Computing.Net > Forums > Security and Virus > Cable Internet Exploit found??

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Cable Internet Exploit found??

Reply to Message Icon

Original Message
Name: Calvin
Date: June 25, 2003 at 09:47:45 Pacific
Subject: Cable Internet Exploit found??
OS: xp
CPU/Ram: 800/256
Comment:

Hey Guyz,
i know this is kind of long but please read the whole thing, because I need some help i have some questions towards the end that I'm very very stumped on. but you'll probably need to read the whole thing to see how this all happned.

I recently edit/changed my M.A.C address for my Linksys Network card in windows XP using regedt32 not regedit. Many

articles on google on how to do that. Just type change mac registry. Anyways It was very interesting. I was able to change my

mac address not phsyicall of course but just as good as if it was. Anyways It was interesting because when I changed it I got

a whole differnt ip address. And I was even logged on to a different sub net as well I hope I'm using the right terminalogy.

for instance instead of 12.255.1.1-255 I was able to obtain a different ip address such as 12.255.8.1-255 each time i changed

my mac address and was able to to get ip address ex. 12.255.1-14.1-255 hope that makes sense. Anyways heres the real

interesting part. I got a MAC address scanner. It would scan my network 12.255.8.1-255 for MAC addresses. Well I was only

able to get mac addresses for only 12.255.8.1-255 even though I put it to scan
12.255.1.1 - 12.255-14.255 it searched all of those numbers but I only got results for any computers in 12.255.8.1-255 so I

changed my MAC address again, and I was able to get into 12.255.10.1-255 so I scanned whole network again, this time I didn't

get reults for 12.255.8.1-255 I got results only for 12.255.10.1-255 which was really interesting to me. I know that means

something and could be exploited more. Perhaps I am given more rights with in my local subnet mask then others. But its funny

because i could keep changing my mac address and get into different subnet masks. Well keep reading there is some more very

interesting stuff I found out about this!!!!


So I figured the Server on ComCast/ATT end assigned you an ip address acording to your MAC address. I noticed that it

would assign u the same ip address everytime for the same MAC address/ different mac address different ip address. So I got

my friends MAC address who leaves down the street a few blocks. I asked him to turn off his computer and and un plug his

cable modem. I then entered in his MAC address into my Registry, then disabled and then enabled my network card. For changes

to take effect. He then booted up and had no internet. I check my IP address I had the same IP address as he did when he had

internet as well as his MAC address. I kind of knew this would happen. Some of u may already did. But keep reading some more

interesting stuff happend that I'm stumped on. So I was thinking wow I could pretty much get any one's IP and Mac address in

my town, and when they logged of the next time they got back on they would have no internet. But anyways so I played with

this for a day or so. Changing my MAC address to all kinds of different numbers and stuff and each time was sucessful and

also I was getting some cool Ip addresses. Anyways well the fun soon stopped for some reason. Perhaps the Network Admin

noticed something. I don't know what he did but now I'll change my MAC address, in my network card status it'll say invalid

IP, So I'll click repair and that fails, But then I'll get a different IP address like I did before even though it Failed to

repair, but no it wasn't 169 it looked to be valid. But None of my internet worked, and every time I tried to Repair the Ip

address it would fail. So I changed it back to my real MAC address. And my interent still didn't work so I called up TEch

Support I guess for some reason my hardware account was removed meaning I guess my cable modem wasn't on the system i had to

re-register it. So I did that and My internet worked fine as long as I didn't change my mac address. Which is funny because I

could change it before to all kinds of stuff and I'd just get a different IP address, As if I changed my network card. This

is interesting because why can't I change it now and get internet still. Are they assingning me an IP address Via my Cable

modem's MAC address? Any ideas what they may have did to make it so I can't do that anymore? All the input we can get on this

would be great. Just trying to figure out what the Network Admins might have done or if theres any way around this. I also

noticed that now when I change my Mac address that I get a private Ip address that starts with 169. but that might be

something on my end but i'm thinking they changed some stuff on their end making it so I can't even get a new IP. This is

another interesting fact. So I called up my friends house up the street. I got his MAC address again and asked him to log off

and everything again like we did before. So I put in his MAC address and same stuff happend no internet. I only have 2

guesses maybe 3 to why this is happening. 1. They know my computer name and are restricting it to only my oringal mac address

or something. or 2. They changed it so I'm only getting an IP address according to my Cable Modem's MAC address. or 3 they

changed the settings for the whole system making it more secure. I"m just trying to figure out what they may have done or if

theres some ways around it. So guyz give me all your ideas and thoughts or experinces. Maybe try it and see if it works for

u.

here are some links
mac address scanner
http://www.youngzsoft.net/cc-get-mac-address/download.htm
http://www.klcconsulting.net/Change_MAC_w2k.htm - changing your mac

1 other though perhaps they are restriciting my IP range to only my 1 Ip address. So put your thoughts ideas or experince

would be great.
Thanks


Report Offensive Message For Removal


Response Number 1
Name: wawadave
Date: June 25, 2003 at 10:24:02 Pacific
Reply: (edit)

they will have blocked you at the server to only have one ip. keep messing around they might just disconect you.you are onto something.some linux people wrote some things on this you might fined it with a search useing linuxgoogle search engine.


Report Offensive Follow Up For Removal

Response Number 2
Name: EC
Date: June 25, 2003 at 16:55:38 Pacific
Reply: (edit)

The ISPs have IP ranges (blocks), of which your and your neighbors can be assigned.
That IP 12.XXX resolves to AT&T WorldNet, likely your ISP.
Those cable people always want your MAC NIC # but you can clone it easily.
Besides, playing around like that is fun, great way to learn BUT ISPs can be real short on patience, so I'd leave it alone as you may be without service...at anytime, and that is just not worth it.


Report Offensive Follow Up For Removal

Response Number 3
Name: FBI Agent
Date: June 26, 2003 at 13:43:23 Pacific
Reply: (edit)

its very likly they assigned you a static address, since no matter what, you always have the same IP. but i have a question. what part of the registry do you edit to change your mac address?


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 7 Days.
Discuss in The Lounge
Poll History




Data Recovery Software