Live data from Hacker News

WiFi deauthentication attacks and home security

mjg59.dreamwidth.org

71–80 of 232 posts

Re: WiFi deauthentication attacks and home security

#71
post #39

Earlier quoted context omitted.

Why are people actually doing this on a wide scale?

I can think of 2 potential reasons but neither seems satisfying. The first would be state agencies testing attack vectors in real life. Would suck to send out an agent who commits their crime 100% flawlessly only for them to get caught by some unsecured doorbell or other random internet device. The second would be attempts to force increases in security through intentional hacks and sabotage. Although if someone can…

More likely bored teenagers discovering Kali than state agencies.

Rehearsals are done in controlled manner.

Re: WiFi deauthentication attacks and home security

#72
I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to send RTC packets and transmitting over them. Businesses close to it have no wifi. As you move away, wifi starts to improve. And no, it's not flooded as there is plenty of open air time not being used by the many devices there.

Steps taken: - Have talked to multiple business owners nearby and they can't figure out why their wifi won't work. - Comcast Business is worthless and weeks of calls by business owners and multiple tickets have led to nothing. - Have talked to the mayor of the town and their tech guy agrees something is wrong. - A "smart guy" that works for the government doing security did a quick scan and said it was because one wifi was on a channel between 1 and 6 so the overlap was causing the problem... that wasn't it. - Have approached university researchers to see if their students would be interested in looking at/for it. No response. - Have walked with laptop watching signal strength and know roughly which building it is coming from.

From what I understand, there is NOTHING one can do to attack it, other than sending massive RF interference, which would be a crime in itself.

How the heck does one get rid of this thing? Any suggestions?

Re: WiFi deauthentication attacks and home security

#73
post #66

Seems widespread; sad state of affairs... wonder how many locations suffer from (mis)configured APs battling each other.. https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig... "In addition to monitoring rogue APs, you can actively prevent your users from connecting to them. When suppression is activated against an AP, the FortiGate WiFi controller sends deauthentication messages to the rogue AP’s clients, p…

Rogue APs are generally defined as APs that you don't manage but have been connected to your wired network. Obviously this could be a significant security risk. I don't think they're sending deauth messages to every client/AP they see.

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortig...

Re: WiFi deauthentication attacks and home security

#74
post #60

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

That’s really interesting. Did you ever publish a report on this? If you feel like it, please post a link. (Norwegian is fine.)

No report, been thinking about it.

Would then drive around with 4 devices collecting data on different channels simultaneously. With GPS and signal-strength you can calculate how often this is.

Been walking around in my neighborhood with a GPS-logger and a simpler setup (WiFi hopping to gather data). Found 4 houses where these signals come from in a 300m radius.

Re: WiFi deauthentication attacks and home security

#75

I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…

Did you talk to the FCC?

Eg. https://www.fastcompany.com/3050060/company-that-blocked-wi-...

Re: WiFi deauthentication attacks and home security

#76

I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…

Use the guide I posted here to locate the device responsible using the signal-strength in Wireshark (search for NKOM).

Could be you can break the device by flooding it with fake SSID, using AirPlay-ng. A bit more technical but should be possible with every Mac or most WIFi dongles that support monitor-mode (could be illegal).

Re: WiFi deauthentication attacks and home security

#77
post #64

Earlier quoted context omitted.

I don't get the point of this post - are you saying deauth attacks are fine and everyone should just abandon Wi-Fi?

I am saying not everyone is affected, only those who solely rely on wifi. Others have realized that a shared medium with questionable security is inherently unreliable and have other options at their disposal.

Let me guess, you can also build a better dropbox with curlftpfs

Re: WiFi deauthentication attacks and home security

#78

I need help with something much more nefarious. I know of a location in a downtown area where someone has set up a malicious wifi "thing". I'm guessing the PWNAGOTCHI since the device changes patterns and comes and goes? It has learned how to use deauth to do man-in-the-middle attacks and absolutely closed down wifi in a half block radius by sending RTC packets of 12 second wait times and also waiting for others to s…

Confused, it seems you realize this might be a crime, but you've talked to everyone except the most obvious point of contact—law enforcement. Is there a reason that's not an option?

Re: WiFi deauthentication attacks and home security

#79

In Norway/Oslo there is a lot of people with equipment sending deauthentication packages, jamming neighboring equipment, and one of the main reason for slow Internet (lot of jitter). Did some research on this together with The Norwegian Communications Authority (NKOM) to isolate the problem. If you want to check for yourself if someone close by i sending deauthentication packages; fire up a Mac and: 1. Open Wi-Fi-dia…

Would you have any recommendation for those of us without a Mac?

Re: WiFi deauthentication attacks and home security

#80
post #39

Earlier quoted context omitted.

Why are people actually doing this on a wide scale?

I can think of 2 potential reasons but neither seems satisfying. The first would be state agencies testing attack vectors in real life. Would suck to send out an agent who commits their crime 100% flawlessly only for them to get caught by some unsecured doorbell or other random internet device. The second would be attempts to force increases in security through intentional hacks and sabotage. Although if someone can…

Before going all conspiracy, most likely it's due to a poorly-implemented WiFi-enabled widget.

There are devices that act as AP like the chromecast. This is then used by a smartphone app to connect and configure the device. I don't think the chromecast in particular is the culprit but I wouldn't be surprised a similar device was sending deauth packets due to an implementation mistake.

Post reply on HN