EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

During a penetration test, an ethical hacker discovers that a web application uses HTTP Basic Authentication over an unencrypted HTTP connection. The hacker intercepts the traffic and easily decodes the Base64-encoded credentials, gaining access to user accounts. Which web server attack countermeasure would have prevented this specific vulnerability?

  1. AEnabling HTTP Strict Transport Security (HSTS).
  2. BImplementing strong password policies.
  3. CUsing HTTPS for all authenticated communication.
  4. DDeploying a Web Application Firewall (WAF).
Show answer & explanation

Correct answer: C. Using HTTPS for all authenticated communication.

HTTP Basic Authentication sends credentials in Base64 encoding, which is not encryption. When used over unencrypted HTTP, these credentials can be easily intercepted and decoded. Using HTTPS ensures that all communication, including Basic Auth credentials, is encrypted via TLS/SSL, preventing eavesdropping.

Why the other options are wrong

  • A. HSTS forces browsers to use HTTPS, but the core countermeasure is the implementation of HTTPS itself, which HSTS reinforces.
  • B. Strong password policies are important but don't prevent credentials from being intercepted if the connection is unencrypted.
  • D. A WAF might detect brute-force attempts but wouldn't prevent the interception of credentials over an unencrypted channel.

HTTP Basic Authentication over HTTP

HTTP Basic Authentication sends credentials (username:password) Base64 encoded in the Authorization header. When used over unencrypted HTTP, these are easily intercepted and decoded.

  • Base64 encoding is not encryption; it's reversible.
  • Vulnerable to eavesdropping attacks if not combined with encryption (e.g., TLS/SSL).
  • Should always be used with HTTPS to protect credentials in transit.

Memory trick: Auth Always Needs Encryption.

More Web Application Hacking questions