Physical Penetration Testing
Return Home
Introduction to physical penetration tests
In this blog post I’m going to try and give an overview of physical penetration tests and how to start doing them from my own perspective (European context, we have to worry less about guns). In addition I will focus on the type of tests where a target asks you to ‘casually’ break in and gain access to a room, plant a device or steal some specific information. ‘Casually’, what does that even mean? In my experience it means that you get one or two days for your preparations and one day to execute the attack. Doesn’t seem like a lot, but you’d be surprised how many targets can be breached with minimal preparations, some courage and the fact that you aren’t really going to jail when caught ;)
I’ll Let Myself In: Tactics of Physical Pen Testers
Many organizations are accustomed to being scared at the results of their network scans and digital penetration tests, but seldom do these tests yield outright “surprise” across an entire enterprise. Some servers are unpatched, some software is vulnerable, and networks are often not properly segmented. No huge shocks there. As head of a Physical Penetration team, however, my deliverable day tends to be quite different. With faces agog, executives routinely watch me describe (or show video) of their doors and cabinets popping open in seconds. This presentation will highlight some of the most exciting and shocking methods by which my team and I routinely let ourselves in on physical jobs.
DefCon 15 - T112 - No-Tech Hacking
Talk about hacking without the need for expensive, unnecessary tools.
Let me know what you think of this article on twitter @_TheGetch_!