05-12-2020, 06:20 PM 
(This post was last modified: 05-12-2020, 07:45 PM by WPA_Catcher.)
		
	
	
		OK I understand about the ROGUE naming thank you.
How does hcxdumptool decide what MAC (BSSID) to use for an AP (ESSID) that a client is probing for if the real AP is not within range of the either the client or the penetration tester?
I assumed hcxdumptool just spoofed one.
I am guessing that the output from hcxhashtool --info= with regard to MAC addresses is not to be used for MAC tracing? I just thought that it was only the "ROGUE attack" AP MAC that was not genuine.
What do you think of the WPS test suggestion?
Thanks
	
	
	
	
How does hcxdumptool decide what MAC (BSSID) to use for an AP (ESSID) that a client is probing for if the real AP is not within range of the either the client or the penetration tester?
I assumed hcxdumptool just spoofed one.
I am guessing that the output from hcxhashtool --info= with regard to MAC addresses is not to be used for MAC tracing? I just thought that it was only the "ROGUE attack" AP MAC that was not genuine.
What do you think of the WPS test suggestion?
Thanks
 
 

 
