In case you want a place to talk about physical security, but don't like the culture or constant advertising of reddit, @breakerandahalf and I run the physec community over at https://lemmy.blahaj.zone/c/physec.

#physec #physicalsecurity #physicalpentesting #pentesting #redteam #blueteam #purpleteam

Physical Security and Pentesting - Blรฅhaj Lemmy

[email protected] is a community dedicated to physical security and penetration testing. Rules: 1. Be kind to each other. 2. Donโ€™t break into systems that arenโ€™t yours without permission. Sites of Interest: - Lock Wiki [http://www.lockwiki.com/index.php/Main_Page], a great wiki with articles on various locks,lockpicking and bypass techniques. - Manuals for Common Alarm Panels [http://www.panelguides.com/panel-guides] - Lock Picking 101 is a forum for learning how to pick locks. [http://www.lockpicking101.com/] - The Open Organization Of Lockpickers [http://toool.us/] is a great community of lock enthusiasts and professionals and a great group to learn from. Here are various stores that sell lock picking and physec testing tools: - https://redteamtools.com [https://redteamtools.com] - https://covertinstruments.com [https://covertinstruments.com] - https://thinkpeterson.com [https://thinkpeterson.com] - https://sparrowslockpicks.com [https://sparrowslockpicks.com] - https://hooligankeys.com [https://hooligankeys.com] - https://hackerwarehouse.com/ [https://hackerwarehouse.com/] - http://www.wallofsheep.com/ [http://www.wallofsheep.com/] - http://www.serepick.com/products/index.html [http://www.serepick.com/products/index.html] - http://www.lockpickshop.com/ [http://www.lockpickshop.com/]

Just finished up another fun SE/physical onsite pentest.

Physical security at this location was TIGHT. Some of the best I've ever seen. iClass SEOS with Elite Keys; downgrade disabled, Mantrap-style turnstiles with reverse-tailgate detection, ADA doors require manual unlock from security (Is that even legal? ๐Ÿค”). Two layers of 8 foot high anti-trespass fencing around the whole perimeter. Mirrored windows. Security cameras everywhere with 24-7 on-site monitoring.

ESPKey was basically my only shot at a technical/physical bypass. I couldn't get them to agree to let me try it, but I honestly wouldn't be surprised if they were actually using OSDP.

So I showed up carrying a cardboard box and security just buzzed me in. ๐Ÿ™„ ๐Ÿคฃ ๐Ÿฅบ

#pentesting #physec #onsite #socialengineering #metalgearbox

Sparrows is having a training class at a prison, and I kinda wanna go.

https://youtu.be/A6JxzSLKG9Q?si=EiqKWlosxekocJYh

#locksport #lockpicking #physec

We rented a prison. You're invited.

YouTube

One critical #infosec thing that will come out in the court system in the next zero to 20yrs will be prosecutions around illegal #nanotech #opticalimplants at the optic nerve in the back of the eye.

An optometrist can image the back of the eye for you to check both of your eyes to see if you have been illegally implanted against your will. If you are being harassed with an #audioloopfeedback in addition to this eye implant that is a cause for great concern. This is a manipulation of you scenario.

This can cause massive physec and infosec security issues in your life from all your passwords being breached, all your keys to things copied and massive loss in physical security in your life. The key is finding which eye or both eyes have the implants, closing that eye, never looking with that eye to your keys and changing your locks and keys often.

You more than likely also have illegal #StateSponsoredMalware installed on your computers and phones and tablets also.

Keep track of the harassment participants names. This will be key later for prosecutions.

#physec #infosec #illegaleyeimplants #eyeimplants #nanotech #illegalnanotechimplants

Gotta l๐Ÿ˜ve #3rdPartyData in #PhySec Dirs / Listed! โ˜‘๏ธ๐Ÿ˜‹๐Ÿ’ฏ๐Ÿค

Know Your Audience in...

#PR๐Ÿค#Legal

In the under #Fortune100 when on camera underlings can cite dates when something stolen by someone Director Level was seen on camera and watch how Legal & PR handle things or not in #infosec๐Ÿค#PhySec ๐Ÿ‘€๐Ÿ‘€๐Ÿ˜‹

The sign of a #ToxicBrand in #FreeWebHosting is annually illustrated by a msg from the #PhySec of said company, saying:

"Don't. Wear. Our. Logos. Home. For. November OR December holiday season."

๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ’ฏ #infosec ๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ’ฏ

Would you say #CBP is the #physec
'router guards' for #BGP in #infosec or nah, @CISA ? /Joke ๐Ÿ˜…

Edit: Obviously this only applies to ~100 miles FROM ) INland of the #BGP router, right? ๐Ÿ˜…๐Ÿ˜‡

This is my wallet sized covert entry EDC. All the bypass tools at the bottom fit in the back of the larger lock pick case. The smaller set in the top left is hidden in a second spot inside my wallet. I've been expanding capabilities over time as I've been learning about this profession and plan a few more additions from this point. Thanks for open sourcing your knowledge @deviantollam! #InfoSec #PhySec #RedTeam #CovertEntry