4 ms·
Q. Can I detect a MITM (machine in the middle) attack? A. No, not easily. https://security.stackexchange.com/questions/12066/can-i-detect-a-mitm-attack https:/
by oropolo 7y ago
Q. Can I detect a MITM (machine in the middle) attack?
A. No, not easily.
https://security.stackexchange.com/questions/12066/can-i-detect-a-mitm-attack https://security.stackexchange.com/questions/12066/can-i-det...
- acdha 7y agoThat’s one answer of many and it’s wrong. A correct answer would discuss the various active and passive detection methods and their weaknesses, and especially how it’s easy to detect an unskilled attack but progressively harder to foil a sophisticated one. Simple examples: 1. Analysis of TCP details could detect an intermediary proxy 2. TLS conflicts tell you a bad attacker is trying; use of a certificate from a different CA or an old one tells you someone has been compromised. 3. Attempts to block or throttle TLS, downgrade protocols, or block/degrade access to security updates tells you someone is trying to encourage you to act in an insecure manner. 4. If you send unique canary hostnames or URLs which are accessed, you know something has compromised your traffic. 5. Timing analysis can tell you that some target sites are being treated differently, which could be a sign that traffic is being more tightly monitored (IIRC this has been noticed with the great firewall). 6. HTTP pages can be requested from multiple sources and compared for modifications. I once learned about some JavaScript being injected into pages on Iranian college computers when their code triggered errors this way.