3 ms·
It often seems like the biggest con that physical pen testers pull on their clients is convincing them to hire them in the first place. What's the threat, exact
by munin 9y ago
It often seems like the biggest con that physical pen testers pull on their clients is convincing them to hire them in the first place. What's the threat, exactly?
Let's say you do something like BeyondCorp. Gaining "network access" doesn't mean anything any more, because you can "gain" "network access" from anywhere in the world since it's all on the internet. Physical access shouldn't be the perimeter, identity should be.
Is that a tall bar? Sure, but it's basically the bar. Instead of wasting money on fancy pen-tests, put that money into the IT budget to get identity management up to that point.
Next, is the risk really that someone will gamble a physical snoop into a secure compound, where the possible negative outcomes are police custody and prison time, for a score of a few thousand dollars, as Sophie mentions in the article? Sure, that's a risk, hobos would cruise in and swipe a laptop off someones desk to sell it on ebay for booze money. Do you need to pay a pentesting shop $80k to know that? No. And, the risk is basically the same as if an employee takes home a laptop and their car is broken into. The fix is the same too: encrypt everything at rest.
These are all basic lessons that you can learn by downloading a CISSP study guide.
However, I think that there will always be failure points because what you want to defend against this is a culture of security, and it's difficult to instill that even when you work in an environment that is rightfully charged with maintaining high security. It's boring and generates friction. If someone shows up for an important meeting at a high security building and they forgot their ID, the guards will not accept any amount of "do you know who I am" because they know that when their supervisor is called in, they'll be backed up. Everyone else knows this too, on some level, so there's much more of a culture of "why didn't X happen?" "oh, there was a paperwork SNAFU somewhere and security stopped us at the front door" "lol! typical! we'll try again next week." That just wouldn't fly in the private sector: because the risk doesn't weigh anywhere near as much as the reward for just cutting the corner and doing it without the I's dotted and T's crossed.
So, sure. You can fast-talk your way past the rent-a-cop at the front desk of the offices of an aluminum siding manufacturing plant and swipe some coffee cups and staplers out of the supply closet, and you'll always be able to do this...
- goialoq 9y agoMany facilities have valuable physical objects, paper documents, and material that could be vandalized and become dangerous.
- salamancara 9y agoYou’re testing a process end-to-end and identifying places where the policy is either too cumbersome or ineffective. Sometimes it’s a training issue, sometimes their processes just suck and need to be changed. Physical access is enough to do a lot of damage. You could drop a 4G wireless sniffer hidden in a wall wart. You can grab someone’s password off a post-it note and then fish the RSA token out of their purse when they go to the bathroom. Now you’ve defeated 2FA and have network access from the outside. Just metasploit/nmap scan, find a vulnerable system and you’re in business. Check out the Bash Bunny — it’s a quad core attack platform running Linux. It looks like a USB drive, but emulates a whole bunch of different USB devices (keyboards, cameras, displays, etc) paired with attack tools to break into the system. Basically, if you get network access, there are almost certainly vulnerabilities somewhere. Imagine someone like the CIA who buys 0-day exploits by the hundreds — physical access makes total pwnage inevitable.
- walshemj 9y agoI got asked to do this for a FTSE 100 client (Rank) of ours and I managed to from a standing start with physical access and to extract the secrets and crack them.
- cwkoss 9y agoPhysical access to a device usually allows you to get full control, or at least be able to 'wiretap' its network packets. Lots of fun little devices to screen capture or keylog allow an attacker to get credentials and harvest secure information. Many of these devices have wireless capabilities now, so you only need to enter facility once to plant it, and then you can download the capture from outside the building. Very few companies can prevent attacks when the attacker has valid credentials. Once you're inside a network, you're past all of the perimeter defenses, and most companies have tons of secure information flying around. Mimikatz and responder are devastating for most Windows networks: grab the credentials, use them to pivot or get more info to grab more credentials, repeat until you get an it admin account, and you've got the keys to the castle.