Can you trust the Wi-Fi networks you connect to? This talk will briefly discuss an incident triage that was conducted after two employee's laptops, connected to a hotel's wireless network, were found to be attempting connections to an IP address (on the internet) via SMB. This sort of activity is generally viewed as suspicious as hackers can use it to capture NTLM password hashes. Once root of the suspicious network traffic is relieved, a proof of concept attack will be explained and demonstrated. It will show how easily connecting to Wi-Fi can lead to sending your computer's username and NTLM password hash to an attacker.