How Iceman Champions PACS Vulnerability Research

Published Oct 27, 2023 14:05 PM

Christian Herrmann, better known as Iceman, is a prominent figure in physical access control systems (PACS) vulnerability research, leading the development of Proxmark rdv4 and moderating PACS hacking communities.

IPVM Image

Based on an interview with Iceman, we examine his background, contributions to RFID research, his company, IceSQL, and ethics within access control hacking.

This is the second in a new series profiling physical security researchers. For our previous security researcher coverage, see: Red Team Alliance / CORE Group Profile - Babak Javadi Interview.

Executive *******

****** **** *** ********* ** *** Physical ****** ******* ******* (****) ************* research ** ******* ******* ******* ** access ******* ******* *** **** *******. Iceman *** **** ************ ** ********** the *********, ******** ** *********** *********** repository, *** ****, * ****** **** security ******** ****. ****** ** ** active ********* ** **** ******* ***********, disseminating ********* *** *********** ************ ** the ***** ***** *********** ******* ******* practices.

Iceman’s ********** ** **** ********

****** ******* **** ******* ** ***** ago, **** ******* ******* ** ******** mastery ** **** ******* **** *** Proxmark, ******** *** ** *** ****** figures ****** *** **** ******* *********. Iceman **** *** **** ******* ********** started **** * *** ***** ******* Proxmark, ***** ** *** ******* ********** setting **.

***** ** ***** ***, * *** very ******* **** ****, *** * thought, "* **** ** ** ********* for ******." *'** ****** ***** ********* and *******, ** * ******* ** buy * ******* ****. *'* ***** my ***** *** ******* *** ***** RFID **** *** ******* ***** *** Proxmark. * ***** $*** ** * device **** *****. **** ** *******, it *** **** * *** *** some ********. * ***** * **** trying ** *** ** **, ****** for **** ** ******, *** ********** failed. ************, * ******* *** ********.

***** ******** *** ****** *** *** months, ** ******** * ***** *** got ** *******. *** ***** ** accomplishment ** *** **** ******* * bus ****** ********** *** ** ***** deeper **** **** *******, ****** *********, going ****“*** ****** **** ** *******” and ********* “****** **** ******.”

** *** ***** **** * *** judging ** **** * **** ***** for *** ******. *******, * **** following ****** ** *** *** ********** how ** *** **. **********, * thought, "*'** ***** ** **** ** this, * **** ** **** ** another ****." **, * **** ** down, ******** * *****, *** *** it *******. *** ***** **** * successfully ****** * *** ****** **** it, * **** * ***** ** accomplishment **** ****** **. ***** ****, it's **** * **** ****** **** of *******; ** ***** ****. **'* layers **** ******.

**** ******* ******* ********* ******, *********** him ** ******** *** ************ ** RFID *******. **** ***** ** * hobby ****** ** ********* *** * need *** ******** *********** ****** * professional *******. *** *************** ****** *** eye ** *** **** ******* *********, and ** ******* ******** **** * leadership ********, ******* ******** *** *********** in **** ***************.

*** ************* ** **** *** **** hacking *** ****** *********** ** *** previous **** ** *** *****, *** he ** "******** ** *** ********* of ******," ****** ****.

** **** ******** *****, **** ** a ******** ********* *** *** *** of * ****** ****** ******* *******. However, ******** *** **** ******* ***** considerable ****, *** ** ** ******** his ******* ** **** ****, ****** added.

******** *** **** ******* *** **** a ***** ** **** **** ***** over **** *** **** ****. ** you **** ** ** **** ** shame ** **** **** ****, **** my ************ ********* ********* *********** **** nobody **** *** *** ******'* ** computer ******* **** ***** ****** ****** asks ***. ** *** ***** **** to ******** ********** *** ****** ******* software. ****'* **** ****** *** **** for **** *** *****. * **** my *** *** ****** *** ******* of ******* *******, *** ****** **** I *** *** *** ** * startup ***** ****** ****** *******.

Key ************* ** **** ********

******’* ************* ** **** *** ************, from ********** ******** ***** *** ********* to ********* ***********. ****** *** *** development ** *********** ****, * ******** **** **** ** most ****** **** *** **** ************* testing. *** ******** **** ** * pivotal **** *** ******** ***********, ****** integrators, *** ************* ** *********** *** understanding ****** ***************. ****** **** **** helps *********** ********** *** ************ ****** PACS.

******** *** ******* ** ** ********** the ********** ******** ************ ** ******* PACS. *** *********** *** ********** **** made ** *** **-** **** *** anyone ******* ***** **** ************* ********.

******* ******* **** ******** **** ******* "Iceman **********," ************ *** ************* ** the *********** ** *** ****** *** continued ******* ** ******** *** *************.

IPVM Image

****** *** ******* *** *************** *********** ********* ** **** *******. ***** ****** ***** ** **** for *********** ********, ******** *********** ** share ********, *************, *** ***** ********** vulnerabilities. *** ************* *********** *** *********** the **** ** ******** *** *** led ** *** ************** ** ******** security ***** **** ***** **** ********* gone *********, ****** ****.

********** ****** *** ********* ** ****** community *** ******** * ******** *** collective ************. *** ****** ********* ****** up *** ********* ** ***************, ****** PACS **** ****** ** *** **** run.

***** *** ********* ***** ***** ***, the **** ******* ******* ********* *** attracted **** *,*** *******. *** ********* is ******, **** ******* ******* *********, answers, *** *********** ***** ****.

IPVM Image

****** *** ****** ******* ******** ******** and ************ ********** ******* *******, ************* *********** ** *** ******* security *********.

IceSQL ********* ******* ********* *** ************

***** ****** ********** ********* ****** ******** for *** ********* ********, *** *** direction ** ********* ******* ******** *** RFID ********, ********** ****** ********, *** providing ******** *** ********** ** **** devices *** ************ ******** ** *** European *******.

*'* ********* *** *** ******** ******** for ********* ******** **** **** ****. It's ***** ** ** ******** ******** for **** *******, ********. **'* ***** to ** ****** ******** ***********. **'* going ** ** ************* *** ********* as ****. *** **'** ***** ** focus ** *** ******** *******.

****** *********** ** *********** *** ********* vulnerabilities ** **** ************. *** ********* includes *********** ***** ******** ** **** the ******** ********** ** ***** *******.

The "******" **********

****** **** *** **** ** *** moderator ** *** *********** ******* ** communicating **** ******* ** *********** *** ensuring **** *** ********** ** *** vulnerabilities *****'* ********* ****** ****** ******.

***** ** "******" ** **** ******* represents * ******** *******. ******** * engage **** ******* ***********, ************* ***** achievements *** *******. **** ******* ************ something ***********, * ********** *********** **. However, **'* ******* ** ********** **** publicizing ***** *************** ***'* *********. **** have ******** ******* ***** ******; ******** only ********** *** ********** ******. * hesitate ** ********* ******* ***** *************** in, *** *******, ***** ******** *******. Such *********** *****'* ******* *** ********* at *****. *** *** **** ** to ****** ***'* *** ***** ************ positively ** *** *********.

Flipper **** ****** **** *** **** ** *****

****** **** *** *** *****, **** as ******* ****, **** *** **** of ***** ** **** ******** *** hacking **** *****, ********* ****** **** ready-to-use *****.

**'* ***** ****. *** *** *** hanging ****** ** ** ****** *** wide ******. ******* ***** ** ********* easy. *** ******* **** ******, ******* and *** ************ ** ***** **** hacking ** *** *****, ** ***** it * ***** *******.

******** ****** ******* ******* **** **** it ***** "*******" ****** ** ****-**-*** tool **** ******** *************** **** ***** harm *******.

******* **** ** ****. ******* ****** come ******* **** **** *****, * don't **** **** ****** ** **** this *****.

******* **** ********** *** *********** ** pursue **** *******, *** *** *** generation ** "**** ***********," ********* *** following ***** **********, *** ******.

******* **** ****'* ***** ******** ***, but *****'* * *** ********** ** RFID ******* ****** ***, *** ****** to ***** ****** *** ** **** excited ***** **. **** *** ****** excited ***** *** ********. *** **** are **** **** ***********, *** ****** about ************, ******* *** ***, ******* Tesla *****, ***. **'* ***** **** or *** ****, *** ** ***** back ** *** ******.

******* **** ******* ****, ******** ****** the *********** *** ** *** ***, can ** ****** ******** ** ******** limitations ******* ** ***********, ****** * threat ** ****** ******, ********* ** Iceman.

**** *********** *** *** ** **** limits ** *** ******. *** **** licenses *** *** ****** ***'* ****. They **** **** **. *** ******* Zero *** *** ******** ********** ** firmware ****** **** ** **** **** within *** ****** ** *** ********* spectrum **** *** *** *** **** and *******, ******* ** *** *********** they **** ** ******. *** **** download ******* ********, *** ****, *** have *** ** *** ******** *** hardware **** *** *********. *** ***'** telling ** *** *** ************ ****? Or *** **** *** ****?

Proxmark3 *********** *** ****

******** ** *** ** *** **** common ******** ***** *** **** ********, and ****** **** ***** *** ******* had *********** *************, *** *********** ***** not ** ******** ******* *** ******* work **** ** ******.

******** ** *** ******** **** **** has **** **** ** *** **** 15 ***** **** ** ***** ** RFID *******. *** **'* *** ****. It's * ********* ******. * **** to *** **** ******* **'** ******** on *** ********* ** ******. **'** been ***** **** *** *********. ***** are **** ***** ****** **** ** the **** *** **** *** ********** for **** ** *** **, *** we **** ** *** ****** *** carried ** **** ****.

*** *** **** ** *****, ****** has ******** *** ****** ** ******* Proxmark, **** ** * ******** *** a ******** ****, ****** ** **** field-useable.

**** *** *** ***** **** * preassembled ******** **** ****** ******** **** out. ** ******, *** *** **** was, "******** *** ** ********; *** just **** ** ********* ** ********." When * *******, * ******** ******** said ** ***** ** ********** *** could ***. **, * *** * vision. ** ****** ** **** *** see, *********** ** *** ****** **** and ******** ****. * ****** ** have * **** **** ******* * lot ** *******. * ****** ** have * **** **** ***** ** my *******. *** * **** ****** to **** ********* *** *** ** out ** *** *****. * **** want ** **** *** *********** ** store **** ****** ** ** ** store ***** ******* ****'* **** *** use ** ***. *** * **** it ** ** *********.

***** **** *** *** ********** *** their ***** **** ******** ***, ** is * ******** ******** **** ******** to **** ** *** ** ***** ago, ****** *****.

** ****'* ****** ** *** *** whole *** **** ** ******* **** was **. **'* ***, *** ***** the ***** **** ******** *******, **** you *** ** ***** ** **** much *** * ***** **** ** to ****. ** *** ** *******, I **** ** *** *** * wanted ** ** ****. ******, ** was ****** ** ****, *** *** pieces ***** ***** *****. *****, ** feels **** **** ** *** *******. You *** ** **** **** ***** are *******, *** ** *****. **** more ****** *** *** ***** *****, but ******** ***** ******* ******.

******** ** *** **-** ******** **** for **** *******. *******, *********** **** more *********** **** **** ****** *** standards ** ***** *** *******, ****** said.

**** *** **** ** ** ****** properly, *** *** **** ** ******* things, *** *** ********. *** ***** thing **** ** ***** ** **** hacking ** **** *** **** **** things. *** **** *** ***********, *** need *** **** ******, *** *** need ********* ** *** **. ** now *** **** **** * ******* software **************. ** *** *** *** commands *** *** ****** ** ** follows *** ******. *** **** **** is *** ** ** ****** ******* setting *** ********. *** ** * break *** ***** *** ** ** with **** ********.

Access ******* "**** ****** ******"

******** ******* *** ********* ********* ** more ****** **** **** ***, *** Iceman **** ***** ******** ************* *** the ****** ***** ***** **** *** secure, **** *** "**** ****** ******."

* ****** ** *** *** **** because *** ******* ** ***** **. Given *** ************* ** **** **'* supposed ** ** *** *** ******, the *********** ******, *** **** ** is ***** ** **, *** ******* of ***** ****** ** ******** **** actually ** ** ** * ****** system. * ***** ****** ************* **** tremendously. *'* ****** **** **** ** your ******** ****** ****** **** **** are ******. *** *** ** *** know *** ***% ********* **** ****'** not ******,just ****** ******. [emphasis added]

*** ******* ********* ** ****** ******* security ** ****** ***********. ****** **** that ** ****** *** ****** ** training, **** ****** **** *** ****** engineering ******, ******** ****** ***************.

**** ****** *** **** ****, *** spamming, ******** ******** ********, ******* ******, a *** ** ******** ************* ***** be ****** ** **. *** *** have ********* ******** **** *****. ** doesn't ******; *** **** **** *** the ****** *********** *****. *'* ***** aware ****** ***'* ******, *** ****'* a **** ** **. * ***** we ********** *** **** ** **** idea ** **** ******* *** ** or ****** **, *** ****** **** the ******** *** ******* *** ******. Vendors *** ** ******* ** ** safe *** ******, *** **'* ***. And ******* ** [****] **** ****. It [*** ******] ** ***** ** be ***** *** ** *****. ******'* changing **. ** *** **** * system, **'* ***** ** ** ***** [before *** ******]. ** ***'** *****, they **** ****** *** ******** **** or *****.

Access ******* ******** **** **** ** *** ****** ********

****** ******* ********* **** ************ **** hostile ****** **** *********** *** ******* (see**** ** *** ******** ********** *** Industry). *******, ****** **** ** ** changing **** ********* ******** *** ********.

**** ** ******* *** ** *** beginning, ** ***** ***, *** **** before ****, *** ******** ****** ******* companies **** ***, *** **** ******* towards *** ********, ******* *******, ******* finding ***************. ***** *** * *** of ***** *******, ******** ******** *********** back ** *** **** **** **** pushed *** ******* ***** *** ** much ********** **** *** *****. ** has ******* *** * ***** *** you **** ** ****** ***** ****** a ***. ** *** **** **** or **** ***** *** ******** *************,**** ****** **** ******, *** ********. Having ******* *** ******** *** *************** disclosure ******** *****. ***** ** * change. *********, ****'** **** ******** *******, hackers *** **** * **** ************* with ****, *** ******** ****** ***, making ****** ******, *** **** *** open **** **.

****** ***** ***** ********* ***** *** disclose **** *** ***************, **** ****** control ********* **** ** ****** ******** in **** ***********, ******* ********* *** changes.

**** ** ***** ** ***** ****, they *** *********, **** **** ** do ******. ** *** *** ** the ***, ********* ***** ** *** RFID ******* ******* [***********], *** ********* reads ****'* ***** **.

*** ****** ******** ***** ********* ** opportunity ** ******** ***** ******** **** a ****** ***********, ***** ***** ** stronger ******* ***********, *** ******.

** **'* **** **** ** ****. You ****, *** **** * ***** of *********. ****'** ***** ** ** a *** *** *** ***'* ****** them ** ******* *** ****** ******* and ********** *** ******* ** ******* out ** *** ***. ** ***** some ****. ****'* *** * ***** we **** *** ****** ********, * don't ***** ** *** **** ******* otherwise ****** **** **** *** *** bounty. *** ****, * ***'* ***** they *** ****** ****.

Comments (19)
JH
John Honovich
Oct 27, 2023
IPVM

*********** *********!

******* ** [****] **** ****. ** [the ******] ** ***** ** ** there *** ** *****. ******'* ******** it. ** *** **** * ******, it's ***** ** ** ***** [****** any ******]. ** ***'** *****, **** will ****** *** ******** **** ** twice.

* *****, ** *** ****** *** premise **** ******* ** ***** ** change *** **'* ***** *** ** years, **** ******* ** ****.

*** ********, ** **, ** ******* we ****** ****** **** *******. *** years ***, ********* ** *****/***** **** relatively ****** ********, *** ***, **********, it's ***.

** ** **** ******** ** ********** access ******* ** ***** ******* ********** to * ********** *** ** ** an *** ******?

Avatar
Brian Karas
Oct 27, 2023
Pelican Zero

*** ********, ** **, ** ******* we ****** ****** **** *******.

***** **** **** ** **** ****** in *** ******.

** *** **** ** "*****/*****", **** was ****** ********** ** ** *** user. **** ** **** ****'* ** first, **** **** ***** ******** *** risk, ** *** **** ** **** a ****** ********.

*** * *** **** ** *** underlying ***** **** **** ** *** inability ** *** ******** ** ********* a ****** **** ********** ********* ** prevent ********, *********, ***. ** *** hardware ****** ***** *** ******* ************, or *** ******** *******, **** ***'** stuck ** **** ***** ** ******** until *** ********* ********* ******. *** can't **** ** * ******** ******, or **** ** "****** ****" ** your ******** ***'* ******* **.

***** **** **** ******** ******* ********* (eg: ****, *********** ****** ***** **** companies **** *********), *** *** ****** don't **** ** **** **** * top ****** ********, ** **** ** are.

(1)
JH
John Honovich
Oct 27, 2023
IPVM

*** ****** ***'* **** ** **** this * *** ****** ********, ** here ** ***. *****

******** *************** ***** **** *****:

IPVM Image

* ** ***** ***** ** * bias ** *** ****** *** **** and **** ***** ******, ******* *** people *** *** ****.

Avatar
Brian Karas
Oct 27, 2023
Pelican Zero

* ** ***** ***** ** * bias ** *** ****** *** **** and **** ***** ******, ******* *** people *** *** ****.

******** ***** **** ****** ***. ****** something "******" ***** *****, *** ** your *********** *** *** ***** ** compete **** *** *** ********* ******, and ** ********* **** ***** ******** more *********, **'* * ***** **** to ***** **** ***** *****.

* **** ***** ***** ** *** much ******** ** **** *****, ** least ******* ******* *******. *** ***** site ** ******** ***** ******* **********. Lots ** ****** **** ** ******* alarms, ***** **** ****-****** ******* *** and ***, ********* ******* ***** ****** off *** ****** *** **** **** into ***** *****, *** ** *****. This **** ** **** ****** ***** up * *** **** ** *** market, *** ******** ********* ******* *&* spending ** ***** ********* **** ***'* pay ***** ***.

** *** *****, * ***** ****** manufacturers **** ** ** **** ***** and **** ********* ***** ***** ******. But, ****'** ******* **** ****** ** this, *** *** ****** ******* **** (and **********) *** * ***** ***** acting ******* ****.

(1)
JH
John Honovich
Oct 27, 2023
IPVM

*** *** ********* **** **** **********?

Avatar
Brian Karas
Oct 27, 2023
Pelican Zero

* ***'* ******.

**********, * **********-********* ******** ****, ***'* seem **** * ******* ********** ****, but * **** ** ******* *********.

JH
John Honovich
Oct 27, 2023
IPVM

********* ********* **** ****** **** ****** want. **'* *** ***** *****? **** are **** ********** * ******? ** that *** **** **** ** ******** that ** ***** ******* ** ****** control ***************?

Avatar
Brian Karas
Oct 28, 2023
Pelican Zero

********* ********* **** ****** **** ****** want.

****, ** *** ********* ***** **** is *** **** **********/******** * ***'* even **** * ********.

(1)
JH
John Honovich
Oct 29, 2023
IPVM

****, ** *** ********* *****

****** ** *** ***** *** **** idea:

IPVM Image

Avatar
Brian Karas
Oct 30, 2023
Pelican Zero

* ***** **** *** *** *********** the **** "*************" ****. ***, ***, I ***'* ***** *** ***** *** best ******** **** *** ********* ********** either.

***, **** ** ** ******** **** technology. ** * ***** ******, ** are ***** ****, ****** *****, ***** locks, *** ***** ***** ** ***** that *** ****** ************. *** *** every *********** ***** *** ****** **** secure **********/***.

***** ** * ********** ******* * network *************, ** *** ***** ** attacker *** ****** * ****** ******* or ****** *** ******* **** **** of ******* **** ** **** ***********, and * ******** ************* ***** *** device ***** *** ** **** ** withstand * ****** ********* ********.

**** ***** ****, **** ***** *** fine *** *** ***** ** ******** that ***** ***** "******* ****** ****** honest", ****** * ******** ****** ** friction ** ************ ******, *** *** immune ** ******** *******.

** **** **** ********** *** * vulnerability ***** * ****** *** ******* that ******* ****** ** **** ** to * ****** *** **** *** lock, ** ***** ** * ********* scenario.

* ***** *** **** *** **** majority ** *****, *****, *********, *** similar ******* ******* *** **** ******** than ****** ******* (**, ***** **** is **** ** *********** **** ******** the*********** ******).

*** * ***** *** ********* ******* is ****. ********** *** * ******* that ******** ******* ** ******** *****, and **** **** ******** ********** (* say ********, ******* ******* **** ****** disagree ;) ). *** **** * prox-based ****** ******* ****** **** ***** to **** *** **** ******** ** people ***, *** *** ***** **** needs **** **** * ****-******** **** (eg: **** ****** ** * **** to *** ** ** **** ** casual ****** *** ************* *********).

(1)
JH
John Honovich
Oct 30, 2023
IPVM
U
Undisclosed #1
Oct 27, 2023

* ****** ** **** ****** *** Val ****** '******'.

(5)
(2)
UI
Undisclosed Integrator #4
Nov 02, 2023

****** ***.

UI
Undisclosed Integrator #2
Oct 30, 2023

***** *** **** *********** ***** ****** in **** ** *** ***** *** same ******* *** *********** **** *** realm ** *********** *** ** *********** money, ****** **** **** ******, ***'* it?

**** *******, ******** ********* ********... *** suddenly *** *** ****-************* **** ***** away.

"* *** **** ****** ** ******** people **** **** **** ** ******* the ******** ** *****" ***** *** keep *** *** ** *** ******* pokey *** ******.

***' *****'.

(1)
Avatar
Brian Karas
Oct 30, 2023
Pelican Zero

***** *** ****** **** ** ***** regarding ************** ********, *** ******** ***** is **** ****** "********" ***** *** can ****. ***** *** ***** ***** to ** ****** ** ****** **. If *** **** $**,*** ** ***** bills ** * ****, ***** ** no ********** ******* **** **** **** you * *** ***** ** $**,*** bills, ** ********* **** *** *** the ******** ****** ** $**,***. (*'** leave ********* *** ** ****, ** that ** * ********* ******).

**** * **** ****, *** **** is * ***** ** **** ***** to ****** * ***** ** ** authorized ****. ** **** *****, ** you **** *** ****, **** ****** will *** ** *******, *** *** will ** ******* * *** **********. While **** ************* *** ****** ** buy ***** ******* ** ********** ******, they ***** ******** ****** ** "****" their *** ***** ****************.

**** ********* ******* **** ********** ********, IMO.

CH
Christan Herrmann
Oct 31, 2023

***** ** ******* ** ******* ********* to *** **** **** *** *** opportunity ** *********** ** **** *********. It *** * ******** ** ****** in * ********** ********** ** *** important ***** ** ****.

***** **** ** ****** ** ****** to ****, **** ** ** *** their ********** ********* *** *** ************ manner ** ***** *** ********* *** conducted. **** ********** ** ********* * space *** ******** ******** ** ******* appreciated.

***** ******* ** ******** ** ******* discussions **** *** **** ********* *** welcome *** ********* ** ******** **** may ***** **** **** *******. ***'* keep *** ************ *****, ******* ********, and ******* ******** ** ******* *** challenges *** ************* ** **** ********.

****'* ** * ******** *** ************ dialogue!

UE
Undisclosed End User #3
Nov 02, 2023

******** ***** *** ********* *** ***** HSPD-12 **** **** ********** ** ******** over ****** ******** **** *** ******* PACS *******. ** ***** **** +*** means *** **** ** *****, ******** surf, ** **** *** *** *** of *** ****.

Avatar
Steve Bell
Nov 02, 2023

** ********* ** ********** ******* *** activates ** *** ****** *********. ** have **** ******** ********* ** *** team **** *** *********** *** *** great ********. *** ** ****** ***** to ***** **** *** ** ***** hackers, ***** *** * *** ** diverse ******** *** ***** ** *** hacker ********* *** **** ** *** some ******** **** *** ** **** we ***** ***** ***** ******* ********* and *** **** **** **** **** more ****** ********.

*** **** **** ********** ******* **** case ******* ** ******** ** *** OSDP ***** ** ***** ******* *** we **** ****** ********* ***** *** tendency ** ****** *** *********.

(1)
CH
Christan Herrmann
Nov 08, 2023

********* ** * ******* **** ** understanding *** *** ** **** ******** with *** *********.