Darket Diaries
Darket Diaries

59: The Courthouse

In this episode we hear from Gary and Justin. Two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong. Sponsors This episode was sponsored by Detectify. Try their web vulnerability scanner free. Go to https://detectify.com/

Featured Speakers

Jack Rhysider HostGary DiMercurio Guest

Topics Discussed

Episode Summary

Executive Summary: In this episode of Darknet Diaries, host Jack Resider interviews physical penetration testers Justin Wynn and Gary DiMercurio from Coalfire. They share stories of legally breaking into financial institutions and courthouses to test security for clients. The episode culminates in their wrongful arrest and felony charges after a contracted test at the Dallas County Courthouse in Adel, Iowa, highlighting failures in communication between state and county authorities and the legal system's impact on security professionals.

Main Topics: Social Engineering in Physical Pen Testing (Priority: 4/5): Justin and Gary describe using pretexts like fake HVAC repairs and internal security codes to gain access to bank branches, showing how employees can be manipulated. Tools and Techniques for Door Bypass (Priority: 3/5): They detail various methods such as under-the-door tools, lockpicking, crash bar bypasses with cutting boards, and leveraging common architectural weaknesses to enter facilities. Rules of Engagement and Legal Contracts (Priority: 5/5): The complexity of defining scope in pen testing contracts is discussed, including phone calls that provide granular details not fully captured in official documents (28-page contract example). The Iowa Courthouse Incident (Priority: 5/5): The duo's arrest at the Dallas County Courthouse after a state-contracted test escalates due to sheriff and prosecutor refusal to accept authorization, leading to felony charges and jail time. Legal System Failures and Aftermath (Priority: 4/5): Despite charges being dropped, the arrest record remains, impacting future background checks and security clearances. The stress and trauma of being wrongfully prosecuted are highlighted.

Key Arguments: Physical penetration testing is a legitimate and necessary security assessment tool, often contracted by organizations to identify vulnerabilities. Clear and documented rules of engagement are critical, but even extensive contracts (28 pages) may not capture all nuances discussed in scoping calls. Miscommunication between state and county authorities can lead to wrongful arrest of security professionals acting under contract, as seen in the Iowa courthouse case. The legal system's near-automatic assumption of guilt and lack of inter-agency coordination can devastate professionals' lives even after charges are dropped. Pen testers should ideally coordinate with local law enforcement before assessments to avoid dangerous misunderstandings.

Data Points: Contract Length: 28 pages - Amount of documentation for rules of engagement for the Iowa Judicial Branch pen test. Bail Amount Increase: $5,000 to $50,000 - Gary's bail was initially set at $5,000 but raised to $50,000 by the judge after the county prosecutor labeled them flight risks. Potential Prison Time: 7 years - The duo faced up to seven years in prison if convicted of felony burglary and possession of burglary tools. Time in Jail: Approximately 20 hours - Time spent in jail before Coalfire posted bail. Police Response Time: Less than 5 minutes - Time it took for sheriff's deputies to respond to the courthouse alarm after it was triggered.

Pivotal Quotes: "You must think I'm stupid." — Judge: The judge's response to Gary when he tried to explain they were authorized by the state to conduct the test, dismissing his explanation. "I can't believe that you went up there as professional as could be, and she disrespected you." — Inmate cellmate to Gary: An inmate's reaction after witnessing Gary's respectful demeanor in court, highlighting the perceived injustice. "The legal system failed you repeatedly. There were so many opportunities and avenues for the county to understand or get more information and then drop the charges and it just never happened." — Gary DiMercurio: Gary summarizing their experience of repeated failures in the legal process despite clear evidence of authorization.

Implications: This story underscores the urgent need for better coordination between cybersecurity professionals and law enforcement, clearer legal frameworks for authorized security testing, and reform in how arrest records are handled when charges are dismissed. It warns that even legitimate security work can have severe personal and professional consequences without proper safeguards.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries