On-Path
Man-in-the-Middle:
On-path positioning
2. LAN requires physical connections
On-path steps
APR Poisoning
Address Resolution Protocol - OSI Layer 2.
MITM mac address
arpspoof
Tool for ARP Spoofing
dnsspoof
sub dns for legit site
bettercap
Tool for ARP and DNS poisoning
Port Stealing
2. Uses victim’s MAC address
SSL Stripping
converts HTTPS to HTTP
Redirect https port (80) to stripped http port (8080)
sslstrip
tool for SSLSTRIPPING
ARP Poisoning
Floods ARP tables