High severity Attack Technique

Man-in-the-Middle (MitM)

The attacker silently relays and alters traffic between two parties who think they are alone.

Overview

On an open Wi-Fi network, ARP or DNS spoofing lets an attacker read and rewrite unencrypted sessions, harvesting cookies and injecting responses.\nSSL stripping downgrades an HTTPS link to HTTP before the browser can object.\nTLS with HSTS, certificate pinning on mobile clients, and trusted DNS are the countermeasures.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Unexpected certificate warnings
  • Gateway MAC changing mid-session
  • Session cookies observed on the wire

Controls that stop it

  • Enforce Multi-Factor Authentication

    Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.

  • Harden TLS and Security Headers

    Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used