2.4 - On-Path Attacks Flashcards
1
Q
On-path network attack
A
- How can an attacker watch without you knowing?
– Formerly known as man-in-the-middle - Redirects your traffic
– Then passes it on to the destination
– You never know your traffic was redirected - ARP poisoning
– On-path attack on the local IP subnet
– ARP has no security
– ARP poisoning (spoofing)
2
Q
On-path browser attack
A
- What if the middleman was on the same
computer as the victim?
– Malware/Trojan does all of the proxy work
– Formerly known as man-in-the-browser - Huge advantages for the attackers
– Relatively easy to proxy encrypted traffic
– Everything looks normal to the victim - The malware in your browser waits for you
to login to your bank
– And cleans you out
3
Q
ARP poisoning (spoofing)
A