How To Hack (almost) Every Keypad
Disclaimer
I do not have official authorized field experience since I am a student and research is limited for this topic. So most of the techniques shown are brainstormed with a mind shaped by listening to every damn episode of Darknet Diaries (love the podcast check it out if you want to) so it may not be entirely accurate. With that said let's dive in.
A story
Ok so I went for a walk the other day and in desperate need of a toilet I stumbled into a Kaufland. The toilet there was at the end of a long narrow corridor without CCTV cameras. But why am I talking about me going to the toilet you may ask? No? Nobody asks? oh its in the title...yeah.. ok yeah I should name my article smth less spoiler-y like... toilet trip. yeah.. probably not, anyways. Halfway through the corridor I see the CCTV surveillance room. Protected by? A keypad. Now: I want you to look at this picture and tell me what you see.
Well. We see a keypad, with the most used Keys getting a white outline. We see some keys even have the rubber worn off. Specifically the 6, 7, 8 & 9 are heavily worn off. Ok... Worn keys wow... who cares right?
Well... let's do a simple calculation. Let's take a 4 digit PIN on a random 10-digit keypad (it is only an assumption we do not know how many digits it has but four for the calculation). If you would want to brute-force it to get into the "highly" protected CCTV door, you'd have anything between 0000-9999 which are 10⁴ = 10.000 combinations if you type one combination every one second (which is insanely fast) you'd stand there worst case for almost 3 hours like a clown typing in on a keypad...not suspicious at all.
Now lets say the 4 keys included in the PIN are smudged due to extended use. Now you don't have 10.000 combinations but only 4!. No not FOUR, I mean 4 factorial. Which is
$$4!=1 \times 2 \times 3 \times 4=24$$
You reduce the combination from 10.000 combinations to 24! (now its 24 and not 24 factorial XD). That's a reduction by unbelievable (pulls out calculator) 99,76%.
Even better if you can predict the combination in the above example if the smudged keys are 6, 7, 8, 9 the PIN could really just be 9876 which is embarrassing.
An example
Ok that shot was not that good because I had to do it quick to not have a very uncomfortable discussion with the security personnel. I mean what would I say? I am a geek and like keypads? So I went on a trip to the whole city to find keypads with a clear smudge pattern. Entrance Door? Nah I don't want to piss my neighbor off. Grocery Store? Too smudged to get a clear pattern. Shopping mall? Not smudgy enough. Until one day I was going out, eating burgers with a friend of mine and we randomly walk past the backdoor entrance of a HOTEL monitored by three CCTV-cameras. So obviously I did not...ok yeah I walked up to it and took a picture.
Thought exercise. Take a minute and use the knowledge you have applied to tell me. What do you see:
You see the digits 2, 6 & 9 are highly used. Also strongly used is the digit 3. Interestingly (* & #) are not used at all which leads us to believe that there should be another mechanism to confirm the sequence. For example the PIN-field only waits for the last n digits to be the right pin. If you type on it you are greeted with a loud BEEP! (you know the classical digit-press sound but unnecessarily loud). As much as I wanted to test that out and see if I was right, I ended up walking away from this keypad, because brute-forcing it would mean to stand by a keypad screaming like a smoke detector on steroids. hmm.... now that I think about it... that is kind of the feature isn't it? If its loud it stops criminals (and apparently also young security students) from just standing there and brute-forcing it. But is there any way you could improve your results?
Advanced Techniques
The Flashlight Trick
The most obvious one would be to hold the flashlight in a specific angle so you get a better view of the greasy smudges and residues remaining on the keys
| pros | cons |
|---|---|
| you don't need advanced tooling a phone flashlight should be enough | the technique is as simple as it is ineffective. I really thought about not putting it into advanced techniques because of how trivial and ineffective it is. |
| You are pretty visible at night and try explaining why you are crouching in front of a keypad and holding a flashlight at different angles. I'm not helping you out of this mess | |
| cleaning basically nullifies this attack |
Sherlock Holmes
We all know the detective shows where our lovely protagonist walks around with this forensic fingerprint set to get ...well fingerprints. This sets typically have a brush. Fingerprint brushes can hold more powder than normal brushes. And typically some sort of silver and black bichromatic fingerprint powder(got that straight from a marketing description from amazon). What does bichromatic mean? Well in that case it means the fingerprint powder is black on light colored surfaces and gray on dark-colored surfaces. And it is pretty intuitive to use too. Just brush the keypad with the powder hope that there is enough grease so the powder can stick and you get the fingerprints aka. the pressed digits. Pro Tip: Clean the keypad afterwards to get rid of your tracks.
| pros | cons |
|---|---|
| relatively cheap and pretty effective | requires cleaning to not leave extra evidence |
| works retroactively (grease can last for hours or even days if indoors) | weather sensitive |
| if the keypad is not cleaned the success rate is pretty high | cleaning basically nullifies this attack |
| You get everything. Wrong digits, someone resting their hand on the keypad. |
The Power Of The Heat
Thermal Cameras. The hide and seek dream of every child... or just me, I kind of was a hide and seek fan. If you manage to get there in time you really could see the body heat of the fingers as a residue on the keypad. And probably (never tried it) also the sequence it is pressed. The only problems really are that heat decays very fast so you got i don't know 15-90 seconds? Although a heat cam is pretty obvious and you do not really have the decision when to go check it you have a time frame... a pretty strict time frame. But there are some phone thermal cameras so maybe you are able to do it less obviously
| pros | cons |
|---|---|
| gets full sequence | expensive...very expensive |
| strict time frame |
Observing Is Good, Manipulating Is Better
Why wait until someone enters when you can actively pre-tamper the keypad...and then wait until someone enters... But it has its benefits. For example instead of dusting the keypad and hoping you get some clean positions you can pre-dust the keypad with an invisible UV-fluorescent powder (or even spray which does not need much time), at any time convenient to you and then come back later use an UV flashlight and voila you get the pressed keys. The only downside. If you have multiple people entering with multiple key codes you either have to go after the first one to type or you are left with a broken imaging.
Solving The Problem
Ok now that we are able to crack (almost) every keypad open without touching the electronics. How do we defend from that. We certainly don't want our keypads wide open, do we? Here a few ideas
The White House
The white house has a digital screen keypad thingy that rotates the numbers "0-9" so, people can not do exactly what we have been trying to do for (1, 2, 3 , 4... yeah no I'm not counting this... for x paragraphs). My very reliable source is the uncle of a redditor who worked in the secret service...yes very reliable but either way it is a genius idea, very inconvenient and evil because now I have to remember the code and not the pattern though.
524 - A Timeout Occurred
We should ensure our lock has an automatic lockout feature after a couple of incorrect attempts which does not only protect you from this whole attack but also from people guessing your password. But it does not stop a determined person it just delays it. But if you log incorrect attempts and maybe even put up a surveillance system you get to scare off most intruders
Long And Often
Try to use a long pin with a lot of digits reused. Let's prove both techniques mathematically.
Making it a 5 digit pin instead of a 4 digit pin would lead to 5 smudged keys which would increase the possible combinations by
$$n_4 = 4! = 24$$
$$n_5=5!=120$$
which makes the combinations 5 times higher. Now if we stay at the 4 digit pin but lets say smudge only 3 keys meaning we reused one key we get
$$n=3⁴=81$$
which is over 3 times higher. (Well technically there are less combinations cause if you have 1, 2 and 3 smudged you can't have the pin 1111 because then only 1 would be smudged but I am not gonna calculate that) Ok who am I kidding I am definitely gonna calculate that. For that we only need to take the possibilities with 4 digits (n) (we divide them by 2! because swapping the identical number doesn't create a new pin) and multiply them with the amount of digits that can repeat themselves (r)
$$r=3$$
$$n=\frac{4!}{2!}=12$$
$$x=r \times n=3 \times 12=36$$
And with that we get 36 combinations. Not as much as 81 but still a decent amount more than the usual 24
Smoke Detector On Steroids
Make the digits loud. Annoying and simple but a pretty easy to achieve early warning system that already scared me off once. So it is effective but not a mitigation more of a little annoying cheap feature.
