Deviant's Lock Advice - Part 05 - Privilege Escalation

preview_player
Показать описание
This is a long-ish video, I know. But it covers an important vulnerability and shows how it can be exploited.

If someone is issued a working key (even a key with very low permissions) as part of a master-keyed system, then that individual can typically pivot from there and use the bitting info from their issued key to attempt a privilege escalation attack and discover the key bitting measurements for the master key in that system.

If suitable key blanks are accessible, there is almost nothing that can be done to stop this kind of attack. This is why we recommend higher-security lock solutions to many of our clients... ones where blanks are harder to obtain or key cutting is harder to perform. There's often still *some* attack vector, even on more advanced systems, but it sure makes it harder.

This video shows a master key privilege escalation attack (the same kind written up by Matt Blaze nearly two decades ago!) in action. It's a LOT faster than many folk might think!

- -- ----- ----------
this is my personal web site. most things i create wind up online...

this is my company. we're good at stuff...

this is where i train. come and learn badass skills...
- -- ----- ----------

Andy Tait, the creator of the PCB version of my Devious Decoder Card, is here on YouTube...

Matt Blaze's write-up concerning the vulnerabilities inherent in master-keyed systems is here...

- -- ----- ----------

NOTE: The winners of some CH751 keys have been chosen. By random selection the winners are Ege Feyzioğlu, Adam Kentrop, Fyrchkn, and Bruno Johnson. That's right, we gave away MULTIPLE keys! ^_^ I will reply to them below and we'll hopefully connect soon. Nice work, everybody!
Рекомендации по теме
Комментарии
Автор

"every time something doesn't work, I'll take a drink"

That's a positive feedback loop lol

cosmicatrophy
Автор

One time I locked my self out of my car with my keys on the dash. The locksmith I called looked through my windshield and used a pak-a-punch to cut a new door key. I was very impressed and got a new door key included with my unlock. I went home and drank some Shiraz to celebrate.

gravewalkerz
Автор

I love this a bit more than the talk you did on attacking master systems because it also perfectly demonstrated the way that you protect yourself from that attack.

Since I've already got myself a ch751, I'll go ahead and not add in the code word this week.

ConnorNolanTech
Автор

That really didn't felt like 30 min, great videos in general! Syrah

Marko-St
Автор

I got the master key for the apartment complex where I used to live. Instead of doing it like this, I found it on a keyring in the property manager's unlocked desk drawer in the basement. Advantage: only had to carry one key for both my apartment and the shared doors. Disadvantage: had to be careful to not drunkenly key into the wrong apartment.

timewave
Автор

Love how you turned it into a drinking game too 😂😂😂
To make it easy for my simple mind, it's like brute forcing numbers on a combination lock where you know all the numbers apart from one, so you try every number on the unknown, then move along to the next pin and start over, okay it's not exactly the same, but it's keeping the method of what's going on simple in my mind, I always try and simplify things, even it's it's not exactly right.
Still loving all the content 👍👍👍

legion
Автор

Watched the whole series. Very nice. I keep seeing that rhinoceros glass and it makes me think of a bar in my town. A dive that also caters to the more exploratory beer and whiskey drinkers. If indeed you got it in missoula, that is mighty awesome to me.

chrisw
Автор

This may be a dumb question and on a two year old video probably no answer will come, but is there a practical reason to not use the invalid positions (around 7:00)? If you rekey them yourself anyway, why not break the rules and make it more difficult?

supermario
Автор

You, syrah, are a scholar and a gentleman. Thanks for the edutainment!

andrewwade
Автор

Thanks for making these videos, they are very informative. Would love to take a class one day, but the lack of time and money shoots that down. I'm glad yall are looking into an online version of the classes though.

Minionz
Автор

I never knew Schlage master systems usually skipped every other cut. Great vid!

thelockpickinglebowski
Автор

Really enjoyed watching the video series. Did have a glass of wine during it but not Syrah as I had never heard of it before. Looks like I will be trying new things here shortly. Stay safe everyone.

braddiel
Автор

I love how much AvE's way of talking has permeated your video making. "Chooch" has entered my vocabulary personally, but I just don't have much reason to tell "focus you fuck" to a camera

thomasrogers
Автор

In case anyone is wondering, the reason he crosses out the bittings one above and below the basic key is because master wafers that are one bitting depth tall don’t exist, or are at least a very bad idea to use because of their tendency to get shaken around and disoriented. Edit: Syrah

CWGminer
Автор

You’ve definitely earned your Syrah this week! Thanks for these videos, great presentation and full of great info.

compgeek
Автор

I caught the locksport bug at Linux.Conf.Au 2020, and have found your videos really helpful and insightful. Thanks for providing your content!

grahambalderstone
Автор

I've got an emergency. A legitimate cause for worry I tell you.

I've been on "lock down" for a couple weeks now and I'm running low on proper drink. Plenty of vodka, gin, and tequila left, but my whisky is scary low. Brandy is completely gone. Send help please.

DEATH_TO_TYRANTS
Автор

You, sirrah, are a true gentleman, and I'm glad you've been willing to make this whole series. I wouldn't make good use of that S*ra* giveaway key, but I hope it goes to someone who enjoys it.

kopasedik
Автор

Syrah, not a dry kind of guy; but if it is wet, ill drink it!


Nice Vjayo (for the aVe Comment). Good stuff, you got me hooked on your stuff a few years ago with Elevator Hacking: From the Pit to the Penthouse.


You got a nice gig!

rmarine
Автор

I like to test the depths with a dial micrometer, since sometimes the cuts with the pak-a-punch are slightly out. An important thing to note is to watch how he squeezes the punch before clipping. I should note that if you're going to file by hand, the real locksmith pippin files are kind of nice to have. I really like the Primus system since they're relatively hard to pick and generate keys for (as oppposed to "trivial") but if you have the coded blanks you can easily make keys without having to invest in a fancy code machine. Is the CA751 key cut onto 997JA with bitting 5452? Are the grapes you speak of related to the Shiraz ones they use in Australia?

tedpark
welcome to shbcf.ru