Intelligence View
⚡ tsecurity.de Intelligence
What is an SSL Stripping Attack and How to Prevent It
For years, people learned to associate HTTPS with a “secure site.” When a browser connects using SSL/TLS, the traffic between the user and the server is enc…
For years, people learned to associate HTTPS with a “secure site.” When a browser connects using SSL/TLS, the traffic between the user and the server is encrypted, which prevents outsiders from reading or modifying the data in transit. SSL stripping attacks exploit a weak moment in that process. An attacker positioned on the network intercepts the initial request and prevents the browser from switching to HTTPS. The victim continues over plain HTTP, while the attacker keeps a secure session with the real server in the background. What looks like a normal browsing session is actually exposed traffic. This article walks through what SSL stripping is, how the attack works, the risks it creates, and the practical defenses that stop it. What is an SSL Stripping Attack? An SSL stripping attack is a downgrade technique that forces a web session to stay on HTTP instead of upgrading to secure network. Because it forces a downgrade from HTTPS to HTTP, the technique is often called an SSL downgrade attack. In this man-in-the-middle attack, the perpetrator intercepts network traffic and either deletes or strips out the encryption layer between the browser and the web server. SSL certificates encrypt the traffic and authenticate the […]
Cyber Threat Intelligence & Forensik
Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC