D2 · Threats

What is SSL stripping?

SSL stripping downgrades HTTPS connections to HTTP — the MITM intercepts the HTTPS connection to the server and serves HTTP to the victim, who never gets the secure connection.
HSTS (HTTP Strict Transport Security) prevents SSL stripping by telling browsers to ALWAYS use HTTPS for a domain. HSTS preloading bakes domains into browsers. Without HSTS, the first HTTP request is vulnerable.
← Back to Glossary Practice Questions →