Tab5 logo
Tab5 Lab Visual documentation
Back

Tutorial

Middle Man

Three traffic interception models: ARP MITM on an existing LAN, GITM on a controlled gateway, and Rogue GITM with a cloned real Wi-Fi network.

This page groups three middle-man attack variants used in Lab5 Monster. In every mode, the device sits on the traffic path and can record it, but it gets into that position in a different way.

  • ARP MITM: Lab5 Monster places itself between the phone and the router on the same LAN, records the traffic, and forwards it onward.
  • GITM: Lab5 Monster serves its own network with Internet access. The phone joins it like normal Wi-Fi, while traffic is recorded quietly in the background.
  • Rogue GITM: the original network is deauthenticated and a clone is created, so phones usually switch automatically. That clone still provides Internet access and monitors all traffic.

Below is a short description of each mode and where the interception actually happens.

In ARP MITM, Lab5 Monster operates on the same network as the phone and the router. Forged ARP replies make the phone send packets to the device instead of directly to the router, and the router does the same in the other direction.

The result is simple: Lab5 Monster sits between them, records the traffic, and forwards it onward, so Internet access still works. This is classic MITM inside an existing LAN, without creating a new Wi-Fi network.

The limitation is also simple: this mode only works when all devices are already on the same local Layer 2 network.

ARP MITM diagram preview. Click to open the full-size image.

GITM does not impersonate the router on someone else's network. Instead, Lab5 Monster starts its own Wi-Fi and gives the client Internet access as the real gateway.

The phone joins that network intentionally. All of its traffic passes through capture_gateway, so the device can record it before packets are translated by NAT onto the upstream link.

This creates a cleaner and more controlled scenario than ARP MITM: there is no need to poison ARP, because the client uses Lab5 Monster as its gateway from the beginning.

Upstream

First, Lab5 Monster needs its own Internet uplink through wifi_connect.

Gateway Start

Then capture_gateway creates the Wi-Fi network, DHCP, DNS proxy, routing, and PCAP recording in one flow.

Capture Scope

The recorded traffic is limited to clients connected to that staged network, before NAT translation.

start_rogue_gitm combines a fake access point with GITM mode. Lab5 Monster creates a clone of the real network with the same SSID and password, but routes all traffic through itself.

To make phones switch automatically, the original network can be deauthenticated. To the client, this looks like a brief disconnect followed by a reconnect to the same network, but in practice it lands on a clone controlled by the device.

From that moment on, the clone provides Internet access and monitors all traffic. It is still GITM, but with a more aggressive client takeover than the standard mode where the user chooses the network manually.

Rogue GITM diagram preview. Click to open the full-size image.