Pentester says he broke into datacenter via hidden route running behind toilets
- Reference: 1657188010
- News link: https://www.theregister.co.uk/2022/07/07/lock_down_your_piss_corridor/
- Source link:
Tierney, who works as a consultant for security services outfit [1]Pen Test Partners , revealed in a Twitter thread how one of his more memorable exploits involved demonstrating that it was possible to gain physical access to the supposedly secure area of a datacenter via its toilet facilities.
Posting a diagram to illustrate, Tierney showed that the unnamed facility had separate toilet facilities for the general office space and the secure area where the IT infrastructure is housed. However, the two toilet facilities were adjoined, and Tierney realized there was actually a shared access space for servicing the toilets that ran behind both sets of cubicles, which he christened the "piss corridor."
One of my favourite physical access jobs to a datacenter involved toilets.Let me explain.I needed to gain access from the less-secure side of a sub basement floor to the more-secure side. General office space to data centre. [2]pic.twitter.com/5C4yXD1Yeq — Cybergibbons (@cybergibbons) [3]July 4, 2022
It turned out this access space could be reached through a concealed door in an accessible cubicle – a larger cubicle designed for wheelchair access – on either side of the secure/insecure divide. So that's exactly what Tierney did, entering the toilets on the general office space side and accessing the "piss corridor" via the accessible cubicle, exiting on the supposedly secure side the same way.
[4]
Tierney omits to mention whether the concealed doors were locked to prevent any curious toilet patrons from entering the access space, or whether he had to pick the locks to gain entry.
[5]Smart homes are hackable homes if not equipped with updated, supported tech
[6]Secure boot for UK electric car chargers isn't mandatory until 2023 – but why the delay?
[7]Pen Test Partners: Anyone could view Gumtree users' GPS location by pressing F12
[8]Infosec bods: After more than a year, Sky gets round to squashing hijacking bug in 6m home broadband routers
The only awkward moment might have come had the accessible cubicle on the secure side been occupied when Tierney opened the concealed door, and so he claims that he only did this after "*really* making sure there wasn't someone else in the other accessible cubicle."
Flushed with his success, Tierney noted that he had just managed to defeat the datacenter's security protection which involved mantrap entry gates where personnel had to "surrender all digital devices" upon entry. Even worse, the toilet layout was visible for all to see on public planning documents, meaning that anyone could have figured out how to bypass security.
[9]
The lesson for operators of secure facilities is take great care that you are not caught short with such obvious ways of bypassing physical security controls, and remember it is always about more than just IP access. ®
Get our [10]Tech Resources
[1] https://www.pentestpartners.com/
[2] https://t.co/5C4yXD1Yeq
[3] https://twitter.com/cybergibbons/status/1544031303468728320?ref_src=twsrc%5Etfw
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YscDICbysiyEgnd6mvEUCwAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.theregister.com/2022/06/01/which_smart_tech_advice/
[6] https://www.theregister.com/2022/01/11/electric_car_charging_security_uk/
[7] https://www.theregister.com/2021/12/15/gumtree_data_breach_idor_f12_badness/
[8] https://www.theregister.com/2021/11/23/in_brief_security/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YscDICbysiyEgnd6mvEUCwAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: Crappy security
I'll bet they had a problem with leaks.
Caught with their trousers down!
I'm going..
Re: Caught with their trousers down!
So did he.
This is just taking the piss.
I'm expecting a long list of toilet based jokes to follow. Don't disappoint :)
Re: This is just taking the piss.
The pen tester was flush with success after throwing this one in the bowl. Security really got the toilet brush-off and had to disinfect the situation once they had recovered from turning yellow with rage at the leak that had occurred.
Visible for all to see on public planning documents
Did the penny drop when they saw the paper trail?
Built a studio complex in the UN building
And discovered we shared a wall with a bank.
Well, we shared the first eight feet of the wall; right up to the false ceiling tiles. Above that was three feet of fresh air... they were a bit concerned when I pointed it out to them.
Urine trouble now!
Comment of the day! W00t!
That's just taking the piss!
Hello, this is the Lock-Picking Lawyer
and today I am going to break out of this piss corridor using a folded-up bit of toilet paper ...
The Security Was Possibly Via a Screwdriver
Often, those panels are only held by screws, though, in this case possibly nothing so secure, as he had bidirectional access. Possibly, only spring clips were used to ensure easy access in the event of an urgent service problem.
Re: The Security Was Possibly Via a Screwdriver
One of those square section keys I expect. Not exactly secure!
Re: The Security Was Possibly Via a Screwdriver
Yep - it was just a square key! Very easy.
"remember it is always about more than just IP access"
IP or "I pee", sounds the same to me...
Brown trouser moment...
I can only imagine the strained look on the faces of the security team when this was explained to them.
I will admit though that I've heard of security going down the crapper but never past the crapper and out the otherside..
I appreciated it at least
"more than just IP access"
Nice, reminds me of those fake names like I.P. Freely.
Also "Yellow River"
by I. P. Daly
Re: I appreciated it at least
The swan's escaped. From the castle.
And who might you be?
Mr Staker. Mr Peter Ian Staker. Yes. PI Staker.
Re: I appreciated it at least
I stumbled across an Alan Terego in an online thread the other day.
Alan, aka 'Al'...
Al Terego...
A/C.
False floors too
I once worked in a 'secure' research centre where the actual work was done behind a key coded door. However, during maintenance we found out that the void beneath the false floors outside and inside was continuous and the space was about 60 cm high, the tiles could be lifted from above with a small lever (e.g. a screwdriver) and from below just by lifting them, so you could in principle crawl past the locked door from outside.
Re: False floors too
I admit, I've never had to do work in an environment with false floors, but 60cm seems like a hell of a large space to me!
I dread to think how many bodies you were hiding down there.
Re: False floors too
"I dread to think how many bodies you were hiding down there."
No room for them - too many cables. That's why the BOFH favours carpet, quicklime and a shallow grave in dense woodland.
Re: False floors too
...but 60cm seems like a hell of a large space to me!
Only 60cm? I've worked in a few DCs with deeper floor voids, so easily deep enough to crawl through comfortably. The first was for a large mainframe site, and asked the facility manager why. Answer was because it used forced air underfloor cooling*. And being a big IBM (ok, Amdahl 5990-1400E) shop, the floor void needed enough space to accomodate massive channel cables that were probably 3cm in diameter, with brick-sized connectors, plus all the thick serial cables going to channel controllers, FEPs etc.
So it allowed decent cable routing & management, without restricting airflow too much. Plus it made it easier for us to do the human ferret thing and crawl under the floor dragging cables. And despite being a secure DC with an even more secure room inside it, we could crawl into that room because the drywall only went as far as the floor tiles. That got fixed by adding sheetrock under the tiles.. Which we then improvised some cable routes with a couple of large screwdrivers. High security doors and mantrap entrances may impress manglement and clients, but won't defeat a determined attacker who can make their own entrance using a skillsaw or a large hammer.
That was a fun introduction to big IT and DC design. I also learned that a lot of DCs since shared the same problem. Plus other incipient risks, like using non-plenum rated cables between fire zones, and the challenges of creating fire stops that could be easily managed if new cables needed to be run.
*Naturally we abused the underfloor cooling and used it to keep a couple of slabs of beer cool under the floor of our comms room inside the DC.
Re: False floors too
Current working location, very large, very old building. Was on the 'third' floor with an FM team to work out where we could possibly run some cables (assuming the 'aboves' would even let us once they saw the plan; they didn't). The FM guy, popped up the floorboards in the corridor and I was expecting maybe a one- or two-foot drop to the ceiling of the floor below, and maybe some rafters and old conduit running around. Nope, it was about eight feet straight down to a solid concrete (?) layer you could walk around on. You could have lived down (up?) there.
A/C b/c location.
Re: False floors too
There was a Telco *unmanned* Data Centre which I had to visit often where the outer wall of the building was literally next to a public pavement (within 50cm or so) and the card-activated door opened outwards.
On multiple occasions as I was about to use my access card I noticed that the door was already sitting about 2-3cm ajar. It seems that sometimes when the door closed (via typical "auto close" mechanism) sometimes it "bounced" and never actually closed. So the open door would be in full view of anyone walking (in one direction) along the pavement.
There were allegedly sensors in place that should have detected any such "door open" events and triggered alarms at the off-site security monitoring station but either that was not the case or else security routinely ignored them.
I've heard of a including a backdoor for system access...
But a back passage for cistern access???
yellow team?
As pen testers like their team colours
Re: yellow team?
Blue-loo team.
Simple
A piece of piss really.
In the 90s I did some work in Moscow in the Central Telegraph building. I was on the civilian side, the other side was restricted military. The toilets were common to both but there was little danger of anyone crossing due to the stench which was only alleviated by the cigarette smoke
You could always smuggle a USB stick out...
by attaching it to a piece of string, dropping it in the bog and intercepting it further down the sewerage system using a bit of bent wire and pulling it back up the pipework.
But that would be a flash in the pan.
I remember many, many moons ago whilst working for a company that liked to keep a tight control on 'expensive' office supplies (think boxes of floppy disks), they decided to lock everything up in a small room - with an 8 foot wall which could easily be climbed over due to someone deciding it would be also be a good idea to put filing cabinets up against said wall. Both sides.
Maybe some engineers requested they build it that way, you know, just for the sake of convenience.
Alternatively, it may perfectly demonstrate the way in which bean-couters consider proper security as a drain on finances.
Crappy security
at this data center.