leveraging social engineering in physical security assessments...stephanie “snow” carruthers...

57
Leveraging Social Engineering in Physical Security Assessments Stephanie “Snow” Carruthers October 26, 2017

Upload: others

Post on 04-Apr-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Leveraging Social Engineering in Physical Security Assessments

Stephanie “Snow” Carruthers

October 26, 2017

Page 2: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

About Me

▪ Professional Social Engineer

▪ DEF CON 22 SECTF Black Badge (2014)

▪ SAINTCON Vault Physical Security Challenge Black Badge (2017)

▪ Tabletop Games

▪ Salt Lake City, Utah

Twitter: @_sn0ww

Stephanie

Page 3: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Proactive Security Services

MindPoint Group’s Proactive Security services allow organizations to become aware of their vulnerabilities and understand what steps to take to secure their information. MPG’s services include:

• Technical Security Assessments

• Application Security

• Penetration Testing

• Social Engineering

Page 4: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Agenda

A OSINT

Y Pretext Development

Agenda

(

I Recon

2 On-Site Goals

O Training

Page 5: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

• Trappings• Badges• Jobs• Out-of-office

Employees• Access Control Systems• Guards• Cameras• Nearby Restaurants• Maps/Floor Plans• Event Calendar

Company Location

• Names• Badges• Business Cards• Uniform

Vendors

Page 6: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Social Media

Page 7: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Business Casual Dress

Some with badges some

without

TRAPPINGS

D

Employee Turnstile Stairs on the leftGlass elevator

FLOOR PLAN

A

HID Clamshell Badge

RFID SYSTEM

4

LayoutDesign

Color Codes

BADGES

T

Page 8: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Problems with

policies….

Page 9: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Page 10: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Page 11: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Security Through

Obscurity

Page 12: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Floor Plans, building information, and

company calendars… oh my!

Page 13: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Places to check

• http://www.loopnet.com

• Real Estate Companies

• Google Maps

• Company website for building management

company

• Company website for calendars

Page 14: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Page 15: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Page 16: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Watering Holes

Page 17: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Recon via YouTubeNew company building, internships, jobs are all common

reasons why companies make videos to promote

themselves. These videos typically contain a lot of useful

information for us.

Page 18: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 19: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 20: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 21: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 22: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 23: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off
Page 24: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

OSINT

Vendors

Page 25: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Pretext Creation

Do NOT impersonate:

• Law Enforcement

• Doctors

• Lawyers

• Maybe others depending on

state law

Pretext Laws

Page 26: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Pretext Creation

Scope Limitations

• Clothing• Transportation• Badges• Business Cards• Clipboards/Documents

Appearance

Documentation of Pretext• Internal • ExternalPretext Reuse

Page 27: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Pretext Creation

Why pretext reuse isn’t always a good idea…

Image Source: https://spellboundbookshop.com/wp-content/uploads/2016/08/storytime-gold.jpg

Page 28: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Pretext Creation

Always have a plan B, and C…

Image Source: https://spellboundbookshop.com/wp-content/uploads/2016/08/storytime-gold.jpg

Page 29: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Recon

Reconnaissance

Page 30: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Recon

• Entrances• Public• Employee Only

• Operating Hours• Access Control Systems• Loading Docks/Service

bays• Dumpsters

Perimeter• Physical Security

Controls• Locks• Turnstiles• RFID

• Guards• Cameras

Interior

• Coffee Shops• Restaurants

Nearby

Page 31: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Risk Chart

Medium

Low

High

Page 32: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Tailgating & Piggybacking

Tailgating

Tailgating means that others are following through

the door without the knowledge of the person who

has opened the door

Piggybacking

Piggybacking implies that the person who has

opened the door with their credentials knows that

others are following them into a secure area

Page 33: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Tailgating & Piggybacking

My favorite piggybacking story…

Image Source: https://spellboundbookshop.com/wp-content/uploads/2016/08/storytime-gold.jpg

Page 34: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Document Management

Where to look:

• Trash Cans

• Dumpsters

• Shred Bins

• Breakrooms

• Mailrooms

• Bathrooms

• Employee Desks

• Conference Rooms

• Print Rooms

Image Source: http://www.shrednorth.com/wp-content/uploads/2013/10/shred-north-shredding-containers.jpg

Page 35: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Elicitation

What I Do:

• Ask an employee to perform a task:Print a file on a USB

Let me in without a badge

• Ask an employee to provide information:I’m with IT, what's your password?

How do you lock the building?

Where are the patient records?

How do VIPs check-in?

Are cameras being actively monitored?

Page 36: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Elicitation

One of my favorite pretexts for elicitation…

Image Source: https://spellboundbookshop.com/wp-content/uploads/2016/08/storytime-gold.jpg

Page 37: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

RFID Cloning

What to use:

• Proxmark

• RFIDler

• Homebrew Solution

• Huntsman (Based off

BishopFox’s Tastic)

Tips:

1. Clone as many as you can during recon

2. Don’t keep RFID cards on you while trying to capture –

Oops …

Page 38: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Non-Destructive Entry

What I Use:

• Simple Lockpick set (thx @Serepick)

• Bogotas

• Shims

• Airbag (thx China)

• Thumb Latch Tool (thx @deviantollam)

• Crash bar tool (thx Sparrows)

• Under the door tool (thx @RiftRecon)

Page 39: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Picking locks…

The risk has to be worth the reward…

Image Source: https://spellboundbookshop.com/wp-content/uploads/2016/08/storytime-gold.jpg

Page 40: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

USB Drops

Where you do not put them:

• A Parking Lot (Thx Lawyer)

Where do I put them:

• Employee Desks

• Mail rooms, in mailboxes

• Interoffice Mail

• In a white envelope with someone’s name on

them (Thx Jayson Street)

Image Source: http://image.made-in-china.com/43f34j00GnYabfVsOPcI/Slid-Design-USB-Flash-Drive-Memory-Stick-ET012-.jpg

Page 41: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

USB Drops

Image Source: http://assets.eflorist.com/assets/products/PHR_/T50-3A.jpg

We’ve added them onto

floral and cookie deliveries.

Page 42: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

USB Drops

What do I name them:

• Q4 Company X Employee Terminations

• 2017 Payroll

• Q4 Bonuses

• 2017 Payroll Decreases

• Company XYZ Merger 2018

Page 43: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

USB DropsStatistics for 2017

20%

80%

Just USB left in the open

Opened Not Opened

60%

40%

USB in envelop with employee name

Opened Not Opened

Page 44: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

USB Drops

Page 45: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

Network Port SecurityThis is done as a minor subcomponent. It is not the holy grail of the test.

What I do:

• Plug a laptop in and run a simple ping scan

Where I do it:

• Conference Rooms

• Unattended Lobbies

• Cubicle Areas

• The Data Center

• Really, where ever I see a jack and an opportunity

Page 46: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

TheftStuff I jack:

• Laptops

• Phones

• Files

• Building Keys

• Badges

Where I put it:

A designated office which I predetermine with the point of

contact.

Page 47: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

On-Site Goals

After-Hours Access

Why come back at night:

• Different staff are working

• No staff is present

• Building usually has more security features to test

What do I do:

• Rinse and repeat!

Page 48: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Risk Chart

Medium

Low

High

• After Hours Access• NDE• Theft

• Network Port Security• Elicitation• Badge Replication

• Tailgating/Piggybacking• Document Management• USB Drops• RFID Cloning

Page 49: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Tips & Tricks

Image Source: http://trikkeacademy.com/wordpress/wp-content/uploads/2016/02/tips-tricks.jpg

Page 50: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Tips & Tricks

Bathrooms are your friend

Bathrooms are generally a great place to hide if you

need to duck away or you think someone is getting

suspicious.

Sneak into a bathroom right before closing time and

wait for everyone to leave.

Page 51: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Tips & Tricks

Get out of jail free card…

Fake copies don’t make you friends. I typically bring

the entire statement of work with me.

Image Source: http://www.thepostturtle.com/wp-content/uploads/2015/02/Get-Out-of-Jail-Free.jpg

Page 52: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Tips & Tricks

“Out of Order”

Place an out of order sign over a shredder and

place an empty bin next to it. Return later in the day

to collect your documents.

Image Source: https://cdn2.bigcommerce.com/server4600/10c6f/products/1525/images/2790/WS26007_Red_Out_Of_Order_sign__53859.1397133707.450.450.png?c=2

Page 53: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Tips & Tricks

Spilled coffee

Spill some coffee on a fake resume.

Ask the front desk employee to help you out of a jam

and print off a fresh copy from your convenient USB

drive.

Image Source: https://static1.squarespace.com/static/54adb763e4b0faae8683e555/t/54b539e5e4b09f5e2402e436/1421680203051/

Page 54: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Training

“Tell me and I forget. Teach me and I remember. Involve me and I learn.” – Benjamin Franklin

• “Teachable moments” can be conducted

on the spot or the next day after the

assessment.

• Hold on-site security awareness training

using the results from the assessment.

Page 55: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Recap

A OSINT

Y Pretext Development

Recap

(

I Recon

2 On-Site Goals

O Training

Page 56: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Q&A

Questions?

Page 57: Leveraging Social Engineering in Physical Security Assessments...Stephanie “Snow” Carruthers October 26, 2017. About Me Professional Social Engineer ... • Huntsman (Based off

Contact Us

Stephanie Carruthers

Twitter: @_sn0ww

Social Engineer Team Lead

[email protected]

www.mindpointgroup.com

Follow Us on Social Media