Jump to content

is there a command/method for searching for a single enemy Mac address to reveal its IP like arp -a but searching by Mac address?


careyjames

Recommended Posts

Posted

is there a command/method for searching for a single enemy Mac address to reveal its IP like arp -a but searching by Mac address?

maybe in Nmap?

had a crappy tp link switch that was broadcasting DHCP as a false gateway at the same IP as the real gateway and it did not show up in arp -a scans, it did show up in the mac-address-table of the switches (really nice dymec switches).

we had to do a manual human search of the entire facility to locate that little *******, so i guess I want to know if there was a better way to reveal more info.

also if i did know the mac address of something and wanted to know its ip address without looking through the entire arp -a result is there a command to filter results to the single mac address? man arp was not too helpful..

Posted

Hold up.. What exactly are you planning to do?

Posted
10 minutes ago, kdodge said:

this is maybe not exactly what you are looking for, but the "arping" took is also very handy to interact with the ARP level

well true because even though I did need this command, in that network it would not have helped nor shown results, its funny that the enemy Mac address only showed up in the switches Mac tables and not in the cradle point E3000...

Posted

ARP packets traverse layer two switches, these are the most common type, but not layer three switches or routers.

The easy way to think of it is a router is where your network address changes so it does its work by IP address whereas switches work on the same subnet and so work by ARP first.

That isn't really the best way to describe it, but should give you the idea.

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...