It's a playback of wireless traffic which provides access to any web mail account, and it appears to work even if the account password or hash is protected by SSL. I don't think it is an MITM attack since the traffic is pulled out of the air.

Seems like a fundamental flaw in web authentication. I can't see how this could be though. Very confused.