CompTIA Network+ (N10-009)Network SecurityHard

An attacker positions a laptop between a victim and a legitimate website using a rogue access point, then intercepts the victim's HTTPS session and forces the browser to communicate over unencrypted HTTP instead, silently capturing login credentials. Which attack technique is being used?

  1. ADeauthentication attack
  2. BMAC flooding
  3. CDNS cache poisoning
  4. DSSL stripping (on-path downgrade attack)
Show answer & explanation

Correct answer: D. SSL stripping (on-path downgrade attack)

SSL stripping is an on-path (man-in-the-middle) technique where the attacker intercepts traffic and downgrades the victim's connection from HTTPS to HTTP, allowing credentials and data to be captured in plaintext while the victim is often unaware the encryption was removed. This differs from deauth attacks, which simply disconnect clients, and MAC flooding, which targets switch CAM tables.

Why the other options are wrong

  • A. A deauthentication attack disconnects wireless clients but does not intercept or downgrade traffic content.
  • B. MAC flooding overwhelms a switch's CAM table to force traffic broadcast, unrelated to protocol downgrading.
  • C. DNS cache poisoning redirects domain lookups but doesn't itself downgrade encryption on an active session.

SSL Stripping (On-Path Downgrade Attack)

A man-in-the-middle technique where an attacker intercepts a session and forces communication to fall back from HTTPS to unencrypted HTTP to capture sensitive data.

  • Requires the attacker to be positioned in the traffic path (on-path/MITM)
  • Victim's browser may show HTTP instead of HTTPS without obvious warning
  • Mitigated by HSTS (HTTP Strict Transport Security)

Memory trick: Strip the 'S' from HTTPS, and the lock on the door disappears.

More Network Security questions