Network Attacks
Attacks That Live on the Network
The network was built to be fast and open, not secure. Many core protocols trust whatever they are told. Network attacks abuse that trust to watch traffic (a passive attack) or to change and redirect it (an active attack). This lesson covers four you must know.
Legal note: Everything here is for understanding and defence. Only test on your own lab or with written permission. Intercepting other people's traffic is a serious offence under Nigeria's Cybercrimes Act 2015, the UK Computer Misuse Act 1990 and the US CFAA.
1. Packet Sniffing
A sniffer (Wireshark, tcpdump) records packets passing a network card. On an open Wi-Fi network, or a hub, or a compromised switch port, an attacker can capture traffic meant for others.
- Clear-text protocols (HTTP, FTP, Telnet) expose usernames, passwords and pages.
- Encrypted protocols (HTTPS, SSH) still leak metadata such as who talked to whom and when, but not the content.
Defence: use HTTPS/TLS and VPNs, avoid clear-text protocols, and never trust open public Wi-Fi.
2. ARP Poisoning
Inside a local network, devices find each other using ARP, which maps an IP address to a hardware (MAC) address. ARP has no authentication: any device can announce "I am the router" and the others will believe it.
Attacker -> Victim : "192.168.1.1 (the router) is at MAC AA:BB:CC:DD:EE:FF" (attacker's MAC)
Attacker -> Router : "192.168.1.24 (the victim) is at MAC AA:BB:CC:DD:EE:FF"
Now all traffic between the victim and the router flows through the attacker. This is the setup for a man-in-the-middle attack.
Defence: dynamic ARP inspection and port security on switches, static ARP entries for critical devices, and encryption so that intercepted data is useless.
3. Man-in-the-Middle (MitM)
In a man-in-the-middle attack the attacker sits between two parties, reading and sometimes altering messages while both believe they are talking directly.
Common ways to get there: ARP poisoning on a LAN, a rogue or "evil twin" Wi-Fi hotspot named like the cafe network, or a compromised router.
Example: in a busy Lagos or Nairobi airport lounge, a fake hotspot called "Airport_Free_WiFi" lets travellers connect. If a user opens a banking site over plain HTTP, the attacker can capture the login. Modern HTTPS with certificate checks and HSTS stop most of these attacks, and the browser's certificate warning is the last line of defence, so never click through it.
Defence: HTTPS/HSTS, VPN on untrusted Wi-Fi, certificate validation, and user awareness of certificate warnings.
4. DNS Spoofing (Cache Poisoning)
If an attacker can put a false answer into a DNS resolver's cache, or answer faster than the real resolver, everyone using that resolver is sent to the wrong IP.
You ask: www.mybank.com ?
Attacker: www.mybank.com is at 203.0.113.66 (attacker's server)
Result: a perfect-looking fake login page
The victim types the correct address and still lands on the attacker's site. Because the fake site can present a login form, this is a powerful way to harvest credentials.
Defence: DNSSEC (signed DNS records), DNS over HTTPS/TLS, patched resolvers with randomised ports, and TLS certificate checks, because the attacker cannot get a valid certificate for the real domain.
Spotting the Signs
| Attack | Warning sign |
|---|---|
| ARP poisoning | Duplicate MAC addresses in the ARP table, sudden "gateway" MAC change |
| Evil twin / MitM | Certificate warnings, two networks with the same name |
| DNS spoofing | Known domain resolving to an unexpected IP, certificate mismatch |
| Sniffing | Hard to detect. Prevent with encryption |
Bringing It Together
Notice the pattern: each attack exploits trust without verification. ARP trusts announcements, DNS trusts answers, users trust Wi-Fi names. The answer is layered defence: encrypt everything, authenticate endpoints, segment the network and monitor for anomalies. Next you will learn the defensive tools that put this into practice.
Try it yourself
Key Takeaways
- Many network protocols (ARP, plain DNS, HTTP) trust what they are told, and attacks abuse that trust.
- Packet sniffing captures traffic, and clear-text protocols expose passwords and content. Encrypt to defend.
- ARP poisoning tricks devices about who owns an IP address, and it is the setup for LAN man-in-the-middle attacks.
- DNS spoofing sends users to a fake site even when they type the correct address. DNSSEC, DoH and certificate checks help.
- Evil twin hotspots and certificate warnings are the everyday face of MitM. Never click through a warning, and use a VPN on untrusted Wi-Fi.
Quick Quiz
1.Why does ARP poisoning work on a local network?
2.You type your bank's correct URL but a valid-looking page appears with a browser certificate warning. What is the safest action?
3.Which control best protects against packet sniffing on public Wi-Fi?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx