10–20 min Updated

Unencrypted Communication

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.

Prevalence
Occasional
Exploitability
Difficult
Impact
Devastating

What is unencrypted communication?

Unencrypted communication is a cryptographic failure in which data travels between a browser and a server over plain HTTP, or another protocol without encryption. Anyone on the network path can mount a monster-in-the-middle (man-in-the-middle) attack, reading or changing the traffic to steal passwords, session cookies and personal data. Transport Layer Security (TLS) prevents this.

What you'll learn

  • How a web request travels across the local network to the internet
  • How ARP spoofing lets an attacker read unencrypted traffic
  • Why every page and cookie should be served over HTTPS

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • Unencrypted Communication lab

    Trace a web request from the browser through the local network to the internet. Then see how an attacker on the same network uses ARP spoofing to route traffic through their own device, reading anything that isn't encrypted before passing it along.

  • How to prevent Unencrypted Communication

    The prevention guide covers two approaches:

    • Buy a Certificate, Install It, and Configure Your Web Server to Use It
    • Serve Every Page over HTTPS
  • Unencrypted Communication quiz

    Three questions. Passing marks the lesson complete.

Sources

  • SSL Stripping

    If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.

  • Downgrade Attacks

    Attackers may be able to intercept, read and manipulate HTTPS traffic if you fail to specify a modern version of TLS.

  • DNS Poisoning

    If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.

  • Weak Session IDs

    Guessable session IDs make your website vulnerable to session hijacking.