[Wifi] Airodump-ng mac address for AP 00:00:00:00:00:00!?


Alright so I havn't fired up the ol' Airodump in a while so i figured might as well see if anybody got any new APs!

But what I found was just the normal... Until!

I found a 3 clients connected to an AP with the mac of 00:00:00:00:00:00!!! lol

The clients had abnormal macs too. something like 52:a5:b3:16:e8:03 which is REALLY odd cuz from what I know, that could only mean a spoofed mac right?

I was just wondering if you guys wud have any thoughts on this???

--Thanks in advance!

It's pretty common these days for people to spoof their wireless mac address.

Broadcast mac addresses I think are all f's (ex: ff:ff:ff:ff:ff:ff)

Someone is most definately spoofing a mac address though. You can look up the vendor portion for mac addresses: http://www.coffer.com/mac_find/

No vendor for the one mac address 52:a5:b3:16:e8:03, so it is most likely spoofed: http://www.coffer.com/mac_find/?string=52%3Aa5%3Ab3

Xerox uses 00-00-00 for its first six hex code identification, but there should be some trailing hex values for the last six, which means, it's most definately spoofed. (A real xerox device would look something like 00:00:00:FA:05:0D)

There is also a quick lookup table if you want to save it to your pc for offline lookup after a night of wardriving: http://standards.ieee.org/regauth/oui/oui.txt

The access point with all 0's might not be a real router, but possibly someone with multiple cards and setting up a fake access point to sniff traffic.

