NLC Lakeview Heist
Speaker: Stephen Symms
When students log into their campus portal, they aren't just checking grades—they are opening their entire digital identity, financial aid, and academic records. But how easy is it for a malicious actor to step in as the middleman? During his second semester, Stephen Symms did a class project and presentation that went over exactly this.
This talk breaks down a basic penetration test simulation modeled as a classic, multi-stage heist targeting a college campus wireless infrastructure. We will walk through the reconnaissance phase, evaluating the physical attack across campus grounds, before diving into the execution of a simple yet effective wireless exploit. Using accessible, pocket-sized hardware including the Wi-Fi Pineapple, Flipper Zero, and a custom Lilygo T-Embed running Bruce firmware, we demonstrate how an attacker can deploy a highly convincing, spoofed captive portal using social engineering triggers like malicious QR codes.
Going beyond the exploit, we map the entire attack surface against the STRIDE threat modeling framework and the CIA triad to analyze the systemic failures of open campus networks. Finally, we pivot to the blue-team defense, outlining how institutions can successfully mitigate rogue access points through WPA2 Enterprise deployments, multi-factor authentication, and active Wireless Intrusion Prevention Systems (WIPS). Attendees will leave with a practical understanding of rogue AP mechanics and the blueprint required to protect enterprise educational networks from becoming the next target.