Skip to main content
Book 07 · SecurityPage 21 of 50

Man-in-the-Middle Attack

Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/man-in-the-middle

In short

A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.

What is a man-in-the-middle attack?

In a man-in-the-middle (MITM) attack, the attacker places themselves on the communication path between a user and a service, such as a browser and a bank's website. Both sides think they are talking directly to each other, but every message passes through the attacker, who can read it, steal passwords or session cookies, or quietly change it. Security guidance increasingly calls this an on-path or adversary-in-the-middle attack.

Attackers get into the middle in several ways: a fake public Wi-Fi hotspot, poisoning a local network so traffic is sent to the wrong machine (ARP spoofing), forged DNS answers that point a domain to the wrong server, or a phishing proxy site that forwards everything to the real site. The attack only works if the traffic is unencrypted or the victim accepts a forged identity, which is why defenses focus on encryption and on verifying who is on the other end.

Picture a mail carrier who opens your letters, reads them, maybe edits them, reseals the envelopes, and delivers them as if nothing happened. TLS, the protocol behind HTTPS, stops this by encrypting the letter and checking a certificate that proves the site's identity, so a middleman sees only scrambled data and cannot impersonate the server without triggering a browser warning. HSTS, a header that tells browsers to always use HTTPS for a site, closes the gap where a first plain HTTP request could be intercepted.

MITM is often confused with eavesdropping or with phishing. Passive eavesdropping only listens, while a MITM attacker actively relays and can modify messages. Phishing tricks a person into visiting a fake site, and some phishing kits then act as a man in the middle to capture both the password and the one-time MFA code, which is why phishing-resistant methods such as passkeys, which are bound to the real domain, are recommended.

Key takeaways

  • The attacker secretly relays, and can alter, traffic between two parties.
  • Common entry points include rogue Wi-Fi, ARP spoofing, DNS spoofing, and phishing proxies.
  • TLS with proper certificate validation is the main defense for network traffic.
  • HSTS keeps browsers from making an unencrypted first request to your site.
  • Passkeys and security keys resist phishing proxies that capture passwords and MFA codes.

Example

Keeping TLS certificate checks turned on (Python)python
import requests

# Safe: requests verifies the server's TLS certificate by default,
# so an attacker in the middle cannot pose as api.example.com
response = requests.get("https://api.example.com/data", timeout=10)

# Dangerous: verify=False accepts any certificate, including an attacker's.
# Never ship this, even "temporarily" to get past a certificate error.
# requests.get("https://api.example.com/data", verify=False)

Readers ask

Can HTTPS prevent man-in-the-middle attacks?

HTTPS stops most of them, because TLS encrypts the traffic and the certificate proves the server's identity. It fails if an app disables certificate validation, if a user clicks through a certificate warning, or if an attacker's certificate authority has been installed on the device.

Is public Wi-Fi safe to use?

It is much safer than it used to be because most sites and apps now use HTTPS, so someone on the same network cannot read the encrypted content. Still, never ignore certificate warnings, keep your device updated, and be cautious with networks you don't recognize.

What is the difference between a man-in-the-middle attack and eavesdropping?

Eavesdropping is passive: the attacker only listens to traffic. A man-in-the-middle attacker is active, relaying messages between both sides and able to change them, such as swapping a bank account number in a payment request.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings