Is a disk image of one of these available anywhere? I find it much more likely that these are being used for what they say they are (basically a proxy so they can buy ads from a residential IP) than some crazy MITM device. The "Attacker" is basically renting an IP connection or paying a co-location fee for their little server. Plugging a device into your network doesn't make it magically see all the traffic. It would…
> Plugging a device into your network doesn't make it magically see all the traffic. Isn't that exactly what Wireshark's "promiscuous mode" does?
You have to use ARP poisoning or some other trick to get other network devices to send ethernet frames to your mac address in order for the switch to forward them out your port.