[00:39.830 --> 00:43.710] Alrighty, good afternoon everybody and welcome to A New HOPE. [00:44.070 --> 00:57.330] Before we get started I ask that you please silence your cell phones as it does mess with the AV equipment and that you please wear your mask fully over your nose and mouth for the duration of your time indoors on any of the A New HOPE facilities. [00:58.790 --> 01:10.670] So vulnerability assessments have a bunch of under-the-door tools, latch-based attacks, and climbing through vents and around walls and fences, but how will does that actually hold up in the field? [01:11.250 --> 01:14.850] So this talk is going to focus on successes and failures and lessons learned. [01:15.130 --> 01:17.590] So please welcome Karen Ng and Bill Graydon. [01:20.490 --> 01:21.170] Thank you Bill. [01:29.270 --> 01:30.190] Oh, there we go. [01:30.410 --> 01:30.850] Okay, thank you. [01:31.230 --> 01:33.450] Alright, so welcome to Lock Bypass Tricks in the Field. [01:34.410 --> 01:36.070] So my name is Karen. [01:36.270 --> 01:37.450] I'm a physical red teamer. [01:37.570 --> 01:40.750] I am also one of the village leads for the physical security village. [01:40.910 --> 01:41.790] We've done a lot of cons. [01:42.210 --> 01:44.550] And I do not need supervision when using a lathe. [01:47.830 --> 01:48.810] My name is Bill Graydon. [01:49.030 --> 01:51.890] I'm a physical security researcher and do some red team as well. [01:52.550 --> 01:56.870] We're in a PhysSec village and apparently I do need supervision when using a lathe. [01:57.850 --> 02:02.010] Those of you who have seen my previous talks will be used to the beard that you see on the screen. [02:02.670 --> 02:03.910] Oh, it is not on the screen. [02:04.830 --> 02:06.250] Oh, it is not on the screen. [02:06.910 --> 02:07.890] Can I get the slides out? [02:08.550 --> 02:09.350] There we go. [02:09.350 --> 02:10.130] There we go. [02:14.230 --> 02:15.930] So, you might have seen... [02:17.050 --> 02:18.550] Let's just turn this right off. [02:18.850 --> 02:20.010] Or take this right off. [02:20.330 --> 02:20.570] Okay. [02:21.770 --> 02:22.290] Yeah. [02:25.450 --> 02:33.530] So, you might have seen our Bypass 101 sessions with the physical security village, formerly known as Lock Bypass Village, in various cons. [02:34.090 --> 02:38.050] And so, we're going to do a lightning review of that for those who haven't seen it. [02:38.370 --> 02:40.770] But this talk is about adding a little bit more to it. [02:40.970 --> 02:44.410] It's about not just those techniques, but what works, what doesn't, etc. [02:44.870 --> 02:51.590] And so, to do that, we're going to start off by giving a high level overview of the overarching goals and objectives that we have as red teamers. [02:51.750 --> 02:56.870] And that's going to help us frame our decisions when we're choosing which Bypass to use. [02:58.090 --> 03:00.150] So, the goal is to simulate a real attacker. [03:00.650 --> 03:01.010] Right? [03:01.130 --> 03:04.170] So, we're going into companies and we are helping them to secure themselves. [03:04.470 --> 03:06.530] So, ultimately, it's, you know, it's helping out the blue team here. [03:06.890 --> 03:09.490] And so, we want to do what a real attacker is going to do. [03:10.430 --> 03:13.810] And part of that is keeping our Bypasses compatible with social engineering. [03:14.110 --> 03:14.470] Right? [03:14.550 --> 03:18.890] So, a real attacker, they don't want to do something where if they get caught, there is no way out. [03:19.470 --> 03:22.290] Sometimes they will, but usually not. [03:22.450 --> 03:22.650] Right? [03:22.770 --> 03:33.990] So, when we're doing non-destructive type Bypasses, that's something that we're keeping in mind is, what happens if someone walks up to us and catches us with whatever tools, whatever technique in the middle of that process. [03:35.150 --> 03:37.070] And so, we're going to use that as an objective going through. [03:37.850 --> 03:38.770] We want to be fast. [03:41.370 --> 03:46.550] So, often, we're working with places that are a little bit more secure. [03:46.730 --> 03:49.110] And it's not a matter of if we're going to get in, but when. [03:49.530 --> 03:50.550] And they know that. [03:50.690 --> 03:57.250] And so, they're going to be trying to detect us early, start responding to us, and ultimately intercept us before we're successful. [03:57.570 --> 03:57.950] Right? [03:58.090 --> 04:04.250] So, we don't want to spend 45 minutes doing a very tricky bypass, because that's going to give the response force 45 minutes to get there. [04:04.590 --> 04:06.410] And of course, we don't want to get detected as well. [04:06.990 --> 04:10.030] We don't want it seen, don't want to get heard, or set off any sensors. [04:10.310 --> 04:16.050] And so, we'll be looking at the noise level primarily of a lot of these bypasses, as well as what sorts of sensors they will trip. [04:17.390 --> 04:23.050] Another thing that we're going to do before we start is analyze the possible paths of entry. [04:23.330 --> 04:26.510] There's always multiple ways to go, or usually multiple ways to go. [04:26.690 --> 04:28.190] And so, we're going to look at all of them. [04:28.290 --> 04:28.750] Right? [04:28.870 --> 04:34.010] So, in this example facility here, we've got a couple different paths that the intruder could take. [04:34.350 --> 04:41.710] Taking certain amounts of time each, having certain amounts of visibility on the cameras each, and setting off sensors at different points along the path. [04:41.710 --> 04:48.590] And so, we're going to look at those, look at the hardware, how long it's going to take to bypass each door, and move each distance within each path. [04:48.930 --> 04:55.290] And we're going to tailor our red team to pick the best case for us, the red team, which is the worst case for the defender. [04:55.670 --> 05:01.150] And that way, we're going to test and retest until the defender is secure on that worst case path. [05:01.510 --> 05:04.810] And so, that way, they know if they're going on the worst case, they're going on everything. [05:05.390 --> 05:05.630] Right? [05:05.810 --> 05:10.770] So, we're going to pick which path we take based on that criterion. [05:13.390 --> 05:24.070] So, when working with companies, we often do more of a white box type assessment, so they'll give us the floor plans ahead of time in a more realistic red teaming environment, or sometimes they want us to do a black box. [05:24.230 --> 05:31.870] And in that case, we're going to do some reconnaissance, some intelligence, and figure out as best we can what that internal layout is going to look like. [05:32.070 --> 05:40.350] And so, two years ago, I gave a HOPE talk all about that, how to look at the outside of a building and figure out, based on that, based on the windows and massing, etc., what's on the inside. [05:40.670 --> 05:43.310] So, if you're interested in that process, I encourage you to check that out. [05:44.890 --> 05:50.410] So, with that context in mind, Karen's going to start running through the options available to us. [05:52.770 --> 05:53.370] All right. [05:53.650 --> 05:54.770] So, whoops. [05:55.110 --> 05:59.270] I'm going to jump right into it and get started with Latch Targeted Bypass, otherwise known as poking. [05:59.970 --> 06:03.530] So, I'm sure you guys have seen this before, poking, carding, it has a bunch of names. [06:03.730 --> 06:06.910] And what it does is it targets the latches that hold the door closed. [06:07.110 --> 06:10.690] And then, depending on the orientation of the latch, you either should shove or pull it. [06:11.490 --> 06:15.710] So, here's an example of a door that we found that has a very visible latch. [06:15.890 --> 06:18.830] So, this is definitely one of the first things that we would try on a door like this. [06:19.910 --> 06:22.410] And the tool itself, there's a bunch of tools you can use. [06:22.530 --> 06:26.050] Latch slips, traveler's hooks, plastic cards, even a well-bent piece of wire works. [06:26.390 --> 06:28.830] I have this card here that I like to use. [06:29.690 --> 06:32.270] But before we can talk about that, we're going to talk about deadlatches. [06:32.550 --> 06:36.170] So, what I have circled here in red is deadlatches. [06:36.370 --> 06:41.190] And what they do is essentially prevent us from doing exactly what I'm about to show you guys that we can do. [06:41.730 --> 06:44.450] So, we have a video here. [06:44.770 --> 06:46.550] But I can also just live demo it. [06:46.890 --> 06:47.710] But let's do the video. [06:51.970 --> 06:54.350] So you can see that the latch goes into the door here. [06:54.490 --> 06:58.850] But when the deadlatch is actuated, pushed in, then you can't actually push in that latch. [06:58.990 --> 07:01.470] So this prevents us from being able to slip or card the door. [07:02.310 --> 07:04.870] Luckily, a lot of the times, the deadlatch is not actuated. [07:04.870 --> 07:07.470] And this means that you can pretty much do whatever you want. [07:07.670 --> 07:10.550] So here's the instructions real quick for pulling the latch. [07:10.730 --> 07:12.990] So, the latch slip tool goes behind the latch. [07:13.110 --> 07:15.430] And you kind of wiggle it until the latch goes into the door. [07:15.770 --> 07:18.650] And then without removing the tool from holding in the latch, you pull the door open. [07:19.190 --> 07:21.090] Could I get a camera onto the door? [07:21.450 --> 07:22.350] Sorry, AV folks. [07:23.970 --> 07:24.690] Oh, perfect. [07:24.870 --> 07:25.170] Thank you. [07:25.510 --> 07:26.850] There's not a lot of room for you. [07:27.010 --> 07:27.290] Oh, boy. [07:27.890 --> 07:28.390] All right. [07:29.190 --> 07:32.250] I'm going to do it as best I can. [07:32.670 --> 07:35.010] So, you can come in from the top or the bottom. [07:35.590 --> 07:36.670] And it's kind of hard to see. [07:36.930 --> 07:40.330] But you kind of wiggle it back and forth while pulling. [07:42.510 --> 07:43.690] And there you go. [07:43.890 --> 07:44.370] The door's open. [07:44.710 --> 07:46.370] I start off an alarm, but the door is open. [07:49.650 --> 07:50.550] Love live demos. [07:55.630 --> 07:58.890] And then if the latch is facing the other direction, you can shove it. [07:58.990 --> 08:04.190] And basically, that's just shoving a card between the latch and the strike plate and then pulling the door open, just like I did. [08:05.250 --> 08:07.150] So, here's a demo video of that. [08:08.630 --> 08:11.390] So, you can see the doors being locked here. [08:11.510 --> 08:12.750] And you can no longer open it. [08:15.800 --> 08:17.700] And then you take a clear plastic card. [08:17.700 --> 08:18.760] Any card works, really. [08:18.980 --> 08:20.060] Just has to be kind of flexible. [08:20.400 --> 08:23.640] And you just shove it in between the door and it just opens. [08:24.280 --> 08:25.320] So, nice and easy. [08:25.480 --> 08:26.200] Very quick bypass. [08:26.460 --> 08:26.980] Very convenient. [08:30.970 --> 08:34.270] And here's us demoing it at Vegas a couple years ago. [08:34.450 --> 08:38.590] We were staying at the Flamingo, so we thought it'd be fun to use our hotel room card to open it. [08:38.730 --> 08:40.110] And, I mean, it works. [08:40.390 --> 08:41.930] So, all right. [08:42.010 --> 08:43.910] Next, I'm going to be talking about handle targeted bypass. [08:44.650 --> 08:48.070] So, we're primarily going to be talking about the under the door tool. [08:48.410 --> 08:51.970] So, this allows us access into areas that have properly functioning deadlatches. [08:52.170 --> 08:55.330] And this, instead of targeting the latch, targets the handle of the door. [08:55.570 --> 08:57.810] It mimics a person exiting from the other side. [08:58.170 --> 09:02.470] And it allows you to use a little bit of wire with some string to open the door. [09:03.550 --> 09:10.190] So, basically, how this tool works is it gets inserted under the door and it maneuvers onto the handle of the door. [09:10.650 --> 09:13.170] And then you pull the string and that pulls it down. [09:13.370 --> 09:14.530] And then you can pull open the door. [09:15.850 --> 09:17.710] So, here is... Can you pop the screen back up? [09:18.530 --> 09:21.710] The wire we got was a little too stiff for this tiny door. [09:21.910 --> 09:23.970] So, unfortunately, we don't have a live demo for that today. [09:24.290 --> 09:24.510] Oh. [09:24.910 --> 09:25.230] Whoop. [09:28.400 --> 09:30.040] So, here's the little video demo. [09:32.420 --> 09:36.360] So, here's our red teamer with the tool. [09:36.620 --> 09:37.860] And it goes underneath the door. [09:47.070 --> 09:47.470] Oh. [09:47.910 --> 09:48.310] Whoop. [09:48.390 --> 09:48.890] There it goes. [09:50.930 --> 09:53.510] And you slide it onto the handle of the door nice and easy. [09:54.210 --> 09:55.650] And then you can pull down on the string. [09:57.170 --> 09:58.590] And it'll open the door for you. [10:00.890 --> 10:01.410] There we go. [10:01.630 --> 10:01.910] Wow. [10:02.230 --> 10:02.550] Amazing. [10:07.160 --> 10:11.700] And then the other thing to note for poking in the under the door tool is you can use them in combination. [10:11.940 --> 10:25.720] So, if you have a lever handle that's kind of slippy so it's easy for the tool to fall off of, or if you have something like a doorknob, what you can do is you can use an under the door tool or a doorknob tool to open it partially so that it deactivates the deadlatch. [10:25.940 --> 10:26.660] And then you can poke it. [10:26.740 --> 10:27.980] And then you can open it the rest of the way. [10:29.060 --> 10:30.580] Next, I'm going to be talking about crash bars. [10:30.800 --> 10:32.340] So, I'm sure you guys have seen these before. [10:32.440 --> 10:33.260] These are crash bars. [10:33.740 --> 10:36.160] They have a large bar across the door. [10:36.300 --> 10:37.000] And you push that down. [10:37.060 --> 10:38.320] And that's what unlocks the door. [10:39.580 --> 10:42.760] And the tool for this is another piece of cleverly bent wire. [10:42.940 --> 10:44.280] It's similar to the under the door tool. [10:44.600 --> 10:47.920] And it uses some string to actuate it and open the door. [10:48.200 --> 10:51.800] So, real quick instructions, but I think a video is going to be a little bit better. [10:53.860 --> 10:54.420] Well, look. [10:54.500 --> 10:54.700] It's me. [10:59.060 --> 11:01.280] So, there goes the tool up the side of the door. [11:06.040 --> 11:06.760] And down. [11:12.970 --> 11:13.330] Yay! [11:19.260 --> 11:19.720] All right. [11:19.800 --> 11:21.080] Next is pulling really hard. [11:21.620 --> 11:26.560] So, surprisingly, there's a lot of doors that, in particular external doors, that are loose in the frame. [11:26.740 --> 11:31.000] And if you have a strong enough arm, you can just pull it open even when it's locked. [11:31.580 --> 11:35.600] In particular, you want to look for springy and loosen the frame doors with a little bit of flex. [11:36.000 --> 11:39.940] In particular, multi-bank doors are vulnerable to this. [11:40.680 --> 11:44.060] And here's the instructions real quick, in case you guys didn't figure it out. [11:45.340 --> 11:48.140] We could demo it on this door, but it'll pull the frame right off. [11:48.420 --> 11:50.620] It's a little, you know, it's a little small, so... [11:50.620 --> 11:53.480] But you'd be surprised how often this actually does work. [11:54.440 --> 11:54.940] All right. [11:55.280 --> 11:56.980] Back to the slides, please. [11:58.380 --> 11:59.140] Thank you, AV. [12:00.420 --> 12:03.100] Next, I'm going to be talking about wheelchair buttons and request exit sensors. [12:03.840 --> 12:06.840] So, wheelchair buttons are a really great accessibility feature. [12:07.040 --> 12:10.100] They allow the door to open itself, pretty much, when the button is pushed. [12:10.460 --> 12:16.520] But sometimes it's installed in such a way that it'll unlock the door and open it, even if the door is supposed to be locked otherwise. [12:17.320 --> 12:19.540] So, here's one that we found a while ago. [12:20.480 --> 12:25.840] So, the door is locked, and we push the wheelchair button there. [12:25.980 --> 12:26.760] Oh, it's open! [12:26.980 --> 12:27.340] Amazing! [12:30.200 --> 12:32.300] And then, of course, request exit sensors. [12:32.660 --> 12:36.380] So, these are primarily installed for the convenience of people leaving the building. [12:36.640 --> 12:40.500] And some are set up so that it'll unlock automatically as you approach from the inside. [12:40.760 --> 12:45.620] And others tell the controller, hey, someone's exiting, don't ring the alarm, no one's forcing the door from the other side. [12:45.800 --> 12:50.300] So, you want to keep an eye out for these when you're doing bypasses so that you don't trip an alarm or do something like that. [12:51.320 --> 12:52.580] Bill, you want to talk about fire alarms? [12:53.100 --> 12:53.200] Yeah. [12:53.580 --> 13:02.520] So, another thing that folks are not necessarily aware of is when you've got a door that's in what's called the access to exit. [13:02.660 --> 13:04.960] So, you need to go through that door to get to an exit. [13:05.760 --> 13:09.060] It must, by code, unlock in a fire alarm situation. [13:09.360 --> 13:12.060] So, looking at the floor plan, you can tell when that happens. [13:12.280 --> 13:15.340] Or if you can see that there's no other way out, that's got to be what happens. [13:15.780 --> 13:19.900] And so, all you got to do then is pull the alarm. [13:20.060 --> 13:21.900] Let's test if my live onstage wiring worked. [13:23.460 --> 13:23.900] Wow! [13:25.520 --> 13:26.600] And the door is open. [13:29.850 --> 13:30.730] There's no alarm. [13:31.290 --> 13:37.530] Folks might not know, but it's actually very straightforward to reset these with a flathead screwdriver up top of it. [13:38.750 --> 13:40.470] And that's just a switch on the inside. [13:40.670 --> 13:46.030] So, when I flip this back, it is now back to normal operation and that alarm starts going off. [13:50.990 --> 13:52.110] Pop back to the slides. [13:55.820 --> 13:56.240] All right. [13:56.400 --> 13:58.640] So, for those who couldn't see, right, flathead up top. [13:59.160 --> 14:00.500] This is just a switch on the inside. [14:06.620 --> 14:07.080] All right. [14:07.280 --> 14:10.400] And next, I'm going to be talking about unlocked or improperly locked doors. [14:10.940 --> 14:12.960] So, if I could get the slides back up. [14:13.140 --> 14:13.640] Thank you. [14:14.940 --> 14:16.460] So, oh, right. [14:16.740 --> 14:17.020] The mic. [14:17.140 --> 14:17.440] All right. [14:17.700 --> 14:21.800] So, there's a lot of reasons why a door won't be locked if you encounter one in the wild. [14:21.920 --> 14:23.460] So, sometimes it can be human error. [14:23.660 --> 14:24.780] So, things like someone propping it. [14:24.820 --> 14:26.700] A staff member forgetting to lock it properly. [14:27.220 --> 14:31.820] Or if you yourself came by when the building was open and propped it open and nobody noticed that it was propped. [14:32.160 --> 14:34.760] It can also be unlocked due to environmental issues. [14:34.880 --> 14:38.280] So, if there's an air pressure difference between the inside and the outside of the building. [14:38.640 --> 14:40.460] Or if the door frame is warped. [14:40.600 --> 14:43.360] So, especially during the summer, door frames kind of expand a little bit. [14:43.420 --> 14:43.940] They get sticky. [14:44.120 --> 14:45.380] They don't close properly. [14:45.740 --> 14:47.460] Or if the door closure doesn't work. [14:47.560 --> 14:48.460] If the lock is broken. [14:48.600 --> 14:50.000] Or if there's no lock there at all. [14:51.060 --> 14:55.420] And, of course, you can go through ceilings and windows and around the obstacle. [14:55.840 --> 14:58.220] So, here's some of us in Vegas. [14:58.540 --> 15:00.540] Just a big fence with barbed wire. [15:00.740 --> 15:01.400] Ooh, real scary. [15:01.980 --> 15:03.520] And easy peasy. [15:03.780 --> 15:04.600] It's like a ladder. [15:04.860 --> 15:05.520] You just go over it. [15:06.120 --> 15:09.660] Here's another example of a building with false ceilings. [15:09.660 --> 15:11.560] So, we have a wall. [15:11.700 --> 15:12.340] A locked door. [15:12.720 --> 15:15.280] And you can just kind of go over it. [15:16.120 --> 15:19.360] So, very conveniently, there's a ladder there that you can go over. [15:20.340 --> 15:22.260] Not all false ceilings will have a ladder. [15:22.400 --> 15:23.220] But this one happened to. [15:23.460 --> 15:25.340] So, if you're able to, like, boost yourself up. [15:25.460 --> 15:26.040] Something like that. [15:26.820 --> 15:32.320] And then you can just disconnect the little wires that hold the ceiling tile in place. [15:32.540 --> 15:33.640] And, oh, there he is. [15:35.740 --> 15:36.720] And then... [15:40.440 --> 15:42.800] And down he comes. [15:43.080 --> 15:46.260] And now he has access to a space that should otherwise be locked out. [15:47.260 --> 15:49.460] Another example of this is ladders. [15:49.800 --> 15:51.920] So, some of you might have seen these before. [15:52.260 --> 15:53.880] There are ladders with these cages around them. [15:54.040 --> 15:58.020] And you'll notice, at the bottom here, there is a panel that can lock in place. [15:58.220 --> 15:59.840] And this prevents people from using the ladder. [16:00.200 --> 16:00.720] Perfect, right? [16:01.740 --> 16:05.900] Except there's a perfectly serviceable ladder on the other side. [16:07.720 --> 16:13.380] So, you can still get up onto access of places that you shouldn't have access to. [16:13.640 --> 16:17.180] But it is very openly able to be accessed. [16:17.720 --> 16:18.820] Here's another example. [16:19.160 --> 16:19.560] Oh, no. [16:19.720 --> 16:20.040] A fence. [16:20.560 --> 16:21.580] Whatever will we do. [16:23.600 --> 16:24.580] Another ceiling tile. [16:24.780 --> 16:27.220] This one looks like it leads directly from the outside. [16:27.760 --> 16:34.100] So, that's a very easy method of entry that pretty much anyone without any skills or training can just easily come into. [16:34.220 --> 16:36.120] So, that's definitely something that we'd want to point out. [16:36.940 --> 16:37.800] Here's another one. [16:38.000 --> 16:38.720] So, there's a door. [16:39.000 --> 16:42.520] And right over it is a vent that leads to the other side of the door. [16:43.040 --> 16:46.980] So, you know, these are the things that you think are kind of obvious and people should know better. [16:47.020 --> 16:54.840] But it is something that we see very, very commonly when doing red team activities, we'll see people just not really thinking about it because it's not really their job. [16:55.020 --> 16:58.920] So, they don't consider the security implications of the things that they're setting up. [16:59.820 --> 17:01.700] You want to talk about purchasing and examining hardware? [17:02.040 --> 17:02.420] Yep. [17:03.260 --> 17:07.280] So, you know, we'll often encounter hardware that we are familiar with. [17:07.820 --> 17:08.220] Right? [17:08.400 --> 17:12.640] So, you know, something you can use poking the latch, under door tool, that sort of thing. [17:12.880 --> 17:15.560] But sometimes we deal with stuff that is new. [17:15.740 --> 17:17.380] And we've got to find some new ways to hack it. [17:17.560 --> 17:24.880] And so, when it's hardware that we're not familiar with, we're usually going to borrow one from the facility or purchase one and try it out and see what we can figure out. [17:25.100 --> 17:29.880] So, one kind of fun example is we were doing a case for loss prevention a few weeks ago. [17:30.260 --> 17:35.400] And we had this pilfer guard alarm lock type setup. [17:35.640 --> 17:39.480] So, you sometimes see them under the two brand names, but they're the same thing. [17:41.140 --> 17:42.100] And so we got one. [17:42.220 --> 17:42.880] Found a number of things. [17:43.020 --> 17:45.240] One is they tell you exactly where to put the magnet. [17:48.120 --> 17:50.300] It says remove label after installation. [17:50.620 --> 17:55.940] The number of times we've seen these that do not have that label removed is non-zero. [17:58.320 --> 18:03.760] And I guess I actually should talk about magnet bypasses as well, if you can pop back to the door for a second. [18:04.920 --> 18:06.540] Oh, did I just pull our power? [18:07.320 --> 18:07.440] No. [18:07.740 --> 18:08.080] Good. [18:09.360 --> 18:09.720] Great. [18:09.980 --> 18:16.240] So, the way these are supposed to operate is you tap your card, mag strike unlocks. [18:16.400 --> 18:17.100] Mike, Mike, Mike. [18:18.200 --> 18:21.560] You tap your card, mag strike unlocks, and the door is open. [18:23.280 --> 18:26.000] If you do a bypass, so from the other side... [18:42.730 --> 18:44.370] Okay, I'm going to do my talking here. [18:46.510 --> 18:55.410] So, if you do a bypass, and it detects that the door is open without the card read, then it's going to alarm, as we heard. [18:57.190 --> 18:58.490] So, what we can do is... [19:01.010 --> 19:02.230] attack the detector. [19:02.470 --> 19:08.490] So, there is this magnetic contact sensor in the side of the door here, and in the frame there... [19:09.070 --> 19:13.330] so, this is a magnet, sorry, in the side of the door, and in the frame is the sensor that attacks this magnet. [19:13.610 --> 19:18.030] Well, we can put in a surrogate magnet and replace the one in the door. [19:29.380 --> 19:30.080] No alarm! [19:34.950 --> 19:36.130] And I remove the magnet. [19:37.150 --> 19:37.890] There we go. [19:42.230 --> 19:43.410] Paw, back to the slides. [19:46.350 --> 19:48.650] And my sincere apologies to the AV folks. [19:48.790 --> 19:50.510] This talk must be a nightmare for you. [19:52.970 --> 19:58.770] So, that's what we're talking about when we say putting a surrogate magnet right in between the arrows where it tells us exactly where to put them. [19:59.410 --> 20:00.710] But there's other things you can do. [20:01.190 --> 20:09.970] So, you got this lock up here that's meant to unlock it, and it hits this piece of metal that flips this switch, and that's our locking and unlocking mechanism. [20:11.310 --> 20:20.170] That corresponds to an indicator on the other side that's just a mechanical, whether you see the red on this or not, and it tells you whether it's locked or not. [20:21.570 --> 20:27.950] So, you know, in theory, if you could find some way to poke through that indicator, you could actually push the indicator until the switch goes. [20:28.410 --> 20:32.990] But they provide us these nice horizontally oriented vents for the sound to get out. [20:33.950 --> 20:36.810] So, you just stick a lock pick in there and slide it on over. [20:37.290 --> 20:37.610] Right? [20:37.810 --> 20:40.470] So, pretty simple, brainless thing to do. [20:40.550 --> 20:46.230] And this is the sort of thing that I would not be surprised if shoplifters out there have figured out how to do with this particular model. [20:46.630 --> 20:46.990] Right? [20:47.130 --> 20:51.650] So, that's something that we're going to do as well, is buy it, examine it, and see what we can find. [20:53.410 --> 20:59.050] And so, now Karen's going to chat about a couple of the bypasses that we talked about that aren't quite as useful and the reasons why. [21:02.580 --> 21:02.940] Alright. [21:03.200 --> 21:06.220] So, the first thing I'm going to talk about in this section is removing the hinges. [21:06.860 --> 21:14.900] So, a lot of the times, you'll have a door and it's locked, but the easiest way to unlock it is just not to unlock the door. [21:14.900 --> 21:21.020] So, some doors, you'll see the hinges are installed backwards, so they're accessible, and you can unscrew them and take them off of the hinges. [21:21.800 --> 21:23.860] So, you can just unscrew the hinges. [21:24.400 --> 21:25.920] You can also remove the hinge pin. [21:26.140 --> 21:33.800] So, a lot of the times, you'll see doors with the hinge pin exposed, and the pin can be removed pretty easily and allow the door to come off the frame. [21:35.660 --> 21:40.180] So, here's a little demo video, because I didn't want to bother with all the noise live. [21:42.460 --> 21:45.280] There's no sound, but, I mean, you know, whack, whack, whack. [21:45.460 --> 21:49.800] Yeah, so, you know, it's a hammer and a bunch of pins, so you hear the thump, thump, thump, thump. [21:51.260 --> 21:52.640] And out comes the first pin. [21:53.760 --> 21:55.840] And then you can use it to take out the second pin. [21:56.400 --> 21:56.760] Video? [21:57.640 --> 21:58.000] Video? [21:58.280 --> 21:58.360] Oh. [22:16.260 --> 22:17.120] And there's the door. [22:17.880 --> 22:18.240] Yay. [22:20.600 --> 22:23.940] So, this is limited utility because of a few reasons. [22:24.260 --> 22:27.580] First of all, you know, you guys saw how long it took me to do it on that minidoor. [22:27.720 --> 22:28.560] So, it takes a lot of time. [22:28.800 --> 22:29.800] It makes a lot of noise. [22:29.940 --> 22:31.340] So, you know, you're going at it with a hammer. [22:31.580 --> 22:34.340] So, someone hears thump, thump, thump, thump from the other room. [22:34.440 --> 22:35.200] They're like, oh, what is that? [22:35.600 --> 22:38.640] So, you know, you're more likely to get detected that way. [22:38.960 --> 22:40.260] It can't be stowed or aborted. [22:40.280 --> 22:46.540] So, if you're, like, halfway through opening it and someone comes by, you can't really be like, oh, I wasn't doing anything. [22:46.540 --> 22:48.180] because the door's halfway off of the frame. [22:49.160 --> 22:59.200] It's often not in the threat model, so a lot of the times you will... it'll be something that you point out and it's not really in the threat model, it's just good to know that someone could, in theory, do it. [22:59.660 --> 23:09.600] It's difficult to do without causing damage, so, you know, especially when it's a big, full-sized door and you're kind of maneuvering it and you're going at it with a hammer, it's, you know, likely to cause some damage. [23:10.000 --> 23:17.660] And, of course, the fire marshal gets really mad about removing doors from the hinges, in particular, if it's a door that prevents venting of the fire. [23:18.240 --> 23:23.060] And so, if that's just wide open and you leave it open, then that can be kind of a problem. [23:23.800 --> 23:40.000] Another reason is because if you leave the door wide open and just off the hinges, that can lead to a problem if someone else happens to come in during your red team engagement with malicious intent and they can just go through this door that you left on the side of the... Yeah. [23:40.200 --> 23:54.760] That's one of the... one of the things that we have to be very careful about, right, when doing red team engagements, is that we're bypassing stuff, we're defeating various security mechanisms, we don't want to create that perfect storm for a real criminal to come in while we are operating, [23:55.120 --> 24:02.640] take advantage of the vulnerabilities we've just created, and have the operation center think that all the alarms they're setting off are just us. [24:05.380 --> 24:07.320] So, it is pretty limited utility. [24:07.620 --> 24:12.260] If you have an unmonitored head in the woods and you need to get through, then I guess it's an option. [24:13.380 --> 24:15.080] Also button push combination boxes. [24:15.740 --> 24:17.980] So, I'm sure you guys have seen these around. [24:18.480 --> 24:21.800] They allow physical access to an area without needing the actual key itself. [24:22.100 --> 24:27.140] There also exist these kinds of boxes that you can push the buttons on and you can put keys or fobs inside of them. [24:28.360 --> 24:31.320] So here's one from... was this one a residential? [24:31.700 --> 24:31.880] Yeah. [24:32.060 --> 24:43.100] Yeah, so you'll see these a lot with like Airbnbs, things like that, or with restaurants and things like that along the street if it's like an opening up kind of thing, so they'll have the external keys in there. [24:44.320 --> 24:49.780] And the other thing is they'll put fobs in there for apartments and condos and things like that if you're running an Airbnb. [24:50.280 --> 24:52.720] And these boxes often are not shielded. [24:52.760 --> 25:03.960] So if you have a little proxmark, a little fob duplicator there, it's very easy to just hold it up to the unshielded box and just duplicate a fob without even needing to touch it. [25:05.820 --> 25:10.040] For these boxes and these simplexes, you can also use UV ink and powder. [25:10.300 --> 25:16.360] So you can apply these to the buttons and you can figure out which buttons are being used and then from there you can brute force the combination. [25:18.720 --> 25:24.440] Sometimes you don't even need UV ink at all to figure out what the combination is if it's worn down enough. [25:25.720 --> 25:27.580] The other thing is simplex locks. [25:27.760 --> 25:31.000] The default code from the factory is 2 and 4 at the same time and 3. [25:31.000 --> 25:35.400] And so many people do not change from the default. [25:35.800 --> 25:42.480] So we've seen tons and tons of places where the simplex lock is the default factory combination. [25:42.840 --> 25:45.280] And this is very easy to look up. [25:45.460 --> 25:46.980] Anyone can find this information online. [25:47.280 --> 25:51.660] So it's definitely something that you want to change given the opportunity to. [25:53.100 --> 25:57.760] However, a lot of these can be limited utilities, in particular using UV ink. [25:57.760 --> 26:03.120] So it's kind of a cool trick to show people, but it's also very limited in how we can use it. [26:03.280 --> 26:04.880] It requires multiple accesses. [26:04.920 --> 26:16.120] So if this is an internal door, you need to get in there, put the UV ink on the buttons, and then come back a couple days later when it's been used to see what's been wiped off by use. [26:16.820 --> 26:22.320] It can also require multiple accesses if somebody goes in and just wipes the buttons off. [26:22.320 --> 26:23.980] And then you have to start over. [26:24.660 --> 26:26.420] It's pretty easy to detect. [26:26.780 --> 26:30.260] You know, anyone can bring a little flashlight and just see if there's ink on the buttons. [26:30.560 --> 26:33.300] It's not reliable, and it's often not in the threat model. [26:33.400 --> 26:36.840] It's not something that a lot of companies that hire us are worried about. [26:37.980 --> 26:44.700] The only time that we've really seen it useful as part of the threat model is if it's like an insider threat. [26:44.700 --> 26:50.500] So if they're worried about somebody with access to that door escalating their privileges when they're not supposed to be. [26:52.140 --> 26:55.480] Next, I'm going to pass it on to Bill, who's going to talk about bypass and social engineering. [26:58.740 --> 27:05.800] Right, so as I mentioned at the start, when we're picking bypass techniques, we have to be careful that it's going to be compatible with what a real attacker would do. [27:06.000 --> 27:12.000] And so as a red team, one of our goals is, you know, if we get caught, we want to be able to try to continue that pretext. [27:12.000 --> 27:16.940] Try to explain it away and see if we can get out of it to test the facility's response. [27:17.260 --> 27:19.040] And we've seen some pretty poor responses. [27:19.300 --> 27:26.300] You know, they catch us with a giant under-the-door tool and don't know what it is, and eventually we're able to talk our way out of it. [27:26.380 --> 27:28.660] Right, so that's a valuable thing that we can report back on. [27:29.390 --> 27:30.960] But ideally, we don't want to do that. [27:31.220 --> 27:37.680] Right, so things like these long under-door tools, we're generally going to roll them up and stow them away as soon as we're done with them. [27:37.680 --> 27:44.960] Any of these wire contraptions, we want to make sure that ideally we don't get seen with them, because that makes social engineering your way out just a whole lot harder. [27:47.600 --> 27:50.220] This is the opposite end of the spectrum, right? [27:50.400 --> 27:56.300] So these little shove tools that are used to slip the latch out of the way, and they are perfect. [27:56.720 --> 28:03.680] So, you know, you're walking up to the door, you're sticking that near the keyhole, and it happens in a couple seconds. [28:03.680 --> 28:09.660] So the motion from a distance looks like you're just using a key, and you're opening that door and you're authorized to go in. [28:09.900 --> 28:12.180] Right, so this is perfect for all of those reasons. [28:12.340 --> 28:13.820] It also doesn't create much noise. [28:14.040 --> 28:18.640] And so, you know, time, noise, what it looks like, this is a good one to use. [28:19.000 --> 28:22.360] And so we will use this technique anywhere we possibly can. [28:24.210 --> 28:34.420] We want to look at the environmental design of the site and try to find places that if we're going to do bypasses, we're a little bit more protected from guards rounds, from noise, etc. [28:34.740 --> 28:39.840] So this is a fun example we found of a mechanical room, and there's lots of things that you can do once you're in there. [28:40.710 --> 28:44.080] And that mechanical room is inside of a locked single-use bathroom stall. [28:44.080 --> 28:47.640] So we go on in, and we're just taking a poop. [28:47.900 --> 28:50.240] Don't mind all the metal-scratching noises, just taking a poop. [28:53.240 --> 28:58.860] And we've got all the time we need and all the privacy we need to do whatever we've got to do to get through that door. [28:59.780 --> 29:04.020] Right, and so, you know, you might have heard of CPTEG, Crime Prevention Through Environmental Design, right? [29:04.020 --> 29:07.280] So on the red team side, we're obviously using that on the flip side. [29:07.440 --> 29:10.680] So trying to find places that's not got great lighting that's covered with hedges, etc. [29:11.220 --> 29:14.380] That gives us a little bit of privacy to do these bypasses undetected. [29:16.660 --> 29:20.380] And so, of course, we don't want to be bringing the whole kitchen sink, right? [29:20.480 --> 29:23.080] So we're going to try to keep our toolkit to as slim as we can. [29:23.260 --> 29:28.280] And that's why scouting out the facility first and knowing what you're going to encounter is very important there. [29:29.640 --> 29:39.960] And so for most, we're going to use just like a messenger bag, laptop bag type of thing, whatever would be at home in that facility or under the pretext that we're doing, right? [29:40.060 --> 29:43.320] And so sometimes our pretext is just, we're the facility's locksmiths. [29:44.580 --> 29:46.220] And that works a lot. [29:49.870 --> 29:52.770] But if we can't do that, then we're going to do something like this. [29:54.290 --> 29:55.550] Right, and of course, tailgating. [29:55.810 --> 29:56.630] Big, big problem. [29:56.850 --> 30:02.070] I mean, this is, you know, we talk about bypasses a lot, but tailgating is the biggest problem most businesses have, right? [30:02.230 --> 30:10.290] And so if we get all of our bypass gear for getting through the inner doors, nice and tucked away so we look like we belong there, it makes it way easier to tailgate in that front door. [30:12.050 --> 30:14.530] Another thing that we're going to look at is getting access later. [30:14.730 --> 30:22.610] So it's not nearly as flashy as some of the bypasses, but it is still very useful and it's extremely much in your threat model. [30:25.010 --> 30:27.030] So, things like megs or meg locks. [30:27.410 --> 30:36.990] If you can get in during, say, building open hours, you open it up, put some gaff tape on or a sticker or a piece of paper or two, because these meg locks have a magnetic holding force. [30:37.090 --> 30:41.990] And that holding force falls off with distance squared, which means that when it's right against itself... [30:42.930 --> 30:43.690] Is it cubed? [30:44.210 --> 30:44.850] Right, cubed. [30:45.110 --> 30:46.530] Yeah, because it's a dipole. [30:46.710 --> 30:47.110] Right, thank you. [30:47.830 --> 30:49.250] So it falls off with distance cubed. [30:51.210 --> 30:54.250] So when it's right against itself, you've got 2,500 pounds of holding force. [30:54.470 --> 30:58.650] If you put just two thin pieces of paper in there, it's now down to 50 pounds. [30:58.950 --> 31:05.410] So it feels like it's locked, it's got 50 pounds of force, but you can push that open and so give yourself access later. [31:07.090 --> 31:16.010] You can also put in a little rock or something in the base there, prevent the door from closing properly, and often people will then exit and not realize that that's what's happening. [31:16.010 --> 31:16.750] You can come in later. [31:17.590 --> 31:24.010] And you can even do things like put your foot on the door and flex the bottom out, and create enough space to put something in there. [31:24.750 --> 31:34.470] And so this door is still locked, but then when someone exits or enters that door, that little rock is now there, and the door is not going to fully close, and you've now got yourself access. [31:35.950 --> 31:44.210] You can also put something into the latch hole, and that prevents the latch from fully engaging and allows you to slip it when the dead latch might otherwise be engaged. [31:44.210 --> 31:57.370] And sometimes, it's hard to make this work, but you can put, you know, a little piece of foam into a plastic bag, squish it down so it stays squished, and maneuver that in there while the door is fully locked, and then the bag leaks and it expands out, [31:57.530 --> 31:59.370] and it'll then give you access later. [32:01.870 --> 32:09.750] So that's sort of the one other general technique that we'll use, and now we've just got a bunch of random stories and whatnot that we'll run through. [32:10.990 --> 32:23.690] Yeah, so, you know, one of the things that's kind of important when we're talking about a threat response is the actual sensors for the response, but also the response of the people itself. [32:24.030 --> 32:32.270] So we'll have times when we'll have an alarm that will set off, and you can prop the door and just leave, come back in an hour, you know, keep an eye on it. [32:32.270 --> 32:36.910] And then we've often had times when nobody shows up. [32:37.290 --> 32:48.670] So you'll have this door, it's alarmed, and a lot of the times if the door is prone to false alarms, things like that, if it's like a windy day, something like that, you know, security's like, oh, there's the alarm again, and they just ignore it. [32:48.730 --> 32:51.030] They shut it off, or they disconnect the alarm altogether. [32:51.770 --> 32:57.130] And this means your door looks alarmed, but it easily allows access into your facility. [32:58.110 --> 33:07.370] Another example of this is we've had facilities where the response time is so abysmal, so it takes them 45 minutes to an hour to actually respond to an alarm being tripped. [33:07.970 --> 33:10.450] And 45 minutes to an hour is a lot of time. [33:10.590 --> 33:18.910] That's enough time to get into a facility, do whatever malintent that you need to get done, and get out before anybody shows up to apprehend you. [33:19.810 --> 33:20.710] Anything to add to that? [33:21.650 --> 33:25.850] Yeah, I mean, I guess the other thing is the response is often woefully inadequate, right? [33:25.850 --> 33:31.490] We bypass in, we set off an alarm, we close the door, the response force shows up 10, 15, 30 minutes later. [33:31.770 --> 33:34.870] They pull on the door, yep, door's secure, it's not unlocked or anything. [33:35.130 --> 33:37.730] And if it's such a huge facility, I mean, they don't know where to check. [33:38.850 --> 33:41.270] So they just check the door's secure and then go away. [33:42.550 --> 33:48.710] So, yeah, there's a lot of problems with the responding force that really renders these alarms less useful than they could be. [33:50.010 --> 33:50.950] Want to talk about this? [33:51.510 --> 34:00.430] Yeah, so another funny example we saw wandering around New York City earlier this week is you'll often see cages like this that have the push bar style doors. [34:00.690 --> 34:06.090] There are bypasses for those without the cage, and I encourage you to check out the Not So Civil Engineers YouTube channel. [34:06.150 --> 34:07.610] He's got some great videos on that. [34:07.870 --> 34:16.330] But when there is a cage, he can stick a tool in and push that push bar in from the other side, or stick in a piece of string and pull it tight, and that'll pull the push bar. [34:17.370 --> 34:20.910] So we saw this interesting method to prevent that from happening. [34:21.450 --> 34:22.990] All right, so they got it recessed right in. [34:23.090 --> 34:28.370] It makes it very difficult to get a tool that's going to reach all the way around and do that, and a string is, of course, not going to work at all. [34:29.370 --> 34:35.870] The problem with that is if we walk over to the lock side, well, there's the latch. [34:40.140 --> 34:43.560] And this building, not anything particularly important. [34:43.800 --> 34:44.720] Just the... [34:50.750 --> 34:55.330] For those who are not familiar, this is one of the main AT&T switch buildings for the Eastern Seaboard. [34:55.550 --> 35:01.810] It also was used by the NSA for many years, known as Titan Point, for listening on all of your phone conversations. [35:02.090 --> 35:06.310] So, you know, a little bit important there that it not get broken into. [35:06.310 --> 35:10.450] To be fair, we didn't go in, that would be crossing an ethical and a legal line. [35:10.650 --> 35:12.030] So we don't know what's beyond that door. [35:12.570 --> 35:14.190] Maybe it's just the garbage compactor. [35:14.530 --> 35:15.090] We don't know, right? [35:15.230 --> 35:18.310] And maybe their threat model here was just transients getting in and sleeping there. [35:18.490 --> 35:19.770] In which case, you know what? [35:19.850 --> 35:23.170] If they were doing that string technique and this fixed it, that's fine, right? [35:23.250 --> 35:24.070] So we don't know, right? [35:24.190 --> 35:25.530] Not shaking on them. [35:25.730 --> 35:29.150] Well, the other thing with this door is the bars were kind of spaced apart. [35:29.370 --> 35:34.910] So if the blockage wasn't there, you could just stick your arm through and push down the push bar as well. [35:34.910 --> 35:35.450] Yeah. [35:36.510 --> 35:37.530] Yeah, lots of ways. [35:40.550 --> 35:47.010] So another thing that we're going to look at when we're actually doing consulting jobs is things like forceful entry, right? [35:47.090 --> 35:49.030] So door like this, you see the two strike holes there. [35:49.390 --> 35:50.750] One's for deadbolt, one's for the latch. [35:50.870 --> 35:52.150] You're going to have to bypass both of those. [35:52.270 --> 35:53.690] That's going to take you five, ten minutes. [35:53.990 --> 35:55.370] But, I mean, look at that jam. [35:55.810 --> 35:57.810] You know, I mean, it's half-inch veneer, right? [35:57.950 --> 36:01.190] A swift kick to that and you're in half a second, right? [36:01.190 --> 36:06.590] So obviously we're not going to be doing that on a site unless it's authorized, which it usually isn't. [36:06.950 --> 36:10.170] But we're going to let them know, like, this takes us 15 minutes to bypass. [36:10.410 --> 36:13.170] But by the way, like, your real problem here is forceful entry. [36:14.190 --> 36:15.670] When we see something like this, right? [36:15.770 --> 36:20.050] So a conduit that's been built to send a contact sensor through the concrete into the door frame. [36:20.050 --> 36:22.270] But that conduit is obviously empty. [36:22.490 --> 36:23.170] So we see that. [36:23.290 --> 36:25.130] We know that there's no alarm here, even though there could be. [36:26.670 --> 36:28.390] And then some funny remediations. [36:28.950 --> 36:32.330] So using a strike plate to protect the dead latch. [36:33.050 --> 36:34.770] That's not really... or the dead bolt, sorry. [36:35.050 --> 36:36.310] That's not really what you need to protect. [36:36.430 --> 36:37.410] You need to protect this down here. [36:39.430 --> 36:41.390] And with gates. [36:42.050 --> 36:45.530] So we often see these that... the hasps that you put the padlock on. [36:45.530 --> 36:46.630] And they're just bolted on. [36:48.710 --> 36:49.930] So it's still locked. [36:50.070 --> 36:51.330] That lock is still on there, isn't it? [36:56.440 --> 36:58.880] And often doors just get propped open, right? [36:59.100 --> 37:01.580] So notice, please keep this door closed. [37:01.860 --> 37:03.380] Okay, well, apparently not. [37:03.640 --> 37:09.740] So when, you know, when we're looking for doors that might be left open, those signs that say, please keep this door closed, well, they're the first ones we're going to go to. [37:12.040 --> 37:12.400] Right? [37:12.620 --> 37:14.820] And also, depending on the conditions, right? [37:14.920 --> 37:16.960] So as the red teamers, we choose when we attack, right? [37:16.960 --> 37:23.480] So if we attack during a power outage or when the cooling system is out on a very hot day when there's just been a leak and whatnot, right? [37:23.600 --> 37:33.680] So for instance, on one occasion we saw a server room that was propped open to have the fan blowing into it because the cooling system was out and there was just a leak in there, right? [37:33.780 --> 37:39.060] And so if we know that that sort of thing is going to be happening, that often leaves things propped that necessarily shouldn't be. [37:40.760 --> 37:46.880] We'll often see interchangeable core deadbolts removed, or not deadbolts, interchangeable cores removed. [37:47.420 --> 37:50.920] And so people think, okay, well, there's no longer a keyhole there, no one can get in. [37:51.140 --> 37:58.160] Well, that means anyone can get in with a flathead screwdriver and you no longer have the lock in the way to prevent you from actuating that mechanism in the back. [37:58.280 --> 38:01.660] So we see this a lot and it basically means that door is unlocked. [38:02.920 --> 38:04.720] Right, and of course the cables as well. [38:05.300 --> 38:13.920] Last year I have a whole other talk at DEFCON on what you can do if these cables are exposed, but in this case you can just unplug it, disable that camera, and do that, right? [38:14.020 --> 38:18.660] So a lot of this is just sort of having that hackerish mindset and applying it in a red team context. [38:20.480 --> 38:22.380] So with that, I'd like to thank you for listening. [38:22.620 --> 38:23.480] We'd like to take any questions. [38:38.310 --> 38:42.670] If you guys have questions, please make a line at the end of the aisle so I'll take the mic down. [38:43.270 --> 38:44.210] Anything to add here? [38:44.630 --> 38:45.150] Nope. [38:45.770 --> 38:46.070] Not bad. [38:46.270 --> 38:47.010] I'd like you to want to see from here. [38:47.670 --> 38:48.210] Yeah. [38:48.870 --> 38:49.210] Yes. [38:50.270 --> 38:50.810] Hi. [38:51.510 --> 38:51.830] Hello. [38:51.830 --> 38:52.330] Is this on? [38:52.970 --> 38:53.950] Is this on? [38:54.070 --> 38:54.270] Good. [38:55.210 --> 39:00.590] I noticed you in your almost last slide talked about interchangeable core. [39:02.250 --> 39:06.770] Often there are construction cylinders in these also, which are keto-like. [39:06.950 --> 39:24.790] And the other thing that people, few people know about IC is that with a single instance of a lock, you can make a control key, which removes all the other cores, replaces them with one of your own, so you can go in and be perfectly safe inside in the secure area. [39:24.970 --> 39:29.690] So I often, in my tests, try to exploit IC technology. [39:30.010 --> 39:33.070] And there are, you know, often padlocks somewhere in the perimeter. [39:33.110 --> 39:38.950] They're on the same system, and you can just take one and reverse engineer it. [39:39.730 --> 39:41.090] Yeah, that's a great point. [39:41.270 --> 39:44.630] And we sort of kept this talk to bypasses instead of keying system attacks. [39:45.490 --> 39:55.990] For those who are interested in what the gentleman just mentioned, I've got a talk at DEFCON 28, so two years ago, the safe mode, all about that exact sort of thing. [39:55.990 --> 39:59.490] So how to get the control from taking apart IC cores. [39:59.690 --> 40:01.230] We've got a nasty echo here. [40:02.150 --> 40:05.570] And how to reverse engineer master systems, et cetera. [40:05.730 --> 40:06.850] So all that sort of thing. [40:06.870 --> 40:09.710] If you're interested in it, I encourage you to check out my DEFCON 28 talk. [40:10.090 --> 40:15.470] Another thing you didn't talk about is what happens when somebody responds and you're detected. [40:16.670 --> 40:23.490] You know, often you have a get-out-of-jail card that says doing an authorized security test, call this number, and what do they do? [40:23.490 --> 40:25.950] They call the number on your get-out-of-jail card. [40:26.690 --> 40:27.570] Instant fail. [40:28.710 --> 40:29.190] Yeah. [40:29.530 --> 40:31.870] And we usually don't run with that, actually. [40:32.010 --> 40:35.550] We often go with facility contacts being with us. [40:35.650 --> 40:37.530] We just found it works so much better. [40:37.530 --> 40:40.090] It avoids problems like the Iowa courthouse case. [40:41.090 --> 40:48.850] And, you know, the facility's internal security team, they are usually so pumped to come with us on a red team engagement and learn what we're doing. [40:49.170 --> 40:53.410] And, you know, they get better training than we could ever give them in a controlled environment. [40:53.410 --> 40:54.270] when doing that. [40:54.490 --> 40:58.810] So, we're usually going to do that instead of using the letter of authorization. [40:59.130 --> 41:03.810] We will also get that letter of authorization in case we get separated because we don't want to take that risk. [41:04.270 --> 41:04.870] But, great point. [41:05.630 --> 41:05.950] Yeah. [41:06.370 --> 41:16.570] Another reason why facilities really like being with us when we're doing engagements is it's a lot more convincing for corporates to fund better security practices within the company. [41:16.950 --> 41:27.990] So, you know, if they can give like a first-hand account of all the things that they saw, all the bypasses, how quickly we're able to do things, then they're a lot more likely to be able to convince corporates to spend that money on fixes and things like that. [41:32.570 --> 41:32.970] Hi. [41:32.970 --> 41:34.550] Cameras and motion sensors. [41:34.730 --> 41:39.650] How much do most enterprises feel that they're safe because of those? [41:39.790 --> 41:44.530] They're like, well, I mean, our locks might be whatever, but like we've got cameras up there and someone's watching those, right? [41:44.530 --> 41:46.110] How do you convince them? [41:46.610 --> 41:50.810] I mean, is it just through going through this process and saying, well, we got in and you didn't see us? [41:50.890 --> 41:53.410] Or what's the conversation look like on that side? [41:53.730 --> 41:54.790] It's a great question. [41:54.790 --> 41:57.930] And it depends on the threat model and the business model, right? [41:58.170 --> 42:03.390] So, we, you know, we're ultimately protecting our clients' businesses and their operation. [42:03.950 --> 42:07.730] The facility is a tool for that, but the facility is not the end goal. [42:07.910 --> 42:16.190] So, many businesses, they choose to transfer that risk and get insurance rather than taking on the risk head on and hardening their facility, right? [42:16.330 --> 42:22.910] So, in that case, if they've got a camera that will show after the fact what happened and allow them to make that insurance claim, they are good with that. [42:23.030 --> 42:27.550] And if they're protecting just assets and not data, that's a perfectly acceptable thing to do. [42:27.790 --> 42:29.710] So, sometimes that's okay, right? [42:29.810 --> 42:31.530] But you got to take it from a risk-based perspective. [42:31.710 --> 42:39.970] And if they're protecting data where it would be catastrophic and you can't just insurance your way out of that, that's something where we're going to be having that conversation. [42:39.970 --> 42:47.610] So, yeah, you know, we're going to take it from a business risk and business continuity perspective and look at it that way. [42:47.810 --> 42:50.850] And then, of course, the analysis that I showed right at the beginning. [42:51.330 --> 42:53.210] So, for cameras and motion sensors, right? [42:53.570 --> 42:57.930] So, you know, we're showing where all the cameras can see, where all the motion sensors can see. [42:58.230 --> 43:02.530] We are plotting that out very rigorously and showing them exactly how someone can get in. [43:02.710 --> 43:07.610] And so, that just provides a little bit of scientific method to back up what we're saying. [43:09.070 --> 43:14.070] Yeah, and the other thing to consider with cameras is that conditions may vary. [43:14.310 --> 43:23.150] So, a camera that can see perfectly well during the day might not be able to see the back of a not-well-lit parking lot at night, during a storm, when it's windy, something like that. [43:23.410 --> 43:29.090] You know, so there's a lot of things that, like, you can't entirely rely on a camera to take care of. [43:29.190 --> 43:30.730] And then on top of that is the response. [43:30.730 --> 43:36.550] So, even if someone shows up on that screen, will the response be appropriate and will it be timely? [43:36.930 --> 43:48.290] You know, if your response to seeing somebody on the camera is going there and seeing if they're still there, well, if it takes you 15 minutes to get there and they're gone, well, I guess there's nothing we can do, right? [43:48.670 --> 43:58.450] So, you know, that's... there's a lot of things to consider to look at security as, like, a whole unit rather than just, oh, these little details are fine, we don't need to worry about them. [43:58.690 --> 44:02.190] So, you need to consider all of these aspects of, you know, your security. [44:03.390 --> 44:05.250] Yeah, it's a tricky problem, right? [44:05.370 --> 44:14.430] And so, we could do a whole other day-long talk on running a security operations center and how you're going to actually look at that footage and figure out where to send your response team. [44:15.330 --> 44:17.250] But...so, that was a long-winded answer, but great question. [44:19.910 --> 44:27.790] Do you have any memorable anecdotes you could share about getting caught and either successfully or unsuccessfully talking your way out of it? [44:29.850 --> 44:33.370] So, we have to be a little bit more general in what we share because we're ND8 on everything. [44:35.310 --> 44:55.330] But, yeah, I mean, most of the time when we're caught by, you know, maintenance and caretaking and whatnot, when we're going in after hours, because we're often doing that, it's, you know, we're...we'll often pretend to be their supervisor or an OSHA inspector or something like that. [44:55.790 --> 45:00.430] And, you know, you just have that body language and don't even say a word, right? [45:00.550 --> 45:03.050] And there's been all kinds of studies on this, right? [45:03.170 --> 45:09.810] You know, that first quarter second of interacting with someone and you've made up your mind on who that person is and whether they're trustworthy and whatnot, right? [45:09.810 --> 45:11.010] So, you have that body language. [45:11.250 --> 45:13.470] You don't pretend like, oh, shit, I just got caught. [45:13.790 --> 45:16.910] You know, you act like, okay, I'm your boss, all right? [45:16.910 --> 45:18.810] You justify to me why you're here. [45:20.090 --> 45:22.270] And that works very effectively, right? [45:22.410 --> 45:27.830] And then during the daytime, we're doing more social engineering type of working with the folks that are actually on scene. [45:27.850 --> 45:34.670] And in that case, we're going to be the maintenance staff or the locksmith or we're going to be pretending to just work there and in a big company that works. [45:34.850 --> 45:40.530] And so, when people call us out on it, in that case, if they have a process, it generally works fairly well. [45:41.010 --> 45:47.850] And if they don't, then we're going to advise them on how to build out that process so that they can actually authenticate visitors and determine that, no, we don't work here. [45:47.970 --> 45:48.850] We're not supposed to be here. [45:49.470 --> 45:56.950] Yeah, and we've definitely had occasions where we'd be in a space that, you know, the public shouldn't have access to. [45:57.250 --> 46:00.830] And a maintenance person will come in and start explaining to us why they're there. [46:01.290 --> 46:03.510] So, you know, they'll be like, oh, I'm here to fix this. [46:03.610 --> 46:05.270] And it's like, okay, you, okay, go ahead. [46:05.430 --> 46:08.690] And we'll tell them to go ahead and they'll be none the wiser as well. [46:11.880 --> 46:13.900] I have a question from the Matrix chat. [46:13.900 --> 46:19.560] David asks, what pretexts have you used when getting caught with, for example, a giant under-the-door tool? [46:20.300 --> 46:24.460] The line of saying you're the locksmith doesn't seem like it would work. [46:26.180 --> 46:38.900] Yep, so in that case, we didn't even need to use a pretext because we could tell that, you know, this was someone working late, busy, stressed out. [46:38.900 --> 46:41.300] He did not want to deal with us. [46:41.740 --> 46:45.260] So, you know, we just apologized and got out of his way. [46:45.580 --> 46:48.780] And he shot us a sideways look and he was on his way. [46:48.860 --> 46:54.820] So that's the one time that we were caught with that when we couldn't make ourselves out to be locksmiths or whatnot. [46:56.220 --> 46:59.760] And so, you know, it depends on the facility and security culture. [46:59.760 --> 47:02.840] But unfortunately, you often don't need to pull out your pretext, right? [47:02.940 --> 47:05.980] Body language is all, and they'll move on. [47:07.480 --> 47:11.580] You talk about alarms getting turned off when they ring too much. [47:11.720 --> 47:15.980] Have you ever, like, set off alarms until somebody just turns them off? [47:17.720 --> 47:25.480] So, it's the sort of thing that we advise clients on constantly because, I mean, sometimes it's a malicious actor that's setting them off. [47:25.600 --> 47:27.280] Often it's just the wind or animals. [47:29.180 --> 47:38.560] But we don't do it super, super often because it's just a pain in the butt for the customer, and it does degrade their security. [47:38.640 --> 47:39.800] And we don't want to be doing that. [47:40.820 --> 47:43.520] So, you know, what we'll do is we'll do testing, right? [47:43.520 --> 47:46.460] So we will test a single time and determine if they've gotten to that point. [47:46.680 --> 47:51.820] And we will build up their Security Operations Center's policies and procedures to make sure that they handle that effectively. [47:53.100 --> 47:59.580] But we usually try not to actually attempt that sort of thing because it's just a pain for the client. [48:01.680 --> 48:03.060] Hey, I was curious. [48:03.160 --> 48:05.660] Have you ever seen anyone deal with tailgating effectively? [48:05.960 --> 48:14.940] And I ask that because I work for a megacorp, and I travel to all our offices, and it's almost always quick for me to just kind of mill around and get myself in and deal with security and whatnot? [48:17.180 --> 48:27.200] Tailgating is a tough problem, you know, especially for workplaces that want to maintain a bit of a more open culture so you don't have those, like, giant turnstiles and whatnot. [48:28.020 --> 48:42.420] The half-height gates, right, like the gates you have on the subway, you know, so those you can hop over them, but those in combination with someone at reception who's going to see you hop over or whoever you're tailgating behind, right, so a full-height door is going to see you hop over. [48:42.640 --> 48:43.780] Those are very effective. [48:44.560 --> 48:54.880] There's a great scene in Mr. Robot on how those might not be effective, but, you know, it gets you down significantly in terms of tailgaters being able to get in. [48:55.260 --> 48:56.940] Tailgating is a huge problem, right? [48:57.060 --> 49:01.480] And so we advise generally segmenting your physical space, right? [49:01.480 --> 49:07.020] So the place that most employees have access and you can tailgate into, you should not have anything important there. [49:07.240 --> 49:15.320] The only thing you should lose if an intruder gets in is maybe a couple of encrypted laptops, right, just monetary value and nothing irreplaceable. [49:15.520 --> 49:19.560] And then your server room and whatnot, you're going to have a little bit more beefy security on that. [49:19.820 --> 49:23.100] Man traps work, yeah. [49:23.420 --> 49:27.100] They're costly and they're a big impediment to employee movement. [49:27.520 --> 49:31.700] They're, you know, a lot of employers don't like having that culture with the man traps in there. [49:31.880 --> 49:36.520] So, you know, they're good for where they're necessary, but it's often not the right solution. [49:37.520 --> 49:38.320] Yeah, and... [49:40.060 --> 49:40.900] Oh, yeah, sorry. [49:41.620 --> 49:43.840] So the question was, man traps work? [49:44.040 --> 49:46.500] And what is a man trap, right? [49:46.640 --> 49:55.900] So it is a turnstile or a turnstile type door or two doors where you go in the first one, it locks behind you, you are now stuck between those two doors. [49:55.900 --> 50:04.220] And if you don't have the credential to get through, you are stuck in there until a guard comes and can verify who you are. [50:04.960 --> 50:10.780] And so, obviously, you need a very robust human response situation for that to be okayed by the fire marshal. [50:11.400 --> 50:16.440] You know, it's a pretty disruptive option and an expensive option. [50:17.120 --> 50:17.640] Yeah. [50:17.940 --> 50:23.800] A lot of times we find, you know, the best thing for the company is just to have a better security culture. [50:23.800 --> 50:29.420] So, you know, calling out people that you don't recognize that are walking around in a space that you know should be restricted. [50:29.960 --> 50:31.480] You know, not letting people tailgate. [50:31.660 --> 50:36.400] And, you know, it's easier said than done, but it's very important to promote that security culture within the workspace. [50:36.980 --> 50:42.780] And, you know, don't be afraid to kind of call someone out if you see someone doing something that they shouldn't be. [50:42.780 --> 50:50.720] You know, a lot of the times we will see, you know, people that will kind of side-eye us when we're on a test, but they won't do anything. [50:50.840 --> 50:51.560] They won't call it in. [50:51.640 --> 50:53.480] They won't stop us and ask where we're going. [50:53.760 --> 50:54.600] They won't do anything. [50:54.680 --> 50:56.960] They'll just kind of be like, oh, that's weird, and keep going about their day. [50:57.360 --> 51:03.180] So, it's really important to have that security culture and not be afraid to be like, hey, are you supposed to be here? [51:03.820 --> 51:07.800] So, I'd say that's kind of one of the bigger things for, like, social engineering and whatnot. [51:08.420 --> 51:08.780] Yeah. [51:09.200 --> 51:11.160] You mentioned exit sensors. [51:11.400 --> 51:12.760] I wanted to hear more about that. [51:12.860 --> 51:17.880] It seems like a good candidate for a bypass, but, like, maybe slip a piece of paper to trigger them or something. [51:18.060 --> 51:20.140] But you said it seems like there's also a concern there. [51:20.820 --> 51:21.100] Yep. [51:21.740 --> 51:24.660] So, yeah, request to exit sensors, right? [51:24.840 --> 51:29.300] So, when the door opens and you've badged in, that's a normal entry, no alarm. [51:29.560 --> 51:37.380] When you're exiting, there's going to be some sort of sensor, a button, or a passive infrared sensor to detect that someone's exiting and cause that to not alarm as well. [51:38.320 --> 51:43.500] So, passive infrared is by far the most common, and you might have seen the canned air attack that you can do with those. [51:45.100 --> 51:50.860] That's difficult to pull off when you don't have a double door, so you can go in the side right near it. [51:51.020 --> 51:57.260] When you're down at the ground, it's usually too far, but with more fluid, it is something that's doable. [51:57.260 --> 52:03.780] So, you know, request to exit sensors, yeah, they're definitely something that can be hacked. [52:06.760 --> 52:08.160] There's some solutions, right? [52:08.280 --> 52:15.140] Like, Interlogix makes a dual technology one that also has range control radar, and so it makes it a whole lot harder to trip out. [52:15.740 --> 52:17.280] Interlogix, unfortunately, just went out of business. [52:17.280 --> 52:22.800] So, one of our favorite recommended upgrades is getting harder to do, right? [52:22.960 --> 52:28.440] But another option that you can implement is a badge-in, badge-out system with pass-back detection, right? [52:28.560 --> 52:37.240] And so that way, you know that if someone's exiting, you're controlling that on your access controller as well, and there's no more any request to access sensor to hack. [52:38.540 --> 52:43.000] Yeah, and another thing that we do with a lot of clients is tuning the sensor. [52:43.680 --> 52:55.000] So, sometimes the sensor will be too sensitive, and if it's in an area where a lot of people walk past, you can just open the locked door without needing to really do anything, because there's people walking close enough on the other side of the door. [52:55.500 --> 53:03.300] So, you know, you want to tune it so that it only detects people exiting, but you don't want it to be tuned in such a way that it doesn't detect people and sets off a false alarm as well. [53:03.300 --> 53:05.440] So, it's kind of a balancing game there as well. [53:05.640 --> 53:07.380] Yeah, it's a big cause of false alarms. [53:08.060 --> 53:08.120] Yeah. [53:09.140 --> 53:11.280] There's so many moving parts with these systems, right? [53:11.400 --> 53:12.400] So much that can go wrong. [53:12.400 --> 53:17.240] You really need some full-time staff for a big facility, right? [53:17.360 --> 53:20.940] That their whole job is making sure these are staying up to tune and keeping them maintained. [53:21.280 --> 53:35.880] Yeah, and especially in like a larger facility, you have so many of these doors, and so you need like a really big team because, you know, even if one door is slightly out of the way and a little bit off, well, that's a huge vulnerability that people can get in through. [53:37.920 --> 53:40.400] So, we're getting the stop sign from our lovely MC. [53:40.840 --> 53:42.300] So, thank you very much, folks. [53:42.400 --> 53:43.520] It was a pleasure taking your questions. [53:47.660 --> 53:55.580] Also, if you guys want to come check out the door in person, we'll probably be in the hardware hacking area after this with all this stuff, so you guys can come play around with it, do whatever you want. [53:55.980 --> 53:56.340] Yeah. [53:56.840 --> 53:57.320] Thank you, guys. [54:00.440 --> 54:03.320] And thank you to both of them for such an amazing talk. [54:03.520 --> 54:04.940] I just want to give you guys a heads-up. [54:05.020 --> 54:09.540] In about 10 minutes, the keynote speaker will be streamed in this room at 2 o'clock. [54:12.340 --> 54:13.560] Enjoy the rest of the conference. [54:15.760 --> 54:20.720] Okay, so this room is going to get streamed, and I guess the keynote is the other building. [54:20.860 --> 54:21.700] Okay, want to go there? [54:21.900 --> 54:22.100] Yeah. [54:22.100 --> 54:23.700] Thank you.