ITJAY2023 Posted September 13, 2023 Posted September 13, 2023 We have a site which uses Netsweeper and there reporting as showed inappropriate searches, it turns out we have 3x Cello TV's which are connected to the Wi-Fi and are 100% confident in saying that searches from these devices aren't being manually made. Weirdly enough it ranges from explicit searches to even sites like tiktok, instagram and Steam. The steam searches are really strange as they are searching for players inventories. Has anyone ever seen anything like this before as the IP addresses of the Cello TV's / MAC address are 100% the ones searching for this.
Jawloms Posted September 13, 2023 Posted September 13, 2023 We have a site which uses Netsweeper and there reporting as showed inappropriate searches, it turns out we have 3x Cello TV's which are connected to the Wi-Fi and are 100% confident in saying that searches from these devices aren't being manually made. Weirdly enough it ranges from explicit searches to even sites like tiktok, instagram and Steam. The steam searches are really strange as they are searching for players inventories. Has anyone ever seen anything like this before as the IP addresses of the Cello TV's / MAC address are 100% the ones searching for this. Just to 101% confirm it's these devices, do the searches stop if you disconnect them from the network?
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Yeah it's 100% them, I got all three of the IP's off of the Cello TV, compared it to the live traffic reports and then also made sure on UniFi that the Mac Addresses was identical. As soon as I blocked Wi-Fi from all 3 of the Cello TV's the searches stopped. Really worrying stuff if the Android TV's are compromised.
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Can they act as hot spots? Nope already thought of that unfortunately, nothing is being broadcasted and the Cello Smart TV doesn't have that capability
Deanuk Posted September 13, 2023 Posted September 13, 2023 Mac spoofing? Have you disconnected them and the traffic stops?
mavhc Posted September 13, 2023 Posted September 13, 2023 Are the searches happening when the school is closed?
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Mac spoofing? Have you disconnected them and the traffic stops? Yeah completely disconnected them and it stops, completely created a new Wi-Fi SSID and removed the old one as well - - - Updated - - - Are the searches happening when the school is closed? Nope only when the Smart TV's were on, just honestly crazy never heard anything like it before.
tom_newton Posted September 13, 2023 Posted September 13, 2023 Have you got a network dump? Could it be these searches are being misidentified? I find it unlikely you're MiTM'ing the TVs, so misidentification of the traffic likely
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Have you got a network dump? Could it be these searches are being misidentified? I find it unlikely you're MiTM'ing the TVs, so misidentification of the traffic likely I'm not to sure what you mean sorry, Netsweeper reported live that 3 IP addresses which were the 3 Cello TV's were searching for Steam Inventories, Explicit searches etc I was watching it in real time and have reports regarding it
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Another thing which kept appearing on the searches on all 3 of the Cello TV's was TTProxy
filteringtech Posted September 13, 2023 Posted September 13, 2023 Any pupils nearby(ish) at the time?
mavhc Posted September 13, 2023 Posted September 13, 2023 I mean if the TV is on but there's 100% chance no one is there to manually do those requests
filteringtech Posted September 13, 2023 Posted September 13, 2023 Another thing which kept appearing on the searches on all 3 of the Cello TV's was TTProxy Implies trying to bypass filtering. It "smells" of pupils.
ITJAY2023 Posted September 13, 2023 Author Posted September 13, 2023 Implies trying to bypass filtering. It "smells" of pupils. Lads I promise you im not a end user, I was in front of one of the TV's and the IP of the TV was searching at the time. I believe someone has compromised all 3 of Cello TV's as there only android boxes and were using it as a proxy.
filteringtech Posted September 13, 2023 Posted September 13, 2023 Can you do Android password resets or set passwords if there are none? "If" they are compromised, the wifi password is likely compromised too.
dhicks Posted September 13, 2023 Posted September 13, 2023 I find it unlikely you're MiTM'ing the TVs, so misidentification of the traffic likely I'm not to sure what you mean sorry I think Tom means: unless you've added your filtering solution's own local HTTPS certificate to the 3 TVs so that you can examine their HTTPS traffic, most network traffic wouldn't even be examineable by your filtering solution these days. Netsweeper reported live that 3 IP addresses which were the 3 Cello TV's were searching for Steam Inventories, Explicit searches etc Something I've seen a few years ago, when Bing search was quite new: given a search term, Bing used to display the results, then do a background call to its server to pre-cache the results of the top-ten or so most popular results related to the current search. Even though the current search term was safe-search filtered, those top-ten results returned in the background weren't, but they still got seen as normal network traffic, so we got a bunch of reports of people using Bing who had searched for a nice, innocent term, then got that transformed into something less innocent. "Steam Inventories, Explicit searches, etc" sounds like it could be a similar top-ten-most-trending-searches or something that some web component on your TVs is refreshing somewhere in the background. 1
TechMonkey Posted September 13, 2023 Posted September 13, 2023 Are the Android bits of the TV locked down? Are there any odd apps installed?
tom_newton Posted September 13, 2023 Posted September 13, 2023 Can you share what the reports look like - my original comment was based on the fact that if we arent decrypting traffic from the TVs, i'd be interested to see what of note netsweeper had seen. May be some false positives in their rules
PotNoodleTech Posted September 13, 2023 Posted September 13, 2023 That's pretty worrying!! Have they been compromised, or were they compromised out the factory is the question!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now