Tag: technology

  • S1x5: eps_1.4_3xpl0its.wmv

    Episode Description: “<mr.rob0t> fsociety arrives @ steel mountain – most secure data facility in USA. elliot needs to get in and get out-wuz he pwned?”

    Cloning Steel Mountain Employee Badge

    Mr.Robot bumps into a Steel Mountain employee and clones his badge with an RFID reader inside his bag while walking up to leave a tip at the counter in a coffee shop.

    The hardware device used to duplicate the badge’s info on a blank card. There are a number of devices that can pull this off nowadays, whether you use a Flipper Zero or any other RFID signal cloning device. MITRE’s got a great brief description of it here and Safe and Sound Security provides a more thorough description of it here.

    Breaking Poor Bill Harper and Trudy Davis

    Mr.Robot and the team have cobbled together a broad psychological profile of Bill using his company contact page, LinkedIn, and Instagram profiles (replaced with generic nameless versions in the show).

    Bill’s staff page on the Steel Mountain site shows that he’s a high performer in the three years he’s been there. His LinkedIn shows that his Steel Mountain job is the best job he’s ever had in years so he’s probably very eager to perform well. And Bill’s Instagram only shows selfies or pictures with his cats, so it can be assumed that he’s single and doesn’t have many friends.

    The fsociety crew uses this to their advantage by having Mobley use his “trusted contributor” status on Wikipedia to create a fake profile of a tech billionaire named Sam Sepiol for Elliot to assume as a persona. Using the pressure of this big name to intimidate Bill, who doesn’t want to cause any problems at work, Elliot gets an impromptu tour with no appointment and later denigrates Bill in order to have him summon his supervisor to take Elliot to level 2.

    Elliot states that Bill’s the perfect exploit because he’s “desperate enough for the business to break protocol and let me in. Lonely enough to break.”

    It’s an incredibly mean scene of Elliot hounding Bill about how no one will truly mourn him when he dies and attacking his self-esteem by reiterating how insignificant he must be. It’s a great advertisement for keeping as many of your social media accounts private as possible. Knowledge is power, and the Internet can be a very cruel place. Don’t give people ammunition to hurt you with. Things like your appearance, relationship status, employment and implied earnings, family situation, and more will be weaponized often for someone else’s amusement.

    The original plan the crew has is to use Bill’s supervisor Wendy to get above Level 1 of the facility to Level 2 where their target is. They plan to send her a fake message stating that her girlfriend’s in labor to force her to immediately leave the facility with Elliot free to roam the area. Unfortunately they miss that the baby’s already been delivered, so Wendy is off that day and they get Trudy instead who’s far more skeptical and suspicious of Elliot.

    In this moment Elliot is, as the kids say, “cooked.”

    Unable to find any obvious exploitable info on Trudy, they turn to using her husband’s cell phone number and spoofing it using the Social Engineering Toolkit to send her an ominous text implying that he’s had some sort of health emergency.

    This leaves Trudy shocked and disoriented, rushing off to her office and leaving Elliot to have reception see him out.

    This is an even crueler trick than what they pulled off with Bill, specifically done by Mobley. Trudy and her husband have been married for 30 years. Their mortgage is paid off meaning they both seem to have stable well paying jobs and you can assume their marriage is pretty strong.

    If you add a race element to this, and I assume Mobley did, it’s statistically probable that Trudy’s husband has some genetic predisposition towards one or more of the following: high blood pressure, diabetes, heart disease, stroke, cancer, or sickle cell disease.

    TL;DR: Mobley’s a real piece of shit for this.

    Trudy’s concern and love for her husband was a “vulnerability.”
    Romero doesn’t seem too happy with this.

    After pulling off this miserable act of social engineering, Elliot learns that the elevator can only be operated by people with the right approval, so he goes looking for a stairwell and picks the door lock.

    Lockpicking’s got a long history of being associated with hacking, whether it’s as a physical penetration test or just a hobby hackers like to get into. Most information security conferences have a lockpicking village you can learn from.

    This doesn’t work since it only leads to a parking garage, but luckily Elliot runs into Tyrell Wellick who invites him to have lunch at the Executive Lounge which is near their target. Elliot excuses himself to go to the restroom and in there is what seems to be a utility or maintenance closet with the thermostat in it. A bit of a stretch but sure.

    With some quick disassembly of the original red ethernet cable’s wires, plugging them into the Pi’s PCB in a separate green ethernet cable, using electrical tape to seal any exposed wiring, and reattaching the thermostat to the wall, Elliot plants their “asymmetric backdoor” and leaves without anyone knowing.

    This is incredibly poor building design, but great for television!

    The fsociety crew pulls off an alarmingly simple compromise of a secure facility. Unfortunately, Darlene later learns after checking in with “The Dark Army” (cringe) that they’re backing out. Darlene protests, and she gets kicked out of their IRC channel which is kind of hilarious.

    Translation: “We’re not throwing away this amazing pre-positioning opportunity on this op with the West.”
    LMAO “Get booted, Capitalist Western scum!”

    Darlene, being the grungy crash out she is, goes to the day job of her Dark Army contact/fake struggle rapper and throws a tantrum knocking over a bunch of books after loudly complaining about the botched operation. He points out how stupid this is and she leaves in a huff.

    Later back at the fsociety lair, Darlene connects to the Steel Mountain network herself using their backdoor and threatens to run their malware herself. Without The Dark Army’s help, Mr.Robot implies it won’t be as effective and Steel Mountain will just recover and strengthen security even more. He pleads with her to leave things alone and Elliot talks her down. Smart move on his part.

    Evidently, this would’ve just given Steel Mountain a black eye but not done any serious damage.

    In conclusion, I really enjoyed episodes 3 and 4. As someone who’s been working in, and learning about, cybersecurity for almost a decade now it’s really cool to see these attacks I’ve only ever read about or seen in proof of concept presentations or papers applied to fiction. These two episodes have had the most impressive hacks so far, and if things escalate throughout the next three seasons this will easily be one of my favorite shows ever.

  • Back After A Year

    The Roadmap for the Future of This Blog

    Things have been moving pretty quickly in my career and life since the last blog post this time one year ago. First off, I got accepted to the SANS Technology Institute’s Master of Science in Information Security Engineering (MSISE) program with a (currently intended) specialization in Penetration Testing.

    After my employer paid for me to take the course and exam for the GIAC Certified Enterprise Defender (GCED) and GIAC Certified Intrusion Analyst (GCIA) in 2023 and I managed to pass both pretty comfortably, I decided to move forward with pursuing a Master’s degree at the accredited university side of SANS. They allow you to make monthly payments and provide a 50% discount on course costs if you get accepted, which I managed to do earlier this year. My employer’s surprisingly willing to cover SANS courses, and I was paying a similar amount to the Master’s program cost monthly in student loan payments (which are now paused due to going back to school) so it was kind of a no-brainer.

    GCED Course Books

    This course was like a more involved (and practical) version of the CISSP in my opinion.

    GCIA Course Books

    LOTS of detail about in-depth packet capture and analysis, hence the additional books over the GCED.

    Second, I had the incredible fortune of being able to attend “Hacker Summer Camp (HSC)” which consists of BSides Las Vegas (and The Diana Initiative, which I wasn’t able to make), Black Hat USA, and DEF CON 32. Even with the absurd Las Vegas heat (113 degrees Fahrenheit at its peak!) I had a phenomenal time, favoring BSides and DEF CON over Black Hat with its flood of corporate and vendor pitches and follow up correspondence (my work e-mail inbox was flooded for weeks). I was also blessed with the opportunity to attend ShmooCon and BSides NOVA this year as well. I’ll make a post about all those experiences soon.

    And lastly, I was promoted into a more technical Blue Team role working with SIEM tools for an enterprise cloud network. This was huge for me since I’ve been aiming for a “hands on keyboard” role (hence the name of this blog) ever since getting my CISSP and CCSP and being disappointed with the world of Cybersecurity Policy and Compliance. Work like this and my intended Master’s specialization is more difficult but will pay dividends in terms of my future career opportunities and understanding of the field as a whole. It’s intimidating looking at the increasingly difficult educational material I have coming up, but I’d be lying if I said I wasn’t excited too.

    So, you may be thinking “Good for you, but I don’t see what all this bragging has to do with the site.” My answer to that would be 1. I’m not nearly as great as all of the above makes me seem, and 2. This is the part where I’ll get into the future of this blog.

    Initially I thought I would be posting walkthroughs for HTB machines and Academy modules until receiving a very polite but firm cease and desist e-mail from them. Now I’m thinking my posts will cover my NDA-friendly thoughts on the courses and trainings I’ve taken, books I’ve read, personal projects I’ve undertaken, and content creators I follow all within the information security ecosystem.

    Here’s the current list I’m looking at of things I intend to cover:

    1. My experience taking the SEC501 course and GCED exam (broken down per book but not giving more detail of the contents than what’s on their public page)
    2. The same for SEC503 and the GCIA exam (again using their public page as my guide)
    3. Also covering SEC504 and the GCIH in a similar fashion (with this page as my guide)
    4. My review and thoughts on the book Countdown to Zero Day (and before you ask, no that’s not an affiliate link so I get no money if you use it to buy the book)
    5. Reading through the book Hands-On Hacking (from what I’ve read so far, it seems pretty legit)
    6. My experience taking the PEN-200 course from OffSec and the OSCP exam (being careful not to upset their legal department by saying too much)
    7. My thoughts and experiences with HTB Academy materials from the CJCA, CWES, CPTS, and CDSA curriculums (let’s see if I can get it right this time, lol)

    As far as 2025 goes juggling this with my career, school, relationship, professional development goals, staying active, and hobbies seems like a full plate. Hopefully I’ll be able to finish the first 4 or 5 of those and complete a good amount of the latter 3 without taking too much time away from the other parts of my life.

    If all goes well I’ll eventually be able to put my MalDev Academy lifetime subscription (as well as my CodeCademy subscription, which I’ve already completed a good chunk of) to good use by working through that material too. That level of knowledge and experience with computing and information security is the goal!

    Additionally, my course plan for future semesters shows that I’ll be taking the GDSA, GPEN, GRTP, and GXPN courses so if you’re interested in reading what I have to say about those stay tuned!