EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A security auditor is examining a web server that hosts multiple virtual hosts. The auditor discovers that one of the virtual hosts is configured with weak ciphers and an outdated TLS protocol version (TLS 1.0). An attacker could potentially exploit this misconfiguration to downgrade the encryption and intercept sensitive data. Which common web server attack category does this scenario fall under?

  1. AInformation Disclosure
  2. BSession Hijacking
  3. CMan-in-the-Middle (MitM)
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: C. Man-in-the-Middle (MitM)

Weak ciphers and outdated TLS protocols are classic vulnerabilities that can be exploited in a Man-in-the-Middle (MitM) attack. An attacker can force the communication to use weaker encryption, allowing them to decrypt and intercept traffic.

Why the other options are wrong

  • A. Information Disclosure might be a consequence, but the direct attack facilitated by weak crypto is MitM.
  • B. Session Hijacking involves stealing an active session, which could be a *result* of MitM, but MitM is the direct exploit of the weak crypto.
  • D. DoS attacks aim to make a service unavailable, not to intercept data via weak encryption.

TLS Downgrade Attack

A TLS downgrade attack forces a client and server to negotiate an older, less secure version of the TLS (or SSL) protocol, making the connection vulnerable to eavesdropping and tampering.

  • Often relies on the server supporting outdated protocols (e.g., TLS 1.0, SSLv3).
  • Can be combined with weak cipher suites for easier exploitation.
  • Prevented by disabling all outdated protocols and weak ciphers on the server.

Memory trick: Network Weaknesses Invite Eavesdroppers.

More Web Application Hacking questions