Skip to content

Man-in-the-Middle

A Man-in-the-Middle (MITM) attack places the attacker between two parties who believe they’re communicating directly, letting them read, modify, or inject traffic. It’s a pattern, not a single technique: it’s achieved many ways (ARP spoofing, DNS spoofing, rogue DHCP, mitm6, rogue AP, WPAD). Once in the middle, the attacker harvests credentials, steals sessions, downgrades encryption, and redirects the victim.

MITM exploits victims’ trust in the network path. If the attacker gets traffic to pass through them —by poisoning ARP, spoofing DNS, posing as the gateway or DHCP server— they can act on communications meant to be private. End-to-end encryption (well-implemented TLS, HSTS, validated certificates) is the defense that turns a MITM into “metadata only”.

ARP spoofing layer 2, same segment (see net-arp) -> the most common
DNS spoofing answer DNS queries with fake IPs (see net-dnsattacks)
rogue DHCP fake DHCP server -> assign controlled gateway/DNS
mitm6 DHCPv6/IPv6 DNS -> IPv6 is usually on and unwatched (see net-ipv6)
LLMNR/NBT-NS answer name resolutions (see ad-llmnr)
Rogue AP / Evil Twin fake WiFi access point (see wireless)
WPAD malicious auto-proxy
# intercept and capture
bettercap -iface eth0 # ARP spoof + sniff + MITM modules
# downgrade encryption
# SSL stripping: force HTTP where HSTS doesn't prevent it (sslstrip/bettercap)
# redirect
# DNS spoofing: the victim asks for bank.com -> you give your IP (phishing)
# capture/relay Windows authentication
Responder + ntlmrelayx # Net-NTLMv2 hashes and relay (see ad-llmnr/ad-ntlm)

On corporate networks, the most rewarding MITM isn’t ARP but spoofing name resolution (LLMNR/NBT-NS/mDNS) and mitm6 (IPv6). You capture Net-NTLMv2 hashes or relay them to other services → direct access (see LLMNR / NBT-NS / mDNS Poisoning, NTLM Relay). It’s the most reliable initial-access chain in AD.

SSL stripping downgrades HTTPS to HTTP by intercepting the first request. HSTS stops it (the browser demands HTTPS), and HSTS preload prevents it entirely. Against well-configured sites, the MITM sees an encrypted connection but not the content.

  • Symptoms of the underlying techniques: ARP changes (ARP Spoofing), unexpected DNS replies, unauthorized DHCP servers, anomalous DHCPv6 traffic (mitm6), unexpected WPAD.
  • Certificate alerts on clients (TLS intercepted with an invalid cert).
  • LLMNR/NBT-NS resolutions answered by non-legitimate hosts.
  • Strong end-to-end encryption: HTTPS + HSTS (preload), SSH, VPN; validate certificates.
  • Layer 2/3: DAI, DHCP snooping, port security, 802.1X; RA Guard/DHCPv6 Guard (mitm6).
  • Disable LLMNR/NBT-NS/WPAD and IPv6 if unused (cuts Responder/mitm6 — see LLMNR / NBT-NS / mDNS Poisoning).
  • Enforce SMB/LDAP signing (breaks relay — see NTLM Relay).
  • Segmentation and network monitoring.

Identify and isolate the attacker host, revert the poisoning (ARP/DNS/DHCP), rotate credentials that may have been captured, and deploy the missing L2/L3 and signing controls.

  • MITM is a category (MITRE T1557: ARP, LLMNR/NBT-NS, DHCP spoofing).
  • mitm6 + ntlmrelayx (Dirk-jan Mollema) is a standard AD-compromise chain via IPv6.
  • SSL stripping (Moxie Marlinspike, 2009) drove the massive adoption of HSTS.
  • Open WiFi and poorly segmented corporate networks remain a common scene of real MITM.
  • Pick the MITM path by environment (ARP/DNS/DHCP/mitm6/LLMNR)
  • Get in the middle without cutting the connection (forwarding)
  • Capture traffic and credentials (sniffing)
  • Try SSL stripping (does HSTS prevent it?)
  • DNS spoofing to redirect to a controlled host
  • Windows: Responder + relay (hashes/access)
  • Blue: are E2E encryption, signing, L2/L3 controls present?
  • Document what stayed protected by encryption