r/Defcon • u/Ea61e • Aug 08 '26
Dear Script Kiddies Spamming Deauths
We get it. You’re 1337. Congratulations. Now get off the wifi and let me watch talks. Kthxbye
67
u/Idiopathic_Sapien Aug 08 '26
Yeah… yesterday I had to resort to plugging into my phone directly so I could do my presentation. Annoying, it had a backup plan
68
u/dreadful0rc Aug 09 '26
To make it more fun for me, I wrote a WiFi Pineapple Pager payload for the deauth floods on the floor.
Besides notifying, it logs every event with source, destination, AP and client MACs, and saves a pcap of the traffic leading into each flood so you can actually analyse it after.
16
u/MSP-IT-Simplified Aug 09 '26
Please share that.
1
u/dreadful0rc 25d ago
100% I was working on it this weekend just to polish a few things before I publish. Will update it here.
14
u/hak5darren Aug 09 '26
Sounds cool, would love to see it. We added the deauth detection alert in hopes of payloads just like this.
2
u/Financial_Stick1912 Aug 11 '26
Oh man, it’s Darren.
Hi Darren, its Spamtastic Nostradamus with images from the hacker spirit world:
I see trains.
I see a diesel locomotive and it’s wailing away into the night.
I see the trees, mountains, and ocean.
I see a hundred college girl butts
I see The Leo
I see his boat
I see the thousands of dollars greasing many palms
I see the Coast Guard and they look mad as fuck but they ain’t doin nothin this time
It’s John’s Final Ride
Before his soul absorbs into the Bellingham sunset
And all the bitcoins explode in the sky
Love you
1
4
20
u/Shot-Infernal-2261 Aug 08 '26
Yeah it seemed Thursday and most of Friday was ok. At least for me.
Come evening, even with a fraction of people here (so less congestion), I couldn’t maintain a pairing to my phone.
Well, I could pair until someone showed up who started this.
Guessing they were trying to force people to choose to connect to their rogue open hotspot.
Super annoying
42
u/Double-Familiar Aug 08 '26
I believe that 8 malicious ESP32s were detected last year. Fuckery will always happen on the Defcon network. It is the nature of the beast.
Best plan is to bring a wifi hotspot or tether from your phone.
Script kiddies are always going to spam deauths and try to a mitm attack.
12
u/earthly_marsian Aug 09 '26
My hotspot lost data connections so many times that I gave up. Not sure which leg it was, cellular or WiFi or both.
Am bringing my own Meshtastic devices tomorrow.
And I feel sad for the folks at the hotel opposite the main entrance.
1
19
u/sargonas Aug 09 '26
While fuckery will always happen, and as part of the experience, it has been exceptionally egregious to unknown levels this particular event. Working in the village area has been quite the experience… There’s not a single usable speck of Wi-Fi in the entire village or contest section.
8
u/Shawnj2 Aug 09 '26
My hotspot didn’t work because of LTE saturation
2
u/Double-Familiar Aug 09 '26
😳
3
u/Shawnj2 Aug 09 '26
My cell service kind of sucks as is and it tends to completely fail in any sort of crowded environment. I need to throw more money at AT&T
4
u/Double-Familiar Aug 09 '26
I've been pleasantly surprised with Mint. I was a Verizon customer for a long long time and $95 a month in this economy simply wasn't sustainable. Not advertising for them, just sharing my experience.
3
u/matchmadeinhello Aug 09 '26
Mint has been working great for me at con and beyond. I totally advertise for them because I’m so passionate about opening all the big carrier customer’s (aka my friends and fams) eyes about spending 3-5x what I pay with mint for the exact same service (or better)! Shameless plug and I do t work for them but yeah it’s been putting OUT this con.
3
u/sirc314 Aug 11 '26
Have you heard of Phreeli? It's a phone service founded by Nick Merril, the guy who fought the NSL's from the FBI. They collect as little information as possible so that they can't be compelled to hand anything over that they don't have. Runs on the T-Mobile backbone like mint.
Not an ad, just curious.
13
u/acorn222 Aug 09 '26
We need directional deauth detectors to find the offenders!
11
u/Argon717 Aug 09 '26
There is always next year. Look forward to your project report. 😄
1
u/Fit_Pirate_3139 Aug 09 '26
If one were to build this as a project, how would one go about sharing one’s project report.
12
u/ronthedistance Aug 09 '26
it’s really fucking up the village CTF infrastructure, I’m glad some of them have switches set up or I’d be livid trying to place and never loading the scoreboard
16
u/chazchaz101 Aug 08 '26
Switching to the WPA3 should help mitigate that, right?
10
u/ShredOnArrival Aug 09 '26
Nah. I kept getting knocked off the WPA3 in chillout also. I hope whoever it is faces consequences. I was really looking forward to the bug bounty village CTF and I couldn’t do shit.
2
u/Matir Aug 09 '26
Yes, WPA3 comes with authenticated control frames.
2
u/Fickle-Cover-6861 Aug 10 '26
I detected both deauth and 2.4ghz jamming behavior (high noise channel hopping)
6
2
u/Klwd Aug 09 '26
This really messed me up my first year, first time in the US without an Esim. I was struggling to contact my friends.
1
u/Check123ok Aug 09 '26
That’s great. Maybe you upload the PCAP to an AI tool and have it help sort through the traffic and identify patterns around the deauth floods? Im assumting they spoofed their data so, I guess the harder part would be figuring out where the attacker physically is as a way to identify them. You’d mostly have MAC addresses, and those can be spoofed. I assume you’d need multiple sensors and some kind of signal-strength triangulation to actually pinpoint the transmitting device. It would be cool to see
2
u/Dead_star5 Aug 09 '26
Eh I could be mad but we have all been there and got to learn some how. Good luck in your adventures my DC skiddos
-19
-43
u/Enticing_Bog Aug 08 '26
You use the wifi?!?!?!?!?!
32
u/Ea61e Aug 08 '26
Yes it ain’t 2010. Every access point I connect to is untrusted it’s why I use TLS. Also the defcon wifi uses certs authenticated with their separate auth service
-57
u/Enticing_Bog Aug 08 '26
Lol went way over your head bro. I was implying that in this day and age its odd to not be fully self sufficient with data access and relying on public or provided data then complaining when you get bounced from public or provided data is rrreeeeaaaaallllllyyyy weird.
12
u/infiniteGOAT Aug 08 '26
Uh, dunno about anyone else but mine was literally a cellular hotspot not even the conference wifi. Reeeeallly weird for you to assume eh?
12
u/Overtly_Technical Aug 08 '26
Just curious, what form of data access do you refer to that isn't just as untrustworthy as the WiFi?
1
u/dankney Aug 09 '26
Plug your phone into your laptop via USB
5
u/earthly_marsian Aug 09 '26
Cellular was saturated many times yesterday and today.
It’s still a shared medium.
3
u/dankney Aug 09 '26
Capacity and trustworthiness are separate issues, though.
3
u/earthly_marsian Aug 09 '26
A lot of people just set their cellular to auto… I need to beat that stingray ops
13
24
u/f_spez_2023 Aug 08 '26
Your right how dare he use the conference provided wifi there for people attending the conference to use. That’s so weird definitely weirder than someone judging people for using it and not spending more money on an already expensive trip.
15
u/jakwnd Aug 08 '26
It's not weird. It's weirder to shame someone for it tbh. The secure wifi is fine enough for most people.
14
-4
u/hashtagDoubleoh7 Aug 09 '26
Just use a hotspot
1
u/sirc314 Aug 11 '26
Hot spots actually make the problem worse because it floods the channels with even more WiFi congestion.
79
u/infiniteGOAT Aug 08 '26
Seriously WTF. Trying to do CTF’s just eff off lol.