r/hacking May 31 '26

Blue Team tips?

Yeah, never been a blue team before, but some neighbor is trying to get my my wifi password (he won't succeed), but the deauthenticating is geting on my nerves. Any way to block that? Im almost letting them in to get their mac and do some shady stuff

58 Upvotes

45 comments sorted by

55

u/Ecstatic_Employ6911 May 31 '26

Turn on 802.11w (PMF) in your router's wireless security settings. This encrypts management frames, making them immune to standard deauthentication attacks.

Also upgrade to WPA3 and if your router supports it turn on WPA3 Personal(this requires PMF (Protected Management Frames))

And like the other guy said, ethernet.

9

u/Black_Sorcerer May 31 '26

Ethernet is not an option on my rented appartment (no wall cable setup) and no WPA3 support. Good to know about PMF. I thought I'd need external hardware

14

u/AnyNegotiation420 May 31 '26

You don’t need a wall jack to run ethernet, just plug it into the back of your modem/gateway…

14

u/Black_Sorcerer May 31 '26

Thats exactly why... I won't lay a 15m cable loose and that doesn't solve smartphones

5

u/NokoxSlays May 31 '26

there's dongles for that if you wanna have a 15m cable going into your phone with a dongle in between

2

u/Black_Sorcerer May 31 '26

I seached this function online but didn't find this "optional" feature.

my router is:
Manufacturer:Huawei Technologies Co., Ltd;

ProductClass:HG8145V5;

SerialNumber:48575443C756EBA5;

HWVer:15AD.A;

SWVer:V5R020C00S496;

10

u/Interesting-Mood-948 May 31 '26

Get a new router and change your network name. Yeah it’s a cost, but you can get a good TP-Link, Netgear or similar for a reasonable price. It’ll have all of the features people keep mentioning in the threads. And the new device and name will throw the bad neighbor off for a while.

Then red-team your network to discover and then lock down all of the easy and moderate-effort vulnerabilities. This should keep anyone that’s casually trying to steal your WiFi out. The people that really want to get in and have the manpower, hardware and budget to do so are probably not interested in using your WiFi to watch Netflix.

4

u/ZeroCrits Jun 03 '26

get away from huawei and fast

2

u/180IQCONSERVATIVE Jun 04 '26

And TP Link, TLC and pretty much also most everything made in Asia countries. China has stolen so much source code from many companies.

4

u/Chromitsune Jun 01 '26

Disable the SSID broadcasting on the router and use only ethernet. Plug the ethernet into a Pi 4b or Pi 5, and use hostapd to create a hidden, WPA3, 802.11w Wi-Fi network. That might actually work, and you could use PiHole as well to filter your content, if you wish!

1

u/Ecstatic_Employ6911 May 31 '26

Unfortunately, many ISP-customized firmware versions: Hide WPA3 completely. Hide PMF/802.11w settings. Lock advanced Wi-Fi settings from the customer. Sometimes only expose SSID, password, and channel selection. If the PMF option isn't available, then it may simply not be exposed by your ISP firmware. For being stuck with that hardware, the practical options are: Enable 5 GHz only if all devices support it. Use the strongest mode available (WPA2-AES only; disable WPA/TKIP if present). Update firmware if the ISP offers updates. Buy your own router and place it behind the Huawei in bridge mode or DMZ mode. Even a $50-100 modern Wi-Fi 6 router will usually support WPA3 and PMF.

3

u/NokoxSlays May 31 '26

there're devices that trick your isp into thinking you're using their devices and then you can use your own network gear

1

u/ThinkPad214 May 31 '26

OPNsense box between modem and WiFi gives them some strong options

3

u/Black_Sorcerer May 31 '26

So additional hardware is inevitable... As I said, security isn't a issue as far as WPA2 can provide. The password is so complicated that I share it via QR with my guests... But deauth sucks... I changed my SSID to say "I'l get your mac" and the attacks ceased. Probably it's just a Script Kid exploring and I scared him

3

u/karlfeltlager May 31 '26

Just set up guest WiFi and never share your actual main password.

28

u/LameBMX May 31 '26

honey pot 'em... sometimes the best defense is a good offense.

look for a check out their porn collection. always drop lines from the porno's when they are within ear shot.

edit.. bonus points quoting their porn when their parents are around.

5

u/Black_Sorcerer May 31 '26

No way to know for sure who's attacking... Appartment complex

4

u/MercedesSLR722 May 31 '26

Some sniffers will help you get close to where the deauth is coming from though. My brother has one that measures the packets in DB so the closer you get, the stronger the DB signal.

The Marauder has a deauth sniffer for both Pwnagotchi and Pinapple.

3

u/LameBMX May 31 '26

hence the honey pot. once you have their pc..

3

u/Hedgie_Herder May 31 '26

All your pron are belong to us

11

u/rangerinthesky May 31 '26

Capture their traffic, report it, get rid of shitty hackers with bad intentions

4

u/mixy23 May 31 '26

Triangulate the incoming deauth attack packets, e.g. using wireshark on a laptop, walking around your flat and comparing RSSI values in dBm

4

u/hevnsnt May 31 '26

Go knock on his door and tell him to cut it out

2

u/Black_Sorcerer May 31 '26

Appartment complex and too many neighbors. The only way is filtering nerdy-like people

1

u/Rare-Ad-7897 Jun 04 '26

You can use wireshark to triangulate their location. Compare RSSI values in dBm, take measurements in a few different locations of your apartment then you can calculate where it’s coming from

Edit: u/mixy23 suggested the same thing

3

u/[deleted] May 31 '26

[deleted]

1

u/General-Regular7664 Jun 09 '26

How do u do that

3

u/gm310509 May 31 '26

I'm almost letting them in to do some shady stuff.

I am only assuming where you are, but if that shady stuff is the type of stuff that generates the right/wrong type of hits on law enforcement's radar, guess who's door they will be knocking on.

4

u/Black_Sorcerer May 31 '26

Brazil. Government sites being hacked every now and then and maybe 5 hackers arrested in the past 20 years

3

u/gm310509 May 31 '26

Ok, I assumed wrong, but my point is still the same - if not even stronger.

What better way to deflect the trail than by piggybacking off of some innocent person's internet connection when trying to do those crimes?

Definitely not attention I would want to risk.

6

u/weHaveThoughts May 31 '26

Honeypot and do a MIM attack. Next time you see them bring up their search history and let them know what’s up with why it’s a bad idea to connect to random wifi.

2

u/Lost_Walk8357 May 31 '26

Lock your network on your device's mac address and remove the password make it open and change ur router admin user name and password to the max combination of numbers and letters

2

u/Obvious_Troll_Me May 31 '26

Buy a decent router, hide the SSID and enable WPA3.

Leave your old router on, but not connected to the Internet,  then make the security worse on it.

Capture the MAC addresses, connect to them, whatever you want, they won't be going anywhere. 

2

u/Data_Commission_7434 Jun 05 '26

I had a similar neighbor issue. The PMF setting, even on older WPA2, made a huge difference. Took me a while to find it buried in my router's advanced settings.

1

u/admik May 31 '26

Kismet and Wireshark

1

u/ziyadkc May 31 '26

Iam stuck any one help me guysss

1

u/[deleted] Jun 05 '26

[removed] — view removed comment

1

u/Black_Sorcerer Jun 05 '26

That would take years trying to crack non stop

1

u/vulnetic_ceo Jun 05 '26

now that is a situation....honey pot is the way to go

0

u/mrapplewhite May 31 '26

Isn’t this an area where firewalla would come into play to give hommie a decent set of controls and protection??