SSL stripping is an attack in which a secure HTTPS connection is secretly downgraded to unencrypted HTTP, allowing an attacker to eavesdrop on login credentials and other sensitive data. You can prevent this by setting up HSTS, always using a valid SSL certificate, forcing all HTTP traffic to HTTPS, and as a visitor, watching for the padlock in your browser. Below you’ll find exactly how this works and what you need to configure.
What is SSL stripping?
With SSL stripping, an attacker intercepts the traffic between your browser and a website. Normally, your browser recognizes a site via HTTPS, but the attacker ensures the connection silently falls back to HTTP. You think you’re safe, while your data travels unencrypted over the line. This often happens on unsecured Wi-Fi networks, such as in cafΓ©s or at train stations, where an attacker positions themselves between you and the router.
The danger lies in the fact that the attack is nearly invisible. The website looks normal, except the padlock is missing from the address bar or it shows HTTP instead of HTTPS. Many people don’t notice this, which allows passwords, payment details, and sessions to be stolen.
How the attack works
An attacker positions themselves between the user and the server, known as a man-in-the-middle position. When the browser sends an initial request to a site, this often still happens via HTTP before the redirect to HTTPS occurs. At exactly that moment, the attacker intervenes: they keep the connection with the user on HTTP, while setting up an HTTPS connection with the real server themselves. This way, everything appears normal to the server, while the user remains unprotected.
Preventing SSL stripping as a website owner
As a website owner, you can take the most important measures yourself. These ensure visitors never end up on an unencrypted version of your site.
Force HTTPS with a redirect
Make sure every HTTP request is automatically forwarded to the HTTPS version of your site. You can set this up via your server configuration or in Plesk under your domain’s settings.
Set up HSTS
HTTP Strict Transport Security tells the browser that your site must always be accessed via HTTPS, even if a user accidentally types HTTP. This greatly reduces the risk of intercepted initial requests.
Use a valid SSL certificate
An expired or invalid certificate gives browsers reason to display warnings, which confuses visitors. Use a free SSL certificate that renews automatically, so this never becomes an issue.
Check your email and domain security
Email traffic and DNS settings can also be exploited as part of a broader attack. Make sure your business email and domain registration are properly secured and kept up to date.
In Plesk, you’ll easily find your domain’s SSL settings under the ‘SSL/TLS Certificates’ section, where you can also directly activate HSTS.
Browsing safely as a user
In addition to server-level measures, you can also limit risks yourself as a user. Always check for the padlock in the address bar before entering sensitive information. Avoid logging into important accounts over open Wi-Fi networks without a password, and use a VPN where possible if you must work on public Wi-Fi.
Browsers nowadays warn increasingly well about insecure connections, but stay alert for unusual URLs or a missing padlock. Not sure about a website? It’s better to close the connection than to enter your details.
Frequently Asked Questions
Is SSL stripping the same as a man-in-the-middle attack?
SSL stripping is a specific form of man-in-the-middle attack, aimed at downgrading a secure connection to unencrypted HTTP.
Does an SSL certificate alone protect against this attack?
An SSL certificate is necessary but not sufficient. Without HSTS and a proper HTTPS redirect, there remains a vulnerable moment during the initial request.
Can this also affect my email?
Yes, unsecured email traffic can be intercepted in a similar way. Always use encrypted connections for business email.
Does HSTS work with any type of hosting?
HSTS operates at the server level and can be easily activated in most modern hosting environments with Plesk via your domain’s SSL settings.
How do I know if my site is vulnerable?
Check whether every page, including subdomains, automatically redirects to HTTPS and whether HSTS is active. Online security tests can provide insight into this.
Conclusion
SSL stripping exploits the moment when a connection is not yet secured. By enforcing HTTPS, setting up HSTS, and using a valid SSL certificate, you effectively close this gap. Learn more about web hosting with free SSL, or see how easily you can switch to Tandata for a securely configured environment.