<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[This 12yrs Old Boy]]></title><description><![CDATA[<p dir="auto">I have been seeing this on Twitter about this 12yrs old hacker who can supposedly get one's WIFI password and screen shows what appears ifconfig print out. Sure, I don't broadcast SSID, yet curious how "poison" can implanted to affect WIFI and Bluetooth.</p>
<p dir="auto"><img src="/assets/uploads/files/1666561458050-screen-shot-2022-10-23-at-4.29.31-pm.png" alt="Screen Shot 2022-10-23 at 4.29.31 PM.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/175443/this-12yrs-old-boy</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Apr 2026 08:11:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/175443.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 23 Oct 2022 21:45:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to This 12yrs Old Boy on Tue, 25 Oct 2022 17:48:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> said in <a href="/post/1067805">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">https://twitter.com/CNET/status/1582763509623836673</p>
</blockquote>
<p dir="auto">I watched 22 seconds of this.<br />
it's not a hack of the your WAP password.</p>
<p dir="auto">It's decrypting the traffic after getting in. Which is usually due to poor SSID deployment, using weak passwords, etc.</p>
<p dir="auto">I was asked last year (and still haven't completed) by a higher up here at Netgate to write a blog post about securing your home WiFi and why firmware updates are important for all devices... I should get back to that.</p>
<p dir="auto">The issue here is manufacturers are building sub-par, poorly secured devices and selling them to consumers as a solution. Weak encryption is just that – weak.</p>
<p dir="auto">I've been doing WiFi design for more than a decade and these are the things I design against.</p>
]]></description><link>https://forum.netgate.com/post/1067807</link><guid isPermaLink="true">https://forum.netgate.com/post/1067807</guid><dc:creator><![CDATA[rcoleman-netgate]]></dc:creator><pubDate>Tue, 25 Oct 2022 17:48:17 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Tue, 25 Oct 2022 17:45:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/1067581">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">That 12 year old kid news nonsense was from what 2018?  Your just now finding it.</p>
</blockquote>
<p dir="auto">As I stated in the first post, it's an ad currently running on Twitter and no, I didn't hear of it back in 2018. Here's the ad link:</p>
<p dir="auto">https://twitter.com/CNET/status/1582763509623836673</p>
]]></description><link>https://forum.netgate.com/post/1067805</link><guid isPermaLink="true">https://forum.netgate.com/post/1067805</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Tue, 25 Oct 2022 17:45:36 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 15:33:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mcdvoiceo1">@<bdi>mcdvoiceo1</bdi></a> said in <a href="/post/1067592">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">sooner or later it will be fixed for sure</p>
</blockquote>
<p dir="auto">what will they fix, arp spoofing?  How are they going to do that - the are already protections against it.  static arp, or just plain L2 isolation for devices that shouldn't be talking to each other - like in the case of some public hotspot wifi network.. Your say a hotel in room 32 - in what scenario would you need to be able to see traffic to from room 46?  On a switch I can do port security so a specific mac can only be on a specific port, etc.. So bad guy can not plug in and say he is the same mac..</p>
<p dir="auto">So you have in your arp cache the mac aa:bb:cc:00::00:01 for IP 192.168.1.1 your gateway..</p>
<p dir="auto">Now that expires, and you arp hey 192.168.1.1 what is your mac, and some bad device answers hey the mac for 192.168.1.1 is aa:bb:cc:00:00:42</p>
<p dir="auto">How is the client going to know that is not legit?  And now he starts sending all traffic meant for the gateway to the bad guy..</p>
<p dir="auto">None of that stuff that kid was doing back in 2018 was new, or really any sort of new exploit or scare -- what made it slow news day news is he was 12.. And users are completely and utterly clueless to how any of their magic boxes work or talk to each other - so sure scare them and throw out some terms they have no clue to what they mean.. Its like watching star trek and they make up technobabble terms..  Can hack any of your password?  Click bait scare tactics for the sheeple.</p>
]]></description><link>https://forum.netgate.com/post/1067599</link><guid isPermaLink="true">https://forum.netgate.com/post/1067599</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 24 Oct 2022 15:33:27 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 15:15:42 GMT]]></title><description><![CDATA[<p dir="auto">mostly they are copying pros bugs and doing nothing new, sooner or later it will be fixed for sure</p>
]]></description><link>https://forum.netgate.com/post/1067592</link><guid isPermaLink="true">https://forum.netgate.com/post/1067592</guid><dc:creator><![CDATA[mcdvoiceo1]]></dc:creator><pubDate>Mon, 24 Oct 2022 15:15:42 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 14:22:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> said in <a href="/post/1067573">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">by practice don't broadcast SSID regardless</p>
</blockquote>
<p dir="auto">Which is completely utterly a waste of time, and back in the day listed in the top 6 dumbest ways to "secure" a wifi.. Broadcasting your ssid in no way shape or form ads any sort of security.. But what it does do it make it harder for you to join your own network.  Depending it could be even making your network more known, because devices always broadcasting for it..</p>
<p dir="auto"><a href="https://www.zdnet.com/home-and-office/networking/the-six-dumbest-ways-to-secure-a-wireless-lan/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.zdnet.com/home-and-office/networking/the-six-dumbest-ways-to-secure-a-wireless-lan/</a></p>
<p dir="auto">"SSID hiding: There is no such thing as "SSID hiding". You're only hiding SSID beaconing on the Access Point. There are 4 other mechanisms that also broadcast the SSID over the 2.4 or 5 GHz spectrum. The 4 mechanisms are; probe requests, probe responses, association requests, and re-association requests. Essentially, youre talking about hiding 1 of 5 SSID broadcast mechanisms. Nothing is hidden and all youve achieved is cause problems for Wi-Fi roaming when a client jumps from AP to AP. Hidden SSIDs also makes wireless LANs less user friendly. "</p>
<p dir="auto">That 12 year old kid news nonsense was from what 2018?  Your just now finding it.. Its a simple poison attack.. Im on the same wifi network as you - I tell you via an arp poison/spoof - hey I am the AP, or I am your destination or gateway.. send traffic to me to get to where your going, Look I can ask you for passwords, or I could do a mitm on where your trying to go, all kinds of things.. This is nothing new, this isn't some crazy new exploit to wifi or really any network..</p>
<p dir="auto">A normal good wifi network would be isolated so clients can not even talk to each other, or send arp traffic, etc.  So some other client on the same wifi network as you, wouldn't be able to talk to you.. This is L2 isolation..</p>
]]></description><link>https://forum.netgate.com/post/1067581</link><guid isPermaLink="true">https://forum.netgate.com/post/1067581</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 24 Oct 2022 14:22:10 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 14:01:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> Nothing as I by practice don't broadcast SSID regardless. However, yes I know it's an ad with hype, yet still curious as how he could reveal the password if true. He mentioned poison, not sure if that's a tool as in the video demo, he revealed the interviewer's Twitter login password. Any insight of possible methodology you could share?</p>
]]></description><link>https://forum.netgate.com/post/1067573</link><guid isPermaLink="true">https://forum.netgate.com/post/1067573</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Mon, 24 Oct 2022 14:01:48 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 01:59:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> said in <a href="/post/1067490">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">the kids statement that he doesn't join a WIFI he doesn't know</p>
</blockquote>
<p dir="auto">huh??  What does that have to do with anything?  So he doesn't join the wifi network at starbucks - what does that with you not broadcasting a SSID?</p>
]]></description><link>https://forum.netgate.com/post/1067495</link><guid isPermaLink="true">https://forum.netgate.com/post/1067495</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 24 Oct 2022 01:59:32 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 01:30:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> It in response to the kids statement that he doesn't join a WIFI he doesn't know but yes I know there are tools to discover hidden WIFI SSID.</p>
]]></description><link>https://forum.netgate.com/post/1067490</link><guid isPermaLink="true">https://forum.netgate.com/post/1067490</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Mon, 24 Oct 2022 01:30:44 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Mon, 24 Oct 2022 01:27:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rcoleman-netgate">@<bdi>rcoleman-netgate</bdi></a> I took a screen shot of the video ad on Twitter and of course it's hyped up to get clicks and seems to be promoting Cisco devices.</p>
]]></description><link>https://forum.netgate.com/post/1067486</link><guid isPermaLink="true">https://forum.netgate.com/post/1067486</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Mon, 24 Oct 2022 01:27:29 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Sun, 23 Oct 2022 22:19:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> said in <a href="/post/1067455">This 12yrs Old Boy</a>:</p>
<blockquote>
<p dir="auto">Sure, I don't broadcast SSID</p>
</blockquote>
<p dir="auto">That has zero to do with anything.. That hides your wifi from the 84 year old grandma across the street..</p>
]]></description><link>https://forum.netgate.com/post/1067458</link><guid isPermaLink="true">https://forum.netgate.com/post/1067458</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 23 Oct 2022 22:19:06 GMT</pubDate></item><item><title><![CDATA[Reply to This 12yrs Old Boy on Sun, 23 Oct 2022 22:02:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> you meant the stock image on your screen cap?  I wouldn't read into that one iota.</p>
]]></description><link>https://forum.netgate.com/post/1067457</link><guid isPermaLink="true">https://forum.netgate.com/post/1067457</guid><dc:creator><![CDATA[rcoleman-netgate]]></dc:creator><pubDate>Sun, 23 Oct 2022 22:02:46 GMT</pubDate></item></channel></rss>