5 ms·
Upside-Down-Ternet (2006)
- avmich 3y agoIn places where I live it's considered polite to keep WiFi open for somebody who may occasionally be without access. You know, neighborly thing to do, like cleaning snow from a common driveway in winter time.
- dang 3y agoRelated: Upside-Down-Ternet (2006) - https://news.ycombinator.com/item?id=22585115 https://news.ycombinator.com/item?id=22585115 - March 2020 (17 comments) Upside-Down-Ternet (2006) - https://news.ycombinator.com/item?id=15767642 https://news.ycombinator.com/item?id=15767642 - Nov 2017 (1 comment) How to prevent your neighbors from stealing your wifi - https://news.ycombinator.com/item?id=5941300 https://news.ycombinator.com/item?id=5941300 - June 2013 (4 comments) Baffle WiFi Leeches With An Upside-Down-Ternet - https://news.ycombinator.com/item?id=337638 https://news.ycombinator.com/item?id=337638 - Oct 2008 (3 comments) How to Screw With People Who Try to Steal Your Wireless - https://news.ycombinator.com/item?id=116728 https://news.ycombinator.com/item?id=116728 - Feb 2008 (1 comment)
- userbinator 3y agoInfinite fun to be had with a MITM proxy... less maliciously, it reminds me of the "mobile proxies" that were common in the 2000s which would resample images dynamically to save bandwidth --- back then, cellular data was both slow and extremely expensive.
- Hikikomori 3y agoDid this in class many years ago, but with arp poisoning instead. Also dumped images from people's webtraffic and showed them on the projector. Didn't take long until lemonparty was shown to everyone.
- mcpackieh 3y agoReminds me of "News tweak", a MITM proxy meant to run on public wifi that would rewrite news headlines. https://news.ycombinator.com/item?id=2598843 https://news.ycombinator.com/item?id=2598843
- geocrasher 3y agoThis came to mind over the weekend as I need to figure out a way to do a very specific type of content filtering for a very specific reason in a very specific setting. Essentially, I need to filter out any content with certain words. Not just porn filtering but a specific type of content. A man in the middle attack is the only way to do it, but since it is legitimate need and legitimate setting, I figure that everything will have to be proxied somehow but I'm not sure how to go about breaking HTTPS and then giving it back to the browser without making everything go haywire. If anybody has suggestions on the project it might be able to be used to do this, I would be grateful.
- shabble 3y agomitmproxy[1] in transparent mode, with a self-signed root cert added to whatever trust stores on devices/browsers/OSes you need to intercept, is where I'd start. I'm not sure how well that copes with modern security features like cert pinning, but it's closest I can think of. [1] https://docs.mitmproxy.org/stable/concepts-modes/#transparent-proxy https://docs.mitmproxy.org/stable/concepts-modes/#transparen...
- WirelessGigabit 3y agomitm-proxy in WireGuard mode is friggin' amazing. I permanently host it to spy on traffic. Now, I did have to set up a root CA on my iPhone before I'm allowed to spy on traffic. But, like you said, cert pinning requires a hack. On Android I use Frida for it. On iOS, I use ... nothing, as I haven't found a good way around it. Actually insane that I am not allowed to look at the traffic that goes over my internet connection...
- geocrasher 3y agoThank you very much, I'll be checking this out!
- Scoundreller 3y agoI've always thought of running a public wifi access point, but all traffic would be tunnelled through TOR to keep me pretty safe. I know a lot of sites break themselves over TOR, but I've always wondered just how much would break or still work, e.g. mobile phone apps. Would iMessage work? WhatsApp? Youtube? Uber? How about a TOR app? Can you run TOR over TOR?
- mhils 3y agoTIL this goes back to 2006, how cool! We nowadays have a much simpler version as a mitmproxy example: https://github.com/mitmproxy/mitmproxy/blob/main/examples/addons/internet-in-mirror.py https://github.com/mitmproxy/mitmproxy/blob/main/examples/ad.... Although it obviously does not work as well anymore with everything being HTTPS nowadays (unless you trust the cert of course). :)