Darket Diaries
Darket Diaries

40: No Parking

Take a ride with a red teamer. A physical penetration tester as he tries to make his away into unauthorized areas, steal sensitive documents, hack into the computers, and escape with company property. This episode was sponsored by CMD. Securing Linux systems is hard, let CMD help you with that. Visi

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: This Darknet Diaries episode follows Kyle, a physical penetration tester on a red team, as he and coworkers repeatedly break into utility company facilities to expose major security failures. By exploiting unlocked doors, poor camera/guard coverage, weak badge controls, and open network ports, they gain physical access, domain admin, and sensitive documents—ultimately proving the company needed both security fixes and budget justification.

Main Topics: Physical penetration testing as a security assessment tool (Priority: 5/5): Kyle describes his job on a red team, where he physically infiltrates buildings to simulate real-world attackers and test defenses across multiple sites. Reconnaissance and social engineering (Priority: 5/5): The team uses LinkedIn, Facebook, Twitter, Google Maps, and employee behavior patterns to choose targets, identify staff, and plan disguises and cover stories. Repeated access failures due to basic physical security lapses (Priority: 5/5): Across warehouses, offices, and headquarters, they exploit unlocked doors, poor lighting, weak guard presence, and accessible desks/lockboxes to enter secured spaces. Network compromise through dropbox devices (Priority: 5/5): Once inside, they plug in a portable Raspberry Pi/cell hotspot device to gain remote network access, quickly reaching domain admin in at least one location. Badge cloning and credential abuse (Priority: 4/5): They recover a valid badge from a smaller office, clone it with a Proxmark, and use the replica to enter the final headquarters and bypass access controls. Security culture and operational response gaps (Priority: 4/5): The story highlights weak guard responses, poor escalation, and how even visible suspicious activity was often ignored until after compromise was already underway. Using findings to drive budget and remediation (Priority: 4/5): The end result is a formal report that demonstrates vulnerability so executives approve fixes, showing how offensive testing can catalyze defensive investment.

Key Arguments: Physical security can fail catastrophically when doors, cameras, guards, and perimeter controls are not layered properly. Open network ports and lack of authentication enable attackers to gain internal access simply by plugging in a device. Social media and mapping tools provide enough intelligence to plan convincing on-site intrusion attempts. Badge systems are only effective if badges are deactivated, accounted for, and monitored for misuse. Security teams need to slow attackers down; they do not need perfection, but they do need enough friction to detect and interrupt intrusions. Multi-site reconnaissance can be chained together to snowball access, credentials, and equipment for a final target. Penetration tests are valuable because they reveal vulnerabilities in a way that can secure budget for real fixes.

Data Points: Sites tested: Multiple facilities across several cities and states - Kyle and team progressively tested warehouses, offices, and headquarters for the utility conglomerate. Security insiders aware of test: 2 people - Only the head of IT security and the head of physical security knew about the engagement. Initial network compromise time: Within a few minutes - At the first warehouse site, the dropbox led to domain admin access quickly after plug-in. Trucks stolen/moved: 12 or 13 - The team moved company vehicles off the lot as part of the objectives. Floor accessed at HQ acquisition building: 5th floor - Kyle guessed a floor on the elevator after badge access confusion and reached the target area. Number of co-workers on the final HQ job: 3 - Kyle and two coworkers conducted the last headquarters intrusion attempt. Days available for testing: A few days - The team had multiple days at the final location, allowing repeat attempts and deeper testing.

Pivotal Quotes: "Just doesn't look right." — Kyle / narrator recounting JDLR meaning: Explaining the mall security acronym that frames the episode’s theme of noticing suspicious behavior. "Hacky as shit. Dumbest thing I've ever done by far, technically speaking, but it did the job really, really well." — Kyle: Describing the improvised dropbox device used to gain network access once physically inside a building. "We successfully breached and compromised the network of the headquarters building without being detected." — Kyle: Summarizing the success of the final headquarters intrusion via the back door and internal network access.

Implications: The episode shows how weak physical controls can collapse enterprise security, especially when combined with poor access management and exposed network ports. For defenders, layered controls, guard vigilance, badge hygiene, and port authentication are essential.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries