The Courthouse - Revisited
Darknet Diaries
This episode revisits the infamous story of penetration testers Gabby DiMercurio and Justin Nguyen, who were wrongfully arrested after attempting to test the security of
Key takeaways
- The lawsuit against the Iowa County Courthouse resulted in a rare and substantial financial settlement of $600,000, highlighting systemic issues with prosecuting ethical hackers.
Main topics
- Ethical hacking and legal boundaries
- Wrongful arrest of security researchers
Notable quotes
"I fought the law and the law won. No, the law fought us and we won."
Conclusion
Gabby and Justin's journey from wrongful arrest to a landmark settlement has transformed their personal
Transcript preview
Speaker 4 (0:00) I just came back from DEF CON and it was so wonderful meeting so many of the listeners there. Many of you asked how my dad is doing. I'll tell you, he's struggling with the modern world. Let me show you what I mean. So like I call my dad a few times a week just to check in on him, but he only calls me when he's got computer problems. Let me play for you what one of these calls sounds like. Speaker 3 (0:22) Okay, so anytime I get a photo or if I want to save it, there's like a... three little dots top right corner. Speaker 4 (0:32) Yeah. Speaker 3 (0:33) Saving a photo. And I hit the dots because I want to save a photo. It used to say save. Save to account. So I'm clicking on that, save to account. But the count is something called OneDrive. Oh, it says add account. How do I add an account? Because OneDrive, I don't use. I don't even know what that is. Speaker 3 (1:06) This is ridiculous. Speaker 4 (1:07) Yeah, where'd you get this tablet? Speaker 3 (1:10) You gave it to me. Right. It's like all of a sudden my photo save image is gone. Where did you get the photo? Well, I just pulled up any one so I could explain to you. Okay, so you took Speaker 2 (1:24) the photo. Speaker 3 (1:26) I took it on the tablet. Speaker 4 (1:29) Did I hear that right? He took a photo on his iPad of some rabbits and doesn't know how to save the photo he took? It's always the most mind-boggling question that he throws at me. I saw the photo. It was dark and blurry. It was not even worth saving. But he manages to stump me every time with these tech questions. I'm just like, Speaker 3 (1:52) uh... Oh, wait a minute. No. I found it. I found it. Pushing buttons. Good. You did it again. Yep. Speaker 4 (2:12) Good work. And there you go. He figures it out all at his own without any help from me at all. I'm just listening to the problem. And that's how a lot of these calls go. He just figures it out over time and then thanks me. Now, as much as I hate handling these calls because it's just so mind-boggling and frustrating to me, I told him he can always call me if he ever needs tech support because he paid for my college to get a computer engineering degree. So he legit deserves... free unlimited tech support for life because of that. And there was another call a few days ago where he got a new doctor and the doctor wanted him to fill out like a 25-page form of all his medical history and stuff. While he was filling it out, he couldn't figure out how to send the form to his doctor. So he called me up. So Speaker 3 (2:57) do I hit the X and go to inbox? Yeah, you can Speaker 4 (3:07) send it to them in an email attachment. Speaker 3 (3:11) Okay, then I'm going to hit the X on this patient form. Speaker 4 (3:15) What patient form are you looking at? Speaker 3 (3:17) The one that they sent me. The one that you filled out? Yep. And it has all... Yeah. Now I went to my email. Speaker 4 (3:27) Does the patient form have all the stuff you typed into it? Speaker 3 (3:31) The one I typed into, yeah. Speaker 4 (3:33) Okay, so it's got your data on there, and when you hit exit, it asks you to save it? Stop, Speaker 3 (3:37) stop, stop. I just went to where I sent it to myself, and there's nothing on it. No, none of this works. Yeah, so I'm Speaker 8 (3:49) asking you if it saved it. So can you open the Speaker 4 (3:52) form again and see if your stuff is still there? Speaker 3 (3:55) No, it's all gone. How is it all gone? Oh, you've got to push save probably. All the stuff, you know? Speaker 4 (4:03) Yeah, that's one option. This call was particularly maddening, and he was so frustrated that he lost all this data from filling out a 25-page form. Speaker 3 (4:13) It doesn't say anywhere on here, save. I'm looking at the new form they sent me, all freaking 25 pages, and nowhere does it say save and send. Speaker 4 (4:23) Okay, you know, one option is just go down to their office and say, give me the form, I'll fill it out right here. Speaker 3 (4:29) I got to go get ink and I got to print that. I got to fill this out. I can't do an hour in Speaker 4 (4:35) the Speaker 3 (4:35) doctor's office. Speaker 4 (4:37) You got nothing else to do today. Speaker 3 (4:39) Prescription. When did you have surgery? Oh, my goodness. Oh, Speaker 4 (4:45) my gosh. Speaker 4 (4:47) should have called you before. As you can see, he's not very good at file management. And I thought I could fix it for him. So I started remotely trying to connect to his computer, his home PC, to troubleshoot this. But after like 10 minutes of trying to connect to his home computer, I finally asked him. Speaker 3 (5:05) Spotify, what item? Speaker 4 (5:07) No, you're not. Is this all on your iPad or is this on your home computer? Speaker 3 (5:11) No, this is on the iPad. Oh, I didn't know that. Speaker 4 (5:13) I thought I was connecting to your computer. That's why I was using the Speaker 3 (5:16) software. If Speaker 4 (5:18) I would have known this from the get-go, I would have been trying a whole different set of instructions. Oh, man. Okay. Speaker 3 (5:26) Big computer doesn't work. Speaker 4 (5:29) So now his big computer doesn't work? Like, now there's three problems that we're trying to fix here, right? A lost form, a printer that's out of ink or something like that. I don't even know what the problem is there. And now his main computer doesn't work? Anyway, for some reason, I couldn't even connect to his iPad remotely on this one. And I just couldn't help him find this form. I thought he might have saved it somewhere or there might be an old revision of it somewhere that we could rescue. But this was one that I could not fix. And he didn't figure it out on his own. So he hung up and drove to the doctor's office to fill out the form there. But what is the deal with this? Why does he struggle so much to adapt to the modern world like this? He's been using a computer every day of his life since the 90s, but his brain just can't keep up with the ever-changing aspect of it. Is it up to me to keep him afloat? Or is ignorance just no excuse anymore? These are true stories from the dark side of the internet. I'm Jack Recider. This is Darknet Diaries. Speaker 4 (6:52) This episode is sponsored by ThreatLocker. The weird part about modern cyber attacks is how normal they look. The attacker logs in from Chrome, uses PowerShell, runs a remote admin tool your IT team already trusts. There's no custom malware, no dramatic movie hacker moment, just normal tools used in the wrong way. That's part of why ThreatLocker exists. ThreatLocker helps organizations control what software can run, what it can do, and how systems communicate. If attackers get credentials or land on a machine, they'll have a much harder time moving through the environment because security teams are realizing something important. The problem isn't always unknown software anymore. Sometimes it's trusted software being used by the wrong person. If you want to see how ThreatLocker works, go to ThreatLocker.com slash Darknet and book a demo today. That's ThreatLocker.com slash Darknet to book a demo. Speaker 4 (7:50) This episode is sponsored by Doppel. Protecting yourself from attackers used to be as simple as deleting dodgy-looking emails. But with AI, the attack surface has outgrown the defense that legacy vendors provide. Doppel was founded in 2022 to give companies back control. Doppel is an AI-native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception and provides digital risk protections across every channel. It even delivers agentic email security that doesn't just score the inbox, but takes down the attack infrastructure behind the message. Those dodgy-looking emails have been replaced by bespoke and personalized texts, URLs, ads, and even social media connections. But Doppel can then turn these attacks your business receives to inform campaigns and security awareness training for your employees so they know what to look out for. Doppel, outpacing what's next in social engineering. Learn more at doppel.com. That's spelled D-O-P-P-E-L. Doppel.com. Speaker 4 (8:52) Okay, this is the epic story of those penetration testers who broke into the Iowa County Courthouse. I first ran this episode back in February 2020. It's episode 59, but I'm revisiting it today for two reasons. First, it's just a really good story. And if you haven't heard it, you definitely should be listening to it. And if you already heard it, you should listen to it again because it's that good. But second, a lot has happened since I posted that episode originally. And I caught up with the two people involved at DEF CON last month to give us a full update on what has happened since. And it's crazy. So first, I'm going to replay the original episode right now. And then in the last 20 minutes or so of this episode, we are going to get an update to this story. And it's really interesting. So stick around to the end. All right, let's go. All right, so let's jump in and meet our guests for this episode. Speaker 8 (9:41) My name is Justin Nguyen. I'm a senior security consultant with Coal Fire Systems. I am an offensive penetration tester who specializes in physical security, which often entails social engineering, physical exploits to gain access to facilities. Speaker 6 (9:54) Yeah, my name is Gary DiMacherio, and pretty much mirror everything Justin said, except I'm a managing senior, and I run the Bellevue office in Washington. Speaker 4 (10:04) I know they said it quickly, but the important part here is that they're both penetration testers. I've been at Coal Fire for six years, and I probably did the military another Speaker 6 (10:12) three. So I've got about nine years of experience on physical pen testing. Speaker 8 (10:16) Right. And I've been with Coal Fire for over four years, so physical penetration testing for over four years. And Speaker 4 (10:22) they've come here today to share some penetration testing stories with us. Now, even though these two live on opposite corners of the U.S., one Florida, one Washington state, They team up together on assignments all over the U.S. And the assignment is typically like this. A company will call up CoalFire, the company that Justin and Gary work for, and ask for a security assessment. And they might want someone to test their website to see if it's secure, or do a password assessment to see how strong the user's passwords in the network are, or conduct some compliance checks. And this is all to make the company more secure. The Iowa Judicial Branch is the State Department of Iowa. It's a government facility. And specifically, they handle the court cases and such within the state of Iowa. So it was the Iowa Judicial Branch that called up Coal Fire and asked the company to come and do a penetration test on the courthouses themselves. It was a full-scope red Speaker 8 (11:19) team penetration test, so it included things like... External pen testing, web application testing, internal testing, which was to be done after we'd gone on site to see if we could gain access into their internal network. And kind of like do like a real life scenario, like can you gain access to our facilities? Can you plug in a, what we call a drone, a remote device to be able to access that network later once we're off site and then conduct the internal network penetration test from there. And throughout the whole time, we're contacting with the guys at... IowaCourts.gov. Speaker 4 (11:50) Justin and Gary get assigned to conduct the physical penetration test on the courthouses together. They've been working together for four years on doing physical penetration tests just like this. So they're used to each other and do good work together. And actually, I have a copy of the rules of engagement here in front of me. So let's see. Okay, yeah. So this is for the Iowa Judicial Branch. And they're specifically asking for a physical penetration test at five locations. There's a judicial branch, the Polk County Courthouse, the Dallas County Courthouse, a juvenile justice center, and the criminal court area. Five locations, and the window to test the security on these buildings is between Sunday, September 8th, and Friday, September 13th. So they had a week to do this assessment, and this was last year, in 2019. The rules of engagement list out a ton of things. Do they have permission to tailgate behind someone to get in? Yes. Do they have permission to dig in the dumpsters? Yes. Does Coal Fire have permission to use lockpicks to get in? Yes. Does Coal Fire have permission to plug USB drives into computers that they get access to? Yes. Does Coal Fire have permission to disable alarms? No. And the goal here looks like they're trying to get into the building, plant rogue devices, look around to see if there's any security problems like unlocked computers, passwords written down, that kind of thing. So, okay, the rules of engagement seem pretty clear. So that gets filled out before we're on the call. And then as Speaker 8 (13:12) we're going through that with the client, the project manager is taking notes in there. So you may see things like, okay, at the JD building, we discussed with the client, floors three and four are specifically off limits during daytime hours because there was going to be the Supreme Court convening and they obviously didn't want us interrupting that. So part of that, we're discussing with the client on the phone. Yeah, during the daytime, do not touch, do not go on floors three and four. And then we enumerate with them. We're like, okay, well, like, what if we're in there after hours? Like, what do you want to see from there? Is that open access? And like, yeah, that'd be more acceptable. But you know what? Let's play it safe and just show us to see if you can reach the doors that enter on that floor. So the contract will say something like, okay, JB building floors Speaker 7 (13:54) three and four are off limits. And like, you see how big those fields are in that table. So it's Speaker 8 (13:59) really like the bare information that the project manager wants in there. And we have a good understanding with the client of what they're actually looking for. Speaker 4 (14:08) So actually, this rules of engagement document I'm looking at is 28 pages long. And this field he's talking about is super small. All these things you cover on the call in great detail only get jotted down with a couple words. It's not Speaker 5 (14:21) fully documented Speaker 6 (14:22) in the scope of work or rules of engagement. And these conversations are so granular. If we were to take and actually take the conversation that we had on the phone. and write it out and put it in a contract, the contract would be Speaker 8 (14:36) 100 Speaker 6 (14:37) pages long. The amount of discussion that we have on what it is exactly they want us to do, it would be unfeasible as far as rules of engagement would be concerned. And so, again, that's why we have phone calls. That's exactly why we have. So we can say, this is what we understand, what exactly you guys want, and then we're all on the same page when we show up. Speaker 8 (15:00) Like, we're going to be there at night. And the client was like, yes, we want you to focus on after hours testing. So a lot of that stuff, unfortunately, which we never would have predicted or seen coming at us, we didn't capture in that document, which would have been great if we did. The Speaker 4 (15:15) Iowa Judicial Branch has actually worked with Coal Fire before to do other penetration tests. So everyone seems to agree on what should be conducted and what's expected here. And an agreement was made. And they create what's called a get out of jail free card. This is a slip of paper that lists all the people who hired Coal Fire to do this penetration test. This is their information security officer, their chief information officer, and the infrastructure manager. These are three people who worked in Iowa's judicial branch who contracted Coal Fire to do these tests. And this get out of jail free card has their names and phone numbers listed with their signatures. So if these guys get... caught, they can ultimately show this to get out of any real trouble. Speaker 8 (15:59) We touched down Sunday night. We entered in a facility. So I don't want to provide too many details that haven't been already disclosed. All Speaker 4 (16:07) right, fine. Unfortunately, we're not going to be able to go into every detail of what happened because I don't want to expose any actual vulnerabilities over there at the Iowa County courthouses. But let me give you an idea of what they're capable of. Speaker 4 (16:20) First of all, these guys mentioned that they sometimes use an under the door tool. So let me tell you what this tool does. It almost looks like a bent fishing rod. It's long, four feet, metal rod, and it has a string on the end. And this is for doors that have a handle that when you push down, it opens a door. So you try to slide this tool under the door. And then you pull it up using that string to get it close to the handle. You try to hook it onto the handle from on the other side of the door. And when you do get it hooked on there, you pull down with both the string and the rod. And it pulls the handle down and it opens the door. It's actually pretty simple. And on top of this, Gary is also really good at lockpicking. So he'll certainly have these in his pockets and ready to use them whenever he needs to. But with lockpicking, it might take you a while. Maybe 10 minutes, maybe 30 minutes to get a lock open. So it just takes more skill Speaker 6 (17:15) and time. If you're talking about my favorite, because I find this a lot in commercial buildings, is going to be crash bar doors, right? Either the ones that come down like the old high school gym type doors or the ones that you just push and go into the door itself. A Speaker 8 (17:32) Von Duprin. Speaker 6 (17:32) Thank you. They'll have the latch on the inside of the door. So you can't really use an under the door tool. They make some tools if you have doors, double doors that come together without the, what's Speaker 8 (17:45) it Speaker 6 (17:45) called in the middle there? Speaker 8 (17:46) The mullion. Speaker 6 (17:47) The mullion, is that what it is? Speaker 8 (17:49) Yeah, there's another term for it too. But there's a bar that runs in between the doors where you're not supposed to be able to insert tools. So you'll Speaker 6 (17:55) see a lot of those doors that don't have that bar that separates the doors. Those are really easy to get into. You just, you stick a tool inside, you turn it to the left or right, and then you pull and it opens the door. What we've come up with that we like to use that's absolutely my favorite tool that is literally in my backpack right now is a cutting board. It's a really, really thin plastic cutting board that I bought from Amazon, and I cut a notch in this cutting board. And so for crash bar doors, especially the single ones where you can't see anything, you stick it through the door, on the edge of the door, and then... And once you feed it through the door, you pull it down until that cutting board rests on top of the latch. And then you'll apply pressure down on that latch and you start pulling the cutting board toward you outward from the door until that notch that you cut falls on top of the latch. So now what you've got is you've got the back half of that cutting board on the other side of the latch on the inside of the door and you pull. And if that latch doesn't have the dead latch, latching it properly, you will open the door every time. Speaker 8 (19:01) So typically when we're talking about door bypasses, we're inserting a tool through whatever method that we can, whether it's an interleaving double door system so you can go in between the doors, or if there's a gap underneath the door, insert a tool there and start manipulating some mechanisms on the other side of the door, whether that's the Von Duprin crash bar or the latching mechanism itself or some peripherals like a requested exit sensor. Speaker 6 (19:25) But I can... what, 80 % if you had to put a number on it, 80 % of doors can be bypassed by bypassing the latch. Speaker 4 (19:33) Right. Just manipulating the latch itself, you can get into 80 % of facilities. And just coincidentally, can you tell us where you guys are or what you guys are doing this week? This week, we're doing three two Speaker 8 (19:45) -day courses comprised of physical access control systems, alarm bypass techniques. and then safe manipulation. So really kind of an action-packed week for us. That's all the kind of juicy James Bond style stuff. So Speaker 4 (19:57) you can imagine what kind of bag of tools these guys have to break into buildings to carry out assessments like this, right? I mean, they've got so many things, I'm surprised the TSA even allowed them on the plane. So even though they can't get into specifics about what tricks they use to bypass the doors of these buildings. you can take a pretty good guess that they've got many options they can use to get into each door that they've run into. Speaker 8 (20:19) So it's pretty much we walked up, assessed the perimeter and kind of matched up with what we were seeing on Google Maps, things like that, and gained entry to that first facility on Sunday night to Monday morning. Speaker 6 (20:30) When we get into a place, it also depends on who is attacking, right? So if Justin is attacking, for instance, and he gets into the door and he's able to get in really, really quick, There's a certain, like, you know, like, he's your teammate. So you're proud. You're like, wow, dude, that was really fast. Like, that was really, really fast. Justin and I have been working together since he's been here. So you get to see this progression of somebody when he's on his first red team or second red team, I think it was, you know, with the guy. And then when he's on his, you know, 15th red team, and you're like, dude, you're getting really, really, really good at this. But you get to see that progression. So it's a lot more personal, if you will, when you're... when you're on a red team with somebody that you've been working with for years and years and years. I was Speaker 8 (21:13) going to say, I'm tearing up over here because Gary, honestly, like I do need to take a moment to thank him, like taught me so much of what I know. Like, yeah, of course, like Deviant and like some huge stars in the industry that you can learn so much by watching YouTube and like learn how to assess security of your facilities. But Gary was like the first guy who handed me the under the door tool and taught me how to use this one. I didn't even know which end of the stick to be holding onto, which is a very common thing when people are given the under the door tool. Speaker 4 (21:39) They get in, they look around for ways to plug in a drone and to take any photos of security problems that they want to put in their report. They even found the desk of the person who hired them for this engagement. So they leave a little present on his desk to prove that they got in overnight and got access to his desk. Speaker 8 (21:56) But we had gained access and we left a calling card. I just left the business card on where the point of contact is to the point where the next day he had emailed me and said, I guess I do. Congratulations. I'm going back. forth over email. I'm like, yeah, I mean, we found some really severe vulnerabilities that, you know, minor fixes that you guys can use to dramatically improve the security of this facility. So going back and forth through things like that. So already in contact with the client, going through things like that. And then, yeah, Tuesday rolls around. Speaker 4 (22:27) So it's Tuesday night. After the courthouse has closed for the day, they get up to the building and see it has two sets of locked doors to get into. We Speaker 6 (22:36) make it to the first door really easy. And then the second door, we could have used the same attack, but we were trying other things. And we weren't having a lot of luck with the other things, but we didn't really want to try the first attack because we wanted to see if we could use different techniques to get in, right? We found other areas that we could attack. So we went around a different area and we were working on, Justin was working on one door and I was working on another. I don't know, did you ever get that door open? Speaker 8 (23:00) Pick the lock, like all sorts of, yeah, like each way and like, no, something else was going on. There's a secondary lashing that Speaker 6 (23:07) we couldn't see or something. Speaker 6 (23:10) I ended up picking two doors in a row to a courtroom, and then we ended up making it, making in, and then we ended up, we ended up getting in. We saw the security, the security, security Speaker 4 (23:23) cameras. Now, when they say they found the security cameras, what they mean is they found the room that you can sit in to watch all the security cameras and what's going on in the whole building. Guard desk. It wasn't really a room. It's just Speaker 6 (23:34) they had security cameras at the guard desk, which was right. which was actually the sheriff's desk during the day that sits there. So they've got a sheriff that, or a deputy sheriff, that monitor that's there on duty for the courthouse that sits in this, it's almost like a front Speaker 8 (23:53) desk Speaker 6 (23:53) type thing where a receptionist would sit and accompany. So the deputy sheriff sits there and has access to all these different cameras which show the courtrooms or office areas. And so at night, when you've got your security guard there who isn't a deputy sheriff, they will also use those same cameras that the deputy sheriff always sits in to check the different offices Speaker 4 (24:15) to make sure that nobody's in there, the lights aren't on. So one of the first things they do is look at all the cameras to see if anyone was there. And they did, in fact, see someone in the building. Somebody was making their rounds, checking on the place. It looked like a security guard. They made sure to keep... a close eye on him while sneaking around this building. And at the same time, they took careful notes on what blind spots there were with the security cameras.