Man In The Middle Editing Websites


If doing a MITM attack, you essentially control what is being passed back and forth to the end user. You could then swap out websites and redirect them to other sites, or even using something like ettercap, change all the images on the sites they visit or worse, phish their logins and passwords by impersonating legitimate sites using something like SET to do the cloning for you in real time..

Once you control their connection, its pretty much limitless control unless they encrypt their traffic. Also know that it is possible to strip SSL from their connection as well, so don't think https alone will save you.

