NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 11-30-2004   #1 (permalink)
sicc
Registered Member
 
Join Date: Aug 2003
Posts: 43
Need help spoofing MAC address, ifconfig down seems to remove wireless card

As the title states, I am looking for a way to spoof my wireless card's MAC address. I have tried all of the obvious methods, but they have all failed.

I am running Slackware 10, kernel 2.4.xx, and using an Orinoco gold classic wireless card. It is also using the patched pcmcia drivers, version 3.2.7, and firmware 8.10 [I've tried downgrading to a lower firmware in the past with no success, so that isn't really an option]

Here is what I've attempted so far, along with the error messages.

-----------------

# ifconfig eth0 hw ether 10:10:10:10:10:10
SIOCSIFHWADDR: Device or resource busy

# ifconfig eth0 down
# ifconfig eth0 hw ether 10:10:10:10:10:10
SIOCSIFHWADDR: No such device

# ifconfig eth0 up
SIOCSIFFLAGS: No such device

# ifconfig
eth1 Link encap:Ethernet HWaddr 00:E0:18:74:B3:EC
inet addr:192.168.0.3 Bcast:192.168.0.255 Mask:255.255.255.0
UP BROADCAST NOTRAILERS RUNNING MULTICAST MTU:1500 Metric:1
RX packets:20 errors:0 dropped:0 overruns:0 frame:0
TX packets:62 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3246 (3.1 Kb) TX bytes:10929 (10.6 Kb)
Interrupt:11 Base address:0xe800

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:2 errors:0 dropped:0 overruns:0 frame:0
TX packets:2 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:100 (100.0 b) TX bytes:100 (100.0 b)

# ifconfig eth0
eth0 Link encap:Ethernet HWaddr 00:02:2D:C3:CB:4B
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:3 Base address:0x100



------------------

Now I know I used to be able to do ifconfig down, then ifconfig up, and it would work fine. I don't know what made this suddenly stop working, but I'm thinking this may be the problem. I have to restart the pcmcia service to get the card back. I have even downloaded macchanger, and it gives the same type of error.

I just tried doing this to my eth1 [wired connection] and it works perfectly as long as I bring it down first. I am going to start searching for errors with 'ifconfig down; ifconfig up' and see what I can find.

If anybody has gone through this please let me know what can be done to fix it. Thanks ;]
__________________

-sicc

Last edited by sicc : 11-30-2004 at 02:35 AM.
sicc is offline   Reply With Quote
Old 11-30-2004   #2 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,098
Some cards/firmware/software seem to fight a spoofed MAC. Other people here have reported that it doesn't seem to work unless certain criteria are met, such as the first six digits matching the OUI # of the manufacturer.

The easiest thing to do is avoid all the drama of doing it yourself, and just use a MAC changing program which will plug in an appropriate number. Chris wrote SirMACsAlot; apparently coding while under the influence of rap music.

You can read about it here:
http://forums.netstumbler.com/showthread.php?t=10144

And download it here:
http://www.michiganwireless.org/tools/sirmacsalot/
__________________
Thorn
"I'm The Doctor. I'm a Time Lord. I am from the planet Gallifrey in the constellation Kasterborous. I'm 903 years old and I am the man who is going to save your lives and all 6 billion people on the planet below... You got a problem with that?"
Thorn is offline   Reply With Quote
Old 11-30-2004   #3 (permalink)
G8tK33per
Asshole Emeritus
 
G8tK33per's Avatar
 
Join Date: May 2003
Location: S.E. VA.
Posts: 5,939
Quote:
Originally Posted by Thorn
Some cards/firmware/software seem to fight a spoofed MAC. Other people here have reported that it doesn't seem to work unless certain criteria are met, such as the first six digits matching the OUI # of the manufacturer.

The easiest thing to do is avoid all the drama of doing it yourself, and just use a MAC changing program which will plug in an appropriate number. Chris wrote SirMACsAlot; apparently coding while under the influence of rap music.
You can read about it here:
http://forums.netstumbler.com/showthread.php?t=10144

And download it here:
http://www.michiganwireless.org/tools/sirmacsalot/
Here we go again...

<cue music>
I.like.big.butts....
__________________
"Benjamin is nobody's friend. If Benjamin were an ice cream flavor, he'd be pralines and dick."

Sons of Confederate Veterans
G8tK33per is offline   Reply With Quote
Old 11-30-2004   #4 (permalink)
Monitr7
Not feeling funny...
 
Monitr7's Avatar
 
Join Date: Jan 2003
Location: Rebrandsoftware's mom's house...
Posts: 1,699
Quote:
Originally Posted by G8tK33per
Here we go again...

<cue music>
I.like.big.butts....
And I cannot lie!

You other Stumblahs can't deny!

When a Orinocah card wit' a itty-bitty MAC

Is jus' beggin' fa you ta crack

That muh'fuggin' WEP, yo!

Word 'em up!
__________________
WTOTD Industries - Where quality is Job #3.

G8tK33per doesn't care about the tarded people!
-Kanye West
Monitr7 is offline   Reply With Quote
Old 11-30-2004   #5 (permalink)
Barry
Managing the iTards.
 
Barry's Avatar
 
Join Date: Dec 2002
Location: Ohio
Posts: 5,383
Dude, you need to lay off the crack!!
__________________
Atheism is a non-prophet organization.
Barry is offline   Reply With Quote
Old 11-30-2004   #6 (permalink)
audit
Country Boy.
 
audit's Avatar
 
Join Date: Aug 2002
Location: Deep in the Woods.
Posts: 1,911
I think my ears are bleeding now bitch!
__________________
audit

Blackberry Outage Mail List. Be the one of first people to know about RIM outages.
Blackberry Chat Mail List.
My day to day life.
audit is offline   Reply With Quote
Old 11-30-2004   #7 (permalink)
Monitr7
Not feeling funny...
 
Monitr7's Avatar
 
Join Date: Jan 2003
Location: Rebrandsoftware's mom's house...
Posts: 1,699
My finest free verse...
__________________
WTOTD Industries - Where quality is Job #3.

G8tK33per doesn't care about the tarded people!
-Kanye West
Monitr7 is offline   Reply With Quote
Old 11-30-2004   #8 (permalink)
sicc
Registered Member
 
Join Date: Aug 2003
Posts: 43
Haha... you guys crack me up. Unfortunately, the problem is deeper than that. I get the same error using that program. The problem isn't that I can't change my MAC, it's that I can't bring my card down, then back up again.

Anybody else have any ideas? I read something about recompiling my kernel with CONFIG_IP_ALIASING=y. I have bad luck recompiling, so I've tried to stay away from this, but does this sound like it would fix this problem?

Also, if somebody could give me some links to some other GOOD linux forums so I can ask there too, that would be cool. I posted this at linuxquestions.org also, but no responses yet.
__________________

-sicc

Last edited by sicc : 11-30-2004 at 04:56 PM.
sicc is offline   Reply With Quote
Old 11-30-2004   #9 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,805
What about running Alchemy in Wine? I used it the other day on my XP machine and noticed that one of the options of Alchemy is to change the MAC address. It's a bit inconvienent having to run Windows but if this is just onesy/twosy type thing you might want to look into it.


Monitr7, it needs more Cowbell!

Quote:
Oh my god
Fekkin , look at her WEP
It is so big
She looks like one of those NS Forum Mods girlfriends
Who understands those NS Forum Mods
They only talk to her because she looks like a total ubergeek
Okay I mean her WEP
It's just so big
I can't believe it's just 128 bit
It's like out there
I mean, it's gross
Look, she's just so WEP

I like big WEPs and I can not lie
You other brothers can't deny
That when a girl walks in with an Orinoco Card
And an omni thing in your face
You get sprung
Wanna pull up front
Cause you notice that WEP was stuffed
Deep in the laptop she's carry'en
I'm hooked and I can't stop staring
Oh, baby I wanna get with ya
And take your picture
My homeboys tried to warn me
But with that WEP you got make
Me so horney
Ooh, all of that encryption
You say you wanna get in my wigle logs
Well use me use me cuz you aint that average groupy
I've seen them dancin'
The hell with romancin'
Sweat, wet, got it goin like a turbo vette
I'm tired of magazines
Saying WPAs are the thing
Take the average formum member and him that
She gotta pack much WEP
Fellas (yeah) Fellas(yeah)
Has your girlfriend got the WEP (hell yeah)
Well encrypt it, encrypt it, encrypt it, encrypt it, encrypt that 128 bit WEP
Baby got WEP
I like'em encrypted and MAC filtered
And when I'm wardriving
I just can't help myself
I'm actin like an animal
Now here's my scandal
I wanna get you home
And --, double up -- --
I aint talkin bout Kismet
Cause peneguin parts were made for toys
I wannem real thick and juicy
So find that juicy double
MACalot's in trouble
Beggin for a piece of that bubble
So I'm lookin' at NS1 outputs
Watchin' these bits walkin like initialazation vectors
You can have them vectors
I'll keep my WEP like Flo Jo
A word to the WEP toting sistas
I wanna get with ya
I won't hack or hit ya
But I gotta be straight when I say I wanna --
Til the break of dawn
I got it goin on
Alot of pimps won't like this song
Cuz them punks lie to log it and quit it
But I'd rather stay and play
Cuz I'm long and I'm strong
And I'm down to get the encryption on
So ladies (yeah), Ladies (yeah)
If you wanna role in my Mercedes (yeah)
Then turn it on
Stick your antenna out
Even white boys got to shout
Baby got WEP
Yeah baby
When it comes to females
Cosmo and got nothin to do with my selection
4e-65-74-73-74-75-6d-62-6c-65-72
Only if it ain't ASCII
So your girlfriend throws a Honda
Playin workout tapes by Fonda
But Fonda and got motor in the back of her Honda
My anaconda don't want none unless you've got WEP hon
You can do XP or Millenium, but please don't lose that WEP
Some brothers wanna play that hard role
And tell you that the WEP and Orinoco gold
So they toss it and leave it
And I pull up quick to retrieve it
So cosmo says you're WAP
Well I aint down with that
Cuz your beacon is small and your RF LOS is kickin
And I'm thinkin bout stickin
To the noob dames who are always gettin' flamed
You aint it miss thing
Give me a sista I can't resist her
Win98 and W-F-W didn't miss her
Some noob tried to dis
Cuz his WEP was on my list
He had game but he chose to hit 'em
And pulled up quick to get with 'em
So ladies if the WEP is strong
And you wanna X11 throw down
Dial 1-900-macsalot and kick them nasty thoughts
Baby got WEP
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘
beakmyn is offline   Reply With Quote
Old 11-30-2004   #10 (permalink)
Monitr7
Not feeling funny...
 
Monitr7's Avatar
 
Join Date: Jan 2003
Location: Rebrandsoftware's mom's house...
Posts: 1,699
THAT... was... friggin'... awesome! I give ya mad props, beakmyn, yo!
__________________
WTOTD Industries - Where quality is Job #3.

G8tK33per doesn't care about the tarded people!
-Kanye West
Monitr7 is offline   Reply With Quote
Old 11-30-2004   #11 (permalink)
sicc
Registered Member
 
Join Date: Aug 2003
Posts: 43
I guess a little backround would have helped [and I'm not talking about for your song haha]. I have been using windows, and just recently started using linux for about a month or so. I am trying to do all of my wardriving in linux, as this is what I prefer now [didn't take long to get me hooked].

I know how to do it in windows by changing the registry value, or any of the other methods.
__________________

-sicc
sicc is offline   Reply With Quote
Old 11-30-2004   #12 (permalink)
The Others
PeaceDriver
 
The Others's Avatar
 
Join Date: Apr 2002
Location: Dos Palabras, Mandoras
Posts: 2,920
Quote:
Originally Posted by sicc
I guess a little backround would have helped [and I'm not talking about for your song haha]. I have been using windows, and just recently started using linux for about a month or so. I am trying to do all of my wardriving in linux, as this is what I prefer now [didn't take long to get me hooked].

I know how to do it in windows by changing the registry value, or any of the other methods.
If you're still dual booting windows, or have access to a windows machine, alchemy may not be a bad idea. It changes the MAC address value on the card it's self. This new value remains intact when you remove the card, reboot, etc. You can change it in windows and the settings will survive a migration to linux. Proving the point, I have used this method to change the MAC address of my access point.

If you have a windows computer available, alchemy will be a very easy method of changing your MAC address.
__________________
all good ends all

?u=273
The Others is offline   Reply With Quote
Old 11-30-2004   #13 (permalink)
sicc
Registered Member
 
Join Date: Aug 2003
Posts: 43
Quote:
Originally Posted by The Others
If you're still dual booting windows, or have access to a windows machine, alchemy may not be a bad idea. It changes the MAC address value on the card it's self. This new value remains intact when you remove the card, reboot, etc. You can change it in windows and the settings will survive a migration to linux. Proving the point, I have used this method to change the MAC address of my access point.

If you have a windows computer available, alchemy will be a very easy method of changing your MAC address.

I did NOT know that! I will try that after I fix my XP partition. Thanks a lot! ;]
__________________

-sicc
sicc is offline   Reply With Quote
Old 11-30-2004   #14 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,098
Quote:
Originally Posted by beakmyn
...
Monitr7, it needs more Cowbell!
beakmyn, I am truly in awe. The "4e-65-74-73-74-75-6d-62-6c-65-72 Only if it ain't ASCII" was especially subtle.

I can only ask: Slow day at work?

sicc, what does DMESG say about eth0? Are your IRQ and interrupts correct and not conflicting?
__________________
Thorn
"I'm The Doctor. I'm a Time Lord. I am from the planet Gallifrey in the constellation Kasterborous. I'm 903 years old and I am the man who is going to save your lives and all 6 billion people on the planet below... You got a problem with that?"
Thorn is offline   Reply With Quote
Old 11-30-2004   #15 (permalink)
sicc
Registered Member
 
Join Date: Aug 2003
Posts: 43
Quote:
Originally Posted by Thorn
beakmyn, I am truly in awe. The "4e-65-74-73-74-75-6d-62-6c-65-72 Only if it ain't ASCII" was especially subtle.

I can only ask: Slow day at work?

sicc, what does DMESG say about eth0? Are your IRQ and interrupts correct and not conflicting?
I don't have access to it at this moment because I'm reinstalling xp, but I looked at DMESG after doing ifconfig eth0 down/up and it said something about eth0 being locked. I can post the details once my laptop is back up.

As far as IRQ conflicts, the card works flawlessly otherwise, so I doubt it.
__________________

-sicc
sicc is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 10:37 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.