How Attackers Use It
Attack Summary
Attacker positions themselves between a client and server — via ARP spoofing, rogue Wi-Fi, or DNS poisoning — to intercept, read, or modify traffic in real time.
- Attacker gains network position through rogue APs or spoofing.
- Traffic is intercepted and optionally downgraded or modified.
- Credentials, session tokens, and sensitive payloads are harvested.
- Manipulated responses deliver malware or force malicious redirects.