Since it was an open network, it was simple scraping the network for other connected devices and spoofing one at random, and I was surprised when the same technique worked in say, hotels with open networks.
Since it was an open network, it was simple scraping the network for other connected devices and spoofing one at random, and I was surprised when the same technique worked in say, hotels with open networks.
Our punishment was something like two weeks with all internet access revoked (except for the use of lab machines for classwork), plus a written apology, plus a signed agreement not to violate the acceptable use policies again or else face the real punishment for what we did.
The school administrator in charge of the punishment asked the security admin what we were downloading (this was when the MPAA/RIAA were cracking down hard on people uploading files on sharing networks), but the security admin had mercy on us and told her he didn't think it was relevant, thank god!
probably they did lookup the MAC address on the switches and saw it on a port that did not match expectations. if you were using a wired connection this would trivially lead to you... on wireless you would have to narrow it down further by monitoring signal strength of the station :)
There were people running internal torrent trackers and file indexing/sharing sites on the LAN that could saturate the network infrastructure between the various dorms and buildings on campus. I guess the whitelisting also helped figure out who was doing what when problems happened.
you should probably know that using the same mac address in parallel will cause connectivity issues for both...
Most of these systems are distributed and having multiple APs connected to some central Radius server.
Because modern systems optimize for roaming between nodes, you can join network, use dns-sd to gather mac addresses of the computers which are not physically connected to your AP (in conjuction with 'tcpdump -I')
Then voila, 2 devices using same MAC without any problems.
PS. I personally use "printer" addresses for 2 reasons: 1: generally everyone forgets to nicely setup firewall for them since they're infrastructure objects. 2: they have relatively less traffic and probably located some obsecure room with an AP for them.
[0] https://gist.github.com/siraben/c3133b39e470d1aed16fd71f42b8...
[0] https://gist.github.com/siraben/c3133b39e470d1aed16fd71f42b8...