12/16/2024

Wherever I am for any reason for more than 10 minutes, instead of sitting on social networks, I turn on the Wi-Fi analyzer and look at what is where
Working part-time in delivery, sometimes I turn on the wireless network scanner; at some point, I just stopped taking screenshots of what I saw.
Of course, there are no malicious intentions to cause any damage to people and businesses. I try to study technical and security issues from the outside because they directly relate to my work.
A vivid example, I took the children to the doctor for an examination. While waiting for the children, I connected to the guest network from my phone. For the sake of interest, I tried to go to the router’s web
interface; the router itself was hanging behind the TV, and I found the username and the password on the sticker. I told the girls at reception about the problem that they had a problem; as proof, I printed them a couple of sheets on their network printer and showed them a picture from their DVR. The backdoor password found on the network allowed me to log in to it. I don’t know if their situation has changed since then. We changed the operator, and we don’t go to that clinic anymore.
After that, I once discussed this topic with the local administrator. According to him, the most important thing is that the patient’s data is protected since almost everyone uses an application that runs in the cloud. All data between the computer and the server is encrypted, and their interception does not give an attacker anything.
I suggested that he consider the option that I, as an attacker, take a screenshot of the screen, and based on it, I make a template, after which I give the program to recognize the data according to the template, i.e. in which field is the first name, last name, address, phone, and the like. I.e. it is not difficult to parse the data from the image.
I did not convince him, but he admitted that the guest network should not give access to the main network.

It`s all strange …

Leave a Reply

Your email address will not be published. Required fields are marked *