Like TAPE said early on in the piece, you can brute force it with mdk3, or you can wait around.
There are some older routers that will glitch if you don't have a *valid* mac in there, so try with a 11:22:33:44:55:66 address (or all zeroes etc.). On the whole though, if you can't sniff a client, or you can't brute force a MAC you're SOL. Another thought occurs - an old pentest revealed that if you could detect a wired MAC it would (in some cases) let you inject frames on the wireless side. I found this out by accident, misread a capture file.
Basically, just try things out and see what happens. You never know.



