Security Basics mailing list archives

RE: Detecting Spoofed MAC


From: "Maxime Ducharme" <mducharme () cybergeneration com>
Date: Thu, 30 Nov 2006 15:50:38 -0500

 

Hello

I use arpwatch to log ARP activity on our networks
http://www.google.com/search?q=arpwatch

It can send you an email when a new MAC is seen

Maxime

 

-----Message d'origine-----
De : listbounce () securityfocus com [mailto:listbounce () securityfocus com] De
la part de divinepresence () gmail com
Envoyé : 29 novembre, 2006 04:45
À : security-basics () securityfocus com
Objet : Detecting Spoofed MAC

Hi all
Is there a tool to determine whether the MAC has been spoofed on a system
(Win/*nix) for a given interface? Also, is it possible to know the real MAC
in such a case? I was wondering if you could hook up to some system info API
which would provide you with this information assuming that this detail is
stored at some location which is not affected by spoofing.

Thanks
Ankur Jindal


Current thread: