[SYS] HACKAACADEMY FIELD TERMINAL v5.3.0
[INTEL] Ghost Protocol comms channel — ARP cache poisoned — INTERCEPTOR in position
[FIND] HTTPS stripped to HTTP — credentials passing in plaintext
[WARN] INTERCEPTOR monitoring — traffic anomaly detection active
[HANDLER] RAVEN — Ghost Protocol Phase 6 — channel secured
[PRIORITY] OPERATION INTERCEPT // OP-17 // MITM + SSL STRIP
[TARGET] Get between sender and receiver. Read every word. Change whatever you want.
[SYS] The Ghost Protocol talks to itself. We are going to listen.
«
‹
HACKAACADEMY
OP-17 // INTERCEPT // MAN-IN-THE-MIDDLE // SSL STRIP
0
XP
R1
RANK
0%
DET
↻
RESET
📷
CAMPAIGN 3 — OPERATION INTERCEPT
MAN-IN-THE-MIDDLE + SSL STRIP // TARGET: GHOST PROTOCOL COMMS
17
NETWORK ATTACK — CAMPAIGN 3

MAN-IN-THE-MIDDLE
+ SSL STRIP

ARP POISONING // TRAFFIC INTERCEPTION // CREDENTIAL THEFT
OPERATION INTERCEPT
📡

SITUATION REPORT

CLASSIFIED
Six Ghost Protocol nodes down. Inside their Amsterdam operations floor the Syndicate is communicating frantically — Director Kane's people scrambling to coordinate a response before we burn the rest. All that communication travels across the local network.

INTERCEPTOR manages the Ghost Protocol internal communications infrastructure. He knows about HTTPS. He uses it. What he does not know: an attacker on the same network can sit between two machines and strip that HTTPS protection away before either machine notices.

Here is how it works: we send fake ARP messages to both machines — the sender and the receiver. Each machine now thinks our device is the other one. Every message between them passes through us first. We read it. We can change it. We pass it on.

Then we strip HTTPS down to HTTP. The sender connects to us over HTTPS. We connect to the real server over HTTPS. But we serve the sender plain HTTP — so their credentials travel to us in plaintext. INTERCEPTOR sees HTTPS in his browser. He has no idea we are in the middle.
THE NOTE PASSER IN CLASS
CHILD-LEVEL EXPLANATION
Imagine two people passing messages through a messenger. The messenger is supposed to deliver messages exactly as received. But instead, he secretly reads and sometimes changes them before passing them on.

Both people believe they are communicating directly with each other.
If someone sits between two friends passing notes — and neither friend knows — what can that person do with every note?
INTERCEPTED — INTERCEPTOR COMMS
14:07 UTC
INTERCEPTOR
"Relax — all Syndicate internal comms use HTTPS and our certificates are valid. The channel is encrypted end to end — no one on the network can read our messages. Not even SHADOW."
RAVEN
Shadow — INTERCEPTOR is right about HTTPS protecting against passive eavesdropping. He forgot about active interception. We are not passively listening. We poisoned the ARP table on both machines. They both think we are each other. The HTTPS goes from the sender to us — not to the real server. We see it all. Then we forward it.
MISSION OBJECTIVES
01
TARGET: the NEXUS office LAN — staff portal served over plain HTTP on the internal VLAN, ARP wide open with no authentication
02
EXPLOIT: Forge an ARP reply to sit between a staffer and the router, then read their login POST in cleartext off the wire
03
SWEEP: Run the Traffic Classifier — read live packets and flag which scenarios show MitM or SSL Strip vs safe traffic
04
WIN: Capture the field flag, then lock it down — the defence that makes MitM useless even on a network you fully control
⚠ ETHICAL NOTICE: Man-in-the-Middle and SSL Strip attacks are covered by CompTIA Security+, CEH, OSCP, and every professional network security certification. All interactions here are fully simulated. Real network interception testing requires explicit written authorisation from the network owner.
THE ATTACK — STEP BY STEP
ARP poisoning — position yourself as a man-in-the-middle on a LAN by convincing both victim and gateway that your MAC address is the other's:
# ARP poison with arpspoof: # Tell victim YOUR MAC = gateway's IP: arpspoof -i eth0 -t 192.168.1.100 192.168.1.1 # Tell gateway YOUR MAC = victim's IP: arpspoof -i eth0 -t 192.168.1.1 192.168.1.100 # Enable forwarding so traffic still flows: echo 1 > /proc/sys/net/ipv4/ip_forward # Capture cleartext credentials: tcpdump -i eth0 -A port 80 | grep -iE "(password|user|login)"
Wireshark passive capture on an open Wi-Fi or misconfigured hub — no ARP poisoning needed, packets arrive promiscuously. Filter: http.request.method == POST to find login forms.
COMMON VARIATIONS
1. SSL stripping — downgrade HTTPS to HTTP transparently using sslstrip, capturing credentials before encryption is applied:
# After ARP poisoning, redirect HTTPS traffic through sslstrip: iptables -t nat -A PREROUTING -p tcp --destination-port 443 -j REDIRECT --to-port 8080 sslstrip -l 8080
2. Wi-Fi Evil Twin — set up a fake access point with the same SSID as a legitimate one. Clients connect, all traffic flows through the attacker.

3. BGP hijacking — at the internet routing level, announce a more specific route for a target IP prefix to reroute traffic through attacker-controlled infrastructure. Used by nation-states.
HOW TO DEFEND
Enforce TLS everywhere and use HSTS to prevent downgrade:
# Nginx — force HTTPS with HSTS: server { listen 80; return 301 https://$host$request_uri; } server { listen 443 ssl; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; # HSTS — browser refuses HTTP for 1 year: add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"; } # Submit domain to hstspreload.org for browser preload list — # then browsers NEVER attempt HTTP even on first visit
At network level: use Dynamic ARP Inspection (DAI) on managed switches to reject forged ARP replies. Use 802.1X port authentication on corporate networks.
⚡ CYBER RANGE — ACTIVE ENVIRONMENT
LIVE
TARGET
ghost-internal-net.ghost-capital.int
IP ADDRESS
10.47.1.0/24
OS / SERVER
Network segment — Linux routing node
KEY SERVICES
ARP · HTTP · HTTPS · sslstrip · arpspoof
ATTACK SCOPE
LAN segment — ARP cache + HTTP traffic in scope
ATTACKER NODE
shadow@sigma9 · 10.99.0.1
📋 ROOM TASKS
01
✓
Understand how ARP spoofing positions an attacker in the traffic path
02
▶
Perform ARP spoofing to intercept and read network traffic
03
○
Classify protected vs vulnerable network configurations
04
○
Identify the HSTS preload + 802.1X fix
05
○
Submit the capture-the-flag token
🚩
CAPTURE THE FLAG
Complete the exploit lab. The flag appears in the terminal output. Copy and submit it here for +50 XP.
PHASE 01
READ THE TRAFFIC
EXPLOIT
SIGMA-9 CAPTURE LOG — HOW WE FOUND IT
02:47 UTC
> passive sniff on the NEXUS office LAN — tcpdump on a mirrored switch port
> staff portal login still served over plain HTTP, no TLS on the internal VLAN
> FOUND: a POST /login flew past with username + password in cleartext
MENDAX: "They encrypted the front door and left the hallway wide open. Everything inside that VLAN is readable. We don't need to break HTTPS — we just stand where it isn't."
MENDAX — HOW THIS IS ACTUALLY DONE
LIVE
MENDAX
First we put our interface on the wire and watch the cleartext HTTP traffic. tcpdump dumps the raw payload of anything on port 80.
$ tcpdump -i eth0 -A 'tcp port 80 and host portal.nexus.int' # -A prints packet payload as ASCII so we can read the form fields listening on eth0, link-type EN10MB (Ethernet)
MENDAX
When a staffer logs in, their credentials cross the wire in plain text. The POST body is right there — no decryption needed.
$ # captured frame: POST /login HTTP/1.1 Host: portal.nexus.int Content-Type: application/x-www-form-urlencoded username=k.reyes&password=Nexus!Spring24
MENDAX
That's a live staff credential, Shadow. We can ride it straight in — or poison ARP and grab every session on the segment. Your call.
RAVEN
ENCRYPTED
You just pulled a staffer's username and password off the wire in cleartext — without breaking a single lock. You sat on the NEXUS LAN, sent one forged ARP reply, and their traffic started flowing through your machine instead of the router.

Here is the mechanism: on a local network every device has an IP address and a MAC address, and ARP (Address Resolution Protocol) is how machines find each other — "who has this IP? What is your MAC?" ARP has no authentication. Any device can lie: "I am 10.10.0.1 — my MAC is AA:BB:CC:DD:EE:FF."

Machine A wants to reach Machine B, looks up B's MAC, and finds your forged answer. So A sends its traffic straight to you. You read it, then pass it along — neither side notices.

You just read their traffic by standing in the middle. Now make the call: why does this still work when the targets are on HTTPS?
TAP AN ANSWER — EXPLANATION APPEARS IMMEDIATELY
RAVEN — HINT (−20 XP)
Think in layers. ARP works at the network layer — it decides which physical machine receives the packet. HTTPS works at the application layer — it encrypts the data inside the packet. If ARP redirects the packet to our machine first, HTTPS still happens — but it happens between the sender and us, not the sender and the real server.
✓
MITM MECHANISM UNDERSTOOD
ARP decides where the packet goes on the physical network. HTTPS encrypts what is inside the packet. When we poison ARP, we redirect packets to our machine before HTTPS even applies. The sender connects to us with HTTPS — thinking we are the real server. We connect to the real server separately. We sit in the middle of both connections.

Simple version: ARP is the postal system that decides which house gets the letter. HTTPS is the sealed envelope inside. We changed the postal routing to deliver to us first. We receive the sealed envelope, open it, read it, reseal it, and deliver it. The envelope was sealed — but it came to us first.

That is why ARP poisoning defeats HTTPS on local networks — unless certificate pinning or HSTS is used.
Real world: In 2011, a researcher demonstrated MitM against HTTPS at a conference by sitting on the same WiFi network as the target. The target saw HTTPS and a padlock. Their credentials were captured in plaintext. SSL Strip is still effective against sites that do not implement HSTS preloading.
PHASE 02
TRAFFIC CLASSIFIER — SPOT THE ATTACK
INTERACTIVE
ARP position confirmed. MENDAX is live on the wire. Now we need to prove the interception is real — six captured packets need classifying before we push to Phase 3.
RAVEN
ENCRYPTED
We have captured network packets from the Ghost Protocol local network. Six packets below. Each one tells a story.

Read each packet carefully. Classify it: is this normal safe traffic, evidence of a MitM interception, or evidence of SSL Strip downgrade?

Look at the protocol, the MAC addresses, and what the content reveals. The details matter.
MISSION OBJECTIVESix packets captured from the Ghost Protocol LAN. For each one, press SAFE, MITM, or SSL STRIP. A correct classification locks the packet. Classify all 6 to proceed.
PACKETS CLASSIFIED
0 of 6 classified
RAVEN — HINT (−20 XP)
Three signals to look for: ARP replies claiming to be another machine (MitM setup), HTTP traffic where HTTPS was expected (SSL Strip), duplicate MAC address appearing for two different IPs (ARP poisoning confirmed). Normal HTTPS traffic with matching MACs and valid certificate info is safe.
✓
ALL PACKETS CORRECTLY CLASSIFIED
You can now read a packet capture and identify MitM activity at a glance. ARP poisoning leaves a clear signature — one MAC address appearing for multiple IPs. SSL Strip is visible as HTTP traffic on a connection that should be HTTPS. Normal encrypted traffic has consistent MAC addresses and HTTPS throughout.

Simple version: The note passer left traces — their handwriting on the refolded note, the different ink, the slightly different fold. If you know what to look for, you can see the interception happened.
Detection tools: Wireshark shows ARP poisoning as duplicate MAC entries. XArp is a dedicated ARP watch tool. Network IDS systems like Snort can alert on ARP anomalies in real time.
PHASE 03
WHICH SCENARIOS ARE SAFE?
CLASSIFY
We can read every packet. Now the harder question: which Ghost Protocol network configurations can we actually attack? Some are armoured. We need to know which ones before we move.
RAVEN
ENCRYPTED
RAVEN pulled a list of network scenarios from Ghost Protocol deployments. Some are safe from MitM. Some are vulnerable.

Tap a scenario to select it. Mark it VULNERABLE to MitM or PROTECTED if MitM cannot succeed in that configuration.

Simple question: can an attacker on the same network get between two communicating machines and read or change the traffic? What stops them if anything?
TAP A SCENARIO — THEN CLASSIFY IT
Select a network scenario above
⚠ VULNERABLE
🔒 PROTECTED
RAVEN — HINT (−20 XP)
Protections that defeat MitM: certificate pinning (app refuses any certificate not on its approved list), HSTS preloading (browser refuses HTTP), mutual TLS (both sides authenticate with certificates), VPN with certificate verification. Shared WiFi with no extra protection = vulnerable, regardless of HTTPS.
✓
ALL SCENARIOS CORRECTLY CLASSIFIED
Being on a shared network — WiFi, office LAN — makes ARP poisoning possible. HTTPS alone does not protect against SSL Strip on a network you do not control. The protections that work are those that authenticate the connection itself: certificate pinning, HSTS preloading, mutual TLS, and verified VPNs.
Why public WiFi is always a risk: Any device on the same WiFi can perform ARP poisoning against any other device. Coffee shop WiFi, hotel networks, conference networks — all vulnerable. A VPN that verifies its certificate before connecting is the only reliable protection on untrusted networks.
PHASE 04
CLOSE THE CHANNEL — THE RIGHT DEFENCE
DEFENSE
INTERCEPTOR's traffic is ours. Before we close this operation, one final call: RAVEN wants to know which single defensive control would have made every phase of this attack impossible from the start.
RAVEN — FINAL DEBRIEF
LAST PHASE
INTERCEPTOR is in custody. Ghost Protocol internal communications are exposed.

RAVEN: "Shadow — final question. The network team is rebuilding the communications infrastructure now. INTERCEPTOR used HTTPS. He thought that was enough. Which single change would have made our interception impossible — even from the same network?"
MISSION OBJECTIVESelect the one defensive control that makes MitM + SSL Strip attacks impossible — even for an attacker already on the same local network. One correct answer closes the operation.
WHICH DEFENCE STOPS MITM + SSL STRIP?
RAVEN — HINT (−20 XP)
SSL Strip worked because the browser accepted HTTP when we served it. The defence that closes this is one that tells the browser — before any connection — that it must always use HTTPS for this domain. Which option does that at the browser level?
► INTEL — OP-17 // OPERATION INTERCEPT
TARGET: NEXUS Corporate Network — Switch Infrastructure
Classification: TOP SECRET // Campaign 3 Ghost Protocol
MENDAX — CHANNEL BRIEFING
PRE-OP
MENDAX
ARP is a stateless protocol with no authentication. Broadcasting a crafted ARP reply poisons the cache of every host on the segment, redirecting their traffic through our interface.
📓

OWASP CLASSIFICATION

INTEL
Network attack: ARP poisoning enables man-in-the-middle on local segments. Combined with SSL stripping, HTTPS sessions are downgraded to HTTP and credentials captured in cleartext.
⚖
GLOSSARY TERMS: ARP Poisoning, ARP Spoofing, Man-in-the-Middle, MITM, SSL Stripping, MAC Table, Gratuitous ARP, 802.1X. All terms auto-logged to your Field Manual as you encounter them.
ACADEMY — MAN-IN-THE-MIDDLE
THE NOTE PASSER READS EVERYTHING.
AND CHANGES WHATEVER THEY WANT.
BEGINNERWhat Is Man-in-the-Middle?›
A Man-in-the-Middle attack happens when an attacker secretly inserts themselves between two communicating parties. Both parties think they are talking directly to each other. The attacker can read, modify, and inject messages without either party knowing.

On local networks, ARP poisoning is the most common method. ARP has no authentication — any device can claim to be any other device. The attacker sends fake ARP replies to redirect traffic through their machine.

Once in the middle, the attacker can read unencrypted traffic immediately. Against HTTPS, they use SSL Strip — serving HTTP to the victim while maintaining HTTPS with the real server. The victim sees HTTP and their credentials travel in plaintext.
Real world: In 2015, Lenovo shipped laptops with pre-installed software (Superfish) that performed MitM against all HTTPS traffic on the machine. It intercepted encrypted banking sessions, social media logins, and email — and injected advertising. Millions of laptops were affected before it was discovered.
INTERMEDIATEAttack Techniques›
ARP Poisoning (local network MitM):
Send fake ARP replies to redirect traffic through the attacker machine. Works on any local network — WiFi, LAN.

SSL Strip:
Intercept the first HTTP request before it redirects to HTTPS. Serve the page to the victim over HTTP. Maintain HTTPS with the real server. Credentials enter in plaintext.

DNS Spoofing:
Respond to DNS queries with a fake IP pointing to an attacker-controlled server. Victim connects to the fake server thinking it is the real one.

Evil Twin WiFi:
Create a fake WiFi access point with the same name as a legitimate one. Devices connect automatically. Attacker sees all traffic.

BGP Hijacking:
At the internet scale — announce false BGP routes to redirect internet traffic through attacker-controlled infrastructure. Used by nation states.
EXPERTDefences and Real CVEs›
Against SSL Strip — HSTS and HSTS Preloading:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Tells browsers to only ever use HTTPS. Preloading bakes this into the browser before any connection is made — SSL Strip has no window to operate.

Against ARP Poisoning:
Dynamic ARP Inspection (DAI) on managed switches
Static ARP entries for critical systems
VPN with strict certificate verification
Network segmentation — attackers on guest WiFi cannot reach production

Against MitM generally:
Certificate pinning for mobile apps
Mutual TLS — both client and server authenticate with certificates
Certificate Transparency logs — detect mis-issued certificates

Notable cases:
2011 DigiNotar CA compromise — fraudulent certificates for Google, used in Iranian MitM
2015 Superfish/Lenovo — MitM on millions of consumer laptops
2017 KRACK — WPA2 WiFi key reinstallation enabling MitM on encrypted WiFi
2011 DigiNotar: Iranian attackers compromised a Dutch certificate authority and issued fraudulent certificates for Google, Mozilla, and others. These certificates were used to perform MitM against Iranian users — their encrypted Google connections were intercepted by the government. 300,000 users affected before the CA was revoked. The incident led to mandatory Certificate Transparency logging.
REAL-WORLD TOOLS — MAN-IN-THE-MIDDLE
WHAT PROFESSIONALS USE
📷
Wireshark
FREE / OPEN SOURCE
Capture and analyse network packets. Detect ARP poisoning by looking for duplicate MAC addresses across multiple IPs. Filter by ARP to see poisoning attempts in real time.
Filter: arp.duplicate-address-detected or http.request
⚡
Bettercap
FREE / OPEN SOURCE
Modern MitM framework. Performs ARP spoofing, DNS spoofing, SSL Strip, and traffic injection. The standard tool for authorised MitM testing on local networks.
bettercap -iface eth0 -eval "net.probe on; arp.spoof on; net.sniff on"
🔎
XArp
FREE TIER
Dedicated ARP watch tool for Windows and Linux. Monitors the ARP table and alerts when suspicious ARP replies are detected — the first line of defence against ARP poisoning.
xarp --monitor --interface eth0 --alert
🔥
mitmproxy
FREE / OPEN SOURCE
Interactive HTTPS proxy for authorised testing. Intercepts, inspects, and modifies HTTPS traffic. Used by security researchers to understand what apps send over encrypted connections.
mitmproxy --mode transparent --showhost
⚡
XP EARNED
+0
FIRST ATTEMPT
RANK: RECRUIT