@IceSolst I think you’re right, but I’ve learned that when something isn’t your full-time job, you can do it for the simplest reason possible: because it’s fun. And that’s probably the main distinction as to why professionals aren’t watching YouTube’s.
ran a Raspberry Pi at DEF CON 34 broadcasting an open WiFi network called “How u SSID’n ;)” with a captive-portal guestbook, plus a passive RF sensor.
2.2M probe requests. 13.7M Bluetooth adverts. 3,681 unique SSIDs.
Exactly one human signed the guestbook. 🧵
1/ #defcon34
9/
What killed it: the Pi rebooted 36 times, twice within 2 seconds of each other. Battery was still at 47%.
Loose USB-C in a moving bag. Every reboot restarted the pcap ring and overwrote it — which is how 4 days of deployment became 19 minutes of usable capture.
8/
Also captured: 3 Meshtastic nodes, a RadiaCode Geiger counter, a Nintendo 3DS and a genre of SSID I’m calling hacker affirmations —
Born To PCAP Forced To Socialize
I Came I Saw I Got Root Access
Coffee First, Then We Hack Stuff
7/
Two ESP32s with 13:37 baked into their MACs beacon-spamming fake OPEN “DefCon-WPA3” networks — while 283 devices were actively probing for the real one
Zero probe responses though, so: beacon spam, not a KARMA evil twin.
6/
Best find: someone at the Wall of Sheep apparently couldn’t get their capture working and started beaconing bug reports AS SSIDs.
NO CLIENT TX IN TAP -CrazyWind
RX WORKS TX DOES NOT -CrazyWind
DefCon NOC. Plz FIX -CrazyWind
UNABLE TO CATCH SHEEP -CrazyWind
5/
Plus travel history: hotels in Hanoi, Brussels airport lounges, Mumbai airport, Air Canada, United, Delta, Marriott, Hilton.
And credentials, because someone was broadcasting an SSID literally named Password: 12345678.
20 devices were probing for it.
4/
The real payload was passive. Phones broadcast the names of networks they’ve joined before, and people were leaking their whole résumé:
CalOES_Mobile (California emergency services)
MOTOTRBO / REMOTE MGT (public-safety radio)
Government LAN
SXM_Talent
FAAGuest
2/
The message:
“I’ve been here!”
— “Cause the fucking open WiFi auxyyx!!!!”
10:32 PM. At a hacker con, ~6 strangers’ devices touched an unknown open AP all day. Nearly all of that was automatic OS captive-portal checks, not people. Turns out this crowd knows better.
I just saw this news. Apparently during DEF CON, someone in Vegas made a fake hotel called Pallete with a website and all. And listed it in booking dot com, expedia, travelocity etc. The hotel didn't exist! People reserved rooms and paid for it!
Strangely if you go to the address, it takes you to Oyo's hotel. And the pics from Pallette's supposed front desk and Oyo's look exactly the same.
What kind of hackery shenanigans is this??
@JackRhysider So. You look like a badass both in person and through the badge cam. My badge did quite well on badge tinder. lol. It was so nice meeting you again.