SlideShare a Scribd company logo
Man-In-The-Middle Attacks
Definition
• Man-in-the-Middle (MitM) attacks happen when traffic
between two parties is observed or manipulated by an
unknown third party.
• A MitM attack is a cybercrime method used to steal
personal information or login credentials. Cyber
criminals also use MitM attacks as a means to spy on,
corrupt information, or disrupt communications
between two parties.
2
Since the 1980s,
MitM attacks
have been used
to infiltrate
traffic between
innocent parties.
Methods
Man-in-the-Middle attacks can happen in a number of
ways:
• Types of Spoofing (IP, DNS, HTTPS)
• Hijacking (Secure Socket Layer, Email)
• Wi-Fi Eavesdropping
• Theft of Browsing Cookies
3
Man-in-the-Browser:
• When a Man-in-the-Browser attack takes place, the
attacker uses a Phishing method in order to
administer malware to a device.
• Malware is software meant to damage a network,
server or personal computer.
4
Phishing is a
method of
sending
fraudulent
emails or text
messages to
trick a user into
revealing
personal
information.
Man-in-the-Browser Continued
• A Man-in-the-Browser attack happens when malware
installs itself on a victim’s browser in order to record
information sent between targeted websites and the
user.
• Online banking institutions are prone to this form of
cybercrime.
5
Example of Man-in-the-Browser
6
IP Spoofing
• All devices that connect to the internet have an IP
Address.
• Spoofing happens when someone or something
impersonates a trusted source.
• Attackers use IP Spoofing in order to deceive users
into revealing sensitive information by “spoofing”
their IP and posing as a website or someone familiar.
7
An IP Address is
like your home
address.
Example of IP Spoofing
8
DNS Spoofing
• DNS refers to “Domain Name Server/System”. The
DNS system converts names to IP Addresses.
• When Spoofing a DNS, a user is forced to an imitation
website, similar to the one intended to be viewed.
• The goal of the attacker is to divert traffic or retrieve
login credentials.
9
Example: The
DNS will return
the IP address of
a visited website
when it is typed
into a browser.
Example of DNS Spoofing
10
HTTPS Spoofing
• HTTPS stands for Hypertext Transfer Protocol Secure.
This protocol is used by the Web to format and
transmit messages.
• Ensure that when visiting a website, the URL indicates
that it uses “https” rather than “http”.
11
HTTPS Spoofing
• In HTTPS Spoofing, the attacker manipulates the
browser into believing it is visiting a trusted website.
• After redirecting your browser, the attacker uses the
vulnerable website to monitor communication and
steal shared information.
12
SSL Hijacking
• SSL stands for Secure Sockets Layer, which was a
protocol developed in order to communicate over the
internet securely.
• Sometimes when a device visits an unsecure website
(http), it is automatically redirected to the secure
version (https).
• An attacker utilizes a computer and secure server to
reroute information of a user right before connection
to a legitimate server, this is SSL Hijacking.
13
Email Hijacking
• Email Hijacking occurs when attackers target financial
organizations for email information.
• After obtaining access to email accounts, attackers
can monitor all financial transactions.
• Attackers then follow up by “spoofing” the financial
institution’s email and possibly providing users with
instructions that would result in the attacker receiving
funds.
14
Wi-fi Eavesdropping
• Wi-Fi connections can be configured and appear to
have a valid name, such as the Wi-fi of a favourite
coffee shop.
• If a user connects to the fraudulent Wi-Fi connection,
the user’s online activities can be observed and
personal information like banking cards can be
attained.
15
Precautions
should be taken
when connecting
to public Wi-Fi
connections.
Example of Wi-fi Eavesdropping
16
Precautions
should be taken
when connecting
to public Wi-Fi
connections.
Browser Cookies
• A browser cookie is a small piece of
data stored by the user’s web
browser. This data is used to track
browsing sessions.
• If browsing data is stored in a cookie
and the browser cookie is hijacked,
cybercriminals may be able to gain
passwords, addresses and other
sensitive information.
17
Protection
• Ensure that the browser is using “https” when
browsing the web.
• Be on alert of Phishing emails that request credentials
to be updated.
18
Protection Continued
• Refrain from connecting to public Wi-Fi connections
without a VPN.
• Make use of internet security applications to thwart
MitB attacks.
19

More Related Content

Similar to Man in the Middle.pptx

Man in the middle
Man in the middleMan in the middle
Man in the middle
AhmadThaqifAimanAhma
 
Cyber attacks
Cyber attacks Cyber attacks
Cyber attacks
Anuradha Moti T
 
edu 3 ppt.pptx
edu 3 ppt.pptxedu 3 ppt.pptx
edu 3 ppt.pptx
ArchaWashington
 
HTTPS
HTTPSHTTPS
Unit 3B.pdf
Unit 3B.pdfUnit 3B.pdf
Unit 3B.pdf
TuhinUtsabPaul
 
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
GIRISHKUMARBC1
 
Types of Attack in Information and Network Security
Types of Attack in Information and Network SecurityTypes of Attack in Information and Network Security
Types of Attack in Information and Network Security
padmeshagrekar
 
Chp-15 Cyber Safety ppt-std 11.pptx
Chp-15 Cyber Safety ppt-std 11.pptxChp-15 Cyber Safety ppt-std 11.pptx
Chp-15 Cyber Safety ppt-std 11.pptx
HarishParthasarathy4
 
Malware attack Social engineering attack
Malware attack  Social engineering attackMalware attack  Social engineering attack
Malware attack Social engineering attack
taufiq463421
 
Cyber Crime
Cyber CrimeCyber Crime
Cyber Crime
Animesh Shaw
 
You think you are safe online. Are You?
You think you are safe online. Are You?You think you are safe online. Are You?
You think you are safe online. Are You?
TechGenie
 
Phishing
PhishingPhishing
Cyber Law & Forensics
Cyber Law & ForensicsCyber Law & Forensics
Cyber Law & Forensics
Harshita Ved
 
Cyber security best practices power point presentation
Cyber security best practices power point presentationCyber security best practices power point presentation
Cyber security best practices power point presentation
AbcdEfg576575
 
E commerce
E commerceE commerce
Lecture 2.pptx
Lecture 2.pptxLecture 2.pptx
Lecture 2.pptx
MuhammadRehan856177
 
Tools and methods used in cyber crime
Tools and methods used in cyber crimeTools and methods used in cyber crime
Tools and methods used in cyber crime
shubhravrat Deshpande
 
Internet security
Internet securityInternet security
Internet security
Mohamed El-malki
 
Lecture 2.pptx
Lecture 2.pptxLecture 2.pptx
Lecture 2.pptx
MuhammadRehan856177
 
Dos & Ddos Attack. Man in The Middle Attack
Dos & Ddos Attack. Man in The Middle AttackDos & Ddos Attack. Man in The Middle Attack
Dos & Ddos Attack. Man in The Middle Attack
marada0033
 

Similar to Man in the Middle.pptx (20)

Man in the middle
Man in the middleMan in the middle
Man in the middle
 
Cyber attacks
Cyber attacks Cyber attacks
Cyber attacks
 
edu 3 ppt.pptx
edu 3 ppt.pptxedu 3 ppt.pptx
edu 3 ppt.pptx
 
HTTPS
HTTPSHTTPS
HTTPS
 
Unit 3B.pdf
Unit 3B.pdfUnit 3B.pdf
Unit 3B.pdf
 
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
Cyber Security Module 3.pptx Cybersecurity is the practice of protecting syst...
 
Types of Attack in Information and Network Security
Types of Attack in Information and Network SecurityTypes of Attack in Information and Network Security
Types of Attack in Information and Network Security
 
Chp-15 Cyber Safety ppt-std 11.pptx
Chp-15 Cyber Safety ppt-std 11.pptxChp-15 Cyber Safety ppt-std 11.pptx
Chp-15 Cyber Safety ppt-std 11.pptx
 
Malware attack Social engineering attack
Malware attack  Social engineering attackMalware attack  Social engineering attack
Malware attack Social engineering attack
 
Cyber Crime
Cyber CrimeCyber Crime
Cyber Crime
 
You think you are safe online. Are You?
You think you are safe online. Are You?You think you are safe online. Are You?
You think you are safe online. Are You?
 
Phishing
PhishingPhishing
Phishing
 
Cyber Law & Forensics
Cyber Law & ForensicsCyber Law & Forensics
Cyber Law & Forensics
 
Cyber security best practices power point presentation
Cyber security best practices power point presentationCyber security best practices power point presentation
Cyber security best practices power point presentation
 
E commerce
E commerceE commerce
E commerce
 
Lecture 2.pptx
Lecture 2.pptxLecture 2.pptx
Lecture 2.pptx
 
Tools and methods used in cyber crime
Tools and methods used in cyber crimeTools and methods used in cyber crime
Tools and methods used in cyber crime
 
Internet security
Internet securityInternet security
Internet security
 
Lecture 2.pptx
Lecture 2.pptxLecture 2.pptx
Lecture 2.pptx
 
Dos & Ddos Attack. Man in The Middle Attack
Dos & Ddos Attack. Man in The Middle AttackDos & Ddos Attack. Man in The Middle Attack
Dos & Ddos Attack. Man in The Middle Attack
 

Recently uploaded

Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
concepsionchomo153
 
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
taqyea
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
Cover Story - China's Investment Leader - Dr. Alyce SU
Cover Story - China's Investment Leader - Dr. Alyce SUCover Story - China's Investment Leader - Dr. Alyce SU
Cover Story - China's Investment Leader - Dr. Alyce SU
msthrill
 
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
valvereliz227
 
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
ISONIKELtd
 
Prescriptive analytics BA4206 Anna University PPT
Prescriptive analytics BA4206 Anna University PPTPrescriptive analytics BA4206 Anna University PPT
Prescriptive analytics BA4206 Anna University PPT
Freelance
 
Science Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around UsScience Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around Us
PennapaKeavsiri
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
CULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for dukeCULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for duke
ZevinAttisha
 
Lukas Rycek - GreenChemForCE - project structure.pptx
Lukas Rycek - GreenChemForCE - project structure.pptxLukas Rycek - GreenChemForCE - project structure.pptx
Lukas Rycek - GreenChemForCE - project structure.pptx
pavelborek
 
L'indice de performance des ports à conteneurs de l'année 2023
L'indice de performance des ports à conteneurs de l'année 2023L'indice de performance des ports à conteneurs de l'année 2023
L'indice de performance des ports à conteneurs de l'année 2023
SPATPortToamasina
 
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
dpbossdpboss69
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
Discover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling ServiceDiscover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling Service
obriengroupinc04
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
Adani case
 
Kirill Klip GEM Royalty TNR Gold Lithium Presentation
Kirill Klip GEM Royalty TNR Gold Lithium PresentationKirill Klip GEM Royalty TNR Gold Lithium Presentation
Kirill Klip GEM Royalty TNR Gold Lithium Presentation
Kirill Klip
 
TriStar Gold Corporate Presentation - June 2024
TriStar Gold Corporate Presentation - June 2024TriStar Gold Corporate Presentation - June 2024
TriStar Gold Corporate Presentation - June 2024
Adnet Communications
 

Recently uploaded (20)

Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
欧洲杯投注-欧洲杯投注外围盘口-欧洲杯投注盘口app|【​网址​🎉ac22.net🎉​】
 
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
Cover Story - China's Investment Leader - Dr. Alyce SU
Cover Story - China's Investment Leader - Dr. Alyce SUCover Story - China's Investment Leader - Dr. Alyce SU
Cover Story - China's Investment Leader - Dr. Alyce SU
 
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
 
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
1 Circular 003_2023 ISO 27001_2022 Transition Arrangments v3.pdf
 
Prescriptive analytics BA4206 Anna University PPT
Prescriptive analytics BA4206 Anna University PPTPrescriptive analytics BA4206 Anna University PPT
Prescriptive analytics BA4206 Anna University PPT
 
Science Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around UsScience Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around Us
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
CULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for dukeCULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for duke
 
Lukas Rycek - GreenChemForCE - project structure.pptx
Lukas Rycek - GreenChemForCE - project structure.pptxLukas Rycek - GreenChemForCE - project structure.pptx
Lukas Rycek - GreenChemForCE - project structure.pptx
 
L'indice de performance des ports à conteneurs de l'année 2023
L'indice de performance des ports à conteneurs de l'année 2023L'indice de performance des ports à conteneurs de l'année 2023
L'indice de performance des ports à conteneurs de l'année 2023
 
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
Call 8867766396 Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian M...
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
Discover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling ServiceDiscover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling Service
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Indian Matka
 
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
Adani Group's Active Interest In Increasing Its Presence in the Cement Manufa...
 
Kirill Klip GEM Royalty TNR Gold Lithium Presentation
Kirill Klip GEM Royalty TNR Gold Lithium PresentationKirill Klip GEM Royalty TNR Gold Lithium Presentation
Kirill Klip GEM Royalty TNR Gold Lithium Presentation
 
TriStar Gold Corporate Presentation - June 2024
TriStar Gold Corporate Presentation - June 2024TriStar Gold Corporate Presentation - June 2024
TriStar Gold Corporate Presentation - June 2024
 

Man in the Middle.pptx

  • 2. Definition • Man-in-the-Middle (MitM) attacks happen when traffic between two parties is observed or manipulated by an unknown third party. • A MitM attack is a cybercrime method used to steal personal information or login credentials. Cyber criminals also use MitM attacks as a means to spy on, corrupt information, or disrupt communications between two parties. 2 Since the 1980s, MitM attacks have been used to infiltrate traffic between innocent parties.
  • 3. Methods Man-in-the-Middle attacks can happen in a number of ways: • Types of Spoofing (IP, DNS, HTTPS) • Hijacking (Secure Socket Layer, Email) • Wi-Fi Eavesdropping • Theft of Browsing Cookies 3
  • 4. Man-in-the-Browser: • When a Man-in-the-Browser attack takes place, the attacker uses a Phishing method in order to administer malware to a device. • Malware is software meant to damage a network, server or personal computer. 4 Phishing is a method of sending fraudulent emails or text messages to trick a user into revealing personal information.
  • 5. Man-in-the-Browser Continued • A Man-in-the-Browser attack happens when malware installs itself on a victim’s browser in order to record information sent between targeted websites and the user. • Online banking institutions are prone to this form of cybercrime. 5
  • 7. IP Spoofing • All devices that connect to the internet have an IP Address. • Spoofing happens when someone or something impersonates a trusted source. • Attackers use IP Spoofing in order to deceive users into revealing sensitive information by “spoofing” their IP and posing as a website or someone familiar. 7 An IP Address is like your home address.
  • 8. Example of IP Spoofing 8
  • 9. DNS Spoofing • DNS refers to “Domain Name Server/System”. The DNS system converts names to IP Addresses. • When Spoofing a DNS, a user is forced to an imitation website, similar to the one intended to be viewed. • The goal of the attacker is to divert traffic or retrieve login credentials. 9 Example: The DNS will return the IP address of a visited website when it is typed into a browser.
  • 10. Example of DNS Spoofing 10
  • 11. HTTPS Spoofing • HTTPS stands for Hypertext Transfer Protocol Secure. This protocol is used by the Web to format and transmit messages. • Ensure that when visiting a website, the URL indicates that it uses “https” rather than “http”. 11
  • 12. HTTPS Spoofing • In HTTPS Spoofing, the attacker manipulates the browser into believing it is visiting a trusted website. • After redirecting your browser, the attacker uses the vulnerable website to monitor communication and steal shared information. 12
  • 13. SSL Hijacking • SSL stands for Secure Sockets Layer, which was a protocol developed in order to communicate over the internet securely. • Sometimes when a device visits an unsecure website (http), it is automatically redirected to the secure version (https). • An attacker utilizes a computer and secure server to reroute information of a user right before connection to a legitimate server, this is SSL Hijacking. 13
  • 14. Email Hijacking • Email Hijacking occurs when attackers target financial organizations for email information. • After obtaining access to email accounts, attackers can monitor all financial transactions. • Attackers then follow up by “spoofing” the financial institution’s email and possibly providing users with instructions that would result in the attacker receiving funds. 14
  • 15. Wi-fi Eavesdropping • Wi-Fi connections can be configured and appear to have a valid name, such as the Wi-fi of a favourite coffee shop. • If a user connects to the fraudulent Wi-Fi connection, the user’s online activities can be observed and personal information like banking cards can be attained. 15 Precautions should be taken when connecting to public Wi-Fi connections.
  • 16. Example of Wi-fi Eavesdropping 16 Precautions should be taken when connecting to public Wi-Fi connections.
  • 17. Browser Cookies • A browser cookie is a small piece of data stored by the user’s web browser. This data is used to track browsing sessions. • If browsing data is stored in a cookie and the browser cookie is hijacked, cybercriminals may be able to gain passwords, addresses and other sensitive information. 17
  • 18. Protection • Ensure that the browser is using “https” when browsing the web. • Be on alert of Phishing emails that request credentials to be updated. 18
  • 19. Protection Continued • Refrain from connecting to public Wi-Fi connections without a VPN. • Make use of internet security applications to thwart MitB attacks. 19

Editor's Notes

  1. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  2. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  3. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  4. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  5. References: https://www.imperva.com/learn/application-security/man-in-the-middle-attack-mitm/
  6. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  7. References: https://en.wikipedia.org/wiki/IP_address_spoofing
  8. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  9. References: https://www.imperva.com/learn/application-security/dns-hijacking-redirection/
  10. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  11. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  12. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  13. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html https://unit42.paloaltonetworks.com/threat-brief-conversation-hijacking-spear-phishing/
  14. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  15. References: https://due.com/blog/12-reasons-never-use-public-wi-fi/
  16. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html https://www.wikiwand.com/en/HTTP_cookie
  17. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html
  18. References: https://us.norton.com/internetsecurity-wifi-what-is-a-man-in-the-middle-attack.html https://www.csoonline.com/article/3340117/what-is-a-man-in-the-middle-attack-how-mitm-attacks-work-and-how-to-prevent-them.html