Darket Diaries
Darket Diaries

125: Jeremiah

Jeremiah Roe is a seasoned penetration tester. In this episode he tells us about a time when he had to break into a building to prove it wasn’t as secure as the company thought. You can catch more of Jeremiah on the We’re In podcast. Sponsors Support for this show comes from Axonius. The Axonius sol

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: The episode centers on Jeremiah Rowe’s physical red-team penetration test of a federal contractor’s satellite office, where weak physical security, an unlocked kiosk, and misconfigured network access let testers enter multiple floors, access office spaces, and bypass NAC by spoofing a printer MAC address. The story highlights how easily insiders or outsiders can exploit mundane oversights and why physical and network security must be tested together.

Main Topics: Michael Fagan as an opening analogy (Priority: 4/5): The episode begins with the famous 1982 Buckingham Palace intrusion to frame the theme of improbable physical access and security failure, setting up the later penetration-test narrative. Planning a physical red-team assessment (Priority: 5/5): Jeremiah explains how he and a teammate scoped a remote contractor office like outside attackers would, using maps, surveillance, and careful preparation before attempting entry. Weak perimeter and door security (Priority: 5/5): The team found an open stairwell door and multiple unsecured office-floor doors, allowing access without badges and demonstrating basic physical access-control failures. Kiosk compromise and workstation exposure (Priority: 4/5): They gained control of an unattended lobby kiosk, proved OS-level access with a Bash Bunny, and observed unlocked employee workstations and exposed network ports. Network access control bypass (Priority: 5/5): By identifying printer MAC prefixes and spoofing one on their laptop, they obtained a different IP and broader network access, showing a practical NAC weakness. Reporting, remediation, and impact (Priority: 4/5): The findings produced significant leadership concern, led to physical and configuration fixes, and changed how the organization viewed red-team testing and its own risk.

Key Arguments: Physical security failures can be as damaging as software vulnerabilities because they enable direct access to sensitive spaces and systems. Organizations often underestimate the risk of contractor facilities, even though attackers may use them as a path to government or enterprise networks. Unattended kiosks and open workstations create easy opportunities for compromise without sophisticated tooling. Network Access Control is only effective if it is implemented in a way that cannot be bypassed with simple MAC spoofing. Penetration tests are valuable precisely because they expose hidden risks that internal teams may ignore or not know exist. A successful assessment should lead not only to findings, but to remediation and stronger security culture.

Data Points: Michael Fagan age: 30 - Described at the start of the Buckingham Palace story as the man who intruded into the palace in June 1982. Buckingham Palace rooms: 775 rooms - Used to emphasize the scale of the palace and how surprising the intrusion was. Buckingham Palace stories: 3 stories - Part of the description of the palace’s size and layout. First palace intrusion date: June 7, 1982 - The date of Michael Fagan’s first break-in. Second palace intrusion date: July 8 - The date of Fagan’s second intrusion, when he reached the Queen’s bedroom. OSCP exam duration: 24 hours - Jeremiah mentions this as the timeframe for the advanced certification exam he passed. Building floors targeted: 2nd and 3rd floors - The contractor’s offices were on the second and third floors, which the team ultimately accessed. Elevator/floor access: 2 access methods observed - They noticed both stairs and elevators in the foyer while scouting the building. Network exposure: 1 kiosk Ethernet jack and multiple wall ports - They found an Ethernet port on the lobby kiosk and additional exposed ports around the office floors. MAC address bypass result: Different IP address and broader access - Spoofing a printer MAC prefix caused the network to assign a more privileged IP. Workstations found unlocked: 2 - They observed two separate unlocked employee laptops and documented the access as a finding. Sponsor claims on ransomware: 85% of organizations affected in the past year - Mentioned in a SpyCloud ad read about ransomware prevalence. Identity records circulating: 63.8 billion - Mentioned in the SpyCloud ad read as a dark web scale statistic. Organizations detecting exposure: 38% - Mentioned in the SpyCloud ad read as the share able to detect historical identity exposure. Corporate users infected by infostealers: Nearly half - Mentioned in the SpyCloud ad read summarizing identity-threat findings.

Pivotal Quotes: "I was going through this breakdown." — Michael Fagan: BBC interview clip describing his mental state before entering Buckingham Palace. "The best defense is good offense." — Jeremiah Rowe: Jeremiah explains why proactive testing is essential for uncovering hidden security weaknesses. "I think what worked here is they looked the part and acted with confidence." — Narrator: Explaining why Jeremiah and BC were able to move through the office without challenge.

Implications: The episode shows that small physical oversights can defeat strong-seeming security programs. For defenders, it underscores the need for layered controls, regular red-team testing, and tighter access control on buildings, kiosks, and network ports.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries