November 2017
Intermediate to advanced
542 pages
14h 24m
English
When you type in your bank's website, do you enter mybank.example.com, or do you enter https://mybank.example.com? If you omit the HTTPS protocol, you are potentially vulnerable to man in the middle attacks. Even if the website performs a redirect to https://mybank.example.com, a malicious user could intercept the initial HTTP request and manipulate the response (redirect to https://mibank.example.com and steal their credentials).
Many users omit the HTTPS protocol, and this is why HSTS was created.
In accordance with RFC6797, the HSTS header is only injected into HTTPS responses. In order for the browser to acknowledge the header, the browser must first trust the CA that signed the SSL certificate used to ...
Read now
Unlock full access