Man-in-the-Middle
A Man-in-the-Middle (MITM) attack places the attacker between two parties who believe they’re communicating directly, letting them read, modify, or inject traffic. It’s a pattern, not a single technique: it’s achieved many ways (ARP spoofing, DNS spoofing, rogue DHCP, mitm6, rogue AP, WPAD). Once in the middle, the attacker harvests credentials, steals sessions, downgrades encryption, and redirects the victim.
Threat model
Section titled “Threat model”MITM exploits victims’ trust in the network path. If the attacker gets traffic to pass through them —by poisoning ARP, spoofing DNS, posing as the gateway or DHCP server— they can act on communications meant to be private. End-to-end encryption (well-implemented TLS, HSTS, validated certificates) is the defense that turns a MITM into “metadata only”.
Red Team — ways to get in the middle
Section titled “Red Team — ways to get in the middle”ARP spoofing layer 2, same segment (see net-arp) -> the most commonDNS spoofing answer DNS queries with fake IPs (see net-dnsattacks)rogue DHCP fake DHCP server -> assign controlled gateway/DNSmitm6 DHCPv6/IPv6 DNS -> IPv6 is usually on and unwatched (see net-ipv6)LLMNR/NBT-NS answer name resolutions (see ad-llmnr)Rogue AP / Evil Twin fake WiFi access point (see wireless)WPAD malicious auto-proxyWhat to do once in the middle
Section titled “What to do once in the middle”# intercept and capturebettercap -iface eth0 # ARP spoof + sniff + MITM modules# downgrade encryption# SSL stripping: force HTTP where HSTS doesn't prevent it (sslstrip/bettercap)# redirect# DNS spoofing: the victim asks for bank.com -> you give your IP (phishing)# capture/relay Windows authenticationResponder + ntlmrelayx # Net-NTLMv2 hashes and relay (see ad-llmnr/ad-ntlm)The Windows case: Responder + relay
Section titled “The Windows case: Responder + relay”On corporate networks, the most rewarding MITM isn’t ARP but spoofing name resolution (LLMNR/NBT-NS/mDNS) and mitm6 (IPv6). You capture Net-NTLMv2 hashes or relay them to other services → direct access (see LLMNR / NBT-NS / mDNS Poisoning, NTLM Relay). It’s the most reliable initial-access chain in AD.
SSL stripping and its limits
Section titled “SSL stripping and its limits”SSL stripping downgrades HTTPS to HTTP by intercepting the first request. HSTS stops it (the browser demands HTTPS), and HSTS preload prevents it entirely. Against well-configured sites, the MITM sees an encrypted connection but not the content.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- Symptoms of the underlying techniques: ARP changes (ARP Spoofing), unexpected DNS replies, unauthorized DHCP servers, anomalous DHCPv6 traffic (mitm6), unexpected WPAD.
- Certificate alerts on clients (TLS intercepted with an invalid cert).
- LLMNR/NBT-NS resolutions answered by non-legitimate hosts.
Hardening
Section titled “Hardening”- Strong end-to-end encryption: HTTPS + HSTS (preload), SSH, VPN; validate certificates.
- Layer 2/3: DAI, DHCP snooping, port security, 802.1X; RA Guard/DHCPv6 Guard (mitm6).
- Disable LLMNR/NBT-NS/WPAD and IPv6 if unused (cuts Responder/mitm6 — see LLMNR / NBT-NS / mDNS Poisoning).
- Enforce SMB/LDAP signing (breaks relay — see NTLM Relay).
- Segmentation and network monitoring.
Response
Section titled “Response”Identify and isolate the attacker host, revert the poisoning (ARP/DNS/DHCP), rotate credentials that may have been captured, and deploy the missing L2/L3 and signing controls.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- MITM is a category (MITRE T1557: ARP, LLMNR/NBT-NS, DHCP spoofing).
- mitm6 + ntlmrelayx (Dirk-jan Mollema) is a standard AD-compromise chain via IPv6.
- SSL stripping (Moxie Marlinspike, 2009) drove the massive adoption of HSTS.
- Open WiFi and poorly segmented corporate networks remain a common scene of real MITM.
Testing checklist
Section titled “Testing checklist”- Pick the MITM path by environment (ARP/DNS/DHCP/mitm6/LLMNR)
- Get in the middle without cutting the connection (forwarding)
- Capture traffic and credentials (sniffing)
- Try SSL stripping (does HSTS prevent it?)
- DNS spoofing to redirect to a controlled host
- Windows: Responder + relay (hashes/access)
- Blue: are E2E encryption, signing, L2/L3 controls present?
- Document what stayed protected by encryption