Perimeter
2/22/2011
12:22 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Using HVAC To Set Up A Hack

Social engineering caper begins with posing as heating ventilation and air conditioning repairmen

My firm was recently hired to perform a network assessment for a large financial institution. The goal of this engagement was circumventing physical controls and gaining access to the organization's internal network infrastructure. The firm's management was concerned that its server room could be easily penetrated, despite training its employees to look for security badges and to question wandering visitors and vendors.

We decided to pose as heating ventilation and air conditioning (HVAC) contractors -- a decision that paid off when we first walked in the door.

Before that, though, we first had to gain as much intelligence as possible about the location. The firm was located in an opulent office park owned and maintained by a management company that also kept an office on-site. My partner and I visited the leasing office as owners of a technology company interested in leasing space. We met with the property manager and were able to get a tour of all the offices and suites located within the building of our customer.

During the tour, we were able to get critical pieces of information that would allow us to determine the best identity needed to gain access to the customer's office. We learned that tenants placed service and maintenance calls through the management company, and the management company would then dispatch certain vendors to address and repair the problem. With a few more probing questions, we obtained the service dispatch forms, the frequency of preventive maintenance performed, but, most importantly, a list of contractors. To get ready for our entry attempt as the HVAC contractor used by the facility, we prepared our usual theatrical props of embroidered shirts, tool belts, ladders, and our van with the HVAC company logo plastered on both sides. Concealed within our toolbelts and boxes were the items we needed to gain internal network access -- a wireless access point and the necessary cables.

When we entered the building in our HVAC repairmen disguises, right away we were met by a person who questioned our activity. We told her that a complaint had came through the management company that the heating and ventilation system was out of balance and needed adjustment. She immediately acknowledged our service call by expressing her complaints about the facility being too warm. She then guided us from location to location, indicating the system was moving either too much air or not enough. This guided tour was helpful in gaining us credibility within the office, but her presence made it impossible to plant the wireless access point. We endured more than 30 minutes of listening to her complaints about the temperature and environment and addressed here specific areas of concern. We told her that we agreed her issues were valid and that we would immediately address them, and then we noticed that she was beginning to relax and trust us.

As we walked through each part of the office looking for a chance to plug in our device, our escort noted that the most important area of heating and cooling was the room that housed all the computers. She swiped her card in the entryway to the computer room, and then led us into this forbidden area. Although the area appeared to be at normal temperature, she requested we check the room's cooling system. Now was our chance: We carefully positioned our ladder to obscure any view of us positioning our wireless device, while at the same time trying to distract her attention. We successfully installed the wireless access point, and then wrapped up our visit so we could come back later and gain access to the network while sitting in the parking lot.

We left the duped guide with a list of "to do" items that we never repaired, and realized the value of what the HVAC repair person brings when social engineering your way into a secured location. There are similarities with gaining access to office networks disguised as a copier technician: While the copier or printer could be working fine, someone always hates it. Turns out the HVAC person has the same luxury of ease-of-entry: The financial services firm had no requests for service, but chances are someone in the office will always want to voice their personal needs or comfort, thus giving us an "in."

Unfortunately, personal comfort ended up leaving the company's network wide open for a breach.

Steve Stasiukonis is vice president and founder of Secure Network Technologies Inc.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-0360
Published: 2014-04-23
Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

CVE-2012-1317
Published: 2014-04-23
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.

CVE-2012-1366
Published: 2014-04-23
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.

CVE-2012-3062
Published: 2014-04-23
Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.

CVE-2012-3918
Published: 2014-04-23
Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/HDLC mode, allows remote attackers to cause a denial of service (serial-interface outage) via certain Frame Relay traffic, aka Bug ID CSCub13317.

Best of the Web