Layer 2 Liberation: Things Your AP Never Dreamed Of
Allan Riordan Ball
RF Village @ DEF CON 33 · Day 1 · RF Village
Overview
Allan Riordan Ball's talk, "Layer 2 Liberation: Things Your AP Never Dreamed Of," presented at RF Village, delves into the fascinating and often overlooked realm of raw 802.11 frame manipulation. The presentation explores how one can bypass the conventional complexities and overheads of standard Wi-Fi protocols – such as access point association, retransmissions, and higher-layer security – to achieve direct, low-level communication between Wi-Fi-enabled devices. Ball describes this pursuit as "for fun and certainly not profit," emphasizing the experimental and unconventional applications rather than immediate practical utility in typical networking scenarios.

Key moments
- 0:00 Introduction: Low-level Wi-Fi, beyond access points
- 1:30 Achieving raw 802.11 frames with sockets or Scapy
- 2:00 Overview of projects: File Drop, Walkie-talkie, Meshtastic, Wi-Fi FS
- 3:00 Barebones transmit/receive demo: 'Hello World' via raw sockets
- 4:20 Simplifying raw frame transmission with Scapy Python library
- 5:00 Introducing 'File Drop': Airdrop-like transfer without an AP
- 7:00 File Drop demo: Sending image, demonstrating packet loss and retransmission
Layer 2 Liberation: Things Your AP Never Dreamed Of
Speakers: Allan Riordan Ball
Conference: RF Village
YouTube: https://www.youtube.com/watch?v=B6_my_bDSx0
Overview
Allan Riordan Ball's talk, "Layer 2 Liberation: Things Your AP Never Dreamed Of," presented at RF Village, delves into the fascinating and often overlooked realm of raw 802.11 frame manipulation. The presentation explores how one can bypass the conventional complexities and overheads of standard Wi-Fi protocols – such as access point association, retransmissions, and higher-layer security – to achieve direct, low-level communication between Wi-Fi-enabled devices. Ball describes this pursuit as "for fun and certainly not profit," emphasizing the experimental and unconventional applications rather than immediate practical utility in typical networking scenarios.
The core premise of the talk is to strip Wi-Fi down to its bare essentials, treating it more like a flexible, low-level radio medium akin to ham radio. By operating directly at Layer 2 (the data link layer) and crafting custom 802.11 frames, Ball demonstrates several creative and "ridiculous" use cases. These range from a custom "File Drop" utility reminiscent of Apple's AirDrop, to a walkie-talkie application, bridging the Meshtastic mesh network protocol over Wi-Fi, and even creating a virtual file system that exposes Wi-Fi traffic as directories and files. The talk serves as a compelling exploration of what's possible when one breaks free from the constraints of standard Wi-Fi stacks.
This deep dive into raw Wi-Fi capabilities is significant for security researchers, network engineers, and enthusiasts alike. It illuminates the fundamental mechanisms of wireless communication, offering insights into potential vulnerabilities that might arise from non-standard protocol implementations or the bypassing of traditional network controls. Furthermore, it inspires innovative approaches to wireless communication, pushing the boundaries of what Wi-Fi hardware can achieve when liberated from its typical software and protocol layers.
Background
▶ Watch: Introduction: Low-level Wi-Fi, beyond access points (0:00)
Traditional Wi-Fi communication, as defined by the 802.11 standard, relies on a sophisticated stack of protocols and mechanisms designed to ensure reliable, secure, and efficient data transfer within a structured network environment. This includes processes like access point (AP) association, authentication, encryption (e.g., WPA2/3), retransmissions for lost packets, and various other Media Access Control (MAC) layer functions. While these features provide the robustness and convenience we expect from modern wireless networks, they also introduce significant overhead in terms of complexity, processing, and latency.
The problem this talk addresses is the desire to bypass this overhead entirely, allowing for direct, peer-to-peer communication with minimal protocol intervention. This concept is not entirely new; systems like Apple's AirDrop achieve direct device-to-device file transfers without requiring a shared AP, though the exact underlying mechanisms are proprietary. Ball's inspiration for this exploration stemmed from realizing "how low-level you can actually go" with Wi-Fi, drawing parallels to the direct, often unacknowledged communication characteristic of ham radio. The motivation was to explore whether similar bare-bones capabilities could be unlocked using off-the-shelf Wi-Fi hardware and open-source tools.
Prior work in this domain often involves specialized hardware or kernel-level modifications for packet injection and monitor mode. Tools like Aircrack-ng have long utilized these capabilities for security auditing and penetration testing. However, Ball's approach focuses on crafting and transmitting custom frames for novel applications, rather than solely for exploitation. The inherent challenges include managing reliability in the absence of retransmission mechanisms, handling packet fragmentation, and ensuring compatibility across different Wi-Fi chipsets and drivers that support raw frame injection.
Key Findings
▶ Watch: Overview of projects: File Drop, Walkie-talkie, Meshtastic, Wi-Fi FS (2:00)
The central finding of Allan Riordan Ball's presentation is the demonstrably practical ability to send and receive raw 802.11 frames directly between Wi-Fi interfaces, effectively bypassing the entire higher-level Wi-Fi stack. This "Layer 2 Liberation" allows for communication without needing to associate with an access point, perform authentication, or rely on built-in retransmission mechanisms. The speaker highlights that this can be achieved with surprisingly few lines of code, primarily leveraging raw sockets in Linux or the Scapy Python library.
Key discoveries include:
- Minimal Overhead Communication: It is possible to craft and transmit 802.11 frames with a bare minimum of headers, significantly reducing the data overhead compared to standard Wi-Fi communication. This enables highly efficient, albeit unreliable, data transfer.
- Direct Device-to-Device Interaction: The technique facilitates direct communication between two Wi-Fi interfaces without any intermediary infrastructure. This opens possibilities for ad-hoc networking and localized data exchange that is independent of traditional Wi-Fi networks.
- Custom Protocol Implementation: By controlling the raw frame content, developers can implement entirely custom protocols on top of this basic transmission mechanism. This was demonstrated through applications like a file transfer utility with custom headers and a simple walkie-talkie.
- Hardware Requirements: Not all Wi-Fi interfaces support the necessary packet injection capabilities. The talk explicitly mentions the need for specific USB dongles or built-in chipsets that provide this functionality, such as the "Eddyax" dongle, though some Samsung laptops' integrated cards were noted to support it.
- Novel Data Visualization and Interaction: The use of FUSE (Filesystem in Userspace) to present live Wi-Fi traffic as a navigable file system demonstrates a highly innovative approach to interacting with and analyzing wireless data, offering an alternative to traditional tools like Wireshark.
These findings underscore the flexibility and untapped potential of Wi-Fi hardware when developers are granted low-level access, moving beyond the standard operating modes and protocols.
Technical Deep Dive
▶ Watch: Barebones transmit/receive demo: 'Hello World' via raw sockets (3:00)
The technical foundation of "Layer 2 Liberation" rests on the ability to interact with Wi-Fi interfaces in a monitor mode that permits raw packet injection. Allan Riordan Ball demonstrated two primary methods for achieving this: directly manipulating raw sockets in Python or utilizing the more abstract and user-friendly Scapy library.
When using raw sockets, the process involves opening a socket and binding it to the Wi-Fi interface. The challenge then lies in manually constructing the necessary frame headers. A minimal 802.11 frame requires several components:
- Radio Tap Header: This is a meta-header added by the operating system or injection driver, not part of the 802.11 standard itself, but crucial for the injection mechanism to function. It contains information about the radio parameters (e.g., signal strength, data rate).
- 802.11 MAC Header: This is the core Layer 2 header. It typically includes:
- Frame Control Field: Specifies the type of frame (e.g., data, management).
- Duration/ID Field.
- Address Fields: Source MAC address, Destination MAC address, and BSSID (Basic Service Set Identifier). In a raw, unassociated context, these can be arbitrary or crafted to simulate a specific sender/receiver.
- Sequence Control Field.
- Optional QoS Control Field.
Ball showed examples where these headers are hardcoded or programmatically generated. For instance, a simple "Hello World" transmission involves setting a made-up source, destination, and BSSID. The payload (the "Hello World" string) is then appended to these headers. On the receiving end, a raw socket is opened, and incoming bytes are read. The receiver then has to "peel away" the radio tap and 802.11 MAC headers to extract the actual payload.
Scapy, a powerful Python packet manipulation program, simplifies this process significantly. Instead of byte-level manipulation, Scapy allows users to construct packets using Python objects and a concise, slash-separated syntax. For example, RadioTap() / Dot11(addr1="dest_mac", addr2="src_mac", addr3="bssid") / Raw(load="hello world") would construct a full frame. Scapy handles the serialization of these objects into raw bytes for transmission and deserialization for reception, making it much quicker to prototype and experiment.
A critical limitation of this raw approach is the absence of retransmissions. If a packet is lost due to interference, distance, or other factors, the sender has no inherent mechanism to detect this or retransmit the data. This makes the link inherently unreliable, a point Ball explicitly highlights, stating it's "more like a very basic radio." To address this for applications like file transfer, custom retransmission logic must be implemented at the application layer, as demonstrated in the "File Drop" example. Furthermore, security is non-existent; frames are sent unencrypted and unauthenticated unless explicitly built into the custom protocol.
Packet size is another technical constraint. Standard 802.11 frames have a maximum size, typically around 2 KB. Larger data, such as files or audio streams, must be fragmented into multiple packets. The "File Drop" demo illustrated this, where a picture of "CAC" (likely a cat image) was sent across 30 packets. The lack of built-in retransmission meant that often only a percentage of packets (e.g., 96%) would arrive on the first attempt, necessitating multiple transmission runs to achieve 100% integrity, verified using an MD5 hash included in the custom header.
For the walkie-talkie demonstration, Ball used the Python sounddevice library to capture and play audio. To make the unreliable link more viable for streaming, the audio resolution was intentionally lowered, increasing the chance of successful packet delivery. The Meshtastic integration involved bridging UDP multicast packets (from Meshtastic's Linux test build within a Docker container) to raw Wi-Fi frames and vice-versa. This required a script to listen on the UDP multicast address, encapsulate the data into 802.11 frames with a "mesh" magic number, and then send them via the raw socket. The receiving script performed the reverse operation.
Finally, the Wi-Fi FS demo showcased the FUSE (Filesystem in Userspace) interface. FUSE allows user-space programs to implement file system semantics. Ball's implementation created a virtual file system where:
- The top-level directories represented available Wi-Fi interfaces (e.g.,
USB1). - Subdirectories represented Wi-Fi channels (e.g.,
channel_6). - Entering a channel directory would cause the Wi-Fi interface to switch to that channel.
- Files within channel directories represented captured 802.11 packets, named by their BSSID and containing the raw packet data.
This allowed users to navigate Wi-Fi traffic using standard file system commands like ls and grep, effectively filtering packets by their content or metadata directly from the command line, offering a novel alternative to Wireshark.
Demo / Proof of Concept
▶ Watch: Introducing 'File Drop': Airdrop-like transfer without an AP (5:00)
Allan Riordan Ball presented several compelling live demonstrations and code snippets to illustrate the capabilities of raw 802.11 frame manipulation. Each demo built upon the foundational concept of bare-bones Wi-Fi communication, showcasing increasingly complex and creative applications.
The first demonstration established the absolute minimum for sending and receiving an 802.11 frame. Using Python, Ball showed two short scripts: one for transmitting "Hello World" via a raw socket, and another for receiving it. The transmitter code involved opening a raw socket, binding it to the Wi-Fi interface, and constructing a minimal 802.11 header with made-up source, destination, and BSSID MAC addresses, along with a radio tap header required for injection. The receiver simply listened on a raw socket and peeled off the headers to reveal the payload. This basic functionality was then replicated using Scapy, demonstrating its more concise syntax for packet crafting, where RadioTap() / Dot11(...) / Raw(load="hello world") could achieve the same result in fewer lines. Wireshark captures were shown to confirm the frames were indeed being transmitted over the air.
Next, Ball presented a "File Drop" utility, designed to mimic Apple's AirDrop by enabling direct file transfer between two devices without an access point. The sender script read a file, fragmented it into 802.11 frames (each limited to approximately 2 KB), and transmitted them sequentially. A custom header containing a "magic number" was added to each packet to identify it as part of the file transfer, along with an MD5 hash for integrity verification. The receiver collected these packets and reassembled the file. A small "hello world" text file was successfully transferred in a single packet. A larger image file, a "picture of CAC," required 30 packets. The demo highlighted the unreliability of raw Wi-Fi: the first transmission only resulted in 96% of packets being received. Ball demonstrated that simply re-running the sender again allowed the missing packets to eventually arrive, achieving 100% completion and a matching MD5 hash after a few attempts.
The Walkie-Talkie demo extended this concept to real-time audio streaming. Instead of reading from a file, the transmitter captured audio from the microphone using the Python sounddevice library, fragmented it into raw 802.11 frames, and sent it. The receiver played the incoming audio through the speaker. To cope with the unreliable nature of the raw link, the audio sample rate and resolution were intentionally lowered to increase the chances of successful packet delivery and maintain a continuous stream. While the live audio output on the speaker encountered an unexpected issue during the presentation, the packet transmission and reception were confirmed, with the receiver displaying a "loudness" meter and the number of packets per second, indicating the underlying mechanism was functional.
A more elaborate proof of concept involved bridging Meshtastic over Wi-Fi. Meshtastic is a mesh networking protocol typically based on LoRa (Long Range) radio technology, used for off-grid messaging. Ball demonstrated how to "shoehorn" Meshtastic to use Wi-Fi instead. Meshtastic provides a Linux build and Docker image that, for testing purposes, emits and listens for messages as UDP multicast packets. The demo involved two separate Docker containers running Meshtastic instances. A Python "bridge" script was developed to listen for these UDP multicast packets from one Meshtastic instance, encapsulate them into raw 802.11 frames (marked with a "mesh" magic number), and transmit them over Wi-Fi. A similar script on the receiving side would capture these Wi-Fi frames, extract the Meshtastic data, and inject it back into the other Meshtastic Docker container's UDP interface. The demonstration successfully showed messages sent from one Meshtastic web UI appearing in the other, with Wireshark capturing the raw "mesh" packets on the Wi-Fi interface, confirming the bridge's operation.
The final, and perhaps most unique, demo was Wi-Fi FS, a FUSE (Filesystem in Userspace) implementation that creates a virtual file system representing Wi-Fi traffic. By mounting a directory (e.g., /mnt/wifi), users could navigate Wi-Fi interfaces as top-level directories (e.g., USB1). Entering a subdirectory named after a channel (e.g., channel_6) would instruct the Wi-Fi interface to switch to that specific channel. Inside these channel directories, the file system would populate with subdirectories named after observed BSSIDs (representing access points or devices), and files within those BSSID directories represented individual captured 802.11 packets. This allowed for novel interactions: performing an ls command in a channel directory would show active BSSIDs, and grep could be used to search for specific content within captured packets, effectively providing a command-line interface for Wi-Fi analysis that felt like navigating a file system. Ball demonstrated capturing beacon frames from "RF Village" and searching for "hello world" packets previously transmitted in an earlier demo.
Defensive Implications
▶ Watch: File Drop demo: Sending image, demonstrating packet loss and retransmission (7:00)
The "Layer 2 Liberation" talk, while focused on experimental and "fun" applications, carries significant defensive implications by highlighting capabilities that can bypass traditional network security models. Understanding these low-level Wi-Fi mechanics is crucial for comprehensive network defense.
Firstly, the ability to send and receive raw 802.11 frames without AP association or authentication means that standard network access controls, which rely on devices connecting to a legitimate access point and presenting credentials, are entirely circumvented. Malicious actors could leverage similar techniques to establish covert communication channels between compromised devices or exfiltrate data directly, bypassing firewalls, IDS/IPS systems, and other security measures that operate at higher network layers or depend on established Wi-Fi connections. Defenders must recognize that the mere presence of a Wi-Fi interface, even if not "connected" to a network, can still be an active communication vector.
Secondly, the absence of inherent encryption and retransmission at this raw level, while a challenge for the attacker in terms of reliability, also presents a detection challenge. If custom protocols are built on this raw layer, they might not conform to expected Wi-Fi traffic patterns. Traditional IDS/IPS signatures often look for known protocol headers or anomalous behavior within standard Wi-Fi frames (e.g., deauthentication attacks, EAPOL frames). Covert raw 802.11 communication could appear as unusual or malformed packets to a superficial analysis, or simply be ignored if not matching known patterns. This emphasizes the need for deep packet inspection and potentially spectrum analysis to identify unusual or non-standard wireless activity that isn't part of the expected 802.11 protocol suite.
Furthermore, the "File Drop" and "Walkie-Talkie" demos illustrate how data can be transferred directly between devices, potentially creating ad-hoc data exfiltration pathways that bypass wired network segmentation or even other Wi-Fi networks. An insider threat could use such a method to transfer sensitive files off a secure device to another nearby device without leaving a trace on the enterprise Wi-Fi logs or wired network.
The Wi-Fi FS demonstration, while presented as an analytical tool, also shows the power of low-level visibility. Defenders could adapt similar FUSE-based or custom sniffing tools to monitor for specific "magic numbers" or unusual packet structures that might indicate unauthorized raw 802.11 communication within their environment. This moves beyond simply monitoring connected clients to actively scanning the wireless spectrum for any arbitrary 802.11 transmissions.
In summary, the defensive implications underscore the need for:
- Comprehensive Wireless Monitoring: Beyond just monitoring APs and associated clients, organizations should consider monitoring the raw wireless spectrum for unauthorized or anomalous 802.11 frames.
- Deep Packet Analysis: Security tools should be capable of analyzing raw 802.11 frames, not just higher-layer protocols, to detect custom or covert communication.
- Awareness of Hardware Capabilities: Understanding that common Wi-Fi hardware, especially USB dongles supporting injection, can be repurposed for these low-level operations is critical for physical security and device control policies.
- Zero Trust for Wireless: Assuming that any Wi-Fi-enabled device can communicate directly with another, regardless of network configuration, encourages a more robust zero-trust security model for wireless environments.
Key Takeaways
- Raw 802.11 Frame Control: It is entirely feasible to send and receive raw 802.11 frames directly between Wi-Fi interfaces using tools like Python's raw sockets or Scapy, bypassing the complexities of standard Wi-Fi protocols.
- Bypassing Higher-Layer Overhead: This low-level approach eliminates the need for access point association, authentication, encryption, and automatic retransmissions, enabling highly efficient, albeit unreliable, direct device-to-device communication.
- Enabling Custom Protocols: The ability to craft custom 802.11 frames allows developers to implement their own application-specific protocols, as demonstrated with "File Drop," a walkie-talkie, and Meshtastic bridging.
- Hardware Dependency: Successful raw packet injection and monitor mode require specific Wi-Fi interfaces that support these capabilities, such as certain USB dongles (e.g., the "Eddyax" dongle) or integrated chipsets.
- Novel Analysis Techniques: Tools like FUSE can be leveraged to create innovative interfaces for interacting with and analyzing raw Wi-Fi traffic, presenting spectrum data as a navigable file system that allows for command-line inspection and filtering.
- Security Implications: Understanding these low-level capabilities is crucial for network defenders, as raw Wi-Fi communication can bypass traditional network security controls, necessitating deeper packet inspection and comprehensive wireless spectrum monitoring for covert channels or anomalous activity.
About the Speaker(s)
Allan Riordan Ball is a security researcher and enthusiast with a passion for exploring the unconventional uses of technology, particularly in the realm of wireless communication. His talk at RF Village stems from his personal curiosity and enjoyment in "playing around with some basic Wi-Fi hacking stuff" and discovering the deep-level control achievable with Wi-Fi hardware. Ball's interest extends to mesh networking, as evidenced by his mention of another talk on Meshtastic, a LoRa-based mesh network protocol. He approaches these topics with a spirit of playful experimentation, emphasizing the "fun" and "ridiculous" aspects of pushing technological boundaries.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent RF Village fare — raw 802.11 injection, Scapy frame crafting, and a FUSE-based Wi-Fi filesystem are genuinely fun demonstrations that show real hands-on work. Nothing here will surprise anyone who's run Aircrack-ng or read the nl80211 docs, but the Meshtastic bridge and WiFi-FS are creative enough to earn a slot at a village stage.
Heather Calloway (CISO) — PASS
Competent hobbyist research into raw 802.11 frame manipulation with genuine technical depth, but this lives entirely in the RF Village lane — exploit craft and wireless experimentation with no meaningful bridge to governance, operations, or institutional defense. The defensive section is tacked on and generic. Not my audience.