1. Current Location: Home >  Router settings >  How can you find out if someone has tried to free your WiFi? Catch the thief first, then block the door—three layers of protection make it impossible for neighbors to connect

How can you find out if someone has tried to free your WiFi? Catch the thief first, then block the door—three layers of protection make it impossible for neighbors to connect

WiFi anti-anti-internet troubleshooting and three-layer protection diagram

there was a period when my broadband would lag every night. Even watching a live stream would spin in circles, and I thought it was speed limited. Until one day, when I tried to restart the router in the background, I found two phones I didn't recognize lying in the device list. There are three people in my family, five devices in total—phones and tablets—seven on the list—the extra two are the so-called internet freeloaders. This article records the entire process of catching the thief and blocking the door. Just follow along and you'll finish it in ten minutes.

first set the code: How do you know you're being taken advantage of

no one will greet you when you mooch online, so you need to be careful. Out of several signals, if you hit two, you should check the backend:

  • internet speed freezes during fixed hours, especially around 7 or 8 PM, when other homes are also at peak hours. This alone isn't solid evidence
  • Strangers appear in the router's device list, or data maps running on your phone even though no one is online
  • showing messages like "logged in elsewhere" (someone is using your account to do something else)
  • When logging into the router background, it prompts "The user is logged in elsewhere," which may mean even the router's background has been accessed

I was the fourth one at that time. Usually, the backend would just log in after remembering the password, but that day it suddenly asked me to log in again. I was puzzled, but then I found two unfamiliar phones in the device list. Looking back, it was the father-in-law who gave the WiFi password to the neighboring in-law when he came over, who took it and then passed it on to his child— password leaks are usually not cracked but spread quickly by the mouth.

Catching Thieves: Catch unfamiliar devices one by one

Connect

your computer or phone to your own WiFi, open 192.168.1.1 in your browser (Xiaomi/Redmi uses 192.168.31.1, Huawei uses 192.168.3.1), enter the background password, and go to 'Device Management' or 'Terminal Management' or 'Connected Devices'. Different families use different names, but they all exist.

Each device in the

list has a name, MAC address, and connection method. Say them one by one: this is my phone, this is the TV, this one is ...... I wonder whose it is? Don't rush to block him; check in this order:

first trick: look at the name. many devices, the hostname directly lists the model number, such as "Redmi-K70" or "HUAWEI-P40." If your company doesn't have this model, it's highly suspicious. On Android phones, go to Settings → 'Phone' to see your device model. Compare the list with the list.

second trick: watch the timing. the "access time" of unfamiliar devices is concentrated during the daytime when no one is home, it basically confirms this. At work, the router at home is still on a phone and I'm downloading things—if that's not a thief, what is?

third trick: elimination. disconnect WiFi from every device in the home (turn off WiFi on phone, unplug the cable from the TV), and the list is filled with outsiders. This is the clumsiest but most accurate, and in the end, I used it to settle the case.

confirmed, just click "Disable" or "Black" in the device entry. It immediately disconnects from the internet, and even restarting the router won't connect. Don't rush to block him just yet? Fine, but if you keep reading, there's even more ruthless—just change the password and wipe it out at once.

Blocking the Door First Layer: Change the password, but don't just change it

most people, upon realizing they've been scraped, their first reaction is to change their WiFi password. Modification is correct, but if two premises are wrong, the change is wasted.

the password itself must be strong enough. 12345678, 88888888, home phone number, pinyin, and birthday—these are basically nothing compared to riding on a SIM card. Length matters more than complexity. 10 or more, mixing uppercase and lowercase letters + numbers . Something like "wojia2016wifi" is more important than "Wf9#xQ2!" Safety—the former is long and irregular, the latter is short and hard to remember. When using the internet to run the dictionary, first run short passwords, and mix passwords of 13 or more characters—enough for home use until the router retires.

encryption method must be WPA2 or WPA3. the backend wireless settings have a "Safe Mode" option and still have WEP or WPA (without 2) attached, replace it quickly. WEP encryption can be broken in just a few minutes with ready-made tools, like a paper gate. If your old router only supports WPA2, choose WPA2-PSK/AES; Most devices from the past five years support WPA3. Choose WPA2/WPA3 hybrid mode (some call it WPA3-Personal Transition). New devices run WPA3, and older devices won't disconnect.

After changing the password, remember to restart the router once to reauthenticate all devices, and also verify that the blacklist takes effect.

Layer 2: Turn off WPS—this feature is a leaker

many people don't know that routers have a feature that overrides your carefully set long password—WPS, which is the small round button on the side of the device you can press or the "WPS One-Click Connection" in the background.

its original design was to let guests connect to the internet with the press of a button, without entering a password. The problem lies in how it is implemented: early WPS used an 8-digit PIN code for verification, and some internet tools had cracking schemes for this PIN (the Reaver tools circulating online do this). It could run in a few hours, and no matter how long the password was set, it didn't work—it bypassed your password. Although there were later improvements to anti-blasting, this feature in home scenarios was basically useless: now, when guests come, isn't it faster to send the password via WeChat than to press a button?

Where to turn off

: In the background 'Wireless Settings' or 'WPS Settings', turn off the WPS feature. The Xiaomi router is called "WPS" in the "WiFi Settings" advanced options, and TP-Link is under "Wireless Apps." When my device was being scraped, WPS was on. After turning it off, the network device never connected again for a week (check the access records in the list).

Third Layer: If an unfamiliar device wants to connect, it must get past you first

the first two steps are done, the normal situation is already calm. But if your home password can't be hidden—if you're sharing a rental, elderly people love to share, or run a small shop—add an extra layer of insurance.

MAC address filtering. each connected device's network card has a globally unique MAC address, routers can set a whitelist: devices outside the list will not be connected even if the password is correct. In the backend, under "Internet Control" or "MAC Filtering," select "Only allow whitelist devices to connect to the internet," then add each home device one by one (checking "Add directly in the device management list" is the most convenient). The downside is that guests have to add them manually, and remember to delete them after they leave. It's a bit more troublesome, but the security is the strictest.

Hide SSID. turn off the WiFi name broadcast (the "Hidden Network" switch), others can't find your signal, so you have to manually enter your name + password to connect. Honestly, this trick can't stop malicious people (as the packet detection tool can see), but it does protect your neighbor's 'master key' apps—those apps rely on users uploading trending info, and your name has never even entered their database.

By the way, a word about apps like Master Key: someone who has installed it connects to your home WiFi, your hotspot information might be uploaded and shared . Tell your family not to install this thing on your own network; if you want to connect to the internet, just ask for the password.

Quick

different brand setup paths

I organized several common backend paths into a table, so when I couldn't find the settings, I took them accordingly:

What
want to do Xiaomi/Redmi (192.168.31.1)TP-Link (192.168.1.1) Huawei (192.168.3.1)
Connected Devices Home Page→ Frequently Used Devices→ View All Device Management→ Connected Devices Terminal Management
blacklist device device details→ prohibit networking device entries→ disable terminal details→ blacklist
Change password/encryption methodWiFi set → security mode wireless settings→WPA-PSK/WPA2-PSK My WiFi → encryption
Off WPSWiFi Settings→ Advanced Settings →WPS Wireless Apps→WPS There is no dedicated WPS switch (by default, it is off)
MAC filtering Security Center→ firewall functions internet control→ MAC filtering terminal filtering

can't be found in the table, there's usually a search box in the top right corner of the backend. You can directly search keywords, which is faster than flipping through menus.

keep guard against this, stay alert in daily life

protection isn't a one-time fix. My current habit is to check the device list in the background every two or three weeks to see if there are new faces. If you find an unfamiliar device, follow the elimination method in section 2: block or block where you should, change your password when you need to. Two more details: Don't set the router's background password to the default admin password, which is different from the WiFi password, otherwise those who use the internet can easily crawl into the background and change all your configurations; When the firmware prompts an upgrade, it upgrades; the security vulnerabilities blocked by the manufacturer are all in the update.

here's a reverse fact: if you want to confirm "who is actually stealing traffic," besides checking the device list, you can also check the real-time speed rankings for each device. I previously wrote a three-step method for finding bandwidth grabbing devices, which goes hand in hand with this article on freeloading the internet. here. I've written about ways to recover WiFi passwords before this . If you realize you've forgotten before changing your password, go ahead and catch up on it. For Xiaomi routers, the background entry and password change path are in the 192.168.31.1, with images and text.

final disclosure: Being freeloading is no small matter. If someone uses your network for anything and holds you accountable, it will fall back to your broadband. Spend ten minutes completing the top three layers—change the hard password, disable WPS, and apply filters—and you can block 99% of freeloading users. The remaining fraction is real hackers, and they don't even care about your broadband.

Read More


Copyright Notice Scan to read on mobile
All Rights Reserved: 《SHUNOT》 => 《How can you find out if someone has tried to free your WiFi? Catch the thief first, then block the door—three layers of protection make it impossible for neighbors to connect
Article URL: https://www.shunot.com/en/luyou/756.html
Unless otherwise stated, all articles are original by 《SHUNOT》. Reposting is welcome! Please indicate the original URL when reposting, thank you.

Contact Us

Online Consultation: Click here to send me a message

WeChat ID: master_135

Scan to follow