This page groups three middle-man attack variants used in Lab5 Monster. In every mode, the device sits on the traffic path and can record it, but it gets into that position in a different way.
- ARP MITM: Lab5 Monster places itself between the phone and the router on the same LAN, records the traffic, and forwards it onward.
- GITM: Lab5 Monster serves its own network with Internet access. The phone joins it like normal Wi-Fi, while traffic is recorded quietly in the background.
- Rogue GITM: the original network is deauthenticated and a clone is created, so phones usually switch automatically. That clone still provides Internet access and monitors all traffic.
Below is a short description of each mode and where the interception actually happens.