06/03/2025
Exploiting information leakage on a Physical test
We have observed that one of the most overlooked aspects of red teaming or physical pe*******on testing is when information is leaked through people exposing physical keys. We have seen organizations with keys hanging in plain view behind reception.
We have noticed maintenance staff with keys hanging on a chain or from a belt.
On many occasions we have seen people routinely leave keys on desks.
However, when the keys are exposed, all it takes is a simple photograph or video for us to be able to take advantage. We can take a quick snap on a phone, a surveillance photo from a range of many meters away or capture a short video clip. Even when the resulting shot is not perfect, some manipulation in graphics editing software can transform it into a flat image of the key that we can use to decode the bitting.
We have options and can choose to use existing overlays (or generate one from key and pinning charts) or an app on a phone such as Frenchkey's KeyDecoder.
(https://play.google.com/store/apps/details?id=com.keydecoder)
Snap Decoder
(https://play.google.com/store/apps/details?id=com.whsoftware.snapdecoderand
we end up with the bitting code of the key.
We can reproduce the key by filing, duplication with space & depth keys and origination if blanks are readily available or 3D printing when they aren't. As we demonstrate in the below video:
We then utilize the produced key for persistent, surreptitious or even clandestine access to areas that the key gives us access.
The difficulty for us is in gaining a photo of the keys we need to achieve our objectives. Targeting privileged users such as security guards or building managers can make life easier or even infiltrating or bribing the cleaning crew, who collect a master key for the building when their shift starts. All are common ways we gain access to privileged keys and our targets!
Physical Red Team Fundamentals @ X33f Con 2025
June 9-11, 2025 Gdynia, Poland,
Let’s break stuff (ethically). 🔓
➡️ https://www.x33fcon.com/ #!t/CovertEntry.md
OR
Physical Access Control Systems
July 15th & 16th, 2025 Virtually,
➡️ https://shop.redteamalliance.com/products/rfid-hacking-and-defense-physical-access-control-systems-pacs-proxmark3-training?variant=42073986302000
For more information, look no further than the best with Mr. Babak Javadi by reading more on his in depth post about information leakage.
➡️ https://www.linkedin.com/pulse/real-world-keys-leak-information-default-babak-javadi-uhtec/?trackingId=UR16vMq33V70mrziVhEz2w%3D%3D