There are 7 types of MITM attacks.
Cybercriminals can use MITM attacks to gain control of devices in a variety of ways.
1⣠IP spoofing
Every device capable of connecting to the internet has an internet protocol (IP) address, which is similar to the street address for your home. By spoofing an IP address, an attacker can trick you into thinking youâre interacting with a website or someone youâre not, perhaps giving the attacker access to information youâd otherwise not share.
2⣠DNS spoofing
Domain Name Server, or DNS, spoofing is a technique that forces a user to a fake website rather than the real one the user intends to visit. If you are a victim of DNS spoofing, you may think youâre visiting a safe, trusted website when youâre actually interacting with a fraudster. The perpetratorâs goal is to divert traffic from the real site or capture user login credentials.
3⣠HTTPS spoofing
When doing business on the internet, seeing âHTTPSâ in the URL, rather than âHTTPâ is a sign that the website is secure and can be trusted. In fact, the âSâ stands for âsecure.â An attacker can fool your browser into believing itâs visiting a trusted website when itâs not. By redirecting your browser to an unsecure website, the attacker can monitor your interactions with that website and possibly steal personal information youâre sharing.
4⣠SSL hijacking
When your device connects to an unsecure server â indicated by âHTTPâ â the server can often automatically redirect you to the secure version of the server, indicated by âHTTPS.â A connection to a secure server means standard security protocols are in place, protecting the data you share with that server. SSL stands for Secure Sockets Layer, a protocol that establishes encrypted links between your browser and the web server.
In an SSL hijacking, the attacker uses another computer and secure server and intercepts all the information passing between the server and the userâs computer.
5⣠Email hijacking
Cybercriminals sometimes target email accounts of banks and other financial institutions. Once they gain access, they can monitor transactions between the institution and its customers. The attackers can then spoof the bankâs email address and send their own instructions to customers. This convinces the customer to follow the attackersâ instructions rather than the bankâs. As a result, an unwitting customer may end up putting money in the attackersâ hands.
6⣠Wi-Fi eavesdropping
Cybercriminals can set up Wi-Fi connections with very legitimate sounding names, similar to a nearby business. Once a user connects to the fraudsterâs Wi-Fi, the attacker will be able to monitor the userâs online activity and be able to intercept login credentials, payment card information, and more. This is just one of several risks associated with using public Wi-Fi. You can learn more about such risks here.
7⣠Stealing browser cookies
To understand the risk of stolen browser cookies, you need to understand what one is. A browser cookie is a small piece of information a website stores on your computer.
For example, an online retailer might store the personal information you enter and shopping cart items youâve selected on a cookie so you donât have to re-enter that information when you return.
A cybercriminal can hijack these browser cookies. Since cookies store information from your browsing session, attackers can gain access to your passwords, address, and other sensitive information.
Please help update this post...