Sunday, July 20, 2008

How MAC SPOOFING is done

For Windows: There are number of tools for MAC spoofing. but here i will discuss how MAC can be spoofed using Registry Editor. All you need is a MAC id.

Before starting spoofing MAC , run ipconfig/all from command line and see what network interfaces are present in the system along with description. Please note the actual MAC Id to verify where it has been changed or not.

1. open start->run->regedit

2. go to HKLM\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}

3. There are various sub folders under it. Browse through all the folders and see the DriverDesc key value.If it is similar to the the interface which you have, see for another key called NetworkAddress. If it is not present,create it with the data type REG_SZ and provide the new MAC Id as its value.

4. Reset the Network Adapter for which MAC has been changed.

5. verify whether MAC has been changed by running ipconfig/all again.


Most probably you have successfully changed your MAC.

how it is Done is Linux ??? Next post.

No comments: