1
00:00:00,090 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,300
we're going to cover access badge cloning.

3
00:00:03,300 --> 00:00:05,790
Now in our modern electronic access control systems,

4
00:00:05,790 --> 00:00:08,070
we often use radio frequency identification

5
00:00:08,070 --> 00:00:10,860
or near-field communication-based access control badges

6
00:00:10,860 --> 00:00:14,280
to gain access to our offices and other secure spaces.

7
00:00:14,280 --> 00:00:17,160
Radio frequency identification known as RFID

8
00:00:17,160 --> 00:00:19,770
and near-field communication known as NFC

9
00:00:19,770 --> 00:00:20,940
are popular technologies

10
00:00:20,940 --> 00:00:22,950
that are used for contactless authentication

11
00:00:22,950 --> 00:00:24,330
in various applications

12
00:00:24,330 --> 00:00:26,880
including access control systems, payment systems,

13
00:00:26,880 --> 00:00:28,710
and identification systems.

14
00:00:28,710 --> 00:00:30,510
While these systems offer convenience,

15
00:00:30,510 --> 00:00:32,189
they aren't immune to attack.

16
00:00:32,189 --> 00:00:33,570
One of the most prevalent vulnerabilities

17
00:00:33,570 --> 00:00:34,470
you need to be aware of

18
00:00:34,470 --> 00:00:36,990
in terms of RFID and NFC technologies

19
00:00:36,990 --> 00:00:39,494
is the ability to easily conduct access badge cloning

20
00:00:39,494 --> 00:00:42,300
to bypass your authentication systems.

21
00:00:42,300 --> 00:00:45,240
So let's take a look at what access badge cloning is,

22
00:00:45,240 --> 00:00:46,290
how it's conducted,

23
00:00:46,290 --> 00:00:48,720
and the ways to mitigate this type of attack.

24
00:00:48,720 --> 00:00:51,330
First, what is access badge cloning?

25
00:00:51,330 --> 00:00:52,740
Well, access badge cloning

26
00:00:52,740 --> 00:00:54,930
refers to copying the data from an RFID

27
00:00:54,930 --> 00:00:58,770
or NFC card or badge onto another card or device.

28
00:00:58,770 --> 00:01:00,660
The clone card or device then behaves

29
00:01:00,660 --> 00:01:02,580
as if it was the original access badge

30
00:01:02,580 --> 00:01:05,069
which can be used to trick the system integrating access

31
00:01:05,069 --> 00:01:07,590
or completing a transaction for the attacker.

32
00:01:07,590 --> 00:01:09,660
Now at its core access badge cloning

33
00:01:09,660 --> 00:01:11,310
involves making an unauthorized copy

34
00:01:11,310 --> 00:01:13,320
of an authorized person's access badge

35
00:01:13,320 --> 00:01:15,750
so the threat actor can bypass security measures

36
00:01:15,750 --> 00:01:18,180
without ever possessing the original badge.

37
00:01:18,180 --> 00:01:21,420
So how does an attacker clone that access badge?

38
00:01:21,420 --> 00:01:23,280
Well, there's four basic steps:

39
00:01:23,280 --> 00:01:25,110
scanning, data extraction,

40
00:01:25,110 --> 00:01:26,700
writing to a new card or device,

41
00:01:26,700 --> 00:01:28,770
and using a cloned access badge.

42
00:01:28,770 --> 00:01:31,290
The first step in access badge cloning is going to be scanning

43
00:01:31,290 --> 00:01:34,080
or reading the targeted individual's access badge.

44
00:01:34,080 --> 00:01:37,200
An attacker can use a handheld RFID or NFC reader

45
00:01:37,200 --> 00:01:39,030
to capture the data from a victim's card

46
00:01:39,030 --> 00:01:41,040
and store it for further processing.

47
00:01:41,040 --> 00:01:43,260
This type of scanning can be done discreetly

48
00:01:43,260 --> 00:01:46,410
and often occurs without the access badge owner's knowledge.

49
00:01:46,410 --> 00:01:48,990
For example, an attacker might hide an access badge scanner

50
00:01:48,990 --> 00:01:49,920
in their backpack,

51
00:01:49,920 --> 00:01:51,540
and as they walk by an authorized individual

52
00:01:51,540 --> 00:01:53,550
while holding this concealed reader in their bag,

53
00:01:53,550 --> 00:01:56,130
they can then read the RFID or NFC data

54
00:01:56,130 --> 00:01:57,600
without needing physical contact

55
00:01:57,600 --> 00:02:00,120
with the authorized person's access badge.

56
00:02:00,120 --> 00:02:02,040
An attacker still will need to be relatively close

57
00:02:02,040 --> 00:02:03,510
to the access badge to clone it,

58
00:02:03,510 --> 00:02:06,420
such as within one to two inches for an NFC access badge

59
00:02:06,420 --> 00:02:09,389
and two to 10 inches for an RFID access badge.

60
00:02:09,389 --> 00:02:10,860
But with a stronger antenna,

61
00:02:10,860 --> 00:02:12,600
you may be able to double those ranges

62
00:02:12,600 --> 00:02:14,220
but that's still going to make the attacker

63
00:02:14,220 --> 00:02:15,930
have to get pretty close to their victim

64
00:02:15,930 --> 00:02:18,060
in order to clone that badge.

65
00:02:18,060 --> 00:02:20,310
Second, we have data extraction.

66
00:02:20,310 --> 00:02:22,680
Once the data is captured, the attacker extracts

67
00:02:22,680 --> 00:02:24,990
the relevant authentication credentials from the card,

68
00:02:24,990 --> 00:02:27,930
such as a unique identifier or a set of encrypted data.

69
00:02:27,930 --> 00:02:29,610
This process can be done at any time

70
00:02:29,610 --> 00:02:31,740
after the initial scan is conducted.

71
00:02:31,740 --> 00:02:34,530
Third, we have writing to a new card or device.

72
00:02:34,530 --> 00:02:36,180
Using specialized writing tools,

73
00:02:36,180 --> 00:02:38,160
the attacker will then transfer the extracted data

74
00:02:38,160 --> 00:02:40,800
onto a blank RFID or NFC card

75
00:02:40,800 --> 00:02:42,540
or other compatible device.

76
00:02:42,540 --> 00:02:44,970
For example, when I conduct penetration testing,

77
00:02:44,970 --> 00:02:47,153
I like to use the Flipper Zero for my RFID

78
00:02:47,153 --> 00:02:49,110
and NFC cloning activities.

79
00:02:49,110 --> 00:02:51,180
This type of device is really simple to use.

80
00:02:51,180 --> 00:02:53,580
It's compact and it can store a lot of different codes

81
00:02:53,580 --> 00:02:55,740
that you've already scanned during your penetration test

82
00:02:55,740 --> 00:02:58,020
as opposed to having a physically cloned access badge

83
00:02:58,020 --> 00:03:00,990
that only contains one user identity or code.

84
00:03:00,990 --> 00:03:03,720
Fourth, we have using the cloned access badge.

85
00:03:03,720 --> 00:03:05,637
Now that the attacker has cloned that access badge

86
00:03:05,637 --> 00:03:07,020
and they have a duplicate of it

87
00:03:07,020 --> 00:03:09,540
or they have a device that has copied it in their hand,

88
00:03:09,540 --> 00:03:11,880
they can now gain unauthorized access to your building,

89
00:03:11,880 --> 00:03:13,800
computer systems or even make payments

90
00:03:13,800 --> 00:03:16,350
using a cloned NFC enabled credit card.

91
00:03:16,350 --> 00:03:18,900
Now let me show you how this works in the real world.

92
00:03:18,900 --> 00:03:21,390
First, let me show you how this door is designed to work.

93
00:03:21,390 --> 00:03:23,460
Notice here there is a badge reader on the left

94
00:03:23,460 --> 00:03:25,770
and we're using an RFID tag

95
00:03:25,770 --> 00:03:28,620
which we're going to have as a small key chain attachment.

96
00:03:28,620 --> 00:03:29,880
As I touch this to the door,

97
00:03:29,880 --> 00:03:32,880
the door will unlock authorizing us to enter the building.

98
00:03:32,880 --> 00:03:36,180
This is what it should look like for an authorized employee.

99
00:03:36,180 --> 00:03:37,710
Now that we see what it's supposed to look like,

100
00:03:37,710 --> 00:03:40,500
let me show you how we can clone that key tag.

101
00:03:40,500 --> 00:03:42,960
Notice here I've been able to get ahold of that key tag

102
00:03:42,960 --> 00:03:44,610
and I have my Flipper Zero.

103
00:03:44,610 --> 00:03:46,560
So first I'm going to take my Flipper Zero.

104
00:03:46,560 --> 00:03:49,560
I'm going to select that I want to use the 125 kilohertz RFID,

105
00:03:49,560 --> 00:03:52,200
which is the type of tag, and I'm going to select Read.

106
00:03:52,200 --> 00:03:55,560
Once I select Read, I'll then hold my Flipper Zero over it

107
00:03:55,560 --> 00:03:58,500
and it will then ask and read the pre shared key from that,

108
00:03:58,500 --> 00:04:00,180
and you can see it here on the screen

109
00:04:00,180 --> 00:04:02,880
which I am blurring out for safety reasons.

110
00:04:02,880 --> 00:04:03,810
Now that I've done that,

111
00:04:03,810 --> 00:04:06,870
I can then save that to my Flipper device, give it a name.

112
00:04:06,870 --> 00:04:08,370
In this case, I'll use the default

113
00:04:08,370 --> 00:04:10,860
and now it's saved inside of this device.

114
00:04:10,860 --> 00:04:13,620
Now if I want to open that door using my Flipper device,

115
00:04:13,620 --> 00:04:15,660
I can simply use the emulate option

116
00:04:15,660 --> 00:04:18,750
or I can write this code back to a blank RFID tag

117
00:04:18,750 --> 00:04:20,970
and then use that to be able to access the door.

118
00:04:20,970 --> 00:04:22,830
Here you can see I'm back at that door,

119
00:04:22,830 --> 00:04:24,360
I'm taking my Flipper Zero,

120
00:04:24,360 --> 00:04:27,180
I'm going to select the 125 Kilohertz RFID,

121
00:04:27,180 --> 00:04:29,520
I'm going to then go into my saved area

122
00:04:29,520 --> 00:04:32,010
which has the clone tag that we've saved before

123
00:04:32,010 --> 00:04:34,050
to this device, and I'll select it.

124
00:04:34,050 --> 00:04:36,090
Once I have that, I can select Emulate

125
00:04:36,090 --> 00:04:38,010
and hold this up to the door, and it'll operate

126
00:04:38,010 --> 00:04:39,594
just as if it was that RFID tag,

127
00:04:39,594 --> 00:04:41,040
and I can enter the building

128
00:04:41,040 --> 00:04:43,050
as if I was that authorized employee.

129
00:04:43,050 --> 00:04:44,130
As you can probably guess,

130
00:04:44,130 --> 00:04:46,560
access badge cloning is a security concern for us

131
00:04:46,560 --> 00:04:48,360
because of the ease of its execution,

132
00:04:48,360 --> 00:04:50,820
its ability to be stealthy when conducting the attack,

133
00:04:50,820 --> 00:04:52,290
and its potential large use

134
00:04:52,290 --> 00:04:54,720
inside of compromising physical security.

135
00:04:54,720 --> 00:04:57,150
Now every day, the tools required for access badge cloning

136
00:04:57,150 --> 00:04:59,130
become more readily available online

137
00:04:59,130 --> 00:05:01,500
and continue to get less expensive over time.

138
00:05:01,500 --> 00:05:03,870
This makes it easy even for unskilled attackers

139
00:05:03,870 --> 00:05:05,850
to attempt access badge cloning.

140
00:05:05,850 --> 00:05:07,560
Access badge cloning is also considered

141
00:05:07,560 --> 00:05:10,320
to be a stealthy way to conduct a physical security attack

142
00:05:10,320 --> 00:05:12,000
since you don't need to maintain possession

143
00:05:12,000 --> 00:05:14,220
of the original access badge or card,

144
00:05:14,220 --> 00:05:15,870
and instead you can simply copy

145
00:05:15,870 --> 00:05:19,080
and reuse the data from the card without raising suspicion.

146
00:05:19,080 --> 00:05:20,850
Also, it's important to think about the fact

147
00:05:20,850 --> 00:05:22,200
that cloned access badges

148
00:05:22,200 --> 00:05:24,150
can be used to compromise physical security

149
00:05:24,150 --> 00:05:26,610
that has large widespread implications.

150
00:05:26,610 --> 00:05:28,230
Using these cloned access badges,

151
00:05:28,230 --> 00:05:30,270
the attacker can gain access to your building,

152
00:05:30,270 --> 00:05:31,474
defeat your physical security controls

153
00:05:31,474 --> 00:05:32,640
that you're trying to protect

154
00:05:32,640 --> 00:05:34,350
your organization's security data,

155
00:05:34,350 --> 00:05:36,480
and it can be used to conduct financial crimes

156
00:05:36,480 --> 00:05:38,100
like credit card or payment fraud

157
00:05:38,100 --> 00:05:40,800
when used against NFC-based payment systems.

158
00:05:40,800 --> 00:05:44,040
So how can you stop access badge cloning?

159
00:05:44,040 --> 00:05:46,470
Well, first, you should implement advanced encryption

160
00:05:46,470 --> 00:05:48,720
in your card-based authentication systems.

161
00:05:48,720 --> 00:05:51,765
Many basic RFID or NFC systems use simple identifiers

162
00:05:51,765 --> 00:05:54,300
without any form of robust encryption.

163
00:05:54,300 --> 00:05:56,700
By ensuring data on your organization's access badges

164
00:05:56,700 --> 00:05:58,680
is encrypted using advanced algorithms,

165
00:05:58,680 --> 00:06:00,660
it becomes much more difficult for an attacker

166
00:06:00,660 --> 00:06:03,300
to clone your organization's access badges.

167
00:06:03,300 --> 00:06:05,648
Second, you should implement multifactor authentication

168
00:06:05,648 --> 00:06:07,650
known as MFA.

169
00:06:07,650 --> 00:06:09,210
Instead of solely relying on an RFID

170
00:06:09,210 --> 00:06:11,460
or NFC badge for access,

171
00:06:11,460 --> 00:06:13,950
you should combine them with a second form of authentication

172
00:06:13,950 --> 00:06:17,670
like a pin, a password, or some kind of biometric input.

173
00:06:17,670 --> 00:06:19,770
This way, even if the badge is cloned,

174
00:06:19,770 --> 00:06:21,210
the attacker still cannot use it

175
00:06:21,210 --> 00:06:23,580
because they need that secondary form of authentication

176
00:06:23,580 --> 00:06:26,070
to gain access to your secure facilities.

177
00:06:26,070 --> 00:06:27,930
For example, many of the organizations

178
00:06:27,930 --> 00:06:28,950
I work for over the years

179
00:06:28,950 --> 00:06:30,930
have implemented RFID access badges

180
00:06:30,930 --> 00:06:32,820
as the first authentication factor

181
00:06:32,820 --> 00:06:34,290
and an eight-digit security pin

182
00:06:34,290 --> 00:06:36,390
as the second authentication factor.

183
00:06:36,390 --> 00:06:39,060
This way, even if the attacker has my access badge,

184
00:06:39,060 --> 00:06:41,010
they still can't get into the building as me

185
00:06:41,010 --> 00:06:43,410
because they don't know my secret eight-digit pin

186
00:06:43,410 --> 00:06:45,690
and they can't enter it after scanning my access badge

187
00:06:45,690 --> 00:06:48,240
or their clone version of my access badge.

188
00:06:48,240 --> 00:06:50,995
Third, you should regularly update your security protocols.

189
00:06:50,995 --> 00:06:53,280
By periodically updating the encryption keys

190
00:06:53,280 --> 00:06:55,410
and authentication mechanisms being used,

191
00:06:55,410 --> 00:06:57,660
your organization can prevent cloned access badges

192
00:06:57,660 --> 00:07:00,360
from being usable for extended periods of time.

193
00:07:00,360 --> 00:07:02,640
Fourth, you should educate your users.

194
00:07:02,640 --> 00:07:04,860
It is important to inform your users about the risk

195
00:07:04,860 --> 00:07:07,320
of badge cloning and to encourage them to be cautious

196
00:07:07,320 --> 00:07:09,150
and report any suspicious activities

197
00:07:09,150 --> 00:07:10,650
or unauthorized access attempts

198
00:07:10,650 --> 00:07:12,780
that are being levied against their badge.

199
00:07:12,780 --> 00:07:14,580
Your users should also be aware

200
00:07:14,580 --> 00:07:15,960
of where they store their cards

201
00:07:15,960 --> 00:07:17,910
to ensure the attacker doesn't get access to them

202
00:07:17,910 --> 00:07:19,980
to be able to clone them in the first place.

203
00:07:19,980 --> 00:07:21,750
Fifth, your users should implement

204
00:07:21,750 --> 00:07:23,610
the use of shielded wallets or sleeves

205
00:07:23,610 --> 00:07:25,980
with your RFID access badges.

206
00:07:25,980 --> 00:07:29,130
RFID shielding wallets or sleeves can prevent scanners

207
00:07:29,130 --> 00:07:30,390
from being able to read the card

208
00:07:30,390 --> 00:07:31,770
while it's inside one of those,

209
00:07:31,770 --> 00:07:34,410
and this offers us extra layers of protection.

210
00:07:34,410 --> 00:07:35,490
Sixth and finally,

211
00:07:35,490 --> 00:07:37,800
you should monitor and audit your access logs.

212
00:07:37,800 --> 00:07:39,690
By regularly reviewing access logs,

213
00:07:39,690 --> 00:07:41,370
your organization can help identify

214
00:07:41,370 --> 00:07:44,160
any unauthorized or suspicious access attempts.

215
00:07:44,160 --> 00:07:46,110
If a cloned access badge is going to be used,

216
00:07:46,110 --> 00:07:48,750
you may be able to identify patterns or anomalies

217
00:07:48,750 --> 00:07:50,850
that indicate the access badge is a cloned badge

218
00:07:50,850 --> 00:07:52,650
and not actually the original.

219
00:07:52,650 --> 00:07:54,900
For example, if you clone my access badge

220
00:07:54,900 --> 00:07:56,220
and then try to enter our offices

221
00:07:56,220 --> 00:07:57,420
while I'm supposed to be at a conference

222
00:07:57,420 --> 00:07:58,860
on the other side of the country,

223
00:07:58,860 --> 00:08:00,210
that should trigger an alert

224
00:08:00,210 --> 00:08:01,530
because the cloned access badge

225
00:08:01,530 --> 00:08:02,910
would appear to be a legitimate,

226
00:08:02,910 --> 00:08:04,980
simply because I wasn't even in the same state

227
00:08:04,980 --> 00:08:06,840
as the building you're trying to gain access to

228
00:08:06,840 --> 00:08:08,880
using my cloned access badge.

229
00:08:08,880 --> 00:08:10,890
So remember, access badge cloning

230
00:08:10,890 --> 00:08:13,320
refers to the copying of data from an RFID

231
00:08:13,320 --> 00:08:16,800
or NFC card or badge onto another card or device.

232
00:08:16,800 --> 00:08:18,360
This is one of the biggest vulnerabilities

233
00:08:18,360 --> 00:08:21,270
involved with using RFID and NFC technologies

234
00:08:21,270 --> 00:08:23,520
when you're dealing with access control systems.

235
00:08:23,520 --> 00:08:25,170
To prevent access badge cloning,

236
00:08:25,170 --> 00:08:26,850
you really need to understand the threat

237
00:08:26,850 --> 00:08:28,320
and implement the appropriate measures,

238
00:08:28,320 --> 00:08:30,390
like user education and awareness training,

239
00:08:30,390 --> 00:08:32,159
using shielded wallets or sleeves,

240
00:08:32,159 --> 00:08:34,200
and monitoring and auditing your access logs

241
00:08:34,200 --> 00:08:37,140
to detect improper or impossible access badge usage

242
00:08:37,140 --> 00:08:38,493
within your organization.

