Still there are IMHO limits, this story appears to me "too easy".
From the article:
>The manufacturing facility looked like a prison. No windows, heavy iron gates, no landscaping. Generally a monstrosity of architecture.
>This facility had armed guards, badge readers, biometric security controls and turnstiles at every entrance.
The above implies that the firm is attempting to have a higher level of security than most offices/factories.
I would have expected that the pentester had to do something more than what she wrote.
I mean, you first put up some basic security/access policies, and later you hire someone to test them.
And I cannot believe that:
>I gained network access and stole several thousands of dollars in physical primitives by picking my way through cheap locks.
One thing is getting access to the premises, another one is managing to be left alone and allowed to have network access, start lockpicking locks, etc.
>Someone leaves their computer unlocked when they walk away -> network access.
Sure, and how much time do you have, alone in someone else's office, sitting down at their desk to steal info?
First part of the article is about having been shown around by "Mary" and her boss, and then being with other employees, when did the pentester have the time to access network, lockpick doors, etc.?
I need about fifteen seconds of quality time with an unlocked computer before it belongs to me. Devices like the USB Rubber Ducky ( https://hakshop.com/products/usb-rubber-ducky-deluxe ) make it trivial to compromise unlocked systems within seconds. Stealing info can then be done at your leisure, from anywhere you have internet access.
Just because she skipped over some unimportant parts of the story doesn't mean she didn't have plenty of time after being shown around the building to accomplish her objectives. She does address this, too:
> I took FOREVER looking around this office space, and eventually they said their goodbyes because they had to go back to work. They had a strict policy of escorting visitors. But I had been seen walking around with trusted insiders so no one questioned me.
> I was free to take my time. I made myself at home. My main objective at this site was to weasel my way into private corner offices.
>Just because she skipped over some unimportant parts of the story doesn't mean she didn't have plenty of time after being shown around the building to accomplish her objectives.
She didn't skip anything, the quote is this one, however (earlier in the article):
>I was given complete and unaccompanied access to the facility where I stayed for several hours.
That is "building #1", the parts you quoted are related to "building #2".
If you did this job, you would not be surprised by the ease with which you can pull off these sorts of things. I've been doing this for a couple years now, and it's terrifyingly easy to compromise data or physical security for organizations that really should know better.
You can pick office furniture locks with a binder clip and a paper clip, which you can often find in the unlocked portions of the office furniture. The paper clip is permanently disfigured in the process, but the binder clip can be put back unharmed.
I know, because I have actually done this occasionally, to remind myself to never leave anything valuable at the office. It can take less than 60 seconds to go from empty-handed to an opened lock. A few more seconds to re-lock it with your makeshift pick.
Cheap locks might as well not exist to a professional attacker. They barely exist for an amateur motivated by curiosity or boredom.
Door locks are a bit more difficult, and may require more sophisticated tools, but those are left unlocked more often, for the extremely ironic reason that the employees that have greatest use for them typically don't have the keys. The only keyed doors that ever get locked are upper management offices, the office supply closet, and wherever it is they keep the sodas and snacks for visiting customers.
As with online security, companies are only willing to pay for the illusion of security. Genuine physical security is difficult, expensive, and wears heavily on employee morale.
That's very true. In many cases, that's even _perfectly fine_. Not every organization needs enough physical security to deter a determined attacker. The ones that do hire people like Sophie (or me), and take the lessons to heart. Even if the organization doesn't make changes to their physical security posture as a result, they know what to be aware of, and they know where their weaknesses are.
A lot of our security--both network and physical--is based on the illusion of security. One of the most important things that penetration testing does is to make organizations aware of the issues, to put the bug in their ear to remind them that security is important, and shouldn't be an afterthought. We see lots of organizations make material improvements to their security as a result of red team exercises. We also see a lot of organizations that don't. It's disheartening when that happens, but I like to think I help make a difference. The next data breach might be mitigated by our recommendations, or even prevented entirely.
Heard a story recently of a major MSP forgetting to disable the Ethernet port on the back of a set top box, and it provided access to a VLAN with direct access to the company’s back-end systems. They didn’t have passwords on many of their databases because they assumed the firewall would protect them. Pwnage ensued.
This is a big company you have definitely heard of. You didn’t hear about the data breach because they basically paid the hacker off with a security consulting contract, then said he was a pen tester. This happens all the time.
Most companies are really bad at security. The bigger they are, the worse they are.
Still there are IMHO limits, this story appears to me "too easy".
From the article:
>The manufacturing facility looked like a prison. No windows, heavy iron gates, no landscaping. Generally a monstrosity of architecture.
>This facility had armed guards, badge readers, biometric security controls and turnstiles at every entrance.
The above implies that the firm is attempting to have a higher level of security than most offices/factories.
I would have expected that the pentester had to do something more than what she wrote.
I mean, you first put up some basic security/access policies, and later you hire someone to test them.
And I cannot believe that:
>I gained network access and stole several thousands of dollars in physical primitives by picking my way through cheap locks.
One thing is getting access to the premises, another one is managing to be left alone and allowed to have network access, start lockpicking locks, etc.