Downgrade Attacks
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Attackers may be able to intercept, read and manipulate HTTPS traffic if you fail to specify a modern version of TLS.
- Prevalence
- Occasional
- Exploitability
- Difficult
- Impact
- Harmful
What is a downgrade attack?
A downgrade attack is a monster-in-the-middle (man-in-the-middle) attack in which an attacker interferes with the negotiation of a secure connection, forcing the client and server to use an older version of TLS or a weaker cipher. The attacker can then exploit known flaws in the older protocol to read or manipulate the encrypted traffic.
What you'll learn
- How client and server agree on encryption during the TLS handshake
- How an attacker in the middle forces a connection onto a weaker protocol
- How to set a minimum TLS version on your server
Where this lesson counts
OWASP Top 10
Weak, missing or misused encryption lets attackers read or tamper with data in transit and at rest.
Learn more about A04PCI DSS 4.0
Requirement 4.2.1: cardholder data crossing open, public networks must be protected with strong cryptography and trusted certificates.
Learn more about 4.2.1This lesson includes
-
Downgrade Attacks lab
See how a client and server agree on encryption algorithms during the TLS handshake, and how an attacker sitting between them can push both sides back to an older, weaker version. The lab ends on the fix: a minimum TLS version set on your server.
-
How to prevent Downgrade Attacks
The prevention guide covers two approaches:
- Specify a Minimum Version of TLS
- Ensure All Traffic is Sent Over HTTPS
-
Downgrade Attacks quiz
Two questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
SSL Stripping
If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.
Unencrypted Communication
Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.
DNS Poisoning
If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.