Nmap Development mailing list archives

Re: scan based on mac address


From: Brandon Enright <bmenrigh () ucsd edu>
Date: Mon, 11 Aug 2008 19:33:53 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun, 10 Aug 2008 12:26:26 +0300
"sara fink" <sara.fink () gmail com> wrote:

...snip...

The host is behind a router. The router is Digital_D (Digital Data
Comm) according to wireshark. Someone happen to know the subnet of
this router? I couldn't find anything on google about it.

I know the mac address of the router and the host.


Hi Sara.  This is somewhat outside the scope of Nmap but I'll respond
anyways.

If you obtained the MAC of the client and router with Kismet,
they I assume you've got a wireless card in monitor mode.  If that is
the case, you should be able to fire up Wireshark/tcpdump and capture
full 802.11 frames.  You should be able to drill-down to the IP or TCP
layer of any frame you capture.

This should reveal both the IP of the router/gateway as well as the IP
of any client for which you've captured frames.

If the frames are WEP encrypted and you don't have the key you'll have
a few more hurdles to overcome.  I can't think of any realistic
scenarios though where without the WEP key (you can't associate to the
AP) you'd still be able to directly scan the target host once you
learn it's IP.  That is, if you can't associate with the local AP
because you don't have the key, knowing that the target client is
192.168.254.100 is likely useless -- you can't get behind the NAT to do
the scan anyways.

You might try posting to the SecurityFocus Pen-Test mailing list for
help.  If you fully describe the scenario you'll probably get several
good ideas for how to proceed.

Brandon

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEARECAAYFAkiglC8ACgkQqaGPzAsl94IGXQCghOBBaqTbNcAmds9nXI0Mn6P/
tNkAnjLLPysZirdwx6N81HZfKLyB9CUZ
=i6ej
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: