Change your MAC address with a shell script (2019)
josh.works
josh.works
”We’ve got a problem; someone’s misusing the crap out of the free wifi”
”Lets narrow it down by hardware: what kind of device are they using?”
”How should I know!?”
”Check the first three bytes of their MAC address; it’ll tell you the mfr”
”OK... checking now... yeah I see them... looking up their MAC... bingo... hey, what is ‘Cray Inc’?”
—
Better versions of this joke are available here:
https://en.m.wikipedia.org/wiki/Cray-1
The idea of someone wheeling one of these into a cafe (because they are stealing the free wifi) causes me non zero amusement.
The NSA example from someone else is better.
Interestingly the only time I’ve ever had the pleasure of reclining on a Cray banquette was at the NSA’s cryptology museum at Ft Mead.
[Motorola Surfboard]->[4p 1GbE Switch]->[Linksys E3000 (08:00:69::)]
Depending on the mood of the ISP, I can have several other networks running from the 4-port switch. If I spoof those MACs repeatedly, I can get an arbitrary (within range) block of public IPs, and there's some seriously weird behavior in allocating those IPs (change my MAC 48 times in a row, end up on the same IP I had just lost from a power outage?)
Just using a random value might give you "interesting" effects and lot of fun debugging those.
#
# 00-20-91 (hex) J125, NATIONAL SECURITY AGENCY
# 002091 (base 16) J125, NATIONAL SECURITY AGENCY
#
$> NSA_MAC=$(echo "00:20:91:"`openssl rand -hex 3 \
| sed 's/\(..\)/\1:/g; s/.$//'`)
$> sudo ifconfig eth0 hw ether $NSA_MAC
But actually do people still bother with mac-spoofing in 2020? It's from a security/nw-admin pov next to useless (whitelist/filtering nor does it boost privacy of end-users). IMHO it gives people false sense of security and as a "practice" seems like a relic from the 90ies.Though I’m not sure I ever bothered to lookup someone’s MAC address.
It does indeed boost privacy as wireless networks in public places have been trying to track phones this way for a while now.
I did politely ask for an IP before doing that, but they said it was a security risk.
Their wifi solution tracked you by MAC -- I think it was Sonicwalls? -- so when you hit the 30-min limit you'd spoof the MAC, re-connect, then back to business as usual.
I'd usually comply when the place was bumping -- hard to work when it's loud and crazy -- but most of the time it was empty in the mornings and the 30-min-limit was pointless.
Since it was an open network, it was simple scraping the network for other connected devices and spoofing one at random, and I was surprised when the same technique worked in say, hotels with open networks.
Our punishment was something like two weeks with all internet access revoked (except for the use of lab machines for classwork), plus a written apology, plus a signed agreement not to violate the acceptable use policies again or else face the real punishment for what we did.
The school administrator in charge of the punishment asked the security admin what we were downloading (this was when the MPAA/RIAA were cracking down hard on people uploading files on sharing networks), but the security admin had mercy on us and told her he didn't think it was relevant, thank god!
probably they did lookup the MAC address on the switches and saw it on a port that did not match expectations. if you were using a wired connection this would trivially lead to you... on wireless you would have to narrow it down further by monitoring signal strength of the station :)
There were people running internal torrent trackers and file indexing/sharing sites on the LAN that could saturate the network infrastructure between the various dorms and buildings on campus. I guess the whitelisting also helped figure out who was doing what when problems happened.
[0] https://gist.github.com/siraben/c3133b39e470d1aed16fd71f42b8...
[0] https://gist.github.com/siraben/c3133b39e470d1aed16fd71f42b8...
you should probably know that using the same mac address in parallel will cause connectivity issues for both...
Most of these systems are distributed and having multiple APs connected to some central Radius server.
Because modern systems optimize for roaming between nodes, you can join network, use dns-sd to gather mac addresses of the computers which are not physically connected to your AP (in conjuction with 'tcpdump -I')
Then voila, 2 devices using same MAC without any problems.
PS. I personally use "printer" addresses for 2 reasons: 1: generally everyone forgets to nicely setup firewall for them since they're infrastructure objects. 2: they have relatively less traffic and probably located some obsecure room with an AP for them.
I learned this at 2 in the morning trying to bring up a second FPGA. Couldn't work out why it didn't work when the first one did, and it turned out to be because someone (possibly me) had picked the MAC Address 01:02:03:04:05:06 (we were on a private network).
Instead, pick an OUI you like (the first 3 bytes), and then randomly generate the last 3.
The first byte of your MAC address should always be an even number. The value of the second bit is supposed to indicate if the MAC is "burned-in" and basically doesn't matter. The LSB of the first byte, however, should always be zero.
The first byte of my bad MAC is '01'. This not even because the LSB is set, making it a multicast address which is bad.
Nowadays people upload to Google Drive, plus other hosts have more relaxed limits, so I haven't had the need to do it as often. But it's still useful to know.
Could you try if it works on your Apple device?
(I'd really wanted to write a bash script, this seemed like a good option.)
For example: https://news.ycombinator.com/item?id=26062315
Or, another solution that looks promising: https://news.ycombinator.com/item?id=26062553
That solution looks clean and simple, though I've not tried it. It might work for you!
ifconfig(8)[0]
"The link-level ("link") address is specified as a series of colon-separated hex digits. This can be used to, for example, set a new MAC address on an Ethernet interface, though the mecha- nism used is not Ethernet specific. Use the ("random") keyword to set a randomly generated MAC address. A randomly-generated MAC address might be the same as one already in use in the net- work. Such duplications are extremely unlikely. If the inter- face is already up when this option is used, it will be briefly brought down and then brought back up again in order to ensure that the receive filter in the underlying Ethernet hardware is properly reprogrammed."
[0] https://www.freebsd.org/cgi/man.cgi?query=ifconfig&manpath=F...
Now you'll spend your next hour option-clicking random stuff. Sorry.
Most irritating for me is if all windows of an app are hidden (minimized), simple Cmd+Tab doesn't brings anything to focus, but some gymnastics with Option and voila now you can see your Slack.
I hope it continues to be useful to you!
13 Jun 2017 changeMACAddress.sh*
#!/bin/bash
sudo ifconfig en0 ether xx:xx:xx:xx:xx:$(od -txC -An -N1 /dev/random|sed 's/ //g'); sudo ifconfig en0 down; sleep 1; sudo ifconfig en0 upI’ve been using it for years without a hitch. Installable with `brew install vitorgalvao/tiny-scripts/macspoof`.
https://github.com/chrislgarry/XFinityHotspotSpoofer/blob/ma...
uci set network.wan.mac_addr=$(hexdump -n3 -e'1/3 "8c:8d:8e" 3/1 ":%02X" "\n"' /dev/random) && uci commit network set mac_addr 1
set preassoc_mac_addr 1
set gas_rand_mac_addr 1
On a home network you may want to disable this to avoid emptying the DHCP address pool. I do this using a dhcpcd run hook that check the network SSID against a whitelist.Besides being riddled with typos, as I've scanned through these comments I'm finding many _far better ways_ of accomplishing what I set out to accomplish.
I might update my script (and consequently the post)! sometime soon. Unfortunately with Covid, I've spent far less time in coffee shops than I once did.
Of course I need to first use wire shark or something to get a MAC address that’s already connected to the network. This is where I’m hazy.
sudo ifconfig en0 ether $(openssl rand -hex 6 | sed 's/\(..\)/\1:/g; s/.$//')
You can always get your original MAC address from About This Mac > System Report > Network > Locations > Hardware (MAC) AddressMany public networks in Turkey require registering with TCKN (national id number) due to some "laws".
I don't want some random guy to log my activity and tie it to me direcly.
In macOS tcpdump command has ability to "monitor mode" wifi card.
sudo tcpdump -Ie
> -e: shows mac addresses
> -I: monitor mode (capital i)Then I use someone who's idle but has legimitate connection.
Please note that those networks are not encrypted/secured at all. So anyone within range (or with large antenna) can essentially capture or inject something...
1. https://ubuntu.com/blog/if-youre-still-using-ifconfig-youre-... 2. https://wiki.archlinux.org/index.php/MAC_address_spoofing#ip... 2.
ifconfig en0 | grep ether # one of these will return a MAC address that matches
ifconfig en1 | grep ether # the value you saw when looking for your current
ifconfig en2 | grep ether # mac address.
ifconfig en3 | grep ether # Keep incrementing the `en0` value until you run out of
# devices
I would have solved this by running “ifconfig -a | less” and then typing “/ether”. I’m curious if anyone has a different way of doing it!In short: "remac -p ibm set" will set your MAC address to a new MAC adress with an "IBM Corp" prefix
ip link set dev en0 address 00:12:34:45:78:90
ip link set en0 address random
ip link set en0 address factory
[0]: https://github.com/brona/iproute2mac sudo ifconfig en0 ether xx:xx:xx:xx:xx:xx
It's been years since I've had a need to spoof a MAC address, but that's the command that worked for me last time on an Ubuntu machine.https://github.com/chrislgarry/XFinityHotspotSpoofer/blob/ma...
What I will do is spoof my mac address to match my laptop, and then pass the login wall to create a session. Then restore the original mac address, and then I can finally use my apple tv on the hotel wifi...
I wish they had a web browser on the apple tv.
brew install spoof-mac
or pip install SpoofMACSwitched to Powerline on the command prompt a while ago and can't go back.
Its not unknown for a manufacturer to mess up and reuse MAC addresses.
On a Mac to change your MAC address of the Wi-Fi card, type: ifconfig en0 ether ab:cd:ef:ab:cd:ef
Replace en0 by another interface if needed
Yes UI shows original address and existing connection will use existing address (ie not changed) But if you re-connect (turn off then on WiFi) it will use new one.
Weirdly "disconnect" was always using whatever set in the ifconfig. Meaning that I could "deauthenticate" other people by spoofing their address.