4 ms·
Since most paid wifi networks let you log in without a network password and then gate internet access by redirecting HTTP/DNS requests to a captive portal, it s
by zanecodes 6y ago
Since most paid wifi networks let you log in without a network password and then gate internet access by redirecting HTTP/DNS requests to a captive portal, it should be possible to launch an ARP spoofing attack [0] to impersonate the default gateway, causing all clients to route their traffic to your device, whereupon you can examine it with WireShark or tcpdump to get at their MAC addresses. I've tried something similar while bored on a flight, but sadly the Surface Pro 7's Windows network drivers don't seem to let you change your MAC address.
[0] https://en.wikipedia.org/wiki/ARP_spoofing https://en.wikipedia.org/wiki/ARP_spoofing
- Nextgrid 6y agoIf it's an open (unencrypted) network you don't even need to ARP spoof. Their MAC address will already be in cleartext in the packets - just start your interface in monitor mode on the proper channel and capture some traffic.