Attack chain 8 steps

Man-in-the-Middle Session Theft

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    The attacker joins the same wireless network as the target, or poisons the local gateway.

  2. 2

    Step 2 of 8

    Unencrypted traffic is observed, revealing which sites the victim visits without TLS.

  3. 3

    Step 3 of 8

    SSL stripping is applied to downgrade the first visit from HTTPS to HTTP.

  4. 4

    Step 4 of 8

    The victim authenticates over the downgraded connection, sending credentials in clear text.

  5. 5

    Step 5 of 8

    Session cookies are captured directly off the wire.

  6. 6

    Step 6 of 8

    Those cookies are replayed from the attacker's browser while the session remains valid.

  7. 7

    Step 7 of 8

    The account is used to change the registered email and lock the victim out.

  8. 8

    Step 8 of 8

    Actions taken under the stolen session are attributed to the legitimate user.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used