What is a Man-in-the-Middle (MitM) attack and how to avoid it!
ເຜີຍແຜ່ເມື່ອ: 28 ມ.ນ. 2021 · ຝ່າຍສະໜັບສະໜູນ · 6 ນາທີອ່ານ

ສາລະບານ
A MitM attack is usually an aggressive, invasive, and covert attack. A man-in-the-middle attack occurs when someone is between two computers (such as a laptop and a remote server) and is capable of intercepting traffic. Such a person can eavesdrop on or even intercept communication between two machines and steal sensitive information. Man-in-the-middle attacks are a serious security problem.
The days when eavesdropping was the main occupation of spies and town gossip are behind us. In the age of the internet, it has become even easier to get sensitive information.
While we can forgive people who more or less accidentally hear our conversations in public places, digital eavesdropping is at an unprecedented level. It is also much simpler to make. It requires two things: a Wi-Fi connection (whether public, private, secure, or not) and an attack on that network.
In the case of mere eavesdropping, the third person shall be a passive observer and shall not interact in any way between the persons exchanging the information. This is not the case with MitM— not only is there classic eavesdropping, but it can also control the conversation. This fact makes the MitM attack an active activity.
How and where the Man-in-the-Middle attack occurs
The MitM attack is about eavesdropping on networks to gain information or affect transaction, conversations, and real-time data transfer. An attacker could do this by exploiting weaknesses in the network or any of its components, such as a browser or VoIP.
Many organizations practice something that, in essence, is a MitM tactic for monitoring their employees (usually without explicitly admitting it). Another use of this type of practice is aimed at displaying ads (this was the case with the Chinese laptop manufacturer Lenovo).
Another actor known for using MitM is governments that actively spy on their citizens, bypass technological security, spy on hostile states, steal sensitive data, or attack other countries’ financial organizations to get funding for their projects (as is very often the case with North Korea).
MitM is, above all, an integral part of how a very large part of cybercriminals operate. In the event of a Business Email Compromise (BEC) attack, they do so by infiltrating the victim’s network, gaining access to correspondence, monitoring third-party payment requests, and finally instructing the victim to send the payment to the bank account they control.
Types of Men-in-the-Middle attacks
- Wi-Fi eavesdropping
- Email acquisitions
- ARP poisoning
- DNS spoofing
- Port stealing
- STP mangling
The first two types of attacks are the most popular and we described them above. Not every type of attack that is listed can be carried out on any type of network. For example, ARP poisoning can be used to attack systems connected to a LAN over Ethernet.
There are different ways an attacker can perform a MitM attack, such as sniffing, injecting, taking over, filtering, and stripping.
Man-in-the-Middle attack forms
One form of attack is man-in-the-browser (MitB), which starts when malware is placed in the system and works together with the browser. MitB is usually used for financial fraud, e.g. by intercepting communication with a bank.
MitB attacks are extremely dangerous because they are difficult to detect. They omit common security controls and encryption on bank pages and may not be visible to antivirus programs.
Another type of MitM that applies to mobile devices is man-in-the-mobile (MitMo) also known as man-in-the-phone. MitMo is a malware whose main task is to bypass two-step identification via SMS. It does this by monitoring messages with verification codes. Malware focusing on Android devices may have access to encrypted messages on WhatsApp.
In the mobile space, there is another type of attack called man-in-the-app, where an attacker uses a certificate (signed by themselves) to communicate with the attacked application.
In the age of the Internet of Things, man-in-the-cloud and man-in-the-IoT attacks can also be distinguished.
How common are man-in-the-middle attacks
MitM attacks are very widespread, though not to the extent of ransomware or phishing. Some of the types of this attack are easy to carry out, and hacking tools are publicly available. They are carried out not only from the outside, but there are incidents inside the organization where MitM is used to attack the intranet.
Unfortunately, these types of incidents are very difficult to detect, which is why preventive action is so important, which can simultaneously improve network security and privacy.
The Internet of Things is a serious risk
Analysts predict that the number of internet-connected devices will reach tens of billions over the next five years. It is no great secret that these devices are not well protected in terms of cybersecurity. This could mean a big jump in MitM attacks. The main problem in this case will be wrong return messages sent by IoT devices, as well as malicious instructions sent to them.
Popular software used for Man-in-The-Middle attack
- Windows – For example, Cain and Abel – did not use, but it seems a powerful tool for capturing passwords on the network.
- Android – cSploit. It is an open source application prepared for Android phones. To start it, you must have root privileges on your phone. It allows a lot, and its operation boils down to choosing from the menu what we want to do – replace the image, check the network traffic, or decode the sent packets. There are many features!
- Linux – Kali Linux is a Linux distribution for hackers.
What can we do to protect ourselves from MitM attacks?
- Install antivirus software – this way you can avoid man-in-the-middle attacks that are based on the installed malware.
- Avoid public WiFi access points, especially when they’re not password protected. If you are forced to use such a network, do so only, to passively use the Internet without using sites that require data.
- Sign out when you’re done using a page that requires you to sign in. Some pages do this automatically when you close your browser.
- Use multi-step authentication if possible. Virtually all financial parties have a two-step authentication option that becomes standard outside the financial industry as well.
- Use pages that use HTTPS. Make sure you’re on the ‘padlock’ page when you provide any data – HTTPS provides encrypted communication. If you have the option, install an HTTPS Everywhere plug-in that forces your browser to use a secure version of the site.
- Use a virtual private network (VPN) to perform transactions and sensitive communications. A VPN is actually necessary when using public WiFi.
- Set up your router. Make sure you haven’t left the manufacturer’s default login information. Also, make sure that the router is updated.
- Watch out for phishing emails.
Summary
The best remedy for MITM attacks is to read all messages attentively, notify administrators ofanomalies, and install the latest patches to the software you are using, and continuously make users aware of potential threats.
ບົດຄວາມທີ່ກ່ຽວຂ້ອງ

การปิดการอัปเดตอัตโนมัติใน Windows 10
ເຜີຍແຜ່ເມື່ອ: 23 ກ.ລ. 2026
ອ່ານບົດຄວາມ
วิธีป้องกันเว็บแคมจากการถูกแฮ็ก
ເຜີຍແຜ່ເມື່ອ: 23 ກ.ລ. 2026
ອ່ານບົດຄວາມ
อะไรคือโปรแกรมสแกนไวรัสออนไลน์ และการล้างไวรัสในคอม (Online Virus Scanner)
ເຜີຍແຜ່ເມື່ອ: 23 ກ.ລ. 2026
ອ່ານບົດຄວາມ
การเพิ่มความเร็วให้กับ Windows 10
ເຜີຍແຜ່ເມື່ອ: 23 ກ.ລ. 2026
ອ່ານບົດຄວາມ