Lex Luthor and The Legion Of Doom/Hackers Present: Identifying, Attacking, Defeating, and Bypassing Physical Security and Intrusion Detection Systems PART I: THE PERIMETER The reasons for writing this article are twofold: 1) To prevent the detection and/or capture of various phreaks, hackers and others, who attempt to gain access to: phone company central offices,phone closets, corporate offices, trash dumpsters, and the like. 2) To create an awareness and prove to various security managers, guards, and consultants how easy it is to defeat their security systems due to their lack of planning, ignorance, and just plain stupidity. In the past, I have written articles on "Attacking, Defeating, and Bypassing" Computer Security. Now I take those techniques and apply them to Physical Security. The information contained herein, has been obtained from research on the different devices used in physical security, and in practical "tests" which I and others have performed on these devices. INTRODUCTION: ------------- Physical Security relies on the following ideas to protect a facility: Deterrence, Prevention, Detection, and Response. Deterrents are used to 'scare' the intruder out of trying to gain access. Prevention tries to stop the intruder from gaining access. Detection 'sees' the intruder while attempting to gain access. Response tries to stop and/or prevent as much damage or access to a facility as possible after detection. There are 3 security levels used in this article and in industry to designate a facility's need. They are: Low, Medium, and High. The amount, and types of security devices used by a facility are directly proportional to the level of security the facility 'thinks' it needs. When I use 'facility' I am refering to the people in charge of security, and the actual building and assets they are trying to protect. This article will be primarily concerned with the protection of the perimeter. I have 2 other articles planned in this series. The second is the security concerning the exterior of a facility: cipher locks, window breakage detectors, magnetic contact switches, etc. The third part will deal with security systems inside a facility: Passive Infra-Red detectors, ultrasonic detectors, interior microwave systems, and the various card access control systems. THE PERIMETER: -------------- A facility's first line of defense against intrusion is its' perimeter. The perimeter may have any or all of the following: * A single fence * An interior fence coupled with an exterior fence * Regular barbed wire * Rolled barbed wire * Various fence mounted noise or vibration sensors * Security lighting and CCTV * Buried seismic sensors and different photoelectric and microwave systems Fences: ------- Fences are commonly used to protect the perimeter. The most common fence in use today is the cyclone fence, better known as the chain link fence. Fences are used as a deterrent and to prevent passage through the perimeter. Common ways of defeating fences are by cutting, climbing, and lifting. Cutting is not usually recommended for surreptitious entry, since it is easily noticeable. In this article, we will be taking the 'Stealth' approach. Climbing is most commonly done, but if the fence is in plain view, it may not be advisable since you can be seen easily. The higher the fence, the longer it takes to climb. The longer it takes to climb, the longer security has to detect and respond to your actions. Lifting is better since you are closer to the ground, and not as easily spotted, but the fence must be very flexible, or the sand very soft so you can get under the fence quickly and easily. Whenever you see a somewhat 'unclimbable' fence (or one that you just don't want to climb) you should check the perimeter for large trees with uncut branches hanging over the fence or other objects which will enable you to bypass the fence without ever touching it. You could use a ladder but you don't want to leave anything behind, especially with your fingerprints on it, not that you plan on doing anything illegal of course. Electric fences are not used for security purposes as much as they were in the past. Today, its main use if to keep cattle or other animals away from the perimeter (either from the inside or outside). There are devices which send a low voltage current through a fence and can detect a drop in the voltage when someone grabs onto the fence. Again, not too common so I will not go into it. For high security installations, there may be 2 fences. An outer fence, and an inner fence which are 5-10 yards apart. It isn't often that you see this type of setup, it is mainly used by government agencies and the military. You can be very sure that there are various intrusion detection devices mounted on the fence, buried underground between them, and/or line-of-sight microwave or photoelectric devices used. These will be mentioned later. If you insist on penetrating the perimeter, then you should try to measure how far it is between fences. Now find a 2 foot by X foot board where X is the distance between the 2 fences. Very slowly place the board on top of both fences. If there are no fence vibration sensors you can just climb the fence and step onto the board to walk across the top. If there are fence sensors, you will need a ladder which cannot touch the fence to get you on top of the board. You can then walk on the board, over the ground in between, and jump down, being careful not to disturb the fences. This will work if there are no sensors after the 2 fences. Identifying sensors will be mentioned later. Obviously the method of using a long board to put on top of the two fences will not work if the fences are spaced too far apart. Also, you and the board can be seen very easily. Barbed Wire: ------------ There are two common types of barbed wire in use today. The more common and less secure is the type that is strung horizontally across the fence with three or more rows. The 'barbs' are spaced about 6" apart, enough for you to put your hand in between while climbing over. Also, it is thin enough to be cut very easily. If you think you will need to leave in a hurry or plan on problem free surreptitious entry and the only way out will be to climb over the fence again you can cut the wire from one post to another, assuming the wire is tied or soldered to each post, and replace it with a plastic wire which looks like the wire you just cut. Tie it to each post, and come back anytime after that. You can then climb over it without being cut. The other type of wire, which is more secure or harmful, depending on how you look at it, is a rolled, circular wire commonly called Razor Ribbon. One manufacturer of this is the American Fence Co. which calls it 'the mean stuff'. And it is. The barbs are as sharp as razors. Of course this can be cut, but you will need very long bolt cutters and once you cut it, jump as far back as you can to avoid the wire from springing into your face. As mentioned earlier, cutting is irreparable, and obvious. If the wire is loosely looped, there may be sufficient room in between to get through without getting stitches and losing lots of blood. If the wire is more tightly looped you may be able to cover the the wire with some tough material such as a leather sheet so you can climb over without getting hurt. This method is not easy to accomplish however. You may want to see if you can get under the fence or jump over rather than climb it. Fence mounted noise or vibration sensors: ----------------------------------------- Let's assume you have found a way to get past the fence. Of course you have not tried this yet, since you should always plan before you act. OK, you have planned how you would theoretically get over or past the fence. You are now past the deterrent and prevention stages. Before you put the plan into action you had better check for the things mentioned earlier. If a fence is the first step in security defense, then fence mounted sensors are the second step. The types of detection equipment that can be mounted on the fence are: Fence shock sensors: These mount on fence posts at intervals of 10 to 20 feet, or on every post. They are small boxes clamped about 2/3 up from ground level. There is a cable, either twisted pair or coax running horizontally across the fence connecting these boxes. The cable can be concealed in conduits or inside the fence itself, thus, making it hard to visually detect. Each fence sensor consists of a seismic shock sensor that detects climbing over, lifting up or cutting through the fence. So if the fence is climbable, it would not be wise to do so since you may be detected. Of course it doesn't matter if your detected if there is no security force to respond and deter you. Another type, is called the E-Flex cable. It's simply a coax cable running horizontally across the fence. This cable can not only be used on chain link fences, but can also be used on concrete block, brick, or other solid barriers. It may be on the outside, or mounted inside the fence, thus, making detection of the device harder. Of course detection of this and other similar devices which cannot be seen, doesn't make it impossible. A way to detect this, is by simply repeatedly hitting the wall with a blunt object or by throwing rocks at it. If nothing out of the ordinary happens, then you can be reasonably sure it is not in place. This is basically a vibration sensor. Low frequency microphones: This is essentially a coax cable that responds to noise transmitted within the fence itself. Vibration sensors: These are based on mercury switches, a ring or ball on a pin, or a ball on a rail. Movement of the fence disturbs the switches and signals alarms. A hint that this is in use is that it can only be used on a securely constructed and tightly mounted fence, with no play or movement in it. Otherwise, they will be getting false alarms like crazy. OK, you know all about these types, how the hell do you get around it? Well, don't touch the fence. But if there is no alternative, and you must climb it, then climb the fence where it makes a 90 degree turn (the corner) or at the gate. Climb it very slowly and carefully, and you should be able to get over without being detected by these sensors! Make sure you climb on the largest pipe and don't fall. Security lighting and CCTV: --------------------------- Sometimes, fences may be backed up by Closed Circuit TV (CCTV) systems to make visual monitoring of the perimeter easier and quicker. By installing an adequate lighting system and conventional CCTV cameras, or by using special low light sensitive cameras, the perimeter can be monitored from a central point. Security personnel can then be dispatched when an intruder is detected on the monitors. Some systems are stationary, and others can be moved to view different areas of the perimeter from within the central station. It would be in your best interest to determine if the camera is stationary or not. If so, you may be able to plan a path which will be out of the view range of the camera. If it is movable, you will have to take your chances. Light control sensor: This utilizes a Passive InfraRed (PIR) sensor to detect the body heat emitted from someone entering the detection area, and can activate a light or other alarm. PIR's will be discussed in Part II of this series. The sensor has an option called: 'night only mode' in which a light will flash when a person enters the area, but only during night hours. It can tell if its dark by either a photoelectric sensor, or by a clock. Of course if its daylight savings time, the clock may not be totally accurate, which can be used to your advantage. If it is photoelectric, you can simply place a flashlight pointing directly into the sensor during daylight hours. When it gets dark, the photoelectric sensor will still 'think' its day since there is sufficient light, thus, not activating the unit to detect alarm conditions. This should enable you to move within the area at will. Buried Seismic Sensors: ----------------------- Seismic detectors are designed to identify an intruder by picking up the sound of your footsteps or other noises related to passing through the protected area. These sensors have a range of about 20 feet and are buried underground and linked by a cable, which carries their signals to a processor. There, the signals are amplified and equalized to eliminate frequencies that are unrelated to intruder motion. The signals are converted to pulses that are compared with a standard signal threshold. Each pulse that crosses this threshold is tested on count and frequency. If it meets all the criteria for a footstep, an alarm is triggered. These sensors can even be installed under asphalt or concrete by cutting a trench through the hard surface. It is also immune to weather and can follow any type of terrain. The only restriction is that the area of detection must be free of any type of obstruction such as a tree or a bush. Electronic field sensor: ------------------------ These detect an intruder by measuring a change in an electric field. The field sensors use a set of two cables, one with holes cut into the cable shielding to allow the electromagnetic field to 'leak' into the surrounding area. The other cable is a receiver to detect the field and any changes in it. Objects passing through the field distort it, triggering an alarm. This sensor can either be buried or free standing, and can follow any type of terrain. But its very sensitive to animals, birds, or wind blown debris, thus, if it is very windy out, and you know this is being used, you can get some paper and throw it so the wind takes it and sets off the alarm repeatedly. If it is done enough, they may temporarily turn it off, or ignore it due to excessive false alarms. It is not hard to tell if these devices are in use. You cannot see them, but you don't have to. Simply get 3-4 medium sized stones. Throw them into the place where you think the protected area is. Repeat this several times. This works on the lesser advanced systems that have trouble distinguishing this type of seismic activity from human walking/running. If nothing happens, you can be reasonably sure this is not in use. Now that you can detect it, how do you defeat it? Well as far as the electronic field sensor is concerned, you should wait for a windy night and cause excessive false alarms and hope they will turn it off. As far as the seismic sensors, you can take it one step at a time, very softly, maybe one step every 30-60 seconds. These sensors have a threshold, say, two or more consecutive footsteps in a 30 second time interval will trigger the alarm. Simply take in one step at a time, slowly, and wait, then take another step, wait, until you reach your destination. These detectors work on the assumption that the intruder has no knowledge of the device, and will walk/run across the protected area normally, thus, causing considerable seismic vibrations. The problem with this method is that it will take you some time to pass through the protected area. This means there is more of a chance that you will be seen. If there are a lot of people going in and out of the facility, you may not want to use this method. Another way would be to run across the protected area, right next to the door, (assuming that is where the response team will come out) and drop a large cat or a dog there. When they come out, they will hopefully blame the alarm on the animal. The sensor shouldn't really pick up a smaller animal, but odds are the security force are contract guards who wouldn't know the capabilities of the device and the blame would fall on the animal and not you, assuming there were no cameras watching... Microwave systems: ------------------ In an outdoor microwave system, a beam of microwave energy is sent from a transmitter to a receiver in a conical pattern. Unlike indoor microwave detectors, which detect an intruders' movement in the microwave field, the outdoor system reacts to an intruders' presence by detecting the decrease in energy in the beam. The beams can protect an area up to 1500 feet long and 40 feet wide. All transmission is line-of-sight and the area between transmitter and receiver should be kept clear of trees and other objects that can block the beam. Microwave systems can operate in bad weather, and won't signal an alarm due to birds or flying debris. These systems work on the Doppler effect, in which they detect motion that changes the energy, and sets off an alarm. These devices will usually be placed inside a fence to avoid false alarms. These devices are very easy to visually detect. They are posts from 1-2 yards high, about 6 inches by 6 inches and there are 2 of them, one receiver and one transmitter. In some cases there will be more, which enables them to protect a larger area. To defeat this, you can enter the field, very slowly, taking one step at a time but each step should be like you are in slow motion. It doesn't matter how hard you hit the ground, since it doesn't detect seismic activity, only how fast you approach the field. If you take it very slowly you may be able to get past. Detectors of this type get more and more sensitive as you approach the posts. Ergo, choose a path which will lead you furthest away from the posts. Photoelectric systems: ---------------------- These systems rely on an invisible barrier created by beams of infrared light sent from a light source to a receiver. When the beam is interrupted, the alarm sounds. The beam can have an effective range of up to 500 feet. Multiple beams can be used to increase the effectiveness of the system, making it harder for you to climb over or crawl under the beams. Photoelectric systems can be prone to false alarms as a result of birds or wind-blown debris passing through the beam. The problem can be corrected by the installation of a circuit that requires the beam to be broken for a specified amount of time before an alarm is sounded. Weather conditions like heavy fog, can also interrupt the beam and cause an alarm. This can also be corrected by a circuit that reacts to gradual signal loss. These systems should not face directly into the rising or setting sun since this also cuts off the signal beam. As you can see this system has many problems which you can take advantage of to bypass this system. As with any system and method, surveillance of the facility should be accomplished in various weather conditions to help verify the existence of a particular detection device, and to see how they react to false alarms. Many times, you will be able to take advantage of various conditions to accomplish your mission. If there is only one set of devices (transmitter and receiver), try to estimate the distance of the sensors from the ground. You can then either crawl under or jump over the beam. This also works on the assumption that the intruder will not recognize that the device is in use. MISCELLANEOUS: -------------- Guards: There are two types, in-house or company paid guards and contract guards. Contract guards are less secure since they do not work for the facility and if they make a mistake they simply get transferred to another facility no big deal. In-house guards know the facility better and have more to lose, thus, they are probably more security conscious. Be aware of any paths around the perimeter in which guards can/will walk/ride to visually inspect the exterior of the facility. Central monitoring: Monitoring of the devices mentioned in this article is usually accomplished at a 'Central Station' within the facility. Usually, guards *SHOULD* be monitoring these. If you have planned well enough, you may find that the guard leaves his/her post to do various things at the same time every night. This would be an ideal time to do anything that may be seen by cameras. Unfortunately, there will probably be more than one guard making this nearly impossible. Gates: Probably the easiest way to pass through the perimeter is to go through the gate. Whether in a car, or by walking. This may not be too easy if it is guarded, or if there is a card reading device used for entry. Exterior card readers: An in-depth look at the types of cards used will be in part 3 of this series. But for now, if the card used is magnetic (not Weigand) it is quite possible to attack this. If you have an ATM card, Visa, or other magnetic card, slide the card thru, jiggle & wiggle it, etc. and quite possibly the gate will open. Reasons for this are that since it is outside, the reader is subjected to extreme weather conditions day in and day out, thus, the detecting heads may not be in the best of shape, or since it is outside it may be a cheap reader. In either case, it may not work as good as it should and can make 'mistakes' to allow you access. Combinations: The devices listed in this article do not have to be used alone. They can and are used in conjunction with each other for greater security. Diversions: In some cases, a diversion could better insure your passage through the perimeter. Keep this in mind. Extreme weather conditions: All devices have an effective operating range of temperatures. On the low end of the scale, most devices will not operate if it is -30 degrees Fahrenheit or lower. Though, quite a few will not operate effectively under the following temperatures: -13 f, -4 f, +10 f, +32 f. On the other side of the scale, they will not operate in excess of: +120 f, +130 f and +150 f. It is unlikely that the outside temperature will be above 120 degrees, but in many places, it may be below freezing. Take this into consideration if a facility has these devices, and you cannot bypass them any other way. I could not have possibly mentioned everything used in perimeter protection in this article. I have tried to inform you of the more common devices used. Some things were intentionally left out, some were not. I welcome any corrections, suggestions, and methods, for this article and the future articles planned. I can be contacted on a few boards or through the LOD/H TJ Staff Account. CONCLUSION: ----------- This article primarily dealt with the identification of various 'tools' used in physical security for the deterrence, prevention, detection, and response to an intruder. There also were some methods which have been used to attack, defeat, and bypass these 'tools'. None of the methods mentioned in this article work 100% of the time in all circumstances, but ALL have worked, some were under controlled circumstances, some were not. But all have worked. Some methods are somewhat crude, but they get the job done. Some methods were intentionally left out for obvious reasons. Even though this article was written in a tutorial fashion, in no way am I advising you to go out and break the law. I am merely showing you how to identify devices that you may not have known were in place to keep you from making a stupid mistake and getting caught. The Establishment doesn't always play fair, so why should we? ACKNOWLEDGEMENTS: ----------------- Gary Seven (LOH) Lex Luthor and The Legion Of Doom/Hackers Present: Identifying, Attacking, Defeating, and Bypassing Physical Security and Intrusion Detection Systems PART II: THE EXTERIOR INTRODUCTION: ------------- The 'exterior' refers to the area directly outside of a building and the things within the building which are on the exterior. These obviously are: doors, air conditioning ducts, windows, walls, roofs, garages, etc. I don't believe the word 'exterior' is the exact definition of what this article will encompass, unlike the 'perimeter', but it's the best I could come up with. This article primarily is of an informative nature, although methods of "attacking, defeating, and bypassing" will be explained. Its purpose is not specifically to encourage you to breach a facility's security, although I acknowledge that it could be used as such. Some of the devices mentioned in the physical security series are used in homes as well as corporate, industrial, and military installations, but my aim is specifically towards the commercial aspect of buildings, not homes and apartments. Entering a facility to obtain information such as passwords or manuals is one thing, breaking into someones' home to steal their personal belongings is another. THE EXTERIOR: ------------- A facility's second line of defense against intrusion is its' exterior. The exterior may have any or all of the following: * Window breakage detectors * Keypad systems * Card access control systems * Magnetic locks and contacts * Security lighting and CCTV CCTV which is also used, was mentioned in Part I: The Perimeter. Card Access Control devices will be mentioned in Part III: The Interior. WINDOWS: -------- Windows are a large security hole for buildings. You may notice that many phone company buildings and data processing centers have few if any windows. There are two things that can be done to secure windows aside from making sure they are locked. One is to make them very difficult to break, and the other is to detect a break when and if it occurs. Here is a quick breakdown of the common types of glass/windows in use today: Plate glass: Can be cut with a glass cutter. Tempered: Normally can't be cut. Breaks up into little pieces when broken. Safety: You need a hatchet to break this stuff. Wire: This has wire criss-crossed inside of the glass, making it very hard to break, and even harder to actually go through the opening it is in place of. Plexy: Very hard to break, doesn't really shatter, but can be melted with the use of a torch. Lexan: This is used in bulletproof glass. One of the strongest and most secure types of glass. Herculite: Similar to Lexan. Foil tape: ---------- This is by far the most common, and probably the most improperly installed form of glass breakage detection, which also makes it the most insecure. This is usually a silver foil tape about 5/16" wide which should be placed on the whole perimeter of a glass window or door. In the case of plexyglass or a similar material, the tape should be placed in rows separated by 6-12 inches. The older foil was covered with a coating of eurathane or epoxy which enabled it to stick onto the glass. The newer foil has an adhesive back making installation much easier. There should be two connectors which are located at the upper top part of a window, and the lower part of the window which connects the foil to the processor, thus, completing the circuit. Foil may or may not have a supervised loop. If it is supervised, and you use a key to scratch the foil (when it is turned off) making a complete break in it, an alarm will sound when it is turned on. Foil is commonly used as a visual deterrent. Many times, it will not even be activated. The easiest way to determine if the facility is trying to 'B.S.'you into thinking they have a security system, is to see if there are any breaks in the foil. If there is a clean break, the 6-12V DC current which is normally making a loop isn't. Thus, breaking the glass will do nothing other than make some noise unless you take steps against that happening. As was stated, foil is the most improperly installed type of glass breakage detection. When it is installed improperly, it will not cover all the area it should. An easy way to defeat this is by the following diagram: +-------------+ ! ........... ! ! . . ! . = foil tape ! . put . ! - = top/bottom of door ! . contact . ! ! = sides of door ! . paper . ! / = dividing line between 2 pieces of contact paper ! . in . ! $ = ideal places for initial breakage ! . this +-! ' = clear area or outline of second piece of contact paper ! . area ! ! <-- door handle ! . +-! ! . . ! ! ........... ! !/////////////! !'''''''''''''! !' '! !$'''''''''''$! +-------------+ As you can see, the installer neglected to place the foil all the way down to the bottom of the glass door. There is enough room for a person to climb through. They may have thought that if someone broke the glass, it would all break, which is normally correct. But if you obtain some strong contact paper, preferably clear, adhere it to the glass as shown, and break the bottom part at the '$' it will break up to the '/' line and thats it. Thus, leaving the foil intact. This will work on tempered glass the best, and will not work on Lexan or Plexyglass. There is a transparent window film with a break strength of up to 100 pounds per square inch which can be obtained from Madico, Inc. It is called, Protekt LCL-400 XSR, and makes glass harder to break and stays essentially in place even when broken. This can be used in place of the contact paper. Obviously, it is also used to protect glass from breakage. Audio discriminators: --------------------- What these do is to compare the frequency of the sound that glass makes when it breaks, to the actual breakage of glass. This frequency is relatively unique, and can accurately determine when and if glass actually breaks. Your best shot at defeating this, is to do the same thing as mentioned above. Cover the glass with a film which will keep the glass in place after breaking it. If you break it properly, the frequency will not match that of glass breaking when it is not held in place. Glass shock sensors: -------------------- These devices detect shock disturbances using a gold-plated ring that "bounces" off a pair of normally closed gold-plated electrical contacts. This will send a signal to a Signal Processor (SP) which determines whether an alarm condition exists. There are two settings the SP can be set to which are: SHOCK-BREAK: This mode requires an initial high energy shock, followed by a very low engery shatter. The shatter must occur within about 1 second before an alarm can occur. SHOCK-ONLY: An alarm will occur once the first shock is detected. This may or may not be accompanied by a shatter. Obviously the more secure setting for a facility would be shock-only. Though, both are equally dangerous for an intruder. The methods mentioned earlier about preventing the glass from shattering will not work when this device is used in the shock-only mode. It may work, depending on the type of glass, if it isn't in the shock-break mode. These devices are usually found protecting large plate glass and multi-pane windows. They are roughly 2 inches by 1 inch and can be mounted on the frame of a window, between two windows, or on the glass itself. These sensors can cover up to 150 square feet of glass. These are the best of the lot for window breakage detection. Most devices have a constantly supervised loop, and if you cut a wire, that loop will break, and cause an alarm condition. They are typically placed somewhere on the window pane and not on the window, thus, making them harder to visually detect...from the outside that is. Though from close inspection, you may be able to determine if these are in place. Obviously they can easily be seen from the inside... The sensor is normally placed no more than a couple of inches from the glass. If it is too far away, or if you can move one over 4 inches from the glass, its detection capability is somewhat diminished. It is probably screwed in, and has an adhesive backing, so moving it may not be too easily accomplished. False alarms are not common, unless the windows rattle. There are sensors available which are not as sensitive, and will not "overreact" to slight vibration, these are called "damped" sensors. MAGNETIC CONTACT SWITCHES: -------------------------- The word "contact" is somewhat contradictory to how these devices are commonly used. In most cases, the magnet and the switch are not in physical contact of each other, rather, they are in a close proximity of each other, although there are some models which are indeed in contact with each other. There are various types and levels of security that these devices possess. They can be surface mounted (floor or wall mounted) or concealed (recessed). The most common are surface mounted which are placed on top of the door. When inspecting for these devices, examine the whole perimeter of the door, from top to bottom. Most doors have a +/- 1/4" gap all the way around, in which you should also check for concealed contacts. These are round cylinders that are recessed into the door or wall, which obviously makes them less visible. The other contacts range from miniature, with dimensions as small as 1x1/4x1/4" to the larger ones at 5x2x1". They are usually in colors of off-white, grey, and brown and are mounted with nails, screws, double sided tape, or are epoxied onto the door or wall surface(s). The switches are hermatetically sealed, as are the glass breakage detectors mentioned earlier, can operate in moist or dusty areas, are corrosion resistant and have indoor/outdoor use. They can also be used on windows, fence gates, truck trailors, boats, heavy equipment, safes, and vaults. The different types of devices in order of least to most secure are: 1) Standard Magnetic Contacts: These consist of one reed switch and one magnet. They may be defeated with the use of a second magnet which would be placed in the vicinity of the switch, while opening the door or window and while closing them also. This way, the switch never detects the abscense of the magnet, thus, no alarm occurs. 2) Biased Magnetic Contacts: These consist of one reed switch with a "biasing" magnet that changes the state of the reed switch. The magnet is then placed at the correct distance to offset the bias magnet, creating a "balanced" condition. The switch can be defeated with the use of a single magnet. The trick is to: A) You must have the correct size magnet, which can be accomplished by obtaining the same type or model as what is in place. B) You must determine the correct polarity which may be accomplished with either a compass, or if the alarm is not activated, (possibly during normal business hours), by openingthe door and placing your magnet near the device's magnet and determine the polarity. If you do not have much time, then its a 50-50 shot. C) The last criteria is to keep the magnet at the same or close to the same distance from the switch as the original magnet was. In some cases the device will be placed in such a manner that correct placement of the second magnet will be difficult if not impossible. 3) Balanced Magnetic Contacts: These consist of one biased reed switch and one unbiased reed switch. The second reed will be of the correct sensitivity and position so as to not operate with the actuator magnet. It must also operate with the addition of a second magnet. It could be defeated by a single magnet that is moved into place as the door is opened. This requires coordinated movement of the door and magnet. 4) Preadjusted Balanced Magnetic Contacts: These consist of three biased reed switches and may have an optional fourth tamper reed. Two reeds are polarized in one direction and the third is polarized in the opposite direction. The housing consists of three magnets with the polarity that corresponds to the switches. It is preadjusted to have a fixed space between the magnet and the switch. This is the most secure type of magnetic contact switch. The three-reed type could be defeated by using one of its own magnets, but not a bar magnet. The type with four reeds cannot be defeated with either of the two magnets because the fourth reed will activate when a magnet is brought within actuating distance. If you are able to determine which is the tamper reed, you can try to keep the three magnets in contact with the corresponding reeds. At the same time you must have the correct polarity, and in the process, not activate the tamper reed. If you accomplish those, you may be able to defeat it. This will most likely require two people and a bit of luck. The most secure devices are made of die cast aluminum instead of plastic, are explosion proof (for vaults and safes), have terminals mounted inside the housing which provides protection from tampering and shorting, and have armored cabling. A wider break distance will prevent fasle alarms due to loose fitting doors, thus, if the door is loose fitting it may have a wide break distance. The wider the break distance, the easier it is to defeat. This will allow you to introduce another magnet in cramped places since the door can be opened a wider distance before an alarm condition occurs. Some devices allow the installer to adjust the gap with a screwdriver instead of placing the switch a certain distance from the magnet. In some devices, use of any ferrous (Iron) material in the vicinity of the switch can cause a change in gap distance. As a gap is increased, the switch may bias and latch. When latched, the switch will remain closed even when the magnet is removed!! This means that when you open the door, it thinks that the door is closed, and you are able to stealthily go thru the door. You can test for a latched condition by removing the magnet (opening the door) and using a Volt Ohm Meter, if it reads INFINITY, the switch is OK. If not, it may be latched. If you can adjust the gap to the point of it being latched, without being noticed, you've got it made. Wireless Switch Transmitters: These are essentially the same as the other devices mentioned except that they use an FM digital signal for alarm conditions (a door or window open) and for maintenance conditions (low battery, transmitter malfunction/removal, long term jamming, etc). There should be continuous polling and a maintenance alarm will occur if the signal is missing for a few minutes. The transmitters are usually powered by a couple of AAA 1 1/2V pen cells, which can last a few years. Most devices will send out a signal after a specific interval. Common intervals are about every 30 seconds. You can verify if the device is indeed sending out a signal by placing a milliammeter capable of reading 10 ua in series with the batteries and reading the discharge current. If it occurs every 30 seconds, then it is sending out a signal every 30 seconds. A hint that this type of device is in use, is since range generally decreases as a transmitter gets closer to the floor, the transmitter will be placed as high as possible. The transmitter probably has a range of about 200 feet, although some environments may reduce this range due to construction materials inherent in the building. The frequency should be in the 314 MHz range. As was mentioned, these are the same as regular magnetic contact switches except that there is a transmitter instead of a wire for transmitting alarm and maintenance conditions, thus, the switch can be defeated in the same manner as has been previously stated. Defeating an X-mitter is much easier than defeating a wire. You can defeat the transmitter if you can sufficiently block or diminish the signal strength so that the receiver is unable to receive it. Radio waves have a tendency to bounce and reflect off of metallic surfaces, which includes foil, and pipes. If you have located the transmitter, which should be attached to or near the actual contact, you can block or jam the signal as you open the door. Hopefully this will be between the 30 second interval that it sends an "i'm ok" signal to the receiver, but it's not critical to do so. As was stated, most receivers will not cause an alarm condition if it doesn't recieve a signal once or twice, but after a few minutes it will. So, as you open the door, it tries to send the signal, you block or jam it, and you slip through without detection. This information can also apply to security relating to the 'interior' of a facility, ie. Part III of this series. Many of the techniques for defeating magnetic contact switches are geared toward being inside the facility. Many facilities have switches on doors to monitor movement of personnel within the facility. But it also is used on the exterior and some methods will work on doors and possibly windows on the exterior. Of course, you have to have a way of opening the door, and that follows. DOORS AND LOCKS: ---------------- As you know, doors are the primary entrance point into a building. Since they are the primary target for unauthorized entry, they have the most security added. I am not going to mention anything about the art of picking locks. Although mechanical locks and keys have been the most common type of security used in the past as well as today, I am going to concentrate on the more advanced security systems in use. Pushbutton keypad locks: ------------------------ There are two types, mechanical and electronic. I will go into detail about each. I will give you a few examples of these devices which comes directly from brochures which I have been sent. I am merely summing up what they said. Electronic: Securitron DK-10: This is a unit which has dimensions of 3x5x1". It has a stainless steel keypad which is weatherproof, mounts via hidden screws and has no moving parts. The keypad beeps as each button is pressed, and an LED lights when the lock is released. It is slightly different in appearence than most other electronic keypads: +----+ ! 1A ! Each block (1A/B2) is one button. Thus, there are 5 buttons ! B2 ! total on this device. The "/"'s at the bottom of the device ! ! represents the name of the company and possibly the model number ! 3C ! of the device. (ie. Securitron DK-10). It has 2-5 digit codes. ! D4 ! Thus, a 2 digit code will have a maximum of 5 the the 2nd power (5 ! ! squared=25) combinations. Of course it increases as the number of ! 5E ! digits used increase. This unit has an 11 or 16 incorrect digit ! F6 ! threshold. If it is reached a buzzer sounds for 30 seconds during ! ! which it will ignore any entries. When a valid code is entered, ! 7G ! the lock is released for a 5, 10, 15 or 20 second interval. ! H8 ! ! ! ! 9K ! ! L0 ! ! ! !////! !////! +----+ Sentex PRO-Key: This device has a keypad resembling one of a payphone. It is a sealed, chrome plated metal keypad. It has the standard 10 digits with * and #. It can have up to 2000 individual codes with a lenght of 4 or 5 digits. It allows 8 time zones, "2-strikes-and-out" software which is its invalid code threshold, and anti-passback software. Obtaining codes-- Your aim is to obtain the correct code in order to open the door. Plain and simple. There are various methods in which you can accomplish this. You can try to obtain a telescope or similar device and attempt to get the exact code as it is being entered. This is obviously the quickest method. If you cannot discern the exact code, the next best thing is to determine exactly how many digits were entered, since most devices have variable code lengths. If you can make out even one digit and when it was entered, you will substantially reduce the possibilities. Another method is to put some substance on the keypad itself, which preferably cannot be noticed by the user. After someone enters a code, you can check the keypad to see where there are smudges or if you use what the police use to find fingerprints, you can see what digits were pushed, although you will have no idea in what order. This will drastically cut down the combos. Say that someone enters a 5 digit code on a 10 digit keypad. You check the keypad and see that, 1,2, 4, 7, and 9 were pushed. If you attempted brute force, you will have 25 combinations to try. If a 4 digit code 'appeared' to be entered, as 0, 2, 4, 8 were 'smudged', it is possible that one of the digits were pushed twice. Keep that in mind. A way to know for sure would be to clean the pad and 'dust' it, most fingerprints will be clear, but one will be less clear than the others. Thus, you can be reasonably sure that the digit which is smudged was pressed twice. Thresholds-- Brute force attempts on electronic keypads is suicide. Once a certain number of invalid attempts has been reached, it will probably be logged and a guard may be dispatched. Your best bet is to try once or twice, wait (leave), try once or twice again, wait, etc. Sooner or later you will get in. Auditlogs-- Many of these devices are run on micro's. The software that runs these devices allows for an increased ability to monitor the status of these devices. They can track a person throughout the facility, record times of entry and exit, and when the maximum invalid code threshold is reached. Anti-passback-- This term is commonly used in card access control, but it applies differently to keypads. This feature prevents the use of two codes being used at the same time. That is, Joe Comosolo uses code #12345 and enters the building. Then, you enter Mr. Comosolo's code, #12345 but the system knows that Joe is already in the building, and has not entered his code before leaving. Thus, you do not gain access, and that action is most likely recorded in the audit log. This option will only be in effect when: 1) Each individual has a different code. 2) There is a keypad used for entry, and a keypad used for exit. Tailgating-- This occurs when more than one person enters through a controlled access point. Joe enters his code, and goes into the building. You follow Joe, and make it in just before the door closes, or in the case of the devices waiting 10 or 20 seconds before the door locks again, you let it close, and open it before it locks. Open access times-- During peak morning, noon, and evening hours, a facility may set the system to not require a code during, say, 8:55AM to 9:05AM, thus, enabling most anyone to gain entry during that time. }CF >A`CyyyyyyyC'q " X l ) w z $ k NHO 5"""#^##$$%%Q%&'Y''D((())u)))*d***K+|+~++,N,,a-a-./g//M002223S3/4q6t666A779:AAABBUBBB4CwCCD]DnDD9FFF!GHHLHHH4IIIJKKNNN2OOOPcPPPR(StSSkVVW WXWWZ[[[[Q_T_{________ `a`d`````aTaaccDdddddeMeeeeeeffff glhhPiiiij|jjjjjkpn qq2qRq|qqq!rnrrrrrrrrs$s'susssZtttvvvxxy\yEzzC{m{{|O||}%~p~~ ZZT9C߂-z{Ç[%mMwzȊ W;svČWAڎ$$mJސ*v[<ՓFۖ``cљG-zĤYknKHک#pS#-0CCڬ$r4ͮ7ٴU7зI׸vC%a-BK[djsZ$`Cwxyz{|}~Page - &p