Wall of Flippers Busts Flipper Zero BLE Spammers Red Handed!

Sdílet
Vložit
  • čas přidán 30. 12. 2023
  • After making so many videos about BLE Spamming with the Flipper Zero, I wanted to highlight an awesome community project, the Wall of Flippers!! After initially being created to collect the names of Flipper Zero's at Defcon, devs Kiyomi & Emilia added functionally to actually detect these BLE spammers so they can be found accountable!
    Did I mention that PCBWay can actually help you design your very own PCB's? No longer do you have to learn how to use complicated software to design your own, PCBWay can help you all along the way! Check out their services here! www.pcbway.com/design-service...
    Wall of Flipper GitHub : github.com/K3YOMI/Wall-of-Fli...
    OwlSec Discord : / discord
    -----------------------------------
    Check Out The Official Squachtopia Hangout Discord Server!:
    / discord
    -----------------------------------
    Support the Channel at my Patreon!!
    www.patreon.com/user?u=29290751
    -----------------------------------
    Follow me on Social Media!
    TikTok : / talkingsasquach
    Instagram : / talking_sasquach
    -----------------------------------
    Email the@talkingsasquach.com for Partnership/Sponsorship Inquiries
  • Věda a technologie

Komentáře • 129

  • @srh0e
    @srh0e Před 5 měsíci +11

    Thank you for the shout out! Your videos are legit a breath of fresh air so thank you for that. Oh, I won't go into anymore Apple Store with my Flipper ;)) (Hopefully).

    • @TalkingSasquach
      @TalkingSasquach  Před 5 měsíci +1

      Lol, I've been wanting to shout out you and your community for ages! Thanks for creating an amazing community!

  • @richland113
    @richland113 Před 3 měsíci +2

    Bought my flipper today after watching a few of your videos. Subscribed as well!

  • @user-zt2vf6vx7p
    @user-zt2vf6vx7p Před 5 měsíci +2

    In regards to the kernel access with your phone, how do you look into what access you can get? I was considering buying a $30 Nokia smartphone for Nethunter myself, but I would like full functionality.

  • @AlexeyPRG
    @AlexeyPRG Před 5 měsíci +3

    Kinda cool! But I see a few issues:
    1. It clearly says "Discover Flipper Zero Devices (Bluetooth must be enabled)". As Bluetooth connection is slow on Flippers, most people disable it.
    2. The name of the device can be changed, easily. An even if the address is not changeable one would still not see the device if you disable Bluetooth in settings.
    3. BLE spam creates new addresses all the time, as they are not the real one. So, you would be able to see that the attack is ongoing, but zero devices around.

  • @WillyJL
    @WillyJL Před 5 měsíci +8

    8:46 to be honest, BLE Spam is open source, could've just looked at how the packets are made lol. Or even just ping me, I have no problems explaining how my code works and what it does :D

    • @uhohretardalert3862
      @uhohretardalert3862 Před 2 měsíci

      Wow hey man I’m a huge fan of what you’ve created. I had a questions about creating custom text and images instead of just sending ‘apple pairing devices.’ Could you provide any insight on whether this is possible for iOS devices? Thanks man!

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci

      What's your discord

  • @CharlieBasta
    @CharlieBasta Před 5 měsíci

    Happy New Year Squatch!

  • @berend5766
    @berend5766 Před 5 měsíci

    Happy newyears dude!!! I would love to see an app of this on my phone to find other flipper users. Be sure to make a video on it if it ever happens and may everyone that reads this have an awesome 2024

  • @hhunnicutt4111
    @hhunnicutt4111 Před 5 měsíci

    I’m new to all of this and I love your content. Do you have any more suggestions on who to follow to become a master at the flipper zero?

  • @DEXV0
    @DEXV0 Před 5 měsíci

    Nice video sas keep ip the great work!

  • @Omega-uj6qz
    @Omega-uj6qz Před 3 měsíci +1

    I’d like to recommend keeping your rgb lights in the background on a solid color, Just to make your transitions just a little more seamless !

  • @IAmOrion
    @IAmOrion Před 5 měsíci +10

    I'll see if I can find it, but there's a thing where you can "compile" or "bundle" depending on your preferred terminology - a python script, it's environment, required libraries etc into a single EXE for windows or APP for MacOS and I believe something for Linux too. Also have the option to build a UI too!

    • @k3yomi
      @k3yomi Před 5 měsíci

      was thinking about that, I did update the documentation for the packages and such.

    • @k3yomi
      @k3yomi Před 5 měsíci

      In fact, I'll look more into that!

  • @zacharyruben1852
    @zacharyruben1852 Před 5 měsíci +4

    Man, its been a journey learning about all this stuff with you. Thanks for everything. You ever thought about doing some videos with the HackRf One Portapak??

    • @PLAYINSKILSSRT
      @PLAYINSKILSSRT Před 5 měsíci +2

      Right I modded the fuck outta some and ya thats way better than this but I use them together makes the flipper nice

  • @AWOK
    @AWOK Před 5 měsíci +7

    Such great talent in the community. Love to see new stuff like this. 🙌🏼

  • @MikeHawke410
    @MikeHawke410 Před 5 měsíci +3

    NGL I've been using Unleashed and I was at a NYE party with a friend and did the "Bex Toy" ble and she started convulsing and I knew it turned her toy on remotely it was hilarious. 😂😂

  • @lukasvolcik5109
    @lukasvolcik5109 Před 5 měsíci +2

    could wall of flippers be run on Flipper itself or more likely ESP32? That would be super cool to detect other flippers with your flipper :D I love that I can at least detect near flipper on windows, I might look into why BLE detection doesn't work.

  • @LJMOO7
    @LJMOO7 Před 5 měsíci +5

    This is amazing! It would be cool to get this as an actual app on the flipper for more portability. I don't know much about app development so this is just an idea. Again this is an awsome video.

    • @TalkingSasquach
      @TalkingSasquach  Před 5 měsíci +1

      Thats a really cool idea!

    • @WillyJL
      @WillyJL Před 5 měsíci

      Not possible, flipper only has the light BLE stack, it cannot see or discover other nearby devices

    • @oisin404
      @oisin404 Před 4 měsíci

      @@WillyJL Would it be possible with some sort of Bluetooth antenna or adapter in the GPIO?

    • @WillyJL
      @WillyJL Před 4 měsíci

      @@oisin404 if you are up to find a chip that can do that, build a board for it, then understand how it works, and write all the code for it on the board and flipper side, plus figure out how it's gonna show on the tiny flipper screen, sure it's possible. No one will ever do it however.

  • @nobodynoone2500
    @nobodynoone2500 Před 5 měsíci +2

    But does this work for Esp32, or SDR based devices? Flippers are not the most common device used in these attacks anymore.

    • @k3yomi
      @k3yomi Před 5 měsíci

      It's not just for flippers. The BLE based attacks should work and if not, a suspicious advertisement will popup with a total amount of mac addresses contributing to that advertisement. For the esp32 or SDR based devices. I have not tested but I will look into expanding into more technologies in the future. So far, there are 3 main ways of detecting the flipper through BLE. Name, Address, and Identifier. Code def needs some work as its a bit messy.

  • @DemocracyManifest-vc5jn

    Where do I get one of those transparent after market cases?

  • @dcriley65
    @dcriley65 Před 5 měsíci +1

    Happy 2024! Gonna get me a Flipper this year & take the plunge into my new career.

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci

      Your money would be better spent elsewhere if you want intro toys for cybersec

  • @weaverdreaming
    @weaverdreaming Před 5 měsíci +4

    I feel like the wall of flippers wouldn't be hard to counter. There are some signal jammer files for the flipper that have made rounds, but are federally illegal 👀

    • @jamesmckee9017
      @jamesmckee9017 Před 5 měsíci +4

      One flipper to jam and another to... Spam?

    • @k3yomi
      @k3yomi Před 5 měsíci +3

      yeah, can't really do much about that besides hope it doesn't happen. If someone is truly wanting to counter it, they would just turn off their bluetooth lol

  • @MyTube4Utoo
    @MyTube4Utoo Před měsícem

    It's sad, but as we all know, some people think that just because they 'can' do something, it's somehow okay for them to do it, screw everyone else.
    I'm old......old enough to remember the Tylenol "situation" in 1982 in the Chicago area. Whether someone just hated people, somehow thought it would be entertaining or whatever, it cost seven people their lives, including a 12-year-old girl. It's now unbelievable that we could have gone until 1982 with really no security methods in place, before something like that happened.

  • @k3yomi
    @k3yomi Před 5 měsíci +3

    Flipper Zero : Advanced Warfare

  • @daveduke8783
    @daveduke8783 Před 5 měsíci +3

    Apple patched the Bt attack weeks ago

  • @samuraidriver4x4
    @samuraidriver4x4 Před 5 měsíci +3

    If you are set on using your onboard bluetooth you might want to consider using a bootable usb stick instead of virtual.
    Then again there is always the option to get a dedicated machine and go bare metal.
    Be aware that kali lacks any security features and its not a daily driver OS.

    • @TalkingSasquach
      @TalkingSasquach  Před 5 měsíci +2

      All very good points! One thing to keep in mind is that I have to record everything, so while running a live OS does get around some of the issues with hardware, it does make it a lot more difficult to record.

    • @samuraidriver4x4
      @samuraidriver4x4 Před 5 měsíci

      @@TalkingSasquach don't know what you normally use but for example OBS runs perfectly fine on Kali.
      But that's indeed a valid argument.

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci

      And for anyone that doesn't believe they make kali broken on purpose, and doesn't want my screenshots, just ask yourself:
      Why is it that anyone with fingers that can use a kayboard can boot raspbian on a pi, apt install any tool, and roll.
      Yet somehow every release of kali requires 20 patches, nine fixes, alternate repo's, asshat workarounds and 4 hours of delving through forum posts to figure out how to fix the traps the kali team laid for you.
      It's a simple question: why is a "hacking distro" the hardest to use as a hacking tool? Further, why is EVERY noob that gets arrested running kali?
      You never hear about some 14 year old getting popped running pumpkin pi 3 in raspbian. It's always some noob running kali.
      Answer me this: why is it that in every rolling release of kali for years, the mac randomizer and the default installation of proxychainz turns themselves off and don't actually provide any op-sec until AFTER you fix them manually.

  • @InfoSecREDD
    @InfoSecREDD Před 5 měsíci +1

    I didn't know you totally switched methods when I told you about the kernels. 😂

    • @TalkingSasquach
      @TalkingSasquach  Před 5 měsíci +1

      The was no custom kernel for the TCL and i didnt want to wipe my Nothin!l ol

  • @Zardoz66
    @Zardoz66 Před 5 měsíci +2

    good info sas!

  • @UrRealestCritic
    @UrRealestCritic Před 5 měsíci +1

    This is why you only do this attack when is necessary

  • @SPUTNIK6996
    @SPUTNIK6996 Před 2 měsíci

    This on the steam deck would be epic

  • @chrome98
    @chrome98 Před 4 měsíci +1

    Will this work on a RasPi? Then I could go incognito mobile.

    • @TalkingSasquach
      @TalkingSasquach  Před 4 měsíci +1

      Yup! it was originally used on a RPI3 i believe

  • @russelladuddell40
    @russelladuddell40 Před 4 měsíci

    @TalkingSasquatch do you have a store?

  • @chelefrancia
    @chelefrancia Před 5 měsíci

    Mighty Sasquatch, I just got my Flipper, but I've got a question, and I'm pretty sure you can help me out. One thing that got me pumped about getting my Flipper is the idea that I could duplicate this UHF tag/sticker I have in my car. I've seen some info about needing a YRM100, but it's a bit confusing. Can I pull it off with different software, or do I need some new hardware? Thanks for your videos! 🤟🏻

  • @benjaminbraun282
    @benjaminbraun282 Před 4 měsíci

    found this channel last night after I was thinking about buying a flipper and have been absolutely ripping through all of your content. Very well made and very informative! loving it

  • @andrewd4916
    @andrewd4916 Před 5 měsíci +1

    im a noob dev but studying cyber at uni (already doing C and R programming). done a bit of python so im willing to give it a go

  • @leonbeck6668
    @leonbeck6668 Před 5 měsíci

    Can you please make a root tutorial for the nothing phone 1 I tried so many times and it didn't work

  • @cameronrich2536
    @cameronrich2536 Před 5 měsíci +1

    It can only find them with BT enabled yea?

    • @k3yomi
      @k3yomi Před 5 měsíci

      Correct, however - BLE advertisment spam detection would still work with BT disabled.

  • @gcmotive
    @gcmotive Před 3 měsíci

    I can't find the video you make from BLE spam MAIN. Because the xtreme firmware works ble spam but not for far away.. that video was way better. When you have time can you share the link.. thanks for everything. Happy valentines day. God bless you. 👍

  • @ncc74656m
    @ncc74656m Před 5 měsíci

    This might finally get me to get off my ass and set up Kali on the spare device I got from work (I keep giving away computers I get to take care of my people). Be kind of interesting to see if I can "meet" other Flippers on the way to work.

  • @pentestvegan
    @pentestvegan Před 5 měsíci +1

    bruh i my extra nothing phone 1 was a hastle to get out of bricking for a sec. i rooted, and installed custom majisk modules... so envemtually i hsd it in bootloop. it was a fun learning expierence but i did get it on the latest OTA and is back to factory working. but it was gonna be great...never got to use it though:(

  • @sideshow4417
    @sideshow4417 Před 5 měsíci +2

    TikTok hand gestures aplenty.

    • @brightlight3520
      @brightlight3520 Před 5 měsíci

      sasquatch is a hand talker apparently. maybe they are part italian

  • @seannewcomb7594
    @seannewcomb7594 Před 5 měsíci

    Good video, kinda wish we could have gotten to the 6:00 minute mark quicker though.

    • @LuxGamer16
      @LuxGamer16 Před 5 měsíci

      attention-span of a 5 year old

  • @andrewhodgkin11
    @andrewhodgkin11 Před 5 měsíci

    What did you use for a Bluetooth adapter?

  • @DirtyPlumbus
    @DirtyPlumbus Před 5 měsíci +2

    Who else is throwing this on their Uconsole? 👍

  • @Alasdair-Morrison
    @Alasdair-Morrison Před 5 měsíci +1

    God creates the Flipper Zero on one hand then tries to take it away on the other by taking away some of the fun it was deigned for....Must get me one.......

    • @LuxGamer16
      @LuxGamer16 Před 5 měsíci +1

      with great power come great responsibility. dont be skid!

  • @aimoannos8277
    @aimoannos8277 Před 4 měsíci

    Good shiat man! Also you must the first one ever to ls with dir in linux (5:20) x)

  • @Fallen012332
    @Fallen012332 Před 2 měsíci

    Shouldn’t this be easy enough to actually run on the Flipper itself?

  • @daviddavidson2357
    @daviddavidson2357 Před 5 měsíci +18

    To be fair, I'm surprised apple products don't just crash at random without help.
    Also android medical devices; that worries me. I'd expect a completely ground up custom OS, not some slightly modified Linux distro for mobile devices.

    • @j00500hall
      @j00500hall Před 5 měsíci +2

      Scary thought hey?! I can see reasons why they could be android based but really as a consumer hate the idea. I don’t mean to minimise anyone’s reliance on medical aids but I’m hoping it was more along the hearing aids lines of device than others that could be much more detrimental.

    • @samsunggalaxyS6-
      @samsunggalaxyS6- Před 5 měsíci +3

      imagine dying by a flipper

    • @MeGaLilCe5ar
      @MeGaLilCe5ar Před 4 měsíci

      This

    • @liverenders
      @liverenders Před 3 měsíci +1

      Unfortunately not.... As an IT for 7 years, most medical systems and devices operate on Linux, android, or worse.... Windows...often XP... Im not exaggerating. It's chilling.

  • @CyclingMikey
    @CyclingMikey Před 5 měsíci

    Ha! I'm one of those diabetics running Loop (google loop docs) and potentially vulnerable to BLE spam.

  • @bubblegumcombo2849
    @bubblegumcombo2849 Před 5 měsíci +3

    "If I wasn't able to fix [my insulin]"... congrats on restarting your device lol

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 5 měsíci

    I can't use my kali anymore RIP...

  • @DirtyPlumbus
    @DirtyPlumbus Před 5 měsíci

    Lol. I was just warning a new Flipper owner about this yesterday. Now I can send him your video.

  • @gomezleonardo60
    @gomezleonardo60 Před 5 měsíci

    Meanwhile Me in Guangzhou selling flippers to Americans

  • @feder-wg5kb
    @feder-wg5kb Před 4 měsíci

    Make this an flipper application

  • @MrGhost9640
    @MrGhost9640 Před 5 měsíci

    Minus a pine phone pro I've tried multiple phones I've set on one plus 7 pro 256 gb

  • @PLAYINSKILSSRT
    @PLAYINSKILSSRT Před 5 měsíci +1

    The newest update was garbage it downgraded my flipper and then my pc with all my files went into bootlocker mode fuck me right 😅

    • @k3yomi
      @k3yomi Před 5 měsíci +2

      Newest update of OFW? If so you slightly gave me a panic attack thinking it was my script if thats the case hahaha

  • @s.i.r.g3366
    @s.i.r.g3366 Před 5 měsíci

    Yay

  • @mikeielOFFICAL
    @mikeielOFFICAL Před 5 měsíci

    you should make your own Linux phone its actually really easy and so much better than having android or ios

  • @ricosuaveyatusabe9179
    @ricosuaveyatusabe9179 Před 5 měsíci

    Yeahhh

  • @mister6497
    @mister6497 Před 5 měsíci

    sup

  • @RetroCudi
    @RetroCudi Před 4 měsíci

    Eventually average Joe flipper users will be seen by using an app on iOS or Android. Game Over after that. It will ping your device as if it is an apple Air Tag. Like games there’s glitches and the developers see things get out of hand if they can’t patch it well they can deflect it. Use your flipper responsibly.

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci

      This makes no sense. Wall of Flippers isn't even a challenge. This entire story is hollow dude.
      This thing can only see a flipper if it's bluetooth is on. And it can't really foxhunt.

  • @kas.x_x
    @kas.x_x Před 5 měsíci +4

    damn, am i stupid or is that useless af? i mean cool u know the name of my flipper congrats for that but if im hiding it in my pocket how do u know that i am the owner of this flipper, if there r like 20 other people in that room? i personally dont use the ble spam btw it was just an example

    • @k3yomi
      @k3yomi Před 5 měsíci +2

      Someone can use a directional antenna and triangulate someone based off their Received signal strength indication. This data alone (with no fancy antennas) would be quite difficult to triangulate someone. However, with the right tools you could attempt. Bluetooth itself is hard to track but with the right tuning and tools. You would be able to accomplish it eventually. I did add other ways of detection a flipper which includes the Flipper name, Flipper Address, and the id corresponding to the flipper type (White, Transparent, or Black). Additionally, this project isn't really used as a mitigation tool but more of a fun project to mess around with. BLE Exploration is quite fun and once you start to learn it, it's hard to go back lol.

    • @kas.x_x
      @kas.x_x Před 5 měsíci +4

      @@k3yomi damn okay but if someone, with a hidden flipper, makes the apple crash and there is one person with like 30 antennas, i would be scared that those people think that the antenna guy made the phones crash and not any other dude with a hidden flipper u know.. but anyways i highly respect that work keep going!

    • @k3yomi
      @k3yomi Před 5 měsíci +1

      We slap a sign on the chest with the text "Flipper police" lmao
      All seriousness though, the phone crashsploit for iOS was patched a few weeks ago.

  • @kauht
    @kauht Před 5 měsíci +1

    I don't think this dude knows what skid means lmfao

    • @LuxGamer16
      @LuxGamer16 Před 5 měsíci

      oh, do tell!

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci

      ​@@LuxGamer16skid is short for [S]cript [KID]die.. which is exactly what squash is

  • @AI4IABETA
    @AI4IABETA Před 5 měsíci

    Lololol

  • @nothanks666
    @nothanks666 Před 3 měsíci

    I challenge you to do a video without moving your hands.

  • @Jpython2-oz1zj
    @Jpython2-oz1zj Před 4 měsíci

    How do we protect against this?

  • @Dtr146
    @Dtr146 Před 5 měsíci

    lol you dont even need a flipper anymore for ble spam. a random anroid phone can do this.

    • @k3yomi
      @k3yomi Před 5 měsíci

      Hence suspicious advertisement implemented. It does state once a ble method is found above: "These packets may not be related to the Flipper Zero."

  • @SuperRobotwarrior
    @SuperRobotwarrior Před 4 měsíci

    LOL there is something magical about hackers countering annoying/unethical hackers with hacks.

  • @mrcrazyadd2
    @mrcrazyadd2 Před 5 měsíci +1

    If you have wireless enabled at DefCon, that's on you 😂

    • @LuxGamer16
      @LuxGamer16 Před 5 měsíci +1

      what about ppl using medical devices?

  • @CatVSDog.
    @CatVSDog. Před 5 měsíci

    (:})-|--[

    • @k3yomi
      @k3yomi Před 5 měsíci

      Wall of Flippers is not fancy in terms of detection and also isn't necessary up to my programming standards. However, I'm always looking for improvements and criticism. :3

    • @CatVSDog.
      @CatVSDog. Před 5 měsíci

      Yeah I'm not a fan of c I like lua more@@k3yomi

  • @iyeetsecurity922
    @iyeetsecurity922 Před 9 dny

    Lol silly furries.

  • @BRAINROTcomps
    @BRAINROTcomps Před 5 měsíci +1

    Hold up, so someone almost sent a furry to the hospital with a flipper zero? pfft hahahahaha

    • @bru681
      @bru681 Před 4 měsíci

      Not funny. They could have died

    • @BRAINROTcomps
      @BRAINROTcomps Před 4 měsíci +1

      @bru681 lmao, a fate too kind for furries.

    • @bru681
      @bru681 Před 4 měsíci

      @@BRAINROTcomps furries are people too yk. Plus What have furries done to you

    • @BRAINROTcomps
      @BRAINROTcomps Před 4 měsíci

      @@bru681 nah furries are like one step up from p3d0s in the circles of degen hell

    • @IKER1000sYT
      @IKER1000sYT Před 4 měsíci

      ​@@bru681your pfp is worrying

  • @paigedoesnotexist
    @paigedoesnotexist Před 5 měsíci

    Spammnig phones can be a little funny until they use it as a medical device. Whoever attacked at the convention should be ashamed of themself.

  • @theactualparadox
    @theactualparadox Před 5 měsíci

    Devices like the flipper should really require some sort of license or a way to easily track anything they do back to them
    EDIT: I wrote this before starting the video, this is amazing!

    • @NewDiscord-hr3jj
      @NewDiscord-hr3jj Před 2 měsíci +1

      Imagine saying this.
      The second amendment covers ARMS. Cyberweapons are ARMS. The government has no right to regulate them.