"I noticed this was left open". How do pentests of companies work?
We decided to translate for you a transcript from the Darknet Diaries podcast — the story of a person companies hire to see whether they have security holes. His main task is to find a loophole and use it to get into a company's building or infrastructure.
But first, a lyrical introduction about Michael Fagan and his amazing story of "breaking into" Buckingham Palace. It happened in 1982 in London. Michael first got into the palace through a drainpipe via an open window. The man walked around the palace for almost an hour, looking at the paintings on the walls. And what about security? None of them noticed the uninvited guest. Michael even went into the office of Charles's personal secretary and drank about half of a bottle of wine found there.
The story seems incredible: the man easily got into the royal palace, sipped royal wine, and left the building as if nothing had happened, without even being caught by the guards. But Michael's story didn't end there. Some time later, he was walking early in the morning through the streets of London, and the desire to get into the palace arose in his head again. Michael greeted the cleaners who were hurrying to work and entered the palace together with them. The man managed to find the queen's room. Michael decided to make sure he was really in the royal chambers, so he pulled back the curtain to get a better look at the queen. Suddenly the queen woke up and asked what the man was doing in her chambers, after which she threw the uninvited guest out.
Just imagine, the man made his way into Buckingham Palace twice, the second time getting into the queen's bedroom while she was asleep, and he was only charged with stealing half a bottle of wine. The jury found him not guilty of the offense, and he was not sentenced to imprisonment.
The story of another pentester
The introductory part is over. Let's move on to another pentester. The hero of this story is Jeremy Rowe, a solutions architect for Synack. Companies hire him to see whether they have security holes and whether he can find them. Even as a child, Jeremy loved creating small websites — that's how his technical career began. After the army, Jeremy got a job at Geek Squad, where he fixed problems in clients' computers. Then he decided to find another job, started studying technology, eventually got into cybersecurity, and earned the OSCP certification. After that, he was hired by an organization that worked for the government. Jeremy's tasks included network-level penetration testing and web application penetration testing; he also tried to find vulnerabilities in buildings.
Since the organization interacted with the government, attackers could target it to gain access to government networks. Jeremy knew this, and so he wanted to check one of the contractor's remote offices and try to find loopholes that attackers could exploit. But the company's management was against it, and Jeremy had to convince them of the importance of testing. The argument was that pentesters think through scenarios by which attackers could potentially attack. That's how Jeremy Rowe got the green light from management for the pentest. "The best defense is a good offense", the hero of the story believed.
The organization allowed an attempt to physically and network-wise penetrate the remote office, but with some conditions. Jeremy was forbidden to install backdoors or malicious programs on physical devices. They did not want him to install "hacking tools" on a network that was actively in use.
Jeremy and his team started coming up with a plan for how to test the office. As a result of the testing, they wanted to get answers to the questions:
- What scenarios could hackers use to attack the organization?
- Is it possible to gain access to devices and the corporate network?
- Is it possible to obtain information that potentially endangers government networks?
Jeremy wanted to run the pentest as if he were an attacker targeting government networks. Although he worked at this company, he had never been to the tested office before and was not going to use internal resources to obtain information.
Plan A and Plan B
So Jeremy started by googling the office's location. This way he got information about what surrounds the building, whether there are coffee shops attached to it, how many entrances there are, and so on. Then he drove there by car to observe the surroundings and study the area in detail.
On the Darknet Diaries podcast, Jeremy Rowe said he had two plans for how events could unfold. Plan A was to walk around the perimeter of the building and check which doors were open. This was a decent plan, because the main entrance is often where all the security is located, and by slipping through the side or back doors, you can avoid meeting them. Plan B was to get into the office through the main entrance. Jeremy and his team didn't know what was inside the office building; they only assumed there might be a lobby on the first floor.
Time to move out
Jeremy worked with a partner (BC). The day before the pentest, they got haircuts and dressed to blend in with the office employees. Jeremy and BC brought laptops, a set of lockpicks, a Bash Bunny, and so on. Jeremy also installed a mobile version of Kali Linux on his phone.
On the day, Jeremy and BC parked the car in the office parking lot, the entrance to which turned out to be free. They decided to walk around the building's perimeter and check the doors. It turned out that one door was ajar due to a technical malfunction. This is how Jeremy and BC ended up in the stairwell. The pentesters decided not to check the first floor, since their contractor's offices were located on the second and third floors. The doors on the second floor, to their surprise, turned out to be open; they got into the organization's office, took photos there, and went back to the stairs. On the third floor, the doors were also unlocked.
After the success of Plan A, the heroes of the story decided to check whether it was possible to freely get into the building through the main entrance. Jeremy assumed there should be an obstacle in their way that would prevent free entry into the office. They entered the building through the main entrance and walked freely to the stairs and elevators that led to the upper floors.
On the floors with the contractor's offices, there were lounge areas with couches — that's where Jeremy and his partner decided to settle in. It turned out that getting into the organization's offices was only possible with a key card, which the employees had. The pentesters turned on their laptops, started thinking about what to do next, and at the same time watched the surroundings. In the lounge with the couches, Jeremy noticed a small computer (an information kiosk); he found it interesting that the computer was left unattended.
It turned out that the computer was running software that only allowed employees to enter a single application. On the back panel of the info kiosk there was a USB port, through which Jeremy connected a Bash Bunny. On the Darknet Diaries podcast, Jeremy Rowe explained that a Bash Bunny looks like a regular flash drive, but when it's connected to a computer, the computer perceives the Bash Bunny as a keyboard. If you write a script of actions into the Bash Bunny in advance, the PC will think a keyboard has been connected and will start accepting keystrokes. Jeremy had pre-written a script that made the computer open Word and start typing on the screen. This was enough for the pentester to take a photo and prove to management that he was in control of this computer.
After that, Jeremy and BC decided to walk through the office once more and check whether all the doors were really locked and accessible only by key card. But for some reason, on this particular day, some of the doors turned out to be open.
Together, Jeremy and BC got into the office through the main entrance, went up the stairs, pulled the handle, and simply walked into the office, where there was a lot of corporate information around. There they noticed network ports, printers, projects the employees were working on; they also saw what was written on the whiteboards, saw labels, and various IP addresses.
Jeremy and his partner moved freely around the office, without badges or passes. They walked past a large number of employees and greeted them. At one point, the pentesters even went up to the employee break room and had some coffee.
While the pentesters were walking around the office, they noticed an open meeting room with several Ethernet ports on the walls. Jeremy and BC happened to have cables with them for connecting. Jeremy saw there was Wi-Fi here, and although he didn't know the password, he didn't need it, because they connected via the Ethernet port. In the podcast, Jeremy explained that Ethernet ports can be configured in different ways. They may grant internal access, or they may not grant any access at all. It's not a given that just because you are physically in the office, you'll be able to connect to and use the network. In a properly configured office, you shouldn't be able to just walk up and connect to any Ethernet port. But they connected their computers to the Ethernet ports and saw that the ports were live.
Jeremy decided to look at what was on this network, but there were no other computers on it. All he could do was get access to the Internet. Jeremy concluded that this company used NAC, so when he connected a computer to the port, the router checked its MAC address and determined that this computer should not have extended access. Jeremy decided to try to get extended access instead of guest access. He wanted to find a MAC address that was on the allowed list and change his computer's MAC address to one of those. He noticed several printers in the office. In the podcast, he explained that the first part of a MAC address belongs to the vendor, so if a company has Cisco equipment, every individual Ethernet port on all Cisco equipment starts with the MAC address 94:36:CC. The second half of the MAC address will differ for each Ethernet port, which makes them unique.
Jeremy looked at what types of printers were in the organization and looked at what that vendor's MAC address started with, and then changed the MAC address on his computer so it matched the one the printer started with. Then he tried reconnecting the Ethernet cable to see if he would get a different IP address. It worked, and Jeremy got extended access inside the network. Another goal was achieved — they had gained access to the network.
After that, the pentesters disconnected from the network and decided to walk through the office once more to look for any vulnerability they might have missed. As they walked around, they noticed that many employees step away from their laptops without locking the session. Jeremy and his partner took several photos of themselves sitting at such laptops. This way they demonstrated to management that the PCs were unlocked and that anything could be done with them.
Then the pentesters headed to the elevator, in which one of the contractor's employees was riding. In the elevator, they greeted him and exchanged a few casual phrases. Jeremy decided to improvise and follow this employee, so he got off with him on the same floor. The employee headed to a door, took out his pass, and held the door for Jeremy. Jeremy thanked the employee and entered the office. Jeremy saw that his partner had stayed in the lobby, so he decided to go around to another door to let him in, but when he turned the corner, his partner was already in the office. It turned out that the other door didn't require a pass. That was another finding for the report.
While the pentesters were on the third floor, they focused on gathering intelligence. They were curious whether there was access to any applications that shouldn't be accessible. As they walked around the office, they photographed whiteboards, documents on desks, files, and file names. They wanted to get as much information as possible about the organization and about who owned these files and how confidential they were for the organization. Jeremy and BC gathered enough information for the report and left the contractor's office through the building's main doors.
So what happened in the end?
Jeremy was able to play out scenarios by which potential attackers could easily gain unimpeded access to the organization. On the podcast, Jeremy said it was hard for management to accept this fact. They were surprised at how easily Jeremy gained control of the info kiosk in the lobby. Management was also shocked that employees, when stepping away from their computers, leave them turned on.
What did management do afterward? Jeremy said they locked the doors and simply removed the computer from the lobby. The organization was impressed by the work of Jeremy and his partner, so they were allowed to conduct additional security testing.


