Posts

Showing posts from March, 2019

Man In the middle attack

Image
A man-in-the-middle attack (MitM) is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.Usually, this is automatically done throught SSL certificates checked by your browser against a given set of recognized certificate authorities).  If you get a security exception message such as this one you might be the victim of a man-in-the-middle attack and should not bypass the warning unless you have another trusted way of checking the certificate's fingerprint with the people running the service.But on top of that the certificate authorities model of trust on the Internet is susceptible to various methods of compromise.  For example, on March 15, 2011, Comodo, one of the major SSL certificates authorities, reported that a user account with a