logo

Mallet in the Middle

ID: 6ea53236-d727-5ced-bab1-43a13a487305

STIX ID: report--6ea53236-d727-5ced-bab1-43a13a487305

Feed Name: SensePost Blog

Date Published: 2018-10-10

Date Updated: 2026-04-29

...
...

This guide explains how to place a small GL.iNet router running OpenWRT between a kiosk and its upstream network to perform transparent man-in-the-middle interception. It covers Wi-Fi management setup, bridging the Ethernet ports, disabling the firewall, installing tcpdump and necessary kernel modules, and crafting ebtables/iptables rules to impersonate the victim and router at both MAC and IP layers. The post then shows how to redirect TCP flows to redsocks and tunnel them via SSH to Mallet for inspection and manipulation, enabling end-to-end interception and analysis of kiosk traffic while keeping the device largely invisible on the wire.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.