[66] Practical Lock Picking for Red Teamers

แชร์
ฝัง
  • เผยแพร่เมื่อ 15 ก.ย. 2024
  • In this video we discuss what level of locks I believe you need to be able to open if you are on a physical red team.

ความคิดเห็น • 29

  • @bowlsallbroken
    @bowlsallbroken 3 ปีที่แล้ว +8

    Too my thinking, the most important metric here is "will what I'm doing provide useful/actionable data to the client". Generally speaking, picking a lock that only the dozen greatest locksport ninjas on Earth can compromise scores low on this scale. The more your bypasses rely on low skill tricks the better, quite frankly.

  • @seanb3516
    @seanb3516 3 ปีที่แล้ว +11

    I would strongly suggest having a set of Jigglers and/or Rockers. They don't always work however they are quick & easy to try.
    As for Master Commercial and Pro series don't be intimidated. I actually have a harder time with No 3 locks than the Commercial series.
    I love seeing a Mul-T-Lok padlock with a Medeco core on a locker that has an Aluminum hasp. Yay Team :D

  • @SecuritySpecial
    @SecuritySpecial 3 ปีที่แล้ว +9

    Thank you : superb video as ever. If anyone does pick or jiggle filing cabinet and drawer locks on the job, make sure you've practiced relocking these types of locks again. No sense in carrying out a successful surreptitious entry when you have to leave an unlocked cabinet as evidence. Zero residual presence is almost as important as gaining access! I also carry a set of three common master keys (L&F 18 / 92 / FFe) I'm always surprised at how many desk / filing cabinet locks of various brands can be opened with these three keys.)

    • @boso1998
      @boso1998 3 ปีที่แล้ว +1

      Do you have a social media or telegram? I’d like to ask some questions lol I’ve seen you in the comments of a few videos now

  • @odinslockllc
    @odinslockllc 3 ปีที่แล้ว +6

    Personally, in a real world application, I try picking with any keyway before I use destructive means. I’ve had locks that should’ve been super easy not pick open and locks that should’ve been hard open when I barely started. Hardest ones are when you have a dozen people watching and after 10 seconds start asking how much longer cause they seen it done quicker in the movies. Thanks for sharing!✌🏼

    • @amihirata
      @amihirata  3 ปีที่แล้ว +7

      It never goes well whenever you have someone shoulder surfing you asking “is it open yet” that’s the worst

    • @jamesbridges7750
      @jamesbridges7750 3 ปีที่แล้ว +2

      Isn't that the truth! There are of course some locks I'm just not going to try, but an Abus or American is at least going to get a few scrubs with a double peak followed by a good probing with a hook - then you get that $7 brinks that just will not open lol

    • @odinslockllc
      @odinslockllc 3 ปีที่แล้ว +3

      @@jamesbridges7750 bump keys are invaluable in some of these circumstances as well. I have a ring of them for different lock keyways.

  • @matt79de
    @matt79de 2 ปีที่แล้ว

    Fully agree, nothing to add.
    Only mess with the locks you have to.
    Love the BosnianBill reference btw. 🤣

  • @legion162
    @legion162 3 ปีที่แล้ว +5

    During red teaming, are you allowed destructive entry, pretty much like a burglar. Like it's so much easier to cut off most padlocks, or use core pullers (think that's what they are called), or even hydraulic jacks to spread doors.
    I know it's only an exercise to highlight a targets vulnerabilities, but still.

    • @amihirata
      @amihirata  3 ปีที่แล้ว +5

      In very rare instances, destructive allowances are permitted, but I’ve never had the pleasure of being permitted to incur damages

    • @legion162
      @legion162 3 ปีที่แล้ว +2

      @@amihirata thanks for the reply. It wasn't something that I thought of until watching some videos on martial arts being pressure tested.
      So although locks might be pick resistant, windows walls and roofs are not.
      Obviously I don't mean that you would destroy a wall or roof to gain access, but these are two methods of entry I've seen used in shops local to me, bypassing high security doors and shutters.

    • @nealdmiller
      @nealdmiller 2 ปีที่แล้ว +1

      @@legion162 Agree! I did contract glazing for over 10 years. Many times to only thing holding in a window is a couple strips of rubber. Pop off the bottom sill, peel the rubber and you slide out the window.
      Still have to be aware of alarms, etc...
      Often the best way to be invisible is to wear a fluorescent orange/green safety vest, and a truck.

  • @traditionaltools5080
    @traditionaltools5080 2 ปีที่แล้ว +1

    Still, the best way into a building is a pack of cigarettes. Find the back "smoking door", make small talk, hand a couple out, then follow everyone in in 15 min. Even if you dont work there but have some type of business. You just needed a smoke out of sight. Right?

  • @spandexsteve5156
    @spandexsteve5156 3 ปีที่แล้ว +3

    Nice BB nod..

  • @l337n1nj41
    @l337n1nj41 3 ปีที่แล้ว +5

    I don't know about the rest of you, but if I were a red-teamer and had a Medeco separating me from my objective, I'd look for an alternative way to breach.

    • @amihirata
      @amihirata  3 ปีที่แล้ว +5

      Absolutely, unless the medeco could be easily bypassed by slipping a latch or using some other form of bypass

    • @Magicspirit11
      @Magicspirit11 2 ปีที่แล้ว

      @@amihirata using a UDT you can bypass almost every deadbolt.

  • @FuttBucker42069
    @FuttBucker42069 2 ปีที่แล้ว

    I think those higher security locks are a little more pickable when you’re actually supposed to be there lol.

  • @alabamalockpicking
    @alabamalockpicking 3 ปีที่แล้ว +1

    He's back

    • @amihirata
      @amihirata  3 ปีที่แล้ว +2

      I never left! I just pivoted to doing some social engineering stuff

    • @willjosephson
      @willjosephson 3 ปีที่แล้ว

      @@amihirata Ha. You can't fool us with social engineering. Nice try.

    • @Adrian-dl9nb
      @Adrian-dl9nb 3 ปีที่แล้ว

      @@amihirata Will you be sharing some with us?

  • @kuukeli
    @kuukeli ปีที่แล้ว

    yay

  • @bearsback5099
    @bearsback5099 3 ปีที่แล้ว +1

    I would suggest that you don't open anything that does not belong to you

    • @aihtdikh
      @aihtdikh 3 ปีที่แล้ว +5

      In general, of course. But (taking your comment at face value) the "red team" in this context is a group that has been hired to simulate an attack on an organization's defenses in order to highlight and fix security issues. Our not-so-civil friend here is involved in this area, so he is actively invited to open things that do not belong to him.

    • @bearsback5099
      @bearsback5099 3 ปีที่แล้ว +2

      @@aihtdikh Now I got it