NOTE

1.11 Man-in-the-Middle Attack

Definition and mechanics of man-in-the-middle attacks and certificate validation.

SecurityCreated Updated 2 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. What Is a Man-in-the-Middle Attack

A man-in-the-middle attack means that an attacker establishes independent connections with both ends of a communication and exchanges the data it receives, making both communicating parties believe that they are talking directly to each other through a private connection, while in fact the entire session is completely controlled by the attacker. In a man-in-the-middle attack, the attacker can intercept communication between both parties and insert new content.

2. Principle

  • The local request is hijacked (for example, through DNS hijacking), and all requests are sent to the man-in-the-middle server.
  • The man-in-the-middle server returns its own certificate.
  • The client creates a random value, encrypts it with the public key in the man-in-the-middle certificate, and sends it to the man in the middle. It then uses the random value to construct symmetric encryption for transmitting content.
  • Because the man in the middle has the client’s random value, it can decrypt the content through the symmetric encryption algorithm.
  • The man in the middle then sends the client’s request content to the legitimate website.
  • Because the communication between the man in the middle and the server is legitimate, the legitimate website returns encrypted data through the established secure channel.
  • The man in the middle decrypts the content using the symmetric encryption established with the legitimate website.
  • The man in the middle encrypts the data returned by the legitimate website using the symmetric encryption established with the client and sends it to the client.
  • The client decrypts the returned data using the symmetric encryption established with the man in the middle.

Because the client lacks correct certificate validation, although it initiates an HTTPS request, it does not know that its network traffic has been intercepted and the transmitted content is stolen by the man in the middle.

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub