Sam Quinn and Steve Povolny: Hacking an Access Control System
A DEF CON 30 talk about compromising the HID Mercury networked physical access control system, widely deployed in government and commercial facilities worldwide.
The researchers uncovered multiple 0-day vulnerabilities that allow remote, unauthenticated code execution and full system compromise — including the ability to unlock doors remotely without triggering alerts or notifications.
The researchers uncovered multiple 0-day vulnerabilities that allow remote, unauthenticated code execution and full system compromise — including the ability to unlock doors remotely without triggering alerts or notifications.