Access Control Exploits: Risky PIRs?

Author: Brian Rhodes, Published on Dec 09, 2012

A panicked end user called us this week about a surprisingly simple way their access control system was compromised. After they shared the details, it became clear that almost any electronic access control system can be impacted. Even though the fix is simple, your systems may be at risk. In the note below, we share the details and the recommended solution.

The Target

*** *** ****, *** **** * ****** ** ****/****** ***** in ***** *********, ****** * ****** ***** ***** * ******* secured **** *** ************* **** ** **** ***** ***** ******* any ******** *****, **** ***********, ** *********. ********** ***** **** should **** **** *** **** ****** ***** ***** **** *** locked, *** *** **** *** **** ** ****** *** ****** it.

**** *** **** *********, ************ *** ************ ****** **** *** building *** ********. ** **** *****, ***** *** **** ******** by * ******** ********* ***** ****** ******* ** ** ******. Alarm ****** *******, ****** **** ******* ********** ** *** *****, and *** ***** *** ******* **********.

*** ******** *********** ************ *** ******** *******, ******* ** ********** how *** ***** *** ********. ***** ******** **** ******** ** how ****** *** ******* *** ** ***** ***, *** *** a **** ****** ** ***** ***** ** ** **** ********** of ***** ****** ******** **.

The *******

*** ***** ******** ** * ***** **** ***** ********** *** homeless ***** **** ****** ** **** ****** ** *****. ** this *****, * ******** ********** *** ******** ** * ***** of ********* **** ******* *** ********** *******. **** ****** *** able ** ***** **** ********* ***** *** **** *****, **** the ****** ****. ******* **** **** *** ***** ******* **** a *******, ***** **** ******** ** **** * '******* ** exit' *** ******* ***** *** ****** **** *****, ** *** maglock ******** ** ** ********* ****** *********.

**** ***, ***** **** *** ****** ******** ******* *** ****, was ******* ** *** ****-*********** ****** ***** ** ********* **** under *** ****. *** ** *** *********'* ******** ** **** and ****** ** *** **** *****, *** *** ****** *** tripped *** ******** *** *******. **** ** **** **** *** door *********, *** *** ******** ********** *** **** ** ***** the ***** ********. *** ***** ***** ** * ******** ************* of * *******/*** ***:

rte pir

*** **** ***** ** *** ******* ******* ************** *** *** - ** ****, *** ****** ********** exactly ** ** ****** ****. *** **** ***** *** *********** to ** *** ********* ***** ******** ** *** *********:

*. *** **** *** *** ************ ******* ** * **** after *****, ** ******* ********** ********. ** *** **** ***** had ****** ****** *** **** ** ********, ** ***** *** have **** ********* ****** ***-********* *****.

*. *** ****** **** *****/********* *** *** ******** ******** *** permitted *** ********* ** ** ******** **** * *** ***. While ** ***** **** * ***** ***** ** *******-*********, *** bottom **** ***** ****** *** *** *** **** ******* ***** like *****, *********, ** ***** ***** **** ******** *** ******* area.

The ********

*** ******** *** *******, *** ******* *********** * ****** ** changes **** ******* ****** ******. *****, *** ****** **** ****** were ******** *** ******** ** ******* *** ****, *** *** access ******* ****** *** ************ ** ****-*** *** *** *** during ********** *****.

******* *** **** ** ******** ** *** ** ******** ********, an ********* ****, *** ** *** **** ** ** ********** with ******** ****** '****** *****', ****** ******* *** *** *** during ********* ***** ** *** * ******* *** *** **** signed *** ** *** ***** **** *******. ** ********, *** customer *** ******** ** ******* ********** '**** ******' ********* **** releases ** ********** ********* ****.

The ****** *******

***** *** *** **** *********** ** **** ** * ****** of **** *****, ** *** ************* ********** *** ***** **** been **** ******. *** **** ** *** *** ***** ****** out ** ** **** **** $** ** **** *********** *** less **** * ******* ** ************* ******* ** *** ****** control ******.

******* *** ***** ****, *** ***** ****** ** * ******** that *** ******** *** ** ******* **** ****** *********** *** hardware **********. ******* **** ********** ******* ***** ** **** ** any ****** ******* ******, ** ** ********** ***** ********** ****** becoming ** *****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on Access Control

Smartcard Copier Tested (13.56MHz) on Jul 05, 2017
Copying 125kHz cards is certainly easy, as our test results showed, but how about 13.56MHz smart cards? Are they more secure? IPVM focused on the...
Biometrics Pros and Cons For Electronic Access Control on Jun 26, 2017
Biometrics has been long sought as an alternative to the security risks of cards, pins and passwords. While biometrics has improved somewhat over...
Access Control Course Winter 2018 on Jun 11, 2017
The Winter 2018 IPVM Access Control Course is now open; save $50 on early registration. IPVM offers the most comprehensive access control course...
RMR Integrator Importance Statistics on Jun 08, 2017
How do integrators feel about offering RMR / recurring revenue services? For many, their business revolves around RMR, while others see no...
HID Edge EVO Tested on Jun 07, 2017
HID Edge controllers have been one of most common offerings in IP door controllers for years. The new generation is called Edge EVO. We tested...
Access Control AHJ Nightmares on Jun 01, 2017
For access control jobs, a single person can be the difference between finishing a job, costing thousands in extra dollars, and being profitable...
US States Security Licensing Guide on May 30, 2017
In the US, many states require integrators to be licensed to install burglar alarms, CCTV, electronic access control, or all three, and...
Anti-Hack Access Card Shields Tested on May 26, 2017
Keeping your access control card information secure is becoming a big priority, especially since cheaper copiers can hack details easily. Multiple...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Smartphone Controlled Kevo Lock Tested on May 04, 2017
Smartlocks are a growing market, with millions sold. Kwikset's Kevo is one of the most common choices, using the Unikey smart phone access control...

Most Recent Industry Reports

Axis Door Station Tested (A8105-E) on Jul 19, 2017
Axis continues their push into niche markets, especially audio, with network speakers, an IP horn, and video door stations. We tested Axis'...
Manufacturer Favorability Guide on Jul 19, 2017
This 120 page PDF guide may be downloaded inside by all IPVM members. It covers our 20 manufacturer favorability rankings and 20 manufacturer...
$8 Billion Utility Georgia Power Enters Surveillance Business Offering Avigilon And Genetec on Jul 19, 2017
Utilities are typically considered major customers of surveillance integrators but one utility, Georgia Power, with $8+ billion in annual revenue...
Knightscope Laughs off Robot Drowning on Jul 18, 2017
A day after a Knightscope robot drowned, Knightscope has issued an 'official statement' making fun of the issue: The implied message is that...
Microsoft Video AI Cloud Services Examined on Jul 18, 2017
Microsoft has released one of the most amazing video analytics marketing videos ever. In it, they detect oil spills, track individual people giving...
Hikvision USA Head of Cybersecurity Exits on Jul 18, 2017
Hikvision USA's Head of Cybersecurity has exited the company. In this note, we review the move, share Hikvision's feedback and examine the...
'Suicidal' Knightscope Robot Drowns on Jul 17, 2017
Knightscope continues its hyper growth, at least when it comes to controversy, this time with a 'suicidal' robot in Washington DC. And here is...
March Networks Company Profile on Jul 17, 2017
March Networks was one of the most well-known video surveillance manufacturers of the 2000s. In 2012, March was acquired by Chinese / American...
Milestone Beats OnSSI In Court on Jul 17, 2017
The litigation between former partners Milestone and OnSSI has finished, confirmed by both parties. In April 2016, OnSSI sued Milestone and in...
Power For Burglar Alarms on Jul 14, 2017
In order to operate, alarm panels require the high voltages found in electrical outlets be converted to the low voltages they run on. In this...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact