One Device, One Hour: The Training Mission
The scenario opens with a diplomatic mission: two known criminals, Vera Unabite and Augustus St. Cloud, are staying at a nearby hotel. Confirming their identities requires evidence before any action. The catch: the agent’s luggage was lost in transit. Only a Flipper Zero remains. The Flipper handles sub-gigahertz RF (everything below 1 GHz), Wi-Fi via an add-on dev board, Bluetooth, infrared, NFC, and RFID. The scenario tests each capability against a real target in a hotel setting, inside one hour, with no additional equipment.
Wi-Fi MAC Tracking and Probe Request Intelligence
First stop is the hotel lobby at 1630 hours. A Wi-Fi scan surfaces “Verer’s iPhone” immediately, flagging a device linked to one target by name. The MAC address becomes a persistent tracking token. Separately, the Flipper captures probe requests: beacons the phone broadcasts for every Wi-Fi network it has ever joined. Cross-referencing those SSIDs against wigle.net reveals a preferred network named “Chateau St. Cloud,” which matches the second target’s surname. A deauthentication attack then knocks the device offline. Watching who reacts by grabbing their phone puts a face to the MAC.
Hotel Key Card Cloning via NFC
The target leaves a hotel key card and car key fob on a restaurant table. The Flipper’s NFC reader pulls data from the card in seconds. This card is a Mifare Classic, which has encrypted sectors. The stock Flipper cannot crack those keys in useful time (five days on device vs. minutes on a laptop), but publicly available default keys decrypt most sectors. The demo was filmed in a Washington DC hotel five blocks from the Capitol. With leaked keys applied, the Flipper emulates the card and opens the door.
Sub-Gigahertz Analysis and Vehicle Identification
Most car key fobs operate at 315 MHz, 433 MHz, or 900 to 915 MHz. The Flipper’s stock firmware lacks a spectrum analyzer, but one downloads free from lab.flipper.net. With it, pressing the fob’s lock button produces a visible spike identifying the exact frequency. The Flipper records the raw signal and replays it in the parking lot. A vehicle flashes its lights. That’s the target’s car. The speaker deliberately replays only the lock signal, not unlock, to avoid advancing the rolling code counter and alerting the owner.
Building a Target Package from Collected Signals
After one hour, the Flipper has built a target package from passive and active collection. The MAC address matches one HVI. License plate reader data ties the vehicle to soft targets in the host nation. A credit card read via NFC surfaces an alias, confirmed by an FBI report linking that card to purchases. Collected deauthentication pcaps contain EAPOL packets with hashed Wi-Fi passwords. An ESP32 chip programmed with a whitelist of MAC addresses can serve as a sigint tripwire, alerting in near-real time when a target re-enters range.
Notable Quotes
getting mad, that is my person. Langston Clement · ▶ 10:52
Remember, don’t be a criminal. Langston Clement · ▶ 16:47
Ask me how I know. Langston Clement · ▶ 22:26
Key Takeaways
- Wi-Fi probe requests expose every network a device has ever joined, enabling historical location mapping
- Mifare Classic hotel key cards can be cloned with a Flipper Zero using publicly available default sector keys
- Replaying a car key fob’s lock signal (not unlock) identifies the vehicle without alerting the owner
- Credit card NFC data yields account numbers, expiration dates, and names for intelligence correlation
- MAC addresses collected across Wi-Fi, Bluetooth, and NFC form a persistent tracking token for a target
About the Speaker(s)
Langston Clement has over fifteen years of public and private sector cybersecurity experience. He began in signals intelligence and digital network intelligence before moving into special operations work focused on offensive security. His specializations include modern social engineering, wireless and RFID attacks, vulnerability analysis, and physical penetration testing.
Dan Goga is a Principal Consultant at NRI, conducting penetration testing and vulnerability assessments. He has eight years of information security experience across public, private, and academic sectors, with extensive knowledge of RFID hacking, phishing, social engineering, and penetration testing.