Talk

Access Granted: Uncovering RFID Readers Vulnerabilities & Bypassing Physical Access Controls

March 13, 16:00 (CAMPUS)

RFID access control systems are becoming increasingly popular and are now commonplace in office buildings, hotels, apartment complexes, universities, and many other locations. You probably heard about RFID tags cloning, or even tried it. But what if cloning someone’s card isn’t an easy option? How else can one gain entry into high-security areas without direct access to the credentials? 

In my presentation, I will discuss techniques for bypassing physical access control security mechanisms in Red Teaming scenarios. We will see:

  • how to intercept the communication between the reader and the controller that are using the Wiegand protocol, along with the demo of this attack;
  • how the reader can be weaponized to perform downgrade attack, allowing for the creation of a malicious clone of a card that would otherwise be difficult to forge;
  • how the OSDP protocol addresses the shortcomings of Wiegand, and what are the security implications of using it; 
  • what are the other ways to bypass the access control security mechanisms? 

I will also share some interesting and fun stories from Red Team engagements, demonstrating practical applications of these techniques in real-life scenarios – hopefully without getting caught 😉

Speaker

Julia Zduńczyk

Julia performs penetration tests and physical Red Teaming for a wide range of IT Projects as an IT Security Specialist at SecuRing. Her main area of interest revolves around Red Teaming, specifically access control systems, RFID hacking, social engineering and other related topics.

Julia's passion for sharing knowledge has given her the opportunity to speak at security conferences across Europe. She was chosen as the top speaker at CONFidence 2023 (Cracow, Poland) and received the title of the best speaker at SEC-T 2023 (Stockholm, Sweden). She also presented at No Hat (Bergamo, Italy), Insomni’Hack (Lausanne, Switzerland), BSides Kraków, UYBHYS (Brest, France) and HackCon (Oslo, Norway).

In her free time she enjoys finding different hobbies such as e.g. climbing, freediving or caving - skills learned through some of these can sometimes be surprisingly helpful during physical Red Team tests 😉

Organized by

Sponsors

Technology partners

Partner events

Scroll to Top