6 ms·
I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNA
by cwingrav 7y ago
I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to send RTC packets and transmitting over them. Businesses close to it have no wifi. As you move away, wifi starts to improve. And no, it's not flooded as there is plenty of open air time not being used by the many devices there.
Steps taken:
- Have talked to multiple business owners nearby and they can't figure out why their wifi won't work.
- Comcast Business is worthless and weeks of calls by business owners and multiple tickets have led to nothing.
- Have talked to the mayor of the town and their tech guy agrees something is wrong.
- A "smart guy" that works for the government doing security did a quick scan and said it was because one wifi was on a channel between 1 and 6 so the overlap was causing the problem... that wasn't it.
- Have approached university researchers to see if their students would be interested in looking at/for it. No response.
- Have walked with laptop watching signal strength and know roughly which building it is coming from.
From what I understand, there is NOTHING one can do to attack it, other than sending massive RF interference, which would be a crime in itself.
How the heck does one get rid of this thing? Any suggestions?
- crazysim 7y agoDid you talk to the FCC? Eg. https://www.fastcompany.com/3050060/company-that-blocked-wi-fi-hotspots-at-conventions-must-pay-750000-fine-to-fcc https://www.fastcompany.com/3050060/company-that-blocked-wi-...
- imglorp 7y agoMy thought also. It might be a hotel or conference or somewhere the host can charge for wifi. That should narrow down the culprits.
- cwingrav 7y agoYes, I told the people about this precedent. And the FCC. Not really my place to get them to call. I think people don't believe a technical glitch is a real world problem. I've tried to tell them that it is definitely impacting their business (restaurants and cafes) and so there is in addition, a monetary impact, just as if someone was causing damage to their business that drove away customers.
- gsail11 7y agoActually, numerous studies have shown that restaurants that offer wifi spend a surprising amount of time assisting customers with logging in, and the average sit time skyrockets when people are checking email instead of consulting the menu. If these aren't designated cyber cafes we're talking about, it could be good for business. On the other hand, the situation described here would drive me crazy and I would be fantasizing about picking locks and climbing on rooftops trying to find the evil little device.
- punnerud 7y agoUse the guide I posted here to locate the device responsible using the signal-strength in Wireshark (search for NKOM). Could be you can break the device by flooding it with fake SSID, using AirPlay-ng. A bit more technical but should be possible with every Mac or most WIFi dongles that support monitor-mode (could be illegal).
- cwingrav 7y agoI did follow it and found roughly where it is. But, have not talked to that landlord. It is a 3 story building with a handful of apartments in an old stone and brick building locked at the ground floor (i.e. refection is a problem but I imagine signal strength outside the door would be a good indicator once inside). Not sure about breaking the device by flooding with SSIDs? Sorry, not my area here. From what I know, it isn't on any network (it does appear to have a network with an SSID though), but it is attacking up and down all nearby devices regardless of channel or SSID.
- clopez 7y ago"Flooding with SSIDs" means generating lots of fake SSIDs each second to trick that device into attacking those fake SSIDs and keep it busy. Keept it genrating even more (use several wifi adapters) until the other device goes crazy. You can use some of the tools (like aireplay) from the aircrack-ng suite for generating fake SSIDs
- rsync 7y ago"I did follow it and found roughly where it is. But, have not talked to that landlord. It is a 3 story building with a handful of apartments in an old stone and brick building locked at the ground floor (i.e. refection is a problem but I imagine signal strength outside the door would be a good indicator once inside)." Have you considered that what you are seeing is unintentional ? I myself have set up many different (RX only!) experiments in GNU Radio, etc., and had to leave them sit for weeks at a time while I was busy with actual work. Maybe someone was tinkering/playing/experimenting and just left it on ? I would suggest putting up a polite, but loud and eye-catching one page sign at the entrance to this building alerting someone that they are dramatically impacting their neighbors.
- mehrdadn 7y agoConfused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?
- claudeganon 7y agoContacting the police about any computer-related crime is just as (if not more) likely to land you in their sights as it is to resolve the problem. Cops in the US routinely pin crimes on people to close cases and juke their stats.
- deleted 7y ago[deleted]
- punnerud 7y agoIn Norway I did that but the similarity to FCC could only look at signal strengths and radio spectrum (not data), it was the equivalent to NSA that had the power to look into network traffic.
- cwingrav 7y agoAgreed. But evidence? I've tried to convince the businesses to talk to the police. But, what they heck do the police/businesses do? How do you prove that there is a crime? They probably would believe me and would probably knock on doors and probably get a warrent. Then what? I'm not a professional cyber security person so how do I prove that device if found is causing damage? Also, the device is intermittent. I can collect traces, but who do I send them to?
- deleted 7y ago[deleted]
- pnutjam 7y agoI called the police once when I noticed a wifi AP that was MiTM'ing traffic at the local Kroger. They sent someone out and said it was a misconfigured system in the Deli. Guy was real nice and seemed to understand what I was worried about.
- noonespecial 7y agoFind a ham. We go nuts on people polluting the airwaves. Even wifi. Most hams will know exactly how to help.
- Avamander 7y agoTurn on protected management frames on the equipment, should make it at least more difficult to deauth.
- rsync 7y agoContact your local HAM group. They do this kind of thing - it's called a "fox hunt".