Secure Socket Layer Stripping Attack Using Address Resolution Protocol Spoofing
Siromani Duddu, Arigela Rishita sai, Ch. L S Sowjanya, G. Ramakoteswara Rao, KarthikSainadh Siddabattula · 2020
This paper describes the step by step procedure to make SSL strip attack any secured https website. Though we are having the SSL certificate for a website, we are subjected to MITM attacks, from this; we can say that SSL provides a false sense of security. Both HTTP and HTTPS are the application layer protocols in the TCP/IP model. Using HTTP communication protocol, the data which is being transmitted is in a decrypted format that is in the form of plain text which, when sniffed by the attacker, is like an open book which is not at all safe and completely useless while using complicated websites like online banking. So https is used where the data is transmitted in a secure tunnel, which is nothing but the link established between the web server and the browser, and the information which is sent between them is encrypted, which when sniffed by an attacker is of no use to him. So, we can say that https is secure until the's' is stripped from https, which is known as an SSL strip attack. SSL strip attack is downgrading the https site to HTTP by using various methods. Here we are using ARP spoofing to strip HTTPS to HTTP.