Video summary
On-path Attacks - CompTIA Security+ SY0-701 - 2.4
Main summary
Key takeaways
Main ideas and concepts
-
On-path attacks (Man-in-the-Middle):
- An attacker positions themselves between two devices so they can observe all traffic exchanged between them.
- The attacker forwards information from one device to the other.
- While forwarding, the attacker can:
- Read/monitor the transmitted data
- Modify data in real time
- Key risk: victims generally have no indication the attack is occurring; it is effectively invisible to the victim devices.
-
On-path attacks via ARP poisoning / ARP spoofing:
- ARP poisoning targets the local IP subnet.
- Because ARP has no built-in security or encryption, it is relatively easy to execute.
-
On-path browser (Man-in-the-Browser):
- Instead of placing an attacker on the network path, malware/Trojan runs on the victim’s own device.
- It acts as a proxy to intercept traffic before and after it leaves the device.
- Even if network traffic is encrypted, this approach can still reveal information because interception happens on the device, where data may be visible in the clear.
ARP poisoning example (step-by-step flow)
-
Setup / scenario
- Victim laptop:
- IP:
192.168.1.9 - MAC: ends in
38 ... Delta 5(as given by the subtitles)
- IP:
- Router:
- IP:
192.168.1.1 - MAC: ends in
... Bravo Bravo Foxtrot Echo
- IP:
- Attacker:
- IP:
192.168.1.14 - MAC: ends in
... Echo Echo Fox Fox
- IP:
- Assumption: the attacker is on the same local subnet as the victim (because ARP poisoning is local).
- Victim laptop:
-
Normal behavior: how the laptop learns the router’s MAC
- When the laptop first connects, it knows the router’s IP but not its MAC.
- The laptop uses Address Resolution Protocol (ARP) to resolve IP → MAC.
- The laptop sends a broadcast: “Who has
192.168.1.1? Send your MAC address.” - The router receives the broadcast and replies with:
- “I am
192.168.1.1” + the router’s MAC address.
- “I am
- The laptop stores this in its local ARP cache so it doesn’t repeat the ARP request every time.
- The ARP cache eventually times out and will be refreshed later (causing ARP to run again).
-
Attack: poisoning the ARP cache
- Because the laptop currently has a cached mapping for the router’s IP → MAC, it won’t immediately re-query.
- The attacker sends an unsolicited ARP response stating:
- “
192.168.1.1is at my MAC address” (the attacker’s MAC).
- “
- Since ARP lacks authentication/security, the laptop accepts the response and overwrites its ARP cache entry for
192.168.1.1with:- IP:
192.168.1.1 - MAC: attacker’s MAC
- IP:
- The same poisoning process can also be applied to the router’s ARP cache so both directions route through the attacker.
-
Resulting impact
- Now, when the laptop ↔ router communicate, traffic is routed through the attacker’s device.
- The attacker can:
- Monitor traffic
- Modify data being sent between devices
- Potentially disrupt/disable the connection between laptop and router
On-path browser (man-in-the-browser) example (conceptual flow)
-
Threat mechanism
- Malware/Trojan on the victim device is configured as a proxy.
- It redirects/intercepts traffic before it goes out and after it comes back.
-
Why encryption doesn’t fully help
- Even if network traffic is encrypted, interception on the same device can allow the attacker to see information in the clear.
-
Credential capture and session abuse
- The malware waits for the victim to log into a sensitive site (e.g., a bank).
- It captures:
- username
- password
- other credentials
- After the victim logs in, the attacker uses the captured credentials to start additional sessions in the background, such as:
- transferring data between accounts
- spending money on online shopping sites
- performing actions requiring captured username/password
Speakers / sources featured
- No specific speakers or named individuals are featured in the provided subtitles.
- The content appears to be instructional narration for the course topic.