Behind Closed Doors - Bypassing RFID Readers

No ratings

Presented at Black Hat Asia 2025 by

Cloning RFID tags - you probably tried it, or at least heard about it.But what if cloning someone's card isn't an easy option? How else can one gain entry into high-security areas without direct access to the credentials?In my presentation, I will discuss techniques for bypassing physical access control security mechanisms in Red Teaming scenarios, accompanied by live demos of the attacks discussed.We will cover:- How to intercept the communication between the reader and the controller that are using the Wiegand protocol;- How to use this entry point to leverage access through different attacks;- How the OSDP protocol addresses the shortcomings of Wiegand, and what are the security implications of using it;- How could you use a DoS attack on a reader to aid you during a Red Team assessment;- What are the other ways to bypass the access control security mechanisms?I will also share some interesting and fun stories from Red Team engagements, demonstrating practical applications of these techniques in real-life scenarios – hopefully without getting caught ;)