Behind Closed Doors - Bypassing RFID Readers

Black Hat Asia 2025 · Day 2 · Briefings

Overview

In his Black Hat Asia presentation, "Behind Closed Doors - Bypassing RFID Readers," Julius Dunuk, an IT Security Specialist at Securing, offered a compelling and often humorous look into the overlooked vulnerabilities of physical access control systems. Dunuk, a seasoned red teamer, shared insights from his extensive experience in penetration testing and physical red team assessments, demonstrating a range of techniques from low-tech social engineering to sophisticated electronic bypasses. The talk served as a critical reminder that even organizations with advanced digital defenses often leave their physical perimeters surprisingly exposed.

Watch on YouTube

Visual summary for Behind Closed Doors - Bypassing RFID Readers
Visual summary for Behind Closed Doors - Bypassing RFID Readers

Key moments

  1. 1:10 Bypassing a door using an 'under door tool'
  2. 2:40 Unusual and 'evil' uses of RFID technology
  3. 4:20 Challenges and limitations of RFID card cloning
  4. 5:10 Introduction to autonomous RFID locks and their operation
  5. 6:20 Live demo: Adding and deleting RFID cards
  6. 7:30 Logic bypass vulnerability: A card that always opens

Behind Closed Doors - Bypassing RFID Readers

Speakers: Julius Dunuk, IT Security Specialist, Securing

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=0NCnjx5wuns

Overview

In his Black Hat Asia presentation, "Behind Closed Doors - Bypassing RFID Readers," Julius Dunuk, an IT Security Specialist at Securing, offered a compelling and often humorous look into the overlooked vulnerabilities of physical access control systems. Dunuk, a seasoned red teamer, shared insights from his extensive experience in penetration testing and physical red team assessments, demonstrating a range of techniques from low-tech social engineering to sophisticated electronic bypasses. The talk served as a critical reminder that even organizations with advanced digital defenses often leave their physical perimeters surprisingly exposed.

Dunuk's presentation meticulously dissected the common failure points in RFID (Radio Frequency Identification)-based access systems, which are ubiquitous in modern facilities. He emphasized that security cannot solely focus on the RFID reader or the lock itself but must consider the entire system architecture and human element. Through live demonstrations and engaging anecdotes, Dunuk highlighted how persistent attackers can exploit design flaws, misconfigurations, and human trust to gain unauthorized entry, underscoring the urgent need for a holistic approach to physical security.

This talk is particularly relevant for security professionals, facility managers, and anyone responsible for protecting physical assets. It provides actionable intelligence on prevalent attack vectors and offers practical defensive strategies. By revealing the often-simple methods employed to circumvent seemingly robust security measures, Dunuk's work encourages a shift in perspective, urging organizations to integrate physical red teaming into their security assessments to identify and remediate vulnerabilities that are frequently missed in traditional audits.

Background

▶ Watch: Bypassing a door using an 'under door tool' (1:10)

RFID technology has become an integral part of modern life, extending far beyond simple access control. Dunuk illustrated its diverse applications, from tracking clothing inventory and facilitating contactless payments to more unusual uses like authenticating coffee machine filters to prevent the use of unoriginal products, or even embedding trackers in road signs to deter theft. Despite its widespread adoption, the security implementations of RFID systems vary dramatically, creating fertile ground for exploitation.

A common perception of RFID security often centers around card cloning. While tools like the Flipper Zero or Proxmark3 can indeed clone certain cards, Dunuk clarified that this method is often limited to less secure, older systems. For instance, Prox cards, which are a type of low-frequency card, typically use no encryption and are relatively easy to clone if an attacker can surreptitiously scan an employee's card. However, modern, high-security cards like HID Seos employ robust encryption and non-default keys, making direct cloning significantly more challenging and time-consuming, requiring specialized tools and potentially cryptographic keys that are not easily obtained during a typical red team engagement. This limitation prompted Dunuk to explore alternative, often more effective, methods for bypassing physical access controls.

Dunuk categorized RFID access control systems into two primary types encountered in the wild: autonomous RFID locks and controller-based access control systems. Autonomous locks, typically found in lower-security environments like apartment buildings or stairwell entrances, integrate the entire decision-making process within the reader itself. These readers store a memory of valid cards and directly command the door lock. In contrast, controller-based systems, prevalent in corporate and high-security facilities, separate the authentication and decision-making functions. Here, the reader authenticates and decrypts card data but then transmits this plaintext data over wires to a central controller, which holds the memory of valid cards and makes the final decision to open or close the door. This architectural distinction forms the basis for many of the advanced attacks Dunuk demonstrated, particularly those targeting the communication channel between the reader and the controller.

Key Findings

▶ Watch: Challenges and limitations of RFID card cloning (4:20)

Julius Dunuk's talk unveiled several critical vulnerabilities and attack methodologies against physical access control systems, ranging from inherent design flaws to configuration oversights and social engineering tactics.

One significant finding related to autonomous RFID locks was a logic bypass vulnerability. Dunuk demonstrated that specific card IDs could always open certain locks, even after being explicitly deleted from the system. Specifically, for MIFARE Classic cards, an ID consisting of all 'F's (0xFFFFFFFF) consistently bypassed the lock, suggesting a software bug where this value might be treated as a default "always valid" or "deleted" state that unintentionally grants access. This highlights how faulty firmware logic can override intended security measures.

Another curious, albeit unreliable, finding was the use of an EMP generator (Electromagnetic Pulse generator). This device, capable of generating strong electromagnetic pulses, could sometimes reset the memory of autonomous locks, causing them to open. However, Dunuk cautioned against its use in red team scenarios due to its unpredictability; it could either open the lock or permanently damage it, making it an impractical and risky tool for professional engagements.

For situations where physical access to the reader's wiring is possible, Dunuk pointed out the danger of "safe open mode" configurations. If a reader is configured to open the door when its connection to the physical lock is severed (e.g., cutting the wires), an attacker can easily bypass the system. This indicates a failure in fail-safe design, where a security device's failure mode inadvertently grants access.

The most profound findings, however, revolved around controller-based access control systems and the widely used Wiegand protocol. Dunuk revealed that despite sophisticated encryption between a modern card (like HID Seos) and its reader, the reader often transmits the decrypted card ID in plaintext over the Wiegand wires to the controller. This fundamental flaw exposes the system to sniffing attacks, allowing an attacker to capture valid card IDs regardless of the card's cryptographic strength.

Building on the Wiegand vulnerability, Dunuk introduced the downgrade attack. If a reader supports both secure modern cards (e.g., Seos) and insecure legacy cards (e.g., Prox cards), an attacker can capture a valid Seos ID via Wiegand sniffing, then write that ID onto an insecure Prox card. Because Prox cards transmit their ID in plaintext, the reader accepts this "downgraded" clone, effectively bypassing the encryption of the original Seos card. This exploit hinges on the common practice of maintaining backward compatibility in access control systems.

Finally, Dunuk highlighted the pervasive issue of neglected tamper detection mechanisms and the power of social engineering. Many readers are equipped with tamper sensors, but often these alarms are either not connected to a central security system or only trigger a local, easily disarmed beep. Furthermore, Dunuk demonstrated that simple acts of confidence, wearing a "professional disguise" (like a server room technician), or even using a plastic card to shim a door, could bypass physical barriers in plain sight due to a lack of awareness or intervention from employees. He also showed that Denial of Service attacks, either by flooding Wiegand lines with random data using a tool like TiC or exploiting vulnerabilities in HID Reader Manager app Bluetooth features, could disrupt access, creating diversions or locking out legitimate users.

Technical Deep Dive

▶ Watch: Introduction to autonomous RFID locks and their operation (5:10)

The technical core of Dunuk's presentation revolved around dissecting the communication protocols and inherent vulnerabilities in different RFID access control architectures.

For autonomous RFID locks, the critical vulnerability demonstrated was a logic bypass related to the card ID. In the example of a MIFARE Classic reader, the speaker showed that a card programmed with the hexadecimal ID 0xFFFFFFFF would consistently open the lock, even after being explicitly deleted from the system's memory. This suggests a potential bug in the reader's firmware where this specific ID might be misinterpreted as a universal master key, a default "empty" state that grants access, or an internal representation of a deleted entry that is improperly handled. Unlike simple card cloning, this attack exploits the reader's internal decision-making process rather than the card's data security.

The transition to controller-based access control systems introduced the fundamental weakness of the Wiegand protocol. This protocol, widely adopted for its simplicity and longevity, operates over two data wires, typically green and white, in addition to power wires. Wiegand communicates by dropping one of the lines low to signify a bit: the white line dropping low sends a '1' bit, and the green line dropping low sends a '0' bit. The critical flaw is that Wiegand transmits the decrypted card ID in plaintext. Regardless of how robustly a card like HID Seos encrypts its data during communication with the reader, once the reader successfully authenticates and decrypts the card's unique identifier, it sends this sensitive information unencrypted to the central controller. This design means that any attacker with physical access to the Wiegand wires can easily sniff and capture valid card credentials.

To facilitate this sniffing, Dunuk introduced TiC (The Invisible Card), a custom tool developed by his colleague Jakob Kash, to which Dunuk contributed. TiC is designed to passively listen to the Wiegand communication, capture the raw bitstream, and then parse it into recognizable card formats (e.g., H10301) and extract the facility and card numbers. Once a valid ID is captured, TiC can also be used to remotely inject this ID back into the Wiegand lines, effectively impersonating a legitimate card and opening the door. This remote access capability turns a passive sniffing device into an active bypass tool, allowing an attacker to open doors from a distance.

The downgrade attack is a sophisticated combination of Wiegand sniffing and legacy system exploitation. It requires a system where the reader supports both secure, encrypted cards (like HID Seos) and insecure, unencrypted cards (like Prox cards). Dunuk demonstrated this using an RF field detector to confirm the reader emitted both high-frequency (for Seos/MIFARE) and low-frequency (for Prox) signals. After capturing a Seos card's decrypted ID via TiC's Wiegand sniffing, Dunuk used a Proxmark3 device with Iceman firmware to write this exact ID onto a blank Prox card. Since Prox cards transmit their ID in plaintext, the reader, configured to support legacy credentials, processes this Prox card as if it were the original, high-security Seos card, thus granting access. This attack leverages the backward compatibility often built into systems to avoid costly upgrades, creating a critical vulnerability.

Beyond data interception, Dunuk also detailed Denial of Service (DoS) attacks. The TiC device, when connected to the Wiegand lines, can be configured to flood these lines with random data. This overload prevents legitimate card data from reaching the controller, effectively locking out all users. A similar DoS can be achieved against unpatched HID readers that have Bluetooth enabled. Using the HID reader manager app, an attacker can repeatedly trigger the "inspect" or "locate" modes. "Inspect" causes the reader to blink and cease authentication for about eight seconds, while "locate" causes it to beep loudly, blink, and halt authentication. Looping these commands creates a persistent DoS, which can serve as a distraction or a localized lockdown mechanism.

Dunuk's deep dive underscored that robust security requires not only strong encryption at the card-to-reader interface but also secure, encrypted communication channels (like OSDP with secure mode and AES encryption) between the reader and controller, robust tamper detection, and the proactive disabling of legacy, insecure protocols and credentials.

Demo / Proof of Concept

▶ Watch: Live demo: Adding and deleting RFID cards (6:20)

Julius Dunuk's presentation was rich with live demonstrations and video footage, vividly illustrating the discussed vulnerabilities and attack vectors.

He began with a low-tech, yet highly effective, physical bypass using an under door tool. A video showed Dunuk successfully manipulating an interior door handle from the outside, utilizing the gap between the door and floor, to gain unauthorized entry into what he humorously referred to as "my boss's backyard." This served as a potent opening, immediately highlighting that sometimes the simplest physical bypasses render complex electronic security irrelevant.

For autonomous RFID locks, Dunuk performed a live demonstration of the logic bypass using a MIFARE Classic reader and a specially programmed card. He first showed a legitimate card opening the lock. Then, using a Proxmark3 with Iceman firmware, he programmed a test card with the ID 0x00000000, which failed to open the lock. Subsequently, he programmed the card with 0xFFFFFFFF (all Fs). This "All Fs" card successfully opened the lock, and critically, it continued to open the lock even after Dunuk used a manager card to explicitly delete it from the system's memory, proving the logic flaw.

Dunuk then presented a video demonstrating an EMP generator opening a lock. He explained that he would not perform this live due to the risk of frying the stage's audio system, having experienced such issues in the past. He also noted the unreliability of the EMP generator, emphasizing it as a "curiosity" rather than a recommended red teaming tool.

The focus then shifted to controller-based systems. Dunuk showcased a custom setup comprising a reader, a physical lock, and a Raspberry Pi acting as the controller. His first challenge was gaining access to the Wiegand wires. He demonstrated how a reader equipped with a tamper sensor would trigger an audible alarm when removed from the wall. He then showed how to easily disarm a simple beeping alarm by untangling specific wires, noting that many tamper alarms are either not connected to a central security system or are merely local noisemakers.

Once the tamper alarm was disarmed and the wires exposed, Dunuk performed a live installation of TiC (The Invisible Card) onto the Wiegand wires (green, white, red, black for power). He meticulously connected the device, showing its blinking LEDs as confirmation of operation. After re-mounting the reader with TiC hidden behind it, he accessed TiC's web dashboard via Wi-Fi. A live demonstration showed an employee (likely himself) authenticating with an HID Seos card, and the TiC dashboard successfully captured and displayed the decrypted card ID in H10301 format, proving the Wiegand plaintext vulnerability. Dunuk then used TiC's remote injection feature to open the door, demonstrating an attacker's ability to control access remotely.

Following the Wiegand sniffing, Dunuk proceeded with the downgrade attack. Using an RFID RF field detector, he confirmed that his demo reader supported both high-frequency (for Seos) and low-frequency (for Prox) cards, indicating potential legacy support. He then took the decrypted Seos card ID captured by TiC and, using the Proxmark3, wrote this ID onto a blank Prox card. The subsequent live demo showed this "cloned" Prox card successfully opening the door, a critical proof of concept for bypassing secure, encrypted cards by leveraging insecure legacy protocols.

Dunuk also demonstrated a Denial of Service attack using TiC. By activating TiC's DoS mode, he showed that neither the original Seos card nor the cloned Prox card could open the door, as the Wiegand lines were being flooded with random data. He also presented screenshots of the HID reader manager app, explaining how its "inspect" and "locate" functions could be looped via Bluetooth to achieve similar DoS effects or create a noisy diversion.

Finally, Dunuk reinforced the power of social engineering with personal anecdotes and video. He shared a photo of himself in a "very professional disguise" (a technician with a ladder), successfully bypassing a reception desk to access a server room. Another video showed him casually using a plastic card to shim open a server room door in broad daylight within an active office environment, with no one questioning his actions, underscoring the common human tendency to overlook suspicious behavior when confidence is projected.

Defensive Implications

▶ Watch: Logic bypass vulnerability: A card that always opens (7:30)

The vulnerabilities exposed by Julius Dunuk underscore a critical need for organizations to reassess and bolster their physical access control systems. Implementing robust defenses requires a multi-faceted approach, addressing both technical and human elements.

Firstly, a fundamental architectural principle must be enforced: always place access controllers in secure areas. Autonomous RFID locks, where the decision-making unit is co-located with the reader on the unsecured side of a door, are inherently vulnerable. By relocating the controller to a physically secure area (e.g., a locked server room), attackers cannot physically tamper with the decision-making logic or cut wires to force a "safe open" mode.

Secondly, organizations must migrate from outdated protocols like Wiegand to more advanced, encrypted solutions such as OSDP (Open Supervised Device Protocol). Crucially, simply installing OSDP-capable hardware is insufficient; the system must be configured to use its secure mode of operation with AES encryption. Dunuk highlighted that many OSDP installations are run without encryption, rendering them as vulnerable as Wiegand to sniffing attacks. Encrypting the communication between the reader and the controller is paramount to prevent plaintext card ID interception.

Thirdly, proper tamper detection is non-negotiable. Readers are often equipped with tamper sensors, but these are frequently either disconnected or merely trigger a local, easily ignored beep. Security teams must ensure that tamper sensors are actively connected to a central security system that generates immediate alerts to security personnel. This enables a rapid response to any attempt to remove a reader from the wall.

Fourthly, maintaining software hygiene is vital. Keep reader firmware up to date to patch known vulnerabilities that could be exploited for denial-of-service attacks (like those demonstrated with the HID reader manager app) or other logic bypasses. Furthermore, disable legacy credentials and protocols if they are not strictly necessary. The downgrade attack, where a secure card's ID is written to an insecure Prox card, relies entirely on the reader's continued support for older, unencrypted card types. Phasing out or strictly segregating legacy systems can significantly reduce the attack surface.

Finally, and perhaps most importantly, organizations must cultivate a strong security awareness culture and periodically engage in physical red teaming assessments. As Dunuk demonstrated, human factors and social engineering are often the easiest bypasses. Employees need to be educated on suspicious behavior, the importance of challenging unfamiliar individuals, and the proper handling of access cards. Physical red teaming, unlike traditional audits, actively tests the entire physical security posture, including social engineering, to uncover vulnerabilities that are otherwise overlooked. This proactive approach allows organizations to identify weak points in their physical defenses before malicious actors exploit them.

Key Takeaways

  • Physical access control systems are often critically insecure: Despite advanced digital defenses, physical perimeters frequently suffer from overlooked vulnerabilities in design, configuration, and human behavior.
  • Wiegand protocol is a major plaintext vulnerability: Regardless of card encryption, the Wiegand protocol transmits decrypted card IDs in plaintext between the reader and controller, enabling easy sniffing and replay attacks.
  • Legacy support enables downgrade attacks: Systems supporting both secure and insecure card types are vulnerable to downgrade attacks, where secure card IDs are captured and cloned onto unencrypted legacy cards.
  • Tamper detection and secure controller placement are crucial: Many tamper alarms are ineffective, and placing decision-making controllers on the unsecured side of a door creates easily exploitable bypasses.
  • Social engineering remains a potent threat: Confidence, simple disguises, and basic physical bypass techniques (e.g., shimming doors) can often circumvent security measures unnoticed, highlighting the need for increased employee awareness.
  • Proactive physical red teaming is essential: Organizations should regularly conduct physical red team assessments to identify and remediate vulnerabilities that traditional security audits often miss.

About the Speaker(s)

Julius Dunuk is an IT Security Specialist at Securing, where he specializes in performing penetration tests and physical red team assessments. Driven by a passion for finding new hobbies that provide an adrenaline rush, such as horse archery, Dunuk also finds excitement in the challenge of bypassing physical access controls and breaking into server rooms. His expertise lies in uncovering overlooked vulnerabilities in physical security systems, a skill he demonstrated extensively during his first Black Hat presentation. Dunuk's work emphasizes the importance of a holistic approach to security, blending technical know-how with an understanding of human behavior to expose weaknesses in even the most seemingly secure environments. He is available on LinkedIn for connections and inquiries regarding physical security assessments.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Julius Dunuk's talk on bypassing RFID readers is a brutally honest, highly practical deep-dive into the often-neglected world of physical access control vulnerabilities. While the fundamental insecurity of Wiegand isn't new, Dunuk's meticulous demonstrations, custom tooling (TiC), and particularly the clever downgrade attack against modern encrypted cards by leveraging legacy protocols, provide actionable insights that are critical for any organization. He merges technical exploitation with sharp observations on social engineering, delivering a compelling case for integrated physical and digital security assessments.

Heather Calloway (CISO) — MUST SEE

Dunuk's Black Hat presentation on bypassing RFID readers is a critical examination of overlooked physical security failures. It moves beyond superficial technical details to expose systemic vulnerabilities in governance, outdated protocols like Wiegand, and pervasive human factors. This is not just about a technical bypass; it's a stark reminder that physical access control failures translate directly into significant business risk, demanding clear accountability, immediate operational changes, and a strategic shift towards integrated physical and digital security assessments.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025