|
| |
|
| |
|
Sponsored by:
Affiliates: ![]() ![]() ![]()
EC-Council ECSA Training Videos
Web Hosting: |
MadMACs: MAC Address Spoofing And
MadMACs was designed with the
privacy paranoid in mind. The two main things a DHCP server records when you get
an IP from it is your host name and the MAC address of the network card you are
connecting from. This is identifying information that not all users want to
leave behind. MadMACs allows you to randomize this information after it runs and
reboots. If you run MadMAX without parameters you are asked "Do you wish to remove MadMACs from startup and clear the registry? Click No to configure MadMACs instead or Cancel to forget the whole matter." Make the logical choice to get the desired outcome. If you want MadMACs to randomly set
your host name make a text file called dic.txt in the same directory as the
binary. This text file's format is one word after another separated by line
feeds. If you are feeling lazy just rename the file "sample dic.txt" that comes
with MadMACs to "dic.txt". MadMACs will randomly select a word from dic.txt and
make that your host name. You may not want to use the host name randomizing
functionality if you need to reach the host with the same name every time. A patron of my website
pointed out that MadMACs, and other similar tools, seem to have a problem
randomizing the MAC address under Windows Vista if you are using the Intel
Wireless WiFi Link 4965AGN chipset. It will work with the 4965AGN if you
randomize only the last two digits, and start it with the prefix 1234567890. It
will also let you set the whole MAC address to DEADBEEFCAFE, or even let you
randomize all 12 hex digits. However, if you take the default prefix of 00,
MadMACs will make a random address up and put it in the NetworkAddress registry
value, but the 4965AGN chipset drivers will not honor it. If anyone knows why,
please contact me. http://www.hak5.org/wiki/MAC_Randomizer Change Log: Ver. 1.2: Qwasty
let me know that if host name randomization is used with MacMACs, and the host
name is over 15 characters (or has certain bad illegal characters) it can cause
all sorts of lsass.exe errors on boot up. To fix this, I've updated the code to
do some sanity checks on the possible hostnames given to it in dic.txt.
Hopefully this fixes the problem. I also compiled it with the newer
Autoit3 v3.2.12.1. blog comments powered by Disqus
Ten most recent posts on Irongeek.com:
|
If
you would like to republish one of the articles from this site on your
webpage or print journal please contact IronGeek.
Copyright 2010, IronGeek
Louisville / Kentuckiana Information Security Enthusiast