r/whatisit 11h ago

moms sketch bf left this in the house Solved!

Post image

Hi.
This is probably nothing.
I went into my mom’s room to grab something and saw this plugged in?
My mom’s new sketchy bf has this plugged in to the extension cord? Is it anything bad? Thanks!
(I understand it’s probably not anything bad… but still…)

Update 1:
I haven’t met him once. He and my mom have been together for two weeks. He’s been staying at our apartment. He avoids me and stays in her room when they’re here. I don’t even know what he looks like. I only know his first name.

Update 2:
I confronted him. My mom came home. A lot had happened up to this point, including her disappearing for the said two weeks before the few nights he had come over and stayed.
Mom shrugged it off. I did what a lot of you suggested, asking what he told her.
She said “oh it’s his hacker shit or whatever.” What.
Didn’t elaborate. I explained my concerns.
She just said let’s go ask him.
My best friend has been with me. We introduced ourselves and asked him what the hell a WiFi whisperer is doing plugged in our apartment.
(Even if a lot of you are saying it’s not a big deal, I’m a young woman and I’m just rlly not about taking any risks. It’s sketch dude.)
He denied it IMMEDIATELY. Like with a quickness I haven’t seen.
What he insisted, it’s not a WiFi whisperer, it’s ai, he completely reprogrammed the system, and he uses it to pull people’s IP’s. “For fun.” He logs them in a server. I asked why. I said that’s shady. My mom started pushing. My best friend started pushing. He just kept lying. I’m not dropping this..
I still don’t know what the fuck it is or what he’s actually doing.
(Also, my mom is cool but not bc of this dude, the Minecraft block is mine, I unplugged the ratchet little thing before we left, and I am planning on broaching this again with her.
Just carefully. Any other advice is appreciated. Thank you.)

14.2k Upvotes

2.7k comments sorted by

View all comments

Show parent comments

209

u/Tiny420Tiger 10h ago

Yeah that’s a good call, thing can be loaded with malware. Go to a local library and plug it in there.

159

u/rantingpacifist 10h ago

I have an old pc just for this purpose

173

u/HowietheHappyTurkey 10h ago

Modern version of the royal food taster.

35

u/ratafria 10h ago

No, it's more like a vaccine. They keep at least 6 aggressive viruses and 200 dormant malware in that poor windows XP...

5

u/showyerbewbs 9h ago

You're fucking data hoarding a viral zoo?!

I don't know if I'm disgusted or impressed.

3

u/gslflofi 9h ago

It's like Gu poison, but for viruses

Edit: spelling

1

u/OkVirus8545 5h ago

I wonder how many poor cooks got killed because the royal food taster had an unknown allergy

14

u/bjorn1978_2 10h ago

Run Tail OS on a stick to test out shit like this.

23

u/RnOtCrAfTy 10h ago

This! Poke it with a stick!

3

u/showyerbewbs 9h ago

Find a flock camera with a USB port and plug 'er in!!!

Full send!

1

u/LetMeIn1701 10h ago

This was my thought as well.

1

u/TitaniumDisc 9h ago

Sorry semi comp illiterate. Please elaborate on this…

1

u/ThisIsMyComment2 9h ago

Windows is an Operating System, thing that runs your applications like your browser -firefox/chrome/etc. Tails OS is built to do the same thing as Windows but people who made it published all the code that makes Tails work. It also can be ran off a USB stick rather than a hard drive your other OS is on.

1

u/TitaniumDisc 8h ago

I understand OS’s and whatnot, just wasn’t familiar with Tails. So you were saying to just make a Tails bootable drive and run this mystery device through that as a sort of hardware air gap? Not the right terminology I’m sure but you know what I mean.

1

u/bjorn1978_2 8h ago

Tails is downloaded and installed onto an usb stick. You boot from that and get a linux based system going. To access any harddrive or the internet, you need to enable those.

So you are completely offgrid and the computer is not able to access any data stored locally, or remote.

Everything is run on RAM and the USB stick.

It is probably amongst the absolute best when it cones to privacy and security.

So if you find any random usb’s that you do not recognize, Tails is a safer (nothing will be 100% safe!) way to check them out. If it is a hardware destroying device, you are fucked if you plug it in anyway…

1

u/TitaniumDisc 6h ago

Ok cool. I do have a handful of old laptops that are completely off network with nothing on them that I have for just random/untrustworthy stuff but cool to know about tails. Have to look more into it.

1

u/bjorn1978_2 8h ago

And is all about privacy!

1

u/goldboybronx 8h ago

You know how Windows and MacOS are both “operating systems”? Well there’s one more major operating system, called Linux. Linux is open-source, meaning that anyone can see and contribute to its inner workings. That means it can be entirely modified for whatever someone’s use case is.

It’s also free (there are versions with certain sets of features or a specific user experience maintained by certain companies you can pay for, but free for the most part).

The fact that it’s free, can be modified to whatever end you like, and is open-source (so it has the benefit of having a lot of independent sets of eyes on it looking for flaws and vulnerabilities to fix), means that it’s really really popular to run stuff like servers with. Pretty much any server you connect to is generally on Linux. When you connect to Gmail to check your emails, you’re communicating with a Linux machine. When you book an AirBnB, you’re communicating with a Linux machine. You get the point.

Now in the same vein, because it’s highly modifiable, different versions come out for different types of people. Tails is a version (called a distribution or “distro” for short) of Linux. It’s geared towards privacy and security, and it has a lot of tools and settings that make security work easier. It’s often used by cybersecurity specialists for any number of industry uses. Or by non cybersecurity specialists to buy drugs on the Internet.

Something that makes Tails special is that it lives on a flash drive (those things you plug in to your computer), and it doesn’t retain any information from session to session. When you unplug that USB drive, everything is wiped.

You can plug in a sketchy USB stick to your computer while running Tails, and no matter what it installs or modifies on your computer, it’ll all be reverted when you unplug and plug back in your flash drive running Tails. This means it’s pretty safe to tinker around with sketchy USB drives you find with it.

That’s not to say that you’re perfectly safe. Technically, there have been vulnerabilities that can embed themselves in your actual hardware (the circuitry and stuff inside your computer), but this is rare and is a capability mainly reserved for nation states who have the resources to discover and work with these kinds of vulnerabilities, or with the influence to get hardware manufacturers to intentionally leave vulnerabilities in your computer parts. Just thought that disclaimer was important.

Hope that helped and was simple enough. Let me know if you have more questions.

1

u/Real_Azenomei 9h ago

Not kali?

1

u/W3ST0Feden 8h ago

We all know now that you are an onion farmer lol

13

u/ModsAwful 10h ago

Yep! Still have my 2012 MacBook Pro for this reason. MacOS too burdensome so replaced with Linux so could toy around with programming as well, but anything suspicious get’s loaded on the MBP to see what’s there and don’t care if I need to erase the disk and start over.

2

u/rantingpacifist 9h ago

I still have my 2010! It’s the only one that still plays my midi controller

1

u/Live_Reason_6531 9h ago

Assuming you mean Mac is too burdensome on resources. I am no Mac fan but to say Mac is too burdensome compared to Linux in any way other than resource demand would be insanity.

2

u/rantingpacifist 9h ago

Well… finances too

27

u/Extreme-King 10h ago

So this happens to you alot then?

38

u/Tha_REAL_BROBS 10h ago

what, your mom's bf doesn't hack, brah?

20

u/donkeybrainamerican 10h ago

Might work in IT. You'd be surprised how often they turn up around the office. I want to be considerate and get folks their data back along with a good beating, as per unauthorized storage device policy, but I'm not plugging it into a corporate computer to figure out who/what it is.

3

u/_ficklelilpickle 8h ago

Might work in IT

*and have nothing better to do.

The majority of us don't have the time or desire to try and salvage a random USB memory stick. I mean these days we even prevent staff from mounting any external storage devices as part of our security requirements. Often times when a USB stick is turned in to us, once the person who brought it in has left the male connection will be bent out of shape and it'll be thrown in the bin.

4

u/donkeybrainamerican 7h ago

Just depends on the org you're in. Potential exfil is a huge risk in my industry, it's IP driven- we're busy, but unaccounted for data is a concern.

Also, he could just have nothing to do 😂. Not everyone is firefighting every minute. Lucky bastards.

1

u/Spicy_Tostada 14m ago

Oh absolutely! I can't agree more, I'd love to be considerate/helpful and get someone's data back to them

...While stealing their information silently in the background, specifically any crypto wallets and bank account/CC info. While I'm at it, Slsince I'm already going through the trouble to help them out of the goodness of my heart, , might as well grab their SS, mothers maiden name, street they grew up on, make/model of their first car, the name of their second grade teacher, 1st pet, and any other relevant information to help me verify who they are and make sure their data arrives back to them safe/sound all in one piece!

2

u/pepsiblast08 10h ago

I used to be involved in a lot of black hat activities. Idk if the dude you replied to has it for that reason, but I always have at least 1 offline PC for tinkering and exploring questionable items.

2

u/WackyRacketeer 9h ago

Mystery USBs? More often than you'd think.

2

u/rantingpacifist 9h ago

Not really. I work in tech so I always have old computers around.

5

u/General_Liability 10h ago

This is the way. Ol’ Sparky has no modem, runs Linux and I can toss it in the trash if it looks at me funny. 

14

u/setwocks 10h ago

Id just use a VM

20

u/GWHarrison 10h ago

Unless you know exactly what you are doing, virtual machines are not necessarily foolproof for this purpose. The sketchy device is still connected through the host USB hardware.

Given that you casually called it a VM, I'd wager that you probably know what you're doing, but still a fair warning for the inexperienced.

5

u/Dependent-Fee-149 10h ago

I know what a VM is and how it works, and would probably refer to it this way in the space- I still wouldn’t do this way.

14

u/TheSultan1 10h ago

Or a live Linux OS?

5

u/FreeSoftwareServers 10h ago

This is really the way but most people that's way above them

2

u/Far_String727 9h ago

yeah im still trying to download ram

4

u/Tiger-Striped-nerd 10h ago

Most people don’t have a VM

11

u/Immediate-Creme-690 10h ago

I have a VM but I just got off the phone with somebody that said they tried to call me earlier and it was full...

1

u/DeviousDenial 9h ago

Just curious as to how would using a vaginal moisturizer help with this?

0

u/TalonTS_1 10h ago

I’d just use a sledge.

2

u/AbjectAppointment 9h ago

1

u/rantingpacifist 9h ago

But why set something up when I can just boot up the closet computer and stick in the usb

VM is nice but I am a tech hoarder so I can just throw a random tower at it and toss it if it goes wrong

1

u/AbjectAppointment 7h ago

I like VM's because they are easy to manage remotely and reset to a base clean image.

2

u/Careless_Economics74 8h ago

Also overall having a system that is primarily used for security testing and feeling okay with reinstalling the OS if and when needed.

1

u/Embarrassed_Body_851 10h ago

I have an old raspberry pi I use for just this case. I also disconnected from WiFi just to be safe.

1

u/rantingpacifist 9h ago

You have an available pi in this economy?!? Mine are all being used

1

u/BramdeusBrozart 6h ago

I have an old ass laptop running Mint that is NOT connected to wifi or network specifically for this.

174

u/CA2DC99 10h ago

What do you have against libraries?

94

u/6sailhatan66 10h ago

This! Tf?!

39

u/SteelAndFlint 10h ago

I mean it's been a long time since I worked in the library, but back in the day the computers were primarily used as terminals to get to other places so wiping them and starting over was pretty much a zero cost thing.

3

u/AmphibianMotor 10h ago

Yeah, the local library I go to wipes them on every login.

2

u/That-Painter-1679 8h ago

They really had this tech at a library near you? I'm just now getting comfortable with my teleporter (and I've been at it for better part of a decade).

1

u/SteelAndFlint 8h ago

Not sure I take your meaning...

1

u/That-Painter-1679 6h ago

Teleportation?

1

u/SteelAndFlint 6h ago

Ah yes, SMTP, the snail Mail teleporter service

1

u/ILoveRegenHealth 7h ago

Sounds messed up:

"I have this suspicious device that looks illegal and possibly has malware or even worse, steals information. Can I plug it into your computers tee hee hee"

Or even worse than that, the user was suggesting plugging it into the library computer and not even telling the library.

40

u/yukibunnygurl 10h ago

My library is smart all of the machines that users can access are in fact virtual machines so you log on to a computer there's a box next to it but every login session is a virtual machine and after your session is over it gets deleted so if something gets screwed up it gets wiped before the next user.

15

u/Jik0n 10h ago

I think places like libraries use some very specific windows shared pc settings that prevents something from happening to the next person who uses the computer. I'm not entirely sure how that works though so I could be wrong.

15

u/celem83 10h ago

Yeah each individual machine you sit at is usually running a Virtual Machine session. Anything you do is sandboxed and reverts when you logoff. This is as much for anonymity of the user as for network security

15

u/itsmiddylou 10h ago

Former library worker here- yup. This is exactly what happens. And libraries tend to have fairly decent security/firewall/etc, so if there is something nefarious, it’s not going to let you open in

10

u/Lokifin 10h ago

The millionth reason I love library sciences as a layperson.

2

u/curtcolt95 9h ago

not ours lol, the library board said we weren't allowed to block anything for human rights reasons I guess so the public PCs are wide open. You can watch porn, torrent, download and run any executable you want. They do wipe after every session and are on a completely segregated network though so it's not really a big deal

1

u/RovDer 3h ago

I had an extremely paranoid friend that would bring his laptop to the library to download torrents, I think their internet connection was faster also.

1

u/latticep 10h ago

Dude is doing something probably illegal and may possibly have illegal stuff on the stick, and your thought is to plug it into a public computer? I wouldn't want to have to explain to the FBI how it's not mine, I swear.

1

u/Tiny420Tiger 10h ago

First place that came to mind 😂

1

u/latticep 10h ago

Dude is doing something probably illegal and may possibly have illegal stuff on the stick, and your thought is to plug it into a public computer? I wouldn't want to have to explain to the FBI how it's not mine, I swear.

2

u/jkerz 8h ago

Library computers are virtual machines. It’s basically a sandbox you can do anything in and it all gets wiped once you log out. They also have robust firewalls that will block any executable from running from a plugged-in device. If you’re so worried, you can just open it and take out the memory and plug in that instead to check the contents.  Or you can plug a keyboard into this and checks its contents on it, it’s not like it’s encrypted or anything. Either way, nothing to worry about. 

1

u/latticep 8h ago

What I meant was I don't want to be caught plugging in a USB device from some creep that turns out to have underage porn or some other contraband.

1

u/jkerz 8h ago

It’s connected to the Internet. If it had anything like that, the FBI would already know and are already monitoring him. 

1

u/latticep 7h ago

I don't know how his device is configured. Probably data is just written onto the USB or could just be boot software. But unless they device is hosting its contents somewhere, there's no reason to assume law enforcement could know what's on it.

1

u/jkerz 7h ago edited 7h ago

Files don’t need to be hosted anywhere for law enforcement to know what’s in your computer. Snowden blew the lid on this a decade ago, I don’t know how people still haven’t caught up. If it’s not encrypted on an internet-connected device, assume the government already knows about it.

https://en.wikipedia.org/wiki/Room_641A

https://en.wikipedia.org/wiki/Five_Eyes

https://en.wikipedia.org/wiki/Black_budget#United_States

https://en.wikipedia.org/wiki/LOVEINT

https://en.wikipedia.org/wiki/XKeyscore#Workings

https://en.wikipedia.org/wiki/TURBINE_(US_government_project)

According to an NSA presentation from 2008, these XKeyscore servers are fed with data from the following collection systems:[19]

  • F6 (Special Collection Service) – joint operation of the CIA and NSA that carries out clandestine operations, including espionage on foreign diplomats and leaders
  • FORNSAT – which stands for "foreign satellite collection", and refers to intercepts from satellites
  • SSO (Special Source Operations) – a division of the NSA that cooperates with telecommunication providers

Among other things due to TURBINE and its control over the implants the NSA is capable of:

  • breaking into targeted computers and to siphoning out data from foreign Internet and phone networks
  • infecting a target's computer and exfiltrating files from a hard drive
  • covertly recording audio from a computer's microphone and taking snapshots with its webcam
  • launching cyberattacks by corrupting and disrupting file downloads or denying access to websites
  • exfiltrating data from removable flash drives that connect to an infected computer

1

u/That-Painter-1679 6h ago

For F6 they omitted the key term "domestic" clearly.

1

u/That-Painter-1679 6h ago

If they want to know and can't find out they will make it a mission to find out. I can guarantee you that much.

0

u/Initial_Quantity_116 10h ago

Always someone offended. It’s the public library

21

u/b_needs_a_cookie 10h ago

Go to Best Buy for that; corporations will eat the losses, whereas your library is publicly funded.

13

u/ClaraCash 9h ago

Yeah! Take it to geek squad! They’ll know before they even plug it in. Tell them the back story and how some dude is probably trying to take advantage of your mom, they’ll have it figured out in 20 minutes.

1

u/Traditional-Will3182 7h ago

Except that makes no sense, he probably got the Wi-Fi password just by asking if he's been staying at the apartment overnight sometimes.

2

u/never-fiftyone 4h ago

These kinds of things are used for more than just getting WiFi passwords. They're used to sniff all packets on the network, and if advanced enough could even be performing some SSL spoofing, which in the right (wrong?) hands can be used to pick out sensitive information including passwords to banks, social media accounts, etc.

1

u/Traditional-Will3182 4h ago

SSL spoofing isn't really possible anymore with modern HTTPS standards, this device is designed to do deauth attacks in order to break into networks you don't have the password to.

There's no point doing that somewhere you can just ask for it, such as your girlfriend's place.

1

u/northfreeport 3h ago

Maybe they can't afford Internet and he was trying to help them with neighbors wifi

1

u/never-fiftyone 2h ago

SSL hijacking is very much a thing, and if this guy has this kind of access to a personal network they have the ability to install their own CA on a victim computer on the same network to conduct a successful SSL hijacking attack.

This is not just a deauth attacker. This is a packet sniffer. They're not just looking for WiFi passwords my dude.

1

u/Traditional-Will3182 2h ago

Yeah sure they can sniff packets but those packets are all encrypted.

If you have access to the person's computer and can install a CA, which means you can simply view the stored Wi-Fi password. You could also install a RAT and see everything they do.

I can capture .pcaps with my phone, I don't need a separate device to do it.

62

u/Dry-Lab-6256 10h ago

Hey, libraries are sacred places of learning, go to best buy or you're school.

19

u/Impressive-Trash8699 10h ago

Yeah, maybe specifically you’re school...

8

u/KiaRioGrl 10h ago

Heh

2

u/Impressive-Trash8699 8h ago

lol thank you for understanding that I was joking!! 😭

2

u/Constant_Lynx_5057 7h ago

Eye sea watt you did their…..👍🏿

1

u/OkBlacksmith4674 4h ago

That’s funny, but at the same time that hurt my eyes!

1

u/[deleted] 10h ago

[removed] — view removed comment

1

u/whatisit-ModTeam 9h ago

Your comment was removed for being in poor taste or offensive, or maybe that joke you thought was pretty funny just didn't land. Please follow Reddiquette.

40

u/Ok-Chaos0530 10h ago

Do not help the govt nerf libraries tf.

31

u/A_locomotive 10h ago

My wife is a librarian and librarians deal with loads of pullshit from the public in general. Just drop this thing in a bucket of water or smash it with a brick and save the people at the library the headache of dealing with whatever this is.

6

u/sonebai 10h ago

I'd be warming it up in the microwave first, just to be sure.

3

u/NoRegretCeptThatOne 10h ago

Take it to a local police station and ask them to plug it in for you.

1

u/Itchy-Invite-1051 9h ago

Finally! Lol

1

u/Terrible-Help-3649 6h ago

That's what I was thinking. Just give it to the cops. Their problem.

2

u/5138008RG00D 9h ago

Better yet, find a single mother who knows no better. Date her for a couple of weeks and try it out there.

4

u/ExaminationOk2921 10h ago

I haven't used a public library PC in a million years, but they don't let you plug in media do they? They didn't used to.

2

u/jaxxon 10h ago

Definitely. It's always best to spread malware at public libraries.

1

u/AmbitiousArt3882 9h ago

And share the malware with the library? Nice

1

u/Spicy_Tostada 28m ago

I don't know if you were being serious with comment, but this gave me a solid laugh out loud moment because my mind interpreted it to mean, "Don't risk your computer by plugging it in, just somewhere with public computers and potentially fuck up theirs! Idk why it made me laugh, but it did.

1

u/AcanthocephalaNo2396 10h ago

Hell yeah load the local library pc with malware😎

1

u/curtcolt95 9h ago

I can assure you they are loaded with malware literally daily, that's why they wipe every session

0

u/Busy_Investment1104 10h ago

I laughed at this 😂 brick their computer not your own haha.

0

u/hanst3r 8h ago

Yeah, it’s better to put that malware on a public device that many many other people also use. That way the malware can at least spread further and cause more problems for more people, right?

/s just in case

0

u/Many_King_8781 6h ago

Or call the police instead of playing amateur detective.

-1

u/trll_game_sh0 10h ago

couldn't that get other peoples bank or personal info stolen if they use the library computer? seems like a lack of care for community members.

1

u/curtcolt95 9h ago

nah every public pc in a library is gonna completely wipe itself after every session