SSL Stripping
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Harmful
What is SSL stripping?
SSL stripping is a monster-in-the-middle (man-in-the-middle) attack in which an attacker intercepts a user's first insecure HTTP request and stops the connection from being upgraded to HTTPS. The attacker talks to the website over HTTPS while serving the user plain HTTP, reading and manipulating everything in between, including passwords. The website cannot detect that anything is wrong.
What you'll learn
- Why serving some pages over HTTP puts the secure ones at risk
- How an attacker in the middle rewrites HTTPS links to capture credentials
- How enforcing HTTPS and HTTP Strict Transport Security prevents stripping
Where this lesson counts
OWASP Top 10
Weak, missing or misused encryption lets attackers read or tamper with data in transit and at rest.
Learn more about A04PCI DSS 4.0
Requirement 4.2.1: cardholder data crossing open, public networks must be protected with strong cryptography and trusted certificates.
Learn more about 4.2.1This lesson includes
-
SSL Stripping lab
Sites used to serve pages over HTTP and switch to HTTPS only at login. See how Moxie Marlinspike's sslstrip tool sits in the middle, rewrites the login form's HTTPS links to HTTP and captures credentials while the server still sees a secure connection.
-
How to prevent SSL Stripping
The prevention guide covers two approaches:
- Enforce HTTPS for All Traffic
- Implement HTTP Strict Transport Security
-
SSL Stripping quiz
Two questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
Downgrade Attacks
Attackers may be able to intercept, read and manipulate HTTPS traffic if you fail to specify a modern version of TLS.
Unencrypted Communication
Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.
DNS Poisoning
If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.
Lax Security Settings
Improper security settings are a common cause of vulnerabilities.