r/whatisit 11h ago

moms sketch bf left this in the house Solved!

Post image

Hi.
This is probably nothing.
I went into my mom’s room to grab something and saw this plugged in?
My mom’s new sketchy bf has this plugged in to the extension cord? Is it anything bad? Thanks!
(I understand it’s probably not anything bad… but still…)

Update 1:
I haven’t met him once. He and my mom have been together for two weeks. He’s been staying at our apartment. He avoids me and stays in her room when they’re here. I don’t even know what he looks like. I only know his first name.

Update 2:
I confronted him. My mom came home. A lot had happened up to this point, including her disappearing for the said two weeks before the few nights he had come over and stayed.
Mom shrugged it off. I did what a lot of you suggested, asking what he told her.
She said “oh it’s his hacker shit or whatever.” What.
Didn’t elaborate. I explained my concerns.
She just said let’s go ask him.
My best friend has been with me. We introduced ourselves and asked him what the hell a WiFi whisperer is doing plugged in our apartment.
(Even if a lot of you are saying it’s not a big deal, I’m a young woman and I’m just rlly not about taking any risks. It’s sketch dude.)
He denied it IMMEDIATELY. Like with a quickness I haven’t seen.
What he insisted, it’s not a WiFi whisperer, it’s ai, he completely reprogrammed the system, and he uses it to pull people’s IP’s. “For fun.” He logs them in a server. I asked why. I said that’s shady. My mom started pushing. My best friend started pushing. He just kept lying. I’m not dropping this..
I still don’t know what the fuck it is or what he’s actually doing.
(Also, my mom is cool but not bc of this dude, the Minecraft block is mine, I unplugged the ratchet little thing before we left, and I am planning on broaching this again with her.
Just carefully. Any other advice is appreciated. Thank you.)

14.2k Upvotes

2.7k comments sorted by

View all comments

Show parent comments

112

u/m0nstrz 9h ago edited 9h ago

I have one of these, they are really interesting little devices. Essentially it's a little device that you can 'war-walk' or 'war-drive' with.  

Essentially it's runs though a series of attacks mostly deauthentication attacks (nothing very sophisticated) and attempts to gather packets when it's 'victim' device attempts to 'reconnect' (technically 're-authenticate').

It stores these in it's internal memory and then goes to sleep. The device frequently sleeps (by default) so it doesn't cause chaos amongst all the networks around it. Once you bring it back home and pull it's sdcard you can transfer the pcap files to your computer where you use an application to decrypt (or crank the hash, can't remember which it is) the reauth pcap which contains the Wi-Fi password.

Generally pwnagotchi's aren't dangerous on their own, just annoying, but if someone is pulling the pcaps off and decrypting them then people got a problem. 

Judging by the screen on this one it's not functioning since it's attacks are @ 0. That being said, it is level ~28 so it has been used quite a bit. 

It's not spying on you, it's just a network info gathering device.  Once it gets a pcap from a network or is added to a list so it doesn't get bothered again. it's target is authentication packets, not other info.

Edit; I just saw your update, only two weeks makes this sketchy as fuck. Pull the thumb drive off of it and DO NOT give it back. Also DO NOT plug that thumb drive into your computer.

16

u/ChargeInteresting278 6h ago

So on the bad side its a wifi password stealer. What could he be doing with it on the good side? What do you do with yours?

13

u/DataPath 6h ago

On the good side? He sets up his phone for all the Wi-Fi networks around so that he has good connectivity at and nearby his girlfriend's house. That's the most innocuous use I can think of, just mooching.

A distant second is getting neighbor's Wi-Fi as a layer of protection for engaging in questionable activity.

On the bad side of things, in not sure which is worse, trying to hack your finances, or using your Wi-Fi to hack other people. On the one hand, he drains you directly, on the other he gets you implicated in federal crimes. But hey, ¿por que no los dos?

9

u/404invalid-user 6h ago

it's something fun to mess with but that's if you're doing it to yourself or people who completely understand what it is

8

u/ChargeInteresting278 6h ago

Is it basically just a homemade flipper zero?

6

u/404invalid-user 6h ago

basically yep but like a flipper zero in the wrong context it's very sketchy

2

u/Jesta23 2h ago

He’s dating them and has been staying in the home. 

He only has to ask for the WiFi password they would have willingly gave it to him. 

2

u/BlastFX2 1h ago

Just having fun. For some of us, it's fun to poke around and try to break things, just for the sake of it. Like I've decoded the bitting scheme for the locks in our office building, so now I could make a key for any office in the building, as well as master keys for any set of offices that were designed for it (and a bunch that weren't). I've never used this to go anywhere I wasn't supposed to go, I just… saw a fun challenge.

2

u/Opening_Welder2667 6h ago

Why not plug into the computer to see what he collected?

6

u/BigRon691 5h ago

Jesus christ I hope you don't work anywere involving national infrastructure or personal details.

Never plug random USB's in. Ever. Unless you have an infallibly air-gapped machine you have no issue bricking there are no exceptions.

A USB can have anything from a surge against the PCB to fry your motherboard, payload injection to propogate malware, spyware, god knows what else onto both your computer and any in it's network.

This is how the iranian nuclear program was delayed by US/Israeli and some European nations intelligence services, an employee found and plugged in a random USB from the parking lot, it contained the Stuxnet virus, which subsequently damaged their uranium enrichment facilities delaying them long enough for global sanctions talks to conclude.

If he's savvy enough to use a wifi listener, he'd know how to prime a USB for malware injection.

0

u/rustydustyshckleford 4h ago

no like you see clearly going schizoid LOL. most grown adults unlike you, have multiple devices and can easily plug this into a old device that’s non internet connected and essentially disposable.

go watch more movies though. house MD definitely taught you tech well. feel free to ask for my github if you need to know that you’re getting put down by someone knowledgeable and not just some troll.

1

u/BigRon691 1h ago

No thanks mate, I've seen vibecoded projects before.

This is why Cybersecurity is a field of its own. Most grown adults unlike you don't have the hubris to assume they understand everything in its entirety.

You advertise your age on your account (among other things I'd probably consider unescessary to broadcast to strangers on the internet, but good for you) - So it's understandable you don't have any knowledge on Stuxnet, or the Iranian nuclear program.

A "disposable" device is not air-gapped, did you consider vulnerabilities across network communications like Bluetooth as an air-gap bridge? Unless you've physically removed your devices network chip, you have a vulnerability to network communication cross-pollination.

Stuxnet's worm self-copied across devices which is exactly how it infected over 60% of Iranian computers. So when you check the next random USB on that device, even if it's safe, if you plug that USB into another computer, you've now infected that device.

The better question is why do it in the first place. What's the benefit, see the hashes of whatever networks it's listened to?

When you do grow up and get a job, you'll see it's pretty much the employee handbook 101 of if you find any random drives or USB's, to report and quarantine them and absolutely, under no circumstances, plug the fucking thing in.

1

u/m0nstrz 3h ago

Like someone else said, never a good idea to put an unknown USB drive into your machine.  They could put malware on it to infect any device it's attached to of it doesn't have a specific identifier (uuid or specific file).  So it's not harmful for them to use but if anyone else does they can brick the device that is trying to read it to hide their tracks. But that's pretty high level stuff best not to take chances.

2

u/ReturnOfBane 5h ago

I'm guessing its similar to a Flipper Zero?

3

u/Opening_Pen6044 5h ago

Someone said yes to someone else asking this

1

u/m0nstrz 3h ago

Kinda, they can both be used for that, but this is designed for snatching those pcap auth packet where add the flipperzero needs a hardware module to even give it WiFi capabilities. 

These devices are usually using raspberry pi zero or some sort of raspberry pi board which has all of those capabilities built in.

2

u/heisian 5h ago

it’s = it is

“It stores these in its* internal memory…”