Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 35 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Forensics
Track someone using thr MAC/Physical Address?
EH-Net
May 24, 2013, 08:23:49 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Forensics
(Moderator:
don
) >
Track someone using thr MAC/Physical Address?
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Track someone using thr MAC/Physical Address? (Read 85033 times)
0 Members and 1 Guest are viewing this topic.
real.whitehat
Newbie
Offline
Posts: 18
Track someone using thr MAC/Physical Address?
«
on:
July 18, 2007, 04:08:36 PM »
Is it possible to track someone on the internet by converting thr MAC/Physical Address into Internet IP Address?
or in other word, suppose I have Physical Address of someone PC(ex- 00-19-5b-9c-21-34) and I want to know thr IP address, how it could be possible?
Logged
www.whitehatguru.net
Craig
EH-Net Columnist
Jr. Member
Offline
Posts: 69
Re: Track someone using thr MAC/Physical Address?
«
Reply #1 on:
July 18, 2007, 05:11:14 PM »
You will only be able to see their MAC address if you are on the same subnet they are. Any machines separated by a router will not see each other's MACs.
Logged
http://www.sourcesec.com
BiotiC
Newbie
Offline
Posts: 15
Re: Track someone using thr MAC/Physical Address?
«
Reply #2 on:
July 18, 2007, 06:05:44 PM »
To expand slightly on heffnercj's post......
MAC to IP resolution is done using the ARP protocol.
ARP is non-routable so as heffnercj says "Any machines separated by a router will not see each other".
To track someone on the internet via their MAC address would therefore require some external mechanism ie software rn directly, as a worm, etc to feedback the IP address/MAC address relationship back to a central location. This approach would also need to ensure the information from devices that were behind firewalls or devices that were NATed could be captured as well.
Just imagine if Google ran some kind of script every time you accessed their site that did this correlation and held it in some kind of big database - EEEK!!. Scary thought and not beyond the realms of possibility.
«
Last Edit: July 20, 2007, 05:26:08 PM by BiotiC
»
Logged
Craig
EH-Net Columnist
Jr. Member
Offline
Posts: 69
Re: Track someone using thr MAC/Physical Address?
«
Reply #3 on:
July 18, 2007, 07:12:34 PM »
If you're trying to track a particular machine over the Internet, BiotiC is right, the best way would be to have some call-home program installed on it. Although you can theoretically trace a computer based on time skews measured from the time stamp option in TCP packets, it requires gathering several thousand packets, and I'm not aware of it being performed in a real-world situation (paper on it here:
http://www.caida.org/publications/papers/2005/fingerprinting/
).
Of course this could be mitigated by turning off the time stamp option too.
Logged
http://www.sourcesec.com
jimbob
Guest
Re: Track someone using thr MAC/Physical Address?
«
Reply #4 on:
July 19, 2007, 02:52:25 AM »
There are some ways of remotely determining a node's MAC address. Good ol' nbtstat comes to mind for windows machines. Today you are much less likely to receive a response to a NetBIOS query than say 5 years ago but this still works in many cases.
Jim
Logged
real.whitehat
Newbie
Offline
Posts: 18
Re: Track someone using thr MAC/Physical Address?
«
Reply #5 on:
July 19, 2007, 03:48:18 PM »
Thank-you all for your answer
Logged
www.whitehatguru.net
oleDB
Recruiters
Full Member
Offline
Posts: 236
Re: Track someone using thr MAC/Physical Address?
«
Reply #6 on:
July 20, 2007, 11:05:08 AM »
Just curious, how did you get their MAC and not their IP/DNS Hostname?
Logged
jimbob
Guest
Re: Track someone using thr MAC/Physical Address?
«
Reply #7 on:
July 22, 2007, 05:32:06 AM »
Quote from: real.whitehat on July 18, 2007, 04:08:36 PM
or in other word, suppose I have Physical Address of someone PC(ex- 00-19-5b-9c-21-34) and I want to know thr IP address, how it could be possible?
One other piece of information you can get from the MAC address is the vendor of the network device. The first three octets show who the range of MAC addresses is assigned to and you can look this up at...
http://standards.ieee.org/regauth/oui/index.shtml
The MAC address you listed is assigned D-Link, so you can be relatively confident you're looking for a device manufactured by D-Link. Beware that the name branded on the device may differ from who the address is assigned to. A good example is that modern Linksys kit resolved to Cisco Corp, since Cisco bought up Linksys a few years back.
Regards,
Jim
Logged
real.whitehat
Newbie
Offline
Posts: 18
Re: Track someone using thr MAC/Physical Address?
«
Reply #8 on:
July 26, 2007, 08:34:29 AM »
Quote from: oleDB on July 20, 2007, 11:05:08 AM
Just curious, how did you get their MAC and not their IP/DNS Hostname?
>because it was my own laptop MAC address which was stolen by someone
it means almost it is impossible to track any one from there MAC address.
But is it Possible to retrieve MAC address from someones IP address? if yes then pls let me know how to do that.
Logged
www.whitehatguru.net
slimjim100
EH-Net Columnist
Sr. Member
Offline
Posts: 385
Re: Track someone using thr MAC/Physical Address?
«
Reply #9 on:
July 26, 2007, 08:40:02 AM »
To get a MAC from IP you would need to be on the same subnet or have some kind of Trojan program on the victims computer cause the MAC (Layer 2) is not routable on the internet (layer 3 & up).
Brian
Logged
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
jimbob
Guest
Re: Track someone using thr MAC/Physical Address?
«
Reply #10 on:
July 26, 2007, 09:26:33 AM »
One remote possibility would be to wardrive and check for an active client with the same MAC, assuming that the interface was a wireless one. This would only work if
a) the laptop was power up
b) it has joined a wireless network
c) both of the above occur while your driving by
You could possibly set up a fake AP as part of your wardriving kit and hope it associates while your passing by. The chance of success is somewhere between long shot and fantasy however.
Jim
Logged
real.whitehat
Newbie
Offline
Posts: 18
Re: Track someone using thr MAC/Physical Address?
«
Reply #11 on:
July 26, 2007, 09:40:45 AM »
Quote from: jimbob on July 26, 2007, 09:26:33 AM
One remote possibility would be to wardrive.....
Jim
If I'm not wrong then with AP wardriving is possible in Local Area only then how could I track them globally over internet..?
Logged
www.whitehatguru.net
jimbob
Guest
Re: Track someone using thr MAC/Physical Address?
«
Reply #12 on:
July 28, 2007, 01:18:50 PM »
Quote
If I'm not wrong then with AP wardriving is possible in Local Area only then how could I track them globally over internet..?
I think if you really needed to track a stolen laptop we need to forget the MAC address idea. The advice on this thread so far basically says in most cases you need to be on the same subnet as the 'physically compromised' machine to have a chance of tracking it.
There are other possibilities for tracking, but again the chances of success are slim. Is there any software on the laptop that 'phones home'? This might be for example an instant messenger account that's set to log in automatically. You could try creating a new account, adding your old account to your contacts and waiting to see if your account is logged in from elsewhere. The IM provider might give up the IP address but only to law enforcement agency.
The long and the short of it is that you're very unlikely to get your laptop back. Your best bet would be to ensure the theft has been reported to the police and that they have the serial number of the laptop in case it's recovered.
Regards,
Jim
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: Track someone using thr MAC/Physical Address?
«
Reply #13 on:
March 03, 2008, 04:47:24 PM »
Dont change back to your old passwords on any of those accounts. Yes that would work if you were working directly with the server it connected to and got the originating IP and if you had a court order for the ISP to give up the location. You could check a few pawn shops or if you had recorded the mac (dont feel bad you didnt, most people dont) you could wardrive around, but dont spend too much time driving around with $3.00 a gallon gas. Even if you had recorded the mac and had managed to find it wardiving, what would you do? Go bang on the front door of the house? Call the police and try and convince them someone in that house has your laptop because Kismet seems to indicate it? Unless the house is full of Al-Qaeda and you had nuclear secrets on your laptop you will be out of luck. In other words, too much hassle and expense. I hate to say it but the place to start is to start saving up for a new laptop.
«
Last Edit: March 03, 2008, 05:02:51 PM by Kev
»
Logged
rok
Newbie
Offline
Posts: 39
Re: Track someone using thr MAC/Physical Address?
«
Reply #14 on:
June 04, 2008, 10:31:45 AM »
well day by day it seems that internet security is getting tighter.Few years back we can easily get ip.host names withe use of cmd in windows,but nowdays its just noway. I just want to ask is there any way nowdays available for getting ip over global network??
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.