If anyone has any ideas on how to investigate this, I'm open to ideas. As of now, I've just blocked the internet access.
If anyone has any ideas on how to investigate this, I'm open to ideas. As of now, I've just blocked the internet access.
I run a local DNS resolver and so I capture all the lookup responses so that I can turn IP addresses back into names. Depending on what firewall/router you have, you may be able to log connections. I use a locally hosted free Gravwell process to grab these logs and correlate with the DNS queries to find which systems are talking to where. If your home network is like mine, then there are probably a bunch of systems that you want to block from talking outside.
Looking at my router log, the only web history request is:
2024-1-08 19:44:10 LG_Smart_Laundry2_open aic-common.lgthinq.com
This was likely after I had removed it from my main wifi and reconnected it to a segregated wifi. I don't see any logs for prior to this point.
Genuinely unsure what would be taking that much data though but honestly my first guess is a bug of some kind. Kind of wondering if the App has some sort of issue reporting page on it, might be worth sending in something about it. Might not get a response, it but could get some gears turning on their end behind the scenes.
1. Install Entware https://github.com/Entware/Entware/wiki/Install-on-Asus-stoc...
2. Then install tcpdump: `opkg install tcpdump`
From there, you can monitor any traffic going through your router.
Depending on the details in each of the layers[1] you might be able to spoof traffic towards it to trick it things.
you may need to try MITM the certs/key exchange stuff[2], hopefully they have a broken implementation that doesnt validate signatures etc.
[1]: https://www.bmc.com/blogs/osi-model-7-layers/
[2]: first promising hit when i googled: https://gbhackers.com/mitm-attack-https-connection-ssl-strip...