Darket Diaries
Darket Diaries

41: Just Visiting

Join JekHyde and Carl on a physical penetration test, a social engineering engagagement, a red team assessment. Their mission is to get into a building they shouldn't be allowed, then plant a rogue computer they can use to hack into the network from a safe place far away. This episode was spons

Featured Speakers

Jack Rhysider HostJack Hyde Guest

Topics Discussed

Episode Summary

Executive Summary: The episode contrasts casual campus visits to Google and Facebook with a detailed account from physical penetration tester Jack Hyde and Carl on using social engineering to breach a secure manufacturing site. It shows how trust, pretexting, and badge access can beat strong physical controls, culminating in a rogue device deployment and later domain admin access. The story ends with a security lesson about human-factor vulnerability and ethical unease.

Main Topics: Google and Facebook campus access contrast (Priority: 4/5): Jack opens with humorous anecdotal visits to Googleplex and Facebook, highlighting open campuses, free bikes, and minimal visible security at Google versus tighter compartmentalization and gate controls at Facebook. Introduction to physical penetration testing (Priority: 5/5): Jack Hyde explains her role as a physical penetration tester/social engineer and how confidence, improvisation, journalism, and theater helped her convincingly enter restricted spaces. Disguises and human-factor exploitation (Priority: 5/5): The episode details disguises, especially a pregnancy prosthetic, and shows how social engineering leverages empathy, urgency, and helpfulness to bypass human defenses. Reconnaissance and planning for a secure facility (Priority: 5/5): Jack and Carl analyze a manufacturing site in a Spanish-speaking country using Google Maps, social media, and on-site observation to map fences, guards, badge readers, and likely weak points. Pretexting through a fake community outreach request (Priority: 5/5): They impersonate corporate employees Bridget and Ted, craft a targeted phishing email praising a food bank project, and gain an invitation into the facility from the employees they targeted. Rogue device deployment and network exploitation (Priority: 5/5): Once inside, Carl plants an Odroid-based rogue device under a conference table, finds a useful network port on the third room attempt, and later uses traffic monitoring to pivot and gain domain administrator access. Ethics, aftermath, and improved security awareness (Priority: 4/5): The hosts and guests feel conflicted about exploiting kind people, but the engagement leads to better awareness, domain-name validation, and stronger scrutiny of visitors and requests.

Key Arguments: Physical security can be strong while human security remains the weakest link; the team could not jump the fence but succeeded by leveraging trust and empathy. Confidence and improvisational communication are essential to social engineering because hesitation makes a pretext less believable. Targeted, personalized phishing is far more effective than generic phishing because it exploits real interests and recognition motives. The most effective social engineering often uses socially accepted roles and sympathy cues, such as pregnancy, illness, or charity work. Even when the intrusion feels ethically uncomfortable, red-team testing reveals real-world attacker paths that organizations need to defend against. Once physical access is achieved, even a small rogue device can create a long-term foothold and lead to major network compromise. Security awareness training should focus on verifying domain names, resisting urgency, and validating unexpected requests and visitors.

Data Points: Number of Google headquarters visits mentioned: 1 - Jack describes a single spontaneous visit to the Googleplex while in Silicon Valley. Facebook campus building count mentioned: 11 buildings - Facebook campus is described as being spread across 11 buildings around a central courtyard. Team size on the physical engagement: 2 people - The intrusion team consisted of Jack Hyde and Carl. Experience duration in physical testing: 3 or 4 years - Jack says she has been doing physical penetration testing for three or four years. Visitor time on site: 3 or 4 hours - Jack and Carl spent several hours touring the facility before deploying the device. Conference room attempts before success: 3 rooms - They tried three conference rooms before finding a network port with useful workstation traffic. Device type: Odroid C2 - Carl used an Odroid C2 mini computer as the rogue dropbox device. Badges used to access site: RFID visitor badges - The hosts issued them RFID visitor badges to enter the facility. Targeted email turnaround time: within minutes - The mark replied very quickly after the fake outreach email was sent. Email domain deception: look-alike domain with 'community resources' - Their phishing pretext used a domain resembling the real company domain, altered to appear related to community resources. Number of guard booths observed: 3 guard booths - On-site reconnaissance found three guard booths around the facility, all manned 24/7. Security coverage: 24/7 - Guards were present around the facility continuously, with police patrols at night.

Pivotal Quotes: "If a good guy can do this, a bad guy can do this." — Carl: Carl reflects on the ethical discomfort of exploiting generous people during the social engineering operation. "I can break into that building. I can convincingly lie to someone because if you are not confident, that comes off in the way you hold yourself and the way your voice sounds." — Jack Hyde: Jack explains confidence as the core skill behind successful physical penetration testing. "We're pretend bad guys and there are real bad guys out there. So we can feel bad about this. That's fine. But we're a vaccination and shots suck." — Jack Hyde: Jack justifies red-team testing as a painful but necessary defense against real attackers.

Implications: The episode underscores that social engineering can defeat even robust physical controls. For organizations, identity verification, domain scrutiny, and employee awareness matter as much as locks, fences, and badges.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries