D2 · Threats

What is an on-path attack?

An on-path attack (formerly called man-in-the-middle) positions the attacker in the communication path to intercept, read, and modify traffic between two parties.
CompTIA now uses "on-path" instead of MITM. Same concept — attacker positioned between two communicating parties. Prevention: TLS/HTTPS, VPNs, certificate pinning, HSTS.
← Back to Glossary Practice Questions →