Attacks
Man in the middle
What is a man in the middle attack?
In a man in the middle attack an attacker slips unnoticed between two parties. They read along and can alter what is transmitted, while both sides believe they are talking directly to each other.
The classic place for this is an open wireless network. The attacker provides an access point that looks like the hotel's or the airport's network. Whoever connects to it sends all their traffic through the attacker's device.
The most effective protection is encryption. On an encrypted connection, recognisable by the https in the address bar, the attacker cannot read the content. Browser warnings about a certificate are to be taken seriously here, because they are exactly what points to such an attempt.
For your business that means access from the road runs through an encrypted connection into the company network, and the accounts are protected with a second factor. A password read in transit is then not yet access.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.