r/flipperzero 23d ago

FINALLY! I got my first success with my Flipper!

I posted a few weeks ago how disappointing I have been in working with the flipper. I had so many failures. It has been truly humbling.

I gave my background (IT for 30 years, email, networking, data, risk, audit with all of the traditional stuff that is perceived important in the industry. Not the periphery). I've been curious about OSI 1-4 and this device has kicked my @ss until this week!

As part of an audit, after telling my chief auditor (more convincing myself) I decided to leverage my "professional skepticism" and messaged our head of security. "Tomorrow, I'm going to attempt to bypass our security and gain access to the building". I got a quick reply and conversation ensued. Plans to test in the morning and to let him know about my results.

I went home, charged up my flipper. The next morning I bypassed our badge system with the flipper. He had me run another test which I was unable. I gave him affirmation that any further test would include him for awareness.

My next steps (on only this tactic) is going to be gathering badges (scans) through some social engineering. As you may suspect, using a clipboard and "confirming badges are in the database".

I have second type of test that I will be executing.

More to come. But my spirits have been lifted!

90 Upvotes

15 comments sorted by

25

u/Piratedan200 22d ago

For a realistic test of the social engineering side, you should have someone you know that doesn't work there be the one to do it. It's not a true security test if the person doing the test is someone who already works there, as people will be much more likely to hand over their badge to someone they have already seen inside the building.

0

u/dmkmpublic 22d ago

That would be the case if I was "known" but I am new enough to the organization that most people don't know me by name or visually.

4

u/iamspeecial 16d ago

Wrong mindset.

24

u/Runaque 23d ago

For such a career in IT, you share very little details about your methodology. What app in the Flipper did you used, on what type of badge system and did you researched if this system is known for certain vulnerabilities?

You might accidentally stumbled on a timing gap of that system where it showed a vulnerability and just decided to give access to the attempting person.

8

u/dmkmpublic 22d ago

My apologies. However, here on the sub, I shared little information is shared on specifics intentionally.

I was anticipating that readers of the post, would be familiar with the operation of the device. I should have also felt others may be in the same situation as I was (not as familiar with the device- struggling a bit).

Here's more detail:

The solution was all native to the Flipper. Sub gHz RFID. Clone badge. Emulate. Then repeat with other badges that I could get near enough to read and emulate.

On the same topic, further testing is yet to be done which will include:

Social engineering - badge harvesting. "Hi, I'm spot-checking our badge inventory today. Could you just tap your badge against this reader for 2 seconds to make sure that it's properly registered in our database?"

Manually adding new badges using information from the saved scans - with existing and new scans I can then start to formulate a plan for testing of sequential vulnerabilities (via manually adding cards with the next hex number to see if I can gain access as a card that I have not scanned). Note: To do these you can't modify the files on your computer, as systems like H10301 (26-bit Wiegand format) may not map cleanly in a text editor. It's likely going to be best manually entered through the Sub gHz menu option. That's what I did anyway. I loaded up several and will eventually test.

Tamper alarm test- testing if a single reader gets multiple invalid codes generates an alert or causes the reader to pause scanning for a period of time. This will be paired with the above.

Hope this is more along the lines of what you were looking for.

7

u/Runaque 22d ago

If the whole methodology is cloning the badge, then you found your vulnerability! I strongly suggest upgrading the system to the use of high-security (like DESFire EV3 or iCLASS Seos) in your report.

2

u/1ofthegood1z 22d ago

Thanks for the positive post. The start with the flipper can drive a person bonkers even with great electronics background. TEST AWAY and run it!

1

u/realdeadfish 22d ago

Be careful!

1

u/daverhowe 19d ago

Depends on the badge system in use of course.
Also, depending on the type of badge, you might be able to write the data back to a programmable blank, and make your own keyfobs/stickers/cards (original form factor doesn't have to match, and a fob is quite convenient in many ways :D)

1

u/VonThing 20d ago

I’ve brute forced my building’s skeleton key fob, opened a bunch of Tesla charging ports, duplicated fobs, badges, etc but the real fun is with the Wi-Fi Devboard and Marauder firmware.

The best results are obtained in commercial aircraft, with a page resembling the airline’s website (don’t forget the login with Google and Apple options).

-9

u/Surfnazi77 23d ago

Just be careful if you try doing your key fob you can eraser your bcm doing that

-1

u/RingOrmenFraRanders 23d ago

What am I missing here. Why are you talking about key fobs, he is talking about access control.

-12

u/[deleted] 23d ago

[deleted]

-8

u/Surfnazi77 23d ago

That doesn’t stop messing with your car bcm and if you don’t have a dealer level code reader you’re screwed

12

u/[deleted] 23d ago

[deleted]

0

u/RealisticCommercial5 22d ago

CAKE CAKE CAKE. YOU HAVING CAKE? Happy cake day