Learn

Filter
CIA Triad - Confidentiality, integrity, availability

The CIA Triad: Confidentiality, Integrity, and Availability Explained

4 min read 761 words 2 months ago

Confidentiality, Integrity, Availability. Every security control exists to protect one of these. Here's what each means, with wireless attack examples for each pillar.

The CIA Triad: Confidentiality, Integrity, and Availability Explained

4 min read 761 words 2 months ago

Confidentiality, Integrity, Availability. Every security control exists to protect one of these. Here's what each means, with wireless attack examples for each pillar.

Red Team Exercise - Pentesting vs red team

What Is a Red Team Exercise? How It Differs From Pentesting

5 min read 1023 words 2 months ago

Red team and pentest are not synonyms. One is a technical audit with a defined scope. The other is adversary simulation with no guard rails. Here's when you'd use each.

What Is a Red Team Exercise? How It Differs From Pentesting

5 min read 1023 words 2 months ago

Red team and pentest are not synonyms. One is a technical audit with a defined scope. The other is adversary simulation with no guard rails. Here's when you'd use each.

BLE Pairing - How it works and fails

BLE Pairing and Bonding: How It Works and Where It Can Go Wrong

8 min read 1819 words 2 months ago

BLE pairing establishes encrypted sessions between devices. Just Works, Passkey, and Out-of-Band have very different security properties. Here's where each one fails.

BLE Pairing and Bonding: How It Works and Where It Can Go Wrong

8 min read 1819 words 2 months ago

BLE pairing establishes encrypted sessions between devices. Just Works, Passkey, and Out-of-Band have very different security properties. Here's where each one fails.

Firmware Updates - Matter for security tools

Why Firmware Updates Matter for Security Tools (And What Happens Without Them)

9 min read 1909 words 2 months ago

Mirai infected hundreds of thousands of IoT devices with no update path. Here's why firmware updates matter, and why a security tool without them is ironic.

Why Firmware Updates Matter for Security Tools (And What Happens Without Them)

9 min read 1909 words 2 months ago

Mirai infected hundreds of thousands of IoT devices with no update path. Here's why firmware updates matter, and why a security tool without them is ironic.

GATT Profiles - BLE device communication

GATT Profiles Explained: How BLE Devices Actually Communicate

8 min read 1754 words 2 months ago

GATT is the protocol that defines how BLE devices expose data and accept commands. Understanding services, characteristics, and descriptors is essential for BLE security work.

GATT Profiles Explained: How BLE Devices Actually Communicate

8 min read 1754 words 2 months ago

GATT is the protocol that defines how BLE devices expose data and accept commands. Understanding services, characteristics, and descriptors is essential for BLE security work.

WPS Vulnerabilities - PIN attack on routers

WPS Vulnerabilities: The PIN Attack That Broke Millions of Routers

8 min read 1893 words 2 months ago

WPS was designed to simplify WiFi setup. Stefan ViehbΓΆck's 2011 disclosure showed that its PIN validation is mathematically broken. Here's why, and why WPS should be disabled.

WPS Vulnerabilities: The PIN Attack That Broke Millions of Routers

8 min read 1893 words 2 months ago

WPS was designed to simplify WiFi setup. Stefan ViehbΓΆck's 2011 disclosure showed that its PIN validation is mathematically broken. Here's why, and why WPS should be disabled.

Penetration Test - Pentest vs real attack

What Is a Penetration Test? The Difference Between a Pentest and a Real Attack

6 min read 1235 words 2 months ago

A penetration test is scoped, authorized, and documented. One word separates it from a crime: authorized. Here's the methodology and why it matters.

What Is a Penetration Test? The Difference Between a Pentest and a Real Attack

6 min read 1235 words 2 months ago

A penetration test is scoped, authorized, and documented. One word separates it from a crime: authorized. Here's the methodology and why it matters.

How ESP32 OTA Updates Work: The Technical Story

How ESP32 OTA Updates Work: The Technical Story

9 min read 1956 words 2 months ago

HTTPS download, SHA256 verification, inactive flash partition write, boot pointer swap, rollback. The full OTA pipeline on ESP32.

How ESP32 OTA Updates Work: The Technical Story

9 min read 1956 words 2 months ago

HTTPS download, SHA256 verification, inactive flash partition write, boot pointer swap, rollback. The full OTA pipeline on ESP32.

Wardriving - History, tools, and today

Wardriving: The History, the Tools, and How It Works Today

8 min read 1791 words 2 months ago

Wardriving started in the WEP era and evolved into a passive WiFi mapping discipline. Here's the history, the tools, and what distinguishes legal passive wardriving from active attacks.

Wardriving: The History, the Tools, and How It Works Today

8 min read 1791 words 2 months ago

Wardriving started in the WEP era and evolved into a passive WiFi mapping discipline. Here's the history, the tools, and what distinguishes legal passive wardriving from active attacks.

WiFi SSID - Funny network names

WiFi SSID Trolling: A Brief History of Funny Network Names

8 min read 1813 words 2 months ago

From 'FBI Surveillance Van' to Rickroll mode - the culture of funny WiFi names, how AP spam lets you broadcast a whole list at once, and where it crosses the...

WiFi SSID Trolling: A Brief History of Funny Network Names

8 min read 1813 words 2 months ago

From 'FBI Surveillance Van' to Rickroll mode - the culture of funny WiFi names, how AP spam lets you broadcast a whole list at once, and where it crosses the...

Network Drops - Deauth attack alert

My Network Keeps Dropping: Could It Be a Deauth Attack?

9 min read 1989 words 2 months ago

Frequent WiFi disconnects could be interference, a bad driver, or an actual deauth attack. Here's how to figure out which one.

My Network Keeps Dropping: Could It Be a Deauth Attack?

9 min read 1989 words 2 months ago

Frequent WiFi disconnects could be interference, a bad driver, or an actual deauth attack. Here's how to figure out which one.

WiFi Channels Explained: 2.4GHz vs 5GHz and Why It Matters for Testing

WiFi Channels Explained: 2.4GHz vs 5GHz and Why It Matters for Testing

8 min read 1855 words 2 months ago

Channel overlap, non-overlapping channels, and why the ESP32's 2.4GHz-only design matters for wireless security testing. Everything you need to know.

WiFi Channels Explained: 2.4GHz vs 5GHz and Why It Matters for Testing

8 min read 1855 words 2 months ago

Channel overlap, non-overlapping channels, and why the ESP32's 2.4GHz-only design matters for wireless security testing. Everything you need to know.

Wireless IDS - Detect network threats

What Is a Wireless Intrusion Detection System (WIDS)?

9 min read 2022 words 2 months ago

How enterprise WIDS platforms work, what they detect, and how the BLEShark Deauth Checker acts as a pocket WIDS for individuals and small teams.

What Is a Wireless Intrusion Detection System (WIDS)?

9 min read 2022 words 2 months ago

How enterprise WIDS platforms work, what they detect, and how the BLEShark Deauth Checker acts as a pocket WIDS for individuals and small teams.

WiFi AP Spam - Disrupting real networks

Can WiFi AP Spam Disrupt Real Networks? What the Research Says

8 min read 1861 words 2 months ago

AP spam floods the spectrum with fake SSIDs, but does it actually block real traffic? The honest answer is more nuanced than most sources suggest.

Can WiFi AP Spam Disrupt Real Networks? What the Research Says

8 min read 1861 words 2 months ago

AP spam floods the spectrum with fake SSIDs, but does it actually block real traffic? The honest answer is more nuanced than most sources suggest.

WPA2 PMKID - Faster WiFi security test

The WPA2 PMKID Attack: A Faster Way to Test WiFi Security

8 min read 1783 words 2 months ago

The PMKID attack doesn't need a 4-way handshake capture or a connected client. Here's the math, the mechanics, and what it means for network security.

The WPA2 PMKID Attack: A Faster Way to Test WiFi Security

8 min read 1783 words 2 months ago

The PMKID attack doesn't need a 4-way handshake capture or a connected client. Here's the math, the mechanics, and what it means for network security.

Detect Deauth - WiFi attack detection

How to Detect WiFi Deauth Attacks on Your Network

9 min read 2120 words 2 months ago

Deauth attacks are easy to launch and hard to spot without the right tools. Here's how to detect them passively using the BLEShark Deauth Checker.

How to Detect WiFi Deauth Attacks on Your Network

9 min read 2120 words 2 months ago

Deauth attacks are easy to launch and hard to spot without the right tools. Here's how to detect them passively using the BLEShark Deauth Checker.

WiFi Shield - Stop deauth attacks

802.11w Protected Management Frames: Does It Stop Deauth Attacks?

9 min read 2064 words 2 months ago

802.11w adds cryptographic protection to WiFi management frames. It stops many deauth attacks - but not all of them. Here's exactly what it protects and where the gaps are.

802.11w Protected Management Frames: Does It Stop Deauth Attacks?

9 min read 2064 words 2 months ago

802.11w adds cryptographic protection to WiFi management frames. It stops many deauth attacks - but not all of them. Here's exactly what it protects and where the gaps are.

AP Spam - Beacon flood explained

Beacon Frame Flooding: How WiFi AP Spam Works at the Packet Level

10 min read 2169 words 2 months ago

How does one chip broadcast hundreds of fake SSIDs? The answer is in the 802.11 beacon frame structure and the ESP32's raw frame injection capability.

Beacon Frame Flooding: How WiFi AP Spam Works at the Packet Level

10 min read 2169 words 2 months ago

How does one chip broadcast hundreds of fake SSIDs? The answer is in the 802.11 beacon frame structure and the ESP32's raw frame injection capability.

ESP32 Showdown - Pick the right chip

Comparing ESP32 Variants: Original, S2, S3, C3, and H2

8 min read 1841 words 2 months ago

The ESP32 family has five main variants. Here's what changed across each one - and why the C3 is the right choice for BLEShark Nano.

Comparing ESP32 Variants: Original, S2, S3, C3, and H2

8 min read 1841 words 2 months ago

The ESP32 family has five main variants. Here's what changed across each one - and why the C3 is the right choice for BLEShark Nano.

WPA2 vs WPA3

WPA3 vs WPA2: What Changed?

9 min read 2052 words 2 months ago

WPA3 brings SAE, mandatory PMF, and forward secrecy. But deauth attacks still work. Here's what actually changed - and what didn't.

WPA3 vs WPA2: What Changed?

9 min read 2052 words 2 months ago

WPA3 brings SAE, mandatory PMF, and forward secrecy. But deauth attacks still work. Here's what actually changed - and what didn't.

Battery Power - BLEShark Nano endurance

ESP32 Power Consumption: How BLEShark Nano Lasts on Battery

10 min read 2157 words 2 months ago

Active WiFi transmit draws 240mA. Deep sleep pulls under 10uA. Here's how the BLEShark Nano manages everything in between.

ESP32 Power Consumption: How BLEShark Nano Lasts on Battery

10 min read 2157 words 2 months ago

Active WiFi transmit draws 240mA. Deep sleep pulls under 10uA. Here's how the BLEShark Nano manages everything in between.

Rogue WiFi - Fake networks uncovered

What Is a Rogue Access Point? How Attackers Use Fake WiFi Networks

9 min read 2114 words 2 months ago

A rogue AP is any access point operating outside your authorized network. Here's how they work, what attackers do with them, and how enterprise tools detect them.

What Is a Rogue Access Point? How Attackers Use Fake WiFi Networks

9 min read 2114 words 2 months ago

A rogue AP is any access point operating outside your authorized network. Here's how they work, what attackers do with them, and how enterprise tools detect them.

What Is Monitor Mode? How WiFi Packet Capture Actually Works

What Is Monitor Mode? How WiFi Packet Capture Actually Works

10 min read 2244 words 2 months ago

Monitor mode lets a WiFi adapter capture every frame in the air, not just ones addressed to it. Here's how it works and what the ESP32 can actually see.

What Is Monitor Mode? How WiFi Packet Capture Actually Works

10 min read 2244 words 2 months ago

Monitor mode lets a WiFi adapter capture every frame in the air, not just ones addressed to it. Here's how it works and what the ESP32 can actually see.

OLED Basics - Microcontroller display guide

How OLED Displays Work on Microcontrollers

9 min read 2130 words 2 months ago

How the SSD1306 OLED on the BLEShark Nano works - I2C, frame buffers, power efficiency, and why OLED beats LCD for small devices.

How OLED Displays Work on Microcontrollers

9 min read 2130 words 2 months ago

How the SSD1306 OLED on the BLEShark Nano works - I2C, frame buffers, power efficiency, and why OLED beats LCD for small devices.