This comes up on nearly every internal pentest scoping call eventually: "we don't really think we need man-in-the-middle testing, everything internal runs over HTTPS." It's usually said with real confidence, and it's usually true at the application layer. It's still the wrong reason to skip the test, because ARP spoofing doesn't operate at the application layer.
ARP spoofing works at layer 2, two full layers below where HTTPS lives. ARP has zero built-in authentication, so sending forged ARP replies telling the switch and the target that your machine's MAC address is the gateway's just works, and traffic starts routing through you. The target's browser can keep showing a padlock the entire time, because as far as the browser is concerned nothing changed, it's still talking HTTPS to what it believes is the real server. The path to that server just happens to run through you now.
So the interesting part once you're in that position isn't the HTTPS traffic itself. It's everything HTTPS was never protecting:
- The printer on the same subnet still authenticating over plaintext SNMP
- The internal admin panel someone stood up in a hurry, never got a real cert, and everyone's been clicking through the browser warning on for a year
- The legacy service two teams forgot still exists, which happily serves a plain HTTP fallback if nothing forces a redirect
- DNS queries, plaintext by default on most internal networks, spoofable to point a completely convincing login page at a clone of it
None of that requires breaking TLS. It requires being on the same network segment and asking layer 2 to lie, and most internal networks do exactly that without a fight.
That's the finding that actually matters at the end of an engagement like this: not "we broke HTTPS," but "here's the cleartext and the unpinned certs someone on this segment would have caught in under an hour, and here's what the scoping call quietly assumed away when it said this test wasn't needed."
This is basically the whole subject of Codelivly's Man-in-the-Middle Attack Book: ARP and DNS spoofing, evil-twin setups, SSL interception, worked through hands-on. If "everything's HTTPS" has ever been the reason a test got scoped out, this is the part of the job that answer skips over.
Source: r/u/Potential-Couple-745 · by /u/Potential-Couple-745