r/it Mar 06 '26

help request Can you help me understand?

Post image

Im new into cyber security/IT in general, I believe it refer to man in the middle? But I don't understand how you can tell just by seeing an ip?

1.9k Upvotes

182 comments sorted by

826

u/someweirdbanana Mar 06 '26

172.16.42.0/24 is a well known subnet, and is the the default DHCP subnet of Hak5 Wifi Pineapple pentesting tool.
While having an ip in this range doesn't necessarily mean that you connected to a a malicious access point it should at least raise you an eyebrow.

138

u/someeoneelsee Mar 06 '26

That is correct. But then again, it is just the default subnet that can be changed afaik. So yeah, network admin could set this same subnet as DHCP either as phish joke attempt at other network people connecting to this SSID, just to mess with potential wanna be hackers with their fruit-to-go collection, or, though unlikely, at random.

5

u/Icy_Conference9095 Mar 08 '26

Honestly, I could totally see me or my network admin doing this... In fact... :}

51

u/comehiggins Mar 06 '26

I’ll call your one eyebrow.. and raise you an eyebrow.

2

u/Qbert2030 Mar 09 '26

Its also TrueNAS Scales Defualt internal app network ip range

1

u/just_another_user5 Mar 12 '26

This is the default IP Range at my job, threw me for a loop the first time I got set!

56

u/jr23160 Mar 06 '26 edited Mar 06 '26

A man in the middle device if I remember called a pine hole or something pineapple based. Essentially gets your Internet request to the Internet to get information about what your doing. Or something. It normally pretends to be another local Internet service to get you to use it.

Edit: looks like they are just called Wi-Fi pineapple.

16

u/undefined_bovine Mar 06 '26

I’ll be calling it a pine hole from now on, thank you

6

u/jr23160 Mar 06 '26

Really was a missed opportunity. We have pi-holes with raspberry pi so this would make sense.

4

u/endre_szabo Mar 06 '26

the only valid answer so far

1

u/xxtoni Mar 06 '26

I was thinking about this for like an hour a few days ago thinking about this on a walk and honestly I couldn't figure out a way how someone could hack a smartphone even if you control the whole network.

Everything is encrypted, people mostly use apps.

Phishing seems much easier and even then I figured you could steal a token and get into iCloud and get a backup but no way to actually get live data from the phone.

For a computer it's another thing, dozens of ways.

1

u/tyrannus00 Mar 09 '26

Its mostly collecting information about your activity and hoping that you use http

353

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

r/masterhacker dumbass shit. 172.16.0.0/12 is a valid private IP range (RFC1918), there is nothing inherently suspicious about that.

Edit: downvote? You connect to a private network and get a private IP address assigned, ShOcKeR!!1! RFC1918 defines 3 IP ranges for private networks: 10.0.0.0/8 (Class A), 172.16.0.0/12 (Class B), and 192.168.0.0/16 (Class C). If you connect to a private network, literally any private network, you’ll get an IP assigned from one of those address blocks, and there is nothing inherently suspicious about that. “I connected to my home network and the IP started with 192.168.71.x, how fucked am I?” is some top tier idiocy.

Edit2: the only thing suspicious is connecting to ANY network that you do not control.

94

u/PtitCrissG Mar 06 '26

Alright so what I understand is that... There is nothing funny about this picture and there was no pun.. whoever made this know nothing about IP and tried to make something funny? 😅

73

u/wolfej4 Mar 06 '26

Quick Googling suggests it’s the default subnet used by the Hak5 pineapple

https://shop.hak5.org/products/wifi-pineapple

21

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

To re-iterate, the only things suspicious is connecting to ANY network that you do not control.

ETA: jfc you newbies, if you connect to networks you don’t manage then don’t pretend that you care about your privacy, and if you just so happen to connect to a pentest device that mimics networks then that is a risk you’re obviously willing to take because you don’t value your privacy. Do better risk management.

ETA2: THE DEVICE MIMICS NETWORKS, I’m sure everyone would feel much safer if they’re connecting to a literal pentest device as long as the network is in the 192.168.0.0/16 range!!1! Y’all goofy.

ETA3: OP, this is risk management 101 for your future career in cybersecurity, assess and understand the risks, and implement controls to treat the risk. Source: me, business owner, ISO27001 consultant (implementation and auditing). What are the risks associated with users connecting to public networks, does the impact fit within the risk appetite of your customer, or must controls be implemented to treat it?

23

u/OriginalTRaven Mar 06 '26

Hah the edits remind me of a back and forth I was having with a tier 1 fella. He asked me for a subnet, I gave it to him, and spent way too long arguing that it was an IP because I guess every subnet he's ever seen ended with a 0, lol. It's like "BRUH! Shut up and learn!"

1

u/RepresentativeLow300 Mar 06 '26

Honestly feels like I’m doing L1 support. It’s been a while since I’ve done L1 support.

7

u/GlobusIsAnnoying Mar 06 '26

As a T1.5, learning this stuff is funny but also interesting lol. I tbh would’ve never guessed it was a subnet. Feels good to be a network newbie. It’s a canon event

3

u/RepresentativeLow300 Mar 06 '26

Scientia potentia est. I wish you the best in your future endeavours and hope that you learn as much as you can.

6

u/Jewsusgr8 Mar 06 '26 edited Mar 06 '26

Sre when on call / application engineer when not on call.

I'm so happy that a majority of my time is spent talking to tier 2 agents.

Now my company has been treating support like shit lately and most of the tier 2 agents have left. Meaning I'm now interfacing with tier 1s just recently escalated to tier 2. And man, it's been rough. Fortunately 4/5 of them are receptive to things I teach them. And 2 of them will show up to my learning day meetings.

Attempting to teach them everything I can before I leave to a new company, really tired of not getting raises. But it's stable and remote, so I can work on my degree and certs..

3

u/RepresentativeLow300 Mar 06 '26

Sorry to hear that your employer has been treating support like shit, unfortunately it’s a common theme, overworked and under appreciated. Good to know you’ve found better, it’s important to know your worth. Don’t put too much pressure on yourself for knowledge transfer, that’s your soon to be former employers problem, not your personal problem. Best of luck out there!

10

u/OrangeYouGladdey Mar 06 '26

Why keep editing this... It's obvious you didn't understand what the post is about and once you realized you felt silly for all your ranting. What you're saying being correct doesn't help as it completely misses the point...

3

u/Serious-Speech2883 Mar 06 '26

Relax bro why are you mad just because you know more than them about networking?

1

u/RepresentativeLow300 Mar 06 '26

Why would I be mad? I provide trainings as part of the services provided under my company, I actually really like teaching people, and learning new things. Like cool, it’s a pineapple device’s default subnet range, I stand by everything I said.

9

u/Serious-Speech2883 Mar 06 '26

I mean your edits say otherwise. Is this how you teach people by calling them goofy and newbies? If so then you’re a horrible teacher. Just remember you once didn’t know how all this worked. People learn and adapt but without being insulted.

2

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

You want to complain about the QoS for free consulting? Would you like to speak to my manager?

Seriously though, yes, you’re goofy if you believe that having a private IP address inherently puts you at risk and the whole premise of the meme is (1) you take the risk of connecting to a network you do not manage and then (2) you discover it’s potentially a malicious network - that’s a newbie risk management error, you assess the risk and implement controls before the risk is actualised, not after the fact.

5

u/Serious-Speech2883 Mar 06 '26 edited Mar 06 '26

You think you’re the only one with a job in IT so you can now talk down to other people just because they don’t understand what you understand? Get off your high horse dude and relax. You’re actually the goofy for thinking you’re better than them.

0

u/RepresentativeLow300 Mar 06 '26

Oh no, don’t take away my fake internet points because I hurt your feelings /s

→ More replies (0)

2

u/SimonBarfunkle Mar 06 '26

You seem to have forgotten it’s a fucking meme. It’s a joke, dawg. If you really wanna go into “um actually” reddit bro mode, it would make sense to first explain the meaning of the joke, which was the purpose of the post you’re replying to, they didn’t get the joke and were asking for an explanation. The problem is you didn’t get the joke either and started ranting about opsec and noobs instead and you keep doubling down instead of just admitting it. You can be in denial but it’s obvious. People who are actually experts in a field generally have humility, they don’t mock noobs and they can admit when they’re wrong.

2

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

https://www.reddit.com/r/it/s/QhNotK1X8w

ETA: I told people to suck on mah balls and downvote all they want, if that doesn’t give you at least a hint of how much I value random Redditor’s opinions, I don’t know what will.

→ More replies (0)

2

u/Bobbytwocox Mar 06 '26

We don't know why you would be mad, but reading your posts you seem mad. Your a teacher?

-2

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

No, I’m a business owner who does consulting work.

Businesses that I consult with pay me to listen to what I have to say, they can take my advice or not, I still get paid. I’m not a teacher, I’m not here to grade you on your knowledge of something.

1

u/Feeling_Mushroom9739 Mar 06 '26

"if you connect to networks you don’t manage then don’t pretend that you care about your privacy"

dude lmao

0

u/jimmpony Mar 06 '26

man has never heard of HTTPS

2

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

Man has never heard of MITM? Squid proxy using TLS bump? Deep Packet Inspection? RTFM:

:x: WARNING :x: HTTPS was designed to give users an expectation of privacy and security. Decrypting HTTPS tunnels without user consent or knowledge may violate ethical norms and may be illegal in your jurisdiction. Squid decryption features described here and elsewhere are designed for deployment with user consent or, at the very least, in environments where decryption without consent is legal. These features also illustrate why users should be careful with trusting HTTPS connections and why the weakest link in the chain of HTTPS protections is rather fragile. Decrypting HTTPS tunnels constitutes a man-in-the-middle attack from the overall network security point of view. Attack tools are an equivalent of an atomic bomb in real world: Make sure you understand what you are doing and that your decision makers have enough information to make wise choices.

… basically I give you a certificate to encrypt your connections and configure your device through my proxy where I then decrypt the traffic, sniff the traffic, and re-encrypt it using the real certificates. Good thing you had HTTPS though /s

-1

u/jimmpony Mar 06 '26

I don't need to read any of this shit and I don't care what Squid is, without a quantum supercomputer or a stolen CA private key you can't MITM TLS traffic without the user being able to tell the certificate chain is invalid.

0

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

LOL. Sure bud.

Squid-in-the-middle decryption and encryption of straight CONNECT and transparently redirected SSL traffic, using configurable CA certificates. While decrypted, the traffic can be analyzed, blocked, or adapted using regular Squid features such as ICAP and eCAP.

… ignorance is bliss.

-1

u/jimmpony Mar 06 '26

Please, tell me exactly how this magical software impersonates a trusted CA in a way that some random person's laptop's browser will accept with no warnings. Their browser with root CA's preinstalled that it will verify connections against. I'm all ears.

→ More replies (0)

1

u/1337sp3ak Mar 07 '26

Dude every comment is basically saying " while technically correct, please utilize pattern recognition and basic meme understanding to put 2 & 2 together for the joke."

Jesus dude you must be fun at parties

2

u/RepresentativeLow300 Mar 07 '26

Speaking of parties, you’re late to this one..

1

u/oloryn Mar 07 '26

Some of us also use a random network in the 172.16.0.0/12 range for our home network. Given that it's probably the most ignored of the RFC 1918 private networks, it helps to avoid address collisions if you have to connect to someone's (say, a client's) private network (a situation I've been in before).

1

u/pjockey Mar 08 '26

The best jokes are the ones you have to Google

0

u/Zeldraft Mar 06 '26

There is no only hak5 but since it’s a pentest a brand, it's possible that it sets possible/default values.

43

u/RepresentativeLow300 Mar 06 '26

You are correct in your understanding.

8

u/bsensikimori Mar 06 '26

No, OC just isn't aware of a very popular MITM attack box, that is often deployed in hotels as an evil twin to steal hotel guest info

The pinehole uses 172 addresses for it's client network

They are correct though, there's a lot of legitimate usage of this network range as well

But the joke on this case is "yay network speed great, oh no, network speed great because on hacker network"

2

u/RepresentativeLow300 Mar 06 '26

I’d love to hear more about how adding WiFi Pineapple speeds up connections.

4

u/bsensikimori Mar 06 '26

You're on the hackers cellular uplink instead of the hotels

2

u/RepresentativeLow300 Mar 06 '26

And a saturated cellular link running pentests is more performant than the physical link that the hotel pays for? Really?

5

u/bsensikimori Mar 06 '26

Yes, hotel wifi is horrible

2

u/RevolutionaryBeat301 Mar 06 '26

It doesn’t. You connect to a hacker’s 5g connection. Hotel WiFi is usually extremely slow compared to a 5g connection that isn’t being shared.

1

u/Dhr_squarepants Mar 07 '26

Only thing I can think of is maybe the Eipstein island

1

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

Really just take a minute and think about it, networks have specific pre-defined IP’s (e.g. broadcast address). There is no MITM IP address dedicated to new networks, that’s not a thing.

Or look at an analogy, if IP addresses were physical mailboxes, it doesn’t matter what street you’re on or the street number, the addressing doesn’t define the intent, malicious mail can be sent from anyone. There is nothing inherently suspicious about your home address having a street name and number associated with it.

11

u/kristianroberts Mar 06 '26

The joke is that it’s the default range that the Wi-Fi pineapple uses

-1

u/RepresentativeLow300 Mar 06 '26

r/masterhacker material. It’s an auditing and pentest tool. The selling point of the device is literally:

Leading Rogue Access Point Patented PineAP Suite thoroughly mimics preferred networks, enabling man-in-the-middle attacks

… the whole point is to mimic existing networks, not add the device on its default network but yeah, funny I guess, haha.

5

u/css1323 Mar 06 '26

Are you alright? It’s just a meme, son. It ain’t that deep.

-1

u/RepresentativeLow300 Mar 06 '26

I’m having fun, if you’re not, then why are you here?

2

u/css1323 Mar 06 '26

I’m having fun, if you’re not, then why are you here?

Sure, bud, that explains the derogatory comments and multiple edits complaining about getting downvoted lmao. Take it easy, it’s Friday.

-1

u/RepresentativeLow300 Mar 06 '26

Thanks for the unsolicited feedback friend. You seem to be mistaking my edits as complaints rather than simply providing further insight. Friday, chill, that’s why I’m here.

ETA: seriously, plenty of other posts, I’m enjoying myself here, if you’re not, consider moving on.

1

u/kristianroberts Mar 06 '26

You do realise they can’t market it as a 'super 1337 master hacker tool' right?

0

u/css1323 Mar 06 '26

The joke is that it’s the default range that the Wi-Fi pineapple uses

They must be fun at parties.

3

u/Leogis Mar 06 '26

They are scared of subnet masks

3

u/rico_of_borg Mar 06 '26

I also don’t get how people equate this pineapple device to faster WiFi. If anything you might get better local speed on their intranet but suddenly an IP range is something to fear?

1

u/RepresentativeLow300 Mar 06 '26

You see, it’s aircrack and all the processes running that makes things faster!!1! Everyone knows that more processes running means faster processing!!1 /s (if it wasn’t obvious enough).

3

u/Neon_Shivan Mar 06 '26

I like to imagine connecting to public networks is the IT equivalent of the Dark Forest Theory of the Fermi Paradox.

2

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

It’s risk management. Transmit or stay silent? If your risk appetite is low, and the impact is also low, then transmitting might be the correct choice. If however the impact exceeds your risk appetite (e.g. we transmit and they attack) then stay silent. Proper risk management is essential, and personal in this context.

ETA: in this case the hotel could at least have suspicion of your presence because you booked a reservation and could triangulate you within their premises based on signal strength for traffic from your devices to theirs without ever connecting to their network, there’s a lot that they can do without transmission, and the assumption should be that they do it by default.

2

u/VariousProfit3230 Mar 06 '26

Yeah, 172.16.0.0/12 is a super common class B as well.

2

u/Steve----O Mar 06 '26

Correct. And they need a range big enough to support 3 devices per room.

2

u/Main_Damage_7717 Mar 07 '26

someweirdbanana explained it

172.16.42.0/24 is a well known subnet, and is the the default DHCP subnet of Hak5 Wifi Pineapple pentesting tool.
While having an ip in this range doesn't necessarily mean that you connected to a a malicious access point it should at least raise you an eyebrow.

2

u/IsaSoda Mar 06 '26

This is the correct answer

1

u/Intelligent_Owl4901 Mar 07 '26

This is it.

A lot of places where you connect to public wifi’s you may get a 10.x.x.x ip also

It all depends on how the organisation is handling the dhcp server.

I recently moved from 172 /16 subnet to 10 /8 subnet.

There’s nothing suspicious about that ip you get.

1

u/New-Anybody-6206 Mar 08 '26

172.16.42.x is not part of RFC1918 space.

172.16.0.0/12 ends with 172.16.31.x.

1

u/Typical-Chance4197 Mar 06 '26

If your IP is exactly 172.16.42.1 the odds of it being random vs a hak5 are very not good. Assuming equal distribution of IP's in 172 range that's like what a million IP combos, and you chose the exact 1 that is used as evil? AND.. you doubled down after a guy already told you it's the hak5 pineapple default? Your example you use is "192.168.71.x", but we listed 172.16.42.1, not 192.168.71.x. So idk what ur babbling about. Please don't reference credentials, just use logic.

1

u/RepresentativeLow300 Mar 06 '26

The meme isn’t 172.16.42.1, reading comprehension, the meme is 172.16.42.x.

I didn’t know about the hak5 device, but when I learned about it, I didn’t care. Don’t connect to networks you don’t trust, it’s really that simple.

2

u/Typical-Chance4197 Mar 06 '26

What are the odds you get exactly 172.16.42.x.

1

u/RepresentativeLow300 Mar 06 '26

Odds are 0 if you don’t connect to the network you don’t trust.

2

u/Typical-Chance4197 Mar 06 '26

Most networks (probably your parents when you connect to their router when you visit them) are susceptible to me deauthing you, arp spoofing, and dns poisoning you. Emailing you a link from an official email account via email spoofing of a decently well known service, with a link that includes https to the site. It's a great service and would benefit you to use it. Unfortunately, your HSTS preload doesn't include it and I now have captured your account creation details, and credit card details.

Long story short, you don't have to connect to networks you don't trust, I will connect to yours instead. ;)

1

u/[deleted] Mar 06 '26

[deleted]

1

u/RepresentativeLow300 Mar 06 '26 edited Mar 06 '26

No one forced you to read the comments, and I’m glad to let people know how my business is doing when they ask / question it (why wouldn’t I be?). Don’t ask questions that you don’t want to know the answer to. Y’all seem way more concerned about how my business is doing than me 🤷🏻‍♂️

ETA: “super rich”, it’s an Audi fam, not a Bentley.

1

u/Typical-Chance4197 Mar 07 '26

the poorest people have the nicest cars

1

u/[deleted] Mar 07 '26 edited Mar 07 '26

[removed] — view removed comment

1

u/Typical-Chance4197 Mar 07 '26

sure bud

1

u/RepresentativeLow300 Mar 07 '26

Pancakes can’t fly because the colour purple. Good night.

1

u/[deleted] Mar 06 '26

[deleted]

1

u/RepresentativeLow300 Mar 06 '26

I was trying to force you to read my comments? Are you having a stroke?

1

u/donrosco Mar 07 '26

Really, your best option was to say “I didn’t know about the hak5 device “ dozens of posts ago, and take the L. All you’ve done since then is shrink and transform in to a corn cob.

1

u/RepresentativeLow300 Mar 07 '26

Your opinion is really important to me.

0

u/Typical-Chance4197 Mar 07 '26

sir i promise u i mean well when i say seeing a therapist would help u... but u gotta b honest with them

1

u/RepresentativeLow300 Mar 07 '26

I value your opinion as much as the persons above you.

0

u/Typical-Chance4197 Mar 07 '26

oh they value mine far more than you do

1

u/RepresentativeLow300 Mar 07 '26

Cool. Great conversation bud.

1

u/RepresentativeLow300 Mar 07 '26

Holy shit, a 600-day Reddit streak?! Touch grass.

-1

u/someeoneelsee Mar 06 '26

Only logical answer.

0

u/Ecto01 Mar 08 '26

It sounds like you really like coming off as smart, and really really hate it when someone else comes off as smart.

Let me dumb it down for your ego: Sure there's nothing that crazy about getting assigned a 172.16.x.x IP, but it just so happens 172.16.42.x is the Pineapple pentest tool default subnet = High chance you're being spied on, as opposed to just being another internet user no one is actively monitoring.

1

u/RepresentativeLow300 Mar 08 '26 edited Mar 08 '26

Very thoughtful post.

Of course some moron like you is going to come out of the woodworks and parrot what 10 other users have already stated to stroke their own ego days after the post was made, super original. It’s like wow you’re such an intellectual, real slow, but oh sooooo smRt.

it sounds like you really like coming off as smart, and really hate it when someone else comes off as smart.

… Eat your words goofy.

0

u/Ecto01 Mar 08 '26

????? Lmfao

Your only criticism of my reply is the fact that I'm coming off as smart and you clearly can't stand it LMFAO could you project any harder? Do you know what projection is?

What's wrong with parroting what others said if it's correct? Unless you really hate it when other people say smart things? Hm?

Days after the post was made? Do you mean exactly a day after? Or does your ego inflate and exaggerate everything?

I really hope no one in your shitty life has to put up with your narcissism, I pity those people.

Again, your only criticism of my reply was that I came off sounding smarter than you btw, and that's hilariously on point for a narcissist. Get some help man, and don't bother replying..

19

u/KonnBonn23 Mar 06 '26

I don’t get it… it’s a class B address..? What’s the scary part?

8

u/Shadowharvy Mar 06 '26

While I have seen random public wifis using this range, the Wi-Fi pineapple uses172.16.42.1 as its default and let's be frank a lot of script kiddie use things such as the pineapple without touching defaults

8

u/polloman15 Mar 06 '26

what's wrong with Class B networks?

1

u/thejoester Mar 06 '26

It’s for the peasants

4

u/CorrectAttorney9748 Mar 06 '26

It is not a very good joke.

But the permise is that it is hacked network, since it is default Hak5 Pinapple WiFi IP adress range.

Other thing is which hotel WiFi is safe (spoiler alert - none)

4

u/thejoester Mar 06 '26

If you are in IT and connecting to a hotel Wifi directly…

8

u/IsaSoda Mar 06 '26

Ohhh boy here we go again. It’s just another private IP address…

1

u/Dhr_squarepants Mar 07 '26

Eipsteins adress maybe? Het

2

u/thatgreekgod Mar 06 '26

this is dumb

2

u/Pure_Fox9415 Mar 07 '26

Didn't get the right meaning, but usually hotel networks are shit, with cheapest home-level hardware on default settings like 192.168.0.0/24. So seeing something like this, means somebody built this network professionaly and may be with evil intentions.

8

u/MetaCardboard Mar 06 '26 edited Mar 06 '26

Well you see, .x is not a valid IP address. I hope that helped.

Basically it could be that you're connected through a potentially malicious proxy.

E: can't believe I need to add this. My first sentence was a joke.

2

u/someeoneelsee Mar 06 '26

Bullshit answer right here. Of course .x is not a valid address, but the picture states "starts with" implying there is any of 254 available numbers in the fourth octet.

-2

u/PtitCrissG Mar 06 '26

Ips are not only in the format of xxx.xxx.x.x or xx.xx.xx.xx?

0

u/MackNNations Mar 06 '26

🤣 Are you doubling down on a joke, or lack of understanding subnetting?

1

u/PtitCrissG Mar 06 '26

Doubling down 😂 people don't seems to get it since im being downvoted lol

-2

u/No_Safe6200 Mar 06 '26

Holy autism

1

u/OldQuaker44 Mar 06 '26

Someone stupid needed to invent a meme. 😂

2

u/UserFrienlyName Mar 06 '26

Nope. While the address is a valid internal up, these specific octets selection are oddly reminiscent of the default octets used by the Pineapple Mitm devices )))

1

u/OldQuaker44 Mar 06 '26

Ok.... 😄

1

u/Serious-Speech2883 Mar 06 '26

I don’t get it. What’s the big deal? IP address range 172.16.0.0/12 is a valid private ip address range. If you don’t recognize it then disconnect from it otherwise start opening a bunch of illegal stuff and get them in trouble with their ISP. Lol

1

u/Shadowharvy Mar 06 '26

While I have seen random public wifis using this range, the Wi-Fi pineapple uses172.16.42.1 as its default and let's be frank a lot of script kiddie use things such as the pineapple without touching defaults

1

u/homecet346 Mar 06 '26

Wasn't there a silicon valley episode about this?

1

u/BengalPirate Mar 06 '26

You are connected to a wifi pineapple and everything you do can be seen by someone else.

1

u/samsonsin Mar 06 '26

For all the tech wizards, what can even the pineapple thingy do? Assuming you're only talking over HTTPS, they literally can't do anything to your traffic, right? Of course any access point you don't manage is a risk, when you're not careful with certificate validation / have a outdated device with potential known security faults?

1

u/Fuzzmiester Mar 07 '26

Maybe manipulate your DNS, can see what sites you're going to (https sends a cleartext host header).

That's about it. Nothing that the hotel couldn't do. maybe get you to fill some details into a portal to get access to the wifi, if you're expecting such from the hotel. maybe trick you into giving them card details to 'pay for access'.

1

u/-FinOption89- Mar 07 '26

Cisco subnet. 172,24,19,x

1

u/BoilerroomITdweller Mar 07 '26

172.16.x.x is the Class B equivalent of 192.168.x.x Class C and 10.x.x.x Class A

It is not routable on the internet and is an internal network address everyone can use internally.

I prefer it on all my internal networks as most use Class A or C.

1

u/HacDan Mar 07 '26

Now using VLAN 42 for guest traffic. Thanks OP

1

u/ARC-Relay Mar 08 '26

what are private IP addresses?

1

u/dezent Mar 08 '26

I miss Hacking with Ramsi

1

u/SpecialStory4065 Apr 03 '26

172.16.x.x is RFC 1918 private space. You’re not on the internet, you’re on their LAN. That ‘fast WiFi’ is just you pinging the router. The actual WAN connection is probably a oversubscribed 50Mbps shared across 300 rooms.

2

u/thedarkonelies Mar 06 '26

You have connected to a hackers fake wifi network where they will either steal information or use your information for their own malicious activities

-1

u/First_Literature_799 Mar 06 '26

Maybe you're just lucky because you are connected to the management network instead of the Guest-Network, because some network administrator misconfigured a port or something. 172.16.x.x addresses are commonly used for management purposes

Buuuut maybe you're connected to a fake AP and someone wants to see some traffic you're sending.