Metasploit mailing list archives

Re: All MAC addresses for subnet 41:41:41:41:41:41


From: Carlos Pantelides <carlos_pantelides () yahoo com>
Date: Tue, 28 Feb 2012 05:22:03 -0800 (PST)

Perhaps all the "hosts" are the same host with virtual interfaces? Some kind of NAT/portforwarding?

 
Carlos Pantelides


-----------------


http://seguridad-agile.blogspot.com/


________________________________
 From: Sagar Belure <sagar.belure () gmail com>
To: framework () spool metasploit com 
Sent: Tuesday, February 28, 2012 9:32 AM
Subject: [framework] All MAC addresses for subnet 41:41:41:41:41:41
 

meterpreter > run arp_scanner -r 192.168.0.0/24
[*] ARP Scanning 192.168.0.0/24
[*] IP: 192.168.0.3 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.0 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.1 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.9 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.2 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.8 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.7 MAC 41:41:41:41:41:41
<..snip..>

[*] IP: 192.168.0.255 MAC 41:41:41:41:41:41
[*] IP: 192.168.0.254 MAC 41:41:41:41:41:41

</..snip..>

Has anyone came across this problem?
Indeed, I found some live hosts having port(80,135,443,445) open on some of the hosts.
But, could not figure out the possibility of all IP addresses bounded to the same MAC address.

Can someone please lend some light on this?

Thanks,
Sagar Belure


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: