Pen Test Partners / PTP provides cyber security services to a huge variety of industries and organisations. info@pentestpartners.com.

Thirty minutes from walking into an office to taking over the domain. Our Paul Brownridge is at @GrrCON in Grand Rapids, Michigan, showing how preparation and a few overlooked building systems can turn physical access into the keys to the kingdom… “Mission Improbable?” JP DeKruiff is there with Paul too, so if you spot either of them, come and say hello! #GrrCON #PhysicalSecurity #PenTesting
3
235
Red Dwarf fans will know Talkie Toaster isn’t good at keeping quiet. When our Colin Kitchen built his own AI-powered version, he discovered that extends to passwords… What started as a long-held ambition to bring a favourite character to life became a practical experiment in AI security. When Colin turned it into a CTF challenge, sometimes all it took to get the password was an ultimatum… Toast or secrets! The blog post follows the whole build, from choosing and configuring a local model and recreating Talkie’s voice to 3D printing the body. Along the way came a few familiar AI security problems and an unhealthy obsession with toasted goods. See the Talkie Toaster in action below: 📌 pentestpartners.com/security… #AISecurity #RedDwarf
1
2
232
Oops, “We weren’t supposed to find that”... Yesterday our Sam Thom (@Blackf3ll) presented at the IET Cyber Security for Critical Industries Conference, sharing a few stories from our OT testing. A remote access device that wasn’t on the network diagram. A corporate Wi-Fi access point plugged into an OT network because someone needed internet access for their laptop. Understandable reasons for connecting things, but consequences that hadn’t been thought through. There’s plenty of guidance on securing OT. The challenge is checking how well it holds up on site, including the kit your suppliers have installed and the workarounds people have made. Thanks to the IET for having us! #OTSecurity #CriticalInfrastructure #IET
2
6
333
Passback attacks… When the printer refuses to print your document but happily hands over credentials. We quite often find insecure printer settings during testing that make these attacks possible. Even so, passback attacks receive less attention than other ways of stealing credentials. Our Morgan Davies built a fake printer interface to show how the attack works. The attacker may not be able to see or extract the printer's stored credentials, but they don't need to. If they can change the LDAP server it connects to, they can get the printer's credentials sent to a system they control when it authenticates. Read Morgan's attack breakdown and mitigations so your printer isn't quite so helpful: 📌pentestpartners.com/security… #PassbackAttacks #PenetrationTesting
1
5
315
Public Wi-Fi is often portrayed as inherently dangerous, but many of the commonly cited threats have not fully caught up with the widespread adoption of HTTPS and modern browser security controls. Someone sharing a coffee shop network cannot simply sniff passwords, messages or payment details from a properly secured HTTPS session. TLS, certificate validation and HSTS make interception far harder than many warnings suggest. The network itself should still be treated as untrusted. HTTPS protects the contents of a legitimate connection, but a malicious access point can still steer users towards a phishing site. It also does nothing for an unpatched device, an exposed local service or a certificate warning that someone clicks straight through. A reputable VPN can reduce what the local network can see and add another layer of protection. However, it also shifts trust to the VPN provider and cannot make a compromised device or malicious website safe. In our latest blog post, Eime Adomaviciute explains where the risk sits, with practical advice for users and small businesses offering public Wi-Fi. 📌 pentestpartners.com/security… #PublicWiFi #CyberSecurity #NetworkSecurity #DataSecurity
1
1
5
395
A friend’s father used strong, unique passwords and kept a record of them in an encrypted Excel spreadsheet. Unfortunately, he passed away. His family found the spreadsheet but nobody knew its password. Everything was safely locked away from the people who now needed it. With the family’s permission, our @AlanMonie used office2john and Hashcat to attack it. But brute force and dictionary attacks got nowhere. The breakthrough came when the family found a format he commonly used. Two dictionary words and a predictable structure made it much easier to attack offline. Luckily, the story has a bittersweet end, and the family got back into the systems they needed. However, it required a powerful cracking server and lots of electricity. Strong passwords are meant to keep people out. But make sure the people you trust have a secure way back in. Alan has written up some helpful guidance below: 📌pentestpartners.com/security… #PasswordSecurity #CyberSecurity
2
3
321
They could break IT/OT segregation without having to do… Anything? During an OT engagement, @Blackf3ll and @OPSEC_failed found that a spare corporate access point had been plugged into the control room network to give staff internet access. It reused the corporate SSID, so when corporate devices went into the control room, they … roamed. This broke segregation, exposing IT threats to the OT network and threatening to bring commodity malware back in to the IT network. The technical fix was easy enough. But if you fix a segmentation issue without finding its root cause, it will come back in another form. 📌 pentestpartners.com/security… #OTSecurity #ICSSecurity #NetworkSegmentation #WiFiSecurity
4
7
560
We were proud to support the @SecureAerospace and @ICS_Village this year at @defcon 34! In case you missed it, here's a wrap-up of what our team was up to: pentestpartners.com/security… Nine cases of hardware. Seven people. Three talks and a flight sim with a mind of its own... A shout-out to our team, Ken, Adam, Sam, Andrew, Paul, JP and Mark, for getting all that hardware to Las Vegas, rebuilding it on site and giving visitors plenty to get stuck into. #DEFCON34 #AviationSecurity #OTSecurity #CyberResearch
1
7
438
The battery itself is good. The networking decisions were not. In 2015, we recovered a home Wi-Fi password from a connected kettle. Nearly ten years later, we found a GivEnergy home battery repeating the trick. But worse than that... The kettle needed a deauthentication attack first. The battery did not. It was usually already connected to the customer’s home network, creating a much more direct backdoor. The gateway exposed Telnet and other local services. Earlier installations recommended either 12345678 or the inverter serial number as the Wi-Fi password. The serial number is also broadcast in the SSID! Once connected, we could recover the customer’s home Wi-Fi password and change how the battery behaved, including preventing it from charging. Given enough time, we could also potentially have affected the battery management system and caused the battery to overheat. We did not test this, for obvious reasons. GivEnergy addressed the credentials used for newer installations. However, we never received a remediation plan for existing customers before GivEnergy Ltd entered administration. That is the awkward reality of connected products. The manufacturer can enter administration while the hardware and its security problems remain in people’s homes. We have published the full research and practical steps owners can take now. 📌 pentestpartners.com/security… #IoTSecurity #HardwareHacking #ProductSecurity #PSTI #EnergySecurity
2
5
382
One exposed cloud secret took us into AWS, GitHub and Azure. It then led us back into another AWS account with admin access. It began with a Terraform state file in an overly permissive S3 bucket. The file contained credentials for a private GitHub repository. Inside that repository, we found another secret. This led us to Azure Key Vault, which held admin keys for a separate AWS account! Our Joe Durbin explains how to break the attack chain by making the secrets less useful to attackers in our latest blog post. The aim is simple. One exposed secret should stay one problem. 📌 pentestpartners.com/security… #CloudSecurity #AWS #Azure
1
1
2
350
Our @TheKenMunroShow is heading to @Hack_Glasgow on Saturday, 15th August. He’ll be sharing some of what we’ve learned from testing connected aviation systems, including electronic flight bags, wireless maintenance systems, passenger Wi-Fi, and satellite communications. Ken will also cover how security findings are disclosed and worked through with manufacturers, airlines and regulators. He’ll be on Stage 1 at 3:30 pm. 📌 pretalx.hackglasgow.live/hac… #HackGlasgow #AviationSecurity #CyberSecurity
4
324
The Hacker Summer Camp is nearly upon us! We’re heading to @defcon 34 with more kit than is probably sensible. @TheKenMunroShow, @OPSEC_failed, @cybergibbons, and @Blackf3ll will be speaking across the @SecureAerospace and @ICS_Village. Expect new research into electronic conspicuity devices, AFDX aircraft networks, and programmable automation controllers used in critical infrastructure, plus a few impromptu talks along the way. 📌 Our full talk lineup and details: pentestpartners.com/security… We will have one of our flight simulators with us, a half cockpit from an Airbus A320. We use it to demonstrate the effects of compromised engine performance calculations on a take off. This often leads to a tail strike and/or ‘runway excursion’ as crashes are sometimes euphemistically referred to as in aviation. Or just try to land it safely! We’re also bringing not one, but two Industrial Cocktail Systems. Both CTFs to help you learn about OT networks, so PLCs, HMIs and industrial switches & gateways. If you succeed, they might just make you a drink too. For anyone who prefers running, at 6:00 am, we’ll be joining DEFCON.run outside the Convention Center each morning. There may even be some spare PTP running swag for those quick enough to claim it. See you there! #DEFCON34 #ICSVillage #AerospaceVillage
1
6
452
Vibe coding has made it remarkably easy to build and ship software. Unfortunately, it hasn’t made that software secure. If anything, software security has dropped as inexperienced non-developers use it to create code. Why? Well, that vibe code was trained on existing code. Existing code with vulnerabilities. So, our Bedir did the obvious thing. He vibe coded a ‘penetration tester’. PenAI started during an Encode Club hackathon. The idea was to see how far an AI agent could get through a penetration test on its own. With the right tools, prompts and guardrails, PenAI reached a root flag on most Hack The Box machines rated ‘easy’, and a few towards the easier end of ‘medium’. It also repeated itself, confidently followed dead ends, lost context and occasionally produced ideas that sounded convincing but were completely wrong. In the blog post, Bedir walks through how he built it, what worked, what got weird, and what the experiment taught us about where AI assisted testing could fit alongside professional testers. We have also made the source code available on our GitHub for anyone who wants to take a closer look. 📌 pentestpartners.com/security… #penetrationtesting #artificialintelligence #cybersecurity #vibecoding
3
305
Click. Customise. Break in. Well, not quite. Gaining physical access through social engineering rarely depends on one perfect fake. To be plausibly accepted requires a combination of familiar details, the right clothing, a plausible pretext, and confident behaviour, helping make the barrier to entry harder for attackers. However, online suppliers of custom clothing have made it easier and cheaper to counterfeit the physical signs of trust. During physical security engagements, we have created fake badges, lanyards, and corporate clothing using available photographs and logos just living on the internet. In our latest blog post, @TBRoberts02 looks at how these items help manufacture trust, how organisations can increase the cost and difficulty of producing counterfeit copies, and why looking the part should never replace proper ID verification. 📌pentestpartners.com/security… #SocialEngineering #PhysicalSecurity #SecurityAwareness
2
5
471
A couple of weeks ago, @thackeraaron was at @Steel_Con talking about a piece of hardware most people probably wouldn’t give a second thought. An unbranded £10 4G USB modem. The slightly odd part is that some of these devices come with 512MB of memory. Once Aaron started pulling them apart, he found that many were effectively headless Android phones hiding inside a USB stick. His talk looked at how they can be rooted, reflashed, and loaded with custom firmware. With some work, an ordinary looking modem could be made to inject keystrokes, exfiltrate data, or carry command and control traffic. And, because “Can it run DOOM?” wasn’t enough, Aaron reflashed one of the modems to run the game, then made it present itself to the host computer as a webcam. Open the camera feed and, instead of anything remotely useful, you get DOOM! Entirely necessary research, obviously. #SteelCon #HardwareHacking #CyberSecurity
1
3
16
822
There has been plenty of chat online about people taking Flipper Zeros on planes. Numerous airlines have asked about the potential risks too. There have also been reports of Flippers being confiscated at airports, which has added to the confusion and consternation for legitimate security pros taking them in hand baggage. In our latest blog post, @TheKenMunroShow dispels these concerns by reviewing the technical capabilities of the Flipper in relation to flight systems. 📌 pentestpartners.com/security… #aviationsecurity #cybersecurity #flipperzero #aviationcybersecurity
4
8
42
7,146
EN 303 645 is a great baseline for IoT security. But a baseline is not the same as a secure product. In our latest blog post, @Blackf3ll looks at what EN 303 645 helps with, and what can still be missed when products are assessed against it. We often find issues in EN 303 645-aligned testing. Some are simple to fix. Others come from early design decisions that are much harder to change later. For example, a product may appear to handle secure storage properly, while still exposing sensitive data through firmware, debug interfaces, external flash, or supporting apps. At that point, it is not just a storage issue. It is a product architecture issue. The standard gives teams a strong place to start. Threat modelling and testing show whether the product actually holds up. 📌Read here: pentestpartners.com/security… #iotsecurity #en303645 #cybersecurity
1
1
1
338
Rust binaries can make string recovery awkward during reverse engineering. Unlike simple C-style strings, Rust strings may be stored as a pointer and length pair, with the string data sitting separately. That means normal string extraction can miss context or return messy output, especially when the tool does not recover the references cleanly. Our @tautology0 walks through the problem, shows how the strings were recovered from the ELF sections, and shares the script and Ghidra plugin he built to make Rust string extraction easier. 📌 pentestpartners.com/security… #ReverseEngineering #RustLang #Ghidra #ELF #BinaryAnalysis #CyberSecurity
1
6
28
1,765
A copy button can be enough. ClickFix, CrashFix, InstallFix and FileFix all rely on the same basic idea. Get the user to do the first step for the attacker. The page might look like a CAPTCHA, a browser repair prompt or an installer. But once the command runs, the name of the lure matters less than what happens next. Our @jwdfir walks through the artefacts defenders should be looking for after the paste, from PowerShell and user-writable path execution to temp files, persistence, staging activity and follow-on network connections. By the time Digital Forensics and Incident Response teams are called in, the landing page may already be gone. The lure looks simple. The consequences usually aren't. 📌Read here: pentestpartners.com/security… #ClickFix #DFIR #IncidentResponse #Infostealer #CyberSecurity
3
4
843