Latest Posts
-
Physical Security: Abusing RFID Access Controls for Fun and Profit (3/3)
Part 3 – Brute-Forcing LF RFID Systems Next up, privilege escalation via a brute-force key attack: In a situation where you have captured an RFID tag, it may be possible to leverage that tag to escalate privileges and gain… Continue reading
-
Physical Security: Abusing RFID Access Controls for Fun and Profit (2/3)
Part 2: Spoofing LF RFID Tags Continuing from Part 1So now the equipment is setup, it’s time to play with LF. This post looks at reading/replaying low frequency RFID tags to simulate the common low frequency proximity badge access cards… Continue reading
-
Physical Security: Abusing RFID Access Controls for Fun and Profit (1/3)
Part 1 – An Approach to Testing RFID Controls One of the fun things to test during a physical pentest is RFID access controls. RFID badge/reader systems are all over, controlling access to parking lots/structures, office buildings and other restricted… Continue reading
-
iOS App Pentesting – Part 2: Getting to Know the App
Ok, I’ve lagged with this article…time to get on with it! So once the iOS device is setup and ready for analysis, the next step is to get to know the app. The following steps will be taken for this… Continue reading
-
iOS App Pentesting – Part 1: Getting Set up
It’s apparent (and becoming more and more so as time goes on) that our computing needs have evolved and have migrated from our desktops and laptops to our handheld phones and tablets. These mobile devices have brought us much convenience… Continue reading



