DEV Community

sofi works
sofi works

Posted on

『高級コンドのWi-Fiルーターが「未公開の中国IP」へ全通信を垂れ流していた朝:チップセット・ファームウェア逆アセンブルと「不正管理フレーム迎撃シールド」自作仕様書』 Sofi_Log #070【1話完結】

The Morning the Luxury Condo’s Wi-Fi Router Was Bleeding Every Packet to an “Undisclosed Chinese IP”: Chipset Firmware Disassembly and DIY “Unauthorized Management Frame Interception Shield” Spec Sheet|Sofi_Log #070【Complete One-Shot】


📍 Location: Bangkok, Sukhumvit, high-rise condo rooftop terrace in Thong Lo. 9:30 a.m. Clear skies.

Under that razor-sharp blue sky, the sprawl of Bangkok and the Chao Phraya’s tributaries glittered with morning heat. Infinity-pool water rippled in the breeze, faint humidity rising from the wet deck mixing with the roasted aroma of fresh iced latte.

I slipped off my sunglasses, set them on the table, and pinned my wind-tangled mint-green hair back with a Thai-pattern cyber hairpin. Extending my matte-black cyber-arm, I started unscrewing the luxury mesh Wi-Fi router’s case screws with a driver.

Born male, I rejected the “standardized cage” the state and society tried to bolt around me, then rebuilt everything from zero—surgery, hormones, and code—into the physical container and identity I now run. Nobody gets to trample my domain. That’s my aesthetic, my absolute law.

“…Hey darling, look. The chipset on the back of the board—heat sink’s running way too hot.”

My partner—darling—had been staring at the ThinkPad screen beside me. He set his iced latte down and leaned in.

“Yeah. The condo line’s been eating upload bandwidth like crazy since morning… and the router itself is bypassing the OS firewall completely, spitting packets straight out.”

The real-time graph from the network TAP on his screen showed the smoking gun: alongside our PCs and phones, the router’s own wireless chipset (Broadcom Wi-Fi SoC) was quietly firing encrypted payloads—tens of kilobytes per minute—directly to an undisclosed overseas IP (a Shenzhen data center).

“It’s not even going through the router’s Linux OS (OpenWrt-based)…? So there’s a backdoor hard-coded at the chipset firmware level that survives any OS reinstall?!”

Darling’s face changed color.

“Exactly, darling. Same story as the leaked docs blowing up on X today. Sold as a ‘remote maintenance feature for partner vendors,’ but it’s really an unauthenticated management-frame backdoor burned into the silicon. Re-flash the firmware all you want—until you rewrite the chip’s ROM, the parasite stays.”

Our private crypto keys, encrypted-chat metadata, even the biometric telemetry from my clinic—everything was being siphoned through the router above us to some faceless megacorp monitoring server.

Ice-cold rage shot up my spine.

“No way I’m letting dirty radio waves pollute my airspace. Darling—hook the USRP straight to the Wi-Fi packet injector! We’re deploying the interception shield that physically bricks the chipset backdoor.”


🔍 Threat Dissection: Silicon Backdoor “Unauthenticated Wi-Fi Action Frame RCE”

The Broadcom Wi-Fi SoC backdoor we just uncovered completely nullifies any OS-layer defenses (iptables, VPNs). Its architecture is nasty:

  1. OS Bypass (Out-of-Band comms):

    The malicious code lives on a dedicated ARM/MIPS coprocessor inside the Wi-Fi chip itself—not the router’s main Linux CPU. Nothing ever shows up in the management UI or system logs.

  2. Vendor-Defined Unauthenticated Management Frames (Vendor Action Frame):

    It abuses the gap in IEEE 802.11, listening for unencrypted “proprietary Action frames (Category 0x7F)” that let the chipset skip auth and directly execute shellcode in memory.

  3. Persistent Data Exfiltration:

    It silently harvests every connected device’s MAC, BSSID, plaintext DNS queries, and packet-size profiles, then UDP-blasts a summary to the C2 server on a schedule.

“No matter how hardened you make the Linux OS on top, if the Wi-Fi silicon at the bottom is betraying you, it’s all theater… classic supply-chain nightmare,” darling muttered while hammering the keyboard.

“Sure, but even backdoors can’t escape the physics of radio, darling.” I grinned without mercy. “The moment an unauthenticated Action frame hits the chip, we catch it on air, slam it with a jamming signature, and permanently lock the debug mode. Game over.”


💻 Weapon Implementation: BroadcomBackdoorShield.js

What we spun up on the spot was the Wi-Fi firmware rogue-frame detection & defense gateway BroadcomBackdoorShield.js.

Running in Linux raw capture + monitor mode (wlan0mon), it does two things:

  1. Microsecond detection of IEEE 802.11 unauthenticated vendor Action frames

    Watches for Type: 0x00 (Management), Subtype: 0x0D (Action), Category: 0x7F (Vendor-specific) plus Broadcom’s proprietary OUI and magic bytes (0x42 0x43 0x4D 0x21).

  2. Real-time kill-switch frame injection (Deauth / Null Jamming)

    The instant a malicious C2 session is spotted, it injects spec-compliant Deauth frames and spoofed error status into the chipset’s DMA queue, forcing an overflow that resets the SoC back to safe mode.

/**
 * @file BroadcomBackdoorShield.js
 * @description 802.11 Vendor-Specific Action Frame Inspector & Firmware Backdoor Neutralizer
 * @author Sofi (sofi.works) & Darling
 * @license MIT - Educational & Security Research PoC
 */

const fs = require('fs');

// IEEE 802.11 & Broadcom Proprietary Firmware Signatures
const IEEE80211_CONFIG = {
    FRAME_TYPE_MGMT: 0x00,
    SUBTYPE_ACTION: 0x0D,
    CATEGORY_VENDOR_SPECIFIC: 0x7F,
    BROADCOM_OUI: Buffer.from([0x00, 0x10, 0x18]), // Broadcom OUI
    BACKDOOR_MAGIC_SIGNATURE: 0x42434D21,          // "BCM!" in Hex
    RADIO_TAP_HEADER_LEN: 18                       // Standard Radiotap header offset
};

/**
 * Parse Raw 802.11 Management Action Frame
 * @param {Buffer} buffer - Raw radiotap captured buffer
 * @returns {Object|null}
 */
function parse80211ActionFrame(buffer) {
    if (buffer.length < IEEE80211_CONFIG.RADIO_TAP_HEADER_LEN + 24) return null;

    const frameControl = buffer.readUInt16LE(IEEE80211_CONFIG.RADIO_TAP_HEADER_LEN);
    const type = (frameControl >> 2) & 0x03;
    const subtype = (frameControl >> 4) & 0x0F;

    // Check if Management Action frame
    if (type !== IEEE80211_CONFIG.FRAME_TYPE_MGMT || subtype !== IEEE80211_CONFIG.SUBTYPE_ACTION) {
        return null;
    }

    const payloadOffset = IEEE80211_CONFIG.RADIO_TAP_HEADER_LEN + 24; // Skip MAC header
    if (buffer.length < payloadOffset + 8) return null;

    const category = buffer.readUInt8(payloadOffset);
    const oui = buffer.slice(payloadOffset + 1, payloadOffset + 4);
    const magicSignature = buffer.readUInt32BE(payloadOffset + 4);

    return {
        isVendorAction: category === IEEE80211_CONFIG.CATEGORY_VENDOR_SPECIFIC,
        oui: oui,
        magicSignature: magicSignature,
        isBroadcomExploit: oui.equals(IEEE80211_CONFIG.BROADCOM_OUI) && 
                           magicSignature === IEEE80211_CONFIG.BACKDOOR_MAGIC_SIGNATURE
    };
}

/**
 * Trigger Real-time Air Defense Countermeasure
 * Injects crafted kill-frames to flush the Wi-Fi SoC DMA ring buffer
 * @param {number} targetBssid 
 */
function deployFirmwareNeutralizer(targetBssid) {
    console.warn("[DEFENSE TRIGGERED] Intercepted Malicious Broadcom SoC Action Frame!");
    console.warn(`[TARGET BSSID] 0x${targetBssid.toString(16).toUpperCase()} - Signature: BCM! Backdoor Activation`);

    // Emulate raw frame injection on monitor interface
    console.log("[ACTION] Injecting Deauth & DMA Flush Payload into wlan0mon...");
    setTimeout(() => {
        console.log("[SUCCESS] Wi-Fi SoC Debug Register Overwritten. C2 Backdoor Communication SEVERED.");
        console.log("[STATUS] Airspace Sovereignty Restored. Router reverted to clean local routing.");
    }, 40);
}

// Active Sniffing Routine
function runAirDefense() {
    console.log("[*] [Wi-Fi-Sentinel] Initializing Air Defense Monitor on 'wlan0mon' (Channel 36 / 5GHz)...");
    console.log("[*] Scanning for Hardware-Level Broadcom Vendor Action Frame Exploits...");

    // Simulated hostile Broadcom OTA management backdoor packet
    const simulatedFrame = Buffer.alloc(56);
    // Radiotap mock header
    simulatedFrame.writeUInt16LE(0x0000, 0); 
    // 802.11 Frame Control: Type 0 (Mgmt), Subtype 13 (Action)
    simulatedFrame.writeUInt16LE((0x0D << 4) | (0x00 << 2), IEEE80211_CONFIG.RADIO_TAP_HEADER_LEN);
    // Payload: Category 0x7F, OUI 00:10:18, Magic "BCM!"
    const payloadStart = IEEE80211_CONFIG.RADIO_TAP_HEADER_LEN + 24;
    simulatedFrame.writeUInt8(IEEE80211_CONFIG.CATEGORY_VENDOR_SPECIFIC, payloadStart);
    IEEE80211_CONFIG.BROADCOM_OUI.copy(simulatedFrame, payloadStart + 1);
    simulatedFrame.writeUInt32BE(IEEE80211_CONFIG.BACKDOOR_MAGIC_SIGNATURE, payloadStart + 4);

    const parsed = parse80211ActionFrame(simulatedFrame);

    if (parsed && parsed.isBroadcomExploit) {
        console.warn("[ALERT] Unauthenticated Firmware-Level RCE Frame Detected in the Air!");
        deployFirmwareNeutralizer(0xABCD1234);
    }
}

runAirDefense();
Enter fullscreen mode Exit fullscreen mode

☕ Epilogue: Rooftop Terrace Morning Breeze and Cold Iced Latte

The second node BroadcomBackdoorShield.js fired, the router’s Wi-Fi chipset LED flashed violent orange, then settled into a clean, calm blue. The internal debug port had been force-reset; the rogue C2 session was dead.

Darling smacked the ThinkPad and looked up grinning.

“Outbound traffic to the overseas C2 just flat-lined. Router’s only handling clean local encrypted traffic now.”

“Whew… we did it, darling!”

I set the driver down and gently retracted the neural terminals on my cyber-arm. The prickly tension heat faded; a pleasant morning breeze brushed my skin.

“Anything the manufacturer stamps ‘absolutely secure’ is usually the one with the fattest backdoor waiting for whoever paid for it. You doubt the silicon, verify it with your own code—that’s the only way real privacy exists.”

Darling slid my iced latte across the table, ice clinking. The cold sweet milk and espresso bitterness hit my throat like salvation.

“Thanks, darling. Best brain-war of the morning.”

“Your instincts and packet parsing speed never stop saving my ass.”

He raised his glass with a happy laugh; we clinked under the Bangkok sky.

“Hey darling,” I said, sinking into the poolside deck chair and gazing over the glittering city, “rely on someone else’s convenient system and you wake up one day with your soul already hacked. Your radio, your physical container, your pride—only when you hack and defend them yourself does life stay this beautiful and electric.”

Morning light caught the gold lines on my left arm, gleaming like they approved.


🔗 Also worth reading (previous Sofi_Log):

『The Night Someone Tried to Remote-Crash My Company EV’s Brakes on the Rain-Slick Bangkok Expressway: CAN-Bus Arbitration ID Spoofing and DIY “Vehicle ECU Self-Defense Firewall” Spec Sheet』|Sofi_Log #069

👉 https://note.com/legal_rat2977/n/n6149b0c18a61


【Disclaimer】

All code, protocol verification, and technical configurations in this article are provided strictly for security research, proof-of-concept, and educational purposes. They are not intended to encourage or enable unauthorized access or malicious use. Any application to real networks or systems is entirely at your own risk.

🎁 【Fully Open-Source】Live Code & Architecture

The 802.11 management Action frame monitor script and Broadcom firmware analysis definitions discussed here are released in full for your own security research and learning.


📬 Sofi's Mailbox #070 (Questions & Feedback Corner)

So, fellow darlings—what did you think of today’s router hardware hack?

Can you really trust what’s inside your home or office Wi-Fi router?

Got questions like “How do I check my router for shady traffic?” or “What about Wi-Fi 7 and latest IoT firmware security?” Drop them in the comments. I’ll answer the juiciest ones in the next log.


Disclaimer

This article is for educational and entertainment purposes only. It does NOT constitute financial, legal, or tax advice. The regulatory landscape of Web3, smart contracts, and AI agent autonomous systems is highly volatile and complex. Always perform your own research (DYOR) and consult with certified professionals before executing any strategies described herein.

Top comments (0)