Olliedawg Posted March 9, 2023 Posted March 9, 2023 We have a student which has decided to call their phone hotspot something rather racist and rude.. Is there anything I can do to stop this showing on other devices? Only information I have is the SSID & WiFi Address
Chuckster Posted March 9, 2023 Posted March 9, 2023 If you have Cisco Meraki you can isolate and block the offending SSID: https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal
Olliedawg Posted March 9, 2023 Author Posted March 9, 2023 If you have Cisco Meraki you can isolate and block the offending SSID: https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal No unfortunately.. We have Sophos XG Firewall & UniFi Network Onsite WiFi (self hosted). Can't seem to find any way to block it with either of these.
chazzy2501 Posted March 9, 2023 Posted March 9, 2023 this happened to us but unifi has a record of the mac address, so I could see previous names.. of the hotspot one being the pupils first name.
mavhc Posted March 9, 2023 Posted March 9, 2023 If you have Cisco Meraki you can isolate and block the offending SSID: https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal Is that doing anything other than sending deauth packets to clients that don't use protected frames? Won't it still appear on lists? What I would do is expel the student
Olliedawg Posted March 9, 2023 Author Posted March 9, 2023 Is that doing anything other than sending deauth packets to clients that don't use protected frames? Won't it still appear on lists? What I would do is expel the student Oh he/she will be in big trouble.. that is if we can find who the device belongs to.. I did try and search for the MAC address on the Student-WiFi network, but no luck..
RLR Posted March 9, 2023 Posted March 9, 2023 We've not come across any nasty SSIDs yet but we did have one broadcasting the name of a website with games on that wasn't being blocked.Once we saw it we blocked that website.
mavhc Posted March 9, 2023 Posted March 9, 2023 Oh he/she will be in big trouble.. that is if we can find who the device belongs to.. I did try and search for the MAC address on the Student-WiFi network, but no luck.. Use your APs to find the general area, then break out the wifi scanner app and track the via signal strength 1
howartp Posted March 9, 2023 Posted March 9, 2023 Oh he/she will be in big trouble.. that is if we can find who the device belongs to.. I did try and search for the MAC address on the Student-WiFi network, but no luck.. If they're apple devices, they'll be broadcasting private MAC addresses. However if you use Radius (eg NPS) you can see the Calling-Station-Id in the logs and back track it to the user that is/was authenticating from that Mac.
Olliedawg Posted March 9, 2023 Author Posted March 9, 2023 If they're apple devices, they'll be broadcasting private MAC addresses. However if you use Radius (eg NPS) you can see the Calling-Station-Id in the logs and back track it to the user that is/was authenticating from that Mac. Most likely will be an apple device, not 100% sure on that though. In my UniFi controller I can see the hotspot, which AP it is near along with the MAC address (possibly private like you say). If we had one AP in each classroom this would have made it easier to find
jthompson Posted March 9, 2023 Posted March 9, 2023 We had a similar thing a while back with a hotspot using the same SSID name as one from our UniFi APs. We monitored the timings of which UniFi APs were detecting it, and cross-referenced that with timetables to narrow down a list of student names. The MAC address also checked out as being a Razer phone, which narrowed that list down to one.
Popular Post LeMarchand Posted March 9, 2023 Popular Post Posted March 9, 2023 A non-technical solution might be an announcement about an unsuitable SSID being broadcast and that if it is not changed by the end of the day and time has to be wasted on tracking its source the there will be serious sanctions. I'd be tempted to get a bunch of beefy looking guys in suits/sunglasses to wander around "scanning" on their phones and tapping "earpieces"/mumbling into "wrist mikes" until you get a runner 7
David44 Posted March 9, 2023 Posted March 9, 2023 A non-technical solution might be an announcement about an unsuitable SSID being broadcast and that if it is not changed by the end of the day and time has to be wasted on tracking its source the there will be serious sanctions. I'd be tempted to get a bunch of beefy looking guys in suits/sunglasses to wander around "scanning" on their phones and tapping "earpieces"/mumbling into "wrist mikes" until you get a runner The school could report it to Ofcom as an obscene broadcast too.
jthompson Posted March 9, 2023 Posted March 9, 2023 A non-technical solution might be an announcement about an unsuitable SSID being broadcast I would be worried about a Streisand effect there. 3
LeMarchand Posted March 9, 2023 Posted March 9, 2023 I would be worried about a Streisand effect there. Good point.
Danp Posted March 9, 2023 Posted March 9, 2023 We have a student which has decided to call their phone hotspot something rather racist and rude.. Is there anything I can do to stop this showing on other devices? Only information I have is the SSID & WiFi Address It's their personal device, not something you/your school have set up. Pass this onto HoY, DSL and or Head and let them deal with it as a discipline issue and not an IT problem. 1
Olliedawg Posted March 9, 2023 Author Posted March 9, 2023 I would be worried about a Streisand effect there. Yes this is concerning me also. Going to let SLT know about it & go from there. Many thanks to everybody for the replies/suggestions
HTCPCP Posted March 9, 2023 Posted March 9, 2023 If the students move classes during the school day, you can probably track it down to a year group or class group by looking at what classes are in reach of the AP that you are seeing it there, and if groups are moved around, you should be able to work out which class it is, so then it's 30 or so kids you can then work on. If not, you can always (space permitting) move each class 1 at a time to a room on the other side of the school as a room change, and then even if they clock the reasoning for the room change, unless they stash their phone somewhere, then it's a case that either they will start broadcasting in the new location, or will not broadcast, either way you should be able to hopefully narrow it down to a class (being friendly with the person who manages these changes is always helpful). We did this to try and find which kid was using one of the portable hotspots back when I was in education, with the pretense of there needing to be some checks on mounts, cabling etc (old projectors) but in reality kids tend not to question it too much as we regularly had room changes throughout the school. Other options would be a "test wifi" which you can connect to, and enter your school email address to sign in (subject to that being something that you can do safely without them being able to access your own network), and hope they are stupid enough to fall for it? At the very least, it will give you a mac address and email address, but depending on your system, you may get a device name, device make and model etc. Don't publicise it (so if questions come up later, it was something for testing and hadn't realised it went live etc), but if a kid is doing something like that, the chances are they will look at what networks are available, and if there is an unsecured one then they may well try to connect
RedwayNetworks_Michael Posted March 10, 2023 Posted March 10, 2023 Yes this is concerning me also. Going to let SLT know about it & go from there. Many thanks to everybody for the replies/suggestions The SSID can be “attacked” by something like Cisco Meraki’s Air Marshal as another user mentioned (other WIPS are available). This works by sending deauthentication packets to the SSID, which can stop users from connecting and using this SSID. However this does not stop the SSID from being broadcast, so it is still visible. This may encourage the user to change their hotspot name. You may be able to track down the device to a specific area based on the RSSI (signal strength of the SSID). But this can be a time-consuming task and it’s often difficult to identify the user without them turning off their hotspot.
BKGarry Posted March 10, 2023 Posted March 10, 2023 I'd be tempted to get a bunch of beefy looking guys in suits/sunglasses to wander around "scanning" on their phones and tapping "earpieces"/mumbling into "wrist mikes" until you get a runner Now that would be an idea to get you closer to the person. WiFiMan (or something similar) on your phone. You know what AP is it near, you could play hunt the AP with the signal strength and get it down to it's approximate location, have a member of SLT with you, so you can go "I am pretty sure it is in that area" and they can then attack and scare into submission
dsmith8 Posted March 10, 2023 Posted March 10, 2023 If you're using GPO I believe you can Hide Specific SSID's Open the group policy console (Start > gpedit.msc > Enter) Go to: Computer Configuration > Policies > Windows Settings > Security Settings > Wireless Network (IEEE 802.11) Policies Click on "Action" in the menu and then click on "Create A New Wireless Network Policy for Windows Vista and Later Releases" Give the policy a name and a description Go to the "Network Permissions" tab Click "Add" and enter in the SSID you want to block and make sure "Permission" is "Deny" Uncheck allow user to view denied networks Click "OK" 1
David44 Posted March 10, 2023 Posted March 10, 2023 Fight fire with fire. Start broadcasting an even ruder SSID. Several of them. 4
LeMarchand Posted March 10, 2023 Posted March 10, 2023 If you're using GPO I believe you can Hide Specific SSID's Open the group policy console (Start > gpedit.msc > Enter) Go to: Computer Configuration > Policies > Windows Settings > Security Settings > Wireless Network (IEEE 802.11) Policies Click on "Action" in the menu and then click on "Create A New Wireless Network Policy for Windows Vista and Later Releases" Give the policy a name and a description Go to the "Network Permissions" tab Click "Add" and enter in the SSID you want to block and make sure "Permission" is "Deny" Uncheck allow user to view denied networks Click "OK" That definitely works (we use it to hide the Guest Network to discourage users trying to swap to it) but I imagine the OP doesn't want pupils seeing the offensive SSID on their phones. 2
Olliedawg Posted March 10, 2023 Author Posted March 10, 2023 Update : We managed to find the approximate location of the device broadcasting the SSID using a combination of the UniFi network controller & WiFiman. This narrowed it down to 4 classrooms. SLT went around and the student actually owned up to it! It was a year 7 student too which surprised me. I'm unsure on what was said/the disciplinary action taken.. although SLT have said it has been dealt with. Fingers crossed it doesnt happen again! Thanks to all who gave suggestions
BKGarry Posted March 10, 2023 Posted March 10, 2023 They probably thought it was just a bit of fun and didn't think about it. Which is a shame, but I am glad you managed to narrow it down. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now