Unencrypted Communication
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.
- Prevalence
- Occasional
- Exploitability
- Difficult
- Impact
- Devastating
What is unencrypted communication?
Unencrypted communication is a cryptographic failure in which data travels between a browser and a server over plain HTTP, or another protocol without encryption. Anyone on the network path can mount a monster-in-the-middle (man-in-the-middle) attack, reading or changing the traffic to steal passwords, session cookies and personal data. Transport Layer Security (TLS) prevents this.
What you'll learn
- How a web request travels across the local network to the internet
- How ARP spoofing lets an attacker read unencrypted traffic
- Why every page and cookie should be served over HTTPS
Where this lesson counts
OWASP Top 10
Weak, missing or misused encryption lets attackers read or tamper with data in transit and at rest.
Learn more about A04PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4Requirement 4.2.1: cardholder data crossing open, public networks must be protected with strong cryptography and trusted certificates.
Requirement 4.2.1 mandates strong cryptography for data in transit; plaintext HTTP fails it outright.
Learn more about 4.2.1This lesson includes
-
Unencrypted Communication lab
Trace a web request from the browser through the local network to the internet. Then see how an attacker on the same network uses ARP spoofing to route traffic through their own device, reading anything that isn't encrypted before passing it along.
-
How to prevent Unencrypted Communication
The prevention guide covers two approaches:
- Buy a Certificate, Install It, and Configure Your Web Server to Use It
- Serve Every Page over HTTPS
-
Unencrypted Communication quiz
Three questions. Passing marks the lesson complete.
Sources
- Transport Layer Security MDN
- Why use TLS 1.3? Cloudflare
- What is TLS? Acunetix
Related lessons
Browse all 45 lessons
SSL Stripping
If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.
Downgrade Attacks
Attackers may be able to intercept, read and manipulate HTTPS traffic if you fail to specify a modern version of TLS.
DNS Poisoning
If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.
Weak Session IDs
Guessable session IDs make your website vulnerable to session hijacking.