Roles to play when tailgaiting into a residential building
Following people into a large RFID protected residential building is ridiculously easy, as not everyone knows everyone else. Just the other day I was let in with a rifle (an airgun, but how could have they known).
But standing helplessly in front of the door, looking in sorrow at the lock, is not the best role to play as it attracts questions like "who are you" or "who are you visiting".
What is a more appropriate behavior when waiting around for someone to enter?
social-engineering physical-access
|
show 3 more comments
Following people into a large RFID protected residential building is ridiculously easy, as not everyone knows everyone else. Just the other day I was let in with a rifle (an airgun, but how could have they known).
But standing helplessly in front of the door, looking in sorrow at the lock, is not the best role to play as it attracts questions like "who are you" or "who are you visiting".
What is a more appropriate behavior when waiting around for someone to enter?
social-engineering physical-access
44
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
17
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
70
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
15
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
7
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26
|
show 3 more comments
Following people into a large RFID protected residential building is ridiculously easy, as not everyone knows everyone else. Just the other day I was let in with a rifle (an airgun, but how could have they known).
But standing helplessly in front of the door, looking in sorrow at the lock, is not the best role to play as it attracts questions like "who are you" or "who are you visiting".
What is a more appropriate behavior when waiting around for someone to enter?
social-engineering physical-access
Following people into a large RFID protected residential building is ridiculously easy, as not everyone knows everyone else. Just the other day I was let in with a rifle (an airgun, but how could have they known).
But standing helplessly in front of the door, looking in sorrow at the lock, is not the best role to play as it attracts questions like "who are you" or "who are you visiting".
What is a more appropriate behavior when waiting around for someone to enter?
social-engineering physical-access
social-engineering physical-access
asked Nov 15 '18 at 13:13
VoracVorac
99331322
99331322
44
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
17
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
70
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
15
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
7
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26
|
show 3 more comments
44
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
17
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
70
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
15
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
7
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26
44
44
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
17
17
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
70
70
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
15
15
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
7
7
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26
|
show 3 more comments
6 Answers
6
active
oldest
votes
There are some basic social engineering approaches to use that work in most situations, not just tailgating:
- urgency
- authority
- curiosity
- pretexting
Urgency
Be someone with a specific task to perform that needs to be done right now. The classics are a delivery person with full arms and someone looking to pick someone else up. A family member needing to check on an elderly resident. People want to be helpful and they don't think that you will be around long enough to be a threat.
Authority
Be someone who the gatekeeper has no right or reason to refuse. Fire marshal, utilities inspector, law enforcement, building security, process server. Lots of studies of people being let in with a just clipboard and a high-visibility vest.
Curiosity
To get close to someone, be very interesting in such a way that they want to know more. Dress up as a clown to deliver a telegram.
Pretexting
Establish a shallow relationship that appears to be deeper. Smoking with people outside on their break is classic. The smokers will assume you are also an employee (why else would you be there?)
Combinations
But these work even better in combination. A fire marshal in an awful rush. A clown who claims he was at the last company party (and knows a few important names). The more combinations you can combine, the more effective the process is — an authority figure, in a rush, to do something interesting, who claims to have a preexisting relationship. If you go over the top or try too hard, it will backfire, though.
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
|
show 6 more comments
Just stand outside the door at some distance talking on your phone. Don't look at the door, don't look at the person coming to open it, don't look like you want to get in. Don't ask to be let in. Don't engage in conversation. Just let the person open the door and go through. Then in the last second before it closes and lock, you calmly walk through still talking on your phone.
Wearing a costume or high-vis will make you... well, highly visible. In some places you might need the costume and the excuse to get in. But in a lot of places, just blending in like an unmemorable nobody is quite enough. Dress like you belong, don't ask, just walk.
As a disclaimer I should note that I have no professional experience with this. But I do use it all the time to get into my office when I forget my RFID tag.
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.
– Strikegently
Nov 16 '18 at 16:07
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
add a comment |
The main element, as you've said, is to not look like you're waiting for your mark to arrive. What you need is a prop that gives a visual indication why you're standing outside the door.
Useful props (that would explain your presence) would include:
- Cigarette or e-Cig.
- Lunch-bag(s).
- Coffee(s) from a local distributor.
- Box of doughnuts.
Having a bulky item or two of something (one in each hand) is especially useful because it would explain why you can't reach for a pass.
Story-time. I was working for a company that had access passes. A local hoodlum bought himself a cheap suit and tried to tailgate into the side-entrance. He was stopped by a member of staff as per the company policy. The hoodlum brazened it out by asking him "was it because he was black?" and the member of staff immediately apologised. The hoodlum demanded his manager's name (so he could make a complaint) and received even more profuse apologies.
The 'mark' then helped him to take laptops out of the conference suite and load them into the back of an unmarked van.
Moral of the story? Social engineering simply requires confidence
add a comment |
Buy one of these:
Look rushed, and knock on the window/door until someone lets you in. Once inside ask for a random name, and have a screenshot of the doordash app on your phone. (Preferably with the name showing)
If you're feeling ambitious:
Become a legitimate employee of doordash (it's not difficult), and then order food to that building from yourself with instructions to go and find someone specific at the company you are targeting.
Have the "customer" leave specific instructions as to where in the building they are. "I'm in the far east corner, in the meeting room. Just show this to the receptionist and tell her that [the CEO] said to let you in". If you encounter further locked doors show the note to the receptionist and ask if they can help you out: "Could you help me find that room?" "My phone is out of data, do you have wifi I could log into?" etc. etc.
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
add a comment |
People are helpful by nature. Approaching a door with your hands full, for example with a huge gift wrapped box, will encourage people to open the door for you, no questions asked.
add a comment |
Residential building? "pretend" to be a tradesman - you don't even need a costume or fake ID in many cases.
I know of a number of residential buildings in my area where on a weekday before 12:00, pressing the TRADE button on the access panel just opens the door.
Instant access and no subterfuge. Of course it depends on the building, but if it has an access option like this...
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "162"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
noCode: true, onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f197732%2froles-to-play-when-tailgaiting-into-a-residential-building%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
6 Answers
6
active
oldest
votes
6 Answers
6
active
oldest
votes
active
oldest
votes
active
oldest
votes
There are some basic social engineering approaches to use that work in most situations, not just tailgating:
- urgency
- authority
- curiosity
- pretexting
Urgency
Be someone with a specific task to perform that needs to be done right now. The classics are a delivery person with full arms and someone looking to pick someone else up. A family member needing to check on an elderly resident. People want to be helpful and they don't think that you will be around long enough to be a threat.
Authority
Be someone who the gatekeeper has no right or reason to refuse. Fire marshal, utilities inspector, law enforcement, building security, process server. Lots of studies of people being let in with a just clipboard and a high-visibility vest.
Curiosity
To get close to someone, be very interesting in such a way that they want to know more. Dress up as a clown to deliver a telegram.
Pretexting
Establish a shallow relationship that appears to be deeper. Smoking with people outside on their break is classic. The smokers will assume you are also an employee (why else would you be there?)
Combinations
But these work even better in combination. A fire marshal in an awful rush. A clown who claims he was at the last company party (and knows a few important names). The more combinations you can combine, the more effective the process is — an authority figure, in a rush, to do something interesting, who claims to have a preexisting relationship. If you go over the top or try too hard, it will backfire, though.
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
|
show 6 more comments
There are some basic social engineering approaches to use that work in most situations, not just tailgating:
- urgency
- authority
- curiosity
- pretexting
Urgency
Be someone with a specific task to perform that needs to be done right now. The classics are a delivery person with full arms and someone looking to pick someone else up. A family member needing to check on an elderly resident. People want to be helpful and they don't think that you will be around long enough to be a threat.
Authority
Be someone who the gatekeeper has no right or reason to refuse. Fire marshal, utilities inspector, law enforcement, building security, process server. Lots of studies of people being let in with a just clipboard and a high-visibility vest.
Curiosity
To get close to someone, be very interesting in such a way that they want to know more. Dress up as a clown to deliver a telegram.
Pretexting
Establish a shallow relationship that appears to be deeper. Smoking with people outside on their break is classic. The smokers will assume you are also an employee (why else would you be there?)
Combinations
But these work even better in combination. A fire marshal in an awful rush. A clown who claims he was at the last company party (and knows a few important names). The more combinations you can combine, the more effective the process is — an authority figure, in a rush, to do something interesting, who claims to have a preexisting relationship. If you go over the top or try too hard, it will backfire, though.
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
|
show 6 more comments
There are some basic social engineering approaches to use that work in most situations, not just tailgating:
- urgency
- authority
- curiosity
- pretexting
Urgency
Be someone with a specific task to perform that needs to be done right now. The classics are a delivery person with full arms and someone looking to pick someone else up. A family member needing to check on an elderly resident. People want to be helpful and they don't think that you will be around long enough to be a threat.
Authority
Be someone who the gatekeeper has no right or reason to refuse. Fire marshal, utilities inspector, law enforcement, building security, process server. Lots of studies of people being let in with a just clipboard and a high-visibility vest.
Curiosity
To get close to someone, be very interesting in such a way that they want to know more. Dress up as a clown to deliver a telegram.
Pretexting
Establish a shallow relationship that appears to be deeper. Smoking with people outside on their break is classic. The smokers will assume you are also an employee (why else would you be there?)
Combinations
But these work even better in combination. A fire marshal in an awful rush. A clown who claims he was at the last company party (and knows a few important names). The more combinations you can combine, the more effective the process is — an authority figure, in a rush, to do something interesting, who claims to have a preexisting relationship. If you go over the top or try too hard, it will backfire, though.
There are some basic social engineering approaches to use that work in most situations, not just tailgating:
- urgency
- authority
- curiosity
- pretexting
Urgency
Be someone with a specific task to perform that needs to be done right now. The classics are a delivery person with full arms and someone looking to pick someone else up. A family member needing to check on an elderly resident. People want to be helpful and they don't think that you will be around long enough to be a threat.
Authority
Be someone who the gatekeeper has no right or reason to refuse. Fire marshal, utilities inspector, law enforcement, building security, process server. Lots of studies of people being let in with a just clipboard and a high-visibility vest.
Curiosity
To get close to someone, be very interesting in such a way that they want to know more. Dress up as a clown to deliver a telegram.
Pretexting
Establish a shallow relationship that appears to be deeper. Smoking with people outside on their break is classic. The smokers will assume you are also an employee (why else would you be there?)
Combinations
But these work even better in combination. A fire marshal in an awful rush. A clown who claims he was at the last company party (and knows a few important names). The more combinations you can combine, the more effective the process is — an authority figure, in a rush, to do something interesting, who claims to have a preexisting relationship. If you go over the top or try too hard, it will backfire, though.
edited Nov 17 '18 at 20:41
NieDzejkob
1033
1033
answered Nov 15 '18 at 13:29
schroeder♦schroeder
77.6k30171207
77.6k30171207
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
|
show 6 more comments
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
238
238
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
So you are saying a smoking clown with with a fire axe on his back and a police cap on the head hodling 6 packages with a cliboard lying on top demanding to enter the building to check on his elderly mother because he is worried that there is a gas leak would not work? I guess, I'll have to send everything back then.
– problemofficer
Nov 15 '18 at 15:08
83
83
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
"Lots of studies of people being let in with a just clipboard and a high-visibility vest." - for most large buildings I've worked/lived in, all you'd have to say is "I'm here to work on the AC (or heater)" and they'll roll out the red carpet for you.
– Lord Farquaad
Nov 15 '18 at 16:05
12
12
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
I suspect combinations are a bad idea. You want to avoid making the mark think too closely. Each of the examples seems to be a normal individual and a lazy thinking mark will let them in. I think you are right with the last sentence that combinations can backfire, but I think the threshold for decreasing your chance of success is lower.
– Ross Millikan
Nov 15 '18 at 16:44
60
60
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
This is a good answer. I would also add "social awkwardness," as in people will avoid interacting with you if they think it would be awkward. For example, you could wait for someone to approach the gate then walk in with them while talking continuously on your cell phone-- most people won't want to interrupt.
– John Wu
Nov 15 '18 at 19:36
26
26
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
@John that's definitely something you could combine. A guy with a vest and clipboard (or suit and clipboard, depending on the place), on the phone with a confident nod toward the security guard as he walks in would be pretty solid.
– Cullub
Nov 16 '18 at 4:13
|
show 6 more comments
Just stand outside the door at some distance talking on your phone. Don't look at the door, don't look at the person coming to open it, don't look like you want to get in. Don't ask to be let in. Don't engage in conversation. Just let the person open the door and go through. Then in the last second before it closes and lock, you calmly walk through still talking on your phone.
Wearing a costume or high-vis will make you... well, highly visible. In some places you might need the costume and the excuse to get in. But in a lot of places, just blending in like an unmemorable nobody is quite enough. Dress like you belong, don't ask, just walk.
As a disclaimer I should note that I have no professional experience with this. But I do use it all the time to get into my office when I forget my RFID tag.
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.
– Strikegently
Nov 16 '18 at 16:07
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
add a comment |
Just stand outside the door at some distance talking on your phone. Don't look at the door, don't look at the person coming to open it, don't look like you want to get in. Don't ask to be let in. Don't engage in conversation. Just let the person open the door and go through. Then in the last second before it closes and lock, you calmly walk through still talking on your phone.
Wearing a costume or high-vis will make you... well, highly visible. In some places you might need the costume and the excuse to get in. But in a lot of places, just blending in like an unmemorable nobody is quite enough. Dress like you belong, don't ask, just walk.
As a disclaimer I should note that I have no professional experience with this. But I do use it all the time to get into my office when I forget my RFID tag.
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.
– Strikegently
Nov 16 '18 at 16:07
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
add a comment |
Just stand outside the door at some distance talking on your phone. Don't look at the door, don't look at the person coming to open it, don't look like you want to get in. Don't ask to be let in. Don't engage in conversation. Just let the person open the door and go through. Then in the last second before it closes and lock, you calmly walk through still talking on your phone.
Wearing a costume or high-vis will make you... well, highly visible. In some places you might need the costume and the excuse to get in. But in a lot of places, just blending in like an unmemorable nobody is quite enough. Dress like you belong, don't ask, just walk.
As a disclaimer I should note that I have no professional experience with this. But I do use it all the time to get into my office when I forget my RFID tag.
Just stand outside the door at some distance talking on your phone. Don't look at the door, don't look at the person coming to open it, don't look like you want to get in. Don't ask to be let in. Don't engage in conversation. Just let the person open the door and go through. Then in the last second before it closes and lock, you calmly walk through still talking on your phone.
Wearing a costume or high-vis will make you... well, highly visible. In some places you might need the costume and the excuse to get in. But in a lot of places, just blending in like an unmemorable nobody is quite enough. Dress like you belong, don't ask, just walk.
As a disclaimer I should note that I have no professional experience with this. But I do use it all the time to get into my office when I forget my RFID tag.
edited Nov 19 '18 at 16:03
answered Nov 16 '18 at 9:54
AndersAnders
49.5k22143164
49.5k22143164
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.
– Strikegently
Nov 16 '18 at 16:07
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
add a comment |
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.
– Strikegently
Nov 16 '18 at 16:07
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
33
33
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.– Strikegently
Nov 16 '18 at 16:07
I do use it all the time to get into my office when I forget my RFID tag
- I sure hope your office doesn't handle any sensitive information.– Strikegently
Nov 16 '18 at 16:07
8
8
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
Ethics aside, this is a good practical solution. Being on the phone and looking like you belong is the key.
– Lightness Races in Orbit
Nov 19 '18 at 13:52
add a comment |
The main element, as you've said, is to not look like you're waiting for your mark to arrive. What you need is a prop that gives a visual indication why you're standing outside the door.
Useful props (that would explain your presence) would include:
- Cigarette or e-Cig.
- Lunch-bag(s).
- Coffee(s) from a local distributor.
- Box of doughnuts.
Having a bulky item or two of something (one in each hand) is especially useful because it would explain why you can't reach for a pass.
Story-time. I was working for a company that had access passes. A local hoodlum bought himself a cheap suit and tried to tailgate into the side-entrance. He was stopped by a member of staff as per the company policy. The hoodlum brazened it out by asking him "was it because he was black?" and the member of staff immediately apologised. The hoodlum demanded his manager's name (so he could make a complaint) and received even more profuse apologies.
The 'mark' then helped him to take laptops out of the conference suite and load them into the back of an unmarked van.
Moral of the story? Social engineering simply requires confidence
add a comment |
The main element, as you've said, is to not look like you're waiting for your mark to arrive. What you need is a prop that gives a visual indication why you're standing outside the door.
Useful props (that would explain your presence) would include:
- Cigarette or e-Cig.
- Lunch-bag(s).
- Coffee(s) from a local distributor.
- Box of doughnuts.
Having a bulky item or two of something (one in each hand) is especially useful because it would explain why you can't reach for a pass.
Story-time. I was working for a company that had access passes. A local hoodlum bought himself a cheap suit and tried to tailgate into the side-entrance. He was stopped by a member of staff as per the company policy. The hoodlum brazened it out by asking him "was it because he was black?" and the member of staff immediately apologised. The hoodlum demanded his manager's name (so he could make a complaint) and received even more profuse apologies.
The 'mark' then helped him to take laptops out of the conference suite and load them into the back of an unmarked van.
Moral of the story? Social engineering simply requires confidence
add a comment |
The main element, as you've said, is to not look like you're waiting for your mark to arrive. What you need is a prop that gives a visual indication why you're standing outside the door.
Useful props (that would explain your presence) would include:
- Cigarette or e-Cig.
- Lunch-bag(s).
- Coffee(s) from a local distributor.
- Box of doughnuts.
Having a bulky item or two of something (one in each hand) is especially useful because it would explain why you can't reach for a pass.
Story-time. I was working for a company that had access passes. A local hoodlum bought himself a cheap suit and tried to tailgate into the side-entrance. He was stopped by a member of staff as per the company policy. The hoodlum brazened it out by asking him "was it because he was black?" and the member of staff immediately apologised. The hoodlum demanded his manager's name (so he could make a complaint) and received even more profuse apologies.
The 'mark' then helped him to take laptops out of the conference suite and load them into the back of an unmarked van.
Moral of the story? Social engineering simply requires confidence
The main element, as you've said, is to not look like you're waiting for your mark to arrive. What you need is a prop that gives a visual indication why you're standing outside the door.
Useful props (that would explain your presence) would include:
- Cigarette or e-Cig.
- Lunch-bag(s).
- Coffee(s) from a local distributor.
- Box of doughnuts.
Having a bulky item or two of something (one in each hand) is especially useful because it would explain why you can't reach for a pass.
Story-time. I was working for a company that had access passes. A local hoodlum bought himself a cheap suit and tried to tailgate into the side-entrance. He was stopped by a member of staff as per the company policy. The hoodlum brazened it out by asking him "was it because he was black?" and the member of staff immediately apologised. The hoodlum demanded his manager's name (so he could make a complaint) and received even more profuse apologies.
The 'mark' then helped him to take laptops out of the conference suite and load them into the back of an unmarked van.
Moral of the story? Social engineering simply requires confidence
edited Nov 16 '18 at 21:24
answered Nov 16 '18 at 18:57
RichardRichard
89059
89059
add a comment |
add a comment |
Buy one of these:
Look rushed, and knock on the window/door until someone lets you in. Once inside ask for a random name, and have a screenshot of the doordash app on your phone. (Preferably with the name showing)
If you're feeling ambitious:
Become a legitimate employee of doordash (it's not difficult), and then order food to that building from yourself with instructions to go and find someone specific at the company you are targeting.
Have the "customer" leave specific instructions as to where in the building they are. "I'm in the far east corner, in the meeting room. Just show this to the receptionist and tell her that [the CEO] said to let you in". If you encounter further locked doors show the note to the receptionist and ask if they can help you out: "Could you help me find that room?" "My phone is out of data, do you have wifi I could log into?" etc. etc.
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
add a comment |
Buy one of these:
Look rushed, and knock on the window/door until someone lets you in. Once inside ask for a random name, and have a screenshot of the doordash app on your phone. (Preferably with the name showing)
If you're feeling ambitious:
Become a legitimate employee of doordash (it's not difficult), and then order food to that building from yourself with instructions to go and find someone specific at the company you are targeting.
Have the "customer" leave specific instructions as to where in the building they are. "I'm in the far east corner, in the meeting room. Just show this to the receptionist and tell her that [the CEO] said to let you in". If you encounter further locked doors show the note to the receptionist and ask if they can help you out: "Could you help me find that room?" "My phone is out of data, do you have wifi I could log into?" etc. etc.
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
add a comment |
Buy one of these:
Look rushed, and knock on the window/door until someone lets you in. Once inside ask for a random name, and have a screenshot of the doordash app on your phone. (Preferably with the name showing)
If you're feeling ambitious:
Become a legitimate employee of doordash (it's not difficult), and then order food to that building from yourself with instructions to go and find someone specific at the company you are targeting.
Have the "customer" leave specific instructions as to where in the building they are. "I'm in the far east corner, in the meeting room. Just show this to the receptionist and tell her that [the CEO] said to let you in". If you encounter further locked doors show the note to the receptionist and ask if they can help you out: "Could you help me find that room?" "My phone is out of data, do you have wifi I could log into?" etc. etc.
Buy one of these:
Look rushed, and knock on the window/door until someone lets you in. Once inside ask for a random name, and have a screenshot of the doordash app on your phone. (Preferably with the name showing)
If you're feeling ambitious:
Become a legitimate employee of doordash (it's not difficult), and then order food to that building from yourself with instructions to go and find someone specific at the company you are targeting.
Have the "customer" leave specific instructions as to where in the building they are. "I'm in the far east corner, in the meeting room. Just show this to the receptionist and tell her that [the CEO] said to let you in". If you encounter further locked doors show the note to the receptionist and ask if they can help you out: "Could you help me find that room?" "My phone is out of data, do you have wifi I could log into?" etc. etc.
edited Nov 19 '18 at 3:56
answered Nov 18 '18 at 0:39
01120112
24315
24315
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
add a comment |
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
4
4
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
I can see this working, but if you "become a legitimate employee of doordash" wouldn't that make you more traceable after whatever nefarious activity you've gained access for has been discovered?
– James Bradbury
Nov 19 '18 at 9:20
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
@JamesBradbury You don't become an employee, you just get enough stuff to look convincing enough, like a uniform or bag. You can't be traced if you aren't with the company. It's all about keeping up appearances.
– shadowmanwkp
Nov 19 '18 at 11:15
2
2
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
@JamesBradbury that is certainly a risk if you do not wish to be traced. For a hired pentest however, this approach may make more sense.
– 0112
Nov 19 '18 at 14:07
6
6
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@0112 I feel that "becoming a legit employee of doordash" is a very clever idea, but it may expose the pentester to legal liability (nytimes.com/1997/02/17/opinion/…). I suspect "doordash" or similar companies would quickly tire of being associated with security breaches.
– emory
Nov 19 '18 at 15:12
@emory All good points.
– 0112
Nov 19 '18 at 16:42
@emory All good points.
– 0112
Nov 19 '18 at 16:42
add a comment |
People are helpful by nature. Approaching a door with your hands full, for example with a huge gift wrapped box, will encourage people to open the door for you, no questions asked.
add a comment |
People are helpful by nature. Approaching a door with your hands full, for example with a huge gift wrapped box, will encourage people to open the door for you, no questions asked.
add a comment |
People are helpful by nature. Approaching a door with your hands full, for example with a huge gift wrapped box, will encourage people to open the door for you, no questions asked.
People are helpful by nature. Approaching a door with your hands full, for example with a huge gift wrapped box, will encourage people to open the door for you, no questions asked.
answered Nov 17 '18 at 20:48
Teun VinkTeun Vink
5,62922130
5,62922130
add a comment |
add a comment |
Residential building? "pretend" to be a tradesman - you don't even need a costume or fake ID in many cases.
I know of a number of residential buildings in my area where on a weekday before 12:00, pressing the TRADE button on the access panel just opens the door.
Instant access and no subterfuge. Of course it depends on the building, but if it has an access option like this...
add a comment |
Residential building? "pretend" to be a tradesman - you don't even need a costume or fake ID in many cases.
I know of a number of residential buildings in my area where on a weekday before 12:00, pressing the TRADE button on the access panel just opens the door.
Instant access and no subterfuge. Of course it depends on the building, but if it has an access option like this...
add a comment |
Residential building? "pretend" to be a tradesman - you don't even need a costume or fake ID in many cases.
I know of a number of residential buildings in my area where on a weekday before 12:00, pressing the TRADE button on the access panel just opens the door.
Instant access and no subterfuge. Of course it depends on the building, but if it has an access option like this...
Residential building? "pretend" to be a tradesman - you don't even need a costume or fake ID in many cases.
I know of a number of residential buildings in my area where on a weekday before 12:00, pressing the TRADE button on the access panel just opens the door.
Instant access and no subterfuge. Of course it depends on the building, but if it has an access option like this...
answered Nov 19 '18 at 11:21
BaldrickkBaldrickk
1013
1013
add a comment |
add a comment |
Thanks for contributing an answer to Information Security Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f197732%2froles-to-play-when-tailgaiting-into-a-residential-building%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
44
Wait for people to come out for a smoke, smoke with them while talking to them. When they go back in, you join them.
– Jeroen - IT Nerdbox
Nov 15 '18 at 13:15
17
"but how could have they known" - Not sure where you're located but if you can buy an air rifle and carry it around without much bother then that likely means you're in a place where the locals know what air rifles look like and you happened to run into one.
– Freiheit
Nov 15 '18 at 20:27
70
If someone carrying a rifle tried to follow you into a building, would you challenge them?
– Jeffrey Bosboom
Nov 15 '18 at 21:29
15
What has become of pushing every button on the doorbell panel? Someone always opens...
– Damon
Nov 17 '18 at 18:39
7
@JustinLardinois in North America and the UK, at least, the buttons connect to each unit, and management is not involved in any way.
– schroeder♦
Nov 19 '18 at 16:26