Disabled hostname verification

Disabled hostname verification

Description

Disabling hostname verification in a TLS connection can let an attacker with a valid certificate for another host impersonate the target server.

Potential impact

  • Man-in-the-middle attacks, eavesdropping, or session hijacking may become possible.

Remediation

Enable hostname verification and remove test settings that disable CURLOPT_SSL_VERIFYHOST.

Examples

Before

c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0L);

After

c
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);

Explanation:

  • Before: The hostname in the certificate is not checked.
  • After: The certificate hostname is checked against the connection target.

References