Home page logo

nmap-dev logo Nmap Development mailing list archives

Re: display local mac address in scan results
From: Toni Ruottu <toni.ruottu () iki fi>
Date: Mon, 23 Jun 2008 00:38:06 +0300

As of version 4.65, this use case is still not supported.

Would it be possible to send a packet to local interface, so the mac
address would be displayed because of the actual traffic, instead of
coding support for resolving the address as a special case?


On Sat, 2007-05-19 at 16:12 +0300, Toni Ruottu wrote:

This is a feature request for a small user interaction improvement that
hopefully won't require lot of coding. I posted earlier about the same
subject, but wasn't a list member at the time, so couldn't take part in
discussion. So here we go again. This time with a use case.

  Joe works as a network administrator in a small company. He uses nmap
  every now and then to map the company network. He is not familiar with
  the most advanced features, but knows how to use the most basic scan
  types, declaring port ranges as well as ip address ranges. He is also
  aware of the man-page and reads it when he encounters difficulties.

  Joe is currently documenting the network and needs to find out mac
  addresses of hosts currently present. Joe also needs to add network
  interface card manufacturers into the documentation. The manufacturer
  information is used in the company as reference when discussing about
  network interface card drivers or buying new cards.

  It is Friday afternoon and Joe has made an agreement to drink a
  few beers with his friend Peter once he is done with writing the
  documentation. Peter isn't working on Fridays so he is ready to go
  once Joe is done with his work. Joe is supposed to call him once he
  completes. Joe opens a terminal on his Ubuntu pc and executes...

joe () joespc:~$ sudo nmap -sP

Starting Nmap 4.21ALPHA4 ( http://insecure.org ) at 2007-05-19 15:11
Host appears to be up.
MAC Address: 00:18:39:33:B4:E8 (Cisco-Linksys)
Host appears to be up.
Nmap finished: 256 IP addresses (2 hosts up) scanned in 5.848 seconds

  (In a real situation there would of course be more than two hosts ;-)

  Joe reads the results and notices that mac address of the local
  network interface was not included in the scanning results. He
  remembers that nmap is able to list local interfaces along with
  their type. Joe looks at the nmap man page and finds the --iflist

  Joe now executes...

joe () joespc:~$ sudo nmap --iflist | grep ethernet
eth0 (eth0) ethernet up 00:02:B3:33:12:6B

  Joe now has all the mac addresses, but he is still missing the
  manufacturer. Joe searches a list of mac address ranges on the
  Internet. In the list he can find name of the manufacturer of
  his card. Joe writes the documentation and leaves to drink beer
  with Peter.

It would spare Joe some time, if nmap displayed the local network
interface card mac address and manufacturer information during a
scan in a similar fashion as it does with the remote hosts. Iflist
could of course also list the manufacturer, but I personally
consider this less important.


Sent through the nmap-dev mailing list
Archived at http://SecLists.Org

Sent through the nmap-dev mailing list
Archived at http://SecLists.Org

  By Date           By Thread  

Current thread:
  • Re: display local mac address in scan results Toni Ruottu (Jun 22)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]