[00:01.180 --> 00:04.300] So, just kind of to give you all a good structure of the talk. [00:04.700 --> 00:05.780] A little introduction. [00:05.780 --> 00:10.520] We're going to talk about how Wi-Fi works from a radio perspective. [00:11.080 --> 00:15.080] Actually, how many hams are there in the audience? [00:16.360 --> 00:20.260] Higher than the normal conference percentage. [00:20.660 --> 00:20.960] That's good. [00:22.980 --> 00:26.220] So, we're going to talk about things from a radio perspective a little bit. [00:26.660 --> 00:30.520] Talk about Wi-Fi monitor mode, which is a particular mode of Wi-Fi. [00:31.490 --> 00:34.440] And then we're going to talk about mapping and tracking and some takeaways. [00:36.560 --> 00:41.860] So, obviously, in 2024, it's almost becoming like 1984 again. [00:41.860 --> 00:52.240] And there's some, like, wild stuff going on, obviously, with privatized surveillance and us helping surveil ourselves. [00:52.600 --> 00:54.980] It's good to be aware of what's going on. [00:55.160 --> 01:00.400] And just, you know, obviously, there's a trade-off for convenience and all of that. [01:00.520 --> 01:07.740] But, you know, obviously, the radio, Wi-Fi is used for more and more stuff, right? [01:07.920 --> 01:11.720] I mean, temperature controls, thermometers. [01:12.660 --> 01:19.800] I think there was news, right, in California of the government changing people's thermometers or something like that recently, right? [01:21.080 --> 01:22.860] Cameras, watching all the time. [01:24.180 --> 01:26.200] Obviously, this stuff is pertinent today. [01:28.400 --> 01:32.300] Today, we're going to be, there's a lot of venturing stuff in Wi-Fi. [01:32.640 --> 01:37.200] I mean, there's, you know, you got HackRF stuff down at the physical layer. [01:37.860 --> 01:46.040] This is the OSI model, you know, kind of a conceptual way to think about networking protocols for anyone who's not familiar. [01:47.260 --> 01:51.860] You know, at the high level, it's kind of like, you know, you've got, like, website stuff. [01:51.920 --> 01:56.180] And then further down, you've got TCP IP at the transport packet layer. [01:57.140 --> 02:04.780] We're going to be talking right here today at the layer 2, the data link layer. [02:05.320 --> 02:08.720] This would be 802.11 layer, basically. [02:09.640 --> 02:12.760] So below that is kind of like the physical modulation of bits. [02:12.760 --> 02:14.040] That's kind of the physical layer. [02:14.100 --> 02:19.340] So that's like if you're dealing with a HackRF and you're, like, modulating radio waves directly kind of stuff. [02:21.220 --> 02:27.280] If you're using, like, Wireshark and that kind of stuff, you're going to be more at, like, layer 3 or 4. [02:27.620 --> 02:31.380] You know, and if you're application hacking, you're, like, at layer 7 at the top. [02:31.560 --> 02:34.540] So this talk is about layer 2 specifically. [02:36.800 --> 02:42.080] And so TCP IP, right, you have IP addresses. [02:42.920 --> 02:47.860] So if you have an IP address, you're at the TCP IP layer. [02:49.040 --> 02:51.460] By the way, is the sound at a good level? [02:51.820 --> 02:53.580] Okay, I want to make sure I'm not over-modulating. [02:54.880 --> 03:01.980] So at the 802.11 OSI layer 2, we're talking about MAC addresses. [03:02.360 --> 03:08.040] And so that's kind of like the physical address for your network interface card. [03:10.600 --> 03:15.600] So, okay, really quick about how radio or how Wi-Fi works from a radio perspective. [03:15.600 --> 03:18.980] So I think most people are at least somewhat familiar. [03:20.340 --> 03:27.500] And it's always a balancing act with this kind of technical stuff because I don't want to bore people and I don't want to bypass people who don't have any familiarity. [03:27.800 --> 03:32.420] So forgive me if I sometimes seem slow or sometimes seem fast in explaining stuff. [03:32.560 --> 03:35.880] I'm just trying to kind of look out for everyone as much as possible. [03:37.720 --> 03:44.580] But, you know, conceptually you have different networks, you know, and they typically operate at different channels. [03:44.840 --> 03:47.580] A channel is just a designated frequency. [03:48.840 --> 03:56.260] You know, so there's the 2.4 gigahertz range and there's the 5 gigahertz range. [03:56.480 --> 04:05.540] So, you know, channel 11 in the 2.4 gigahertz range is centered around 2462 megahertz, for example. [04:06.300 --> 04:09.080] And so, but ultimately it's just radio waves. [04:09.200 --> 04:10.840] It's just radio frequencies. [04:11.860 --> 04:16.980] There's particular digital modulation on top of it, but it operates just like any other radio, right? [04:18.820 --> 04:23.920] And so the signals are not in wires. [04:23.920 --> 04:29.260] They're out in the airwaves and anyone within radio distance can receive them. [04:31.160 --> 04:32.420] So we're going to talk about that. [04:32.620 --> 04:37.300] So if you've ever done any like Wi-Fi hacking or radio hacking. [04:38.200 --> 04:38.600] Okay. [04:38.700 --> 04:43.180] Who, who, let me ask, who all here has used promiscuous mode? [04:43.360 --> 04:44.320] Can you raise your hands? [04:44.560 --> 04:44.700] Okay. [04:44.840 --> 04:44.940] Yeah. [04:45.080 --> 04:48.860] Again, more than most people, most conferences. [04:49.320 --> 04:49.940] So that's cool. [04:50.140 --> 04:54.220] So, you know, if you're using like Wireshark or something like that, you want to get into promiscuous mode. [04:54.220 --> 04:57.920] And that's basically where you tell your network interface card. [04:59.500 --> 05:05.960] If, you know, if it's, your card is whatever you want to say, let's just call it, call it FF for short. [05:06.120 --> 05:08.800] You know, it's my, my, my Mac address is FF. [05:09.920 --> 05:17.440] Typically your network interface card will just discard any packets that are not specifically addressed to your Mac address. [05:17.680 --> 05:18.640] Very simple way. [05:18.920 --> 05:19.760] Cut down on processing. [05:19.760 --> 05:31.960] But if you put your card into monitor or sorry, into promiscuous mode, it'll just accept packets, even if it's not just with the destination of your Mac address. [05:32.300 --> 05:39.920] And so that's a really good way of, if you're on a network, if you're on a network, it's a good way of seeing other traffic. [05:43.280 --> 05:46.740] So monitor mode in Wi-Fi is a little bit different. [05:46.980 --> 05:52.420] So monitor mode basically works if you are not connected to the network at all. [05:52.760 --> 05:53.360] Okay. [05:53.700 --> 06:00.460] So we're not authenticating with the SSID or with the access point or anything like that. [06:00.460 --> 06:07.020] We are just in pure radio receive all the packets mode. [06:07.520 --> 06:20.540] Um, now, uh, it's worth noting that, you know, so I, you can see here, there's stuff from channel, you know, there's a theoretical, uh, you know, Wi-Fi network, three, three theoretical Wi-Fi networks. [06:20.540 --> 06:24.180] One's on channel one, one's on channel six, one's on channel nine. [06:24.800 --> 06:33.880] Um, and they all have, you know, ultimately when you authenticate with an access control or with a router or whatever, you know, there's ultimately some encryption, encryption information that's shared. [06:34.520 --> 06:37.980] And at that point, all the traffic on the network is encrypted. [06:38.420 --> 06:45.640] And so one thing to be very clear of is when you're in monitor mode, all the traffic you're receiving is encrypted traffic. [06:45.640 --> 06:50.880] Okay, so you're losing out on some stuff you can potentially do. [06:52.280 --> 06:54.700] Also, just one other note with monitor mode. [06:56.240 --> 07:05.140] Just so you're understanding, you probably can't actually receive from three different channels simultaneously, right? [07:05.260 --> 07:07.940] Because they're actually on different frequencies. [07:08.300 --> 07:15.620] And so, like, you have to hop from channel to channel and frequency to frequency to kind of get everything. [07:15.640 --> 07:24.460] Of course, if you had, like, a large array of network interface cards, you know, and you have them all plugged in, it's theoretically possible to be receiving everything all the time. [07:26.620 --> 07:27.800] But what can you see? [07:27.900 --> 07:30.240] What can you see in Wi-Fi monitor mode? [07:32.060 --> 07:36.860] You can see the source MAC address, the destination MAC address. [07:37.640 --> 07:42.500] You can see the network that things are connected to, at least usually. [07:43.340 --> 07:48.940] You can see there's different frame types, you know, it's a data frame, or it's a main management or whatever. [07:49.500 --> 07:53.120] And like I said, the data is encrypted. [07:54.860 --> 08:06.220] You can also, in addition to this stuff we just said, you can also infer additional data that's not explicit, but it's kind of metadata that you get when you're receiving, such as the power level, right? [08:06.220 --> 08:19.140] If you're a Wi-Fi, if you've got your Wi-Fi adapter card, you can, you're, it's implicitly picking up, we received this packet at a negative 73 decibel power level or something like that. [08:19.320 --> 08:24.920] And so the power, obviously, is potentially a proxy for how close it is to you. [08:25.020 --> 08:26.980] So that can be interesting for fox hunting. [08:27.580 --> 08:33.500] For example, if you've got a directional antenna, and you just look for higher power, or you can track someone down pretty easily. [08:34.880 --> 08:36.560] The time, obviously. [08:36.920 --> 08:40.280] The manufacturer, actually, also is an interesting piece of data. [08:40.580 --> 08:48.940] The first three hexadecimal digits, I believe, of the MAC address is a organizationally unique identifier. [08:49.400 --> 08:53.960] So you can figure out who the manufacturer is. [08:54.080 --> 08:58.720] So you can see, are these, you know, Apple devices or whatever. [09:00.920 --> 09:05.320] And the, yeah, so I mentioned the network, the network that it's on. [09:06.320 --> 09:08.680] Not all frames have the network. [09:10.420 --> 09:18.240] But, and this is something where if you're only looking, if you're only capturing data and saying, from this frame alone, what can I, what can I look at? [09:18.300 --> 09:18.760] What can I infer? [09:19.260 --> 09:30.560] You can actually, if you take context and you're keeping track of who's talking to who, you can start to build graphs and infer the different connections. [09:30.940 --> 09:34.460] And so I want to talk about that a little bit here in a minute. [09:35.520 --> 09:36.380] Okay, so yeah. [09:36.520 --> 09:38.700] So what kind of stuff can you do with this data? [09:38.960 --> 09:44.160] I mean, so one thing, you can be alerted when security cameras notice activity. [09:45.220 --> 09:47.500] You can track the movements of people. [09:47.500 --> 09:49.940] You can see what devices are connected, et cetera. [09:50.640 --> 09:57.860] So there's this, so I created this tool, tool called Tracker Jacker some years ago. [09:58.040 --> 09:59.880] And just quick, interesting story. [10:00.020 --> 10:02.880] I'm not going to do a demo on this particular thing. [10:03.900 --> 10:07.920] But I had a security system, the Wink security system. [10:08.040 --> 10:09.640] I think they're maybe out now. [10:10.220 --> 10:15.660] If anyone, I had a Canary security camera. [10:17.240 --> 10:22.080] And so it was kind of, this was probably like five or six years, seven years ago. [10:22.320 --> 10:25.740] So it was kind of the beginnings of the home automation stuff. [10:25.920 --> 10:29.780] And, you know, things didn't talk, things still don't talk very well together, do they? [10:29.880 --> 10:32.720] But it was worse, I think, I think. [10:33.080 --> 10:36.120] So my Canary didn't talk to my security system. [10:36.920 --> 10:46.280] And so I basically just wanted it to be where if the security camera sees motion, the alarms on the security system go off. [10:47.740 --> 10:52.100] So I was just going through different ways, like how can I make those things talk to each other? [10:52.340 --> 10:57.860] And, you know, it's like, ah, I could try to put my own, you know, I could try to root the device. [10:58.100 --> 10:59.340] No, that's going to be too, whatever. [10:59.340 --> 11:03.120] But anyway, after thinking about it, I realized, well, it's an IP-based camera. [11:04.780 --> 11:07.720] So it's going to have to upload any video it takes. [11:07.720 --> 11:10.800] It's going to want to upload to the cloud ASAP, right? [11:10.860 --> 11:16.340] If you've got an intruder situation and they break in, they see the security camera, they're going to smash it. [11:16.460 --> 11:18.860] So you've got to get the video uploaded ASAP. [11:19.600 --> 11:38.180] So I realized I can just, if I just watch a particular MAC address, the MAC address of the Canary security camera, I can basically just set a threshold and say, you know, if it uploads more than a half a megabyte of data, like in a 10-second window, let's assume it's uploading video. [11:39.160 --> 11:40.020] And it worked. [11:40.140 --> 11:40.840] It worked very well. [11:40.980 --> 11:46.660] It was, you know, but anyway, the weird thing, so I built this program called Tracker Jacker. [11:46.660 --> 11:48.960] We'll do a demo and look at it here in a minute. [11:49.720 --> 11:55.300] But just to finish off the story, the origin story of it, you know, I was testing this thing out. [11:55.580 --> 12:00.860] And, you know, ultimately the Canary has kind of like an arm-disarm setting, right? [12:01.420 --> 12:04.580] And anyway, you know, I had it disarmed and I walked into the kitchen. [12:04.960 --> 12:08.020] And then I hear an alert go off on my computer when it was disarmed. [12:09.160 --> 12:12.800] And that was like, huh, is it a bug? [12:12.800 --> 12:14.160] Oh, tested it. [12:14.260 --> 12:22.580] No, no, the Canary appeared to be uploading video both when it was armed and when it was disarmed. [12:23.900 --> 12:25.040] That's not cool. [12:27.880 --> 12:29.740] I ended up looking into it. [12:29.960 --> 12:38.960] There ended up being a setting hidden very deep in the configuration settings of the Canary to say, only upload video when it's armed. [12:41.720 --> 12:43.460] So I don't know if that's still the case. [12:43.820 --> 12:46.740] My Canary is kind of like in a box in a closet at this point. [12:47.640 --> 13:00.020] But if anyone has a Canary, and I was talking to someone about this yesterday, and I realized I never actually like reported this to Canary and probably should have. [13:00.680 --> 13:02.080] So I don't know if it's still the case. [13:02.460 --> 13:02.540] Okay. [13:03.240 --> 13:09.740] Anyway, so Tracker Jacker, that was kind of a, you know, just, you know, this is what we do sometimes. [13:09.740 --> 13:18.840] It's a ridiculously over-engineered solution that took way more time than it would have taken to solve the problem in a different way, but such is life. [13:19.780 --> 13:23.060] So Tracker Jacker, it's an open-source software. [13:23.060 --> 13:33.680] Tracker Jacker, you can find the source on GitHub, and it's also on PyPy, so it's pip install tracker jacker. [13:36.540 --> 13:46.280] And let's actually go ahead and exit this slideshow and do some demos, hopefully. [14:06.020 --> 14:12.860] Okay, so the first kind of main feature of Tracker Jacker is mapping functionality. [14:13.440 --> 14:23.700] So this is, you know, as I was trying to get into some of this Wi-Fi stuff, it was just the question was, that arose in my mind was, what all Wi-Fi devices are actually around? [14:25.200 --> 14:27.040] All right, so we're live scanning now. [14:27.280 --> 14:32.780] Now, one thing to look at, if you look at the channel on the right, you can see channel one, channel four, channel five, right? [14:33.100 --> 14:36.620] What it's doing is, it's doing just a round-robin scanning through the channels. [14:37.360 --> 14:42.500] Remember, it's just radio, so we've got to hop from frequency to frequency to see all the stuff that's out there, right? [14:43.480 --> 14:49.700] There is a couple different modes for configuring the channel hopping scheme. [14:49.920 --> 14:51.560] You can do a round-robin. [14:51.880 --> 14:58.320] You can also do things where, if you're looking for a particular device, it'll do kind of like a Markov Chain Monte Carlo-esque. [15:00.340 --> 15:02.700] Wherever it's getting results, it'll focus there more. [15:03.340 --> 15:09.500] You know, so if it's seeing a lot of action on channel 11, it'll tend to prefer channel 11, for example. [15:09.740 --> 15:10.520] So there are some options. [15:11.560 --> 15:18.800] So this is picking up all kind of Mac addresses and stuff from all of y'all, of course. [15:20.500 --> 15:28.040] And what it does is it builds a YAML file. [15:29.660 --> 15:31.480] Who all here is familiar with YAML? [15:32.240 --> 15:33.340] Okay, so a decent amount. [15:33.500 --> 15:36.320] So it's just a standard format, human-readable file. [15:37.060 --> 15:44.620] So ultimately, this is kind of outputted in a way where you can go and parse it with other stuff. [15:45.860 --> 15:48.940] But basically, let me scroll up here to a good spot. [15:49.780 --> 15:53.040] So basically, the structure is you've got the network. [15:53.400 --> 15:56.960] So this is like the network ID, right? [15:56.980 --> 16:01.560] And you've got multiple nodes on it, BSSID, BSSID. [16:02.560 --> 16:07.340] It's got information like this one is running on channel one. [16:09.580 --> 16:14.120] We see the power level, the vendors. [16:15.600 --> 16:23.340] If we look down at this device, for example, this Wi-Fi network, guest Wi-Fi, we can see it's got one device connected. [16:23.980 --> 16:25.700] We see its power level. [16:26.640 --> 16:28.300] The last time it was seen. [16:31.560 --> 16:35.760] You can see here, this one's got a couple... [16:35.760 --> 16:37.320] Okay, the HOPE network. [16:40.060 --> 16:42.280] It's seen a few devices connected. [16:42.440 --> 16:43.460] Here's an Apple device. [16:43.980 --> 16:47.480] It's seen this one transfer 114 bytes. [16:49.220 --> 16:51.340] So basically, Tracker Jacker is just... [16:51.340 --> 17:03.860] When it's in map mode, it's just continually trying to pick up all of the Wi-Fi data that's out there and correlating it and building a map of it. [17:04.480 --> 17:08.640] Sometimes it's nice to mirror, and sometimes it's nice not to... [17:09.440 --> 17:11.300] Right now, it's in between... [17:11.300 --> 17:12.700] Where's my pointer at? [17:38.430 --> 17:51.120] It's taken in about 28,000 data points, or not data points, but it's got something like 28,000 pieces of data that it's recorded in a database, I guess. [17:52.960 --> 17:55.820] I don't want to do the grub thing to figure out exactly how many MAC addresses. [17:57.780 --> 17:58.680] Okay, so... [17:58.680 --> 18:00.220] But that's kind of the idea. [18:00.340 --> 18:01.900] So the idea is to have like a... [18:03.780 --> 18:05.760] Let me just see if I can export this file a little better. [18:05.880 --> 18:09.040] It's really hard from this angle, but... [18:09.040 --> 18:15.020] Ultimately, it's an exhaustive list of all of the Wi-Fi networks in the area. [18:15.500 --> 18:23.340] It will then have all of the nodes that each of those devices has, and all of the devices connected to each of them. [18:25.640 --> 18:27.560] So that's kind of mapping mode. [18:27.720 --> 18:33.880] It's really good for just really kind of in mapping around the Wi-Fi space and seeing what all is out there. [18:36.820 --> 18:37.780] Other modes... [18:38.660 --> 18:41.500] Let me just show kind of an unfiltered mode. [18:43.160 --> 18:52.820] Now, this project is actually built on top of another library called Scapee. [18:53.300 --> 18:56.300] Who all is familiar with the Python Scapee library? [18:56.660 --> 18:56.840] Cool. [18:57.480 --> 19:01.500] Scapee is a really awesome library for doing like packet crafting and that kind of stuff. [19:02.060 --> 19:05.080] And so anyway, this is basically just doing a raw dump. [19:05.260 --> 19:08.880] So just, you know, it's just kind of cool to see what does the Wi-Fi space look like. [19:09.020 --> 19:10.660] And it's not completely raw. [19:10.660 --> 19:14.160] It's actually, you know, like parsed, so to speak. [19:14.300 --> 19:21.940] But, you know, this is ultimately what it kind of looks like to just be bouncing around from channel to channel and sucking up all of the frames that we see. [19:23.680 --> 19:30.040] And Scapee ultimately breaks things down at different levels, kind of like the OSI model we talked about earlier, right? [19:30.240 --> 19:33.540] So the RadioTap interface, for example, is the physical layer. [19:33.540 --> 19:42.360] So if you want to get the power level, you access the RadioTap layer and do the .power to get the power level, for example. [19:43.320 --> 19:43.780] Okay. [19:45.720 --> 20:02.430] Another example of what we can do with Scapee I want to show is there's basically a very flexible plug-in system for Tracker Jacker. [20:02.530 --> 20:04.570] So you can write your own Python plug-ins. [20:04.790 --> 20:06.350] And so the idea is... [20:06.350 --> 20:09.090] And I'm going to show a really small code example in a minute. [20:09.570 --> 20:11.210] So this plug-in is kind of a... [20:11.210 --> 20:11.730] There's... [20:11.730 --> 20:13.850] Actually, this is the only built-in plug-in right now. [20:14.830 --> 20:19.170] But you can just write your own plug-in and you don't have to commit it to the source or anything. [20:19.270 --> 20:21.310] You can just run it, you know, just give it the path kind of thing. [20:21.310 --> 20:27.010] But this is a built-in plug-in, which is, you know, nothing novel here. [20:27.110 --> 20:28.090] This is just a fox hunt. [20:28.310 --> 20:32.290] So this is basically just a plug-in. [20:32.290 --> 20:38.690] So as the packets are coming in, it's basically just keeping track of the highest power devices and keeping them at the top. [20:39.350 --> 20:42.370] So this would be like what you'd use in a fox hunt, for example. [20:42.710 --> 20:53.410] Like if you have a directional antenna and you just want to find whatever that Broadcom is or, you know, just point, find which way the power is highest and walk in that direction kind of thing. [20:56.710 --> 20:59.190] And let me show another example. [21:00.370 --> 21:01.450] Let me see if I can... [21:11.000 --> 21:11.400] Okay. [21:15.950 --> 21:19.930] So this is a really simple example of a Tracker Jacker plug-in. [21:20.250 --> 21:22.550] So as you can see, it's just plain Python. [21:22.710 --> 21:25.050] There's no subclassing or anything like that. [21:25.050 --> 21:32.690] And essentially, it's just got to be a class called Trigger with a call function that takes some keyword arguments. [21:33.630 --> 21:34.730] That's the interface. [21:34.930 --> 21:37.690] As long as you conform to that interface, you're good. [21:39.550 --> 21:49.990] And basically then, Tracker Jacker, for every frame received, it's going to call in to your function and say, here's the device ID that's like the MAC address. [21:53.450 --> 22:00.030] So in this case, we're actually taking advantage of that vendor keyword argument to say, okay, let's take the vendor. [22:00.850 --> 22:02.170] It looked up the vendor. [22:02.410 --> 22:10.950] By the way, the IEEE puts out the OUI, the Organizational Unique Identifier Mapping List. [22:11.210 --> 22:11.970] It's a tech... [22:11.970 --> 22:17.450] So basically, I have it compiled as a text file within the source code of Tracker Jacker. [22:18.250 --> 22:20.670] So it's not having to look stuff up on the Internet. [22:20.850 --> 22:21.490] You know what I mean? [22:21.550 --> 22:22.890] It's not going... [22:22.890 --> 22:24.110] So it's all self-contained. [22:24.390 --> 22:29.510] And if you need to look up a MAC address, it's just a good source for that as well. [22:30.570 --> 22:34.450] So yeah, so this is basically just counting Apple devices. [22:34.650 --> 22:36.510] So let's run this one. [22:36.670 --> 22:37.970] And oh, actually, just... [22:37.970 --> 22:38.710] You know, you can... [22:38.710 --> 22:39.530] A couple other things. [22:39.690 --> 22:40.810] You know, the power level, right? [22:40.810 --> 22:43.130] You know, so that was the one that's used for that fox hunt. [22:43.510 --> 22:48.030] You know, you could imagine doing all kinds of interesting different things with this kind of interface. [22:48.310 --> 22:52.170] But let's try to run it real quick. [23:14.920 --> 23:21.420] And now we wait to see if anyone is using Apple devices in the area. [23:23.720 --> 23:24.440] Uh-oh. [23:26.300 --> 23:27.180] Maybe not. [23:27.400 --> 23:30.320] Maybe the demo gods are... [23:30.800 --> 23:31.820] are not with me today. [23:34.540 --> 23:34.980] Weird. [23:35.520 --> 23:35.600] Okay. [23:37.800 --> 23:38.680] Oh, there we go. [23:38.820 --> 23:38.920] Okay. [23:39.500 --> 23:40.220] One brave new soul. [23:41.420 --> 23:42.540] Surprisingly low level. [23:42.740 --> 23:42.860] Wow. [23:44.160 --> 23:44.460] Okay. [23:45.120 --> 23:45.360] Well, yeah. [23:45.520 --> 23:49.480] So anyway, it's scanning around, jumping from node to node. [23:50.060 --> 23:53.000] Let's do one other one that's going to get hit more often. [24:07.780 --> 24:10.940] This is a plug-in called Count Manufacturers. [24:11.280 --> 24:16.840] And so I'll just mention it's worth looking at the command line argument itself. [24:16.980 --> 24:17.960] So it's Tracker Jacker. [24:18.100 --> 24:21.480] It has to run as root because it's got to do monitor mode. [24:22.320 --> 24:28.020] Um, the track kind of, uh, parameter is for tracking and running plugins. [24:28.660 --> 24:30.060] And you have a path. [24:32.850 --> 24:37.630] Um, and, uh, you know, the dash I stands for the interface. [24:41.520 --> 24:44.860] Okay, so this is basically then just counting up different manufacturers. [24:46.360 --> 24:52.880] And, um, so this would be like, hey, I want to know how many Huawei devices are in the area or whatever. [24:53.420 --> 25:04.880] Um, and then periodically it will save to a .txt file, um, on some kind of, I think it's once a minute or something. [25:04.880 --> 25:06.480] So let me wait for it to save. [25:08.840 --> 25:09.820] Ah, there. [25:11.440 --> 25:12.980] Saved top manufacturers. [25:13.220 --> 25:13.320] Okay. [25:14.020 --> 25:19.140] So let's top manufacturers. [25:20.040 --> 25:21.360] Uh, okay. [25:21.500 --> 25:22.820] So, so it wrote this file, right? [25:23.020 --> 25:24.100] So, yeah. [25:25.180 --> 25:27.980] Cisco is apparently number one in this crowd. [25:28.820 --> 25:33.200] Um, and obviously it's not very useful on its own. [25:33.360 --> 25:42.140] It's just kind of to give some demonstrations of the, the kind of, um, stuff you can, you can do with the plugin system. [25:43.600 --> 25:45.060] Um, all right. [25:46.280 --> 25:48.700] Um, by the way, this is going to be a shorter talk. [25:48.840 --> 25:50.120] I'm actually close to wrapping up. [25:50.240 --> 25:54.900] If you want to be thinking of any questions you have or anything like that, be thinking about that. [25:55.080 --> 25:57.640] But a couple more things I want to say about the environment. [25:58.480 --> 26:03.720] Um, so right, right now, Tracker Jacker is just tested in Linux. [26:03.720 --> 26:06.280] Um, I'd like to bring it to Mac probably. [26:06.280 --> 26:08.960] I just, I haven't got around to it yet. [26:09.600 --> 26:12.540] Um, it's also, uh, worth noting. [26:12.640 --> 26:17.260] So I, I, I, I like to run, I typically run like in a VM. [26:17.760 --> 26:19.920] Um, I like Kali for that. [26:19.920 --> 26:23.840] Um, and I also, I'm going to try to lift my computer up here. [26:24.220 --> 26:27.620] I have a little, uh, Wi-Fi dongle that I use. [26:28.240 --> 26:30.600] Um, an external Wi-Fi adapter. [26:31.900 --> 26:42.360] Um, because, uh, a lot of times the built-in ones don't have monitor mode capabilities, for example, as well as other stuff you might want to do if you're doing, like, wireless hacking. [26:42.840 --> 26:46.480] Um, so a couple examples, a couple that I've worked with that I like. [26:46.940 --> 26:49.480] Um, there's the Panda brand. [26:49.780 --> 26:52.780] I, I hadn't actually heard of them prior to doing some of this stuff. [26:52.840 --> 26:55.540] But they have these nice little adapters for reasonable price. [26:55.700 --> 26:56.860] These are a couple adapters. [26:57.140 --> 27:01.580] And I have these, by the way, on the GitHub, uh, repo at the bottom. [27:01.820 --> 27:05.040] Just for reference of known adapters that are good. [27:05.680 --> 27:14.560] If any of y'all use another Wi-Fi adapter and have success with it, definitely feel free to hit me up. [27:14.640 --> 27:15.460] Or you know what you could do? [27:15.740 --> 27:20.120] You can do a pull request on the GitHub, uh, readme page. [27:20.280 --> 27:28.280] And, you know, uh, if you got some evidence and you can show me, yeah, it works, then, you know, we'll accept it and have a contribution there. [27:29.500 --> 27:30.480] Uh, okay. [27:30.780 --> 27:38.120] So, uh, the core takeaways, I guess, you know, at the, um, physical layer, ultimately Wi-Fi is just radio. [27:38.360 --> 27:43.120] And, you know, so there's these nice, um, you know, it's nice to think about. [27:43.260 --> 27:48.400] You've got your nice closed Wi-Fi network, but, you know, it's radio, so it's just airspace. [27:48.540 --> 27:49.640] It's not like wires, right? [27:49.700 --> 27:50.980] It's just, it's all getting out there. [27:51.080 --> 27:52.660] So it's good to keep that in mind. [27:52.980 --> 27:54.860] Uh, monitor mode, it's interesting. [27:55.380 --> 28:03.760] And, you know, it's interesting, too, because, like, I started doing this stuff and I realized, okay, I've got a security, I've got this, this, this, this camera, uh, like, this canary, right? [28:04.800 --> 28:23.120] And, um, people, if they knew, you know, and it, it, it's got the manufacturer on there, so, in theory, I can just go, say, look for drop cams, look for ring cameras, and I, without being connected to the network, right, I can see when those things are uploading videos, [28:23.760 --> 28:24.400] you know? [28:24.500 --> 28:27.060] I can theoretically see when so-and-so. [28:27.060 --> 28:37.140] Um, also, kind of another takeaway is, if you don't want to get tracked, maybe turning off your Wi-Fi when you're traveling around is a good idea. [28:37.360 --> 28:47.600] Because ultimately, your phone and all that stuff is sending out, um, probes looking for Wi-Fi devices, and every time it does, it's saying, hey, here's my Mac address. [28:48.880 --> 29:00.920] Now, there have been some attempts to, uh, remediate this kind of, uh, data leakage by, um, broadcasting randomized Mac addresses, right? [29:01.120 --> 29:03.200] So, like, Apple, I believe, does this. [29:03.360 --> 29:13.460] So, like, if you're not connected to the network and you're just sending out probes looking for Wi-Fi networks, at least some devices, such as, I believe, iPhones, will randomize their Mac addresses, right? [29:14.160 --> 29:15.360] Um, and so that's good. [29:15.520 --> 29:15.960] That's nice. [29:16.340 --> 29:20.920] But, as soon as you connect, it uses its real Mac address, right? [29:21.040 --> 29:32.480] So, in theory, if you're at the coffee shop in your town that you often go to and you're on their Wi-Fi, it's very trivial for, you know, people to see that you're there. [29:34.420 --> 29:37.760] Um, you could obviously, uh, do all kinds of other tracking. [29:38.020 --> 29:43.940] I mean, I'm sure this kind of stuff is being done, right, by the government, and blah, blah, blah, blah, blah. [29:44.280 --> 29:45.820] Um, but it's good to be aware of it. [29:45.920 --> 29:50.820] It's good to maybe have tools, uh, we need to fight back or anything like that. [29:53.440 --> 29:55.360] Um, and, um, [29:58.940 --> 29:59.100] yeah. [29:59.360 --> 30:03.060] So, anyway, I think that's, uh, about all I had to say. [30:03.520 --> 30:05.360] Uh, so, yeah. [30:05.500 --> 30:06.360] Thank you for listening. [30:07.260 --> 30:08.960] And, uh, that's it. [30:15.300 --> 30:19.320] Uh, obviously, we're done here half an hour early. [30:19.480 --> 30:23.760] Uh, if there's any questions, uh, we have a few minutes for questions now. [30:25.800 --> 30:28.360] Yep, we've got mics on both sides, so please come on down. [30:29.840 --> 30:30.220] Yeah. [30:30.980 --> 30:32.380] Yeah, I have a question real quick. [30:32.620 --> 30:37.100] Um, IOT devices were primarily 2.4. [30:37.220 --> 30:41.660] Are you starting to see more that are running on 5 gigahertz, or is it still pretty much exclusively 2.4? [30:42.920 --> 30:43.700] I'm not sure. [30:43.980 --> 30:45.760] I've, I've not kept up to date on that. [30:45.860 --> 30:46.560] Oh, I was just curious. [30:46.760 --> 30:48.080] Yeah, yeah, and that's a good question, though. [30:48.980 --> 30:56.940] Um, obviously, like, 2.4 gigahertz, one thing is it typically will go further, um, because lower frequency radio waves can penetrate better and stuff like that. [30:57.460 --> 30:58.400] Yeah, next question. [30:58.760 --> 31:01.900] What's, like, the general range for, uh, Tracker Jacker? [31:03.200 --> 31:16.580] Uh, um, ultimately, it's radio distance, um, and the way that higher frequency, um, radio works typically is kind of like line of sight. [31:16.760 --> 31:20.880] So it can go through maybe some then-ish walls and stuff like that. [31:21.560 --> 31:36.160] Um, I, I mean, I, I, at my house in, when I was in, when I lived in Milwaukee, I tried going out, and I was probably, uh, some thousands of feet away from my router. [31:37.720 --> 31:40.880] Um, and it could, it could still, I have it still connected. [31:40.880 --> 31:48.300] So, I mean, it basically Wi-Fi, you know, I mean, and actually, its range is going to be even better than you can get Wi-Fi connectivity on, right? [31:48.520 --> 31:55.220] Because if you've just barely got Wi-Fi connectivity, you're going to be having dropping signals and all that, but you'll still get a few frames, right? [31:55.340 --> 31:59.400] So any frame is enough to, to, to be seen. [32:03.840 --> 32:06.420] Any, any other questions, or is that? [32:06.680 --> 32:12.760] Yeah, and also, yeah, good, good to have some links up here, um, if you want to use Tracker Jacker. [32:13.460 --> 32:19.700] Um, also just, uh, I guess, um, kind of a shameless plug. [32:19.740 --> 32:24.320] I'm, uh, also doing art these days, worn out. [32:24.700 --> 32:31.680] Um, I've got a booth over at the vendor area, and, yeah, just doing some art and stuff like that. [32:31.820 --> 32:36.540] I, I kind of use math that I learned doing radio hacking to do visual stuff. [32:36.840 --> 32:37.920] So, yes. [32:37.920 --> 32:38.340] Cool stuff. [32:38.700 --> 32:43.040] Um, yeah, I was kind of wondering how accurate the power level could be for distance. [32:43.240 --> 32:50.460] Like, and there was some talk about actually using it to, like, 2D co-locate, uh, uh, devices. [32:50.880 --> 32:58.580] Would it be possible with multiple of these Tracker Jackers to actually build a 2D representation of where people are in a space? [32:59.600 --> 33:01.600] Theoretically, yes, but that is untested. [33:02.260 --> 33:02.660] Okay. [33:03.120 --> 33:04.720] But I, I mean, yeah, it sounds like a project. [33:05.040 --> 33:05.740] It should work, yeah. [33:06.160 --> 33:06.480] Okay, cool. [33:06.800 --> 33:06.880] Yeah. [33:08.480 --> 33:10.980] Yeah, especially with directional antennas, that's right. [33:11.440 --> 33:12.540] This is, hmm, maybe. [33:13.280 --> 33:20.760] The only thing about directional antennas is directional antennas, it would have to move for you to locate someone, right? [33:20.760 --> 33:22.280] That, I mean... [33:22.280 --> 33:22.400] Yeah. [33:24.280 --> 33:27.140] I'm wondering about a stationary... [33:28.060 --> 33:29.200] It, it, it would still work. [33:29.360 --> 33:30.180] You could triangulate, yeah. [33:30.340 --> 33:31.340] And if you've got more... [33:31.340 --> 33:32.240] I'm thinking about triangulation, yeah. [33:32.480 --> 33:36.640] Yeah, and the more devices you have, the more you can, you know, error correct. [33:36.820 --> 33:36.940] Yeah. [33:38.100 --> 33:38.920] Okay, interesting. [33:39.420 --> 33:40.160] Yeah, yeah, that'd be, yeah. [33:40.380 --> 33:41.260] If you do it, let me know. [33:41.360 --> 33:41.740] I'm curious. [33:42.340 --> 33:49.240] Um, but it's, uh, Tracker Jack, if you look for Tracker Jacker, um, you know, you'll, you should find it out there. [33:49.820 --> 33:51.980] So, thanks all for coming, appreciate it. [33:52.180 --> 33:52.880] Applause .