2.4 On Path Attacks Flashcards

(2 cards)

1
Q

On-path network attack

A
  • How can an attacker watch without you knowing?– Formerly known as man-in-the-middle
  • Redirects your traffic– Then passes it on to the destination– You never know your traffic was redirected
  • ARP poisoning– On-path attack on the local IP subnet– ARP has no security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

On-path browser attack

A
  • What if the middleman was on the same computer
    as the victim?– Malware/Trojan does all of the proxy work– Formerly known as man-in-the-browser
  • Huge advantages for the attackers– Relatively easy to proxy encrypted traffic– Everything looks normal to the victim
  • The malware in your browser waits for you to
    login to your bank– And cleans you out
How well did you know this?
1
Not at all
2
3
4
5
Perfectly