February 2019
Beginner to intermediate
366 pages
7h 49m
English
Just using passive scanning, which means without aggressive actions, Burp Suite detected that the users can force the application to be used in an unprotected channel. This means that instead of using the HTTPS protocol, a user can force the use of the HTTP protocol and send information in clear text. It could be exploited by a malicious user, combined with other flaws to steal a user's information, as shown in the following example:

This flaw is confirmed.
Read now
Unlock full access