ARP reports the hardware (MAC) addresses of the network segment you are connected to. In the case of a local connection to a router, ARP reports the address of the LAN side of the router. The WAN side will often be one number away.
ARP reports the hardware (MAC) addresses of the network segment you are connected to. In the case of a local connection to a router, ARP reports the address of the LAN side of the router. The WAN side will often be one number away.
Well, given that, the first "attempt" at changing the MAC on the PC to that of the bridge on the roof failed but with interesting results.
Request {GET http://192.168.4.1/login?dst=http%3A%2F%2Fwww.google.com%2F
Somewhat easier might be to get a backtrack CD image from t'interweb and burn a CD. Boot a PC off it and bobs your uncle. The hardest bit for me was to find out how to switch round between consoles. That took about two hours since all I knew was I needed more windows. The rest was easy.
aLT-f1, f2 ... f6 -- Default linux consoles. 6 of them.
Mind you you don't seem to mind quite hard:)
With either kismet or backtrack the main issue is to make sure that your wireless card is supported for "monitor mode" with available drivers. There are lists.
This will allow you to sniff the conversation off the air as it transits from your LAN to the internet. The packets will contain the MAC addresses of both your bridge and the remote ISP router.
OOPS. I have just realised that I don't know enough about how wireless works and that the strategy might not work.
Someone will likely correct me if required:-)
In any case backtrack or kismet will let you see the beacons which I believe contain the SSID and certainly the MAC.
Try: Start -> Run Firefox -safe-mode There's also a short cut at: Start -> Programs -> Mozilla Firefox -> Firefox (safe mode). Make sure you do *NOT* have another copy of Firefox running or this will fail.
It's grown to a DVD with 2 GB of programs. That's 500GB of new stuff since the "final" release. The new "Backtrack 4 r1" version just appeared today after Defcon 18. I just downloaded it (it took all day). As before, it's a pain to run as a Live-DVD and works better on a seperate hard disk partition. Do NOT run install.sh unless you plan to install it on your hard disk drive:
I just used v3 since I didn't have any DVDs. Obviously the new one will have more and more-recent drivers. v3 did automagically mount my NTFS partitions (Vista) which allowed me to save files without any messing about despite claiming not to be able to.
If all that is required is the MAC of a single bridge then booting off a CD/DVD is likely to be sufficient:)
E:\backtrack>type step1 modprobe -r iwl3945 # load your driver here modprobe ipwraw iwconfig airmon-ng stop wifi0 ifconfig wifi0 down # mess around in here a bit to set up for my needs airmon-ng start wifi0 airodump-ng wifi0
I think that is enough to see the SSIDs but I forget for now.
You may need to run these in more than one window.
I have the idea that you may need to stop airmon-ng if you want airodump-ng. Again I forget. I had some crashes before I realised that there was a clash somewhere anyway.
500MB ;)
Try a (fast) bootable flash drive instead:
Or Wubi:
Meanwhile, at the alt.internet.wireless Job Justification Hearings, Brent chose the tried and tested strategy of:
Have something to add? Share your thoughts — no account required.
Ask the community — no account required