15–25 min Updated

SSL Stripping

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.

Prevalence
Occasional
Exploitability
Easy
Impact
Harmful

What is SSL stripping?

SSL stripping is a monster-in-the-middle (man-in-the-middle) attack in which an attacker intercepts a user's first insecure HTTP request and stops the connection from being upgraded to HTTPS. The attacker talks to the website over HTTPS while serving the user plain HTTP, reading and manipulating everything in between, including passwords. The website cannot detect that anything is wrong.

What you'll learn

  • Why serving some pages over HTTP puts the secure ones at risk
  • How an attacker in the middle rewrites HTTPS links to capture credentials
  • How enforcing HTTPS and HTTP Strict Transport Security prevents stripping

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • SSL Stripping lab

    Sites used to serve pages over HTTP and switch to HTTPS only at login. See how Moxie Marlinspike's sslstrip tool sits in the middle, rewrites the login form's HTTPS links to HTTP and captures credentials while the server still sees a secure connection.

  • How to prevent SSL Stripping

    The prevention guide covers two approaches:

    • Enforce HTTPS for All Traffic
    • Implement HTTP Strict Transport Security
  • SSL Stripping quiz

    Two questions. Passing marks the lesson complete.

Sources

  • Downgrade Attacks

    Attackers may be able to intercept, read and manipulate HTTPS traffic if you fail to specify a modern version of TLS.

  • Unencrypted Communication

    Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.

  • DNS Poisoning

    If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.

  • Lax Security Settings

    Improper security settings are a common cause of vulnerabilities.