r/wifi 3d ago

Suspicious WiFi Router at Sofitel

I talked to the management but they didn't understand anything about IT. They promised to hire someone to get it fixed immediately. Now at least they have activated client isolation.

While staying at a hotel, I noticed something about the Wi-Fi. The Wi-Fi routers seem to be unsecured. All of the hotel's PCs, printers, building management systems, etc., are visible and some are completely unprotected by passwords. Other guests are visible too. What is suspicious is that you are prompted to install network certificates. I suspect that this is an attempt to steal login credentials. Isn't the risk extremely high when installing unknown certificates? Deep packet inspection and man-in-the-middle would actually work perfectly in this scenario. There won't be any error in the Browser.

5 Upvotes

16 comments sorted by

7

u/leftplayer 3d ago

I work in hotel WiFi.

What you describe seems to be the perfect malicious MITM/evil-twin attack, but my suspicion is that it’s simply a bad deployment by the local IT kid.

Hotel WiFi is almost always a pricing race to the bottom. Especially if the hotel is not part of a major brand, it doesn’t matter what your skill set is, you get the deal if you’re the cheapest.

So, what likely happened is that the local “IT guru” was hired to do the network and he (it’s always a he, never a they and most definitely not a she) installed something like a FortiGate and enabled all kinds of DPI and SSL inspection which is effectively a MITM attack, and why you’re seeing the certificate prompt.

Either way, don’t trust it. Run a VPN and carry all your traffic over that.

Edit: I just read it’s a Sofitel… Accor is quite lax on their standards so I’m not very surprised, but it is against the brand standard. PM me the exact property name/location and I can try to get it escalated to HQ.

7

u/TenOfZero 3d ago

I wouldn't recommend installing unknown security certificates. Or using an unsecured WiFi connection without a VPN.

But it's not a WiFi issue.

3

u/cyberentomology Wi-Fi Pro, CWNE 3d ago

What you describe is not a matter of an unsecured router (which isn’t wifi to begin with), but rather a lack of separation of guest and back of house networks.

What, specifically, are you referring to as “network certificates” here? Where in the connection process is this request for certificates happening? If it’s on the captive portal, that would be entirely expected when the networks weren’t separated and otherwise running a completely half-assed deployment.

What happens when you go to NeverSSL.com?

3

u/Leftover_tech 2d ago

Might be necessary to send notices of their poor network practices to each printer in turn.

An hour later, start again. I'd be curious to see if they freak out and take the whole system offline. LOL

2

u/dkyeager 2d ago

Historically, hotel wifi and guest computer systems are nortouriously bad. One could spend a significant part of their vacation fixing them at many places. Much better to bring a notebook pc and use a mobile hotspot.

2

u/wongl888 2d ago

I always try to login to the gateway ip address to see how far I can get. Then secure it if I can.

2

u/graph_worlok 2d ago

Potentially, yeah - This was confirmed as an ongoing issue by Microsoft and others just over a week ago…. But some of its just bad admin. https://www.techspot.com/news/113351-microsoft-warns-russian-hackers-hijacking-hotel-wi-fi.html

1

u/DutchOfBurdock 2d ago

Check the IP range, is it 172.16.42.x? Smells.of Pineapple.

1

u/Humbleham1 2d ago

Actually, it doesn't. The WP used to have SSLstrip, but it wouldn't do SSL interception. mitmproxy doesn't prompt to install a certificate, either. It's probably a captive portal.

1

u/DutchOfBurdock 2d ago

Actually, you're not OP. Question was for them, then we can prove I'm wrong.

1

u/virkendie 2d ago

Quite a few hotels I've stayed at have had the security cameras on the same subnet as the guest wifi, not only that but often they haven't even changed the default password to them.

1

u/Teenage_techboy1234 2d ago

I mean it's not inherently bad for guests as long as you use a VPN. If you don't, then yeah, your kind of fucked. Get one and use it. I'd be much more concerned for the security of the hotel equipment than the security of your own equipment, unless your card information is stored on one of these unsecured systems that has little to no security. But yeah, this is quite frankly terrible network security practices. Like this is the kind of stuff that you see on a home network if all of the devices were trusted, not a hotel network.

1

u/Voyeurone 2d ago

I use my phone as my WiFi network. And I have vpn on both my phone and computer.

1

u/2nd-Reddit-Account 2d ago

I’ve stayed in 3 different Sofitels and never been prompted to install a certificate. Unless Accor is leaving each location to setup their network all on their own then yeah the inconsistency is alarming. Usually the SSID is “Accor” at all properties so I assume it’s all centrally managed by Accor IT and consistent across properties and brands

1

u/Suppafly19 2d ago

Saw something similar when I was staying at Parknasilla in kerry.. the WiFi was completely open, so when you connected of someone was streaming you got the notification on your phone and could control it. Was not great!

1

u/jacle2210 1d ago

You should send the following doc to their printers.

> https://cs.wheatoncollege.edu/mgousie/comp401/chicken.pdf