Skip to main content
  1. Posts/

Physical security testing: from RFID cloning to the dropbox in the conference room

··4313 words·21 mins·
Table of Contents
Physical penetration testing is among the highest-risk work an operator does. Get written authorization that names the specific buildings, time windows, and what the on-site security team and local police should do if they encounter you. Carry a copy. The Coalfire arrest covered at the end of this post is what happens when scope and authorization are not airtight, even with paperwork in hand. Without authorization, every technique in this post is a felony in most jurisdictions.

Physical security is the layer everyone in IT defers to “facilities” and that facilities defers right back. The result on most engagements: the network is hardened, the laptops are encrypted, MFA is enforced everywhere, and the side door to the data center is propped open with a fire extinguisher because the badge reader makes deliveries take too long. Getting past the firewall takes weeks. Getting past the receptionist takes a clipboard and a high-vis vest.

This walkthrough covers the tradecraft: social engineering for physical access, locks and the bypasses for them, the badge-cloning kit every operator carries on engagement (Proxmark3, Flipper Zero, long-range readers), tapping the Wiegand wire behind the reader, surveillance and counter-surveillance, network dropboxes for persistence after the operator leaves, the HID attack devices (Bash Bunny, Rubber Ducky) and the USB-drop technique. The closing case study is the Coalfire arrest in Iowa, which is the canonical example of why your authorization paperwork has to name the specific building and the specific local sheriff’s office.

Social engineering for physical access
#

The cheapest path through any door is a person on the other side of it deciding to let you through. People want to be helpful, they get rushed, and they default to assuming the person in front of them belongs where they appear to be standing. The operator’s job is to engineer the scenario in which the helpful default produces the access they want.

Pretexting is the discipline of constructing a plausible scenario the target plays a comfortable role in. The vendor technician arriving for “the printer maintenance ticket,” the new contractor whose badge “hasn’t been activated yet,” the delivery person with a stack of catering trays whose hands are full. Each of these gives the target a script: hold the door, escort to the conference room, look the other way. Backstop the pretext (a real ticket number reachable in the vendor’s portal, a LinkedIn profile that’s been aged for six months, an answering service that picks up the burner number) and the operator’s chances of getting past a trained receptionist go from zero to most of the way there.

Tailgating is the simpler physical-only case. Wait near a high-traffic entrance, time the approach so an authorized person is opening the door, carry something that makes the target instinctively hold it for you (a stack of boxes, a tray of coffees, three pizzas). Most receptions don’t have a verification policy that survives “hands full, visibly burdened, and clearly in a hurry.”

Phishing as a precursor to physical access deserves a mention because it gives the operator the names, schedules, and badge layouts they need before they ever walk in the front door. An “HR benefits update” email that captures employees’ names and titles, a clone of the corporate-branded badge layout in the email signature, a couple of well-placed LinkedIn connection requests. By the time the operator arrives on site, the pretext is anchored in details the target recognizes.

The two case studies everyone references for this work are Kevin Mitnick (whose Art of Deception and Ghost in the Wires document the social engineering side of his career better than most academic papers do) and Chris Hadnagy at Social-Engineer.org (whose books and DEF CON SECTF competitions formalized pretexting as a discipline). Hadnagy’s Social-Engineer Toolkit (SET) and the broader Social-Engineer.org training are the operator’s standard reading list. Frank Abagnale’s “Catch Me If You Can” gets cited a lot too; recent reporting (Alan Logan’s investigative work, NYT 2020) has substantially challenged how much of Abagnale’s self-narrative actually happened, so treat the story as a parable rather than a case study.

Lock picking
#

Lock picking gets disproportionate attention from people who watch the LockPickingLawyer’s YouTube channel and underrated attention from operators who notice that most commercial buildings use Schlage SC1 keyway locks on perimeter doors and that those locks ship with five pin stacks at standard cuts. The discipline matters because picked locks leave no forensic trace, and because once you can open a door without breaking it, you’ve eliminated the noise that makes other entry methods detectable.

The two primary techniques are single-pin picking (apply light rotational tension to the plug, lift each pin individually to its shear line, feel each one set, repeat) and raking (insert a serrated pick, jiggle it in and out while applying tension, hope the pins set at random heights that happen to align with the shear line). Single-pin is slower but works against most locks; raking is faster but defeats only cheap pin tumbler locks with no security pins. Bump keys (a specially cut key struck with a small mallet while turning) shock all the pins to the shear line simultaneously and work shockingly well against cheap residential locks; the technique was popularized publicly in the mid-2000s and most security-aware lock manufacturers have shipped bump-resistant designs since. Impressioning (filing a blank key based on the marks left when it’s wiggled in the lock) is the slowest but produces a working key the operator can keep.

High-security locks (Medeco, Mul-T-Lock, Abloy Protec) raise the bar significantly. Most are pickable in published research but require specialized tools, hours of practice on the specific lock model, and conditions you don’t get on engagement (silence, light, time). The reliable move against high-security locks isn’t picking; it’s bypass (described below), shimming, or finding the alternate entry the building has because the architect forgot the front door was high-security.

The reference figures: Marc Weber Tobias, Matt Fiddler, and Toby Bluzmanis, whose DEF CON 16 (2008) talk “Open in Thirty Seconds” and the book of the same title document picking, bumping, and mechanical bypass of Medeco’s Biaxial and m3 lines. Deviant Ollam, whose books (Practical Lock Picking, Keys to the Kingdom) and DEF CON talks are the standard reading. TOOOL (The Open Organisation of Lockpickers) runs the Lockpick Village at DEF CON and most regional cons; show up, sit down at a table, and within an hour someone will have taught you to pick a basic Master Lock.

RFID and NFC: the invisible key
#

Most offices in 2026 still issue RFID badges for door access, and a meaningful percentage of them are running technology that was broken in academic papers a decade ago. The two technology families worth knowing:

  • 125 kHz LF (low frequency). HID Prox, EM4100, AWID. These cards broadcast a static serial number with no authentication. Read once, clone forever. Most older office building systems use HID Prox; many casinos do too.
  • 13.56 MHz HF (high frequency). Mifare Classic, Mifare DESFire, HID iCLASS, NXP NTAG. Smart cards that implement crypto and challenge-response. Mifare Classic’s CRYPTO1 cipher was broken in 2007 (Nohl, Plötz, Garcia) and is recoverable with the mfoc and mfcuk tools; DESFire EV1 had key extraction attacks (Oswald, Paar 2011); iCLASS Legacy was broken by Garcia et al. in 2013. DESFire EV2/EV3 and Mifare Plus AES mode hold up if implemented correctly, which they often aren’t.

The operator’s toolkit:

  • Proxmark3: the reference RFID multi-tool. Reads, writes, clones, and simulates almost any 125 kHz or 13.56 MHz tag. The RDV4 model is the current production version; older Proxmark3 Easy boards are cheap and work for most attacks.
  • Flipper Zero: portable, friendlier UI, slower than the Proxmark for serious work but excellent for field cloning when you need to keep the gear in your pocket.
  • Long-range readers: kits like the Tastic RFID Thief or BLEKey-style covert readers paired with a high-gain antenna can read a 125 kHz card from 3 feet through a backpack or jacket. In a crowded coffee shop or elevator, that’s everything you need.

Cloning a Mifare Classic with a Proxmark3:

hf search                                 # identify the card
hf mf autopwn                             # recover sector keys via nested attack
hf mf dump                                # save card contents to .bin
hf mf restore 1 --uid [original-UID]      # write to a Magic Card (rewriteable UID)

The whole sequence runs in under 30 seconds against most Mifare Classic deployments. Cloning HID Prox is faster: lf hid read, then lf hid clone [ID] to a T5577 blank.

Wiegand: the wire behind the reader
#

The card reader on the wall isn’t the access control system; it’s the sensor. The actual decision (open the door / don’t) is made by a controller in a closet somewhere, which the reader talks to over the Wiegand protocol, a 1980s wire format that sends the card’s badge number as a series of timed pulses on two wires (Data0 and Data1) with no authentication, no encryption, and no error detection. If you can attach to those two wires between the reader and the controller, you control the building.

The attack hardware is a pair of well-known devices: the ESPKey (introduced by Phineas Fisher / Redteam Tools, hardware design now open) and the older BLEKey (Mark Baseggio and Eric Evenchick, presented at Black Hat 2015). Both clip onto the Data0 and Data1 wires inside the reader’s housing, log every badge scan that passes by, and either expose those scans for download or replay them on command, over Wi-Fi for the ESPKey, Bluetooth for the BLEKey.

Deployment:

  1. Approach the reader after-hours or during a busy time when nobody’s watching.
  2. Remove the reader from the wall. Most are held on by two security Torx screws; the “vandal-resistant” reader housings are usually two-piece designs that come off without removing the reader from the controller wiring.
  3. Identify the green (Data0) and white (Data1) leads and clip the implant onto them.
  4. Reattach the reader. The implant sits behind the reader, invisible from the outside, until someone removes the reader specifically to look for it.

From the operator’s phone or laptop, every badge scan that passes through the reader is now logged. Replay any captured scan to the controller and the door opens, no cloned card required. The defense is OSDP (Open Supervised Device Protocol), which replaces Wiegand with encrypted reader-to-controller communication; OSDP is shipping in newer Mercury, HID, and AMAG hardware, but the installed base of Wiegand readers in 2026 is still enormous.

Physical bypass
#

Bypass is what you do when the lock is fine but the rest of the assembly isn’t. Most office doors are vulnerable to one or more of these:

  • Latch shimming (“loiding”). A flexible strip of plastic or shim metal slid between the door and the frame depresses the spring-loaded latch and the door opens. Works against any door with a beveled latch and no deadbolt thrown.
  • Under-the-door tools (UDT). A wire with a hooked end fished under the gap at the bottom of the door, looped around the inside lever handle, and pulled. Hotel rooms and commercial offices with lever handles fall to this in seconds.
  • Air wedges and pressure shims. An inflatable bladder slipped into the door gap creates enough lever to manipulate the latch from outside, or to spread the door frame far enough to defeat a poorly-fitted deadbolt.
  • Crash-bar manipulation. Commercial doors with crash bars (the horizontal push-to-exit bars on emergency exits) can often be triggered from the outside with a coat hanger fed under the door or through the gap.
  • Padlock shimming. A thin piece of shim metal pushed down the side of a padlock’s shackle releases the locking dog without ever touching the keyway. Most cheap luggage padlocks fall to this in seconds.
  • Door jamb attacks. Beyond shimming, the harder cases involve prying the frame, using a hydraulic spreader (the same tool firefighters carry) to bow the door enough that the bolt clears the strike plate, or in the worst case, breaching with a halligan and a sledgehammer. These are loud and leave evidence; they’re not stealth tradecraft but they are reliable.

The two case studies worth knowing for the bypass family:

  • Hatton Garden Safe Deposit (Easter 2015). A crew of six older burglars rented the empty office below the vault, took the elevator shaft down, and over the long weekend drilled three overlapping cylinders through 50cm of reinforced concrete with a Hilti DD350 diamond-core drill. Once through the wall they pried open 72 safe deposit boxes inside the vault and walked out with about £14 million in jewelry and cash. Not subtle, but the technique is the point: when the lock and the door aren’t the weakest link in the wall, the operator goes around them.
  • Samy Kamkar’s OpenSesame (2015). A modified Mattel IM-ME children’s toy reprogrammed to defeat fixed-code garage door openers via a De Bruijn sequence attack. The trick: instead of brute-forcing every possible code one at a time, OpenSesame encodes a De Bruijn sequence that contains every possible code as overlapping substrings, cutting the attack from minutes to about eight seconds. The complementary attack (RollJam) defeats rolling-code systems by jamming the legitimate signal, capturing it, and replaying it later.

Surveillance and counter-surveillance
#

Before walking in, you walk by. Reconnaissance for physical engagements means sitting in the parking lot at shift change to map who comes in and out, photographing the badge designs people are wearing on lanyards, noting which doors get propped open for smokers, identifying where the cameras are mounted and what their fields of view cover, and reading the company’s own LinkedIn posts for the badge designs and office layouts they unwittingly publish.

The reconnaissance toolkit is mostly soft:

  • Physical observation. Sit in a coffee shop across the street. Walk the perimeter. Pick up the trash in the parking lot at lunch, discarded calendars and printouts from the day before. Time the rhythm of the building.
  • OSINT. LinkedIn (“Smith just joined as IT Director” tells you who to spoof on the phone), the company blog (office tour photos that show the inside of the reception area), Glassdoor (employee complaints that name the building’s quirks), real-estate listings (floor plans from when the building was last on the market).
  • Tools. Recon-ng for automated OSINT module-style; theHarvester for email and subdomain enumeration; Maltego for relationship mapping; OSINT Framework (osintframework.com) as the bookmark of bookmarks.

The defender-side example everyone references is the 2008 Mumbai attacks, where David Coleman Headley conducted five reconnaissance trips for Lashkar-e-Taiba between September 2006 and July 2008, GPS-tagging the Taj Mahal Palace Hotel, Oberoi-Trident, Leopold Café, and Nariman House, photographing approaches, and helping build a physical model of the Taj for the operational team. The technique is not new; the discipline of seeing your own building the way an outside observer sees it is what defenders are usually missing.

Counter-surveillance: defeating the cameras
#

Once you’re on site, the cameras become a constraint:

  • Blind spots. Most camera systems have them. Ceiling-mounted PTZs have a cone of dead space directly below them; pole-mounted cameras lose the area immediately beneath their bases; the area between two cameras pointing at each other is often nobody’s responsibility. A few minutes of observation maps these for any installation that wasn’t designed by someone paranoid.
  • Tampering. Covering a lens with a piece of black tape, spray paint, or a strategically placed sticker works against any camera nobody is actively watching. Loud, somebody will notice when the footage goes black, but reliable for the few minutes you need.
  • IR floods. Most security cameras use 850nm IR LEDs for night vision. A high-output IR flashlight pointed at the camera blinds the sensor without producing any visible light. Goggles or a hat-mounted IR LED work for face-obscuration on the same principle.
  • RF jamming. Wireless cameras are vulnerable to active jamming on the relevant band. Worth knowing as a technique; in the US, transmit-jamming is a federal crime under the Communications Act of 1934 (47 USC § 333), so lab-only unless your authorization specifically covers RF.

Network dropboxes: persistence after you leave
#

Getting in is half the problem. The other half is keeping access once you walk out. Sitting in the server room indefinitely is not a strategy; planting a small computer that calls home over guest Wi-Fi or LTE is.

A dropbox is a small device (Raspberry Pi 4, Hak5 LAN Turtle, Intel NUC, refurbished thin client) that plugs into the internal network and tunnels traffic back to the operator’s C2 over an out-of-band channel. The operator drops it in the morning, the device callbacks happen all day, and the operator picks it up two weeks later, or doesn’t, because the cost of a Pi is less than the cost of going back to the building.

The mainstays:

  • Hak5 LAN Turtle. A USB-Ethernet adapter form-factor device that looks like the dongles already in every IT closet. Bridges the network while providing a reverse SSH shell over the cellular modem.
  • Hak5 Packet Squirrel. A small inline Ethernet box that sits between two devices and captures or modifies traffic in transit. Useful for sniffing the printer-to-server traffic that contains every print job and the embedded credentials in it.
  • Hak5 Plunder Bug (and similar passive taps from Dualcomm or NetGear). Pure passive tap for capturing traffic without altering the link.
  • Raspberry Pi with a 4G modem. The DIY equivalent. Cheap, flexible, runs your own tooling. The reference build is the “Pwn Pi” image; in 2026 most operators roll their own with a stripped Debian and an OpenVPN or WireGuard client.

Deployment: look for printers, VoIP phones, or unmonitored conference room jacks. Unplug the existing device, plug your implant into the wall jack, plug the device into the implant. Most enterprises run 802.1x port security on user-facing workstation ports but not on printer or phone ports, the printer doesn’t speak 802.1x, so the port is configured to skip authentication, and your implant inherits that exemption. The device that was there before is still there, still works, and now you have a tap on the wire.

HID attack devices: the keyboard-as-weapon
#

If you can’t drop a network device, target the workstation. The standard tradecraft is Human Interface Device (HID) attack hardware that registers as a keyboard and types arbitrarily fast:

  • Hak5 USB Rubber Ducky. Looks like a USB drive, registers as a keyboard, runs DuckyScript payloads that type commands faster than any human. The classic payload: open Run, paste a one-line PowerShell that downloads and executes a Beacon. Five seconds plugged in is enough.
  • Hak5 Bash Bunny. The Rubber Ducky’s bigger sibling. Registers as keyboard plus storage plus Ethernet plus serial, can run multi-stage payloads, and has on-device storage for exfiltration.
  • OMG Cable. A USB-C or Lightning cable indistinguishable from a real one, with the HID payload-and-Wi-Fi-C2 silicon hidden in the connector head. Sits on a target’s desk passing as their charger until the operator triggers the payload remotely.

These work against unlocked workstations and against workstations the operator can briefly unlock (target’s lunch break, server room walk-through, accomplice-style “I just need to print this real quick” coffee shop scenarios). They don’t work against locked workstations, modern Windows respects the lock screen against HID input, and “BadUSB”-style firmware-level attacks against the host’s USB stack are the next escalation but require specific drivers.

USB drops: the technique that shouldn’t still work
#

Drop USB drives in the parking lot, lobby, and break room. Label them in ways the finder will find appealing: “Layoffs 2026”, “Salary Survey Q3”, “Confidential HR”. Wait. The published research (Tischer, Durumeric, Foster, Duan, Mori, Bursztein, “Users Really Do Plug In USB Drives They Find,” IEEE S&P 2016) dropped 297 drives across the University of Illinois Urbana-Champaign campus in April 2015. 98% of the drives were physically removed from where they were dropped; an estimated 45 to 98% were actually plugged into a computer, depending on the labeling. The most attractive label was “exam answers.”

Twenty-plus years after Stuxnet’s USB delivery vector demonstrated the technique against an air-gapped Iranian nuclear facility, drop attacks still work. The defender side knows it, the awareness training programs cover it, and people still pick them up.

Physical access control: the system as a whole
#

A modern access control system has three layers: the credential (the badge), the reader (the thing on the wall), and the controller (the locked box that decides whether to open the door). Each layer is attackable in its own way:

  • Credential. Cloned with a Proxmark3 or a Flipper, brought back from a long-range read, or harvested through a captured-and-replayed Wiegand scan.
  • Reader. Pulled off the wall, tapped with an ESPKey or BLEKey, or bypassed by reaching the controller wires directly.
  • Controller. Frequently a Mercury, HID, or AMAG box mounted in a closet. If the closet isn’t itself secured (it often isn’t), the controller can be reached directly via its serial port or Ethernet management interface. Default credentials, exposed admin web UIs, and unpatched firmware are common.

The complementary credential families:

  • Magnetic stripe. Mostly historical for door access; some hotels still use it. Samy Kamkar’s MagSpoof (2015) emulates any magstripe via a coil and microcontroller, defeating systems that rely on swipe authentication.
  • PIN keypads. Shoulder-surfed, residue-analyzed (a thermal camera reveals the recently-pressed keys for up to a minute after entry), or simply guessed, most facility codes are still 1234 or the building’s address.
  • Biometric. Fingerprint and face scanners that fall to printed-print or photographed-face attacks; Tencent X-Lab demonstrated a 20-minute glass-to-spoof attack against smartphone fingerprint sensors at GeekPwn 2019. Higher-grade systems with liveness detection raise the bar but rarely to a level that defeats a determined operator with budget.

Fort Knox gets cited as the example of physical access control done right, with armed Mint Police, the 22-ton blast-resistant vault door, multi-person access protocols, and (per public reporting) biometric controls layered with the rest. The Treasury doesn’t publish the specifics, by design. What matters for the operator: Fort Knox is the standard for what “expensive physical security” looks like, and almost nothing the operator will engage against is built to that standard. The corporate office park is not Fort Knox.

The case study every physical operator should know: Coalfire in Iowa
#

On the night of September 10-11, 2019, Coalfire Labs operators Justin Wynn and Gary DeMercurio were conducting an authorized physical penetration test of the Dallas County Courthouse in Adel, Iowa. The engagement was contracted by the Iowa State Judicial Branch, which administers the state court system. The scope, in writing, covered after-hours physical entry to assess the courthouse’s perimeter security.

At about 12:30 a.m. on the 11th, Wynn and DeMercurio triggered an alarm while entering. Dallas County sheriff’s deputies arrived. The operators produced their engagement letter. The deputies arrested them anyway, charged them with third-degree felony burglary and possession of burglary tools, and held them on $50,000 bond.

The disconnect was in the authorization chain. The State Judicial Branch had contracted Coalfire and had authority over the building’s security testing. The Dallas County Sheriff and the County Board of Supervisors had not been notified and disputed the State’s authority to authorize testing of a county-owned building. The dispute went legal, the prosecutor pursued the charges initially, and Wynn and DeMercurio spent the night in jail and the following months under indictment.

Charges were reduced to misdemeanor trespass, then dismissed on January 30, 2020. Coalfire kept its operators, paid their legal bills, and pursued a defamation suit against the retired sheriff that is heading to trial as of this writing. Dallas County paid Wynn and DeMercurio a $600,000 settlement.

The lessons for the operator are concrete:

  1. Authorization paperwork has to name the building and the property owner. “The State Judicial Branch authorized us to test courthouses” is not enough if a county owns the courthouse and the county hasn’t agreed.
  2. Local law enforcement must be looped in. A pre-engagement briefing to the local sheriff or PD, naming the operator’s vehicle, the dates and time windows, the cell numbers, and the verification contact at the client, costs nothing and prevents nights in jail.
  3. Carry the engagement letter and a get-out-of-jail card. A signed letter on the client’s letterhead, with the security contact’s name and 24-hour phone number, that explicitly authorizes physical entry and asks any responding officer to call the contact before arrest. Show it immediately.
  4. The legal risk does not go away just because the engagement is real. Coalfire’s operators were doing exactly what they were paid to do, and they still spent the night in jail. The discipline of physical pen testing is partly the technical work and partly the bureaucratic work that protects the operator from the technical work being misread as a crime.

The Coalfire case is the reason a generation of physical pen testing engagements since 2020 have started with a checklist that includes “Dallas County” as shorthand for “did we get every necessary authorization, in writing, signed by every entity with authority over the target building, before we step on the property?”

What this comes down to
#

Physical security testing is the part of the engagement where the cost of failure stops being a finding in a report and starts being a night in a county jail or a wrongful-arrest lawsuit. Everything above is real tradecraft used on real engagements; everything above is also a felony absent the paperwork that makes it not. The technical skills (picking, RFID cloning, Wiegand tapping, dropbox planting, HID payloads, USB drops) are learnable in a weekend. The procedural discipline (scope, authorization, law enforcement coordination, on-site behavior when something goes wrong) is what separates the operator who finishes the engagement with a report from the one who finishes it with a mugshot.

Run physical work like the Coalfire case is in your head every step of the way, because most of the time the gap between “successful engagement” and “incident” is the engagement letter in your pocket and the phone number of the security director who hired you. Carry both.

UncleSp1d3r
Author
UncleSp1d3r
As a computer security professional, I’m passionate about building secure systems and exploring new technologies to enhance threat detection and response capabilities. My experience with Rails development has enabled me to create efficient and scalable web applications. At the same time, my passion for learning Rust has allowed me to develop more secure and high-performance software. I’m also interested in Nim and love creating custom security tools.