When a Stranger Comes to Visit: Hacking Visitor Management Systems

Presented at THOTCON 0xA (2019), May 3, 2019, 1:30 p.m. (25 minutes)

Visitor management systems (VMS) simplify the process of admitting trusted outsiders into a campus. Unfortunately, anything you attach to a computer can be hacked, and VMS are no exception. We set out to find out how vulnerable the systems companies use to admit visitors are, and what we found was surprising--an industry with little focus on security. This talk will focus on the vulnerabilities found while analyzing several visitor management systems and demonstrate how to exploit those vulnerabilities and other misconfigurations to become a trusted visitor--without an appointment.


Presenters:

  • Scott Brink (sandw1ch)
    Hannah is a junior at University of Tulsa and Scott is a senior at RIT. They'll work with X-Force Red again this summer.
  • Hannah Robbins (robbinbs)
    Hannah is a junior at University of Tulsa and Scott is a senior at RIT. They'll work with X-Force Red again this summer.

Similar Presentations: