Reverse engineering a mysterious UDP stream in my hotel (2016)
gkbrk.com
gkbrk.com
There is a useful tool called ‘binwalk’ that goes through a binary offset by offset looking for signatures like this. Don’t know if it would’ve worked here, but it’s pretty awesome for finding various data formats hidden in files, and was originally made for analyzing firmware files.
He was able to control lights from all the bedrooms in another hotel by putting his laptop between the tablets controlling the lights and the ethernet cables. Funny story, the IP adresses were assigned based on the bedroom number, eg the bedroom 714 had an IP of 172.16.20 7.14.
Edit: my bad, the second story was included in the French article but was written by another person, Matthew Garrett. Here is the story in English: https://mjg59.dreamwidth.org/40505.html
EDIT: Just saw your edit, ignore this one :P
I noticed something quite similar at my old residential block, where wifi was provided building wide. When you connected to the (open) WiFi network you were in a VLAN with all other unauthenticated devices. Attempts to access the internet directed you to a captive portal. After signing in (it was over HTTPS) you were then punted in to your own VLAN, where you could see all your other authenticated devices on layer 2. The system remembered your MAC so you only had to do the captive portal once
With wireshark you could figure out the MACs available on the network and use the signin of someone else when they were not online by using their MAC adress.
Staying in a Marriott in Oklahoma last week and my laptop joined the wifi. Captive portal said "welcome back Adam, click here to connect" WTF? How did they know who I am?
When connecting my phone I got a prompt to enter my room number / name and select higher speeds (which I get free for premium status) and saw the checkbox labeled "remember my device" ah, so, that's how they remembered me.
Did some digging and the last time I was in a Marriott was in 2019 (Thanks Pandemic!). In Tel-Aviv. Equal parts creepy and impressive and slick.
> By default, a network switch which is not configured to use IGMP will forward Multicast traffic to all switchports on the switch. Devices will be responsible for filtering out the traffic that they do not want to receive.
https://service.shure.com/Service/s/article/multicast-and-ig...
edit: seems the IETF are currently in process of deprecating any-source multicast and recommending people focus on keeping single-source multicast working well in as many networks as possible: https://datatracker.ietf.org/doc/rfc8815/
- Multicast frames caused our FDDI switches to reboot, had to filter everywhere those were used
- When setting up our local CoffeeCam, we used Multicast video stream -- this would have been accessable from anywhere (which would cause a security incident, no one can know when the Rear Admiral drinks coffee) so we were careful to monitor outbound advertisements and used a low TTL
- SDR, VIC, VAT, RAT, and all those other tools for doing multicast stuff worked but were very clunky
- NASA TV was broadcast over the MBone and times they would go to break in other broadcasts were continued to stream, I think various cameras were available
But really, this would just add one more layer of complication that doesn't buy you anything. It's not like this is security data. This is the kind of application where keeping it simple can help the reliability.
Is it not wonderful to find out by some hacking that elevator music is broadcast via UDP in the hotel? It's a fantastic project for a hotel room!
It's one of the caveats of bargain hunting. Sometimes you end up in sketchy situations.
This was when I discovered Samsung TVs have a menu option to scan for viruses, which I still think is hilarious.
P.S. Will we have horror movies based on Internet and IoTs, that would be very exciting.
There’s Demon Seed from 1977, an actual horror movie about too-smart devices.
The concept was then revisited in 1984 as a romantic comedy, “Electric Dreams”.
And home automation features briefly in Back to the Future II and The Computer Wore Tennis Shoes.
The TV was angled so that its IR sensor was aimed towards the bathroom door. I always assumed that it was just interference from the bathroom lights starting up just happening to make the same IR pattern as the ON button on the remote.
I once hooked a TV remote up to a logic analyser to have a look and here's how the on/off signal looked for this brand: http://olivernash.org/2010/01/03/the-telly-terminator/rc6-6-...
Some further details here: http://olivernash.org/2010/01/03/the-telly-terminator/
Of course it's still possible!
After two instances of jokers starting to stream something over it I just left it unplugged when I wasn't using it. My bad for introducing an insecure device onto the hotel wifi rather than setting up my own little network, but I was lazy.
> Let others control your cast media
> Show a notification on all Android devices connected to your Wi-Fi and let them control media casting from DEVICENAME
It’s come in handy, because our neighbors sometimes accidentally choose our Apple TV instead of theirs apparently. The only thing that happens on our side is that the TV turns on and displays the code, but our neighbors don’t see the code and likely realize their mistake then.
I wonder if it would be possible to multicast our own stream and get it played on the elevators. The malicious prankster in me thinks something along the lines of faked radio crosstalk where the other side is in the middle of a disaster. E.g. "This is $NAME of $MILITARY_RANK. The date is April 5, 2021. We have survived the April 4 nuclear attack at $CITY. Is anyone else out there?"
Thank you for documenting this kind of tinkering in a blog.
Added your feed to my RSS reader in the meantime
Reverse Engineering a Mysterious UDP Stream in My Hotel (2016) - https://news.ycombinator.com/item?id=16197436 - Jan 2018 (15 comments)
Reverse Engineering a Mysterious UDP Stream in My Hotel - https://news.ycombinator.com/item?id=11744518 - May 2016 (181 comments)
This is a perfect April Fool's day article!
But in all of this, IANAL, so I'm probably wrong.
By using multicast, the device playing the music can simply subscribe to the transmission and passively listen in.
I built a system once that used a bunch of inexpensive SBCs. Due to their physical location being close to users who could easily physically tamper with them; I placed them on my client network and treated them just like regular clients rather than putting them on a more trusted network. I'm not going to put a $50 IOT device on a subnet next to $10,000 servers. If you only have a handful of devices maintaining them is easier by throwing them in the least trusted tier and applying standard user monitoring rather than trying to micro manage them. The data they're dealing with is inconsequential to the operation of the business.
By the way I'm not talking about Chinese IOT devices with default root passwords and ssh enabled. I'm talking headless Windows clients.
So it seems like if you started sending multicast packets, the sound would be interleaved with the other stream. If you used a lower bitrate (they are using 192kbps) you could have a bigger piece of the playing time slice, since each of your packets would be a longer running snippet. Similarly, going mono vs stereo would extend that more.
Given that it's a hotel, lots of the devices probably have default admin passwords though, so shutting off the other stream is probably not hard :)