What is man-in-the-middle (MITM)?
Man-in-the-Middle (MITM) is a type of network attack in which the attacker secretly places themselves between two communicating parties and intercepts or alters the transmitted data.
In simple terms: you think you are communicating directly with the server, but in reality someone is "sitting in the middle" and seeing everything.
How MITM works in simple terms
Normally:
User ⇄ Server
With MITM:
User ⇄ Attacker ⇄ Server
In this case:
- the user thinks they are communicating with the server;
- the server thinks it is communicating with the user;
- the attacker can read, alter or record the data.
What the attacker can do
During a MITM attack, they can:
- steal logins and passwords;
- intercept cookies and sessions;
- read private messages;
- alter data (for example, payment details).
Often the user notices nothing.
Typical examples of MITM attacks
1. Interception on public Wi-Fi
- an open network in a cafe or airport;
- the attacker controls the access point;
- traffic is read or altered.
2. ARP spoofing on a local network
- the attacker forges ARP tables;
- traffic passes through their device.
3. HTTPS spoofing
- if the connection is not secured or the certificate is forged;
- the attacker reads the data "in plain form."
Which security properties are violated
- Confidentiality - the data is read;
- Integrity - the data can be altered.
How to defend against MITM
Main measures:
- traffic encryption (HTTPS, TLS);
- VPN;
- certificate verification;
- avoiding open Wi-Fi without protection;
- using HSTS.
Encryption is the main defense against MITM.
A simple example
MITM is like:
you send a letter to a friend, and the mail carrier opens it, reads it, sometimes changes the text, and seals it again.
Short Answer
Interview readyPremium
A concise answer to help you respond confidently on this topic during an interview.