& RFID Attacks for Physical Access
BOLO
Echelon Risk + Cyber
Black Hills Information Security
Red Team Operators, Penetration Testers, Aspiring Physical Operators
Common RFID technologies that we see most often as Physical Security Practitioners
Existing & New Tools that are readily available
TTPs that we've found to work and some that are a bad idea
HID PROX (Common)
Indala (Rare)
EM (More Rare / Low Budget)
AWID (Extremely Rare / Expensive)
These cards/readers leverage legacy technology that does not support encryption. This makes reading, writing, and emulating a breeze.
125kHz Readers
HID Slimeline
HID Mini Mullion
HID Wall Switch Keypad
Indala Proximity Mid-Range
Indala Proximity Classic
13.56MHz iCLASS Legacy
13.56MHz iCLASS SE
13.56MHz & 125kHz
multiCLASS
multiCLASS SE
13.56MHz & 125kHz
Biometric 25B
40 Series
Express
Enrollment
20 Series
iCLASS R90SE
MAXIPROX 5375
Indala asr-620++
iCLASS R90SE
MAXIPROX 5375
Indala asr-620++
Doppelgänger
ESP32 Firmware
Actively Supported
Wiring Diagram
R90SE Installation
Briefcase
Backpack
multiCLASS SE
13.56 Mhz (High Frequency)
iCLASS SE
SEOS
iCLASS SR
iCLASS (Legacy)
SE for MIFARE Classic
SE for MIFARE DESFire EV1
125 kHz (Low Frequency)
HID AWID
EM4102
Prox Credentials
Can be flashed to convert to SIO-Enabled mode.
multiCLASS SE
Keypad Equipped
13.56 Mhz (High Frequency)
iCLASS SE
SEOS
iCLASS SR
iCLASS (Legacy)
SE for MIFARE Classic
SE for MIFARE DESFire EV1
125 kHz (Low Frequency)
HID AWID
EM4102
HID Prox Credentials
Pros / Use Case
Potential Issues
Tech Specs
Use Case
Known Issues
Use Case
Known Issues
Use Case
Standard 26-bit Wiegand Format
For these reasons, customers tend to adopt multiCLASS (SE) technology to reduce the upfront costs and complications.
Why are there so many legacy readers?
iCLASS SE/SEOS >> iCLASS legacy
The controller does not care about the technology being presented. It only cares about the Facility Code and Card Number that are being presented.
iCLASS Legacy/SE/SEOS >> Prox/EM/AWID
The controller does not care about the technology being presented. It only cares about the Facility Code and Card Number that are being presented.
A company can significantly increase its security posture by implementing Elite keys instead of Standard keys. This will prevent non-client iCLASS SE readers from being able to capture the data.
Elite Keys
OSDP
OSDP has recently hit the streets and aims to replace the Wiegand communication between readers and their controllers. While it touts unique encryption between each reader and the controller, some flaws still exist.
Adhere to the principle: Two is one, one is none.
Chokepoint Identification: Exterior of Facility
Chokepoint Identification: Interior of Facility
Tips for Success
Stealth Placement
Application
Reasons not to do it...
https://raw.githubusercontent.com/tweathers-sec/useful_physical_information/main/card_calculator.py
Three Days / Tampa, FL
- Pre-sales & Authorization
- Remote Reconnaissance
- Digital Surveillance
- Surreptitious Entry Tactics
- Badge Cloning & Replication
- Post-Exploitation
- Live Facility Breach Exercise
Upcoming Dates (2024):
October 16 - 18
PRIVATE CORP. & GOVERNMENT TRAINING AVAILABLE
Mobile Recon
Lockpicking & Dumpster Diving
Facility Access
Post Exploitation
Mission Complete
Longrange Cloning
Static Analysis
Writing Cards
Installing PM3
Stealth / MFAS
https://physicalexploit.com/docs/products/getting-started/