Breaking Into Buildings Is Way Too Easy (A Hacker's Physical Pentest Toolkit)

Поділитися
Вставка
  • Опубліковано 16 вер 2024
  • ❓Info❓
    ___________________________________________
    Hire me: tcm-sec.com
    Get Trained: academy.tcm-se...
    Get Certified: certifications...
    Sponsorship Inquiries: info@thecybermentor.com
    Products featured in this video
    ___________________________________________
    Night School - Tuxedo Edition Lockpick Set - www.sparrowslo...
    Bump Key Set - www.sparrowslo...
    DDT - www.sparrowslo...
    Under Door Tool - www.sparrowslo...
    Door Shims - www.sparrowslo...
    Travelers Hooks - www.sparrowslo...
    Flex Pass - www.sparrowslo...
    Body Camera - amzn.to/3evg4q9
    Under the Door Camera - amzn.to/3EsUEog
    Compressed Air - amzn.to/33SOqBk
    5-in-1 Tool - amzn.to/3z8FrI2
    Leatherman Multitool - amzn.to/32Fy52z
    Common Key Set - www.ebay.com/i...
    Boscloner - www.boscloner....
    TrustedSec Physical Docs: github.com/tru...
    📱Social Media📱
    ___________________________________________
    Twitter: / thecybermentor
    Twitch: / thecybermentor
    Instagram: / thecybermentor
    LinkedIn: / heathadams
    Discord: / discord
    💸Donate💸
    ___________________________________________
    Like the channel? Please consider supporting me on Patreon:
    / thecybermentor
    Support the stream (one-time): streamlabs.com...
    Hacker Books:
    Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
    The Hacker Playbook 3: amzn.to/34XkIY2
    Hacking: The Art of Exploitation: amzn.to/2VchDyL
    The Web Application Hacker's Handbook: amzn.to/30Fj21S
    Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
    Social Engineering: The Science of Human Hacking: amzn.to/31HAmVx
    Linux Basics for Hackers: amzn.to/34WvcXP
    Python Crash Course, 2nd Edition: amzn.to/30gINu0
    Violent Python: amzn.to/2QoGoJn
    Black Hat Python: amzn.to/2V9GpQk
    My Build:
    lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
    darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
    EVGA 2080TI: amzn.to/30d2lj7
    MSI Z390 MotherBoard: amzn.to/30eu5TL
    Intel 9700K: amzn.to/2M7hM2p
    G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
    Razer Nommo Chroma Speakers: amzn.to/30bWjiK
    Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
    CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
    Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
    My Recording Equipment:
    Panasonic G85 4K Camera: amzn.to/2Mk9vsf
    Logitech C922x Pro Webcam: amzn.to/2LIRxAp
    Aston Origin Microphone: amzn.to/2LFtNNE
    Rode VideoMicro: amzn.to/309yLKH
    Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
    Elgato Cam Link 4K: amzn.to/2QlicYx
    Elgate Stream Deck: amzn.to/2OlchA5
    *We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.

КОМЕНТАРІ • 57

  • @robertfling6173
    @robertfling6173 2 роки тому +17

    Another tool to add to your tool box would be about a 18" piece of simple weed eater string. Super easy to conceal. It becomes your go to tool when you have a door where the striker is covered by something as a metal plate. Normally a shove tool or the painters tool you showed would work if the plate was not there however the plate now makes those tools useless. Simply thread the weed eater string down behind the plate, rock it back and forth while pulling gently and you will defeat the lock and open the door.

  • @trikto9120
    @trikto9120 2 роки тому +71

    What if someone recognizes you during a physical pentest, like "Oh you are the cybermentor, I am a huge fan of yours, you are pentesting here?" 😅

    • @simmsimmons3690
      @simmsimmons3690 2 роки тому +1

      rt lol

    • @3nertia
      @3nertia Рік тому +2

      "I'm sorry, have we met?"

    • @showxating9885
      @showxating9885 7 місяців тому

      Just wait a few years. A gray hair or bearded white man is invisible. Put safety orange on him, truly invisible. No one looks service people in the eye.

  • @activeturtle770
    @activeturtle770 2 роки тому +9

    Obligatory comment for making UA-cam promote this legend!

  • @QuantumRealmM
    @QuantumRealmM 2 роки тому +11

    This is like my dream career, breaking into buildings legally. I am in love

  • @andyli
    @andyli 2 роки тому +15

    Nice video TCM. I recently did my first physical pentest, it was a fun one 😁

    • @CyberZyro
      @CyberZyro 2 роки тому +4

      would love to hear the experience via a video on your channel :)

    • @tammyd7595
      @tammyd7595 2 роки тому +1

      Same

  • @Intuitronix
    @Intuitronix Рік тому +1

    Great video! I did about 7 physical pentests this year and some of these tools would have been super handy. It’s always tough to know what your gonna run into. Social engineering and being confident about who I was pretending to be helped in being successful on most of them.

  • @airbourne3625
    @airbourne3625 2 роки тому +2

    Appreciate all that you do for the community, you’re a rockstar

  • @TheKATON132
    @TheKATON132 2 роки тому +1

    yea... rfid badges, silent alarms. I doubt they did pen testing in the 80's and early 90's but If they did it would have been a walk in the park.

  • @MarkAnthonyHenderson
    @MarkAnthonyHenderson 2 роки тому +1

    It's worth noting that a roll of 35mm film can be used as an "over-the-door (top)" tool if you do not have an "under the door" tool. Naturally, it depends on the door. Also, it's probably a good idea to ensure you check the latch assembly to ensure that you can exit without the door locking one way (think roof access).

    • @markotb
      @markotb Рік тому +2

      I think this method is old. I have tested many doors in office buildings in my city and NONE of the handles will open in an upward action, UDT is viable but film isnt.

  • @vinnu333
    @vinnu333 2 роки тому +4

    Yeah.. that was seriously 🔥🔥🔥🔥

  • @JoeC_aka_PwnerJoe
    @JoeC_aka_PwnerJoe 2 роки тому +5

    Thank you, Heath! I always appreciate your realistic and practical videos. I agree when you say that most other youtubers end up trying to sell us Hack5 gear, and most aren't going to be used. Your videos are truly a breath of fresh air.

  • @Rob_Huskett
    @Rob_Huskett 2 роки тому +9

    Hi Heath. Great video and very useful. I just completed your course on ethical hacking on Udemy. Just wanted to say a huge thank you! I have learned a ton already based on your course and this helps as well. I begin my security journey professionally in February 😁

  • @dropcake
    @dropcake 2 роки тому +3

    Awesome video TCM. I want to get a lock pick practice set so I can start learning how to lockpick.

  • @AlexTushinsky
    @AlexTushinsky 2 роки тому

    I used the air can trick on a door in my office. Very easy and very effective!

  • @jagernet
    @jagernet 2 роки тому +2

    Have you ever considered using a device like a pwn phone on a pentest? In my experience its almost undetectable which is useful in the field and while it will never take over the role of a laptop for exfiltration and post-exploitation purposes it does in my eyes fit the best for infiltration. Plus you feel straight outta Watch Dogs!

  • @InfiniteLogins
    @InfiniteLogins 2 роки тому +1

    This is super cool to see. I am curious what Hak5 gear you'd use as well

  • @user-et1hg6kh6n
    @user-et1hg6kh6n Рік тому +1

    The crossover from pen testing to physical pen testing will never cease to seem odd to me. I feel like certain LE/MIL backgrounds lend themselves better to the pursuit of physical pen testing personally but I dont think that shout deter people from looking to get into it as a line of work. I will say it seems theres alot of unnecessary gatekeeping in physical pen testing as well, often hiding behind alot of mostly useless pay to play certifications for what could otherwise be a trade.

  • @daryldixon5560
    @daryldixon5560 2 роки тому

    Hey TCM, been following you since very long when i fell into the ocean of info sec. Just wanted to request you to please make a video on the OSCP 2022 CHANGES !!!

  • @victorslinv2920
    @victorslinv2920 2 роки тому

    Great video. Just surprised you didn’t mention a Proxmark3 or something similar for badge access and sort lol

  • @hawk__
    @hawk__ 2 роки тому +1

    Now, Mr Robot is looking more realistic :P

  • @spexy4799
    @spexy4799 2 роки тому +1

    I wish I can get a raspberry pi nowadays for $30-40 😂

  • @prodbydramatic
    @prodbydramatic 2 роки тому

    how do I get into the field? where does a more than average person start and I'm serious about it. thanks for your time been watching for a while now. happy new year

  • @timmehwimmy
    @timmehwimmy 2 роки тому

    Cool video. Not sure I agree about the plastic lovk though. :-)

  • @moonlightsoldier8443
    @moonlightsoldier8443 29 днів тому

    With bump leys you dont really need a hamer just line up ram while twisting bango

  • @noobsaibot203
    @noobsaibot203 2 роки тому

    I see you Heath growing that beard to be unnoticeable during that physical engagement ;)

  • @foxtailedcritter
    @foxtailedcritter 2 роки тому

    I have a bar that goes underneath the doors of emergency exits and pushes the handles. Literally gives me access to 99 percent of buildings in Australia.

  • @dustinhxc
    @dustinhxc Рік тому

    So awesome!

  • @michaelgrimes5588
    @michaelgrimes5588 Рік тому

    My lockpick set is similar, but looks much more like a sawzall

  • @linuxdriver
    @linuxdriver 2 роки тому

    Great video

  • @dauntingdonut74
    @dauntingdonut74 2 роки тому

    Great video with a lot of interesting tools.

  • @likjou
    @likjou 2 роки тому

    I like your new look.

  • @powerd0wn
    @powerd0wn 2 роки тому

    Hey man, when you can please make another video on how to use lan turtle, rubber duck etc

  • @JasonEyerly
    @JasonEyerly 2 роки тому

    Looked at the badge cloner, saw $3,000 whelp...next lmfao. DIY I guess it is though I'm sure it'll pay for itself in one good gig.

  • @yankeesouth
    @yankeesouth 2 роки тому +2

    You didn’t even wear a Guy Fawkes mask so, was it even real?

  • @Bambamni
    @Bambamni 2 роки тому

    Love this 🤣

  • @justsunny1899
    @justsunny1899 2 роки тому

    Hey TCM , i want persue masters in cyber security in US , can you suggest any uni for me

  • @SuperChannel777
    @SuperChannel777 2 роки тому

    👍🏽

  • @nallachi2913
    @nallachi2913 2 роки тому

    TCM❤️❤️❤️

  • @HackerSumitJi
    @HackerSumitJi 2 роки тому

    How much you take for one advertisement on your channel, i want to do a advertisement on your channel

  • @muhammadfarooq4386
    @muhammadfarooq4386 2 роки тому

    This voice ❤❤

  • @hackrowd
    @hackrowd 2 роки тому

    🔥🔥🔥🔥

  • @francisdonald4298
    @francisdonald4298 2 роки тому

    TCM

  • @bughousetv7363
    @bughousetv7363 2 роки тому

    Commented

  • @deutschmitvkEins
    @deutschmitvkEins 2 роки тому

    🕵️👷👩‍🔧

  • @JuanBotes
    @JuanBotes 2 роки тому

    diet coke plus \o/

  • @anirudhdilli6250
    @anirudhdilli6250 2 роки тому +1

    You look burnt out mate.

  • @pinakidas4695
    @pinakidas4695 2 роки тому

    🧐

  • @tarunteck6034
    @tarunteck6034 2 роки тому

    2nd view bros