272
Practical Hacking Techniques and Countermeasures
Return to the SMAC computer and type a new ???spoofed??? address in the
Spoofed MAC Address
block.
*Note:
In order for SMAC to work correctly, you must enter a valid MAC address. It
does not have to be from the same manufacturer as the real NIC but must
be a valid NIC address.
Spoofing
273
Click on the
Update MAC
address and the new spoofed MAC address will
appear in the lower-left corner of the application. Click the
Exit
button.
Restart
the computer.
Once the computer has rebooted, open the SMAC address. Notice the
???spoofed??? address is now the active MAC address for the computer.
274
Practical Hacking Techniques and Countermeasures
Bring up an MS-DOS prompt and repeat the
ping
command against a target.
From the target computer, repeat the Ethereal test as above. From the
results, the source has a MAC address of 00:0c:29:b6:40:10, which is identical
to what the ???spoofed??? MAC address should be according to SMAC.
Spoofing
275
Because SMAC allows for reboots it must provide a way to release the
???spoofed??? MAC address to return to normal. The ???spoofed??? MAC address will
disappear in the lower-left corner of the application.
Click the
Exit
button.
Reboot
the computer.
Once the computer has rebooted, open the SMAC address. Notice the
active MAC address is the actual MAC address of the computer.
276
Practical Hacking Techniques and Countermeasures
To verify the change repeat the
ping
process.
Pages:
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121