bam

play08:01

hit the door right absolutely works

play08:04

why because weather stripping is not a

play08:06

security device

play08:08

weather stripping is not the same thing

play08:10

as a plate or even a movable astragal of

play08:12

metal

play08:13

if that is just rubber or that little

play08:15

brush material

play08:16

if i can slip something through and

play08:18

smack on that crash bar they make

play08:20

specially designed tools

play08:22

just for this here's robert one our guys

play08:25

on our team reaching through with a

play08:26

reinforced tool

play08:27

hitting the crash bar bam

play08:31

exit paddles smaller target how many

play08:33

times do you see glass doors glass doors

play08:35

are wonderful because you can see

play08:36

exactly what you're hitting or not

play08:37

hitting

play08:38

but going back you can barely see it's a

play08:40

really dark photo you can't see it here

play08:43

easily you can see it in the video

play08:44

though sometimes

play08:46

is this daytime or night time

play08:49

this what is it it's not it's like three

play08:52

in the morning i know it's a little bit

play08:53

white out here but it's it's very dark

play08:54

out this is a low occupancy structure at

play08:56

night what could they have done and not

play08:58

violated code

play08:59

they could have set the deadbolt it's

play09:00

right [ __ ] there right

play09:03

well this tool is there's a tool that

play09:05

exists for this the idea of a deadbolt

play09:07

again for code many of these attacks as

play09:09

you all know like

play09:10

fire code and actually egress like

play09:13

restrictions and allowances

play09:14

you have to set up doors certain ways if

play09:17

you have a deadbolt it probably has a

play09:18

thumb turn on the inside

play09:20

this tool exists i have it in my room

play09:22

this is a thumb turn flipper

play09:24

you stick it through the door and you go

play09:26

boop

play09:29

absolutely that like these tools are out

play09:31

there man they are not expensive

play09:33

and again like here we have a nice

play09:36

this is a classic california office

play09:38

building why because it has

play09:40

frameless glass doors oh my god

play09:42

california where the weather is so nice

play09:44

you don't care about insulation

play09:45

frameless glass doors everywhere

play09:49

so yes reach through with the tool the

play09:50

hardest part was just getting it to stop

play09:53

slipping off the knob was so tiny but

play09:55

eventually

play09:56

sure enough you get it on there you twit

play09:58

it's just like a braided cable

play10:00

attached to a it's not a sophisticated

play10:03

tool right

play10:04

but eventually bam well that's open

play10:07

post office near where i live you can

play10:09

see like right on the other side of the

play10:10

door i'm not gonna go steal a bunch of

play10:12

mail or anything but the gap is huge you

play10:14

could get through there

play10:15

tesla dealership of course it's

play10:17

california why because frameless glass

play10:19

doors that's why

play10:21

middle of the night no one around i'm

play10:23

not saying i wanted to uh duplicate

play10:24

tiger team

play10:25

like steal a car but absolutely like

play10:28

frameless glass doors boom

play10:30

thumb turns that's the only thing

play10:32

preventing anyone from getting in here

play10:33

and the gap is like a half inch wide

play10:36

talk about another gap problem here's a

play10:39

locked door

play10:41

there's some noise and then dr tran

play10:44

comes through like ninja in a cloud of

play10:46

smoke

play10:47

what happened there many of you know

play10:48

this one already i hope

play10:50

this is a lab where we do a lot of

play10:51

prototyping and we just show like bobbik

play10:53

in the hat just showed ross

play10:55

and ross is like hey building owner evan

play10:57

come here i want to show you this thing

play10:58

i just learned so you'll see he's trying

play11:00

to do something with a tool up in the

play11:02

time

play11:02

bobbit says no reposition it a little

play11:04

bit out here and look through the glass

play11:06

you'll see the same thing you'll see

play11:08

this sort of

play11:08

cloud of vapor and all of a sudden this

play11:11

locked door

play11:12

is no longer locked yay

play11:15

well who knows what government there's a

play11:17

very restricted government tool that

play11:19

they're using

play11:19

i don't know if you can get it like talk

play11:21

to someone you know who's kind of spooky

play11:23

you can find out how to order this it

play11:25

comes with a one-page

play11:26

idiot proof government instruction

play11:28

manual that says hold tool like this

play11:30

so all you're doing if you invert one of

play11:32

these spray dusters

play11:33

you're boiling off that r134a

play11:36

essentially is what's in there

play11:37

and you're creating this cold gas cloud

play11:40

what's actually tripping

play11:42

many doors have sensors on the inside

play11:45

especially electronic lock doors

play11:47

they are called request to exit sensor

play11:49

if you have a system where you badge in

play11:51

but you don't have to badge out you just

play11:53

walk to the door and just open it

play11:55

you might not realize you have a request

play11:57

to exit sensor you have

play11:59

most of the time a simple passive

play12:01

thermal sensor

play12:02

it's not the only technology out there

play12:04

it's far and away the most common one

play12:07

and if you can get that sensor to trip

play12:09

in this case just by blowing a cloud of

play12:10

gas through the door

play12:12

the door unlocks these are old tricks

play12:15

you should know them

play12:16

dave if you saw his keynote this morning

play12:18

dave did he's a big

play12:19

you know vape guy he's a big ecig guy oh

play12:21

yes so he and ben 10 recorded this is

play12:24

one of the best videos ever of it

play12:26

so like i don't know if you sub ohm your

play12:28

coils or something because he makes this

play12:29

amazing cloud through there

play12:32

but he's just listening to hear that

play12:33

solenoid he's listening to hear it

play12:35

trigger

play12:36

and when he knows that electromagnet is

play12:37

done bam

play12:39

door's unlocked boom

play12:42

now unlocked yeah chris up here i think

play12:45

is the he was like hey dave you should

play12:47

try this on that door this is totally at

play12:48

we don't [ __ ] where we eat right yeah

play12:51

this was this this was the dirty derby

play12:52

class yeah

play12:53

yeah and like i think eventually people

play12:56

other people kept trying it until the

play12:57

point where there was staff

play12:58

in that because it's like a staff area

play13:00

and staff was like what's the smoke

play13:01

coming through the door are they like

play13:02

freaking out

play13:04

i don't smoke uh i do drink too much my

play13:07

wife caught this video once

play13:08

we're walking home from like a bar this

play13:10

was late at night this is a bank the

play13:12

bank is closed

play13:14

but i'm like well there is a wreck

play13:15

sensor up there and i had just kind of

play13:16

walked out of a bar with a drink

play13:20

so i just spit that through the door and

play13:22

like that works

play13:23

so yeah man passive infrared doesn't

play13:27

understand hot cold it just says

play13:29

different oh different must be a human

play13:31

this one up top here the honeywell

play13:34

passive infrared sensor

play13:35

i guarantee you've seen it or you've

play13:37

seen it rebranded and re-badged as

play13:39

somebody else's

play13:40

almost always white sometimes you see

play13:42

them in black or beige you will see that

play13:44

everywhere all over the place and why

play13:47

are they calibrated this way well you

play13:48

don't want someone with a bunch of boxes

play13:50

to like bang into the door and fall over

play13:52

these are tuned

play13:54

and the installers mount them in a way

play13:56

to get the most wide spectrum hit

play13:58

because they don't want to be called out

play13:59

repeatedly hey the rec sensor's not

play14:01

working it's not picking us up it's

play14:03

causing you know mary just fell down

play14:04

with her cane and her walker

play14:06

the installer doesn't want that

play14:07

installers and integrators want to

play14:09

always have these things trip so you're

play14:11

going to see that on a lot of doors

play14:13

because it's got really good coverage

play14:15

and you're going to always see it open

play14:16

the door what is this on the bottom

play14:18

though

play14:19

that's your solution ge is the only one

play14:21

i've ever seen that

play14:22

reasonably brings to market a dual

play14:24

technology rec sensor

play14:26

yes it does passive infrared it also

play14:28

does microwave radar

play14:30

so it has to see some temperature change

play14:33

and it also has to see something

play14:35

vaguely human-sized coming vaguely

play14:37

toward the door

play14:39

we knew like um tr a hacktrust hector

play14:42

zo9val

play14:43

val actually she'll put balloons through

play14:45

doors and blow them up

play14:46

and let them go because the old trick

play14:48

with the pirs you usually just put them

play14:50

further away from the door you just put

play14:52

them down the hall

play14:53

and you know if i'm trying to gas the

play14:55

dog i'm not hitting it so her solution

play14:56

for that was like

play14:58

like send balloons like blowing down the

play15:00

hall to try to trip them

play15:02

ge's product will stop that i don't work

play15:04

for ge i'm not here shilling for like

play15:06

mubics and his buddies moving still with

play15:07

ge i don't know

play15:08

no all right but yeah it's the only

play15:11

dual technology sensor that i've ever

play15:13

seen that's good for this

play15:16

also code let's talk about door handles

play15:19

when's the last time you've seen a door

play15:20

knob like in an office

play15:22

you don't because if someone like has

play15:25

reduced grip and tactile function or

play15:27

what if someone doesn't have a hand

play15:28

they need to be able to get in and out

play15:29

of the building especially in

play15:30

emergencies

play15:32

lever style door handles are are the

play15:34

norm now

play15:35

well inside i mean you see the front one

play15:37

facing me that's locked and has a

play15:39

you know shitty little hid prox reader

play15:42

on the inside there's also

play15:43

a lever handle which many times that's

play15:45

going to be the case

play15:48

there are tools like this that exist

play15:50

this is an under door tool

play15:51

i'm doing a little show with a guy named

play15:53

tyler gray he's like well show me this

play15:54

tool and his cameraman is like how would

play15:56

you get in here

play15:57

and they expected me to do something at

play15:58

the door they didn't realize i just

play16:00

knelt down

play16:01

and kind of banged the door open and

play16:03

actually it's one of the cameraman was

play16:04

like

play16:05

can you do that like again like slower

play16:07

that was way too fast i didn't

play16:08

understand what was happening

play16:10

well these are actual tools that we use

play16:12

on jobs

play16:13

what we're doing with this tool it's

play16:14

called an under door tool

play16:16

we're reaching a rod under the door and

play16:19

because

play16:20

modern doors have those lever style

play16:22

handles

play16:23

they're really really trivial to grab

play16:26

that handle

play16:26

and hit it on the inside i'll show you a

play16:29

picture from flipped around in a second

play16:30

this is robert

play16:31

middle of the night getting into a

play16:33

server room you know people see this

play16:35

video and they thought they see him

play16:36

crouched down like oh he's going to

play16:37

unscrew like with a multi-tool to get

play16:39

through that crawl through the grate no

play16:40

he's not

play16:40

he's going to lean his head into the

play16:42

door and just push it open because on

play16:43

the inside

play16:44

we're just swinging a rod pulling down

play16:47

on a line

play16:48

and yanking this handle absolutely works

play16:52

because when's the last time you've been

play16:53

in the server room and had to badge out

play16:55

some some real secure facilities maybe

play16:58

most of the time you hit the handle and

play16:59

you leave

play17:00

there are solutions for this there are

play17:02

what are called dynamic

play17:04

door bottoms this little animation

play17:07

shows you a black plunger if this black

play17:09

plunger gets pushed in

play17:11

what happens you'll see this bottom bar

play17:13

drops down

play17:15

so when the door shuts that bar drops

play17:17

down now this is not a security product

play17:19

this is like a heating and cooling

play17:20

insulation product but the same

play17:22

principle applies

play17:24

to much more robust models so a company

play17:26

called pemco p-e-m-k-o pemco makes the

play17:29

door bottom now they're sold by assa

play17:31

abloy big contoured floor plate

play17:34

interlocks in this metal bar and unless

play17:36

that plunger is

play17:37

relieved of its pressure that door

play17:39

bottom is dropped down you're not

play17:40

getting a tool

play17:41

underneath the door now you might get

play17:44

something

play17:44

over the door this is a video from utah

play17:48

a buddy of ours named the infosec pope

play17:50

he loves demoing this

play17:51

all he uses is 35 millimeter film for

play17:54

the young kids of the room film

play17:56

is what we used to take photographs with

play17:59

but he literally just feeds a bow of

play18:01

film over the door

play18:03

walks it over to the handle and then

play18:05

pulls and

play18:06

you might not do this as a user but if

play18:08

you pull up on a handle it's usually

play18:10

going to open the door

play18:11

so pull bam that door is open and i i

play18:14

mean pemko makes the door bottom i've

play18:16

never seen anyone sell the door topper

play18:18

so like what do you actually do to

play18:19

prevent this problem well

play18:21

consider a shroud i was one time

play18:25

working an underdoor tool in this one

play18:26

job and i'm like

play18:28

[ __ ] [ __ ] god damn it [ __ ] i've like

play18:30

radioed to robert like robert get in

play18:32

here can you and robert's trying he's

play18:33

like son of a [ __ ]

play18:35

bobbitt comes around from another

play18:36

building and he throws a boar scope

play18:38

under the door

play18:39

and we're like oh crap what is that and

play18:41

eventually like with the borescope we

play18:42

could kind of see

play18:43

and shove the wiggle the tool we got it

play18:45

open and i asked the client i was like

play18:48

man that one door gave us freaking hell

play18:50

where did you get these things that you

play18:52

installed in the server room

play18:53

and they're like ah they were like on

play18:55

the building when we got here i don't

play18:56

know what that this

play18:57

used to be like a storeroom or something

play18:59

these are like ingrainger catalogs these

play19:01

are so

play19:02

carts don't crash into door handles when

play19:04

you they're just shrouds for like

play19:05

protecting the door handle

play19:07

not for like security they're just so

play19:08

you don't bang into it with stuff

play19:11

brilliant no money solution if you've

play19:13

ever been in a hotel

play19:14

and you've seen the door handle mounted

play19:16

like down who's seen this before

play19:19

hotels know about this man hotels have

play19:21

had break-ins with under door tools

play19:23

they mount these handles down for a

play19:24

reason this is one of my favorite

play19:26

pictures render man sent me this

play19:28

and i've started to see hotels and other

play19:31

doors with these like little clips

play19:33

i was like i stayed in a hotel once for

play19:35

like a week in san francisco on this job

play19:37

and

play19:37

you know talking to the staff late at

play19:39

night hanging out [ __ ] and i'm like

play19:40

hey so i got i got to ask you

play19:43

the freaking clip thing that looks very

play19:45

out of place on the doors

play19:47

is that like un under door tools and the

play19:49

guy was like oh yeah

play19:50

we have people breaking into rooms and

play19:52

stuff we i was like i

play19:54

gotta know where you get these my

play19:55

clients could rip because i could that

play19:57

would be a [ __ ] nightmare trying to

play19:58

get an underdoor over door attack

play20:00

he's like well you know the closet in

play20:03

your bedroom with the the sliding doors

play20:05

yeah these are just those little feet

play20:07

that like you put in the carpet on slide

play20:09

like

play20:09

literally at home depot four dollars if

play20:12

you don't care that it looks a little

play20:13

weird

play20:14

put these on your server room door man

play20:16

it will completely frustrate the hell

play20:17

out of me

play20:19

so i love this kind of thinking i love

play20:22

weird and hilarious ways of getting in

play20:24

and i've got just i just i'm guessing

play20:26

this crowd i added some funny [ __ ] right

play20:28

like

play20:30

stealing keys you think we're above

play20:32

steel just outright stealing stuff

play20:34

this was the security cart on a facility

play20:36

once

play20:37

we just found it and i was on a job with

play20:39

a guy i was actually subbed in on a job

play20:41

had every

play20:41

f and key like everything all over the

play20:44

building

play20:45

and of course like yes we still i'm not

play20:47

gonna i guess we're allowed to say jay

play20:49

wouldn't mind i'm not gonna say who it

play20:50

was but like eventually we just stole

play20:51

the cart and just drove it around

play20:53

because if you get to that point i mean

play20:55

you don't want jobs where you're like

play20:56

you've gotten everything

play20:57

and there's still time and you call the

play20:59

client and you're like so we're

play21:01

in every they haven't stopped us do you

play21:02

want to start doing stupid [ __ ]

play21:04

and the client's like yeah just push it

play21:06

so yeah we literally took this little

play21:07

golf carty thing and drove it around the

play21:09

parking lot until it ran out of juice

play21:11

and we're like puttering back at like no

play21:13

miles per hour just to try to get it

play21:15

back to where we left it

play21:16

so it looked really and we're not in

play21:18

uniform no one stopped us

play21:20

but i love that like all the keys were

play21:22

there

play21:24

lock boxes oh my god talk about stealing

play21:26

keys stealing keys from a lock box

play21:29

these show up on a ton of buildings

play21:31

possibly your buildings

play21:32

if you have con if you have

play21:33

infrastructure like cell towers and

play21:36

stuff on high buildings

play21:37

and other contractors are coming in to

play21:39

service that gear

play21:40

i bet you there's lock boxes somewhere

play21:42

that you might not even know about

play21:44

tunnelers one two three four five six

play21:46

seven

play21:47

different people have to get into this

play21:48

building i can't even think of that many

play21:51

cable and wireless providers

play21:52

i don't know what's going on here

play21:56

these kind of boxes oh my god telephony

play21:58

boxes right

play22:00

this i just throw in because mostly you

play22:02

know

play22:03

chris knows this guy in this slide you

play22:04

guys dennis like dennis is a good cat

play22:07

right dennis is standing next to

play22:08

a lanier access control box i am

play22:11

standing next to another brand called

play22:12

door king

play22:13

let's talk about these two big players

play22:15

in the industry just because this is

play22:17

stuff that's not usually in my slide

play22:18

deck

play22:19

i just had to throw you some fun [ __ ]

play22:20

right most of the stuff that cracks me

play22:22

up when it comes to stealing the key

play22:25

like i don't even think it counts as

play22:26

stealing in the instance of like linear

play22:28

you got this nice lit up keypad you got

play22:30

the little w grill

play22:32

linear boxes all have the same key it

play22:34

used to be called the a126 key it's not

play22:37

really it's the 222343 key but

play22:39

if you google like linear key or linear

play22:42

two two two three four three or linear

play22:43

a126

play22:45

you'll get this key it's the same key on

play22:47

all the freaking panels

play22:49

it's not a restricted key or an

play22:51

expensive key

play22:52

but it lets you do crap like this so

play22:55

here we have a locked door

play22:57

now my wife is going to enter through a

play22:58

different technique

play23:00

beep whoops this is actually the

play23:02

apartment where we stuck marcus hutchins

play23:04

while he was waiting for trial so we

play23:05

only got one key fob we cloned it to her

play23:07

hand so she could come and go and have

play23:09

an extra key

play23:10

but now i don't have a you know the key

play23:12

fob the door is locked

play23:14

so what can i do well linear boxes are

play23:16

all key to like

play23:18

a126 key there's a little momentary

play23:20

switch and just boom flip the relay

play23:22

so that works same key on all these

play23:26

boxes man

play23:27

absolutely so yeah door king the one i'm

play23:31

standing next to here

play23:32

i personally think door king has even

play23:34

more market penetration

play23:36

do they have the same key yes they do

play23:38

the 16 120 key it's been the door king

play23:40

key i think since 1992

play23:42

and it's never like i go to trade shows

play23:45

i go to like the trade shows with all

play23:46

this gear and the door king booth is

play23:48

huge

play23:48

and i take i just walk around like use

play23:50

my key just open stuff and just walk

play23:52

away

play23:52

every few hours just walk by the boot

play23:54

this was like a giant parking gate

play23:56

arm like a huge crash barrier thing and

play23:59

it's again

play23:59

16 120 key they're all the same key

play24:03

door king systems let's let's dive into

play24:05

this for a moment here we got a lot

play24:06

going on here

play24:07

all right you can always always always

play24:10

tell a door king system

play24:12

boom boom boom a-z call those three huge

play24:14

buttons

play24:15

you'll spot them a mile away now there's

play24:17

not just that

play24:18

we have a we clearly have hid procs

play24:20

going on here we'll talk about

play24:21

electronic credentials

play24:23

but let's get right into it all right

play24:24

let's use our 16 120 key

play24:26

look at all these electronicals well

play24:28

there's a lot of stuff going on in there

play24:30

we got a big bank of connections here

play24:33

what's going on in this terminal block

play24:34

well punch in doorking manual.pete file

play24:37

type pdf

play24:38

in google you get a big manual with this

play24:41

on one of the pages

play24:42

what's the most giant writing you see on

play24:44

this page relay one relay two those are

play24:47

the door relays right there

play24:48

they're just dry contacts on the

play24:50

freaking panel

play24:52

so if you have like door relay one

play24:54

either normally open or normally closed

play24:56

you can just bridge that circuit and

play24:58

like boom

play24:59

fire the relay open the door fire relay

play25:02

2 open that door

play25:03

so in this case do you see how this is

play25:06

wired by the way you can see one common

play25:08

and you can see what normally open so

play25:11

that tells you this is probably a

play25:12

solenoid powered door lock so

play25:14

normally there's no power put power just

play25:16

literally by bridging that with a piece

play25:18

of wire

play25:18

the door suddenly is open there's

play25:21

another

play25:22

useful feature however if you don't want

play25:23

to like carry around wire and i'll show

play25:25

you what i carry around

play25:26

way up top let's look at this psw

play25:29

function what is psw

play25:30

it's postal switch a closure between

play25:33

these terminals and the common

play25:34

will cause whatever relays are set up

play25:36

however they're set up

play25:37

to fire how does this normally work in

play25:40

fact is the postal switch wired up

play25:42

yes it is it's right there a little

play25:44

white and a little blue a little white

play25:46

and blue that come down you've got these

play25:47

two beam connectors and they come

play25:49

somewhere else let's look all the way

play25:50

down in the front

play25:52

amazingly low tech this is the postal

play25:55

switch right here

play25:56

it's literally just a momentary and on

play25:59

the front of the panel you'll see they

play26:00

they have these knockouts that you can

play26:02

just bang out a piece of metal and

play26:03

install your own lock

play26:05

and the tail piece of that lock just

play26:07

comes around and hits the momentary

play26:08

switch many

play26:10

many door kings are installed this way

play26:13

so we got a locked door now of course

play26:16

you know we could clone the hid prox we

play26:18

could install a sniffer or whatever we

play26:19

want

play26:20

we don't really care what lock they're

play26:22

using for the postal switch

play26:24

because it could be a good lock it could

play26:25

be a bad lock i don't give a damn

play26:26

because i have the 16 120 key oh no

play26:28

oh laptop don't do things that laptops

play26:31

sometimes do

play26:32

you're killing me who's phoning my

play26:34

laptop

play26:36

so ultimately here hopefully we can get

play26:38

it to play because it's really hilarious

play26:40

this is outside of like

play26:41

romer's apartment i think we're in town

play26:43

for band practice and

play26:45

you know we called him up he wasn't

play26:46

answering like try shaggy he wasn't

play26:48

answering

play26:48

and i was like do you want me to just

play26:50

let us in so you know we walked inside

play26:51

so

play26:52

you know we have this postal switch

play26:54

let's see if my 16 120 key works if

play26:56

our video plays nice here we go

play26:59

momentary switch

play27:01

fires doors unlocked how many buildings

play27:05

have these on them

play27:06

and people don't realize many times it's

play27:08

not like your office right it might just

play27:10

be the front

play27:11

vestibule but if i can get in if i can

play27:13

leverage this access in

play27:15

and find a way then i get the next step

play27:17

i get the next step i ride the elevator

play27:18

etc if you're keeping keys like on you

play27:21

oh my god

play27:22

there's a whole talk i did with howard

play27:24

payne the ch-751 is like the everything

play27:27

key

play27:28

it's the most common key in this country

play27:31

for

play27:31

all kind of dumb dumb stuff every little

play27:34

wafer lock

play27:35

everything like steel toilet paper i

play27:36

don't know what you're doing if you're

play27:38

you know you

play27:38

live in a trailer you need toilet paper

play27:40

i'll steal it from this hotel whatever

play27:41

like the ch-751 my favorite story was we

play27:44

were on a job

play27:45

we got into an office like a room in

play27:48

this office building and there were all

play27:49

these filing cabinets on the wall

play27:51

and we're like i don't want to pick

play27:53

every one of these open

play27:54

to see which one has the valuable [ __ ]

play27:56

but let's try a ch751

play27:58

totally worked and it turns out every

play28:01

one of them had valuable

play28:02

[ __ ] it was like their hr archives going

play28:04

back

play28:05

years the great part and i just added

play28:07

this story because kjoe gave his talk

play28:09

and he talked about finding the exploit

play28:11

from the last job you were on like still

play28:13

on the server

play28:14

we found this we showed the client we're

play28:16

like boy these are really terrible

play28:18

filing cabinets and you're leaving this

play28:20

around in a room that we just waltzed in

play28:22

so the client was like oh my god we'll

play28:23

get on that we were hired seven months

play28:25

later to a different office

play28:27

and we got into like another room and

play28:29

we're like whoa look at all these

play28:30

falling cabinets

play28:31

and we open them we're like are these

play28:32

the same [ __ ]

play28:34

well these are the same filing cabinets

play28:35

they had moved them from one office

play28:38

to another office but didn't actually

play28:40

change them so we had the same finding

play28:42

just in a different state

play28:44

ch 751 all day long for maximum low

play28:47

larity in the key to like

play28:49

space stick 1284x

play28:52

into your google engine right look some

play28:55

look at some image searches you're

play28:56

seeing a lot of the same

play28:57

vehicle here the 1284x is the ford motor

play29:00

company's fleet key

play29:02

the number of crown vics and excursions

play29:05

and explorers in this country

play29:06

that are keyed alike to 1284x tons of

play29:10

police departments in this country

play29:12

will all and not even knowing it that

play29:14

all of their cruisers

play29:15

are the same key and what's the most

play29:16

common use of a

play29:18

crown vic after it's got enough use

play29:20

hours and they have to kick it out of

play29:21

the force

play29:22

taxis they auction them off and maybe

play29:24

become taxis there are cities in this

play29:26

country

play29:26

where the entire taxi fleet is key to

play29:29

like and it's key to like to the entire

play29:30

police fleet

play29:32

1284x is not a restricted key it's not a

play29:34

special like

play29:35

this is the paper still attached to it

play29:37

from home depot you get a 1284x take it

play29:39

to home depot cut as many as you like

play29:42

yes it will open the doors yes it will

play29:44

open the glove box

play29:45

yes it will open the trunk nothing

play29:47

interesting in a cop's trunk right

play29:49

and it's not a chipped key it's not a

play29:51

key lock it's nothing like that yes

play29:52

it'll start the freaking car

play29:54

so if you have cop friends and we have

play29:57

plenty

play29:58

show them the 1284x if you get your

play30:00

hands on one it might pop their eyes out

play30:03

if you're curious my like everyday

play30:04

keyring that sometimes people will see

play30:06

me with

play30:07

they say what do you actually have in

play30:08

your pocket all the time well i have an

play30:09

elevator key the most common elevator

play30:11

key on me at all times i have the two

play30:13

most common filing cabinet keys the c47

play30:15

c41

play30:16

c415a ch751 i definitely carry that

play30:20

1284x because it's funny

play30:22

right i have a couple jigglers because

play30:24

why not little

play30:25

tiny jigglers that we make if i can't

play30:27

get through a simple shitty lock

play30:29

this is my wire bridge when i'm

play30:31

attacking door king in other boxes it's

play30:33

just a paper clip

play30:34

that i burned the insulation off the

play30:35

tips and looped it around

play30:38

door king key if you didn't get it

play30:39

earlier is the 16 120

play30:41

linear the 222343 which is sometimes

play30:44

called a126

play30:46

and a cuff key that is that that's my

play30:49

smash right there that's like deviant's

play30:50

devious key ring

play30:52

giving you pearls here i don't think

play30:53

i've ever shown the slide before outside

play30:55

of our training so woohoo

play30:56

there you go because i love you john

play30:58

strand and everyone else who invited me

play30:59

here

play31:02

if you are not an electronic person in

play31:04

fact you know

play31:05

we were talking about this earlier about

play31:06

where i hire people from our team

play31:09

we either have people that came from the

play31:11

electronic digital world

play31:12

and we sort of train them up on physical

play31:14

or we've pulled people who are door

play31:16

kickers they're just cops and other

play31:17

people

play31:18

that were like hey want to make a better

play31:19

salary and not be evil come come work

play31:21

for us and like

play31:21

we have to train those people on

play31:23

electronic learn some

play31:25

things about electronic access controls

play31:27

learn a little bit about badge systems

play31:30

it's not that hard to get you spun up we

play31:32

can get you spun up in a day or two

play31:34

on basic cloning and sniffing and a lot

play31:37

of credential stuff

play31:38

the the fact that we take long-range

play31:40

readers and weaponize them bobbik our

play31:42

electronics dude

play31:43

changes the guts packages up a

play31:45

self-contained power supply

play31:47

power on this reader let it sit in a bag

play31:50

you know the the idea of like very mr

play31:52

robotish kind of stuff right if you've

play31:53

seen that

play31:54

credential grabbing scene this is real

play31:56

this is about 18 inches away

play31:58

credential grab out of someone's pocket

play32:00

because with a nice antenna and a good

play32:02

power supply

play32:03

inside that backpack that reader is

play32:05

going to grab that card and it's going

play32:06

to work

play32:07

we can talk about that later if you want

play32:08

we can talk about how if you get the

play32:10

reader off the wall

play32:11

you can install a sniffer on the

play32:13

backside of the reader

play32:14

and you can sniff replay get credentials

play32:17

that way there's a whole world out there

play32:19

and it's not

play32:20

hard if you've never done any kind of

play32:22

digital electronic work like this if you

play32:24

are just a door buster

play32:26

this is within your grasp and i

play32:27

encourage you to get kind of

play32:28

cross-trained like that

play32:31

a little story time for you now new

play32:33

stuff i promised as i tweeted earlier

play32:34

it's not i've given

play32:35

versions of this talk in the past this

play32:37

is all this is all new

play32:39

because war stories are great and we've

play32:40

heard about them from other speakers

play32:42

so let me give you a few good ones most

play32:44

of which if you had to distill this down

play32:46

the lesson is just be confident and look

play32:49

like you belong

play32:50

if you've never seen this footage here

play32:51

this is a robbery of a walmart

play32:54

where a guy came in and said oh i'm here

play32:55

from loomis i'm here for the the pickup

play32:57

you know i'm the armed guard he's not

play32:59

he's not the armed car guy he's wearing

play33:01

a runner's vest

play33:02

with like you know weights and the

play33:03

tactical pants and his hats down i think

play33:05

they found out later he had an airsoft

play33:06

pistol

play33:07

and he took 75 he's i'm here from loomis

play33:11

no he got into chevy lumina

play33:12

and drove away this dude another guy

play33:16

keep your hat down and don't bother

play33:17

anybody look i'm just here from you know

play33:19

your beverage services i'm stocking your

play33:21

shelves

play33:22

no you're not this guy hit seven stores

play33:24

in one weekend in alabama

play33:26

he's just stealing beer he just went in

play33:28

with a cart

play33:29

loaded the thing up and just freaking

play33:31

left

play33:33

look like you know what you're doing and

play33:35

people will tend to believe that [ __ ]

play33:37

so the elevator repair story all right

play33:41

we got into a building it was an

play33:43

interconnect we we gassed off you know a

play33:45

wreck sensor because again

play33:46

you could see it on the ceiling

play33:47

honeywell pir boom

play33:50

gas the rec sensor get through okay

play33:52

we're in the building

play33:54

now we've got to go if you like where

play33:56

come in we're the first time you get in

play33:57

you get that like adrenaline rush

play33:59

and i'm with somebody on this other job

play34:00

another company we're partnered with

play34:02

and this guy's like man what do we where

play34:04

do we go what do we do i was like calm

play34:06

down i got an idea let's come walk

play34:07

find the nearest elevator we just got in

play34:09

an elevator

play34:11

okay why because i mocked myself up i'm

play34:14

here from i've got my little otis badge

play34:16

i've got my clipboard i'm an elevator

play34:17

repair technician why not

play34:19

you want another like great tip from me

play34:21

to you this is your cover story for

play34:23

being any elevator repair guy ever

play34:25

have a stupid clipboard and learn these

play34:27

three steps

play34:29

you press that e phone somebody picks up

play34:32

it's many times it's a computer if it's

play34:34

a human

play34:35

hello this is a test of the emergency

play34:38

phone in this elevator

play34:40

step two can you hear me clearly right

play34:43

now

play34:44

step three where am i calling from

play34:47

and that last one flummoxes the hell out

play34:49

of people a lot of the time because they

play34:50

should be able to know where you are in

play34:52

event of emergency

play34:53

you will sound like a legit elevator

play34:55

tech if you do that you're not really

play34:56

breaking any laws you're not causing any

play34:58

harm to the elevator

play34:59

you can just sit there and just try

play35:01

elevator you know like try elevator

play35:02

phones and

play35:03

just to get this dude to calm down i was

play35:05

like hey just relax let's try some

play35:06

e-phones man

play35:07

so we're just being the elevator tax and

play35:09

it turns out

play35:10

the third question really flummoxed

play35:12

somebody because it wasn't like a

play35:13

service that went out to otis line

play35:15

it was the the front desk and we wound

play35:17

up consistently hitting the front desk

play35:19

and like

play35:20

oh is this another one of those elevator

play35:21

tests yeah i i don't know where you are

play35:24

though it just says extension 39

play35:26

and i'm like so you can't tell me where

play35:28

i'm calling from

play35:29

like i mean you're in an elevator i'm

play35:31

like

play35:32

okay sir i'm gonna have to write down

play35:34

that you uh don't know where i'm calling

play35:35

from and it got them all panicked right

play35:38

turns out the security guard was so

play35:40

flummoxed by not knowing where the

play35:42

elevator emergency was i'm like don't

play35:43

worry so there's just

play35:44

a test you're not at fault here we just

play35:46

we just have to put this in the notes

play35:47

that came into play later so while we're

play35:50

in the elevator

play35:51

the guy says to me he's like okay so all

play35:53

we got to do is get the pwn plug and

play35:54

deploy it

play35:55

and oh [ __ ] oh man i didn't grab it i'm

play35:58

like oh you didn't grab the phone plug

play36:00

well you know the hotel's like 10

play36:02

minutes away just drive back and get it

play36:04

i'll stay in the building and i'll let

play36:06

you back in he's like

play36:07

uh okay that sounds good you're gonna

play36:09

look okay i'm like dude i got my metal

play36:11

clipboard like come on

play36:12

who's going to mess up metal clipboard

play36:14

is great because you can hide a bunch of

play36:15

tulle and gear in it and like

play36:17

all your stuff's in there but the better

play36:19

thing about the elevator story is if you

play36:22

actually watch the elevator hacking talk

play36:23

we have a lot of keys that do things

play36:25

well my partner was back at the hotel

play36:27

which was not going well

play36:28

he was like hey man i got some delays

play36:30

here i'm like all right i'll just hang

play36:31

out in an elevator so i just disabled an

play36:33

elevator with my keys

play36:34

i'm just in the elevator just hanging

play36:36

out nothing i'm like reading twitter and

play36:38

stuff

play36:39

occasionally asking like hey how's that

play36:41

going at the hotel it turns out what

play36:42

happened is his usb keyboard wasn't

play36:44

playing nice

play36:45

with the phone plug he was hooked up to

play36:47

the hotel tv

play36:48

and he couldn't get the so he had to use

play36:50

on-screen keyboard to like

play36:51

set up all the scripts and it was taking

play36:54

forever

play36:55

and i'm like dude that's fine i got

play36:56

twitter i'm fine i'm just sitting in an

play36:58

elevator

play36:59

until i almost had a heart attack

play37:01

because i thought i heard someone

play37:02

banging

play37:04

on the elevator door because it's like

play37:06

you're camping in the woods like

play37:07

everything sounds loud in the woods when

play37:08

you're asleep

play37:09

in the i thought someone was pounding on

play37:11

the elevator i was like oh my god

play37:12

there's is there like a camera i didn't

play37:14

see

play37:14

is there a security trying to kick their

play37:16

way in i'm like no calm down

play37:18

it's it's 5 5 15. the cleaners are here

play37:21

they're probably like

play37:22

windexing the fingerprints off of the

play37:24

hoistway doors like

play37:25

all right calm down eventually the guy

play37:28

comes back

play37:28

and he's like all right let me in like

play37:30

okay i go to let it it turns out it

play37:31

wasn't the cleaners

play37:33

turns out security had come by the

play37:34

elevator not because they thought i was

play37:36

in there

play37:37

i had been in there so long that they

play37:39

had stuck

play37:40

a sign on the elevator that said

play37:43

elevator out of order

play37:45

do not use this elevator use other side

play37:46

of building which was great because when

play37:48

we came back in my buddy and i now we're

play37:50

the only people in the damn building

play37:51

security came down a hall of sauce saw

play37:54

my otis badge

play37:55

and went wow you got here fast

play37:59

and i was like oh yeah i got that uh you

play38:01

got that otis elite care service so like

play38:02

they dispatched us out here

play38:04

i'm you know doing things with keys that

play38:06

because clearly the elevator's working

play38:07

now that i turned it back on

play38:08

but he was so thrilled he's like were

play38:10

you guys doing that elevator test

play38:12

earlier i was like

play38:13

no that was the other team but i heard

play38:14

you had some problems but

play38:16

you know what the elevator dispatcher is

play38:18

in this room can you let me in this room

play38:20

and sir sure enough the guard just like

play38:21

led us everywhere we wanted to go

play38:23

because you know who wouldn't want their

play38:24

elevators to run right right i'm the i'm

play38:26

the helpful elevator guy

play38:28

i'm getting the light on time i'll give

play38:29

you i'll give you one more story i got a

play38:31

couple more stories here

play38:32

but how much time do you actually have

play38:34

five or ten minutes five

play38:36

we can do another story and a half and

play38:37

five so the armed guard story is it's a

play38:40

good story

play38:42

most guards a crap shoot a lot of guards

play38:45

are under trained a lot of guards are

play38:47

third party

play38:48

this was a guard desk that literally had

play38:49

no one at it and one time i just sat

play38:51

there i actually took the binder of keys

play38:53

and key cards and just kind of like spun

play38:55

around in the chair

play38:56

just waiting for a guard to come up to

play38:58

see i wanted to like know what the hell

play38:59

they would say

play39:00

and it took so long that i just got up

play39:02

and left like the guard literally never

play39:03

showed

play39:05

arm guards are a different story they're

play39:07

a little more mastered

play39:08

they're a little better with interaction

play39:10

and they're going to be more cautious

play39:11

now this was an instance where we needed

play39:13

electronic credentials

play39:14

we really wanted to get in using a badge

play39:17

and all the employees like we couldn't

play39:18

get close to the employees at all they

play39:20

were using a separate entrance so like

play39:21

the vestibule was the only place we

play39:22

could get in

play39:24

and during the day the only people in

play39:25

the vestibule were the armed guards this

play39:26

was a private development space

play39:28

well we know how to do credential

play39:31

cloning right we have our gear we have

play39:32

our long range reader

play39:34

that you saw earlier right shove that in

play39:36

a backpack once you power it on

play39:38

shove that oh we already saw this video

play39:39

shove that in a backpack

play39:41

get somebody to go in just try to get

play39:42

close enough you saw 18 inches or so

play39:46

so when we said who's going to go in

play39:47

right well what does every guard

play39:49

especially armed guards kind of wish

play39:51

they want to be or maybe they're trying

play39:53

to be

play39:54

they're trying to be cops right sending

play39:56

a cop like rob's on our team rob used to

play39:58

be a cop we're like just get in there

play39:59

and cop it up man just talk about cop

play40:01

stuff

play40:02

so he goes in bobik is in the back seat

play40:05

of a rental car

play40:06

in the parking lot like remote onto the

play40:08

reader he's like trying to check the

play40:09

status of it and goes out of range

play40:11

because robert goes in all the way to

play40:13

the vestibule so bobbix like man i

play40:15

really hope

play40:15

i really hope that reader is getting

play40:17

some credentials and robert's trying

play40:19

everything robert's like getting close

play40:20

but they're armed guards

play40:21

so they keep blading off every time he

play40:24

gets near them

play40:25

at one point he put it like his bag on a

play40:27

counter and he was like asking the guard

play40:29

he's like hey is this a good restaurant

play40:30

i started on yelp trying to get the

play40:31

guard to like lean over the counter

play40:33

wouldn't do it

play40:34

so he keeps trying he keeps trying he

play40:36

keeps trying getting nothing

play40:37

finally at the end of the interview he's

play40:39

telling cop stories right so he's

play40:40

friendly with him

play40:41

he's like all right well i gotta if he

play40:43

stays any longer he's like this is just

play40:44

weird

play40:45

it's like all right fellas i gotta i

play40:46

gotta go all right take it easy man it's

play40:48

nice meeting you

play40:48

and the last guard he just [ __ ]

play40:51

surprise hugs

play40:52

him and like very very kennedy he's like

play40:54

make it a little weird make a little

play40:55

weird all right brother all right

play40:58

and gets out of there in the car

play41:01

bobik is in the back seat like what did

play41:03

you do i was

play41:04

dying back here it's like well here

play41:05

check check the logs man

play41:07

bobby check dumps the creds he's like

play41:09

you were in there

play41:10

47 minutes and you got one read

play41:15

and that was it but then who are we

play41:17

we're the armed guard at that point

play41:19

so getting you never know exactly what's

play41:22

going to work out for you

play41:23

in terms of getting in i had one other

play41:26

story about you know find me in the bar

play41:27

i'll tell you about uh

play41:29

about some other stuff what i really

play41:30

wanted to get to i'm going to quiz you

play41:32

at the end here we got a little we got a

play41:33

little q

play41:34

a and i promise i'm wrapping it up right

play41:36

so this is i hope you're paying

play41:37

attention right

play41:38

what kind of unit is this here door king

play41:41

why'd you know that

play41:43

three [ __ ] huge buttons who remembers

play41:44

the door king key

play41:47

16 120 key buy it buy it online

play41:50

what kind of unit is this it's one of

play41:52

the ones we talked about has a little

play41:53

recess

play41:53

lit keypad linear linear absolutely

play41:56

what's the linear key

play41:58

a126 or technically 222343

play42:02

blurry dark picture but who is it door

play42:05

king exactly three buttons

play42:07

you can do this [ __ ] on google street

play42:09

view

play42:11

we got a building here let's zoom on in

play42:13

you can't see it clearly but you see a

play42:15

recessed lit keypad what do you got

play42:17

you got a linear a126 key absolutely

play42:20

let's look at this john over here all

play42:21

right

play42:22

can't see it from here but let's zoom in

play42:23

and google what do you see three giant

play42:25

freaking buttons door king

play42:28

absolutely door king we got a lot going

play42:31

on here let's let's talk about this all

play42:32

right first of all we clearly got a door

play42:34

king system

play42:35

we're using what key is the door king

play42:37

key

play42:38

16 120 go buy one they're also using hit

play42:42

old school [ __ ] prehistoric hid procs

play42:44

so prox card two

play42:45

you know they're using cloneable

play42:46

credentials you know you could sniff the

play42:48

back end of this

play42:49

because you could pop that circuit board

play42:50

open easily they've got a ton of key

play42:52

boxes this was for deliveries

play42:54

i don't know if that was a ch-751 but

play42:56

i'm sure i tried it in there

play42:58

little freaking you know kitty access

play43:00

point in here what is what is this one

play43:02

turns out it's also a key box it's just

play43:03

a different key box so we have multiple

play43:06

key boxes

play43:07

we have a lock that we know the key for

play43:08

we have a clone a clonable cred

play43:10

there's one more thing that you can also

play43:12

see in this picture

play43:14

can anyone tell what i what i would look

play43:15

for through the windows maybe

play43:17

you could tell what elevator fixtures

play43:18

they have so i know what elevator keys

play43:20

i'm gonna need

play43:21

so i can prep my story and i can bomb in

play43:23

there

play43:24

all equipped and ready to rock so keep

play43:27

these kind of attacks in mind

play43:28

keep physical side in mind try it out if

play43:31

you think it's all about lock picking

play43:33

you're not exactly right

play43:34

most of the time we're just doing dumb

play43:36

stuff to bypass our way in

play43:38

but i love sharing this and i love

play43:40

trying to give a little hope you got a

play43:41

couple of pearls in this one

play43:43

to make your jobs easier and your life

play43:44

better and my job harder

play43:46

because that's in the end that's a win

play43:47

for me like i like being the guy in the

play43:49

server room

play43:50

but i also like telling people what they

play43:51

did right and a lot of it's not hard to

play43:53

do

play43:54

so thank you very much for listening and

play43:55

i hope you enjoyed this

play44:16

you

Rate This

5.0 / 5 (0 votes)

Ähnliche Tags
Physical SecurityLock PickingPenetration TestingSecurity HackingDoor Entry SystemsCovert EntryKey ManipulationElevator HackingCredential CloningSecurity Awareness
Benötigen Sie eine Zusammenfassung auf Englisch?