Security Testing Tactics Reveal Common Security Problems
Most security failures aren’t actually tech issues. They’re because of human behavior. Everyday habits and small, seemingly-insignificant moments of trust can lead to serious issues and breaches. Strategies experts use for security testing reveal many of these weaknesses. But they also reveal what can make people, places, and systems safer.
See Exploiting Trust (Part 1) with FC Barker for a complete transcript of the Easy Prey podcast episode.
FC Barker is better known professionally by his ethical hacking handle, Freakyclown. He’s been a cybersecurity professional for over thirty years, including as the head of ethical hacking, penetration testing, and physical security at several different places. His last job was as head of offensive cybersecurity at Raytheon, a large defense firm. After leaving there, he started his own company, Cygenta, with his wife. He is also the author of the bestselling book How I Rob Banks that talks about his career breaking into places and systems to test their security.
FC predates the cybersecurity industry. When he was growing up, there was no such thing. The internet existed, but there was no World Wide Web. His first computer didn’t even have a mouse or a keyboard, just toggle switches. Back then, when you got a computer, it came with a big manual on how to use it. After you turned it on, you’d have to program it yourself to get it to do anything. So he grew up tinkering with them. Computers weren’t a field of study when he went to college, so he studied science. Eventually he dropped out to become a sysadmin for a small company. While doing that, he realized that criminals were using these devices, too – and the only way to defend against them was to learn their tactics himself.
The Start of Penetration Testing
Cybersecurity was a different world back then. The whole web ran off FTP. It wasn’t secure. Logging into some things just required a username, no password. You used to be able to dial up other computers. The whole system was peer-to-peer. It was a big transition for people to realize there were malicious people out there doing things with computers that nobody expected, and that we had to defend against them.
Decades ago, offering a service to break into someone’s system for security testing was a much harder sell. From FC’s perspective, it happened gradually. Web servers run on a physical box in a data center somewhere. That’s expensive, so many companies sold space on their web server to other companies. If you have someone doing security testing, it’s easy to offer that service to everyone on the server. People realized that it didn’t matter how great your security was. If someone on the same server had bad security, the hackers can still get in.
Some of those companies got bigger, got their own servers and infrastructure, and realized they need someone to look at security. They realized it made more sense to focus on whatever their business was and get an external expert in to test things. External validation is often easier to sell to the board, too. And it adds an extra set of eyes. FC’s book is full of stories where people who installed the security systems don’t understand the big picture well enough. Everybody has their own blind spots, and if the installer is also doing the validation, it’s easier to miss them.
[Often] people that have installed the security systems don’t understand them enough in the bigger picture that it’s very easy to bypass them.
FC Barker
Doing Interesting Things for Clients
FC has done a lot of interesting things for clients, and some across all kinds of random things poking around clients’ systems. In one particularly awkward situation, he discovered a secret web server running on the client’s stack with some racy content. FC talked to the board, and they called in a tech guy. He comes in, and they ask him if he knows about the server. The guy responds, “Yeah, that’s my wife’s site. If you’re interested in any other content, let me know.” It was the weirdest moment FC has ever had in a pen test.
You get all sorts of interesting things doing pen testing. FC is lucky to get to choose his clients carefully and primarily work with strange, esoteric, and fun stuff. For one client, they did security testing on some underwater sensors that nobody had ever tested before because there was never a reason to. It was a fun challenge.
In the recent Venezuela operation, they turned off the power. Fifteen years ago, FC created a device to do just that when involved in an operation to help change the regime of a country. It took his team a few weeks to reverse engineer some hardware. This was pre-Raspberry Pi, so they created an Arduino-type device to give to the team. A squad went in and planted it, because FC certainly wasn’t going. But once it was planted, it turned off the power in twenty-one seconds. He’s had a lot of very cool experiences, and is very fortunate to get to choose what he works on.
Common Gaps Revealed by Security Testing
Many of the biggest problems that FC’s security testing reveals are around company culture or employee education. But on the technical side, the biggest thing he sees is a network that’s not segmented well enough. Whether that’s a proper air gap system for sensitive information or just assigning IP ranges to certain departments, that’s a big one.
One bank that FC went to test told him that their network was flat but segmented. That was a bit of a confusing statement. But FC and his team started scanning stuff, and a moment later, the client comes rushing over and says that Brazil has gone offline because the line was saturated. FC responded that they were just port scanning, and that shouldn’t saturate the line. Then the client revealed that they still used ISDN – the original high-speed internet developed in the 1990s and still using phone lines.
It’s the foundational things that FC finds hilarious. Companies spend so much money on security software that they never configure. They spend billions on the latest shiny things and miss the basic, foundational things. One bank that FC used to do annual pen testing for never switched to RFC 1918-complaint addresses – meaning that their entire internal network was internet-facing. They’d just picked an IP range from the internet. FC looked it up with WhatIsMyIPAddress.com and discovered that it was a Department of Defense IP range. If anything got misconfigured, they would be getting an unpleasant knock at the door. Every year for five years, that was the top issue on his report, and they never changed it. So he fired them as a client.

The Old Machine Sometimes Matters
There are lots of stories in security testing about an old, extremely outdated machine in a closet somewhere that everybody says not to touch, because if you do anything with it everything breaks. There are quite a few of those. And a lot of people don’t appreciate all the implications. The blanket advice is just to make sure everything’s updated. But that doesn’t work in every situation.
The blanket statement is … just make sure everything’s updated. Well, that doesn’t work in every situation.
FC Barker
Take, for example, a $1,000,000 MRI machine in a hospital that runs on Windows XP. They can’t upgrade it because the manufacturer no longer exists. The software to use the machine only runs on Windows XP, so they’re stuck with that operating system. They can’t update it if they want to keep using that machine. New MRI machines cost $10,000,000. What should the hospital do? Should they spend $10,000,000 on a new machine that runs on Windows 11? Or keep the machine they already have that works, segment the Windows XP device from the rest of their network, and protect it with other stuff? If they’re aware of the risk and take appropriate measures, it’s just as secure.
Keeping things updated is often good advice. But it’s not always as simple as making a blanket statement. There legitimately are machines that need to stay in the corner collecting dust and not get updated. And that’s not always a major risk, either. FC once saw a place running an AS/400 from the 1980s. He’d love to watch script kiddies or people running AI try to figure that one out. It’s so different from the way modern computers work that hackers would have a hard time.
Social Engineering in Security Testing
Social engineering is more the subject area of FC’s wife. But he uses it in physical security testing to get people to open doors he shouldn’t get through and see things he shouldn’t. For him, he’s found it more effective to avoid people, or at least avoid interacting with them, where possible.
There’s the scenario where you’re trying to get through a locked door. A common strategy is tailgating – waiting for someone to open the door and follow them through. But that can be a problem if they turn around and ask you who you are. FC avoids this by having a drink in one hand and a chocolate bar in the other. But he can still speak. So when he sees someone approaching the door, he puts the chocolate bar in his mouth. Now he has an excuse for why he didn’t open the door and can’t answer any questions. They open the door, he holds it open with his one free hand and does some sort of nod, and they let him through. Just a nod is very effective. People want to be helpful, and this resolves their question of why you’re tailgating without you having to say anything.
When getting into any building, FC likes to get up to the highest floor he can, then work his way down. There’s a psychological aspect to that. People know that the higher up you are in a building, the higher your rank. If you start at the top and go down, people are seeing you coming downstairs. They won’t challenge you because they assume you had a reason to be up there. It’s more suspicious to go up than go down. Going down also has the implication of leaving. You’re not someone coming into the building, you’re someone leaving it. Even suspicious people are more on the lookout for people going in than people coming out.
Dressing the Part
FC always dresses appropriately for the target, which often means a suit. Once he gets to a high floor, he stashes the jacket in a bathroom stall. Then he’s just walking around in a shirt and tie, implying that his jacket is hanging on a desk chair somewhere. This is also a useful strategy to get into a building when it’s raining. Ditch the jacket somewhere, get to the door soaking wet, and say that you left your jacket with your badge in your office. Nobody thinks this guy in a wet shirt is trying to break in. They just feel bad for the idiot who left his jacket and badge inside.
FC once got yelled at for not wearing a tie at an office he didn’t work in. He was doing security testing for an investment bank. He did all his tasks, then decided to see the investment floor. As soon as he arrived, one of the bankers started yelling at him. For a moment, he was afraid he’d been caught. But the man was just furious that he wasn’t wearing a tie. He didn’t care what FC was doing, just that he wasn’t dressed appropriately.
It works the other way, too. Once, FC was trying to break into a bank’s headquarters. He showed up on a Friday morning dressed in a suit, planning to jump the barrier after the security guard’s patrol. But as he waited, a dinosaur walked across the reception area, followed by Jack Sparrow. Then he noticed the receptionist had cat ears and whiskers, and the security guard had devil horns and a little plastic pitchfork. They were having a charity dress-up day, and FC’s suit was suddenly out of place. He had to come back the next week.
Think Like a Criminal
If you’re not ready to do security testing but want to up your game, start thinking like a criminal. An easy way to do this is to think about your house. Think about when we forget our keys and now have to break in with the least amount of damage or the neighbors calling the police. Suddenly, you’ll start thinking about things like the bathroom window doesn’t close properly, or you could climb over the back wall, or the cellar doorframe is rotten and you could probably just pull the door off. You can think of five or six ways into your house. And you realize how much your house is open to any criminal who comes past.
Then you can take that mindset to the office. If you didn’t have a badge, could you just jump this barrier? Would anybody notice? Would you get in trouble? FC guarantees that just about everybody has at one point needed to get through something at the office and found a way around it. Just think about how you could stop that, or make it slightly harder. Could you raise the barrier, because it looks more suspicious to have to climb than to just step over? Once you’ve spotted the issues, you can start to mitigate them.
I can guarantee you everyone has done this in their own office at some point where they’ve needed to get through something and they’ve found a way around it.
FC Barker
Cygenta Security probably isn’t a good fit for your first pen test, but if you have some esoteric hardware or a crazy new thing, feel free to reach out. Learn more about Cygenta and contact them at cygentasecurity.com. Find FC on YouTube @MrFreakyclown, LinkedIn, and Twitter/X @_freakyclown_. Find his wife through her website, drjessicabarker.com.
