Physicals, Badges, and why it matters

No ratings

Presented at GrrCon2018 2018 by

This talk will cover recent developments in physical security and badge access controls. Research presented at Hushcon and Thotcon in the past year has created a whole new approach towards gaining unauthorized physical access by attacking the door controllers directly on the network. Recently released exploits on these devices allow attackers unfettered access, if they’re willing to set foot inside your building. You can now blame Russia for raiding the break room fridge too! Pacu: Attack and Post-Exploitation in AWSSpencer Gietzen N/AN/ACloud infrastructure security and configuration has been shown to be a difficult task to master. Sysadmins and developers with years of traditional IT experience are now being pushed to the cloud, where there is a whole new set of rules. This is what makes AWS environments particularly exciting to attack as a penetration tester. Best practices are often overlooked or ignored, which can leave gaps throughout an AWS environment that are ripe for exploitation. With an increasing number of breaches leaking AWS secret keys, companies are working to be proactive and are looking for red-team-like post exploitation penetration tests, so that they can be sure that their client data is as safe as possible post-breach. Due to this need and the lack of AWS specific attack tools, I wrote Pacu, a modular, open source Amazon Web Services post exploitation attack tool created and used for Rhino Security Labs pentests. In this talk I will cover how red teamers can use Pacu to simulate real-world attack scenarios against AWS environments, starting from IAM enumeration and scanning through exploitation, privilege escalation, data exfiltration and even providing reporting documentation. It will be released as an open source project to encourage collaboration and discussion of different AWS attack techniques and methodologies with both attackers and defenders. This way, both myself and the community can contribute new modules to expand the functionality and usefulness of Pacu continuously.