Skip to main content

Overview

HSTS forces browsers to use HTTPS only. Without it, attacker can intercept HTTP requests and perform SSL stripping (downgrade HTTPS → HTTP).

Check HSTS

Expected Header


Directives


Misconfigurations

Missing HSTS

No header → SSL stripping possible on first visit.

Low max-age

max-age=0 disables HSTS. Low values = short protection window.

Missing includeSubDomains

Subdomains still accessible via HTTP → MITM on subdomain.

HSTS on HTTP Response

HSTS header on HTTP (not HTTPS) response is ignored by browsers. Must be served over HTTPS.

Missing preload

Without preload, first visit to site is still vulnerable (TOFU — Trust On First Use).

SSL Stripping Attack

When HSTS is missing or expired:

bettercap

sslstrip (Legacy)

Intercepts HTTP → HTTPS redirects. Victim stays on HTTP, attacker proxies to HTTPS.

HSTS Preload

Browser ships with hardcoded list of HSTS domains. Protects even first visit.
Requirements:
  • Valid HTTPS on root domain
  • Redirect HTTP → HTTPS
  • HSTS header with max-age >= 31536000, includeSubDomains, preload
  • All subdomains serve HTTPS

Testing

Check Preload Status

Check HTTP → HTTPS Redirect

Check Certificate


Quick Reference


Sources