Home > Ask the Networking Experts > Network security with Puneet Mehta Questions & Answers > What is a "man in the middle" attack?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What is a "man in the middle" attack?

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 August 2005
What is a ?man in the middle? attack?

>
EXPERT RESPONSE
A "man in the middle" attack or "TCP hijacking" or an "eavesdropping attack" is a well-known attack where an attacker sniffs packets from a network, modifies them and then inserts them back into the network. Simply put, the attacker intercepts network transmissions between two hosts. The attacker then masquerades as one of the hosts, often inserting additional transmissions into the network dialogue.

The man in the middle attack is prevalent in wireless networks as well. In this, the attacker may place a rogue access point in a legitimate wireless network, configure the rogue access point with the valid SSID of the victim's wireless network and thus gather all the sensitive information from authorized users connecting to the wireless network. Some attackers also use a laptop with two wireless network cards, where one card acts as an access point and the other wireless card forwards all the connections from the access point card to the legitimate access point. In cryptography the man in the middle attack is particularly applicable to the original Diffie-Hellman Key exchange protocol, when used without authentication.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network security with Puneet Mehta
What network security threat does a QM FSM error pose in IPsec VPNs?
How to block porn with ISA-server firewalls
Who is responsible for updating network firewalls?
How to locate the lost IP address of an Access Point (AP)
What HIPPA-compliant software would you recommend for online medicine?
To simulate voice over IPSec VPNs which simulators work?
How to set passwords on folders in Windows 2003 servers
What commands allow network traffic to pass through PIX firewalls?
For an SMB firewall, what features should I look at?
Can users on my LAN view my computer from other machines?

Network Security Monitoring
What is a genetic algorithm and where can I learn more about them online?
Networking data visualization not just for pointy-headed bosses
Visual Security Analysis -- 'Applied Security Visualization,' Chapter 5
SIEM platform secures university's open network
Network forensics appliance gets storage boost and 10 GbE support
Tracking NetFlow over MPLS helps airline with compliance
Securing the new network architecture: Security for distributed, dynamic networks
When it comes to data loss prevention, networking should be part of the conversation
What is data loss prevention? -- An introduction to DLP
What are the best methods for handling rogue access points?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts