2

I was surfing the web at 3 in the morning and I got a warning which seems to indicate a MITM attack. Does this mean the attacker was able to passive sniff my activity in real-time in order to launch the attack?

user7149
  • 129
  • 2
  • 8

1 Answers1

1

I think Yes, it has to be in real time.

As I understand the attack, it poisons the cache of arp entries in your OS using arp replies, and due to ARP protocol standards, it updates the cache of the OS immediately even if the entries is not expired.

After the attack is finished, the OS updates the ARP cache after multiple 'futile' requests using the poisoned cache.

Eibo
  • 2,485
  • 3
  • 19
  • 32